/
usr
/
sbin
/
/usr/sbin
mkdir
upload
Name
Size
Mode
Actions
aa-load
39680
0755
edit
dl
rm
aa-remove-unknown
3225
0755
edit
dl
rm
aa-status
40000
0755
edit
dl
rm
aa-teardown
137
0755
edit
dl
rm
accessdb
14904
0755
edit
dl
rm
acpid
53920
0755
edit
dl
rm
add-shell
1053
0755
edit
dl
rm
addgnupghome
3075
0755
edit
dl
rm
addgroup
55191
0755
edit
dl
rm
adduser
55191
0755
edit
dl
rm
agetty
60992
0755
edit
dl
rm
apparmor_parser
1629848
0755
edit
dl
rm
apparmor_status
40000
0755
edit
dl
rm
applygnupgdefaults
2217
0755
edit
dl
rm
argdist-bpfcc
36862
0755
edit
dl
rm
arpd
26960
0755
edit
dl
rm
arptables
224424
0755
edit
dl
rm
arptables-nft
224424
0755
edit
dl
rm
arptables-nft-restore
224424
0755
edit
dl
rm
arptables-nft-save
224424
0755
edit
dl
rm
arptables-restore
224424
0755
edit
dl
rm
arptables-save
224424
0755
edit
dl
rm
badblocks
35144
0755
edit
dl
rm
bashreadline-bpfcc
2380
0755
edit
dl
rm
bashreadline.bt
698
0755
edit
dl
rm
bcache-super-show
14648
0755
edit
dl
rm
bindsnoop-bpfcc
16346
0755
edit
dl
rm
biolatency-bpfcc
11365
0755
edit
dl
rm
biolatency-kp.bt
664
0755
edit
dl
rm
biolatency.bt
681
0755
edit
dl
rm
biolatpcts-bpfcc
10248
0755
edit
dl
rm
biopattern-bpfcc
3957
0755
edit
dl
rm
biosdecode
27856
0755
edit
dl
rm
biosnoop-bpfcc
10833
0755
edit
dl
rm
biosnoop.bt
1148
0755
edit
dl
rm
biostacks.bt
915
0755
edit
dl
rm
biotop-bpfcc
9567
0755
edit
dl
rm
bitesize-bpfcc
1166
0755
edit
dl
rm
bitesize.bt
567
0755
edit
dl
rm
blkdeactivate
16351
0755
edit
dl
rm
blkdiscard
22912
0755
edit
dl
rm
blkid
55720
0755
edit
dl
rm
blkzone
35200
0755
edit
dl
rm
blockdev
35200
0755
edit
dl
rm
bpflist-bpfcc
2601
0755
edit
dl
rm
bpftool
1622
0755
edit
dl
rm
bridge
111096
0755
edit
dl
rm
btrfsdist-bpfcc
6627
0755
edit
dl
rm
btrfsslower-bpfcc
9985
0755
edit
dl
rm
cachestat-bpfcc
6531
0755
edit
dl
rm
cachetop-bpfcc
9367
0755
edit
dl
rm
cache_check
1430568
0755
edit
dl
rm
cache_dump
1430568
0755
edit
dl
rm
cache_metadata_size
1430568
0755
edit
dl
rm
cache_repair
1430568
0755
edit
dl
rm
cache_restore
1430568
0755
edit
dl
rm
cache_writeback
1430568
0755
edit
dl
rm
capable-bpfcc
8477
0755
edit
dl
rm
capable.bt
1926
0755
edit
dl
rm
capsh
58456
0755
edit
dl
rm
cfdisk
97008
0755
edit
dl
rm
cgdisk
170480
0755
edit
dl
rm
chcpu
31104
0755
edit
dl
rm
chgpasswd
59720
0755
edit
dl
rm
chmem
35200
0755
edit
dl
rm
chpasswd
55736
0755
edit
dl
rm
chronyd
306232
0755
edit
dl
rm
chroot
39432
0755
edit
dl
rm
cobjnew-bpfcc
53
0755
edit
dl
rm
compactsnoop-bpfcc
11369
0755
edit
dl
rm
cpgr
49608
0755
edit
dl
rm
cppw
49608
0755
edit
dl
rm
cpudist-bpfcc
7013
0755
edit
dl
rm
cpuunclaimed-bpfcc
14938
0755
edit
dl
rm
cpuwalk.bt
497
0755
edit
dl
rm
criticalstat-bpfcc
8607
0755
edit
dl
rm
cron
60080
0755
edit
dl
rm
cryptdisks_start
1544
0755
edit
dl
rm
cryptdisks_stop
844
0755
edit
dl
rm
cryptsetup
231320
0755
edit
dl
rm
ctrlaltdel
14720
0755
edit
dl
rm
dbslower-bpfcc
7391
0755
edit
dl
rm
dbstat-bpfcc
3790
0755
edit
dl
rm
dcb
82448
0755
edit
dl
rm
dcsnoop-bpfcc
4126
0755
edit
dl
rm
dcsnoop.bt
1261
0755
edit
dl
rm
dcstat-bpfcc
3859
0755
edit
dl
rm
deadlock-bpfcc
20943
0755
edit
dl
rm
debugfs
231288
0755
edit
dl
rm
delgroup
18977
0755
edit
dl
rm
deluser
18977
0755
edit
dl
rm
depmod
174328
0755
edit
dl
rm
devlink
154480
0755
edit
dl
rm
dhcpcd
404888
0755
edit
dl
rm
dirtop-bpfcc
8568
0755
edit
dl
rm
dmeventd
51592
0755
edit
dl
rm
dmidecode
138496
0755
edit
dl
rm
dmsetup
175160
0755
edit
dl
rm
dmstats
175160
0755
edit
dl
rm
dosfsck
80264
0755
edit
dl
rm
dosfslabel
39304
0755
edit
dl
rm
dpkg-preconfigure
4356
0755
edit
dl
rm
dpkg-reconfigure
4536
0755
edit
dl
rm
drsnoop-bpfcc
6889
0755
edit
dl
rm
dumpe2fs
35136
0755
edit
dl
rm
e2freefrag
18744
0755
edit
dl
rm
e2fsck
373080
0755
edit
dl
rm
e2image
43328
0755
edit
dl
rm
e2label
113216
0755
edit
dl
rm
e2mmpstatus
35136
0755
edit
dl
rm
e2scrub
7294
0755
edit
dl
rm
e2scrub_all
5394
0755
edit
dl
rm
e2undo
22840
0755
edit
dl
rm
e4crypt
31104
0755
edit
dl
rm
e4defrag
35128
0755
edit
dl
rm
ebtables
224424
0755
edit
dl
rm
ebtables-nft
224424
0755
edit
dl
rm
ebtables-nft-restore
224424
0755
edit
dl
rm
ebtables-nft-save
224424
0755
edit
dl
rm
ebtables-restore
224424
0755
edit
dl
rm
ebtables-save
224424
0755
edit
dl
rm
ebtables-translate
224424
0755
edit
dl
rm
era_check
1430568
0755
edit
dl
rm
era_dump
1430568
0755
edit
dl
rm
era_invalidate
1430568
0755
edit
dl
rm
era_restore
1430568
0755
edit
dl
rm
ethtool
667320
0755
edit
dl
rm
execsnoop-bpfcc
10059
0755
edit
dl
rm
execsnoop.bt
928
0755
edit
dl
rm
exitsnoop-bpfcc
9646
0755
edit
dl
rm
ext4dist-bpfcc
6683
0755
edit
dl
rm
ext4slower-bpfcc
9948
0755
edit
dl
rm
faillock
22848
0755
edit
dl
rm
fatlabel
39304
0755
edit
dl
rm
fdisk
117168
0755
edit
dl
rm
filefrag
18760
0755
edit
dl
rm
filegone-bpfcc
5776
0755
edit
dl
rm
filelife-bpfcc
6528
0755
edit
dl
rm
fileslower-bpfcc
7372
0755
edit
dl
rm
filetop-bpfcc
6499
0755
edit
dl
rm
findfs
14720
0755
edit
dl
rm
fixparts
59880
0755
edit
dl
rm
fsadm
24580
0755
edit
dl
rm
fsck
43440
0755
edit
dl
rm
fsck.btrfs
1185
0755
edit
dl
rm
fsck.cramfs
31168
0755
edit
dl
rm
fsck.ext2
373080
0755
edit
dl
rm
fsck.ext3
373080
0755
edit
dl
rm
fsck.ext4
373080
0755
edit
dl
rm
fsck.fat
80264
0755
edit
dl
rm
fsck.minix
55712
0755
edit
dl
rm
fsck.msdos
80264
0755
edit
dl
rm
fsck.vfat
80264
0755
edit
dl
rm
fsck.xfs
2566
0755
edit
dl
rm
fsfreeze
14720
0755
edit
dl
rm
fstab-decode
14648
0755
edit
dl
rm
fstrim
43392
0755
edit
dl
rm
funccount-bpfcc
12981
0755
edit
dl
rm
funcinterval-bpfcc
5590
0755
edit
dl
rm
funclatency-bpfcc
11549
0755
edit
dl
rm
