Debugging: Difference between revisions

From miki
Jump to navigation Jump to search
 
(12 intermediate revisions by the same user not shown)
Line 1: Line 1:
This is a general page on debugging tools, techniques, tips, etc.
This is a general page on debugging tools, techniques, tips, etc.

== Debuggers environment ==

=== [http://www.ollydbg.de/ OllyDbg] ===
OllyDbg is a 32-bit assembler level analysing debugger for Microsoft® Windows®.

=== IDAPro ===

=== SoftIce ===

=== [http://www.hopperapp.com/ Hopper Disassembler] ===
Hopper is a reverse engineering tool for OS X and Linux, that lets you disassemble, decompile and debug your 32/64bits Intel Mac, Linux, Windows and iOS executables.



== Linux tools ==
== Linux tools ==
Line 5: Line 18:
See [[Linux Commands#addr2line|addr2line]] page.
See [[Linux Commands#addr2line|addr2line]] page.


=== gdb ===
=== GDB and GDB front-ends ===
See [[gdb]] page.
See [[gdb|GDB]] page.


== C/C++ - Debugging with gcc ==
== C/C++ - Debugging with gcc ==
Line 17: Line 30:
</source>
</source>


Object and executables need to build with '''<tt>gcc -g -rdynamic</tt>'''!
Object and executables need to be built (i.e. compiled and <u>linked</u>) with '''<tt>gcc -g -rdynamic</tt>''' (also '''<tt>-fvisibility</tt>''' must either be ''default'', ''protected'' or not set at all)!
<source lang="bash">
<source lang="bash">
gcc -o0 -g -rdynamic main.c -o myprogram
gcc -O0 -g -rdynamic main.c -o myprogram
</source>
</source>


Line 282: Line 295:


=== Getting function name from its address ===
=== Getting function name from its address ===
* {{red|'''TODO:'''}} There is maybe an alternate solution using <code>dlopen</code>, which would let an application to browse its own symbols.
* {{red|'''TODO:'''}} Check whether we can force export of (debug) symbols even if declared static.


The following program show how to use the <tt>backtrace_symbols</tt> function to get the name of a function given its address. The program must be compiled with gcc options '''-g -rdynamic''':
The following program show how to use the <tt>backtrace_symbols</tt> function to get the name of a function given its address.

The program must be compiled (and <u>linked</u>) with gcc options '''-g -rdynamic''' (also option '''<tt>-fvisibility</tt>''' must either be ''default'', ''protected'' or not set at all):


<source lang="bash">
<source lang="bash">
gcc -g -rdynamic -o0 main.c -o symfromaddr
gcc -g -rdynamic -O0 main.c -o symfromaddr
</source>
</source>


Line 315: Line 332:
//Isolate fctname in './path/with/(parens)/pgm(fctname+0) [0x1234abcd]'
//Isolate fctname in './path/with/(parens)/pgm(fctname+0) [0x1234abcd]'
(*sym)=p=((char **)buftofree)[0];
(*sym)=p=((char **)buftofree)[0];
while( '+' != (*p) )
while( (*p) && ('+' != (*p)) )
{
{
if( '(' == *(p++) )
if( '(' == *(p++) )
Line 322: Line 339:
}
}
}
}
if(!*p)
(*sym)=p;
*p = 0;
*p = 0;
}
}
Line 366: Line 385:


beg=end=strings[0];
beg=end=strings[0];
while( '+' != (*end) )
while( (*end) && ('+' != (*end)) )
{
{
if( '(' == *(end++) )
if( '(' == *(end++) )
Line 373: Line 392:
}
}
}
}

*end = 0;
strncpy(sym,beg,n);
sym[0]=0;
if (n>0)
if(*end) {
sym[n-1]=0;
*end = 0;
strncpy(sym,beg,n);
if (n>0)
sym[n-1]=0;
}

free(strings);
free(strings);


Line 393: Line 417:


