ebpf_vfs.c 35 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include <sys/resource.h>
  3. #include "ebpf.h"
  4. #include "ebpf_vfs.h"
  5. static char *vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_END] = { "delete", "read", "write",
  6. "fsync", "open", "create" };
  7. static char *vfs_id_names[NETDATA_KEY_PUBLISH_VFS_END] = { "vfs_unlink", "vfs_read", "vfs_write",
  8. "vfs_fsync", "vfs_open", "vfs_create"};
  9. static netdata_idx_t *vfs_hash_values = NULL;
  10. static netdata_syscall_stat_t vfs_aggregated_data[NETDATA_KEY_PUBLISH_PROCESS_END];
  11. static netdata_publish_syscall_t vfs_publish_aggregated[NETDATA_KEY_PUBLISH_PROCESS_END];
  12. netdata_publish_vfs_t **vfs_pid = NULL;
  13. netdata_publish_vfs_t *vfs_vector = NULL;
  14. static ebpf_data_t vfs_data;
  15. static ebpf_local_maps_t vfs_maps[] = {{.name = "tbl_vfs_pid", .internal_input = ND_EBPF_DEFAULT_PID_SIZE,
  16. .user_input = 0, .type = NETDATA_EBPF_MAP_RESIZABLE | NETDATA_EBPF_MAP_PID,
  17. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  18. {.name = "tbl_vfs_stats", .internal_input = NETDATA_VFS_COUNTER,
  19. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  20. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  21. {.name = "vfs_ctrl", .internal_input = NETDATA_CONTROLLER_END,
  22. .user_input = 0,
  23. .type = NETDATA_EBPF_MAP_CONTROLLER,
  24. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  25. {.name = NULL, .internal_input = 0, .user_input = 0}};
  26. struct config vfs_config = { .first_section = NULL,
  27. .last_section = NULL,
  28. .mutex = NETDATA_MUTEX_INITIALIZER,
  29. .index = { .avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  30. .rwlock = AVL_LOCK_INITIALIZER } };
  31. static struct bpf_object *objects = NULL;
  32. static struct bpf_link **probe_links = NULL;
  33. struct netdata_static_thread vfs_threads = {"VFS KERNEL",
  34. NULL, NULL, 1, NULL,
  35. NULL, NULL};
  36. static int read_thread_closed = 1;
  37. /*****************************************************************
  38. *
  39. * FUNCTIONS TO CLOSE THE THREAD
  40. *
  41. *****************************************************************/
  42. /**
  43. * Clean PID structures
  44. *
  45. * Clean the allocated structures.
  46. */
  47. void clean_vfs_pid_structures() {
  48. struct pid_stat *pids = root_of_pids;
  49. while (pids) {
  50. freez(vfs_pid[pids->pid]);
  51. pids = pids->next;
  52. }
  53. }
  54. /**
  55. * Clean up the main thread.
  56. *
  57. * @param ptr thread data.
  58. **/
  59. static void ebpf_vfs_cleanup(void *ptr)
  60. {
  61. ebpf_module_t *em = (ebpf_module_t *)ptr;
  62. if (!em->enabled)
  63. return;
  64. heartbeat_t hb;
  65. heartbeat_init(&hb);
  66. uint32_t tick = 50 * USEC_PER_MS;
  67. while (!read_thread_closed) {
  68. usec_t dt = heartbeat_next(&hb, tick);
  69. UNUSED(dt);
  70. }
  71. freez(vfs_data.map_fd);
  72. freez(vfs_hash_values);
  73. freez(vfs_vector);
  74. if (probe_links) {
  75. struct bpf_program *prog;
  76. size_t i = 0 ;
  77. bpf_object__for_each_program(prog, objects) {
  78. bpf_link__destroy(probe_links[i]);
  79. i++;
  80. }
  81. bpf_object__close(objects);
  82. }
  83. }
  84. /*****************************************************************
  85. *
  86. * FUNCTIONS WITH THE MAIN LOOP
  87. *
  88. *****************************************************************/
  89. /**
  90. * Send data to Netdata calling auxiliar functions.
