]> git.ipfire.org Git - thirdparty/qemu.git/blame_incremental - gdbstub.c
gdbstub: add multiprocess support to 'H' and 'T' packets
[thirdparty/qemu.git] / gdbstub.c
... / ...
CommitLineData
1/*
2 * gdb server stub
3 *
4 * Copyright (c) 2003-2005 Fabrice Bellard
5 *
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
10 *
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
15 *
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
18 */
19#include "qemu/osdep.h"
20#include "qapi/error.h"
21#include "qemu/error-report.h"
22#include "qemu/cutils.h"
23#include "trace-root.h"
24#ifdef CONFIG_USER_ONLY
25#include "qemu.h"
26#else
27#include "monitor/monitor.h"
28#include "chardev/char.h"
29#include "chardev/char-fe.h"
30#include "sysemu/sysemu.h"
31#include "exec/gdbstub.h"
32#include "hw/cpu/cluster.h"
33#endif
34
35#define MAX_PACKET_LENGTH 4096
36
37#include "qemu/sockets.h"
38#include "sysemu/hw_accel.h"
39#include "sysemu/kvm.h"
40#include "exec/semihost.h"
41#include "exec/exec-all.h"
42
43#ifdef CONFIG_USER_ONLY
44#define GDB_ATTACHED "0"
45#else
46#define GDB_ATTACHED "1"
47#endif
48
49static inline int target_memory_rw_debug(CPUState *cpu, target_ulong addr,
50 uint8_t *buf, int len, bool is_write)
51{
52 CPUClass *cc = CPU_GET_CLASS(cpu);
53
54 if (cc->memory_rw_debug) {
55 return cc->memory_rw_debug(cpu, addr, buf, len, is_write);
56 }
57 return cpu_memory_rw_debug(cpu, addr, buf, len, is_write);
58}
59
60/* Return the GDB index for a given vCPU state.
61 *
62 * For user mode this is simply the thread id. In system mode GDB
63 * numbers CPUs from 1 as 0 is reserved as an "any cpu" index.
64 */
65static inline int cpu_gdb_index(CPUState *cpu)
66{
67#if defined(CONFIG_USER_ONLY)
68 TaskState *ts = (TaskState *) cpu->opaque;
69 return ts->ts_tid;
70#else
71 return cpu->cpu_index + 1;
72#endif
73}
74
75enum {
76 GDB_SIGNAL_0 = 0,
77 GDB_SIGNAL_INT = 2,
78 GDB_SIGNAL_QUIT = 3,
79 GDB_SIGNAL_TRAP = 5,
80 GDB_SIGNAL_ABRT = 6,
81 GDB_SIGNAL_ALRM = 14,
82 GDB_SIGNAL_IO = 23,
83 GDB_SIGNAL_XCPU = 24,
84 GDB_SIGNAL_UNKNOWN = 143
85};
86
87#ifdef CONFIG_USER_ONLY
88
89/* Map target signal numbers to GDB protocol signal numbers and vice
90 * versa. For user emulation's currently supported systems, we can
91 * assume most signals are defined.
92 */
93
94static int gdb_signal_table[] = {
95 0,
96 TARGET_SIGHUP,
97 TARGET_SIGINT,
98 TARGET_SIGQUIT,
99 TARGET_SIGILL,
100 TARGET_SIGTRAP,
101 TARGET_SIGABRT,
102 -1, /* SIGEMT */
103 TARGET_SIGFPE,
104 TARGET_SIGKILL,
105 TARGET_SIGBUS,
106 TARGET_SIGSEGV,
107 TARGET_SIGSYS,
108 TARGET_SIGPIPE,
109 TARGET_SIGALRM,
110 TARGET_SIGTERM,
111 TARGET_SIGURG,
112 TARGET_SIGSTOP,
113 TARGET_SIGTSTP,
114 TARGET_SIGCONT,
115 TARGET_SIGCHLD,
116 TARGET_SIGTTIN,
117 TARGET_SIGTTOU,
118 TARGET_SIGIO,
119 TARGET_SIGXCPU,
120 TARGET_SIGXFSZ,
121 TARGET_SIGVTALRM,
122 TARGET_SIGPROF,
123 TARGET_SIGWINCH,
124 -1, /* SIGLOST */
125 TARGET_SIGUSR1,
126 TARGET_SIGUSR2,
127#ifdef TARGET_SIGPWR
128 TARGET_SIGPWR,
129#else
130 -1,
131#endif
132 -1, /* SIGPOLL */
133 -1,
134 -1,
135 -1,
136 -1,
137 -1,
138 -1,
139 -1,
140 -1,
141 -1,
142 -1,
143 -1,
144#ifdef __SIGRTMIN
145 __SIGRTMIN + 1,
146 __SIGRTMIN + 2,
147 __SIGRTMIN + 3,
148 __SIGRTMIN + 4,
149 __SIGRTMIN + 5,
150 __SIGRTMIN + 6,
151 __SIGRTMIN + 7,
152 __SIGRTMIN + 8,
153 __SIGRTMIN + 9,
154 __SIGRTMIN + 10,
155 __SIGRTMIN + 11,
156 __SIGRTMIN + 12,
157 __SIGRTMIN + 13,
158 __SIGRTMIN + 14,
159 __SIGRTMIN + 15,
160 __SIGRTMIN + 16,
161 __SIGRTMIN + 17,
162 __SIGRTMIN + 18,
163 __SIGRTMIN + 19,
164 __SIGRTMIN + 20,
165 __SIGRTMIN + 21,
166 __SIGRTMIN + 22,
167 __SIGRTMIN + 23,
168 __SIGRTMIN + 24,
169 __SIGRTMIN + 25,
170 __SIGRTMIN + 26,
171 __SIGRTMIN + 27,
172 __SIGRTMIN + 28,
173 __SIGRTMIN + 29,
174 __SIGRTMIN + 30,
175 __SIGRTMIN + 31,
176 -1, /* SIGCANCEL */
177 __SIGRTMIN,
178 __SIGRTMIN + 32,
179 __SIGRTMIN + 33,
180 __SIGRTMIN + 34,
181 __SIGRTMIN + 35,
182 __SIGRTMIN + 36,
183 __SIGRTMIN + 37,
184 __SIGRTMIN + 38,
185 __SIGRTMIN + 39,
186 __SIGRTMIN + 40,
187 __SIGRTMIN + 41,
188 __SIGRTMIN + 42,
189 __SIGRTMIN + 43,
190 __SIGRTMIN + 44,
191 __SIGRTMIN + 45,
192 __SIGRTMIN + 46,
193 __SIGRTMIN + 47,
194 __SIGRTMIN + 48,
195 __SIGRTMIN + 49,
196 __SIGRTMIN + 50,
197 __SIGRTMIN + 51,
198 __SIGRTMIN + 52,
199 __SIGRTMIN + 53,
200 __SIGRTMIN + 54,
201 __SIGRTMIN + 55,
202 __SIGRTMIN + 56,
203 __SIGRTMIN + 57,
204 __SIGRTMIN + 58,
205 __SIGRTMIN + 59,
206 __SIGRTMIN + 60,
207 __SIGRTMIN + 61,
208 __SIGRTMIN + 62,
209 __SIGRTMIN + 63,
210 __SIGRTMIN + 64,
211 __SIGRTMIN + 65,
212 __SIGRTMIN + 66,
213 __SIGRTMIN + 67,
214 __SIGRTMIN + 68,
215 __SIGRTMIN + 69,
216 __SIGRTMIN + 70,
217 __SIGRTMIN + 71,
218 __SIGRTMIN + 72,
219 __SIGRTMIN + 73,
220 __SIGRTMIN + 74,
221 __SIGRTMIN + 75,
222 __SIGRTMIN + 76,
223 __SIGRTMIN + 77,
224 __SIGRTMIN + 78,
225 __SIGRTMIN + 79,
226 __SIGRTMIN + 80,
227 __SIGRTMIN + 81,
228 __SIGRTMIN + 82,
229 __SIGRTMIN + 83,
230 __SIGRTMIN + 84,
231 __SIGRTMIN + 85,
232 __SIGRTMIN + 86,
233 __SIGRTMIN + 87,
234 __SIGRTMIN + 88,
235 __SIGRTMIN + 89,
236 __SIGRTMIN + 90,
237 __SIGRTMIN + 91,
238 __SIGRTMIN + 92,
239 __SIGRTMIN + 93,
240 __SIGRTMIN + 94,
241 __SIGRTMIN + 95,
242 -1, /* SIGINFO */
243 -1, /* UNKNOWN */
244 -1, /* DEFAULT */
245 -1,
246 -1,
247 -1,
248 -1,
249 -1,
250 -1
251#endif
252};
253#else
254/* In system mode we only need SIGINT and SIGTRAP; other signals
255 are not yet supported. */
256
257enum {
258 TARGET_SIGINT = 2,
259 TARGET_SIGTRAP = 5
260};
261
262static int gdb_signal_table[] = {
263 -1,
264 -1,
265 TARGET_SIGINT,
266 -1,
267 -1,
268 TARGET_SIGTRAP
269};
270#endif
271
272#ifdef CONFIG_USER_ONLY
273static int target_signal_to_gdb (int sig)
274{
275 int i;
276 for (i = 0; i < ARRAY_SIZE (gdb_signal_table); i++)
277 if (gdb_signal_table[i] == sig)
278 return i;
279 return GDB_SIGNAL_UNKNOWN;
280}
281#endif
282
283static int gdb_signal_to_target (int sig)
284{
285 if (sig < ARRAY_SIZE (gdb_signal_table))
286 return gdb_signal_table[sig];
287 else
288 return -1;
289}
290
291typedef struct GDBRegisterState {
292 int base_reg;
293 int num_regs;
294 gdb_reg_cb get_reg;
295 gdb_reg_cb set_reg;
296 const char *xml;
297 struct GDBRegisterState *next;
298} GDBRegisterState;
299
300typedef struct GDBProcess {
301 uint32_t pid;
302 bool attached;
303} GDBProcess;
304
305enum RSState {
306 RS_INACTIVE,
307 RS_IDLE,
308 RS_GETLINE,
309 RS_GETLINE_ESC,
310 RS_GETLINE_RLE,
311 RS_CHKSUM1,
312 RS_CHKSUM2,
313};
314typedef struct GDBState {
315 CPUState *c_cpu; /* current CPU for step/continue ops */
316 CPUState *g_cpu; /* current CPU for other ops */
317 CPUState *query_cpu; /* for q{f|s}ThreadInfo */
318 enum RSState state; /* parsing state */
319 char line_buf[MAX_PACKET_LENGTH];
320 int line_buf_index;
321 int line_sum; /* running checksum */
322 int line_csum; /* checksum at the end of the packet */
323 uint8_t last_packet[MAX_PACKET_LENGTH + 4];
324 int last_packet_len;
325 int signal;
326#ifdef CONFIG_USER_ONLY
327 int fd;
328 int running_state;
329#else
330 CharBackend chr;
331 Chardev *mon_chr;
332#endif
333 bool multiprocess;
334 GDBProcess *processes;
335 int process_num;
336 char syscall_buf[256];
337 gdb_syscall_complete_cb current_syscall_cb;
338} GDBState;
339
340/* By default use no IRQs and no timers while single stepping so as to
341 * make single stepping like an ICE HW step.
342 */
343static int sstep_flags = SSTEP_ENABLE|SSTEP_NOIRQ|SSTEP_NOTIMER;
344
345static GDBState *gdbserver_state;
346
347bool gdb_has_xml;
348
349#ifdef CONFIG_USER_ONLY
350/* XXX: This is not thread safe. Do we care? */
351static int gdbserver_fd = -1;
352
353static int get_char(GDBState *s)
354{
355 uint8_t ch;
356 int ret;
357
358 for(;;) {
359 ret = qemu_recv(s->fd, &ch, 1, 0);
360 if (ret < 0) {
361 if (errno == ECONNRESET)
362 s->fd = -1;
363 if (errno != EINTR)
364 return -1;
365 } else if (ret == 0) {
366 close(s->fd);
367 s->fd = -1;
368 return -1;
369 } else {
370 break;
371 }
372 }
373 return ch;
374}
375#endif
376
377static enum {
378 GDB_SYS_UNKNOWN,
379 GDB_SYS_ENABLED,
380 GDB_SYS_DISABLED,
381} gdb_syscall_mode;
382
383/* Decide if either remote gdb syscalls or native file IO should be used. */
384int use_gdb_syscalls(void)
385{
386 SemihostingTarget target = semihosting_get_target();
387 if (target == SEMIHOSTING_TARGET_NATIVE) {
388 /* -semihosting-config target=native */
389 return false;
390 } else if (target == SEMIHOSTING_TARGET_GDB) {
391 /* -semihosting-config target=gdb */
392 return true;
393 }
394
395 /* -semihosting-config target=auto */
396 /* On the first call check if gdb is connected and remember. */
397 if (gdb_syscall_mode == GDB_SYS_UNKNOWN) {
398 gdb_syscall_mode = (gdbserver_state ? GDB_SYS_ENABLED
399 : GDB_SYS_DISABLED);
400 }
401 return gdb_syscall_mode == GDB_SYS_ENABLED;
402}
403
404/* Resume execution. */
405static inline void gdb_continue(GDBState *s)
406{
407
408#ifdef CONFIG_USER_ONLY
409 s->running_state = 1;
410 trace_gdbstub_op_continue();
411#else
412 if (!runstate_needs_reset()) {
413 trace_gdbstub_op_continue();
414 vm_start();
415 }
416#endif
417}
418
419/*
420 * Resume execution, per CPU actions. For user-mode emulation it's
421 * equivalent to gdb_continue.
422 */
423static int gdb_continue_partial(GDBState *s, char *newstates)
424{
425 CPUState *cpu;
426 int res = 0;
427#ifdef CONFIG_USER_ONLY
428 /*
429 * This is not exactly accurate, but it's an improvement compared to the
430 * previous situation, where only one CPU would be single-stepped.
431 */
432 CPU_FOREACH(cpu) {
433 if (newstates[cpu->cpu_index] == 's') {
434 trace_gdbstub_op_stepping(cpu->cpu_index);
435 cpu_single_step(cpu, sstep_flags);
436 }
437 }
438 s->running_state = 1;
439#else
440 int flag = 0;
441
442 if (!runstate_needs_reset()) {
443 if (vm_prepare_start()) {
444 return 0;
445 }
446
447 CPU_FOREACH(cpu) {
448 switch (newstates[cpu->cpu_index]) {
449 case 0:
450 case 1:
451 break; /* nothing to do here */
452 case 's':
453 trace_gdbstub_op_stepping(cpu->cpu_index);
454 cpu_single_step(cpu, sstep_flags);
455 cpu_resume(cpu);
456 flag = 1;
457 break;
458 case 'c':
459 trace_gdbstub_op_continue_cpu(cpu->cpu_index);
460 cpu_resume(cpu);
461 flag = 1;
462 break;
463 default:
464 res = -1;
465 break;
466 }
467 }
468 }
469 if (flag) {
470 qemu_clock_enable(QEMU_CLOCK_VIRTUAL, true);
471 }
472#endif
473 return res;
474}
475
476static void put_buffer(GDBState *s, const uint8_t *buf, int len)
477{
478#ifdef CONFIG_USER_ONLY
479 int ret;
480
481 while (len > 0) {
482 ret = send(s->fd, buf, len, 0);
483 if (ret < 0) {
484 if (errno != EINTR)
485 return;
486 } else {
487 buf += ret;
488 len -= ret;
489 }
490 }
491#else
492 /* XXX this blocks entire thread. Rewrite to use
493 * qemu_chr_fe_write and background I/O callbacks */
494 qemu_chr_fe_write_all(&s->chr, buf, len);
495#endif
496}
497
498static inline int fromhex(int v)
499{
500 if (v >= '0' && v <= '9')
501 return v - '0';
502 else if (v >= 'A' && v <= 'F')
503 return v - 'A' + 10;
504 else if (v >= 'a' && v <= 'f')
505 return v - 'a' + 10;
506 else
507 return 0;
508}
509
510static inline int tohex(int v)
511{
512 if (v < 10)
513 return v + '0';
514 else
515 return v - 10 + 'a';
516}
517
518/* writes 2*len+1 bytes in buf */
519static void memtohex(char *buf, const uint8_t *mem, int len)
520{
521 int i, c;
522 char *q;
523 q = buf;
524 for(i = 0; i < len; i++) {
525 c = mem[i];
526 *q++ = tohex(c >> 4);
527 *q++ = tohex(c & 0xf);
528 }
529 *q = '\0';
530}
531
532static void hextomem(uint8_t *mem, const char *buf, int len)
533{
534 int i;
535
536 for(i = 0; i < len; i++) {
537 mem[i] = (fromhex(buf[0]) << 4) | fromhex(buf[1]);
538 buf += 2;
539 }
540}
541
542static void hexdump(const char *buf, int len,
543 void (*trace_fn)(size_t ofs, char const *text))
544{
545 char line_buffer[3 * 16 + 4 + 16 + 1];
546
547 size_t i;
548 for (i = 0; i < len || (i & 0xF); ++i) {
549 size_t byte_ofs = i & 15;
550
551 if (byte_ofs == 0) {
552 memset(line_buffer, ' ', 3 * 16 + 4 + 16);
553 line_buffer[3 * 16 + 4 + 16] = 0;
554 }
555
556 size_t col_group = (i >> 2) & 3;
557 size_t hex_col = byte_ofs * 3 + col_group;
558 size_t txt_col = 3 * 16 + 4 + byte_ofs;
559
560 if (i < len) {
561 char value = buf[i];
562
563 line_buffer[hex_col + 0] = tohex((value >> 4) & 0xF);
564 line_buffer[hex_col + 1] = tohex((value >> 0) & 0xF);
565 line_buffer[txt_col + 0] = (value >= ' ' && value < 127)
566 ? value
567 : '.';
568 }
569
570 if (byte_ofs == 0xF)
571 trace_fn(i & -16, line_buffer);
572 }
573}
574
575/* return -1 if error, 0 if OK */
576static int put_packet_binary(GDBState *s, const char *buf, int len, bool dump)
577{
578 int csum, i;
579 uint8_t *p;
580
581 if (dump && trace_event_get_state_backends(TRACE_GDBSTUB_IO_BINARYREPLY)) {
582 hexdump(buf, len, trace_gdbstub_io_binaryreply);
583 }
584
585 for(;;) {
586 p = s->last_packet;
587 *(p++) = '$';
588 memcpy(p, buf, len);
589 p += len;
590 csum = 0;
591 for(i = 0; i < len; i++) {
592 csum += buf[i];
593 }
594 *(p++) = '#';
595 *(p++) = tohex((csum >> 4) & 0xf);
596 *(p++) = tohex((csum) & 0xf);
597
598 s->last_packet_len = p - s->last_packet;
599 put_buffer(s, (uint8_t *)s->last_packet, s->last_packet_len);
600
601#ifdef CONFIG_USER_ONLY
602 i = get_char(s);
603 if (i < 0)
604 return -1;
605 if (i == '+')
606 break;
607#else
608 break;
609#endif
610 }
611 return 0;
612}
613
614/* return -1 if error, 0 if OK */
615static int put_packet(GDBState *s, const char *buf)
616{
617 trace_gdbstub_io_reply(buf);
618
619 return put_packet_binary(s, buf, strlen(buf), false);
620}
621
622/* Encode data using the encoding for 'x' packets. */
623static int memtox(char *buf, const char *mem, int len)
624{
625 char *p = buf;
626 char c;
627
628 while (len--) {
629 c = *(mem++);
630 switch (c) {
631 case '#': case '$': case '*': case '}':
632 *(p++) = '}';
633 *(p++) = c ^ 0x20;
634 break;
635 default:
636 *(p++) = c;
637 break;
638 }
639 }
640 return p - buf;
641}
642
643static uint32_t gdb_get_cpu_pid(const GDBState *s, CPUState *cpu)
644{
645#ifndef CONFIG_USER_ONLY
646 gchar *path, *name = NULL;
647 Object *obj;
648 CPUClusterState *cluster;
649 uint32_t ret;
650
651 path = object_get_canonical_path(OBJECT(cpu));
652
653 if (path == NULL) {
654 /* Return the default process' PID */
655 ret = s->processes[s->process_num - 1].pid;
656 goto out;
657 }
658
659 name = object_get_canonical_path_component(OBJECT(cpu));
660 assert(name != NULL);
661
662 /*
663 * Retrieve the CPU parent path by removing the last '/' and the CPU name
664 * from the CPU canonical path.
