xref: /freebsd/sys/sys/ktrace.h (revision a91a2465)
1 /*-
2  * SPDX-License-Identifier: BSD-3-Clause
3  *
4  * Copyright (c) 1988, 1993
5  *	The Regents of the University of California.  All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  * 3. Neither the name of the University nor the names of its contributors
16  *    may be used to endorse or promote products derived from this software
17  *    without specific prior written permission.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29  * SUCH DAMAGE.
30  */
31 
32 #ifndef _SYS_KTRACE_H_
33 #define _SYS_KTRACE_H_
34 
35 #include <sys/caprights.h>
36 #include <sys/signal.h>
37 #include <sys/_uio.h>
38 
39 /*
40  * operations to ktrace system call  (KTROP(op))
41  */
42 #define KTROP_SET		0	/* set trace points */
43 #define KTROP_CLEAR		1	/* clear trace points */
44 #define KTROP_CLEARFILE		2	/* stop all tracing to file */
45 #define	KTROP(o)		((o)&3)	/* macro to extract operation */
46 /*
47  * flags (ORed in with operation)
48  */
49 #define KTRFLAG_DESCEND		4	/* perform op on all children too */
50 
51 /*
52  * ktrace record header
53  */
54 struct ktr_header_v0 {
55 	int	ktr_len;		/* length of buf */
56 	short	ktr_type;		/* trace record type */
57 	pid_t	ktr_pid;		/* process id */
58 	char	ktr_comm[MAXCOMLEN + 1];/* command name */
59 	struct	timeval ktr_time;	/* timestamp */
60 	long	ktr_tid;		/* thread id */
61 };
62 
63 struct ktr_header {
64 	int	ktr_len;		/* length of buf */
65 	short	ktr_type;		/* trace record type */
66 	short	ktr_version;		/* ktr_header version */
67 	pid_t	ktr_pid;		/* process id */
68 	char	ktr_comm[MAXCOMLEN + 1];/* command name */
69 	struct	timespec ktr_time;	/* timestamp */
70 	/* XXX: make ktr_tid an lwpid_t on next ABI break */
71 	long	ktr_tid;		/* thread id */
72 	int	ktr_cpu;		/* cpu id */
73 };
74 
75 #define	KTR_VERSION0	0
76 #define	KTR_VERSION1	1
77 #define	KTR_OFFSET_V0	sizeof(struct ktr_header_v0) - \
78 			    sizeof(struct ktr_header)
79 /*
80  * Test for kernel trace point (MP SAFE).
81  *
82  * KTRCHECK() just checks that the type is enabled and is only for
83  * internal use in the ktrace subsystem.  KTRPOINT() checks against
84  * ktrace recursion as well as checking that the type is enabled and
85  * is the public interface.
86  */
87 #define	KTRCHECK(td, type)	((td)->td_proc->p_traceflag & (1 << type))
88 #define KTRPOINT(td, type)  (__predict_false(KTRCHECK((td), (type))))
89 #define	KTRCHECKDRAIN(td)	(!(STAILQ_EMPTY(&(td)->td_proc->p_ktr)))
90 #define	KTRUSERRET(td) do {						\
91 	if (__predict_false(KTRCHECKDRAIN(td)))				\
92 		ktruserret(td);						\
93 } while (0)
94 
95 /*
96  * ktrace record types
97  */
98 
99 /*
100  * KTR_SYSCALL - system call record
101  */
102 #define KTR_SYSCALL	1
103 struct ktr_syscall {
104 	short	ktr_code;		/* syscall number */
105 	short	ktr_narg;		/* number of arguments */
106 	/*
107 	 * followed by ktr_narg register_t
108 	 */
109 	register_t	ktr_args[1];
110 };
111 
112 /*
113  * KTR_SYSRET - return from system call record
114  */
115 #define KTR_SYSRET	2
116 struct ktr_sysret {
117 	short	ktr_code;
118 	short	ktr_eosys;
119 	int	ktr_error;
120 	register_t	ktr_retval;
121 };
122 
123 /*
