2014-07-13 10:37:44 -07:00
|
|
|
#!/bin/bash
|
|
|
|
|
#
|
|
|
|
|
# functrace - trace kernel function calls matching specified wildcards.
|
2014-07-29 11:50:52 -07:00
|
|
|
# Uses Linux ftrace.
|
2014-07-13 10:37:44 -07:00
|
|
|
#
|
2014-07-20 12:20:20 -07:00
|
|
|
# This is a proof of concept using Linux ftrace capabilities on older kernels.
|
2014-07-13 10:37:44 -07:00
|
|
|
#
|
2017-09-04 09:58:50 -04:00
|
|
|
# USAGE: functrace [-hH] [-p PID] [-L TID] [-d secs] funcstring
|
2014-07-13 10:37:44 -07:00
|
|
|
# eg,
|
|
|
|
|
# functrace '*sleep' # trace all functions ending in "sleep"
|
|
|
|
|
#
|
|
|
|
|
# Run "functrace -h" for full usage.
|
|
|
|
|
#
|
|
|
|
|
# The output format is the same as the ftrace function trace format, described
|
|
|
|
|
# in the kernel source under Documentation/trace/ftrace.txt.
|
|
|
|
|
#
|
|
|
|
|
# The "-d duration" mode leaves the trace data in the kernel buffer, and
|
|
|
|
|
# only reads it at the end. If the trace data is large, beware of exhausting
|
|
|
|
|
# buffer space (/sys/kernel/debug/tracing/buffer_size_kb) and losing data.
|
|
|
|
|
#
|
|
|
|
|
# Also beware of feedback loops: tracing tcp* functions over an ssh session,
|
|
|
|
|
# or writing ext4* functions to an ext4 file system. For the former, tcp
|
|
|
|
|
# trace data could be redirected to a file (as in the usage message). For
|
|
|
|
|
# the latter, trace to the screen or a different file system.
|
|
|
|
|
#
|
|
|
|
|
# WARNING: This uses dynamic tracing of kernel functions, and could cause
|
|
|
|
|
# kernel panics or freezes. Test, and know what you are doing, before use.
|
|
|
|
|
#
|
|
|
|
|
# OVERHEADS: This can generate a lot of trace data quickly, depending on the
|
|
|
|
|
# frequency of the traced events. Such data will cause performance overheads.
|
2014-07-14 20:14:59 -07:00
|
|
|
# This also works without buffering by default, printing function events
|
|
|
|
|
# as they happen (uses trace_pipe), context switching and consuming CPU to do
|
|
|
|
|
# so. If needed, you can try the "-d secs" option, which buffers events
|
|
|
|
|
# instead, reducing overhead. If you think the buffer option is losing events,
|
|
|
|
|
# try increasing the buffer size (buffer_size_kb).
|
2014-07-13 10:37:44 -07:00
|
|
|
#
|
|
|
|
|
# From perf-tools: https://github.com/brendangregg/perf-tools
|
|
|
|
|
#
|
|
|
|
|
# COPYRIGHT: Copyright (c) 2014 Brendan Gregg.
|
|
|
|
|
#
|
|
|
|
|
# This program is free software; you can redistribute it and/or
|
|
|
|
|
# modify it under the terms of the GNU General Public License
|
|
|
|
|
# as published by the Free Software Foundation; either version 2
|
|
|
|
|
# of the License, or (at your option) any later version.
|
|
|
|
|
#
|
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
|
#
|
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
|
# along with this program; if not, write to the Free Software Foundation,
|
|
|
|
|
# Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
|
|
|
|
|
#
|
|
|
|
|
# (http://www.gnu.org/copyleft/gpl.html)
|
|
|
|
|
#
|
|
|
|
|
# 12-Jul-2014 Brendan Gregg Created this.
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### default variables
|
2014-07-13 10:37:44 -07:00
|
|
|
tracing=/sys/kernel/debug/tracing
|
2014-07-14 20:14:59 -07:00
|
|
|
flock=/var/tmp/.ftrace-lock
|
2017-09-04 09:58:50 -04:00
|
|
|
opt_duration=0; duration=; opt_pid=0; pid=; opt_tid=0; tid=; pidtext=
|
|
|
|
|
opt_headers=0
|
2014-07-24 16:00:14 -07:00
|
|
|
trap ':' INT QUIT TERM PIPE HUP # sends execution to end tracing section
|
2014-07-13 10:37:44 -07:00
|
|
|
|
|
|
|
|
function usage {
|
|
|
|
|
cat <<-END >&2
|
2017-09-04 09:58:50 -04:00
|
|
|
USAGE: functrace [-hH] [-p PID] [-L TID] [-d secs] funcstring
|
2014-07-14 20:14:59 -07:00
|
|
|
-d seconds # trace duration, and use buffers
|
2014-07-13 10:37:44 -07:00
|
|
|
-h # this usage message
|
2014-07-19 23:55:02 -07:00
|
|
|
-H # include column headers
|
2014-07-14 20:14:59 -07:00
|
|
|
-p PID # trace when this pid is on-CPU
|
2017-09-04 09:58:50 -04:00
|
|
|
-L TID # trace when this thread is on-CPU
|
2014-07-13 10:37:44 -07:00
|
|
|
eg,
|
2014-07-22 01:02:19 -07:00
|
|
|
functrace do_nanosleep # trace the do_nanosleep() function
|
|
|
|
|
functrace '*sleep' # trace functions ending in "sleep"
|
|
|
|
|
functrace -p 198 'vfs*' # trace "vfs*" funcs for PID 198
|
|
|
|
|
functrace 'tcp*' > out # trace all "tcp*" funcs to out file
|
|
|
|
|
functrace -d 1 'tcp*' > out # trace 1 sec, then write out file
|
2014-07-31 15:46:18 -07:00
|
|
|
|
|
|
|
|
See the man page and example file for more info.
|
2014-07-20 00:26:10 -07:00
|
|
|
END
|
2014-07-13 10:37:44 -07:00
|
|
|
exit
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function warn {
|
|
|
|
|
if ! eval "$@"; then
|
2014-07-13 16:33:54 -07:00
|
|
|
echo >&2 "WARNING: command failed \"$@\""
|
2014-07-13 10:37:44 -07:00
|
|
|
fi
|
|
|
|
|
}
|
|
|
|
|
|
2014-07-21 19:28:03 -07:00
|
|
|
function end {
|
|
|
|
|
# disable tracing
|
|
|
|
|
echo 2>/dev/null
|
|
|
|
|
echo "Ending tracing..." 2>/dev/null
|
|
|
|
|
cd $tracing
|
|
|
|
|
warn "echo nop > current_tracer"
|
2017-09-04 09:58:50 -04:00
|
|
|
(( opt_pid || opt_tid )) && warn "echo > set_ftrace_pid"
|
2014-07-21 19:28:03 -07:00
|
|
|
warn "echo > set_ftrace_filter"
|
|
|
|
|
warn "echo > trace"
|
|
|
|
|
(( wroteflock )) && warn "rm $flock"
|
|
|
|
|
}
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
function die {
|
|
|
|
|
echo >&2 "$@"
|
|
|
|
|
exit 1
|
|
|
|
|
}
|
|
|
|
|
|
2014-07-21 19:28:03 -07:00
|
|
|
function edie {
|
|
|
|
|
# die with a quiet end()
|
|
|
|
|
echo >&2 "$@"
|
|
|
|
|
exec >/dev/null 2>&1
|
|
|
|
|
end
|
|
|
|
|
exit 1
|
2014-07-18 00:53:45 -07:00
|
|
|
}
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### process options
|
2017-09-04 09:58:50 -04:00
|
|
|
while getopts d:hHp:L: opt
|
2014-07-13 10:37:44 -07:00
|
|
|
do
|
2014-07-14 20:14:59 -07:00
|
|
|
case $opt in
|
2014-07-13 10:37:44 -07:00
|
|
|
d) opt_duration=1; duration=$OPTARG ;;
|
2014-07-14 20:14:59 -07:00
|
|
|
p) opt_pid=1; pid=$OPTARG ;;
|
2017-09-04 09:58:50 -04:00
|
|
|
L) opt_tid=1; tid=$OPTARG ;;
|
2014-07-19 23:55:02 -07:00
|
|
|
H) opt_headers=1; ;;
|
2014-07-13 10:37:44 -07:00
|
|
|
h|?) usage ;;
|
|
|
|
|
esac
|
|
|
|
|
done
|
|
|
|
|
shift $(( $OPTIND - 1 ))
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### option logic
|
2014-07-13 10:37:44 -07:00
|
|
|
(( $# == 0 )) && usage
|
2017-09-04 09:58:50 -04:00
|
|
|
(( opt_pid && opt_tid )) && edie "ERROR: You can use -p or -L but not both."
