2011-09-23 12:00:45 +04:00
|
|
|
#include <unistd.h>
|
|
|
|
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include <sys/wait.h>
|
2012-05-29 20:11:00 +04:00
|
|
|
#include <sys/mman.h>
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
#include "protobuf.h"
|
|
|
|
#include "protobuf/sa.pb-c.h"
|
|
|
|
#include "protobuf/itimer.pb-c.h"
|
|
|
|
#include "protobuf/creds.pb-c.h"
|
|
|
|
|
2011-09-23 12:00:45 +04:00
|
|
|
#include "syscall.h"
|
2011-12-19 21:57:59 +04:00
|
|
|
#include "ptrace.h"
|
2013-01-09 17:02:47 +04:00
|
|
|
#include "asm/processor-flags.h"
|
2011-09-23 12:00:45 +04:00
|
|
|
#include "parasite-syscall.h"
|
|
|
|
#include "parasite-blob.h"
|
|
|
|
#include "parasite.h"
|
2012-05-29 20:11:00 +04:00
|
|
|
#include "crtools.h"
|
2012-08-02 08:10:22 +04:00
|
|
|
#include "namespaces.h"
|
2012-10-08 18:59:36 +04:00
|
|
|
#include "pstree.h"
|
2012-05-29 20:11:00 +04:00
|
|
|
|
|
|
|
#include <string.h>
|
|
|
|
#include <stdlib.h>
|
2011-09-23 12:00:45 +04:00
|
|
|
|
|
|
|
#ifdef CONFIG_X86_64
|
2013-01-09 17:26:31 +04:00
|
|
|
#include "asm/parasite-syscall.h"
|
2011-09-23 12:00:45 +04:00
|
|
|
|
|
|
|
#define parasite_size (round_up(sizeof(parasite_blob), sizeof(long)))
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
static int can_run_syscall(unsigned long ip, unsigned long start, unsigned long end)
|
|
|
|
{
|
|
|
|
return ip >= start && ip < (end - code_syscall_size);
|
|
|
|
}
|
|
|
|
|
2011-09-23 12:00:45 +04:00
|
|
|
static int syscall_fits_vma_area(struct vma_area *vma_area)
|
|
|
|
{
|
|
|
|
return can_run_syscall((unsigned long)vma_area->vma.start,
|
|
|
|
(unsigned long)vma_area->vma.start,
|
|
|
|
(unsigned long)vma_area->vma.end);
|
|
|
|
}
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
static struct vma_area *get_vma_by_ip(struct list_head *vma_area_list, unsigned long ip)
|
2011-09-23 12:00:45 +04:00
|
|
|
{
|
2012-02-15 18:00:50 +04:00
|
|
|
struct vma_area *vma_area;
|
|
|
|
|
|
|
|
list_for_each_entry(vma_area, vma_area_list, list) {
|
|
|
|
if (!in_vma_area(vma_area, ip))
|
|
|
|
continue;
|
|
|
|
if (!(vma_area->vma.prot & PROT_EXEC))
|
|
|
|
continue;
|
|
|
|
if (syscall_fits_vma_area(vma_area))
|
|
|
|
return vma_area;
|
|
|
|
}
|
|
|
|
|
|
|
|
return NULL;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
/* we run at @regs->ip */
|
2012-02-21 09:25:16 +03:00
|
|
|
static int __parasite_execute(struct parasite_ctl *ctl, pid_t pid, user_regs_struct_t *regs)
|
2011-09-23 12:00:45 +04:00
|
|
|
{
|
|
|
|
siginfo_t siginfo;
|
|
|
|
int status;
|
|
|
|
int ret = -1;
|
|
|
|
|
|
|
|
again:
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace(PTRACE_SETREGS, pid, NULL, regs)) {
|
|
|
|
pr_err("Can't set registers (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Most ideas are taken from Tejun Heo's parasite thread
|
|
|
|
* https://code.google.com/p/ptrace-parasite/
|
|
|
|
*/
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace(PTRACE_CONT, pid, NULL, NULL)) {
|
|
|
|
pr_err("Can't continue (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (wait4(pid, &status, __WALL, NULL) != pid) {
|
|
|
|
pr_err("Waited pid mismatch (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!WIFSTOPPED(status)) {
|
|
|
|
pr_err("Task is still running (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ptrace(PTRACE_GETSIGINFO, pid, NULL, &siginfo)) {
|
|
|
|
pr_err("Can't get siginfo (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace(PTRACE_GETREGS, pid, NULL, regs)) {
|
|
|
|
pr_err("Can't obtain registers (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
|
|
|
if (WSTOPSIG(status) != SIGTRAP || siginfo.si_code != SI_KERNEL) {
|
|
|
|
retry_signal:
|
2012-02-15 18:00:50 +04:00
|
|
|
pr_debug("** delivering signal %d si_code=%d\n",
|
|
|
|
siginfo.si_signo, siginfo.si_code);
|
|
|
|
|
2012-03-01 19:01:05 +04:00
|
|
|
if (ctl->signals_blocked) {
|
|
|
|
pr_err("Unexpected %d task interruption, aborting\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
2012-02-13 23:06:18 +04:00
|
|
|
/* FIXME: jerr(siginfo.si_code > 0, err_restore); */
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
/*
|
|
|
|
* This requires some explanation. If a signal from original
|
|
|
|
* program delivered while we're trying to execute our
|
|
|
|
* injected blob -- we need to setup original registers back
|
|
|
|
* so the kernel would make sigframe for us and update the
|
|
|
|
* former registers.
|
|
|
|
*
|
|
|
|
* Then we should swap registers back to our modified copy
|
|
|
|
* and retry.
