1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <lttng/events.h>
32 #include <lttng/events-internal.h>
33 #include <lttng/utils.h>
35 #include "lttng-syscalls.h"
38 # ifndef is_compat_task
39 # define is_compat_task() (0)
43 /* in_compat_syscall appears in kernel 4.6. */
44 #ifndef in_compat_syscall
45 #define in_compat_syscall() is_compat_task()
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
65 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
66 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
69 * Forward declarations for old kernels.
73 struct oldold_utsname
;
75 struct sel_arg_struct
;
76 struct mmap_arg_struct
;
81 * Forward declaration for kernels >= 5.6
88 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
89 typedef __kernel_old_time_t
time_t;
92 #ifdef IA32_NR_syscalls
93 #define NR_compat_syscalls IA32_NR_syscalls
95 #define NR_compat_syscalls NR_syscalls
99 * Create LTTng tracepoint probes.
101 #define LTTNG_PACKAGE_BUILD
102 #define CREATE_TRACE_POINTS
103 #define TP_MODULE_NOINIT
104 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
106 #define PARAMS(args...) args
108 /* Handle unknown syscalls */
110 #define TRACE_SYSTEM syscalls_unknown
111 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
116 extern const struct trace_syscall_table sc_table
;
117 extern const struct trace_syscall_table compat_sc_table
;
119 /* Event syscall exit table */
120 extern const struct trace_syscall_table sc_exit_table
;
121 extern const struct trace_syscall_table compat_sc_exit_table
;
126 #undef CREATE_SYSCALL_TABLE
128 struct lttng_syscall_filter
{
129 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
130 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
131 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
132 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
135 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
136 struct pt_regs
*regs
, long id
)
138 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
139 struct lttng_kernel_event_common_private
*event_priv
;
141 lttng_syscall_get_arguments(current
, regs
, args
);
142 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
143 if (unlikely(in_compat_syscall()))
144 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
146 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
150 static __always_inline
151 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
152 void *func
, unsigned int nrargs
,
153 struct pt_regs
*regs
)
155 struct lttng_kernel_event_common_private
*event_priv
;
160 void (*fptr
)(void *__data
) = func
;
162 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
163 fptr(event_priv
->pub
);
168 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
169 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
171 lttng_syscall_get_arguments(current
, regs
, args
);
172 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
173 fptr(event_priv
->pub
, args
[0]);
178 void (*fptr
)(void *__data
,
180 unsigned long arg1
) = func
;
181 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
183 lttng_syscall_get_arguments(current
, regs
, args
);
184 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
185 fptr(event_priv
->pub
, args
[0], args
[1]);
190 void (*fptr
)(void *__data
,
193 unsigned long arg2
) = func
;
194 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
196 lttng_syscall_get_arguments(current
, regs
, args
);
197 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
198 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
203 void (*fptr
)(void *__data
,
207 unsigned long arg3
) = func
;
208 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
210 lttng_syscall_get_arguments(current
, regs
, args
);
211 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
212 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
217 void (*fptr
)(void *__data
,
222 unsigned long arg4
) = func
;
223 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
225 lttng_syscall_get_arguments(current
, regs
, args
);
226 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
227 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
232 void (*fptr
)(void *__data
,
238 unsigned long arg5
) = func
;
239 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
241 lttng_syscall_get_arguments(current
, regs
, args
);
242 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
243 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
244 args
[3], args
[4], args
[5]);
252 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
254 struct lttng_kernel_syscall_table
*syscall_table
= __data
;
255 struct hlist_head
*action_list
, *unknown_action_list
;
256 const struct trace_syscall_entry
*table
, *entry
;
259 if (unlikely(in_compat_syscall())) {
260 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
262 if (id
< 0 || id
>= NR_compat_syscalls
263 || (!READ_ONCE(syscall_table
->syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
264 /* System call filtered out. */
267 table
= compat_sc_table
.table
;
268 table_len
= compat_sc_table
.len
;
269 unknown_action_list
= &syscall_table
->compat_unknown_syscall_dispatch
;
271 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
273 if (id
< 0 || id
>= NR_syscalls
274 || (!READ_ONCE(syscall_table
->syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
275 /* System call filtered out. */
278 table
= sc_table
.table
;
279 table_len
= sc_table
.len
;
280 unknown_action_list
= &syscall_table
->unknown_syscall_dispatch
;
282 if (unlikely(id
< 0 || id
>= table_len
)) {
283 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
288 if (!entry
->event_func
) {
289 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
293 if (unlikely(in_compat_syscall())) {
294 action_list
= &syscall_table
->compat_syscall_dispatch
[id
];
296 action_list
