1 /* SPDX-License-Identifier: (GPL-2.0-only or LGPL-2.1-only)
5 * LTTng syscall probes.
7 * Copyright (C) 2010-2012 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
10 #include <linux/module.h>
11 #include <linux/slab.h>
12 #include <linux/compat.h>
13 #include <linux/err.h>
14 #include <linux/bitmap.h>
16 #include <linux/in6.h>
17 #include <linux/seq_file.h>
18 #include <linux/stringify.h>
19 #include <linux/file.h>
20 #include <linux/anon_inodes.h>
21 #include <linux/fcntl.h>
22 #include <linux/mman.h>
23 #include <asm/ptrace.h>
24 #include <asm/syscall.h>
26 #include <lttng/bitfield.h>
27 #include <wrapper/tracepoint.h>
28 #include <wrapper/file.h>
29 #include <wrapper/rcu.h>
30 #include <wrapper/syscall.h>
31 #include <lttng/events.h>
32 #include <lttng/events-internal.h>
33 #include <lttng/utils.h>
35 #include "lttng-syscalls.h"
38 # ifndef is_compat_task
39 # define is_compat_task() (0)
43 /* in_compat_syscall appears in kernel 4.6. */
44 #ifndef in_compat_syscall
45 #define in_compat_syscall() is_compat_task()
55 #define SYSCALL_ENTRY_TOK syscall_entry_
56 #define COMPAT_SYSCALL_ENTRY_TOK compat_syscall_entry_
57 #define SYSCALL_EXIT_TOK syscall_exit_
58 #define COMPAT_SYSCALL_EXIT_TOK compat_syscall_exit_
60 #define SYSCALL_ENTRY_STR __stringify(SYSCALL_ENTRY_TOK)
61 #define COMPAT_SYSCALL_ENTRY_STR __stringify(COMPAT_SYSCALL_ENTRY_TOK)
62 #define SYSCALL_EXIT_STR __stringify(SYSCALL_EXIT_TOK)
63 #define COMPAT_SYSCALL_EXIT_STR __stringify(COMPAT_SYSCALL_EXIT_TOK)
65 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
);
66 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
);
69 * Forward declarations for old kernels.
73 struct oldold_utsname
;
75 struct sel_arg_struct
;
76 struct mmap_arg_struct
;
81 * Forward declaration for kernels >= 5.6
88 #if (LTTNG_LINUX_VERSION_CODE >= LTTNG_KERNEL_VERSION(5,6,0))
89 typedef __kernel_old_time_t
time_t;
92 #ifdef IA32_NR_syscalls
93 #define NR_compat_syscalls IA32_NR_syscalls
95 #define NR_compat_syscalls NR_syscalls
99 * Create LTTng tracepoint probes.
101 #define LTTNG_PACKAGE_BUILD
102 #define CREATE_TRACE_POINTS
103 #define TP_MODULE_NOINIT
104 #define TRACE_INCLUDE_PATH instrumentation/syscalls/headers
106 #define PARAMS(args...) args
108 /* Handle unknown syscalls */
110 #define TRACE_SYSTEM syscalls_unknown
111 #include <instrumentation/syscalls/headers/syscalls_unknown.h>
116 extern const struct trace_syscall_table sc_table
;
117 extern const struct trace_syscall_table compat_sc_table
;
119 /* Event syscall exit table */
120 extern const struct trace_syscall_table sc_exit_table
;
121 extern const struct trace_syscall_table compat_sc_exit_table
;
126 #undef CREATE_SYSCALL_TABLE
128 struct lttng_syscall_filter
{
129 DECLARE_BITMAP(sc_entry
, NR_syscalls
);
130 DECLARE_BITMAP(sc_exit
, NR_syscalls
);
131 DECLARE_BITMAP(sc_compat_entry
, NR_compat_syscalls
);
132 DECLARE_BITMAP(sc_compat_exit
, NR_compat_syscalls
);
136 int lttng_syscalls_create_matching_event_notifiers(struct lttng_event_enabler_common
*event_enabler
);
138 static void syscall_entry_event_unknown(struct hlist_head
*unknown_action_list_head
,
139 struct pt_regs
*regs
, long id
)
141 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
142 struct lttng_kernel_event_common_private
*event_priv
;
144 lttng_syscall_get_arguments(current
, regs
, args
);
145 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
146 if (unlikely(in_compat_syscall()))
147 __event_probe__compat_syscall_entry_unknown(event_priv
->pub
, id
, args
);
149 __event_probe__syscall_entry_unknown(event_priv
->pub
, id
, args
);
153 static __always_inline
154 void syscall_entry_event_call_func(struct hlist_head
*action_list
,
155 void *func
, unsigned int nrargs
,
156 struct pt_regs
*regs
)
158 struct lttng_kernel_event_common_private
*event_priv
;
163 void (*fptr
)(void *__data
) = func
;
165 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
166 fptr(event_priv
->pub
);
171 void (*fptr
)(void *__data
, unsigned long arg0
) = func
;
172 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
174 lttng_syscall_get_arguments(current
, regs
, args
);
175 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
176 fptr(event_priv
->pub
, args
[0]);
181 void (*fptr
)(void *__data
,
183 unsigned long arg1
) = func
;
184 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
186 lttng_syscall_get_arguments(current
, regs
, args
);
187 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
188 fptr(event_priv
->pub
, args
[0], args
[1]);
193 void (*fptr
)(void *__data
,
196 unsigned long arg2
) = func
;
197 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
199 lttng_syscall_get_arguments(current
, regs
, args
);
200 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
201 fptr(event_priv
->pub
, args
[0], args
[1], args
[2]);
206 void (*fptr
)(void *__data
,
210 unsigned long arg3
) = func
;
211 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