|
|
|
|
*/
|
|
|
|
|
|
|
|
if (ptrace(PTRACE_SETREGS, pid, NULL, &ctl->regs_orig)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("Can't set registers (pid: %d)\n", pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ptrace(PTRACE_INTERRUPT, pid, NULL, NULL)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("Can't interrupt (pid: %d)\n", pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ptrace(PTRACE_CONT, pid, NULL, (void *)(unsigned long)siginfo.si_signo)) {
|
|
|
|
pr_err("Can't continue (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (wait4(pid, &status, __WALL, NULL) != pid) {
|
|
|
|
pr_err("Waited pid mismatch (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!WIFSTOPPED(status)) {
|
|
|
|
pr_err("Task is still running (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (ptrace(PTRACE_GETSIGINFO, pid, NULL, &siginfo)) {
|
|
|
|
pr_err("Can't get siginfo (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-04-25 21:34:05 +04:00
|
|
|
if (SI_EVENT(siginfo.si_code) != PTRACE_EVENT_STOP)
|
2011-09-23 12:00:45 +04:00
|
|
|
goto retry_signal;
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
/*
|
|
|
|
* Signal is delivered, so we should update
|
|
|
|
* original registers.
|
|
|
|
*/
|
|
|
|
{
|
|
|
|
user_regs_struct_t r;
|
|
|
|
if (ptrace(PTRACE_GETREGS, pid, NULL, &r)) {
|
|
|
|
pr_err("Can't obtain registers (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
ctl->regs_orig = r;
|
|
|
|
}
|
|
|
|
|
2011-09-23 12:00:45 +04:00
|
|
|
goto again;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2012-10-29 13:40:45 +04:00
|
|
|
* We've reached this point iif int3 is triggered inside our
|
|
|
|
* parasite code. So we're done.
|
2011-09-23 12:00:45 +04:00
|
|
|
*/
|
2012-02-15 18:00:50 +04:00
|
|
|
ret = 0;
|
2011-09-23 12:00:45 +04:00
|
|
|
err:
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
static void *parasite_args_s(struct parasite_ctl *ctl, int args_size)
|
2012-10-11 15:59:43 +04:00
|
|
|
{
|
|
|
|
BUG_ON(args_size > PARASITE_ARG_SIZE);
|
|
|
|
return ctl->addr_args;
|
|
|
|
}
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
#define parasite_args(ctl, type) ({ \
|
|
|
|
BUILD_BUG_ON(sizeof(type) > PARASITE_ARG_SIZE); \
|
|
|
|
ctl->addr_args; \
|
|
|
|
})
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
static int parasite_execute_by_pid(unsigned int cmd, struct parasite_ctl *ctl, pid_t pid)
|
2012-02-12 00:32:32 +04:00
|
|
|
{
|
|
|
|
int ret;
|
2012-02-21 09:25:16 +03:00
|
|
|
user_regs_struct_t regs_orig, regs;
|
|
|
|
|
|
|
|
if (ctl->pid == pid)
|
|
|
|
regs = ctl->regs_orig;
|
|
|
|
else {
|
|
|
|
if (ptrace(PTRACE_GETREGS, pid, NULL, ®s_orig)) {
|
|
|
|
pr_err("Can't obtain registers (pid: %d)\n", pid);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
regs = regs_orig;
|
|
|
|
}
|
2012-02-12 00:32:32 +04:00
|
|
|
|
2012-10-11 17:59:10 +04:00
|
|
|
*ctl->addr_cmd = cmd;
|
2012-02-12 00:32:32 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
parasite_setup_regs(ctl->parasite_ip, ®s);
|
2012-02-12 00:32:32 +04:00
|
|
|
|
2012-02-21 09:25:16 +03:00
|
|
|
ret = __parasite_execute(ctl, pid, ®s);
|
2012-06-26 20:00:00 +04:00
|
|
|
if (ret == 0)
|
2012-11-06 16:56:55 +04:00
|
|
|
ret = (int)regs.ax;
|
2012-02-12 00:32:32 +04:00
|
|
|
|
2012-02-16 21:54:49 +04:00
|
|
|
if (ret)
|
2012-06-26 20:01:00 +04:00
|
|
|
pr_err("Parasite exited with %d\n", ret);
|
2012-02-16 21:54:49 +04:00
|
|
|
|
2012-02-21 09:25:16 +03:00
|
|
|
if (ctl->pid != pid)
|
|
|
|
if (ptrace(PTRACE_SETREGS, pid, NULL, ®s_orig)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("Can't restore registers (pid: %d)\n", ctl->pid);
|
2012-02-21 09:25:16 +03:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2012-02-12 00:32:32 +04:00
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
static int parasite_execute(unsigned int cmd, struct parasite_ctl *ctl)
|
2012-02-21 09:25:16 +03:00
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
return parasite_execute_by_pid(cmd, ctl, ctl->pid);
|
2012-02-21 09:25:16 +03:00
|
|
|
}
|
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
int syscall_seized(struct parasite_ctl *ctl, int nr, unsigned long *ret,
|
|
|
|
unsigned long arg1,
|
|
|
|
unsigned long arg2,
|
|
|
|
unsigned long arg3,
|
|
|
|
unsigned long arg4,
|
|
|
|
unsigned long arg5,
|
|
|
|
unsigned long arg6)
|
2011-11-29 13:33:59 +03:00
|
|
|
{
|
2012-02-15 18:00:50 +04:00
|
|
|
user_regs_struct_t regs = ctl->regs_orig;
|
2012-12-17 22:52:06 +03:00
|
|
|
int err;
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
regs.ax = (unsigned long)nr;
|
|
|
|
regs.di = arg1;
|
|
|
|
regs.si = arg2;
|
|
|
|
regs.dx = arg3;
|
|
|
|
regs.r10 = arg4;
|
|
|
|
regs.r8 = arg5;
|
|
|
|
regs.r9 = arg6;
|
2012-02-12 14:51:38 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
parasite_setup_regs(ctl->syscall_ip, ®s);
|
2012-12-17 22:52:06 +03:00
|
|
|
err = __parasite_execute(ctl, ctl->pid, ®s);
|
