4 * LTTng syscall probes.
6 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
8 * This library is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU Lesser General Public
10 * License as published by the Free Software Foundation; only
11 * version 2.1 of the License.
13 * This library is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * Lesser General Public License for more details.
18 * You should have received a copy of the GNU Lesser General Public
19 * License along with this library; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
23 #include <linux/module.h>
24 #include <linux/slab.h>
25 #include <linux/compat.h>
26 #include <linux/err.h>
27 #include <linux/bitmap.h>
28 #include <asm/ptrace.h>
29 #include <asm/syscall.h>
31 #include "wrapper/tracepoint.h"
32 #include "lttng-events.h"
35 # ifndef is_compat_task
36 # define is_compat_task() (0)
47 #define SYSCALL_ENTRY_STR "syscall_entry_"
48 #define COMPAT_SYSCALL_ENTRY_STR "compat_syscall_entry_"
49 #define SYSCALL_EXIT_STR "syscall_exit_"
50 #define COMPAT_SYSCALL_EXIT_STR "compat_syscall_exit_"
53 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
55 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
58 * Forward declarations for old kernels.
62 struct oldold_utsname
;
64 struct sel_arg_struct
;
65 struct mmap_arg_struct
;
67 #ifdef IA32_NR_syscalls
68 #define NR_compat_syscalls IA32_NR_syscalls
70 #define NR_compat_syscalls NR_syscalls
74 * Take care of NOARGS not supported by mainline.
76 #define DECLARE_EVENT_CLASS_NOARGS(name, tstruct, assign, print)
77 #define DEFINE_EVENT_NOARGS(template, name)
78 #define TRACE_EVENT_NOARGS(name, struct, assign, print)
81 * Create LTTng tracepoint probes.
83 #define LTTNG_PACKAGE_BUILD
84 #define CREATE_TRACE_POINTS
85 #define TP_MODULE_NOINIT
86 #define TRACE_INCLUDE_PATH ../instrumentation/syscalls/headers
88 #define PARAMS(args...) args
90 /* Handle unknown syscalls */
91 #define TRACE_SYSTEM syscalls_unknown
92 #include "instrumentation/syscalls/headers/syscalls_unknown.h"
96 /* Hijack probe callback for system call enter */
98 #define TP_PROBE_CB(_template) &syscall_entry_probe
99 #define SC_TRACE_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
100 TRACE_EVENT(syscall_enter_##_name, PARAMS(_proto), PARAMS(_args),\
101 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
102 #define SC_DECLARE_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
103 DECLARE_EVENT_CLASS_NOARGS(syscall_enter_##_name, PARAMS(_struct), PARAMS(_assign),\
105 #define SC_DEFINE_EVENT_NOARGS(_template, _name) \
106 DEFINE_EVENT_NOARGS(syscall_enter_##_template, syscall_enter_##_name)
108 #define TRACE_SYSTEM syscall_enter_integers
109 #define TRACE_INCLUDE_FILE syscalls_integers
110 #include "instrumentation/syscalls/headers/syscalls_integers.h"
111 #undef TRACE_INCLUDE_FILE
113 #define TRACE_SYSTEM syscall_enter_pointers
114 #define TRACE_INCLUDE_FILE syscalls_pointers
115 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
116 #undef TRACE_INCLUDE_FILE
118 #undef SC_TRACE_EVENT
119 #undef SC_DECLARE_EVENT_CLASS_NOARGS
120 #undef SC_DEFINE_EVENT_NOARGS
122 #undef _TRACE_SYSCALLS_integers_H
123 #undef _TRACE_SYSCALLS_pointers_H
126 /* Hijack probe callback for compat system call enter */
127 #define TP_PROBE_CB(_template) &syscall_entry_probe
128 #define SC_TRACE_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
129 TRACE_EVENT(compat_syscall_enter_##_name, PARAMS(_proto), PARAMS(_args), \
130 PARAMS(_struct), PARAMS(_assign), \
132 #define SC_DECLARE_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
133 DECLARE_EVENT_CLASS_NOARGS(compat_syscall_enter_##_name, PARAMS(_struct), \
134 PARAMS(_assign), PARAMS(_printk))
135 #define SC_DEFINE_EVENT_NOARGS(_template, _name) \
136 DEFINE_EVENT_NOARGS(compat_syscall_enter_##_template, \
137 compat_syscall_enter_##_name)
138 #define TRACE_SYSTEM compat_syscall_enter_integers
139 #define TRACE_INCLUDE_FILE compat_syscalls_integers
