/usr/share/doc/bpfcc-tools/examples/doc
NameSizeModeActions
lib/-0755rm
argdist_example.txt230290644editdlrm
bashreadline_example.txt8820644editdlrm
bindsnoop_example.txt45300644editdlrm
biolatency_example.txt240210644editdlrm
biolatpcts_example.txt30400644editdlrm
biopattern_example.txt14060644editdlrm
biosnoop_example.txt35490644editdlrm
biotop_example.txt93260644editdlrm
bitesize_example.txt51000644editdlrm
bpflist_example.txt21790644editdlrm
btrfsdist_example.txt95450644editdlrm
btrfsslower_example.txt68120644editdlrm
cachestat_example.txt40120644editdlrm
cachetop_example.txt39180644editdlrm
capable_example.txt66550644editdlrm
cobjnew_example.txt30440644editdlrm
compactsnoop_example.txt101600644editdlrm
cpudist_example.txt168760644editdlrm
cpuunclaimed_example.txt155680644editdlrm
criticalstat_example.txt49260644editdlrm
cthreads_example.txt21320644editdlrm
dbslower_example.txt39810644editdlrm
dbstat_example.txt66560644editdlrm
dcsnoop_example.txt43710644editdlrm
dcstat_example.txt33430644editdlrm
deadlock_example.txt166430644editdlrm
dirtop_example.txt50970644editdlrm
drsnoop_example.txt51200644editdlrm
execsnoop_example.txt67950644editdlrm
exitsnoop_example.txt63730644editdlrm
ext4dist_example.txt89910644editdlrm
ext4slower_example.txt113350644editdlrm
filegone_example.txt7430644editdlrm
filelife_example.txt20920644editdlrm
fileslower_example.txt57110644editdlrm
filetop_example.txt69680644editdlrm
funccount_example.txt136050644editdlrm
funcinterval_example.txt156460644editdlrm
funclatency_example.txt214850644editdlrm
funcslower_example.txt67860644editdlrm
gethostlatency_example.txt13170644editdlrm
hardirqs_example.txt379360644editdlrm
inject_example.txt68320644editdlrm
javacalls_example.txt40000644editdlrm
javaflow_example.txt60170644editdlrm
javagc_example.txt38670644editdlrm
javaobjnew_example.txt30440644editdlrm
javastat_example.txt30520644editdlrm
javathreads_example.txt21320644editdlrm
killsnoop_example.txt13390644editdlrm
klockstat_example.txt85360644editdlrm
kvmexit_example.txt119090644editdlrm
llcstat_example.txt33150644editdlrm
mdflush_example.txt17800644editdlrm
memleak_example.txt102630644editdlrm
mountsnoop_example.txt14810644editdlrm
mysqld_qslower_example.txt23510644editdlrm
netqtop_example.txt124970644editdlrm
nfsdist_example.txt85080644editdlrm
nfsslower_example.txt78670644editdlrm
nodegc_example.txt38670644editdlrm
nodestat_example.txt30520644editdlrm
offcputime_example.txt196620644editdlrm
offwaketime_example.txt382580644editdlrm
oomkill_example.txt19250644editdlrm
opensnoop_example.txt105730644editdlrm
perlcalls_example.txt40000644editdlrm
perlflow_example.txt60170644editdlrm
perlstat_example.txt30520644editdlrm
phpcalls_example.txt40000644editdlrm
phpflow_example.txt60170644editdlrm
phpstat_example.txt30520644editdlrm
pidpersec_example.txt6770644editdlrm
ppchcalls_example.txt70970644editdlrm
profile_example.txt318260644editdlrm
pythoncalls_example.txt40000644editdlrm
pythonflow_example.txt60170644editdlrm
pythongc_example.txt38670644editdlrm
pythonstat_example.txt30520644editdlrm
rdmaucma_example.txt19830644editdlrm
readahead_example.txt32480644editdlrm
reset-trace_example.txt93650644editdlrm
rubycalls_example.txt40000644editdlrm
rubyflow_example.txt60170644editdlrm
