]> git.saurik.com Git - apple/system_cmds.git/blobdiff - fs_usage.tproj/fs_usage.c
system_cmds-790.tar.gz
[apple/system_cmds.git] / fs_usage.tproj / fs_usage.c
index 6f8b2f22dc8efd0a0b00ed544cb5fa49a437f895..f7f9bfc29119ba62d82d4ecacf36eecec5ce4c6e 100644 (file)
@@ -1,8 +1,8 @@
 /*
- * Copyright (c) 1999 Apple Computer, Inc. All rights reserved.
+ * Copyright (c) 1999-2016 Apple Inc. All rights reserved.
  *
  * @APPLE_LICENSE_HEADER_START@
- * 
+ *
  * "Portions Copyright (c) 1999 Apple Computer, Inc.  All Rights
  * Reserved.  This file contains Original Code and/or Modifications of
  * Original Code as defined in and that are subject to the Apple Public
@@ -10,7 +10,7 @@
  * except in compliance with the License.  Please obtain a copy of the
  * License at http://www.apple.com/publicsource and read it before using
  * this file.
- * 
+ *
  * The Original Code and all software distributed under the License are
  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
  * FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT.  Please see the
  * License for the specific language governing rights and limitations
  * under the License."
- * 
+ *
  * @APPLE_LICENSE_HEADER_END@
  */
 
 /*
-cc -I. -DPRIVATE -D__APPLE_PRIVATE -O -o fs_usage fs_usage.c
-*/
-
-#define        Default_DELAY   1       /* default delay interval */
+ * SDKROOT=macosx.internal cc -I`xcrun -sdk macosx.internal --show-sdk-path`/System/Library/Frameworks/System.framework/Versions/B/PrivateHeaders -arch x86_64 -Os -lktrace -lutil -o fs_usage fs_usage.c
+ */
 
 #include <stdlib.h>
 #include <stdio.h>
 #include <signal.h>
 #include <strings.h>
-#include <nlist.h>
 #include <fcntl.h>
+#include <aio.h>
 #include <string.h>
 #include <dirent.h>
-
-#include <sys/types.h>
-#include <sys/param.h>
-#include <sys/time.h>
-
 #include <libc.h>
 #include <termios.h>
-#include <sys/ioctl.h>
-
-#ifndef KERNEL_PRIVATE
-#define KERNEL_PRIVATE
-#include <sys/kdebug.h>
-#undef KERNEL_PRIVATE
-#else
-#include <sys/kdebug.h>
-#endif /*KERNEL_PRIVATE*/
-
-#include <sys/sysctl.h>
 #include <errno.h>
-#import <mach/clock_types.h>
-#import <mach/mach_time.h>
 #include <err.h>
+#include <libutil.h>
 
-extern int errno;
+#include <ktrace/session.h>
+#include <System/sys/kdebug.h>
+#include <assert.h>
 
+#include <sys/disk.h>
+#include <sys/fcntl.h>
+#include <sys/file.h>
+#include <sys/ioctl.h>
+#include <sys/mman.h>
+#include <sys/param.h>
+#include <sys/socket.h>
+#include <sys/syslimits.h>
+#include <sys/time.h>
+#include <sys/types.h>
 
-
-#define MAXINDEX 2048
-
-typedef struct LibraryInfo {
-     unsigned long address;
-     char     *name;
-} LibraryInfo;
-
-LibraryInfo frameworkInfo[MAXINDEX];
-int numFrameworks = 0;
-
-char seg_addr_table[256]="/AppleInternal/Developer/seg_addr_table";
-
-char *lookup_name();
-
-
-/* 
-   MAXCOLS controls when extra data kicks in.
-   MAX_WIDE_MODE_COLS controls -w mode to get even wider data in path.
-   If NUMPARMS changes to match the kernel, it will automatically
-   get reflected in the -w mode output.
-*/
-#define NUMPARMS 23
-#define PATHLENGTH (NUMPARMS*sizeof(long))
-#define MAXCOLS 131
-#define MAX_WIDE_MODE_COLS (PATHLENGTH + 80)
-
-struct th_info {
-        int  in_filemgr;
-        int  thread;
-        int  pid;
-        int  type;
-        int  arg1;
-        int  arg2;
-        int  arg3;
-        int  arg4;
-        int  child_thread;
-        int  waited;
-        double stime;
-        long *pathptr;
-        char pathname[PATHLENGTH + 1];   /* add room for null terminator */
-};
-
-#define MAX_THREADS 512
-struct th_info th_state[MAX_THREADS];
-
-
-int  cur_max = 0;
-int  need_new_map = 1;
-int  bias_secs;
-int  wideflag = 0;
-int  columns = 0;
-int  select_pid_mode = 0;  /* Flag set indicates that output is restricted
-                             to selected pids or commands */
-
-int  one_good_pid = 0;    /* Used to fail gracefully when bad pids given */
-
-char   *arguments = 0;
-int     argmax = 0;
+#import <mach/clock_types.h>
+#import <mach/mach_time.h>
 
 /*
- * Network only or filesystem only output filter
- * Default of zero means report all activity - no filtering
+ * MAXCOLS controls when extra data kicks in.
+ * MAX_WIDE_MODE_COLS controls -w mode to get even wider data in path.
  */
-#define FILESYS_FILTER    0x01
-#define NETWORK_FILTER    0x02
-#define CACHEHIT_FILTER   0x04
-#define EXEC_FILTER      0x08
-#define DEFAULT_DO_NOT_FILTER  0x00
+#define MAXCOLS 132
+#define MAX_WIDE_MODE_COLS 264
+#define MAXWIDTH MAX_WIDE_MODE_COLS + 64
 
-int filter_mode = CACHEHIT_FILTER;
+typedef struct th_info {
+       struct th_info *next;
+       uintptr_t thread;
 
-#define NFS_DEV -1
+       /* this is needed for execve()/posix_spawn(), because the command name at the end probe is the new name, which we don't want */
+       char command[MAXCOMLEN + 1];
 
-struct diskrec {
-        struct diskrec *next;
-        char *diskname;
-        int   dev;
-};
+       /*
+        * sometimes a syscall can cause multiple VFS_LOOKUPs of the same vnode with multiple paths
+        * (e.g., one absolute, one relative).  traditional fs_usage behavior was to display the
+        * *first* lookup, so we need to save it off once we see it.
+        */
+       unsigned long vnodeid; /* the vp of the VFS_LOOKUP we're currently in, 0 if we are not in one */
+       char pathname[MAXPATHLEN];
+       char pathname2[MAXPATHLEN];
+       char *newest_pathname; /* points to pathname2 if it's filled, otherwise pathname if it's filled, otherwise NULL */
+
+       int pid;
+       int type;
+       unsigned long arg1;
+       unsigned long arg2;
+       unsigned long arg3;
+       unsigned long arg4;
+       unsigned long arg5;
+       unsigned long arg6;
+       unsigned long arg7;
+       unsigned long arg8;
+       int waited;
+       uint64_t stime;
+} *th_info_t;
 
 struct diskio {
-        struct diskio *next;
-        struct diskio *prev;
-        int  type;
-        int  bp;
-        int  dev;
-        int  blkno;
-        int  iosize;
-        int  io_errno;
-        int  issuing_thread;
-        int  completion_thread;
-        char issuing_command[MAXCOMLEN];
-        double issued_time;
-        double completed_time;
+       struct diskio *next;
+       struct diskio *prev;
+       unsigned long  type;
+       unsigned long  bp;
+       unsigned long  dev;
+       unsigned long  blkno;
+       unsigned long  iosize;
+       unsigned long  io_errno;
+       unsigned long  is_meta;
+       uint64_t   vnodeid;
+       uintptr_t  issuing_thread;
+       pid_t      issuing_pid;
+       uintptr_t  completion_thread;
+       char issuing_command[MAXCOMLEN + 1];
+       uint64_t issued_time;
+       uint64_t completed_time;
+       struct timeval completed_walltime;
+       uint32_t bc_info;
 };
 
-struct diskrec *disk_list = NULL;
-struct diskio *free_diskios = NULL;
-struct diskio *busy_diskios = NULL;
+#define HASH_SIZE       1024
+#define HASH_MASK       (HASH_SIZE - 1)
+
+void setup_ktrace_callbacks(void);
+void extend_syscall(uintptr_t thread, int type, ktrace_event_t event);
+
+/* printing routines */
+bool check_filter_mode(pid_t pid, th_info_t ti, unsigned long type, int error, int retval, char *sc_name);
+void format_print(th_info_t ti, char *sc_name, ktrace_event_t event, unsigned long type, int format, uint64_t now, uint64_t stime, int waited, const char *pathname, struct diskio *dio);
+int print_open(ktrace_event_t event, uintptr_t flags);
+
+/* metadata info hash routines */
+void meta_add_name(uint64_t blockno, const char *pathname);
+const char *meta_find_name(uint64_t blockno);
+void meta_delete_all(void);
+
+/* event ("thread info") routines */
+void event_enter(int type, ktrace_event_t event);
+void event_exit(char *sc_name, int type, ktrace_event_t event, int format);
+th_info_t event_find(uintptr_t thread, int type);
+void event_delete(th_info_t ti_to_delete);
+void event_delete_all(void);
+void event_mark_thread_waited(uintptr_t);
+
+/* network fd set routines */
+void fd_set_is_network(pid_t pid, unsigned long fd, bool set);
+bool fd_is_network(pid_t pid, unsigned long fd);
+void fd_clear_pid(pid_t pid);
+void fd_clear_all(void);
+
+/* shared region address lookup routines */
+void init_shared_cache_mapping(void);
+void lookup_name(uint64_t user_addr, char **type, char **name);
+
+/* disk I/O tracking routines */
+struct diskio *diskio_start(unsigned long type, unsigned long bp, unsigned long dev, unsigned long blkno, unsigned long iosize, ktrace_event_t event);
+struct diskio *diskio_find(unsigned long bp);
+struct diskio *diskio_complete(unsigned long bp, unsigned long io_errno, unsigned long resid, uintptr_t thread, uint64_t curtime, struct timeval curtime_wall);
+void diskio_print(struct diskio *dio);
+void diskio_free(struct diskio *dio);
+
+/* disk name routines */
+#define NFS_DEV -1
+#define CS_DEV -2
+char *generate_cs_disk_name(unsigned long dev, char *s);
+char *find_disk_name(unsigned long dev);
+void cache_disk_names(void);
+
+#define CLASS_MASK     0xff000000
+#define CSC_MASK       0xffff0000
+#define BSC_INDEX(type)        ((type >> 2) & 0x3fff)
 
-struct diskio *insert_diskio();
-struct diskio *complete_diskio();
-void           free_diskio();
-void           print_diskio();
-void           format_print();
-char           *find_disk_name();
-void           cache_disk_names();
-int            ReadSegAddrTable();
-void           mark_thread_waited(int);
-int            check_filter_mode(struct th_info *, int, int, int, char *);
-void           fs_usage_fd_set(unsigned int, unsigned int);
-int            fs_usage_fd_isset(unsigned int, unsigned int);
-void           fs_usage_fd_clear(unsigned int, unsigned int);
-void           init_arguments_buffer();
-int            get_real_command_name(int, char *, int);
-void            create_map_entry(int, int, char *);
-
-void           enter_syscall();
-void           exit_syscall();
-void           extend_syscall();
-void           kill_thread_map();
-
-#define TRACE_DATA_NEWTHREAD   0x07000004
-#define TRACE_DATA_EXEC        0x07000008
-#define TRACE_STRING_NEWTHREAD 0x07010004
-#define TRACE_STRING_EXEC      0x07010008
-
-#define MACH_vmfault    0x01300000
+#define MACH_vmfault    0x01300008
 #define MACH_pageout    0x01300004
 #define MACH_sched      0x01400000
 #define MACH_stkhandoff 0x01400008
-#define VFS_LOOKUP      0x03010090
-#define BSC_exit        0x040C0004
-
-#define P_WrData       0x03020000
-#define P_RdData       0x03020008
-#define P_WrMeta       0x03020020
-#define P_RdMeta       0x03020028
-#define P_PgOut                0x03020040
-#define P_PgIn         0x03020048
-#define P_WrDataAsync  0x03020010
-#define P_RdDataAsync  0x03020018
-#define P_WrMetaAsync  0x03020030
-#define P_RdMetaAsync  0x03020038
-#define P_PgOutAsync   0x03020050
-#define P_PgInAsync    0x03020058
-
-#define P_WrDataDone   0x03020004
-#define P_RdDataDone   0x0302000C
-#define P_WrMetaDone   0x03020024
-#define P_RdMetaDone   0x0302002C
-#define P_PgOutDone    0x03020044
-#define P_PgInDone     0x0302004C
-#define P_WrDataAsyncDone      0x03020014
-#define P_RdDataAsyncDone      0x0302001C
-#define P_WrMetaAsyncDone      0x03020034
-#define P_RdMetaAsyncDone      0x0302003C
-#define P_PgOutAsyncDone       0x03020054
-#define P_PgInAsyncDone                0x0302005C
-
+#define MACH_idle      0x01400024
+
+#define BSC_thread_terminate    0x040c05a4
+
+#define HFS_update          0x3018000
+#define HFS_modify_block_end 0x3018004
+
+#define Throttled      0x3010184
+#define SPEC_ioctl     0x3060000
+#define SPEC_unmap_info        0x3060004
+#define proc_exit      0x4010004
+
+#define BC_IO_HIT                              0x03070010
+#define BC_IO_HIT_STALLED              0x03070020
+#define BC_IO_MISS                             0x03070040
+#define BC_IO_MISS_CUT_THROUGH 0x03070080
+#define BC_PLAYBACK_IO                 0x03070100
+#define BC_STR(s)      ( \
+       (s == BC_IO_HIT) ? "HIT" : \
+       (s == BC_IO_HIT_STALLED) ? "STALL" : \
+       (s == BC_IO_MISS) ? "MISS" : \
+       (s == BC_IO_MISS_CUT_THROUGH) ? "CUT" : \
+       (s == BC_PLAYBACK_IO) ? "PLBK" : \
+       (s == 0x0) ? "NONE" : "UNKN" )
+
+#define P_DISKIO_READ    (DKIO_READ << 2)
+#define P_DISKIO_ASYNC   (DKIO_ASYNC << 2)
+#define P_DISKIO_META    (DKIO_META << 2)
+#define P_DISKIO_PAGING   (DKIO_PAGING << 2)
+#define P_DISKIO_THROTTLE (DKIO_THROTTLE << 2)
+#define P_DISKIO_PASSIVE  (DKIO_PASSIVE << 2)
+#define P_DISKIO_NOCACHE  (DKIO_NOCACHE << 2)
+#define P_DISKIO_TIER_MASK  (DKIO_TIER_MASK << 2)
+#define P_DISKIO_TIER_SHIFT (DKIO_TIER_SHIFT + 2)
+#define P_DISKIO_TIER_UPGRADE (DKIO_TIER_UPGRADE << 2)
+
+#define P_DISKIO       (FSDBG_CODE(DBG_DKRW, 0))
+#define P_DISKIO_DONE  (P_DISKIO | (DKIO_DONE << 2))
+#define P_DISKIO_TYPE  (P_DISKIO | P_DISKIO_READ | P_DISKIO_META | P_DISKIO_PAGING)
+#define P_DISKIO_MASK  (CSC_MASK | 0x4)
+
+#define P_WrData       (P_DISKIO)
+#define P_RdData       (P_DISKIO | P_DISKIO_READ)
+#define P_WrMeta       (P_DISKIO | P_DISKIO_META)
+#define P_RdMeta       (P_DISKIO | P_DISKIO_META | P_DISKIO_READ)
+#define P_PgOut                (P_DISKIO | P_DISKIO_PAGING)
+#define P_PgIn         (P_DISKIO | P_DISKIO_PAGING | P_DISKIO_READ)
+
+#define P_CS_Class             0x0a000000      // DBG_CORESTORAGE
+#define P_CS_Type_Mask         0xfffffff0
+#define P_CS_IO_Done           0x00000004
+
+#define P_CS_ReadChunk         0x0a000200      // chopped up request
+#define P_CS_WriteChunk                0x0a000210
+#define P_CS_MetaRead          0x0a000300      // meta data
+#define P_CS_MetaWrite         0x0a000310
+#define P_CS_TransformRead     0x0a000500      // background transform
+#define P_CS_TransformWrite    0x0a000510
+#define P_CS_MigrationRead     0x0a000600      // composite disk block migration
+#define P_CS_MigrationWrite    0x0a000610
+#define P_CS_SYNC_DISK         0x0a010000
 
