1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <lttng/events.h>
32 #include <lttng/events-internal.h>
33 #include <lttng/utils.h>
35 #include "lttng-syscalls.h"
38 # ifndef is_compat_task
39 # define is_compat_task() (0)
43 /* in_compat_syscall appears in kernel 4.6. */
44 #ifndef in_compat_syscall
45 #define in_compat_syscall() is_compat_task()
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
65 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
66 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
68 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
70 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
74 * Forward declarations for old kernels.
78 struct oldold_utsname
;
80 struct sel_arg_struct
;
81 struct mmap_arg_struct
;
86 * Forward declaration for kernels >= 5.6
93 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
94 typedef __kernel_old_time_t
time_t;
97 #ifdef IA32_NR_syscalls
98 #define NR_compat_syscalls IA32_NR_syscalls
100 #define NR_compat_syscalls NR_syscalls
104 * Create LTTng tracepoint probes.
106 #define LTTNG_PACKAGE_BUILD
107 #define CREATE_TRACE_POINTS
108 #define TP_MODULE_NOINIT
109 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
111 #define PARAMS(args...) args
113 /* Handle unknown syscalls */
115 #define TRACE_SYSTEM syscalls_unknown
116 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
121 extern const struct trace_syscall_table sc_table
;
122 extern const struct trace_syscall_table compat_sc_table
;
124 /* Event syscall exit table */
125 extern const struct trace_syscall_table sc_exit_table
;
126 extern const struct trace_syscall_table compat_sc_exit_table
;
131 #undef CREATE_SYSCALL_TABLE
133 struct lttng_syscall_filter
{
134 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
135 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
136 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
137 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
140 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
141 struct pt_regs
*regs
, long id
)
143 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
144 struct lttng_kernel_event_common_private
*event_priv
;
146 lttng_syscall_get_arguments(current
, regs
, args
);
147 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
148 if (unlikely(in_compat_syscall()))
149 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
151 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
155 static __always_inline
156 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
157 void *func
, unsigned int nrargs
,
158 struct pt_regs
*regs
)
160 struct lttng_kernel_event_common_private
*event_priv
;
165 void (*fptr
)(void *__data
) = func
;
167 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
168 fptr(event_priv
->pub
);
173 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
174 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
176 lttng_syscall_get_arguments(current
, regs
, args
);
177 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
178 fptr(event_priv
->pub
, args
[0]);
183 void (*fptr
)(void *__data
,
185 unsigned long arg1
) = func
;
186 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
188 lttng_syscall_get_arguments(current
, regs
, args
);
189 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
190 fptr(event_priv
->pub
, args
[0], args
[1]);
195 void (*fptr
)(void *__data
,
198 unsigned long arg2
) = func
;
199 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
201 lttng_syscall_get_arguments(current
, regs
, args
);
202 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
203 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
208 void (*fptr
)(void *__data
,
212 unsigned long arg3
) = func
;
213 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
215 lttng_syscall_get_arguments(current
, regs
, args
);
216 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
217 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
222 void (*fptr
)(void *__data
,
227 unsigned long arg4
) = func
;
228 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
230 lttng_syscall_get_arguments(current
, regs
, args
);
231 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
232 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
237 void (*fptr
)(void *__data
,
243 unsigned long arg5
) = func
;
244 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
246 lttng_syscall_get_arguments(current
, regs
, args
);
247 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
248 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
249 args
[3], args
[4], args
[5]);
257 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
259 struct lttng_kernel_channel_buffer
*chan
= __data
;
260 struct hlist_head
*action_list
, *unknown_action_list
;
261 const struct trace_syscall_entry
*table
, *entry
;
264 if (unlikely(in_compat_syscall())) {
265 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
267 if (id
< 0 || id
>= NR_compat_syscalls
268 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
269 /* System call filtered out. */
272 table
= compat_sc_table
.table
;
273 table_len
= compat_sc_table
.len
;
274 unknown_action_list
= &chan
->priv
->parent
.sc_compat_unknown
;
276 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
278 if (id
< 0 || id
>= NR_syscalls
279 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
280 /* System call filtered out. */
283 table
= sc_table
.table
;
284 table_len
= sc_table
.len
;
285 unknown_action_list
= &chan
->priv
->parent
.sc_unknown
;
287 if (unlikely(id
< 0 || id
>= table_len
)) {
288 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
293 if (!entry
->event_func
) {
294 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
298 if (unlikely(in_compat_syscall())) {
299 action_list
= &chan
->priv
->parent
.compat_sc_table
[id
];
301 action_list
= &chan
->priv
->parent
.sc_table
[id
];
303 if (unlikely(hlist_empty(action_list
)))
306 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
309 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
312 struct lttng_event_notifier_group
*group
= __data
;
313 const struct trace_syscall_entry
*table
, *entry
;
314 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
317 if (unlikely(in_compat_syscall())) {
318 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
320 if (id
< 0 || id
>= NR_compat_syscalls
321 || (!READ_ONCE(group
->syscall_all_entry
) &&
322 !test_bit(id
, filter
->sc_compat_entry
))) {
323 /* System call filtered out. */
326 table
= compat_sc_table
.table
;
327 table_len
= compat_sc_table
.len
;
328 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
330 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
332 if (id
< 0 || id
>= NR_syscalls
333 || (!READ_ONCE(group
->syscall_all_entry
) &&
334 !test_bit(id
, filter
->sc_entry
))) {
335 /* System call filtered out. */
338 table
= sc_table
.table
;
339 table_len
= sc_table
.len
;
340 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
342 /* Check if the syscall id is out of bound. */
343 if (unlikely(id
< 0 || id
>= table_len
)) {
344 syscall_entry_event_unknown(unknown_dispatch_list
,
350 if (!entry
->event_func
) {
351 syscall_entry_event_unknown(unknown_dispatch_list
,
356 if (unlikely(in_compat_syscall())) {
357 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[id
];
359 dispatch_list
= &group
->event_notifier_syscall_dispatch
[id
];
361 if (unlikely(hlist_empty(dispatch_list
)))
364 syscall_entry_event_call_func(dispatch_list
,
365 entry
->event_func
, entry
->nrargs
, regs
);
368 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
369 struct pt_regs
*regs
, long id
, long ret
)
371 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
372 struct lttng_kernel_event_common_private
*event_priv
;
374 lttng_syscall_get_arguments(current
, regs
, args
);
375 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
376 if (unlikely(in_compat_syscall()))
377 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
380 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
384 static __always_inline
385 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
386 void *func
, unsigned int nrargs
,
387 struct pt_regs
*regs
, long ret
)
389 struct lttng_kernel_event_common_private
*event_priv
;
394 void (*fptr
)(void *__data
, long ret
) = func
;
396 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
397 fptr(event_priv
->pub
, ret
);
402 void (*fptr
)(void *__data
,
404 unsigned long arg0
) = func
;
405 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
407 lttng_syscall_get_arguments(current
, regs
, args
);
408 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
409 fptr(event_priv
->pub
, ret
, args
[0]);
414 void (*fptr
)(void *__data
,
417 unsigned long arg1
) = func
;
418 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
420 lttng_syscall_get_arguments(current
, regs
, args
);
421 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
422 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
427 void (*fptr
)(void *__data
,
431 unsigned long arg2
) = func
;
432 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
434 lttng_syscall_get_arguments(current
, regs
, args
);
435 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
436 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
441 void (*fptr
)(void *__data
,
446 unsigned long arg3
) = func
;
447 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
449 lttng_syscall_get_arguments(current
, regs
, args
);
450 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
451 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
456 void (*fptr
)(void *__data
,
462 unsigned long arg4
) = func
;
463 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
465 lttng_syscall_get_arguments(current
, regs
, args
);
466 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
467 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
472 void (*fptr
)(void *__data
,
479 unsigned long arg5
) = func
;
480 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
482 lttng_syscall_get_arguments(current
, regs
, args
);
483 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
484 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
485 args
[3], args
[4], args
[5]);
493 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
495 struct lttng_kernel_channel_buffer
*chan
= __data
;
496 struct hlist_head
*action_list
, *unknown_action_list
;
497 const struct trace_syscall_entry
*table
, *entry
;
501 id
= syscall_get_nr(current
, regs
);
503 if (unlikely(in_compat_syscall())) {
504 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
506 if (id
< 0 || id
>= NR_compat_syscalls
507 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
508 /* System call filtered out. */
511 table
= compat_sc_exit_table
.table
;
512 table_len
= compat_sc_exit_table
.len
;
513 unknown_action_list
= &chan
->priv
->parent
.compat_sc_exit_unknown
;
515 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
517 if (id
< 0 || id
>= NR_syscalls
518 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
519 /* System call filtered out. */
522 table
= sc_exit_table
.table
;
523 table_len
= sc_exit_table
.len
;
524 unknown_action_list
= &chan
->priv
->parent
.sc_exit_unknown
;
526 if (unlikely(id
< 0 || id
>= table_len
)) {
527 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
532 if (!entry
->event_func
) {
533 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
537 if (unlikely(in_compat_syscall())) {
538 action_list
= &chan
->priv
->parent
.compat_sc_exit_table
[id
];
540 action_list
= &chan
->priv
->parent
.sc_exit_table
[id
];
542 if (unlikely(hlist_empty(action_list
)))
545 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
549 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
552 struct lttng_event_notifier_group
*group
= __data
;
553 const struct trace_syscall_entry
*table
, *entry
;
554 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
558 id
= syscall_get_nr(current
, regs
);
560 if (unlikely(in_compat_syscall())) {
561 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
563 if (id
< 0 || id
>= NR_compat_syscalls
564 || (!READ_ONCE(group
->syscall_all_exit
) &&
565 !test_bit(id
, filter
->sc_compat_exit
))) {
566 /* System call filtered out. */
569 table
= compat_sc_exit_table
.table
;
570 table_len
= compat_sc_exit_table
.len
;
571 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
573 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
575 if (id
< 0 || id
>= NR_syscalls
576 || (!READ_ONCE(group
->syscall_all_exit
) &&
577 !test_bit(id
, filter
->sc_exit
))) {
578 /* System call filtered out. */
581 table
= sc_exit_table
.table
;
582 table_len
= sc_exit_table
.len
;
583 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
585 /* Check if the syscall id is out of bound. */
586 if (unlikely(id
< 0 || id
>= table_len
)) {
587 syscall_exit_event_unknown(unknown_dispatch_list
,
593 if (!entry
->event_func
) {
594 syscall_entry_event_unknown(unknown_dispatch_list
,
599 if (unlikely(in_compat_syscall())) {
600 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[id
];
602 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[id
];
604 if (unlikely(hlist_empty(dispatch_list
)))
607 syscall_exit_event_call_func(dispatch_list
,
608 entry
->event_func
, entry
->nrargs
, regs
, ret
);
611 * noinline to diminish caller stack size.