665 */
666 path[strlen(path) - strlen(name) - 1] = '\0';
667
668 obj = object_resolve_path_type(path, TYPE_CPU_CLUSTER, NULL);
669
670 if (obj == NULL) {
671 /* Return the default process' PID */
672 ret = s->processes[s->process_num - 1].pid;
673 goto out;
674 }
675
676 cluster = CPU_CLUSTER(obj);
677 ret = cluster->cluster_id + 1;
678
679out:
680 g_free(name);
681 g_free(path);
682
683 return ret;
684
685#else
686 /* TODO: In user mode, we should use the task state PID */
687 return s->processes[s->process_num - 1].pid;
688#endif
689}
690
691static GDBProcess *gdb_get_process(const GDBState *s, uint32_t pid)
692{
693 int i;
694
695 if (!pid) {
696 /* 0 means any process, we take the first one */
697 return &s->processes[0];
698 }
699
700 for (i = 0; i < s->process_num; i++) {
701 if (s->processes[i].pid == pid) {
702 return &s->processes[i];
703 }
704 }
705
706 return NULL;
707}
708
709static GDBProcess *gdb_get_cpu_process(const GDBState *s, CPUState *cpu)
710{
711 return gdb_get_process(s, gdb_get_cpu_pid(s, cpu));
712}
713
714static CPUState *find_cpu(uint32_t thread_id)
715{
716 CPUState *cpu;
717
718 CPU_FOREACH(cpu) {
719 if (cpu_gdb_index(cpu) == thread_id) {
720 return cpu;
721 }
722 }
723
724 return NULL;
725}
726
727static CPUState *gdb_get_cpu(const GDBState *s, uint32_t pid, uint32_t tid)
728{
729 GDBProcess *process;
730 CPUState *cpu;
731
732 if (!tid) {
733 /* 0 means any thread, we take the first one */
734 tid = 1;
735 }
736
737 cpu = find_cpu(tid);
738
739 if (cpu == NULL) {
740 return NULL;
741 }
742
743 process = gdb_get_cpu_process(s, cpu);
744
745 if (process->pid != pid) {
746 return NULL;
747 }
748
749 if (!process->attached) {
750 return NULL;
751 }
752
753 return cpu;
754}
755
756static const char *get_feature_xml(const char *p, const char **newp,
757 CPUClass *cc)
758{
759 size_t len;
760 int i;
761 const char *name;
762 static char target_xml[1024];
763
764 len = 0;
765 while (p[len] && p[len] != ':')
766 len++;
767 *newp = p + len;
768
769 name = NULL;
770 if (strncmp(p, "target.xml", len) == 0) {
771 /* Generate the XML description for this CPU. */
772 if (!target_xml[0]) {
773 GDBRegisterState *r;
774 CPUState *cpu = first_cpu;
775
776 pstrcat(target_xml, sizeof(target_xml),
777 "<?xml version=\"1.0\"?>"
778 "<!DOCTYPE target SYSTEM \"gdb-target.dtd\">"
779 "<target>");
780 if (cc->gdb_arch_name) {
781 gchar *arch = cc->gdb_arch_name(cpu);
782 pstrcat(target_xml, sizeof(target_xml), "<architecture>");
783 pstrcat(target_xml, sizeof(target_xml), arch);
784 pstrcat(target_xml, sizeof(target_xml), "</architecture>");
785 g_free(arch);
786 }
787 pstrcat(target_xml, sizeof(target_xml), "<xi:include href=\"");
788 pstrcat(target_xml, sizeof(target_xml), cc->gdb_core_xml_file);
789 pstrcat(target_xml, sizeof(target_xml), "\"/>");
790 for (r = cpu->gdb_regs; r; r = r->next) {
791 pstrcat(target_xml, sizeof(target_xml), "<xi:include href=\"");
792 pstrcat(target_xml, sizeof(target_xml), r->xml);
793 pstrcat(target_xml, sizeof(target_xml), "\"/>");
794 }
795 pstrcat(target_xml, sizeof(target_xml), "</target>");
796 }
797 return target_xml;
798 }
799 if (cc->gdb_get_dynamic_xml) {
800 CPUState *cpu = first_cpu;
801 char *xmlname = g_strndup(p, len);
802 const char *xml = cc->gdb_get_dynamic_xml(cpu, xmlname);
803
804 g_free(xmlname);
805 if (xml) {
806 return xml;
807 }
808 }
809 for (i = 0; ; i++) {
810 name = xml_builtin[i][0];
811 if (!name || (strncmp(name, p, len) == 0 && strlen(name) == len))
812 break;
813 }
814 return name ? xml_builtin[i][1] : NULL;
815}
816
817static int gdb_read_register(CPUState *cpu, uint8_t *mem_buf, int reg)
818{
819 CPUClass *cc = CPU_GET_CLASS(cpu);
820 CPUArchState *env = cpu->env_ptr;
821 GDBRegisterState *r;
822
823 if (reg < cc->gdb_num_core_regs) {
824 return cc->gdb_read_register(cpu, mem_buf, reg);
825 }
826
827 for (r = cpu->gdb_regs; r; r = r->next) {
828 if (r->base_reg <= reg && reg < r->base_reg + r->num_regs) {
829 return r->get_reg(env, mem_buf, reg - r->base_reg);
830 }
831 }
832 return 0;
833}
834
835static int gdb_write_register(CPUState *cpu, uint8_t *mem_buf, int reg)
836{
837 CPUClass *cc = CPU_GET_CLASS(cpu);
838 CPUArchState *env = cpu->env_ptr;
839 GDBRegisterState *r;
840
841 if (reg < cc->gdb_num_core_regs) {
842 return cc->gdb_write_register(cpu, mem_buf, reg);
843 }
844
845 for (r = cpu->gdb_regs; r; r = r->next) {
846 if (r->base_reg <= reg && reg < r->base_reg + r->num_regs) {
847 return r->set_reg(env, mem_buf, reg - r->base_reg);
848 }
849 }
850 return 0;
851}
852
853/* Register a supplemental set of CPU registers. If g_pos is nonzero it
854 specifies the first register number and these registers are included in
855 a standard "g" packet. Direction is relative to gdb, i.e. get_reg is
856 gdb reading a CPU register, and set_reg is gdb modifying a CPU register.