|
2014-07-13 10:37:44 -07:00
|
|
|
funcs="$1"
|
2014-07-14 20:14:59 -07:00
|
|
|
(( opt_pid )) && pidtext=" for PID $pid"
|
2017-09-04 09:58:50 -04:00
|
|
|
(( opt_tid )) && pidtext=" for TID $pid"
|
2014-07-13 10:37:44 -07:00
|
|
|
if (( opt_duration )); then
|
2014-07-14 20:14:59 -07:00
|
|
|
echo "Tracing \"$funcs\"$pidtext for $duration seconds..."
|
2014-07-13 10:37:44 -07:00
|
|
|
else
|
2014-07-14 20:14:59 -07:00
|
|
|
echo "Tracing \"$funcs\"$pidtext... Ctrl-C to end."
|
2014-07-13 10:37:44 -07:00
|
|
|
fi
|
|
|
|
|
|
2014-07-21 19:28:03 -07:00
|
|
|
### check permissions
|
|
|
|
|
cd $tracing || die "ERROR: accessing tracing. Root user? Kernel has FTRACE?
|
|
|
|
|
debugfs mounted? (mount -t debugfs debugfs /sys/kernel/debug)"
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### ftrace lock
|
2014-07-14 20:33:39 -07:00
|
|
|
[[ -e $flock ]] && die "ERROR: ftrace may be in use by PID $(cat $flock) $flock"
|
2014-07-14 20:14:59 -07:00
|
|
|
echo $$ > $flock || die "ERROR: unable to write $flock."
|
2014-07-21 19:28:03 -07:00
|
|
|
wroteflock=1
|
2014-07-14 20:14:59 -07:00
|
|
|
|
|
|
|
|
### setup and commence tracing
|
2014-07-13 10:37:44 -07:00
|
|
|
sysctl -q kernel.ftrace_enabled=1 # doesn't set exit status
|
2014-07-14 20:33:39 -07:00
|
|
|
read mode < current_tracer
|
2014-07-21 19:28:03 -07:00
|
|
|
[[ "$mode" != "nop" ]] && edie "ERROR: ftrace active (current_tracer=$mode)"
|
2014-07-14 20:14:59 -07:00
|
|
|
if (( opt_pid )); then
|
2017-09-04 09:58:50 -04:00
|
|
|
echo > set_ftrace_pid
|
|
|
|
|
# ftrace expects kernel pids, which are thread ids
|
|
|
|
|
for tid in /proc/$pid/task/*; do
|
|
|
|
|
if ! echo ${tid##*/} >> set_ftrace_pid; then
|
|
|
|
|
edie "ERROR: setting -p $pid (PID exist?). Exiting."
|
|
|
|
|
fi
|
|
|
|
|
done
|
|
|
|
|
fi
|
|
|
|
|
if (( opt_tid )); then
|
|
|
|
|
if ! echo $tid > set_ftrace_pid; then
|
|
|
|
|
edie "ERROR: setting -L $tid (TID exist?). Exiting."
|
|
|
|
|
fi
|
2014-07-14 20:14:59 -07:00
|
|
|
fi
|
|
|
|
|
if ! echo "$funcs" > set_ftrace_filter; then
|
2014-07-21 19:28:03 -07:00
|
|
|
edie "ERROR: enabling \"$funcs\". Exiting."
|
2014-07-13 10:37:44 -07:00
|
|
|
fi
|
2014-07-14 20:14:59 -07:00
|
|
|
if ! echo function > current_tracer; then
|
2014-07-21 19:28:03 -07:00
|
|
|
edie "ERROR: setting current_tracer to \"function\". Exiting."
|
2014-07-13 10:37:44 -07:00
|
|
|
fi
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### print trace buffer
|
|
|
|
|
warn "echo > trace"
|
2014-07-13 10:37:44 -07:00
|
|
|
if (( opt_duration )); then
|
|
|
|
|
sleep $duration
|
2014-07-19 23:55:02 -07:00
|
|
|
if (( opt_headers )); then
|
|
|
|
|
cat trace
|
|
|
|
|
else
|
|
|
|
|
grep -v '^#' trace
|
|
|
|
|
fi
|
2014-07-13 10:37:44 -07:00
|
|
|
else
|
2014-07-19 23:55:02 -07:00
|
|
|
# trace_pipe lack headers, so fetch them from trace
|
|
|
|
|
(( opt_headers )) && cat trace
|
2014-07-14 20:14:59 -07:00
|
|
|
cat trace_pipe
|
2014-07-13 10:37:44 -07:00
|
|
|
fi
|
|
|
|
|
|
2014-07-14 20:14:59 -07:00
|
|
|
### end tracing
|
2014-07-21 19:28:03 -07:00
|
|
|
end
|