-
Notifications
You must be signed in to change notification settings - Fork 19
/
Copy pathmain.go
104 lines (89 loc) · 2.22 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
package main
import (
"debug/gosym"
"fmt"
"os"
"os/exec"
"syscall"
)
var targetfile string
var line int
var pc uint64
var fn *gosym.Func
var symTable *gosym.Table
var regs syscall.PtraceRegs
var ws syscall.WaitStatus
var originalCode []byte
var breakpointSet bool
var interruptCode = []byte{0xCC}
func main() {
target := os.Args[1]
symTable = getSymbolTable(target)
fn = symTable.LookupFunc("main.main")
targetfile, line, fn = symTable.PCToLine(fn.Entry)
run(target)
}
func run(target string) {
var filename string
cmd := exec.Command(target)
cmd.Stderr = os.Stderr
cmd.Stdin = os.Stdin
cmd.Stdout = os.Stdout
cmd.SysProcAttr = &syscall.SysProcAttr{
Ptrace: true,
}
cmd.Start()
err := cmd.Wait()
if err != nil {
fmt.Printf("Wait returned: %v\n\n", err)
}
pid := cmd.Process.Pid
pgid, _ := syscall.Getpgid(pid)
must(syscall.PtraceSetOptions(pid, syscall.PTRACE_O_TRACECLONE))
if inputContinue(pid) {
must(syscall.PtraceCont(pid, 0))
} else {
must(syscall.PtraceSingleStep(pid))
}
for {
wpid, err := syscall.Wait4(-1*pgid, &ws, 0, nil)
must(err)
if ws.Exited() {
if wpid == pid {
break
}
} else {
// We are only interested in tracing if we're stopped by a trap and
// if the trap was generated by our breakpoint.
// Cloning a child process also generates a trap, and we want to ignore that.
if ws.StopSignal() == syscall.SIGTRAP && ws.TrapCause() != syscall.PTRACE_EVENT_CLONE {
must(syscall.PtraceGetRegs(wpid, ®s))
filename, line, fn = symTable.PCToLine(regs.Rip)
fmt.Printf("Stopped at %s at %d in %s\n", fn.Name, line, filename)
outputStack(symTable, wpid, regs.Rip, regs.Rsp, regs.Rbp)
if breakpointSet {
replaceCode(wpid, pc, originalCode)
breakpointSet = false
}
if inputContinue(wpid) {
must(syscall.PtraceCont(wpid, 0))
} else {
must(syscall.PtraceSingleStep(wpid))
}
} else {
must(syscall.PtraceCont(wpid, 0))
}
}
}
}
func replaceCode(pid int, breakpoint uint64, code []byte) []byte {
original := make([]byte, len(code))
syscall.PtracePeekData(pid, uintptr(breakpoint), original)
syscall.PtracePokeData(pid, uintptr(breakpoint), code)
return original
}
func must(err error) {
if err != nil {
panic(err)
}
}