gdbstub.c 61.7 KB
Newer Older
B
bellard 已提交
1 2
/*
 * gdb server stub
3
 *
B
bellard 已提交
4
 * Copyright (c) 2003-2005 Fabrice Bellard
B
bellard 已提交
5 6 7 8 9 10 11 12 13 14 15 16
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
17
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
B
bellard 已提交
18
 */
19
#include "config.h"
P
pbrook 已提交
20
#include "qemu-common.h"
B
bellard 已提交
21 22 23 24 25 26 27
#ifdef CONFIG_USER_ONLY
#include <stdlib.h>
#include <stdio.h>
#include <stdarg.h>
#include <string.h>
#include <errno.h>
#include <unistd.h>
28
#include <fcntl.h>
B
bellard 已提交
29 30 31

#include "qemu.h"
#else
32
#include "monitor/monitor.h"
33
#include "sysemu/char.h"
34
#include "sysemu/sysemu.h"
35
#include "exec/gdbstub.h"
B
bellard 已提交
36
#endif
B
bellard 已提交
37

P
pbrook 已提交
38 39
#define MAX_PACKET_LENGTH 4096

40
#include "cpu.h"
41
#include "qemu/sockets.h"
42
#include "sysemu/kvm.h"
R
Richard Henderson 已提交
43
#include "qemu/bitops.h"
44

45 46
static inline int target_memory_rw_debug(CPUState *cpu, target_ulong addr,
                                         uint8_t *buf, int len, bool is_write)
47
{
48 49 50 51 52 53
    CPUClass *cc = CPU_GET_CLASS(cpu);

    if (cc->memory_rw_debug) {
        return cc->memory_rw_debug(cpu, addr, buf, len, is_write);
    }
    return cpu_memory_rw_debug(cpu, addr, buf, len, is_write);
54
}
55 56 57 58

enum {
    GDB_SIGNAL_0 = 0,
    GDB_SIGNAL_INT = 2,
59
    GDB_SIGNAL_QUIT = 3,
60
    GDB_SIGNAL_TRAP = 5,
61 62 63 64
    GDB_SIGNAL_ABRT = 6,
    GDB_SIGNAL_ALRM = 14,
    GDB_SIGNAL_IO = 23,
    GDB_SIGNAL_XCPU = 24,
65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107
    GDB_SIGNAL_UNKNOWN = 143
};

#ifdef CONFIG_USER_ONLY

/* Map target signal numbers to GDB protocol signal numbers and vice
 * versa.  For user emulation's currently supported systems, we can
 * assume most signals are defined.
 */

static int gdb_signal_table[] = {
    0,
    TARGET_SIGHUP,
    TARGET_SIGINT,
    TARGET_SIGQUIT,
    TARGET_SIGILL,
    TARGET_SIGTRAP,
    TARGET_SIGABRT,
    -1, /* SIGEMT */
    TARGET_SIGFPE,
    TARGET_SIGKILL,
    TARGET_SIGBUS,
    TARGET_SIGSEGV,
    TARGET_SIGSYS,
    TARGET_SIGPIPE,
    TARGET_SIGALRM,
    TARGET_SIGTERM,
    TARGET_SIGURG,
    TARGET_SIGSTOP,
    TARGET_SIGTSTP,
    TARGET_SIGCONT,
    TARGET_SIGCHLD,
    TARGET_SIGTTIN,
    TARGET_SIGTTOU,
    TARGET_SIGIO,
    TARGET_SIGXCPU,
    TARGET_SIGXFSZ,
    TARGET_SIGVTALRM,
    TARGET_SIGPROF,
    TARGET_SIGWINCH,
    -1, /* SIGLOST */
    TARGET_SIGUSR1,
    TARGET_SIGUSR2,
B
blueswir1 已提交
108
#ifdef TARGET_SIGPWR
109
    TARGET_SIGPWR,
B
blueswir1 已提交
110 111 112
#else
    -1,
#endif
113 114 115 116 117 118 119 120 121 122 123 124
    -1, /* SIGPOLL */
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
    -1,
B
blueswir1 已提交
125
#ifdef __SIGRTMIN
126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231
    __SIGRTMIN + 1,
    __SIGRTMIN + 2,
    __SIGRTMIN + 3,
    __SIGRTMIN + 4,
    __SIGRTMIN + 5,
    __SIGRTMIN + 6,
    __SIGRTMIN + 7,
    __SIGRTMIN + 8,
    __SIGRTMIN + 9,
    __SIGRTMIN + 10,
    __SIGRTMIN + 11,
    __SIGRTMIN + 12,
    __SIGRTMIN + 13,
    __SIGRTMIN + 14,
    __SIGRTMIN + 15,
    __SIGRTMIN + 16,
    __SIGRTMIN + 17,
    __SIGRTMIN + 18,
    __SIGRTMIN + 19,
    __SIGRTMIN + 20,
    __SIGRTMIN + 21,
    __SIGRTMIN + 22,
    __SIGRTMIN + 23,
    __SIGRTMIN + 24,
    __SIGRTMIN + 25,
    __SIGRTMIN + 26,
    __SIGRTMIN + 27,
    __SIGRTMIN + 28,
    __SIGRTMIN + 29,
    __SIGRTMIN + 30,
    __SIGRTMIN + 31,
    -1, /* SIGCANCEL */
    __SIGRTMIN,
    __SIGRTMIN + 32,
    __SIGRTMIN + 33,
    __SIGRTMIN + 34,
    __SIGRTMIN + 35,
    __SIGRTMIN + 36,
    __SIGRTMIN + 37,
    __SIGRTMIN + 38,
    __SIGRTMIN + 39,
    __SIGRTMIN + 40,
    __SIGRTMIN + 41,
    __SIGRTMIN + 42,
    __SIGRTMIN + 43,
    __SIGRTMIN + 44,
    __SIGRTMIN + 45,
    __SIGRTMIN + 46,
    __SIGRTMIN + 47,
    __SIGRTMIN + 48,
    __SIGRTMIN + 49,
    __SIGRTMIN + 50,
    __SIGRTMIN + 51,
    __SIGRTMIN + 52,
    __SIGRTMIN + 53,
    __SIGRTMIN + 54,
    __SIGRTMIN + 55,
    __SIGRTMIN + 56,
    __SIGRTMIN + 57,
    __SIGRTMIN + 58,
    __SIGRTMIN + 59,
    __SIGRTMIN + 60,
    __SIGRTMIN + 61,
    __SIGRTMIN + 62,
    __SIGRTMIN + 63,
    __SIGRTMIN + 64,
    __SIGRTMIN + 65,
    __SIGRTMIN + 66,
    __SIGRTMIN + 67,
    __SIGRTMIN + 68,
    __SIGRTMIN + 69,
    __SIGRTMIN + 70,
    __SIGRTMIN + 71,
    __SIGRTMIN + 72,
    __SIGRTMIN + 73,
    __SIGRTMIN + 74,
    __SIGRTMIN + 75,
    __SIGRTMIN + 76,
    __SIGRTMIN + 77,
    __SIGRTMIN + 78,
    __SIGRTMIN + 79,
    __SIGRTMIN + 80,
    __SIGRTMIN + 81,
    __SIGRTMIN + 82,
    __SIGRTMIN + 83,
    __SIGRTMIN + 84,
    __SIGRTMIN + 85,
    __SIGRTMIN + 86,
    __SIGRTMIN + 87,
    __SIGRTMIN + 88,
    __SIGRTMIN + 89,
    __SIGRTMIN + 90,
    __SIGRTMIN + 91,
    __SIGRTMIN + 92,
    __SIGRTMIN + 93,
    __SIGRTMIN + 94,
    __SIGRTMIN + 95,
    -1, /* SIGINFO */
    -1, /* UNKNOWN */
    -1, /* DEFAULT */
    -1,
    -1,
    -1,
    -1,
    -1,
    -1
B
blueswir1 已提交
232
#endif
233
};
B
bellard 已提交
234
#else
235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261
/* In system mode we only need SIGINT and SIGTRAP; other signals
   are not yet supported.  */

enum {
    TARGET_SIGINT = 2,
    TARGET_SIGTRAP = 5
};

static int gdb_signal_table[] = {
    -1,
    -1,
    TARGET_SIGINT,
    -1,
    -1,
    TARGET_SIGTRAP
};
#endif

#ifdef CONFIG_USER_ONLY
static int target_signal_to_gdb (int sig)
{
    int i;
    for (i = 0; i < ARRAY_SIZE (gdb_signal_table); i++)
        if (gdb_signal_table[i] == sig)
            return i;
    return GDB_SIGNAL_UNKNOWN;
}
B
bellard 已提交
262
#endif
B
bellard 已提交
263

264 265 266 267 268 269 270 271
static int gdb_signal_to_target (int sig)
{
    if (sig < ARRAY_SIZE (gdb_signal_table))
        return gdb_signal_table[sig];
    else
        return -1;
}

B
bellard 已提交
272
//#define DEBUG_GDB
B
bellard 已提交
273

P
pbrook 已提交
274 275 276 277 278 279 280 281 282
typedef struct GDBRegisterState {
    int base_reg;
    int num_regs;
    gdb_reg_cb get_reg;
    gdb_reg_cb set_reg;
    const char *xml;
    struct GDBRegisterState *next;
} GDBRegisterState;

283
enum RSState {
284
    RS_INACTIVE,
285 286 287 288 289 290
    RS_IDLE,
    RS_GETLINE,
    RS_CHKSUM1,
    RS_CHKSUM2,
};
typedef struct GDBState {
291 292
    CPUState *c_cpu; /* current CPU for step/continue ops */
    CPUState *g_cpu; /* current CPU for other ops */
293
    CPUState *query_cpu; /* for q{f|s}ThreadInfo */
B
bellard 已提交
294
    enum RSState state; /* parsing state */
P
pbrook 已提交
295
    char line_buf[MAX_PACKET_LENGTH];
296 297
    int line_buf_index;
    int line_csum;
P
pbrook 已提交
298
    uint8_t last_packet[MAX_PACKET_LENGTH + 4];
299
    int last_packet_len;
300
    int signal;
B
bellard 已提交
301
#ifdef CONFIG_USER_ONLY
302
    int fd;
B
bellard 已提交
303
    int running_state;
304 305
#else
    CharDriverState *chr;
306
    CharDriverState *mon_chr;
B
bellard 已提交
307
#endif
308 309
    char syscall_buf[256];
    gdb_syscall_complete_cb current_syscall_cb;
310
} GDBState;
B
bellard 已提交
311

312 313 314 315 316
/* By default use no IRQs and no timers while single stepping so as to
 * make single stepping like an ICE HW step.
 */
static int sstep_flags = SSTEP_ENABLE|SSTEP_NOIRQ|SSTEP_NOTIMER;

317 318
static GDBState *gdbserver_state;

P
pbrook 已提交
319 320 321 322 323
/* This is an ugly hack to cope with both new and old gdb.
   If gdb sends qXfer:features:read then assume we're talking to a newish
   gdb that understands target descriptions.  */
static int gdb_has_xml;

B
bellard 已提交
324
#ifdef CONFIG_USER_ONLY
325 326 327
/* XXX: This is not thread safe.  Do we care?  */
static int gdbserver_fd = -1;

