2 * Copyright (c) 1991, 1992 Paul Kranenburg <pk@cs.few.eur.nl>
3 * Copyright (c) 1993 Branko Lankester <branko@hacktic.nl>
4 * Copyright (c) 1993, 1994, 1995, 1996 Rick Sladkey <jrs@world.std.com>
5 * Copyright (c) 1996-1999 Wichert Akkerman <wichert@cistron.nl>
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. The name of the author may not be used to endorse or promote products
17 * derived from this software without specific prior written permission.
19 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
20 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
21 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
22 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
23 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
24 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
33 #include <sys/types.h>
38 #include <sys/param.h>
40 #include <sys/resource.h>
48 #include <sys/stropts.h>
55 int debug = 0, followfork = 0, followvfork = 0, interactive = 0;
56 int rflag = 0, tflag = 0, dtime = 0, cflag = 0;
57 int iflag = 0, xflag = 0, qflag = 0;
60 char *username = NULL;
64 int acolumn = DEFAULT_ACOLUMN;
65 int max_strlen = DEFAULT_STRLEN;
66 char *outfname = NULL;
68 struct tcb tcbtab[MAX_PROCS];
71 extern char version[];
72 extern char **environ;
74 static struct tcb *pid2tcb P((int pid));
75 static int trace P((void));
76 static void cleanup P((void));
77 static void interrupt P((int sig));
78 static sigset_t empty_set, blocked_set;
80 #ifdef HAVE_SIG_ATOMIC_T
81 static volatile sig_atomic_t interrupted;
82 #else /* !HAVE_SIG_ATOMIC_T */
84 static volatile int interrupted;
86 static int interrupted;
87 #endif /* !__STDC__ */
88 #endif /* !HAVE_SIG_ATOMIC_T */
92 static struct tcb *pfd2tcb P((int pfd));
93 static void reaper P((int sig));
94 static void rebuild_pollv P((void));
95 struct pollfd pollv[MAX_PROCS];
97 #ifndef HAVE_POLLABLE_PROCFS
99 static void proc_poll_open P((void));
100 static void proc_poller P((int pfd));
108 static int poller_pid;
109 static int proc_poll_pipe[2] = { -1, -1 };
111 #endif /* !HAVE_POLLABLE_PROCFS */
113 #ifdef HAVE_MP_PROCFS
114 #define POLLWANT POLLWRNORM
116 #define POLLWANT POLLPRI
126 usage: strace [-dffhiqrtttTvVxx] [-a column] [-e expr] ... [-o file]\n\
127 [-p pid] ... [-s strsize] [-u username] [command [arg ...]]\n\
128 or: strace -c [-e expr] ... [-O overhead] [-S sortby] [command [arg ...]]\n\
129 -c -- count time, calls, and errors for each syscall and report summary\n\
130 -f -- follow forks, -ff -- with output into separate files\n\
131 -F -- attempt to follow vforks, -h -- print help message\n\
132 -i -- print instruction pointer at time of syscall\n\
133 -q -- suppress messages about attaching, detaching, etc.\n\
134 -r -- print relative timestamp, -t -- absolute timestamp, -tt -- with usecs\n\
135 -T -- print time spent in each syscall, -V -- print version\n\
136 -v -- verbose mode: print unabbreviated argv, stat, termio[s], etc. args\n\
137 -x -- print non-ascii strings in hex, -xx -- print all strings in hex\n\
138 -a column -- alignment COLUMN for printing syscall results (default %d)\n\
139 -e expr -- a qualifying expression: option=[!]all or option=[!]val1[,val2]...\n\
140 options: trace, abbrev, verbose, raw, signal, read, or write\n\
141 -o file -- send trace output to FILE instead of stderr\n\
142 -O overhead -- set overhead for tracing syscalls to OVERHEAD usecs\n\
143 -p pid -- trace process with process id PID, may be repeated\n\
144 -s strsize -- limit length of print strings to STRSIZE chars (default %d)\n\
145 -S sortby -- sort syscall counts by: time, calls, name, nothing (default %s)\n\
146 -u username -- run command as username handling setuid and/or setgid\n\
147 ", DEFAULT_ACOLUMN, DEFAULT_STRLEN, DEFAULT_SORTBY);
