1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <asm/ptrace.h>
23 #include <asm/syscall.h>
25 #include <lib/bitfield.h>
26 #include <lttng-events.h>
27 #include "lttng-tracepoint.h"
29 #define LTTNG_SYSCALL_NR_ARGS 6
32 # ifndef is_compat_task
33 # define is_compat_task() (0)
37 /* in_compat_syscall appears in kernel 4.6. */
38 #ifndef in_compat_syscall
39 #define in_compat_syscall() is_compat_task()
49 #define SYSCALL_ENTRY_TOK syscall_entry_
50 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
51 #define SYSCALL_EXIT_TOK syscall_exit_
52 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
54 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
55 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
56 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
57 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
60 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
);
62 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
);
65 * Forward declarations for old kernels.
69 struct oldold_utsname
;
71 struct sel_arg_struct
;
72 struct mmap_arg_struct
;
77 * Forward declaration for kernels >= 5.6
84 typedef __kernel_old_time_t
time_t;
86 #ifdef IA32_NR_syscalls
87 #define NR_compat_syscalls IA32_NR_syscalls
89 #define NR_compat_syscalls NR_syscalls
93 * Create LTTng tracepoint probes.
95 #define LTTNG_PACKAGE_BUILD
96 #define CREATE_TRACE_POINTS
97 #define TP_MODULE_NOINIT
98 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
100 #define PARAMS(args...) args
102 /* Handle unknown syscalls */
104 #define TRACE_SYSTEM syscalls_unknown
105 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
113 #define sc_in(...) __VA_ARGS__
117 #define sc_inout(...) __VA_ARGS__
119 /* Hijack probe callback for system call enter */
121 #define TP_PROBE_CB(_template) &syscall_entry_probe
122 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
123 LTTNG_TRACEPOINT_EVENT(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
125 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
126 LTTNG_TRACEPOINT_EVENT_CODE(syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
127 PARAMS(_locvar), PARAMS(_code_pre), \
128 PARAMS(_fields), PARAMS(_code_post))
129 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
130 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_entry_##_name, PARAMS(_fields))
131 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
132 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_entry_##_template, syscall_entry_##_name)
133 /* Enumerations only defined at first inclusion. */
134 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values) \
135 LTTNG_TRACEPOINT_ENUM(_name, PARAMS(_values))
137 #define TRACE_SYSTEM syscall_entry_integers
138 #define TRACE_INCLUDE_FILE syscalls_integers
139 #include <instrumentation/syscalls/headers/syscalls_integers.h>
140 #undef TRACE_INCLUDE_FILE
142 #define TRACE_SYSTEM syscall_entry_pointers
143 #define TRACE_INCLUDE_FILE syscalls_pointers
144 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
145 #undef TRACE_INCLUDE_FILE
147 #undef SC_LTTNG_TRACEPOINT_ENUM
148 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
149 #undef SC_LTTNG_TRACEPOINT_EVENT
150 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
151 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
153 #undef _TRACE_SYSCALLS_INTEGERS_H
154 #undef _TRACE_SYSCALLS_POINTERS_H
156 /* Hijack probe callback for compat system call enter */
157 #define TP_PROBE_CB(_template) &syscall_entry_probe
158 #define LTTNG_SC_COMPAT
159 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
160 LTTNG_TRACEPOINT_EVENT(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
162 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
163 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_entry_##_name, PARAMS(_proto), PARAMS(_args), \
164 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
165 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
166 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_entry_##_name, PARAMS(_fields))
167 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
168 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_entry_##_template, \
169 compat_syscall_entry_##_name)
170 /* Enumerations only defined at inital inclusion (not here). */
171 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
172 #define TRACE_SYSTEM compat_syscall_entry_integers
173 #define TRACE_INCLUDE_FILE compat_syscalls_integers
174 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
175 #undef TRACE_INCLUDE_FILE
177 #define TRACE_SYSTEM compat_syscall_entry_pointers
178 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
179 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
180 #undef TRACE_INCLUDE_FILE
182 #undef SC_LTTNG_TRACEPOINT_ENUM
183 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
184 #undef SC_LTTNG_TRACEPOINT_EVENT
185 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
186 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
188 #undef _TRACE_SYSCALLS_INTEGERS_H
189 #undef _TRACE_SYSCALLS_POINTERS_H
190 #undef LTTNG_SC_COMPAT
197 #define sc_exit(...) __VA_ARGS__
201 #define sc_out(...) __VA_ARGS__
203 #define sc_inout(...) __VA_ARGS__
205 /* Hijack probe callback for system call exit */
206 #define TP_PROBE_CB(_template) &syscall_exit_probe
207 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
208 LTTNG_TRACEPOINT_EVENT(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
210 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
211 LTTNG_TRACEPOINT_EVENT_CODE(syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
212 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
213 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
214 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(syscall_exit_##_name, PARAMS(_fields))
215 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
216 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(syscall_exit_##_template, \
217 syscall_exit_##_name)
218 /* Enumerations only defined at inital inclusion (not here). */
219 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
220 #define TRACE_SYSTEM syscall_exit_integers
221 #define TRACE_INCLUDE_FILE syscalls_integers
222 #include <instrumentation/syscalls/headers/syscalls_integers.h>
223 #undef TRACE_INCLUDE_FILE
225 #define TRACE_SYSTEM syscall_exit_pointers
226 #define TRACE_INCLUDE_FILE syscalls_pointers
227 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
228 #undef TRACE_INCLUDE_FILE
230 #undef SC_LTTNG_TRACEPOINT_ENUM
231 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
232 #undef SC_LTTNG_TRACEPOINT_EVENT
233 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
234 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
236 #undef _TRACE_SYSCALLS_INTEGERS_H
237 #undef _TRACE_SYSCALLS_POINTERS_H
240 /* Hijack probe callback for compat system call exit */
241 #define TP_PROBE_CB(_template) &syscall_exit_probe
242 #define LTTNG_SC_COMPAT
243 #define SC_LTTNG_TRACEPOINT_EVENT(_name, _proto, _args, _fields) \
244 LTTNG_TRACEPOINT_EVENT(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
246 #define SC_LTTNG_TRACEPOINT_EVENT_CODE(_name, _proto, _args, _locvar, _code_pre, _fields, _code_post) \
247 LTTNG_TRACEPOINT_EVENT_CODE(compat_syscall_exit_##_name, PARAMS(_proto), PARAMS(_args), \
248 PARAMS(_locvar), PARAMS(_code_pre), PARAMS(_fields), PARAMS(_code_post))
249 #define SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(_name, _fields) \
250 LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS(compat_syscall_exit_##_name, PARAMS(_fields))
251 #define SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(_template, _name) \
252 LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS(compat_syscall_exit_##_template, \
253 compat_syscall_exit_##_name)
254 /* Enumerations only defined at inital inclusion (not here). */
255 #define SC_LTTNG_TRACEPOINT_ENUM(_name, _values)
256 #define TRACE_SYSTEM compat_syscall_exit_integers
257 #define TRACE_INCLUDE_FILE compat_syscalls_integers
258 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
259 #undef TRACE_INCLUDE_FILE
261 #define TRACE_SYSTEM compat_syscall_exit_pointers
262 #define TRACE_INCLUDE_FILE compat_syscalls_pointers
263 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
264 #undef TRACE_INCLUDE_FILE
266 #undef SC_LTTNG_TRACEPOINT_ENUM
267 #undef SC_LTTNG_TRACEPOINT_EVENT_CODE
268 #undef SC_LTTNG_TRACEPOINT_EVENT
269 #undef SC_LTTNG_TRACEPOINT_EVENT_CLASS_NOARGS
270 #undef SC_LTTNG_TRACEPOINT_EVENT_INSTANCE_NOARGS
272 #undef _TRACE_SYSCALLS_INTEGERS_H
273 #undef _TRACE_SYSCALLS_POINTERS_H
274 #undef LTTNG_SC_COMPAT
278 #undef TP_MODULE_NOINIT
279 #undef LTTNG_PACKAGE_BUILD
280 #undef CREATE_TRACE_POINTS
282 struct trace_syscall_entry
{
284 const struct lttng_event_desc
*desc
;
285 const struct lttng_event_field