funcslower-bpfcc
10630
0755
edit
dl
rm
gdisk
203248
0755
edit
dl
rm
genl
123472
0755
edit
dl
rm
getcap
14648
0755
edit
dl
rm
gethostlatency-bpfcc
3914
0755
edit
dl
rm
gethostlatency.bt
1222
0755
edit
dl
rm
getpcaps
14648
0755
edit
dl
rm
getty
60992
0755
edit
dl
rm
groupadd
72840
0755
edit
dl
rm
groupdel
64424
0755
edit
dl
rm
groupmems
59744
0755
edit
dl
rm
groupmod
72744
0755
edit
dl
rm
grpck
59720
0755
edit
dl
rm
grpconv
51368
0755
edit
dl
rm
grpunconv
51368
0755
edit
dl
rm
grub-bios-setup
981552
0755
edit
dl
rm
grub-install
1225824
0755
edit
dl
rm
grub-macbless
969128
0755
edit
dl
rm
grub-mkconfig
8840
0755
edit
dl
rm
grub-mkdevicemap
72384
0755
edit
dl
rm
grub-probe
977576
0755
edit
dl
rm
grub-reboot
4841
0755
edit
dl
rm
grub-set-default
3556
0755
edit
dl
rm
halt
1501304
0755
edit
dl
rm
hardirqs-bpfcc
7019
0755
edit
dl
rm
hdparm
142776
0755
edit
dl
rm
iconvconfig
35296
0755
edit
dl
rm
init
100816
0755
edit
dl
rm
inject-bpfcc
16445
0755
edit
dl
rm
insmod
174328
0755
edit
dl
rm
install-sgmlcatalog
4551
0755
edit
dl
rm
installkernel
2659
0755
edit
dl
rm
integritysetup
68672
0755
edit
dl
rm
invoke-rc.d
16517
0755
edit
dl
rm
ip
772920
0755
edit
dl
rm
ip6tables
224424
0755
edit
dl
rm
ip6tables-apply
7052
0755
edit
dl
rm
ip6tables-legacy
95176
0755
edit
dl
rm
ip6tables-legacy-restore
95176
0755
edit
dl
rm
ip6tables-legacy-save
95176
0755
edit
dl
rm
ip6tables-nft
224424
0755
edit
dl
rm
ip6tables-nft-restore
224424
0755
edit
dl
rm
ip6tables-nft-save
224424
0755
edit
dl
rm
ip6tables-restore
224424
0755
edit
dl
rm
ip6tables-restore-translate
224424
0755
edit
dl
rm
ip6tables-save
224424
0755
edit
dl
rm
ip6tables-translate
224424
0755
edit
dl
rm
iptables
224424
0755
edit
dl
rm
iptables-apply
7052
0755
edit
dl
rm
iptables-legacy
95176
0755
edit
dl
rm
iptables-legacy-restore
95176
0755
edit
dl
rm
iptables-legacy-save
95176
0755
edit
dl
rm
iptables-nft
224424
0755
edit
dl
rm
iptables-nft-restore
224424
0755
edit
dl
rm
iptables-nft-save
224424
0755
edit
dl
rm
iptables-restore
224424
0755
edit
dl
rm
iptables-restore-translate
224424
0755
edit
dl
rm
iptables-save
224424
0755
edit
dl
rm
iptables-translate
224424
0755
edit
dl
rm
irqbalance
60272
0755
edit
dl
rm
irqbalance-ui
39304
0755
edit
dl
rm
iscsi-iname
18744
0755
edit
dl
rm
iscsiadm
379320
0755
edit
dl
rm
iscsid
293432
0755
edit
dl
rm
iscsistart
281080
0755
edit
dl
rm
iscsi_discovery
5293
0755
edit
dl
rm
isosize
14720
0755
edit
dl
rm
iucode-tool
55640
0755
edit
dl
rm
iucode_tool
55640
0755
edit
dl
rm
javacalls-bpfcc
55
0755
edit
dl
rm
javaflow-bpfcc
54
0755
edit
dl
rm
javagc-bpfcc
52
0755
edit
dl
rm
javaobjnew-bpfcc
56
0755
edit
dl
rm
javastat-bpfcc
54
0755
edit
dl
rm
javathreads-bpfcc
57
0755
edit
dl
rm
kbdrate
18752
0755
edit
dl
rm
killall5
26856
0755
edit
dl
rm
killsnoop-bpfcc
4554
0755
edit
dl
rm
killsnoop.bt
873
0755
edit
dl
rm
klockstat-bpfcc
13356
0755
edit
dl
rm
kpartx
43176
0755
edit
dl
rm
kvmexit-bpfcc
11461
0755
edit
dl
rm
ldattach
27008
0755
edit
dl
rm
ldconfig
387
0755
edit
dl
rm
ldconfig.real
1051280
0755
edit
dl
rm
llcstat-bpfcc
4584
0755
edit
dl
rm
loads.bt
1127
0755
edit
dl
rm
locale-gen
4316
0755
edit
dl
rm
logrotate
96504
0755
edit
dl
rm
logsave
14496
0755
edit
dl
rm
losetup
76304
0755
edit
dl
rm
lsmod
174328
0755
edit
dl
rm
luksformat
3401
0755
edit
dl
rm
lvchange
3156712
0755
edit
dl
rm
lvconvert
3156712
0755
edit
dl
rm
lvcreate
3156712
0755
edit
dl
rm
lvdisplay
3156712
0755
edit
dl
rm
lvextend
3156712
0755
edit
dl
rm
lvm
3156712
0755
edit
dl
rm
lvmconfig
3156712
0755
edit
dl
rm
lvmdiskscan
3156712
0755
edit
dl
rm
lvmdump
10364
0755
edit
dl
rm
lvmpolld
241632
0755
edit
dl
rm
lvmsadc
3156712
0755
edit
dl
rm
lvmsar
3156712
0755
edit
dl
rm
lvreduce
3156712
0755
edit
dl
rm
lvremove
3156712
0755
edit
dl
rm
lvrename
3156712
0755
edit
dl
rm
lvresize
3156712
0755
edit
dl
rm
lvs
3156712
0755
edit
dl
rm
lvscan
3156712
0755
edit
dl
rm
lxc
589
0755
edit
dl
rm
lxd
589
0755
edit
dl
rm
make-bcache
22912
0755
edit
dl
rm
mdadm
637144
0755
edit
dl
rm
mdflush-bpfcc
2295
0755
edit
dl
rm
mdflush.bt
775
0755
edit
dl
rm
mdmon
265016
0755
edit
dl
rm
memleak-bpfcc
21298
0755
edit
dl
rm
mkdosfs
52048
0755
edit
dl
rm
mke2fs
133752
0755
edit
dl
rm
mkfs
14720
0755
edit
dl
rm
mkfs.bfs
22912
0755
edit
dl
rm
mkfs.btrfs
573752
0755
edit
dl
rm
mkfs.cramfs
35144
0755
edit
dl
rm
mkfs.ext2
133752
0755
edit
dl
rm
mkfs.ext3
133752
0755
edit
dl
rm
mkfs.ext4
133752
0755
edit
dl
rm
mkfs.fat
52048
0755
edit
dl
rm
mkfs.minix
43408
0755
edit
dl
rm
mkfs.msdos
52048
0755
edit
dl
rm
mkfs.ntfs
67976
0755
edit
dl
rm
mkfs.vfat
52048
0755
edit
dl
rm
mkfs.xfs
449528
0755
edit
dl
rm
mkhomedir_helper
22872
0755
edit
dl
rm
mkinitramfs
15762
0755
edit
dl
rm
mklost+found
14648
0755
edit
dl
rm
mkntfs
67976
0755
edit
dl
rm
mkswap
51592
0755
edit
dl
rm
ModemManager
2165576
0755
edit
dl
rm
modinfo
174328
0755
edit
dl
rm
modprobe
174328
0755
edit
dl
rm
mount.fuse
18736
0755
edit
dl
rm
mount.fuse3
18736
0755
edit
dl
rm
mount.lowntfs-3g
121832
0755
edit
dl
rm
mount.ntfs
162824
0755
edit
dl
rm
mount.ntfs-3g
162824
0755
edit
dl
rm
mountsnoop-bpfcc
14968
0755
edit
dl
rm
mpathpersist
31960
0755
edit
dl
rm
multipath
35128
0755
edit
dl
rm
multipathc
18744
0755
edit
dl
rm
multipathd
145880
0755
edit
dl
rm
mysqld
55467944
0755
edit
dl
rm
mysqld_qslower-bpfcc
3125
0755
edit
dl
rm
naptime.bt
1035
0755
edit
dl
rm
needrestart
41092
0755
edit
dl
rm
netplan
802
0755
edit
dl
rm
netqtop-bpfcc
5725
0755
edit
dl
rm
newusers
89048
0755
edit
dl
rm
nfnl_osf
18736
0755
edit
dl
rm
nfsdist-bpfcc
5068
0755
edit
dl
rm
