X-Git-Url: http://git.annexia.org/?p=virt-mem.git;a=blobdiff_plain;f=lib%2Fvirt_mem.ml;h=9a00ead4cd4bfe4a9f377245c37231fa7d84cbde;hp=bcee6696b68f8da3300a498e1ff89eb393123e8d;hb=eb9dbe2bc7656aed41ed207016746c983fcba4ef;hpb=46037cd89c23b0f94dc691006ee1d9cd0fec24f0 diff --git a/lib/virt_mem.ml b/lib/virt_mem.ml index bcee669..9a00ead 100644 --- a/lib/virt_mem.ml +++ b/lib/virt_mem.ml @@ -22,6 +22,9 @@ open Printf open ExtList open ExtString +module C = Libvirt.Connect +module D = Libvirt.Domain + open Virt_mem_gettext.Gettext open Virt_mem_utils module MMap = Virt_mem_mmap @@ -29,6 +32,9 @@ module MMap = Virt_mem_mmap let min_kallsyms_tabsize = 1_000L let max_kallsyms_tabsize = 250_000L +let kernel_size = 0x100_0000 +let max_memory_peek = 0x1_000 + type ksym = string type image = @@ -42,8 +48,8 @@ type kallsyms_compr = | Uncompressed of (string * MMap.addr) list let start usage_msg = - (* Verbose messages. *) - let verbose = ref false in + (* Debug messages. *) + let debug = ref false in (* Default wordsize. *) let def_wordsize = ref None in @@ -87,6 +93,7 @@ let start usage_msg = (* List of kernel images. *) let images = ref [] in + let uri = ref "" in let memory_image filename = images := @@ -94,19 +101,35 @@ let start usage_msg = :: !images in + let version () = + printf "virt-mem %s\n" Virt_mem_version.version; + + let major, minor, release = + let v, _ = Libvirt.get_version () in + v / 1_000_000, (v / 1_000) mod 1_000, v mod 1_000 in + printf "libvirt %d.%d.%d\n" major minor release; + exit 0 + in + let argspec = Arg.align [ "-A", Arg.String set_architecture, - "arch " ^ s_"Set kernel architecture, endianness and word size"; + "arch " ^ s_"Set kernel architecture, endianness and word size"; "-E", Arg.String set_endian, - "endian " ^ s_"Set kernel endianness"; + "endian " ^ s_"Set kernel endianness"; "-T", Arg.String set_text_addr, - "addr " ^ s_"Set kernel text address"; + "addr " ^ s_"Set kernel text address"; "-W", Arg.String set_wordsize, - "addr " ^ s_"Set kernel word size"; + "addr " ^ s_"Set kernel word size"; + "-c", Arg.Set_string uri, + "uri " ^ s_ "Connect to URI"; + "--connect", Arg.Set_string uri, + "uri " ^ s_ "Connect to URI"; + "--debug", Arg.Set debug, + " " ^ s_"Debug mode (default: false)"; "-t", Arg.String memory_image, - "image " ^ s_"Use saved kernel memory image"; - "-verbose", Arg.Set verbose, - " " ^ s_"Verbose messages"; + "image " ^ s_"Use saved kernel memory image"; + "--version", Arg.Unit version, + " " ^ s_"Display version and exit"; ] in let anon_fun str = @@ -115,14 +138,104 @@ let start usage_msg = Arg.parse argspec anon_fun usage_msg; let images = !images in - let verbose = !verbose in + let debug = !debug in + let uri = if !uri = "" then None else Some !uri in (* Get the kernel images. *) let images = - if images = [] then - (* XXX use libvirt to get images *) - failwith "libvirt: not yet implemented" - else + if images = [] then ( + let conn = + let name = uri in + try C.connect_readonly ?name () + with Libvirt.Virterror err -> + prerr_endline (Libvirt.Virterror.to_string err); + (* If non-root and no explicit connection URI, print a warning. *) + if Unix.geteuid () <> 0 && name = None then ( + print_endline (s_ "NB: If you want to monitor a local Xen hypervisor, you usually need to be root"); + ); + exit 1 in + + (* List of active domains. *) + let doms = + let nr_active_doms = C.num_of_domains conn in + let active_doms = + Array.to_list (C.list_domains conn nr_active_doms) in + let active_doms = + List.map (D.lookup_by_id conn) active_doms in + active_doms in + + (* Get their XML. *) + let xmls = List.map (fun dom -> dom, D.get_xml_desc dom) doms in + + (* Parse the XML. *) + let xmls = List.map (fun (dom, xml) -> + dom, Xml.parse_string xml) xmls in + + (* XXX Do something with the XML XXX + * such as detecting arch, wordsize, endianness. + * XXXXXXXXXXXXXX + * + * + * + *) + + + List.map ( + fun (dom, _) -> + let name = D.get_name dom in + + let wordsize = + match !def_wordsize with + | None -> + failwith + (sprintf (f_"%s: use -W to define word size for this image") + name); + | Some ws -> ws