1 /*- 2 * SPDX-License-Identifier: BSD-3-Clause 3 * 4 * Copyright (c) 1988, 1993 5 * The Regents of the University of California. All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the University nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32 #ifndef lint 33 static const char copyright[] = 34 "@(#) Copyright (c) 1988, 1993\n\ 35 The Regents of the University of California. All rights reserved.\n"; 36 #endif /* not lint */ 37 38 #ifndef lint 39 #if 0 40 static char sccsid[] = "@(#)kdump.c 8.1 (Berkeley) 6/6/93"; 41 #endif 42 #endif /* not lint */ 43 #include <sys/cdefs.h> 44 __FBSDID("$FreeBSD$"); 45 46 #define _WANT_KERNEL_ERRNO 47 #ifdef __LP64__ 48 #define _WANT_KEVENT32 49 #endif 50 #define _WANT_FREEBSD11_KEVENT 51 #include <sys/param.h> 52 #include <sys/capsicum.h> 53 #include <sys/errno.h> 54 #include <sys/time.h> 55 #include <sys/uio.h> 56 #include <sys/event.h> 57 #include <sys/ktrace.h> 58 #include <sys/ioctl.h> 59 #include <sys/socket.h> 60 #include <sys/stat.h> 61 #include <sys/sysent.h> 62 #include <sys/umtx.h> 63 #include <sys/un.h> 64 #include <sys/queue.h> 65 #include <sys/wait.h> 66 #ifdef WITH_CASPER 67 #include <sys/nv.h> 68 #endif 69 #include <arpa/inet.h> 70 #include <netinet/in.h> 71 #include <ctype.h> 72 #include <capsicum_helpers.h> 73 #include <err.h> 74 #include <grp.h> 75 #include <inttypes.h> 76 #include <locale.h> 77 #include <netdb.h> 78 #include <nl_types.h> 79 #include <pwd.h> 80 #include <stddef.h> 81 #include <stdio.h> 82 #include <stdlib.h> 83 #include <string.h> 84 #include <sysdecode.h> 85 #include <time.h> 86 #include <unistd.h> 87 #include <vis.h> 88 #include "ktrace.h" 89 90 #ifdef WITH_CASPER 91 #include <libcasper.h> 92 93 #include <casper/cap_grp.h> 94 #include <casper/cap_pwd.h> 95 #endif 96 97 int fetchprocinfo(struct ktr_header *, u_int *); 98 u_int findabi(struct ktr_header *); 99 int fread_tail(void *, int, int); 100 void dumpheader(struct ktr_header *, u_int); 101 void ktrsyscall(struct ktr_syscall *, u_int); 102 void ktrsysret(struct ktr_sysret *, u_int); 103 void ktrnamei(char *, int); 104 void hexdump(char *, int, int); 105 void visdump(char *, int, int); 106 void ktrgenio(struct ktr_genio *, int); 107 void ktrpsig(struct ktr_psig *); 108 void ktrcsw(struct ktr_csw *); 109 void ktrcsw_old(struct ktr_csw_old *); 110 void ktruser(int, void *); 111 void ktrcaprights(cap_rights_t *); 112 void ktritimerval(struct itimerval *it); 113 void ktrsockaddr(struct sockaddr *); 114 void ktrstat(struct stat *); 115 void ktrstruct(char *, size_t); 116 void ktrcapfail(struct ktr_cap_fail *); 117 void ktrfault(struct ktr_fault *); 118 void ktrfaultend(struct ktr_faultend *); 119 void ktrkevent(struct kevent *); 120 void ktrstructarray(struct ktr_struct_array *, size_t); 121 void usage(void); 122 123 #define TIMESTAMP_NONE 0x0 124 #define TIMESTAMP_ABSOLUTE 0x1 125 #define TIMESTAMP_ELAPSED 0x2 126 #define TIMESTAMP_RELATIVE 0x4 127 128 static int timestamp, decimal, fancy = 1, suppressdata, tail, threads, maxdata, 129 resolv = 0, abiflag = 0, syscallno = 0; 130 static const char *tracefile = DEF_TRACEFILE; 131 static struct ktr_header ktr_header; 132 133 #define TIME_FORMAT "%b %e %T %Y" 134 #define eqs(s1, s2) (strcmp((s1), (s2)) == 0) 135 136 #define print_number64(first,i,n,c) do { \ 137 uint64_t __v; \ 138 \ 139 if (quad_align && (((ptrdiff_t)((i) - (first))) & 1) == 1) { \ 140 (i)++; \ 141 (n)--; \ 142 } \ 143 if (quad_slots == 2) \ 144 __v = (uint64_t)(uint32_t)(i)[0] | \ 145 ((uint64_t)(uint32_t)(i)[1]) << 32; \ 146 else \ 147 __v = (uint64_t)*(i); \ 148 if (decimal) \ 149 printf("%c%jd", (c), (intmax_t)__v); \ 150 else \ 151 printf("%c%#jx", (c), (uintmax_t)__v); \ 152 (i) += quad_slots; \ 153 (n) -= quad_slots; \ 154 (c) = ','; \ 155 } while (0) 156 157 #define print_number(i,n,c) do { \ 158 if (decimal) \ 159 printf("%c%jd", c, (intmax_t)*i); \ 160 else \ 161 printf("%c%#jx", c, (uintmax_t)(u_register_t)*i); \ 162 i++; \ 163 n--; \ 164 c = ','; \ 165 } while (0) 166 167 struct proc_info 168 { 169 TAILQ_ENTRY(proc_info) info; 170 u_int sv_flags; 171 pid_t pid; 172 }; 173 174 static TAILQ_HEAD(trace_procs, proc_info) trace_procs; 175 176 #ifdef WITH_CASPER 177 static cap_channel_t *cappwd, *capgrp; 178 179 static int 180 cappwdgrp_setup(cap_channel_t **cappwdp, cap_channel_t **capgrpp) 181 { 182 cap_channel_t *capcas, *cappwdloc, *capgrploc; 183 const char *cmds[1], *fields[1]; 184 185 capcas = cap_init(); 186 if (capcas == NULL) { 187 err(1, "unable to create casper process"); 188 exit(1); 189 } 190 cappwdloc = cap_service_open(capcas, "system.pwd"); 191 capgrploc = cap_service_open(capcas, "system.grp"); 192 /* Casper capability no longer needed. */ 193 cap_close(capcas); 194 if (cappwdloc == NULL || capgrploc == NULL) { 195 if (cappwdloc == NULL) 196 warn("unable to open system.pwd service"); 197 if (capgrploc == NULL) 198 warn("unable to open system.grp service"); 199 exit(1); 200 } 201 /* Limit system.pwd to only getpwuid() function and pw_name field. */ 202 cmds[0] = "getpwuid"; 203 if (cap_pwd_limit_cmds(cappwdloc, cmds, 1) < 0) 204 err(1, "unable to limit system.pwd service"); 205 fields[0] = "pw_name"; 206 if (cap_pwd_limit_fields(cappwdloc, fields, 1) < 0) 207 err(1, "unable to limit system.pwd service"); 208 /* Limit system.grp to only getgrgid() function and gr_name field. */ 209 cmds[0] = "getgrgid"; 210 if (cap_grp_limit_cmds(capgrploc, cmds, 1) < 0) 211 err(1, "unable to limit system.grp service"); 212 fields[0] = "gr_name"; 213 if (cap_grp_limit_fields(capgrploc, fields, 1) < 0) 214 err(1, "unable to limit system.grp service"); 215 216 *cappwdp = cappwdloc; 217 *capgrpp = capgrploc; 218 return (0); 219 } 220 #endif /* WITH_CASPER */ 221 222 static void 223 print_integer_arg(const char *(*decoder)(int), int value) 224 { 225 const char *str; 226 227 str = decoder(value); 228 if (str != NULL) 229 printf("%s", str); 230 else { 231 if (decimal) 232 printf("<invalid=%d>", value); 233 else 234 printf("<invalid=%#x>", value); 235 } 236 } 237 238 /* Like print_integer_arg but unknown values are treated as valid. */ 239 static void 240 print_integer_arg_valid(const char *(*decoder)(int), int value) 241 { 242 const char *str; 243 244 str = decoder(value); 245 if (str != NULL) 246 printf("%s", str); 247 else { 248 if (decimal) 249 printf("%d", value); 250 else 251 printf("%#x", value); 252 } 253 } 254 255 static