1 /*-
2 * SPDX-License-Identifier: BSD-3-Clause
3 *
4 * Copyright (c) 1988, 1993
5 * The Regents of the University of California. All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. Neither the name of the University nor the names of its contributors
16 * may be used to endorse or promote products derived from this software
17 * without specific prior written permission.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * SUCH DAMAGE.
30 */
31
32 #ifndef _SYS_KTRACE_H_
33 #define _SYS_KTRACE_H_
34
35 #include <sys/param.h>
36 #include <sys/caprights.h>
37 #include <sys/signal.h>
38 #include <sys/socket.h>
39 #include <sys/_uio.h>
40
41 /*
42 * operations to ktrace system call (KTROP(op))
43 */
44 #define KTROP_SET 0 /* set trace points */
45 #define KTROP_CLEAR 1 /* clear trace points */
46 #define KTROP_CLEARFILE 2 /* stop all tracing to file */
47 #define KTROP(o) ((o)&3) /* macro to extract operation */
48 /*
49 * flags (ORed in with operation)
50 */
51 #define KTRFLAG_DESCEND 4 /* perform op on all children too */
52
53 /*
54 * ktrace record header
55 */
56 struct ktr_header_v0 {
57 int ktr_len; /* length of buf */
58 short ktr_type; /* trace record type */
59 pid_t ktr_pid; /* process id */
60 char ktr_comm[MAXCOMLEN + 1];/* command name */
61 struct timeval ktr_time; /* timestamp */
62 long ktr_tid; /* thread id */
63 };
64
65 struct ktr_header {
66 int ktr_len; /* length of buf */
67 short ktr_type; /* trace record type */
68 short ktr_version; /* ktr_header version */
69 pid_t ktr_pid; /* process id */
70 char ktr_comm[MAXCOMLEN + 1];/* command name */
71 struct timespec ktr_time; /* timestamp */
72 /* XXX: make ktr_tid an lwpid_t on next ABI break */
73 long ktr_tid; /* thread id */
74 int ktr_cpu; /* cpu id */
75 };
76
77 #define KTR_VERSION0 0
78 #define KTR_VERSION1 1
79 #define KTR_OFFSET_V0 sizeof(struct ktr_header_v0) - \
80 sizeof(struct ktr_header)
81 /*
82 * Test for kernel trace point (MP SAFE).
83 *
84 * KTRCHECK() just checks that the type is enabled and is only for
85 * internal use in the ktrace subsystem. KTRPOINT() checks against
86 * ktrace recursion as well as checking that the type is enabled and
87 * is the public interface.
88 */
89 #define KTRCHECK(td, type) ((td)->td_proc->p_traceflag & (1 << type))
90 #define KTRPOINT(td, type) (__predict_false(KTRCHECK((td), (type))))
91 #define KTRUSERRET(td) do { \
92 if (__predict_false(!STAILQ_EMPTY_ATOMIC(&(td)->td_proc->p_ktr))) \
93 ktruserret(td); \
94 } while (0)
95
96 /*
97 * ktrace record types
98 */
99
100 /*
101 * KTR_SYSCALL - system call record
102 */
103 #define KTR_SYSCALL 1
104 struct ktr_syscall {
105 short ktr_code; /* syscall number */
106 short ktr_narg; /* number of arguments */
107 /*
108 * followed by ktr_narg register_t
109 */
110 register_t ktr_args[1];
111 };
112
113 /*
114 * KTR_SYSRET - return from system call record
115 */
116 #define KTR_SYSRET 2
117 struct ktr_sysret {
118 short ktr_code;
119 short ktr_eosys;
120 int ktr_error;
121 register_t ktr_retval;
122 };
123
124 /*
125 * KTR_NAMEI - namei record
126 */
127 #define KTR_NAMEI 3
128 /* record contains pathname */
129
130 /*
131 * KTR_GENIO - trace generic process i/o
132 */
133 #define KTR_GENIO 4
134 struct ktr_genio {
135 int ktr_fd;
136 enum uio_rw ktr_rw;
137 /*
138 * followed by data successfully read/written
139 */
140 };
141
142 /*
143 * KTR_PSIG - trace processed signal
