-
-
Notifications
You must be signed in to change notification settings - Fork 0
/
lldb_disasm.py
250 lines (202 loc) · 8.91 KB
/
lldb_disasm.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
#!/usr/bin/env python
#coding: utf-8
#
# Usage: run `command script import -r misc/lldb_disasm.py` on LLDB
#
#
# (lldb) p iseq
# (rb_iseq_t *) $147 = 0x0000000101068400
# (lldb) rbdisasm iseq
# 0000 putspecialobject( 3 )
# 0002 putnil
# 0003 defineclass( ID: 0x560b, (rb_iseq_t *)0x1010681d0, 2 )
# 0007 pop
# 0008 putspecialobject( 3 )
# 0010 putnil
# 0011 defineclass( ID: 0x56eb, (rb_iseq_t *)0x101063b58, 2 )
# 0015 leave
import lldb
import os
import shlex
class IseqDisassembler:
TS_VARIABLE = b'.'[0]
TS_CALLDATA = b'C'[0]
TS_CDHASH = b'H'[0]
TS_IC = b'K'[0]
TS_IVC = b'A'[0]
TS_ICVARC = b'J'[0]
TS_ID = b'I'[0]
TS_ISE = b'T'[0]
TS_ISEQ = b'S'[0]
TS_OFFSET = b'O'[0]
TS_VALUE = b'V'[0]
TS_LINDEX = b'L'[0]
TS_FUNCPTR = b'F'[0]
TS_NUM = b'N'[0]
TS_BUILTIN = b'R'[0]
ISEQ_OPT_DISPATCH = {
TS_BUILTIN: "(rb_builtin_function *)%0#x",
TS_NUM: "%d",
TS_FUNCPTR: "(rb_insn_func_t) %0#x",
TS_LINDEX: "%d",
TS_VALUE: "(VALUE)%0#x",
TS_OFFSET: "%d",
TS_ISEQ: "(rb_iseq_t *)%0#x",
TS_ISE: "(iseq_inline_storage_entry *)%0#x",
TS_ID: "ID: %0#x",
TS_IVC: "(struct iseq_inline_iv_cache_entry *)%0#x",
TS_ICVARC: "(struct iseq_inline_cvar_cache_entry *)%0#x",
TS_IC: "(struct iseq_inline_cache_entry *)%0#x",
TS_CDHASH: "CDHASH (VALUE)%0#x",
TS_CALLDATA: "(struct rb_call_data *)%0#x",
TS_VARIABLE: "VARIABLE %0#x",
}
def __init__(self, debugger, command, result, internal_dict):
self.debugger = debugger
self.command = command
self.result = result
self.internal_dict = internal_dict
self.target = debugger.GetSelectedTarget()
self.insns_address_table = self.__get_insns_address_table()
self.process = self.target.GetProcess()
self.thread = self.process.GetSelectedThread()
self.frame = self.thread.GetSelectedFrame()
self.addr2insn = self.build_addr2insn(self.target)
self.tChar = self.target.FindFirstType("char")
def disasm(self, val):
tRbISeq = self.target.FindFirstType("struct rb_iseq_struct").GetPointerType()
val = val.Cast(tRbISeq)
iseq_size = val.GetValueForExpressionPath("->body->iseq_size").GetValueAsUnsigned()
iseqs = val.GetValueForExpressionPath("->body->iseq_encoded")
idx = 0
print("PC IDX insn_name(operands) ", file=self.result)
while idx < iseq_size:
m = self.iseq_extract_values(self.debugger, self.target, self.process, self.result, iseqs, idx)
if m < 1:
print("Error decoding", file=self.result)
return
else:
idx += m
def build_addr2insn(self, target):
tIntPtr = target.FindFirstType("intptr_t")
size = target.EvaluateExpression('ruby_vminsn_type::VM_INSTRUCTION_SIZE').unsigned
sizeOfIntPtr = tIntPtr.GetByteSize()
addr_of_table = self.insns_address_table.GetStartAddress().GetLoadAddress(target)
my_dict = {}
for insn in range(size):
addr_in_table = addr_of_table + (insn * sizeOfIntPtr)
addr = lldb.SBAddress(addr_in_table, target)
machine_insn = target.CreateValueFromAddress("insn", addr, tIntPtr).GetValueAsUnsigned()
my_dict[machine_insn] = insn
return my_dict
def rb_vm_insn_addr2insn2(self, target, result, wanted_addr):
return self.addr2insn.get(wanted_addr)
def iseq_extract_values(self, debugger, target, process, result, iseqs, n):
tValueP = target.FindFirstType("VALUE")
sizeofValueP = tValueP.GetByteSize()
pc = iseqs.unsigned + (n * sizeofValueP)
insn = target.CreateValueFromAddress("i", lldb.SBAddress(pc, target), tValueP)
addr = insn.GetValueAsUnsigned()
orig_insn = self.rb_vm_insn_addr2insn2(target, result, addr)
name = self.insn_name(target, process, result, orig_insn)
length = self.insn_len(target, orig_insn)
op_str = self.insn_op_types(target, process, result, orig_insn)
op_types = bytes(op_str, 'utf-8')
if length != (len(op_types) + 1):
print("error decoding iseqs", file=result)
