ebpf_vfs.c 70 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include <sys/resource.h>
  3. #include "ebpf.h"
  4. #include "ebpf_vfs.h"
  5. static char *vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_END] = { "delete", "read", "write",
  6. "fsync", "open", "create" };
  7. static char *vfs_id_names[NETDATA_KEY_PUBLISH_VFS_END] = { "vfs_unlink", "vfs_read", "vfs_write",
  8. "vfs_fsync", "vfs_open", "vfs_create"};
  9. static netdata_idx_t *vfs_hash_values = NULL;
  10. static netdata_syscall_stat_t vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_END];
  11. static netdata_publish_syscall_t vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_END];
  12. netdata_publish_vfs_t **vfs_pid = NULL;
  13. netdata_publish_vfs_t *vfs_vector = NULL;
  14. static ebpf_local_maps_t vfs_maps[] = {{.name = "tbl_vfs_pid", .internal_input = ND_EBPF_DEFAULT_PID_SIZE,
  15. .user_input = 0, .type = NETDATA_EBPF_MAP_RESIZABLE | NETDATA_EBPF_MAP_PID,
  16. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  17. {.name = "tbl_vfs_stats", .internal_input = NETDATA_VFS_COUNTER,
  18. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  19. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  20. {.name = "vfs_ctrl", .internal_input = NETDATA_CONTROLLER_END,
  21. .user_input = 0,
  22. .type = NETDATA_EBPF_MAP_CONTROLLER,
  23. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED},
  24. {.name = NULL, .internal_input = 0, .user_input = 0}};
  25. struct config vfs_config = { .first_section = NULL,
  26. .last_section = NULL,
  27. .mutex = NETDATA_MUTEX_INITIALIZER,
  28. .index = { .avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  29. .rwlock = AVL_LOCK_INITIALIZER } };
  30. static struct bpf_object *objects = NULL;
  31. static struct bpf_link **probe_links = NULL;
  32. struct netdata_static_thread vfs_threads = {"VFS KERNEL",
  33. NULL, NULL, 1, NULL,
  34. NULL, NULL};
  35. static int read_thread_closed = 1;
  36. /*****************************************************************
  37. *
  38. * FUNCTIONS TO CLOSE THE THREAD
  39. *
  40. *****************************************************************/
  41. /**
  42. * Clean PID structures
  43. *
  44. * Clean the allocated structures.
  45. */
  46. void clean_vfs_pid_structures() {
  47. struct pid_stat *pids = root_of_pids;
  48. while (pids) {
  49. freez(vfs_pid[pids->pid]);
  50. pids = pids->next;
  51. }
  52. }
  53. /**
  54. * Clean up the main thread.
  55. *
  56. * @param ptr thread data.
  57. **/
  58. static void ebpf_vfs_cleanup(void *ptr)
  59. {
  60. ebpf_module_t *em = (ebpf_module_t *)ptr;
  61. if (!em->enabled)
  62. return;
  63. heartbeat_t hb;
  64. heartbeat_init(&hb);
  65. uint32_t tick = 50 * USEC_PER_MS;
  66. while (!read_thread_closed) {
  67. usec_t dt = heartbeat_next(&hb, tick);
  68. UNUSED(dt);
  69. }
  70. freez(vfs_hash_values);
  71. freez(vfs_vector);
  72. if (probe_links) {
  73. struct bpf_program *prog;
  74. size_t i = 0 ;
  75. bpf_object__for_each_program(prog, objects) {
  76. bpf_link__destroy(probe_links[i]);
  77. i++;
  78. }
  79. bpf_object__close(objects);
  80. }
  81. }
  82. /*****************************************************************
  83. *
  84. * FUNCTIONS WITH THE MAIN LOOP
  85. *
  86. *****************************************************************/
  87. /**
  88. * Send data to Netdata calling auxiliary functions.
  89. *
  90. * @param em the structure with thread information
  91. */
  92. static void ebpf_vfs_send_data(ebpf_module_t *em)
  93. {
  94. netdata_publish_vfs_common_t pvc;
  95. pvc.write = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes;
  96. pvc.read = (long)vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes;
  97. write_count_chart(NETDATA_VFS_FILE_CLEAN_COUNT, NETDATA_FILESYSTEM_FAMILY,
  98. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK], 1);
  99. write_count_chart(NETDATA_VFS_FILE_IO_COUNT, NETDATA_FILESYSTEM_FAMILY,
  100. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  101. if (em->mode < MODE_ENTRY) {
  102. write_err_chart(NETDATA_VFS_FILE_ERR_COUNT, NETDATA_FILESYSTEM_FAMILY,
  103. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ], 2);
  104. }
  105. write_io_chart(NETDATA_VFS_IO_FILE_BYTES, NETDATA_FILESYSTEM_FAMILY, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  106. (long long)pvc.write, vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ], (long long)pvc.read);
  107. write_count_chart(NETDATA_VFS_FSYNC, NETDATA_FILESYSTEM_FAMILY,
  108. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  109. if (em->mode < MODE_ENTRY) {
  110. write_err_chart(NETDATA_VFS_FSYNC_ERR, NETDATA_FILESYSTEM_FAMILY,
  111. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC], 1);
  112. }
  113. write_count_chart(NETDATA_VFS_OPEN, NETDATA_FILESYSTEM_FAMILY,
  114. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  115. if (em->mode < MODE_ENTRY) {
  116. write_err_chart(NETDATA_VFS_OPEN_ERR, NETDATA_FILESYSTEM_FAMILY,
  117. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN], 1);
  118. }
  119. write_count_chart(NETDATA_VFS_CREATE, NETDATA_FILESYSTEM_FAMILY,
  120. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE], 1);
  121. if (em->mode < MODE_ENTRY) {
  122. write_err_chart(
  123. NETDATA_VFS_CREATE_ERR,
  124. NETDATA_FILESYSTEM_FAMILY,
  125. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  126. 1);
  127. }
  128. }
  129. /**
  130. * Read the hash table and store data to allocated vectors.
