home.social

#bpftrace — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bpftrace, aggregated by home.social.

fetched live
  1. Proving SQLx’s Statement Cache with bpftrace

    SQLx prepares and caches every query you run, transparently, in an LRU that belongs to the connection rather than the pool. This post traces the Postgres wire protocol with bpftrace to watch what is happening under the hood.

    Read more

  2. Proving SQLx’s Statement Cache with bpftrace

    SQLx prepares and caches every query you run, transparently, in an LRU that belongs to the connection rather than the pool. This post traces the Postgres wire protocol with bpftrace to watch what is happening under the hood.

    Read more

  3. Proving SQLx’s Statement Cache with bpftrace

    SQLx prepares and caches every query you run, transparently, in an LRU that belongs to the connection rather than the pool. This post traces the Postgres wire protocol with bpftrace to watch what is happening under the hood.

    Read more

  4. Proving SQLx’s Statement Cache with bpftrace

    SQLx prepares and caches every query you run, transparently, in an LRU that belongs to the connection rather than the pool. This post traces the Postgres wire protocol with bpftrace to watch what is happening under the hood.

    Read more

  5. Proving SQLx’s Statement Cache with bpftrace

    SQLx prepares and caches every query you run, transparently, in an LRU that belongs to the connection rather than the pool. This post traces the Postgres wire protocol with bpftrace to watch what is happening under the hood.

    Read more

  6. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  7. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  8. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  9. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  10. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  11. Kprobes и где они обитают

    Про eBPF уже сказано и написано достаточно много, поэтому я хочу сделать следующий шаг и чуть глубже рассмотреть практические аспекты работы c таким механизмом, как kprobe , который позволяет использовать функции ядра Linux для динамического запуска пользовательского кода. Статья поможет ответить на вопросы: - Как понять, какую функцию ядра выбрать для использования с механизмом kprobe? - С чего начать ее поиск? - Какими инструментами пользоваться? kprobe — это, по сути, ловушка, или брейкпоинт, который можно установить почти в любом месте кода ядра Linux.

    habr.com/ru/companies/pt/artic

    #ebpf #kprobes #linux #linux_kernel #container_security #контейнеризация #tetragon #ftrace #bpftrace #open_source

  12. Kprobes и где они обитают

    Про eBPF уже сказано и написано достаточно много, поэтому я хочу сделать следующий шаг и чуть глубже рассмотреть практические аспекты работы c таким механизмом, как kprobe , который позволяет использовать функции ядра Linux для динамического запуска пользовательского кода. Статья поможет ответить на вопросы: - Как понять, какую функцию ядра выбрать для использования с механизмом kprobe? - С чего начать ее поиск? - Какими инструментами пользоваться? kprobe — это, по сути, ловушка, или брейкпоинт, который можно установить почти в любом месте кода ядра Linux.

    habr.com/ru/companies/pt/artic

    #ebpf #kprobes #linux #linux_kernel #container_security #контейнеризация #tetragon #ftrace #bpftrace #open_source

  13. Kprobes и где они обитают

    Про eBPF уже сказано и написано достаточно много, поэтому я хочу сделать следующий шаг и чуть глубже рассмотреть практические аспекты работы c таким механизмом, как kprobe , который позволяет использовать функции ядра Linux для динамического запуска пользовательского кода. Статья поможет ответить на вопросы: - Как понять, какую функцию ядра выбрать для использования с механизмом kprobe? - С чего начать ее поиск? - Какими инструментами пользоваться? kprobe — это, по сути, ловушка, или брейкпоинт, который можно установить почти в любом месте кода ядра Linux.

    habr.com/ru/companies/pt/artic

    #ebpf #kprobes #linux #linux_kernel #container_security #контейнеризация #tetragon #ftrace #bpftrace #open_source

  14. 🐧🐝 Learn essential eBPF #Linux command line tools to improve your service observability with #opensource: t.ly/wNy6b

    Check out #Coroot (we’re #FOSS!) to turn manual service analysis into instant root cause insights. Resolve issues and deploy faster with #eBPF: n9.cl/kfm0rw

