1 /*- 2 * SPDX-License-Identifier: BSD-3-Clause 3 * 4 * Copyright (c) 1988, 1993 5 * The Regents of the University of California. All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the University nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32 #ifndef lint 33 static const char copyright[] = 34 "@(#) Copyright (c) 1988, 1993\n\ 35 The Regents of the University of California. All rights reserved.\n"; 36 #endif /* not lint */ 37 38 #ifndef lint 39 #if 0 40 static char sccsid[] = "@(#)kdump.c 8.1 (Berkeley) 6/6/93"; 41 #endif 42 #endif /* not lint */ 43 #include <sys/cdefs.h> 44 __FBSDID("$FreeBSD$"); 45 46 #define _WANT_KERNEL_ERRNO 47 #ifdef __LP64__ 48 #define _WANT_KEVENT32 49 #endif 50 #define _WANT_FREEBSD11_KEVENT 51 #include <sys/param.h> 52 #include <sys/capsicum.h> 53 #include <sys/errno.h> 54 #include <sys/time.h> 55 #include <sys/uio.h> 56 #include <sys/event.h> 57 #include <sys/ktrace.h> 58 #include <sys/ioctl.h> 59 #include <sys/socket.h> 60 #include <sys/stat.h> 61 #include <sys/sysent.h> 62 #include <sys/umtx.h> 63 #include <sys/un.h> 64 #include <sys/queue.h> 65 #include <sys/wait.h> 66 #ifdef WITH_CASPER 67 #include <sys/nv.h> 68 #endif 69 #include <arpa/inet.h> 70 #include <netinet/in.h> 71 #include <ctype.h> 72 #include <capsicum_helpers.h> 73 #include <err.h> 74 #include <grp.h> 75 #include <inttypes.h> 76 #include <locale.h> 77 #include <netdb.h> 78 #include <nl_types.h> 79 #include <pwd.h> 80 #include <stddef.h> 81 #include <stdio.h> 82 #include <stdlib.h> 83 #include <string.h> 84 #include <sysdecode.h> 85 #include <time.h> 86 #include <unistd.h> 87 #include <vis.h> 88 #include "ktrace.h" 89 90 #ifdef WITH_CASPER 91 #include <libcasper.h> 92 93 #include <casper/cap_grp.h> 94 #include <casper/cap_pwd.h> 95 #endif 96 97 u_int abidump(struct ktr_header *); 98 int fetchprocinfo(struct ktr_header *, u_int *); 99 int fread_tail(void *, int, int); 100 void dumpheader(struct ktr_header *); 101 void ktrsyscall(struct ktr_syscall *, u_int); 102 void ktrsysret(struct ktr_sysret *, u_int); 103 void ktrnamei(char *, int); 104 void hexdump(char *, int, int); 105 void visdump(char *, int, int); 106 void ktrgenio(struct ktr_genio *, int); 107 void ktrpsig(struct ktr_psig *); 108 void ktrcsw(struct ktr_csw *); 109 void ktrcsw_old(struct ktr_csw_old *); 110 void ktruser(int, void *); 111 void ktrcaprights(cap_rights_t *); 112 void ktritimerval(struct itimerval *it); 113 void ktrsockaddr(struct sockaddr *); 114 void ktrstat(struct stat *); 115 void ktrstruct(char *, size_t); 116 void ktrcapfail(struct ktr_cap_fail *); 117 void ktrfault(struct ktr_fault *); 118 void ktrfaultend(struct ktr_faultend *); 119 void ktrkevent(struct kevent *); 120 void ktrstructarray(struct ktr_struct_array *, size_t); 121 void usage(void); 122 123 #define TIMESTAMP_NONE 0x0 124 #define TIMESTAMP_ABSOLUTE 0x1 125 #define TIMESTAMP_ELAPSED 0x2 126 #define TIMESTAMP_RELATIVE 0x4 127 128 static int timestamp, decimal, fancy = 1, suppressdata, tail, threads, maxdata, 129 resolv = 0, abiflag = 0, syscallno = 0; 130 static const char *tracefile = DEF_TRACEFILE; 131 static struct ktr_header ktr_header; 132 133 #define TIME_FORMAT "%b %e %T %Y" 134 #define eqs(s1, s2) (strcmp((s1), (s2)) == 0) 135 136 #define print_number64(first,i,n,c) do { \ 137 uint64_t __v; \ 138 \ 139 if (quad_align && (((ptrdiff_t)((i) - (first))) & 1) == 1) { \ 140 (i)++; \ 141 (n)--; \ 142 } \ 143 if (quad_slots == 2) \ 144 __v = (uint64_t)(uint32_t)(i)[0] | \ 145 ((uint64_t)(uint32_t)(i)[1]) << 32; \ 146 else \ 147 __v = (uint64_t)*(i); \ 148 if (decimal) \ 149 printf("%c%jd", (c), (intmax_t)__v); \ 150 else \ 151 printf("%c%#jx", (c), (uintmax_t)__v); \ 152 (i) += quad_slots; \ 153 (n) -= quad_slots; \ 154 (c) = ','; \ 155 } while (0) 156 157 #define print_number(i,n,c) do { \ 158 if (decimal) \ 159 printf("%c%jd", c, (intmax_t)*i); \ 160 else \ 161 printf("%c%#jx", c, (uintmax_t)(u_register_t)*i); \ 162 i++; \ 163 n--; \ 164 c = ','; \ 165 } while (0) 166 167 struct proc_info 168 { 169 TAILQ_ENTRY(proc_info) info; 170 u_int sv_flags; 171 pid_t pid; 172 }; 173 174 static TAILQ_HEAD(trace_procs, proc_info) trace_procs; 175 176 #ifdef WITH_CASPER 177 static cap_channel_t *cappwd, *capgrp; 178 #endif 179 180 static void 181 strerror_init(void) 182 { 183 184 /* 185 * Cache NLS data before entering capability mode. 186 * XXXPJD: There should be strerror_init() and strsignal_init() in libc. 187 */ 188 (void)catopen("libc", NL_CAT_LOCALE); 189 } 190 191 static void 192 localtime_init(void) 193 { 194 time_t ltime; 195 196 /* 197 * Allow localtime(3) to cache /etc/localtime content before entering 198 * capability mode. 199 * XXXPJD: There should be localtime_init() in libc. 200 */ 201 (void)time(<ime); 202 (void)localtime(<ime); 203 } 204 205 #ifdef WITH_CASPER 206 static int 207 cappwdgrp_setup(cap_channel_t **cappwdp, cap_channel_t **capgrpp) 208 { 209 cap_channel_t *capcas, *cappwdloc, *capgrploc; 210 const char *cmds[1], *fields[1]; 211 212 capcas = cap_init(); 213 if (capcas == NULL) { 214 err(1, "unable to create casper process"); 215 exit(1); 216 } 217 cappwdloc = cap_service_open(capcas, "system.pwd"); 218 capgrploc = cap_service_open(capcas, "system.grp"); 219 /* Casper capability no longer needed. */ 220 cap_close(capcas); 221 if (cappwdloc == NULL || capgrploc == NULL) { 222 if (cappwdloc == NULL) 223 warn("unable to open system.pwd service"); 224 if (capgrploc == NULL) 225 warn("unable to open system.grp service"); 226 exit(1); 227 } 228 /* Limit system.pwd to only getpwuid() function and pw_name field. */ 229 cmds[0] = "getpwuid"; 230 if (cap_pwd_limit_cmds(cappwdloc, cmds, 1) < 0) 231 err(1, "unable to limit system.pwd service"); 232 fields[0] = "pw_name"; 233 if (cap_pwd_limit_fields(cappwdloc, fields, 1) < 0) 234 err(1, "unable to limit system.pwd service"); 235 /* Limit system.grp to only getgrgid() function and gr_name field. */ 236 cmds[0] = "getgrgid"; 237 if (cap_grp_limit_cmds(capgrploc, cmds, 1) < 0) 238 err(1, "unable to limit system.grp service"); 239 fields[0] = "gr_name"; 240 if (cap_grp_limit_fields(capgrploc, fields, 1) < 0) 241 err(1, "unable to limit system.grp service"); 242 243 *cappwdp = cappwdloc; 244 *capgrpp = capgrploc; 245 return (0); 246 } 247 #endif /* WITH_CASPER */ 248 249 static void 250 print_integer_arg(const char *(*decoder)(int), int value) 251 { 252 const char *str; 253 254 str = decoder(value); 255 if (str != NULL) 256 printf("%s", str); 257 else { 258 if (decimal) 259 printf("<invalid=%d>", value); 