213 lttng_syscall_get_arguments(current
, regs
, args
);
214 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
215 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3]);
220 void (*fptr
)(void *__data
,
225 unsigned long arg4
) = func
;
226 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
228 lttng_syscall_get_arguments(current
, regs
, args
);
229 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
230 fptr(event_priv
->pub
, args
[0], args
[1], args
[2], args
[3], args
[4]);
235 void (*fptr
)(void *__data
,
241 unsigned long arg5
) = func
;
242 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
244 lttng_syscall_get_arguments(current
, regs
, args
);
245 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
246 fptr(event_priv
->pub
, args
[0], args
[1], args
[2],
247 args
[3], args
[4], args
[5]);
255 void syscall_entry_event_probe(void *__data
, struct pt_regs
*regs
, long id
)
257 struct lttng_kernel_syscall_table
*syscall_table
= __data
;
258 struct hlist_head
*action_list
, *unknown_action_list
;
259 const struct trace_syscall_entry
*table
, *entry
;
262 if (unlikely(in_compat_syscall())) {
263 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
265 if (id
< 0 || id
>= NR_compat_syscalls
266 || (!READ_ONCE(syscall_table
->syscall_all_entry
) && !test_bit(id
, filter
->sc_compat_entry
))) {
267 /* System call filtered out. */
270 table
= compat_sc_table
.table
;
271 table_len
= compat_sc_table
.len
;
272 unknown_action_list
= &syscall_table
->compat_unknown_syscall_dispatch
;
274 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
276 if (id
< 0 || id
>= NR_syscalls
277 || (!READ_ONCE(syscall_table
->syscall_all_entry
) && !test_bit(id
, filter
->sc_entry
))) {
278 /* System call filtered out. */
281 table
= sc_table
.table
;
282 table_len
= sc_table
.len
;
283 unknown_action_list
= &syscall_table
->unknown_syscall_dispatch
;
285 if (unlikely(id
< 0 || id
>= table_len
)) {
286 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
291 if (!entry
->event_func
) {
292 syscall_entry_event_unknown(unknown_action_list
, regs
, id
);
296 if (unlikely(in_compat_syscall())) {
297 action_list
= &syscall_table
->compat_syscall_dispatch
[id
];
299 action_list
= &syscall_table
->syscall_dispatch
[id
];
301 if (unlikely(hlist_empty(action_list
)))
304 syscall_entry_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
, regs
);
307 static void syscall_exit_event_unknown(struct hlist_head
*unknown_action_list_head
,
308 struct pt_regs
*regs
, long id
, long ret
)
310 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
311 struct lttng_kernel_event_common_private
*event_priv
;
313 lttng_syscall_get_arguments(current
, regs
, args
);
314 lttng_hlist_for_each_entry_rcu(event_priv
, unknown_action_list_head
, u
.syscall
.node
) {
315 if (unlikely(in_compat_syscall()))
316 __event_probe__compat_syscall_exit_unknown(event_priv
->pub
, id
, ret
,
319 __event_probe__syscall_exit_unknown(event_priv
->pub
, id
, ret
, args
);
323 static __always_inline
324 void syscall_exit_event_call_func(struct hlist_head
*action_list
,
325 void *func
, unsigned int nrargs
,
326 struct pt_regs
*regs
, long ret
)
328 struct lttng_kernel_event_common_private
*event_priv
;
333 void (*fptr
)(void *__data
, long ret
) = func
;
335 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
336 fptr(event_priv
->pub
, ret
);
341 void (*fptr
)(void *__data
,
343 unsigned long arg0
) = func
;
344 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
346 lttng_syscall_get_arguments(current
, regs
, args
);
347 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
348 fptr(event_priv
->pub
, ret
, args
[0]);
353 void (*fptr
)(void *__data
,
356 unsigned long arg1
) = func
;
357 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
359 lttng_syscall_get_arguments(current
, regs
, args
);
360 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
361 fptr(event_priv
->pub
, ret
, args
[0], args
[1]);
366 void (*fptr
)(void *__data
,
370 unsigned long arg2
) = func
;
371 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
373 lttng_syscall_get_arguments(current
, regs
, args
);
374 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
375 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2]);
380 void (*fptr
)(void *__data
,
385 unsigned long arg3
) = func
;
386 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
388 lttng_syscall_get_arguments(current
, regs
, args
);
389 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
390 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3]);
395 void (*fptr
)(void *__data
,
401 unsigned long arg4
) = func
;
402 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
404 lttng_syscall_get_arguments(current
, regs
, args
);
405 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
406 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2], args
[3], args
[4]);
411 void (*fptr
)(void *__data
,
