4 * LTTng syscall probes.
6 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; only
11 * version 2.1 of the License.
13 * This library is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with this library; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
23 #include <linux/module.h>
24 #include <linux/slab.h>
25 #include <linux/compat.h>
26 #include <linux/err.h>
27 #include <linux/bitmap.h>
29 #include <linux/in6.h>
30 #include <linux/seq_file.h>
31 #include <linux/stringify.h>
32 #include <linux/file.h>
33 #include <linux/anon_inodes.h>
34 #include <asm/ptrace.h>
35 #include <asm/syscall.h>
37 #include "lib/bitfield.h"
38 #include "wrapper/tracepoint.h"
39 #include "wrapper/file.h"
40 #include "lttng-events.h"
43 # ifndef is_compat_task
44 # define is_compat_task() (0)
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
66 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
68 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
71 * Forward declarations for old kernels.
75 struct oldold_utsname
;
77 struct sel_arg_struct
;
78 struct mmap_arg_struct
;
80 #ifdef IA32_NR_syscalls
81 #define NR_compat_syscalls IA32_NR_syscalls
83 #define NR_compat_syscalls NR_syscalls
87 * Create LTTng tracepoint probes.
89 #define LTTNG_PACKAGE_BUILD
90 #define CREATE_TRACE_POINTS
91 #define TP_MODULE_NOINIT
92 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
94 #define PARAMS(args...) args
96 /* Handle unknown syscalls */
98 #define TRACE_SYSTEM syscalls_unknown
99 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
107 #define sc_in(...) __VA_ARGS__
111 #define sc_inout(...) __VA_ARGS__
113 /* Hijack probe callback for system call enter */
115 #define TP_PROBE_CB(_template) &syscall_entry_probe
116 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
117 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
118 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
119 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
120 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
121 PARAMS(_locvar), PARAMS(_code), \
122 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
123 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
124 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_struct), PARAMS(_assign), \
126 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
127 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
129 #define TRACE_SYSTEM syscall_entry_integers
130 #define TRACE_INCLUDE_FILE syscalls_integers
131 #include "instrumentation/syscalls/headers/syscalls_integers.h"
132 #undef TRACE_INCLUDE_FILE
134 #define TRACE_SYSTEM syscall_entry_pointers
135 #define TRACE_INCLUDE_FILE syscalls_pointers
136 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
137 #undef TRACE_INCLUDE_FILE
139 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
140 #undef SC_LTTNG_TRACEPOINT_EVENT
141 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
142 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
144 #undef _TRACE_SYSCALLS_INTEGERS_H
145 #undef _TRACE_SYSCALLS_POINTERS_H
147 /* Hijack probe callback for compat system call enter */
148 #define TP_PROBE_CB(_template) &syscall_entry_probe
149 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
150 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
151 PARAMS(_struct), PARAMS(_assign), \
153 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
154 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
155 PARAMS(_locvar), PARAMS(_code), \
156 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
157 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
158 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_struct), \
159 PARAMS(_assign), PARAMS(_printk))
160 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
161 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
162 compat_syscall_entry_##_name)
163 #define TRACE_SYSTEM compat_syscall_entry_integers
164 #define TRACE_INCLUDE_FILE compat_syscalls_integers
165 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
166 #undef TRACE_INCLUDE_FILE
168 #define TRACE_SYSTEM compat_syscall_entry_pointers
169 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
170 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
171 #undef TRACE_INCLUDE_FILE
173 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
174 #undef SC_LTTNG_TRACEPOINT_EVENT
175 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
176 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
178 #undef _TRACE_SYSCALLS_INTEGERS_H
179 #undef _TRACE_SYSCALLS_POINTERS_H
186 #define sc_exit(...) __VA_ARGS__
190 #define sc_out(...) __VA_ARGS__
192 #define sc_inout(...) __VA_ARGS__
194 /* Hijack probe callback for system call exit */
195 #define TP_PROBE_CB(_template) &syscall_exit_probe