612 * Should be called with sessions lock held.
615 int lttng_create_syscall_event_if_missing(const struct trace_syscall_entry
*table
, size_t table_len
,
616 struct hlist_head
*chan_table
, struct lttng_event_enabler
*syscall_event_enabler
,
619 struct lttng_kernel_channel_buffer
*chan
= syscall_event_enabler
->chan
;
620 struct lttng_kernel_session
*session
= chan
->parent
.session
;
623 /* Allocate events for each syscall matching enabler, insert into table */
624 for (i
= 0; i
< table_len
; i
++) {
625 const struct lttng_kernel_event_desc
*desc
= table
[i
].desc
;
626 struct lttng_event_enabler
*event_enabler
;
627 struct lttng_kernel_abi_event ev
;
628 struct lttng_kernel_event_recorder_private
*event_recorder_priv
;
629 struct lttng_kernel_event_recorder
*event_recorder
;
630 struct hlist_head
*head
;
634 /* Unknown syscall */
637 if (lttng_desc_match_enabler(desc
,
638 lttng_event_enabler_as_enabler(syscall_event_enabler
)) <= 0)
641 * Check if already created.
643 head
= utils_borrow_hash_table_bucket(
644 session
->priv
->events_ht
.table
, LTTNG_EVENT_HT_SIZE
,
646 lttng_hlist_for_each_entry(event_recorder_priv
, head
, hlist
) {
647 if (event_recorder_priv
->parent
.desc
== desc
648 && event_recorder_priv
->pub
->chan
== chan
)
654 /* We need to create an event for this syscall/enabler. */
655 memset(&ev
, 0, sizeof(ev
));
658 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
659 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
662 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
663 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
665 case SC_TYPE_COMPAT_ENTRY
:
666 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
667 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
669 case SC_TYPE_COMPAT_EXIT
:
670 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
671 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
674 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
675 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
676 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
677 event_enabler
= lttng_event_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
678 if (!event_enabler
) {
681 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
682 WARN_ON_ONCE(!event_recorder
);
683 lttng_event_enabler_destroy(event_enabler
);
684 if (IS_ERR(event_recorder
)) {
686 * If something goes wrong in event registration
687 * after the first one, we have no choice but to
688 * leave the previous events in there, until
689 * deleted by session teardown.
691 return PTR_ERR(event_recorder
);
693 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan_table
[i
]);
699 * Should be called with sessions lock held.
701 int lttng_syscalls_register_event(struct lttng_event_enabler
*syscall_event_enabler
)
703 struct lttng_kernel_channel_buffer
*chan
= syscall_event_enabler
->chan
;
704 struct lttng_kernel_abi_event ev
;
707 wrapper_vmalloc_sync_mappings();
709 if (!chan
->priv
->parent
.sc_table
) {
710 /* create syscall table mapping syscall to events */
711 chan
->priv
->parent
.sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
712 * sc_table
.len
, GFP_KERNEL
);
713 if (!chan
->priv
->parent
.sc_table
)
716 if (!chan
->priv
->parent
.sc_exit_table
) {
717 /* create syscall table mapping syscall to events */
718 chan
->priv
->parent
.sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
719 * sc_exit_table
.len
, GFP_KERNEL
);
720 if (!chan
->priv
->parent
.sc_exit_table
)
726 if (!chan
->priv
->parent
.compat_sc_table
) {
727 /* create syscall table mapping compat syscall to events */
728 chan
->priv
->parent
.compat_sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
729 * compat_sc_table
.len
, GFP_KERNEL
);
730 if (!chan
->priv
->parent
.compat_sc_table
)
734 if (!chan
->priv
->parent
.compat_sc_exit_table
) {
735 /* create syscall table mapping compat syscall to events */
736 chan
->priv
->parent
.compat_sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
737 * compat_sc_exit_table
.len
, GFP_KERNEL
);
738 if (!chan
->priv
->parent
.compat_sc_exit_table
)
742 if (hlist_empty(&chan
->priv
->parent
.sc_unknown
)) {
743 const struct lttng_kernel_event_desc
*desc
=
744 &__event_desc___syscall_entry_unknown
;
745 struct lttng_kernel_event_recorder
*event_recorder
;
746 struct lttng_event_enabler
*event_enabler
;
748 memset(&ev
, 0, sizeof(ev
));
749 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
750 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
751 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
752 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
753 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
754 event_enabler
= lttng_event_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
755 if (!event_enabler
) {
758 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
