17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate  * CDDL HEADER START
37c478bd9Sstevel@tonic-gate  *
47c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5843e1988Sjohnlev  * Common Development and Distribution License (the "License").
6843e1988Sjohnlev  * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate  *
87c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate  * and limitations under the License.
127c478bd9Sstevel@tonic-gate  *
137c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate  *
197c478bd9Sstevel@tonic-gate  * CDDL HEADER END
207c478bd9Sstevel@tonic-gate  */
217c478bd9Sstevel@tonic-gate /*
22843e1988Sjohnlev  * Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
237c478bd9Sstevel@tonic-gate  * Use is subject to license terms.
247c478bd9Sstevel@tonic-gate  */
250a47c91cSRobert Mustacchi /*
26*9c3024a3SHans Rosenfeld  * Copyright (c) 2018, Joyent, Inc.  All rights reserved.
270b453801SGordon Ross  * Copyright 2014 Nexenta Systems, Inc.  All rights reserved.
280a47c91cSRobert Mustacchi  */
297c478bd9Sstevel@tonic-gate 
307c478bd9Sstevel@tonic-gate #include <sys/types.h>
31*9c3024a3SHans Rosenfeld #include <sys/types32.h>
327c478bd9Sstevel@tonic-gate #include <sys/reg.h>
337c478bd9Sstevel@tonic-gate #include <sys/privregs.h>
347c478bd9Sstevel@tonic-gate #include <sys/stack.h>
357c478bd9Sstevel@tonic-gate #include <sys/frame.h>
367c478bd9Sstevel@tonic-gate 
37*9c3024a3SHans Rosenfeld #include <mdb/mdb_isautil.h>
387c478bd9Sstevel@tonic-gate #include <mdb/mdb_ia32util.h>
397c478bd9Sstevel@tonic-gate #include <mdb/mdb_target_impl.h>
407c478bd9Sstevel@tonic-gate #include <mdb/mdb_kreg_impl.h>
417c478bd9Sstevel@tonic-gate #include <mdb/mdb_debug.h>
427c478bd9Sstevel@tonic-gate #include <mdb/mdb_modapi.h>
437c478bd9Sstevel@tonic-gate #include <mdb/mdb_err.h>
447c478bd9Sstevel@tonic-gate #include <mdb/mdb.h>
457c478bd9Sstevel@tonic-gate 
46*9c3024a3SHans Rosenfeld #ifndef __amd64
477c478bd9Sstevel@tonic-gate /*
487c478bd9Sstevel@tonic-gate  * We also define an array of register names and their corresponding
497c478bd9Sstevel@tonic-gate  * array indices.  This is used by the getareg and putareg entry points,
507c478bd9Sstevel@tonic-gate  * and also by our register variable discipline.
51*9c3024a3SHans Rosenfeld  *
52*9c3024a3SHans Rosenfeld  * When built into an amd64 mdb this won't be used as it's only a subset of
53*9c3024a3SHans Rosenfeld  * mdb_amd64_kregs, hence the #ifdef.
547c478bd9Sstevel@tonic-gate  */
557c478bd9Sstevel@tonic-gate const mdb_tgt_regdesc_t mdb_ia32_kregs[] = {
567c478bd9Sstevel@tonic-gate 	{ "savfp", KREG_SAVFP, MDB_TGT_R_EXPORT },
577c478bd9Sstevel@tonic-gate 	{ "savpc", KREG_SAVPC, MDB_TGT_R_EXPORT },
587c478bd9Sstevel@tonic-gate 	{ "eax", KREG_EAX, MDB_TGT_R_EXPORT },
590a47c91cSRobert Mustacchi 	{ "ax", KREG_EAX, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
600a47c91cSRobert Mustacchi 	{ "ah", KREG_EAX, MDB_TGT_R_EXPORT | MDB_TGT_R_8H },
610a47c91cSRobert Mustacchi 	{ "al", KREG_EAX, MDB_TGT_R_EXPORT | MDB_TGT_R_8L },
627c478bd9Sstevel@tonic-gate 	{ "ebx", KREG_EBX, MDB_TGT_R_EXPORT },
630a47c91cSRobert Mustacchi 	{ "bx", KREG_EBX, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
640a47c91cSRobert Mustacchi 	{ "bh", KREG_EBX, MDB_TGT_R_EXPORT | MDB_TGT_R_8H },
650a47c91cSRobert Mustacchi 	{ "bl", KREG_EBX, MDB_TGT_R_EXPORT | MDB_TGT_R_8L },
667c478bd9Sstevel@tonic-gate 	{ "ecx", KREG_ECX, MDB_TGT_R_EXPORT },
670a47c91cSRobert Mustacchi 	{ "cx", KREG_ECX, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
680a47c91cSRobert Mustacchi 	{ "ch", KREG_ECX, MDB_TGT_R_EXPORT | MDB_TGT_R_8H },
690a47c91cSRobert Mustacchi 	{ "cl", KREG_ECX, MDB_TGT_R_EXPORT | MDB_TGT_R_8L },
707c478bd9Sstevel@tonic-gate 	{ "edx", KREG_EDX, MDB_TGT_R_EXPORT },
710a47c91cSRobert Mustacchi 	{ "dx", KREG_EDX, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
720a47c91cSRobert Mustacchi 	{ "dh", KREG_EDX, MDB_TGT_R_EXPORT | MDB_TGT_R_8H },
730a47c91cSRobert Mustacchi 	{ "dl", KREG_EDX, MDB_TGT_R_EXPORT | MDB_TGT_R_8L },
747c478bd9Sstevel@tonic-gate 	{ "esi", KREG_ESI, MDB_TGT_R_EXPORT },
750a47c91cSRobert Mustacchi 	{ "si", KREG_ESI, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
767c478bd9Sstevel@tonic-gate 	{ "edi", KREG_EDI, MDB_TGT_R_EXPORT },
770a47c91cSRobert Mustacchi 	{ "di",	EDI, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
787c478bd9Sstevel@tonic-gate 	{ "ebp", KREG_EBP, MDB_TGT_R_EXPORT },
790a47c91cSRobert Mustacchi 	{ "bp", KREG_EBP, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
807c478bd9Sstevel@tonic-gate 	{ "esp", KREG_ESP, MDB_TGT_R_EXPORT },
810a47c91cSRobert Mustacchi 	{ "sp", KREG_ESP, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
827c478bd9Sstevel@tonic-gate 	{ "cs", KREG_CS, MDB_TGT_R_EXPORT },
837c478bd9Sstevel@tonic-gate 	{ "ds", KREG_DS, MDB_TGT_R_EXPORT },
847c478bd9Sstevel@tonic-gate 	{ "ss", KREG_SS, MDB_TGT_R_EXPORT },
857c478bd9Sstevel@tonic-gate 	{ "es", KREG_ES, MDB_TGT_R_EXPORT },
867c478bd9Sstevel@tonic-gate 	{ "fs", KREG_FS, MDB_TGT_R_EXPORT },
877c478bd9Sstevel@tonic-gate 	{ "gs", KREG_GS, MDB_TGT_R_EXPORT },
887c478bd9Sstevel@tonic-gate 	{ "eflags", KREG_EFLAGS, MDB_TGT_R_EXPORT },
897c478bd9Sstevel@tonic-gate 	{ "eip", KREG_EIP, MDB_TGT_R_EXPORT },
907c478bd9Sstevel@tonic-gate 	{ "uesp", KREG_UESP, MDB_TGT_R_EXPORT | MDB_TGT_R_PRIV },
910a47c91cSRobert Mustacchi 	{ "usp", KREG_UESP, MDB_TGT_R_EXPORT | MDB_TGT_R_16 },
927c478bd9Sstevel@tonic-gate 	{ "trapno", KREG_TRAPNO, MDB_TGT_R_EXPORT | MDB_TGT_R_PRIV },
937c478bd9Sstevel@tonic-gate 	{ "err", KREG_ERR, MDB_TGT_R_EXPORT | MDB_TGT_R_PRIV },
947c478bd9Sstevel@tonic-gate 	{ NULL, 0, 0 }
957c478bd9Sstevel@tonic-gate };
96*9c3024a3SHans Rosenfeld #endif
977c478bd9Sstevel@tonic-gate 
987c478bd9Sstevel@tonic-gate void
mdb_ia32_printregs(const mdb_tgt_gregset_t * gregs)997c478bd9Sstevel@tonic-gate mdb_ia32_printregs(const mdb_tgt_gregset_t *gregs)
1007c478bd9Sstevel@tonic-gate {
1017c478bd9Sstevel@tonic-gate 	const kreg_t *kregs = &gregs->kregs[0];
1027c478bd9Sstevel@tonic-gate 	kreg_t eflags = kregs[KREG_EFLAGS];
1037c478bd9Sstevel@tonic-gate 
104*9c3024a3SHans Rosenfeld 	mdb_printf("%%cs = 0x%04x\t\t%%eax = 0x%08p %A\n",
1057c478bd9Sstevel@tonic-gate 	    kregs[KREG_CS], kregs[KREG_EAX], kregs[KREG_EAX]);
1067c478bd9Sstevel@tonic-gate 
107*9c3024a3SHans Rosenfeld 	mdb_printf("%%ds = 0x%04x\t\t%%ebx = 0x%08p %A\n",
1087c478bd9Sstevel@tonic-gate 	    kregs[KREG_DS], kregs[KREG_EBX], kregs[KREG_EBX]);
1097c478bd9Sstevel@tonic-gate 
110*9c3024a3SHans Rosenfeld 	mdb_printf("%%ss = 0x%04x\t\t%%ecx = 0x%08p %A\n",
1117c478bd9Sstevel@tonic-gate 	    kregs[KREG_SS], kregs[KREG_ECX], kregs[KREG_ECX]);
1127c478bd9Sstevel@tonic-gate 
113*9c3024a3SHans Rosenfeld 	mdb_printf("%%es = 0x%04x\t\t%%edx = 0x%08p %A\n",
1147c478bd9Sstevel@tonic-gate 	    kregs[KREG_ES], kregs[KREG_EDX], kregs[KREG_EDX]);
1157c478bd9Sstevel@tonic-gate 
116*9c3024a3SHans Rosenfeld 	mdb_printf("%%fs = 0x%04x\t\t%%esi = 0x%08p %A\n",
1177c478bd9Sstevel@tonic-gate 	    kregs[KREG_FS], kregs[KREG_ESI], kregs[KREG_ESI]);
1187c478bd9Sstevel@tonic-gate 
119*9c3024a3SHans Rosenfeld 	mdb_printf("%%gs = 0x%04x\t\t%%edi = 0x%08p %A\n\n",
1207c478bd9Sstevel@tonic-gate 	    kregs[KREG_GS], kregs[KREG_EDI], kregs[KREG_EDI]);
1217c478bd9Sstevel@tonic-gate 
122*9c3024a3SHans Rosenfeld 	mdb_printf("%%eip = 0x%08p %A\n", kregs[KREG_EIP], kregs[KREG_EIP]);
123*9c3024a3SHans Rosenfeld 	mdb_printf("%%ebp = 0x%08p\n", kregs[KREG_EBP]);
124*9c3024a3SHans Rosenfeld 	mdb_printf("%%esp = 0x%08p\n\n", kregs[KREG_ESP]);
1257c478bd9Sstevel@tonic-gate 	mdb_printf("%%eflags = 0x%08x\n", eflags);
1267c478bd9Sstevel@tonic-gate 
1277c478bd9Sstevel@tonic-gate 	mdb_printf("  id=%u vip=%u vif=%u ac=%u vm=%u rf=%u nt=%u iopl=0x%x\n",
1287c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_ID_MASK) >> KREG_EFLAGS_ID_SHIFT,
1297c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_VIP_MASK) >> KREG_EFLAGS_VIP_SHIFT,
1307c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_VIF_MASK) >> KREG_EFLAGS_VIF_SHIFT,
1317c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_AC_MASK) >> KREG_EFLAGS_AC_SHIFT,
1327c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_VM_MASK) >> KREG_EFLAGS_VM_SHIFT,
1337c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_RF_MASK) >> KREG_EFLAGS_RF_SHIFT,
1347c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_NT_MASK) >> KREG_EFLAGS_NT_SHIFT,
1357c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_IOPL_MASK) >> KREG_EFLAGS_IOPL_SHIFT);
1367c478bd9Sstevel@tonic-gate 
1377c478bd9Sstevel@tonic-gate 	mdb_printf("  status=<%s,%s,%s,%s,%s,%s,%s,%s,%s>\n\n",
1387c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_OF_MASK) ? "OF" : "of",
1397c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_DF_MASK) ? "DF" : "df",
1407c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_IF_MASK) ? "IF" : "if",
1417c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_TF_MASK) ? "TF" : "tf",
1427c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_SF_MASK) ? "SF" : "sf",
1437c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_ZF_MASK) ? "ZF" : "zf",
1447c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_AF_MASK) ? "AF" : "af",
1457c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_PF_MASK) ? "PF" : "pf",
1467c478bd9Sstevel@tonic-gate 	    (eflags & KREG_EFLAGS_CF_MASK) ? "CF" : "cf");
1477c478bd9Sstevel@tonic-gate 
148*9c3024a3SHans Rosenfeld #if !defined(__amd64) && !defined(_KMDB)
149*9c3024a3SHans Rosenfeld 	mdb_printf("  %%uesp = 0x%08x\n", kregs[KREG_UESP]);
1507c478bd9Sstevel@tonic-gate #endif
1517c478bd9Sstevel@tonic-gate 	mdb_printf("%%trapno = 0x%x\n", kregs[KREG_TRAPNO]);
1527c478bd9Sstevel@tonic-gate 	mdb_printf("   %%err = 0x%x\n", kregs[KREG_ERR]);
1537c478bd9Sstevel@tonic-gate }
1547c478bd9Sstevel@tonic-gate 
1557c478bd9Sstevel@tonic-gate /*
1567c478bd9Sstevel@tonic-gate  * Given a return address (%eip), determine the likely number of arguments
1577c478bd9Sstevel@tonic-gate  * that were pushed on the stack prior to its execution.  We do this by
1587c478bd9Sstevel@tonic-gate  * expecting that a typical call sequence consists of pushing arguments on
1597c478bd9Sstevel@tonic-gate  * the stack, executing a call instruction, and then performing an add
1607c478bd9Sstevel@tonic-gate  * on %esp to restore it to the value prior to pushing the arguments for
1617c478bd9Sstevel@tonic-gate  * the call.  We attempt to detect such an add, and divide the addend
1627c478bd9Sstevel@tonic-gate  * by the size of a word to determine the number of pushed arguments.
1637c478bd9Sstevel@tonic-gate  */
1647c478bd9Sstevel@tonic-gate static uint_t
kvm_argcount(mdb_tgt_t * t,uintptr_t eip,ssize_t size)1657c478bd9Sstevel@tonic-gate kvm_argcount(mdb_tgt_t *t, uintptr_t eip, ssize_t size)
1667c478bd9Sstevel@tonic-gate {
1677c478bd9Sstevel@tonic-gate 	uint8_t ins[6];
1687c478bd9Sstevel@tonic-gate 	ulong_t n;
1697c478bd9Sstevel@tonic-gate 
1707c478bd9Sstevel@tonic-gate 	enum {
1717c478bd9Sstevel@tonic-gate 		M_MODRM_ESP = 0xc4,	/* Mod/RM byte indicates %esp */
1727c478bd9Sstevel@tonic-gate 		M_ADD_IMM32 = 0x81,	/* ADD imm32 to r/m32 */
1737c478bd9Sstevel@tonic-gate 		M_ADD_IMM8  = 0x83	/* ADD imm8 to r/m32 */
1747c478bd9Sstevel@tonic-gate 	};
1757c478bd9Sstevel@tonic-gate 
176*9c3024a3SHans Rosenfeld 	if (mdb_tgt_aread(t, MDB_TGT_AS_VIRT_I, ins, sizeof (ins), eip) !=
177*9c3024a3SHans Rosenfeld 	    sizeof (ins))
1787c478bd9Sstevel@tonic-gate 		return (0);
1797c478bd9Sstevel@tonic-gate 
1807c478bd9Sstevel@tonic-gate 	if (ins[1] != M_MODRM_ESP)
1817c478bd9Sstevel@tonic-gate 		return (0);
1827c478bd9Sstevel@tonic-gate 
1837c478bd9Sstevel@tonic-gate 	switch (ins[0]) {
1847c478bd9Sstevel@tonic-gate 	case M_ADD_IMM32:
1857c478bd9Sstevel@tonic-gate 		n = ins[2] + (ins[3] << 8) + (ins[4] << 16) + (ins[5] << 24);
1867c478bd9Sstevel@tonic-gate 		break;
1877c478bd9Sstevel@tonic-gate 
1887c478bd9Sstevel@tonic-gate 	case M_ADD_IMM8:
1897c478bd9Sstevel@tonic-gate 		n = ins[2];
1907c478bd9Sstevel@tonic-gate 		break;
1917c478bd9Sstevel@tonic-gate 
1927c478bd9Sstevel@tonic-gate 	default:
1937c478bd9Sstevel@tonic-gate 		n = 0;
1947c478bd9Sstevel@tonic-gate 	}
1957c478bd9Sstevel@tonic-gate 
196*9c3024a3SHans Rosenfeld 	return (MIN((ssize_t)n, size) / sizeof (uint32_t));
1977c478bd9Sstevel@tonic-gate }
1987c478bd9Sstevel@tonic-gate 
1997c478bd9Sstevel@tonic-gate int
mdb_ia32_kvm_stack_iter(mdb_tgt_t * t,const mdb_tgt_gregset_t * gsp,mdb_tgt_stack_f * func,void * arg)2007c478bd9Sstevel@tonic-gate mdb_ia32_kvm_stack_iter(mdb_tgt_t *t, const mdb_tgt_gregset_t *gsp,
2017c478bd9Sstevel@tonic-gate     mdb_tgt_stack_f *func, void *arg)
2027c478bd9Sstevel@tonic-gate {
2037c478bd9Sstevel@tonic-gate 	mdb_tgt_gregset_t gregs;
2047c478bd9Sstevel@tonic-gate 	kreg_t *kregs = &gregs.kregs[0];
2057c478bd9Sstevel@tonic-gate 	int got_pc = (gsp->kregs[KREG_EIP] != 0);
2060b453801SGordon Ross 	int err;
2077c478bd9Sstevel@tonic-gate 
20832b5e9f0SRichard Lowe 	struct fr {
209*9c3024a3SHans Rosenfeld 		uintptr32_t fr_savfp;
210*9c3024a3SHans Rosenfeld 		uintptr32_t fr_savpc;
211*9c3024a3SHans Rosenfeld 		uint32_t fr_argv[32];
2127c478bd9Sstevel@tonic-gate 	} fr;
2137c478bd9Sstevel@tonic-gate 
2147c478bd9Sstevel@tonic-gate 	uintptr_t fp = gsp->kregs[KREG_EBP];
2157c478bd9Sstevel@tonic-gate 	uintptr_t pc = gsp->kregs[KREG_EIP];
2160b453801SGordon Ross 	uintptr_t lastfp = 0;
2177c478bd9Sstevel@tonic-gate 
2187c478bd9Sstevel@tonic-gate 	ssize_t size;
2197c478bd9Sstevel@tonic-gate 	uint_t argc;
220843e1988Sjohnlev 	int detect_exception_frames = 0;
22132b5e9f0SRichard Lowe 	int advance_tortoise = 1;
22232b5e9f0SRichard Lowe 	uintptr_t tortoise_fp = 0;
223843e1988Sjohnlev #ifndef	_KMDB
224843e1988Sjohnlev 	int xp;
225843e1988Sjohnlev 
226843e1988Sjohnlev 	if ((mdb_readsym(&xp, sizeof (xp), "xpv_panicking") != -1) && (xp > 0))
227843e1988Sjohnlev 		detect_exception_frames = 1;
228843e1988Sjohnlev #endif
2297c478bd9Sstevel@tonic-gate 
2307c478bd9Sstevel@tonic-gate 	bcopy(gsp, &gregs, sizeof (gregs));
2317c478bd9Sstevel@tonic-gate 
2327c478bd9Sstevel@tonic-gate 	while (fp != 0) {
2330b453801SGordon Ross 		if (fp & (STACK_ALIGN - 1)) {
2340b453801SGordon Ross 			err = EMDB_STKALIGN;
2350b453801SGordon Ross 			goto badfp;
2360b453801SGordon Ross 		}
237*9c3024a3SHans Rosenfeld 		if ((size = mdb_tgt_aread(t, MDB_TGT_AS_VIRT_S, &fr,
238*9c3024a3SHans Rosenfeld 		    sizeof (fr), fp)) >= (ssize_t)(2 * sizeof (uintptr32_t))) {
239*9c3024a3SHans Rosenfeld 			size -= (ssize_t)(2 * sizeof (uintptr32_t));
2407c478bd9Sstevel@tonic-gate 			argc = kvm_argcount(t, fr.fr_savpc, size);
2417c478bd9Sstevel@tonic-gate 		} else {
2420b453801SGordon Ross 			err = EMDB_NOMAP;
2430b453801SGordon Ross 			goto badfp;
2447c478bd9Sstevel@tonic-gate 		}
2457c478bd9Sstevel@tonic-gate 
24632b5e9f0SRichard Lowe 		if (tortoise_fp == 0) {
24732b5e9f0SRichard Lowe 			tortoise_fp = fp;
24832b5e9f0SRichard Lowe 		} else {
24932b5e9f0SRichard Lowe 			/*
25032b5e9f0SRichard Lowe 			 * Advance tortoise_fp every other frame, so we detect
25132b5e9f0SRichard Lowe 			 * cycles with Floyd's tortoise/hare.
25232b5e9f0SRichard Lowe 			 */
25332b5e9f0SRichard Lowe 			if (advance_tortoise != 0) {
25432b5e9f0SRichard Lowe 				struct fr tfr;
25532b5e9f0SRichard Lowe 
256*9c3024a3SHans Rosenfeld 				if (mdb_tgt_aread(t, MDB_TGT_AS_VIRT_S, &tfr,
257*9c3024a3SHans Rosenfeld 				    sizeof (tfr), tortoise_fp) !=
258*9c3024a3SHans Rosenfeld 				    sizeof (tfr)) {
25932b5e9f0SRichard Lowe 					err = EMDB_NOMAP;
26032b5e9f0SRichard Lowe 					goto badfp;
26132b5e9f0SRichard Lowe 				}
26232b5e9f0SRichard Lowe 
26332b5e9f0SRichard Lowe 				tortoise_fp = tfr.fr_savfp;
26432b5e9f0SRichard Lowe 			}
26532b5e9f0SRichard Lowe 
26632b5e9f0SRichard Lowe 			if (fp == tortoise_fp) {
26732b5e9f0SRichard Lowe 				err = EMDB_STKFRAME;
26832b5e9f0SRichard Lowe 				goto badfp;
26932b5e9f0SRichard Lowe 			}
27032b5e9f0SRichard Lowe 		}
27132b5e9f0SRichard Lowe 
27232b5e9f0SRichard Lowe 		advance_tortoise = !advance_tortoise;
27332b5e9f0SRichard Lowe 
274*9c3024a3SHans Rosenfeld 		if (got_pc &&
275*9c3024a3SHans Rosenfeld 		    func(arg, pc, argc, (const long *)fr.fr_argv, &gregs) != 0)
2767c478bd9Sstevel@tonic-gate 			break;
2777c478bd9Sstevel@tonic-gate 
2787c478bd9Sstevel@tonic-gate 		kregs[KREG_ESP] = kregs[KREG_EBP];
2797c478bd9Sstevel@tonic-gate 
280843e1988Sjohnlev 		lastfp = fp;
281843e1988Sjohnlev 		fp = fr.fr_savfp;
282843e1988Sjohnlev 		/*
283843e1988Sjohnlev 		 * The Xen hypervisor marks a stack frame as belonging to
284843e1988Sjohnlev 		 * an exception by inverting the bits of the pointer to
285843e1988Sjohnlev 		 * that frame.  We attempt to identify these frames by
286843e1988Sjohnlev 		 * inverting the pointer and seeing if it is within 0xfff
287843e1988Sjohnlev 		 * bytes of the last frame.
