1 /*- 2 * Copyright (c) 1988, 1993 3 * The Regents of the University of California. All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 3. Neither the name of the University nor the names of its contributors 14 * may be used to endorse or promote products derived from this software 15 * without specific prior written permission. 16 * 17 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 18 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 19 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 20 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 21 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 22 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 23 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 24 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 25 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 26 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 27 * SUCH DAMAGE. 28 */ 29 30 #ifndef lint 31 static const char copyright[] = 32 "@(#) Copyright (c) 1988, 1993\n\ 33 The Regents of the University of California. All rights reserved.\n"; 34 #endif /* not lint */ 35 36 #ifndef lint 37 #if 0 38 static char sccsid[] = "@(#)kdump.c 8.1 (Berkeley) 6/6/93"; 39 #endif 40 #endif /* not lint */ 41 #include <sys/cdefs.h> 42 __FBSDID("$FreeBSD$"); 43 44 #define _WANT_KERNEL_ERRNO 45 #include <sys/param.h> 46 #include <sys/capsicum.h> 47 #include <sys/errno.h> 48 #include <sys/time.h> 49 #include <sys/uio.h> 50 #include <sys/ktrace.h> 51 #include <sys/ioctl.h> 52 #include <sys/socket.h> 53 #include <sys/stat.h> 54 #include <sys/sysent.h> 55 #include <sys/umtx.h> 56 #include <sys/un.h> 57 #include <sys/queue.h> 58 #include <sys/wait.h> 59 #ifdef WITH_CASPER 60 #include <sys/nv.h> 61 #endif 62 #include <arpa/inet.h> 63 #include <netinet/in.h> 64 #include <ctype.h> 65 #include <capsicum_helpers.h> 66 #include <err.h> 67 #include <grp.h> 68 #include <inttypes.h> 69 #include <locale.h> 70 #include <netdb.h> 71 #include <nl_types.h> 72 #include <pwd.h> 73 #include <stddef.h> 74 #include <stdio.h> 75 #include <stdlib.h> 76 #include <string.h> 77 #include <sysdecode.h> 78 #include <time.h> 79 #include <unistd.h> 80 #include <vis.h> 81 #include "ktrace.h" 82 83 #ifdef WITH_CASPER 84 #include <libcasper.h> 85 86 #include <casper/cap_grp.h> 87 #include <casper/cap_pwd.h> 88 #endif 89 90 u_int abidump(struct ktr_header *); 91 int fetchprocinfo(struct ktr_header *, u_int *); 92 int fread_tail(void *, int, int); 93 void dumpheader(struct ktr_header *); 94 void ktrsyscall(struct ktr_syscall *, u_int); 95 void ktrsysret(struct ktr_sysret *, u_int); 96 void ktrnamei(char *, int); 97 void hexdump(char *, int, int); 98 void visdump(char *, int, int); 99 void ktrgenio(struct ktr_genio *, int); 100 void ktrpsig(struct ktr_psig *); 101 void ktrcsw(struct ktr_csw *); 102 void ktrcsw_old(struct ktr_csw_old *); 103 void ktruser(int, void *); 104 void ktrcaprights(cap_rights_t *); 105 void ktritimerval(struct itimerval *it); 106 void ktrsockaddr(struct sockaddr *); 107 void ktrstat(struct stat *); 108 void ktrstruct(char *, size_t); 109 void ktrcapfail(struct ktr_cap_fail *); 110 void ktrfault(struct ktr_fault *); 111 void ktrfaultend(struct ktr_faultend *); 112 void usage(void); 113 114 #define TIMESTAMP_NONE 0x0 115 #define TIMESTAMP_ABSOLUTE 0x1 116 #define TIMESTAMP_ELAPSED 0x2 117 #define TIMESTAMP_RELATIVE 0x4 118 119 static int timestamp, decimal, fancy = 1, suppressdata, tail, threads, maxdata, 120 resolv = 0, abiflag = 0, syscallno = 0; 121 static const char *tracefile = DEF_TRACEFILE; 122 static struct ktr_header ktr_header; 123 124 #define TIME_FORMAT "%b %e %T %Y" 125 #define eqs(s1, s2) (strcmp((s1), (s2)) == 0) 126 127 #define print_number64(first,i,n,c) do { \ 128 uint64_t __v; \ 129 \ 130 if (quad_align && (((ptrdiff_t)((i) - (first))) & 1) == 1) { \ 131 (i)++; \ 132 (n)--; \ 133 } \ 134 if (quad_slots == 2) \ 135 __v = (uint64_t)(uint32_t)(i)[0] | \ 136 ((uint64_t)(uint32_t)(i)[1]) << 32; \ 137 else \ 138 __v = (uint64_t)*(i); \ 139 if (decimal) \ 140 printf("%c%jd", (c), (intmax_t)__v); \ 141 else \ 142 printf("%c%#jx", (c), (uintmax_t)__v); \ 143 (i) += quad_slots; \ 144 (n) -= quad_slots; \ 145 (c) = ','; \ 146 } while (0) 147 148 #define print_number(i,n,c) do { \ 149 if (decimal) \ 150 printf("%c%jd", c, (intmax_t)*i); \ 151 else \ 152 printf("%c%#jx", c, (uintmax_t)(u_register_t)*i); \ 153 i++; \ 154 n--; \ 155 c = ','; \ 156 } while (0) 157 158 struct proc_info 159 { 160 TAILQ_ENTRY(proc_info) info; 161 u_int sv_flags; 162 pid_t pid; 163 }; 164 165 static TAILQ_HEAD(trace_procs, proc_info) trace_procs; 166 167 #ifdef WITH_CASPER 168 static cap_channel_t *cappwd, *capgrp; 169 #endif 170 171 static void 172 strerror_init(void) 173 { 174 175 /* 176 * Cache NLS data before entering capability mode. 177 * XXXPJD: There should be strerror_init() and strsignal_init() in libc. 178 */ 179 (void)catopen("libc", NL_CAT_LOCALE); 180 } 181 182 static void 183 localtime_init(void) 184 { 185 time_t ltime; 186 187 /* 188 * Allow localtime(3) to cache /etc/localtime content before entering 189 * capability mode. 190 * XXXPJD: There should be localtime_init() in libc. 191 */ 192 (void)time(<ime); 193 (void)localtime(<ime); 194 } 195 196 #ifdef WITH_CASPER 197 static int 198 cappwdgrp_setup(cap_channel_t **cappwdp, cap_channel_t **capgrpp) 199 { 200 cap_channel_t *capcas, *cappwdloc, *capgrploc; 201 const char *cmds[1], *fields[1]; 202 203 capcas = cap_init(); 204 if (capcas == NULL) { 205 err(1, "unable to create casper process"); 206 exit(1); 207 } 208 cappwdloc = cap_service_open(capcas, "system.pwd"); 209 capgrploc = cap_service_open(capcas, "system.grp"); 210 /* Casper capability no longer needed. */ 211 cap_close(capcas); 212 if (cappwdloc == NULL || capgrploc == NULL) { 213 if (cappwdloc == NULL) 214 warn("unable to open system.pwd service"); 215 if (capgrploc == NULL) 216 warn("unable to open system.grp service"); 217 exit(1); 218 } 219 /* Limit system.pwd to only getpwuid() function and pw_name field. */ 220 cmds[0] = "getpwuid"; 221 if (cap_pwd_limit_cmds(cappwdloc, cmds, 