1*4f1223e8SApple OSS DistributionsKernel Data Descriptors 2*4f1223e8SApple OSS Distributions======================= 3*4f1223e8SApple OSS Distributions 4*4f1223e8SApple OSS DistributionsThis project allows for dynamic data to be passed from the kernel to userspace tools without binding them to particular version of 5*4f1223e8SApple OSS Distributionsstruct definition. The `libkdd` library provides convenient API for parsing and interpreting `kernel chunked data`. 6*4f1223e8SApple OSS Distributions 7*4f1223e8SApple OSS DistributionsThe libkdd APIs are defined in [kdd.h](./kdd.h) 8*4f1223e8SApple OSS Distributions 9*4f1223e8SApple OSS DistributionsThe `KCDATA` format 10*4f1223e8SApple OSS Distributions=================== 11*4f1223e8SApple OSS Distributions 12*4f1223e8SApple OSS DistributionsThe format for data is setup in a generic format as follows 13*4f1223e8SApple OSS Distributions 14*4f1223e8SApple OSS DistributionsLayout of data structure 15*4f1223e8SApple OSS Distributions------------------------ 16*4f1223e8SApple OSS Distributions 17*4f1223e8SApple OSS Distributions | 8 - bytes | 18*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 00 19*4f1223e8SApple OSS Distributions | type = MAGIC | LENGTH | # BEGIN Header 20*4f1223e8SApple OSS Distributions | 0 | 21*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 16 22*4f1223e8SApple OSS Distributions | type | size | # chunk header 23*4f1223e8SApple OSS Distributions | flags | 24*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 32 25*4f1223e8SApple OSS Distributions | data | # arbitrary data (len=16) 26*4f1223e8SApple OSS Distributions |___________data____________| 27*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 48 28*4f1223e8SApple OSS Distributions | type | size | # chunk header 29*4f1223e8SApple OSS Distributions | flags | 30*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 64 31*4f1223e8SApple OSS Distributions | data | # arbitrary data (len=32) 32*4f1223e8SApple OSS Distributions | data | 33*4f1223e8SApple OSS Distributions | data | 34*4f1223e8SApple OSS Distributions |___________data____________| 35*4f1223e8SApple OSS Distributions |---------------------------| ------ offset = 96 36*4f1223e8SApple OSS Distributions | type = END | size=0 | # chunk header 37*4f1223e8SApple OSS Distributions | 0 | 38*4f1223e8SApple OSS Distributions 39*4f1223e8SApple OSS Distributions 40*4f1223e8SApple OSS DistributionsThe type field describes what kind of data is passed. For example type = `TASK_CRASHINFO_UUID` means the following data is a uuid. 41*4f1223e8SApple OSS DistributionsThese types need to be defined in task_corpses.h for easy consumption by userspace inspection tools. 42*4f1223e8SApple OSS Distributions 43*4f1223e8SApple OSS DistributionsSome range of types is reserved for special types like ints, longs etc. A cool new functionality made possible with this 44*4f1223e8SApple OSS Distributionsextensible data format is that kernel can decide to put more information as required without requiring user space tools to 45*4f1223e8SApple OSS Distributionsre-compile to be compatible. The case of `rusage` struct versions could be introduced without breaking existing tools. 46*4f1223e8SApple OSS Distributions 47*4f1223e8SApple OSS DistributionsFeature description: Generic data with description 48*4f1223e8SApple OSS Distributions------------------- 49*4f1223e8SApple OSS DistributionsFurther more generic data with description is very much possible now. For example 50*4f1223e8SApple OSS Distributions 51*4f1223e8SApple OSS Distributions - kcdata_add_uint64_with_description(cdatainfo, 0x700, "NUM MACH PORTS"); 52*4f1223e8SApple OSS Distributions - and more functions that allow adding description. 53*4f1223e8SApple OSS Distributions 54*4f1223e8SApple OSS DistributionsThe userspace tools can then look at the description and print the data even if they are not compiled with knowledge of the field apriori. 55*4f1223e8SApple OSS Distributions 56*4f1223e8SApple OSS Distributions Example data: 57*4f1223e8SApple OSS Distributions 0000 57 f1 ad de 00 00 00 00 00 00 00 00 00 00 00 00 W............... 58*4f1223e8SApple OSS Distributions 0010 01 00 00 00 00 00 00 00 30 00 00 00 00 00 00 00 ........0....... 