260 else 261 printf("<invalid=%#x>", value); 262 } 263 } 264 265 /* Like print_integer_arg but unknown values are treated as valid. */ 266 static void 267 print_integer_arg_valid(const char *(*decoder)(int), int value) 268 { 269 const char *str; 270 271 str = decoder(value); 272 if (str != NULL) 273 printf("%s", str); 274 else { 275 if (decimal) 276 printf("%d", value); 277 else 278 printf("%#x", value); 279 } 280 } 281 282 static void 283 print_mask_arg(bool (*decoder)(FILE *, int, int *), int value) 284 { 285 bool invalid; 286 int rem; 287 288 printf("%#x<", value); 289 invalid = !decoder(stdout, value, &rem); 290 printf(">"); 291 if (invalid) 292 printf("<invalid>%u", rem); 293 } 294 295 static void 296 print_mask_arg0(bool (*decoder)(FILE *, int, int *), int value) 297 { 298 bool invalid; 299 int rem; 300 301 if (value == 0) { 302 printf("0"); 303 return; 304 } 305 printf("%#x<", value); 306 invalid = !decoder(stdout, value, &rem); 307 printf(">"); 308 if (invalid) 309 printf("<invalid>%u", rem); 310 } 311 312 static void 313 decode_fileflags(fflags_t value) 314 { 315 bool invalid; 316 fflags_t rem; 317 318 if (value == 0) { 319 printf("0"); 320 return; 321 } 322 printf("%#x<", value); 323 invalid = !sysdecode_fileflags(stdout, value, &rem); 324 printf(">"); 325 if (invalid) 326 printf("<invalid>%u", rem); 327 } 328 329 static void 330 decode_filemode(int value) 331 { 332 bool invalid; 333 int rem; 334 335 if (value == 0) { 336 printf("0"); 337 return; 338 } 339 printf("%#o<", value); 340 invalid = !sysdecode_filemode(stdout, value, &rem); 341 printf(">"); 342 if (invalid) 343 printf("<invalid>%u", rem); 344 } 345 346 static void 347 print_mask_arg32(bool (*decoder)(FILE *, uint32_t, uint32_t *), uint32_t value) 348 { 349 bool invalid; 350 uint32_t rem; 351 352 printf("%#x<", value); 353 invalid = !decoder(stdout, value, &rem); 354 printf(">"); 355 if (invalid) 356 printf("<invalid>%u", rem); 357 } 358 359 static void 360 print_mask_argul(bool (*decoder)(FILE *, u_long, u_long *), u_long value) 361 { 362 bool invalid; 363 u_long rem; 364 365 if (value == 0) { 366 printf("0"); 367 return; 368 } 369 printf("%#lx<", value); 370 invalid = !decoder(stdout, value, &rem); 371 printf(">"); 372 if (invalid) 373 printf("<invalid>%lu", rem); 374 } 375 376 int 377 main(int argc, char *argv[]) 378 { 379 int ch, ktrlen, size; 380 void *m; 381 int trpoints = ALL_POINTS; 382 int drop_logged; 383 pid_t pid = 0; 384 u_int sv_flags; 385 386 setlocale(LC_CTYPE, ""); 387 388 timestamp = TIMESTAMP_NONE; 389 390 while ((ch = getopt(argc,argv,"f:dElm:np:AHRrSsTt:")) != -1) 391 switch (ch) { 392 case 'A': 393 abiflag = 1; 394 break; 395 case 'f': 396 tracefile = optarg; 397 break; 398 case 'd': 399 decimal = 1; 400 break; 401 case 'l': 402 tail = 1; 403 break; 404 case 'm': 405 maxdata = atoi(optarg); 406 break; 407 case 'n': 408 fancy = 0; 409 break; 410 case 'p': 411 pid = atoi(optarg); 412 break; 413 case 'r': 414 resolv = 1; 415 break; 416 case 'S': 417 syscallno = 1; 418 break; 419 case 's': 420 suppressdata = 1; 421 break; 422 case 'E': 423 timestamp |= TIMESTAMP_ELAPSED; 424 break; 425 case 'H': 426 threads = 1; 427 break; 428 case 'R': 429 timestamp |= TIMESTAMP_RELATIVE; 430 break; 431 case 'T': 432 timestamp |= TIMESTAMP_ABSOLUTE; 433 break; 434 case 't': 435 trpoints = getpoints(optarg); 436 if (trpoints < 0) 437 errx(1, "unknown trace point in %s", optarg); 438 break; 439 default: 440 usage(); 441 } 442 443 if (argc > optind) 444 usage(); 445 446 m = malloc(size = 1025); 447 if (m == NULL) 448 errx(1, "%s", strerror(ENOMEM)); 449 if (strcmp(tracefile, "-") != 0) 450 if (!freopen(tracefile, "r", stdin)) 451 err(1, "%s", tracefile); 452 453 strerror_init(); 454 localtime_init(); 455 #ifdef WITH_CASPER 456 if (resolv != 0) { 457 if (cappwdgrp_setup(&cappwd, &capgrp) < 0) { 458 cappwd = NULL; 459 capgrp = NULL; 460 } 461 } 462 if (resolv == 0 || (cappwd != NULL && capgrp != NULL)) { 463 if (cap_enter() < 0 && errno != ENOSYS) 464 err(1, "unable to enter capability mode"); 465 } 466 #else 467 if (resolv == 0) { 468 if (cap_enter() < 0 && errno != ENOSYS) 469 err(1, "unable to enter capability mode"); 470 } 471 #endif 472 if (caph_limit_stdio() == -1) 473 err(1, "unable to limit stdio"); 474 475 TAILQ_INIT(&trace_procs); 476 drop_logged = 0; 477 while (fread_tail(&ktr_header, sizeof(struct ktr_header), 1)) { 478 if (ktr_header.ktr_type & KTR_DROP) { 479 ktr_header.ktr_type &= ~KTR_DROP; 480 if (!drop_logged && threads) { 481 printf( 482 "%6jd %6jd %-8.*s Events dropped.\n", 483 (intmax_t)ktr_header.ktr_pid, 484 ktr_header.ktr_tid > 0 ? 485 (intmax_t)ktr_header.ktr_tid : 0, 486 MAXCOMLEN, ktr_header.ktr_comm); 487 drop_logged = 1; 488 } else if (!drop_logged) { 489 printf("%6jd %-8.*s Events dropped.\n", 490 (intmax_t)ktr_header.ktr_pid, MAXCOMLEN, 491 ktr_header.ktr_comm); 492 drop_logged = 1; 493 } 494 } 495 if (trpoints & (1<<ktr_header.ktr_type)) 496 if (pid == 0 || ktr_header.ktr_pid == pid || 497 ktr_header.ktr_tid == pid) 498 dumpheader(&ktr_header); 499 if ((ktrlen = ktr_header.ktr_len) < 0) 500 errx(1, "bogus length 0x%x", ktrlen); 501 if (ktrlen > size) { 502 m = realloc(m, ktrlen+1); 503 if (m == NULL) 504 errx(1, "%s", strerror(ENOMEM)); 505 size = ktrlen; 506 } 507 if (ktrlen && fread_tail(m, ktrlen, 1) == 0) 508 errx(1, "data too short"); 509 if (fetchprocinfo(&ktr_header, (u_int *)m) != 0) 510 continue; 511 sv_flags = abidump(&ktr_header); 512 if (pid && ktr_header.ktr_pid != pid && 513 ktr_header.ktr_tid != pid) 514 continue; 515 if ((trpoints & (1<<ktr_header.ktr_type)) == 0) 516 continue; 517 drop_logged = 0; 518 switch (ktr_header.ktr_type) { 519 case KTR_SYSCALL: 520 ktrsyscall((struct ktr_syscall *)m, sv_flags); 521 break; 522 case KTR_SYSRET: 523 ktrsysret((struct ktr_sysret *)m, sv_flags); 524 break; 525 case KTR_NAMEI: 526 case KTR_SYSCTL: 527 ktrnamei(m, ktrlen); 528 break; 529 case KTR_GENIO: 530 ktrgenio((struct ktr_genio *)m, ktrlen); 531 break; 532 case KTR_PSIG: 533 ktrpsig((struct ktr_psig *)m); 534 break; 535 case KTR_CSW: 536 if (ktrlen == sizeof(struct ktr_csw_old)) 537 ktrcsw_old((struct ktr_csw_old *)m); 538 else 539 ktrcsw((struct ktr_csw *)m); 540 break; 541 case KTR_USER: 542 ktruser(ktrlen, m); 543 break; 544 case KTR_STRUCT: 545 ktrstruct(m, ktrlen); 546 break; 547 case KTR_CAPFAIL: 548 ktrcapfail((struct ktr_cap_fail *)m); 549 break; 550 case KTR_FAULT: 551 ktrfault((struct ktr_fault *)m); 552 break; 553 case KTR_FAULTEND: 554 ktrfaultend((struct ktr_faultend *)m); 555 break; 556 case KTR_STRUCT_ARRAY: 557 ktrstructarray((struct ktr_struct_array *)m, ktrlen); 558 break; 559 default: 560 printf("\n"); 561 break; 562 } 563 if (tail) 564 fflush(stdout); 565 } 566 return 0; 567 } 568 569 int 570 fread_tail(void *buf, int size, int num) 571 { 572 int i; 573 574 while ((i = fread(buf, size, num, stdin)) == 0 && tail) { 575 sleep(1); 576 clearerr(stdin); 577 } 578 return (i); 579 } 580 581 int 582 fetchprocinfo(struct ktr_header *kth, u_int *flags) 583 { 584 struct proc_info *pi; 585 586 switch (kth->ktr_type) { 587 case KTR_PROCCTOR: 588 TAILQ_FOREACH(pi, &trace_procs, info) { 589 if (pi->pid == kth->ktr_pid) { 590 TAILQ_REMOVE(&trace_procs, pi, info); 591 break; 592 } 593 } 594 pi = malloc(sizeof(struct proc_info)); 595 if (pi == NULL) 596 errx(1, "%s", strerror(ENOMEM)); 597 pi->sv_flags = *flags; 598 pi->pid = kth->ktr_pid; 599 TAILQ_INSERT_TAIL(&trace_procs, pi, info); 600 return (1); 601 602 case KTR_PROCDTOR: 603 TAILQ_FOREACH(pi, &trace_procs, info) { 604 if (pi->pid == kth->ktr_pid) { 605 TAILQ_REMOVE(&trace_procs, pi, info); 606 free(pi); 607 break; 608 } 609 } 610 return (1); 611 } 612 613 return (0); 614 } 615 616 u_int 617 abidump(struct ktr_header *kth) 618 { 619 struct proc_info *pi; 620 const char *abi; 621 const char *arch; 622 u_int flags = 0; 623 624 TAILQ_FOREACH(pi, &trace_procs, info) { 625 if (pi->pid == kth->ktr_pid) { 626 flags = pi->sv_flags; 627 break; 628 } 629 } 630 631 if (abiflag == 0) 632 return (flags); 633 634 switch (flags & SV_ABI_MASK) { 635 case SV_ABI_LINUX: 636 abi = "L"; 637 break; 638 case SV_ABI_FREEBSD: 639 abi = "F"; 640 break; 641 case SV_ABI_CLOUDABI: 642 abi = "C"; 643 break; 644 default: 645 abi = "U"; 646 break; 647 } 648 649 if (flags & SV_LP64) 650 arch = "64"; 651 else if (flags & SV_ILP32) 652 arch = "32"; 653 else 654 arch = "00"; 655 656 printf("%s%s ", abi, arch); 657 658 return (flags); 659 } 660 661 void 662 dumpheader(struct ktr_header *kth) 663 { 664 static char unknown[64]; 665 static struct timeval prevtime, prevtime_e; 666 struct timeval temp; 667 const char *type; 668 const char *sign; 669 670 switch (kth->ktr_type) { 671 case KTR_SYSCALL: 672 type = "CALL"; 673 break; 674 case KTR_SYSRET: 675 type = "RET "; 676 break; 677 case KTR_NAMEI: 678 type = "NAMI"; 679 break; 680 case KTR_GENIO: 681 type = "GIO "; 682 break; 683 case KTR_PSIG: 684 type = "PSIG"; 685 break; 686 case KTR_CSW: 687 type = "CSW "; 688 break; 689 case KTR_USER: 690 type = "USER"; 691 break; 692 case KTR_STRUCT: 693 case KTR_STRUCT_ARRAY: 694 type = "STRU"; 695 break; 696 case KTR_SYSCTL: 697 type = "SCTL"; 698 break; 699 case KTR_PROCCTOR: 700 /* FALLTHROUGH */ 701 case KTR_PROCDTOR: 702 return; 703 case KTR_CAPFAIL: 704 type = "CAP "; 705 break; 706 case KTR_FAULT: 707 type = "PFLT"; 708 break; 709 case KTR_FAULTEND: 710 type = "PRET"; 711 break; 712 default: 713 sprintf(unknown, "UNKNOWN(%d)", kth->ktr_type); 714 type = unknown; 715 } 716 717 /* 718 * The ktr_tid field was previously the ktr_buffer field, which held 719 * the kernel pointer value for the buffer associated with data 720 * following the record header. It now holds a threadid, but only 721 * for trace files after the change. Older trace files still contain 722 * kernel pointers. Detect this and suppress the results by printing 723 * negative tid's as 0. 724 */ 725 if (threads) 726 printf("%6jd %6jd %-8.*s ", (intmax_t)kth->ktr_pid, 727 kth->ktr_tid > 0 ? (intmax_t)kth->ktr_tid : 0, 728 MAXCOMLEN, kth->ktr_comm); 729 else 730 printf("%6jd %-8.*s ", (intmax_t)kth->ktr_pid, MAXCOMLEN, 731 kth->ktr_comm); 732 if (timestamp) { 733 if (timestamp & TIMESTAMP_ABSOLUTE) { 734 printf("%jd.%06ld ", (intmax_t)kth->ktr_time.tv_sec, 735 kth->ktr_time.tv_usec); 736 } 737 if (timestamp & TIMESTAMP_ELAPSED) { 738 if (prevtime_e.tv_sec == 0) 739 prevtime_e = kth->ktr_time; 740 timersub(&kth->ktr_time, &prevtime_e, &temp); 741 printf("%jd.%06ld ", (intmax_t)temp.tv_sec, 742 temp.tv_usec); 743 } 744 if (timestamp & TIMESTAMP_RELATIVE) { 745 if (prevtime.tv_sec == 0) 746 prevtime = kth->ktr_time; 747 if (timercmp(&kth->ktr_time, &prevtime, <)) { 748 timersub(&prevtime, &kth->ktr_time, &temp); 749 sign = "-"; 750 } else { 751 timersub(&kth->ktr_time, &prevtime, &temp); 752 sign = ""; 753 } 754 prevtime = kth->ktr_time; 755 printf("%s%jd.%06ld ", sign, (intmax_t)temp.tv_sec, 756 temp.tv_usec); 757 } 758 } 759 printf("%s ", type); 760 } 761 762 #include <sys/syscall.h> 763 764 static void 765 ioctlname(unsigned long val) 766 { 767 const char *str; 768 769 str = sysdecode_ioctlname(val); 770 if (str != NULL) 771 printf("%s", str); 772 else if (decimal) 773 printf("%lu", val); 774 else 775 printf("%#lx", val); 776 } 777 778 static enum sysdecode_abi 779 syscallabi(u_int sv_flags) 780 { 781 782 if (sv_flags == 0) 783 return (SYSDECODE_ABI_FREEBSD); 784 switch (sv_flags & SV_ABI_MASK) { 785 case SV_ABI_FREEBSD: 786 return (SYSDECODE_ABI_FREEBSD); 787 #if defined(__amd64__) || defined(__i386__) 788 case SV_ABI_LINUX: 789 #ifdef __amd64__ 790 if (sv_flags & SV_ILP32) 791 return (SYSDECODE_ABI_LINUX32); 792 #endif 793 return (SYSDECODE_ABI_LINUX); 794 #endif 795 #if defined(__aarch64__) || defined(__amd64__) 796 case SV_ABI_CLOUDABI: 797 return (SYSDECODE_ABI_CLOUDABI64); 798 #endif 799 default: 800 return (SYSDECODE_ABI_UNKNOWN); 801 } 802 } 803 804 static void 805 syscallname(u_int code, u_int sv_flags) 806 { 807 const char *name; 808 809 name = sysdecode_syscallname(syscallabi(sv_flags), code); 810 if (name == NULL) 811 printf("[%d]", code); 812 else { 813 printf("%s", name); 814 if (syscallno) 815 printf("[%d]", code); 816 } 817 } 818 819 static void 820 print_signal(int signo) 821 { 822 const char *signame; 823 824 signame = sysdecode_signal(signo); 825 if (signame != NULL) 826 printf("%s", signame); 827 else 828 printf("SIG %d", signo); 829 } 830 831 void 832 ktrsyscall(struct ktr_syscall *ktr, u_int sv_flags) 833 { 834 int narg = ktr->ktr_narg; 835 register_t *ip, *first; 836 intmax_t arg; 837 int quad_align, quad_slots; 838 839 syscallname(ktr->ktr_code, sv_flags); 840 ip = first = &ktr->ktr_args[0]; 841 if (narg) { 842 char c = '('; 843 if (fancy && 844 (sv_flags == 0 || 845 (sv_flags & SV_ABI_MASK) == SV_ABI_FREEBSD)) { 846 quad_align = 0; 847 if (sv_flags & SV_ILP32) { 848 #ifdef __powerpc__ 849 quad_align = 1; 850 #endif 851 quad_slots = 2; 852 } else 853 quad_slots = 1; 854 switch (ktr->ktr_code) { 855 case SYS_bindat: 856 case SYS_chflagsat: 857 case SYS_connectat: 