Show HN: bpfquery – experimenting with compiling SQL to bpf(trace)
bpfquery.com
bpfquery.com
note you don't need the casts if you use kfuncs instead, which also let you reference arguments by name (from https://github.com/bpftrace/bpftrace/blob/master/man/adoc/bp... ):
kfunc:tcp_connect {
if (args->sk->__sk_common.skc_daddr == (uint32)pton("127.0.0.1"))
...
}
With that said, kfuncs don't work (yet?) on aarch64, so this is great for me -- I'll definitely give it a try next time I need it.(EDIT: formatting)
Also, you might also enjoy https://github.com/zmaril/hancock which is some of the code I've been using to run ctags across the versions of the kernel.
(edit: I checked bpftrace -l and saw that it does have the arguments and type structs ahead of time, which is absolutely perfect, thank you very much! Super helpful.)
bpftrace -lv kfunc:*
(or any specific function instead of wildcard) will get you all kfuncs and their respective arguments.output snippet:
kfunc:vmlinux:tcp_conn_request
struct request_sock_ops * rsk_ops
const struct tcp_request_sock_ops * af_ops
struct sock * sk
struct sk_buff * skb
int retval
kfunc:vmlinux:tcp_connect
struct sock * sk
int retval
kfunc:vmlinux:tcp_create_openreq_child
const struct sock * sk
struct request_sock * req
struct sk_buff * skb
struct sock * retval
I'm not sure how to get this info without bpftrace itself - bpftool might have the info available somehow?I'm on Firefox Mobile on Android and the first time I visited the page the 3rd/data section just kept refreshing continuously rather than showing results (maybe showed results the first load, but then refreshes of just rows with a dash?). On the second visit to the page the 2nd/C translation section failed to load.
And I will endeavor to fix those bugs. I put the web interface on over the last few days and when it works it is great, but often times, it does not work. Thank you for looking at it!
It looks like the issues I reported earlier have been resolved, though the second time it took a while to load (hopefully due to all the traffic!).
There are many open query planners; maybe most are hardly reusable.
There's a wasm-bpf; and also duckdb-wasm, sqlite in WASM with replication and synchronization, datasette-lite, JupyterLite
wasm-bpf: https://github.com/eunomia-bpf/wasm-bpf#how-it-works
Does this make databases faster or more efficient? Is there process or query isolation?