2003-02-05 22:30:00  Muli Ben-Yehuda  <mulix@mulix.org>
	
	FOURTEENTH ALPHA VERSION - syscalltrack-0.82, "Minty Chinchilla" 

2003-02-03 13:32:37  Muli Ben-Yehuda  <mulix@mulix.org>

	Install syscalls.dat in libdir instead of sysconfdir -
	${prefix}/lib/syscalltrack-version instead of
	${prefix}/etc/syscalltrack-version. 

	* Makefile.in: see above. 
	* make.common.in: see above. 
	* tests/release/release.py: fix to work with the new tests
	directory layout. 

2003-02-01 21:06:49  Muli Ben-Yehuda  <mulix@mulix.org>

	Install the kernel modules to /lib/modules/`uname
	-r`/syscalltrack-$(VERSION) and syscalls.dat to
	/usr/local/etc/syscalltrack-$(VERSION)/syscalls.dat-$(KERNEL_VERSION)

	Fix silly bug in encode/decode string and buffer. 

	* Makefile.in: see above. 
	* gtksct/Makefile: small fixes to get it to compile. 
	* gtksct/gtksct.c: (parse_config_file): initialize parselib
	appropriately. 
	* make.common.in: change SYSCALLS_DAT_DIR and rename
	SYSCALLS_DAT_LOCATION to SYSCALLS_DAT_LOCATION_BASE. 
	* module/sct_load.in: MODINSTALLDIR changed to
	.../syscalltrack-$(VERSION) 
	* sct_config/Makefile.in: forgot this one when doing the previous
	"install binaries as name-version" previously. 
	* sct_ctrl_lib/dev_file_impl.c: (dev_file_common): fix the error
	return to return what the caller expects. 
	* sct_parselib/parselib.cpp: find and use the syscalls.dat
	matching this kernel version. 
	* sct_parselib/parselib.h: add include guards. 
	* sct_rules/encode_decode.c: (encode_string), (decode_string),
	(encode_buffer), (decode_buffer), (decode_ptr): fix stupid bug in
	encode/decode string and buffer. 
	* sctrace/Makefile.in: comments should start with '#' in column 1
	* utils/sct_logctrl/Makefile.in: likewise. 
	* utils/sctdbg/Makefile.in: likewise. 
	* utils/sctlog/Makefile.in: likewise. 
	* sctrace/main.cpp: call sct_parselib_init() instead of doing it
	ourselves. 
	* tests/regression/reg.pl: print '$in' instead of $in, for
	clarity. 
	* tests/stress/sct_rules_module_tests.c: dont print dots for
	progress, it can confuse reg.pl. 


2003-02-01 19:41:50  Muli Ben-Yehuda  <mulix@mulix.org>

	Install binaries to ${prefix}/bin/name-version, and make
	${prefix}/bin/name a symlink to name-version. 

	Remove the default config file from sct_config. 

	* make.common.in: export VERSION to the makefiles including us. 
	* sct_config/main.cpp: remove DEFAULT_CONFIG_FILE_NAME
	* sctrace/Makefile.in: install binaries to ${prefix}/bin/name-version.
	* utils/sct_logctrl/Makefile.in: likewise. 
	* utils/sctdbg/Makefile.in: likweise. 
	* utils/sctlog/Makefile.in: likewise. 

2003-02-01 11:51:07  Orna Agmon  <agmon@tx.technion.ac.il>

	reg.pl takes the output of tester and compares it to a previous
	output, stored in .previous. If no such file exists, .previous is
	created from current input.
	If the test is repeatable, then the output is
	compared word for word.
	The output is a report of the number of erred lines and the number
	of erred tests.

	* tests/regression/reg.pl: added

2003-01-31 21:09:07  Muli Ben-Yehuda  <mulix@mulix.org>

	Modify the various scripts to handle the new locations under
	tests/. 

	* tests/Makefile.in:
	* tests/correctness/correctness.pl:
	* tests/correctness/rules.conf:
	* tests/correctness/tests/rules.conf:
	* tests/release/release.py:

2003-01-31 20:57:52  Muli Ben-Yehuda  <mulix@mulix.org>

	Reorganize the tests/ directory. Put each test in its own
	subdirectory. 

2003-01-31 20:11:01  Muli Ben-Yehuda  <mulix@mulix.org>

	More tester cleanups. When printing a test banner, print whether
	it's printable or not. 

	* tests/tester.c: (run_test): see above. 
	* tests/tests.c: make all rules tests repeatable (some of them
	aren't, but it's a good test case for my script). 

2003-01-31 19:50:51  Muli Ben-Yehuda  <mulix@mulix.org>

	Make the initial request membufs bigger, and prepare the tests
	data structure for "repeatable test". 

	* module/rules/ctrl_dev.c: make the initial request membuf size	32K. 
	* sct_ctrl_lib/dev_file_impl.c: (dev_file_common): use a 16k
	initial size. 
	* sct_ctrl_lib/sysctl_impl.c: (sysctl_common): likewise. 
	* tests/get_rules_test.c: (test_get_rules): renamed
	all_syscalls_register_rules ro test_all_syscalls_register_rules
	* tests/sct_rules_module_tests.c:
	(test_all_syscalls_register_rules), (test_all_syscalls_usage):
	likewise. 
	* tests/tester.c: (run_test), (run_subsystem_tests): test->subsys
	is now test->flags, and contains other flags. Use (flags &
	SCT_SUBSYS_BITS) to get the subsys out. 
	* tests/tests.c: (subsystem_as_str), (list_tests): use a macro to
	define the table to avoid extraneous typing ;-) 
	* tests/tests.h: rename subsys to flags, add SCT_TEST_REPEATABLE
	and SCT_TEST_REPEATABLE_BITS. 

2003-01-31 15:53:41  Muli Ben-Yehuda  <mulix@mulix.org>

	Fix a bug in sctrace where if a program had an argument, sctrace
	might not exec it correctly. 

