xref: /aosp_15_r20/external/bcc/libbpf-tools/filelife.c (revision 387f9dfdfa2baef462e92476d413c7bc2470293e)
1 // SPDX-License-Identifier: (LGPL-2.1 OR BSD-2-Clause)
2 // Copyright (c) 2020 Wenbo Zhang
3 //
4 // Based on filelife(8) from BCC by Brendan Gregg & Allan McAleavy.
5 // 20-Mar-2020   Wenbo Zhang   Created this.
6 // 13-Nov-2022   Rong Tao      Check btf struct field for CO-RE and add vfs_open()
7 // 23-Aug-2023   Rong Tao      Add vfs_* 'struct mnt_idmap' support.(CO-RE)
8 #include <argp.h>
9 #include <signal.h>
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include <string.h>
13 #include <unistd.h>
14 #include <time.h>
15 #include <bpf/libbpf.h>
16 #include <bpf/bpf.h>
17 #include "filelife.h"
18 #include "filelife.skel.h"
19 #include "btf_helpers.h"
20 #include "trace_helpers.h"
21 
22 #define PERF_BUFFER_PAGES	16
23 #define PERF_POLL_TIMEOUT_MS	100
24 
25 static volatile sig_atomic_t exiting = 0;
26 
27 static struct env {
28 	pid_t pid;
29 	bool verbose;
30 } env = { };
31 
32 const char *argp_program_version = "filelife 0.1";
33 const char *argp_program_bug_address =
34 	"https://github.com/iovisor/bcc/tree/master/libbpf-tools";
35 const char argp_program_doc[] =
36 "Trace the lifespan of short-lived files.\n"
37 "\n"
38 "USAGE: filelife  [--help] [-p PID]\n"
39 "\n"
40 "EXAMPLES:\n"
41 "    filelife         # trace all events\n"
42 "    filelife -p 123  # trace pid 123\n";
43 
44 static const struct argp_option opts[] = {
45 	{ "pid", 'p', "PID", 0, "Process PID to trace" },
46 	{ "verbose", 'v', NULL, 0, "Verbose debug output" },
47 	{ NULL, 'h', NULL, OPTION_HIDDEN, "Show the full help" },
48 	{},
49 };
50 
parse_arg(int key,char * arg,struct argp_state * state)51 static error_t parse_arg(int key, char *arg, struct argp_state *state)
52 {
53 	int pid;
54 
55 	switch (key) {
56 	case 'h':
57 		argp_state_help(state, stderr, ARGP_HELP_STD_HELP);
58 		break;
59 	case 'v':
60 		env.verbose = true;
61 		break;
62 	case 'p':
63 		errno = 0;
64 		pid = strtol(arg, NULL, 10);
65 		if (errno || pid <= 0) {
66 			fprintf(stderr, "invalid PID: %s\n", arg);
67 			argp_usage(state);
68 		}
69 		env.pid = pid;
70 		break;
71 	default:
72 		return ARGP_ERR_UNKNOWN;
73 	}
74 	return 0;
75 }
76 
libbpf_print_fn(enum libbpf_print_level level,const char * format,va_list args)77 static int libbpf_print_fn(enum libbpf_print_level level, const char *format, va_list args)
78 {
79 	if (level == LIBBPF_DEBUG && !env.verbose)
80 		return 0;
81 	return vfprintf(stderr, format, args);
82 }
83 
sig_int(int signo)84 static void sig_int(int signo)
85 {
86 	exiting = 1;
87 }
88 
handle_event(void * ctx,int cpu,void * data,__u32 data_sz)89 void handle_event(void *ctx, int cpu, void *data, __u32 data_sz)
90 {
91 	const struct event *e = data;
92 	struct tm *tm;
93 	char ts[32];
94 	time_t t;
95 
96 	time(&t);
97 	tm = localtime(&t);
98 	strftime(ts, sizeof(ts), "%H:%M:%S", tm);
99 	printf("%-8s %-6d %-16s %-7.2f %s\n",
100 	       ts, e->tgid, e->task, (double)e->delta_ns / 1000000000,
101 	       e->file);
102 }
103 
handle_lost_events(void * ctx,int cpu,__u64 lost_cnt)104 void handle_lost_events(void *ctx, int cpu, __u64 lost_cnt)
105 {
106 	fprintf(stderr, "lost %llu events on CPU #%d\n", lost_cnt, cpu);
107 }
108 
main(int argc,char ** argv)109 int main(int argc, char **argv)
110 {
111 	LIBBPF_OPTS(bpf_object_open_opts, open_opts);
112 	static const struct argp argp = {
113 		.options = opts,
114 		.parser = parse_arg,
115 		.doc = argp_program_doc,
116 	};
117 	struct perf_buffer *pb = NULL;
118 	struct filelife_bpf *obj;
119 	int err;
120 
121 	err = argp_parse(&argp, argc, argv, 0, NULL, NULL);
122 	if (err)
123 		return err;
124 
125 	libbpf_set_print(libbpf_print_fn);
126 
127 	err = ensure_core_btf(&open_opts);
128 	if (err) {
129 		fprintf(stderr, "failed to fetch necessary BTF for CO-RE: %s\n", strerror(-err));
130 		return 1;
131 	}
132 
133 	obj = filelife_bpf__open_opts(&open_opts);
134 	if (!obj) {
135 		fprintf(stderr, "failed to open BPF object\n");
136 		return 1;
137 	}
138 
139 	/* initialize global data (filtering options) */
140 	obj->rodata->targ_tgid = env.pid;
141 
142 	if (!kprobe_exists("security_inode_create"))
143 		bpf_program__set_autoload(obj->progs.security_inode_create, false);
144 
145 	err = filelife_bpf__load(obj);
146 	if (err) {
147 		fprintf(stderr, "failed to load BPF object: %d\n", err);
148 		goto cleanup;
149 	}
150 
151 	err = filelife_bpf__attach(obj);
152 	if (err) {
153 		fprintf(stderr, "failed to attach BPF programs\n");
154 		goto cleanup;
155 	}
156 
157 	printf("Tracing the lifespan of short-lived files ... Hit Ctrl-C to end.\n");
158 	printf("%-8s %-6s %-16s %-7s %s\n", "TIME", "PID", "COMM", "AGE(s)", "FILE");
159 
160 	pb = perf_buffer__new(bpf_map__fd(obj->maps.events), PERF_BUFFER_PAGES,
161 			      handle_event, handle_lost_events, NULL, NULL);
162 	if (!pb) {
163 		err = -errno;
164 		fprintf(stderr, "failed to open perf buffer: %d\n", err);
165 		goto cleanup;
166 	}
167 
168 	if (signal(SIGINT, sig_int) == SIG_ERR) {
169 		fprintf(stderr, "can't set signal handler: %s\n", strerror(errno));
170 		err = 1;
171 		goto cleanup;
172 	}
173 
174 	while (!exiting) {
175 		err = perf_buffer__poll(pb, PERF_POLL_TIMEOUT_MS);
176 		if (err < 0 && err != -EINTR) {
177 			fprintf(stderr, "error polling perf buffer: %s\n", strerror(-err));
178 			goto cleanup;
179 		}
180 		/* reset err to return 0 if exiting */
181 		err = 0;
182 	}
183 
184 cleanup:
185 	perf_buffer__free(pb);
186 	filelife_bpf__destroy(obj);
187 	cleanup_core_btf(&open_opts);
188 
189 	return err != 0;
190 }
191