1*5e3eaea3SApple OSS Distributionsfrom __future__ import absolute_import, division, print_function 2*5e3eaea3SApple OSS Distributions 3*5e3eaea3SApple OSS Distributionsfrom builtins import chr 4*5e3eaea3SApple OSS Distributionsfrom builtins import hex 5*5e3eaea3SApple OSS Distributionsfrom builtins import range 6*5e3eaea3SApple OSS Distributionsfrom builtins import bytes 7*5e3eaea3SApple OSS Distributions 8*5e3eaea3SApple OSS Distributionsfrom xnu import * 9*5e3eaea3SApple OSS Distributionsfrom utils import * 10*5e3eaea3SApple OSS Distributionsfrom process import * 11*5e3eaea3SApple OSS Distributionsfrom pmap import * 12*5e3eaea3SApple OSS Distributionsimport struct 13*5e3eaea3SApple OSS Distributions 14*5e3eaea3SApple OSS Distributionsdef GetBinaryNameForPC(pc_val, user_lib_info = None): 15*5e3eaea3SApple OSS Distributions """ find the binary in user_lib_info that the passed pc_val falls in range of. 16*5e3eaea3SApple OSS Distributions params: 17*5e3eaea3SApple OSS Distributions pc_val : int - integer form of the pc address 18*5e3eaea3SApple OSS Distributions user_lib_info: [] of [] which hold start, end, binary name 19*5e3eaea3SApple OSS Distributions returns: 20*5e3eaea3SApple OSS Distributions str - Name of binary or "unknown" if not found. 21*5e3eaea3SApple OSS Distributions """ 22*5e3eaea3SApple OSS Distributions retval = "unknown" 23*5e3eaea3SApple OSS Distributions if not user_lib_info: 24*5e3eaea3SApple OSS Distributions return retval 25*5e3eaea3SApple OSS Distributions matches = [] 26*5e3eaea3SApple OSS Distributions for info in user_lib_info: 27*5e3eaea3SApple OSS Distributions if pc_val >= info[0] and pc_val <= info[1]: 28*5e3eaea3SApple OSS Distributions matches.append((pc_val - info[0], info[2])) 29*5e3eaea3SApple OSS Distributions matches.sort() 30*5e3eaea3SApple OSS Distributions if matches: 31*5e3eaea3SApple OSS Distributions retval = matches[0][1] 32*5e3eaea3SApple OSS Distributions return retval 33*5e3eaea3SApple OSS Distributions 34*5e3eaea3SApple OSS Distributionsdef ShowX86UserStack(thread, user_lib_info = None): 35*5e3eaea3SApple OSS Distributions """ Display user space stack frame and pc addresses. 36*5e3eaea3SApple OSS Distributions params: 37*5e3eaea3SApple OSS Distributions thread: obj referencing thread value 38*5e3eaea3SApple OSS Distributions returns: 39*5e3eaea3SApple OSS Distributions Nothing 40*5e3eaea3SApple OSS Distributions """ 41*5e3eaea3SApple OSS Distributions iss = Cast(thread.machine.iss, 'x86_saved_state_t *') 42*5e3eaea3SApple OSS Distributions abi = int(iss.flavor) 43*5e3eaea3SApple OSS Distributions user_ip = 0 44*5e3eaea3SApple OSS Distributions user_frame = 0 45*5e3eaea3SApple OSS Distributions user_abi_ret_offset = 0 46*5e3eaea3SApple OSS Distributions if abi == 0xf: 47*5e3eaea3SApple OSS Distributions debuglog("User process is 64 bit") 48*5e3eaea3SApple OSS Distributions user_ip = iss.uss.ss_64.isf.rip 49*5e3eaea3SApple OSS Distributions user_frame = iss.uss.ss_64.rbp 50*5e3eaea3SApple OSS Distributions user_abi_ret_offset = 8 51*5e3eaea3SApple OSS Distributions user_abi_type = "uint64_t" 52*5e3eaea3SApple OSS Distributions else: 53*5e3eaea3SApple OSS Distributions debuglog("user process is 32 bit") 54*5e3eaea3SApple OSS Distributions user_ip = iss.uss.ss_32.eip 55*5e3eaea3SApple OSS Distributions user_frame = iss.uss.ss_32.ebp 56*5e3eaea3SApple OSS Distributions user_abi_ret_offset = 4 57*5e3eaea3SApple OSS Distributions user_abi_type = "uint32_t" 58*5e3eaea3SApple OSS Distributions 59*5e3eaea3SApple OSS Distributions if user_ip == 0: 60*5e3eaea3SApple OSS Distributions print("This activation does not appear to have a valid user context.") 61*5e3eaea3SApple OSS Distributions return False 62*5e3eaea3SApple OSS Distributions 63*5e3eaea3SApple OSS Distributions cur_ip = user_ip 64*5e3eaea3SApple OSS Distributions cur_frame = user_frame 65*5e3eaea3SApple OSS Distributions debuglog("ip= 0x%x , fr = 0x%x " % (cur_ip, cur_frame)) 66*5e3eaea3SApple OSS Distributions 67*5e3eaea3SApple OSS Distributions frameformat = "{0:d} FP: 0x{1:x} PC: 0x{2:x}" 68*5e3eaea3SApple OSS Distributions if user_lib_info is not None: 69*5e3eaea3SApple OSS Distributions frameformat = "{0:d} {3: <30s} 0x{2:x}" 70*5e3eaea3SApple OSS Distributions print(frameformat.format(0, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))) 71*5e3eaea3SApple OSS Distributions 72*5e3eaea3SApple OSS Distributions print(kern.Symbolicate(cur_ip)) 73*5e3eaea3SApple OSS Distributions 74*5e3eaea3SApple OSS Distributions frameno = 0 75*5e3eaea3SApple OSS Distributions while True: 76*5e3eaea3SApple OSS Distributions frameno = frameno + 1 77*5e3eaea3SApple OSS Distributions frame = GetUserDataAsString(thread.t_tro.tro_task, unsigned(cur_frame), user_abi_ret_offset*2) 78*5e3eaea3SApple OSS Distributions cur_ip = _ExtractDataFromString(frame, user_abi_ret_offset, user_abi_type) 79*5e3eaea3SApple OSS Distributions cur_frame = _ExtractDataFromString(frame, 0, user_abi_type) 80*5e3eaea3SApple OSS Distributions if not cur_frame or cur_frame == 0x0000000800000008: 81*5e3eaea3SApple OSS Distributions break 82*5e3eaea3SApple OSS Distributions print(frameformat.format(frameno, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))) 83*5e3eaea3SApple OSS Distributions print(kern.Symbolicate(cur_ip)) 84*5e3eaea3SApple OSS Distributions return 85*5e3eaea3SApple OSS Distributions 86*5e3eaea3SApple OSS Distributionsdef _PrintARMUserStack(task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=None): 87*5e3eaea3SApple OSS Distributions cur_pc = kern.StripUserPAC(cur_pc) 88*5e3eaea3SApple OSS Distributions if cur_pc == 0: 89*5e3eaea3SApple OSS Distributions "No valid user context for this activation." 90*5e3eaea3SApple OSS Distributions return 91*5e3eaea3SApple OSS Distributions frameno = 0 92*5e3eaea3SApple OSS Distributions print(frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))) 93*5e3eaea3SApple OSS Distributions while True: 94*5e3eaea3SApple OSS Distributions frameno = frameno + 1 95*5e3eaea3SApple OSS Distributions frame = GetUserDataAsString(task, cur_fp, framesize) 96*5e3eaea3SApple OSS Distributions cur_fp = _ExtractDataFromString(frame, 0, frametype) 97*5e3eaea3SApple OSS Distributions cur_pc = _ExtractDataFromString(frame, (framesize // 2), frametype) 98*5e3eaea3SApple OSS Distributions cur_pc = kern.StripUserPAC(cur_pc) 99*5e3eaea3SApple OSS Distributions if not cur_fp: 100*5e3eaea3SApple OSS Distributions break 101*5e3eaea3SApple OSS Distributions print(frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))) 102*5e3eaea3SApple OSS Distributions 103*5e3eaea3SApple OSS Distributionsdef ShowARM64UserStack(thread, user_lib_info = None): 104*5e3eaea3SApple OSS Distributions SAVED_STATE_FLAVOR_ARM=20 105*5e3eaea3SApple OSS Distributions SAVED_STATE_FLAVOR_ARM64=21 106*5e3eaea3SApple OSS Distributions upcb_addr = kern.StripKernelPAC(thread.machine.upcb) 107*5e3eaea3SApple OSS Distributions upcb = kern.GetValueFromAddress(upcb_addr, 'arm_saved_state_t *') 108*5e3eaea3SApple OSS Distributions flavor = upcb.ash.flavor 109*5e3eaea3SApple OSS Distributions frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}" 110*5e3eaea3SApple OSS Distributions if flavor == SAVED_STATE_FLAVOR_ARM64: 111*5e3eaea3SApple OSS Distributions cur_pc = unsigned(upcb.uss.ss_64.pc) 112*5e3eaea3SApple OSS Distributions cur_fp = unsigned(upcb.uss.ss_64.fp) 113*5e3eaea3SApple OSS Distributions if user_lib_info is not None: 114*5e3eaea3SApple OSS Distributions frameformat = "{0:>2d} {3: <30s} 0x{2:x}" 115*5e3eaea3SApple OSS Distributions framesize = 16 116*5e3eaea3SApple OSS Distributions frametype = "uint64_t" 117*5e3eaea3SApple OSS Distributions elif flavor == SAVED_STATE_FLAVOR_ARM: 118*5e3eaea3SApple OSS Distributions cur_pc = unsigned(upcb.uss.ss_32.pc) 119*5e3eaea3SApple OSS Distributions cur_fp = unsigned(upcb.uss.ss_32.r[7]) 120*5e3eaea3SApple OSS Distributions if user_lib_info is not None: 121*5e3eaea3SApple OSS Distributions frameformat = "{0:>2d}: {3: <30s} 0x{2:x}" 122*5e3eaea3SApple OSS Distributions framesize = 8 123*5e3eaea3SApple OSS Distributions frametype = "uint32_t" 124*5e3eaea3SApple OSS Distributions else: 125*5e3eaea3SApple OSS Distributions raise RuntimeError("Thread {0} has an invalid flavor {1}".format(unsigned(thread), flavor)) 126*5e3eaea3SApple OSS Distributions 127*5e3eaea3SApple OSS Distributions _PrintARMUserStack(thread.t_tro.tro_task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info) 128*5e3eaea3SApple OSS Distributions 129*5e3eaea3SApple OSS Distributions 130*5e3eaea3SApple OSS Distributions@lldb_command('showthreaduserstack') 131*5e3eaea3SApple OSS Distributionsdef ShowThreadUserStack(cmd_args=None): 132*5e3eaea3SApple OSS Distributions """ Show user stack for a given thread. 