1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <wrapper/limits.h>
32 #include <lttng/events.h>
33 #include <lttng/events-internal.h>
34 #include <lttng/utils.h>
35 #include <lttng/kernel-version.h>
37 #include "lttng-syscalls.h"
40 # ifndef is_compat_task
41 # define is_compat_task() (0)
45 /* in_compat_syscall appears in kernel 4.6. */
46 #ifndef in_compat_syscall
47 # define in_compat_syscall() is_compat_task()
50 /* in_x32_syscall appears in kernel 4.7. */
51 #if (LTTNG_LINUX_VERSION_CODE < LTTNG_KERNEL_VERSION(4,7,0))
52 # ifdef CONFIG_X86_X32_ABI
53 # define in_x32_syscall() is_x32_task()
64 #define SYSCALL_ENTRY_TOK syscall_entry_
65 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
66 #define SYSCALL_EXIT_TOK syscall_exit_
67 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
69 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
70 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
71 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
72 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
74 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
75 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
77 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
79 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
83 * Forward declarations for old kernels.
87 struct oldold_utsname
;
89 struct sel_arg_struct
;
90 struct mmap_arg_struct
;
95 * Forward declaration for kernels >= 5.6
102 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
103 typedef __kernel_old_time_t
time_t;
106 #ifdef IA32_NR_syscalls
107 #define NR_compat_syscalls IA32_NR_syscalls
109 #define NR_compat_syscalls NR_syscalls
113 * Create LTTng tracepoint probes.
115 #define LTTNG_PACKAGE_BUILD
116 #define CREATE_TRACE_POINTS
117 #define TP_MODULE_NOINIT
118 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
120 #define PARAMS(args...) args
122 /* Handle unknown syscalls */
124 #define TRACE_SYSTEM syscalls_unknown
125 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
130 extern const struct trace_syscall_table sc_table
;
131 extern const struct trace_syscall_table compat_sc_table
;
133 /* Event syscall exit table */
134 extern const struct trace_syscall_table sc_exit_table
;
135 extern const struct trace_syscall_table compat_sc_exit_table
;
140 #undef CREATE_SYSCALL_TABLE
142 struct lttng_syscall_filter
{
143 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
144 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
145 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
146 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
149 * Reference counters keeping track of number of events enabled
152 u32 sc_entry_refcount_map
[NR_syscalls
];
153 u32 sc_exit_refcount_map
[NR_syscalls
];
154 u32 sc_compat_entry_refcount_map
[NR_compat_syscalls
];
155 u32 sc_compat_exit_refcount_map
[NR_compat_syscalls
];
158 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
159 struct pt_regs
*regs
, long id
)
161 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
162 struct lttng_kernel_event_common_private
*event_priv
;
164 lttng_syscall_get_arguments(current
, regs
, args
);
165 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
166 if (unlikely(in_compat_syscall()))
167 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
169 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
173 static __always_inline
174 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
175 void *func
, unsigned int nrargs
,
176 struct pt_regs
*regs
)
178 struct lttng_kernel_event_common_private
*event_priv
;
183 void (*fptr
)(void *__data
) = func
;
185 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
186 fptr(event_priv
->pub
);
191 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
192 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
194 lttng_syscall_get_arguments(current
, regs
, args
);
195 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
196 fptr(event_priv
->pub
, args
[0]);
201 void (*fptr
)(void *__data
,
203 unsigned long arg1
) = func
;
204 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
206 lttng_syscall_get_arguments(current
, regs
, args
);
207 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
208 fptr(event_priv
->pub
, args
[0], args
[1]);
213 void (*fptr
)(void *__data
,
216 unsigned long arg2
) = func
;
217 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
219 lttng_syscall_get_arguments(current
, regs
, args
);
220 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
221 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
226 void (*fptr
)(void *__data
,
230 unsigned long arg3
) = func
;
231 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
233 lttng_syscall_get_arguments(current
, regs
, args
);
234 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
235 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
240 void (*fptr
)(void *__data
,
245 unsigned long arg4
) = func
;
246 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
248 lttng_syscall_get_arguments(current
, regs
, args
);
249 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
250 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
255 void (*fptr
)(void *__data
,
261 unsigned long arg5
) = func
;
262 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
264 lttng_syscall_get_arguments(current
, regs
, args
);
265 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
266 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
267 args
[3], args
[4], args
[5]);
275 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
277 struct lttng_kernel_channel_buffer
*chan
= __data
;
278 struct hlist_head
*action_list
, *unknown_action_list
;
279 const struct trace_syscall_entry
*table
, *entry
;
282 #ifdef CONFIG_X86_X32_ABI
283 if (in_x32_syscall()) {
284 /* x32 system calls are not supported. */
288 if (unlikely(in_compat_syscall())) {
289 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
291 if (id
< 0 || id
>= NR_compat_syscalls
292 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
293 /* System call filtered out. */
296 table
= compat_sc_table
.table
;
297 table_len
= compat_sc_table
.len
;
298 unknown_action_list
= &chan
->priv
->parent
.sc_compat_unknown
;
300 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
302 if (id
< 0 || id
>= NR_syscalls
303 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
304 /* System call filtered out. */
307 table
= sc_table
.table
;
308 table_len
= sc_table
.len
;
309 unknown_action_list
= &chan
->priv
->parent
.sc_unknown
;
311 if (unlikely(id
< 0 || id
>= table_len
)) {
312 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
317 if (!entry
->event_func
) {
318 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
322 if (unlikely(in_compat_syscall())) {
323 action_list
= &chan
->priv
->parent
.compat_sc_table
[id
];
325 action_list
= &chan
->priv
->parent
.sc_table
[id
];
327 if (unlikely(hlist_empty(action_list
)))
330 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
333 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
336 struct lttng_event_notifier_group
*group
= __data
;
337 const struct trace_syscall_entry
*table
, *entry
;
338 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
341 if (unlikely(in_compat_syscall())) {
342 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
344 if (id
< 0 || id
>= NR_compat_syscalls
345 || (!READ_ONCE(group
->syscall_all_entry
) &&
346 !test_bit(id
, filter
->sc_compat_entry
))) {
347 /* System call filtered out. */
350 table
= compat_sc_table
.table
;
351 table_len
= compat_sc_table
.len
;
352 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
354 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
356 if (id
< 0 || id
>= NR_syscalls
357 || (!READ_ONCE(group
->syscall_all_entry
) &&
358 !test_bit(id
, filter
->sc_entry
))) {
359 /* System call filtered out. */
362 table
= sc_table
.table
;
363 table_len
= sc_table
.len
;
364 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
366 /* Check if the syscall id is out of bound. */
367 if (unlikely(id
< 0 || id
>= table_len
)) {
368 syscall_entry_event_unknown(unknown_dispatch_list
,
374 if (!entry
->event_func
) {
375 syscall_entry_event_unknown(unknown_dispatch_list
,
380 if (unlikely(in_compat_syscall())) {
381 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[id
];
383 dispatch_list
= &group
->event_notifier_syscall_dispatch
[id
];
385 if (unlikely(hlist_empty(dispatch_list
)))
388 syscall_entry_event_call_func(dispatch_list
,
389 entry
->event_func
, entry
->nrargs
, regs
);
392 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
393 struct pt_regs
*regs
, long id
, long ret
)
395 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
396 struct lttng_kernel_event_common_private
*event_priv
;
398 lttng_syscall_get_arguments(current
, regs
, args
);
399 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
400 if (unlikely(in_compat_syscall()))
401 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
404 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
408 static __always_inline
409 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
410 void *func
, unsigned int nrargs
,
411 struct pt_regs
*regs
, long ret
)
413 struct lttng_kernel_event_common_private
*event_priv
;
418 void (*fptr
)(void *__data
, long ret
) = func
;
420 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
421 fptr(event_priv
->pub
, ret
);
426 void (*fptr
)(void *__data
,
428 unsigned long arg0
) = func
;
429 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
431 lttng_syscall_get_arguments(current
, regs
, args
);
432 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
433 fptr(event_priv
->pub
, ret
, args
[0]);
438 void (*fptr
)(void *__data
,
441 unsigned long arg1
) = func
;
442 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
444 lttng_syscall_get_arguments(current
, regs
, args
);
445 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
446 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
451 void (*fptr
)(void *__data
,
455 unsigned long arg2
) = func
;
456 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
458 lttng_syscall_get_arguments(current
, regs
, args
);
459 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
460 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
465 void (*fptr
)(void *__data
,
470 unsigned long arg3
) = func
;
471 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
473 lttng_syscall_get_arguments(current
, regs
, args
);
474 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
475 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
480 void (*fptr
)(void *__data
,
486 unsigned long arg4
) = func
;
487 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
489 lttng_syscall_get_arguments(current
, regs
, args
);
490 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
491 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
496 void (*fptr
)(void *__data
,
503 unsigned long arg5
) = func
;
504 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
506 lttng_syscall_get_arguments(current
, regs
, args
);
507 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
508 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
509 args
[3], args
[4], args
[5]);
517 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
519 struct lttng_kernel_channel_buffer
*chan
= __data
;
520 struct hlist_head
*action_list
, *unknown_action_list
;
521 const struct trace_syscall_entry
*table
, *entry
;
525 #ifdef CONFIG_X86_X32_ABI
526 if (in_x32_syscall()) {
527 /* x32 system calls are not supported. */
531 id
= syscall_get_nr(current
, regs
);
533 if (unlikely(in_compat_syscall())) {
534 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
536 if (id
< 0 || id
>= NR_compat_syscalls
537 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
538 /* System call filtered out. */
541 table
= compat_sc_exit_table
.table
;
542 table_len
= compat_sc_exit_table
.len
;
543 unknown_action_list
= &chan
->priv
->parent
.compat_sc_exit_unknown
;
545 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
547 if (id
< 0 || id
>= NR_syscalls
548 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
549 /* System call filtered out. */
552 table
= sc_exit_table
.table
;
553 table_len
= sc_exit_table
.len
;
554 unknown_action_list
= &chan
->priv
->parent
.sc_exit_unknown
;
556 if (unlikely(id
< 0 || id
>= table_len
)) {
557 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
562 if (!entry
->event_func
) {
563 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
567 if (unlikely(in_compat_syscall())) {
568 action_list
= &chan
->priv
->parent
.compat_sc_exit_table
[id
];
570 action_list
= &chan
->priv
->parent
.sc_exit_table
[id
];
572 if (unlikely(hlist_empty(action_list
)))
575 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
579 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
582 struct lttng_event_notifier_group
*group
= __data
;
583 const struct trace_syscall_entry
*table
, *entry
;
584 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
588 id
= syscall_get_nr(current
, regs
);
590 if (unlikely(in_compat_syscall())) {
591 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
593 if (id
< 0 || id
>= NR_compat_syscalls
594 || (!READ_ONCE(group
->syscall_all_exit
) &&
595 !test_bit(id
, filter
->sc_compat_exit
))) {
596 /* System call filtered out. */
599 table
= compat_sc_exit_table
.table
;
600 table_len
= compat_sc_exit_table
.len
;
601 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
603 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
605 if (id
< 0 || id
>= NR_syscalls
606 || (!READ_ONCE(group
->syscall_all_exit
) &&
607 !test_bit(id
, filter
->sc_exit
))) {
608 /* System call filtered out. */
611 table
= sc_exit_table
.table
;
612 table_len
= sc_exit_table
.len
;
613 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
615 /* Check if the syscall id is out of bound. */
616 if (unlikely(id
< 0 || id
>= table_len
)) {
617 syscall_exit_event_unknown(unknown_dispatch_list
,
623 if (!entry
->event_func
) {
624 syscall_entry_event_unknown(unknown_dispatch_list
,
629 if (unlikely(in_compat_syscall())) {
630 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[id
];
632 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[id
];
634 if (unlikely(hlist_empty(dispatch_list
)))
637 syscall_exit_event_call_func(dispatch_list
,
638 entry
->event_func
, entry
->nrargs
, regs
, ret
);
641 * noinline to diminish caller stack size.
642 * Should be called with sessions lock held.
645 int lttng_create_syscall_event_if_missing(const struct trace_syscall_entry
*table
, size_t table_len
,
646 struct hlist_head
*chan_table
, struct lttng_event_enabler
*event_enabler
,
649 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
650 struct lttng_kernel_session
*session
= chan
->parent
.session
;
653 /* Allocate events for each syscall matching enabler, insert into table */
654 for (i
= 0; i
< table_len
; i
++) {
655 const struct lttng_kernel_event_desc
*desc
= table
[i
].desc
;
656 struct lttng_kernel_abi_event ev
;
657 struct lttng_kernel_event_recorder_private
*event_recorder_priv
;
658 struct lttng_kernel_event_recorder
*event_recorder
;
659 struct hlist_head
*head
;
663 /* Unknown syscall */
666 if (lttng_desc_match_enabler(desc
,
667 lttng_event_enabler_as_enabler(event_enabler
)) <= 0)
670 * Check if already created.
672 head
= utils_borrow_hash_table_bucket(
673 session
->priv
->events_ht
.table
, LTTNG_EVENT_HT_SIZE
,
675 lttng_hlist_for_each_entry(event_recorder_priv
, head
, hlist
) {
676 if (event_recorder_priv
->parent
.desc
== desc
677 && event_recorder_priv
->pub
->chan
== event_enabler
->chan
)
683 /* We need to create an event for this syscall/enabler. */
684 memset(&ev
, 0, sizeof(ev
));
687 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
688 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
691 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
692 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
694 case SC_TYPE_COMPAT_ENTRY
:
695 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
696 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
698 case SC_TYPE_COMPAT_EXIT
:
699 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
700 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
703 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
704 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
705 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
706 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
, ev
.instrumentation
);
707 WARN_ON_ONCE(!event_recorder
);
708 if (IS_ERR(event_recorder
)) {
710 * If something goes wrong in event registration
711 * after the first one, we have no choice but to
712 * leave the previous events in there, until
713 * deleted by session teardown.
715 return PTR_ERR(event_recorder
);
717 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan_table
[i
]);
723 * Should be called with sessions lock held.
725 int lttng_syscalls_register_event(struct lttng_event_enabler
*event_enabler
)
727 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
728 struct lttng_kernel_abi_event ev
;
731 wrapper_vmalloc_sync_mappings();
733 if (!chan
->priv
->parent
.sc_table
) {
734 /* create syscall table mapping syscall to events */
735 chan
->priv
->parent
.sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
736 * sc_table
.len
, GFP_KERNEL
);
737 if (!chan
->priv
->parent
.sc_table
)
740 if (!chan
->priv
->parent
.sc_exit_table
) {
741 /* create syscall table mapping syscall to events */
742 chan
->priv
->parent
.sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
743 * sc_exit_table
.len
, GFP_KERNEL
);
744 if (!chan
->priv
->parent
.sc_exit_table
)
750 if (!chan
->priv
->parent
.compat_sc_table
) {
751 /* create syscall table mapping compat syscall to events */
752 chan
->priv
->parent
.compat_sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
753 * compat_sc_table
.len
, GFP_KERNEL
);
754 if (!chan
->priv
->parent
.compat_sc_table
)
758 if (!chan
->priv
->parent
.compat_sc_exit_table
) {
759 /* create syscall table mapping compat syscall to events */
760 chan
->priv
->parent
.compat_sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
761 * compat_sc_exit_table
.len
, GFP_KERNEL
);
762 if (!chan
->priv
->parent
.compat_sc_exit_table
)
766 if (hlist_empty(&chan
->priv
->parent
.sc_unknown
)) {
767 const struct lttng_kernel_event_desc
*desc
=
768 &__event_desc___syscall_entry_unknown
;
769 struct lttng_kernel_event_recorder
*event_recorder
;
771 memset(&ev
, 0, sizeof(ev
));
772 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
773 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
774 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
775 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
776 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
777 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
779 WARN_ON_ONCE(!event_recorder
);
780 if (IS_ERR(event_recorder
)) {
781 return PTR_ERR(event_recorder
);
783 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_unknown
);
786 if (hlist_empty(&chan
->priv
->parent
.sc_compat_unknown
)) {
787 const struct lttng_kernel_event_desc
*desc
=
788 &__event_desc___compat_syscall_entry_unknown
;
789 struct lttng_kernel_event_recorder
*event_recorder
;
791 memset(&ev
, 0, sizeof(ev
));
792 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
793 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
794 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
795 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
796 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
797 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
799 WARN_ON_ONCE(!event_recorder
);
800 if (IS_ERR(event_recorder
)) {
801 return PTR_ERR(event_recorder
);
803 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_compat_unknown
);
806 if (hlist_empty(&chan
->priv
->parent
.compat_sc_exit_unknown
)) {
807 const struct lttng_kernel_event_desc
*desc
=
808 &__event_desc___compat_syscall_exit_unknown
;
809 struct lttng_kernel_event_recorder
*event_recorder
;
811 memset(&ev
, 0, sizeof(ev
));
812 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
813 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
814 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
815 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
816 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
817 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
819 WARN_ON_ONCE(!event_recorder
);
820 if (IS_ERR(event_recorder
)) {
821 return PTR_ERR(event_recorder
);
823 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.compat_sc_exit_unknown
);
826 if (hlist_empty(&chan
->priv
->parent
.sc_exit_unknown
)) {
827 const struct lttng_kernel_event_desc
*desc
=
828 &__event_desc___syscall_exit_unknown
;
829 struct lttng_kernel_event_recorder
*event_recorder
;
831 memset(&ev
, 0, sizeof(ev
));
832 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
833 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
834 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
835 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
836 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
837 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
839 WARN_ON_ONCE(!event_recorder
);
840 if (IS_ERR(event_recorder
)) {
841 return PTR_ERR(event_recorder
);
843 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_exit_unknown
);
846 ret
= lttng_create_syscall_event_if_missing(sc_table
.table
, sc_table
.len
,
847 chan
->priv
->parent
.sc_table
, event_enabler
, SC_TYPE_ENTRY
);
850 ret
= lttng_create_syscall_event_if_missing(sc_exit_table
.table
, sc_exit_table
.len
,
851 chan
->priv
->parent
.sc_exit_table
, event_enabler
, SC_TYPE_EXIT
);
856 ret
= lttng_create_syscall_event_if_missing(compat_sc_table
.table
, compat_sc_table
.len
,
857 chan
->priv
->parent
.compat_sc_table
, event_enabler
, SC_TYPE_COMPAT_ENTRY
);
860 ret
= lttng_create_syscall_event_if_missing(compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
861 chan
->priv
->parent
.compat_sc_exit_table
, event_enabler
, SC_TYPE_COMPAT_EXIT
);
866 if (!chan
->priv
->parent
.sc_filter
) {
867 chan
->priv
->parent
.sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
869 if (!chan
->priv
->parent
.sc_filter
)
873 if (!chan
->priv
->parent
.sys_enter_registered
) {
874 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
875 (void *) syscall_entry_event_probe
, chan
);
878 chan
->priv
->parent
.sys_enter_registered
= 1;
881 * We change the name of sys_exit tracepoint due to namespace
882 * conflict with sys_exit syscall entry.
884 if (!chan
->priv
->parent
.sys_exit_registered
) {
885 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
886 (void *) syscall_exit_event_probe
, chan
);
888 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
889 (void *) syscall_entry_event_probe
, chan
));
892 chan
->priv
->parent
.sys_exit_registered
= 1;
898 * Should be called with sessions lock held.
900 int lttng_syscalls_register_event_notifier(
901 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
903 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
907 wrapper_vmalloc_sync_mappings();
909 if (!group
->event_notifier_syscall_dispatch
) {
910 group
->event_notifier_syscall_dispatch
=
911 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
913 if (!group
->event_notifier_syscall_dispatch
)
916 /* Initialize all list_head */
917 for (i
= 0; i
< sc_table
.len
; i
++)
918 INIT_HLIST_HEAD(&group
->event_notifier_syscall_dispatch
[i
]);
920 /* Init the unknown syscall notifier list. */
921 INIT_HLIST_HEAD(&group
->event_notifier_unknown_syscall_dispatch
);
924 if (!group
->event_notifier_exit_syscall_dispatch
) {
925 group
->event_notifier_exit_syscall_dispatch
=
926 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
928 if (!group
->event_notifier_exit_syscall_dispatch
)
931 /* Initialize all list_head */
932 for (i
= 0; i
< sc_table
.len
; i
++)
933 INIT_HLIST_HEAD(&group
->event_notifier_exit_syscall_dispatch
[i
]);
935 /* Init the unknown exit syscall notifier list. */
936 INIT_HLIST_HEAD(&group
->event_notifier_exit_unknown_syscall_dispatch
);
940 if (!group
->event_notifier_compat_syscall_dispatch
) {
941 group
->event_notifier_compat_syscall_dispatch
=
942 kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
,
944 if (!group
->event_notifier_syscall_dispatch
)
947 /* Initialize all list_head */
948 for (i
= 0; i
< compat_sc_table
.len
; i
++)
949 INIT_HLIST_HEAD(&group
->event_notifier_compat_syscall_dispatch
[i
]);
951 /* Init the unknown syscall notifier list. */
952 INIT_HLIST_HEAD(&group
->event_notifier_compat_unknown_syscall_dispatch
);
955 if (!group
->event_notifier_exit_compat_syscall_dispatch
) {
956 group
->event_notifier_exit_compat_syscall_dispatch
=
957 kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
,
959 if (!group
->event_notifier_exit_syscall_dispatch
)
962 /* Initialize all list_head */
963 for (i
= 0; i
< compat_sc_exit_table
.len
; i
++)
964 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_syscall_dispatch
[i
]);
966 /* Init the unknown exit syscall notifier list. */
967 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_unknown_syscall_dispatch
);
971 if (!group
->sc_filter
) {
972 group
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
974 if (!group
->sc_filter
)
978 if (!group
->sys_enter_registered
) {
979 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
980 (void *) syscall_entry_event_notifier_probe
, group
);
983 group
->sys_enter_registered
= 1;
986 if (!group
->sys_exit_registered
) {
987 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
988 (void *) syscall_exit_event_notifier_probe
, group
);
990 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
991 (void *) syscall_entry_event_notifier_probe
, group
));
994 group
->sys_exit_registered
= 1;
1001 int create_unknown_event_notifier(
1002 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1005 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1006 struct lttng_kernel_event_notifier
*event_notifier
;
1007 const struct lttng_kernel_event_desc
*desc
;
1008 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1009 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1010 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1011 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1012 struct lttng_enabler
*base_enabler
= lttng_event_notifier_enabler_as_enabler(
1013 event_notifier_enabler
);
1014 struct hlist_head
*unknown_dispatch_list
;
1017 enum lttng_kernel_abi_syscall_abi abi
;
1018 enum lttng_kernel_abi_syscall_entryexit entryexit
;
1019 struct hlist_head
*head
;
1023 desc
= &__event_desc___syscall_entry_unknown
;
1024 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
1025 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1026 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1029 desc
= &__event_desc___syscall_exit_unknown
;
1030 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
1031 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1032 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1034 case SC_TYPE_COMPAT_ENTRY
:
1035 desc
= &__event_desc___compat_syscall_entry_unknown
;
1036 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
1037 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1038 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1040 case SC_TYPE_COMPAT_EXIT
:
1041 desc
= &__event_desc___compat_syscall_exit_unknown
;
1042 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
1043 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1044 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1051 * Check if already created.
1053 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1054 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1055 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1056 if (event_notifier_priv
->parent
.desc
== desc
&&
1057 event_notifier_priv
->parent
.user_token
== base_enabler
->user_token
)
1063 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1064 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1065 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1067 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1069 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1070 event_notifier_param
.event
.u
.syscall
.abi
= abi
;
1071 event_notifier_param
.event
.u
.syscall
.entryexit
= entryexit
;
1073 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1074 error_counter_index
, group
, &event_notifier_param
,
1075 event_notifier_param
.event
.instrumentation
);
1076 if (IS_ERR(event_notifier
)) {
1077 printk(KERN_INFO
"Unable to create unknown notifier %s\n",
1083 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, unknown_dispatch_list
);
1089 static int create_matching_event_notifiers(
1090 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1091 const struct trace_syscall_entry
*table
,
1092 size_t table_len
, enum sc_type type
)
1094 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1095 const struct lttng_kernel_event_desc
*desc
;
1096 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1097 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1101 /* iterate over all syscall and create event_notifier that match */
1102 for (i
= 0; i
< table_len
; i
++) {
1103 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1104 struct lttng_kernel_event_notifier
*event_notifier
;
1105 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1106 struct hlist_head
*head
;
1109 desc
= table
[i
].desc
;
1111 /* Unknown syscall */
1115 if (!lttng_desc_match_enabler(desc
,
1116 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
)))
1120 * Check if already created.
1122 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1123 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1124 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1125 if (event_notifier_priv
->parent
.desc
== desc
1126 && event_notifier_priv
->parent
.user_token
== event_notifier_enabler
->base
.user_token
)
1132 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1135 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1136 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1139 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1140 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1142 case SC_TYPE_COMPAT_ENTRY
:
1143 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1144 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1146 case SC_TYPE_COMPAT_EXIT
:
1147 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1148 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1151 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1152 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1153 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1154 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1156 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1157 error_counter_index
, group
, &event_notifier_param
,
1158 event_notifier_param
.event
.instrumentation
);
1159 if (IS_ERR(event_notifier
)) {
1160 printk(KERN_INFO
"Unable to create event_notifier %s\n",
1166 event_notifier
->priv
->parent
.u
.syscall
.syscall_id
= i
;
1174 int lttng_syscalls_create_matching_event_notifiers(
1175 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
1178 struct lttng_enabler
*base_enabler
=
1179 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
);
1180 enum lttng_kernel_abi_syscall_entryexit entryexit
=
1181 base_enabler
->event_param
.u
.syscall
.entryexit
;
1183 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1184 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1185 sc_table
.table
, sc_table
.len
, SC_TYPE_ENTRY
);
1189 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1190 compat_sc_table
.table
, compat_sc_table
.len
,
1191 SC_TYPE_COMPAT_ENTRY
);
1195 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1200 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1201 SC_TYPE_COMPAT_ENTRY
);
1206 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1207 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1208 sc_exit_table
.table
, sc_exit_table
.len
,
1213 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1218 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1219 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
1220 SC_TYPE_COMPAT_EXIT
);
1224 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1225 SC_TYPE_COMPAT_EXIT
);
1235 * Unregister the syscall event_notifier probes from the callsites.
1237 int lttng_syscalls_unregister_event_notifier_group(
1238 struct lttng_event_notifier_group
*event_notifier_group
)
1243 * Only register the event_notifier probe on the `sys_enter` callsite for now.
1244 * At the moment, we don't think it's desirable to have one fired
1245 * event_notifier for the entry and one for the exit of a syscall.
1247 if (event_notifier_group
->sys_enter_registered
) {
1248 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1249 (void *) syscall_entry_event_notifier_probe
, event_notifier_group
);
1252 event_notifier_group
->sys_enter_registered
= 0;
1254 if (event_notifier_group
->sys_exit_registered
) {
1255 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1256 (void *) syscall_exit_event_notifier_probe
, event_notifier_group
);
1259 event_notifier_group
->sys_enter_registered
= 0;
1262 kfree(event_notifier_group
->event_notifier_syscall_dispatch
);
1263 kfree(event_notifier_group
->event_notifier_exit_syscall_dispatch
);
1264 #ifdef CONFIG_COMPAT
1265 kfree(event_notifier_group
->event_notifier_compat_syscall_dispatch
);
1266 kfree(event_notifier_group
->event_notifier_exit_compat_syscall_dispatch
);
1271 int lttng_syscalls_unregister_channel(struct lttng_kernel_channel_buffer
*chan
)
1275 if (!chan
->priv
->parent
.sc_table
)
1277 if (chan
->priv
->parent
.sys_enter_registered
) {
1278 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1279 (void *) syscall_entry_event_probe
, chan
);
1282 chan
->priv
->parent
.sys_enter_registered
= 0;
1284 if (chan
->priv
->parent
.sys_exit_registered
) {
1285 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1286 (void *) syscall_exit_event_probe
, chan
);
1289 chan
->priv
->parent
.sys_exit_registered
= 0;
1294 int lttng_syscalls_destroy_event(struct lttng_kernel_channel_buffer
*chan
)
1296 kfree(chan
->priv
->parent
.sc_table
);
1297 kfree(chan
->priv
->parent
.sc_exit_table
);
1298 #ifdef CONFIG_COMPAT
1299 kfree(chan
->priv
->parent
.compat_sc_table
);
1300 kfree(chan
->priv
->parent
.compat_sc_exit_table
);
1302 kfree(chan
->priv
->parent
.sc_filter
);
1307 int get_syscall_nr(const char *syscall_name
)
1309 int syscall_nr
= -1;
1312 for (i
= 0; i
< sc_table
.len
; i
++) {
1313 const struct trace_syscall_entry
*entry
;
1314 const char *it_name
;
1316 entry
= &sc_table
.table
[i
];
1319 it_name
= entry
->desc
->event_name
;
1320 it_name
+= strlen(SYSCALL_ENTRY_STR
);
1321 if (!strcmp(syscall_name
, it_name
)) {
1330 int get_compat_syscall_nr(const char *syscall_name
)
1332 int syscall_nr
= -1;
1335 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
1336 const struct trace_syscall_entry
*entry
;
1337 const char *it_name
;
1339 entry
= &compat_sc_table
.table
[i
];
1342 it_name
= entry
->desc
->event_name
;
1343 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1344 if (!strcmp(syscall_name
, it_name
)) {
1353 uint32_t get_sc_tables_len(void)
1355 return sc_table
.len
+ compat_sc_table
.len
;
1359 const char *get_syscall_name(const char *desc_name
,
1360 enum lttng_syscall_abi abi
,
1361 enum lttng_syscall_entryexit entryexit
)
1363 size_t prefix_len
= 0;
1366 switch (entryexit
) {
1367 case LTTNG_SYSCALL_ENTRY
:
1369 case LTTNG_SYSCALL_ABI_NATIVE
:
1370 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
1372 case LTTNG_SYSCALL_ABI_COMPAT
:
1373 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1377 case LTTNG_SYSCALL_EXIT
:
1379 case LTTNG_SYSCALL_ABI_NATIVE
:
1380 prefix_len
= strlen(SYSCALL_EXIT_STR
);
1382 case LTTNG_SYSCALL_ABI_COMPAT
:
1383 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
1388 WARN_ON_ONCE(prefix_len
== 0);
1389 return desc_name
+ prefix_len
;
1393 int lttng_syscall_filter_enable(
1394 struct lttng_syscall_filter
*filter
,
1395 const char *desc_name
, enum lttng_syscall_abi abi
,
1396 enum lttng_syscall_entryexit entryexit
)
1398 const char *syscall_name
;
1399 unsigned long *bitmap
;
1403 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1406 case LTTNG_SYSCALL_ABI_NATIVE
:
1407 syscall_nr
= get_syscall_nr(syscall_name
);
1409 case LTTNG_SYSCALL_ABI_COMPAT
:
1410 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1418 switch (entryexit
) {
1419 case LTTNG_SYSCALL_ENTRY
:
1421 case LTTNG_SYSCALL_ABI_NATIVE
:
1422 bitmap
= filter
->sc_entry
;
1423 refcount_map
= filter
->sc_entry_refcount_map
;
1425 case LTTNG_SYSCALL_ABI_COMPAT
:
1426 bitmap
= filter
->sc_compat_entry
;
1427 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1433 case LTTNG_SYSCALL_EXIT
:
1435 case LTTNG_SYSCALL_ABI_NATIVE
:
1436 bitmap
= filter
->sc_exit
;
1437 refcount_map
= filter
->sc_exit_refcount_map
;
1439 case LTTNG_SYSCALL_ABI_COMPAT
:
1440 bitmap
= filter
->sc_compat_exit
;
1441 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1450 if (refcount_map
[syscall_nr
] == U32_MAX
)
1452 if (refcount_map
[syscall_nr
]++ == 0)
1453 bitmap_set(bitmap
, syscall_nr
, 1);
1457 int lttng_syscall_filter_enable_event_notifier(
1458 struct lttng_kernel_event_notifier
*event_notifier
)
1460 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1461 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1462 struct hlist_head
*dispatch_list
;
1465 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1467 /* Skip unknown syscall */
1468 if (syscall_id
== -1U)
1471 ret
= lttng_syscall_filter_enable(group
->sc_filter
,
1472 event_notifier
->priv
->parent
.desc
->event_name
,
1473 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1474 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1478 switch (event_notifier
->priv
->parent
.u
.syscall
.entryexit
) {
1479 case LTTNG_SYSCALL_ENTRY
:
1480 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1481 case LTTNG_SYSCALL_ABI_NATIVE
:
1482 dispatch_list
= &group
->event_notifier_syscall_dispatch
[syscall_id
];
1484 case LTTNG_SYSCALL_ABI_COMPAT
:
1485 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[syscall_id
];
1492 case LTTNG_SYSCALL_EXIT
:
1493 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1494 case LTTNG_SYSCALL_ABI_NATIVE
:
1495 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[syscall_id
];
1497 case LTTNG_SYSCALL_ABI_COMPAT
:
1498 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[syscall_id
];
1510 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, dispatch_list
);
1516 int lttng_syscall_filter_enable_event(
1517 struct lttng_kernel_channel_buffer
*channel
,
1518 struct lttng_kernel_event_recorder
*event_recorder
)
1520 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1522 WARN_ON_ONCE(event_recorder
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1524 /* Skip unknown syscall */
1525 if (syscall_id
== -1U)
1528 return lttng_syscall_filter_enable(channel
->priv
->parent
.sc_filter
,
1529 event_recorder
->priv
->parent
.desc
->event_name
,
1530 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1531 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1535 int lttng_syscall_filter_disable(
1536 struct lttng_syscall_filter
*filter
,
1537 const char *desc_name
, enum lttng_syscall_abi abi
,
1538 enum lttng_syscall_entryexit entryexit
)
1540 const char *syscall_name
;
1541 unsigned long *bitmap
;
1545 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1548 case LTTNG_SYSCALL_ABI_NATIVE
:
1549 syscall_nr
= get_syscall_nr(syscall_name
);
1551 case LTTNG_SYSCALL_ABI_COMPAT
:
1552 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1560 switch (entryexit
) {
1561 case LTTNG_SYSCALL_ENTRY
:
1563 case LTTNG_SYSCALL_ABI_NATIVE
:
1564 bitmap
= filter
->sc_entry
;
1565 refcount_map
= filter
->sc_entry_refcount_map
;
1567 case LTTNG_SYSCALL_ABI_COMPAT
:
1568 bitmap
= filter
->sc_compat_entry
;
1569 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1575 case LTTNG_SYSCALL_EXIT
:
1577 case LTTNG_SYSCALL_ABI_NATIVE
:
1578 bitmap
= filter
->sc_exit
;
1579 refcount_map
= filter
->sc_exit_refcount_map
;
1581 case LTTNG_SYSCALL_ABI_COMPAT
:
1582 bitmap
= filter
->sc_compat_exit
;