171 static char buf[BUFSIZ];
176 qualify("trace=all");
177 qualify("abbrev=all");
178 qualify("verbose=all");
179 qualify("signal=all");
180 set_sortby(DEFAULT_SORTBY);
181 set_personality(DEFAULT_PERSONALITY);
182 while ((c = getopt(argc, argv,
183 "+cdfFhiqrtTvVxa:e:o:O:p:s:S:u:")) != EOF) {
221 qualify("abbrev=none");
224 printf("%s\n", version);
228 acolumn = atoi(optarg);
234 outfname = strdup(optarg);
237 set_overhead(atoi(optarg));
240 if ((pid = atoi(optarg)) == 0) {
241 fprintf(stderr, "%s: Invalid process id: %s\n",
245 if (pid == getpid()) {
246 fprintf(stderr, "%s: I'm sorry, I can't let you do that, Dave.\n", progname);
249 if ((tcp = alloctcb(pid)) == NULL) {
250 fprintf(stderr, "%s: tcb table full, please recompile strace\n",
254 tcp->flags |= TCB_ATTACHED;
258 max_strlen = atoi(optarg);
264 username = strdup(optarg);
272 /* See if they want to run as another user. */
273 if (username != NULL) {
276 if (getuid() != 0 || geteuid() != 0) {
278 "%s: you must be root to use the -u option\n",
282 if ((pent = getpwnam(username)) == NULL) {
283 fprintf(stderr, "%s: cannot find user `%s'\n",
287 run_uid = pent->pw_uid;
288 run_gid = pent->pw_gid;
296 setreuid(geteuid(), getuid());
299 /* See if they want to pipe the output. */
300 if (outfname && (outfname[0] == '|' || outfname[0] == '!')) {
301 if ((outf = popen(outfname + 1, "w")) == NULL) {
302 fprintf(stderr, "%s: can't popen '%s': %s\n",
303 progname, outfname + 1, strerror(errno));
310 /* Check if they want to redirect the output. */
312 if ((outf = fopen(outfname, "w")) == NULL) {
313 fprintf(stderr, "%s: can't fopen '%s': %s\n",
314 progname, outfname, strerror(errno));
320 setreuid(geteuid(), getuid());
325 setvbuf(outf, buf, _IOLBF, BUFSIZ);
327 else if (optind < argc)
332 for (c = 0, tcp = tcbtab; c < MAX_PROCS; c++, tcp++) {
333 /* Reinitialize the output since it may have changed. */
335 if (!(tcp->flags & TCB_INUSE) || !(tcp->flags & TCB_ATTACHED))
338 if (proc_open(tcp, 1) < 0) {
339 fprintf(stderr, "trouble opening proc file\n");
344 if (ptrace(PTRACE_ATTACH, tcp->pid, (char *) 1, 0) < 0) {
345 perror("attach: ptrace(PTRACE_ATTACH, ...)");
352 "Process %u attached - interrupt to quit\n",
359 char pathname[MAXPATHLEN];
361 filename = argv[optind];
362 if (strchr(filename, '/'))
363 strcpy(pathname, filename);
364 #ifdef USE_DEBUGGING_EXEC
366 * Debuggers customarily check the current directory
367 * first regardless of the path but doing that gives
368 * security geeks a panic attack.
370 else if (stat(filename, &statbuf) == 0)
371 strcpy(pathname, filename);
372 #endif /* USE_DEBUGGING_EXEC */
377 for (path = getenv("PATH"); path && *path; path += m) {
378 if (strchr(path, ':')) {
379 n = strchr(path, ':') - path;
383 m = n = strlen(path);
385 getcwd(pathname, MAXPATHLEN);
386 len = strlen(pathname);
389 strncpy(pathname, path, n);
392 if (len && pathname[len - 1] != '/')
393 pathname[len++] = '/';
394 strcpy(pathname + len, filename);
395 if (stat(pathname, &statbuf) == 0)
399 if (stat(pathname, &statbuf) < 0) {
400 fprintf(stderr, "%s: %s: command not found\n",
404 switch (pid = fork()) {
406 perror("strace: fork");
412 if (outf != stderr) close (fileno (outf));
414 /* Kludge for SGI, see proc_open for details. */
415 sa.sa_handler = foobar;
417 sigemptyset(&sa.sa_mask);
418 sigaction(SIGINT, &sa, NULL);
422 if (ptrace(PTRACE_TRACEME, 0, (char *) 1, 0) < 0) {
423 perror("strace: ptrace(PTRACE_TRACEME, ...)");
427 kill(getpid(), SIGSTOP);
429 if (username != NULL || geteuid() == 0) {
430 uid_t run_euid = run_uid;
431 gid_t run_egid = run_gid;
433 if (statbuf.st_mode & S_ISUID)
434 run_euid = statbuf.st_uid;
435 if (statbuf.st_mode & S_ISGID)
436 run_egid = statbuf.st_gid;
439 * It is important to set groups before we
440 * lose privileges on setuid.