	Fix a couple of buglets in the membufs converston. 

	* sct_config/main.cpp: add '+' to the getopt spec string, so that
	matching will stop on the first non option argument. 
	* sctrace/main.cpp: likewise. 
	* utils/sct_logctrl/sct_logctrl.c: (parse_options): likewise. 
	* sct_ctrl_lib/dev_file_private.c: (build_request): if the membuf
	is NULL, don't try to get its size or data. 
	* sct_rules/rule_engine.c: (do_deserialize_action_node): correct
	deserialization of action attributes. 

2003-01-31 13:33:00  Muli Ben-Yehuda  <mulix@mulix.org>

	Fix a one byte buffer overflow in detecting if the modules are
	loaded or not. Spotted by Mike Shea <mshea@fitch.math.uwaterloo.ca>

	* sct_ctrl_lib.c: (kernel_modules_loaded) rewrite and simplify the
	module detection loop. 

2003-01-30 13:52:34  Muli Ben-Yehuda  <mulix@mulix.org>

	Everything builds with membufs for serialize/deserialize. 

	* module/rules/ctrl_dev.c: (handle_update_packet):
	* module/rules/module_main.c: (tracker_sysctl_from_user):
	* module/rules/update_rules.c: (tracker_build_rule):
	* module/rules/update_rules.h:
	* sct_ctrl_lib/dev_file_impl.c: (dev_file_common):
	* sct_ctrl_lib/dev_file_private.c: (build_request),
	(dev_file_update_kernel):
	* sct_ctrl_lib/dev_file_private.h:
	* sct_ctrl_lib/sysctl_impl.c: (sysctl_common),
	(sysctl_get_all_rules):
	* sct_ctrl_lib/sysctl_private.c: (do_sysctl):
	* sct_ctrl_lib/sysctl_private.h:

2003-01-30 13:17:51  Muli Ben-Yehuda  <mulix@mulix.org>

	sct_rules now passes all of the rules library tests and gives
	identical output to running the tests on HEAD. 

	* sct_rules/encode_decode.c: (do_decode), (decode_string),
	(decode_buffer): small fixes - get_chunk returns size of returned
	chunk on success, not 0. we return 0 on success. 
	* sct_rules/filter_vector.c: (sct_deserialize_filter_node_vector):
	* sct_rules/rule_engine.c: (do_serialize_action_node),
	(do_deserialize_action_node), (sct_serialize_tracking_rule),
	(sct_deserialize_tracking_rule_list): return values mismatch. 
	* tests/sct_rules_tests.c: (test_filter_serialize_deserialize),
	(test_rules_serialize_deserialize), (test_serialize_vectors):
	change to use membufs. 

2003-01-30 00:19:39  Muli Ben-Yehuda  <mulix@mulix.org>

	sct_rules now compiles with all serialization/deserialization done
	via membufs. WIP. 

	* sct_rules/encode_decode.c: (do_encode), (do_decode),
	(decode_float), (encode_string), (decode_string):
	* sct_rules/filter_in_out.c: (sct_print_filter_node_compound),
	(sct_serialize_filter_node_var), (sct_serialize_filter_node_const),
	(sct_deserialize_filter_node_const),
	(sct_serialize_filter_node_compound), (do_serialize_filter_node):
	* sct_rules/filter_vector.c: (sct_print_filter_node_vec),
	(sct_serialize_filter_node_vector),
	(sct_deserialize_filter_node_vector):
	* sct_rules/rule_engine.c: (do_serialize_action_node),
	(do_deserialize_action_node), (sct_serialize_action_node),
	(sct_deserialize_action_node), (sct_serialize_tracking_rule),
	(sct_deserialize_tracking_rule),
	(sct_serialize_tracking_rule_list),
	(sct_deserialize_tracking_rule_list):
	* sct_rules/rule_engine_private.h:

2003-01-29 20:59:09  Muli Ben-Yehuda  <mulix@mulix.org>

	Start converting sct_rules to membuf for
	serialize/deserialize. Work in progress. 

	* sct_rules/encode_decode.c: (do_encode), (do_decode),
	(encode_uchar), (decode_uchar), (encode_char), (decode_char),
	(encode_int), (decode_int), (encode_uint), (decode_uint),
	(encode_long), (decode_long), (encode_ulong), (decode_ulong),
	(encode_long_long), (decode_long_long), (encode_short),
	(decode_short), (encode_ushort), (decode_ushort), (encode_float),
	(decode_float), (encode_string), (decode_string), (encode_buffer),
	(decode_buffer), (encode_ptr), (decode_ptr):
	* sct_rules/encode_decode_public.h:
	* sct_rules/filter_in_out.c: (print_indent),
	(sct_print_filter_node_var), (sct_print_filter_node_const),
	(sct_print_filter_node_compound), (do_print_filter_node),
	(sct_print_filter_node), (sct_serialize_filter_node_var),
	(sct_deserialize_filter_node_var),
	(sct_serialize_filter_node_const):
	* sct_rules/filter_vector.c: (sct_serialize_filter_node_vector),
	(sct_deserialize_filter_node_vector):
	* sct_rules/rule_engine.c: (do_deserialize_action_node):
	* sct_rules/rule_engine_private.h:
	* sct_rules/rule_engine_public.h:

2003-01-29 17:42:56  Muli Ben-Yehuda  <mulix@mulix.org>

	cosmetics: moving away from 'foo_t' for structures to 'struct
	foo', which is the prefered kernel coding style. This patch does
	s/sct_membuf_t/struct sct_membuf/. 

2003-01-28 19:43:13  Muli Ben-Yehuda  <mulix@mulix.org>

	Tiny cleanups to printouts to make sct more user friendly. 

