1*1031c584SApple OSS DistributionsKernel Data Descriptors 2*1031c584SApple OSS Distributions======================= 3*1031c584SApple OSS Distributions 4*1031c584SApple OSS DistributionsThis project allows for dynamic data to be passed from the kernel to userspace tools without binding them to particular version of 5*1031c584SApple OSS Distributionsstruct definition. The `libkdd` library provides convenient API for parsing and interpreting `kernel chunked data`. 6*1031c584SApple OSS Distributions 7*1031c584SApple OSS DistributionsThe libkdd APIs are defined in [kdd.h](./kdd.h) 8*1031c584SApple OSS Distributions 9*1031c584SApple OSS DistributionsThe `KCDATA` format 10*1031c584SApple OSS Distributions=================== 11*1031c584SApple OSS Distributions 12*1031c584SApple OSS DistributionsThe format for data is setup in a generic format as follows 13*1031c584SApple OSS Distributions 14*1031c584SApple OSS DistributionsLayout of data structure 15*1031c584SApple OSS Distributions------------------------ 16*1031c584SApple OSS Distributions 17*1031c584SApple OSS Distributions | 8 - bytes | 18*1031c584SApple OSS Distributions |---------------------------| ------ offset = 00 19*1031c584SApple OSS Distributions | type = MAGIC | LENGTH | # BEGIN Header 20*1031c584SApple OSS Distributions | 0 | 21*1031c584SApple OSS Distributions |---------------------------| ------ offset = 16 22*1031c584SApple OSS Distributions | type | size | # chunk header 23*1031c584SApple OSS Distributions | flags | 24*1031c584SApple OSS Distributions |---------------------------| ------ offset = 32 25*1031c584SApple OSS Distributions | data | # arbitrary data (len=16) 26*1031c584SApple OSS Distributions |___________data____________| 27*1031c584SApple OSS Distributions |---------------------------| ------ offset = 48 28*1031c584SApple OSS Distributions | type | size | # chunk header 29*1031c584SApple OSS Distributions | flags | 30*1031c584SApple OSS Distributions |---------------------------| ------ offset = 64 31*1031c584SApple OSS Distributions | data | # arbitrary data (len=32) 32*1031c584SApple OSS Distributions | data | 33*1031c584SApple OSS Distributions | data | 34*1031c584SApple OSS Distributions |___________data____________| 35*1031c584SApple OSS Distributions |---------------------------| ------ offset = 96 36*1031c584SApple OSS Distributions | type = END | size=0 | # chunk header 37*1031c584SApple OSS Distributions | 0 | 38*1031c584SApple OSS Distributions 39*1031c584SApple OSS Distributions 40*1031c584SApple OSS DistributionsThe type field describes what kind of data is passed. For example type = `TASK_CRASHINFO_UUID` means the following data is a uuid. 41*1031c584SApple OSS DistributionsThese types need to be defined in task_corpses.h for easy consumption by userspace inspection tools. 42*1031c584SApple OSS Distributions 43*1031c584SApple OSS DistributionsSome range of types is reserved for special types like ints, longs etc. A cool new functionality made possible with this 44*1031c584SApple OSS Distributionsextensible data format is that kernel can decide to put more information as required without requiring user space tools to 45*1031c584SApple OSS Distributionsre-compile to be compatible. The case of `rusage` struct versions could be introduced without breaking existing tools. 46*1031c584SApple OSS Distributions 47*1031c584SApple OSS DistributionsFeature description: Generic data with description 48*1031c584SApple OSS Distributions------------------- 49*1031c584SApple OSS DistributionsFurther more generic data with description is very much possible now. For example 50*1031c584SApple OSS Distributions 51*1031c584SApple OSS Distributions - kcdata_add_uint64_with_description(cdatainfo, 0x700, "NUM MACH PORTS"); 52*1031c584SApple OSS Distributions - and more functions that allow adding description. 53*1031c584SApple OSS Distributions 54*1031c584SApple OSS DistributionsThe userspace tools can then look at the description and print the data even if they are not compiled with knowledge of the field apriori. 55*1031c584SApple OSS Distributions 56*1031c584SApple OSS Distributions Example data: 57*1031c584SApple OSS Distributions 0000 57 f1 ad de 00 00 00 00 00 00 00 00 00 00 00 00 W............... 58*1031c584SApple OSS Distributions 0010 01 00 00 00 00 00 00 00 30 00 00 00 00 00 00 00 ........0....... 59*1031c584SApple OSS Distributions 0020 50 49 44 00 00 00 00 00 00 00 00 00 00 00 00 00 PID............. 60*1031c584SApple OSS Distributions 0030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 61*1031c584SApple OSS Distributions 0040 9c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 62*1031c584SApple OSS Distributions 0050 01 00 00 00 00 00 00 00 30 00 00 00 00 00 00 00 ........0....... 63*1031c584SApple OSS Distributions 0060 50 41 52 45 4e 54 20 50 49 44 00 00 00 00 00 00 PARENT PID...... 64*1031c584SApple OSS Distributions 0070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 65*1031c584SApple OSS Distributions 0080 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 66*1031c584SApple OSS Distributions 0090 ed 58 91 f1 67*1031c584SApple OSS Distributions 68*1031c584SApple OSS Distributions 69*1031c584SApple OSS DistributionsFeature description: Container markers for compound data 70*1031c584SApple OSS Distributions------------------ 71*1031c584SApple OSS Distributions 72*1031c584SApple OSS DistributionsIf a given kernel data type is complex and requires adding multiple optional fields inside a container 73*1031c584SApple OSS Distributionsobject for a consumer to understand arbitrary data, we package it using container markers. 74*1031c584SApple OSS Distributions 75*1031c584SApple OSS DistributionsFor example, the stackshot code gathers information and describes the state of a given task with respect 76*1031c584SApple OSS Distributionsto many subsystems. It includes data such as io stats, vm counters, process names/flags and syscall counts. 77*1031c584SApple OSS Distributions 78*1031c584SApple OSS Distributions kcdata_add_container_marker(kcdata_p, KCDATA_TYPE_CONTAINER_BEGIN, STACKSHOT_KCCONTAINER_TASK, task_uniqueid); 79*1031c584SApple OSS Distributions // add multiple data, or add_<type>_with_description()s here 80*1031c584SApple OSS Distributions 81*1031c584SApple OSS Distributions kcdata_add_container_marker(kcdata_p, KCDATA_TYPE_CONTAINER_END, STACKSHOT_KCCONTAINER_TASK, task_uniqueid); 82*1031c584SApple OSS Distributions 83*1031c584SApple OSS Distributions 84*1031c584SApple OSS DistributionsFeature description: Custom Data formats on demand 85*1031c584SApple OSS Distributions-------------------- 86*1031c584SApple OSS Distributions 87*1031c584SApple OSS DistributionsWith the self describing nature of format, the kernel provider can describe a data type (uniquely identified by a number) and use 88*1031c584SApple OSS Distributionsit in the buffer for sending data. The consumer can parse the type information and have knowledge of describing incoming data. 89*1031c584SApple OSS DistributionsFollowing is an example of how we can describe a kernel specific struct sample_disk_io_stats in buffer. 90*1031c584SApple OSS Distributions 91*1031c584SApple OSS Distributions struct sample_disk_io_stats { 92*1031c584SApple OSS Distributions uint64_t disk_reads_count; 93*1031c584SApple OSS Distributions uint64_t disk_reads_size; 94*1031c584SApple OSS Distributions uint64_t io_priority_count[4]; 95*1031c584SApple OSS Distributions uint64_t io_priority_size; 96*1031c584SApple OSS Distributions } __attribute__ ((packed)); 97*1031c584SApple OSS Distributions 98*1031c584SApple OSS Distributions 99*1031c584SApple OSS Distributions struct kcdata_subtype_descriptor disk_io_stats_def[] = { 100*1031c584SApple OSS Distributions {KCS_SUBTYPE_FLAGS_NONE, KC_ST_UINT64, 0 * sizeof(uint64_t), sizeof(uint64_t), "disk_reads_count"}, 101*1031c584SApple OSS Distributions {KCS_SUBTYPE_FLAGS_NONE, KC_ST_UINT64, 1 * sizeof(uint64_t), sizeof(uint64_t), "disk_reads_size"}, 102*1031c584SApple OSS Distributions {KCS_SUBTYPE_FLAGS_ARRAY, KC_ST_UINT64, 2 * sizeof(uint64_t), KCS_SUBTYPE_PACK_SIZE(4, sizeof(uint64_t)), "io_priority_count"}, 103*1031c584SApple OSS Distributions {KCS_SUBTYPE_FLAGS_ARRAY, KC_ST_UINT64, (2 + 4) * sizeof(uint64_t), sizeof(uint64_t), "io_priority_size"}, 104*1031c584SApple OSS Distributions }; 105*1031c584SApple OSS Distributions 106*1031c584SApple OSS DistributionsNow you can add this custom type definition into the buffer as 107*1031c584SApple OSS Distributions kcdata_add_type_definition(kcdata_p, KCTYPE_SAMPLE_DISK_IO_STATS, "sample_disk_io_stats", 108*1031c584SApple OSS Distributions &disk_io_stats_def[0], sizeof(disk_io_stats_def)/sizeof(struct kcdata_subtype_descriptor)); 109*1031c584SApple OSS Distributions 110