I. probe the stack frame structure The original idea is to unwind the function call stack according to a determined prologue on the begin of a frame. For example:

-------

PC

-------

LR

-------

SP

-------

FP

-------

.......

The precondition of this idea is that every frame stores all these infomations in same order at the front of the frame. But the practices tell us that's not true. In fact, some functions do so, some not. Why do some functions not do so? (Not understand till now. Maybe in order to save some memery, maybe it is not necessary to do so, maybe other unknown reasons.)

To prove this jugement, we did following things.

1. The output call stack is not complete with the method refered above.

2. Produce coredump file, then analyze the frame structures with gdb. We found three strange things:

1st, the caller frame of the frame before the signal process frame is itself, so we can't unwind to inner frame.

2nd, in stack memery we can't find any frame address showed by "info frame" command. How so?

3rd, then we dissamble different frames, we were astonished to found that different functions push very different  registers to the stack, even some functions didn't push any register at all.

3. Finally, we found an offical hint on gdb web site: "whether each function has a frame pointer and if not".

II. Try with backtrace of glibc.   Since there is not a determined frame structure, can the backtrace function of glibc work?   We did a lot of tries. But the results are the same with the above method. We are so wondering. So we read the   source code of backtrace function of glibc-linaro. The answer is it use the same method we did before. So the   results are same.

III. Try with unwind library first time.   Search on google and baidu. We found a library unwind. It's the library to unwind function call stack. And we   integrated it in our project immedially. Soon we got the result. It only has one frame more than the backtrace   function, and there is some other unkown error messages. It seems not suit to our project still. We guess, maybe   our project is more complicated than libunwind can apply, because we have 64bit CPU and OS, but 32bit application.   Or maybe it's not suitable for EABI.

IV. Try to learn from GDB.   Hitherto, the only one practicable method is GDB, why not to find the method that GDB use? Factually, She gong   and I had tried to read GDB's code before. But had to terminate for it's too complicated and too big to understand   in a short time. This time, we returned to it again. Though we didn't understand how it unwind the stack still, we   found some usefull infomations.   1. GDB use ptrace to get the registers.   2. GDB try to parse the function prologues when there isn't frame pointer. But how and what's the criteria, we      didn't know still.

V. Try with unwind library second time.   During we try to understand GDB's unwinding method. We found a usefull infomation that .eh_frame or .ARM.exidx or   .ARM.extab section in elf file can help to unwind the stack. This inspired a sparkle: can we unwind stack only with   these section? We tried to find a way and found the attachment document. It introduced these sections and   the compile paramter "-funwind-tables" and the related libunwind. So we try according it. It works!

[References]:

https://wiki.linaro.org/KenWerner/Sandbox/libunwind?action=AttachFile&do=get&target=libunwind-LDS.pdf

https://sourceware.org/gdb/papers/unwind.html

https://www.airs.com/blog/archives/460

https://www.facebook.com/notes/scott-tsai/%E5%9C%A8%E6%B2%92%E6%9C%89-frame-pointer-%E7%9A%84%E6%83%85%E6%B3%81%E4%B8%8B%E9%80%B2%E8%A1%8C-stack-unwind/784226238316104/

[A sparkle]:

Can we use _Unwind_Backtrace() of ligcc_s.so to unwind the function stack?

The way to unwind the stack on Linux EABI的更多相关文章

  1. Extended TCP/IP Stack In Linux: Netfilter Hooks and IP Table

    https://www.amazon.com/gp/product/1118887735 The chapter about debugging is rather outdated - it des ...

  2. Linux常用获取进程占用资源情况手段

    测试环境:Ubuntu14.04 1.  获取进程ID号 ps -aux | grep your_process_name 例如: xxx@xxx:~$ ps -e |grep Midlet|awk ...

  3. Coping with the TCP TIME-WAIT state on busy Linux servers

    Coping with the TCP TIME-WAIT state on busy Linux servers 文章源自于:https://vincent.bernat.im/en/blog/20 ...

  4. Linux: 20 Iptables Examples For New SysAdmins

    Linux comes with a host based firewall called Netfilter. According to the official project site: net ...

  5. linux 内核参数图解

    https://www.suse.com/documentation/sles11/book_sle_tuning/data/part_tuning_kernel.html http://blog.c ...

  6. Error handling in Swift does not involve stack unwinding. What does it mean?

    Stack unwinding is just the process of navigating up the stack looking for the handler. Wikipedia su ...

  7. Linux 驱动开发

    linux驱动开发总结(一) 基础性总结 1, linux驱动一般分为3大类: * 字符设备 * 块设备 * 网络设备 2, 开发环境构建: * 交叉工具链构建 * NFS和tftp服务器安装 3, ...

  8. android 官方文档 JNI TIPS

    文章地址  http://developer.android.com/training/articles/perf-jni.html JNI Tips JNI is the Java Native I ...

  9. NDK(5) Android JNI官方综合教程[JavaVM and JNIEnv,Threads ,jclass, jmethodID, and jfieldID,UTF-8 and UTF-16 Strings,Exceptions,Native Libraries等等]

    JNI Tips In this document JavaVM and JNIEnv Threads jclass, jmethodID, and jfieldID Local and Global ...

随机推荐

  1. java logAspect

    @Around("execution(* com.iotx.cep.biz.rpc.impl.*.*(..)) " + "&& !execution(* ...

  2. MATLAB 统计元素出现的次数

    可以使用 hist 函数: A = [1 2 8 8 1 8 2 1 8 2 1]; count = hist(A,unique(A)) count的结果与unique(A)对应.

  3. “5W1H”带你来学习JavaScript

    上次的设计模式讲课,从中学习到了非常多.不仅是技术上,更重要的是怎样来学习.我们学习的技术.科技的更新速度超过我们的想象,对于我们这个有生命年限的个体,怎样可以在有生之年可以让自己立足于科技的不败浪潮 ...

  4. C# 托管内存与非托管内存之间的转换

    c#有自己的内存回收机制,所以在c#中我们可以只new,不用关心怎样delete,c#使用gc来清理内存,这部分内存就是managed memory,大部分时候我们工作于c#环境中,都是在使用托管内存 ...

  5. Postman 接口测试神器

    Postman 接口测试神器 Postman 是一个接口测试和 http 请求的神器,非常好用. 官方 github 地址: https://github.com/postmanlabs Postma ...

  6. 基于expressjs老项目的翻新方案

    刚开始接触这方面的项目时,对ES规范理解不深,查了一些资料,发现如果不改expressjs的代码,大概率是没法用到最新的async/await了,后续也就没有继续往这个方面想. 这两天突然想起这个问题 ...

  7. RabbitMQ内存爆出

    RabbitMQ升级到3.6.1版本后,随着业务和系统功能的增加,出现RabbitMQ内存陡增直至服务宕掉的情况.内存增加时,在management管理控制台上可以见到如下警告: The manage ...

  8. Android全面屏适配

    什么是全面屏 概念 很多人可能把全面屏跟曲面屏混淆,其实这是两个不同的概念. 一般手机的屏幕纵横比为16:9,如1080x1920.1440x2560等,其比值为1.777777……,全面屏手机出现之 ...

  9. win10 安装node.js node.js 安装成功但npm -v 报错问题解决

    错误症状官网下载node-v8 .node-v10 的msi 安装进行安装. npm -v 错误如下 0 info it worked if it ends with ok 1 verbose cli ...

  10. TCP断线重连

    struct sockaddr_in TempSadd; TempSadd.sin_family = AF_INET; TempSadd.sin_port = htons(m_ServerPort); ...