|
|
|
if (err)
|
|
|
|
return err;
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
*ret = regs.ax;
|
|
|
|
return 0;
|
2012-02-15 18:00:50 +04:00
|
|
|
}
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
static void *mmap_seized(struct parasite_ctl *ctl,
|
|
|
|
void *addr, size_t length, int prot,
|
|
|
|
int flags, int fd, off_t offset)
|
2012-02-15 18:00:50 +04:00
|
|
|
{
|
2012-12-17 22:52:06 +03:00
|
|
|
unsigned long map;
|
|
|
|
int err;
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
err = syscall_seized(ctl, __NR_mmap, &map,
|
|
|
|
(unsigned long)addr, length, prot, flags, fd, offset);
|
|
|
|
if (err < 0 || (long)map < 0)
|
|
|
|
map = 0;
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
return (void *)map;
|
|
|
|
}
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
static int munmap_seized(struct parasite_ctl *ctl, void *addr, size_t length)
|
|
|
|
{
|
|
|
|
unsigned long x;
|
2011-11-29 13:33:59 +03:00
|
|
|
|
2012-12-17 22:52:06 +03:00
|
|
|
return syscall_seized(ctl, __NR_munmap, &x,
|
|
|
|
(unsigned long)addr, length, 0, 0, 0, 0);
|
2011-11-29 13:33:59 +03:00
|
|
|
}
|
|
|
|
|
2012-03-21 11:47:00 +04:00
|
|
|
static int gen_parasite_saddr(struct sockaddr_un *saddr, int key)
|
2012-02-01 16:23:50 +03:00
|
|
|
{
|
|
|
|
int sun_len;
|
|
|
|
|
|
|
|
saddr->sun_family = AF_UNIX;
|
|
|
|
snprintf(saddr->sun_path, UNIX_PATH_MAX,
|
2012-03-21 11:47:00 +04:00
|
|
|
"X/crtools-pr-%d", key);
|
2012-02-01 16:23:50 +03:00
|
|
|
|
|
|
|
sun_len = SUN_LEN(saddr);
|
|
|
|
*saddr->sun_path = '\0';
|
|
|
|
|
|
|
|
return sun_len;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int parasite_send_fd(struct parasite_ctl *ctl, int fd)
|
|
|
|
{
|
2012-07-14 15:36:00 +04:00
|
|
|
if (send_fd(ctl->tsock, NULL, 0, fd) < 0) {
|
2012-02-01 16:23:50 +03:00
|
|
|
pr_perror("Can't send file descriptor");
|
2012-07-14 15:36:00 +04:00
|
|
|
return -1;
|
2012-02-01 16:23:50 +03:00
|
|
|
}
|
2012-07-14 15:36:00 +04:00
|
|
|
return 0;
|
2012-02-01 16:23:50 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
static int parasite_set_logfd(struct parasite_ctl *ctl, pid_t pid)
|
|
|
|
{
|
|
|
|
int ret;
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_log_args *a;
|
2012-02-01 16:23:50 +03:00
|
|
|
|
2012-03-01 18:52:42 +04:00
|
|
|
ret = parasite_send_fd(ctl, log_get_fd());
|
2012-02-01 16:23:50 +03:00
|
|
|
if (ret)
|
|
|
|
return ret;
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
a = parasite_args(ctl, struct parasite_log_args);
|
2012-10-11 15:59:43 +04:00
|
|
|
a->log_level = log_get_loglevel();
|
2012-10-08 19:56:12 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = parasite_execute(PARASITE_CMD_CFG_LOG, ctl);
|
2012-02-01 16:23:50 +03:00
|
|
|
if (ret < 0)
|
|
|
|
return ret;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2012-11-12 17:42:48 +04:00
|
|
|
static int parasite_init(struct parasite_ctl *ctl, pid_t pid, int nr_threads)
|
2012-07-14 15:36:00 +04:00
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_init_args *args;
|
2012-08-01 10:17:14 +04:00
|
|
|
static int sock = -1;
|
2012-07-14 15:36:00 +04:00
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
args = parasite_args(ctl, struct parasite_init_args);
|
2012-10-11 15:59:43 +04:00
|
|
|
|
2012-08-01 10:17:14 +04:00
|
|
|
pr_info("Putting tsock into pid %d\n", pid);
|
2012-12-20 16:07:44 +04:00
|
|
|
args->h_addr_len = gen_parasite_saddr(&args->h_addr, getpid());
|
2012-10-11 15:59:43 +04:00
|
|
|
args->p_addr_len = gen_parasite_saddr(&args->p_addr, pid);
|
2012-11-12 17:42:48 +04:00
|
|
|
args->nr_threads = nr_threads;
|
2012-07-14 15:36:00 +04:00
|
|
|
|
2012-08-01 10:17:14 +04:00
|
|
|
if (sock == -1) {
|
2012-08-02 08:10:22 +04:00
|
|
|
int rst = -1;
|
|
|
|
|
2012-08-02 16:25:52 +04:00
|
|
|
if (opts.namespaces_flags & CLONE_NEWNET) {
|
2012-08-02 08:10:22 +04:00
|
|
|
pr_info("Switching to %d's net for tsock creation\n", pid);
|
|
|
|
|
|
|
|
if (switch_ns(pid, CLONE_NEWNET, "net", &rst))
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2012-08-01 10:17:14 +04:00
|
|
|
sock = socket(PF_UNIX, SOCK_DGRAM, 0);
|
|
|
|
if (sock < 0) {
|
|
|
|
pr_perror("Can't create socket");
|
|
|
|
return -1;
|
|
|
|
}
|
2012-07-14 15:36:00 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
if (bind(sock, (struct sockaddr *)&args->h_addr, args->h_addr_len) < 0) {
|
2012-08-01 10:17:14 +04:00
|
|
|
pr_perror("Can't bind socket");
|
|
|
|
goto err;
|
|
|
|
}
|
2012-08-02 08:10:22 +04:00
|
|
|
|
|
|
|
if (rst > 0 && restore_ns(rst, CLONE_NEWNET) < 0)
|
|
|
|
goto err;
|
2012-08-01 10:17:14 +04:00
|
|
|
} else {
|
|
|
|
struct sockaddr addr = { .sa_family = AF_UNSPEC, };
|
|
|
|
|
|
|
|
/*
|
|
|
|
* When the peer of a dgram socket dies the original socket
|
|
|
|
* remains in connected state, thus denying any connections
|
|
|
|
* from "other" sources. Unconnect the socket by hands thus
|
|
|
|
* allowing for parasite to connect back.