140 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
141 #undef TRACE_INCLUDE_FILE
143 #define TRACE_SYSTEM compat_syscall_enter_pointers
144 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
145 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
146 #undef TRACE_INCLUDE_FILE
148 #undef SC_TRACE_EVENT
149 #undef SC_DECLARE_EVENT_CLASS_NOARGS
150 #undef SC_DEFINE_EVENT_NOARGS
152 #undef _TRACE_SYSCALLS_integers_H
153 #undef _TRACE_SYSCALLS_pointers_H
156 /* Hijack probe callback for system call exit */
157 #define TP_PROBE_CB(_template) &syscall_exit_probe
158 #define SC_TRACE_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
159 TRACE_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args),\
160 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
161 #define SC_DECLARE_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
162 DECLARE_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_struct), \
163 PARAMS(_assign), PARAMS(_printk))
164 #define SC_DEFINE_EVENT_NOARGS(_template, _name) \
165 DEFINE_EVENT_NOARGS(syscall_exit_##_template, \
166 syscall_exit_##_name)
167 #define TRACE_SYSTEM syscall_exit_integers
168 #define TRACE_INCLUDE_FILE syscalls_integers
169 #include "instrumentation/syscalls/headers/syscalls_integers.h"
170 #undef TRACE_INCLUDE_FILE
172 #define TRACE_SYSTEM syscall_exit_pointers
173 #define TRACE_INCLUDE_FILE syscalls_pointers
174 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
175 #undef TRACE_INCLUDE_FILE
177 #undef SC_TRACE_EVENT
178 #undef SC_DECLARE_EVENT_CLASS_NOARGS
179 #undef SC_DEFINE_EVENT_NOARGS
181 #undef _TRACE_SYSCALLS_integers_H
182 #undef _TRACE_SYSCALLS_pointers_H
185 /* Hijack probe callback for compat system call exit */
186 #define TP_PROBE_CB(_template) &syscall_exit_probe
187 #define SC_TRACE_EVENT(_name, _proto, _args, _struct, _assign, _printk) \
188 TRACE_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
189 PARAMS(_struct), PARAMS(_assign), PARAMS(_printk))
190 #define SC_DECLARE_EVENT_CLASS_NOARGS(_name, _struct, _assign, _printk) \
191 DECLARE_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_struct), \
192 PARAMS(_assign), PARAMS(_printk))
193 #define SC_DEFINE_EVENT_NOARGS(_template, _name) \
194 DEFINE_EVENT_NOARGS(compat_syscall_exit_##_template, \
195 compat_syscall_exit_##_name)
196 #define TRACE_SYSTEM compat_syscall_exit_integers
197 #define TRACE_INCLUDE_FILE compat_syscalls_integers
198 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
199 #undef TRACE_INCLUDE_FILE
201 #define TRACE_SYSTEM compat_syscall_exit_pointers
202 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
203 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
204 #undef TRACE_INCLUDE_FILE
206 #undef SC_TRACE_EVENT
207 #undef SC_DECLARE_EVENT_CLASS_NOARGS
208 #undef SC_DEFINE_EVENT_NOARGS
210 #undef _TRACE_SYSCALLS_integers_H
211 #undef _TRACE_SYSCALLS_pointers_H
214 #undef TP_MODULE_NOINIT
215 #undef LTTNG_PACKAGE_BUILD
216 #undef CREATE_TRACE_POINTS
218 struct trace_syscall_entry
{
220 const struct lttng_event_desc
*desc
;
221 const struct lttng_event_field
*fields
;
225 #define CREATE_SYSCALL_TABLE
227 #undef TRACE_SYSCALL_TABLE
228 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
230 .func = __event_probe__syscall_enter_##_template, \
231 .nrargs = (_nrargs), \
232 .fields = __event_fields___syscall_enter_##_template, \
233 .desc = &__event_desc___syscall_enter_##_name, \
236 /* Syscall enter tracing table */
237 static const struct trace_syscall_entry sc_table
[] = {
238 #include "instrumentation/syscalls/headers/syscalls_integers.h"
239 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
242 #undef TRACE_SYSCALL_TABLE
243 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
245 .func = __event_probe__compat_syscall_enter_##_template, \
246 .nrargs = (_nrargs), \
247 .fields = __event_fields___compat_syscall_enter_##_template, \
248 .desc = &__event_desc___compat_syscall_enter_##_name, \
251 /* Compat syscall enter table */
252 const struct trace_syscall_entry compat_sc_table
[] = {
253 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
254 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
257 #undef TRACE_SYSCALL_TABLE
258 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
260 .func = __event_probe__syscall_exit_##_template, \
261 .nrargs = (_nrargs), \
262 .fields = __event_fields___syscall_exit_##_template, \
263 .desc = &__event_desc___syscall_exit_##_name, \
266 /* Syscall exit table */
267 static const struct trace_syscall_entry sc_exit_table
[] = {
268 #include "instrumentation/syscalls/headers/syscalls_integers.h"
269 #include "instrumentation/syscalls/headers/syscalls_pointers.h"
272 #undef TRACE_SYSCALL_TABLE
273 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
275 .func = __event_probe__compat_syscall_exit_##_template, \
276 .nrargs = (_nrargs), \
277 .fields = __event_fields___compat_syscall_exit_##_template, \
278 .desc = &__event_desc___compat_syscall_exit_##_name, \
281 /* Compat syscall exit table */
282 const struct trace_syscall_entry compat_sc_exit_table
[] = {
283 #include "instrumentation/syscalls/headers/compat_syscalls_integers.h"
284 #include "instrumentation/syscalls/headers/compat_syscalls_pointers.h"
287 #undef CREATE_SYSCALL_TABLE
289 struct lttng_syscall_filter
{
290 DECLARE_BITMAP(sc
, NR_syscalls
);
291 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
294 static void syscall_entry_unknown(struct lttng_event
*event
,
295 struct pt_regs
*regs
, unsigned int id
)
297 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
299 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
300 if (unlikely(is_compat_task()))
301 __event_probe__compat_syscall_enter_unknown(event
, id
, args
);
303 __event_probe__syscall_enter_unknown(event
, id
, args
);
306 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
308 struct lttng_channel
*chan
= __data
;
309 struct lttng_event
*event
, *unknown_event
;
310 const struct trace_syscall_entry
*table
, *entry
;
313 if (unlikely(is_compat_task())) {
314 struct lttng_syscall_filter
*filter
;
316 filter
= rcu_dereference(chan
->sc_filter
);
318 if (id
>= NR_compat_syscalls
319 || !test_bit(id
, filter
->sc_compat
)) {
320 /* System call filtered out. */
324 table
= compat_sc_table
;
325 table_len
= ARRAY_SIZE(compat_sc_table
);
326 unknown_event
= chan
->sc_compat_unknown
;
328 struct lttng_syscall_filter
*filter
;
330 filter
= rcu_dereference(chan
->sc_filter
);
332 if (id
>= NR_syscalls
333 || !test_bit(id
, filter
->sc
)) {
334 /* System call filtered out. */
339 table_len
= ARRAY_SIZE(sc_table
);
340 unknown_event
= chan
->sc_unknown
;
342 if (unlikely(id
>= table_len
)) {
343 syscall_entry_unknown(unknown_event
, regs
, id
);
346 if (unlikely(is_compat_task()))
347 event
= chan
->compat_sc_table
[id
];
349 event
= chan
->sc_table
[id
];
350 if (unlikely(!event
)) {
351 syscall_entry_unknown(unknown_event
, regs
, id
);
355 WARN_ON_ONCE(!entry
);
357 switch (entry
->nrargs
) {
360 void (*fptr
)(void *__data
) = entry
->func
;
367 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
368 unsigned long args
[1];
370 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
371 fptr(event
, args
[0]);
376 void (*fptr
)(void *__data
,
378 unsigned long arg1
) = entry
->func
;
379 unsigned long args
[2];
381 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
382 fptr(event
, args
[0], args
[1]);
387 void (*fptr
)(void *__data
,
390 unsigned long arg2
) = entry
->func
;
391 unsigned long args
[3];
393 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
394 fptr(event
, args
[0], args
[1], args
[2]);
399 void (*fptr
)(void *__data
,
403 unsigned long arg3
) = entry
->func
;
404 unsigned long args
[4];
406 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
407 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
412 void (*fptr
)(void *__data
,
417 unsigned long arg4
) = entry
->func
;
