1 /* SPDX-License-Identifier: (GPL-2.0 or LGPL-2.1)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <asm/ptrace.h>
22 #include <asm/syscall.h>
24 #include <lib/bitfield.h>
25 #include <wrapper/tracepoint.h>
26 #include <wrapper/file.h>
27 #include <wrapper/rcu.h>
28 #include <lttng-events.h>
31 # ifndef is_compat_task
32 # define is_compat_task() (0)
36 /* in_compat_syscall appears in kernel 4.6. */
37 #ifndef in_compat_syscall
38 #define in_compat_syscall() is_compat_task()
48 #define SYSCALL_ENTRY_TOK syscall_entry_
49 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
50 #define SYSCALL_EXIT_TOK syscall_exit_
51 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
53 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
54 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
55 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
56 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
59 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
61 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
64 * Forward declarations for old kernels.
68 struct oldold_utsname
;
70 struct sel_arg_struct
;
71 struct mmap_arg_struct
;
75 #ifdef IA32_NR_syscalls
76 #define NR_compat_syscalls IA32_NR_syscalls
78 #define NR_compat_syscalls NR_syscalls
82 * Create LTTng tracepoint probes.
84 #define LTTNG_PACKAGE_BUILD
85 #define CREATE_TRACE_POINTS
86 #define TP_MODULE_NOINIT
87 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
89 #define PARAMS(args...) args
91 /* Handle unknown syscalls */
93 #define TRACE_SYSTEM syscalls_unknown
94 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
102 #define sc_in(...) __VA_ARGS__
106 #define sc_inout(...) __VA_ARGS__
108 /* Hijack probe callback for system call enter */
110 #define TP_PROBE_CB(_template) &syscall_entry_probe
111 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
112 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
114 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
115 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
116 PARAMS(_locvar), PARAMS(_code_pre), \
117 PARAMS(_fields), PARAMS(_code_post))
118 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
119 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_fields))
120 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
121 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
122 /* Enumerations only defined at first inclusion. */
123 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values) \
124 LTTNG_TRACEPOINT_ENUM(_name, PARAMS(_values))
126 #define TRACE_SYSTEM syscall_entry_integers
127 #define TRACE_INCLUDE_FILE syscalls_integers
128 #include <instrumentation/syscalls/headers/syscalls_integers.h>
129 #undef TRACE_INCLUDE_FILE
131 #define TRACE_SYSTEM syscall_entry_pointers
132 #define TRACE_INCLUDE_FILE syscalls_pointers
133 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
134 #undef TRACE_INCLUDE_FILE
136 #undef SC_LTTNG_TRACEPOINT_ENUM
137 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
138 #undef SC_LTTNG_TRACEPOINT_EVENT
139 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
140 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
142 #undef _TRACE_SYSCALLS_INTEGERS_H
143 #undef _TRACE_SYSCALLS_POINTERS_H
145 /* Hijack probe callback for compat system call enter */
146 #define TP_PROBE_CB(_template) &syscall_entry_probe
147 #define LTTNG_SC_COMPAT
148 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
149 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
151 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
152 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
153 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
154 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
155 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_fields))
156 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
157 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
158 compat_syscall_entry_##_name)
159 /* Enumerations only defined at inital inclusion (not here). */
160 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
161 #define TRACE_SYSTEM compat_syscall_entry_integers
162 #define TRACE_INCLUDE_FILE compat_syscalls_integers
163 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
164 #undef TRACE_INCLUDE_FILE
166 #define TRACE_SYSTEM compat_syscall_entry_pointers
167 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
168 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
169 #undef TRACE_INCLUDE_FILE
171 #undef SC_LTTNG_TRACEPOINT_ENUM
172 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
173 #undef SC_LTTNG_TRACEPOINT_EVENT
174 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
175 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
177 #undef _TRACE_SYSCALLS_INTEGERS_H
178 #undef _TRACE_SYSCALLS_POINTERS_H
179 #undef LTTNG_SC_COMPAT
186 #define sc_exit(...) __VA_ARGS__
190 #define sc_out(...) __VA_ARGS__
192 #define sc_inout(...) __VA_ARGS__
194 /* Hijack probe callback for system call exit */
195 #define TP_PROBE_CB(_template) &syscall_exit_probe
196 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
197 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
199 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
200 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
201 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
202 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
203 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_fields))
204 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
205 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
206 syscall_exit_##_name)
207 /* Enumerations only defined at inital inclusion (not here). */
208 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
209 #define TRACE_SYSTEM syscall_exit_integers
210 #define TRACE_INCLUDE_FILE syscalls_integers
211 #include <instrumentation/syscalls/headers/syscalls_integers.h>
212 #undef TRACE_INCLUDE_FILE
214 #define TRACE_SYSTEM syscall_exit_pointers
215 #define TRACE_INCLUDE_FILE syscalls_pointers
216 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
217 #undef TRACE_INCLUDE_FILE
219 #undef SC_LTTNG_TRACEPOINT_ENUM
220 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
221 #undef SC_LTTNG_TRACEPOINT_EVENT
222 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
223 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
225 #undef _TRACE_SYSCALLS_INTEGERS_H
226 #undef _TRACE_SYSCALLS_POINTERS_H
229 /* Hijack probe callback for compat system call exit */
230 #define TP_PROBE_CB(_template) &syscall_exit_probe
231 #define LTTNG_SC_COMPAT
232 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
233 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
235 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
236 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
237 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
238 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
239 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_fields))
240 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
241 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
242 compat_syscall_exit_##_name)
243 /* Enumerations only defined at inital inclusion (not here). */
244 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
245 #define TRACE_SYSTEM compat_syscall_exit_integers
246 #define TRACE_INCLUDE_FILE compat_syscalls_integers
247 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
248 #undef TRACE_INCLUDE_FILE
250 #define TRACE_SYSTEM compat_syscall_exit_pointers
251 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
252 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
253 #undef TRACE_INCLUDE_FILE
255 #undef SC_LTTNG_TRACEPOINT_ENUM
256 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
257 #undef SC_LTTNG_TRACEPOINT_EVENT
258 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
259 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
261 #undef _TRACE_SYSCALLS_INTEGERS_H
262 #undef _TRACE_SYSCALLS_POINTERS_H
263 #undef LTTNG_SC_COMPAT
267 #undef TP_MODULE_NOINIT
268 #undef LTTNG_PACKAGE_BUILD
269 #undef CREATE_TRACE_POINTS
271 struct trace_syscall_entry
{
273 const struct lttng_event_desc
*desc
;
274 const struct lttng_event_field
*fields
;
278 #define CREATE_SYSCALL_TABLE
285 #undef TRACE_SYSCALL_TABLE
286 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
288 .func = __event_probe__syscall_entry_##_template, \
289 .nrargs = (_nrargs), \
290 .fields = __event_fields___syscall_entry_##_template, \
291 .desc = &__event_desc___syscall_entry_##_name, \
294 /* Syscall enter tracing table */
295 static const struct trace_syscall_entry sc_table
[] = {
296 #include <instrumentation/syscalls/headers/syscalls_integers.h>
297 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
300 #undef TRACE_SYSCALL_TABLE
301 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
303 .func = __event_probe__compat_syscall_entry_##_template, \
304 .nrargs = (_nrargs), \
305 .fields = __event_fields___compat_syscall_entry_##_template, \
306 .desc = &__event_desc___compat_syscall_entry_##_name, \
309 /* Compat syscall enter table */
310 const struct trace_syscall_entry compat_sc_table
[] = {
311 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
312 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
320 #define sc_exit(...) __VA_ARGS__
322 #undef TRACE_SYSCALL_TABLE
323 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
325 .func = __event_probe__syscall_exit_##_template, \
326 .nrargs = (_nrargs), \
327 .fields = __event_fields___syscall_exit_##_template, \
328 .desc = &__event_desc___syscall_exit_##_name, \
331 /* Syscall exit table */
332 static const struct trace_syscall_entry sc_exit_table
[] = {
333 #include <instrumentation/syscalls/headers/syscalls_integers.h>
334 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