858 case SYS_faccessat: 859 case SYS_fchmodat: 860 case SYS_fchownat: 861 case SYS_fstatat: 862 case SYS_futimesat: 863 case SYS_linkat: 864 case SYS_mkdirat: 865 case SYS_mkfifoat: 866 case SYS_mknodat: 867 case SYS_openat: 868 case SYS_readlinkat: 869 case SYS_renameat: 870 case SYS_unlinkat: 871 case SYS_utimensat: 872 putchar('('); 873 print_integer_arg_valid(sysdecode_atfd, *ip); 874 c = ','; 875 ip++; 876 narg--; 877 break; 878 } 879 switch (ktr->ktr_code) { 880 case SYS_ioctl: { 881 print_number(ip, narg, c); 882 putchar(c); 883 ioctlname(*ip); 884 c = ','; 885 ip++; 886 narg--; 887 break; 888 } 889 case SYS_ptrace: 890 putchar('('); 891 print_integer_arg(sysdecode_ptrace_request, *ip); 892 c = ','; 893 ip++; 894 narg--; 895 break; 896 case SYS_access: 897 case SYS_eaccess: 898 case SYS_faccessat: 899 print_number(ip, narg, c); 900 putchar(','); 901 print_mask_arg(sysdecode_access_mode, *ip); 902 ip++; 903 narg--; 904 break; 905 case SYS_open: 906 case SYS_openat: 907 print_number(ip, narg, c); 908 putchar(','); 909 print_mask_arg(sysdecode_open_flags, ip[0]); 910 if ((ip[0] & O_CREAT) == O_CREAT) { 911 putchar(','); 912 decode_filemode(ip[1]); 913 } 914 ip += 2; 915 narg -= 2; 916 break; 917 case SYS_wait4: 918 print_number(ip, narg, c); 919 print_number(ip, narg, c); 920 putchar(','); 921 print_mask_arg0(sysdecode_wait4_options, *ip); 922 ip++; 923 narg--; 924 break; 925 case SYS_wait6: 926 putchar('('); 927 print_integer_arg(sysdecode_idtype, *ip); 928 c = ','; 929 ip++; 930 narg--; 931 print_number64(first, ip, narg, c); 932 print_number(ip, narg, c); 933 putchar(','); 934 print_mask_arg(sysdecode_wait6_options, *ip); 935 ip++; 936 narg--; 937 break; 938 case SYS_chmod: 939 case SYS_fchmod: 940 case SYS_lchmod: 941 case SYS_fchmodat: 942 print_number(ip, narg, c); 943 putchar(','); 944 decode_filemode(*ip); 945 ip++; 946 narg--; 947 break; 948 case SYS_mknodat: 949 print_number(ip, narg, c); 950 putchar(','); 951 decode_filemode(*ip); 952 ip++; 953 narg--; 954 break; 955 case SYS_getfsstat: 956 print_number(ip, narg, c); 957 print_number(ip, narg, c); 958 putchar(','); 959 print_integer_arg(sysdecode_getfsstat_mode, *ip); 960 ip++; 961 narg--; 962 break; 963 case SYS_mount: 964 print_number(ip, narg, c); 965 print_number(ip, narg, c); 966 putchar(','); 967 print_mask_arg(sysdecode_mount_flags, *ip); 968 ip++; 969 narg--; 970 break; 971 case SYS_unmount: 972 print_number(ip, narg, c); 973 putchar(','); 974 print_mask_arg(sysdecode_mount_flags, *ip); 975 ip++; 976 narg--; 977 break; 978 case SYS_recvmsg: 979 case SYS_sendmsg: 980 print_number(ip, narg, c); 981 print_number(ip, narg, c); 982 putchar(','); 983 print_mask_arg0(sysdecode_msg_flags, *ip); 984 ip++; 985 narg--; 986 break; 987 case SYS_recvfrom: 988 case SYS_sendto: 989 print_number(ip, narg, c); 990 print_number(ip, narg, c); 991 print_number(ip, narg, c); 992 putchar(','); 993 print_mask_arg0(sysdecode_msg_flags, *ip); 994 ip++; 995 narg--; 996 break; 997 case SYS_chflags: 998 case SYS_chflagsat: 999 case SYS_fchflags: 1000 case SYS_lchflags: 1001 print_number(ip, narg, c); 1002 putchar(','); 1003 decode_fileflags(*ip); 1004 ip++; 1005 narg--; 1006 break; 1007 case SYS_kill: 1008 print_number(ip, narg, c); 1009 putchar(','); 1010 print_signal(*ip); 1011 ip++; 1012 narg--; 1013 break; 1014 case SYS_reboot: 1015 putchar('('); 1016 print_mask_arg(sysdecode_reboot_howto, *ip); 1017 ip++; 1018 narg--; 1019 break; 1020 case SYS_umask: 1021 putchar('('); 1022 decode_filemode(*ip); 1023 ip++; 1024 narg--; 1025 break; 1026 case SYS_msync: 1027 print_number(ip, narg, c); 1028 print_number(ip, narg, c); 1029 putchar(','); 1030 print_mask_arg(sysdecode_msync_flags, *ip); 1031 ip++; 1032 narg--; 1033 break; 1034 #ifdef SYS_freebsd6_mmap 1035 case SYS_freebsd6_mmap: 1036 print_number(ip, narg, c); 1037 print_number(ip, narg, c); 1038 putchar(','); 1039 print_mask_arg(sysdecode_mmap_prot, *ip); 1040 putchar(','); 1041 ip++; 1042 narg--; 1043 print_mask_arg(sysdecode_mmap_flags, *ip); 1044 ip++; 1045 narg--; 1046 break; 1047 #endif 1048 case SYS_mmap: 1049 print_number(ip, narg, c); 1050 print_number(ip, narg, c); 1051 putchar(','); 1052 print_mask_arg(sysdecode_mmap_prot, *ip); 1053 putchar(','); 1054 ip++; 1055 narg--; 1056 print_mask_arg(sysdecode_mmap_flags, *ip); 1057 ip++; 1058 narg--; 1059 break; 1060 case SYS_mprotect: 1061 print_number(ip, narg, c); 1062 print_number(ip, narg, c); 1063 putchar(','); 1064 print_mask_arg(sysdecode_mmap_prot, *ip); 1065 ip++; 1066 narg--; 1067 break; 1068 case SYS_madvise: 1069 print_number(ip, narg, c); 1070 print_number(ip, narg, c); 1071 putchar(','); 1072 print_integer_arg(sysdecode_madvice, *ip); 1073 ip++; 1074 narg--; 1075 break; 1076 case SYS_pathconf: 1077 case SYS_lpathconf: 1078 case SYS_fpathconf: 1079 print_number(ip, narg, c); 1080 putchar(','); 1081 print_integer_arg(sysdecode_pathconf_name, *ip); 1082 ip++; 1083 narg--; 1084 break; 1085 case SYS_getpriority: 1086 case SYS_setpriority: 1087 putchar('('); 1088 print_integer_arg(sysdecode_prio_which, *ip); 1089 c = ','; 1090 ip++; 1091 narg--; 1092 break; 1093 case SYS_fcntl: 1094 print_number(ip, narg, c); 1095 putchar(','); 1096 print_integer_arg(sysdecode_fcntl_cmd, ip[0]); 1097 if (sysdecode_fcntl_arg_p(ip[0])) { 1098 putchar(','); 1099 if (ip[0] == F_SETFL) 1100 print_mask_arg( 1101 sysdecode_fcntl_fileflags, 1102 ip[1]); 1103 else 1104 sysdecode_fcntl_arg(stdout, 1105 ip[0], ip[1], 1106 decimal ? 10 : 16); 1107 } 1108 ip += 2; 1109 narg -= 2; 1110 break; 1111 case SYS_socket: { 1112 int sockdomain; 1113 putchar('('); 1114 sockdomain = *ip; 1115 print_integer_arg(sysdecode_socketdomain, 1116 sockdomain); 1117 ip++; 1118 narg--; 1119 putchar(','); 1120 print_mask_arg(sysdecode_socket_type, *ip); 1121 ip++; 1122 narg--; 1123 if (sockdomain == PF_INET || 1124 sockdomain == PF_INET6) { 1125 putchar(','); 1126 print_integer_arg(sysdecode_ipproto, 1127 *ip); 1128 ip++; 1129 narg--; 1130 } 1131 c = ','; 1132 break; 1133 } 1134 case SYS_setsockopt: 1135 case SYS_getsockopt: { 1136 const char *str; 1137 1138 print_number(ip, narg, c); 1139 putchar(','); 1140 print_integer_arg_valid(sysdecode_sockopt_level, 1141 *ip); 1142 str = sysdecode_sockopt_name(ip[0], ip[1]); 1143 if (str != NULL) { 1144 printf(",%s", str); 1145 ip++; 1146 narg--; 1147 } 1148 ip++; 1149 narg--; 1150 break; 1151 } 1152 #ifdef SYS_freebsd6_lseek 1153 case SYS_freebsd6_lseek: 1154 print_number(ip, narg, c); 1155 /* Hidden 'pad' argument, not in lseek(2) */ 1156 print_number(ip, narg, c); 1157 print_number64(first, ip, narg, c); 1158 putchar(','); 1159 print_integer_arg(sysdecode_whence, *ip); 1160 ip++; 1161 narg--; 1162 break; 1163 #endif 1164 case SYS_lseek: 1165 print_number(ip, narg, c); 1166 print_number64(first, ip, narg, c); 1167 putchar(','); 1168 print_integer_arg(sysdecode_whence, *ip); 1169 ip++; 1170 narg--; 1171 break; 1172 case SYS_flock: 1173 print_number(ip, narg, c); 1174 putchar(','); 1175 print_mask_arg(sysdecode_flock_operation, *ip); 1176 ip++; 1177 narg--; 1178 break; 1179 case SYS_mkfifo: 1180 case SYS_mkfifoat: 1181 case SYS_mkdir: 1182 case SYS_mkdirat: 1183 print_number(ip, narg, c); 1184 putchar(','); 1185 decode_filemode(*ip); 1186 ip++; 1187 narg--; 1188 break; 1189 case SYS_shutdown: 1190 print_number(ip, narg, c); 1191 putchar(','); 1192 print_integer_arg(sysdecode_shutdown_how, *ip); 1193 ip++; 1194 narg--; 1195 break; 1196 case SYS_socketpair: 1197 putchar('('); 1198 print_integer_arg(sysdecode_socketdomain, *ip); 1199 ip++; 1200 narg--; 1201 putchar(','); 1202 print_mask_arg(sysdecode_socket_type, *ip); 1203 ip++; 1204 narg--; 1205 c = ','; 1206 break; 1207 case SYS_getrlimit: 1208 case SYS_setrlimit: 1209 putchar('('); 1210 print_integer_arg(sysdecode_rlimit, *ip); 1211 ip++; 1212 narg--; 1213 c = ','; 1214 break; 1215 case SYS_getrusage: 1216 putchar('('); 1217 print_integer_arg(sysdecode_getrusage_who, *ip); 1218 ip++; 1219 narg--; 1220 c = ','; 1221 break; 1222 case SYS_quotactl: 1223 print_number(ip, narg, c); 1224 putchar(','); 1225 if (!sysdecode_quotactl_cmd(stdout, *ip)) { 1226 if (decimal) 1227 printf("<invalid=%d>", (int)*ip); 1228 else 1229 printf("<invalid=%#x>", 1230 (int)*ip); 1231 } 1232 ip++; 1233 narg--; 1234 c = ','; 1235 break; 1236 case SYS_nfssvc: 1237 putchar('('); 1238 print_integer_arg(sysdecode_nfssvc_flags, *ip); 1239 ip++; 1240 narg--; 1241 c = ','; 1242 break; 1243 case SYS_rtprio: 1244 case SYS_rtprio_thread: 1245 putchar('('); 1246 print_integer_arg(sysdecode_rtprio_function, 1247 *ip); 1248 ip++; 1249 narg--; 1250 c = ','; 1251 break; 1252 case SYS___semctl: 1253 print_number(ip, narg, c); 1254 print_number(ip, narg, c); 1255 putchar(','); 1256 print_integer_arg(sysdecode_semctl_cmd, *ip); 1257 ip++; 1258 narg--; 1259 break; 1260 case SYS_semget: 1261 print_number(ip, narg, c); 1262 print_number(ip, narg, c); 1263 putchar(','); 1264 print_mask_arg(sysdecode_semget_flags, *ip); 1265 ip++; 1266 narg--; 1267 break; 1268 case SYS_msgctl: 1269 print_number(ip, narg, c); 1270 putchar(','); 1271 print_integer_arg(sysdecode_msgctl_cmd, *ip); 1272 ip++; 1273 narg--; 1274 break; 1275 case SYS_shmat: 1276 print_number(ip, narg, c); 1277 print_number(ip, narg, c); 1278 putchar(','); 1279 print_mask_arg(sysdecode_shmat_flags, *ip); 1280 ip++; 1281 narg--; 1282 break; 1283 case SYS_shmctl: 1284 print_number(ip, narg, c); 1285 putchar(','); 1286 print_integer_arg(sysdecode_shmctl_cmd, *ip); 1287 ip++; 1288 narg--; 1289 break; 1290 case SYS_shm_open: 1291 print_number(ip, narg, c); 1292 putchar(','); 1293 print_mask_arg(sysdecode_open_flags, ip[0]); 1294 putchar(','); 1295 decode_filemode(ip[1]); 1296 ip += 2; 1297 narg -= 2; 1298 break; 1299 case SYS_minherit: 1300 print_number(ip, narg, c); 1301 print_number(ip, narg, c); 1302 putchar(','); 1303 print_integer_arg(sysdecode_minherit_inherit, 1304 *ip); 1305 ip++; 1306 narg--; 1307 break; 1308 case SYS_rfork: 1309 putchar('('); 1310 print_mask_arg(sysdecode_rfork_flags, *ip); 1311 ip++; 1312 narg--; 1313 c = ','; 1314 break; 1315 case SYS_lio_listio: 1316 putchar('('); 1317 print_integer_arg(sysdecode_lio_listio_mode, 1318 *ip); 1319 ip++; 1320 narg--; 1321 c = ','; 1322 break; 1323 case SYS_mlockall: 1324 putchar('('); 1325 print_mask_arg(sysdecode_mlockall_flags, *ip); 1326 ip++; 1327 narg--; 1328 break; 1329 case SYS_sched_setscheduler: 1330 print_number(ip, narg, c); 1331 putchar(','); 1332 print_integer_arg(sysdecode_scheduler_policy, 1333 *ip); 1334 ip++; 1335 narg--; 1336 break; 1337 case SYS_sched_get_priority_max: 1338 case SYS_sched_get_priority_min: 1339 putchar('('); 1340 print_integer_arg(sysdecode_scheduler_policy, 1341 *ip); 1342 ip++; 1343 narg--; 1344 break; 1345 case SYS_sendfile: 1346 print_number(ip, narg, c); 1347 print_number(ip, narg, c); 1348 print_number(ip, narg, c); 1349 print_number(ip, narg, c); 1350 print_number(ip, narg, c); 1351 print_number(ip, narg, c); 1352 putchar(','); 1353 print_mask_arg(sysdecode_sendfile_flags, *ip); 1354 ip++; 1355 narg--; 1356 break; 1357 case SYS_kldsym: 1358 print_number(ip, narg, c); 1359 putchar(','); 1360 print_integer_arg(sysdecode_kldsym_cmd, *ip); 1361 ip++; 1362 narg--; 1363 break; 1364 case SYS_sigprocmask: 1365 putchar('('); 1366 print_integer_arg(sysdecode_sigprocmask_how, 1367 *ip); 1368 ip++; 1369 narg--; 1370 c = ','; 1371 break; 1372 case SYS___acl_get_file: 1373 case SYS___acl_set_file: 1374 case SYS___acl_get_fd: 1375 case SYS___acl_set_fd: 1376 case SYS___acl_delete_file: 1377 case SYS___acl_delete_fd: 1378 case SYS___acl_aclcheck_file: 1379 case SYS___acl_aclcheck_fd: 1380 case SYS___acl_get_link: 1381 case SYS___acl_set_link: 1382 case SYS___acl_delete_link: 1383 case SYS___acl_aclcheck_link: 1384 print_number(ip, narg, c); 1385 putchar(','); 1386 print_integer_arg(sysdecode_acltype, *ip); 1387 ip++; 1388 narg--; 1389 break; 1390 case SYS_sigaction: 1391 putchar('('); 1392 print_signal(*ip); 1393 ip++; 1394 narg--; 1395 c = ','; 1396 break; 1397 case SYS_extattrctl: 1398 print_number(ip, narg, c); 1399 putchar(','); 1400 print_integer_arg(sysdecode_extattrnamespace, 1401 *ip); 1402 ip++; 1403 narg--; 1404 break; 1405 case SYS_nmount: 1406 print_number(ip, narg, c); 1407 print_number(ip, narg, c); 1408 putchar(','); 1409 print_mask_arg(sysdecode_mount_flags, *ip); 1410 ip++; 1411 narg--; 1412 break; 1413 case SYS_thr_create: 1414 print_number(ip, narg, c); 1415 print_number(ip, narg, c); 1416 putchar(','); 1417 print_mask_arg(sysdecode_thr_create_flags, *ip); 1418 ip++; 1419 narg--; 1420 break; 1421 case SYS_thr_kill: 1422 print_number(ip, narg, c); 1423 putchar(','); 1424 print_signal(*ip); 1425 ip++; 1426 narg--; 1427 break; 1428 case SYS_kldunloadf: 1429 print_number(ip, narg, c); 1430 putchar(','); 1431 print_integer_arg(sysdecode_kldunload_flags, 1432 *ip); 1433 ip++; 1434 narg--; 1435 break; 1436 case SYS_linkat: 1437 case SYS_renameat: 1438 case SYS_symlinkat: 1439 print_number(ip, narg, c); 1440 putchar(','); 1441 print_integer_arg_valid(sysdecode_atfd, *ip); 1442 ip++; 