196 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
197 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
198 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
199 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
200 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
201 PARAMS(_locvar), PARAMS(_code), \
202 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
203 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
204 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_struct), \
205 PARAMS(_assign), PARAMS(_printk))
206 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
207 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
208 syscall_exit_##_name)
209 #define TRACE_SYSTEM syscall_exit_integers
210 #define TRACE_INCLUDE_FILE syscalls_integers
211 #include "instrumentation/syscalls/headers/syscalls_integers.h"
212 #undef TRACE_INCLUDE_FILE
214 #define TRACE_SYSTEM syscall_exit_pointers
215 #define TRACE_INCLUDE_FILE syscalls_pointers
216 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
217 #undef TRACE_INCLUDE_FILE
219 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
220 #undef SC_LTTNG_TRACEPOINT_EVENT
221 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
222 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
224 #undef _TRACE_SYSCALLS_INTEGERS_H
225 #undef _TRACE_SYSCALLS_POINTERS_H
228 /* Hijack probe callback for compat system call exit */
229 #define TP_PROBE_CB(_template) &syscall_exit_probe
230 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
231 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
232 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
233 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
234 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
235 PARAMS(_locvar), PARAMS(_code), \
236 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
237 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
238 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_struct), \
239 PARAMS(_assign), PARAMS(_printk))
240 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
241 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
242 compat_syscall_exit_##_name)
243 #define TRACE_SYSTEM compat_syscall_exit_integers
244 #define TRACE_INCLUDE_FILE compat_syscalls_integers
245 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
246 #undef TRACE_INCLUDE_FILE
248 #define TRACE_SYSTEM compat_syscall_exit_pointers
249 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
250 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
251 #undef TRACE_INCLUDE_FILE
253 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
254 #undef SC_LTTNG_TRACEPOINT_EVENT
255 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
256 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
258 #undef _TRACE_SYSCALLS_INTEGERS_H
259 #undef _TRACE_SYSCALLS_POINTERS_H
263 #undef TP_MODULE_NOINIT
264 #undef LTTNG_PACKAGE_BUILD
265 #undef CREATE_TRACE_POINTS
267 struct trace_syscall_entry
{
269 const struct lttng_event_desc
*desc
;
270 const struct lttng_event_field
*fields
;
274 #define CREATE_SYSCALL_TABLE
281 #undef TRACE_SYSCALL_TABLE
282 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
284 .func = __event_probe__syscall_entry_##_template, \
285 .nrargs = (_nrargs), \
286 .fields = __event_fields___syscall_entry_##_template, \
287 .desc = &__event_desc___syscall_entry_##_name, \
290 /* Syscall enter tracing table */
291 static const struct trace_syscall_entry sc_table
[] = {
292 #include "instrumentation/syscalls/headers/syscalls_integers.h"
293 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
296 #undef TRACE_SYSCALL_TABLE
297 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
299 .func = __event_probe__compat_syscall_entry_##_template, \
300 .nrargs = (_nrargs), \
301 .fields = __event_fields___compat_syscall_entry_##_template, \
302 .desc = &__event_desc___compat_syscall_entry_##_name, \
305 /* Compat syscall enter table */
306 const struct trace_syscall_entry compat_sc_table
[] = {
307 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
308 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
316 #define sc_exit(...) __VA_ARGS__
318 #undef TRACE_SYSCALL_TABLE
319 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
321 .func = __event_probe__syscall_exit_##_template, \
322 .nrargs = (_nrargs), \
323 .fields = __event_fields___syscall_exit_##_template, \
324 .desc = &__event_desc___syscall_exit_##_name, \
327 /* Syscall exit table */
328 static const struct trace_syscall_entry sc_exit_table
[] = {
329 #include "instrumentation/syscalls/headers/syscalls_integers.h"
330 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
333 #undef TRACE_SYSCALL_TABLE
334 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
336 .func = __event_probe__compat_syscall_exit_##_template, \
