4 * LTTng syscall probes.
6 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; only
11 * version 2.1 of the License.
13 * This library is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with this library; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
23 #include <linux/module.h>
24 #include <linux/slab.h>
25 #include <linux/compat.h>
26 #include <linux/err.h>
27 #include <linux/bitmap.h>
29 #include <linux/in6.h>
30 #include <linux/seq_file.h>
31 #include <linux/stringify.h>
32 #include <linux/file.h>
33 #include <linux/anon_inodes.h>
34 #include <asm/ptrace.h>
35 #include <asm/syscall.h>
37 #include "lib/bitfield.h"
38 #include "wrapper/tracepoint.h"
39 #include "lttng-events.h"
42 # ifndef is_compat_task
43 # define is_compat_task() (0)
54 #define SYSCALL_ENTRY_TOK syscall_entry_
55 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
56 #define SYSCALL_EXIT_TOK syscall_exit_
57 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
59 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
60 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
61 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
62 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
65 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
67 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
70 * Forward declarations for old kernels.
74 struct oldold_utsname
;
76 struct sel_arg_struct
;
77 struct mmap_arg_struct
;
79 #ifdef IA32_NR_syscalls
80 #define NR_compat_syscalls IA32_NR_syscalls
82 #define NR_compat_syscalls NR_syscalls
86 * Create LTTng tracepoint probes.
88 #define LTTNG_PACKAGE_BUILD
89 #define CREATE_TRACE_POINTS
90 #define TP_MODULE_NOINIT
91 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
93 #define PARAMS(args...) args
95 /* Handle unknown syscalls */
97 #define TRACE_SYSTEM syscalls_unknown
98 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
106 #define sc_in(...) __VA_ARGS__
110 #define sc_inout(...) __VA_ARGS__
112 /* Hijack probe callback for system call enter */
114 #define TP_PROBE_CB(_template) &syscall_entry_probe
115 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
116 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
117 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
118 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
119 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
120 PARAMS(_locvar), PARAMS(_code), \
121 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
122 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
123 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_struct), PARAMS(_assign), \
125 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
126 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
128 #define TRACE_SYSTEM syscall_entry_integers
129 #define TRACE_INCLUDE_FILE syscalls_integers
130 #include "instrumentation/syscalls/headers/syscalls_integers.h"
131 #undef TRACE_INCLUDE_FILE
133 #define TRACE_SYSTEM syscall_entry_pointers
134 #define TRACE_INCLUDE_FILE syscalls_pointers
135 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
136 #undef TRACE_INCLUDE_FILE
138 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
139 #undef SC_LTTNG_TRACEPOINT_EVENT
140 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
141 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
143 #undef _TRACE_SYSCALLS_INTEGERS_H
144 #undef _TRACE_SYSCALLS_POINTERS_H
146 /* Hijack probe callback for compat system call enter */
147 #define TP_PROBE_CB(_template) &syscall_entry_probe
148 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
149 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
150 PARAMS(_struct), PARAMS(_assign), \
152 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
153 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
154 PARAMS(_locvar), PARAMS(_code), \
155 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
156 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
157 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_struct), \
158 PARAMS(_assign), PARAMS(_printk))
159 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
160 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
161 compat_syscall_entry_##_name)
162 #define TRACE_SYSTEM compat_syscall_entry_integers
163 #define TRACE_INCLUDE_FILE compat_syscalls_integers
164 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
165 #undef TRACE_INCLUDE_FILE
167 #define TRACE_SYSTEM compat_syscall_entry_pointers
168 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
169 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
170 #undef TRACE_INCLUDE_FILE
172 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
173 #undef SC_LTTNG_TRACEPOINT_EVENT
174 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
175 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
177 #undef _TRACE_SYSCALLS_INTEGERS_H
