2 * Copyright (c) 2011, Comtrol Corp.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 * 3. The name of the author may not be used to endorse or promote products
14 * derived from this software without specific prior written permission.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
21 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
25 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
37 #ifdef HAVE_SYS_POLL_H
43 #define MAXSELECTED 256 /* max number of "selected" paths */
44 static const char *selected[MAXSELECTED]; /* paths selected for tracing */
47 * Return true if specified path matches one that we're tracing.
50 pathmatch(const char *path)
54 for (i = 0; i < ARRAY_SIZE(selected); ++i) {
55 if (selected[i] == NULL)
57 if (!strcmp(path, selected[i]))
64 * Return true if specified path (in user-space) matches.
67 upathmatch(struct tcb *tcp, unsigned long upath)
69 char path[PATH_MAX + 1];
71 return umovestr(tcp, upath, sizeof path, path) == 0 &&
76 * Return true if specified fd maps to a path we're tracing.
79 fdmatch(struct tcb *tcp, int fd)
81 const char *path = getfdpath(tcp, fd);
83 return path && pathmatch(path);
87 * Add a path to the set we're tracing.
88 * Secifying NULL will delete all paths.
91 storepath(const char *path)
96 for (i = 0; i < ARRAY_SIZE(selected); ++i)
98 free((char *) selected[i]);
104 for (i = 0; i < ARRAY_SIZE(selected); ++i)
110 fprintf(stderr, "Max trace paths exceeded, only using first %u\n",
111 (unsigned int) ARRAY_SIZE(selected));
116 * Get path associated with fd.
118 const char *getfdpath(struct tcb *tcp, int fd)
121 static char path[PATH_MAX+1];
128 snprintf(linkpath, sizeof linkpath, "/proc/%d/fd/%d", tcp->pid, fd);
129 n = readlink(linkpath, path, (sizeof path) - 1);
140 * Add a path to the set we're tracing. Also add the canonicalized
141 * version of the path. Secifying NULL will delete all paths.
144 pathtrace_select(const char *path)
149 return storepath(path);
154 rpath = realpath(path, NULL);
159 /* if realpath and specified path are same, we're done */
160 if (!strcmp(path, rpath)) {
165 fprintf(stderr, "Requested path '%s' resolved into '%s'\n",
167 return storepath(rpath);
171 * Return true if syscall accesses a selected path
172 * (or if no paths have been specified for tracing).
175 pathtrace_match(struct tcb *tcp)
177 const struct sysent *s;
179 if (selected[0] == NULL)
182 s = &sysent[tcp->scno];
184 if (!(s->sys_flags & (TRACE_FILE | TRACE_DESC)))
188 * Check for special cases where we need to do something
189 * other than test arg[0].
194 if (s->sys_func == sys_dup2 ||
195 s->sys_func == sys_dup3 ||
196 s->sys_func == sys_sendfile ||
197 s->sys_func == sys_sendfile64 ||
198 !strcmp(s->sys_name, "tee"))
201 return fdmatch(tcp, tcp->u_arg[0]) ||
202 fdmatch(tcp, tcp->u_arg[1]);
205 if (s->sys_func == sys_inotify_add_watch ||
206 s->sys_func == sys_faccessat ||
207 s->sys_func == sys_fchmodat ||
208 s->sys_func == sys_futimesat ||
209 s->sys_func == sys_mkdirat ||
210 s->sys_func == sys_unlinkat ||
211 s->sys_func == sys_newfstatat ||
212 s->sys_func == sys_mknodat ||
213 s->sys_func == sys_openat ||
214 s->sys_func == sys_readlinkat ||
215 s->sys_func == sys_utimensat ||
216 s->sys_func == sys_fchownat ||
217 s->sys_func == sys_pipe2)
220 return fdmatch(tcp, tcp->u_arg[0]) ||
221 upathmatch(tcp, tcp->u_arg[1]);
224 if (s->sys_func == sys_link ||
225 s->sys_func == sys_pivotroot ||
226 s->sys_func == sys_rename ||
227 s->sys_func == sys_symlink ||
228 s->sys_func == sys_mount)
231 return upathmatch(tcp, tcp->u_arg[0]) ||
232 upathmatch(tcp, tcp->u_arg[1]);
235 if (s->sys_func == sys_renameat ||
236 s->sys_func == sys_linkat)
238 /* fd, path, fd, path */
239 return fdmatch(tcp, tcp->u_arg[0]) ||
240 fdmatch(tcp, tcp->u_arg[2]) ||
241 upathmatch(tcp, tcp->u_arg[1]) ||
242 upathmatch(tcp, tcp->u_arg[3]);
245 if (s->sys_func == sys_old_mmap || s->sys_func == sys_mmap) {
247 return fdmatch(tcp, tcp->u_arg[4]);
250 if (s->sys_func == sys_symlinkat) {
252 return fdmatch(tcp, tcp->u_arg[1]) ||
253 upathmatch(tcp, tcp->u_arg[0]) ||
254 upathmatch(tcp, tcp->u_arg[2]);
257 if (!strcmp(s->sys_name, "splice")) {
258 /* fd, x, fd, x, x */
259 return fdmatch(tcp, tcp->u_arg[0]) ||
260 fdmatch(tcp, tcp->u_arg[2]);
263 if (s->sys_func == sys_epoll_ctl) {
265 return fdmatch(tcp, tcp->u_arg[2]);
268 if (s->sys_func == sys_select ||
269 s->sys_func == sys_oldselect ||
270 s->sys_func == sys_pselect6)
273 long *args, oldargs[5];
277 if (s->sys_func == sys_oldselect) {
278 if (umoven(tcp, tcp->u_arg[0], sizeof oldargs,
279 (char*) oldargs) < 0)
281 fprintf(stderr, "umoven() failed\n");
289 fdsize = ((((nfds + 7) / 8) + sizeof(long) - 1)
291 fds = malloc(fdsize);
294 fprintf(stderr, "out of memory\n");
298 for (i = 1; i <= 3; ++i) {
302 if (umoven(tcp, args[i], fdsize, (char *) fds) < 0) {
303 fprintf(stderr, "umoven() failed\n");
307 for (j = 0; j < nfds; ++j)
308 if (FD_ISSET(j, fds) && fdmatch(tcp, j)) {
317 if (s->sys_func == sys_poll ||
318 s->sys_func == sys_ppoll)
322 unsigned long start, cur, end;
324 start = tcp->u_arg[0];
325 nfds = tcp->u_arg[1];
327 end = start + sizeof(fds) * nfds;
329 if (nfds == 0 || end < start)
332 for (cur = start; cur < end; cur += sizeof(fds))
333 if ((umoven(tcp, cur, sizeof fds, (char *) &fds) == 0)
334 && fdmatch(tcp, fds.fd))
340 if (s->sys_func == printargs ||
341 s->sys_func == sys_pipe ||
342 s->sys_func == sys_pipe2 ||
343 s->sys_func == sys_eventfd2 ||
344 s->sys_func == sys_eventfd ||
345 s->sys_func == sys_inotify_init1 ||
346 s->sys_func == sys_timerfd_create ||
347 s->sys_func == sys_timerfd_settime ||
348 s->sys_func == sys_timerfd_gettime ||
349 s->sys_func == sys_epoll_create ||
350 !strcmp(s->sys_name, "fanotify_init"))
353 * These have TRACE_FILE or TRACE_DESCRIPTOR set, but they
354 * don't have any file descriptor or path args to test.
359 #warning "path tracing only using arg[0]"
363 * Our fallback position for calls that haven't already
364 * been handled is to just check arg[0].
367 if (s->sys_flags & TRACE_FILE)
368 return upathmatch(tcp, tcp->u_arg[0]);
370 if (s->sys_flags & TRACE_DESC)
371 return fdmatch(tcp, tcp->u_arg[0]);