|
|
|
|
*/
|
|
|
|
|
|
|
|
if (connect(sock, &addr, sizeof(addr)) < 0) {
|
|
|
|
pr_perror("Can't unconnect");
|
|
|
|
goto err;
|
|
|
|
}
|
2012-07-14 15:36:00 +04:00
|
|
|
}
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
if (parasite_execute(PARASITE_CMD_INIT, ctl) < 0) {
|
2012-08-01 09:48:02 +04:00
|
|
|
pr_err("Can't init parasite\n");
|
2012-07-14 15:36:00 +04:00
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
if (connect(sock, (struct sockaddr *)&args->p_addr, args->p_addr_len) < 0) {
|
2012-08-01 09:48:02 +04:00
|
|
|
pr_perror("Can't connect a transport socket");
|
2012-07-14 15:36:00 +04:00
|
|
|
goto err;
|
2012-08-01 09:48:02 +04:00
|
|
|
}
|
2012-07-14 15:36:00 +04:00
|
|
|
|
|
|
|
ctl->tsock = sock;
|
|
|
|
return 0;
|
|
|
|
err:
|
|
|
|
close(sock);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2012-06-19 15:53:00 +04:00
|
|
|
int parasite_dump_thread_seized(struct parasite_ctl *ctl, pid_t pid,
|
2012-11-12 17:42:56 +04:00
|
|
|
unsigned int **tid_addr, pid_t *tid,
|
|
|
|
void *blocked)
|
2012-02-21 09:25:17 +03:00
|
|
|
{
|
2012-11-12 17:42:53 +04:00
|
|
|
struct parasite_dump_thread *args;
|
2012-02-21 09:25:17 +03:00
|
|
|
int ret;
|
|
|
|
|
2012-11-12 17:42:53 +04:00
|
|
|
args = parasite_args(ctl, struct parasite_dump_thread);
|
2012-10-11 15:59:43 +04:00
|
|
|
|
2012-11-12 17:42:53 +04:00
|
|
|
ret = parasite_execute_by_pid(PARASITE_CMD_DUMP_THREAD, ctl, pid);
|
2012-02-21 09:25:17 +03:00
|
|
|
|
2012-11-12 17:42:56 +04:00
|
|
|
memcpy(blocked, &args->blocked, sizeof(args->blocked));
|
2012-10-11 15:59:43 +04:00
|
|
|
*tid_addr = args->tid_addr;
|
|
|
|
*tid = args->tid;
|
2012-02-21 09:25:17 +03:00
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-01-24 16:45:19 +04:00
|
|
|
int parasite_dump_sigacts_seized(struct parasite_ctl *ctl, struct cr_fdset *cr_fdset)
|
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_dump_sa_args *args;
|
2012-12-04 19:26:54 +04:00
|
|
|
int ret, sig, fd;
|
2012-07-18 16:25:06 +04:00
|
|
|
SaEntry se = SA_ENTRY__INIT;
|
2012-07-15 10:18:35 +04:00
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
args = parasite_args(ctl, struct parasite_dump_sa_args);
|
2012-10-11 15:59:43 +04:00
|
|
|
|
|
|
|
ret = parasite_execute(PARASITE_CMD_DUMP_SIGACTS, ctl);
|
2012-07-15 10:18:35 +04:00
|
|
|
if (ret < 0)
|
|
|
|
return ret;
|
|
|
|
|
|
|
|
fd = fdset_fd(cr_fdset, CR_FD_SIGACT);
|
|
|
|
|
2012-12-04 19:26:54 +04:00
|
|
|
for (sig = 1; sig <= SIGMAX; sig++) {
|
|
|
|
int i = sig - 1;
|
|
|
|
|
|
|
|
if (sig == SIGSTOP || sig == SIGKILL)
|
2012-07-15 10:18:35 +04:00
|
|
|
continue;
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ASSIGN_TYPED(se.sigaction, args->sas[i].rt_sa_handler);
|
|
|
|
ASSIGN_TYPED(se.flags, args->sas[i].rt_sa_flags);
|
|
|
|
ASSIGN_TYPED(se.restorer, args->sas[i].rt_sa_restorer);
|
|
|
|
ASSIGN_TYPED(se.mask, args->sas[i].rt_sa_mask.sig[0]);
|
2012-07-15 10:18:35 +04:00
|
|
|
|
2012-08-07 02:26:50 +04:00
|
|
|
if (pb_write_one(fd, &se, PB_SIGACT) < 0)
|
2012-07-15 10:18:35 +04:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
2012-01-24 16:45:19 +04:00
|
|
|
}
|
|
|
|
|
2012-07-18 07:23:05 +04:00
|
|
|
static int dump_one_timer(struct itimerval *v, int fd)
|
|
|
|
{
|
2012-07-18 16:27:01 +04:00
|
|
|
ItimerEntry ie = ITIMER_ENTRY__INIT;
|
2012-07-18 07:23:05 +04:00
|
|
|
|
|
|
|
ie.isec = v->it_interval.tv_sec;
|
|
|
|
ie.iusec = v->it_interval.tv_usec;
|
|
|
|
ie.vsec = v->it_value.tv_sec;
|
|
|
|
ie.vusec = v->it_value.tv_sec;
|
|
|
|
|
2012-08-07 02:26:50 +04:00
|
|
|
return pb_write_one(fd, &ie, PB_ITIMERS);
|
2012-07-18 07:23:05 +04:00
|
|
|
}
|
|
|
|
|
2012-01-24 16:45:19 +04:00
|
|
|
int parasite_dump_itimers_seized(struct parasite_ctl *ctl, struct cr_fdset *cr_fdset)
|
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_dump_itimers_args *args;
|
2012-07-18 07:23:05 +04:00
|
|
|
int ret, fd;
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
args = parasite_args(ctl, struct parasite_dump_itimers_args);
|
2012-10-11 15:59:43 +04:00
|
|
|
|
|
|
|
ret = parasite_execute(PARASITE_CMD_DUMP_ITIMERS, ctl);
|
2012-07-18 07:23:05 +04:00
|
|
|
if (ret < 0)
|
|
|
|
return ret;
|
|
|
|
|
|
|
|
fd = fdset_fd(cr_fdset, CR_FD_ITIMERS);
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = dump_one_timer(&args->real, fd);
|
2012-07-18 07:23:05 +04:00
|
|
|
if (!ret)
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = dump_one_timer(&args->virt, fd);
|
2012-07-18 07:23:05 +04:00
|
|
|
if (!ret)
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = dump_one_timer(&args->prof, fd);
|
2012-07-18 07:23:05 +04:00
|
|
|
|
|
|
|
return ret;
|
2012-01-24 16:45:19 +04:00
|
|
|
}
|
|
|
|
|
2012-01-27 21:35:59 +04:00
|
|
|
int parasite_dump_misc_seized(struct parasite_ctl *ctl, struct parasite_dump_misc *misc)
|
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_dump_misc *ma;
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
ma = parasite_args(ctl, struct parasite_dump_misc);
|
2012-10-11 15:59:43 +04:00
|
|
|
if (parasite_execute(PARASITE_CMD_DUMP_MISC, ctl) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
*misc = *ma;
|
|
|
|
return 0;
|
2012-01-27 21:35:59 +04:00
|
|
|
}
|
|
|
|
|
2012-10-15 23:55:34 +04:00
|
|
|
struct parasite_tty_args *parasite_dump_tty(struct parasite_ctl *ctl, int fd)
|
2012-10-15 23:42:49 +04:00
|
|
|
{
|
2012-10-15 23:55:34 +04:00
|
|
|
struct parasite_tty_args *p;
|
2012-10-15 23:42:49 +04:00
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
p = parasite_args(ctl, struct parasite_tty_args);
|
2012-10-15 23:55:34 +04:00
|
|
|
p->fd = fd;
|
|
|
|
|
2012-10-15 23:42:49 +04:00
|
|
|
if (parasite_execute(PARASITE_CMD_DUMP_TTY, ctl) < 0)
|
2012-10-15 23:55:34 +04:00
|
|
|
return NULL;
|
2012-10-15 23:42:49 +04:00
|
|
|
|
2012-10-15 23:55:34 +04:00
|
|
|
return p;
|
2012-10-15 23:42:49 +04:00
|
|
|
}
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
int parasite_dump_creds(struct parasite_ctl *ctl, CredsEntry *ce)
|
|
|
|
{
|
|
|
|
struct parasite_dump_creds *pc;
|
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
pc = parasite_args(ctl, struct parasite_dump_creds);
|
2012-10-11 15:59:43 +04:00
|
|
|
if (parasite_execute(PARASITE_CMD_DUMP_CREDS, ctl) < 0)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
ce->secbits = pc->secbits;
|
2012-10-11 16:52:52 +04:00
|
|
|
ce->n_groups = pc->ngroups;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Achtung! We leak the parasite args pointer to the caller.
|
|
|
|
* It's not safe in general, but in our case is OK, since the
|
|
|
|
* latter doesn't go to parasite before using the data in it.
|
|
|
|
*/
|
|
|
|
|
|
|
|
BUILD_BUG_ON(sizeof(ce->groups[0]) != sizeof(pc->groups[0]));
|
|
|
|
ce->groups = pc->groups;
|
2012-10-11 15:59:43 +04:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2011-10-13 16:36:50 +04:00
|
|
|
/*
|
|
|
|
* This routine drives parasite code (been previously injected into a victim
|
|
|
|
* process) and tells it to dump pages into the file.
|
|
|
|
*/
|
2011-09-23 12:00:45 +04:00
|
|
|
int parasite_dump_pages_seized(struct parasite_ctl *ctl, struct list_head *vma_area_list,
|
2012-01-11 13:30:38 +04:00
|
|
|
struct cr_fdset *cr_fdset)
|
2011-09-23 12:00:45 +04:00
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
struct parasite_dump_pages_args *parasite_dumppages;
|
2012-04-27 04:53:17 +04:00
|
|
|
unsigned long nrpages_dumped = 0, nrpages_skipped = 0, nrpages_total = 0;
|
2011-09-23 12:00:45 +04:00
|
|
|
struct vma_area *vma_area;
|
2012-02-15 18:00:50 +04:00
|
|
|
int ret = -1;
|
2011-09-23 12:00:45 +04:00
|
|
|
|
|
|
|
pr_info("\n");
|
2012-01-11 13:30:38 +04:00
|
|
|
pr_info("Dumping pages (type: %d pid: %d)\n", CR_FD_PAGES, ctl->pid);
|
2011-09-23 12:00:45 +04:00
|
|
|
pr_info("----------------------------------------\n");
|
|
|
|
|
2012-12-18 21:01:53 +03:00
|
|
|
ret = parasite_send_fd(ctl, fdset_fd(cr_fdset, CR_FD_PAGES));
|
2012-01-24 16:40:55 +04:00
|
|
|
if (ret < 0)
|
2011-11-23 13:08:28 +04:00
|
|
|
goto out;
|
2011-10-03 11:52:13 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = parasite_execute(PARASITE_CMD_DUMPPAGES_INIT, ctl);
|
2012-02-12 00:26:54 +04:00
|
|
|
if (ret < 0) {
|
2012-06-26 20:01:00 +04:00
|
|
|
pr_err("Dumping pages failed with %i\n", ret);
|
2012-02-12 00:26:54 +04:00
|
|
|
goto out;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-10-30 20:58:03 +03:00
|
|
|
parasite_dumppages = parasite_args(ctl, struct parasite_dump_pages_args);
|
2012-10-11 15:59:43 +04:00
|
|
|
|
2011-09-23 12:00:45 +04:00
|
|
|
list_for_each_entry(vma_area, vma_area_list, list) {
|
|
|
|
|
|
|
|
/*
|
|
|
|
* The special areas are not dumped.