443 && initgroups(username, run_gid) < 0) {
444 perror("initgroups");
447 if (setregid(run_gid, run_egid) < 0) {
451 if (setreuid(run_uid, run_euid) < 0) {
457 setreuid(run_uid, run_uid);
460 execv(pathname, &argv[optind]);
461 perror("strace: exec");
466 if ((tcp = alloctcb(pid)) == NULL) {
467 fprintf(stderr, "tcb table full\n");
472 if (proc_open(tcp, 0) < 0) {
473 fprintf(stderr, "trouble opening proc file\n");
479 fake_execve(tcp, pathname, &argv[optind], environ);
484 else if (pflag_seen == 0)
487 sigemptyset(&empty_set);
488 sigemptyset(&blocked_set);
489 sa.sa_handler = SIG_IGN;
490 sigemptyset(&sa.sa_mask);
492 sigaction(SIGTTOU, &sa, NULL);
493 sigaction(SIGTTIN, &sa, NULL);
495 sigaddset(&blocked_set, SIGHUP);
496 sigaddset(&blocked_set, SIGINT);
497 sigaddset(&blocked_set, SIGQUIT);
498 sigaddset(&blocked_set, SIGPIPE);
499 sigaddset(&blocked_set, SIGTERM);
500 sa.sa_handler = interrupt;
502 /* POSIX signals on sunos4.1 are a little broken. */
503 sa.sa_flags = SA_INTERRUPT;
506 sigaction(SIGHUP, &sa, NULL);
507 sigaction(SIGINT, &sa, NULL);
508 sigaction(SIGQUIT, &sa, NULL);
509 sigaction(SIGPIPE, &sa, NULL);
510 sigaction(SIGTERM, &sa, NULL);
512 sa.sa_handler = reaper;
513 sigaction(SIGCHLD, &sa, NULL);
526 char name[MAXPATHLEN];
529 if (outfname && followfork > 1) {
530 sprintf(name, "%s.%u", outfname, tcp->pid);
532 setreuid(geteuid(), getuid());
534 fp = fopen(name, "w");
536 setreuid(geteuid(), getuid());
554 for (i = 0, tcp = tcbtab; i < MAX_PROCS; i++, tcp++) {
555 if ((tcp->flags & TCB_INUSE) == 0) {
559 tcp->flags = TCB_INUSE | TCB_STARTUP;
560 tcp->outf = outf; /* Initialise to current out file */
561 tcp->stime.tv_sec = 0;
562 tcp->stime.tv_usec = 0;
573 proc_open(tcp, attaching)
579 sysset_t sc_enter, sc_exit;
582 #ifndef HAVE_POLLABLE_PROCFS
586 #ifdef HAVE_MP_PROCFS
587 /* Open the process pseudo-files in /proc. */
588 sprintf(proc, "/proc/%d/ctl", tcp->pid);
589 if ((tcp->pfd = open(proc, O_WRONLY|O_EXCL)) < 0) {
590 perror("strace: open(\"/proc/...\", ...)");
593 if ((arg = fcntl(tcp->pfd, F_GETFD)) < 0) {
597 if (fcntl(tcp->pfd, F_SETFD, arg|FD_CLOEXEC) < 0) {
601 sprintf(proc, "/proc/%d/status", tcp->pid);
602 if ((tcp->pfd_stat = open(proc, O_RDONLY|O_EXCL)) < 0) {
603 perror("strace: open(\"/proc/...\", ...)");
606 if ((arg = fcntl(tcp->pfd_stat, F_GETFD)) < 0) {
610 if (fcntl(tcp->pfd_stat, F_SETFD, arg|FD_CLOEXEC) < 0) {
614 sprintf(proc, "/proc/%d/as", tcp->pid);
615 if ((tcp->pfd_as = open(proc, O_RDONLY|O_EXCL)) < 0) {
616 perror("strace: open(\"/proc/...\", ...)");
619 if ((arg = fcntl(tcp->pfd_as, F_GETFD)) < 0) {
623 if (fcntl(tcp->pfd_as, F_SETFD, arg|FD_CLOEXEC) < 0) {
628 /* Open the process pseudo-file in /proc. */
629 sprintf(proc, "/proc/%d", tcp->pid);
630 if ((tcp->pfd = open(proc, O_RDWR|O_EXCL)) < 0) {
631 perror("strace: open(\"/proc/...\", ...)");
634 if ((arg = fcntl(tcp->pfd, F_GETFD)) < 0) {
638 if (fcntl(tcp->pfd, F_SETFD, arg|FD_CLOEXEC) < 0) {
646 * Wait for the child to pause. Because of a race
647 * condition we have to poll for the event.
