1*2c2f96dcSApple OSS Distributionsfrom xnu import * 2*2c2f96dcSApple OSS Distributionsfrom utils import * 3*2c2f96dcSApple OSS Distributionsfrom process import * 4*2c2f96dcSApple OSS Distributionsfrom pmap import * 5*2c2f96dcSApple OSS Distributionsimport struct 6*2c2f96dcSApple OSS Distributions 7*2c2f96dcSApple OSS Distributionsdef GetBinaryNameForPC(pc_val, user_lib_info = None): 8*2c2f96dcSApple OSS Distributions """ find the binary in user_lib_info that the passed pc_val falls in range of. 9*2c2f96dcSApple OSS Distributions params: 10*2c2f96dcSApple OSS Distributions pc_val : int - integer form of the pc address 11*2c2f96dcSApple OSS Distributions user_lib_info: [] of [] which hold start, end, binary name 12*2c2f96dcSApple OSS Distributions returns: 13*2c2f96dcSApple OSS Distributions str - Name of binary or "unknown" if not found. 14*2c2f96dcSApple OSS Distributions """ 15*2c2f96dcSApple OSS Distributions retval = "unknown" 16*2c2f96dcSApple OSS Distributions if not user_lib_info: 17*2c2f96dcSApple OSS Distributions return retval 18*2c2f96dcSApple OSS Distributions matches = [] 19*2c2f96dcSApple OSS Distributions for info in user_lib_info: 20*2c2f96dcSApple OSS Distributions if pc_val >= info[0] and pc_val <= info[1]: 21*2c2f96dcSApple OSS Distributions matches.append((pc_val - info[0], info[2])) 22*2c2f96dcSApple OSS Distributions matches.sort() 23*2c2f96dcSApple OSS Distributions if matches: 24*2c2f96dcSApple OSS Distributions retval = matches[0][1] 25*2c2f96dcSApple OSS Distributions return retval 26*2c2f96dcSApple OSS Distributions 27*2c2f96dcSApple OSS Distributionsdef ShowX86UserStack(thread, user_lib_info = None): 28*2c2f96dcSApple OSS Distributions """ Display user space stack frame and pc addresses. 29*2c2f96dcSApple OSS Distributions params: 30*2c2f96dcSApple OSS Distributions thread: obj referencing thread value 31*2c2f96dcSApple OSS Distributions returns: 32*2c2f96dcSApple OSS Distributions Nothing 33*2c2f96dcSApple OSS Distributions """ 34*2c2f96dcSApple OSS Distributions iss = Cast(thread.machine.iss, 'x86_saved_state_t *') 35*2c2f96dcSApple OSS Distributions abi = int(iss.flavor) 36*2c2f96dcSApple OSS Distributions user_ip = 0 37*2c2f96dcSApple OSS Distributions user_frame = 0 38*2c2f96dcSApple OSS Distributions user_abi_ret_offset = 0 39*2c2f96dcSApple OSS Distributions if abi == 0xf: 40*2c2f96dcSApple OSS Distributions debuglog("User process is 64 bit") 41*2c2f96dcSApple OSS Distributions user_ip = iss.uss.ss_64.isf.rip 42*2c2f96dcSApple OSS Distributions user_frame = iss.uss.ss_64.rbp 43*2c2f96dcSApple OSS Distributions user_abi_ret_offset = 8 44*2c2f96dcSApple OSS Distributions user_abi_type = "uint64_t" 45*2c2f96dcSApple OSS Distributions else: 46*2c2f96dcSApple OSS Distributions debuglog("user process is 32 bit") 47*2c2f96dcSApple OSS Distributions user_ip = iss.uss.ss_32.eip 48*2c2f96dcSApple OSS Distributions user_frame = iss.uss.ss_32.ebp 49*2c2f96dcSApple OSS Distributions user_abi_ret_offset = 4 50*2c2f96dcSApple OSS Distributions user_abi_type = "uint32_t" 51*2c2f96dcSApple OSS Distributions 52*2c2f96dcSApple OSS Distributions if user_ip == 0: 53*2c2f96dcSApple OSS Distributions print("This activation does not appear to have a valid user context.") 54*2c2f96dcSApple OSS Distributions return False 55*2c2f96dcSApple OSS Distributions 56*2c2f96dcSApple OSS Distributions cur_ip = user_ip 57*2c2f96dcSApple OSS Distributions cur_frame = user_frame 58*2c2f96dcSApple OSS Distributions debuglog("ip= 0x%x , fr = 0x%x " % (cur_ip, cur_frame)) 59*2c2f96dcSApple OSS Distributions 60*2c2f96dcSApple OSS Distributions frameformat = "{0:d} FP: 0x{1:x} PC: 0x{2:x}" 61*2c2f96dcSApple OSS Distributions if user_lib_info is not None: 62*2c2f96dcSApple OSS Distributions frameformat = "{0:d} {3: <30s} 0x{2:x}" 63*2c2f96dcSApple OSS Distributions print(frameformat.format(0, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))) 64*2c2f96dcSApple OSS Distributions 65*2c2f96dcSApple OSS Distributions print(kern.Symbolicate(cur_ip)) 66*2c2f96dcSApple OSS Distributions 67*2c2f96dcSApple OSS Distributions frameno = 0 68*2c2f96dcSApple OSS Distributions while True: 69*2c2f96dcSApple OSS Distributions frameno = frameno + 1 70*2c2f96dcSApple OSS Distributions frame = GetUserDataAsString(thread.t_tro.tro_task, unsigned(cur_frame), user_abi_ret_offset*2) 71*2c2f96dcSApple OSS Distributions cur_ip = _ExtractDataFromString(frame, user_abi_ret_offset, user_abi_type) 72*2c2f96dcSApple OSS Distributions cur_frame = _ExtractDataFromString(frame, 0, user_abi_type) 73*2c2f96dcSApple OSS Distributions if not cur_frame or cur_frame == 0x0000000800000008: 74*2c2f96dcSApple OSS Distributions break 75*2c2f96dcSApple OSS Distributions print(frameformat.format(frameno, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))) 76*2c2f96dcSApple OSS Distributions print(kern.Symbolicate(cur_ip)) 77*2c2f96dcSApple OSS Distributions return 78*2c2f96dcSApple OSS Distributions 79*2c2f96dcSApple OSS Distributionsdef _PrintARMUserStack(task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=None): 80*2c2f96dcSApple OSS Distributions cur_pc = kern.StripUserPAC(cur_pc) 81*2c2f96dcSApple OSS Distributions if cur_pc == 0: 82*2c2f96dcSApple OSS Distributions "No valid user context for this activation." 83*2c2f96dcSApple OSS Distributions return 84*2c2f96dcSApple OSS Distributions frameno = 0 85*2c2f96dcSApple OSS Distributions print(frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))) 86*2c2f96dcSApple OSS Distributions while True: 87*2c2f96dcSApple OSS Distributions frameno = frameno + 1 88*2c2f96dcSApple OSS Distributions frame = GetUserDataAsString(task, cur_fp, framesize) 89*2c2f96dcSApple OSS Distributions cur_fp = _ExtractDataFromString(frame, 0, frametype) 90*2c2f96dcSApple OSS Distributions cur_pc = _ExtractDataFromString(frame, (framesize // 2), frametype) 91*2c2f96dcSApple OSS Distributions cur_pc = kern.StripUserPAC(cur_pc) 92*2c2f96dcSApple OSS Distributions if not cur_fp: 93*2c2f96dcSApple OSS Distributions break 94*2c2f96dcSApple OSS Distributions print(frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))) 95*2c2f96dcSApple OSS Distributions 96*2c2f96dcSApple OSS Distributionsdef ShowARM64UserStack(thread, user_lib_info = None): 97*2c2f96dcSApple OSS Distributions SAVED_STATE_FLAVOR_ARM=20 98*2c2f96dcSApple OSS Distributions SAVED_STATE_FLAVOR_ARM64=21 99*2c2f96dcSApple OSS Distributions upcb_addr = kern.StripKernelPAC(thread.machine.upcb) 100*2c2f96dcSApple OSS Distributions upcb = kern.GetValueFromAddress(upcb_addr, 'arm_saved_state_t *') 101*2c2f96dcSApple OSS Distributions flavor = upcb.ash.flavor 102*2c2f96dcSApple OSS Distributions frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}" 103*2c2f96dcSApple OSS Distributions if flavor == SAVED_STATE_FLAVOR_ARM64: 104*2c2f96dcSApple OSS Distributions cur_pc = unsigned(upcb.uss.ss_64.pc) 105*2c2f96dcSApple OSS Distributions cur_fp = unsigned(upcb.uss.ss_64.fp) 106*2c2f96dcSApple OSS Distributions if user_lib_info is not None: 107*2c2f96dcSApple OSS Distributions frameformat = "{0:>2d} {3: <30s} 0x{2:x}" 108*2c2f96dcSApple OSS Distributions framesize = 16 109*2c2f96dcSApple OSS Distributions frametype = "uint64_t" 110*2c2f96dcSApple OSS Distributions elif flavor == SAVED_STATE_FLAVOR_ARM: 111*2c2f96dcSApple OSS Distributions cur_pc = unsigned(upcb.uss.ss_32.pc) 112*2c2f96dcSApple OSS Distributions cur_fp = unsigned(upcb.uss.ss_32.r[7]) 113*2c2f96dcSApple OSS Distributions if user_lib_info is not None: 114*2c2f96dcSApple OSS Distributions frameformat = "{0:>2d}: {3: <30s} 0x{2:x}" 115*2c2f96dcSApple OSS Distributions framesize = 8 116*2c2f96dcSApple OSS Distributions frametype = "uint32_t" 117*2c2f96dcSApple OSS Distributions else: 118*2c2f96dcSApple OSS Distributions raise RuntimeError("Thread {0} has an invalid flavor {1}".format(unsigned(thread), flavor)) 119*2c2f96dcSApple OSS Distributions 120*2c2f96dcSApple OSS Distributions _PrintARMUserStack(thread.t_tro.tro_task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info) 121*2c2f96dcSApple OSS Distributions 122*2c2f96dcSApple OSS Distributions 123*2c2f96dcSApple OSS Distributions@lldb_command('showthreaduserstack') 124*2c2f96dcSApple OSS Distributionsdef ShowThreadUserStack(cmd_args=None): 125*2c2f96dcSApple OSS Distributions """ Show user stack for a given thread. 