|
|
|
|
*/
|
|
|
|
if (!(vma_area->vma.status & VMA_AREA_REGULAR))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
/* No dumps for file-shared mappings */
|
|
|
|
if (vma_area->vma.status & VMA_FILE_SHARED)
|
|
|
|
continue;
|
|
|
|
|
2012-02-14 20:19:49 +03:00
|
|
|
/* No dumps for SYSV IPC mappings */
|
|
|
|
if (vma_area->vma.status & VMA_AREA_SYSVIPC)
|
|
|
|
continue;
|
|
|
|
|
2012-03-21 10:12:00 +04:00
|
|
|
if (vma_area_is(vma_area, VMA_ANON_SHARED))
|
|
|
|
continue;
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
parasite_dumppages->vma_entry = vma_area->vma;
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-03-21 10:12:00 +04:00
|
|
|
if (!vma_area_is(vma_area, VMA_ANON_PRIVATE) &&
|
|
|
|
!vma_area_is(vma_area, VMA_FILE_PRIVATE)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_warn("Unexpected VMA area found\n");
|
2012-02-12 00:26:54 +04:00
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
2013-01-09 17:23:48 +04:00
|
|
|
if (vma_area->vma.end > TASK_SIZE)
|
|
|
|
continue;
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = parasite_execute(PARASITE_CMD_DUMPPAGES, ctl);
|
2011-11-29 13:33:59 +03:00
|
|
|
if (ret) {
|
2012-06-26 20:01:00 +04:00
|
|
|
pr_err("Dumping pages failed with %d\n", ret);
|
2012-09-29 08:28:53 +04:00
|
|
|
goto out_fini;
|
2011-11-22 20:07:20 +04:00
|
|
|
}
|
|
|
|
|
2012-04-27 04:53:17 +04:00
|
|
|
pr_info("vma %lx-%lx dumped: %lu pages %lu skipped %lu total\n",
|
|
|
|
vma_area->vma.start, vma_area->vma.end,
|
2012-10-11 15:59:43 +04:00
|
|
|
parasite_dumppages->nrpages_dumped,
|
|
|
|
parasite_dumppages->nrpages_skipped,
|
|
|
|
parasite_dumppages->nrpages_total);
|
2012-04-27 04:53:17 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
nrpages_dumped += parasite_dumppages->nrpages_dumped;
|
|
|
|
nrpages_skipped += parasite_dumppages->nrpages_skipped;
|
|
|
|
nrpages_total += parasite_dumppages->nrpages_total;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
pr_info("\n");
|
2012-04-27 04:53:17 +04:00
|
|
|
pr_info("Summary: %lu dumped %lu skipped %lu total\n",
|
|
|
|
nrpages_dumped, nrpages_skipped, nrpages_total);
|
2012-02-08 14:11:54 +04:00
|
|
|
ret = 0;
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-09-29 08:28:53 +04:00
|
|
|
out_fini:
|
2012-10-11 15:59:43 +04:00
|
|
|
parasite_execute(PARASITE_CMD_DUMPPAGES_FINI, ctl);
|
2011-11-23 13:08:28 +04:00
|
|
|
out:
|
2011-09-23 12:00:45 +04:00
|
|
|
pr_info("----------------------------------------\n");
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-08-21 19:59:07 +04:00
|
|
|
int parasite_drain_fds_seized(struct parasite_ctl *ctl,
|
2012-09-05 16:41:14 +04:00
|
|
|
struct parasite_drain_fd *dfds, int *lfds, struct fd_opts *opts)
|
2012-03-28 17:36:00 +04:00
|
|
|
{
|
2012-10-11 15:59:43 +04:00
|
|
|
int ret = -1, size;
|
|
|
|
struct parasite_drain_fd *args;
|
|
|
|
|
|
|
|
size = drain_fds_size(dfds);
|
2012-10-30 20:58:03 +03:00
|
|
|
args = parasite_args_s(ctl, size);
|
2012-10-11 15:59:43 +04:00
|
|
|
memcpy(args, dfds, size);
|
2012-03-28 17:36:00 +04:00
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = parasite_execute(PARASITE_CMD_DRAIN_FDS, ctl);
|
2012-03-28 17:36:00 +04:00
|
|
|
if (ret) {
|
|
|
|
pr_err("Parasite failed to drain descriptors\n");
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
2012-09-05 16:41:14 +04:00
|
|
|
ret = recv_fds(ctl->tsock, lfds, dfds->nr_fds, opts);
|
2012-03-28 17:36:00 +04:00
|
|
|
if (ret) {
|
|
|
|
pr_err("Can't retrieve FDs from socket\n");
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
err:
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-09-07 19:16:33 +04:00
|
|
|
int parasite_get_proc_fd_seized(struct parasite_ctl *ctl)
|
|
|
|
{
|
|
|
|
int ret = -1, fd;
|
|
|
|
|
2012-10-11 15:59:43 +04:00
|
|
|
ret = parasite_execute(PARASITE_CMD_GET_PROC_FD, ctl);
|
2012-09-07 19:16:33 +04:00
|
|
|
if (ret) {
|
|
|
|
pr_err("Parasite failed to get proc fd\n");
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
fd = recv_fd(ctl->tsock);
|
|
|
|
if (fd < 0) {
|
|
|
|
pr_err("Can't retrieve FD from socket\n");
|
|
|
|
return fd;
|
|
|
|
}
|
|
|
|
|
|
|
|
return fd;
|
|
|
|
}
|
|
|
|
|
2012-11-12 17:42:51 +04:00
|
|
|
int parasite_init_threads_seized(struct parasite_ctl *ctl, struct pstree_item *item)
|
|
|
|
{
|
|
|
|
int ret = 0, i;
|
|
|
|
|
|
|
|
for (i = 0; i < item->nr_threads; i++) {
|
|
|
|
if (item->pid.real == item->threads[i].real)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
ret = parasite_execute_by_pid(PARASITE_CMD_INIT_THREAD, ctl,
|
|
|
|
item->threads[i].real);
|
|
|
|
if (ret) {
|
|
|
|
pr_err("Can't init thread in parasite %d\n",
|
|
|
|
item->threads[i].real);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
|
|
|
int parasite_fini_threads_seized(struct parasite_ctl *ctl, struct pstree_item *item)
|
|
|
|
{
|
|
|
|
int ret = 0, i;
|
|
|
|
|
|
|
|
for (i = 0; i < item->nr_threads; i++) {
|
|
|
|
if (item->pid.real == item->threads[i].real)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
ret = parasite_execute_by_pid(PARASITE_CMD_FINI_THREAD, ctl,
|
|
|
|
item->threads[i].real);
|
|
|
|
/*
|
|
|
|
* Note the thread's fini() can be called even when not
|
|
|
|
* all threads were init()'ed, say we're rolling back from
|
|
|
|
* error happened while we were init()'ing some thread, thus
|
|
|
|
* -ENOENT will be returned but we should continie for the
|
|
|
|
* rest of threads set.
