ptrace_syscall.c 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294
  1. #define _GNU_SOURCE
  2. #include <sys/ptrace.h>
  3. #include <sys/types.h>
  4. #include <sys/wait.h>
  5. #include <sys/syscall.h>
  6. #include <sys/user.h>
  7. #include <unistd.h>
  8. #include <errno.h>
  9. #include <stddef.h>
  10. #include <stdio.h>
  11. #include <err.h>
  12. #include <string.h>
  13. #include <asm/ptrace-abi.h>
  14. #include <sys/auxv.h>
  15. /* Bitness-agnostic defines for user_regs_struct fields. */
  16. #ifdef __x86_64__
  17. # define user_syscall_nr orig_rax
  18. # define user_arg0 rdi
  19. # define user_arg1 rsi
  20. # define user_arg2 rdx
  21. # define user_arg3 r10
  22. # define user_arg4 r8
  23. # define user_arg5 r9
  24. # define user_ip rip
  25. # define user_ax rax
  26. #else
  27. # define user_syscall_nr orig_eax
  28. # define user_arg0 ebx
  29. # define user_arg1 ecx
  30. # define user_arg2 edx
  31. # define user_arg3 esi
  32. # define user_arg4 edi
  33. # define user_arg5 ebp
  34. # define user_ip eip
  35. # define user_ax eax
  36. #endif
  37. static int nerrs = 0;
  38. struct syscall_args32 {
  39. uint32_t nr, arg0, arg1, arg2, arg3, arg4, arg5;
  40. };
  41. #ifdef __i386__
  42. extern void sys32_helper(struct syscall_args32 *, void *);
  43. extern void int80_and_ret(void);
  44. #endif
  45. /*
  46. * Helper to invoke int80 with controlled regs and capture the final regs.
  47. */
  48. static void do_full_int80(struct syscall_args32 *args)
  49. {
  50. #ifdef __x86_64__
  51. register unsigned long bp asm("bp") = args->arg5;
  52. asm volatile ("int $0x80"
  53. : "+a" (args->nr),
  54. "+b" (args->arg0), "+c" (args->arg1), "+d" (args->arg2),
  55. "+S" (args->arg3), "+D" (args->arg4), "+r" (bp));
  56. args->arg5 = bp;
  57. #else
  58. sys32_helper(args, int80_and_ret);
  59. #endif
  60. }
  61. #ifdef __i386__
  62. static void (*vsyscall32)(void);
  63. /*
  64. * Nasty helper to invoke AT_SYSINFO (i.e. __kernel_vsyscall) with
  65. * controlled regs and capture the final regs. This is so nasty that it
  66. * crashes my copy of gdb :)
  67. */
  68. static void do_full_vsyscall32(struct syscall_args32 *args)
  69. {
  70. sys32_helper(args, vsyscall32);
  71. }
  72. #endif
  73. static siginfo_t wait_trap(pid_t chld)
  74. {
  75. siginfo_t si;
  76. if (waitid(P_PID, chld, &si, WEXITED|WSTOPPED) != 0)
  77. err(1, "waitid");
  78. if (si.si_pid != chld)
  79. errx(1, "got unexpected pid in event\n");
  80. if (si.si_code != CLD_TRAPPED)
  81. errx(1, "got unexpected event type %d\n", si.si_code);
  82. return si;
  83. }
  84. static void sethandler(int sig, void (*handler)(int, siginfo_t *, void *),
  85. int flags)
  86. {
  87. struct sigaction sa;
  88. memset(&sa, 0, sizeof(sa));
  89. sa.sa_sigaction = handler;
  90. sa.sa_flags = SA_SIGINFO | flags;
  91. sigemptyset(&sa.sa_mask);
  92. if (sigaction(sig, &sa, 0))
  93. err(1, "sigaction");
  94. }
  95. static void clearhandler(int sig)
  96. {
  97. struct sigaction sa;
  98. memset(&sa, 0, sizeof(sa));
  99. sa.sa_handler = SIG_DFL;
  100. sigemptyset(&sa.sa_mask);
  101. if (sigaction(sig, &sa, 0))
  102. err(1, "sigaction");
  103. }
  104. #ifdef __x86_64__
  105. # define REG_BP REG_RBP
  106. #else
  107. # define REG_BP REG_EBP
  108. #endif
  109. static void empty_handler(int sig, siginfo_t *si, void *ctx_void)
  110. {
  111. }
  112. static void test_sys32_regs(void (*do_syscall)(struct syscall_args32 *))
  113. {
  114. struct syscall_args32 args = {
  115. .nr = 224, /* gettid */
  116. .arg0 = 10, .arg1 = 11, .arg2 = 12,
  117. .arg3 = 13, .arg4 = 14, .arg5 = 15,
  118. };
  119. do_syscall(&args);
  120. if (args.nr != getpid() ||
  121. args.arg0 != 10 || args.arg1 != 11 || args.arg2 != 12 ||
  122. args.arg3 != 13 || args.arg4 != 14 || args.arg5 != 15) {
  123. printf("[FAIL]\tgetpid() failed to preseve regs\n");
  124. nerrs++;
  125. } else {
  126. printf("[OK]\tgetpid() preserves regs\n");
  127. }
  128. sethandler(SIGUSR1, empty_handler, 0);
  129. args.nr = 37; /* kill */
  130. args.arg0 = getpid();
  131. args.arg1 = SIGUSR1;
  132. do_syscall(&args);
  133. if (args.nr != 0 ||
  134. args.arg0 != getpid() || args.arg1 != SIGUSR1 || args.arg2 != 12 ||
  135. args.arg3 != 13 || args.arg4 != 14 || args.arg5 != 15) {
  136. printf("[FAIL]\tkill(getpid(), SIGUSR1) failed to preseve regs\n");
  137. nerrs++;
  138. } else {
  139. printf("[OK]\tkill(getpid(), SIGUSR1) preserves regs\n");
  140. }
  141. clearhandler(SIGUSR1);
  142. }
  143. static void test_ptrace_syscall_restart(void)
  144. {
  145. printf("[RUN]\tptrace-induced syscall restart\n");
  146. pid_t chld = fork();
  147. if (chld < 0)
  148. err(1, "fork");
  149. if (chld == 0) {
  150. if (ptrace(PTRACE_TRACEME, 0, 0, 0) != 0)
  151. err(1, "PTRACE_TRACEME");
  152. printf("\tChild will make one syscall\n");
  153. raise(SIGSTOP);
  154. syscall(SYS_gettid, 10, 11, 12, 13, 14, 15);
  155. _exit(0);
  156. }
  157. int status;
  158. /* Wait for SIGSTOP. */
  159. if (waitpid(chld, &status, 0) != chld || !WIFSTOPPED(status))
  160. err(1, "waitpid");
  161. struct user_regs_struct regs;
  162. printf("[RUN]\tSYSEMU\n");
  163. if (ptrace(PTRACE_SYSEMU, chld, 0, 0) != 0)
  164. err(1, "PTRACE_SYSCALL");
  165. wait_trap(chld);
  166. if (ptrace(PTRACE_GETREGS, chld, 0, &regs) != 0)
  167. err(1, "PTRACE_GETREGS");
  168. if (regs.user_syscall_nr != SYS_gettid ||
  169. regs.user_arg0 != 10 || regs.user_arg1 != 11 ||
  170. regs.user_arg2 != 12 || regs.user_arg3 != 13 ||
  171. regs.user_arg4 != 14 || regs.user_arg5 != 15) {
  172. printf("[FAIL]\tInitial args are wrong (nr=%lu, args=%lu %lu %lu %lu %lu %lu)\n", (unsigned long)regs.user_syscall_nr, (unsigned long)regs.user_arg0, (unsigned long)regs.user_arg1, (unsigned long)regs.user_arg2, (unsigned long)regs.user_arg3, (unsigned long)regs.user_arg4, (unsigned long)regs.user_arg5);
  173. nerrs++;
  174. } else {
  175. printf("[OK]\tInitial nr and args are correct\n");
  176. }
  177. printf("[RUN]\tRestart the syscall (ip = 0x%lx)\n",
  178. (unsigned long)regs.user_ip);
  179. /*
  180. * This does exactly what it appears to do if syscall is int80 or
  181. * SYSCALL64. For SYSCALL32 or SYSENTER, though, this is highly
  182. * magical. It needs to work so that ptrace and syscall restart
  183. * work as expected.
