A thorough introduction to bpftrace
brendangregg.com
brendangregg.com
I wanted to print a debug log as it was being saved in a kernel module - that's fine, the module has an equivalent of save_log(char* foo), just probe on entrance and print that, right?
...except bpftrace has a hard cap of 200-odd bytes for getting char *s out with str() at a time. [1]
Fine, so you just do some pointer math and print foo, foo+200, etc, right?
No strlen, no printf return value, so you don't know where the end of the string is.
At that point, I said "sod it" and broke out systemtap.
It's possible that in the future strace will use BPF as well to lower its overhead.
bpftrace is also more versatile. You could use it to e.g. collect stack traces for all the syscalls a program makes. You can also attach actions to more things than just syscalls. You can e.g. use kprobes to inject code into kernel functions which aren't exported as syscalls.
strace will tell you it failed, but bpftrace can help understand why.
Note that I said "help": bpftrace can tell you "this function failed with EPERM", but e.g. ovl_fill_super() can fill with EPERM for lots of different reasons. So it's a bit like printf debugging. And you're SOL if the error is generated within that function or from an inlined function :(
strace requires less than 2 MB
Bigger is better :)
apt install bpftrace: needs 1,201 kB
apt remove strace: frees 1,792 kB
For example, is clang already installed
45MB is still huge; its not even statically-linked
The largest programs I use, even when statically-linked against musl are all under 6MB