Skip to content

GhostScope v0.1.6

Latest

Choose a tag to compare

@swananan swananan released this 01 Jul 11:17
· 122 commits to main since this release

Overview

GhostScope v0.1.6 focuses on execution context: not only printing live values, but also showing how execution reached the probe point.

This release adds DWARF-backed stack backtraces to the scripting workflow and continues hardening GhostScope for production-style runtime diagnostics. The main user-facing change is that a trace script can now combine a normal print line with bt / backtrace, so a live probe can answer both "what state is here?" and "which call path brought the process here?" without stopping the target.

Highlights

  • Added DWARF-unwound bt / backtrace support for GhostScope scripts
  • Added bt full output for symbolized, source-aware stack frames and bt raw output for lower-level frame metadata
  • Added backtrace support to repeatable CLI script workflows, including --script-file demos that combine request state with call context
  • Added runtime module refresh support for backtraces, including modules loaded later through dlopen
  • Improved multi-module and target-mode backtrace handling, including better behavior when the stack crosses module boundaries
  • Expanded backtrace coverage for PID mode, target mode, combined -t -p sessions, and container/PID-namespace scenarios
  • Added runtime backtrace CFI map sharing so multiple trace loaders can use the same prepared unwind metadata more safely
  • Improved debug-info loading and reporting, including explicit debug-file handling, stricter debuglink matching, and clearer missing/unusable debug-info diagnostics
  • Improved script output rendering for backtrace payloads in plain and pretty output modes
  • Updated the README and runtime-analysis skill examples to show that GhostScope can inspect both live values and source-aware call stacks

Bug Fixes

This release also includes correctness and reliability fixes across the tracing pipeline, including:

  • Fixed trace context overflow handling so oversized trace metadata returns a clear error
  • Fixed source shortcut parsing in Input Mode
  • Fixed packaging so CLI scripting documentation is included correctly
  • Fixed target-mode backtraces in child-container topologies
  • Fixed runtime CFI map and sysmon fallback safety for backtrace paths
  • Fixed target dlopen module refresh behavior for backtraces
  • Fixed runtime module identity checks so mismatched proc-root module identities are rejected instead of silently reused
  • Fixed handling for unusable debuglink files so they are treated as missing debug information
  • Fixed explicit debug-file loading for DWARF-backed tracing
  • Fixed disabled traces so loading a saved trace set preserves disabled state
  • Updated supply-chain dependencies, including RustSec-related dependency bumps

What's Next

Next, I plan to focus on reducing startup cost for production diagnostics by moving expensive DWARF/script preparation out of the hot attach path.

The next milestones are:

  • a non-privileged prepare mode that builds reusable trace bundles
  • a run-bundle attach path for faster production tracing
  • a longer-term remote/daemon workflow that can keep target metadata warm across repeated attach requests

See Issue #240 for the tracking discussion.