	* module/rules/log_dev.c: (log_ioctl): remove the unconditional
	printk and replace it with a debug printotu. 
	* sct_config/main.cpp: Capitalize error messages properly. 
	* sct_parselib/sstreamwrap.h: Make sure to terminate string
	streams with 'std::ends', aka NULL, to avoid printing of
	garabage. 

2003-01-28 18:48:33  Muli Ben-Yehuda  <mulix@mulix.org>

	Add a test for CWD in log formats. 

	* tests/correctness_test.pl: allow macros such as %%CWD%% in test
	specifications. 
	* tests/correctness_tests/rules.conf: add test2_open.c
	* tests/correctness_tests/test2_open.c: another open test,
	indirectly testing the CWD variable in the log format. 

2003-01-28 15:40:53  Muli Ben-Yehuda  <mulix@mulix.org>

	alloc memory for membufs using vmalloc - patch from Simon Patarin
	<simon.patarin@inria.fr>:

	"Here is another patch that allocates the memory used in membufs
	with vmalloc rather than kmalloc in the linux
	kernel. Documentation says that kmalloc should generally not be
	used for areas larger than a page, and we typically want to
	allocate much more than that. This patch allows for example to
	allocate as much as 2MB for the logging device (whereas kmalloc is
	limited to 132K at most)."

	* sct_rules/arch-freebsd-kernel.h: define vmem_{alloc/free}
	* sct_rules/arch-linux-kernel.h: define vmem_{alloc/free}
	* sct_rules/arch-userspace.h: define vmem_{alloc/free}
	* sct_rules/membuf.c: (sct_membuf_create), (sct_membuf_destroy),
	(sct_membuf_resize): use vmem_{alloc/free}
	
2003-01-28 15:14:02  Muli Ben-Yehuda  <mulix@mulix.org>

	add support for CWD - patch from Simon Patarin
	<simon.patarin@inria.fr>:  

	"Here is a patch (against CVS head) that adds support for '%cwd'
	in logging format and a CWD variable in sct_config. I feel that
	the '%cwd' macro in logging format is really useful since it
	allows to know if 'open("passwd", ...)' relates to '/etc/passwd'
	rather than '/home/joe/tmp/passwd'. The CWD variable is much less
	intersting but I added it for completeness."

	* module/rules/module_main.c: (init_callback_functions): add a
	persistent callback for the CWD variable. 
	* module/rules/var_callbacks.c: (proc_current_callback):
	implement the callback for CWD. 
	* sct_parselib/filter_parser.cpp: CWD support. 
	* sct_parselib/filter_parser.h: likewise. 
	* sct_parselib/param_types.cpp: likewise. 
	* sct_parselib/param_types.h: likewise. 
	* sct_parselib/process_conditional.cpp: likewise. 
	* sct_parselib/tokens_to_types.cpp: likewise. 
	* sct_rules/filter_in_out.c: (sct_get_var_type_as_str): likewise. 
	* sct_rules/logging.c: (tracker_translate_macro): likewise. 
	* sct_rules/rule_engine_public.h: add VT_PROC_CWD. 

2003-01-28 13:48:00  Muli Ben-Yehuda  <mulix@mulix.org>
	
	THIRTEENTH ALPHA VERSION - syscalltrack-0.81, "Cruel Ducky". 

2003-01-27 19:17:00  Muli Ben-Yehuda  <mulix@mulix.org>

	Merge the r_sctrace_follow_forks_bug branch into HEAD. It now
	appears to work correctly and passes all of the tests. 

2003-01-27 19:01:00  Muli Ben-Yehuda  <mulix@mulix.org>

	Revert the param handling functions in filter_vars.c to their
	original state, they were broken. Also, remove assorted debug
	cruft that has served its purpose. 

	* module/common/util.h: add debug_is_set(level), which will return
	true if debug is enabled and we're debugging for this level. 
	* module/rules/module_main.c: (init_callback_functions): remove
	debug printout. 
	* module/rules/var_callbacks.c: (read_ancestors_into_vector),
	(proc_current_callback), (global_retval_callback): remove various
	debug printouts, and add some others. 
	* sct_rules/filter_eval.c: (do_eval_var_node),
	(sct_eval_filter_node_vector): remove debug printouts. 
	* sct_rules/filter_in_out.c: (do_sct_print_filter_node):
	likewise. 
	* sct_rules/filter_vars.c: (get_param), (get_param_field),
	(get_param_attr), (set_param), (set_param_attr),
	(set_param_callback), (set_param_callback2),
	(set_param_field_callback), (free_params_list), (init_vars),
	(reset_all_vars), (get_var): revert all of the parameter function
	cleanups, they were subtly broken. make get_var slightly cleaner. 
	* sct_rules/rule_engine.c: (sct_filter_syscall): remove debug
	printout. 

2003-01-27 16:29:35  Muli Ben-Yehuda  <mulix@mulix.org>

	Add a small test for checking vector serialize/deserialize. 

	* sct_rules/filter_vector.c: (sct_serialize_filter_node_vector),
	(sct_deserialize_filter_node_vector): cleanups. 
	* tests/sct_rules_tests.c: (test_serialize_vectors): the new
	vector serialize/deserialize test. 
	* tests/tests.c: test function added here to tests array. 
	* tests/tests.h: test function declared here. 

2003-01-27 10:12:35  Muli Ben-Yehuda  <mulix@mulix.org>

	Fix a silly mistake in the debug printk that caused crashes when
	evaluating nodes. sctrace -f xemacs doesn't crash now!

	* sct_rules/filter_eval.c: (do_eval_var_node): fix the silliest
	possible mistake a C programmer can make: '=' instead of
	'=='... sigh. 
	* sct_rules/filter_vars.c: (set_var), (get_var): assert that we
	aren't asked to set a NULl var, and slightly better debug
	printouts. 