  131. */
  132. static void read_global_table()
  133. {
  134. uint64_t idx;
  135. netdata_idx_t res[NETDATA_VFS_COUNTER];
  136. netdata_idx_t *val = vfs_hash_values;
  137. int fd = vfs_maps[NETDATA_VFS_ALL].map_fd;
  138. for (idx = 0; idx < NETDATA_VFS_COUNTER; idx++) {
  139. uint64_t total = 0;
  140. if (!bpf_map_lookup_elem(fd, &idx, val)) {
  141. int i;
  142. int end = ebpf_nprocs;
  143. for (i = 0; i < end; i++)
  144. total += val[i];
  145. }
  146. res[idx] = total;
  147. }
  148. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].ncall = res[NETDATA_KEY_CALLS_VFS_UNLINK];
  149. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].ncall = res[NETDATA_KEY_CALLS_VFS_READ] +
  150. res[NETDATA_KEY_CALLS_VFS_READV];
  151. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].ncall = res[NETDATA_KEY_CALLS_VFS_WRITE] +
  152. res[NETDATA_KEY_CALLS_VFS_WRITEV];
  153. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].ncall = res[NETDATA_KEY_CALLS_VFS_FSYNC];
  154. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].ncall = res[NETDATA_KEY_CALLS_VFS_OPEN];
  155. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].ncall = res[NETDATA_KEY_CALLS_VFS_CREATE];
  156. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].nerr = res[NETDATA_KEY_ERROR_VFS_UNLINK];
  157. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].nerr = res[NETDATA_KEY_ERROR_VFS_READ] +
  158. res[NETDATA_KEY_ERROR_VFS_READV];
  159. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].nerr = res[NETDATA_KEY_ERROR_VFS_WRITE] +
  160. res[NETDATA_KEY_ERROR_VFS_WRITEV];
  161. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].nerr = res[NETDATA_KEY_ERROR_VFS_FSYNC];
  162. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].nerr = res[NETDATA_KEY_ERROR_VFS_OPEN];
  163. vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].nerr = res[NETDATA_KEY_ERROR_VFS_CREATE];
  164. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_WRITE].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITE] +
  165. (uint64_t)res[NETDATA_KEY_BYTES_VFS_WRITEV];
  166. vfs_aggregated_data[NETDATA_KEY_PUBLISH_VFS_READ].bytes = (uint64_t)res[NETDATA_KEY_BYTES_VFS_READ] +
  167. (uint64_t)res[NETDATA_KEY_BYTES_VFS_READV];
  168. }
  169. /**
  170. * Sum PIDs
  171. *
  172. * Sum values for all targets.
  173. *
  174. * @param swap output structure
  175. * @param root link list with structure to be used
  176. */
  177. static void ebpf_vfs_sum_pids(netdata_publish_vfs_t *vfs, struct pid_on_target *root)
  178. {
  179. netdata_publish_vfs_t accumulator;
  180. memset(&accumulator, 0, sizeof(accumulator));
  181. while (root) {
  182. int32_t pid = root->pid;
  183. netdata_publish_vfs_t *w = vfs_pid[pid];
  184. if (w) {
  185. accumulator.write_call += w->write_call;
  186. accumulator.writev_call += w->writev_call;
  187. accumulator.read_call += w->read_call;
  188. accumulator.readv_call += w->readv_call;
  189. accumulator.unlink_call += w->unlink_call;
  190. accumulator.fsync_call += w->fsync_call;
  191. accumulator.open_call += w->open_call;
  192. accumulator.create_call += w->create_call;
  193. accumulator.write_bytes += w->write_bytes;
  194. accumulator.writev_bytes += w->writev_bytes;
  195. accumulator.read_bytes += w->read_bytes;
  196. accumulator.readv_bytes += w->readv_bytes;
  197. accumulator.write_err += w->write_err;
  198. accumulator.writev_err += w->writev_err;
  199. accumulator.read_err += w->read_err;
  200. accumulator.readv_err += w->readv_err;
  201. accumulator.unlink_err += w->unlink_err;
  202. accumulator.fsync_err += w->fsync_err;
  203. accumulator.open_err += w->open_err;
  204. accumulator.create_err += w->create_err;
  205. }
  206. root = root->next;
  207. }
  208. // These conditions were added, because we are using incremental algorithm
  209. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  210. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  211. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  212. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  213. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  214. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  215. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  216. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  217. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  218. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  219. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  220. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  221. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  222. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  223. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  224. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  225. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  226. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  227. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  228. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  229. }
  230. /**
  231. * Send data to Netdata calling auxiliary functions.
  232. *
  233. * @param em the structure with thread information
  234. * @param root the target list.
  235. */
  236. void ebpf_vfs_send_apps_data(ebpf_module_t *em, struct target *root)
  237. {
  238. struct target *w;
  239. for (w = root; w; w = w->next) {
  240. if (unlikely(w->exposed && w->processes)) {
  241. ebpf_vfs_sum_pids(&w->vfs, w->root_pid);
  242. }
  243. }
  244. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED);
  245. for (w = root; w; w = w->next) {
  246. if (unlikely(w->exposed && w->processes)) {
  247. write_chart_dimension(w->name, w->vfs.unlink_call);
  248. }
  249. }
  250. write_end_chart();
  251. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  252. for (w = root; w; w = w->next) {
  253. if (unlikely(w->exposed && w->processes)) {
  254. write_chart_dimension(w->name, w->vfs.write_call + w->vfs.writev_call);
  255. }
  256. }
  257. write_end_chart();
  258. if (em->mode < MODE_ENTRY) {
  259. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  260. for (w = root; w; w = w->next) {
  261. if (unlikely(w->exposed && w->processes)) {
  262. write_chart_dimension(w->name, w->vfs.write_err + w->vfs.writev_err);
  263. }
  264. }
  265. write_end_chart();
  266. }
  267. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  268. for (w = root; w; w = w->next) {
  269. if (unlikely(w->exposed && w->processes)) {
  270. write_chart_dimension(w->name, w->vfs.read_call + w->vfs.readv_call);
  271. }
  272. }
  273. write_end_chart();
  274. if (em->mode < MODE_ENTRY) {
  275. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  276. for (w = root; w; w = w->next) {
  277. if (unlikely(w->exposed && w->processes)) {
  278. write_chart_dimension(w->name, w->vfs.read_err + w->vfs.readv_err);
  279. }
  280. }
  281. write_end_chart();
  282. }
  283. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  284. for (w = root; w; w = w->next) {
  285. if (unlikely(w->exposed && w->processes)) {
  286. write_chart_dimension(w->name, w->vfs.write_bytes + w->vfs.writev_bytes);
  287. }
  288. }
  289. write_end_chart();
  290. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  291. for (w = root; w; w = w->next) {
  292. if (unlikely(w->exposed && w->processes)) {
  293. write_chart_dimension(w->name, w->vfs.read_bytes + w->vfs.readv_bytes);
  294. }
  295. }
  296. write_end_chart();
  297. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  298. for (w = root; w; w = w->next) {
  299. if (unlikely(w->exposed && w->processes)) {
  300. write_chart_dimension(w->name, w->vfs.fsync_call);
  301. }
  302. }
  303. write_end_chart();
  304. if (em->mode < MODE_ENTRY) {
  305. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  306. for (w = root; w; w = w->next) {
  307. if (unlikely(w->exposed && w->processes)) {
  308. write_chart_dimension(w->name, w->vfs.fsync_err);
  309. }
  310. }
  311. write_end_chart();
  312. }
  313. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN);
  314. for (w = root; w; w = w->next) {
  315. if (unlikely(w->exposed && w->processes)) {
  316. write_chart_dimension(w->name, w->vfs.open_call);
  317. }
  318. }
  319. write_end_chart();
  320. if (em->mode < MODE_ENTRY) {
  321. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  322. for (w = root; w; w = w->next) {
  323. if (unlikely(w->exposed && w->processes)) {
  324. write_chart_dimension(w->name, w->vfs.open_err);
  325. }
  326. }
  327. write_end_chart();
  328. }
  329. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE);
  330. for (w = root; w; w = w->next) {
  331. if (unlikely(w->exposed && w->processes)) {
  332. write_chart_dimension(w->name, w->vfs.create_call);
  333. }
  334. }
  335. write_end_chart();
  336. if (em->mode < MODE_ENTRY) {
  337. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  338. for (w = root; w; w = w->next) {
  339. if (unlikely(w->exposed && w->processes)) {
  340. write_chart_dimension(w->name, w->vfs.create_err);
  341. }
  342. }
  343. write_end_chart();
  344. }
  345. }
  346. /**
  347. * Apps Accumulator
  348. *
  349. * Sum all values read from kernel and store in the first address.
