trace_syscalls.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680
  1. #include <trace/syscall.h>
  2. #include <trace/events/syscalls.h>
  3. #include <linux/slab.h>
  4. #include <linux/kernel.h>
  5. #include <linux/ftrace.h>
  6. #include <linux/perf_event.h>
  7. #include <asm/syscall.h>
  8. #include "trace_output.h"
  9. #include "trace.h"
  10. static DEFINE_MUTEX(syscall_trace_lock);
  11. static int sys_refcount_enter;
  12. static int sys_refcount_exit;
  13. static DECLARE_BITMAP(enabled_enter_syscalls, NR_syscalls);
  14. static DECLARE_BITMAP(enabled_exit_syscalls, NR_syscalls);
  15. static int syscall_enter_register(struct ftrace_event_call *event,
  16. enum trace_reg type);
  17. static int syscall_exit_register(struct ftrace_event_call *event,
  18. enum trace_reg type);
  19. static int syscall_enter_define_fields(struct ftrace_event_call *call);
  20. static int syscall_exit_define_fields(struct ftrace_event_call *call);
  21. static struct list_head *
  22. syscall_get_enter_fields(struct ftrace_event_call *call)
  23. {
  24. struct syscall_metadata *entry = call->data;
  25. return &entry->enter_fields;
  26. }
  27. struct trace_event_functions enter_syscall_print_funcs = {
  28. .trace = print_syscall_enter,
  29. };
  30. struct trace_event_functions exit_syscall_print_funcs = {
  31. .trace = print_syscall_exit,
  32. };
  33. struct ftrace_event_class event_class_syscall_enter = {
  34. .system = "syscalls",
  35. .reg = syscall_enter_register,
  36. .define_fields = syscall_enter_define_fields,
  37. .get_fields = syscall_get_enter_fields,
  38. .raw_init = init_syscall_trace,
  39. };
  40. struct ftrace_event_class event_class_syscall_exit = {
  41. .system = "syscalls",
  42. .reg = syscall_exit_register,
  43. .define_fields = syscall_exit_define_fields,
  44. .fields = LIST_HEAD_INIT(event_class_syscall_exit.fields),
  45. .raw_init = init_syscall_trace,
  46. };
  47. extern struct syscall_metadata *__start_syscalls_metadata[];
  48. extern struct syscall_metadata *__stop_syscalls_metadata[];
  49. static struct syscall_metadata **syscalls_metadata;
  50. static __init struct syscall_metadata *
  51. find_syscall_meta(unsigned long syscall)
  52. {
  53. struct syscall_metadata **start;
  54. struct syscall_metadata **stop;
  55. char str[KSYM_SYMBOL_LEN];
  56. start = __start_syscalls_metadata;
  57. stop = __stop_syscalls_metadata;
  58. kallsyms_lookup(syscall, NULL, NULL, NULL, str);
  59. for ( ; start < stop; start++) {
  60. /*
  61. * Only compare after the "sys" prefix. Archs that use
  62. * syscall wrappers may have syscalls symbols aliases prefixed
  63. * with "SyS" instead of "sys", leading to an unwanted
  64. * mismatch.
