4 * LTTng syscall probes.
6 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; only
11 * version 2.1 of the License.
13 * This library is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with this library; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
23 #include <linux/module.h>
24 #include <linux/slab.h>
25 #include <linux/compat.h>
26 #include <linux/err.h>
27 #include <linux/bitmap.h>
29 #include <linux/in6.h>
30 #include <linux/seq_file.h>
31 #include <linux/stringify.h>
32 #include <linux/file.h>
33 #include <linux/anon_inodes.h>
34 #include <asm/ptrace.h>
35 #include <asm/syscall.h>
37 #include "lib/bitfield.h"
38 #include "wrapper/tracepoint.h"
39 #include "wrapper/file.h"
40 #include "lttng-events.h"
43 # ifndef is_compat_task
44 # define is_compat_task() (0)
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
66 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
68 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
71 * Forward declarations for old kernels.
75 struct oldold_utsname
;
77 struct sel_arg_struct
;
78 struct mmap_arg_struct
;
81 #ifdef IA32_NR_syscalls
82 #define NR_compat_syscalls IA32_NR_syscalls
84 #define NR_compat_syscalls NR_syscalls
88 * Create LTTng tracepoint probes.
90 #define LTTNG_PACKAGE_BUILD
91 #define CREATE_TRACE_POINTS
92 #define TP_MODULE_NOINIT
93 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
95 #define PARAMS(args...) args
97 /* Handle unknown syscalls */
99 #define TRACE_SYSTEM syscalls_unknown
100 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
108 #define sc_in(...) __VA_ARGS__
112 #define sc_inout(...) __VA_ARGS__
114 /* Hijack probe callback for system call enter */
116 #define TP_PROBE_CB(_template) &syscall_entry_probe
117 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
118 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
119 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
120 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
121 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
122 PARAMS(_locvar), PARAMS(_code), \
123 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
124 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
125 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_struct), PARAMS(_assign), \
127 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
128 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
130 #define TRACE_SYSTEM syscall_entry_integers
131 #define TRACE_INCLUDE_FILE syscalls_integers
132 #include "instrumentation/syscalls/headers/syscalls_integers.h"
133 #undef TRACE_INCLUDE_FILE
135 #define TRACE_SYSTEM syscall_entry_pointers
136 #define TRACE_INCLUDE_FILE syscalls_pointers
137 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
138 #undef TRACE_INCLUDE_FILE
140 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
141 #undef SC_LTTNG_TRACEPOINT_EVENT
142 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
143 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
145 #undef _TRACE_SYSCALLS_INTEGERS_H
146 #undef _TRACE_SYSCALLS_POINTERS_H
148 /* Hijack probe callback for compat system call enter */
149 #define TP_PROBE_CB(_template) &syscall_entry_probe
150 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
151 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
152 PARAMS(_struct), PARAMS(_assign), \
154 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
155 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
156 PARAMS(_locvar), PARAMS(_code), \
157 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
158 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
159 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_struct), \
160 PARAMS(_assign), PARAMS(_printk))
161 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
162 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
163 compat_syscall_entry_##_name)
164 #define TRACE_SYSTEM compat_syscall_entry_integers
165 #define TRACE_INCLUDE_FILE compat_syscalls_integers
166 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
167 #undef TRACE_INCLUDE_FILE
169 #define TRACE_SYSTEM compat_syscall_entry_pointers
170 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
171 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
172 #undef TRACE_INCLUDE_FILE
174 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
175 #undef SC_LTTNG_TRACEPOINT_EVENT
176 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
177 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
179 #undef _TRACE_SYSCALLS_INTEGERS_H
180 #undef _TRACE_SYSCALLS_POINTERS_H
187 #define sc_exit(...) __VA_ARGS__
191 #define sc_out(...) __VA_ARGS__
193 #define sc_inout(...) __VA_ARGS__
195 /* Hijack probe callback for system call exit */
196 #define TP_PROBE_CB(_template) &syscall_exit_probe
