git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v5] tr2: log parent process name

From
Emily Shaffer <emilyshaffer@google.com>
Date
Jun 29, 2021, 23:51 UTC
Message-ID
<YNux62he9Mk43Y1B@google.com>
In-Reply-To
<3327f108-6cd1-1d3d-eae9-2cdff96e1375@jeffhostetler.com>
On Mon, Jun 28, 2021 at 12:45:24PM -0400, Jeff Hostetler wrote:
Show 14 quoted lines
> On 6/8/21 6:10 PM, Emily Shaffer wrote:
> > Range-diff against v4:
> > 1:  efb0a3ccb4 ! 1:  7a7e1ebbfa tr2: log parent process name
> >      @@ compat/procinfo.c (new)
> >       +	strbuf_addf(&procfs_path, "/proc/%d/comm", getppid());
> >       +	if (strbuf_read_file(&name, procfs_path.buf, 0)) {
> >       +		strbuf_release(&procfs_path);
> >      ++		strbuf_trim_trailing_newline(&name);
> >       +		strvec_push(names, strbuf_detach(&name, NULL));
> >       +	}
> >       +
> 
> You're only getting the name of the command (argv[0]) and not the
> full command line, right?  That is a good thing.

Roughly. The name can be reset by the process itself (that's what happened, I guess, in the tmux case I pasted below) but by default it's argv[0]. It's also truncated to 15ch or something.

Show 15 quoted lines
> >   ------------
> > +`"cmd_ancestry"`::
> > +	This event contains the text command name for the parent (and earlier
> > +	generations of parents) of the current process, in an array ordered from
> > +	nearest parent to furthest great-grandparent. It may not be implemented
> > +	on all platforms.
> > ++
> > +------------
> > +{
> > +	"event":"cmd_ancestry",
> > +	...
> > +	"ancestry":["bash","tmux: server","systemd"]
> 
> Is the second element really "tmux: server".  Seems odd that that's what
> the command name (argv[0]) is.  Perhaps I misread something??

See above. This is what shows up in pstree, though, and by poking around in /proc I confirmed that this is indeed the content of /proc/<tmux-pid>/comm:

        ├─tmux: server─┬─bash───mutt───open-vim-in-new───vim
        │              ├─bash───pstree
        │              └─mutt

This is a somewhat contrived example, though, because in Linux as of this patch, only one ancestor is gathered. So maybe I had better make the doc reflect what's actually possible. I'm planning on sending a follow-on sometime soon exposing more generations of ancestry, so I guess I could update the docs back to this state around then.

Show 6 quoted lines
> 
> > +}
> 
> This array is bounded and that implies that you captured all of
> the grand parents back to "init" (or whatever it is called these
> days).

In this case it does - pid 1 is systemd, which hasn't got a parent process.

> Is there value in having a final "..." or "(truncated)" element
> to indicate that the list incomplete?  I did the latter in the
> Windows version.

Hrm. I'm not the one who wants to parse these - it's someone else who's working with our team internally - so I'll ask around and see what they think is best.

Show 36 quoted lines
> > +#ifdef HAVE_PROCFS_LINUX
> > +	/*
> > +	 * NEEDSWORK: We could gather the entire pstree into an array to match
> > +	 * functionality with compat/win32/trace2_win32_process_info.c.
> > +	 * To do so, we may want to examine /proc/<pid>/stat. For now, just
> > +	 * gather the immediate parent name which is readily accessible from
> > +	 * /proc/$(getppid())/comm.
> > +	 */
> > +	struct strbuf procfs_path = STRBUF_INIT;
> > +	struct strbuf name = STRBUF_INIT;
> > +
> > +	/* try to use procfs if it's present. */
> > +	strbuf_addf(&procfs_path, "/proc/%d/comm", getppid());
> > +	if (strbuf_read_file(&name, procfs_path.buf, 0)) {
> > +		strbuf_release(&procfs_path);
> > +		strbuf_trim_trailing_newline(&name);
> > +		strvec_push(names, strbuf_detach(&name, NULL));
> > +	}
> > +
> > +	return;
> > +#endif
> > +	/* NEEDSWORK: add non-procfs-linux implementations here */
> > +}
> 
> Perhaps this has already been discussed, but would it be better
> to have a "compat/linux/trace2_linux_process_info.c"
> or "compat/procfs/trace2_procfs_process_info.c" source file and
> only compile it in Linux-compatible builds -- rather than #ifdef'ing
> the source.  This is a highly platform-specific feature.
> 
> For example, if I convert the Win32 version to use your new event,
> I wouldn't want to move the code.
> 
> I just noticed that you have both "BASIC_CFLAGS+=" and a "COMPAT_OBSJ+="
> lines.  If you made this source file procfs-specific, you wouldn't need
> the ifdef and you could avoid the new CFLAG.
Sure, I'll investigate it, thanks.
Show 17 quoted lines
> > +
> > +		if (names.nr == 0) {
> > +			strvec_clear(&names);
> > +			return;
> > +		}
> > +
> > +		trace2_cmd_ancestry(names.v);
> > +
> > +		strvec_clear(&names);
> 
> I agree with Junio here, it would be simpler to say it like this:
> 
> 		get_ancestry_names(&names);
> 		if (names.nr)
> 			trace2_cmd_ancestry(names.v);
> 		strvec_clear(&names);
> 
Thanks both, done locally.
> Otherwise, this looks good to me.

