1#!/usr/bin/python 2 3import lldb 4import struct 5 6class OperatingSystemPlugIn(object): 7 """Class that provides data for an instance of a LLDB 'OperatingSystemPython' plug-in class""" 8 9 def __init__(self, process): 10 '''Initialization needs a valid.SBProcess object. 11 12 This plug-in will get created after a live process is valid and has stopped for the 13 first time.''' 14 self.process = None 15 self.registers = None 16 self.threads = None 17 if type(process) is lldb.SBProcess and process.IsValid(): 18 self.process = process 19 self.threads = None # Will be an dictionary containing info for each thread 20 21 def get_target(self): 22 # NOTE: Don't use "lldb.target" when trying to get your target as the "lldb.target" 23 # tracks the current target in the LLDB command interpreter which isn't the 24 # correct thing to use for this plug-in. 25 return self.process.target 26 27 def create_thread(self, tid, context): 28 if tid == 0x444444444: 29 thread_info = { 'tid' : tid, 'name' : 'four' , 'queue' : 'queue4', 'state' : 'stopped', 'stop_reason' : 'none' } 30 self.threads.append(thread_info) 31 return thread_info 32 return None 33 34 def get_thread_info(self): 35 if not self.threads: 36 # The sample dictionary below shows the values that can be returned for a thread 37 # tid => thread ID (mandatory) 38 # name => thread name (optional key/value pair) 39 # queue => thread dispatch queue name (optional key/value pair) 40 # state => thred state (mandatory, set to 'stopped' for now) 41 # stop_reason => thread stop reason. (mandatory, usually set to 'none') 42 # Possible values include: 43 # 'breakpoint' if the thread is stopped at a breakpoint 44 # 'none' thread is just stopped because the process is stopped 45 # 'trace' the thread just single stepped 46 # The usual value for this while threads are in memory is 'none' 47 # register_data_addr => the address of the register data in memory (optional key/value pair) 48 # Specifying this key/value pair for a thread will avoid a call to get_register_data() 49 # and can be used when your registers are in a thread context structure that is contiguous 50 # in memory. Don't specify this if your register layout in memory doesn't match the layout 51 # described by the dictionary returned from a call to the get_register_info() method. 52 self.threads = [ 53 { 'tid' : 0x111111111, 'name' : 'one' , 'queue' : 'queue1', 'state' : 'stopped', 'stop_reason' : 'breakpoint'}, 54 { 'tid' : 0x222222222, 'name' : 'two' , 'queue' : 'queue2', 'state' : 'stopped', 'stop_reason' : 'none' }, 55 { 'tid' : 0x333333333, 'name' : 'three', 'queue' : 'queue3', 'state' : 'stopped', 'stop_reason' : 'trace' , 'register_data_addr' : 0x100000000 } 56 ] 57 return self.threads 58 59 def get_register_info(self): 60 if self.registers == None: 61 self.registers = dict() 62 triple = self.process.target.triple 63 if triple: 64 arch = triple.split('-')[0] 65 if arch == 'x86_64': 66 self.registers['sets'] = ['GPR', 'FPU', 'EXC'] 67 self.registers['registers'] = [ 68 { 'name':'rax' , 'bitsize' : 64, 'offset' : 0, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 0, 'dwarf' : 0}, 69 { 'name':'rbx' , 'bitsize' : 64, 'offset' : 8, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 3, 'dwarf' : 3}, 70 { 'name':'rcx' , 'bitsize' : 64, 'offset' : 16, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 2, 'dwarf' : 2, 'generic':'arg4', 'alt-name':'arg4', }, 71 { 'name':'rdx' , 'bitsize' : 64, 'offset' : 24, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 1, 'dwarf' : 1, 'generic':'arg3', 'alt-name':'arg3', }, 72 { 'name':'rdi' , 'bitsize' : 64, 'offset' : 32, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 5, 'dwarf' : 5, 'generic':'arg1', 'alt-name':'arg1', }, 73 { 'name':'rsi' , 'bitsize' : 64, 'offset' : 40, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 4, 'dwarf' : 4, 'generic':'arg2', 'alt-name':'arg2', }, 74 { 'name':'rbp' , 'bitsize' : 64, 'offset' : 48, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 6, 'dwarf' : 6, 'generic':'fp' , 'alt-name':'fp', }, 75 { 'name':'rsp' , 'bitsize' : 64, 'offset' : 56, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 7, 'dwarf' : 7, 'generic':'sp' , 'alt-name':'sp', }, 76 { 'name':'r8' , 'bitsize' : 64, 'offset' : 64, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 8, 'dwarf' : 8, 'generic':'arg5', 'alt-name':'arg5', }, 77 { 'name':'r9' , 'bitsize' : 64, 'offset' : 72, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 9, 'dwarf' : 9, 'generic':'arg6', 'alt-name':'arg6', }, 78 { 'name':'r10' , 'bitsize' : 64, 'offset' : 80, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 10, 'dwarf' : 10}, 79 { 'name':'r11' , 'bitsize' : 64, 'offset' : 88, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 11, 'dwarf' : 11}, 80 { 'name':'r12' , 'bitsize' : 64, 'offset' : 96, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 12, 'dwarf' : 12}, 81 { 'name':'r13' , 'bitsize' : 64, 'offset' : 104, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 13, 'dwarf' : 13}, 82 { 'name':'r14' , 'bitsize' : 64, 'offset' : 112, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 14, 'dwarf' : 14}, 83 { 'name':'r15' , 'bitsize' : 64, 'offset' : 120, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 15, 'dwarf' : 15}, 84 { 'name':'rip' , 'bitsize' : 64, 'offset' : 128, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'gcc' : 16, 'dwarf' : 16, 'generic':'pc', 'alt-name':'pc' }, 85 { 'name':'rflags' , 'bitsize' : 64, 'offset' : 136, 'encoding':'uint' , 'format':'hex' , 'set': 0, 'generic':'flags', 'alt-name':'flags' }, 86 { 'name':'cs' , 'bitsize' : 64, 'offset' : 144, 'encoding':'uint' , 'format':'hex' , 'set': 0 }, 87 { 'name':'fs' , 'bitsize' : 64, 'offset' : 152, 'encoding':'uint' , 'format':'hex' , 'set': 0 }, 88 { 'name':'gs' , 'bitsize' : 64, 'offset' : 160, 'encoding':'uint' , 'format':'hex' , 'set': 0 }, 89 ] 90 return self.registers 91 92 def get_register_data(self, tid): 93 if tid == 0x111111111: 94 return struct.pack('21Q',1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21); 95 elif tid == 0x222222222: 96 return struct.pack('21Q',11,12,13,14,15,16,17,18,19,110,111,112,113,114,115,116,117,118,119,120,121); 97 elif tid == 0x333333333: 98 return struct.pack('21Q',21,22,23,24,25,26,27,28,29,210,211,212,213,214,215,216,217,218,219,220,221); 99 elif tid == 0x444444444: 100 return struct.pack('21Q',31,32,33,34,35,36,37,38,39,310,311,312,313,314,315,316,317,318,319,320,321); 101 else: 102 return struct.pack('21Q',41,42,43,44,45,46,47,48,49,410,411,412,413,414,415,416,417,418,419,420,421); 103 return None 104 105