Server IP : 103.169.32.36 / Your IP : 216.73.217.13 Web Server : Apache System : Linux web.dpmptsp 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64 User : apache ( 48) PHP Version : 5.6.40 Disable Function : NONE MySQL : ON | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : ON | Pkexec : ON Directory : /var/opt/eset/efs/eventd/eset_rtp/ |
Upload File : |
| Current File : /var/opt/eset/efs/eventd/eset_rtp/ertp_handlers.c |
/*
* eset_rtp (ESET Real-time file system protection module)
* Copyright (C) 1992-2023 ESET, spol. s r.o.
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*
* In case of any questions, you can contact us at ESET, spol. s r.o., Einsteinova 24, 851 01 Bratislava, Slovakia.
*/
#undef CONFIG_FTRACE_SYSCALLS
#include "ertp_handlers.h"
#include "ertp_debug.h"
#include "ertp_event_queue.h"
#include "ertp_ftrace_hooks.h"
#include "ertp_logs.h"
#include <linux/cred.h>
#include <linux/delay.h>
#include <linux/fdtable.h>
#include <linux/file.h>
#include <linux/namei.h>
atomic_t ertp_running_syscalls_counter = ATOMIC_INIT(0);
DECLARE_WAIT_QUEUE_HEAD(ertp_syscall_handlers_unregister_wait);
static void ertp_wait_for_running_syscalls(void) {
msleep(500);
atomic_dec(&ertp_running_syscalls_counter);
ertp_pr_log(ERTP_LOG_HOOKS, "waiting for %d caught syscalls",
atomic_read(&ertp_running_syscalls_counter));
wait_event(ertp_syscall_handlers_unregister_wait,
atomic_read(&ertp_running_syscalls_counter) == 0);
msleep(500);
}
int ertp_handlers_init(void) {
int rv;
atomic_inc(&ertp_running_syscalls_counter);
rv = ertp_ftrace_hooks_init();
if (rv != 0) {
return rv;
}
ertp_pr_info("registered syscall handlers");
return 0;
}
void ertp_handlers_deinit(void) {
ertp_ftrace_hooks_deinit();
ertp_wait_for_running_syscalls();
ertp_pr_info("unregistered syscall handlers");
}