418 unsigned long arg5
) = func
;
419 unsigned long args
[LTTNG_SYSCALL_NR_ARGS
];
421 lttng_syscall_get_arguments(current
, regs
, args
);
422 lttng_hlist_for_each_entry_rcu(event_priv
, action_list
, u
.syscall
.node
)
423 fptr(event_priv
->pub
, ret
, args
[0], args
[1], args
[2],
424 args
[3], args
[4], args
[5]);
432 void syscall_exit_event_probe(void *__data
, struct pt_regs
*regs
, long ret
)
434 struct lttng_kernel_syscall_table
*syscall_table
= __data
;
435 struct hlist_head
*action_list
, *unknown_action_list
;
436 const struct trace_syscall_entry
*table
, *entry
;
440 id
= syscall_get_nr(current
, regs
);
442 if (unlikely(in_compat_syscall())) {
443 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
445 if (id
< 0 || id
>= NR_compat_syscalls
446 || (!READ_ONCE(syscall_table
->syscall_all_exit
) && !test_bit(id
, filter
->sc_compat_exit
))) {
447 /* System call filtered out. */
450 table
= compat_sc_exit_table
.table
;
451 table_len
= compat_sc_exit_table
.len
;
452 unknown_action_list
= &syscall_table
->compat_unknown_syscall_exit_dispatch
;
454 struct lttng_syscall_filter
*filter
= syscall_table
->sc_filter
;
456 if (id
< 0 || id
>= NR_syscalls
457 || (!READ_ONCE(syscall_table
->syscall_all_exit
) && !test_bit(id
, filter
->sc_exit
))) {
458 /* System call filtered out. */
461 table
= sc_exit_table
.table
;
462 table_len
= sc_exit_table
.len
;
463 unknown_action_list
= &syscall_table
->unknown_syscall_exit_dispatch
;
465 if (unlikely(id
< 0 || id
>= table_len
)) {
466 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
471 if (!entry
->event_func
) {
472 syscall_exit_event_unknown(unknown_action_list
, regs
, id
, ret
);
476 if (unlikely(in_compat_syscall())) {
477 action_list
= &syscall_table
->compat_syscall_exit_dispatch
[id
];
479 action_list
= &syscall_table
->syscall_exit_dispatch
[id
];
481 if (unlikely(hlist_empty(action_list
)))
484 syscall_exit_event_call_func(action_list
, entry
->event_func
, entry
->nrargs
,
489 struct lttng_kernel_syscall_table
*get_syscall_table_from_enabler(struct lttng_event_enabler_common
*event_enabler
)
491 switch (event_enabler
->enabler_type
) {
492 case LTTNG_EVENT_ENABLER_TYPE_RECORDER
:
494 struct lttng_event_recorder_enabler
*event_recorder_enabler
=
495 container_of(event_enabler
, struct lttng_event_recorder_enabler
, parent
);
496 return &event_recorder_enabler
->chan
->priv
->parent
.syscall_table
;
498 case LTTNG_EVENT_ENABLER_TYPE_NOTIFIER
:
500 struct lttng_event_notifier_enabler
*event_notifier_enabler
=
501 container_of(event_enabler
, struct lttng_event_notifier_enabler
, parent
);
502 return &event_notifier_enabler
->group
->syscall_table
;
510 struct lttng_kernel_syscall_table
*get_syscall_table_from_event(struct lttng_kernel_event_common
*event
)
512 switch (event
->type
) {
513 case LTTNG_KERNEL_EVENT_TYPE_RECORDER
:
515 struct lttng_kernel_event_recorder
*event_recorder
=
516 container_of(event
, struct lttng_kernel_event_recorder
, parent
);
517 return &event_recorder
->chan
->priv
->parent
.syscall_table
;
519 case LTTNG_KERNEL_EVENT_TYPE_NOTIFIER
:
521 struct lttng_kernel_event_notifier
*event_notifier
=
522 container_of(event
, struct lttng_kernel_event_notifier
, parent
);
523 return &event_notifier
->priv
->group
->syscall_table
;
531 void lttng_syscall_event_enabler_create_event(struct lttng_event_enabler_common
*syscall_event_enabler
,
532 const struct lttng_kernel_event_desc
*desc
, struct hlist_head
*dispatch_table
,
533 enum sc_type type
, unsigned int syscall_nr
)
535 struct lttng_kernel_event_common
*event
;
537 switch (syscall_event_enabler
->enabler_type
) {
538 case LTTNG_EVENT_ENABLER_TYPE_RECORDER
:
540 struct lttng_event_recorder_enabler
*syscall_event_recorder_enabler
=
541 container_of(syscall_event_enabler
, struct lttng_event_recorder_enabler
, parent
);
542 struct lttng_event_recorder_enabler
*event_recorder_enabler
;
543 struct lttng_kernel_abi_event ev
;
545 /* We need to create an event for this syscall/enabler. */
546 memset(&ev
, 0, sizeof(ev
));
549 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
550 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
553 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
554 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
556 case SC_TYPE_COMPAT_ENTRY
:
557 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
558 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
560 case SC_TYPE_COMPAT_EXIT
:
561 ev
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
562 ev
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
565 strncpy(ev
.name
, desc
->event_name
, LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1);
566 ev
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
567 ev
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
568 event_recorder_enabler
= lttng_event_recorder_enabler_create(LTTNG_ENABLER_FORMAT_NAME
, &ev
,
569 syscall_event_recorder_enabler
->chan
);