337 #undef TRACE_SYSCALL_TABLE
338 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
340 .func = __event_probe__compat_syscall_exit_##_template, \
341 .nrargs = (_nrargs), \
342 .fields = __event_fields___compat_syscall_exit_##_template, \
343 .desc = &__event_desc___compat_syscall_exit_##_name, \
346 /* Compat syscall exit table */
347 const struct trace_syscall_entry compat_sc_exit_table
[] = {
348 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
349 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
354 #undef CREATE_SYSCALL_TABLE
356 struct lttng_syscall_filter
{
357 DECLARE_BITMAP(sc
, NR_syscalls
);
358 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
361 static void syscall_entry_unknown(struct lttng_event
*event
,
362 struct pt_regs
*regs
, unsigned int id
)
364 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
366 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
367 if (unlikely(in_compat_syscall()))
368 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
370 __event_probe__syscall_entry_unknown(event
, id
, args
);
373 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
375 struct lttng_channel
*chan
= __data
;
376 struct lttng_event
*event
, *unknown_event
;
377 const struct trace_syscall_entry
*table
, *entry
;
380 if (unlikely(in_compat_syscall())) {
381 struct lttng_syscall_filter
*filter
;
383 filter
= lttng_rcu_dereference(chan
->sc_filter
);
385 if (id
< 0 || id
>= NR_compat_syscalls
386 || !test_bit(id
, filter
->sc_compat
)) {
387 /* System call filtered out. */
391 table
= compat_sc_table
;
392 table_len
= ARRAY_SIZE(compat_sc_table
);
393 unknown_event
= chan
->sc_compat_unknown
;
395 struct lttng_syscall_filter
*filter
;
397 filter
= lttng_rcu_dereference(chan
->sc_filter
);
399 if (id
< 0 || id
>= NR_syscalls
400 || !test_bit(id
, filter
->sc
)) {
401 /* System call filtered out. */
406 table_len
= ARRAY_SIZE(sc_table
);
407 unknown_event
= chan
->sc_unknown
;
409 if (unlikely(id
< 0 || id
>= table_len
)) {
410 syscall_entry_unknown(unknown_event
, regs
, id
);
413 if (unlikely(in_compat_syscall()))
414 event
= chan
->compat_sc_table
[id
];
416 event
= chan
->sc_table
[id
];
417 if (unlikely(!event
)) {
418 syscall_entry_unknown(unknown_event
, regs
, id
);
422 WARN_ON_ONCE(!entry
);
424 switch (entry
->nrargs
) {
427 void (*fptr
)(void *__data
) = entry
->func
;
434 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
435 unsigned long args
[1];
437 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
438 fptr(event
, args
[0]);
443 void (*fptr
)(void *__data
,
445 unsigned long arg1
) = entry
->func
;
446 unsigned long args
[2];
448 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
449 fptr(event
, args
[0], args
[1]);
454 void (*fptr
)(void *__data
,
457 unsigned long arg2
) = entry
->func
;
458 unsigned long args
[3];
460 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
461 fptr(event
, args
[0], args
[1], args
[2]);
466 void (*fptr
)(void *__data
,
470 unsigned long arg3
) = entry
->func
;
471 unsigned long args
[4];
473 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
474 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
479 void (*fptr
)(void *__data
,
484 unsigned long arg4
) = entry
->func
;
485 unsigned long args
[5];
487 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
488 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
493 void (*fptr
)(void *__data
,
499 unsigned long arg5
) = entry
->func
;
500 unsigned long args
[6];
502 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
503 fptr(event
, args
[0], args
[1], args
[2],
504 args
[3], args
[4], args
[5]);
512 static void syscall_exit_unknown(struct lttng_event
*event
,
513 struct pt_regs
*regs
, int id
, long ret
)
515 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
517 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
518 if (unlikely(in_compat_syscall()))
519 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
522 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
525 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
527 struct lttng_channel
*chan
= __data
;
528 struct lttng_event
*event
, *unknown_event
;
529 const struct trace_syscall_entry
*table
, *entry
;
533 id
= syscall_get_nr(current
, regs
);
534 if (unlikely(in_compat_syscall())) {
535 struct lttng_syscall_filter
*filter
;
537 filter
= lttng_rcu_dereference(chan
->sc_filter
);
539 if (id
< 0 || id
>= NR_compat_syscalls
540 || !test_bit(id
, filter
->sc_compat
)) {
541 /* System call filtered out. */
545 table
= compat_sc_exit_table
;
546 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
547 unknown_event
= chan
->compat_sc_exit_unknown
;
549 struct lttng_syscall_filter
*filter
;
551 filter
= lttng_rcu_dereference(chan
->sc_filter
);
553 if (id
< 0 || id
>= NR_syscalls
554 || !test_bit(id
, filter
->sc
)) {
555 /* System call filtered out. */
559 table