  91. *
  92. * @param em the structure with thread information
  93. */
  94. static void ebpf_vfs_send_data(ebpf_module_t *em)
  95. {
  96. netdata_publish_vfs_common_t pvc;
  97. pvc.write = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes;
  98. pvc.read = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes;
  99. write_count_chart(NETDATA_VFS_FILE_CLEAN_COUNT, NETDATA_FILESYSTEM_FAMILY,
  100. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK], 1);
  101. write_count_chart(NETDATA_VFS_FILE_IO_COUNT, NETDATA_FILESYSTEM_FAMILY,
  102. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  103. if (em->mode < MODE_ENTRY) {
  104. write_err_chart(NETDATA_VFS_FILE_ERR_COUNT, NETDATA_FILESYSTEM_FAMILY,
  105. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  106. }
  107. write_io_chart(NETDATA_VFS_IO_FILE_BYTES, NETDATA_FILESYSTEM_FAMILY, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  108. (long long)pvc.write, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ], (long long)pvc.read);
  109. write_count_chart(NETDATA_VFS_FSYNC, NETDATA_FILESYSTEM_FAMILY,
  110. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  111. if (em->mode < MODE_ENTRY) {
  112. write_err_chart(NETDATA_VFS_FSYNC_ERR, NETDATA_FILESYSTEM_FAMILY,
  113. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  114. }
  115. write_count_chart(NETDATA_VFS_OPEN, NETDATA_FILESYSTEM_FAMILY,
  116. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  117. if (em->mode < MODE_ENTRY) {
  118. write_err_chart(NETDATA_VFS_OPEN_ERR, NETDATA_FILESYSTEM_FAMILY,
  119. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  120. }
  121. write_count_chart(NETDATA_VFS_CREATE, NETDATA_FILESYSTEM_FAMILY,
  122. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE], 1);
  123. if (em->mode < MODE_ENTRY) {
  124. write_err_chart(
  125. NETDATA_VFS_CREATE_ERR,
  126. NETDATA_FILESYSTEM_FAMILY,
  127. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  128. 1);
  129. }
  130. }
  131. /**
  132. * Read the hash table and store data to allocated vectors.
  133. */
  134. static void read_global_table()
  135. {
  136. uint64_t idx;
  137. netdata_idx_t res[NETDATA_VFS_COUNTER];
  138. netdata_idx_t *val = vfs_hash_values;
  139. int fd = vfs_maps[NETDATA_VFS_ALL].map_fd;
  140. for (idx = 0; idx < NETDATA_VFS_COUNTER; idx++) {
  141. uint64_t total = 0;
  142. if (!bpf_map_lookup_elem(fd, &idx, val)) {
  143. int i;
  144. int end = ebpf_nprocs;
  145. for (i = 0; i < end; i++)
  146. total += val[i];
  147. }
  148. res[idx] = total;
  149. }
  150. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].ncall = res[NETDATA_KEY_CALLS_VFS_UNLINK];
  151. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].ncall = res[NETDATA_KEY_CALLS_VFS_READ] +
  152. res[NETDATA_KEY_CALLS_VFS_READV];
  153. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].ncall = res[NETDATA_KEY_CALLS_VFS_WRITE] +
  154. res[NETDATA_KEY_CALLS_VFS_WRITEV];
  155. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].ncall = res[NETDATA_KEY_CALLS_VFS_FSYNC];
  156. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].ncall = res[NETDATA_KEY_CALLS_VFS_OPEN];
  157. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].ncall = res[NETDATA_KEY_CALLS_VFS_CREATE];
  158. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].nerr = res[NETDATA_KEY_ERROR_VFS_UNLINK];
  159. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].nerr = res[NETDATA_KEY_ERROR_VFS_READ] +
  160. res[NETDATA_KEY_ERROR_VFS_READV];
  161. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].nerr = res[NETDATA_KEY_ERROR_VFS_WRITE] +
  162. res[NETDATA_KEY_ERROR_VFS_WRITEV];
  163. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].nerr = res[NETDATA_KEY_ERROR_VFS_FSYNC];
  164. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].nerr = res[NETDATA_KEY_ERROR_VFS_OPEN];
  165. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].nerr = res[NETDATA_KEY_ERROR_VFS_CREATE];
  166. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITE] +
  167. (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITEV];
  168. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_READ] +
  169. (uint64_t)res[NETDATA_KEY_BYTES_VFS_READV];
  170. }
  171. /**
  172. * Sum PIDs
  173. *
  174. * Sum values for all targets.
  175. *
  176. * @param swap output structure
  177. * @param root link list with structure to be used
  178. */
  179. static void ebpf_vfs_sum_pids(netdata_publish_vfs_t *vfs, struct pid_on_target *root)
  180. {
  181. netdata_publish_vfs_t accumulator;
  182. memset(&accumulator, 0, sizeof(accumulator));
  183. while (root) {
  184. int32_t pid = root->pid;
  185. netdata_publish_vfs_t *w = vfs_pid[pid];
  186. if (w) {
  187. accumulator.write_call += w->write_call;
  188. accumulator.writev_call += w->writev_call;
  189. accumulator.read_call += w->read_call;
  190. accumulator.readv_call += w->readv_call;
  191. accumulator.unlink_call += w->unlink_call;
  192. accumulator.fsync_call += w->fsync_call;
  193. accumulator.open_call += w->open_call;
  194. accumulator.create_call += w->create_call;
  195. accumulator.write_bytes += w->write_bytes;
  196. accumulator.writev_bytes += w->writev_bytes;
  197. accumulator.read_bytes += w->read_bytes;
  198. accumulator.readv_bytes += w->readv_bytes;
  199. accumulator.write_err += w->write_err;
  200. accumulator.writev_err += w->writev_err;
  201. accumulator.read_err += w->read_err;
  202. accumulator.readv_err += w->readv_err;
  203. accumulator.unlink_err += w->unlink_err;
  204. accumulator.fsync_err += w->fsync_err;
  205. accumulator.open_err += w->open_err;
  206. accumulator.create_err += w->create_err;
  207. }
  208. root = root->next;
  209. }
  210. // These conditions were added, because we are using incremental algorithm
  211. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  212. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  213. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  214. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  215. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  216. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  217. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  218. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  219. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  220. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  221. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  222. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  223. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  224. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  225. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  226. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  227. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  228. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  229. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  230. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  231. }
  232. /**
  233. * Send data to Netdata calling auxiliar functions.
  234. *
  235. * @param em the structure with thread information
  236. * @param root the target list.
  237. */
  238. void ebpf_vfs_send_apps_data(ebpf_module_t *em, struct target *root)
  239. {
  240. struct target *w;
  241. for (w = root; w; w = w->next) {
  242. if (unlikely(w->exposed && w->processes)) {
  243. ebpf_vfs_sum_pids(&w->vfs, w->root_pid);
  244. }
  245. }
  246. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED);
  247. for (w = root; w; w = w->next) {
  248. if (unlikely(w->exposed && w->processes)) {
  249. write_chart_dimension(w->name, w->vfs.unlink_call);
  250. }
  251. }
  252. write_end_chart();
  253. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  254. for (w = root; w; w = w->next) {
  255. if (unlikely(w->exposed && w->processes)) {
  256. write_chart_dimension(w->name, w->vfs.write_call + w->vfs.writev_call);
  257. }
  258. }
  259. write_end_chart();
  260. if (em->mode < MODE_ENTRY) {
  261. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  262. for (w = root; w; w = w->next) {
  263. if (unlikely(w->exposed && w->processes)) {
  264. write_chart_dimension(w->name, w->vfs.write_err + w->vfs.writev_err);
  265. }
  266. }
  267. write_end_chart();
  268. }
  269. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  270. for (w = root; w; w = w->next) {
  271. if (unlikely(w->exposed && w->processes)) {
  272. write_chart_dimension(w->name, w->vfs.read_call + w->vfs.readv_call);
  273. }
  274. }
