1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <lttng/events.h>
32 #include <lttng/events-internal.h>
33 #include <lttng/utils.h>
35 #include "lttng-syscalls.h"
38 # ifndef is_compat_task
39 # define is_compat_task() (0)
43 /* in_compat_syscall appears in kernel 4.6. */
44 #ifndef in_compat_syscall
45 #define in_compat_syscall() is_compat_task()
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
65 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
66 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
68 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
70 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
74 * Forward declarations for old kernels.
78 struct oldold_utsname
;
80 struct sel_arg_struct
;
81 struct mmap_arg_struct
;
86 * Forward declaration for kernels >= 5.6
93 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
94 typedef __kernel_old_time_t
time_t;
97 #ifdef IA32_NR_syscalls
98 #define NR_compat_syscalls IA32_NR_syscalls
100 #define NR_compat_syscalls NR_syscalls
104 * Create LTTng tracepoint probes.
106 #define LTTNG_PACKAGE_BUILD
107 #define CREATE_TRACE_POINTS
108 #define TP_MODULE_NOINIT
109 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
111 #define PARAMS(args...) args
113 /* Handle unknown syscalls */
115 #define TRACE_SYSTEM syscalls_unknown
116 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
121 extern const struct trace_syscall_table sc_table
;
122 extern const struct trace_syscall_table compat_sc_table
;
124 /* Event syscall exit table */
125 extern const struct trace_syscall_table sc_exit_table
;
126 extern const struct trace_syscall_table compat_sc_exit_table
;
131 #undef CREATE_SYSCALL_TABLE
133 struct lttng_syscall_filter
{
134 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
135 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
136 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
137 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
140 * Reference counters keeping track of number of events enabled
143 u32 sc_entry_refcount_map
[NR_syscalls
];
144 u32 sc_exit_refcount_map
[NR_syscalls
];
145 u32 sc_compat_entry_refcount_map
[NR_compat_syscalls
];
146 u32 sc_compat_exit_refcount_map
[NR_compat_syscalls
];
149 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
150 struct pt_regs
*regs
, long id
)
152 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
153 struct lttng_kernel_event_common_private
*event_priv
;
155 lttng_syscall_get_arguments(current
, regs
, args
);
156 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
157 if (unlikely(in_compat_syscall()))
158 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
160 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
164 static __always_inline
165 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
166 void *func
, unsigned int nrargs
,
167 struct pt_regs
*regs
)
169 struct lttng_kernel_event_common_private
*event_priv
;
174 void (*fptr
)(void *__data
) = func
;
176 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
177 fptr(event_priv
->pub
);
182 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
183 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
185 lttng_syscall_get_arguments(current
, regs
, args
);
186 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
187 fptr(event_priv
->pub
, args
[0]);
192 void (*fptr
)(void *__data
,
194 unsigned long arg1
) = func
;
195 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
197 lttng_syscall_get_arguments(current
, regs
, args
);
198 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
199 fptr(event_priv
->pub
, args
[0], args
[1]);
204 void (*fptr
)(void *__data
,
207 unsigned long arg2
) = func
;
208 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
210 lttng_syscall_get_arguments(current
, regs
, args
);
211 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
212 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
217 void (*fptr
)(void *__data
,
221 unsigned long arg3
) = func
;
222 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
224 lttng_syscall_get_arguments(current
, regs
, args
);
225 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
226 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
231 void (*fptr
)(void *__data
,
236 unsigned long arg4
) = func
;
237 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
239 lttng_syscall_get_arguments(current
, regs
, args
);
240 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
241 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
246 void (*fptr
)(void *__data
,
252 unsigned long arg5
) = func
;
253 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
255 lttng_syscall_get_arguments(current
, regs
, args
);
256 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
257 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
258 args
[3], args
[4], args
[5]);
266 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
268 struct lttng_kernel_channel_buffer
*chan
= __data
;
269 struct hlist_head
*action_list
, *unknown_action_list
;
270 const struct trace_syscall_entry
*table
, *entry
;
273 if (unlikely(in_compat_syscall())) {
274 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
276 if (id
< 0 || id
>= NR_compat_syscalls
277 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
278 /* System call filtered out. */
281 table
= compat_sc_table
.table
;
282 table_len
= compat_sc_table
.len
;
283 unknown_action_list
= &chan
->priv
->parent
.sc_compat_unknown
;
285 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
287 if (id
< 0 || id
>= NR_syscalls
288 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
289 /* System call filtered out. */
292 table
= sc_table
.table
;
293 table_len
= sc_table
.len
;
294 unknown_action_list
= &chan
->priv
->parent
.sc_unknown
;
296 if (unlikely(id
< 0 || id
>= table_len
)) {
297 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
302 if (!entry
->event_func
) {
303 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
307 if (unlikely(in_compat_syscall())) {
308 action_list
= &chan
->priv
->parent
.compat_sc_table
[id
];
310 action_list
= &chan
->priv
->parent
.sc_table
[id
];
312 if (unlikely(hlist_empty(action_list
)))
315 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
318 void syscall_entry_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
321 struct lttng_event_notifier_group
*group
= __data
;
322 const struct trace_syscall_entry
*table
, *entry
;
323 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
326 if (unlikely(in_compat_syscall())) {
327 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
329 if (id
< 0 || id
>= NR_compat_syscalls
330 || (!READ_ONCE(group
->syscall_all_entry
) &&
331 !test_bit(id
, filter
->sc_compat_entry
))) {
332 /* System call filtered out. */
335 table
= compat_sc_table
.table
;
336 table_len
= compat_sc_table
.len
;