570 WARN_ON_ONCE(!event_recorder_enabler
);
571 if (!event_recorder_enabler
)
573 event
= _lttng_kernel_event_create(&event_recorder_enabler
->parent
, desc
);
574 WARN_ON_ONCE(!event
|| IS_ERR(event
));
575 lttng_event_enabler_destroy(&event_recorder_enabler
->parent
);
576 if (!event
|| IS_ERR(event
)) {
577 printk(KERN_INFO
"Unable to create event recorder %s\n", desc
->event_name
);
581 hlist_add_head_rcu(&event
->priv
->u
.syscall
.node
, &dispatch_table
[syscall_nr
]);
584 case LTTNG_EVENT_ENABLER_TYPE_NOTIFIER
:
586 struct lttng_event_notifier_enabler
*syscall_event_notifier_enabler
=
587 container_of(syscall_event_enabler
, struct lttng_event_notifier_enabler
, parent
);
588 struct lttng_event_notifier_enabler
*event_notifier_enabler
;
589 struct lttng_kernel_abi_event_notifier event_notifier_param
;
590 uint64_t user_token
= syscall_event_enabler
->user_token
;
591 uint64_t error_counter_index
= syscall_event_notifier_enabler
->error_counter_index
;
593 memset(&event_notifier_param
, 0, sizeof(event_notifier_param
));
596 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
597 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
600 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
601 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_NATIVE
;
603 case SC_TYPE_COMPAT_ENTRY
:
604 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_ENTRY
;
605 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
607 case SC_TYPE_COMPAT_EXIT
:
608 event_notifier_param
.event
.u
.syscall
.entryexit
= LTTNG_KERNEL_ABI_SYSCALL_EXIT
;
609 event_notifier_param
.event
.u
.syscall
.abi
= LTTNG_KERNEL_ABI_SYSCALL_ABI_COMPAT
;
612 strncat(event_notifier_param
.event
.name
, desc
->event_name
,
613 LTTNG_KERNEL_ABI_SYM_NAME_LEN
- strlen(event_notifier_param
.event
.name
) - 1);
614 event_notifier_param
.event
.name
[LTTNG_KERNEL_ABI_SYM_NAME_LEN
- 1] = '\0';
615 event_notifier_param
.event
.instrumentation
= LTTNG_KERNEL_ABI_SYSCALL
;
616 event_notifier_param
.event
.token
= user_token
;
617 event_notifier_param
.error_counter_index
= error_counter_index
;
619 event_notifier_enabler
= lttng_event_notifier_enabler_create(LTTNG_ENABLER_FORMAT_NAME
,
620 &event_notifier_param
, syscall_event_notifier_enabler
->group
);
621 WARN_ON_ONCE(!event_notifier_enabler
);
622 event
= _lttng_kernel_event_create(&event_notifier_enabler
->parent
, desc
);
623 WARN_ON_ONCE(!event
|| IS_ERR(event
));
624 lttng_event_enabler_destroy(&event_notifier_enabler
->parent
);
625 if (!event
|| IS_ERR(event
)) {
626 printk(KERN_INFO
"Unable to create event notifier %s\n", desc
->event_name
);
629 event
->priv
->u
.syscall
.syscall_id
= syscall_nr
;
631 hlist_add_head_rcu(&event
->priv
->u
.syscall
.node
, dispatch_table
);
640 void lttng_syscall_event_enabler_create_matching_events(struct lttng_event_enabler_common
*syscall_event_enabler_common
,
641 const struct trace_syscall_entry
*table
,
643 struct hlist_head
*dispatch_table
,
646 struct lttng_event_ht
*events_ht
= lttng_get_event_ht_from_enabler(syscall_event_enabler_common
);
647 const struct lttng_kernel_event_desc
*desc
;
650 /* iterate over all syscall and create event_notifier that match */
651 for (i
= 0; i
< table_len
; i
++) {
652 struct lttng_kernel_event_common_private
*event_priv
;
653 struct hlist_head
*head
;
656 desc
= table
[i
].desc
;
658 /* Unknown syscall */
662 if (!lttng_desc_match_enabler(desc
, syscall_event_enabler_common
))
666 * Check if already created.
668 head
= utils_borrow_hash_table_bucket(events_ht
->table
, LTTNG_EVENT_HT_SIZE
, desc
->event_name
);
669 lttng_hlist_for_each_entry(event_priv
, head
, hlist_node
) {
670 if (lttng_event_enabler_desc_match_event(syscall_event_enabler_common
, desc
, event_priv
->pub
))
676 lttng_syscall_event_enabler_create_event(syscall_event_enabler_common
, desc
, dispatch_table
, type
, i
);
681 void create_unknown_syscall_event(struct lttng_event_enabler_common
*event_enabler
, enum sc_type type
)
683 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(event_enabler
);
684 struct lttng_event_ht
*events_ht
= lttng_get_event_ht_from_enabler(event_enabler
);
685 struct lttng_kernel_event_common_private
*event_priv
;
686 const struct lttng_kernel_event_desc
*desc
;
687 struct hlist_head
*unknown_dispatch_list
;
689 struct hlist_head
*head
;
693 desc
= &__event_desc___syscall_entry_unknown
;
694 unknown_dispatch_list
= &syscall_table
->unknown_syscall_dispatch
;
697 desc
= &__event_desc___syscall_exit_unknown
;
698 unknown_dispatch_list
= &syscall_table
->unknown_syscall_exit_dispatch
;
700 case SC_TYPE_COMPAT_ENTRY
:
701 desc
= &__event_desc___compat_syscall_entry_unknown
;
702 unknown_dispatch_list
= &syscall_table
->compat_unknown_syscall_dispatch
;
704 case SC_TYPE_COMPAT_EXIT
:
705 desc
= &__event_desc___compat_syscall_exit_unknown
;
706 unknown_dispatch_list
= &syscall_table
->compat_unknown_syscall_exit_dispatch
;
713 * Check if already created.