1) < 0) 222 err(1, "unable to limit system.pwd service"); 223 fields[0] = "pw_name"; 224 if (cap_pwd_limit_fields(cappwdloc, fields, 1) < 0) 225 err(1, "unable to limit system.pwd service"); 226 /* Limit system.grp to only getgrgid() function and gr_name field. */ 227 cmds[0] = "getgrgid"; 228 if (cap_grp_limit_cmds(capgrploc, cmds, 1) < 0) 229 err(1, "unable to limit system.grp service"); 230 fields[0] = "gr_name"; 231 if (cap_grp_limit_fields(capgrploc, fields, 1) < 0) 232 err(1, "unable to limit system.grp service"); 233 234 *cappwdp = cappwdloc; 235 *capgrpp = capgrploc; 236 return (0); 237 } 238 #endif /* WITH_CASPER */ 239 240 static void 241 print_integer_arg(const char *(*decoder)(int), int value) 242 { 243 const char *str; 244 245 str = decoder(value); 246 if (str != NULL) 247 printf("%s", str); 248 else { 249 if (decimal) 250 printf("<invalid=%d>", value); 251 else 252 printf("<invalid=%#x>", value); 253 } 254 } 255 256 /* Like print_integer_arg but unknown values are treated as valid. */ 257 static void 258 print_integer_arg_valid(const char *(*decoder)(int), int value) 259 { 260 const char *str; 261 262 str = decoder(value); 263 if (str != NULL) 264 printf("%s", str); 265 else { 266 if (decimal) 267 printf("%d", value); 268 else 269 printf("%#x", value); 270 } 271 } 272 273 static void 274 print_mask_arg(bool (*decoder)(FILE *, int, int *), int value) 275 { 276 bool invalid; 277 int rem; 278 279 printf("%#x<", value); 280 invalid = !decoder(stdout, value, &rem); 281 printf(">"); 282 if (invalid) 283 printf("<invalid>%u", rem); 284 } 285 286 static void 287 print_mask_arg0(bool (*decoder)(FILE *, int, int *), int value) 288 { 289 bool invalid; 290 int rem; 291 292 if (value == 0) { 293 printf("0"); 294 return; 295 } 296 printf("%#x<", value); 297 invalid = !decoder(stdout, value, &rem); 298 printf(">"); 299 if (invalid) 300 printf("<invalid>%u", rem); 301 } 302 303 static void 304 decode_fileflags(fflags_t value) 305 { 306 bool invalid; 307 fflags_t rem; 308 309 if (value == 0) { 310 printf("0"); 311 return; 312 } 313 printf("%#x<", value); 314 invalid = !sysdecode_fileflags(stdout, value, &rem); 315 printf(">"); 316 if (invalid) 317 printf("<invalid>%u", rem); 318 } 319 320 static void 321 decode_filemode(int value) 322 { 323 bool invalid; 324 int rem; 325 326 if (value == 0) { 327 printf("0"); 328 return; 329 } 330 printf("%#o<", value); 331 invalid = !sysdecode_filemode(stdout, value, &rem); 332 printf(">"); 333 if (invalid) 334 printf("<invalid>%u", rem); 335 } 336 337 static void 338 print_mask_arg32(bool (*decoder)(FILE *, uint32_t, uint32_t *), uint32_t value) 339 { 340 bool invalid; 341 uint32_t rem; 342 343 printf("%#x<", value); 344 invalid = !decoder(stdout, value, &rem); 345 printf(">"); 346 if (invalid) 347 printf("<invalid>%u", rem); 348 } 349 350 static void 351 print_mask_argul(bool (*decoder)(FILE *, u_long, u_long *), u_long value) 352 { 353 bool invalid; 354 u_long rem; 355 356 if (value == 0) { 357 printf("0"); 358 return; 359 } 360 printf("%#lx<", value); 361 invalid = !decoder(stdout, value, &rem); 362 printf(">"); 363 if (invalid) 364 printf("<invalid>%lu", rem); 365 } 366 367 int 368 main(int argc, char *argv[]) 369 { 370 int ch, ktrlen, size; 371 void *m; 372 int trpoints = ALL_POINTS; 373 int drop_logged; 374 pid_t pid = 0; 375 u_int sv_flags; 376 377 setlocale(LC_CTYPE, ""); 378 379 timestamp = TIMESTAMP_NONE; 380 381 while ((ch = getopt(argc,argv,"f:dElm:np:AHRrSsTt:")) != -1) 382 switch (ch) { 383 case 'A': 384 abiflag = 1; 385 break; 386 case 'f': 387 tracefile = optarg; 388 break; 389 case 'd': 390 decimal = 1; 391 break; 392 case 'l': 393 tail = 1; 394 break; 395 case 'm': 396 maxdata = atoi(optarg); 397 break; 398 case 'n': 399 fancy = 0; 400 break; 401 case 'p': 402 pid = atoi(optarg); 403 break; 404 case 'r': 405 resolv = 1; 406 break; 407 case 'S': 408 syscallno = 1; 409 break; 410 case 's': 411 suppressdata = 1; 412 break; 413 case 'E': 414 timestamp |= TIMESTAMP_ELAPSED; 415 break; 416 case 'H': 417 threads = 1; 418 break; 419 case 'R': 420 timestamp |= TIMESTAMP_RELATIVE; 421 break; 422 case 'T': 423 timestamp |= TIMESTAMP_ABSOLUTE; 424 break; 425 case 't': 426 trpoints = getpoints(optarg); 427 if (trpoints < 0) 428 errx(1, "unknown trace point in %s", optarg); 429 break; 430 default: 431 usage(); 432 } 433 434 if (argc > optind) 435 usage(); 436 437 m = malloc(size = 1025); 438 if (m == NULL) 439 errx(1, "%s", strerror(ENOMEM)); 440 if (strcmp(tracefile, "-") != 0) 441 if (!freopen(tracefile, "r", stdin)) 442 err(1, "%s", tracefile); 443 444 strerror_init(); 445 localtime_init(); 446 #ifdef WITH_CASPER 447 if (resolv != 0) { 448 if (cappwdgrp_setup(&cappwd, &capgrp) < 0) { 449 cappwd = NULL; 450 capgrp = NULL; 451 } 452 } 453 if (resolv == 0 || (cappwd != NULL && capgrp != NULL)) { 454 if (cap_enter() < 0 && errno != ENOSYS) 455 err(1, "unable to enter capability mode"); 456 } 457 #else 458 if (resolv == 0) { 459 if (cap_enter() < 0 && errno != ENOSYS) 460 err(1, "unable to enter capability mode"); 461 } 462 #endif 463 if (caph_limit_stdio() == -1) 464 err(1, "unable to limit stdio"); 465 466 TAILQ_INIT(&trace_procs); 467 drop_logged = 0; 468 while (fread_tail(&ktr_header, sizeof(struct ktr_header), 1)) { 469 if (ktr_header.ktr_type & KTR_DROP) { 470 ktr_header.ktr_type &= ~KTR_DROP; 471 if (!drop_logged && threads) { 472 printf( 473 "%6jd %6jd %-8.*s Events dropped.\n", 474 (intmax_t)ktr_header.ktr_pid, 475 ktr_header.ktr_tid > 0 ? 476 (intmax_t)ktr_header.ktr_tid : 0, 477 MAXCOMLEN, ktr_header.ktr_comm); 478 drop_logged = 1; 479 } else if (!drop_logged) { 480 printf("%6jd %-8.*s Events dropped.