1 /*
2  * Copyright (C) 2012-2014 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #define LOG_TAG "DEBUG"
18 
19 #include <dirent.h>
20 #include <errno.h>
21 #include <fcntl.h>
22 #include <inttypes.h>
23 #include <signal.h>
24 #include <stddef.h>
25 #include <stdio.h>
26 #include <stdlib.h>
27 #include <string.h>
28 #include <sys/ptrace.h>
29 #include <sys/stat.h>
30 #include <time.h>
31 
32 #include <memory>
33 #include <string>
34 
35 #include <android-base/file.h>
36 #include <android-base/stringprintf.h>
37 #include <android-base/unique_fd.h>
38 #include <android/log.h>
39 #include <backtrace/Backtrace.h>
40 #include <backtrace/BacktraceMap.h>
41 #include <cutils/properties.h>
42 #include <log/log.h>
43 #include <log/logprint.h>
44 #include <private/android_filesystem_config.h>
45 
46 #include "debuggerd/handler.h"
47 
48 #include "backtrace.h"
49 #include "elf_utils.h"
50 #include "machine.h"
51 #include "open_files_list.h"
52 #include "tombstone.h"
53 
54 using android::base::StringPrintf;
55 
56 #define STACK_WORDS 16
57 
58 #define MAX_TOMBSTONES  10
59 #define TOMBSTONE_DIR   "/data/tombstones"
60 #define TOMBSTONE_TEMPLATE (TOMBSTONE_DIR"/tombstone_%02d")
61 
signal_has_si_addr(int si_signo,int si_code)62 static bool signal_has_si_addr(int si_signo, int si_code) {
63   // Manually sent signals won't have si_addr.
64   if (si_code == SI_USER || si_code == SI_QUEUE || si_code == SI_TKILL) {
65     return false;
66   }
67 
68   switch (si_signo) {
69     case SIGBUS:
70     case SIGFPE:
71     case SIGILL:
72     case SIGSEGV:
73     case SIGTRAP:
74       return true;
75     default:
76       return false;
77   }
78 }
79 
get_signame(int sig)80 static const char* get_signame(int sig) {
81   switch (sig) {
82     case SIGABRT: return "SIGABRT";
83     case SIGBUS: return "SIGBUS";
84     case SIGFPE: return "SIGFPE";
85     case SIGILL: return "SIGILL";
86     case SIGSEGV: return "SIGSEGV";
87 #if defined(SIGSTKFLT)
88     case SIGSTKFLT: return "SIGSTKFLT";
89 #endif
90     case SIGSTOP: return "SIGSTOP";
91     case SIGSYS: return "SIGSYS";
92     case SIGTRAP: return "SIGTRAP";
93     case DEBUGGER_SIGNAL: return "<debuggerd signal>";
94     default: return "?";
95   }
96 }
97 
get_sigcode(int signo,int code)98 static const char* get_sigcode(int signo, int code) {
99   // Try the signal-specific codes...
