2015-03-02 13:06:34 -08:00
|
|
|
|
// Copyright 2015 The Crashpad Authors. All rights reserved.
|
|
|
|
|
//
|
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
|
//
|
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
//
|
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
|
// limitations under the License.
|
|
|
|
|
|
|
|
|
|
#ifndef CRASHPAD_SNAPSHOT_WIN_PROCESS_READER_WIN_H_
|
|
|
|
|
#define CRASHPAD_SNAPSHOT_WIN_PROCESS_READER_WIN_H_
|
|
|
|
|
|
|
|
|
|
#include <windows.h>
|
2016-01-06 12:22:50 -05:00
|
|
|
|
#include <sys/time.h>
|
2015-03-02 13:06:34 -08:00
|
|
|
|
|
2015-05-11 13:29:52 -07:00
|
|
|
|
#include <vector>
|
|
|
|
|
|
2016-01-06 12:22:50 -05:00
|
|
|
|
#include "base/macros.h"
|
2015-09-18 16:06:05 -07:00
|
|
|
|
#include "build/build_config.h"
|
2015-03-02 13:06:34 -08:00
|
|
|
|
#include "util/misc/initialization_state_dcheck.h"
|
2015-05-01 13:48:23 -07:00
|
|
|
|
#include "util/win/address_types.h"
|
2015-03-06 16:05:34 -08:00
|
|
|
|
#include "util/win/process_info.h"
|
2015-03-02 13:06:34 -08:00
|
|
|
|
|
|
|
|
|
namespace crashpad {
|
|
|
|
|
|
2015-09-09 12:29:29 -07:00
|
|
|
|
//! \brief State of process being read by ProcessReaderWin.
|
|
|
|
|
enum class ProcessSuspensionState : bool {
|
|
|
|
|
//! \brief The process has not been suspended.
|
|
|
|
|
kRunning,
|
|
|
|
|
|
|
|
|
|
//! \brief The process is suspended.
|
|
|
|
|
kSuspended,
|
|
|
|
|
};
|
|
|
|
|
|
2015-08-10 12:23:50 -04:00
|
|
|
|
//! \brief Accesses information about another process, identified by a `HANDLE`.
|
2015-03-02 13:06:34 -08:00
|
|
|
|
class ProcessReaderWin {
|
|
|
|
|
public:
|
2015-05-11 13:29:52 -07:00
|
|
|
|
//! \brief Contains information about a thread that belongs to a process.
|
|
|
|
|
struct Thread {
|
|
|
|
|
Thread();
|
|
|
|
|
~Thread() {}
|
|
|
|
|
|
2015-09-18 16:06:05 -07:00
|
|
|
|
union {
|
|
|
|
|
CONTEXT native;
|
|
|
|
|
#if defined(ARCH_CPU_64_BITS)
|
|
|
|
|
WOW64_CONTEXT wow64;
|
2015-10-01 14:04:49 -07:00
|
|
|
|
#endif
|
2015-09-18 16:06:05 -07:00
|
|
|
|
} context;
|
2015-05-11 13:29:52 -07:00
|
|
|
|
uint64_t id;
|
2015-10-01 14:04:49 -07:00
|
|
|
|
WinVMAddress teb_address;
|
|
|
|
|
WinVMSize teb_size;
|
2015-05-11 13:29:52 -07:00
|
|
|
|
WinVMAddress stack_region_address;
|
|
|
|
|
WinVMSize stack_region_size;
|
|
|
|
|
uint32_t suspend_count;
|
|
|
|
|
uint32_t priority_class;
|
|
|
|
|
uint32_t priority;
|
|
|
|
|
};
|
|
|
|
|
|
2015-03-02 13:06:34 -08:00
|
|
|
|
ProcessReaderWin();
|
|
|
|
|
~ProcessReaderWin();
|
|
|
|
|
|
|
|
|
|
//! \brief Initializes this object. This method must be called before any
|
|
|
|
|
//! other.
|
|
|
|
|
//!
|
2015-08-10 12:23:50 -04:00
|
|
|
|
//! \param[in] process Process handle, must have `PROCESS_QUERY_INFORMATION`,
|
|
|
|
|
//! `PROCESS_VM_READ`, and `PROCESS_DUP_HANDLE` access.
|
2015-09-09 12:29:29 -07:00
|
|
|
|
//! \param[in] suspension_state Whether \a process has already been suspended
|
|
|
|
|
//! by the caller. Typically, this will be
|
|
|
|
|
//! ProcessSuspensionState::kSuspended, except for testing uses and where
|
|
|
|
|
//! the reader is reading itself.
|
2015-03-02 13:06:34 -08:00
|
|
|
|
//!
|
|
|
|
|
//! \return `true` on success, indicating that this object will respond
|
|
|
|
|
//! validly to further method calls. `false` on failure. On failure, no
|
|
|
|
|
//! further method calls should be made.
|
2015-09-09 12:29:29 -07:00
|
|
|
|
//!
|
|
|
|
|
//! \sa ScopedProcessSuspend
|
|
|
|
|
bool Initialize(HANDLE process, ProcessSuspensionState suspension_state);
|
2015-03-02 13:06:34 -08:00
|
|
|
|
|
|
|
|
|
//! \return `true` if the target task is a 64-bit process.
|
2015-03-06 16:05:34 -08:00
|
|
|
|
bool Is64Bit() const { return process_info_.Is64Bit(); }
|
2015-03-02 13:06:34 -08:00
|
|
|
|
|
2015-10-01 15:24:12 -07:00
|
|
|
|
//! \brief Attempts to read \a num_bytes bytes from the target process
|
|
|
|
|
//! starting at address \a at into \a into.
|
|
|
|
|
//!
|
|
|
|
|
//! \return `true` if the entire region could be read, or `false` with an
|
|
|
|
|
//! error logged.
|
|
|
|
|
//!
|
|
|
|
|
//! \sa ReadAvailableMemory
|
2015-09-16 12:42:20 -07:00
|
|
|
|
bool ReadMemory(WinVMAddress at, WinVMSize num_bytes, void* into) const;
|
2015-05-01 13:48:23 -07:00
|
|
|
|
|
2015-10-01 15:24:12 -07:00
|
|
|
|
//! \brief Attempts to read \a num_bytes bytes from the target process
|
|
|
|
|
//! starting at address \a at into \a into. If some of the specified range
|
|
|
|
|
//! is not accessible, reads up to the first inaccessible byte.
|
|
|
|
|
//!
|
|
|
|
|
//! \return The actual number of bytes read.
|
|
|
|
|
//!
|
|
|
|
|
//! \sa ReadMemory
|
|
|
|
|
WinVMSize ReadAvailableMemory(WinVMAddress at,
|
|
|
|
|
WinVMSize num_bytes,
|
|
|
|
|
void* into) const;
|
|
|
|
|
|
2015-05-06 11:13:44 -07:00
|
|
|
|
//! \brief Determines the target process' start time.
|
|
|
|
|
//!
|
|
|
|
|
//! \param[out] start_time The time that the process started.
|
|
|
|
|
//!
|
|
|
|
|
//! \return `true` on success, `false` on failure, with a warning logged.
|
|
|
|
|
bool StartTime(timeval* start_time) const;
|
|
|
|
|
|
|
|
|
|
//! \brief Determines the target process' execution time.
|
|
|
|
|
//!
|
|
|
|
|
//! \param[out] user_time The amount of time the process has executed code in
|
|
|
|
|
//! user mode.
|
|
|
|
|
//! \param[out] system_time The amount of time the process has executed code
|
|
|
|
|
//! in kernel mode.
|
|
|
|
|
//!
|
|
|
|
|
//! \return `true` on success, `false` on failure, with a warning logged.
|
|
|
|
|
bool CPUTimes(timeval* user_time, timeval* system_time) const;
|
|
|
|
|
|
2015-05-11 13:29:52 -07:00
|
|
|
|
//! \return The threads that are in the process. The first element (at index
|
|
|
|
|
//! `0`) corresponds to the main thread.
|
|
|
|
|
const std::vector<Thread>& Threads();
|
|
|
|
|
|
2015-05-01 13:48:23 -07:00
|
|
|
|
//! \return The modules loaded in the process. The first element (at index
|
|
|
|
|
//! `0`) corresponds to the main executable.
|
|
|
|
|
const std::vector<ProcessInfo::Module>& Modules();
|
|
|
|
|
|
2015-09-25 10:31:02 -07:00
|
|
|
|
//! \return A ProcessInfo object for the process being read.
|
|
|
|
|
const ProcessInfo& GetProcessInfo() const;
|
|
|
|
|
|
2016-05-02 11:36:41 -07:00
|
|
|
|
//! \brief Decrements the thread suspend counts for all thread ids other than
|
|
|
|
|
//! \a except_thread_id.
|
|
|
|
|
//!
|
|
|
|
|
//! Used to adjust the thread suspend count to correspond to the actual values
|
|
|
|
|
//! for the process before Crashpad got involved.
|
|
|
|
|
void DecrementThreadSuspendCounts(uint64_t except_thread_id);
|
|
|
|
|
|
2015-03-02 13:06:34 -08:00
|
|
|
|
private:
|
2015-09-16 12:42:20 -07:00
|
|
|
|
template <class Traits>
|
2015-09-18 16:06:05 -07:00
|
|
|
|
void ReadThreadData(bool is_64_reading_32);
|
2015-09-16 12:42:20 -07:00
|
|
|
|
|
2015-05-01 13:48:23 -07:00
|
|
|
|
HANDLE process_;
|
2015-03-06 16:05:34 -08:00
|
|
|
|
ProcessInfo process_info_;
|
2015-05-11 13:29:52 -07:00
|
|
|
|
std::vector<Thread> threads_;
|
2015-05-01 13:48:23 -07:00
|
|
|
|
std::vector<ProcessInfo::Module> modules_;
|
2015-09-09 12:29:29 -07:00
|
|
|
|
ProcessSuspensionState suspension_state_;
|
2015-05-11 13:29:52 -07:00
|
|
|
|
bool initialized_threads_;
|
2015-03-02 13:06:34 -08:00
|
|
|
|
InitializationStateDcheck initialized_;
|
|
|
|
|
|
|
|
|
|
DISALLOW_COPY_AND_ASSIGN(ProcessReaderWin);
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
} // namespace crashpad
|
|
|
|
|
|
|
|
|
|
#endif // CRASHPAD_SNAPSHOT_WIN_PROCESS_READER_WIN_H_
|