GDB Rocks!
GDB
The GNU Project
Kent Chen Debugger
Kent Chen (chenkaie)
chenkaie@[Link]
[Link]
@chenkaie on GitHub
@chenkaie on SlideShare
@chenkaie on LinkedIn
@chenkaie on Twitter
為什麼要學
GDB
Why everybody learns GDB?
非互動式/交談式
Non-Interactive
Debugging
strace - system call, signal
ltrace - library call
printf / printk
“打印”久了
也挺煩人的
Debugging by Endless Printing
GDB
Source-Level
Debugger
互動式/交談式
你叫它幹麻它就幹麻
Interactive Debugging
有了Debugger
Coding是彩色的
- by Jserv/宅色夫大大
No Debugger, No Happy Coding
學會了GDB
我有種山頂洞人
學會用火的感動
- by 張至
張至是誰?! 我也不認識, Google到的,某某鄉民吧!
GDB
Front Ends
gdbtui
cgdb
ddd (Joe’s Fav)
insight
clewn / vim + gdb
pyclewn
gdbmgr
分享小弟
入門經驗
Sharing my real-world GDB experience
牛刀小試
幼幼班
GDB Beginner’s training
Change memory contents on-the-fly
Change memory contents on-the-fly
stack backtrace
Attach to a process
Jump $pc (program counter)
core dump
core dump (cont.)
core dump (cont.)
Patch binary file
Patch binary file (cont.)
$objdump -d -S -l -shrt [Link] Change “ef01” to “ef00”
奇技淫巧
進階班
Advanced GDB Tricks
奇技淫巧:
奇異而眩人耳目の
技能或事物
(from 教育部國語辭典)
SIGSEGV + GDB
C interpreter
1. $ gdb `which gdb`
2. (gdb) start
3. Enjoy your world…
• Example:
(gdb) p 1 + 2 + abs(-‐3)
(gdb) p strcmp("VIVOTEK", "AXIS")
(gdb) x/s getenv(“HOME”)
(gdb) p (char*)getenv("HOME")
(gdb) p (char)*getenv("HOME")
(gdb) p printf("%d\n", 12345678)
Signal Handler
Terminal hang / Reboot PC
You have to close terminal (e.g., PuTTY, iTerm,...)
Conventional solution
(gdb) handle SIGHUP
GNU Screen / Tmux Signal Stop Print Pass to program Description
SIGHUP Yes Yes Yes Hangup
(gdb) handle SIGHUP nopass
Signal Stop Print Pass to program Description
nohup SIGHUP Yes Yes No Hangup
Program received signal SIGHUP, Hangup.
GDB solution 0x0000003ac7a954e0 in __nanosleep_nocancel () from /lib64/[Link].6
(gdb)
Continuing.
$ gdb [program] [pid]
(gdb) handle SIGHUP nopass
(gdb) continue
經典案例
實戰探討
A real-world case study
案例一、
Case 1
GNU C Library
(glibc)
debugging / 除錯
Why?
追求
卓越
Pursuit of excellence :)
DieLink
呆吝蚵
江湖中
流傳已久
A well-know issue
某某
Daemon
之死
Process crash issue
dmesg
cat /proc/`pidof configer`/maps
SIGSEGV
@[Link]
WTF!!
不會吧(驚)
ㄎㄎ
我有學過
Core dump
無敵の gdb core dump
backtrace (bt)
_IO_strn_overflow ()
vfprintf ()
C language !?
WTF!!
不會吧(驚驚)
欲窮千里目
更上一層樓
ㄎㄎ我有學過
gdb frame UP
frame [index] / up / down
WTF!!
ARM assembly
組合語言
什麼鬼呀
大學修完課後就通通還給老師了
C Code & ARM assembly
看似
專業 Pro
Looks “GEEK”
In fact
實際上
發現 gcc -O3
TMD
實在太難看了
It’s god damn hard to read after gcc -O3
我們需要
Source Level
Debugging
Use the
Source
Loser... Orz
May
The Source
Be With
You
How?
RTFM
Read The
Fucking Manual
load by symbol-file cmd
Re-build
debug version
shared library
with "-g"
set solib-absolute-prefix
Source be with You
發現傳入
snprintf()
の資料都正確
OMFG!
電梯繼續向下
gdb frame down
到了
/lib/[Link].6
-> [Link]
Shit!
若仿照
上面作法
難不成要自己
build debug
版のlibc-2.5.90
Oh No !
使用大廠の
偷偷Solution
你有權利
Say NO
MontaVista
已經幫我們
Build 好了
lib*.*.so.*.debug
glibc source level debug
DEMO
Null pointer access issue
多虧了
神器 GDB
我們終於學會
Shared Library
Debugging
某Daemon之死
至今仍是個謎 (驚)
案例二、
Case 2
劫持 FDs
File Descriptors Hijacking
時間有限
下回揭曉
File Descriptor Hijacking / 劫持 FDs 之奇技淫巧
Reference
快快樂樂學 GNU Debugger (gdb) Part I + II (Jserv)
[Link]
[Link]
[Link]
[Link]
GDB的妙用 (vgod)
[GDB Tricks] File Descriptor Hijacking / 劫持 FDs 之奇技淫巧