100   switch (signo) {
101     case SIGILL:
102       switch (code) {
103         case ILL_ILLOPC: return "ILL_ILLOPC";
104         case ILL_ILLOPN: return "ILL_ILLOPN";
105         case ILL_ILLADR: return "ILL_ILLADR";
106         case ILL_ILLTRP: return "ILL_ILLTRP";
107         case ILL_PRVOPC: return "ILL_PRVOPC";
108         case ILL_PRVREG: return "ILL_PRVREG";
109         case ILL_COPROC: return "ILL_COPROC";
110         case ILL_BADSTK: return "ILL_BADSTK";
111       }
112       static_assert(NSIGILL == ILL_BADSTK, "missing ILL_* si_code");
113       break;
114     case SIGBUS:
115       switch (code) {
116         case BUS_ADRALN: return "BUS_ADRALN";
117         case BUS_ADRERR: return "BUS_ADRERR";
118         case BUS_OBJERR: return "BUS_OBJERR";
119         case BUS_MCEERR_AR: return "BUS_MCEERR_AR";
120         case BUS_MCEERR_AO: return "BUS_MCEERR_AO";
121       }
122       static_assert(NSIGBUS == BUS_MCEERR_AO, "missing BUS_* si_code");
123       break;
124     case SIGFPE:
125       switch (code) {
126         case FPE_INTDIV: return "FPE_INTDIV";
127         case FPE_INTOVF: return "FPE_INTOVF";
128         case FPE_FLTDIV: return "FPE_FLTDIV";
129         case FPE_FLTOVF: return "FPE_FLTOVF";
130         case FPE_FLTUND: return "FPE_FLTUND";
131         case FPE_FLTRES: return "FPE_FLTRES";
132         case FPE_FLTINV: return "FPE_FLTINV";
133         case FPE_FLTSUB: return "FPE_FLTSUB";
134       }
135       static_assert(NSIGFPE == FPE_FLTSUB, "missing FPE_* si_code");
136       break;
137     case SIGSEGV:
138       switch (code) {
139         case SEGV_MAPERR: return "SEGV_MAPERR";
140         case SEGV_ACCERR: return "SEGV_ACCERR";
141 #if defined(SEGV_BNDERR)
142         case SEGV_BNDERR: return "SEGV_BNDERR";
143 #endif
144 #if defined(SEGV_PKUERR)
145         case SEGV_PKUERR: return "SEGV_PKUERR";
146 #endif
147       }
148 #if defined(SEGV_PKUERR)
149       static_assert(NSIGSEGV == SEGV_PKUERR, "missing SEGV_* si_code");
150 #elif defined(SEGV_BNDERR)
151       static_assert(NSIGSEGV == SEGV_BNDERR, "missing SEGV_* si_code");
152 #else
153       static_assert(NSIGSEGV == SEGV_ACCERR, "missing SEGV_* si_code");
154 #endif
155       break;
156 #if defined(SYS_SECCOMP) // Our glibc is too old, and we build this for the host too.
157     case SIGSYS:
158       switch (code) {
159         case SYS_SECCOMP: return "SYS_SECCOMP";
160       }
161       static_assert(NSIGSYS == SYS_SECCOMP, "missing SYS_* si_code");
162       break;
163 #endif
164     case SIGTRAP:
165       switch (code) {
166         case TRAP_BRKPT: return "TRAP_BRKPT";
167         case TRAP_TRACE: return "TRAP_TRACE";
168         case TRAP_BRANCH: return "TRAP_BRANCH";
169         case TRAP_HWBKPT: return "TRAP_HWBKPT";
170       }
171       static_assert(NSIGTRAP == TRAP_HWBKPT, "missing TRAP_* si_code");
172       break;
173   }
174   // Then the other codes...
175   switch (code) {
176     case SI_USER: return "SI_USER";
177     case SI_KERNEL: return "SI_KERNEL";
178     case SI_QUEUE: return "SI_QUEUE";
179     case SI_TIMER: return "SI_TIMER";
180     case SI_MESGQ: return "SI_MESGQ";
181     case SI_ASYNCIO: return "SI_ASYNCIO";
182     case SI_SIGIO: return "SI_SIGIO";
183     case SI_TKILL: return "SI_TKILL";
184     case SI_DETHREAD: return "SI_DETHREAD";
185   }
186   // Then give up...