void 256 print_mask_arg(bool (*decoder)(FILE *, int, int *), int value) 257 { 258 bool invalid; 259 int rem; 260 261 printf("%#x<", value); 262 invalid = !decoder(stdout, value, &rem); 263 printf(">"); 264 if (invalid) 265 printf("<invalid>%u", rem); 266 } 267 268 static void 269 print_mask_arg0(bool (*decoder)(FILE *, int, int *), int value) 270 { 271 bool invalid; 272 int rem; 273 274 if (value == 0) { 275 printf("0"); 276 return; 277 } 278 printf("%#x<", value); 279 invalid = !decoder(stdout, value, &rem); 280 printf(">"); 281 if (invalid) 282 printf("<invalid>%u", rem); 283 } 284 285 static void 286 decode_fileflags(fflags_t value) 287 { 288 bool invalid; 289 fflags_t rem; 290 291 if (value == 0) { 292 printf("0"); 293 return; 294 } 295 printf("%#x<", value); 296 invalid = !sysdecode_fileflags(stdout, value, &rem); 297 printf(">"); 298 if (invalid) 299 printf("<invalid>%u", rem); 300 } 301 302 static void 303 decode_filemode(int value) 304 { 305 bool invalid; 306 int rem; 307 308 if (value == 0) { 309 printf("0"); 310 return; 311 } 312 printf("%#o<", value); 313 invalid = !sysdecode_filemode(stdout, value, &rem); 314 printf(">"); 315 if (invalid) 316 printf("<invalid>%u", rem); 317 } 318 319 static void 320 print_mask_arg32(bool (*decoder)(FILE *, uint32_t, uint32_t *), uint32_t value) 321 { 322 bool invalid; 323 uint32_t rem; 324 325 printf("%#x<", value); 326 invalid = !decoder(stdout, value, &rem); 327 printf(">"); 328 if (invalid) 329 printf("<invalid>%u", rem); 330 } 331 332 static void 333 print_mask_argul(bool (*decoder)(FILE *, u_long, u_long *), u_long value) 334 { 335 bool invalid; 336 u_long rem; 337 338 if (value == 0) { 339 printf("0"); 340 return; 341 } 342 printf("%#lx<", value); 343 invalid = !decoder(stdout, value, &rem); 344 printf(">"); 345 if (invalid) 346 printf("<invalid>%lu", rem); 347 } 348 349 int 350 main(int argc, char *argv[]) 351 { 352 int ch, ktrlen, size; 353 void *m; 354 int trpoints = ALL_POINTS; 355 int drop_logged; 356 pid_t pid = 0; 357 u_int sv_flags; 358 359 setlocale(LC_CTYPE, ""); 360 361 timestamp = TIMESTAMP_NONE; 362 363 while ((ch = getopt(argc,argv,"f:dElm:np:AHRrSsTt:")) != -1) 364 switch (ch) { 365 case 'A': 366 abiflag = 1; 367 break; 368 case 'f': 369 tracefile = optarg; 370 break; 371 case 'd': 372 decimal = 1; 373 break; 374 case 'l': 375 tail = 1; 376 break; 377 case 'm': 378 maxdata = atoi(optarg); 379 break; 380 case 'n': 381 fancy = 0; 382 break; 383 case 'p': 384 pid = atoi(optarg); 385 break; 386 case 'r': 387 resolv = 1; 388 break; 389 case 'S': 390 syscallno = 1; 391 break; 392 case 's': 393 suppressdata = 1; 394 break; 395 case 'E': 396 timestamp |= TIMESTAMP_ELAPSED; 397 break; 398 case 'H': 399 threads = 1; 400 break; 401 case 'R': 402 timestamp |= TIMESTAMP_RELATIVE; 403 break; 404 case 'T': 405 timestamp |= TIMESTAMP_ABSOLUTE; 406 break; 407 case 't': 408 trpoints = getpoints(optarg); 409 if (trpoints < 0) 410 errx(1, "unknown trace point in %s", optarg); 411 break; 412 default: 413 usage(); 414 } 415 416 if (argc > optind) 417 usage(); 418 419 m = malloc(size = 1025); 420 if (m == NULL) 421 errx(1, "%s", strerror(ENOMEM)); 422 if (strcmp(tracefile, "-") != 0) 423 if (!freopen(tracefile, "r", stdin)) 424 err(1, "%s", tracefile); 425 426 caph_cache_catpages(); 427 caph_cache_tzdata(); 428 429 #ifdef WITH_CASPER 430 if (resolv != 0) { 431 if (cappwdgrp_setup(&cappwd, &capgrp) < 0) { 432 cappwd = NULL; 433 capgrp = NULL; 434 } 435 } 436 if (resolv == 0 || (cappwd != NULL && capgrp != NULL)) { 437 if (caph_enter() < 0) 438 err(1, "unable to enter capability mode"); 439 } 440 #else 441 if (resolv == 0) { 442 if (caph_enter() < 0) 443 err(1, "unable to enter capability mode"); 444 } 445 #endif 446 if (caph_limit_stdio() == -1) 447 err(1, "unable to limit stdio"); 448 449 TAILQ_INIT(&trace_procs); 450 drop_logged = 0; 451 while (fread_tail(&ktr_header, sizeof(struct ktr_header), 1)) { 452 if (ktr_header.ktr_type & KTR_DROP) { 453 ktr_header.ktr_type &= ~KTR_DROP; 454 if (!drop_logged && threads) { 455 printf( 456 "%6jd %6jd %-8.*s Events dropped.\n", 457 (intmax_t)ktr_header.ktr_pid, 458 ktr_header.ktr_tid > 0 ? 459 (intmax_t)ktr_header.ktr_tid : 0, 460 MAXCOMLEN, ktr_header.ktr_comm); 461 drop_logged = 1; 462 } else if (!drop_logged) { 463 printf("%6jd %-8.*s Events dropped.\n", 464 (intmax_t)ktr_header.ktr_pid, MAXCOMLEN, 465 ktr_header.ktr_comm); 466 drop_logged = 1; 467 } 468 } 469 if ((ktrlen = ktr_header.ktr_len) < 0) 470 errx(1, "bogus length 0x%x", ktrlen); 471 if (ktrlen > size) { 472 m = realloc(m, ktrlen+1); 473 if (m == NULL) 474 errx(1, "%s", strerror(ENOMEM)); 475 size = ktrlen; 476 } 477 if (ktrlen && fread_tail(m, ktrlen, 1) == 0) 478 errx(1, "data too short"); 479 if (fetchprocinfo(&ktr_header, (u_int *)m) != 0) 480 continue; 481 if (pid && ktr_header.ktr_pid != pid && 482 ktr_header.ktr_tid != pid) 483 continue; 484 if ((trpoints & (1<<ktr_header.ktr_type)) == 0) 485 continue; 486 sv_flags = findabi(&ktr_header); 487 dumpheader(&ktr_header, sv_flags); 488 drop_logged = 0; 489 switch (ktr_header.ktr_type) { 490 case KTR_SYSCALL: 491 ktrsyscall((struct ktr_syscall *)m, sv_flags); 492 break; 493 case KTR_SYSRET: 494 ktrsysret((struct ktr_sysret *)m, sv_flags); 495 break; 496 case KTR_NAMEI: 497 case KTR_SYSCTL: 498 ktrnamei(m, ktrlen); 499 break; 500 case KTR_GENIO: 501 ktrgenio((struct ktr_genio *)m, ktrlen); 502 break; 503 case KTR_PSIG: 504 ktrpsig((struct ktr_psig *)m); 505 break; 506 case KTR_CSW: 507 if (ktrlen == sizeof(struct ktr_csw_old)) 508 ktrcsw_old((struct ktr_csw_old *)m); 509 else 510 ktrcsw((struct ktr_csw *)m); 511 break; 512 case KTR_USER: 513 ktruser(ktrlen, m); 514 break; 515 case KTR_STRUCT: 516 ktrstruct(m, ktrlen); 517 break; 518 case KTR_CAPFAIL: 519 ktrcapfail((struct ktr_cap_fail *)m); 520 break; 521 case KTR_FAULT: 522 ktrfault((struct ktr_fault *)m); 523 break; 524 case KTR_FAULTEND: 525 ktrfaultend((struct ktr_faultend *)m); 526 break; 527 case KTR_STRUCT_ARRAY: 528 ktrstructarray((struct ktr_struct_array *)m, ktrlen); 529 break; 530 default: 531 printf("\n"); 532 break; 533 } 534 if (tail) 535 fflush(stdout); 536 } 537 return 0; 538 } 539 540 int 541 fread_tail(void *buf, int size, int num) 542 { 543 int i; 544 545 while ((i = fread(buf, size, num, stdin)) == 0 && tail) { 546 sleep(1); 547 clearerr(stdin); 548 } 549 return (i); 550 } 551 552 int 553 fetchprocinfo(struct