759 lttng_event_enabler_destroy(event_enabler
);
760 WARN_ON_ONCE(!event_recorder
);
761 if (IS_ERR(event_recorder
)) {
762 return PTR_ERR(event_recorder
);
764 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_unknown
);
767 if (hlist_empty(&chan
->priv
->parent
.sc_compat_unknown
)) {
768 const struct lttng_kernel_event_desc
*desc
=
769 &__event_desc___compat_syscall_entry_unknown
;
770 struct lttng_kernel_event_recorder
*event_recorder
;
771 struct lttng_event_enabler
*event_enabler
;
773 memset(&ev
, 0, sizeof(ev
));
774 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
775 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
776 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
777 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
778 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
779 event_enabler
= lttng_event_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
780 if (!event_enabler
) {
783 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
784 WARN_ON_ONCE(!event_recorder
);
785 lttng_event_enabler_destroy(event_enabler
);
786 if (IS_ERR(event_recorder
)) {
787 return PTR_ERR(event_recorder
);
789 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_compat_unknown
);
792 if (hlist_empty(&chan
->priv
->parent
.compat_sc_exit_unknown
)) {
793 const struct lttng_kernel_event_desc
*desc
=
794 &__event_desc___compat_syscall_exit_unknown
;
795 struct lttng_kernel_event_recorder
*event_recorder
;
796 struct lttng_event_enabler
*event_enabler
;
798 memset(&ev
, 0, sizeof(ev
));
799 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
800 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
801 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
802 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
803 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
804 event_enabler
= lttng_event_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
805 if (!event_enabler
) {
808 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
809 WARN_ON_ONCE(!event_recorder
);
810 lttng_event_enabler_destroy(event_enabler
);
811 if (IS_ERR(event_recorder
)) {
812 return PTR_ERR(event_recorder
);
814 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.compat_sc_exit_unknown
);
817 if (hlist_empty(&chan
->priv
->parent
.sc_exit_unknown
)) {
818 const struct lttng_kernel_event_desc
*desc
=
819 &__event_desc___syscall_exit_unknown
;
820 struct lttng_kernel_event_recorder
*event_recorder
;
821 struct lttng_event_enabler
*event_enabler
;
823 memset(&ev
, 0, sizeof(ev
));
824 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
825 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
826 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
827 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
828 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
829 event_enabler
= lttng_event_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
, chan
);
830 if (!event_enabler
) {
833 event_recorder
= _lttng_kernel_event_recorder_create(event_enabler
, desc
);
834 WARN_ON_ONCE(!event_recorder
);
835 lttng_event_enabler_destroy(event_enabler
);
836 if (IS_ERR(event_recorder
)) {
837 return PTR_ERR(event_recorder
);
839 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_exit_unknown
);
842 ret
= lttng_create_syscall_event_if_missing(sc_table
.table
, sc_table
.len
,
843 chan
->priv
->parent
.sc_table
, syscall_event_enabler
, SC_TYPE_ENTRY
);
846 ret
= lttng_create_syscall_event_if_missing(sc_exit_table
.table
, sc_exit_table
.len
,
847 chan
->priv
->parent
.sc_exit_table
, syscall_event_enabler
, SC_TYPE_EXIT
);
852 ret
= lttng_create_syscall_event_if_missing(compat_sc_table
.table
, compat_sc_table
.len
,
853 chan
->priv
->parent
.compat_sc_table
, syscall_event_enabler
, SC_TYPE_COMPAT_ENTRY
);
856 ret
= lttng_create_syscall_event_if_missing(compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
857 chan
->priv
->parent
.compat_sc_exit_table
, syscall_event_enabler
, SC_TYPE_COMPAT_EXIT
);
862 if (!chan
->priv
->parent
.sc_filter
) {
863 chan
->priv
->parent
.sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
865 if (!chan
->priv
->parent
.sc_filter
)
869 if (!chan
->priv
->parent
.sys_enter_registered
) {
870 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
871 (void *) syscall_entry_event_probe
, chan
);
874 chan
->priv
->parent
.sys_enter_registered
= 1;
877 * We change the name of sys_exit tracepoint due to namespace
878 * conflict with sys_exit syscall entry.
880 if (!chan
->priv
->parent
.sys_exit_registered
) {
881 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
882 (void *) syscall_exit_event_probe
, chan
);
884 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
885 (void *) syscall_entry_event_probe
, chan
));
888 chan
->priv
->parent
.sys_exit_registered
= 1;
894 * Should be called with sessions lock held.
896 int lttng_syscalls_register_event_notifier(
897 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
899 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
903 wrapper_vmalloc_sync_mappings();
905 if (!group
->event_notifier_syscall_dispatch
) {
906 group
->event_notifier_syscall_dispatch
=
907 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
909 if (!group
->event_notifier_syscall_dispatch
)
912 /* Initialize all list_head */
913 for (i
= 0; i
< sc_table
.len
; i
++)
914 INIT_HLIST_HEAD(&group
->event_notifier_syscall_dispatch
[i
]);
916 /* Init the unknown syscall notifier list. */
917 INIT_HLIST_HEAD(&group
->event_notifier_unknown_syscall_dispatch
);
920 if (!group
->event_notifier_exit_syscall_dispatch
) {
921 group
->event_notifier_exit_syscall_dispatch
=
922 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
924 if (!group
->event_notifier_exit_syscall_dispatch
)
927 /* Initialize all list_head */
928 for (i
= 0; i
< sc_table
.len
; i
++)
929 INIT_HLIST_HEAD(&group
->event_notifier_exit_syscall_dispatch
[i
]);
931 /* Init the unknown exit syscall notifier list. */
932 INIT_HLIST_HEAD(&group
->event_notifier_exit_unknown_syscall_dispatch
);
936 if (!group
->event_notifier_compat_syscall_dispatch
) {
937 group
->event_notifier_compat_syscall_dispatch
=
938 kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
,
940 if (!group
->event_notifier_syscall_dispatch
)
943 /* Initialize all list_head */
944 for (i
= 0; i
< compat_sc_table
.len
; i
++)
945 INIT_HLIST_HEAD(&group
->event_notifier_compat_syscall_dispatch
[i
]);
947 /* Init the unknown syscall notifier list. */
948 INIT_HLIST_HEAD(&group
->event_notifier_compat_unknown_syscall_dispatch
);
951 if (!group
->event_notifier_exit_compat_syscall_dispatch
) {
952 group
->event_notifier_exit_compat_syscall_dispatch
=
953 kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
,
955 if (!group
->event_notifier_exit_syscall_dispatch
)
958 /* Initialize all list_head */
959 for (i
= 0; i
< compat_sc_exit_table
.len
; i
++)
960 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_syscall_dispatch
[i
]);
962 /* Init the unknown exit syscall notifier list. */
963 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_unknown_syscall_dispatch
);
967 if (!group
->sc_filter
) {
968 group
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
970 if (!group
->sc_filter
)
974 if (!group
->sys_enter_registered
) {
975 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
976 (void *) syscall_entry_event_notifier_probe
, group
);
979 group
->sys_enter_registered
= 1;
982 if (!group
->sys_exit_registered
) {
983 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
984 (void *) syscall_exit_event_notifier_probe
, group
);
986 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
987 (void *) syscall_entry_event_notifier_probe
, group
));
990 group
->sys_exit_registered
= 1;
997 int create_unknown_event_notifier(
998 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1001 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1002 struct lttng_kernel_event_notifier
*event_notifier
;
1003 const struct lttng_kernel_event_desc
*desc
;
1004 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1005 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1006 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1007 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1008 struct lttng_event_enabler_common
*base_enabler
= lttng_event_notifier_enabler_as_enabler(
1009 event_notifier_enabler
);
1010 struct hlist_head
*unknown_dispatch_list
;
1013 enum lttng_kernel_abi_syscall_abi abi
;
1014 enum lttng_kernel_abi_syscall_entryexit entryexit
;
1015 struct hlist_head
*head
;
1019 desc
= &__event_desc___syscall_entry_unknown
;
1020 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
1021 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1022 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1025 desc
= &__event_desc___syscall_exit_unknown
;
1026 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
1027 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1028 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1030 case SC_TYPE_COMPAT_ENTRY
:
1031 desc
= &__event_desc___compat_syscall_entry_unknown
;
1032 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
1033 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1034 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1036 case SC_TYPE_COMPAT_EXIT
:
1037 desc
= &__event_desc___compat_syscall_exit_unknown
;
1038 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
1039 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1040 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1047 * Check if already created.
1049 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1050 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1051 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1052 if (event_notifier_priv
->parent
.desc
== desc
&&
1053 event_notifier_priv
->parent
.user_token
== base_enabler
->user_token
)
1059 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1060 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1061 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1063 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1065 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1066 event_notifier_param
.event
.u
.syscall
.abi
= abi
;
1067 event_notifier_param
.event
.u
.syscall
.entryexit
= entryexit
;
1069 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1070 error_counter_index
, group
, &event_notifier_param
,
1071 event_notifier_param
.event
.instrumentation
);
1072 if (IS_ERR(event_notifier
)) {
1073 printk(KERN_INFO
"Unable to create unknown notifier %s\n",
1079 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, unknown_dispatch_list
);
1085 static int create_matching_event_notifiers(
1086 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1087 const struct trace_syscall_entry
*table
,
1088 size_t table_len
, enum sc_type type
)
1090 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1091 const struct lttng_kernel_event_desc
*desc
;
1092 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1093 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1097 /* iterate over all syscall and create event_notifier that match */
1098 for (i
= 0; i
< table_len
; i
++) {
1099 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1100 struct lttng_kernel_event_notifier
*event_notifier
;
1101 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1102 struct hlist_head
*head
;
1105 desc
= table
[i
].desc
;
1107 /* Unknown syscall */
1111 if (!lttng_desc_match_enabler(desc
,
1112 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
)))
1116 * Check if already created.