    #BPFtrace #BPF #kernel #freesoftware #FLOSS #SRE #DevOps #Coroot #tech #IT #kubernetes

  15. 🐧🐝 Learn essential eBPF #Linux command line tools to improve your service observability with #opensource: t.ly/wNy6b

    Check out #Coroot (we’re #FOSS!) to turn manual service analysis into instant root cause insights. Resolve issues and deploy faster with #eBPF: n9.cl/kfm0rw

    #BPFtrace #BPF #kernel #freesoftware #FLOSS #SRE #DevOps #Coroot #tech #IT #kubernetes

  16. 🐧🐝 Learn essential eBPF #Linux command line tools to improve your service observability with #opensource: t.ly/wNy6b

    Check out #Coroot (we’re #FOSS!) to turn manual service analysis into instant root cause insights. Resolve issues and deploy faster with #eBPF: n9.cl/kfm0rw

    #BPFtrace #BPF #kernel #freesoftware #FLOSS #SRE #DevOps #Coroot #tech #IT #kubernetes

  17. 🐧🐝 Learn essential eBPF #Linux command line tools to improve your service observability with #opensource: t.ly/wNy6b

    Check out #Coroot (we’re #FOSS!) to turn manual service analysis into instant root cause insights. Resolve issues and deploy faster with #eBPF: n9.cl/kfm0rw

    #BPFtrace #BPF #kernel #freesoftware #FLOSS #SRE #DevOps #Coroot #tech #IT #kubernetes

  18. 🐧🐝 Learn essential eBPF #Linux command line tools to improve your service observability with #opensource: t.ly/wNy6b

    Check out #Coroot (we’re #FOSS!) to turn manual service analysis into instant root cause insights. Resolve issues and deploy faster with #eBPF: n9.cl/kfm0rw

    #BPFtrace #BPF #kernel #freesoftware #FLOSS #SRE #DevOps #Coroot #tech #IT #kubernetes

  19. Is there a way to detect #bpftrace version in in its preprocessor in order to support different versions of syntax? The delete syntax changed recently and that breaks a lot of my scripts...

    #ebpf #osdev #linux

  20. Is there a way to detect #bpftrace version in in its preprocessor in order to support different versions of syntax? The delete syntax changed recently and that breaks a lot of my scripts...

    #ebpf #osdev #linux

  21. Is there a way to detect #bpftrace version in in its preprocessor in order to support different versions of syntax? The delete syntax changed recently and that breaks a lot of my scripts...

    #ebpf #osdev #linux

  22. Is there a way to detect #bpftrace version in in its preprocessor in order to support different versions of syntax? The delete syntax changed recently and that breaks a lot of my scripts...

    #ebpf #osdev #linux

  23. Is there a way to detect #bpftrace version in in its preprocessor in order to support different versions of syntax? The delete syntax changed recently and that breaks a lot of my scripts...

    #ebpf #osdev #linux

  24. I was playing with an MDM solution (mobile device management), and looking at why it did not support Ubuntu 24.04 yet (works on 22.04); unfortunately it uses malware-like techniques of execve-ing shell scripts from a memfd.

    Here is how to get the script with bpftrace's execsnoop (could also work with iovisor's or libbpf's):

    sudo execsnoop.bt | stdbuf -o0  grep proc/self/fd | awk -W interactive '{system("sudo cat /proc/"$2"/fd/"substr($4, 15)) }'

    (it did not take me 45 minutes to re-discover mawk's -W interactive )

    I could then analyze the script and discovered that a change in behaviour in jq 1.7 was the source of the issue. Minimal reproducer:

    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.6
    ["a","b"]
    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.7
    ["a","b",""]

    (I won't be reporting to jq upstream, because I don't really care about whether or not this is a regression or a fix)

    #eBPF #mdm #ubuntu #jq #awk #bpftrace

  25. I was playing with an MDM solution (mobile device management), and looking at why it did not support Ubuntu 24.04 yet (works on 22.04); unfortunately it uses malware-like techniques of execve-ing shell scripts from a memfd.

    Here is how to get the script with bpftrace's execsnoop (could also work with iovisor's or libbpf's):

    sudo execsnoop.bt | stdbuf -o0  grep proc/self/fd | awk -W interactive '{system("sudo cat /proc/"$2"/fd/"substr($4, 15)) }'

    (it did not take me 45 minutes to re-discover mawk's -W interactive )

    I could then analyze the script and discovered that a change in behaviour in jq 1.7 was the source of the issue. Minimal reproducer:

    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.6
    ["a","b"]
    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.7
    ["a","b",""]

    (I won't be reporting to jq upstream, because I don't really care about whether or not this is a regression or a fix)

    #eBPF #mdm #ubuntu #jq #awk #bpftrace

  26. I was playing with an MDM solution (mobile device management), and looking at why it did not support Ubuntu 24.04 yet (works on 22.04); unfortunately it uses malware-like techniques of execve-ing shell scripts from a memfd.

    Here is how to get the script with bpftrace's execsnoop (could also work with iovisor's or libbpf's):

    sudo execsnoop.bt | stdbuf -o0  grep proc/self/fd | awk -W interactive '{system("sudo cat /proc/"$2"/fd/"substr($4, 15)) }'

    (it did not take me 45 minutes to re-discover mawk's -W interactive )

    I could then analyze the script and discovered that a change in behaviour in jq 1.7 was the source of the issue. Minimal reproducer:

    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.6
    ["a","b"]
    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.7
    ["a","b",""]

    (I won't be reporting to jq upstream, because I don't really care about whether or not this is a regression or a fix)

    #eBPF #mdm #ubuntu #jq #awk #bpftrace

  27. I was playing with an MDM solution (mobile device management), and looking at why it did not support Ubuntu 24.04 yet (works on 22.04); unfortunately it uses malware-like techniques of execve-ing shell scripts from a memfd.

    Here is how to get the script with bpftrace's execsnoop (could also work with iovisor's or libbpf's):

    sudo execsnoop.bt | stdbuf -o0  grep proc/self/fd | awk -W interactive '{system("sudo cat /proc/"$2"/fd/"substr($4, 15)) }'

    (it did not take me 45 minutes to re-discover mawk's -W interactive )

    I could then analyze the script and discovered that a change in behaviour in jq 1.7 was the source of the issue. Minimal reproducer:

    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.6
    ["a","b"]
    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.7
    ["a","b",""]

    (I won't be reporting to jq upstream, because I don't really care about whether or not this is a regression or a fix)

    #eBPF #mdm #ubuntu #jq #awk #bpftrace

  28. I was playing with an MDM solution (mobile device management), and looking at why it did not support Ubuntu 24.04 yet (works on 22.04); unfortunately it uses malware-like techniques of execve-ing shell scripts from a memfd.

    Here is how to get the script with bpftrace's execsnoop (could also work with iovisor's or libbpf's):

    sudo execsnoop.bt | stdbuf -o0  grep proc/self/fd | awk -W interactive '{system("sudo cat /proc/"$2"/fd/"substr($4, 15)) }'

    (it did not take me 45 minutes to re-discover mawk's -W interactive )

    I could then analyze the script and discovered that a change in behaviour in jq 1.7 was the source of the issue. Minimal reproducer:

    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.6
    ["a","b"]
    > jq --version; printf "a\0b\0" | jq -Rsc 'split("\u0000")'
    jq-1.7
    ["a","b",""]

    (I won't be reporting to jq upstream, because I don't really care about whether or not this is a regression or a fix)

    #eBPF #mdm #ubuntu #jq #awk #bpftrace

  29. I wrote a profiler for process lifecycle events, and you can read about it here: tinkering.xyz/proctrace/

    It's written in #Rust and uses #eBPF under the hood (via #bpftrace). There's a macOS bug that prevents us from using DTrace at the moment. But you can record processes on #Linux and process the recording on macOS.

    The code is at github.com/zmitchell/proctrace and the documentation site is at proctrace.xyz

  30. I wrote a profiler for process lifecycle events, and you can read about it here: tinkering.xyz/proctrace/

    It's written in #Rust and uses #eBPF under the hood (via #bpftrace). There's a macOS bug that prevents us from using DTrace at the moment. But you can record processes on #Linux and process the recording on macOS.

    The code is at github.com/zmitchell/proctrace and the documentation site is at proctrace.xyz

  31. I wrote a profiler for process lifecycle events, and you can read about it here: tinkering.xyz/proctrace/

    It's written in and uses under the hood (via ). There's a macOS bug that prevents us from using DTrace at the moment. But you can record processes on and process the recording on macOS.

    The code is at github.com/zmitchell/proctrace and the documentation site is at proctrace.xyz

  32. I wrote a profiler for process lifecycle events, and you can read about it here: tinkering.xyz/proctrace/

    It's written in #Rust and uses #eBPF under the hood (via #bpftrace). There's a macOS bug that prevents us from using DTrace at the moment. But you can record processes on #Linux and process the recording on macOS.

    The code is at github.com/zmitchell/proctrace and the documentation site is at proctrace.xyz

  33. I wrote a profiler for process lifecycle events, and you can read about it here: tinkering.xyz/proctrace/

    It's written in #Rust and uses #eBPF under the hood (via #bpftrace). There's a macOS bug that prevents us from using DTrace at the moment. But you can record processes on #Linux and process the recording on macOS.

    The code is at github.com/zmitchell/proctrace and the documentation site is at proctrace.xyz

  34. The year is 2024 and bpftrace crashes when there's an extra whitespace.

    bpftrace is DTrace 2.0? DTrace my ass. I've never seen DTrace crash because of an extra whitespace.

    Hell, I've never seen DTrace crash, ever.

    #DTrace #bpftrace #Unix #Linux #sysadmin #illumos

  35. The year is 2024 and bpftrace crashes when there's an extra whitespace.

    bpftrace is DTrace 2.0? DTrace my ass. I've never seen DTrace crash because of an extra whitespace.

    Hell, I've never seen DTrace crash, ever.

    #DTrace #bpftrace #Unix #Linux #sysadmin #illumos

  36. The year is 2024 and bpftrace crashes when there's an extra whitespace.

    bpftrace is DTrace 2.0? DTrace my ass. I've never seen DTrace crash because of an extra whitespace.

    Hell, I've never seen DTrace crash, ever.

    #DTrace #bpftrace #Unix #Linux #sysadmin #illumos

  37. The year is 2024 and bpftrace crashes when there's an extra whitespace.

    bpftrace is DTrace 2.0? DTrace my ass. I've never seen DTrace crash because of an extra whitespace.

    Hell, I've never seen DTrace crash, ever.

    #DTrace #bpftrace #Unix #Linux #sysadmin #illumos

  38. The year is 2024 and bpftrace crashes when there's an extra whitespace.

    bpftrace is DTrace 2.0? DTrace my ass. I've never seen DTrace crash because of an extra whitespace.

    Hell, I've never seen DTrace crash, ever.

    #DTrace #bpftrace #Unix #Linux #sysadmin #illumos

  39. PPAs Updates

    Latest versions of BCC (v0.29.1) and libbpf (v1.3.0) are now available from the bpftrace PPA for bionic, focal and jammy. There's also latest bpftrace (0.19.0) available but only for jammy (I [...]

    🔗 chbk.co/GdMhw

    #ubuntu #bpfcc #bcc #bpftrace #libbpf

  40. PPAs Updates

    Latest versions of BCC (v0.29.1) and libbpf (v1.3.0) are now available from the bpftrace PPA for bionic, focal and jammy. There's also latest bpftrace (0.19.0) available but only for jammy (I [...]

    🔗 chbk.co/GdMhw

  41. PPAs Updates

    Latest versions of BCC (v0.29.1) and libbpf (v1.3.0) are now available from the bpftrace PPA for bionic, focal and jammy. There's also latest bpftrace (0.19.0) available but only for jammy (I [...]

    🔗 chbk.co/GdMhw

    #ubuntu #bpfcc #bcc #bpftrace #libbpf

  42. PPAs Updates

    Latest versions of BCC (v0.29.1) and libbpf (v1.3.0) are now available from the bpftrace PPA for bionic, focal and jammy. There's also latest bpftrace (0.19.0) available but only for jammy (I [...]

    🔗 chbk.co/GdMhw

    #ubuntu #bpfcc #bcc #bpftrace #libbpf

  43. PPAs Updates

    Latest versions of BCC (v0.29.1) and libbpf (v1.3.0) are now available from the bpftrace PPA for bionic, focal and jammy. There's also latest bpftrace (0.19.0) available but only for jammy (I [...]

    🔗 chbk.co/GdMhw

    #ubuntu #bpfcc #bcc #bpftrace #libbpf

  44. New cool example for ebpf_exporter: CFS delay histogram. In addition to knowing overall CFS throttlig delay from cgroups in cpu.state, now you can have a histogram of individual throttling durations in prometheus.

    * github.com/cloudflare/ebpf_exp

    As a bonus, you get a bpftrace command to observe these.

    #ebpf #ebpf_exporter #cgroups #cfs #bpftrace #prometheus

  45. New cool example for ebpf_exporter: CFS delay histogram. In addition to knowing overall CFS throttlig delay from cgroups in cpu.state, now you can have a histogram of individual throttling durations in prometheus.

    * github.com/cloudflare/ebpf_exp

    As a bonus, you get a bpftrace command to observe these.

    #ebpf #ebpf_exporter #cgroups #cfs #bpftrace #prometheus

  46. New cool example for ebpf_exporter: CFS delay histogram. In addition to knowing overall CFS throttlig delay from cgroups in cpu.state, now you can have a histogram of individual throttling durations in prometheus.

    * github.com/cloudflare/ebpf_exp

    As a bonus, you get a bpftrace command to observe these.

    #ebpf #ebpf_exporter #cgroups #cfs #bpftrace #prometheus

  47. New cool example for ebpf_exporter: CFS delay histogram. In addition to knowing overall CFS throttlig delay from cgroups in cpu.state, now you can have a histogram of individual throttling durations in prometheus.

    * github.com/cloudflare/ebpf_exp

    As a bonus, you get a bpftrace command to observe these.

    #ebpf #ebpf_exporter #cgroups #cfs #bpftrace #prometheus

  48. New cool example for ebpf_exporter: CFS delay histogram. In addition to knowing overall CFS throttlig delay from cgroups in cpu.state, now you can have a histogram of individual throttling durations in prometheus.

    * github.com/cloudflare/ebpf_exp

    As a bonus, you get a bpftrace command to observe these.

    #ebpf #ebpf_exporter #cgroups #cfs #bpftrace #prometheus

  49. Today I used #bpftrace on a #Linux system to investigate a performance issue. Really took me back to my days working on #Solaris at Sun Microsystems. I used #dtrace quite a bit at that time, and it's good to see the same good ideas thriving in Linux.

    I worked in #AIX development at #IBM for many years, and I was always a little sad that people didn't use #probevue more. Perhaps this is because AIX has a good system trace infrastructure and the culture grew up using that. Hard to say.

  50. Today I used on a system to investigate a performance issue. Really took me back to my days working on at Sun Microsystems. I used quite a bit at that time, and it's good to see the same good ideas thriving in Linux.

    I worked in development at for many years, and I was always a little sad that people didn't use more. Perhaps this is because AIX has a good system trace infrastructure and the culture grew up using that. Hard to say.

  51. Today I used #bpftrace on a #Linux system to investigate a performance issue. Really took me back to my days working on #Solaris at Sun Microsystems. I used #dtrace quite a bit at that time, and it's good to see the same good ideas thriving in Linux.

    I worked in #AIX development at #IBM for many years, and I was always a little sad that people didn't use #probevue more. Perhaps this is because AIX has a good system trace infrastructure and the culture grew up using that. Hard to say.