rubygc_example.txt38670644editdlrm
rubyobjnew_example.txt30440644editdlrm
rubystat_example.txt30520644editdlrm
runqlat_example.txt320510644editdlrm
runqlen_example.txt121360644editdlrm
runqslower_example.txt21840644editdlrm
shmsnoop_example.txt27980644editdlrm
slabratetop_example.txt53470644editdlrm
sofdsnoop_example.txt32110644editdlrm
softirqs_example.txt112860644editdlrm
solisten_example.txt23550644editdlrm
sslsniff_example.txt69020644editdlrm
stackcount_example.txt219650644editdlrm
statsnoop_example.txt30910644editdlrm
swapin.txt26320644editdlrm
swapin_example.txt14210644editdlrm
syncsnoop_example.txt3870644editdlrm
syscount_example.txt64190644editdlrm
tclcalls_example.txt40000644editdlrm
tclflow_example.txt60170644editdlrm
tclobjnew_example.txt30440644editdlrm
tclstat_example.txt30520644editdlrm
tcpaccept_example.txt28220644editdlrm
tcpcong_example.txt341060644editdlrm
tcpconnect_example.txt64200644editdlrm
tcpconnlat_example.txt26160644editdlrm
tcpdrop_example.txt20010644editdlrm
tcplife_example.txt69950644editdlrm
tcpretrans_example.txt39380644editdlrm
tcprtt_example.txt100700644editdlrm
tcpstates_example.txt29080644editdlrm
tcpsubnet_example.txt55030644editdlrm
tcpsynbl_example.txt11790644editdlrm
tcptop_example.txt58900644editdlrm
tcptracer_example.txt20290644editdlrm
threadsnoop_example.txt10940644editdlrm
tplist_example.txt45070644editdlrm
trace_example.txt221360644editdlrm
ttysnoop_example.txt33150644editdlrm
vfscount_example.txt22210644editdlrm
vfsstat_example.txt16960644editdlrm
virtiostat_example.txt26780644editdlrm
wakeuptime_example.txt340480644editdlrm
xfsdist_example.txt69280644editdlrm
xfsslower_example.txt70800644editdlrm
zfsdist_example.txt97530644editdlrm
zfsslower_example.txt75510644editdlrm
Edit: /usr/share/doc/bpfcc-tools/examples/doc/lib/uflow_example.txt (6017B)
Demonstrations of uflow. uflow traces method entry and exit events and prints a visual flow graph that shows how methods are entered and exited, similar to a tracing debugger with breakpoints. This can be useful for understanding program flow in high-level languages such as Java, Perl, PHP, Python, Ruby, and Tcl which provide USDT probes for method invocations. For example, trace all Ruby method calls in a specific process: # ./uflow -l ruby 27245 Tracing method calls in ruby process 27245... Ctrl-C to quit. CPU PID TID TIME(us) METHOD 3 27245 27245 4.536 <- IO.gets 3 27245 27245 4.536 <- IRB::StdioInputMethod.gets 3 27245 27245 4.536 -> IRB::Context.verbose? 3 27245 27245 4.536 -> NilClass.nil? 3 27245 27245 4.536 <- NilClass.nil? 3 27245 27245 4.536 -> IO.tty? 3 27245 27245 4.536 <- IO.tty? 3 27245 27245 4.536 -> Kernel.kind_of? 3 27245 27245 4.536 <- Kernel.kind_of? 3 27245 27245 4.536 <- IRB::Context.verbose? 3 27245 27245 4.536 <- IRB::Irb.signal_status 3 27245 27245 4.536 -> String.chars 3 27245 27245 4.536 <- String.chars ^C In the preceding output, indentation indicates the depth of the flow graph, and the <- and -> arrows indicate the direction of the event (exit or entry). Often, the amount of output can be overwhelming. You can filter specific classes or methods. For example, trace only methods from the Thread class: # ./uflow -C java/lang/Thread $(pidof java) Tracing method calls in java process 27722... Ctrl-C to quit. CPU PID TID TIME(us) METHOD 3 27722 27731 3.144 -> java/lang/Thread. 3 27722 27731 3.144 -> java/lang/Thread.init 3 27722 27731 3.144 -> java/lang/Thread.init 3 27722 27731 3.144 -> java/lang/Thread.currentThread 3 27722 27731 3.144 <- java/lang/Thread.currentThread 3 27722 27731 3.144 -> java/lang/Thread.getThreadGroup 3 27722 27731 3.144 <- java/lang/Thread.getThreadGroup 3 27722 27731 3.144 -> java/lang/ThreadGroup.checkAccess 3 27722 27731 3.144 <- java/lang/ThreadGroup.checkAccess 3 27722 27731 3.144 -> java/lang/ThreadGroup.addUnstarted 3 27722 27731 3.144 <- java/lang/ThreadGroup.addUnstarted 3 27722 27731 3.145 -> java/lang/Thread.isDaemon 3 27722 27731 3.145 <- java/lang/Thread.isDaemon 3 27722 27731 3.145 -> java/lang/Thread.getPriority 3 27722 27731 3.145 <- java/lang/Thread.getPriority 3 27722 27731 3.145 -> java/lang/Thread.getContextClassLoader 3 27722 27731 3.145 <- java/lang/Thread.getContextClassLoader 3 27722 27731 3.145 -> java/lang/Thread.setPriority 3 27722 27731 3.145 -> java/lang/Thread.checkAccess 3 27722 27731 3.145 <- java/lang/Thread.checkAccess 3 27722 27731 3.145 -> java/lang/Thread.getThreadGroup 3 27722 27731 3.145 <- java/lang/Thread.getThreadGroup 3 27722 27731 3.145 -> java/lang/ThreadGroup.getMaxPriority 3 27722 27731 3.145 <- java/lang/ThreadGroup.getMaxPriority 3 27722 27731 3.145 -> java/lang/Thread.setPriority0 3 27722 27731 3.145 <- java/lang/Thread.setPriority0 3 27722 27731 3.145 <- java/lang/Thread.setPriority 3 27722 27731 3.145 -> java/lang/Thread.nextThreadID 3 27722 27731 3.145 <- java/lang/Thread.nextThreadID 3 27722 27731 3.145 <- java/lang/Thread.init 3 27722 27731 3.145 <- java/lang/Thread.init 3 27722 27731 3.145 <- java/lang/Thread. 3 27722 27731 3.145 -> java/lang/Thread.start 3 27722 27731 3.145 -> java/lang/ThreadGroup.add 3 27722 27731 3.145 <- java/lang/ThreadGroup.add 3 27722 27731 3.145 -> java/lang/Thread.start0 3 27722 27731 3.145 <- java/lang/Thread.start0 3 27722 27731 3.146 <- java/lang/Thread.start 2 27722 27742 3.146 -> java/lang/Thread.run ^C The reason that the CPU number is printed in the first column is that events from different threads can be reordered when running on different CPUs, and produce non-sensible output. By looking for changes in the CPU column, you can easily see if the events you're following make sense and belong to the same thread running on the same CPU. USAGE message: # ./uflow -h usage: uflow.py [-h] [-l {java,perl,php,python,ruby,tcl}] [-M METHOD] [-C CLAZZ] [-v] pid Trace method execution flow in high-level languages. positional arguments: pid process id to attach to optional arguments: -h, --help show this help message and exit -l {java,perl,php,python,ruby,tcl}, --language {java,perl,php,python,ruby,tcl} language to trace -M METHOD, --method METHOD trace only calls to methods starting with this prefix -C CLAZZ, --class CLAZZ trace only calls to classes starting with this prefix -v, --verbose verbose mode: print the BPF program (for debugging purposes) examples: ./uflow -l java 185 # trace Java method calls in process 185 ./uflow -l ruby 134 # trace Ruby method calls in process 134 ./uflow -M indexOf -l java 185 # trace only 'indexOf'-prefixed methods ./uflow -C '' -l python 180 # trace only REPL-defined methods