ebpf_vfs.c 111 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include <sys/resource.h>
  3. #include "ebpf.h"
  4. #include "ebpf_vfs.h"
  5. static char *vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_END] = { "delete", "read", "write",
  6. "fsync", "open", "create" };
  7. static char *vfs_id_names[NETDATA_KEY_PUBLISH_VFS_END] = { "vfs_unlink", "vfs_read", "vfs_write",
  8. "vfs_fsync", "vfs_open", "vfs_create"};
  9. static netdata_idx_t *vfs_hash_values = NULL;
  10. static netdata_syscall_stat_t vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_END];
  11. static netdata_publish_syscall_t vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_END];
  12. netdata_publish_vfs_t *vfs_vector = NULL;
  13. static ebpf_local_maps_t vfs_maps[] = {{.name = "tbl_vfs_pid", .internal_input = ND_EBPF_DEFAULT_PID_SIZE,
  14. .user_input = 0, .type = NETDATA_EBPF_MAP_RESIZABLE | NETDATA_EBPF_MAP_PID,
  15. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  16. #ifdef LIBBPF_MAJOR_VERSION
  17. .map_type = BPF_MAP_TYPE_PERCPU_HASH
  18. #endif
  19. },
  20. {.name = "tbl_vfs_stats", .internal_input = NETDATA_VFS_COUNTER,
  21. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  22. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  23. #ifdef LIBBPF_MAJOR_VERSION
  24. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  25. #endif
  26. },
  27. {.name = "vfs_ctrl", .internal_input = NETDATA_CONTROLLER_END,
  28. .user_input = 0,
  29. .type = NETDATA_EBPF_MAP_CONTROLLER,
  30. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  31. #ifdef LIBBPF_MAJOR_VERSION
  32. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  33. #endif
  34. },
  35. {.name = NULL, .internal_input = 0, .user_input = 0,
  36. #ifdef LIBBPF_MAJOR_VERSION
  37. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  38. #endif
  39. }};
  40. struct config vfs_config = { .first_section = NULL,
  41. .last_section = NULL,
  42. .mutex = NETDATA_MUTEX_INITIALIZER,
  43. .index = { .avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  44. .rwlock = AVL_LOCK_INITIALIZER } };
  45. netdata_ebpf_targets_t vfs_targets[] = { {.name = "vfs_write", .mode = EBPF_LOAD_TRAMPOLINE},
  46. {.name = "vfs_writev", .mode = EBPF_LOAD_TRAMPOLINE},
  47. {.name = "vfs_read", .mode = EBPF_LOAD_TRAMPOLINE},
  48. {.name = "vfs_readv", .mode = EBPF_LOAD_TRAMPOLINE},
  49. {.name = "vfs_unlink", .mode = EBPF_LOAD_TRAMPOLINE},
  50. {.name = "vfs_fsync", .mode = EBPF_LOAD_TRAMPOLINE},
  51. {.name = "vfs_open", .mode = EBPF_LOAD_TRAMPOLINE},
  52. {.name = "vfs_create", .mode = EBPF_LOAD_TRAMPOLINE},
  53. {.name = "release_task", .mode = EBPF_LOAD_TRAMPOLINE},
  54. {.name = NULL, .mode = EBPF_LOAD_TRAMPOLINE}};
  55. #ifdef NETDATA_DEV_MODE
  56. int vfs_disable_priority;
  57. #endif
  58. #ifdef LIBBPF_MAJOR_VERSION
  59. /**
  60. * Disable probe
  61. *
  62. * Disable all probes to use exclusively another method.
  63. *
  64. * @param obj is the main structure for bpf objects
  65. */
  66. static void ebpf_vfs_disable_probes(struct vfs_bpf *obj)
  67. {
  68. bpf_program__set_autoload(obj->progs.netdata_vfs_write_kprobe, false);
  69. bpf_program__set_autoload(obj->progs.netdata_vfs_write_kretprobe, false);
  70. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_kprobe, false);
  71. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_kretprobe, false);
  72. bpf_program__set_autoload(obj->progs.netdata_vfs_read_kprobe, false);
  73. bpf_program__set_autoload(obj->progs.netdata_vfs_read_kretprobe, false);
  74. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_kprobe, false);
  75. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_kretprobe, false);
  76. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_kprobe, false);
  77. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_kretprobe, false);
  78. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_kprobe, false);
  79. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_kretprobe, false);
  80. bpf_program__set_autoload(obj->progs.netdata_vfs_open_kprobe, false);
  81. bpf_program__set_autoload(obj->progs.netdata_vfs_open_kretprobe, false);
  82. bpf_program__set_autoload(obj->progs.netdata_vfs_create_kprobe, false);
  83. bpf_program__set_autoload(obj->progs.netdata_vfs_create_kretprobe, false);
  84. }
  85. /*
  86. * Disable trampoline
  87. *
  88. * Disable all trampoline to use exclusively another method.
  89. *
  90. * @param obj is the main structure for bpf objects.
  91. */
  92. static void ebpf_vfs_disable_trampoline(struct vfs_bpf *obj)
  93. {
  94. bpf_program__set_autoload(obj->progs.netdata_vfs_write_fentry, false);
  95. bpf_program__set_autoload(obj->progs.netdata_vfs_write_fexit, false);
  96. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_fentry, false);
  97. bpf_program__set_autoload(obj->progs.netdata_vfs_writev_fexit, false);
  98. bpf_program__set_autoload(obj->progs.netdata_vfs_read_fentry, false);
  99. bpf_program__set_autoload(obj->progs.netdata_vfs_read_fexit, false);
  100. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_fentry, false);
  101. bpf_program__set_autoload(obj->progs.netdata_vfs_readv_fexit, false);
  102. bpf_program__set_autoload(obj->progs.netdata_vfs_unlink_fentry, false);
  103. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_fentry, false);
  104. bpf_program__set_autoload(obj->progs.netdata_vfs_fsync_fexit, false);
  105. bpf_program__set_autoload(obj->progs.netdata_vfs_open_fentry, false);
  106. bpf_program__set_autoload(obj->progs.netdata_vfs_open_fexit, false);
  107. bpf_program__set_autoload(obj->progs.netdata_vfs_create_fentry, false);
  108. }
  109. /**
  110. * Set trampoline target
  111. *
  112. * Set the targets we will monitor.
  113. *
  114. * @param obj is the main structure for bpf objects.
  115. */
  116. static void ebpf_vfs_set_trampoline_target(struct vfs_bpf *obj)
  117. {
  118. bpf_program__set_attach_target(obj->progs.netdata_vfs_write_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  119. bpf_program__set_attach_target(obj->progs.netdata_vfs_write_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  120. bpf_program__set_attach_target(obj->progs.netdata_vfs_writev_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  121. bpf_program__set_attach_target(obj->progs.netdata_vfs_writev_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  122. bpf_program__set_attach_target(obj->progs.netdata_vfs_read_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_READ].name);
  123. bpf_program__set_attach_target(obj->progs.netdata_vfs_read_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_READ].name);
  124. bpf_program__set_attach_target(obj->progs.netdata_vfs_readv_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_READV].name);
  125. bpf_program__set_attach_target(obj->progs.netdata_vfs_readv_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_READV].name);
  126. bpf_program__set_attach_target(obj->progs.netdata_vfs_unlink_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  127. bpf_program__set_attach_target(obj->progs.netdata_vfs_fsync_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  128. bpf_program__set_attach_target(obj->progs.netdata_vfs_fsync_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  129. bpf_program__set_attach_target(obj->progs.netdata_vfs_open_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  130. bpf_program__set_attach_target(obj->progs.netdata_vfs_open_fexit, 0, vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  131. bpf_program__set_attach_target(obj->progs.netdata_vfs_create_fentry, 0, vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  132. }
  133. /**
  134. * Attach Probe
  135. *
  136. * Attach probes to target
  137. *
  138. * @param obj is the main structure for bpf objects.
  139. *
  140. * @return It returns 0 on success and -1 otherwise.
  141. */
  142. static int ebpf_vfs_attach_probe(struct vfs_bpf *obj)
  143. {
  144. obj->links.netdata_vfs_write_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_write_kprobe, false,
  145. vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  146. int ret = libbpf_get_error(obj->links.netdata_vfs_write_kprobe);
  147. if (ret)
  148. return -1;
  149. obj->links.netdata_vfs_write_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_write_kretprobe, true,
  150. vfs_targets[NETDATA_EBPF_VFS_WRITE].name);
  151. ret = libbpf_get_error(obj->links.netdata_vfs_write_kretprobe);
  152. if (ret)
  153. return -1;
  154. obj->links.netdata_vfs_writev_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_writev_kprobe, false,
  155. vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  156. ret = libbpf_get_error(obj->links.netdata_vfs_writev_kprobe);
  157. if (ret)
  158. return -1;
  159. obj->links.netdata_vfs_writev_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_writev_kretprobe, true,
  160. vfs_targets[NETDATA_EBPF_VFS_WRITEV].name);
  161. ret = libbpf_get_error(obj->links.netdata_vfs_writev_kretprobe);
  162. if (ret)
  163. return -1;
  164. obj->links.netdata_vfs_read_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_read_kprobe, false,
  165. vfs_targets[NETDATA_EBPF_VFS_READ].name);
  166. ret = libbpf_get_error(obj->links.netdata_vfs_read_kprobe);
  167. if (ret)
  168. return -1;
  169. obj->links.netdata_vfs_read_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_read_kretprobe, true,
  170. vfs_targets[NETDATA_EBPF_VFS_READ].name);
  171. ret = libbpf_get_error(obj->links.netdata_vfs_read_kretprobe);
  172. if (ret)
  173. return -1;
  174. obj->links.netdata_vfs_readv_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_readv_kprobe, false,
  175. vfs_targets[NETDATA_EBPF_VFS_READV].name);
  176. ret = libbpf_get_error(obj->links.netdata_vfs_readv_kprobe);
  177. if (ret)
  178. return -1;
  179. obj->links.netdata_vfs_readv_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_readv_kretprobe, true,
  180. vfs_targets[NETDATA_EBPF_VFS_READV].name);
  181. ret = libbpf_get_error(obj->links.netdata_vfs_readv_kretprobe);
  182. if (ret)
  183. return -1;
  184. obj->links.netdata_vfs_unlink_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_unlink_kprobe, false,
  185. vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  186. ret = libbpf_get_error(obj->links.netdata_vfs_unlink_kprobe);
  187. if (ret)
  188. return -1;
  189. obj->links.netdata_vfs_unlink_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_unlink_kretprobe, true,
  190. vfs_targets[NETDATA_EBPF_VFS_UNLINK].name);
  191. ret = libbpf_get_error(obj->links.netdata_vfs_unlink_kretprobe);
  192. if (ret)
  193. return -1;
  194. obj->links.netdata_vfs_fsync_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kprobe, false,
  195. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  196. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kprobe);
  197. if (ret)
  198. return -1;
  199. obj->links.netdata_vfs_fsync_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kretprobe, true,
  200. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  201. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kretprobe);
  202. if (ret)
  203. return -1;
  204. obj->links.netdata_vfs_open_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kprobe, false,
  205. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  206. ret = libbpf_get_error(obj->links.netdata_vfs_open_kprobe);
  207. if (ret)
  208. return -1;
  209. obj->links.netdata_vfs_open_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kretprobe, true,
  210. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  211. ret = libbpf_get_error(obj->links.netdata_vfs_open_kretprobe);
  212. if (ret)
  213. return -1;
  214. obj->links.netdata_vfs_create_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kprobe, false,
  215. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  216. ret = libbpf_get_error(obj->links.netdata_vfs_create_kprobe);
  217. if (ret)
  218. return -1;
  219. obj->links.netdata_vfs_create_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kretprobe, true,
  220. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  221. ret = libbpf_get_error(obj->links.netdata_vfs_create_kretprobe);
  222. if (ret)
  223. return -1;
  224. obj->links.netdata_vfs_fsync_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kprobe, false,
  225. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  226. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kprobe);
  227. if (ret)
  228. return -1;
  229. obj->links.netdata_vfs_fsync_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_fsync_kretprobe, true,
  230. vfs_targets[NETDATA_EBPF_VFS_FSYNC].name);
  231. ret = libbpf_get_error(obj->links.netdata_vfs_fsync_kretprobe);
  232. if (ret)
  233. return -1;
  234. obj->links.netdata_vfs_open_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kprobe, false,
  235. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  236. ret = libbpf_get_error(obj->links.netdata_vfs_open_kprobe);
  237. if (ret)
  238. return -1;
  239. obj->links.netdata_vfs_open_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_open_kretprobe, true,
  240. vfs_targets[NETDATA_EBPF_VFS_OPEN].name);
  241. ret = libbpf_get_error(obj->links.netdata_vfs_open_kretprobe);
  242. if (ret)
  243. return -1;
  244. obj->links.netdata_vfs_create_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kprobe, false,
  245. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  246. ret = libbpf_get_error(obj->links.netdata_vfs_create_kprobe);
  247. if (ret)
  248. return -1;
  249. obj->links.netdata_vfs_create_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_vfs_create_kretprobe, true,
  250. vfs_targets[NETDATA_EBPF_VFS_CREATE].name);
  251. ret = libbpf_get_error(obj->links.netdata_vfs_create_kretprobe);
  252. if (ret)
  253. return -1;
  254. return 0;
  255. }
  256. /**
  257. * Adjust Size
  258. *
  259. * Resize maps according input from users.
  260. *
  261. * @param obj is the main structure for bpf objects.
  262. * @param em structure with configuration
  263. */
  264. static void ebpf_vfs_adjust_map(struct vfs_bpf *obj, ebpf_module_t *em)
  265. {
  266. ebpf_update_map_size(obj->maps.tbl_vfs_pid, &vfs_maps[NETDATA_VFS_PID],
  267. em, bpf_map__name(obj->maps.tbl_vfs_pid));
  268. ebpf_update_map_type(obj->maps.tbl_vfs_pid, &vfs_maps[NETDATA_VFS_PID]);
  269. ebpf_update_map_type(obj->maps.tbl_vfs_stats, &vfs_maps[NETDATA_VFS_ALL]);
  270. ebpf_update_map_type(obj->maps.vfs_ctrl, &vfs_maps[NETDATA_VFS_CTRL]);
  271. }
  272. /**
  273. * Set hash tables
  274. *
  275. * Set the values for maps according the value given by kernel.
  276. *
  277. * @param obj is the main structure for bpf objects.
  278. */
  279. static void ebpf_vfs_set_hash_tables(struct vfs_bpf *obj)
  280. {
  281. vfs_maps[NETDATA_VFS_ALL].map_fd = bpf_map__fd(obj->maps.tbl_vfs_stats);
  282. vfs_maps[NETDATA_VFS_PID].map_fd = bpf_map__fd(obj->maps.tbl_vfs_pid);
  283. vfs_maps[NETDATA_VFS_CTRL].map_fd = bpf_map__fd(obj->maps.vfs_ctrl);
  284. }
  285. /**
  286. * Load and attach
  287. *
  288. * Load and attach the eBPF code in kernel.
  289. *
  290. * @param obj is the main structure for bpf objects.
  291. * @param em structure with configuration
  292. *
  293. * @return it returns 0 on success and -1 otherwise
  294. */
  295. static inline int ebpf_vfs_load_and_attach(struct vfs_bpf *obj, ebpf_module_t *em)
  296. {
  297. netdata_ebpf_targets_t *mt = em->targets;
  298. netdata_ebpf_program_loaded_t test = mt[NETDATA_EBPF_VFS_WRITE].mode;
  299. if (test == EBPF_LOAD_TRAMPOLINE) {
  300. ebpf_vfs_disable_probes(obj);
  301. ebpf_vfs_set_trampoline_target(obj);
  302. } else {
  303. ebpf_vfs_disable_trampoline(obj);
  304. }
  305. ebpf_vfs_adjust_map(obj, em);
  306. int ret = vfs_bpf__load(obj);
  307. if (ret) {
  308. return ret;
  309. }
  310. ret = (test == EBPF_LOAD_TRAMPOLINE) ? vfs_bpf__attach(obj) : ebpf_vfs_attach_probe(obj);
  311. if (!ret) {
  312. ebpf_vfs_set_hash_tables(obj);
  313. ebpf_update_controller(vfs_maps[NETDATA_VFS_CTRL].map_fd, em);
  314. }
  315. return ret;
  316. }
  317. #endif
  318. /*****************************************************************
  319. *
  320. * FUNCTIONS TO CLOSE THE THREAD
  321. *
  322. *****************************************************************/
  323. static void ebpf_obsolete_specific_vfs_charts(char *type, ebpf_module_t *em);
  324. /**
  325. * Obsolete services
  326. *
  327. * Obsolete all service charts created
  328. *
  329. * @param em a pointer to `struct ebpf_module`
  330. */
  331. static void ebpf_obsolete_vfs_services(ebpf_module_t *em)
  332. {
  333. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  334. NETDATA_SYSCALL_APPS_FILE_DELETED,
  335. "",
  336. "Files deleted",
  337. EBPF_COMMON_DIMENSION_CALL,
  338. NETDATA_VFS_CGROUP_GROUP,
  339. NETDATA_EBPF_CHART_TYPE_STACKED,
  340. NULL,
  341. 20065,
  342. em->update_every);
  343. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  344. NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS,
  345. "",
  346. "Write to disk",
  347. EBPF_COMMON_DIMENSION_CALL,
  348. NETDATA_VFS_CGROUP_GROUP,
  349. NETDATA_EBPF_CHART_TYPE_STACKED,
  350. NULL,
  351. 20066,
  352. em->update_every);
  353. if (em->mode < MODE_ENTRY) {
  354. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  355. NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR,
  356. "",
  357. "Fails to write",
  358. EBPF_COMMON_DIMENSION_CALL,
  359. NETDATA_VFS_CGROUP_GROUP,
  360. NETDATA_EBPF_CHART_TYPE_STACKED,
  361. NULL,
  362. 20067,
  363. em->update_every);
  364. }
  365. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  366. NETDATA_SYSCALL_APPS_VFS_READ_CALLS,
  367. "",
  368. "Read from disk",
  369. EBPF_COMMON_DIMENSION_CALL,
  370. NETDATA_VFS_CGROUP_GROUP,
  371. NETDATA_EBPF_CHART_TYPE_STACKED,
  372. NULL,
  373. 20068,
  374. em->update_every);
  375. if (em->mode < MODE_ENTRY) {
  376. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  377. NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR,
  378. "",
  379. "Fails to read",
  380. EBPF_COMMON_DIMENSION_CALL,
  381. NETDATA_VFS_CGROUP_GROUP,
  382. NETDATA_EBPF_CHART_TYPE_STACKED,
  383. NULL,
  384. 20069,
  385. em->update_every);
  386. }
  387. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  388. NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES,
  389. "",
  390. "Bytes written on disk",
  391. EBPF_COMMON_DIMENSION_BYTES,
  392. NETDATA_VFS_CGROUP_GROUP,
  393. NETDATA_EBPF_CHART_TYPE_STACKED,
  394. NULL,
  395. 20070,
  396. em->update_every);
  397. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  398. NETDATA_SYSCALL_APPS_VFS_READ_BYTES,
  399. "",
  400. "Bytes read from disk",
  401. EBPF_COMMON_DIMENSION_BYTES,
  402. NETDATA_VFS_CGROUP_GROUP,
  403. NETDATA_EBPF_CHART_TYPE_STACKED,
  404. NULL,
  405. 20071,
  406. em->update_every);
  407. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  408. NETDATA_SYSCALL_APPS_VFS_FSYNC,
  409. "",
  410. "Calls to vfs_fsync.",
  411. EBPF_COMMON_DIMENSION_CALL,
  412. NETDATA_VFS_CGROUP_GROUP,
  413. NETDATA_EBPF_CHART_TYPE_STACKED,
  414. NULL,
  415. 20072,
  416. em->update_every);
  417. if (em->mode < MODE_ENTRY) {
  418. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  419. NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR,
  420. "",
  421. "Sync error",
  422. EBPF_COMMON_DIMENSION_CALL,
  423. NETDATA_VFS_CGROUP_GROUP,
  424. NETDATA_EBPF_CHART_TYPE_STACKED,
  425. NULL,
  426. 20073,
  427. em->update_every);
  428. }
  429. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  430. NETDATA_SYSCALL_APPS_VFS_OPEN,
  431. "",
  432. "Calls to vfs_open.",
  433. EBPF_COMMON_DIMENSION_CALL,
  434. NETDATA_VFS_CGROUP_GROUP,
  435. NETDATA_EBPF_CHART_TYPE_STACKED,
  436. NULL,
  437. 20074,
  438. em->update_every);
  439. if (em->mode < MODE_ENTRY) {
  440. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  441. NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR,
  442. "",
  443. "Open error",
  444. EBPF_COMMON_DIMENSION_CALL,
  445. NETDATA_VFS_CGROUP_GROUP,
  446. NETDATA_EBPF_CHART_TYPE_STACKED,
  447. NULL,
  448. 20075,
  449. em->update_every);
  450. }
  451. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  452. NETDATA_SYSCALL_APPS_VFS_CREATE,
  453. "",
  454. "Calls to vfs_create.",
  455. EBPF_COMMON_DIMENSION_CALL,
  456. NETDATA_VFS_CGROUP_GROUP,
  457. NETDATA_EBPF_CHART_TYPE_STACKED,
  458. NULL,
  459. 20076,
  460. em->update_every);
  461. if (em->mode < MODE_ENTRY) {
  462. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  463. NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR,
  464. "",
  465. "Create error",
  466. EBPF_COMMON_DIMENSION_CALL,
  467. NETDATA_VFS_CGROUP_GROUP,
  468. NETDATA_EBPF_CHART_TYPE_STACKED,
  469. NULL,
  470. 20077,
  471. em->update_every);
  472. }
  473. }
  474. /**
  475. * Obsolete cgroup chart
  476. *
  477. * Send obsolete for all charts created before to close.
  478. *
  479. * @param em a pointer to `struct ebpf_module`
  480. */
  481. static inline void ebpf_obsolete_vfs_cgroup_charts(ebpf_module_t *em) {
  482. pthread_mutex_lock(&mutex_cgroup_shm);
  483. ebpf_obsolete_vfs_services(em);
  484. ebpf_cgroup_target_t *ect;
  485. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  486. if (ect->systemd)
  487. continue;
  488. ebpf_obsolete_specific_vfs_charts(ect->name, em);
  489. }
  490. pthread_mutex_unlock(&mutex_cgroup_shm);
  491. }
  492. /**
  493. * Obsolette apps charts
  494. *
  495. * Obsolete apps charts.
  496. *
  497. * @param em a pointer to the structure with the default values.
  498. */
  499. void ebpf_obsolete_vfs_apps_charts(struct ebpf_module *em)
  500. {
  501. int order = 20275;
  502. struct ebpf_target *w;
  503. int update_every = em->update_every;
  504. for (w = apps_groups_root_target; w; w = w->next) {
  505. if (unlikely(!(w->charts_created & (1<<EBPF_MODULE_VFS_IDX))))
  506. continue;
  507. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  508. w->clean_name,
  509. "_ebpf_call_vfs_unlink",
  510. "Files deleted.",
  511. EBPF_COMMON_DIMENSION_CALL,
  512. NETDATA_VFS_GROUP,
  513. NETDATA_EBPF_CHART_TYPE_STACKED,
  514. "app.ebpf_call_vfs_unlink",
  515. order++,
  516. update_every);
  517. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  518. w->clean_name,
  519. "_ebpf_call_vfs_write",
  520. "Write to disk.",
  521. EBPF_COMMON_DIMENSION_CALL,
  522. NETDATA_VFS_GROUP,
  523. NETDATA_EBPF_CHART_TYPE_STACKED,
  524. "app.ebpf_call_vfs_write",
  525. order++,
  526. update_every);
  527. if (em->mode < MODE_ENTRY) {
  528. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  529. w->clean_name,
  530. "_ebpf_call_vfs_write_error",
  531. "Fails to write.",
  532. EBPF_COMMON_DIMENSION_CALL,
  533. NETDATA_VFS_GROUP,
  534. NETDATA_EBPF_CHART_TYPE_STACKED,
  535. "app.ebpf_call_vfs_write_error",
  536. order++,
  537. update_every);
  538. }
  539. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  540. w->clean_name,
  541. "_ebpf_call_vfs_read",
  542. "Read from disk.",
  543. EBPF_COMMON_DIMENSION_CALL,
  544. NETDATA_VFS_GROUP,
  545. NETDATA_EBPF_CHART_TYPE_STACKED,
  546. "app.ebpf_call_vfs_read",
  547. order++,
  548. update_every);
  549. if (em->mode < MODE_ENTRY) {
  550. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  551. w->clean_name,
  552. "_ebpf_call_vfs_read_error",
  553. "Fails to read.",
  554. EBPF_COMMON_DIMENSION_CALL,
  555. NETDATA_VFS_GROUP,
  556. NETDATA_EBPF_CHART_TYPE_STACKED,
  557. "app.ebpf_call_vfs_read_error",
  558. order++,
  559. update_every);
  560. }
  561. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  562. w->clean_name,
  563. "_ebpf_call_vfs_write_bytes",
  564. "Bytes written on disk.",
  565. EBPF_COMMON_DIMENSION_BYTES,
  566. NETDATA_VFS_GROUP,
  567. NETDATA_EBPF_CHART_TYPE_STACKED,
  568. "app.ebpf_call_vfs_write_bytes",
  569. order++,
  570. update_every);
  571. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  572. w->clean_name,
  573. "_ebpf_call_vfs_read_bytes",
  574. "Bytes read from disk.",
  575. EBPF_COMMON_DIMENSION_BYTES,
  576. NETDATA_VFS_GROUP,
  577. NETDATA_EBPF_CHART_TYPE_STACKED,
  578. "app.ebpf_call_vfs_read_bytes",
  579. order++,
  580. update_every);
  581. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  582. w->clean_name,
  583. "_ebpf_call_vfs_fsync",
  584. "Calls to vfs_fsync.",
  585. EBPF_COMMON_DIMENSION_CALL,
  586. NETDATA_VFS_GROUP,
  587. NETDATA_EBPF_CHART_TYPE_STACKED,
  588. "app.ebpf_call_vfs_fsync",
  589. order++,
  590. update_every);
  591. if (em->mode < MODE_ENTRY) {
  592. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  593. w->clean_name,
  594. "_ebpf_call_vfs_fsync_error",
  595. "Fails to sync.",
  596. EBPF_COMMON_DIMENSION_CALL,
  597. NETDATA_VFS_GROUP,
  598. NETDATA_EBPF_CHART_TYPE_STACKED,
  599. "app.ebpf_call_vfs_fsync_error",
  600. order++,
  601. update_every);
  602. }
  603. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  604. w->clean_name,
  605. "_ebpf_call_vfs_open",
  606. "Calls to vfs_open.",
  607. EBPF_COMMON_DIMENSION_CALL,
  608. NETDATA_VFS_GROUP,
  609. NETDATA_EBPF_CHART_TYPE_STACKED,
  610. "app.ebpf_call_vfs_open",
  611. order++,
  612. update_every);
  613. if (em->mode < MODE_ENTRY) {
  614. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  615. w->clean_name,
  616. "_ebpf_call_vfs_open_error",
  617. "Fails to open.",
  618. EBPF_COMMON_DIMENSION_CALL,
  619. NETDATA_VFS_GROUP,
  620. NETDATA_EBPF_CHART_TYPE_STACKED,
  621. "app.ebpf_call_vfs_open_error",
  622. order++,
  623. update_every);
  624. }
  625. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  626. w->clean_name,
  627. "_ebpf_call_vfs_create",
  628. "Calls to vfs_create.",
  629. EBPF_COMMON_DIMENSION_CALL,
  630. NETDATA_VFS_GROUP,
  631. NETDATA_EBPF_CHART_TYPE_STACKED,
  632. "app.ebpf_call_vfs_create",
  633. order++,
  634. update_every);
  635. if (em->mode < MODE_ENTRY) {
  636. ebpf_write_chart_obsolete(NETDATA_APP_FAMILY,
  637. w->clean_name,
  638. "_ebpf_call_vfs_create_error",
  639. "Fails to create.",
  640. EBPF_COMMON_DIMENSION_CALL,
  641. NETDATA_VFS_GROUP,
  642. NETDATA_EBPF_CHART_TYPE_STACKED,
  643. "app.ebpf_call_vfs_create_error",
  644. order++,
  645. update_every);
  646. }
  647. w->charts_created &= ~(1<<EBPF_MODULE_VFS_IDX);
  648. }
  649. }
  650. /**
  651. * Obsolete global
  652. *
  653. * Obsolete global charts created by thread.
  654. *
  655. * @param em a pointer to `struct ebpf_module`
  656. */
  657. static void ebpf_obsolete_vfs_global(ebpf_module_t *em)
  658. {
  659. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  660. NETDATA_VFS_FILE_CLEAN_COUNT,
  661. "",
  662. "Remove files",
  663. EBPF_COMMON_DIMENSION_CALL,
  664. NETDATA_VFS_GROUP,
  665. NETDATA_EBPF_CHART_TYPE_LINE,
  666. NULL,
  667. NETDATA_CHART_PRIO_FILESYSTEM_VFS_CLEAN,
  668. em->update_every);
  669. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  670. NETDATA_VFS_FILE_IO_COUNT,
  671. "",
  672. "Calls to IO",
  673. EBPF_COMMON_DIMENSION_CALL,
  674. NETDATA_VFS_GROUP,
  675. NETDATA_EBPF_CHART_TYPE_LINE,
  676. NULL,
  677. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_COUNT,
  678. em->update_every);
  679. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  680. NETDATA_VFS_IO_FILE_BYTES,
  681. "",
  682. "Bytes written and read",
  683. EBPF_COMMON_DIMENSION_BYTES,
  684. NETDATA_VFS_GROUP,
  685. NETDATA_EBPF_CHART_TYPE_LINE,
  686. NULL,
  687. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_BYTES,
  688. em->update_every);
  689. if (em->mode < MODE_ENTRY) {
  690. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  691. NETDATA_VFS_FILE_ERR_COUNT,
  692. "",
  693. "Fails to write or read",
  694. EBPF_COMMON_DIMENSION_CALL,
  695. NETDATA_VFS_GROUP,
  696. NETDATA_EBPF_CHART_TYPE_LINE,
  697. NULL,
  698. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EBYTES,
  699. em->update_every);
  700. }
  701. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  702. NETDATA_VFS_FSYNC,
  703. "",
  704. "Calls to vfs_fsync.",
  705. EBPF_COMMON_DIMENSION_CALL,
  706. NETDATA_VFS_GROUP,
  707. NETDATA_EBPF_CHART_TYPE_LINE,
  708. NULL,
  709. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_FSYNC,
  710. em->update_every);
  711. if (em->mode < MODE_ENTRY) {
  712. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  713. NETDATA_VFS_FSYNC_ERR,
  714. "",
  715. "Fails to synchronize",
  716. EBPF_COMMON_DIMENSION_CALL,
  717. NETDATA_VFS_GROUP,
  718. NETDATA_EBPF_CHART_TYPE_LINE,
  719. NULL,
  720. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EFSYNC,
  721. em->update_every);
  722. }
  723. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  724. NETDATA_VFS_OPEN,
  725. "",
  726. "Calls to vfs_open.",
  727. EBPF_COMMON_DIMENSION_CALL,
  728. NETDATA_VFS_GROUP,
  729. NETDATA_EBPF_CHART_TYPE_LINE,
  730. NULL,
  731. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_OPEN,
  732. em->update_every);
  733. if (em->mode < MODE_ENTRY) {
  734. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  735. NETDATA_VFS_OPEN_ERR,
  736. "",
  737. "Fails to open a file",
  738. EBPF_COMMON_DIMENSION_CALL,
  739. NETDATA_VFS_GROUP,
  740. NETDATA_EBPF_CHART_TYPE_LINE,
  741. NULL,
  742. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EOPEN,
  743. em->update_every);
  744. }
  745. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  746. NETDATA_VFS_CREATE,
  747. "",
  748. "Calls to vfs_create.",
  749. EBPF_COMMON_DIMENSION_CALL,
  750. NETDATA_VFS_GROUP,
  751. NETDATA_EBPF_CHART_TYPE_LINE,
  752. NULL,
  753. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_CREATE,
  754. em->update_every);
  755. if (em->mode < MODE_ENTRY) {
  756. ebpf_write_chart_obsolete(NETDATA_FILESYSTEM_FAMILY,
  757. NETDATA_VFS_CREATE_ERR,
  758. "",
  759. "Fails to create a file.",
  760. EBPF_COMMON_DIMENSION_CALL,
  761. NETDATA_VFS_GROUP,
  762. NETDATA_EBPF_CHART_TYPE_LINE,
  763. NULL,
  764. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_ECREATE,
  765. em->update_every);
  766. }
  767. }
  768. /**
  769. * Exit
  770. *
  771. * Cancel thread and exit.