418 unsigned long args
[5];
420 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
421 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
426 void (*fptr
)(void *__data
,
432 unsigned long arg5
) = entry
->func
;
433 unsigned long args
[6];
435 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
436 fptr(event
, args
[0], args
[1], args
[2],
437 args
[3], args
[4], args
[5]);
445 static void syscall_exit_unknown(struct lttng_event
*event
,
446 struct pt_regs
*regs
, unsigned int id
, long ret
)
448 unsigned long args
[UNKNOWN_SYSCALL_NRARGS
];
450 syscall_get_arguments(current
, regs
, 0, UNKNOWN_SYSCALL_NRARGS
, args
);
451 if (unlikely(is_compat_task()))
452 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
455 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
458 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
460 struct lttng_channel
*chan
= __data
;
461 struct lttng_event
*event
, *unknown_event
;
462 const struct trace_syscall_entry
*table
, *entry
;
466 id
= syscall_get_nr(current
, regs
);
467 if (unlikely(is_compat_task())) {
468 struct lttng_syscall_filter
*filter
;
470 filter
= rcu_dereference(chan
->sc_filter
);
472 if (id
>= NR_compat_syscalls
473 || !test_bit(id
, filter
->sc_compat
)) {
474 /* System call filtered out. */
478 table
= compat_sc_exit_table
;
479 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
480 unknown_event
= chan
->compat_sc_exit_unknown
;
482 struct lttng_syscall_filter
*filter
;
484 filter
= rcu_dereference(chan
->sc_filter
);
486 if (id
>= NR_syscalls
487 || !test_bit(id
, filter
->sc
)) {
488 /* System call filtered out. */
492 table
= sc_exit_table
;
493 table_len
= ARRAY_SIZE(sc_exit_table
);
494 unknown_event
= chan
->sc_exit_unknown
;
496 if (unlikely(id
>= table_len
)) {
497 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
500 if (unlikely(is_compat_task()))
501 event
= chan
->compat_sc_exit_table
[id
];
503 event
= chan
->sc_exit_table
[id
];
504 if (unlikely(!event
)) {
505 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
509 WARN_ON_ONCE(!entry
);
511 switch (entry
->nrargs
) {
514 void (*fptr
)(void *__data
) = entry
->func
;
521 void (*fptr
)(void *__data
,
522 unsigned long arg0
) = entry
->func
;
523 unsigned long args
[1];
525 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
526 fptr(event
, args
[0]);
531 void (*fptr
)(void *__data
,
533 unsigned long arg1
) = entry
->func
;
534 unsigned long args
[2];
536 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
537 fptr(event
, args
[0], args
[1]);
542 void (*fptr
)(void *__data
,
545 unsigned long arg2
) = entry
->func
;
546 unsigned long args
[3];
548 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
549 fptr(event
, args
[0], args
[1], args
[2]);
554 void (*fptr
)(void *__data
,
558 unsigned long arg3
) = entry
->func
;
559 unsigned long args
[4];
561 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
562 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
567 void (*fptr
)(void *__data
,
572 unsigned long arg4
) = entry
->func
;
573 unsigned long args
[5];
575 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
576 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
581 void (*fptr
)(void *__data
,
587 unsigned long arg5
) = entry
->func
;
588 unsigned long args
[6];
590 syscall_get_arguments(current
, regs
, 0, entry
->nrargs
, args
);
591 fptr(event
, args
[0], args
[1], args
[2],
592 args
[3], args
[4], args
[5]);
600 /* noinline to diminish caller stack size */
602 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
603 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
604 void *filter
, enum sc_type type
)
606 const struct lttng_event_desc
*desc
;
609 /* Allocate events for each syscall, insert into table */
610 for (i
= 0; i
< table_len
; i
++) {
611 struct lttng_kernel_event ev
;
612 desc
= table
[i
].desc
;
615 /* Unknown syscall */
619 * Skip those already populated by previous failed
620 * register for this channel.
