xref: /qemu/gdbstub/system.c (revision 7703a1d1e6479084d58ee3106a3c8a72ed7357eb)
1 /*
2  * gdb server stub - system specific bits
3  *
4  * Debug integration depends on support from the individual
5  * accelerators so most of this involves calling the ops helpers.
6  *
7  * Copyright (c) 2003-2005 Fabrice Bellard
8  * Copyright (c) 2022 Linaro Ltd
9  *
10  * SPDX-License-Identifier: LGPL-2.0-or-later
11  */
12 
13 #include "qemu/osdep.h"
14 #include "qapi/error.h"
15 #include "qemu/error-report.h"
16 #include "qemu/cutils.h"
17 #include "exec/gdbstub.h"
18 #include "gdbstub/syscalls.h"
19 #include "gdbstub/commands.h"
20 #include "exec/hwaddr.h"
21 #include "exec/tb-flush.h"
22 #include "system/cpus.h"
23 #include "system/runstate.h"
24 #include "system/replay.h"
25 #include "hw/core/cpu.h"
26 #include "hw/cpu/cluster.h"
27 #include "hw/boards.h"
28 #include "chardev/char.h"
29 #include "chardev/char-fe.h"
30 #include "monitor/monitor.h"
31 #include "trace.h"
32 #include "internals.h"
33 
34 /* System emulation specific state */
35 typedef struct {
36     CharBackend chr;
37     Chardev *mon_chr;
38 } GDBSystemState;
39 
40 GDBSystemState gdbserver_system_state;
41 
42 static void reset_gdbserver_state(void)
43 {
44     g_free(gdbserver_state.processes);
45     gdbserver_state.processes = NULL;
46     gdbserver_state.process_num = 0;
47     gdbserver_state.allow_stop_reply = false;
48 }
49 
50 /*
51  * Return the GDB index for a given vCPU state.
52  *
53  * In system mode GDB numbers CPUs from 1 as 0 is reserved as an "any
54  * cpu" index.
55  */
56 int gdb_get_cpu_index(CPUState *cpu)
57 {
58     return cpu->cpu_index + 1;
59 }
60 
61 /*
62  * We check the status of the last message in the chardev receive code
63  */
64 bool gdb_got_immediate_ack(void)
65 {
66     return true;
67 }
68 
69 /*
70  * GDB Connection management. For system emulation we do all of this
71  * via our existing Chardev infrastructure which allows us to support
72  * network and unix sockets.
73  */
74 
75 void gdb_put_buffer(const uint8_t *buf, int len)
76 {
77     /*
78      * XXX this blocks entire thread. Rewrite to use
79      * qemu_chr_fe_write and background I/O callbacks
80      */
81     qemu_chr_fe_write_all(&gdbserver_system_state.chr, buf, len);
82 }
83 
84 static void gdb_chr_event(void *opaque, QEMUChrEvent event)
85 {
86     int i;
87     GDBState *s = (GDBState *) opaque;
88 
89     switch (event) {
90     case CHR_EVENT_OPENED:
91         /* Start with first process attached, others detached */
92         for (i = 0; i < s->process_num; i++) {
93             s->processes[i].attached = !i;
94         }
95 
96         s->c_cpu = gdb_first_attached_cpu();
97         s->g_cpu = s->c_cpu;
98 
99         vm_stop(RUN_STATE_PAUSED);
100         replay_gdb_attached();
101         break;
102     default:
103         break;
104     }
105 }
106 
107 /*
108  * In system-mode we stop the VM and wait to send the syscall packet
109  * until notification that the CPU has stopped. This must be done
110  * because if the packet is sent now the reply from the syscall
111  * request could be received while the CPU is still in the running
112  * state, which can cause packets to be dropped and state transition
113  * 'T' packets to be sent while the syscall is still being processed.
