Background of the Invention
1. Field of the Invention
This invention relates to debugging computer systems, and more particularly to a debugging engine that is resident in the hardware/software interface segment of memory on a development computing system and communicates debugging information to a remote host computer via a parallel port on the development system.
2. Background Art
BIOS Background
The architecture of most computers is generally defined by functional layers. The lowest layer is the hardware-the actual machine. The highest layer is the application program that interfaces with a user. In between the hardware and application program is the system software. The system software itself may be composed of several elements, including: the operating system kernel and shell, device drivers, and, perhaps, a multitasking supervisor.
Most architectures also include a low-level software layer between the hardware and the system software, called BIOS--Basic Input/Output System. The BIOS insulates the system and application software from the hardware by providing primitive I/O services and by handling interrupts issued by the computing system. Most computing systems are mainly controlled through the use of interrupts. Interrupts can be generated by the microprocessor, by the system hardware, or by software. The BIOS provides a logical handling of the interrupt signals. When an interrupt occurs, control of the computer is transferred to an interrupt vector which defines the "segment:offset" address of the routing in BIOS assigned to the given interrupt number.
BIOS Interrupt Service Routines (ISRs) handle interrupts issued by hardware devices. ISRs use registers in the microprocessor and BIOS data areas. The BIOS Device Service Routines (DSRs) handle software interrupts issued by the INT instruction.
The BIOS generally uses three data areas in RAM, including the Interrupt Vector Table, the BIOS Data Area, and the Extended BIOS Data Area (e.g., for power management). The BIOS also uses various input/output (I/O) ports.
BIOS Debugging
Debugging a computer system at the BIOS level is conventionally done with an in-circuit emulator (ICE). An ICE physically replaces the CPU in the development or target machine. The ICE is connected to the development machine through one buffer and with the host computer through another buffer. BIOS commands are received by the ICE through the buffers and processed by RAM resident in the ICE. The development computer BIOS accesses the ICE RAM exactly as if it was on the development machine. Attempts have been made to make ICE machines faster in order to handle debugging processing requirements. See for example, U.S. Pat. No. 4,674,089 (Poret, et al.) that discloses an improved very large scale integrated ICE that attaches to the motherboard.
ICE technology has many severe limitations. For example, ICE software is platform or CPU-specific and very expensive (around $50,000 per platform). An ICE tester is large and requires physical setup (removal of target CPU). This also necessitates a socket on the target machine for hookup. In addition, system specific ICE software may not be available when a new chip enters the market, thus ICE testing of development systems using the new chip are not possible.
Some modifications to minimize the amount of external circuitry required have been made in various debug peripherals or daughter boards. See, for example, U.S. Pat. No. 5,053,949 (Allison et al.) or U.S. Pat. No. 5,047,926 (Kuo, et at.). However, these systems still required a physical connection to the development machine CPU memory space, e.g., via CPU TAP, an internal CPU data bus connection, or ROM (read only memory) socket, and also require peripheral buffers.
Software debugging programs, such as Soft-ICE, allow for analysis of application-issued BIOS commands. However, these systems assume fully functional hardware, microprocessor, memory, stack, BIOS, and operating system on the development machine. Only BIOS commands to/from the application program are analyzed.
Limitations of the prior art reveal the need for a BIOS-level real-time debugger that is resident on the development system and does not require external circuitry for the debugging interface. It would also be desirable to have a low-cost, easily installed and accessible, low-level debugger capable of communicating debugging information to a remote host computer. Furthermore, it would be desirable to have such a system on a development machine that may not have RAM, a stack, a booted operating system, power management, or otherwise be fully functional.
Summary of the Invention
A debug engine is resident in the BIOS segment of memory in a development system. Interrupt-handling macros direct debug codes issuing from the development system to the debug engine. The debug engine sends the codes to a remote host computer via a communication channel (e.g., a bi-directional parallel port) on the development system. The contents of various registers on the development system are saved on the host computer and later restored to the development system. Thus, the present invention can be used in a stackless environment. Debug commands can be issued from the host computer to the development system via the communications channel. Such commands are processed in accordance with program instructions in the debug engine. Data associated with the development system (e.g., memory dump) may be sent to the host computer via the communications channel in response to a debug command.