650 if (IOCTL_STATUS (tcp) < 0) {
651 perror("strace: PIOCSTATUS");
654 if (tcp->status.PR_FLAGS & PR_ASLEEP)
658 /* Stop the process so that we own the stop. */
659 if (IOCTL(tcp->pfd, PIOCSTOP, NULL) < 0) {
660 perror("strace: PIOCSTOP");
664 /* Set Run-on-Last-Close. */
666 if (IOCTL(tcp->pfd, PIOCSET, &arg) < 0) {
667 perror("PIOCSET PR_RLC");
670 /* Set or Reset Inherit-on-Fork. */
672 if (IOCTL(tcp->pfd, followfork ? PIOCSET : PIOCRESET, &arg) < 0) {
673 perror("PIOC{SET,RESET} PR_FORK");
677 if (ioctl(tcp->pfd, PIOCSRLC) < 0) {
681 if (ioctl(tcp->pfd, followfork ? PIOCSFORK : PIOCRFORK) < 0) {
682 perror("PIOC{S,R}FORK");
685 #endif /* !PIOCSET */
686 /* Enable all syscall entries. */
687 prfillset(&sc_enter);
688 if (IOCTL(tcp->pfd, PIOCSENTRY, &sc_enter) < 0) {
689 perror("PIOCSENTRY");
692 /* Enable all syscall exits. */
694 if (IOCTL(tcp->pfd, PIOCSEXIT, &sc_exit) < 0) {
698 /* Enable all signals. */
700 if (IOCTL(tcp->pfd, PIOCSTRACE, &signals) < 0) {
701 perror("PIOCSTRACE");
704 /* Enable all faults. */
706 if (IOCTL(tcp->pfd, PIOCSFAULT, &faults) < 0) {
707 perror("PIOCSFAULT");
713 * The SGI PRSABORT doesn't work for pause() so
714 * we send it a caught signal to wake it up.
716 kill(tcp->pid, SIGINT);
718 /* The child is in a pause(), abort it. */
720 if (IOCTL (tcp->pfd, PIOCRUN, &arg) < 0) {
726 /* Wait for the child to do something. */
727 if (IOCTL_WSTOP (tcp) < 0) {
731 if (tcp->status.PR_WHY == PR_SYSENTRY) {
732 #ifdef HAVE_PR_SYSCALL
733 int scno = tcp->status.pr_syscall;
734 #else /* !HAVE_PR_SYSCALL */
735 int scno = tcp->status.PR_WHAT;
736 #endif /* !HAVE_PR_SYSCALL */
737 if (scno == SYS_execve)
740 /* Set it running: maybe execve will be next. */
742 if (IOCTL(tcp->pfd, PIOCRUN, &arg) < 0) {
748 #ifndef HAVE_POLLABLE_PROCFS
749 if (proc_poll_pipe[0] != -1)
750 proc_poller(tcp->pfd);
751 else if (nprocs > 1) {
753 proc_poller(last_pfd);
754 proc_poller(tcp->pfd);
757 #endif /* !HAVE_POLLABLE_PROCFS */
770 for (i = 0, tcp = tcbtab; i < MAX_PROCS; i++, tcp++) {
771 if (pid && tcp->pid != pid)
773 if (tcp->flags & TCB_INUSE)
788 for (i = 0, tcp = tcbtab; i < MAX_PROCS; i++, tcp++) {
791 if (tcp->flags & TCB_INUSE)
808 if (tcp->pfd != -1) {
815 if (tcp->parent != NULL) {
816 tcp->parent->nchildren--;
820 if (tcp->outf != stderr)
835 if (!(tcp->flags & TCB_SUSPENDED)) {
836 fprintf(stderr, "PANIC: pid %u not suspended\n", tcp->pid);
839 tcp->flags &= ~TCB_SUSPENDED;
841 if (ptrace(PTRACE_SYSCALL, tcp->pid, (char *) 1, 0) < 0) {
842 perror("resume: ptrace(PTRACE_SYSCALL, ...)");
847 fprintf(stderr, "Process %u resumed\n", tcp->pid);
853 /* detach traced process; continue with sig */
865 if (tcp->flags & TCB_BPTSET)
870 * Linux wrongly insists the child be stopped
871 * before detaching. Arghh. We go through hoops
872 * to make a clean break of things.