114  */
115 void gdb_syscall_handling(const char *syscall_packet)
116 {
117     vm_stop(RUN_STATE_DEBUG);
118     qemu_cpu_kick(gdbserver_state.c_cpu);
119 }
120 
121 static void gdb_vm_state_change(void *opaque, bool running, RunState state)
122 {
123     CPUState *cpu = gdbserver_state.c_cpu;
124     g_autoptr(GString) buf = g_string_new(NULL);
125     g_autoptr(GString) tid = g_string_new(NULL);
126     const char *type;
127     int ret;
128 
129     if (running || gdbserver_state.state == RS_INACTIVE) {
130         return;
131     }
132 
133     /* Is there a GDB syscall waiting to be sent?  */
134     if (gdb_handled_syscall()) {
135         return;
136     }
137 
138     if (cpu == NULL) {
139         /* No process attached */
140         return;
141     }
142 
143     if (!gdbserver_state.allow_stop_reply) {
144         return;
145     }
146 
147     gdb_append_thread_id(cpu, tid);
148 
149     switch (state) {
150     case RUN_STATE_DEBUG:
151         if (cpu->watchpoint_hit) {
152             switch (cpu->watchpoint_hit->flags & BP_MEM_ACCESS) {
153             case BP_MEM_READ:
154                 type = "r";
155                 break;
156             case BP_MEM_ACCESS:
157                 type = "a";
158                 break;
159             default:
160                 type = "";
161                 break;
162             }
163             trace_gdbstub_hit_watchpoint(type,
164                                          gdb_get_cpu_index(cpu),
165                                          cpu->watchpoint_hit->vaddr);
166             g_string_printf(buf, "T%02xthread:%s;%swatch:%" VADDR_PRIx ";",
167                             GDB_SIGNAL_TRAP, tid->str, type,
168                             cpu->watchpoint_hit->vaddr);
169             cpu->watchpoint_hit = NULL;
170             goto send_packet;
171         } else {
172             trace_gdbstub_hit_break();
173         }
174         tb_flush(cpu);
175         ret = GDB_SIGNAL_TRAP;
176         break;
177     case RUN_STATE_PAUSED:
178         trace_gdbstub_hit_paused();
179         ret = GDB_SIGNAL_INT;
180         break;
181     case RUN_STATE_SHUTDOWN:
182         trace_gdbstub_hit_shutdown();
183         ret = GDB_SIGNAL_QUIT;
184         break;
185     case RUN_STATE_IO_ERROR:
186         trace_gdbstub_hit_io_error();
187         ret = GDB_SIGNAL_STOP;
188         break;
189     case RUN_STATE_WATCHDOG:
190         trace_gdbstub_hit_watchdog();
191         ret = GDB_SIGNAL_ALRM;
192         break;
193     case RUN_STATE_INTERNAL_ERROR:
194         trace_gdbstub_hit_internal_error();
195         ret = GDB_SIGNAL_ABRT;
196         break;
197     case RUN_STATE_SAVE_VM:
198     case RUN_STATE_RESTORE_VM:
199         return;
200     case RUN_STATE_FINISH_MIGRATE:
201         ret = GDB_SIGNAL_XCPU;
202         break;
203     default:
204         trace_gdbstub_hit_unknown(state);
205         ret = GDB_SIGNAL_UNKNOWN;
206         break;
207     }
208     gdb_set_stop_cpu(cpu);
209     g_string_printf(buf, "T%02xthread:%s;", ret, tid->str);
210 
211 send_packet:
212     gdb_put_packet(buf->str);
213     gdbserver_state.allow_stop_reply = false;
214 
215     /* disable single step if it was enabled */
216     cpu_single_step(cpu, 0);
217 }
218 
219 #ifndef _WIN32
220 static void gdb_sigterm_handler(int signal)
221 {
222     if (runstate_is_running()) {
223         vm_stop(RUN_STATE_PAUSED);
224     }
225 }
226 #endif
227 
228 static int gdb_monitor_write(Chardev *chr, const uint8_t *buf, int len)
229 {
230     g_autoptr(GString) hex_buf = g_string_new("O");
231     gdb_memtohex(hex_buf, buf, len);
232     gdb_put_packet(hex_buf->str);
233     return len;
234 }
235 
236 static void gdb_monitor_open(Chardev *chr, ChardevBackend *backend,
237                              bool *be_opened, Error **errp)
238 {
239     *be_opened = false;
240 }
241 
242 static void char_gdb_class_init(ObjectClass *oc, void *data)
243 {
244     ChardevClass *cc = CHARDEV_CLASS(oc);
245 
246     cc->internal = true;
247     cc->open = gdb_monitor_open;
248     cc->chr_write = gdb_monitor_write;
249 }
250 
251 #define TYPE_CHARDEV_GDB "chardev-gdb"
252 
253 static const TypeInfo char_gdb_type_info = {
254     .name = TYPE_CHARDEV_GDB,
255     .parent = TYPE_CHARDEV,
256     .class_init = char_gdb_class_init,
257 };
258 
259 static int gdb_chr_can_receive(void *opaque)
260 {
261   /*
262    * We can handle an arbitrarily large amount of data.
