You are browsing as a guest. Sign up (or log in) to start making projects!

whyslow

  • 1 Devlogs
  • 18 Total hours

whyslow traces sched_switch, futex, and block I/O events via eBPF to show you the actual causal chain behind a slow Linux process, not just isolated symptoms. Built at a 48hr hackathon in my house!

Ship #1 Pending review

whyslow traces sched_switch, futex, and block I/O events via eBPF to show you the actual causal chain behind a slow Linux process, not just isolated symptoms. Built at a 48hr hackathon in my house!

  • 1 devlog
  • 18h
Try project → See source code →
Open comments for this post

18h 18m 27s logged

Shipping whyslow v1

The problem

Every Linux dev has hit “my program is slow” and reached for strace,
perf, or py-spy — but each tool sees one layer. None of them tell you
why across layers. You end up manually cross-referencing three terminal
windows and timestamps by hand.

What I built

whyslow — a CLI that watches sched_switch, futex, and block I/O events
via eBPF and stitches them into a single causal chain:

$ sudo whyslow run -- ./my-slow-program
 
14:32:07.001 — tid 4821 blocked 412ms on futex 0x7f2a3c001000
 ← woken by tid 4809
 ← tid 4809 blocked 380ms on block I/O (dev nvme0n1p2, sector 88213)

No manual correlation. It finds the root cause and walks you back to it.

Stack

  • Rust, aya for pure-Rust eBPF (no libbpf/C toolchain needed)
  • Ring buffer for low-overhead event collection — can’t perturb the thing
    you’re measuring
  • Interval tree + happens-before edge inference for the causal graph
  • Workspace: whyslow-cli, whyslow-ebpf, whyslow-common

Scope for v1

  • x86_64 + aarch64 Linux, kernel 5.8+
  • Three event sources: sched_switch, futex, block I/O
  • No stack symbolication yet — tid/pid/comm only
  • Needs root or CAP_BPF — no way around that, eBPF is privileged
    Kept scope narrow on purpose: three event sources done correctly beats
    eight done half right. Validated against a synthetic program that
    deliberately causes futex contention + a disk stall, so there’s ground
    truth to check the causal chain against, not just vibes.

Distribution

  • curl -sSf .../install.sh | sh
  • Homebrew tap, APT repo, pip wrapper — see DISTRIBUTION.md
  • crates.io publish still pending — cargo install works via --git for now

What’s next

  • Stack symbolication (native + interpreted languages)
  • More event sources without losing causal-chain accuracy
  • Actual crates.io publish so cargo install whyslow just works

Repo

github.com/kaorii-ako/whyslow

1
0
8

Delete project?

Are you sure you want to permanently delete this project? This action cannot be undone.

All devlogs, followers, and associated data will be removed.

Followers

Loading…