Received: by 2002:a05:7412:d1aa:b0:fc:a2b0:25d7 with SMTP id ba42csp1926832rdb; Wed, 31 Jan 2024 13:31:59 -0800 (PST) X-Google-Smtp-Source: AGHT+IEEjDVARwMdMze5S+2ozDEFEdjK/njKcsWyPyX8TVD+RNBdit8BHDdJzQd7uDGaZO4UjyyF X-Received: by 2002:a05:6a20:2a15:b0:19e:2d02:56c3 with SMTP id e21-20020a056a202a1500b0019e2d0256c3mr2700447pzh.6.1706736718705; Wed, 31 Jan 2024 13:31:58 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1706736718; cv=pass; d=google.com; s=arc-20160816; b=SdlfcBFB+e/3NEJMHcfo7kMCAjptIz5lEYuVULHwFr9AJu6lPcpTfBduOXatYNPMI3 ZBcpA8ojVEYXEQY626KyX9b3oeN+3feBsJE4xBNwjwo8/ZMBYd41pnju7RM/dSfVhfaG 6UhgtkHzximvglFCpXCGlIT6PtRbWaE4SsnMvhD8lTFJRFMGsVKwVNjWL9pIcBVZS42h IfLLJXDhoaJXxcqhQbhtitYebY1aJwsHaqPeehXTF3bUYtWGix+oU5zxZlLRRgc1qJgP YHlbz2OJwzR6w52J+808gEFgj8FZOCYC5e1bBLHr10QWrd5xOIEvSTpKDntAqI2SmmIx s1gw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-disposition:mime-version:list-unsubscribe:list-subscribe :list-id:precedence:message-id:subject:cc:to:from:date :dkim-signature; bh=oftJ6mCASaFoVyuuw6idt8tNMHN7Rv3MoeTBn7MQpzY=; fh=8qQEcNoATpAgMdD74HGD3xvhQSz4yVgaw8v5ycMiWhg=; b=ynh+xdPNPSwlJyA0CV0UtVpMwFedLL+Bd3ZMhHDYdvujqyeXDrR/wL2flOnn45mOhD 4Si3tB21OHKCT06IXYyXD0mnLjTq2c1guQbxe3STMW+6OjME96AbVo2/dsmn3O4hDTE9 hQPmcQvOzBgEhI9EziDunHWMR7+99B2nRewQBafKFs2MxoYZD6cIdcRyBdYnLW86M088 cr/RRM/3fKgUF+hqiViRz5B3dfsCw+A+1h4X2n1irm1jHOPFArl9dLanTPFCPIOvYcw5 o8wEiguGjh5/XrSa2EONWQV10pizW9rQX7b7bmD9reXnvdFDKxGtGZsI/yhrXlSoypuf UW2w==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=lL5GxUM8; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-47172-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-47172-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org X-Forwarded-Encrypted: i=1; AJvYcCWXwaK1+ngXok/kiDHC0ug0l155YrgrMxRtEfSJHv0iSWCqquR3oln92fivlyYXhlbO2uArYOgNxzB8HbYlq57jIRF+Ch1zyM8ul7cs1g== Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [139.178.88.99]) by mx.google.com with ESMTPS id v5-20020a17090a898500b0028fffb2361esi20771pjn.82.2024.01.31.13.31.58 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 31 Jan 2024 13:31:58 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-47172-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) client-ip=139.178.88.99; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=lL5GxUM8; arc=pass (i=1 dkim=pass dkdomain=kernel.org); spf=pass (google.com: domain of linux-kernel+bounces-47172-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-47172-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id 5EBFD28681D for ; Wed, 31 Jan 2024 21:31:58 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id B984039AFB; Wed, 31 Jan 2024 21:30:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="lL5GxUM8" Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AB8763A8CC; Wed, 31 Jan 2024 21:30:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706736604; cv=none; b=aQq/WWrNC+GGsvKChUIbV1w/F52URBQwKCJdEOJ3g7ESCzAFdV5u0RL4onqvNlFcrVLbF3/mDtQ+laSCSc3JyR2QdwW4lAvI0pxq9HPyefU6fzMBZ4gyEBasv6QeTII7ODZ9Bq5rKKZan1rTXaBeIQDaaAkYuvv3ZAVABzxPGjs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1706736604; c=relaxed/simple; bh=FN2JscihD3Za9BUNC92yN8oh07Kc0nONt2xuzIQoyLI=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=jtDcaivAavqXkNbQfZ0aHHtnxziewvfycudYCK6+OvCb4sqIAhsR8IeSJMydIsQITwwjeMj4TLgfUBKJ04GlsTZumKAdOnWH7rc7G6DjmKLh1FN87LR8vlqyXQo3mKs0kP5CF8ZZSoyKGo99M9mAyML5EplJ7x4j6RoOLlgMyF0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=lL5GxUM8; arc=none smtp.client-ip=10.30.226.201 Received: by smtp.kernel.org (Postfix) with ESMTPSA id E19B5C433C7; Wed, 31 Jan 2024 21:30:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1706736604; bh=FN2JscihD3Za9BUNC92yN8oh07Kc0nONt2xuzIQoyLI=; h=Date:From:To:Cc:Subject:From; b=lL5GxUM8vGEs2NHzXiYgPRr9XrRp/the9rww+dnHE/77OQd+8xkegs0xA7gmDeUWu g1N73zju3baMpxXZOgRm9QOmTW0oeeUIjdNTIPg0LtXHjzsPRZOLRo6pC+GcbxrIR3 IwxXJt6MzVKDdjHTI65OjsUKYBYvJSYAit6PjiUyJfG540ZOvmO+av/igkYYG/Zt+s dljcf1c36NWe0+etAIsfrnMEQGphm1jsYEFe8lAmcs40237P9/CU7P/L9ggVv05nlG p7ZWylXbxVsHW2OdLuid3+X0NbUtee9OMp7D/jSrMvxZTJW8qvnA/5boALJlVortwK RUQLpnjc1D8Xg== Received: by quaco.ghostprotocols.net (Postfix, from userid 1000) id 8EC5840441; Wed, 31 Jan 2024 18:30:01 -0300 (-03) Date: Wed, 31 Jan 2024 18:30:01 -0300 From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Adrian Hunter , Ian Rogers , Jiri Olsa , Linux Kernel Mailing List , linux-perf-users@vger.kernel.org Subject: [PATCH 1/1] perf trace: Collect sys_nanosleep first argument Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline That is a 'struct timespec' passed from userspace to the kernel as we can see with a system wide syscall tracing: root@number:~# perf trace -e nanosleep 0.000 (10.102 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 38.924 (10.077 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 100.177 (10.107 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 139.171 (10.063 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 200.603 (10.105 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 239.399 (10.064 