1 /* SPDX-License-Identifier: (GPL-2.0 or LGPL-2.1)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <asm/ptrace.h>
22 #include <asm/syscall.h>
24 #include <lib/bitfield.h>
25 #include <wrapper/tracepoint.h>
26 #include <wrapper/file.h>
27 #include <wrapper/rcu.h>
28 #include <wrapper/syscall.h>
29 #include <lttng-events.h>
32 # ifndef is_compat_task
33 # define is_compat_task() (0)
37 /* in_compat_syscall appears in kernel 4.6. */
38 #ifndef in_compat_syscall
39 #define in_compat_syscall() is_compat_task()
49 #define SYSCALL_ENTRY_TOK syscall_entry_
50 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
51 #define SYSCALL_EXIT_TOK syscall_exit_
52 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
54 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
55 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
56 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
57 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
60 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
62 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
65 * Forward declarations for old kernels.
69 struct oldold_utsname
;
71 struct sel_arg_struct
;
72 struct mmap_arg_struct
;
77 * Forward declaration for kernels >= 5.6
81 #ifdef IA32_NR_syscalls
82 #define NR_compat_syscalls IA32_NR_syscalls
84 #define NR_compat_syscalls NR_syscalls
88 * Create LTTng tracepoint probes.
90 #define LTTNG_PACKAGE_BUILD
91 #define CREATE_TRACE_POINTS
92 #define TP_MODULE_NOINIT
93 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
95 #define PARAMS(args...) args
97 /* Handle unknown syscalls */
99 #define TRACE_SYSTEM syscalls_unknown
100 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
108 #define sc_in(...) __VA_ARGS__
112 #define sc_inout(...) __VA_ARGS__
114 /* Hijack probe callback for system call enter */
116 #define TP_PROBE_CB(_template) &syscall_entry_probe
117 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
118 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
120 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
121 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
122 PARAMS(_locvar), PARAMS(_code_pre), \
123 PARAMS(_fields), PARAMS(_code_post))
124 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
125 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_fields))
126 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
127 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
128 /* Enumerations only defined at first inclusion. */
129 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values) \
130 LTTNG_TRACEPOINT_ENUM(_name, PARAMS(_values))
132 #define TRACE_SYSTEM syscall_entry_integers
133 #define TRACE_INCLUDE_FILE syscalls_integers
134 #include <instrumentation/syscalls/headers/syscalls_integers.h>
135 #undef TRACE_INCLUDE_FILE
137 #define TRACE_SYSTEM syscall_entry_pointers
138 #define TRACE_INCLUDE_FILE syscalls_pointers
139 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
140 #undef TRACE_INCLUDE_FILE
142 #undef SC_LTTNG_TRACEPOINT_ENUM
143 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
144 #undef SC_LTTNG_TRACEPOINT_EVENT
145 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
146 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
148 #undef _TRACE_SYSCALLS_INTEGERS_H
149 #undef _TRACE_SYSCALLS_POINTERS_H
151 /* Hijack probe callback for compat system call enter */
152 #define TP_PROBE_CB(_template) &syscall_entry_probe
153 #define LTTNG_SC_COMPAT
154 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
155 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
157 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
158 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
159 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
160 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
161 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_fields))
162 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
163 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
164 compat_syscall_entry_##_name)
165 /* Enumerations only defined at inital inclusion (not here). */
166 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
167 #define TRACE_SYSTEM compat_syscall_entry_integers
168 #define TRACE_INCLUDE_FILE compat_syscalls_integers
169 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
170 #undef TRACE_INCLUDE_FILE
172 #define TRACE_SYSTEM compat_syscall_entry_pointers
173 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
174 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
175 #undef TRACE_INCLUDE_FILE
177 #undef SC_LTTNG_TRACEPOINT_ENUM
178 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
179 #undef SC_LTTNG_TRACEPOINT_EVENT
180 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
181 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
183 #undef _TRACE_SYSCALLS_INTEGERS_H
184 #undef _TRACE_SYSCALLS_POINTERS_H
185 #undef LTTNG_SC_COMPAT
192 #define sc_exit(...) __VA_ARGS__
196 #define sc_out(...) __VA_ARGS__
198 #define sc_inout(...) __VA_ARGS__
200 /* Hijack probe callback for system call exit */
201 #define TP_PROBE_CB(_template) &syscall_exit_probe
202 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
203 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
205 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
206 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
207 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
208 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
209 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_fields))
210 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
211 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
212 syscall_exit_##_name)
213 /* Enumerations only defined at inital inclusion (not here). */
214 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
215 #define TRACE_SYSTEM syscall_exit_integers
216 #define TRACE_INCLUDE_FILE syscalls_integers
217 #include <instrumentation/syscalls/headers/syscalls_integers.h>
218 #undef TRACE_INCLUDE_FILE
220 #define TRACE_SYSTEM syscall_exit_pointers
221 #define TRACE_INCLUDE_FILE syscalls_pointers
222 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
223 #undef TRACE_INCLUDE_FILE
225 #undef SC_LTTNG_TRACEPOINT_ENUM
226 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
227 #undef SC_LTTNG_TRACEPOINT_EVENT
228 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
229 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
231 #undef _TRACE_SYSCALLS_INTEGERS_H
232 #undef _TRACE_SYSCALLS_POINTERS_H
235 /* Hijack probe callback for compat system call exit */
236 #define TP_PROBE_CB(_template) &syscall_exit_probe
237 #define LTTNG_SC_COMPAT
238 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
239 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
241 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
242 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
243 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
244 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
245 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_fields))
246 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
247 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
248 compat_syscall_exit_##_name)
249 /* Enumerations only defined at inital inclusion (not here). */
250 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
251 #define TRACE_SYSTEM compat_syscall_exit_integers
252 #define TRACE_INCLUDE_FILE compat_syscalls_integers
253 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
254 #undef TRACE_INCLUDE_FILE
256 #define TRACE_SYSTEM compat_syscall_exit_pointers
257 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
258 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
259 #undef TRACE_INCLUDE_FILE
261 #undef SC_LTTNG_TRACEPOINT_ENUM
262 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
263 #undef SC_LTTNG_TRACEPOINT_EVENT
264 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
265 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
267 #undef _TRACE_SYSCALLS_INTEGERS_H
268 #undef _TRACE_SYSCALLS_POINTERS_H
269 #undef LTTNG_SC_COMPAT
273 #undef TP_MODULE_NOINIT
274 #undef LTTNG_PACKAGE_BUILD
275 #undef CREATE_TRACE_POINTS
277 struct trace_syscall_entry
{
279 const struct lttng_event_desc
*desc
;
280 const struct lttng_event_field
*fields
;
284 #define CREATE_SYSCALL_TABLE
291 #undef TRACE_SYSCALL_TABLE
292 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
294 .func = __event_probe__syscall_entry_##_template, \
295 .nrargs = (_nrargs), \
296 .fields = __event_fields___syscall_entry_##_template, \
297 .desc = &__event_desc___syscall_entry_##_name, \
300 /* Syscall enter tracing table */
301 static const struct trace_syscall_entry sc_table
[] = {
302 #include <instrumentation/syscalls/headers/syscalls_integers.h>
303 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
306 #undef TRACE_SYSCALL_TABLE
307 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
309 .func = __event_probe__compat_syscall_entry_##_template, \
310 .nrargs = (_nrargs), \
311 .fields = __event_fields___compat_syscall_entry_##_template, \
312 .desc = &__event_desc___compat_syscall_entry_##_name, \
315 /* Compat syscall enter table */
316 const struct trace_syscall_entry compat_sc_table
[] = {
317 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
318 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
326 #define sc_exit(...) __VA_ARGS__
328 #undef TRACE_SYSCALL_TABLE
329 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
331 .func = __event_probe__syscall_exit_##_template, \
332 .nrargs = (_nrargs), \
333 .fields = __event_fields___syscall_exit_##_template, \
334 .desc = &__event_desc___syscall_exit_##_name, \
337 /* Syscall exit table */
338 static const struct trace_syscall_entry sc_exit_table
[] = {
339 #include <instrumentation/syscalls/headers/syscalls_integers.h>
340 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
343 #undef TRACE_SYSCALL_TABLE
344 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
346 .func = __event_probe__compat_syscall_exit_##_template, \
347 .nrargs = (_nrargs), \
348 .fields = __event_fields___compat_syscall_exit_##_template, \
349 .desc = &__event_desc___compat_syscall_exit_##_name, \
352 /* Compat syscall exit table */
353 const struct trace_syscall_entry compat_sc_exit_table
[] = {
354 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
355 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
360 #undef CREATE_SYSCALL_TABLE
362 struct lttng_syscall_filter
{
363 DECLARE_BITMAP(sc
, NR_syscalls
);
364 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
367 static void syscall_entry_unknown(struct lttng_event
*event
,
368 struct pt_regs
*regs
, unsigned int id
)
370 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
372 lttng_syscall_get_arguments(current
, regs
, args
);
373 if (unlikely(in_compat_syscall()))
374 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
376 __event_probe__syscall_entry_unknown(event
, id
, args
);
379 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
381 struct lttng_channel
*chan
= __data
;
382 struct lttng_event
*event
, *unknown_event
;
383 const struct trace_syscall_entry
*table
, *entry
;
386 if (unlikely(in_compat_syscall())) {
387 struct lttng_syscall_filter
*filter
;
389 filter
= lttng_rcu_dereference(chan
->sc_filter
);
391 if (id
< 0 || id
>= NR_compat_syscalls
392 || !test_bit(id
, filter
->sc_compat
)) {
393 /* System call filtered out. */
397 table
= compat_sc_table
;
398 table_len
= ARRAY_SIZE(compat_sc_table
);
399 unknown_event
= chan
->sc_compat_unknown
;
401 struct lttng_syscall_filter
*filter
;
403 filter
= lttng_rcu_dereference(chan
->sc_filter
);
405 if (id
< 0 || id
>= NR_syscalls
406 || !test_bit(id
, filter
->sc
)) {
407 /* System call filtered out. */
412 table_len
= ARRAY_SIZE(sc_table
);
413 unknown_event
= chan
->sc_unknown
;
415 if (unlikely(id
< 0 || id
>= table_len
)) {
416 syscall_entry_unknown(unknown_event
, regs
, id
);
419 if (unlikely(in_compat_syscall()))
420 event
= chan
->compat_sc_table
[id
];
422 event
= chan
->sc_table
[id
];
423 if (unlikely(!event
)) {
424 syscall_entry_unknown(unknown_event
, regs
, id
);
428 WARN_ON_ONCE(!entry
);
430 switch (entry
->nrargs
) {
433 void (*fptr
)(void *__data
) = entry
->func
;
440 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
441 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
443 lttng_syscall_get_arguments(current
, regs
, args
);
444 fptr(event
, args
[0]);
449 void (*fptr
)(void *__data
,
451 unsigned long arg1
) = entry
->func
;
452 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
454 lttng_syscall_get_arguments(current
, regs
, args
);
455 fptr(event
, args
[0], args
[1]);
460 void (*fptr
)(void *__data
,
463 unsigned long arg2
) = entry
->func
;
464 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
466 lttng_syscall_get_arguments(current
, regs
, args
);
467 fptr(event
, args
[0], args
[1], args
[2]);
472 void (*fptr
)(void *__data
,
476 unsigned long arg3
) = entry
->func
;
477 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
479 lttng_syscall_get_arguments(current
, regs
, args
);
480 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
485 void (*fptr
)(void *__data
,
490 unsigned long arg4
) = entry
->func
;
491 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
493 lttng_syscall_get_arguments(current
, regs
, args
);
494 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
499 void (*fptr
)(void *__data
,
505 unsigned long arg5
) = entry
->func
;
506 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
508 lttng_syscall_get_arguments(current
, regs
, args
);
509 fptr(event
, args
[0], args
[1], args
[2],
510 args
[3], args
[4], args
[5]);
518 static void syscall_exit_unknown(struct lttng_event
*event
,
519 struct pt_regs
*regs
, int id
, long ret
)
521 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
523 lttng_syscall_get_arguments(current
, regs
, args
);
524 if (unlikely(in_compat_syscall()))
525 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
528 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
531 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
533 struct lttng_channel
*chan
= __data
;
534 struct lttng_event
*event
, *unknown_event
;
535 const struct trace_syscall_entry
*table
, *entry
;
539 id
= syscall_get_nr(current
, regs
);
540 if (unlikely(in_compat_syscall())) {
541 struct lttng_syscall_filter
*filter
;
543 filter
= lttng_rcu_dereference(chan
->sc_filter
);
545 if (id
< 0 || id
>= NR_compat_syscalls
546 || !test_bit(id
, filter
->sc_compat
)) {
547 /* System call filtered out. */
551 table
= compat_sc_exit_table
;
552 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
553 unknown_event
= chan
->compat_sc_exit_unknown
;
555 struct lttng_syscall_filter
*filter
;
557 filter
= lttng_rcu_dereference(chan
->sc_filter
);
559 if (id
< 0 || id
>= NR_syscalls
560 || !test_bit(id
, filter
->sc
)) {
561 /* System call filtered out. */
565 table
= sc_exit_table
;
566 table_len
= ARRAY_SIZE(sc_exit_table
);
567 unknown_event
= chan
->sc_exit_unknown
;
569 if (unlikely(id
< 0 || id
>= table_len
)) {
570 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
573 if (unlikely(in_compat_syscall()))
574 event
= chan
->compat_sc_exit_table
[id
];
576 event
= chan
->sc_exit_table
[id
];
577 if (unlikely(!event
)) {
578 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
582 WARN_ON_ONCE(!entry
);
584 switch (entry
->nrargs
) {
587 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
594 void (*fptr
)(void *__data
,
596 unsigned long arg0
) = entry
->func
;
597 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
599 lttng_syscall_get_arguments(current
, regs
, args
);
600 fptr(event
, ret
, args
[0]);
605 void (*fptr
)(void *__data
,
608 unsigned long arg1
) = entry
->func
;
609 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
611 lttng_syscall_get_arguments(current
, regs
, args
);
612 fptr(event
, ret
, args
[0], args
[1]);
617 void (*fptr
)(void *__data
,
621 unsigned long arg2
) = entry
->func
;
622 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
624 lttng_syscall_get_arguments(current
, regs
, args
);
625 fptr(event
, ret
, args
[0], args
[1], args
[2]);
630 void (*fptr
)(void *__data
,
635 unsigned long arg3
) = entry
->func
;
636 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
638 lttng_syscall_get_arguments(current
, regs
, args
);
639 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
644 void (*fptr
)(void *__data
,
650 unsigned long arg4
) = entry
->func
;
651 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
653 lttng_syscall_get_arguments(current
, regs
, args
);
654 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
659 void (*fptr
)(void *__data
,
666 unsigned long arg5
) = entry
->func
;
667 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
669 lttng_syscall_get_arguments(current
, regs
, args
);
670 fptr(event
, ret
, args
[0], args
[1], args
[2],
671 args
[3], args
[4], args
[5]);
680 * noinline to diminish caller stack size.
681 * Should be called with sessions lock held.
684 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
685 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
686 void *filter
, enum sc_type type
)
688 const struct lttng_event_desc
*desc
;
691 /* Allocate events for each syscall, insert into table */
692 for (i
= 0; i
< table_len
; i
++) {
693 struct lttng_kernel_event ev
;
694 desc
= table
[i
].desc
;
697 /* Unknown syscall */
701 * Skip those already populated by previous failed
702 * register for this channel.
