在Android ARM64上使用ptrace跟踪进程

时间:2016-09-08 17:30:23

标签: android c debugging arm64 ptrace

我在使用模拟AARCH64的Android ARM64仿真器上的ptrace()尝试跟踪简单的hello世界时遇到了无限循环。我不确定为什么它没有停止。我试图跟踪一个hello world程序并获取所有已执行的指令,但似乎这个条件永远不会返回false:while (WIFSTOPPED(wait_status))

int main(int argc, char** argv)
{
    pid_t child_pid;

    if(argc < 2)
    {
        fprintf(stderr, "Expected a program name as argument\n");
        return -1;
    }

    child_pid = fork(); 

    if (child_pid == 0)
        run_target(argv[1]);
    else if (child_pid > 0)
        run_debugger(child_pid);
    else 
    {
        perror("fork");
        return -1;
    }

    return 0;
}


void run_target(const char* programname)
{
    printf("target started. will run '%s'\n", programname);

    /* Allow tracing of this process */
    if (ptrace(PTRACE_TRACEME, 0, 0, 0) < 0)
    {
        perror("ptrace");
        return;
    }

    /* Replace this process's image with the given program */
    execl(programname, programname, 0);
}

void run_debugger(pid_t child_pid)
{
    int wait_status;
    unsigned icounter = 0;
    printf("debugger started\n");

    /* Wait for child to stop on its first instruction */
    wait(&wait_status);

    while (WIFSTOPPED(wait_status)) 
    {
        icounter++;

        struct user_pt_regs regs;
        struct iovec io;
        io.iov_base = &regs;
        io.iov_len = sizeof(regs);


        if (ptrace(PTRACE_GETREGSET, child_pid, (void*)NT_PRSTATUS, (void*)&io) == -1)
            printf("BAD REGISTER REQUEST\n");

        unsigned instr = ptrace(PTRACE_PEEKTEXT, child_pid, regs.pc, 0);

        printf("icounter = %u.  PCP = 0x%08x.  instr = 0x%08x\n", icounter, regs.pc, instr);

        /* Make the child execute another instruction */
        if (ptrace(PTRACE_SINGLESTEP, child_pid, 0, 0) < 0) 
        {
            perror("ptrace");
            return;
        }

        /* Wait for child to stop on its next instruction */
        wait(&wait_status);
    }

    printf("the child executed %u instructions\n", icounter);
}

0 个答案:

没有答案