1 /*- 2 * SPDX-License-Identifier: BSD-3-Clause 3 * 4 * Copyright (c) 1988, 1993 5 * The Regents of the University of California. All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the University nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32 #ifndef lint 33 static const char copyright[] = 34 "@(#) Copyright (c) 1988, 1993\n\ 35 The Regents of the University of California. All rights reserved.\n"; 36 #endif /* not lint */ 37 38 #ifndef lint 39 #if 0 40 static char sccsid[] = "@(#)kdump.c 8.1 (Berkeley) 6/6/93"; 41 #endif 42 #endif /* not lint */ 43 #include <sys/cdefs.h> 44 __FBSDID("$FreeBSD$"); 45 46 #define _WANT_KERNEL_ERRNO 47 #ifdef __LP64__ 48 #define _WANT_KEVENT32 49 #endif 50 #define _WANT_FREEBSD11_KEVENT 51 #include <sys/param.h> 52 #include <sys/capsicum.h> 53 #include <sys/errno.h> 54 #include <sys/time.h> 55 #include <sys/uio.h> 56 #include <sys/event.h> 57 #include <sys/ktrace.h> 58 #include <sys/ioctl.h> 59 #include <sys/socket.h> 60 #include <sys/stat.h> 61 #include <sys/sysent.h> 62 #include <sys/umtx.h> 63 #include <sys/un.h> 64 #include <sys/queue.h> 65 #include <sys/wait.h> 66 #ifdef WITH_CASPER 67 #include <sys/nv.h> 68 #endif 69 #include <arpa/inet.h> 70 #include <netinet/in.h> 71 #include <ctype.h> 72 #include <capsicum_helpers.h> 73 #include <err.h> 74 #include <grp.h> 75 #include <inttypes.h> 76 #include <locale.h> 77 #include <netdb.h> 78 #include <nl_types.h> 79 #include <pwd.h> 80 #include <stddef.h> 81 #include <stdio.h> 82 #include <stdlib.h> 83 #include <string.h> 84 #include <sysdecode.h> 85 #include <time.h> 86 #include <unistd.h> 87 #include <vis.h> 88 #include "ktrace.h" 89 90 #ifdef WITH_CASPER 91 #include <libcasper.h> 92 93 #include <casper/cap_grp.h> 94 #include <casper/cap_pwd.h> 95 #endif 96 97 u_int abidump(struct ktr_header *); 98 int fetchprocinfo(struct ktr_header *, u_int *); 99 int fread_tail(void *, int, int); 100 void dumpheader(struct ktr_header *); 101 void ktrsyscall(struct ktr_syscall *, u_int); 102 void ktrsysret(struct ktr_sysret *, u_int); 103 void ktrnamei(char *, int); 104 void hexdump(char *, int, int); 105 void visdump(char *, int, int); 106 void ktrgenio(struct ktr_genio *, int); 107 void ktrpsig(struct ktr_psig *); 108 void ktrcsw(struct ktr_csw *); 109 void ktrcsw_old(struct ktr_csw_old *); 110 void ktruser(int, void *); 111 void ktrcaprights(cap_rights_t *); 112 void ktritimerval(struct itimerval *it); 113 void ktrsockaddr(struct sockaddr *); 114 void ktrstat(struct stat *); 115 void ktrstruct(char *, size_t); 116 void ktrcapfail(struct ktr_cap_fail *); 117 void ktrfault(struct ktr_fault *); 118 void ktrfaultend(struct ktr_faultend *); 119 void ktrkevent(struct kevent *); 120 void ktrstructarray(struct ktr_struct_array *, size_t); 121 void usage(void); 122 123 #define TIMESTAMP_NONE 0x0 124 #define TIMESTAMP_ABSOLUTE 0x1 125 #define TIMESTAMP_ELAPSED 0x2 126 #define TIMESTAMP_RELATIVE 0x4 127 128 static int timestamp, decimal, fancy = 1, suppressdata, tail, threads, maxdata, 129 resolv = 0, abiflag = 0, syscallno = 0; 130 static const char *tracefile = DEF_TRACEFILE; 131 static struct ktr_header ktr_header; 132 133 #define TIME_FORMAT "%b %e %T %Y" 134 #define eqs(s1, s2) (strcmp((s1), (s2)) == 0) 135 136 #define print_number64(first,i,n,c) do { \ 137 uint64_t __v; \ 138 \ 139 if (quad_align && (((ptrdiff_t)((i) - (first))) & 1) == 1) { \ 140 (i)++; \ 141 (n)--; \ 142 } \ 143 if (quad_slots == 2) \ 144 __v = (uint64_t)(uint32_t)(i)[0] | \ 145 ((uint64_t)(uint32_t)(i)[1]) << 32; \ 146 else \ 147 __v = (uint64_t)*(i); \ 148 if (decimal) \ 149 printf("%c%jd", (c), (intmax_t)__v); \ 150 else \ 151 printf("%c%#jx", (c), (uintmax_t)__v); \ 152 (i) += quad_slots; \ 153 (n) -= quad_slots; \ 154 (c) = ','; \ 155 } while (0) 156 157 #define print_number(i,n,c) do { \ 158 if (decimal) \ 159 printf("%c%jd", c, (intmax_t)*i); \ 160 else \ 161 printf("%c%#jx", c, (uintmax_t)(u_register_t)*i); \ 162 i++; \ 163 n--; \ 164 c = ','; \ 165 } while (0) 166 167 struct proc_info 168 { 169 TAILQ_ENTRY(proc_info) info; 170 u_int sv_flags; 171 pid_t pid; 172 }; 173 174 static TAILQ_HEAD(trace_procs, proc_info) trace_procs; 175 176 #ifdef WITH_CASPER 177 static cap_channel_t *cappwd, *capgrp; 178 179 static int 180 cappwdgrp_setup(cap_channel_t **cappwdp, cap_channel_t **capgrpp) 181 { 182 cap_channel_t *capcas, *cappwdloc, *capgrploc; 183 const char *cmds[1], *fields[1]; 184 185 capcas = cap_init(); 186 if (capcas == NULL) { 187 err(1, "unable to create casper process"); 188 exit(1); 189 } 190 cappwdloc = cap_service_open(capcas, "system.pwd"); 191 capgrploc = cap_service_open(capcas, "system.grp"); 192 /* Casper capability no longer needed. */ 193 cap_close(capcas); 194 if (cappwdloc == NULL || capgrploc == NULL) { 195 if (cappwdloc == NULL) 196 warn("unable to open system.pwd service"); 197 if (capgrploc == NULL) 198 warn("unable to open system.grp service"); 199 exit(1); 200 } 201 /* Limit system.pwd to only getpwuid() function and pw_name field. */ 202 cmds[0] = "getpwuid"; 203 if (cap_pwd_limit_cmds(cappwdloc, cmds, 1) < 0) 204 err(1, "unable to limit system.pwd service"); 205 fields[0] = "pw_name"; 206 if (cap_pwd_limit_fields(cappwdloc, fields, 1) < 0) 207 err(1, "unable to limit system.pwd service"); 208 /* Limit system.grp to only getgrgid() function and gr_name field. */ 209 cmds[0] = "getgrgid"; 210 if (cap_grp_limit_cmds(capgrploc, cmds, 1) < 0) 211 err(1, "unable to limit system.grp service"); 212 fields[0] = "gr_name"; 213 if (cap_grp_limit_fields(capgrploc, fields, 1) < 0) 214 err(1, "unable to limit system.grp service"); 215 216 *cappwdp = cappwdloc; 217 *capgrpp = capgrploc; 218 return (0); 219 } 220 #endif /* WITH_CASPER */ 221 222 static void 223 print_integer_arg(const char *(*decoder)(int), int value) 224 { 225 const char *str; 226 227 str = decoder(value); 228 if (str != NULL) 229 printf("%s", str); 230 else { 231 if (decimal) 232 printf("<invalid=%d>", value); 233 else 234 printf("<invalid=%#x>", value); 235 } 236 } 237 238 /* Like print_integer_arg but unknown values are treated as valid. */ 239 static void 240 print_integer_arg_valid(const char *(*decoder)(int), int value) 241 { 242 const char *str; 243 244 str = decoder(value); 245 if (str != NULL) 246 printf("%s", str); 247 else { 248 if (decimal) 249 printf("%d", value); 250 else 251 printf("%#x", value); 252 } 253 } 254 255 static void 256 print_mask_arg(bool (*decoder)(FILE *, int, int *), int value) 257 { 258 bool invalid; 259 int rem; 260 261 printf("%#x<", value); 262 invalid = !decoder(stdout, value, &rem); 263 printf(">"); 264 if (invalid) 265 printf("<invalid>%u", rem); 266 } 267 268 static void 269 print_mask_arg0(bool (*decoder)(FILE *, int, int *), int value) 270 { 271 bool invalid; 272 int rem; 273 274 if (value == 0) { 275 printf("0"); 276 return; 277 } 278 printf("%#x<", value); 279 invalid = !decoder(stdout, value, &rem); 280 printf(">"); 281 if (invalid) 282 printf("<invalid>%u", rem); 283 } 284 285 static void 286 decode_fileflags(fflags_t value) 287 { 288 bool invalid; 289 fflags_t rem; 290 291 if (value == 0) { 292 printf("0"); 293 return; 294 } 295 printf("%#x<", value); 296 invalid = !sysdecode_fileflags(stdout, value, &rem); 297 printf(">"); 298 if (invalid) 299 printf("<invalid>%u", rem); 300 } 301 302 static void 303 decode_filemode(int value) 304 { 305 bool invalid; 306 int rem; 307 308 if (value == 0) { 309 printf("0"); 310 return; 311 } 312 printf("%#o<", value); 313 invalid = !sysdecode_filemode(stdout, value, &rem); 314 printf(">"); 315 if (invalid) 316 printf("<invalid>%u", rem); 317 } 318 319 static void 320 print_mask_arg32(bool (*decoder)(FILE *, uint32_t, uint32_t *), uint32_t value) 321 { 322 bool invalid; 323 uint32_t rem; 324 325 printf("%#x<", value); 326 invalid = !decoder(stdout, value, &rem); 327 printf(">"); 328 if (invalid) 329 printf("<invalid>%u", rem); 330 } 331 332 static void 333 print_mask_argul(bool (*decoder)(FILE *, u_long, u_long *), u_long value) 334 { 335 bool invalid; 336 u_long rem; 337 338 if (value == 0) { 339 printf("0"); 340 return; 341 } 342 printf("%#lx<", value); 343 invalid = !decoder(stdout, value, &rem); 344 printf(">"); 345 if (invalid) 346 printf("<invalid>%lu", rem); 347 } 348 349 int 350 main(int argc, char *argv[]) 351 { 352 int ch, ktrlen, size; 353 void *m; 354 int trpoints = ALL_POINTS; 355 int drop_logged; 356 pid_t pid = 0; 357 u_int sv_flags; 358 359 setlocale(LC_CTYPE, ""); 360 361 timestamp = TIMESTAMP_NONE; 362 363 while ((ch = getopt(argc,argv,"f:dElm:np:AHRrSsTt:")) != -1) 364 switch (ch) { 365 case 'A': 366 abiflag = 1; 367 break; 368 case 'f': 369 tracefile = optarg; 370 break; 371 case 'd': 372 decimal = 1; 373 break; 374 case 'l': 375 tail = 1; 376 break; 377 case 'm': 378 maxdata = atoi(optarg); 379 break; 380 case 'n': 381 fancy = 0; 382 break; 383 case 'p': 384 pid = atoi(optarg); 385 break; 386 case 'r': 387 resolv = 1; 388 break; 389 case 'S': 390 syscallno = 1; 391 break; 392 case 's': 393 suppressdata = 1; 394 break; 395 case 'E': 396 timestamp |= TIMESTAMP_ELAPSED; 397 break; 398 case 'H': 399 threads = 1; 400 break; 401 case 'R': 402 timestamp |= TIMESTAMP_RELATIVE; 403 break; 404 case 'T': 405 timestamp |= TIMESTAMP_ABSOLUTE; 406 break; 407 case 't': 408 trpoints = getpoints(optarg); 409 if (trpoints < 0) 410 errx(1, "unknown trace point in %s", optarg); 411 break; 412 default: 413 usage(); 414 } 415 416 if (argc > optind) 417 usage(); 418 419 m = malloc(size = 1025); 420 if (m == NULL) 421 errx(1, "%s", strerror(ENOMEM)); 422 if (strcmp(tracefile, "-") != 0) 423 if (!freopen(tracefile, "r", stdin)) 424 err(1, "%s", tracefile); 425 426 caph_cache_catpages(); 427 caph_cache_tzdata(); 428 429 #ifdef WITH_CASPER 430 if (resolv != 0) { 431 if (cappwdgrp_setup(&cappwd, &capgrp) < 0) { 432 cappwd = NULL; 433 capgrp = NULL; 434 } 435 } 436 if (resolv == 0 || (cappwd != NULL && capgrp != NULL)) { 437 if (cap_enter() < 0 && errno != ENOSYS) 438 err(1, "unable to enter capability mode"); 439 } 440 #else 441 if (resolv == 0) { 442 if (cap_enter() < 0 && errno != ENOSYS) 443 err(1, "unable to enter capability mode"); 444 } 445 #endif 446 if (caph_limit_stdio() == -1) 447 err(1, "unable to limit stdio"); 448 449 TAILQ_INIT(&trace_procs); 450 drop_logged = 0; 451 while (fread_tail(&ktr_header, sizeof(struct ktr_header), 1)) { 452 if (ktr_header.ktr_type & KTR_DROP) { 453 ktr_header.ktr_type &= ~KTR_DROP; 454 if (!drop_logged && threads) { 455 printf( 456 "%6jd %6jd %-8.*s Events dropped.\n", 457 (intmax_t)ktr_header.ktr_pid, 458 ktr_header.ktr_tid > 0 ? 459 (intmax_t)ktr_header.ktr_tid : 0, 460 MAXCOMLEN, ktr_header.ktr_comm); 461 drop_logged = 1; 462 } else if (!drop_logged) { 463 printf("%6jd %-8.*s Events dropped.\n", 464 (intmax_t)ktr_header.ktr_pid, MAXCOMLEN, 465 ktr_header.ktr_comm); 466 drop_logged = 1; 467 } 468 } 469 if (trpoints & (1<<ktr_header.ktr_type)) 470 if (pid == 0 || ktr_header.ktr_pid == pid || 471 ktr_header.ktr_tid == pid) 472 dumpheader(&ktr_header); 473 if ((ktrlen = ktr_header.ktr_len) < 0) 474 errx(1, "bogus length 0x%x", ktrlen); 475 if (ktrlen > size) { 476 m = realloc(m, ktrlen+1); 477 if (m == NULL) 478 errx(1, "%s", strerror(ENOMEM)); 479 size = ktrlen; 480 } 481 if (ktrlen && fread_tail(m, ktrlen, 1) == 0) 482 errx(1, "data too short"); 483 if (fetchprocinfo(&ktr_header, (u_int *)m) != 0) 484 continue; 485 sv_flags = abidump(&ktr_header); 486 if (pid && ktr_header.ktr_pid != pid && 487 ktr_header.ktr_tid != pid) 488 continue; 489 if ((trpoints & (1<<ktr_header.ktr_type)) == 0) 490 continue; 491 drop_logged = 0; 492 switch (ktr_header.ktr_type) { 493 case KTR_SYSCALL: 494 ktrsyscall((struct ktr_syscall *)m, sv_flags); 495 break; 496 case KTR_SYSRET: 497 ktrsysret((struct ktr_sysret *)m, sv_flags); 498 break; 499 case KTR_NAMEI: 500 case KTR_SYSCTL: 501 ktrnamei(m, ktrlen); 502 break; 503 case KTR_GENIO: 504 ktrgenio((struct ktr_genio *)m, ktrlen); 505 break; 506 case KTR_PSIG: 507 ktrpsig((struct ktr_psig *)m); 508 break; 509 case KTR_CSW: 510 if (ktrlen == sizeof(struct ktr_csw_old)) 511 ktrcsw_old((struct ktr_csw_old *)m); 512 else 513 ktrcsw((struct ktr_csw *)m); 514 break; 515 case KTR_USER: 516 ktruser(ktrlen, m); 517 break; 518 case KTR_STRUCT: 519 ktrstruct(m, ktrlen); 520 break; 521 case KTR_CAPFAIL: 522 ktrcapfail((struct ktr_cap_fail *)m); 523 break; 524 case KTR_FAULT: 525 ktrfault((struct ktr_fault *)m); 526 break; 527 case KTR_FAULTEND: 528 ktrfaultend((struct ktr_faultend *)m); 529 break; 530 case KTR_STRUCT_ARRAY: 531 ktrstructarray((struct ktr_struct_array *)m, ktrlen); 532 break; 533 default: 534 printf("\n"); 535 break; 536 } 537 if (tail) 538 fflush(stdout); 539 } 540 return 0; 541 } 542 543 int 544 fread_tail(void *buf, int size, int num) 545 { 546 int i; 547 548 while ((i = fread(buf, size, num, stdin)) == 0 && tail) { 549 sleep(1); 550 clearerr(stdin); 551 } 552 