Topic 06: Kernel Telemetry Interfaces — Procfs & Sysfs Subsystems

Target Duration: 2–4 minutes (~300–450 spoken words)
Focus: Pointwise verbal delivery comparing historical procfs streams against modern structured sysfs kobjects, single-opener mutual exclusion, and granular attribute show/store callbacks.

🎯 Strategic Follow-Up Hook (From Elevator Pitch)

What You Mentioned: "Kernel telemetry via /proc and sysfs"

Why It Was Done (The Motivation): Contrast procedural stream interfaces with structured object-oriented sysfs attributes.

Problems Faced & How Solved (The Reality): Implemented struct proc_ops for lockless page-fault streaming and a sysfs kobject with container_of for per-PID memory queries.


🎙️ Pointwise Spoken Speech (Word-for-Word Delivery)


📋 Step-by-Step Summary (What, How & Why)

Step What Was Done How It Works Why This Mechanism / Order Code Reference
1. Procfs Creation Registered /proc/get_pgfaults Uses proc_create with struct proc_ops callback table. Exposes system-wide aggregate telemetry via a familiar procfs entry. 3.1/get_pgfaults.c:68, 76
2. Concurrency Guard Implemented open_count guard Increments counter on open; rejects concurrent openers with -EBUSY. Prevents multiple readers from interleaving buffered stream outputs. 3.1/get_pgfaults.c:20-35
3. Sysfs Kobject Created /sys/kernel/get_memstats Anchored kobject under root kernel_kobj. Adheres to modern kernel object hierarchy and device model standards. 3.2/get_memstats.c:234
4. Attribute Handlers Defined show and store callbacks Uses __ATTR macros to bind read/write functions to attribute files. Enforces strict 'one value per file' philosophy, enabling scriptable automation. 3.2/get_memstats.c:34-212
5. Subsystem Teardown Invoked remove_proc_entry & kobject_put Cleans up directory nodes and decrements kobject reference counts. Prevents kernel memory leaks and dangling virtual filesystem pointers. 3.1/get_pgfaults.c:89
3.2/get_memstats.c:245

❓ Anticipated Interview Questions & Crisp Answers

Q1: Why did you build both a /proc and a /sys interface? When would you use one over the other?

Answer: They serve distinct architectural roles. We used /proc/get_pgfaults for system-wide streaming telemetry (aggregate page fault counters), where a single read stream dumps an overall metric snapshot. We used /sys/kernel/get_memstats for interactive, object-oriented process inspection where user space dynamically sets target PIDs and unit scaling (Bytes/KB/MB) via store callbacks, and reads back specific metrics via show callbacks. Sysfs strictly enforces the modern Linux device model's "one value per file" philosophy, making it clean and script-friendly for automated monitoring agents.

Q2: What concurrency bug did you encounter when multiple processes opened /proc/get_pgfaults simultaneously?

Answer: Reading /proc/get_pgfaults formats kernel fault counters into a shared module buffer before copying to user space. If two processes (or two threads) opened and read /proc/get_pgfaults concurrently, their read offsets and buffer state interleaved, causing truncated output, corrupted text, or duplicated lines. To solve this without complex dynamic per-client streaming locks, we added an atomic single-opener guard in proc_open: if the file was already open by an active reader, subsequent open() attempts were immediately rejected with -EBUSY.

Q3: What happens if an administrator unloads the module (rmmod) while a user-space monitoring script has /sys/kernel/get_memstats open?

Answer: In Linux sysfs, kobject nodes are reference-counted via kref. When user space opens a sysfs attribute file, the VFS takes a reference count on the underlying kobject and increments the module's refcount (THIS_MODULE). If someone executes rmmod, the kernel detects that the module reference count is non-zero and refuses to unload (rmmod: ERROR: Module is in use). Once user space closes all file descriptors, the refcount decrements to zero, allowing kobject_put() to cleanly unlink attribute files and free descriptors without leaving dangling pointers.