Skip to content

[DNM] macos: record the process tree with the kernel trace facility - #34

Draft
LalitMaganti wants to merge 1 commit into
readme-rationalizefrom
macos-record-1
Draft

LalitMaganti wants to merge 1 commit into
readme-rationalizefrom
macos-record-1

Conversation

@LalitMaganti

Copy link
Copy Markdown
Owner

Prototype for #2, step 1 of 6, on top of #33. Do not merge; the design is still TBD.

Records the process tree on macOS by reading the kernel trace facility. Starting a trace session needs root, but access is granted to the owning process and survives dropping privileges, so buildprof is privileged only while it starts: it configures the session, gives up root for good, then runs the build, reads events and writes the trace as you. The build does not run as root and keeps your environment.

This step records which process started which, what program each ran, and how each exited. Command lines, file events and compiler traces follow in the rest of the stack.

Verified on macOS 26: records a 23-process build and propagates its exit status.

macOS has no unprivileged way to follow a process tree. Configuring the
kernel trace facility needs root, but the kernel keeps granting access to
the process that owns a session, so recording is privileged only while it
starts: configure the session, give up root for good, then run the build,
read events and write the trace as the person who ran it.

This records the process tree: which process started which, what program
each ran, and how each exited. The kernel also reports an exit when a
process replaces its image, so an exit is held briefly and cancelled by
anything further from that pid.

Command lines, file events and compiler traces follow.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant