4 * LTTng syscall probes.
6 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; only
11 * version 2.1 of the License.
13 * This library is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with this library; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
23 #include <linux/module.h>
24 #include <linux/slab.h>
25 #include <linux/compat.h>
26 #include <linux/err.h>
27 #include <linux/bitmap.h>
29 #include <linux/in6.h>
30 #include <linux/seq_file.h>
31 #include <linux/stringify.h>
32 #include <linux/file.h>
33 #include <linux/anon_inodes.h>
34 #include <asm/ptrace.h>
35 #include <asm/syscall.h>
37 #include "lib/bitfield.h"
38 #include "wrapper/tracepoint.h"
39 #include "wrapper/file.h"
40 #include "wrapper/rcu.h"
41 #include "lttng-events.h"
44 # ifndef is_compat_task
45 # define is_compat_task() (0)
56 #define SYSCALL_ENTRY_TOK syscall_entry_
57 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
58 #define SYSCALL_EXIT_TOK syscall_exit_
59 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
61 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
62 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
63 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
64 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
67 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
69 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
72 * Forward declarations for old kernels.
76 struct oldold_utsname
;
78 struct sel_arg_struct
;
79 struct mmap_arg_struct
;
81 #ifdef IA32_NR_syscalls
82 #define NR_compat_syscalls IA32_NR_syscalls
84 #define NR_compat_syscalls NR_syscalls
88 * Create LTTng tracepoint probes.
90 #define LTTNG_PACKAGE_BUILD
91 #define CREATE_TRACE_POINTS
92 #define TP_MODULE_NOINIT
93 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
95 #define PARAMS(args...) args
97 /* Handle unknown syscalls */
99 #define TRACE_SYSTEM syscalls_unknown
100 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
108 #define sc_in(...) __VA_ARGS__
112 #define sc_inout(...) __VA_ARGS__
114 /* Hijack probe callback for system call enter */
116 #define TP_PROBE_CB(_template) &syscall_entry_probe
117 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
118 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
120 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _fields) \
121 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
122 PARAMS(_locvar), PARAMS(_code), \
124 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
125 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_fields))
126 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
127 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
129 #define TRACE_SYSTEM syscall_entry_integers
130 #define TRACE_INCLUDE_FILE syscalls_integers
131 #include "instrumentation/syscalls/headers/syscalls_integers.h"
132 #undef TRACE_INCLUDE_FILE
134 #define TRACE_SYSTEM syscall_entry_pointers
135 #define TRACE_INCLUDE_FILE syscalls_pointers
136 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
137 #undef TRACE_INCLUDE_FILE
139 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
140 #undef SC_LTTNG_TRACEPOINT_EVENT
141 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
142 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
144 #undef _TRACE_SYSCALLS_INTEGERS_H
145 #undef _TRACE_SYSCALLS_POINTERS_H
147 /* Hijack probe callback for compat system call enter */
148 #define TP_PROBE_CB(_template) &syscall_entry_probe
149 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
150 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
152 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _fields) \
153 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
154 PARAMS(_locvar), PARAMS(_code), PARAMS(_fields))
155 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
156 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_fields))
157 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
158 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
159 compat_syscall_entry_##_name)
160 #define TRACE_SYSTEM compat_syscall_entry_integers
161 #define TRACE_INCLUDE_FILE compat_syscalls_integers
162 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
163 #undef TRACE_INCLUDE_FILE
165 #define TRACE_SYSTEM compat_syscall_entry_pointers
166 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
167 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
168 #undef TRACE_INCLUDE_FILE
170 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
171 #undef SC_LTTNG_TRACEPOINT_EVENT
172 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
173 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
175 #undef _TRACE_SYSCALLS_INTEGERS_H
176 #undef _TRACE_SYSCALLS_POINTERS_H
183 #define sc_exit(...) __VA_ARGS__
187 #define sc_out(...) __VA_ARGS__
189 #define sc_inout(...) __VA_ARGS__
191 /* Hijack probe callback for system call exit */
192 #define TP_PROBE_CB(_template) &syscall_exit_probe
193 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
194 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
196 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _fields) \
197 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
198 PARAMS(_locvar), PARAMS(_code), PARAMS(_fields))
199 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
200 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_fields))
201 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
202 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
203 syscall_exit_##_name)
204 #define TRACE_SYSTEM syscall_exit_integers
205 #define TRACE_INCLUDE_FILE syscalls_integers
206 #include "instrumentation/syscalls/headers/syscalls_integers.h"
207 #undef TRACE_INCLUDE_FILE
209 #define TRACE_SYSTEM syscall_exit_pointers
210 #define TRACE_INCLUDE_FILE syscalls_pointers
211 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
212 #undef TRACE_INCLUDE_FILE
214 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
215 #undef SC_LTTNG_TRACEPOINT_EVENT
216 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
217 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
219 #undef _TRACE_SYSCALLS_INTEGERS_H
220 #undef _TRACE_SYSCALLS_POINTERS_H
223 /* Hijack probe callback for compat system call exit */
224 #define TP_PROBE_CB(_template) &syscall_exit_probe
225 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
226 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
228 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code, _fields) \
229 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
230 PARAMS(_locvar), PARAMS(_code), PARAMS(_fields))
231 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
232 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_fields))
233 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
234 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
235 compat_syscall_exit_##_name)
236 #define TRACE_SYSTEM compat_syscall_exit_integers
237 #define TRACE_INCLUDE_FILE compat_syscalls_integers
238 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
239 #undef TRACE_INCLUDE_FILE
241 #define TRACE_SYSTEM compat_syscall_exit_pointers
242 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
243 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
244 #undef TRACE_INCLUDE_FILE
246 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
247 #undef SC_LTTNG_TRACEPOINT_EVENT
248 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
249 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
251 #undef _TRACE_SYSCALLS_INTEGERS_H
252 #undef _TRACE_SYSCALLS_POINTERS_H
256 #undef TP_MODULE_NOINIT
257 #undef LTTNG_PACKAGE_BUILD
258 #undef CREATE_TRACE_POINTS
260 struct trace_syscall_entry
{
262 const struct lttng_event_desc
*desc
;
263 const struct lttng_event_field
*fields
;
267 #define CREATE_SYSCALL_TABLE
274 #undef TRACE_SYSCALL_TABLE
275 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
277 .func = __event_probe__syscall_entry_##_template, \
278 .nrargs = (_nrargs), \
279 .fields = __event_fields___syscall_entry_##_template, \
280 .desc = &__event_desc___syscall_entry_##_name, \
283 /* Syscall enter tracing table */
284 static const struct trace_syscall_entry sc_table
[] = {
285 #include "instrumentation/syscalls/headers/syscalls_integers.h"
286 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
289 #undef TRACE_SYSCALL_TABLE
290 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
292 .func = __event_probe__compat_syscall_entry_##_template, \
293 .nrargs = (_nrargs), \
294 .fields = __event_fields___compat_syscall_entry_##_template, \
295 .desc = &__event_desc___compat_syscall_entry_##_name, \
298 /* Compat syscall enter table */
299 const struct trace_syscall_entry compat_sc_table
[] = {
300 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
301 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
309 #define sc_exit(...) __VA_ARGS__
311 #undef TRACE_SYSCALL_TABLE
312 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
314 .func = __event_probe__syscall_exit_##_template, \
315 .nrargs = (_nrargs), \
316 .fields = __event_fields___syscall_exit_##_template, \
317 .desc = &__event_desc___syscall_exit_##_name, \
320 /* Syscall exit table */
321 static const struct trace_syscall_entry sc_exit_table
[] = {
322 #include "instrumentation/syscalls/headers/syscalls_integers.h"
323 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
326 #undef TRACE_SYSCALL_TABLE
327 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
329 .func = __event_probe__compat_syscall_exit_##_template, \
330 .nrargs = (_nrargs), \
331 .fields = __event_fields___compat_syscall_exit_##_template, \
332 .desc = &__event_desc___compat_syscall_exit_##_name, \
335 /* Compat syscall exit table */
336 const struct trace_syscall_entry compat_sc_exit_table
[] = {
337 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
338 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
343 #undef CREATE_SYSCALL_TABLE
345 struct lttng_syscall_filter
{
346 DECLARE_BITMAP(sc
, NR_syscalls
);
347 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
350 static void syscall_entry_unknown(struct lttng_event
*event
,
351 struct pt_regs
*regs
, unsigned int id
)
353 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
355 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
356 if (unlikely(is_compat_task()))
357 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
359 __event_probe__syscall_entry_unknown(event
, id
, args
);
362 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
364 struct lttng_channel
*chan
= __data
;
365 struct lttng_event
*event
, *unknown_event
;
366 const struct trace_syscall_entry
*table
, *entry
;
369 if (unlikely(is_compat_task())) {
370 struct lttng_syscall_filter
*filter
;
372 filter
= lttng_rcu_dereference(chan
->sc_filter
);
374 if (id
< 0 || id
>= NR_compat_syscalls
375 || !test_bit(id
, filter
->sc_compat
)) {
376 /* System call filtered out. */
380 table
= compat_sc_table
;
381 table_len
= ARRAY_SIZE(compat_sc_table
);
382 unknown_event
= chan
->sc_compat_unknown
;
384 struct lttng_syscall_filter
*filter
;
386 filter
= lttng_rcu_dereference(chan
->sc_filter
);
388 if (id
< 0 || id
>= NR_syscalls
389 || !test_bit(id
, filter
->sc
)) {
390 /* System call filtered out. */
395 table_len
= ARRAY_SIZE(sc_table
);
396 unknown_event
= chan
->sc_unknown
;
398 if (unlikely(id
< 0 || id
>= table_len
)) {
399 syscall_entry_unknown(unknown_event
, regs
, id
);
402 if (unlikely(is_compat_task()))
403 event
= chan
->compat_sc_table
[id
];
405 event
= chan
->sc_table
[id
];
406 if (unlikely(!event
)) {
407 syscall_entry_unknown(unknown_event
, regs
, id
);
411 WARN_ON_ONCE(!entry
);
413 switch (entry
->nrargs
) {
416 void (*fptr
)(void *__data
) = entry
->func
;
423 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
424 unsigned long args
[1];
426 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
427 fptr(event
, args
[0]);
432 void (*fptr
)(void *__data
,
434 unsigned long arg1
) = entry
->func
;
435 unsigned long args
[2];
437 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
438 fptr(event
, args
[0], args
[1]);
443 void (*fptr
)(void *__data
,
446 unsigned long arg2
) = entry
->func
;
447 unsigned long args
[3];
449 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
450 fptr(event
, args
[0], args
[1], args
[2]);
455 void (*fptr
)(void *__data
,
459 unsigned long arg3
) = entry
->func
;
460 unsigned long args
[4];
462 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
463 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
468 void (*fptr
)(void *__data
,
473 unsigned long arg4
) = entry
->func
;
474 unsigned long args
[5];
476 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
477 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
482 void (*fptr
)(void *__data
,
488 unsigned long arg5
) = entry
->func
;
489 unsigned long args
[6];
491 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
492 fptr(event
, args
[0], args
[1], args
[2],
493 args
[3], args
[4], args
[5]);
501 static void syscall_exit_unknown(struct lttng_event
*event
,
502 struct pt_regs
*regs
, int id
, long ret
)
504 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
506 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
507 if (unlikely(is_compat_task()))
508 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
511 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
514 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
516 struct lttng_channel
*chan
= __data
;
517 struct lttng_event
*event
, *unknown_event
;
518 const struct trace_syscall_entry
*table
, *entry
;
522 id
= syscall_get_nr(current
, regs
);
523 if (unlikely(is_compat_task())) {
524 struct lttng_syscall_filter
*filter
;
526 filter
= lttng_rcu_dereference(chan
->sc_filter
);
528 if (id
< 0 || id
>= NR_compat_syscalls
529 || !test_bit(id
, filter
->sc_compat
)) {
530 /* System call filtered out. */
534 table
= compat_sc_exit_table
;
535 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
536 unknown_event
= chan
->compat_sc_exit_unknown
;
538 struct lttng_syscall_filter
*filter
;
540 filter
= lttng_rcu_dereference(chan
->sc_filter
);
542 if (id
< 0 || id
>= NR_syscalls
543 || !test_bit(id
, filter
->sc
)) {
544 /* System call filtered out. */
548 table
= sc_exit_table
;
549 table_len
= ARRAY_SIZE(sc_exit_table
);
550 unknown_event
= chan
->sc_exit_unknown
;
552 if (unlikely(id
< 0 || id
>= table_len
)) {
553 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
556 if (unlikely(is_compat_task()))
557 event
= chan
->compat_sc_exit_table
[id
];
559 event
= chan
->sc_exit_table
[id
];
560 if (unlikely(!event
)) {
561 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
565 WARN_ON_ONCE(!entry
);
567 switch (entry
->nrargs
) {
570 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
577 void (*fptr
)(void *__data
,
579 unsigned long arg0
) = entry
->func
;
580 unsigned long args
[1];
582 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
583 fptr(event
, ret
, args
[0]);
588 void (*fptr
)(void *__data
,
591 unsigned long arg1
) = entry
->func
;
592 unsigned long args
[2];
594 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
595 fptr(event
, ret
, args
[0], args
[1]);
600 void (*fptr
)(void *__data
,
604 unsigned long arg2
) = entry
->func
;
605 unsigned long args
[3];
607 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
608 fptr(event
, ret
, args
[0], args
[1], args
[2]);
613 void (*fptr
)(void *__data
,
618 unsigned long arg3
) = entry
->func
;
619 unsigned long args
[4];
621 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
622 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
627 void (*fptr
)(void *__data
,
633 unsigned long arg4
) = entry
->func
;
634 unsigned long args
[5];
636 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
637 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
642 void (*fptr
)(void *__data
,
649 unsigned long arg5
) = entry
->func
;
650 unsigned long args
[6];
652 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
653 fptr(event
, ret
, args
[0], args
[1], args
[2],
654 args
[3], args
[4], args
[5]);
663 * noinline to diminish caller stack size.
664 * Should be called with sessions lock held.
667 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
668 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
669 void *filter
, enum sc_type type
)
671 const struct lttng_event_desc
*desc
;
674 /* Allocate events for each syscall, insert into table */
675 for (i
= 0; i
< table_len
; i
++) {
676 struct lttng_kernel_event ev
;
677 desc
= table
[i
].desc
;
680 /* Unknown syscall */
684 * Skip those already populated by previous failed
685 * register for this channel.
689 memset(&ev
, 0, sizeof(ev
));
692 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
693 LTTNG_KERNEL_SYM_NAME_LEN
);
696 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
697 LTTNG_KERNEL_SYM_NAME_LEN
);
699 case SC_TYPE_COMPAT_ENTRY
:
700 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
701 LTTNG_KERNEL_SYM_NAME_LEN
);
703 case SC_TYPE_COMPAT_EXIT
:
704 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
705 LTTNG_KERNEL_SYM_NAME_LEN
);
711 strncat(ev
.name
, desc
->name
,
712 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
713 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
714 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
715 chan_table
[i
] = _lttng_event_create(chan
, &ev
, filter
,
716 desc
, ev
.instrumentation
);
717 WARN_ON_ONCE(!chan_table
[i
]);
718 if (IS_ERR(chan_table
[i
])) {
720 * If something goes wrong in event registration
721 * after the first one, we have no choice but to
722 * leave the previous events in there, until
723 * deleted by session teardown.
725 return PTR_ERR(chan_table
[i
]);
732 * Should be called with sessions lock held.
734 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
736 struct lttng_kernel_event ev
;
739 wrapper_vmalloc_sync_all();
741 if (!chan
->sc_table
) {
742 /* create syscall table mapping syscall to events */
743 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
744 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
748 if (!chan
->sc_exit_table
) {
749 /* create syscall table mapping syscall to events */
750 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
751 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
752 if (!chan
->sc_exit_table
)
758 if (!chan
->compat_sc_table
) {
759 /* create syscall table mapping compat syscall to events */
760 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
761 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
762 if (!chan
->compat_sc_table
)
766 if (!chan
->compat_sc_exit_table
) {
767 /* create syscall table mapping compat syscall to events */
768 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
769 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
770 if (!chan
->compat_sc_exit_table
)
774 if (!chan
->sc_unknown
) {
775 const struct lttng_event_desc
*desc
=
776 &__event_desc___syscall_entry_unknown
;
778 memset(&ev
, 0, sizeof(ev
));
779 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
780 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
781 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
782 chan
->sc_unknown
= _lttng_event_create(chan
, &ev
, filter
,
785 WARN_ON_ONCE(!chan
->sc_unknown
);
786 if (IS_ERR(chan
->sc_unknown
)) {
787 return PTR_ERR(chan
->sc_unknown
);
791 if (!chan
->sc_compat_unknown
) {
792 const struct lttng_event_desc
*desc
=
793 &__event_desc___compat_syscall_entry_unknown
;
795 memset(&ev
, 0, sizeof(ev
));
796 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
797 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
798 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
799 chan
->sc_compat_unknown
= _lttng_event_create(chan
, &ev
, filter
,
802 WARN_ON_ONCE(!chan
->sc_unknown
);
803 if (IS_ERR(chan
->sc_compat_unknown
)) {
804 return PTR_ERR(chan
->sc_compat_unknown
);
808 if (!chan
->compat_sc_exit_unknown
) {
809 const struct lttng_event_desc
*desc
=
810 &__event_desc___compat_syscall_exit_unknown
;
812 memset(&ev
, 0, sizeof(ev
));
813 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
814 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
815 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
816 chan
->compat_sc_exit_unknown
= _lttng_event_create(chan
, &ev
,
819 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
820 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
821 return PTR_ERR(chan
->compat_sc_exit_unknown
);
825 if (!chan
->sc_exit_unknown
) {
826 const struct lttng_event_desc
*desc
=
827 &__event_desc___syscall_exit_unknown
;
829 memset(&ev
, 0, sizeof(ev
));
830 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
831 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
832 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
833 chan
->sc_exit_unknown
= _lttng_event_create(chan
, &ev
, filter
,
834 desc
, ev
.instrumentation
);
835 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
836 if (IS_ERR(chan
->sc_exit_unknown
)) {
837 return PTR_ERR(chan
->sc_exit_unknown
);
841 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
842 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
845 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
846 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
851 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
852 chan
->compat_sc_table
, chan
, filter
,
853 SC_TYPE_COMPAT_ENTRY
);
856 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
857 chan
->compat_sc_exit_table
, chan
, filter
,
858 SC_TYPE_COMPAT_EXIT
);
862 if (!chan
->sys_enter_registered
) {
863 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
864 (void *) syscall_entry_probe
, chan
);
867 chan
->sys_enter_registered
= 1;
870 * We change the name of sys_exit tracepoint due to namespace
871 * conflict with sys_exit syscall entry.
873 if (!chan
->sys_exit_registered
) {
874 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
875 (void *) syscall_exit_probe
, chan
);
877 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
878 (void *) syscall_entry_probe
, chan
));
881 chan
->sys_exit_registered
= 1;
887 * Only called at session destruction.
889 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
895 if (chan
->sys_enter_registered
) {
896 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
897 (void *) syscall_exit_probe
, chan
);
900 chan
->sys_enter_registered
= 0;
902 if (chan
->sys_exit_registered
) {
903 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
904 (void *) syscall_entry_probe
, chan
);
907 chan
->sys_exit_registered
= 0;
909 /* lttng_event destroy will be performed by lttng_session_destroy() */
910 kfree(chan
->sc_table
);
911 kfree(chan
->sc_exit_table
);
913 kfree(chan
->compat_sc_table
);
914 kfree(chan
->compat_sc_exit_table
);
916 kfree(chan
->sc_filter
);
921 int get_syscall_nr(const char *syscall_name
)
926 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
927 const struct trace_syscall_entry
*entry
;
930 entry
= &sc_table
[i
];
933 it_name
= entry
->desc
->name
;
934 it_name
+= strlen(SYSCALL_ENTRY_STR
);
935 if (!strcmp(syscall_name
, it_name
)) {
944 int get_compat_syscall_nr(const char *syscall_name
)
949 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
950 const struct trace_syscall_entry
*entry
;
953 entry
= &compat_sc_table
[i
];
956 it_name
= entry
->desc
->name
;
957 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
958 if (!strcmp(syscall_name
, it_name
)) {
967 uint32_t get_sc_tables_len(void)
969 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
972 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
975 int syscall_nr
, compat_syscall_nr
, ret
;
976 struct lttng_syscall_filter
*filter
;
978 WARN_ON_ONCE(!chan
->sc_table
);
981 /* Enable all system calls by removing filter */
982 if (chan
->sc_filter
) {
983 filter
= chan
->sc_filter
;
984 rcu_assign_pointer(chan
->sc_filter
, NULL
);
988 chan
->syscall_all
= 1;
992 if (!chan
->sc_filter
) {
993 if (chan
->syscall_all
) {
995 * All syscalls are already enabled.
