4 * Copyright 2010 (c) - Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * Dual LGPL v2.1/GPL v2 license.
11 #include <linux/module.h>
12 #include <linux/slab.h>
13 #include <linux/compat.h>
14 #include <asm/ptrace.h>
15 #include <asm/syscall.h>
17 #include "ltt-events.h"
20 static inline int is_compat_task(void)
26 static void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
29 * Take care of NOARGS not supported by mainline.
31 #define DECLARE_EVENT_CLASS_NOARGS(name, tstruct, assign, print)
32 #define DEFINE_EVENT_NOARGS(template, name)
33 #define TRACE_EVENT_NOARGS(name, struct, assign, print)
36 * Create LTTng tracepoint probes.
38 #define LTTNG_PACKAGE_BUILD
39 #define CREATE_TRACE_POINTS
40 #define TP_MODULE_OVERRIDE
41 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
43 /* Hijack probe callback for system calls */
44 #define TP_PROBE_CB(_template) &syscall_entry_probe
45 #include "instrumentation/syscalls/headers/syscalls_integers.h"
46 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
49 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
51 #undef TP_MODULE_OVERRIDE
52 #undef LTTNG_PACKAGE_BUILD
53 #undef CREATE_TRACE_POINTS
55 struct trace_syscall_entry
{
57 const struct lttng_event_desc
*desc
;
58 const struct lttng_event_field
*fields
;
62 #define CREATE_SYSCALL_TABLE
64 #undef TRACE_SYSCALL_TABLE
65 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
67 .func = __event_probe__##_template, \
68 .nrargs = (_nrargs), \
69 .fields = __event_fields___##_template, \
70 .desc = &__event_desc___##_name, \
73 static struct trace_syscall_entry sc_table
[] = {
74 #include "instrumentation/syscalls/headers/syscalls_integers.h"
75 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
78 #undef CREATE_SYSCALL_TABLE
80 static void syscall_entry_unknown(struct ltt_channel
*chan
,
81 struct pt_regs
*regs
, unsigned int id
)
83 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
84 struct ltt_event
*event
;
86 event
= chan
->sc_unknown
;
87 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
88 __event_probe__sys_unknown(event
, id
, args
);
92 * Currently, given that the kernel syscall metadata extraction only
93 * considers native system calls (not 32-bit compability ones), we
94 * fall-back on the "unknown" system call tracing for 32-bit compat.
96 static void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
98 struct trace_syscall_entry
*entry
;
99 struct ltt_channel
*chan
= __data
;
100 struct ltt_event
*event
;
102 if (unlikely(is_compat_task() || id
>= ARRAY_SIZE(sc_table
))) {
103 syscall_entry_unknown(chan
, regs
, id
);
106 event
= chan
->sc_table
[id
];
107 if (unlikely(!event
)) {
108 syscall_entry_unknown(chan
, regs
, id
);
111 entry
= &sc_table
[id
];
112 WARN_ON_ONCE(!entry
);
114 switch (entry
->nrargs
) {
117 void (*fptr
)(void *__data
) = entry
->func
;
124 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
125 unsigned long args
[1];
127 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
128 fptr(event
, args
[0]);
133 void (*fptr
)(void *__data
,
135 unsigned long arg1
) = entry
->func
;
136 unsigned long args
[2];
138 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
139 fptr(event
, args
[0], args
[1]);
144 void (*fptr
)(void *__data
,
147 unsigned long arg2
) = entry
->func
;
148 unsigned long args
[3];
150 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
151 fptr(event
, args
[0], args
[1], args
[2]);
156 void (*fptr
)(void *__data
,
160 unsigned long arg3
) = entry
->func
;
161 unsigned long args
[4];
163 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
164 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
169 void (*fptr
)(void *__data
,
174 unsigned long arg4
) = entry
->func
;
175 unsigned long args
[5];
177 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
178 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
183 void (*fptr
)(void *__data
,
189 unsigned long arg5
) = entry
->func
;
190 unsigned long args
[6];
192 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
193 fptr(event
, args
[0], args
[1], args
[2],
194 args
[3], args
[4], args
[5]);
202 int lttng_syscalls_register(struct ltt_channel
*chan
, void *filter
)
207 wrapper_vmalloc_sync_all();
209 if (!chan
->sc_table
) {
210 /* create syscall table mapping syscall to events */
211 chan
->sc_table
= kzalloc(sizeof(struct ltt_event
*)
212 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
217 if (!chan
->sc_unknown
) {
218 struct lttng_kernel_event ev
;
219 const struct lttng_event_desc
*desc
=
220 &__event_desc___sys_unknown
;
222 memset(&ev
, 0, sizeof(ev
));
223 strncpy(ev
.name
, desc
->name
, LTTNG_SYM_NAME_LEN
);
224 ev
.name
[LTTNG_SYM_NAME_LEN
- 1] = '\0';
225 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
226 chan
->sc_unknown
= ltt_event_create(chan
, &ev
, filter
,
228 if (!chan
->sc_unknown
) {
233 if (!chan
->sc_exit
) {
234 struct lttng_kernel_event ev
;
235 const struct lttng_event_desc
*desc
=
236 &__event_desc___exit_syscall
;
238 memset(&ev
, 0, sizeof(ev
));
239 strncpy(ev
.name
, desc
->name
, LTTNG_SYM_NAME_LEN
);
240 ev
.name
[LTTNG_SYM_NAME_LEN
- 1] = '\0';
241 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
242 chan
->sc_exit
= ltt_event_create(chan
, &ev
, filter
,
244 if (!chan
->sc_exit
) {
249 /* Allocate events for each syscall, insert into table */
250 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
251 struct lttng_kernel_event ev
;
252 const struct lttng_event_desc
*desc
= sc_table
[i
].desc
;
255 /* Unknown syscall */
259 * Skip those already populated by previous failed
260 * register for this channel.
262 if (chan
->sc_table
[i
])
264 memset(&ev
, 0, sizeof(ev
));
265 strncpy(ev
.name
, desc
->name
, LTTNG_SYM_NAME_LEN
);
266 ev
.name
[LTTNG_SYM_NAME_LEN
- 1] = '\0';
267 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
268 chan
->sc_table
[i
] = ltt_event_create(chan
, &ev
, filter
,
270 if (!chan
->sc_table
[i
]) {
272 * If something goes wrong in event registration
273 * after the first one, we have no choice but to
274 * leave the previous events in there, until
275 * deleted by session teardown.
280 ret
= tracepoint_probe_register("sys_enter",
281 (void *) syscall_entry_probe
, chan
);
285 * We change the name of sys_exit tracepoint due to namespace
286 * conflict with sys_exit syscall entry.
288 ret
= tracepoint_probe_register("sys_exit",
289 (void *) __event_probe__exit_syscall
,
292 WARN_ON_ONCE(tracepoint_probe_unregister("sys_enter",
293 (void *) syscall_entry_probe
, chan
));
299 * Only called at session destruction.
301 int lttng_syscalls_unregister(struct ltt_channel
*chan
)
307 ret
= tracepoint_probe_unregister("sys_exit",
308 (void *) __event_probe__exit_syscall
,
312 ret
= tracepoint_probe_unregister("sys_enter",
313 (void *) syscall_entry_probe
, chan
);
316 /* ltt_event destroy will be performed by ltt_session_destroy() */
317 kfree(chan
->sc_table
);