I. probe the stack frame structure The original idea is to unwind the function call stack according to a determined prologue on the begin of a frame. For example:

-------

PC

-------

LR

-------

SP

-------

FP

-------

.......

The precondition of this idea is that every frame stores all these infomations in same order at the front of the frame. But the practices tell us that's not true. In fact, some functions do so, some not. Why do some functions not do so? (Not understand till now. Maybe in order to save some memery, maybe it is not necessary to do so, maybe other unknown reasons.)

To prove this jugement, we did following things.

1. The output call stack is not complete with the method refered above.

2. Produce coredump file, then analyze the frame structures with gdb. We found three strange things:

1st, the caller frame of the frame before the signal process frame is itself, so we can't unwind to inner frame.

2nd, in stack memery we can't find any frame address showed by "info frame" command. How so?

3rd, then we dissamble different frames, we were astonished to found that different functions push very different  registers to the stack, even some functions didn't push any register at all.

3. Finally, we found an offical hint on gdb web site: "whether each function has a frame pointer and if not".

II. Try with backtrace of glibc.   Since there is not a determined frame structure, can the backtrace function of glibc work?   We did a lot of tries. But the results are the same with the above method. We are so wondering. So we read the   source code of backtrace function of glibc-linaro. The answer is it use the same method we did before. So the   results are same.

III. Try with unwind library first time.   Search on google and baidu. We found a library unwind. It's the library to unwind function call stack. And we   integrated it in our project immedially. Soon we got the result. It only has one frame more than the backtrace   function, and there is some other unkown error messages. It seems not suit to our project still. We guess, maybe   our project is more complicated than libunwind can apply, because we have 64bit CPU and OS, but 32bit application.   Or maybe it's not suitable for EABI.

IV. Try to learn from GDB.   Hitherto, the only one practicable method is GDB, why not to find the method that GDB use? Factually, She gong   and I had tried to read GDB's code before. But had to terminate for it's too complicated and too big to understand   in a short time. This time, we returned to it again. Though we didn't understand how it unwind the stack still, we   found some usefull infomations.   1. GDB use ptrace to get the registers.   2. GDB try to parse the function prologues when there isn't frame pointer. But how and what's the criteria, we      didn't know still.

V. Try with unwind library second time.   During we try to understand GDB's unwinding method. We found a usefull infomation that .eh_frame or .ARM.exidx or   .ARM.extab section in elf file can help to unwind the stack. This inspired a sparkle: can we unwind stack only with   these section? We tried to find a way and found the attachment document. It introduced these sections and   the compile paramter "-funwind-tables" and the related libunwind. So we try according it. It works!

[References]:

https://wiki.linaro.org/KenWerner/Sandbox/libunwind?action=AttachFile&do=get&target=libunwind-LDS.pdf

https://sourceware.org/gdb/papers/unwind.html

https://www.airs.com/blog/archives/460

https://www.facebook.com/notes/scott-tsai/%E5%9C%A8%E6%B2%92%E6%9C%89-frame-pointer-%E7%9A%84%E6%83%85%E6%B3%81%E4%B8%8B%E9%80%B2%E8%A1%8C-stack-unwind/784226238316104/

[A sparkle]:

Can we use _Unwind_Backtrace() of ligcc_s.so to unwind the function stack?

The way to unwind the stack on Linux EABI的更多相关文章

  1. Extended TCP/IP Stack In Linux: Netfilter Hooks and IP Table

    https://www.amazon.com/gp/product/1118887735 The chapter about debugging is rather outdated - it des ...

  2. Linux常用获取进程占用资源情况手段

    测试环境:Ubuntu14.04 1.  获取进程ID号 ps -aux | grep your_process_name 例如: xxx@xxx:~$ ps -e |grep Midlet|awk ...

  3. Coping with the TCP TIME-WAIT state on busy Linux servers

    Coping with the TCP TIME-WAIT state on busy Linux servers 文章源自于:https://vincent.bernat.im/en/blog/20 ...

  4. Linux: 20 Iptables Examples For New SysAdmins

    Linux comes with a host based firewall called Netfilter. According to the official project site: net ...

  5. linux 内核参数图解

    https://www.suse.com/documentation/sles11/book_sle_tuning/data/part_tuning_kernel.html http://blog.c ...

  6. Error handling in Swift does not involve stack unwinding. What does it mean?

    Stack unwinding is just the process of navigating up the stack looking for the handler. Wikipedia su ...

  7. Linux 驱动开发

    linux驱动开发总结(一) 基础性总结 1, linux驱动一般分为3大类: * 字符设备 * 块设备 * 网络设备 2, 开发环境构建: * 交叉工具链构建 * NFS和tftp服务器安装 3, ...

  8. android 官方文档 JNI TIPS

    文章地址  http://developer.android.com/training/articles/perf-jni.html JNI Tips JNI is the Java Native I ...

  9. NDK(5) Android JNI官方综合教程[JavaVM and JNIEnv,Threads ,jclass, jmethodID, and jfieldID,UTF-8 and UTF-16 Strings,Exceptions,Native Libraries等等]

    JNI Tips In this document JavaVM and JNIEnv Threads jclass, jmethodID, and jfieldID Local and Global ...

随机推荐

  1. unit3d 初次接触

    最近, 有朋友告我,他们做那个 vr 视频啥的,告我看后,感觉很好,故 ,就去网上搜索一下,了解如下: 1..unit 3d 是啥? Unity3D是一个跨平台的游戏引擎 是由Unity Techno ...

  2. Effective Java 第三版——64. 通过对象的接口引用对象

    Tips 书中的源代码地址:https://github.com/jbloch/effective-java-3e-source-code 注意,书中的有些代码里方法是基于Java 9 API中的,所 ...

  3. Python分页组件

    分页组件的实现: class Pagination(object): """ 自定义分页 """ def __init__(self,cur ...

  4. zabbix之微信告警(python版):微信个人报警,微信企业号告警脚本

    微信个人告警脚本 微信个人告警:使用个人微信,发送到微信群组,微信好友 两个脚本执行: 1)能连接网络2)先执行server.py,扫描登录微信,登录之后没有报错,打开新终端查看端口是否起来了3)在z ...

  5. Android 源码学习

    工具篇:如何使用 Visual Studio Code 阅读 Android 源码:https://jekton.github.io/2018/05/11/how-to-read-android-so ...

  6. fiddler的编程文章

    https://www.cnblogs.com/trevan/p/9487223.html https://www.cnblogs.com/rufus-hua/p/5275980.html https ...

  7. Cobalt Strike DNS通讯实例

    一.域名设置 如果没有域名,可以参考另一篇博客,申请Freenom免费域名,并使用DNSPod解析 链接:https://www.cnblogs.com/ssooking/p/6364639.html ...

  8. "title_activity_dist" is not translated in "zh-rCN" (Chinese: China)

    根据报错提示,是说我没有对string文件做国际化翻译操作,但是我报错的项目并没有做国际化,所以并没有values-zh-rCN和values-zh-rTW两个文件夹,最后我发现原来是当前项目引用的一 ...

  9. windows环境下命令打到服务中

    1.正常redis在本地命令行中启动,现在直接在服务中启动(tomcat同理) cmd下命令如下: sc create redis binPath= D:\redis\redis-server.exe ...

  10. java.lang.Exception: No tests found matching [{ExactMatcher:fDisplayName=test]解决办法

    在进行简单的Junit单元测试时,测试一直报错: 先来看一下我的单元测试类: import org.junit.Test; import org.junit.runner.RunWith; impor ...