133*5e3eaea3SApple OSS Distributions Syntax: (lldb) showthreaduserstack <thread_ptr> 134*5e3eaea3SApple OSS Distributions """ 135*5e3eaea3SApple OSS Distributions if not cmd_args: 136*5e3eaea3SApple OSS Distributions raise ArgumentError("Insufficient arguments") 137*5e3eaea3SApple OSS Distributions 138*5e3eaea3SApple OSS Distributions thread = kern.GetValueFromAddress(ArgumentStringToInt(cmd_args[0]), 'thread *') 139*5e3eaea3SApple OSS Distributions if kern.arch == "x86_64": 140*5e3eaea3SApple OSS Distributions ShowX86UserStack(thread) 141*5e3eaea3SApple OSS Distributions elif kern.arch.startswith("arm64"): 142*5e3eaea3SApple OSS Distributions ShowARM64UserStack(thread) 143*5e3eaea3SApple OSS Distributions return True 144*5e3eaea3SApple OSS Distributions 145*5e3eaea3SApple OSS Distributions@lldb_command('printuserdata','XO:') 146*5e3eaea3SApple OSS Distributionsdef PrintUserspaceData(cmd_args=None, cmd_options={}): 147*5e3eaea3SApple OSS Distributions """ Read userspace data for given task and print based on format provided. 148*5e3eaea3SApple OSS Distributions Syntax: (lldb) printuserdata <task_t> <uspace_address> <format_specifier> 149*5e3eaea3SApple OSS Distributions params: 150*5e3eaea3SApple OSS Distributions <task_t> : pointer to task 151*5e3eaea3SApple OSS Distributions <uspace_address> : address to user space memory 152*5e3eaea3SApple OSS Distributions <format_specifier> : String representation for processing the data and printing it. 153*5e3eaea3SApple OSS Distributions e.g Q -> unsigned long long, q -> long long, I -> unsigned int, i -> int 154*5e3eaea3SApple OSS Distributions 10i -> 10 ints, 20s -> 20 character string, s -> null terminated string 155*5e3eaea3SApple OSS Distributions See: https://docs.python.org/2/library/struct.html#format-characters 156*5e3eaea3SApple OSS Distributions options: 157*5e3eaea3SApple OSS Distributions -X : print all values in hex. 158*5e3eaea3SApple OSS Distributions -O <file path>: Save data to file 159*5e3eaea3SApple OSS Distributions """ 160*5e3eaea3SApple OSS Distributions 161*5e3eaea3SApple OSS Distributions if not cmd_args or len(cmd_args) < 3: 162*5e3eaea3SApple OSS Distributions raise ArgumentError("Insufficient arguments") 163*5e3eaea3SApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task *') 164*5e3eaea3SApple OSS Distributions uspace_addr = ArgumentStringToInt(cmd_args[1]) 165*5e3eaea3SApple OSS Distributions format_specifier_str = cmd_args[2] 166*5e3eaea3SApple OSS Distributions user_data_len = 0 167*5e3eaea3SApple OSS Distributions if format_specifier_str == "s": 168*5e3eaea3SApple OSS Distributions print("0x%x: " % uspace_addr + GetUserspaceString(task, uspace_addr)) 169*5e3eaea3SApple OSS Distributions return True 170*5e3eaea3SApple OSS Distributions 171*5e3eaea3SApple OSS Distributions try: 172*5e3eaea3SApple OSS Distributions user_data_len = struct.calcsize(format_specifier_str) 173*5e3eaea3SApple OSS Distributions except Exception as e: 174*5e3eaea3SApple OSS Distributions raise ArgumentError("Invalid format specifier provided.") 175*5e3eaea3SApple OSS Distributions 176*5e3eaea3SApple OSS Distributions user_data_string = GetUserDataAsString(task, uspace_addr, user_data_len) 177*5e3eaea3SApple OSS Distributions if not user_data_string: 178*5e3eaea3SApple OSS Distributions print("Could not read any data from userspace address.") 179*5e3eaea3SApple OSS Distributions return False 180*5e3eaea3SApple OSS Distributions if "-O" in cmd_options: 181*5e3eaea3SApple OSS Distributions fh = open(cmd_options["-O"],"w") 182*5e3eaea3SApple OSS Distributions fh.write(user_data_string) 183*5e3eaea3SApple OSS Distributions fh.close() 184*5e3eaea3SApple OSS Distributions print("Written %d bytes to %s." % (user_data_len, cmd_options['-O'])) 185*5e3eaea3SApple OSS Distributions return True 186*5e3eaea3SApple OSS Distributions upacked_data = struct.unpack(format_specifier_str, user_data_string) 187*5e3eaea3SApple OSS Distributions element_size = user_data_len // len(upacked_data) 188*5e3eaea3SApple OSS Distributions for i in range(len(upacked_data)): 189*5e3eaea3SApple OSS Distributions if "-X" in cmd_options: 190*5e3eaea3SApple OSS Distributions print("0x%x: " % (uspace_addr + i*element_size) + hex(upacked_data[i])) 191*5e3eaea3SApple OSS Distributions else: 192*5e3eaea3SApple OSS Distributions print("0x%x: " % (uspace_addr + i*element_size) + str(upacked_data[i])) 193*5e3eaea3SApple OSS Distributions 194*5e3eaea3SApple OSS Distributions return True 195*5e3eaea3SApple OSS Distributions 196*5e3eaea3SApple OSS Distributions@lldb_command('showtaskuserargs') 197*5e3eaea3SApple OSS Distributionsdef ShowTaskUserArgs(cmd_args=None, cmd_options={}): 198*5e3eaea3SApple OSS Distributions """ Read the process argv, env, and apple strings from the user stack 199*5e3eaea3SApple OSS Distributions Syntax: (lldb) showtaskuserargs <task_t> 200*5e3eaea3SApple OSS Distributions params: 201*5e3eaea3SApple OSS Distributions <task_t> : pointer to task 202*5e3eaea3SApple OSS Distributions """ 203*5e3eaea3SApple OSS Distributions if not cmd_args or len(cmd_args) != 1: 204*5e3eaea3SApple OSS Distributions raise ArgumentError("Insufficient arguments") 205*5e3eaea3SApple OSS Distributions 206*5e3eaea3SApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task *') 207*5e3eaea3SApple OSS Distributions proc = GetProcFromTask(task) 208*5e3eaea3SApple OSS Distributions if not proc: 209*5e3eaea3SApple OSS Distributions print("Task has no associated BSD process.") 210*5e3eaea3SApple OSS Distributions return False 211*5e3eaea3SApple OSS Distributions ptrsize = 8 if int(task.t_flags) & 0x1 else 4 212*5e3eaea3SApple OSS Distributions 213*5e3eaea3SApple OSS Distributions format_string = "Q" if ptrsize == 8 else "I" 214*5e3eaea3SApple OSS Distributions 215*5e3eaea3SApple OSS Distributions string_area_size = proc.p_argslen 216*5e3eaea3SApple OSS Distributions string_area_addr = proc.user_stack - string_area_size 217*5e3eaea3SApple OSS Distributions 218*5e3eaea3SApple OSS Distributions string_area = GetUserDataAsString(task, string_area_addr, string_area_size) 219*5e3eaea3SApple OSS Distributions if not string_area: 220*5e3eaea3SApple OSS Distributions print("Could not read any data from userspace address.") 221*5e3eaea3SApple OSS Distributions return False 222*5e3eaea3SApple OSS Distributions 223*5e3eaea3SApple OSS Distributions i = 0 224*5e3eaea3SApple OSS Distributions pos = string_area_addr - ptrsize 225*5e3eaea3SApple OSS Distributions 226*5e3eaea3SApple OSS Distributions for name in ["apple", "env", "argv"] : 227*5e3eaea3SApple OSS Distributions while True: 228*5e3eaea3SApple OSS Distributions if name == "argv" : 229*5e3eaea3SApple OSS Distributions if i == proc.p_argc: 230*5e3eaea3SApple OSS Distributions break 231*5e3eaea3SApple OSS Distributions i += 1 232*5e3eaea3SApple OSS Distributions 233*5e3eaea3SApple OSS Distributions pos -= ptrsize 234*5e3eaea3SApple OSS Distributions 235*5e3eaea3SApple OSS Distributions user_data_string = GetUserDataAsString(task, pos, ptrsize) 236*5e3eaea3SApple OSS Distributions ptr = struct.unpack(format_string, user_data_string)[0] 237*5e3eaea3SApple OSS Distributions 238*5e3eaea3SApple OSS Distributions if ptr == 0: 239*5e3eaea3SApple OSS Distributions break 240*5e3eaea3SApple OSS Distributions 241*5e3eaea3SApple OSS Distributions if string_area_addr <= ptr and ptr < string_area_addr+string_area_size : 242*5e3eaea3SApple OSS Distributions string_offset = ptr - string_area_addr 243*5e3eaea3SApple OSS Distributions string = string_area[string_offset:] 244*5e3eaea3SApple OSS Distributions else: 245*5e3eaea3SApple OSS Distributions string = GetUserspaceString(task, ptr) 246*5e3eaea3SApple OSS Distributions 247*5e3eaea3SApple OSS Distributions print(name + "[]: " + string) 248*5e3eaea3SApple OSS Distributions 249*5e3eaea3SApple OSS Distributions return True 250*5e3eaea3SApple OSS Distributions 251*5e3eaea3SApple OSS Distributionsdef ShowTaskUserStacks(task): 252*5e3eaea3SApple OSS Distributions #print GetTaskSummary.header + " " + GetProcSummary.header 253*5e3eaea3SApple OSS Distributions pval = GetProcFromTask(task) 254*5e3eaea3SApple OSS Distributions #print GetTaskSummary(task) + " " + GetProcSummary(pval) + "\n \n" 255*5e3eaea3SApple OSS Distributions crash_report_format_string = """\ 256*5e3eaea3SApple OSS DistributionsProcess: {pname:s} [{pid:d}] 257*5e3eaea3SApple OSS DistributionsPath: {path: <50s} 258*5e3eaea3SApple OSS DistributionsIdentifier: {pname: <30s} 259*5e3eaea3SApple OSS DistributionsVersion: ??? (???) 