715 head
= utils_borrow_hash_table_bucket(events_ht
->table
, LTTNG_EVENT_HT_SIZE
, desc
->event_name
);
716 lttng_hlist_for_each_entry(event_priv
, head
, hlist_node
) {
717 if (lttng_event_enabler_desc_match_event(event_enabler
, desc
, event_priv
->pub
))
721 lttng_syscall_event_enabler_create_event(event_enabler
, desc
, unknown_dispatch_list
, type
, -1U);
725 int lttng_syscalls_populate_events(struct lttng_event_enabler_common
*syscall_event_enabler
)
727 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(syscall_event_enabler
);
728 struct lttng_event_recorder_enabler
*event_recorder_enabler
;
729 struct lttng_kernel_channel_buffer
*chan
;
732 if (syscall_event_enabler
->enabler_type
!= LTTNG_EVENT_ENABLER_TYPE_RECORDER
)
734 event_recorder_enabler
= container_of(syscall_event_enabler
, struct lttng_event_recorder_enabler
, parent
);
735 chan
= event_recorder_enabler
->chan
;
737 lttng_syscall_event_enabler_create_matching_events(&event_recorder_enabler
->parent
, sc_table
.table
, sc_table
.len
,
738 syscall_table
->syscall_dispatch
, SC_TYPE_ENTRY
);
739 lttng_syscall_event_enabler_create_matching_events(&event_recorder_enabler
->parent
, sc_exit_table
.table
, sc_exit_table
.len
,
740 syscall_table
->syscall_exit_dispatch
, SC_TYPE_EXIT
);
741 create_unknown_syscall_event(syscall_event_enabler
, SC_TYPE_ENTRY
);
742 create_unknown_syscall_event(syscall_event_enabler
, SC_TYPE_EXIT
);
745 lttng_syscall_event_enabler_create_matching_events(&event_recorder_enabler
->parent
, compat_sc_table
.table
, compat_sc_table
.len
,
746 syscall_table
->compat_syscall_dispatch
, SC_TYPE_COMPAT_ENTRY
);
747 lttng_syscall_event_enabler_create_matching_events(&event_recorder_enabler
->parent
, compat_sc_exit_table
.table
, compat_sc_exit_table
.len
,
748 syscall_table
->compat_syscall_exit_dispatch
, SC_TYPE_COMPAT_EXIT
);
749 create_unknown_syscall_event(syscall_event_enabler
, SC_TYPE_COMPAT_ENTRY
);
750 create_unknown_syscall_event(syscall_event_enabler
, SC_TYPE_COMPAT_EXIT
);
756 * Should be called with sessions lock held.
758 int lttng_event_enabler_create_syscall_events_if_missing(struct lttng_event_enabler_common
*syscall_event_enabler
)
760 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(syscall_event_enabler
);
763 if (!syscall_table
->syscall_dispatch
) {
764 /* create syscall table mapping syscall to events */
765 syscall_table
->syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_table
.len
, GFP_KERNEL
);
766 if (!syscall_table
->syscall_dispatch
)
769 if (!syscall_table
->syscall_exit_dispatch
) {
770 /* create syscall table mapping syscall to events */
771 syscall_table
->syscall_exit_dispatch
= kzalloc(sizeof(struct hlist_head
) * sc_exit_table
.len
, GFP_KERNEL
);
772 if (!syscall_table
->syscall_exit_dispatch
)
778 if (!syscall_table
->compat_syscall_dispatch
) {
779 /* create syscall table mapping compat syscall to events */
780 syscall_table
->compat_syscall_dispatch
= kzalloc(sizeof(struct hlist_head
) * compat_sc_table
.len
, GFP_KERNEL
);
781 if (!syscall_table
->compat_syscall_dispatch
)
785 if (!syscall_table
->compat_syscall_exit_dispatch
) {
786 /* create syscall table mapping compat syscall to events */
787 syscall_table
->compat_syscall_exit_dispatch
= kzalloc(sizeof(struct hlist_head
) * compat_sc_exit_table
.len
, GFP_KERNEL
);
788 if (!syscall_table
->compat_syscall_exit_dispatch
)
792 if (!syscall_table
->sc_filter
) {
793 syscall_table
->sc_filter
= kzalloc(sizeof(struct lttng_syscall_filter
),
795 if (!syscall_table
->sc_filter
)
799 ret
= lttng_syscalls_populate_events(syscall_event_enabler
);
803 ret
= lttng_syscalls_create_matching_event_notifiers(syscall_event_enabler
);
807 if (!syscall_table
->sys_enter_registered
) {
808 ret
= lttng_wrapper_tracepoint_probe_register("sys_enter",
809 (void *) syscall_entry_event_probe
, syscall_table
);
812 syscall_table
->sys_enter_registered
= 1;
814 if (!syscall_table
->sys_exit_registered
) {
815 ret
= lttng_wrapper_tracepoint_probe_register("sys_exit",
816 (void *) syscall_exit_event_probe
, syscall_table
);
818 WARN_ON_ONCE(lttng_wrapper_tracepoint_probe_unregister("sys_enter",
819 (void *) syscall_entry_event_probe
, syscall_table
));
822 syscall_table
->sys_exit_registered
= 1;