  772. *
  773. * @param ptr thread data.
  774. **/
  775. static void ebpf_vfs_exit(void *ptr)
  776. {
  777. ebpf_module_t *em = (ebpf_module_t *)ptr;
  778. if (em->enabled == NETDATA_THREAD_EBPF_FUNCTION_RUNNING) {
  779. pthread_mutex_lock(&lock);
  780. if (em->cgroup_charts) {
  781. ebpf_obsolete_vfs_cgroup_charts(em);
  782. fflush(stdout);
  783. }
  784. if (em->apps_charts & NETDATA_EBPF_APPS_FLAG_CHART_CREATED) {
  785. ebpf_obsolete_vfs_apps_charts(em);
  786. }
  787. ebpf_obsolete_vfs_global(em);
  788. #ifdef NETDATA_DEV_MODE
  789. if (ebpf_aral_vfs_pid)
  790. ebpf_statistic_obsolete_aral_chart(em, vfs_disable_priority);
  791. #endif
  792. fflush(stdout);
  793. pthread_mutex_unlock(&lock);
  794. }
  795. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_REMOVE);
  796. #ifdef LIBBPF_MAJOR_VERSION
  797. if (vfs_bpf_obj) {
  798. vfs_bpf__destroy(vfs_bpf_obj);
  799. vfs_bpf_obj = NULL;
  800. }
  801. #endif
  802. if (em->objects) {
  803. ebpf_unload_legacy_code(em->objects, em->probe_links);
  804. em->objects = NULL;
  805. em->probe_links = NULL;
  806. }
  807. pthread_mutex_lock(&ebpf_exit_cleanup);
  808. em->enabled = NETDATA_THREAD_EBPF_STOPPED;
  809. ebpf_update_stats(&plugin_statistics, em);
  810. pthread_mutex_unlock(&ebpf_exit_cleanup);
  811. }
  812. /*****************************************************************
  813. *
  814. * FUNCTIONS WITH THE MAIN LOOP
  815. *
  816. *****************************************************************/
  817. /**
  818. * Send data to Netdata calling auxiliary functions.
  819. *
  820. * @param em the structure with thread information
  821. */
  822. static void ebpf_vfs_send_data(ebpf_module_t *em)
  823. {
  824. netdata_publish_vfs_common_t pvc;
  825. pvc.write = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes;
  826. pvc.read = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes;
  827. write_count_chart(NETDATA_VFS_FILE_CLEAN_COUNT, NETDATA_FILESYSTEM_FAMILY,
  828. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK], 1);
  829. write_count_chart(NETDATA_VFS_FILE_IO_COUNT, NETDATA_FILESYSTEM_FAMILY,
  830. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  831. if (em->mode < MODE_ENTRY) {
  832. write_err_chart(NETDATA_VFS_FILE_ERR_COUNT, NETDATA_FILESYSTEM_FAMILY,
  833. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  834. }
  835. write_io_chart(NETDATA_VFS_IO_FILE_BYTES, NETDATA_FILESYSTEM_FAMILY, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  836. (long long)pvc.write, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ], (long long)pvc.read);
  837. write_count_chart(NETDATA_VFS_FSYNC, NETDATA_FILESYSTEM_FAMILY,
  838. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  839. if (em->mode < MODE_ENTRY) {
  840. write_err_chart(NETDATA_VFS_FSYNC_ERR, NETDATA_FILESYSTEM_FAMILY,
  841. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  842. }
  843. write_count_chart(NETDATA_VFS_OPEN, NETDATA_FILESYSTEM_FAMILY,
  844. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  845. if (em->mode < MODE_ENTRY) {
  846. write_err_chart(NETDATA_VFS_OPEN_ERR, NETDATA_FILESYSTEM_FAMILY,
  847. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  848. }
  849. write_count_chart(NETDATA_VFS_CREATE, NETDATA_FILESYSTEM_FAMILY,
  850. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE], 1);
  851. if (em->mode < MODE_ENTRY) {
  852. write_err_chart(
  853. NETDATA_VFS_CREATE_ERR,
  854. NETDATA_FILESYSTEM_FAMILY,
  855. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  856. 1);
  857. }
  858. }
  859. /**
  860. * Read the hash table and store data to allocated vectors.
  861. *
  862. * @param stats vector used to read data from control table.
  863. * @param maps_per_core do I need to read all cores?
  864. */
  865. static void ebpf_vfs_read_global_table(netdata_idx_t *stats, int maps_per_core)
  866. {
  867. netdata_idx_t res[NETDATA_VFS_COUNTER];
  868. ebpf_read_global_table_stats(res,
  869. vfs_hash_values,
  870. vfs_maps[NETDATA_VFS_ALL].map_fd,
  871. maps_per_core,
  872. NETDATA_KEY_CALLS_VFS_WRITE,
  873. NETDATA_VFS_COUNTER);
  874. ebpf_read_global_table_stats(stats,
  875. vfs_hash_values,
  876. vfs_maps[NETDATA_VFS_CTRL].map_fd,
  877. maps_per_core,
  878. NETDATA_CONTROLLER_PID_TABLE_ADD,
  879. NETDATA_CONTROLLER_END);
  880. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].ncall = res[NETDATA_KEY_CALLS_VFS_UNLINK];
  881. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].ncall = res[NETDATA_KEY_CALLS_VFS_READ] +
  882. res[NETDATA_KEY_CALLS_VFS_READV];
  883. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].ncall = res[NETDATA_KEY_CALLS_VFS_WRITE] +
  884. res[NETDATA_KEY_CALLS_VFS_WRITEV];
  885. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].ncall = res[NETDATA_KEY_CALLS_VFS_FSYNC];
  886. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].ncall = res[NETDATA_KEY_CALLS_VFS_OPEN];
  887. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].ncall = res[NETDATA_KEY_CALLS_VFS_CREATE];
  888. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].nerr = res[NETDATA_KEY_ERROR_VFS_UNLINK];
  889. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].nerr = res[NETDATA_KEY_ERROR_VFS_READ] +
  890. res[NETDATA_KEY_ERROR_VFS_READV];
  891. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].nerr = res[NETDATA_KEY_ERROR_VFS_WRITE] +
  892. res[NETDATA_KEY_ERROR_VFS_WRITEV];
  893. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].nerr = res[NETDATA_KEY_ERROR_VFS_FSYNC];
  894. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].nerr = res[NETDATA_KEY_ERROR_VFS_OPEN];
  895. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].nerr = res[NETDATA_KEY_ERROR_VFS_CREATE];
  896. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITE] +
  897. (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITEV];
  898. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_READ] +
  899. (uint64_t)res[NETDATA_KEY_BYTES_VFS_READV];
  900. }
  901. /**
  902. * Sum PIDs
  903. *
  904. * Sum values for all targets.
  905. *
  906. * @param swap output structure
  907. * @param root link list with structure to be used
  908. */
  909. static void ebpf_vfs_sum_pids(netdata_publish_vfs_t *vfs, struct ebpf_pid_on_target *root)
  910. {
  911. netdata_publish_vfs_t accumulator;
  912. memset(&accumulator, 0, sizeof(accumulator));
  913. while (root) {
  914. int32_t pid = root->pid;
  915. netdata_publish_vfs_t *w = vfs_pid[pid];
  916. if (w) {
  917. accumulator.write_call += w->write_call;
  918. accumulator.writev_call += w->writev_call;
  919. accumulator.read_call += w->read_call;
  920. accumulator.readv_call += w->readv_call;
  921. accumulator.unlink_call += w->unlink_call;
  922. accumulator.fsync_call += w->fsync_call;
  923. accumulator.open_call += w->open_call;
  924. accumulator.create_call += w->create_call;
  925. accumulator.write_bytes += w->write_bytes;
  926. accumulator.writev_bytes += w->writev_bytes;
  927. accumulator.read_bytes += w->read_bytes;
  928. accumulator.readv_bytes += w->readv_bytes;
  929. accumulator.write_err += w->write_err;
  930. accumulator.writev_err += w->writev_err;
  931. accumulator.read_err += w->read_err;
  932. accumulator.readv_err += w->readv_err;
  933. accumulator.unlink_err += w->unlink_err;
  934. accumulator.fsync_err += w->fsync_err;
  935. accumulator.open_err += w->open_err;
  936. accumulator.create_err += w->create_err;
  937. }
  938. root = root->next;
  939. }
  940. // These conditions were added, because we are using incremental algorithm
  941. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  942. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  943. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  944. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  945. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  946. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  947. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  948. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  949. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  950. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  951. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  952. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  953. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  954. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  955. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  956. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  957. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  958. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  959. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  960. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  961. }
  962. /**
  963. * Send data to Netdata calling auxiliary functions.
  964. *
  965. * @param em the structure with thread information
  966. * @param root the target list.
  967. */
  968. void ebpf_vfs_send_apps_data(ebpf_module_t *em, struct ebpf_target *root)
  969. {
  970. struct ebpf_target *w;
  971. for (w = root; w; w = w->next) {
  972. if (unlikely(!(w->charts_created & (1<<EBPF_MODULE_VFS_IDX))))
  973. continue;
  974. ebpf_vfs_sum_pids(&w->vfs, w->root_pid);
  975. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_unlink");
  976. write_chart_dimension("calls", w->vfs.unlink_call);
  977. ebpf_write_end_chart();
  978. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_write");
  979. write_chart_dimension("calls", w->vfs.write_call + w->vfs.writev_call);
  980. ebpf_write_end_chart();
  981. if (em->mode < MODE_ENTRY) {
  982. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_write_error");
  983. write_chart_dimension("calls", w->vfs.write_err + w->vfs.writev_err);
  984. ebpf_write_end_chart();
  985. }
  986. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_read");
  987. write_chart_dimension("calls", w->vfs.read_call + w->vfs.readv_call);
  988. ebpf_write_end_chart();
  989. if (em->mode < MODE_ENTRY) {
  990. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_read_error");
  991. write_chart_dimension("calls", w->vfs.read_err + w->vfs.readv_err);
  992. ebpf_write_end_chart();
  993. }
  994. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_write_bytes");
  995. write_chart_dimension("writes", w->vfs.write_bytes + w->vfs.writev_bytes);
  996. ebpf_write_end_chart();
  997. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_read_bytes");
  998. write_chart_dimension("reads", w->vfs.read_bytes + w->vfs.readv_bytes);
  999. ebpf_write_end_chart();
  1000. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_fsync");
  1001. write_chart_dimension("calls", w->vfs.fsync_call);
  1002. ebpf_write_end_chart();
  1003. if (em->mode < MODE_ENTRY) {
  1004. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_fsync_error");
  1005. write_chart_dimension("calls", w->vfs.fsync_err);
  1006. ebpf_write_end_chart();
  1007. }
  1008. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_open");
  1009. write_chart_dimension("calls", w->vfs.open_call);
  1010. ebpf_write_end_chart();
  1011. if (em->mode < MODE_ENTRY) {
  1012. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_open_error");
  1013. write_chart_dimension("calls", w->vfs.open_err);
  1014. ebpf_write_end_chart();
  1015. }
  1016. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_create");
  1017. write_chart_dimension("calls", w->vfs.create_call);
  1018. ebpf_write_end_chart();
  1019. if (em->mode < MODE_ENTRY) {
  1020. ebpf_write_begin_chart(NETDATA_APP_FAMILY, w->clean_name, "_ebpf_call_vfs_create_error");
  1021. write_chart_dimension("calls", w->vfs.create_err);
  1022. ebpf_write_end_chart();
  1023. }
  1024. }
  1025. }
  1026. /**
  1027. * Apps Accumulator
  1028. *
  1029. * Sum all values read from kernel and store in the first address.
