1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
|
#!/usr/bin/env python3
# SPDX-License-Identifier: GPL-2.0
"""
Displays system-wide system call totals, broken down by syscall.
If a [comm] arg is specified, only syscalls called by [comm] are displayed.
"""
from __future__ import annotations
import argparse
from collections import defaultdict
from typing import (Dict, Tuple)
import perf
syscalls: Dict[Tuple[str, int, int], int] = defaultdict(int)
for_comm = None
for_pid = None
session = None
def print_syscall_totals():
"""Print aggregated statistics."""
if for_comm is not None:
print(f"\nsyscall events for {for_comm}:\n")
elif for_pid is not None:
print(f"\nsyscall events for PID {for_pid}:\n")
else:
print("\nsyscall events:\n")
print(f"{'comm [pid]/syscalls':<40} {'count':>10}")
print("---------------------------------------- -----------")
sorted_keys = sorted(syscalls.keys(), key=lambda k: (k[0], k[1], -syscalls[k], k[2]))
current_comm_pid = None
for comm, pid, sc_id in sorted_keys:
if current_comm_pid != (comm, pid):
print(f"\n{comm} [{pid}]")
current_comm_pid = (comm, pid)
e_machine = getattr(session, "e_machine", 0) or 0
# Mask out the x86_64 x32 ABI bit (__X32_SYSCALL_BIT = 0x40000000) before
# resolving the syscall number in the architecture's syscall table.
raw_sc_id = sc_id & ~0x40000000
if e_machine:
name = perf.syscall_name(raw_sc_id, e_machine) or str(sc_id)
else:
name = perf.syscall_name(raw_sc_id) or str(sc_id)
print(f" {name:<38} {syscalls[(comm, pid, sc_id)]:>10}")
def process_event(sample):
"""Process a single sample event."""
event_name = str(sample.evsel)
# Per-syscall syscalls:sys_enter_* tracepoints expose '__syscall_nr' (or 'nr')
# and may have an unrelated syscall argument named 'id', whereas
# raw_syscalls:sys_enter (and legacy pre-2.6.35 syscalls:sys_enter) expose 'id'.
if event_name.startswith("evsel(syscalls:sys_enter_"):
sc_id = getattr(sample, "__syscall_nr", None)
if sc_id is not None and not (0 <= (sc_id & ~0x40000000) <= 0xffff):
sc_id = None
if sc_id is None:
sc_id = getattr(sample, "nr", -1)
elif event_name.startswith(("evsel(raw_syscalls:sys_enter", "evsel(syscalls:sys_enter")):
sc_id = getattr(sample, "id", -1)
if not (0 <= (sc_id & ~0x40000000) <= 0xffff):
sc_id = getattr(sample, "__syscall_nr", -1)
if not (0 <= (sc_id & ~0x40000000) <= 0xffff):
sc_id = getattr(sample, "nr", -1)
else:
return
# Mask out __X32_SYSCALL_BIT (0x40000000) when validating the syscall ID range.
if not (0 <= (sc_id & ~0x40000000) <= 0xffff):
return
pid = sample.sample_pid
if for_pid is not None and pid != for_pid:
return
comm = "unknown"
try:
if session:
proc = session.find_thread(sample.sample_pid, sample.sample_tid)
if proc:
comm = proc.comm() or "unknown"
except (TypeError, AttributeError):
pass
if for_comm and comm != for_comm:
return
syscalls[(comm, pid, sc_id)] += 1
if __name__ == "__main__":
ap = argparse.ArgumentParser()
ap.add_argument("filter", nargs="?", help="COMM or PID to filter by")
ap.add_argument("-i", "--input", default="perf.data", help="Input file name")
args = ap.parse_args()
if args.filter:
try:
for_pid = int(args.filter)
except ValueError:
for_comm = args.filter
try:
session = perf.session(perf.data(args.input), sample=process_event)
session.process_events()
print_syscall_totals()
finally:
# Break the reference cycle between session and process_event (whose module
# globals reference session) since perf.session lacks cyclic GC (tp_traverse).
session = None
|