197 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
198 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
199 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
200 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
201 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
202 PARAMS(_locvar), PARAMS(_code), \
203 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
204 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
205 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_struct), \
206 PARAMS(_assign), PARAMS(_printk))
207 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
208 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
209 syscall_exit_##_name)
210 #define TRACE_SYSTEM syscall_exit_integers
211 #define TRACE_INCLUDE_FILE syscalls_integers
212 #include "instrumentation/syscalls/headers/syscalls_integers.h"
213 #undef TRACE_INCLUDE_FILE
215 #define TRACE_SYSTEM syscall_exit_pointers
216 #define TRACE_INCLUDE_FILE syscalls_pointers
217 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
218 #undef TRACE_INCLUDE_FILE
220 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
221 #undef SC_LTTNG_TRACEPOINT_EVENT
222 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
223 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
225 #undef _TRACE_SYSCALLS_INTEGERS_H
226 #undef _TRACE_SYSCALLS_POINTERS_H
229 /* Hijack probe callback for compat system call exit */
230 #define TP_PROBE_CB(_template) &syscall_exit_probe
231 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
232 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
233 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
234 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _struct, _assign, _printk) \
235 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
236 PARAMS(_locvar), PARAMS(_code), \
237 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
238 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
239 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_struct), \
240 PARAMS(_assign), PARAMS(_printk))
241 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
242 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
243 compat_syscall_exit_##_name)
244 #define TRACE_SYSTEM compat_syscall_exit_integers
245 #define TRACE_INCLUDE_FILE compat_syscalls_integers
246 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
247 #undef TRACE_INCLUDE_FILE
249 #define TRACE_SYSTEM compat_syscall_exit_pointers
250 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
251 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
252 #undef TRACE_INCLUDE_FILE
254 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
255 #undef SC_LTTNG_TRACEPOINT_EVENT
256 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
257 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
259 #undef _TRACE_SYSCALLS_INTEGERS_H
260 #undef _TRACE_SYSCALLS_POINTERS_H
264 #undef TP_MODULE_NOINIT
265 #undef LTTNG_PACKAGE_BUILD
266 #undef CREATE_TRACE_POINTS
268 struct trace_syscall_entry
{
270 const struct lttng_event_desc
*desc
;
271 const struct lttng_event_field
*fields
;
275 #define CREATE_SYSCALL_TABLE
282 #undef TRACE_SYSCALL_TABLE
283 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
285 .func = __event_probe__syscall_entry_##_template, \
286 .nrargs = (_nrargs), \
287 .fields = __event_fields___syscall_entry_##_template, \
288 .desc = &__event_desc___syscall_entry_##_name, \
291 /* Syscall enter tracing table */
292 static const struct trace_syscall_entry sc_table
[] = {
293 #include "instrumentation/syscalls/headers/syscalls_integers.h"
294 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
297 #undef TRACE_SYSCALL_TABLE
298 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
300 .func = __event_probe__compat_syscall_entry_##_template, \
301 .nrargs = (_nrargs), \
302 .fields = __event_fields___compat_syscall_entry_##_template, \
303 .desc = &__event_desc___compat_syscall_entry_##_name, \
306 /* Compat syscall enter table */
307 const struct trace_syscall_entry compat_sc_table
[] = {
308 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
309 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
317 #define sc_exit(...) __VA_ARGS__
319 #undef TRACE_SYSCALL_TABLE
320 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
322 .func = __event_probe__syscall_exit_##_template, \
323 .nrargs = (_nrargs), \
324 .fields = __event_fields___syscall_exit_##_template, \
325 .desc = &__event_desc___syscall_exit_##_name, \
328 /* Syscall exit table */
329 static const struct trace_syscall_entry sc_exit_table
[] = {
330 #include "instrumentation/syscalls/headers/syscalls_integers.h"
331 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
334 #undef TRACE_SYSCALL_TABLE
335 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