  1030. *
  1031. * @param out the vector with read values.
  1032. */
  1033. static void vfs_apps_accumulator(netdata_publish_vfs_t *out, int maps_per_core)
  1034. {
  1035. int i, end = (maps_per_core) ? ebpf_nprocs : 1;
  1036. netdata_publish_vfs_t *total = &out[0];
  1037. for (i = 1; i < end; i++) {
  1038. netdata_publish_vfs_t *w = &out[i];
  1039. total->write_call += w->write_call;
  1040. total->writev_call += w->writev_call;
  1041. total->read_call += w->read_call;
  1042. total->readv_call += w->readv_call;
  1043. total->unlink_call += w->unlink_call;
  1044. total->write_bytes += w->write_bytes;
  1045. total->writev_bytes += w->writev_bytes;
  1046. total->read_bytes += w->read_bytes;
  1047. total->readv_bytes += w->readv_bytes;
  1048. total->write_err += w->write_err;
  1049. total->writev_err += w->writev_err;
  1050. total->read_err += w->read_err;
  1051. total->readv_err += w->readv_err;
  1052. total->unlink_err += w->unlink_err;
  1053. }
  1054. }
  1055. /**
  1056. * Fill PID
  1057. *
  1058. * Fill PID structures
  1059. *
  1060. * @param current_pid pid that we are collecting data
  1061. * @param out values read from hash tables;
  1062. */
  1063. static void vfs_fill_pid(uint32_t current_pid, netdata_publish_vfs_t *publish)
  1064. {
  1065. netdata_publish_vfs_t *curr = vfs_pid[current_pid];
  1066. if (!curr) {
  1067. curr = ebpf_vfs_get();
  1068. vfs_pid[current_pid] = curr;
  1069. }
  1070. memcpy(curr, &publish[0], sizeof(netdata_publish_vfs_t));
  1071. }
  1072. /**
  1073. * Read the hash table and store data to allocated vectors.
  1074. */
  1075. static void ebpf_vfs_read_apps(int maps_per_core)
  1076. {
  1077. struct ebpf_pid_stat *pids = ebpf_root_of_pids;
  1078. netdata_publish_vfs_t *vv = vfs_vector;
  1079. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  1080. size_t length = sizeof(netdata_publish_vfs_t);
  1081. if (maps_per_core)
  1082. length *= ebpf_nprocs;
  1083. while (pids) {
  1084. uint32_t key = pids->pid;
  1085. if (bpf_map_lookup_elem(fd, &key, vv)) {
  1086. pids = pids->next;
  1087. continue;
  1088. }
  1089. vfs_apps_accumulator(vv, maps_per_core);
  1090. vfs_fill_pid(key, vv);
  1091. // We are cleaning to avoid passing data read from one process to other.
  1092. memset(vv, 0, length);
  1093. pids = pids->next;
  1094. }
  1095. }
  1096. /**
  1097. * Update cgroup
  1098. *
  1099. * Update cgroup data based in PID.
  1100. *
  1101. * @param maps_per_core do I need to read all cores?
  1102. */
  1103. static void read_update_vfs_cgroup(int maps_per_core)
  1104. {
  1105. ebpf_cgroup_target_t *ect ;
  1106. netdata_publish_vfs_t *vv = vfs_vector;
  1107. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  1108. size_t length = sizeof(netdata_publish_vfs_t);
  1109. if (maps_per_core)
  1110. length *= ebpf_nprocs;
  1111. pthread_mutex_lock(&mutex_cgroup_shm);
  1112. for (ect = ebpf_cgroup_pids; ect; ect = ect->next) {
  1113. struct pid_on_target2 *pids;
  1114. for (pids = ect->pids; pids; pids = pids->next) {
  1115. int pid = pids->pid;
  1116. netdata_publish_vfs_t *out = &pids->vfs;
  1117. if (likely(vfs_pid) && vfs_pid[pid]) {
  1118. netdata_publish_vfs_t *in = vfs_pid[pid];
  1119. memcpy(out, in, sizeof(netdata_publish_vfs_t));
  1120. } else {
  1121. memset(vv, 0, length);
  1122. if (!bpf_map_lookup_elem(fd, &pid, vv)) {
  1123. vfs_apps_accumulator(vv, maps_per_core);
  1124. memcpy(out, vv, sizeof(netdata_publish_vfs_t));
  1125. }
  1126. }
  1127. }
  1128. }
  1129. pthread_mutex_unlock(&mutex_cgroup_shm);
  1130. }
  1131. /**
  1132. * Sum PIDs
  1133. *
  1134. * Sum values for all targets.
  1135. *
  1136. * @param vfs structure used to store data
  1137. * @param pids input data
  1138. */
  1139. static void ebpf_vfs_sum_cgroup_pids(netdata_publish_vfs_t *vfs, struct pid_on_target2 *pids)
  1140. {
  1141. netdata_publish_vfs_t accumulator;
  1142. memset(&accumulator, 0, sizeof(accumulator));
  1143. while (pids) {
  1144. netdata_publish_vfs_t *w = &pids->vfs;
  1145. accumulator.write_call += w->write_call;
  1146. accumulator.writev_call += w->writev_call;
  1147. accumulator.read_call += w->read_call;
  1148. accumulator.readv_call += w->readv_call;
  1149. accumulator.unlink_call += w->unlink_call;
  1150. accumulator.fsync_call += w->fsync_call;
  1151. accumulator.open_call += w->open_call;
  1152. accumulator.create_call += w->create_call;
  1153. accumulator.write_bytes += w->write_bytes;
  1154. accumulator.writev_bytes += w->writev_bytes;
  1155. accumulator.read_bytes += w->read_bytes;
  1156. accumulator.readv_bytes += w->readv_bytes;
  1157. accumulator.write_err += w->write_err;
  1158. accumulator.writev_err += w->writev_err;
  1159. accumulator.read_err += w->read_err;
  1160. accumulator.readv_err += w->readv_err;
  1161. accumulator.unlink_err += w->unlink_err;
  1162. accumulator.fsync_err += w->fsync_err;
  1163. accumulator.open_err += w->open_err;
  1164. accumulator.create_err += w->create_err;
  1165. pids = pids->next;
  1166. }
  1167. // These conditions were added, because we are using incremental algorithm
  1168. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  1169. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  1170. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  1171. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  1172. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  1173. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  1174. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  1175. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  1176. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  1177. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  1178. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  1179. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  1180. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  1181. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  1182. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  1183. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  1184. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  1185. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  1186. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  1187. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  1188. }
  1189. /**
  1190. * Create specific VFS charts
  1191. *
  1192. * Create charts for cgroup/application.
  1193. *
  1194. * @param type the chart type.
  1195. * @param em the main thread structure.
  1196. */
  1197. static void ebpf_create_specific_vfs_charts(char *type, ebpf_module_t *em)
  1198. {
  1199. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED,"Files deleted",
  1200. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  1201. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500,
  1202. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  1203. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1204. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  1205. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  1206. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501,
  1207. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1208. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1209. if (em->mode < MODE_ENTRY) {
  1210. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  1211. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  1212. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502,
  1213. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1214. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1215. }
  1216. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  1217. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_CONTEXT,
  1218. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503,
  1219. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1220. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1221. if (em->mode < MODE_ENTRY) {
  1222. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  1223. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  1224. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504,
  1225. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1226. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1227. }
  1228. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  1229. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  1230. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505,
  1231. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1232. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1233. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  1234. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  1235. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506,
  1236. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1237. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1238. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls to vfs_fsync.",
  1239. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  1240. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507,
  1241. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1242. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1243. if (em->mode < MODE_ENTRY) {
  1244. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  1245. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  1246. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508,
  1247. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1248. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1249. }
  1250. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls to vfs_open.",
  1251. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  1252. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509,
  1253. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1254. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1255. if (em->mode < MODE_ENTRY) {
  1256. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  1257. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  1258. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510,
  1259. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1260. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1261. }
  1262. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls to vfs_create.",
  1263. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  1264. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511,
  1265. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1266. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1267. if (em->mode < MODE_ENTRY) {
  1268. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  1269. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  1270. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512,
  1271. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1272. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1273. }
  1274. }
  1275. /**
  1276. * Obsolete specific VFS charts
  1277. *
  1278. * Obsolete charts for cgroup/application.
  1279. *
  1280. * @param type the chart type.
  1281. * @param em the main thread structure.
  1282. */
  1283. static void ebpf_obsolete_specific_vfs_charts(char *type, ebpf_module_t *em)
  1284. {
  1285. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_FILE_DELETED, "", "Files deleted",
  1286. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1287. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  1288. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500, em->update_every);
  1289. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "", "Write to disk",
  1290. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1291. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  1292. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501, em->update_every);
  1293. if (em->mode < MODE_ENTRY) {
  1294. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "", "Fails to write",
  1295. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1296. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  1297. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502, em->update_every);
  1298. }
  1299. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "", "Read from disk",
  1300. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1301. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_CONTEXT,
  1302. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503, em->update_every);
  1303. if (em->mode < MODE_ENTRY) {
  1304. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "", "Fails to read",
  1305. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1306. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  1307. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504, em->update_every);
  1308. }
  1309. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "", "Bytes written on disk",
  1310. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  1311. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  1312. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505, em->update_every);
  1313. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "", "Bytes read from disk",
  1314. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  1315. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  1316. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506, em->update_every);
  1317. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "", "Calls to vfs_fsync.",
  1318. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1319. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  1320. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507, em->update_every);
  1321. if (em->mode < MODE_ENTRY) {
  1322. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "", "Sync error",
  1323. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1324. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  1325. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508, em->update_every);
  1326. }
  1327. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "", "Calls to vfs_open.",
  1328. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1329. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  1330. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509, em->update_every);
  1331. if (em->mode < MODE_ENTRY) {
  1332. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "", "Open error",
  1333. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1334. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  1335. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510, em->update_every);
  1336. }
  1337. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "", "Calls to vfs_create.",
  1338. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1339. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  1340. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511, em->update_every);
  1341. if (em->mode < MODE_ENTRY) {
  1342. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "", "Create error",
  1343. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  1344. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  1345. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512, em->update_every);
  1346. }
  1347. }
  1348. /*
  1349. * Send specific VFS data
  1350. *
  1351. * Send data for specific cgroup/apps.