  275. write_end_chart();
  276. if (em->mode < MODE_ENTRY) {
  277. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  278. for (w = root; w; w = w->next) {
  279. if (unlikely(w->exposed && w->processes)) {
  280. write_chart_dimension(w->name, w->vfs.read_err + w->vfs.readv_err);
  281. }
  282. }
  283. write_end_chart();
  284. }
  285. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  286. for (w = root; w; w = w->next) {
  287. if (unlikely(w->exposed && w->processes)) {
  288. write_chart_dimension(w->name, w->vfs.write_bytes + w->vfs.writev_bytes);
  289. }
  290. }
  291. write_end_chart();
  292. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  293. for (w = root; w; w = w->next) {
  294. if (unlikely(w->exposed && w->processes)) {
  295. write_chart_dimension(w->name, w->vfs.read_bytes + w->vfs.readv_bytes);
  296. }
  297. }
  298. write_end_chart();
  299. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  300. for (w = root; w; w = w->next) {
  301. if (unlikely(w->exposed && w->processes)) {
  302. write_chart_dimension(w->name, w->vfs.fsync_call);
  303. }
  304. }
  305. write_end_chart();
  306. if (em->mode < MODE_ENTRY) {
  307. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  308. for (w = root; w; w = w->next) {
  309. if (unlikely(w->exposed && w->processes)) {
  310. write_chart_dimension(w->name, w->vfs.fsync_err);
  311. }
  312. }
  313. write_end_chart();
  314. }
  315. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN);
  316. for (w = root; w; w = w->next) {
  317. if (unlikely(w->exposed && w->processes)) {
  318. write_chart_dimension(w->name, w->vfs.open_call);
  319. }
  320. }
  321. write_end_chart();
  322. if (em->mode < MODE_ENTRY) {
  323. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  324. for (w = root; w; w = w->next) {
  325. if (unlikely(w->exposed && w->processes)) {
  326. write_chart_dimension(w->name, w->vfs.open_err);
  327. }
  328. }
  329. write_end_chart();
  330. }
  331. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE);
  332. for (w = root; w; w = w->next) {
  333. if (unlikely(w->exposed && w->processes)) {
  334. write_chart_dimension(w->name, w->vfs.create_call);
  335. }
  336. }
  337. write_end_chart();
  338. if (em->mode < MODE_ENTRY) {
  339. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  340. for (w = root; w; w = w->next) {
  341. if (unlikely(w->exposed && w->processes)) {
  342. write_chart_dimension(w->name, w->vfs.create_err);
  343. }
  344. }
  345. write_end_chart();
  346. }
  347. }
  348. /**
  349. * Apps Accumulator
  350. *
  351. * Sum all values read from kernel and store in the first address.
  352. *
  353. * @param out the vector with read values.
  354. */
  355. static void vfs_apps_accumulator(netdata_publish_vfs_t *out)
  356. {
  357. int i, end = (running_on_kernel >= NETDATA_KERNEL_V4_15) ? ebpf_nprocs : 1;
  358. netdata_publish_vfs_t *total = &out[0];
  359. for (i = 1; i < end; i++) {
  360. netdata_publish_vfs_t *w = &out[i];
  361. total->write_call += w->write_call;
  362. total->writev_call += w->writev_call;
  363. total->read_call += w->read_call;
  364. total->readv_call += w->readv_call;
  365. total->unlink_call += w->unlink_call;
  366. total->write_bytes += w->write_bytes;
  367. total->writev_bytes += w->writev_bytes;
  368. total->read_bytes += w->read_bytes;
  369. total->readv_bytes += w->readv_bytes;
  370. total->write_err += w->write_err;
  371. total->writev_err += w->writev_err;
  372. total->read_err += w->read_err;
  373. total->readv_err += w->readv_err;
  374. total->unlink_err += w->unlink_err;
  375. }
  376. }
  377. /**
  378. * Fill PID
  379. *
  380. * Fill PID structures
  381. *
  382. * @param current_pid pid that we are collecting data
  383. * @param out values read from hash tables;
  384. */
  385. static void vfs_fill_pid(uint32_t current_pid, netdata_publish_vfs_t *publish)
  386. {
  387. netdata_publish_vfs_t *curr = vfs_pid[current_pid];
  388. if (!curr) {
  389. curr = callocz(1, sizeof(netdata_publish_vfs_t));
  390. vfs_pid[current_pid] = curr;
  391. }
  392. memcpy(curr, &publish[0], sizeof(netdata_publish_vfs_t));
  393. }
  394. /**
  395. * Read the hash table and store data to allocated vectors.