337 .func = __event_probe__compat_syscall_exit_##_template, \
338 .nrargs = (_nrargs), \
339 .fields = __event_fields___compat_syscall_exit_##_template, \
340 .desc = &__event_desc___compat_syscall_exit_##_name, \
343 /* Compat syscall exit table */
344 const struct trace_syscall_entry compat_sc_exit_table
[] = {
345 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
346 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
351 #undef CREATE_SYSCALL_TABLE
353 struct lttng_syscall_filter
{
354 DECLARE_BITMAP(sc
, NR_syscalls
);
355 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
358 static void syscall_entry_unknown(struct lttng_event
*event
,
359 struct pt_regs
*regs
, unsigned int id
)
361 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
363 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
364 if (unlikely(is_compat_task()))
365 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
367 __event_probe__syscall_entry_unknown(event
, id
, args
);
370 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
372 struct lttng_channel
*chan
= __data
;
373 struct lttng_event
*event
, *unknown_event
;
374 const struct trace_syscall_entry
*table
, *entry
;
377 if (unlikely(is_compat_task())) {
378 struct lttng_syscall_filter
*filter
;
380 filter
= rcu_dereference(chan
->sc_filter
);
382 if (id
< 0 || id
>= NR_compat_syscalls
383 || !test_bit(id
, filter
->sc_compat
)) {
384 /* System call filtered out. */
388 table
= compat_sc_table
;
389 table_len
= ARRAY_SIZE(compat_sc_table
);
390 unknown_event
= chan
->sc_compat_unknown
;
392 struct lttng_syscall_filter
*filter
;
394 filter
= rcu_dereference(chan
->sc_filter
);
396 if (id
< 0 || id
>= NR_syscalls
397 || !test_bit(id
, filter
->sc
)) {
398 /* System call filtered out. */
403 table_len
= ARRAY_SIZE(sc_table
);
404 unknown_event
= chan
->sc_unknown
;
406 if (unlikely(id
< 0 || id
>= table_len
)) {
407 syscall_entry_unknown(unknown_event
, regs
, id
);
410 if (unlikely(is_compat_task()))
411 event
= chan
->compat_sc_table
[id
];
413 event
= chan
->sc_table
[id
];
414 if (unlikely(!event
)) {
415 syscall_entry_unknown(unknown_event
, regs
, id
);
419 WARN_ON_ONCE(!entry
);
421 switch (entry
->nrargs
) {
424 void (*fptr
)(void *__data
) = entry
->func
;
431 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
432 unsigned long args
[1];
434 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
435 fptr(event
, args
[0]);
440 void (*fptr
)(void *__data
,
442 unsigned long arg1
) = entry
->func
;
443 unsigned long args
[2];
445 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
446 fptr(event
, args
[0], args
[1]);
451 void (*fptr
)(void *__data
,
454 unsigned long arg2
) = entry
->func
;
455 unsigned long args
[3];
457 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
458 fptr(event
, args
[0], args
[1], args
[2]);
463 void (*fptr
)(void *__data
,
467 unsigned long arg3
) = entry
->func
;
468 unsigned long args
[4];
470 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
471 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
476 void (*fptr
)(void *__data
,
481 unsigned long arg4
) = entry
->func
;
482 unsigned long args
[5];
484 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
485 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
490 void (*fptr
)(void *__data
,
496 unsigned long arg5
) = entry
->func
;
497 unsigned long args
[6];
499 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
500 fptr(event
, args
[0], args
[1], args
[2],
501 args
[3], args
[4], args
[5]);
509 static void syscall_exit_unknown(struct lttng_event
*event
,
510 struct pt_regs
*regs
, int id
, long ret
)
512 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
514 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
515 if (unlikely(is_compat_task()))
516 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
519 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
522 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
524 struct lttng_channel
*chan
= __data
;
525 struct lttng_event
*event
, *unknown_event
;
526 const struct trace_syscall_entry
*table
, *entry
;
530 id
= syscall_get_nr(current
, regs
);
531 if (unlikely(is_compat_task())) {
532 struct lttng_syscall_filter
*filter
;
534 filter
= rcu_dereference(chan
->sc_filter
);
536 if (id
< 0 || id
>= NR_compat_syscalls
537 || !test_bit(id
, filter
->sc_compat
)) {
538 /* System call filtered out. */
542 table
= compat_sc_exit_table
;
543 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
544 unknown_event
= chan
->compat_sc_exit_unknown
;
546 struct lttng_syscall_filter
*filter
;
548 filter
= rcu_dereference(chan
->sc_filter
);
550 if (id
< 0 || id
>= NR_syscalls
551 || !test_bit(id
, filter
->sc
)) {
552 /* System call filtered out. */
556 table
= sc_exit_table
;
557 table_len
= ARRAY_SIZE(sc_exit_table