126*2c2f96dcSApple OSS Distributions Syntax: (lldb) showthreaduserstack <thread_ptr> 127*2c2f96dcSApple OSS Distributions """ 128*2c2f96dcSApple OSS Distributions if not cmd_args: 129*2c2f96dcSApple OSS Distributions raise ArgumentError("Insufficient arguments") 130*2c2f96dcSApple OSS Distributions 131*2c2f96dcSApple OSS Distributions thread = kern.GetValueFromAddress(ArgumentStringToInt(cmd_args[0]), 'thread *') 132*2c2f96dcSApple OSS Distributions if kern.arch == "x86_64": 133*2c2f96dcSApple OSS Distributions ShowX86UserStack(thread) 134*2c2f96dcSApple OSS Distributions elif kern.arch.startswith("arm64"): 135*2c2f96dcSApple OSS Distributions ShowARM64UserStack(thread) 136*2c2f96dcSApple OSS Distributions return True 137*2c2f96dcSApple OSS Distributions 138*2c2f96dcSApple OSS Distributions@lldb_command('printuserdata','XO:') 139*2c2f96dcSApple OSS Distributionsdef PrintUserspaceData(cmd_args=None, cmd_options={}): 140*2c2f96dcSApple OSS Distributions """ Read userspace data for given task and print based on format provided. 141*2c2f96dcSApple OSS Distributions Syntax: (lldb) printuserdata <task_t> <uspace_address> <format_specifier> 142*2c2f96dcSApple OSS Distributions params: 143*2c2f96dcSApple OSS Distributions <task_t> : pointer to task 144*2c2f96dcSApple OSS Distributions <uspace_address> : address to user space memory 145*2c2f96dcSApple OSS Distributions <format_specifier> : String representation for processing the data and printing it. 146*2c2f96dcSApple OSS Distributions e.g Q -> unsigned long long, q -> long long, I -> unsigned int, i -> int 147*2c2f96dcSApple OSS Distributions 10i -> 10 ints, 20s -> 20 character string, s -> null terminated string 148*2c2f96dcSApple OSS Distributions See: https://docs.python.org/2/library/struct.html#format-characters 149*2c2f96dcSApple OSS Distributions options: 150*2c2f96dcSApple OSS Distributions -X : print all values in hex. 151*2c2f96dcSApple OSS Distributions -O <file path>: Save data to file 152*2c2f96dcSApple OSS Distributions """ 153*2c2f96dcSApple OSS Distributions 154*2c2f96dcSApple OSS Distributions if not cmd_args or len(cmd_args) < 3: 155*2c2f96dcSApple OSS Distributions raise ArgumentError("Insufficient arguments") 156*2c2f96dcSApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task *') 157*2c2f96dcSApple OSS Distributions uspace_addr = ArgumentStringToInt(cmd_args[1]) 158*2c2f96dcSApple OSS Distributions format_specifier_str = cmd_args[2] 159*2c2f96dcSApple OSS Distributions user_data_len = 0 160*2c2f96dcSApple OSS Distributions if format_specifier_str == "s": 161*2c2f96dcSApple OSS Distributions print("0x%x: " % uspace_addr + GetUserspaceString(task, uspace_addr)) 162*2c2f96dcSApple OSS Distributions return True 163*2c2f96dcSApple OSS Distributions 164*2c2f96dcSApple OSS Distributions try: 165*2c2f96dcSApple OSS Distributions user_data_len = struct.calcsize(format_specifier_str) 166*2c2f96dcSApple OSS Distributions except Exception as e: 167*2c2f96dcSApple OSS Distributions raise ArgumentError("Invalid format specifier provided.") 168*2c2f96dcSApple OSS Distributions 169*2c2f96dcSApple OSS Distributions user_data_string = GetUserDataAsString(task, uspace_addr, user_data_len) 170*2c2f96dcSApple OSS Distributions if not user_data_string: 171*2c2f96dcSApple OSS Distributions print("Could not read any data from userspace address.") 172*2c2f96dcSApple OSS Distributions return False 173*2c2f96dcSApple OSS Distributions if "-O" in cmd_options: 174*2c2f96dcSApple OSS Distributions fh = open(cmd_options["-O"],"w") 175*2c2f96dcSApple OSS Distributions fh.write(user_data_string) 176*2c2f96dcSApple OSS Distributions fh.close() 177*2c2f96dcSApple OSS Distributions print("Written %d bytes to %s." % (user_data_len, cmd_options['-O'])) 178*2c2f96dcSApple OSS Distributions return True 179*2c2f96dcSApple OSS Distributions upacked_data = struct.unpack(format_specifier_str, user_data_string) 180*2c2f96dcSApple OSS Distributions element_size = user_data_len // len(upacked_data) 181*2c2f96dcSApple OSS Distributions for i in range(len(upacked_data)): 182*2c2f96dcSApple OSS Distributions if "-X" in cmd_options: 183*2c2f96dcSApple OSS Distributions print("0x%x: " % (uspace_addr + i*element_size) + hex(upacked_data[i])) 184*2c2f96dcSApple OSS Distributions else: 185*2c2f96dcSApple OSS Distributions print("0x%x: " % (uspace_addr + i*element_size) + str(upacked_data[i])) 186*2c2f96dcSApple OSS Distributions 187*2c2f96dcSApple OSS Distributions return True 188*2c2f96dcSApple OSS Distributions 189*2c2f96dcSApple OSS Distributions@lldb_command('showtaskuserargs') 190*2c2f96dcSApple OSS Distributionsdef ShowTaskUserArgs(cmd_args=None, cmd_options={}): 191*2c2f96dcSApple OSS Distributions """ Read the process argv, env, and apple strings from the user stack 192*2c2f96dcSApple OSS Distributions Syntax: (lldb) showtaskuserargs <task_t> 193*2c2f96dcSApple OSS Distributions params: 194*2c2f96dcSApple OSS Distributions <task_t> : pointer to task 195*2c2f96dcSApple OSS Distributions """ 196*2c2f96dcSApple OSS Distributions if not cmd_args or len(cmd_args) != 1: 197*2c2f96dcSApple OSS Distributions raise ArgumentError("Insufficient arguments") 198*2c2f96dcSApple OSS Distributions 199*2c2f96dcSApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task *') 200*2c2f96dcSApple OSS Distributions proc = GetProcFromTask(task) 201*2c2f96dcSApple OSS Distributions if not proc: 202*2c2f96dcSApple OSS Distributions print("Task has no associated BSD process.") 203*2c2f96dcSApple OSS Distributions return False 204*2c2f96dcSApple OSS Distributions ptrsize = 8 if int(task.t_flags) & 0x1 else 4 205*2c2f96dcSApple OSS Distributions 206*2c2f96dcSApple OSS Distributions format_string = "Q" if ptrsize == 8 else "I" 207*2c2f96dcSApple OSS Distributions 208*2c2f96dcSApple OSS Distributions string_area_size = proc.p_argslen 209*2c2f96dcSApple OSS Distributions string_area_addr = proc.user_stack - string_area_size 210*2c2f96dcSApple OSS Distributions 211*2c2f96dcSApple OSS Distributions string_area = GetUserDataAsString(task, string_area_addr, string_area_size) 212*2c2f96dcSApple OSS Distributions if not string_area: 213*2c2f96dcSApple OSS Distributions print("Could not read any data from userspace address.") 214*2c2f96dcSApple OSS Distributions return False 215*2c2f96dcSApple OSS Distributions 216*2c2f96dcSApple OSS Distributions i = 0 217*2c2f96dcSApple OSS Distributions pos = string_area_addr - ptrsize 218*2c2f96dcSApple OSS Distributions 219*2c2f96dcSApple OSS Distributions for name in ["apple", "env", "argv"] : 220*2c2f96dcSApple OSS Distributions while True: 221*2c2f96dcSApple OSS Distributions if name == "argv" : 222*2c2f96dcSApple OSS Distributions if i == proc.p_argc: 223*2c2f96dcSApple OSS Distributions break 224*2c2f96dcSApple OSS Distributions i += 1 225*2c2f96dcSApple OSS Distributions 226*2c2f96dcSApple OSS Distributions pos -= ptrsize 227*2c2f96dcSApple OSS Distributions 228*2c2f96dcSApple OSS Distributions user_data_string = GetUserDataAsString(task, pos, ptrsize) 229*2c2f96dcSApple OSS Distributions ptr = struct.unpack(format_string, user_data_string)[0] 230*2c2f96dcSApple OSS Distributions 231*2c2f96dcSApple OSS Distributions if ptr == 0: 232*2c2f96dcSApple OSS Distributions break 233*2c2f96dcSApple OSS Distributions 234*2c2f96dcSApple OSS Distributions if string_area_addr <= ptr and ptr < string_area_addr+string_area_size : 235*2c2f96dcSApple OSS Distributions string_offset = ptr - string_area_addr 236*2c2f96dcSApple OSS Distributions string = string_area[string_offset:].decode() 237*2c2f96dcSApple OSS Distributions else: 238*2c2f96dcSApple OSS Distributions string = GetUserspaceString(task, ptr) 239*2c2f96dcSApple OSS Distributions 240*2c2f96dcSApple OSS Distributions print(name + "[]: " + string + '\n') 241*2c2f96dcSApple OSS Distributions 242*2c2f96dcSApple OSS Distributions return True 243*2c2f96dcSApple OSS Distributions 244*2c2f96dcSApple OSS Distributionsdef ShowTaskUserStacks(task): 245*2c2f96dcSApple OSS Distributions #print GetTaskSummary.header + " " + GetProcSummary.header 246*2c2f96dcSApple OSS Distributions pval = GetProcFromTask(task) 247*2c2f96dcSApple OSS Distributions #print GetTaskSummary(task) + " " + GetProcSummary(pval) + "\n \n" 248*2c2f96dcSApple OSS Distributions crash_report_format_string = """\ 249*2c2f96dcSApple OSS DistributionsProcess: {pname:s} [{pid:d}] 250*2c2f96dcSApple OSS DistributionsPath: {path: <50s} 251*2c2f96dcSApple OSS DistributionsIdentifier: {pname: <30s} 252*2c2f96dcSApple OSS DistributionsVersion: ??? (???) 253*2c2f96dcSApple OSS DistributionsCode Type: {parch: <20s} 254*2c2f96dcSApple OSS DistributionsParent Process: {ppname:s} [{ppid:d}] 255*2c2f96dcSApple OSS Distributions 256*2c2f96dcSApple OSS DistributionsDate/Time: {timest:s}.000 -0800 257*2c2f96dcSApple OSS DistributionsOS Version: {osversion: <20s} 258*2c2f96dcSApple OSS DistributionsReport Version: 8 259*2c2f96dcSApple OSS Distributions 260*2c2f96dcSApple OSS DistributionsException Type: n/a 261*2c2f96dcSApple OSS DistributionsException Codes: n/a 262*2c2f96dcSApple OSS DistributionsCrashed Thread: 0 263*2c2f96dcSApple OSS Distributions 264*2c2f96dcSApple OSS DistributionsApplication Specific Information: 265*2c2f96dcSApple OSS DistributionsSynthetic crash log generated from Kernel userstacks 266*2c2f96dcSApple OSS Distributions 267*2c2f96dcSApple OSS Distributions""" 268*2c2f96dcSApple OSS Distributions user_lib_rex = re.compile("([0-9a-fx]+)\s-\s([0-9a-fx]+)\s+(.*?)\s", re.IGNORECASE|re.MULTILINE) 269*2c2f96dcSApple OSS Distributions from datetime import datetime 270*2c2f96dcSApple OSS Distributions if pval: 271*2c2f96dcSApple OSS Distributions ts = datetime.fromtimestamp(int(pval.p_start.tv_sec)) 272*2c2f96dcSApple OSS Distributions date_string = ts.strftime('%Y-%m-%d %H:%M:%S') 273*2c2f96dcSApple OSS Distributions else: 274*2c2f96dcSApple OSS Distributions date_string = "none" 275*2c2f96dcSApple OSS Distributions is_64 = True 276*2c2f96dcSApple OSS Distributions if pval and (pval.p_flag & 0x4) == 0 : 277*2c2f96dcSApple OSS Distributions is_64 = False 278*2c2f96dcSApple OSS Distributions 279*2c2f96dcSApple OSS Distributions parch_s = "" 280*2c2f96dcSApple OSS Distributions if kern.arch == "x86_64" or kern.arch == "i386": 281*2c2f96dcSApple OSS Distributions osversion = "Mac OS X 10.8" 282*2c2f96dcSApple OSS Distributions parch_s = "I386 (32 bit)" 283*2c2f96dcSApple OSS Distributions if is_64: 284*2c2f96dcSApple OSS Distributions parch_s = "X86-64 (Native)" 285*2c2f96dcSApple OSS Distributions else: 286*2c2f96dcSApple OSS Distributions parch_s = kern.arch 287*2c2f96dcSApple OSS Distributions osversion = "iOS" 288*2c2f96dcSApple OSS Distributions osversion += " ({:s})".format(kern.globals.osversion) 289*2c2f96dcSApple OSS Distributions if pval: 290*2c2f96dcSApple OSS Distributions pid = GetProcPID(pval) 291*2c2f96dcSApple OSS Distributions pname = GetProcName(pval) 292*2c2f96dcSApple OSS Distributions path = GetProcName(pval) 293*2c2f96dcSApple OSS Distributions ppid = pval.p_ppid 294*2c2f96dcSApple OSS Distributions else: 295*2c2f96dcSApple OSS Distributions pid = 0 296*2c2f96dcSApple OSS Distributions pname = "unknown" 297*2c2f96dcSApple OSS Distributions path = "unknown" 298*2c2f96dcSApple OSS Distributions ppid = 0 299*2c2f96dcSApple OSS Distributions 300*2c2f96dcSApple OSS Distributions print(crash_report_format_string.format(pid = pid, 301*2c2f96dcSApple OSS Distributions pname = pname, 302*2c2f96dcSApple OSS Distributions path = path, 303*2c2f96dcSApple OSS Distributions ppid = ppid, 304*2c2f96dcSApple OSS Distributions ppname = GetProcNameForPid(ppid), 305*2c2f96dcSApple OSS Distributions timest = date_string, 306*2c2f96dcSApple OSS Distributions parch = parch_s, 307*2c2f96dcSApple OSS Distributions osversion = osversion 308*2c2f96dcSApple OSS Distributions )) 309*2c2f96dcSApple OSS Distributions print("Binary Images:") 310*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries([hex(task)]) 311*2c2f96dcSApple OSS Distributions usertask_lib_info = [] # will host [startaddr, endaddr, lib_name] entries 312*2c2f96dcSApple OSS Distributions for entry in ShowTaskUserLibraries.found_images: 313*2c2f96dcSApple OSS Distributions #print "processing line %s" % line 314*2c2f96dcSApple OSS Distributions arr = user_lib_rex.findall(entry[3]) 315*2c2f96dcSApple OSS Distributions #print "%r" % arr 316*2c2f96dcSApple OSS Distributions if len(arr) == 0 : 317*2c2f96dcSApple OSS Distributions continue 318*2c2f96dcSApple OSS Distributions usertask_lib_info.append([int(arr[0][0],16), int(arr[0][1],16), str(arr[0][2]).strip()]) 319*2c2f96dcSApple OSS Distributions 320*2c2f96dcSApple OSS Distributions printthread_user_stack_ptr = ShowX86UserStack 321*2c2f96dcSApple OSS Distributions if kern.arch.startswith("arm64"): 322*2c2f96dcSApple OSS Distributions printthread_user_stack_ptr = ShowARM64UserStack 323*2c2f96dcSApple OSS Distributions 324*2c2f96dcSApple OSS Distributions counter = 0 325*2c2f96dcSApple OSS Distributions for thval in IterateQueue(task.threads, 'thread *', 'task_threads'): 326*2c2f96dcSApple OSS Distributions print("\nThread {0:d} name:0x{1:x}\nThread {0:d}:".format(counter, thval)) 327*2c2f96dcSApple OSS Distributions counter += 1 328*2c2f96dcSApple OSS Distributions try: 329*2c2f96dcSApple OSS Distributions printthread_user_stack_ptr(thval, usertask_lib_info) 330*2c2f96dcSApple OSS Distributions except Exception as exc_err: 331*2c2f96dcSApple OSS Distributions print("Failed to show user stack for thread 0x{0:x}".format(thval)) 332*2c2f96dcSApple OSS Distributions if config['debug']: 333*2c2f96dcSApple OSS Distributions raise exc_err 334*2c2f96dcSApple OSS Distributions else: 335*2c2f96dcSApple OSS Distributions print("Enable debugging ('(lldb) xnudebug debug') to see detailed trace.") 336*2c2f96dcSApple OSS Distributions return 337*2c2f96dcSApple OSS Distributions 338*2c2f96dcSApple OSS Distributions@lldb_command('showtaskuserstacks', "P:F:") 339*2c2f96dcSApple OSS Distributionsdef ShowTaskUserStacksCmdHelper(cmd_args=None, cmd_options={}): 340*2c2f96dcSApple OSS Distributions """ Print out the user stack for each thread in a task, followed by the user libraries. 341*2c2f96dcSApple OSS Distributions Syntax: (lldb) showtaskuserstacks <task_t> 342*2c2f96dcSApple OSS Distributions or: (lldb) showtaskuserstacks -P <pid> 343*2c2f96dcSApple OSS Distributions or: (lldb) showtaskuserstacks -F <task_name> 344*2c2f96dcSApple OSS Distributions The format is compatible with CrashTracer. You can also use the speedtracer plugin as follows 345*2c2f96dcSApple OSS Distributions (lldb) showtaskuserstacks <task_t> -p speedtracer 346*2c2f96dcSApple OSS Distributions 347*2c2f96dcSApple OSS Distributions Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures 348*2c2f96dcSApple OSS Distributions and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate 349*2c2f96dcSApple OSS Distributions """ 350*2c2f96dcSApple OSS Distributions task_list = [] 351*2c2f96dcSApple OSS Distributions if "-F" in cmd_options: 352*2c2f96dcSApple OSS Distributions task_list = FindTasksByName(cmd_options["-F"]) 353*2c2f96dcSApple OSS Distributions elif "-P" in cmd_options: 354*2c2f96dcSApple OSS Distributions pidval = ArgumentStringToInt(cmd_options["-P"]) 355*2c2f96dcSApple OSS Distributions for t in kern.tasks: 356*2c2f96dcSApple OSS Distributions pval = GetProcFromTask(t) 357*2c2f96dcSApple OSS Distributions if pval and GetProcPID(pval) == pidval: 358*2c2f96dcSApple OSS Distributions task_list.append(t) 359*2c2f96dcSApple OSS Distributions break 360*2c2f96dcSApple OSS Distributions elif cmd_args: 361*2c2f96dcSApple OSS Distributions t = kern.GetValueFromAddress(cmd_args[0], 'task *') 362*2c2f96dcSApple OSS Distributions task_list.append(t) 363*2c2f96dcSApple OSS Distributions else: 364*2c2f96dcSApple OSS Distributions raise ArgumentError("Insufficient arguments") 365*2c2f96dcSApple OSS Distributions 366*2c2f96dcSApple OSS Distributions for task in task_list: 367*2c2f96dcSApple OSS Distributions ShowTaskUserStacks(task) 368*2c2f96dcSApple OSS Distributions 369*2c2f96dcSApple OSS Distributionsdef GetUserDataAsString(task, addr, size): 370*2c2f96dcSApple OSS Distributions """ Get data from task's address space as a string of bytes 371*2c2f96dcSApple OSS Distributions params: 372*2c2f96dcSApple OSS Distributions task: task object from which to extract information 373*2c2f96dcSApple OSS Distributions addr: int - start address to get data from. 374*2c2f96dcSApple OSS Distributions size: int - no of bytes to read. 375*2c2f96dcSApple OSS Distributions returns: 376*2c2f96dcSApple OSS Distributions data - a stream of bytes. Empty bytes() if read fails. 377*2c2f96dcSApple OSS Distributions """ 378*2c2f96dcSApple OSS Distributions err = lldb.SBError() 379*2c2f96dcSApple OSS Distributions if GetConnectionProtocol() == "kdp": 380*2c2f96dcSApple OSS Distributions kdp_pmap_addr = unsigned(addressof(kern.globals.kdp_pmap)) 381*2c2f96dcSApple OSS Distributions if not WriteInt64ToMemoryAddress(unsigned(task.map.pmap), kdp_pmap_addr): 382*2c2f96dcSApple OSS Distributions debuglog("Failed to write in kdp_pmap from GetUserDataAsString.") 383*2c2f96dcSApple OSS Distributions return b"" 384*2c2f96dcSApple OSS Distributions content = LazyTarget.GetProcess().ReadMemory(addr, size, err) 385*2c2f96dcSApple OSS Distributions if not err.Success(): 386*2c2f96dcSApple OSS Distributions debuglog("Failed to read process memory. Error: " + err.description) 387*2c2f96dcSApple OSS Distributions return b"" 388*2c2f96dcSApple OSS Distributions if not WriteInt64ToMemoryAddress(0, kdp_pmap_addr): 389*2c2f96dcSApple OSS Distributions debuglog("Failed to reset in kdp_pmap from GetUserDataAsString.") 390*2c2f96dcSApple OSS Distributions return b"" 391*2c2f96dcSApple OSS Distributions elif (kern.arch == 'x86_64' or kern.arch.startswith('arm')) and (int(size) < (2 * kern.globals.page_size)): 392*2c2f96dcSApple OSS Distributions # Without the benefit of a KDP stub on the target, try to 393*2c2f96dcSApple OSS Distributions # find the user task's physical mapping and memcpy the data. 394*2c2f96dcSApple OSS Distributions # If it straddles a page boundary, copy in two passes 395*2c2f96dcSApple OSS Distributions range1_addr = int(addr) 396*2c2f96dcSApple OSS Distributions range1_size = int(size) 397*2c2f96dcSApple OSS Distributions if kern.StraddlesPage(range1_addr, range1_size): 398*2c2f96dcSApple OSS Distributions range2_addr = int(kern.TruncPage(range1_addr + range1_size)) 399*2c2f96dcSApple OSS Distributions range2_size = int(range1_addr + range1_size - range2_addr) 400*2c2f96dcSApple OSS Distributions range1_size = int(range2_addr - range1_addr) 401*2c2f96dcSApple OSS Distributions else: 402*2c2f96dcSApple OSS Distributions range2_addr = 0 403*2c2f96dcSApple OSS Distributions range2_size = 0 404*2c2f96dcSApple OSS Distributions range2_in_kva = 0 405*2c2f96dcSApple OSS Distributions 406*2c2f96dcSApple OSS Distributions paddr_range1 = PmapWalk(task.map.pmap, range1_addr, vSILENT) 407*2c2f96dcSApple OSS Distributions if not paddr_range1: 408*2c2f96dcSApple OSS Distributions debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr)) 409*2c2f96dcSApple OSS Distributions return b"" 410*2c2f96dcSApple OSS Distributions 411*2c2f96dcSApple OSS Distributions range1_in_kva = kern.PhysToKernelVirt(paddr_range1) 412*2c2f96dcSApple OSS Distributions content = LazyTarget.GetProcess().ReadMemory(range1_in_kva, range1_size, err) 413*2c2f96dcSApple OSS Distributions if not err.Success(): 414*2c2f96dcSApple OSS Distributions raise RuntimeError("Failed to read process memory. Error: " + err.description) 415*2c2f96dcSApple OSS Distributions 416*2c2f96dcSApple OSS Distributions if range2_addr: 417*2c2f96dcSApple OSS Distributions paddr_range2 = PmapWalk(task.map.pmap, range2_addr, vSILENT) 418*2c2f96dcSApple OSS Distributions if not paddr_range2: 419*2c2f96dcSApple OSS Distributions debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr)) 420*2c2f96dcSApple OSS Distributions return b"" 421*2c2f96dcSApple OSS Distributions range2_in_kva = kern.PhysToKernelVirt(paddr_range2) 422*2c2f96dcSApple OSS Distributions content += LazyTarget.GetProcess().ReadMemory(range2_in_kva, range2_size, err) 423*2c2f96dcSApple OSS Distributions if not err.Success(): 424*2c2f96dcSApple OSS Distributions raise RuntimeError("Failed to read process memory. Error: " + err.description) 425*2c2f96dcSApple OSS Distributions else: 426*2c2f96dcSApple OSS Distributions raise NotImplementedError("GetUserDataAsString does not support this configuration") 427*2c2f96dcSApple OSS Distributions 428*2c2f96dcSApple OSS Distributions return content 429*2c2f96dcSApple OSS Distributions 430*2c2f96dcSApple OSS Distributionsdef _ExtractDataFromString(strdata, offset, data_type, length=0): 431*2c2f96dcSApple OSS Distributions """ Extract specific data from string buffer 432*2c2f96dcSApple OSS Distributions params: 433*2c2f96dcSApple OSS Distributions strdata: str - string data give from GetUserDataAsString 434*2c2f96dcSApple OSS Distributions offset: int - 0 based offset into the data. 435*2c2f96dcSApple OSS Distributions data_type: str - defines what type to be read as. Supported values are: 436*2c2f96dcSApple OSS Distributions 'uint64_t', 'uint32_t', 'string' 437*2c2f96dcSApple OSS Distributions length: int - used when data_type=='string' 438*2c2f96dcSApple OSS Distributions returns 439*2c2f96dcSApple OSS Distributions None - if extraction failed. 440*2c2f96dcSApple OSS Distributions obj - based on what is requested in data_type 441*2c2f96dcSApple OSS Distributions """ 442*2c2f96dcSApple OSS Distributions unpack_str = "s" 443*2c2f96dcSApple OSS Distributions if data_type == 'uint64_t': 444*2c2f96dcSApple OSS Distributions length = 8 445*2c2f96dcSApple OSS Distributions unpack_str = "Q" 446*2c2f96dcSApple OSS Distributions elif data_type == "uint32_t": 447*2c2f96dcSApple OSS Distributions length = 4 448*2c2f96dcSApple OSS Distributions unpack_str = "I" 449*2c2f96dcSApple OSS Distributions else: 450*2c2f96dcSApple OSS Distributions unpack_str= "%ds" % length 451*2c2f96dcSApple OSS Distributions 452*2c2f96dcSApple OSS Distributions data_len = len(strdata) 453*2c2f96dcSApple OSS Distributions if offset > data_len or (offset + length) > data_len or offset < 0: 454*2c2f96dcSApple OSS Distributions debuglog("Invalid arguments to _ExtractDataFromString.") 455*2c2f96dcSApple OSS Distributions return 0 456*2c2f96dcSApple OSS Distributions 457*2c2f96dcSApple OSS Distributions data = struct.unpack(unpack_str, strdata[offset:(offset + length)])[0] 458*2c2f96dcSApple OSS Distributions if data_type == 'string': 459*2c2f96dcSApple OSS Distributions return data.decode() 460*2c2f96dcSApple OSS Distributions 461*2c2f96dcSApple OSS Distributions return data 462*2c2f96dcSApple OSS Distributions 463*2c2f96dcSApple OSS Distributionsdef GetUserspaceString(task, string_address): 464*2c2f96dcSApple OSS Distributions """ Maps 32 bytes at a time and packs as string 465*2c2f96dcSApple OSS Distributions params: 466*2c2f96dcSApple OSS Distributions task: obj - referencing task to read data from 467*2c2f96dcSApple OSS Distributions string_address: int - address where the image path is stored 468*2c2f96dcSApple OSS Distributions returns: 469*2c2f96dcSApple OSS Distributions str - string path of the file. "" if failed to read. 470*2c2f96dcSApple OSS Distributions """ 471*2c2f96dcSApple OSS Distributions retval = [] 472*2c2f96dcSApple OSS Distributions while string_address > 0: 473*2c2f96dcSApple OSS Distributions str_data = GetUserDataAsString(task, string_address, 32) 474*2c2f96dcSApple OSS Distributions if not str_data: 475*2c2f96dcSApple OSS Distributions break 476*2c2f96dcSApple OSS Distributions str_data = str_data.split(b"\x00", 1)[0] 477*2c2f96dcSApple OSS Distributions retval.append(str_data) 478*2c2f96dcSApple OSS Distributions if len(str_data) < 32: 479*2c2f96dcSApple OSS Distributions break # short read or found NUL byte 480*2c2f96dcSApple OSS Distributions string_address += 32 481*2c2f96dcSApple OSS Distributions return b"".join(retval).decode() 482*2c2f96dcSApple OSS Distributions 483*2c2f96dcSApple OSS Distributionsdef GetImageInfo(task, mh_image_address, mh_path_address, approx_end_address=None): 484*2c2f96dcSApple OSS Distributions """ Print user library informaiton. 485*2c2f96dcSApple OSS Distributions params: 486*2c2f96dcSApple OSS Distributions task : obj referencing the task for which Image info printed 487*2c2f96dcSApple OSS Distributions mh_image_address : int - address which has image info 488*2c2f96dcSApple OSS Distributions mh_path_address : int - address which holds path name string 489*2c2f96dcSApple OSS Distributions approx_end_address: int - address which lldbmacros think is end address. 490*2c2f96dcSApple OSS Distributions returns: 491*2c2f96dcSApple OSS Distributions str - string representing image info. "" if failure to read data. 492*2c2f96dcSApple OSS Distributions """ 493*2c2f96dcSApple OSS Distributions if approx_end_address: 494*2c2f96dcSApple OSS Distributions image_end_load_address = int(approx_end_address) -1 495*2c2f96dcSApple OSS Distributions else: 496*2c2f96dcSApple OSS Distributions image_end_load_address = int(mh_image_address) + 0xffffffff 497*2c2f96dcSApple OSS Distributions 498*2c2f96dcSApple OSS Distributions print_format = "0x{0:x} - 0x{1:x} {2: <50s} (??? - ???) <{3: <36s}> {4: <50s}" 499*2c2f96dcSApple OSS Distributions # 32 bytes enough for mach_header/mach_header_64 500*2c2f96dcSApple OSS Distributions mh_data = GetUserDataAsString(task, mh_image_address, 32) 501*2c2f96dcSApple OSS Distributions if len(mh_data) == 0: 502*2c2f96dcSApple OSS Distributions debuglog("unable to get userdata for task 0x{:x} img_addr 0x{:x} path_address 0x{:x}".format( 503*2c2f96dcSApple OSS Distributions task, mh_image_address, mh_path_address)) 504*2c2f96dcSApple OSS Distributions return "" 505*2c2f96dcSApple OSS Distributions mh_magic = _ExtractDataFromString(mh_data, (4 * 0), "uint32_t") 506*2c2f96dcSApple OSS Distributions mh_cputype = _ExtractDataFromString(mh_data,(4 * 1), "uint32_t") 507*2c2f96dcSApple OSS Distributions mh_cpusubtype = _ExtractDataFromString(mh_data,(4 * 2), "uint32_t") 508*2c2f96dcSApple OSS Distributions mh_filetype = _ExtractDataFromString(mh_data,(4 * 3), "uint32_t") 509*2c2f96dcSApple OSS Distributions mh_ncmds = _ExtractDataFromString(mh_data,(4 * 4), "uint32_t") 510*2c2f96dcSApple OSS Distributions mh_sizeofcmds = _ExtractDataFromString(mh_data,(4 * 5), "uint32_t") 511*2c2f96dcSApple OSS Distributions mh_flags = _ExtractDataFromString(mh_data,(4 * 6), "uint32_t") 512*2c2f96dcSApple OSS Distributions 513*2c2f96dcSApple OSS Distributions if mh_magic == 0xfeedfacf: 514*2c2f96dcSApple OSS Distributions mh_64 = True 515*2c2f96dcSApple OSS Distributions lc_address = mh_image_address + 32 516*2c2f96dcSApple OSS Distributions else: 517*2c2f96dcSApple OSS Distributions mh_64 = False 518*2c2f96dcSApple OSS Distributions lc_address = mh_image_address + 28 519*2c2f96dcSApple OSS Distributions 520*2c2f96dcSApple OSS Distributions lc_idx = 0 521*2c2f96dcSApple OSS Distributions uuid_data = 0 522*2c2f96dcSApple OSS Distributions found_uuid_data = False 523*2c2f96dcSApple OSS Distributions retval = None 524*2c2f96dcSApple OSS Distributions while lc_idx < mh_ncmds: 525*2c2f96dcSApple OSS Distributions # 24 bytes is the size of uuid_command 526*2c2f96dcSApple OSS Distributions lcmd_data = GetUserDataAsString(task, lc_address, 24) 527*2c2f96dcSApple OSS Distributions lc_cmd = _ExtractDataFromString(lcmd_data, 4 * 0, "uint32_t") 528*2c2f96dcSApple OSS Distributions lc_cmd_size = _ExtractDataFromString(lcmd_data, 4 * 1, "uint32_t") 529*2c2f96dcSApple OSS Distributions lc_data = _ExtractDataFromString(lcmd_data, 4*2, "string", 16) 530*2c2f96dcSApple OSS Distributions 531*2c2f96dcSApple OSS Distributions uuid_out_string = "" 532*2c2f96dcSApple OSS Distributions path_out_string = "" 533*2c2f96dcSApple OSS Distributions 534*2c2f96dcSApple OSS Distributions if lc_cmd == 0x1b: 535*2c2f96dcSApple OSS Distributions # need to print the uuid now. 536*2c2f96dcSApple OSS Distributions uuid_data = bytes(lc_data) 537*2c2f96dcSApple OSS Distributions found_uuid_data = True 538*2c2f96dcSApple OSS Distributions uuid_out_string = "{a[0]:02X}{a[1]:02X}{a[2]:02X}{a[3]:02X}-{a[4]:02X}{a[5]:02X}-{a[6]:02X}{a[7]:02X}-{a[8]:02X}{a[9]:02X}-{a[10]:02X}{a[11]:02X}{a[12]:02X}{a[13]:02X}{a[14]:02X}{a[15]:02X}".format(a=uuid_data) 539*2c2f96dcSApple OSS Distributions #also print image path 540*2c2f96dcSApple OSS Distributions path_out_string = GetUserspaceString(task, mh_path_address) 541*2c2f96dcSApple OSS Distributions path_base_name = path_out_string.split("/")[-1] 542*2c2f96dcSApple OSS Distributions retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string) 543*2c2f96dcSApple OSS Distributions elif lc_cmd == 0xe: 544*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.exec_load_path = lc_address + _ExtractDataFromString(lcmd_data, 4*2, "uint32_t") 545*2c2f96dcSApple OSS Distributions debuglog("Found load command to be 0xe for address %s" % hex(ShowTaskUserLibraries.exec_load_path)) 546*2c2f96dcSApple OSS Distributions lc_address = lc_address + lc_cmd_size 547*2c2f96dcSApple OSS Distributions lc_idx += 1 548*2c2f96dcSApple OSS Distributions 549*2c2f96dcSApple OSS Distributions if not found_uuid_data: 550*2c2f96dcSApple OSS Distributions path_out_string = GetUserspaceString(task, mh_path_address) 551*2c2f96dcSApple OSS Distributions path_base_name = path_out_string.split("/")[-1] 552*2c2f96dcSApple OSS Distributions uuid_out_string = "" 553*2c2f96dcSApple OSS Distributions 554*2c2f96dcSApple OSS Distributions retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string) 555*2c2f96dcSApple OSS Distributions return retval 556*2c2f96dcSApple OSS Distributions 557*2c2f96dcSApple OSS Distributions@static_var("found_images", []) # holds entries of format (startaddr, endaddr, image_path_addr, infostring) 558*2c2f96dcSApple OSS Distributions@static_var("exec_load_path", 0) 559*2c2f96dcSApple OSS Distributions@lldb_command("showtaskuserlibraries") 560*2c2f96dcSApple OSS Distributionsdef ShowTaskUserLibraries(cmd_args=None): 561*2c2f96dcSApple OSS Distributions """ Show binary images known by dyld in target task 562*2c2f96dcSApple OSS Distributions For a given user task, inspect the dyld shared library state and print information about all Mach-O images. 563*2c2f96dcSApple OSS Distributions Syntax: (lldb)showtaskuserlibraries <task_t> 564*2c2f96dcSApple OSS Distributions Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures 565*2c2f96dcSApple OSS Distributions and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate 566*2c2f96dcSApple OSS Distributions """ 567*2c2f96dcSApple OSS Distributions if not cmd_args: 568*2c2f96dcSApple OSS Distributions raise ArgumentError("Insufficient arguments") 569*2c2f96dcSApple OSS Distributions 570*2c2f96dcSApple OSS Distributions #reset the found_images array 571*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.found_images = [] 572*2c2f96dcSApple OSS Distributions 573*2c2f96dcSApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task_t') 574*2c2f96dcSApple OSS Distributions is_task_64 = int(task.t_flags) & 0x1 575*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address = unsigned(task.all_image_info_addr) 576*2c2f96dcSApple OSS Distributions debuglog("dyld_all_image_infos_address = %s" % hex(dyld_all_image_infos_address)) 577*2c2f96dcSApple OSS Distributions 578*2c2f96dcSApple OSS Distributions cur_data_offset = 0 579*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_address == 0: 580*2c2f96dcSApple OSS Distributions print("No dyld shared library information available for task") 581*2c2f96dcSApple OSS Distributions return False 582*2c2f96dcSApple OSS Distributions 583*2c2f96dcSApple OSS Distributions debuglog("Extracting version information.") 584*2c2f96dcSApple OSS Distributions vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112) 585*2c2f96dcSApple OSS Distributions version = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t") 586*2c2f96dcSApple OSS Distributions cur_data_offset += 4 587*2c2f96dcSApple OSS Distributions if version > 14: 588*2c2f96dcSApple OSS Distributions print("Unknown dyld all_image_infos version number %d" % version) 589*2c2f96dcSApple OSS Distributions image_info_count = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t") 590*2c2f96dcSApple OSS Distributions debuglog("version = %d count = %d is_task_64 = %s" % (version, image_info_count, repr(is_task_64))) 591*2c2f96dcSApple OSS Distributions 592*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.exec_load_path = 0 593*2c2f96dcSApple OSS Distributions if is_task_64: 594*2c2f96dcSApple OSS Distributions image_info_size = 24 595*2c2f96dcSApple OSS Distributions image_info_array_address = _ExtractDataFromString(vers_info_data, 8, "uint64_t") 596*2c2f96dcSApple OSS Distributions dyld_load_address = _ExtractDataFromString(vers_info_data, 8*4, "uint64_t") 597*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 8*13, "uint64_t") 598*2c2f96dcSApple OSS Distributions else: 599*2c2f96dcSApple OSS Distributions image_info_size = 12 600*2c2f96dcSApple OSS Distributions image_info_array_address = _ExtractDataFromString(vers_info_data, 4*2, "uint32_t") 601*2c2f96dcSApple OSS Distributions dyld_load_address = _ExtractDataFromString(vers_info_data, 4*5, "uint32_t") 602*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 4*14, "uint32_t") 603*2c2f96dcSApple OSS Distributions # Account for ASLR slide before dyld can fix the structure 604*2c2f96dcSApple OSS Distributions dyld_load_address = dyld_load_address + (dyld_all_image_infos_address - dyld_all_image_infos_address_from_struct) 605*2c2f96dcSApple OSS Distributions 606*2c2f96dcSApple OSS Distributions i = 0 607*2c2f96dcSApple OSS Distributions image_info_list = [] 608*2c2f96dcSApple OSS Distributions while i < image_info_count: 609*2c2f96dcSApple OSS Distributions image_info_address = image_info_array_address + i * image_info_size 610*2c2f96dcSApple OSS Distributions debuglog("i = %d, image_info_address = %s, image_info_size = %d" % (i, hex(image_info_address), image_info_size)) 611*2c2f96dcSApple OSS Distributions n_im_info_addr = None 612*2c2f96dcSApple OSS Distributions img_data = "" 613*2c2f96dcSApple OSS Distributions try: 614*2c2f96dcSApple OSS Distributions img_data = GetUserDataAsString(task, image_info_address, image_info_size) 615*2c2f96dcSApple OSS Distributions except Exception as e: 616*2c2f96dcSApple OSS Distributions debuglog("Failed to read user data for task 0x{:x} addr 0x{:x}, exception {:s}".format(task, image_info_address, str(e))) 617*2c2f96dcSApple OSS Distributions pass 618*2c2f96dcSApple OSS Distributions 619*2c2f96dcSApple OSS Distributions if is_task_64: 620*2c2f96dcSApple OSS Distributions image_info_addr = _ExtractDataFromString(img_data, 0, "uint64_t") 621*2c2f96dcSApple OSS Distributions image_info_path = _ExtractDataFromString(img_data, 8, "uint64_t") 622*2c2f96dcSApple OSS Distributions else: 623*2c2f96dcSApple OSS Distributions image_info_addr = _ExtractDataFromString(img_data, 0, "uint32_t") 624*2c2f96dcSApple OSS Distributions image_info_path = _ExtractDataFromString(img_data, 4, "uint32_t") 625*2c2f96dcSApple OSS Distributions 626*2c2f96dcSApple OSS Distributions if image_info_addr : 627*2c2f96dcSApple OSS Distributions debuglog("Found image: image_info_addr = %s, image_info_path= %s" % (hex(image_info_addr), hex(image_info_path))) 628*2c2f96dcSApple OSS Distributions image_info_list.append((image_info_addr, image_info_path)) 629*2c2f96dcSApple OSS Distributions i += 1 630*2c2f96dcSApple OSS Distributions 631*2c2f96dcSApple OSS Distributions image_info_list.sort() 632*2c2f96dcSApple OSS Distributions num_images_found = len(image_info_list) 633*2c2f96dcSApple OSS Distributions 634*2c2f96dcSApple OSS Distributions for ii in range(num_images_found): 635*2c2f96dcSApple OSS Distributions n_im_info_addr = dyld_load_address 636*2c2f96dcSApple OSS Distributions if ii + 1 < num_images_found: 637*2c2f96dcSApple OSS Distributions n_im_info_addr = image_info_list[ii+1][0] 638*2c2f96dcSApple OSS Distributions 639*2c2f96dcSApple OSS Distributions image_info_addr = image_info_list[ii][0] 640*2c2f96dcSApple OSS Distributions image_info_path = image_info_list[ii][1] 641*2c2f96dcSApple OSS Distributions try: 642*2c2f96dcSApple OSS Distributions image_print_s = GetImageInfo(task, image_info_addr, image_info_path, approx_end_address=n_im_info_addr) 643*2c2f96dcSApple OSS Distributions if len(image_print_s) > 0: 644*2c2f96dcSApple OSS Distributions print(image_print_s) 645*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.found_images.append((image_info_addr, n_im_info_addr, image_info_path, image_print_s)) 646*2c2f96dcSApple OSS Distributions else: 647*2c2f96dcSApple OSS Distributions debuglog("Failed to print image info for task 0x{:x} image_info 0x{:x}".format(task, image_info_addr)) 648*2c2f96dcSApple OSS Distributions except Exception as e: 649*2c2f96dcSApple OSS Distributions if config['debug']: 650*2c2f96dcSApple OSS Distributions raise e 651*2c2f96dcSApple OSS Distributions 652*2c2f96dcSApple OSS Distributions # load_path might get set when the main executable is processed. 653*2c2f96dcSApple OSS Distributions if ShowTaskUserLibraries.exec_load_path != 0: 654*2c2f96dcSApple OSS Distributions debuglog("main executable load_path is set.") 655*2c2f96dcSApple OSS Distributions image_print_s = GetImageInfo(task, dyld_load_address, ShowTaskUserLibraries.exec_load_path) 656*2c2f96dcSApple OSS Distributions if len(image_print_s) > 0: 657*2c2f96dcSApple OSS Distributions print(image_print_s) 658*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.found_images.append((dyld_load_address, dyld_load_address + 0xffffffff, 659*2c2f96dcSApple OSS Distributions ShowTaskUserLibraries.exec_load_path, image_print_s)) 660*2c2f96dcSApple OSS Distributions else: 661*2c2f96dcSApple OSS Distributions debuglog("Failed to print image for main executable for task 0x{:x} dyld_load_addr 0x{:x}".format(task, dyld_load_address)) 662*2c2f96dcSApple OSS Distributions else: 663*2c2f96dcSApple OSS Distributions debuglog("Falling back to vm entry method for finding executable load address") 664*2c2f96dcSApple OSS Distributions print("# NOTE: Failed to find executable using all_image_infos. Using fuzzy match to find best possible load address for executable.") 665*2c2f96dcSApple OSS Distributions ShowTaskLoadInfo([cmd_args[0]]) 666*2c2f96dcSApple OSS Distributions return 667*2c2f96dcSApple OSS Distributions 668*2c2f96dcSApple OSS Distributions@lldb_command("showtaskuserdyldinfo") 669*2c2f96dcSApple OSS Distributionsdef ShowTaskUserDyldInfo(cmd_args=None): 670*2c2f96dcSApple OSS Distributions """ Inspect the dyld global info for the given user task & print out all fields including error messages 671*2c2f96dcSApple OSS Distributions Syntax: (lldb)showtaskuserdyldinfo <task_t> 672*2c2f96dcSApple OSS Distributions """ 673*2c2f96dcSApple OSS Distributions if cmd_args is None or len(cmd_args) < 1: 674*2c2f96dcSApple OSS Distributions print("No arguments passed") 675*2c2f96dcSApple OSS Distributions print(ShowTaskUserDyldInfo.__doc__.strip()) 676*2c2f96dcSApple OSS Distributions return 677*2c2f96dcSApple OSS Distributions 678*2c2f96dcSApple OSS Distributions out_str = "" 679*2c2f96dcSApple OSS Distributions task = kern.GetValueFromAddress(cmd_args[0], 'task_t') 680*2c2f96dcSApple OSS Distributions is_task_64 = int(task.t_flags) & 0x1 681*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address = unsigned(task.all_image_info_addr) 682*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_address == 0: 683*2c2f96dcSApple OSS Distributions print("No dyld shared library information available for task") 684*2c2f96dcSApple OSS Distributions return False 685*2c2f96dcSApple OSS Distributions vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112) 686*2c2f96dcSApple OSS Distributions dyld_all_image_infos_version = _ExtractDataFromString(vers_info_data, 0, "uint32_t") 687*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_version > 14: 688*2c2f96dcSApple OSS Distributions out_str += "Unknown dyld all_image_infos version number %d" % dyld_all_image_infos_version 689*2c2f96dcSApple OSS Distributions 690*2c2f96dcSApple OSS Distributions # Find fields by byte offset. We assume at least version 9 is supported 691*2c2f96dcSApple OSS Distributions if is_task_64: 692*2c2f96dcSApple OSS Distributions dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t") 693*2c2f96dcSApple OSS Distributions dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint64_t") 694*2c2f96dcSApple OSS Distributions dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 16, "uint64_t") 695*2c2f96dcSApple OSS Distributions dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 24, "string") 696*2c2f96dcSApple OSS Distributions dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 25, "string") 697*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 32, "uint64_t") 698*2c2f96dcSApple OSS Distributions dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 40, "uint64_t") 699*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 48, "uint64_t") 700*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 56, "uint64_t") 701*2c2f96dcSApple OSS Distributions dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 64, "uint64_t") 702*2c2f96dcSApple OSS Distributions dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 72, "uint64_t") 703*2c2f96dcSApple OSS Distributions dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 80, "uint64_t") 704*2c2f96dcSApple OSS Distributions dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 88, "uint64_t") 705*2c2f96dcSApple OSS Distributions dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 96, "uint64_t") 706*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 104, "uint64_t") 707*2c2f96dcSApple OSS Distributions else: 708*2c2f96dcSApple OSS Distributions dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t") 709*2c2f96dcSApple OSS Distributions dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint32_t") 710*2c2f96dcSApple OSS Distributions dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 12, "uint32_t") 711*2c2f96dcSApple OSS Distributions dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 16, "string") 712*2c2f96dcSApple OSS Distributions dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 17, "string") 713*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 20, "uint32_t") 714*2c2f96dcSApple OSS Distributions dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 24, "uint32_t") 715*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 28, "uint32_t") 716*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 32, "uint32_t") 717*2c2f96dcSApple OSS Distributions dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 36, "uint32_t") 718*2c2f96dcSApple OSS Distributions dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 40, "uint32_t") 719*2c2f96dcSApple OSS Distributions dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 44, "uint32_t") 720*2c2f96dcSApple OSS Distributions dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 48, "uint32_t") 721*2c2f96dcSApple OSS Distributions dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 52, "uint32_t") 722*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 56, "uint32_t") 723*2c2f96dcSApple OSS Distributions 724*2c2f96dcSApple OSS Distributions dyld_all_imfo_infos_slide = (dyld_all_image_infos_address - dyld_all_image_infos_dyldAllImageInfosAddress) 725*2c2f96dcSApple OSS Distributions dyld_all_image_infos_dyldVersion_postslide = (dyld_all_image_infos_dyldVersion + dyld_all_imfo_infos_slide) 726*2c2f96dcSApple OSS Distributions 727*2c2f96dcSApple OSS Distributions path_out = GetUserspaceString(task, dyld_all_image_infos_dyldVersion_postslide) 728*2c2f96dcSApple OSS Distributions out_str += "[dyld-{:s}]\n".format(path_out) 729*2c2f96dcSApple OSS Distributions out_str += "version \t\t\t\t: {:d}\n".format(dyld_all_image_infos_version) 730*2c2f96dcSApple OSS Distributions out_str += "infoArrayCount \t\t\t\t: {:d}\n".format(dyld_all_image_infos_infoArrayCount) 731*2c2f96dcSApple OSS Distributions out_str += "infoArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_infoArray) 732*2c2f96dcSApple OSS Distributions out_str += "notification \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_notification) 733*2c2f96dcSApple OSS Distributions 734*2c2f96dcSApple OSS Distributions out_str += "processDetachedFromSharedRegion \t: " 735*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_processDetachedFromSharedRegion != "": 736*2c2f96dcSApple OSS Distributions out_str += "TRUE\n".format(dyld_all_image_infos_processDetachedFromSharedRegion) 737*2c2f96dcSApple OSS Distributions else: 738*2c2f96dcSApple OSS Distributions out_str += "FALSE\n" 739*2c2f96dcSApple OSS Distributions 740*2c2f96dcSApple OSS Distributions out_str += "libSystemInitialized \t\t\t: " 741*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_libSystemInitialized != "": 742*2c2f96dcSApple OSS Distributions out_str += "TRUE\n".format(dyld_all_image_infos_libSystemInitialized) 743*2c2f96dcSApple OSS Distributions else: 744*2c2f96dcSApple OSS Distributions out_str += "FALSE\n" 745*2c2f96dcSApple OSS Distributions 746*2c2f96dcSApple OSS Distributions out_str += "dyldImageLoadAddress \t\t\t: {:#x}\n".format(dyld_all_image_infos_dyldImageLoadAddress) 747*2c2f96dcSApple OSS Distributions out_str += "jitInfo \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_jitInfo) 748*2c2f96dcSApple OSS Distributions out_str += "\ndyldVersion \t\t\t\t: {:#x}".format(dyld_all_image_infos_dyldVersion) 749*2c2f96dcSApple OSS Distributions if (dyld_all_imfo_infos_slide != 0): 750*2c2f96dcSApple OSS Distributions out_str += " (currently {:#x})\n".format(dyld_all_image_infos_dyldVersion_postslide) 751*2c2f96dcSApple OSS Distributions else: 752*2c2f96dcSApple OSS Distributions out_str += "\n" 753*2c2f96dcSApple OSS Distributions 754*2c2f96dcSApple OSS Distributions out_str += "errorMessage \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorMessage) 755*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_errorMessage != 0: 756*2c2f96dcSApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorMessage) 757*2c2f96dcSApple OSS Distributions 758*2c2f96dcSApple OSS Distributions out_str += "terminationFlags \t\t\t: {:#x}\n".format(dyld_all_image_infos_terminationFlags) 759*2c2f96dcSApple OSS Distributions out_str += "coreSymbolicationShmPage \t\t: {:#x}\n".format(dyld_all_image_infos_coreSymbolicationShmPage) 760*2c2f96dcSApple OSS Distributions out_str += "systemOrderFlag \t\t\t: {:#x}\n".format(dyld_all_image_infos_systemOrderFlag) 761*2c2f96dcSApple OSS Distributions out_str += "uuidArrayCount \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArrayCount) 762*2c2f96dcSApple OSS Distributions out_str += "uuidArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArray) 763*2c2f96dcSApple OSS Distributions out_str += "dyldAllImageInfosAddress \t\t: {:#x}".format(dyld_all_image_infos_dyldAllImageInfosAddress) 764*2c2f96dcSApple OSS Distributions if (dyld_all_imfo_infos_slide != 0): 765*2c2f96dcSApple OSS Distributions out_str += " (currently {:#x})\n".format(dyld_all_image_infos_address) 766*2c2f96dcSApple OSS Distributions else: 767*2c2f96dcSApple OSS Distributions out_str += "\n" 768*2c2f96dcSApple OSS Distributions 769*2c2f96dcSApple OSS Distributions if is_task_64: 770*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address = dyld_all_image_infos_address + 112 771*2c2f96dcSApple OSS Distributions dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 64) 772*2c2f96dcSApple OSS Distributions dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 112-112, "uint64_t") 773*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 120-112, "uint64_t") 774*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 128-112, "uint64_t") 