linux/samples/bpf/trace_event_kern.c
<<
>>
Prefs
   1/* Copyright (c) 2016 Facebook
   2 *
   3 * This program is free software; you can redistribute it and/or
   4 * modify it under the terms of version 2 of the GNU General Public
   5 * License as published by the Free Software Foundation.
   6 */
   7#include <linux/ptrace.h>
   8#include <linux/version.h>
   9#include <uapi/linux/bpf.h>
  10#include <uapi/linux/bpf_perf_event.h>
  11#include <uapi/linux/perf_event.h>
  12#include <bpf/bpf_helpers.h>
  13#include <bpf/bpf_tracing.h>
  14
  15struct key_t {
  16        char comm[TASK_COMM_LEN];
  17        u32 kernstack;
  18        u32 userstack;
  19};
  20
  21struct {
  22        __uint(type, BPF_MAP_TYPE_HASH);
  23        __type(key, struct key_t);
  24        __type(value, u64);
  25        __uint(max_entries, 10000);
  26} counts SEC(".maps");
  27
  28struct {
  29        __uint(type, BPF_MAP_TYPE_STACK_TRACE);
  30        __uint(key_size, sizeof(u32));
  31        __uint(value_size, PERF_MAX_STACK_DEPTH * sizeof(u64));
  32        __uint(max_entries, 10000);
  33} stackmap SEC(".maps");
  34
  35#define KERN_STACKID_FLAGS (0 | BPF_F_FAST_STACK_CMP)
  36#define USER_STACKID_FLAGS (0 | BPF_F_FAST_STACK_CMP | BPF_F_USER_STACK)
  37
  38SEC("perf_event")
  39int bpf_prog1(struct bpf_perf_event_data *ctx)
  40{
  41        char time_fmt1[] = "Time Enabled: %llu, Time Running: %llu";
  42        char time_fmt2[] = "Get Time Failed, ErrCode: %d";
  43        char addr_fmt[] = "Address recorded on event: %llx";
  44        char fmt[] = "CPU-%d period %lld ip %llx";
  45        u32 cpu = bpf_get_smp_processor_id();
  46        struct bpf_perf_event_value value_buf;
  47        struct key_t key;
  48        u64 *val, one = 1;
  49        int ret;
  50
  51        if (ctx->sample_period < 10000)
  52                /* ignore warmup */
  53                return 0;
  54        bpf_get_current_comm(&key.comm, sizeof(key.comm));
  55        key.kernstack = bpf_get_stackid(ctx, &stackmap, KERN_STACKID_FLAGS);
  56        key.userstack = bpf_get_stackid(ctx, &stackmap, USER_STACKID_FLAGS);
  57        if ((int)key.kernstack < 0 && (int)key.userstack < 0) {
  58                bpf_trace_printk(fmt, sizeof(fmt), cpu, ctx->sample_period,
  59                                 PT_REGS_IP(&ctx->regs));
  60                return 0;
  61        }
  62
  63        ret = bpf_perf_prog_read_value(ctx, (void *)&value_buf, sizeof(struct bpf_perf_event_value));
  64        if (!ret)
  65          bpf_trace_printk(time_fmt1, sizeof(time_fmt1), value_buf.enabled, value_buf.running);
  66        else
  67          bpf_trace_printk(time_fmt2, sizeof(time_fmt2), ret);
  68
  69        if (ctx->addr != 0)
  70          bpf_trace_printk(addr_fmt, sizeof(addr_fmt), ctx->addr);
  71
  72        val = bpf_map_lookup_elem(&counts, &key);
  73        if (val)
  74                (*val)++;
  75        else
  76                bpf_map_update_elem(&counts, &key, &one, BPF_NOEXIST);
  77        return 0;
  78}
  79
  80char _license[] SEC("license") = "GPL";
  81