intel® processor trace - mad) workshop · 2016. 3. 22. · intel® processor trace what it is and...

15
Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Upload: others

Post on 19-Jan-2021

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Intel® Processor Trace What it is and how to decode it

Markus Metzger, Intel GmbH

Page 2: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace What is it? How can I use it?

• New h/w feature for execution tracing

• Compact trace format

• Low trace collection overhead

• Trace contains time stamps

• Usage models:

• Crash debug: how did I get here?

• Analysis: provide context around samples

• Latency debug: what was the code doing around time X?

2

Page 3: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace H/W and S/W components

Ring0 Agent (OS, BIOS)

Intel® PT

decoder

IA

CPU 1..n

HW creates Intel®

PT packet log per

LP

Intel® PT-

enabled

tools

SW provides runtime data

• Map linear-address to

image files

• Map CR3 value to

application

• Log module load/unload

and JIT info

Binary

image files

Decoder uses Intel® PT s/w runtime data to

reconstruct execution flow from compressed

h/w packet data and code images

Debug tools provide

visualization layer, present

data to the user

Intel® PT

h/w

Ring0 s/w

configures &

enables Intel®

PT

3

Page 4: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Decoding Intel® Processor Trace Control Flow

• PSB: packet stream boundary

• Unique pattern for synchronizing onto the PT stream

• TNT: taken/not-taken packet

• One bit for each conditional jump

• TIP: target ip packet

• One packet for each indirect jump or call

• FUP: flow update packet

• Indicate IP for other packets

• FUP+TIP: asynchronous control transfer

4

Page 5: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Decoding Intel® Processor Trace Execution State Information

• MODE.EXEC: execution mode packet

• Execution mode, i.e. 16bit, 32bit, 64bit

• MODE.TSX: tsx state packet

• Transactional execution state changes

• PIP: paging information packet

• Paging changes, e.g. switching processes

• TIP.PGE/TIP.PGD: trace generation enable/disable

• Indicate start/stop of tracing

• TSC: time stamp counter

• Timing information 5

Page 6: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Decoding Intel® Processor Trace Packet Binding

• Packets bind together to describe events

• MODE.EXEC+TIP: change exec mode after this branch

• MODE.TSX+FUP: tsx state change at this IP

• Packets may bind to packet combinations

• MODE.TSX(abort)+FUP+TIP: (async) transaction abort

• Context sensitive packet semantics

• TIP: binds to next indirect jump or call

• FUP+TIP: asynchronous jump

• Bindings and semantics specified for each packet in SDM: http://download-software.intel.com/sites/default/files/319433-015.pdf.

6

Page 7: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace Decoder Library

• Intel‘s reference package of s/w building blocks: • Packet encoding/decoding

• Execution event reconstruction (packet binding)

• Execution flow reconstruction

• Samples

– packet dumper

– instruction flow dumper (using XED disassembler)

• Testing

– tools for creating and running tests

– test suite covering sample tools

• S/W enabling ahead of Si.

• Written in C – runs on Linux, Windows, and OS X.

• Available at http://01.org under 3-clause BSD license.

7

Page 8: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace Decoder Library Decoding Layers

8

Execution Flow Reconstruction

Packet Binding

Enabled Tool

packet stream

execution flow

analysis & visualization Intel® Processor Trace Decoder Library

Packet Decoding

event stream

Interpret raw Intel® processor trace data and extracts packets.

Apply low level packet semantics and create a stream of execution events.

Reconstruct execution flow from disassembly and side-band information.

Use Intel® processor trace for performance and functional debugging.

Page 9: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace Decoder Library Packet Decoding • Decode a single Intel® PT packet

into a C struct:

• Intel® PT opcode

• Intel® PT payload

• Payload interpretation where necessary

• Intel® PT packet dumper built on top.

9

Page 10: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace Decoder Library Packet Binding

• Combine Intel® PT packets to extract semantics.

• Keep track of time.

• Read ahead to signal upcoming events.

• Query interface for

• Conditional branches

• Indirect branches

• Events

• Time

10

Page 11: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace Decoder Library Execution Flow Reconstruction

• Fast, special-purpose instruction decoder.

• Reconstruct the execution flow based on

• Instruction analysis

• Event stream (query interface)

• Interface to iterate over instructions providing:

• Instruction virtual address

• Raw instruction bytes and size

• Execution mode

• Coarse classification

• Add. information like enable/disable, speculation, ... 11

Page 12: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

https://01.org Processor Trace Decoder Library

Page 13: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

Intel® Processor Trace in GDB

• Print trace on instruction level

• Print trace on function level (show call structure)

• Limited reverse execution and replay

• Patches being discussed at gdb mailing list

13

(gdb) record function-call-history /cli

12 fib inst 101,111 at src/fib.c:3,7

13 fib inst 112,124 at src/fib.c:3,8

14 fib inst 125,129 at src/fib.c:7

15 fib inst 130,142 at src/fib.c:3,8

16 fib inst 143,147 at src/fib.c:7,8

17 fib inst 148,152 at src/fib.c:7,8

18 fib inst 153,157 at src/fib.c:7

19 fib inst 158,168 at src/fib.c:3,7

20 fib inst 169,179 at src/fib.c:3,7

21 fib inst 180,185 at src/fib.c:3,4

• Current implementation supports BTS

Page 14: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH

Copyright© 2013, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

INFORMATION IN THIS DOCUMENT IS PROVIDED “AS IS”. NO LICENSE, EXPRESS OR IMPLIED, BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERTY RIGHTS IS GRANTED BY THIS DOCUMENT. INTEL ASSUMES NO LIABILITY WHATSOEVER AND INTEL DISCLAIMS ANY EXPRESS OR IMPLIED WARRANTY, RELATING TO THIS INFORMATION INCLUDING LIABILITY OR WARRANTIES RELATING TO FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, OR INFRINGEMENT OF ANY PATENT, COPYRIGHT OR OTHER INTELLECTUAL PROPERTY RIGHT. Software and workloads used in performance tests may have been optimized for performance only on Intel microprocessors. Performance tests, such as SYSmark and MobileMark, are measured using specific computer systems, components, software, operations and functions. Any change to any of those factors may cause the results to vary. You should consult other information and performance tests to assist you in fully evaluating your contemplated purchases, including the performance of that product when combined with other products. Copyright © , Intel Corporation. All rights reserved. Intel, the Intel logo, Xeon, Core, VTune, and Cilk are trademarks of Intel Corporation in the U.S. and other countries.

Optimization Notice

Intel’s compilers may or may not optimize to the same degree for non-Intel microprocessors for optimizations that are not unique to Intel microprocessors. These optimizations include SSE2, SSE3, and SSSE3 instruction sets and other optimizations. Intel does not guarantee the availability, functionality, or effectiveness of any optimization on microprocessors not manufactured by Intel. Microprocessor-dependent optimizations in this product are intended for use with Intel microprocessors. Certain optimizations not specific to Intel microarchitecture are reserved for Intel microprocessors. Please refer to the applicable product User and Reference Guides for more information regarding the specific instruction sets covered by this notice.

Notice revision #20110804

Legal Disclaimer & Optimization Notice

Copyright© 2012, Intel Corporation. All rights reserved. *Other brands and names are the property of their respective owners.

14

Page 15: Intel® Processor Trace - MAD) Workshop · 2016. 3. 22. · Intel® Processor Trace What it is and how to decode it Markus Metzger, Intel GmbH