|
|
|
|
*
|
|
|
|
* Strictly speaking we always init() threads in sequence thus
|
|
|
|
* we could simply break the loop once first -ENOENT returned
|
|
|
|
* but I prefer to be on a safe side even if some future changes
|
|
|
|
* would change the code logic.
|
|
|
|
*/
|
|
|
|
if (ret && ret != -ENOENT) {
|
|
|
|
pr_err("Can't fini thread in parasite %d\n",
|
|
|
|
item->threads[i].real);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-11-12 17:42:55 +04:00
|
|
|
int parasite_cure_seized(struct parasite_ctl *ctl, struct pstree_item *item)
|
2011-09-23 12:00:45 +04:00
|
|
|
{
|
2012-02-15 18:00:50 +04:00
|
|
|
int ret = 0;
|
2012-02-01 16:23:50 +03:00
|
|
|
|
2012-08-01 10:17:14 +04:00
|
|
|
ctl->tsock = -1;
|
2012-07-14 15:36:00 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ctl->parasite_ip) {
|
2012-03-01 19:01:05 +04:00
|
|
|
ctl->signals_blocked = 0;
|
2012-11-12 17:42:55 +04:00
|
|
|
parasite_fini_threads_seized(ctl, item);
|
2012-10-11 15:59:43 +04:00
|
|
|
parasite_execute(PARASITE_CMD_FINI, ctl);
|
2012-02-01 16:23:50 +03:00
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ctl->remote_map) {
|
|
|
|
if (munmap_seized(ctl, (void *)ctl->remote_map, ctl->map_length)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("munmap_seized failed (pid: %d)\n", ctl->pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
ret = -1;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ctl->local_map) {
|
2012-12-18 20:48:56 +03:00
|
|
|
if (munmap(ctl->local_map, ctl->map_length)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("munmap failed (pid: %d)\n", ctl->pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
ret = -1;
|
|
|
|
}
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace_poke_area(ctl->pid, (void *)ctl->code_orig,
|
|
|
|
(void *)ctl->syscall_ip, sizeof(ctl->code_orig))) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("Can't restore syscall blob (pid: %d)\n", ctl->pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
ret = -1;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace(PTRACE_SETREGS, ctl->pid, NULL, &ctl->regs_orig)) {
|
2012-03-01 18:52:42 +04:00
|
|
|
pr_err("Can't restore registers (pid: %d)\n", ctl->pid);
|
2012-02-08 14:11:54 +04:00
|
|
|
ret = -1;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
2012-01-11 13:32:43 +04:00
|
|
|
free(ctl);
|
2011-09-23 12:00:45 +04:00
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2012-12-17 22:53:23 +03:00
|
|
|
struct parasite_ctl *parasite_prep_ctl(pid_t pid, struct list_head *vma_area_list)
|
2011-09-23 12:00:45 +04:00
|
|
|
{
|
|
|
|
struct parasite_ctl *ctl = NULL;
|
|
|
|
struct vma_area *vma_area;
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
/*
|
|
|
|
* Control block early setup.
|
|
|
|
*/
|
2012-01-13 17:20:57 +04:00
|
|
|
ctl = xzalloc(sizeof(*ctl));
|
2011-09-23 12:00:45 +04:00
|
|
|
if (!ctl) {
|
2011-09-30 14:37:12 +04:00
|
|
|
pr_err("Parasite control block allocation failed (pid: %d)\n", pid);
|
2011-09-23 12:00:45 +04:00
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
2012-07-14 15:36:00 +04:00
|
|
|
ctl->tsock = -1;
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
if (ptrace(PTRACE_GETREGS, pid, NULL, &ctl->regs_orig)) {
|
|
|
|
pr_err("Can't obtain registers (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
vma_area = get_vma_by_ip(vma_area_list, ctl->regs_orig.ip);
|
2011-09-23 12:00:45 +04:00
|
|
|
if (!vma_area) {
|
2011-09-30 14:37:12 +04:00
|
|
|
pr_err("No suitable VMA found to run parasite "
|
2012-02-15 18:00:50 +04:00
|
|
|
"bootstrap code (pid: %d)\n", pid);
|
2012-02-13 23:17:51 +04:00
|
|
|
goto err;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
ctl->pid = pid;
|
|
|
|
ctl->syscall_ip = vma_area->vma.start;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Inject syscall instruction and remember original code,
|
|
|
|
* we will need it to restore original program content.