1118 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1119 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1120 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1121 if (event_notifier_priv
->parent
.desc
== desc
1122 && event_notifier_priv
->parent
.user_token
== event_notifier_enabler
->base
.user_token
)
1128 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1131 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1132 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1135 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1136 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1138 case SC_TYPE_COMPAT_ENTRY
:
1139 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1140 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1142 case SC_TYPE_COMPAT_EXIT
:
1143 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1144 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1147 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1148 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1149 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1150 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1152 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1153 error_counter_index
, group
, &event_notifier_param
,
1154 event_notifier_param
.event
.instrumentation
);
1155 if (IS_ERR(event_notifier
)) {
1156 printk(KERN_INFO
"Unable to create event_notifier %s\n",
1162 event_notifier
->priv
->parent
.u
.syscall
.syscall_id
= i
;
1170 int lttng_syscalls_create_matching_event_notifiers(
1171 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
1174 struct lttng_event_enabler_common
*base_enabler
=
1175 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
);
1176 enum lttng_kernel_abi_syscall_entryexit entryexit
=
1177 base_enabler
->event_param
.u
.syscall
.entryexit
;
1179 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1180 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1181 sc_table
.table
, sc_table
.len
, SC_TYPE_ENTRY
);
1185 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1186 compat_sc_table
.table
, compat_sc_table
.len
,
1187 SC_TYPE_COMPAT_ENTRY
);
1191 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1196 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1197 SC_TYPE_COMPAT_ENTRY
);
1202 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1203 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1204 sc_exit_table
.table
, sc_exit_table
.len
,
1209 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1214 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1215 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
1216 SC_TYPE_COMPAT_EXIT
);
1220 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1221 SC_TYPE_COMPAT_EXIT
);
1231 * Unregister the syscall event_notifier probes from the callsites.
1233 int lttng_syscalls_unregister_event_notifier_group(
1234 struct lttng_event_notifier_group
*event_notifier_group
)
1239 * Only register the event_notifier probe on the `sys_enter` callsite for now.
1240 * At the moment, we don't think it's desirable to have one fired
1241 * event_notifier for the entry and one for the exit of a syscall.
1243 if (event_notifier_group
->sys_enter_registered
) {
1244 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1245 (void *) syscall_entry_event_notifier_probe
, event_notifier_group
);
1248 event_notifier_group
->sys_enter_registered
= 0;
1250 if (event_notifier_group
->sys_exit_registered
) {
1251 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1252 (void *) syscall_exit_event_notifier_probe
, event_notifier_group
);
1255 event_notifier_group
->sys_enter_registered
= 0;
1258 kfree(event_notifier_group
->event_notifier_syscall_dispatch
);
1259 kfree(event_notifier_group
->event_notifier_exit_syscall_dispatch
);
1260 #ifdef CONFIG_COMPAT
1261 kfree(event_notifier_group
->event_notifier_compat_syscall_dispatch
);
1262 kfree(event_notifier_group
->event_notifier_exit_compat_syscall_dispatch
);
1267 int lttng_syscalls_unregister_channel(struct lttng_kernel_channel_buffer
*chan
)
1271 if (!chan
->priv
->parent
.sc_table
)
1273 if (chan
->priv
->parent
.sys_enter_registered
) {
1274 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1275 (void *) syscall_entry_event_probe
, chan
);
1278 chan
->priv
->parent
.sys_enter_registered
= 0;
1280 if (chan
->priv
->parent
.sys_exit_registered
) {
1281 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1282 (void *) syscall_exit_event_probe
, chan
);
1285 chan
->priv
->parent
.sys_exit_registered
= 0;
1290 int lttng_syscalls_destroy_event(struct lttng_kernel_channel_buffer
*chan
)
1292 kfree(chan
->priv
->parent
.sc_table
);
1293 kfree(chan
->priv
->parent
.sc_exit_table
);
1294 #ifdef CONFIG_COMPAT
1295 kfree(chan
->priv
->parent
.compat_sc_table
);
1296 kfree(chan
->priv
->parent
.compat_sc_exit_table
);
1298 kfree(chan
->priv
->parent
.sc_filter
);
1303 int get_syscall_nr(const char *syscall_name
)
1305 int syscall_nr
= -1;
1308 for (i
= 0; i
< sc_table
.len
; i
++) {
1309 const struct trace_syscall_entry
*entry
;