Thanks. Look for a v6 from me this week, hopefully with the build stuff sorted out.

 - Emily
Previous: Jeff HostetlerNext: Ævar Arnfjörð Bjarmason
Message 38 of 87 in “tr2: log parent process name”
  1. tr2: log parent process nameEmily Shaffer, May 7, 2021
  2. Bagas SanjayaMay 7, 2021
  3. Emily ShafferMay 7, 2021
  4. Ævar Arnfjörð BjarmasonMay 10, 2021
  5. Junio C HamanoMay 11, 2021
  6. Emily ShafferMay 14, 2021
  7. Junio C HamanoMay 16, 2021
  8. Emily ShafferMay 17, 2021
  9. Jeff HostetlerMay 11, 2021
  10. Emily ShafferMay 14, 2021
  11. tr2: log parent process nameEmily Shaffer, May 20, 2021
  12. Randall S. BeckerMay 20, 2021
  13. Emily ShafferMay 20, 2021
  14. Randall S. BeckerMay 21, 2021
  15. Randall S. BeckerMay 21, 2021
  16. Junio C HamanoMay 21, 2021
  17. Emily ShafferMay 21, 2021
  18. Junio C HamanoMay 21, 2021
  19. Emily ShafferMay 24, 2021
  20. Jeff HostetlerMay 21, 2021
  21. Emily ShafferMay 21, 2021
  22. Randall S. BeckerMay 21, 2021
  23. Jeff HostetlerMay 22, 2021
  24. Ævar Arnfjörð BjarmasonMay 24, 2021
  25. tr2: log parent process nameEmily Shaffer, May 24, 2021
  26. Emily ShafferMay 24, 2021
  27. Junio C HamanoMay 25, 2021
  28. Randall S. BeckerMay 25, 2021
  29. tr2: log parent process nameEmily Shaffer, Jun 8, 2021
  30. Emily ShafferJun 8, 2021
  31. tr2: log parent process nameEmily Shaffer, Jun 8, 2021
  32. Randall S. BeckerJun 8, 2021
  33. Emily ShafferJun 8, 2021
  34. Randall S. BeckerJun 8, 2021
  35. Emily ShafferJun 9, 2021
  36. Junio C HamanoJun 16, 2021
  37. Jeff HostetlerJun 28, 2021
  38. Emily ShafferJun 29, 2021
  39. Ævar Arnfjörð BjarmasonJun 30, 2021
  40. Emily ShafferJul 22, 2021
  41. 0/2 tr2: log parent process nameEmily Shaffer, Jul 22, 2021
  42. 1/2 tr2: make process info collection platform-genericEmily Shaffer, Jul 22, 2021
  43. Ævar Arnfjörð BjarmasonAug 2, 2021
  44. 2/2 tr2: log parent process nameEmily Shaffer, Jul 22, 2021
  45. Junio C HamanoJul 22, 2021
  46. Ævar Arnfjörð BjarmasonAug 2, 2021
  47. Ævar Arnfjörð BjarmasonAug 2, 2021
  48. Ævar Arnfjörð BjarmasonAug 2, 2021
  49. Ævar Arnfjörð BjarmasonAug 2, 2021
  50. Jeff HostetlerAug 2, 2021
  51. Randall S. BeckerAug 2, 2021
  52. Ævar Arnfjörð BjarmasonAug 2, 2021
  53. 0/6 tr2: plug memory leaks + logic errors + Win32 & Linux feature parityÆvar Arnfjörð Bjarmason, Aug 25, 2021
  54. 1/6 tr2: remove NEEDSWORK comment for "non-procfs" implementationsÆvar Arnfjörð Bjarmason, Aug 25, 2021
  55. 2/6 tr2: clarify TRACE2_PROCESS_INFO_EXIT comment under LinuxÆvar Arnfjörð Bjarmason, Aug 25, 2021
  56. 3/6 tr2: stop leaking "thread_name" memoryÆvar Arnfjörð Bjarmason, Aug 25, 2021
  57. Taylor BlauAug 26, 2021
  58. 4/6 tr2: fix memory leak & logic error in 2f732bf15e6Ævar Arnfjörð Bjarmason, Aug 25, 2021
  59. Taylor BlauAug 26, 2021
  60. 5/6 tr2: do compiler enum check in trace2_collect_process_info()Ævar Arnfjörð Bjarmason, Aug 25, 2021
  61. Taylor BlauAug 26, 2021
  62. 6/6 tr2: log N parent process names on LinuxÆvar Arnfjörð Bjarmason, Aug 25, 2021
  63. Eric SunshineAug 25, 2021
  64. Taylor BlauAug 26, 2021
  65. "I don't know what the author meant by that..." (was "Re: [PATCH 6/6] tr2: log N parent process names on Linux")Ævar Arnfjörð Bjarmason, Aug 26, 2021
  66. 0/6 tr2: plug memory leaks + logic errors + Win32 & Linux feature parityÆvar Arnfjörð Bjarmason, Aug 26, 2021
  67. 1/6 tr2: remove NEEDSWORK comment for "non-procfs" implementationsÆvar Arnfjörð Bjarmason, Aug 26, 2021
  68. 2/6 tr2: clarify TRACE2_PROCESS_INFO_EXIT comment under LinuxÆvar Arnfjörð Bjarmason, Aug 26, 2021
  69. 3/6 tr2: stop leaking "thread_name" memoryÆvar Arnfjörð Bjarmason, Aug 26, 2021
  70. 5/6 tr2: do compiler enum check in trace2_collect_process_info()Ævar Arnfjörð Bjarmason, Aug 26, 2021
  71. 4/6 tr2: fix memory leak & logic error in 2f732bf15e6Ævar Arnfjörð Bjarmason, Aug 26, 2021
  72. Eric SunshineAug 26, 2021
  73. Junio C HamanoAug 26, 2021
  74. 6/6 tr2: log N parent process names on LinuxÆvar Arnfjörð Bjarmason, Aug 26, 2021
  75. Taylor BlauAug 26, 2021
  76. 0/6 tr2: plug memory leaks + logic errors + Win32 & Linux feature parityÆvar Arnfjörð Bjarmason, Aug 27, 2021
  77. 2/6 tr2: clarify TRACE2_PROCESS_INFO_EXIT comment under LinuxÆvar Arnfjörð Bjarmason, Aug 27, 2021
  78. 1/6 tr2: remove NEEDSWORK comment for "non-procfs" implementationsÆvar Arnfjörð Bjarmason, Aug 27, 2021
  79. 3/6 tr2: stop leaking "thread_name" memoryÆvar Arnfjörð Bjarmason, Aug 27, 2021
  80. 6/6 tr2: log N parent process names on LinuxÆvar Arnfjörð Bjarmason, Aug 27, 2021
  81. 4/6 tr2: leave the parent list empty upon failure & don't leak memoryÆvar Arnfjörð Bjarmason, Aug 27, 2021
  82. 5/6 tr2: do compiler enum check in trace2_collect_process_info()Ævar Arnfjörð Bjarmason, Aug 27, 2021
  83. Taylor BlauAug 31, 2021
  84. Ævar Arnfjörð BjarmasonAug 2, 2021
  85. Junio C HamanoAug 2, 2021
  86. Ævar Arnfjörð BjarmasonAug 2, 2021
  87. Jeff HostetlerJul 22, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.