1583 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1592 if (refcount_map
[syscall_nr
] == 0)
1594 if (--refcount_map
[syscall_nr
] == 0)
1595 bitmap_clear(bitmap
, syscall_nr
, 1);
1599 int lttng_syscall_filter_disable_event_notifier(
1600 struct lttng_kernel_event_notifier
*event_notifier
)
1602 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1603 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1606 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1608 /* Skip unknown syscall */
1609 if (syscall_id
== -1U)
1612 ret
= lttng_syscall_filter_disable(group
->sc_filter
,
1613 event_notifier
->priv
->parent
.desc
->event_name
,
1614 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1615 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1619 hlist_del_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
);
1623 int lttng_syscall_filter_disable_event(
1624 struct lttng_kernel_channel_buffer
*channel
,
1625 struct lttng_kernel_event_recorder
*event_recorder
)
1627 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1629 /* Skip unknown syscall */
1630 if (syscall_id
== -1U)
1633 return lttng_syscall_filter_disable(channel
->priv
->parent
.sc_filter
,
1634 event_recorder
->priv
->parent
.desc
->event_name
,
1635 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1636 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1640 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1642 const struct trace_syscall_entry
*entry
;
1645 for (entry
= sc_table
.table
;
1646 entry
< sc_table
.table
+ sc_table
.len
;
1651 for (entry
= compat_sc_table
.table
;
1652 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1662 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1664 return (void *) syscall_list_get_entry(pos
);
1668 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1671 return (void *) syscall_list_get_entry(ppos
);
1675 void syscall_list_stop(struct seq_file
*m
, void *p
)
1680 int get_sc_table(const struct trace_syscall_entry
*entry
,
1681 const struct trace_syscall_entry
**table
,
1682 unsigned int *bitness
)
1684 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1686 *bitness
= BITS_PER_LONG
;
1688 *table
= sc_table
.table
;
1691 if (!(entry
>= compat_sc_table
.table
1692 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1698 *table
= compat_sc_table
.table
;
1703 int syscall_list_show(struct seq_file
*m
, void *p
)
1705 const struct trace_syscall_entry
*table
, *entry
= p
;
1706 unsigned int bitness
;
1707 unsigned long index
;
1711 ret
= get_sc_table(entry
, &table
, &bitness
);
1716 if (table
== sc_table
.table
) {
1717 index
= entry
- table
;
1718 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1720 index
= (entry
- table
) + sc_table
.len
;
1721 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1723 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1724 index
, name
, bitness
);
1729 const struct seq_operations lttng_syscall_list_seq_ops
= {
1730 .start
= syscall_list_start
,
1731 .next
= syscall_list_next
,
1732 .stop
= syscall_list_stop
,
1733 .show
= syscall_list_show
,
1737 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1739 return seq_open(file
, <tng_syscall_list_seq_ops
);
1742 const struct file_operations lttng_syscall_list_fops
= {
1743 .owner
= THIS_MODULE
,
1744 .open
= lttng_syscall_list_open
,
1746 .llseek
= seq_lseek
,
1747 .release
= seq_release
,
1751 * A syscall is enabled if it is traced for either entry or exit.
1753 long lttng_channel_syscall_mask(struct lttng_kernel_channel_buffer
*channel
,
1754 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1756 uint32_t len
, sc_tables_len
, bitmask_len
;
1759 struct lttng_syscall_filter
*filter
;
1761 ret
= get_user(len
, &usyscall_mask
->len
);
1764 sc_tables_len
= get_sc_tables_len();
1765 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1766 if (len
< sc_tables_len
) {
1767 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1769 /* Array is large enough, we can copy array to user-space. */
1770 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1773 filter
= channel
->priv
->parent
.sc_filter
;
1775 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1778 if (channel
->priv
->parent
.sc_table
) {
1779 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1780 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1781 state
= test_bit(bit
, filter
->sc_entry
)
1782 || test_bit(bit
, filter
->sc_exit
);
1788 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1790 for (; bit
< sc_tables_len
; bit
++) {
1793 if (channel
->priv
->parent
.compat_sc_table
) {
1794 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1795 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1796 state
= test_bit(bit
- sc_table
.len
,
1797 filter
->sc_compat_entry
)
1798 || test_bit(bit
- sc_table
.len
,
1799 filter
->sc_compat_exit
);
1805 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1807 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1813 int lttng_abi_syscall_list(void)
1815 struct file
*syscall_list_file
;
1818 file_fd
= lttng_get_unused_fd();
1824 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1825 <tng_syscall_list_fops
,
1827 if (IS_ERR(syscall_list_file
)) {
1828 ret
= PTR_ERR(syscall_list_file
);
1831 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1834 fd_install(file_fd
, syscall_list_file
);
1838 fput(syscall_list_file
);
1840 put_unused_fd(file_fd
);