876 #define PTRACE_DETACH PTRACE_SUNDETACH
878 if ((error = ptrace(PTRACE_DETACH, tcp->pid, (char *) 1, sig)) == 0) {
879 /* On a clear day, you can see forever. */
881 else if (errno != ESRCH) {
882 /* Shouldn't happen. */
883 perror("detach: ptrace(PTRACE_DETACH, ...)");
885 else if (kill(tcp->pid, 0) < 0) {
887 perror("detach: checking sanity");
889 else if (kill(tcp->pid, SIGSTOP) < 0) {
891 perror("detach: stopping child");
895 if (waitpid(tcp->pid, &status, 0) < 0) {
897 perror("detach: waiting");
900 if (!WIFSTOPPED(status)) {
901 /* Au revoir, mon ami. */
904 if (WSTOPSIG(status) == SIGSTOP) {
905 if ((error = ptrace(PTRACE_DETACH,
906 tcp->pid, (char *) 1, sig)) < 0) {
908 perror("detach: ptrace(PTRACE_DETACH, ...)");
913 if ((error = ptrace(PTRACE_CONT, tcp->pid, (char *) 1,
914 WSTOPSIG(status) == SIGTRAP ?
915 0 : WSTOPSIG(status))) < 0) {
917 perror("detach: ptrace(PTRACE_CONT, ...)");
925 /* PTRACE_DETACH won't respect `sig' argument, so we post it here. */
926 if (sig && kill(tcp->pid, sig) < 0)
927 perror("detach: kill");
929 if ((error = ptrace(PTRACE_DETACH, tcp->pid, (char *) 1, sig)) < 0)
930 perror("detach: ptrace(PTRACE_DETACH, ...)");
934 if (waiting_parent(tcp))
935 error = resume(tcp->parent);
939 fprintf(stderr, "Process %u detached\n", tcp->pid);
954 while ((pid = waitpid(-1, &status, WNOHANG)) > 0) {
973 for (i = 0, tcp = tcbtab; i < MAX_PROCS; i++, tcp++) {
974 if (!(tcp->flags & TCB_INUSE))
978 "cleanup: looking at pid %u\n", tcp->pid);
980 (!outfname || followfork < 2 || tcp_last == tcp)) {
981 tprintf(" <unfinished ...>\n");
984 if (tcp->flags & TCB_ATTACHED)
987 kill(tcp->pid, SIGCONT);
988 kill(tcp->pid, SIGTERM);
1002 #ifndef HAVE_STRERROR
1004 #ifndef SYS_ERRLIST_DECLARED
1005 extern int sys_nerr;
1006 extern char *sys_errlist[];
1007 #endif /* SYS_ERRLIST_DECLARED */
1013 static char buf[64];
1015 if (errno < 1 || errno >= sys_nerr) {
1016 sprintf(buf, "Unknown error %d", errno);
1019 return sys_errlist[errno];
1022 #endif /* HAVE_STERRROR */
1024 #ifndef HAVE_STRSIGNAL
1026 #ifndef SYS_SIGLIST_DECLARED
1027 #ifdef HAVE__SYS_SIGLIST
1028 extern char *_sys_siglist[];
1030 extern char *sys_siglist[];
1032 #endif /* SYS_SIGLIST_DECLARED */
1038 static char buf[64];
1040 if (sig < 1 || sig >= NSIG) {
1041 sprintf(buf, "Unknown signal %d", sig);
1044 #ifdef HAVE__SYS_SIGLIST
1045 return _sys_siglist[sig];
1047 return sys_siglist[sig];
1051 #endif /* HAVE_STRSIGNAL */
1061 for (i = j = 0, tcp = tcbtab; i < MAX_PROCS; i++, tcp++) {
1062 if (!(tcp->flags & TCB_INUSE))
1064 pollv[j].fd = tcp->pfd;
1065 pollv[j].events = POLLWANT;
1069 fprintf(stderr, "strace: proc miscount\n");
1074 #ifndef HAVE_POLLABLE_PROCFS
1082 if (pipe(proc_poll_pipe) < 0) {
1086 for (i = 0; i < 2; i++) {
1087 if ((arg = fcntl(proc_poll_pipe[i], F_GETFD)) < 0) {
1091 if (fcntl(proc_poll_pipe[i], F_SETFD, arg|FD_CLOEXEC) < 0) {
1099 proc_poll(pollv, nfds, timeout)
1100 struct pollfd *pollv;
1106 struct proc_pollfd pollinfo;
1108 if ((n = read(proc_poll_pipe[0], &pollinfo, sizeof(pollinfo))) < 0)
1110 if (n != sizeof(struct proc_pollfd)) {
1111 fprintf(stderr, "panic: short read: %d\n", n);
1114 for (i = 0; i < nprocs; i++) {
1115 if (pollv[i].fd == pollinfo.fd)
1116 pollv[i].revents = pollinfo.revents;
1118 pollv[i].revents = 0;
1120 poller_pid = pollinfo.pid;