263    * Pick the maximum packet size, which is as good as anything.
264    */
265   return MAX_PACKET_LENGTH;
266 }
267 
268 static void gdb_chr_receive(void *opaque, const uint8_t *buf, int size)
269 {
270     int i;
271 
272     for (i = 0; i < size; i++) {
273         gdb_read_byte(buf[i]);
274     }
275 }
276 
277 static int find_cpu_clusters(Object *child, void *opaque)
278 {
279     if (object_dynamic_cast(child, TYPE_CPU_CLUSTER)) {
280         GDBState *s = (GDBState *) opaque;
281         CPUClusterState *cluster = CPU_CLUSTER(child);
282         GDBProcess *process;
283 
284         s->processes = g_renew(GDBProcess, s->processes, ++s->process_num);
285 
286         process = &s->processes[s->process_num - 1];
287 
288         /*
289          * GDB process IDs -1 and 0 are reserved. To avoid subtle errors at
290          * runtime, we enforce here that the machine does not use a cluster ID
291          * that would lead to PID 0.
292          */
293         assert(cluster->cluster_id != UINT32_MAX);
294         process->pid = cluster->cluster_id + 1;
295         process->attached = false;
296         process->target_xml = NULL;
297 
298         return 0;
299     }
300 
301     return object_child_foreach(child, find_cpu_clusters, opaque);
302 }
303 
304 static int pid_order(const void *a, const void *b)
305 {
306     GDBProcess *pa = (GDBProcess *) a;
307     GDBProcess *pb = (GDBProcess *) b;
308 
309     if (pa->pid < pb->pid) {
310         return -1;
311     } else if (pa->pid > pb->pid) {
312         return 1;
313     } else {
314         return 0;
315     }
316 }
317 
318 static void create_processes(GDBState *s)
319 {
320     object_child_foreach(object_get_root(), find_cpu_clusters, s);
321 
322     if (gdbserver_state.processes) {
323         /* Sort by PID */
324         qsort(gdbserver_state.processes,
325               gdbserver_state.process_num,
326               sizeof(gdbserver_state.processes[0]),
327               pid_order);
328     }
329 
330     gdb_create_default_process(s);
331 }
332 
333 bool gdbserver_start(const char *device, Error **errp)
334 {
335     Chardev *chr = NULL;
336     Chardev *mon_chr;
337     g_autoptr(GString) cs = g_string_new(device);
338 
339     if (!first_cpu) {
340         error_setg(errp, "gdbstub: meaningless to attach gdb to a "
341                    "machine without any CPU.");
342         return false;
343     }
344 
345     if (!gdb_supports_guest_debug()) {
346         error_setg(errp, "gdbstub: current accelerator doesn't "
347                    "support guest debugging");
348         return false;
349     }
350 
351     if (cs->len == 0) {
352         error_setg(errp, "gdbstub: missing connection string");
353         return false;
354     }
355 
356     trace_gdbstub_op_start(cs->str);
357 
358     if (g_strcmp0(cs->str, "none") != 0) {
359         if (g_str_has_prefix(cs->str, "tcp:")) {
360             /* enforce required TCP attributes */
361             g_string_append_printf(cs, ",wait=off,nodelay=on,server=on");
362         }
363 #ifndef _WIN32
364         else if (strcmp(device, "stdio") == 0) {
365             struct sigaction act;
366 
367             memset(&act, 0, sizeof(act));
368             act.sa_handler = gdb_sigterm_handler;
369             sigaction(SIGINT, &act, NULL);
370         }
371 #endif
372         /*
373          * FIXME: it's a bit weird to allow using a mux chardev here
374          * and implicitly setup a monitor. We may want to break this.