1443 narg--; 1444 print_number(ip, narg, c); 1445 break; 1446 case SYS_cap_fcntls_limit: 1447 print_number(ip, narg, c); 1448 putchar(','); 1449 arg = *ip; 1450 ip++; 1451 narg--; 1452 print_mask_arg32(sysdecode_cap_fcntlrights, arg); 1453 break; 1454 case SYS_posix_fadvise: 1455 print_number(ip, narg, c); 1456 print_number(ip, narg, c); 1457 print_number(ip, narg, c); 1458 (void)putchar(','); 1459 print_integer_arg(sysdecode_fadvice, *ip); 1460 ip++; 1461 narg--; 1462 break; 1463 case SYS_procctl: 1464 putchar('('); 1465 print_integer_arg(sysdecode_idtype, *ip); 1466 c = ','; 1467 ip++; 1468 narg--; 1469 print_number64(first, ip, narg, c); 1470 putchar(','); 1471 print_integer_arg(sysdecode_procctl_cmd, *ip); 1472 ip++; 1473 narg--; 1474 break; 1475 case SYS__umtx_op: 1476 print_number(ip, narg, c); 1477 putchar(','); 1478 print_integer_arg(sysdecode_umtx_op, *ip); 1479 switch (*ip) { 1480 case UMTX_OP_CV_WAIT: 1481 ip++; 1482 narg--; 1483 putchar(','); 1484 print_mask_argul( 1485 sysdecode_umtx_cvwait_flags, *ip); 1486 break; 1487 case UMTX_OP_RW_RDLOCK: 1488 ip++; 1489 narg--; 1490 putchar(','); 1491 print_mask_argul( 1492 sysdecode_umtx_rwlock_flags, *ip); 1493 break; 1494 } 1495 ip++; 1496 narg--; 1497 break; 1498 case SYS_ftruncate: 1499 case SYS_truncate: 1500 print_number(ip, narg, c); 1501 print_number64(first, ip, narg, c); 1502 break; 1503 case SYS_fchownat: 1504 print_number(ip, narg, c); 1505 print_number(ip, narg, c); 1506 print_number(ip, narg, c); 1507 break; 1508 case SYS_fstatat: 1509 case SYS_utimensat: 1510 print_number(ip, narg, c); 1511 print_number(ip, narg, c); 1512 break; 1513 case SYS_unlinkat: 1514 print_number(ip, narg, c); 1515 break; 1516 case SYS_sysarch: 1517 putchar('('); 1518 print_integer_arg(sysdecode_sysarch_number, *ip); 1519 ip++; 1520 narg--; 1521 c = ','; 1522 break; 1523 } 1524 switch (ktr->ktr_code) { 1525 case SYS_chflagsat: 1526 case SYS_fchownat: 1527 case SYS_faccessat: 1528 case SYS_fchmodat: 1529 case SYS_fstatat: 1530 case SYS_linkat: 1531 case SYS_unlinkat: 1532 case SYS_utimensat: 1533 putchar(','); 1534 print_mask_arg0(sysdecode_atflags, *ip); 1535 ip++; 1536 narg--; 1537 break; 1538 } 1539 } 1540 while (narg > 0) { 1541 print_number(ip, narg, c); 1542 } 1543 putchar(')'); 1544 } 1545 putchar('\n'); 1546 } 1547 1548 void 1549 ktrsysret(struct ktr_sysret *ktr, u_int sv_flags) 1550 { 1551 register_t ret = ktr->ktr_retval; 1552 int error = ktr->ktr_error; 1553 1554 syscallname(ktr->ktr_code, sv_flags); 1555 printf(" "); 1556 1557 if (error == 0) { 1558 if (fancy) { 1559 printf("%ld", (long)ret); 1560 if (ret < 0 || ret > 9) 1561 printf("/%#lx", (unsigned long)ret); 1562 } else { 1563 if (decimal) 1564 printf("%ld", (long)ret); 1565 else 1566 printf("%#lx", (unsigned long)ret); 1567 } 1568 } else if (error == ERESTART) 1569 printf("RESTART"); 1570 else if (error == EJUSTRETURN) 1571 printf("JUSTRETURN"); 1572 else { 1573 printf("-1 errno %d", sysdecode_freebsd_to_abi_errno( 1574 syscallabi(sv_flags), error)); 1575 if (fancy) 1576 printf(" %s", strerror(ktr->ktr_error)); 1577 } 1578 putchar('\n'); 1579 } 1580 1581 void 1582 ktrnamei(char *cp, int len) 1583 { 1584 printf("\"%.*s\"\n", len, cp); 1585 } 1586 1587 void 1588 hexdump(char *p, int len, int screenwidth) 1589 { 1590 int n, i; 1591 int width; 1592 1593 width = 0; 1594 do { 1595 width += 2; 1596 i = 13; /* base offset */ 1597 i += (width / 2) + 1; /* spaces every second byte */ 1598 i += (width * 2); /* width of bytes */ 1599 i += 3; /* " |" */ 1600 i += width; /* each byte */ 1601 i += 1; /* "|" */ 1602 } while (i < screenwidth); 1603 width -= 2; 1604 1605 for (n = 0; n < len; n += width) { 1606 for (i = n; i < n + width; i++) { 1607 if ((i % width) == 0) { /* beginning of line */ 1608 printf(" 0x%04x", i); 1609 } 1610 if ((i % 2) == 0) { 1611 printf(" "); 1612 } 1613 if (i < len) 1614 printf("%02x", p[i] & 0xff); 1615 else 1616 printf(" "); 1617 } 1618 printf(" |"); 1619 for (i = n; i < n + width; i++) { 1620 if (i >= len) 1621 break; 1622 if (p[i] >= ' ' && p[i] <= '~') 1623 printf("%c", p[i]); 1624 else 1625 printf("."); 1626 } 1627 printf("|\n"); 1628 } 1629 if ((i % width) != 0) 1630 printf("\n"); 1631 } 1632 1633 void 1634 visdump(char *dp, int datalen, int screenwidth) 1635 { 1636 int col = 0; 1637 char *cp; 1638 int width; 1639 char visbuf[5]; 1640 1641 printf(" \""); 1642 col = 8; 1643 for (;datalen > 0; datalen--, dp++) { 1644 vis(visbuf, *dp, VIS_CSTYLE, *(dp+1)); 1645 cp = visbuf; 1646 /* 1647 * Keep track of printables and 1648 * space chars (like fold(1)). 1649 */ 1650 if (col == 0) { 1651 putchar('\t'); 1652 col = 8; 1653 } 1654 switch(*cp) { 1655 case '\n': 1656 col = 0; 1657 putchar('\n'); 1658 continue; 1659 case '\t': 1660 width = 8 - (col&07); 1661 break; 1662 default: 1663 width = strlen(cp); 1664 } 1665 if (col + width > (screenwidth-2)) { 1666 printf("\\\n\t"); 1667 col = 8; 1668 } 1669 col += width; 1670 do { 1671 putchar(*cp++); 1672 } while (*cp); 1673 } 1674 if (col == 0) 1675 printf(" "); 1676 printf("\"\n"); 1677 } 1678 1679 void 1680 ktrgenio(struct ktr_genio *ktr, int len) 1681 { 1682 int datalen = len - sizeof (struct ktr_genio); 1683 char *dp = (char *)ktr + sizeof (struct ktr_genio); 1684 static int screenwidth = 0; 1685 int i, binary; 1686 1687 printf("fd %d %s %d byte%s\n", ktr->ktr_fd, 1688 ktr->ktr_rw == UIO_READ ? "read" : "wrote", datalen, 1689 datalen == 1 ? "" : "s"); 1690 if (suppressdata) 1691 return; 1692 if (screenwidth == 0) { 1693 struct winsize ws; 1694 1695 if (fancy && ioctl(fileno(stderr), TIOCGWINSZ, &ws) != -1 && 1696 ws.ws_col > 8) 1697 screenwidth = ws.ws_col; 1698 else 1699 screenwidth = 80; 1700 } 1701 if (maxdata && datalen > maxdata) 1702 datalen = maxdata; 1703 1704 for (i = 0, binary = 0; i < datalen && binary == 0; i++) { 1705 if (dp[i] >= 32 && dp[i] < 127) 1706 continue; 1707 if (dp[i] == 10 || dp[i] == 13 || dp[i] == 0 || dp[i] == 9) 1708 continue; 1709 binary = 1; 1710 } 1711 if (binary) 1712 hexdump(dp, datalen, screenwidth); 1713 else 1714 visdump(dp, datalen, screenwidth); 1715 } 1716 1717 void 1718 ktrpsig(struct ktr_psig *psig) 1719 { 1720 const char *str; 1721 1722 print_signal(psig->signo); 1723 if (psig->action == SIG_DFL) { 1724 printf(" SIG_DFL"); 1725 } else { 1726 printf(" caught handler=0x%lx mask=0x%x", 1727 (u_long)psig->action, psig->mask.__bits[0]); 1728 } 1729 printf(" code="); 1730 str = sysdecode_sigcode(psig->signo, psig->code); 1731 if (str != NULL) 1732 printf("%s", str); 1733 else 1734 printf("<invalid=%#x>", psig->code); 1735 putchar('\n'); 1736 } 1737 1738 void 1739 ktrcsw_old(struct ktr_csw_old *cs) 1740 { 1741 printf("%s %s\n", cs->out ? "stop" : "resume", 1742 cs->user ? "user" : "kernel"); 1743 } 1744 1745 void 1746 ktrcsw(struct ktr_csw *cs) 1747 { 1748 printf("%s %s \"%s\"\n", cs->out ? "stop" : "resume", 1749 cs->user ? "user" : "kernel", cs->wmesg); 1750 } 1751 1752 void 1753 ktruser(int len, void *p) 1754 { 1755 unsigned char *cp; 1756 1757 if (sysdecode_utrace(stdout, p, len)) { 1758 printf("\n"); 1759 return; 1760 } 1761 1762 printf("%d ", len); 1763 cp = p; 1764 while (len--) 1765 if (decimal) 1766 printf(" %d", *cp++); 1767 else 1768 printf(" %02x", *cp++); 1769 printf("\n"); 1770 } 1771 1772 void 1773 ktrcaprights(cap_rights_t *rightsp) 1774 { 1775 1776 printf("cap_rights_t "); 1777 sysdecode_cap_rights(stdout, rightsp); 1778 printf("\n"); 1779 } 1780 1781 static void 1782 ktrtimeval(struct timeval *tv) 1783 { 1784 1785 printf("{%ld, %ld}", (long)tv->tv_sec, tv->tv_usec); 1786 } 1787 1788 void 1789 ktritimerval(struct itimerval *it) 1790 { 1791 1792 printf("itimerval { .interval = "); 1793 ktrtimeval(&it->it_interval); 1794 printf(", .value = "); 1795 ktrtimeval(&it->it_value); 1796 printf(" }\n"); 1797 } 1798 1799 void 1800 ktrsockaddr(struct sockaddr *sa) 1801 { 1802 /* 1803 TODO: Support additional address families 1804 #include <netsmb/netbios.h> 1805 struct sockaddr_nb *nb; 1806 */ 1807 const char *str; 1808 char addr[64]; 1809 1810 /* 1811 * note: ktrstruct() has already verified that sa points to a 1812 * buffer at least sizeof(struct sockaddr) bytes long and exactly 1813 * sa->sa_len bytes long. 1814 */ 1815 printf("struct sockaddr { "); 1816 str = sysdecode_sockaddr_family(sa->sa_family); 1817 if (str != NULL) 1818 printf("%s", str); 1819 else 1820 printf("<invalid=%d>", sa->sa_family); 1821 printf(", "); 1822 1823 #define check_sockaddr_len(n) \ 1824 if (sa_##n.s##n##_len < sizeof(struct sockaddr_##n)) { \ 1825 printf("invalid"); \ 1826 break; \ 1827 } 1828 1829 switch(sa->sa_family) { 1830 case AF_INET: { 1831 struct sockaddr_in sa_in; 1832 1833 memset(&sa_in, 0, sizeof(sa_in)); 1834 memcpy(&sa_in, sa, sa->sa_len); 1835 check_sockaddr_len(in); 1836 inet_ntop(AF_INET, &sa_in.sin_addr, addr, sizeof addr); 1837 printf("%s:%u", addr, ntohs(sa_in.sin_port)); 1838 break; 1839 } 1840 case AF_INET6: { 1841 struct sockaddr_in6 sa_in6; 1842 1843 memset(&sa_in6, 0, sizeof(sa_in6)); 1844 memcpy(&sa_in6, sa, sa->sa_len); 1845 check_sockaddr_len(in6); 1846 getnameinfo((struct sockaddr *)&sa_in6, sizeof(sa_in6), 1847 addr, sizeof(addr), NULL, 0, NI_NUMERICHOST); 1848 printf("[%s]:%u", addr, htons(sa_in6.sin6_port)); 1849 break; 1850 } 1851 case AF_UNIX: { 1852 struct sockaddr_un sa_un; 1853 1854 memset(&sa_un, 0, sizeof(sa_un)); 1855 memcpy(&sa_un, sa, sa->sa_len); 1856 printf("%.*s", (int)sizeof(sa_un.sun_path), sa_un.sun_path); 1857 break; 1858 } 1859 default: 1860 printf("unknown address family"); 1861 } 1862 printf(" }\n"); 1863 } 1864 1865 void 1866 ktrstat(struct stat *statp) 1867 { 1868 char mode[12], timestr[PATH_MAX + 4]; 1869 struct passwd *pwd; 1870 struct group *grp; 1871 struct tm *tm; 1872 1873 /* 1874 * note: ktrstruct() has already verified that statp points to a 1875 * buffer exactly sizeof(struct stat) bytes long. 1876 */ 1877 printf("struct stat {"); 1878 printf("dev=%ju, ino=%ju, ", 1879 (uintmax_t)statp->st_dev, (uintmax_t)statp->st_ino); 1880 if (resolv == 0) 1881 printf("mode=0%jo, ", (uintmax_t)statp->st_mode); 1882 else { 1883 strmode(statp->st_mode, mode); 1884 printf("mode=%s, ", mode); 1885 } 1886 printf("nlink=%ju, ", (uintmax_t)statp->st_nlink); 1887 if (resolv == 0) { 1888 pwd = NULL; 1889 } else { 1890 #ifdef WITH_CASPER 1891 if (cappwd != NULL) 1892 pwd = cap_getpwuid(cappwd, statp->st_uid); 1893 else 1894 #endif 1895 pwd = getpwuid(statp->st_uid); 1896 } 1897 if (pwd == NULL) 1898 printf("uid=%ju, ", (uintmax_t)statp->st_uid); 1899 else 1900 printf("uid=\"%s\", ", pwd->pw_name); 1901 if (resolv == 0) { 1902 grp = NULL; 1903 } else { 1904 #ifdef WITH_CASPER 1905 if (capgrp != NULL) 1906 grp = cap_getgrgid(capgrp, statp->st_gid); 1907 else 1908 #endif 1909 grp = getgrgid(statp->st_gid); 1910 } 1911 if (grp == NULL) 1912 printf("gid=%ju, ", (uintmax_t)statp->st_gid); 1913 else 1914 printf("gid=\"%s\", ", grp->gr_name); 1915 printf("rdev=%ju, ", (uintmax_t)statp->st_rdev); 1916 printf("atime="); 1917 if (resolv == 0) 1918 printf("%jd", (intmax_t)statp->st_atim.tv_sec); 1919 else { 1920 tm = localtime(&statp->st_atim.tv_sec); 1921 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1922 printf("\"%s\"", timestr); 1923 } 1924 if (statp->st_atim.tv_nsec != 0) 1925 printf(".%09ld, ", statp->st_atim.tv_nsec); 1926 else 1927 printf(", "); 1928 printf("mtime="); 1929 if (resolv == 0) 1930 printf("%jd", (intmax_t)statp->st_mtim.tv_sec); 1931 else { 1932 tm = localtime(&statp->st_mtim.tv_sec); 1933 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1934 printf("\"%s\"", timestr); 1935 } 1936 if (statp->st_mtim.tv_nsec != 0) 1937 printf(".%09ld, ", statp->st_mtim.tv_nsec); 1938 else 1939 printf(", "); 1940 printf("ctime="); 1941 if (resolv == 0) 1942 printf("%jd", (intmax_t)statp->st_ctim.tv_sec); 1943 else { 1944 tm = localtime(&statp->st_ctim.tv_sec); 1945 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1946 printf("\"%s\"", timestr); 1947 } 1948 if (statp->st_ctim.tv_nsec != 0) 1949 printf(".%09ld, ", statp->st_ctim.tv_nsec); 1950 else 1951 printf(", "); 1952 printf("birthtime="); 1953 if (resolv == 0) 1954 printf("%jd", (intmax_t)statp->st_birthtim.tv_sec); 1955 else { 1956 tm = localtime(&statp->st_birthtim.tv_sec); 1957 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1958 printf("\"%s\"", timestr); 1959 } 1960 if (statp->st_birthtim.tv_nsec != 0) 1961 printf(".