\n", 481 (intmax_t)ktr_header.ktr_pid, MAXCOMLEN, 482 ktr_header.ktr_comm); 483 drop_logged = 1; 484 } 485 } 486 if (trpoints & (1<<ktr_header.ktr_type)) 487 if (pid == 0 || ktr_header.ktr_pid == pid || 488 ktr_header.ktr_tid == pid) 489 dumpheader(&ktr_header); 490 if ((ktrlen = ktr_header.ktr_len) < 0) 491 errx(1, "bogus length 0x%x", ktrlen); 492 if (ktrlen > size) { 493 m = realloc(m, ktrlen+1); 494 if (m == NULL) 495 errx(1, "%s", strerror(ENOMEM)); 496 size = ktrlen; 497 } 498 if (ktrlen && fread_tail(m, ktrlen, 1) == 0) 499 errx(1, "data too short"); 500 if (fetchprocinfo(&ktr_header, (u_int *)m) != 0) 501 continue; 502 sv_flags = abidump(&ktr_header); 503 if (pid && ktr_header.ktr_pid != pid && 504 ktr_header.ktr_tid != pid) 505 continue; 506 if ((trpoints & (1<<ktr_header.ktr_type)) == 0) 507 continue; 508 drop_logged = 0; 509 switch (ktr_header.ktr_type) { 510 case KTR_SYSCALL: 511 ktrsyscall((struct ktr_syscall *)m, sv_flags); 512 break; 513 case KTR_SYSRET: 514 ktrsysret((struct ktr_sysret *)m, sv_flags); 515 break; 516 case KTR_NAMEI: 517 case KTR_SYSCTL: 518 ktrnamei(m, ktrlen); 519 break; 520 case KTR_GENIO: 521 ktrgenio((struct ktr_genio *)m, ktrlen); 522 break; 523 case KTR_PSIG: 524 ktrpsig((struct ktr_psig *)m); 525 break; 526 case KTR_CSW: 527 if (ktrlen == sizeof(struct ktr_csw_old)) 528 ktrcsw_old((struct ktr_csw_old *)m); 529 else 530 ktrcsw((struct ktr_csw *)m); 531 break; 532 case KTR_USER: 533 ktruser(ktrlen, m); 534 break; 535 case KTR_STRUCT: 536 ktrstruct(m, ktrlen); 537 break; 538 case KTR_CAPFAIL: 539 ktrcapfail((struct ktr_cap_fail *)m); 540 break; 541 case KTR_FAULT: 542 ktrfault((struct ktr_fault *)m); 543 break; 544 case KTR_FAULTEND: 545 ktrfaultend((struct ktr_faultend *)m); 546 break; 547 default: 548 printf("\n"); 549 break; 550 } 551 if (tail) 552 fflush(stdout); 553 } 554 return 0; 555 } 556 557 int 558 fread_tail(void *buf, int size, int num) 559 { 560 int i; 561 562 while ((i = fread(buf, size, num, stdin)) == 0 && tail) { 563 sleep(1); 564 clearerr(stdin); 565 } 566 return (i); 567 } 568 569 int 570 fetchprocinfo(struct ktr_header *kth, u_int *flags) 571 { 572 struct proc_info *pi; 573 574 switch (kth->ktr_type) { 575 case KTR_PROCCTOR: 576 TAILQ_FOREACH(pi, &trace_procs, info) { 577 if (pi->pid == kth->ktr_pid) { 578 TAILQ_REMOVE(&trace_procs, pi, info); 579 break; 580 } 581 } 582 pi = malloc(sizeof(struct proc_info)); 583 if (pi == NULL) 584 errx(1, "%s", strerror(ENOMEM)); 585 pi->sv_flags = *flags; 586 pi->pid = kth->ktr_pid; 587 TAILQ_INSERT_TAIL(&trace_procs, pi, info); 588 return (1); 589 590 case KTR_PROCDTOR: 591 TAILQ_FOREACH(pi, &trace_procs, info) { 592 if (pi->pid == kth->ktr_pid) { 593 TAILQ_REMOVE(&trace_procs, pi, info); 594 free(pi); 595 break; 596 } 597 } 598 return (1); 599 } 600 601 return (0); 602 } 603 604 u_int 605 abidump(struct ktr_header *kth) 606 { 607 struct proc_info *pi; 608 const char *abi; 609 const char *arch; 610 u_int flags = 0; 611 612 TAILQ_FOREACH(pi, &trace_procs, info) { 613 if (pi->pid == kth->ktr_pid) { 614 flags = pi->sv_flags; 615 break; 616 } 617 } 618 619 if (abiflag == 0) 620 return (flags); 621 622 switch (flags & SV_ABI_MASK) { 623 case SV_ABI_LINUX: 624 abi = "L"; 625 break; 626 case SV_ABI_FREEBSD: 627 abi = "F"; 628 break; 629 case SV_ABI_CLOUDABI: 630 abi = "C"; 631 break; 632 default: 633 abi = "U"; 634 break; 635 } 636 637 if (flags & SV_LP64) 638 arch = "64"; 639 else if (flags & SV_ILP32) 640 arch = "32"; 641 else 642 arch = "00"; 643 644 printf("%s%s ", abi, arch); 645 646 return (flags); 647 } 648 649 void 650 dumpheader(struct ktr_header *kth) 651 { 652 static char unknown[64]; 653 static struct timeval prevtime, prevtime_e; 654 struct timeval temp; 655 const char *type; 656 const char *sign; 657 658 switch (kth->ktr_type) { 659 case KTR_SYSCALL: 660 type = "CALL"; 661 break; 662 case KTR_SYSRET: 663 type = "RET "; 664 break; 665 case KTR_NAMEI: 666 type = "NAMI"; 667 break; 668 case KTR_GENIO: 669 type = "GIO "; 670 break; 671 case KTR_PSIG: 672 type = "PSIG"; 673 break; 674 case KTR_CSW: 675 type = "CSW "; 676 break; 677 case KTR_USER: 678 type = "USER"; 679 break; 680 case KTR_STRUCT: 681 type = "STRU"; 682 break; 683 case KTR_SYSCTL: 684 type = "SCTL"; 685 break; 686 case KTR_PROCCTOR: 687 /* FALLTHROUGH */ 688 case KTR_PROCDTOR: 689 return; 690 case KTR_CAPFAIL: 691 type = "CAP "; 692 break; 693 case KTR_FAULT: 694 type = "PFLT"; 695 break; 696 case KTR_FAULTEND: 697 type = "PRET"; 698 break; 699 default: 700 sprintf(unknown, "UNKNOWN(%d)", kth->ktr_type); 701 type = unknown; 702 } 703 704 /* 705 * The ktr_tid field was previously the ktr_buffer field, which held 706 * the kernel pointer value for the buffer associated with data 707 * following the record header. It now holds a threadid, but only 708 * for trace files after the change. Older trace files still contain 709 * kernel pointers. Detect this and suppress the results by printing 710 * negative tid's as 0. 711 */ 712 if (threads) 713 printf("%6jd %6jd %-8.*s ", (intmax_t)kth->ktr_pid, 714 kth->ktr_tid > 0 ? (intmax_t)kth->ktr_tid : 0, 715 MAXCOMLEN, kth->ktr_comm); 716 else 717 printf("%6jd %-8.*s ", (intmax_t)kth->ktr_pid, MAXCOMLEN, 718 kth->ktr_comm); 719 if (timestamp) { 720 if (timestamp & TIMESTAMP_ABSOLUTE) { 721 printf("%jd.%06ld ", (intmax_t)kth->ktr_time.tv_sec, 722 kth->ktr_time.tv_usec); 723 } 724 if (timestamp & TIMESTAMP_ELAPSED) { 725 if (prevtime_e.tv_sec == 0) 726 prevtime_e = kth->ktr_time; 727 timersub(&kth->ktr_time, &prevtime_e, &temp); 728 printf("%jd.%06ld ", (intmax_t)temp.tv_sec, 729 temp.tv_usec); 730 } 731 if (timestamp & TIMESTAMP_RELATIVE) { 732 if (prevtime.tv_sec == 0) 733 prevtime = kth->ktr_time; 734 if (timercmp(&kth->ktr_time, &prevtime, <)) { 735 timersub(&prevtime, &kth->ktr_time, &temp); 736 sign = "-"; 737 } else { 738 timersub(&kth->ktr_time, &prevtime, &temp); 739 sign = ""; 740 } 741 prevtime = kth->ktr_time; 742 printf("%s%jd.