return (i); 553 } 554 555 int 556 fetchprocinfo(struct ktr_header *kth, u_int *flags) 557 { 558 struct proc_info *pi; 559 560 switch (kth->ktr_type) { 561 case KTR_PROCCTOR: 562 TAILQ_FOREACH(pi, &trace_procs, info) { 563 if (pi->pid == kth->ktr_pid) { 564 TAILQ_REMOVE(&trace_procs, pi, info); 565 break; 566 } 567 } 568 pi = malloc(sizeof(struct proc_info)); 569 if (pi == NULL) 570 errx(1, "%s", strerror(ENOMEM)); 571 pi->sv_flags = *flags; 572 pi->pid = kth->ktr_pid; 573 TAILQ_INSERT_TAIL(&trace_procs, pi, info); 574 return (1); 575 576 case KTR_PROCDTOR: 577 TAILQ_FOREACH(pi, &trace_procs, info) { 578 if (pi->pid == kth->ktr_pid) { 579 TAILQ_REMOVE(&trace_procs, pi, info); 580 free(pi); 581 break; 582 } 583 } 584 return (1); 585 } 586 587 return (0); 588 } 589 590 u_int 591 abidump(struct ktr_header *kth) 592 { 593 struct proc_info *pi; 594 const char *abi; 595 const char *arch; 596 u_int flags = 0; 597 598 TAILQ_FOREACH(pi, &trace_procs, info) { 599 if (pi->pid == kth->ktr_pid) { 600 flags = pi->sv_flags; 601 break; 602 } 603 } 604 605 if (abiflag == 0) 606 return (flags); 607 608 switch (flags & SV_ABI_MASK) { 609 case SV_ABI_LINUX: 610 abi = "L"; 611 break; 612 case SV_ABI_FREEBSD: 613 abi = "F"; 614 break; 615 case SV_ABI_CLOUDABI: 616 abi = "C"; 617 break; 618 default: 619 abi = "U"; 620 break; 621 } 622 623 if (flags & SV_LP64) 624 arch = "64"; 625 else if (flags & SV_ILP32) 626 arch = "32"; 627 else 628 arch = "00"; 629 630 printf("%s%s ", abi, arch); 631 632 return (flags); 633 } 634 635 void 636 dumpheader(struct ktr_header *kth) 637 { 638 static char unknown[64]; 639 static struct timeval prevtime, prevtime_e; 640 struct timeval temp; 641 const char *type; 642 const char *sign; 643 644 switch (kth->ktr_type) { 645 case KTR_SYSCALL: 646 type = "CALL"; 647 break; 648 case KTR_SYSRET: 649 type = "RET "; 650 break; 651 case KTR_NAMEI: 652 type = "NAMI"; 653 break; 654 case KTR_GENIO: 655 type = "GIO "; 656 break; 657 case KTR_PSIG: 658 type = "PSIG"; 659 break; 660 case KTR_CSW: 661 type = "CSW "; 662 break; 663 case KTR_USER: 664 type = "USER"; 665 break; 666 case KTR_STRUCT: 667 case KTR_STRUCT_ARRAY: 668 type = "STRU"; 669 break; 670 case KTR_SYSCTL: 671 type = "SCTL"; 672 break; 673 case KTR_PROCCTOR: 674 /* FALLTHROUGH */ 675 case KTR_PROCDTOR: 676 return; 677 case KTR_CAPFAIL: 678 type = "CAP "; 679 break; 680 case KTR_FAULT: 681 type = "PFLT"; 682 break; 683 case KTR_FAULTEND: 684 type = "PRET"; 685 break; 686 default: 687 sprintf(unknown, "UNKNOWN(%d)", kth->ktr_type); 688 type = unknown; 689 } 690 691 /* 692 * The ktr_tid field was previously the ktr_buffer field, which held 693 * the kernel pointer value for the buffer associated with data 694 * following the record header. It now holds a threadid, but only 695 * for trace files after the change. Older trace files still contain 696 * kernel pointers. Detect this and suppress the results by printing 697 * negative tid's as 0. 698 */ 699 if (threads) 700 printf("%6jd %6jd %-8.*s ", (intmax_t)kth->ktr_pid, 701 kth->ktr_tid > 0 ? (intmax_t)kth->ktr_tid : 0, 702 MAXCOMLEN, kth->ktr_comm); 703 else 704 printf("%6jd %-8.*s ", (intmax_t)kth->ktr_pid, MAXCOMLEN, 705 kth->ktr_comm); 706 if (timestamp) { 707 if (timestamp & TIMESTAMP_ABSOLUTE) { 708 printf("%jd.%06ld ", (intmax_t)kth->ktr_time.tv_sec, 709 kth->ktr_time.tv_usec); 710 } 711 if (timestamp & TIMESTAMP_ELAPSED) { 712 if (prevtime_e.tv_sec == 0) 713 prevtime_e = kth->ktr_time; 714 timersub(&kth->ktr_time, &prevtime_e, &temp); 715 printf("%jd.%06ld ", (intmax_t)temp.tv_sec, 716 temp.tv_usec); 717 } 718 if (timestamp & TIMESTAMP_RELATIVE) { 719 if (prevtime.tv_sec == 0) 720 prevtime = kth->ktr_time; 721 if (timercmp(&kth->ktr_time, &prevtime, <)) { 722 timersub(&prevtime, &kth->ktr_time, &temp); 723 sign = "-"; 724 } else { 725 timersub(&kth->ktr_time, &prevtime, &temp); 726 sign = ""; 727 } 728 prevtime = kth->ktr_time; 729 printf("%s%jd.%06ld ", sign, (intmax_t)temp.tv_sec, 730 temp.tv_usec); 731 } 732 } 733 printf("%s ", type); 734 } 735 736 #include <sys/syscall.h> 737 738 static void 739 ioctlname(unsigned long val) 740 { 741 const char *str; 742 743 str = sysdecode_ioctlname(val); 744 if (str != NULL) 745 printf("%s", str); 746 else if (decimal) 747 printf("%lu", val); 748 else 749 printf("%#lx", val); 750 } 751 752 static enum sysdecode_abi 753 syscallabi(u_int sv_flags) 754 { 755 756 if (sv_flags == 0) 757 return (SYSDECODE_ABI_FREEBSD); 758 switch (sv_flags & SV_ABI_MASK) { 759 case SV_ABI_FREEBSD: 760 return (SYSDECODE_ABI_FREEBSD); 761 #if defined(__amd64__) || defined(__i386__) 762 case SV_ABI_LINUX: 763 #ifdef __amd64__ 764 if (sv_flags & SV_ILP32) 765 return (SYSDECODE_ABI_LINUX32); 766 #endif 767 return (SYSDECODE_ABI_LINUX); 768 #endif 769 #if defined(__aarch64__) || defined(__amd64__) 770 case SV_ABI_CLOUDABI: 771 return (SYSDECODE_ABI_CLOUDABI64); 772 #endif 773 default: 774 return (SYSDECODE_ABI_UNKNOWN); 775 } 776 } 777 778 static void 779 syscallname(u_int code, u_int sv_flags) 780 { 781 const char *name; 782 783 name = sysdecode_syscallname(syscallabi(sv_flags), code); 784 if (name == NULL) 785 printf("[%d]", code); 786 else { 787 printf("%s", name); 788 if (syscallno) 789 printf("[%d]", code); 790 } 791 } 792 793 static void 794 print_signal(int signo) 795 { 796 const char *signame; 797 798 signame = sysdecode_signal(signo); 799 if (signame != NULL) 800 printf("%s", signame); 801 else 802 printf("SIG %d", signo); 803 } 804 805 void 806 ktrsyscall(struct ktr_syscall *ktr, u_int sv_flags) 807 { 808 int narg = ktr->ktr_narg; 809 register_t *ip, *first; 810 intmax_t arg; 811 int quad_align, quad_slots; 812 813 syscallname(ktr->ktr_code, sv_flags); 814 ip = first = &ktr->ktr_args[0]; 815 if (narg) { 816 char c = '('; 817 if (fancy && 818 (sv_flags == 0 || 819 (sv_flags & SV_ABI_MASK) == SV_ABI_FREEBSD)) { 820 quad_align = 0; 821 if (sv_flags & SV_ILP32) { 822 #ifdef __powerpc__ 823 quad_align = 1; 824 #endif 825 quad_slots = 2; 826 } else 827 quad_slots = 1; 828 switch (ktr->ktr_code) { 829 case SYS_bindat: 830 case SYS_chflagsat: 831 case SYS_connectat: 832 case SYS_faccessat: 833 case SYS_fchmodat: 834 case SYS_fchownat: 835 case SYS_fstatat: 836 case SYS_futimesat: 837 case SYS_linkat: 838 case SYS_mkdirat: 839 case SYS_mkfifoat: 840 case SYS_mknodat: 841 case SYS_openat: 842 case SYS_readlinkat: 843 case SYS_renameat: 844 case SYS_unlinkat: 845 case SYS_utimensat: 846 putchar('('); 