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 300.994 (10.096 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 339.584 (10.067 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 401.335 (10.057 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 439.758 (10.166 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 501.814 (10.110 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 539.983 (10.227 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 602.284 (10.199 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 640.208 (10.105 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 702.662 (10.163 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 740.440 (10.107 ms): podman/2195174 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 802.993 (10.159 ms): podman/9150 nanosleep(rqtp: { .tv_sec: 0, .tv_nsec: 10000000 }) = 0 ^Croot@number:~# strace -p 9150 -e nanosleep If we then use the ptrace method to look at that podman process: root@number:~# strace -p 9150 -e nanosleep strace: Process 9150 attached nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 nanosleep({tv_sec=0, tv_nsec=10000000}, NULL) = 0 ^Cstrace: Process 9150 detached root@number:~# With some changes we can get something closer to the strace output, still in system wide mode: root@number:~# perf config trace.show_arg_names=false root@number:~# perf config trace.show_duration=false root@number:~# perf config trace.show_timestamp=false root@number:~# perf config trace.show_zeros=true root@number:~# perf config trace.args_alignment=0 root@number:~# perf trace -e nanosleep --max-events=10 podman/2195174 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/9150 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/2195174 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/9150 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/2195174 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/9150 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/2195174 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/9150 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/2195174 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 podman/9150 nanosleep({ .tv_sec: 0, .tv_nsec: 10000000 }, NULL) = 0 root@number:~# root@number:~# perf config trace.show_arg_names=false trace.show_duration=false trace.show_timestamp=false trace.show_zeros=true trace.args_alignment=0 root@number:~# cat ~/.perfconfig # this file is auto-generated. [trace] show_arg_names = false show_duration = false show_timestamp = false show_zeros = true args_alignment = 0 root@number:~# This will not get reused by any other syscall as nanosleep is the only one to have as its first argument a 'struct timespec" pointer argument passed from userspace to the kernel: root@number:~# grep timespec /sys/kernel/tracing/events/syscalls/sys_enter_*/format | grep offset:16 /sys/kernel/tracing/events/syscalls/sys_enter_nanosleep/format: field:struct __kernel_timespec * rqtp; offset:16; size:8; signed:0; root@number:~# BTF based pretty printing will simplify all this, but then lets just get the low hanging fruits first. Cc: Adrian Hunter Cc: Ian Rogers Cc: Jiri Olsa Cc: Namhyung Kim Link: https://lore.kernel.org/lkml/ Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/builtin-trace.c | 2 ++ .../bpf_skel/augmented_raw_syscalls.bpf.c | 21 +++++++++++++++++++ 2 files changed, 23 insertions(+) diff --git a/tools/perf/builtin-trace.c b/tools/perf/builtin-trace.c index 109b8e64fe69ae32..6abe280dc38f1921 100644 --- a/tools/perf/builtin-trace.c +++ b/tools/perf/builtin-trace.c @@ -1048,6 +1048,8 @@ static const struct syscall_fmt syscall_fmts[] = { .arg = { [3] = { .scnprintf = SCA_MREMAP_FLAGS, /* flags */ }, }, }, { .name = "name_to_handle_at", .arg = { [0] = { .scnprintf = SCA_FDAT, /* dfd */ }, }, }, + { .name = "nanosleep", + .arg = { [0] = { .scnprintf = SCA_TIMESPEC, /* req */ }, }, }, { .name = "newfstatat", .arg = { [0] = { .scnprintf = SCA_FDAT, /* dfd */ }, }, }, { .name = "open", diff --git a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c index 52c270330ae0d2f3..baecffbece14fb68 100644 --- a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c +++ b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c @@ -354,6 +354,27 @@ int sys_enter_clock_nanosleep(struct syscall_enter_args *args) return 1; /* Failure: don't filter */ } +SEC("tp/syscalls/sys_enter_nanosleep") +int sys_enter_nanosleep(struct syscall_enter_args *args) +{ + struct augmented_args_payload *augmented_args = augmented_args_payload(); + const void *req_arg = (const void *)args->args[0]; + unsigned int len = sizeof(augmented_args->args); + __u32 size = sizeof(struct timespec64); + + if (augmented_args == NULL) + goto failure; + + if (size > sizeof(augmented_args->__data)) + goto failure; + + bpf_probe_read_user(&augmented_args->__data, size, req_arg); + + return augmented__output(args, augmented_args, len + size); +failure: + return 1; /* Failure: don't filter */ +} + static pid_t getpid(void) { return bpf_get_current_pid_tgid(); -- 2.43.0