ktr_header *kth, u_int *flags) 554 { 555 struct proc_info *pi; 556 557 switch (kth->ktr_type) { 558 case KTR_PROCCTOR: 559 TAILQ_FOREACH(pi, &trace_procs, info) { 560 if (pi->pid == kth->ktr_pid) { 561 TAILQ_REMOVE(&trace_procs, pi, info); 562 break; 563 } 564 } 565 pi = malloc(sizeof(struct proc_info)); 566 if (pi == NULL) 567 errx(1, "%s", strerror(ENOMEM)); 568 pi->sv_flags = *flags; 569 pi->pid = kth->ktr_pid; 570 TAILQ_INSERT_TAIL(&trace_procs, pi, info); 571 return (1); 572 573 case KTR_PROCDTOR: 574 TAILQ_FOREACH(pi, &trace_procs, info) { 575 if (pi->pid == kth->ktr_pid) { 576 TAILQ_REMOVE(&trace_procs, pi, info); 577 free(pi); 578 break; 579 } 580 } 581 return (1); 582 } 583 584 return (0); 585 } 586 587 u_int 588 findabi(struct ktr_header *kth) 589 { 590 struct proc_info *pi; 591 592 TAILQ_FOREACH(pi, &trace_procs, info) { 593 if (pi->pid == kth->ktr_pid) { 594 return (pi->sv_flags); 595 } 596 } 597 return (0); 598 } 599 600 void 601 dumpheader(struct ktr_header *kth, u_int sv_flags) 602 { 603 static char unknown[64]; 604 static struct timeval prevtime, prevtime_e; 605 struct timeval temp; 606 const char *abi; 607 const char *arch; 608 const char *type; 609 const char *sign; 610 611 switch (kth->ktr_type) { 612 case KTR_SYSCALL: 613 type = "CALL"; 614 break; 615 case KTR_SYSRET: 616 type = "RET "; 617 break; 618 case KTR_NAMEI: 619 type = "NAMI"; 620 break; 621 case KTR_GENIO: 622 type = "GIO "; 623 break; 624 case KTR_PSIG: 625 type = "PSIG"; 626 break; 627 case KTR_CSW: 628 type = "CSW "; 629 break; 630 case KTR_USER: 631 type = "USER"; 632 break; 633 case KTR_STRUCT: 634 case KTR_STRUCT_ARRAY: 635 type = "STRU"; 636 break; 637 case KTR_SYSCTL: 638 type = "SCTL"; 639 break; 640 case KTR_CAPFAIL: 641 type = "CAP "; 642 break; 643 case KTR_FAULT: 644 type = "PFLT"; 645 break; 646 case KTR_FAULTEND: 647 type = "PRET"; 648 break; 649 default: 650 sprintf(unknown, "UNKNOWN(%d)", kth->ktr_type); 651 type = unknown; 652 } 653 654 /* 655 * The ktr_tid field was previously the ktr_buffer field, which held 656 * the kernel pointer value for the buffer associated with data 657 * following the record header. It now holds a threadid, but only 658 * for trace files after the change. Older trace files still contain 659 * kernel pointers. Detect this and suppress the results by printing 660 * negative tid's as 0. 661 */ 662 if (threads) 663 printf("%6jd %6jd %-8.*s ", (intmax_t)kth->ktr_pid, 664 kth->ktr_tid > 0 ? (intmax_t)kth->ktr_tid : 0, 665 MAXCOMLEN, kth->ktr_comm); 666 else 667 printf("%6jd %-8.*s ", (intmax_t)kth->ktr_pid, MAXCOMLEN, 668 kth->ktr_comm); 669 if (timestamp) { 670 if (timestamp & TIMESTAMP_ABSOLUTE) { 671 printf("%jd.%06ld ", (intmax_t)kth->ktr_time.tv_sec, 672 kth->ktr_time.tv_usec); 673 } 674 if (timestamp & TIMESTAMP_ELAPSED) { 675 if (prevtime_e.tv_sec == 0) 676 prevtime_e = kth->ktr_time; 677 timersub(&kth->ktr_time, &prevtime_e, &temp); 678 printf("%jd.%06ld ", (intmax_t)temp.tv_sec, 679 temp.tv_usec); 680 } 681 if (timestamp & TIMESTAMP_RELATIVE) { 682 if (prevtime.tv_sec == 0) 683 prevtime = kth->ktr_time; 684 if (timercmp(&kth->ktr_time, &prevtime, <)) { 685 timersub(&prevtime, &kth->ktr_time, &temp); 686 sign = "-"; 687 } else { 688 timersub(&kth->ktr_time, &prevtime, &temp); 689 sign = ""; 690 } 691 prevtime = kth->ktr_time; 692 printf("%s%jd.%06ld ", sign, (intmax_t)temp.tv_sec, 693 temp.tv_usec); 694 } 695 } 696 printf("%s ", type); 697 if (abiflag != 0) { 698 switch (sv_flags & SV_ABI_MASK) { 699 case SV_ABI_LINUX: 700 abi = "L"; 701 break; 702 case SV_ABI_FREEBSD: 703 abi = "F"; 704 break; 705 case SV_ABI_CLOUDABI: 706 abi = "C"; 707 break; 708 default: 709 abi = "U"; 710 break; 711 } 712 713 if ((sv_flags & SV_LP64) != 0) 714 arch = "64"; 715 else if ((sv_flags & SV_ILP32) != 0) 716 arch = "32"; 717 else 718 arch = "00"; 719 720 printf("%s%s ", abi, arch); 721 } 722 } 723 724 #include <sys/syscall.h> 725 726 static void 727 ioctlname(unsigned long val) 728 { 729 const char *str; 730 731 str = sysdecode_ioctlname(val); 732 if (str != NULL) 733 printf("%s", str); 734 else if (decimal) 735 printf("%lu", val); 736 else 737 printf("%#lx", val); 738 } 739 740 static enum sysdecode_abi 741 syscallabi(u_int sv_flags) 742 { 743 744 if (sv_flags == 0) 745 return (SYSDECODE_ABI_FREEBSD); 746 switch (sv_flags & SV_ABI_MASK) { 747 case SV_ABI_FREEBSD: 748 return (SYSDECODE_ABI_FREEBSD); 749 case SV_ABI_LINUX: 750 #ifdef __LP64__ 751 if (sv_flags & SV_ILP32) 752 return (SYSDECODE_ABI_LINUX32); 753 #endif 754 return (SYSDECODE_ABI_LINUX); 755 case SV_ABI_CLOUDABI: 756 return (SYSDECODE_ABI_CLOUDABI64); 757 default: 758 return (SYSDECODE_ABI_UNKNOWN); 759 } 760 } 761 762 static void 763 syscallname(u_int code, u_int sv_flags) 764 { 765 const char *name; 766 767 name = sysdecode_syscallname(syscallabi(sv_flags), code); 768 if (name == NULL) 769 printf("[%d]", code); 770 else { 771 printf("%s", name); 772 if (syscallno) 773 printf("[%d]", code); 774 } 775 } 776 777 static void 778 print_signal(int signo) 779 { 780 const char *signame; 781 782 signame = sysdecode_signal(signo); 783 if (signame != NULL) 784 printf("%s", signame); 785 else 786 printf("SIG %d", signo); 787 } 788 789 void 790 ktrsyscall(struct ktr_syscall *ktr, u_int sv_flags) 791 { 792 int narg = ktr->ktr_narg; 793 register_t *ip, *first; 794 intmax_t arg; 795 int quad_align, quad_slots; 796 797 syscallname(ktr->ktr_code, sv_flags); 798 ip = first = &ktr->ktr_args[0]; 799 if (narg) { 800 char c = '('; 801 if (fancy && 802 (sv_flags == 0 || 803 (sv_flags & SV_ABI_MASK) == SV_ABI_FREEBSD)) { 804 quad_align = 0; 805 if (sv_flags & SV_ILP32) { 806 #ifdef __powerpc__ 807 quad_align = 1; 808 #endif 809 quad_slots = 2; 810 } else 811 quad_slots = 1; 812 switch (ktr->ktr_code) { 813 case SYS_bindat: 814 case SYS_chflagsat: 815 case SYS_connectat: 816 case SYS_faccessat: 817 case SYS_fchmodat: 818 case SYS_fchownat: 819 case SYS_fstatat: 820 case SYS_futimesat: 821 case SYS_linkat: 822 case SYS_mkdirat: 823 case SYS_mkfifoat: 824 case SYS_mknodat: 825 case SYS_openat: 826 case SYS_readlinkat: 827 case SYS_renameat: 828 case SYS_unlinkat: 829 case SYS_utimensat: 830 putchar('('); 831 print_integer_arg_valid(sysdecode_atfd, *ip); 832 c = ','; 833 ip++; 834 narg--; 835 break; 836 } 837 switch (ktr->ktr_code) { 838 case SYS_ioctl: { 839 print_number(ip, narg, c); 840 putchar(c); 841 ioctlname(*ip); 842 c = ','; 843 ip++; 844 narg--; 845 break; 846 } 847 case SYS_ptrace: 848 putchar('('); 849 print_integer_arg(sysdecode_ptrace_request, *ip); 850 c = ','; 851 ip++; 852 narg--; 853 break; 854 case SYS_access: 855 case SYS_eaccess: 856 case SYS_faccessat: 857 print_number(ip, narg, c); 858 putchar(','); 859 print_mask_arg(sysdecode_access_mode, *ip); 860 ip++; 861 narg--; 862 break; 863 case SYS_open: 864 case SYS_openat: 865 print_number(ip, narg, c); 866 putchar(','); 867 print_mask_arg(sysdecode_open_flags, ip[0]); 868 if ((ip[0] & O_CREAT) == O_CREAT) { 869 putchar(','); 870 decode_filemode(ip[1]); 871 } 872 ip += 2; 873 narg -= 2; 874 break; 875 case SYS_wait4: 876 print_number(ip, narg, c); 877 print_number(ip, narg, c); 878 putchar(','); 879 print_mask_arg0(sysdecode_wait4_options, *ip); 880 ip++; 881 narg--; 882 break; 883 case SYS_wait6: 884 putchar('('); 885 print_integer_arg(sysdecode_idtype, *ip); 886 c = ','; 887 ip++; 888 narg--; 889 print_number64(first, ip, narg, c); 890 print_number(ip, narg, c); 891 putchar(','); 892 print_mask_arg(sysdecode_wait6_options, *ip); 893 ip++; 894 narg--; 895 break; 896 case SYS_chmod: 897 case SYS_fchmod: 898 case SYS_lchmod: 899 case SYS_fchmodat: 900 print_number(ip, narg, c); 901 putchar(','); 902 decode_filemode(*ip); 903 ip++; 904 narg--; 905 break; 906 case SYS_mknodat: 907 print_number(ip, narg, c); 908 putchar(','); 909 decode_filemode(*ip); 910 ip++; 911 narg--; 912 break; 913 case SYS_getfsstat: 914 print_number(ip, narg, c); 915 print_number(ip, narg, c); 916 putchar(','); 917 print_integer_arg(sysdecode_getfsstat_mode, *ip); 918 ip++; 919 narg--; 920 break; 921 case SYS_mount: 922 print_number(ip, narg, c); 923 print_number(ip, narg, c); 924 putchar(','); 925 print_mask_arg(sysdecode_mount_flags, *ip); 926 ip++; 927 narg--; 928 break; 929 case SYS_unmount: 930 print_number(ip, narg, c); 931 putchar(','); 932 print_mask_arg(sysdecode_mount_flags, *ip); 933 ip++; 934 narg--; 935 break; 936 case SYS_recvmsg: 937 case SYS_sendmsg: 938 print_number(ip, narg, c); 939 print_number(ip, narg, c); 940 putchar(','); 941 print_mask_arg0(sysdecode_msg_flags, *ip); 942 ip++; 943 narg--; 944 break; 945 case SYS_recvfrom: 946 case SYS_sendto: 947 print_number(ip, narg, c); 948 print_number(ip, narg, c); 949 print_number(ip, narg, c); 950 putchar(','); 951 print_mask_arg0(sysdecode_msg_flags, *ip); 952 ip++; 953 narg--; 954 break; 955 case SYS_chflags: 956 case SYS_chflagsat: 957 case SYS_fchflags: 958 case SYS_lchflags: 959 print_number(ip, narg, c); 960 putchar(','); 961 decode_fileflags(*ip); 962 ip++; 963 narg--; 964 break; 965 case SYS_kill: 966 print_number(ip, narg, c); 967 putchar(','); 968 print_signal(*ip); 969 ip++; 970 narg--; 971 break; 972 case SYS_reboot: 973 putchar('('); 974 print_mask_arg(sysdecode_reboot_howto, *ip); 975 ip++; 976 narg--; 977 break; 978 case SYS_umask: 979 putchar('('); 980 decode_filemode(*ip); 981 ip++; 982 narg--; 983 break; 984 case SYS_msync: 985 print_number(ip, narg, c); 986 print_number(ip, narg, c); 987 putchar(','); 988 print_mask_arg(sysdecode_msync_flags, *ip); 989 ip++; 990 narg--; 991 break; 992 #ifdef SYS_freebsd6_mmap 993 case SYS_freebsd6_mmap: 994 print_number(ip, narg, c); 995 print_number(ip, narg, c); 996 putchar(','); 997 print_mask_arg(sysdecode_mmap_prot, *ip); 998 putchar(','); 999 ip++; 1000 narg--; 1001 print_mask_arg(sysdecode_mmap_flags, *ip); 1002 ip++; 1003 narg--; 1004 break; 1005 #endif 1006 case SYS_mmap: 1007 print_number(ip, narg, c); 1008 print_number(ip, narg, c); 1009 putchar(','); 1010 print_mask_arg(sysdecode_mmap_prot, *ip); 1011 putchar(','); 1012 ip++; 1013 narg--; 1014 print_mask_arg(sysdecode_mmap_flags, *ip); 1015 ip++; 1016 narg--; 1017 break; 1018 case SYS_mprotect: 1019 print_number(ip, narg, c); 1020 print_number(ip, narg, c); 1021 putchar(','); 1022 print_mask_arg(sysdecode_mmap_prot, *ip); 1023 ip++; 1024 narg--; 1025 break; 1026 case SYS_madvise: 1027 print_number(ip, narg, c); 1028 print_number(ip, narg, c); 1029 putchar(','); 1030 print_integer_arg(sysdecode_madvice, *ip); 1031 ip++; 1032 narg--; 1033 break; 1034 case SYS_pathconf: 1035 case SYS_lpathconf: 1036 case SYS_fpathconf: 1037 print_number(ip, narg, c); 1038 putchar(','); 1039 print_integer_arg(sysdecode_pathconf_name, *ip); 1040 ip++; 1041 narg--; 1042 break; 1043 case SYS_getpriority: 1044 case SYS_setpriority: 1045 putchar('('); 1046 print_integer_arg(sysdecode_prio_which, *ip); 1047 c = ','; 1048 ip++; 1049 narg--; 1050 break; 1051 case SYS_fcntl: 1052 print_number(ip, narg, c); 1053 putchar(','); 1054 print_integer_arg(sysdecode_fcntl_cmd, ip[0]); 1055 if (sysdecode_fcntl_arg_p(ip[0])) { 1056 putchar(','); 1057 if (ip[0] == F_SETFL) 1058 print_mask_arg( 1059 sysdecode_fcntl_fileflags, 1060 ip[1]); 1061 else 1062 sysdecode_fcntl_arg(stdout, 1063 ip[0], ip[1], 1064 decimal ? 10 : 16); 1065 } 1066 ip += 2; 1067 narg -= 2; 1068 break; 1069 case SYS_socket: { 1070 int sockdomain; 1071 putchar('('); 1072 sockdomain = *ip; 1073 print_integer_arg(sysdecode_socketdomain, 1074 sockdomain); 1075 ip++; 1076 narg--; 1077 putchar(','); 1078 print_mask_arg(sysdecode_socket_type, *ip); 1079 ip++; 1080 narg--; 1081 if (sockdomain == PF_INET || 1082 sockdomain == PF_INET6) { 1083 putchar(','); 1084 print_integer_arg(sysdecode_ipproto, 1085 *ip); 1086 ip++; 1087 narg--; 1088 } 1089 c = ','; 1090 break; 1091 } 1092 case SYS_setsockopt: 1093 case SYS_getsockopt: { 1094 const char *str; 1095 1096 print_number(ip, narg, c); 1097 putchar(','); 1098 print_integer_arg_valid(sysdecode_sockopt_level, 1099 *ip); 1100 str = sysdecode_sockopt_name(ip[0], ip[1]); 1101 if (str != NULL) { 1102 printf(",%s", str); 1103 ip++; 1104 narg--; 1105 } 1106 ip++; 1107 narg--; 1108 break; 1109 } 1110 #ifdef SYS_freebsd6_lseek 1111 case SYS_freebsd6_lseek: 1112 print_number(ip, narg, c); 1113 /* Hidden 'pad' argument, not in lseek(2) */ 1114 print_number(ip, narg, c); 1115 print_number64(first, ip, narg, c); 1116 putchar(','); 1117 print_integer_arg(sysdecode_whence, *ip); 1118 ip++; 1119 narg--; 1120 break; 1121 #endif 1122 case SYS_lseek: 1123 print_number(ip, narg, c); 1124 print_number64(first, ip, narg, c); 1125 putchar(','); 1126 print_integer_arg(sysdecode_whence, *ip); 1127 ip++; 1128 narg--; 1129 break; 1130 case SYS_flock: 1131 print_number(ip, narg, c); 1132 putchar(','); 1133 print_mask_arg(sysdecode_flock_operation, *ip); 