  350. *
  351. * @param out the vector with read values.
  352. */
  353. static void vfs_apps_accumulator(netdata_publish_vfs_t *out)
  354. {
  355. int i, end = (running_on_kernel >= NETDATA_KERNEL_V4_15) ? ebpf_nprocs : 1;
  356. netdata_publish_vfs_t *total = &out[0];
  357. for (i = 1; i < end; i++) {
  358. netdata_publish_vfs_t *w = &out[i];
  359. total->write_call += w->write_call;
  360. total->writev_call += w->writev_call;
  361. total->read_call += w->read_call;
  362. total->readv_call += w->readv_call;
  363. total->unlink_call += w->unlink_call;
  364. total->write_bytes += w->write_bytes;
  365. total->writev_bytes += w->writev_bytes;
  366. total->read_bytes += w->read_bytes;
  367. total->readv_bytes += w->readv_bytes;
  368. total->write_err += w->write_err;
  369. total->writev_err += w->writev_err;
  370. total->read_err += w->read_err;
  371. total->readv_err += w->readv_err;
  372. total->unlink_err += w->unlink_err;
  373. }
  374. }
  375. /**
  376. * Fill PID
  377. *
  378. * Fill PID structures
  379. *
  380. * @param current_pid pid that we are collecting data
  381. * @param out values read from hash tables;
  382. */
  383. static void vfs_fill_pid(uint32_t current_pid, netdata_publish_vfs_t *publish)
  384. {
  385. netdata_publish_vfs_t *curr = vfs_pid[current_pid];
  386. if (!curr) {
  387. curr = callocz(1, sizeof(netdata_publish_vfs_t));
  388. vfs_pid[current_pid] = curr;
  389. }
  390. memcpy(curr, &publish[0], sizeof(netdata_publish_vfs_t));
  391. }
  392. /**
  393. * Read the hash table and store data to allocated vectors.
  394. */
  395. static void ebpf_vfs_read_apps()
  396. {
  397. struct pid_stat *pids = root_of_pids;
  398. netdata_publish_vfs_t *vv = vfs_vector;
  399. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  400. size_t length = sizeof(netdata_publish_vfs_t) * ebpf_nprocs;
  401. while (pids) {
  402. uint32_t key = pids->pid;
  403. if (bpf_map_lookup_elem(fd, &key, vv)) {
  404. pids = pids->next;
  405. continue;
  406. }
  407. vfs_apps_accumulator(vv);
  408. vfs_fill_pid(key, vv);
  409. // We are cleaning to avoid passing data read from one process to other.
  410. memset(vv, 0, length);
  411. pids = pids->next;
  412. }
  413. }
  414. /**
  415. * Update cgroup
  416. *
  417. * Update cgroup data based in
  418. */
  419. static void read_update_vfs_cgroup()
  420. {
  421. ebpf_cgroup_target_t *ect ;
  422. netdata_publish_vfs_t *vv = vfs_vector;
  423. int fd = vfs_maps[NETDATA_VFS_PID].map_fd;
  424. size_t length = sizeof(netdata_publish_vfs_t) * ebpf_nprocs;
  425. pthread_mutex_lock(&mutex_cgroup_shm);
  426. for (ect = ebpf_cgroup_pids; ect; ect = ect->next) {
  427. struct pid_on_target2 *pids;
  428. for (pids = ect->pids; pids; pids = pids->next) {
  429. int pid = pids->pid;
  430. netdata_publish_vfs_t *out = &pids->vfs;
  431. if (likely(vfs_pid) && vfs_pid[pid]) {
  432. netdata_publish_vfs_t *in = vfs_pid[pid];
  433. memcpy(out, in, sizeof(netdata_publish_vfs_t));
  434. } else {
  435. memset(vv, 0, length);
  436. if (!bpf_map_lookup_elem(fd, &pid, vv)) {
  437. vfs_apps_accumulator(vv);
  438. memcpy(out, vv, sizeof(netdata_publish_vfs_t));
  439. }
  440. }
  441. }
  442. }
  443. pthread_mutex_unlock(&mutex_cgroup_shm);
  444. }
  445. /**
  446. * VFS read hash
  447. *
  448. * This is the thread callback.
  449. * This thread is necessary, because we cannot freeze the whole plugin to read the data.
  450. *
  451. * @param ptr It is a NULL value for this thread.
  452. *
  453. * @return It always returns NULL.
  454. */
  455. void *ebpf_vfs_read_hash(void *ptr)
  456. {
  457. read_thread_closed = 0;
  458. heartbeat_t hb;
  459. heartbeat_init(&hb);
  460. ebpf_module_t *em = (ebpf_module_t *)ptr;
  461. usec_t step = NETDATA_LATENCY_VFS_SLEEP_MS * em->update_every;
  462. while (!close_ebpf_plugin) {
  463. usec_t dt = heartbeat_next(&hb, step);
  464. (void)dt;
  465. read_global_table();
  466. }
  467. read_thread_closed = 1;
  468. return NULL;
  469. }
  470. /**
  471. * Sum PIDs
  472. *
  473. * Sum values for all targets.