178 #undef _TRACE_SYSCALLS_POINTERS_H
185 #define sc_exit(...) __VA_ARGS__
189 #define sc_out(...) __VA_ARGS__
191 #define sc_inout(...) __VA_ARGS__
193 /* Hijack probe callback for system call exit */
194 #define TP_PROBE_CB(_template) &syscall_exit_probe
195 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
196 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
197 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
198 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
199 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
200 PARAMS(_locvar), PARAMS(_code), \
201 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
202 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
203 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_struct), \
204 PARAMS(_assign), PARAMS(_printk))
205 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
206 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
207 syscall_exit_##_name)
208 #define TRACE_SYSTEM syscall_exit_integers
209 #define TRACE_INCLUDE_FILE syscalls_integers
210 #include "instrumentation/syscalls/headers/syscalls_integers.h"
211 #undef TRACE_INCLUDE_FILE
213 #define TRACE_SYSTEM syscall_exit_pointers
214 #define TRACE_INCLUDE_FILE syscalls_pointers
215 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
216 #undef TRACE_INCLUDE_FILE
218 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
219 #undef SC_LTTNG_TRACEPOINT_EVENT
220 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
221 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
223 #undef _TRACE_SYSCALLS_INTEGERS_H
224 #undef _TRACE_SYSCALLS_POINTERS_H
227 /* Hijack probe callback for compat system call exit */
228 #define TP_PROBE_CB(_template) &syscall_exit_probe
229 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
230 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
231 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
232 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
233 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
234 PARAMS(_locvar), PARAMS(_code), \
235 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
236 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
237 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_struct), \
238 PARAMS(_assign), PARAMS(_printk))
239 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
240 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
241 compat_syscall_exit_##_name)
242 #define TRACE_SYSTEM compat_syscall_exit_integers
243 #define TRACE_INCLUDE_FILE compat_syscalls_integers
244 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
245 #undef TRACE_INCLUDE_FILE
247 #define TRACE_SYSTEM compat_syscall_exit_pointers
248 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
249 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
250 #undef TRACE_INCLUDE_FILE
252 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
253 #undef SC_LTTNG_TRACEPOINT_EVENT
254 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
255 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
257 #undef _TRACE_SYSCALLS_INTEGERS_H
258 #undef _TRACE_SYSCALLS_POINTERS_H
262 #undef TP_MODULE_NOINIT
263 #undef LTTNG_PACKAGE_BUILD
264 #undef CREATE_TRACE_POINTS
266 struct trace_syscall_entry
{
268 const struct lttng_event_desc
*desc
;
269 const struct lttng_event_field
*fields
;
273 #define CREATE_SYSCALL_TABLE
280 #undef TRACE_SYSCALL_TABLE
281 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
283 .func = __event_probe__syscall_entry_##_template, \
284 .nrargs = (_nrargs), \
285 .fields = __event_fields___syscall_entry_##_template, \
286 .desc = &__event_desc___syscall_entry_##_name, \
289 /* Syscall enter tracing table */
290 static const struct trace_syscall_entry sc_table
[] = {
291 #include "instrumentation/syscalls/headers/syscalls_integers.h"
292 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
295 #undef TRACE_SYSCALL_TABLE
296 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
298 .func = __event_probe__compat_syscall_entry_##_template, \
299 .nrargs = (_nrargs), \
300 .fields = __event_fields___compat_syscall_entry_##_template, \
301 .desc = &__event_desc___compat_syscall_entry_##_name, \
304 /* Compat syscall enter table */
305 const struct trace_syscall_entry compat_sc_table
[] = {
306 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
307 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
315 #define sc_exit(...) __VA_ARGS__
317 #undef TRACE_SYSCALL_TABLE
318 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
320 .func = __event_probe__syscall_exit_##_template, \
321 .nrargs = (_nrargs), \
322 .fields = __event_fields___syscall_exit_##_template, \
323 .desc = &__event_desc___syscall_exit_##_name, \
326 /* Syscall exit table */
327 static const struct trace_syscall_entry sc_exit_table
[] = {
328 #include "instrumentation/syscalls/headers/syscalls_integers.h"