847 print_integer_arg_valid(sysdecode_atfd, *ip); 848 c = ','; 849 ip++; 850 narg--; 851 break; 852 } 853 switch (ktr->ktr_code) { 854 case SYS_ioctl: { 855 print_number(ip, narg, c); 856 putchar(c); 857 ioctlname(*ip); 858 c = ','; 859 ip++; 860 narg--; 861 break; 862 } 863 case SYS_ptrace: 864 putchar('('); 865 print_integer_arg(sysdecode_ptrace_request, *ip); 866 c = ','; 867 ip++; 868 narg--; 869 break; 870 case SYS_access: 871 case SYS_eaccess: 872 case SYS_faccessat: 873 print_number(ip, narg, c); 874 putchar(','); 875 print_mask_arg(sysdecode_access_mode, *ip); 876 ip++; 877 narg--; 878 break; 879 case SYS_open: 880 case SYS_openat: 881 print_number(ip, narg, c); 882 putchar(','); 883 print_mask_arg(sysdecode_open_flags, ip[0]); 884 if ((ip[0] & O_CREAT) == O_CREAT) { 885 putchar(','); 886 decode_filemode(ip[1]); 887 } 888 ip += 2; 889 narg -= 2; 890 break; 891 case SYS_wait4: 892 print_number(ip, narg, c); 893 print_number(ip, narg, c); 894 putchar(','); 895 print_mask_arg0(sysdecode_wait4_options, *ip); 896 ip++; 897 narg--; 898 break; 899 case SYS_wait6: 900 putchar('('); 901 print_integer_arg(sysdecode_idtype, *ip); 902 c = ','; 903 ip++; 904 narg--; 905 print_number64(first, ip, narg, c); 906 print_number(ip, narg, c); 907 putchar(','); 908 print_mask_arg(sysdecode_wait6_options, *ip); 909 ip++; 910 narg--; 911 break; 912 case SYS_chmod: 913 case SYS_fchmod: 914 case SYS_lchmod: 915 case SYS_fchmodat: 916 print_number(ip, narg, c); 917 putchar(','); 918 decode_filemode(*ip); 919 ip++; 920 narg--; 921 break; 922 case SYS_mknodat: 923 print_number(ip, narg, c); 924 putchar(','); 925 decode_filemode(*ip); 926 ip++; 927 narg--; 928 break; 929 case SYS_getfsstat: 930 print_number(ip, narg, c); 931 print_number(ip, narg, c); 932 putchar(','); 933 print_integer_arg(sysdecode_getfsstat_mode, *ip); 934 ip++; 935 narg--; 936 break; 937 case SYS_mount: 938 print_number(ip, narg, c); 939 print_number(ip, narg, c); 940 putchar(','); 941 print_mask_arg(sysdecode_mount_flags, *ip); 942 ip++; 943 narg--; 944 break; 945 case SYS_unmount: 946 print_number(ip, narg, c); 947 putchar(','); 948 print_mask_arg(sysdecode_mount_flags, *ip); 949 ip++; 950 narg--; 951 break; 952 case SYS_recvmsg: 953 case SYS_sendmsg: 954 print_number(ip, narg, c); 955 print_number(ip, narg, c); 956 putchar(','); 957 print_mask_arg0(sysdecode_msg_flags, *ip); 958 ip++; 959 narg--; 960 break; 961 case SYS_recvfrom: 962 case SYS_sendto: 963 print_number(ip, narg, c); 964 print_number(ip, narg, c); 965 print_number(ip, narg, c); 966 putchar(','); 967 print_mask_arg0(sysdecode_msg_flags, *ip); 968 ip++; 969 narg--; 970 break; 971 case SYS_chflags: 972 case SYS_chflagsat: 973 case SYS_fchflags: 974 case SYS_lchflags: 975 print_number(ip, narg, c); 976 putchar(','); 977 decode_fileflags(*ip); 978 ip++; 979 narg--; 980 break; 981 case SYS_kill: 982 print_number(ip, narg, c); 983 putchar(','); 984 print_signal(*ip); 985 ip++; 986 narg--; 987 break; 988 case SYS_reboot: 989 putchar('('); 990 print_mask_arg(sysdecode_reboot_howto, *ip); 991 ip++; 992 narg--; 993 break; 994 case SYS_umask: 995 putchar('('); 996 decode_filemode(*ip); 997 ip++; 998 narg--; 999 break; 1000 case SYS_msync: 1001 print_number(ip, narg, c); 1002 print_number(ip, narg, c); 1003 putchar(','); 1004 print_mask_arg(sysdecode_msync_flags, *ip); 1005 ip++; 1006 narg--; 1007 break; 1008 #ifdef SYS_freebsd6_mmap 1009 case SYS_freebsd6_mmap: 1010 print_number(ip, narg, c); 1011 print_number(ip, narg, c); 1012 putchar(','); 1013 print_mask_arg(sysdecode_mmap_prot, *ip); 1014 putchar(','); 1015 ip++; 1016 narg--; 1017 print_mask_arg(sysdecode_mmap_flags, *ip); 1018 ip++; 1019 narg--; 1020 break; 1021 #endif 1022 case SYS_mmap: 1023 print_number(ip, narg, c); 1024 print_number(ip, narg, c); 1025 putchar(','); 1026 print_mask_arg(sysdecode_mmap_prot, *ip); 1027 putchar(','); 1028 ip++; 1029 narg--; 1030 print_mask_arg(sysdecode_mmap_flags, *ip); 1031 ip++; 1032 narg--; 1033 break; 1034 case SYS_mprotect: 1035 print_number(ip, narg, c); 1036 print_number(ip, narg, c); 1037 putchar(','); 1038 print_mask_arg(sysdecode_mmap_prot, *ip); 1039 ip++; 1040 narg--; 1041 break; 1042 case SYS_madvise: 1043 print_number(ip, narg, c); 1044 print_number(ip, narg, c); 1045 putchar(','); 1046 print_integer_arg(sysdecode_madvice, *ip); 1047 ip++; 1048 narg--; 1049 break; 1050 case SYS_pathconf: 1051 case SYS_lpathconf: 1052 case SYS_fpathconf: 1053 print_number(ip, narg, c); 1054 putchar(','); 1055 print_integer_arg(sysdecode_pathconf_name, *ip); 1056 ip++; 1057 narg--; 1058 break; 1059 case SYS_getpriority: 1060 case SYS_setpriority: 1061 putchar('('); 1062 print_integer_arg(sysdecode_prio_which, *ip); 1063 c = ','; 1064 ip++; 1065 narg--; 1066 break; 1067 case SYS_fcntl: 1068 print_number(ip, narg, c); 1069 putchar(','); 1070 print_integer_arg(sysdecode_fcntl_cmd, ip[0]); 1071 if (sysdecode_fcntl_arg_p(ip[0])) { 1072 putchar(','); 1073 if (ip[0] == F_SETFL) 1074 print_mask_arg( 1075 sysdecode_fcntl_fileflags, 1076 ip[1]); 1077 else 1078 sysdecode_fcntl_arg(stdout, 1079 ip[0], ip[1], 1080 decimal ? 10 : 16); 1081 } 1082 ip += 2; 1083 narg -= 2; 1084 break; 1085 case SYS_socket: { 1086 int sockdomain; 1087 putchar('('); 1088 sockdomain = *ip; 1089 print_integer_arg(sysdecode_socketdomain, 1090 sockdomain); 1091 ip++; 1092 narg--; 1093 putchar(','); 1094 print_mask_arg(sysdecode_socket_type, *ip); 1095 ip++; 1096 narg--; 1097 if (sockdomain == PF_INET || 1098 sockdomain == PF_INET6) { 1099 putchar(','); 1100 print_integer_arg(sysdecode_ipproto, 1101 *ip); 1102 ip++; 1103 narg--; 1104 } 1105 c = ','; 1106 break; 1107 } 1108 case SYS_setsockopt: 1109 case SYS_getsockopt: { 1110 const char *str; 1111 1112 print_number(ip, narg, c); 1113 putchar(','); 1114 print_integer_arg_valid(sysdecode_sockopt_level, 1115 *ip); 1116 str = sysdecode_sockopt_name(ip[0], ip[1]); 1117 if (str != NULL) { 1118 printf(",%s", str); 1119 ip++; 1120 narg--; 1121 } 1122 ip++; 1123 narg--; 1124 break; 1125 } 1126 #ifdef SYS_freebsd6_lseek 1127 case SYS_freebsd6_lseek: 1128 print_number(ip, narg, c); 1129 /* Hidden 'pad' argument, not in lseek(2) */ 1130 print_number(ip, narg, c); 1131 print_number64(first, ip, narg, c); 1132 putchar(','); 1133 print_integer_arg(sysdecode_whence, *ip); 1134 ip++; 1135 narg--; 1136 break; 1137 #endif 1138 case SYS_lseek: 1139 print_number(ip, narg, c); 1140 print_number64(first, ip, narg, c); 1141 putchar(','); 1142 print_integer_arg(sysdecode_whence, *ip); 1143 ip++; 1144 narg--; 1145 break; 1146 case SYS_flock: 1147 print_number(ip, narg, c); 1148 putchar(','); 1149 print_mask_arg(sysdecode_flock_operation, *ip); 1150 ip++; 1151 narg--; 1152 break; 1153 case SYS_mkfifo: 1154 case SYS_mkfifoat: 1155 case SYS_mkdir: 1156 case SYS_mkdirat: 1157 print_number(ip, narg, c); 1158 putchar(','); 1159 decode_filemode(*ip); 1160 ip++; 1161 narg--; 1162 break; 1163 case SYS_shutdown: 1164 print_number(ip, narg, c); 1165 putchar(','); 1166 print_integer_arg(sysdecode_shutdown_how, *ip); 1167 ip++; 1168 narg--; 1169 break; 1170 case SYS_socketpair: 1171 putchar('('); 1172 print_integer_arg(sysdecode_socketdomain, *ip); 1173 ip++; 1174 narg--; 1175 putchar(','); 1176 print_mask_arg(sysdecode_socket_type, *ip); 1177 ip++; 1178 narg--; 1179 c = ','; 1180 break; 1181 case SYS_getrlimit: 1182 case SYS_setrlimit: 1183 putchar('('); 1184 print_integer_arg(sysdecode_rlimit, *ip); 1185 ip++; 1186 narg--; 1187 c = ','; 1188 break; 1189 case SYS_getrusage: 1190 putchar('('); 1191 print_integer_arg(sysdecode_getrusage_who, *ip); 1192 ip++; 1193 narg--; 1194 c = ','; 1195 break; 1196 case SYS_quotactl: 1197 print_number(ip, narg, c); 1198 putchar(','); 1199 if (!sysdecode_quotactl_cmd(stdout, *ip)) { 1200 if (decimal) 1201 printf("<invalid=%d>", (int)*ip); 1202 else 1203 printf("<invalid=%#x>", 1204 (int)*ip); 1205 } 1206 ip++; 1207 narg--; 1208 c = ','; 1209 break; 1210 case SYS_nfssvc: 1211 putchar('('); 1212 print_integer_arg(sysdecode_nfssvc_flags, *ip); 1213 ip++; 1214 narg--; 1215 c = ','; 1216 break; 1217 case SYS_rtprio: 1218 case SYS_rtprio_thread: 1219 putchar('('); 1220 print_integer_arg(sysdecode_rtprio_function, 1221 *ip); 1222 ip++; 1223 narg--; 1224 c = ','; 1225 break; 1226 case SYS___semctl: 1227 print_number(ip, narg, c); 1228 print_number(ip, narg, c); 1229 putchar(','); 1230 print_integer_arg(sysdecode_semctl_cmd, *ip); 1231 ip++; 1232 narg--; 1233 break; 1234 case SYS_semget: 1235 print_number(ip, narg, c); 1236 print_number(ip, narg, c); 1237 putchar(','); 1238 print_mask_arg(sysdecode_semget_flags, *ip); 1239 ip++; 1240 narg--; 1241 break; 1242 case SYS_msgctl: 1243 print_number(ip, narg, c); 1244 putchar(','); 1245 print_integer_arg(sysdecode_msgctl_cmd, *ip); 1246 ip++; 1247 narg--; 1248 break; 1249 case SYS_shmat: 1250 print_number(ip, narg, c); 1251 print_number(ip, narg, c); 1252 putchar(','); 1253 print_mask_arg(sysdecode_shmat_flags, *ip); 1254 ip++; 1255 narg--; 1256 break; 1257 case SYS_shmctl: 1258 print_number(ip, narg, c); 1259 putchar(','); 1260 print_integer_arg(sysdecode_shmctl_cmd, *ip); 1261 ip++; 1262 narg--; 1263 break; 1264 case SYS_shm_open: 1265 print_number(ip, narg, c); 1266 putchar(','); 1267 print_mask_arg(sysdecode_open_flags, ip[0]); 1268 putchar(','); 1269 decode_filemode(ip[1]); 1270 ip += 2; 1271 narg -= 2; 1272 break; 1273 case SYS_minherit: 1274 print_number(ip, narg, c); 1275 print_number(ip, narg, c); 1276 putchar(','); 1277 print_integer_arg(sysdecode_minherit_inherit, 1278 *ip); 1279 ip++; 1280 narg--; 1281 break; 1282 case SYS_rfork: 1283 putchar('('); 1284 print_mask_arg(sysdecode_rfork_flags, *ip); 1285 ip++; 1286 narg--; 1287 c = ','; 1288 break; 1289 case SYS_lio_listio: 1290 putchar('('); 1291 print_integer_arg(sysdecode_lio_listio_mode, 1292 *ip); 1293 ip++; 1294 narg--; 1295 c = ','; 1296 break; 1297 case SYS_mlockall: 1298 putchar('('); 1299 print_mask_arg(sysdecode_mlockall_flags, *ip); 1300 ip++; 1301 narg--; 1302 break; 1303 case SYS_sched_setscheduler: 1304 print_number(ip, narg, c); 1305 putchar(','); 1306 print_integer_arg(sysdecode_scheduler_policy, 1307 *ip); 1308 ip++; 1309 narg--; 1310 break; 1311 case SYS_sched_get_priority_max: 1312 case SYS_sched_get_priority_min: 1313 putchar('('); 1314 print_integer_arg(sysdecode_scheduler_policy, 1315 *ip); 1316 ip++; 1317 narg--; 1318 break; 1319 case SYS_sendfile: 1320 print_number(ip, narg, c); 1321 print_number(ip, narg, c); 1322 print_number(ip, narg, c); 1323 print_number(ip, narg, c); 1324 print_number(ip, narg, c); 1325 print_number(ip, narg, c); 1326 putchar(','); 1327 print_mask_arg(sysdecode_sendfile_flags, *ip); 1328 ip++; 1329 narg--; 1330 break; 1331 case SYS_kldsym: 1332 print_number(ip, narg, c); 1333 putchar(','); 1334 print_integer_arg(sysdecode_kldsym_cmd, *ip); 1335 ip++; 1336 narg--; 1337 break; 1338 case SYS_sigprocmask: 1339 putchar('('); 1340 print_integer_arg(sysdecode_sigprocmask_how, 1341 *ip); 1342 ip++; 1343 narg--; 1344 c = ','; 1345 break; 1346 case SYS___acl_get_file: 1347 case SYS___acl_set_file: 1348 case SYS___acl_get_fd: 1349 case SYS___acl_set_fd: 1350 case SYS___acl_delete_file: 1351 case SYS___acl_delete_fd: 1352 case SYS___acl_aclcheck_file: 1353 case SYS___acl_aclcheck_fd: 1354 case SYS___acl_get_link: 1355 case SYS___acl_set_link: 1356 case SYS___acl_delete_link: 1357 case SYS___acl_aclcheck_link: 1358 print_number(ip, narg, c); 1359 putchar(','); 1360 print_integer_arg(sysdecode_acltype, *ip); 1361 ip++; 1362 narg--; 1363 break; 1364 case SYS_sigaction: 1365 putchar('('); 1366 print_signal(*ip); 1367 ip++; 1368 narg--; 1369 c = ','; 1370 break; 1371 case SYS_extattrctl: 1372 print_number(ip, narg, c); 1373 putchar(','); 1374 print_integer_arg(sysdecode_extattrnamespace, 1375 *ip); 1376 ip++; 1377 narg--; 1378 break; 1379 case SYS_nmount: 1380 print_number(ip, narg, c); 1381 print_number(ip, narg, c); 1382 putchar(','); 1383 print_mask_arg(sysdecode_mount_flags, *ip); 1384 ip++; 1385 narg--; 1386 break; 1387 case SYS_thr_create: 1388 print_number(ip, narg, c); 1389 print_number(ip, narg, c); 1390 putchar(','); 1391 print_mask_arg(sysdecode_thr_create_flags, *ip); 1392 ip++; 1393 narg--; 1394 break; 1395 case SYS_thr_kill: 1396 print_number(ip, narg, c); 1397 putchar(','); 1398 print_signal(*ip); 1399 ip++; 1400 narg--; 1401 break; 1402 case SYS_kldunloadf: 1403 print_number(ip, narg, c); 1404 putchar(','); 1405 print_integer_arg(sysdecode_kldunload_flags, 1406 *ip); 1407 ip++; 1408 narg--; 1409 break; 1410 case SYS_linkat: 1411 case SYS_renameat: 1412 case SYS_symlinkat: 1413 print_number(ip, narg, c); 1414 putchar(','); 1415 print_integer_arg_valid(sysdecode_atfd, *ip); 1416 ip++; 1417 narg--; 1418 print_number(ip, narg, c); 1419 break; 1420 case SYS_cap_fcntls_limit: 1421 print_number(ip, narg, c); 1422 putchar(','); 1423 arg = *ip; 1424 ip++; 1425 narg--; 1426 print_mask_arg32(sysdecode_cap_fcntlrights, arg); 