#include <sys/param.h>
#include <sys/file.h>
#include <sys/systm.h>
#include <sys/buf.h>
#include <sys/capsicum.h>
#include <sys/condvar.h>
#include <sys/conf.h>
#include <sys/fcntl.h>
#include <sys/ioccom.h>
#include <sys/kernel.h>
#include <sys/lock.h>
#include <sys/malloc.h>
#include <sys/module.h>
#include <sys/poll.h>
#include <sys/proc.h>
#include <sys/sx.h>
#include <sys/syscall.h>
#include <sys/sysent.h>
#include <sys/sysproto.h>
#include <sys/uio.h>
#include "filemon.h"
#if defined(COMPAT_FREEBSD32)
#include <compat/freebsd32/freebsd32_syscall.h>
#include <compat/freebsd32/freebsd32_proto.h>
#include <compat/freebsd32/freebsd32_util.h>
#endif
static d_close_t filemon_close;
static d_ioctl_t filemon_ioctl;
static d_open_t filemon_open;
static struct cdevsw filemon_cdevsw = {
.d_version = D_VERSION,
.d_close = filemon_close,
.d_ioctl = filemon_ioctl,
.d_open = filemon_open,
.d_name = "filemon",
};
MALLOC_DECLARE(M_FILEMON);
MALLOC_DEFINE(M_FILEMON, "filemon", "File access monitor");
struct filemon {
struct sx lock;
struct file *fp;
struct ucred *cred;
char fname1[MAXPATHLEN];
char fname2[MAXPATHLEN];
char msgbufr[2*MAXPATHLEN + 100];
int error;
u_int refcnt;
u_int proccnt;
};
static struct cdev *filemon_dev;
static void filemon_output(struct filemon *filemon, char *msg, size_t len);
static __inline struct filemon *
filemon_acquire(struct filemon *filemon)
{
if (filemon != NULL)
refcount_acquire(&filemon->refcnt);
return (filemon);
}
static void
filemon_release(struct filemon *filemon)
{
if (refcount_release(&filemon->refcnt) == 0)
return;
sx_assert(&filemon->lock, SA_UNLOCKED);
if (filemon->cred != NULL)
crfree(filemon->cred);
sx_destroy(&filemon->lock);
free(filemon, M_FILEMON);
}
static struct filemon *
filemon_proc_get(struct proc *p)
{
struct filemon *filemon;
if (p->p_filemon == NULL)
return (NULL);
PROC_LOCK(p);
filemon = filemon_acquire(p->p_filemon);
PROC_UNLOCK(p);
if (filemon == NULL)
return (NULL);
sx_xlock(&filemon->lock);
return (filemon);
}
static void
filemon_proc_drop(struct proc *p)
{
struct filemon *filemon;
KASSERT(p->p_filemon != NULL, ("%s: proc %p NULL p_filemon",
__func__, p));
sx_assert(&p->p_filemon->lock, SA_XLOCKED);
PROC_LOCK(p);
filemon = p->p_filemon;
p->p_filemon = NULL;
--filemon->proccnt;
PROC_UNLOCK(p);
KASSERT(filemon->refcnt > 1, ("%s: proc %p dropping filemon %p "
"with last reference", __func__, p, filemon));
filemon_release(filemon);
}
static __inline void
filemon_drop(struct filemon *filemon)
{
sx_xunlock(&filemon->lock);
filemon_release(filemon);
}
#include "filemon_wrapper.c"
static void
filemon_write_header(struct filemon *filemon)
{
int len;
struct timeval now;
getmicrotime(&now);
len = snprintf(filemon->msgbufr, sizeof(filemon->msgbufr),
"# filemon version %d\n# Target pid %d\n# Start %ju.%06ju\nV %d\n",
FILEMON_VERSION, curproc->p_pid, (uintmax_t)now.tv_sec,
(uintmax_t)now.tv_usec, FILEMON_VERSION);
if (len < sizeof(filemon->msgbufr))
filemon_output(filemon, filemon->msgbufr, len);
}
static void
filemon_untrack_processes(struct filemon *filemon)
{
struct proc *p;
sx_assert(&filemon->lock, SA_XLOCKED);
if (filemon->proccnt == 0)
return;
sx_slock(&allproc_lock);
FOREACH_PROC_IN_SYSTEM(p) {
if (p->p_filemon == filemon)
filemon_proc_drop(p);
}
sx_sunlock(&allproc_lock);
KASSERT(filemon->refcnt > 0, ("%s: filemon %p should have "
"references still.", __func__, filemon));
KASSERT(filemon->proccnt == 0, ("%s: filemon %p should not have "
"attached procs still.", __func__, filemon));
}
static void
filemon_close_log(struct filemon *filemon)
{
struct file *fp;
struct timeval now;
size_t len;
sx_assert(&filemon->lock, SA_XLOCKED);
if (filemon->fp == NULL)
return;
getmicrotime(&now);
len = snprintf(filemon->msgbufr,
sizeof(filemon->msgbufr),
"# Stop %ju.%06ju\n# Bye bye\n",
(uintmax_t)now.tv_sec, (uintmax_t)now.tv_usec);
if (len < sizeof(filemon->msgbufr))
filemon_output(filemon, filemon->msgbufr, len);
fp = filemon->fp;
filemon->fp = NULL;
sx_xunlock(&filemon->lock);
fdrop(fp, curthread);
sx_xlock(&filemon->lock);
}
static void
filemon_dtr(void *data)
{
struct filemon *filemon = data;
if (filemon == NULL)
return;
sx_xlock(&filemon->lock);
filemon_untrack_processes(filemon);
filemon_close_log(filemon);
filemon_drop(filemon);
}
static int
filemon_attach_proc(struct filemon *filemon, struct proc *p)
{
struct filemon *filemon2;
sx_assert(&filemon->lock, SA_XLOCKED);
PROC_LOCK_ASSERT(p, MA_OWNED);
KASSERT((p->p_flag & P_WEXIT) == 0,
("%s: filemon %p attaching to exiting process %p",
__func__, filemon, p));
KASSERT((p->p_flag & P_INEXEC) == 0,
("%s: filemon %p attaching to execing process %p",
__func__, filemon, p));
if (p->p_filemon == filemon)
return (0);
if (p->p_filemon != NULL && p != curproc)
return (EBUSY);
while (p->p_filemon != NULL) {
PROC_UNLOCK(p);
sx_xunlock(&filemon->lock);
while ((filemon2 = filemon_proc_get(p)) != NULL) {
if (p->p_filemon == filemon2)
filemon_proc_drop(p);
filemon_drop(filemon2);
}
sx_xlock(&filemon->lock);
PROC_LOCK(p);
}
KASSERT(p->p_filemon == NULL,
("%s: proc %p didn't detach filemon %p", __func__, p,
p->p_filemon));
p->p_filemon = filemon_acquire(filemon);
++filemon->proccnt;
return (0);
}
static int
filemon_ioctl(struct cdev *dev, u_long cmd, caddr_t data, int flag __unused,
struct thread *td)
{
struct filemon *filemon;
struct file *fp;
struct proc *p;
int error;
if ((error = devfs_get_cdevpriv((void **) &filemon)) != 0)
return (error);
sx_xlock(&filemon->lock);
switch (cmd) {
case FILEMON_SET_FD:
if (filemon->fp != NULL) {
error = EEXIST;
break;
}
error = fget_write(td, *(int *)data, &cap_pwrite_rights, &fp);
if (error == 0) {
if ((fp->f_ops->fo_flags & DFLAG_PASSABLE) == 0) {
fdrop(fp, curthread);
error = EINVAL;
break;
}
filemon->fp = fp;
filemon_write_header(filemon);
}
break;
case FILEMON_SET_PID:
filemon_untrack_processes(filemon);
error = pget(*((pid_t *)data),
PGET_CANDEBUG | PGET_NOTWEXIT | PGET_NOTINEXEC, &p);
if (error == 0) {
KASSERT(p->p_filemon != filemon,
("%s: proc %p didn't untrack filemon %p",
__func__, p, filemon));
error = filemon_attach_proc(filemon, p);
PROC_UNLOCK(p);
}
break;
default:
error = EINVAL;
break;
}
sx_xunlock(&filemon->lock);
return (error);
}
static int
filemon_open(struct cdev *dev, int oflags __unused, int devtype __unused,
struct thread *td)
{
int error;
struct filemon *filemon;
filemon = malloc(sizeof(*filemon), M_FILEMON,
M_WAITOK | M_ZERO);
sx_init(&filemon->lock, "filemon");
refcount_init(&filemon->refcnt, 1);
filemon->cred = crhold(td->td_ucred);
error = devfs_set_cdevpriv(filemon, filemon_dtr);
if (error != 0)
filemon_release(filemon);
return (error);
}
static int
filemon_close(struct cdev *dev __unused, int flag __unused, int fmt __unused,
struct thread *td __unused)
{
struct filemon *filemon;
int error;
if ((error = devfs_get_cdevpriv((void **) &filemon)) != 0)
return (error);
sx_xlock(&filemon->lock);
filemon_close_log(filemon);
error = filemon->error;
sx_xunlock(&filemon->lock);
return (error);
}
static void
filemon_load(void *dummy __unused)
{
filemon_wrapper_install();
filemon_dev = make_dev(&filemon_cdevsw, 0, UID_ROOT, GID_WHEEL, 0666,
"filemon");
}
static int
filemon_unload(void)
{
destroy_dev(filemon_dev);
filemon_wrapper_deinstall();
return (0);
}
static int
filemon_modevent(module_t mod __unused, int type, void *data)
{
int error = 0;
switch (type) {
case MOD_LOAD:
filemon_load(data);
break;
case MOD_UNLOAD:
error = filemon_unload();
break;
case MOD_QUIESCE:
error = EBUSY;
break;
case MOD_SHUTDOWN:
break;
default:
error = EOPNOTSUPP;
break;
}
return (error);
}
DEV_MODULE(filemon, filemon_modevent, NULL);
MODULE_VERSION(filemon, 1);