brintos

brintos / llvm-project-archived public Read only

0
0
Text · 26.5 KiB · 601cfdc Raw
867 lines · cpp
1//===-- StopInfoMachException.cpp -----------------------------------------===//2//3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.4// See https://llvm.org/LICENSE.txt for license information.5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception6//7//===----------------------------------------------------------------------===//8 9#include "StopInfoMachException.h"10 11#include "lldb/lldb-forward.h"12 13#if defined(__APPLE__)14// Needed for the EXC_RESOURCE interpretation macros15#include <kern/exc_resource.h>16#endif17 18#include "lldb/Breakpoint/Watchpoint.h"19#include "lldb/Symbol/Symbol.h"20#include "lldb/Target/ABI.h"21#include "lldb/Target/DynamicLoader.h"22#include "lldb/Target/ExecutionContext.h"23#include "lldb/Target/Process.h"24#include "lldb/Target/RegisterContext.h"25#include "lldb/Target/Target.h"26#include "lldb/Target/Thread.h"27#include "lldb/Target/ThreadPlan.h"28#include "lldb/Target/UnixSignals.h"29#include "lldb/Utility/LLDBLog.h"30#include "lldb/Utility/Log.h"31#include "lldb/Utility/StreamString.h"32#include <optional>33 34using namespace lldb;35using namespace lldb_private;36 37/// Information about a pointer-authentication related instruction.38struct PtrauthInstructionInfo {39  bool IsAuthenticated;40  bool IsLoad;41  bool DoesBranch;42};43 44/// Get any pointer-authentication related information about the instruction45/// at address \p at_addr.46static std::optional<PtrauthInstructionInfo>47GetPtrauthInstructionInfo(Target &target, const ArchSpec &arch,48                          const Address &at_addr) {49  const char *plugin_name = nullptr;50  const char *flavor = nullptr;51  const char *cpu = nullptr;52  const char *features = nullptr;53  AddressRange range_bounds(at_addr, 4);54  const bool prefer_file_cache = true;55  DisassemblerSP disassembler_sp =56      Disassembler::DisassembleRange(arch, plugin_name, flavor, cpu, features,57                                     target, range_bounds, prefer_file_cache);58  if (!disassembler_sp)59    return std::nullopt;60 61  InstructionList &insn_list = disassembler_sp->GetInstructionList();62  InstructionSP insn = insn_list.GetInstructionAtIndex(0);63  if (!insn)64    return std::nullopt;65 66  return PtrauthInstructionInfo{insn->IsAuthenticated(), insn->IsLoad(),67                                insn->DoesBranch()};68}69 70/// Describe the load address of \p addr using the format filename:line:col.71static void DescribeAddressBriefly(Stream &strm, const Address &addr,72                                   Target &target) {73  strm.Printf("at address=0x%" PRIx64, addr.GetLoadAddress(&target));74  StreamString s;75  if (addr.GetDescription(s, target, eDescriptionLevelBrief))76    strm.Printf(" %s", s.GetString().data());77  strm.Printf(".\n");78}79 80static constexpr uint8_t g_mte_tag_shift = 64 - 8;81static constexpr addr_t g_mte_tag_mask = (addr_t)0x0f << g_mte_tag_shift;82 83bool StopInfoMachException::DetermineTagMismatch(ExecutionContext &exe_ctx) {84  const bool IsBadAccess = m_value == 1;            // EXC_BAD_ACCESS85  const bool IsMTETagFault = (m_exc_code == 0x106); // EXC_ARM_MTE_TAG_FAULT86  if (!IsBadAccess || !IsMTETagFault)87    return false;88 89  if (m_exc_data_count < 2)90    return false;91 92  const uint64_t bad_address = m_exc_subcode;93 94  StreamString strm;95  strm.Printf("EXC_ARM_MTE_TAG_FAULT (code=%" PRIu64 ", address=0x%" PRIx6496              ")\n",97              m_exc_code, bad_address);98 99  const uint8_t tag = (bad_address & g_mte_tag_mask) >> g_mte_tag_shift;100  const addr_t canonical_addr = bad_address & ~g_mte_tag_mask;101  strm.Printf(102      "Note: MTE tag mismatch detected: pointer tag=%d, address=0x%" PRIx64,103      tag, canonical_addr);104  m_description = std::string(strm.GetString());105 106  return true;107}108 109bool StopInfoMachException::DeterminePtrauthFailure(ExecutionContext &exe_ctx) {110  bool IsBreakpoint = m_value == 6; // EXC_BREAKPOINT111  bool IsBadAccess = m_value == 1;  // EXC_BAD_ACCESS112  if (!IsBreakpoint && !IsBadAccess)113    return false;114 115  // Check that we have a live process.116  if (!exe_ctx.HasProcessScope() || !exe_ctx.HasThreadScope() ||117      !exe_ctx.HasTargetScope())118    return false;119 120  Thread &thread = *exe_ctx.GetThreadPtr();121  StackFrameSP current_frame = thread.GetStackFrameAtIndex(0);122  if (!current_frame)123    return false;124 125  Target &target = *exe_ctx.GetTargetPtr();126  Process &process = *exe_ctx.GetProcessPtr();127  const ArchSpec &arch = target.GetArchitecture();128 129  // Check for a ptrauth-enabled target.130  const bool ptrauth_enabled_target =131      arch.GetCore() == ArchSpec::eCore_arm_arm64e;132  if (!ptrauth_enabled_target)133    return false;134 135  // Set up a stream we can write a diagnostic into.136  StreamString strm;137  auto emit_ptrauth_prologue = [&](uint64_t at_address) {138    strm.Printf("EXC_BAD_ACCESS (code=%" PRIu64 ", address=0x%" PRIx64 ")\n",139                m_exc_code, at_address);140    strm.Printf("Note: Possible pointer authentication failure detected.\n");141  };142 143  ABISP abi_sp = process.GetABI();144  assert(abi_sp && "Missing ABI info");145 146  // Check if we have a "brk 0xc47x" trap, where the value that failed to147  // authenticate is in x16.148  Address current_address = current_frame->GetFrameCodeAddress();149  if (IsBreakpoint) {150    RegisterContext *reg_ctx = exe_ctx.GetRegisterContext();151    if (!reg_ctx)152      return false;153 154    const RegisterInfo *X16Info = reg_ctx->GetRegisterInfoByName("x16");155    RegisterValue X16Val;156    if (!reg_ctx->ReadRegister(X16Info, X16Val))157      return false;158    uint64_t bad_address = X16Val.GetAsUInt64();159 160    uint64_t fixed_bad_address = abi_sp->FixCodeAddress(bad_address);161    Address brk_address;162    if (!target.ResolveLoadAddress(fixed_bad_address, brk_address))163      return false;164 165    auto brk_ptrauth_info =166        GetPtrauthInstructionInfo(target, arch, current_address);167    if (brk_ptrauth_info && brk_ptrauth_info->IsAuthenticated) {168      emit_ptrauth_prologue(bad_address);169      strm.Printf("Found value that failed to authenticate ");170      DescribeAddressBriefly(strm, brk_address, target);171      m_description = std::string(strm.GetString());172      return true;173    }174    return false;175  }176 177  assert(IsBadAccess && "Handle EXC_BAD_ACCESS only after this point");178 179  // Check that we have the "bad address" from an EXC_BAD_ACCESS.180  if (m_exc_data_count < 2)181    return false;182 183  // Ok, we know the Target is valid and that it describes a ptrauth-enabled184  // device. Now, we need to determine whether this exception was caused by a185  // ptrauth failure.186 187  uint64_t bad_address = m_exc_subcode;188  uint64_t fixed_bad_address = abi_sp->FixCodeAddress(bad_address);189  uint64_t current_pc = current_address.GetLoadAddress(&target);190 191  // Detect: LDRAA, LDRAB (Load Register, with pointer authentication).192  //193  // If an authenticated load results in an exception, the instruction at the194  // current PC should be one of LDRAx.195  if (bad_address != current_pc && fixed_bad_address != current_pc) {196    auto ptrauth_info =197        GetPtrauthInstructionInfo(target, arch, current_address);198    if (ptrauth_info && ptrauth_info->IsAuthenticated && ptrauth_info->IsLoad) {199      emit_ptrauth_prologue(bad_address);200      strm.Printf("Found authenticated load instruction ");201      DescribeAddressBriefly(strm, current_address, target);202      m_description = std::string(strm.GetString());203      return true;204    }205  }206 207  // Detect: BLRAA, BLRAAZ, BLRAB, BLRABZ (Branch with Link to Register, with208  // pointer authentication).209  //210  // TODO: Detect: BRAA, BRAAZ, BRAB, BRABZ (Branch to Register, with pointer211  // authentication). At a minimum, this requires call site info support for212  // indirect calls.213  //214  // If an authenticated call or tail call results in an exception, stripping215  // the bad address should give the current PC, which points to the address216  // we tried to branch to.217  if (bad_address != current_pc && fixed_bad_address == current_pc) {218    if (StackFrameSP parent_frame = thread.GetStackFrameAtIndex(1)) {219      addr_t return_pc =220          parent_frame->GetFrameCodeAddress().GetLoadAddress(&target);221      Address blr_address;222      if (!target.ResolveLoadAddress(return_pc - 4, blr_address))223        return false;224 225      auto blr_ptrauth_info =226          GetPtrauthInstructionInfo(target, arch, blr_address);227      if (blr_ptrauth_info && blr_ptrauth_info->IsAuthenticated &&228          blr_ptrauth_info->DoesBranch) {229        emit_ptrauth_prologue(bad_address);230        strm.Printf("Found authenticated indirect branch ");231        DescribeAddressBriefly(strm, blr_address, target);232        m_description = std::string(strm.GetString());233        return true;234      }235    }236  }237 238  // TODO: Detect: RETAA, RETAB (Return from subroutine, with pointer239  // authentication).240  //241  // Is there a motivating, non-malicious code snippet that corrupts LR?242 243  return false;244}245 246const char *StopInfoMachException::GetDescription() {247  if (!m_description.empty())248    return m_description.c_str();249  if (GetValue() == eStopReasonInvalid)250    return "invalid stop reason!";251 252  ExecutionContext exe_ctx(m_thread_wp.lock());253  Target *target = exe_ctx.GetTargetPtr();254  const llvm::Triple::ArchType cpu =255      target ? target->GetArchitecture().GetMachine()256             : llvm::Triple::UnknownArch;257 258  const char *exc_desc = nullptr;259  const char *code_label = "code";260  const char *code_desc = nullptr;261  const char *subcode_label = "subcode";262  const char *subcode_desc = nullptr;263 264#if defined(__APPLE__)265  char code_desc_buf[32];266  char subcode_desc_buf[32];267#endif268 269  switch (m_value) {270  case 1: // EXC_BAD_ACCESS271    exc_desc = "EXC_BAD_ACCESS";272    subcode_label = "address";273    switch (cpu) {274    case llvm::Triple::x86:275    case llvm::Triple::x86_64:276      switch (m_exc_code) {277      case 0xd:278        code_desc = "EXC_I386_GPFLT";279        m_exc_data_count = 1;280        break;281      }282      break;283    case llvm::Triple::arm:284    case llvm::Triple::thumb:285      switch (m_exc_code) {286      case 0x101:287        code_desc = "EXC_ARM_DA_ALIGN";288        break;289      case 0x102:290        code_desc = "EXC_ARM_DA_DEBUG";291        break;292      }293      break;294 295    case llvm::Triple::aarch64:296      if (DeterminePtrauthFailure(exe_ctx))297        return m_description.c_str();298      if (DetermineTagMismatch(exe_ctx))299        return m_description.c_str();300      break;301 302    default:303      break;304    }305    break;306 307  case 2: // EXC_BAD_INSTRUCTION308    exc_desc = "EXC_BAD_INSTRUCTION";309    switch (cpu) {310    case llvm::Triple::x86:311    case llvm::Triple::x86_64:312      if (m_exc_code == 1)313        code_desc = "EXC_I386_INVOP";314      break;315 316    case llvm::Triple::arm:317    case llvm::Triple::thumb:318      if (m_exc_code == 1)319        code_desc = "EXC_ARM_UNDEFINED";320      break;321 322    default:323      break;324    }325    break;326 327  case 3: // EXC_ARITHMETIC328    exc_desc = "EXC_ARITHMETIC";329    switch (cpu) {330    case llvm::Triple::x86:331    case llvm::Triple::x86_64:332      switch (m_exc_code) {333      case 1:334        code_desc = "EXC_I386_DIV";335        break;336      case 2:337        code_desc = "EXC_I386_INTO";338        break;339      case 3:340        code_desc = "EXC_I386_NOEXT";341        break;342      case 4:343        code_desc = "EXC_I386_EXTOVR";344        break;345      case 5:346        code_desc = "EXC_I386_EXTERR";347        break;348      case 6:349        code_desc = "EXC_I386_EMERR";350        break;351      case 7:352        code_desc = "EXC_I386_BOUND";353        break;354      case 8:355        code_desc = "EXC_I386_SSEEXTERR";356        break;357      }358      break;359 360    default:361      break;362    }363    break;364 365  case 4: // EXC_EMULATION366    exc_desc = "EXC_EMULATION";367    break;368 369  case 5: // EXC_SOFTWARE370    exc_desc = "EXC_SOFTWARE";371    if (m_exc_code == 0x10003) {372      subcode_desc = "EXC_SOFT_SIGNAL";373      subcode_label = "signo";374    }375    break;376 377  case 6: // EXC_BREAKPOINT378  {379    exc_desc = "EXC_BREAKPOINT";380    switch (cpu) {381    case llvm::Triple::x86:382    case llvm::Triple::x86_64:383      switch (m_exc_code) {384      case 1:385        code_desc = "EXC_I386_SGL";386        break;387      case 2:388        code_desc = "EXC_I386_BPT";389        break;390      }391      break;392 393    case llvm::Triple::arm:394    case llvm::Triple::thumb:395      switch (m_exc_code) {396      case 0x101:397        code_desc = "EXC_ARM_DA_ALIGN";398        break;399      case 0x102:400        code_desc = "EXC_ARM_DA_DEBUG";401        break;402      case 1:403        code_desc = "EXC_ARM_BREAKPOINT";404        break;405      // FIXME temporary workaround, exc_code 0 does not really mean406      // EXC_ARM_BREAKPOINT407      case 0:408        code_desc = "EXC_ARM_BREAKPOINT";409        break;410      }411      break;412 413    case llvm::Triple::aarch64:414      if (DeterminePtrauthFailure(exe_ctx))415        return m_description.c_str();416      break;417 418    default:419      break;420    }421  } break;422 423  case 7:424    exc_desc = "EXC_SYSCALL";425    break;426 427  case 8:428    exc_desc = "EXC_MACH_SYSCALL";429    break;430 431  case 9:432    exc_desc = "EXC_RPC_ALERT";433    break;434 435  case 10:436    exc_desc = "EXC_CRASH";437    break;438  case 11:439    exc_desc = "EXC_RESOURCE";440#if defined(__APPLE__)441    {442      int resource_type = EXC_RESOURCE_DECODE_RESOURCE_TYPE(m_exc_code);443 444      code_label = "limit";445      code_desc = code_desc_buf;446      subcode_label = "observed";447      subcode_desc = subcode_desc_buf;448 449      switch (resource_type) {450      case RESOURCE_TYPE_CPU:451        exc_desc =452            "EXC_RESOURCE (RESOURCE_TYPE_CPU: CPU usage monitor tripped)";453        snprintf(code_desc_buf, sizeof(code_desc_buf), "%d%%",454                 (int)EXC_RESOURCE_CPUMONITOR_DECODE_PERCENTAGE(m_exc_code));455        snprintf(subcode_desc_buf, sizeof(subcode_desc_buf), "%d%%",456                 (int)EXC_RESOURCE_CPUMONITOR_DECODE_PERCENTAGE_OBSERVED(457                     m_exc_subcode));458        break;459      case RESOURCE_TYPE_WAKEUPS:460        exc_desc = "EXC_RESOURCE (RESOURCE_TYPE_WAKEUPS: idle wakeups monitor "461                   "tripped)";462        snprintf(463            code_desc_buf, sizeof(code_desc_buf), "%d w/s",464            (int)EXC_RESOURCE_CPUMONITOR_DECODE_WAKEUPS_PERMITTED(m_exc_code));465        snprintf(subcode_desc_buf, sizeof(subcode_desc_buf), "%d w/s",466                 (int)EXC_RESOURCE_CPUMONITOR_DECODE_WAKEUPS_OBSERVED(467                     m_exc_subcode));468        break;469      case RESOURCE_TYPE_MEMORY:470        exc_desc = "EXC_RESOURCE (RESOURCE_TYPE_MEMORY: high watermark memory "471                   "limit exceeded)";472        snprintf(code_desc_buf, sizeof(code_desc_buf), "%d MB",473                 (int)EXC_RESOURCE_HWM_DECODE_LIMIT(m_exc_code));474        subcode_desc = nullptr;475        subcode_label = nullptr;476        break;477#if defined(RESOURCE_TYPE_IO)478      // RESOURCE_TYPE_IO is introduced in macOS SDK 10.12.479      case RESOURCE_TYPE_IO:480        exc_desc = "EXC_RESOURCE RESOURCE_TYPE_IO";481        snprintf(code_desc_buf, sizeof(code_desc_buf), "%d MB",482                 (int)EXC_RESOURCE_IO_DECODE_LIMIT(m_exc_code));483        snprintf(subcode_desc_buf, sizeof(subcode_desc_buf), "%d MB",484                 (int)EXC_RESOURCE_IO_OBSERVED(m_exc_subcode));485        ;486        break;487#endif488      }489    }490#endif491    break;492  case 12:493    exc_desc = "EXC_GUARD";494    break;495  }496 497  StreamString strm;498 499  if (exc_desc)500    strm.PutCString(exc_desc);501  else502    strm.Printf("EXC_??? (%" PRIu64 ")", m_value);503 504  if (m_exc_data_count >= 1) {505    if (code_desc)506      strm.Printf(" (%s=%s", code_label, code_desc);507    else508      strm.Printf(" (%s=%" PRIu64, code_label, m_exc_code);509  }510 511  if (m_exc_data_count >= 2) {512    if (subcode_label && subcode_desc)513      strm.Printf(", %s=%s", subcode_label, subcode_desc);514    else if (subcode_label)515      strm.Printf(", %s=0x%" PRIx64, subcode_label, m_exc_subcode);516  }517 518  if (m_exc_data_count > 0)519    strm.PutChar(')');520 521  m_description = std::string(strm.GetString());522  return m_description.c_str();523}524 525#if defined(__APPLE__)526const char *527StopInfoMachException::MachException::Name(exception_type_t exc_type) {528  switch (exc_type) {529  case EXC_BAD_ACCESS:530    return "EXC_BAD_ACCESS";531  case EXC_BAD_INSTRUCTION:532    return "EXC_BAD_INSTRUCTION";533  case EXC_ARITHMETIC:534    return "EXC_ARITHMETIC";535  case EXC_EMULATION:536    return "EXC_EMULATION";537  case EXC_SOFTWARE:538    return "EXC_SOFTWARE";539  case EXC_BREAKPOINT:540    return "EXC_BREAKPOINT";541  case EXC_SYSCALL:542    return "EXC_SYSCALL";543  case EXC_MACH_SYSCALL:544    return "EXC_MACH_SYSCALL";545  case EXC_RPC_ALERT:546    return "EXC_RPC_ALERT";547#ifdef EXC_CRASH548  case EXC_CRASH:549    return "EXC_CRASH";550#endif551  case EXC_RESOURCE:552    return "EXC_RESOURCE";553#ifdef EXC_GUARD554  case EXC_GUARD:555    return "EXC_GUARD";556#endif557#ifdef EXC_CORPSE_NOTIFY558  case EXC_CORPSE_NOTIFY:559    return "EXC_CORPSE_NOTIFY";560#endif561#ifdef EXC_CORPSE_VARIANT_BIT562  case EXC_CORPSE_VARIANT_BIT:563    return "EXC_CORPSE_VARIANT_BIT";564#endif565  default:566    break;567  }568  return NULL;569}570 571std::optional<exception_type_t>572StopInfoMachException::MachException::ExceptionCode(const char *name) {573  return llvm::StringSwitch<std::optional<exception_type_t>>(name)574      .Case("EXC_BAD_ACCESS", EXC_BAD_ACCESS)575      .Case("EXC_BAD_INSTRUCTION", EXC_BAD_INSTRUCTION)576      .Case("EXC_ARITHMETIC", EXC_ARITHMETIC)577      .Case("EXC_EMULATION", EXC_EMULATION)578      .Case("EXC_SOFTWARE", EXC_SOFTWARE)579      .Case("EXC_BREAKPOINT", EXC_BREAKPOINT)580      .Case("EXC_SYSCALL", EXC_SYSCALL)581      .Case("EXC_MACH_SYSCALL", EXC_MACH_SYSCALL)582      .Case("EXC_RPC_ALERT", EXC_RPC_ALERT)583#ifdef EXC_CRASH584      .Case("EXC_CRASH", EXC_CRASH)585#endif586      .Case("EXC_RESOURCE", EXC_RESOURCE)587#ifdef EXC_GUARD588      .Case("EXC_GUARD", EXC_GUARD)589#endif590#ifdef EXC_CORPSE_NOTIFY591      .Case("EXC_CORPSE_NOTIFY", EXC_CORPSE_NOTIFY)592#endif593      .Default(std::nullopt);594}595#endif596 597StopInfoSP StopInfoMachException::CreateStopReasonWithMachException(598    Thread &thread, uint32_t exc_type, uint32_t exc_data_count,599    uint64_t exc_code, uint64_t exc_sub_code, uint64_t exc_sub_sub_code,600    bool pc_already_adjusted, bool adjust_pc_if_needed) {601  if (exc_type == 0)602    return StopInfoSP();603 604  bool not_stepping_but_got_singlestep_exception = false;605  uint32_t pc_decrement = 0;606  ExecutionContext exe_ctx(thread.shared_from_this());607  Target *target = exe_ctx.GetTargetPtr();608  const llvm::Triple::ArchType cpu =609      target ? target->GetArchitecture().GetMachine()610             : llvm::Triple::UnknownArch;611 612  ProcessSP process_sp(thread.GetProcess());613  RegisterContextSP reg_ctx_sp(thread.GetRegisterContext());614  // Caveat: with x86 KDP if we've hit a breakpoint, the pc we615  // receive is past the breakpoint instruction.616  // If we have a breakpoints at 0x100 and 0x101, we hit the617  // 0x100 breakpoint and the pc is reported at 0x101.618  // We will initially mark this thread as being stopped at an619  // unexecuted breakpoint at 0x101. Later when we see that620  // we stopped for a Breakpoint reason, we will decrement the621  // pc, and update the thread to record that we hit the622  // breakpoint at 0x100.623  // The fact that the pc may be off by one at this point624  // (for an x86 KDP breakpoint hit) is not a problem.625  addr_t pc = reg_ctx_sp->GetPC();626  BreakpointSiteSP bp_site_sp =627      process_sp->GetBreakpointSiteList().FindByAddress(pc);628  if (bp_site_sp && bp_site_sp->IsEnabled())629    thread.SetThreadStoppedAtUnexecutedBP(pc);630 631  switch (exc_type) {632  case 1: // EXC_BAD_ACCESS633  case 2: // EXC_BAD_INSTRUCTION634  case 3: // EXC_ARITHMETIC635  case 4: // EXC_EMULATION636    break;637 638  case 5:                    // EXC_SOFTWARE639    if (exc_code == 0x10003) // EXC_SOFT_SIGNAL640    {641      if (exc_sub_code == 5) {642        // On MacOSX, a SIGTRAP can signify that a process has called exec,643        // so we should check with our dynamic loader to verify.644        ProcessSP process_sp(thread.GetProcess());645        if (process_sp) {646          DynamicLoader *dynamic_loader = process_sp->GetDynamicLoader();647          if (dynamic_loader && dynamic_loader->ProcessDidExec()) {648            // The program was re-exec'ed649            return StopInfo::CreateStopReasonWithExec(thread);650          }651        }652      }653      return StopInfo::CreateStopReasonWithSignal(thread, exc_sub_code);654    }655    break;656 657    // A mach exception comes with 2-4 pieces of data.658    // The sub-codes are only provided for certain types659    // of mach exceptions.660    // [exc_type, exc_code, exc_sub_code, exc_sub_sub_code]661    //662    // Here are all of the EXC_BREAKPOINT, exc_type==6,663    // exceptions we can receive.664    //665    // Instruction step:666    //   [6, 1, 0]667    //   Intel KDP [6, 3, ??]668    //   armv7 [6, 0x102, <stop-pc>]  Same as software breakpoint!669    //670    // Software breakpoint:671    //   x86 [6, 2, 0]672    //   Intel KDP [6, 2, <bp-addr + 1>]673    //   arm64 [6, 1, <bp-addr>]674    //   armv7 [6, 0x102, <bp-addr>]  Same as instruction step!675    //676    // Hardware breakpoint:677    //   x86 [6, 1, <bp-addr>, 0]678    //   x86/Rosetta not implemented, see software breakpoint679    //   arm64 [6, 1, <bp-addr>]680    //   armv7 not implemented, see software breakpoint681    //682    // Hardware watchpoint:683    //   x86 [6, 1, <accessed-addr>, 0] (both Intel hw and Rosetta)684    //   arm64 [6, 0x102, <accessed-addr>, 0]685    //   armv7 [6, 0x102, <accessed-addr>, 0]686    //687    // arm64 BRK instruction (imm arg not reflected in the ME)688    //   [ 6, 1, <addr-of-BRK-insn>]689    //690    // In order of codes mach exceptions:691    //   [6, 1, 0] - instruction step692    //   [6, 1, <bp-addr>] - hardware breakpoint or watchpoint693    //694    //   [6, 2, 0] - software breakpoint695    //   [6, 2, <bp-addr + 1>] - software breakpoint696    //697    //   [6, 3] - instruction step698    //699    //   [6, 0x102, <stop-pc>] armv7 instruction step700    //   [6, 0x102, <bp-addr>] armv7 software breakpoint701    //   [6, 0x102, <accessed-addr>, 0] arm64/armv7 watchpoint702 703  case 6: // EXC_BREAKPOINT704  {705    bool stopped_by_hitting_breakpoint = false;706    bool stopped_by_completing_stepi = false;707    bool stopped_watchpoint = false;708    std::optional<addr_t> address;709 710    // exc_code 1711    if (exc_code == 1) {712      if (exc_sub_code == 0) {713        stopped_by_completing_stepi = true;714      } else {715        // Ambiguous: could be signalling a716        // breakpoint or watchpoint hit.717        stopped_by_hitting_breakpoint = true;718        stopped_watchpoint = true;719        address = exc_sub_code;720      }721    }722 723    // exc_code 2724    if (exc_code == 2) {725      if (exc_sub_code == 0)726        stopped_by_hitting_breakpoint = true;727      else {728        stopped_by_hitting_breakpoint = true;729        // Intel KDP software breakpoint730        if (!pc_already_adjusted)731          pc_decrement = 1;732      }733    }734 735    // exc_code 3736    if (exc_code == 3)737      stopped_by_completing_stepi = true;738 739    // exc_code 0x102740    if (exc_code == 0x102 && exc_sub_code != 0) {741      if (cpu == llvm::Triple::arm || cpu == llvm::Triple::thumb) {742        stopped_by_hitting_breakpoint = true;743        stopped_by_completing_stepi = true;744      }745      stopped_watchpoint = true;746      address = exc_sub_code;747    }748 749    // The Mach Exception may have been ambiguous --750    // e.g. we stopped either because of a breakpoint751    // or a watchpoint.  We'll disambiguate which it752    // really was.753 754    if (stopped_by_hitting_breakpoint) {755      addr_t pc = reg_ctx_sp->GetPC() - pc_decrement;756 757      if (address)758        bp_site_sp =759            process_sp->GetBreakpointSiteList().FindByAddress(*address);760      if (!bp_site_sp && reg_ctx_sp) {761        bp_site_sp = process_sp->GetBreakpointSiteList().FindByAddress(pc);762      }763      if (bp_site_sp && bp_site_sp->IsEnabled()) {764        // We've hit this breakpoint, whether it was intended for this thread765        // or not.  