1 //===-- DynamicLoaderMacOS.cpp --------------------------------------------===//
2 //
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6 //
7 //===----------------------------------------------------------------------===//
8 
9 #include "lldb/Breakpoint/StoppointCallbackContext.h"
10 #include "lldb/Core/Debugger.h"
11 #include "lldb/Core/Module.h"
12 #include "lldb/Core/PluginManager.h"
13 #include "lldb/Core/Section.h"
14 #include "lldb/Symbol/ObjectFile.h"
15 #include "lldb/Symbol/SymbolVendor.h"
16 #include "lldb/Target/ABI.h"
17 #include "lldb/Target/StackFrame.h"
18 #include "lldb/Target/Target.h"
19 #include "lldb/Target/Thread.h"
20 #include "lldb/Utility/Log.h"
21 #include "lldb/Utility/State.h"
22 
23 #include "DynamicLoaderDarwin.h"
24 #include "DynamicLoaderMacOS.h"
25 
26 #include "Plugins/TypeSystem/Clang/TypeSystemClang.h"
27 
28 using namespace lldb;
29 using namespace lldb_private;
30 
31 // Create an instance of this class. This function is filled into the plugin
32 // info class that gets handed out by the plugin factory and allows the lldb to
33 // instantiate an instance of this class.
CreateInstance(Process * process,bool force)34 DynamicLoader *DynamicLoaderMacOS::CreateInstance(Process *process,
35                                                   bool force) {
36   bool create = force;
37   if (!create) {
38     create = true;
39     Module *exe_module = process->GetTarget().GetExecutableModulePointer();
40     if (exe_module) {
41       ObjectFile *object_file = exe_module->GetObjectFile();
42       if (object_file) {
43         create = (object_file->GetStrata() == ObjectFile::eStrataUser);
44       }
45     }
46 
47     if (create) {
48       const llvm::Triple &triple_ref =
49           process->GetTarget().GetArchitecture().GetTriple();
50       switch (triple_ref.getOS()) {
51       case llvm::Triple::Darwin:
52       case llvm::Triple::MacOSX:
53       case llvm::Triple::IOS:
54       case llvm::Triple::TvOS:
55       case llvm::Triple::WatchOS:
56       // NEED_BRIDGEOS_TRIPLE case llvm::Triple::BridgeOS:
57         create = triple_ref.getVendor() == llvm::Triple::Apple;
58         break;
59       default:
60         create = false;
61         break;
62       }
63     }
64   }
65 
66   if (!UseDYLDSPI(process)) {
67     create = false;
68   }
69 
70   if (create)
71     return new DynamicLoaderMacOS(process);
72   return nullptr;
73 }
74 
75 // Constructor
DynamicLoaderMacOS(Process * process)76 DynamicLoaderMacOS::DynamicLoaderMacOS(Process *process)
77     : DynamicLoaderDarwin(process), m_image_infos_stop_id(UINT32_MAX),
78       m_break_id(LLDB_INVALID_BREAK_ID), m_mutex(),
79       m_maybe_image_infos_address(LLDB_INVALID_ADDRESS) {}
80 
81 // Destructor
~DynamicLoaderMacOS()82 DynamicLoaderMacOS::~DynamicLoaderMacOS() {
83   if (LLDB_BREAK_ID_IS_VALID(m_break_id))
84     m_process->GetTarget().RemoveBreakpointByID(m_break_id);
85 }
86 
ProcessDidExec()87 bool DynamicLoaderMacOS::ProcessDidExec() {
88   std::lock_guard<std::recursive_mutex> baseclass_guard(GetMutex());
89   bool did_exec = false;
90   if (m_process) {
91     // If we are stopped after an exec, we will have only one thread...
92     if (m_process->GetThreadList().GetSize() == 1) {
93       // Maybe we still have an image infos address around?  If so see
94       // if that has changed, and if so we have exec'ed.
95       if (m_maybe_image_infos_address != LLDB_INVALID_ADDRESS) {
96         lldb::addr_t image_infos_address = m_process->GetImageInfoAddress();
97         if (image_infos_address != m_maybe_image_infos_address) {
98           // We don't really have to reset this here, since we are going to
99           // call DoInitialImageFetch right away to handle the exec.  But in
100           // case anybody looks at it in the meantime, it can't hurt.
101           m_maybe_image_infos_address = image_infos_address;
102           did_exec = true;
103         }
104       }
105 
106       if (!did_exec) {
107         // See if we are stopped at '_dyld_start'
108         ThreadSP thread_sp(m_process->GetThreadList().GetThreadAtIndex(0));
109         if (thread_sp) {
110           lldb::StackFrameSP frame_sp(thread_sp->GetStackFrameAtIndex(0));
111           if (frame_sp) {
112             const Symbol *symbol =
113                 frame_sp->GetSymbolContext(eSymbolContextSymbol).symbol;
114             if (symbol) {
115               if (symbol->GetName() == "_dyld_start")
116                 did_exec = true;
117             }
118           }
119         }
120       }
121     }
122   }
123 
124   if (did_exec) {
125     m_libpthread_module_wp.reset();
126     m_pthread_getspecific_addr.Clear();
127   }
128   return did_exec;
129 }
130 
131 // Clear out the state of this class.
DoClear()132 void DynamicLoaderMacOS::DoClear() {
133   std::lock_guard<std::recursive_mutex> guard(m_mutex);
134 
135   if (LLDB_BREAK_ID_IS_VALID(m_break_id))
136     m_process->GetTarget().RemoveBreakpointByID(m_break_id);
137 
138   m_break_id = LLDB_INVALID_BREAK_ID;
139 }
140 
141 // Check if we have found DYLD yet
DidSetNotificationBreakpoint()142 bool DynamicLoaderMacOS::DidSetNotificationBreakpoint() {
143   return LLDB_BREAK_ID_IS_VALID(m_break_id);
144 }
145 
ClearNotificationBreakpoint()146 void DynamicLoaderMacOS::ClearNotificationBreakpoint() {
147   if (LLDB_BREAK_ID_IS_VALID(m_break_id)) {
148     m_process->GetTarget().RemoveBreakpointByID(m_break_id);
149     m_break_id = LLDB_INVALID_BREAK_ID;
150   }
151 }
152 
153 // Try and figure out where dyld is by first asking the Process if it knows
154 // (which currently calls down in the lldb::Process to get the DYLD info
155 // (available on SnowLeopard only). If that fails, then check in the default
156 // addresses.
DoInitialImageFetch()157 void DynamicLoaderMacOS::DoInitialImageFetch() {
158   Log *log(lldb_private::GetLogIfAnyCategoriesSet(LIBLLDB_LOG_DYNAMIC_LOADER));
159 
160   // Remove any binaries we pre-loaded in the Target before
161   // launching/attaching. If the same binaries are present in the process,
162   // we'll get them from the shared module cache, we won't need to re-load them
163   // from disk.
164   UnloadAllImages();
165 
166   StructuredData::ObjectSP all_image_info_json_sp(
167       m_process->GetLoadedDynamicLibrariesInfos());
168   ImageInfo::collection image_infos;
169   if (all_image_info_json_sp.get() &&
170       all_image_info_json_sp->GetAsDictionary() &&
171       all_image_info_json_sp->GetAsDictionary()->HasKey("images") &&
172       all_image_info_json_sp->GetAsDictionary()
173           ->GetValueForKey("images")
174           ->GetAsArray()) {
175     if (JSONImageInformationIntoImageInfo(all_image_info_json_sp,
176                                           image_infos)) {
177       LLDB_LOGF(log, "Initial module fetch:  Adding %" PRId64 " modules.\n",
178                 (uint64_t)image_infos.size());
179 
180       UpdateSpecialBinariesFromNewImageInfos(image_infos);
181       AddModulesUsingImageInfos(image_infos);
182     }
183   }
184 
185   m_dyld_image_infos_stop_id = m_process->GetStopID();
186   m_maybe_image_infos_address = m_process->GetImageInfoAddress();
187 }
188 
NeedToDoInitialImageFetch()189 bool DynamicLoaderMacOS::NeedToDoInitialImageFetch() { return true; }
190 
191 // Static callback function that gets called when our DYLD notification
192 // breakpoint gets hit. We update all of our image infos and then let our super
193 // class DynamicLoader class decide if we should stop or not (based on global
194 // preference).