  65. */
  66. if ((*start)->name && !strcmp((*start)->name + 3, str + 3))
  67. return *start;
  68. }
  69. return NULL;
  70. }
  71. static struct syscall_metadata *syscall_nr_to_meta(int nr)
  72. {
  73. if (!syscalls_metadata || nr >= NR_syscalls || nr < 0)
  74. return NULL;
  75. return syscalls_metadata[nr];
  76. }
  77. enum print_line_t
  78. print_syscall_enter(struct trace_iterator *iter, int flags,
  79. struct trace_event *event)
  80. {
  81. struct trace_seq *s = &iter->seq;
  82. struct trace_entry *ent = iter->ent;
  83. struct syscall_trace_enter *trace;
  84. struct syscall_metadata *entry;
  85. int i, ret, syscall;
  86. trace = (typeof(trace))ent;
  87. syscall = trace->nr;
  88. entry = syscall_nr_to_meta(syscall);
  89. if (!entry)
  90. goto end;
  91. if (entry->enter_event->event.type != ent->type) {
  92. WARN_ON_ONCE(1);
  93. goto end;
  94. }
  95. ret = trace_seq_printf(s, "%s(", entry->name);
  96. if (!ret)
  97. return TRACE_TYPE_PARTIAL_LINE;
  98. for (i = 0; i < entry->nb_args; i++) {
  99. /* parameter types */
  100. if (trace_flags & TRACE_ITER_VERBOSE) {
  101. ret = trace_seq_printf(s, "%s ", entry->types[i]);
  102. if (!ret)
  103. return TRACE_TYPE_PARTIAL_LINE;
  104. }
  105. /* parameter values */
  106. ret = trace_seq_printf(s, "%s: %lx%s", entry->args[i],
  107. trace->args[i],
  108. i == entry->nb_args - 1 ? "" : ", ");
  109. if (!ret)
  110. return TRACE_TYPE_PARTIAL_LINE;
  111. }
  112. ret = trace_seq_putc(s, ')');
  113. if (!ret)
  114. return TRACE_TYPE_PARTIAL_LINE;
  115. end:
  116. ret = trace_seq_putc(s, '\n');
  117. if (!ret)
  118. return TRACE_TYPE_PARTIAL_LINE;
  119. return TRACE_TYPE_HANDLED;
  120. }
  121. enum print_line_t
  122. print_syscall_exit(struct trace_iterator *iter, int flags,
  123. struct trace_event *event)
  124. {
  125. struct trace_seq *s = &iter->seq;
  126. struct trace_entry *ent = iter->ent;
  127. struct syscall_trace_exit *trace;
  128. int syscall;
  129. struct syscall_metadata *entry;
  130. int ret;
  131. trace = (typeof(trace))ent;
  132. syscall = trace->nr;
  133. entry = syscall_nr_to_meta(syscall);
  134. if (!entry) {
  135. trace_seq_printf(s, "\n");
  136. return TRACE_TYPE_HANDLED;
  137. }
  138. if (entry->exit_event->event.type != ent->type) {
  139. WARN_ON_ONCE(1);
  140. return TRACE_TYPE_UNHANDLED;
  141. }
  142. ret = trace_seq_printf(s, "%s -> 0x%lx\n", entry->name,
  143. trace->ret);
  144. if (!ret)
  145. return TRACE_TYPE_PARTIAL_LINE;
  146. return TRACE_TYPE_HANDLED;
  147. }
  148. extern char *__bad_type_size(void);
  149. #define SYSCALL_FIELD(type, name) \
  150. sizeof(type) != sizeof(trace.name) ? \
  151. __bad_type_size() : \
  152. #type, #name, offsetof(typeof(trace), name), \
  153. sizeof(trace.name), is_signed_type(type)
  154. static
  155. int __set_enter_print_fmt(struct syscall_metadata *entry, char *buf, int len)
  156. {
  157. int i;
  158. int pos = 0;
  159. /* When len=0, we just calculate the needed length */
  160. #define LEN_OR_ZERO (len ? len - pos : 0)
  161. pos += snprintf(buf + pos, LEN_OR_ZERO, "\"");
  162. for (i = 0; i < entry->nb_args; i++) {
  163. pos += snprintf(buf + pos, LEN_OR_ZERO, "%s: 0x%%0%zulx%s",
  164. entry->args[i], sizeof(unsigned long),
  165. i == entry->nb_args - 1 ? "" : ", ");
  166. }
  167. pos += snprintf(buf + pos, LEN_OR_ZERO, "\"");
  168. for (i = 0; i < entry->nb_args; i++) {
  169. pos += snprintf(buf + pos, LEN_OR_ZERO,
  170. ", ((unsigned long)(REC->%s))", entry->args[i]);
  171. }
  172. #undef LEN_OR_ZERO
  173. /* return the length of print_fmt */
  174. return pos;
  175. }
  176. static int set_syscall_print_fmt(struct ftrace_event_call *call)
  177. {
  178. char *print_fmt;
  179. int len;
  180. struct syscall_metadata *entry = call->data;
  181. if (entry->enter_event != call) {
  182. call->print_fmt = "\"0x%lx\", REC->ret";
  183. return 0;
  184. }
  185. /* First: called with 0 length to calculate the needed length */
  186. len = __set_enter_print_fmt(entry, NULL, 0);
  187. print_fmt = kmalloc(len + 1, GFP_KERNEL);
  188. if (!print_fmt)
  189. return -ENOMEM;
  190. /* Second: actually write the @print_fmt */
  191. __set_enter_print_fmt(entry, print_fmt, len + 1);
  192. call->print_fmt = print_fmt;
  193. return 0;
  194. }
  195. static void free_syscall_print_fmt(struct ftrace_event_call *call)
  196. {
  197. struct syscall_metadata *entry = call->data;
  198. if (entry->enter_event == call)
  199. kfree(call->print_fmt);
  200. }
  201. static int syscall_enter_define_fields(struct ftrace_event_call *call)
  202. {
  203. struct syscall_trace_enter trace;
  204. struct syscall_metadata *meta = call->data;
  205. int ret;
  206. int i;
  207. int offset = offsetof(typeof(trace), args);
  208. ret = trace_define_field(call, SYSCALL_FIELD(int, nr), FILTER_OTHER);
  209. if (ret)
  210. return ret;
  211. for (i = 0; i < meta->nb_args; i++) {
  212. ret = trace_define_field(call, meta->types[i],
  213. meta->args[i], offset,
  214. sizeof(unsigned long), 0,
  215. FILTER_OTHER);
  216. offset += sizeof(unsigned long);
  217. }
  218. return ret;
  219. }
  220. static int syscall_exit_define_fields(struct ftrace_event_call *call)
  221. {
  222. struct syscall_trace_exit trace;
  223. int ret;
  224. ret = trace_define_field(call, SYSCALL_FIELD(int, nr), FILTER_OTHER);
  225. if (ret)
  226. return ret;
  227. ret = trace_define_field(call, SYSCALL_FIELD(long, ret),
  228. FILTER_OTHER);
  229. return ret;
  230. }
  231. void ftrace_syscall_enter(void *ignore, struct pt_regs *regs, long id)
  232. {
  233. struct syscall_trace_enter *entry;
  234. struct syscall_metadata *sys_data;
  235. struct ring_buffer_event *event;
  236. struct ring_buffer *buffer;
  237. int size;
  238. int syscall_nr;
  239. syscall_nr = syscall_get_nr(current, regs);
  240. if (syscall_nr < 0)
  241. return;
  242. if (!test_bit(syscall_nr, enabled_enter_syscalls))
  243. return;
  244. sys_data = syscall_nr_to_meta(syscall_nr);
  245. if (!sys_data)
  246. return;
  247. size = sizeof(*entry) + sizeof(unsigned long) * sys_data->nb_args;
  248. event = trace_current_buffer_lock_reserve(&buffer,
  249. sys_data->enter_event->event.type, size, 0, 0);
  250. if (!event)
  251. return;
  252. entry = ring_buffer_event_data(event);
  253. entry->nr = syscall_nr;
  254. syscall_get_arguments(current, regs, 0, sys_data->nb_args, entry->args);
  255. if (!filter_current_check_discard(buffer, sys_data->enter_event,
  256. entry, event))
  257. trace_current_buffer_unlock_commit(buffer, event, 0, 0);
  258. }
  259. void ftrace_syscall_exit(void *ignore, struct pt_regs *regs, long ret)
  260. {
  261. struct syscall_trace_exit *entry;
  262. struct syscall_metadata *sys_data;
  263. struct ring_buffer_event *event;
  264. struct ring_buffer *buffer;
  265. int syscall_nr;
  266. syscall_nr = syscall_get_nr(current, regs);
  267. if (syscall_nr < 0)
  268. return;
  269. if (!test_bit(syscall_nr, enabled_exit_syscalls))
  270. return;
  271. sys_data = syscall_nr_to_meta(syscall_nr);
  272. if (!sys_data)
  273. return;
  274. event = trace_current_buffer_lock_reserve(&buffer,
  275. sys_data->exit_event->event.type, sizeof(*entry), 0, 0);
  276. if (!event)
  277. return;
  278. entry = ring_buffer_event_data(event);
  279. entry->nr = syscall_nr;
  280. entry->ret = syscall_get_return_value(current, regs);
  281. if (!filter_current_check_discard(buffer, sys_data->exit_event,
  282. entry, event))
  283. trace_current_buffer_unlock_commit(buffer, event, 0, 0);
  284. }
  285. int reg_event_syscall_enter(struct ftrace_event_call *call)
  286. {
  287. int ret = 0;
  288. int num;
  289. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  290. if (WARN_ON_ONCE(num < 0 || num >= NR_syscalls))
  291. return -ENOSYS;
  292. mutex_lock(&syscall_trace_lock);
  293. if (!sys_refcount_enter)
  294. ret = register_trace_sys_enter(ftrace_syscall_enter, NULL);
  295. if (!ret) {
  296. set_bit(num, enabled_enter_syscalls);
  297. sys_refcount_enter++;
  298. }
  299. mutex_unlock(&syscall_trace_lock);
  300. return ret;
  301. }
  302. void unreg_event_syscall_enter(struct ftrace_event_call *call)
  303. {
  304. int num;
  305. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  306. if (WARN_ON_ONCE(num < 0 || num >= NR_syscalls))
  307. return;
  308. mutex_lock(&syscall_trace_lock);
  309. sys_refcount_enter--;
  310. clear_bit(num, enabled_enter_syscalls);
  311. if (!sys_refcount_enter)
  312. unregister_trace_sys_enter(ftrace_syscall_enter, NULL);
  313. mutex_unlock(&syscall_trace_lock);
  314. }
  315. int reg_event_syscall_exit(struct ftrace_event_call *call)
  316. {
  317. int ret = 0;
  318. int num;
  319. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  320. if (WARN_ON_ONCE(num < 0 || num >= NR_syscalls))
  321. return -ENOSYS;
  322. mutex_lock(&syscall_trace_lock);
  323. if (!sys_refcount_exit)
  324. ret = register_trace_sys_exit(ftrace_syscall_exit, NULL);
  325. if (!ret) {
  326. set_bit(num, enabled_exit_syscalls);
  327. sys_refcount_exit++;
  328. }
  329. mutex_unlock(&syscall_trace_lock);
  330. return ret;
  331. }
  332. void unreg_event_syscall_exit(struct ftrace_event_call *call)
  333. {
  334. int num;
  335. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  336. if (WARN_ON_ONCE(num < 0 || num >= NR_syscalls))
  337. return;
  338. mutex_lock(&syscall_trace_lock);
  339. sys_refcount_exit--;
  340. clear_bit(num, enabled_exit_syscalls);
  341. if (!sys_refcount_exit)
  342. unregister_trace_sys_exit(ftrace_syscall_exit, NULL);
  343. mutex_unlock(&syscall_trace_lock);
  344. }
  345. int init_syscall_trace(struct ftrace_event_call *call)
  346. {
  347. int id;
  348. int num;
  349. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  350. if (num < 0 || num >= NR_syscalls) {
  351. pr_debug("syscall %s metadata not mapped, disabling ftrace event\n",
  352. ((struct syscall_metadata *)call->data)->name);
  353. return -ENOSYS;
  354. }
  355. if (set_syscall_print_fmt(call) < 0)
  356. return -ENOMEM;
  357. id = trace_event_raw_init(call);
  358. if (id < 0) {
  359. free_syscall_print_fmt(call);
  360. return id;
  361. }
  362. return id;
  363. }
  364. unsigned long __init __weak arch_syscall_addr(int nr)
  365. {
  366. return (unsigned long)sys_call_table[nr];
  367. }
  368. int __init init_ftrace_syscalls(void)
  369. {
  370. struct syscall_metadata *meta;
  371. unsigned long addr;
  372. int i;
  373. syscalls_metadata = kzalloc(sizeof(*syscalls_metadata) *
  374. NR_syscalls, GFP_KERNEL);
  375. if (!syscalls_metadata) {
  376. WARN_ON(1);
  377. return -ENOMEM;
  378. }
  379. for (i = 0; i < NR_syscalls; i++) {
  380. addr = arch_syscall_addr(i);
  381. meta = find_syscall_meta(addr);
  382. if (!meta)
  383. continue;
  384. meta->syscall_nr = i;
  385. syscalls_metadata[i] = meta;
  386. }
  387. return 0;
  388. }
  389. core_initcall(init_ftrace_syscalls);
  390. #ifdef CONFIG_PERF_EVENTS
  391. static DECLARE_BITMAP(enabled_perf_enter_syscalls, NR_syscalls);
  392. static DECLARE_BITMAP(enabled_perf_exit_syscalls, NR_syscalls);
  393. static int sys_perf_refcount_enter;
  394. static int sys_perf_refcount_exit;
  395. static void perf_syscall_enter(void *ignore, struct pt_regs *regs, long id)
  396. {
  397. struct syscall_metadata *sys_data;
  398. struct syscall_trace_enter *rec;
  399. struct hlist_head *head;
  400. int syscall_nr;
  401. int rctx;
  402. int size;
  403. syscall_nr = syscall_get_nr(current, regs);
  404. if (!test_bit(syscall_nr, enabled_perf_enter_syscalls))
  405. return;
  406. sys_data = syscall_nr_to_meta(syscall_nr);
  407. if (!sys_data)
  408. return;
  409. /* get the size after alignment with the u32 buffer size field */
  410. size = sizeof(unsigned long) * sys_data->nb_args + sizeof(*rec);
  411. size = ALIGN(size + sizeof(u32), sizeof(u64));
  412. size -= sizeof(u32);
  413. if (WARN_ONCE(size > PERF_MAX_TRACE_SIZE,
  414. "perf buffer not large enough"))
  415. return;
  416. rec = (struct syscall_trace_enter *)perf_trace_buf_prepare(size,
  417. sys_data->enter_event->event.type, regs, &rctx);
  418. if (!rec)
  419. return;
  420. rec->nr = syscall_nr;
  421. syscall_get_arguments(current, regs, 0, sys_data->nb_args,
  422. (unsigned long *)&rec->args);
  423. head = this_cpu_ptr(sys_data->enter_event->perf_events);
  424. perf_trace_buf_submit(rec, size, rctx, 0, 1, regs, head);
  425. }
  426. int perf_sysenter_enable(struct ftrace_event_call *call)
  427. {
  428. int ret = 0;
  429. int num;
  430. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  431. mutex_lock(&syscall_trace_lock);
  432. if (!sys_perf_refcount_enter)
  433. ret = register_trace_sys_enter(perf_syscall_enter, NULL);
  434. if (ret) {
  435. pr_info("event trace: Could not activate"
  436. "syscall entry trace point");
  437. } else {
  438. set_bit(num, enabled_perf_enter_syscalls);
  439. sys_perf_refcount_enter++;
  440. }
  441. mutex_unlock(&syscall_trace_lock);
  442. return ret;
  443. }
  444. void perf_sysenter_disable(struct ftrace_event_call *call)
  445. {
  446. int num;
  447. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  448. mutex_lock(&syscall_trace_lock);
  449. sys_perf_refcount_enter--;
  450. clear_bit(num, enabled_perf_enter_syscalls);
  451. if (!sys_perf_refcount_enter)
  452. unregister_trace_sys_enter(perf_syscall_enter, NULL);
  453. mutex_unlock(&syscall_trace_lock);
  454. }
  455. static void perf_syscall_exit(void *ignore, struct pt_regs *regs, long ret)
  456. {
  457. struct syscall_metadata *sys_data;
  458. struct syscall_trace_exit *rec;
  459. struct hlist_head *head;
  460. int syscall_nr;
  461. int rctx;
  462. int size;
  463. syscall_nr = syscall_get_nr(current, regs);
  464. if (!test_bit(syscall_nr, enabled_perf_exit_syscalls))
  465. return;
  466. sys_data = syscall_nr_to_meta(syscall_nr);
  467. if (!sys_data)
  468. return;
  469. /* We can probably do that at build time */
  470. size = ALIGN(sizeof(*rec) + sizeof(u32), sizeof(u64));
  471. size -= sizeof(u32);
  472. /*
  473. * Impossible, but be paranoid with the future
  474. * How to put this check outside runtime?
  475. */
  476. if (WARN_ONCE(size > PERF_MAX_TRACE_SIZE,
  477. "exit event has grown above perf buffer size"))
  478. return;
  479. rec = (struct syscall_trace_exit *)perf_trace_buf_prepare(size,
  480. sys_data->exit_event->event.type, regs, &rctx);
  481. if (!rec)
  482. return;
  483. rec->nr = syscall_nr;
  484. rec->ret = syscall_get_return_value(current, regs);
  485. head = this_cpu_ptr(sys_data->exit_event->perf_events);
  486. perf_trace_buf_submit(rec, size, rctx, 0, 1, regs, head);
  487. }
  488. int perf_sysexit_enable(struct ftrace_event_call *call)
  489. {
  490. int ret = 0;
  491. int num;
  492. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  493. mutex_lock(&syscall_trace_lock);
  494. if (!sys_perf_refcount_exit)
  495. ret = register_trace_sys_exit(perf_syscall_exit, NULL);
  496. if (ret) {
  497. pr_info("event trace: Could not activate"
  498. "syscall exit trace point");
  499. } else {
  500. set_bit(num, enabled_perf_exit_syscalls);
  501. sys_perf_refcount_exit++;
  502. }
  503. mutex_unlock(&syscall_trace_lock);
  504. return ret;
  505. }
  506. void perf_sysexit_disable(struct ftrace_event_call *call)
  507. {
  508. int num;
  509. num = ((struct syscall_metadata *)call->data)->syscall_nr;
  510. mutex_lock(&syscall_trace_lock);
  511. sys_perf_refcount_exit--;
  512. clear_bit(num, enabled_perf_exit_syscalls);
  513. if (!sys_perf_refcount_exit)
  514. unregister_trace_sys_exit(perf_syscall_exit, NULL);
  515. mutex_unlock(&syscall_trace_lock);
  516. }
  517. #endif /* CONFIG_PERF_EVENTS */
  518. static int syscall_enter_register(struct ftrace_event_call *event,
  519. enum trace_reg type)
  520. {
  521. switch (type) {
  522. case TRACE_REG_REGISTER:
  523. return reg_event_syscall_enter(event);
  524. case TRACE_REG_UNREGISTER:
  525. unreg_event_syscall_enter(event);
  526. return 0;
  527. #ifdef CONFIG_PERF_EVENTS
  528. case TRACE_REG_PERF_REGISTER:
  529. return perf_sysenter_enable(event);
  530. case TRACE_REG_PERF_UNREGISTER:
  531. perf_sysenter_disable(event);
  532. return 0;
  533. #endif
  534. }
  535. return 0;
  536. }
  537. static int syscall_exit_register(struct ftrace_event_call *event,
  538. enum trace_reg type)
  539. {
  540. switch (type) {
  541. case TRACE_REG_REGISTER:
  542. return reg_event_syscall_exit(event);
  543. case TRACE_REG_UNREGISTER:
  544. unreg_event_syscall_exit(event);
  545. return 0;
  546. #ifdef CONFIG_PERF_EVENTS
  547. case TRACE_REG_PERF_REGISTER:
  548. return perf_sysexit_enable(event);
  549. case TRACE_REG_PERF_UNREGISTER:
  550. perf_sysexit_disable(event);
  551. return 0;
  552. #endif
  553. }
  554. return 0;
  555. }