375          */
376         chr = qemu_chr_new_noreplay("gdb", cs->str, true, NULL);
377         if (!chr) {
378             error_setg(errp, "gdbstub: couldn't create chardev");
379             return false;
380         }
381     }
382 
383     if (!gdbserver_state.init) {
384         gdb_init_gdbserver_state();
385 
386         qemu_add_vm_change_state_handler(gdb_vm_state_change, NULL);
387 
388         /* Initialize a monitor terminal for gdb */
389         mon_chr = qemu_chardev_new(NULL, TYPE_CHARDEV_GDB,
390                                    NULL, NULL, &error_abort);
391         monitor_init_hmp(mon_chr, false, &error_abort);
392     } else {
393         qemu_chr_fe_deinit(&gdbserver_system_state.chr, true);
394         mon_chr = gdbserver_system_state.mon_chr;
395         reset_gdbserver_state();
396     }
397 
398     create_processes(&gdbserver_state);
399 
400     if (chr) {
401         qemu_chr_fe_init(&gdbserver_system_state.chr, chr, &error_abort);
402         qemu_chr_fe_set_handlers(&gdbserver_system_state.chr,
403                                  gdb_chr_can_receive,
404                                  gdb_chr_receive, gdb_chr_event,
405                                  NULL, &gdbserver_state, NULL, true);
406     }
407     gdbserver_state.state = chr ? RS_IDLE : RS_INACTIVE;
408     gdbserver_system_state.mon_chr = mon_chr;
409     gdb_syscall_reset();
410 
411     return true;
412 }
413 
414 static void register_types(void)
415 {
416     type_register_static(&char_gdb_type_info);
417 }
418 
419 type_init(register_types);
420 
421 /* Tell the remote gdb that the process has exited.  */
422 void gdb_exit(int code)
423 {
424     char buf[4];
425 
426     if (!gdbserver_state.init) {
427         return;
428     }
429 
430     trace_gdbstub_op_exiting((uint8_t)code);
431 
432     if (gdbserver_state.allow_stop_reply) {
433         snprintf(buf, sizeof(buf), "W%02x", (uint8_t)code);
434         gdb_put_packet(buf);
435         gdbserver_state.allow_stop_reply = false;
436     }
437 
438     qemu_chr_fe_deinit(&gdbserver_system_state.chr, true);
439 }
440 
441 void gdb_qemu_exit(int code)
442 {
443     qemu_system_shutdown_request_with_code(SHUTDOWN_CAUSE_GUEST_SHUTDOWN,
444                                            code);
445 }
446 
447 /*
448  * Memory access
449  */
450 static int phy_memory_mode;
451 
452 int gdb_target_memory_rw_debug(CPUState *cpu, hwaddr addr,
453                                uint8_t *buf, int len, bool is_write)
454 {
455     CPUClass *cc;
456 
457     if (phy_memory_mode) {
458         if (is_write) {
459             cpu_physical_memory_write(addr, buf, len);
460         } else {
461             cpu_physical_memory_read(addr, buf, len);
462         }
463         return 0;
464     }
465 
466     cc = CPU_GET_CLASS(cpu);
467     if (cc->memory_rw_debug) {
468         return cc->memory_rw_debug(cpu, addr, buf, len, is_write);
469     }
470 
471     return cpu_memory_rw_debug(cpu, addr, buf, len, is_write);
472 }
473 
474 /*
475  * cpu helpers
476  */
477 
478 unsigned int gdb_get_max_cpus(void)
479 {
480     MachineState *ms = MACHINE(qdev_get_machine());
481     return ms->smp.max_cpus;
482 }
483 
484 bool gdb_can_reverse(void)
485 {
486     return replay_mode == REPLAY_MODE_PLAY;
487 }
488 
489 /*
490  * Softmmu specific command helpers
491  */
492 
493 void gdb_handle_query_qemu_phy_mem_mode(GArray *params,
494                                         void *ctx)
495 {
496     g_string_printf(gdbserver_state.str_buf, "%d", phy_memory_mode);
497     gdb_put_strbuf();
498 }
499 
500 void gdb_handle_set_qemu_phy_mem_mode(GArray *params, void *ctx)
501 {
502     if (!params->len) {
503         gdb_put_packet("E22");
504         return;
505     }
506 
507     if (!gdb_get_cmd_param(params, 0)->val_ul) {
508         phy_memory_mode = 0;
509     } else {
510         phy_memory_mode = 1;
511     }
512     gdb_put_packet("OK");
513 }
514 
515 void gdb_handle_query_rcmd(GArray *params, void *ctx)
516 {
517     const guint8 zero = 0;
518     int len;
519 
520     if (!params->len) {
521         gdb_put_packet("E22");
522         return;
523     }
524 
525     len = strlen(gdb_get_cmd_param(params, 0)->data);
526     if (len % 2) {
527         gdb_put_packet("E01");
528         return;
529     }
530 
531     g_assert(gdbserver_state.mem_buf->len == 0);
532     len = len / 2;
533     gdb_hextomem(gdbserver_state.mem_buf, gdb_get_cmd_param(params, 0)->data, len);
534     g_byte_array_append(gdbserver_state.mem_buf, &zero, 1);
535     qemu_chr_be_write(gdbserver_system_state.mon_chr,
536                       gdbserver_state.mem_buf->data,
537                       gdbserver_state.mem_buf->len);
538     gdb_put_packet("OK");
539 }
540 
541 /*
542  * Execution state helpers
543  */
544 
545 void gdb_handle_query_attached(GArray *params, void *ctx)
546 {
547     gdb_put_packet("1");
548 }
549 
550 void gdb_continue(void)
551 {
552     if (!runstate_needs_reset()) {
553         trace_gdbstub_op_continue();
554         vm_start();
555     }
556 }
557 
558 /*
559  * Resume execution, per CPU actions.