= &syscall_table
->syscall_dispatch
[id
];
298 if (unlikely(hlist_empty(action_list
)))
301 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
304 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
305 struct pt_regs
*regs
, long id
, long ret
)
307 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
308 struct lttng_kernel_event_common_private
*event_priv
;
310 lttng_syscall_get_arguments(current
, regs
, args
);
311 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
312 if (unlikely(in_compat_syscall()))
313 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
316 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
320 static __always_inline
321 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
322 void *func
, unsigned int nrargs
,
323 struct pt_regs
*regs
, long ret
)
325 struct lttng_kernel_event_common_private
*event_priv
;
330 void (*fptr
)(void *__data
, long ret
) = func
;
332 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
333 fptr(event_priv
->pub
, ret
);
338 void (*fptr
)(void *__data
,
340 unsigned long arg0
) = func
;
341 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
343 lttng_syscall_get_arguments(current
, regs
, args
);
344 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
345 fptr(event_priv
->pub
, ret
, args
[0]);
350 void (*fptr
)(void *__data
,
353 unsigned long arg1
) = func
;
354 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
356 lttng_syscall_get_arguments(current
, regs
, args
);
357 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
358 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
363 void (*fptr
)(void *__data
,
367 unsigned long arg2
) = func
;
368 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
370 lttng_syscall_get_arguments(current
, regs
, args
);
371 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
372 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
377 void (*fptr
)(void *__data
,
382 unsigned long arg3
) = func
;
383 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
385 lttng_syscall_get_arguments(current
, regs
, args
);
386 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
387 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
392 void (*fptr
)(void *__data
,
398 unsigned long arg4
) = func
;
399 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
401 lttng_syscall_get_arguments(current
, regs
, args
);
402 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
403 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
408 void (*fptr
)(void *__data
,
415 unsigned long arg5
) = func
;
416 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
418 lttng_syscall_get_arguments(current
, regs
, args
);
419 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
420 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
421 args
[3], args
[4], args
[5]);
429 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
431 struct lttng_kernel_syscall_table
*syscall_table
= __data
;
432 struct hlist_head
*action_list
, *unknown_action_list
;
433 const struct trace_syscall_entry
*table
, *entry
;
437 id
= syscall_get_nr(current
, regs
);
439 if (unlikely(in_compat_syscall())) {
440 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
442 if (id
< 0 || id
>= NR_compat_syscalls
443 || (!READ_ONCE(syscall_table
->syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
444 /* System call filtered out. */
447 table
= compat_sc_exit_table
.table
;
448 table_len
= compat_sc_exit_table
.len
;
449 unknown_action_list
= &syscall_table
->compat_unknown_syscall_exit_dispatch
;
451 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
453 if (id
< 0 || id
>= NR_syscalls
454 || (!READ_ONCE(syscall_table
->syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
455 /* System call filtered out. */
458 table
= sc_exit_table
.table
;
459 table_len
= sc_exit_table
.len
;
460 unknown_action_list
= &syscall_table
->unknown_syscall_exit_dispatch
;
462 if (unlikely(id
< 0 || id
>= table_len
)) {
463 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
468 if (!entry
->event_func
) {
469 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
473 if (unlikely(in_compat_syscall())) {
474 action_list
= &syscall_table
->compat_syscall_exit_dispatch
[id
];
476 action_list
= &syscall_table
->syscall_exit_dispatch
[id
];
478 if (unlikely(hlist_empty(action_list
)))
481 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
486 struct lttng_kernel_syscall_table
*get_syscall_table_from_enabler(struct lttng_event_enabler_common
*event_enabler
)
488 switch (event_enabler
->enabler_type
) {
489 case LTTNG_EVENT_ENABLER_TYPE_RECORDER
:
491 struct lttng_event_recorder_enabler
*event_recorder_enabler
=
492 container_of(event_enabler
, struct lttng_event_recorder_enabler
, parent
);
493 return &event_recorder_enabler
->chan
->priv
->parent
.syscall_table
;
495 case LTTNG_EVENT_ENABLER_TYPE_NOTIFIER
:
497 struct lttng_event_notifier_enabler
*event_notifier_enabler
=
498 container_of(event_enabler
, struct lttng_event_notifier_enabler
, parent
);
499 return &event_notifier_enabler
->group
->syscall_table
;
507 struct lttng_kernel_syscall_table
*get_syscall_table_from_event(struct lttng_kernel_event_common
*event
)
509 switch (event
->type
) {
510 case LTTNG_KERNEL_EVENT_TYPE_RECORDER
:
512 struct lttng_kernel_event_recorder
*event_recorder
=
513 container_of(event
, struct lttng_kernel_event_recorder
, parent
);
514 return &event_recorder
->chan
->priv
->parent
.syscall_table
;
516 case LTTNG_KERNEL_EVENT_TYPE_NOTIFIER
:
518 struct lttng_kernel_event_notifier
*event_notifier
=
519 container_of(event
, struct lttng_kernel_event_notifier
, parent
);
520 return &event_notifier
->priv
->group
->syscall_table
;
528 * noinline to diminish caller stack size.
529 * Should be called with sessions lock held.
532 int lttng_create_syscall_event_if_missing(const struct trace_syscall_entry
*table
, size_t table_len
,
533 struct hlist_head
*chan_table
, struct lttng_event_recorder_enabler
*syscall_event_enabler
,
536 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(&syscall_event_enabler
->parent
);
537 struct lttng_kernel_channel_buffer
*chan
= syscall_event_enabler
->chan
;
538 struct lttng_kernel_session
*session
= chan
->parent
.session
;
541 /* Allocate events for each syscall matching enabler, insert into table */
542 for (i
= 0; i
< table_len
; i
++) {
543 const struct lttng_kernel_event_desc
*desc
= table
[i
].desc
;
544 struct lttng_event_recorder_enabler
*event_enabler
;
545 struct lttng_kernel_abi_event ev
;
546 struct lttng_kernel_event_recorder_private
*event_recorder_priv
;
547 struct lttng_kernel_event_recorder
*event_recorder
;
548 struct hlist_head
*head
;
552 /* Unknown syscall */
555 if (lttng_desc_match_enabler(desc
,
556 lttng_event_recorder_enabler_as_enabler(syscall_event_enabler
)) <= 0)
559 * Check if already created.
561 head
= utils_borrow_hash_table_bucket(
562 session
->priv
->events_ht
.table
, LTTNG_EVENT_HT_SIZE
,
564 lttng_hlist_for_each_entry(event_recorder_priv
, head
, hlist
) {
565 if (event_recorder_priv
->parent
.desc
== desc
566 && get_syscall_table_from_event(event_recorder_priv
->parent
.pub
) == syscall_table
)
572 /* We need to create an event for this syscall/enabler. */
573 memset(&ev
, 0, sizeof(ev
));
576 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
577 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
580 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
581 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
583 case SC_TYPE_COMPAT_ENTRY
:
584 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
585 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
587 case SC_TYPE_COMPAT_EXIT
:
588 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
589 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
592 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
593 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
594 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
595 event_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
596 if (!event_enabler
) {
599 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
600 WARN_ON_ONCE(!event_recorder
);
601 lttng_event_enabler_destroy(&event_enabler
->parent
);
602 if (IS_ERR(event_recorder
)) {
604 * If something goes wrong in event registration
605 * after the first one, we have no choice but to
606 * leave the previous events in there, until
607 * deleted by session teardown.
609 return PTR_ERR(event_recorder
);
611 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan_table
[i
]);
617 * Should be called with sessions lock held.
619 int lttng_syscalls_register_event(struct lttng_event_recorder_enabler
*syscall_event_enabler
)
621 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(&syscall_event_enabler
->parent
);
622 struct lttng_kernel_abi_event ev
;
625 wrapper_vmalloc_sync_mappings();
627 if (!syscall_table
->syscall_dispatch
) {
628 /* create syscall table mapping syscall to events */
629 syscall_table
->syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_table
.len
, GFP_KERNEL
);
630 if (!syscall_table
->syscall_dispatch
)
633 if (!syscall_table
->syscall_exit_dispatch
) {
634 /* create syscall table mapping syscall to events */
635 syscall_table
->syscall_exit_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_exit_table
.len
, GFP_KERNEL
);
636 if (!syscall_table
->syscall_exit_dispatch
)
642 if (!syscall_table
->compat_syscall_dispatch
) {
643 /* create syscall table mapping compat syscall to events */
644 syscall_table
->compat_syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
, GFP_KERNEL
);
645 if (!syscall_table
->compat_syscall_dispatch
)
649 if (!syscall_table
->compat_syscall_exit_dispatch
) {
650 /* create syscall table mapping compat syscall to events */
651 syscall_table
->compat_syscall_exit_dispatch
= kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
, GFP_KERNEL
);
652 if (!syscall_table
->compat_syscall_exit_dispatch
)
656 if (hlist_empty(&syscall_table
->unknown_syscall_dispatch
)) {
657 const struct lttng_kernel_event_desc
*desc
=
658 &__event_desc___syscall_entry_unknown
;
659 struct lttng_kernel_event_recorder
*event_recorder
;
660 struct lttng_event_recorder_enabler
*event_enabler
;
662 memset(&ev
, 0, sizeof(ev
));
663 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
664 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
665 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
666 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
667 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
668 event_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, syscall_event_enabler
->chan
);
669 if (!event_enabler
) {
672 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
673 lttng_event_enabler_destroy(&event_enabler
->parent
);
674 WARN_ON_ONCE(!event_recorder
);
675 if (IS_ERR(event_recorder
)) {
676 return PTR_ERR(event_recorder
);
678 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &syscall_table
->unknown_syscall_dispatch
);
681 if (hlist_empty(&syscall_table
->compat_unknown_syscall_dispatch
)) {
682 const struct lttng_kernel_event_desc
*desc
=
683 &__event_desc___compat_syscall_entry_unknown
;
684 struct lttng_kernel_event_recorder
*event_recorder
;
685 struct lttng_event_recorder_enabler
*event_enabler
;
687 memset(&ev
, 0, sizeof(ev
));
688 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
689 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
690 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
691 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
692 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
693 event_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, syscall_event_enabler
->chan
);
694 if (!event_enabler
) {
697 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
698 WARN_ON_ONCE(!event_recorder
);
699 lttng_event_enabler_destroy(&event_enabler
->parent
);
700 if (IS_ERR(event_recorder
)) {
701 return PTR_ERR(event_recorder
);
703 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &syscall_table
->compat_unknown_syscall_dispatch
);
706 if (hlist_empty(&syscall_table
->compat_unknown_syscall_exit_dispatch
)) {
707 const struct lttng_kernel_event_desc
*desc
=
708 &__event_desc___compat_syscall_exit_unknown
;
709 struct lttng_kernel_event_recorder
*event_recorder
;
710 struct lttng_event_recorder_enabler
*event_enabler
;
712 memset(&ev
, 0, sizeof(ev
));
713 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
714 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
715 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
716 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
717 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
718 event_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, syscall_event_enabler
->chan
);
719 if (!event_enabler
) {
722 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
723 WARN_ON_ONCE(!event_recorder
);
724 lttng_event_enabler_destroy(&event_enabler
->parent
);
725 if (IS_ERR(event_recorder
)) {
726 return PTR_ERR(event_recorder
);
728 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &syscall_table
->compat_unknown_syscall_exit_dispatch
);
731 if (hlist_empty(&syscall_table
->unknown_syscall_exit_dispatch
)) {
732 const struct lttng_kernel_event_desc
*desc
=
733 &__event_desc___syscall_exit_unknown
;
734 struct lttng_kernel_event_recorder
*event_recorder
;
735 struct lttng_event_recorder_enabler
*event_enabler
;
737 memset(&ev
, 0, sizeof(ev
));
738 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
739 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
740 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
741 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
742 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
743 event_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, syscall_event_enabler
->chan
);
744 if (!event_enabler
) {
747 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
748 WARN_ON_ONCE(!event_recorder
);
749 lttng_event_enabler_destroy(&event_enabler
->parent
);
750 if (IS_ERR(event_recorder
)) {
751 return PTR_ERR(event_recorder
);
753 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &syscall_table
->unknown_syscall_exit_dispatch
);
756 ret
= lttng_create_syscall_event_if_missing(sc_table
.table
, sc_table
.len
,
757 syscall_table
->syscall_dispatch
, syscall_event_enabler
, SC_TYPE_ENTRY
);
760 ret
= lttng_create_syscall_event_if_missing(sc_exit_table
.table
, sc_exit_table
.len
,
761 syscall_table
->syscall_exit_dispatch
, syscall_event_enabler
, SC_TYPE_EXIT
);
766 ret
= lttng_create_syscall_event_if_missing(compat_sc_table
.table
, compat_sc_table
.len
,
767 syscall_table
->compat_syscall_dispatch
, syscall_event_enabler
, SC_TYPE_COMPAT_ENTRY
);
770 ret
= lttng_create_syscall_event_if_missing(compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
771 syscall_table
->compat_syscall_exit_dispatch
, syscall_event_enabler
, SC_TYPE_COMPAT_EXIT
);
776 if (!syscall_table
->sc_filter
) {
777 syscall_table
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
779 if (!syscall_table
->sc_filter
)
783 if (!syscall_table
->sys_enter_registered
) {
784 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
785 (void *) syscall_entry_event_probe
, syscall_table
);
788 syscall_table
->sys_enter_registered
= 1;
791 * We change the name of sys_exit tracepoint due to namespace
792 * conflict with sys_exit syscall entry.
794 if (!syscall_table
->sys_exit_registered
) {
795 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
796 (void *) syscall_exit_event_probe
, syscall_table
);
798 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
799 (void *) syscall_entry_event_probe
, syscall_table
));
802 syscall_table
->sys_exit_registered
= 1;
808 * Should be called with sessions lock held.
810 int lttng_syscalls_register_event_notifier(
811 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
813 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
814 struct lttng_kernel_syscall_table
*syscall_table
= &group
->syscall_table
;
818 wrapper_vmalloc_sync_mappings();
820 if (!syscall_table
->syscall_dispatch
) {
821 syscall_table
->syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_table
.len
, GFP_KERNEL
);
822 if (!syscall_table
->syscall_dispatch
)
825 /* Initialize all list_head */
826 for (i
= 0; i
< sc_table
.len
; i
++)
827 INIT_HLIST_HEAD(&syscall_table
->syscall_dispatch
[i
]);
829 /* Init the unknown syscall notifier list. */
830 INIT_HLIST_HEAD(&syscall_table
->unknown_syscall_dispatch
);
833 if (!syscall_table
->syscall_exit_dispatch
) {
834 syscall_table
->syscall_exit_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_table
.len
, GFP_KERNEL
);
835 if (!syscall_table
->syscall_exit_dispatch
)
838 /* Initialize all list_head */
839 for (i
= 0; i
< sc_table
.len
; i
++)
840 INIT_HLIST_HEAD(&syscall_table
->syscall_exit_dispatch
[i
]);
842 /* Init the unknown exit syscall notifier list. */
843 INIT_HLIST_HEAD(&syscall_table
->unknown_syscall_exit_dispatch
);
847 if (!syscall_table
->compat_syscall_dispatch
) {
848 syscall_table
->compat_syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
, GFP_KERNEL
);
849 if (!syscall_table
->compat_syscall_dispatch
)
852 /* Initialize all list_head */
853 for (i
= 0; i
< compat_sc_table
.len
; i
++)
854 INIT_HLIST_HEAD(&syscall_table
->compat_syscall_dispatch
[i
]);
856 /* Init the unknown syscall notifier list. */
857 INIT_HLIST_HEAD(&syscall_table
->compat_unknown_syscall_dispatch
);
860 if (!syscall_table
->compat_syscall_exit_dispatch
) {
861 syscall_table
->compat_syscall_exit_dispatch
=
862 kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
,
864 if (!syscall_table
->compat_syscall_exit_dispatch
)
867 /* Initialize all list_head */
868 for (i
= 0; i
< compat_sc_exit_table
.len
; i
++)
869 INIT_HLIST_HEAD(&syscall_table
->compat_syscall_exit_dispatch
[i
]);
871 /* Init the unknown exit syscall notifier list. */
872 INIT_HLIST_HEAD(&syscall_table
->compat_unknown_syscall_exit_dispatch
);
876 if (!syscall_table
->sc_filter
) {
877 syscall_table
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
879 if (!syscall_table
->sc_filter
)
883 if (!syscall_table
->sys_enter_registered
) {
884 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
885 (void *) syscall_entry_event_probe
, syscall_table
);
888 syscall_table
->sys_enter_registered
= 1;
891 if (!syscall_table
->sys_exit_registered
) {
892 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
893 (void *) syscall_exit_event_probe
, syscall_table
);
895 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
896 (void *) syscall_entry_event_probe
, syscall_table
));
899 syscall_table
->sys_exit_registered
= 1;
906 int create_unknown_event_notifier(
907 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
910 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
911 struct lttng_kernel_event_notifier
*event_notifier
;
912 const struct lttng_kernel_event_desc
*desc
;
913 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
914 struct lttng_kernel_syscall_table
*syscall_table
= &group
->syscall_table
;
915 struct lttng_kernel_abi_event_notifier event_notifier_param
;
916 uint64_t user_token
= event_notifier_enabler
->parent
.user_token
;
917 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
918 struct lttng_event_enabler_common
*base_enabler
= lttng_event_notifier_enabler_as_enabler(
919 event_notifier_enabler
);
920 struct hlist_head
*unknown_dispatch_list
;
923 enum lttng_kernel_abi_syscall_abi abi
;
924 enum lttng_kernel_abi_syscall_entryexit entryexit
;
925 struct hlist_head
*head
;
929 desc
= &__event_desc___syscall_entry_unknown
;
930 unknown_dispatch_list
= &syscall_table
->unknown_syscall_dispatch
;
931 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
932 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
935 desc
= &__event_desc___syscall_exit_unknown
;
936 unknown_dispatch_list
= &syscall_table
->unknown_syscall_exit_dispatch
;
937 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
938 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
940 case SC_TYPE_COMPAT_ENTRY
:
941 desc
= &__event_desc___compat_syscall_entry_unknown
;
942 unknown_dispatch_list
= &syscall_table
->compat_unknown_syscall_dispatch
;
943 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
944 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
946 case SC_TYPE_COMPAT_EXIT
:
947 desc
= &__event_desc___compat_syscall_exit_unknown
;
948 unknown_dispatch_list
= &syscall_table
->compat_unknown_syscall_exit_dispatch
;
949 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
950 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
957 * Check if already created.
959 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
960 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
961 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
962 if (event_notifier_priv
->parent
.desc
== desc
&&
963 event_notifier_priv
->parent
.user_token
== base_enabler
->user_token
)
969 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
970 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
971 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
973 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
975 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
976 event_notifier_param
.event
.u
.syscall
.abi
= abi
;
977 event_notifier_param
.event
.u
.syscall
.entryexit
= entryexit
;
979 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
980 error_counter_index
, group
, &event_notifier_param
,
981 event_notifier_param
.event
.instrumentation
);
982 if (IS_ERR(event_notifier
)) {
983 printk(KERN_INFO
"Unable to create unknown notifier %s\n",
989 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, unknown_dispatch_list
);
995 static int create_matching_event_notifiers(
996 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
997 const struct trace_syscall_entry
*table
,
998 size_t table_len
, enum sc_type type
)
1000 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1001 const struct lttng_kernel_event_desc
*desc
;
1002 uint64_t user_token
= event_notifier_enabler
->parent
.user_token
;
1003 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1007 /* iterate over all syscall and create event_notifier that match */
1008 for (i
= 0; i
< table_len
; i
++) {
1009 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1010 struct lttng_kernel_event_notifier
*event_notifier
;
1011 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1012 struct hlist_head
*head
;
1015 desc
= table
[i
].desc
;
1017 /* Unknown syscall */
1021 if (!lttng_desc_match_enabler(desc
,
1022 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
)))
1026 * Check if already created.
1028 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1029 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1030 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1031 if (event_notifier_priv
->parent
.desc
== desc
1032 && event_notifier_priv
->parent
.user_token
== event_notifier_enabler
->parent
.user_token
)
1038 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1041 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1042 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1045 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1046 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1048 case SC_TYPE_COMPAT_ENTRY
:
1049 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1050 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1052 case SC_TYPE_COMPAT_EXIT
:
1053 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1054 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1057 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1058 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1059 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1060 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1062 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1063 error_counter_index
, group
, &event_notifier_param
,
1064 event_notifier_param
.event
.instrumentation
);
1065 if (IS_ERR(event_notifier
)) {
1066 printk(KERN_INFO
"Unable to create event_notifier %s\n",
1072 event_notifier
->priv
->parent
.u
.syscall
.syscall_id
= i
;
1080 int lttng_syscalls_create_matching_event_notifiers(
1081 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
1084 struct lttng_event_enabler_common
*base_enabler
=
1085 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
);
1086 enum lttng_kernel_abi_syscall_entryexit entryexit
=
1087 base_enabler
->event_param
.u
.syscall
.entryexit
;
1089 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1090 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1091 sc_table
.table
, sc_table
.len
, SC_TYPE_ENTRY
);
1095 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1096 compat_sc_table
.table
, compat_sc_table
.len
,
1097 SC_TYPE_COMPAT_ENTRY
);
1101 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1106 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1107 SC_TYPE_COMPAT_ENTRY
);
1112 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1113 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1114 sc_exit_table
.table
, sc_exit_table
.len
,
1119 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1124 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1125 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
1126 SC_TYPE_COMPAT_EXIT
);
1130 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1131 SC_TYPE_COMPAT_EXIT
);
1141 * Unregister the syscall event_notifier probes from the callsites.
1143 int lttng_syscalls_unregister_event_notifier_group(
1144 struct lttng_event_notifier_group
*event_notifier_group
)
1146 struct lttng_kernel_syscall_table
*syscall_table
= &event_notifier_group
->syscall_table
;
1150 * Only register the event_notifier probe on the `sys_enter` callsite for now.
1151 * At the moment, we don't think it's desirable to have one fired
1152 * event_notifier for the entry and one for the exit of a syscall.
1154 if (syscall_table
->sys_enter_registered
) {
1155 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1156 (void *) syscall_entry_event_probe
, syscall_table
);
1159 syscall_table
->sys_enter_registered
= 0;
1161 if (syscall_table
->sys_exit_registered
) {
1162 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1163 (void *) syscall_exit_event_probe
, syscall_table
);
1166 syscall_table
->sys_enter_registered
= 0;
1169 kfree(syscall_table
->syscall_dispatch
);
1170 kfree(syscall_table
->syscall_exit_dispatch
);
1171 #ifdef CONFIG_COMPAT
1172 kfree(syscall_table
->compat_syscall_dispatch
);
1173 kfree(syscall_table
->compat_syscall_exit_dispatch
);
1178 int lttng_syscalls_unregister_channel(struct lttng_kernel_channel_buffer
*chan
)
1180 struct lttng_kernel_syscall_table
*syscall_table
= &chan
->priv
->parent
.syscall_table
;
1183 if (!syscall_table
->syscall_dispatch
)
1185 if (syscall_table
->sys_enter_registered
) {
1186 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1187 (void *) syscall_entry_event_probe
, syscall_table
);
1190 syscall_table
->sys_enter_registered
= 0;
1192 if (syscall_table
->sys_exit_registered
) {
1193 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1194 (void *) syscall_exit_event_probe
, syscall_table
);
1197 syscall_table
->sys_exit_registered
= 0;
1202 int lttng_syscalls_destroy_event(struct lttng_kernel_channel_buffer
*chan
)
1204 struct lttng_kernel_syscall_table
*syscall_table
= &chan
->priv
->parent
.syscall_table
;
1206 kfree(syscall_table
->syscall_dispatch
);
1207 kfree(syscall_table
->syscall_exit_dispatch
);
1208 #ifdef CONFIG_COMPAT
1209 kfree(syscall_table
->compat_syscall_dispatch
);
1210 kfree(syscall_table
->compat_syscall_exit_dispatch
);
1212 kfree(syscall_table
->sc_filter
);
1217 int get_syscall_nr(const char *syscall_name
)
1219 int syscall_nr
= -1;
1222 for (i
= 0; i
< sc_table
.len
; i
++) {
1223 const struct trace_syscall_entry
*entry
;
1224 const char *it_name
;
1226 entry
= &sc_table
.table
[i
];
1229 it_name
= entry
->desc
->event_name
;
1230 it_name
+= strlen(SYSCALL_ENTRY_STR
);
1231 if (!strcmp(syscall_name
, it_name
)) {
1240 int get_compat_syscall_nr(const char *syscall_name
)
1242 int syscall_nr
= -1;
1245 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
1246 const struct trace_syscall_entry
*entry
;
1247 const char *it_name
;
1249 entry
= &compat_sc_table
.table
[i
];
1252 it_name
= entry
->desc
->event_name
;
1253 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1254 if (!strcmp(syscall_name
, it_name
)) {
1263 uint32_t get_sc_tables_len(void)
1265 return sc_table
.len
+ compat_sc_table
.len
;
1269 const char *get_syscall_name(const char *desc_name
,
1270 enum lttng_syscall_abi abi
,
1271 enum lttng_syscall_entryexit entryexit
)
1273 size_t prefix_len
= 0;
1276 switch (entryexit
) {
1277 case LTTNG_SYSCALL_ENTRY
:
1279 case LTTNG_SYSCALL_ABI_NATIVE
:
1280 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
1282 case LTTNG_SYSCALL_ABI_COMPAT
:
1283 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1287 case LTTNG_SYSCALL_EXIT
:
1289 case LTTNG_SYSCALL_ABI_NATIVE
:
1290 prefix_len
= strlen(SYSCALL_EXIT_STR
);
1292 case LTTNG_SYSCALL_ABI_COMPAT
:
1293 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
1298 WARN_ON_ONCE(prefix_len
== 0);
1299 return desc_name
+ prefix_len
;
1303 int lttng_syscall_filter_enable(
1304 struct lttng_syscall_filter
*filter
,
1305 const char *desc_name
, enum lttng_syscall_abi abi
,
1306 enum lttng_syscall_entryexit entryexit
)
1308 const char *syscall_name
;
1309 unsigned long *bitmap
;
1312 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1315 case LTTNG_SYSCALL_ABI_NATIVE
:
1316 syscall_nr
= get_syscall_nr(syscall_name
);
1318 case LTTNG_SYSCALL_ABI_COMPAT
:
1319 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1327 switch (entryexit
) {
1328 case LTTNG_SYSCALL_ENTRY
:
1330 case LTTNG_SYSCALL_ABI_NATIVE
:
1331 bitmap
= filter
->sc_entry
;
1333 case LTTNG_SYSCALL_ABI_COMPAT
:
1334 bitmap
= filter
->sc_compat_entry
;
1340 case LTTNG_SYSCALL_EXIT
:
1342 case LTTNG_SYSCALL_ABI_NATIVE
:
1343 bitmap
= filter
->sc_exit
;
1345 case LTTNG_SYSCALL_ABI_COMPAT
:
1346 bitmap
= filter
->sc_compat_exit
;
1355 if (test_bit(syscall_nr
, bitmap
))
1357 bitmap_set(bitmap
, syscall_nr
, 1);
1361 int lttng_syscall_filter_enable_event_notifier(
1362 struct lttng_kernel_event_notifier
*event_notifier
)
1364 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1365 struct lttng_kernel_syscall_table
*syscall_table
= &group
->syscall_table
;
1366 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1367 struct hlist_head
*dispatch_list
;
1370 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1372 ret
= lttng_syscall_filter_enable(syscall_table
->sc_filter
,
1373 event_notifier
->priv
->parent
.desc
->event_name
,
1374 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1375 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1380 switch (event_notifier
->priv
->parent
.u
.syscall
.entryexit
) {
1381 case LTTNG_SYSCALL_ENTRY
:
1382 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1383 case LTTNG_SYSCALL_ABI_NATIVE
:
1384 dispatch_list
= &syscall_table
->syscall_dispatch
[syscall_id
];
1386 case LTTNG_SYSCALL_ABI_COMPAT
:
1387 dispatch_list
= &syscall_table
->compat_syscall_dispatch
[syscall_id
];
1394 case LTTNG_SYSCALL_EXIT
:
1395 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1396 case LTTNG_SYSCALL_ABI_NATIVE
:
1397 dispatch_list
= &syscall_table
->syscall_exit_dispatch
[syscall_id
];
1399 case LTTNG_SYSCALL_ABI_COMPAT
:
1400 dispatch_list
= &syscall_table
->compat_syscall_exit_dispatch
[syscall_id
];
1412 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, dispatch_list
);
1418 int lttng_syscall_filter_enable_event(
1419 struct lttng_kernel_channel_buffer
*channel
,
1420 struct lttng_kernel_event_recorder
*event_recorder
)
1422 struct lttng_kernel_syscall_table
*syscall_table
= &channel
->priv
->parent
.syscall_table
;
1424 WARN_ON_ONCE(event_recorder
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1426 return lttng_syscall_filter_enable(syscall_table
->sc_filter
,
1427 event_recorder
->priv
->parent
.desc
->event_name
,
1428 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1429 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1433 int lttng_syscall_filter_disable(
1434 struct lttng_syscall_filter
*filter
,
1435 const char *desc_name
, enum lttng_syscall_abi abi
,
1436 enum lttng_syscall_entryexit entryexit
)
1438 const char *syscall_name
;
1439 unsigned long *bitmap
;
1442 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1445 case LTTNG_SYSCALL_ABI_NATIVE
:
1446 syscall_nr
= get_syscall_nr(syscall_name
);
1448 case LTTNG_SYSCALL_ABI_COMPAT
:
1449 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1457 switch (entryexit
) {
1458 case LTTNG_SYSCALL_ENTRY
:
1460 case LTTNG_SYSCALL_ABI_NATIVE
:
1461 bitmap
= filter
->sc_entry
;
1463 case LTTNG_SYSCALL_ABI_COMPAT
:
1464 bitmap
= filter
->sc_compat_entry
;
1470 case LTTNG_SYSCALL_EXIT
:
1472 case LTTNG_SYSCALL_ABI_NATIVE
:
1473 bitmap
= filter
->sc_exit
;
1475 case LTTNG_SYSCALL_ABI_COMPAT
:
1476 bitmap
= filter
->sc_compat_exit
;
1485 if (!test_bit(syscall_nr
, bitmap
))
1487 bitmap_clear(bitmap
, syscall_nr
, 1);
1492 int lttng_syscall_filter_disable_event_notifier(
1493 struct lttng_kernel_event_notifier
*event_notifier
)
1495 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1496 struct lttng_kernel_syscall_table
*syscall_table
= &group
->syscall_table
;
1499 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1501 ret
= lttng_syscall_filter_disable(syscall_table
->sc_filter
,
1502 event_notifier
->priv
->parent
.desc
->event_name
,
1503 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1504 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1505 WARN_ON_ONCE(ret
!= 0);
1507 hlist_del_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
);
1511 int lttng_syscall_filter_disable_event(
1512 struct lttng_kernel_channel_buffer
*channel
,
1513 struct lttng_kernel_event_recorder
*event_recorder
)
1515 struct lttng_kernel_syscall_table
*syscall_table
= &channel
->priv
->parent
.syscall_table
;
1517 return lttng_syscall_filter_disable(syscall_table
->sc_filter
,
1518 event_recorder
->priv
->parent
.desc
->event_name
,
1519 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1520 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1524 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1526 const struct trace_syscall_entry
*entry
;
1529 for (entry
= sc_table
.table
;
1530 entry
< sc_table
.table
+ sc_table
.len
;
1535 for (entry
= compat_sc_table
.table
;
1536 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1546 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1548 return (void *) syscall_list_get_entry(pos
);
1552 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1555 return (void *) syscall_list_get_entry(ppos
);
1559 void syscall_list_stop(struct seq_file
*m
, void *p
)
1564 int get_sc_table(const struct trace_syscall_entry
*entry
,
1565 const struct trace_syscall_entry
**table
,
1566 unsigned int *bitness
)
1568 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1570 *bitness
= BITS_PER_LONG
;
1572 *table
= sc_table
.table
;
1575 if (!(entry
>= compat_sc_table
.table
1576 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1582 *table
= compat_sc_table
.table
;
1587 int syscall_list_show(struct seq_file
*m
, void *p
)
1589 const struct trace_syscall_entry
*table
, *entry
= p
;
1590 unsigned int bitness
;
1591 unsigned long index
;
1595 ret
= get_sc_table(entry
, &table
, &bitness
);
1600 if (table
== sc_table
.table
) {
1601 index
= entry
- table
;
1602 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1604 index
= (entry
- table
) + sc_table
.len
;
1605 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1607 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1608 index
, name
, bitness
);
1613 const struct seq_operations lttng_syscall_list_seq_ops
= {
1614 .start
= syscall_list_start
,
1615 .next
= syscall_list_next
,
1616 .stop
= syscall_list_stop
,
1617 .show
= syscall_list_show
,
1621 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1623 return seq_open(file
, <tng_syscall_list_seq_ops
);
1626 const struct file_operations lttng_syscall_list_fops
= {
1627 .owner
= THIS_MODULE
,
1628 .open
= lttng_syscall_list_open
,
1630 .llseek
= seq_lseek
,
1631 .release
= seq_release
,
1635 * A syscall is enabled if it is traced for either entry or exit.
1637 long lttng_channel_syscall_mask(struct lttng_kernel_channel_buffer
*channel
,
1638 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1640 struct lttng_kernel_syscall_table
*syscall_table
= &channel
->priv
->parent
.syscall_table
;
1641 uint32_t len
, sc_tables_len
, bitmask_len
;
1644 struct lttng_syscall_filter
*filter
;
1646 ret
= get_user(len
, &usyscall_mask
->len
);
1649 sc_tables_len
= get_sc_tables_len();
1650 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1651 if (len
< sc_tables_len
) {
1652 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1654 /* Array is large enough, we can copy array to user-space. */
1655 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1658 filter
= syscall_table
->sc_filter
;
1660 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1663 if (syscall_table
->syscall_dispatch
) {
1664 if (!(READ_ONCE(syscall_table
->syscall_all_entry
)
1665 || READ_ONCE(syscall_table
->syscall_all_exit
)) && filter
)
1666 state
= test_bit(bit
, filter
->sc_entry
)
1667 || test_bit(bit
, filter
->sc_exit
);
1673 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1675 for (; bit
< sc_tables_len
; bit
++) {
1678 if (syscall_table
->compat_syscall_dispatch
) {
1679 if (!(READ_ONCE(syscall_table
->syscall_all_entry
)
1680 || READ_ONCE(syscall_table
->syscall_all_exit
)) && filter
)
1681 state
= test_bit(bit
- sc_table
.len
,
1682 filter
->sc_compat_entry
)
1683 || test_bit(bit
- sc_table
.len
,
1684 filter
->sc_compat_exit
);
1690 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1692 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1698 int lttng_abi_syscall_list(void)
1700 struct file
*syscall_list_file
;
1703 file_fd
= lttng_get_unused_fd();
1709 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1710 <tng_syscall_list_fops
,
1712 if (IS_ERR(syscall_list_file
)) {
1713 ret
= PTR_ERR(syscall_list_file
);
1716 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1719 fd_install(file_fd
, syscall_list_file
);
1723 fput(syscall_list_file
);
1725 put_unused_fd(file_fd
);