为何我的Linux perf工具中没有syscall计数器?
Let's break down why you're hitting those errors and how to fix them—your 3.10 kernel setup needs a few tweaks to expose the syscall tracepoint events you're looking for.
1. Check if Your Kernel Has Syscall Tracepoints Enabled
The syscalls:sys_enter_* events rely on two key kernel config options that might not be enabled by default in some 3.10 distro kernels:
CONFIG_FTRACE: Enables the kernel tracing frameworkCONFIG_SYSCALL_TRACEPOINTS: Exposes syscall entry/exit events via tracepoints
To verify, run this command to check your kernel config:
grep -E 'CONFIG_FTRACE|CONFIG_SYSCALL_TRACEPOINTS' /boot/config-$(uname -r)
If either line shows =n or doesn't exist at all, you'll need to recompile your kernel with these options set to =y. For most distros, you can grab the kernel source package, copy your existing config, enable these flags, and build/install the new kernel.
2. Fix Permission Issues
The "Permission denied" error happens because accessing tracepoint events requires elevated privileges. You have a few options:
- Run perf with sudo: The simplest fix is to prefix your command with
sudo:sudo perf top -e 'syscalls:sys_enter_*' - Set capabilities on perf: Let regular users run perf without sudo (note: this has security implications, so use cautiously):
sudo setcap cap_sys_ptrace,cap_sys_admin=ep /usr/bin/perf - Adjust perf event paranoia level: Temporarily relax kernel restrictions:
(You can set it back to the default value later, usuallysudo sysctl -w kernel.perf_event_paranoid=01or2.)
3. Ensure debugfs is Mounted
Tracepoint events are exposed through debugfs, which might not be mounted by default on your system. Check if the directory exists:
ls /sys/kernel/debug/tracing/events/syscalls/
If you get a "No such file or directory" error, mount debugfs first:
sudo mount -t debugfs none /sys/kernel/debug
After mounting, you should see all the sys_enter_* and sys_exit_* event files in that directory.
4. Verify the Events Are Visible
Once the above steps are done, run perf list syscalls—you should now see all the syscall-related events listed. Test with a specific event first to confirm:
perf top -e syscalls:sys_enter_select
If that works, the wildcard version (syscalls:sys_enter_*) should also function correctly.
A quick note: Linux 3.10 is a relatively old kernel, but the syscalls:sys_enter_* naming convention is consistent here, so you don't have to worry about event name mismatches with newer kernels.
内容的提问来源于stack exchange,提问作者John Zwinck