nfsslower-bpfcc
13939
0755
edit
dl
rm
nft
26856
0755
edit
dl
rm
nginx
1314168
0755
edit
dl
rm
nodegc-bpfcc
52
0755
edit
dl
rm
nodestat-bpfcc
54
0755
edit
dl
rm
nologin
14640
0755
edit
dl
rm
ntfsclone
51592
0755
edit
dl
rm
ntfscp
31104
0755
edit
dl
rm
ntfslabel
22912
0755
edit
dl
rm
ntfsresize
63888
0755
edit
dl
rm
ntfsundelete
51592
0755
edit
dl
rm
offcputime-bpfcc
13779
0755
edit
dl
rm
offwaketime-bpfcc
15676
0755
edit
dl
rm
on_ac_power
3788
0755
edit
dl
rm
oomkill-bpfcc
2084
0755
edit
dl
rm
oomkill.bt
1198
0755
edit
dl
rm
opensnoop-bpfcc
14581
0755
edit
dl
rm
opensnoop.bt
953
0755
edit
dl
rm
overlayroot-chroot
2510
0755
edit
dl
rm
ownership
14792
0755
edit
dl
rm
pam-auth-update
21465
0755
edit
dl
rm
pam_extrausers_chkpwd
26944
2755
edit
dl
rm
pam_extrausers_update
35136
0755
edit
dl
rm
pam_getenv
2890
0755
edit
dl
rm
pam_namespace_helper
467
0755
edit
dl
rm
pam_timestamp_check
14656
0755
edit
dl
rm
parted
96664
0755
edit
dl
rm
partprobe
14720
0755
edit
dl
rm
pdata_tools
1430568
0755
edit
dl
rm
perlcalls-bpfcc
55
0755
edit
dl
rm
perlflow-bpfcc
54
0755
edit
dl
rm
perlstat-bpfcc
54
0755
edit
dl
rm
php-fpm7.4
4803376
0755
edit
dl
rm
phpcalls-bpfcc
54
0755
edit
dl
rm
phpdismod
7278
0755
edit
dl
rm
phpenmod
7278
0755
edit
dl
rm
phpflow-bpfcc
53
0755
edit
dl
rm
phpquery
6389
0755
edit
dl
rm
phpstat-bpfcc
53
0755
edit
dl
rm
pidpersec-bpfcc
1111
0755
edit
dl
rm
pidpersec.bt
628
0755
edit
dl
rm
pivot_root
14720
0755
edit
dl
rm
plymouthd
150088
0755
edit
dl
rm
poweroff
1501304
0755
edit
dl
rm
ppchcalls-bpfcc
14224
0755
edit
dl
rm
profile-bpfcc
14756
0755
edit
dl
rm
pvchange
3156712
0755
edit
dl
rm
pvck
3156712
0755
edit
dl
rm
pvcreate
3156712
0755
edit
dl
rm
pvdisplay
3156712
0755
edit
dl
rm
pvmove
3156712
0755
edit
dl
rm
pvremove
3156712
0755
edit
dl
rm
pvresize
3156712
0755
edit
dl
rm
pvs
3156712
0755
edit
dl
rm
pvscan
3156712
0755
edit
dl
rm
pwck
55592
0755
edit
dl
rm
pwconv
47272
0755
edit
dl
rm
pwhistory_helper
22848
0755
edit
dl
rm
pwunconv
47272
0755
edit
dl
rm
pythoncalls-bpfcc
57
0755
edit
dl
rm
pythonflow-bpfcc
56
0755
edit
dl
rm
pythongc-bpfcc
54
0755
edit
dl
rm
pythonstat-bpfcc
56
0755
edit
dl
rm
rdmaucma-bpfcc
5073
0755
edit
dl
rm
readahead-bpfcc
6694
0755
edit
dl
rm
readprofile
22944
0755
edit
dl
rm
reboot
1501304
0755
edit
dl
rm
remove-shell
1111
0755
edit
dl
rm
reset-trace-bpfcc
3498
0755
edit
dl
rm
resize2fs
71992
0755
edit
dl
rm
resolvconf
162480
0755
edit
dl
rm
rmmod
174328
0755
edit
dl
rm
rmt
56024
0755
edit
dl
rm
rmt-tar
56024
0755
edit
dl
rm
rsyslogd
790192
0755
edit
dl
rm
rtacct
28992
0755
edit
dl
rm
rtcwake
35200
0755
edit
dl
rm
rtmon
119312
0755
edit
dl
rm
rubycalls-bpfcc
55
0755
edit
dl
rm
rubyflow-bpfcc
54
0755
edit
dl
rm
rubygc-bpfcc
52
0755
edit
dl
rm
rubyobjnew-bpfcc
56
0755
edit
dl
rm
rubystat-bpfcc
54
0755
edit
dl
rm
runlevel
1501304
0755
edit
dl
rm
runqlat-bpfcc
9526
0755
edit
dl
rm
runqlat.bt
788
0755
edit
dl
rm
runqlen-bpfcc
8248
0755
edit
dl
rm
runqlen.bt
1037
0755
edit
dl
rm
runqslower-bpfcc
9225
0755
edit
dl
rm
runuser
55680
0755
edit
dl
rm
service
9104
0755
edit
dl
rm
setcap
14648
0755
edit
dl
rm
setuids.bt
1799
0755
edit
dl
rm
setvesablank
14712
0755
edit
dl
rm
setvtrgb
14776
0755
edit
dl
rm
sfdisk
108928
0755
edit
dl
rm
sgdisk
182768
0755
edit
dl
rm
shadowconfig
2273
0755
edit
dl
rm
shmsnoop-bpfcc
7985
0755
edit
dl
rm
shutdown
1501304
0755
edit
dl
rm
slabratetop-bpfcc
6537
0755
edit
dl
rm
sofdsnoop-bpfcc
8255
0755
edit
dl
rm
softirqs-bpfcc
5723
0755
edit
dl
rm
solisten-bpfcc
6103
0755
edit
dl
rm
sshd
921416
0755
edit
dl
rm
ssllatency.bt
2133
0755
edit
dl
rm
sslsniff-bpfcc
14013
0755
edit
dl
rm
sslsnoop.bt
2041
0755
edit
dl
rm
stackcount-bpfcc
16655
0755
edit
dl
rm
start-stop-daemon
48632
0755
edit
dl
rm
statsnoop-bpfcc
5041
0755
edit
dl
rm
statsnoop.bt
1294
0755
edit
dl
rm
sudo_logsrvd
254464
0755
edit
dl
rm
sudo_sendlog
134832
0755
edit
dl
rm
sulogin
43392
0755
edit
dl
rm
swapin.bt
600
0755
edit
dl
rm
swaplabel
18816
0755
edit
dl
rm
swapoff
22912
0755
edit
dl
rm
swapon
43392
0755
edit
dl
rm
switch_root
22912
0755
edit
dl
rm
syncsnoop-bpfcc
1300
0755
edit
dl
rm
syncsnoop.bt
839
0755
edit
dl
rm
syscount-bpfcc
8771
0755
edit
dl
rm
syscount.bt
872
0755
edit
dl
rm
sysctl
31112
0755
edit
dl
rm
tarcat
936
0755
edit
dl
rm
tc
645200
0755
edit
dl
rm
tclcalls-bpfcc
54
0755
edit
dl
rm
tclflow-bpfcc
53
0755
edit
dl
rm
tclobjnew-bpfcc
55
0755
edit
dl
rm
tclstat-bpfcc
53
0755
edit
dl
rm
tcpaccept-bpfcc
9220
0755
edit
dl
rm
tcpaccept.bt
1756
0755
edit
dl
rm
tcpcong-bpfcc
20591
0755
edit
dl
rm
tcpconnect-bpfcc
18902
0755
edit
dl
rm
tcpconnect.bt
1615
0755
edit
dl
rm
tcpconnlat-bpfcc
9285
0755
edit
dl
rm
tcpdrop-bpfcc
7616
0755
edit
dl
rm
tcpdrop.bt
2469
0755
edit
dl
rm
tcplife-bpfcc
16949
0755
edit
dl
rm
tcplife.bt
2785
0755
edit
dl
rm
tcpretrans-bpfcc
14098
0755
edit
dl
rm
tcpretrans.bt
2120
0755
edit
dl
rm
tcprtt-bpfcc
8913
0755
edit
dl
rm
tcpstates-bpfcc
14064
0755
edit
dl
rm
tcpsubnet-bpfcc
7814
0755
edit
dl
rm
tcpsynbl-bpfcc
2175
0755
edit
dl
rm
tcpsynbl.bt
962
0755
edit
dl
rm
tcptop-bpfcc
12943
0755
edit
dl
rm
tcptracer-bpfcc
18130
0755
edit
dl
rm
telinit
1501304
0755
edit
dl
rm
thin_check
1430568
0755
edit
dl
rm
thin_delta
1430568
0755
edit
dl
rm
thin_dump
1430568
0755
edit
dl
rm
thin_ls
1430568
0755
edit
dl
rm
thin_metadata_size
1430568
0755
edit
dl
rm
thin_repair
1430568
0755
edit
dl
rm
thin_restore
1430568
0755
edit
dl
rm
thin_rmap
1430568
0755
edit
dl
rm
thin_trim
1430568
0755
edit
dl
rm
threadsnoop-bpfcc
1858
0755
edit
dl
rm
threadsnoop.bt
712
0755
edit
dl
rm
tipc
