Skip to content

feat(ktrace): recorded scheduler, syscall and page fault events and streamed sessions into a file - #348

Merged
FlareCoding merged 9 commits into
masterfrom
pr/ktrace-sched-switch
Oct 8, 2026
Merged

FlareCoding merged 9 commits into
masterfrom
pr/ktrace-sched-switch

Conversation

@FlareCoding

@FlareCoding FlareCoding commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • ktrace sessions recorded no events, and rings of a fixed size could only hold the last few seconds of a busy system, so a long session lost its start.
  • Sessions record context switches, wakeups, syscalls and page faults, and each session chooses which of these event ids it records.
  • A userland recorder streams each session into a file while it records, through ktrace start -o FILE or ktrace record -o FILE in place of ktrace dump. The ring size then bounds only how far the recorder may fall behind, not how long a session runs, and the file counts any records a full ring dropped.

Note

Medium Risk
Adds optional hot-path tracing on every context switch, wakeup, syscall, and user page fault, and replaces ktrace I/O with a concurrent ring-drain/streaming model where reader/session lifecycle bugs could drop or mis-order data.

Overview
ktrace moves from post-stop snapshot dumps to live streaming while a session records: /dev/ktrace/trace must be open first, only one reader is allowed, and closing the reader stops the session. The on-disk layout switches from a CPU table to chunked records (CHUNK_RECORDS / CHUNK_END), with an event_mask in the file header and per-chunk lost counts when rings fill before the reader drains them.

Sessions now take start(uint64_t event_mask); control start records all events. Rings track drained vs head so full buffers drop new events instead of wrapping silently. Status reports records/lost per CPU and bytes_streamed.

Kernel instrumentation (when the matching bit is set): scheduler context switches (with reason), wakeups, syscall duration/result (excluding SYS_ELEVATE), and user page-fault handling time/result. Helpers live in ktrace_events.{h,cpp} with is_recording() fast paths.

Userland ktrace replaces dump with record -o FILE (open trace → start → stream) and start -o FILE (detached recorder via proc_create). fs::ERR_PIPE surfaces start-without-reader; file provider maps ERR_INTR / ERR_PIPE.

Kernel tests were rewritten around the streaming protocol, masks, ring loss, and reader lifecycle.

Reviewed by Cursor Bugbot for commit e8abe5d. Bugbot is set up for automated code reviews on this repo. Configure here.

cursor[bot]

This comment was marked as resolved.

@FlareCoding
FlareCoding merged commit ecb2c2c into master Oct 8, 2026
10 checks passed
@FlareCoding
FlareCoding deleted the pr/ktrace-sched-switch branch October 8, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant