ebpf_vfs.c 85 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include <sys/resource.h>
  3. #include "ebpf.h"
  4. #include "ebpf_vfs.h"
  5. static char *vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_END] = { "delete", "read", "write",
  6. "fsync", "open", "create" };
  7. static char *vfs_id_names[NETDATA_KEY_PUBLISH_VFS_END] = { "vfs_unlink", "vfs_read", "vfs_write",
  8. "vfs_fsync", "vfs_open", "vfs_create"};
  9. static netdata_idx_t *vfs_hash_values = NULL;
  10. static netdata_syscall_stat_t vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_END];
  11. static netdata_publish_syscall_t vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_END];
  12. netdata_publish_vfs_t *vfs_vector = NULL;
  13. static ebpf_local_maps_t vfs_maps[] = {{.name = "tbl_vfs_pid", .internal_input = ND_EBPF_DEFAULT_PID_SIZE,
  14. .user_input = 0, .type = NETDATA_EBPF_MAP_RESIZABLE | NETDATA_EBPF_MAP_PID,
  15. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  16. {.name = "tbl_vfs_stats", .internal_input = NETDATA_VFS_COUNTER,
  17. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  18. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  19. {.name = "vfs_ctrl", .internal_input = NETDATA_CONTROLLER_END,
  20. .user_input = 0,
  21. .type = NETDATA_EBPF_MAP_CONTROLLER,
  22. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  23. {.name = NULL, .internal_input = 0, .user_input = 0}};
  24. struct config vfs_config = { .first_section = NULL,
  25. .last_section = NULL,
  26. .mutex = NETDATA_MUTEX_INITIALIZER,
  27. .index = { .avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  28. .rwlock = AVL_LOCK_INITIALIZER } };
  29. netdata_ebpf_targets_t vfs_targets[] = { {.name = "vfs_write", .mode = EBPF_LOAD_TRAMPOLINE},
  30. {.name = "vfs_writev", .mode = EBPF_LOAD_TRAMPOLINE},
  31. {.name = "vfs_read", .mode = EBPF_LOAD_TRAMPOLINE},
  32. {.name = "vfs_readv", .mode = EBPF_LOAD_TRAMPOLINE},
  33. {.name = "vfs_unlink", .mode = EBPF_LOAD_TRAMPOLINE},
  34. {.name = "vfs_fsync", .mode = EBPF_LOAD_TRAMPOLINE},
  35. {.name = "vfs_open", .mode = EBPF_LOAD_TRAMPOLINE},
  36. {.name = "vfs_create", .mode = EBPF_LOAD_TRAMPOLINE},
  37. {.name = "release_task", .mode = EBPF_LOAD_TRAMPOLINE},
  38. {.name = NULL, .mode = EBPF_LOAD_TRAMPOLINE}};
  39. #ifdef LIBBPF_MAJOR_VERSION
  40. /**
  41. * Disable probe
  42. *
  43. * Disable all probes to use exclusively another method.
  44. *
  45. * @param obj is the main structure for bpf objects
  46. */
  47. static void ebpf_vfs_disable_probes(struct vfs_bpf *obj)
  48. {
  49. bpf_program__set_autoload(obj->progs.netdata_vfs_write_kprobe, false);
  50. bpf_program__set_autoload(obj->progs.netdata_vfs_write_kretprobe, false);
  51. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_kprobe, false);
  52. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_kretprobe, false);
  53. bpf_program__set_autoload(obj->progs.netdata_vfs_read_kprobe, false);
  54. bpf_program__set_autoload(obj->progs.netdata_vfs_read_kretprobe, false);
  55. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_kprobe, false);
  56. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_kretprobe, false);
  57. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_kprobe, false);
  58. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_kretprobe, false);
  59. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_kprobe, false);
  60. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_kretprobe, false);
  61. bpf_program__set_autoload(obj->progs.netdata_vfs_open_kprobe, false);
  62. bpf_program__set_autoload(obj->progs.netdata_vfs_open_kretprobe, false);
  63. bpf_program__set_autoload(obj->progs.netdata_vfs_create_kprobe, false);
  64. bpf_program__set_autoload(obj->progs.netdata_vfs_create_kretprobe, false);
  65. bpf_program__set_autoload(obj->progs.netdata_vfs_release_task_kprobe, false);
  66. }
  67. /*
  68. * Disable trampoline
  69. *
  70. * Disable all trampoline to use exclusively another method.
  71. *
  72. * @param obj is the main structure for bpf objects.
  73. */
  74. static void ebpf_vfs_disable_trampoline(struct vfs_bpf *obj)
  75. {
  76. bpf_program__set_autoload(obj->progs.netdata_vfs_write_fentry, false);
  77. bpf_program__set_autoload(obj->progs.netdata_vfs_write_fexit, false);
  78. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_fentry, false);
  79. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_fexit, false);
  80. bpf_program__set_autoload(obj->progs.netdata_vfs_read_fentry, false);
  81. bpf_program__set_autoload(obj->progs.netdata_vfs_read_fexit, false);
  82. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_fentry, false);
  83. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_fexit, false);
  84. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_fentry, false);
  85. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_fentry, false);
  86. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_fexit, false);
  87. bpf_program__set_autoload(obj->progs.netdata_vfs_open_fentry, false);
  88. bpf_program__set_autoload(obj->progs.netdata_vfs_open_fexit, false);
  89. bpf_program__set_autoload(obj->progs.netdata_vfs_create_fentry, false);
  90. bpf_program__set_autoload(obj->progs.netdata_vfs_release_task_fentry, false);
  91. }
  92. /**
  93. * Set trampoline target
  94. *
  95. * Set the targets we will monitor.
  96. *
  97. * @param obj is the main structure for bpf objects.
  98. */
  99. static void ebpf_vfs_set_trampoline_target(struct vfs_bpf *obj)
  100. {
  101. bpf_program__set_attach_target(obj->progs.netdata_vfs_write_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  102. bpf_program__set_attach_target(obj->progs.netdata_vfs_write_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  103. bpf_program__set_attach_target(obj->progs.netdata_vfs_writev_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  104. bpf_program__set_attach_target(obj->progs.netdata_vfs_writev_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  105. bpf_program__set_attach_target(obj->progs.netdata_vfs_read_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_READ].name);
  106. bpf_program__set_attach_target(obj->progs.netdata_vfs_read_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_READ].name);
  107. bpf_program__set_attach_target(obj->progs.netdata_vfs_readv_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_READV].name);
  108. bpf_program__set_attach_target(obj->progs.netdata_vfs_readv_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_READV].name);
  109. bpf_program__set_attach_target(obj->progs.netdata_vfs_unlink_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  110. bpf_program__set_attach_target(obj->progs.netdata_vfs_fsync_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  111. bpf_program__set_attach_target(obj->progs.netdata_vfs_fsync_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  112. bpf_program__set_attach_target(obj->progs.netdata_vfs_open_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  113. bpf_program__set_attach_target(obj->progs.netdata_vfs_open_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  114. bpf_program__set_attach_target(obj->progs.netdata_vfs_create_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  115. bpf_program__set_attach_target(obj->progs.netdata_vfs_release_task_fentry, 0, EBPF_COMMON_FNCT_CLEAN_UP);
  116. }
  117. /**
  118. * Attach Probe
  119. *
  120. * Attach probes to target
  121. *
  122. * @param obj is the main structure for bpf objects.
  123. *
  124. * @return It returns 0 on success and -1 otherwise.
  125. */
  126. static int ebpf_vfs_attach_probe(struct vfs_bpf *obj)
  127. {
  128. obj->links.netdata_vfs_write_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_write_kprobe, false,
  129. vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  130. int ret = libbpf_get_error(obj->links.netdata_vfs_write_kprobe);
  131. if (ret)
  132. return -1;
  133. obj->links.netdata_vfs_write_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_write_kretprobe, true,
  134. vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  135. ret = libbpf_get_error(obj->links.netdata_vfs_write_kretprobe);
  136. if (ret)
  137. return -1;
  138. obj->links.netdata_vfs_writev_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_writev_kprobe, false,
  139. vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  140. ret = libbpf_get_error(obj->links.netdata_vfs_writev_kprobe);
  141. if (ret)
  142. return -1;
  143. obj->links.netdata_vfs_writev_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_writev_kretprobe, true,
  144. vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  145. ret = libbpf_get_error(obj->links.netdata_vfs_writev_kretprobe);
  146. if (ret)
  147. return -1;
  148. obj->links.netdata_vfs_read_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_read_kprobe, false,
  149. vfs_targets[NETDATA_EBPF_VFS_READ].name);
  150. ret = libbpf_get_error(obj->links.netdata_vfs_read_kprobe);
  151. if (ret)
  152. return -1;
  153. obj->links.netdata_vfs_read_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_read_kretprobe, true,
  154. vfs_targets[NETDATA_EBPF_VFS_READ].name);
  155. ret = libbpf_get_error(obj->links.netdata_vfs_read_kretprobe);
  156. if (ret)
  157. return -1;
  158. obj->links.netdata_vfs_readv_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_readv_kprobe, false,
  159. vfs_targets[NETDATA_EBPF_VFS_READV].name);
  160. ret = libbpf_get_error(obj->links.netdata_vfs_readv_kprobe);
  161. if (ret)
  162. return -1;
  163. obj->links.netdata_vfs_readv_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_readv_kretprobe, true,
  164. vfs_targets[NETDATA_EBPF_VFS_READV].name);
  165. ret = libbpf_get_error(obj->links.netdata_vfs_readv_kretprobe);
  166. if (ret)
  167. return -1;
  168. obj->links.netdata_vfs_unlink_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_unlink_kprobe, false,
  169. vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  170. ret = libbpf_get_error(obj->links.netdata_vfs_unlink_kprobe);
  171. if (ret)
  172. return -1;
  173. obj->links.netdata_vfs_unlink_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_unlink_kretprobe, true,
  174. vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  175. ret = libbpf_get_error(obj->links.netdata_vfs_unlink_kretprobe);
  176. if (ret)
  177. return -1;
  178. obj->links.netdata_vfs_fsync_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kprobe, false,
  179. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  180. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kprobe);
  181. if (ret)
  182. return -1;
  183. obj->links.netdata_vfs_fsync_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kretprobe, true,
  184. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  185. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kretprobe);
  186. if (ret)
  187. return -1;
  188. obj->links.netdata_vfs_open_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kprobe, false,
  189. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  190. ret = libbpf_get_error(obj->links.netdata_vfs_open_kprobe);
  191. if (ret)
  192. return -1;
  193. obj->links.netdata_vfs_open_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kretprobe, true,
  194. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  195. ret = libbpf_get_error(obj->links.netdata_vfs_open_kretprobe);
  196. if (ret)
  197. return -1;
  198. obj->links.netdata_vfs_create_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kprobe, false,
  199. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  200. ret = libbpf_get_error(obj->links.netdata_vfs_create_kprobe);
  201. if (ret)
  202. return -1;
  203. obj->links.netdata_vfs_create_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kretprobe, true,
  204. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  205. ret = libbpf_get_error(obj->links.netdata_vfs_create_kretprobe);
  206. if (ret)
  207. return -1;
  208. obj->links.netdata_vfs_fsync_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kprobe, false,
  209. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  210. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kprobe);
  211. if (ret)
  212. return -1;
  213. obj->links.netdata_vfs_fsync_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kretprobe, true,
  214. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  215. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kretprobe);
  216. if (ret)
  217. return -1;
  218. obj->links.netdata_vfs_open_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kprobe, false,
  219. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  220. ret = libbpf_get_error(obj->links.netdata_vfs_open_kprobe);
  221. if (ret)
  222. return -1;
  223. obj->links.netdata_vfs_open_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kretprobe, true,
  224. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  225. ret = libbpf_get_error(obj->links.netdata_vfs_open_kretprobe);
  226. if (ret)
  227. return -1;
  228. obj->links.netdata_vfs_create_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kprobe, false,
  229. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  230. ret = libbpf_get_error(obj->links.netdata_vfs_create_kprobe);
  231. if (ret)
  232. return -1;
  233. obj->links.netdata_vfs_create_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kretprobe, true,
  234. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  235. ret = libbpf_get_error(obj->links.netdata_vfs_create_kretprobe);
  236. if (ret)
  237. return -1;
  238. obj->links.netdata_vfs_release_task_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_release_task_fentry,
  239. true,
  240. EBPF_COMMON_FNCT_CLEAN_UP);
  241. ret = libbpf_get_error(obj->links.netdata_vfs_release_task_kprobe);
  242. if (ret)
  243. return -1;
  244. return 0;
  245. }
  246. /**
  247. * Adjust Map Size
  248. *
  249. * Resize maps according input from users.
  250. *
  251. * @param obj is the main structure for bpf objects.
  252. * @param em structure with configuration
  253. */
  254. static void ebpf_vfs_adjust_map_size(struct vfs_bpf *obj, ebpf_module_t *em)
  255. {
  256. ebpf_update_map_size(obj->maps.tbl_vfs_pid, &vfs_maps[NETDATA_VFS_PID],
  257. em, bpf_map__name(obj->maps.tbl_vfs_pid));
  258. }
  259. /**
  260. * Set hash tables
  261. *
  262. * Set the values for maps according the value given by kernel.
  263. *
  264. * @param obj is the main structure for bpf objects.
  265. */
  266. static void ebpf_vfs_set_hash_tables(struct vfs_bpf *obj)
  267. {
  268. vfs_maps[NETDATA_VFS_ALL].map_fd = bpf_map__fd(obj->maps.tbl_vfs_stats);
  269. vfs_maps[NETDATA_VFS_PID].map_fd = bpf_map__fd(obj->maps.tbl_vfs_pid);
  270. vfs_maps[NETDATA_VFS_CTRL].map_fd = bpf_map__fd(obj->maps.vfs_ctrl);
  271. }
  272. /**
  273. * Disable Release Task
  274. *
  275. * Disable release task when apps is not enabled.
  276. *
  277. * @param obj is the main structure for bpf objects.
  278. */
  279. static void ebpf_vfs_disable_release_task(struct vfs_bpf *obj)
  280. {
  281. bpf_program__set_autoload(obj->progs.netdata_vfs_release_task_fentry, false);
  282. bpf_program__set_autoload(obj->progs.netdata_vfs_release_task_kprobe, false);
  283. }
  284. /**
  285. * Load and attach
  286. *
  287. * Load and attach the eBPF code in kernel.
  288. *
  289. * @param obj is the main structure for bpf objects.
  290. * @param em structure with configuration
  291. *
  292. * @return it returns 0 on success and -1 otherwise
  293. */
  294. static inline int ebpf_vfs_load_and_attach(struct vfs_bpf *obj, ebpf_module_t *em)
  295. {
  296. netdata_ebpf_targets_t *mt = em->targets;
  297. netdata_ebpf_program_loaded_t test = mt[NETDATA_EBPF_VFS_WRITE].mode;
  298. if (test == EBPF_LOAD_TRAMPOLINE) {
  299. ebpf_vfs_disable_probes(obj);
  300. ebpf_vfs_set_trampoline_target(obj);
  301. } else {
  302. ebpf_vfs_disable_trampoline(obj);
  303. }
  304. ebpf_vfs_adjust_map_size(obj, em);
  305. if (!em->apps_charts && !em->cgroup_charts)
  306. ebpf_vfs_disable_release_task(obj);
  307. int ret = vfs_bpf__load(obj);
  308. if (ret) {
  309. return ret;
  310. }
  311. ret = (test == EBPF_LOAD_TRAMPOLINE) ? vfs_bpf__attach(obj) : ebpf_vfs_attach_probe(obj);
  312. if (!ret) {
  313. ebpf_vfs_set_hash_tables(obj);
  314. ebpf_update_controller(vfs_maps[NETDATA_VFS_CTRL].map_fd, em);
  315. }
  316. return ret;
  317. }
  318. #endif
  319. /*****************************************************************
  320. *
  321. * FUNCTIONS TO CLOSE THE THREAD
  322. *
  323. *****************************************************************/
  324. /**
  325. * Cachestat Free
  326. *
  327. * Cleanup variables after child threads to stop
  328. *
  329. * @param ptr thread data.
  330. */
  331. static void ebpf_vfs_free(ebpf_module_t *em)
  332. {
  333. freez(vfs_hash_values);
  334. freez(vfs_vector);
  335. pthread_mutex_lock(&ebpf_exit_cleanup);
  336. em->enabled = NETDATA_THREAD_EBPF_STOPPED;
  337. pthread_mutex_unlock(&ebpf_exit_cleanup);
  338. }
  339. /**
  340. * Exit
  341. *
  342. * Cancel thread and exit.
  343. *
  344. * @param ptr thread data.
  345. **/
  346. static void ebpf_vfs_exit(void *ptr)
  347. {
  348. ebpf_module_t *em = (ebpf_module_t *)ptr;
  349. ebpf_vfs_free(em);
  350. }
  351. /*****************************************************************
  352. *
  353. * FUNCTIONS WITH THE MAIN LOOP
  354. *
  355. *****************************************************************/
  356. /**
  357. * Send data to Netdata calling auxiliary functions.
  358. *
  359. * @param em the structure with thread information
  360. */
  361. static void ebpf_vfs_send_data(ebpf_module_t *em)
  362. {
  363. netdata_publish_vfs_common_t pvc;
  364. pvc.write = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes;
  365. pvc.read = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes;
  366. write_count_chart(NETDATA_VFS_FILE_CLEAN_COUNT, NETDATA_FILESYSTEM_FAMILY,
  367. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK], 1);
  368. write_count_chart(NETDATA_VFS_FILE_IO_COUNT, NETDATA_FILESYSTEM_FAMILY,
  369. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  370. if (em->mode < MODE_ENTRY) {
  371. write_err_chart(NETDATA_VFS_FILE_ERR_COUNT, NETDATA_FILESYSTEM_FAMILY,
  372. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  373. }
  374. write_io_chart(NETDATA_VFS_IO_FILE_BYTES, NETDATA_FILESYSTEM_FAMILY, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  375. (long long)pvc.write, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ], (long long)pvc.read);
  376. write_count_chart(NETDATA_VFS_FSYNC, NETDATA_FILESYSTEM_FAMILY,
  377. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  378. if (em->mode < MODE_ENTRY) {
  379. write_err_chart(NETDATA_VFS_FSYNC_ERR, NETDATA_FILESYSTEM_FAMILY,
  380. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  381. }
  382. write_count_chart(NETDATA_VFS_OPEN, NETDATA_FILESYSTEM_FAMILY,
  383. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  384. if (em->mode < MODE_ENTRY) {
  385. write_err_chart(NETDATA_VFS_OPEN_ERR, NETDATA_FILESYSTEM_FAMILY,
  386. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  387. }
  388. write_count_chart(NETDATA_VFS_CREATE, NETDATA_FILESYSTEM_FAMILY,
  389. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE], 1);
  390. if (em->mode < MODE_ENTRY) {
  391. write_err_chart(
  392. NETDATA_VFS_CREATE_ERR,
  393. NETDATA_FILESYSTEM_FAMILY,
  394. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  395. 1);
  396. }
  397. }
  398. /**
  399. * Read the hash table and store data to allocated vectors.
  400. */
  401. static void ebpf_vfs_read_global_table()
  402. {
  403. uint64_t idx;
  404. netdata_idx_t res[NETDATA_VFS_COUNTER];
  405. netdata_idx_t *val = vfs_hash_values;
  406. int fd = vfs_maps[NETDATA_VFS_ALL].map_fd;
  407. for (idx = 0; idx < NETDATA_VFS_COUNTER; idx++) {
  408. uint64_t total = 0;
  409. if (!bpf_map_lookup_elem(fd, &idx, val)) {
  410. int i;
  411. int end = ebpf_nprocs;
  412. for (i = 0; i < end; i++)
  413. total += val[i];
  414. }
  415. res[idx] = total;
  416. }
  417. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].ncall = res[NETDATA_KEY_CALLS_VFS_UNLINK];
  418. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].ncall = res[NETDATA_KEY_CALLS_VFS_READ] +
  419. res[NETDATA_KEY_CALLS_VFS_READV];
  420. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].ncall = res[NETDATA_KEY_CALLS_VFS_WRITE] +
  421. res[NETDATA_KEY_CALLS_VFS_WRITEV];
  422. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].ncall = res[NETDATA_KEY_CALLS_VFS_FSYNC];
  423. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].ncall = res[NETDATA_KEY_CALLS_VFS_OPEN];
  424. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].ncall = res[NETDATA_KEY_CALLS_VFS_CREATE];
  425. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].nerr = res[NETDATA_KEY_ERROR_VFS_UNLINK];
  426. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].nerr = res[NETDATA_KEY_ERROR_VFS_READ] +
  427. res[NETDATA_KEY_ERROR_VFS_READV];
  428. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].nerr = res[NETDATA_KEY_ERROR_VFS_WRITE] +
  429. res[NETDATA_KEY_ERROR_VFS_WRITEV];
  430. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].nerr = res[NETDATA_KEY_ERROR_VFS_FSYNC];
  431. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].nerr = res[NETDATA_KEY_ERROR_VFS_OPEN];
  432. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].nerr = res[NETDATA_KEY_ERROR_VFS_CREATE];
  433. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITE] +
  434. (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITEV];
  435. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_READ] +
  436. (uint64_t)res[NETDATA_KEY_BYTES_VFS_READV];
  437. }
  438. /**
  439. * Sum PIDs
  440. *
  441. * Sum values for all targets.
  442. *
  443. * @param swap output structure
  444. * @param root link list with structure to be used
  445. */
  446. static void ebpf_vfs_sum_pids(netdata_publish_vfs_t *vfs, struct ebpf_pid_on_target *root)
  447. {
  448. netdata_publish_vfs_t accumulator;
  449. memset(&accumulator, 0, sizeof(accumulator));
  450. while (root) {
  451. int32_t pid = root->pid;
  452. netdata_publish_vfs_t *w = vfs_pid[pid];
  453. if (w) {
  454. accumulator.write_call += w->write_call;
  455. accumulator.writev_call += w->writev_call;
  456. accumulator.read_call += w->read_call;
  457. accumulator.readv_call += w->readv_call;
  458. accumulator.unlink_call += w->unlink_call;
  459. accumulator.fsync_call += w->fsync_call;
  460. accumulator.open_call += w->open_call;
  461. accumulator.create_call += w->create_call;
  462. accumulator.write_bytes += w->write_bytes;
  463. accumulator.writev_bytes += w->writev_bytes;
  464. accumulator.read_bytes += w->read_bytes;
  465. accumulator.readv_bytes += w->readv_bytes;
  466. accumulator.write_err += w->write_err;
  467. accumulator.writev_err += w->writev_err;
  468. accumulator.read_err += w->read_err;
  469. accumulator.readv_err += w->readv_err;
  470. accumulator.unlink_err += w->unlink_err;
  471. accumulator.fsync_err += w->fsync_err;
  472. accumulator.open_err += w->open_err;
  473. accumulator.create_err += w->create_err;
  474. }
  475. root = root->next;
  476. }
  477. // These conditions were added, because we are using incremental algorithm
  478. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  479. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  480. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  481. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  482. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  483. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  484. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  485. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  486. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  487. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  488. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  489. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  490. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  491. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  492. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  493. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  494. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  495. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  496. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  497. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  498. }
  499. /**
  500. * Send data to Netdata calling auxiliary functions.
  501. *
  502. * @param em the structure with thread information
  503. * @param root the target list.
  504. */
  505. void ebpf_vfs_send_apps_data(ebpf_module_t *em, struct ebpf_target *root)
  506. {
  507. struct ebpf_target *w;
  508. for (w = root; w; w = w->next) {
  509. if (unlikely(w->exposed && w->processes)) {
  510. ebpf_vfs_sum_pids(&w->vfs, w->root_pid);
  511. }
  512. }
  513. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED);
  514. for (w = root; w; w = w->next) {
  515. if (unlikely(w->exposed && w->processes)) {
  516. write_chart_dimension(w->name, w->vfs.unlink_call);
  517. }
  518. }
  519. write_end_chart();
  520. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  521. for (w = root; w; w = w->next) {
  522. if (unlikely(w->exposed && w->processes)) {
  523. write_chart_dimension(w->name, w->vfs.write_call + w->vfs.writev_call);
  524. }
  525. }
  526. write_end_chart();
  527. if (em->mode < MODE_ENTRY) {
  528. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  529. for (w = root; w; w = w->next) {
  530. if (unlikely(w->exposed && w->processes)) {
  531. write_chart_dimension(w->name, w->vfs.write_err + w->vfs.writev_err);
  532. }
  533. }
  534. write_end_chart();
  535. }
  536. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  537. for (w = root; w; w = w->next) {
  538. if (unlikely(w->exposed && w->processes)) {
  539. write_chart_dimension(w->name, w->vfs.read_call + w->vfs.readv_call);
  540. }
  541. }
  542. write_end_chart();
  543. if (em->mode < MODE_ENTRY) {
  544. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  545. for (w = root; w; w = w->next) {
  546. if (unlikely(w->exposed && w->processes)) {
  547. write_chart_dimension(w->name, w->vfs.read_err + w->vfs.readv_err);
  548. }
  549. }
  550. write_end_chart();
  551. }
  552. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  553. for (w = root; w; w = w->next) {
  554. if (unlikely(w->exposed && w->processes)) {
  555. write_chart_dimension(w->name, w->vfs.write_bytes + w->vfs.writev_bytes);
  556. }
  557. }
  558. write_end_chart();
  559. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  560. for (w = root; w; w = w->next) {
  561. if (unlikely(w->exposed && w->processes)) {
  562. write_chart_dimension(w->name, w->vfs.read_bytes + w->vfs.readv_bytes);
  563. }
  564. }
  565. write_end_chart();
  566. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  567. for (w = root; w; w = w->next) {
  568. if (unlikely(w->exposed && w->processes)) {
  569. write_chart_dimension(w->name, w->vfs.fsync_call);
  570. }
  571. }
  572. write_end_chart();
  573. if (em->mode < MODE_ENTRY) {
  574. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  575. for (w = root; w; w = w->next) {
  576. if (unlikely(w->exposed && w->processes)) {
  577. write_chart_dimension(w->name, w->vfs.fsync_err);
  578. }
  579. }
  580. write_end_chart();
  581. }
  582. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN);
  583. for (w = root; w; w = w->next) {
  584. if (unlikely(w->exposed && w->processes)) {
  585. write_chart_dimension(w->name, w->vfs.open_call);
  586. }
  587. }
  588. write_end_chart();
  589. if (em->mode < MODE_ENTRY) {
  590. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  591. for (w = root; w; w = w->next) {
  592. if (unlikely(w->exposed && w->processes)) {
  593. write_chart_dimension(w->name, w->vfs.open_err);
  594. }
  595. }
  596. write_end_chart();
  597. }
  598. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE);
  599. for (w = root; w; w = w->next) {
  600. if (unlikely(w->exposed && w->processes)) {
  601. write_chart_dimension(w->name, w->vfs.create_call);
  602. }
  603. }
  604. write_end_chart();
  605. if (em->mode < MODE_ENTRY) {
  606. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  607. for (w = root; w; w = w->next) {
  608. if (unlikely(w->exposed && w->processes)) {
  609. write_chart_dimension(w->name, w->vfs.create_err);
  610. }
  611. }
  612. write_end_chart();
  613. }
  614. }
  615. /**
  616. * Apps Accumulator
  617. *
  618. * Sum all values read from kernel and store in the first address.
  619. *
  620. * @param out the vector with read values.
  621. */
  622. static void vfs_apps_accumulator(netdata_publish_vfs_t *out)
  623. {
  624. int i, end = (running_on_kernel >= NETDATA_KERNEL_V4_15) ? ebpf_nprocs : 1;
  625. netdata_publish_vfs_t *total = &out[0];
  626. for (i = 1; i < end; i++) {
  627. netdata_publish_vfs_t *w = &out[i];
  628. total->write_call += w->write_call;
  629. total->writev_call += w->writev_call;
  630. total->read_call += w->read_call;
  631. total->readv_call += w->readv_call;
  632. total->unlink_call += w->unlink_call;
  633. total->write_bytes += w->write_bytes;
  634. total->writev_bytes += w->writev_bytes;
  635. total->read_bytes += w->read_bytes;
  636. total->readv_bytes += w->readv_bytes;
  637. total->write_err += w->write_err;
  638. total->writev_err += w->writev_err;
  639. total->read_err += w->read_err;
  640. total->readv_err += w->readv_err;
  641. total->unlink_err += w->unlink_err;
  642. }
  643. }
  644. /**
  645. * Fill PID
  646. *
  647. * Fill PID structures
  648. *
  649. * @param current_pid pid that we are collecting data
  650. * @param out values read from hash tables;
  651. */
  652. static void vfs_fill_pid(uint32_t current_pid, netdata_publish_vfs_t *publish)
  653. {
  654. netdata_publish_vfs_t *curr = vfs_pid[current_pid];
  655. if (!curr) {
  656. curr = ebpf_vfs_get();
  657. vfs_pid[current_pid] = curr;
  658. }
  659. memcpy(curr, &publish[0], sizeof(netdata_publish_vfs_t));
  660. }
  661. /**
  662. * Read the hash table and store data to allocated vectors.
  663. */
  664. static void ebpf_vfs_read_apps()
  665. {
  666. struct ebpf_pid_stat *pids = ebpf_root_of_pids;
  667. netdata_publish_vfs_t *vv = vfs_vector;
  668. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  669. size_t length = sizeof(netdata_publish_vfs_t) * ebpf_nprocs;
  670. while (pids) {
  671. uint32_t key = pids->pid;
  672. if (bpf_map_lookup_elem(fd, &key, vv)) {
  673. pids = pids->next;
  674. continue;
  675. }
  676. vfs_apps_accumulator(vv);
  677. vfs_fill_pid(key, vv);
  678. // We are cleaning to avoid passing data read from one process to other.
  679. memset(vv, 0, length);
  680. pids = pids->next;
  681. }
  682. }
  683. /**
  684. * Update cgroup
  685. *
  686. * Update cgroup data based in
  687. */
  688. static void read_update_vfs_cgroup()
  689. {
  690. ebpf_cgroup_target_t *ect ;
  691. netdata_publish_vfs_t *vv = vfs_vector;
  692. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  693. size_t length = sizeof(netdata_publish_vfs_t) * ebpf_nprocs;
  694. pthread_mutex_lock(&mutex_cgroup_shm);
  695. for (ect = ebpf_cgroup_pids; ect; ect = ect->next) {
  696. struct pid_on_target2 *pids;
  697. for (pids = ect->pids; pids; pids = pids->next) {
  698. int pid = pids->pid;
  699. netdata_publish_vfs_t *out = &pids->vfs;
  700. if (likely(vfs_pid) && vfs_pid[pid]) {
  701. netdata_publish_vfs_t *in = vfs_pid[pid];
  702. memcpy(out, in, sizeof(netdata_publish_vfs_t));
  703. } else {
  704. memset(vv, 0, length);
  705. if (!bpf_map_lookup_elem(fd, &pid, vv)) {
  706. vfs_apps_accumulator(vv);
  707. memcpy(out, vv, sizeof(netdata_publish_vfs_t));
  708. }
  709. }
  710. }
  711. }
  712. pthread_mutex_unlock(&mutex_cgroup_shm);
  713. }
  714. /**
  715. * Sum PIDs
  716. *
  717. * Sum values for all targets.