  474. *
  475. * @param vfs structure used to store data
  476. * @param pids input data
  477. */
  478. static void ebpf_vfs_sum_cgroup_pids(netdata_publish_vfs_t *vfs, struct pid_on_target2 *pids)
  479. {
  480. netdata_publish_vfs_t accumulator;
  481. memset(&accumulator, 0, sizeof(accumulator));
  482. while (pids) {
  483. netdata_publish_vfs_t *w = &pids->vfs;
  484. accumulator.write_call += w->write_call;
  485. accumulator.writev_call += w->writev_call;
  486. accumulator.read_call += w->read_call;
  487. accumulator.readv_call += w->readv_call;
  488. accumulator.unlink_call += w->unlink_call;
  489. accumulator.fsync_call += w->fsync_call;
  490. accumulator.open_call += w->open_call;
  491. accumulator.create_call += w->create_call;
  492. accumulator.write_bytes += w->write_bytes;
  493. accumulator.writev_bytes += w->writev_bytes;
  494. accumulator.read_bytes += w->read_bytes;
  495. accumulator.readv_bytes += w->readv_bytes;
  496. accumulator.write_err += w->write_err;
  497. accumulator.writev_err += w->writev_err;
  498. accumulator.read_err += w->read_err;
  499. accumulator.readv_err += w->readv_err;
  500. accumulator.unlink_err += w->unlink_err;
  501. accumulator.fsync_err += w->fsync_err;
  502. accumulator.open_err += w->open_err;
  503. accumulator.create_err += w->create_err;
  504. pids = pids->next;
  505. }
  506. // These conditions were added, because we are using incremental algorithm
  507. vfs->write_call = (accumulator.write_call >= vfs->write_call) ? accumulator.write_call : vfs->write_call;
  508. vfs->writev_call = (accumulator.writev_call >= vfs->writev_call) ? accumulator.writev_call : vfs->writev_call;
  509. vfs->read_call = (accumulator.read_call >= vfs->read_call) ? accumulator.read_call : vfs->read_call;
  510. vfs->readv_call = (accumulator.readv_call >= vfs->readv_call) ? accumulator.readv_call : vfs->readv_call;
  511. vfs->unlink_call = (accumulator.unlink_call >= vfs->unlink_call) ? accumulator.unlink_call : vfs->unlink_call;
  512. vfs->fsync_call = (accumulator.fsync_call >= vfs->fsync_call) ? accumulator.fsync_call : vfs->fsync_call;
  513. vfs->open_call = (accumulator.open_call >= vfs->open_call) ? accumulator.open_call : vfs->open_call;
  514. vfs->create_call = (accumulator.create_call >= vfs->create_call) ? accumulator.create_call : vfs->create_call;
  515. vfs->write_bytes = (accumulator.write_bytes >= vfs->write_bytes) ? accumulator.write_bytes : vfs->write_bytes;
  516. vfs->writev_bytes = (accumulator.writev_bytes >= vfs->writev_bytes) ? accumulator.writev_bytes : vfs->writev_bytes;
  517. vfs->read_bytes = (accumulator.read_bytes >= vfs->read_bytes) ? accumulator.read_bytes : vfs->read_bytes;
  518. vfs->readv_bytes = (accumulator.readv_bytes >= vfs->readv_bytes) ? accumulator.readv_bytes : vfs->readv_bytes;
  519. vfs->write_err = (accumulator.write_err >= vfs->write_err) ? accumulator.write_err : vfs->write_err;
  520. vfs->writev_err = (accumulator.writev_err >= vfs->writev_err) ? accumulator.writev_err : vfs->writev_err;
  521. vfs->read_err = (accumulator.read_err >= vfs->read_err) ? accumulator.read_err : vfs->read_err;
  522. vfs->readv_err = (accumulator.readv_err >= vfs->readv_err) ? accumulator.readv_err : vfs->readv_err;
  523. vfs->unlink_err = (accumulator.unlink_err >= vfs->unlink_err) ? accumulator.unlink_err : vfs->unlink_err;
  524. vfs->fsync_err = (accumulator.fsync_err >= vfs->fsync_err) ? accumulator.fsync_err : vfs->fsync_err;
  525. vfs->open_err = (accumulator.open_err >= vfs->open_err) ? accumulator.open_err : vfs->open_err;
  526. vfs->create_err = (accumulator.create_err >= vfs->create_err) ? accumulator.create_err : vfs->create_err;
  527. }
  528. /**
  529. * Create specific VFS charts
  530. *
  531. * Create charts for cgroup/application.
  532. *
  533. * @param type the chart type.
  534. * @param em the main thread structure.
  535. */
  536. static void ebpf_create_specific_vfs_charts(char *type, ebpf_module_t *em)
  537. {
  538. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED,"Files deleted",
  539. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  540. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500,
  541. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  542. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  543. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  544. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  545. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501,
  546. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  547. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  548. if (em->mode < MODE_ENTRY) {
  549. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  550. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  551. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502,
  552. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  553. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  554. }
  555. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  556. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_CONTEXT,
  557. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503,
  558. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  559. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  560. if (em->mode < MODE_ENTRY) {
  561. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  562. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  563. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504,
  564. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  565. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  566. }
  567. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  568. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  569. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505,
  570. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE],
  571. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  572. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  573. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  574. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506,
  575. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  576. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  577. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls for <code>vfs_fsync</code>",
  578. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  579. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507,
  580. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  581. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  582. if (em->mode < MODE_ENTRY) {
  583. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  584. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  585. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508,
  586. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  587. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  588. }
  589. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls for <code>vfs_open</code>",
  590. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  591. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509,
  592. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  593. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  594. if (em->mode < MODE_ENTRY) {
  595. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  596. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  597. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510,
  598. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  599. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  600. }
  601. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls for <code>vfs_create</code>",
  602. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  603. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511,
  604. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  605. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  606. if (em->mode < MODE_ENTRY) {
  607. ebpf_create_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  608. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  609. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512,
  610. ebpf_create_global_dimension, &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  611. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SWAP);
  612. }
  613. }
  614. /**
  615. * Obsolete specific VFS charts
  616. *
  617. * Obsolete charts for cgroup/application.
  618. *
  619. * @param type the chart type.
  620. * @param em the main thread structure.
  621. */
  622. static void ebpf_obsolete_specific_vfs_charts(char *type, ebpf_module_t *em)
  623. {
  624. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_FILE_DELETED, "Files deleted",
  625. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  626. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_UNLINK_CONTEXT,
  627. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5500, em->update_every);
  628. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  629. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  630. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_CONTEXT,
  631. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5501, em->update_every);
  632. if (em->mode < MODE_ENTRY) {
  633. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  634. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  635. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_ERROR_CONTEXT,
  636. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5502, em->update_every);
  637. }
  638. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  639. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  640. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_CONTEXT,
  641. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5503, em->update_every);
  642. if (em->mode < MODE_ENTRY) {
  643. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  644. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  645. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_ERROR_CONTEXT,
  646. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5504, em->update_every);
  647. }
  648. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  649. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  650. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_WRITE_BYTES_CONTEXT,
  651. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5505, em->update_every);
  652. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  653. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_GROUP,
  654. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_READ_BYTES_CONTEXT,
  655. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5506, em->update_every);
  656. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls for <code>vfs_fsync</code>",
  657. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  658. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_CONTEXT,
  659. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5507, em->update_every);
  660. if (em->mode < MODE_ENTRY) {
  661. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  662. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  663. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_FSYNC_ERROR_CONTEXT,
  664. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5508, em->update_every);
  665. }
  666. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls for <code>vfs_open</code>",
  667. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  668. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_CONTEXT,
  669. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5509, em->update_every);
  670. if (em->mode < MODE_ENTRY) {
  671. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  672. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  673. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_OPEN_ERROR_CONTEXT,
  674. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5510, em->update_every);
  675. }
  676. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls for <code>vfs_create</code>",
  677. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  678. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_CONTEXT,
  679. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5511, em->update_every);
  680. if (em->mode < MODE_ENTRY) {
  681. ebpf_write_chart_obsolete(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  682. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_GROUP,
  683. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_CGROUP_VFS_CREATE_ERROR_CONTEXT,
  684. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + 5512, em->update_every);
  685. }
  686. }
  687. /*
  688. * Send specific VFS data
  689. *
  690. * Send data for specific cgroup/apps.
