]>
Commit | Line | Data |
---|---|---|
595c3649 MH |
1 | perf-probe(1) |
2 | ============= | |
3 | ||
4 | NAME | |
5 | ---- | |
6 | perf-probe - Define new dynamic tracepoints | |
7 | ||
8 | SYNOPSIS | |
9 | -------- | |
10 | [verse] | |
c937fe20 | 11 | 'perf probe' [options] --add='PROBE' [...] |
c43f9d1e | 12 | or |
c937fe20 MH |
13 | 'perf probe' [options] PROBE |
14 | or | |
15 | 'perf probe' [options] --del='[GROUP:]EVENT' [...] | |
16 | or | |
b6a89643 | 17 | 'perf probe' --list[=[GROUP:]EVENT] |
631c9def | 18 | or |
e116dfa1 | 19 | 'perf probe' [options] --line='LINE' |
cf6eb489 | 20 | or |
469b9b88 | 21 | 'perf probe' [options] --vars='PROBEPOINT' |
b3ac032b MH |
22 | or |
23 | 'perf probe' [options] --funcs | |
1c20b1d1 MH |
24 | or |
25 | 'perf probe' [options] --definition='PROBE' [...] | |
595c3649 MH |
26 | |
27 | DESCRIPTION | |
28 | ----------- | |
29 | This command defines dynamic tracepoint events, by symbol and registers | |
30 | without debuginfo, or by C expressions (C line numbers, C function names, | |
31 | and C local variables) with debuginfo. | |
32 | ||
33 | ||
34 | OPTIONS | |
35 | ------- | |
36 | -k:: | |
c43f9d1e | 37 | --vmlinux=PATH:: |
595c3649 | 38 | Specify vmlinux path which has debuginfo (Dwarf binary). |
428aff82 MH |
39 | Only when using this with --definition, you can give an offline |
40 | vmlinux file. | |
595c3649 | 41 | |
469b9b88 | 42 | -m:: |
14a8fd7c | 43 | --module=MODNAME|PATH:: |
469b9b88 | 44 | Specify module name in which perf-probe searches probe points |
14a8fd7c MH |
45 | or lines. If a path of module file is passed, perf-probe |
46 | treat it as an offline module (this means you can add a probe on | |
47 | a module which has not been loaded yet). | |
469b9b88 | 48 | |
9ed7e1b8 CD |
49 | -s:: |
50 | --source=PATH:: | |
51 | Specify path to kernel source. | |
52 | ||
595c3649 MH |
53 | -v:: |
54 | --verbose:: | |
55 | Be more verbose (show parsed arguments, etc). | |
8b72805f MH |
56 | Can not use with -q. |
57 | ||
58 | -q:: | |
59 | --quiet:: | |
60 | Be quiet (do not show any messages including errors). | |
61 | Can not use with -v. | |
595c3649 | 62 | |
c43f9d1e | 63 | -a:: |
c937fe20 MH |
64 | --add=:: |
65 | Define a probe event (see PROBE SYNTAX for detail). | |
66 | ||
67 | -d:: | |
68 | --del=:: | |
ee391de8 MH |
69 | Delete probe events. This accepts glob wildcards('*', '?') and character |
70 | classes(e.g. [a-z], [!A-Z]). | |
c937fe20 MH |
71 | |
72 | -l:: | |
b6a89643 | 73 | --list[=[GROUP:]EVENT]:: |
1f3736c9 MH |
74 | List up current probe events. This can also accept filtering patterns of |
75 | event names. | |
76 | When this is used with --cache, perf shows all cached probes instead of | |
77 | the live probes. | |
595c3649 | 78 | |
631c9def MH |
79 | -L:: |
80 | --line=:: | |
81 | Show source code lines which can be probed. This needs an argument | |
ee391de8 MH |
82 | which specifies a range of the source code. (see LINE SYNTAX for detail) |
83 | ||
cf6eb489 MH |
84 | -V:: |
85 | --vars=:: | |
86 | Show available local variables at given probe point. The argument | |
87 | syntax is same as PROBE SYNTAX, but NO ARGs. | |
88 | ||
fb8c5a56 MH |
89 | --externs:: |
90 | (Only for --vars) Show external defined variables in addition to local | |
91 | variables. | |
92 | ||
6cfd1f68 MH |
93 | --no-inlines:: |
94 | (Only for --add) Search only for non-inlined functions. The functions | |
95 | which do not have instances are ignored. | |
96 | ||
e80711ca | 97 | -F:: |
9f7811d0 | 98 | --funcs[=FILTER]:: |
225466f1 SD |
99 | Show available functions in given module or kernel. With -x/--exec, |
100 | can also list functions in a user space executable / shared library. | |
9f7811d0 | 101 | This also can accept a FILTER rule argument. |
e80711ca | 102 | |
1c20b1d1 MH |
103 | -D:: |
104 | --definition=:: | |
105 | Show trace-event definition converted from given probe-event instead | |
106 | of write it into tracing/[k,u]probe_events. | |
107 | ||
bd09d7b5 | 108 | --filter=FILTER:: |
3c42258c MH |
109 | (Only for --vars and --funcs) Set filter. FILTER is a combination of glob |
110 | pattern, see FILTER PATTERN for detail. | |
111 | Default FILTER is "!__k???tab_* & !__crc_*" for --vars, and "!_*" | |
112 | for --funcs. | |
113 | If several filters are specified, only the last filter is used. | |
bd09d7b5 | 114 | |
ee391de8 MH |
115 | -f:: |
116 | --force:: | |
117 | Forcibly add events with existing name. | |
631c9def | 118 | |
f4d7da49 MH |
119 | -n:: |
120 | --dry-run:: | |
121 | Dry run. With this option, --add and --del doesn't execute actual | |
122 | adding and removal operations. | |
123 | ||
2fd457a3 | 124 | --cache:: |
1f3736c9 | 125 | (With --add) Cache the probes. Any events which successfully added |
2fd457a3 | 126 | are also stored in the cache file. |
1f3736c9 | 127 | (With --list) Show cached probes. |
4a0f65c1 | 128 | (With --del) Remove cached probes. |
2fd457a3 | 129 | |
8b72805f | 130 | --max-probes=NUM:: |
ef4a3565 MH |
131 | Set the maximum number of probe points for an event. Default is 128. |
132 | ||
544abd44 KJ |
133 | --target-ns=PID: |
134 | Obtain mount namespace information from the target pid. This is | |
135 | used when creating a uprobe for a process that resides in a | |
136 | different mount namespace from the perf(1) utility. | |
137 | ||
225466f1 SD |
138 | -x:: |
139 | --exec=PATH:: | |
140 | Specify path to the executable or shared library file for user | |
141 | space tracing. Can also be used with --funcs option. | |
142 | ||
8b72805f MH |
143 | --demangle:: |
144 | Demangle application symbols. --no-demangle is also available | |
145 | for disabling demangling. | |
146 | ||
763122ad | 147 | --demangle-kernel:: |
8b72805f MH |
148 | Demangle kernel symbols. --no-demangle-kernel is also available |
149 | for disabling kernel demangling. | |
763122ad | 150 | |
73eff9f5 SD |
151 | In absence of -m/-x options, perf probe checks if the first argument after |
152 | the options is an absolute path name. If its an absolute path, perf probe | |
153 | uses it as a target module/target user space binary to probe. | |
154 | ||
595c3649 MH |
155 | PROBE SYNTAX |
156 | ------------ | |
157 | Probe points are defined by following syntax. | |
158 | ||
2a9c8c36 | 159 | 1) Define event based on function name |
8d993d96 | 160 | [[GROUP:]EVENT=]FUNC[@SRC][:RLN|+OFFS|%return|;PTN] [ARG ...] |
2a9c8c36 MH |
161 | |
162 | 2) Define event based on source file with line number | |
8d993d96 | 163 | [[GROUP:]EVENT=]SRC:ALN [ARG ...] |
2a9c8c36 MH |
164 | |
165 | 3) Define event based on source file with lazy pattern | |
8d993d96 | 166 | [[GROUP:]EVENT=]SRC;PTN [ARG ...] |
2a9c8c36 | 167 | |
36a009fe | 168 | 4) Pre-defined SDT events or cached event with name |
7e9fca51 MH |
169 | %[sdt_PROVIDER:]SDTEVENT |
170 | or, | |
171 | sdt_PROVIDER:SDTEVENT | |
595c3649 | 172 | |
e63c625a | 173 | 'EVENT' specifies the name of new event, if omitted, it will be set the name of the probed function, and for return probes, a "\_\_return" suffix is automatically added to the function name. You can also specify a group name by 'GROUP', if omitted, set 'probe' is used for kprobe and 'probe_<bin>' is used for uprobe. |
8d993d96 MH |
174 | Note that using existing group name can conflict with other events. Especially, using the group name reserved for kernel modules can hide embedded events in the |
175 | modules. | |
2a9c8c36 MH |
176 | 'FUNC' specifies a probed function name, and it may have one of the following options; '+OFFS' is the offset from function entry address in bytes, ':RLN' is the relative-line number from function entry line, and '%return' means that it probes function return. And ';PTN' means lazy matching pattern (see LAZY MATCHING). Note that ';PTN' must be the end of the probe point definition. In addition, '@SRC' specifies a source file which has that function. |
177 | It is also possible to specify a probe point by the source line number or lazy matching by using 'SRC:ALN' or 'SRC;PTN' syntax, where 'SRC' is the source file path, ':ALN' is the line number and ';PTN' is the lazy matching pattern. | |
48481938 | 178 | 'ARG' specifies the arguments of this probe point, (see PROBE ARGUMENT). |
36a009fe MH |
179 | 'SDTEVENT' and 'PROVIDER' is the pre-defined event name which is defined by user SDT (Statically Defined Tracing) or the pre-cached probes with event name. |
180 | Note that before using the SDT event, the target binary (on which SDT events are defined) must be scanned by linkperf:perf-buildid-cache[1] to make SDT events as cached events. | |
181 | ||
182 | For details of the SDT, see below. | |
183 | https://sourceware.org/gdb/onlinedocs/gdb/Static-Probe-Points.html | |
48481938 | 184 | |
c588d158 MH |
185 | ESCAPED CHARACTER |
186 | ----------------- | |
187 | ||
188 | In the probe syntax, '=', '@', '+', ':' and ';' are treated as a special character. You can use a backslash ('\') to escape the special characters. | |
189 | This is useful if you need to probe on a specific versioned symbols, like @GLIBC_... suffixes, or also you need to specify a source file which includes the special characters. | |
190 | Note that usually single backslash is consumed by shell, so you might need to pass double backslash (\\) or wrapping with single quotes (\'AAA\@BBB'). | |
191 | See EXAMPLES how it is used. | |
192 | ||
48481938 MH |
193 | PROBE ARGUMENT |
194 | -------------- | |
195 | Each probe argument follows below syntax. | |
196 | ||
1e032f7c | 197 | [NAME=]LOCALVAR|$retval|%REG|@SYMBOL[:TYPE][@user] |
48481938 | 198 | |
b2a3c12b | 199 | 'NAME' specifies the name of this argument (optional). You can use the name of local variable, local data structure member (e.g. var->field, var.field2), local array with fixed index (e.g. array[1], var->array[0], var->pointer[2]), or kprobe-tracer argument format (e.g. $retval, %ax, etc). Note that the name of this argument will be set as the last member name if you specify a local data structure member (e.g. field2 for 'var->field1.field2'.) |
f8bffbf1 | 200 | '$vars' and '$params' special arguments are also available for NAME, '$vars' is expanded to the local variables (including function parameters) which can access at given probe point. '$params' is expanded to only the function parameters. |
bdca79c2 | 201 | 'TYPE' casts the type of this argument (optional). If omitted, perf probe automatically set the type based on debuginfo (*). Currently, basic types (u8/u16/u32/u64/s8/s16/s32/s64), hexadecimal integers (x/x8/x16/x32/x64), signedness casting (u/s), "string" and bitfield are supported. (see TYPES for detail) |
5b439820 | 202 | On x86 systems %REG is always the short form of the register: for example %AX. %RAX or %EAX is not valid. |
1e032f7c | 203 | "@user" is a special attribute which means the LOCALVAR will be treated as a user-space memory. This is only valid for kprobe event. |
5b439820 | 204 | |
19f00b01 NA |
205 | TYPES |
206 | ----- | |
bdca79c2 | 207 | Basic types (u8/u16/u32/u64/s8/s16/s32/s64) and hexadecimal integers (x8/x16/x32/x64) are integer types. Prefix 's' and 'u' means those types are signed and unsigned respectively, and 'x' means that is shown in hexadecimal format. Traced arguments are shown in decimal (sNN/uNN) or hex (xNN). You can also use 's' or 'u' to specify only signedness and leave its size auto-detected by perf probe. Moreover, you can use 'x' to explicitly specify to be shown in hexadecimal (the size is also auto-detected). |
19f00b01 NA |
208 | String type is a special type, which fetches a "null-terminated" string from kernel space. This means it will fail and store NULL if the string container has been paged out. You can specify 'string' type only for the local variable or structure member which is an array of or a pointer to 'char' or 'unsigned char' type. |
209 | Bitfield is another special type, which takes 3 parameters, bit-width, bit-offset, and container-size (usually 32). The syntax is; | |
210 | ||
211 | b<bit-width>@<bit-offset>/<container-size> | |
212 | ||
631c9def MH |
213 | LINE SYNTAX |
214 | ----------- | |
9d5b7f5b | 215 | Line range is described by following syntax. |
631c9def | 216 | |
e116dfa1 | 217 | "FUNC[@SRC][:RLN[+NUM|-RLN2]]|SRC[:ALN[+NUM|-ALN2]]" |
631c9def MH |
218 | |
219 | FUNC specifies the function name of showing lines. 'RLN' is the start line | |
220 | number from function entry line, and 'RLN2' is the end line number. As same as | |
221 | probe syntax, 'SRC' means the source file path, 'ALN' is start line number, | |
222 | and 'ALN2' is end line number in the file. It is also possible to specify how | |
e116dfa1 MH |
223 | many lines to show by using 'NUM'. Moreover, 'FUNC@SRC' combination is good |
224 | for searching a specific function when several functions share same name. | |
631c9def MH |
225 | So, "source.c:100-120" shows lines between 100th to l20th in source.c file. And "func:10+20" shows 20 lines from 10th line of func function. |
226 | ||
2a9c8c36 MH |
227 | LAZY MATCHING |
228 | ------------- | |
fe4f3eb1 | 229 | The lazy line matching is similar to glob matching but ignoring spaces in both of pattern and target. So this accepts wildcards('*', '?') and character classes(e.g. [a-z], [!A-Z]). |
2a9c8c36 MH |
230 | |
231 | e.g. | |
232 | 'a=*' can matches 'a=b', 'a = b', 'a == b' and so on. | |
233 | ||
234 | This provides some sort of flexibility and robustness to probe point definitions against minor code changes. For example, actual 10th line of schedule() can be moved easily by modifying schedule(), but the same line matching 'rq=cpu_rq*' may still exist in the function.) | |
235 | ||
bd09d7b5 MH |
236 | FILTER PATTERN |
237 | -------------- | |
fe4f3eb1 MH |
238 | The filter pattern is a glob matching pattern(s) to filter variables. |
239 | In addition, you can use "!" for specifying filter-out rule. You also can give several rules combined with "&" or "|", and fold those rules as one rule by using "(" ")". | |
bd09d7b5 MH |
240 | |
241 | e.g. | |
242 | With --filter "foo* | bar*", perf probe -V shows variables which start with "foo" or "bar". | |
243 | With --filter "!foo* & *bar", perf probe -V shows variables which don't start with "foo" and end with "bar", like "fizzbar". But "foobar" is filtered out. | |
2a9c8c36 | 244 | |
ee391de8 MH |
245 | EXAMPLES |
246 | -------- | |
247 | Display which lines in schedule() can be probed: | |
248 | ||
249 | ./perf probe --line schedule | |
250 | ||
251 | Add a probe on schedule() function 12th line with recording cpu local variable: | |
252 | ||
253 | ./perf probe schedule:12 cpu | |
254 | or | |
255 | ./perf probe --add='schedule:12 cpu' | |
256 | ||
d89269a8 | 257 | Add one or more probes which has the name start with "schedule". |
ee391de8 | 258 | |
d89269a8 SP |
259 | ./perf probe schedule* |
260 | or | |
261 | ./perf probe --add='schedule*' | |
262 | ||
263 | Add probes on lines in schedule() function which calls update_rq_clock(). | |
2a9c8c36 MH |
264 | |
265 | ./perf probe 'schedule;update_rq_clock*' | |
266 | or | |
267 | ./perf probe --add='schedule;update_rq_clock*' | |
268 | ||
ee391de8 MH |
269 | Delete all probes on schedule(). |
270 | ||
271 | ./perf probe --del='schedule*' | |
272 | ||
225466f1 SD |
273 | Add probes at zfree() function on /bin/zsh |
274 | ||
73eff9f5 | 275 | ./perf probe -x /bin/zsh zfree or ./perf probe /bin/zsh zfree |
225466f1 SD |
276 | |
277 | Add probes at malloc() function on libc | |
278 | ||
73eff9f5 | 279 | ./perf probe -x /lib/libc.so.6 malloc or ./perf probe /lib/libc.so.6 malloc |
ee391de8 | 280 | |
544abd44 KJ |
281 | Add a uprobe to a target process running in a different mount namespace |
282 | ||
283 | ./perf probe --target-ns <target pid> -x /lib64/libc.so.6 malloc | |
284 | ||
f045b8c4 KJ |
285 | Add a USDT probe to a target process running in a different mount namespace |
286 | ||
287 | ./perf probe --target-ns <target pid> -x /usr/lib/jvm/java-1.8.0-openjdk-1.8.0.121-0.b13.el7_3.x86_64/jre/lib/amd64/server/libjvm.so %sdt_hotspot:thread__sleep__end | |
288 | ||
c588d158 MH |
289 | Add a probe on specific versioned symbol by backslash escape |
290 | ||
291 | ./perf probe -x /lib64/libc-2.25.so 'malloc_get_state\@GLIBC_2.2.5' | |
292 | ||
293 | Add a probe in a source file using special characters by backslash escape | |
294 | ||
295 | ./perf probe -x /opt/test/a.out 'foo\+bar.c:4' | |
296 | ||
f045b8c4 | 297 | |
fe4f3eb1 MH |
298 | PERMISSIONS AND SYSCTL |
299 | ---------------------- | |
300 | Since perf probe depends on ftrace (tracefs) and kallsyms (/proc/kallsyms), you have to care about the permission and some sysctl knobs. | |
301 | ||
302 | - Since tracefs and kallsyms requires root or privileged user to access it, the following perf probe commands also require it; --add, --del, --list (except for --cache option) | |
303 | ||
304 | - The system admin can remount the tracefs with 755 (`sudo mount -o remount,mode=755 /sys/kernel/tracing/`) to allow unprivileged user to run the perf probe --list command. | |
305 | ||
306 | - /proc/sys/kernel/kptr_restrict = 2 (restrict all users) also prevents perf probe to retrieve the important information from kallsyms. You also need to set to 1 (restrict non CAP_SYSLOG users) for the above commands. Since the user-space probe doesn't need to access kallsyms, this is only for probing the kernel function (kprobes). | |
307 | ||
308 | - Since the perf probe commands read the vmlinux (for kernel) and/or the debuginfo file (including user-space application), you need to ensure that you can read those files. | |
309 | ||
310 | ||
595c3649 MH |
311 | SEE ALSO |
312 | -------- | |
36a009fe | 313 | linkperf:perf-trace[1], linkperf:perf-record[1], linkperf:perf-buildid-cache[1] |