187   return "?";
188 }
189 
dump_header_info(log_t * log)190 static void dump_header_info(log_t* log) {
191   char fingerprint[PROPERTY_VALUE_MAX];
192   char revision[PROPERTY_VALUE_MAX];
193 
194   property_get("ro.build.fingerprint", fingerprint, "unknown");
195   property_get("ro.revision", revision, "unknown");
196 
197   _LOG(log, logtype::HEADER, "Build fingerprint: '%s'\n", fingerprint);
198   _LOG(log, logtype::HEADER, "Revision: '%s'\n", revision);
199   _LOG(log, logtype::HEADER, "ABI: '%s'\n", ABI_STRING);
200 }
201 
dump_probable_cause(log_t * log,const siginfo_t & si)202 static void dump_probable_cause(log_t* log, const siginfo_t& si) {
203   std::string cause;
204   if (si.si_signo == SIGSEGV && si.si_code == SEGV_MAPERR) {
205     if (si.si_addr < reinterpret_cast<void*>(4096)) {
206       cause = StringPrintf("null pointer dereference");
207     } else if (si.si_addr == reinterpret_cast<void*>(0xffff0ffc)) {
208       cause = "call to kuser_helper_version";
209     } else if (si.si_addr == reinterpret_cast<void*>(0xffff0fe0)) {
210       cause = "call to kuser_get_tls";
211     } else if (si.si_addr == reinterpret_cast<void*>(0xffff0fc0)) {
212       cause = "call to kuser_cmpxchg";
213     } else if (si.si_addr == reinterpret_cast<void*>(0xffff0fa0)) {
214       cause = "call to kuser_memory_barrier";
215     } else if (si.si_addr == reinterpret_cast<void*>(0xffff0f60)) {
216       cause = "call to kuser_cmpxchg64";
217     }
218   } else if (si.si_signo == SIGSYS && si.si_code == SYS_SECCOMP) {
219     cause = StringPrintf("seccomp prevented call to disallowed %s system call %d",
220                          ABI_STRING, si.si_syscall);
221   }
222 
223   if (!cause.empty()) _LOG(log, logtype::HEADER, "Cause: %s\n", cause.c_str());
224 }
225 
dump_signal_info(log_t * log,const siginfo_t * siginfo)226 static void dump_signal_info(log_t* log, const siginfo_t* siginfo) {
227   const siginfo_t& si = *siginfo;
228   char addr_desc[32]; // ", fault addr 0x1234"
229   if (signal_has_si_addr(si.si_signo, si.si_code)) {
230     snprintf(addr_desc, sizeof(addr_desc), "%p", si.si_addr);
231   } else {
232     snprintf(addr_desc, sizeof(addr_desc), "--------");
233   }
234 
235   _LOG(log, logtype::HEADER, "signal %d (%s), code %d (%s), fault addr %s\n", si.si_signo,
236        get_signame(si.si_signo), si.si_code, get_sigcode(si.si_signo, si.si_code), addr_desc);
237 
238   dump_probable_cause(log, si);
239 }
240 
dump_signal_info(log_t * log,pid_t tid)241 static void dump_signal_info(log_t* log, pid_t tid) {
242   siginfo_t si;
243   memset(&si, 0, sizeof(si));
244   if (ptrace(PTRACE_GETSIGINFO, tid, 0, &si) == -1) {
245     ALOGE("cannot get siginfo: %s\n", strerror(errno));
246     return;
247   }
248 
249   dump_signal_info(log, &si);
250 }
251 
dump_thread_info(log_t * log,pid_t pid,pid_t tid,const char * process_name,const char * thread_name)252 static void dump_thread_info(log_t* log, pid_t pid, pid_t tid, const char* process_name,
253                              const char* thread_name) {
254   // Blacklist logd, logd.reader, logd.writer, logd.auditd, logd.control ...
255   // TODO: Why is this controlled by thread name?
256   if (strcmp(thread_name, "logd") == 0 || strncmp(thread_name, "logd.", 4) == 0) {
257     log->should_retrieve_logcat = false;
258   }
259 
260   _LOG(log, logtype::HEADER, "pid: %d, tid: %d, name: %s  >>> %s <<<\n", pid, tid, thread_name,
261        process_name);
262 }
263 
dump_stack_segment(Backtrace * backtrace,log_t * log,uintptr_t * sp,size_t words,int label)264 static void dump_stack_segment(
265     Backtrace* backtrace, log_t* log, uintptr_t* sp, size_t words, int label) {
266   // Read the data all at once.
267   word_t stack_data[words];
268   size_t bytes_read = backtrace->Read(*sp, reinterpret_cast<uint8_t*>(&stack_data[0]), sizeof(word_t) * words);
269   words = bytes_read / sizeof(word_t);
270   std::string line;
271   for (size_t i = 0; i < words; i++) {
272     line = "    ";
273     if (i == 0 && label >= 0) {
274       // Print the label once.
275       line += StringPrintf("#%02d  ", label);
276     } else {
277       line += "     ";
278     }
279     line += StringPrintf("%" PRIPTR "  %" PRIPTR, *sp, stack_data[i]);
280 
281     backtrace_map_t map;
282     backtrace->FillInMap(stack_data[i], &map);
283     if (BacktraceMap::IsValid(map) && !map.name.empty()) {
284       line += "  " + map.name;
285       uintptr_t offset = 0;
286       std::string func_name(backtrace->GetFunctionName(stack_data[i], &offset, &map));
287       if (!func_name.empty()) {
288         line += " (" + func_name;
289         if (offset) {
290           line += StringPrintf("+%" PRIuPTR, offset);
291         }
292         line += ')';
293       }
294     }
295     _LOG(log, logtype::STACK, "%s\n", line.c_str());
296 
297     *sp += sizeof(word_t);
298   }
299 }
300 
dump_stack(Backtrace * backtrace,log_t * log)301 static void dump_stack(Backtrace* backtrace, log_t* log) {
302   size_t first = 0, last;
303   for (size_t i = 0; i < backtrace->NumFrames(); i++) {
304     const backtrace_frame_data_t* frame = backtrace->GetFrame(i);
305     if (frame->sp) {
306       if (!first) {
307         first = i+1;
308       }
309       last = i;
310     }
311   }
312   if (!first) {
313     return;
314   }
315   first--;
316 
317   // Dump a few words before the first frame.
318   word_t sp = backtrace->GetFrame(first)->sp - STACK_WORDS * sizeof(word_t);
319   dump_stack_segment(backtrace, log, &sp, STACK_WORDS, -1);
320 
321   // Dump a few words from all successive frames.
322   // Only log the first 3 frames, put the rest in the tombstone.
323   for (size_t i = first; i <= last; i++) {
324     const backtrace_frame_data_t* frame = backtrace->GetFrame(i);
325     if (sp != frame->sp) {
326       _LOG(log, logtype::STACK, "         ........  ........\n");
327       sp = frame->sp;
328     }
329     if (i == last) {
330       dump_stack_segment(backtrace, log, &sp, STACK_WORDS, i);
331       if (sp < frame->sp + frame->stack_size) {
332         _LOG(log, logtype::STACK, "         ........  ........\n");
333       }
334     } else {
335       size_t words = frame->stack_size / sizeof(word_t);
336       if (words == 0) {
337         words = 1;
338       } else if (words > STACK_WORDS) {
339         words = STACK_WORDS;
340       }
341       dump_stack_segment(backtrace, log, &sp, words, i);
342     }
343   }
344 }
345 
get_addr_string(uintptr_t addr)346 static std::string get_addr_string(uintptr_t addr) {
347   std::string addr_str;
348 #if defined(__LP64__)
349   addr_str = StringPrintf("%08x'%08x",
350                           static_cast<uint32_t>(addr >> 32),
351                           static_cast<uint32_t>(addr & 0xffffffff));
352 #else
353   addr_str = StringPrintf("%08x", addr);
354 #endif
355   return addr_str;
356 }
357 
dump_abort_message(Backtrace * backtrace,log_t * log,uintptr_t address)358 static void dump_abort_message(Backtrace* backtrace, log_t* log, uintptr_t address) {
359   if (address == 0) {
360     return;
361   }
362 
363   address += sizeof(size_t);  // Skip the buffer length.