1134 ip++; 1135 narg--; 1136 break; 1137 case SYS_mkfifo: 1138 case SYS_mkfifoat: 1139 case SYS_mkdir: 1140 case SYS_mkdirat: 1141 print_number(ip, narg, c); 1142 putchar(','); 1143 decode_filemode(*ip); 1144 ip++; 1145 narg--; 1146 break; 1147 case SYS_shutdown: 1148 print_number(ip, narg, c); 1149 putchar(','); 1150 print_integer_arg(sysdecode_shutdown_how, *ip); 1151 ip++; 1152 narg--; 1153 break; 1154 case SYS_socketpair: 1155 putchar('('); 1156 print_integer_arg(sysdecode_socketdomain, *ip); 1157 ip++; 1158 narg--; 1159 putchar(','); 1160 print_mask_arg(sysdecode_socket_type, *ip); 1161 ip++; 1162 narg--; 1163 c = ','; 1164 break; 1165 case SYS_getrlimit: 1166 case SYS_setrlimit: 1167 putchar('('); 1168 print_integer_arg(sysdecode_rlimit, *ip); 1169 ip++; 1170 narg--; 1171 c = ','; 1172 break; 1173 case SYS_getrusage: 1174 putchar('('); 1175 print_integer_arg(sysdecode_getrusage_who, *ip); 1176 ip++; 1177 narg--; 1178 c = ','; 1179 break; 1180 case SYS_quotactl: 1181 print_number(ip, narg, c); 1182 putchar(','); 1183 if (!sysdecode_quotactl_cmd(stdout, *ip)) { 1184 if (decimal) 1185 printf("<invalid=%d>", (int)*ip); 1186 else 1187 printf("<invalid=%#x>", 1188 (int)*ip); 1189 } 1190 ip++; 1191 narg--; 1192 c = ','; 1193 break; 1194 case SYS_nfssvc: 1195 putchar('('); 1196 print_integer_arg(sysdecode_nfssvc_flags, *ip); 1197 ip++; 1198 narg--; 1199 c = ','; 1200 break; 1201 case SYS_rtprio: 1202 case SYS_rtprio_thread: 1203 putchar('('); 1204 print_integer_arg(sysdecode_rtprio_function, 1205 *ip); 1206 ip++; 1207 narg--; 1208 c = ','; 1209 break; 1210 case SYS___semctl: 1211 print_number(ip, narg, c); 1212 print_number(ip, narg, c); 1213 putchar(','); 1214 print_integer_arg(sysdecode_semctl_cmd, *ip); 1215 ip++; 1216 narg--; 1217 break; 1218 case SYS_semget: 1219 print_number(ip, narg, c); 1220 print_number(ip, narg, c); 1221 putchar(','); 1222 print_mask_arg(sysdecode_semget_flags, *ip); 1223 ip++; 1224 narg--; 1225 break; 1226 case SYS_msgctl: 1227 print_number(ip, narg, c); 1228 putchar(','); 1229 print_integer_arg(sysdecode_msgctl_cmd, *ip); 1230 ip++; 1231 narg--; 1232 break; 1233 case SYS_shmat: 1234 print_number(ip, narg, c); 1235 print_number(ip, narg, c); 1236 putchar(','); 1237 print_mask_arg(sysdecode_shmat_flags, *ip); 1238 ip++; 1239 narg--; 1240 break; 1241 case SYS_shmctl: 1242 print_number(ip, narg, c); 1243 putchar(','); 1244 print_integer_arg(sysdecode_shmctl_cmd, *ip); 1245 ip++; 1246 narg--; 1247 break; 1248 case SYS_shm_open: 1249 print_number(ip, narg, c); 1250 putchar(','); 1251 print_mask_arg(sysdecode_open_flags, ip[0]); 1252 putchar(','); 1253 decode_filemode(ip[1]); 1254 ip += 2; 1255 narg -= 2; 1256 break; 1257 case SYS_minherit: 1258 print_number(ip, narg, c); 1259 print_number(ip, narg, c); 1260 putchar(','); 1261 print_integer_arg(sysdecode_minherit_inherit, 1262 *ip); 1263 ip++; 1264 narg--; 1265 break; 1266 case SYS_rfork: 1267 putchar('('); 1268 print_mask_arg(sysdecode_rfork_flags, *ip); 1269 ip++; 1270 narg--; 1271 c = ','; 1272 break; 1273 case SYS_lio_listio: 1274 putchar('('); 1275 print_integer_arg(sysdecode_lio_listio_mode, 1276 *ip); 1277 ip++; 1278 narg--; 1279 c = ','; 1280 break; 1281 case SYS_mlockall: 1282 putchar('('); 1283 print_mask_arg(sysdecode_mlockall_flags, *ip); 1284 ip++; 1285 narg--; 1286 break; 1287 case SYS_sched_setscheduler: 1288 print_number(ip, narg, c); 1289 putchar(','); 1290 print_integer_arg(sysdecode_scheduler_policy, 1291 *ip); 1292 ip++; 1293 narg--; 1294 break; 1295 case SYS_sched_get_priority_max: 1296 case SYS_sched_get_priority_min: 1297 putchar('('); 1298 print_integer_arg(sysdecode_scheduler_policy, 1299 *ip); 1300 ip++; 1301 narg--; 1302 break; 1303 case SYS_sendfile: 1304 print_number(ip, narg, c); 1305 print_number(ip, narg, c); 1306 print_number(ip, narg, c); 1307 print_number(ip, narg, c); 1308 print_number(ip, narg, c); 1309 print_number(ip, narg, c); 1310 putchar(','); 1311 print_mask_arg(sysdecode_sendfile_flags, *ip); 1312 ip++; 1313 narg--; 1314 break; 1315 case SYS_kldsym: 1316 print_number(ip, narg, c); 1317 putchar(','); 1318 print_integer_arg(sysdecode_kldsym_cmd, *ip); 1319 ip++; 1320 narg--; 1321 break; 1322 case SYS_sigprocmask: 1323 putchar('('); 1324 print_integer_arg(sysdecode_sigprocmask_how, 1325 *ip); 1326 ip++; 1327 narg--; 1328 c = ','; 1329 break; 1330 case SYS___acl_get_file: 1331 case SYS___acl_set_file: 1332 case SYS___acl_get_fd: 1333 case SYS___acl_set_fd: 1334 case SYS___acl_delete_file: 1335 case SYS___acl_delete_fd: 1336 case SYS___acl_aclcheck_file: 1337 case SYS___acl_aclcheck_fd: 1338 case SYS___acl_get_link: 1339 case SYS___acl_set_link: 1340 case SYS___acl_delete_link: 1341 case SYS___acl_aclcheck_link: 1342 print_number(ip, narg, c); 1343 putchar(','); 1344 print_integer_arg(sysdecode_acltype, *ip); 1345 ip++; 1346 narg--; 1347 break; 1348 case SYS_sigaction: 1349 putchar('('); 1350 print_signal(*ip); 1351 ip++; 1352 narg--; 1353 c = ','; 1354 break; 1355 case SYS_extattrctl: 1356 print_number(ip, narg, c); 1357 putchar(','); 1358 print_integer_arg(sysdecode_extattrnamespace, 1359 *ip); 1360 ip++; 1361 narg--; 1362 break; 1363 case SYS_nmount: 1364 print_number(ip, narg, c); 1365 print_number(ip, narg, c); 1366 putchar(','); 1367 print_mask_arg(sysdecode_mount_flags, *ip); 1368 ip++; 1369 narg--; 1370 break; 1371 case SYS_thr_create: 1372 print_number(ip, narg, c); 1373 print_number(ip, narg, c); 1374 putchar(','); 1375 print_mask_arg(sysdecode_thr_create_flags, *ip); 1376 ip++; 1377 narg--; 1378 break; 1379 case SYS_thr_kill: 1380 print_number(ip, narg, c); 1381 putchar(','); 1382 print_signal(*ip); 1383 ip++; 1384 narg--; 1385 break; 1386 case SYS_kldunloadf: 1387 print_number(ip, narg, c); 1388 putchar(','); 1389 print_integer_arg(sysdecode_kldunload_flags, 1390 *ip); 1391 ip++; 1392 narg--; 1393 break; 1394 case SYS_linkat: 1395 case SYS_renameat: 1396 case SYS_symlinkat: 1397 print_number(ip, narg, c); 1398 putchar(','); 1399 print_integer_arg_valid(sysdecode_atfd, *ip); 1400 ip++; 1401 narg--; 1402 print_number(ip, narg, c); 1403 break; 1404 case SYS_cap_fcntls_limit: 1405 print_number(ip, narg, c); 1406 putchar(','); 1407 arg = *ip; 1408 ip++; 1409 narg--; 1410 print_mask_arg32(sysdecode_cap_fcntlrights, arg); 1411 break; 1412 case SYS_posix_fadvise: 1413 print_number(ip, narg, c); 1414 print_number(ip, narg, c); 1415 print_number(ip, narg, c); 