NotifyBreakpointHit(void * baton,StoppointCallbackContext * context,lldb::user_id_t break_id,lldb::user_id_t break_loc_id)195 bool DynamicLoaderMacOS::NotifyBreakpointHit(void *baton,
196                                              StoppointCallbackContext *context,
197                                              lldb::user_id_t break_id,
198                                              lldb::user_id_t break_loc_id) {
199   // Let the event know that the images have changed
200   // DYLD passes three arguments to the notification breakpoint.
201   // Arg1: enum dyld_notify_mode mode - 0 = adding, 1 = removing, 2 = remove
202   // all Arg2: unsigned long icount        - Number of shared libraries
203   // added/removed Arg3: uint64_t mach_headers[]     - Array of load addresses
204   // of binaries added/removed
205 
206   DynamicLoaderMacOS *dyld_instance = (DynamicLoaderMacOS *)baton;
207 
208   ExecutionContext exe_ctx(context->exe_ctx_ref);
209   Process *process = exe_ctx.GetProcessPtr();
210 
211   // This is a sanity check just in case this dyld_instance is an old dyld
212   // plugin's breakpoint still lying around.
213   if (process != dyld_instance->m_process)
214     return false;
215 
216   if (dyld_instance->m_image_infos_stop_id != UINT32_MAX &&
217       process->GetStopID() < dyld_instance->m_image_infos_stop_id) {
218     return false;
219   }
220 
221   const lldb::ABISP &abi = process->GetABI();
222   if (abi) {
223     // Build up the value array to store the three arguments given above, then
224     // get the values from the ABI:
225 
226     TypeSystemClang *clang_ast_context =
227         ScratchTypeSystemClang::GetForTarget(process->GetTarget());
228     if (!clang_ast_context)
229       return false;
230 
231     ValueList argument_values;
232 
233     Value mode_value;    // enum dyld_notify_mode { dyld_notify_adding=0,
234                          // dyld_notify_removing=1, dyld_notify_remove_all=2 };
235     Value count_value;   // unsigned long count
236     Value headers_value; // uint64_t machHeaders[] (aka void*)
237 
238     CompilerType clang_void_ptr_type =
239         clang_ast_context->GetBasicType(eBasicTypeVoid).GetPointerType();
240     CompilerType clang_uint32_type =
241         clang_ast_context->GetBuiltinTypeForEncodingAndBitSize(
242             lldb::eEncodingUint, 32);
243     CompilerType clang_uint64_type =
244         clang_ast_context->GetBuiltinTypeForEncodingAndBitSize(
245             lldb::eEncodingUint, 32);
246 
247     mode_value.SetValueType(Value::eValueTypeScalar);
248     mode_value.SetCompilerType(clang_uint32_type);
249 
250     if (process->GetTarget().GetArchitecture().GetAddressByteSize() == 4) {
251       count_value.SetValueType(Value::eValueTypeScalar);
252       count_value.SetCompilerType(clang_uint32_type);
253     } else {
254       count_value.SetValueType(Value::eValueTypeScalar);
255       count_value.SetCompilerType(clang_uint64_type);
256     }
257 
258     headers_value.SetValueType(Value::eValueTypeScalar);
259     headers_value.SetCompilerType(clang_void_ptr_type);
260 
261     argument_values.PushValue(mode_value);
262     argument_values.PushValue(count_value);
263     argument_values.PushValue(headers_value);
264 
265     if (abi->GetArgumentValues(exe_ctx.GetThreadRef(), argument_values)) {
266       uint32_t dyld_mode =
267           argument_values.GetValueAtIndex(0)->GetScalar().UInt(-1);
268       if (dyld_mode != static_cast<uint32_t>(-1)) {
269         // Okay the mode was right, now get the number of elements, and the
270         // array of new elements...