2003-01-27 08:51:05  Muli Ben-Yehuda  <mulix@mulix.org>

	Make it possible to specify only the prefix of a test for 'tester
	-t test_name', provided the prefix is unique. 

	* tests/tester.c: (run_one_test): find_test now returns the number
	of tests it found with this prefix. Only run a test if the prefix
	is unique. 
	* tests/tests.c: (min), (find_test): return the number of tests
	found. 
	* tests/tests.h: comment find_test return value. 

2003-01-11 12:01:13  Muli Ben-Yehuda  <mulix@mulix.org>

	* sct_rules/filter_eval.c: (eval_param_var_node),
	(do_eval_var_node), (eval_var_node), (do_sct_eval_filter_node):
	a better rewrite, again keeping the same logic. 

2003-01-10 20:43:04  Muli Ben-Yehuda  <mulix@mulix.org>

	* sct_rules/filter_eval.c: (get_regular_var), (get_param_var),
	(sct_eval_filter_node_var): rewrite but keep the same logic. 

2003-01-10 18:58:28  Muli Ben-Yehuda  <mulix@mulix.org>

	* sct_rules/filter_eval.c: (sct_eval_filter_node_var): comment
	before rewrite. 

2002-12-09 23:02:11  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Disallow AFTER rules with FAIL actions in sct_config. 

	* sct_parselib/logger.cpp: make the default log level INFO. 
	* sct_parselib/rule.cpp: disallow AFTER rules with FAIL actions. 
	* sct_rules/filter_type_check.c: (check_in_match): fix a bug,
	in_match is valid where the first param is anything and the second
	is a vector. 
	* sct_rules/filter_vector.c: indentation and cleanups, work in
	progress. 
	* sct_rules/rule_engine.c: (sct_fuzzy_cmp_actions): compare two
	actions, based only on their type. 
	* sct_rules/rule_engine_public.h: add decl. for
	sct_fuzzy_cmp_actions and sct_cmp_actions (not implemented yet). 
	* tests/sct_rules_tests.c: more vector testing, work in progress. 
	* tests/tests.c: likewise. 
	* tests/tests.h: likewise. 

2002-12-08 23:18:38  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Implemenet sys_vfork and sys_bdflush, the two remaining system
	calls. Yip Yip Hooray!

	* module/arch-i386/special_hijack.c: (stub_syscall_vfork): vfork. 
	* module/hijack/special_hijack.c: (stub_bdflush),
	(init_hijack_syscalls): vfork and bdflush. 
	* module/rules/special_tracker.c: (track_before_bdflush),
	(track_before_syscall_vfork), (track_after_syscall_vfork),
	(init_special_syscalls): the tracking functions. 
	* module/rules/update_rules.c: (tracker_del_all_module_rules):
	remove an annoying printks. 
	* module/syscalls.dat: bdflush and vfork. 
	* tests/correctness_tests/rules.conf: add bdflush and vfork test. 
	* tests/correctness_tests/test1_bdflush.c: (main): bdflush test. 
	* tests/correctness_tests/test1_vfork.c: (main): vfork test. 

2002-12-06 16:18:17  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Enable matching on the real 'pointer' arguments in syscalls.dat. 

 	When logging user space structs, log the kernel copy of them
	instead.

	* Makefile.in: some cleanups, more autogeneration dependancies. 
	* module/common/module_interface.h: add DEB_STRUCTS. 
	* module/gen_syscalls.pl: cleanups and see above. 
	* module/rules/module_main.c: (struct_logger_callback): make the
	struct_logger_callback less generic and more understandable, and
	add lots of debug printouts. 
	* module/rules/struct_handling.h: indent. 
	* module/syscalls.dat: enable matching on 'pointer' arguments. 
	* sct_rules/logging.c: (do_logger_callback),
	(tracker_stringify_params): cleanup. 
	* tests/correctness_tests/rules.conf: add tests for matching on
	pointers, for shmat, shmdt, brk, sysctl, sendmsg and mount. 
	* utils/sctdbg/sctdbg.cpp: add support for DEB_STRUCTUS. 

2002-12-06 12:50:02  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Add a warning to the templates that changing them almost always
	requires changing the special syscalls as well. 

	* module/gen_syscalls.pl: ignore lines starting with '$' in the
	template files (don't want to use #...)

2002-12-05 17:55:53  Muli Ben-Yehuda  <mulix@actcom.co.il>

	* TODO: update, divided roughly per release. 

2002-11-30 11:46:16  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Make the userspace tools behave sensibly when the modules aren't
	loaded. sct_ctrl_lib will now fail to initialize, unless the
	modules are already loaded. 

	* sct_config/main.cpp: better error message if we fail to
	initialize sct_ctrl_lib. 
	* sctrace/main.cpp: likewise. 
	* sct_ctrl_lib/dev_file_impl.h: indentation. 
	* sct_ctrl_lib/sct_ctrl_lib.h: indentation. 
	* sct_ctrl_lib/sct_ctrl_lib.c: (kernel_modules_loaded),
	(sct_ctrl_init): see above - fail to initialize unless the modules
	are loaded. 
	* sct_ctrl_lib/sct_ctrl_lib_private.c: (get_user_data):
	indentation. 
	* sct_ctrl_lib/sct_ctrl_lib_private.h: indentation. 
	* utils/sct_logctrl/sct_logctrl.c: (main): if we can't open
	/dev/sct_log, inquire whether the kernel modules are loaded. 

2002-11-30 09:39:39  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Make logctrl well behaved and support '-h' and '--help'. 

	* utils/sct_logctrl/sct_logctrl.c: (usage), (parse_options): add
	'-h' and '--help' options. 

2002-11-29 19:50:22  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Put a band-aid on the 'invalid packet' bug, by increasing the
	temporary buffers. This need to be fixed properly. 

	* module/rules/ctrl_dev.c: (handle_get_packet): increase buffer
	from 16k->32k. 
	* sct_ctrl_lib/dev_file_private.c: (recv_response): likewise. 

2002-11-25 22:50:36  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Misc fixes: fix the gcalc crashed, reenabling shmat and
	msgrcv. Fix memory leaks in the tests, and disable the
	/proc/sct_hijack/syscalls debugging, which was broken. 

	* module/hijack/pidtrace.h: disable the syscall debugging stuff,
	which is broken.
	* module/rules/module_main.c: (sct_sys_ipc), (sct_sys_ipc_after):
	fix shmat (the real cause of the gcalc crashes) and reenable
	msgrcv. 
	* module/syscall_hijack_autogen.c: regen. 
	* module/syscall_tracker_autogen.c: regen. 
	* module/syscalls.dat: see above. 
	* tests/buffer_test.c: (test_void_ptr_buffer): fix memory leaks. 
	* tests/correctness_tests/rules.conf: split the mount and msync
	tests into one file per test. 
	* tests/correctness_tests/test1_mount.c: 
	* tests/correctness_tests/test1_msync.c: 
	* tests/correctness_tests/test2_mount.c: 
	* tests/correctness_tests/test2_msync.c: 
	* tests/logging_test.c: fix memory leaks. 
	* tests/membuf_test.c: fix memory leaks. 
	* tests/rule_engine_test.c: likewise. 
	* tests/struct_test.c: likewise. 
	* tests/release_tests.py: crude hack to not run apptest unless
	specifies. 

2002-11-24 19:24:21  Muli Ben-Yehuda  <mulix@actcom.co.il>

	If the syscalls.dat file was changed, regenerate the autogenerated
	files. 
	
	* Makefile.in: see above. 
	* module/.cvsignore: ignore module/.autogen
	* module/rules/module_main.c: (sct_sys_ipc): fix a buglet, the
	union in semctl is passed by value, not by reference (pointer). 
	* module/syscalls.dat: fix declaration of semctl in regards to the
	union.

2002-11-23 23:40:00  Muli Ben-Yehuda  <mulix@actcom.co.il> 

	Merged Itai's void pointer support work. 

2002-11-23 20:19:00  Muli Ben-Yehuda  <mulix@actcom.co.il> 
	
	TWELFTH ALPHA VERSION - syscalltrack-0.80, "Tanned Otter"

2002-11-23 01:35:35  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Fix buglet in app_test.py and add app_test.py to the release tests
	script. 

	* tests/apptest/app_test.py: flush writes to the rule file and
	make the timeout before checking if gcalc exists configurable
	* tests/release_tests.py: see above. 

2002-11-22 13:23:04  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Fix the 'gcalc crash bug' by disabling the culprit mux functions
	in sys_ipc. Need to fix it better later, but since it has been
	broken since the beginning, just disabling them is enough for now.

	* module/rules/module_main.c: (sct_sys_ipc), (sct_sys_ipc_after):
	disable 'semctl', 'msgrcv' and 'shmat', because the support for
	them is broken. 
	* module/syscalls.dat: likewise. 
	* module/syscall_hijack_autogen.c: regenerate. 
	* module/syscall_tracker_autogen.c: likewise. 
	* tests/apptest/app_test.py: a short test to load 1..num_rules
	rules, one for each syscall, and try to run an application with
	them loaded. If the application crashes or doesn't load, shout the
	name of the culprit syscall. . 
	* tests/apptest/syscalls.list: used for the apptest script. 
	* tests/correctness_test.pl: ignore comments and empty lines in
	rules.conf 
	* tests/correctness_tests/rules.conf: comment out the tests for
	the three disabled ipc mux functions. 

2002-11-01  Amir S.  <amir@boom.org.il>

	Small cleanups and bugfixes.

	* configure.in: export SCT_KERNEL_MAKEFILE_VERS variable
	after setting it.
	* sct_rules/arch-linux-kernel.h: add sct_getpid().
	* sct_rules/arch-userspace.h: add sct_getpid()
	* sct_rules/encode_decode.c: change private functions into static 
	functions
	* sct_rules/filter_eval.c: (buf_pattern_match): likewise
	and fix const handling in buf_pattern_match()
	* sct_rules/filter_in_out.c: change private functions into static 
	functions
	* sct_rules/filter_node_build.c: likewise
	* sct_rules/filter_vars.c: likewise
	* sct_rules/logging.c: (get_logger_callback_index): likewise
	* sct_rules/loguser.c: make use of sct_sem_t 
	instand of struct semaphore
	* sct_rules/membuf.c: (common_add): fix const handling
	* sct_rules/printer.c: add function declartions.
	* sct_rules/rule_engine.c: (find_tracking_rule),
	(do_add_tracking_rule), (do_del_tracking_rule),
	(sct_tracker_perform_action): change private functions into static 
	functions and fix bug where we printed the wrong pid in suspend.
	* sct_rules/rule_engine_private.h: add missing declartion for
	cast_long_long()

2002-09-30 21:28:28  Muli Ben-Yehuda  <mulix@actcom.co.il>

	More documentation updates - this time, the man pages. 

	* Makefile.in: some cleanups, add 'install' and 'uninstall'
	targets for manpages.
	* configure.in: cleanup. 
	* doc/Version-1.0-features: update. 
	* doc/sct_config.1: update. 
	* doc/sct_load.1: update. 
	* doc/sct_logctrl.1: new manpage. 
	* doc/sct_unload.1: update. 
	* doc/sctdbg.1: new manpage. 
	* doc/sctlog.1: new manpage. 
	* doc/sctrace.1: update. 
	* module/Makefile-2.4: cleanup. 
	* module/Makefile.common.in: cleanup. 

2002-09-30 09:29:21  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Massive documentation update. More to come. 