337 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
339 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
341 if (id
< 0 || id
>= NR_syscalls
342 || (!READ_ONCE(group
->syscall_all_entry
) &&
343 !test_bit(id
, filter
->sc_entry
))) {
344 /* System call filtered out. */
347 table
= sc_table
.table
;
348 table_len
= sc_table
.len
;
349 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
351 /* Check if the syscall id is out of bound. */
352 if (unlikely(id
< 0 || id
>= table_len
)) {
353 syscall_entry_event_unknown(unknown_dispatch_list
,
359 if (!entry
->event_func
) {
360 syscall_entry_event_unknown(unknown_dispatch_list
,
365 if (unlikely(in_compat_syscall())) {
366 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[id
];
368 dispatch_list
= &group
->event_notifier_syscall_dispatch
[id
];
370 if (unlikely(hlist_empty(dispatch_list
)))
373 syscall_entry_event_call_func(dispatch_list
,
374 entry
->event_func
, entry
->nrargs
, regs
);
377 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
378 struct pt_regs
*regs
, long id
, long ret
)
380 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
381 struct lttng_kernel_event_common_private
*event_priv
;
383 lttng_syscall_get_arguments(current
, regs
, args
);
384 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
385 if (unlikely(in_compat_syscall()))
386 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
389 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
393 static __always_inline
394 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
395 void *func
, unsigned int nrargs
,
396 struct pt_regs
*regs
, long ret
)
398 struct lttng_kernel_event_common_private
*event_priv
;
403 void (*fptr
)(void *__data
, long ret
) = func
;
405 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
406 fptr(event_priv
->pub
, ret
);
411 void (*fptr
)(void *__data
,
413 unsigned long arg0
) = func
;
414 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
416 lttng_syscall_get_arguments(current
, regs
, args
);
417 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
418 fptr(event_priv
->pub
, ret
, args
[0]);
423 void (*fptr
)(void *__data
,
426 unsigned long arg1
) = func
;
427 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
429 lttng_syscall_get_arguments(current
, regs
, args
);
430 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
431 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
436 void (*fptr
)(void *__data
,
440 unsigned long arg2
) = func
;
441 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
443 lttng_syscall_get_arguments(current
, regs
, args
);
444 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
445 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
450 void (*fptr
)(void *__data
,
455 unsigned long arg3
) = func
;
456 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
458 lttng_syscall_get_arguments(current
, regs
, args
);
459 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
460 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
465 void (*fptr
)(void *__data
,
471 unsigned long arg4
) = func
;
472 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
474 lttng_syscall_get_arguments(current
, regs
, args
);
475 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
476 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
481 void (*fptr
)(void *__data
,
488 unsigned long arg5
) = func
;
489 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
491 lttng_syscall_get_arguments(current
, regs
, args
);
492 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
493 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
494 args
[3], args
[4], args
[5]);
502 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
504 struct lttng_kernel_channel_buffer
*chan
= __data
;
505 struct hlist_head
*action_list
, *unknown_action_list
;
506 const struct trace_syscall_entry
*table
, *entry
;
510 id
= syscall_get_nr(current
, regs
);
512 if (unlikely(in_compat_syscall())) {
513 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
515 if (id
< 0 || id
>= NR_compat_syscalls
516 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
517 /* System call filtered out. */
520 table
= compat_sc_exit_table
.table
;
521 table_len
= compat_sc_exit_table
.len
;
522 unknown_action_list
= &chan
->priv
->parent
.compat_sc_exit_unknown
;
524 struct lttng_syscall_filter
*filter
= chan
->priv
->parent
.sc_filter
;
526 if (id
< 0 || id
>= NR_syscalls
527 || (!READ_ONCE(chan
->priv
->parent
.syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
528 /* System call filtered out. */
531 table
= sc_exit_table
.table
;
532 table_len
= sc_exit_table
.len
;
533 unknown_action_list
= &chan
->priv
->parent
.sc_exit_unknown
;
535 if (unlikely(id
< 0 || id
>= table_len
)) {
536 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
541 if (!entry
->event_func
) {
542 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
546 if (unlikely(in_compat_syscall())) {
547 action_list
= &chan
->priv
->parent
.compat_sc_exit_table
[id
];
549 action_list
= &chan
->priv
->parent
.sc_exit_table
[id
];
551 if (unlikely(hlist_empty(action_list
)))
554 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
558 void syscall_exit_event_notifier_probe(void *__data
, struct pt_regs
*regs
,
561 struct lttng_event_notifier_group
*group
= __data
;
562 const struct trace_syscall_entry
*table
, *entry
;
563 struct hlist_head
*dispatch_list
, *unknown_dispatch_list
;
567 id
= syscall_get_nr(current
, regs
);
569 if (unlikely(in_compat_syscall())) {
570 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
572 if (id
< 0 || id
>= NR_compat_syscalls
573 || (!READ_ONCE(group
->syscall_all_exit
) &&
574 !test_bit(id
, filter
->sc_compat_exit
))) {
575 /* System call filtered out. */
578 table
= compat_sc_exit_table
.table
;
579 table_len
= compat_sc_exit_table
.len
;
580 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
582 struct lttng_syscall_filter
*filter
= group
->sc_filter
;
584 if (id
< 0 || id
>= NR_syscalls
585 || (!READ_ONCE(group
->syscall_all_exit
) &&
586 !test_bit(id
, filter
->sc_exit
))) {
587 /* System call filtered out. */
590 table
= sc_exit_table
.table
;
591 table_len
= sc_exit_table
.len
;
592 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
594 /* Check if the syscall id is out of bound. */
595 if (unlikely(id
< 0 || id
>= table_len
)) {
596 syscall_exit_event_unknown(unknown_dispatch_list
,
602 if (!entry
->event_func
) {
603 syscall_entry_event_unknown(unknown_dispatch_list
,
608 if (unlikely(in_compat_syscall())) {
609 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[id
];
611 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[id
];
613 if (unlikely(hlist_empty(dispatch_list
)))
616 syscall_exit_event_call_func(dispatch_list
,
617 entry
->event_func
, entry
->nrargs
, regs
, ret
);
620 * noinline to diminish caller stack size.