1427 break; 1428 case SYS_posix_fadvise: 1429 print_number(ip, narg, c); 1430 print_number(ip, narg, c); 1431 print_number(ip, narg, c); 1432 (void)putchar(','); 1433 print_integer_arg(sysdecode_fadvice, *ip); 1434 ip++; 1435 narg--; 1436 break; 1437 case SYS_procctl: 1438 putchar('('); 1439 print_integer_arg(sysdecode_idtype, *ip); 1440 c = ','; 1441 ip++; 1442 narg--; 1443 print_number64(first, ip, narg, c); 1444 putchar(','); 1445 print_integer_arg(sysdecode_procctl_cmd, *ip); 1446 ip++; 1447 narg--; 1448 break; 1449 case SYS__umtx_op: 1450 print_number(ip, narg, c); 1451 putchar(','); 1452 print_integer_arg(sysdecode_umtx_op, *ip); 1453 switch (*ip) { 1454 case UMTX_OP_CV_WAIT: 1455 ip++; 1456 narg--; 1457 putchar(','); 1458 print_mask_argul( 1459 sysdecode_umtx_cvwait_flags, *ip); 1460 break; 1461 case UMTX_OP_RW_RDLOCK: 1462 ip++; 1463 narg--; 1464 putchar(','); 1465 print_mask_argul( 1466 sysdecode_umtx_rwlock_flags, *ip); 1467 break; 1468 } 1469 ip++; 1470 narg--; 1471 break; 1472 case SYS_ftruncate: 1473 case SYS_truncate: 1474 print_number(ip, narg, c); 1475 print_number64(first, ip, narg, c); 1476 break; 1477 case SYS_fchownat: 1478 print_number(ip, narg, c); 1479 print_number(ip, narg, c); 1480 print_number(ip, narg, c); 1481 break; 1482 case SYS_fstatat: 1483 case SYS_utimensat: 1484 print_number(ip, narg, c); 1485 print_number(ip, narg, c); 1486 break; 1487 case SYS_unlinkat: 1488 print_number(ip, narg, c); 1489 break; 1490 case SYS_sysarch: 1491 putchar('('); 1492 print_integer_arg(sysdecode_sysarch_number, *ip); 1493 ip++; 1494 narg--; 1495 c = ','; 1496 break; 1497 } 1498 switch (ktr->ktr_code) { 1499 case SYS_chflagsat: 1500 case SYS_fchownat: 1501 case SYS_faccessat: 1502 case SYS_fchmodat: 1503 case SYS_fstatat: 1504 case SYS_linkat: 1505 case SYS_unlinkat: 1506 case SYS_utimensat: 1507 putchar(','); 1508 print_mask_arg0(sysdecode_atflags, *ip); 1509 ip++; 1510 narg--; 1511 break; 1512 } 1513 } 1514 while (narg > 0) { 1515 print_number(ip, narg, c); 1516 } 1517 putchar(')'); 1518 } 1519 putchar('\n'); 1520 } 1521 1522 void 1523 ktrsysret(struct ktr_sysret *ktr, u_int sv_flags) 1524 { 1525 register_t ret = ktr->ktr_retval; 1526 int error = ktr->ktr_error; 1527 1528 syscallname(ktr->ktr_code, sv_flags); 1529 printf(" "); 1530 1531 if (error == 0) { 1532 if (fancy) { 1533 printf("%ld", (long)ret); 1534 if (ret < 0 || ret > 9) 1535 printf("/%#lx", (unsigned long)ret); 1536 } else { 1537 if (decimal) 1538 printf("%ld", (long)ret); 1539 else 1540 printf("%#lx", (unsigned long)ret); 1541 } 1542 } else if (error == ERESTART) 1543 printf("RESTART"); 1544 else if (error == EJUSTRETURN) 1545 printf("JUSTRETURN"); 1546 else { 1547 printf("-1 errno %d", sysdecode_freebsd_to_abi_errno( 1548 syscallabi(sv_flags), error)); 1549 if (fancy) 1550 printf(" %s", strerror(ktr->ktr_error)); 1551 } 1552 putchar('\n'); 1553 } 1554 1555 void 1556 ktrnamei(char *cp, int len) 1557 { 1558 printf("\"%.*s\"\n", len, cp); 1559 } 1560 1561 void 1562 hexdump(char *p, int len, int screenwidth) 1563 { 1564 int n, i; 1565 int width; 1566 1567 width = 0; 1568 do { 1569 width += 2; 1570 i = 13; /* base offset */ 1571 i += (width / 2) + 1; /* spaces every second byte */ 1572 i += (width * 2); /* width of bytes */ 1573 i += 3; /* " |" */ 1574 i += width; /* each byte */ 1575 i += 1; /* "|" */ 1576 } while (i < screenwidth); 1577 width -= 2; 1578 1579 for (n = 0; n < len; n += width) { 1580 for (i = n; i < n + width; i++) { 1581 if ((i % width) == 0) { /* beginning of line */ 1582 printf(" 0x%04x", i); 1583 } 1584 if ((i % 2) == 0) { 1585 printf(" "); 1586 } 1587 if (i < len) 1588 printf("%02x", p[i] & 0xff); 1589 else 1590 printf(" "); 1591 } 1592 printf(" |"); 1593 for (i = n; i < n + width; i++) { 1594 if (i >= len) 1595 break; 1596 if (p[i] >= ' ' && p[i] <= '~') 1597 printf("%c", p[i]); 1598 else 1599 printf("."); 1600 } 1601 printf("|\n"); 1602 } 1603 if ((i % width) != 0) 1604 printf("\n"); 1605 } 1606 1607 void 1608 visdump(char *dp, int datalen, int screenwidth) 1609 { 1610 int col = 0; 1611 char *cp; 1612 int width; 1613 char visbuf[5]; 1614 1615 printf(" \""); 1616 col = 8; 1617 for (;datalen > 0; datalen--, dp++) { 1618 vis(visbuf, *dp, VIS_CSTYLE, *(dp+1)); 1619 cp = visbuf; 1620 /* 1621 * Keep track of printables and 1622 * space chars (like fold(1)). 1623 */ 1624 if (col == 0) { 1625 putchar('\t'); 1626 col = 8; 1627 } 1628 switch(*cp) { 1629 case '\n': 1630 col = 0; 1631 putchar('\n'); 1632 continue; 1633 case '\t': 1634 width = 8 - (col&07); 1635 break; 1636 default: 1637 width = strlen(cp); 1638 } 1639 if (col + width > (screenwidth-2)) { 1640 printf("\\\n\t"); 1641 col = 8; 1642 } 1643 col += width; 1644 do { 1645 putchar(*cp++); 1646 } while (*cp); 1647 } 1648 if (col == 0) 1649 printf(" "); 1650 printf("\"\n"); 1651 } 1652 1653 void 1654 ktrgenio(struct ktr_genio *ktr, int len) 1655 { 1656 int datalen = len - sizeof (struct ktr_genio); 1657 char *dp = (char *)ktr + sizeof (struct ktr_genio); 1658 static int screenwidth = 0; 1659 int i, binary; 1660 1661 printf("fd %d %s %d byte%s\n", ktr->ktr_fd, 1662 ktr->ktr_rw == UIO_READ ? "read" : "wrote", datalen, 1663 datalen == 1 ? "" : "s"); 1664 if (suppressdata) 1665 return; 1666 if (screenwidth == 0) { 1667 struct winsize ws; 1668 1669 if (fancy && ioctl(fileno(stderr), TIOCGWINSZ, &ws) != -1 && 1670 ws.ws_col > 8) 1671 screenwidth = ws.ws_col; 1672 else 1673 screenwidth = 80; 1674 } 1675 if (maxdata && datalen > maxdata) 1676 datalen = maxdata; 1677 1678 for (i = 0, binary = 0; i < datalen && binary == 0; i++) { 1679 if (dp[i] >= 32 && dp[i] < 127) 1680 continue; 1681 if (dp[i] == 10 || dp[i] == 13 || dp[i] == 0 || dp[i] == 9) 1682 continue; 1683 binary = 1; 1684 } 1685 if (binary) 1686 hexdump(dp, datalen, screenwidth); 1687 else 1688 visdump(dp, datalen, screenwidth); 1689 } 1690 1691 void 1692 ktrpsig(struct ktr_psig *psig) 1693 { 1694 const char *str; 1695 1696 print_signal(psig->signo); 1697 if (psig->action == SIG_DFL) { 1698 printf(" SIG_DFL"); 1699 } else { 1700 printf(" caught handler=0x%lx mask=0x%x", 1701 (u_long)psig->action, psig->mask.