364 
365   char msg[512];
366   memset(msg, 0, sizeof(msg));
367   char* p = &msg[0];
368   while (p < &msg[sizeof(msg)]) {
369     word_t data;
370     size_t len = sizeof(word_t);
371     if (!backtrace->ReadWord(address, &data)) {
372       break;
373     }
374     address += sizeof(word_t);
375 
376     while (len > 0 && (*p++ = (data >> (sizeof(word_t) - len) * 8) & 0xff) != 0) {
377       len--;
378     }
379   }
380   msg[sizeof(msg) - 1] = '\0';
381 
382   _LOG(log, logtype::HEADER, "Abort message: '%s'\n", msg);
383 }
384 
dump_all_maps(Backtrace * backtrace,BacktraceMap * map,log_t * log,pid_t tid)385 static void dump_all_maps(Backtrace* backtrace, BacktraceMap* map, log_t* log, pid_t tid) {
386   bool print_fault_address_marker = false;
387   uintptr_t addr = 0;
388   siginfo_t si;
389   memset(&si, 0, sizeof(si));
390   if (ptrace(PTRACE_GETSIGINFO, tid, 0, &si) != -1) {
391     print_fault_address_marker = signal_has_si_addr(si.si_signo, si.si_code);
392     addr = reinterpret_cast<uintptr_t>(si.si_addr);
393   } else {
394     ALOGE("Cannot get siginfo for %d: %s\n", tid, strerror(errno));
395   }
396 
397   ScopedBacktraceMapIteratorLock lock(map);
398   _LOG(log, logtype::MAPS, "\n");
399   if (!print_fault_address_marker) {
400     _LOG(log, logtype::MAPS, "memory map:\n");
401   } else {
402     _LOG(log, logtype::MAPS, "memory map: (fault address prefixed with --->)\n");
403     if (map->begin() != map->end() && addr < map->begin()->start) {
404       _LOG(log, logtype::MAPS, "--->Fault address falls at %s before any mapped regions\n",
405            get_addr_string(addr).c_str());
406       print_fault_address_marker = false;
407     }
408   }
409 
410   std::string line;
411   for (BacktraceMap::const_iterator it = map->begin(); it != map->end(); ++it) {
412     line = "    ";
413     if (print_fault_address_marker) {
414       if (addr < it->start) {
415         _LOG(log, logtype::MAPS, "--->Fault address falls at %s between mapped regions\n",
416              get_addr_string(addr).c_str());
417         print_fault_address_marker = false;
418       } else if (addr >= it->start && addr < it->end) {
419         line = "--->";
420         print_fault_address_marker = false;
421       }
422     }
423     line += get_addr_string(it->start) + '-' + get_addr_string(it->end - 1) + ' ';
424     if (it->flags & PROT_READ) {
425       line += 'r';
426     } else {
427       line += '-';
428     }
429     if (it->flags & PROT_WRITE) {
430       line += 'w';
431     } else {
432       line += '-';
433     }
434     if (it->flags & PROT_EXEC) {
435       line += 'x';
436     } else {
437       line += '-';
438     }
439     line += StringPrintf("  %8" PRIxPTR "  %8" PRIxPTR, it->offset, it->end - it->start);
440     bool space_needed = true;
441     if (it->name.length() > 0) {
442       space_needed = false;
443       line += "  " + it->name;
444       std::string build_id;
445       if ((it->flags & PROT_READ) && elf_get_build_id(backtrace, it->start, &build_id)) {
446         line += " (BuildId: " + build_id + ")";
447       }
448     }
449     if (it->load_base != 0) {
450       if (space_needed) {
451         line += ' ';
452       }
453       line += StringPrintf(" (load base 0x%" PRIxPTR ")", it->load_base);
454     }
455     _LOG(log, logtype::MAPS, "%s\n", line.c_str());
456   }
457   if (print_fault_address_marker) {
458     _LOG(log, logtype::MAPS, "--->Fault address falls at %s after any mapped regions\n",
459          get_addr_string(addr).c_str());
460   }
461 }
462 
dump_backtrace_and_stack(Backtrace * backtrace,log_t * log)463 static void dump_backtrace_and_stack(Backtrace* backtrace, log_t* log) {
464   if (backtrace->NumFrames()) {
465     _LOG(log, logtype::BACKTRACE, "\nbacktrace:\n");
466     dump_backtrace_to_log(backtrace, log, "    ");
467 
468     _LOG(log, logtype::STACK, "\nstack:\n");
469     dump_stack(backtrace, log);
470   }
471 }
472 
473 // Weak noop implementation, real implementations are in <arch>/machine.cpp.