*fields
;
289 #define CREATE_SYSCALL_TABLE
296 #undef TRACE_SYSCALL_TABLE
297 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
299 .func = __event_probe__syscall_entry_##_template, \
300 .nrargs = (_nrargs), \
301 .fields = __event_fields___syscall_entry_##_template, \
302 .desc = &__event_desc___syscall_entry_##_name, \
305 /* Syscall enter tracing table */
306 static const struct trace_syscall_entry sc_table
[] = {
307 #include <instrumentation/syscalls/headers/syscalls_integers.h>
308 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
311 #undef TRACE_SYSCALL_TABLE
312 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
314 .func = __event_probe__compat_syscall_entry_##_template, \
315 .nrargs = (_nrargs), \
316 .fields = __event_fields___compat_syscall_entry_##_template, \
317 .desc = &__event_desc___compat_syscall_entry_##_name, \
320 /* Compat syscall enter table */
321 const struct trace_syscall_entry compat_sc_table
[] = {
322 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
323 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
331 #define sc_exit(...) __VA_ARGS__
333 #undef TRACE_SYSCALL_TABLE
334 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
336 .func = __event_probe__syscall_exit_##_template, \
337 .nrargs = (_nrargs), \
338 .fields = __event_fields___syscall_exit_##_template, \
339 .desc = &__event_desc___syscall_exit_##_name, \
342 /* Syscall exit table */
343 static const struct trace_syscall_entry sc_exit_table
[] = {
344 #include <instrumentation/syscalls/headers/syscalls_integers.h>
345 #include <instrumentation/syscalls/headers/syscalls_pointers.h>
348 #undef TRACE_SYSCALL_TABLE
349 #define TRACE_SYSCALL_TABLE(_template, _name, _nr, _nrargs) \
351 .func = __event_probe__compat_syscall_exit_##_template, \
352 .nrargs = (_nrargs), \
353 .fields = __event_fields___compat_syscall_exit_##_template, \
354 .desc = &__event_desc___compat_syscall_exit_##_name, \
357 /* Compat syscall exit table */
358 const struct trace_syscall_entry compat_sc_exit_table
[] = {
359 #include <instrumentation/syscalls/headers/compat_syscalls_integers.h>
360 #include <instrumentation/syscalls/headers/compat_syscalls_pointers.h>
365 #undef CREATE_SYSCALL_TABLE
367 struct lttng_syscall_filter
{
368 DECLARE_BITMAP(sc
, NR_syscalls
);
369 DECLARE_BITMAP(sc_compat
, NR_compat_syscalls
);
372 static void syscall_entry_unknown(struct lttng_event
*event
,
373 struct pt_regs
*regs
, unsigned int id
)
375 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
377 syscall_get_arguments(current
, regs
, args
);
378 if (unlikely(in_compat_syscall()))
379 __event_probe__compat_syscall_entry_unknown(event
, id
, args
);
381 __event_probe__syscall_entry_unknown(event
, id
, args
);
384 void syscall_entry_probe(void *__data
, struct pt_regs
*regs
, long id
)
386 struct lttng_channel
*chan
= __data
;
387 struct lttng_event
*event
, *unknown_event
;
388 const struct trace_syscall_entry
*table
, *entry
;
391 if (unlikely(in_compat_syscall())) {
392 struct lttng_syscall_filter
*filter
;
394 filter
= lttng_rcu_dereference(chan
->sc_filter
);
396 if (id
< 0 || id
>= NR_compat_syscalls
397 || !test_bit(id
, filter
->sc_compat
)) {
398 /* System call filtered out. */
402 table
= compat_sc_table
;
403 table_len
= ARRAY_SIZE(compat_sc_table
);
404 unknown_event
= chan
->sc_compat_unknown
;
406 struct lttng_syscall_filter
*filter
;
408 filter
= lttng_rcu_dereference(chan
->sc_filter
);
410 if (id
< 0 || id
>= NR_syscalls
411 || !test_bit(id
, filter
->sc
)) {
412 /* System call filtered out. */
417 table_len
= ARRAY_SIZE(sc_table
);
418 unknown_event
= chan
->sc_unknown
;
420 if (unlikely(id
< 0 || id
>= table_len
)) {
421 syscall_entry_unknown(unknown_event
, regs
, id
);
424 if (unlikely(in_compat_syscall()))
425 event
= chan
->compat_sc_table
[id
];
427 event
= chan
->sc_table
[id
];
428 if (unlikely(!event
)) {
429 syscall_entry_unknown(unknown_event
, regs
, id
);
433 WARN_ON_ONCE(!entry
);
435 switch (entry
->nrargs
) {
438 void (*fptr
)(void *__data
) = entry
->func
;
445 void (*fptr
)(void *__data
, unsigned long arg0
) = entry
->func
;
446 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
448 syscall_get_arguments(current
, regs
, args
);
449 fptr(event
, args
[0]);
454 void (*fptr
)(void *__data
,
456 unsigned long arg1
) = entry
->func
;
457 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
459 syscall_get_arguments(current
, regs
, args
);
460 fptr(event
, args
[0], args
[1]);
465 void (*fptr
)(void *__data
,
468 unsigned long arg2
) = entry
->func
;
469 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
471 syscall_get_arguments(current
, regs
, args
);
472 fptr(event
, args
[0], args
[1], args
[2]);
477 void (*fptr
)(void *__data
,
481 unsigned long arg3
) = entry
->func
;
482 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
484 syscall_get_arguments(current
, regs
, args
);
485 fptr(event
, args
[0], args
[1], args
[2], args
[3]);
490 void (*fptr
)(void *__data
,
495 unsigned long arg4
) = entry
->func
;
496 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
498 syscall_get_arguments(current
, regs
, args
);
499 fptr(event
, args
[0], args
[1], args
[2], args
[3], args
[4]);
504 void (*fptr
)(void *__data
,
510 unsigned long arg5
) = entry
->func
;
511 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
513 syscall_get_arguments(current
, regs
, args
);
514 fptr(event
, args
[0], args
[1], args
[2],
515 args
[3], args
[4], args
[5]);
523 static void syscall_exit_unknown(struct lttng_event
*event
,
524 struct pt_regs
*regs
, int id
, long ret
)
526 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
528 syscall_get_arguments(current
, regs
, args
);
529 if (unlikely(in_compat_syscall()))
530 __event_probe__compat_syscall_exit_unknown(event
, id
, ret
,
533 __event_probe__syscall_exit_unknown(event
, id
, ret
, args
);
536 void syscall_exit_probe(void *__data
, struct pt_regs
*regs
, long ret
)
538 struct lttng_channel
*chan
= __data
;
539 struct lttng_event
*event
, *unknown_event
;
540 const struct trace_syscall_entry
*table
, *entry
;
544 id
= syscall_get_nr(current
, regs
);
545 if (unlikely(in_compat_syscall())) {
546 struct lttng_syscall_filter
*filter
;
548 filter
= lttng_rcu_dereference(chan
->sc_filter
);
550 if (id
< 0 || id
>= NR_compat_syscalls
551 || !test_bit(id
, filter
->sc_compat
)) {
552 /* System call filtered out. */
556 table
= compat_sc_exit_table
;
557 table_len
= ARRAY_SIZE(compat_sc_exit_table
);
558 unknown_event
= chan
->compat_sc_exit_unknown
;
560 struct lttng_syscall_filter
*filter
;
562 filter
= lttng_rcu_dereference(chan
->sc_filter
);
564 if (id
< 0 || id
>= NR_syscalls
565 || !test_bit(id
, filter
->sc
)) {
566 /* System call filtered out. */
570 table
= sc_exit_table
;
571 table_len
= ARRAY_SIZE(sc_exit_table
);
572 unknown_event
= chan
->sc_exit_unknown
;
574 if (unlikely(id
< 0 || id
>= table_len
)) {
575 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
578 if (unlikely(in_compat_syscall()))
579 event
= chan
->compat_sc_exit_table
[id
];
581 event
= chan
->sc_exit_table
[id
];
582 if (unlikely(!event
)) {
583 syscall_exit_unknown(unknown_event
, regs
, id
, ret
);
587 WARN_ON_ONCE(!entry
);
589 switch (entry
->nrargs
) {
592 void (*fptr
)(void *__data
, long ret
) = entry
->func
;
599 void (*fptr
)(void *__data
,
601 unsigned long arg0
) = entry
->func
;
602 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
604 syscall_get_arguments(current
, regs
, args
);
605 fptr(event
, ret
, args
[0]);
610 void (*fptr
)(void *__data
,
613 unsigned long arg1
) = entry
->func
;
614 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
616 syscall_get_arguments(current
, regs
, args
);
617 fptr(event
, ret
, args
[0], args
[1]);
622 void (*fptr
)(void *__data
,
626 unsigned long arg2
) = entry
->func
;
627 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
629 syscall_get_arguments(current
, regs
, args
);
630 fptr(event
, ret
, args
[0], args
[1], args
[2]);
635 void (*fptr
)(void *__data
,
640 unsigned long arg3
) = entry
->func
;
641 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
643 syscall_get_arguments(current
, regs
, args
);
644 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3]);
649 void (*fptr
)(void *__data
,
655 unsigned long arg4
) = entry
->func
;
656 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
658 syscall_get_arguments(current
, regs
, args
);
659 fptr(event
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
664 void (*fptr
)(void *__data
,
671 unsigned long arg5
) = entry
->func
;
672 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
674 syscall_get_arguments(current
, regs
, args
);
675 fptr(event
, ret
, args
[0], args
[1], args
[2],
676 args
[3], args
[4], args
[5]);
685 * noinline to diminish caller stack size.