621 * Should be called with sessions lock held.
624 int lttng_create_syscall_event_if_missing(const struct trace_syscall_entry
*table
, size_t table_len
,
625 struct hlist_head
*chan_table
, struct lttng_event_enabler
*event_enabler
,
628 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
629 struct lttng_kernel_session
*session
= chan
->parent
.session
;
632 /* Allocate events for each syscall matching enabler, insert into table */
633 for (i
= 0; i
< table_len
; i
++) {
634 const struct lttng_kernel_event_desc
*desc
= table
[i
].desc
;
635 struct lttng_kernel_abi_event ev
;
636 struct lttng_kernel_event_recorder_private
*event_recorder_priv
;
637 struct lttng_kernel_event_recorder
*event_recorder
;
638 struct hlist_head
*head
;
642 /* Unknown syscall */
645 if (lttng_desc_match_enabler(desc
,
646 lttng_event_enabler_as_enabler(event_enabler
)) <= 0)
649 * Check if already created.
651 head
= utils_borrow_hash_table_bucket(
652 session
->priv
->events_ht
.table
, LTTNG_EVENT_HT_SIZE
,
654 lttng_hlist_for_each_entry(event_recorder_priv
, head
, hlist
) {
655 if (event_recorder_priv
->parent
.desc
== desc
656 && event_recorder_priv
->pub
->chan
== event_enabler
->chan
)
662 /* We need to create an event for this syscall/enabler. */
663 memset(&ev
, 0, sizeof(ev
));
666 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
667 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
670 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
671 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
673 case SC_TYPE_COMPAT_ENTRY
:
674 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
675 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
677 case SC_TYPE_COMPAT_EXIT
:
678 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
679 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
682 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
683 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
684 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
685 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
, ev
.instrumentation
);
686 WARN_ON_ONCE(!event_recorder
);
687 if (IS_ERR(event_recorder
)) {
689 * If something goes wrong in event registration
690 * after the first one, we have no choice but to
691 * leave the previous events in there, until
692 * deleted by session teardown.
694 return PTR_ERR(event_recorder
);
696 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan_table
[i
]);
702 * Should be called with sessions lock held.
704 int lttng_syscalls_register_event(struct lttng_event_enabler
*event_enabler
)
706 struct lttng_kernel_channel_buffer
*chan
= event_enabler
->chan
;
707 struct lttng_kernel_abi_event ev
;
710 wrapper_vmalloc_sync_mappings();
712 if (!chan
->priv
->parent
.sc_table
) {
713 /* create syscall table mapping syscall to events */
714 chan
->priv
->parent
.sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
715 * sc_table
.len
, GFP_KERNEL
);
716 if (!chan
->priv
->parent
.sc_table
)
719 if (!chan
->priv
->parent
.sc_exit_table
) {
720 /* create syscall table mapping syscall to events */
721 chan
->priv
->parent
.sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
722 * sc_exit_table
.len
, GFP_KERNEL
);
723 if (!chan
->priv
->parent
.sc_exit_table
)
729 if (!chan
->priv
->parent
.compat_sc_table
) {
730 /* create syscall table mapping compat syscall to events */
731 chan
->priv
->parent
.compat_sc_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
732 * compat_sc_table
.len
, GFP_KERNEL
);
733 if (!chan
->priv
->parent
.compat_sc_table
)
737 if (!chan
->priv
->parent
.compat_sc_exit_table
) {
738 /* create syscall table mapping compat syscall to events */
739 chan
->priv
->parent
.compat_sc_exit_table
= kzalloc(sizeof(struct lttng_kernel_event_recorder
*)
740 * compat_sc_exit_table
.len
, GFP_KERNEL
);
741 if (!chan
->priv
->parent
.compat_sc_exit_table
)
745 if (hlist_empty(&chan
->priv
->parent
.sc_unknown
)) {
746 const struct lttng_kernel_event_desc
*desc
=
747 &__event_desc___syscall_entry_unknown
;
748 struct lttng_kernel_event_recorder
*event_recorder
;
750 memset(&ev
, 0, sizeof(ev
));
751 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
752 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
753 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
754 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
755 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
756 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
758 WARN_ON_ONCE(!event_recorder
);
759 if (IS_ERR(event_recorder
)) {
760 return PTR_ERR(event_recorder
);
762 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_unknown
);
765 if (hlist_empty(&chan
->priv
->parent
.sc_compat_unknown
)) {
766 const struct lttng_kernel_event_desc
*desc
=
767 &__event_desc___compat_syscall_entry_unknown
;
768 struct lttng_kernel_event_recorder
*event_recorder
;
770 memset(&ev
, 0, sizeof(ev
));
771 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
772 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
773 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
774 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
775 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
776 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
778 WARN_ON_ONCE(!event_recorder
);
779 if (IS_ERR(event_recorder
)) {
780 return PTR_ERR(event_recorder
);
782 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_compat_unknown
);
785 if (hlist_empty(&chan
->priv
->parent
.compat_sc_exit_unknown
)) {
786 const struct lttng_kernel_event_desc
*desc
=
787 &__event_desc___compat_syscall_exit_unknown
;
788 struct lttng_kernel_event_recorder
*event_recorder
;
790 memset(&ev
, 0, sizeof(ev
));
791 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
792 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
793 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
794 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
795 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
796 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
798 WARN_ON_ONCE(!event_recorder
);
799 if (IS_ERR(event_recorder
)) {
800 return PTR_ERR(event_recorder
);
802 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.compat_sc_exit_unknown
);
805 if (hlist_empty(&chan
->priv
->parent
.sc_exit_unknown
)) {
806 const struct lttng_kernel_event_desc
*desc
=
807 &__event_desc___syscall_exit_unknown
;
808 struct lttng_kernel_event_recorder
*event_recorder
;
810 memset(&ev
, 0, sizeof(ev
));
811 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
);
812 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
813 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
814 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
815 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
816 event_recorder
= _lttng_kernel_event_recorder_create(chan
, &ev
, desc
,
818 WARN_ON_ONCE(!event_recorder
);
819 if (IS_ERR(event_recorder
)) {
820 return PTR_ERR(event_recorder
);
822 hlist_add_head(&event_recorder
->priv
->parent
.u
.syscall
.node
, &chan
->priv
->parent
.sc_exit_unknown
);
825 ret
= lttng_create_syscall_event_if_missing(sc_table
.table
, sc_table
.len
,
826 chan
->priv
->parent
.sc_table
, event_enabler
, SC_TYPE_ENTRY
);
829 ret
= lttng_create_syscall_event_if_missing(sc_exit_table
.table
, sc_exit_table
.len
,
830 chan
->priv
->parent
.sc_exit_table
, event_enabler
, SC_TYPE_EXIT
);
835 ret
= lttng_create_syscall_event_if_missing(compat_sc_table
.table
, compat_sc_table
.len
,
836 chan
->priv
->parent
.compat_sc_table
, event_enabler
, SC_TYPE_COMPAT_ENTRY
);
839 ret
= lttng_create_syscall_event_if_missing(compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
840 chan
->priv
->parent
.compat_sc_exit_table
, event_enabler
, SC_TYPE_COMPAT_EXIT
);
845 if (!chan
->priv
->parent
.sc_filter
) {
846 chan
->priv
->parent
.sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
848 if (!chan
->priv
->parent
.sc_filter
)
852 if (!chan
->priv
->parent
.sys_enter_registered
) {
853 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
854 (void *) syscall_entry_event_probe
, chan
);
857 chan
->priv
->parent
.sys_enter_registered
= 1;
860 * We change the name of sys_exit tracepoint due to namespace
861 * conflict with sys_exit syscall entry.
863 if (!chan
->priv
->parent
.sys_exit_registered
) {
864 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
865 (void *) syscall_exit_event_probe
, chan
);
867 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
868 (void *) syscall_entry_event_probe
, chan
));
871 chan
->priv
->parent
.sys_exit_registered
= 1;
877 * Should be called with sessions lock held.
879 int lttng_syscalls_register_event_notifier(
880 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
882 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
886 wrapper_vmalloc_sync_mappings();
888 if (!group
->event_notifier_syscall_dispatch
) {
889 group
->event_notifier_syscall_dispatch
=
890 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
892 if (!group
->event_notifier_syscall_dispatch
)
895 /* Initialize all list_head */
896 for (i
= 0; i
< sc_table
.len
; i
++)
897 INIT_HLIST_HEAD(&group
->event_notifier_syscall_dispatch
[i
]);
899 /* Init the unknown syscall notifier list. */
900 INIT_HLIST_HEAD(&group
->event_notifier_unknown_syscall_dispatch
);
903 if (!group
->event_notifier_exit_syscall_dispatch
) {
904 group
->event_notifier_exit_syscall_dispatch
=
905 kzalloc(sizeof(struct hlist_head
) * sc_table
.len
,
907 if (!group
->event_notifier_exit_syscall_dispatch
)
910 /* Initialize all list_head */
911 for (i
= 0; i
< sc_table
.len
; i
++)
912 INIT_HLIST_HEAD(&group
->event_notifier_exit_syscall_dispatch
[i
]);
914 /* Init the unknown exit syscall notifier list. */
915 INIT_HLIST_HEAD(&group
->event_notifier_exit_unknown_syscall_dispatch
);
919 if (!group
->event_notifier_compat_syscall_dispatch
) {
920 group
->event_notifier_compat_syscall_dispatch
=
921 kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
,
923 if (!group
->event_notifier_syscall_dispatch
)
926 /* Initialize all list_head */
927 for (i
= 0; i
< compat_sc_table
.len
; i
++)
928 INIT_HLIST_HEAD(&group
->event_notifier_compat_syscall_dispatch
[i
]);
930 /* Init the unknown syscall notifier list. */
931 INIT_HLIST_HEAD(&group
->event_notifier_compat_unknown_syscall_dispatch
);
934 if (!group