288843e1988Sjohnlev 		 */
289843e1988Sjohnlev 		if (detect_exception_frames)
290843e1988Sjohnlev 			if ((fp != 0) && (fp < lastfp) &&
291843e1988Sjohnlev 			    ((lastfp ^ ~fp) < 0xfff))
292843e1988Sjohnlev 				fp = ~fp;
293843e1988Sjohnlev 
294843e1988Sjohnlev 		kregs[KREG_EBP] = fp;
2957c478bd9Sstevel@tonic-gate 		kregs[KREG_EIP] = pc = fr.fr_savpc;
2967c478bd9Sstevel@tonic-gate 
2977c478bd9Sstevel@tonic-gate 		got_pc = (pc != 0);
2987c478bd9Sstevel@tonic-gate 	}
2997c478bd9Sstevel@tonic-gate 
3007c478bd9Sstevel@tonic-gate 	return (0);
3010b453801SGordon Ross 
3020b453801SGordon Ross badfp:
3030b453801SGordon Ross 	mdb_printf("%p [%s]", fp, mdb_strerror(err));
3040b453801SGordon Ross 	return (set_errno(err));
3057c478bd9Sstevel@tonic-gate }
3067c478bd9Sstevel@tonic-gate 
307*9c3024a3SHans Rosenfeld #ifndef __amd64
308*9c3024a3SHans Rosenfeld /*
309*9c3024a3SHans Rosenfeld  * The functions mdb_ia32_step_out and mdb_ia32_next haven't yet been adapted
310*9c3024a3SHans Rosenfeld  * to work when built for an amd64 mdb. They are unused by the amd64-only bhyve
311*9c3024a3SHans Rosenfeld  * target, hence the #ifdef.
312*9c3024a3SHans Rosenfeld  */
3137c478bd9Sstevel@tonic-gate /*
3147c478bd9Sstevel@tonic-gate  * Determine the return address for the current frame.  Typically this is the
3157c478bd9Sstevel@tonic-gate  * fr_savpc value from the current frame, but we also perform some special
3167c478bd9Sstevel@tonic-gate  * handling to see if we are stopped on one of the first two instructions of a
3177c478bd9Sstevel@tonic-gate  * typical function prologue, in which case %ebp will not be set up yet.
3187c478bd9Sstevel@tonic-gate  */
3197c478bd9Sstevel@tonic-gate int
mdb_ia32_step_out(mdb_tgt_t * t,uintptr_t * p,kreg_t pc,kreg_t fp,kreg_t sp,mdb_instr_t curinstr)3207c478bd9Sstevel@tonic-gate mdb_ia32_step_out(mdb_tgt_t *t, uintptr_t *p, kreg_t pc, kreg_t fp, kreg_t sp,
3217c478bd9Sstevel@tonic-gate     mdb_instr_t curinstr)
3227c478bd9Sstevel@tonic-gate {
3237c478bd9Sstevel@tonic-gate 	struct frame fr;
3247c478bd9Sstevel@tonic-gate 	GElf_Sym s;
3257c478bd9Sstevel@tonic-gate 	char buf[1];
3267c478bd9Sstevel@tonic-gate 
3277c478bd9Sstevel@tonic-gate 	enum {
3287c478bd9Sstevel@tonic-gate 		M_PUSHL_EBP	= 0x55, /* pushl %ebp */
3297c478bd9Sstevel@tonic-gate 		M_MOVL_EBP	= 0x8b  /* movl %esp, %ebp */
3307c478bd9Sstevel@tonic-gate 	};
3317c478bd9Sstevel@tonic-gate 
3327c478bd9Sstevel@tonic-gate 	if (mdb_tgt_lookup_by_addr(t, pc, MDB_TGT_SYM_FUZZY,
3337c478bd9Sstevel@tonic-gate 	    buf, 0, &s, NULL) == 0) {
3347c478bd9Sstevel@tonic-gate 		if (pc == s.st_value && curinstr == M_PUSHL_EBP)
3357c478bd9Sstevel@tonic-gate 			fp = sp - 4;
3367c478bd9Sstevel@tonic-gate 		else if (pc == s.st_value + 1 && curinstr == M_MOVL_EBP)
3377c478bd9Sstevel@tonic-gate 			fp = sp;
3387c478bd9Sstevel@tonic-gate 	}
3397c478bd9Sstevel@tonic-gate 
340*9c3024a3SHans Rosenfeld 	if (mdb_tgt_aread(t, MDB_TGT_AS_VIRT_S, &fr, sizeof (fr), fp) ==
341*9c3024a3SHans Rosenfeld 	    sizeof (fr)) {
3427c478bd9Sstevel@tonic-gate 		*p = fr.fr_savpc;
3437c478bd9Sstevel@tonic-gate 		return (0);
3447c478bd9Sstevel@tonic-gate 	}
3457c478bd9Sstevel@tonic-gate 
3467c478bd9Sstevel@tonic-gate 	return (-1); /* errno is set for us */
3477c478bd9Sstevel@tonic-gate }
3487c478bd9Sstevel@tonic-gate 
3497c478bd9Sstevel@tonic-gate /*
3507c478bd9Sstevel@tonic-gate  * Return the address of the next instruction following a call, or return -1
3517c478bd9Sstevel@tonic-gate  * and set errno to EAGAIN if the target should just single-step.  We perform
3527c478bd9Sstevel@tonic-gate  * a bit of disassembly on the current instruction in order to determine if it
3537c478bd9Sstevel@tonic-gate  * is a call and how many bytes should be skipped, depending on the exact form
3547c478bd9Sstevel@tonic-gate  * of the call instruction that is being used.