	* AUTHORS: 
	* BUGS:
	* COMPILING:
	* DEVELOPING:
	* README:
	* RUNNING:

2002-09-30 07:00:41  Muli Ben-Yehuda  <mulix@actcom.co.il>

	* Makefile.in: use full path for depmod, in case it does not
	appear in PATH. Patch from Oleg Goldshmidt
	<ogoldshmidt@computer.org>. 

2002-09-27 22:50:39 Gilad Ben-Yossef <gilad@benyossef.com>

	Fixed correctness_test.pl path to module directory 
	to adjust it to new autoconf directory layout.
	
	* tests/correctness_tests.pl

2002-09-28 07:28:39  Muli Ben-Yehuda  <mulix@actcom.co.il>

	* utils/sctlog/sctlog: rewrite in python, to handle the case where
	our args have spaces in them, which got munged in the shell
	version. 

2002-09-22 08:31:44  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Misc. fixes stemming from an attempt to add vm86 and vm86old
	support (the attempt failed, we won't be supporting them for
	now). 

	* module/arch-i386-linux2.2/special_tracker.c:
	(init_arch_special_syscalls): arch tracker functions framework
	(not currently used). 
	* module/arch-i386/special_tracker.c:
	(init_arch_special_syscalls): likewise. 
	* module/arch-uml/special_tracker.c: (init_arch_special_syscalls):
	likewise. 
	* module/gen_syscalls.pl: count not generated system calls. 
	* module/rules/archdep_tracker.h: bring in the correct arch
	special_tracker.c file. 
	* module/rules/module_main.c: include archdep_tracker.h
	* module/rules/special_tracker.c: (init_special_syscalls): call
	init_arch_special_syscalls(). 
	* module/syscalls.dat: comment vm86 and vm86old
	* sct_parselib/syscalls.cpp: better syscall line detection. 
	* tests/Makefile.in: delete 'testdir*' on clean. 

2002-09-20 15:12:57  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Add a -v (verbose) flag to sct_logctrl. 

	* utils/sct_logctrl/sct_logctrl.c: (usage), (parse_options),
	(cmd_to_str), (do_cmd), (main): what it says. 

2002-09-20 14:12:50  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Make printed rules look more like the rule file, and various misc
	cleanups. 

	* module/common/module_interface.h: add DEB_INIT, for debugging
	module initialization and cleanup. 
	* module/hijack/pidtrace.h: remove debug printouts. 
	* module/rules/ctrl_dev.c: (handle_update_packet),
	(req_has_whole_packet): give debug printouts the correct level. 
	* module/rules/module_main.c: (init_module), (cleanup_module):
	likewise. 
	* module/rules/update_rules.c: (tracker_add_rule),
	(tracker_print_all_rules): when printing rules, pass the indent
	level to sct_print_xxx. 
	* module/sct_load.in: print the version when starting up. 
	* sct_config/main.cpp: pretty print the rules, and initialize the
	parselib via sct_parselib_init(). 
	* sct_ctrl_lib/dev_file_impl.c: (dev_file_get_all_rules): remove
	superflous debug message. 
	* sct_ctrl_lib/sysctl_impl.c: (sysctl_get_all_rules): likewise. 
	* sct_parselib/Makefile.in: add parselib.o
	* sct_parselib/rule.cpp: pass the indent level to
	sct_print_filter_node and remove debug printout. 
	* sct_parselib/syscalls.cpp: better error message when parsing the
	syscalls file and add a "syscall_name", to translate id -> name. 
	* sct_parselib/syscalls.h: see above. 
	* sct_rules/filter_in_out.c: (sct_print_filter_node_var),
	(sct_print_filter_node_compound), (sct_print_filter_node): when
	printing filters, do the right thing in regards to indentation. 
	* sct_rules/rule_engine.c: (sct_get_action_as_string): translate
	non printable characters in the log format,
	(sct_print_action_node), (sct_print_tracking_rules): do the right
	thing in regards to idnentation. 
	* sct_rules/rule_engine_private.h: make INDENT_LEVEL 8. 
	* sct_rules/rule_engine_public.h: add 'unsigned int indent' to the
	pritning functions. 
	* tests/release_tests.py: no need to muck around with the log
	device anymore. 
	* tests/rule_engine_test.c: (test_tracking_rule_list),
	(test_long_long): pass the indent. 
	* tests/sct_rules_tests.c: likewise. 
	* utils/sctdbg/sctdbg.cpp: add 'init'. 

2002-09-19 18:50:27  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Rearrange and cleanup the 'syscall invocations' debugging
	code. Make it compile only if SCT_MODULE_DEBUG is defined, and
	make the syscall_pid data structure be allocated on the heap and
	not on 	the stack, to avoid crashes if a program crashes in the
	middle of a system call invocation (instead, we'll just leak some
	memory...). 

	Add system call 174, sys_rt_sigaction. 

	* module/common/module_interface.h: rearrange the DEB_XXX constants. 
	* module/hijack/pidtrace.h: move the 'syscall invocation
	debugging' stuff here, and make it dependant on SCT_MODULE_DEBUG. 
	* module/hijack/syscall_hijack.c: (init_debug), (cleanup_module):
	remove the 'syscall invocation debugging' stuff. 
	* module/hijack/syscall_hijack_private.h: shared definitions. 
	* module/rules/update_rules.c: DEB_MISC is now DEB_RULES. 
	* module/syscall_hijack_autogen.c: regen. 
	* module/syscall_tracker_autogen.c: regen. 
	* module/syscalls.dat: add system call 174, sys_rt_sigaction. 
	* module/templates/syscall_hijack_stub.tmpl.Linux: call the
	pidtrace debugging functions. 
	* sct_rules/filter_eval.c: (filter_node_cmp): remove debug printout. 
	* utils/sctdbg/sctdbg.cpp: update. 

2002-11-19 22:05:55  Itai Segall  <spapuk@t2.technion.ac.il>

        Add a correctness test for matching a void ptr argument to msync.
	