=== libunwind (non-gnu) ===
=== libunwind (non-gnu) ===
* See http://www.nongnu.org/libunwind/docs.html
* See http://www.nongnu.org/libunwind/docs.html (see also [http://codingrelic.geekhold.com/2009/05/pre-mortem-backtracing.html here for example])

== Debugging pthreads ==
'''GDB''':
* [http://www.sourceware.org/gdb/current/onlinedocs/gdb/Threads.html#Threads Debugging Programs with Multiple Threads]
* [http://sources.redhat.com/gdb/current/onlinedocs/gdb/Thread-Stops.html#Thread-Stops GDB: Stopping and starting multi-thread programs]
* [http://sources.redhat.com/gdb/current/onlinedocs/gdb/GDB_002fMI-Thread-Commands.html#GDB_002fMI-Thread-Commands GDB/MI: Threads commands]
'''DDD''':
* [http://www.gnu.org/software/ddd/manual/html_mono/ddd.html#Threads Examining Threads]

Latest revision as of 13:09, 16 October 2014

This is a general page on debugging tools, techniques, tips, etc.

Debuggers environment

OllyDbg

OllyDbg is a 32-bit assembler level analysing debugger for Microsoft® Windows®.

IDAPro

SoftIce

Hopper Disassembler

Hopper is a reverse engineering tool for OS X and Linux, that lets you disassemble, decompile and debug your 32/64bits Intel Mac, Linux, Windows and iOS executables.


Linux tools

addr2line

See addr2line page.

GDB and GDB front-ends

See GDB page.

C/C++ - Debugging with gcc

backtrace, backtrace_symbols, backtrace_symbols_fd

See manual page, or gcc manual.

int     backtrace            (void **      buffer, int size)
char ** backtrace_symbols    (void *const *buffer, int size)
void    backtrace_symbols_fd (void *const *buffer, int size, int fd)

Object and executables need to be built (i.e. compiled and linked) with gcc -g -rdynamic (also -fvisibility must either be default, protected or not set at all)!

gcc -O0 -g -rdynamic main.c -o myprogram

Short example:

#include <stdio.h>
#include <execinfo.h>
#include <signal.h>
#include <stdlib.h>

void handler(int sig) {
  void *array[10];
  int size;

  size = backtrace(array, 10);                  // get void*'s for all entries on the stack

  fprintf(stderr, "Error: signal %d:\n", sig);  // print out all the frames to stderr
  backtrace_symbols_fd(array, size, 2);
  exit(1);
}

void baz() {
  int *foo = (int*)-1;                          // make a bad pointer
  printf("%d\n", *foo);                         // causes segfault
}

void bar() { baz(); }
void foo() { bar(); }

int main(int argc, char **argv) {
  signal(SIGSEGV, handler);                     // install our handler
  foo();                                        // this will call foo, bar, and baz.  baz segfaults.
  return 0;
}

It can also be used to print the symbol name of any function of which we know the address (a bit like SymFromAddr on windows):

#include <stdio.h>
#include <execinfo.h>

void foo(void) {
    printf("foo\n");
}

int main(int argc, char *argv[]) {
    void    *funptr = &foo;

    backtrace_symbols_fd(&funptr, 1, 1);

    return 0;
}


A very extensive answer on StackOverflow:

  • Using backtrace:
  • Demangling symbols in C++ by calling __cxa_demangle (like is done in tool c++filt):

Getting function name from its address

  • TODO: There is maybe an alternate solution using dlopen, which would let an application to browse its own symbols.
  • TODO: Check whether we can force export of (debug) symbols even if declared static.

The following program show how to use the backtrace_symbols function to get the name of a function given its address.

The program must be compiled (and linked) with gcc options -g -rdynamic (also option -fvisibility must either be default, protected or not set at all):

gcc -g -rdynamic -O0 main.c -o symfromaddr

A less efficient but more convenient version:

libunwind (non-gnu)

Debugging pthreads

GDB:

DDD: