1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <wrapper/limits.h>
32 #include <lttng/events.h>
33 #include <lttng/events-internal.h>
34 #include <lttng/utils.h>
36 #include "lttng-syscalls.h"
39 # ifndef is_compat_task
40 # define is_compat_task() (0)
44 /* in_compat_syscall appears in kernel 4.6. */
45 #ifndef in_compat_syscall
46 #define in_compat_syscall() is_compat_task()
56 #define SYSCALL_ENTRY_TOK syscall_entry_
57 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
58 #define SYSCALL_EXIT_TOK syscall_exit_
59 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
61 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
62 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
63 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
64 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
66 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
67 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
69 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
71 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
75 * Forward declarations for old kernels.
79 struct oldold_utsname
;
81 struct sel_arg_struct
;
82 struct mmap_arg_struct
;
87 * Forward declaration for kernels >= 5.6
94 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
95 typedef __kernel_old_time_t
time_t;
98 #ifdef IA32_NR_syscalls
99 #define NR_compat_syscalls IA32_NR_syscalls
101 #define NR_compat_syscalls NR_syscalls
105 * Create LTTng tracepoint probes.
107 #define LTTNG_PACKAGE_BUILD
108 #define CREATE_TRACE_POINTS
109 #define TP_MODULE_NOINIT
110 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
112 #define PARAMS(args...) args
114 /* Handle unknown syscalls */
116 #define TRACE_SYSTEM syscalls_unknown
117 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
122 extern const struct trace_syscall_table sc_table
;
123 extern const struct trace_syscall_table compat_sc_table
;
125 /* Event syscall exit table */
126 extern const struct trace_syscall_table sc_exit_table
;
127 extern const struct trace_syscall_table compat_sc_exit_table
;
132 #undef CREATE_SYSCALL_TABLE
134 struct lttng_syscall_filter
{
135 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
136 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
137 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
138 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
141 * Reference counters keeping track of number of events enabled
144 u32 sc_entry_refcount_map
[NR_syscalls
];
145 u32 sc_exit_refcount_map
[NR_syscalls
];
146 u32 sc_compat_entry_refcount_map
[NR_compat_syscalls
];
147 u32 sc_compat_exit_refcount_map
[NR_compat_syscalls
];
150 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
151 struct pt_regs
*regs
, long id
)
153 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
154 struct lttng_kernel_event_common_private
*event_priv
;
156 lttng_syscall_get_arguments(current
, regs
, args
);
157 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
158 if (unlikely(in_compat_syscall()))
159 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
161 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
165 static __always_inline
166 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
167 void *func
, unsigned int nrargs
,
168 struct pt_regs
*regs
)
170 struct lttng_kernel_event_common_private
*event_priv
;
175 void (*fptr
)(void *__data
) = func
;
177 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
178 fptr(event_priv
->pub
);
183 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
184 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
186 lttng_syscall_get_arguments(current
, regs
, args
);
187 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
188 fptr(event_priv
->pub
, args
[0]);
193 void (*fptr
)(void *__data
,
195 unsigned long arg1
) = func
;
196 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
198 lttng_syscall_get_arguments(current
, regs
, args
);
199 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
200 fptr(event_priv
->pub
, args
[0], args
[1]);
205 void (*fptr
)(void *__data
,
208 unsigned long arg2
) = func
;
209 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
211 lttng_syscall_get_arguments(current
, regs
, args
);
212 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
213 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
218 void (*fptr
)(void *__data
,
222 unsigned long arg3
) = func
;
223 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
225 lttng_syscall_get_arguments(current
, regs
, args
);
226 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
227 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
232 void (*fptr
)(void *__data
,
237 unsigned long arg4
) = func
;
238 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
240 lttng_syscall_get_arguments(current
, regs
, args
);
241 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
242 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
247 void (*fptr
)(void *__data
,
253 unsigned long arg5
) = func
;
254 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
256 lttng_syscall_get_arguments(current
, regs
, args
);
257 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
258 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
259 args
[3], args
[4], args
[5]);
267 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
269 struct lttng_kernel_channel_buffer
*chan
= __data
;
270 struct hlist_head
*action_list
, *unknown_action_list
;
271 const struct trace_syscall_entry
*table
, *entry
;
274 if (unlikely(in_compat_syscall())) {
275 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
277 if (id
< 0 || id
>= NR_compat_syscalls
278 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
279 /* System call filtered out. */
282 table
= compat_sc_table
.table
;
283 table_len
= compat_sc_table
.len
;
284 unknown_action_list
= &chan
->priv
->parent
.sc_compat_unknown
;
286 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
288 if (id
< 0 || id
>= NR_syscalls
289 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
290 /* System call filtered out. */
293 table
= sc_table
.table
;
294 table_len
= sc_table
.len
;
295 unknown_action_list
= &chan
->priv
->parent
.sc_unknown
;
297 if (unlikely(id
< 0 || id
>= table_len
)) {
298 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
303 if (!entry
->event_func
) {
304 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
308 if (unlikely(in_compat_syscall())) {
309 action_list
= &chan
->priv
->parent
.compat_sc_table
[id
];
311 action_list
= &chan
->priv
->parent
.sc_table
[id
];
313 if (unlikely(hlist_empty(action_list
)))
316 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
319 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
322 struct lttng_event_notifier_group
*group
= __data
;
323 const struct trace_syscall_entry
*table
, *entry
;
324 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
327 if (unlikely(in_compat_syscall())) {
328 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
330 if (id
< 0 || id
>= NR_compat_syscalls
331 || (!READ_ONCE(group
->syscall_all_entry
) &&
332 !test_bit(id
, filter
->sc_compat_entry
))) {
333 /* System call filtered out. */
336 table
= compat_sc_table
.table
;
337 table_len
= compat_sc_table
.len
;
338 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
340 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
342 if (id
< 0 || id
>= NR_syscalls
343 || (!READ_ONCE(group
->syscall_all_entry
) &&
344 !test_bit(id
, filter
->sc_entry
))) {
345 /* System call filtered out. */
348 table
= sc_table
.table
;
349 table_len
= sc_table
.len
;
350 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
352 /* Check if the syscall id is out of bound. */
353 if (unlikely(id
< 0 || id
>= table_len
)) {
354 syscall_entry_event_unknown(unknown_dispatch_list
,
360 if (!entry
->event_func
) {
361 syscall_entry_event_unknown(unknown_dispatch_list
,
366 if (unlikely(in_compat_syscall())) {
367 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[id
];
369 dispatch_list
= &group
->event_notifier_syscall_dispatch
[id
];
371 if (unlikely(hlist_empty(dispatch_list
)))
374 syscall_entry_event_call_func(dispatch_list
,
375 entry
->event_func
, entry
->nrargs
, regs
);
378 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
379 struct pt_regs
*regs
, long id
, long ret
)
381 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
382 struct lttng_kernel_event_common_private
*event_priv
;
384 lttng_syscall_get_arguments(current
, regs
, args
);
385 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
386 if (unlikely(in_compat_syscall()))
387 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
390 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
394 static __always_inline
395 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
396 void *func
, unsigned int nrargs
,
397 struct pt_regs
*regs
, long ret
)
399 struct lttng_kernel_event_common_private
*event_priv
;
404 void (*fptr
)(void *__data
, long ret
) = func
;
406 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
407 fptr(event_priv
->pub
, ret
);
412 void (*fptr
)(void *__data
,
414 unsigned long arg0
) = func
;
415 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
417 lttng_syscall_get_arguments(current
, regs
, args
);
418 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
419 fptr(event_priv
->pub
, ret
, args
[0]);
424 void (*fptr
)(void *__data
,
427 unsigned long arg1
) = func
;
428 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
430 lttng_syscall_get_arguments(current
, regs
, args
);
431 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
432 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
437 void (*fptr
)(void *__data
,
441 unsigned long arg2
) = func
;
442 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
444 lttng_syscall_get_arguments(current
, regs
, args
);
445 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
446 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
451 void (*fptr
)(void *__data
,
456 unsigned long arg3
) = func
;
457 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
459 lttng_syscall_get_arguments(current
, regs
, args
);
460 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
461 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
466 void (*fptr
)(void *__data
,
472 unsigned long arg4
) = func
;
473 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
475 lttng_syscall_get_arguments(current
, regs
, args
);
476 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
477 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
482 void (*fptr
)(void *__data
,
489 unsigned long arg5
) = func
;
490 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
492 lttng_syscall_get_arguments(current
, regs
, args
);
493 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
494 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
495 args
[3], args
[4], args
[5]);
503 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
505 struct lttng_kernel_channel_buffer
*chan
= __data
;
506 struct hlist_head
*action_list
, *unknown_action_list
;
507 const struct trace_syscall_entry
*table
, *entry
;
511 id
= syscall_get_nr(current
, regs
);
513 if (unlikely(in_compat_syscall())) {
514 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
516 if (id
< 0 || id
>= NR_compat_syscalls
517 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
518 /* System call filtered out. */
521 table
= compat_sc_exit_table
.table
;
522 table_len
= compat_sc_exit_table
.len
;
523 unknown_action_list
= &chan
->priv
->parent
.compat_sc_exit_unknown
;
525 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
527 if (id
< 0 || id
>= NR_syscalls
528 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
529 /* System call filtered out. */
532 table
= sc_exit_table
.table
;
533 table_len
= sc_exit_table
.len
;
534 unknown_action_list
= &chan
->priv
->parent
.sc_exit_unknown
;
536 if (unlikely(id
< 0 || id
>= table_len
)) {
537 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
542 if (!entry
->event_func
) {
543 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
547 if (unlikely(in_compat_syscall())) {
548 action_list
= &chan
->priv
->parent
.compat_sc_exit_table
[id
];
550 action_list
= &chan
->priv
->parent
.sc_exit_table
[id
];
552 if (unlikely(hlist_empty(action_list
)))
555 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
559 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
562 struct lttng_event_notifier_group
*group
= __data
;
563 const struct trace_syscall_entry
*table
, *entry
;
564 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
568 id
= syscall_get_nr(current
, regs
);
570 if (unlikely(in_compat_syscall())) {
571 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
573 if (id
< 0 || id
>= NR_compat_syscalls
574 || (!READ_ONCE(group
->syscall_all_exit
) &&
575 !test_bit(id
, filter
->sc_compat_exit
))) {
576 /* System call filtered out. */
579 table
= compat_sc_exit_table
.table
;
580 table_len
= compat_sc_exit_table
.len
;
581 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
583 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
585 if (id
< 0 || id
>= NR_syscalls
586 || (!READ_ONCE(group
->syscall_all_exit
) &&
587 !test_bit(id
, filter
->sc_exit
))) {
588 /* System call filtered out. */
591 table
= sc_exit_table
.table
;
592 table_len
= sc_exit_table
.len
;
593 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
595 /* Check if the syscall id is out of bound. */
596 if (unlikely(id
< 0 || id
>= table_len
)) {
597 syscall_exit_event_unknown(unknown_dispatch_list
,
603 if (!entry
->event_func
) {
604 syscall_entry_event_unknown(unknown_dispatch_list
,
609 if (unlikely(in_compat_syscall())) {
610 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[id
];
612 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[id
];
614 if (unlikely(hlist_empty(dispatch_list
)))
617 syscall_exit_event_call_func(dispatch_list
,
618 entry
->event_func
, entry
->nrargs
, regs
, ret
);
621 * noinline to diminish caller stack size.
622 * Should be called with sessions lock held.
625 int lttng_create_syscall_event_if_missing(const struct trace_syscall_entry
*table
, size_t table_len
,
626 struct hlist_head
*chan_table
, struct lttng_event_enabler
*event_enabler
,
629 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
630 struct lttng_kernel_session
*session
= chan
->parent
.session
;
633 /* Allocate events for each syscall matching enabler, insert into table */
634 for (i
= 0; i
< table_len
; i
++) {
635 const struct lttng_kernel_event_desc
*desc
= table
[i
].desc
;
636 struct lttng_kernel_abi_event ev
;
637 struct lttng_kernel_event_recorder_private
*event_recorder_priv
;
638 struct lttng_kernel_event_recorder
*event_recorder
;
639 struct hlist_head
*head
;
643 /* Unknown syscall */
646 if (lttng_desc_match_enabler(desc
,
647 lttng_event_enabler_as_enabler(event_enabler
)) <= 0)
650 * Check if already created.
652 head
= utils_borrow_hash_table_bucket(
653 session
->priv
->events_ht
.table
, LTTNG_EVENT_HT_SIZE
,
655 lttng_hlist_for_each_entry(event_recorder_priv
, head
, hlist
) {
656 if (event_recorder_priv
->parent
.desc
== desc
657 && event_recorder_priv
->pub
->chan
== event_enabler
->chan
)
663 /* We need to create an event for this syscall/enabler. */
664 memset(&ev
, 0, sizeof(ev
));
667 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
668 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
671 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
672 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
674 case SC_TYPE_COMPAT_ENTRY
:
675 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
676 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
678 case SC_TYPE_COMPAT_EXIT
:
679 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
680 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
683 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
684 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
685 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
686 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
, ev
.instrumentation
);
687 WARN_ON_ONCE(!event_recorder
);
688 if (IS_ERR(event_recorder
)) {
690 * If something goes wrong in event registration
691 * after the first one, we have no choice but to
692 * leave the previous events in there, until
693 * deleted by session teardown.
695 return PTR_ERR(event_recorder
);
697 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan_table
[i
]);
703 * Should be called with sessions lock held.
705 int lttng_syscalls_register_event(struct lttng_event_enabler
*event_enabler
)
707 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
708 struct lttng_kernel_abi_event ev
;
711 wrapper_vmalloc_sync_mappings();
713 if (!chan
->priv
->parent
.sc_table
) {
714 /* create syscall table mapping syscall to events */
715 chan
->priv
->parent
.sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
716 * sc_table
.len
, GFP_KERNEL
);
717 if (!chan
->priv
->parent
.sc_table
)
720 if (!chan
->priv
->parent
.sc_exit_table
) {
721 /* create syscall table mapping syscall to events */
722 chan
->priv
->parent
.sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
723 * sc_exit_table
.len
, GFP_KERNEL
);
724 if (!chan
->priv
->parent
.sc_exit_table
)
730 if (!chan
->priv
->parent
.compat_sc_table
) {
731 /* create syscall table mapping compat syscall to events */
732 chan
->priv
->parent
.compat_sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
733 * compat_sc_table
.len
, GFP_KERNEL
);
734 if (!chan
->priv
->parent
.compat_sc_table
)
738 if (!chan
->priv
->parent
.compat_sc_exit_table
) {
739 /* create syscall table mapping compat syscall to events */
740 chan
->priv
->parent
.compat_sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
741 * compat_sc_exit_table
.len
, GFP_KERNEL
);
742 if (!chan
->priv
->parent
.compat_sc_exit_table
)
746 if (hlist_empty(&chan
->priv
->parent
.sc_unknown
)) {
747 const struct lttng_kernel_event_desc
*desc
=
748 &__event_desc___syscall_entry_unknown
;
749 struct lttng_kernel_event_recorder
*event_recorder
;
751 memset(&ev
, 0, sizeof(ev
));
752 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
753 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
754 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
755 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
756 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
757 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
759 WARN_ON_ONCE(!event_recorder
);
760 if (IS_ERR(event_recorder
)) {
761 return PTR_ERR(event_recorder
);
763 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_unknown
);
766 if (hlist_empty(&chan
->priv
->parent
.sc_compat_unknown
)) {
767 const struct lttng_kernel_event_desc
*desc
=
768 &__event_desc___compat_syscall_entry_unknown
;
769 struct lttng_kernel_event_recorder
*event_recorder
;
771 memset(&ev
, 0, sizeof(ev
));
772 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
773 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
774 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
775 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
776 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
777 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
779 WARN_ON_ONCE(!event_recorder
);
780 if (IS_ERR(event_recorder
)) {
781 return PTR_ERR(event_recorder
);
783 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_compat_unknown
);
786 if (hlist_empty(&chan
->priv
->parent
.compat_sc_exit_unknown
)) {
787 const struct lttng_kernel_event_desc
*desc
=
788 &__event_desc___compat_syscall_exit_unknown
;
789 struct lttng_kernel_event_recorder
*event_recorder
;
791 memset(&ev
, 0, sizeof(ev
));
792 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
793 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
794 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
795 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
796 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
797 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
799 WARN_ON_ONCE(!event_recorder
);
800 if (IS_ERR(event_recorder
)) {
801 return PTR_ERR(event_recorder
);
803 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.compat_sc_exit_unknown
);
806 if (hlist_empty(&chan
->priv
->parent
.sc_exit_unknown
)) {
807 const struct lttng_kernel_event_desc
*desc
=
808 &__event_desc___syscall_exit_unknown
;
809 struct lttng_kernel_event_recorder
*event_recorder
;
811 memset(&ev
, 0, sizeof(ev
));
812 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
813 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
814 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
815 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
816 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
817 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
819 WARN_ON_ONCE(!event_recorder
);
820 if (IS_ERR(event_recorder
)) {
821 return PTR_ERR(event_recorder
);
823 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_exit_unknown
);
826 ret
= lttng_create_syscall_event_if_missing(sc_table
.table
, sc_table
.len
,
827 chan
->priv
->parent
.sc_table
, event_enabler
, SC_TYPE_ENTRY
);
830 ret
= lttng_create_syscall_event_if_missing(sc_exit_table
.table
, sc_exit_table
.len
,
831 chan
->priv
->parent
.sc_exit_table
, event_enabler
, SC_TYPE_EXIT
);
836 ret
= lttng_create_syscall_event_if_missing(compat_sc_table
.table
, compat_sc_table
.len
,
837 chan
->priv
->parent
.compat_sc_table
, event_enabler
, SC_TYPE_COMPAT_ENTRY
);
840 ret
= lttng_create_syscall_event_if_missing(compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
841 chan
->priv
->parent
.compat_sc_exit_table
, event_enabler
, SC_TYPE_COMPAT_EXIT
);
846 if (!chan
->priv
->parent
.sc_filter
) {
847 chan
->priv
->parent
.sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
849 if (!chan
->priv
->parent
.sc_filter
)
853 if (!chan
->priv
->parent
.sys_enter_registered
) {
854 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
855 (void *) syscall_entry_event_probe
, chan
);
858 chan
->priv
->parent
.sys_enter_registered
= 1;
861 * We change the name of sys_exit tracepoint due to namespace
862 * conflict with sys_exit syscall entry.
864 if (!chan
->priv
->parent
.sys_exit_registered
) {
865 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
866 (void *) syscall_exit_event_probe
, chan
);
868 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
869 (void *) syscall_entry_event_probe
, chan
));
872 chan
->priv
->parent
.sys_exit_registered
= 1;
878 * Should be called with sessions lock held.
880 int lttng_syscalls_register_event_notifier(
881 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
883 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
887 wrapper_vmalloc_sync_mappings();
889 if (!group
->event_notifier_syscall_dispatch
) {
890 group
->event_notifier_syscall_dispatch
=
891 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
893 if (!group
->event_notifier_syscall_dispatch
)
896 /* Initialize all list_head */
897 for (i
= 0; i
< sc_table
.len
; i
++)
898 INIT_HLIST_HEAD(&group
->event_notifier_syscall_dispatch
[i
]);
900 /* Init the unknown syscall notifier list. */
901 INIT_HLIST_HEAD(&group
->event_notifier_unknown_syscall_dispatch
);
904 if (!group
->event_notifier_exit_syscall_dispatch
) {
905 group
->event_notifier_exit_syscall_dispatch
=
906 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
908 if (!group
->event_notifier_exit_syscall_dispatch
)
911 /* Initialize all list_head */
912 for (i
= 0; i
< sc_table
.len
; i
++)
913 INIT_HLIST_HEAD(&group
->event_notifier_exit_syscall_dispatch
[i
]);
915 /* Init the unknown exit syscall notifier list. */
916 INIT_HLIST_HEAD(&group
->event_notifier_exit_unknown_syscall_dispatch
);
920 if (!group
->event_notifier_compat_syscall_dispatch
) {
921 group
->event_notifier_compat_syscall_dispatch
=
922 kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
,
924 if (!group
->event_notifier_syscall_dispatch
)
927 /* Initialize all list_head */
928 for (i
= 0; i
< compat_sc_table
.len
; i
++)
929 INIT_HLIST_HEAD(&group
->event_notifier_compat_syscall_dispatch
[i
]);
931 /* Init the unknown syscall notifier list. */
932 INIT_HLIST_HEAD(&group
->event_notifier_compat_unknown_syscall_dispatch
);
935 if (!group
->event_notifier_exit_compat_syscall_dispatch
) {
936 group
->event_notifier_exit_compat_syscall_dispatch
=
937 kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
,
939 if (!group
->event_notifier_exit_syscall_dispatch
)
942 /* Initialize all list_head */
943 for (i
= 0; i
< compat_sc_exit_table
.len
; i
++)
944 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_syscall_dispatch
[i
]);
946 /* Init the unknown exit syscall notifier list. */
947 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_unknown_syscall_dispatch
);
951 if (!group
->sc_filter
) {
952 group
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
954 if (!group
->sc_filter
)
958 if (!group
->sys_enter_registered
) {
959 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
960 (void *) syscall_entry_event_notifier_probe
, group
);
963 group
->sys_enter_registered
= 1;
966 if (!group
->sys_exit_registered
) {
967 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
968 (void *) syscall_exit_event_notifier_probe
, group
);
970 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
971 (void *) syscall_entry_event_notifier_probe
, group
));
974 group
->sys_exit_registered
= 1;
981 int create_unknown_event_notifier(
982 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
985 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
986 struct lttng_kernel_event_notifier
*event_notifier
;
987 const struct lttng_kernel_event_desc
*desc
;
988 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
989 struct lttng_kernel_abi_event_notifier event_notifier_param
;
990 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
991 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
992 struct lttng_enabler
*base_enabler
= lttng_event_notifier_enabler_as_enabler(
993 event_notifier_enabler
);
994 struct hlist_head
*unknown_dispatch_list
;
997 enum lttng_kernel_abi_syscall_abi abi
;
998 enum lttng_kernel_abi_syscall_entryexit entryexit
;
999 struct hlist_head
*head
;
1003 desc
= &__event_desc___syscall_entry_unknown
;
1004 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
1005 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1006 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1009 desc
= &__event_desc___syscall_exit_unknown
;
1010 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
1011 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1012 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1014 case SC_TYPE_COMPAT_ENTRY
:
1015 desc
= &__event_desc___compat_syscall_entry_unknown
;
1016 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
1017 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1018 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1020 case SC_TYPE_COMPAT_EXIT
:
1021 desc
= &__event_desc___compat_syscall_exit_unknown
;
1022 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
1023 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1024 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1031 * Check if already created.
1033 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1034 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1035 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1036 if (event_notifier_priv
->parent
.desc
== desc
&&
1037 event_notifier_priv
->parent
.user_token
== base_enabler
->user_token
)
1043 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1044 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1045 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1047 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1049 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1050 event_notifier_param
.event
.u
.syscall
.abi
= abi
;
1051 event_notifier_param
.event
.u
.syscall
.entryexit
= entryexit
;
1053 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1054 error_counter_index
, group
, &event_notifier_param
,
1055 event_notifier_param
.event
.instrumentation
);
1056 if (IS_ERR(event_notifier
)) {
1057 printk(KERN_INFO
"Unable to create unknown notifier %s\n",
1063 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, unknown_dispatch_list
);
1069 static int create_matching_event_notifiers(
1070 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1071 const struct trace_syscall_entry
*table
,
1072 size_t table_len
, enum sc_type type
)
1074 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1075 const struct lttng_kernel_event_desc
*desc
;
1076 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1077 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1081 /* iterate over all syscall and create event_notifier that match */
1082 for (i
= 0; i
< table_len
; i
++) {
1083 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1084 struct lttng_kernel_event_notifier
*event_notifier
;
1085 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1086 struct hlist_head
*head
;
1089 desc
= table
[i
].desc
;
1091 /* Unknown syscall */
1095 if (!lttng_desc_match_enabler(desc
,
1096 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
)))
1100 * Check if already created.
1102 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1103 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1104 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1105 if (event_notifier_priv
->parent
.desc
== desc
1106 && event_notifier_priv
->parent
.user_token
== event_notifier_enabler
->base
.user_token
)
1112 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1115 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1116 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1119 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1120 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1122 case SC_TYPE_COMPAT_ENTRY
:
1123 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1124 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1126 case SC_TYPE_COMPAT_EXIT
:
1127 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1128 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1131 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1132 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1133 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1134 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1136 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1137 error_counter_index
, group
, &event_notifier_param
,
1138 event_notifier_param
.event
.instrumentation
);
1139 if (IS_ERR(event_notifier
)) {
1140 printk(KERN_INFO
"Unable to create event_notifier %s\n",
1146 event_notifier
->priv
->parent
.u
.syscall
.syscall_id
= i
;
1154 int lttng_syscalls_create_matching_event_notifiers(
1155 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
1158 struct lttng_enabler
*base_enabler
=
1159 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
);
1160 enum lttng_kernel_abi_syscall_entryexit entryexit
=
1161 base_enabler
->event_param
.u
.syscall
.entryexit
;
1163 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1164 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1165 sc_table
.table
, sc_table
.len
, SC_TYPE_ENTRY
);
1169 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1170 compat_sc_table
.table
, compat_sc_table
.len
,
1171 SC_TYPE_COMPAT_ENTRY
);
1175 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1180 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1181 SC_TYPE_COMPAT_ENTRY
);
1186 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1187 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1188 sc_exit_table
.table
, sc_exit_table
.len
,
1193 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1198 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1199 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
1200 SC_TYPE_COMPAT_EXIT
);
1204 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1205 SC_TYPE_COMPAT_EXIT
);
1215 * Unregister the syscall event_notifier probes from the callsites.
1217 int lttng_syscalls_unregister_event_notifier_group(
1218 struct lttng_event_notifier_group
*event_notifier_group
)
1223 * Only register the event_notifier probe on the `sys_enter` callsite for now.
1224 * At the moment, we don't think it's desirable to have one fired
1225 * event_notifier for the entry and one for the exit of a syscall.
1227 if (event_notifier_group
->sys_enter_registered
) {
1228 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1229 (void *) syscall_entry_event_notifier_probe
, event_notifier_group
);
1232 event_notifier_group
->sys_enter_registered
= 0;
1234 if (event_notifier_group
->sys_exit_registered
) {
1235 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1236 (void *) syscall_exit_event_notifier_probe
, event_notifier_group
);
1239 event_notifier_group
->sys_enter_registered
= 0;
1242 kfree(event_notifier_group
->event_notifier_syscall_dispatch
);
1243 kfree(event_notifier_group
->event_notifier_exit_syscall_dispatch
);
1244 #ifdef CONFIG_COMPAT
1245 kfree(event_notifier_group
->event_notifier_compat_syscall_dispatch
);
1246 kfree(event_notifier_group
->event_notifier_exit_compat_syscall_dispatch
);
1251 int lttng_syscalls_unregister_channel(struct lttng_kernel_channel_buffer
*chan
)
1255 if (!chan
->priv
->parent
.sc_table
)
1257 if (chan
->priv
->parent
.sys_enter_registered
) {
1258 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1259 (void *) syscall_entry_event_probe
, chan
);
1262 chan
->priv
->parent
.sys_enter_registered
= 0;
1264 if (chan
->priv
->parent
.sys_exit_registered
) {
1265 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1266 (void *) syscall_exit_event_probe
, chan
);
1269 chan
->priv
->parent
.sys_exit_registered
= 0;
1274 int lttng_syscalls_destroy_event(struct lttng_kernel_channel_buffer
*chan
)
1276 kfree(chan
->priv
->parent
.sc_table
);
1277 kfree(chan
->priv
->parent
.sc_exit_table
);
1278 #ifdef CONFIG_COMPAT
1279 kfree(chan
->priv
->parent
.compat_sc_table
);
1280 kfree(chan
->priv
->parent
.compat_sc_exit_table
);
1282 kfree(chan
->priv
->parent
.sc_filter
);
1287 int get_syscall_nr(const char *syscall_name
)
1289 int syscall_nr
= -1;
1292 for (i
= 0; i
< sc_table
.len
; i
++) {
1293 const struct trace_syscall_entry
*entry
;
1294 const char *it_name
;
1296 entry
= &sc_table
.table
[i
];
1299 it_name
= entry
->desc
->event_name
;
1300 it_name
+= strlen(SYSCALL_ENTRY_STR
);
1301 if (!strcmp(syscall_name
, it_name
)) {
1310 int get_compat_syscall_nr(const char *syscall_name
)
1312 int syscall_nr
= -1;
1315 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