329 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
332 #undef TRACE_SYSCALL_TABLE
333 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
335 .func = __event_probe__compat_syscall_exit_##_template, \
336 .nrargs = (_nrargs), \
337 .fields = __event_fields___compat_syscall_exit_##_template, \
338 .desc = &__event_desc___compat_syscall_exit_##_name, \
341 /* Compat syscall exit table */
342 const struct trace_syscall_entry compat_sc_exit_table
[] = {
343 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
344 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
349 #undef CREATE_SYSCALL_TABLE
351 struct lttng_syscall_filter
{
352 DECLARE_BITMAP(sc
, NR_syscalls
);
353 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
356 static void syscall_entry_unknown(struct lttng_event
*event
,
357 struct pt_regs
*regs
, unsigned int id
)
359 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
361 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
362 if (unlikely(is_compat_task()))
363 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
365 __event_probe__syscall_entry_unknown(event
, id
, args
);
368 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
370 struct lttng_channel
*chan
= __data
;
371 struct lttng_event
*event
, *unknown_event
;
372 const struct trace_syscall_entry
*table
, *entry
;
375 if (unlikely(is_compat_task())) {
376 struct lttng_syscall_filter
*filter
;
378 filter
= rcu_dereference(chan
->sc_filter
);
380 if (id
< 0 || id
>= NR_compat_syscalls
381 || !test_bit(id
, filter
->sc_compat
)) {
382 /* System call filtered out. */
386 table
= compat_sc_table
;
387 table_len
= ARRAY_SIZE(compat_sc_table
);
388 unknown_event
= chan
->sc_compat_unknown
;
390 struct lttng_syscall_filter
*filter
;
392 filter
= rcu_dereference(chan
->sc_filter
);
394 if (id
< 0 || id
>= NR_syscalls
395 || !test_bit(id
, filter
->sc
)) {
396 /* System call filtered out. */
401 table_len
= ARRAY_SIZE(sc_table
);
402 unknown_event
= chan
->sc_unknown
;
404 if (unlikely(id
< 0 || id
>= table_len
)) {
405 syscall_entry_unknown(unknown_event
, regs
, id
);
408 if (unlikely(is_compat_task()))
409 event
= chan
->compat_sc_table
[id
];
411 event
= chan
->sc_table
[id
];
412 if (unlikely(!event
)) {
413 syscall_entry_unknown(unknown_event
, regs
, id
);
417 WARN_ON_ONCE(!entry
);
419 switch (entry
->nrargs
) {
422 void (*fptr
)(void *__data
) = entry
->func
;
429 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
430 unsigned long args
[1];
432 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
433 fptr(event
, args
[0]);
438 void (*fptr
)(void *__data
,
440 unsigned long arg1
) = entry
->func
;
441 unsigned long args
[2];
443 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
444 fptr(event
, args
[0], args
[1]);
449 void (*fptr
)(void *__data
,
452 unsigned long arg2
) = entry
->func
;
453 unsigned long args
[3];
455 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
456 fptr(event
, args
[0], args
[1], args
[2]);
461 void (*fptr
)(void *__data
,
465 unsigned long arg3
) = entry
->func
;
466 unsigned long args
[4];
468 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
469 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
474 void (*fptr
)(void *__data
,
479 unsigned long arg4
) = entry
->func
;
480 unsigned long args
[5];
482 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
483 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
488 void (*fptr
)(void *__data
,
494 unsigned long arg5
) = entry
->func
;
495 unsigned long args
[6];
497 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
498 fptr(event
, args
[0], args
[1], args
[2],
499 args
[3], args
[4], args
[5]);
507 static void syscall_exit_unknown(struct lttng_event
*event
,
508 struct pt_regs
*regs
, int id
, long ret
)
510 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
512 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
513 if (unlikely(is_compat_task()))
514 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
517 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
520 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
522 struct lttng_channel
*chan
= __data
;
523 struct lttng_event
*event
, *unknown_event
;
524 const struct trace_syscall_entry
*table
, *entry
;
528 id
= syscall_get_nr(current
, regs
);
529 if (unlikely(is_compat_task())) {
530 struct lttng_syscall_filter
*filter
;
532 filter
= rcu_dereference(chan
->sc_filter
);
534 if (id
< 0 || id
>= NR_compat_syscalls
535 || !test_bit(id
, filter
->sc_compat
)) {
536 /* System call filtered out. */
540 table
= compat_sc_exit_table
;
541 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
542 unknown_event
= chan
->compat_sc_exit_unknown
;
544 struct lttng_syscall_filter
*filter
;
546 filter
= rcu_dereference(chan
->sc_filter
);
548 if (id
< 0 || id
>= NR_syscalls
549 || !test_bit(id
