Alex Rivera | Logout

Low-overhead way to access the memory space of a traced process?

Asked 2009-06-05T22:05:43.930
9

I'm looking for an efficient way to access(for both read and write operations) the memory space of my ptraced child process. The size of blocks being accessed may vary from several bytes up to several megabytes in size, so using the ptrace call with PTRACE_PEEKDATA and PTRACE_POKEDATA which read only one word at a time and switch context every time they're called seems like a pointless waste of resources. The only one alternative solution I could find, though, was the /proc/<pid>/mem file, but it has long since been made read only.

Is there any other (relatively simple) way to do that job? The ideal solution would be to somehow share the address space of my child process with its parent and then use the simple memcpy call to copy data I need in both directions, but I have no clues how to do it and where to begin.

Any ideas?

Edit
Report

2 Answers

2

For reading, your best bet is to parse the /proc/<pid>/maps file for the virtual addresses of the memory regions of interest.

You can then read these by opening /proc/<pid>/mem and perform read() call with a large buffer on areas of interest.

For writing, I've yet to find an easy way to write entire blocks, I believe this has to do with locking and stability for the child process, calls through ptrace() can guarantee this, but direct access to another process' memory cannot. I typically write a wrapper around ptrace(PTRACE_POKEDATA, ...) to mirror Windows' WriteProcessMemory().

answered 2010-02-14T05:31:16.480
-1

clone or mmap are what you are looking for. mmap a temp file between the two processes and use that memory space for passing data back and forth.

answered 2010-03-26T21:50:55.737

Your Answer