337 .nrargs = (_nrargs), \
338 .fields = __event_fields___compat_syscall_exit_##_template, \
339 .desc = &__event_desc___compat_syscall_exit_##_name, \
342 /* Compat syscall exit table */
343 const struct trace_syscall_entry compat_sc_exit_table
[] = {
344 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
345 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
350 #undef CREATE_SYSCALL_TABLE
352 struct lttng_syscall_filter
{
353 DECLARE_BITMAP(sc
, NR_syscalls
);
354 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
357 static void syscall_entry_unknown(struct lttng_event
*event
,
358 struct pt_regs
*regs
, unsigned int id
)
360 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
362 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
363 if (unlikely(is_compat_task()))
364 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
366 __event_probe__syscall_entry_unknown(event
, id
, args
);
369 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
371 struct lttng_channel
*chan
= __data
;
372 struct lttng_event
*event
, *unknown_event
;
373 const struct trace_syscall_entry
*table
, *entry
;
376 if (unlikely(is_compat_task())) {
377 struct lttng_syscall_filter
*filter
;
379 filter
= rcu_dereference(chan
->sc_filter
);
381 if (id
< 0 || id
>= NR_compat_syscalls
382 || !test_bit(id
, filter
->sc_compat
)) {
383 /* System call filtered out. */
387 table
= compat_sc_table
;
388 table_len
= ARRAY_SIZE(compat_sc_table
);
389 unknown_event
= chan
->sc_compat_unknown
;
391 struct lttng_syscall_filter
*filter
;
393 filter
= rcu_dereference(chan
->sc_filter
);
395 if (id
< 0 || id
>= NR_syscalls
396 || !test_bit(id
, filter
->sc
)) {
397 /* System call filtered out. */
402 table_len
= ARRAY_SIZE(sc_table
);
403 unknown_event
= chan
->sc_unknown
;
405 if (unlikely(id
< 0 || id
>= table_len
)) {
406 syscall_entry_unknown(unknown_event
, regs
, id
);
409 if (unlikely(is_compat_task()))
410 event
= chan
->compat_sc_table
[id
];
412 event
= chan
->sc_table
[id
];
413 if (unlikely(!event
)) {
414 syscall_entry_unknown(unknown_event
, regs
, id
);
418 WARN_ON_ONCE(!entry
);
420 switch (entry
->nrargs
) {
423 void (*fptr
)(void *__data
) = entry
->func
;
430 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
431 unsigned long args
[1];
433 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
434 fptr(event
, args
[0]);
439 void (*fptr
)(void *__data
,
441 unsigned long arg1
) = entry
->func
;
442 unsigned long args
[2];
444 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
445 fptr(event
, args
[0], args
[1]);
450 void (*fptr
)(void *__data
,
453 unsigned long arg2
) = entry
->func
;
454 unsigned long args
[3];
456 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
457 fptr(event
, args
[0], args
[1], args
[2]);
462 void (*fptr
)(void *__data
,
466 unsigned long arg3
) = entry
->func
;
467 unsigned long args
[4];
469 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
470 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
475 void (*fptr
)(void *__data
,
480 unsigned long arg4
) = entry
->func
;
481 unsigned long args
[5];
483 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
484 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
489 void (*fptr
)(void *__data
,
495 unsigned long arg5
) = entry
->func
;
496 unsigned long args
[6];
498 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
499 fptr(event
, args
[0], args
[1], args
[2],
500 args
[3], args
[4], args
[5]);
508 static void syscall_exit_unknown(struct lttng_event
*event
,
509 struct pt_regs
*regs
, int id
, long ret
)
511 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
513 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
514 if (unlikely(is_compat_task()))
515 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
518 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
521 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
523 struct lttng_channel
*chan
= __data
;
524 struct lttng_event
*event
, *unknown_event
;
525 const struct trace_syscall_entry
*table
, *entry
;
529 id
= syscall_get_nr(current
, regs
);
530 if (unlikely(is_compat_task())) {
531 struct lttng_syscall_filter
*filter
;
533 filter
= rcu_dereference(chan
->sc_filter
);
535 if (id
< 0 || id
>= NR_compat_syscalls
536 || !test_bit(id
, filter
->sc_compat
)) {
537 /* System call filtered out. */
541 table
= compat_sc_exit_table
;
542 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
543 unknown_event
= chan
->compat_sc_exit_unknown
;
545 struct lttng_syscall_filter
*filter
;
547 filter
= rcu_dereference(chan
->sc_filter
);
549 if (id
< 0 || id
>= NR_syscalls
550 || !test_bit(id
, filter
->sc
)) {
551 /* System call filtered out. */
555 table
= sc_exit_table
;
556 table_len
= ARRAY_SIZE(sc_exit_table
);
