| 1 | /*	$OpenBSD: ktrace.h,v 1.50 2024/07/27 02:10:26 guenther Exp $	*/ |
| 2 | /*	$NetBSD: ktrace.h,v 1.12 1996/02/04 02:12:29 christos Exp $	*/ |
| 3 | |
| 4 | /* |
| 5 | * Copyright (c) 1988, 1993 |
| 6 | *	The Regents of the University of California. All rights reserved. |
| 7 | * |
| 8 | * Redistribution and use in source and binary forms, with or without |
| 9 | * modification, are permitted provided that the following conditions |
| 10 | * are met: |
| 11 | * 1. Redistributions of source code must retain the above copyright |
| 12 | * notice, this list of conditions and the following disclaimer. |
| 13 | * 2. Redistributions in binary form must reproduce the above copyright |
| 14 | * notice, this list of conditions and the following disclaimer in the |
| 15 | * documentation and/or other materials provided with the distribution. |
| 16 | * 3. Neither the name of the University nor the names of its contributors |
| 17 | * may be used to endorse or promote products derived from this software |
| 18 | * without specific prior written permission. |
| 19 | * |
| 20 | * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND |
| 21 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| 22 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| 23 | * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE |
| 24 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL |
| 25 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS |
| 26 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
| 27 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
| 28 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
| 29 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 30 | * SUCH DAMAGE. |
| 31 | * |
| 32 | *	@(#)ktrace.h	8.1 (Berkeley) 6/2/93 |
| 33 | */ |
| 34 | |
| 35 | #include <sys/uio.h> |
| 36 | #include <sys/syslimits.h> |
| 37 | #include <sys/signal.h> |
| 38 | #include <sys/time.h> |
| 39 | |
| 40 | /* |
| 41 | * operations to ktrace system call (KTROP(op)) |
| 42 | */ |
| 43 | #define KTROP_SET		0	/* set trace points */ |
| 44 | #define KTROP_CLEAR		1	/* clear trace points */ |
| 45 | #define KTROP_CLEARFILE		2	/* stop all tracing to file */ |
| 46 | #define	KTROP(o)		((o)&3)	/* macro to extract operation */ |
| 47 | /* |
| 48 | * flags (ORed in with operation) |
| 49 | */ |
| 50 | #define KTRFLAG_DESCEND		4	/* perform op on all children too */ |
| 51 | |
| 52 | /* |
| 53 | * ktrace record header |
| 54 | */ |
| 55 | struct ktr_header { |
| 56 | 	uint	ktr_type;		/* trace record type */ |
| 57 | 	pid_t	ktr_pid;		/* process id */ |
| 58 | 	pid_t	ktr_tid;		/* thread id */ |
| 59 | 	struct	timespec ktr_time;	/* timestamp */ |
| 60 | 	char	ktr_comm[_MAXCOMLEN];	/* command name, incl NUL */ |
| 61 | 	size_t	ktr_len;		/* length of buf */ |
| 62 | }; |
| 63 | |
| 64 | /* |
| 65 | * ktrace record types |
| 66 | */ |
| 67 | |
| 68 | /* |
| 69 | * KTR_START - start of trace record, one per ktrace(KTROP_SET) syscall |
| 70 | */ |
| 71 | #define KTR_START	0x4b545200	/* "KTR" */ |
| 72 | |
| 73 | /* |
| 74 | * KTR_SYSCALL - system call record |
| 75 | */ |
| 76 | #define KTR_SYSCALL	1 |
| 77 | struct ktr_syscall { |
| 78 | 	int	ktr_code;		/* syscall number */ |
| 79 | 	int	ktr_argsize;		/* size of arguments */ |
| 80 | 	/* |
| 81 | 	 * followed by ktr_argsize/sizeof(register_t) "register_t"s |
| 82 | 	 */ |
| 83 | }; |
| 84 | |
| 85 | /* |
| 86 | * KTR_SYSRET - return from system call record |
| 87 | */ |
| 88 | #define KTR_SYSRET	2 |
| 89 | struct ktr_sysret { |
| 90 | 	int	ktr_code; |
| 91 | 	int	ktr_error; |
| 92 | 	/* |
| 93 | 	 * If ktr_error is zero, then followed by retval: register_t for |
| 94 | 	 * all syscalls except lseek(), which uses long long |
| 95 | 	 */ |
| 96 | }; |
| 97 | |
| 98 | /* |
| 99 | * KTR_NAMEI - namei record |
| 100 | */ |
| 101 | #define KTR_NAMEI	3 |
| 102 | 	/* record contains pathname */ |
| 103 | |
| 104 | /* |
| 105 | * KTR_GENIO - trace generic process i/o |
| 106 | */ |
| 107 | #define KTR_GENIO	4 |
| 108 | struct ktr_genio { |
| 109 | 	int	ktr_fd; |
| 110 | 	enum	uio_rw ktr_rw; |
| 111 | 	/* |
| 112 | 	 * followed by data successfully read/written |
| 113 | 	 */ |
| 114 | }; |
| 115 | |
| 116 | /* |
| 117 | * KTR_PSIG - trace processed signal |
| 118 | */ |
| 119 | #define	KTR_PSIG	5 |
| 120 | struct ktr_psig { |
| 121 | 	int	signo; |
| 122 | 	sig_t	action; |
| 123 | 	int	mask; |
| 124 | 	int	code; |
| 125 | 	siginfo_t si; |
| 126 | }; |
| 127 | |
| 128 | /* |
| 129 | * KTR_STRUCT - misc. structs |
| 130 | */ |
| 131 | #define KTR_STRUCT	8 |
| 132 | 	/* |
| 133 | 	 * record contains null-terminated struct name followed by |
| 134 | 	 * struct contents |
| 135 | 	 */ |
| 136 | struct sockaddr; |
| 137 | struct stat; |
| 138 | |
| 139 | /* |
| 140 | * KTR_USER - user record |
| 141 | */ |
| 142 | #define KTR_USER	9 |
| 143 | #define KTR_USER_MAXIDLEN	20 |
| 144 | #define KTR_USER_MAXLEN		2048	/* maximum length of passed data */ |
| 145 | struct ktr_user { |
| 146 | 	char ktr_id[KTR_USER_MAXIDLEN]; /* string id of caller */ |
| 147 | 	/* |
| 148 | 	 * Followed by ktr_len - sizeof(struct ktr_user) of user data. |
| 149 | 	 */ |
| 150 | }; |
| 151 | |
| 152 | /* |
| 153 | * KTR_EXECARGS and KTR_EXECENV - args and environment records |
| 154 | */ |
| 155 | #define KTR_EXECARGS	10 |
| 156 | #define KTR_EXECENV	11 |
| 157 | |
| 158 | |
| 159 | /* |
| 160 | * KTR_PLEDGE - details of pledge violation |
| 161 | */ |
| 162 | #define	KTR_PLEDGE	12 |
| 163 | struct ktr_pledge { |
| 164 | 	int		error; |
| 165 | 	int		syscall; |
| 166 | 	uint64_t	code; |
| 167 | }; |
| 168 | |
| 169 | /* |
| 170 | * KTR_PINSYSCALL - details of pinsyscall violation |
| 171 | */ |
| 172 | #define	KTR_PINSYSCALL	13 |
| 173 | struct ktr_pinsyscall { |
| 174 | 	int		error; |
| 175 | 	int		syscall; |
| 176 | 	vaddr_t		addr; |
| 177 | }; |
| 178 | |
| 179 | /* |
| 180 | * kernel trace points (in ps_traceflag) |
| 181 | */ |
| 182 | #define KTRFAC_MASK	0x00ffffff |
| 183 | #define KTRFAC_SYSCALL	(1<<KTR_SYSCALL) |
| 184 | #define KTRFAC_SYSRET	(1<<KTR_SYSRET) |
| 185 | #define KTRFAC_NAMEI	(1<<KTR_NAMEI) |
| 186 | #define KTRFAC_GENIO	(1<<KTR_GENIO) |
| 187 | #define	KTRFAC_PSIG	(1<<KTR_PSIG) |
| 188 | #define KTRFAC_STRUCT (1<<KTR_STRUCT) |
| 189 | #define KTRFAC_USER	(1<<KTR_USER) |
| 190 | #define KTRFAC_EXECARGS	(1<<KTR_EXECARGS) |
| 191 | #define KTRFAC_EXECENV	(1<<KTR_EXECENV) |
| 192 | #define	KTRFAC_PLEDGE	(1<<KTR_PLEDGE) |
| 193 | #define	KTRFAC_PINSYSCALL	(1<<KTR_PINSYSCALL) |
| 194 | |
| 195 | /* |
| 196 | * trace flags (also in ps_traceflag) |
| 197 | */ |
| 198 | #define KTRFAC_ROOT	0x80000000U	/* root set this trace */ |
| 199 | #define KTRFAC_INHERIT	0x40000000	/* pass trace flags to children */ |
| 200 | |
| 201 | #ifndef	_KERNEL |
| 202 | |
| 203 | #include <sys/cdefs.h> |
| 204 | |
| 205 | __BEGIN_DECLS |
| 206 | int	ktrace(const char *, int, int, pid_t); |
| 207 | int	utrace(const char *, const void *, size_t); |
| 208 | __END_DECLS |
| 209 | |
| 210 | #else |
| 211 | |
| 212 | /* |
| 213 | * Test for kernel trace point |
| 214 | */ |
| 215 | #define KTRPOINT(p, type)	\ |
| 216 | 	((p)->p_p->ps_traceflag & (1<<(type)) && ((p)->p_flag & P_INKTR) == 0) |
| 217 | |
| 218 | void ktrgenio(struct proc *, int, enum uio_rw, struct iovec *, ssize_t); |
| 219 | void ktrnamei(struct proc *, char *); |
| 220 | void ktrpsig(struct proc *, int, sig_t, int, int, siginfo_t *); |
| 221 | void ktrsyscall(struct proc *, register_t, size_t, register_t []); |
| 222 | void ktrsysret(struct proc *, register_t, int, const register_t [2]); |
| 223 | int ktruser(struct proc *, const char *, const void *, size_t); |
| 224 | void ktrexec(struct proc *, int, const char *, ssize_t); |
| 225 | void ktrpledge(struct proc *, int, uint64_t, int); |
| 226 | void ktrpinsyscall(struct proc *, int, int, vaddr_t); |
| 227 | |
| 228 | void ktrcleartrace(struct process *); |
| 229 | void ktrsettrace(struct process *, int, struct vnode *, struct ucred *); |
| 230 | |
| 231 | void ktrstruct(struct proc *, const char *, const void *, size_t); |
| 232 | |
| 233 | /* please keep these sorted by second argument to ktrstruct() */ |
| 234 | #define ktrabstimespec(p, s) \ |
| 235 | 	ktrstruct(p, "abstimespec", s, sizeof(struct timespec)) |
| 236 | #define ktrabstimeval(p, s) \ |
| 237 | 	ktrstruct(p, "abstimeval", s, sizeof(struct timeval)) |
| 238 | #define ktrcmsghdr(p, s, l) \ |
| 239 | 	ktrstruct(p, "cmsghdr", s, l) |
| 240 | #define ktrfds(p, s, c) \ |
| 241 | 	ktrstruct(p, "fds", s, (c) * sizeof(int)) |
| 242 | #define ktrfdset(p, s, l) \ |
| 243 | 	ktrstruct(p, "fdset", s, l) |
| 244 | #define ktrflock(p, s) \ |
| 245 | 	ktrstruct(p, "flock", s, sizeof(struct flock)) |
| 246 | #define ktriovec(p, s, c) \ |
| 247 | 	ktrstruct(p, "iovec", s, (c) * sizeof(struct iovec)) |
| 248 | #define ktritimerval(p, s) \ |
| 249 | 	ktrstruct(p, "itimerval", s, sizeof(struct itimerval)) |
| 250 | #define ktrevent(p, s, c) \ |
| 251 | 	ktrstruct(p, "kevent", s, (c) * sizeof(struct kevent)) |
| 252 | #define ktrmmsghdr(p, s) \ |
| 253 | 	ktrstruct(p, "mmsghdr", s, sizeof(struct mmsghdr)) |
| 254 | #define ktrmsghdr(p, s) \ |
| 255 | 	ktrstruct(p, "msghdr", s, sizeof(struct msghdr)) |
| 256 | #define ktrpollfd(p, s, c) \ |
| 257 | 	ktrstruct(p, "pollfd", s, (c) * sizeof(struct pollfd)) |
| 258 | #define ktrquota(p, s) \ |
| 259 | 	ktrstruct(p, "quota", s, sizeof(struct dqblk)) |
| 260 | #define ktrreltimespec(p, s) \ |
| 261 | 	ktrstruct(p, "reltimespec", s, sizeof(struct timespec)) |
| 262 | #define ktrreltimeval(p, s) \ |
| 263 | 	ktrstruct(p, "reltimeval", s, sizeof(struct timeval)) |
| 264 | #define ktrrlimit(p, s) \ |
| 265 | 	ktrstruct(p, "rlimit", s, sizeof(struct rlimit)) |
| 266 | #define ktrrusage(p, s) \ |
| 267 | 	ktrstruct(p, "rusage", s, sizeof(struct rusage)) |
| 268 | #define ktrsigaction(p, s) \ |
| 269 | 	ktrstruct(p, "sigaction", s, sizeof(struct sigaction)) |
| 270 | #define ktrsiginfo(p, s) \ |
| 271 | 	ktrstruct(p, "siginfo", s, sizeof(siginfo_t)) |
| 272 | #define ktrsockaddr(p, s, l) \ |
| 273 | 	ktrstruct(p, "sockaddr", s, l) |
| 274 | #define ktrstat(p, s) \ |
| 275 | 	ktrstruct(p, "stat", s, sizeof(struct stat)) |
| 276 | |
| 277 | #endif	/* !_KERNEL */ |