124  * KTR_NAMEI - namei record
125  */
126 #define KTR_NAMEI	3
127 	/* record contains pathname */
128 
129 /*
130  * KTR_GENIO - trace generic process i/o
131  */
132 #define KTR_GENIO	4
133 struct ktr_genio {
134 	int	ktr_fd;
135 	enum	uio_rw ktr_rw;
136 	/*
137 	 * followed by data successfully read/written
138 	 */
139 };
140 
141 /*
142  * KTR_PSIG - trace processed signal
143  */
144 #define	KTR_PSIG	5
145 struct ktr_psig {
146 	int	signo;
147 	sig_t	action;
148 	int	code;
149 	sigset_t mask;
150 };
151 
152 /*
153  * KTR_CSW - trace context switches
154  */
155 #define KTR_CSW		6
156 struct ktr_csw_old {
157 	int	out;	/* 1 if switch out, 0 if switch in */
158 	int	user;	/* 1 if usermode (ivcsw), 0 if kernel (vcsw) */
159 };
160 
161 struct ktr_csw {
162 	int	out;	/* 1 if switch out, 0 if switch in */
163 	int	user;	/* 1 if usermode (ivcsw), 0 if kernel (vcsw) */
164 	char	wmesg[8];
165 };
166 
167 /*
168  * KTR_USER - data coming from userland
169  */
170 #define KTR_USER_MAXLEN	2048	/* maximum length of passed data */
171 #define KTR_USER	7
172 
173 /*
174  * KTR_STRUCT - misc. structs
175  */
176 #define KTR_STRUCT	8
177 	/*
178 	 * record contains null-terminated struct name followed by
179 	 * struct contents
180 	 */
181 struct sockaddr;
182 struct stat;
183 struct sysentvec;
184 
185 /*
186  * KTR_SYSCTL - name of a sysctl MIB
187  */
188 #define	KTR_SYSCTL	9
189 	/* record contains null-terminated MIB name */
190 
191 /*
192  * KTR_PROCCTOR - trace process creation (multiple ABI support)
193  */
194 #define KTR_PROCCTOR	10
195 struct ktr_proc_ctor {
196 	u_int	sv_flags;	/* struct sysentvec sv_flags copy */
197 };
198 
199 /*
200  * KTR_PROCDTOR - trace process destruction (multiple ABI support)
201  */
202 #define KTR_PROCDTOR	11
203 
204 /*
205  * KTR_CAPFAIL - trace capability check failures
206  */
207 #define KTR_CAPFAIL	12
208 enum ktr_cap_fail_type {
209 	CAPFAIL_NOTCAPABLE,	/* insufficient capabilities in cap_check() */
210 	CAPFAIL_INCREASE,	/* attempt to increase capabilities */
211 	CAPFAIL_SYSCALL,	/* disallowed system call */
212 	CAPFAIL_LOOKUP,		/* disallowed VFS lookup */
213 };
214 struct ktr_cap_fail {
215 	enum ktr_cap_fail_type cap_type;
216 	cap_rights_t	cap_needed;
217 	cap_rights_t	cap_held;
218 };
219 
220 /*
221  * KTR_FAULT - page fault record
222  */
223 #define KTR_FAULT	13
224 struct ktr_fault {
225 	vm_offset_t vaddr;
226 	int type;
227 };
228 
229 /*
230  * KTR_FAULTEND - end of page fault record
231  */
232 #define KTR_FAULTEND	14
233 struct ktr_faultend {
234 	int result;
235 };
236 
237 /*
238  * KTR_STRUCT_ARRAY - array of misc. structs
239  */
240 #define	KTR_STRUCT_ARRAY 15
241 struct ktr_struct_array {
242 	size_t struct_size;
243 	/*
244 	 * Followed by null-terminated structure name and then payload
245 	 * contents.
246 	 */
247 };
248 
249 /*
250  * KTR_DROP - If this bit is set in ktr_type, then at least one event
251  * between the previous record and this record was dropped.
252  */
253 #define	KTR_DROP	0x8000
254 /*
255  * KTR_VERSIONED - If this bit is set in ktr_type, then the kernel
256  * exposes the new struct ktr_header (versioned), otherwise the old
257  * struct ktr_header_v0 is exposed.
258  */
259 #define	KTR_VERSIONED	0x4000
260 #define	KTR_TYPE	(KTR_DROP | KTR_VERSIONED)
261 
262 /*
263  * kernel trace points (in p_traceflag)
264  */
265 #define KTRFAC_MASK	0x00ffffff
266 #define KTRFAC_SYSCALL	(1<<KTR_SYSCALL)
267 #define KTRFAC_SYSRET	(1<<KTR_SYSRET)
268 #define KTRFAC_NAMEI	(1<<KTR_NAMEI)
269 #define KTRFAC_GENIO	(1<<KTR_GENIO)
270 #define	KTRFAC_PSIG	(1<<KTR_PSIG)
271 #define KTRFAC_CSW	(1<<KTR_CSW)
272 #define KTRFAC_USER	(1<<KTR_USER)
273 #define KTRFAC_STRUCT	(1<<KTR_STRUCT)
274 #define KTRFAC_SYSCTL	(1<<KTR_SYSCTL)
275 #define KTRFAC_PROCCTOR	(1<<KTR_PROCCTOR)
276 #define KTRFAC_PROCDTOR	(1<<KTR_PROCDTOR)
277 #define KTRFAC_CAPFAIL	(1<<KTR_CAPFAIL)
278 #define KTRFAC_FAULT	(1<<KTR_FAULT)
279 #define KTRFAC_FAULTEND	(1<<KTR_FAULTEND)
280 #define	KTRFAC_STRUCT_ARRAY (1<<KTR_STRUCT_ARRAY)
281 
282 /*
283  * trace flags (also in p_traceflags)
284  */
285 #define KTRFAC_ROOT	0x80000000	/* root set this trace */
286 #define KTRFAC_INHERIT	0x40000000	/* pass trace flags to children */
287 #define	KTRFAC_DROP	0x20000000	/* last event was dropped */
288 
289 #ifdef	_KERNEL
290 struct ktr_io_params;
291 
292 #ifdef	KTRACE
293 struct vnode *ktr_get_tracevp(struct proc *, bool);
294 #else
295 static inline struct vnode *
296 ktr_get_tracevp(struct proc *p, bool ref)
297 {
298 
299 	return (NULL);
300 }
301 #endif
302 void	ktr_io_params_free(struct ktr_io_params *);
303 void	ktrnamei(const char *);
304 void	ktrcsw(int, int, const char *);
305 void	ktrpsig(int, sig_t, sigset_t *, int);
306 void	ktrfault(vm_offset_t, int);
307 void	ktrfaultend(int);
308 void	ktrgenio(int, enum uio_rw, struct uio *, int);
309 void	ktrsyscall(int, int narg, syscallarg_t args[]);
310 void	ktrsysctl(int *name, u_int namelen);
311 void	ktrsysret(int, int, register_t);
312 void	ktrprocctor(struct proc *);
313 struct ktr_io_params *ktrprocexec(struct proc *);
314 void	ktrprocexit(struct thread *);
315 void	ktrprocfork(struct proc *, struct proc *);
316 void	ktruserret(struct thread *);
317 void	ktrstruct(const char *, const void *, size_t);
318 void	ktrstruct_error(const char *, const void *, size_t, int);
319 void	ktrstructarray(const char *, enum uio_seg, const void *, int, size_t);
320 void	ktrcapfail(enum ktr_cap_fail_type, const cap_rights_t *,
321 	    const cap_rights_t *);
322 #define ktrcaprights(s) \
323 	ktrstruct("caprights", (s), sizeof(cap_rights_t))
324 #define	ktritimerval(s) \
325 	ktrstruct("itimerval", (s), sizeof(struct itimerval))
326 #define ktrsockaddr(s) \
327 	ktrstruct("sockaddr", (s), ((struct sockaddr *)(s))->sa_len)
328 #define ktrstat(s) \
329 	ktrstruct("stat", (s), sizeof(struct stat))
330 #define ktrstat_error(s, error) \
331 	ktrstruct_error("stat", (s), sizeof(struct stat), error)
332 #define ktrcpuset(s, l) \
333 	ktrstruct("cpuset_t", (s), l)
334 extern u_int ktr_geniosize;
335 #ifdef	KTRACE
336 extern int ktr_filesize_limit_signal;
337 #define	__ktrace_used
338 #else
339 #define	ktr_filesize_limit_signal 0
340 #define	__ktrace_used	__unused
341 #endif
342 #else
343 
344 #include <sys/cdefs.h>
345 
346 __BEGIN_DECLS
347 int	ktrace(const char *, int, int, pid_t);
348 int	utrace(const void *, size_t);
349 __END_DECLS
350 
351 #endif
352 
353 #endif
354