  718. *
  719. * @param vfs structure used to store data
  720. * @param pids input data
  721. */
  722. static void ebpf_vfs_sum_cgroup_pids(netdata_publish_vfs_t *vfs, struct pid_on_target2 *pids)
  723. {
  724. netdata_publish_vfs_t accumulator;
  725. memset(&accumulator, 0, sizeof(accumulator));
  726. while (pids) {
  727. netdata_publish_vfs_t *w = &pids->vfs;
  728. accumulator.write_call += w->write_call;
  729. accumulator.writev_call += w->writev_call;
  730. accumulator.read_call += w->read_call;
  731. accumulator.readv_call += w->readv_call;
  732. accumulator.unlink_call += w->unlink_call;
  733. accumulator.fsync_call += w->fsync_call;
  734. accumulator.open_call += w->open_call;
  735. accumulator.create_call += w->create_call;
  736. accumulator.write_bytes += w->write_bytes;
  737. accumulator.writev_bytes += w->writev_bytes;
  738. accumulator.read_bytes += w->read_bytes;
  739. accumulator.readv_bytes += w->readv_bytes;
  740. accumulator.write_err += w->write_err;
  741. accumulator.writev_err += w->writev_err;
  742. accumulator.read_err += w->read_err;
  743. accumulator.readv_err += w->readv_err;
  744. accumulator.unlink_err += w->unlink_err;
  745. accumulator.fsync_err += w->fsync_err;
  746. accumulator.open_err += w->open_err;
  747. accumulator.create_err += w->create_err;
  748. pids = pids->next;
  749. }
  750. // These conditions were added, because we are using incremental algorithm
  751. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  752. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  753. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  754. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  755. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  756. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  757. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  758. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  759. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  760. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  761. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  762. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  763. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  764. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  765. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  766. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  767. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  768. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  769. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  770. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  771. }
  772. /**
  773. * Create specific VFS charts
  774. *
  775. * Create charts for cgroup/application.
  776. *
  777. * @param type the chart type.
  778. * @param em the main thread structure.
  779. */
  780. static void ebpf_create_specific_vfs_charts(char *type, ebpf_module_t *em)
  781. {
  782. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED,"Files deleted",
  783. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  784. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500,
  785. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  786. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  787. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  788. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  789. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501,
  790. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  791. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  792. if (em->mode < MODE_ENTRY) {
  793. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  794. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  795. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502,
  796. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  797. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  798. }
  799. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  800. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_CONTEXT,
  801. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503,
  802. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  803. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  804. if (em->mode < MODE_ENTRY) {
  805. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  806. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  807. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504,
  808. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  809. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  810. }
  811. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  812. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  813. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505,
  814. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  815. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  816. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  817. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  818. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506,
  819. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  820. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  821. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls for <code>vfs_fsync</code>",
  822. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  823. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507,
  824. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  825. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  826. if (em->mode < MODE_ENTRY) {
  827. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  828. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  829. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508,
  830. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  831. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  832. }
  833. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls for <code>vfs_open</code>",
  834. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  835. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509,
  836. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  837. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  838. if (em->mode < MODE_ENTRY) {
  839. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  840. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  841. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510,
  842. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  843. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  844. }
  845. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls for <code>vfs_create</code>",
  846. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  847. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511,
  848. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  849. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  850. if (em->mode < MODE_ENTRY) {
  851. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  852. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  853. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512,
  854. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  855. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  856. }
  857. }
  858. /**
  859. * Obsolete specific VFS charts
  860. *
  861. * Obsolete charts for cgroup/application.
  862. *
  863. * @param type the chart type.
  864. * @param em the main thread structure.
  865. */
  866. static void ebpf_obsolete_specific_vfs_charts(char *type, ebpf_module_t *em)
  867. {
  868. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_FILE_DELETED, "Files deleted",
  869. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  870. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  871. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500, em->update_every);
  872. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  873. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  874. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  875. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501, em->update_every);
  876. if (em->mode < MODE_ENTRY) {
  877. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  878. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  879. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  880. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502, em->update_every);
  881. }
  882. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  883. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  884. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_CONTEXT,
  885. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503, em->update_every);
  886. if (em->mode < MODE_ENTRY) {
  887. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  888. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  889. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  890. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504, em->update_every);
  891. }
  892. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  893. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  894. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  895. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505, em->update_every);
  896. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  897. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  898. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  899. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506, em->update_every);
  900. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls for <code>vfs_fsync</code>",
  901. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  902. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  903. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507, em->update_every);
  904. if (em->mode < MODE_ENTRY) {
  905. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  906. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  907. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  908. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508, em->update_every);
  909. }
  910. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls for <code>vfs_open</code>",
  911. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  912. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  913. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509, em->update_every);
  914. if (em->mode < MODE_ENTRY) {
  915. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  916. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  917. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  918. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510, em->update_every);
  919. }
  920. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls for <code>vfs_create</code>",
  921. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  922. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  923. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511, em->update_every);
  924. if (em->mode < MODE_ENTRY) {
  925. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  926. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  927. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  928. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512, em->update_every);
  929. }
  930. }
  931. /*
  932. * Send specific VFS data
  933. *
  934. * Send data for specific cgroup/apps.
  935. *
  936. * @param type chart type
  937. * @param values structure with values that will be sent to netdata
  938. */
  939. static void ebpf_send_specific_vfs_data(char *type, netdata_publish_vfs_t *values, ebpf_module_t *em)
  940. {
  941. write_begin_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED);
  942. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].name, (long long)values->unlink_call);
  943. write_end_chart();
  944. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  945. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  946. (long long)values->write_call + (long long)values->writev_call);
  947. write_end_chart();
  948. if (em->mode < MODE_ENTRY) {
  949. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  950. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  951. (long long)values->write_err + (long long)values->writev_err);
  952. write_end_chart();
  953. }
  954. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  955. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  956. (long long)values->read_call + (long long)values->readv_call);
  957. write_end_chart();
  958. if (em->mode < MODE_ENTRY) {
  959. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  960. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  961. (long long)values->read_err + (long long)values->readv_err);
  962. write_end_chart();
  963. }
  964. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  965. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  966. (long long)values->write_bytes + (long long)values->writev_bytes);
  967. write_end_chart();
  968. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  969. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  970. (long long)values->read_bytes + (long long)values->readv_bytes);
  971. write_end_chart();
  972. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  973. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  974. (long long)values->fsync_call);
  975. write_end_chart();
  976. if (em->mode < MODE_ENTRY) {
  977. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  978. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  979. (long long)values->fsync_err);
  980. write_end_chart();
  981. }
  982. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN);
  983. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  984. (long long)values->open_call);
  985. write_end_chart();
  986. if (em->mode < MODE_ENTRY) {
  987. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  988. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  989. (long long)values->open_err);
  990. write_end_chart();
  991. }
  992. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE);
  993. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  994. (long long)values->create_call);
  995. write_end_chart();
  996. if (em->mode < MODE_ENTRY) {
  997. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  998. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  999. (long long)values->create_err);
  1000. write_end_chart();
  1001. }
  1002. }
  1003. /**
  1004. * Create Systemd Socket Charts
  1005. *
  1006. * Create charts when systemd is enabled
  1007. *
  1008. * @param em the main collector structure
  1009. **/
  1010. static void ebpf_create_systemd_vfs_charts(ebpf_module_t *em)
  1011. {
  1012. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_FILE_DELETED, "Files deleted",
  1013. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1014. NETDATA_EBPF_CHART_TYPE_STACKED, 20065,
  1015. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_UNLINK_CONTEXT,
  1016. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1017. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  1018. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1019. NETDATA_EBPF_CHART_TYPE_STACKED, 20066,
  1020. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_CONTEXT,
  1021. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1022. if (em->mode < MODE_ENTRY) {
  1023. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  1024. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1025. NETDATA_EBPF_CHART_TYPE_STACKED, 20067,
  1026. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1027. NETDATA_SYSTEMD_VFS_WRITE_ERROR_CONTEXT,
  1028. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1029. }
  1030. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  1031. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1032. NETDATA_EBPF_CHART_TYPE_STACKED, 20068,
  1033. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_CONTEXT,
  1034. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1035. if (em->mode < MODE_ENTRY) {
  1036. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  1037. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1038. NETDATA_EBPF_CHART_TYPE_STACKED, 20069,
  1039. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1040. NETDATA_SYSTEMD_VFS_READ_ERROR_CONTEXT,
  1041. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1042. }
  1043. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  1044. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  1045. NETDATA_EBPF_CHART_TYPE_STACKED, 20070,
  1046. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_BYTES_CONTEXT,
  1047. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1048. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  1049. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  1050. NETDATA_EBPF_CHART_TYPE_STACKED, 20071,
  1051. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_BYTES_CONTEXT,
  1052. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1053. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls to <code>vfs_fsync</code>",
  1054. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1055. NETDATA_EBPF_CHART_TYPE_STACKED, 20072,
  1056. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_CONTEXT,
  1057. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1058. if (em->mode < MODE_ENTRY) {
  1059. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  1060. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1061. NETDATA_EBPF_CHART_TYPE_STACKED, 20073,
  1062. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_ERROR_CONTEXT,
  1063. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1064. }
  1065. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls to <code>vfs_open</code>",
  1066. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1067. NETDATA_EBPF_CHART_TYPE_STACKED, 20074,
  1068. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_CONTEXT,
  1069. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1070. if (em->mode < MODE_ENTRY) {
  1071. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  1072. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1073. NETDATA_EBPF_CHART_TYPE_STACKED, 20075,
  1074. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_ERROR_CONTEXT,
  1075. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1076. }
  1077. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls to <code>vfs_create</code>",
  1078. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1079. NETDATA_EBPF_CHART_TYPE_STACKED, 20076,
  1080. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_CONTEXT,
  1081. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1082. if (em->mode < MODE_ENTRY) {
  1083. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  1084. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1085. NETDATA_EBPF_CHART_TYPE_STACKED, 20077,
  1086. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_ERROR_CONTEXT,
  1087. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1088. }
  1089. }
  1090. /**
  1091. * Send Systemd charts
  1092. *
  1093. * Send collected data to Netdata.
  1094. *
  1095. * @param em the main collector structure
  1096. */
  1097. static void ebpf_send_systemd_vfs_charts(ebpf_module_t *em)
  1098. {
  1099. ebpf_cgroup_target_t *ect;
  1100. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED);
  1101. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1102. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1103. write_chart_dimension(ect->name, ect->publish_systemd_vfs.unlink_call);
  1104. }
  1105. }
  1106. write_end_chart();
  1107. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  1108. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1109. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1110. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_call +
  1111. ect->publish_systemd_vfs.writev_call);
  1112. }
  1113. }
  1114. write_end_chart();
  1115. if (em->mode < MODE_ENTRY) {
  1116. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  1117. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1118. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1119. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_err +
  1120. ect->publish_systemd_vfs.writev_err);
  1121. }
  1122. }
  1123. write_end_chart();
  1124. }
  1125. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  1126. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1127. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1128. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_call +
  1129. ect->publish_systemd_vfs.readv_call);
  1130. }
  1131. }
  1132. write_end_chart();
  1133. if (em->mode < MODE_ENTRY) {
  1134. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  1135. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1136. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1137. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_err +
  1138. ect->publish_systemd_vfs.readv_err);
  1139. }
  1140. }
  1141. write_end_chart();
  1142. }
  1143. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  1144. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1145. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1146. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_bytes +
  1147. ect->publish_systemd_vfs.writev_bytes);
  1148. }
  1149. }
  1150. write_end_chart();
  1151. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  1152. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1153. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1154. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_bytes +
  1155. ect->publish_systemd_vfs.readv_bytes);
  1156. }
  1157. }
  1158. write_end_chart();
  1159. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  1160. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1161. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1162. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_call);
  1163. }
  1164. }
  1165. write_end_chart();
  1166. if (em->mode < MODE_ENTRY) {
  1167. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  1168. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1169. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1170. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_err);
  1171. }
  1172. }
  1173. write_end_chart();
  1174. }
  1175. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN);
  1176. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1177. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1178. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_call);
  1179. }
  1180. }
  1181. write_end_chart();
  1182. if (em->mode < MODE_ENTRY) {
  1183. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  1184. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1185. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1186. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_err);
  1187. }
  1188. }
  1189. write_end_chart();
  1190. }
  1191. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE);
  1192. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1193. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1194. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_call);
  1195. }
  1196. }
  1197. write_end_chart();
  1198. if (em->mode < MODE_ENTRY) {
  1199. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  1200. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1201. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1202. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_err);
  1203. }
  1204. }
  1205. write_end_chart();
  1206. }
  1207. }
  1208. /**
  1209. * Send data to Netdata calling auxiliary functions.
  1210. *
  1211. * @param em the main collector structure
  1212. */
  1213. static void ebpf_vfs_send_cgroup_data(ebpf_module_t *em)
  1214. {
  1215. if (!ebpf_cgroup_pids)
  1216. return;
  1217. pthread_mutex_lock(&mutex_cgroup_shm);
  1218. ebpf_cgroup_target_t *ect;
  1219. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1220. ebpf_vfs_sum_cgroup_pids(&ect->publish_systemd_vfs, ect->pids);
  1221. }
  1222. int has_systemd = shm_ebpf_cgroup.header->systemd_enabled;
  1223. if (has_systemd) {
  1224. if (send_cgroup_chart) {
  1225. ebpf_create_systemd_vfs_charts(em);
  1226. }
  1227. ebpf_send_systemd_vfs_charts(em);
  1228. }
  1229. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1230. if (ect->systemd)
  1231. continue;
  1232. if (!(ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) && ect->updated) {
  1233. ebpf_create_specific_vfs_charts(ect->name, em);
  1234. ect->flags |= NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  1235. }
  1236. if (ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) {
  1237. if (ect->updated) {
  1238. ebpf_send_specific_vfs_data(ect->name, &ect->publish_systemd_vfs, em);
  1239. } else {
  1240. ebpf_obsolete_specific_vfs_charts(ect->name, em);
  1241. ect->flags &= ~NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  1242. }
  1243. }
  1244. }
  1245. pthread_mutex_unlock(&mutex_cgroup_shm);
  1246. }
  1247. /**
  1248. * Main loop for this collector.
  1249. *
  1250. * @param step the number of microseconds used with heart beat
  1251. * @param em the structure with thread information
  1252. */
  1253. static void vfs_collector(ebpf_module_t *em)
  1254. {
  1255. int cgroups = em->cgroup_charts;
  1256. heartbeat_t hb;
  1257. heartbeat_init(&hb);
  1258. int update_every = em->update_every;
  1259. int counter = update_every - 1;
  1260. while (!ebpf_exit_plugin) {
  1261. (void)heartbeat_next(&hb, USEC_PER_SEC);
  1262. if (ebpf_exit_plugin || ++counter != update_every)
  1263. continue;
  1264. counter = 0;
  1265. netdata_apps_integration_flags_t apps = em->apps_charts;
  1266. ebpf_vfs_read_global_table();
  1267. pthread_mutex_lock(&collect_data_mutex);
  1268. if (apps)
  1269. ebpf_vfs_read_apps();
  1270. #ifdef NETDATA_DEV_MODE
  1271. if (ebpf_aral_vfs_pid)
  1272. ebpf_send_data_aral_chart(ebpf_aral_vfs_pid, em);
  1273. #endif
  1274. if (cgroups)
  1275. read_update_vfs_cgroup();
  1276. pthread_mutex_lock(&lock);
  1277. ebpf_vfs_send_data(em);
  1278. fflush(stdout);
  1279. if (apps & NETDATA_EBPF_APPS_FLAG_CHART_CREATED)
  1280. ebpf_vfs_send_apps_data(em, apps_groups_root_target);
  1281. if (cgroups)
  1282. ebpf_vfs_send_cgroup_data(em);
  1283. pthread_mutex_unlock(&lock);
  1284. pthread_mutex_unlock(&collect_data_mutex);
  1285. }
  1286. }
  1287. /*****************************************************************
  1288. *
  1289. * FUNCTIONS TO CREATE CHARTS
  1290. *
  1291. *****************************************************************/
  1292. /**
  1293. * Create IO chart
  1294. *
  1295. * @param family the chart family
  1296. * @param name the chart name
  1297. * @param axis the axis label
  1298. * @param web the group name used to attach the chart on dashboard
  1299. * @param order the order number of the specified chart
  1300. * @param algorithm the algorithm used to make the charts.
  1301. * @param update_every value to overwrite the update frequency set by the server.
  1302. */
  1303. static void ebpf_create_io_chart(char *family, char *name, char *axis, char *web,
  1304. int order, int algorithm, int update_every)
  1305. {
  1306. printf("CHART %s.%s '' 'Bytes written and read' '%s' '%s' '' line %d %d '' 'ebpf.plugin' 'filesystem'\n",
  1307. family,
  1308. name,
  1309. axis,
  1310. web,
  1311. order,
  1312. update_every);
  1313. printf("DIMENSION %s %s %s 1 1\n",
  1314. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1315. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1316. ebpf_algorithms[algorithm]);
  1317. printf("DIMENSION %s %s %s -1 1\n",
  1318. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1319. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1320. ebpf_algorithms[algorithm]);
  1321. }
  1322. /**
  1323. * Create global charts
  1324. *
  1325. * Call ebpf_create_chart to create the charts for the collector.
  1326. *
  1327. * @param em a pointer to the structure with the default values.
  1328. */
  1329. static void ebpf_create_global_charts(ebpf_module_t *em)
  1330. {
  1331. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1332. NETDATA_VFS_FILE_CLEAN_COUNT,
  1333. "Remove files",
  1334. EBPF_COMMON_DIMENSION_CALL,
  1335. NETDATA_VFS_GROUP,
  1336. NULL,
  1337. NETDATA_EBPF_CHART_TYPE_LINE,
  1338. NETDATA_CHART_PRIO_FILESYSTEM_VFS_CLEAN,
  1339. ebpf_create_global_dimension,
  1340. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  1341. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1342. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1343. NETDATA_VFS_FILE_IO_COUNT,
  1344. "Calls to IO",
  1345. EBPF_COMMON_DIMENSION_CALL,
  1346. NETDATA_VFS_GROUP,
  1347. NULL,
  1348. NETDATA_EBPF_CHART_TYPE_LINE,
  1349. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_COUNT,
  1350. ebpf_create_global_dimension,
  1351. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1352. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1353. ebpf_create_io_chart(NETDATA_FILESYSTEM_FAMILY,
  1354. NETDATA_VFS_IO_FILE_BYTES, EBPF_COMMON_DIMENSION_BYTES,
  1355. NETDATA_VFS_GROUP,
  1356. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_BYTES,
  1357. NETDATA_EBPF_INCREMENTAL_IDX, em->update_every);
  1358. if (em->mode < MODE_ENTRY) {
  1359. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1360. NETDATA_VFS_FILE_ERR_COUNT,
  1361. "Fails to write or read",
  1362. EBPF_COMMON_DIMENSION_CALL,
  1363. NETDATA_VFS_GROUP,
  1364. NULL,
  1365. NETDATA_EBPF_CHART_TYPE_LINE,
  1366. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EBYTES,
  1367. ebpf_create_global_dimension,
  1368. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1369. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1370. }
  1371. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1372. NETDATA_VFS_FSYNC,
  1373. "Calls for <code>vfs_fsync</code>",
  1374. EBPF_COMMON_DIMENSION_CALL,
  1375. NETDATA_VFS_GROUP,
  1376. NULL,
  1377. NETDATA_EBPF_CHART_TYPE_LINE,
  1378. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_FSYNC,
  1379. ebpf_create_global_dimension,
  1380. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1381. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1382. if (em->mode < MODE_ENTRY) {
  1383. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1384. NETDATA_VFS_FSYNC_ERR,
  1385. "Fails to synchronize",
  1386. EBPF_COMMON_DIMENSION_CALL,
  1387. NETDATA_VFS_GROUP,
  1388. NULL,
  1389. NETDATA_EBPF_CHART_TYPE_LINE,
  1390. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EFSYNC,
  1391. ebpf_create_global_dimension,
  1392. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1393. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1394. }
  1395. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1396. NETDATA_VFS_OPEN,
  1397. "Calls for <code>vfs_open</code>",
  1398. EBPF_COMMON_DIMENSION_CALL,
  1399. NETDATA_VFS_GROUP,
  1400. NULL,
  1401. NETDATA_EBPF_CHART_TYPE_LINE,
  1402. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_OPEN,
  1403. ebpf_create_global_dimension,
  1404. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1405. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1406. if (em->mode < MODE_ENTRY) {
  1407. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1408. NETDATA_VFS_OPEN_ERR,
  1409. "Fails to open a file",
  1410. EBPF_COMMON_DIMENSION_CALL,
  1411. NETDATA_VFS_GROUP,
  1412. NULL,
  1413. NETDATA_EBPF_CHART_TYPE_LINE,
  1414. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EOPEN,
  1415. ebpf_create_global_dimension,
  1416. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1417. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1418. }
  1419. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1420. NETDATA_VFS_CREATE,
  1421. "Calls for <code>vfs_create</code>",
  1422. EBPF_COMMON_DIMENSION_CALL,
  1423. NETDATA_VFS_GROUP,
  1424. NULL,
  1425. NETDATA_EBPF_CHART_TYPE_LINE,
  1426. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_CREATE,
  1427. ebpf_create_global_dimension,
  1428. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1429. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1430. if (em->mode < MODE_ENTRY) {
  1431. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1432. NETDATA_VFS_CREATE_ERR,
  1433. "Fails to create a file.",
  1434. EBPF_COMMON_DIMENSION_CALL,
  1435. NETDATA_VFS_GROUP,
  1436. NULL,
  1437. NETDATA_EBPF_CHART_TYPE_LINE,
  1438. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_ECREATE,
  1439. ebpf_create_global_dimension,
  1440. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1441. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1442. }
  1443. }
  1444. /**
  1445. * Create process apps charts
  1446. *
  1447. * Call ebpf_create_chart to create the charts on apps submenu.
  1448. *
  1449. * @param em a pointer to the structure with the default values.
  1450. * @param ptr a pointer for the targets.
