1 /* 2 * gdb server stub - system specific bits 3 * 4 * Debug integration depends on support from the individual 5 * accelerators so most of this involves calling the ops helpers. 6 * 7 * Copyright (c) 2003-2005 Fabrice Bellard 8 * Copyright (c) 2022 Linaro Ltd 9 * 10 * SPDX-License-Identifier: LGPL-2.0-or-later 11 */ 12 13 #include "qemu/osdep.h" 14 #include "qapi/error.h" 15 #include "qemu/error-report.h" 16 #include "qemu/cutils.h" 17 #include "exec/gdbstub.h" 18 #include "gdbstub/syscalls.h" 19 #include "gdbstub/commands.h" 20 #include "exec/hwaddr.h" 21 #include "exec/tb-flush.h" 22 #include "system/cpus.h" 23 #include "system/runstate.h" 24 #include "system/replay.h" 25 #include "hw/core/cpu.h" 26 #include "hw/cpu/cluster.h" 27 #include "hw/boards.h" 28 #include "chardev/char.h" 29 #include "chardev/char-fe.h" 30 #include "monitor/monitor.h" 31 #include "trace.h" 32 #include "internals.h" 33 34 /* System emulation specific state */ 35 typedef struct { 36 CharBackend chr; 37 Chardev *mon_chr; 38 } GDBSystemState; 39 40 GDBSystemState gdbserver_system_state; 41 42 static void reset_gdbserver_state(void) 43 { 44 g_free(gdbserver_state.processes); 45 gdbserver_state.processes = NULL; 46 gdbserver_state.process_num = 0; 47 gdbserver_state.allow_stop_reply = false; 48 } 49 50 /* 51 * Return the GDB index for a given vCPU state. 52 * 53 * In system mode GDB numbers CPUs from 1 as 0 is reserved as an "any 54 * cpu" index. 55 */ 56 int gdb_get_cpu_index(CPUState *cpu) 57 { 58 return cpu->cpu_index + 1; 59 } 60 61 /* 62 * We check the status of the last message in the chardev receive code 63 */ 64 bool gdb_got_immediate_ack(void) 65 { 66 return true; 67 } 68 69 /* 70 * GDB Connection management. For system emulation we do all of this 71 * via our existing Chardev infrastructure which allows us to support 72 * network and unix sockets. 73 */ 74 75 void gdb_put_buffer(const uint8_t *buf, int len) 76 { 77 /* 78 * XXX this blocks entire thread. Rewrite to use 79 * qemu_chr_fe_write and background I/O callbacks 80 */ 81 qemu_chr_fe_write_all(&gdbserver_system_state.chr, buf, len); 82 } 83 84 static void gdb_chr_event(void *opaque, QEMUChrEvent event) 85 { 86 int i; 87 GDBState *s = (GDBState *) opaque; 88 89 switch (event) { 90 case CHR_EVENT_OPENED: 91 /* Start with first process attached, others detached */ 92 for (i = 0; i < s->process_num; i++) { 93 s->processes[i].attached = !i; 94 } 95 96 s->c_cpu = gdb_first_attached_cpu(); 97 s->g_cpu = s->c_cpu; 98 99 vm_stop(RUN_STATE_PAUSED); 100 replay_gdb_attached(); 101 break; 102 default: 103 break; 104 } 105 } 106 107 /* 108 * In system-mode we stop the VM and wait to send the syscall packet 109 * until notification that the CPU has stopped. This must be done 110 * because if the packet is sent now the reply from the syscall 111 * request could be received while the CPU is still in the running 112 * state, which can cause packets to be dropped and state transition 113 * 'T' packets to be sent while the syscall is still being processed. 