260*5e3eaea3SApple OSS DistributionsCode Type: {parch: <20s} 261*5e3eaea3SApple OSS DistributionsParent Process: {ppname:s} [{ppid:d}] 262*5e3eaea3SApple OSS Distributions 263*5e3eaea3SApple OSS DistributionsDate/Time: {timest:s}.000 -0800 264*5e3eaea3SApple OSS DistributionsOS Version: {osversion: <20s} 265*5e3eaea3SApple OSS DistributionsReport Version: 8 266*5e3eaea3SApple OSS Distributions 267*5e3eaea3SApple OSS DistributionsException Type: n/a 268*5e3eaea3SApple OSS DistributionsException Codes: n/a 269*5e3eaea3SApple OSS DistributionsCrashed Thread: 0 270*5e3eaea3SApple OSS Distributions 271*5e3eaea3SApple OSS DistributionsApplication Specific Information: 272*5e3eaea3SApple OSS DistributionsSynthetic crash log generated from Kernel userstacks 273*5e3eaea3SApple OSS Distributions 274*5e3eaea3SApple OSS Distributions""" 275*5e3eaea3SApple OSS Distributions user_lib_rex = re.compile("([0-9a-fx]+)\s-\s([0-9a-fx]+)\s+(.*?)\s", re.IGNORECASE|re.MULTILINE) 276*5e3eaea3SApple OSS Distributions from datetime import datetime 277*5e3eaea3SApple OSS Distributions if pval: 278*5e3eaea3SApple OSS Distributions ts = datetime.fromtimestamp(int(pval.p_start.tv_sec)) 279*5e3eaea3SApple OSS Distributions date_string = ts.strftime('%Y-%m-%d %H:%M:%S') 280*5e3eaea3SApple OSS Distributions else: 281*5e3eaea3SApple OSS Distributions date_string = "none" 282*5e3eaea3SApple OSS Distributions is_64 = True 283*5e3eaea3SApple OSS Distributions if pval and (pval.p_flag & 0x4) == 0 : 284*5e3eaea3SApple OSS Distributions is_64 = False 285*5e3eaea3SApple OSS Distributions 286*5e3eaea3SApple OSS Distributions parch_s = "" 287*5e3eaea3SApple OSS Distributions if kern.arch == "x86_64" or kern.arch == "i386": 288*5e3eaea3SApple OSS Distributions osversion = "Mac OS X 10.8" 289*5e3eaea3SApple OSS Distributions parch_s = "I386 (32 bit)" 290*5e3eaea3SApple OSS Distributions if is_64: 291*5e3eaea3SApple OSS Distributions parch_s = "X86-64 (Native)" 292*5e3eaea3SApple OSS Distributions else: 293*5e3eaea3SApple OSS Distributions parch_s = kern.arch 294*5e3eaea3SApple OSS Distributions osversion = "iOS" 295*5e3eaea3SApple OSS Distributions osversion += " ({:s})".format(kern.globals.osversion) 296*5e3eaea3SApple OSS Distributions if pval: 297*5e3eaea3SApple OSS Distributions pid = GetProcPID(pval) 298*5e3eaea3SApple OSS Distributions pname = GetProcName(pval) 299*5e3eaea3SApple OSS Distributions path = GetProcName(pval) 300*5e3eaea3SApple OSS Distributions ppid = pval.p_ppid 301*5e3eaea3SApple OSS Distributions else: 302*5e3eaea3SApple OSS Distributions pid = 0 303*5e3eaea3SApple OSS Distributions pname = "unknown" 304*5e3eaea3SApple OSS Distributions path = "unknown" 305*5e3eaea3SApple OSS Distributions ppid = 0 306*5e3eaea3SApple OSS Distributions 307*5e3eaea3SApple OSS Distributions print(crash_report_format_string.format(pid = pid, 308*5e3eaea3SApple OSS Distributions pname = pname, 309*5e3eaea3SApple OSS Distributions path = path, 310*5e3eaea3SApple OSS Distributions ppid = ppid, 311*5e3eaea3SApple OSS Distributions ppname = GetProcNameForPid(ppid), 312*5e3eaea3SApple OSS Distributions timest = date_string, 313*5e3eaea3SApple OSS Distributions parch = parch_s, 314*5e3eaea3SApple OSS Distributions osversion = osversion 315*5e3eaea3SApple OSS Distributions )) 316*5e3eaea3SApple OSS Distributions print("Binary Images:") 317*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries([hex(task)]) 318*5e3eaea3SApple OSS Distributions usertask_lib_info = [] # will host [startaddr, endaddr, lib_name] entries 319*5e3eaea3SApple OSS Distributions for entry in ShowTaskUserLibraries.found_images: 320*5e3eaea3SApple OSS Distributions #print "processing line %s" % line 321*5e3eaea3SApple OSS Distributions arr = user_lib_rex.findall(entry[3]) 322*5e3eaea3SApple OSS Distributions #print "%r" % arr 323*5e3eaea3SApple OSS Distributions if len(arr) == 0 : 324*5e3eaea3SApple OSS Distributions continue 325*5e3eaea3SApple OSS Distributions usertask_lib_info.append([int(arr[0][0],16), int(arr[0][1],16), str(arr[0][2]).strip()]) 326*5e3eaea3SApple OSS Distributions 327*5e3eaea3SApple OSS Distributions printthread_user_stack_ptr = ShowX86UserStack 328*5e3eaea3SApple OSS Distributions if kern.arch.startswith("arm64"): 329*5e3eaea3SApple OSS Distributions printthread_user_stack_ptr = ShowARM64UserStack 330*5e3eaea3SApple OSS Distributions 331*5e3eaea3SApple OSS Distributions counter = 0 332*5e3eaea3SApple OSS Distributions for thval in IterateQueue(task.threads, 'thread *', 'task_threads'): 333*5e3eaea3SApple OSS Distributions print("\nThread {0:d} name:0x{1:x}\nThread {0:d}:".format(counter, thval)) 334*5e3eaea3SApple OSS Distributions counter += 1 335*5e3eaea3SApple OSS Distributions try: 336*5e3eaea3SApple OSS Distributions printthread_user_stack_ptr(thval, usertask_lib_info) 337*5e3eaea3SApple OSS Distributions except Exception as exc_err: 338*5e3eaea3SApple OSS Distributions print("Failed to show user stack for thread 0x{0:x}".format(thval)) 339*5e3eaea3SApple OSS Distributions if config['debug']: 340*5e3eaea3SApple OSS Distributions raise exc_err 341*5e3eaea3SApple OSS Distributions else: 342*5e3eaea3SApple OSS Distributions print("Enable debugging ('(lldb) xnudebug debug') to see detailed trace.") 343*5e3eaea3SApple OSS Distributions return 344*5e3eaea3SApple OSS Distributions 345*5e3eaea3SApple OSS Distributions@lldb_command('showtaskuserstacks', "P:F:") 346*5e3eaea3SApple OSS Distributionsdef ShowTaskUserStacksCmdHelper(cmd_args=None, cmd_options={}): 347*5e3eaea3SApple OSS Distributions """ Print out the user stack for each thread in a task, followed by the user libraries. 348*5e3eaea3SApple OSS Distributions Syntax: (lldb) showtaskuserstacks <task_t> 349*5e3eaea3SApple OSS Distributions or: (lldb) showtaskuserstacks -P <pid> 350*5e3eaea3SApple OSS Distributions or: (lldb) showtaskuserstacks -F <task_name> 351*5e3eaea3SApple OSS Distributions The format is compatible with CrashTracer. You can also use the speedtracer plugin as follows 352*5e3eaea3SApple OSS Distributions (lldb) showtaskuserstacks <task_t> -p speedtracer 353*5e3eaea3SApple OSS Distributions 354*5e3eaea3SApple OSS Distributions Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures 355*5e3eaea3SApple OSS Distributions and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate 356*5e3eaea3SApple OSS Distributions """ 357*5e3eaea3SApple OSS Distributions task_list = [] 358*5e3eaea3SApple OSS Distributions if "-F" in cmd_options: 359*5e3eaea3SApple OSS Distributions task_list = FindTasksByName(cmd_options["-F"]) 360*5e3eaea3SApple OSS Distributions elif "-P" in cmd_options: 361*5e3eaea3SApple OSS Distributions pidval = ArgumentStringToInt(cmd_options["-P"]) 362*5e3eaea3SApple OSS Distributions for t in kern.tasks: 363*5e3eaea3SApple OSS Distributions pval = GetProcFromTask(t) 364*5e3eaea3SApple OSS Distributions if pval and GetProcPID(pval) == pidval: 365*5e3eaea3SApple OSS Distributions task_list.append(t) 366*5e3eaea3SApple OSS Distributions break 367*5e3eaea3SApple OSS Distributions elif cmd_args: 368*5e3eaea3SApple OSS Distributions t = kern.GetValueFromAddress(cmd_args[0], 'task *') 369*5e3eaea3SApple OSS Distributions task_list.append(t) 370*5e3eaea3SApple OSS Distributions else: 371*5e3eaea3SApple OSS Distributions raise ArgumentError("Insufficient arguments") 372*5e3eaea3SApple OSS Distributions 373*5e3eaea3SApple OSS Distributions for task in task_list: 374*5e3eaea3SApple OSS Distributions ShowTaskUserStacks(task) 375*5e3eaea3SApple OSS Distributions 376*5e3eaea3SApple OSS Distributionsdef GetUserDataAsString(task, addr, size): 377*5e3eaea3SApple OSS Distributions """ Get data from task's address space as a string of bytes 378*5e3eaea3SApple OSS Distributions params: 379*5e3eaea3SApple OSS Distributions task: task object from which to extract information 380*5e3eaea3SApple OSS Distributions addr: int - start address to get data from. 381*5e3eaea3SApple OSS Distributions size: int - no of bytes to read. 382*5e3eaea3SApple OSS Distributions returns: 383*5e3eaea3SApple OSS Distributions data - a stream of bytes. Empty bytes() if read fails. 