686 * Should be called with sessions lock held.
689 int fill_table(const struct trace_syscall_entry
*table
, size_t table_len
,
690 struct lttng_event
**chan_table
, struct lttng_channel
*chan
,
691 void *filter
, enum sc_type type
)
693 const struct lttng_event_desc
*desc
;
696 /* Allocate events for each syscall, insert into table */
697 for (i
= 0; i
< table_len
; i
++) {
698 struct lttng_kernel_event ev
;
699 desc
= table
[i
].desc
;
702 /* Unknown syscall */
706 * Skip those already populated by previous failed
707 * register for this channel.
711 memset(&ev
, 0, sizeof(ev
));
714 strncpy(ev
.name
, SYSCALL_ENTRY_STR
,
715 LTTNG_KERNEL_SYM_NAME_LEN
);
718 strncpy(ev
.name
, SYSCALL_EXIT_STR
,
719 LTTNG_KERNEL_SYM_NAME_LEN
);
721 case SC_TYPE_COMPAT_ENTRY
:
722 strncpy(ev
.name
, COMPAT_SYSCALL_ENTRY_STR
,
723 LTTNG_KERNEL_SYM_NAME_LEN
);
725 case SC_TYPE_COMPAT_EXIT
:
726 strncpy(ev
.name
, COMPAT_SYSCALL_EXIT_STR
,
727 LTTNG_KERNEL_SYM_NAME_LEN
);
733 strncat(ev
.name
, desc
->name
,
734 LTTNG_KERNEL_SYM_NAME_LEN
- strlen(ev
.name
) - 1);
735 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
736 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
737 chan_table
[i
] = _lttng_event_create(chan
, &ev
, filter
,
738 desc
, ev
.instrumentation
);
739 WARN_ON_ONCE(!chan_table
[i
]);
740 if (IS_ERR(chan_table
[i
])) {
742 * If something goes wrong in event registration
743 * after the first one, we have no choice but to
744 * leave the previous events in there, until
745 * deleted by session teardown.
747 return PTR_ERR(chan_table
[i
]);
754 * Should be called with sessions lock held.
756 int lttng_syscalls_register(struct lttng_channel
*chan
, void *filter
)
758 struct lttng_kernel_event ev
;
761 if (!chan
->sc_table
) {
762 /* create syscall table mapping syscall to events */
763 chan
->sc_table
= kzalloc(sizeof(struct lttng_event
*)
764 * ARRAY_SIZE(sc_table
), GFP_KERNEL
);
768 if (!chan
->sc_exit_table
) {
769 /* create syscall table mapping syscall to events */
770 chan
->sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
771 * ARRAY_SIZE(sc_exit_table
), GFP_KERNEL
);
772 if (!chan
->sc_exit_table
)
778 if (!chan
->compat_sc_table
) {
779 /* create syscall table mapping compat syscall to events */
780 chan
->compat_sc_table
= kzalloc(sizeof(struct lttng_event
*)
781 * ARRAY_SIZE(compat_sc_table
), GFP_KERNEL
);
782 if (!chan
->compat_sc_table
)
786 if (!chan
->compat_sc_exit_table
) {
787 /* create syscall table mapping compat syscall to events */
788 chan
->compat_sc_exit_table
= kzalloc(sizeof(struct lttng_event
*)
789 * ARRAY_SIZE(compat_sc_exit_table
), GFP_KERNEL
);
790 if (!chan
->compat_sc_exit_table
)
794 if (!chan
->sc_unknown
) {
795 const struct lttng_event_desc
*desc
=
796 &__event_desc___syscall_entry_unknown
;
798 memset(&ev
, 0, sizeof(ev
));
799 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
800 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
801 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