829 int lttng_syscalls_create_matching_event_notifiers(struct lttng_event_enabler_common
*event_enabler
)
832 enum lttng_kernel_abi_syscall_entryexit entryexit
=
833 event_enabler
->event_param
.u
.syscall
.entryexit
;
834 struct lttng_event_notifier_enabler
*event_notifier_enabler
;
836 if (event_enabler
->enabler_type
!= LTTNG_EVENT_ENABLER_TYPE_NOTIFIER
)
838 event_notifier_enabler
= container_of(event_enabler
, struct lttng_event_notifier_enabler
, parent
);
840 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
841 lttng_syscall_event_enabler_create_matching_events(&event_notifier_enabler
->parent
,
842 sc_table
.table
, sc_table
.len
, NULL
, SC_TYPE_ENTRY
);
843 lttng_syscall_event_enabler_create_matching_events(&event_notifier_enabler
->parent
,
844 compat_sc_table
.table
, compat_sc_table
.len
, NULL
, SC_TYPE_COMPAT_ENTRY
);
845 create_unknown_syscall_event(event_enabler
, SC_TYPE_ENTRY
);
846 create_unknown_syscall_event(event_enabler
, SC_TYPE_COMPAT_ENTRY
);
849 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
) {
850 lttng_syscall_event_enabler_create_matching_events(&event_notifier_enabler
->parent
,
851 sc_exit_table
.table
, sc_exit_table
.len
, NULL
, SC_TYPE_EXIT
);
852 lttng_syscall_event_enabler_create_matching_events(&event_notifier_enabler
->parent
,
853 compat_sc_exit_table
.table
, compat_sc_exit_table
.len
, NULL
, SC_TYPE_COMPAT_EXIT
);
854 create_unknown_syscall_event(event_enabler
, SC_TYPE_EXIT
);
855 create_unknown_syscall_event(event_enabler
, SC_TYPE_COMPAT_EXIT
);
860 int lttng_syscalls_unregister_syscall_table(struct lttng_kernel_syscall_table
*syscall_table
)
864 if (!syscall_table
->syscall_dispatch
)
866 if (syscall_table
->sys_enter_registered
) {
867 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_enter",
868 (void *) syscall_entry_event_probe
, syscall_table
);
871 syscall_table
->sys_enter_registered
= 0;
873 if (syscall_table
->sys_exit_registered
) {
874 ret
= lttng_wrapper_tracepoint_probe_unregister("sys_exit",
875 (void *) syscall_exit_event_probe
, syscall_table
);
878 syscall_table
->sys_exit_registered
= 0;
883 int lttng_syscalls_destroy_syscall_table(struct lttng_kernel_syscall_table
*syscall_table
)
885 kfree(syscall_table
->syscall_dispatch
);
886 kfree(syscall_table
->syscall_exit_dispatch
);
888 kfree(syscall_table
->compat_syscall_dispatch
);
889 kfree(syscall_table
->compat_syscall_exit_dispatch
);
891 kfree(syscall_table
->sc_filter
);
896 int get_syscall_nr(const char *syscall_name
)
901 for (i
= 0; i
< sc_table
.len
; i
++) {
902 const struct trace_syscall_entry
*entry
;
905 entry
= &sc_table
.table
[i
];
908 it_name
= entry
->desc
->event_name
;
909 it_name
+= strlen(SYSCALL_ENTRY_STR
);
910 if (!strcmp(syscall_name
, it_name
)) {
919 int get_compat_syscall_nr(const char *syscall_name
)
924 for (i
= 0; i
< compat_sc_table
.len
; i
++) {
925 const struct trace_syscall_entry
*entry
;
928 entry
= &compat_sc_table
.table
[i
];
931 it_name
= entry
->desc
->event_name
;
932 it_name
+= strlen(COMPAT_SYSCALL_ENTRY_STR
);
933 if (!strcmp(syscall_name
, it_name
)) {
942 uint32_t get_sc_tables_len(void)
944 return sc_table
.len
+ compat_sc_table
.len
;
948 const char *get_syscall_name(const char *desc_name
,
949 enum lttng_syscall_abi abi
,
950 enum lttng_syscall_entryexit entryexit
)
952 size_t prefix_len
= 0;
956 case LTTNG_SYSCALL_ENTRY
:
958 case LTTNG_SYSCALL_ABI_NATIVE
:
959 prefix_len
= strlen(SYSCALL_ENTRY_STR
);
961 case LTTNG_SYSCALL_ABI_COMPAT
:
962 prefix_len
= strlen(COMPAT_SYSCALL_ENTRY_STR
);
966 case LTTNG_SYSCALL_EXIT
:
968 case LTTNG_SYSCALL_ABI_NATIVE
:
969 prefix_len
= strlen(SYSCALL_EXIT_STR
);
971 case LTTNG_SYSCALL_ABI_COMPAT
:
972 prefix_len
= strlen(COMPAT_SYSCALL_EXIT_STR
);
977 WARN_ON_ONCE(prefix_len
== 0);
978 return desc_name
+ prefix_len
;
982 int lttng_syscall_filter_enable(
983 struct lttng_syscall_filter
*filter
,
984 const char *desc_name
, enum lttng_syscall_abi abi
,
985 enum lttng_syscall_entryexit entryexit
)
987 const char *syscall_name
;
988 unsigned long *bitmap
;
991 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
994 case LTTNG_SYSCALL_ABI_NATIVE
:
995 syscall_nr
= get_syscall_nr(syscall_name
);
997 case LTTNG_SYSCALL_ABI_COMPAT
:
998 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1006 switch (entryexit
) {
1007 case LTTNG_SYSCALL_ENTRY
