xref: /freebsd/sys/dev/filemon/filemon.c (revision 596596fec79f04e1f413850b44159224ff1fb8dc)
1 /*-
2  * Copyright (c) 2011, David E. O'Brien.
3  * Copyright (c) 2009-2011, Juniper Networks, Inc.
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer.
11  * 2. Redistributions in binary form must reproduce the above copyright
12  *    notice, this list of conditions and the following disclaimer in the
13  *    documentation and/or other materials provided with the distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY JUNIPER NETWORKS AND CONTRIBUTORS ``AS IS'' AND
16  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18  * ARE DISCLAIMED. IN NO EVENT SHALL JUNIPER NETWORKS OR CONTRIBUTORS BE LIABLE
19  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25  * SUCH DAMAGE.
26  */
27 
28 #include <sys/cdefs.h>
29 __FBSDID("$FreeBSD$");
30 
31 #include "opt_compat.h"
32 
33 #include <sys/param.h>
34 #include <sys/file.h>
35 #include <sys/systm.h>
36 #include <sys/buf.h>
37 #include <sys/condvar.h>
38 #include <sys/conf.h>
39 #include <sys/fcntl.h>
40 #include <sys/ioccom.h>
41 #include <sys/kernel.h>
42 #include <sys/malloc.h>
43 #include <sys/module.h>
44 #include <sys/mutex.h>
45 #include <sys/poll.h>
46 #include <sys/proc.h>
47 #include <sys/queue.h>
48 #include <sys/syscall.h>
49 #include <sys/sysent.h>
50 #include <sys/sysproto.h>
51 #include <sys/uio.h>
52 
53 #if __FreeBSD_version >= 900041
54 #include <sys/capsicum.h>
55 #endif
56 
57 #include "filemon.h"
58 
59 #if defined(COMPAT_IA32) || defined(COMPAT_FREEBSD32) || defined(COMPAT_ARCH32)
60 #include <compat/freebsd32/freebsd32_syscall.h>
61 #include <compat/freebsd32/freebsd32_proto.h>
62 
63 extern struct sysentvec ia32_freebsd_sysvec;
64 #endif
65 
66 extern struct sysentvec elf32_freebsd_sysvec;
67 extern struct sysentvec elf64_freebsd_sysvec;
68 
69 static d_close_t	filemon_close;
70 static d_ioctl_t	filemon_ioctl;
71 static d_open_t		filemon_open;
72 static int		filemon_unload(void);
73 static void		filemon_load(void *);
74 
75 static struct cdevsw filemon_cdevsw = {
76 	.d_version	= D_VERSION,
77 	.d_close	= filemon_close,
78 	.d_ioctl	= filemon_ioctl,
79 	.d_open		= filemon_open,
80 	.d_name		= "filemon",
81 };
82 
83 MALLOC_DECLARE(M_FILEMON);
84 MALLOC_DEFINE(M_FILEMON, "filemon", "File access monitor");
85 
86 struct filemon {
87 	TAILQ_ENTRY(filemon) link;	/* Link into the in-use list. */
88 	struct mtx	mtx;		/* Lock mutex for this filemon. */
89 	struct cv	cv;		/* Lock condition variable for this
90 					   filemon. */
91 	struct file	*fp;		/* Output file pointer. */
92 	struct thread	*locker;	/* Ptr to the thread locking this
93 					   filemon. */
94 	pid_t		pid;		/* The process ID being monitored. */
95 	char		fname1[MAXPATHLEN]; /* Temporary filename buffer. */
96 	char		fname2[MAXPATHLEN]; /* Temporary filename buffer. */
97 	char		msgbufr[1024];	/* Output message buffer. */
98 };
99 
100 static TAILQ_HEAD(, filemon) filemons_inuse = TAILQ_HEAD_INITIALIZER(filemons_inuse);
101 static TAILQ_HEAD(, filemon) filemons_free = TAILQ_HEAD_INITIALIZER(filemons_free);
102 static int n_readers = 0;
103 static struct mtx access_mtx;
104 static struct cv access_cv;
105 static struct thread *access_owner = NULL;
106 static struct thread *access_requester = NULL;
107 
108 static struct cdev *filemon_dev;
109 
110 #include "filemon_lock.c"
111 #include "filemon_wrapper.c"
112 
113 static void
114 filemon_dtr(void *data)
115 {
116 	struct filemon *filemon = data;
117 
118 	if (filemon != NULL) {
119 		struct file *fp = filemon->fp;
120 
121 		/* Get exclusive write access. */
122 		filemon_lock_write();
123 
124 		/* Remove from the in-use list. */
125 		TAILQ_REMOVE(&filemons_inuse, filemon, link);
126 
127 		filemon->fp = NULL;
128 		filemon->pid = -1;
129 
130 		/* Add to the free list. */
131 		TAILQ_INSERT_TAIL(&filemons_free, filemon, link);
132 
133 		/* Give up write access. */
134 		filemon_unlock_write();
135 
136 		if (fp != NULL)
137 			fdrop(fp, curthread);
138 	}