dump_registers(log_t * log,const ucontext_t *)474 __attribute__((weak)) void dump_registers(log_t* log, const ucontext_t*) {
475   _LOG(log, logtype::REGISTERS, "    register dumping unimplemented on this architecture");
476 }
477 
dump_thread(log_t * log,pid_t pid,pid_t tid,const std::string & process_name,const std::string & thread_name,BacktraceMap * map,uintptr_t abort_msg_address,bool primary_thread)478 static void dump_thread(log_t* log, pid_t pid, pid_t tid, const std::string& process_name,
479                         const std::string& thread_name, BacktraceMap* map,
480                         uintptr_t abort_msg_address, bool primary_thread) {
481   log->current_tid = tid;
482   if (!primary_thread) {
483     _LOG(log, logtype::THREAD, "--- --- --- --- --- --- --- --- --- --- --- --- --- --- --- ---\n");
484   }
485   dump_thread_info(log, pid, tid, process_name.c_str(), thread_name.c_str());
486   dump_signal_info(log, tid);
487 
488   std::unique_ptr<Backtrace> backtrace(Backtrace::Create(pid, tid, map));
489   if (primary_thread) {
490     dump_abort_message(backtrace.get(), log, abort_msg_address);
491   }
492   dump_registers(log, tid);
493   if (backtrace->Unwind(0)) {
494     dump_backtrace_and_stack(backtrace.get(), log);
495   } else {
496     ALOGE("Unwind failed: pid = %d, tid = %d", pid, tid);
497   }
498 
499   if (primary_thread) {
500     dump_memory_and_code(log, backtrace.get());
501     if (map) {
502       dump_all_maps(backtrace.get(), map, log, tid);
503     }
504   }
505 
506   log->current_tid = log->crashed_tid;
507 }
508 
509 // Reads the contents of the specified log device, filters out the entries
510 // that don't match the specified pid, and writes them to the tombstone file.
511 //
512 // If "tail" is non-zero, log the last "tail" number of lines.
513 static EventTagMap* g_eventTagMap = NULL;
514 
dump_log_file(log_t * log,pid_t pid,const char * filename,unsigned int tail)515 static void dump_log_file(
516     log_t* log, pid_t pid, const char* filename, unsigned int tail) {
517   bool first = true;
518   struct logger_list* logger_list;
519 
520   if (!log->should_retrieve_logcat) {
521     return;
522   }
523 
524   logger_list = android_logger_list_open(
525       android_name_to_log_id(filename), ANDROID_LOG_RDONLY | ANDROID_LOG_NONBLOCK, tail, pid);
526 
527   if (!logger_list) {
528     ALOGE("Unable to open %s: %s\n", filename, strerror(errno));
529     return;
530   }
531 
532   struct log_msg log_entry;
533 
534   while (true) {
535     ssize_t actual = android_logger_list_read(logger_list, &log_entry);
536     struct logger_entry* entry;
537 
538     if (actual < 0) {
539       if (actual == -EINTR) {
540         // interrupted by signal, retry
541         continue;
542       } else if (actual == -EAGAIN) {
543         // non-blocking EOF; we're done
544         break;
545       } else {
546         ALOGE("Error while reading log: %s\n", strerror(-actual));
547         break;
548       }
549     } else if (actual == 0) {
550       ALOGE("Got zero bytes while reading log: %s\n", strerror(errno));
551       break;
552     }
553 
554     // NOTE: if you ALOGV something here, this will spin forever,
555     // because you will be writing as fast as you're reading.  Any
556     // high-frequency debug diagnostics should just be written to
557     // the tombstone file.
558 
559     entry = &log_entry.entry_v1;
560 
561     if (first) {
562       _LOG(log, logtype::LOGS, "--------- %slog %s\n",
563         tail ? "tail end of " : "", filename);
564       first = false;
565     }
566 
567     // Msg format is: <priority:1><tag:N>\0<message:N>\0
568     //
569     // We want to display it in the same format as "logcat -v threadtime"
570     // (although in this case the pid is redundant).