114 */ 115 void gdb_syscall_handling(const char *syscall_packet) 116 { 117 vm_stop(RUN_STATE_DEBUG); 118 qemu_cpu_kick(gdbserver_state.c_cpu); 119 } 120 121 static void gdb_vm_state_change(void *opaque, bool running, RunState state) 122 { 123 CPUState *cpu = gdbserver_state.c_cpu; 124 g_autoptr(GString) buf = g_string_new(NULL); 125 g_autoptr(GString) tid = g_string_new(NULL); 126 const char *type; 127 int ret; 128 129 if (running || gdbserver_state.state == RS_INACTIVE) { 130 return; 131 } 132 133 /* Is there a GDB syscall waiting to be sent? */ 134 if (gdb_handled_syscall()) { 135 return; 136 } 137 138 if (cpu == NULL) { 139 /* No process attached */ 140 return; 141 } 142 143 if (!gdbserver_state.allow_stop_reply) { 144 return; 145 } 146 147 gdb_append_thread_id(cpu, tid); 148 149 switch (state) { 150 case RUN_STATE_DEBUG: 151 if (cpu->watchpoint_hit) { 152 switch (cpu->watchpoint_hit->flags & BP_MEM_ACCESS) { 153 case BP_MEM_READ: 154 type = "r"; 155 break; 156 case BP_MEM_ACCESS: 157 type = "a"; 158 break; 159 default: 160 type = ""; 161 break; 162 } 163 trace_gdbstub_hit_watchpoint(type, 164 gdb_get_cpu_index(cpu), 165 cpu->watchpoint_hit->vaddr); 166 g_string_printf(buf, "T%02xthread:%s;%swatch:%" VADDR_PRIx ";", 167 GDB_SIGNAL_TRAP, tid->str, type, 168 cpu->watchpoint_hit->vaddr); 169 cpu->watchpoint_hit = NULL; 170 goto send_packet; 171 } else { 172 trace_gdbstub_hit_break(); 173 } 174 tb_flush(cpu); 175 ret = GDB_SIGNAL_TRAP; 176 break; 177 case RUN_STATE_PAUSED: 178 trace_gdbstub_hit_paused(); 179 ret = GDB_SIGNAL_INT; 180 break; 181 case RUN_STATE_SHUTDOWN: 182 trace_gdbstub_hit_shutdown(); 183 ret = GDB_SIGNAL_QUIT; 184 break; 185 case RUN_STATE_IO_ERROR: 186 trace_gdbstub_hit_io_error(); 187 ret = GDB_SIGNAL_STOP; 188 break; 189 case RUN_STATE_WATCHDOG: 190 trace_gdbstub_hit_watchdog(); 191 ret = GDB_SIGNAL_ALRM; 192 break; 193 case RUN_STATE_INTERNAL_ERROR: 194 trace_gdbstub_hit_internal_error(); 195 ret = GDB_SIGNAL_ABRT; 196 break; 197 case RUN_STATE_SAVE_VM: 198 case RUN_STATE_RESTORE_VM: 199 return; 200 case RUN_STATE_FINISH_MIGRATE: 201 ret = GDB_SIGNAL_XCPU; 202 break; 203 default: 204 trace_gdbstub_hit_unknown(state); 205 ret = GDB_SIGNAL_UNKNOWN; 206 break; 207 } 208 gdb_set_stop_cpu(cpu); 209 g_string_printf(buf, "T%02xthread:%s;", ret, tid->str); 210 211 send_packet: 212 gdb_put_packet(buf->str); 213 gdbserver_state.allow_stop_reply = false; 214 215 /* disable single step if it was enabled */ 216 cpu_single_step(cpu, 0); 217 } 218 219 #ifndef _WIN32 220 static void gdb_sigterm_handler(int signal) 221 { 222 if (runstate_is_running()) { 223 vm_stop(RUN_STATE_PAUSED); 224 } 225 } 226 #endif 227 228 static int gdb_monitor_write(Chardev *chr, const uint8_t *buf, int len) 229 { 230 g_autoptr(GString) hex_buf = g_string_new("O"); 231 gdb_memtohex(hex_buf, buf, len); 232 gdb_put_packet(hex_buf->str); 233 return len; 234 } 235 236 static void gdb_monitor_open(Chardev *chr, ChardevBackend *backend, 237 bool *be_opened, Error **errp) 238 { 239 *be_opened = false; 240 } 241 242 static void char_gdb_class_init(ObjectClass *oc, void *data) 243 { 244 ChardevClass *cc = CHARDEV_CLASS(oc); 245 246 cc->internal = true; 247 cc->open = gdb_monitor_open; 248 cc->chr_write = gdb_monitor_write; 249 } 250 251 #define TYPE_CHARDEV_GDB "chardev-gdb" 252 253 static const TypeInfo char_gdb_type_info = { 254 .name = TYPE_CHARDEV_GDB, 255 .parent = TYPE_CHARDEV, 256 .class_init = char_gdb_class_init, 257 }; 258 259 static int gdb_chr_can_receive(void *opaque) 260 { 261 /* 262 * We can handle an arbitrarily large amount of data. 263 * Pick the maximum packet size, which is as good as anything. 