= sc_exit_table
;
560 table_len
= ARRAY_SIZE(sc_exit_table
);
561 unknown_event
= chan
->sc_exit_unknown
;
563 if (unlikely(id
< 0 || id
>= table_len
)) {
564 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
567 if (unlikely(in_compat_syscall()))
568 event
= chan
->compat_sc_exit_table
[id
];
570 event
= chan
->sc_exit_table
[id
];
571 if (unlikely(!event
)) {
572 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
576 WARN_ON_ONCE(!entry
);
578 switch (entry
->nrargs
) {
581 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
588 void (*fptr
)(void *__data
,
590 unsigned long arg0
) = entry
->func
;
591 unsigned long args
[1];
593 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
594 fptr(event
, ret
, args
[0]);
599 void (*fptr
)(void *__data
,
602 unsigned long arg1
) = entry
->func
;
603 unsigned long args
[2];
605 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
606 fptr(event
, ret
, args
[0], args
[1]);
611 void (*fptr
)(void *__data
,
615 unsigned long arg2
) = entry
->func
;
616 unsigned long args
[3];
618 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
619 fptr(event
, ret
, args
[0], args
[1], args
[2]);
624 void (*fptr
)(void *__data
,
629 unsigned long arg3
) = entry
->func
;
630 unsigned long args
[4];
632 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
633 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
638 void (*fptr
)(void *__data
,
644 unsigned long arg4
) = entry
->func
;
645 unsigned long args
[5];
647 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
648 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
653 void (*fptr
)(void *__data
,
660 unsigned long arg5
) = entry
->func
;
661 unsigned long args
[6];
663 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
664 fptr(event
, ret
, args
[0], args
[1], args
[2],
665 args
[3], args
[4], args
[5]);
674 * noinline to diminish caller stack size.
675 * Should be called with sessions lock held.
678 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
679 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
680 void *filter
, enum sc_type type
)
682 const struct lttng_event_desc
*desc
;
685 /* Allocate events for each syscall, insert into table */
686 for (i
= 0; i
< table_len
; i
++) {
687 struct lttng_kernel_event ev
;
688 desc
= table
[i
].desc
;
691 /* Unknown syscall */
695 * Skip those already populated by previous failed
696 * register for this channel.
700 memset(&ev
, 0, sizeof(ev
));
703 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
704 LTTNG_KERNEL_SYM_NAME_LEN
);
707 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
708 LTTNG_KERNEL_SYM_NAME_LEN
);
710 case SC_TYPE_COMPAT_ENTRY
:
711 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
712 LTTNG_KERNEL_SYM_NAME_LEN
);
714 case SC_TYPE_COMPAT_EXIT
:
715 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
716 LTTNG_KERNEL_SYM_NAME_LEN
);
722 strncat(ev
.name
, desc
->name
,
723 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
724 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
725 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
726 chan_table
[i
] = _lttng_event_create(chan
, &ev
, filter
,
727 desc
, ev
.instrumentation
);
728 WARN_ON_ONCE(!chan_table
[i
]);
729 if (IS_ERR(chan_table
[i
])) {
731 * If something goes wrong in event registration
732 * after the first one, we have no choice but to
733 * leave the previous events in there, until
734 * deleted by session teardown.
736 return PTR_ERR(chan_table
[i
]);
743 * Should be called with sessions lock held.
745 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
747 struct lttng_kernel_event ev
;
750 wrapper_vmalloc_sync_all();
752 if (!chan
->sc_table
) {
753 /* create syscall table mapping syscall to events */
754 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
755 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
759 if (!chan
->sc_exit_table
) {
760 /* create syscall table mapping syscall to events */
761 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
762 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
763 if (!chan
->sc_exit_table
)
769 if (!chan
->compat_sc_table
) {
770 /* create syscall table mapping compat syscall to events */
771 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
772 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
773 if (!chan
->compat_sc_table
)
777 if (!chan
->compat_sc_exit_table
) {
778 /* create syscall table mapping compat syscall to events */
779 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
780 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
781 if (!chan
->compat_sc_exit_table
)
785 if (!chan
->sc_unknown
) {
786 const struct lttng_event_desc
*desc
=
787 &__event_desc___syscall_entry_unknown
;
789 memset(&ev
, 0, sizeof(ev
));
790 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
791 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