560  */
561 int gdb_continue_partial(char *newstates)
562 {
563     CPUState *cpu;
564     int res = 0;
565     int flag = 0;
566 
567     if (!runstate_needs_reset()) {
568         bool step_requested = false;
569         CPU_FOREACH(cpu) {
570             if (newstates[cpu->cpu_index] == 's') {
571                 step_requested = true;
572                 break;
573             }
574         }
575 
576         if (vm_prepare_start(step_requested)) {
577             return 0;
578         }
579 
580         CPU_FOREACH(cpu) {
581             switch (newstates[cpu->cpu_index]) {
582             case 0:
583             case 1:
584                 break; /* nothing to do here */
585             case 's':
586                 trace_gdbstub_op_stepping(cpu->cpu_index);
587                 cpu_single_step(cpu, gdbserver_state.sstep_flags);
588                 cpu_resume(cpu);
589                 flag = 1;
590                 break;
591             case 'c':
592                 trace_gdbstub_op_continue_cpu(cpu->cpu_index);
593                 cpu_resume(cpu);
594                 flag = 1;
595                 break;
596             default:
597                 res = -1;
598                 break;
599             }
600         }
601     }
602     if (flag) {
603         qemu_clock_enable(QEMU_CLOCK_VIRTUAL, true);
604     }
605     return res;
606 }
607 
608 /*
609  * Signal Handling - in system mode we only need SIGINT and SIGTRAP; other
610  * signals are not yet supported.
611  */
612 
613 enum {
614     TARGET_SIGINT = 2,
615     TARGET_SIGTRAP = 5
616 };
617 
618 int gdb_signal_to_target(int sig)
619 {
620     switch (sig) {
621     case 2:
622         return TARGET_SIGINT;
623     case 5:
624         return TARGET_SIGTRAP;
625     default:
626         return -1;
627     }
628 }
629 
630 /*
631  * Break/Watch point helpers
632  */
633 
634 bool gdb_supports_guest_debug(void)
635 {
636     const AccelOpsClass *ops = cpus_get_accel();
637     if (ops->supports_guest_debug) {
638         return ops->supports_guest_debug();
639     }
640     return false;
641 }
642 
643 int gdb_breakpoint_insert(CPUState *cs, int type, vaddr addr, vaddr len)
644 {
645     const AccelOpsClass *ops = cpus_get_accel();
646     if (ops->insert_breakpoint) {
647         return ops->insert_breakpoint(cs, type, addr, len);
648     }
649     return -ENOSYS;
650 }
651 
652 int gdb_breakpoint_remove(CPUState *cs, int type, vaddr addr, vaddr len)
653 {
654     const AccelOpsClass *ops = cpus_get_accel();
655     if (ops->remove_breakpoint) {
656         return ops->remove_breakpoint(cs, type, addr, len);
657     }
658     return -ENOSYS;
659 }
660 
661 void gdb_breakpoint_remove_all(CPUState *cs)
662 {
663     const AccelOpsClass *ops = cpus_get_accel();
664     if (ops->remove_all_breakpoints) {
665         ops->remove_all_breakpoints(cs);
666     }
667 }
668