264 */ 265 return MAX_PACKET_LENGTH; 266 } 267 268 static void gdb_chr_receive(void *opaque, const uint8_t *buf, int size) 269 { 270 int i; 271 272 for (i = 0; i < size; i++) { 273 gdb_read_byte(buf[i]); 274 } 275 } 276 277 static int find_cpu_clusters(Object *child, void *opaque) 278 { 279 if (object_dynamic_cast(child, TYPE_CPU_CLUSTER)) { 280 GDBState *s = (GDBState *) opaque; 281 CPUClusterState *cluster = CPU_CLUSTER(child); 282 GDBProcess *process; 283 284 s->processes = g_renew(GDBProcess, s->processes, ++s->process_num); 285 286 process = &s->processes[s->process_num - 1]; 287 288 /* 289 * GDB process IDs -1 and 0 are reserved. To avoid subtle errors at 290 * runtime, we enforce here that the machine does not use a cluster ID 291 * that would lead to PID 0. 292 */ 293 assert(cluster->cluster_id != UINT32_MAX); 294 process->pid = cluster->cluster_id + 1; 295 process->attached = false; 296 process->target_xml = NULL; 297 298 return 0; 299 } 300 301 return object_child_foreach(child, find_cpu_clusters, opaque); 302 } 303 304 static int pid_order(const void *a, const void *b) 305 { 306 GDBProcess *pa = (GDBProcess *) a; 307 GDBProcess *pb = (GDBProcess *) b; 308 309 if (pa->pid < pb->pid) { 310 return -1; 311 } else if (pa->pid > pb->pid) { 312 return 1; 313 } else { 314 return 0; 315 } 316 } 317 318 static void create_processes(GDBState *s) 319 { 320 object_child_foreach(object_get_root(), find_cpu_clusters, s); 321 322 if (gdbserver_state.processes) { 323 /* Sort by PID */ 324 qsort(gdbserver_state.processes, 325 gdbserver_state.process_num, 326 sizeof(gdbserver_state.processes[0]), 327 pid_order); 328 } 329 330 gdb_create_default_process(s); 331 } 332 333 bool gdbserver_start(const char *device, Error **errp) 334 { 335 Chardev *chr = NULL; 336 Chardev *mon_chr; 337 g_autoptr(GString) cs = g_string_new(device); 338 339 if (!first_cpu) { 340 error_setg(errp, "gdbstub: meaningless to attach gdb to a " 341 "machine without any CPU."); 342 return false; 343 } 344 345 if (!gdb_supports_guest_debug()) { 346 error_setg(errp, "gdbstub: current accelerator doesn't " 347 "support guest debugging"); 348 return false; 349 } 350 351 if (cs->len == 0) { 352 error_setg(errp, "gdbstub: missing connection string"); 353 return false; 354 } 355 356 trace_gdbstub_op_start(cs->str); 357 358 if (g_strcmp0(cs->str, "none") != 0) { 359 if (g_str_has_prefix(cs->str, "tcp:")) { 360 /* enforce required TCP attributes */ 361 g_string_append_printf(cs, ",wait=off,nodelay=on,server=on"); 362 } 363 #ifndef _WIN32 364 else if (strcmp(device, "stdio") == 0) { 365 struct sigaction act; 366 367 memset(&act, 0, sizeof(act)); 368 act.sa_handler = gdb_sigterm_handler; 369 sigaction(SIGINT, &act, NULL); 370 } 371 #endif 372 /* 373 * FIXME: it's a bit weird to allow using a mux chardev here 374 * and implicitly setup a monitor. We may want to break this. 375 */ 376 chr = qemu_chr_new_noreplay("gdb", cs->str, true, NULL); 377 if (!chr) { 378 error_setg(errp, "gdbstub: couldn't create chardev"); 379 return false; 380 } 381 } 382 383 if (!gdbserver_state.init) { 384 gdb_init_gdbserver_state(); 385 386 qemu_add_vm_change_state_handler(gdb_vm_state_change, NULL); 387 388 /* Initialize a monitor terminal for gdb */ 389 mon_chr = qemu_chardev_new(NULL, TYPE_CHARDEV_GDB, 390 NULL, NULL, &error_abort); 391 monitor_init_hmp(mon_chr, false, &error_abort); 392 } else { 393 qemu_chr_fe_deinit(&gdbserver_system_state.chr, true); 394 mon_chr = gdbserver_system_state.mon_chr; 395 reset_gdbserver_state(); 396 } 397 398 create_processes(&gdbserver_state); 399 400 if (chr) { 401 qemu_chr_fe_init(&gdbserver_system_state.chr, chr, &error_abort); 402 qemu_chr_fe_set_handlers(&gdbserver_system_state.chr, 403 gdb_chr_can_receive, 404 gdb_chr_receive, gdb_chr_event, 405 NULL, &gdbserver_state, NULL, true); 406 } 407 gdbserver_state.state = chr ? RS_IDLE : RS_INACTIVE; 408 gdbserver_system_state.mon_chr = mon_chr; 409 gdb_syscall_reset(); 410 411 return true; 412 } 413 414 static void register_types(void) 415 { 416 type_register_static(&char_gdb_type_info); 417 } 418 419 type_init(register_types); 420 421 /* Tell the remote gdb that the process has exited. */ 422 void gdb_exit(int code) 423 { 424 char buf[4]; 425 426 if (!gdbserver_state.init) { 427 return; 428 } 429 430 trace_gdbstub_op_exiting((uint8_t)code); 431 432 if (gdbserver_state.allow_stop_reply) { 433 snprintf(buf, sizeof(buf), "W%02x", (uint8_t)code); 434 gdb_put_packet(buf); 435 gdbserver_state.allow_stop_reply = false; 436 } 437 438 qemu_chr_fe_deinit(&gdbserver_system_state.chr, true); 439 } 440 441 void gdb_qemu_exit(int code) 442 { 443 qemu_system_shutdown_request_with_code(SHUTDOWN_CAUSE_GUEST_SHUTDOWN, 444 code); 445 } 446 447 /* 448 * Memory access 449 */ 450 static int phy_memory_mode; 451 452 int gdb_target_memory_rw_debug(CPUState *cpu, hwaddr addr, 453 uint8_t *buf, int len, bool is_write) 454 { 455 CPUClass *cc; 456 457 if (phy_memory_mode) { 458 if (is_write) { 459 cpu_physical_memory_write(addr, buf, len); 460 } else { 461 cpu_physical_memory_read(addr, buf, len); 462 } 463 return 0; 464 } 465 466 cc = CPU_GET_CLASS(cpu); 467 if (cc->memory_rw_debug) { 468 return cc->memory_rw_debug(cpu, addr, buf, len, is_write); 469 } 470 471 return cpu_memory_rw_debug(cpu, addr, buf, len, is_write); 472 } 473 474 /* 475 * cpu helpers 476 */ 477 478 unsigned int gdb_get_max_cpus(void) 479 { 480 MachineState *ms = MACHINE(qdev_get_machine()); 481 return ms->smp.max_cpus; 482 } 483 484 bool gdb_can_reverse(void) 485 { 486 return replay_mode == REPLAY_MODE_PLAY; 487 } 488 489 /* 490 * Softmmu specific command helpers 491 */ 492 493 void gdb_handle_query_qemu_phy_mem_mode(GArray *params, 494 void *ctx) 495 { 496 g_string_printf(gdbserver_state.str_buf, "%d", phy_memory_mode); 497 gdb_put_strbuf(); 498 } 499 500 void gdb_handle_set_qemu_phy_mem_mode(GArray *params, void *ctx) 501 { 502 if (!params->len) { 503 gdb_put_packet("E22"); 504 return; 505 } 506 507 if (!gdb_get_cmd_param(params, 0)->val_ul) { 508 phy_memory_mode = 0; 509 } else { 510 phy_memory_mode = 1; 511 } 512 gdb_put_packet("OK"); 513 } 514 515 void gdb_handle_query_rcmd(GArray *params, void *ctx) 516 { 517 