:
1009 case LTTNG_SYSCALL_ABI_NATIVE
:
1010 bitmap
= filter
->sc_entry
;
1012 case LTTNG_SYSCALL_ABI_COMPAT
:
1013 bitmap
= filter
->sc_compat_entry
;
1019 case LTTNG_SYSCALL_EXIT
:
1021 case LTTNG_SYSCALL_ABI_NATIVE
:
1022 bitmap
= filter
->sc_exit
;
1024 case LTTNG_SYSCALL_ABI_COMPAT
:
1025 bitmap
= filter
->sc_compat_exit
;
1034 if (test_bit(syscall_nr
, bitmap
))
1036 bitmap_set(bitmap
, syscall_nr
, 1);
1040 int lttng_syscall_filter_enable_event(struct lttng_kernel_event_common
*event
)
1042 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_event(event
);
1045 WARN_ON_ONCE(event
->priv
->instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
);
1047 ret
= lttng_syscall_filter_enable(syscall_table
->sc_filter
,
1048 event
->priv
->desc
->event_name
, event
->priv
->u
.syscall
.abi
,
1049 event
->priv
->u
.syscall
.entryexit
);
1053 switch (event
->type
) {
1054 case LTTNG_KERNEL_EVENT_TYPE_RECORDER
:
1056 case LTTNG_KERNEL_EVENT_TYPE_NOTIFIER
:
1058 unsigned int syscall_id
= event
->priv
->u
.syscall
.syscall_id
;
1059 struct hlist_head
*dispatch_list
;
1061 switch (event
->priv
->u
.syscall
.entryexit
) {
1062 case LTTNG_SYSCALL_ENTRY
:
1063 switch (event
->priv
->u
.syscall
.abi
) {
1064 case LTTNG_SYSCALL_ABI_NATIVE
:
1065 dispatch_list
= &syscall_table
->syscall_dispatch
[syscall_id
];
1067 case LTTNG_SYSCALL_ABI_COMPAT
:
1068 dispatch_list
= &syscall_table
->compat_syscall_dispatch
[syscall_id
];
1075 case LTTNG_SYSCALL_EXIT
:
1076 switch (event
->priv
->u
.syscall
.abi
) {
1077 case LTTNG_SYSCALL_ABI_NATIVE
:
1078 dispatch_list
= &syscall_table
->syscall_exit_dispatch
[syscall_id
];
1080 case LTTNG_SYSCALL_ABI_COMPAT
:
1081 dispatch_list
= &syscall_table
->compat_syscall_exit_dispatch
[syscall_id
];
1093 hlist_add_head_rcu(&event
->priv
->u
.syscall
.node
, dispatch_list
);
1105 int lttng_syscall_filter_disable(struct lttng_syscall_filter
*filter
,
1106 const char *desc_name
, enum lttng_syscall_abi abi
,
1107 enum lttng_syscall_entryexit entryexit
)
1109 const char *syscall_name
;
1110 unsigned long *bitmap
;
1113 syscall_name
= get_syscall_name(desc_name
, abi
, entryexit
);
1116 case LTTNG_SYSCALL_ABI_NATIVE
:
1117 syscall_nr
= get_syscall_nr(syscall_name
);
1119 case LTTNG_SYSCALL_ABI_COMPAT
:
1120 syscall_nr
= get_compat_syscall_nr(syscall_name
);
1128 switch (entryexit
) {
1129 case LTTNG_SYSCALL_ENTRY
:
1131 case LTTNG_SYSCALL_ABI_NATIVE
:
1132 bitmap
= filter
->sc_entry
;
1134 case LTTNG_SYSCALL_ABI_COMPAT
:
1135 bitmap
= filter
->sc_compat_entry
;
1141 case LTTNG_SYSCALL_EXIT
:
1143 case LTTNG_SYSCALL_ABI_NATIVE
:
1144 bitmap
= filter
->sc_exit
;
1146 case LTTNG_SYSCALL_ABI_COMPAT
:
1147 bitmap
= filter
->sc_compat_exit
;
1156 if (!test_bit(syscall_nr
, bitmap
))
1158 bitmap_clear(bitmap
, syscall_nr
, 1);
1163 int lttng_syscall_filter_disable_event(struct lttng_kernel_event_common
*event
)
1165 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_event(event
);
1168 ret
= lttng_syscall_filter_disable(syscall_table
->sc_filter
,
1169 event
->priv
->desc
->event_name
, event
->priv
->u
.syscall
.abi
,
1170 event
->priv
->u
.syscall
.entryexit
);
1174 switch (event
->type
) {
1175 case LTTNG_KERNEL_EVENT_TYPE_RECORDER
:
1177 case LTTNG_KERNEL_EVENT_TYPE_NOTIFIER
:
1179 hlist_del_rcu(&event
->priv
->u
.syscall
.node
);
1189 void lttng_syscall_table_set_wildcard_all(struct lttng_event_enabler_common
*event_enabler
)
1191 struct lttng_kernel_syscall_table
*syscall_table
= get_syscall_table_from_enabler(event_enabler
);
1192 enum lttng_kernel_abi_syscall_entryexit entryexit
;
1193 int enabled
= event_enabler
->enabled
;
1195 if (event_enabler
->event_param
.instrumentation
!= LTTNG_KERNEL_ABI_SYSCALL
)
1197 if (event_enabler
->event_param
.u
.syscall
.abi
!= LTTNG_KERNEL_ABI_SYSCALL_ABI_ALL
)
1199 if (event_enabler
->event_param
.u
.syscall
.match
!= LTTNG_KERNEL_ABI_SYSCALL_MATCH_NAME
)
1201 if (strcmp(event_enabler
->event_param
.name
, "*"))
1204 entryexit
= event_enabler
->event_param
.u
.syscall
.entryexit
;
1205 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRY
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
)
1206 WRITE_ONCE(syscall_table
->syscall_all_entry
, enabled
);
1208 if (entryexit
== LTTNG_KERNEL_ABI_SYSCALL_EXIT
|| entryexit
== LTTNG_KERNEL_ABI_SYSCALL_ENTRYEXIT