%06ld ", sign, (intmax_t)temp.tv_sec, 743 temp.tv_usec); 744 } 745 } 746 printf("%s ", type); 747 } 748 749 #include <sys/syscall.h> 750 751 static void 752 ioctlname(unsigned long val) 753 { 754 const char *str; 755 756 str = sysdecode_ioctlname(val); 757 if (str != NULL) 758 printf("%s", str); 759 else if (decimal) 760 printf("%lu", val); 761 else 762 printf("%#lx", val); 763 } 764 765 static enum sysdecode_abi 766 syscallabi(u_int sv_flags) 767 { 768 769 if (sv_flags == 0) 770 return (SYSDECODE_ABI_FREEBSD); 771 switch (sv_flags & SV_ABI_MASK) { 772 case SV_ABI_FREEBSD: 773 return (SYSDECODE_ABI_FREEBSD); 774 #if defined(__amd64__) || defined(__i386__) 775 case SV_ABI_LINUX: 776 #ifdef __amd64__ 777 if (sv_flags & SV_ILP32) 778 return (SYSDECODE_ABI_LINUX32); 779 #endif 780 return (SYSDECODE_ABI_LINUX); 781 #endif 782 #if defined(__aarch64__) || defined(__amd64__) 783 case SV_ABI_CLOUDABI: 784 return (SYSDECODE_ABI_CLOUDABI64); 785 #endif 786 default: 787 return (SYSDECODE_ABI_UNKNOWN); 788 } 789 } 790 791 static void 792 syscallname(u_int code, u_int sv_flags) 793 { 794 const char *name; 795 796 name = sysdecode_syscallname(syscallabi(sv_flags), code); 797 if (name == NULL) 798 printf("[%d]", code); 799 else { 800 printf("%s", name); 801 if (syscallno) 802 printf("[%d]", code); 803 } 804 } 805 806 static void 807 print_signal(int signo) 808 { 809 const char *signame; 810 811 signame = sysdecode_signal(signo); 812 if (signame != NULL) 813 printf("%s", signame); 814 else 815 printf("SIG %d", signo); 816 } 817 818 void 819 ktrsyscall(struct ktr_syscall *ktr, u_int sv_flags) 820 { 821 int narg = ktr->ktr_narg; 822 register_t *ip, *first; 823 intmax_t arg; 824 int quad_align, quad_slots; 825 826 syscallname(ktr->ktr_code, sv_flags); 827 ip = first = &ktr->ktr_args[0]; 828 if (narg) { 829 char c = '('; 830 if (fancy && 831 (sv_flags == 0 || 832 (sv_flags & SV_ABI_MASK) == SV_ABI_FREEBSD)) { 833 quad_align = 0; 834 if (sv_flags & SV_ILP32) { 835 #ifdef __powerpc__ 836 quad_align = 1; 837 #endif 838 quad_slots = 2; 839 } else 840 quad_slots = 1; 841 switch (ktr->ktr_code) { 842 case SYS_bindat: 843 case SYS_chflagsat: 844 case SYS_connectat: 845 case SYS_faccessat: 846 case SYS_fchmodat: 847 case SYS_fchownat: 848 case SYS_fstatat: 849 case SYS_futimesat: 850 case SYS_linkat: 851 case SYS_mkdirat: 852 case SYS_mkfifoat: 853 case SYS_mknodat: 854 case SYS_openat: 855 case SYS_readlinkat: 856 case SYS_renameat: 857 case SYS_unlinkat: 858 case SYS_utimensat: 859 putchar('('); 860 print_integer_arg_valid(sysdecode_atfd, *ip); 861 c = ','; 862 ip++; 863 narg--; 864 break; 865 } 866 switch (ktr->ktr_code) { 867 case SYS_ioctl: { 868 print_number(ip, narg, c); 869 putchar(c); 870 ioctlname(*ip); 871 c = ','; 872 ip++; 873 narg--; 874 break; 875 } 876 case SYS_ptrace: 877 putchar('('); 878 print_integer_arg(sysdecode_ptrace_request, *ip); 879 c = ','; 880 ip++; 881 narg--; 882 break; 883 case SYS_access: 884 case SYS_eaccess: 885 case SYS_faccessat: 886 print_number(ip, narg, c); 887 putchar(','); 888 print_mask_arg(sysdecode_access_mode, *ip); 889 ip++; 890 narg--; 891 break; 892 case SYS_open: 893 case SYS_openat: 894 print_number(ip, narg, c); 895 putchar(','); 896 print_mask_arg(sysdecode_open_flags, ip[0]); 897 if ((ip[0] & O_CREAT) == O_CREAT) { 898 putchar(','); 899 decode_filemode(ip[1]); 900 } 901 ip += 2; 902 narg -= 2; 903 break; 904 case SYS_wait4: 905 print_number(ip, narg, c); 906 print_number(ip, narg, c); 907 putchar(','); 908 print_mask_arg0(sysdecode_wait4_options, *ip); 909 ip++; 910 narg--; 911 break; 912 case SYS_wait6: 913 putchar('('); 914 print_integer_arg(sysdecode_idtype, *ip); 915 c = ','; 916 ip++; 917 narg--; 918 print_number64(first, ip, narg, c); 919 print_number(ip, narg, c); 920 putchar(','); 921 print_mask_arg(sysdecode_wait6_options, *ip); 922 ip++; 923 narg--; 924 break; 925 case SYS_chmod: 926 case SYS_fchmod: 927 case SYS_lchmod: 928 case SYS_fchmodat: 929 print_number(ip, narg, c); 930 putchar(','); 931 decode_filemode(*ip); 932 ip++; 933 narg--; 934 break; 935 case SYS_mknodat: 936 print_number(ip, narg, c); 937 putchar(','); 938 decode_filemode(*ip); 939 ip++; 940 narg--; 941 break; 942 case SYS_getfsstat: 943 print_number(ip, narg, c); 944 print_number(ip, narg, c); 945 putchar(','); 946 print_integer_arg(sysdecode_getfsstat_mode, *ip); 947 ip++; 948 narg--; 949 break; 950 case SYS_mount: 951 print_number(ip, narg, c); 952 print_number(ip, narg, c); 953 putchar(','); 954 print_mask_arg(sysdecode_mount_flags, *ip); 955 ip++; 956 narg--; 957 break; 958 case SYS_unmount: 959 print_number(ip, narg, c); 960 putchar(','); 961 print_mask_arg(sysdecode_mount_flags, *ip); 962 ip++; 963 narg--; 964 break; 965 case SYS_recvmsg: 966 case SYS_sendmsg: 967 print_number(ip, narg, c); 968 print_number(ip, narg, c); 969 putchar(','); 970 print_mask_arg0(sysdecode_msg_flags, *ip); 971 ip++; 972 narg--; 973 break; 974 case SYS_recvfrom: 975 case SYS_sendto: 976 print_number(ip, narg, c); 977 print_number(ip, narg, c); 978 print_number(ip, narg, c); 979 putchar(','); 980 print_mask_arg0(sysdecode_msg_flags, *ip); 981 ip++; 982 narg--; 983 break; 984 case SYS_chflags: 985 case SYS_chflagsat: 986 case SYS_fchflags: 987 case SYS_lchflags: 988 print_number(ip, narg, c); 989 putchar(','); 990 decode_fileflags(*ip); 991 ip++; 992 narg--; 993 break; 994 case SYS_kill: 995 print_number(ip, narg, c); 996 putchar(','); 997 print_signal(*ip); 998 ip++; 999 narg--; 1000 break; 1001 case SYS_reboot: 1002 putchar('('); 1003 print_mask_arg(sysdecode_reboot_howto, *ip); 1004 ip++; 1005 narg--; 1006 break; 1007 case SYS_umask: 1008 putchar('('); 1009 decode_filemode(*ip); 1010 ip++; 1011 narg--; 1012 break; 1013 case SYS_msync: 1014 print_number(ip, narg, c); 1015 print_number(ip, narg, c); 1016 putchar(','); 1017 print_mask_arg(sysdecode_msync_flags, *ip); 1018 ip++; 1019 narg--; 1020 break; 1021 #ifdef SYS_freebsd6_mmap 1022 case SYS_freebsd6_mmap: 1023 print_number(ip, narg, c); 1024 print_number(ip, narg, c); 1025 putchar(','); 1026 print_mask_arg(sysdecode_mmap_prot, *ip); 1027 putchar(','); 1028 ip++; 1029 narg--; 1030 print_mask_arg(sysdecode_mmap_flags, *ip); 1031 ip++; 1032 narg--; 1033 break; 1034 #endif 1035 case SYS_mmap: 1036 print_number(ip, narg, c); 1037 print_number(ip, narg, c); 1038 putchar(','); 1039 print_mask_arg(sysdecode_mmap_prot, *ip); 1040 putchar(','); 1041 ip++; 1042 narg--; 1043 print_mask_arg(sysdecode_mmap_flags, *ip); 1044 ip++; 1045 narg--; 1046 break; 1047 case SYS_mprotect: 1048 print_number(ip, narg, c); 1049 print_number(ip, narg, c); 1050 putchar(','); 1051 print_mask_arg(sysdecode_mmap_prot, *ip); 1052 ip++; 1053 narg--; 