144 */
145 #define KTR_PSIG 5
146 struct ktr_psig {
147 int signo;
148 sig_t action;
149 int code;
150 sigset_t mask;
151 };
152
153 /*
154 * KTR_CSW - trace context switches
155 */
156 #define KTR_CSW 6
157 struct ktr_csw_old {
158 int out; /* 1 if switch out, 0 if switch in */
159 int user; /* 1 if usermode (ivcsw), 0 if kernel (vcsw) */
160 };
161
162 struct ktr_csw {
163 int out; /* 1 if switch out, 0 if switch in */
164 int user; /* 1 if usermode (ivcsw), 0 if kernel (vcsw) */
165 char wmesg[8];
166 };
167
168 /*
169 * KTR_USER - data coming from userland
170 */
171 #define KTR_USER_MAXLEN 2048 /* maximum length of passed data */
172 #define KTR_USER 7
173
174 /*
175 * KTR_STRUCT - misc. structs
176 */
177 #define KTR_STRUCT 8
178 /*
179 * record contains null-terminated struct name followed by
180 * struct contents
181 */
182 struct sockaddr;
183 struct stat;
184 struct sysentvec;
185
186 /*
187 * KTR_SYSCTL - name of a sysctl MIB
188 */
189 #define KTR_SYSCTL 9
190 /* record contains null-terminated MIB name */
191
192 /*
193 * KTR_PROCCTOR - trace process creation (multiple ABI support)
194 */
195 #define KTR_PROCCTOR 10
196 struct ktr_proc_ctor {
197 u_int sv_flags; /* struct sysentvec sv_flags copy */
198 };
199
200 /*
201 * KTR_PROCDTOR - trace process destruction (multiple ABI support)
202 */
203 #define KTR_PROCDTOR 11
204
205 /*
206 * KTR_CAPFAIL - trace capability check failures
207 */
208 #define KTR_CAPFAIL 12
209 enum ktr_cap_violation {
210 CAPFAIL_NOTCAPABLE, /* insufficient capabilities in cap_check() */
211 CAPFAIL_INCREASE, /* attempt to increase rights on a capability */
212 CAPFAIL_SYSCALL, /* disallowed system call */
213 CAPFAIL_SIGNAL, /* sent signal to process other than self */
214 CAPFAIL_PROTO, /* disallowed protocol */
215 CAPFAIL_SOCKADDR, /* restricted address lookup */
216 CAPFAIL_NAMEI, /* restricted namei lookup */
217 CAPFAIL_CPUSET, /* restricted CPU set modification */
218 };
219
220 union ktr_cap_data {
221 cap_rights_t cap_rights[2];
222 #define cap_needed cap_rights[0]
223 #define cap_held cap_rights[1]
224 int cap_int;
225 struct sockaddr cap_sockaddr;
226 char cap_path[MAXPATHLEN];
227 };
228
229 struct ktr_cap_fail {
230 enum ktr_cap_violation cap_type;
231 short cap_code;
232 u_int cap_svflags;
233 union ktr_cap_data cap_data;
234 };
235
236 /*
237 * KTR_FAULT - page fault record
238 */
239 #define KTR_FAULT 13
240 struct ktr_fault {
241 vm_offset_t vaddr;
242 int type;
243 };
244
245 /*
246 * KTR_FAULTEND - end of page fault record
247 */
248 #define KTR_FAULTEND 14
249 struct ktr_faultend {
250 int result;
251 };
252
253 /*
254 * KTR_STRUCT_ARRAY - array of misc. structs
255 */
256 #define KTR_STRUCT_ARRAY 15
257 struct ktr_struct_array {
258 size_t struct_size;
259 /*
260 * Followed by null-terminated structure name and then payload
261 * contents.
262 */
263 };
264
265 /*
266 * KTR_ARGS - arguments of execve()
267 */
268 #define KTR_ARGS 16
269
270 /*
271 * KTR_ENVS - environment variables of execve()
272 */
273 #define KTR_ENVS 17
274
275 /*
276 * KTR_DROP - If this bit is set in ktr_type, then at least one event
277 * between the previous record and this record was dropped.
278 */
279 #define KTR_DROP 0x8000
280 /*
281 * KTR_VERSIONED - If this bit is set in ktr_type, then the kernel
282 * exposes the new struct ktr_header (versioned), otherwise the old
283 * struct ktr_header_v0 is exposed.