857 */
858
859void gdb_register_coprocessor(CPUState *cpu,
860 gdb_reg_cb get_reg, gdb_reg_cb set_reg,
861 int num_regs, const char *xml, int g_pos)
862{
863 GDBRegisterState *s;
864 GDBRegisterState **p;
865
866 p = &cpu->gdb_regs;
867 while (*p) {
868 /* Check for duplicates. */
869 if (strcmp((*p)->xml, xml) == 0)
870 return;
871 p = &(*p)->next;
872 }
873
874 s = g_new0(GDBRegisterState, 1);
875 s->base_reg = cpu->gdb_num_regs;
876 s->num_regs = num_regs;
877 s->get_reg = get_reg;
878 s->set_reg = set_reg;
879 s->xml = xml;
880
881 /* Add to end of list. */
882 cpu->gdb_num_regs += num_regs;
883 *p = s;
884 if (g_pos) {
885 if (g_pos != s->base_reg) {
886 error_report("Error: Bad gdb register numbering for '%s', "
887 "expected %d got %d", xml, g_pos, s->base_reg);
888 } else {
889 cpu->gdb_num_g_regs = cpu->gdb_num_regs;
890 }
891 }
892}
893
894#ifndef CONFIG_USER_ONLY
895/* Translate GDB watchpoint type to a flags value for cpu_watchpoint_* */
896static inline int xlat_gdb_type(CPUState *cpu, int gdbtype)
897{
898 static const int xlat[] = {
899 [GDB_WATCHPOINT_WRITE] = BP_GDB | BP_MEM_WRITE,
900 [GDB_WATCHPOINT_READ] = BP_GDB | BP_MEM_READ,
901 [GDB_WATCHPOINT_ACCESS] = BP_GDB | BP_MEM_ACCESS,
902 };
903
904 CPUClass *cc = CPU_GET_CLASS(cpu);
905 int cputype = xlat[gdbtype];
906
907 if (cc->gdb_stop_before_watchpoint) {
908 cputype |= BP_STOP_BEFORE_ACCESS;
909 }
910 return cputype;
911}
912#endif
913
914static int gdb_breakpoint_insert(target_ulong addr, target_ulong len, int type)
915{
916 CPUState *cpu;
917 int err = 0;
918
919 if (kvm_enabled()) {
920 return kvm_insert_breakpoint(gdbserver_state->c_cpu, addr, len, type);
921 }
922
923 switch (type) {
924 case GDB_BREAKPOINT_SW:
925 case GDB_BREAKPOINT_HW:
926 CPU_FOREACH(cpu) {
927 err = cpu_breakpoint_insert(cpu, addr, BP_GDB, NULL);
928 if (err) {
929 break;
930 }
931 }
932 return err;
933#ifndef CONFIG_USER_ONLY
934 case GDB_WATCHPOINT_WRITE:
935 case GDB_WATCHPOINT_READ:
936 case GDB_WATCHPOINT_ACCESS:
937 CPU_FOREACH(cpu) {
938 err = cpu_watchpoint_insert(cpu, addr, len,
939 xlat_gdb_type(cpu, type), NULL);
940 if (err) {
941 break;
942 }
943 }
944 return err;
945#endif
946 default:
947 return -ENOSYS;
948 }
949}
950
951static int gdb_breakpoint_remove(target_ulong addr, target_ulong len, int type)
952{
953 CPUState *cpu;
954 int err = 0;
955
956 if (kvm_enabled()) {
957 return kvm_remove_breakpoint(gdbserver_state->c_cpu, addr, len, type);
958 }
959
960 switch (type) {
961 case GDB_BREAKPOINT_SW:
962 case GDB_BREAKPOINT_HW:
963 CPU_FOREACH(cpu) {
964 err = cpu_breakpoint_remove(cpu, addr, BP_GDB);
965 if (err) {
966 break;
967 }
968 }
969 return err;
970#ifndef CONFIG_USER_ONLY
971 case GDB_WATCHPOINT_WRITE:
972 case GDB_WATCHPOINT_READ:
973 case GDB_WATCHPOINT_ACCESS:
974 CPU_FOREACH(cpu) {
975 err = cpu_watchpoint_remove(cpu, addr, len,
976 xlat_gdb_type(cpu, type));
977 if (err)
978 break;
979 }
980 return err;
981#endif
982 default:
983 return -ENOSYS;
984 }
985}
986
987static void gdb_breakpoint_remove_all(void)
988{
989 CPUState *cpu;
990
991 if (kvm_enabled()) {
992 kvm_remove_all_breakpoints(gdbserver_state->c_cpu);
993 return;
994 }
995
996 CPU_FOREACH(cpu) {
997 cpu_breakpoint_remove_all(cpu, BP_GDB);
998#ifndef CONFIG_USER_ONLY
999 cpu_watchpoint_remove_all(cpu, BP_GDB);
1000#endif
1001 }
1002}
1003
1004static void gdb_set_cpu_pc(GDBState *s, target_ulong pc)
1005{
1006 CPUState *cpu = s->c_cpu;
1007
1008 cpu_synchronize_state(cpu);
1009 cpu_set_pc(cpu, pc);
1010}
1011
1012static char *gdb_fmt_thread_id(const GDBState *s, CPUState *cpu,
1013 char *buf, size_t buf_size)
1014{
1015 if (s->multiprocess) {
1016 snprintf(buf, buf_size, "p%02x.%02x",
1017 gdb_get_cpu_pid(s, cpu), cpu_gdb_index(cpu));
1018 } else {
1019 snprintf(buf, buf_size, "%02x", cpu_gdb_index(cpu));
1020 }
1021
1022 return buf;
1023}
1024
1025typedef enum GDBThreadIdKind {
1026 GDB_ONE_THREAD = 0,
1027 GDB_ALL_THREADS, /* One process, all threads */
1028 GDB_ALL_PROCESSES,
1029 GDB_READ_THREAD_ERR
1030} GDBThreadIdKind;
1031
1032static GDBThreadIdKind read_thread_id(const char *buf, const char **end_buf,
1033 uint32_t *pid, uint32_t *tid)
1034{
1035 unsigned long p, t;
1036 int ret;
1037
1038 if (*buf == 'p') {
1039 buf++;
1040 ret = qemu_strtoul(buf, &buf, 16, &p);
1041
1042 if (ret) {
1043 return GDB_READ_THREAD_ERR;
1044 }
1045
1046 /* Skip '.' */
1047 buf++;
1048 } else {
1049 p = 1;
1050 }
1051
1052 ret = qemu_strtoul(buf, &buf, 16, &t);
1053
1054 if (ret) {
1055 return GDB_READ_THREAD_ERR;
1056 }
1057
1058 *end_buf = buf;
1059
1060 if (p == -1) {
1061 return GDB_ALL_PROCESSES;
1062 }
1063
1064 if (pid) {
1065 *pid = p;
1066 }
1067
1068 if (t == -1) {
1069 return GDB_ALL_THREADS;
1070 }
1071
1072 if (tid) {
1073 *tid = t;
1074 }
1075
1076 return GDB_ONE_THREAD;
1077}
1078
1079static int is_query_packet(const char *p, const char *query, char separator)
1080{
1081 unsigned int query_len = strlen(query);
1082
1083 return strncmp(p, query, query_len) == 0 &&
1084 (p[query_len] == '\0' || p[query_len] == separator);
1085}
1086
1087/**
1088 * gdb_handle_vcont - Parses and handles a vCont packet.
1089 * returns -ENOTSUP if a command is unsupported, -EINVAL or -ERANGE if there is
1090 * a format error, 0 on success.
1091 */
1092static int gdb_handle_vcont(GDBState *s, const char *p)
1093{
1094 int res, idx, signal = 0;
1095 char cur_action;
1096 char *newstates;
1097 unsigned long tmp;
1098 CPUState *cpu;
1099#ifdef CONFIG_USER_ONLY
1100 int max_cpus = 1; /* global variable max_cpus exists only in system mode */
1101
1102 CPU_FOREACH(cpu) {
1103 max_cpus = max_cpus <= cpu->cpu_index ? cpu->cpu_index + 1 : max_cpus;
1104 }
1105#endif
1106 /* uninitialised CPUs stay 0 */
1107 newstates = g_new0(char, max_cpus);
1108
1109 /* mark valid CPUs with 1 */
1110 CPU_FOREACH(cpu) {
1111 newstates[cpu->cpu_index] = 1;
1112 }
1113
1114 /*
1115 * res keeps track of what error we are returning, with -ENOTSUP meaning
1116 * that the command is unknown or unsupported, thus returning an empty
1117 * packet, while -EINVAL and -ERANGE cause an E22 packet, due to invalid,
1118 * or incorrect parameters passed.
1119 */
1120 res = 0;
1121 while (*p) {
1122 if (*p++ != ';') {
1123 res = -ENOTSUP;
1124 goto out;
1125 }
1126
1127 cur_action = *p++;
1128 if (cur_action == 'C' || cur_action == 'S') {
1129 cur_action = qemu_tolower(cur_action);
1130 res = qemu_strtoul(p + 1, &p, 16, &tmp);
1131 if (res) {
1132 goto out;
1133 }
1134 signal = gdb_signal_to_target(tmp);
1135 } else if (cur_action != 'c' && cur_action != 's') {
1136 /* unknown/invalid/unsupported command */
1137 res = -ENOTSUP;
1138 goto out;
1139 }
1140 /* thread specification. special values: (none), -1 = all; 0 = any */
1141 if ((p[0] == ':' && p[1] == '-' && p[2] == '1') || (p[0] != ':')) {
1142 if (*p == ':') {
1143 p += 3;
1144 }
1145 for (idx = 0; idx < max_cpus; idx++) {
1146 if (newstates[idx] == 1) {
1147 newstates[idx] = cur_action;
1148 }
1149 }
1150 } else if (*p == ':') {
1151 p++;
1152 res = qemu_strtoul(p, &p, 16, &tmp);
1153 if (res) {
1154 goto out;
1155 }
1156
1157 /* 0 means any thread, so we pick the first valid CPU */
1158 cpu = tmp ? find_cpu(tmp) : first_cpu;
1159
1160 /* invalid CPU/thread specified */
1161 if (!cpu) {
1162 res = -EINVAL;
1163 goto out;
1164 }
1165
1166 /* only use if no previous match occourred */
1167 if (newstates[cpu->cpu_index] == 1) {
1168 newstates[cpu->cpu_index] = cur_action;
1169 }
1170 }
1171 }
1172 s->signal = signal;
1173 gdb_continue_partial(s, newstates);
1174
1175out:
1176 g_free(newstates);
1177
1178 return res;
1179}
1180
1181static int gdb_handle_packet(GDBState *s, const char *line_buf)
1182{
1183 CPUState *cpu;
1184 CPUClass *cc;
1185 const char *p;
1186 uint32_t thread;
1187 uint32_t pid, tid;
1188 int ch, reg_size, type, res;
1189 uint8_t mem_buf[MAX_PACKET_LENGTH];
1190 char buf[sizeof(mem_buf) + 1 /* trailing NUL */];
1191 char thread_id[16];
1192 uint8_t *registers;
1193 target_ulong addr, len;
1194 GDBThreadIdKind thread_kind;
1195
1196 trace_gdbstub_io_command(line_buf);
1197
1198 p = line_buf;
1199 ch = *p++;
1200 switch(ch) {
1201 case '?':
1202 /* TODO: Make this return the correct value for user-mode. */
1203 snprintf(buf, sizeof(buf), "T%02xthread:%s;", GDB_SIGNAL_TRAP,
1204 gdb_fmt_thread_id(s, s->c_cpu, thread_id, sizeof(thread_id)));
1205 put_packet(s, buf);
1206 /* Remove all the breakpoints when this query is issued,
1207 * because gdb is doing and initial connect and the state
1208 * should be cleaned up.