1054 break; 1055 case SYS_madvise: 1056 print_number(ip, narg, c); 1057 print_number(ip, narg, c); 1058 putchar(','); 1059 print_integer_arg(sysdecode_madvice, *ip); 1060 ip++; 1061 narg--; 1062 break; 1063 case SYS_pathconf: 1064 case SYS_lpathconf: 1065 case SYS_fpathconf: 1066 print_number(ip, narg, c); 1067 putchar(','); 1068 print_integer_arg(sysdecode_pathconf_name, *ip); 1069 ip++; 1070 narg--; 1071 break; 1072 case SYS_getpriority: 1073 case SYS_setpriority: 1074 putchar('('); 1075 print_integer_arg(sysdecode_prio_which, *ip); 1076 c = ','; 1077 ip++; 1078 narg--; 1079 break; 1080 case SYS_fcntl: 1081 print_number(ip, narg, c); 1082 putchar(','); 1083 print_integer_arg(sysdecode_fcntl_cmd, ip[0]); 1084 if (sysdecode_fcntl_arg_p(ip[0])) { 1085 putchar(','); 1086 if (ip[0] == F_SETFL) 1087 print_mask_arg( 1088 sysdecode_fcntl_fileflags, 1089 ip[1]); 1090 else 1091 sysdecode_fcntl_arg(stdout, 1092 ip[0], ip[1], 1093 decimal ? 10 : 16); 1094 } 1095 ip += 2; 1096 narg -= 2; 1097 break; 1098 case SYS_socket: { 1099 int sockdomain; 1100 putchar('('); 1101 sockdomain = *ip; 1102 print_integer_arg(sysdecode_socketdomain, 1103 sockdomain); 1104 ip++; 1105 narg--; 1106 putchar(','); 1107 print_mask_arg(sysdecode_socket_type, *ip); 1108 ip++; 1109 narg--; 1110 if (sockdomain == PF_INET || 1111 sockdomain == PF_INET6) { 1112 putchar(','); 1113 print_integer_arg(sysdecode_ipproto, 1114 *ip); 1115 ip++; 1116 narg--; 1117 } 1118 c = ','; 1119 break; 1120 } 1121 case SYS_setsockopt: 1122 case SYS_getsockopt: { 1123 const char *str; 1124 1125 print_number(ip, narg, c); 1126 putchar(','); 1127 print_integer_arg_valid(sysdecode_sockopt_level, 1128 *ip); 1129 str = sysdecode_sockopt_name(ip[0], ip[1]); 1130 if (str != NULL) { 1131 printf(",%s", str); 1132 ip++; 1133 narg--; 1134 } 1135 ip++; 1136 narg--; 1137 break; 1138 } 1139 #ifdef SYS_freebsd6_lseek 1140 case SYS_freebsd6_lseek: 1141 print_number(ip, narg, c); 1142 /* Hidden 'pad' argument, not in lseek(2) */ 1143 print_number(ip, narg, c); 1144 print_number64(first, ip, narg, c); 1145 putchar(','); 1146 print_integer_arg(sysdecode_whence, *ip); 1147 ip++; 1148 narg--; 1149 break; 1150 #endif 1151 case SYS_lseek: 1152 print_number(ip, narg, c); 1153 print_number64(first, ip, narg, c); 1154 putchar(','); 1155 print_integer_arg(sysdecode_whence, *ip); 1156 ip++; 1157 narg--; 1158 break; 1159 case SYS_flock: 1160 print_number(ip, narg, c); 1161 putchar(','); 1162 print_mask_arg(sysdecode_flock_operation, *ip); 1163 ip++; 1164 narg--; 1165 break; 1166 case SYS_mkfifo: 1167 case SYS_mkfifoat: 1168 case SYS_mkdir: 1169 case SYS_mkdirat: 1170 print_number(ip, narg, c); 1171 putchar(','); 1172 decode_filemode(*ip); 1173 ip++; 1174 narg--; 1175 break; 1176 case SYS_shutdown: 1177 print_number(ip, narg, c); 1178 putchar(','); 1179 print_integer_arg(sysdecode_shutdown_how, *ip); 1180 ip++; 1181 narg--; 1182 break; 1183 case SYS_socketpair: 1184 putchar('('); 1185 print_integer_arg(sysdecode_socketdomain, *ip); 1186 ip++; 1187 narg--; 1188 putchar(','); 1189 print_mask_arg(sysdecode_socket_type, *ip); 1190 ip++; 1191 narg--; 1192 c = ','; 1193 break; 1194 case SYS_getrlimit: 1195 case SYS_setrlimit: 1196 putchar('('); 1197 print_integer_arg(sysdecode_rlimit, *ip); 1198 ip++; 1199 narg--; 1200 c = ','; 1201 break; 1202 case SYS_getrusage: 1203 putchar('('); 1204 print_integer_arg(sysdecode_getrusage_who, *ip); 1205 ip++; 1206 narg--; 1207 c = ','; 1208 break; 1209 case SYS_quotactl: 1210 print_number(ip, narg, c); 1211 putchar(','); 1212 if (!sysdecode_quotactl_cmd(stdout, *ip)) { 1213 if (decimal) 1214 printf("<invalid=%d>", (int)*ip); 1215 else 1216 printf("<invalid=%#x>", 1217 (int)*ip); 1218 } 1219 ip++; 1220 narg--; 1221 c = ','; 1222 break; 1223 case SYS_nfssvc: 1224 putchar('('); 1225 print_integer_arg(sysdecode_nfssvc_flags, *ip); 1226 ip++; 1227 narg--; 1228 c = ','; 1229 break; 1230 case SYS_rtprio: 1231 case SYS_rtprio_thread: 1232 putchar('('); 1233 print_integer_arg(sysdecode_rtprio_function, 1234 *ip); 1235 ip++; 1236 narg--; 1237 c = ','; 1238 break; 1239 case SYS___semctl: 1240 print_number(ip, narg, c); 1241 print_number(ip, narg, c); 1242 putchar(','); 1243 print_integer_arg(sysdecode_semctl_cmd, *ip); 1244 ip++; 1245 narg--; 1246 break; 1247 case SYS_semget: 1248 print_number(ip, narg, c); 1249 print_number(ip, narg, c); 1250 putchar(','); 1251 print_mask_arg(sysdecode_semget_flags, *ip); 1252 ip++; 1253 narg--; 1254 break; 1255 case SYS_msgctl: 1256 print_number(ip, narg, c); 1257 putchar(','); 1258 print_integer_arg(sysdecode_msgctl_cmd, *ip); 1259 ip++; 1260 narg--; 1261 break; 1262 case SYS_shmat: 1263 print_number(ip, narg, c); 1264 print_number(ip, narg, c); 1265 putchar(','); 1266 print_mask_arg(sysdecode_shmat_flags, *ip); 1267 ip++; 1268 narg--; 1269 break; 1270 case SYS_shmctl: 1271 print_number(ip, narg, c); 1272 putchar(','); 1273 print_integer_arg(sysdecode_shmctl_cmd, *ip); 1274 ip++; 1275 narg--; 1276 break; 1277 case SYS_shm_open: 1278 print_number(ip, narg, c); 1279 putchar(','); 1280 print_mask_arg(sysdecode_open_flags, ip[0]); 1281 putchar(','); 1282 decode_filemode(ip[1]); 1283 ip += 2; 1284 narg -= 2; 1285 break; 1286 case SYS_minherit: 1287 print_number(ip, narg, c); 1288 print_number(ip, narg, c); 1289 putchar(','); 1290 print_integer_arg(sysdecode_minherit_inherit, 1291 *ip); 1292 ip++; 1293 narg--; 1294 break; 1295 case SYS_rfork: 1296 putchar('('); 1297 print_mask_arg(sysdecode_rfork_flags, *ip); 1298 ip++; 1299 narg--; 1300 c = ','; 1301 break; 1302 case SYS_lio_listio: 1303 putchar('('); 1304 print_integer_arg(sysdecode_lio_listio_mode, 1305 *ip); 1306 ip++; 1307 narg--; 1308 c = ','; 1309 break; 1310 case SYS_mlockall: 1311 putchar('('); 1312 print_mask_arg(sysdecode_mlockall_flags, *ip); 1313 ip++; 1314 narg--; 1315 break; 1316 case SYS_sched_setscheduler: 1317 print_number(ip, narg, c); 1318 putchar(','); 1319 print_integer_arg(sysdecode_scheduler_policy, 1320 *ip); 1321 ip++; 1322 narg--; 1323 break; 1324 case SYS_sched_get_priority_max: 1325 case SYS_sched_get_priority_min: 1326 putchar('('); 1327 print_integer_arg(sysdecode_scheduler_policy, 1328 *ip); 1329 ip++; 1330 narg--; 1331 break; 1332 case SYS_sendfile: 1333 print_number(ip, narg, c); 1334 print_number(ip, narg, c); 1335 print_number(ip, narg, c); 1336 print_number(ip, narg, c); 1337 print_number(ip, narg, c); 1338 print_number(ip, narg, c); 1339 putchar(','); 1340 print_mask_arg(sysdecode_sendfile_flags, *ip); 1341 ip++; 1342 narg--; 1343 break; 1344 case SYS_kldsym: 1345 print_number(ip, narg, c); 1346 putchar(','); 1347 print_integer_arg(sysdecode_kldsym_cmd, *ip); 1348 ip++; 1349 narg--; 1350 break; 1351 case SYS_sigprocmask: 1352 putchar('('); 1353 print_integer_arg(sysdecode_sigprocmask_how, 1354 *ip); 1355 ip++; 1356 narg--; 1357 c = ','; 1358 break; 1359 case SYS___acl_get_file: 1360 case SYS___acl_set_file: 1361 case SYS___acl_get_fd: 1362 case SYS___acl_set_fd: 1363 case SYS___acl_delete_file: 1364 case SYS___acl_delete_fd: 1365 case SYS___acl_aclcheck_file: 1366 case SYS___acl_aclcheck_fd: 1367 case SYS___acl_get_link: 1368 case SYS___acl_set_link: 1369 case SYS___acl_delete_link: 1370 case SYS___acl_aclcheck_link: 1371 print_number(ip, narg, c); 1372 putchar(','); 1373 print_integer_arg(sysdecode_acltype, *ip); 1374 ip++; 1375 narg--; 1376 break; 1377 case SYS_sigaction: 1378 putchar('('); 1379 print_signal(*ip); 1380 ip++; 1381 narg--; 1382 c = ','; 1383 break; 1384 case SYS_extattrctl: 1385 print_number(ip, narg, c); 1386 putchar(','); 1387 print_integer_arg(sysdecode_extattrnamespace, 1388 *ip); 1389 ip++; 1390 narg--; 1391 break; 1392 case SYS_nmount: 1393 print_number(ip, narg, c); 1394 print_number(ip, narg, c); 1395 putchar(','); 1396 print_mask_arg(sysdecode_mount_flags, *ip); 1397 ip++; 1398 narg--; 1399 break; 1400 case SYS_thr_create: 1401 print_number(ip, narg, c); 1402 print_number(ip, narg, c); 1403 putchar(','); 1404 print_mask_arg(sysdecode_thr_create_flags, *ip); 1405 ip++; 1406 narg--; 1407 break; 1408 case SYS_thr_kill: 1409 print_number(ip, narg, c); 1410 putchar(','); 1411 print_signal(*ip); 1412 ip++; 1413 narg--; 1414 break; 1415 case SYS_kldunloadf: 1416 print_number(ip, narg, c); 1417 putchar(','); 1418 print_integer_arg(sysdecode_kldunload_flags, 1419 *ip); 1420 ip++; 1421 narg--; 1422 break; 1423 case SYS_linkat: 1424 case SYS_renameat: 1425 case SYS_symlinkat: 1426 print_number(ip, narg, c); 1427 putchar(','); 1428 print_integer_arg_valid(sysdecode_atfd, *ip); 1429 ip++; 1430 narg--; 1431 print_number(ip, narg, c); 1432 break; 1433 case SYS_cap_fcntls_limit: 1434 print_number(ip, narg, c); 1435 putchar(','); 1436 arg = *ip; 1437 ip++; 1438 narg--; 1439 print_mask_arg32(sysdecode_cap_fcntlrights, arg); 1440 break; 1441 case SYS_posix_fadvise: 1442 print_number(ip, narg, c); 1443 print_number(ip, narg, c); 1444 print_number(ip, narg, c); 1445 (void)putchar(','); 1446 print_integer_arg(sysdecode_fadvice, *ip); 1447 ip++; 1448 narg--; 1449 break; 1450 case SYS_procctl: 1451 putchar('('); 1452 print_integer_arg(sysdecode_idtype, *ip); 1453 c = ','; 1454 ip++; 1455 narg--; 1456 print_number64(first, ip, narg, c); 1457 putchar(','); 1458 print_integer_arg(sysdecode_procctl_cmd, *ip); 1459 ip++; 1460 narg--; 1461 break; 1462 case SYS__umtx_op: 1463 print_number(ip, narg, c); 1464 putchar(','); 1465 print_integer_arg(sysdecode_umtx_op, *ip); 1466 switch (*ip) { 1467 case UMTX_OP_CV_WAIT: 1468 ip++; 1469 narg--; 1470 putchar(','); 1471 print_mask_argul( 1472 sysdecode_umtx_cvwait_flags, *ip); 1473 break; 1474 case UMTX_OP_RW_RDLOCK: 1475 ip++; 1476 narg--; 1477 putchar(','); 1478 print_mask_argul( 1479 sysdecode_umtx_rwlock_flags, *ip); 1480 break; 1481 } 1482 ip++; 1483 narg--; 1484 break; 1485 case SYS_ftruncate: 1486 case SYS_truncate: 1487 print_number(ip, narg, c); 1488 print_number64(first, ip, narg, c); 1489 break; 1490 case SYS_fchownat: 1491 print_number(ip, narg, c); 1492 print_number(ip, narg, c); 1493 print_number(ip, narg, c); 1494 break; 1495 case SYS_fstatat: 1496 case SYS_utimensat: 1497 print_number(ip, narg, c); 1498 print_number(ip, narg, c); 1499 break; 1500 case SYS_unlinkat: 1501 print_number(ip, narg, c); 1502 break; 1503 case SYS_sysarch: 1504 putchar('('); 1505 print_integer_arg(sysdecode_sysarch_number, *ip); 1506 ip++; 1507 narg--; 1508 c = ','; 1509 break; 1510 } 1511 switch (ktr->ktr_code) { 1512 case SYS_chflagsat: 1513 case SYS_fchownat: 1514 case SYS_faccessat: 1515 case SYS_fchmodat: 1516 case SYS_fstatat: 1517 case SYS_linkat: 1518 case SYS_unlinkat: 1519 case SYS_utimensat: 1520 putchar(','); 1521 print_mask_arg0(sysdecode_atflags, *ip); 1522 ip++; 1523 narg--; 1524 break; 1525 } 1526 } 1527 while (narg > 0) { 1528 print_number(ip, narg, c); 1529 } 1530 putchar(')'); 1531 } 1532 putchar('\n'); 1533 } 1534 1535 void 1536 ktrsysret(struct ktr_sysret *ktr, u_int sv_flags) 1537 { 1538 register_t ret = ktr->ktr_retval; 1539 int error = ktr->ktr_error; 1540 1541 syscallname(ktr->ktr_code, sv_flags); 1542 printf(" "); 1543 1544 if (error == 0) { 1545 if (fancy) { 1546 printf("%ld", (long)ret); 1547 if (ret < 0 || ret > 9) 1548 printf("/%#lx", (unsigned long)ret); 1549 } else { 1550 if (decimal) 1551 printf("%ld", (long)ret); 1552 else 1553 printf("%#lx", (unsigned long)ret); 1554 } 1555 } else if (error == ERESTART) 1556 printf("RESTART"); 1557 else if (error == EJUSTRETURN) 1558 printf("JUSTRETURN"); 1559 else { 1560 printf("-1 errno %d", sysdecode_freebsd_to_abi_errno( 1561 syscallabi(sv_flags), error)); 1562 if (fancy) 1563 printf(" %s", strerror(ktr->ktr_error)); 1564 } 1565 putchar('\n'); 1566 } 1567 1568 void 1569 ktrnamei(char *cp, int len) 1570 { 1571 printf("\"%.