284 */
285 #define KTR_VERSIONED 0x4000
286 #define KTR_TYPE (KTR_DROP | KTR_VERSIONED)
287
288 /*
289 * kernel trace points (in p_traceflag)
290 */
291 #define KTRFAC_MASK 0x00ffffff
292 #define KTRFAC_SYSCALL (1<<KTR_SYSCALL)
293 #define KTRFAC_SYSRET (1<<KTR_SYSRET)
294 #define KTRFAC_NAMEI (1<<KTR_NAMEI)
295 #define KTRFAC_GENIO (1<<KTR_GENIO)
296 #define KTRFAC_PSIG (1<<KTR_PSIG)
297 #define KTRFAC_CSW (1<<KTR_CSW)
298 #define KTRFAC_USER (1<<KTR_USER)
299 #define KTRFAC_STRUCT (1<<KTR_STRUCT)
300 #define KTRFAC_SYSCTL (1<<KTR_SYSCTL)
301 #define KTRFAC_PROCCTOR (1<<KTR_PROCCTOR)
302 #define KTRFAC_PROCDTOR (1<<KTR_PROCDTOR)
303 #define KTRFAC_CAPFAIL (1<<KTR_CAPFAIL)
304 #define KTRFAC_FAULT (1<<KTR_FAULT)
305 #define KTRFAC_FAULTEND (1<<KTR_FAULTEND)
306 #define KTRFAC_STRUCT_ARRAY (1<<KTR_STRUCT_ARRAY)
307 #define KTRFAC_ARGS (1<<KTR_ARGS)
308 #define KTRFAC_ENVS (1<<KTR_ENVS)
309
310 /*
311 * trace flags (also in p_traceflags)
312 */
313 #define KTRFAC_ROOT 0x80000000 /* root set this trace */
314 #define KTRFAC_INHERIT 0x40000000 /* pass trace flags to children */
315 #define KTRFAC_DROP 0x20000000 /* last event was dropped */
316
317 #ifdef _KERNEL
318 struct ktr_io_params;
319
320 #ifdef KTRACE
321 struct vnode *ktr_get_tracevp(struct proc *, bool);
322 #else
323 static inline struct vnode *
ktr_get_tracevp(struct proc * p,bool ref)324 ktr_get_tracevp(struct proc *p, bool ref)
325 {
326
327 return (NULL);
328 }
329 #endif
330 void ktr_io_params_free(struct ktr_io_params *);
331 void ktrnamei(const char *);
332 void ktrcsw(int, int, const char *);
333 void ktrpsig(int, sig_t, sigset_t *, int);
334 void ktrfault(vm_offset_t, int);
335 void ktrfaultend(int);
336 void ktrgenio(int, enum uio_rw, struct uio *, int);
337 void ktrsyscall(int, int narg, syscallarg_t args[]);
338 void ktrsysctl(int *name, u_int namelen);
339 void ktrsysret(int, int, register_t);
340 void ktrprocctor(struct proc *);
341 struct ktr_io_params *ktrprocexec(struct proc *);
342 void ktrprocexit(struct thread *);
343 void ktrprocfork(struct proc *, struct proc *);
344 void ktruserret(struct thread *);
345 void ktrstruct(const char *, const void *, size_t);
346 void ktrstruct_error(const char *, const void *, size_t, int);
347 void ktrstructarray(const char *, enum uio_seg, const void *, int, size_t);
348 void ktrcapfail(enum ktr_cap_violation, const void *);
349 void ktrdata(int, const void *, size_t);
350 #define ktrcaprights(s) \
351 ktrstruct("caprights", (s), sizeof(cap_rights_t))
352 #define ktritimerval(s) \
353 ktrstruct("itimerval", (s), sizeof(struct itimerval))
354 #define ktrsockaddr(s) \
355 ktrstruct("sockaddr", (s), ((struct sockaddr *)(s))->sa_len)
356 #define ktrstat(s) \
357 ktrstruct("stat", (s), sizeof(struct stat))
358 #define ktrstat_error(s, error) \
359 ktrstruct_error("stat", (s), sizeof(struct stat), error)
360 #define ktrcpuset(s, l) \
361 ktrstruct("cpuset_t", (s), l)
362 #define ktrsplice(s) \
363 ktrstruct("splice", (s), sizeof(struct splice))
364 extern u_int ktr_geniosize;
365 #ifdef KTRACE
366 extern int ktr_filesize_limit_signal;
367 #define __ktrace_used
368 #else
369 #define ktr_filesize_limit_signal 0
370 #define __ktrace_used __unused
371 #endif
372 #else
373
374 #include <sys/cdefs.h>
375
376 __BEGIN_DECLS
377 int ktrace(const char *, int, int, pid_t);
378 int utrace(const void *, size_t);
379 __END_DECLS
380
381 #endif
382
383 #endif
384