92688
0755
edit
dl
rm
tplist-bpfcc
4157
0755
edit
dl
rm
trace-bpfcc
43892
0755
edit
dl
rm
ttysnoop-bpfcc
7694
0755
edit
dl
rm
tune2fs
113216
0755
edit
dl
rm
ucalls
11970
0755
edit
dl
rm
uflow
8115
0755
edit
dl
rm
ufw
4959
0755
edit
dl
rm
ugc
7823
0755
edit
dl
rm
umount.udisks2
14640
0755
edit
dl
rm
undump.bt
789
0755
edit
dl
rm
unix_chkpwd
31040
2755
edit
dl
rm
unix_update
35136
0755
edit
dl
rm
uobjnew
6181
0755
edit
dl
rm
update-ca-certificates
5446
0755
edit
dl
rm
update-catalog
9393
0755
edit
dl
rm
update-grub
64
0755
edit
dl
rm
update-grub-gfxpayload
301
0755
edit
dl
rm
update-grub2
64
0755
edit
dl
rm
update-ieee-data
3492
0755
edit
dl
rm
update-info-dir
1700
0755
edit
dl
rm
update-initramfs
6908
0755
edit
dl
rm
update-locale
3057
0755
edit
dl
rm
update-passwd
35392
0755
edit
dl
rm
update-pciids
1778
0755
edit
dl
rm
update-rc.d
18147
0755
edit
dl
rm
update-secureboot-policy
7605
0755
edit
dl
rm
update-shells
3984
0755
edit
dl
rm
update-xmlcatalog
17284
0755
edit
dl
rm
upgrade-from-grub-legacy
1596
0755
edit
dl
rm
usb_modeswitch
61096
0755
edit
dl
rm
usb_modeswitch_dispatcher
27418
0755
edit
dl
rm
useradd
143232
0755
edit
dl
rm
userdel
93192
0755
edit
dl
rm
usermod
130712
0755
edit
dl
rm
ustat
12412
0755
edit
dl
rm
uthreads
4100
0755
edit
dl
rm
uuidd
31624
0755
edit
dl
rm
validlocale
1773
0755
edit
dl
rm
vcstime
14640
0755
edit
dl
rm
vdpa
35392
0755
edit
dl
rm
veritysetup
44992
0755
edit
dl
rm
vfscount-bpfcc
1390
0755
edit
dl
rm
vfscount.bt
515
0755
edit
dl
rm
vfsstat-bpfcc
4159
0755
edit
dl
rm
vfsstat.bt
721
0755
edit
dl
rm
vgcfgbackup
3156712
0755
edit
dl
rm
vgcfgrestore
3156712
0755
edit
dl
rm
vgchange
3156712
0755
edit
dl
rm
vgck
3156712
0755
edit
dl
rm
vgconvert
3156712
0755
edit
dl
rm
vgcreate
3156712
0755
edit
dl
rm
vgdisplay
3156712
0755
edit
dl
rm
vgexport
3156712
0755
edit
dl
rm
vgextend
3156712
0755
edit
dl
rm
vgimport
3156712
0755
edit
dl
rm
vgimportclone
3156712
0755
edit
dl
rm
vgmerge
3156712
0755
edit
dl
rm
vgmknodes
3156712
0755
edit
dl
rm
vgreduce
3156712
0755
edit
dl
rm
vgremove
3156712
0755
edit
dl
rm
vgrename
3156712
0755
edit
dl
rm
vgs
3156712
0755
edit
dl
rm
vgscan
3156712
0755
edit
dl
rm
vgsplit
3156712
0755
edit
dl
rm
vigr
62144
0755
edit
dl
rm
vipw
62144
0755
edit
dl
rm
virtiostat-bpfcc
8900
0755
edit
dl
rm
visudo
258776
0755
edit
dl
rm
vpddecode
14928
0755
edit
dl
rm
wakeuptime-bpfcc
8291
0755
edit
dl
rm
wipefs
39296
0755
edit
dl
rm
writeback.bt
1699
0755
edit
dl
rm
xfsdist-bpfcc
4723
0755
edit
dl
rm
xfsdist.bt
972
0755
edit
dl
rm
xfsslower-bpfcc
7964
0755
edit
dl
rm
xfs_admin
2174
0755
edit
dl
rm
xfs_bmap
695
0755
edit
dl
rm
xfs_copy
92608
0755
edit
dl
rm
xfs_db
705088
0755
edit
dl
rm
xfs_estimate
14504
0755
edit
dl
rm
xfs_freeze
800
0755
edit
dl
rm
xfs_fsr
43192
0755
edit
dl
rm
xfs_growfs
39152
0755
edit
dl
rm
xfs_info
1294
0755
edit
dl
rm
xfs_io
208536
0755
edit
dl
rm
xfs_logprint
80144
0755
edit
dl
rm
xfs_mdrestore
35048
0755
edit
dl
rm
xfs_metadump
816
0755
edit
dl
rm
xfs_mkfile
1040
0755
edit
dl
rm
xfs_ncheck
685
0755
edit
dl
rm
xfs_quota
92328
0755
edit
dl
rm
xfs_repair
658760
0755
edit
dl
rm
xfs_rtcp
18584
0755
edit
dl
rm
xfs_scrub
108816
0755
edit
dl
rm
xfs_scrub_all
7841
0755
edit
dl
rm
xfs_spaceman
43320
0755
edit
dl
rm
xtables-legacy-multi
95176
0755
edit
dl
rm
xtables-monitor
224424
0755
edit
dl
rm
xtables-nft-multi
224424
0755
edit
dl
rm
zerofree
14488
0755
edit
dl
rm
zfsdist-bpfcc
5427
0755
edit
dl
rm
zfsslower-bpfcc
8657
0755
edit
dl
rm
zic
67984
0755
edit
dl
rm
zramctl
55824
0755
edit
dl
rm
Edit:
/usr/sbin/argdist-bpfcc
(36862B)
#! /usr/bin/python3 # # argdist Trace a function and display a distribution of its # parameter values as a histogram or frequency count. # # USAGE: argdist [-h] [-p PID] [-z STRING_SIZE] [-i INTERVAL] [-n COUNT] [-v] # [-c] [-T TOP] [-C specifier] [-H specifier] [-I header] # [-t TID] # # Licensed under the Apache License, Version 2.0 (the "License") # Copyright (C) 2016 Sasha Goldshtein. from bcc import BPF, USDT, StrcmpRewrite from time import sleep, strftime import argparse import re import traceback import os import sys class Probe(object): next_probe_index = 0 streq_index = 0 aliases = {"$PID": "(bpf_get_current_pid_tgid() >> 32)", "$COMM": "&val.name"} def _substitute_aliases(self, expr): if expr is None: return expr for alias, subst in Probe.aliases.items(): expr = expr.replace(alias, subst) return expr def _parse_signature(self): params = map(str.strip, self.signature.split(',')) self.param_types = {} for param in params: # If the type is a pointer, the * can be next to the # param name. Other complex types like arrays are not # supported right now. index = param.rfind('*') index = index if index != -1 else param.rfind(' ') param_type = param[0:index + 1].strip() param_name = param[index + 1:].strip() self.param_types[param_name] = param_type # Maintain list of user params. Then later decide to # switch to bpf_probe_read_kernel or bpf_probe_read_user. if "__user" in param_type.split(): self.probe_user_list.add(param_name) def _generate_entry(self): self.entry_probe_func = self.probe_func_name + "_entry" text = """ int PROBENAME(struct pt_regs *ctx SIGNATURE) { u64 __pid_tgid = bpf_get_current_pid_tgid(); u32 __pid = __pid_tgid; // lower 32 bits u32 __tgid = __pid_tgid >> 32; // upper 32 bits PID_FILTER TID_FILTER COLLECT return 0; } """ text = text.replace("PROBENAME", self.entry_probe_func) text = text.replace("SIGNATURE", "" if len(self.signature) == 0 else ", " + self.signature) text = text.replace("PID_FILTER", self._generate_pid_filter()) text = text.replace("TID_FILTER", self._generate_tid_filter()) collect = "" for pname in self.args_to_probe: param_hash = self.hashname_prefix + pname if pname == "__latency": collect += """ u64 __time = bpf_ktime_get_ns(); %s.update(&__pid, &__time); """ % param_hash else: collect += "%s.update(&__pid, &%s);\n" % \ (param_hash, pname) text = text.replace("COLLECT", collect) return text def _generate_entry_probe(self): # Any $entry(name) expressions result in saving that argument # when entering the function. self.args_to_probe = set() regex = r"\$entry\((\w+)\)" for expr in self.exprs: for arg in re.finditer(regex, expr): self.args_to_probe.add(arg.group(1)) for arg in re.finditer(regex, self.filter): self.args_to_probe.add(arg.group(1)) if any(map(lambda expr: "$latency" in expr, self.exprs)) or \ "$latency" in self.filter: self.args_to_probe.add("__latency") self.param_types["__latency"] = "u64" # nanoseconds for pname in self.args_to_probe: if pname not in self.param_types: raise ValueError("$entry(%s): no such param" % arg) self.hashname_prefix = "%s_param_" % self.probe_hash_name text = "" for pname in self.args_to_probe: # Each argument is stored in a separate hash that is # keyed by pid. text += "BPF_HASH(%s, u32, %s);\n" % \ (self.hashname_prefix + pname, self.param_types[pname]) text += self._generate_entry() return text def _generate_retprobe_prefix(self): # After we're done here, there are __%s_val variables for each # argument we needed to probe using $entry(name), and they all # have values (which isn't necessarily the case if we missed # the method entry probe). text = "" self.param_val_names = {} for pname in self.args_to_probe: val_name = "__%s_val" % pname text += "%s *%s = %s.lookup(&__pid);\n" % \ (self.param_types[pname], val_name, self.hashname_prefix + pname) text += "if (%s == 0) { return 0 ; }\n" % val_name self.param_val_names[pname] = val_name return text def _generate_comm_prefix(self): text = """ struct val_t { u32 pid; char name[sizeof(struct __string_t)]; }; struct val_t val = {.pid = (bpf_get_current_pid_tgid() >> 32) }; bpf_get_current_comm(&val.name, sizeof(val.name)); """ return text def _replace_entry_exprs(self): for pname, vname in self.param_val_names.items(): if pname == "__latency": entry_expr = "$latency" val_expr = "(bpf_ktime_get_ns() - *%s)" % vname else: entry_expr = "$entry(%s)" % pname val_expr = "(*%s)" % vname for i in range(0, len(self.exprs)): self.exprs[i] = self.exprs[i].replace( entry_expr, val_expr) self.filter = self.filter.replace(entry_expr, val_expr) def _attach_entry_probe(self): if self.is_user: self.bpf.attach_uprobe(name=self.library, sym=self.function, fn_name=self.entry_probe_func, pid=self.pid or -1) else: self.bpf.attach_kprobe(event=self.function, fn_name=self.entry_probe_func) def _bail(self, error): raise ValueError("error parsing probe '%s': %s" % (self.raw_spec, error)) def _validate_specifier(self): # Everything after '#' is the probe label, ignore it spec = self.raw_spec.split('#')[0] parts = spec.strip().split(':') if len(parts) < 3: self._bail("at least the probe type, library, and " + "function signature must be specified") if len(parts) > 6: self._bail("extraneous ':'-separated parts detected") if parts[0] not in ["r", "p", "t", "u"]: self._bail("probe type must be 'p', 'r', 't', or 'u'" + " but got '%s'" % parts[0]) if re.match(r"\S+\(.*\)", parts[2]) is None: self._bail(("function signature '%s' has an invalid " + "format") % parts[2]) def _parse_expr_types(self, expr_types): if len(expr_types) == 0: self._bail("no expr types specified") self.expr_types = expr_types.split(',') def _parse_exprs(self, exprs): if len(exprs) == 0: self._bail("no exprs specified") self.exprs = exprs.split(',') def _make_valid_identifier(self, ident): return re.sub(r'[^A-Za-z0-9_]', '_', ident) def __init__(self, tool, type, specifier): self.usdt_ctx = None self.streq_functions = "" self.pid = tool.args.pid self.tid = tool.args.tid self.cumulative = tool.args.cumulative or False self.raw_spec = specifier self.probe_user_list = set() self.bin_cmp = False self._validate_specifier() spec_and_label = specifier.split('#') self.label = spec_and_label[1] \ if len(spec_and_label) == 2 else None parts = spec_and_label[0].strip().split(':') self.type = type # hist or freq self.probe_type = parts[0] fparts = parts[2].split('(') self.function = fparts[0].strip() if self.probe_type == "t": self.library = "" # kernel self.tp_category = parts[1] self.tp_event = self.function elif self.probe_type == "u": self.library = parts[1] self.probe_func_name = self._make_valid_identifier( "%s_probe%d" % (self.function, Probe.next_probe_index)) self._enable_usdt_probe() else: self.library = parts[1] self.is_user = len(self.library) > 0 self.signature = fparts[1].strip()[:-1] self._parse_signature() # If the user didn't specify an expression to probe, we probe # the retval in a ret probe, or simply the value "1" otherwise. self.is_default_expr = len(parts) < 5 if not self.is_default_expr: self._parse_expr_types(parts[3]) self._parse_exprs(parts[4]) if len(self.exprs) != len(self.expr_types): self._bail("mismatched # of exprs and types") if self.type == "hist" and len(self.expr_types) > 1: self._bail("histograms can only have 1 expr") else: if not self.probe_type == "r" and self.type == "hist": self._bail("histograms must have expr") self.expr_types = \ ["u64" if not self.probe_type == "r" else "int"] self.exprs = \ ["1" if