)
1209 WRITE_ONCE(syscall_table
->syscall_all_exit
, enabled
);
1213 const struct trace_syscall_entry
*syscall_list_get_entry(loff_t
*pos
)
1215 const struct trace_syscall_entry
*entry
;
1218 for (entry
= sc_table
.table
;
1219 entry
< sc_table
.table
+ sc_table
.len
;
1224 for (entry
= compat_sc_table
.table
;
1225 entry
< compat_sc_table
.table
+ compat_sc_table
.len
;
1235 void *syscall_list_start(struct seq_file
*m
, loff_t
*pos
)
1237 return (void *) syscall_list_get_entry(pos
);
1241 void *syscall_list_next(struct seq_file
*m
, void *p
, loff_t
*ppos
)
1244 return (void *) syscall_list_get_entry(ppos
);
1248 void syscall_list_stop(struct seq_file
*m
, void *p
)
1253 int get_sc_table(const struct trace_syscall_entry
*entry
,
1254 const struct trace_syscall_entry
**table
,
1255 unsigned int *bitness
)
1257 if (entry
>= sc_table
.table
&& entry
< sc_table
.table
+ sc_table
.len
) {
1259 *bitness
= BITS_PER_LONG
;
1261 *table
= sc_table
.table
;
1264 if (!(entry
>= compat_sc_table
.table
1265 && entry
< compat_sc_table
.table
+ compat_sc_table
.len
)) {
1271 *table
= compat_sc_table
.table
;
1276 int syscall_list_show(struct seq_file
*m
, void *p
)
1278 const struct trace_syscall_entry
*table
, *entry
= p
;
1279 unsigned int bitness
;
1280 unsigned long index
;
1284 ret
= get_sc_table(entry
, &table
, &bitness
);
1289 if (table
== sc_table
.table
) {
1290 index
= entry
- table
;
1291 name
= &entry
->desc
->event_name
[strlen(SYSCALL_ENTRY_STR
)];
1293 index
= (entry
- table
) + sc_table
.len
;
1294 name
= &entry
->desc
->event_name
[strlen(COMPAT_SYSCALL_ENTRY_STR
)];
1296 seq_printf(m
, "syscall { index = %lu; name = %s; bitness = %u; };\n",
1297 index
, name
, bitness
);
1302 const struct seq_operations lttng_syscall_list_seq_ops
= {
1303 .start
= syscall_list_start
,
1304 .next
= syscall_list_next
,
1305 .stop
= syscall_list_stop
,
1306 .show
= syscall_list_show
,
1310 int lttng_syscall_list_open(struct inode
*inode
, struct file
*file
)
1312 return seq_open(file
, <tng_syscall_list_seq_ops
);
1315 const struct file_operations lttng_syscall_list_fops
= {
1316 .owner
= THIS_MODULE
,
1317 .open
= lttng_syscall_list_open
,
1319 .llseek
= seq_lseek
,
1320 .release
= seq_release
,
1324 * A syscall is enabled if it is traced for either entry or exit.
1326 long lttng_syscall_table_get_active_mask(struct lttng_kernel_syscall_table
*syscall_table
,
1327 struct lttng_kernel_abi_syscall_mask __user
*usyscall_mask
)
1329 uint32_t len
, sc_tables_len
, bitmask_len
;
1332 struct lttng_syscall_filter
*filter
;
1334 ret
= get_user(len
, &usyscall_mask
->len
);
1337 sc_tables_len
= get_sc_tables_len();
1338 bitmask_len
= ALIGN(sc_tables_len
, 8) >> 3;
1339 if (len
< sc_tables_len
) {
1340 return put_user(sc_tables_len
, &usyscall_mask
->len
);
1342 /* Array is large enough, we can copy array to user-space. */
1343 tmp_mask
= kzalloc(bitmask_len
, GFP_KERNEL
);
1346 filter
= syscall_table
->sc_filter
;
1348 for (bit
= 0; bit
< sc_table
.len
; bit
++) {
1351 if (syscall_table
->syscall_dispatch
) {
1352 if (!(READ_ONCE(syscall_table
->syscall_all_entry
)
1353 || READ_ONCE(syscall_table
->syscall_all_exit
)) && filter
)
1354 state
= test_bit(bit
, filter
->sc_entry
)
1355 || test_bit(bit
, filter
->sc_exit
);
1361 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1363 for (; bit
< sc_tables_len
; bit
++) {
1366 if (syscall_table
->compat_syscall_dispatch
) {
1367 if (!(READ_ONCE(syscall_table
->syscall_all_entry
)
1368 || READ_ONCE(syscall_table
->syscall_all_exit
)) && filter
)
1369 state
= test_bit(bit
- sc_table
.len
,
1370 filter
->sc_compat_entry
)
1371 || test_bit(bit
- sc_table
.len
,
1372 filter
->sc_compat_exit
);
1378 bt_bitfield_write_be(tmp_mask
, char, bit
, 1, state
);
1380 if (copy_to_user(usyscall_mask
->mask
, tmp_mask
, bitmask_len
))
1386 int lttng_abi_syscall_list(void)
1388 struct file
*syscall_list_file
;
1391 file_fd
= lttng_get_unused_fd();
1397 syscall_list_file
= anon_inode_getfile("[lttng_syscall_list]",
1398 <tng_syscall_list_fops
,
1400 if (IS_ERR(syscall_list_file
)) {
1401 ret
= PTR_ERR(syscall_list_file
);
1404 ret
= lttng_syscall_list_fops
.open(NULL
, syscall_list_file
);
1407 fd_install(file_fd
, syscall_list_file
);
1411 fput(syscall_list_file
);
1413 put_unused_fd(file_fd
);