  396. */
  397. static void ebpf_vfs_read_apps()
  398. {
  399. struct pid_stat *pids = root_of_pids;
  400. netdata_publish_vfs_t *vv = vfs_vector;
  401. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  402. size_t length = sizeof(netdata_publish_vfs_t) * ebpf_nprocs;
  403. while (pids) {
  404. uint32_t key = pids->pid;
  405. if (bpf_map_lookup_elem(fd, &key, vv)) {
  406. pids = pids->next;
  407. continue;
  408. }
  409. vfs_apps_accumulator(vv);
  410. vfs_fill_pid(key, vv);
  411. // We are cleaning to avoid passing data read from one process to other.
  412. memset(vv, 0, length);
  413. pids = pids->next;
  414. }
  415. }
  416. /**
  417. * VFS read hash
  418. *
  419. * This is the thread callback.
  420. * This thread is necessary, because we cannot freeze the whole plugin to read the data.
  421. *
  422. * @param ptr It is a NULL value for this thread.
  423. *
  424. * @return It always returns NULL.
  425. */
  426. void *ebpf_vfs_read_hash(void *ptr)
  427. {
  428. read_thread_closed = 0;
  429. heartbeat_t hb;
  430. heartbeat_init(&hb);
  431. ebpf_module_t *em = (ebpf_module_t *)ptr;
  432. usec_t step = NETDATA_LATENCY_VFS_SLEEP_MS * em->update_time;
  433. while (!close_ebpf_plugin) {
  434. usec_t dt = heartbeat_next(&hb, step);
  435. (void)dt;
  436. read_global_table();
  437. }
  438. read_thread_closed = 1;
  439. return NULL;
  440. }
  441. /**
  442. * Main loop for this collector.
  443. *
  444. * @param step the number of microseconds used with heart beat
  445. * @param em the structure with thread information
  446. */
  447. static void vfs_collector(ebpf_module_t *em)
  448. {
  449. vfs_threads.thread = mallocz(sizeof(netdata_thread_t));
  450. vfs_threads.start_routine = ebpf_vfs_read_hash;
  451. netdata_thread_create(vfs_threads.thread, vfs_threads.name, NETDATA_THREAD_OPTION_JOINABLE,
  452. ebpf_vfs_read_hash, em);
  453. int apps = em->apps_charts;
  454. while (!close_ebpf_plugin) {
  455. pthread_mutex_lock(&collect_data_mutex);
  456. pthread_cond_wait(&collect_data_cond_var, &collect_data_mutex);
  457. if (apps)
  458. ebpf_vfs_read_apps();
  459. pthread_mutex_lock(&lock);
  460. ebpf_vfs_send_data(em);
  461. fflush(stdout);
  462. if (apps)
  463. ebpf_vfs_send_apps_data(em, apps_groups_root_target);
  464. pthread_mutex_unlock(&lock);
  465. pthread_mutex_unlock(&collect_data_mutex);
  466. }
  467. }
  468. /*****************************************************************
  469. *
  470. * FUNCTIONS TO CREATE CHARTS
  471. *
  472. *****************************************************************/
  473. /**
  474. * Create IO chart
  475. *
  476. * @param family the chart family
  477. * @param name the chart name
  478. * @param axis the axis label
  479. * @param web the group name used to attach the chart on dashboard
  480. * @param order the order number of the specified chart
  481. * @param algorithm the algorithm used to make the charts.
  482. */
  483. static void ebpf_create_io_chart(char *family, char *name, char *axis, char *web, int order, int algorithm)
  484. {
  485. printf("CHART %s.%s '' 'Bytes written and read' '%s' '%s' '' line %d %d\n",
  486. family,
  487. name,
  488. axis,
  489. web,
  490. order,
  491. update_every);
  492. printf("DIMENSION %s %s %s 1 1\n",
  493. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ],
  494. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_READ],
  495. ebpf_algorithms[algorithm]);
  496. printf("DIMENSION %s %s %s -1 1\n",
  497. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  498. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  499. ebpf_algorithms[algorithm]);
  500. }
  501. /**
  502. * Create global charts
  503. *
  504. * Call ebpf_create_chart to create the charts for the collector.