not self.probe_type == "r" else "$retval"] self.filter = "" if len(parts) != 6 else parts[5] self._substitute_exprs() # Do we need to attach an entry probe so that we can collect an # argument that is required for an exit (return) probe? def check(expr): keywords = ["$entry", "$latency"] return any(map(lambda kw: kw in expr, keywords)) self.entry_probe_required = self.probe_type == "r" and \ (any(map(check, self.exprs)) or check(self.filter)) self.probe_func_name = self._make_valid_identifier( "%s_probe%d" % (self.function, Probe.next_probe_index)) self.probe_hash_name = self._make_valid_identifier( "%s_hash%d" % (self.function, Probe.next_probe_index)) Probe.next_probe_index += 1 def _enable_usdt_probe(self): self.usdt_ctx = USDT(path=self.library, pid=self.pid) self.usdt_ctx.enable_probe( self.function, self.probe_func_name) def _substitute_exprs(self): def repl(expr): expr = self._substitute_aliases(expr) rdict = StrcmpRewrite.rewrite_expr(expr, self.bin_cmp, self.library, self.probe_user_list, self.streq_functions, Probe.streq_index) expr = rdict["expr"] self.streq_functions = rdict["streq_functions"] Probe.streq_index = rdict["probeid"] return expr.replace("$retval", "PT_REGS_RC(ctx)") for i in range(0, len(self.exprs)): self.exprs[i] = repl(self.exprs[i]) self.filter = repl(self.filter) def _is_string(self, expr_type): return expr_type == "char*" or expr_type == "char *" def _generate_hash_field(self, i): if self._is_string(self.expr_types[i]): return "struct __string_t v%d;\n" % i else: return "%s v%d;\n" % (self.expr_types[i], i) def _generate_usdt_arg_assignment(self, i): expr = self.exprs[i] if self.probe_type == "u" and expr[0:3] == "arg": arg_index = int(expr[3]) arg_ctype = self.usdt_ctx.get_probe_arg_ctype( self.function, arg_index - 1) return (" %s %s = 0;\n" + " bpf_usdt_readarg(%s, ctx, &%s);\n") \ % (arg_ctype, expr, expr[3], expr) else: return "" def _generate_field_assignment(self, i): text = self._generate_usdt_arg_assignment(i) if self._is_string(self.expr_types[i]): if self.is_user or \ self.exprs[i] in self.probe_user_list: probe_readfunc = "bpf_probe_read_user" else: probe_readfunc = "bpf_probe_read_kernel" return (text + " %s(&__key.v%d.s," + " sizeof(__key.v%d.s), (void *)%s);\n") % \ (probe_readfunc, i, i, self.exprs[i]) else: return text + " __key.v%d = %s;\n" % \ (i, self.exprs[i]) def _generate_hash_decl(self): if self.type == "hist": return "BPF_HISTOGRAM(%s, %s);" % \ (self.probe_hash_name, self.expr_types[0]) else: text = "struct %s_key_t {\n" % self.probe_hash_name for i in range(0, len(self.expr_types)): text += self._generate_hash_field(i) text += "};\n" text += "BPF_HASH(%s, struct %s_key_t, u64);\n" % \ (self.probe_hash_name, self.probe_hash_name) return text def _generate_key_assignment(self): if self.type == "hist": return self._generate_usdt_arg_assignment(0) + \ ("%s __key = %s;\n" % (self.expr_types[0], self.exprs[0])) else: text = "struct %s_key_t __key = {};\n" % \ self.probe_hash_name for i in range(0, len(self.exprs)): text += self._generate_field_assignment(i) return text def _generate_hash_update(self): if self.type == "hist": return "%s.atomic_increment(bpf_log2l(__key));" % \ self.probe_hash_name else: return "%s.atomic_increment(__key);" % \ self.probe_hash_name def _generate_pid_filter(self): # Kernel probes need to explicitly filter pid, because the # attach interface doesn't support pid filtering if self.pid is not None and not self.is_user: return "if (__tgid != %d) { return 0; }" % self.pid else: return "" def _generate_tid_filter(self): if self.tid is not None and not self.is_user: return "if (__pid != %d) { return 0; }" % self.tid else: return "" def generate_text(self): program = "" probe_text = """ DATA_DECL """ + ( "TRACEPOINT_PROBE(%s, %s)" % (self.tp_category, self.tp_event) if self.probe_type == "t" else "int PROBENAME(struct pt_regs *ctx SIGNATURE)") + """ { u64 __pid_tgid = bpf_get_current_pid_tgid(); u32 __pid = __pid_tgid; // lower 32 bits u32 __tgid = __pid_tgid >> 32; // upper 32 bits PID_FILTER TID_FILTER PREFIX KEY_EXPR if (!(FILTER)) return 0; COLLECT return 0; } """ prefix = "" signature = "" # If any entry arguments are probed in a ret probe, we need # to generate an entry probe to collect them if self.entry_probe_required: program += self._generate_entry_probe() prefix += self._generate_retprobe_prefix() # Replace $entry(paramname) with a reference to the # value we collected when entering the function: self._replace_entry_exprs() if self.probe_type == "p" and len(self.signature) > 0: # Only entry uprobes/kprobes can have user-specified # signatures. Other probes force it to (). signature = ", " + self.signature # If COMM is specified prefix with code to get process name if self.exprs.count(self.aliases['$COMM']): prefix += self._generate_comm_prefix() program += probe_text.replace("PROBENAME", self.probe_func_name) program = program.replace("SIGNATURE", signature) program = program.replace("PID_FILTER", self._generate_pid_filter()) program = program.replace("TID_FILTER", self._generate_tid_filter()) decl = self._generate_hash_decl() key_expr = self._generate_key_assignment() collect = self._generate_hash_update() program = program.replace("DATA_DECL", decl) program = program.replace("KEY_EXPR", key_expr) program = program.replace("FILTER", "1" if len(self.filter) == 0 else self.filter) program = program.replace("COLLECT", collect) program = program.replace("PREFIX", prefix) return self.streq_functions + program def _attach_u(self): libpath = BPF.find_library(self.library) if libpath is None: libpath = BPF.find_exe(self.library) if libpath is None or len(libpath) == 0: self._bail("unable to find library %s" % self.library) if self.probe_type == "r": self.bpf.attach_uretprobe(name=libpath, sym=self.function, fn_name=self.probe_func_name, pid=self.pid or -1) else: self.bpf.attach_uprobe(name=libpath, sym=self.function, fn_name=self.probe_func_name, pid=self.pid or -1) def _attach_k(self): if self.probe_type == "t": pass # Nothing to do for tracepoints elif self.probe_type == "r": self.bpf.attach_kretprobe(event=self.function, fn_name=self.probe_func_name) else: self.bpf.attach_kprobe(event=self.function, fn_name=self.probe_func_name) def attach(self, bpf): self.bpf = bpf if self.probe_type == "u": return if self.is_user: self._attach_u() else: self._attach_k() if self.entry_probe_required: self._attach_entry_probe() # Check whether hash table batch ops is supported if self.type == "freq" and self.bpf.kernel_struct_has_field( b'bpf_map_ops', b'map_lookup_and_delete_batch') == 1: self.htab_batch_ops = True else: self.htab_batch_ops = False def _v2s(self, v): # Most fields can be converted with plain str(), but strings # are wrapped in a __string_t which has an .s field if "__string_t" in type(v).__name__: return str(v.s) return str(v) def _display_expr(self, i): # Replace ugly latency calculation with $latency expr = self.exprs[i].replace( "(bpf_ktime_get_ns() - *____latency_val)", "$latency") # Replace alias values back with the alias name for alias, subst in Probe.aliases.items(): expr = expr.replace(subst, alias) # Replace retval expression with $retval expr = expr.replace("PT_REGS_RC(ctx)", "$retval") # Replace ugly (*__param_val) expressions with param name return re.sub(r"\(\*__(\w+)_val\)", r"\1", expr) def _display_key(self, key): if self.is_default_expr: if not self.probe_type == "r": return "total calls" else: return "retval = %s" % str(key.v0) else: # The key object has v0, ..., vk fields containing # the values of the expressions from self.exprs def str_i(i): key_i = self._v2s(getattr(key, "v%d" % i)) return "%s = %s" % \ (self._display_expr(i), key_i) return ", ".join(map(str_i, range(0, len(self.exprs)))) def display(self, top): data = self.bpf.get_table(self.probe_hash_name) if self.type == "freq": print(self.label or self.raw_spec) print("\t%-10s %s" % ("COUNT", "EVENT")) sdata = sorted(data.items_lookup_batch() if self.htab_batch_ops else data.items(), key=lambda p: p[1].value) if top is not None: sdata = sdata[-top:] for key, value in sdata: # Print some nice values if the user didn't # specify an expression to probe if self.is_default_expr: if not self.probe_type == "r": key_str = "total calls" else: key_str = "retval = %s" % \ self._v2s(key.v0) else: key_str = self._display_key(key) print("\t%-10s %s" % (str(value.value), key_str)) elif self.type == "hist": label = self.label or (self._display_expr(0) if not self.is_default_expr else "retval") data.print_log2_hist(val_type=label) if not self.cumulative: if self.htab_batch_ops: data.items_delete_batch() else: data.clear() def __str__(self): return self.label or self.raw_spec class Tool(object): examples = """ Probe specifier syntax: {p,r,t,u}:{[library],category}:function(signature):type[,type...]:expr[,expr...][:filter]][#label] Where: p,r,t,u -- probe at function entry, function exit, kernel tracepoint, or USDT probe in exit probes: can use $retval, $entry(param), $latency library -- the library that contains the function (leave empty for kernel functions) category -- the category of the kernel tracepoint (e.g. net, sched) function -- the function name to trace (or tracepoint name) signature -- the function's parameters, as in the C header type -- the type of the expression to collect (supports multiple) expr -- the expression to collect (supports multiple) filter -- the filter that is applied to collected values label -- the label for this probe in the resulting output EXAMPLES: argdist -H 'p::__kmalloc(u64 size):u64:size' Print a histogram of allocation sizes passed to kmalloc argdist -p 1005 -C 'p:c:malloc(size_t size):size_t:size:size==16' Print a frequency count of how many times process 1005 called malloc with an allocation size of 16 bytes argdist -C 'r:c:gets():char*:(char*)$retval#snooped strings' Snoop on all strings returned by gets() argdist -H 'r::__kmalloc(size_t size):u64:$latency/$entry(size)#ns per byte' Print a histogram of nanoseconds per byte from kmalloc allocations argdist -C 'p::__kmalloc(size_t sz, gfp_t flags):size_t:sz:flags&GFP_ATOMIC' Print frequency count of kmalloc allocation sizes that have GFP_ATOMIC argdist -p 1005 -C 'p:c:write(int fd):int:fd' -T 5 Print frequency counts of how many times writes were issued to a particular file descriptor number, in process 1005, but only show the top 5 busiest fds argdist -p 1005 -H 'r:c:read()' Print a histogram of results (sizes) returned by read() in process 1005 argdist -C 'r::__vfs_read():u32:$PID:$latency > 100000' Print frequency of reads by process where the latency was >0.1ms argdist -C 'r::__vfs_read():u32:$COMM:$latency > 100000' Print frequency of reads by process name where the latency was >0.1ms argdist -H 'r::__vfs_read(void *file, void *buf, size_t count):size_t: $entry(count):$latency > 1000000' Print a histogram of read sizes that were longer than 1ms argdist -H \\ 'p:c:write(int fd, const void *buf, size_t count):size_t:count:fd==1' Print