  691. *
  692. * @param type chart type
  693. * @param values structure with values that will be sent to netdata
  694. */
  695. static void ebpf_send_specific_vfs_data(char *type, netdata_publish_vfs_t *values, ebpf_module_t *em)
  696. {
  697. write_begin_chart(type, NETDATA_SYSCALL_APPS_FILE_DELETED);
  698. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK].name, (long long)values->unlink_call);
  699. write_end_chart();
  700. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  701. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  702. (long long)values->write_call + (long long)values->writev_call);
  703. write_end_chart();
  704. if (em->mode < MODE_ENTRY) {
  705. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  706. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  707. (long long)values->write_err + (long long)values->writev_err);
  708. write_end_chart();
  709. }
  710. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  711. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  712. (long long)values->read_call + (long long)values->readv_call);
  713. write_end_chart();
  714. if (em->mode < MODE_ENTRY) {
  715. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  716. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  717. (long long)values->read_err + (long long)values->readv_err);
  718. write_end_chart();
  719. }
  720. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  721. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_WRITE].name,
  722. (long long)values->write_bytes + (long long)values->writev_bytes);
  723. write_end_chart();
  724. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  725. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ].name,
  726. (long long)values->read_bytes + (long long)values->readv_bytes);
  727. write_end_chart();
  728. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  729. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  730. (long long)values->fsync_call);
  731. write_end_chart();
  732. if (em->mode < MODE_ENTRY) {
  733. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  734. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC].name,
  735. (long long)values->fsync_err);
  736. write_end_chart();
  737. }
  738. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN);
  739. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  740. (long long)values->open_call);
  741. write_end_chart();
  742. if (em->mode < MODE_ENTRY) {
  743. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  744. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN].name,
  745. (long long)values->open_err);
  746. write_end_chart();
  747. }
  748. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE);
  749. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  750. (long long)values->create_call);
  751. write_end_chart();
  752. if (em->mode < MODE_ENTRY) {
  753. write_begin_chart(type, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  754. write_chart_dimension(vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE].name,
  755. (long long)values->create_err);
  756. write_end_chart();
  757. }
  758. }
  759. /**
  760. * Create Systemd Socket Charts
  761. *
  762. * Create charts when systemd is enabled
  763. *
  764. * @param em the main collector structure
  765. **/
  766. static void ebpf_create_systemd_vfs_charts(ebpf_module_t *em)
  767. {
  768. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_FILE_DELETED, "Files deleted",
  769. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  770. NETDATA_EBPF_CHART_TYPE_STACKED, 20065,
  771. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_UNLINK_CONTEXT,
  772. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  773. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS, "Write to disk",
  774. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  775. NETDATA_EBPF_CHART_TYPE_STACKED, 20066,
  776. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_CONTEXT,
  777. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  778. if (em->mode < MODE_ENTRY) {
  779. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR, "Fails to write",
  780. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  781. NETDATA_EBPF_CHART_TYPE_STACKED, 20067,
  782. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  783. NETDATA_SYSTEMD_VFS_WRITE_ERROR_CONTEXT,
  784. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  785. }
  786. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS, "Read from disk",
  787. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  788. NETDATA_EBPF_CHART_TYPE_STACKED, 20068,
  789. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_CONTEXT,
  790. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  791. if (em->mode < MODE_ENTRY) {
  792. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR, "Fails to read",
  793. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  794. NETDATA_EBPF_CHART_TYPE_STACKED, 20069,
  795. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  796. NETDATA_SYSTEMD_VFS_READ_ERROR_CONTEXT,
  797. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  798. }
  799. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES, "Bytes written on disk",
  800. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  801. NETDATA_EBPF_CHART_TYPE_STACKED, 20070,
  802. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_WRITE_BYTES_CONTEXT,
  803. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  804. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_READ_BYTES, "Bytes read from disk",
  805. EBPF_COMMON_DIMENSION_BYTES, NETDATA_VFS_CGROUP_GROUP,
  806. NETDATA_EBPF_CHART_TYPE_STACKED, 20071,
  807. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_READ_BYTES_CONTEXT,
  808. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  809. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC, "Calls to <code>vfs_fsync</code>",
  810. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  811. NETDATA_EBPF_CHART_TYPE_STACKED, 20072,
  812. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_CONTEXT,
  813. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  814. if (em->mode < MODE_ENTRY) {
  815. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR, "Sync error",
  816. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  817. NETDATA_EBPF_CHART_TYPE_STACKED, 20073,
  818. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_FSYNC_ERROR_CONTEXT,
  819. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  820. }
  821. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN, "Calls to <code>vfs_open</code>",
  822. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  823. NETDATA_EBPF_CHART_TYPE_STACKED, 20074,
  824. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_CONTEXT,
  825. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  826. if (em->mode < MODE_ENTRY) {
  827. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR, "Open error",
  828. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  829. NETDATA_EBPF_CHART_TYPE_STACKED, 20075,
  830. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_OPEN_ERROR_CONTEXT,
  831. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  832. }
  833. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE, "Calls to <code>vfs_create</code>",
  834. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  835. NETDATA_EBPF_CHART_TYPE_STACKED, 20076,
  836. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_CONTEXT,
  837. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  838. if (em->mode < MODE_ENTRY) {
  839. ebpf_create_charts_on_systemd(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR, "Create error",
  840. EBPF_COMMON_DIMENSION_CALL, NETDATA_VFS_CGROUP_GROUP,
  841. NETDATA_EBPF_CHART_TYPE_STACKED, 20077,
  842. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX], NETDATA_SYSTEMD_VFS_CREATE_ERROR_CONTEXT,
  843. NETDATA_EBPF_MODULE_NAME_VFS, em->update_every);
  844. }
  845. }
  846. /**
  847. * Send Systemd charts
  848. *
  849. * Send collected data to Netdata.
  850. *
  851. * @param em the main collector structure
  852. *
  853. * @return It returns the status for chart creation, if it is necessary to remove a specific dimension, zero is returned
  854. * otherwise function returns 1 to avoid chart recreation
  855. */
  856. static int ebpf_send_systemd_vfs_charts(ebpf_module_t *em)
  857. {
  858. int ret = 1;
  859. ebpf_cgroup_target_t *ect;
  860. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_FILE_DELETED);
  861. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  862. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  863. write_chart_dimension(ect->name, ect->publish_systemd_vfs.unlink_call);
  864. } else
  865. ret = 0;
  866. }
  867. write_end_chart();
  868. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS);
  869. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  870. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  871. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_call +
  872. ect->publish_systemd_vfs.writev_call);
  873. }
  874. }
  875. write_end_chart();
  876. if (em->mode < MODE_ENTRY) {
  877. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR);
  878. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  879. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  880. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_err +
  881. ect->publish_systemd_vfs.writev_err);
  882. }
  883. }
  884. write_end_chart();
  885. }
  886. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS);
  887. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  888. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  889. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_call +
  890. ect->publish_systemd_vfs.readv_call);
  891. }
  892. }
  893. write_end_chart();
  894. if (em->mode < MODE_ENTRY) {
  895. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR);
  896. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  897. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  898. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_err +
  899. ect->publish_systemd_vfs.readv_err);
  900. }
  901. }
  902. write_end_chart();
  903. }
  904. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES);
  905. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  906. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  907. write_chart_dimension(ect->name, ect->publish_systemd_vfs.write_bytes +
  908. ect->publish_systemd_vfs.writev_bytes);
  909. }
  910. }
  911. write_end_chart();
  912. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_READ_BYTES);
  913. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  914. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  915. write_chart_dimension(ect->name, ect->publish_systemd_vfs.read_bytes +
  916. ect->publish_systemd_vfs.readv_bytes);
  917. }
  918. }
  919. write_end_chart();
  920. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC);
  921. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  922. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  923. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_call);
  924. }
  925. }
  926. write_end_chart();
  927. if (em->mode < MODE_ENTRY) {
  928. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR);
  929. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  930. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  931. write_chart_dimension(ect->name, ect->publish_systemd_vfs.fsync_err);
  932. }
  933. }
  934. write_end_chart();
  935. }
  936. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN);
  937. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  938. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  939. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_call);
  940. }
  941. }
  942. write_end_chart();
  943. if (em->mode < MODE_ENTRY) {
  944. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR);
  945. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  946. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  947. write_chart_dimension(ect->name, ect->publish_systemd_vfs.open_err);
  948. }
  949. }
  950. write_end_chart();
  951. }
  952. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE);
  953. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  954. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  955. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_call);
  956. }
  957. }
  958. write_end_chart();
  959. if (em->mode < MODE_ENTRY) {
  960. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR);
  961. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  962. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  963. write_chart_dimension(ect->name, ect->publish_systemd_vfs.create_err);
  964. }
  965. }
  966. write_end_chart();
  967. }
  968. return ret;
  969. }
  970. /**
  971. * Send data to Netdata calling auxiliary functions.
  972. *
  973. * @param em the main collector structure
  974. */
  975. static void ebpf_vfs_send_cgroup_data(ebpf_module_t *em)
  976. {
  977. if (!ebpf_cgroup_pids)
  978. return;
  979. pthread_mutex_lock(&mutex_cgroup_shm);
  980. ebpf_cgroup_target_t *ect;
  981. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  982. ebpf_vfs_sum_cgroup_pids(&ect->publish_systemd_vfs, ect->pids);
  983. }
  984. int has_systemd = shm_ebpf_cgroup.header->systemd_enabled;
  985. if (has_systemd) {
  986. static int systemd_charts = 0;
  987. if (!systemd_charts) {
  988. ebpf_create_systemd_vfs_charts(em);
  989. systemd_charts = 1;
  990. }
  991. systemd_charts = ebpf_send_systemd_vfs_charts(em);
  992. }
  993. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  994. if (ect->systemd)
  995. continue;
  996. if (!(ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) && ect->updated) {
  997. ebpf_create_specific_vfs_charts(ect->name, em);
  998. ect->flags |= NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  999. }
  1000. if (ect->flags & NETDATA_EBPF_CGROUP_HAS_VFS_CHART) {
  1001. if (ect->updated) {
  1002. ebpf_send_specific_vfs_data(ect->name, &ect->publish_systemd_vfs, em);
  1003. } else {
  1004. ebpf_obsolete_specific_vfs_charts(ect->name, em);
  1005. ect->flags &= ~NETDATA_EBPF_CGROUP_HAS_VFS_CHART;
  1006. }
  1007. }
  1008. }
  1009. pthread_mutex_unlock(&mutex_cgroup_shm);
  1010. }
  1011. /**
  1012. * Main loop for this collector.
  1013. *
  1014. * @param step the number of microseconds used with heart beat
  1015. * @param em the structure with thread information
  1016. */
  1017. static void vfs_collector(ebpf_module_t *em)
  1018. {
  1019. vfs_threads.thread = mallocz(sizeof(netdata_thread_t));
  1020. vfs_threads.start_routine = ebpf_vfs_read_hash;
  1021. netdata_thread_create(vfs_threads.thread, vfs_threads.name, NETDATA_THREAD_OPTION_JOINABLE,
  1022. ebpf_vfs_read_hash, em);
  1023. int apps = em->apps_charts;
  1024. int cgroups = em->cgroup_charts;
  1025. int update_every = em->update_every;
  1026. int counter = update_every - 1;
  1027. while (!close_ebpf_plugin) {
  1028. pthread_mutex_lock(&collect_data_mutex);
  1029. pthread_cond_wait(&collect_data_cond_var, &collect_data_mutex);
  1030. if (++counter == update_every) {
  1031. counter = 0;
  1032. if (apps)
  1033. ebpf_vfs_read_apps();
  1034. if (cgroups)
  1035. read_update_vfs_cgroup();
  1036. pthread_mutex_lock(&lock);
  1037. ebpf_vfs_send_data(em);
  1038. fflush(stdout);
  1039. if (apps)
  1040. ebpf_vfs_send_apps_data(em, apps_groups_root_target);
  1041. if (cgroups)
  1042. ebpf_vfs_send_cgroup_data(em);
  1043. pthread_mutex_unlock(&lock);
  1044. }
  1045. pthread_mutex_unlock(&collect_data_mutex);
  1046. }
  1047. }
  1048. /*****************************************************************
  1049. *
  1050. * FUNCTIONS TO CREATE CHARTS
  1051. *
  1052. *****************************************************************/
  1053. /**
  1054. * Create IO chart
  1055. *
  1056. * @param family the chart family
  1057. * @param name the chart name
  1058. * @param axis the axis label
  1059. * @param web the group name used to attach the chart on dashboard
  1060. * @param order the order number of the specified chart
  1061. * @param algorithm the algorithm used to make the charts.
  1062. * @param update_every value to overwrite the update frequency set by the server.