, filter
->sc
)) {
550 /* System call filtered out. */
554 table
= sc_exit_table
;
555 table_len
= ARRAY_SIZE(sc_exit_table
);
556 unknown_event
= chan
->sc_exit_unknown
;
558 if (unlikely(id
< 0 || id
>= table_len
)) {
559 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
562 if (unlikely(is_compat_task()))
563 event
= chan
->compat_sc_exit_table
[id
];
565 event
= chan
->sc_exit_table
[id
];
566 if (unlikely(!event
)) {
567 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
571 WARN_ON_ONCE(!entry
);
573 switch (entry
->nrargs
) {
576 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
583 void (*fptr
)(void *__data
,
585 unsigned long arg0
) = entry
->func
;
586 unsigned long args
[1];
588 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
589 fptr(event
, ret
, args
[0]);
594 void (*fptr
)(void *__data
,
597 unsigned long arg1
) = entry
->func
;
598 unsigned long args
[2];
600 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
601 fptr(event
, ret
, args
[0], args
[1]);
606 void (*fptr
)(void *__data
,
610 unsigned long arg2
) = entry
->func
;
611 unsigned long args
[3];
613 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
614 fptr(event
, ret
, args
[0], args
[1], args
[2]);
619 void (*fptr
)(void *__data
,
624 unsigned long arg3
) = entry
->func
;
625 unsigned long args
[4];
627 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
628 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
633 void (*fptr
)(void *__data
,
639 unsigned long arg4
) = entry
->func
;
640 unsigned long args
[5];
642 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
643 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
648 void (*fptr
)(void *__data
,
655 unsigned long arg5
) = entry
->func
;
656 unsigned long args
[6];
658 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
659 fptr(event
, ret
, args
[0], args
[1], args
[2],
660 args
[3], args
[4], args
[5]);
668 /* noinline to diminish caller stack size */
670 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
671 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
672 void *filter
, enum sc_type type
)
674 const struct lttng_event_desc
*desc
;
677 /* Allocate events for each syscall, insert into table */
678 for (i
= 0; i
< table_len
; i
++) {
679 struct lttng_kernel_event ev
;
680 desc
= table
[i
].desc
;
683 /* Unknown syscall */
687 * Skip those already populated by previous failed
688 * register for this channel.
692 memset(&ev
, 0, sizeof(ev
));
695 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
696 LTTNG_KERNEL_SYM_NAME_LEN
);
699 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
700 LTTNG_KERNEL_SYM_NAME_LEN
);
702 case SC_TYPE_COMPAT_ENTRY
:
703 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
704 LTTNG_KERNEL_SYM_NAME_LEN
);
706 case SC_TYPE_COMPAT_EXIT
:
707 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
708 LTTNG_KERNEL_SYM_NAME_LEN
);
714 strncat(ev
.name
, desc
->name
,
715 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
716 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
717 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
718 chan_table
[i
] = lttng_event_create(chan
, &ev
, filter
,
720 WARN_ON_ONCE(!chan_table
[i
]);
721 if (IS_ERR(chan_table
[i
])) {
723 * If something goes wrong in event registration
724 * after the first one, we have no choice but to
725 * leave the previous events in there, until
726 * deleted by session teardown.
728 return PTR_ERR(chan_table
[i
]);
734 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
736 struct lttng_kernel_event ev
;
739 wrapper_vmalloc_sync_all();
741 if (!chan
->sc_table
) {
742 /* create syscall table mapping syscall to events */
743 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
744 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
748 if (!chan
->sc_exit_table
) {
749 /* create syscall table mapping syscall to events */
750 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
751 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
752 if (!chan
->sc_exit_table
)
758 if (!chan
->compat_sc_table
) {
759 /* create syscall table mapping compat syscall to events */
760 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
761 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
762 if (!chan
->compat_sc_table
)
766 if (!chan
->compat_sc_exit_table
) {
767 /* create syscall table mapping compat syscall to events */
768 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
769 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
770 if (!chan
->compat_sc_exit_table
)
774 if (!chan
->sc_unknown
) {
775 const struct lttng_event_desc
*desc
=
776 &__event_desc___syscall_entry_unknown
;
778 memset(&ev
, 0, sizeof(ev
));
779 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
780 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
781 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
782 chan
->sc_unknown
= lttng_event_create(chan
, &ev
, filter
,
784 WARN_ON_ONCE(!chan
->sc_unknown
);
785 if (IS_ERR(chan
->sc_unknown
)) {
786 return PTR_ERR(chan
->sc_unknown
);
790 if (!chan
->sc_compat_unknown
) {
791 const struct lttng_event_desc
*desc
=
792 &__event_desc___compat_syscall_entry_unknown
;
794 memset(&ev
, 0, sizeof(ev
));
795 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
796 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
797 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
798 chan
->sc_compat_unknown
= lttng_event_create(chan
, &ev
, filter
,
800 WARN_ON_ONCE(!chan
->sc_unknown
);
801 if (IS_ERR(chan
->sc_compat_unknown
)) {
802 return PTR_ERR(chan
->sc_compat_unknown
);
806 if (!chan
->compat_sc_exit_unknown
) {
807 const struct lttng_event_desc
*desc
=
808 &__event_desc___compat_syscall_exit_unknown
;
810 memset(&ev
, 0, sizeof(ev
));
811 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
812 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
813 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
814 chan
->compat_sc_exit_unknown
= lttng_event_create(chan
, &ev
,
816 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
817 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
818 return PTR_ERR(chan
->compat_sc_exit_unknown
);
822 if (!chan
->sc_exit_unknown
) {
823 const struct lttng_event_desc
*desc
=
824 &__event_desc___syscall_exit_unknown
;
826 memset(&ev
, 0, sizeof(ev
));
827 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
828 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
829 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
830 chan
->sc_exit_unknown
= lttng_event_create(chan
, &ev
, filter
,
832 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
833 if (IS_ERR(chan
->sc_exit_unknown
)) {
834 return PTR_ERR(chan
->sc_exit_unknown
);
838 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
839 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
842 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
843 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
848 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
849 chan
->compat_sc_table
, chan
, filter
,
850 SC_TYPE_COMPAT_ENTRY
);
853 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
854 chan
->compat_sc_exit_table
, chan
, filter
,
855 SC_TYPE_COMPAT_EXIT
);
859 if (!chan
->sys_enter_registered
) {
860 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
861 (void *) syscall_entry_probe
, chan
);
864 chan
->sys_enter_registered
= 1;
867 * We change the name of sys_exit tracepoint due to namespace
868 * conflict with sys_exit syscall entry.
870 if (!chan
->sys_exit_registered
) {
871 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
872 (void *) syscall_exit_probe
, chan
);
874 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
875 (void *) syscall_entry_probe
, chan
));
878 chan
->sys_exit_registered
= 1;
884 * Only called at session destruction.
886 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
892 if (chan
->sys_enter_registered
) {
893 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
894 (void *) syscall_exit_probe
, chan
);
897 chan
->sys_enter_registered
= 0;
899 if (chan
->sys_exit_registered
) {
900 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
901 (void *) syscall_entry_probe
, chan
);
904 chan
->sys_exit_registered
= 0;
906 /* lttng_event destroy will be performed by lttng_session_destroy() */
907 kfree(chan
->sc_table
);
908 kfree(chan
->sc_exit_table
);
910 kfree(chan
->compat_sc_table
);
911 kfree(chan
->compat_sc_exit_table
);
913 kfree(chan
->sc_filter
);
918 int get_syscall_nr(const char *syscall_name
)
923 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
924 const struct trace_syscall_entry
*entry
;
927 entry
= &sc_table
[i
];
930 it_name
= entry
->desc
->name
;
931 it_name
+= strlen(SYSCALL_ENTRY_STR
);
932 if (!strcmp(syscall_name
, it_name
)) {
941 int get_compat_syscall_nr(const char *syscall_name
)
946 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
947 const struct trace_syscall_entry
*entry
;
950 entry
= &compat_sc_table
[i
];
953 it_name
= entry
->desc
->name
;
954 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
955 if (!strcmp(syscall_name
, it_name
)) {
964 uint32_t get_sc_tables_len(void)
966 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
969 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
972 int syscall_nr
, compat_syscall_nr
, ret
;
973 struct lttng_syscall_filter
*filter
;
975 WARN_ON_ONCE(!chan
->sc_table
);
978 /* Enable all system calls by removing filter */
979 if (chan
->sc_filter
) {
980 filter
= chan
->sc_filter
;
981 rcu_assign_pointer(chan
->sc_filter
, NULL
);
985 chan
->syscall_all
= 1;
989 if (!chan
->sc_filter
) {
990 if (chan
->syscall_all
) {
992 * All syscalls are already enabled.