In one embodiment, BIOS-level macros (e.g., in segment F000) comprise a near entry macro that provides the offset of the debug engine in the BIOS. Non-BIOS-level macros comprise a far entry macro that provides the segment and offset of the debug engine. Debug codes are passed to the entry macros as parameters or by using a memory register (e.g., the AL memory register) .
Brief Description of the Drawings
FIG. 1 is a simplified block diagram of the debugging invention.
FIG. 2 is a simplified block diagram of one embodiment of debug engine 112.
FIG. 3 is a flowchart of one embodiment of the interrupt-handling method of the debugging invention.
FIG. 4 is a continuation of FIG. 3 and is a flowchart of one embodiment of the debug command processing method of the debugging invention.
Description of the Preferred Embodiments
FIG. 1 shows a block diagram of software and hardware tools for
implementing one embodiment of the present debugging invention 100. Debugging generally refers to, for example, error, fault, interrupt, or operation signal detection and/or monitoring, and/or the handling, diagnosing, or analyzing such information. Target or development system 102 is a computing system under development and is the subject of the debugging effort. Development system 102 may be a computer, a computer board, or other computing system or subsystem, and may comprise a processor 104, communications channel 106, and memory 108. Processor 104 may be a central processing unit (CPU) (e.g., Intel 80386, 80486, Pentium; Motorola 68020, 68030, RISC processor, SPARC processors and the like) or similar computer processing elements. Communications channel 106 is communicatively coupled to processor 104. Communications channel 106 may be a conventional communication port such as a bi-directional parallel or a serial port. Memory 108 is coupled to processor 104. Memory 108 may be conventional computer memory such ROM or RAM storage. In a preferred embodiment memory 108 is read only memory (ROM). Memory (or portions of memory) 108 may be fabricated into a silicon chip (e.g., a ROM chip).
Memory 108 comprises a low-level software system, interrupt-handling, or basic input/output system (BIOS), module, or portion 110 that communicates between hardware and software elements of development system 102. According to the present invention, BIOS 110 comprises debug module, program, means, or engine 112. As described in detail below, debug engine 112 facilitates the debugging of development system 102 by sending debug codes issued by development system 102 to host computer 118. Host computer 118 sends debug commands 120 to debug engine 112, which responds with appropriate action and/or sends debug data to host computer 118.
Development system 102 may also comprise additional memory or random access memory (RAM) 114 coupled to processor 104. Memory 114 may be conventional computer memory such as that provided by RAM on a computer chip, a RAM disk, and the like. Development system 102 may also comprise various other communications and/or input/output (I/O) ports 116. Port 116 may include a port for displaying debug codes (sometimes called"port 80" as is conventionally known in the art).
Development system 102 is communicatively coupled to host computer 118. Communication may be between a port 106 in development system 102 and a port in host computer 118 (not shown) with a conventional cable. Alternate modes of communication, such as fiber optic or infrared communications are also possible. In one embodiment, a bi-directional parallel port in host computer 118 is connected to a bi-directional parallel port 106 in development system 102 via a conventional DB 25 (25 pin) 8 channel straight through male to male parallel cable with the following modifications:
Pin 1 of side A connected to pin 11 of side B;
Pin 11 of side A connected to pin 1 of side B;
Pin 13 of side A connected to pin 14 of side B;
Pin 14 of side A connected to pin 13 of side B;
Pin 17 disconnected. Alternatively, a serial port in the host computer 118 is connected to a serial port 106 in the development system 102 via a conventional DB25/3 channel cable.
Host system, platform, or computer 118 may be any conventional computing system such as an IBM PC or compatible, a Macintosh, DEC, Sun or Hewlett-Packard workstation, and the like. Host computer 118 generally comprises a processor, monitor, keyboard, and/or mouse (not shown) for data input/output from/to a user. In the present invention, host computer 118 comprises debug software 120 and optionally user interface 122.
Debug software 120 provides conventional debugging tools and commands. Debug software 120 may depend on development system 102 being debugged and BIOS 110 running on development system 102. Typical command capabilities provided by debug software may comprise: memory dump, move memory data, modify memory content, trace, break address, replace debug code, exit process, go execute process, go to next debug code and stop, interrupt set, break address replace, disable break address (e.g., DR0 for Intel products), disassembly of the next instruction, initialize parallel port, dump registers, dump output of debug session to file, symbolic debugging, help, and the like. See, for example, the commands set forth in Appendix A which is attached thereto to form a part hereof.
User interface 122 provides, for example, display capability of data returned from development system 102, debug command entry, and other conventional user interface utilities such as windowing, text display, and graphics. This utility 122 may also serve as a general purpose hardware editor allowing the user to edit RAM, I/O ports, or registers, and the like.
FIG. 2 is a simplified block diagram illustrating BIOS 110 including debug engine 112. In one embodiment, debug engine 112 boot defaults are setup at memory location F000:E3f0H of PhoenixBIOS 1.03 (also called CBG103), and in the BCPS.INC file in PhoenixBIOS 4.0 (also called NuBIOS). See Tables I and II below. PhoneixBIOS 1.03 and PhoenixBIOS 4.0 are comercially available BIOS. Debug engine 112 facilitates the debugging of development system 102. Debug codes 205 are sent to host computer 118. Host computer 118 sends debug commands to debug engine 112, which executes the debug command on development system 102 and may send debug data to host computer 118. Debug engine 112 itself requires approximately 3K bytes in BIOS 110. A flowchart of the interrupt-handling and debug command processing of debug engine 112 is further detailed below with reference to FIGS. 3 and 4.
Conventionally, certain events or interrupts 201,208 during operation of development system 102 initiate macros, functions, or programs 203,209 in BIOS 110 that output information or codes 205 to a designated manufacturing diagnostics port. These events 201,208 may occur, for example, during the power-on-self-test (POST) of the development system, the providing of BIOS services, power management services, operating system startup, power management runtime services, and/or application software services. The designated diagnostics port 116 is generally port 080H, thus macros 203,209 are commonly referred to as port 80 macros and codes 205 are referred to as port 80 codes. See, for example, a list of port 80 codes as set forth in Appendix B which is attached hereto to form a part hereof. In addition,"beep codes" 205 are used to identify POST errors that occur when a monitor or screen is not available (e.g., not available or not functioning). See also Appendix B for example beep codes. Beep, status, warning, debug, port 80, interrupt, operating system, error, signal, diagnostic, and other similar information output from development system 102 are collectively referred to as "codes" 205. Normally, these codes 205 are not displayed. However, during development of development system 102, a diagnostic computer card can be inserted into a port 80 slot (116) to display the output codes 205. Such computer cards are conventionally known as diagnostic port 80 cards and are commercially available. As described above, certain ICE machines can also access some of these codes 205.
According to the present invention, BIOS-segment macro 203 (e.g., an interrupt-handling macro in segment F000) comprises near entry macro 207. Near entry macro 207 directs output code 205 to debug engine 112. From debug engine 112 code 205 can be sent to host 118 via communication channel 106. Near entry interrupts or events 201 only require an offset address to enter debug engine 112 (as opposed to a segment and offset) because they occur in the BIOS segment where debug engine 112 is normally located (e.g., F000segment). In one embodiment, near entry macro 207 is approximately 19 bytes. See Appendix C for a listing of example entry macros for PhoenixBIOS 1.03 and PhoneixBIOS 4.0
Similarly, various interrupts or events occurring in segments other than BIOS segment, or far entry events 208, also initiate interrupt-handling macros 209 that output codes 205. For example, power management, operating system (OS), video, application software interrupts, and other programs that do not reside in the BIOS segment may initiate interrupts that are handled by macros 209. Macro 209 comprises far entry macro 211 which also directs output code 205 to debug engine 112. Far entry macro 211 provides, among other things, the segment and address of debug engine 112 (e.g., F000:E3f0H in PhoenixBIOS 1.03). The size of far entry macro is approximately 44 bytes. Far entry macro 211 also comprises a reference to the segment it is used in. This enables debug engine 112 to return to the running program correctly after a debugging session. For example, to use the invention in a power management macro 209, far entry macro 211 should reference the segment that power management is running in. See Appendix C for a listing of example entry macros for PhoenixBIOS 1.03 and PhoneixBIOS 4.0
The function of near 207 and far 211 entry macros can be accomplished in one entry macro, however, memory is saved by providing separate entry macros for each type of macro. For example, one macro that provides to an interrupt macro 203/209 the segment:offset location of debug engine 112 in BIOS 110 and a reference to the macro it is used in could be constructed. Alternatively, a separate custom entry macro could be provided for each every macro 203,209.
Most CPUs have temporary storage registers (e.g., DR0 through DR7 in Itnel products). In one embodiment, near 207 and far 211 entry macros utilize various CPU debug registers for temporary storage (e.g., DR1 through DR3 registers). In one embodiment, if BIOS 100 is PhoneixBIOS 4.0 and debug engine 112 is not included in the BIOS segment, the contents of the debug registers (e.g., DR0-DR 7) will not be modified or destroyed. Thus, after debugging development system 102, debug engine 112 can be disabled (e.g., not linked into BIOS) without further effect on development system 102.
In one embodiment, code 205 is passed to entry macros 207, 211 as a parameter or by using a register (e.g., AL register). Both near 207 and far 211 entry macros can execute in stack or stackless environments. Also, in macros 203, 209, some "JMP short" (e.g., jump less than a set number of addresses) instructions might have to be changed to regular JMP instructions because of the additional address space occupied by the near 207 and far 211 entry macros.
If too many macros 203,209 (e.g., port 80 code display macros) have been modified to include entry macros 207, 211, BIOS 110 may be too large and build incorrectly (e.g., link and compile incorrectly). Several steps can be taken to alleviate this problem. For example, the unused features in BIOS or Power Management may be turned off to create more space, or the BIOS size may be made larger (e.g., modify Code Size and the ROM size in ROMOPT.INC file in PhoenixBIOS 1.03), or unused port 80 macros in the BIOS may be removed, or only the macros 203,209 for areas to be debugged (e.g., BIOS, Power Management, Video) may be modified to include entry macros 207, 211.
It is also possible to enter debug engine 112 via a break address set or DR0 interrupt 1 (213). When the address of the instruction being executed on development system 102 is equal to the address set in DR0, the break address, then a break entry into debug engine 112, defined by interrupt vector 1, will be made 213.
Debug engine 112 also comprises various debug command modules 217 that perform various debug commands such as memory dump, move memory data, modify memory content, trace break address, replace debug code, exit process, go execute process, go to next debug code, interrupt set, break address replace, disable DR0 break, and the like. Debug engine 112 receives debug commands form host computer 118 via communication channel 106 (e.g., bi-directional parallel port) and responds by executing command modules 217 and sending data, if requested, to host 118 via communication channel 106. Commands may be entered by a user through debug software 120 and/or user interface 122 running on host computer 118. Thus, the user is able to remotely and interactively debug development system 102 via communication channel 106. Debug mode or I/O mode 219 may be selectively set by the user to alter the communication of codes 205 to I/O port 116 (e.g., port 80) and/or communication channel 106. In one embodiment, BIOS 110 is PhoenixBIOS 1.03, and debug mode 219 may be set as follows: in the COMPAS.ASM file, the following lines as set forth in Table I are added before the SYNCA HRDDSRA hard disk DSR interrupt 13h:
In another embodiment, BIOS 110 is PhoenixBIOS 4.0, and debug mode 219 is set in the C:.backslash.NUBIOS.backslash.INCLUDE.backslash.BCPS.INC file, by setting values to variables as set forth in Table II according to the communication port 106 available on development system 102.
Then, add to the BCP.ASM file at the SAMPLES or OEM level to link the debug engine to the BIOS:
MAKE.sub.-- BC P.sub.-- DEBUG
INSTALL.sub.-- DEBUG
When debug mode 219 is set to direct codes 205 to communication channel 106, the user needs to ensure that the communication channel chosen 106 is properly programmed and functional. One embodiment of debug engine 112 assumes that parallel port 106 always power up bi-directional, enabled, and set to port 3BCH. Most parallel ports are bi-directional parallel ports and usually default to bi-directional and enabled upon power up or reset. However, some development systems 102 may require the parallel port to be specifically enabled, assigned a certain address, and/or set to bi-directional after every power up or reset. If so, initialization code may be added to debug engine 112 prior to use. Parallel port base address can be modified to, for example, 3BCH, 378H, or 278H as specified above.