in + let endian = + match !def_endian with + | None -> + failwith + (sprintf (f_"%s: use -E to define endianness for this image") + name); + | Some e -> e in + + let arch = + match !def_architecture with + | Some I386 -> I386 | Some X86_64 -> X86_64 + | _ -> + failwith + (sprintf (f_"%s: use -A to define architecture (i386/x86-64 only) for this image") name) in + + if !def_text_addr = 0L then + failwith + (sprintf (f_"%s: use -T to define kernel load address for this image") + name); + + (* Read the kernel memory. + * Maximum 64K can be read over remote connections. + *) + let str = String.create kernel_size in + let rec loop i = + let remaining = kernel_size - i in + if remaining > 0 then ( + let size = min remaining max_memory_peek in + D.memory_peek dom [D.Virtual] + (!def_text_addr +^ Int64.of_int i) size str i; + loop (i + size) + ) + in + loop 0; + + (* Map the virtual memory. *) + let mem = MMap.of_string str !def_text_addr in + + (* Force the wordsize and endianness. *) + let mem = MMap.set_wordsize mem wordsize in + let mem = MMap.set_endian mem endian in + + (name, arch, mem) + ) xmls + ) else List.map ( fun (wordsize, endian, arch, text_addr, filename) -> (* Quite a lot of limitations on the kernel images we can @@ -257,7 +370,7 @@ let start usage_msg = (* Simply ignore any symbol table candidates which are too small. *) let ksymtabs = List.filter (fun (_, size) -> size > 64L) ksymtabs in - if verbose then ( + if debug then ( printf "%s: candidate symbol tables at:\n" name; List.iter ( fun (addr, size) -> @@ -280,7 +393,7 @@ let start usage_msg = (fun _ -> raise Not_found) | (_, (ksymtab_addr, ksymtab_size)) :: _ -> - if verbose then + if debug then printf "%s: Kernel symbol table found at %Lx, size %Lx bytes\n%!" name ksymtab_addr ksymtab_size; @@ -342,7 +455,7 @@ let start usage_msg = (* Search upwards from address until we find the length field. * If found, jump backwards by length and check all addresses. *) - if verbose then + if debug then printf "%s: testing candidate kallsyms at %Lx\n" name addr; let rec loop addr = let addrp = MMap.follow_pointer mem addr in @@ -369,7 +482,7 @@ let start usage_msg = ) else (* ok! *) let names_addr = MMap.succ_long mem end_addr in - if verbose then + if debug then printf "%s: candidate kallsyms found at %Lx (names_addr at %Lx, num_entries %d)\n" name start_addr names_addr num_entries; Some (start_addr, num_entries, names_addr) @@ -444,7 +557,7 @@ let start usage_msg = Invalid_argument _ -> None (* bad names list *) ) ksym_addrs in - if verbose then ( + if debug then ( printf "%s: candidate kallsyms at:\n" name; List.iter ( function @@ -507,19 +620,19 @@ let start usage_msg = let names = List.filter_map ( fun (name, sym_value) -> let f c = tokens.(Char.code c) in - let name' = String.replace_chars f name in - (*printf "%S -> %S\n" name name';*) + let name = String.replace_chars f name in (* First character in uncompressed output is the symbol - * type, eg. 'T'/'t' for text etc. Since we will never - * be using functions, and since some functions (eg. - * con_start) overlap with data symbols, drop functions. + * type, eg. 'T'/'t' for text etc. *) - let typ = name'.[0] in - if typ = 't' || typ = 'T' then None - else ( - let name' = String.sub name' 1 (String.length name' - 1) in - Some (name', sym_value) - ) + (* NOTE: Symbol names are NOT unique + * (eg. 'con_start' is both a function and data in + * some kernels). XXX We need to handle this situation + * better. + *) + (*let typ = name.[0] in*) + let name = String.sub name 1 (String.length name - 1) in + (*printf "%S -> %Lx\n" name sym_value;*) + Some (name, sym_value) ) compressed_names in let lookup_ksym name = @@ -532,10 +645,10 @@ let start usage_msg = lookup_ksym in (* Just wrap the lookup_ksym call in something which prints - * the query when verbose is set. + * the query when debug is set. *) let lookup_ksym = - if verbose then + if debug then let lookup_ksym sym = try let value = lookup_ksym sym in @@ -553,4 +666,4 @@ let start usage_msg = ((name, arch, mem, lookup_ksym) : image) ) images in - verbose, images + debug, images