  1063. */
  1064. static void ebpf_create_io_chart(char *family, char *name, char *axis, char *web,
  1065. int order, int algorithm, int update_every)
  1066. {
  1067. printf("CHART %s.%s '' 'Bytes written and read' '%s' '%s' '' line %d %d '' 'ebpf.plugin' 'filesystem'\n",
  1068. family,
  1069. name,
  1070. axis,
  1071. web,
  1072. order,
  1073. update_every);
  1074. printf("DIMENSION %s %s %s 1 1\n",
  1075. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1076. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_READ],
  1077. ebpf_algorithms[algorithm]);
  1078. printf("DIMENSION %s %s %s -1 1\n",
  1079. vfs_id_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1080. vfs_dimension_names[NETDATA_KEY_PUBLISH_VFS_WRITE],
  1081. ebpf_algorithms[algorithm]);
  1082. }
  1083. /**
  1084. * Create global charts
  1085. *
  1086. * Call ebpf_create_chart to create the charts for the collector.
  1087. *
  1088. * @param em a pointer to the structure with the default values.
  1089. */
  1090. static void ebpf_create_global_charts(ebpf_module_t *em)
  1091. {
  1092. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1093. NETDATA_VFS_FILE_CLEAN_COUNT,
  1094. "Remove files",
  1095. EBPF_COMMON_DIMENSION_CALL,
  1096. NETDATA_VFS_GROUP,
  1097. NULL,
  1098. NETDATA_EBPF_CHART_TYPE_LINE,
  1099. NETDATA_CHART_PRIO_FILESYSTEM_VFS_CLEAN,
  1100. ebpf_create_global_dimension,
  1101. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_UNLINK],
  1102. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1103. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1104. NETDATA_VFS_FILE_IO_COUNT,
  1105. "Calls to IO",
  1106. EBPF_COMMON_DIMENSION_CALL,
  1107. NETDATA_VFS_GROUP,
  1108. NULL,
  1109. NETDATA_EBPF_CHART_TYPE_LINE,
  1110. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_COUNT,
  1111. ebpf_create_global_dimension,
  1112. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1113. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1114. ebpf_create_io_chart(NETDATA_FILESYSTEM_FAMILY,
  1115. NETDATA_VFS_IO_FILE_BYTES, EBPF_COMMON_DIMENSION_BYTES,
  1116. NETDATA_VFS_GROUP,
  1117. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_BYTES,
  1118. NETDATA_EBPF_INCREMENTAL_IDX, em->update_every);
  1119. if (em->mode < MODE_ENTRY) {
  1120. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1121. NETDATA_VFS_FILE_ERR_COUNT,
  1122. "Fails to write or read",
  1123. EBPF_COMMON_DIMENSION_CALL,
  1124. NETDATA_VFS_GROUP,
  1125. NULL,
  1126. NETDATA_EBPF_CHART_TYPE_LINE,
  1127. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EBYTES,
  1128. ebpf_create_global_dimension,
  1129. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_READ],
  1130. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1131. }
  1132. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1133. NETDATA_VFS_FSYNC,
  1134. "Calls for <code>vfs_fsync</code>",
  1135. EBPF_COMMON_DIMENSION_CALL,
  1136. NETDATA_VFS_GROUP,
  1137. NULL,
  1138. NETDATA_EBPF_CHART_TYPE_LINE,
  1139. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_FSYNC,
  1140. ebpf_create_global_dimension,
  1141. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1142. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1143. if (em->mode < MODE_ENTRY) {
  1144. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1145. NETDATA_VFS_FSYNC_ERR,
  1146. "Fails to synchronize",
  1147. EBPF_COMMON_DIMENSION_CALL,
  1148. NETDATA_VFS_GROUP,
  1149. NULL,
  1150. NETDATA_EBPF_CHART_TYPE_LINE,
  1151. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EFSYNC,
  1152. ebpf_create_global_dimension,
  1153. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_FSYNC],
  1154. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1155. }
  1156. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1157. NETDATA_VFS_OPEN,
  1158. "Calls for <code>vfs_open</code>",
  1159. EBPF_COMMON_DIMENSION_CALL,
  1160. NETDATA_VFS_GROUP,
  1161. NULL,
  1162. NETDATA_EBPF_CHART_TYPE_LINE,
  1163. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_OPEN,
  1164. ebpf_create_global_dimension,
  1165. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1166. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1167. if (em->mode < MODE_ENTRY) {
  1168. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1169. NETDATA_VFS_OPEN_ERR,
  1170. "Fails to open a file",
  1171. EBPF_COMMON_DIMENSION_CALL,
  1172. NETDATA_VFS_GROUP,
  1173. NULL,
  1174. NETDATA_EBPF_CHART_TYPE_LINE,
  1175. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_EOPEN,
  1176. ebpf_create_global_dimension,
  1177. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_OPEN],
  1178. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1179. }
  1180. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1181. NETDATA_VFS_CREATE,
  1182. "Calls for <code>vfs_create</code>",
  1183. EBPF_COMMON_DIMENSION_CALL,
  1184. NETDATA_VFS_GROUP,
  1185. NULL,
  1186. NETDATA_EBPF_CHART_TYPE_LINE,
  1187. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_CREATE,
  1188. ebpf_create_global_dimension,
  1189. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1190. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1191. if (em->mode < MODE_ENTRY) {
  1192. ebpf_create_chart(NETDATA_FILESYSTEM_FAMILY,
  1193. NETDATA_VFS_CREATE_ERR,
  1194. "Fails to create a file.",
  1195. EBPF_COMMON_DIMENSION_CALL,
  1196. NETDATA_VFS_GROUP,
  1197. NULL,
  1198. NETDATA_EBPF_CHART_TYPE_LINE,
  1199. NETDATA_CHART_PRIO_FILESYSTEM_VFS_IO_ECREATE,
  1200. ebpf_create_global_dimension,
  1201. &vfs_publish_aggregated[NETDATA_KEY_PUBLISH_VFS_CREATE],
  1202. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1203. }
  1204. }
  1205. /**
  1206. * Create process apps charts
  1207. *
  1208. * Call ebpf_create_chart to create the charts on apps submenu.
  1209. *
  1210. * @param em a pointer to the structure with the default values.
  1211. * @param ptr a pointer for the targets.