792 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
793 chan
->sc_unknown
= _lttng_event_create(chan
, &ev
, filter
,
796 WARN_ON_ONCE(!chan
->sc_unknown
);
797 if (IS_ERR(chan
->sc_unknown
)) {
798 return PTR_ERR(chan
->sc_unknown
);
802 if (!chan
->sc_compat_unknown
) {
803 const struct lttng_event_desc
*desc
=
804 &__event_desc___compat_syscall_entry_unknown
;
806 memset(&ev
, 0, sizeof(ev
));
807 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
808 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
809 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
810 chan
->sc_compat_unknown
= _lttng_event_create(chan
, &ev
, filter
,
813 WARN_ON_ONCE(!chan
->sc_unknown
);
814 if (IS_ERR(chan
->sc_compat_unknown
)) {
815 return PTR_ERR(chan
->sc_compat_unknown
);
819 if (!chan
->compat_sc_exit_unknown
) {
820 const struct lttng_event_desc
*desc
=
821 &__event_desc___compat_syscall_exit_unknown
;
823 memset(&ev
, 0, sizeof(ev
));
824 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
825 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
826 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
827 chan
->compat_sc_exit_unknown
= _lttng_event_create(chan
, &ev
,
830 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
831 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
832 return PTR_ERR(chan
->compat_sc_exit_unknown
);
836 if (!chan
->sc_exit_unknown
) {
837 const struct lttng_event_desc
*desc
=
838 &__event_desc___syscall_exit_unknown
;
840 memset(&ev
, 0, sizeof(ev
));
841 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
842 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
843 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
844 chan
->sc_exit_unknown
= _lttng_event_create(chan
, &ev
, filter
,
845 desc
, ev
.instrumentation
);
846 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
847 if (IS_ERR(chan
->sc_exit_unknown
)) {
848 return PTR_ERR(chan
->sc_exit_unknown
);
852 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
853 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
856 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
857 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
862 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
863 chan
->compat_sc_table
, chan
, filter
,
864 SC_TYPE_COMPAT_ENTRY
);
867 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
868 chan
->compat_sc_exit_table
, chan
, filter
,
869 SC_TYPE_COMPAT_EXIT
);
873 if (!chan
->sys_enter_registered
) {
874 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
875 (void *) syscall_entry_probe
, chan
);
878 chan
->sys_enter_registered
= 1;
881 * We change the name of sys_exit tracepoint due to namespace
882 * conflict with sys_exit syscall entry.
884 if (!chan
->sys_exit_registered
) {
885 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
886 (void *) syscall_exit_probe
, chan
);
888 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
889 (void *) syscall_entry_probe
, chan
));
892 chan
->sys_exit_registered
= 1;
898 * Only called at session destruction.
900 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
906 if (chan
->sys_enter_registered
) {
907 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
908 (void *) syscall_exit_probe
, chan
);
911 chan
->sys_enter_registered
= 0;
913 if (chan
->sys_exit_registered
) {
914 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
915 (void *) syscall_entry_probe
, chan
);
918 chan
->sys_exit_registered
= 0;
920 /* lttng_event destroy will be performed by lttng_session_destroy() */
921 kfree(chan
->sc_table
);
922 kfree(chan
->sc_exit_table
);
924 kfree(chan
->compat_sc_table
);
925 kfree(chan
->compat_sc_exit_table
);
927 kfree(chan
->sc_filter
);
932 int get_syscall_nr(const char *syscall_name
)
937 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
938 const struct trace_syscall_entry
*entry
;
941 entry
= &sc_table
[i
];
944 it_name
= entry
->desc
->name
;
945 it_name
+= strlen(SYSCALL_ENTRY_STR
);
946 if (!strcmp(syscall_name
, it_name
)) {
955 int get_compat_syscall_nr(const char *syscall_name
)
960 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
961 const struct trace_syscall_entry
*entry
;
964 entry
= &compat_sc_table
[i
];
967 it_name
= entry
->desc
->name
;
968 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
969 if (!strcmp(syscall_name
, it_name
)) {
978 uint32_t get_sc_tables_len(void)
980 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
983 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
986 int syscall_nr
, compat_syscall_nr
, ret
;
987 struct lttng_syscall_filter
*filter
;
989 WARN_ON_ONCE(!chan
->sc_table
);
992 /* Enable all system calls by removing filter */
993 if (chan
->sc_filter
) {
994 filter
= chan
->sc_filter
;
995 rcu_assign_pointer(chan
->sc_filter
, NULL
);
999 chan
->syscall_all
= 1;
1003 if (!chan
->sc_filter
) {
1004 if (chan
->syscall_all
) {
1006 * All syscalls are already enabled.