802 chan
->sc_unknown
= _lttng_event_create(chan
, &ev
, filter
,
805 WARN_ON_ONCE(!chan
->sc_unknown
);
806 if (IS_ERR(chan
->sc_unknown
)) {
807 return PTR_ERR(chan
->sc_unknown
);
811 if (!chan
->sc_compat_unknown
) {
812 const struct lttng_event_desc
*desc
=
813 &__event_desc___compat_syscall_entry_unknown
;
815 memset(&ev
, 0, sizeof(ev
));
816 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
817 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
818 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
819 chan
->sc_compat_unknown
= _lttng_event_create(chan
, &ev
, filter
,
822 WARN_ON_ONCE(!chan
->sc_unknown
);
823 if (IS_ERR(chan
->sc_compat_unknown
)) {
824 return PTR_ERR(chan
->sc_compat_unknown
);
828 if (!chan
->compat_sc_exit_unknown
) {
829 const struct lttng_event_desc
*desc
=
830 &__event_desc___compat_syscall_exit_unknown
;
832 memset(&ev
, 0, sizeof(ev
));
833 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
834 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
835 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
836 chan
->compat_sc_exit_unknown
= _lttng_event_create(chan
, &ev
,
839 WARN_ON_ONCE(!chan
->compat_sc_exit_unknown
);
840 if (IS_ERR(chan
->compat_sc_exit_unknown
)) {
841 return PTR_ERR(chan
->compat_sc_exit_unknown
);
845 if (!chan
->sc_exit_unknown
) {
846 const struct lttng_event_desc
*desc
=
847 &__event_desc___syscall_exit_unknown
;
849 memset(&ev
, 0, sizeof(ev
));
850 strncpy(ev
.name
, desc
->name
, LTTNG_KERNEL_SYM_NAME_LEN
);
851 ev
.name
[LTTNG_KERNEL_SYM_NAME_LEN
- 1] = '\0';
852 ev
.instrumentation
= LTTNG_KERNEL_SYSCALL
;
853 chan
->sc_exit_unknown
= _lttng_event_create(chan
, &ev
, filter
,
854 desc
, ev
.instrumentation
);
855 WARN_ON_ONCE(!chan
->sc_exit_unknown
);
856 if (IS_ERR(chan
->sc_exit_unknown
)) {
857 return PTR_ERR(chan
->sc_exit_unknown
);
861 ret
= fill_table(sc_table
, ARRAY_SIZE(sc_table
),
862 chan
->sc_table
, chan
, filter
, SC_TYPE_ENTRY
);
865 ret
= fill_table(sc_exit_table
, ARRAY_SIZE(sc_exit_table
),
866 chan
->sc_exit_table
, chan
, filter
, SC_TYPE_EXIT
);
871 ret
= fill_table(compat_sc_table
, ARRAY_SIZE(compat_sc_table
),
872 chan
->compat_sc_table
, chan
, filter
,
873 SC_TYPE_COMPAT_ENTRY
);
876 ret
= fill_table(compat_sc_exit_table
, ARRAY_SIZE(compat_sc_exit_table
),
877 chan
->compat_sc_exit_table
, chan
, filter
,
878 SC_TYPE_COMPAT_EXIT
);
882 if (!chan
->sys_enter_registered
) {
883 ret
= lttng_tracepoint_probe_register("sys_enter",
884 (void *) syscall_entry_probe
, chan
);
887 chan
->sys_enter_registered
= 1;
890 * We change the name of sys_exit tracepoint due to namespace
891 * conflict with sys_exit syscall entry.
893 if (!chan
->sys_exit_registered
) {
894 ret
= lttng_tracepoint_probe_register("sys_exit",
895 (void *) syscall_exit_probe
, chan
);
897 WARN_ON_ONCE(lttng_tracepoint_probe_unregister("sys_enter",
898 (void *) syscall_entry_probe
, chan
));
901 chan
->sys_exit_registered
= 1;
907 * Only called at session destruction.