  184. */
  185. regs.user_ax = regs.user_syscall_nr;
  186. regs.user_ip -= 2;
  187. if (ptrace(PTRACE_SETREGS, chld, 0, &regs) != 0)
  188. err(1, "PTRACE_SETREGS");
  189. if (ptrace(PTRACE_SYSEMU, chld, 0, 0) != 0)
  190. err(1, "PTRACE_SYSCALL");
  191. wait_trap(chld);
  192. if (ptrace(PTRACE_GETREGS, chld, 0, &regs) != 0)
  193. err(1, "PTRACE_GETREGS");
  194. if (regs.user_syscall_nr != SYS_gettid ||
  195. regs.user_arg0 != 10 || regs.user_arg1 != 11 ||
  196. regs.user_arg2 != 12 || regs.user_arg3 != 13 ||
  197. regs.user_arg4 != 14 || regs.user_arg5 != 15) {
  198. printf("[FAIL]\tRestart nr or args are wrong (nr=%lu, args=%lu %lu %lu %lu %lu %lu)\n", (unsigned long)regs.user_syscall_nr, (unsigned long)regs.user_arg0, (unsigned long)regs.user_arg1, (unsigned long)regs.user_arg2, (unsigned long)regs.user_arg3, (unsigned long)regs.user_arg4, (unsigned long)regs.user_arg5);
  199. nerrs++;
  200. } else {
  201. printf("[OK]\tRestarted nr and args are correct\n");
  202. }
  203. printf("[RUN]\tChange nr and args and restart the syscall (ip = 0x%lx)\n",
  204. (unsigned long)regs.user_ip);
  205. regs.user_ax = SYS_getpid;
  206. regs.user_arg0 = 20;
  207. regs.user_arg1 = 21;
  208. regs.user_arg2 = 22;
  209. regs.user_arg3 = 23;
  210. regs.user_arg4 = 24;
  211. regs.user_arg5 = 25;
  212. regs.user_ip -= 2;
  213. if (ptrace(PTRACE_SETREGS, chld, 0, &regs) != 0)
  214. err(1, "PTRACE_SETREGS");
  215. if (ptrace(PTRACE_SYSEMU, chld, 0, 0) != 0)
  216. err(1, "PTRACE_SYSCALL");
  217. wait_trap(chld);
  218. if (ptrace(PTRACE_GETREGS, chld, 0, &regs) != 0)
  219. err(1, "PTRACE_GETREGS");
  220. if (regs.user_syscall_nr != SYS_getpid ||
  221. regs.user_arg0 != 20 || regs.user_arg1 != 21 || regs.user_arg2 != 22 ||
  222. regs.user_arg3 != 23 || regs.user_arg4 != 24 || regs.user_arg5 != 25) {
  223. printf("[FAIL]\tRestart nr or args are wrong (nr=%lu, args=%lu %lu %lu %lu %lu %lu)\n", (unsigned long)regs.user_syscall_nr, (unsigned long)regs.user_arg0, (unsigned long)regs.user_arg1, (unsigned long)regs.user_arg2, (unsigned long)regs.user_arg3, (unsigned long)regs.user_arg4, (unsigned long)regs.user_arg5);
  224. nerrs++;
  225. } else {
  226. printf("[OK]\tReplacement nr and args are correct\n");
  227. }
  228. if (ptrace(PTRACE_CONT, chld, 0, 0) != 0)
  229. err(1, "PTRACE_CONT");
  230. if (waitpid(chld, &status, 0) != chld)
  231. err(1, "waitpid");
  232. if (!WIFEXITED(status) || WEXITSTATUS(status) != 0) {
  233. printf("[FAIL]\tChild failed\n");
  234. nerrs++;
  235. } else {
  236. printf("[OK]\tChild exited cleanly\n");
  237. }
  238. }
  239. int main()
  240. {
  241. printf("[RUN]\tCheck int80 return regs\n");
  242. test_sys32_regs(do_full_int80);
  243. #if defined(__i386__) && (!defined(__GLIBC__) || __GLIBC__ > 2 || __GLIBC_MINOR__ >= 16)
  244. vsyscall32 = (void *)getauxval(AT_SYSINFO);
  245. printf("[RUN]\tCheck AT_SYSINFO return regs\n");
  246. test_sys32_regs(do_full_vsyscall32);
  247. #endif
  248. test_ptrace_syscall_restart();
  249. return 0;
  250. }