1316 const struct trace_syscall_entry
*entry
;
1317 const char *it_name
;
1319 entry
= &compat_sc_table
.table
[i
];
1322 it_name
= entry
->desc
->event_name
;
1323 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1324 if (!strcmp(syscall_name
, it_name
)) {
1333 uint32_t get_sc_tables_len(void)
1335 return sc_table
.len
+ compat_sc_table
.len
;
1339 const char *get_syscall_name(const char *desc_name
,
1340 enum lttng_syscall_abi abi
,
1341 enum lttng_syscall_entryexit entryexit
)
1343 size_t prefix_len
= 0;
1346 switch (entryexit
) {
1347 case LTTNG_SYSCALL_ENTRY
:
1349 case LTTNG_SYSCALL_ABI_NATIVE
:
1350 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
1352 case LTTNG_SYSCALL_ABI_COMPAT
:
1353 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1357 case LTTNG_SYSCALL_EXIT
:
1359 case LTTNG_SYSCALL_ABI_NATIVE
:
1360 prefix_len
= strlen(SYSCALL_EXIT_STR
);
1362 case LTTNG_SYSCALL_ABI_COMPAT
:
1363 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
1368 WARN_ON_ONCE(prefix_len
== 0);
1369 return desc_name
+ prefix_len
;
1373 int lttng_syscall_filter_enable(
1374 struct lttng_syscall_filter
*filter
,
1375 const char *desc_name
, enum lttng_syscall_abi abi
,
1376 enum lttng_syscall_entryexit entryexit
)
1378 const char *syscall_name
;
1379 unsigned long *bitmap
;
1383 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1386 case LTTNG_SYSCALL_ABI_NATIVE
:
1387 syscall_nr
= get_syscall_nr(syscall_name
);
1389 case LTTNG_SYSCALL_ABI_COMPAT
:
1390 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1398 switch (entryexit
) {
1399 case LTTNG_SYSCALL_ENTRY
:
1401 case LTTNG_SYSCALL_ABI_NATIVE
:
1402 bitmap
= filter
->sc_entry
;
1403 refcount_map
= filter
->sc_entry_refcount_map
;
1405 case LTTNG_SYSCALL_ABI_COMPAT
:
1406 bitmap
= filter
->sc_compat_entry
;
1407 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1413 case LTTNG_SYSCALL_EXIT
:
1415 case LTTNG_SYSCALL_ABI_NATIVE
:
1416 bitmap
= filter
->sc_exit
;
1417 refcount_map
= filter
->sc_exit_refcount_map
;
1419 case LTTNG_SYSCALL_ABI_COMPAT
:
1420 bitmap
= filter
->sc_compat_exit
;
1421 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1430 if (refcount_map
[syscall_nr
] == U32_MAX
)
1432 if (refcount_map
[syscall_nr
]++ == 0)
1433 bitmap_set(bitmap
, syscall_nr
, 1);
1437 int lttng_syscall_filter_enable_event_notifier(
1438 struct lttng_kernel_event_notifier
*event_notifier
)
1440 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1441 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1442 struct hlist_head
*dispatch_list
;
1445 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1447 /* Skip unknown syscall */
1448 if (syscall_id
== -1U)
1451 ret
= lttng_syscall_filter_enable(group
->sc_filter
,
1452 event_notifier
->priv
->parent
.desc
->event_name
,
1453 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1454 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1458 switch (event_notifier
->priv
->parent
.u
.syscall
.entryexit
) {
1459 case LTTNG_SYSCALL_ENTRY
:
1460 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1461 case LTTNG_SYSCALL_ABI_NATIVE
:
1462 dispatch_list
= &group
->event_notifier_syscall_dispatch
[syscall_id
];
1464 case LTTNG_SYSCALL_ABI_COMPAT
:
1465 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[syscall_id
];
1472 case LTTNG_SYSCALL_EXIT
:
1473 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1474 case LTTNG_SYSCALL_ABI_NATIVE
:
1475 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[syscall_id
];
1477 case LTTNG_SYSCALL_ABI_COMPAT
:
1478 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[syscall_id
];
1490 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, dispatch_list
);
1496 int lttng_syscall_filter_enable_event(
1497 struct lttng_kernel_channel_buffer
*channel
,
1498 struct lttng_kernel_event_recorder
*event_recorder
)
1500 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1502 WARN_ON_ONCE(event_recorder
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1504 /* Skip unknown syscall */
1505 if (syscall_id
== -1U)
1508 return lttng_syscall_filter_enable(channel
->priv
->parent
.sc_filter
,
1509 event_recorder
->priv
->parent
.desc
->event_name
,
1510 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1511 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1515 int lttng_syscall_filter_disable(
1516 struct lttng_syscall_filter
*filter
,
1517 const char *desc_name
, enum lttng_syscall_abi abi
,
1518 enum lttng_syscall_entryexit entryexit
)
1520 const char *syscall_name
;
1521 unsigned long *bitmap
;
1525 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1528 case LTTNG_SYSCALL_ABI_NATIVE
:
1529 syscall_nr
= get_syscall_nr(syscall_name
);
1531 case LTTNG_SYSCALL_ABI_COMPAT
:
1532 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1540 switch (entryexit
) {
1541 case LTTNG_SYSCALL_ENTRY
:
1543 case LTTNG_SYSCALL_ABI_NATIVE
:
1544 bitmap
= filter
->sc_entry
;
1545 refcount_map
= filter
->sc_entry_refcount_map
;
1547 case LTTNG_SYSCALL_ABI_COMPAT
:
1548 bitmap
= filter
->sc_compat_entry
;
1549 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1555 case LTTNG_SYSCALL_EXIT
:
1557 case LTTNG_SYSCALL_ABI_NATIVE
:
1558 bitmap
= filter
->sc_exit
;
1559 refcount_map
= filter
->sc_exit_refcount_map
;
1561 case LTTNG_SYSCALL_ABI_COMPAT
:
1562 bitmap
= filter
->sc_compat_exit
;
1563 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1572 if (refcount_map
[syscall_nr
] == 0)
1574 if (--refcount_map
[syscall_nr
] == 0)
1575 bitmap_clear(bitmap
, syscall_nr
, 1);
1579 int lttng_syscall_filter_disable_event_notifier(
1580 struct lttng_kernel_event_notifier
*event_notifier
)
1582 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1583 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1586 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1588 /* Skip unknown syscall */
1589 if (syscall_id
== -1U)
1592 ret
= lttng_syscall_filter_disable(group
->sc_filter
,
1593 event_notifier
->priv
->parent
.desc
->event_name
,
1594 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1595 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1599 hlist_del_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
);
1603 int lttng_syscall_filter_disable_event(
1604 struct lttng_kernel_channel_buffer
*channel
,
1605 struct lttng_kernel_event_recorder
*event_recorder
)
1607 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1609 /* Skip unknown syscall */
1610 if (syscall_id
== -1U)
1613 return lttng_syscall_filter_disable(channel
->priv
->parent
.sc_filter
,
1614 event_recorder
->priv
->parent
.desc
->event_name
,
1615 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1616 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1620 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1622 const struct trace_syscall_entry
*entry
;
1625 for (entry
= sc_table
.table
;
1626 entry
< sc_table
.table
+ sc_table
.len
;
1631 for (entry
= compat_sc_table
.table
;
1632 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1642 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1644 return (void *) syscall_list_get_entry(pos
);
1648 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1651 return (void *) syscall_list_get_entry(ppos
);
1655 void syscall_list_stop(struct seq_file
*m
, void *p
)
1660 int get_sc_table(const struct trace_syscall_entry
*entry
,
1661 const struct trace_syscall_entry
**table
,
1662 unsigned int *bitness
)
1664 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1666 *bitness
= BITS_PER_LONG
;
1668 *table
= sc_table
.table
;
1671 if (!(entry
>= compat_sc_table
.table
1672 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1678 *table
= compat_sc_table
.table
;
1683 int syscall_list_show(struct seq_file
*m
, void *p
)
1685 const struct trace_syscall_entry
*table
, *entry
= p
;
1686 unsigned int bitness
;
1687 unsigned long index
;
1691 ret
= get_sc_table(entry
, &table
, &bitness
);
1696 if (table
== sc_table
.table
) {
1697 index
= entry
- table
;
1698 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1700 index
= (entry
- table
) + sc_table
.len
;
1701 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1703 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1704 index
, name
, bitness
);
1709 const struct seq_operations lttng_syscall_list_seq_ops
= {
1710 .start
= syscall_list_start
,
1711 .next
= syscall_list_next
,
1712 .stop
= syscall_list_stop
,
1713 .show
= syscall_list_show
,
1717 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1719 return seq_open(file
, <tng_syscall_list_seq_ops
);
1722 const struct file_operations lttng_syscall_list_fops
= {
1723 .owner
= THIS_MODULE
,
1724 .open
= lttng_syscall_list_open
,
1726 .llseek
= seq_lseek
,
1727 .release
= seq_release
,
1731 * A syscall is enabled if it is traced for either entry or exit.
1733 long lttng_channel_syscall_mask(struct lttng_kernel_channel_buffer
*channel
,
1734 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1736 uint32_t len
, sc_tables_len
, bitmask_len
;
1739 struct lttng_syscall_filter
*filter
;
1741 ret
= get_user(len
, &usyscall_mask
->len
);
1744 sc_tables_len
= get_sc_tables_len();
1745 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1746 if (len
< sc_tables_len
) {
1747 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1749 /* Array is large enough, we can copy array to user-space. */
1750 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1753 filter
= channel
->priv
->parent
.sc_filter
;
1755 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1758 if (channel
->priv
->parent
.sc_table
) {
1759 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1760 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1761 state
= test_bit(bit
, filter
->sc_entry
)
1762 || test_bit(bit
, filter
->sc_exit
);
1768 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1770 for (; bit
< sc_tables_len
; bit
++) {
1773 if (channel
->priv
->parent
.compat_sc_table
) {
1774 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1775 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1776 state
= test_bit(bit
- sc_table
.len
,
1777 filter
->sc_compat_entry
)
1778 || test_bit(bit
- sc_table
.len
,
1779 filter
->sc_compat_exit
);
1785 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1787 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1793 int lttng_abi_syscall_list(void)
1795 struct file
*syscall_list_file
;
1798 file_fd
= lttng_get_unused_fd();
1804 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1805 <tng_syscall_list_fops
,
1807 if (IS_ERR(syscall_list_file
)) {
1808 ret
= PTR_ERR(syscall_list_file
);
1811 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1814 fd_install(file_fd
, syscall_list_file
);
1818 fput(syscall_list_file
);
1820 put_unused_fd(file_fd
);