Clear this in the Tread object so we step past it on resume.766        thread.SetThreadHitBreakpointSite();767 768        if (bp_site_sp->ValidForThisThread(thread)) {769          // Update the PC if we were asked to do so, but only do so if we find770          // a breakpoint that we know about because this could be a trap771          // instruction in the code.772          if (pc_decrement > 0 && adjust_pc_if_needed && reg_ctx_sp)773            reg_ctx_sp->SetPC(pc);774 775          return StopInfo::CreateStopReasonWithBreakpointSiteID(776              thread, bp_site_sp->GetID());777        } else {778          return StopInfoSP();779        }780      }781    }782 783    // Breakpoint-hit events are handled.784    // Now handle watchpoints.785 786    if (stopped_watchpoint && address) {787      WatchpointResourceSP wp_rsrc_sp =788          target->GetProcessSP()->GetWatchpointResourceList().FindByAddress(789              *address);790      if (wp_rsrc_sp && wp_rsrc_sp->GetNumberOfConstituents() > 0) {791        return StopInfo::CreateStopReasonWithWatchpointID(792            thread, wp_rsrc_sp->GetConstituentAtIndex(0)->GetID());793      }794    }795 796    // Finally, handle instruction step.797 798    if (stopped_by_completing_stepi) {799      if (thread.GetTemporaryResumeState() != eStateStepping)800        not_stepping_but_got_singlestep_exception = true;801      else802        return StopInfo::CreateStopReasonToTrace(thread);803    }804 805  } break;806 807  case 7:  // EXC_SYSCALL808  case 8:  // EXC_MACH_SYSCALL809  case 9:  // EXC_RPC_ALERT810  case 10: // EXC_CRASH811    break;812  }813 814  return std::make_shared<StopInfoMachException>(815      thread, exc_type, exc_data_count, exc_code, exc_sub_code,816      not_stepping_but_got_singlestep_exception);817}818 819// Detect an unusual situation on Darwin where:820//821//   0. We did an instruction-step before this.822//   1. We have a hardware breakpoint or watchpoint set.823//   2. We resumed the process, but not with an instruction-step.824//   3. The thread gets an "instruction-step completed" mach exception.825//   4. The pc has not advanced - it is the same as before.826//827// This method returns true for that combination of events.828bool StopInfoMachException::WasContinueInterrupted(Thread &thread) {829  Log *log = GetLog(LLDBLog::Step);830 831  // We got an instruction-step completed mach exception but we were not832  // doing an instruction step on this thread.833  if (!m_not_stepping_but_got_singlestep_exception)834    return false;835 836  RegisterContextSP reg_ctx_sp(thread.GetRegisterContext());837  std::optional<addr_t> prev_pc = thread.GetPreviousFrameZeroPC();838  if (!reg_ctx_sp || !prev_pc)839    return false;840 841  // The previous pc value and current pc value are the same.842  if (*prev_pc != reg_ctx_sp->GetPC())843    return false;844 845  // We have a watchpoint -- this is the kernel bug.846  ProcessSP process_sp = thread.GetProcess();847  if (process_sp->GetWatchpointResourceList().GetSize()) {848    LLDB_LOGF(log,849              "Thread stopped with insn-step completed mach exception but "850              "thread was not stepping; there is a hardware watchpoint set.");851    return true;852  }853 854  // We have a hardware breakpoint -- this is the kernel bug.855  auto &bp_site_list = process_sp->GetBreakpointSiteList();856  for (auto &site : bp_site_list.Sites()) {857    if (site->IsHardware() && site->IsEnabled()) {858      LLDB_LOGF(log,859                "Thread stopped with insn-step completed mach exception but "860                "thread was not stepping; there is a hardware breakpoint set.");861      return true;862    }863  }864 865  return false;866}867