FIGS. 3 and 4 comprise a flowchart of one embodiment of the debugging method of the present invention. As described with reference to FIG. 2, depending on event 201,208, either near entry macro 207 (e.g, interrupts from segment F000H) or far entry macro 211 (e.g., interrupts from segments other than F000H) is used by macros 203,209, respectively, to enter debug engine 112. Unless all debug communication is disabled (e.g., debug mode 219 is 0 in Table I), code 205 is output 301 to port 80 or other designated diagnostics port. If communication to host computer 118 is not enabled 303 (e.g., debug mode 219 is 1 in Table I), a return 305 is made to the program running on development system 102 (e.g., at the next address). Another code 205 may then processed similarly. If communication to host computer is enabled 303 (e.g., debug mode 219 is not 0 or 1 in Table I), the contents of various registers in development system 102 are saved 307 on host computer 118 via communication channel 106 (see Table I or II for communication channel designation, for example). Because the development system 102 registers are saved on host computer 118, the present invention can be used in a stackless environment. Alternatively, development system registers can be pushed to a stack on development system 102, if available. A communication channel error check is made 309, and code 205 is sent 311 to host computer 118 via communication channel 106.
The method illustrated in the flowchart of FIG. 3 continues 311 in FIG. 4. After sending code 205 to host computer 118 (311 ), debug engine 112 determines 413 if a stop/wait flag is set, or if code 205 is a designated debug code (e.g., port 80 or beep code). If the determination at step 413 is "no", the contents of all registers are restored from host computer 118 via communication channel 106 (447) and a return to the program running on development system 102 may resume 449 (e.g., at the next address). Another code 205 may be processed similarly.
If the determination at step 413 is "yes" (e.g., stop/wait flag set or break code is equal to a designated break code), development system 102 stops executing and debug engine 112 awaits a debug command from host computer 118 via communication channel 106 (415). Depending on debug command 417 issued from host computer 118, debug engine 112 responds by executing the requested command 417 on development system 102. Conventional debug commands 417 may be issued to debug engine 112 as determined by, for example, debug software 120 running on host computer 118. See above in reference to debug 120 and Appendix A for a list of typical commands. Debug engine 112 comprises modules 419-443 (217) that, for example, execute the command 417 on development system 102, send data to host computer 118, and/or return to the running program.
For example, debug engine 112 may comprise the following modules in order to execute the corresponding command 417: exit process 419 or go execute process 421 (followed by exit process 419), will exit the debug engine process 447 and return to the next program process or return and execute the designated process 449; interrupt 1 vector set 423 sets a break address (set break entry point 213); break address replace 425, replaces the break address; disable DR0 break 427 disables the DR0 break interrupt; replace debug code 429 replaces the designated debug break code; memory dump 431 reads current memory storage, or a subset thereof (e.g., ROM 108 and/or RAM 114) and sends this information to host computer 118 (445); move memory data 433 moves memory in memory (e.g., RAM 114); trace 437, turns the tracer on and sends such data to host computer 118 (445); input from port 439 instructs debug engine to read data or an instruction from a designated I/O port; output to port 44 1 instructs debug engine to write to a designated I/O port. Other commands 417 may also be similarly implemented in corresponding modules 443.
Note, for the PhoenixBIOS 1.03 base code 110, when entering the power management SMI (system management interface) environment, debug engine 112 saves 307 and restores 447 the CPU debug registers (e.g., DR0 through DR7 for Intel products). Thus, if the user sets a break at an address (e.g., using DR0) 425 inside the SMI mode, this address may be overwritten when the registers are restored 447. Therefore, the save 307 and restore 447 routines of debug engine 112 may be removed to avoid overwriting.
When entering the SMI environment, the CPU 104 copies the content of the DR7 CPU register to SMRAM, clears the DR7 register and then restores its contents upon exit from SMI. This will disable the user specified break at an address feature 425 while in the SMI mode. Accordingly, the contents the DR7 register may be restored upon entry to the SMI environment from the SMRAM, or the break address command can be reactivated while inside the SMI.
Some parallel port cards may require substantial power to drive the input data to low (e.g., cards not designed according to conventional PS/2 bus standards). When such parallel port cards are used in conjunction with some notebook-type computers 112 which are designed to save power, development system 102 may not be able to drive parallel port data line 106. In this situation, a different parallel card (e.g., with lower power requirement), or a host computer 118 with a higher drive parallel port may be used.
During the initialization of development system 102 (e.g., during a POST), the operating system (e.g., DOS) may replace the interrupt vector 1 to its own interrupt vector. Therefore, interrupt vector 1 break addresses set 423 during POST and before DOS is initialized may not break at the address selected if the execution of the address happens after DOS boot. Break addresses set after DOS boot 423 will replace the interrupt vector 1 and will function correctly. Also, in order to break at an address specified by the user 423, the CPU requires stack space in memory 108. Thus, in a no-stack environment, alternate stack space is required in order to break at a specified address 423.