mirror of
https://sourceware.org/git/binutils-gdb.git
synced 2026-08-27 00:26:02 -04:00
Several watchpoint-related testcases, such as gdb.threads/watchthreads.exp for example, when tested with the backend in non-stop mode, exposed an interesting detail of the Windows debug API that wasn't considered before. The symptom observed is spurious SIGTRAPs, like: Thread 1 "watchthreads" received signal SIGTRAP, Trace/breakpoint trap. 0x00000001004010b1 in main () at .../src/gdb/testsuite/gdb.threads/watchthreads.c:48 48 args[i] = 1; usleep (1); /* Init value. */ After a good amount of staring at logs and headscratching, I realized the problem: #0 - It all starts with the fact that multiple threads can hit an event at the same time. Say, a watchpoint for thread A, and a breakpoint for thread B. #1 - Say, WaitForDebugEvent reports the breakpoint hit for thread B first, then GDB for some reason decides to update debug registers, and continue. Updating debug registers means writing the debug registers to _all_ threads, with SetThreadContext. #2 - WaitForDebugEvent reports the watchpoint hit for thread A. Watchpoint hits are reported as EXCEPTION_SINGLE_STEP. #3 - windows-nat checks the Dr6 debug register to check if the step was a watchpoint or hardware breakpoint stop, and finds that Dr6 is completely cleared. So windows-nat reports a plain SIGTRAP (given EXCEPTION_SINGLE_STEP) to the core. #4 - Thread A was not supposed to be stepping, so infrun reports the SIGTRAP to the user as a random signal. The strange part is #3 above. Why was Dr6 cleared? Turns out that (at least in Windows 10 & 11), writing to _any_ debug register has the side effect of clearing Dr6, even if you write the same values the registers already had, back to the registers. I confirmed it clearly by adding this hack to GDB: if (th->context.ContextFlags == 0) { th->context.ContextFlags = CONTEXT_DEBUGGER_DR; /* Get current values of debug registers. */ CHECK (GetThreadContext (th->h, &th->context)); DEBUG_EVENTS ("For 0x%x (once), Dr6=0x%llx", th->tid, th->context.Dr6); /* Write debug registers back to thread, same values, and re-read them. */ CHECK (SetThreadContext (th->h, &th->context)); CHECK (GetThreadContext (th->h, &th->context)); DEBUG_EVENTS ("For 0x%x (twice), Dr6=0x%llx", th->tid, th->context.Dr6); } Which showed Dr6=0 after the write + re-read: [windows events] fill_thread_context: For 0x6a0 (once), Dr6=0xffff0ff1 [windows events] fill_thread_context: For 0x6a0 (twice), Dr6=0x0 This commit fixes the issue by detecting that a thread has a pending watchpoint hit to report (Dr6 has interesting bits set), and if so, avoid modifying any debug register. Instead, let the pending watchpoint hit be reported by WaitForDebugEvent. If infrun did want to modify watchpoints, it will still be done when the thread is eventually re-resumed after the pending watchpoint hit is reported. (infrun knows how to gracefully handle the case of a watchpoint hit for a watchpoint that has since been deleted.) Move the fill_thread_context method from windows_nat_target to windows_per_inferior so it can be used by gdbserver too. Approved-By: Tom Tromey <tom@tromey.com> Change-Id: I21a3daa9e34eecfa054f0fea706e5ab40aabe70a commit-id:a28f8d4e |
||
|---|---|---|
| .. | ||
| .dir-locals.el | ||
| .gitattributes | ||
| .gitignore | ||
| acinclude.m4 | ||
| aclocal.m4 | ||
| ax-result-types.def | ||
| ax.cc | ||
| ax.h | ||
| ChangeLog-2002-2021 | ||
| config.in | ||
| configure | ||
| configure.ac | ||
| configure.srv | ||
| debug.cc | ||
| debug.h | ||
| dll.cc | ||
| dll.h | ||
| fork-child.cc | ||
| gdb_proc_service.h | ||
| gdbreplay.cc | ||
| gdbthread.h | ||
| hostio.cc | ||
| hostio.h | ||
| i387-fp.cc | ||
| i387-fp.h | ||
| inferiors.cc | ||
| inferiors.h | ||
| linux-aarch32-low.cc | ||
| linux-aarch32-low.h | ||
| linux-aarch32-tdesc.cc | ||
| linux-aarch32-tdesc.h | ||
| linux-aarch64-ipa.cc | ||
| linux-aarch64-low.cc | ||
| linux-aarch64-tdesc.cc | ||
| linux-aarch64-tdesc.h | ||
| linux-amd64-ipa.cc | ||
| linux-arc-low.cc | ||
| linux-arm-low.cc | ||
| linux-arm-tdesc.cc | ||
| linux-arm-tdesc.h | ||
| linux-csky-low.cc | ||
| linux-i386-ipa.cc | ||
| linux-ia64-low.cc | ||
| linux-loongarch-low.cc | ||
| linux-low.cc | ||
| linux-low.h | ||
| linux-m68k-low.cc | ||
| linux-microblaze-low.cc | ||
| linux-mips-low.cc | ||
| linux-or1k-low.cc | ||
| linux-ppc-ipa.cc | ||
| linux-ppc-low.cc | ||
| linux-ppc-tdesc-init.h | ||
| linux-riscv-low.cc | ||
| linux-s390-ipa.cc | ||
| linux-s390-low.cc | ||
| linux-s390-tdesc.h | ||
| linux-sh-low.cc | ||
| linux-sparc-low.cc | ||
| linux-tic6x-low.cc | ||
| linux-x86-low.cc | ||
| linux-x86-tdesc.cc | ||
| linux-xtensa-low.cc | ||
| Makefile.in | ||
| mem-break.cc | ||
| mem-break.h | ||
| netbsd-aarch64-low.cc | ||
| netbsd-amd64-low.cc | ||
| netbsd-i386-low.cc | ||
| netbsd-low.cc | ||
| netbsd-low.h | ||
| notif.cc | ||
| notif.h | ||
| proc-service.cc | ||
| proc-service.list | ||
| README | ||
| regcache.cc | ||
| regcache.h | ||
| remote-utils.cc | ||
| remote-utils.h | ||
| server.cc | ||
| server.h | ||
| symbol.cc | ||
| target.cc | ||
| target.h | ||
| tdesc.cc | ||
| tdesc.h | ||
| thread-db.cc | ||
| tracepoint.cc | ||
| tracepoint.h | ||
| utils.cc | ||
| utils.h | ||
| win32-aarch64-low.cc | ||
| win32-i386-low.cc | ||
| win32-low.cc | ||
| win32-low.h | ||
| x86-low.cc | ||
| x86-low.h | ||
| x86-tdesc.h | ||
| xtensa-xtregs.cc | ||
README for GDBserver & GDBreplay
by Stu Grossman and Fred Fish
Introduction:
This is GDBserver, a remote server for Un*x-like systems. It can be used to
control the execution of a program on a target system from a GDB on a different
host. GDB and GDBserver communicate using the standard remote serial protocol.
They communicate via either a serial line or a TCP connection.
For more information about GDBserver, see the GDB manual:
https://sourceware.org/gdb/current/onlinedocs/gdb/Remote-Protocol.html
Usage (server (target) side):
First, you need to have a copy of the program you want to debug put onto
the target system. The program can be stripped to save space if needed, as
GDBserver doesn't care about symbols. All symbol handling is taken care of by
the GDB running on the host system.
To use the server, you log on to the target system, and run the `gdbserver'
program. You must tell it (a) how to communicate with GDB, (b) the name of
your program, and (c) its arguments. The general syntax is:
target> gdbserver COMM PROGRAM [ARGS ...]
For example, using a serial port, you might say:
target> gdbserver /dev/com1 emacs foo.txt
This tells GDBserver to debug emacs with an argument of foo.txt, and to
communicate with GDB via /dev/com1. GDBserver now waits patiently for the
host GDB to communicate with it.
To use a TCP connection, you could say:
target> gdbserver host:2345 emacs foo.txt
This says pretty much the same thing as the last example, except that we are
going to communicate with the host GDB via TCP. The `host:2345' argument means
that we are expecting to see a TCP connection to local TCP port 2345.
(Currently, the `host' part is ignored.) You can choose any number you want for
the port number as long as it does not conflict with any existing TCP ports on
the target system. This same port number must be used in the host GDB's
`target remote' command, which will be described shortly. Note that if you chose
a port number that conflicts with another service, GDBserver will print an error
message and exit.
On some targets, GDBserver can also attach to running programs. This is
accomplished via the --attach argument. The syntax is:
target> gdbserver --attach COMM PID
PID is the process ID of a currently running process. It isn't necessary
to point GDBserver at a binary for the running process.
Usage (host side):
You need an unstripped copy of the target program on your host system, since
GDB needs to examine it's symbol tables and such. Start up GDB as you normally
would, with the target program as the first argument. (You may need to use the
--baud option if the serial line is running at anything except 9600 baud.)
Ie: `gdb TARGET-PROG', or `gdb --baud BAUD TARGET-PROG'. After that, the only
new command you need to know about is `target remote'. It's argument is either
a device name (usually a serial device, like `/dev/ttyb'), or a HOST:PORT
descriptor. For example:
(gdb) target remote /dev/ttyb
communicates with the server via serial line /dev/ttyb, and:
(gdb) target remote the-target:2345
communicates via a TCP connection to port 2345 on host `the-target', where
you previously started up GDBserver with the same port number. Note that for
TCP connections, you must start up GDBserver prior to using the `target remote'
command, otherwise you may get an error that looks something like
`Connection refused'.
Building GDBserver:
See the `configure.srv` file for the list of host triplets you can build
GDBserver for.
Building GDBserver for your host is very straightforward. If you build
GDB natively on a host which GDBserver supports, it will be built
automatically when you build GDB. You can also build just GDBserver:
% mkdir obj
% cd obj
% path-to-toplevel-sources/configure --disable-gdb
% make all-gdbserver
(If you have a combined binutils+gdb tree, you may want to also
disable other directories when configuring, e.g., binutils, gas, gold,
gprof, and ld.)
If you prefer to cross-compile to your target, then you can also build
GDBserver that way. For example:
% export CC=your-cross-compiler
% path-to-topevel-sources/configure --disable-gdb
% make all-gdbserver
Using GDBreplay:
A special hacked down version of GDBserver can be used to replay remote
debug log files created by GDB. Before using the GDB "target" command to
initiate a remote debug session, use "set remotelogfile <filename>" to tell
GDB that you want to make a recording of the serial or tcp session. Note
that when replaying the session, GDB communicates with GDBreplay via tcp,
regardless of whether the original session was via a serial link or tcp.
Once you are done with the remote debug session, start GDBreplay and
tell it the name of the log file and the host and port number that GDB
should connect to (typically the same as the host running GDB):
$ gdbreplay logfile host:port
Then start GDB (preferably in a different screen or window) and use the
"target" command to connect to GDBreplay:
(gdb) target remote host:port
Repeat the same sequence of user commands to GDB that you gave in the
original debug session. GDB should not be able to tell that it is talking
to GDBreplay rather than a real target, all other things being equal.
As GDBreplay communicates with GDB, it outputs only the commands
it expects from GDB. The --debug-logging option turns printing the
remotelogfile to stderr on. GDBreplay then echos the command lines
to stderr, as well as the contents of the packets it sends and receives.