  1212. **/
  1213. void ebpf_vfs_create_apps_charts(struct ebpf_module *em, void *ptr)
  1214. {
  1215. struct target *root = ptr;
  1216. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_FILE_DELETED,
  1217. "Files deleted",
  1218. EBPF_COMMON_DIMENSION_CALL,
  1219. NETDATA_VFS_GROUP,
  1220. NETDATA_EBPF_CHART_TYPE_STACKED,
  1221. 20065,
  1222. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1223. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1224. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS,
  1225. "Write to disk",
  1226. EBPF_COMMON_DIMENSION_CALL,
  1227. NETDATA_VFS_GROUP,
  1228. NETDATA_EBPF_CHART_TYPE_STACKED,
  1229. 20066,
  1230. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1231. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1232. if (em->mode < MODE_ENTRY) {
  1233. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_CALLS_ERROR,
  1234. "Fails to write",
  1235. EBPF_COMMON_DIMENSION_CALL,
  1236. NETDATA_VFS_GROUP,
  1237. NETDATA_EBPF_CHART_TYPE_STACKED,
  1238. 20067,
  1239. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1240. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1241. }
  1242. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS,
  1243. "Read from disk",
  1244. EBPF_COMMON_DIMENSION_CALL,
  1245. NETDATA_VFS_GROUP,
  1246. NETDATA_EBPF_CHART_TYPE_STACKED,
  1247. 20068,
  1248. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1249. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1250. if (em->mode < MODE_ENTRY) {
  1251. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_CALLS_ERROR,
  1252. "Fails to read",
  1253. EBPF_COMMON_DIMENSION_CALL,
  1254. NETDATA_VFS_GROUP,
  1255. NETDATA_EBPF_CHART_TYPE_STACKED,
  1256. 20069,
  1257. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1258. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1259. }
  1260. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_WRITE_BYTES,
  1261. "Bytes written on disk", EBPF_COMMON_DIMENSION_BYTES,
  1262. NETDATA_VFS_GROUP,
  1263. NETDATA_EBPF_CHART_TYPE_STACKED,
  1264. 20070,
  1265. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1266. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1267. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_READ_BYTES,
  1268. "Bytes read from disk", EBPF_COMMON_DIMENSION_BYTES,
  1269. NETDATA_VFS_GROUP,
  1270. NETDATA_EBPF_CHART_TYPE_STACKED,
  1271. 20071,
  1272. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1273. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1274. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC,
  1275. "Calls for <code>vfs_fsync</code>", EBPF_COMMON_DIMENSION_CALL,
  1276. NETDATA_VFS_GROUP,
  1277. NETDATA_EBPF_CHART_TYPE_STACKED,
  1278. 20072,
  1279. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1280. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1281. if (em->mode < MODE_ENTRY) {
  1282. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_FSYNC_CALLS_ERROR,
  1283. "Sync error",
  1284. EBPF_COMMON_DIMENSION_CALL,
  1285. NETDATA_VFS_GROUP,
  1286. NETDATA_EBPF_CHART_TYPE_STACKED,
  1287. 20073,
  1288. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1289. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1290. }
  1291. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN,
  1292. "Calls for <code>vfs_open</code>", EBPF_COMMON_DIMENSION_CALL,
  1293. NETDATA_VFS_GROUP,
  1294. NETDATA_EBPF_CHART_TYPE_STACKED,
  1295. 20074,
  1296. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1297. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1298. if (em->mode < MODE_ENTRY) {
  1299. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_OPEN_CALLS_ERROR,
  1300. "Open error",
  1301. EBPF_COMMON_DIMENSION_CALL,
  1302. NETDATA_VFS_GROUP,
  1303. NETDATA_EBPF_CHART_TYPE_STACKED,
  1304. 20075,
  1305. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1306. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1307. }
  1308. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE,
  1309. "Calls for <code>vfs_create</code>", EBPF_COMMON_DIMENSION_CALL,
  1310. NETDATA_VFS_GROUP,
  1311. NETDATA_EBPF_CHART_TYPE_STACKED,
  1312. 20076,
  1313. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1314. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1315. if (em->mode < MODE_ENTRY) {
  1316. ebpf_create_charts_on_apps(NETDATA_SYSCALL_APPS_VFS_CREATE_CALLS_ERROR,
  1317. "Create error",
  1318. EBPF_COMMON_DIMENSION_CALL,
  1319. NETDATA_VFS_GROUP,
  1320. NETDATA_EBPF_CHART_TYPE_STACKED,
  1321. 20077,
  1322. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1323. root, em->update_every, NETDATA_EBPF_MODULE_NAME_VFS);
  1324. }
  1325. }
  1326. /*****************************************************************
  1327. *
  1328. * FUNCTIONS TO START THREAD
  1329. *
  1330. *****************************************************************/
  1331. /**
  1332. * Allocate vectors used with this thread.
  1333. * We are not testing the return, because callocz does this and shutdown the software
  1334. * case it was not possible to allocate.
  1335. *
  1336. * @param apps is apps enabled?
  1337. */
  1338. static void ebpf_vfs_allocate_global_vectors(int apps)
  1339. {
  1340. memset(vfs_aggregated_data, 0, sizeof(vfs_aggregated_data));
  1341. memset(vfs_publish_aggregated, 0, sizeof(vfs_publish_aggregated));
  1342. vfs_hash_values = callocz(ebpf_nprocs, sizeof(netdata_idx_t));
  1343. vfs_vector = callocz(ebpf_nprocs, sizeof(netdata_publish_vfs_t));
  1344. if (apps)
  1345. vfs_pid = callocz((size_t)pid_max, sizeof(netdata_publish_vfs_t *));
  1346. }
  1347. /*****************************************************************
  1348. *
  1349. * EBPF VFS THREAD
  1350. *
  1351. *****************************************************************/
  1352. /**
  1353. * Process thread
  1354. *
  1355. * Thread used to generate process charts.
  1356. *
  1357. * @param ptr a pointer to `struct ebpf_module`
  1358. *
  1359. * @return It always return NULL
  1360. */
  1361. void *ebpf_vfs_thread(void *ptr)
  1362. {
  1363. netdata_thread_cleanup_push(ebpf_vfs_cleanup, ptr);
  1364. ebpf_module_t *em = (ebpf_module_t *)ptr;
  1365. em->maps = vfs_maps;
  1366. ebpf_update_pid_table(&vfs_maps[NETDATA_VFS_PID], em);
  1367. ebpf_vfs_allocate_global_vectors(em->apps_charts);
  1368. if (!em->enabled)
  1369. goto endvfs;
  1370. probe_links = ebpf_load_program(ebpf_plugin_dir, em, running_on_kernel, isrh, &objects);
  1371. if (!probe_links) {
  1372. em->enabled = CONFIG_BOOLEAN_NO;
  1373. goto endvfs;
  1374. }
  1375. int algorithms[NETDATA_KEY_PUBLISH_VFS_END] = {
  1376. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX,
  1377. NETDATA_EBPF_INCREMENTAL_IDX, NETDATA_EBPF_INCREMENTAL_IDX,NETDATA_EBPF_INCREMENTAL_IDX
  1378. };
  1379. ebpf_global_labels(vfs_aggregated_data, vfs_publish_aggregated, vfs_dimension_names,
  1380. vfs_id_names, algorithms, NETDATA_KEY_PUBLISH_VFS_END);
  1381. pthread_mutex_lock(&lock);
  1382. ebpf_create_global_charts(em);
  1383. ebpf_update_stats(&plugin_statistics, em);
  1384. pthread_mutex_unlock(&lock);
  1385. vfs_collector(em);
  1386. endvfs:
  1387. if (!em->enabled)
  1388. ebpf_update_disabled_plugin_stats(em);
  1389. netdata_thread_cleanup_pop(1);
  1390. return NULL;
  1391. }