);
558 unknown_event
= chan
->sc_exit_unknown
;
560 if (unlikely(id
< 0 || id
>= table_len
)) {
561 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
564 if (unlikely(is_compat_task()))
565 event
= chan
->compat_sc_exit_table
[id
];
567 event
= chan
->sc_exit_table
[id
];
568 if (unlikely(!event
)) {
569 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
573 WARN_ON_ONCE(!entry
);
575 switch (entry
->nrargs
) {
578 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
585 void (*fptr
)(void *__data
,
587 unsigned long arg0
) = entry
->func
;
588 unsigned long args
[1];
590 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
591 fptr(event
, ret
, args
[0]);
596 void (*fptr
)(void *__data
,
599 unsigned long arg1
) = entry
->func
;
600 unsigned long args
[2];
602 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
603 fptr(event
, ret
, args
[0], args
[1]);
608 void (*fptr
)(void *__data
,
612 unsigned long arg2
) = entry
->func
;
613 unsigned long args
[3];
615 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
616 fptr(event
, ret
, args
[0], args
[1], args
[2]);
621 void (*fptr
)(void *__data
,
626 unsigned long arg3
) = entry
->func
;
627 unsigned long args
[4];
629 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
630 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
635 void (*fptr
)(void *__data
,
641 unsigned long arg4
) = entry
->func
;
642 unsigned long args
[5];
644 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
645 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
650 void (*fptr
)(void *__data
,
657 unsigned long arg5
) = entry
->func
;
658 unsigned long args
[6];
660 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
661 fptr(event
, ret
, args
[0], args
[1], args
[2],
662 args
[3], args
[4], args
[5]);
670 /* noinline to diminish caller stack size */
672 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
673 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
674 void *filter
, enum sc_type type
)
676 const struct lttng_event_desc
*desc
;
679 /* Allocate events for each syscall, insert into table */
680 for (i
= 0; i
< table_len
; i
++) {
681 struct lttng_kernel_event ev
;
682 desc
= table
[i
].desc
;
685 /* Unknown syscall */
689 * Skip those already populated by previous failed
690 * register for this channel.
694 memset(&ev
, 0, sizeof(ev
));
697 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
698 LTTNG_KERNEL_SYM_NAME_LEN
);
701 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
702 LTTNG_KERNEL_SYM_NAME_LEN
);
704 case SC_TYPE_COMPAT_ENTRY
:
705 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
706 LTTNG_KERNEL_SYM_NAME_LEN
);
708 case SC_TYPE_COMPAT_EXIT
:
709 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
710 LTTNG_KERNEL_SYM_NAME_LEN
);
716 strncat(ev
.name
, desc
->name
,
717 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
718 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
719 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
720 chan_table
[i
] = lttng_event_create(chan
, &ev
, filter
,
722 WARN_ON_ONCE(!chan_table
[i
]);
723 if (IS_ERR(chan_table
[i
])) {
725 * If something goes wrong in event registration
726 * after the first one, we have no choice but to
727 * leave the previous events in there, until
728 * deleted by session teardown.
730 return PTR_ERR(chan_table
[i
]);
736 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
738 struct lttng_kernel_event ev
;
741 wrapper_vmalloc_sync_all();
743 if (!chan
->sc_table
) {
744 /* create syscall table mapping syscall to events */
745 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
746 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
750 if (!chan
->sc_exit_table
) {
751 /* create syscall table mapping syscall to events */
752 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
753 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
754 if (!chan
->sc_exit_table
)
760 if (!chan
->compat_sc_table
) {
761 /* create syscall table mapping compat syscall to events */
762 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
763 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
764 if (!chan
->compat_sc_table
)
768 if (!chan
->compat_sc_exit_table
) {
769 /* create syscall table mapping compat syscall to events */
770 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
771 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
772 if (!chan
->compat_sc_exit_table
)
776 if (!chan
->sc_unknown
) {
777 const struct lttng_event_desc
*desc
=
778 &__event_desc___syscall_entry_unknown
;
780 memset(&ev
, 0, sizeof(ev
));
781 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
782 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
783 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
784 chan
->sc_unknown
= lttng_event_create(chan