557 unknown_event
= chan
->sc_exit_unknown
;
559 if (unlikely(id
< 0 || id
>= table_len
)) {
560 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
563 if (unlikely(is_compat_task()))
564 event
= chan
->compat_sc_exit_table
[id
];
566 event
= chan
->sc_exit_table
[id
];
567 if (unlikely(!event
)) {
568 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
572 WARN_ON_ONCE(!entry
);
574 switch (entry
->nrargs
) {
577 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
584 void (*fptr
)(void *__data
,
586 unsigned long arg0
) = entry
->func
;
587 unsigned long args
[1];
589 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
590 fptr(event
, ret
, args
[0]);
595 void (*fptr
)(void *__data
,
598 unsigned long arg1
) = entry
->func
;
599 unsigned long args
[2];
601 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
602 fptr(event
, ret
, args
[0], args
[1]);
607 void (*fptr
)(void *__data
,
611 unsigned long arg2
) = entry
->func
;
612 unsigned long args
[3];
614 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
615 fptr(event
, ret
, args
[0], args
[1], args
[2]);
620 void (*fptr
)(void *__data
,
625 unsigned long arg3
) = entry
->func
;
626 unsigned long args
[4];
628 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
629 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
634 void (*fptr
)(void *__data
,
640 unsigned long arg4
) = entry
->func
;
641 unsigned long args
[5];
643 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
644 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
649 void (*fptr
)(void *__data
,
656 unsigned long arg5
) = entry
->func
;
657 unsigned long args
[6];
659 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
660 fptr(event
, ret
, args
[0], args
[1], args
[2],
661 args
[3], args
[4], args
[5]);
669 /* noinline to diminish caller stack size */
671 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
672 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
673 void *filter
, enum sc_type type
)
675 const struct lttng_event_desc
*desc
;
678 /* Allocate events for each syscall, insert into table */
679 for (i
= 0; i
< table_len
; i
++) {
680 struct lttng_kernel_event ev
;
681 desc
= table
[i
].desc
;
684 /* Unknown syscall */
688 * Skip those already populated by previous failed
689 * register for this channel.
693 memset(&ev
, 0, sizeof(ev
));
696 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
697 LTTNG_KERNEL_SYM_NAME_LEN
);
700 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
701 LTTNG_KERNEL_SYM_NAME_LEN
);
703 case SC_TYPE_COMPAT_ENTRY
:
704 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
705 LTTNG_KERNEL_SYM_NAME_LEN
);
707 case SC_TYPE_COMPAT_EXIT
:
708 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
709 LTTNG_KERNEL_SYM_NAME_LEN
);
715 strncat(ev
.name
, desc
->name
,
716 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
717 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
718 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
719 chan_table
[i
] = lttng_event_create(chan
, &ev
, filter
,
721 WARN_ON_ONCE(!chan_table
[i
]);
722 if (IS_ERR(chan_table
[i
])) {
724 * If something goes wrong in event registration
725 * after the first one, we have no choice but to
726 * leave the previous events in there, until
727 * deleted by session teardown.
729 return PTR_ERR(chan_table
[i
]);
735 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
737 struct lttng_kernel_event ev
;
740 wrapper_vmalloc_sync_all();
742 if (!chan
->sc_table
) {
743 /* create syscall table mapping syscall to events */
744 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
745 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
749 if (!chan
->sc_exit_table
) {
750 /* create syscall table mapping syscall to events */
751 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
752 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
753 if (!chan
->sc_exit_table
)
759 if (!chan
->compat_sc_table
) {
760 /* create syscall table mapping compat syscall to events */
761 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
762 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
763 if (!chan
->compat_sc_table
)
767 if (!chan
->compat_sc_exit_table
) {
768 /* create syscall table mapping compat syscall to events */
769 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
770 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
771 if (!chan
->compat_sc_exit_table
)
775 if (!chan
->sc_unknown
) {
776 const struct lttng_event_desc
*desc
=
777 &__event_desc___syscall_entry_unknown
;
779 memset(&ev
, 0, sizeof(ev
));
780 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
781 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
782 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
783 chan
->sc_unknown
= lttng_event_create(chan
, &ev
, filter
,
785 WARN_ON_ONCE(!chan
->sc_unknown
);
786 if (IS_ERR(chan
->sc_unknown
)) {
787 return PTR_ERR(chan
->sc_unknown
);
791 if (!chan
->sc_compat_unknown
) {
792 const struct lttng_event_desc
*desc
=
793 &__event_desc___compat_syscall_entry_unknown
;
795 memset(&ev
, 0, sizeof(ev
));
796 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
797 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
798 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
799 chan
->sc_compat_unknown
= lttng_event_create(chan
, &ev
, filter
,
801 WARN_ON_ONCE(!chan
->sc_unknown
);
802 if (IS_ERR(chan
->sc_compat_unknown
)) {
803 return PTR_ERR(chan
->sc_compat_unknown
);
807 if (!chan
->compat_sc_exit_unknown
) {
808 const struct lttng_event_desc
*desc
=
809 &__event_desc___compat_syscall_exit_unknown
;
811 memset(&ev
, 0, sizeof(ev
));
812 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
813 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
814 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
815 chan
->compat_sc_exit_unknown
= lttng_event_create(chan
, &ev
,
817 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
818 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
819 return PTR_ERR(chan
->compat_sc_exit_unknown
);
823 if (!chan
->sc_exit_unknown
) {
824 const struct lttng_event_desc
*desc
=
825 &__event_desc___syscall_exit_unknown
;
827 memset(&ev
, 0, sizeof(ev
));
828 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
829 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
830 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
831 chan
->sc_exit_unknown
= lttng_event_create(chan
, &ev
, filter
,
833 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
834 if (IS_ERR(chan
->sc_exit_unknown
)) {
835 return PTR_ERR(chan
->sc_exit_unknown
);
839 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
840 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
843 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
844 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
849 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
850 chan
->compat_sc_table
, chan
, filter
,
851 SC_TYPE_COMPAT_ENTRY
);
854 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
855 chan
->compat_sc_exit_table
, chan
, filter
,
856 SC_TYPE_COMPAT_EXIT
);
860 if (!chan
->sys_enter_registered
) {
861 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
862 (void *) syscall_entry_probe
, chan
);
865 chan
->sys_enter_registered
= 1;
868 * We change the name of sys_exit tracepoint due to namespace
869 * conflict with sys_exit syscall entry.
871 if (!chan
->sys_exit_registered
) {
872 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
873 (void *) syscall_exit_probe
, chan
);
875 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
876 (void *) syscall_entry_probe
, chan
));
879 chan
->sys_exit_registered
= 1;
885 * Only called at session destruction.
887 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
893 if (chan
->sys_enter_registered
) {
894 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
895 (void *) syscall_exit_probe
, chan
);
898 chan
->sys_enter_registered
= 0;
900 if (chan
->sys_exit_registered
) {
901 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
902 (void *) syscall_entry_probe
, chan
);
905 chan
->sys_exit_registered
= 0;
907 /* lttng_event destroy will be performed by lttng_session_destroy() */
908 kfree(chan
->sc_table
);
909 kfree(chan
->sc_exit_table
);
911 kfree(chan
->compat_sc_table
);
912 kfree(chan
->compat_sc_exit_table
);
914 kfree(chan
->sc_filter
);
919 int get_syscall_nr(const char *syscall_name
)
924 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
925 const struct trace_syscall_entry
*entry
;
928 entry
= &sc_table
[i
];
931 it_name
= entry
->desc
->name
;
932 it_name
+= strlen(SYSCALL_ENTRY_STR
);
933 if (!strcmp(syscall_name
, it_name
)) {
942 int get_compat_syscall_nr(const char *syscall_name
)
947 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
948 const struct trace_syscall_entry
*entry
;
951 entry
= &compat_sc_table
[i
];
954 it_name
= entry
->desc
->name
;
955 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
956 if (!strcmp(syscall_name
, it_name
)) {
965 uint32_t get_sc_tables_len(void)
967 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
970 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
973 int syscall_nr
, compat_syscall_nr
, ret
;
974 struct lttng_syscall_filter
*filter
;
976 WARN_ON_ONCE(!chan
->sc_table
);
979 /* Enable all system calls by removing filter */
980 if (chan
->sc_filter
) {
981 filter
= chan
->sc_filter
;
982 rcu_assign_pointer(chan
->sc_filter
, NULL
);
986 chan
->syscall_all
= 1;
990 if (!chan
->sc_filter
) {
991 if (chan
->syscall_all
) {
993 * All syscalls are already enabled.
997 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1002 filter
= chan
->sc_filter
;
1004 syscall_nr
= get_syscall_nr(name
);
1005 compat_syscall_nr
= get_compat_syscall_nr(name
);
1006 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1010 if (syscall_nr
>= 0) {
1011 if (test_bit(syscall_nr
, filter
->sc
)) {
1015 bitmap_set(filter
->sc
, syscall_nr
, 1);
1017 if (compat_syscall_nr
>= 0) {
1018 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1022 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1024 if (!chan
->sc_filter
)
1025 rcu_assign_pointer(chan
->sc_filter
, filter
);
1029 if (!chan
->sc_filter
)
1034 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1037 int syscall_nr
, compat_syscall_nr
, ret
;
1038 struct lttng_syscall_filter
*filter
;
1040 WARN_ON_ONCE(!chan
->sc_table
);
1042 if (!chan
->sc_filter
) {
1043 if (!chan
->syscall_all
)
1045 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1049 /* Trace all system calls, then apply disable. */
1050 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1051 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1053 filter
= chan
->sc_filter
;
1057 /* Fail if all syscalls are already disabled. */
1058 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1059 && bitmap_empty(filter
->sc_compat
,
1060 NR_compat_syscalls
)) {
1065 /* Disable all system calls */
1066 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1067 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1070 syscall_nr
= get_syscall_nr(name
);
1071 compat_syscall_nr
= get_compat_syscall_nr(name
);
1072 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1076 if (syscall_nr
>= 0) {
1077 if (!test_bit(syscall_nr
, filter
->sc
)) {
1081 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1083 if (compat_syscall_nr
>= 0) {
1084 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1088 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1091 if (!chan
->sc_filter
)
1092 rcu_assign_pointer(chan
->sc_filter
, filter
);
1093 chan
->syscall_all
= 0;
1097 if (!chan
->sc_filter
)
1103 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1105 const struct trace_syscall_entry
*entry
;
1108 for (entry
= sc_table
;
1109 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1114 for (entry
= compat_sc_table
;
1115 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1125 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1127 return (void *) syscall_list_get_entry(pos
);
1131 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1134 return (void *) syscall_list_get_entry(ppos
);
1138 void syscall_list_stop(struct seq_file
*m
, void *p
)
1143 int get_sc_table(const struct trace_syscall_entry
*entry
,
1144 const struct trace_syscall_entry
**table
,
1145 unsigned int *bitness
)
1147 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1149 *bitness
= BITS_PER_LONG
;
1154 if (!(entry
>= compat_sc_table
1155 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1161 *table
= compat_sc_table
;
1166 int syscall_list_show(struct seq_file
*m
, void *p
)
1168 const struct trace_syscall_entry
*table
, *entry
= p
;
1169 unsigned int bitness
;
1170 unsigned long index
;
1174 ret
= get_sc_table(entry
, &table
, &bitness
);
1179 if (table
== sc_table
) {
1180 index
= entry
- table
;
1181 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1183 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1184 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1186 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1187 index
, name
, bitness
);
1192 const struct seq_operations lttng_syscall_list_seq_ops
= {
1193 .start
= syscall_list_start
,
1194 .next
= syscall_list_next
,
1195 .stop
= syscall_list_stop
,
1196 .show
= syscall_list_show
,
1200 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1202 return seq_open(file
, <tng_syscall_list_seq_ops
);
1205 const struct file_operations lttng_syscall_list_fops
= {
1206 .owner
= THIS_MODULE
,
1207 .open
= lttng_syscall_list_open
,
1209 .llseek
= seq_lseek
,
1210 .release
= seq_release
,
1213 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1214 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1216 uint32_t len
, sc_tables_len
, bitmask_len
;
1219 struct lttng_syscall_filter
*filter
;
1221 ret
= get_user(len
, &usyscall_mask
->len
);
1224 sc_tables_len
= get_sc_tables_len();
1225 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1226 if (len
< sc_tables_len
) {
1227 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1229 /* Array is large enough, we can copy array to user-space. */
1230 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1233 filter
= channel
->sc_filter
;
1235 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1238 if (channel
->sc_table
) {
1240 state
= test_bit(bit
, filter
->sc
);
1246 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1248 for (; bit
< sc_tables_len
; bit
++) {
1251 if (channel
->compat_sc_table
) {
1253 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1260 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1262 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1268 int lttng_abi_syscall_list(void)
1270 struct file
*syscall_list_file
;
1273 file_fd
= lttng_get_unused_fd();
1279 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1280 <tng_syscall_list_fops
,
1282 if (IS_ERR(syscall_list_file
)) {
1283 ret
= PTR_ERR(syscall_list_file
);
1286 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1289 fd_install(file_fd
, syscall_list_file
);
1297 fput(syscall_list_file
);
1299 put_unused_fd(file_fd
);