328
static int get_char(GDBState *s)
B
bellard 已提交
329 330 331 332 333
{
    uint8_t ch;
    int ret;

    for(;;) {
B
Blue Swirl 已提交
334
        ret = qemu_recv(s->fd, &ch, 1, 0);
B
bellard 已提交
335
        if (ret < 0) {
336 337
            if (errno == ECONNRESET)
                s->fd = -1;
B
bellard 已提交
338 339 340
            if (errno != EINTR && errno != EAGAIN)
                return -1;
        } else if (ret == 0) {
341 342
            close(s->fd);
            s->fd = -1;
B
bellard 已提交
343 344 345 346 347 348 349
            return -1;
        } else {
            break;
        }
    }
    return ch;
}
350
#endif
B
bellard 已提交
351

352
static enum {
P
pbrook 已提交
353 354 355 356 357 358 359 360 361 362
    GDB_SYS_UNKNOWN,
    GDB_SYS_ENABLED,
    GDB_SYS_DISABLED,
} gdb_syscall_mode;

/* If gdb is connected when the first semihosting syscall occurs then use
   remote gdb syscalls.  Otherwise use native file IO.  */
int use_gdb_syscalls(void)
{
    if (gdb_syscall_mode == GDB_SYS_UNKNOWN) {
363 364
        gdb_syscall_mode = (gdbserver_state ? GDB_SYS_ENABLED
                                            : GDB_SYS_DISABLED);
P
pbrook 已提交
365 366 367 368
    }
    return gdb_syscall_mode == GDB_SYS_ENABLED;
}

369 370 371 372 373 374
/* Resume execution.  */
static inline void gdb_continue(GDBState *s)
{
#ifdef CONFIG_USER_ONLY
    s->running_state = 1;
#else
375 376 377
    if (runstate_check(RUN_STATE_GUEST_PANICKED)) {
        runstate_set(RUN_STATE_DEBUG);
    }
378
    if (!runstate_needs_reset()) {
379 380
        vm_start();
    }
381 382 383
#endif
}

384
static void put_buffer(GDBState *s, const uint8_t *buf, int len)
B
bellard 已提交
385
{
386
#ifdef CONFIG_USER_ONLY
B
bellard 已提交
387 388 389
    int ret;

    while (len > 0) {
B
bellard 已提交
390
        ret = send(s->fd, buf, len, 0);
B
bellard 已提交
391 392 393 394 395 396 397 398
        if (ret < 0) {
            if (errno != EINTR && errno != EAGAIN)
                return;
        } else {
            buf += ret;
            len -= ret;
        }
    }
399
#else
400
    qemu_chr_fe_write(s->chr, buf, len);
401
#endif
B
bellard 已提交
402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447
}

static inline int fromhex(int v)
{
    if (v >= '0' && v <= '9')
        return v - '0';
    else if (v >= 'A' && v <= 'F')
        return v - 'A' + 10;
    else if (v >= 'a' && v <= 'f')
        return v - 'a' + 10;
    else
        return 0;
}

static inline int tohex(int v)
{
    if (v < 10)
        return v + '0';
    else
        return v - 10 + 'a';
}

static void memtohex(char *buf, const uint8_t *mem, int len)
{
    int i, c;
    char *q;
    q = buf;
    for(i = 0; i < len; i++) {
        c = mem[i];
        *q++ = tohex(c >> 4);
        *q++ = tohex(c & 0xf);
    }
    *q = '\0';
}

static void hextomem(uint8_t *mem, const char *buf, int len)
{
    int i;

    for(i = 0; i < len; i++) {
        mem[i] = (fromhex(buf[0]) << 4) | fromhex(buf[1]);
        buf += 2;
    }
}

/* return -1 if error, 0 if OK */
P
pbrook 已提交
448
static int put_packet_binary(GDBState *s, const char *buf, int len)
B
bellard 已提交
449
{
P
pbrook 已提交
450
    int csum, i;
T
ths 已提交
451
    uint8_t *p;
B
bellard 已提交
452 453

    for(;;) {
454 455 456 457
        p = s->last_packet;
        *(p++) = '$';
        memcpy(p, buf, len);
        p += len;
B
bellard 已提交
458 459 460 461
        csum = 0;
        for(i = 0; i < len; i++) {
            csum += buf[i];
        }
462 463 464
        *(p++) = '#';
        *(p++) = tohex((csum >> 4) & 0xf);
        *(p++) = tohex((csum) & 0xf);
B
bellard 已提交
465

466
        s->last_packet_len = p - s->last_packet;
T
ths 已提交
467
        put_buffer(s, (uint8_t *)s->last_packet, s->last_packet_len);
B
bellard 已提交
468

469 470 471
#ifdef CONFIG_USER_ONLY
        i = get_char(s);
        if (i < 0)
B
bellard 已提交
472
            return -1;
473
        if (i == '+')
B
bellard 已提交
474
            break;
475 476 477
#else
        break;
#endif
B
bellard 已提交
478 479 480 481
    }
    return 0;
}

P
pbrook 已提交
482 483 484 485 486 487
/* return -1 if error, 0 if OK */
static int put_packet(GDBState *s, const char *buf)
{
#ifdef DEBUG_GDB
    printf("reply='%s'\n", buf);
#endif
B
bellard 已提交
488

P
pbrook 已提交
489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518
    return put_packet_binary(s, buf, strlen(buf));
}

/* The GDB remote protocol transfers values in target byte order.  This means
   we can use the raw memory access routines to access the value buffer.
   Conveniently, these also handle the case where the buffer is mis-aligned.
 */
#define GET_REG8(val) do { \
    stb_p(mem_buf, val); \
    return 1; \
    } while(0)
#define GET_REG16(val) do { \
    stw_p(mem_buf, val); \
    return 2; \
    } while(0)
#define GET_REG32(val) do { \
    stl_p(mem_buf, val); \
    return 4; \
    } while(0)
#define GET_REG64(val) do { \
    stq_p(mem_buf, val); \
    return 8; \
    } while(0)

#if TARGET_LONG_BITS == 64
#define GET_REGL(val) GET_REG64(val)
#define ldtul_p(addr) ldq_p(addr)
#else
#define GET_REGL(val) GET_REG32(val)
#define ldtul_p(addr) ldl_p(addr)
B
bellard 已提交
519 520
#endif

P
pbrook 已提交
521
#if defined(TARGET_I386)
522

523
#include "target-i386/gdbstub.c"
B
bellard 已提交
524

B
bellard 已提交
525 526
#elif defined (TARGET_PPC)

527 528 529 530 531
#if defined (TARGET_PPC64)
#define GDB_CORE_XML "power64-core.xml"
#else
#define GDB_CORE_XML "power-core.xml"
#endif
B
bellard 已提交
532

533
#include "target-ppc/gdbstub.c"
P
pbrook 已提交
534

535
#elif defined (TARGET_SPARC)
P
pbrook 已提交
536

537
#include "target-sparc/gdbstub.c"
538

B
bellard 已提交
539
#elif defined (TARGET_ARM)
B
bellard 已提交
540

P
pbrook 已提交
541
#define GDB_CORE_XML "arm-core.xml"
P
pbrook 已提交
542

543
#include "target-arm/gdbstub.c"
544

P
pbrook 已提交
545
#elif defined (TARGET_M68K)
546

P
pbrook 已提交
547
#define GDB_CORE_XML "cf-core.xml"
548

549
static int cpu_gdb_read_register(CPUM68KState *env, uint8_t *mem_buf, int n)
P
pbrook 已提交
550 551 552 553 554 555 556 557
{
    if (n < 8) {
        /* D0-D7 */
        GET_REG32(env->dregs[n]);
    } else if (n < 16) {
        /* A0-A7 */
        GET_REG32(env->aregs[n - 8]);
    } else {
558 559 560 561 562
        switch (n) {
        case 16:
            GET_REG32(env->sr);
        case 17:
            GET_REG32(env->pc);
P
pbrook 已提交
563 564 565 566 567 568
        }
    }
    /* FP registers not included here because they vary between
       ColdFire and m68k.  Use XML bits for these.  */
    return 0;
}
569

570
static int cpu_gdb_write_register(CPUM68KState *env, uint8_t *mem_buf, int n)
P
pbrook 已提交
571 572
{
    uint32_t tmp;
573

P
pbrook 已提交
574
    tmp = ldl_p(mem_buf);
575

P
pbrook 已提交
576 577 578
    if (n < 8) {
        /* D0-D7 */
        env->dregs[n] = tmp;
579
    } else if (n < 16) {
P
pbrook 已提交
580 581 582 583
        /* A0-A7 */
        env->aregs[n - 8] = tmp;
    } else {
        switch (n) {
584 585 586 587 588 589 590 591
        case 16:
            env->sr = tmp;
            break;
        case 17:
            env->pc = tmp;
            break;
        default:
            return 0;
P
pbrook 已提交
592 593 594 595 596
        }
    }
    return 4;
}
#elif defined (TARGET_MIPS)
T
ths 已提交
597

598
static int cpu_gdb_read_register(CPUMIPSState *env, uint8_t *mem_buf, int n)
P
pbrook 已提交
599 600 601 602 603 604
{
    if (n < 32) {
        GET_REGL(env->active_tc.gpr[n]);
    }
    if (env->CP0_Config1 & (1 << CP0C1_FP)) {
        if (n >= 38 && n < 70) {
605 606 607 608 609
            if (env->CP0_Status & (1 << CP0St_FR)) {
                GET_REGL(env->active_fpu.fpr[n - 38].d);
            } else {
                GET_REGL(env->active_fpu.fpr[n - 38].w[FP_ENDIAN_IDX]);
            }
P
pbrook 已提交
610 611
        }
        switch (n) {
612 613 614 615
        case 70:
            GET_REGL((int32_t)env->active_fpu.fcr31);
        case 71:
            GET_REGL((int32_t)env->active_fpu.fcr0);
P
pbrook 已提交
616 617 618
        }
    }
    switch (n) {
619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634
    case 32:
        GET_REGL((int32_t)env->CP0_Status);
    case 33:
        GET_REGL(env->active_tc.LO[0]);
    case 34:
        GET_REGL(env->active_tc.HI[0]);
    case 35:
        GET_REGL(env->CP0_BadVAddr);
    case 36:
        GET_REGL((int32_t)env->CP0_Cause);
    case 37:
        GET_REGL(env->active_tc.PC | !!(env->hflags & MIPS_HFLAG_M16));
    case 72:
        GET_REGL(0); /* fp */
    case 89:
        GET_REGL((int32_t)env->CP0_PRid);
P
pbrook 已提交
635 636
    }
    if (n >= 73 && n <= 88) {
637 638
        /* 16 embedded regs.  */
        GET_REGL(0);
P
pbrook 已提交
639
    }
640

P
pbrook 已提交
641
    return 0;
642 643
}

644
/* convert MIPS rounding mode in FCR31 to IEEE library */
645
static unsigned int ieee_rm[] = {
646 647 648 649
    float_round_nearest_even,
    float_round_to_zero,
    float_round_up,
    float_round_down
650
};
651
#define RESTORE_ROUNDING_MODE \
652 653
    set_float_rounding_mode(ieee_rm[env->active_fpu.fcr31 & 3], \
                            &env->active_fpu.fp_status)
654

655
static int cpu_gdb_write_register(CPUMIPSState *env, uint8_t *mem_buf, int n)
656
{
P
pbrook 已提交
657
    target_ulong tmp;
658

P
pbrook 已提交
659
    tmp = ldtul_p(mem_buf);
660

P
pbrook 已提交
661 662 663 664 665 666 667
    if (n < 32) {
        env->active_tc.gpr[n] = tmp;
        return sizeof(target_ulong);
    }
    if (env->CP0_Config1 & (1 << CP0C1_FP)
            && n >= 38 && n < 73) {
        if (n < 70) {
668 669 670 671 672
            if (env->CP0_Status & (1 << CP0St_FR)) {
                env->active_fpu.fpr[n - 38].d = tmp;
            } else {
                env->active_fpu.fpr[n - 38].w[FP_ENDIAN_IDX] = tmp;
            }
P
pbrook 已提交
673 674 675 676 677 678 679
        }
        switch (n) {
        case 70:
            env->active_fpu.fcr31 = tmp & 0xFF83FFFF;
            /* set rounding mode */
            RESTORE_ROUNDING_MODE;
            break;
680 681 682
        case 71:
            env->active_fpu.fcr0 = tmp;
            break;
P
pbrook 已提交
683 684 685 686
        }
        return sizeof(target_ulong);
    }
    switch (n) {
687 688 689 690 691 692 693 694 695 696 697 698 699 700 701
    case 32:
        env->CP0_Status = tmp;
        break;
    case 33:
        env->active_tc.LO[0] = tmp;
        break;
    case 34:
        env->active_tc.HI[0] = tmp;
        break;
    case 35:
        env->CP0_BadVAddr = tmp;
        break;
    case 36:
        env->CP0_Cause = tmp;
        break;
N
Nathan Froyd 已提交
702 703 704 705 706 707 708 709
    case 37:
        env->active_tc.PC = tmp & ~(target_ulong)1;
        if (tmp & 1) {
            env->hflags |= MIPS_HFLAG_M16;
        } else {
            env->hflags &= ~(MIPS_HFLAG_M16);
        }
        break;
710 711 712 713 714 715 716 717
    case 72: /* fp, ignored */
        break;
    default:
        if (n > 89) {
            return 0;
        }
        /* Other registers are readonly.  Ignore writes.  */
        break;
P
pbrook 已提交
718 719 720
    }

    return sizeof(target_ulong);
721
}
J
Jia Liu 已提交
722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748
#elif defined(TARGET_OPENRISC)

static int cpu_gdb_read_register(CPUOpenRISCState *env, uint8_t *mem_buf, int n)
{
    if (n < 32) {
        GET_REG32(env->gpr[n]);
    } else {
        switch (n) {
        case 32:    /* PPC */
            GET_REG32(env->ppc);

        case 33:    /* NPC */
            GET_REG32(env->npc);

        case 34:    /* SR */
            GET_REG32(env->sr);

        default:
            break;
        }
    }
    return 0;
}

static int cpu_gdb_write_register(CPUOpenRISCState *env,
                                  uint8_t *mem_buf, int n)
{
749 750
    OpenRISCCPU *cpu = openrisc_env_get_cpu(env);
    CPUClass *cc = CPU_GET_CLASS(cpu);
J
Jia Liu 已提交
751 752
    uint32_t tmp;

753
    if (n > cc->gdb_num_core_regs) {
J
Jia Liu 已提交
754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780
        return 0;
    }

    tmp = ldl_p(mem_buf);

    if (n < 32) {
        env->gpr[n] = tmp;
    } else {
        switch (n) {
        case 32: /* PPC */
            env->ppc = tmp;
            break;

        case 33: /* NPC */
            env->npc = tmp;
            break;

        case 34: /* SR */
            env->sr = tmp;
            break;

        default:
            break;
        }
    }
    return 4;
}
B
bellard 已提交
781
#elif defined (TARGET_SH4)
782 783

/* Hint: Use "set architecture sh4" in GDB to see fpu registers */
P
pbrook 已提交
784 785
/* FIXME: We should use XML for this.  */

786
static int cpu_gdb_read_register(CPUSH4State *env, uint8_t *mem_buf, int n)
B
bellard 已提交
787
{
788 789
    switch (n) {
    case 0 ... 7:
P
pbrook 已提交
790 791 792 793 794
        if ((env->sr & (SR_MD | SR_RB)) == (SR_MD | SR_RB)) {
            GET_REGL(env->gregs[n + 16]);
        } else {
            GET_REGL(env->gregs[n]);
        }
795
    case 8 ... 15:
796
        GET_REGL(env->gregs[n]);
797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829
    case 16:
        GET_REGL(env->pc);
    case 17:
        GET_REGL(env->pr);
    case 18:
        GET_REGL(env->gbr);
    case 19:
        GET_REGL(env->vbr);
    case 20:
        GET_REGL(env->mach);
    case 21:
        GET_REGL(env->macl);
    case 22:
        GET_REGL(env->sr);
    case 23:
        GET_REGL(env->fpul);
    case 24:
        GET_REGL(env->fpscr);
    case 25 ... 40:
        if (env->fpscr & FPSCR_FR) {
            stfl_p(mem_buf, env->fregs[n - 9]);
        } else {
            stfl_p(mem_buf, env->fregs[n - 25]);
        }
        return 4;
    case 41:
        GET_REGL(env->ssr);
    case 42:
        GET_REGL(env->spc);
    case 43 ... 50:
        GET_REGL(env->gregs[n - 43]);
    case 51 ... 58:
        GET_REGL(env->gregs[n - (51 - 16)]);
P
pbrook 已提交
830 831 832
    }

    return 0;
B
bellard 已提交
833 834
}

835
static int cpu_gdb_write_register(CPUSH4State *env, uint8_t *mem_buf, int n)
B
bellard 已提交
836
{
837 838
    switch (n) {
    case 0 ... 7:
P
pbrook 已提交
839
        if ((env->sr & (SR_MD | SR_RB)) == (SR_MD | SR_RB)) {
840
            env->gregs[n + 16] = ldl_p(mem_buf);
P
pbrook 已提交
841
        } else {
842
            env->gregs[n] = ldl_p(mem_buf);
P
pbrook 已提交
843
        }
844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893
        break;
    case 8 ... 15:
        env->gregs[n] = ldl_p(mem_buf);
        break;
    case 16:
        env->pc = ldl_p(mem_buf);
        break;
    case 17:
        env->pr = ldl_p(mem_buf);
        break;
    case 18:
        env->gbr = ldl_p(mem_buf);
        break;
    case 19:
        env->vbr = ldl_p(mem_buf);
        break;
    case 20:
        env->mach = ldl_p(mem_buf);
        break;
    case 21:
        env->macl = ldl_p(mem_buf);
        break;
    case 22:
        env->sr = ldl_p(mem_buf);
        break;
    case 23:
        env->fpul = ldl_p(mem_buf);
        break;
    case 24:
        env->fpscr = ldl_p(mem_buf);
        break;
    case 25 ... 40:
        if (env->fpscr & FPSCR_FR) {
            env->fregs[n - 9] = ldfl_p(mem_buf);
        } else {
            env->fregs[n - 25] = ldfl_p(mem_buf);
        }
        break;
    case 41:
        env->ssr = ldl_p(mem_buf);
        break;
    case 42:
        env->spc = ldl_p(mem_buf);
        break;
    case 43 ... 50:
        env->gregs[n - 43] = ldl_p(mem_buf);
        break;
    case 51 ... 58:
        env->gregs[n - (51 - 16)] = ldl_p(mem_buf);
        break;
894 895
    default:
        return 0;
P
pbrook 已提交
896 897 898
    }

    return 4;
B
bellard 已提交
899
}
900 901
#elif defined (TARGET_MICROBLAZE)

902
static int cpu_gdb_read_register(CPUMBState *env, uint8_t *mem_buf, int n)
903 904
{
    if (n < 32) {
905
        GET_REG32(env->regs[n]);
906
    } else {
907
        GET_REG32(env->sregs[n - 32]);
908 909 910 911
    }
    return 0;
}

912
static int cpu_gdb_write_register(CPUMBState *env, uint8_t *mem_buf, int n)
913
{
914 915
    MicroBlazeCPU *cpu = mb_env_get_cpu(env);
    CPUClass *cc = CPU_GET_CLASS(cpu);
916 917
    uint32_t tmp;

918
    if (n > cc->gdb_num_core_regs) {
919 920
        return 0;
    }
921 922 923 924

    tmp = ldl_p(mem_buf);

    if (n < 32) {
925
        env->regs[n] = tmp;
926
    } else {
927
        env->sregs[n - 32] = tmp;
928 929 930
    }
    return 4;
}
931 932
#elif defined (TARGET_CRIS)

933
static int
934
read_register_crisv10(CPUCRISState *env, uint8_t *mem_buf, int n)
935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962
{
    if (n < 15) {
        GET_REG32(env->regs[n]);
    }

    if (n == 15) {
        GET_REG32(env->pc);
    }

    if (n < 32) {
        switch (n) {
        case 16:
            GET_REG8(env->pregs[n - 16]);
        case 17:
            GET_REG8(env->pregs[n - 16]);
        case 20:
        case 21:
            GET_REG16(env->pregs[n - 16]);
        default:
            if (n >= 23) {
                GET_REG32(env->pregs[n - 16]);
            }
            break;
        }
    }
    return 0;
}

963
static int cpu_gdb_read_register(CPUCRISState *env, uint8_t *mem_buf, int n)
964
{
P
pbrook 已提交
965 966
    uint8_t srs;

967
    if (env->pregs[PR_VR] < 32) {
968
        return read_register_crisv10(env, mem_buf, n);
969
    }
970

P
pbrook 已提交
971 972
    srs = env->pregs[PR_SRS];
    if (n < 16) {
973
        GET_REG32(env->regs[n]);
P
pbrook 已提交
974 975 976
    }

    if (n >= 21 && n < 32) {
977
        GET_REG32(env->pregs[n - 16]);
P
pbrook 已提交
978 979
    }
    if (n >= 33 && n < 49) {
980
        GET_REG32(env->sregs[srs][n - 33]);
P
pbrook 已提交
981 982
    }
    switch (n) {
983 984 985 986 987 988 989 990 991 992 993 994
    case 16:
        GET_REG8(env->pregs[0]);
    case 17:
        GET_REG8(env->pregs[1]);
    case 18:
        GET_REG32(env->pregs[2]);
    case 19:
        GET_REG8(srs);
    case 20:
        GET_REG16(env->pregs[4]);
    case 32:
        GET_REG32(env->pc);
P
pbrook 已提交
995 996 997
    }

    return 0;
998
}
P
pbrook 已提交
999

1000
static int cpu_gdb_write_register(CPUCRISState *env, uint8_t *mem_buf, int n)
1001
{
P
pbrook 已提交
1002 1003
    uint32_t tmp;

1004 1005 1006
    if (n > 49) {
        return 0;
    }
P
pbrook 已提交
1007 1008 1009 1010

    tmp = ldl_p(mem_buf);

    if (n < 16) {
1011
        env->regs[n] = tmp;
P
pbrook 已提交
1012 1013
    }

E
edgar_igl 已提交
1014
    if (n >= 21 && n < 32) {
1015
        env->pregs[n - 16] = tmp;
E
edgar_igl 已提交
1016 1017 1018
    }

    /* FIXME: Should support function regs be writable?  */
P
pbrook 已提交
1019
    switch (n) {
1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033
    case 16:
        return 1;
    case 17:
        return 1;
    case 18:
        env->pregs[PR_PID] = tmp;
        break;
    case 19:
        return 1;
    case 20:
        return 2;
    case 32:
        env->pc = tmp;
        break;
P
pbrook 已提交
1034 1035 1036
    }

    return 4;
1037
}
A
aurel32 已提交
1038 1039
#elif defined (TARGET_ALPHA)

1040
static int cpu_gdb_read_register(CPUAlphaState *env, uint8_t *mem_buf, int n)
A
aurel32 已提交
1041
{
1042 1043
    uint64_t val;
    CPU_DoubleU d;
A
aurel32 已提交
1044

1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069
    switch (n) {
    case 0 ... 30:
        val = env->ir[n];
        break;
    case 32 ... 62:
        d.d = env->fir[n - 32];
        val = d.ll;
        break;
    case 63:
        val = cpu_alpha_load_fpcr(env);
        break;
    case 64:
        val = env->pc;
        break;
    case 66:
        val = env->unique;
        break;
    case 31:
    case 65:
        /* 31 really is the zero register; 65 is unassigned in the
           gdb protocol, but is still required to occupy 8 bytes. */
        val = 0;
        break;
    default:
        return 0;
A
aurel32 已提交
1070
    }
1071
    GET_REGL(val);
A
aurel32 已提交
1072 1073
}

1074
static int cpu_gdb_write_register(CPUAlphaState *env, uint8_t *mem_buf, int n)
A
aurel32 已提交
1075
{
1076 1077
    target_ulong tmp = ldtul_p(mem_buf);
    CPU_DoubleU d;
A
aurel32 已提交
1078

1079 1080
    switch (n) {
    case 0 ... 30:
A
aurel32 已提交
1081
        env->ir[n] = tmp;
1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102
        break;
    case 32 ... 62:
        d.ll = tmp;
        env->fir[n - 32] = d.d;
        break;
    case 63:
        cpu_alpha_store_fpcr(env, tmp);
        break;
    case 64:
        env->pc = tmp;
        break;
    case 66:
        env->unique = tmp;
        break;
    case 31:
    case 65:
        /* 31 really is the zero register; 65 is unassigned in the
           gdb protocol, but is still required to occupy 8 bytes. */
        break;
    default:
        return 0;
A
aurel32 已提交
1103 1104 1105
    }
    return 8;
}
A
Alexander Graf 已提交
1106 1107
#elif defined (TARGET_S390X)

1108
static int cpu_gdb_read_register(CPUS390XState *env, uint8_t *mem_buf, int n)
A
Alexander Graf 已提交
1109
{
R
Richard Henderson 已提交
1110 1111 1112
    uint64_t val;
    int cc_op;

A
Alexander Graf 已提交
1113
    switch (n) {
R
Richard Henderson 已提交
1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127
    case S390_PSWM_REGNUM:
        cc_op = calc_cc(env, env->cc_op, env->cc_src, env->cc_dst, env->cc_vr);
        val = deposit64(env->psw.mask, 44, 2, cc_op);
        GET_REGL(val);
    case S390_PSWA_REGNUM:
        GET_REGL(env->psw.addr);
    case S390_R0_REGNUM ... S390_R15_REGNUM:
        GET_REGL(env->regs[n-S390_R0_REGNUM]);
    case S390_A0_REGNUM ... S390_A15_REGNUM:
        GET_REG32(env->aregs[n-S390_A0_REGNUM]);
    case S390_FPC_REGNUM:
        GET_REG32(env->fpc);
    case S390_F0_REGNUM ... S390_F15_REGNUM:
        GET_REG64(env->fregs[n-S390_F0_REGNUM].ll);
A
Alexander Graf 已提交
1128 1129 1130 1131 1132
    }

    return 0;
}

1133
static int cpu_gdb_write_register(CPUS390XState *env, uint8_t *mem_buf, int n)
A
Alexander Graf 已提交
1134 1135 1136 1137 1138 1139 1140 1141
{
    target_ulong tmpl;
    uint32_t tmp32;
    int r = 8;
    tmpl = ldtul_p(mem_buf);
    tmp32 = ldl_p(mem_buf);

    switch (n) {
R
Richard Henderson 已提交
1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164
    case S390_PSWM_REGNUM:
        env->psw.mask = tmpl;
        env->cc_op = extract64(tmpl, 44, 2);
        break;
    case S390_PSWA_REGNUM:
        env->psw.addr = tmpl;
        break;
    case S390_R0_REGNUM ... S390_R15_REGNUM:
        env->regs[n-S390_R0_REGNUM] = tmpl;
        break;
    case S390_A0_REGNUM ... S390_A15_REGNUM:
        env->aregs[n-S390_A0_REGNUM] = tmp32;
        r = 4;
        break;
    case S390_FPC_REGNUM:
        env->fpc = tmp32;
        r = 4;
        break;
    case S390_F0_REGNUM ... S390_F15_REGNUM:
        env->fregs[n-S390_F0_REGNUM].ll = tmpl;
        break;
    default:
        return 0;
A
Alexander Graf 已提交
1165 1166 1167
    }
    return r;
}
M
Michael Walle 已提交
1168 1169
#elif defined (TARGET_LM32)

P
Paolo Bonzini 已提交
1170
#include "hw/lm32/lm32_pic.h"
M
Michael Walle 已提交
1171

1172
static int cpu_gdb_read_register(CPULM32State *env, uint8_t *mem_buf, int n)
M
Michael Walle 已提交
1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197
{
    if (n < 32) {
        GET_REG32(env->regs[n]);
    } else {
        switch (n) {
        case 32:
            GET_REG32(env->pc);
        /* FIXME: put in right exception ID */
        case 33:
            GET_REG32(0);
        case 34:
            GET_REG32(env->eba);
        case 35:
            GET_REG32(env->deba);
        case 36:
            GET_REG32(env->ie);
        case 37:
            GET_REG32(lm32_pic_get_im(env->pic_state));
        case 38:
            GET_REG32(lm32_pic_get_ip(env->pic_state));
        }
    }
    return 0;
}

1198
static int cpu_gdb_write_register(CPULM32State *env, uint8_t *mem_buf, int n)
M
Michael Walle 已提交
1199
{
1200 1201
    LM32CPU *cpu = lm32_env_get_cpu(env);
    CPUClass *cc = CPU_GET_CLASS(cpu);
M
Michael Walle 已提交
1202 1203
    uint32_t tmp;

1204
    if (n > cc->gdb_num_core_regs) {
M
Michael Walle 已提交
1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235
        return 0;
    }

    tmp = ldl_p(mem_buf);

    if (n < 32) {
        env->regs[n] = tmp;
    } else {
        switch (n) {
        case 32:
            env->pc = tmp;
            break;
        case 34:
            env->eba = tmp;
            break;
        case 35:
            env->deba = tmp;
            break;
        case 36:
            env->ie = tmp;
            break;
        case 37:
            lm32_pic_set_im(env->pic_state, tmp);
            break;
        case 38:
            lm32_pic_set_ip(env->pic_state, tmp);
            break;
        }
    }
    return 4;
}
M
Max Filippov 已提交
1236 1237
#elif defined(TARGET_XTENSA)

1238
static int cpu_gdb_read_register(CPUXtensaState *env, uint8_t *mem_buf, int n)
M
Max Filippov 已提交
1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259
{
    const XtensaGdbReg *reg = env->config->gdb_regmap.reg + n;

    if (n < 0 || n >= env->config->gdb_regmap.num_regs) {
        return 0;
    }

    switch (reg->type) {
    case 9: /*pc*/
        GET_REG32(env->pc);

    case 1: /*ar*/
        xtensa_sync_phys_from_window(env);
        GET_REG32(env->phys_regs[(reg->targno & 0xff) % env->config->nareg]);

    case 2: /*SR*/
        GET_REG32(env->sregs[reg->targno & 0xff]);

    case 3: /*UR*/
        GET_REG32(env->uregs[reg->targno & 0xff]);

M
Max Filippov 已提交
1260 1261 1262
    case 4: /*f*/
        GET_REG32(float32_val(env->fregs[reg->targno & 0x0f]));

M
Max Filippov 已提交
1263 1264 1265 1266 1267
    case 8: /*a*/
        GET_REG32(env->regs[reg->targno & 0x0f]);

    default:
        qemu_log("%s from reg %d of unsupported type %d\n",
1268
                 __func__, n, reg->type);
M
Max Filippov 已提交
1269 1270 1271 1272
        return 0;
    }
}

1273
static int cpu_gdb_write_register(CPUXtensaState *env, uint8_t *mem_buf, int n)
M
Max Filippov 已提交
1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301
{
    uint32_t tmp;
    const XtensaGdbReg *reg = env->config->gdb_regmap.reg + n;

    if (n < 0 || n >= env->config->gdb_regmap.num_regs) {
        return 0;
    }

    tmp = ldl_p(mem_buf);

    switch (reg->type) {
    case 9: /*pc*/
        env->pc = tmp;
        break;

    case 1: /*ar*/
        env->phys_regs[(reg->targno & 0xff) % env->config->nareg] = tmp;
        xtensa_sync_window_from_phys(env);
        break;

    case 2: /*SR*/
        env->sregs[reg->targno & 0xff] = tmp;
        break;

    case 3: /*UR*/
        env->uregs[reg->targno & 0xff] = tmp;
        break;

M
Max Filippov 已提交
1302 1303 1304 1305
    case 4: /*f*/
        env->fregs[reg->targno & 0x0f] = make_float32(tmp);
        break;

M
Max Filippov 已提交
1306 1307 1308 1309 1310 1311
    case 8: /*a*/
        env->regs[reg->targno & 0x0f] = tmp;
        break;

    default:
        qemu_log("%s to reg %d of unsupported type %d\n",
1312
                 __func__, n, reg->type);
M
Max Filippov 已提交
1313 1314 1315 1316 1317
        return 0;
    }

    return 4;
}
P
pbrook 已提交
1318 1319
#else

1320
static int cpu_gdb_read_register(CPUArchState *env, uint8_t *mem_buf, int n)
1321
{
P
pbrook 已提交
1322
    return 0;
1323 1324
}

1325
static int cpu_gdb_write_register(CPUArchState *env, uint8_t *mem_buf, int n)
1326
{
P
pbrook 已提交
1327 1328
    return 0;
}
1329

P
pbrook 已提交
1330
#endif
1331

P
pbrook 已提交
1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352
#ifdef GDB_CORE_XML
/* Encode data using the encoding for 'x' packets.  */
static int memtox(char *buf, const char *mem, int len)
{
    char *p = buf;
    char c;

    while (len--) {
        c = *(mem++);
        switch (c) {
        case '#': case '$': case '*': case '}':
            *(p++) = '}';
            *(p++) = c ^ 0x20;
            break;
        default:
            *(p++) = c;
            break;
        }
    }
    return p - buf;
}
1353

A
aurel32 已提交
1354
static const char *get_feature_xml(const char *p, const char **newp)
P
pbrook 已提交
1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370
{
    size_t len;
    int i;
    const char *name;
    static char target_xml[1024];

    len = 0;
    while (p[len] && p[len] != ':')
        len++;
    *newp = p + len;

    name = NULL;
    if (strncmp(p, "target.xml", len) == 0) {
        /* Generate the XML description for this CPU.  */
        if (!target_xml[0]) {
            GDBRegisterState *r;
1371
            CPUState *cpu = first_cpu;
P
pbrook 已提交
1372

B
blueswir1 已提交
1373 1374 1375 1376 1377 1378
            snprintf(target_xml, sizeof(target_xml),
                     "<?xml version=\"1.0\"?>"
                     "<!DOCTYPE target SYSTEM \"gdb-target.dtd\">"
                     "<target>"
                     "<xi:include href=\"%s\"/>",
                     GDB_CORE_XML);
P
pbrook 已提交
1379

1380
            for (r = cpu->gdb_regs; r; r = r->next) {
1381 1382 1383
                pstrcat(target_xml, sizeof(target_xml), "<xi:include href=\"");
                pstrcat(target_xml, sizeof(target_xml), r->xml);
                pstrcat(target_xml, sizeof(target_xml), "\"/>");
P
pbrook 已提交
1384
            }
1385
            pstrcat(target_xml, sizeof(target_xml), "</target>");
P
pbrook 已提交
1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396
        }
        return target_xml;
    }
    for (i = 0; ; i++) {
        name = xml_builtin[i][0];
        if (!name || (strncmp(name, p, len) == 0 && strlen(name) == len))
            break;
    }
    return name ? xml_builtin[i][1] : NULL;
}
#endif
1397

1398
static int gdb_read_register(CPUState *cpu, uint8_t *mem_buf, int reg)
P
pbrook 已提交
1399
{
1400
    CPUClass *cc = CPU_GET_CLASS(cpu);
1401
    CPUArchState *env = cpu->env_ptr;
P
pbrook 已提交
1402
    GDBRegisterState *r;
1403

1404
    if (reg < cc->gdb_num_core_regs) {
P
pbrook 已提交
1405
        return cpu_gdb_read_register(env, mem_buf, reg);
1406
    }
1407

1408
    for (r = cpu->gdb_regs; r; r = r->next) {
P
pbrook 已提交
1409 1410 1411 1412 1413
        if (r->base_reg <= reg && reg < r->base_reg + r->num_regs) {
            return r->get_reg(env, mem_buf, reg - r->base_reg);
        }
    }
    return 0;
1414 1415
}

1416
static int gdb_write_register(CPUState *cpu, uint8_t *mem_buf, int reg)
1417
{
1418
    CPUClass *cc = CPU_GET_CLASS(cpu);
1419
    CPUArchState *env = cpu->env_ptr;
P
pbrook 已提交
1420
    GDBRegisterState *r;
1421

1422
    if (reg < cc->gdb_num_core_regs) {
P
pbrook 已提交
1423
        return cpu_gdb_write_register(env, mem_buf, reg);
1424
    }
P
pbrook 已提交
1425

1426
    for (r = cpu->gdb_regs; r; r = r->next) {
P
pbrook 已提交
1427 1428 1429 1430
        if (r->base_reg <= reg && reg < r->base_reg + r->num_regs) {
            return r->set_reg(env, mem_buf, reg - r->base_reg);
        }
    }
B
bellard 已提交
1431 1432 1433
    return 0;
}

P
pbrook 已提交
1434 1435 1436 1437 1438 1439
/* Register a supplemental set of CPU registers.  If g_pos is nonzero it
   specifies the first register number and these registers are included in
   a standard "g" packet.  Direction is relative to gdb, i.e. get_reg is
   gdb reading a CPU register, and set_reg is gdb modifying a CPU register.
 */

1440 1441 1442
void gdb_register_coprocessor(CPUState *cpu,
                              gdb_reg_cb get_reg, gdb_reg_cb set_reg,
                              int num_regs, const char *xml, int g_pos)
B
bellard 已提交
1443
{
P
pbrook 已提交
1444 1445 1446
    GDBRegisterState *s;
    GDBRegisterState **p;

1447
    p = &cpu->gdb_regs;
P
pbrook 已提交
1448 1449 1450 1451 1452 1453
    while (*p) {
        /* Check for duplicates.  */
        if (strcmp((*p)->xml, xml) == 0)
            return;
        p = &(*p)->next;
    }
S
Stefan Weil 已提交
1454 1455

    s = g_new0(GDBRegisterState, 1);
1456
    s->base_reg = cpu->gdb_num_regs;
S
Stefan Weil 已提交
1457 1458 1459 1460 1461
    s->num_regs = num_regs;
    s->get_reg = get_reg;
    s->set_reg = set_reg;
    s->xml = xml;

P
pbrook 已提交
1462
    /* Add to end of list.  */
1463
    cpu->gdb_num_regs += num_regs;
P
pbrook 已提交
1464 1465 1466 1467 1468 1469 1470
    *p = s;
    if (g_pos) {
        if (g_pos != s->base_reg) {
            fprintf(stderr, "Error: Bad gdb register numbering for '%s'\n"
                    "Expected %d got %d\n", xml, g_pos, s->base_reg);
        }
    }
B
bellard 已提交
1471 1472
}

1473 1474 1475 1476 1477 1478 1479 1480
#ifndef CONFIG_USER_ONLY
static const int xlat_gdb_type[] = {
    [GDB_WATCHPOINT_WRITE]  = BP_GDB | BP_MEM_WRITE,
    [GDB_WATCHPOINT_READ]   = BP_GDB | BP_MEM_READ,
    [GDB_WATCHPOINT_ACCESS] = BP_GDB | BP_MEM_ACCESS,
};
#endif

1481
static int gdb_breakpoint_insert(target_ulong addr, target_ulong len, int type)
1482
{
1483
    CPUState *cpu;
1484
    CPUArchState *env;
1485 1486
    int err = 0;

1487
    if (kvm_enabled()) {
1488
        return kvm_insert_breakpoint(gdbserver_state->c_cpu, addr, len, type);
1489
    }
1490

1491 1492 1493
    switch (type) {
    case GDB_BREAKPOINT_SW:
    case GDB_BREAKPOINT_HW:
1494 1495
        for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
            env = cpu->env_ptr;
1496 1497 1498 1499 1500
            err = cpu_breakpoint_insert(env, addr, BP_GDB, NULL);
            if (err)
                break;
        }
        return err;
1501 1502 1503 1504
#ifndef CONFIG_USER_ONLY
    case GDB_WATCHPOINT_WRITE:
    case GDB_WATCHPOINT_READ:
    case GDB_WATCHPOINT_ACCESS:
1505 1506
        for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
            env = cpu->env_ptr;
1507 1508 1509 1510 1511 1512
            err = cpu_watchpoint_insert(env, addr, len, xlat_gdb_type[type],
                                        NULL);
            if (err)
                break;
        }
        return err;
1513 1514 1515 1516 1517 1518
#endif
    default:
        return -ENOSYS;
    }
}

1519
static int gdb_breakpoint_remove(target_ulong addr, target_ulong len, int type)
1520
{
1521
    CPUState *cpu;
1522
    CPUArchState *env;
1523 1524
    int err = 0;

1525
    if (kvm_enabled()) {
1526
        return kvm_remove_breakpoint(gdbserver_state->c_cpu, addr, len, type);
1527
    }
1528

1529 1530 1531
    switch (type) {
    case GDB_BREAKPOINT_SW:
    case GDB_BREAKPOINT_HW:
1532 1533
        for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
            env = cpu->env_ptr;
1534 1535 1536 1537 1538
            err = cpu_breakpoint_remove(env, addr, BP_GDB);
            if (err)
                break;
        }
        return err;
1539 1540 1541 1542
#ifndef CONFIG_USER_ONLY
    case GDB_WATCHPOINT_WRITE:
    case GDB_WATCHPOINT_READ:
    case GDB_WATCHPOINT_ACCESS:
1543 1544
        for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
            env = cpu->env_ptr;
1545 1546 1547 1548 1549
            err = cpu_watchpoint_remove(env, addr, len, xlat_gdb_type[type]);
            if (err)
                break;
        }
        return err;
1550 1551 1552 1553 1554 1555
#endif
    default:
        return -ENOSYS;
    }
}

1556
static void gdb_breakpoint_remove_all(void)
1557
{
1558
    CPUState *cpu;
1559
    CPUArchState *env;
1560

1561
    if (kvm_enabled()) {
1562
        kvm_remove_all_breakpoints(gdbserver_state->c_cpu);
1563 1564 1565
        return;
    }

1566 1567
    for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
        env = cpu->env_ptr;
1568
        cpu_breakpoint_remove_all(env, BP_GDB);
1569
#ifndef CONFIG_USER_ONLY
1570
        cpu_watchpoint_remove_all(env, BP_GDB);
1571
#endif
1572
    }
1573 1574
}

A
aurel32 已提交
1575 1576
static void gdb_set_cpu_pc(GDBState *s, target_ulong pc)
{
1577
    CPUState *cpu = s->c_cpu;
1578 1579 1580 1581 1582
    CPUClass *cc = CPU_GET_CLASS(cpu);

    cpu_synchronize_state(cpu);
    if (cc->set_pc) {
        cc->set_pc(cpu, pc);
N
Nathan Froyd 已提交
1583
    }
A
aurel32 已提交
1584 1585
}

1586
static CPUState *find_cpu(uint32_t thread_id)
1587
{
1588
    CPUState *cpu;
1589

1590
    for (cpu = first_cpu; cpu != NULL; cpu = cpu->next_cpu) {
1591
        if (cpu_index(cpu) == thread_id) {
1592
            return cpu;
1593
        }
1594
    }
1595 1596

    return NULL;
1597 1598
}

1599
static int gdb_handle_packet(GDBState *s, const char *line_buf)
B
bellard 已提交
1600
{
1601
    CPUState *cpu;
B
bellard 已提交
1602
    const char *p;
1603 1604
    uint32_t thread;
    int ch, reg_size, type, res;
P
pbrook 已提交
1605 1606 1607
    char buf[MAX_PACKET_LENGTH];
    uint8_t mem_buf[MAX_PACKET_LENGTH];
    uint8_t *registers;
1608
    target_ulong addr, len;
1609

1610 1611 1612 1613 1614 1615 1616
#ifdef DEBUG_GDB
    printf("command='%s'\n", line_buf);
#endif
    p = line_buf;
    ch = *p++;
    switch(ch) {
    case '?':
B
bellard 已提交
1617
        /* TODO: Make this return the correct value for user-mode.  */
1618
        snprintf(buf, sizeof(buf), "T%02xthread:%02x;", GDB_SIGNAL_TRAP,
1619
                 cpu_index(s->c_cpu));
1620
        put_packet(s, buf);
1621 1622 1623 1624
        /* Remove all the breakpoints when this query is issued,
         * because gdb is doing and initial connect and the state
         * should be cleaned up.
         */
1625
        gdb_breakpoint_remove_all();
1626 1627 1628
        break;
    case 'c':
        if (*p != '\0') {
1629
            addr = strtoull(p, (char **)&p, 16);
A
aurel32 已提交
1630
            gdb_set_cpu_pc(s, addr);
1631
        }
1632
        s->signal = 0;
1633
        gdb_continue(s);
B
bellard 已提交
1634
	return RS_IDLE;
1635
    case 'C':
1636 1637 1638
        s->signal = gdb_signal_to_target (strtoul(p, (char **)&p, 16));
        if (s->signal == -1)
            s->signal = 0;
1639 1640
        gdb_continue(s);
        return RS_IDLE;
J
Jan Kiszka 已提交
1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680
    case 'v':
        if (strncmp(p, "Cont", 4) == 0) {
            int res_signal, res_thread;

            p += 4;
            if (*p == '?') {
                put_packet(s, "vCont;c;C;s;S");
                break;
            }
            res = 0;
            res_signal = 0;
            res_thread = 0;
            while (*p) {
                int action, signal;

                if (*p++ != ';') {
                    res = 0;
                    break;
                }
                action = *p++;
                signal = 0;
                if (action == 'C' || action == 'S') {
                    signal = strtoul(p, (char **)&p, 16);
                } else if (action != 'c' && action != 's') {
                    res = 0;
                    break;
                }
                thread = 0;
                if (*p == ':') {
                    thread = strtoull(p+1, (char **)&p, 16);
                }
                action = tolower(action);
                if (res == 0 || (res == 'c' && action == 's')) {
                    res = action;
                    res_signal = signal;
                    res_thread = thread;
                }
            }
            if (res) {
                if (res_thread != -1 && res_thread != 0) {
1681 1682
                    cpu = find_cpu(res_thread);
                    if (cpu == NULL) {
J
Jan Kiszka 已提交
1683 1684 1685
                        put_packet(s, "E22");
                        break;
                    }
1686
                    s->c_cpu = cpu;
J
Jan Kiszka 已提交
1687 1688
                }
                if (res == 's') {
1689
                    cpu_single_step(s->c_cpu, sstep_flags);
J
Jan Kiszka 已提交
1690 1691 1692 1693 1694 1695 1696 1697 1698
                }
                s->signal = res_signal;
                gdb_continue(s);
                return RS_IDLE;
            }
            break;
        } else {
            goto unknown_command;
        }
1699
    case 'k':
1700
#ifdef CONFIG_USER_ONLY
1701 1702 1703
        /* Kill the target */
        fprintf(stderr, "\nQEMU: Terminated via GDBstub\n");
        exit(0);
1704
#endif
1705 1706
    case 'D':
        /* Detach packet */
1707
        gdb_breakpoint_remove_all();
D
Daniel Gutson 已提交
1708
        gdb_syscall_mode = GDB_SYS_DISABLED;
1709 1710 1711
        gdb_continue(s);
        put_packet(s, "OK");
        break;
1712 1713
    case 's':
        if (*p != '\0') {
1714
            addr = strtoull(p, (char **)&p, 16);
A
aurel32 已提交
1715
            gdb_set_cpu_pc(s, addr);
1716
        }
1717
        cpu_single_step(s->c_cpu, sstep_flags);
1718
        gdb_continue(s);
B
bellard 已提交
1719
	return RS_IDLE;
P
pbrook 已提交
1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734
    case 'F':
        {
            target_ulong ret;
            target_ulong err;

            ret = strtoull(p, (char **)&p, 16);
            if (*p == ',') {
                p++;
                err = strtoull(p, (char **)&p, 16);
            } else {
                err = 0;
            }
            if (*p == ',')
                p++;
            type = *p;
1735
            if (s->current_syscall_cb) {
1736
                s->current_syscall_cb(s->c_cpu, ret, err);
1737 1738
                s->current_syscall_cb = NULL;
            }
P
pbrook 已提交
1739 1740 1741
            if (type == 'C') {
                put_packet(s, "T02");
            } else {
1742
                gdb_continue(s);
P
pbrook 已提交
1743 1744 1745
            }
        }
        break;
1746
    case 'g':
1747
        cpu_synchronize_state(s->g_cpu);
P
pbrook 已提交
1748
        len = 0;
1749
        for (addr = 0; addr < s->g_cpu->gdb_num_regs; addr++) {
1750
            reg_size = gdb_read_register(s->g_cpu, mem_buf + len, addr);
P
pbrook 已提交
1751 1752 1753
            len += reg_size;
        }
        memtohex(buf, mem_buf, len);
1754 1755 1756
        put_packet(s, buf);
        break;
    case 'G':
1757
        cpu_synchronize_state(s->g_cpu);
P
pbrook 已提交
1758
        registers = mem_buf;
1759 1760
        len = strlen(p) / 2;
        hextomem((uint8_t *)registers, p, len);
1761
        for (addr = 0; addr < s->g_cpu->gdb_num_regs && len > 0; addr++) {
1762
            reg_size = gdb_write_register(s->g_cpu, registers, addr);
P
pbrook 已提交
1763 1764 1765
            len -= reg_size;
            registers += reg_size;
        }
1766 1767 1768
        put_packet(s, "OK");
        break;
    case 'm':
1769
        addr = strtoull(p, (char **)&p, 16);
1770 1771
        if (*p == ',')
            p++;
1772
        len = strtoull(p, NULL, 16);
1773
        if (target_memory_rw_debug(s->g_cpu, addr, mem_buf, len, false) != 0) {
1774 1775 1776 1777 1778
            put_packet (s, "E14");
        } else {
            memtohex(buf, mem_buf, len);
            put_packet(s, buf);
        }
1779 1780
        break;
    case 'M':
1781
        addr = strtoull(p, (char **)&p, 16);
1782 1783
        if (*p == ',')
            p++;
1784
        len = strtoull(p, (char **)&p, 16);
1785
        if (*p == ':')
1786 1787
            p++;
        hextomem(mem_buf, p, len);
1788
        if (target_memory_rw_debug(s->g_cpu, addr, mem_buf, len,
1789
                                   true) != 0) {
B
bellard 已提交
1790
            put_packet(s, "E14");
1791
        } else {
1792
            put_packet(s, "OK");
1793
        }
1794
        break;
P
pbrook 已提交
1795 1796 1797 1798 1799 1800 1801
    case 'p':
        /* Older gdb are really dumb, and don't use 'g' if 'p' is avaialable.
           This works, but can be very slow.  Anything new enough to
           understand XML also knows how to use this properly.  */
        if (!gdb_has_xml)
            goto unknown_command;
        addr = strtoull(p, (char **)&p, 16);
1802
        reg_size = gdb_read_register(s->g_cpu, mem_buf, addr);
P
pbrook 已提交
1803 1804 1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817
        if (reg_size) {
            memtohex(buf, mem_buf, reg_size);
            put_packet(s, buf);
        } else {
            put_packet(s, "E14");
        }
        break;
    case 'P':
        if (!gdb_has_xml)
            goto unknown_command;
        addr = strtoull(p, (char **)&p, 16);
        if (*p == '=')
            p++;
        reg_size = strlen(p) / 2;
        hextomem(mem_buf, p, reg_size);
1818
        gdb_write_register(s->g_cpu, mem_buf, addr);
P
pbrook 已提交
1819 1820
        put_packet(s, "OK");
        break;
1821 1822 1823 1824 1825
    case 'Z':
    case 'z':
        type = strtoul(p, (char **)&p, 16);
        if (*p == ',')
            p++;
1826
        addr = strtoull(p, (char **)&p, 16);
1827 1828
        if (*p == ',')
            p++;
1829
        len = strtoull(p, (char **)&p, 16);
1830
        if (ch == 'Z')
1831
            res = gdb_breakpoint_insert(addr, len, type);
1832
        else
1833
            res = gdb_breakpoint_remove(addr, len, type);
1834 1835 1836
        if (res >= 0)
             put_packet(s, "OK");
        else if (res == -ENOSYS)
P
pbrook 已提交
1837
            put_packet(s, "");
1838 1839
        else
            put_packet(s, "E22");
1840
        break;
1841 1842 1843 1844 1845 1846 1847
    case 'H':
        type = *p++;
        thread = strtoull(p, (char **)&p, 16);
        if (thread == -1 || thread == 0) {
            put_packet(s, "OK");
            break;
        }
1848 1849
        cpu = find_cpu(thread);
        if (cpu == NULL) {
1850 1851 1852 1853 1854
            put_packet(s, "E22");
            break;
        }
        switch (type) {
        case 'c':
1855
            s->c_cpu = cpu;
1856 1857 1858
            put_packet(s, "OK");
            break;
        case 'g':
1859
            s->g_cpu = cpu;
1860 1861 1862 1863 1864 1865 1866 1867 1868
            put_packet(s, "OK");
            break;
        default:
             put_packet(s, "E22");
             break;
        }
        break;
    case 'T':
        thread = strtoull(p, (char **)&p, 16);
1869
        cpu = find_cpu(thread);
1870

1871
        if (cpu != NULL) {
1872 1873
            put_packet(s, "OK");
        } else {
1874
            put_packet(s, "E22");
1875
        }
1876
        break;
1877
    case 'q':
1878 1879 1880 1881
    case 'Q':
        /* parse any 'q' packets here */
        if (!strcmp(p,"qemu.sstepbits")) {
            /* Query Breakpoint bit definitions */
B
blueswir1 已提交
1882 1883 1884 1885
            snprintf(buf, sizeof(buf), "ENABLE=%x,NOIRQ=%x,NOTIMER=%x",
                     SSTEP_ENABLE,
                     SSTEP_NOIRQ,
                     SSTEP_NOTIMER);
1886 1887 1888 1889 1890 1891 1892
            put_packet(s, buf);
            break;
        } else if (strncmp(p,"qemu.sstep",10) == 0) {
            /* Display or change the sstep_flags */
            p += 10;
            if (*p != '=') {
                /* Display current setting */
B
blueswir1 已提交
1893
                snprintf(buf, sizeof(buf), "0x%x", sstep_flags);
1894 1895 1896 1897 1898 1899 1900 1901
                put_packet(s, buf);
                break;
            }
            p++;
            type = strtoul(p, (char **)&p, 16);
            sstep_flags = type;
            put_packet(s, "OK");
            break;
1902 1903 1904 1905 1906 1907
        } else if (strcmp(p,"C") == 0) {
            /* "Current thread" remains vague in the spec, so always return
             *  the first CPU (gdb returns the first thread). */
            put_packet(s, "QC1");
            break;
        } else if (strcmp(p,"fThreadInfo") == 0) {
1908
            s->query_cpu = first_cpu;
1909 1910 1911 1912
            goto report_cpuinfo;
        } else if (strcmp(p,"sThreadInfo") == 0) {
        report_cpuinfo:
            if (s->query_cpu) {
1913
                snprintf(buf, sizeof(buf), "m%x", cpu_index(s->query_cpu));
1914
                put_packet(s, buf);
1915
                s->query_cpu = s->query_cpu->next_cpu;
1916 1917 1918 1919 1920
            } else
                put_packet(s, "l");
            break;
        } else if (strncmp(p,"ThreadExtraInfo,", 16) == 0) {
            thread = strtoull(p+16, (char **)&p, 16);
1921 1922
            cpu = find_cpu(thread);
            if (cpu != NULL) {
1923
                cpu_synchronize_state(cpu);
1924
                len = snprintf((char *)mem_buf, sizeof(mem_buf),
1925
                               "CPU#%d [%s]", cpu->cpu_index,
1926
                               cpu->halted ? "halted " : "running");
1927 1928 1929
                memtohex(buf, mem_buf, len);
                put_packet(s, buf);
            }
1930
            break;
1931
        }
B
blueswir1 已提交
1932
#ifdef CONFIG_USER_ONLY
1933
        else if (strncmp(p, "Offsets", 7) == 0) {
1934 1935
            CPUArchState *env = s->c_cpu->env_ptr;
            TaskState *ts = env->opaque;
1936

B
blueswir1 已提交
1937 1938 1939 1940 1941 1942
            snprintf(buf, sizeof(buf),
                     "Text=" TARGET_ABI_FMT_lx ";Data=" TARGET_ABI_FMT_lx
                     ";Bss=" TARGET_ABI_FMT_lx,
                     ts->info->code_offset,
                     ts->info->data_offset,
                     ts->info->data_offset);
1943 1944 1945
            put_packet(s, buf);
            break;
        }
B
blueswir1 已提交
1946
#else /* !CONFIG_USER_ONLY */
1947 1948 1949 1950 1951 1952 1953 1954 1955 1956
        else if (strncmp(p, "Rcmd,", 5) == 0) {
            int len = strlen(p + 5);

            if ((len % 2) != 0) {
                put_packet(s, "E01");
                break;
            }
            hextomem(mem_buf, p + 5, len);
            len = len / 2;
            mem_buf[len++] = 0;
1957
            qemu_chr_be_write(s->mon_chr, mem_buf, len);
1958 1959 1960
            put_packet(s, "OK");
            break;
        }
B
blueswir1 已提交
1961
#endif /* !CONFIG_USER_ONLY */
P
pbrook 已提交
1962
        if (strncmp(p, "Supported", 9) == 0) {
B
blueswir1 已提交
1963
            snprintf(buf, sizeof(buf), "PacketSize=%x", MAX_PACKET_LENGTH);
P
pbrook 已提交
1964
#ifdef GDB_CORE_XML
1965
            pstrcat(buf, sizeof(buf), ";qXfer:features:read+");
P
pbrook 已提交
1966 1967 1968 1969 1970 1971 1972 1973 1974 1975 1976
#endif
            put_packet(s, buf);
            break;
        }
#ifdef GDB_CORE_XML
        if (strncmp(p, "Xfer:features:read:", 19) == 0) {
            const char *xml;
            target_ulong total_len;

            gdb_has_xml = 1;
            p += 19;
1977
            xml = get_feature_xml(p, &p);
P
pbrook 已提交
1978
            if (!xml) {
B
blueswir1 已提交
1979
                snprintf(buf, sizeof(buf), "E00");
P
pbrook 已提交
1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 1991 1992
                put_packet(s, buf);
                break;
            }

            if (*p == ':')
                p++;
            addr = strtoul(p, (char **)&p, 16);
            if (*p == ',')
                p++;
            len = strtoul(p, (char **)&p, 16);

            total_len = strlen(xml);
            if (addr > total_len) {
B
blueswir1 已提交
1993
                snprintf(buf, sizeof(buf), "E00");
P
pbrook 已提交
1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012
                put_packet(s, buf);
                break;
            }
            if (len > (MAX_PACKET_LENGTH - 5) / 2)
                len = (MAX_PACKET_LENGTH - 5) / 2;
            if (len < total_len - addr) {
                buf[0] = 'm';
                len = memtox(buf + 1, xml + addr, len);
            } else {
                buf[0] = 'l';
                len = memtox(buf + 1, xml + addr, total_len - addr);
            }
            put_packet_binary(s, buf, len + 1);
            break;
        }
#endif
        /* Unrecognised 'q' command.  */
        goto unknown_command;

2013
    default:
P
pbrook 已提交
2014
    unknown_command:
2015 2016 2017 2018 2019 2020 2021 2022
        /* put empty packet */
        buf[0] = '\0';
        put_packet(s, buf);
        break;
    }
    return RS_IDLE;
}

2023
void gdb_set_stop_cpu(CPUState *cpu)
2024
{
2025 2026
    gdbserver_state->c_cpu = cpu;
    gdbserver_state->g_cpu = cpu;
2027 2028
}

B
bellard 已提交
2029
#ifndef CONFIG_USER_ONLY
2030
static void gdb_vm_state_change(void *opaque, int running, RunState state)
2031
{
2032
    GDBState *s = gdbserver_state;
2033 2034
    CPUArchState *env = s->c_cpu->env_ptr;
    CPUState *cpu = s->c_cpu;
2035
    char buf[256];
2036
    const char *type;
2037 2038
    int ret;

2039 2040 2041 2042 2043 2044
    if (running || s->state == RS_INACTIVE) {
        return;
    }
    /* Is there a GDB syscall waiting to be sent?  */
    if (s->current_syscall_cb) {
        put_packet(s, s->syscall_buf);
P
pbrook 已提交
2045
        return;
J
Jan Kiszka 已提交
2046
    }
2047
    switch (state) {
2048
    case RUN_STATE_DEBUG:
2049 2050
        if (env->watchpoint_hit) {
            switch (env->watchpoint_hit->flags & BP_MEM_ACCESS) {
2051
            case BP_MEM_READ:
2052 2053
                type = "r";
                break;
2054
            case BP_MEM_ACCESS:
2055 2056 2057 2058 2059 2060
                type = "a";
                break;
            default:
                type = "";
                break;
            }
2061 2062
            snprintf(buf, sizeof(buf),
                     "T%02xthread:%02x;%swatch:" TARGET_FMT_lx ";",
2063
                     GDB_SIGNAL_TRAP, cpu_index(cpu), type,
2064 2065
                     env->watchpoint_hit->vaddr);
            env->watchpoint_hit = NULL;
2066
            goto send_packet;
2067
        }
2068
        tb_flush(env);
2069
        ret = GDB_SIGNAL_TRAP;
2070
        break;
2071
    case RUN_STATE_PAUSED:
2072
        ret = GDB_SIGNAL_INT;
2073
        break;
2074
    case RUN_STATE_SHUTDOWN:
2075 2076
        ret = GDB_SIGNAL_QUIT;
        break;
2077
    case RUN_STATE_IO_ERROR:
2078 2079
        ret = GDB_SIGNAL_IO;
        break;
2080
    case RUN_STATE_WATCHDOG:
2081 2082
        ret = GDB_SIGNAL_ALRM;
        break;
2083
    case RUN_STATE_INTERNAL_ERROR:
2084 2085
        ret = GDB_SIGNAL_ABRT;
        break;
2086 2087
    case RUN_STATE_SAVE_VM:
    case RUN_STATE_RESTORE_VM:
2088
        return;
2089
    case RUN_STATE_FINISH_MIGRATE:
2090 2091 2092 2093 2094
        ret = GDB_SIGNAL_XCPU;
        break;
    default:
        ret = GDB_SIGNAL_UNKNOWN;
        break;
B
bellard 已提交
2095
    }
2096
    snprintf(buf, sizeof(buf), "T%02xthread:%02x;", ret, cpu_index(cpu));
2097 2098

send_packet:
2099
    put_packet(s, buf);
2100 2101

    /* disable single step if it was enabled */
2102
    cpu_single_step(cpu, 0);
2103
}
B
bellard 已提交
2104
#endif
2105

P
pbrook 已提交
2106 2107
/* Send a gdb syscall request.
   This accepts limited printf-style format specifiers, specifically:
P
pbrook 已提交
2108 2109 2110
    %x  - target_ulong argument printed in hex.
    %lx - 64-bit argument printed in hex.
    %s  - string pointer (target_ulong) and length (int) pair.  */
2111
void gdb_do_syscall(gdb_syscall_complete_cb cb, const char *fmt, ...)
P
pbrook 已提交
2112 2113 2114
{
    va_list va;
    char *p;
2115
    char *p_end;
P
pbrook 已提交
2116
    target_ulong addr;
P
pbrook 已提交
2117
    uint64_t i64;
P
pbrook 已提交
2118 2119
    GDBState *s;

2120
    s = gdbserver_state;
P
pbrook 已提交
2121 2122
    if (!s)
        return;
2123
    s->current_syscall_cb = cb;
P
pbrook 已提交
2124
#ifndef CONFIG_USER_ONLY
2125
    vm_stop(RUN_STATE_DEBUG);
P
pbrook 已提交
2126 2127
#endif
    va_start(va, fmt);
2128 2129
    p = s->syscall_buf;
    p_end = &s->syscall_buf[sizeof(s->syscall_buf)];
P
pbrook 已提交
2130 2131 2132 2133 2134 2135 2136
    *(p++) = 'F';
    while (*fmt) {
        if (*fmt == '%') {
            fmt++;
            switch (*fmt++) {
            case 'x':
                addr = va_arg(va, target_ulong);
2137
                p += snprintf(p, p_end - p, TARGET_FMT_lx, addr);
P
pbrook 已提交
2138
                break;
P
pbrook 已提交
2139 2140 2141 2142
            case 'l':
                if (*(fmt++) != 'x')
                    goto bad_format;
                i64 = va_arg(va, uint64_t);
2143
                p += snprintf(p, p_end - p, "%" PRIx64, i64);
P
pbrook 已提交
2144
                break;
P
pbrook 已提交
2145 2146
            case 's':
                addr = va_arg(va, target_ulong);
2147
                p += snprintf(p, p_end - p, TARGET_FMT_lx "/%x",
B
blueswir1 已提交
2148
                              addr, va_arg(va, int));
P
pbrook 已提交
2149 2150
                break;
            default:
P
pbrook 已提交
2151
            bad_format:
P
pbrook 已提交
2152 2153 2154 2155 2156 2157 2158 2159
                fprintf(stderr, "gdbstub: Bad syscall format string '%s'\n",
                        fmt - 1);
                break;
            }
        } else {
            *(p++) = *(fmt++);
        }
    }
P
pbrook 已提交
2160
    *p = 0;
P
pbrook 已提交
2161 2162
    va_end(va);
#ifdef CONFIG_USER_ONLY
2163
    put_packet(s, s->syscall_buf);
2164
    gdb_handlesig(s->c_cpu, 0);
P
pbrook 已提交
2165
#else
2166 2167 2168 2169 2170 2171
    /* In this case wait to send the syscall packet until notification that
       the CPU has stopped.  This must be done because if the packet is sent
       now the reply from the syscall request could be received while the CPU
       is still in the running state, which can cause packets to be dropped
       and state transition 'T' packets to be sent while the syscall is still
       being processed.  */
2172
    cpu_exit(s->c_cpu);
P
pbrook 已提交
2173 2174 2175
#endif
}

B
bellard 已提交
2176
static void gdb_read_byte(GDBState *s, int ch)
2177 2178
{
    int i, csum;
T
ths 已提交
2179
    uint8_t reply;
2180

B
bellard 已提交
2181
#ifndef CONFIG_USER_ONLY
2182 2183 2184 2185 2186 2187 2188
    if (s->last_packet_len) {
        /* Waiting for a response to the last packet.  If we see the start
           of a new command then abandon the previous response.  */
        if (ch == '-') {
#ifdef DEBUG_GDB
            printf("Got NACK, retransmitting\n");
#endif
T
ths 已提交
2189
            put_buffer(s, (uint8_t *)s->last_packet, s->last_packet_len);
2190 2191 2192 2193 2194 2195 2196 2197 2198 2199 2200 2201
        }
#ifdef DEBUG_GDB
        else if (ch == '+')
            printf("Got ACK\n");
        else
            printf("Got '%c' when expecting ACK/NACK\n", ch);
#endif
        if (ch == '+' || ch == '$')
            s->last_packet_len = 0;
        if (ch != '$')
            return;
    }
2202
    if (runstate_is_running()) {
2203 2204
        /* when the CPU is running, we cannot do anything except stop
           it when receiving a char */
2205
        vm_stop(RUN_STATE_PAUSED);
2206
    } else
B
bellard 已提交
2207
#endif
B
bellard 已提交
2208
    {
2209 2210 2211 2212 2213
        switch(s->state) {
        case RS_IDLE:
            if (ch == '$') {
                s->line_buf_index = 0;
                s->state = RS_GETLINE;
B
bellard 已提交
2214
            }
B
bellard 已提交
2215
            break;
2216 2217 2218 2219 2220
        case RS_GETLINE:
            if (ch == '#') {
            s->state = RS_CHKSUM1;
            } else if (s->line_buf_index >= sizeof(s->line_buf) - 1) {
                s->state = RS_IDLE;
B
bellard 已提交
2221
            } else {
2222
            s->line_buf[s->line_buf_index++] = ch;
B
bellard 已提交
2223 2224
            }
            break;
2225 2226 2227 2228 2229 2230 2231 2232 2233 2234 2235 2236
        case RS_CHKSUM1:
            s->line_buf[s->line_buf_index] = '\0';
            s->line_csum = fromhex(ch) << 4;
            s->state = RS_CHKSUM2;
            break;
        case RS_CHKSUM2:
            s->line_csum |= fromhex(ch);
            csum = 0;
            for(i = 0; i < s->line_buf_index; i++) {
                csum += s->line_buf[i];
            }
            if (s->line_csum != (csum & 0xff)) {
T
ths 已提交
2237 2238
                reply = '-';
                put_buffer(s, &reply, 1);
2239
                s->state = RS_IDLE;
B
bellard 已提交
2240
            } else {
T
ths 已提交
2241 2242
                reply = '+';
                put_buffer(s, &reply, 1);
2243
                s->state = gdb_handle_packet(s, s->line_buf);
B
bellard 已提交
2244 2245
            }
            break;
P
pbrook 已提交
2246 2247
        default:
            abort();
2248 2249 2250 2251
        }
    }
}

P
Paul Brook 已提交
2252
/* Tell the remote gdb that the process has exited.  */
2253
void gdb_exit(CPUArchState *env, int code)
P
Paul Brook 已提交
2254 2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269
{
  GDBState *s;
  char buf[4];

  s = gdbserver_state;
  if (!s) {
      return;
  }
#ifdef CONFIG_USER_ONLY
  if (gdbserver_fd < 0 || s->fd < 0) {
      return;
  }
#endif

  snprintf(buf, sizeof(buf), "W%02x", (uint8_t)code);
  put_packet(s, buf);
2270 2271 2272

#ifndef CONFIG_USER_ONLY
  if (s->chr) {
2273
      qemu_chr_delete(s->chr);
2274 2275
  }
#endif
P
Paul Brook 已提交
2276 2277
}

B
bellard 已提交
2278
#ifdef CONFIG_USER_ONLY
2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291
int
gdb_queuesig (void)
{
    GDBState *s;

    s = gdbserver_state;

    if (gdbserver_fd < 0 || s->fd < 0)
        return 0;
    else
        return 1;
}

B
bellard 已提交
2292
int
2293
gdb_handlesig(CPUState *cpu, int sig)
B
bellard 已提交
2294
{
2295
    CPUArchState *env = cpu->env_ptr;
2296 2297 2298
    GDBState *s;
    char buf[256];
    int n;
B
bellard 已提交
2299

2300 2301 2302 2303
    s = gdbserver_state;
    if (gdbserver_fd < 0 || s->fd < 0) {
        return sig;
    }
B
bellard 已提交
2304

2305
    /* disable single step if it was enabled */
2306
    cpu_single_step(cpu, 0);
2307
    tb_flush(env);
B
bellard 已提交
2308

2309 2310 2311 2312 2313 2314 2315 2316 2317
    if (sig != 0) {
        snprintf(buf, sizeof(buf), "S%02x", target_signal_to_gdb(sig));
        put_packet(s, buf);
    }
    /* put_packet() might have detected that the peer terminated the
       connection.  */
    if (s->fd < 0) {
        return sig;
    }
B
bellard 已提交
2318

2319 2320 2321 2322 2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333
    sig = 0;
    s->state = RS_IDLE;
    s->running_state = 0;
    while (s->running_state == 0) {
        n = read(s->fd, buf, 256);
        if (n > 0) {
            int i;

            for (i = 0; i < n; i++) {
                gdb_read_byte(s, buf[i]);
            }
        } else if (n == 0 || errno != EAGAIN) {
            /* XXX: Connection closed.  Should probably wait for another
               connection before continuing.  */
            return sig;
B
bellard 已提交
2334
        }
2335 2336 2337 2338
    }
    sig = s->signal;
    s->signal = 0;
    return sig;
B
bellard 已提交
2339
}
2340

2341
/* Tell the remote gdb that the process has exited due to SIG.  */
2342
void gdb_signalled(CPUArchState *env, int sig)
2343
{
2344 2345
    GDBState *s;
    char buf[4];
2346

2347 2348 2349 2350
    s = gdbserver_state;
    if (gdbserver_fd < 0 || s->fd < 0) {
        return;
    }
2351

2352 2353
    snprintf(buf, sizeof(buf), "X%02x", target_signal_to_gdb(sig));
    put_packet(s, buf);
2354
}
B
bellard 已提交
2355

2356
static void gdb_accept(void)
2357 2358 2359 2360
{
    GDBState *s;
    struct sockaddr_in sockaddr;
    socklen_t len;
2361
    int fd;
2362 2363 2364 2365 2366 2367 2368 2369

    for(;;) {
        len = sizeof(sockaddr);
        fd = accept(gdbserver_fd, (struct sockaddr *)&sockaddr, &len);
        if (fd < 0 && errno != EINTR) {
            perror("accept");
            return;
        } else if (fd >= 0) {
K
Kevin Wolf 已提交
2370 2371 2372
#ifndef _WIN32
            fcntl(fd, F_SETFD, FD_CLOEXEC);
#endif
B
bellard 已提交
2373 2374 2375
            break;
        }
    }
2376 2377

    /* set short latency */
2378
    socket_set_nodelay(fd);
2379

2380
    s = g_malloc0(sizeof(GDBState));
2381 2382
    s->c_cpu = first_cpu;
    s->g_cpu = first_cpu;
2383
    s->fd = fd;
P
pbrook 已提交
2384
    gdb_has_xml = 0;
2385

2386
    gdbserver_state = s;
P
pbrook 已提交
2387

2388 2389 2390 2391 2392 2393 2394 2395 2396 2397 2398 2399 2400
    fcntl(fd, F_SETFL, O_NONBLOCK);
}

static int gdbserver_open(int port)
{
    struct sockaddr_in sockaddr;
    int fd, val, ret;

    fd = socket(PF_INET, SOCK_STREAM, 0);
    if (fd < 0) {
        perror("socket");
        return -1;
    }
K
Kevin Wolf 已提交
2401 2402 2403
#ifndef _WIN32
    fcntl(fd, F_SETFD, FD_CLOEXEC);
#endif
2404 2405 2406

    /* allow fast reuse */
    val = 1;
2407
    qemu_setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, &val, sizeof(val));
2408 2409 2410 2411 2412 2413 2414

    sockaddr.sin_family = AF_INET;
    sockaddr.sin_port = htons(port);
    sockaddr.sin_addr.s_addr = 0;
    ret = bind(fd, (struct sockaddr *)&sockaddr, sizeof(sockaddr));
    if (ret < 0) {
        perror("bind");
2415
        close(fd);
2416 2417 2418 2419 2420
        return -1;
    }
    ret = listen(fd, 0);
    if (ret < 0) {
        perror("listen");
2421
        close(fd);
2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432
        return -1;
    }
    return fd;
}

int gdbserver_start(int port)
{
    gdbserver_fd = gdbserver_open(port);
    if (gdbserver_fd < 0)
        return -1;
    /* accept connections */
2433
    gdb_accept();
2434 2435
    return 0;
}
2436 2437

/* Disable gdb stub for child processes.  */
2438
void gdbserver_fork(CPUArchState *env)
2439 2440
{
    GDBState *s = gdbserver_state;
E
edgar_igl 已提交
2441
    if (gdbserver_fd < 0 || s->fd < 0)
2442 2443 2444 2445 2446 2447
      return;
    close(s->fd);
    s->fd = -1;
    cpu_breakpoint_remove_all(env, BP_GDB);
    cpu_watchpoint_remove_all(env, BP_GDB);
}
B
bellard 已提交
2448
#else
T
ths 已提交
2449
static int gdb_chr_can_receive(void *opaque)
2450
{
P
pbrook 已提交
2451 2452 2453
  /* We can handle an arbitrarily large amount of data.
   Pick the maximum packet size, which is as good as anything.  */
  return MAX_PACKET_LENGTH;
2454 2455
}

T
ths 已提交
2456
static void gdb_chr_receive(void *opaque, const uint8_t *buf, int size)
2457 2458 2459 2460
{
    int i;

    for (i = 0; i < size; i++) {
2461
        gdb_read_byte(gdbserver_state, buf[i]);
2462 2463 2464 2465 2466 2467
    }
}

static void gdb_chr_event(void *opaque, int event)
{
    switch (event) {
2468
    case CHR_EVENT_OPENED:
2469
        vm_stop(RUN_STATE_PAUSED);
P
pbrook 已提交
2470
        gdb_has_xml = 0;
2471 2472 2473 2474 2475 2476
        break;
    default:
        break;
    }
}

2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487 2488 2489 2490 2491 2492 2493 2494 2495 2496 2497 2498 2499 2500 2501 2502 2503 2504 2505
static void gdb_monitor_output(GDBState *s, const char *msg, int len)
{
    char buf[MAX_PACKET_LENGTH];

    buf[0] = 'O';
    if (len > (MAX_PACKET_LENGTH/2) - 1)
        len = (MAX_PACKET_LENGTH/2) - 1;
    memtohex(buf + 1, (uint8_t *)msg, len);
    put_packet(s, buf);
}

static int gdb_monitor_write(CharDriverState *chr, const uint8_t *buf, int len)
{
    const char *p = (const char *)buf;
    int max_sz;

    max_sz = (sizeof(gdbserver_state->last_packet) - 2) / 2;
    for (;;) {
        if (len <= max_sz) {
            gdb_monitor_output(gdbserver_state, p, len);
            break;
        }
        gdb_monitor_output(gdbserver_state, p, max_sz);
        p += max_sz;
        len -= max_sz;
    }
    return len;
}

2506 2507 2508
#ifndef _WIN32
static void gdb_sigterm_handler(int signal)
{
2509
    if (runstate_is_running()) {
2510
        vm_stop(RUN_STATE_PAUSED);
J
Jan Kiszka 已提交
2511
    }
2512 2513 2514 2515
}
#endif

int gdbserver_start(const char *device)
2516 2517
{
    GDBState *s;
2518
    char gdbstub_device_name[128];
2519 2520
    CharDriverState *chr = NULL;
    CharDriverState *mon_chr;
2521

2522 2523 2524 2525 2526 2527 2528 2529
    if (!device)
        return -1;
    if (strcmp(device, "none") != 0) {
        if (strstart(device, "tcp:", NULL)) {
            /* enforce required TCP attributes */
            snprintf(gdbstub_device_name, sizeof(gdbstub_device_name),
                     "%s,nowait,nodelay,server", device);
            device = gdbstub_device_name;
2530
        }
2531 2532 2533
#ifndef _WIN32
        else if (strcmp(device, "stdio") == 0) {
            struct sigaction act;
2534

2535 2536 2537 2538 2539
            memset(&act, 0, sizeof(act));
            act.sa_handler = gdb_sigterm_handler;
            sigaction(SIGINT, &act, NULL);
        }
#endif
2540
        chr = qemu_chr_new("gdb", device, NULL);
2541 2542 2543
        if (!chr)
            return -1;

2544
        qemu_chr_fe_claim_no_fail(chr);
2545 2546
        qemu_chr_add_handlers(chr, gdb_chr_can_receive, gdb_chr_receive,
                              gdb_chr_event, NULL);
2547 2548
    }

2549 2550
    s = gdbserver_state;
    if (!s) {
2551
        s = g_malloc0(sizeof(GDBState));
2552
        gdbserver_state = s;
2553

2554 2555 2556
        qemu_add_vm_change_state_handler(gdb_vm_state_change, NULL);

        /* Initialize a monitor terminal for gdb */
2557
        mon_chr = g_malloc0(sizeof(*mon_chr));
2558 2559 2560 2561
        mon_chr->chr_write = gdb_monitor_write;
        monitor_init(mon_chr, 0);
    } else {
        if (s->chr)
2562
            qemu_chr_delete(s->chr);
2563 2564 2565
        mon_chr = s->mon_chr;
        memset(s, 0, sizeof(GDBState));
    }
2566 2567
    s->c_cpu = first_cpu;
    s->g_cpu = first_cpu;
2568
    s->chr = chr;
2569 2570
    s->state = chr ? RS_IDLE : RS_INACTIVE;
    s->mon_chr = mon_chr;
2571
    s->current_syscall_cb = NULL;
2572

B
bellard 已提交
2573 2574
    return 0;
}
2575
#endif