384*5e3eaea3SApple OSS Distributions """ 385*5e3eaea3SApple OSS Distributions err = lldb.SBError() 386*5e3eaea3SApple OSS Distributions if GetConnectionProtocol() == "kdp": 387*5e3eaea3SApple OSS Distributions kdp_pmap_addr = unsigned(addressof(kern.globals.kdp_pmap)) 388*5e3eaea3SApple OSS Distributions if not WriteInt64ToMemoryAddress(unsigned(task.map.pmap), kdp_pmap_addr): 389*5e3eaea3SApple OSS Distributions debuglog("Failed to write in kdp_pmap from GetUserDataAsString.") 390*5e3eaea3SApple OSS Distributions return b"" 391*5e3eaea3SApple OSS Distributions content = LazyTarget.GetProcess().ReadMemory(addr, size, err) 392*5e3eaea3SApple OSS Distributions if not err.Success(): 393*5e3eaea3SApple OSS Distributions debuglog("Failed to read process memory. Error: " + err.description) 394*5e3eaea3SApple OSS Distributions return b"" 395*5e3eaea3SApple OSS Distributions if not WriteInt64ToMemoryAddress(0, kdp_pmap_addr): 396*5e3eaea3SApple OSS Distributions debuglog("Failed to reset in kdp_pmap from GetUserDataAsString.") 397*5e3eaea3SApple OSS Distributions return b"" 398*5e3eaea3SApple OSS Distributions elif (kern.arch == 'x86_64' or kern.arch.startswith('arm')) and (int(size) < (2 * kern.globals.page_size)): 399*5e3eaea3SApple OSS Distributions # Without the benefit of a KDP stub on the target, try to 400*5e3eaea3SApple OSS Distributions # find the user task's physical mapping and memcpy the data. 401*5e3eaea3SApple OSS Distributions # If it straddles a page boundary, copy in two passes 402*5e3eaea3SApple OSS Distributions range1_addr = int(addr) 403*5e3eaea3SApple OSS Distributions range1_size = int(size) 404*5e3eaea3SApple OSS Distributions if kern.StraddlesPage(range1_addr, range1_size): 405*5e3eaea3SApple OSS Distributions range2_addr = int(kern.TruncPage(range1_addr + range1_size)) 406*5e3eaea3SApple OSS Distributions range2_size = int(range1_addr + range1_size - range2_addr) 407*5e3eaea3SApple OSS Distributions range1_size = int(range2_addr - range1_addr) 408*5e3eaea3SApple OSS Distributions else: 409*5e3eaea3SApple OSS Distributions range2_addr = 0 410*5e3eaea3SApple OSS Distributions range2_size = 0 411*5e3eaea3SApple OSS Distributions range2_in_kva = 0 412*5e3eaea3SApple OSS Distributions 413*5e3eaea3SApple OSS Distributions paddr_range1 = PmapWalk(task.map.pmap, range1_addr, vSILENT) 414*5e3eaea3SApple OSS Distributions if not paddr_range1: 415*5e3eaea3SApple OSS Distributions debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr)) 416*5e3eaea3SApple OSS Distributions return b"" 417*5e3eaea3SApple OSS Distributions 418*5e3eaea3SApple OSS Distributions range1_in_kva = kern.PhysToKernelVirt(paddr_range1) 419*5e3eaea3SApple OSS Distributions content = LazyTarget.GetProcess().ReadMemory(range1_in_kva, range1_size, err) 420*5e3eaea3SApple OSS Distributions if not err.Success(): 421*5e3eaea3SApple OSS Distributions raise RuntimeError("Failed to read process memory. Error: " + err.description) 422*5e3eaea3SApple OSS Distributions 423*5e3eaea3SApple OSS Distributions if range2_addr: 424*5e3eaea3SApple OSS Distributions paddr_range2 = PmapWalk(task.map.pmap, range2_addr, vSILENT) 425*5e3eaea3SApple OSS Distributions if not paddr_range2: 426*5e3eaea3SApple OSS Distributions debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr)) 427*5e3eaea3SApple OSS Distributions return b"" 428*5e3eaea3SApple OSS Distributions range2_in_kva = kern.PhysToKernelVirt(paddr_range2) 429*5e3eaea3SApple OSS Distributions content += LazyTarget.GetProcess().ReadMemory(range2_in_kva, range2_size, err) 430*5e3eaea3SApple OSS Distributions if not err.Success(): 431*5e3eaea3SApple OSS Distributions raise RuntimeError("Failed to read process memory. Error: " + err.description) 432*5e3eaea3SApple OSS Distributions else: 433*5e3eaea3SApple OSS Distributions raise NotImplementedError("GetUserDataAsString does not support this configuration") 434*5e3eaea3SApple OSS Distributions 435*5e3eaea3SApple OSS Distributions return content 436*5e3eaea3SApple OSS Distributions 437*5e3eaea3SApple OSS Distributionsdef _ExtractDataFromString(strdata, offset, data_type, length=0): 438*5e3eaea3SApple OSS Distributions """ Extract specific data from string buffer 439*5e3eaea3SApple OSS Distributions params: 440*5e3eaea3SApple OSS Distributions strdata: str - string data give from GetUserDataAsString 441*5e3eaea3SApple OSS Distributions offset: int - 0 based offset into the data. 442*5e3eaea3SApple OSS Distributions data_type: str - defines what type to be read as. Supported values are: 443*5e3eaea3SApple OSS Distributions 'uint64_t', 'uint32_t', 'string' 444*5e3eaea3SApple OSS Distributions length: int - used when data_type=='string' 445*5e3eaea3SApple OSS Distributions returns 446*5e3eaea3SApple OSS Distributions None - if extraction failed. 447*5e3eaea3SApple OSS Distributions obj - based on what is requested in data_type 448*5e3eaea3SApple OSS Distributions """ 449*5e3eaea3SApple OSS Distributions unpack_str = "s" 450*5e3eaea3SApple OSS Distributions if data_type == 'uint64_t': 451*5e3eaea3SApple OSS Distributions length = 8 452*5e3eaea3SApple OSS Distributions unpack_str = "Q" 453*5e3eaea3SApple OSS Distributions elif data_type == "uint32_t": 454*5e3eaea3SApple OSS Distributions length = 4 455*5e3eaea3SApple OSS Distributions unpack_str = "I" 456*5e3eaea3SApple OSS Distributions else: 457*5e3eaea3SApple OSS Distributions unpack_str= "%ds" % length 458*5e3eaea3SApple OSS Distributions 459*5e3eaea3SApple OSS Distributions data_len = len(strdata) 460*5e3eaea3SApple OSS Distributions if offset > data_len or (offset + length) > data_len or offset < 0: 461*5e3eaea3SApple OSS Distributions debuglog("Invalid arguments to _ExtractDataFromString.") 462*5e3eaea3SApple OSS Distributions return 0 463*5e3eaea3SApple OSS Distributions 464*5e3eaea3SApple OSS Distributions data = struct.unpack(unpack_str, strdata[offset:(offset + length)])[0] 465*5e3eaea3SApple OSS Distributions if data_type == 'string': 466*5e3eaea3SApple OSS Distributions return six.ensure_binary(data) 467*5e3eaea3SApple OSS Distributions 468*5e3eaea3SApple OSS Distributions return data 469*5e3eaea3SApple OSS Distributions 470*5e3eaea3SApple OSS Distributionsdef GetUserspaceString(task, string_address): 471*5e3eaea3SApple OSS Distributions """ Maps 32 bytes at a time and packs as string 472*5e3eaea3SApple OSS Distributions params: 473*5e3eaea3SApple OSS Distributions task: obj - referencing task to read data from 474*5e3eaea3SApple OSS Distributions string_address: int - address where the image path is stored 475*5e3eaea3SApple OSS Distributions returns: 476*5e3eaea3SApple OSS Distributions str - string path of the file. "" if failed to read. 477*5e3eaea3SApple OSS Distributions """ 478*5e3eaea3SApple OSS Distributions retval = [] 479*5e3eaea3SApple OSS Distributions while string_address > 0: 480*5e3eaea3SApple OSS Distributions str_data = GetUserDataAsString(task, string_address, 32) 481*5e3eaea3SApple OSS Distributions if not str_data: 482*5e3eaea3SApple OSS Distributions break 483*5e3eaea3SApple OSS Distributions str_data = str_data.split(b"\x00", 1)[0] 484*5e3eaea3SApple OSS Distributions retval.append(str_data) 485*5e3eaea3SApple OSS Distributions if len(str_data) < 32: 486*5e3eaea3SApple OSS Distributions break # short read or found NUL byte 487*5e3eaea3SApple OSS Distributions string_address += 32 488*5e3eaea3SApple OSS Distributions return six.ensure_str(b"".join(retval)) 489*5e3eaea3SApple OSS Distributions 490*5e3eaea3SApple OSS Distributionsdef GetImageInfo(task, mh_image_address, mh_path_address, approx_end_address=None): 491*5e3eaea3SApple OSS Distributions """ Print user library informaiton. 