  505. *
  506. * @param em a pointer to the structure with the default values.
  507. */
  508. static void ebpf_create_global_charts(ebpf_module_t *em)
  509. {
  510. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  511. NETDATA_VFS_FILE_CLEAN_COUNT,
  512. "Remove files",
  513. EBPF_COMMON_DIMENSION_CALL,
  514. NETDATA_VFS_GROUP,
  515. NULL,
  516. NETDATA_EBPF_CHART_TYPE_LINE,
  517. NETDATA_CHART_PRIO_FILESYSTEM_VFS_CLEAN,
  518. ebpf_create_global_dimension,
  519. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  520. 1);
  521. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  522. NETDATA_VFS_FILE_IO_COUNT,
  523. "Calls to IO",
  524. EBPF_COMMON_DIMENSION_CALL,
  525. NETDATA_VFS_GROUP,
  526. NULL,
  527. NETDATA_EBPF_CHART_TYPE_LINE,
  528. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_COUNT,
  529. ebpf_create_global_dimension,
  530. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  531. 2);
  532. ebpf_create_io_chart(NETDATA_FILESYSTEM_FAMILY,
  533. NETDATA_VFS_IO_FILE_BYTES, EBPF_COMMON_DIMENSION_BYTES,
  534. NETDATA_VFS_GROUP,
  535. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_BYTES,
  536. NETDATA_EBPF_INCREMENTAL_IDX);
  537. if (em->mode < MODE_ENTRY) {
  538. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  539. NETDATA_VFS_FILE_ERR_COUNT,
  540. "Fails to write or read",
  541. EBPF_COMMON_DIMENSION_CALL,
  542. NETDATA_VFS_GROUP,
  543. NULL,
  544. NETDATA_EBPF_CHART_TYPE_LINE,
  545. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EBYTES,
  546. ebpf_create_global_dimension,
  547. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  548. 2);
  549. }
  550. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  551. NETDATA_VFS_FSYNC,
  552. "Calls to vfs_fsync",
  553. EBPF_COMMON_DIMENSION_CALL,
  554. NETDATA_VFS_GROUP,
  555. NULL,
  556. NETDATA_EBPF_CHART_TYPE_LINE,
  557. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_FSYNC,
  558. ebpf_create_global_dimension,
  559. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  560. 1);
  561. if (em->mode < MODE_ENTRY) {
  562. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  563. NETDATA_VFS_FSYNC_ERR,
  564. "Fails to synchronize",
  565. EBPF_COMMON_DIMENSION_CALL,
  566. NETDATA_VFS_GROUP,
  567. NULL,
  568. NETDATA_EBPF_CHART_TYPE_LINE,
  569. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EFSYNC,
  570. ebpf_create_global_dimension,
  571. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  572. 1);
  573. }
  574. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  575. NETDATA_VFS_OPEN,
  576. "Calls to vfs_open",
  577. EBPF_COMMON_DIMENSION_CALL,
  578. NETDATA_VFS_GROUP,
  579. NULL,
  580. NETDATA_EBPF_CHART_TYPE_LINE,
  581. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_OPEN,
  582. ebpf_create_global_dimension,
  583. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  584. 1);
  585. if (em->mode < MODE_ENTRY) {
  586. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  587. NETDATA_VFS_OPEN_ERR,
  588. "Fails to open a file",
  589. EBPF_COMMON_DIMENSION_CALL,
  590. NETDATA_VFS_GROUP,
  591. NULL,
  592. NETDATA_EBPF_CHART_TYPE_LINE,
  593. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EOPEN,
  594. ebpf_create_global_dimension,
  595. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  596. 1);
  597. }
  598. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  599. NETDATA_VFS_CREATE,
  600. "Calls to vfs_create",
  601. EBPF_COMMON_DIMENSION_CALL,
  602. NETDATA_VFS_GROUP,
  603. NULL,
  604. NETDATA_EBPF_CHART_TYPE_LINE,
  605. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_CREATE,
  606. ebpf_create_global_dimension,
  607. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  608. 1);
  609. if (em->mode < MODE_ENTRY) {
  610. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  611. NETDATA_VFS_CREATE_ERR,
  612. "Fails to create a file.",
  613. EBPF_COMMON_DIMENSION_CALL,
  614. NETDATA_VFS_GROUP,
  615. NULL,
  616. NETDATA_EBPF_CHART_TYPE_LINE,
  617. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_ECREATE,
  618. ebpf_create_global_dimension,
  619. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  620. 1);
  621. }
  622. }
  623. /**
  624. * Create process apps charts
  625. *
  626. * Call ebpf_create_chart to create the charts on apps submenu.