|
|
|
|
*/
|
|
|
|
memcpy(ctl->code_orig, code_syscall, sizeof(ctl->code_orig));
|
|
|
|
if (ptrace_swap_area(ctl->pid, (void *)ctl->syscall_ip,
|
|
|
|
(void *)ctl->code_orig, sizeof(ctl->code_orig))) {
|
|
|
|
pr_err("Can't inject syscall blob (pid: %d)\n", pid);
|
|
|
|
goto err;
|
|
|
|
}
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-12-17 22:53:23 +03:00
|
|
|
return ctl;
|
|
|
|
|
|
|
|
err:
|
|
|
|
xfree(ctl);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
int parasite_map_exchange(struct parasite_ctl *ctl, unsigned long size)
|
|
|
|
{
|
|
|
|
int fd;
|
|
|
|
|
2012-12-18 20:48:56 +03:00
|
|
|
ctl->remote_map = mmap_seized(ctl, NULL, size,
|
2012-02-13 23:17:51 +04:00
|
|
|
PROT_READ | PROT_WRITE | PROT_EXEC,
|
|
|
|
MAP_ANONYMOUS | MAP_SHARED, -1, 0);
|
|
|
|
if (!ctl->remote_map) {
|
2012-12-17 22:53:23 +03:00
|
|
|
pr_err("Can't allocate memory for parasite blob (pid: %d)\n", ctl->pid);
|
|
|
|
return -1;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
2012-12-18 20:48:56 +03:00
|
|
|
ctl->map_length = round_up(size, PAGE_SIZE);
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-12-17 22:53:23 +03:00
|
|
|
fd = open_proc_rw(ctl->pid, "map_files/%p-%p",
|
2012-02-15 18:00:50 +04:00
|
|
|
ctl->remote_map, ctl->remote_map + ctl->map_length);
|
2012-02-17 01:39:36 +04:00
|
|
|
if (fd < 0)
|
2012-12-17 22:53:23 +03:00
|
|
|
return -1;
|
2011-09-23 12:00:45 +04:00
|
|
|
|
2012-12-18 20:48:56 +03:00
|
|
|
ctl->local_map = mmap(NULL, size, PROT_READ | PROT_WRITE,
|
2012-02-13 23:17:51 +04:00
|
|
|
MAP_SHARED | MAP_FILE, fd, 0);
|
2012-02-12 14:50:34 +04:00
|
|
|
close(fd);
|
|
|
|
|
|
|
|
if (ctl->local_map == MAP_FAILED) {
|
2012-02-15 18:00:50 +04:00
|
|
|
ctl->local_map = NULL;
|
2012-02-12 14:50:34 +04:00
|
|
|
pr_perror("Can't map remote parasite map");
|
2012-12-17 22:53:23 +03:00
|
|
|
return -1;
|
2012-02-12 14:50:34 +04:00
|
|
|
}
|
|
|
|
|
2012-12-17 22:53:23 +03:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct parasite_ctl *parasite_infect_seized(pid_t pid, struct pstree_item *item, struct list_head *vma_area_list)
|
|
|
|
{
|
|
|
|
int ret;
|
|
|
|
struct parasite_ctl *ctl;
|
|
|
|
|
|
|
|
ctl = parasite_prep_ctl(pid, vma_area_list);
|
|
|
|
if (!ctl)
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Inject a parasite engine. Ie allocate memory inside alien
|
|
|
|
* space and copy engine code there. Then re-map the engine
|
|
|
|
* locally, so we will get an easy way to access engine memory
|
|
|
|
* without using ptrace at all.
|
|
|
|
*/
|
|
|
|
|
|
|
|
ret = parasite_map_exchange(ctl, parasite_size);
|
|
|
|
if (ret)
|
|
|
|
goto err_restore;
|
|
|
|
|
2012-02-12 14:50:34 +04:00
|
|
|
pr_info("Putting parasite blob into %p->%p\n", ctl->local_map, ctl->remote_map);
|
2012-02-13 21:49:18 +04:00
|
|
|
memcpy(ctl->local_map, parasite_blob, sizeof(parasite_blob));
|
2012-02-12 14:50:34 +04:00
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
/* Setup the rest of a control block */
|
2012-11-13 20:51:32 +03:00
|
|
|
ctl->parasite_ip = (unsigned long)parasite_sym(ctl->remote_map, __export_parasite_head_start);
|
|
|
|
ctl->addr_cmd = parasite_sym(ctl->local_map, __export_parasite_cmd);
|
|
|
|
ctl->addr_args = parasite_sym(ctl->local_map, __export_parasite_args);
|
2012-02-12 14:51:38 +04:00
|
|
|
|
2012-11-12 17:42:48 +04:00
|
|
|
ret = parasite_init(ctl, pid, item->nr_threads);
|
2012-02-01 16:23:50 +03:00
|
|
|
if (ret) {
|
|
|
|
pr_err("%d: Can't create a transport socket\n", pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
goto err_restore;
|
2012-02-01 16:23:50 +03:00
|
|
|
}
|
|
|
|
|
2012-03-01 19:01:05 +04:00
|
|
|
ctl->signals_blocked = 1;
|
|
|
|
|
2012-02-01 16:23:50 +03:00
|
|
|
ret = parasite_set_logfd(ctl, pid);
|
|
|
|
if (ret) {
|
|
|
|
pr_err("%d: Can't set a logging descriptor\n", pid);
|
2012-02-15 18:00:50 +04:00
|
|
|
goto err_restore;
|
2012-02-01 16:23:50 +03:00
|
|
|
}
|
|
|
|
|
2012-11-12 17:42:55 +04:00
|
|
|
ret = parasite_init_threads_seized(ctl, item);
|
|
|
|
if (ret)
|
|
|
|
goto err_restore;
|
|
|
|
|
2011-09-23 12:00:45 +04:00
|
|
|
return ctl;
|
|
|
|
|
2012-02-15 18:00:50 +04:00
|
|
|
err_restore:
|
2012-11-12 17:42:55 +04:00
|
|
|
parasite_cure_seized(ctl, item);
|
2012-04-06 17:58:00 +04:00
|
|
|
return NULL;
|
2011-09-23 12:00:45 +04:00
|
|
|
}
|
|
|
|
|
|
|
|
#else /* CONFIG_X86_64 */
|
|
|
|
# error x86-32 is not yet implemented
|
|
|
|
#endif /* CONFIG_X86_64 */
|