const guint8 zero = 0; 518 int len; 519 520 if (!params->len) { 521 gdb_put_packet("E22"); 522 return; 523 } 524 525 len = strlen(gdb_get_cmd_param(params, 0)->data); 526 if (len % 2) { 527 gdb_put_packet("E01"); 528 return; 529 } 530 531 g_assert(gdbserver_state.mem_buf->len == 0); 532 len = len / 2; 533 gdb_hextomem(gdbserver_state.mem_buf, gdb_get_cmd_param(params, 0)->data, len); 534 g_byte_array_append(gdbserver_state.mem_buf, &zero, 1); 535 qemu_chr_be_write(gdbserver_system_state.mon_chr, 536 gdbserver_state.mem_buf->data, 537 gdbserver_state.mem_buf->len); 538 gdb_put_packet("OK"); 539 } 540 541 /* 542 * Execution state helpers 543 */ 544 545 void gdb_handle_query_attached(GArray *params, void *ctx) 546 { 547 gdb_put_packet("1"); 548 } 549 550 void gdb_continue(void) 551 { 552 if (!runstate_needs_reset()) { 553 trace_gdbstub_op_continue(); 554 vm_start(); 555 } 556 } 557 558 /* 559 * Resume execution, per CPU actions. 560 */ 561 int gdb_continue_partial(char *newstates) 562 { 563 CPUState *cpu; 564 int res = 0; 565 int flag = 0; 566 567 if (!runstate_needs_reset()) { 568 bool step_requested = false; 569 CPU_FOREACH(cpu) { 570 if (newstates[cpu->cpu_index] == 's') { 571 step_requested = true; 572 break; 573 } 574 } 575 576 if (vm_prepare_start(step_requested)) { 577 return 0; 578 } 579 580 CPU_FOREACH(cpu) { 581 switch (newstates[cpu->cpu_index]) { 582 case 0: 583 case 1: 584 break; /* nothing to do here */ 585 case 's': 586 trace_gdbstub_op_stepping(cpu->cpu_index); 587 cpu_single_step(cpu, gdbserver_state.sstep_flags); 588 cpu_resume(cpu); 589 flag = 1; 590 break; 591 case 'c': 592 trace_gdbstub_op_continue_cpu(cpu->cpu_index); 593 cpu_resume(cpu); 594 flag = 1; 595 break; 596 default: 597 res = -1; 598 break; 599 } 600 } 601 } 602 if (flag) { 603 qemu_clock_enable(QEMU_CLOCK_VIRTUAL, true); 604 } 605 return res; 606 } 607 608 /* 609 * Signal Handling - in system mode we only need SIGINT and SIGTRAP; other 610 * signals are not yet supported. 611 */ 612 613 enum { 614 TARGET_SIGINT = 2, 615 TARGET_SIGTRAP = 5 616 }; 617 618 int gdb_signal_to_target(int sig) 619 { 620 switch (sig) { 621 case 2: 622 return TARGET_SIGINT; 623 case 5: 624 return TARGET_SIGTRAP; 625 default: 626 return -1; 627 } 628 } 629 630 /* 631 * Break/Watch point helpers 632 */ 633 634 bool gdb_supports_guest_debug(void) 635 { 636 const AccelOpsClass *ops = cpus_get_accel(); 637 if (ops->supports_guest_debug) { 638 return ops->supports_guest_debug(); 639 } 640 return false; 641 } 642 643 int gdb_breakpoint_insert(CPUState *cs, int type, vaddr addr, vaddr len) 644 { 645 const AccelOpsClass *ops = cpus_get_accel(); 646 if (ops->insert_breakpoint) { 647 return ops->insert_breakpoint(cs, type, addr, len); 648 } 649 return -ENOSYS; 650 } 651 652 int gdb_breakpoint_remove(CPUState *cs, int type, vaddr addr, vaddr len) 653 { 654 const AccelOpsClass *ops = cpus_get_accel(); 655 if (ops->remove_breakpoint) { 656 return ops->remove_breakpoint(cs, type, addr, len); 657 } 658 return -ENOSYS; 659 } 660 661 void gdb_breakpoint_remove_all(CPUState *cs) 662 { 663 const AccelOpsClass *ops = cpus_get_accel(); 664 if (ops->remove_all_breakpoints) { 665 ops->remove_all_breakpoints(cs); 666 } 667 } 668