  627. *
  628. * @param em a pointer to the structure with the default values.
  629. * @param ptr a pointer for the targets.
  630. **/
  631. void ebpf_vfs_create_apps_charts(struct ebpf_module *em, void *ptr)
  632. {
  633. struct target *root = ptr;
  634. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_FILE_DELETED,
  635. "Files deleted",
  636. EBPF_COMMON_DIMENSION_CALL,
  637. NETDATA_APPS_VFS_GROUP,
  638. NETDATA_EBPF_CHART_TYPE_STACKED,
  639. 20065,
  640. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  641. root);
  642. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS,
  643. "Write to disk",
  644. EBPF_COMMON_DIMENSION_CALL,
  645. NETDATA_APPS_VFS_GROUP,
  646. NETDATA_EBPF_CHART_TYPE_STACKED,
  647. 20066,
  648. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  649. apps_groups_root_target);
  650. if (em->mode < MODE_ENTRY) {
  651. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR,
  652. "Fails to write",
  653. EBPF_COMMON_DIMENSION_CALL,
  654. NETDATA_APPS_VFS_GROUP,
  655. NETDATA_EBPF_CHART_TYPE_STACKED,
  656. 20067,
  657. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  658. root);
  659. }
  660. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS,
  661. "Read from disk",
  662. EBPF_COMMON_DIMENSION_CALL,
  663. NETDATA_APPS_VFS_GROUP,
  664. NETDATA_EBPF_CHART_TYPE_STACKED,
  665. 20068,
  666. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  667. root);
  668. if (em->mode < MODE_ENTRY) {
  669. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR,
  670. "Fails to read",
  671. EBPF_COMMON_DIMENSION_CALL,
  672. NETDATA_APPS_VFS_GROUP,
  673. NETDATA_EBPF_CHART_TYPE_STACKED,
  674. 20069,
  675. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  676. root);
  677. }
  678. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES,
  679. "Bytes written on disk", EBPF_COMMON_DIMENSION_BYTES,
  680. NETDATA_APPS_VFS_GROUP,
  681. NETDATA_EBPF_CHART_TYPE_STACKED,
  682. 20070,
  683. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  684. root);
  685. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_BYTES,
  686. "Bytes read from disk", EBPF_COMMON_DIMENSION_BYTES,
  687. NETDATA_APPS_VFS_GROUP,
  688. NETDATA_EBPF_CHART_TYPE_STACKED,
  689. 20071,
  690. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  691. root);
  692. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC,
  693. "Calls for <code>vfs_fsync</code>", EBPF_COMMON_DIMENSION_CALL,
  694. NETDATA_APPS_VFS_GROUP,
  695. NETDATA_EBPF_CHART_TYPE_STACKED,
  696. 20072,
  697. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  698. root);
  699. if (em->mode < MODE_ENTRY) {
  700. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR,
  701. "Sync error",
  702. EBPF_COMMON_DIMENSION_CALL,
  703. NETDATA_APPS_VFS_GROUP,
  704. NETDATA_EBPF_CHART_TYPE_STACKED,
  705. 20073,
  706. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  707. root);
  708. }
  709. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN,
  710. "Calls for <code>vfs_open</code>", EBPF_COMMON_DIMENSION_CALL,
  711. NETDATA_APPS_VFS_GROUP,
  712. NETDATA_EBPF_CHART_TYPE_STACKED,
  713. 20074,
  714. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  715. root);
  716. if (em->mode < MODE_ENTRY) {
  717. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR,