1209 */
1210 gdb_breakpoint_remove_all();
1211 break;
1212 case 'c':
1213 if (*p != '\0') {
1214 addr = strtoull(p, (char **)&p, 16);
1215 gdb_set_cpu_pc(s, addr);
1216 }
1217 s->signal = 0;
1218 gdb_continue(s);
1219 return RS_IDLE;
1220 case 'C':
1221 s->signal = gdb_signal_to_target (strtoul(p, (char **)&p, 16));
1222 if (s->signal == -1)
1223 s->signal = 0;
1224 gdb_continue(s);
1225 return RS_IDLE;
1226 case 'v':
1227 if (strncmp(p, "Cont", 4) == 0) {
1228 p += 4;
1229 if (*p == '?') {
1230 put_packet(s, "vCont;c;C;s;S");
1231 break;
1232 }
1233
1234 res = gdb_handle_vcont(s, p);
1235
1236 if (res) {
1237 if ((res == -EINVAL) || (res == -ERANGE)) {
1238 put_packet(s, "E22");
1239 break;
1240 }
1241 goto unknown_command;
1242 }
1243 break;
1244 } else {
1245 goto unknown_command;
1246 }
1247 case 'k':
1248 /* Kill the target */
1249 error_report("QEMU: Terminated via GDBstub");
1250 exit(0);
1251 case 'D':
1252 /* Detach packet */
1253 gdb_breakpoint_remove_all();
1254 gdb_syscall_mode = GDB_SYS_DISABLED;
1255 gdb_continue(s);
1256 put_packet(s, "OK");
1257 break;
1258 case 's':
1259 if (*p != '\0') {
1260 addr = strtoull(p, (char **)&p, 16);
1261 gdb_set_cpu_pc(s, addr);
1262 }
1263 cpu_single_step(s->c_cpu, sstep_flags);
1264 gdb_continue(s);
1265 return RS_IDLE;
1266 case 'F':
1267 {
1268 target_ulong ret;
1269 target_ulong err;
1270
1271 ret = strtoull(p, (char **)&p, 16);
1272 if (*p == ',') {
1273 p++;
1274 err = strtoull(p, (char **)&p, 16);
1275 } else {
1276 err = 0;
1277 }
1278 if (*p == ',')
1279 p++;
1280 type = *p;
1281 if (s->current_syscall_cb) {
1282 s->current_syscall_cb(s->c_cpu, ret, err);
1283 s->current_syscall_cb = NULL;
1284 }
1285 if (type == 'C') {
1286 put_packet(s, "T02");
1287 } else {
1288 gdb_continue(s);
1289 }
1290 }
1291 break;
1292 case 'g':
1293 cpu_synchronize_state(s->g_cpu);
1294 len = 0;
1295 for (addr = 0; addr < s->g_cpu->gdb_num_g_regs; addr++) {
1296 reg_size = gdb_read_register(s->g_cpu, mem_buf + len, addr);
1297 len += reg_size;
1298 }
1299 memtohex(buf, mem_buf, len);
1300 put_packet(s, buf);
1301 break;
1302 case 'G':
1303 cpu_synchronize_state(s->g_cpu);
1304 registers = mem_buf;
1305 len = strlen(p) / 2;
1306 hextomem((uint8_t *)registers, p, len);
1307 for (addr = 0; addr < s->g_cpu->gdb_num_g_regs && len > 0; addr++) {
1308 reg_size = gdb_write_register(s->g_cpu, registers, addr);
1309 len -= reg_size;
1310 registers += reg_size;
1311 }
1312 put_packet(s, "OK");
1313 break;
1314 case 'm':
1315 addr = strtoull(p, (char **)&p, 16);
1316 if (*p == ',')
1317 p++;
1318 len = strtoull(p, NULL, 16);
1319
1320 /* memtohex() doubles the required space */
1321 if (len > MAX_PACKET_LENGTH / 2) {
1322 put_packet (s, "E22");
1323 break;
1324 }
1325
1326 if (target_memory_rw_debug(s->g_cpu, addr, mem_buf, len, false) != 0) {
1327 put_packet (s, "E14");
1328 } else {
1329 memtohex(buf, mem_buf, len);
1330 put_packet(s, buf);
1331 }
1332 break;
1333 case 'M':
1334 addr = strtoull(p, (char **)&p, 16);
1335 if (*p == ',')
1336 p++;
1337 len = strtoull(p, (char **)&p, 16);
1338 if (*p == ':')
1339 p++;
1340
1341 /* hextomem() reads 2*len bytes */
1342 if (len > strlen(p) / 2) {
1343 put_packet (s, "E22");
1344 break;
1345 }
1346 hextomem(mem_buf, p, len);
1347 if (target_memory_rw_debug(s->g_cpu, addr, mem_buf, len,
1348 true) != 0) {
1349 put_packet(s, "E14");
1350 } else {
1351 put_packet(s, "OK");
1352 }
1353 break;
1354 case 'p':
1355 /* Older gdb are really dumb, and don't use 'g' if 'p' is avaialable.
1356 This works, but can be very slow. Anything new enough to
1357 understand XML also knows how to use this properly. */
1358 if (!gdb_has_xml)
1359 goto unknown_command;
1360 addr = strtoull(p, (char **)&p, 16);
1361 reg_size = gdb_read_register(s->g_cpu, mem_buf, addr);
1362 if (reg_size) {
1363 memtohex(buf, mem_buf, reg_size);
1364 put_packet(s, buf);
1365 } else {
1366 put_packet(s, "E14");
1367 }
1368 break;
1369 case 'P':
1370 if (!gdb_has_xml)
1371 goto unknown_command;
1372 addr = strtoull(p, (char **)&p, 16);
1373 if (*p == '=')
1374 p++;
1375 reg_size = strlen(p) / 2;
1376 hextomem(mem_buf, p, reg_size);
1377 gdb_write_register(s->g_cpu, mem_buf, addr);
1378 put_packet(s, "OK");
1379 break;
1380 case 'Z':
1381 case 'z':
1382 type = strtoul(p, (char **)&p, 16);
1383 if (*p == ',')
1384 p++;
1385 addr = strtoull(p, (char **)&p, 16);
1386 if (*p == ',')
1387 p++;
1388 len = strtoull(p, (char **)&p, 16);
1389 if (ch == 'Z')
1390 res = gdb_breakpoint_insert(addr, len, type);
1391 else
1392 res = gdb_breakpoint_remove(addr, len, type);
1393 if (res >= 0)
1394 put_packet(s, "OK");
1395 else if (res == -ENOSYS)
1396 put_packet(s, "");
1397 else
1398 put_packet(s, "E22");
1399 break;
1400 case 'H':
1401 type = *p++;
1402
1403 thread_kind = read_thread_id(p, &p, &pid, &tid);
1404 if (thread_kind == GDB_READ_THREAD_ERR) {
1405 put_packet(s, "E22");
1406 break;
1407 }
1408
1409 if (thread_kind != GDB_ONE_THREAD) {
1410 put_packet(s, "OK");
1411 break;
1412 }
1413 cpu = gdb_get_cpu(s, pid, tid);
1414 if (cpu == NULL) {
1415 put_packet(s, "E22");
1416 break;
1417 }
1418 switch (type) {
1419 case 'c':
1420 s->c_cpu = cpu;
1421 put_packet(s, "OK");
1422 break;
1423 case 'g':
1424 s->g_cpu = cpu;
1425 put_packet(s, "OK");
1426 break;
1427 default:
1428 put_packet(s, "E22");
1429 break;
1430 }
1431 break;
1432 case 'T':
1433 thread_kind = read_thread_id(p, &p, &pid, &tid);
1434 if (thread_kind == GDB_READ_THREAD_ERR) {
1435 put_packet(s, "E22");
1436 break;
1437 }
1438 cpu = gdb_get_cpu(s, pid, tid);
1439
1440 if (cpu != NULL) {
1441 put_packet(s, "OK");
1442 } else {
1443 put_packet(s, "E22");
1444 }
1445 break;
1446 case 'q':
1447 case 'Q':
1448 /* parse any 'q' packets here */
1449 if (!strcmp(p,"qemu.sstepbits")) {
1450 /* Query Breakpoint bit definitions */
1451 snprintf(buf, sizeof(buf), "ENABLE=%x,NOIRQ=%x,NOTIMER=%x",
1452 SSTEP_ENABLE,
1453 SSTEP_NOIRQ,
1454 SSTEP_NOTIMER);
1455 put_packet(s, buf);
1456 break;
1457 } else if (is_query_packet(p, "qemu.sstep", '=')) {
1458 /* Display or change the sstep_flags */
1459 p += 10;
1460 if (*p != '=') {
1461 /* Display current setting */
1462 snprintf(buf, sizeof(buf), "0x%x", sstep_flags);
1463 put_packet(s, buf);
1464 break;
1465 }
1466 p++;
1467 type = strtoul(p, (char **)&p, 16);
1468 sstep_flags = type;
1469 put_packet(s, "OK");
1470 break;
1471 } else if (strcmp(p,"C") == 0) {
1472 /* "Current thread" remains vague in the spec, so always return
1473 * the first CPU (gdb returns the first thread). */
1474 put_packet(s, "QC1");
1475 break;
1476 } else if (strcmp(p,"fThreadInfo") == 0) {
1477 s->query_cpu = first_cpu;
1478 goto report_cpuinfo;
1479 } else if (strcmp(p,"sThreadInfo") == 0) {
1480 report_cpuinfo:
1481 if (s->query_cpu) {
1482 snprintf(buf, sizeof(buf), "m%x", cpu_gdb_index(s->query_cpu));
1483 put_packet(s, buf);
1484 s->query_cpu = CPU_NEXT(s->query_cpu);
1485 } else
1486 put_packet(s, "l");
1487 break;
1488 } else if (strncmp(p,"ThreadExtraInfo,", 16) == 0) {
1489 thread = strtoull(p+16, (char **)&p, 16);
1490 cpu = find_cpu(thread);
1491 if (cpu != NULL) {
1492 cpu_synchronize_state(cpu);
1493 /* memtohex() doubles the required space */
1494 len = snprintf((char *)mem_buf, sizeof(buf) / 2,
1495 "CPU#%d [%s]", cpu->cpu_index,
1496 cpu->halted ? "halted " : "running");