999 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1004 filter
= chan
->sc_filter
;
1006 syscall_nr
= get_syscall_nr(name
);
1007 compat_syscall_nr
= get_compat_syscall_nr(name
);
1008 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1012 if (syscall_nr
>= 0) {
1013 if (test_bit(syscall_nr
, filter
->sc
)) {
1017 bitmap_set(filter
->sc
, syscall_nr
, 1);
1019 if (compat_syscall_nr
>= 0) {
1020 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1024 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1026 if (!chan
->sc_filter
)
1027 rcu_assign_pointer(chan
->sc_filter
, filter
);
1031 if (!chan
->sc_filter
)
1036 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1039 int syscall_nr
, compat_syscall_nr
, ret
;
1040 struct lttng_syscall_filter
*filter
;
1042 WARN_ON_ONCE(!chan
->sc_table
);
1044 if (!chan
->sc_filter
) {
1045 if (!chan
->syscall_all
)
1047 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1051 /* Trace all system calls, then apply disable. */
1052 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1053 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1055 filter
= chan
->sc_filter
;
1059 /* Fail if all syscalls are already disabled. */
1060 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1061 && bitmap_empty(filter
->sc_compat
,
1062 NR_compat_syscalls
)) {
1067 /* Disable all system calls */
1068 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1069 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1072 syscall_nr
= get_syscall_nr(name
);
1073 compat_syscall_nr
= get_compat_syscall_nr(name
);
1074 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1078 if (syscall_nr
>= 0) {
1079 if (!test_bit(syscall_nr
, filter
->sc
)) {
1083 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1085 if (compat_syscall_nr
>= 0) {
1086 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1090 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1093 if (!chan
->sc_filter
)
1094 rcu_assign_pointer(chan
->sc_filter
, filter
);
1095 chan
->syscall_all
= 0;
1099 if (!chan
->sc_filter
)
1105 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1107 const struct trace_syscall_entry
*entry
;
1110 for (entry
= sc_table
;
1111 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1116 for (entry
= compat_sc_table
;
1117 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1127 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1129 return (void *) syscall_list_get_entry(pos
);
1133 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1136 return (void *) syscall_list_get_entry(ppos
);
1140 void syscall_list_stop(struct seq_file
*m
, void *p
)
1145 int get_sc_table(const struct trace_syscall_entry
*entry
,
1146 const struct trace_syscall_entry
**table
,
1147 unsigned int *bitness
)
1149 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1151 *bitness
= BITS_PER_LONG
;
1156 if (!(entry
>= compat_sc_table
1157 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1163 *table
= compat_sc_table
;
1168 int syscall_list_show(struct seq_file
*m
, void *p
)
1170 const struct trace_syscall_entry
*table
, *entry
= p
;
1171 unsigned int bitness
;
1172 unsigned long index
;
1176 ret
= get_sc_table(entry
, &table
, &bitness
);
1181 if (table
== sc_table
) {
1182 index
= entry
- table
;
1183 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1185 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1186 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1188 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1189 index
, name
, bitness
);
1194 const struct seq_operations lttng_syscall_list_seq_ops
= {
1195 .start
= syscall_list_start
,
1196 .next
= syscall_list_next
,
1197 .stop
= syscall_list_stop
,
1198 .show
= syscall_list_show
,
1202 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1204 return seq_open(file
, <tng_syscall_list_seq_ops
);
1207 const struct file_operations lttng_syscall_list_fops
= {
1208 .owner
= THIS_MODULE
,
1209 .open
= lttng_syscall_list_open
,
1211 .llseek
= seq_lseek
,
1212 .release
= seq_release
,
1215 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1216 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1218 uint32_t len
, sc_tables_len
, bitmask_len
;
1221 struct lttng_syscall_filter
*filter
;
1223 ret
= get_user(len
, &usyscall_mask
->len
);
1226 sc_tables_len
= get_sc_tables_len();
1227 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1228 if (len
< sc_tables_len
) {
1229 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1231 /* Array is large enough, we can copy array to user-space. */
1232 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1235 filter
= channel
->sc_filter
;
1237 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1240 if (channel
->sc_table
) {
1242 state
= test_bit(bit
, filter
->sc
);
1248 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1250 for (; bit
< sc_tables_len
; bit
++) {
1253 if (channel
->compat_sc_table
) {
1255 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1262 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1264 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1270 int lttng_abi_syscall_list(void)
1272 struct file
*syscall_list_file
;
1275 file_fd
= lttng_get_unused_fd();
1281 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1282 <tng_syscall_list_fops
,
1284 if (IS_ERR(syscall_list_file
)) {
1285 ret
= PTR_ERR(syscall_list_file
);
1288 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1291 fd_install(file_fd
, syscall_list_file
);
1299 fput(syscall_list_file
);
1301 put_unused_fd(file_fd
);