775*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 136-112, "uint64_t") 776*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 144-112, "uint64_t") 777*2c2f96dcSApple OSS Distributions dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 152-112, "uint64_t") 778*2c2f96dcSApple OSS Distributions dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 160-112, "string") 779*2c2f96dcSApple OSS Distributions else: 780*2c2f96dcSApple OSS Distributions dyld_all_image_infos_address = dyld_all_image_infos_address + 60 781*2c2f96dcSApple OSS Distributions dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 40) 782*2c2f96dcSApple OSS Distributions dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 60-60, "uint32_t") 783*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 64-60, "uint32_t") 784*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 68-60, "uint32_t") 785*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 72-60, "uint32_t") 786*2c2f96dcSApple OSS Distributions dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 76-60, "uint32_t") 787*2c2f96dcSApple OSS Distributions dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 80-60, "uint32_t") 788*2c2f96dcSApple OSS Distributions dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 84-60, "string") 789*2c2f96dcSApple OSS Distributions 790*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_version >= 10: 791*2c2f96dcSApple OSS Distributions out_str += "\ninitialImageCount \t\t\t: {:#x}\n".format(dyld_all_image_infos_initialImageCount) 792*2c2f96dcSApple OSS Distributions 793*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_version >= 11: 794*2c2f96dcSApple OSS Distributions out_str += "errorKind \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorKind) 795*2c2f96dcSApple OSS Distributions out_str += "errorClientOfDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorClientOfDylibPath) 796*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_errorClientOfDylibPath != 0: 797*2c2f96dcSApple OSS Distributions out_str += "\t\t\t\t" 798*2c2f96dcSApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorClientOfDylibPath) 799*2c2f96dcSApple OSS Distributions out_str += "\n" 800*2c2f96dcSApple OSS Distributions out_str += "errorTargetDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorTargetDylibPath) 801*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_errorTargetDylibPath != 0: 802*2c2f96dcSApple OSS Distributions out_str += "\t\t\t\t" 803*2c2f96dcSApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorTargetDylibPath) 804*2c2f96dcSApple OSS Distributions out_str += "\n" 805*2c2f96dcSApple OSS Distributions out_str += "errorSymbol \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorSymbol) 806*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_errorSymbol != 0: 807*2c2f96dcSApple OSS Distributions out_str += "\t\t\t\t" 808*2c2f96dcSApple OSS Distributions out_str += GetUserspaceString(task, dyld_all_image_infos_errorSymbol) 809*2c2f96dcSApple OSS Distributions out_str += "\n" 810*2c2f96dcSApple OSS Distributions 811*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_version >= 12: 812*2c2f96dcSApple OSS Distributions out_str += "sharedCacheSlide \t\t\t: {:#x}\n".format(dyld_all_image_infos_sharedCacheSlide) 813*2c2f96dcSApple OSS Distributions if dyld_all_image_infos_version >= 13 and dyld_all_image_infos_sharedCacheUUID != "": 814*2c2f96dcSApple OSS Distributions out_str += "sharedCacheUUID \t\t\t: {:s}\n".format(dyld_all_image_infos_sharedCacheUUID) 815*2c2f96dcSApple OSS Distributions else: 816*2c2f96dcSApple OSS Distributions out_str += "No dyld information available for task\n" 817*2c2f96dcSApple OSS Distributions print(out_str) 818*2c2f96dcSApple OSS Distributions 819*2c2f96dcSApple OSS Distributionsdef SaveDataToFile(start_addr, length, outputfile, task=None,): 820*2c2f96dcSApple OSS Distributions """ Save the data at the specified address (of the specified length) to the file. 821*2c2f96dcSApple OSS Distributions params: start_addr : start address of the region of memory to save 822*2c2f96dcSApple OSS Distributions length : length of the region of memory to save 823*2c2f96dcSApple OSS Distributions outputfile : file to save the data in 824*2c2f96dcSApple OSS Distributions task (optional) : task containing the memory region (if from user data) 825*2c2f96dcSApple OSS Distributions returns: True if we saved the requested data, False otherwise 826*2c2f96dcSApple OSS Distributions """ 827*2c2f96dcSApple OSS Distributions if task: 828*2c2f96dcSApple OSS Distributions memory_data = GetUserDataAsString(task, start_addr, length) 829*2c2f96dcSApple OSS Distributions else: 830*2c2f96dcSApple OSS Distributions err = lldb.SBError() 831*2c2f96dcSApple OSS Distributions memory_data = LazyTarget.GetProcess().ReadMemory(start_addr, length, err) 832*2c2f96dcSApple OSS Distributions if not err.Success(): 833*2c2f96dcSApple OSS Distributions print("Failed to read process memory. {:d} bytes from address {: <#020x}. Error: {}".format(length, start_addr, err.description)) 834*2c2f96dcSApple OSS Distributions return False 835*2c2f96dcSApple OSS Distributions 836*2c2f96dcSApple OSS Distributions if len(memory_data) != length: 837*2c2f96dcSApple OSS Distributions print("Failed to read {:d} bytes from address {: <#020x}".format(length, start_addr)) 838*2c2f96dcSApple OSS Distributions return False 839*2c2f96dcSApple OSS Distributions 840*2c2f96dcSApple OSS Distributions fh = open(outputfile, 'wb') 841*2c2f96dcSApple OSS Distributions fh.write(memory_data) 842*2c2f96dcSApple OSS Distributions fh.close() 843*2c2f96dcSApple OSS Distributions print("Saved {:d} bytes to file {:s}".format(length, outputfile)) 844*2c2f96dcSApple OSS Distributions return True 845*2c2f96dcSApple OSS Distributions 846*2c2f96dcSApple OSS Distributions 847*2c2f96dcSApple OSS Distributions@lldb_command('savekcdata', 'T:O:') 848*2c2f96dcSApple OSS Distributionsdef SaveKCDataToFile(cmd_args=None, cmd_options={}): 849*2c2f96dcSApple OSS Distributions """ Save the data referred by the kcdata_descriptor structure. 850*2c2f96dcSApple OSS Distributions options: 851*2c2f96dcSApple OSS Distributions -T: <task_t> pointer to task if memory referenced is in userstask. 852*2c2f96dcSApple OSS Distributions -O: <output file path> path to file to save data. default: /tmp/kcdata.<timestamp>.bin 853*2c2f96dcSApple OSS Distributions Usage: (lldb) savekcdata <kcdata_descriptor_t> -T <task_t> -O /path/to/outputfile.bin 854*2c2f96dcSApple OSS Distributions """ 855*2c2f96dcSApple OSS Distributions if not cmd_args: 856*2c2f96dcSApple OSS Distributions raise ArgumentError('Please provide the kcdata descriptor.') 857*2c2f96dcSApple OSS Distributions 858*2c2f96dcSApple OSS Distributions kcdata = kern.GetValueFromAddress(cmd_args[0], 'kcdata_descriptor_t') 859*2c2f96dcSApple OSS Distributions 860*2c2f96dcSApple OSS Distributions outputfile = '/tmp/kcdata.{:s}.bin'.format(str(time.time())) 861*2c2f96dcSApple OSS Distributions task = None 862*2c2f96dcSApple OSS Distributions if '-O' in cmd_options: 863*2c2f96dcSApple OSS Distributions outputfile = cmd_options['-O'] 864*2c2f96dcSApple OSS Distributions if '-T' in cmd_options: 865*2c2f96dcSApple OSS Distributions task = kern.GetValueFromAddress(cmd_options['-T'], 'task_t') 866*2c2f96dcSApple OSS Distributions 867*2c2f96dcSApple OSS Distributions memory_begin_address = unsigned(kcdata.kcd_addr_begin) 868*2c2f96dcSApple OSS Distributions memory_size = 16 + unsigned(kcdata.kcd_addr_end) - memory_begin_address 869*2c2f96dcSApple OSS Distributions flags_copyout = unsigned(kcdata.kcd_flags) 870*2c2f96dcSApple OSS Distributions if flags_copyout: 871*2c2f96dcSApple OSS Distributions if not task: 872*2c2f96dcSApple OSS Distributions raise ArgumentError('Invalid task pointer provided.') 873*2c2f96dcSApple OSS Distributions return SaveDataToFile(memory_begin_address, memory_size, outputfile, task) 874*2c2f96dcSApple OSS Distributions else: 875*2c2f96dcSApple OSS Distributions return SaveDataToFile(memory_begin_address, memory_size, outputfile, None) 876