492*5e3eaea3SApple OSS Distributions params: 493*5e3eaea3SApple OSS Distributions task : obj referencing the task for which Image info printed 494*5e3eaea3SApple OSS Distributions mh_image_address : int - address which has image info 495*5e3eaea3SApple OSS Distributions mh_path_address : int - address which holds path name string 496*5e3eaea3SApple OSS Distributions approx_end_address: int - address which lldbmacros think is end address. 497*5e3eaea3SApple OSS Distributions returns: 498*5e3eaea3SApple OSS Distributions str - string representing image info. "" if failure to read data. 499*5e3eaea3SApple OSS Distributions """ 500*5e3eaea3SApple OSS Distributions if approx_end_address: 501*5e3eaea3SApple OSS Distributions image_end_load_address = int(approx_end_address) -1 502*5e3eaea3SApple OSS Distributions else: 503*5e3eaea3SApple OSS Distributions image_end_load_address = int(mh_image_address) + 0xffffffff 504*5e3eaea3SApple OSS Distributions 505*5e3eaea3SApple OSS Distributions print_format = "0x{0:x} - 0x{1:x} {2: <50s} (??? - ???) <{3: <36s}> {4: <50s}" 506*5e3eaea3SApple OSS Distributions # 32 bytes enough for mach_header/mach_header_64 507*5e3eaea3SApple OSS Distributions mh_data = GetUserDataAsString(task, mh_image_address, 32) 508*5e3eaea3SApple OSS Distributions if len(mh_data) == 0: 509*5e3eaea3SApple OSS Distributions debuglog("unable to get userdata for task 0x{:x} img_addr 0x{:x} path_address 0x{:x}".format( 510*5e3eaea3SApple OSS Distributions task, mh_image_address, mh_path_address)) 511*5e3eaea3SApple OSS Distributions return "" 512*5e3eaea3SApple OSS Distributions mh_magic = _ExtractDataFromString(mh_data, (4 * 0), "uint32_t") 513*5e3eaea3SApple OSS Distributions mh_cputype = _ExtractDataFromString(mh_data,(4 * 1), "uint32_t") 514*5e3eaea3SApple OSS Distributions mh_cpusubtype = _ExtractDataFromString(mh_data,(4 * 2), "uint32_t") 515*5e3eaea3SApple OSS Distributions mh_filetype = _ExtractDataFromString(mh_data,(4 * 3), "uint32_t") 516*5e3eaea3SApple OSS Distributions mh_ncmds = _ExtractDataFromString(mh_data,(4 * 4), "uint32_t") 517*5e3eaea3SApple OSS Distributions mh_sizeofcmds = _ExtractDataFromString(mh_data,(4 * 5), "uint32_t") 518*5e3eaea3SApple OSS Distributions mh_flags = _ExtractDataFromString(mh_data,(4 * 6), "uint32_t") 519*5e3eaea3SApple OSS Distributions 520*5e3eaea3SApple OSS Distributions if mh_magic == 0xfeedfacf: 521*5e3eaea3SApple OSS Distributions mh_64 = True 522*5e3eaea3SApple OSS Distributions lc_address = mh_image_address + 32 523*5e3eaea3SApple OSS Distributions else: 524*5e3eaea3SApple OSS Distributions mh_64 = False 525*5e3eaea3SApple OSS Distributions lc_address = mh_image_address + 28 526*5e3eaea3SApple OSS Distributions 527*5e3eaea3SApple OSS Distributions lc_idx = 0 528*5e3eaea3SApple OSS Distributions uuid_data = 0 529*5e3eaea3SApple OSS Distributions found_uuid_data = False 530*5e3eaea3SApple OSS Distributions retval = None 531*5e3eaea3SApple OSS Distributions while lc_idx < mh_ncmds: 532*5e3eaea3SApple OSS Distributions # 24 bytes is the size of uuid_command 533*5e3eaea3SApple OSS Distributions lcmd_data = GetUserDataAsString(task, lc_address, 24) 534*5e3eaea3SApple OSS Distributions lc_cmd = _ExtractDataFromString(lcmd_data, 4 * 0, "uint32_t") 535*5e3eaea3SApple OSS Distributions lc_cmd_size = _ExtractDataFromString(lcmd_data, 4 * 1, "uint32_t") 536*5e3eaea3SApple OSS Distributions lc_data = _ExtractDataFromString(lcmd_data, 4*2, "string", 16) 537*5e3eaea3SApple OSS Distributions 538*5e3eaea3SApple OSS Distributions uuid_out_string = "" 539*5e3eaea3SApple OSS Distributions path_out_string = "" 540*5e3eaea3SApple OSS Distributions 541*5e3eaea3SApple OSS Distributions if lc_cmd == 0x1b: 542*5e3eaea3SApple OSS Distributions # need to print the uuid now. 543*5e3eaea3SApple OSS Distributions uuid_data = bytes(lc_data) 544*5e3eaea3SApple OSS Distributions found_uuid_data = True 545*5e3eaea3SApple OSS Distributions uuid_out_string = "{a[0]:02X}{a[1]:02X}{a[2]:02X}{a[3]:02X}-{a[4]:02X}{a[5]:02X}-{a[6]:02X}{a[7]:02X}-{a[8]:02X}{a[9]:02X}-{a[10]:02X}{a[11]:02X}{a[12]:02X}{a[13]:02X}{a[14]:02X}{a[15]:02X}".format(a=uuid_data) 546*5e3eaea3SApple OSS Distributions #also print image path 547*5e3eaea3SApple OSS Distributions path_out_string = GetUserspaceString(task, mh_path_address) 548*5e3eaea3SApple OSS Distributions path_base_name = path_out_string.split("/")[-1] 549*5e3eaea3SApple OSS Distributions retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string) 550*5e3eaea3SApple OSS Distributions elif lc_cmd == 0xe: 551*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.exec_load_path = lc_address + _ExtractDataFromString(lcmd_data, 4*2, "uint32_t") 552*5e3eaea3SApple OSS Distributions debuglog("Found load command to be 0xe for address %s" % hex(ShowTaskUserLibraries.exec_load_path)) 553*5e3eaea3SApple OSS Distributions lc_address = lc_address + lc_cmd_size 554*5e3eaea3SApple OSS Distributions lc_idx += 1 555*5e3eaea3SApple OSS Distributions 556*5e3eaea3SApple OSS Distributions if not found_uuid_data: 557*5e3eaea3SApple OSS Distributions path_out_string = GetUserspaceString(task, mh_path_address) 558*5e3eaea3SApple OSS Distributions path_base_name = path_out_string.split("/")[-1] 559*5e3eaea3SApple OSS Distributions uuid_out_string = "" 560*5e3eaea3SApple OSS Distributions 561*5e3eaea3SApple OSS Distributions retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string) 562*5e3eaea3SApple OSS Distributions return retval 563*5e3eaea3SApple OSS Distributions 564*5e3eaea3SApple OSS Distributions@static_var("found_images", []) # holds entries of format (startaddr, endaddr, image_path_addr, infostring) 565*5e3eaea3SApple OSS Distributions@static_var("exec_load_path", 0) 566*5e3eaea3SApple OSS Distributions@lldb_command("showtaskuserlibraries") 567*5e3eaea3SApple OSS Distributionsdef ShowTaskUserLibraries(cmd_args=None): 568*5e3eaea3SApple OSS Distributions """ Show binary images known by dyld in target task 569*5e3eaea3SApple OSS Distributions For a given user task, inspect the dyld shared library state and print information about all Mach-O images. 570*5e3eaea3SApple OSS Distributions Syntax: (lldb)showtaskuserlibraries <task_t> 571*5e3eaea3SApple OSS Distributions Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures 572*5e3eaea3SApple OSS Distributions and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate 573*5e3eaea3SApple OSS Distributions """ 574*5e3eaea3SApple OSS Distributions if not cmd_args: 575*5e3eaea3SApple OSS Distributions raise ArgumentError("Insufficient arguments") 576*5e3eaea3SApple OSS Distributions 577*5e3eaea3SApple OSS Distributions #reset the found_images array 578*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.found_images = [] 579*5e3eaea3SApple OSS Distributions 580*5e3eaea3SApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task_t') 581*5e3eaea3SApple OSS Distributions is_task_64 = int(task.t_flags) & 0x1 582*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address = unsigned(task.all_image_info_addr) 583*5e3eaea3SApple OSS Distributions debuglog("dyld_all_image_infos_address = %s" % hex(dyld_all_image_infos_address)) 584*5e3eaea3SApple OSS Distributions 585*5e3eaea3SApple OSS Distributions cur_data_offset = 0 586*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_address == 0: 587*5e3eaea3SApple OSS Distributions print("No dyld shared library information available for task") 588*5e3eaea3SApple OSS Distributions return False 589*5e3eaea3SApple OSS Distributions 590*5e3eaea3SApple OSS Distributions debuglog("Extracting version information.") 