571     static const char* kPrioChars = "!.VDIWEFS";
572     unsigned hdr_size = log_entry.entry.hdr_size;
573     if (!hdr_size) {
574       hdr_size = sizeof(log_entry.entry_v1);
575     }
576     if ((hdr_size < sizeof(log_entry.entry_v1)) ||
577         (hdr_size > sizeof(log_entry.entry))) {
578       continue;
579     }
580     char* msg = reinterpret_cast<char*>(log_entry.buf) + hdr_size;
581 
582     char timeBuf[32];
583     time_t sec = static_cast<time_t>(entry->sec);
584     struct tm tmBuf;
585     struct tm* ptm;
586     ptm = localtime_r(&sec, &tmBuf);
587     strftime(timeBuf, sizeof(timeBuf), "%m-%d %H:%M:%S", ptm);
588 
589     if (log_entry.id() == LOG_ID_EVENTS) {
590       if (!g_eventTagMap) {
591         g_eventTagMap = android_openEventTagMap(NULL);
592       }
593       AndroidLogEntry e;
594       char buf[512];
595       android_log_processBinaryLogBuffer(entry, &e, g_eventTagMap, buf, sizeof(buf));
596       _LOG(log, logtype::LOGS, "%s.%03d %5d %5d %c %-8.*s: %s\n",
597          timeBuf, entry->nsec / 1000000, entry->pid, entry->tid,
598          'I', (int)e.tagLen, e.tag, e.message);
599       continue;
600     }
601 
602     unsigned char prio = msg[0];
603     char* tag = msg + 1;
604     msg = tag + strlen(tag) + 1;
605 
606     // consume any trailing newlines
607     char* nl = msg + strlen(msg) - 1;
608     while (nl >= msg && *nl == '\n') {
609       *nl-- = '\0';
610     }
611 
612     char prioChar = (prio < strlen(kPrioChars) ? kPrioChars[prio] : '?');
613 
614     // Look for line breaks ('\n') and display each text line
615     // on a separate line, prefixed with the header, like logcat does.
616     do {
617       nl = strchr(msg, '\n');
618       if (nl) {
619         *nl = '\0';
620         ++nl;
621       }
622 
623       _LOG(log, logtype::LOGS, "%s.%03d %5d %5d %c %-8s: %s\n",
624          timeBuf, entry->nsec / 1000000, entry->pid, entry->tid,
625          prioChar, tag, msg);
626     } while ((msg = nl));
627   }
628 
629   android_logger_list_free(logger_list);
630 }
631 
632 // Dumps the logs generated by the specified pid to the tombstone, from both
633 // "system" and "main" log devices.  Ideally we'd interleave the output.
dump_logs(log_t * log,pid_t pid,unsigned int tail)634 static void dump_logs(log_t* log, pid_t pid, unsigned int tail) {
635   dump_log_file(log, pid, "system", tail);
636   dump_log_file(log, pid, "main", tail);
637 }
638 
639 // Dumps all information about the specified pid to the tombstone.
dump_crash(log_t * log,BacktraceMap * map,const OpenFilesList * open_files,pid_t pid,pid_t tid,const std::string & process_name,const std::map<pid_t,std::string> & threads,uintptr_t abort_msg_address)640 static void dump_crash(log_t* log, BacktraceMap* map, const OpenFilesList* open_files, pid_t pid,
641                        pid_t tid, const std::string& process_name,
642                        const std::map<pid_t, std::string>& threads, uintptr_t abort_msg_address) {
643   // don't copy log messages to tombstone unless this is a dev device
644   char value[PROPERTY_VALUE_MAX];
645   property_get("ro.debuggable", value, "0");
646   bool want_logs = (value[0] == '1');
647 
648   _LOG(log, logtype::HEADER,
649        "*** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***\n");
650   dump_header_info(log);
651   dump_thread(log, pid, tid, process_name, threads.find(tid)->second, map, abort_msg_address, true);
652   if (want_logs) {
653     dump_logs(log, pid, 5);
654   }
655 
656   for (const auto& it : threads) {
657     pid_t thread_tid = it.first;
658     const std::string& thread_name = it.second;
659 
660     if (thread_tid != tid) {
661       dump_thread(log, pid, thread_tid, process_name, thread_name, map, 0, false);
662     }
663   }
664 
665   if (open_files) {
666     _LOG(log, logtype::OPEN_FILES, "\nopen files:\n");
667     dump_open_files_list_to_log(*open_files, log, "    ");
668   }
669 
670   if (want_logs) {
671     dump_logs(log, pid, 0);
672   }
673 }
674 
675 // open_tombstone - find an available tombstone slot, if any, of the
676 // form tombstone_XX where XX is 00 to MAX_TOMBSTONES-1, inclusive. If no
677 // file is available, we reuse the least-recently-modified file.
open_tombstone(std::string * out_path)678 int open_tombstone(std::string* out_path) {
679   // In a single pass, find an available slot and, in case none
680   // exist, find and record the least-recently-modified file.