909 int lttng_syscalls_unregister(struct lttng_channel
*chan
)
915 if (chan
->sys_enter_registered
) {
916 ret
= lttng_tracepoint_probe_unregister("sys_enter",
917 (void *) syscall_entry_probe
, chan
);
920 chan
->sys_enter_registered
= 0;
922 if (chan
->sys_exit_registered
) {
923 ret
= lttng_tracepoint_probe_unregister("sys_exit",
924 (void *) syscall_exit_probe
, chan
);
927 chan
->sys_exit_registered
= 0;
929 /* lttng_event destroy will be performed by lttng_session_destroy() */
930 kfree(chan
->sc_table
);
931 kfree(chan
->sc_exit_table
);
933 kfree(chan
->compat_sc_table
);
934 kfree(chan
->compat_sc_exit_table
);
936 kfree(chan
->sc_filter
);
941 int get_syscall_nr(const char *syscall_name
)
946 for (i
= 0; i
< ARRAY_SIZE(sc_table
); i
++) {
947 const struct trace_syscall_entry
*entry
;
950 entry
= &sc_table
[i
];
953 it_name
= entry
->desc
->name
;
954 it_name
+= strlen(SYSCALL_ENTRY_STR
);
955 if (!strcmp(syscall_name
, it_name
)) {
964 int get_compat_syscall_nr(const char *syscall_name
)
969 for (i
= 0; i
< ARRAY_SIZE(compat_sc_table
); i
++) {
970 const struct trace_syscall_entry
*entry
;
973 entry
= &compat_sc_table
[i
];
976 it_name
= entry
->desc
->name
;
977 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
978 if (!strcmp(syscall_name
, it_name
)) {
987 uint32_t get_sc_tables_len(void)
989 return ARRAY_SIZE(sc_table
) + ARRAY_SIZE(compat_sc_table
);
992 int lttng_syscall_filter_enable(struct lttng_channel
*chan
,
995 int syscall_nr
, compat_syscall_nr
, ret
;
996 struct lttng_syscall_filter
*filter
;
998 WARN_ON_ONCE(!chan
->sc_table
);
1001 /* Enable all system calls by removing filter */
1002 if (chan
->sc_filter
) {
1003 filter
= chan
->sc_filter
;
1004 rcu_assign_pointer(chan
->sc_filter
, NULL
);
1005 synchronize_trace();
1008 chan
->syscall_all
= 1;
1012 if (!chan
->sc_filter
) {
1013 if (chan
->syscall_all
) {
1015 * All syscalls are already enabled.
1019 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1024 filter
= chan
->sc_filter
;
1026 syscall_nr
= get_syscall_nr(name
);
1027 compat_syscall_nr
= get_compat_syscall_nr(name
);
1028 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1032 if (syscall_nr
>= 0) {
1033 if (test_bit(syscall_nr
, filter
->sc
)) {
1037 bitmap_set(filter
->sc
, syscall_nr
, 1);
1039 if (compat_syscall_nr
>= 0) {
1040 if (test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1044 bitmap_set(filter
->sc_compat
, compat_syscall_nr
, 1);
1046 if (!chan
->sc_filter
)
1047 rcu_assign_pointer(chan
->sc_filter
, filter
);
1051 if (!chan
->sc_filter
)
1056 int lttng_syscall_filter_disable(struct lttng_channel
*chan
,
1059 int syscall_nr
, compat_syscall_nr
, ret
;
1060 struct lttng_syscall_filter
*filter
;
1062 WARN_ON_ONCE(!chan
->sc_table
);
1064 if (!chan
->sc_filter
) {
1065 if (!chan
->syscall_all
)
1067 filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
1071 /* Trace all system calls, then apply disable. */
1072 bitmap_set(filter
->sc
, 0, NR_syscalls
);
1073 bitmap_set(filter
->sc_compat
, 0, NR_compat_syscalls
);
1075 filter
= chan
->sc_filter
;
1079 /* Fail if all syscalls are already disabled. */
1080 if (bitmap_empty(filter
->sc
, NR_syscalls
)
1081 && bitmap_empty(filter
->sc_compat
,
1082 NR_compat_syscalls
)) {
1087 /* Disable all system calls */
1088 bitmap_clear(filter
->sc
, 0, NR_syscalls
);
1089 bitmap_clear(filter
->sc_compat
, 0, NR_compat_syscalls
);
1092 syscall_nr
= get_syscall_nr(name
);
1093 compat_syscall_nr
= get_compat_syscall_nr(name
);
1094 if (syscall_nr
< 0 && compat_syscall_nr
< 0) {
1098 if (syscall_nr
>= 0) {
1099 if (!test_bit(syscall_nr
, filter
->sc
)) {
1103 bitmap_clear(filter
->sc
, syscall_nr
, 1);
1105 if (compat_syscall_nr
>= 0) {
1106 if (!test_bit(compat_syscall_nr
, filter