, &ev
, filter
,
786 WARN_ON_ONCE(!chan
->sc_unknown
);
787 if (IS_ERR(chan
->sc_unknown
)) {
788 return PTR_ERR(chan
->sc_unknown
);
792 if (!chan
->sc_compat_unknown
) {
793 const struct lttng_event_desc
*desc
=
794 &__event_desc___compat_syscall_entry_unknown
;
796 memset(&ev
, 0, sizeof(ev
));
797 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
798 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
799 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
800 chan
->sc_compat_unknown
= lttng_event_create(chan
, &ev
, filter
,
802 WARN_ON_ONCE(!chan
->sc_unknown
);
803 if (IS_ERR(chan
->sc_compat_unknown
)) {
804 return PTR_ERR(chan
->sc_compat_unknown
);
808 if (!chan
->compat_sc_exit_unknown
) {
809 const struct lttng_event_desc
*desc
=
810 &__event_desc___compat_syscall_exit_unknown
;
812 memset(&ev
, 0, sizeof(ev
));
813 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
814 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
815 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
816 chan
->compat_sc_exit_unknown
= lttng_event_create(chan
, &ev
,
818 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
819 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
820 return PTR_ERR(chan
->compat_sc_exit_unknown
);
824 if (!chan
->sc_exit_unknown
) {
825 const struct lttng_event_desc
*desc
=
826 &__event_desc___syscall_exit_unknown
;
828 memset(&ev
, 0, sizeof(ev
));
829 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
830 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
831 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
832 chan
->sc_exit_unknown
= lttng_event_create(chan
, &ev
, filter
,
834 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
835 if (IS_ERR(chan
->sc_exit_unknown
)) {
836 return PTR_ERR(chan
->sc_exit_unknown
);
840 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
841 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
844 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
845 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
850 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
851 chan
->compat_sc_table
, chan
, filter
,
852 SC_TYPE_COMPAT_ENTRY
);
855 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
856 chan
->compat_sc_exit_table
, chan
, filter
,
857 SC_TYPE_COMPAT_EXIT
);
861 if (!chan
->sys_enter_registered
) {
862 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
863 (void *) syscall_entry_probe
, chan
);
866 chan
->sys_enter_registered
= 1;
869 * We change the name of sys_exit tracepoint due to namespace
870 * conflict with sys_exit syscall entry.
872 if (!chan
->sys_exit_registered
) {
873 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
874 (void *) syscall_exit_probe
, chan
);
876 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
877 (void *) syscall_entry_probe
, chan
));
880 chan
->sys_exit_registered
= 1;
886 * Only called at session destruction.
888 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
894 if (chan
->sys_enter_registered
) {
895 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
896 (void *) syscall_exit_probe
, chan
);
899 chan
->sys_enter_registered
= 0;
901 if (chan
->sys_exit_registered
) {
902 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
903 (void *) syscall_entry_probe
, chan
);
906 chan
->sys_exit_registered
= 0;
908 /* lttng_event destroy will be performed by lttng_session_destroy() */
909 kfree(chan
->sc_table
);
910 kfree(chan
->sc_exit_table
);
912 kfree(chan
->compat_sc_table
);
913 kfree(chan
->compat_sc_exit_table
);
915 kfree(chan
->sc_filter
);
920 int get_syscall_nr(const char *syscall_name
)
925 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
926 const struct trace_syscall_entry
*entry
;
929 entry
= &sc_table
[i
];
932 it_name
= entry
->desc
->name
;
933 it_name
+= strlen(SYSCALL_ENTRY_STR
);
934 if (!strcmp(syscall_name
, it_name
)) {
943 int get_compat_syscall_nr(const char *syscall_name
)
948 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
949 const struct trace_syscall_entry
*entry
;
952 entry
= &compat_sc_table
[i
];
955 it_name
= entry
->desc
->name
;
956 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
957 if (!strcmp(syscall_name
, it_name
)) {
966 uint32_t get_sc_tables_len(void)
968 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
971 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
974 int syscall_nr
, compat_syscall_nr
, ret
;
975 struct lttng_syscall_filter
*filter
;
977 WARN_ON_ONCE(!chan
->sc_table
);
980 /* Enable all system calls by removing filter */
981 if (chan
->sc_filter
) {
982 filter
= chan
->sc_filter
;
983 rcu_assign_pointer(chan
->sc_filter
, NULL
);
987 chan
->syscall_all
= 1;
991 if (!chan
->sc_filter
) {
992 if (chan
->syscall_all
) {
994 * All syscalls are already enabled.