3557c478bd9Sstevel@tonic-gate  */
3567c478bd9Sstevel@tonic-gate int
mdb_ia32_next(mdb_tgt_t * t,uintptr_t * p,kreg_t pc,mdb_instr_t curinstr)3577c478bd9Sstevel@tonic-gate mdb_ia32_next(mdb_tgt_t *t, uintptr_t *p, kreg_t pc, mdb_instr_t curinstr)
3587c478bd9Sstevel@tonic-gate {
3597c478bd9Sstevel@tonic-gate 	uint8_t m;
3607c478bd9Sstevel@tonic-gate 
3617c478bd9Sstevel@tonic-gate 	enum {
3627c478bd9Sstevel@tonic-gate 		M_CALL_REL = 0xe8, /* call near with relative displacement */
3637c478bd9Sstevel@tonic-gate 		M_CALL_REG = 0xff, /* call near indirect or call far register */
3647c478bd9Sstevel@tonic-gate 
3657c478bd9Sstevel@tonic-gate 		M_MODRM_MD = 0xc0, /* mask for Mod/RM byte Mod field */
3667c478bd9Sstevel@tonic-gate 		M_MODRM_OP = 0x38, /* mask for Mod/RM byte opcode field */
3677c478bd9Sstevel@tonic-gate 		M_MODRM_RM = 0x07, /* mask for Mod/RM byte R/M field */
3687c478bd9Sstevel@tonic-gate 
3697c478bd9Sstevel@tonic-gate 		M_MD_IND   = 0x00, /* Mod code for [REG] */
3707c478bd9Sstevel@tonic-gate 		M_MD_DSP8  = 0x40, /* Mod code for disp8[REG] */
3717c478bd9Sstevel@tonic-gate 		M_MD_DSP32 = 0x80, /* Mod code for disp32[REG] */
3727c478bd9Sstevel@tonic-gate 		M_MD_REG   = 0xc0, /* Mod code for REG */
3737c478bd9Sstevel@tonic-gate 
3747c478bd9Sstevel@tonic-gate 		M_OP_IND   = 0x10, /* Opcode for call near indirect */
3757c478bd9Sstevel@tonic-gate 		M_RM_DSP32 = 0x05  /* R/M code for disp32 */
3767c478bd9Sstevel@tonic-gate 	};
3777c478bd9Sstevel@tonic-gate 
3787c478bd9Sstevel@tonic-gate 	/*
3797c478bd9Sstevel@tonic-gate 	 * If the opcode is a near call with relative displacement, assume the
3807c478bd9Sstevel@tonic-gate 	 * displacement is a rel32 from the next instruction.
3817c478bd9Sstevel@tonic-gate 	 */
3827c478bd9Sstevel@tonic-gate 	if (curinstr == M_CALL_REL) {
3837c478bd9Sstevel@tonic-gate 		*p = pc + sizeof (mdb_instr_t) + sizeof (uint32_t);
3847c478bd9Sstevel@tonic-gate 		return (0);
3857c478bd9Sstevel@tonic-gate 	}
3867c478bd9Sstevel@tonic-gate 
3877c478bd9Sstevel@tonic-gate 	/*
3887c478bd9Sstevel@tonic-gate 	 * If the opcode is a call near indirect or call far register opcode,
3897c478bd9Sstevel@tonic-gate 	 * read the subsequent Mod/RM byte to perform additional decoding.
3907c478bd9Sstevel@tonic-gate 	 */
3917c478bd9Sstevel@tonic-gate 	if (curinstr == M_CALL_REG) {
392*9c3024a3SHans Rosenfeld 		if (mdb_tgt_aread(t, MDB_TGT_AS_VIRT_I, &m, sizeof (m), pc + 1)
393*9c3024a3SHans Rosenfeld 		    != sizeof (m))
3947c478bd9Sstevel@tonic-gate 			return (-1); /* errno is set for us */
3957c478bd9Sstevel@tonic-gate 
3967c478bd9Sstevel@tonic-gate 		/*
3977c478bd9Sstevel@tonic-gate 		 * If the Mod/RM opcode extension indicates a near indirect
3987c478bd9Sstevel@tonic-gate 		 * call, then skip the appropriate number of additional
3997c478bd9Sstevel@tonic-gate 		 * bytes depending on the addressing form that is used.