->sc_compat
)) {
1110 bitmap_clear(filter
->sc_compat
, compat_syscall_nr
, 1);
1113 if (!chan
->sc_filter
)
1114 rcu_assign_pointer(chan
->sc_filter
, filter
);
1115 chan
->syscall_all
= 0;
1119 if (!chan
->sc_filter
)
1125 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1127 const struct trace_syscall_entry
*entry
;
1130 for (entry
= sc_table
;
1131 entry
< sc_table
+ ARRAY_SIZE(sc_table
);
1136 for (entry
= compat_sc_table
;
1137 entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
);
1147 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1149 return (void *) syscall_list_get_entry(pos
);
1153 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1156 return (void *) syscall_list_get_entry(ppos
);
1160 void syscall_list_stop(struct seq_file
*m
, void *p
)
1165 int get_sc_table(const struct trace_syscall_entry
*entry
,
1166 const struct trace_syscall_entry
**table
,
1167 unsigned int *bitness
)
1169 if (entry
>= sc_table
&& entry
< sc_table
+ ARRAY_SIZE(sc_table
)) {
1171 *bitness
= BITS_PER_LONG
;
1176 if (!(entry
>= compat_sc_table
1177 && entry
< compat_sc_table
+ ARRAY_SIZE(compat_sc_table
))) {
1183 *table
= compat_sc_table
;
1188 int syscall_list_show(struct seq_file
*m
, void *p
)
1190 const struct trace_syscall_entry
*table
, *entry
= p
;
1191 unsigned int bitness
;
1192 unsigned long index
;
1196 ret
= get_sc_table(entry
, &table
, &bitness
);
1201 if (table
== sc_table
) {
1202 index
= entry
- table
;
1203 name
= &entry
->desc
->name
[strlen(SYSCALL_ENTRY_STR
)];
1205 index
= (entry
- table
) + ARRAY_SIZE(sc_table
);
1206 name
= &entry
->desc
->name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1208 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1209 index
, name
, bitness
);
1214 const struct seq_operations lttng_syscall_list_seq_ops
= {
1215 .start
= syscall_list_start
,
1216 .next
= syscall_list_next
,
1217 .stop
= syscall_list_stop
,
1218 .show
= syscall_list_show
,
1222 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1224 return seq_open(file
, <tng_syscall_list_seq_ops
);
1227 const struct file_operations lttng_syscall_list_fops
= {
1228 .owner
= THIS_MODULE
,
1229 .open
= lttng_syscall_list_open
,
1231 .llseek
= seq_lseek
,
1232 .release
= seq_release
,
1235 long lttng_channel_syscall_mask(struct lttng_channel
*channel
,
1236 struct lttng_kernel_syscall_mask __user
*usyscall_mask
)
1238 uint32_t len
, sc_tables_len
, bitmask_len
;
1241 struct lttng_syscall_filter
*filter
;
1243 ret
= get_user(len
, &usyscall_mask
->len
);
1246 sc_tables_len
= get_sc_tables_len();
1247 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1248 if (len
< sc_tables_len
) {
1249 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1251 /* Array is large enough, we can copy array to user-space. */
1252 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1255 filter
= channel
->sc_filter
;
1257 for (bit
= 0; bit
< ARRAY_SIZE(sc_table
); bit
++) {
1260 if (channel
->sc_table
) {
1262 state
= test_bit(bit
, filter
->sc
);
1268 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1270 for (; bit
< sc_tables_len
; bit
++) {
1273 if (channel
->compat_sc_table
) {
1275 state
= test_bit(bit
- ARRAY_SIZE(sc_table
),
1282 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1284 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1290 int lttng_abi_syscall_list(void)
1292 struct file
*syscall_list_file
;
1295 file_fd
= get_unused_fd_flags(0);
1301 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1302 <tng_syscall_list_fops
,
1304 if (IS_ERR(syscall_list_file
)) {
1305 ret
= PTR_ERR(syscall_list_file
);
1308 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1311 fd_install(file_fd
, syscall_list_file
);
1315 fput(syscall_list_file
);
1317 put_unused_fd(file_fd
);