	* tests/correctness_tests/test1_msync.c: (main): see above

2002-11-19 17:47:45  Itai Segall  <spapuk@t2.technion.ac.il>

	Fix a memory leak in test_long_long and test_void_ptr

	* tests/rule_engine_test.c: (test_long_long), (test_void_ptr)

2002-11-18 23:55:10  Itai Segall  <spapuk@t2.technion.ac.il>

	Added a test for comparing two void* nodes.

	* tests/rule_engine_test.c: (test_void_ptr): define test_void_ptr
	* tests/tests.c: add void_ptr test to the list of tests
	* tests/tests.h: declare test_void_ptr

2002-11-05 00:25:03  Itai Segall  <spapuk@t2.technion.ac.il>

	Further support for void pointers - void pointers can now be 
	matched. For now, only msync's first parameter has been made
	a matchable pointer until further testing.
	
	* module/gen_syscalls.pl: add void* data type
	* module/rules/var_callbacks.c: (global_param_callback):
	  handle DT_PTR
	* module/syscall_hijack_autogen.c: regenerated
	* module/syscall_tracker_autogen.c: (track_before_syscall_144),
	(track_after_syscall_144): regenerated
	* module/syscalls.dat: make msync's first parameter matchable 
	  pointer.
	* sct_parselib/syscalls.cpp: few ptr related cleanups, and 
	  allow pointers to be matchable
	* sct_parselib/tokens_to_types.cpp: add "pointer"
	* sct_rules/filter_eval.c: (cast_char_ptr), (filter_node_cmp),
	(sct_eval_filter_node_var): cast numerical values into ptrs, 
	  and allow comparing void* to numerical values

2002-10-22 17:49:52  Itai Segall  <spapuk@t2.technion.ac.il>

	Cast pointers into char* and print pointers using %p.

	* sct_rules/filter_eval.c: (cast_char_ptr), (cast_string),
	(filter_node_cmp): add cast_char_ptr (which currently casts
	only DT_PTRs), and see above
	* sct_rules/filter_in_out.c: (sct_print_filter_node_const)
	* sct_rules/logging.c: (tracker_stringify_var_node)
	* sct_rules/rule_engine_private.h: declare cast_char_ptr.

2002-09-19 00:18:19  Itai Segall  <spapuk@t2.technion.ac.il>

	start supporting matching and logging pointers, no dereferencing yet.

	* sct_rules/encode_decode.c: (encode_ptr), (decode_ptr): added 
	functions for encoding and decoding void*.
	* sct_rules/encode_decode_public.h: declaration of the above.
	* sct_rules/filter_eval.c: (cast_bool), (cast_char), (cast_short),
	(cast_ushort), (cast_int), (cast_uint), (cast_long), (cast_ulong),
	(cast_long_long), (cast_string), (filter_node_cmp),
	(sct_eval_filter_node_const), (eval_op_minus),
	(eval_op_shift_left), (eval_op_shift_right), (eval_op_bit_and),
	(eval_op_bit_or), (eval_op_bit_xor), (eval_op_bit_not): cast and 
	evaluate pointers, only compare operatoins are supported.
	* sct_rules/filter_in_out.c: (sct_print_filter_node_const),
	(sct_serialize_filter_node_const),
	(sct_deserialize_filter_node_const): serialize and deserialize void*
	* sct_rules/filter_node_build.c: (sct_make_ptr_val): build a ptr node
	* sct_rules/filter_type_check.c: (check_math_ops),
	(check_logic_not), (check_bit_not), (check_in_match): only math ops
	allowed on pointers.
	* sct_rules/logging.c: (tracker_stringify_var_node): stringify a 
	pointer
	* sct_rules/rule_engine_private.h: define CONST_PTR
	* sct_rules/rule_engine_public.h: add DT_PTR to the data_types struct.

2002-09-18 20:19:41  Itai Segall  <spapuk@t2.technion.ac.il>

	use CHECK in loguser tests.

	* tests/sct_rules_module_tests.c: (test_loguser): see above

2002-09-18 10:59:38  Muli Ben-Yehuda  <mulix@actcom.co.il>

	fix a buglet where setting the 'max_rec_len' more than once would
	cause sct_logctrl to fail.

	* module/rules/log_dev.c: (log_ioctl): whitespace. 
	* sct_rules/loguser.c: (sct_loguser_set_max_record_len): return 0
	for success instead of the previous value. You can get the
	previous value by calling the getter function. 
	* utils/sct_logctrl/sct_logctrl.c: (usage), (parse_options),
	(translate_special_chars), (main): small cleanups. 
	* utils/sctlog/sctlog: add a "die" function. 

2002-09-18 01:09:27  Itai Segall  <spapuk@t2.technion.ac.il>

	Support different log formats for before and after rules,
	when using log_dev.

	* module/common/module_interface.h: split the ioctl command
	* module/gen_syscalls.pl: add a default of 256 system calls
	* module/rules/log_dev.c: (log_release), (change_log_format),
	(log_ioctl), (create_loguser), (destroy_loguser).
	* module/rules/special_tracker.c: update calls to perform_action()
	to pass RW_BEFORE or RW_AFTER as an argument.
	* module/syscall_hijack_autogen.c: regenerated
	* module/syscall_tracker_autogen.c: regenerated
	* module/templates/syscall_tracker_mux_stub.tmpl.Linux: calls to
	perform_action() pass RW_BEFORE as argument.
	* module/templates/syscall_tracker_mux_stub_after.tmpl.Linux: calls
	to perform_action() pass RW_AFTER as argument.
	* module/templates/syscall_tracker_stub.tmpl.Linux: see above.
	* module/templates/syscall_tracker_stub_after.tmpl.Linux: see above.
	* sct_rules/loguser.c: (sct_loguser_create), (sct_loguser_destroy),
	(sct_loguser_get_log_format), (sct_loguser_change_log_format):
	split log_format into before_log_format and after_log_format.
	* sct_rules/loguser.h
	* sct_rules/rule_engine.c: (do_action_log),
	(sct_tracker_perform_action): both take sct_rule_when_t as an 
	argument.
	* sct_rules/rule_engine_public.h: update perform_action() declaration
	* tests/logging_test.c: (test_logging_cyclic)
	* tests/sct_rules_module_tests.c: (test_loguser): add a test for 
	different before log format and after log format.
	* tests/struct_test.c: (test_struct_syscall):
	* utils/sct_logctrl/sct_logctrl.c: (usage), (parse_options),
	(cmd_to_str), (main): add two new commands: --beforelogformat for
	updating before log format and --afterlogformat for the after one.
	--logformat updates both.

2002-09-15 12:55:59  Muli Ben-Yehuda  <mulix@actcom.co.il>

	This patch adds support for 'max record length' to the device
	file. When logging the parameters for read() or write(), for
	example, the buffers could be very large. This patch allows you to
	set the max record length to something sane, so only the first
	bytes of the buffer are printed, followed by '...'. Set it to 0 to
	disable. It also cleans up a few logging related things. 

	* module/common/module_interface.h: add CTL_IOC_MAX_REC_SIZE. 
	* module/rules/log_dev.c: (log_read), (log_ioctl): change
	lock_loguser to lock_loguser_interruptible, add
	CTL_IOC_MAX_REC_SIZE, make ENABLE_DEV a noop if the device is
	already enabled. 
	* module/rules/logger_helpers.c: (lhf_inet_ntoa), (lhf_ntohs),
	(lhf_ntohl), (logger_helper_mux): pass the 'max_rec_len' parameter
	where necessary. 
	* module/rules/logger_helpers.h: likewise. 
	* module/rules/module_main.c: (struct_logger_callback): likewise. 
	* module/rules/struct_handling.h: likewise. 
	* module/templates/syscall_tracker_struct_log.tmpl.Linux:
	likewise. 
	* module/syscall_hijack_autogen.c: regen. 
	* module/syscall_tracker_autogen.c: regen. 
	* sct_rules/arch-linux-kernel.h: add sct_lock_sem_interruptible. 
	* sct_rules/arch-userspace.h: likewise. 
	* sct_rules/logging.c: (tracker_stringify_string): use the
	'max_rec_len' parameter to decide how much to log. 
	(tracker_stringify_unum), (tracker_stringify_pointer),
	(tracker_stringify_num), (tracker_stringify_num64),
	(tracker_stringify_var_node), (tracker_stringify_var),
	(tracker_stringify_var_indexed), (tracker_stringify_params),
	(sct_tracker_stringify_params): likewise, also factor out common
	code. (tracker_translate_macro): pass the 'max_rec_len' param. 
	(tracker_do_logging): likewise. (sct_get_loguser_head): return the
	loguser head. 
	* sct_rules/loguser.c: (sct_loguser_create),
	(sct_loguser_set_max_record_len),
	(sct_loguser_get_max_record_len): suport for the max_rec_len
	parameter. (lock_loguser_interruptible), (lock_loguser): split
	lock into lock() and lock_interruptible(). 
	* sct_rules/loguser.h: add spaces between lines. 
	* sct_rules/rule_engine.c: (do_action_log),
	(set_action_attributes), (sct_tracker_perform_action): move
	set_action_attributes() and do_action_log() to their own
	functions. 
	* sct_rules/rule_engine_private.h: tracker_do_logging takes a
	loguser parameter, not a membuf. 
	* sct_rules/rule_engine_public.h: max_rec_len stuff. 
	* tests/correctness_test.pl: use the log device by default, not
	syslog. 
	* tests/logging_test.c: (test_logging_cyclic): max_rec_len. 
	* tests/sct_rules_module_tests.c: (test_loguser): dont
	enable/disable the device, it should be enabled by default. 
	* tests/struct_test.c: (sct_log_struct_fields_timeval), 
	(sct_log_struct_fields_timezone), (struct_logger_callback):
	max_rec_len stuff. 
	* utils/sct_logctrl/sct_logctrl.c: (usage), (parse_options),
	(translate_special_chars), (main): add support for max_rec_len,
	translate special characters in the log format to their ascii
	values (\\n -> 10). 
	* utils/sctlog/Makefile.in: add a dummy clean target. 
	* utils/sctlog/sctlog: pass the parameters we're given to
	sct_logctrl. 

2002-09-14 22:03:09  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Minimze SMP races by marking that a system call invocation is in
	effect as soon as possible, and marking that it's done as late as
	possible. 

	* module/arch-i386-linux2.2/special_hijack.c: see above. 
	* module/arch-i386/special_hijack.c: likewise. 
	* module/arch-uml/special_hijack.c: likewise. 
	* module/hijack/special_hijack.c: likewise. 
	* module/hijack/syscall_hijack.c: likewise. 
	* module/syscall_hijack_autogen.c: likewise. 
	* module/templates/syscall_hijack_stub.tmpl.Linux: likewise. 
	* tests/tester.c: (dir_cleanup): fix a buglet - if we fail to
	remove a file, don't retry. 

2002-09-14 16:29:28  Muli Ben-Yehuda  <mulix@actcom.co.il>

	Make the log device and control device the default (for logging
	and communication, respectively). 

	* module/rules/log_dev.c: (init_log_dev_file): use the log device
	by default. 
	* sct_ctrl_lib/sct_ctrl_lib.c: (sct_ctrl_init): make the control
	device the default communication method. 
	* utils/sctlog/Makefile.in: generate the Makefile from here, for
	consistency. 

2002-09-14 09:10:00  Muli Ben-Yehuda  <mulix@actcom.co.il> 

	Merge Itai's multiple log device users work. 