624 memset(&ev
, 0, sizeof(ev
));
627 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
628 LTTNG_KERNEL_SYM_NAME_LEN
);
631 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
632 LTTNG_KERNEL_SYM_NAME_LEN
);
634 case SC_TYPE_COMPAT_ENTRY
:
635 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
636 LTTNG_KERNEL_SYM_NAME_LEN
);
638 case SC_TYPE_COMPAT_EXIT
:
639 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
640 LTTNG_KERNEL_SYM_NAME_LEN
);
646 strncat(ev
.name
, desc
->name
,
647 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
648 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
649 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
650 chan_table
[i
] = lttng_event_create(chan
, &ev
, filter
,
652 WARN_ON_ONCE(!chan_table
[i
]);
653 if (IS_ERR(chan_table
[i
])) {
655 * If something goes wrong in event registration
656 * after the first one, we have no choice but to
657 * leave the previous events in there, until
658 * deleted by session teardown.
660 return PTR_ERR(chan_table
[i
]);
666 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
668 struct lttng_kernel_event ev
;
671 wrapper_vmalloc_sync_all();
673 if (!chan
->sc_table
) {
674 /* create syscall table mapping syscall to events */
675 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
676 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
680 if (!chan
->sc_exit_table
) {
681 /* create syscall table mapping syscall to events */
682 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
683 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
684 if (!chan
->sc_exit_table
)
690 if (!chan
->compat_sc_table
) {
691 /* create syscall table mapping compat syscall to events */
692 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
693 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
694 if (!chan
->compat_sc_table
)
698 if (!chan
->compat_sc_exit_table
) {
699 /* create syscall table mapping compat syscall to events */
700 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
701 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
702 if (!chan
->compat_sc_exit_table
)
706 if (!chan
->sc_unknown
) {
707 const struct lttng_event_desc
*desc
=
708 &__event_desc___syscall_enter_unknown
;
710 memset(&ev
, 0, sizeof(ev
));
711 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
712 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
713 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
714 chan
->sc_unknown
= lttng_event_create(chan
, &ev
, filter
,
716 WARN_ON_ONCE(!chan
->sc_unknown
);
717 if (IS_ERR(chan
->sc_unknown
)) {
718 return PTR_ERR(chan
->sc_unknown
);
722 if (!chan
->sc_compat_unknown
) {
723 const struct lttng_event_desc
*desc
=
724 &__event_desc___compat_syscall_enter_unknown
;
726 memset(&ev
, 0, sizeof(ev
));
727 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
728 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
729 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
730 chan
->sc_compat_unknown
= lttng_event_create(chan
, &ev
, filter
,
732 WARN_ON_ONCE(!chan
->sc_unknown
);
733 if (IS_ERR(chan
->sc_compat_unknown
)) {
734 return PTR_ERR(chan
->sc_compat_unknown
);
738 if (!chan
->compat_sc_exit_unknown
) {
739 const struct lttng_event_desc
*desc
=
740 &__event_desc___compat_syscall_exit_unknown
;
742 memset(&ev
, 0, sizeof(ev
));
743 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
744 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
745 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
746 chan
->compat_sc_exit_unknown
= lttng_event_create(chan
, &ev
,
748 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
749 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
750 return PTR_ERR(chan
->compat_sc_exit_unknown
);
754 if (!chan
->sc_exit_unknown
) {
755 const struct lttng_event_desc
*desc
=
756 &__event_desc___syscall_exit_unknown
;
758 memset(&ev
, 0, sizeof(ev
));
759 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
760 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
761 ev
.instrumentation
= LTTNG_KERNEL_NOOP
;
762 chan
->sc_exit_unknown
= lttng_event_create(chan
, &ev
, filter
,
764 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
765 if (IS_ERR(chan
->sc_exit_unknown
)) {
766 return PTR_ERR(chan
->sc_exit_unknown
);
770 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
771 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
774 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
775 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
780 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
781 chan
->compat_sc_table
, chan
, filter
,
782 SC_TYPE_COMPAT_ENTRY
);
785 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
786 chan
->compat_sc_exit_table
, chan
, filter
,
787 SC_TYPE_COMPAT_EXIT
);
791 if (!chan
->sys_enter_registered
) {
792 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
793 (void *) syscall_entry_probe
, chan
);
796 chan
->sys_enter_registered
= 1;
799 * We change the name of sys_exit tracepoint due to namespace
800 * conflict with sys_exit syscall entry.
802 if (!chan
->sys_exit_registered
) {
803 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
804 (void *) syscall_exit_probe
, chan
);
806 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
807 (void *) syscall_entry_probe
, chan
));
810 chan
->sys_exit_registered
= 1;
816 * Only called at session destruction.
818 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
824 if (chan
->sys_enter_registered
) {
825 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
826 (void *) syscall_exit_probe
, chan
);
829 chan
->sys_enter_registered
= 0;
831 if (chan
->sys_exit_registered
) {
832 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
833 (void *) syscall_entry_probe
, chan
);
836 chan
->sys_exit_registered
= 0;
838 /* lttng_event destroy will be performed by lttng_session_destroy() */
839 kfree(chan
->sc_table
);
840 kfree(chan
->sc_exit_table
);
842 kfree(chan
->compat_sc_table
);
843 kfree(chan
->compat_sc_exit_table
);
845 kfree(chan
->sc_filter
);
850 int get_syscall_nr(const char *syscall_name
)
855 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
856 const struct trace_syscall_entry
*entry
;
859 entry
= &sc_table
[i
];
862 it_name
= entry
->desc
->name
;
863 it_name
+= strlen(SYSCALL_ENTRY_STR
);
864 if (!strcmp(syscall_name
, it_name
)) {
873 int get_compat_syscall_nr(const char *syscall_name
)
878 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
879 const struct trace_syscall_entry
*entry
;
882 entry
= &compat_sc_table
[i
];
885 it_name
= entry
->desc
->name
;
886 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
887 if (!strcmp(syscall_name
, it_name
)) {
895 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
898 int syscall_nr
, compat_syscall_nr
, ret
;
899 struct lttng_syscall_filter
*filter
;
901 WARN_ON_ONCE(!chan
->sc_table
);
904 /* Enable all system calls by removing filter */
905 if (chan
->sc_filter
) {
906 filter
= chan
->sc_filter
;
907 rcu_assign_pointer(chan
->sc_filter
, NULL
);
911 chan
->syscall_all
= 1;
915 if (!chan
->sc_filter
) {
916 if (chan
->syscall_all
) {
918 * All syscalls are already enabled.
922 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
927 filter
= chan
->sc_filter
;
929 syscall_nr
= get_syscall_nr(name
);
930 compat_syscall_nr
= get_compat_syscall_nr(name
);
931 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
935 if (syscall_nr
>= 0) {
936 if (test_bit(syscall_nr
, filter
->sc
)) {
940 bitmap_set(filter
->sc
, syscall_nr
, 1);
942 if (compat_syscall_nr
>= 0) {
943 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
947 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
949 if (!chan
->sc_filter
)
950 rcu_assign_pointer(chan
->sc_filter
, filter
);
954 if (!chan
->sc_filter
)
959 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
962 int syscall_nr
, compat_syscall_nr
, ret
;
963 struct lttng_syscall_filter
*filter
;
965 WARN_ON_ONCE(!chan
->sc_table
);
967 if (!chan
->sc_filter
) {
968 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
972 /* Trace all system calls, then apply disable. */
973 bitmap_set(filter
->sc
, 0, NR_syscalls
);
974 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
976 filter
= chan
->sc_filter
;
979 syscall_nr
= get_syscall_nr(name
);
980 compat_syscall_nr
= get_compat_syscall_nr(name
);
981 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
985 if (syscall_nr
>= 0) {
986 if (!test_bit(syscall_nr
, chan
->sc_filter
->sc
)) {
990 bitmap_clear(chan
->sc_filter
->sc
, syscall_nr
, 1);
992 if (compat_syscall_nr
>= 0) {
993 if (!test_bit(compat_syscall_nr
, chan
->sc_filter
->sc_compat
)) {
997 bitmap_clear(chan
->sc_filter
->sc_compat
, compat_syscall_nr
, 1);
999 if (!chan
->sc_filter
)
1000 rcu_assign_pointer(chan
->sc_filter
, filter
);
1001 chan
->syscall_all
= 0;
1005 if (!chan
->sc_filter
)