1134 struct proc_pollfd pollinfo;
1135 struct sigaction sa;
1136 sigset_t blocked_set, empty_set;
1151 sa.sa_handler = interactive ? SIG_DFL : SIG_IGN;
1153 sigemptyset(&sa.sa_mask);
1154 sigaction(SIGHUP, &sa, NULL);
1155 sigaction(SIGINT, &sa, NULL);
1156 sigaction(SIGQUIT, &sa, NULL);
1157 sigaction(SIGPIPE, &sa, NULL);
1158 sigaction(SIGTERM, &sa, NULL);
1159 sa.sa_handler = wakeup_handler;
1160 sigaction(SIGUSR1, &sa, NULL);
1161 sigemptyset(&blocked_set);
1162 sigaddset(&blocked_set, SIGUSR1);
1163 sigprocmask(SIG_BLOCK, &blocked_set, NULL);
1164 sigemptyset(&empty_set);
1166 if (getrlimit(RLIMIT_NOFILE, &rl) < 0) {
1167 perror("getrlimit(RLIMIT_NOFILE, ...)");
1171 for (i = 0; i < n; i++) {
1172 if (i != pfd && i != proc_poll_pipe[1])
1177 pollinfo.pid = getpid();
1179 if (ioctl(pfd, PIOCWSTOP, NULL) < 0)
1185 pollinfo.revents = POLLERR;
1188 pollinfo.revents = POLLHUP;
1191 perror("proc_poller: PIOCWSTOP");
1193 write(proc_poll_pipe[1], &pollinfo, sizeof(pollinfo));
1196 pollinfo.revents = POLLWANT;
1197 write(proc_poll_pipe[1], &pollinfo, sizeof(pollinfo));
1198 sigsuspend(&empty_set);
1202 #endif /* !HAVE_POLLABLE_PROCFS */
1212 if (followfork < 2 &&
1213 last < nprocs && (pollv[last].revents & POLLWANT)) {
1215 * The previous process is ready to run again. We'll
1216 * let it do so if it is currently in a syscall. This
1217 * heuristic improves the readability of the trace.
1219 tcp = pfd2tcb(pollv[last].fd);
1220 if (tcp && (tcp->flags & TCB_INSYSCALL))
1221 return pollv[last].fd;
1224 for (i = 0; i < nprocs; i++) {
1225 /* Let competing children run round robin. */
1226 j = (i + last + 1) % nprocs;
1227 if (pollv[j].revents & (POLLHUP | POLLERR)) {
1228 tcp = pfd2tcb(pollv[j].fd);
1230 fprintf(stderr, "strace: lost proc\n");
1236 if (pollv[j].revents & POLLWANT) {
1241 fprintf(stderr, "strace: nothing ready\n");
1249 struct tcb *in_syscall;
1254 int ioctl_result = 0, ioctl_errno = 0;
1259 sigprocmask(SIG_SETMASK, &empty_set, NULL);
1266 #ifndef HAVE_POLLABLE_PROCFS
1267 if (proc_poll_pipe[0] == -1) {
1276 #ifndef HAVE_POLLABLE_PROCFS
1278 /* fall through ... */
1279 #endif /* !HAVE_POLLABLE_PROCFS */
1281 #ifdef HAVE_POLLABLE_PROCFS
1283 /* On some systems (e.g. UnixWare) we get too much ugly
1284 "unfinished..." stuff when multiple proceses are in
1285 syscalls. Here's a nasty hack */
1292 pv.events = POLLWANT;
1293 if ((what = poll (&pv, 1, 1)) < 0) {
1298 else if (what == 1 && pv.revents & POLLWANT) {
1304 if (poll(pollv, nprocs, INFTIM) < 0) {
1309 #else /* !HAVE_POLLABLE_PROCFS */
1310 if (proc_poll(pollv, nprocs, INFTIM) < 0) {
1315 #endif /* !HAVE_POLLABLE_PROCFS */
1322 /* Look up `pfd' in our table. */
1323 if ((tcp = pfd2tcb(pfd)) == NULL) {
1324 fprintf(stderr, "unknown pfd: %u\n", pfd);
1328 /* Get the status of the process. */
1330 ioctl_result = IOCTL_WSTOP (tcp);
1331 ioctl_errno = errno;
1332 #ifndef HAVE_POLLABLE_PROCFS
1333 if (proc_poll_pipe[0] != -1) {
1334 if (ioctl_result < 0)
1335 kill(poller_pid, SIGKILL);
1337 kill(poller_pid, SIGUSR1);
1339 #endif /* !HAVE_POLLABLE_PROCFS */
1345 sigprocmask(SIG_BLOCK, &blocked_set, NULL);
1347 if (ioctl_result < 0) {
1348 /* Find out what happened if it failed. */
1349 switch (ioctl_errno) {
1357 perror("PIOCWSTOP");
1362 /* clear the just started flag */