681   char path[128];
682   int fd = -1;
683   int oldest = -1;
684   struct stat oldest_sb;
685   for (int i = 0; i < MAX_TOMBSTONES; i++) {
686     snprintf(path, sizeof(path), TOMBSTONE_TEMPLATE, i);
687 
688     struct stat sb;
689     if (stat(path, &sb) == 0) {
690       if (oldest < 0 || sb.st_mtime < oldest_sb.st_mtime) {
691         oldest = i;
692         oldest_sb.st_mtime = sb.st_mtime;
693       }
694       continue;
695     }
696     if (errno != ENOENT) continue;
697 
698     fd = open(path, O_CREAT | O_EXCL | O_WRONLY | O_NOFOLLOW | O_CLOEXEC, 0600);
699     if (fd < 0) continue;  // raced ?
700 
701     if (out_path) {
702       *out_path = path;
703     }
704     fchown(fd, AID_SYSTEM, AID_SYSTEM);
705     return fd;
706   }
707 
708   if (oldest < 0) {
709     ALOGE("debuggerd: failed to find a valid tombstone, default to using tombstone 0.\n");
710     oldest = 0;
711   }
712 
713   // we didn't find an available file, so we clobber the oldest one
714   snprintf(path, sizeof(path), TOMBSTONE_TEMPLATE, oldest);
715   fd = open(path, O_CREAT | O_TRUNC | O_WRONLY | O_NOFOLLOW | O_CLOEXEC, 0600);
716   if (fd < 0) {
717     ALOGE("debuggerd: failed to open tombstone file '%s': %s\n", path, strerror(errno));
718     return -1;
719   }
720 
721   if (out_path) {
722     *out_path = path;
723   }
724   fchown(fd, AID_SYSTEM, AID_SYSTEM);
725   return fd;
726 }
727 
engrave_tombstone(int tombstone_fd,BacktraceMap * map,const OpenFilesList * open_files,pid_t pid,pid_t tid,const std::string & process_name,const std::map<pid_t,std::string> & threads,uintptr_t abort_msg_address,std::string * amfd_data)728 void engrave_tombstone(int tombstone_fd, BacktraceMap* map, const OpenFilesList* open_files,
729                        pid_t pid, pid_t tid, const std::string& process_name,
730                        const std::map<pid_t, std::string>& threads, uintptr_t abort_msg_address,
731                        std::string* amfd_data) {
732   log_t log;
733   log.current_tid = tid;
734   log.crashed_tid = tid;
735   log.tfd = tombstone_fd;
736   log.amfd_data = amfd_data;
737   dump_crash(&log, map, open_files, pid, tid, process_name, threads, abort_msg_address);
738 }
739 
engrave_tombstone_ucontext(int tombstone_fd,uintptr_t abort_msg_address,siginfo_t * siginfo,ucontext_t * ucontext)740 void engrave_tombstone_ucontext(int tombstone_fd, uintptr_t abort_msg_address, siginfo_t* siginfo,
741                                 ucontext_t* ucontext) {
742   pid_t pid = getpid();
743   pid_t tid = gettid();
744 
745   log_t log;
746   log.current_tid = tid;
747   log.crashed_tid = tid;
748   log.tfd = tombstone_fd;
749   log.amfd_data = nullptr;
750 
751   char thread_name[16];
752   char process_name[128];
753 
754   read_with_default("/proc/self/comm", thread_name, sizeof(thread_name), "<unknown>");
755   read_with_default("/proc/self/cmdline", process_name, sizeof(process_name), "<unknown>");
756 
757   _LOG(&log, logtype::HEADER, "*** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***\n");
758   dump_header_info(&log);
759   dump_thread_info(&log, pid, tid, thread_name, process_name);
760   dump_signal_info(&log, siginfo);
761 
762   std::unique_ptr<Backtrace> backtrace(Backtrace::Create(pid, tid));
763   dump_abort_message(backtrace.get(), &log, abort_msg_address);
764   dump_registers(&log, ucontext);
765 
766   // TODO: Dump registers from the ucontext.
767   if (backtrace->Unwind(0, ucontext)) {
768     dump_backtrace_and_stack(backtrace.get(), &log);
769   } else {
770     ALOGE("Unwind failed: pid = %d, tid = %d", pid, tid);
771   }
772 }
773