1310 const char *it_name
;
1312 entry
= &sc_table
.table
[i
];
1315 it_name
= entry
->desc
->event_name
;
1316 it_name
+= strlen(SYSCALL_ENTRY_STR
);
1317 if (!strcmp(syscall_name
, it_name
)) {
1326 int get_compat_syscall_nr(const char *syscall_name
)
1328 int syscall_nr
= -1;
1331 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
1332 const struct trace_syscall_entry
*entry
;
1333 const char *it_name
;
1335 entry
= &compat_sc_table
.table
[i
];
1338 it_name
= entry
->desc
->event_name
;
1339 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1340 if (!strcmp(syscall_name
, it_name
)) {
1349 uint32_t get_sc_tables_len(void)
1351 return sc_table
.len
+ compat_sc_table
.len
;
1355 const char *get_syscall_name(const char *desc_name
,
1356 enum lttng_syscall_abi abi
,
1357 enum lttng_syscall_entryexit entryexit
)
1359 size_t prefix_len
= 0;
1362 switch (entryexit
) {
1363 case LTTNG_SYSCALL_ENTRY
:
1365 case LTTNG_SYSCALL_ABI_NATIVE
:
1366 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
1368 case LTTNG_SYSCALL_ABI_COMPAT
:
1369 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1373 case LTTNG_SYSCALL_EXIT
:
1375 case LTTNG_SYSCALL_ABI_NATIVE
:
1376 prefix_len
= strlen(SYSCALL_EXIT_STR
);
1378 case LTTNG_SYSCALL_ABI_COMPAT
:
1379 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
1384 WARN_ON_ONCE(prefix_len
== 0);
1385 return desc_name
+ prefix_len
;
1389 int lttng_syscall_filter_enable(
1390 struct lttng_syscall_filter
*filter
,
1391 const char *desc_name
, enum lttng_syscall_abi abi
,
1392 enum lttng_syscall_entryexit entryexit
)
1394 const char *syscall_name
;
1395 unsigned long *bitmap
;
1398 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1401 case LTTNG_SYSCALL_ABI_NATIVE
:
1402 syscall_nr
= get_syscall_nr(syscall_name
);
1404 case LTTNG_SYSCALL_ABI_COMPAT
:
1405 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1413 switch (entryexit
) {
1414 case LTTNG_SYSCALL_ENTRY
:
1416 case LTTNG_SYSCALL_ABI_NATIVE
:
1417 bitmap
= filter
->sc_entry
;
1419 case LTTNG_SYSCALL_ABI_COMPAT
:
1420 bitmap
= filter
->sc_compat_entry
;
1426 case LTTNG_SYSCALL_EXIT
:
1428 case LTTNG_SYSCALL_ABI_NATIVE
:
1429 bitmap
= filter
->sc_exit
;
1431 case LTTNG_SYSCALL_ABI_COMPAT
:
1432 bitmap
= filter
->sc_compat_exit
;
1441 if (test_bit(syscall_nr
, bitmap
))
1443 bitmap_set(bitmap
, syscall_nr
, 1);
1447 int lttng_syscall_filter_enable_event_notifier(
1448 struct lttng_kernel_event_notifier
*event_notifier
)
1450 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1451 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1452 struct hlist_head
*dispatch_list
;
1455 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1457 ret
= lttng_syscall_filter_enable(group
->sc_filter
,
1458 event_notifier
->priv
->parent
.desc
->event_name
,
1459 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1460 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1465 switch (event_notifier
->priv
->parent
.u
.syscall
.entryexit
) {
1466 case LTTNG_SYSCALL_ENTRY
:
1467 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1468 case LTTNG_SYSCALL_ABI_NATIVE
:
1469 dispatch_list
= &group
->event_notifier_syscall_dispatch
[syscall_id
];
1471 case LTTNG_SYSCALL_ABI_COMPAT
:
1472 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[syscall_id
];
1479 case LTTNG_SYSCALL_EXIT
:
1480 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1481 case LTTNG_SYSCALL_ABI_NATIVE
:
1482 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[syscall_id
];
1484 case LTTNG_SYSCALL_ABI_COMPAT
:
1485 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[syscall_id
];
1497 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, dispatch_list
);
1503 int lttng_syscall_filter_enable_event(
1504 struct lttng_kernel_channel_buffer
*channel
,
1505 struct lttng_kernel_event_recorder
*event_recorder
)
1507 WARN_ON_ONCE(event_recorder
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1509 return lttng_syscall_filter_enable(channel
->priv
->parent
.sc_filter
,
1510 event_recorder
->priv
->parent
.desc
->event_name
,
1511 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1512 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1516 int lttng_syscall_filter_disable(
1517 struct lttng_syscall_filter
*filter
,
1518 const char *desc_name
, enum lttng_syscall_abi abi
,
1519 enum lttng_syscall_entryexit entryexit
)
1521 const char *syscall_name
;
1522 unsigned long *bitmap
;
1525 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1528 case LTTNG_SYSCALL_ABI_NATIVE
:
1529 syscall_nr
= get_syscall_nr(syscall_name
);
1531 case LTTNG_SYSCALL_ABI_COMPAT
:
1532 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1540 switch (entryexit
) {
1541 case LTTNG_SYSCALL_ENTRY
:
1543 case LTTNG_SYSCALL_ABI_NATIVE
:
1544 bitmap
= filter
->sc_entry
;
1546 case LTTNG_SYSCALL_ABI_COMPAT
:
1547 bitmap
= filter
->sc_compat_entry
;
1553 case LTTNG_SYSCALL_EXIT
:
1555 case LTTNG_SYSCALL_ABI_NATIVE
:
1556 bitmap
= filter
->sc_exit
;
1558 case LTTNG_SYSCALL_ABI_COMPAT
:
1559 bitmap
= filter
->sc_compat_exit
;
1568 if (!test_bit(syscall_nr
, bitmap
))
1570 bitmap_clear(bitmap
, syscall_nr
, 1);
1575 int lttng_syscall_filter_disable_event_notifier(
1576 struct lttng_kernel_event_notifier
*event_notifier
)
1578 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1581 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1583 ret
= lttng_syscall_filter_disable(group
->sc_filter
,
1584 event_notifier
->priv
->parent
.desc
->event_name
,
1585 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1586 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1587 WARN_ON_ONCE(ret
!= 0);
1589 hlist_del_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
);
1593 int lttng_syscall_filter_disable_event(
1594 struct lttng_kernel_channel_buffer
*channel
,
1595 struct lttng_kernel_event_recorder
*event_recorder
)
1597 return lttng_syscall_filter_disable(channel
->priv
->parent
.sc_filter
,
1598 event_recorder
->priv
->parent
.desc
->event_name
,
1599 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1600 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1604 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1606 const struct trace_syscall_entry
*entry
;
1609 for (entry
= sc_table
.table
;
1610 entry
< sc_table
.table
+ sc_table
.len
;
1615 for (entry
= compat_sc_table
.table
;
1616 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1626 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1628 return (void *) syscall_list_get_entry(pos
);
1632 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1635 return (void *) syscall_list_get_entry(ppos
);
1639 void syscall_list_stop(struct seq_file
*m
, void *p
)
1644 int get_sc_table(const struct trace_syscall_entry
*entry
,
1645 const struct trace_syscall_entry
**table
,
1646 unsigned int *bitness
)
1648 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1650 *bitness
= BITS_PER_LONG
;
1652 *table
= sc_table
.table
;
1655 if (!(entry
>= compat_sc_table
.table
1656 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1662 *table
= compat_sc_table
.table
;
1667 int syscall_list_show(struct seq_file
*m
, void *p
)
1669 const struct trace_syscall_entry
*table
, *entry
= p
;
1670 unsigned int bitness
;
1671 unsigned long index
;
1675 ret
= get_sc_table(entry
, &table
, &bitness
);
1680 if (table
== sc_table
.table
) {
1681 index
= entry
- table
;
1682 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1684 index
= (entry
- table
) + sc_table
.len
;
1685 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1687 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1688 index
, name
, bitness
);
1693 const struct seq_operations lttng_syscall_list_seq_ops
= {
1694 .start
= syscall_list_start
,
1695 .next
= syscall_list_next
,
1696 .stop
= syscall_list_stop
,
1697 .show
= syscall_list_show
,
1701 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1703 return seq_open(file
, <tng_syscall_list_seq_ops
);
1706 const struct file_operations lttng_syscall_list_fops
= {
1707 .owner
= THIS_MODULE
,
1708 .open
= lttng_syscall_list_open
,
1710 .llseek
= seq_lseek
,
1711 .release
= seq_release
,
1715 * A syscall is enabled if it is traced for either entry or exit.
1717 long lttng_channel_syscall_mask(struct lttng_kernel_channel_buffer
*channel
,
1718 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1720 uint32_t len
, sc_tables_len
, bitmask_len
;
1723 struct lttng_syscall_filter
*filter
;
1725 ret
= get_user(len
, &usyscall_mask
->len
);
1728 sc_tables_len
= get_sc_tables_len();
1729 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1730 if (len
< sc_tables_len
) {
1731 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1733 /* Array is large enough, we can copy array to user-space. */
1734 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1737 filter
= channel
->priv
->parent
.sc_filter
;
1739 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1742 if (channel
->priv
->parent
.sc_table
) {
1743 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1744 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1745 state
= test_bit(bit
, filter
->sc_entry
)
1746 || test_bit(bit
, filter
->sc_exit
);
1752 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1754 for (; bit
< sc_tables_len
; bit
++) {
1757 if (channel
->priv
->parent
.compat_sc_table
) {
1758 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1759 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1760 state
= test_bit(bit
- sc_table
.len
,
1761 filter
->sc_compat_entry
)
1762 || test_bit(bit
- sc_table
.len
,
1763 filter
->sc_compat_exit
);
1769 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1771 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1777 int lttng_abi_syscall_list(void)
1779 struct file
*syscall_list_file
;
1782 file_fd
= lttng_get_unused_fd();
1788 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1789 <tng_syscall_list_fops
,
1791 if (IS_ERR(syscall_list_file
)) {
1792 ret
= PTR_ERR(syscall_list_file
);
1795 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1798 fd_install(file_fd
, syscall_list_file
);
1802 fput(syscall_list_file
);
1804 put_unused_fd(file_fd
);