998 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1003 filter
= chan
->sc_filter
;
1005 syscall_nr
= get_syscall_nr(name
);
1006 compat_syscall_nr
= get_compat_syscall_nr(name
);
1007 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1011 if (syscall_nr
>= 0) {
1012 if (test_bit(syscall_nr
, filter
->sc
)) {
1016 bitmap_set(filter
->sc
, syscall_nr
, 1);
1018 if (compat_syscall_nr
>= 0) {
1019 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1023 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1025 if (!chan
->sc_filter
)
1026 rcu_assign_pointer(chan
->sc_filter
, filter
);
1030 if (!chan
->sc_filter
)
1035 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1038 int syscall_nr
, compat_syscall_nr
, ret
;
1039 struct lttng_syscall_filter
*filter
;
1041 WARN_ON_ONCE(!chan
->sc_table
);
1043 if (!chan
->sc_filter
) {
1044 if (!chan
->syscall_all
)
1046 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1050 /* Trace all system calls, then apply disable. */
1051 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1052 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1054 filter
= chan
->sc_filter
;
1058 /* Fail if all syscalls are already disabled. */
1059 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1060 && bitmap_empty(filter
->sc_compat
,
1061 NR_compat_syscalls
)) {
1066 /* Disable all system calls */
1067 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1068 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1071 syscall_nr
= get_syscall_nr(name
);
1072 compat_syscall_nr
= get_compat_syscall_nr(name
);
1073 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1077 if (syscall_nr
>= 0) {
1078 if (!test_bit(syscall_nr
, filter
->sc
)) {
1082 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1084 if (compat_syscall_nr
>= 0) {
1085 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1089 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1092 if (!chan
->sc_filter
)
1093 rcu_assign_pointer(chan
->sc_filter
, filter
);
1094 chan
->syscall_all
= 0;
1098 if (!chan
->sc_filter
)
1104 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1106 const struct trace_syscall_entry
*entry
;
1109 for (entry
= sc_table
;
1110 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1115 for (entry
= compat_sc_table
;
1116 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1126 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1128 return (void *) syscall_list_get_entry(pos
);
1132 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1135 return (void *) syscall_list_get_entry(ppos
);
1139 void syscall_list_stop(struct seq_file
*m
, void *p
)
1144 int get_sc_table(const struct trace_syscall_entry
*entry
,
1145 const struct trace_syscall_entry
**table
,
1146 unsigned int *bitness
)
1148 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1150 *bitness
= BITS_PER_LONG
;
1155 if (!(entry
>= compat_sc_table
1156 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1162 *table
= compat_sc_table
;
1167 int syscall_list_show(struct seq_file
*m
, void *p
)
1169 const struct trace_syscall_entry
*table
, *entry
= p
;
1170 unsigned int bitness
;
1171 unsigned long index
;
1175 ret
= get_sc_table(entry
, &table
, &bitness
);
1180 if (table
== sc_table
) {
1181 index
= entry
- table
;
1182 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1184 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1185 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1187 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1188 index
, name
, bitness
);
1193 const struct seq_operations lttng_syscall_list_seq_ops
= {
1194 .start
= syscall_list_start
,
1195 .next
= syscall_list_next
,
1196 .stop
= syscall_list_stop
,
1197 .show
= syscall_list_show
,
1201 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1203 return seq_open(file
, <tng_syscall_list_seq_ops
);
1206 const struct file_operations lttng_syscall_list_fops
= {
1207 .owner
= THIS_MODULE
,
1208 .open
= lttng_syscall_list_open
,
1210 .llseek
= seq_lseek
,
1211 .release
= seq_release
,
1214 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1215 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1217 uint32_t len
, sc_tables_len
, bitmask_len
;
1220 struct lttng_syscall_filter
*filter
;
1222 ret
= get_user(len
, &usyscall_mask
->len
);
1225 sc_tables_len
= get_sc_tables_len();
1226 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1227 if (len
< sc_tables_len
) {
1228 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1230 /* Array is large enough, we can copy array to user-space. */
1231 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1234 filter
= channel
->sc_filter
;
1236 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1239 if (channel
->sc_table
) {
1241 state
= test_bit(bit
, filter
->sc
);
1247 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1249 for (; bit
< sc_tables_len
; bit
++) {
1252 if (channel
->compat_sc_table
) {
1254 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1261 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1263 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1269 int lttng_abi_syscall_list(void)
1271 struct file
*syscall_list_file
;
1274 file_fd
= lttng_get_unused_fd();
1280 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1281 <tng_syscall_list_fops
,
1283 if (IS_ERR(syscall_list_file
)) {
1284 ret
= PTR_ERR(syscall_list_file
);
1287 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1290 fd_install(file_fd
, syscall_list_file
);
1298 fput(syscall_list_file
);
1300 put_unused_fd(file_fd
);