271         uint32_t image_infos_count =
272             argument_values.GetValueAtIndex(1)->GetScalar().UInt(-1);
273         if (image_infos_count != static_cast<uint32_t>(-1)) {
274           addr_t header_array =
275               argument_values.GetValueAtIndex(2)->GetScalar().ULongLong(-1);
276           if (header_array != static_cast<uint64_t>(-1)) {
277             std::vector<addr_t> image_load_addresses;
278             for (uint64_t i = 0; i < image_infos_count; i++) {
279               Status error;
280               addr_t addr = process->ReadUnsignedIntegerFromMemory(
281                   header_array + (8 * i), 8, LLDB_INVALID_ADDRESS, error);
282               if (addr != LLDB_INVALID_ADDRESS) {
283                 image_load_addresses.push_back(addr);
284               }
285             }
286             if (dyld_mode == 0) {
287               // dyld_notify_adding
288               dyld_instance->AddBinaries(image_load_addresses);
289             } else if (dyld_mode == 1) {
290               // dyld_notify_removing
291               dyld_instance->UnloadImages(image_load_addresses);
292             } else if (dyld_mode == 2) {
293               // dyld_notify_remove_all
294               dyld_instance->UnloadAllImages();
295             }
296           }
297         }
298       }
299     }
300   } else {
301     process->GetTarget().GetDebugger().GetAsyncErrorStream()->Printf(
302         "No ABI plugin located for triple %s -- shared libraries will not be "
303         "registered!\n",
304         process->GetTarget().GetArchitecture().GetTriple().getTriple().c_str());
305   }
306 
307   // Return true to stop the target, false to just let the target run
308   return dyld_instance->GetStopWhenImagesChange();
309 }
310 
AddBinaries(const std::vector<lldb::addr_t> & load_addresses)311 void DynamicLoaderMacOS::AddBinaries(
312     const std::vector<lldb::addr_t> &load_addresses) {
313   Log *log(lldb_private::GetLogIfAnyCategoriesSet(LIBLLDB_LOG_DYNAMIC_LOADER));
314   ImageInfo::collection image_infos;
315 
316   LLDB_LOGF(log, "Adding %" PRId64 " modules.",
317             (uint64_t)load_addresses.size());
318   StructuredData::ObjectSP binaries_info_sp =
319       m_process->GetLoadedDynamicLibrariesInfos(load_addresses);
320   if (binaries_info_sp.get() && binaries_info_sp->GetAsDictionary() &&
321       binaries_info_sp->GetAsDictionary()->HasKey("images") &&
322       binaries_info_sp->GetAsDictionary()
323           ->GetValueForKey("images")
324           ->GetAsArray() &&
325       binaries_info_sp->GetAsDictionary()
326               ->GetValueForKey("images")
327               ->GetAsArray()
328               ->GetSize() == load_addresses.size()) {
329     if (JSONImageInformationIntoImageInfo(binaries_info_sp, image_infos)) {
330       UpdateSpecialBinariesFromNewImageInfos(image_infos);
331       AddModulesUsingImageInfos(image_infos);
332     }
333     m_dyld_image_infos_stop_id = m_process->GetStopID();
334   }
335 }
336 
337 // Dump the _dyld_all_image_infos members and all current image infos that we
338 // have parsed to the file handle provided.