return -1
print("%0#14x %04d %s" % (pc, n, name), file=result, end="")
if length == 1:
print("", file=result)
return length
print("(", end="", file=result)
for idx, op_type in enumerate(op_types):
if idx == 0:
print(" ", end="", file=result)
else:
print(", ", end="", file=result)
opAddr = lldb.SBAddress(iseqs.unsigned + ((n + idx + 1) * sizeofValueP), target)
opValue = target.CreateValueFromAddress("op", opAddr, tValueP)
op = opValue.GetValueAsUnsigned()
print(self.ISEQ_OPT_DISPATCH.get(op_type) % op, end="", file=result)
print(" )", file=result)
return length
def insn_len(self, target, offset):
size_of_char = self.tChar.GetByteSize()
symbol = target.FindSymbols("rb_vm_insn_len_info")[0].GetSymbol()
section = symbol.GetStartAddress().GetSection()
addr_of_table = symbol.GetStartAddress().GetOffset()
error = lldb.SBError()
length = section.GetSectionData().GetUnsignedInt8(error, addr_of_table + (offset * size_of_char))
if error.Success():
return length
else:
print("error getting length: ", error)
def insn_op_types(self, target, process, result, insn):
tUShort = target.FindFirstType("unsigned short")
size_of_short = tUShort.GetByteSize()
size_of_char = self.tChar.GetByteSize()
symbol = target.FindSymbols("rb_vm_insn_op_offset")[0].GetSymbol()
section = symbol.GetStartAddress().GetSection()
addr_of_table = symbol.GetStartAddress().GetOffset()
addr_in_table = addr_of_table + (insn * size_of_short)
error = lldb.SBError()
offset = section.GetSectionData().GetUnsignedInt16(error, addr_in_table)
if not error.Success():
print("error getting op type offset: ", error)
symbol = target.FindSymbols("rb_vm_insn_op_base")[0].GetSymbol()
section = symbol.GetStartAddress().GetSection()
addr_of_table = symbol.GetStartAddress().GetOffset()
addr_in_name_table = addr_of_table + (offset * size_of_char)
error = lldb.SBError()
types = section.GetSectionData().GetString(error, addr_in_name_table)
if error.Success():
return types
else:
print("error getting op types: ", error)
def insn_name_table_offset(self, target, offset):
tUShort = target.FindFirstType("unsigned short")
size_of_short = tUShort.GetByteSize()
symbol = target.FindSymbols("rb_vm_insn_name_offset")[0].GetSymbol()
section = symbol.GetStartAddress().GetSection()
table_offset = symbol.GetStartAddress().GetOffset()
table_offset = table_offset + (offset * size_of_short)
error = lldb.SBError()
offset = section.GetSectionData().GetUnsignedInt16(error, table_offset)
if error.Success():
return offset
else:
print("error getting insn name table offset: ", error)
def insn_name(self, target, process, result, offset):
symbol = target.FindSymbols("rb_vm_insn_name_base")[0].GetSymbol()
section = symbol.GetStartAddress().GetSection()
addr_of_table = symbol.GetStartAddress().GetOffset()
name_table_offset = self.insn_name_table_offset(target, offset)
addr_in_name_table = addr_of_table + name_table_offset
error = lldb.SBError()
name = section.GetSectionData().GetString(error, addr_in_name_table)
if error.Success():
return name
else:
print('error getting insn name', error)
def __get_insns_address_table(self):
module = self.target.FindSymbols("vm_exec_core")[0].GetModule()
for symbol in module:
if "insns_address_table" in symbol.name and symbol.GetType() == lldb.eSymbolTypeData:
print(f"found symbol {symbol.name}")
return symbol
def disasm(debugger, command, result, internal_dict):
disassembler = IseqDisassembler(debugger, command, result, internal_dict)
frame = disassembler.frame
if frame.IsValid():
val = frame.EvaluateExpression(command)
else:
val = target.EvaluateExpression(command)
error = val.GetError()
if error.Fail():
print >> result, error
return
disassembler.disasm(val);
def __lldb_init_module(debugger, internal_dict):
debugger.HandleCommand("command script add -f lldb_disasm.disasm rbdisasm")
print("lldb Ruby disasm installed.")