4007c478bd9Sstevel@tonic-gate 		 */
4017c478bd9Sstevel@tonic-gate 		if ((m & M_MODRM_OP) == M_OP_IND) {
4027c478bd9Sstevel@tonic-gate 			switch (m & M_MODRM_MD) {
4037c478bd9Sstevel@tonic-gate 			case M_MD_DSP8:
4047c478bd9Sstevel@tonic-gate 				*p = pc + 3; /* skip pr_instr, m, disp8 */
4057c478bd9Sstevel@tonic-gate 				break;
4067c478bd9Sstevel@tonic-gate 			case M_MD_DSP32:
4077c478bd9Sstevel@tonic-gate 				*p = pc + 6; /* skip pr_instr, m, disp32 */
4087c478bd9Sstevel@tonic-gate 				break;
4097c478bd9Sstevel@tonic-gate 			case M_MD_IND:
4107c478bd9Sstevel@tonic-gate 				if ((m & M_MODRM_RM) == M_RM_DSP32) {
4117c478bd9Sstevel@tonic-gate 					*p = pc + 6;
4127c478bd9Sstevel@tonic-gate 					break; /* skip pr_instr, m, disp32 */
4137c478bd9Sstevel@tonic-gate 				}
4147c478bd9Sstevel@tonic-gate 				/* FALLTHRU */
4157c478bd9Sstevel@tonic-gate 			case M_MD_REG:
4167c478bd9Sstevel@tonic-gate 				*p = pc + 2; /* skip pr_instr, m */
4177c478bd9Sstevel@tonic-gate 				break;
4187c478bd9Sstevel@tonic-gate 			}
4197c478bd9Sstevel@tonic-gate 			return (0);
4207c478bd9Sstevel@tonic-gate 		}
4217c478bd9Sstevel@tonic-gate 	}
4227c478bd9Sstevel@tonic-gate 
4237c478bd9Sstevel@tonic-gate 	return (set_errno(EAGAIN));
4247c478bd9Sstevel@tonic-gate }
425*9c3024a3SHans Rosenfeld #endif
4267c478bd9Sstevel@tonic-gate 
4277c478bd9Sstevel@tonic-gate /*ARGSUSED*/
4287c478bd9Sstevel@tonic-gate int
mdb_ia32_kvm_frame(void * arglim,uintptr_t pc,uint_t argc,const long * largv,const mdb_tgt_gregset_t * gregs)429*9c3024a3SHans Rosenfeld mdb_ia32_kvm_frame(void *arglim, uintptr_t pc, uint_t argc, const long *largv,
4307c478bd9Sstevel@tonic-gate     const mdb_tgt_gregset_t *gregs)
4317c478bd9Sstevel@tonic-gate {
432*9c3024a3SHans Rosenfeld 	const uint32_t *argv = (const uint32_t *)largv;
433*9c3024a3SHans Rosenfeld 
434*9c3024a3SHans Rosenfeld 	argc = MIN(argc, (uintptr_t)arglim);
4357c478bd9Sstevel@tonic-gate 	mdb_printf("%a(", pc);
4367c478bd9Sstevel@tonic-gate 
4377c478bd9Sstevel@tonic-gate 	if (argc != 0) {
4387c478bd9Sstevel@tonic-gate 		mdb_printf("%lr", *argv++);
4397c478bd9Sstevel@tonic-gate 		for (argc--; argc != 0; argc--)
4407c478bd9Sstevel@tonic-gate 			mdb_printf(", %lr", *argv++);
4417c478bd9Sstevel@tonic-gate 	}
4427c478bd9Sstevel@tonic-gate 
4437c478bd9Sstevel@tonic-gate 	mdb_printf(")\n");
4447c478bd9Sstevel@tonic-gate 	return (0);
4457c478bd9Sstevel@tonic-gate }
4467c478bd9Sstevel@tonic-gate 
4477c478bd9Sstevel@tonic-gate int
mdb_ia32_kvm_framev(void * arglim,uintptr_t pc,uint_t argc,const long * largv,const mdb_tgt_gregset_t * gregs)448*9c3024a3SHans Rosenfeld mdb_ia32_kvm_framev(void *arglim, uintptr_t pc, uint_t argc, const long *largv,
4497c478bd9Sstevel@tonic-gate     const mdb_tgt_gregset_t *gregs)
4507c478bd9Sstevel@tonic-gate {
451*9c3024a3SHans Rosenfeld 	const uint32_t *argv = (const uint32_t *)largv;
452*9c3024a3SHans Rosenfeld 
453*9c3024a3SHans Rosenfeld 	argc = MIN(argc, (uintptr_t)arglim);
454*9c3024a3SHans Rosenfeld 	mdb_printf("%08lr %a(", gregs->kregs[KREG_EBP], pc);
4557c478bd9Sstevel@tonic-gate 
4567c478bd9Sstevel@tonic-gate 	if (argc != 0) {
4577c478bd9Sstevel@tonic-gate 		mdb_printf("%lr", *argv++);
4587c478bd9Sstevel@tonic-gate 		for (argc--; argc != 0; argc--)
4597c478bd9Sstevel@tonic-gate 			mdb_printf(", %lr", *argv++);
4607c478bd9Sstevel@tonic-gate 	}
4617c478bd9Sstevel@tonic-gate 
4627c478bd9Sstevel@tonic-gate 	mdb_printf(")\n");
4637c478bd9Sstevel@tonic-gate 	return (0);
4647c478bd9Sstevel@tonic-gate }
465