a histogram of buffer sizes passed to write() across all processes, where the file descriptor was 1 (STDOUT) argdist -C 'p:c:fork()#fork calls' Count fork() calls in libc across all processes Can also use funccount.py, which is easier and more flexible argdist -H 't:block:block_rq_complete():u32:args->nr_sector' Print histogram of number of sectors in completing block I/O requests argdist -C 't:irq:irq_handler_entry():int:args->irq' Aggregate interrupts by interrupt request (IRQ) argdist -C 'u:pthread:pthread_start():u64:arg2' -p 1337 Print frequency of function addresses used as a pthread start function, relying on the USDT pthread_start probe in process 1337 argdist -H 'p:c:sleep(u32 seconds):u32:seconds' \\ -H 'p:c:nanosleep(struct timespec *req):long:req->tv_nsec' Print histograms of sleep() and nanosleep() parameter values argdist -p 2780 -z 120 \\ -C 'p:c:write(int fd, char* buf, size_t len):char*:buf:fd==1' Spy on writes to STDOUT performed by process 2780, up to a string size of 120 characters argdist -I 'kernel/sched/sched.h' \\ -C 'p::__account_cfs_rq_runtime(struct cfs_rq *cfs_rq):s64:cfs_rq->runtime_remaining' Trace on the cfs scheduling runqueue remaining runtime. The struct cfs_rq is defined in kernel/sched/sched.h which is in kernel source tree and not in kernel-devel package. So this command needs to run at the kernel source tree root directory so that the added header file can be found by the compiler. """ def __init__(self): parser = argparse.ArgumentParser(description="Trace a " + "function and display a summary of its parameter values.", formatter_class=argparse.RawDescriptionHelpFormatter, epilog=Tool.examples) parser.add_argument("-p", "--pid", type=int, help="id of the process to trace (optional)") parser.add_argument("-t", "--tid", type=int, help="id of the thread to trace (optional)") parser.add_argument("-z", "--string-size", default=80, type=int, help="maximum string size to read from char* arguments") parser.add_argument("-i", "--interval", default=1, type=int, help="output interval, in seconds (default 1 second)") parser.add_argument("-d", "--duration", type=int, help="total duration of trace, in seconds") parser.add_argument("-n", "--number", type=int, dest="count", help="number of outputs") parser.add_argument("-v", "--verbose", action="store_true", help="print resulting BPF program code before executing") parser.add_argument("-c", "--cumulative", action="store_true", help="do not clear histograms and freq counts at " + "each interval") parser.add_argument("-T", "--top", type=int, help="number of top results to show (not applicable to " + "histograms)") parser.add_argument("-H", "--histogram", action="append", dest="histspecifier", metavar="specifier", help="probe specifier to capture histogram of " + "(see examples below)") parser.add_argument("-C", "--count", action="append", dest="countspecifier", metavar="specifier", help="probe specifier to capture count of " + "(see examples below)") parser.add_argument("-I", "--include", action="append", metavar="header", help="additional header files to include in the BPF program " "as either full path, " "or relative to relative to current working directory, " "or relative to default kernel header search path") parser.add_argument("--ebpf", action="store_true", help=argparse.SUPPRESS) self.args = parser.parse_args() self.usdt_ctx = None def _create_probes(self): self.probes = [] for specifier in (self.args.countspecifier or []): self.probes.append(Probe(self, "freq", specifier)) for histspecifier in (self.args.histspecifier or []): self.probes.append(Probe(self, "hist", histspecifier)) if len(self.probes) == 0: print("at least one specifier is required") exit(1) def _generate_program(self): bpf_source = """ struct __string_t { char s[%d]; }; #include <uapi/linux/ptrace.h> """ % self.args.string_size for include in (self.args.include or []): if include.startswith((".", "/")): include = os.path.abspath(include) bpf_source += "#include \"%s\"\n" % include else: bpf_source += "#include <%s>\n" % include bpf_source += BPF.generate_auto_includes( map(lambda p: p.raw_spec, self.probes)) for probe in self.probes: bpf_source += probe.generate_text() if self.args.verbose: for text in [probe.usdt_ctx.get_text() for probe in self.probes if probe.usdt_ctx]: print(text) if self.args.verbose or self.args.ebpf: print(bpf_source) if self.args.ebpf: exit() usdt_contexts = [probe.usdt_ctx for probe in self.probes if probe.usdt_ctx] self.bpf = BPF(text=bpf_source, usdt_contexts=usdt_contexts) def _attach(self): for probe in self.probes: probe.attach(self.bpf) if self.args.verbose: print("open uprobes: %s" % list(self.bpf.uprobe_fds.keys())) print("open kprobes: %s" % list(self.bpf.kprobe_fds.keys())) def _main_loop(self): count_so_far = 0 seconds = 0 while True: try: sleep(self.args.interval) seconds += self.args.interval except KeyboardInterrupt: exit() print("[%s]" % strftime("%H:%M:%S")) for probe in self.probes: probe.display(self.args.top) count_so_far += 1 if self.args.count is not None and \ count_so_far >= self.args.count: exit() if self.args.duration and \ seconds >= self.args.duration: exit() def run(self): try: self._create_probes() self._generate_program() self._attach() self._main_loop() except: exc_info = sys.exc_info() sys_exit = exc_info[0] is SystemExit if self.args.verbose: traceback.print_exc() elif not sys_exit: print(exc_info[1]) exit(0 if sys_exit else 1) if __name__ == "__main__": Tool().run()
Save
cmd:
run