139 }
140 
141 static int
142 filemon_ioctl(struct cdev *dev, u_long cmd, caddr_t data, int flag __unused,
143     struct thread *td)
144 {
145 	int error = 0;
146 	struct filemon *filemon;
147 	struct proc *p;
148 #if __FreeBSD_version >= 900041
149 	cap_rights_t rights;
150 #endif
151 
152 	devfs_get_cdevpriv((void **) &filemon);
153 
154 	switch (cmd) {
155 	/* Set the output file descriptor. */
156 	case FILEMON_SET_FD:
157 		error = fget_write(td, *(int *)data,
158 #if __FreeBSD_version >= 900041
159 		    cap_rights_init(&rights, CAP_PWRITE),
160 #endif
161 		    &filemon->fp);
162 		if (error == 0)
163 			/* Write the file header. */
164 			filemon_comment(filemon);
165 		break;
166 
167 	/* Set the monitored process ID. */
168 	case FILEMON_SET_PID:
169 		error = pget(*((pid_t *)data), PGET_CANDEBUG | PGET_NOTWEXIT,
170 		    &p);
171 		if (error == 0) {
172 			filemon->pid = p->p_pid;
173 			PROC_UNLOCK(p);
174 		}
175 		break;
176 
177 	default:
178 		error = EINVAL;
179 		break;
180 	}
181 
182 	return (error);
183 }
184 
185 static int
186 filemon_open(struct cdev *dev, int oflags __unused, int devtype __unused,
187     struct thread *td __unused)
188 {
189 	struct filemon *filemon;
190 
191 	/* Get exclusive write access. */
192 	filemon_lock_write();
193 
194 	if ((filemon = TAILQ_FIRST(&filemons_free)) != NULL)
195 		TAILQ_REMOVE(&filemons_free, filemon, link);
196 
197 	/* Give up write access. */
198 	filemon_unlock_write();
199 
200 	if (filemon == NULL) {
201 		filemon = malloc(sizeof(struct filemon), M_FILEMON,
202 		    M_WAITOK | M_ZERO);
203 
204 		filemon->fp = NULL;
205 
206 		mtx_init(&filemon->mtx, "filemon", "filemon", MTX_DEF);
207 		cv_init(&filemon->cv, "filemon");
208 	}
209 
210 	filemon->pid = curproc->p_pid;
211 
212 	devfs_set_cdevpriv(filemon, filemon_dtr);
213 
214 	/* Get exclusive write access. */
215 	filemon_lock_write();
216 
217 	/* Add to the in-use list. */
218 	TAILQ_INSERT_TAIL(&filemons_inuse, filemon, link);
219 
220 	/* Give up write access. */
221 	filemon_unlock_write();
222 
223 	return (0);
224 }
225 
226 static int
227 filemon_close(struct cdev *dev __unused, int flag __unused, int fmt __unused,
228     struct thread *td __unused)
229 {
230 
231 	return (0);
232 }
233 
234 static void
235 filemon_load(void *dummy __unused)
236 {
237 	mtx_init(&access_mtx, "filemon", "filemon", MTX_DEF);
238 	cv_init(&access_cv, "filemon");
239 
240 	/* Install the syscall wrappers. */
241 	filemon_wrapper_install();
242 
243 	filemon_dev = make_dev(&filemon_cdevsw, 0, UID_ROOT, GID_WHEEL, 0666,
244 	    "filemon");
245 }
246 
247 static int
248 filemon_unload(void)
249 {
250  	struct filemon *filemon;
251 	int error = 0;
252 
253 	/* Get exclusive write access. */
254 	filemon_lock_write();
255 
256 	if (TAILQ_FIRST(&filemons_inuse) != NULL)
257 		error = EBUSY;
258 	else {
259 		destroy_dev(filemon_dev);
260 
261 		/* Deinstall the syscall wrappers. */
262 		filemon_wrapper_deinstall();
263 	}
264 
265 	/* Give up write access. */
266 	filemon_unlock_write();
267 
268 	if (error == 0) {
269 		/* free() filemon structs free list. */
270 		filemon_lock_write();
271 		while ((filemon = TAILQ_FIRST(&filemons_free)) != NULL) {
272 			TAILQ_REMOVE(&filemons_free, filemon, link);
273 			mtx_destroy(&filemon->mtx);
274 			cv_destroy(&filemon->cv);
275 			free(filemon, M_FILEMON);
276 		}
277 		filemon_unlock_write();
278 
279 		mtx_destroy(&access_mtx);
280 		cv_destroy(&access_cv);
281 	}
282 
283 	return (error);
284 }
285 
286 static int
287 filemon_modevent(module_t mod __unused, int type, void *data)
288 {
289 	int error = 0;
290 
291 	switch (type) {
292 	case MOD_LOAD:
293 		filemon_load(data);
294 		break;
295 
296 	case MOD_UNLOAD:
297 		error = filemon_unload();
298 		break;
299 
300 	case MOD_SHUTDOWN:
301 		break;
302 
303 	default:
304 		error = EOPNOTSUPP;
305 		break;
306 
307 	}
308 
309 	return (error);
310 }
311 
312 DEV_MODULE(filemon, filemon_modevent, NULL);
313 MODULE_VERSION(filemon, 1);
314