__bits[0]); 1702 } 1703 printf(" code="); 1704 str = sysdecode_sigcode(psig->signo, psig->code); 1705 if (str != NULL) 1706 printf("%s", str); 1707 else 1708 printf("<invalid=%#x>", psig->code); 1709 putchar('\n'); 1710 } 1711 1712 void 1713 ktrcsw_old(struct ktr_csw_old *cs) 1714 { 1715 printf("%s %s\n", cs->out ? "stop" : "resume", 1716 cs->user ? "user" : "kernel"); 1717 } 1718 1719 void 1720 ktrcsw(struct ktr_csw *cs) 1721 { 1722 printf("%s %s \"%s\"\n", cs->out ? "stop" : "resume", 1723 cs->user ? "user" : "kernel", cs->wmesg); 1724 } 1725 1726 void 1727 ktruser(int len, void *p) 1728 { 1729 unsigned char *cp; 1730 1731 if (sysdecode_utrace(stdout, p, len)) { 1732 printf("\n"); 1733 return; 1734 } 1735 1736 printf("%d ", len); 1737 cp = p; 1738 while (len--) 1739 if (decimal) 1740 printf(" %d", *cp++); 1741 else 1742 printf(" %02x", *cp++); 1743 printf("\n"); 1744 } 1745 1746 void 1747 ktrcaprights(cap_rights_t *rightsp) 1748 { 1749 1750 printf("cap_rights_t "); 1751 sysdecode_cap_rights(stdout, rightsp); 1752 printf("\n"); 1753 } 1754 1755 static void 1756 ktrtimeval(struct timeval *tv) 1757 { 1758 1759 printf("{%ld, %ld}", (long)tv->tv_sec, tv->tv_usec); 1760 } 1761 1762 void 1763 ktritimerval(struct itimerval *it) 1764 { 1765 1766 printf("itimerval { .interval = "); 1767 ktrtimeval(&it->it_interval); 1768 printf(", .value = "); 1769 ktrtimeval(&it->it_value); 1770 printf(" }\n"); 1771 } 1772 1773 void 1774 ktrsockaddr(struct sockaddr *sa) 1775 { 1776 /* 1777 TODO: Support additional address families 1778 #include <netsmb/netbios.h> 1779 struct sockaddr_nb *nb; 1780 */ 1781 const char *str; 1782 char addr[64]; 1783 1784 /* 1785 * note: ktrstruct() has already verified that sa points to a 1786 * buffer at least sizeof(struct sockaddr) bytes long and exactly 1787 * sa->sa_len bytes long. 1788 */ 1789 printf("struct sockaddr { "); 1790 str = sysdecode_sockaddr_family(sa->sa_family); 1791 if (str != NULL) 1792 printf("%s", str); 1793 else 1794 printf("<invalid=%d>", sa->sa_family); 1795 printf(", "); 1796 1797 #define check_sockaddr_len(n) \ 1798 if (sa_##n.s##n##_len < sizeof(struct sockaddr_##n)) { \ 1799 printf("invalid"); \ 1800 break; \ 1801 } 1802 1803 switch(sa->sa_family) { 1804 case AF_INET: { 1805 struct sockaddr_in sa_in; 1806 1807 memset(&sa_in, 0, sizeof(sa_in)); 1808 memcpy(&sa_in, sa, sa->sa_len); 1809 check_sockaddr_len(in); 1810 inet_ntop(AF_INET, &sa_in.sin_addr, addr, sizeof addr); 1811 printf("%s:%u", addr, ntohs(sa_in.sin_port)); 1812 break; 1813 } 1814 case AF_INET6: { 1815 struct sockaddr_in6 sa_in6; 1816 1817 memset(&sa_in6, 0, sizeof(sa_in6)); 1818 memcpy(&sa_in6, sa, sa->sa_len); 1819 check_sockaddr_len(in6); 1820 getnameinfo((struct sockaddr *)&sa_in6, sizeof(sa_in6), 1821 addr, sizeof(addr), NULL, 0, NI_NUMERICHOST); 1822 printf("[%s]:%u", addr, htons(sa_in6.sin6_port)); 1823 break; 1824 } 1825 case AF_UNIX: { 1826 struct sockaddr_un sa_un; 1827 1828 memset(&sa_un, 0, sizeof(sa_un)); 1829 memcpy(&sa_un, sa, sa->sa_len); 1830 printf("%.*s", (int)sizeof(sa_un.sun_path), sa_un.sun_path); 1831 break; 1832 } 1833 default: 1834 printf("unknown address family"); 1835 } 1836 printf(" }\n"); 1837 } 1838 1839 void 1840 ktrstat(struct stat *statp) 1841 { 1842 char mode[12], timestr[PATH_MAX + 4]; 1843 struct passwd *pwd; 1844 struct group *grp; 1845 struct tm *tm; 1846 1847 /* 1848 * note: ktrstruct() has already verified that statp points to a 1849 * buffer exactly sizeof(struct stat) bytes long. 1850 */ 1851 printf("struct stat {"); 1852 printf("dev=%ju, ino=%ju, ", 1853 (uintmax_t)statp->st_dev, (uintmax_t)statp->st_ino); 1854 if (resolv == 0) 1855 printf("mode=0%jo, ", (uintmax_t)statp->st_mode); 1856 else { 1857 strmode(statp->st_mode, mode); 1858 printf("mode=%s, ", mode); 1859 } 1860 printf("nlink=%ju, ", (uintmax_t)statp->st_nlink); 1861 if (resolv == 0) { 1862 pwd = NULL; 1863 } else { 1864 #ifdef WITH_CASPER 1865 if (cappwd != NULL) 1866 pwd = cap_getpwuid(cappwd, statp->st_uid); 1867 else 1868 #endif 1869 pwd = getpwuid(statp->st_uid); 1870 } 1871 if (pwd == NULL) 1872 printf("uid=%ju, ", (uintmax_t)statp->st_uid); 1873 else 1874 printf("uid=\"%s\", ", pwd->pw_name); 1875 if (resolv == 0) { 1876 grp = NULL; 1877 } else { 1878 #ifdef WITH_CASPER 1879 if (capgrp != NULL) 1880 grp = cap_getgrgid(capgrp, statp->st_gid); 1881 else 1882 #endif 1883 grp = getgrgid(statp->st_gid); 1884 } 1885 if (grp == NULL) 1886 printf("gid=%ju, ", (uintmax_t)statp->st_gid); 1887 else 1888 printf("gid=\"%s\", ", grp->gr_name); 1889 printf("rdev=%ju, ", (uintmax_t)statp->st_rdev); 1890 printf("atime="); 1891 if (resolv == 0) 1892 printf("%jd", (intmax_t)statp->st_atim.tv_sec); 1893 else { 1894 tm = localtime(&statp->st_atim.tv_sec); 1895 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1896 printf("\"%s\"", timestr); 1897 } 1898 if (statp->st_atim.tv_nsec != 0) 1899 printf(".%09ld, ", statp->st_atim.tv_nsec); 1900 else 1901 printf(", "); 1902 printf("mtime="); 1903 if (resolv == 0) 1904 printf("%jd", (intmax_t)statp->st_mtim.tv_sec); 1905 else { 1906 tm = localtime(&statp->st_mtim.tv_sec); 1907 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1908 printf("\"%s\"", timestr); 1909 } 1910 if (statp->st_mtim.tv_nsec != 0) 1911 printf(".%09ld, ", statp->st_mtim.tv_nsec); 1912 else 1913 printf(", "); 1914 printf("ctime="); 1915 if (resolv == 0) 1916 printf("%jd", (intmax_t)statp->st_ctim.tv_sec); 1917 else { 1918 tm = localtime(&statp->st_ctim.tv_sec); 1919 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1920 printf("\"%s\"", timestr); 1921 } 1922 if (statp->st_ctim.tv_nsec != 0) 1923 printf(".%09ld, ", statp->st_ctim.tv_nsec); 1924 else 1925 printf(", "); 1926 printf("birthtime="); 1927 if (resolv == 0) 1928 printf("%jd", (intmax_t)statp->st_birthtim.tv_sec); 1929 else { 1930 tm = localtime(&statp->st_birthtim.tv_sec); 1931 strftime(timestr, sizeof(timestr), TIME_FORMAT, tm); 1932 printf("\"%s\"", timestr); 1933 } 1934 if (statp->st_birthtim.tv_nsec != 0) 1935 printf(".%09ld, ", statp->st_birthtim.tv_nsec); 1936 else 1937 printf(", "); 1938 printf("size=%jd, blksize=%ju, blocks=%jd, flags=0x%x", 1939 (uintmax_t)statp->st_size, (uintmax_t)statp->st_blksize, 1940 (intmax_t)statp->st_blocks, statp->st_flags); 1941 printf(" }\n"); 1942 } 1943 1944 void 1945 ktrstruct(char *buf, size_t buflen) 1946 { 1947 char *name, *data; 1948 size_t namelen, datalen; 1949 int i; 1950 cap_rights_t rights; 1951 struct itimerval it; 1952 struct stat sb; 1953 struct sockaddr_storage ss; 1954 1955 for (name = buf, namelen = 0; 1956 namelen < buflen && name[namelen] != '\0'; 1957 ++namelen) 1958 /* nothing */; 1959 if (namelen == buflen) 1960 goto invalid; 1961 if (name[namelen] != '\0') 1962 goto invalid; 1963 data = buf + namelen + 1; 1964 datalen = buflen - namelen - 1; 1965 if (datalen == 0) 1966 goto invalid; 1967 /* sanity check */ 1968 for (i = 0; i < (int)namelen; ++i) 1969 if (!isalpha(name[i])) 1970 goto invalid; 1971 if (strcmp(name, "caprights") == 0) { 1972 if (datalen != sizeof(cap_rights_t)) 1973 goto invalid; 1974 memcpy(&rights, data, datalen); 1975 ktrcaprights(&rights); 1976 } else if (strcmp(name, "itimerval") == 0) { 1977 if (datalen != sizeof(struct itimerval)) 1978 goto invalid; 1979 memcpy(&it, data, datalen); 1980 ktritimerval(&it); 1981 } else if (strcmp(name, "stat") == 0) { 1982 if (datalen != sizeof(struct stat)) 1983 goto invalid; 1984 memcpy(&sb, data, datalen); 1985 ktrstat(&sb); 1986 } else if (strcmp(name, "sockaddr") == 0) { 1987 if (datalen > sizeof(ss)) 1988 goto invalid; 1989 memcpy(&ss, data, datalen); 1990 if (datalen != ss.ss_len) 1991 goto invalid; 1992 ktrsockaddr((struct sockaddr *)&ss); 1993 } else { 1994 printf("unknown structure\n"); 1995 } 1996 return; 1997 invalid: 1998 printf("invalid record\n"); 1999 } 2000 2001 void 2002 ktrcapfail(struct ktr_cap_fail *ktr) 2003 { 2004 switch (ktr->cap_type) { 2005 case CAPFAIL_NOTCAPABLE: 2006 /* operation on fd with insufficient capabilities */ 2007 printf("operation requires "); 2008 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2009 printf(", descriptor holds "); 2010 sysdecode_cap_rights(stdout, &ktr->cap_held); 2011 break; 2012 case CAPFAIL_INCREASE: 2013 /* requested more capabilities than fd already has */ 2014 printf("attempt to increase capabilities from "); 2015 sysdecode_cap_rights(stdout, &ktr->cap_held); 2016 printf(" to "); 2017 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2018 break; 2019 case CAPFAIL_SYSCALL: 2020 /* called restricted syscall */ 2021 printf("disallowed system call"); 2022 break; 2023 case CAPFAIL_LOOKUP: 2024 /* used ".." in strict-relative mode */ 2025 printf("restricted VFS lookup"); 2026 break; 2027 default: 2028 printf("unknown capability failure: "); 2029 sysdecode_cap_rights(stdout, &ktr->cap_needed); 2030 printf(" "); 2031 sysdecode_cap_rights(stdout, &ktr->cap_held); 2032 break; 2033 } 2034 printf("\n"); 2035 } 2036 2037 void 2038 ktrfault(struct ktr_fault *ktr) 2039 { 2040 2041 printf("0x%jx ", (uintmax_t)ktr->vaddr); 2042 print_mask_arg(sysdecode_vmprot, ktr->type); 2043 printf("\n"); 2044 } 2045 2046 void 2047 ktrfaultend(struct ktr_faultend *ktr) 2048 { 2049 const char *str; 2050 2051 str = sysdecode_vmresult(ktr->result); 2052 if (str != NULL) 2053 printf("%s", str); 2054 else 2055 printf("<invalid=%d>", ktr->result); 2056 printf("\n"); 2057 } 2058 2059 void 2060 ktrkevent(struct kevent *kev) 2061 { 2062 2063 printf("{ ident="); 2064 switch (kev->filter) { 2065 case EVFILT_READ: 2066 case EVFILT_WRITE: 2067 case EVFILT_VNODE: 2068 case EVFILT_PROC: 2069 case EVFILT_TIMER: 2070 case EVFILT_PROCDESC: 2071 case EVFILT_EMPTY: 2072 printf("%ju", (uintmax_t)kev->ident); 2073 break; 2074 case EVFILT_SIGNAL: 2075 print_signal(kev->ident); 2076 break; 2077 default: 2078 printf("%p", (void *)kev->ident); 2079 } 2080 printf(", filter="); 2081 print_integer_arg(sysdecode_kevent_filter, kev->filter); 2082 printf(", flags="); 2083 print_mask_arg0(sysdecode_kevent_flags, kev->flags); 2084 printf(", fflags="); 2085 sysdecode_kevent_fflags(stdout, kev->filter, kev->fflags, 2086 decimal ? 10 : 16); 2087 printf(", data=%#jx, udata=%p }", (uintmax_t)kev->data, kev->udata); 2088 } 2089 2090 void 2091 ktrstructarray(struct ktr_struct_array *ksa, size_t buflen) 2092 { 2093 struct kevent kev; 2094 char *name, *data; 2095 size_t namelen, datalen; 2096 int i; 2097 bool first; 2098 2099 buflen -= sizeof(*ksa); 2100 for (name = (char *)(ksa + 1), namelen = 0; 2101 namelen < buflen && name[namelen] != '\0'; 2102 ++namelen) 2103 /* nothing */; 2104 if (namelen == buflen) 2105 goto invalid; 2106 if (name[namelen] != '\0') 2107 goto invalid; 2108 /* sanity check */ 2109 for (i = 0; i < (int)namelen; ++i) 2110 if (!isalnum(name[i]) && name[i] != '_') 2111 goto invalid; 2112 data = name + namelen + 1; 2113 datalen = buflen - namelen - 1; 2114 printf("struct %s[] = { ", name); 2115 first = true; 2116 for (; datalen >= ksa->struct_size; 2117 data += ksa->struct_size, datalen -= ksa->struct_size) { 2118 if (!first) 2119 printf("\n "); 2120 else 2121 first = false; 2122 if (strcmp(name, "kevent") == 0) { 2123 if (ksa->struct_size != sizeof(kev)) 2124 goto bad_size; 2125 memcpy(&kev, data, sizeof(kev)); 2126 ktrkevent(&kev); 2127 } else if (strcmp(name, "kevent_freebsd11") == 0) { 2128 struct kevent_freebsd11 kev11; 2129 2130 if (ksa->struct_size != sizeof(kev11)) 2131 goto bad_size; 2132 memcpy(&kev11, data, sizeof(kev11)); 2133 memset(&kev, 0, sizeof(kev)); 2134 kev.ident = kev11.ident; 2135 kev.filter = kev11.filter; 2136 kev.flags = kev11.flags; 2137 kev.fflags = kev11.fflags; 2138 kev.data = kev11.data; 2139 kev.udata = kev11.udata; 2140 ktrkevent(&kev); 2141 #ifdef _WANT_KEVENT32 2142 } else if (strcmp(name, "kevent32") == 0) { 2143 struct kevent32 kev32; 2144 2145 if (ksa->struct_size != sizeof(kev32)) 2146 goto bad_size; 2147 memcpy(&kev32, data, sizeof(kev32)); 2148 memset(&kev, 0, sizeof(kev)); 2149 kev.ident = kev32.ident; 2150 kev.filter = kev32.filter; 2151 kev.flags = kev32.flags; 2152 kev.fflags = kev32.fflags; 2153 #if BYTE_ORDER == BIG_ENDIAN 2154 kev.data = kev32.data2 | ((int64_t)kev32.data1 << 32); 2155 #else 2156 kev.data = kev32.data1 | ((int64_t)kev32.data2 << 32); 2157 #endif 2158 kev.udata = (void *)(uintptr_t)kev32.udata; 2159 ktrkevent(&kev); 2160 } else if (strcmp(name, "kevent32_freebsd11") == 0) { 2161 struct kevent32_freebsd11 kev32; 2162 2163 if (ksa->struct_size != sizeof(kev32)) 2164 goto bad_size; 2165 memcpy(&kev32, data, sizeof(kev32)); 2166 memset(&kev, 0, sizeof(kev)); 2167 kev.ident = kev32.ident; 2168 kev.filter = kev32.filter; 2169 kev.flags = kev32.flags; 2170 kev.fflags = kev32.fflags; 2171 kev.data = kev32.data; 2172 kev.udata = (void *)(uintptr_t)kev32.udata; 2173 ktrkevent(&kev); 2174 #endif 2175 } else { 2176 printf("<unknown structure> }\n"); 2177 return; 2178 } 2179 } 2180 printf(" }\n"); 2181 return; 2182 invalid: 2183 printf("invalid record\n"); 2184 return; 2185 bad_size: 2186 printf("<bad size> }\n"); 2187 return; 2188 } 2189 2190 void 2191 usage(void) 2192 { 2193 fprintf(stderr, "usage: kdump [-dEnlHRrSsTA] [-f trfile] " 2194 "[-m maxdata] [-p pid] [-t trstr]\n"); 2195 exit(1); 2196 } 2197