  1451. **/
  1452. void ebpf_vfs_create_apps_charts(struct ebpf_module *em, void *ptr)
  1453. {
  1454. struct ebpf_target *root = ptr;
  1455. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_FILE_DELETED,
  1456. "Files deleted",
  1457. EBPF_COMMON_DIMENSION_CALL,
  1458. NETDATA_VFS_GROUP,
  1459. NETDATA_EBPF_CHART_TYPE_STACKED,
  1460. 20065,
  1461. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1462. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1463. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS,
  1464. "Write to disk",
  1465. EBPF_COMMON_DIMENSION_CALL,
  1466. NETDATA_VFS_GROUP,
  1467. NETDATA_EBPF_CHART_TYPE_STACKED,
  1468. 20066,
  1469. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1470. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1471. if (em->mode < MODE_ENTRY) {
  1472. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR,
  1473. "Fails to write",
  1474. EBPF_COMMON_DIMENSION_CALL,
  1475. NETDATA_VFS_GROUP,
  1476. NETDATA_EBPF_CHART_TYPE_STACKED,
  1477. 20067,
  1478. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1479. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1480. }
  1481. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS,
  1482. "Read from disk",
  1483. EBPF_COMMON_DIMENSION_CALL,
  1484. NETDATA_VFS_GROUP,
  1485. NETDATA_EBPF_CHART_TYPE_STACKED,
  1486. 20068,
  1487. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1488. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1489. if (em->mode < MODE_ENTRY) {
  1490. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR,
  1491. "Fails to read",
  1492. EBPF_COMMON_DIMENSION_CALL,
  1493. NETDATA_VFS_GROUP,
  1494. NETDATA_EBPF_CHART_TYPE_STACKED,
  1495. 20069,
  1496. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1497. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1498. }
  1499. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES,
  1500. "Bytes written on disk", EBPF_COMMON_DIMENSION_BYTES,
  1501. NETDATA_VFS_GROUP,
  1502. NETDATA_EBPF_CHART_TYPE_STACKED,
  1503. 20070,
  1504. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1505. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1506. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_BYTES,
  1507. "Bytes read from disk", EBPF_COMMON_DIMENSION_BYTES,
  1508. NETDATA_VFS_GROUP,
  1509. NETDATA_EBPF_CHART_TYPE_STACKED,
  1510. 20071,
  1511. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1512. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1513. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC,
  1514. "Calls for <code>vfs_fsync</code>", EBPF_COMMON_DIMENSION_CALL,
  1515. NETDATA_VFS_GROUP,
  1516. NETDATA_EBPF_CHART_TYPE_STACKED,
  1517. 20072,
  1518. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1519. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1520. if (em->mode < MODE_ENTRY) {
  1521. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR,
  1522. "Sync error",
  1523. EBPF_COMMON_DIMENSION_CALL,
  1524. NETDATA_VFS_GROUP,
  1525. NETDATA_EBPF_CHART_TYPE_STACKED,
  1526. 20073,
  1527. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1528. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1529. }
  1530. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN,
  1531. "Calls for <code>vfs_open</code>", EBPF_COMMON_DIMENSION_CALL,
  1532. NETDATA_VFS_GROUP,
  1533. NETDATA_EBPF_CHART_TYPE_STACKED,
  1534. 20074,
  1535. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1536. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1537. if (em->mode < MODE_ENTRY) {
  1538. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR,
  1539. "Open error",
  1540. EBPF_COMMON_DIMENSION_CALL,
  1541. NETDATA_VFS_GROUP,
  1542. NETDATA_EBPF_CHART_TYPE_STACKED,
  1543. 20075,
  1544. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1545. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1546. }
  1547. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE,
  1548. "Calls for <code>vfs_create</code>", EBPF_COMMON_DIMENSION_CALL,
  1549. NETDATA_VFS_GROUP,
  1550. NETDATA_EBPF_CHART_TYPE_STACKED,
  1551. 20076,
  1552. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1553. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1554. if (em->mode < MODE_ENTRY) {
  1555. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR,
  1556. "Create error",
  1557. EBPF_COMMON_DIMENSION_CALL,
  1558. NETDATA_VFS_GROUP,
  1559. NETDATA_EBPF_CHART_TYPE_STACKED,
  1560. 20077,
  1561. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1562. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1563. }
  1564. em->apps_charts |= NETDATA_EBPF_APPS_FLAG_CHART_CREATED;
  1565. }
  1566. /*****************************************************************
  1567. *
  1568. * FUNCTIONS TO START THREAD
  1569. *
  1570. *****************************************************************/
  1571. /**
  1572. * Allocate vectors used with this thread.
  1573. * We are not testing the return, because callocz does this and shutdown the software
  1574. * case it was not possible to allocate.
  1575. *
  1576. * @param apps is apps enabled?
  1577. */
  1578. static void ebpf_vfs_allocate_global_vectors(int apps)
  1579. {
  1580. if (apps) {
  1581. ebpf_vfs_aral_init();
  1582. vfs_pid = callocz((size_t)pid_max, sizeof(netdata_publish_vfs_t *));
  1583. vfs_vector = callocz(ebpf_nprocs, sizeof(netdata_publish_vfs_t));
  1584. }
  1585. memset(vfs_aggregated_data, 0, sizeof(vfs_aggregated_data));
  1586. memset(vfs_publish_aggregated, 0, sizeof(vfs_publish_aggregated));
  1587. vfs_hash_values = callocz(ebpf_nprocs, sizeof(netdata_idx_t));
  1588. }
  1589. /*****************************************************************
  1590. *
  1591. * EBPF VFS THREAD
  1592. *
  1593. *****************************************************************/
  1594. /*
  1595. * Load BPF
  1596. *
  1597. * Load BPF files.
  1598. *
  1599. * @param em the structure with configuration
  1600. */
  1601. static int ebpf_vfs_load_bpf(ebpf_module_t *em)
  1602. {
  1603. int ret = 0;
  1604. ebpf_adjust_apps_cgroup(em, em->targets[NETDATA_EBPF_VFS_WRITE].mode);
  1605. if (em->load & EBPF_LOAD_LEGACY) {
  1606. em->probe_links = ebpf_load_program(ebpf_plugin_dir, em, running_on_kernel, isrh, &em->objects);
  1607. if (!em->probe_links) {
  1608. ret = -1;
  1609. }
  1610. }
  1611. #ifdef LIBBPF_MAJOR_VERSION
  1612. else {
  1613. vfs_bpf_obj = vfs_bpf__open();
  1614. if (!vfs_bpf_obj)
  1615. ret = -1;
  1616. else
  1617. ret = ebpf_vfs_load_and_attach(vfs_bpf_obj, em);
  1618. }
  1619. #endif
  1620. return ret;
  1621. }
  1622. /**
  1623. * Process thread
  1624. *
  1625. * Thread used to generate process charts.
  1626. *
  1627. * @param ptr a pointer to `struct ebpf_module`
  1628. *
  1629. * @return It always return NULL
  1630. */
  1631. void *ebpf_vfs_thread(void *ptr)
  1632. {
  1633. netdata_thread_cleanup_push(ebpf_vfs_exit, ptr);
  1634. ebpf_module_t *em = (ebpf_module_t *)ptr;
  1635. em->maps = vfs_maps;
  1636. ebpf_update_pid_table(&vfs_maps[NETDATA_VFS_PID], em);
  1637. ebpf_vfs_allocate_global_vectors(em->apps_charts);
  1638. #ifdef LIBBPF_MAJOR_VERSION
  1639. ebpf_adjust_thread_load(em, default_btf);
  1640. #endif
  1641. if (ebpf_vfs_load_bpf(em)) {
  1642. goto endvfs;
  1643. }
  1644. int algorithms[NETDATA_KEY_PUBLISH_VFS_END] = {
  1645. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX,
  1646. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX
  1647. };
  1648. ebpf_global_labels(vfs_aggregated_data, vfs_publish_aggregated, vfs_dimension_names,
  1649. vfs_id_names, algorithms, NETDATA_KEY_PUBLISH_VFS_END);
  1650. pthread_mutex_lock(&lock);
  1651. ebpf_create_global_charts(em);
  1652. ebpf_update_stats(&plugin_statistics, em);
  1653. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps);
  1654. #ifdef NETDATA_DEV_MODE
  1655. if (ebpf_aral_vfs_pid)
  1656. ebpf_statistic_create_aral_chart(NETDATA_EBPF_VFS_ARAL_NAME, em);
  1657. #endif
  1658. pthread_mutex_unlock(&lock);
  1659. vfs_collector(em);
  1660. endvfs:
  1661. ebpf_update_disabled_plugin_stats(em);
  1662. netdata_thread_cleanup_pop(1);
  1663. return NULL;
  1664. }