996 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1001 filter
= chan
->sc_filter
;
1003 syscall_nr
= get_syscall_nr(name
);
1004 compat_syscall_nr
= get_compat_syscall_nr(name
);
1005 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1009 if (syscall_nr
>= 0) {
1010 if (test_bit(syscall_nr
, filter
->sc
)) {
1014 bitmap_set(filter
->sc
, syscall_nr
, 1);
1016 if (compat_syscall_nr
>= 0) {
1017 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1021 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1023 if (!chan
->sc_filter
)
1024 rcu_assign_pointer(chan
->sc_filter
, filter
);
1028 if (!chan
->sc_filter
)
1033 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1036 int syscall_nr
, compat_syscall_nr
, ret
;
1037 struct lttng_syscall_filter
*filter
;
1039 WARN_ON_ONCE(!chan
->sc_table
);
1041 if (!chan
->sc_filter
) {
1042 if (!chan
->syscall_all
)
1044 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1048 /* Trace all system calls, then apply disable. */
1049 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1050 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1052 filter
= chan
->sc_filter
;
1056 /* Fail if all syscalls are already disabled. */
1057 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1058 && bitmap_empty(filter
->sc_compat
,
1059 NR_compat_syscalls
)) {
1064 /* Disable all system calls */
1065 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1066 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1069 syscall_nr
= get_syscall_nr(name
);
1070 compat_syscall_nr
= get_compat_syscall_nr(name
);
1071 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1075 if (syscall_nr
>= 0) {
1076 if (!test_bit(syscall_nr
, filter
->sc
)) {
1080 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1082 if (compat_syscall_nr
>= 0) {
1083 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1087 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1090 if (!chan
->sc_filter
)
1091 rcu_assign_pointer(chan
->sc_filter
, filter
);
1092 chan
->syscall_all
= 0;
1096 if (!chan
->sc_filter
)
1102 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1104 const struct trace_syscall_entry
*entry
;
1107 for (entry
= sc_table
;
1108 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1113 for (entry
= compat_sc_table
;
1114 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1124 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1126 return (void *) syscall_list_get_entry(pos
);
1130 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1133 return (void *) syscall_list_get_entry(ppos
);
1137 void syscall_list_stop(struct seq_file
*m
, void *p
)
1142 int get_sc_table(const struct trace_syscall_entry
*entry
,
1143 const struct trace_syscall_entry
**table
,
1144 unsigned int *bitness
)
1146 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1148 *bitness
= BITS_PER_LONG
;
1153 if (!(entry
>= compat_sc_table
1154 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1160 *table
= compat_sc_table
;
1165 int syscall_list_show(struct seq_file
*m
, void *p
)
1167 const struct trace_syscall_entry
*table
, *entry
= p
;
1168 unsigned int bitness
;
1169 unsigned long index
;
1173 ret
= get_sc_table(entry
, &table
, &bitness
);
1178 if (table
== sc_table
) {
1179 index
= entry
- table
;
1180 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1182 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1183 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1185 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1186 index
, name
, bitness
);
1191 const struct seq_operations lttng_syscall_list_seq_ops
= {
1192 .start
= syscall_list_start
,
1193 .next
= syscall_list_next
,
1194 .stop
= syscall_list_stop
,
1195 .show
= syscall_list_show
,
1199 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1201 return seq_open(file
, <tng_syscall_list_seq_ops
);
1204 const struct file_operations lttng_syscall_list_fops
= {
1205 .owner
= THIS_MODULE
,
1206 .open
= lttng_syscall_list_open
,
1208 .llseek
= seq_lseek
,
1209 .release
= seq_release
,
1212 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1213 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1215 uint32_t len
, sc_tables_len
, bitmask_len
;
1218 struct lttng_syscall_filter
*filter
;
1220 ret
= get_user(len
, &usyscall_mask
->len
);
1223 sc_tables_len
= get_sc_tables_len();
1224 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1225 if (len
< sc_tables_len
) {
1226 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1228 /* Array is large enough, we can copy array to user-space. */
1229 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1232 filter
= channel
->sc_filter
;
1234 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1237 if (channel
->sc_table
) {
1239 state
= test_bit(bit
, filter
->sc
);
1245 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1247 for (; bit
< sc_tables_len
; bit
++) {
1250 if (channel
->compat_sc_table
) {
1252 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1259 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1261 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1267 int lttng_abi_syscall_list(void)
1269 struct file
*syscall_list_file
;
1272 file_fd
= get_unused_fd();
1278 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1279 <tng_syscall_list_fops
,
1281 if (IS_ERR(syscall_list_file
)) {
1282 ret
= PTR_ERR(syscall_list_file
);
1285 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1288 fd_install(file_fd
, syscall_list_file
);
1296 fput(syscall_list_file
);
1298 put_unused_fd(file_fd
);