PutToLog(Log * log) const339 void DynamicLoaderMacOS::PutToLog(Log *log) const {
340   if (log == nullptr)
341     return;
342 }
343 
SetNotificationBreakpoint()344 bool DynamicLoaderMacOS::SetNotificationBreakpoint() {
345   if (m_break_id == LLDB_INVALID_BREAK_ID) {
346     ConstString g_symbol_name("_dyld_debugger_notification");
347     const Symbol *symbol = nullptr;
348     ModuleSP dyld_sp(GetDYLDModule());
349     if (dyld_sp) {
350       symbol = dyld_sp->FindFirstSymbolWithNameAndType(g_symbol_name,
351                                                        eSymbolTypeCode);
352     }
353     if (symbol &&
354         (symbol->ValueIsAddress() || symbol->GetAddressRef().IsValid())) {
355       addr_t symbol_address =
356           symbol->GetAddressRef().GetOpcodeLoadAddress(&m_process->GetTarget());
357       if (symbol_address != LLDB_INVALID_ADDRESS) {
358         bool internal = true;
359         bool hardware = false;
360         Breakpoint *breakpoint =
361             m_process->GetTarget()
362                 .CreateBreakpoint(symbol_address, internal, hardware)
363                 .get();
364         breakpoint->SetCallback(DynamicLoaderMacOS::NotifyBreakpointHit, this,
365                                 true);
366         breakpoint->SetBreakpointKind("shared-library-event");
367         m_break_id = breakpoint->GetID();
368       }
369     }
370   }
371   return m_break_id != LLDB_INVALID_BREAK_ID;
372 }
373 
374 addr_t
GetDyldLockVariableAddressFromModule(Module * module)375 DynamicLoaderMacOS::GetDyldLockVariableAddressFromModule(Module *module) {
376   SymbolContext sc;
377   Target &target = m_process->GetTarget();
378   if (Symtab *symtab = module->GetSymtab()) {
379     std::vector<uint32_t> match_indexes;
380     ConstString g_symbol_name("_dyld_global_lock_held");
381     uint32_t num_matches = 0;
382     num_matches =
383         symtab->AppendSymbolIndexesWithName(g_symbol_name, match_indexes);
384     if (num_matches == 1) {
385       Symbol *symbol = symtab->SymbolAtIndex(match_indexes[0]);
386       if (symbol &&
387           (symbol->ValueIsAddress() || symbol->GetAddressRef().IsValid())) {
388         return symbol->GetAddressRef().GetOpcodeLoadAddress(&target);
389       }
390     }
391   }
392   return LLDB_INVALID_ADDRESS;
393 }
394 
395 //  Look for this symbol:
396 //
397 //  int __attribute__((visibility("hidden")))           _dyld_global_lock_held =
398 //  0;
399 //
400 //  in libdyld.dylib.
CanLoadImage()401 Status DynamicLoaderMacOS::CanLoadImage() {
402   Status error;
403   addr_t symbol_address = LLDB_INVALID_ADDRESS;
404   ConstString g_libdyld_name("libdyld.dylib");
405   Target &target = m_process->GetTarget();
406   const ModuleList &target_modules = target.GetImages();
407   std::lock_guard<std::recursive_mutex> guard(target_modules.GetMutex());
408 
409   // Find any modules named "libdyld.dylib" and look for the symbol there first
410   for (ModuleSP module_sp : target.GetImages().ModulesNoLocking()) {
411     if (module_sp) {
412       if (module_sp->GetFileSpec().GetFilename() == g_libdyld_name) {
413         symbol_address = GetDyldLockVariableAddressFromModule(module_sp.get());
414         if (symbol_address != LLDB_INVALID_ADDRESS)
415           break;
416       }
417     }
418   }
419 
420   // Search through all modules looking for the symbol in them
421   if (symbol_address == LLDB_INVALID_ADDRESS) {
422     for (ModuleSP module_sp : target.GetImages().Modules()) {
423       if (module_sp) {
424         addr_t symbol_address =
425             GetDyldLockVariableAddressFromModule(module_sp.get());
426         if (symbol_address != LLDB_INVALID_ADDRESS)
427           break;
428       }
429     }
430   }
431 
432   // Default assumption is that it is OK to load images. Only say that we
433   // cannot load images if we find the symbol in libdyld and it indicates that
434   // we cannot.