1497 trace_gdbstub_op_extra_info((char *)mem_buf);
1498 memtohex(buf, mem_buf, len);
1499 put_packet(s, buf);
1500 }
1501 break;
1502 }
1503#ifdef CONFIG_USER_ONLY
1504 else if (strcmp(p, "Offsets") == 0) {
1505 TaskState *ts = s->c_cpu->opaque;
1506
1507 snprintf(buf, sizeof(buf),
1508 "Text=" TARGET_ABI_FMT_lx ";Data=" TARGET_ABI_FMT_lx
1509 ";Bss=" TARGET_ABI_FMT_lx,
1510 ts->info->code_offset,
1511 ts->info->data_offset,
1512 ts->info->data_offset);
1513 put_packet(s, buf);
1514 break;
1515 }
1516#else /* !CONFIG_USER_ONLY */
1517 else if (strncmp(p, "Rcmd,", 5) == 0) {
1518 int len = strlen(p + 5);
1519
1520 if ((len % 2) != 0) {
1521 put_packet(s, "E01");
1522 break;
1523 }
1524 len = len / 2;
1525 hextomem(mem_buf, p + 5, len);
1526 mem_buf[len++] = 0;
1527 qemu_chr_be_write(s->mon_chr, mem_buf, len);
1528 put_packet(s, "OK");
1529 break;
1530 }
1531#endif /* !CONFIG_USER_ONLY */
1532 if (is_query_packet(p, "Supported", ':')) {
1533 snprintf(buf, sizeof(buf), "PacketSize=%x", MAX_PACKET_LENGTH);
1534 cc = CPU_GET_CLASS(first_cpu);
1535 if (cc->gdb_core_xml_file != NULL) {
1536 pstrcat(buf, sizeof(buf), ";qXfer:features:read+");
1537 }
1538 put_packet(s, buf);
1539 break;
1540 }
1541 if (strncmp(p, "Xfer:features:read:", 19) == 0) {
1542 const char *xml;
1543 target_ulong total_len;
1544
1545 cc = CPU_GET_CLASS(first_cpu);
1546 if (cc->gdb_core_xml_file == NULL) {
1547 goto unknown_command;
1548 }
1549
1550 gdb_has_xml = true;
1551 p += 19;
1552 xml = get_feature_xml(p, &p, cc);
1553 if (!xml) {
1554 snprintf(buf, sizeof(buf), "E00");
1555 put_packet(s, buf);
1556 break;
1557 }
1558
1559 if (*p == ':')
1560 p++;
1561 addr = strtoul(p, (char **)&p, 16);
1562 if (*p == ',')
1563 p++;
1564 len = strtoul(p, (char **)&p, 16);
1565
1566 total_len = strlen(xml);
1567 if (addr > total_len) {
1568 snprintf(buf, sizeof(buf), "E00");
1569 put_packet(s, buf);
1570 break;
1571 }
1572 if (len > (MAX_PACKET_LENGTH - 5) / 2)
1573 len = (MAX_PACKET_LENGTH - 5) / 2;
1574 if (len < total_len - addr) {
1575 buf[0] = 'm';
1576 len = memtox(buf + 1, xml + addr, len);
1577 } else {
1578 buf[0] = 'l';
1579 len = memtox(buf + 1, xml + addr, total_len - addr);
1580 }
1581 put_packet_binary(s, buf, len + 1, true);
1582 break;
1583 }
1584 if (is_query_packet(p, "Attached", ':')) {
1585 put_packet(s, GDB_ATTACHED);
1586 break;
1587 }
1588 /* Unrecognised 'q' command. */
1589 goto unknown_command;
1590
1591 default:
1592 unknown_command:
1593 /* put empty packet */
1594 buf[0] = '\0';
1595 put_packet(s, buf);
1596 break;
1597 }
1598 return RS_IDLE;
1599}
1600
1601void gdb_set_stop_cpu(CPUState *cpu)
1602{
1603 gdbserver_state->c_cpu = cpu;
1604 gdbserver_state->g_cpu = cpu;
1605}
1606
1607#ifndef CONFIG_USER_ONLY
1608static void gdb_vm_state_change(void *opaque, int running, RunState state)
1609{
1610 GDBState *s = gdbserver_state;
1611 CPUState *cpu = s->c_cpu;
1612 char buf[256];
1613 const char *type;
1614 int ret;
1615
1616 if (running || s->state == RS_INACTIVE) {
1617 return;
1618 }
1619 /* Is there a GDB syscall waiting to be sent? */
1620 if (s->current_syscall_cb) {
1621 put_packet(s, s->syscall_buf);
1622 return;
1623 }
1624 switch (state) {
1625 case RUN_STATE_DEBUG:
1626 if (cpu->watchpoint_hit) {
1627 switch (cpu->watchpoint_hit->flags & BP_MEM_ACCESS) {
1628 case BP_MEM_READ:
1629 type = "r";
1630 break;
1631 case BP_MEM_ACCESS:
1632 type = "a";
1633 break;
1634 default:
1635 type = "";
1636 break;
1637 }
1638 trace_gdbstub_hit_watchpoint(type, cpu_gdb_index(cpu),
1639 (target_ulong)cpu->watchpoint_hit->vaddr);
1640 snprintf(buf, sizeof(buf),
1641 "T%02xthread:%02x;%swatch:" TARGET_FMT_lx ";",
1642 GDB_SIGNAL_TRAP, cpu_gdb_index(cpu), type,
1643 (target_ulong)cpu->watchpoint_hit->vaddr);
1644 cpu->watchpoint_hit = NULL;
1645 goto send_packet;
1646 } else {
1647 trace_gdbstub_hit_break();
1648 }
1649 tb_flush(cpu);
1650 ret = GDB_SIGNAL_TRAP;
1651 break;
1652 case RUN_STATE_PAUSED:
1653 trace_gdbstub_hit_paused();
1654 ret = GDB_SIGNAL_INT;
1655 break;
1656 case RUN_STATE_SHUTDOWN:
1657 trace_gdbstub_hit_shutdown();
1658 ret = GDB_SIGNAL_QUIT;
1659 break;
1660 case RUN_STATE_IO_ERROR:
1661 trace_gdbstub_hit_io_error();
1662 ret = GDB_SIGNAL_IO;
1663 break;
1664 case RUN_STATE_WATCHDOG:
1665 trace_gdbstub_hit_watchdog();
1666 ret = GDB_SIGNAL_ALRM;
1667 break;
1668 case RUN_STATE_INTERNAL_ERROR:
1669 trace_gdbstub_hit_internal_error();
1670 ret = GDB_SIGNAL_ABRT;
1671 break;
1672 case RUN_STATE_SAVE_VM:
1673 case RUN_STATE_RESTORE_VM:
1674 return;
1675 case RUN_STATE_FINISH_MIGRATE:
1676 ret = GDB_SIGNAL_XCPU;
1677 break;
1678 default:
1679 trace_gdbstub_hit_unknown(state);
1680 ret = GDB_SIGNAL_UNKNOWN;
1681 break;
1682 }
1683 gdb_set_stop_cpu(cpu);
1684 snprintf(buf, sizeof(buf), "T%02xthread:%02x;", ret, cpu_gdb_index(cpu));
1685
1686send_packet:
1687 put_packet(s, buf);
1688
1689 /* disable single step if it was enabled */
1690 cpu_single_step(cpu, 0);
1691}
1692#endif
1693
1694/* Send a gdb syscall request.
1695 This accepts limited printf-style format specifiers, specifically:
1696 %x - target_ulong argument printed in hex.
1697 %lx - 64-bit argument printed in hex.
1698 %s - string pointer (target_ulong) and length (int) pair. */
1699void gdb_do_syscallv(gdb_syscall_complete_cb cb, const char *fmt, va_list va)
1700{
1701 char *p;
1702 char *p_end;
1703 target_ulong addr;
1704 uint64_t i64;
1705 GDBState *s;
1706
1707 s = gdbserver_state;
1708 if (!s)
1709 return;
1710 s->current_syscall_cb = cb;
1711#ifndef CONFIG_USER_ONLY
1712 vm_stop(RUN_STATE_DEBUG);
1713#endif
1714 p = s->syscall_buf;
1715 p_end = &s->syscall_buf[sizeof(s->syscall_buf)];
1716 *(p++) = 'F';
1717 while (*fmt) {
1718 if (*fmt == '%') {
1719 fmt++;
1720 switch (*fmt++) {
1721 case 'x':
1722 addr = va_arg(va, target_ulong);
1723 p += snprintf(p, p_end - p, TARGET_FMT_lx, addr);
1724 break;
1725 case 'l':
1726 if (*(fmt++) != 'x')
1727 goto bad_format;
1728 i64 = va_arg(va, uint64_t);
1729 p += snprintf(p, p_end - p, "%" PRIx64, i64);
1730 break;
1731 case 's':
1732 addr = va_arg(va, target_ulong);
1733 p += snprintf(p, p_end - p, TARGET_FMT_lx "/%x",
1734 addr, va_arg(va, int));
1735 break;
1736 default:
1737 bad_format:
1738 error_report("gdbstub: Bad syscall format string '%s'",
1739 fmt - 1);
1740 break;
1741 }
1742 } else {
1743 *(p++) = *(fmt++);
1744 }
1745 }
1746 *p = 0;
1747#ifdef CONFIG_USER_ONLY
1748 put_packet(s, s->syscall_buf);
1749 /* Return control to gdb for it to process the syscall request.
1750 * Since the protocol requires that gdb hands control back to us
1751 * using a "here are the results" F packet, we don't need to check
1752 * gdb_handlesig's return value (which is the signal to deliver if
1753 * execution was resumed via a continue packet).
1754 */
1755 gdb_handlesig(s->c_cpu, 0);
1756#else
1757 /* In this case wait to send the syscall packet until notification that
1758 the CPU has stopped. This must be done because if the packet is sent
1759 now the reply from the syscall request could be received while the CPU
1760 is still in the running state, which can cause packets to be dropped
1761 and state transition 'T' packets to be sent while the syscall is still
1762 being processed. */
1763 qemu_cpu_kick(s->c_cpu);
1764#endif
1765}
1766
1767void gdb_do_syscall(gdb_syscall_complete_cb cb, const char *fmt, ...)