706 memset(&ev
, 0, sizeof(ev
));
709 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
710 LTTNG_KERNEL_SYM_NAME_LEN
);
713 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
714 LTTNG_KERNEL_SYM_NAME_LEN
);
716 case SC_TYPE_COMPAT_ENTRY
:
717 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
718 LTTNG_KERNEL_SYM_NAME_LEN
);
720 case SC_TYPE_COMPAT_EXIT
:
721 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
722 LTTNG_KERNEL_SYM_NAME_LEN
);
728 strncat(ev
.name
, desc
->name
,
729 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
730 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
731 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
732 chan_table
[i
] = _lttng_event_create(chan
, &ev
, filter
,
733 desc
, ev
.instrumentation
);
734 WARN_ON_ONCE(!chan_table
[i
]);
735 if (IS_ERR(chan_table
[i
])) {
737 * If something goes wrong in event registration
738 * after the first one, we have no choice but to
739 * leave the previous events in there, until
740 * deleted by session teardown.
742 return PTR_ERR(chan_table
[i
]);
749 * Should be called with sessions lock held.
751 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
753 struct lttng_kernel_event ev
;
756 wrapper_vmalloc_sync_all();
758 if (!chan
->sc_table
) {
759 /* create syscall table mapping syscall to events */
760 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
761 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
765 if (!chan
->sc_exit_table
) {
766 /* create syscall table mapping syscall to events */
767 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
768 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
769 if (!chan
->sc_exit_table
)
775 if (!chan
->compat_sc_table
) {
776 /* create syscall table mapping compat syscall to events */
777 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
778 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
779 if (!chan
->compat_sc_table
)
783 if (!chan
->compat_sc_exit_table
) {
784 /* create syscall table mapping compat syscall to events */
785 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
786 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
787 if (!chan
->compat_sc_exit_table
)
791 if (!chan
->sc_unknown
) {
792 const struct lttng_event_desc
*desc
=
793 &__event_desc___syscall_entry_unknown
;
795 memset(&ev
, 0, sizeof(ev
));
796 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
797 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
798 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
799 chan
->sc_unknown
= _lttng_event_create(chan
, &ev
, filter
,
802 WARN_ON_ONCE(!chan
->sc_unknown
);
803 if (IS_ERR(chan
->sc_unknown
)) {
804 return PTR_ERR(chan
->sc_unknown
);
808 if (!chan
->sc_compat_unknown
) {
809 const struct lttng_event_desc
*desc
=
810 &__event_desc___compat_syscall_entry_unknown
;
812 memset(&ev
, 0, sizeof(ev
));
813 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
814 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
815 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
816 chan
->sc_compat_unknown
= _lttng_event_create(chan
, &ev
, filter
,
819 WARN_ON_ONCE(!chan
->sc_unknown
);
820 if (IS_ERR(chan
->sc_compat_unknown
)) {
821 return PTR_ERR(chan
->sc_compat_unknown
);
825 if (!chan
->compat_sc_exit_unknown
) {
826 const struct lttng_event_desc
*desc
=
827 &__event_desc___compat_syscall_exit_unknown
;
829 memset(&ev
, 0, sizeof(ev
));
830 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
831 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
832 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
833 chan
->compat_sc_exit_unknown
= _lttng_event_create(chan
, &ev
,
836 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
837 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
838 return PTR_ERR(chan
->compat_sc_exit_unknown
);
842 if (!chan
->sc_exit_unknown
) {
843 const struct lttng_event_desc
*desc
=
844 &__event_desc___syscall_exit_unknown
;
846 memset(&ev
, 0, sizeof(ev
));
847 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
848 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
849 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
850 chan
->sc_exit_unknown
= _lttng_event_create(chan
, &ev
, filter
,
851 desc
, ev
.instrumentation
);
852 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
853 if (IS_ERR(chan
->sc_exit_unknown
)) {
854 return PTR_ERR(chan
->sc_exit_unknown
);
858 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
859 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
862 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
863 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
868 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
869 chan
->compat_sc_table
, chan
, filter
,
870 SC_TYPE_COMPAT_ENTRY
);
873 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
874 chan
->compat_sc_exit_table
, chan
, filter
,
875 SC_TYPE_COMPAT_EXIT
);
879 if (!chan
->sys_enter_registered
) {
880 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
881 (void *) syscall_entry_probe
, chan
);
884 chan
->sys_enter_registered
= 1;
887 * We change the name of sys_exit tracepoint due to namespace
888 * conflict with sys_exit syscall entry.
890 if (!chan
->sys_exit_registered
) {
891 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
892 (void *) syscall_exit_probe
, chan
);
894 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
895 (void *) syscall_entry_probe
, chan
));
898 chan
->sys_exit_registered
= 1;
904 * Only called at session destruction.
906 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
912 if (chan
->sys_enter_registered
) {
913 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
914 (void *) syscall_entry_probe
, chan
);
917 chan
->sys_enter_registered
= 0;
919 if (chan
->sys_exit_registered
) {
920 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
921 (void *) syscall_exit_probe
, chan
);
924 chan
->sys_exit_registered
= 0;
926 /* lttng_event destroy will be performed by lttng_session_destroy() */
927 kfree(chan
->sc_table
);
928 kfree(chan
->sc_exit_table
);
930 kfree(chan
->compat_sc_table
);
931 kfree(chan
->compat_sc_exit_table
);
933 kfree(chan
->sc_filter
);
938 int get_syscall_nr(const char *syscall_name
)
943 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
944 const struct trace_syscall_entry
*entry
;
947 entry
= &sc_table
[i
];
950 it_name
= entry
->desc
->name
;
951 it_name
+= strlen(SYSCALL_ENTRY_STR
);
952 if (!strcmp(syscall_name
, it_name
)) {
961 int get_compat_syscall_nr(const char *syscall_name
)
966 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
967 const struct trace_syscall_entry
*entry
;
970 entry
= &compat_sc_table
[i
];
973 it_name
= entry
->desc
->name
;
974 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
975 if (!strcmp(syscall_name
, it_name
)) {
984 uint32_t get_sc_tables_len(void)
986 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
989 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
992 int syscall_nr
, compat_syscall_nr
, ret
;
993 struct lttng_syscall_filter
*filter
;
995 WARN_ON_ONCE(!chan
->sc_table
);
998 /* Enable all system calls by removing filter */
999 if (chan
->sc_filter
) {
1000 filter
= chan
->sc_filter
;
1001 rcu_assign_pointer(chan
->sc_filter
, NULL
);
1002 synchronize_trace();
1005 chan
->syscall_all
= 1;
1009 if (!chan
->sc_filter
) {
1010 if (chan
->syscall_all
) {
1012 * All syscalls are already enabled.
1016 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1021 filter
= chan
->sc_filter
;
1023 syscall_nr
= get_syscall_nr(name
);
1024 compat_syscall_nr
= get_compat_syscall_nr(name
);
1025 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1029 if (syscall_nr
>= 0) {
1030 if (test_bit(syscall_nr
, filter
->sc
)) {
1034 bitmap_set(filter
->sc
, syscall_nr
, 1);
1036 if (compat_syscall_nr
>= 0) {
1037 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1041 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1043 if (!chan
->sc_filter
)
1044 rcu_assign_pointer(chan
->sc_filter
, filter
);
1048 if (!chan
->sc_filter
)
1053 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1056 int syscall_nr
, compat_syscall_nr
, ret
;
1057 struct lttng_syscall_filter
*filter
;
1059 WARN_ON_ONCE(!chan
->sc_table
);
1061 if (!chan
->sc_filter
) {
1062 if (!chan
->syscall_all
)
1064 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1068 /* Trace all system calls, then apply disable. */
1069 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1070 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1072 filter
= chan
->sc_filter
;
1076 /* Fail if all syscalls are already disabled. */
1077 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1078 && bitmap_empty(filter
->sc_compat
,
1079 NR_compat_syscalls
)) {
1084 /* Disable all system calls */
1085 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1086 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1089 syscall_nr
= get_syscall_nr(name
);
1090 compat_syscall_nr
= get_compat_syscall_nr(name
);
1091 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1095 if (syscall_nr
>= 0) {
1096 if (!test_bit(syscall_nr
, filter
->sc
)) {
1100 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1102 if (compat_syscall_nr
>= 0) {
1103 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1107 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1110 if (!chan
->sc_filter
)
1111 rcu_assign_pointer(chan
->sc_filter
, filter
);
1112 chan
->syscall_all
= 0;
1116 if (!chan
->sc_filter
)
1122 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1124 const struct trace_syscall_entry
*entry
;
1127 for (entry
= sc_table
;
1128 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1133 for (entry
= compat_sc_table
;
1134 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1144 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1146 return (void *) syscall_list_get_entry(pos
);
1150 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1153 return (void *) syscall_list_get_entry(ppos
);
1157 void syscall_list_stop(struct seq_file
*m
, void *p
)
1162 int get_sc_table(const struct trace_syscall_entry
*entry
,
1163 const struct trace_syscall_entry
**table
,
1164 unsigned int *bitness
)
1166 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1168 *bitness
= BITS_PER_LONG
;
1173 if (!(entry
>= compat_sc_table
1174 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1180 *table
= compat_sc_table
;
1185 int syscall_list_show(struct seq_file
*m
, void *p
)
1187 const struct trace_syscall_entry
*table
, *entry
= p
;
1188 unsigned int bitness
;
1189 unsigned long index
;
1193 ret
= get_sc_table(entry
, &table
, &bitness
);
1198 if (table
== sc_table
) {
1199 index
= entry
- table
;
1200 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1202 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1203 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1205 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1206 index
, name
, bitness
);
1211 const struct seq_operations lttng_syscall_list_seq_ops
= {
1212 .start
= syscall_list_start
,
1213 .next
= syscall_list_next
,
1214 .stop
= syscall_list_stop
,
1215 .show
= syscall_list_show
,
1219 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1221 return seq_open(file
, <tng_syscall_list_seq_ops
);
1224 const struct file_operations lttng_syscall_list_fops
= {
1225 .owner
= THIS_MODULE
,
1226 .open
= lttng_syscall_list_open
,
1228 .llseek
= seq_lseek
,
1229 .release
= seq_release
,
1232 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1233 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1235 uint32_t len
, sc_tables_len
, bitmask_len
;
1238 struct lttng_syscall_filter
*filter
;
1240 ret
= get_user(len
, &usyscall_mask
->len
);
1243 sc_tables_len
= get_sc_tables_len();
1244 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1245 if (len
< sc_tables_len
) {
1246 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1248 /* Array is large enough, we can copy array to user-space. */
1249 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1252 filter
= channel
->sc_filter
;
1254 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1257 if (channel
->sc_table
) {
1259 state
= test_bit(bit
, filter
->sc
);
1265 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1267 for (; bit
< sc_tables_len
; bit
++) {
1270 if (channel
->compat_sc_table
) {
1272 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1279 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1281 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1287 int lttng_abi_syscall_list(void)
1289 struct file
*syscall_list_file
;
1292 file_fd
= lttng_get_unused_fd();
1298 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1299 <tng_syscall_list_fops
,
1301 if (IS_ERR(syscall_list_file
)) {
1302 ret
= PTR_ERR(syscall_list_file
);
1305 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1308 fd_install(file_fd
, syscall_list_file
);
1312 fput(syscall_list_file
);
1314 put_unused_fd(file_fd
);