435 
436   if (symbol_address != LLDB_INVALID_ADDRESS) {
437     {
438       int lock_held =
439           m_process->ReadUnsignedIntegerFromMemory(symbol_address, 4, 0, error);
440       if (lock_held != 0) {
441         error.SetErrorString("dyld lock held - unsafe to load images.");
442       }
443     }
444   } else {
445     // If we were unable to find _dyld_global_lock_held in any modules, or it
446     // is not loaded into memory yet, we may be at process startup (sitting  at
447     // _dyld_start) - so we should not allow dlopen calls. But if we found more
448     // than one module then we are clearly past _dyld_start so in that case
449     // we'll default to "it's safe".
450     if (target.GetImages().GetSize() <= 1)
451       error.SetErrorString("could not find the dyld library or "
452                            "the dyld lock symbol");
453   }
454   return error;
455 }
456 
GetSharedCacheInformation(lldb::addr_t & base_address,UUID & uuid,LazyBool & using_shared_cache,LazyBool & private_shared_cache)457 bool DynamicLoaderMacOS::GetSharedCacheInformation(
458     lldb::addr_t &base_address, UUID &uuid, LazyBool &using_shared_cache,
459     LazyBool &private_shared_cache) {
460   base_address = LLDB_INVALID_ADDRESS;
461   uuid.Clear();
462   using_shared_cache = eLazyBoolCalculate;
463   private_shared_cache = eLazyBoolCalculate;
464 
465   if (m_process) {
466     StructuredData::ObjectSP info = m_process->GetSharedCacheInfo();
467     StructuredData::Dictionary *info_dict = nullptr;
468     if (info.get() && info->GetAsDictionary()) {
469       info_dict = info->GetAsDictionary();
470     }
471 
472     // {"shared_cache_base_address":140735683125248,"shared_cache_uuid
473     // ":"DDB8D70C-
474     // C9A2-3561-B2C8-BE48A4F33F96","no_shared_cache":false,"shared_cache_private_cache":false}
475 
476     if (info_dict && info_dict->HasKey("shared_cache_uuid") &&
477         info_dict->HasKey("no_shared_cache") &&
478         info_dict->HasKey("shared_cache_base_address")) {
479       base_address = info_dict->GetValueForKey("shared_cache_base_address")
480                          ->GetIntegerValue(LLDB_INVALID_ADDRESS);
481       std::string uuid_str = std::string(
482           info_dict->GetValueForKey("shared_cache_uuid")->GetStringValue());
483       if (!uuid_str.empty())
484         uuid.SetFromStringRef(uuid_str);
485       if (!info_dict->GetValueForKey("no_shared_cache")->GetBooleanValue())
486         using_shared_cache = eLazyBoolYes;
487       else
488         using_shared_cache = eLazyBoolNo;
489       if (info_dict->GetValueForKey("shared_cache_private_cache")
490               ->GetBooleanValue())
491         private_shared_cache = eLazyBoolYes;
492       else
493         private_shared_cache = eLazyBoolNo;
494 
495       return true;
496     }
497   }
498   return false;
499 }
500 
Initialize()501 void DynamicLoaderMacOS::Initialize() {
502   PluginManager::RegisterPlugin(GetPluginNameStatic(),
503                                 GetPluginDescriptionStatic(), CreateInstance);
504 }
505 
Terminate()506 void DynamicLoaderMacOS::Terminate() {
507   PluginManager::UnregisterPlugin(CreateInstance);
508 }
509 
GetPluginNameStatic()510 lldb_private::ConstString DynamicLoaderMacOS::GetPluginNameStatic() {
511   static ConstString g_name("macos-dyld");
512   return g_name;
513 }
514 
GetPluginDescriptionStatic()515 const char *DynamicLoaderMacOS::GetPluginDescriptionStatic() {
516   return "Dynamic loader plug-in that watches for shared library loads/unloads "
517          "in MacOSX user processes.";
518 }
519 
520 // PluginInterface protocol
GetPluginName()521 lldb_private::ConstString DynamicLoaderMacOS::GetPluginName() {
522   return GetPluginNameStatic();
523 }
524 
GetPluginVersion()525 uint32_t DynamicLoaderMacOS::GetPluginVersion() { return 1; }
526