1010 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1015 filter
= chan
->sc_filter
;
1017 syscall_nr
= get_syscall_nr(name
);
1018 compat_syscall_nr
= get_compat_syscall_nr(name
);
1019 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1023 if (syscall_nr
>= 0) {
1024 if (test_bit(syscall_nr
, filter
->sc
)) {
1028 bitmap_set(filter
->sc
, syscall_nr
, 1);
1030 if (compat_syscall_nr
>= 0) {
1031 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1035 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1037 if (!chan
->sc_filter
)
1038 rcu_assign_pointer(chan
->sc_filter
, filter
);
1042 if (!chan
->sc_filter
)
1047 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1050 int syscall_nr
, compat_syscall_nr
, ret
;
1051 struct lttng_syscall_filter
*filter
;
1053 WARN_ON_ONCE(!chan
->sc_table
);
1055 if (!chan
->sc_filter
) {
1056 if (!chan
->syscall_all
)
1058 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1062 /* Trace all system calls, then apply disable. */
1063 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1064 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1066 filter
= chan
->sc_filter
;
1070 /* Fail if all syscalls are already disabled. */
1071 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1072 && bitmap_empty(filter
->sc_compat
,
1073 NR_compat_syscalls
)) {
1078 /* Disable all system calls */
1079 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1080 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1083 syscall_nr
= get_syscall_nr(name
);
1084 compat_syscall_nr
= get_compat_syscall_nr(name
);
1085 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1089 if (syscall_nr
>= 0) {
1090 if (!test_bit(syscall_nr
, filter
->sc
)) {
1094 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1096 if (compat_syscall_nr
>= 0) {
1097 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1101 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1104 if (!chan
->sc_filter
)
1105 rcu_assign_pointer(chan
->sc_filter
, filter
);
1106 chan
->syscall_all
= 0;
1110 if (!chan
->sc_filter
)
1116 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1118 const struct trace_syscall_entry
*entry
;
1121 for (entry
= sc_table
;
1122 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1127 for (entry
= compat_sc_table
;
1128 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1138 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1140 return (void *) syscall_list_get_entry(pos
);
1144 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1147 return (void *) syscall_list_get_entry(ppos
);
1151 void syscall_list_stop(struct seq_file
*m
, void *p
)
1156 int get_sc_table(const struct trace_syscall_entry
*entry
,
1157 const struct trace_syscall_entry
**table
,
1158 unsigned int *bitness
)
1160 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1162 *bitness
= BITS_PER_LONG
;
1167 if (!(entry
>= compat_sc_table
1168 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1174 *table
= compat_sc_table
;
1179 int syscall_list_show(struct seq_file
*m
, void *p
)
1181 const struct trace_syscall_entry
*table
, *entry
= p
;
1182 unsigned int bitness
;
1183 unsigned long index
;
1187 ret
= get_sc_table(entry
, &table
, &bitness
);
1192 if (table
== sc_table
) {
1193 index
= entry
- table
;
1194 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1196 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1197 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1199 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1200 index
, name
, bitness
);
1205 const struct seq_operations lttng_syscall_list_seq_ops
= {
1206 .start
= syscall_list_start
,
1207 .next
= syscall_list_next
,
1208 .stop
= syscall_list_stop
,
1209 .show
= syscall_list_show
,
1213 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1215 return seq_open(file
, <tng_syscall_list_seq_ops
);
1218 const struct file_operations lttng_syscall_list_fops
= {
1219 .owner
= THIS_MODULE
,
1220 .open
= lttng_syscall_list_open
,
1222 .llseek
= seq_lseek
,
1223 .release
= seq_release
,
1226 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1227 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1229 uint32_t len
, sc_tables_len
, bitmask_len
;
1232 struct lttng_syscall_filter
*filter
;
1234 ret
= get_user(len
, &usyscall_mask
->len
);
1237 sc_tables_len
= get_sc_tables_len();
1238 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1239 if (len
< sc_tables_len
) {
1240 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1242 /* Array is large enough, we can copy array to user-space. */
1243 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1246 filter
= channel
->sc_filter
;
1248 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1251 if (channel
->sc_table
) {
1253 state
= test_bit(bit
, filter
->sc
);
1259 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1261 for (; bit
< sc_tables_len
; bit
++) {
1264 if (channel
->compat_sc_table
) {
1266 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1273 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1275 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1281 int lttng_abi_syscall_list(void)
1283 struct file
*syscall_list_file
;
1286 file_fd
= lttng_get_unused_fd();
1292 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1293 <tng_syscall_list_fops
,
1295 if (IS_ERR(syscall_list_file
)) {
1296 ret
= PTR_ERR(syscall_list_file
);
1299 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1302 fd_install(file_fd
, syscall_list_file
);
1306 fput(syscall_list_file
);
1308 put_unused_fd(file_fd
);