591*5e3eaea3SApple OSS Distributions vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112) 592*5e3eaea3SApple OSS Distributions version = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t") 593*5e3eaea3SApple OSS Distributions cur_data_offset += 4 594*5e3eaea3SApple OSS Distributions if version > 14: 595*5e3eaea3SApple OSS Distributions print("Unknown dyld all_image_infos version number %d" % version) 596*5e3eaea3SApple OSS Distributions image_info_count = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t") 597*5e3eaea3SApple OSS Distributions debuglog("version = %d count = %d is_task_64 = %s" % (version, image_info_count, repr(is_task_64))) 598*5e3eaea3SApple OSS Distributions 599*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.exec_load_path = 0 600*5e3eaea3SApple OSS Distributions if is_task_64: 601*5e3eaea3SApple OSS Distributions image_info_size = 24 602*5e3eaea3SApple OSS Distributions image_info_array_address = _ExtractDataFromString(vers_info_data, 8, "uint64_t") 603*5e3eaea3SApple OSS Distributions dyld_load_address = _ExtractDataFromString(vers_info_data, 8*4, "uint64_t") 604*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 8*13, "uint64_t") 605*5e3eaea3SApple OSS Distributions else: 606*5e3eaea3SApple OSS Distributions image_info_size = 12 607*5e3eaea3SApple OSS Distributions image_info_array_address = _ExtractDataFromString(vers_info_data, 4*2, "uint32_t") 608*5e3eaea3SApple OSS Distributions dyld_load_address = _ExtractDataFromString(vers_info_data, 4*5, "uint32_t") 609*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 4*14, "uint32_t") 610*5e3eaea3SApple OSS Distributions # Account for ASLR slide before dyld can fix the structure 611*5e3eaea3SApple OSS Distributions dyld_load_address = dyld_load_address + (dyld_all_image_infos_address - dyld_all_image_infos_address_from_struct) 612*5e3eaea3SApple OSS Distributions 613*5e3eaea3SApple OSS Distributions i = 0 614*5e3eaea3SApple OSS Distributions image_info_list = [] 615*5e3eaea3SApple OSS Distributions while i < image_info_count: 616*5e3eaea3SApple OSS Distributions image_info_address = image_info_array_address + i * image_info_size 617*5e3eaea3SApple OSS Distributions debuglog("i = %d, image_info_address = %s, image_info_size = %d" % (i, hex(image_info_address), image_info_size)) 618*5e3eaea3SApple OSS Distributions n_im_info_addr = None 619*5e3eaea3SApple OSS Distributions img_data = "" 620*5e3eaea3SApple OSS Distributions try: 621*5e3eaea3SApple OSS Distributions img_data = GetUserDataAsString(task, image_info_address, image_info_size) 622*5e3eaea3SApple OSS Distributions except Exception as e: 623*5e3eaea3SApple OSS Distributions debuglog("Failed to read user data for task 0x{:x} addr 0x{:x}, exception {:s}".format(task, image_info_address, str(e))) 624*5e3eaea3SApple OSS Distributions pass 625*5e3eaea3SApple OSS Distributions 626*5e3eaea3SApple OSS Distributions if is_task_64: 627*5e3eaea3SApple OSS Distributions image_info_addr = _ExtractDataFromString(img_data, 0, "uint64_t") 628*5e3eaea3SApple OSS Distributions image_info_path = _ExtractDataFromString(img_data, 8, "uint64_t") 629*5e3eaea3SApple OSS Distributions else: 630*5e3eaea3SApple OSS Distributions image_info_addr = _ExtractDataFromString(img_data, 0, "uint32_t") 631*5e3eaea3SApple OSS Distributions image_info_path = _ExtractDataFromString(img_data, 4, "uint32_t") 632*5e3eaea3SApple OSS Distributions 633*5e3eaea3SApple OSS Distributions if image_info_addr : 634*5e3eaea3SApple OSS Distributions debuglog("Found image: image_info_addr = %s, image_info_path= %s" % (hex(image_info_addr), hex(image_info_path))) 635*5e3eaea3SApple OSS Distributions image_info_list.append((image_info_addr, image_info_path)) 636*5e3eaea3SApple OSS Distributions i += 1 637*5e3eaea3SApple OSS Distributions 638*5e3eaea3SApple OSS Distributions image_info_list.sort() 639*5e3eaea3SApple OSS Distributions num_images_found = len(image_info_list) 640*5e3eaea3SApple OSS Distributions 641*5e3eaea3SApple OSS Distributions for ii in range(num_images_found): 642*5e3eaea3SApple OSS Distributions n_im_info_addr = dyld_load_address 643*5e3eaea3SApple OSS Distributions if ii + 1 < num_images_found: 644*5e3eaea3SApple OSS Distributions n_im_info_addr = image_info_list[ii+1][0] 645*5e3eaea3SApple OSS Distributions 646*5e3eaea3SApple OSS Distributions image_info_addr = image_info_list[ii][0] 647*5e3eaea3SApple OSS Distributions image_info_path = image_info_list[ii][1] 648*5e3eaea3SApple OSS Distributions try: 649*5e3eaea3SApple OSS Distributions image_print_s = GetImageInfo(task, image_info_addr, image_info_path, approx_end_address=n_im_info_addr) 650*5e3eaea3SApple OSS Distributions if len(image_print_s) > 0: 651*5e3eaea3SApple OSS Distributions print(image_print_s) 652*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.found_images.append((image_info_addr, n_im_info_addr, image_info_path, image_print_s)) 653*5e3eaea3SApple OSS Distributions else: 654*5e3eaea3SApple OSS Distributions debuglog("Failed to print image info for task 0x{:x} image_info 0x{:x}".format(task, image_info_addr)) 655*5e3eaea3SApple OSS Distributions except Exception as e: 656*5e3eaea3SApple OSS Distributions if config['debug']: 657*5e3eaea3SApple OSS Distributions raise e 658*5e3eaea3SApple OSS Distributions 659*5e3eaea3SApple OSS Distributions # load_path might get set when the main executable is processed. 660*5e3eaea3SApple OSS Distributions if ShowTaskUserLibraries.exec_load_path != 0: 661*5e3eaea3SApple OSS Distributions debuglog("main executable load_path is set.") 662*5e3eaea3SApple OSS Distributions image_print_s = GetImageInfo(task, dyld_load_address, ShowTaskUserLibraries.exec_load_path) 663*5e3eaea3SApple OSS Distributions if len(image_print_s) > 0: 664*5e3eaea3SApple OSS Distributions print(image_print_s) 665*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.found_images.append((dyld_load_address, dyld_load_address + 0xffffffff, 666*5e3eaea3SApple OSS Distributions ShowTaskUserLibraries.exec_load_path, image_print_s)) 667*5e3eaea3SApple OSS Distributions else: 668*5e3eaea3SApple OSS Distributions debuglog("Failed to print image for main executable for task 0x{:x} dyld_load_addr 0x{:x}".format(task, dyld_load_address)) 669*5e3eaea3SApple OSS Distributions else: 670*5e3eaea3SApple OSS Distributions debuglog("Falling back to vm entry method for finding executable load address") 671*5e3eaea3SApple OSS Distributions print("# NOTE: Failed to find executable using all_image_infos. Using fuzzy match to find best possible load address for executable.") 672*5e3eaea3SApple OSS Distributions ShowTaskLoadInfo([cmd_args[0]]) 673*5e3eaea3SApple OSS Distributions return 674*5e3eaea3SApple OSS Distributions 675*5e3eaea3SApple OSS Distributions@lldb_command("showtaskuserdyldinfo") 676*5e3eaea3SApple OSS Distributionsdef ShowTaskUserDyldInfo(cmd_args=None): 677*5e3eaea3SApple OSS Distributions """ Inspect the dyld global info for the given user task & print out all fields including error messages 678*5e3eaea3SApple OSS Distributions Syntax: (lldb)showtaskuserdyldinfo <task_t> 679*5e3eaea3SApple OSS Distributions """ 680*5e3eaea3SApple OSS Distributions if cmd_args is None or len(cmd_args) < 1: 681*5e3eaea3SApple OSS Distributions print("No arguments passed") 682*5e3eaea3SApple OSS Distributions print(ShowTaskUserDyldInfo.__doc__.strip()) 683*5e3eaea3SApple OSS Distributions return 684*5e3eaea3SApple OSS Distributions 685*5e3eaea3SApple OSS Distributions out_str = "" 686*5e3eaea3SApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task_t') 687*5e3eaea3SApple OSS Distributions is_task_64 = int(task.t_flags) & 0x1 688*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address = unsigned(task.all_image_info_addr) 689*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_address == 0: 690*5e3eaea3SApple OSS Distributions print("No dyld shared library information available for task") 691*5e3eaea3SApple OSS Distributions return False 692*5e3eaea3SApple OSS Distributions vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112) 693*5e3eaea3SApple OSS Distributions dyld_all_image_infos_version = _ExtractDataFromString(vers_info_data, 0, "uint32_t") 694*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_version > 14: 695*5e3eaea3SApple OSS Distributions out_str += "Unknown dyld all_image_infos version number %d" % dyld_all_image_infos_version 696*5e3eaea3SApple OSS Distributions 697*5e3eaea3SApple OSS Distributions # Find fields by byte offset. We assume at least version 9 is supported 698*5e3eaea3SApple OSS Distributions if is_task_64: 699*5e3eaea3SApple OSS Distributions dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t") 700*5e3eaea3SApple OSS Distributions dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint64_t") 701*5e3eaea3SApple OSS Distributions dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 16, "uint64_t") 702*5e3eaea3SApple OSS Distributions dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 24, "string") 703*5e3eaea3SApple OSS Distributions dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 25, "string") 704*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 32, "uint64_t") 705*5e3eaea3SApple OSS Distributions dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 40, "uint64_t") 706*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 48, "uint64_t") 707*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 56, "uint64_t") 708*5e3eaea3SApple OSS Distributions dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 64, "uint64_t") 709*5e3eaea3SApple OSS Distributions dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 72, "uint64_t") 710*5e3eaea3SApple OSS Distributions dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 80, "uint64_t") 711*5e3eaea3SApple OSS Distributions dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 88, "uint64_t") 712*5e3eaea3SApple OSS Distributions dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 96, "uint64_t") 713*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 104, "uint64_t") 714*5e3eaea3SApple OSS Distributions else: 715*5e3eaea3SApple OSS Distributions dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t") 716*5e3eaea3SApple OSS Distributions dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint32_t") 717*5e3eaea3SApple OSS Distributions dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 12, "uint32_t") 718*5e3eaea3SApple OSS Distributions dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 16, "string") 719*5e3eaea3SApple OSS Distributions dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 17, "string") 720*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 20, "uint32_t") 721*5e3eaea3SApple OSS Distributions dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 24, "uint32_t") 722*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 28, "uint32_t") 723*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 32, "uint32_t") 724*5e3eaea3SApple OSS Distributions dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 36, "uint32_t") 725*5e3eaea3SApple OSS Distributions dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 40, "uint32_t") 726*5e3eaea3SApple OSS Distributions dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 44, "uint32_t") 727*5e3eaea3SApple OSS Distributions dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 48, "uint32_t") 728*5e3eaea3SApple OSS Distributions dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 52, "uint32_t") 729*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 56, "uint32_t") 730*5e3eaea3SApple OSS Distributions 731*5e3eaea3SApple OSS Distributions dyld_all_imfo_infos_slide = (dyld_all_image_infos_address - dyld_all_image_infos_dyldAllImageInfosAddress) 732*5e3eaea3SApple OSS Distributions dyld_all_image_infos_dyldVersion_postslide = (dyld_all_image_infos_dyldVersion + dyld_all_imfo_infos_slide) 733*5e3eaea3SApple OSS Distributions 734*5e3eaea3SApple OSS Distributions path_out = GetUserspaceString(task, dyld_all_image_infos_dyldVersion_postslide) 735*5e3eaea3SApple OSS Distributions out_str += "[dyld-{:s}]\n".format(path_out) 736*5e3eaea3SApple OSS Distributions out_str += "version \t\t\t\t: {:d}\n".format(dyld_all_image_infos_version) 737*5e3eaea3SApple OSS Distributions out_str += "infoArrayCount \t\t\t\t: {:d}\n".format(dyld_all_image_infos_infoArrayCount) 738*5e3eaea3SApple OSS Distributions out_str += "infoArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_infoArray) 739*5e3eaea3SApple OSS Distributions out_str += "notification \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_notification) 740*5e3eaea3SApple OSS Distributions 741*5e3eaea3SApple OSS Distributions out_str += "processDetachedFromSharedRegion \t: " 742*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_processDetachedFromSharedRegion != "": 743*5e3eaea3SApple OSS Distributions out_str += "TRUE\n".format(dyld_all_image_infos_processDetachedFromSharedRegion) 744*5e3eaea3SApple OSS Distributions else: 745*5e3eaea3SApple OSS Distributions out_str += "FALSE\n" 746*5e3eaea3SApple OSS Distributions 747*5e3eaea3SApple OSS Distributions out_str += "libSystemInitialized \t\t\t: " 748*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_libSystemInitialized != "": 749*5e3eaea3SApple OSS Distributions out_str += "TRUE\n".format(dyld_all_image_infos_libSystemInitialized) 750*5e3eaea3SApple OSS Distributions else: 751*5e3eaea3SApple OSS Distributions out_str += "FALSE\n" 752*5e3eaea3SApple OSS Distributions 753*5e3eaea3SApple OSS Distributions out_str += "dyldImageLoadAddress \t\t\t: {:#x}\n".format(dyld_all_image_infos_dyldImageLoadAddress) 754*5e3eaea3SApple OSS Distributions out_str += "jitInfo \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_jitInfo) 755*5e3eaea3SApple OSS Distributions out_str += "\ndyldVersion \t\t\t\t: {:#x}".format(dyld_all_image_infos_dyldVersion) 756*5e3eaea3SApple OSS Distributions if (dyld_all_imfo_infos_slide != 0): 757*5e3eaea3SApple OSS Distributions out_str += " (currently {:#x})\n".format(dyld_all_image_infos_dyldVersion_postslide) 758*5e3eaea3SApple OSS Distributions else: 759*5e3eaea3SApple OSS Distributions out_str += "\n" 760*5e3eaea3SApple OSS Distributions 761*5e3eaea3SApple OSS Distributions out_str += "errorMessage \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorMessage) 762*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_errorMessage != 0: 763*5e3eaea3SApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorMessage) 764*5e3eaea3SApple OSS Distributions 765*5e3eaea3SApple OSS Distributions out_str += "terminationFlags \t\t\t: {:#x}\n".format(dyld_all_image_infos_terminationFlags) 766*5e3eaea3SApple OSS Distributions out_str += "coreSymbolicationShmPage \t\t: {:#x}\n".format(dyld_all_image_infos_coreSymbolicationShmPage) 767*5e3eaea3SApple OSS Distributions out_str += "systemOrderFlag \t\t\t: {:#x}\n".format(dyld_all_image_infos_systemOrderFlag) 768*5e3eaea3SApple OSS Distributions out_str += "uuidArrayCount \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArrayCount) 769*5e3eaea3SApple OSS Distributions out_str += "uuidArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArray) 770*5e3eaea3SApple OSS Distributions out_str += "dyldAllImageInfosAddress \t\t: {:#x}".format(dyld_all_image_infos_dyldAllImageInfosAddress) 771*5e3eaea3SApple OSS Distributions if (dyld_all_imfo_infos_slide != 0): 772*5e3eaea3SApple OSS Distributions out_str += " (currently {:#x})\n".format(dyld_all_image_infos_address) 773*5e3eaea3SApple OSS Distributions else: 774*5e3eaea3SApple OSS Distributions out_str += "\n" 775*5e3eaea3SApple OSS Distributions 776*5e3eaea3SApple OSS Distributions if is_task_64: 777*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address = dyld_all_image_infos_address + 112 778*5e3eaea3SApple OSS Distributions dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 64) 779*5e3eaea3SApple OSS Distributions dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 112-112, "uint64_t") 780*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 120-112, "uint64_t") 781*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 128-112, "uint64_t") 782*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 136-112, "uint64_t") 783*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 144-112, "uint64_t") 784*5e3eaea3SApple OSS Distributions dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 152-112, "uint64_t") 785*5e3eaea3SApple OSS Distributions dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 160-112, "string") 786*5e3eaea3SApple OSS Distributions else: 787*5e3eaea3SApple OSS Distributions dyld_all_image_infos_address = dyld_all_image_infos_address + 60 788*5e3eaea3SApple OSS Distributions dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 40) 789*5e3eaea3SApple OSS Distributions dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 60-60, "uint32_t") 790*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 64-60, "uint32_t") 791*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 68-60, "uint32_t") 792*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 72-60, "uint32_t") 793*5e3eaea3SApple OSS Distributions dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 76-60, "uint32_t") 794*5e3eaea3SApple OSS Distributions dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 80-60, "uint32_t") 795*5e3eaea3SApple OSS Distributions dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 84-60, "string") 796*5e3eaea3SApple OSS Distributions 797*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_version >= 10: 798*5e3eaea3SApple OSS Distributions out_str += "\ninitialImageCount \t\t\t: {:#x}\n".format(dyld_all_image_infos_initialImageCount) 799*5e3eaea3SApple OSS Distributions 800*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_version >= 11: 801*5e3eaea3SApple OSS Distributions out_str += "errorKind \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorKind) 802*5e3eaea3SApple OSS Distributions out_str += "errorClientOfDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorClientOfDylibPath) 803*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_errorClientOfDylibPath != 0: 804*5e3eaea3SApple OSS Distributions out_str += "\t\t\t\t" 805*5e3eaea3SApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorClientOfDylibPath) 806*5e3eaea3SApple OSS Distributions out_str += "\n" 807*5e3eaea3SApple OSS Distributions out_str += "errorTargetDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorTargetDylibPath) 808*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_errorTargetDylibPath != 0: 809*5e3eaea3SApple OSS Distributions out_str += "\t\t\t\t" 810*5e3eaea3SApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorTargetDylibPath) 811*5e3eaea3SApple OSS Distributions out_str += "\n" 812*5e3eaea3SApple OSS Distributions out_str += "errorSymbol \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorSymbol) 813*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_errorSymbol != 0: 814*5e3eaea3SApple OSS Distributions out_str += "\t\t\t\t" 815*5e3eaea3SApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorSymbol) 816*5e3eaea3SApple OSS Distributions out_str += "\n" 817*5e3eaea3SApple OSS Distributions 818*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_version >= 12: 819*5e3eaea3SApple OSS Distributions out_str += "sharedCacheSlide \t\t\t: {:#x}\n".format(dyld_all_image_infos_sharedCacheSlide) 820*5e3eaea3SApple OSS Distributions if dyld_all_image_infos_version >= 13 and dyld_all_image_infos_sharedCacheUUID != b"": 821*5e3eaea3SApple OSS Distributions out_str += "sharedCacheUUID \t\t\t: {:s}\n".format(six.ensure_str(dyld_all_image_infos_sharedCacheUUID)) 822*5e3eaea3SApple OSS Distributions else: 823*5e3eaea3SApple OSS Distributions out_str += "No dyld information available for task\n" 824*5e3eaea3SApple OSS Distributions print(out_str) 825*5e3eaea3SApple OSS Distributions 826*5e3eaea3SApple OSS Distributionsdef SaveDataToFile(start_addr, length, outputfile, task=None,): 827*5e3eaea3SApple OSS Distributions """ Save the data at the specified address (of the specified length) to the file. 828*5e3eaea3SApple OSS Distributions params: start_addr : start address of the region of memory to save 829*5e3eaea3SApple OSS Distributions length : length of the region of memory to save 830*5e3eaea3SApple OSS Distributions outputfile : file to save the data in 831*5e3eaea3SApple OSS Distributions task (optional) : task containing the memory region (if from user data) 832*5e3eaea3SApple OSS Distributions returns: True if we saved the requested data, False otherwise 833*5e3eaea3SApple OSS Distributions """ 834*5e3eaea3SApple OSS Distributions if task: 835*5e3eaea3SApple OSS Distributions memory_data = GetUserDataAsString(task, start_addr, length) 836*5e3eaea3SApple OSS Distributions else: 837*5e3eaea3SApple OSS Distributions err = lldb.SBError() 838*5e3eaea3SApple OSS Distributions memory_data = LazyTarget.GetProcess().ReadMemory(start_addr, length, err) 839*5e3eaea3SApple OSS Distributions if not err.Success(): 840*5e3eaea3SApple OSS Distributions print("Failed to read process memory. {:d} bytes from address {: <#020x}. Error: {}".format(length, start_addr, err.description)) 841*5e3eaea3SApple OSS Distributions return False 842*5e3eaea3SApple OSS Distributions 843*5e3eaea3SApple OSS Distributions if len(memory_data) != length: 844*5e3eaea3SApple OSS Distributions print("Failed to read {:d} bytes from address {: <#020x}".format(length, start_addr)) 845*5e3eaea3SApple OSS Distributions return False 846*5e3eaea3SApple OSS Distributions 847*5e3eaea3SApple OSS Distributions fh = open(outputfile, 'wb') 848*5e3eaea3SApple OSS Distributions fh.write(memory_data) 849*5e3eaea3SApple OSS Distributions fh.close() 850*5e3eaea3SApple OSS Distributions print("Saved {:d} bytes to file {:s}".format(length, outputfile)) 851*5e3eaea3SApple OSS Distributions return True 852*5e3eaea3SApple OSS Distributions 853*5e3eaea3SApple OSS Distributions 854*5e3eaea3SApple OSS Distributions@lldb_command('savekcdata', 'T:O:') 855*5e3eaea3SApple OSS Distributionsdef SaveKCDataToFile(cmd_args=None, cmd_options={}): 856*5e3eaea3SApple OSS Distributions """ Save the data referred by the kcdata_descriptor structure. 857*5e3eaea3SApple OSS Distributions options: 858*5e3eaea3SApple OSS Distributions -T: <task_t> pointer to task if memory referenced is in userstask. 859*5e3eaea3SApple OSS Distributions -O: <output file path> path to file to save data. default: /tmp/kcdata.<timestamp>.bin 860*5e3eaea3SApple OSS Distributions Usage: (lldb) savekcdata <kcdata_descriptor_t> -T <task_t> -O /path/to/outputfile.bin 861*5e3eaea3SApple OSS Distributions """ 862*5e3eaea3SApple OSS Distributions if not cmd_args: 863*5e3eaea3SApple OSS Distributions raise ArgumentError('Please provide the kcdata descriptor.') 864*5e3eaea3SApple OSS Distributions 865*5e3eaea3SApple OSS Distributions kcdata = kern.GetValueFromAddress(cmd_args[0], 'kcdata_descriptor_t') 866*5e3eaea3SApple OSS Distributions 867*5e3eaea3SApple OSS Distributions outputfile = '/tmp/kcdata.{:s}.bin'.format(str(time.time())) 868*5e3eaea3SApple OSS Distributions task = None 869*5e3eaea3SApple OSS Distributions if '-O' in cmd_options: 870*5e3eaea3SApple OSS Distributions outputfile = cmd_options['-O'] 871*5e3eaea3SApple OSS Distributions if '-T' in cmd_options: 872*5e3eaea3SApple OSS Distributions task = kern.GetValueFromAddress(cmd_options['-T'], 'task_t') 873*5e3eaea3SApple OSS Distributions 874*5e3eaea3SApple OSS Distributions memory_begin_address = unsigned(kcdata.kcd_addr_begin) 875*5e3eaea3SApple OSS Distributions memory_size = 16 + unsigned(kcdata.kcd_addr_end) - memory_begin_address 876*5e3eaea3SApple OSS Distributions flags_copyout = unsigned(kcdata.kcd_flags) 877*5e3eaea3SApple OSS Distributions if flags_copyout: 878*5e3eaea3SApple OSS Distributions if not task: 879*5e3eaea3SApple OSS Distributions raise ArgumentError('Invalid task pointer provided.') 880*5e3eaea3SApple OSS Distributions return SaveDataToFile(memory_begin_address, memory_size, outputfile, task) 881*5e3eaea3SApple OSS Distributions else: 882*5e3eaea3SApple OSS Distributions return SaveDataToFile(memory_begin_address, memory_size, outputfile, None) 883