*s\"\n", len, cp); 1572 } 1573 1574 void 1575 hexdump(char *p, int len, int screenwidth) 1576 { 1577 int n, i; 1578 int width; 1579 1580 width = 0; 1581 do { 1582 width += 2; 1583 i = 13; /* base offset */ 1584 i += (width / 2) + 1; /* spaces every second byte */ 1585 i += (width * 2); /* width of bytes */ 1586 i += 3; /* " |" */ 1587 i += width; /* each byte */ 1588 i += 1; /* "|" */ 1589 } while (i < screenwidth); 1590 width -= 2; 1591 1592 for (n = 0; n < len; n += width) { 1593 for (i = n; i < n + width; i++) { 1594 if ((i % width) == 0) { /* beginning of line */ 1595 printf(" 0x%04x", i); 1596 } 1597 if ((i % 2) == 0) { 1598 printf(" "); 1599 } 1600 if (i < len) 1601 printf("%02x", p[i] & 0xff); 1602 else 1603 printf(" "); 1604 } 1605 printf(" |"); 1606 for (i = n; i < n + width; i++) { 1607 if (i >= len) 1608 break; 1609 if (p[i] >= ' ' && p[i] <= '~') 1610 printf("%c", p[i]); 1611 else 1612 printf("."); 1613 } 1614 printf("|\n"); 1615 } 1616 if ((i % width) != 0) 1617 printf("\n"); 1618 } 1619 1620 void 1621 visdump(char *dp, int datalen, int screenwidth) 1622 { 1623 int col = 0; 1624 char *cp; 1625 int width; 1626 char visbuf[5]; 1627 1628 printf(" \""); 1629 col = 8; 1630 for (;datalen > 0; datalen--, dp++) { 1631 vis(visbuf, *dp, VIS_CSTYLE, *(dp+1)); 1632 cp = visbuf; 1633 /* 1634 * Keep track of printables and 1635 * space chars (like fold(1)). 1636 */ 1637 if (col == 0) { 1638 putchar('\t'); 1639 col = 8; 1640 } 1641 switch(*cp) { 1642 case '\n': 1643 col = 0; 1644 putchar('\n'); 1645 continue; 1646 case '\t': 1647 width = 8 - (col&07); 1648 break; 1649 default: 1650 width = strlen(cp); 1651 } 1652 if (col + width > (screenwidth-2)) { 1653 printf("\\\n\t"); 1654 col = 8; 1655 } 1656 col += width; 1657 do { 1658 putchar(*cp++); 1659 } while (*cp); 1660 } 1661 if (col == 0) 1662 printf(" "); 1663 printf("\"\n"); 1664 } 1665 1666 void 1667 ktrgenio(struct ktr_genio *ktr, int len) 1668 { 1669 int datalen = len - sizeof (struct ktr_genio); 1670 char *dp = (char *)ktr + sizeof (struct ktr_genio); 1671 static int screenwidth = 0; 1672 int i, binary; 1673 1674 printf("fd %d %s %d byte%s\n", ktr->ktr_fd, 1675 ktr->ktr_rw == UIO_READ ? "read" : "wrote", datalen, 1676 datalen == 1 ? "" : "s"); 1677 if (suppressdata) 1678 return; 1679 if (screenwidth == 0) { 1680 struct winsize ws; 1681 1682 if (fancy && ioctl(fileno(stderr), TIOCGWINSZ, &ws) != -1 && 1683 ws.ws_col > 8) 1684 screenwidth = ws.ws_col; 1685 else 1686 screenwidth = 80; 1687 } 1688 if (maxdata && datalen > maxdata) 1689 datalen = maxdata; 1690 1691 for (i = 0, binary = 0; i < datalen && binary == 0; i++) { 1692 if (dp[i] >= 32 && dp[i] < 127) 1693 continue; 1694 if (dp[i] == 10 || dp[i] == 13 || dp[i] == 0 || dp[i] == 9) 1695 continue; 1696 binary = 1; 1697 } 1698 if (binary) 1699 hexdump(dp, datalen, screenwidth); 1700 else 1701 visdump(dp, datalen, screenwidth); 1702 } 1703 1704 void 1705 ktrpsig(struct ktr_psig *psig) 1706 { 1707 const char *str; 1708 1709 print_signal(psig->signo); 1710 if (psig->action == SIG_DFL) { 1711 printf(" SIG_DFL"); 1712 } else { 1713 printf(" caught handler=0x%lx mask=0x%x", 1714 (u_long)psig->action, psig->mask.__bits[0]); 1715 } 1716 printf(" code="); 1717 str = sysdecode_sigcode(psig->signo, psig->code); 1718 if (str != NULL) 1719 printf("%s", str); 1720 else 1721 printf("<invalid=%#x>", psig->code); 1722 putchar('\n'); 1723 } 1724 1725 void 1726 ktrcsw_old(struct ktr_csw_old *cs) 1727 { 1728 printf("%s %s\n", cs->out ? "stop" : "resume", 1729 cs->user ? "user" : "kernel"); 1730 } 1731 1732 void 1733 ktrcsw(struct ktr_csw *cs) 1734 { 1735 printf("%s %s \"%s\"\n", cs->out ? "stop" : "resume", 1736 cs->user ? "user" : "kernel", cs->wmesg); 1737 } 1738 1739 void 1740 ktruser(int len, void *p) 1741 { 1742 unsigned char *cp; 1743 1744 if (sysdecode_utrace(stdout, p, len)) { 1745 printf("\n"); 1746 return; 1747 } 1748 1749 printf("%d ", len); 1750 cp = p; 1751 while (len--) 1752 if (decimal) 1753 printf(" %d", *cp++); 1754 else 1755 printf(" %02x", *cp++); 1756 printf("\n"); 1757 } 1758 1759 void 1760 ktrcaprights(cap_rights_t *rightsp) 1761 { 1762 1763 printf("cap_rights_t "); 1764 sysdecode_cap_rights(stdout, rightsp); 1765 printf("\n"); 1766 } 1767 1768 static void 1769 ktrtimeval(struct timeval *tv) 1770 { 1771 1772 printf("{%ld, %ld}", (long)tv->tv_sec, tv->tv_usec); 1773 } 1774 1775 void 1776 ktritimerval(struct itimerval *it) 1777 { 1778 1779 printf("itimerval { .interval = "); 1780 ktrtimeval(&it->it_interval); 1781 printf(", .value = "); 1782 ktrtimeval(&it->it_value); 1783 printf(" }\n"); 1784 } 1785 1786 void 1787 ktrsockaddr(struct sockaddr *sa) 1788 { 1789 /* 1790 TODO: Support additional address families 1791 #include <netsmb/netbios.h> 1792 struct sockaddr_nb *nb; 1793 */ 1794 const char *str; 1795 char addr[64]; 1796 1797 /* 1798 * note: ktrstruct() has already verified that sa points to a 1799 * buffer at least sizeof(struct sockaddr) bytes long and exactly 1800 * sa->sa_len bytes long. 1801 */ 1802 printf("struct sockaddr { "); 1803 str = sysdecode_sockaddr_family(sa->sa_family); 1804 if (str != NULL) 1805 printf("%s", str); 1806 else 1807 printf("<invalid=%d>", sa->sa_family); 1808 printf(", "); 1809 1810 #define check_sockaddr_len(n) \ 1811 if (sa_##n.s##n##_len < sizeof(struct sockaddr_##n)) { \ 1812 printf("invalid"); \ 1813 break; \ 1814 } 1815 1816 switch(sa->sa_family) { 1817 case AF_INET: { 1818 struct sockaddr_in sa_in; 1819 1820 memset(&sa_in, 0, sizeof(sa_in)); 1821 memcpy(&sa_in, sa, sa->sa_len); 1822 check_sockaddr_len(in); 1823 inet_ntop(AF_INET, &sa_in.sin_addr, addr, sizeof addr); 1824 printf("%s:%u", addr, ntohs(sa_in.sin_port)); 1825 break; 1826 } 1827 case AF_INET6: { 1828 struct sockaddr_in6 sa_in6; 1829 1830 memset(&sa_in6, 0, sizeof(sa_in6)); 1831 memcpy(&sa_in6, sa, sa->sa_len); 1832 check_sockaddr_len(in6); 1833 getnameinfo((struct sockaddr *)&sa_in6, sizeof(sa_in6), 1834 addr, sizeof(addr), NULL, 0, NI_NUMERICHOST); 1835 printf("[%s]:%u", addr, htons(sa_in6.sin6_port)); 1836 break; 1837 } 1838 case AF_UNIX: { 1839 struct sockaddr_un sa_un; 1840 1841 memset(&sa_un, 0, sizeof(sa_un)); 1842 memcpy(&sa_un, sa, sa->sa_len); 1843 printf("%.