%09ld, ", statp->st_birthtim.tv_nsec); 1962 else 1963 printf(", "); 1964 printf("size=%jd, blksize=%ju, blocks=%jd, flags=0x%x", 1965 (uintmax_t)statp->st_size, (uintmax_t)statp->st_blksize, 1966 (intmax_t)statp->st_blocks, statp->st_flags); 1967 printf(" }\n"); 1968 } 1969 1970 void 1971 ktrstruct(char *buf, size_t buflen) 1972 { 1973 char *name, *data; 1974 size_t namelen, datalen; 1975 int i; 1976 cap_rights_t rights; 1977 struct itimerval it; 1978 struct stat sb; 1979 struct sockaddr_storage ss; 1980 1981 for (name = buf, namelen = 0; 1982 namelen < buflen && name[namelen] != '\0'; 1983 ++namelen) 1984 /* nothing */; 1985 if (namelen == buflen) 1986 goto invalid; 1987 if (name[namelen] != '\0') 1988 goto invalid; 1989 data = buf + namelen + 1; 1990 datalen = buflen - namelen - 1; 1991 if (datalen == 0) 1992 goto invalid; 1993 /* sanity check */ 1994 for (i = 0; i < (int)namelen; ++i) 1995 if (!isalpha(name[i])) 1996 goto invalid; 1997 if (strcmp(name, "caprights") == 0) { 1998 if (datalen != sizeof(cap_rights_t)) 1999 goto invalid; 2000 memcpy(&rights, data, datalen); 2001 ktrcaprights(&rights); 2002 } else if (strcmp(name, "itimerval") == 0) { 2003 if (datalen != sizeof(struct itimerval)) 2004 goto invalid; 2005 memcpy(&it, data, datalen); 2006 ktritimerval(&it); 2007 } else if (strcmp(name, "stat") == 0) { 2008 if (datalen != sizeof(struct stat)) 2009 goto invalid; 2010 memcpy(&sb, data, datalen); 2011 ktrstat(&sb); 2012 } else if (strcmp(name, "sockaddr") == 0) { 2013 if (datalen > sizeof(ss)) 2014 goto invalid; 2015 memcpy(&ss, data, datalen); 2016 if (datalen != ss.ss_len) 2017 goto invalid; 2018 ktrsockaddr((struct sockaddr *)&ss); 2019 } else { 2020 printf("unknown structure\n"); 2021 } 2022 return; 2023 invalid: 2024 printf("invalid record\n"); 2025 } 2026 2027 void 2028 ktrcapfail(struct ktr_cap_fail *ktr) 2029 { 2030 switch (ktr->cap_type) { 2031 case CAPFAIL_NOTCAPABLE: 2032 /* operation on fd with insufficient capabilities */ 2033 printf("operation requires "); 2034 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2035 printf(", descriptor holds "); 2036 sysdecode_cap_rights(stdout, &ktr->cap_held); 2037 break; 2038 case CAPFAIL_INCREASE: 2039 /* requested more capabilities than fd already has */ 2040 printf("attempt to increase capabilities from "); 2041 sysdecode_cap_rights(stdout, &ktr->cap_held); 2042 printf(" to "); 2043 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2044 break; 2045 case CAPFAIL_SYSCALL: 2046 /* called restricted syscall */ 2047 printf("disallowed system call"); 2048 break; 2049 case CAPFAIL_LOOKUP: 2050 /* used ".." in strict-relative mode */ 2051 printf("restricted VFS lookup"); 2052 break; 2053 default: 2054 printf("unknown capability failure: "); 2055 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2056 printf(" "); 2057 sysdecode_cap_rights(stdout, &ktr->cap_held); 2058 break; 2059 } 2060 printf("\n"); 2061 } 2062 2063 void 2064 ktrfault(struct ktr_fault *ktr) 2065 { 2066 2067 printf("0x%jx ", (uintmax_t)ktr->vaddr); 2068 print_mask_arg(sysdecode_vmprot, ktr->type); 2069 printf("\n"); 2070 } 2071 2072 void 2073 ktrfaultend(struct ktr_faultend *ktr) 2074 { 2075 const char *str; 2076 2077 str = sysdecode_vmresult(ktr->result); 2078 if (str != NULL) 2079 printf("%s", str); 2080 else 2081 printf("<invalid=%d>", ktr->result); 2082 printf("\n"); 2083 } 2084 2085 void 2086 ktrkevent(struct kevent *kev) 2087 { 2088 2089 printf("{ ident="); 2090 switch (kev->filter) { 2091 case EVFILT_READ: 2092 case EVFILT_WRITE: 2093 case EVFILT_VNODE: 2094 case EVFILT_PROC: 2095 case EVFILT_TIMER: 2096 case EVFILT_PROCDESC: 2097 case EVFILT_EMPTY: 2098 printf("%ju", (uintmax_t)kev->ident); 2099 break; 2100 case EVFILT_SIGNAL: 2101 print_signal(kev->ident); 2102 break; 2103 default: 2104 printf("%p", (void *)kev->ident); 2105 } 2106 printf(", filter="); 2107 print_integer_arg(sysdecode_kevent_filter, kev->filter); 2108 printf(", flags="); 2109 print_mask_arg0(sysdecode_kevent_flags, kev->flags); 2110 printf(", fflags="); 2111 sysdecode_kevent_fflags(stdout, kev->filter, kev->fflags, 2112 decimal ? 10 : 16); 2113 printf(", data=%#jx, udata=%p }", (uintmax_t)kev->data, kev->udata); 2114 } 2115 2116 void 2117 ktrstructarray(struct ktr_struct_array *ksa, size_t buflen) 2118 { 2119 struct kevent kev; 2120 char *name, *data; 2121 size_t namelen, datalen; 2122 int i; 2123 bool first; 2124 2125 buflen -= sizeof(*ksa); 2126 for (name = (char *)(ksa + 1), namelen = 0; 2127 namelen < buflen && name[namelen] != '\0'; 2128 ++namelen) 2129 /* nothing */; 2130 if (namelen == buflen) 2131 goto invalid; 2132 if (name[namelen] != '\0') 2133 goto invalid; 2134 /* sanity check */ 2135 for (i = 0; i < (int)namelen; ++i) 2136 if (!isalnum(name[i]) && name[i] != '_') 2137 goto invalid; 2138 data = name + namelen + 1; 2139 datalen = buflen - namelen - 1; 2140 printf("struct %s[] = { ", name); 2141 first = true; 2142 for (; datalen >= ksa->struct_size; 2143 data += ksa->struct_size, datalen -= ksa->struct_size) { 2144 if (!first) 2145 printf("\n "); 2146 else 2147 first = false; 2148 if (strcmp(name, "kevent") == 0) { 2149 if (ksa->struct_size != sizeof(kev)) 2150 goto bad_size; 2151 memcpy(&kev, data, sizeof(kev)); 2152 ktrkevent(&kev); 2153 } else if (strcmp(name, "kevent_freebsd11") == 0) { 2154 struct kevent_freebsd11 kev11; 2155 2156 if (ksa->struct_size != sizeof(kev11)) 2157 goto bad_size; 2158 memcpy(&kev11, data, sizeof(kev11)); 2159 memset(&kev, 0, sizeof(kev)); 2160 kev.ident = kev11.ident; 2161 kev.filter = kev11.filter; 2162 kev.flags = kev11.flags; 2163 kev.fflags = kev11.fflags; 2164 kev.data = kev11.data; 2165 kev.udata = kev11.udata; 2166 ktrkevent(&kev); 2167 #ifdef _WANT_KEVENT32 2168 } else if (strcmp(name, "kevent32") == 0) { 2169 struct kevent32 kev32; 2170 2171 if (ksa->struct_size != sizeof(kev32)) 2172 goto bad_size; 2173 memcpy(&kev32, data, sizeof(kev32)); 2174 memset(&kev, 0, sizeof(kev)); 2175 kev.ident = kev32.ident; 2176 kev.filter = kev32.filter; 2177 kev.flags = kev32.flags; 2178 kev.fflags = kev32.fflags; 2179 #if BYTE_ORDER == BIG_ENDIAN 2180 kev.data = kev32.data2 | ((int64_t)kev32.data1 << 32); 2181 #else 2182 kev.data = kev32.data1 | ((int64_t)kev32.data2 << 32); 2183 #endif 2184 kev.udata = (void *)(uintptr_t)kev32.udata; 2185 ktrkevent(&kev); 2186 } else if (strcmp(name, "kevent32_freebsd11") == 0) { 2187 struct kevent32_freebsd11 kev32; 2188 2189 if (ksa->struct_size != sizeof(kev32)) 2190 goto bad_size; 2191 memcpy(&kev32, data, sizeof(kev32)); 2192 memset(&kev, 0, sizeof(kev)); 2193 kev.ident = kev32.ident; 2194 kev.filter = kev32.filter; 2195 kev.flags = kev32.flags; 2196 kev.fflags = kev32.fflags; 2197 kev.data = kev32.data; 2198 kev.udata = (void *)(uintptr_t)kev32.udata; 2199 ktrkevent(&kev); 2200 #endif 2201 } else { 2202 printf("<unknown structure> }\n"); 2203 return; 2204 } 2205 } 2206 printf(" }\n"); 2207 return; 2208 invalid: 2209 printf("invalid record\n"); 2210 return; 2211 bad_size: 2212 printf("<bad size> }\n"); 2213 return; 2214 } 2215 2216 void 2217 usage(void) 2218 { 2219 fprintf(stderr, "usage: kdump [-dEnlHRrSsTA] [-f trfile] " 2220 "[-m maxdata] [-p pid] [-t trstr]\n"); 2221 exit(1); 2222 } 2223