【问题标题】:Using GDB to change a for loop condition?使用 GDB 更改 for 循环条件?
【发布时间】:2017-09-03 18:13:36
【问题描述】:

我正在尝试调试程序并且对 for(int i =0; i

【问题讨论】:

  • gdb 无法更改您的代码,它被设置为只读...
  • 我同意:我认为有一些工具可以让您在调试器(Visual Studio?)中实际替换代码......但我怀疑 gdb 可以做到这一点.
  • 我猜,你可以改变寄存器来翻转跳转条件...
  • 嗯,这有点可疑。在这种情况下,可能只有一个跳转条件被改变,也许......
  • 移动(通过编辑代码)10 到变量中,然后通过 gdb 将变量编辑为 11

标签: c loops debugging gdb


【解决方案1】:

想在 GDB 调试器中将 i

有几种方法可以做到这一点,具体取决于正是您需要什么。

我假设你只需要这样做一次,你的二进制文件是在x86_64上构建的,没有优化。

给定:

#include <stdio.h>
int main()
{
  for (int i = 0; i < 10; i++)
    printf("%d\n", i);
  return 0;
}

gcc -g -std=c99 t.c && gdb -q ./a.out

gdb) disas main
Dump of assembler code for function main:
   0x000000000040052d <+0>:     push   %rbp
   0x000000000040052e <+1>:     mov    %rsp,%rbp
   0x0000000000400531 <+4>:     sub    $0x10,%rsp
   0x0000000000400535 <+8>:     movl   $0x0,-0x4(%rbp)
   0x000000000040053c <+15>:    jmp    0x400556 <main+41>
   0x000000000040053e <+17>:    mov    -0x4(%rbp),%eax
   0x0000000000400541 <+20>:    mov    %eax,%esi
   0x0000000000400543 <+22>:    mov    $0x4005f4,%edi
   0x0000000000400548 <+27>:    mov    $0x0,%eax
   0x000000000040054d <+32>:    callq  0x400410 <printf@plt>
   0x0000000000400552 <+37>:    addl   $0x1,-0x4(%rbp)
   0x0000000000400556 <+41>:    cmpl   $0x9,-0x4(%rbp)
   0x000000000040055a <+45>:    jle    0x40053e <main+17>
   0x000000000040055c <+47>:    mov    $0x0,%eax
   0x0000000000400561 <+52>:    leaveq 
   0x0000000000400562 <+53>:    retq   
End of assembler dump.

在这里你可以看到地址0x400556的指令将i的值(存储在$rbp-4的堆栈中)与常量9进行比较,如果值小于或等于@则跳转回来987654327@.

所以你可以在0x40055a 的指令上设置一个断点,然后强制即使编译后的代码说它不应该进行跳转:

(gdb) b *0x40055a if i == 10
Breakpoint 1 at 0x40055a: file t.c, line 4.
(gdb) run
Starting program: /tmp/a.out 
0
1
2
3
4
5
6
7
8
9

Breakpoint 1, 0x000000000040055a in main () at t.c:4
4             for (int i = 0; i < 10; i++)
(gdb) p i
$1 = 10
(gdb) jump *0x40053e
Continuing at 0x40053e.
10
[Inferior 1 (process 22210) exited normally]

瞧:我们打印了一个额外的值。

另一种可能的方法:在指令上设置断点0x400556,将i的值调整为i-1,单步,将i的值调整为i+1,继续。

另一种方法:二进制修补0x400556处的指令以与常量10而不是9进行比较:

(gdb) disas/r 0x400556,0x400557
Dump of assembler code from 0x400556 to 0x400557:
   0x0000000000400556 <main+41>:        83 7d fc 09     cmpl   $0x9,-0x4(%rbp)
End of assembler dump.

在这里您可以看到常量9 是指令字节的一部分,特别是地址0x400559 处的字节。您可以更改该字节:

(gdb) start

Starting program: /tmp/a.out 

Temporary breakpoint 1, main () at t.c:4
4             for (int i = 0; i < 10; i++)

让我们重写指令并再次反汇编:

(gdb) set *(char*)0x400559 = 10
(gdb) disas/r 0x400556,0x400557
Dump of assembler code from 0x400556 to 0x400557:
   0x0000000000400556 <main+41>:        83 7d fc 0a     cmpl   $0xa,-0x4(%rbp)
End of assembler dump.

看起来不错:我们现在比较 10 而不是 9。有用吗?

(gdb) c
Continuing.
0
1
2
3
4
5
6
7
8
9
10
[Inferior 1 (process 23131) exited normally]

是的,确实如此!

附:二进制补丁指令相当于编辑源代码并重建二进制文件,除了补丁在下一个run 被“忘记”。

【讨论】:

    猜你喜欢
    • 2013-08-14
    • 1970-01-01
    • 2016-01-28
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2016-04-10
    • 1970-01-01
    • 2016-08-18
    相关资源
    最近更新 更多