*s", (int)sizeof(sa_un.sun_path), sa_un.sun_path); 1844 break; 1845 } 1846 default: 1847 printf("unknown address family"); 1848 } 1849 printf(" }\n"); 1850 } 1851 1852 void 1853 ktrstat(struct stat *statp) 1854 { 1855 char mode[12], timestr[PATH_MAX + 4]; 1856 struct passwd *pwd; 1857 struct group *grp; 1858 struct tm *tm; 1859 1860 /* 1861 * note: ktrstruct() has already verified that statp points to a 1862 * buffer exactly sizeof(struct stat) bytes long. 1863 */ 1864 printf("struct stat {"); 1865 printf("dev=%ju, ino=%ju, ", 1866 (uintmax_t)statp->st_dev, (uintmax_t)statp->st_ino); 1867 if (resolv == 0) 1868 printf("mode=0%jo, ", (uintmax_t)statp->st_mode); 1869 else { 1870 strmode(statp->st_mode, mode); 1871 printf("mode=%s, ", mode); 1872 } 1873 printf("nlink=%ju, ", (uintmax_t)statp->st_nlink); 1874 if (resolv == 0) { 1875 pwd = NULL; 1876 } else { 1877 #ifdef WITH_CASPER 1878 if (cappwd != NULL) 1879 pwd = cap_getpwuid(cappwd, statp->st_uid); 1880 else 1881 #endif 1882 pwd = getpwuid(statp->st_uid); 1883 } 1884 if (pwd == NULL) 1885 printf("uid=%ju, ", (uintmax_t)statp->st_uid); 1886 else 1887 printf("uid=\"%s\", ", pwd->pw_name); 1888 if (resolv == 0) { 1889 grp = NULL; 1890 } else { 1891 #ifdef WITH_CASPER 1892 if (capgrp != NULL) 1893 grp = cap_getgrgid(capgrp, statp->st_gid); 1894 else 1895 #endif 1896 grp = getgrgid(statp->st_gid); 1897 } 1898 if (grp == NULL) 1899 printf("gid=%ju, ", (uintmax_t)statp->st_gid); 1900 else 1901 printf("gid=\"%s\", ", grp->gr_name); 1902 printf("rdev=%ju, ", (uintmax_t)statp->st_rdev); 1903 printf("atime="); 1904 if (resolv == 0) 1905 printf("%jd", (intmax_t)statp->st_atim.tv_sec); 1906 else { 1907 tm = localtime(&statp->st_atim.tv_sec); 1908 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1909 printf("\"%s\"", timestr); 1910 } 1911 if (statp->st_atim.tv_nsec != 0) 1912 printf(".%09ld, ", statp->st_atim.tv_nsec); 1913 else 1914 printf(", "); 1915 printf("mtime="); 1916 if (resolv == 0) 1917 printf("%jd", (intmax_t)statp->st_mtim.tv_sec); 1918 else { 1919 tm = localtime(&statp->st_mtim.tv_sec); 1920 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1921 printf("\"%s\"", timestr); 1922 } 1923 if (statp->st_mtim.tv_nsec != 0) 1924 printf(".%09ld, ", statp->st_mtim.tv_nsec); 1925 else 1926 printf(", "); 1927 printf("ctime="); 1928 if (resolv == 0) 1929 printf("%jd", (intmax_t)statp->st_ctim.tv_sec); 1930 else { 1931 tm = localtime(&statp->st_ctim.tv_sec); 1932 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1933 printf("\"%s\"", timestr); 1934 } 1935 if (statp->st_ctim.tv_nsec != 0) 1936 printf(".%09ld, ", statp->st_ctim.tv_nsec); 1937 else 1938 printf(", "); 1939 printf("birthtime="); 1940 if (resolv == 0) 1941 printf("%jd", (intmax_t)statp->st_birthtim.tv_sec); 1942 else { 1943 tm = localtime(&statp->st_birthtim.tv_sec); 1944 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1945 printf("\"%s\"", timestr); 1946 } 1947 if (statp->st_birthtim.tv_nsec != 0) 1948 printf(".%09ld, ", statp->st_birthtim.tv_nsec); 1949 else 1950 printf(", "); 1951 printf("size=%jd, blksize=%ju, blocks=%jd, flags=0x%x", 1952 (uintmax_t)statp->st_size, (uintmax_t)statp->st_blksize, 1953 (intmax_t)statp->st_blocks, statp->st_flags); 1954 printf(" }\n"); 1955 } 1956 1957 void 1958 ktrstruct(char *buf, size_t buflen) 1959 { 1960 char *name, *data; 1961 size_t namelen, datalen; 1962 int i; 1963 cap_rights_t rights; 1964 struct itimerval it; 1965 struct stat sb; 1966 struct sockaddr_storage ss; 1967 1968 for (name = buf, namelen = 0; 1969 namelen < buflen && name[namelen] != '\0'; 1970 ++namelen) 1971 /* nothing */; 1972 if (namelen == buflen) 1973 goto invalid; 1974 if (name[namelen] != '\0') 1975 goto invalid; 1976 data = buf + namelen + 1; 1977 datalen = buflen - namelen - 1; 1978 if (datalen == 0) 1979 goto invalid; 1980 /* sanity check */ 1981 for (i = 0; i < (int)namelen; ++i) 1982 if (!isalpha(name[i])) 1983 goto invalid; 1984 if (strcmp(name, "caprights") == 0) { 1985 if (datalen != sizeof(cap_rights_t)) 1986 goto invalid; 1987 memcpy(&rights, data, datalen); 1988 ktrcaprights(&rights); 1989 } else if (strcmp(name, "itimerval") == 0) { 1990 if (datalen != sizeof(struct itimerval)) 1991 goto invalid; 1992 memcpy(&it, data, datalen); 1993 ktritimerval(&it); 1994 } else if (strcmp(name, "stat") == 0) { 1995 if (datalen != sizeof(struct stat)) 1996 goto invalid; 1997 memcpy(&sb, data, datalen); 1998 ktrstat(&sb); 1999 } else if (strcmp(name, "sockaddr") == 0) { 2000 if (datalen > sizeof(ss)) 2001 goto invalid; 2002 memcpy(&ss, data, datalen); 2003 if (datalen != ss.ss_len) 2004 goto invalid; 2005 ktrsockaddr((struct sockaddr *)&ss); 2006 } else { 2007 printf("unknown structure\n"); 2008 } 2009 return; 2010 invalid: 2011 printf("invalid record\n"); 2012 } 2013 2014 void 2015 ktrcapfail(struct ktr_cap_fail *ktr) 2016 { 2017 switch (ktr->cap_type) { 2018 case CAPFAIL_NOTCAPABLE: 2019 /* operation on fd with insufficient capabilities */ 2020 printf("operation requires "); 2021 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2022 printf(", descriptor holds "); 2023 sysdecode_cap_rights(stdout, &ktr->cap_held); 2024 break; 2025 case CAPFAIL_INCREASE: 2026 /* requested more capabilities than fd already has */ 2027 printf("attempt to increase capabilities from "); 2028 sysdecode_cap_rights(stdout, &ktr->cap_held); 2029 printf(" to "); 2030 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2031 break; 2032 case CAPFAIL_SYSCALL: 2033 /* called restricted syscall */ 2034 printf("disallowed system call"); 2035 break; 2036 case CAPFAIL_LOOKUP: 2037 /* used ".." in strict-relative mode */ 2038 printf("restricted VFS lookup"); 2039 break; 2040 default: 2041 printf("unknown capability failure: "); 2042 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2043 printf(" "); 2044 sysdecode_cap_rights(stdout, &ktr->cap_held); 2045 break; 2046 } 2047 printf("\n"); 2048 } 2049 2050 void 2051 ktrfault(struct ktr_fault *ktr) 2052 { 2053 2054 printf("0x%jx ", (uintmax_t)ktr->vaddr); 2055 print_mask_arg(sysdecode_vmprot, ktr->type); 2056 printf("\n"); 2057 } 2058 2059 void 2060 ktrfaultend(struct ktr_faultend *ktr) 2061 { 2062 const char *str; 2063 2064 str = sysdecode_vmresult(ktr->result); 2065 if (str != NULL) 2066 printf("%s", str); 2067 else 2068 printf("<invalid=%d>", ktr->result); 2069 printf("\n"); 2070 } 2071 2072 void 2073 usage(void) 2074 { 2075 fprintf(stderr, "usage: kdump [-dEnlHRrSsTA] [-f trfile] " 2076 "[-m maxdata] [-p pid] [-t trstr]\n"); 2077 exit(1); 2078 } 2079