1363 tcp->flags &= ~TCB_STARTUP;
1365 /* set current output file */
1369 struct timeval stime;
1371 stime.tv_sec = tcp->status.pr_stime.tv_sec;
1372 stime.tv_usec = tcp->status.pr_stime.tv_nsec/1000;
1373 tv_sub(&tcp->dtime, &stime, &tcp->stime);
1377 what = tcp->status.PR_WHAT;
1378 switch (tcp->status.PR_WHY) {
1380 if (tcp->status.PR_FLAGS & PR_ASLEEP) {
1381 tcp->status.PR_WHY = PR_SYSENTRY;
1382 if (trace_syscall(tcp) < 0) {
1383 fprintf(stderr, "syscall trouble\n");
1393 if (trace_syscall(tcp) < 0) {
1394 fprintf(stderr, "syscall trouble\n");
1399 if (!cflag && (qual_flags[what] & QUAL_SIGNAL)) {
1401 tprintf("--- %s (%s) ---",
1402 signame(what), strsignal(what));
1407 if (!cflag && (qual_flags[what] & QUAL_FAULT)) {
1409 tprintf("=== FAULT %d ===", what);
1414 fprintf(stderr, "odd stop %d\n", tcp->status.PR_WHY);
1419 if (IOCTL (tcp->pfd, PIOCRUN, &arg) < 0) {
1440 while (nprocs != 0) {
1442 sigprocmask(SIG_SETMASK, &empty_set, NULL);
1444 pid = wait4(-1, &status, 0, cflag ? &ru : NULL);
1447 pid = wait(&status);
1451 sigprocmask(SIG_BLOCK, &blocked_set, NULL);
1457 switch (wait_errno) {
1462 * We would like to verify this case
1463 * but sometimes a race in Solbourne's
1464 * version of SunOS sometimes reports
1465 * ECHILD before sending us SIGCHILD.
1470 fprintf(stderr, "strace: proc miscount\n");
1476 perror("strace: wait");
1481 fprintf(stderr, " [wait(%#x) = %u]\n", status, pid);
1483 /* Look up `pid' in our table. */
1484 if ((tcp = pid2tcb(pid)) == NULL) {
1485 #if 0 /* XXX davidm */ /* WTA: disabled again */
1486 struct tcb *tcpchild;
1488 if ((tcpchild = alloctcb(pid)) == NULL) {
1489 fprintf(stderr, " [tcb table full]\n");
1490 kill(pid, SIGKILL); /* XXX */
1493 tcpchild->flags |= TCB_ATTACHED;
1497 fprintf(stderr, "Process %d attached\n", pid);
1499 fprintf(stderr, "unknown pid: %u\n", pid);
1500 if (WIFSTOPPED(status))
1501 ptrace(PTRACE_CONT, pid, (char *) 1, 0);
1505 /* set current output file */
1509 tv_sub(&tcp->dtime, &ru.ru_stime, &tcp->stime);
1510 tcp->stime = ru.ru_stime;
1514 if (tcp->flags & TCB_SUSPENDED) {
1516 * Apparently, doing any ptrace() call on a stopped
1517 * process, provokes the kernel to report the process
1518 * status again on a subsequent wait(), even if the
1519 * process has not been actually restarted.
1520 * Since we have inspected the arguments of suspended
1521 * processes we end up here testing for this case.
1525 if (WIFSIGNALED(status)) {
1527 && (qual_flags[WTERMSIG(status)] & QUAL_SIGNAL)) {
1529 tprintf("+++ killed by %s +++",
1530 signame(WTERMSIG(status)));
1536 if (WIFEXITED(status)) {
1538 fprintf(stderr, "pid %u exited\n", pid);
1539 if (tcp->flags & TCB_ATTACHED)
1541 "PANIC: attached pid %u exited\n",
1546 if (!WIFSTOPPED(status)) {
1547 fprintf(stderr, "PANIC: pid %u not stopped\n", pid);
1552 fprintf(stderr, "pid %u stopped, [%s]\n",
1553 pid, signame(WSTOPSIG(status)));
1555 if (tcp->flags & TCB_STARTUP) {
1557 * This flag is there to keep us in sync.
1558 * Next time this process stops it should
1559 * really be entering a system call.
1561 tcp->flags &= ~TCB_STARTUP;
1562 if (tcp->flags & TCB_ATTACHED) {
1564 * Interestingly, the process may stop
1565 * with STOPSIG equal to some other signal
1566 * than SIGSTOP if we happend to attach
1567 * just before the process takes a signal.
1569 if (!WIFSTOPPED(status)) {
1571 "pid %u not stopped\n", pid);
1572 detach(tcp, WSTOPSIG(status));
1578 /* A child of us stopped at exec */
1579 if (WSTOPSIG(status) == SIGTRAP && followvfork)
1583 if (tcp->flags & TCB_BPTSET) {
1584 if (clearbpt(tcp) < 0) /* Pretty fatal */ {
1593 if (WSTOPSIG(status) != SIGTRAP) {
1594 if (WSTOPSIG(status) == SIGSTOP &&
1595 (tcp->flags & TCB_SIGTRAPPED)) {
1597 * Trapped attempt to block SIGTRAP
1598 * Hope we are back in control now.
1600 tcp->flags &= ~(TCB_INSYSCALL | TCB_SIGTRAPPED);
1601 if (ptrace(PTRACE_SYSCALL,
1602 pid, (char *) 1, 0) < 0) {
1603 perror("trace: ptrace(PTRACE_SYSCALL, ...)");
1610 && (qual_flags[WSTOPSIG(status)] & QUAL_SIGNAL)) {
1612 tprintf("--- %s (%s) ---",
1613 signame(WSTOPSIG(status)),
1614 strsignal(WSTOPSIG(status)));
1617 if ((tcp->flags & TCB_ATTACHED) &&
1618 !sigishandled(tcp, WSTOPSIG(status))) {
1619 detach(tcp, WSTOPSIG(status));
1622 if (ptrace(PTRACE_SYSCALL, pid, (char *) 1,
1623 WSTOPSIG(status)) < 0) {
1624 perror("trace: ptrace(PTRACE_SYSCALL, ...)");
1628 tcp->flags &= ~TCB_SUSPENDED;
1631 if (trace_syscall(tcp) < 0) {
1632 if (tcp->flags & TCB_ATTACHED)
1636 tcp->pid, (char *) 1, SIGTERM);
1641 if (tcp->flags & TCB_EXITING) {
1642 if (tcp->flags & TCB_ATTACHED)
1644 else if (ptrace(PTRACE_CONT, pid, (char *) 1, 0) < 0) {
1645 perror("strace: ptrace(PTRACE_CONT, ...)");
1651 if (tcp->flags & TCB_SUSPENDED) {
1653 fprintf(stderr, "Process %u suspended\n", pid);
1657 if (ptrace(PTRACE_SYSCALL, pid, (char *) 1, 0) < 0) {
1658 perror("trace: ptrace(PTRACE_SYSCALL, ...)");
1672 #define VA_START(a, b) va_start(a, b)
1674 #include <varargs.h>
1675 #define VA_START(a, b) va_start(a)
1680 tprintf(const char *fmt, ...)
1682 tprintf(fmt, va_alist)
1689 VA_START(args, fmt);
1691 curcol += vfprintf(outf, fmt, args);
1700 if (tcp_last && (!outfname || followfork < 2 || tcp_last == tcp)) {
1701 tcp_last->flags |= TCB_REPRINT;
1702 tprintf(" <unfinished ...>\n");
1705 if ((followfork == 1 || pflag_seen > 1) && outfname)
1706 tprintf("%-5d ", tcp->pid);
1707 else if (nprocs > 1 && !outfname)
1708 tprintf("[pid %5u] ", tcp->pid);
1710 char str[sizeof("HH:MM:SS")];
1711 struct timeval tv, dtv;
1712 static struct timeval otv;
1714 gettimeofday(&tv, NULL);
1716 if (otv.tv_sec == 0)
1718 tv_sub(&dtv, &tv, &otv);
1719 tprintf("%6ld.%06ld ",
1720 (long) dtv.tv_sec, (long) dtv.tv_usec);
1723 else if (tflag > 2) {
1724 tprintf("%ld.%06ld ",
1725 (long) tv.tv_sec, (long) tv.tv_usec);
1728 time_t local = tv.tv_sec;
1729 strftime(str, sizeof(str), "%T", localtime(&local));
1731 tprintf("%s.%06ld ", str, (long) tv.tv_usec);
1733 tprintf("%s ", str);
1745 tprintf("%*s", col - curcol, "");
1756 #ifdef HAVE_MP_PROCFS
1758 int mp_ioctl (int fd, int cmd, void *arg, int size) {
1760 struct iovec iov[2];
1763 iov[0].iov_base = &cmd;
1764 iov[0].iov_len = sizeof cmd;
1767 iov[1].iov_base = arg;
1768 iov[1].iov_len = size;
1771 return writev (fd, iov, n);