1416 (void)putchar(','); 1417 print_integer_arg(sysdecode_fadvice, *ip); 1418 ip++; 1419 narg--; 1420 break; 1421 case SYS_procctl: 1422 putchar('('); 1423 print_integer_arg(sysdecode_idtype, *ip); 1424 c = ','; 1425 ip++; 1426 narg--; 1427 print_number64(first, ip, narg, c); 1428 putchar(','); 1429 print_integer_arg(sysdecode_procctl_cmd, *ip); 1430 ip++; 1431 narg--; 1432 break; 1433 case SYS__umtx_op: 1434 print_number(ip, narg, c); 1435 putchar(','); 1436 print_integer_arg(sysdecode_umtx_op, *ip); 1437 switch (*ip) { 1438 case UMTX_OP_CV_WAIT: 1439 ip++; 1440 narg--; 1441 putchar(','); 1442 print_mask_argul( 1443 sysdecode_umtx_cvwait_flags, *ip); 1444 break; 1445 case UMTX_OP_RW_RDLOCK: 1446 ip++; 1447 narg--; 1448 putchar(','); 1449 print_mask_argul( 1450 sysdecode_umtx_rwlock_flags, *ip); 1451 break; 1452 } 1453 ip++; 1454 narg--; 1455 break; 1456 case SYS_ftruncate: 1457 case SYS_truncate: 1458 print_number(ip, narg, c); 1459 print_number64(first, ip, narg, c); 1460 break; 1461 case SYS_fchownat: 1462 print_number(ip, narg, c); 1463 print_number(ip, narg, c); 1464 print_number(ip, narg, c); 1465 break; 1466 case SYS_fstatat: 1467 case SYS_utimensat: 1468 print_number(ip, narg, c); 1469 print_number(ip, narg, c); 1470 break; 1471 case SYS_unlinkat: 1472 print_number(ip, narg, c); 1473 break; 1474 case SYS_sysarch: 1475 putchar('('); 1476 print_integer_arg(sysdecode_sysarch_number, *ip); 1477 ip++; 1478 narg--; 1479 c = ','; 1480 break; 1481 } 1482 switch (ktr->ktr_code) { 1483 case SYS_chflagsat: 1484 case SYS_fchownat: 1485 case SYS_faccessat: 1486 case SYS_fchmodat: 1487 case SYS_fstatat: 1488 case SYS_linkat: 1489 case SYS_unlinkat: 1490 case SYS_utimensat: 1491 putchar(','); 1492 print_mask_arg0(sysdecode_atflags, *ip); 1493 ip++; 1494 narg--; 1495 break; 1496 } 1497 } 1498 while (narg > 0) { 1499 print_number(ip, narg, c); 1500 } 1501 putchar(')'); 1502 } 1503 putchar('\n'); 1504 } 1505 1506 void 1507 ktrsysret(struct ktr_sysret *ktr, u_int sv_flags) 1508 { 1509 register_t ret = ktr->ktr_retval; 1510 int error = ktr->ktr_error; 1511 1512 syscallname(ktr->ktr_code, sv_flags); 1513 printf(" "); 1514 1515 if (error == 0) { 1516 if (fancy) { 1517 printf("%ld", (long)ret); 1518 if (ret < 0 || ret > 9) 1519 printf("/%#lx", (unsigned long)ret); 1520 } else { 1521 if (decimal) 1522 printf("%ld", (long)ret); 1523 else 1524 printf("%#lx", (unsigned long)ret); 1525 } 1526 } else if (error == ERESTART) 1527 printf("RESTART"); 1528 else if (error == EJUSTRETURN) 1529 printf("JUSTRETURN"); 1530 else { 1531 printf("-1 errno %d", sysdecode_freebsd_to_abi_errno( 1532 syscallabi(sv_flags), error)); 1533 if (fancy) 1534 printf(" %s", strerror(ktr->ktr_error)); 1535 } 1536 putchar('\n'); 1537 } 1538 1539 void 1540 ktrnamei(char *cp, int len) 1541 { 1542 printf("\"%.*s\"\n", len, cp); 1543 } 1544 1545 void 1546 hexdump(char *p, int len, int screenwidth) 1547 { 1548 int n, i; 1549 int width; 1550 1551 width = 0; 1552 do { 1553 width += 2; 1554 i = 13; /* base offset */ 1555 i += (width / 2) + 1; /* spaces every second byte */ 1556 i += (width * 2); /* width of bytes */ 1557 i += 3; /* " |" */ 1558 i += width; /* each byte */ 1559 i += 1; /* "|" */ 1560 } while (i < screenwidth); 1561 width -= 2; 1562 1563 for (n = 0; n < len; n += width) { 1564 for (i = n; i < n + width; i++) { 1565 if ((i % width) == 0) { /* beginning of line */ 1566 printf(" 0x%04x", i); 1567 } 1568 if ((i % 2) == 0) { 1569 printf(" "); 1570 } 1571 if (i < len) 1572 printf("%02x", p[i] & 0xff); 1573 else 1574 printf(" "); 1575 } 1576 printf(" |"); 1577 for (i = n; i < n + width; i++) { 1578 if (i >= len) 1579 break; 1580 if (p[i] >= ' ' && p[i] <= '~') 1581 printf("%c", p[i]); 1582 else 1583 printf("."); 1584 } 1585 printf("|\n"); 1586 } 1587 if ((i % width) != 0) 1588 printf("\n"); 1589 } 1590 1591 void 1592 visdump(char *dp, int datalen, int screenwidth) 1593 { 1594 int col = 0; 1595 char *cp; 1596 int width; 1597 char visbuf[5]; 1598 1599 printf(" \""); 1600 col = 8; 1601 for (;datalen > 0; datalen--, dp++) { 1602 vis(visbuf, *dp, VIS_CSTYLE, *(dp+1)); 1603 cp = visbuf; 1604 /* 1605 * Keep track of printables and 1606 * space chars (like fold(1)). 1607 */ 1608 if (col == 0) { 1609 putchar('\t'); 1610 col = 8; 1611 } 1612 switch(*cp) { 1613 case '\n': 1614 col = 0; 1615 putchar('\n'); 1616 continue; 1617 case '\t': 1618 width = 8 - (col&07); 1619 break; 1620 default: 1621 width = strlen(cp); 1622 } 1623 if (col + width > (screenwidth-2)) { 1624 printf("\\\n\t"); 1625 col = 8; 1626 } 1627 col += width; 1628 do { 1629 putchar(*cp++); 1630 } while (*cp); 1631 } 1632 if (col == 0) 1633 printf(" "); 1634 printf("\"\n"); 1635 } 1636 1637 void 1638 ktrgenio(struct ktr_genio *ktr, int len) 1639 { 1640 int datalen = len - sizeof (struct ktr_genio); 1641 char *dp = (char *)ktr + sizeof (struct ktr_genio); 1642 static int screenwidth = 0; 1643 int i, binary; 1644 1645 printf("fd %d %s %d byte%s\n", ktr->ktr_fd, 1646 ktr->ktr_rw == UIO_READ ? "read" : "wrote", datalen, 1647 datalen == 1 ? "" : "s"); 1648 if (suppressdata) 1649 return; 1650 if (screenwidth == 0) { 1651 struct winsize ws; 1652 1653 if (fancy && ioctl(fileno(stderr), TIOCGWINSZ, &ws) != -1 && 1654 ws.ws_col > 8) 1655 screenwidth = ws.ws_col; 1656 else 1657 screenwidth = 80; 1658 } 1659 if (maxdata && datalen > maxdata) 1660 datalen = maxdata; 1661 1662 for (i = 0, binary = 0; i < datalen && binary == 0; i++) { 1663 if (dp[i] >= 32 && dp[i] < 127) 1664 continue; 1665 if (dp[i] == 10 || dp[i] == 13 || dp[i] == 0 || dp[i] == 9) 1666 continue; 1667 binary = 1; 1668 } 1669 if (binary) 1670 hexdump(dp, datalen, screenwidth); 1671 else 1672 visdump(dp, datalen, screenwidth); 1673 } 1674 1675 void 1676 ktrpsig(struct ktr_psig *psig) 1677 { 1678 const char *str; 1679 1680 print_signal(psig->signo); 1681 if (psig->action == SIG_DFL) { 1682 printf(" SIG_DFL"); 1683 } else { 1684 printf(" caught handler=0x%lx mask=0x%x", 1685 (u_long)psig->action, psig->mask.__bits[0]); 1686 } 1687 printf(" code="); 1688 str = sysdecode_sigcode(psig->signo, psig->code); 1689 if (str != NULL) 1690 printf("%s", str); 1691 else 1692 printf("<invalid=%#x>", psig->code); 1693 putchar('\n'); 1694 } 1695 1696 void 1697 ktrcsw_old(struct ktr_csw_old *cs) 1698 { 1699 printf("%s %s\n", cs->out ? "stop" : "resume", 1700 cs->user ? "user" : "kernel"); 1701 } 1702 1703 void 1704 ktrcsw(struct ktr_csw *cs) 1705 { 1706 printf("%s %s \"%s\"\n", cs->out ? "stop" : "resume", 1707 cs->user ? "user" : "kernel", cs->wmesg); 1708 } 1709 1710 void 1711 ktruser(int len, void *p) 1712 { 1713 unsigned char *cp; 1714 1715 if (sysdecode_utrace(stdout, p, len)) { 1716 printf("\n"); 1717 return; 1718 } 1719 1720 printf("%d ", len); 1721 cp = p; 1722 while (len--) 1723 if (decimal) 1724 printf(" %d", *cp++); 1725 else 1726 printf(" %02x", *cp++); 1727 printf("\n"); 1728 } 1729 1730 void 1731 ktrcaprights(cap_rights_t *rightsp) 1732 { 1733 1734 printf("cap_rights_t "); 1735 sysdecode_cap_rights(stdout, rightsp); 1736 printf("\n"); 1737 } 1738 1739 static void 1740 ktrtimeval(struct timeval *tv) 1741 { 1742 1743 printf("{%ld, %ld}", (long)tv->tv_sec, tv->tv_usec); 1744 } 1745 1746 void 1747 ktritimerval(struct itimerval *it) 1748 { 1749 1750 printf("itimerval { .interval = "); 1751 ktrtimeval(&it->it_interval); 1752 printf(", .value = "); 1753 ktrtimeval(&it->it_value); 1754 printf(" }\n"); 1755 } 1756 1757 void 1758 ktrsockaddr(struct sockaddr *sa) 1759 { 1760 /* 1761 TODO: Support additional address families 1762 #include <netsmb/netbios.h> 1763 struct sockaddr_nb *nb; 1764 */ 1765 const char *str; 1766 char addr[64]; 1767 1768 /* 1769 * note: ktrstruct() has already verified that sa points to a 1770 * buffer at least sizeof(struct sockaddr) bytes long and exactly 1771 * sa->sa_len bytes long. 1772 */ 1773 printf("struct sockaddr { "); 1774 str = sysdecode_sockaddr_family(sa->sa_family); 1775 if (str != NULL) 1776 printf("%s", str); 1777 else 1778 printf("<invalid=%d>", sa->sa_family); 1779 printf(", "); 1780 1781 #define check_sockaddr_len(n) \ 1782 if (sa_##n.s##n##_len < sizeof(struct sockaddr_##n)) { \ 1783 printf("invalid"); \ 1784 break; \ 1785 } 1786 1787 switch(sa->sa_family) { 1788 case AF_INET: { 1789 struct sockaddr_in sa_in; 1790 1791 memset(&sa_in, 0, sizeof(sa_in)); 1792 memcpy(&sa_in, sa, sa->sa_len); 1793 check_sockaddr_len(in); 1794 inet_ntop(AF_INET, &sa_in.sin_addr, addr, sizeof addr); 1795 printf("%s:%u", addr, ntohs(sa_in.sin_port)); 1796 break; 1797 } 1798 case AF_INET6: { 1799 struct sockaddr_in6 sa_in6; 1800 1801 memset(&sa_in6, 0, sizeof(sa_in6)); 1802 memcpy(&sa_in6, sa, sa->sa_len); 1803 check_sockaddr_len(in6); 1804 getnameinfo((struct sockaddr *)&sa_in6, sizeof(sa_in6), 1805 addr, sizeof(addr), NULL, 0, NI_NUMERICHOST); 1806 printf("[%s]:%u", addr, htons(sa_in6.sin6_port)); 1807 break; 1808 } 1809 case AF_UNIX: { 1810 struct sockaddr_un sa_un; 1811 1812 memset(&sa_un, 0, sizeof(sa_un)); 1813 memcpy(&sa_un, sa, sa->sa_len); 1814 printf("%.*s", (int)sizeof(sa_un.sun_path), sa_un.sun_path); 1815 break; 1816 } 1817 default: 1818 printf("unknown address family"); 1819 } 1820 printf(" }\n"); 1821 } 1822 1823 void 1824 ktrstat(struct stat *statp) 1825 { 1826 char mode[12], timestr[PATH_MAX + 4]; 1827 struct passwd *pwd; 1828 struct group *grp; 1829 struct tm *tm; 1830 1831 /* 1832 * note: ktrstruct() has already verified that statp points to a 1833 * buffer exactly sizeof(struct stat) bytes long. 1834 */ 1835 printf("struct stat {"); 1836 printf("dev=%ju, ino=%ju, ", 1837 (uintmax_t)statp->st_dev, (uintmax_t)statp->st_ino); 1838 if (resolv == 0) 1839 printf("mode=0%jo, ", (uintmax_t)statp->st_mode); 1840 else { 1841 strmode(statp->st_mode, mode); 1842 printf("mode=%s, ", mode); 1843 } 1844 printf("nlink=%ju, ", (uintmax_t)statp->st_nlink); 1845 if (resolv == 0) { 1846 pwd = NULL; 1847 } else { 1848 #ifdef WITH_CASPER 1849 if (cappwd != NULL) 1850 pwd = cap_getpwuid(cappwd, statp->st_uid); 1851 else 1852 #endif 1853 pwd = getpwuid(statp->st_uid); 1854 } 1855 if (pwd == NULL) 1856 printf("uid=%ju, ", (uintmax_t)statp->st_uid); 1857 else 1858 printf("uid=\"%s\", ", pwd->pw_name); 1859 if (resolv == 0) { 1860 grp = NULL; 1861 } else { 1862 #ifdef WITH_CASPER 1863 if (capgrp != NULL) 1864 grp = cap_getgrgid(capgrp, statp->st_gid); 1865 else 1866 #endif 1867 grp = getgrgid(statp->st_gid); 1868 } 1869 if (grp == NULL) 1870 printf("gid=%ju, ", (uintmax_t)statp->st_gid); 1871 else 1872 printf("gid=\"%s\", ", grp->gr_name); 1873 printf("rdev=%ju, ", (uintmax_t)statp->st_rdev); 1874 printf("atime="); 1875 if (resolv == 0) 1876 printf("%jd", (intmax_t)statp->st_atim.tv_sec); 1877 else { 1878 tm = localtime(&statp->st_atim.tv_sec); 1879 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1880 printf("\"%s\"", timestr); 1881 } 1882 if (statp->st_atim.tv_nsec != 0) 1883 printf(".%09ld, ", statp->st_atim.tv_nsec); 1884 else 1885 printf(", "); 1886 printf("mtime="); 1887 if (resolv == 0) 1888 printf("%jd", (intmax_t)statp->st_mtim.tv_sec); 1889 else { 1890 tm = localtime(&statp->st_mtim.tv_sec); 1891 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1892 printf("\"%s\"", timestr); 1893 } 1894 if (statp->st_mtim.tv_nsec != 0) 1895 printf(".%09ld, ", statp->st_mtim.tv_nsec); 1896 else 1897 printf(", "); 1898 printf("ctime="); 1899 if (resolv == 0) 1900 printf("%jd", (intmax_t)statp->st_ctim.tv_sec); 1901 else { 1902 tm = localtime(&statp->st_ctim.tv_sec); 1903 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1904 printf("\"%s\"", timestr); 1905 } 1906 if (statp->st_ctim.tv_nsec != 0) 1907 printf(".%09ld, ", statp->st_ctim.tv_nsec); 1908 else 1909 printf(", "); 1910 printf("birthtime="); 1911 if (resolv == 0) 1912 printf("%jd", (intmax_t)statp->st_birthtim.tv_sec); 1913 else { 1914 tm = localtime(&statp->st_birthtim.tv_sec); 1915 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1916 printf("\"%s\"", timestr); 1917 } 1918 if (statp->st_birthtim.tv_nsec != 0) 1919 printf(".