59*4f1223e8SApple OSS Distributions 0020 50 49 44 00 00 00 00 00 00 00 00 00 00 00 00 00 PID............. 60*4f1223e8SApple OSS Distributions 0030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 61*4f1223e8SApple OSS Distributions 0040 9c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 62*4f1223e8SApple OSS Distributions 0050 01 00 00 00 00 00 00 00 30 00 00 00 00 00 00 00 ........0....... 63*4f1223e8SApple OSS Distributions 0060 50 41 52 45 4e 54 20 50 49 44 00 00 00 00 00 00 PARENT PID...... 64*4f1223e8SApple OSS Distributions 0070 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 65*4f1223e8SApple OSS Distributions 0080 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 66*4f1223e8SApple OSS Distributions 0090 ed 58 91 f1 67*4f1223e8SApple OSS Distributions 68*4f1223e8SApple OSS Distributions 69*4f1223e8SApple OSS DistributionsFeature description: Container markers for compound data 70*4f1223e8SApple OSS Distributions------------------ 71*4f1223e8SApple OSS Distributions 72*4f1223e8SApple OSS DistributionsIf a given kernel data type is complex and requires adding multiple optional fields inside a container 73*4f1223e8SApple OSS Distributionsobject for a consumer to understand arbitrary data, we package it using container markers. 74*4f1223e8SApple OSS Distributions 75*4f1223e8SApple OSS DistributionsFor example, the stackshot code gathers information and describes the state of a given task with respect 76*4f1223e8SApple OSS Distributionsto many subsystems. It includes data such as io stats, vm counters, process names/flags and syscall counts. 77*4f1223e8SApple OSS Distributions 78*4f1223e8SApple OSS Distributions kcdata_add_container_marker(kcdata_p, KCDATA_TYPE_CONTAINER_BEGIN, STACKSHOT_KCCONTAINER_TASK, task_uniqueid); 79*4f1223e8SApple OSS Distributions // add multiple data, or add_<type>_with_description()s here 80*4f1223e8SApple OSS Distributions 81*4f1223e8SApple OSS Distributions kcdata_add_container_marker(kcdata_p, KCDATA_TYPE_CONTAINER_END, STACKSHOT_KCCONTAINER_TASK, task_uniqueid); 82*4f1223e8SApple OSS Distributions 83*4f1223e8SApple OSS Distributions 84*4f1223e8SApple OSS DistributionsFeature description: Custom Data formats on demand 85*4f1223e8SApple OSS Distributions-------------------- 86*4f1223e8SApple OSS Distributions 87*4f1223e8SApple OSS DistributionsWith the self describing nature of format, the kernel provider can describe a data type (uniquely identified by a number) and use 88*4f1223e8SApple OSS Distributionsit in the buffer for sending data. The consumer can parse the type information and have knowledge of describing incoming data. 89*4f1223e8SApple OSS DistributionsFollowing is an example of how we can describe a kernel specific struct sample_disk_io_stats in buffer. 90*4f1223e8SApple OSS Distributions 91*4f1223e8SApple OSS Distributions struct sample_disk_io_stats { 92*4f1223e8SApple OSS Distributions uint64_t disk_reads_count; 93*4f1223e8SApple OSS Distributions uint64_t disk_reads_size; 94*4f1223e8SApple OSS Distributions uint64_t io_priority_count[4]; 95*4f1223e8SApple OSS Distributions uint64_t io_priority_size; 96*4f1223e8SApple OSS Distributions } __attribute__ ((packed)); 97*4f1223e8SApple OSS Distributions 98*4f1223e8SApple OSS Distributions 99*4f1223e8SApple OSS Distributions struct kcdata_subtype_descriptor disk_io_stats_def[] = { 100*4f1223e8SApple OSS Distributions {KCS_SUBTYPE_FLAGS_NONE, KC_ST_UINT64, 0 * sizeof(uint64_t), sizeof(uint64_t), "disk_reads_count"}, 101*4f1223e8SApple OSS Distributions {KCS_SUBTYPE_FLAGS_NONE, KC_ST_UINT64, 1 * sizeof(uint64_t), sizeof(uint64_t), "disk_reads_size"}, 102*4f1223e8SApple OSS Distributions {KCS_SUBTYPE_FLAGS_ARRAY, KC_ST_UINT64, 2 * sizeof(uint64_t), KCS_SUBTYPE_PACK_SIZE(4, sizeof(uint64_t)), "io_priority_count"}, 103*4f1223e8SApple OSS Distributions {KCS_SUBTYPE_FLAGS_ARRAY, KC_ST_UINT64, (2 + 4) * sizeof(uint64_t), sizeof(uint64_t), "io_priority_size"}, 104*4f1223e8SApple OSS Distributions }; 105*4f1223e8SApple OSS Distributions 106*4f1223e8SApple OSS DistributionsNow you can add this custom type definition into the buffer as 107*4f1223e8SApple OSS Distributions kcdata_add_type_definition(kcdata_p, KCTYPE_SAMPLE_DISK_IO_STATS, "sample_disk_io_stats", 108*4f1223e8SApple OSS Distributions &disk_io_stats_def[0], sizeof(disk_io_stats_def)/sizeof(struct kcdata_subtype_descriptor)); 109*4f1223e8SApple OSS Distributions 110