  718. "Open error",
  719. EBPF_COMMON_DIMENSION_CALL,
  720. NETDATA_APPS_VFS_GROUP,
  721. NETDATA_EBPF_CHART_TYPE_STACKED,
  722. 20075,
  723. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  724. root);
  725. }
  726. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE,
  727. "Calls for <code>vfs_create</code>", EBPF_COMMON_DIMENSION_CALL,
  728. NETDATA_APPS_VFS_GROUP,
  729. NETDATA_EBPF_CHART_TYPE_STACKED,
  730. 20076,
  731. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  732. root);
  733. if (em->mode < MODE_ENTRY) {
  734. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR,
  735. "Create error",
  736. EBPF_COMMON_DIMENSION_CALL,
  737. NETDATA_APPS_VFS_GROUP,
  738. NETDATA_EBPF_CHART_TYPE_STACKED,
  739. 20077,
  740. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  741. root);
  742. }
  743. }
  744. /*****************************************************************
  745. *
  746. * FUNCTIONS TO START THREAD
  747. *
  748. *****************************************************************/
  749. /**
  750. * Allocate vectors used with this thread.
  751. * We are not testing the return, because callocz does this and shutdown the software
  752. * case it was not possible to allocate.
  753. *
  754. * @param length is the length for the vectors used inside the collector.
  755. */
  756. static void ebpf_vfs_allocate_global_vectors()
  757. {
  758. memset(vfs_aggregated_data, 0, sizeof(vfs_aggregated_data));
  759. memset(vfs_publish_aggregated, 0, sizeof(vfs_publish_aggregated));
  760. vfs_hash_values = callocz(ebpf_nprocs, sizeof(netdata_idx_t));
  761. vfs_vector = callocz(ebpf_nprocs, sizeof(netdata_publish_vfs_t));
  762. vfs_pid = callocz((size_t)pid_max, sizeof(netdata_publish_vfs_t *));
  763. }
  764. /*****************************************************************
  765. *
  766. * EBPF PROCESS THREAD
  767. *
  768. *****************************************************************/
  769. /**
  770. * Process thread
  771. *
  772. * Thread used to generate process charts.
  773. *
  774. * @param ptr a pointer to `struct ebpf_module`
  775. *
  776. * @return It always return NULL
  777. */
  778. void *ebpf_vfs_thread(void *ptr)
  779. {
  780. netdata_thread_cleanup_push(ebpf_vfs_cleanup, ptr);
  781. ebpf_module_t *em = (ebpf_module_t *)ptr;
  782. em->maps = vfs_maps;
  783. fill_ebpf_data(&vfs_data);
  784. ebpf_update_pid_table(&vfs_maps[NETDATA_VFS_PID], em);
  785. ebpf_vfs_allocate_global_vectors();
  786. if (!em->enabled)
  787. goto endvfs;
  788. if (ebpf_update_kernel(&vfs_data)) {
  789. goto endvfs;
  790. }
  791. probe_links = ebpf_load_program(ebpf_plugin_dir, em, kernel_string, &objects, vfs_data.map_fd);
  792. if (!probe_links) {
  793. goto endvfs;
  794. }
  795. int algorithms[NETDATA_KEY_PUBLISH_PROCESS_END] = {
  796. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX,
  797. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX
  798. };
  799. ebpf_global_labels(vfs_aggregated_data, vfs_publish_aggregated, vfs_dimension_names,
  800. vfs_id_names, algorithms, NETDATA_KEY_PUBLISH_VFS_END);
  801. pthread_mutex_lock(&lock);
  802. ebpf_create_global_charts(em);
  803. pthread_mutex_unlock(&lock);
  804. vfs_collector(em);
  805. endvfs:
  806. netdata_thread_cleanup_pop(1);
  807. return NULL;
  808. }