1768{
1769 va_list va;
1770
1771 va_start(va, fmt);
1772 gdb_do_syscallv(cb, fmt, va);
1773 va_end(va);
1774}
1775
1776static void gdb_read_byte(GDBState *s, int ch)
1777{
1778 uint8_t reply;
1779
1780#ifndef CONFIG_USER_ONLY
1781 if (s->last_packet_len) {
1782 /* Waiting for a response to the last packet. If we see the start
1783 of a new command then abandon the previous response. */
1784 if (ch == '-') {
1785 trace_gdbstub_err_got_nack();
1786 put_buffer(s, (uint8_t *)s->last_packet, s->last_packet_len);
1787 } else if (ch == '+') {
1788 trace_gdbstub_io_got_ack();
1789 } else {
1790 trace_gdbstub_io_got_unexpected((uint8_t)ch);
1791 }
1792
1793 if (ch == '+' || ch == '$')
1794 s->last_packet_len = 0;
1795 if (ch != '$')
1796 return;
1797 }
1798 if (runstate_is_running()) {
1799 /* when the CPU is running, we cannot do anything except stop
1800 it when receiving a char */
1801 vm_stop(RUN_STATE_PAUSED);
1802 } else
1803#endif
1804 {
1805 switch(s->state) {
1806 case RS_IDLE:
1807 if (ch == '$') {
1808 /* start of command packet */
1809 s->line_buf_index = 0;
1810 s->line_sum = 0;
1811 s->state = RS_GETLINE;
1812 } else {
1813 trace_gdbstub_err_garbage((uint8_t)ch);
1814 }
1815 break;
1816 case RS_GETLINE:
1817 if (ch == '}') {
1818 /* start escape sequence */
1819 s->state = RS_GETLINE_ESC;
1820 s->line_sum += ch;
1821 } else if (ch == '*') {
1822 /* start run length encoding sequence */
1823 s->state = RS_GETLINE_RLE;
1824 s->line_sum += ch;
1825 } else if (ch == '#') {
1826 /* end of command, start of checksum*/
1827 s->state = RS_CHKSUM1;
1828 } else if (s->line_buf_index >= sizeof(s->line_buf) - 1) {
1829 trace_gdbstub_err_overrun();
1830 s->state = RS_IDLE;
1831 } else {
1832 /* unescaped command character */
1833 s->line_buf[s->line_buf_index++] = ch;
1834 s->line_sum += ch;
1835 }
1836 break;
1837 case RS_GETLINE_ESC:
1838 if (ch == '#') {
1839 /* unexpected end of command in escape sequence */
1840 s->state = RS_CHKSUM1;
1841 } else if (s->line_buf_index >= sizeof(s->line_buf) - 1) {
1842 /* command buffer overrun */
1843 trace_gdbstub_err_overrun();
1844 s->state = RS_IDLE;
1845 } else {
1846 /* parse escaped character and leave escape state */
1847 s->line_buf[s->line_buf_index++] = ch ^ 0x20;
1848 s->line_sum += ch;
1849 s->state = RS_GETLINE;
1850 }
1851 break;
1852 case RS_GETLINE_RLE:
1853 if (ch < ' ') {
1854 /* invalid RLE count encoding */
1855 trace_gdbstub_err_invalid_repeat((uint8_t)ch);
1856 s->state = RS_GETLINE;
1857 } else {
1858 /* decode repeat length */
1859 int repeat = (unsigned char)ch - ' ' + 3;
1860 if (s->line_buf_index + repeat >= sizeof(s->line_buf) - 1) {
1861 /* that many repeats would overrun the command buffer */
1862 trace_gdbstub_err_overrun();
1863 s->state = RS_IDLE;
1864 } else if (s->line_buf_index < 1) {
1865 /* got a repeat but we have nothing to repeat */
1866 trace_gdbstub_err_invalid_rle();
1867 s->state = RS_GETLINE;
1868 } else {
1869 /* repeat the last character */
1870 memset(s->line_buf + s->line_buf_index,
1871 s->line_buf[s->line_buf_index - 1], repeat);
1872 s->line_buf_index += repeat;
1873 s->line_sum += ch;
1874 s->state = RS_GETLINE;
1875 }
1876 }
1877 break;
1878 case RS_CHKSUM1:
1879 /* get high hex digit of checksum */
1880 if (!isxdigit(ch)) {
1881 trace_gdbstub_err_checksum_invalid((uint8_t)ch);
1882 s->state = RS_GETLINE;
1883 break;
1884 }
1885 s->line_buf[s->line_buf_index] = '\0';
1886 s->line_csum = fromhex(ch) << 4;
1887 s->state = RS_CHKSUM2;
1888 break;
1889 case RS_CHKSUM2:
1890 /* get low hex digit of checksum */
1891 if (!isxdigit(ch)) {
1892 trace_gdbstub_err_checksum_invalid((uint8_t)ch);
1893 s->state = RS_GETLINE;
1894 break;
1895 }
1896 s->line_csum |= fromhex(ch);
1897
1898 if (s->line_csum != (s->line_sum & 0xff)) {
1899 trace_gdbstub_err_checksum_incorrect(s->line_sum, s->line_csum);
1900 /* send NAK reply */
1901 reply = '-';
1902 put_buffer(s, &reply, 1);
1903 s->state = RS_IDLE;
1904 } else {
1905 /* send ACK reply */
1906 reply = '+';
1907 put_buffer(s, &reply, 1);
1908 s->state = gdb_handle_packet(s, s->line_buf);
1909 }
1910 break;
1911 default:
1912 abort();
1913 }
1914 }
1915}
1916
1917/* Tell the remote gdb that the process has exited. */
1918void gdb_exit(CPUArchState *env, int code)
1919{
1920 GDBState *s;
1921 char buf[4];
1922
1923 s = gdbserver_state;
1924 if (!s) {
1925 return;
1926 }
1927#ifdef CONFIG_USER_ONLY
1928 if (gdbserver_fd < 0 || s->fd < 0) {
1929 return;
1930 }
1931#endif
1932
1933 trace_gdbstub_op_exiting((uint8_t)code);
1934
1935 snprintf(buf, sizeof(buf), "W%02x", (uint8_t)code);
1936 put_packet(s, buf);
1937
1938#ifndef CONFIG_USER_ONLY
1939 qemu_chr_fe_deinit(&s->chr, true);
1940#endif
1941}
1942
1943/*
1944 * Create the process that will contain all the "orphan" CPUs (that are not
1945 * part of a CPU cluster). Note that if this process contains no CPUs, it won't
1946 * be attachable and thus will be invisible to the user.
1947 */
1948static void create_default_process(GDBState *s)
1949{
1950 GDBProcess *process;
1951 int max_pid = 0;
1952
1953 if (s->process_num) {
1954 max_pid = s->processes[s->process_num - 1].pid;
1955 }
1956
1957 s->processes = g_renew(GDBProcess, s->processes, ++s->process_num);
1958 process = &s->processes[s->process_num - 1];
1959
1960 /* We need an available PID slot for this process */
1961 assert(max_pid < UINT32_MAX);
1962
1963 process->pid = max_pid + 1;
1964 process->attached = false;
1965}
1966
1967#ifdef CONFIG_USER_ONLY
1968int
1969gdb_handlesig(CPUState *cpu, int sig)
1970{
1971 GDBState *s;
1972 char buf[256];
1973 int n;
1974
1975 s = gdbserver_state;
1976 if (gdbserver_fd < 0 || s->fd < 0) {
1977 return sig;
1978 }
1979
1980 /* disable single step if it was enabled */
1981 cpu_single_step(cpu, 0);
1982 tb_flush(cpu);
1983
1984 if (sig != 0) {
1985 snprintf(buf, sizeof(buf), "S%02x", target_signal_to_gdb(sig));
1986 put_packet(s, buf);
1987 }
1988 /* put_packet() might have detected that the peer terminated the
1989 connection. */
1990 if (s->fd < 0) {
1991 return sig;
1992 }
1993
1994 sig = 0;
1995 s->state = RS_IDLE;
1996 s->running_state = 0;
1997 while (s->running_state == 0) {
1998 n = read(s->fd, buf, 256);
1999 if (n > 0) {
2000 int i;
2001
2002 for (i = 0; i < n; i++) {
2003 gdb_read_byte(s, buf[i]);
2004 }
2005 } else {
2006 /* XXX: Connection closed. Should probably wait for another
2007 connection before continuing. */
2008 if (n == 0) {
2009 close(s->fd);
2010 }
2011 s->fd = -1;
2012 return sig;
2013 }
2014 }
2015 sig = s->signal;
2016 s->signal = 0;
2017 return sig;
2018}
2019
2020/* Tell the remote gdb that the process has exited due to SIG. */
2021void gdb_signalled(CPUArchState *env, int sig)
2022{
2023 GDBState *s;
2024 char buf[4];
2025
2026 s = gdbserver_state;
2027 if (gdbserver_fd < 0 || s->fd < 0) {
2028 return;
2029 }
2030
2031 snprintf(buf, sizeof(buf), "X%02x", target_signal_to_gdb(sig));
2032 put_packet(s, buf);
2033}
2034
2035static bool gdb_accept(void)
2036{
2037 GDBState *s;
2038 struct sockaddr_in sockaddr;
2039 socklen_t len;
2040 int fd;
2041
2042 for(;;) {
2043 len = sizeof(sockaddr);
2044 fd = accept(gdbserver_fd, (struct sockaddr *)&sockaddr, &len);
2045 if (fd < 0 && errno != EINTR) {
2046 perror("accept");
2047 return false;
2048 } else if (fd >= 0) {
2049 qemu_set_cloexec(fd);
2050 break;
2051 }
2052 }
2053
2054 /* set short latency */
2055 if (socket_set_nodelay(fd)) {
2056 perror("setsockopt");
2057 close(fd);
2058 return false;
2059 }
2060
2061 s = g_malloc0(sizeof(GDBState));
2062 s->c_cpu = first_cpu;
2063 s->g_cpu = first_cpu;
2064 create_default_process(s);
2065 s->fd = fd;
2066 gdb_has_xml = false;
2067
2068 gdbserver_state = s;
2069 return true;
2070}
2071
2072static int gdbserver_open(int port)
2073{
2074 struct sockaddr_in sockaddr;
2075 int fd, ret;
2076
2077 fd = socket(PF_INET, SOCK_STREAM, 0);
2078 if (fd < 0) {
2079 perror("socket");
2080 return -1;
2081 }
2082 qemu_set_cloexec(fd);
2083
2084 socket_set_fast_reuse(fd);
2085
2086 sockaddr.sin_family = AF_INET;
2087 sockaddr.sin_port = htons(port);
2088 sockaddr.sin_addr.s_addr = 0;
2089 ret = bind(fd, (struct sockaddr *)&sockaddr, sizeof(sockaddr));
2090 if (ret < 0) {
2091 perror("bind");
2092 close(fd);
2093 return -1;
2094 }
2095 ret = listen(fd, 1);
2096 if (ret < 0) {
2097 perror("listen");
2098 close(fd);
2099 return -1;
2100 }
2101 return fd;
2102}
2103
2104int gdbserver_start(int port)
2105{
2106 gdbserver_fd = gdbserver_open(port);
2107 if (gdbserver_fd < 0)
2108 return -1;
2109 /* accept connections */
2110 if (!gdb_accept()) {
2111 close(gdbserver_fd);
2112 gdbserver_fd = -1;
2113 return -1;
2114 }
2115 return 0;
2116}
2117
2118/* Disable gdb stub for child processes. */
2119void gdbserver_fork(CPUState *cpu)
2120{
2121 GDBState *s = gdbserver_state;
2122
2123 if (gdbserver_fd < 0 || s->fd < 0) {
2124 return;
2125 }
2126 close(s->fd);
2127 s->fd = -1;
2128 cpu_breakpoint_remove_all(cpu, BP_GDB);
2129 cpu_watchpoint_remove_all(cpu, BP_GDB);
2130}
2131#else
2132static int gdb_chr_can_receive(void *opaque)
2133{
2134 /* We can handle an arbitrarily large amount of data.
2135 Pick the maximum packet size, which is as good as anything. */
2136 return MAX_PACKET_LENGTH;
2137}
2138
2139static void gdb_chr_receive(void *opaque, const uint8_t *buf, int size)
2140{
2141 int i;
2142
2143 for (i = 0; i < size; i++) {
2144 gdb_read_byte(gdbserver_state, buf[i]);
2145 }
2146}
2147
2148static void gdb_chr_event(void *opaque, int event)
2149{
2150 switch (event) {
2151 case CHR_EVENT_OPENED:
2152 vm_stop(RUN_STATE_PAUSED);
2153 gdb_has_xml = false;
2154 break;
2155 default:
2156 break;
2157 }
2158}
2159
2160static void gdb_monitor_output(GDBState *s, const char *msg, int len)
2161{
2162 char buf[MAX_PACKET_LENGTH];
2163
2164 buf[0] = 'O';
2165 if (len > (MAX_PACKET_LENGTH/2) - 1)
2166 len = (MAX_PACKET_LENGTH/2) - 1;
2167 memtohex(buf + 1, (uint8_t *)msg, len);
2168 put_packet(s, buf);
2169}
2170
2171static int gdb_monitor_write(Chardev *chr, const uint8_t *buf, int len)
2172{
2173 const char *p = (const char *)buf;
2174 int max_sz;
2175
2176 max_sz = (sizeof(gdbserver_state->last_packet) - 2) / 2;
2177 for (;;) {
2178 if (len <= max_sz) {
2179 gdb_monitor_output(gdbserver_state, p, len);
2180 break;
2181 }
2182 gdb_monitor_output(gdbserver_state, p, max_sz);
2183 p += max_sz;
2184 len -= max_sz;
2185 }
2186 return len;
2187}
2188
2189#ifndef _WIN32
2190static void gdb_sigterm_handler(int signal)
2191{
2192 if (runstate_is_running()) {
2193 vm_stop(RUN_STATE_PAUSED);
2194 }
2195}
2196#endif
2197
2198static void gdb_monitor_open(Chardev *chr, ChardevBackend *backend,
2199 bool *be_opened, Error **errp)
2200{
2201 *be_opened = false;
2202}
2203
2204static void char_gdb_class_init(ObjectClass *oc, void *data)
2205{
2206 ChardevClass *cc = CHARDEV_CLASS(oc);
2207
2208 cc->internal = true;
2209 cc->open = gdb_monitor_open;
2210 cc->chr_write = gdb_monitor_write;
2211}
2212
2213#define TYPE_CHARDEV_GDB "chardev-gdb"
2214
2215static const TypeInfo char_gdb_type_info = {
2216 .name = TYPE_CHARDEV_GDB,
2217 .parent = TYPE_CHARDEV,
2218 .class_init = char_gdb_class_init,
2219};
2220
2221static int find_cpu_clusters(Object *child, void *opaque)
2222{
2223 if (object_dynamic_cast(child, TYPE_CPU_CLUSTER)) {
2224 GDBState *s = (GDBState *) opaque;
2225 CPUClusterState *cluster = CPU_CLUSTER(child);
2226 GDBProcess *process;
2227
2228 s->processes = g_renew(GDBProcess, s->processes, ++s->process_num);
2229
2230 process = &s->processes[s->process_num - 1];
2231
2232 /*
2233 * GDB process IDs -1 and 0 are reserved. To avoid subtle errors at
2234 * runtime, we enforce here that the machine does not use a cluster ID
2235 * that would lead to PID 0.
2236 */
2237 assert(cluster->cluster_id != UINT32_MAX);
2238 process->pid = cluster->cluster_id + 1;
2239 process->attached = false;
2240
2241 return 0;
2242 }
2243
2244 return object_child_foreach(child, find_cpu_clusters, opaque);
2245}
2246
2247static int pid_order(const void *a, const void *b)
2248{
2249 GDBProcess *pa = (GDBProcess *) a;
2250 GDBProcess *pb = (GDBProcess *) b;
2251
2252 if (pa->pid < pb->pid) {
2253 return -1;
2254 } else if (pa->pid > pb->pid) {
2255 return 1;
2256 } else {
2257 return 0;
2258 }
2259}
2260
2261static void create_processes(GDBState *s)
2262{
2263 object_child_foreach(object_get_root(), find_cpu_clusters, s);
2264
2265 if (s->processes) {
2266 /* Sort by PID */
2267 qsort(s->processes, s->process_num, sizeof(s->processes[0]), pid_order);
2268 }
2269
2270 create_default_process(s);
2271}
2272
2273static void cleanup_processes(GDBState *s)
2274{
2275 g_free(s->processes);
2276 s->process_num = 0;
2277 s->processes = NULL;
2278}
2279
2280int gdbserver_start(const char *device)
2281{
2282 trace_gdbstub_op_start(device);
2283
2284 GDBState *s;
2285 char gdbstub_device_name[128];
2286 Chardev *chr = NULL;
2287 Chardev *mon_chr;
2288
2289 if (!first_cpu) {
2290 error_report("gdbstub: meaningless to attach gdb to a "
2291 "machine without any CPU.");
2292 return -1;
2293 }
2294
2295 if (!device)
2296 return -1;
2297 if (strcmp(device, "none") != 0) {
2298 if (strstart(device, "tcp:", NULL)) {
2299 /* enforce required TCP attributes */
2300 snprintf(gdbstub_device_name, sizeof(gdbstub_device_name),
2301 "%s,nowait,nodelay,server", device);
2302 device = gdbstub_device_name;
2303 }
2304#ifndef _WIN32
2305 else if (strcmp(device, "stdio") == 0) {
2306 struct sigaction act;
2307
2308 memset(&act, 0, sizeof(act));
2309 act.sa_handler = gdb_sigterm_handler;
2310 sigaction(SIGINT, &act, NULL);
2311 }
2312#endif
2313 /*
2314 * FIXME: it's a bit weird to allow using a mux chardev here
2315 * and implicitly setup a monitor. We may want to break this.
2316 */
2317 chr = qemu_chr_new_noreplay("gdb", device, true);
2318 if (!chr)
2319 return -1;
2320 }
2321
2322 s = gdbserver_state;
2323 if (!s) {
2324 s = g_malloc0(sizeof(GDBState));
2325 gdbserver_state = s;
2326
2327 qemu_add_vm_change_state_handler(gdb_vm_state_change, NULL);
2328
2329 /* Initialize a monitor terminal for gdb */
2330 mon_chr = qemu_chardev_new(NULL, TYPE_CHARDEV_GDB,
2331 NULL, &error_abort);
2332 monitor_init(mon_chr, 0);
2333 } else {
2334 qemu_chr_fe_deinit(&s->chr, true);
2335 mon_chr = s->mon_chr;
2336 cleanup_processes(s);
2337 memset(s, 0, sizeof(GDBState));
2338 s->mon_chr = mon_chr;
2339 }
2340 s->c_cpu = first_cpu;
2341 s->g_cpu = first_cpu;
2342
2343 create_processes(s);
2344
2345 if (chr) {
2346 qemu_chr_fe_init(&s->chr, chr, &error_abort);
2347 qemu_chr_fe_set_handlers(&s->chr, gdb_chr_can_receive, gdb_chr_receive,
2348 gdb_chr_event, NULL, NULL, NULL, true);
2349 }
2350 s->state = chr ? RS_IDLE : RS_INACTIVE;
2351 s->mon_chr = mon_chr;
2352 s->current_syscall_cb = NULL;
2353
2354 return 0;
2355}
2356
2357void gdbserver_cleanup(void)
2358{
2359 if (gdbserver_state) {
2360 put_packet(gdbserver_state, "W00");
2361 }
2362}
2363
2364static void register_types(void)
2365{
2366 type_register_static(&char_gdb_type_info);
2367}
2368
2369type_init(register_types);
2370#endif