->event_notifier_exit_compat_syscall_dispatch
) {
935 group
->event_notifier_exit_compat_syscall_dispatch
=
936 kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
,
938 if (!group
->event_notifier_exit_syscall_dispatch
)
941 /* Initialize all list_head */
942 for (i
= 0; i
< compat_sc_exit_table
.len
; i
++)
943 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_syscall_dispatch
[i
]);
945 /* Init the unknown exit syscall notifier list. */
946 INIT_HLIST_HEAD(&group
->event_notifier_exit_compat_unknown_syscall_dispatch
);
950 if (!group
->sc_filter
) {
951 group
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
953 if (!group
->sc_filter
)
957 if (!group
->sys_enter_registered
) {
958 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
959 (void *) syscall_entry_event_notifier_probe
, group
);
962 group
->sys_enter_registered
= 1;
965 if (!group
->sys_exit_registered
) {
966 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
967 (void *) syscall_exit_event_notifier_probe
, group
);
969 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
970 (void *) syscall_entry_event_notifier_probe
, group
));
973 group
->sys_exit_registered
= 1;
980 int create_unknown_event_notifier(
981 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
984 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
985 struct lttng_kernel_event_notifier
*event_notifier
;
986 const struct lttng_kernel_event_desc
*desc
;
987 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
988 struct lttng_kernel_abi_event_notifier event_notifier_param
;
989 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
990 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
991 struct lttng_enabler
*base_enabler
= lttng_event_notifier_enabler_as_enabler(
992 event_notifier_enabler
);
993 struct hlist_head
*unknown_dispatch_list
;
996 enum lttng_kernel_abi_syscall_abi abi
;
997 enum lttng_kernel_abi_syscall_entryexit entryexit
;
998 struct hlist_head
*head
;
1002 desc
= &__event_desc___syscall_entry_unknown
;
1003 unknown_dispatch_list
= &group
->event_notifier_unknown_syscall_dispatch
;
1004 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1005 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1008 desc
= &__event_desc___syscall_exit_unknown
;
1009 unknown_dispatch_list
= &group
->event_notifier_exit_unknown_syscall_dispatch
;
1010 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1011 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1013 case SC_TYPE_COMPAT_ENTRY
:
1014 desc
= &__event_desc___compat_syscall_entry_unknown
;
1015 unknown_dispatch_list
= &group
->event_notifier_compat_unknown_syscall_dispatch
;
1016 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1017 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1019 case SC_TYPE_COMPAT_EXIT
:
1020 desc
= &__event_desc___compat_syscall_exit_unknown
;
1021 unknown_dispatch_list
= &group
->event_notifier_exit_compat_unknown_syscall_dispatch
;
1022 entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1023 abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1030 * Check if already created.
1032 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1033 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1034 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1035 if (event_notifier_priv
->parent
.desc
== desc
&&
1036 event_notifier_priv
->parent
.user_token
== base_enabler
->user_token
)
1042 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1043 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1044 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1046 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1048 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1049 event_notifier_param
.event
.u
.syscall
.abi
= abi
;
1050 event_notifier_param
.event
.u
.syscall
.entryexit
= entryexit
;
1052 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1053 error_counter_index
, group
, &event_notifier_param
,
1054 event_notifier_param
.event
.instrumentation
);
1055 if (IS_ERR(event_notifier
)) {
1056 printk(KERN_INFO
"Unable to create unknown notifier %s\n",
1062 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, unknown_dispatch_list
);
1068 static int create_matching_event_notifiers(
1069 struct lttng_event_notifier_enabler
*event_notifier_enabler
,
1070 const struct trace_syscall_entry
*table
,
1071 size_t table_len
, enum sc_type type
)
1073 struct lttng_event_notifier_group
*group
= event_notifier_enabler
->group
;
1074 const struct lttng_kernel_event_desc
*desc
;
1075 uint64_t user_token
= event_notifier_enabler
->base
.user_token
;
1076 uint64_t error_counter_index
= event_notifier_enabler
->error_counter_index
;
1080 /* iterate over all syscall and create event_notifier that match */
1081 for (i
= 0; i
< table_len
; i
++) {
1082 struct lttng_kernel_event_notifier_private
*event_notifier_priv
;
1083 struct lttng_kernel_event_notifier
*event_notifier
;
1084 struct lttng_kernel_abi_event_notifier event_notifier_param
;
1085 struct hlist_head
*head
;
1088 desc
= table
[i
].desc
;
1090 /* Unknown syscall */
1094 if (!lttng_desc_match_enabler(desc
,
1095 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
)))
1099 * Check if already created.
1101 head
= utils_borrow_hash_table_bucket(group
->event_notifiers_ht
.table
,
1102 LTTNG_EVENT_NOTIFIER_HT_SIZE
, desc
->event_name
);
1103 lttng_hlist_for_each_entry(event_notifier_priv
, head
, hlist
) {
1104 if (event_notifier_priv
->parent
.desc
== desc
1105 && event_notifier_priv
->parent
.user_token
== event_notifier_enabler
->base
.user_token
)
1111 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
1114 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1115 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1118 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1119 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
1121 case SC_TYPE_COMPAT_ENTRY
:
1122 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
1123 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1125 case SC_TYPE_COMPAT_EXIT
:
1126 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
1127 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
1130 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
1131 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
1132 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
1133 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
1135 event_notifier
= _lttng_event_notifier_create(desc
, user_token
,
1136 error_counter_index
, group
, &event_notifier_param
,
1137 event_notifier_param
.event
.instrumentation
);
1138 if (IS_ERR(event_notifier
)) {
1139 printk(KERN_INFO
"Unable to create event_notifier %s\n",
1145 event_notifier
->priv
->parent
.u
.syscall
.syscall_id
= i
;
1153 int lttng_syscalls_create_matching_event_notifiers(
1154 struct lttng_event_notifier_enabler
*event_notifier_enabler
)
1157 struct lttng_enabler
*base_enabler
=
1158 lttng_event_notifier_enabler_as_enabler(event_notifier_enabler
);
1159 enum lttng_kernel_abi_syscall_entryexit entryexit
=
1160 base_enabler
->event_param
.u
.syscall
.entryexit
;
1162 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1163 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1164 sc_table
.table
, sc_table
.len
, SC_TYPE_ENTRY
);
1168 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1169 compat_sc_table
.table
, compat_sc_table
.len
,
1170 SC_TYPE_COMPAT_ENTRY
);
1174 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1179 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1180 SC_TYPE_COMPAT_ENTRY
);
1185 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
1186 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1187 sc_exit_table
.table
, sc_exit_table
.len
,
1192 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1197 ret
= create_matching_event_notifiers(event_notifier_enabler
,
1198 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
1199 SC_TYPE_COMPAT_EXIT
);
1203 ret
= create_unknown_event_notifier(event_notifier_enabler
,
1204 SC_TYPE_COMPAT_EXIT
);
1214 * Unregister the syscall event_notifier probes from the callsites.
1216 int lttng_syscalls_unregister_event_notifier_group(
1217 struct lttng_event_notifier_group
*event_notifier_group
)
1222 * Only register the event_notifier probe on the `sys_enter` callsite for now.
1223 * At the moment, we don't think it's desirable to have one fired
1224 * event_notifier for the entry and one for the exit of a syscall.
1226 if (event_notifier_group
->sys_enter_registered
) {
1227 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1228 (void *) syscall_entry_event_notifier_probe
, event_notifier_group
);
1231 event_notifier_group
->sys_enter_registered
= 0;
1233 if (event_notifier_group
->sys_exit_registered
) {
1234 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1235 (void *) syscall_exit_event_notifier_probe
, event_notifier_group
);
1238 event_notifier_group
->sys_enter_registered
= 0;
1241 kfree(event_notifier_group
->event_notifier_syscall_dispatch
);
1242 kfree(event_notifier_group
->event_notifier_exit_syscall_dispatch
);
1243 #ifdef CONFIG_COMPAT
1244 kfree(event_notifier_group
->event_notifier_compat_syscall_dispatch
);
1245 kfree(event_notifier_group
->event_notifier_exit_compat_syscall_dispatch
);
1250 int lttng_syscalls_unregister_channel(struct lttng_kernel_channel_buffer
*chan
)
1254 if (!chan
->priv
->parent
.sc_table
)
1256 if (chan
->priv
->parent
.sys_enter_registered
) {
1257 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
1258 (void *) syscall_entry_event_probe
, chan
);
1261 chan
->priv
->parent
.sys_enter_registered
= 0;
1263 if (chan
->priv
->parent
.sys_exit_registered
) {
1264 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
1265 (void *) syscall_exit_event_probe
, chan
);
1268 chan
->priv
->parent
.sys_exit_registered
= 0;
1273 int lttng_syscalls_destroy_event(struct lttng_kernel_channel_buffer
*chan
)
1275 kfree(chan
->priv
->parent
.sc_table
);
1276 kfree(chan
->priv
->parent
.sc_exit_table
);
1277 #ifdef CONFIG_COMPAT
1278 kfree(chan
->priv
->parent
.compat_sc_table
);
1279 kfree(chan
->priv
->parent
.compat_sc_exit_table
);
1281 kfree(chan
->priv
->parent
.sc_filter
);
1286 int get_syscall_nr(const char *syscall_name
)
1288 int syscall_nr
= -1;
1291 for (i
= 0; i
< sc_table
.len
; i
++) {
1292 const struct trace_syscall_entry
*entry
;
1293 const char *it_name
;
1295 entry
= &sc_table
.table
[i
];
1298 it_name
= entry
->desc
->event_name
;
1299 it_name
+= strlen(SYSCALL_ENTRY_STR
);
1300 if (!strcmp(syscall_name
, it_name
)) {
1309 int get_compat_syscall_nr(const char *syscall_name
)
1311 int syscall_nr
= -1;
1314 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
1315 const struct trace_syscall_entry
*entry
;
1316 const char *it_name
;
1318 entry
= &compat_sc_table
.table
[i
];
1321 it_name
= entry
->desc
->event_name
;
1322 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1323 if (!strcmp(syscall_name
, it_name
)) {
1332 uint32_t get_sc_tables_len(void)
1334 return sc_table
.len
+ compat_sc_table
.len
;
1338 const char *get_syscall_name(const char *desc_name
,
1339 enum lttng_syscall_abi abi
,
1340 enum lttng_syscall_entryexit entryexit
)
1342 size_t prefix_len
= 0;
1345 switch (entryexit
) {
1346 case LTTNG_SYSCALL_ENTRY
:
1348 case LTTNG_SYSCALL_ABI_NATIVE
:
1349 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
1351 case LTTNG_SYSCALL_ABI_COMPAT
:
1352 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
1356 case LTTNG_SYSCALL_EXIT
:
1358 case LTTNG_SYSCALL_ABI_NATIVE
:
1359 prefix_len
= strlen(SYSCALL_EXIT_STR
);
1361 case LTTNG_SYSCALL_ABI_COMPAT
:
1362 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
1367 WARN_ON_ONCE(prefix_len
== 0);
1368 return desc_name
+ prefix_len
;
1372 int lttng_syscall_filter_enable(
1373 struct lttng_syscall_filter
*filter
,
1374 const char *desc_name
, enum lttng_syscall_abi abi
,
1375 enum lttng_syscall_entryexit entryexit
)
1377 const char *syscall_name
;
1378 unsigned long *bitmap
;
1382 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1385 case LTTNG_SYSCALL_ABI_NATIVE
:
1386 syscall_nr
= get_syscall_nr(syscall_name
);
1388 case LTTNG_SYSCALL_ABI_COMPAT
:
1389 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1397 switch (entryexit
) {
1398 case LTTNG_SYSCALL_ENTRY
:
1400 case LTTNG_SYSCALL_ABI_NATIVE
:
1401 bitmap
= filter
->sc_entry
;
1402 refcount_map
= filter
->sc_entry_refcount_map
;
1404 case LTTNG_SYSCALL_ABI_COMPAT
:
1405 bitmap
= filter
->sc_compat_entry
;
1406 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1412 case LTTNG_SYSCALL_EXIT
:
1414 case LTTNG_SYSCALL_ABI_NATIVE
:
1415 bitmap
= filter
->sc_exit
;
1416 refcount_map
= filter
->sc_exit_refcount_map
;
1418 case LTTNG_SYSCALL_ABI_COMPAT
:
1419 bitmap
= filter
->sc_compat_exit
;
1420 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1429 if (refcount_map
[syscall_nr
] == U32_MAX
)
1431 if (refcount_map
[syscall_nr
]++ == 0)
1432 bitmap_set(bitmap
, syscall_nr
, 1);
1436 int lttng_syscall_filter_enable_event_notifier(
1437 struct lttng_kernel_event_notifier
*event_notifier
)
1439 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1440 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1441 struct hlist_head
*dispatch_list
;
1444 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1446 /* Skip unknown syscall */
1447 if (syscall_id
== -1U)
1450 ret
= lttng_syscall_filter_enable(group
->sc_filter
,
1451 event_notifier
->priv
->parent
.desc
->event_name
,
1452 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1453 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1457 switch (event_notifier
->priv
->parent
.u
.syscall
.entryexit
) {
1458 case LTTNG_SYSCALL_ENTRY
:
1459 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1460 case LTTNG_SYSCALL_ABI_NATIVE
:
1461 dispatch_list
= &group
->event_notifier_syscall_dispatch
[syscall_id
];
1463 case LTTNG_SYSCALL_ABI_COMPAT
:
1464 dispatch_list
= &group
->event_notifier_compat_syscall_dispatch
[syscall_id
];
1471 case LTTNG_SYSCALL_EXIT
:
1472 switch (event_notifier
->priv
->parent
.u
.syscall
.abi
) {
1473 case LTTNG_SYSCALL_ABI_NATIVE
:
1474 dispatch_list
= &group
->event_notifier_exit_syscall_dispatch
[syscall_id
];
1476 case LTTNG_SYSCALL_ABI_COMPAT
:
1477 dispatch_list
= &group
->event_notifier_exit_compat_syscall_dispatch
[syscall_id
];
1489 hlist_add_head_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
, dispatch_list
);
1495 int lttng_syscall_filter_enable_event(
1496 struct lttng_kernel_channel_buffer
*channel
,
1497 struct lttng_kernel_event_recorder
*event_recorder
)
1499 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1501 WARN_ON_ONCE(event_recorder
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1503 /* Skip unknown syscall */
1504 if (syscall_id
== -1U)
1507 return lttng_syscall_filter_enable(channel
->priv
->parent
.sc_filter
,
1508 event_recorder
->priv
->parent
.desc
->event_name
,
1509 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1510 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1514 int lttng_syscall_filter_disable(
1515 struct lttng_syscall_filter
*filter
,
1516 const char *desc_name
, enum lttng_syscall_abi abi
,
1517 enum lttng_syscall_entryexit entryexit
)
1519 const char *syscall_name
;
1520 unsigned long *bitmap
;
1524 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1527 case LTTNG_SYSCALL_ABI_NATIVE
:
1528 syscall_nr
= get_syscall_nr(syscall_name
);
1530 case LTTNG_SYSCALL_ABI_COMPAT
:
1531 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1539 switch (entryexit
) {
1540 case LTTNG_SYSCALL_ENTRY
:
1542 case LTTNG_SYSCALL_ABI_NATIVE
:
1543 bitmap
= filter
->sc_entry
;
1544 refcount_map
= filter
->sc_entry_refcount_map
;
1546 case LTTNG_SYSCALL_ABI_COMPAT
:
1547 bitmap
= filter
->sc_compat_entry
;
1548 refcount_map
= filter
->sc_compat_entry_refcount_map
;
1554 case LTTNG_SYSCALL_EXIT
:
1556 case LTTNG_SYSCALL_ABI_NATIVE
:
1557 bitmap
= filter
->sc_exit
;
1558 refcount_map
= filter
->sc_exit_refcount_map
;
1560 case LTTNG_SYSCALL_ABI_COMPAT
:
1561 bitmap
= filter
->sc_compat_exit
;
1562 refcount_map
= filter
->sc_compat_exit_refcount_map
;
1571 if (refcount_map
[syscall_nr
] == 0)
1573 if (--refcount_map
[syscall_nr
] == 0)
1574 bitmap_clear(bitmap
, syscall_nr
, 1);
1578 int lttng_syscall_filter_disable_event_notifier(
1579 struct lttng_kernel_event_notifier
*event_notifier
)
1581 struct lttng_event_notifier_group
*group
= event_notifier
->priv
->group
;
1582 unsigned int syscall_id
= event_notifier
->priv
->parent
.u
.syscall
.syscall_id
;
1585 WARN_ON_ONCE(event_notifier
->priv
->parent
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1587 /* Skip unknown syscall */
1588 if (syscall_id
== -1U)
1591 ret
= lttng_syscall_filter_disable(group
->sc_filter
,
1592 event_notifier
->priv
->parent
.desc
->event_name
,
1593 event_notifier
->priv
->parent
.u
.syscall
.abi
,
1594 event_notifier
->priv
->parent
.u
.syscall
.entryexit
);
1598 hlist_del_rcu(&event_notifier
->priv
->parent
.u
.syscall
.node
);
1602 int lttng_syscall_filter_disable_event(
1603 struct lttng_kernel_channel_buffer
*channel
,
1604 struct lttng_kernel_event_recorder
*event_recorder
)
1606 unsigned int syscall_id
= event_recorder
->priv
->parent
.u
.syscall
.syscall_id
;
1608 /* Skip unknown syscall */
1609 if (syscall_id
== -1U)
1612 return lttng_syscall_filter_disable(channel
->priv
->parent
.sc_filter
,
1613 event_recorder
->priv
->parent
.desc
->event_name
,
1614 event_recorder
->priv
->parent
.u
.syscall
.abi
,
1615 event_recorder
->priv
->parent
.u
.syscall
.entryexit
);
1619 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1621 const struct trace_syscall_entry
*entry
;
1624 for (entry
= sc_table
.table
;
1625 entry
< sc_table
.table
+ sc_table
.len
;
1630 for (entry
= compat_sc_table
.table
;
1631 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1641 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1643 return (void *) syscall_list_get_entry(pos
);
1647 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1650 return (void *) syscall_list_get_entry(ppos
);
1654 void syscall_list_stop(struct seq_file
*m
, void *p
)
1659 int get_sc_table(const struct trace_syscall_entry
*entry
,
1660 const struct trace_syscall_entry
**table
,
1661 unsigned int *bitness
)
1663 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1665 *bitness
= BITS_PER_LONG
;
1667 *table
= sc_table
.table
;
1670 if (!(entry
>= compat_sc_table
.table
1671 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1677 *table
= compat_sc_table
.table
;
1682 int syscall_list_show(struct seq_file
*m
, void *p
)
1684 const struct trace_syscall_entry
*table
, *entry
= p
;
1685 unsigned int bitness
;
1686 unsigned long index
;
1690 ret
= get_sc_table(entry
, &table
, &bitness
);
1695 if (table
== sc_table
.table
) {
1696 index
= entry
- table
;
1697 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1699 index
= (entry
- table
) + sc_table
.len
;
1700 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1702 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1703 index
, name
, bitness
);
1708 const struct seq_operations lttng_syscall_list_seq_ops
= {
1709 .start
= syscall_list_start
,
1710 .next
= syscall_list_next
,
1711 .stop
= syscall_list_stop
,
1712 .show
= syscall_list_show
,
1716 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1718 return seq_open(file
, <tng_syscall_list_seq_ops
);
1721 const struct file_operations lttng_syscall_list_fops
= {
1722 .owner
= THIS_MODULE
,
1723 .open
= lttng_syscall_list_open
,
1725 .llseek
= seq_lseek
,
1726 .release
= seq_release
,
1730 * A syscall is enabled if it is traced for either entry or exit.
1732 long lttng_channel_syscall_mask(struct lttng_kernel_channel_buffer
*channel
,
1733 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1735 uint32_t len
, sc_tables_len
, bitmask_len
;
1738 struct lttng_syscall_filter
*filter
;
1740 ret
= get_user(len
, &usyscall_mask
->len
);
1743 sc_tables_len
= get_sc_tables_len();
1744 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1745 if (len
< sc_tables_len
) {
1746 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1748 /* Array is large enough, we can copy array to user-space. */
1749 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1752 filter
= channel
->priv
->parent
.sc_filter
;
1754 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1757 if (channel
->priv
->parent
.sc_table
) {
1758 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1759 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1760 state
= test_bit(bit
, filter
->sc_entry
)
1761 || test_bit(bit
, filter
->sc_exit
);
1767 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1769 for (; bit
< sc_tables_len
; bit
++) {
1772 if (channel
->priv
->parent
.compat_sc_table
) {
1773 if (!(READ_ONCE(channel
->priv
->parent
.syscall_all_entry
)
1774 || READ_ONCE(channel
->priv
->parent
.syscall_all_exit
)) && filter
)
1775 state
= test_bit(bit
- sc_table
.len
,
1776 filter
->sc_compat_entry
)
1777 || test_bit(bit
- sc_table
.len
,
1778 filter
->sc_compat_exit
);
1784 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1786 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1792 int lttng_abi_syscall_list(void)
1794 struct file
*syscall_list_file
;
1797 file_fd
= lttng_get_unused_fd();
1803 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1804 <tng_syscall_list_fops
,
1806 if (IS_ERR(syscall_list_file
)) {
1807 ret
= PTR_ERR(syscall_list_file
);
1810 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1813 fd_install(file_fd
, syscall_list_file
);
1817 fput(syscall_list_file
);
1819 put_unused_fd(file_fd
);