  1352. *
  1353. * @param type chart type
  1354. * @param values structure with values that will be sent to netdata
  1355. */
  1356. static void ebpf_send_specific_vfs_data(char *type, netdata_publish_vfs_t *values, ebpf_module_t *em)
  1357. {
  1358. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED, "");
  1359. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].name, (long long)values->unlink_call);
  1360. ebpf_write_end_chart();
  1361. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "");
  1362. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  1363. (long long)values->write_call + (long long)values->writev_call);
  1364. ebpf_write_end_chart();
  1365. if (em->mode < MODE_ENTRY) {
  1366. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "");
  1367. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  1368. (long long)values->write_err + (long long)values->writev_err);
  1369. ebpf_write_end_chart();
  1370. }
  1371. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "");
  1372. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  1373. (long long)values->read_call + (long long)values->readv_call);
  1374. ebpf_write_end_chart();
  1375. if (em->mode < MODE_ENTRY) {
  1376. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "");
  1377. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  1378. (long long)values->read_err + (long long)values->readv_err);
  1379. ebpf_write_end_chart();
  1380. }
  1381. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "");
  1382. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  1383. (long long)values->write_bytes + (long long)values->writev_bytes);
  1384. ebpf_write_end_chart();
  1385. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "");
  1386. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  1387. (long long)values->read_bytes + (long long)values->readv_bytes);
  1388. ebpf_write_end_chart();
  1389. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "");
  1390. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  1391. (long long)values->fsync_call);
  1392. ebpf_write_end_chart();
  1393. if (em->mode < MODE_ENTRY) {
  1394. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "");
  1395. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  1396. (long long)values->fsync_err);
  1397. ebpf_write_end_chart();
  1398. }
  1399. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "");
  1400. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  1401. (long long)values->open_call);
  1402. ebpf_write_end_chart();
  1403. if (em->mode < MODE_ENTRY) {
  1404. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "");
  1405. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  1406. (long long)values->open_err);
  1407. ebpf_write_end_chart();
  1408. }
  1409. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "");
  1410. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  1411. (long long)values->create_call);
  1412. ebpf_write_end_chart();
  1413. if (em->mode < MODE_ENTRY) {
  1414. ebpf_write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "");
  1415. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  1416. (long long)values->create_err);
  1417. ebpf_write_end_chart();
  1418. }
  1419. }
  1420. /**
  1421. * Create Systemd Socket Charts
  1422. *
  1423. * Create charts when systemd is enabled
  1424. *
  1425. * @param em the main collector structure
  1426. **/
  1427. static void ebpf_create_systemd_vfs_charts(ebpf_module_t *em)
  1428. {
  1429. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_FILE_DELETED, "Files deleted",
  1430. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1431. NETDATA_EBPF_CHART_TYPE_STACKED, 20065,
  1432. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_UNLINK_CONTEXT,
  1433. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1434. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  1435. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1436. NETDATA_EBPF_CHART_TYPE_STACKED, 20066,
  1437. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_CONTEXT,
  1438. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1439. if (em->mode < MODE_ENTRY) {
  1440. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  1441. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1442. NETDATA_EBPF_CHART_TYPE_STACKED, 20067,
  1443. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1444. NETDATA_SYSTEMD_VFS_WRITE_ERROR_CONTEXT,
  1445. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1446. }
  1447. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  1448. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1449. NETDATA_EBPF_CHART_TYPE_STACKED, 20068,
  1450. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_CONTEXT,
  1451. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1452. if (em->mode < MODE_ENTRY) {
  1453. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  1454. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1455. NETDATA_EBPF_CHART_TYPE_STACKED, 20069,
  1456. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1457. NETDATA_SYSTEMD_VFS_READ_ERROR_CONTEXT,
  1458. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1459. }
  1460. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  1461. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  1462. NETDATA_EBPF_CHART_TYPE_STACKED, 20070,
  1463. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_BYTES_CONTEXT,
  1464. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1465. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  1466. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  1467. NETDATA_EBPF_CHART_TYPE_STACKED, 20071,
  1468. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_BYTES_CONTEXT,
  1469. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1470. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls to vfs_fsync.",
  1471. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1472. NETDATA_EBPF_CHART_TYPE_STACKED, 20072,
  1473. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_CONTEXT,
  1474. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1475. if (em->mode < MODE_ENTRY) {
  1476. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  1477. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1478. NETDATA_EBPF_CHART_TYPE_STACKED, 20073,
  1479. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_ERROR_CONTEXT,
  1480. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1481. }
  1482. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls to vfs_open.",
  1483. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1484. NETDATA_EBPF_CHART_TYPE_STACKED, 20074,
  1485. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_CONTEXT,
  1486. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1487. if (em->mode < MODE_ENTRY) {
  1488. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  1489. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1490. NETDATA_EBPF_CHART_TYPE_STACKED, 20075,
  1491. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_ERROR_CONTEXT,
  1492. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1493. }
  1494. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls to vfs_create.",
  1495. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1496. NETDATA_EBPF_CHART_TYPE_STACKED, 20076,
  1497. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_CONTEXT,
  1498. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1499. if (em->mode < MODE_ENTRY) {
  1500. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  1501. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  1502. NETDATA_EBPF_CHART_TYPE_STACKED, 20077,
  1503. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_ERROR_CONTEXT,
  1504. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  1505. }
  1506. }
  1507. /**
  1508. * Send Systemd charts
  1509. *
  1510. * Send collected data to Netdata.
  1511. *
  1512. * @param em the main collector structure
  1513. */
  1514. static void ebpf_send_systemd_vfs_charts(ebpf_module_t *em)
  1515. {
  1516. ebpf_cgroup_target_t *ect;
  1517. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED, "");
  1518. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1519. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1520. write_chart_dimension(ect->name, ect->publish_systemd_vfs.unlink_call);
  1521. }
  1522. }
  1523. ebpf_write_end_chart();
  1524. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "");
  1525. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1526. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1527. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_call +
  1528. ect->publish_systemd_vfs.writev_call);
  1529. }
  1530. }
  1531. ebpf_write_end_chart();
  1532. if (em->mode < MODE_ENTRY) {
  1533. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "");
  1534. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1535. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1536. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_err +
  1537. ect->publish_systemd_vfs.writev_err);
  1538. }
  1539. }
  1540. ebpf_write_end_chart();
  1541. }
  1542. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "");
  1543. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1544. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1545. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_call +
  1546. ect->publish_systemd_vfs.readv_call);
  1547. }
  1548. }
  1549. ebpf_write_end_chart();
  1550. if (em->mode < MODE_ENTRY) {
  1551. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "");
  1552. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1553. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1554. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_err +
  1555. ect->publish_systemd_vfs.readv_err);
  1556. }
  1557. }
  1558. ebpf_write_end_chart();
  1559. }
  1560. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "");
  1561. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1562. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1563. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_bytes +
  1564. ect->publish_systemd_vfs.writev_bytes);
  1565. }
  1566. }
  1567. ebpf_write_end_chart();
  1568. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "");
  1569. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1570. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1571. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_bytes +
  1572. ect->publish_systemd_vfs.readv_bytes);
  1573. }
  1574. }
  1575. ebpf_write_end_chart();
  1576. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC, "");
  1577. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1578. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1579. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_call);
  1580. }
  1581. }
  1582. ebpf_write_end_chart();
  1583. if (em->mode < MODE_ENTRY) {
  1584. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "");
  1585. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1586. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1587. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_err);
  1588. }
  1589. }
  1590. ebpf_write_end_chart();
  1591. }
  1592. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN, "");
  1593. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1594. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1595. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_call);
  1596. }
  1597. }
  1598. ebpf_write_end_chart();
  1599. if (em->mode < MODE_ENTRY) {
  1600. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "");
  1601. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1602. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1603. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_err);
  1604. }
  1605. }
  1606. ebpf_write_end_chart();
  1607. }
  1608. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE, "");
  1609. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1610. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1611. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_call);
  1612. }
  1613. }
  1614. ebpf_write_end_chart();
  1615. if (em->mode < MODE_ENTRY) {
  1616. ebpf_write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "");
  1617. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1618. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  1619. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_err);
  1620. }
  1621. }
  1622. ebpf_write_end_chart();
  1623. }
  1624. }
  1625. /**
  1626. * Send data to Netdata calling auxiliary functions.
  1627. *
  1628. * @param em the main collector structure
  1629. */
  1630. static void ebpf_vfs_send_cgroup_data(ebpf_module_t *em)
  1631. {
  1632. if (!ebpf_cgroup_pids)
  1633. return;
  1634. pthread_mutex_lock(&mutex_cgroup_shm);
  1635. ebpf_cgroup_target_t *ect;
  1636. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1637. ebpf_vfs_sum_cgroup_pids(&ect->publish_systemd_vfs, ect->pids);
  1638. }
  1639. int has_systemd = shm_ebpf_cgroup.header->systemd_enabled;
  1640. if (has_systemd) {
  1641. if (send_cgroup_chart) {
  1642. ebpf_create_systemd_vfs_charts(em);
  1643. }
  1644. ebpf_send_systemd_vfs_charts(em);
  1645. }
  1646. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  1647. if (ect->systemd)
  1648. continue;
  1649. if (!(ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) && ect->updated) {
  1650. ebpf_create_specific_vfs_charts(ect->name, em);
  1651. ect->flags |= NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  1652. }
  1653. if (ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) {
  1654. if (ect->updated) {
  1655. ebpf_send_specific_vfs_data(ect->name, &ect->publish_systemd_vfs, em);
  1656. } else {
  1657. ebpf_obsolete_specific_vfs_charts(ect->name, em);
  1658. ect->flags &= ~NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  1659. }
  1660. }
  1661. }
  1662. pthread_mutex_unlock(&mutex_cgroup_shm);
  1663. }
  1664. /**
  1665. * Main loop for this collector.
  1666. *
  1667. * @param step the number of microseconds used with heart beat
  1668. * @param em the structure with thread information
  1669. */
  1670. static void vfs_collector(ebpf_module_t *em)
  1671. {
  1672. int cgroups = em->cgroup_charts;
  1673. heartbeat_t hb;
  1674. heartbeat_init(&hb);
  1675. int update_every = em->update_every;
  1676. int counter = update_every - 1;
  1677. int maps_per_core = em->maps_per_core;
  1678. uint32_t running_time = 0;
  1679. uint32_t lifetime = em->lifetime;
  1680. netdata_idx_t *stats = em->hash_table_stats;
  1681. memset(stats, 0, sizeof(em->hash_table_stats));
  1682. while (!ebpf_plugin_exit && running_time < lifetime) {
  1683. (void)heartbeat_next(&hb, USEC_PER_SEC);
  1684. if (ebpf_plugin_exit || ++counter != update_every)
  1685. continue;
  1686. counter = 0;
  1687. netdata_apps_integration_flags_t apps = em->apps_charts;
  1688. ebpf_vfs_read_global_table(stats, maps_per_core);
  1689. pthread_mutex_lock(&collect_data_mutex);
  1690. if (apps)
  1691. ebpf_vfs_read_apps(maps_per_core);
  1692. if (cgroups)
  1693. read_update_vfs_cgroup(maps_per_core);
  1694. pthread_mutex_lock(&lock);
  1695. #ifdef NETDATA_DEV_MODE
  1696. if (ebpf_aral_vfs_pid)
  1697. ebpf_send_data_aral_chart(ebpf_aral_vfs_pid, em);
  1698. #endif
  1699. ebpf_vfs_send_data(em);
  1700. fflush(stdout);
  1701. if (apps & NETDATA_EBPF_APPS_FLAG_CHART_CREATED)
  1702. ebpf_vfs_send_apps_data(em, apps_groups_root_target);
  1703. if (cgroups)
  1704. ebpf_vfs_send_cgroup_data(em);
  1705. pthread_mutex_unlock(&lock);
  1706. pthread_mutex_unlock(&collect_data_mutex);
  1707. pthread_mutex_lock(&ebpf_exit_cleanup);
  1708. if (running_time && !em->running_time)
  1709. running_time = update_every;
  1710. else
  1711. running_time += update_every;
  1712. em->running_time = running_time;
  1713. pthread_mutex_unlock(&ebpf_exit_cleanup);
  1714. }
  1715. }
  1716. /*****************************************************************
  1717. *
  1718. * FUNCTIONS TO CREATE CHARTS
  1719. *
  1720. *****************************************************************/
  1721. /**
  1722. * Create IO chart
  1723. *
  1724. * @param family the chart family
  1725. * @param name the chart name
  1726. * @param axis the axis label
  1727. * @param web the group name used to attach the chart on dashboard
  1728. * @param order the order number of the specified chart
  1729. * @param algorithm the algorithm used to make the charts.
  1730. * @param update_every value to overwrite the update frequency set by the server.
  1731. */
  1732. static void ebpf_create_io_chart(char *family, char *name, char *axis, char *web,
  1733. int order, int algorithm, int update_every)
  1734. {
  1735. printf("CHART %s.%s '' 'Bytes written and read' '%s' '%s' '' line %d %d '' 'ebpf.plugin' 'filesystem'\n",
  1736. family,
  1737. name,
  1738. axis,
  1739. web,
  1740. order,
  1741. update_every);
  1742. printf("DIMENSION %s %s %s 1 1\n",
  1743. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1744. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1745. ebpf_algorithms[algorithm]);
  1746. printf("DIMENSION %s %s %s -1 1\n",
  1747. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1748. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1749. ebpf_algorithms[algorithm]);
  1750. }
  1751. /**
  1752. * Create global charts
  1753. *
  1754. * Call ebpf_create_chart to create the charts for the collector.
  1755. *
  1756. * @param em a pointer to the structure with the default values.
  1757. */
  1758. static void ebpf_create_global_charts(ebpf_module_t *em)
  1759. {
  1760. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1761. NETDATA_VFS_FILE_CLEAN_COUNT,
  1762. "Remove files",
  1763. EBPF_COMMON_DIMENSION_CALL,
  1764. NETDATA_VFS_GROUP,
  1765. NULL,
  1766. NETDATA_EBPF_CHART_TYPE_LINE,
  1767. NETDATA_CHART_PRIO_FILESYSTEM_VFS_CLEAN,
  1768. ebpf_create_global_dimension,
  1769. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  1770. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1771. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1772. NETDATA_VFS_FILE_IO_COUNT,
  1773. "Calls to IO",
  1774. EBPF_COMMON_DIMENSION_CALL,
  1775. NETDATA_VFS_GROUP,
  1776. NULL,
  1777. NETDATA_EBPF_CHART_TYPE_LINE,
  1778. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_COUNT,
  1779. ebpf_create_global_dimension,
  1780. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1781. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1782. ebpf_create_io_chart(NETDATA_FILESYSTEM_FAMILY,
  1783. NETDATA_VFS_IO_FILE_BYTES, EBPF_COMMON_DIMENSION_BYTES,
  1784. NETDATA_VFS_GROUP,
  1785. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_BYTES,
  1786. NETDATA_EBPF_INCREMENTAL_IDX, em->update_every);
  1787. if (em->mode < MODE_ENTRY) {
  1788. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1789. NETDATA_VFS_FILE_ERR_COUNT,
  1790. "Fails to write or read",
  1791. EBPF_COMMON_DIMENSION_CALL,
  1792. NETDATA_VFS_GROUP,
  1793. NULL,
  1794. NETDATA_EBPF_CHART_TYPE_LINE,
  1795. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EBYTES,
  1796. ebpf_create_global_dimension,
  1797. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1798. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1799. }
  1800. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1801. NETDATA_VFS_FSYNC,
  1802. "Calls to vfs_fsync.",
  1803. EBPF_COMMON_DIMENSION_CALL,
  1804. NETDATA_VFS_GROUP,
  1805. NULL,
  1806. NETDATA_EBPF_CHART_TYPE_LINE,
  1807. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_FSYNC,
  1808. ebpf_create_global_dimension,
  1809. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1810. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1811. if (em->mode < MODE_ENTRY) {
  1812. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1813. NETDATA_VFS_FSYNC_ERR,
  1814. "Fails to synchronize",
  1815. EBPF_COMMON_DIMENSION_CALL,
  1816. NETDATA_VFS_GROUP,
  1817. NULL,
  1818. NETDATA_EBPF_CHART_TYPE_LINE,
  1819. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EFSYNC,
  1820. ebpf_create_global_dimension,
  1821. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1822. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1823. }
  1824. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1825. NETDATA_VFS_OPEN,
  1826. "Calls to vfs_open.",
  1827. EBPF_COMMON_DIMENSION_CALL,
  1828. NETDATA_VFS_GROUP,
  1829. NULL,
  1830. NETDATA_EBPF_CHART_TYPE_LINE,
  1831. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_OPEN,
  1832. ebpf_create_global_dimension,
  1833. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1834. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1835. if (em->mode < MODE_ENTRY) {
  1836. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1837. NETDATA_VFS_OPEN_ERR,
  1838. "Fails to open a file",
  1839. EBPF_COMMON_DIMENSION_CALL,
  1840. NETDATA_VFS_GROUP,
  1841. NULL,
  1842. NETDATA_EBPF_CHART_TYPE_LINE,
  1843. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EOPEN,
  1844. ebpf_create_global_dimension,
  1845. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1846. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1847. }
  1848. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1849. NETDATA_VFS_CREATE,
  1850. "Calls to vfs_create.",
  1851. EBPF_COMMON_DIMENSION_CALL,
  1852. NETDATA_VFS_GROUP,
  1853. NULL,
  1854. NETDATA_EBPF_CHART_TYPE_LINE,
  1855. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_CREATE,
  1856. ebpf_create_global_dimension,
  1857. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1858. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1859. if (em->mode < MODE_ENTRY) {
  1860. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1861. NETDATA_VFS_CREATE_ERR,
  1862. "Fails to create a file.",
  1863. EBPF_COMMON_DIMENSION_CALL,
  1864. NETDATA_VFS_GROUP,
  1865. NULL,
  1866. NETDATA_EBPF_CHART_TYPE_LINE,
  1867. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_ECREATE,
  1868. ebpf_create_global_dimension,
  1869. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1870. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1871. }
  1872. fflush(stdout);
  1873. }
  1874. /**
  1875. * Create process apps charts
  1876. *
  1877. * Call ebpf_create_chart to create the charts on apps submenu.
  1878. *
  1879. * @param em a pointer to the structure with the default values.
  1880. * @param ptr a pointer for the targets.
  1881. **/
  1882. void ebpf_vfs_create_apps_charts(struct ebpf_module *em, void *ptr)
  1883. {
  1884. struct ebpf_target *root = ptr;
  1885. struct ebpf_target *w;
  1886. int order = 20275;
  1887. int update_every = em->update_every;
  1888. for (w = root; w; w = w->next) {
  1889. if (unlikely(!w->exposed))
  1890. continue;
  1891. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1892. w->clean_name,
  1893. "_ebpf_call_vfs_unlink",
  1894. "Files deleted.",
  1895. EBPF_COMMON_DIMENSION_CALL,
  1896. NETDATA_VFS_GROUP,
  1897. NETDATA_EBPF_CHART_TYPE_STACKED,
  1898. "app.ebpf_call_vfs_unlink",
  1899. order++,
  1900. update_every,
  1901. NETDATA_EBPF_MODULE_NAME_VFS);
  1902. ebpf_create_chart_labels("app_group", w->name, 0);
  1903. ebpf_commit_label();
  1904. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1905. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1906. w->clean_name,
  1907. "_ebpf_call_vfs_write",
  1908. "Write to disk.",
  1909. EBPF_COMMON_DIMENSION_CALL,
  1910. NETDATA_VFS_GROUP,
  1911. NETDATA_EBPF_CHART_TYPE_STACKED,
  1912. "app.ebpf_call_vfs_write",
  1913. order++,
  1914. update_every,
  1915. NETDATA_EBPF_MODULE_NAME_VFS);
  1916. ebpf_create_chart_labels("app_group", w->name, 0);
  1917. ebpf_commit_label();
  1918. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1919. if (em->mode < MODE_ENTRY) {
  1920. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1921. w->clean_name,
  1922. "_ebpf_call_vfs_write_error",
  1923. "Fails to write.",
  1924. EBPF_COMMON_DIMENSION_CALL,
  1925. NETDATA_VFS_GROUP,
  1926. NETDATA_EBPF_CHART_TYPE_STACKED,
  1927. "app.ebpf_call_vfs_write_error",
  1928. order++,
  1929. update_every,
  1930. NETDATA_EBPF_MODULE_NAME_VFS);
  1931. ebpf_create_chart_labels("app_group", w->name, 0);
  1932. ebpf_commit_label();
  1933. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1934. }
  1935. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1936. w->clean_name,
  1937. "_ebpf_call_vfs_read",
  1938. "Read from disk.",
  1939. EBPF_COMMON_DIMENSION_CALL,
  1940. NETDATA_VFS_GROUP,
  1941. NETDATA_EBPF_CHART_TYPE_STACKED,
  1942. "app.ebpf_call_vfs_read",
  1943. order++,
  1944. update_every,
  1945. NETDATA_EBPF_MODULE_NAME_VFS);
  1946. ebpf_create_chart_labels("app_group", w->name, 0);
  1947. ebpf_commit_label();
  1948. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1949. if (em->mode < MODE_ENTRY) {
  1950. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1951. w->clean_name,
  1952. "_ebpf_call_vfs_read_error",
  1953. "Fails to read.",
  1954. EBPF_COMMON_DIMENSION_CALL,
  1955. NETDATA_VFS_GROUP,
  1956. NETDATA_EBPF_CHART_TYPE_STACKED,
  1957. "app.ebpf_call_vfs_read_error",
  1958. order++,
  1959. update_every,
  1960. NETDATA_EBPF_MODULE_NAME_VFS);
  1961. ebpf_create_chart_labels("app_group", w->name, 0);
  1962. ebpf_commit_label();
  1963. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1964. }
  1965. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1966. w->clean_name,
  1967. "_ebpf_call_vfs_write_bytes",
  1968. "Bytes written on disk.",
  1969. EBPF_COMMON_DIMENSION_BYTES,
  1970. NETDATA_VFS_GROUP,
  1971. NETDATA_EBPF_CHART_TYPE_STACKED,
  1972. "app.ebpf_call_vfs_write_bytes",
  1973. order++,
  1974. update_every,
  1975. NETDATA_EBPF_MODULE_NAME_VFS);
  1976. ebpf_create_chart_labels("app_group", w->name, 0);
  1977. ebpf_commit_label();
  1978. fprintf(stdout, "DIMENSION writes '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1979. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1980. w->clean_name,
  1981. "_ebpf_call_vfs_read_bytes",
  1982. "Bytes read from disk.",
  1983. EBPF_COMMON_DIMENSION_BYTES,
  1984. NETDATA_VFS_GROUP,
  1985. NETDATA_EBPF_CHART_TYPE_STACKED,
  1986. "app.ebpf_call_vfs_read_bytes",
  1987. order++,
  1988. update_every,
  1989. NETDATA_EBPF_MODULE_NAME_VFS);
  1990. ebpf_create_chart_labels("app_group", w->name, 0);
  1991. ebpf_commit_label();
  1992. fprintf(stdout, "DIMENSION reads '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  1993. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  1994. w->clean_name,
  1995. "_ebpf_call_vfs_fsync",
  1996. "Calls to vfs_fsync.",
  1997. EBPF_COMMON_DIMENSION_CALL,
  1998. NETDATA_VFS_GROUP,
  1999. NETDATA_EBPF_CHART_TYPE_STACKED,
  2000. "app.ebpf_call_vfs_fsync",
  2001. order++,
  2002. update_every,
  2003. NETDATA_EBPF_MODULE_NAME_VFS);
  2004. ebpf_create_chart_labels("app_group", w->name, 0);
  2005. ebpf_commit_label();
  2006. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2007. if (em->mode < MODE_ENTRY) {
  2008. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  2009. w->clean_name,
  2010. "_ebpf_call_vfs_fsync_error",
  2011. "Fails to sync.",
  2012. EBPF_COMMON_DIMENSION_CALL,
  2013. NETDATA_VFS_GROUP,
  2014. NETDATA_EBPF_CHART_TYPE_STACKED,
  2015. "app.ebpf_call_vfs_fsync_error",
  2016. order++,
  2017. update_every,
  2018. NETDATA_EBPF_MODULE_NAME_VFS);
  2019. ebpf_create_chart_labels("app_group", w->name, 0);
  2020. ebpf_commit_label();
  2021. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2022. }
  2023. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  2024. w->clean_name,
  2025. "_ebpf_call_vfs_open",
  2026. "Calls to vfs_open.",
  2027. EBPF_COMMON_DIMENSION_CALL,
  2028. NETDATA_VFS_GROUP,
  2029. NETDATA_EBPF_CHART_TYPE_STACKED,
  2030. "app.ebpf_call_vfs_open",
  2031. order++,
  2032. update_every,
  2033. NETDATA_EBPF_MODULE_NAME_VFS);
  2034. ebpf_create_chart_labels("app_group", w->name, 0);
  2035. ebpf_commit_label();
  2036. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2037. if (em->mode < MODE_ENTRY) {
  2038. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  2039. w->clean_name,
  2040. "_ebpf_call_vfs_open_error",
  2041. "Fails to open.",
  2042. EBPF_COMMON_DIMENSION_CALL,
  2043. NETDATA_VFS_GROUP,
  2044. NETDATA_EBPF_CHART_TYPE_STACKED,
  2045. "app.ebpf_call_vfs_open_error",
  2046. order++,
  2047. update_every,
  2048. NETDATA_EBPF_MODULE_NAME_VFS);
  2049. ebpf_create_chart_labels("app_group", w->name, 0);
  2050. ebpf_commit_label();
  2051. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2052. }
  2053. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  2054. w->clean_name,
  2055. "_ebpf_call_vfs_create",
  2056. "Calls to vfs_create.",
  2057. EBPF_COMMON_DIMENSION_CALL,
  2058. NETDATA_VFS_GROUP,
  2059. NETDATA_EBPF_CHART_TYPE_STACKED,
  2060. "app.ebpf_call_vfs_create",
  2061. order++,
  2062. update_every,
  2063. NETDATA_EBPF_MODULE_NAME_VFS);
  2064. ebpf_create_chart_labels("app_group", w->name, 0);
  2065. ebpf_commit_label();
  2066. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2067. if (em->mode < MODE_ENTRY) {
  2068. ebpf_write_chart_cmd(NETDATA_APP_FAMILY,
  2069. w->clean_name,
  2070. "_ebpf_call_vfs_create_error",
  2071. "Fails to create a file.",
  2072. EBPF_COMMON_DIMENSION_CALL,
  2073. NETDATA_VFS_GROUP,
  2074. NETDATA_EBPF_CHART_TYPE_STACKED,
  2075. "app.ebpf_call_vfs_create_error",
  2076. order++,
  2077. update_every,
  2078. NETDATA_EBPF_MODULE_NAME_VFS);
  2079. ebpf_create_chart_labels("app_group", w->name, 0);
  2080. ebpf_commit_label();
  2081. fprintf(stdout, "DIMENSION calls '' %s 1 1\n", ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX]);
  2082. }
  2083. w->charts_created |= 1<<EBPF_MODULE_VFS_IDX;
  2084. }
  2085. em->apps_charts |= NETDATA_EBPF_APPS_FLAG_CHART_CREATED;
  2086. }
  2087. /*****************************************************************
  2088. *
  2089. * FUNCTIONS TO START THREAD
  2090. *
  2091. *****************************************************************/
  2092. /**
  2093. * Allocate vectors used with this thread.
  2094. * We are not testing the return, because callocz does this and shutdown the software
  2095. * case it was not possible to allocate.
  2096. *
  2097. * @param apps is apps enabled?
  2098. */
  2099. static void ebpf_vfs_allocate_global_vectors(int apps)
  2100. {
  2101. if (apps) {
  2102. ebpf_vfs_aral_init();
  2103. vfs_pid = callocz((size_t)pid_max, sizeof(netdata_publish_vfs_t *));
  2104. vfs_vector = callocz(ebpf_nprocs, sizeof(netdata_publish_vfs_t));
  2105. }
  2106. memset(vfs_aggregated_data, 0, sizeof(vfs_aggregated_data));
  2107. memset(vfs_publish_aggregated, 0, sizeof(vfs_publish_aggregated));
  2108. vfs_hash_values = callocz(ebpf_nprocs, sizeof(netdata_idx_t));
  2109. }
  2110. /*****************************************************************
  2111. *
  2112. * EBPF VFS THREAD
  2113. *
  2114. *****************************************************************/
  2115. /*
  2116. * Load BPF
  2117. *
  2118. * Load BPF files.
  2119. *
  2120. * @param em the structure with configuration
  2121. */
  2122. static int ebpf_vfs_load_bpf(ebpf_module_t *em)
  2123. {
  2124. #ifdef LIBBPF_MAJOR_VERSION
  2125. ebpf_define_map_type(em->maps, em->maps_per_core, running_on_kernel);
  2126. #endif
  2127. int ret = 0;
  2128. ebpf_adjust_apps_cgroup(em, em->targets[NETDATA_EBPF_VFS_WRITE].mode);
  2129. if (em->load & EBPF_LOAD_LEGACY) {
  2130. em->probe_links = ebpf_load_program(ebpf_plugin_dir, em, running_on_kernel, isrh, &em->objects);
  2131. if (!em->probe_links) {
  2132. ret = -1;
  2133. }
  2134. }
  2135. #ifdef LIBBPF_MAJOR_VERSION
  2136. else {
  2137. vfs_bpf_obj = vfs_bpf__open();
  2138. if (!vfs_bpf_obj)
  2139. ret = -1;
  2140. else
  2141. ret = ebpf_vfs_load_and_attach(vfs_bpf_obj, em);
  2142. }
  2143. #endif
  2144. return ret;
  2145. }
  2146. /**
  2147. * Process thread
  2148. *
  2149. * Thread used to generate process charts.
  2150. *
  2151. * @param ptr a pointer to `struct ebpf_module`
  2152. *
  2153. * @return It always return NULL
  2154. */
  2155. void *ebpf_vfs_thread(void *ptr)
  2156. {
  2157. netdata_thread_cleanup_push(ebpf_vfs_exit, ptr);
  2158. ebpf_module_t *em = (ebpf_module_t *)ptr;
  2159. em->maps = vfs_maps;
  2160. ebpf_update_pid_table(&vfs_maps[NETDATA_VFS_PID], em);
  2161. ebpf_vfs_allocate_global_vectors(em->apps_charts);
  2162. #ifdef LIBBPF_MAJOR_VERSION
  2163. ebpf_adjust_thread_load(em, default_btf);
  2164. #endif
  2165. if (ebpf_vfs_load_bpf(em)) {
  2166. goto endvfs;
  2167. }
  2168. int algorithms[NETDATA_KEY_PUBLISH_VFS_END] = {
  2169. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX,
  2170. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX
  2171. };
  2172. ebpf_global_labels(vfs_aggregated_data, vfs_publish_aggregated, vfs_dimension_names,
  2173. vfs_id_names, algorithms, NETDATA_KEY_PUBLISH_VFS_END);
  2174. pthread_mutex_lock(&lock);
  2175. ebpf_create_global_charts(em);
  2176. ebpf_update_stats(&plugin_statistics, em);
  2177. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_ADD);
  2178. #ifdef NETDATA_DEV_MODE
  2179. if (ebpf_aral_vfs_pid)
  2180. vfs_disable_priority = ebpf_statistic_create_aral_chart(NETDATA_EBPF_VFS_ARAL_NAME, em);
  2181. #endif
  2182. pthread_mutex_unlock(&lock);
  2183. vfs_collector(em);
  2184. endvfs:
  2185. ebpf_update_disabled_plugin_stats(em);
  2186. netdata_thread_cleanup_pop(1);
  2187. return NULL;
  2188. }