%09ld, ", statp->st_birthtim.tv_nsec); 1920 else 1921 printf(", "); 1922 printf("size=%jd, blksize=%ju, blocks=%jd, flags=0x%x", 1923 (uintmax_t)statp->st_size, (uintmax_t)statp->st_blksize, 1924 (intmax_t)statp->st_blocks, statp->st_flags); 1925 printf(" }\n"); 1926 } 1927 1928 void 1929 ktrstruct(char *buf, size_t buflen) 1930 { 1931 char *name, *data; 1932 size_t namelen, datalen; 1933 int i; 1934 cap_rights_t rights; 1935 struct itimerval it; 1936 struct stat sb; 1937 struct sockaddr_storage ss; 1938 1939 for (name = buf, namelen = 0; 1940 namelen < buflen && name[namelen] != '\0'; 1941 ++namelen) 1942 /* nothing */; 1943 if (namelen == buflen) 1944 goto invalid; 1945 if (name[namelen] != '\0') 1946 goto invalid; 1947 data = buf + namelen + 1; 1948 datalen = buflen - namelen - 1; 1949 if (datalen == 0) 1950 goto invalid; 1951 /* sanity check */ 1952 for (i = 0; i < (int)namelen; ++i) 1953 if (!isalpha(name[i])) 1954 goto invalid; 1955 if (strcmp(name, "caprights") == 0) { 1956 if (datalen != sizeof(cap_rights_t)) 1957 goto invalid; 1958 memcpy(&rights, data, datalen); 1959 ktrcaprights(&rights); 1960 } else if (strcmp(name, "itimerval") == 0) { 1961 if (datalen != sizeof(struct itimerval)) 1962 goto invalid; 1963 memcpy(&it, data, datalen); 1964 ktritimerval(&it); 1965 } else if (strcmp(name, "stat") == 0) { 1966 if (datalen != sizeof(struct stat)) 1967 goto invalid; 1968 memcpy(&sb, data, datalen); 1969 ktrstat(&sb); 1970 } else if (strcmp(name, "sockaddr") == 0) { 1971 if (datalen > sizeof(ss)) 1972 goto invalid; 1973 memcpy(&ss, data, datalen); 1974 if (datalen != ss.ss_len) 1975 goto invalid; 1976 ktrsockaddr((struct sockaddr *)&ss); 1977 } else { 1978 printf("unknown structure\n"); 1979 } 1980 return; 1981 invalid: 1982 printf("invalid record\n"); 1983 } 1984 1985 void 1986 ktrcapfail(struct ktr_cap_fail *ktr) 1987 { 1988 switch (ktr->cap_type) { 1989 case CAPFAIL_NOTCAPABLE: 1990 /* operation on fd with insufficient capabilities */ 1991 printf("operation requires "); 1992 sysdecode_cap_rights(stdout, &ktr->cap_needed); 1993 printf(", descriptor holds "); 1994 sysdecode_cap_rights(stdout, &ktr->cap_held); 1995 break; 1996 case CAPFAIL_INCREASE: 1997 /* requested more capabilities than fd already has */ 1998 printf("attempt to increase capabilities from "); 1999 sysdecode_cap_rights(stdout, &ktr->cap_held); 2000 printf(" to "); 2001 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2002 break; 2003 case CAPFAIL_SYSCALL: 2004 /* called restricted syscall */ 2005 printf("disallowed system call"); 2006 break; 2007 case CAPFAIL_LOOKUP: 2008 /* used ".." in strict-relative mode */ 2009 printf("restricted VFS lookup"); 2010 break; 2011 default: 2012 printf("unknown capability failure: "); 2013 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2014 printf(" "); 2015 sysdecode_cap_rights(stdout, &ktr->cap_held); 2016 break; 2017 } 2018 printf("\n"); 2019 } 2020 2021 void 2022 ktrfault(struct ktr_fault *ktr) 2023 { 2024 2025 printf("0x%jx ", (uintmax_t)ktr->vaddr); 2026 print_mask_arg(sysdecode_vmprot, ktr->type); 2027 printf("\n"); 2028 } 2029 2030 void 2031 ktrfaultend(struct ktr_faultend *ktr) 2032 { 2033 const char *str; 2034 2035 str = sysdecode_vmresult(ktr->result); 2036 if (str != NULL) 2037 printf("%s", str); 2038 else 2039 printf("<invalid=%d>", ktr->result); 2040 printf("\n"); 2041 } 2042 2043 void 2044 ktrkevent(struct kevent *kev) 2045 { 2046 2047 printf("{ ident="); 2048 switch (kev->filter) { 2049 case EVFILT_READ: 2050 case EVFILT_WRITE: 2051 case EVFILT_VNODE: 2052 case EVFILT_PROC: 2053 case EVFILT_TIMER: 2054 case EVFILT_PROCDESC: 2055 case EVFILT_EMPTY: 2056 printf("%ju", (uintmax_t)kev->ident); 2057 break; 2058 case EVFILT_SIGNAL: 2059 print_signal(kev->ident); 2060 break; 2061 default: 2062 printf("%p", (void *)kev->ident); 2063 } 2064 printf(", filter="); 2065 print_integer_arg(sysdecode_kevent_filter, kev->filter); 2066 printf(", flags="); 2067 print_mask_arg0(sysdecode_kevent_flags, kev->flags); 2068 printf(", fflags="); 2069 sysdecode_kevent_fflags(stdout, kev->filter, kev->fflags, 2070 decimal ? 10 : 16); 2071 printf(", data=%#jx, udata=%p }", (uintmax_t)kev->data, kev->udata); 2072 } 2073 2074 void 2075 ktrstructarray(struct ktr_struct_array *ksa, size_t buflen) 2076 { 2077 struct kevent kev; 2078 char *name, *data; 2079 size_t namelen, datalen; 2080 int i; 2081 bool first; 2082 2083 buflen -= sizeof(*ksa); 2084 for (name = (char *)(ksa + 1), namelen = 0; 2085 namelen < buflen && name[namelen] != '\0'; 2086 ++namelen) 2087 /* nothing */; 2088 if (namelen == buflen) 2089 goto invalid; 2090 if (name[namelen] != '\0') 2091 goto invalid; 2092 /* sanity check */ 2093 for (i = 0; i < (int)namelen; ++i) 2094 if (!isalnum(name[i]) && name[i] != '_') 2095 goto invalid; 2096 data = name + namelen + 1; 2097 datalen = buflen - namelen - 1; 2098 printf("struct %s[] = { ", name); 2099 first = true; 2100 for (; datalen >= ksa->struct_size; 2101 data += ksa->struct_size, datalen -= ksa->struct_size) { 2102 if (!first) 2103 printf("\n "); 2104 else 2105 first = false; 2106 if (strcmp(name, "kevent") == 0) { 2107 if (ksa->struct_size != sizeof(kev)) 2108 goto bad_size; 2109 memcpy(&kev, data, sizeof(kev)); 2110 ktrkevent(&kev); 2111 } else if (strcmp(name, "kevent_freebsd11") == 0) { 2112 struct kevent_freebsd11 kev11; 2113 2114 if (ksa->struct_size != sizeof(kev11)) 2115 goto bad_size; 2116 memcpy(&kev11, data, sizeof(kev11)); 2117 memset(&kev, 0, sizeof(kev)); 2118 kev.ident = kev11.ident; 2119 kev.filter = kev11.filter; 2120 kev.flags = kev11.flags; 2121 kev.fflags = kev11.fflags; 2122 kev.data = kev11.data; 2123 kev.udata = kev11.udata; 2124 ktrkevent(&kev); 2125 #ifdef _WANT_KEVENT32 2126 } else if (strcmp(name, "kevent32") == 0) { 2127 struct kevent32 kev32; 2128 2129 if (ksa->struct_size != sizeof(kev32)) 2130 goto bad_size; 2131 memcpy(&kev32, data, sizeof(kev32)); 2132 memset(&kev, 0, sizeof(kev)); 2133 kev.ident = kev32.ident; 2134 kev.filter = kev32.filter; 2135 kev.flags = kev32.flags; 2136 kev.fflags = kev32.fflags; 2137 #if BYTE_ORDER == BIG_ENDIAN 2138 kev.data = kev32.data2 | ((int64_t)kev32.data1 << 32); 2139 #else 2140 kev.data = kev32.data1 | ((int64_t)kev32.data2 << 32); 2141 #endif 2142 kev.udata = (void *)(uintptr_t)kev32.udata; 2143 ktrkevent(&kev); 2144 } else if (strcmp(name, "kevent32_freebsd11") == 0) { 2145 struct kevent32_freebsd11 kev32; 2146 2147 if (ksa->struct_size != sizeof(kev32)) 2148 goto bad_size; 2149 memcpy(&kev32, data, sizeof(kev32)); 2150 memset(&kev, 0, sizeof(kev)); 2151 kev.ident = kev32.ident; 2152 kev.filter = kev32.filter; 2153 kev.flags = kev32.flags; 2154 kev.fflags = kev32.fflags; 2155 kev.data = kev32.data; 2156 kev.udata = (void *)(uintptr_t)kev32.udata; 2157 ktrkevent(&kev); 2158 #endif 2159 } else { 2160 printf("<unknown structure> }\n"); 2161 return; 2162 } 2163 } 2164 printf(" }\n"); 2165 return; 2166 invalid: 2167 printf("invalid record\n"); 2168 return; 2169 bad_size: 2170 printf("<bad size> }\n"); 2171 return; 2172 } 2173 2174 void 2175 usage(void) 2176 { 2177 fprintf(stderr, "usage: kdump [-dEnlHRrSsTA] [-f trfile] " 2178 "[-m maxdata] [-p pid] [-t trstr]\n"); 2179 exit(1); 2180 } 2181