xref: /linux/samples/bpf/trace_event_kern.c (revision 2c97b5ae83dca56718774e7b4bf9640f05d11867)
1 /* Copyright (c) 2016 Facebook
2  *
3  * This program is free software; you can redistribute it and/or
4  * modify it under the terms of version 2 of the GNU General Public
5  * License as published by the Free Software Foundation.
6  */
7 #include <linux/ptrace.h>
8 #include <linux/version.h>
9 #include <uapi/linux/bpf.h>
10 #include <uapi/linux/bpf_perf_event.h>
11 #include <uapi/linux/perf_event.h>
12 #include "bpf_helpers.h"
13 #include "bpf_tracing.h"
14 
15 struct key_t {
16 	char comm[TASK_COMM_LEN];
17 	u32 kernstack;
18 	u32 userstack;
19 };
20 
21 struct bpf_map_def SEC("maps") counts = {
22 	.type = BPF_MAP_TYPE_HASH,
23 	.key_size = sizeof(struct key_t),
24 	.value_size = sizeof(u64),
25 	.max_entries = 10000,
26 };
27 
28 struct bpf_map_def SEC("maps") stackmap = {
29 	.type = BPF_MAP_TYPE_STACK_TRACE,
30 	.key_size = sizeof(u32),
31 	.value_size = PERF_MAX_STACK_DEPTH * sizeof(u64),
32 	.max_entries = 10000,
33 };
34 
35 #define KERN_STACKID_FLAGS (0 | BPF_F_FAST_STACK_CMP)
36 #define USER_STACKID_FLAGS (0 | BPF_F_FAST_STACK_CMP | BPF_F_USER_STACK)
37 
38 SEC("perf_event")
39 int bpf_prog1(struct bpf_perf_event_data *ctx)
40 {
41 	char time_fmt1[] = "Time Enabled: %llu, Time Running: %llu";
42 	char time_fmt2[] = "Get Time Failed, ErrCode: %d";
43 	char addr_fmt[] = "Address recorded on event: %llx";
44 	char fmt[] = "CPU-%d period %lld ip %llx";
45 	u32 cpu = bpf_get_smp_processor_id();
46 	struct bpf_perf_event_value value_buf;
47 	struct key_t key;
48 	u64 *val, one = 1;
49 	int ret;
50 
51 	if (ctx->sample_period < 10000)
52 		/* ignore warmup */
53 		return 0;
54 	bpf_get_current_comm(&key.comm, sizeof(key.comm));
55 	key.kernstack = bpf_get_stackid(ctx, &stackmap, KERN_STACKID_FLAGS);
56 	key.userstack = bpf_get_stackid(ctx, &stackmap, USER_STACKID_FLAGS);
57 	if ((int)key.kernstack < 0 && (int)key.userstack < 0) {
58 		bpf_trace_printk(fmt, sizeof(fmt), cpu, ctx->sample_period,
59 				 PT_REGS_IP(&ctx->regs));
60 		return 0;
61 	}
62 
63 	ret = bpf_perf_prog_read_value(ctx, (void *)&value_buf, sizeof(struct bpf_perf_event_value));
64 	if (!ret)
65 	  bpf_trace_printk(time_fmt1, sizeof(time_fmt1), value_buf.enabled, value_buf.running);
66 	else
67 	  bpf_trace_printk(time_fmt2, sizeof(time_fmt2), ret);
68 
69 	if (ctx->addr != 0)
70 	  bpf_trace_printk(addr_fmt, sizeof(addr_fmt), ctx->addr);
71 
72 	val = bpf_map_lookup_elem(&counts, &key);
73 	if (val)
74 		(*val)++;
75 	else
76 		bpf_map_update_elem(&counts, &key, &one, BPF_NOEXIST);
77 	return 0;
78 }
79 
80 char _license[] SEC("license") = "GPL";
81