本文へ移動
cccskills
無料GitHub で公開

kernel-debugging-advanced

Use when tracing kernel functions with ftrace or trace-cmd, profiling with perf, kprobes, or dyndbg, or analyzing a vmcore with crash. Not for QEMU GDB stubs: use qemu-for-kernel-development.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md5.7 KB
  • agents/openai.yaml213 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Advanced kernel debugging

Contract

FieldBound contract
TriggerProduction-grade kernel tracing and post-mortem work: ftrace function graph, trace-cmd, kernel perf probes, dynamic kprobes, dyndbg, breaking into kgdb/kdb, or analyzing a vmcore after a panic.
AuthorityRead-only. Writes nothing. Chat output only. No remote mutation.
Side effectReturns commands and analysis procedures the caller runs on their target. No source files are modified.
DoneThe trace, probe, or vmcore analysis plan is delivered with the config and mount prerequisites named.

Inputs

  1. Symptom (required): the latency spike, wrong behavior, or panic to explain.
  2. Target (required): the kernel build, whether it has debug symbols and tracepoints, and whether the box runs production traffic.
  3. Access (optional): serial console for kgdb, kdump capture for vmcore, root for tracefs.

Procedure

  1. Graph the suspect function with ftrace before reaching for heavier tools. Prerequisites: CONFIG_FUNCTION_GRAPH_TRACER and tracefs mounted (mount -t tracefs none /sys/kernel/tracing; the /sys/kernel/debug/tracing path works when debugfs is mounted).

    cd /sys/kernel/tracing
    echo function_graph > current_tracer
    echo my_driver_probe > set_graph_function
    echo 1 > tracing_on
    # reproduce the issue
    echo 0 > tracing_on
    cat trace
    

    Graphing every function drowns the output and costs overhead; the set_graph_function filter is not optional. Done when: the trace shows entry and exit of the named function with durations.

  2. Use trace-cmd when the capture must be shared or replayed. -g sets the graph filter; -F would run a command, not filter a kernel function.

    trace-cmd record -p function_graph -g my_probe
    trace-cmd report
    trace-cmd stat
    

    Done when: the report opens on another machine with trace-cmd report.

  3. Profile in kernel context with perf. perf ships inside the kernel tree under tools/perf, so its features track the kernel being debugged.

    perf record -a -g -- sleep 10
    perf report --stdio
    perf probe --add my_probe        # define a probe at the function
    perf record -e probe:my_probe -aR -- sleep 10
    

    Done when: the report names kernel functions or the probe fires with the expected count.

  4. Instrument precisely with a kprobe when a static tracepoint does not exist. Register it against a symbol; inlined functions have no symbol to attach to.

    #include <linux/kprobes.h>
    
    static struct kprobe kp = {
        .symbol_name = "do_sys_open",
        .pre_handler = handler,
    };
    register_kprobe(&kp);
    

    Use kprobes sparingly on production boxes; prefer static tracepoints when one exists for the event. Done when: the probe registers (or the registration fails with the inline reason) and the handler records what the diagnosis needs.

  5. Turn on dyndbg for the driver's own debug prints instead of recompiling.

    echo 'module mydriver +p' > /sys/kernel/debug/dynamic_debug/control
    # /proc/dynamic_debug/control is the same control file
    echo 'file drivers/foo/*.c +p' > /sys/kernel/debug/dynamic_debug/control
    

    In code, prefer pr_debug and pr_warn_ratelimited over raw printk; rate-limit anything an external party can trigger. Done when: the debug lines appear in dmesg for the failing path and stop after the diagnosis.

  6. Break into kgdb/kdb only with a serial or console path arranged in advance.

    # kernel cmdline: kgdboc=ttyS0,115200 kgdbwait
    echo g > /proc/sysrq-trigger   # enter the debugger on a live system
    

    Done when: the debugger prompt answers over the configured console.

  7. Analyze a vmcore with crash when the box panicked and kdump captured it. The vmlinux must carry debug info and match the running kernel build.

    crash /usr/lib/debug/boot/vmlinux-$(uname -r) /var/crash/<timestamp>/vmcore
    crash> bt
    crash> dev -s
    

    Where the distribution ships symbols as debug packages (linux-image-*-dbg) or via debuginfod, fetch the matching one. Done when: the backtrace names the faulting path and the state that led to it.

  8. Assemble the findings into one causal story: the traced function, the measured duration, the probe evidence, or the panic backtrace. Route deeper work: ebpf for BPF-based tracing alternatives, device-drivers when the trace target is an ioctl path; keep kgdb guidance grounded in Documentation/process/debugging/gdb-kernel-debugging-guide.rst of the target kernel. Done when: the story answers the reported symptom with evidence from steps 1 to 7.

Failure and recovery

SymptomCauseRecovery
Empty traceTracer off or wrong tracerCheck current_tracer and tracing_on; confirm tracefs is mounted.
ftrace overhead too highGraphing all functionsSet set_graph_function to the suspect.
kprobe registration failsSymbol is inlinedPick a nearby non-inlined symbol or a static tracepoint.
kgdb does not connectWrong kgdboc deviceMatch the actual serial or USB gadget console.
crash prints no symbolsMissing debug info for the exact buildInstall the matching debug package or fetch via debuginfod.

Output

The ftrace or trace-cmd capture plan with prerequisites; the perf or kprobe evidence; the dyndbg recipe; the kgdb entry path; the crash analysis commands against the matched vmcore and vmlinux; the causal story for the reported symptom.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use when explaining System V AMD64, ARM AAPCS, RISC-V psABI, stack frames, variadic calls, or FFI register rules. Not for the Rust FFI binding layer: use rust-ffi.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

Use when configuring ADC sampling time, DMA-driven ADC, calibration, or DAC channel setup on bare-metal MCUs. Not for the DMA stream itself: use dma-baremetal.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

af-xdp

無料

Use when creating AF_XDP sockets, configuring UMEM and XSK rings, writing an XDP redirect program, or choosing copy versus zero-copy mode. Not for full kernel bypass: use dpdk.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

Use when a completed session needs an agent-environment retrospective. Not for an engineering retrospective from telemetry: use engineering-retrospective.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

Use when a redacted, trimmed agent transcript must be appended to a GitHub PR or issue body, with human approval and preview. Not for automated or model-initiated insertion.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

agents-md

無料

Use when a repo needs agent setup, AGENTS.md added or made lean, CLAUDE.md audited, or agent instructions scored or pruned. Not for remote, credential, publish, deploy, or irreversible changes.

日本語の概要は準備中です。原文の説明を表示しています。

OutlineDriven/odin-claude-plugin372026年9月29日 更新

OutlineDriven のスキルをすべて見る

このスキルの問題を報告する