 #define MSC_map_fd   0x010c00ac
 
+#define BSC_BASE     0x040C0000
+
 // Network related codes
-#define        BSC_recvmsg  0x040C006C
-#define        BSC_sendmsg  0x040C0070
-#define        BSC_recvfrom 0x040C0074
-#define BSC_accept   0x040C0078
-#define BSC_select   0x040C0174
-#define BSC_socket   0x040C0184
-#define BSC_connect  0x040C0188
-#define BSC_bind     0x040C01A0
-#define BSC_listen   0x040C01A8
-#define        BSC_sendto   0x040C0214
-#define BSC_socketpair 0x040C021C
-
-#define BSC_read     0x040C000C
-#define BSC_write    0x040C0010
-#define BSC_open     0x040C0014
-#define BSC_close    0x040C0018
-#define BSC_link     0x040C0024
-#define BSC_unlink   0x040C0028
-#define BSC_chdir    0x040c0030
-#define BSC_fchdir   0x040c0034
-#define BSC_mknod    0x040C0038        
-#define BSC_chmod    0x040C003C        
-#define BSC_chown    0x040C0040        
-#define BSC_access   0x040C0084        
-#define BSC_chflags  0x040C0088        
-#define BSC_fchflags 0x040C008C
-#define BSC_sync     0x040C0090
-#define BSC_dup      0x040C00A4
-#define BSC_revoke   0x040C00E0
-#define BSC_symlink  0x040C00E4        
-#define BSC_readlink 0x040C00E8
-#define BSC_execve   0x040C00EC
-#define BSC_chroot   0x040C00F4
-#define BSC_dup2     0x040C0168
-#define BSC_fsync    0x040C017C        
-#define BSC_readv    0x040C01E0        
-#define BSC_writev   0x040C01E4        
-#define BSC_fchown   0x040C01EC        
-#define BSC_fchmod   0x040C01F0        
-#define BSC_rename   0x040C0200
-#define BSC_mkfifo   0x040c0210        
-#define BSC_mkdir    0x040C0220        
-#define BSC_rmdir    0x040C0224
-#define BSC_utimes   0x040C0228
-#define BSC_futimes  0x040C022C
-#define BSC_pread    0x040C0264
-#define BSC_pread_extended    0x040E0264
-#define BSC_pwrite   0x040C0268
-#define BSC_pwrite_extended   0x040E0268
-#define BSC_statfs   0x040C0274        
-#define BSC_fstatfs  0x040C0278        
-#define BSC_stat     0x040C02F0        
-#define BSC_fstat    0x040C02F4        
-#define BSC_lstat    0x040C02F8        
-#define BSC_pathconf 0x040C02FC        
-#define BSC_fpathconf     0x040C0300
-#define BSC_getdirentries 0x040C0310
-#define BSC_mmap     0x040c0314
-#define BSC_lseek    0x040c031c
-#define BSC_truncate 0x040C0320
-#define BSC_ftruncate     0x040C0324
-#define BSC_undelete 0x040C0334
-#define BSC_statv    0x040C0364        
-#define BSC_lstatv   0x040C0368        
-#define BSC_fstatv   0x040C036C        
-#define BSC_mkcomplex   0x040C0360     
-#define BSC_getattrlist 0x040C0370     
-#define BSC_setattrlist 0x040C0374     
-#define BSC_getdirentriesattr 0x040C0378       
-#define BSC_exchangedata  0x040C037C   
-#define BSC_checkuseraccess   0x040C0380       
-#define BSC_searchfs    0x040C0384
-#define BSC_delete      0x040C0388
-#define BSC_copyfile    0x040C038C
-#define BSC_getxattr   0x040C03A8
-#define BSC_fgetxattr  0x040C03AC
-#define BSC_setxattr   0x040C03B0
-#define BSC_fsetxattr  0x040C03B4
-#define BSC_removexattr        0x040C03B8
-#define BSC_fremovexattr      0x040C03BC
-#define BSC_listxattr  0x040C03C0
-#define BSC_flistxattr 0x040C03C4
-#define BSC_fsctl       0x040C03C8
-#define BSC_open_extended     0x040C0454
-#define BSC_stat_extended     0x040C045C
-#define BSC_lstat_extended    0x040C0460
-#define BSC_fstat_extended    0x040C0464
-#define BSC_chmod_extended    0x040C0468
-#define BSC_fchmod_extended   0x040C046C
-#define BSC_access_extended   0x040C0470
-#define BSC_mkfifo_extended   0x040C048C
-#define BSC_mkdir_extended    0x040C0490
-#define BSC_load_shared_file  0x040C04A0
-#define BSC_lchown     0x040C05B0
-
-// Carbon File Manager support
-#define FILEMGR_PBGETCATALOGINFO                0x1e000020
-#define FILEMGR_PBGETCATALOGINFOBULK    0x1e000024
-#define FILEMGR_PBCREATEFILEUNICODE             0x1e000028
-#define FILEMGR_PBCREATEDIRECTORYUNICODE 0x1e00002c
-#define FILEMGR_PBCREATEFORK                    0x1e000030
-#define FILEMGR_PBDELETEFORK                    0x1e000034
-#define FILEMGR_PBITERATEFORK                   0x1e000038
-#define FILEMGR_PBOPENFORK                              0x1e00003c
-#define FILEMGR_PBREADFORK                              0x1e000040
-#define FILEMGR_PBWRITEFORK                             0x1e000044
-#define FILEMGR_PBALLOCATEFORK                  0x1e000048
-#define FILEMGR_PBDELETEOBJECT                  0x1e00004c
-#define FILEMGR_PBEXCHANGEOBJECT                0x1e000050
-#define FILEMGR_PBGETFORKCBINFO                         0x1e000054
-#define FILEMGR_PBGETVOLUMEINFO                         0x1e000058
-#define FILEMGR_PBMAKEFSREF                             0x1e00005c
-#define FILEMGR_PBMAKEFSREFUNICODE              0x1e000060
-#define FILEMGR_PBMOVEOBJECT                    0x1e000064
-#define FILEMGR_PBOPENITERATOR                  0x1e000068
-#define FILEMGR_PBRENAMEUNICODE                         0x1e00006c
-#define FILEMGR_PBSETCATALOGINFO                0x1e000070
-#define FILEMGR_PBSETVOLUMEINFO                         0x1e000074
-#define FILEMGR_FSREFMAKEPATH                   0x1e000078
-#define FILEMGR_FSPATHMAKEREF                   0x1e00007c
-
-#define FILEMGR_PBGETCATINFO                    0x1e010000
-#define FILEMGR_PBGETCATINFOLITE                0x1e010004
-#define FILEMGR_PBHGETFINFO                             0x1e010008
-#define FILEMGR_PBXGETVOLINFO                   0x1e01000c
-#define FILEMGR_PBHCREATE                               0x1e010010
-#define FILEMGR_PBHOPENDF                               0x1e010014
-#define FILEMGR_PBHOPENRF                               0x1e010018
-#define FILEMGR_PBHGETDIRACCESS                         0x1e01001c
-#define FILEMGR_PBHSETDIRACCESS                         0x1e010020
-#define FILEMGR_PBHMAPID                                0x1e010024
-#define FILEMGR_PBHMAPNAME                              0x1e010028
-#define FILEMGR_PBCLOSE                                         0x1e01002c
-#define FILEMGR_PBFLUSHFILE                             0x1e010030
-#define FILEMGR_PBGETEOF                                0x1e010034
-#define FILEMGR_PBSETEOF                                0x1e010038
-#define FILEMGR_PBGETFPOS                               0x1e01003c
-#define FILEMGR_PBREAD                                  0x1e010040
-#define FILEMGR_PBWRITE                                         0x1e010044
-#define FILEMGR_PBGETFCBINFO                    0x1e010048
-#define FILEMGR_PBSETFINFO                              0x1e01004c
-#define FILEMGR_PBALLOCATE                              0x1e010050
-#define FILEMGR_PBALLOCCONTIG                   0x1e010054
-#define FILEMGR_PBSETFPOS                               0x1e010058
-#define FILEMGR_PBSETCATINFO                    0x1e01005c
-#define FILEMGR_PBGETVOLPARMS                   0x1e010060
-#define FILEMGR_PBSETVINFO                              0x1e010064
-#define FILEMGR_PBMAKEFSSPEC                    0x1e010068
-#define FILEMGR_PBHGETVINFO                             0x1e01006c
-#define FILEMGR_PBCREATEFILEIDREF               0x1e010070
-#define FILEMGR_PBDELETEFILEIDREF               0x1e010074
-#define FILEMGR_PBRESOLVEFILEIDREF              0x1e010078
-#define FILEMGR_PBFLUSHVOL                              0x1e01007c
-#define FILEMGR_PBHRENAME                               0x1e010080
-#define FILEMGR_PBCATMOVE                               0x1e010084
-#define FILEMGR_PBEXCHANGEFILES                         0x1e010088
-#define FILEMGR_PBHDELETE                               0x1e01008c
-#define FILEMGR_PBDIRCREATE                             0x1e010090
-#define FILEMGR_PBCATSEARCH                             0x1e010094
-#define FILEMGR_PBHSETFLOCK                             0x1e010098
-#define FILEMGR_PBHRSTFLOCK                             0x1e01009c
-#define FILEMGR_PBLOCKRANGE                             0x1e0100a0
-#define FILEMGR_PBUNLOCKRANGE                   0x1e0100a4
-
-
-#define FILEMGR_CLASS   0x1e
-
-#define MAX_PIDS 32
-int    pids[MAX_PIDS];
-
-int    num_of_pids = 0;
-int    exclude_pids = 0;
-int    exclude_default_pids = 1;
-
-struct kinfo_proc *kp_buffer = 0;
-int kp_nentries = 0;
-
-#define SAMPLE_SIZE 60000
-
-#define DBG_ZERO_FILL_FAULT   1
-#define DBG_PAGEIN_FAULT      2
-#define DBG_COW_FAULT         3
-#define DBG_CACHE_HIT_FAULT   4
+#define        BSC_recvmsg             0x040C006C
+#define        BSC_sendmsg             0x040C0070
+#define        BSC_recvfrom            0x040C0074
+#define BSC_accept             0x040C0078
+#define BSC_select             0x040C0174
+#define BSC_socket             0x040C0184
+#define BSC_connect            0x040C0188
+#define BSC_bind               0x040C01A0
+#define BSC_listen             0x040C01A8
+#define        BSC_sendto              0x040C0214
+#define BSC_socketpair         0x040C021C
+#define BSC_recvmsg_nocancel   0x040c0644
+#define BSC_sendmsg_nocancel   0x040c0648
+#define BSC_recvfrom_nocancel  0x040c064c
+#define BSC_accept_nocancel    0x040c0650
+#define BSC_connect_nocancel   0x040c0664
+#define BSC_sendto_nocancel    0x040c0674
+
+#define BSC_exit               0x040C0004
+#define BSC_read               0x040C000C
+#define BSC_write              0x040C0010
+#define BSC_open               0x040C0014
+#define BSC_close              0x040C0018
+#define BSC_link               0x040C0024
+#define BSC_unlink             0x040C0028
+#define BSC_chdir              0x040c0030
+#define BSC_fchdir             0x040c0034
+#define BSC_mknod              0x040C0038
+#define BSC_chmod              0x040C003C
+#define BSC_chown              0x040C0040
+#define BSC_getfsstat          0x040C0048
+#define BSC_access             0x040C0084
+#define BSC_chflags            0x040C0088
+#define BSC_fchflags           0x040C008C
+#define BSC_sync               0x040C0090
+#define BSC_dup                        0x040C00A4
+#define BSC_ioctl              0x040C00D8
+#define BSC_revoke             0x040C00E0
+#define BSC_symlink            0x040C00E4
+#define BSC_readlink           0x040C00E8
+#define BSC_execve             0x040C00EC
+#define BSC_umask              0x040C00F0
+#define BSC_chroot             0x040C00F4
+#define BSC_msync              0x040C0104
+#define BSC_dup2               0x040C0168
+#define BSC_fcntl              0x040C0170
+#define BSC_fsync              0x040C017C
+#define BSC_readv              0x040C01E0
+#define BSC_writev             0x040C01E4
+#define BSC_fchown             0x040C01EC
+#define BSC_fchmod             0x040C01F0
+#define BSC_rename             0x040C0200
+#define BSC_flock              0x040C020C
+#define BSC_mkfifo             0x040C0210
+#define BSC_mkdir              0x040C0220
+#define BSC_rmdir              0x040C0224
+#define BSC_utimes             0x040C0228
+#define BSC_futimes            0x040C022C
+#define BSC_pread              0x040C0264
+#define BSC_pwrite             0x040C0268
+#define BSC_statfs             0x040C0274
+#define BSC_fstatfs            0x040C0278
+#define BSC_unmount            0x040C027C
+#define BSC_mount              0x040C029C
+#define BSC_fdatasync          0x040C02EC
+#define BSC_stat               0x040C02F0
+#define BSC_fstat              0x040C02F4
+#define BSC_lstat              0x040C02F8
+#define BSC_pathconf           0x040C02FC
+#define BSC_fpathconf          0x040C0300
+#define BSC_getdirentries      0x040C0310
+#define BSC_mmap               0x040c0314
+#define BSC_lseek              0x040c031c
+#define BSC_truncate           0x040C0320
+#define BSC_ftruncate          0x040C0324
+#define BSC_undelete           0x040C0334
+#define BSC_open_dprotected_np 0x040C0360
+#define BSC_getattrlist                0x040C0370
+#define BSC_setattrlist                0x040C0374
+#define BSC_getdirentriesattr  0x040C0378
+#define BSC_exchangedata       0x040C037C
+#define BSC_checkuseraccess    0x040C0380
+#define BSC_searchfs           0x040C0384
+#define BSC_delete             0x040C0388
+#define BSC_copyfile           0x040C038C
+#define BSC_fgetattrlist       0x040C0390
+#define BSC_fsetattrlist       0x040C0394
+#define BSC_getxattr           0x040C03A8
+#define BSC_fgetxattr          0x040C03AC
+#define BSC_setxattr           0x040C03B0
+#define BSC_fsetxattr          0x040C03B4
+#define BSC_removexattr                0x040C03B8
+#define BSC_fremovexattr       0x040C03BC
+#define BSC_listxattr          0x040C03C0
+#define BSC_flistxattr         0x040C03C4
+#define BSC_fsctl              0x040C03C8
+#define BSC_posix_spawn                0x040C03D0
+#define BSC_ffsctl             0x040C03D4
+#define BSC_open_extended      0x040C0454
+#define BSC_umask_extended     0x040C0458
+#define BSC_stat_extended      0x040C045C
+#define BSC_lstat_extended     0x040C0460
+#define BSC_fstat_extended     0x040C0464
+#define BSC_chmod_extended     0x040C0468
+#define BSC_fchmod_extended    0x040C046C
+#define BSC_access_extended    0x040C0470
+#define BSC_mkfifo_extended    0x040C048C
+#define BSC_mkdir_extended     0x040C0490
+#define BSC_aio_fsync          0x040C04E4
+#define        BSC_aio_return          0x040C04E8
+#define BSC_aio_suspend                0x040C04EC
+#define BSC_aio_cancel         0x040C04F0
+#define BSC_aio_error          0x040C04F4
+#define BSC_aio_read           0x040C04F8
+#define BSC_aio_write          0x040C04FC
+#define BSC_lio_listio         0x040C0500
+#define BSC_sendfile           0x040C0544
+#define BSC_stat64             0x040C0548
+#define BSC_fstat64            0x040C054C
+#define BSC_lstat64            0x040C0550
+#define BSC_stat64_extended    0x040C0554
+#define BSC_lstat64_extended   0x040C0558
+#define BSC_fstat64_extended   0x040C055C
+#define BSC_getdirentries64    0x040C0560
+#define BSC_statfs64           0x040C0564
+#define BSC_fstatfs64          0x040C0568
+#define BSC_getfsstat64                0x040C056C
+#define BSC_pthread_chdir      0x040C0570
+#define BSC_pthread_fchdir     0x040C0574
+#define BSC_lchown             0x040C05B0
+
+#define BSC_read_nocancel      0x040c0630
+#define BSC_write_nocancel     0x040c0634
+#define BSC_open_nocancel      0x040c0638
+#define BSC_close_nocancel      0x040c063c
+#define BSC_msync_nocancel     0x040c0654
+#define BSC_fcntl_nocancel     0x040c0658
+#define BSC_select_nocancel    0x040c065c
+#define BSC_fsync_nocancel     0x040c0660
+#define BSC_readv_nocancel     0x040c066c
+#define BSC_writev_nocancel    0x040c0670
+#define BSC_pread_nocancel     0x040c0678
+#define BSC_pwrite_nocancel    0x040c067c
+#define BSC_aio_suspend_nocancel 0x40c0694
+#define BSC_guarded_open_np    0x040c06e4
+#define BSC_guarded_close_np   0x040c06e8
+
+#define BSC_fsgetpath          0x040c06ac
+
+#define        BSC_getattrlistbulk 0x040c0734
+
+#define BSC_openat             0x040c073c
+#define BSC_openat_nocancel    0x040c0740
+#define BSC_renameat           0x040c0744
+#define BSC_chmodat            0x040c074c
+#define BSC_chownat            0x040c0750
+#define BSC_fstatat            0x040c0754
+#define BSC_fstatat64          0x040c0758
+#define BSC_linkat             0x040c075c
+#define BSC_unlinkat           0x040c0760
+#define BSC_readlinkat         0x040c0764
+#define BSC_symlinkat          0x040c0768
+#define BSC_mkdirat            0x040c076c
+#define BSC_getattrlistat      0x040c0770
+
+#define BSC_msync_extended     0x040e0104
+#define BSC_pread_extended     0x040e0264
+#define BSC_pwrite_extended    0x040e0268
+#define BSC_mmap_extended      0x040e0314
+#define BSC_mmap_extended2     0x040f0314
+
+#define FMT_NOTHING -1
+#define        FMT_DEFAULT     0
+#define FMT_FD         1
+#define FMT_FD_IO      2
+#define FMT_FD_2       3
+#define FMT_SOCKET     4
+#define        FMT_PGIN        5
+#define        FMT_PGOUT       6
+#define        FMT_CACHEHIT    7
+#define FMT_DISKIO     8
+#define FMT_LSEEK      9
+#define FMT_PREAD      10
+#define FMT_FTRUNC     11
+#define FMT_TRUNC      12
+#define FMT_SELECT     13
+#define FMT_OPEN       14
+#define        FMT_AIO_FSYNC   15
+#define        FMT_AIO_RETURN  16
+#define        FMT_AIO_SUSPEND 17
+#define        FMT_AIO_CANCEL  18
+#define        FMT_AIO         19
+#define        FMT_LIO_LISTIO  20
+#define FMT_MSYNC      21
+#define        FMT_FCNTL       22
+#define FMT_ACCESS     23
+#define FMT_CHMOD      24
+#define FMT_FCHMOD     25
+#define        FMT_CHMOD_EXT   26
+#define        FMT_FCHMOD_EXT  27
+#define FMT_CHFLAGS    28
+#define FMT_FCHFLAGS   29
+#define        FMT_IOCTL       30
+#define FMT_MMAP       31
+#define FMT_UMASK      32
+#define FMT_SENDFILE   33
+#define FMT_IOCTL_SYNC 34
+#define FMT_MOUNT      35
+#define FMT_UNMOUNT    36
+#define FMT_DISKIO_CS  37
+#define FMT_SYNC_DISK_CS       38
+#define FMT_IOCTL_UNMAP        39
+#define FMT_UNMAP_INFO 40
+#define FMT_HFS_update 41
+#define FMT_FLOCK      42
+#define FMT_AT         43
+#define FMT_CHMODAT    44
+#define FMT_OPENAT  45
+#define FMT_RENAMEAT   46
+#define FMT_IOCTL_SYNCCACHE 47
 
 #define DBG_FUNC_ALL   (DBG_FUNC_START | DBG_FUNC_END)
-#define DBG_FUNC_MASK  0xfffffffc
 
-double divisor = 0.0;       /* Trace divisor converts to microseconds */
+#pragma mark global state
 
-int mib[6];
-size_t needed;
-char  *my_buffer;
+ktrace_session_t s;
+bool BC_flag = false;
+bool RAW_flag = false;
+bool wideflag = false;
+bool include_waited_flag = false;
+bool want_kernel_task = true;
+dispatch_source_t stop_timer, sigquit_source, sigpipe_source, sighup_source, sigterm_source, sigwinch_source;
+uint64_t mach_time_of_first_event;
+uint64_t start_time_ns = 0;
+uint64_t end_time_ns = UINT64_MAX;
+unsigned int columns = 0;
 
-kbufinfo_t bufinfo = {0, 0, 0, 0, 0};
-
-int total_threads = 0;
-kd_threadmap *mapptr = 0;      /* pointer to list of threads */
-
-/* defines for tracking file descriptor state */
-#define FS_USAGE_FD_SETSIZE 256                /* Initial number of file descriptors per
-                                          thread that we will track */
-
-#define FS_USAGE_NFDBITS      (sizeof (unsigned long) * 8)
-#define FS_USAGE_NFDBYTES(n)  (((n) / FS_USAGE_NFDBITS) * sizeof (unsigned long))
+/*
+ * Network only or filesystem only output filter
+ * Default of zero means report all activity - no filtering
+ */
+#define FILESYS_FILTER    0x01
+#define NETWORK_FILTER    0x02
+#define EXEC_FILTER      0x08
+#define PATHNAME_FILTER          0x10
+#define DISKIO_FILTER  0x20
+#define DEFAULT_DO_NOT_FILTER  0x00
 
-typedef struct {
-    unsigned int   fd_valid;       /* set if this is a valid entry */
-    unsigned int   fd_thread;
-    unsigned int   fd_setsize;     /* this is a bit count */
-    unsigned long  *fd_setptr;     /* file descripter bitmap */
-} fd_threadmap;
+int filter_mode = DEFAULT_DO_NOT_FILTER;
+bool show_cachehits = false;
 
-fd_threadmap *fdmapptr = 0;    /* pointer to list of threads for fd tracking */
+#pragma mark syscall lookup table
 
-int trace_enabled = 0;
-int set_remove_flag = 1;
+#define MAX_BSD_SYSCALL        526
 
-void set_numbufs();
-void set_init();
-void set_enable();
-void sample_sc();
-int quit();
+struct bsd_syscall {
+       char *sc_name;
+       int     sc_format;
+};
 
-/*
- *  signal handlers
- */
+#define NORMAL_SYSCALL(name) \
+       [BSC_INDEX(BSC_##name)] = {#name, FMT_DEFAULT}
+
+#define SYSCALL(name, format) \
+       [BSC_INDEX(BSC_##name)] = {#name, format}
+
+#define SYSCALL_NAMED(name, displayname, format) \
+       [BSC_INDEX(BSC_##name)] = {#displayname, format}
+
+#define SYSCALL_WITH_NOCANCEL(name, format) \
+       [BSC_INDEX(BSC_##name)] = {#name, format}, \
+       [BSC_INDEX(BSC_##name##_nocancel)] = {#name, format}
+
+const struct bsd_syscall bsd_syscalls[MAX_BSD_SYSCALL] = {
+       SYSCALL(sendfile, FMT_FD), /* this should be changed to FMT_SENDFILE once we add an extended info trace event */
+       SYSCALL_WITH_NOCANCEL(recvmsg, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(sendmsg, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(recvfrom, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(sendto, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(select, FMT_SELECT),
+       SYSCALL_WITH_NOCANCEL(accept, FMT_FD_2),
+       SYSCALL(socket, FMT_SOCKET),
+       SYSCALL_WITH_NOCANCEL(connect, FMT_FD),
+       SYSCALL(bind, FMT_FD),
+       SYSCALL(listen, FMT_FD),
+       SYSCALL(mmap, FMT_MMAP),
+       NORMAL_SYSCALL(socketpair),
+       NORMAL_SYSCALL(getxattr),
+       NORMAL_SYSCALL(setxattr),
+       NORMAL_SYSCALL(removexattr),
+       NORMAL_SYSCALL(listxattr),
+       NORMAL_SYSCALL(stat),
+       NORMAL_SYSCALL(stat64),
+       NORMAL_SYSCALL(stat_extended),
+       SYSCALL_NAMED(stat64_extended, stat_extended64, FMT_DEFAULT), /* should be stat64_extended ? */
+       SYSCALL(mount, FMT_MOUNT),
+       SYSCALL(unmount, FMT_UNMOUNT),
+       NORMAL_SYSCALL(exit),
+       NORMAL_SYSCALL(execve),
+       NORMAL_SYSCALL(posix_spawn),
+       SYSCALL_WITH_NOCANCEL(open, FMT_OPEN),
+       SYSCALL(open_extended, FMT_OPEN),
+       SYSCALL(guarded_open_np, FMT_OPEN),
+       SYSCALL_NAMED(open_dprotected_np, open_dprotected, FMT_OPEN),
+       SYSCALL(dup, FMT_FD_2),
+       SYSCALL(dup2, FMT_FD_2),
+       SYSCALL_WITH_NOCANCEL(close, FMT_FD),
+       SYSCALL(guarded_close_np, FMT_FD),
+       SYSCALL_WITH_NOCANCEL(read, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(write, FMT_FD_IO),
+       SYSCALL(fgetxattr, FMT_FD),
+       SYSCALL(fsetxattr, FMT_FD),
+       SYSCALL(fremovexattr, FMT_FD),
+       SYSCALL(flistxattr, FMT_FD),
+       SYSCALL(fstat, FMT_FD),
+       SYSCALL(fstat64, FMT_FD),
+       SYSCALL(fstat_extended, FMT_FD),
+       SYSCALL(fstat64_extended, FMT_FD),
+       NORMAL_SYSCALL(lstat),
+       NORMAL_SYSCALL(lstat64),
+       NORMAL_SYSCALL(lstat_extended),
+       SYSCALL_NAMED(lstat64_extended, lstat_extended64, FMT_DEFAULT),
+       NORMAL_SYSCALL(link),
+       NORMAL_SYSCALL(unlink),
+       NORMAL_SYSCALL(mknod),
+       SYSCALL(umask, FMT_UMASK),
+       SYSCALL(umask_extended, FMT_UMASK),
+       SYSCALL(chmod, FMT_CHMOD),
+       SYSCALL(chmod_extended, FMT_CHMOD_EXT),
+       SYSCALL(fchmod, FMT_FCHMOD),
+       SYSCALL(fchmod_extended, FMT_FCHMOD_EXT),
+       NORMAL_SYSCALL(chown),
+       NORMAL_SYSCALL(lchown),
+       SYSCALL(fchown, FMT_FD),
+       SYSCALL(access, FMT_ACCESS),
+       NORMAL_SYSCALL(access_extended),
+       NORMAL_SYSCALL(chdir),
+       NORMAL_SYSCALL(pthread_chdir),
+       NORMAL_SYSCALL(chroot),
+       NORMAL_SYSCALL(utimes),
+       SYSCALL_NAMED(delete, delete-Carbon, FMT_DEFAULT),
+       NORMAL_SYSCALL(undelete),
+       NORMAL_SYSCALL(revoke),
+       NORMAL_SYSCALL(fsctl),
+       SYSCALL(ffsctl, FMT_FD),
+       SYSCALL(chflags, FMT_CHFLAGS),
+       SYSCALL(fchflags, FMT_FCHFLAGS),
+       SYSCALL(fchdir, FMT_FD),
+       SYSCALL(pthread_fchdir, FMT_FD),
+       SYSCALL(futimes, FMT_FD),
+       NORMAL_SYSCALL(sync),
+       NORMAL_SYSCALL(symlink),
+       NORMAL_SYSCALL(readlink),
+       SYSCALL_WITH_NOCANCEL(fsync, FMT_FD),
+       SYSCALL(fdatasync, FMT_FD),
+       SYSCALL_WITH_NOCANCEL(readv, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(writev, FMT_FD_IO),
+       SYSCALL_WITH_NOCANCEL(pread, FMT_PREAD),
+       SYSCALL_WITH_NOCANCEL(pwrite, FMT_PREAD),
+       NORMAL_SYSCALL(mkdir),
+       NORMAL_SYSCALL(mkdir_extended),
+       NORMAL_SYSCALL(mkfifo),
+       NORMAL_SYSCALL(mkfifo_extended),
+       NORMAL_SYSCALL(rmdir),
+       NORMAL_SYSCALL(statfs),
+       NORMAL_SYSCALL(statfs64),
+       NORMAL_SYSCALL(getfsstat),
+       NORMAL_SYSCALL(getfsstat64),
+       SYSCALL(fstatfs, FMT_FD),
+       SYSCALL(fstatfs64, FMT_FD),
+       NORMAL_SYSCALL(pathconf),
+       SYSCALL(fpathconf, FMT_FD),
+       SYSCALL(getdirentries, FMT_FD_IO),
+       SYSCALL(getdirentries64, FMT_FD_IO),
+       SYSCALL(lseek, FMT_LSEEK),
+       SYSCALL(truncate, FMT_TRUNC),
+       SYSCALL(ftruncate, FMT_FTRUNC),
+       SYSCALL(flock, FMT_FLOCK),
+       NORMAL_SYSCALL(getattrlist),
+       NORMAL_SYSCALL(setattrlist),
+       SYSCALL(fgetattrlist, FMT_FD),
+       SYSCALL(fsetattrlist, FMT_FD),
+       SYSCALL(getdirentriesattr, FMT_FD),
+       NORMAL_SYSCALL(exchangedata),
+       NORMAL_SYSCALL(rename),
+       NORMAL_SYSCALL(copyfile),
+       NORMAL_SYSCALL(checkuseraccess),
+       NORMAL_SYSCALL(searchfs),
+       SYSCALL(aio_fsync, FMT_AIO_FSYNC),
+       SYSCALL(aio_return, FMT_AIO_RETURN),
+       SYSCALL_WITH_NOCANCEL(aio_suspend, FMT_AIO_SUSPEND),
+       SYSCALL(aio_cancel, FMT_AIO_CANCEL),
+       SYSCALL(aio_error, FMT_AIO),
+       SYSCALL(aio_read, FMT_AIO),
+       SYSCALL(aio_write, FMT_AIO),
+       SYSCALL(lio_listio, FMT_LIO_LISTIO),
+       SYSCALL_WITH_NOCANCEL(msync, FMT_MSYNC),
+       SYSCALL_WITH_NOCANCEL(fcntl, FMT_FCNTL),
+       SYSCALL(ioctl, FMT_IOCTL),
+       NORMAL_SYSCALL(fsgetpath),
+       NORMAL_SYSCALL(getattrlistbulk),
+       SYSCALL_WITH_NOCANCEL(openat, FMT_OPENAT), /* open_nocancel() was previously shown as "open_nocanel" (note spelling) */
+       SYSCALL(renameat, FMT_RENAMEAT),
+       SYSCALL(chmodat, FMT_CHMODAT),
+       SYSCALL(chownat, FMT_AT),
+       SYSCALL(fstatat, FMT_AT),
+       SYSCALL(fstatat64, FMT_AT),
+       SYSCALL(linkat, FMT_AT),
+       SYSCALL(unlinkat, FMT_AT),
+       SYSCALL(readlinkat, FMT_AT),
+       SYSCALL(symlinkat, FMT_AT),
+       SYSCALL(mkdirat, FMT_AT),
+       SYSCALL(getattrlistat, FMT_AT),
+};
 
-void leave()                   /* exit under normal conditions -- INT handler */
+static void
+get_screenwidth(void)
 {
-        int i;
-       void set_enable();
-       void set_pidcheck();
-       void set_pidexclude();
-       void set_remove();
+       struct winsize size;
+
+       columns = MAXCOLS;
 
-       set_enable(0);
+       if (isatty(STDOUT_FILENO)) {
+               if (ioctl(1, TIOCGWINSZ, &size) != -1) {
+                       columns = size.ws_col;
 
-       if (exclude_pids == 0) {
-               for (i = 0; i < num_of_pids; i++)
-                       set_pidcheck(pids[i], 0);
-       }
-       else {
-               for (i = 0; i < num_of_pids; i++)
-                       set_pidexclude(pids[i], 0);
+                       if (columns > MAXWIDTH)
+                               columns = MAXWIDTH;
+               }
        }
-       set_remove();
-       exit(0);
 }
 
-
-void get_screenwidth()
+static uint64_t
+mach_to_nano(uint64_t mach)
 {
-        struct winsize size;
+       uint64_t nanoseconds = 0;
+       assert(ktrace_convert_timestamp_to_nanoseconds(s, mach, &nanoseconds) == 0);
 
-       columns = MAXCOLS;
-
-       if (isatty(1)) {
-               if (ioctl(1, TIOCGWINSZ, &size) != -1)
-                       columns = size.ws_col;
-       }
+       return nanoseconds;
 }
 
-
-void sigwinch()
+static void
+exit_usage(void)
 {
-        if (!wideflag)
-               get_screenwidth();
-}
+       const char *myname;
 
-int
-exit_usage(char *myname) {
+       myname = getprogname();
 
-        fprintf(stderr, "Usage: %s [-e] [-w] [-f mode] [pid | cmd [pid | cmd]....]\n", myname);
+       fprintf(stderr, "Usage: %s [-e] [-w] [-f mode] [-b] [-t seconds] [-R rawfile [-S start_time] [-E end_time]] [pid | cmd [pid | cmd] ...]\n", myname);
        fprintf(stderr, "  -e    exclude the specified list of pids from the sample\n");
        fprintf(stderr, "        and exclude fs_usage by default\n");
        fprintf(stderr, "  -w    force wider, detailed, output\n");
-       fprintf(stderr, "  -f    Output is based on the mode provided\n");
-       fprintf(stderr, "          mode = \"network\"  Show only network related output\n");
-       fprintf(stderr, "          mode = \"filesys\"  Show only file system related output\n");
-       fprintf(stderr, "          mode = \"exec\"     Show only execs\n");
-       fprintf(stderr, "          mode = \"cachehit\" In addition, show cachehits\n");
+       fprintf(stderr, "  -f    output is based on the mode provided\n");
+       fprintf(stderr, "          mode = \"network\"  Show network-related events\n");
+       fprintf(stderr, "          mode = \"filesys\"  Show filesystem-related events\n");
+       fprintf(stderr, "          mode = \"pathname\" Show only pathname-related events\n");
+       fprintf(stderr, "          mode = \"exec\"     Show only exec and spawn events\n");
+       fprintf(stderr, "          mode = \"diskio\"   Show only disk I/O events\n");
+       fprintf(stderr, "          mode = \"cachehit\" In addition, show cache hits\n");
+       fprintf(stderr, "  -b    annotate disk I/O events with BootCache info (if available)\n");
+       fprintf(stderr, "  -t    specifies timeout in seconds (for use in automated tools)\n");
+       fprintf(stderr, "  -R    specifies a raw trace file to process\n");
+       fprintf(stderr, "  -S    if -R is specified, selects a start point in microseconds\n");
+       fprintf(stderr, "  -E    if -R is specified, selects an end point in microseconds\n");
        fprintf(stderr, "  pid   selects process(s) to sample\n");
        fprintf(stderr, "  cmd   selects process(s) matching command string to sample\n");
-       fprintf(stderr, "\n%s will handle a maximum list of %d pids.\n\n", myname, MAX_PIDS);
        fprintf(stderr, "By default (no options) the following processes are excluded from the output:\n");
        fprintf(stderr, "fs_usage, Terminal, telnetd, sshd, rlogind, tcsh, csh, sh\n\n");
 
@@ -517,1693 +714,555 @@ exit_usage(char *myname) {
 }
 
 int
-main(argc, argv)
-       int     argc;
-       char    *argv[];
+main(int argc, char *argv[])
 {
-       char    *myname = "fs_usage";
-       int     i;
-       char    ch;
-       void getdivisor();
-       void argtopid();
-       void set_remove();
-       void set_pidcheck();
-       void set_pidexclude();
-       int quit();
-
-        if ( geteuid() != 0 ) {
-            fprintf(stderr, "'fs_usage' must be run as root...\n");
-            exit(1);
-        }
+       char ch;
+       int rv;
+       bool exclude_pids = false;
+       uint64_t time_limit_ns = 0;
+
        get_screenwidth();
 
-       /* get our name */
-       if (argc > 0) {
-               if ((myname = rindex(argv[0], '/')) == 0) {
-                       myname = argv[0];
-               }
-               else {
-                       myname++;
+       s = ktrace_session_create();
+       assert(s);
+
+       while ((ch = getopt(argc, argv, "bewf:R:S:E:t:W")) != -1) {
+               switch (ch) {
+                       case 'e':
+                               exclude_pids = true;
+                               break;
+
+                       case 'w':
+                               wideflag = 1;
+                               columns = MAX_WIDE_MODE_COLS;
+                               break;
+
+                       case 'W':
+                               include_waited_flag = true;
+                               break;
+
+                       case 'f':
+                               if (!strcmp(optarg, "network"))
+                                       filter_mode |= NETWORK_FILTER;
+                               else if (!strcmp(optarg, "filesys"))
+                                       filter_mode |= FILESYS_FILTER;
+                               else if (!strcmp(optarg, "cachehit"))
+                                       show_cachehits = true;
+                               else if (!strcmp(optarg, "exec"))
+                                       filter_mode |= EXEC_FILTER;
+                               else if (!strcmp(optarg, "pathname"))
+                                       filter_mode |= PATHNAME_FILTER;
+                               else if (!strcmp(optarg, "diskio"))
+                                       filter_mode |= DISKIO_FILTER;
+
+                               break;
+
+                       case 'b':
+                               BC_flag = true;
+                               break;
+
+                       case 't':
+                               time_limit_ns = (uint64_t)(NSEC_PER_SEC * atof(optarg));
+                               if (time_limit_ns == 0) {
+                                       fprintf(stderr, "ERROR: could not set time limit to %s\n",
+                                                       optarg);
+                                       exit(1);
+                               }
+                               break;
+
+                       case 'R':
+                               RAW_flag = true;
+                               rv = ktrace_set_file(s, optarg);
+                               if (rv) {
+                                       fprintf(stderr, "ERROR: reading trace from '%s' failed (%s)\n", optarg, strerror(errno));
+                                       exit(1);
+                               }
+                               break;
+
+                       case 'S':
+                               start_time_ns = NSEC_PER_SEC * atof(optarg);
+                               break;
+
+                       case 'E':
+                               end_time_ns = NSEC_PER_SEC * atof(optarg);
+                               break;
+
+                       default:
+                               exit_usage();
                }
        }
 
-       
-       while ((ch = getopt(argc, argv, "ewf:")) != EOF) {
-               switch(ch) {
-                case 'e':
-                   exclude_pids = 1;
-                   exclude_default_pids = 0;
-                   break;
-                case 'w':
-                   wideflag = 1;
-                   if ((uint)columns < MAX_WIDE_MODE_COLS)
-                     columns = MAX_WIDE_MODE_COLS;
-                   break;
-              case 'f':
-                  if (!strcmp(optarg, "network"))
-                      filter_mode |= NETWORK_FILTER;
-                  else if (!strcmp(optarg, "filesys"))
-                      filter_mode |= FILESYS_FILTER;
-                  else if (!strcmp(optarg, "cachehit"))
-                      filter_mode &= ~CACHEHIT_FILTER;   /* turns on CACHE_HIT */
-                  else if (!strcmp(optarg, "exec"))
-                      filter_mode |= EXEC_FILTER;
-                  break;
-                      
-              default:
-                exit_usage(myname);             
-              }
-       }
-
-        argc -= optind;
-        argv += optind;
-
-       /* If we process any list of pids/cmds, then turn off the defaults */
-       if (argc > 0)
-         exclude_default_pids = 0;
-
-       while (argc > 0 && num_of_pids < (MAX_PIDS - 1)) {
-         select_pid_mode++;
-         argtopid(argv[0]);
-         argc--;
-         argv++;
-       }
+       argc -= optind;
+       argv += optind;
 
-       /* Exclude a set of default pids */
-       if (exclude_default_pids)
-         {
-           argtopid("Terminal");
-           argtopid("telnetd");
-           argtopid("telnet");
-           argtopid("sshd");
-           argtopid("rlogind");
-           argtopid("tcsh");
-           argtopid("csh");
-           argtopid("sh");
-           exclude_pids = 1;
-         }
-
-       if (exclude_pids)
-         {
-           if (num_of_pids < (MAX_PIDS - 1))
-               pids[num_of_pids++] = getpid();
-           else
-             exit_usage(myname);
-         }
+       if (time_limit_ns > 0) {
+               if (RAW_flag) {
+                       fprintf(stderr, "NOTE: time limit ignored when a raw file is specified\n");
+               } else {
+                       dispatch_after(dispatch_time(DISPATCH_TIME_NOW, time_limit_ns),
+                                       dispatch_get_global_queue(QOS_CLASS_USER_INITIATED, 0),
+                       ^{
+                               ktrace_end(s, 0);
+                       });
+               }
+       }
 
-#if 0
-       for (i = 0; i < num_of_pids; i++)
-         {
-           if (exclude_pids)
-             fprintf(stderr, "exclude pid %d\n", pids[i]);
-           else
-             fprintf(stderr, "pid %d\n", pids[i]);
-         }
-#endif
+       if (!RAW_flag) {
+               if (geteuid() != 0) {
+                       fprintf(stderr, "'fs_usage' must be run as root...\n");
+                       exit(1);
+               }
 
-       /* set up signal handlers */
-       signal(SIGINT, leave);
-       signal(SIGQUIT, leave);
-       signal(SIGHUP, leave);
-       signal(SIGTERM, leave);
-       signal(SIGWINCH, sigwinch);
+               /*
+                * ktrace can't both *in*clude and *ex*clude pids, so: if we are
+                * already excluding pids, or if we are not explicitly including
+                * or excluding any pids, then exclude the defaults.
+                *
+                * if on the other hand we are explicitly including pids, we'll
+                * filter the defaults out naturally.
+                */
+               if (exclude_pids || argc == 0) {
+                       ktrace_exclude_process(s, "fs_usage");
+                       ktrace_exclude_process(s, "Terminal");
+                       ktrace_exclude_process(s, "telnetd");
+                       ktrace_exclude_process(s, "telnet");
+                       ktrace_exclude_process(s, "sshd");
+                       ktrace_exclude_process(s, "rlogind");
+                       ktrace_exclude_process(s, "tcsh");
+                       ktrace_exclude_process(s, "csh");
+                       ktrace_exclude_process(s, "sh");
+                       ktrace_exclude_process(s, "zsh");
+#if TARGET_OS_EMBEDDED
+                       ktrace_exclude_process(s, "dropbear");
+#endif /* TARGET_OS_EMBEDDED */
+               }
+       }
 
-       if ((my_buffer = malloc(SAMPLE_SIZE * sizeof(kd_buf))) == (char *)0)
-           quit("can't allocate memory for tracing info\n");
+       /*
+        * If we're *in*cluding processes, also *in*clude the kernel_task, which
+        * issues trace points when disk I/Os complete.  But set a flag for us to
+        * avoid showing events attributed to the kernel_task.
+        *
+        * If the user actually wants to those events, we'll change that flag in
+        * the loop below.
+        */
+       if (argc > 0 && !exclude_pids) {
+               ktrace_filter_pid(s, 0);
+               want_kernel_task = false;
+       }
 
-       ReadSegAddrTable();
-        cache_disk_names();
+       /*
+        * Process the list of specified pids, and in/exclude them as
+        * appropriate.
+        */
+       while (argc > 0) {
+               pid_t pid;
+               char *name;
+               char *endptr;
+
+               name = argv[0];
+               pid = (pid_t)strtoul(name, &endptr, 10);
+
+               if (*name != '\0' && *endptr == '\0') {
+                       if (exclude_pids) {
+                               rv = ktrace_exclude_pid(s, pid);
+                       } else {
+                               if (pid == 0)
+                                       want_kernel_task = true;
+                               else
+                                       rv = ktrace_filter_pid(s, pid);
+                       }
+               } else {
+                       if (exclude_pids) {
+                               rv = ktrace_exclude_process(s, name);
+                       } else {
+                               if (!strcmp(name, "kernel_task"))
+                                       want_kernel_task = true;
+                               else
+                                       rv = ktrace_filter_process(s, name);
+                       }
+               }
 
-       set_remove();
-       set_numbufs(SAMPLE_SIZE);
-       set_init();
+               if (rv == EINVAL) {
+                       fprintf(stderr, "ERROR: cannot both include and exclude simultaneously\n");
+                       exit(1);
+               } else {
+                       assert(!rv);
+               }
 
-       if (exclude_pids == 0) {
-               for (i = 0; i < num_of_pids; i++)
-                       set_pidcheck(pids[i], 1);
-       } else {
-               for (i = 0; i < num_of_pids; i++)
-                       set_pidexclude(pids[i], 1);
+               argc--;
+               argv++;
        }
 
-       if (select_pid_mode && !one_good_pid)
-         {
-           /* 
-              An attempt to restrict output to a given
-              pid or command has failed. Exit gracefully
-           */
-           set_remove();
-           exit_usage(myname);
-         }
+       /* provides SIGINT, SIGHUP, SIGPIPE, SIGTERM handlers */
+       ktrace_set_signal_handler(s);
 
-       set_enable(1);
-       getdivisor();
-       init_arguments_buffer();
+       ktrace_set_completion_handler(s, ^{
+               exit(0);
+       });
 
+       signal(SIGWINCH, SIG_IGN);
+       sigwinch_source = dispatch_source_create(DISPATCH_SOURCE_TYPE_SIGNAL, SIGWINCH, 0, dispatch_get_main_queue());
+       dispatch_source_set_event_handler(sigwinch_source, ^{
+               if (!wideflag)
+                       get_screenwidth();
+       });
+       dispatch_activate(sigwinch_source);
 
-       /* main loop */
+       init_shared_cache_mapping();
 
-       while (1) {
-               usleep(1000 * 20);
+       cache_disk_names();
 
-               sample_sc();
-       }
-}
+       setup_ktrace_callbacks();
 
-void
-find_proc_names()
-{
-        size_t                 bufSize = 0;
-       struct kinfo_proc       *kp;
-       int quit();
-
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_PROC;
-       mib[2] = KERN_PROC_ALL;
-       mib[3] = 0;
-
-       if (sysctl(mib, 4, NULL, &bufSize, NULL, 0) < 0)
-               quit("trace facility failure, KERN_PROC_ALL\n");
-
-       if((kp = (struct kinfo_proc *)malloc(bufSize)) == (struct kinfo_proc *)0)
-           quit("can't allocate memory for proc buffer\n");
-       
-       if (sysctl(mib, 4, kp, &bufSize, NULL, 0) < 0)
-               quit("trace facility failure, KERN_PROC_ALL\n");
-
-        kp_nentries = bufSize/ sizeof(struct kinfo_proc);
-       kp_buffer = kp;
-}
+       ktrace_set_dropped_events_handler(s, ^{
+               fprintf(stderr, "fs_usage: buffer overrun, events generated too quickly\n");
 
+               /* clear any state that is now potentially invalid */
 
-struct th_info *find_thread(int thread, int type) {
-       struct th_info *ti;
-
-       for (ti = th_state; ti < &th_state[cur_max]; ti++) {
-              if (ti->thread == thread) {
-                      if (type == ti->type)
-                              return(ti);
-                      if (ti->in_filemgr) {
-                              if (type == -1)
-                                      return(ti);
-                              continue;
-                      }
-                      if (type == 0)
-                              return(ti);
-              }
-       }
-       return ((struct th_info *)0);
-}
+               event_delete_all();
+               fd_clear_all();
+               meta_delete_all();
+       });
 
+       ktrace_set_default_event_names_enabled(KTRACE_FEATURE_DISABLED);
+       ktrace_set_execnames_enabled(s, KTRACE_FEATURE_LAZY);
+       ktrace_set_vnode_paths_enabled(s, true);
+       /* no need to symbolicate addresses */
+       ktrace_set_uuid_map_enabled(s, KTRACE_FEATURE_DISABLED);
 
-void
-mark_thread_waited(int thread) {
-       struct th_info *ti;
-
-       for (ti = th_state; ti < &th_state[cur_max]; ti++) {
-              if (ti->thread == thread) {
-                    ti->waited = 1;
-              }
-       }
-}
+       rv = ktrace_start(s, dispatch_get_main_queue());
 
+       if (rv) {
+               perror("ktrace_start");
+               exit(1);
+       }
 
-void
-set_enable(int val) 
-{
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDENABLE;         /* protocol */
-       mib[3] = val;
-       mib[4] = 0;
-       mib[5] = 0;                     /* no flags */
-       if (sysctl(mib, 4, NULL, &needed, NULL, 0) < 0)
-               quit("trace facility failure, KERN_KDENABLE\n");
-
-       if (val)
-         trace_enabled = 1;
-       else
-         trace_enabled = 0;
-}
+       dispatch_main();
 
-void
-set_numbufs(int nbufs) 
-{
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDSETBUF;
-       mib[3] = nbufs;
-       mib[4] = 0;
-       mib[5] = 0;                     /* no flags */
-       if (sysctl(mib, 4, NULL, &needed, NULL, 0) < 0)
-               quit("trace facility failure, KERN_KDSETBUF\n");
-
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDSETUP;          
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;                     /* no flags */
-       if (sysctl(mib, 3, NULL, &needed, NULL, 0) < 0)
-               quit("trace facility failure, KERN_KDSETUP\n");
+       return 0;
 }
 
 void
-set_pidcheck(int pid, int on_off) 
+setup_ktrace_callbacks(void)
 {
-        kd_regtype kr;
-
-       kr.type = KDBG_TYPENONE;
-       kr.value1 = pid;
-       kr.value2 = on_off;
-       needed = sizeof(kd_regtype);
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDPIDTR;
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;
-
-       if (sysctl(mib, 3, &kr, &needed, NULL, 0) < 0) {
-               if (on_off == 1)
-                       fprintf(stderr, "pid %d does not exist\n", pid);
-       }
-       else {
-         one_good_pid++;
-       }
-}
+       ktrace_events_subclass(s, DBG_MACH, DBG_MACH_EXCP_SC, ^(ktrace_event_t event) {
+               int type;
 
-/* 
-   on_off == 0 turns off pid exclusion
-   on_off == 1 turns on pid exclusion
-*/
-void
-set_pidexclude(int pid, int on_off) 
-{
-        kd_regtype kr;
-
-       one_good_pid++;
-
-       kr.type = KDBG_TYPENONE;
-       kr.value1 = pid;
-       kr.value2 = on_off;
-       needed = sizeof(kd_regtype);
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDPIDEX;
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;
-
-       if (sysctl(mib, 3, &kr, &needed, NULL, 0) < 0) {
-               if (on_off == 1)
-                         fprintf(stderr, "pid %d does not exist\n", pid);
-       }
-}
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-void
-get_bufinfo(kbufinfo_t *val)
-{
-        needed = sizeof (*val);
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDGETBUF;         
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;             /* no flags */
+               if (type == MSC_map_fd) {
+                       if (event->debugid & DBG_FUNC_START) {
+                               event_enter(type, event);
+                       } else {
+                               event_exit("map_fd", type, event, FMT_FD);
+                       }
+               }
+       });
 
-       if (sysctl(mib, 3, val, &needed, 0, 0) < 0)
-               quit("trace facility failure, KERN_KDGETBUF\n");  
+       ktrace_events_subclass(s, DBG_MACH, DBG_MACH_VM, ^(ktrace_event_t event) {
+               th_info_t ti;
+               unsigned int type;
 
-}
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-void
-set_remove() 
-{
-        errno = 0;
-
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDREMOVE;         /* protocol */
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;             /* no flags */
-       if (sysctl(mib, 3, NULL, &needed, NULL, 0) < 0)
-         {
-           set_remove_flag = 0;
-
-           if (errno == EBUSY)
-               quit("the trace facility is currently in use...\n          fs_usage, sc_usage, and latency use this feature.\n\n");
-           else
-               quit("trace facility failure, KERN_KDREMOVE\n");
-         }
-}
+               if (type != MACH_pageout && type != MACH_vmfault)
+                       return;
 
-void
-set_init() 
-{       kd_regtype kr;
-
-       kr.type = KDBG_RANGETYPE;
-       kr.value1 = 0;
-       kr.value2 = -1;
-       needed = sizeof(kd_regtype);
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDSETREG;         
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;             /* no flags */
-
-       if (sysctl(mib, 3, &kr, &needed, NULL, 0) < 0)
-               quit("trace facility failure, KERN_KDSETREG\n");
-
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDSETUP;          
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;             /* no flags */
-
-       if (sysctl(mib, 3, NULL, &needed, NULL, 0) < 0)
-               quit("trace facility failure, KERN_KDSETUP\n");
-}
+               if (event->debugid & DBG_FUNC_START) {
+                       event_enter(type, event);
+               } else {
+                       switch (type) {
+                               case MACH_pageout:
+                                       if (event->arg2)
+                                               event_exit("PAGE_OUT_ANON", type, event, FMT_PGOUT);
+                                       else
+                                               event_exit("PAGE_OUT_FILE", type, event, FMT_PGOUT);
 
-void
-sample_sc()
-{
-       kd_buf *kd;
-       int i, count;
-       size_t needed;
-       void read_command_map();
-       void create_map_entry();
-
-        /* Get kernel buffer information */
-       get_bufinfo(&bufinfo);
-
-       if (need_new_map) {
-               read_command_map();
-               need_new_map = 0;
-       }
-       needed = bufinfo.nkdbufs * sizeof(kd_buf);
-       mib[0] = CTL_KERN;
-       mib[1] = KERN_KDEBUG;
-       mib[2] = KERN_KDREADTR;         
-       mib[3] = 0;
-       mib[4] = 0;
-       mib[5] = 0;             /* no flags */
-
-       if (sysctl(mib, 3, my_buffer, &needed, NULL, 0) < 0)
-                quit("trace facility failure, KERN_KDREADTR\n");
-       count = needed;
-
-       if (bufinfo.flags & KDBG_WRAPPED) {
-               fprintf(stderr, "fs_usage: buffer overrun, events generated too quickly\n");
-
-               for (i = 0; i < cur_max; i++) {
-                       th_state[i].thread = 0;
-                       th_state[i].pid = 0;
-                       th_state[i].pathptr = (long *)0;
-                       th_state[i].pathname[0] = 0;
+                                       break;
+
+                               case MACH_vmfault:
+                                       if (event->arg4 == DBG_PAGEIN_FAULT)
+                                               event_exit("PAGE_IN", type, event, FMT_PGIN);
+                                       else if (event->arg4 == DBG_PAGEINV_FAULT)
+                                               event_exit("PAGE_IN_FILE", type, event, FMT_PGIN);
+                                       else if (event->arg4 == DBG_PAGEIND_FAULT)
+                                               event_exit("PAGE_IN_ANON", type, event, FMT_PGIN);
+                                       else if (event->arg4 == DBG_CACHE_HIT_FAULT)
+                                               event_exit("CACHE_HIT", type, event, FMT_CACHEHIT);
+                                       else if ((ti = event_find(event->threadid, type)))
+                                               event_delete(ti);
+
+                                       break;
+
+                               default:
+                                       abort();
+                       }
                }
-               cur_max = 0;
-               need_new_map = 1;
-               
-               set_enable(0);
-               set_enable(1);
+       });
+
+       if (include_waited_flag || RAW_flag) {
+               ktrace_events_subclass(s, DBG_MACH, DBG_MACH_SCHED, ^(ktrace_event_t event) {
+                       int type;
+
+                       type = event->debugid & KDBG_EVENTID_MASK;
+
+                       switch (type) {
+                               case MACH_idle:
+                               case MACH_sched:
+                               case MACH_stkhandoff:
+                                       event_mark_thread_waited(event->threadid);
+                       }
+               });
        }
-       kd = (kd_buf *)my_buffer;
-#if 0
-       fprintf(stderr, "READTR returned %d items\n", count);
-#endif
-       for (i = 0; i < count; i++) {
-               int debugid, thread;
-               int type, n;
-               long *sargptr;
-               uint64_t now;
-               long long l_usecs;
-               int secs;
-               long curr_time;
-               struct th_info *ti;
-                struct diskio  *dio;
-
-
-               thread  = kd[i].arg5;
-               debugid = kd[i].debugid;
-               type    = kd[i].debugid & DBG_FUNC_MASK;
-
-                now = kd[i].timestamp & KDBG_TIMESTAMP_MASK;
-
-               if (i == 0)
-               {
-                   /*
-                    * Compute bias seconds after each trace buffer read.
-                    * This helps resync timestamps with the system clock
-                    * in the event of a system sleep.
-                    */
-                   l_usecs = (long long)(now / divisor);
-                   secs = l_usecs / 1000000;
-                   curr_time = time((long *)0);
-                   bias_secs = curr_time - secs;
-               }
 
+       ktrace_events_subclass(s, DBG_FSYSTEM, DBG_FSRW, ^(ktrace_event_t event) {
+               th_info_t ti;
+               int type;
 
-               switch (type) {
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-                case P_RdMeta:
-                case P_WrMeta:
-                case P_RdData:
-                case P_WrData:
-                case P_PgIn:
-                case P_PgOut:
-                case P_RdMetaAsync:
-                case P_WrMetaAsync:
-                case P_RdDataAsync:
-                case P_WrDataAsync:
-                case P_PgInAsync:
-                case P_PgOutAsync:
-                    insert_diskio(type, kd[i].arg1, kd[i].arg2, kd[i].arg3, kd[i].arg4, thread, (double)now);
-                    continue;
-                
-                case P_RdMetaDone:
-                case P_WrMetaDone:
-                case P_RdDataDone:
-                case P_WrDataDone:
-                case P_PgInDone:
-                case P_PgOutDone:
-                case P_RdMetaAsyncDone:
-                case P_WrMetaAsyncDone:
-                case P_RdDataAsyncDone:
-                case P_WrDataAsyncDone:
-                case P_PgInAsyncDone:
-                case P_PgOutAsyncDone:
-                    if ((dio = complete_diskio(kd[i].arg1, kd[i].arg4, kd[i].arg3, thread, (double)now))) {
-                        print_diskio(dio);
-                        free_diskio(dio);
-                    }
-                    continue;
-
-
-               case TRACE_DATA_NEWTHREAD:
-                   
-                   for (n = 0, ti = th_state; ti < &th_state[MAX_THREADS]; ti++, n++) {
-                       if (ti->thread == 0)
-                          break;
-                   }
-                   if (ti == &th_state[MAX_THREADS])
-                       continue;
-                   if (n >= cur_max)
-                       cur_max = n + 1;
-
-                   ti->thread = thread;
-                   ti->child_thread = kd[i].arg1;
-                   ti->pid = kd[i].arg2;
-                   continue;
-
-               case TRACE_STRING_NEWTHREAD:
-                   if ((ti = find_thread(thread, 0)) == (struct th_info *)0)
-                           continue;
-                   if (ti->child_thread == 0)
-                           continue;
-                   create_map_entry(ti->child_thread, ti->pid, (char *)&kd[i].arg1);
-
-                   if (ti == &th_state[cur_max - 1])
-                       cur_max--;
-                   ti->child_thread = 0;
-                   ti->thread = 0;
-                   ti->pid = 0;
-                   continue;
-       
-               case TRACE_DATA_EXEC:
-
-                   for (n = 0, ti = th_state; ti < &th_state[MAX_THREADS]; ti++, n++) {
-                       if (ti->thread == 0)
-                          break;
-                   }
-                   if (ti == &th_state[MAX_THREADS])
-                       continue;
-                   if (n >= cur_max)
-                       cur_max = n + 1;
-
-                   ti->thread = thread;
-                   ti->pid = kd[i].arg1;
-                   continue;       
-
-               case TRACE_STRING_EXEC:
-                   if ((ti = find_thread(thread, 0)) == (struct th_info *)0)
-                   {
-                       /* this is for backwards compatibility */
-                       create_map_entry(thread, 0, (char *)&kd[i].arg1);
-                   }
-                   else
-                   {
-                       create_map_entry(thread, ti->pid, (char *)&kd[i].arg1);
-
-                       if (ti == &th_state[cur_max - 1])
-                           cur_max--;
-                       ti->thread = 0;
-                       ti->pid = 0;
-                   }
-                   continue;
-
-               case BSC_exit:
-                   kill_thread_map(thread);
-                   continue;
-
-               case MACH_sched:
-               case MACH_stkhandoff:
-                    mark_thread_waited(thread);
-                   continue;
-
-               case VFS_LOOKUP:
-                   if ((ti = find_thread(thread, 0)) == (struct th_info *)0)
-                           continue;
-
-                   if (!ti->pathptr) {
-                           sargptr = (long *)&ti->pathname[0];
-                           memset(&ti->pathname[0], 0, (PATHLENGTH + 1));
-                           *sargptr++ = kd[i].arg2;
-                           *sargptr++ = kd[i].arg3;
-                           *sargptr++ = kd[i].arg4;
-                           ti->pathptr = sargptr;
-                   } else {
-                           sargptr = ti->pathptr;
-
-                           /* 
-                              We don't want to overrun our pathname buffer if the
-                              kernel sends us more VFS_LOOKUP entries than we can
-                              handle.
-                           */
-
-                           if ((long *)sargptr >= (long *)&ti->pathname[PATHLENGTH]) {
-                               continue;
-                           }
-                            /*
-                             We need to detect consecutive vfslookup entries.
-                             So, if we get here and find a START entry,
-                             fake the pathptr so we can bypass all further
-                             vfslookup entries.
-                           */
-
-                           if (debugid & DBG_FUNC_START) {
-                               (long *)ti->pathptr = (long *)&ti->pathname[PATHLENGTH];
-                               continue;
-                           }
-
-                           *sargptr++ = kd[i].arg1;
-                           *sargptr++ = kd[i].arg2;
-                           *sargptr++ = kd[i].arg3;
-                           *sargptr++ = kd[i].arg4;
-                           ti->pathptr = sargptr;
-                   }
-                   continue;
+               switch (type) {
+                       case HFS_modify_block_end:
+                               /*
+                                * the expected path here is as follows:
+                                * enter syscall
+                                * look up a path, which gets stored in ti->vnode / ti->pathname
+                                * modify a metadata block -- we assume the modification has something to do with the path that was looked up
+                                * leave syscall
+                                * ...
+                                * later, someone writes that metadata block; the last path associated with it is attributed
+                                */
+                               if ((ti = event_find(event->threadid, 0))) {
+                                       if (ti->newest_pathname)
+                                               meta_add_name(event->arg2, ti->newest_pathname);
+                               }
+
+                               break;
+
+                       case VFS_LOOKUP:
+                               if (event->debugid & DBG_FUNC_START) {
+                                       if ((ti = event_find(event->threadid, 0)) && !ti->vnodeid) {
+                                               ti->vnodeid = event->arg1;
+                                       }
+                               }
+
+                               /* it can be both start and end */
+
+                               if (event->debugid & DBG_FUNC_END) {
+                                       if ((ti = event_find(event->threadid, 0)) && ti->vnodeid) {
+                                               const char *pathname;
+
+                                               pathname = ktrace_get_path_for_vp(s, ti->vnodeid);
+
+                                               ti->vnodeid = 0;
+
+                                               if (pathname) {
+                                                       if (ti->pathname[0] == '\0') {
+                                                               strncpy(ti->pathname, pathname, MAXPATHLEN);
+                                                               ti->newest_pathname = ti->pathname;
+                                                       } else if (ti->pathname2[0] == '\0') {
+                                                               strncpy(ti->pathname2, pathname, MAXPATHLEN);
+                                                               ti->newest_pathname = ti->pathname2;
+                                                       }
+                                               }
+                                       }
+                               }
+
+                               break;
                }
 
-               if (debugid & DBG_FUNC_START) {
-                      char *p;
+               if (type != Throttled && type != HFS_update)
+                       return;
 
-                      switch (type) {
-                          case FILEMGR_PBGETCATALOGINFO:
-                                       p = "GetCatalogInfo";
-                                       break;
-                          case FILEMGR_PBGETCATALOGINFOBULK:
-                                       p = "GetCatalogInfoBulk";
-                                       break;
-                          case FILEMGR_PBCREATEFILEUNICODE:
-                                       p = "CreateFileUnicode";
-                                       break;
-                          case FILEMGR_PBCREATEDIRECTORYUNICODE:
-                                       p = "CreateDirectoryUnicode";
-                                       break;
-                          case FILEMGR_PBCREATEFORK:
-                                       p = "PBCreateFork";
-                                       break;
-                          case FILEMGR_PBDELETEFORK:
-                                       p = "PBDeleteFork";
-                                       break;
-                          case FILEMGR_PBITERATEFORK:
-                                       p = "PBIterateFork";
-                                       break;
-                          case FILEMGR_PBOPENFORK:
-                                       p = "PBOpenFork";
-                                       break;
-                          case FILEMGR_PBREADFORK:
-                                       p = "PBReadFork";
-                                       break;
-                          case FILEMGR_PBWRITEFORK:
-                                       p = "PBWriteFork";
-                                       break;
-                          case FILEMGR_PBALLOCATEFORK:
-                                       p = "PBAllocateFork";
-                                       break;
-                          case FILEMGR_PBDELETEOBJECT:
-                                       p = "PBDeleteObject";
-                                       break;
-                          case FILEMGR_PBEXCHANGEOBJECT:
-                                       p = "PBExchangeObject";
-                                       break;
-                          case FILEMGR_PBGETFORKCBINFO:
-                                       p = "PBGetForkCBInfo";
-                                       break;
-                          case FILEMGR_PBGETVOLUMEINFO:
-                                       p = "PBGetVolumeInfo";
-                                       break;
-                          case FILEMGR_PBMAKEFSREF:
-                                       p = "PBMakeFSRef";
-                                       break;
-                          case FILEMGR_PBMAKEFSREFUNICODE:
-                                       p = "PBMakeFSRefUnicode";
-                                       break;
-                          case FILEMGR_PBMOVEOBJECT:
-                                       p = "PBMoveObject";
-                                       break;
-                          case FILEMGR_PBOPENITERATOR:
-                                       p = "PBOpenIterator";
-                                       break;
-                          case FILEMGR_PBRENAMEUNICODE:
-                                       p = "PBRenameUnicode";
-                                       break;
-                          case FILEMGR_PBSETCATALOGINFO:
-                                       p = "SetCatalogInfo";
-                                       break;
-                          case FILEMGR_PBSETVOLUMEINFO:
-                                       p = "SetVolumeInfo";
-                                       break;
-                          case FILEMGR_FSREFMAKEPATH:
-                                       p = "FSRefMakePath";
-                                       break;
-                          case FILEMGR_FSPATHMAKEREF:
-                                       p = "FSPathMakeRef";
-                                       break;
-                          // SPEC based calls
-                          case FILEMGR_PBGETCATINFO:
-                                       p = "GetCatInfo";
-                                       break;
-                          case FILEMGR_PBGETCATINFOLITE:
-                                       p = "GetCatInfoLite";
-                                       break;
-                          case FILEMGR_PBHGETFINFO:
-                                       p = "PBHGetFInfo";
-                                       break;
-                          case FILEMGR_PBXGETVOLINFO:
-                                       p = "PBXGetVolInfo";
-                                       break;
-                          case FILEMGR_PBHCREATE:
-                                       p = "PBHCreate";
-                                       break;
-                          case FILEMGR_PBHOPENDF:
-                                       p = "PBHOpenDF";
-                                       break;
-                          case FILEMGR_PBHOPENRF:
-                                       p = "PBHOpenRF";
-                                       break;
-                          case FILEMGR_PBHGETDIRACCESS:
-                                       p = "PBHGetDirAccess";
-                                       break;
-                          case FILEMGR_PBHSETDIRACCESS:
-                                       p = "PBHSetDirAccess";
-                                       break;
-                          case FILEMGR_PBHMAPID:
-                                       p = "PBHMapID";
-                                       break;
-                          case FILEMGR_PBHMAPNAME:
-                                       p = "PBHMapName";
-                                       break;
-                          case FILEMGR_PBCLOSE:
-                                       p = "PBClose";
-                                       break;
-                          case FILEMGR_PBFLUSHFILE:
-                                       p = "PBFlushFile";
-                                       break;
-                          case FILEMGR_PBGETEOF:
-                                       p = "PBGetEOF";
-                                       break;
-                          case FILEMGR_PBSETEOF:
-                                       p = "PBSetEOF";
-                                       break;
-                          case FILEMGR_PBGETFPOS:
-                                       p = "PBGetFPos";
-                                       break;
-                          case FILEMGR_PBREAD:
-                                       p = "PBRead";
-                                       break;
-                          case FILEMGR_PBWRITE:
-                                       p = "PBWrite";
-                                       break;
-                          case FILEMGR_PBGETFCBINFO:
-                                       p = "PBGetFCBInfo";
-                                       break;
-                          case FILEMGR_PBSETFINFO:
-                                       p = "PBSetFInfo";
-                                       break;
-                          case FILEMGR_PBALLOCATE:
-                                       p = "PBAllocate";
-                                       break;
-                          case FILEMGR_PBALLOCCONTIG:
-                                       p = "PBAllocContig";
-                                       break;
-                          case FILEMGR_PBSETFPOS:
-                                       p = "PBSetFPos";
-                                       break;
-                          case FILEMGR_PBSETCATINFO:
-                                       p = "PBSetCatInfo";
-                                       break;
-                          case FILEMGR_PBGETVOLPARMS:
-                                       p = "PBGetVolParms";
-                                       break;
-                          case FILEMGR_PBSETVINFO:
-                                       p = "PBSetVInfo";
-                                       break;
-                          case FILEMGR_PBMAKEFSSPEC:
-                                       p = "PBMakeFSSpec";
-                                       break;
-                          case FILEMGR_PBHGETVINFO:
-                                       p = "PBHGetVInfo";
-                                       break;
-                          case FILEMGR_PBCREATEFILEIDREF:
-                                       p = "PBCreateFileIDRef";
-                                       break;
-                          case FILEMGR_PBDELETEFILEIDREF:
-                                       p = "PBDeleteFileIDRef";
-                                       break;
-                          case FILEMGR_PBRESOLVEFILEIDREF:
-                                       p = "PBResolveFileIDRef";
-                                       break;
-                          case FILEMGR_PBFLUSHVOL:
-                                       p = "PBFlushVol";
-                                       break;
-                          case FILEMGR_PBHRENAME:
-                                       p = "PBHRename";
-                                       break;
-                          case FILEMGR_PBCATMOVE:
-                                       p = "PBCatMove";
-                                       break;
-                          case FILEMGR_PBEXCHANGEFILES:
-                                       p = "PBExchangeFiles";
-                                       break;
-                          case FILEMGR_PBHDELETE:
-                                       p = "PBHDelete";
-                                       break;
-                          case FILEMGR_PBDIRCREATE:
-                                       p = "PBDirCreate";
-                                       break;
-                          case FILEMGR_PBCATSEARCH:
-                                       p = "PBCatSearch";
-                                       break;
-                          case FILEMGR_PBHSETFLOCK:
-                                       p = "PBHSetFlock";
-                                       break;
-                          case FILEMGR_PBHRSTFLOCK:
-                                       p = "PBHRstFLock";
-                                       break;
-                          case FILEMGR_PBLOCKRANGE:
-                                       p = "PBLockRange";
-                                       break;
-                          case FILEMGR_PBUNLOCKRANGE:
-                                       p = "PBUnlockRange";
+               if (event->debugid & DBG_FUNC_START) {
+                       event_enter(type, event);
+               } else {
+                       switch (type) {
+                               case Throttled:
+                                       event_exit("  THROTTLED", type, event, FMT_NOTHING);
                                        break;
-                          default:
-                                       p = (char *)0;
+
+                               case HFS_update:
+                                       event_exit("  HFS_update", type, event, FMT_HFS_update);
                                        break;
+
+                               default:
+                                       abort();
                        }
-                       enter_syscall(thread, type, &kd[i], p, (double)now);
-                       continue;
                }
-               
-               switch (type) {
-                   
-               case BSC_pread_extended:
-               case BSC_pwrite_extended:
-                   extend_syscall(thread, type, &kd[i], (double)now);
+       });
 
-               case MACH_pageout:
-                   if (kd[i].arg2) 
-                           exit_syscall("PAGE_OUT_D", thread, type, 0, kd[i].arg1, 0, 4, (double)now);
-                   else
-                           exit_syscall("PAGE_OUT_V", thread, type, 0, kd[i].arg1, 0, 4, (double)now);
-                   break;
+       ktrace_events_subclass(s, DBG_FSYSTEM, DBG_DKRW, ^(ktrace_event_t event) {
+               struct diskio *dio;
+               unsigned int type;
 
-               case MACH_vmfault:
-                   if (kd[i].arg2 == DBG_PAGEIN_FAULT)
-                           exit_syscall("PAGE_IN", thread, type, kd[i].arg4, kd[i].arg1, 0, 6, (double)now);
-                    else if (kd[i].arg2 == DBG_CACHE_HIT_FAULT)
-                           exit_syscall("CACHE_HIT", thread, type, 0, kd[i].arg1, 0, 2, (double)now);
-                   else {
-                           if ((ti = find_thread(thread, type))) {
-                                   if (ti == &th_state[cur_max - 1])
-                                           cur_max--;
-                                   ti->thread = 0;
-                           }
-                   }
-                   break;
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-               case MSC_map_fd:
-                   exit_syscall("map_fd", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
+               if ((type & P_DISKIO_MASK) == P_DISKIO) {
+                       diskio_start(type, event->arg1, event->arg2, event->arg3, event->arg4, event);
+               } else if ((type & P_DISKIO_MASK) == P_DISKIO_DONE) {
+                       if ((dio = diskio_complete(event->arg1, event->arg4, event->arg3, event->threadid, event->timestamp, event->walltime))) {
+                               dio->vnodeid = event->arg2;
+                               diskio_print(dio);
+                               diskio_free(dio);
+                       }
+               }
+       });
 
-               case BSC_mmap:
-                   exit_syscall("mmap", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                   
-               case BSC_recvmsg:
-                   exit_syscall("recvmsg", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
+       ktrace_events_subclass(s, DBG_FSYSTEM, DBG_IOCTL, ^(ktrace_event_t event) {
+               th_info_t ti;
+               int type;
+               pid_t pid;
 
-               case BSC_sendmsg:
-                   exit_syscall("sendmsg", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-               case BSC_recvfrom:
-                   exit_syscall("recvfrom", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
+               switch (type) {
+                       case SPEC_unmap_info:
+                               pid = ktrace_get_pid_for_thread(s, event->threadid);
+
+                               if (check_filter_mode(pid, NULL, SPEC_unmap_info, 0, 0, "SPEC_unmap_info"))
+                                       format_print(NULL, "  TrimExtent", event, type, FMT_UNMAP_INFO, event->timestamp, event->timestamp, 0, "", NULL);
+
+                               break;
+
+                       case SPEC_ioctl:
+                               if (event->debugid & DBG_FUNC_START) {
+                                       event_enter(type, event);
+                               } else {
+                                       if (event->arg2 == DKIOCSYNCHRONIZECACHE)
+                                               event_exit("IOCTL", type, event, FMT_IOCTL_SYNCCACHE);
+                                       else if (event->arg2 == DKIOCUNMAP)
+                                               event_exit("IOCTL", type, event, FMT_IOCTL_UNMAP);
+                                       else if (event->arg2 == DKIOCSYNCHRONIZE && (event->debugid & DBG_FUNC_ALL) == DBG_FUNC_NONE)
+                                               event_exit("IOCTL", type, event, FMT_IOCTL_SYNC);
+                                       else if ((ti = event_find(event->threadid, type)))
+                                               event_delete(ti);
+                               }
+
+                               break;
+               }
+       });
+
+       if (BC_flag || RAW_flag) {
+               ktrace_events_subclass(s, DBG_FSYSTEM, DBG_BOOTCACHE, ^(ktrace_event_t event) {
+                       struct diskio *dio;
+                       unsigned int type;
+
+                       type = event->debugid & KDBG_EVENTID_MASK;
+
+                       switch (type) {
+                               case BC_IO_HIT:
+                               case BC_IO_HIT_STALLED:
+                               case BC_IO_MISS:
+                               case BC_IO_MISS_CUT_THROUGH:
+                               case BC_PLAYBACK_IO:
+                                       if ((dio = diskio_find(event->arg1)) != NULL)
+                                               dio->bc_info = type;
+                       }
+               });
+       }
 
-               case BSC_accept:
-                   exit_syscall("accept", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;
-                   
-               case BSC_select:
-                   exit_syscall("select", thread, type, kd[i].arg1, kd[i].arg2, 0, 8, (double)now);
-                   break;
-                   
-               case BSC_socket:
-                   exit_syscall("socket", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;
+       void (^bsd_sc_proc_cb)(ktrace_event_t event) = ^(ktrace_event_t event) {
+               int type, index;
+               pid_t pid;
 
-               case BSC_connect:
-                   exit_syscall("connect", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
+               type = event->debugid & KDBG_EVENTID_MASK;
 
-               case BSC_bind:
-                   exit_syscall("bind", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
+               switch (type) {
+                       case BSC_exit: /* see below */
+                               return;
 
-               case BSC_listen:
-                   exit_syscall("listen", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
+                       case proc_exit:
+                               event->arg1 = event->arg2 >> 8;
+                               type = BSC_exit;
 
-               case BSC_sendto:
-                   exit_syscall("sendto", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
+                               pid = ktrace_get_pid_for_thread(s, event->threadid);
+                               fd_clear_pid(pid);
 
-               case BSC_socketpair:
-                   exit_syscall("socketpair", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                   
-               case BSC_getxattr:
-                   exit_syscall("getxattr", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_setxattr:
-                   exit_syscall("setxattr", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_removexattr:
-                   exit_syscall("removexattr", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_listxattr:
-                   exit_syscall("listxattr", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_stat:
-                   exit_syscall("stat", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_stat_extended:
-                   exit_syscall("stat_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_execve:
-                   exit_syscall("execve", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_load_shared_file:
-                   exit_syscall("load_sf", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_open:
-                   exit_syscall("open", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;
-
-               case BSC_open_extended:
-                   exit_syscall("open_extended", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;
+                               break;
 
-               case BSC_dup:
-                   exit_syscall("dup", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;
+                       case BSC_mmap:
+                               if (event->arg4 & MAP_ANON)
+                                       return;
 
-               case BSC_dup2:
-                   exit_syscall("dup2", thread, type, kd[i].arg1, kd[i].arg2, 2, 0, (double)now);
-                   break;                  
+                               break;
+               }
 
-               case BSC_close:
-                   exit_syscall("close", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
+               if ((index = BSC_INDEX(type)) >= MAX_BSD_SYSCALL)
+                       return;
 
-               case BSC_read:
-                   exit_syscall("read", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
+               if (!bsd_syscalls[index].sc_name)
+                       return;
 
-               case BSC_write:
-                   exit_syscall("write", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
-
-               case BSC_fgetxattr:
-                   exit_syscall("fgetxattr", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fsetxattr:
-                   exit_syscall("fsetxattr", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fremovexattr:
-                   exit_syscall("fremovexattr", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_flistxattr:
-                   exit_syscall("flistxattr", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fstat:
-                   exit_syscall("fstat", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fstat_extended:
-                   exit_syscall("fstat_extended", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_lstat:
-                   exit_syscall("lstat", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_lstat_extended:
-                   exit_syscall("lstat_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_link:
-                   exit_syscall("link", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_unlink:
-                   exit_syscall("unlink", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_mknod:
-                   exit_syscall("mknod", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_chmod:
-                   exit_syscall("chmod", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_chmod_extended:
-                   exit_syscall("chmod_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_chown:
-                   exit_syscall("chown", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_lchown:
-                   exit_syscall("lchown", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_access:
-                   exit_syscall("access", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_access_extended:
-                   exit_syscall("access_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_chdir:
-                   exit_syscall("chdir", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_chroot:
-                   exit_syscall("chroot", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_utimes:
-                   exit_syscall("utimes", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_delete:
-                   exit_syscall("delete", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_undelete:
-                   exit_syscall("undelete", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_revoke:
-                   exit_syscall("revoke", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_fsctl:
-                   exit_syscall("fsctl", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_chflags:
-                   exit_syscall("chflags", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_fchflags:
-                   exit_syscall("fchflags", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-                    
-               case BSC_fchdir:
-                   exit_syscall("fchdir", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-                    
-               case BSC_futimes:
-                   exit_syscall("futimes", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_sync:
-                   exit_syscall("sync", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_symlink:
-                   exit_syscall("symlink", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_readlink:
-                   exit_syscall("readlink", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_fsync:
-                   exit_syscall("fsync", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_readv:
-                   exit_syscall("readv", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
-
-               case BSC_writev:
-                   exit_syscall("writev", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
-
-               case BSC_pread:
-                   exit_syscall("pread", thread, type, kd[i].arg1, kd[i].arg2, 1, 9, (double)now);
-                   break;
-
-               case BSC_pwrite:
-                   exit_syscall("pwrite", thread, type, kd[i].arg1, kd[i].arg2, 1, 9, (double)now);
-                   break;
-
-               case BSC_fchown:
-                   exit_syscall("fchown", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fchmod:
-                   exit_syscall("fchmod", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_fchmod_extended:
-                   exit_syscall("fchmod_extended", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_mkdir:
-                   exit_syscall("mkdir", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_mkdir_extended:
-                   exit_syscall("mkdir_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_mkfifo:
-                   exit_syscall("mkfifo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_mkfifo_extended:
-                   exit_syscall("mkfifo_extended", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_rmdir:
-                   exit_syscall("rmdir", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_statfs:
-                   exit_syscall("statfs", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_fstatfs:
-                   exit_syscall("fstatfs", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_pathconf:
-                   exit_syscall("pathconf", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_fpathconf:
-                   exit_syscall("fpathconf", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_getdirentries:
-                   exit_syscall("getdirentries", thread, type, kd[i].arg1, kd[i].arg2, 1, 1, (double)now);
-                   break;
-
-               case BSC_lseek:
-                   exit_syscall("lseek", thread, type, kd[i].arg1, kd[i].arg3, 1, 5, (double)now);
-                   break;
-
-               case BSC_truncate:
-                   exit_syscall("truncate", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_ftruncate:
-                   exit_syscall("ftruncate", thread, type, kd[i].arg1, kd[i].arg2, 1, 3, (double)now);
-                   break;
-
-               case BSC_statv:
-                   exit_syscall("statv", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_lstatv:
-                   exit_syscall("lstatv", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_fstatv:
-                   exit_syscall("fstatv", thread, type, kd[i].arg1, kd[i].arg2, 1, 0, (double)now);
-                   break;
-
-               case BSC_mkcomplex:
-                   exit_syscall("mkcomplex", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_getattrlist:
-                   exit_syscall("getattrlist", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_setattrlist:
-                   exit_syscall("setattrlist", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_getdirentriesattr:
-                   exit_syscall("getdirentriesattr", thread, type, kd[i].arg1, kd[i].arg2, 0, 1, (double)now);
-                   break;
-
-
-               case BSC_exchangedata:
-                   exit_syscall("exchangedata", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-                    
-               case BSC_rename:
-                   exit_syscall("rename", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_copyfile:
-                   exit_syscall("copyfile", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-
-               case BSC_checkuseraccess:
-                   exit_syscall("checkuseraccess", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-               case BSC_searchfs:
-                   exit_syscall("searchfs", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-
-          case FILEMGR_PBGETCATALOGINFO:
-                   exit_syscall("GetCatalogInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETCATALOGINFOBULK:
-                   exit_syscall("GetCatalogInfoBulk", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCREATEFILEUNICODE:
-                   exit_syscall("CreateFileUnicode", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCREATEDIRECTORYUNICODE:
-                   exit_syscall("CreateDirectoryUnicode", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCREATEFORK:
-                   exit_syscall("PBCreateFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBDELETEFORK:
-                   exit_syscall("PBDeleteFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBITERATEFORK:
-                   exit_syscall("PBIterateFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBOPENFORK:
-                   exit_syscall("PBOpenFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBREADFORK:
-                   exit_syscall("PBReadFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBWRITEFORK:
-                   exit_syscall("PBWriteFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBALLOCATEFORK:
-                   exit_syscall("PBAllocateFork", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBDELETEOBJECT:
-                   exit_syscall("PBDeleteObject", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBEXCHANGEOBJECT:
-                   exit_syscall("PBExchangeObject", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETFORKCBINFO:
-                   exit_syscall("PBGetForkCBInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETVOLUMEINFO:
-                   exit_syscall("PBGetVolumeInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBMAKEFSREF:
-                   exit_syscall("PBMakeFSRef", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBMAKEFSREFUNICODE:
-                   exit_syscall("PBMakeFSRefUnicode", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBMOVEOBJECT:
-                   exit_syscall("PBMoveObject", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBOPENITERATOR:
-                   exit_syscall("PBOpenIterator", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBRENAMEUNICODE:
-                   exit_syscall("PBRenameUnicode", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETCATALOGINFO:
-                   exit_syscall("PBSetCatalogInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETVOLUMEINFO:
-                   exit_syscall("PBSetVolumeInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_FSREFMAKEPATH:
-                   exit_syscall("FSRefMakePath", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_FSPATHMAKEREF:
-                   exit_syscall("FSPathMakeRef", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETCATINFO:
-                   exit_syscall("GetCatInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETCATINFOLITE:
-                   exit_syscall("GetCatInfoLite", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHGETFINFO:
-                   exit_syscall("PBHGetFInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBXGETVOLINFO:
-                   exit_syscall("PBXGetVolInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHCREATE:
-                   exit_syscall("PBHCreate", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHOPENDF:
-                   exit_syscall("PBHOpenDF", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHOPENRF:
-                   exit_syscall("PBHOpenRF", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHGETDIRACCESS:
-                   exit_syscall("PBHGetDirAccess", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHSETDIRACCESS:
-                   exit_syscall("PBHSetDirAccess", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHMAPID:
-                   exit_syscall("PBHMapID", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHMAPNAME:
-                   exit_syscall("PBHMapName", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCLOSE:
-                   exit_syscall("PBClose", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBFLUSHFILE:
-                   exit_syscall("PBFlushFile", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETEOF:
-                   exit_syscall("PBGetEOF", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETEOF:
-                   exit_syscall("PBSetEOF", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETFPOS:
-                   exit_syscall("PBGetFPos", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBREAD:
-                   exit_syscall("PBRead", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBWRITE:
-                   exit_syscall("PBWrite", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETFCBINFO:
-                   exit_syscall("PBGetFCBInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETFINFO:
-                   exit_syscall("PBSetFInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBALLOCATE:
-                   exit_syscall("PBAllocate", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBALLOCCONTIG:
-                   exit_syscall("PBAllocContig", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETFPOS:
-                   exit_syscall("PBSetFPos", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETCATINFO:
-                   exit_syscall("PBSetCatInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBGETVOLPARMS:
-                   exit_syscall("PBGetVolParms", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBSETVINFO:
-                   exit_syscall("PBSetVInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBMAKEFSSPEC:
-                   exit_syscall("PBMakeFSSpec", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHGETVINFO:
-                   exit_syscall("PBHGetVInfo", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCREATEFILEIDREF:
-                   exit_syscall("PBCreateFileIDRef", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBDELETEFILEIDREF:
-                   exit_syscall("PBDeleteFileIDRef", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBRESOLVEFILEIDREF:
-                   exit_syscall("PBResolveFileIDRef", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBFLUSHVOL:
-                   exit_syscall("PBFlushVol", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHRENAME:
-                   exit_syscall("PBHRename", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCATMOVE:
-                   exit_syscall("PBCatMove", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBEXCHANGEFILES:
-                   exit_syscall("PBExchangeFiles", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHDELETE:
-                   exit_syscall("PBHDelete", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBDIRCREATE:
-                   exit_syscall("PBDirCreate", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBCATSEARCH:
-                   exit_syscall("PBCatSearch", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHSETFLOCK:
-                   exit_syscall("PBHSetFLock", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBHRSTFLOCK:
-                   exit_syscall("PBHRstFLock", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBLOCKRANGE:
-                   exit_syscall("PBLockRange", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-          case FILEMGR_PBUNLOCKRANGE:
-                   exit_syscall("PBUnlockRange", thread, type, kd[i].arg1, kd[i].arg2, 0, 0, (double)now);
-                   break;
-               default:
-                   break;
+               if (event->debugid & DBG_FUNC_START) {
+                       event_enter(type, event);
+               } else {
+                       event_exit(bsd_syscalls[index].sc_name, type, event, bsd_syscalls[index].sc_format);
                }
-       }
-       fflush(0);
-}
+       };
+
+       ktrace_events_subclass(s, DBG_BSD, DBG_BSD_EXCP_SC, bsd_sc_proc_cb);
+       ktrace_events_subclass(s, DBG_BSD, DBG_BSD_PROC, bsd_sc_proc_cb);
+
+       ktrace_events_range(s, KDBG_EVENTID(DBG_BSD, DBG_BSD_SC_EXTENDED_INFO, 0), KDBG_EVENTID(DBG_BSD, DBG_BSD_SC_EXTENDED_INFO2 + 1, 0), ^(ktrace_event_t event) {
+               extend_syscall(event->threadid, event->debugid & KDBG_EVENTID_MASK, event);
+       });
+
+       ktrace_events_subclass(s, DBG_CORESTORAGE, DBG_CS_IO, ^(ktrace_event_t event) {
+               // the usual DBG_FUNC_START/END does not work for i/o since it will
+               // return on a different thread, this code uses the P_CS_IO_Done (0x4) bit
+               // instead. the trace command doesn't know how handle either method
+               // (unmatched start/end or 0x4) but works a little better this way.
+
+               struct diskio *dio;
+               int cs_type = event->debugid & P_CS_Type_Mask;   // strip out the done bit
+               bool start = (event->debugid & P_CS_IO_Done) != P_CS_IO_Done;
+
+               switch (cs_type) {
+                       case P_CS_ReadChunk:
+                       case P_CS_WriteChunk:
+                       case P_CS_MetaRead:
+                       case P_CS_MetaWrite:
+                               if (start) {
+                                       diskio_start(cs_type, event->arg2, event->arg1, event->arg3, event->arg4, event);
+                               } else {
+                                       if ((dio = diskio_complete(event->arg2, event->arg4, event->arg3, event->threadid, event->timestamp, event->walltime))) {
+                                               diskio_print(dio);
+                                               diskio_free(dio);
+                                       }
+                               }
+
+                               break;
+                       case P_CS_TransformRead:
+                       case P_CS_TransformWrite:
+                       case P_CS_MigrationRead:
+                       case P_CS_MigrationWrite:
+                               if (start) {
+                                       diskio_start(cs_type, event->arg2, CS_DEV, event->arg3, event->arg4, event);
+                               } else {
+                                       if ((dio = diskio_complete(event->arg2, event->arg4, event->arg3, event->threadid, event->timestamp, event->walltime))) {
+                                               diskio_print(dio);
+                                               diskio_free(dio);
+                                       }
+                               }
+
+                               break;
+               }
+       });
 
-void
-enter_syscall(int thread, int type, kd_buf *kd, char *name, double now)
-{
-       struct th_info *ti;
-       int    i;
-       int    secs;
-       int    usecs;
-       long long l_usecs;
-       long curr_time;
-       kd_threadmap *map;
-       kd_threadmap *find_thread_map();
-       int clen = 0;
-       int tsclen = 0;
-       int nmclen = 0;
-       int argsclen = 0;
-       char buf[MAXCOLS];
-
-       switch (type) {
-
-       case MACH_pageout:
-       case MACH_vmfault:
-       case MSC_map_fd:
-       case BSC_mmap:
-       case BSC_recvmsg:
-       case BSC_sendmsg:
-       case BSC_recvfrom:
-       case BSC_accept:
-       case BSC_select:
-       case BSC_socket:
-       case BSC_connect:
-       case BSC_bind:
-       case BSC_listen:
-       case BSC_sendto:
-       case BSC_socketpair:
-       case BSC_execve:
-       case BSC_getxattr:
-       case BSC_fgetxattr:
-       case BSC_setxattr:
-       case BSC_fsetxattr:
-       case BSC_removexattr:
-       case BSC_fremovexattr:
-       case BSC_listxattr:
-       case BSC_flistxattr:
-       case BSC_open_extended:
-       case BSC_stat_extended:
-       case BSC_lstat_extended:
-       case BSC_fstat_extended:
-       case BSC_chmod_extended:
-       case BSC_fchmod_extended:
-       case BSC_access_extended:
-       case BSC_mkfifo_extended:
-       case BSC_mkdir_extended:
-       case BSC_stat:
-       case BSC_load_shared_file:
-       case BSC_open:
-       case BSC_dup:
-       case BSC_dup2:
-       case BSC_close:
-       case BSC_read:
-       case BSC_write:
-       case BSC_fstat:
-       case BSC_lstat:
-       case BSC_link:
-       case BSC_unlink:
-       case BSC_mknod:
-       case BSC_chmod:
-       case BSC_chown:
-       case BSC_lchown:
-       case BSC_access:
-       case BSC_chflags:
-       case BSC_fchflags:
-       case BSC_fchdir:
-       case BSC_futimes:
-       case BSC_chdir:
-       case BSC_utimes:
-       case BSC_chroot:
-       case BSC_undelete:
-       case BSC_delete:
-       case BSC_revoke:
-       case BSC_fsctl:
-       case BSC_copyfile:
-       case BSC_sync:
-       case BSC_symlink:
-       case BSC_readlink:
-       case BSC_fsync:
-       case BSC_readv:
-       case BSC_writev:
-       case BSC_pread:
-       case BSC_pwrite:
-       case BSC_fchown:
-       case BSC_fchmod:
-       case BSC_rename:
-       case BSC_mkdir:
-       case BSC_mkfifo:
-       case BSC_rmdir:
-       case BSC_statfs:
-       case BSC_fstatfs:
-       case BSC_pathconf:
-       case BSC_fpathconf:
-       case BSC_getdirentries:
-       case BSC_lseek:
-       case BSC_truncate:
-       case BSC_ftruncate:
-       case BSC_statv:
-       case BSC_lstatv:
-       case BSC_fstatv:
-       case BSC_mkcomplex:
-       case BSC_getattrlist:
-       case BSC_setattrlist:
-       case BSC_getdirentriesattr:
-       case BSC_exchangedata:
-       case BSC_checkuseraccess:
-       case BSC_searchfs:
-          case FILEMGR_PBGETCATALOGINFO:
-          case FILEMGR_PBGETCATALOGINFOBULK:
-          case FILEMGR_PBCREATEFILEUNICODE:
-          case FILEMGR_PBCREATEDIRECTORYUNICODE:
-          case FILEMGR_PBCREATEFORK:
-          case FILEMGR_PBDELETEFORK:
-          case FILEMGR_PBITERATEFORK:
-          case FILEMGR_PBOPENFORK:
-          case FILEMGR_PBREADFORK:
-          case FILEMGR_PBWRITEFORK:
-          case FILEMGR_PBALLOCATEFORK:
-          case FILEMGR_PBDELETEOBJECT:
-          case FILEMGR_PBEXCHANGEOBJECT:
-          case FILEMGR_PBGETFORKCBINFO:
-          case FILEMGR_PBGETVOLUMEINFO:
-          case FILEMGR_PBMAKEFSREF:
-          case FILEMGR_PBMAKEFSREFUNICODE:
-          case FILEMGR_PBMOVEOBJECT:
-          case FILEMGR_PBOPENITERATOR:
-          case FILEMGR_PBRENAMEUNICODE:
-          case FILEMGR_PBSETCATALOGINFO:
-          case FILEMGR_PBSETVOLUMEINFO:
-          case FILEMGR_FSREFMAKEPATH:
-          case FILEMGR_FSPATHMAKEREF:
-
-          case FILEMGR_PBGETCATINFO:
-          case FILEMGR_PBGETCATINFOLITE:
-          case FILEMGR_PBHGETFINFO:
-          case FILEMGR_PBXGETVOLINFO:
-          case FILEMGR_PBHCREATE:
-          case FILEMGR_PBHOPENDF:
-          case FILEMGR_PBHOPENRF:
-          case FILEMGR_PBHGETDIRACCESS:
-          case FILEMGR_PBHSETDIRACCESS:
-          case FILEMGR_PBHMAPID:
-          case FILEMGR_PBHMAPNAME:
-          case FILEMGR_PBCLOSE:
-          case FILEMGR_PBFLUSHFILE:
-          case FILEMGR_PBGETEOF:
-          case FILEMGR_PBSETEOF:
-          case FILEMGR_PBGETFPOS:
-          case FILEMGR_PBREAD:
-          case FILEMGR_PBWRITE:
-          case FILEMGR_PBGETFCBINFO:
-          case FILEMGR_PBSETFINFO:
-          case FILEMGR_PBALLOCATE:
-          case FILEMGR_PBALLOCCONTIG:
-          case FILEMGR_PBSETFPOS:
-          case FILEMGR_PBSETCATINFO:
-          case FILEMGR_PBGETVOLPARMS:
-          case FILEMGR_PBSETVINFO:
-          case FILEMGR_PBMAKEFSSPEC:
-          case FILEMGR_PBHGETVINFO:
-          case FILEMGR_PBCREATEFILEIDREF:
-          case FILEMGR_PBDELETEFILEIDREF:
-          case FILEMGR_PBRESOLVEFILEIDREF:
-          case FILEMGR_PBFLUSHVOL:
-          case FILEMGR_PBHRENAME:
-          case FILEMGR_PBCATMOVE:
-          case FILEMGR_PBEXCHANGEFILES:
-          case FILEMGR_PBHDELETE:
-          case FILEMGR_PBDIRCREATE:
-          case FILEMGR_PBCATSEARCH:
-          case FILEMGR_PBHSETFLOCK:
-          case FILEMGR_PBHRSTFLOCK:
-          case FILEMGR_PBLOCKRANGE:
-          case FILEMGR_PBUNLOCKRANGE:
-
-          if ((ti = find_thread(thread, BSC_execve))) {
-                   if (ti->pathptr) {
-                           exit_syscall("execve", thread, BSC_execve, 0, 0, 0, 0, (double)now);
-                   }
-          }
-          for (i = 0, ti = th_state; ti < &th_state[MAX_THREADS]; ti++, i++) {
-                  if (ti->thread == 0)
-                          break;
-          }
-          if (ti == &th_state[MAX_THREADS])
-                  return;
-          if (i >= cur_max)
-                  cur_max = i + 1;
-                   
-          if ((type >> 24) == FILEMGR_CLASS) {
-                  ti->in_filemgr = 1;
-
-                  l_usecs = (long long)(now / divisor);
-                  secs = l_usecs / 1000000;
-                  curr_time = bias_secs + secs;
-                  
-                  sprintf(buf, "%-8.8s", &(ctime(&curr_time)[11]));
-                  tsclen = strlen(buf);
-
-                  if (columns > MAXCOLS || wideflag) {
-                          usecs = l_usecs - (long long)((long long)secs * 1000000);
-                          sprintf(&buf[tsclen], ".%03ld", (long)usecs / 1000);
-                          tsclen = strlen(buf);
-                  }
-
-                  /* Print timestamp column */
-                  printf("%s", buf);
-
-                  map = find_thread_map(thread);
-                  if (map) {
-                      sprintf(buf, "  %-25.25s ", name);
-                      nmclen = strlen(buf);
-                      printf("%s", buf);
-
-                      sprintf(buf, "(%d, 0x%x, 0x%x, 0x%x)", (short)kd->arg1, kd->arg2, kd->arg3, kd->arg4);
-                      argsclen = strlen(buf);
-                      
-                      /*
-                        Calculate white space out to command
-                      */
-                      if (columns > MAXCOLS || wideflag)
-                        {
-                          clen = columns - (tsclen + nmclen + argsclen + 20);
-                        }
-                      else
-                        clen = columns - (tsclen + nmclen + argsclen + 12);
-
-                      if(clen > 0)
-                        {
-                          printf("%s", buf);   /* print the kdargs */
-                          memset(buf, ' ', clen);
-                          buf[clen] = '\0';
-                          printf("%s", buf);
-                        }
-                      else if ((argsclen + clen) > 0)
-                        {
-                          /* no room so wipe out the kdargs */
-                          memset(buf, ' ', (argsclen + clen));
-                          buf[argsclen + clen] = '\0';
-                          printf("%s", buf);
-                        }
-
-                      if (columns > MAXCOLS || wideflag)
-                          printf("%-20.20s\n", map->command); 
-                      else
-                          printf("%-12.12s\n", map->command); 
-                  } else
-                          printf("  %-24.24s (%5d, %#x, 0x%x, 0x%x)\n",         name, (short)kd->arg1, kd->arg2, kd->arg3, kd->arg4);
-          } else {
-                          ti->in_filemgr = 0;
-          }
-          ti->thread = thread;
-          ti->waited = 0;
-          ti->type   = type;
-          ti->stime  = now;
-          ti->arg1   = kd->arg1;
-          ti->arg2   = kd->arg2;
-          ti->arg3   = kd->arg3;
-          ti->arg4   = kd->arg4;
-          ti->pathptr = (long *)0;
-          ti->pathname[0] = 0;
-          break;
-
-       default:
-          break;
-       }
-       fflush (0);
+       ktrace_events_subclass(s, DBG_CORESTORAGE, 1 /* DBG_CS_SYNC */, ^(ktrace_event_t event) {
+               int cs_type = event->debugid & P_CS_Type_Mask; // strip out the done bit
+               bool start = (event->debugid & P_CS_IO_Done) != P_CS_IO_Done;
+
+               if (cs_type == P_CS_SYNC_DISK) {
+                       if (start) {
+                               event_enter(cs_type, event);
+                       } else {
+                               event_exit("  SyncCacheCS", cs_type, event, FMT_SYNC_DISK_CS);
+                       }
+               }
+       });
 }
 
 /*
@@ -2212,1235 +1271,2381 @@ enter_syscall(int thread, int type, kd_buf *kd, char *name, double now)
  *     Wipe out the kd args that were collected upon syscall_entry
  *     because it is the extended info that we really want, and it
  *     is all we really need.
-*/
-
+ */
 void
-extend_syscall(int thread, int type, kd_buf *kd, char *name, double now)
+extend_syscall(uintptr_t thread, int type, ktrace_event_t event)
 {
-       struct th_info *ti;
-
-       switch (type) {
-       case BSC_pread_extended:
-          if ((ti = find_thread(thread, BSC_pread)) == (struct th_info *)0)
-              return;
-          ti->arg1   = kd->arg1;  /* the fd */
-          ti->arg2   = kd->arg2;  /* nbytes */
-          ti->arg3   = kd->arg3;  /* top half offset */
-          ti->arg4   = kd->arg4;  /* bottom half offset */        
-          break;
-       case BSC_pwrite_extended:
-          if ((ti = find_thread(thread, BSC_pwrite)) == (struct th_info *)0)
-              return;
-          ti->arg1   = kd->arg1;  /* the fd */
-          ti->arg2   = kd->arg2;  /* nbytes */
-          ti->arg3   = kd->arg3;  /* top half offset */
-          ti->arg4   = kd->arg4;  /* bottom half offset */
-          break;
-       default:
-          return;
-       }
+       th_info_t ti;
+
+       switch (type) {
+               case BSC_mmap_extended:
+                       if ((ti = event_find(thread, BSC_mmap)) == NULL)
+                               return;
+
+                       ti->arg8   = ti->arg3;  /* save protection */
+                       ti->arg1   = event->arg1;  /* the fd */
+                       ti->arg3   = event->arg2;  /* bottom half address */
+                       ti->arg5   = event->arg3;  /* bottom half size */
+                       break;
+
+               case BSC_mmap_extended2:
+                       if ((ti = event_find(thread, BSC_mmap)) == NULL)
+                               return;
+
+                       ti->arg2   = event->arg1;  /* top half address */
+                       ti->arg4   = event->arg2;  /* top half size */
+                       ti->arg6   = event->arg3;  /* top half file offset */
+                       ti->arg7   = event->arg4;  /* bottom half file offset */
+                       break;
+
+               case BSC_msync_extended:
+                       if ((ti = event_find(thread, BSC_msync)) == NULL) {
+                               if ((ti = event_find(thread, BSC_msync_nocancel)) == NULL)
+                                       return;
+                       }
+
+                       ti->arg4   = event->arg1;  /* top half address */
+                       ti->arg5   = event->arg2;  /* top half size */
+                       break;
+
+               case BSC_pread_extended:
+                       if ((ti = event_find(thread, BSC_pread)) == NULL) {
+                               if ((ti = event_find(thread, BSC_pread_nocancel)) == NULL)
+                                       return;
+                       }
+
+                       ti->arg1   = event->arg1;  /* the fd */
+                       ti->arg2   = event->arg2;  /* nbytes */
+                       ti->arg3   = event->arg3;  /* top half offset */
+                       ti->arg4   = event->arg4;  /* bottom half offset */
+                       break;
+
+               case BSC_pwrite_extended:
+                       if ((ti = event_find(thread, BSC_pwrite)) == NULL) {
+                               if ((ti = event_find(thread, BSC_pwrite_nocancel)) == NULL)
+                                       return;
+                       }
+
+                       ti->arg1   = event->arg1;  /* the fd */
+                       ti->arg2   = event->arg2;  /* nbytes */
+                       ti->arg3   = event->arg3;  /* top half offset */
+                       ti->arg4   = event->arg4;  /* bottom half offset */
+                       break;
+       }
 }
 
-void
-exit_syscall(char *sc_name, int thread, int type, int error, int retval,
-                           int has_fd, int has_ret, double now)
+#pragma mark printing routines
+
+static void
+get_mode_nibble(char *buf, unsigned long smode, unsigned long special, char x_on, char x_off)
 {
-    struct th_info *ti;
-      
-    if ((ti = find_thread(thread, type)) == (struct th_info *)0)
-        return;
+       if (smode & 04)
+               buf[0] = 'r';
 
-    if (check_filter_mode(ti, type, error, retval, sc_name))
-       format_print(ti, sc_name, thread, type, error, retval, has_fd, has_ret, now, ti->stime, ti->waited, ti->pathname, NULL);
+       if (smode & 02)
+               buf[1] = 'w';
 
-    if (ti == &th_state[cur_max - 1])
-        cur_max--;
-    ti->thread = 0;
+       if (smode & 01) {
+               if (special)
+                       buf[2] = x_on;
+               else
+                       buf[2] = 'x';
+       } else {
+               if (special)
+                       buf[2] = x_off;
+       }
 }
 
+static void
+get_mode_string(unsigned long mode, char *buf)
+{
+       memset(buf, '-', 9);
+       buf[9] = '\0';
 
+       get_mode_nibble(&buf[6], mode, (mode & 01000), 't', 'T');
+       get_mode_nibble(&buf[3], (mode>>3), (mode & 02000), 's', 'S');
+       get_mode_nibble(&buf[0], (mode>>6), (mode & 04000), 's', 'S');
+}
 
-void
-format_print(struct th_info *ti, char *sc_name, int thread, int type, int error, int retval,
-                           int has_fd, int has_ret, double now, double stime, int waited, char *pathname, struct diskio *dio)
+static int
+clip_64bit(char *s, uint64_t value)
 {
-       int secs;
-       int usecs;
-       int nopadding;
-       long long l_usecs;
-       long curr_time;
-       char *command_name;
-       kd_threadmap *map;
-       kd_threadmap *find_thread_map();
-       int len = 0;
-       int clen = 0;
-       char *framework_name;
-       char buf[MAXCOLS];
-      
-       command_name = "";
-       
-       if (dio)
-            command_name = dio->issuing_command;
-       else {
-          if ((map = find_thread_map(thread)))
-                command_name = map->command;
-       }
-       
-       l_usecs = (long long)(now / divisor);
-       secs = l_usecs / 1000000;
-       curr_time = bias_secs + secs;
-       sprintf(buf, "%-8.8s", &(ctime(&curr_time)[11]));
-       clen = strlen(buf);
-
-       if (columns > MAXCOLS || wideflag) {
-              nopadding = 0;
-              usecs = l_usecs - (long long)((long long)secs * 1000000);
-              sprintf(&buf[clen], ".%03ld", (long)usecs / 1000);
-              clen = strlen(buf);
-               
-              if ((type >> 24) != FILEMGR_CLASS) {
-                  if (find_thread(thread, -1)) {
-                      sprintf(&buf[clen], "   ");
-                      clen = strlen(buf);
-                      nopadding = 1;
-                  }
-              }
-       } else
-              nopadding = 1;
-
-       if (((type >> 24) == FILEMGR_CLASS) && (columns > MAXCOLS || wideflag))
-              sprintf(&buf[clen], "  %-18.18s", sc_name);
-       else
-              sprintf(&buf[clen], "  %-15.15s", sc_name);
-
-       clen = strlen(buf);
-       
-       framework_name = (char *)0;
-
-       if (columns > MAXCOLS || wideflag) {
-            if (has_ret == 7) {
-                sprintf(&buf[clen], " D=0x%8.8x", dio->blkno);
-                
-                clen = strlen(buf);
-                
-                if (dio->io_errno)
-                    sprintf(&buf[clen], "  [%3d]       ", dio->io_errno);
-                else
-                    sprintf(&buf[clen], "  B=0x%-6x   /dev/%s", dio->iosize, find_disk_name(dio->dev));
-            } else {
+       int clen = 0;
+
+       if ( (value & 0xff00000000000000LL) )
+               clen = printf("%s0x%16.16qx", s, value);
+       else if ( (value & 0x00ff000000000000LL) )
+               clen = printf("%s0x%14.14qx  ", s, value);
+       else if ( (value & 0x0000ff0000000000LL) )
+               clen = printf("%s0x%12.12qx    ", s, value);
+       else if ( (value & 0x000000ff00000000LL) )
+               clen = printf("%s0x%10.10qx      ", s, value);
+       else
+               clen = printf("%s0x%8.8qx        ", s, value);
 
-               off_t offset_reassembled = 0LL;
-               
-              if (has_fd == 2 && error == 0)
-                      sprintf(&buf[clen], " F=%-3d", retval);
-              else if (has_fd == 1)
-                      sprintf(&buf[clen], " F=%-3d", ti->arg1);
-              else if (has_ret != 2 && has_ret != 6)
-                      sprintf(&buf[clen], "      ");
-
-              clen = strlen(buf);
-
-              if (has_ret == 2 || has_ret == 6)
-                      framework_name = lookup_name(retval);
-
-              if (error && has_ret != 6)
-                      sprintf(&buf[clen], "[%3d]       ", error);
-              else if (has_ret == 3)
-                      sprintf(&buf[clen], "O=0x%8.8x", ti->arg3);
-              else if (has_ret == 5)
-                      sprintf(&buf[clen], "O=0x%8.8x", retval);
-              else if (has_ret == 2) 
-                      sprintf(&buf[clen], " A=0x%8.8x              ", retval);
-              else if (has_ret == 6) 
-                      sprintf(&buf[clen], " A=0x%8.8x  B=0x%-8x", retval, error);
-              else if (has_ret == 1)
-                      sprintf(&buf[clen], "  B=0x%-6x", retval);
-              else if (has_ret == 4)
-                      sprintf(&buf[clen], "B=0x%-8x", retval);
-              else if (has_ret == 8)  /* BSC_select */
-                      sprintf(&buf[clen], "  S=%-3d     ", retval);           
-              else if (has_ret == 9)  /* BSC_pread, BSC_pwrite */
-              {
-                  sprintf(&buf[clen], "B=0x%-8x", retval);
-                  clen = strlen(buf);
-                  offset_reassembled = (((off_t)(unsigned int)(ti->arg3)) << 32) | (unsigned int)(ti->arg4);
-                  if ((offset_reassembled >> 32) != 0)
-                      sprintf(&buf[clen], "O=0x%16.16qx", (off_t)offset_reassembled);
-                  else
-                      sprintf(&buf[clen], "O=0x%8.8qx", (off_t)offset_reassembled);
-              }
-              else
-                      sprintf(&buf[clen], "            ");
-            }
-            clen = strlen(buf);
-       }
-       printf("%s", buf);
-
-       /*
-        Calculate space available to print pathname
-       */
-       if (columns > MAXCOLS || wideflag)
-        clen =  columns - (clen + 13 + 20);
-       else
-        clen =  columns - (clen + 13 + 12);
-
-       if ((type >> 24) != FILEMGR_CLASS && !nopadding)
-        clen -= 3;
-
-       if (framework_name)
-        sprintf(&buf[0], " %s ", framework_name);
-       else
-        sprintf(&buf[0], " %s ", pathname);
-       len = strlen(buf);
-       
-       if (clen > len)
-        {
-          /* 
-             Add null padding if column length
-             is wider than the pathname length.
-          */
-          memset(&buf[len], ' ', clen - len);
-          buf[clen] = '\0';
-          printf("%s", buf);
-        }
-       else if (clen == len)
-        {
-          printf("%s", buf);
-        }
-       else if ((clen > 0) && (clen < len))
-        {
-          /* This prints the tail end of the pathname */
-          buf[len-clen] = ' ';
-          printf("%s", &buf[len - clen]);
-        }
-
-       usecs = (unsigned long)((now - stime) / divisor);
-       secs = usecs / 1000000;
-       usecs -= secs * 1000000;
-
-       if ((type >> 24) != FILEMGR_CLASS && !nopadding)
-              printf("   ");
-              
-       printf(" %2ld.%06ld", (unsigned long)secs, (unsigned long)usecs);
-       
-       if (waited)
-              printf(" W");
-       else
-              printf("  ");
-
-       if (columns > MAXCOLS || wideflag)
-               printf(" %-20.20s", command_name);
-       else
-               printf(" %-12.12s", command_name);
-
-       printf("\n");
-       fflush (0);
+       return clen;
 }
 
-int
-quit(s)
-char *s;
+/*
+ * ret = 1 means print the entry
+ * ret = 0 means don't print the entry
+ */
+
+/*
+ * meaning of filter flags:
+ * cachehit    turn on display of CACHE_HIT events (which are filtered out by default)
+ *
+ * exec                show exec/posix_spawn
+ * pathname    show events with a pathname and close()
+ * diskio      show disk I/Os
+ * filesys     show filesystem events
+ * network     show network events
+ *
+ * filters may be combined; default is all filters on (except cachehit)
+ */
+bool
+check_filter_mode(pid_t pid, th_info_t ti, unsigned long type, int error, int retval, char *sc_name)
 {
-        if (trace_enabled)
-              set_enable(0);
+       bool ret = false;
+       int network_fd_isset = 0;
+       unsigned long fd;
 
-       /* 
-          This flag is turned off when calling
-          quit() due to a set_remove() failure.
-       */
-       if (set_remove_flag)
-               set_remove();
+       /* cachehit is special -- it's not on by default */
+       if (sc_name[0] == 'C' && !strcmp(sc_name, "CACHE_HIT")) {
+               return show_cachehits;
+       }
 
-        fprintf(stderr, "fs_usage: ");
-       if (s)
-               fprintf(stderr, "%s", s);
+       if (filter_mode == DEFAULT_DO_NOT_FILTER)
+               return true;
 
-       exit(1);
-}
+       if (filter_mode & DISKIO_FILTER) {
+               if ((type & P_DISKIO_MASK) == P_DISKIO)
+                       return true;
 
+               if (type == Throttled)
+                       return true;
+       }
 
-void getdivisor()
-{
-    struct mach_timebase_info mti;
+       if (filter_mode & EXEC_FILTER) {
+               if (type == BSC_execve || type == BSC_posix_spawn)
+                       return true;
+       }
+
+       if (filter_mode & PATHNAME_FILTER) {
+               if (ti && ti->pathname[0])
+                       return true;
+
+               if (type == BSC_close || type == BSC_close_nocancel ||
+                       type == BSC_guarded_close_np)
+                       return true;
+       }
+
+       if (!ti) {
+               if (filter_mode & FILESYS_FILTER)
+                       return true;
+
+               return 0;
+       }
+
+       switch (type) {
+               case BSC_close:
+               case BSC_close_nocancel:
+               case BSC_guarded_close_np:
+                       fd = ti->arg1;
+                       network_fd_isset = fd_is_network(pid, fd);
+
+                       if (error == 0)
+                               fd_set_is_network(pid, fd, false);
+
+                       if (network_fd_isset) {
+                               if (filter_mode & NETWORK_FILTER)
+                                       ret = true;
+                       } else {
+                               if (filter_mode & FILESYS_FILTER)
+                                       ret = true;
+                       }
+
+                       break;
+
+               case BSC_read:
+               case BSC_write:
+               case BSC_read_nocancel:
+               case BSC_write_nocancel:
+                       /*
+                        * we don't care about error in these cases
+                        */
+                       fd = ti->arg1;
+
+                       if (fd_is_network(pid, fd)) {
+                               if (filter_mode & NETWORK_FILTER)
+                                       ret = true;
+                       } else if (filter_mode & FILESYS_FILTER) {
+                               ret = true;
+                       }
+
+                       break;
+
+               case BSC_accept:
+               case BSC_accept_nocancel:
+               case BSC_socket:
+                       fd = retval;
+
+                       if (error == 0)
+                               fd_set_is_network(pid, fd, true);
+
+                       if (filter_mode & NETWORK_FILTER)
+                               ret = true;
+
+                       break;
+
+               case BSC_recvfrom:
+               case BSC_sendto:
+               case BSC_recvmsg:
+               case BSC_sendmsg:
+               case BSC_connect:
+               case BSC_bind:
+               case BSC_listen:
+               case BSC_sendto_nocancel:
+               case BSC_recvfrom_nocancel:
+               case BSC_recvmsg_nocancel:
+               case BSC_sendmsg_nocancel:
+               case BSC_connect_nocancel:
+                       fd = ti->arg1;
+
+                       if (error == 0)
+                               fd_set_is_network(pid, fd, true);
+
+                       if (filter_mode & NETWORK_FILTER)
+                               ret = true;
+
+                       break;
+
+               case BSC_select:
+               case BSC_select_nocancel:
+               case BSC_socketpair:
+                       /*
+                        * Cannot determine info about file descriptors
+                        */
+                       if (filter_mode & NETWORK_FILTER)
+                               ret = true;
+
+                       break;
+
+               case BSC_dup:
+               case BSC_dup2:
+                       /*
+                        * We track these cases for fd state only
+                        */
+                       fd = ti->arg1;
+
+                       if (error == 0 && fd_is_network(pid, fd)) {
+                               /*
+                                * then we are duping a socket descriptor
+                                */
+                               fd = retval;  /* the new fd */
+                               fd_set_is_network(pid, fd, true);
+                       }
+
+                       break;
+
+               default:
+                       if (filter_mode & FILESYS_FILTER)
+                               ret = true;
 
-    mach_timebase_info(&mti);
+                       break;
+       }
 
-    divisor = ((double)mti.denom / (double)mti.numer) * 1000;
+       return ret;
 }
 
+int
+print_open(ktrace_event_t event, uintptr_t flags)
+{
+       char mode[] = "______";
+
+       if (flags & O_RDWR) {
+               mode[0] = 'R';
+               mode[1] = 'W';
+       } else if (flags & O_WRONLY) {
+               mode[1] = 'W';
+       } else {
+               mode[0] = 'R';
+       }
+
+       if (flags & O_CREAT) {
+               mode[2] = 'C';
+       }
+       if (flags & O_APPEND) {
+               mode[3] = 'A';
+       }
+       if (flags & O_TRUNC) {
+               mode[4] = 'T';
+       }
+       if (flags & O_EXCL) {
+               mode[5] = 'E';
+       }
+
+       if (event->arg1) {
+               return printf("      [%3d] (%s) ", (int)event->arg1, mode);
+       } else {
+               return printf(" F=%-3d      (%s) ", (int)event->arg2, mode);
+       }
+}
 
-void read_command_map()
+/*
+ * called from:
+ *
+ * exit_event() (syscalls etc.)
+ * print_diskio() (disk I/Os)
+ * block callback for TrimExtent
+ */
+void
+format_print(th_info_t ti, char *sc_name, ktrace_event_t event,
+            unsigned long type, int format, uint64_t now, uint64_t stime,
+            int waited, const char *pathname, struct diskio *dio)
 {
-    size_t size;
-    int i;
-    int prev_total_threads;
-    int mib[6];
-  
-    if (mapptr) {
-       free(mapptr);
-       mapptr = 0;
-    }
-
-    prev_total_threads = total_threads;
-    total_threads = bufinfo.nkdthreads;
-    size = bufinfo.nkdthreads * sizeof(kd_threadmap);
-
-    if (size)
-    {
-        if ((mapptr = (kd_threadmap *) malloc(size)))
-       {
-            bzero (mapptr, size);
-            /* Now read the threadmap */
-            mib[0] = CTL_KERN;
-            mib[1] = KERN_KDEBUG;
-            mib[2] = KERN_KDTHRMAP;
-            mib[3] = 0;
-            mib[4] = 0;
-            mib[5] = 0;                /* no flags */
-            if (sysctl(mib, 3, mapptr, &size, NULL, 0) < 0)
-            {
-                /* This is not fatal -- just means I cant map command strings */
-                free(mapptr);
-                mapptr = 0;
-            }
+       uint64_t secs, usecs;
+       int nopadding = 0;
+       static time_t last_walltime_secs = -1;
+       const char *command_name;
+       pid_t pid;
+       int len = 0;
+       int clen = 0;
+       size_t tlen = 0;
+       unsigned long class;
+       uint64_t user_addr;
+       uint64_t user_size;
+       char *framework_name;
+       char *framework_type;
+       char *p1;
+       char *p2;
+       char buf[MAXWIDTH];
+       char cs_diskname[32];
+       unsigned long threadid;
+       struct timeval now_walltime;
+
+       static char timestamp[32];
+       static size_t timestamp_len = 0;
+
+       if (!mach_time_of_first_event)
+               mach_time_of_first_event = now;
+
+       if (format == FMT_DISKIO || format == FMT_DISKIO_CS) {
+               assert(dio);
+       } else {
+               assert(event);
+
+               if (format != FMT_UNMAP_INFO)
+                       assert(ti);
        }
-    }
-
-    if (mapptr && (filter_mode & (NETWORK_FILTER | FILESYS_FILTER)))
-    {
-       if (fdmapptr)
-       {
-           /* We accept the fact that we lose file descriptor state if the
-              kd_buffer wraps */
-           for (i = 0; i < prev_total_threads; i++)
-           {
-               if (fdmapptr[i].fd_setptr)
-                   free (fdmapptr[i].fd_setptr);
-           }
-           free(fdmapptr);
-           fdmapptr = 0;
+
+       /* <rdar://problem/19852325> Filter out WindowServer/xcpm ioctls in fs_usage */
+       if (type == BSC_ioctl && ti->arg2 == 0xffffffffc030581dUL)
+               return;
+
+       /* honor -S and -E */
+       if (RAW_flag) {
+               uint64_t relative_time_ns;
+
+               relative_time_ns = mach_to_nano(now - mach_time_of_first_event);
+
+               if (relative_time_ns < start_time_ns || relative_time_ns > end_time_ns)
+                       return;
        }
 
-       size = total_threads * sizeof(fd_threadmap);
-       if ((fdmapptr = (fd_threadmap *) malloc(size)))
-       {
-           bzero (fdmapptr, size);
-           /* reinitialize file descriptor state map */
-           for (i = 0; i < total_threads; i++)
-           {
-               fdmapptr[i].fd_thread = mapptr[i].thread;
-               fdmapptr[i].fd_valid = mapptr[i].valid;
-               fdmapptr[i].fd_setsize = 0;
-               fdmapptr[i].fd_setptr = 0;
-           }
+       class = KDBG_EXTRACT_CLASS(type);
+
+       if (dio) {
+               command_name = dio->issuing_command;
+               threadid = dio->issuing_thread;
+               pid = dio->issuing_pid;
+               now_walltime = dio->completed_walltime;
+       } else {
+               if (ti && ti->command[0] != '\0') {
+                       command_name = ti->command;
+                       threadid = ti->thread;
+                       pid = ti->pid;
+               } else {
+                       command_name = ktrace_get_execname_for_thread(s, event->threadid);
+                       threadid = event->threadid;
+                       pid = ktrace_get_pid_for_thread(s, event->threadid);
+               }
+
+               now_walltime = event->walltime;
        }
-    }
-
-    /* Resolve any LaunchCFMApp command names */
-    if (mapptr && arguments)
-    {
-       for (i=0; i < total_threads; i++)
-       {
-           int pid;
-
-           pid = mapptr[i].valid;
-           
-           if (pid == 0 || pid == 1)
-               continue;
-           else if (!strncmp(mapptr[i].command,"LaunchCFMA", 10))
-           {
-               (void)get_real_command_name(pid, mapptr[i].command, sizeof(mapptr[i].command));
-           }
+
+       if (!want_kernel_task && pid == 0)
+               return;
+
+       if (!command_name)
+               command_name = "";
+
+       assert(now_walltime.tv_sec || now_walltime.tv_usec);
+
+       /* try and reuse the timestamp string */
+       if (last_walltime_secs != now_walltime.tv_sec) {
+               timestamp_len = strftime(timestamp, sizeof (timestamp), "%H:%M:%S", localtime(&now_walltime.tv_sec));
+               last_walltime_secs = now_walltime.tv_sec;
        }
-    }
-}
 
+       if (columns > MAXCOLS || wideflag) {
+               tlen = timestamp_len;
+               nopadding = 0;
 
-void create_map_entry(int thread, int pid, char *command)
-{
-    int i, n;
-    kd_threadmap *map;
-    fd_threadmap *fdmap = 0;
-
-    if (!mapptr)
-        return;
-
-    for (i = 0, map = 0; !map && i < total_threads; i++)
-    {
-        if ((int)mapptr[i].thread == thread )
-       {
-           map = &mapptr[i];   /* Reuse this entry, the thread has been
-                                * reassigned */
-           if ((filter_mode & (NETWORK_FILTER | FILESYS_FILTER)) && fdmapptr)
-           {
-               fdmap = &fdmapptr[i];
-               if (fdmap->fd_thread != thread)    /* This shouldn't happen */
-                   fdmap = (fd_threadmap *)0;
-           }
+               sprintf(&timestamp[tlen], ".%06d", now_walltime.tv_usec);
+               tlen += 7;
+
+               timestamp[tlen] = '\0';
+       } else {
+               nopadding = 1;
        }
-    }
-
-    if (!map)   /* look for invalid entries that I can reuse*/
-    {
-        for (i = 0, map = 0; !map && i < total_threads; i++)
-       {
-           if (mapptr[i].valid == 0 )  
-               map = &mapptr[i];   /* Reuse this invalid entry */
-           if ((filter_mode & (NETWORK_FILTER | FILESYS_FILTER)) && fdmapptr)
-           {
-               fdmap = &fdmapptr[i];
-           }
+
+       clen = printf("%s  %-17.17s", timestamp, sc_name);
+
+       framework_name = NULL;
+
+       if (columns > MAXCOLS || wideflag) {
+               off_t offset_reassembled = 0LL;
+
+               switch (format) {
+                       case FMT_NOTHING:
+                               clen += printf("                  ");
+                               break;
+
+                       case FMT_AT:
+                       case FMT_RENAMEAT:
+                       case FMT_DEFAULT:
+                               /*
+                                * pathname based system calls or
+                                * calls with no fd or pathname (i.e.  sync)
+                                */
+                               if (event->arg1)
+                                       clen += printf("      [%3d]       ", (int)event->arg1);
+                               else
+                                       clen += printf("                  ");
+
+                               break;
+
+                       case FMT_FD:
+                               /*
+                                * fd based system call... no I/O
+                                */
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                               else
+                                       clen += printf(" F=%-3d", (int)ti->arg1);
+
+                               break;
+
+                       case FMT_FD_2:
+                               /*
+                                * accept, dup, dup2
+                                */
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                               else
+                                       clen += printf(" F=%-3d  F=%-3d", (int)ti->arg1, (int)event->arg2);
+
+                               break;
+
+                       case FMT_FD_IO:
+                               /*
+                                * system calls with fd's that return an I/O completion count
+                                */
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                               else
+                                       clen += printf(" F=%-3d  B=0x%-6lx", (int)ti->arg1, event->arg2);
+
+                               break;
+
+                       case FMT_PGIN:
+                               /*
+                                * pagein
+                                */
+                               user_addr = ((uint64_t)event->arg1 << 32) | (uint32_t)event->arg2;
+
+                               lookup_name(user_addr, &framework_type, &framework_name);
+                               clen += clip_64bit(" A=", user_addr);
+                               break;
+
+                       case FMT_CACHEHIT:
+                               /*
+                                * cache hit
+                                */
+                               user_addr = ((uint64_t)event->arg1 << 32) | (uint32_t)event->arg2;
+
+                               lookup_name(user_addr, &framework_type, &framework_name);
+                               clen += clip_64bit(" A=", user_addr);
+                               break;
+
+                       case FMT_PGOUT:
+                               /*
+                                * pageout
+                                */
+                               clen += printf("      B=0x%-8lx", event->arg1);
+                               break;
+
+                       case FMT_HFS_update:
+                       {
+                               static const struct {
+                                       int flag;
+                                       char ch;
+                               } hfsflags[] = {
+                                       { DBG_HFS_UPDATE_SKIPPED,   'S' },
+                                       { DBG_HFS_UPDATE_FORCE,     'F' },
+                                       { DBG_HFS_UPDATE_MODIFIED,  'M' },
+                                       { DBG_HFS_UPDATE_MINOR,     'N' },
+                                       { DBG_HFS_UPDATE_DATEADDED, 'd' },
+                                       { DBG_HFS_UPDATE_CHGTIME,   'c' },
+                                       { DBG_HFS_UPDATE_ACCTIME,   'a' },
+                                       { DBG_HFS_UPDATE_MODTIME,   'm' },
+                               };
+                               size_t i;
+                               int flagcount;
+                               char *sbuf;
+                               int  sflag = (int)event->arg2;
+
+                               flagcount = sizeof (hfsflags) / sizeof (*hfsflags);
+                               sbuf = malloc(flagcount + 1);
+
+                               for (i = 0; i < flagcount; i++) {
+                                       if (sflag & hfsflags[i].flag) {
+                                               sbuf[i] = hfsflags[i].ch;
+                                       } else {
+                                               sbuf[i] = '_';
+                                       }
+                               }
+
+                               sbuf[flagcount] = '\0';
+
+                               clen += printf(" %*s(%s) ", 17 - flagcount, "", sbuf);
+
+                               free(sbuf);
+
+                               pathname = ktrace_get_path_for_vp(s, event->arg1);
+
+                               if (!pathname)
+                                       pathname = "";
+
+                               nopadding = 1;
+
+                               break;
+                       }
+
+                       case FMT_DISKIO:
+                               /*
+                                * physical disk I/O
+                                */
+                               if (dio->io_errno) {
+                                       clen += printf(" D=0x%8.8lx  [%3d]", dio->blkno, (int)dio->io_errno);
+                               } else {
+                                       if (BC_flag)
+                                               clen += printf(" D=0x%8.8lx  B=0x%-6lx BC:%s /dev/%s ", dio->blkno, dio->iosize, BC_STR(dio->bc_info), find_disk_name(dio->dev));
+                                       else
+                                               clen += printf(" D=0x%8.8lx  B=0x%-6lx /dev/%s ", dio->blkno, dio->iosize, find_disk_name(dio->dev));
+
+                                       if (dio->is_meta) {
+                                               if (!(type & P_DISKIO_READ)) {
+                                                       pathname = meta_find_name(dio->blkno);
+                                               }
+                                       } else {
+                                               pathname = ktrace_get_path_for_vp(s, dio->vnodeid);
+
+                                               if (!pathname)
+                                                       pathname = "";
+                                       }
+
+                                       nopadding = 1;
+                               }
+
+                               break;
+
+                       case FMT_DISKIO_CS:
+                               /*
+                                * physical disk I/O
+                                */
+                               if (dio->io_errno)
+                                       clen += printf(" D=0x%8.8lx  [%3lu]", dio->blkno, dio->io_errno);
+                               else
+                                       clen += printf(" D=0x%8.8lx  B=0x%-6lx /dev/%s", dio->blkno, dio->iosize, generate_cs_disk_name(dio->dev, cs_diskname));
+
+                               break;
+
+                       case FMT_SYNC_DISK_CS:
+                               /*
+                                * physical disk sync cache
+                                */
+                               clen += printf("                          /dev/%s", generate_cs_disk_name(event->arg1, cs_diskname));
+
+                               break;
+
+                       case FMT_MSYNC:
+                       {
+                               /*
+                                * msync
+                                */
+                               int  mlen = 0;
+
+                               buf[0] = '\0';
+
+                               if (ti->arg3 & MS_ASYNC)
+                                       mlen += sprintf(&buf[mlen], "MS_ASYNC | ");
+                               else
+                                       mlen += sprintf(&buf[mlen], "MS_SYNC | ");
+
+                               if (ti->arg3 & MS_INVALIDATE)
+                                       mlen += sprintf(&buf[mlen], "MS_INVALIDATE | ");
+                               if (ti->arg3 & MS_KILLPAGES)
+                                       mlen += sprintf(&buf[mlen], "MS_KILLPAGES | ");
+                               if (ti->arg3 & MS_DEACTIVATE)
+                                       mlen += sprintf(&buf[mlen], "MS_DEACTIVATE | ");
+
+                               if (ti->arg3 & ~(MS_ASYNC | MS_SYNC | MS_INVALIDATE | MS_KILLPAGES | MS_DEACTIVATE))
+                                       mlen += sprintf(&buf[mlen], "UNKNOWN | ");
+
+                               if (mlen)
+                                       buf[mlen - 3] = '\0';
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d]", (int)event->arg1);
+
+                               user_addr = (((off_t)(unsigned int)(ti->arg4)) << 32) | (unsigned int)(ti->arg1);
+                               clen += clip_64bit(" A=", user_addr);
+
+                               user_size = (((off_t)(unsigned int)(ti->arg5)) << 32) | (unsigned int)(ti->arg2);
+
+                               clen += printf("  B=0x%-16qx  <%s>", user_size, buf);
+
+                               break;
+                       }
+
+                       case FMT_FLOCK:
+                       {
+                               /*
+                                * flock
+                                */
+                               int  mlen = 0;
+
+                               buf[0] = '\0';
+
+                               if (ti->arg2 & LOCK_SH)
+                                       mlen += sprintf(&buf[mlen], "LOCK_SH | ");
+                               if (ti->arg2 & LOCK_EX)
+                                       mlen += sprintf(&buf[mlen], "LOCK_EX | ");
+                               if (ti->arg2 & LOCK_NB)
+                                       mlen += sprintf(&buf[mlen], "LOCK_NB | ");
+                               if (ti->arg2 & LOCK_UN)
+                                       mlen += sprintf(&buf[mlen], "LOCK_UN | ");
+
+                               if (ti->arg2 & ~(LOCK_SH | LOCK_EX | LOCK_NB | LOCK_UN))
+                                       mlen += sprintf(&buf[mlen], "UNKNOWN | ");
+
+                               if (mlen)
+                                       buf[mlen - 3] = '\0';
+
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]  <%s>", (int)ti->arg1, (int)event->arg1, buf);
+                               else
+                                       clen += printf(" F=%-3d  <%s>", (int)ti->arg1, buf);
+
+                               break;
+                       }
+
+                       case FMT_FCNTL:
+                       {
+                               /*
+                                * fcntl
+                                */
+                               char *p = NULL;
+                               int fd = -1;
+
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                               else
+                                       clen += printf(" F=%-3d", (int)ti->arg1);
+
+                               switch(ti->arg2) {
+                                       case F_DUPFD:
+                                               p = "DUPFD";
+                                               break;
+
+                                       case F_GETFD:
+                                               p = "GETFD";
+                                               break;
+
+                                       case F_SETFD:
+                                               p = "SETFD";
+                                               break;
+
+                                       case F_GETFL:
+                                               p = "GETFL";
+                                               break;
+
+                                       case F_SETFL:
+                                               p = "SETFL";
+                                               break;
+
+                                       case F_GETOWN:
+                                               p = "GETOWN";
+                                               break;
+
+                                       case F_SETOWN:
+                                               p = "SETOWN";
+                                               break;
+
+                                       case F_GETLK:
+                                               p = "GETLK";
+                                               break;
+
+                                       case F_SETLK:
+                                               p = "SETLK";
+                                               break;
+
+                                       case F_SETLKW:
+                                               p = "SETLKW";
+                                               break;
+
+                                       case F_PREALLOCATE:
+                                               p = "PREALLOCATE";
+                                               break;
+
+                                       case F_SETSIZE:
+                                               p = "SETSIZE";
+                                               break;
+
+                                       case F_RDADVISE:
+                                               p = "RDADVISE";
+                                               break;
+
+                                       case F_GETPATH:
+                                               p = "GETPATH";
+                                               break;
+
+                                       case F_FULLFSYNC:
+                                               p = "FULLFSYNC";
+                                               break;
+
+                                       case F_PATHPKG_CHECK:
+                                               p = "PATHPKG_CHECK";
+                                               break;
+
+                                       case F_OPENFROM:
+                                               p = "OPENFROM";
+
+                                               if (event->arg1 == 0)
+                                                       fd = (int)event->arg2;
+                                               break;
+
+                                       case F_UNLINKFROM:
+                                               p = "UNLINKFROM";
+                                               break;
+
+                                       case F_CHECK_OPENEVT:
+                                               p = "CHECK_OPENEVT";
+                                               break;
+
+                                       case F_NOCACHE:
+                                               if (ti->arg3)
+                                                       p = "CACHING OFF";
+                                               else
+                                                       p = "CACHING ON";
+                                               break;
+
+                                       case F_GLOBAL_NOCACHE:
+                                               if (ti->arg3)
+                                                       p = "CACHING OFF (GLOBAL)";
+                                               else
+                                                       p = "CACHING ON (GLOBAL)";
+                                               break;
+
+                               }
+
+                               if (p) {
+                                       if (fd == -1)
+                                               clen += printf(" <%s>", p);
+                                       else
+                                               clen += printf(" <%s> F=%d", p, fd);
+                               } else {
+                                       clen += printf(" <CMD=%d>", (int)ti->arg2);
+                               }
+
+                               break;
+                       }
+
+                       case FMT_IOCTL:
+                       {
+                               /*
+                                * ioctl
+                                */
+                               if (event->arg1)
+                                       clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                               else
+                                       clen += printf(" F=%-3d", (int)ti->arg1);
+
+                               clen += printf(" <CMD=0x%x>", (int)ti->arg2);
+
+                               break;
+                       }
+
+                       case FMT_IOCTL_SYNC:
+                       {
+                               /*
+                                * ioctl
+                                */
+                               clen += printf(" <DKIOCSYNCHRONIZE>  B=%lu /dev/%s", event->arg3, find_disk_name(event->arg1));
+
+                               break;
+                       }
+
+                       case FMT_IOCTL_SYNCCACHE:
+                       {
+                               /*
+                                * ioctl
+                                */
+                               clen += printf(" <DKIOCSYNCHRONIZECACHE>  /dev/%s", find_disk_name(event->arg1));
+
+                               break;
+                       }
+
+                       case FMT_IOCTL_UNMAP:
+                       {
+                               /*
+                                * ioctl
+                                */
+                               clen += printf(" <DKIOCUNMAP>             /dev/%s", find_disk_name(event->arg1));
+
+                               break;
+                       }
+
+                       case FMT_UNMAP_INFO:
+                       {
+                               clen += printf(" D=0x%8.8lx  B=0x%-6lx /dev/%s", event->arg2, event->arg3, find_disk_name(event->arg1));
+
+                               break;
+                       }
+
+                       case FMT_SELECT:
+                               /*
+                                * select
+                                */
+                               if (event->arg1)
+                                       clen += printf("      [%3d]", (int)event->arg1);
+                               else
+                                       clen += printf("        S=%-3d", (int)event->arg2);
+
+                               break;
+
+                       case FMT_LSEEK:
+                       case FMT_PREAD:
+                               /*
+                                * pread, pwrite, lseek
+                                */
+                               clen += printf(" F=%-3d", (int)ti->arg1);
+
+                               if (event->arg1) {
+                                       clen += printf("[%3d]  ", (int)event->arg1);
+                               } else {
+                                       if (format == FMT_PREAD)
+                                               clen += printf("  B=0x%-8lx ", event->arg2);
+                                       else
+                                               clen += printf("  ");
+                               }
+
+                               if (format == FMT_PREAD)
+                                       offset_reassembled = (((off_t)(unsigned int)(ti->arg3)) << 32) | (unsigned int)(ti->arg4);
+                               else
+#ifdef __ppc__
+                                       offset_reassembled = (((off_t)(unsigned int)(arg2)) << 32) | (unsigned int)(arg3);
+#else
+                                       offset_reassembled = (((off_t)(unsigned int)(event->arg3)) << 32) | (unsigned int)(event->arg2);
+#endif
+
+                               clen += clip_64bit("O=", offset_reassembled);
+
+                               if (format == FMT_LSEEK) {
+                                       char *mode;
+
+                                       if (ti->arg3 == SEEK_SET)
+                                               mode = "SEEK_SET";
+                                       else if (ti->arg3 == SEEK_CUR)
+                                               mode = "SEEK_CUR";
+                                       else if (ti->arg3 == SEEK_END)
+                                               mode = "SEEK_END";
+                                       else
+                                               mode = "UNKNOWN";
+
+                                       clen += printf(" <%s>", mode);
+                               }
+
+                               break;
+
+                       case FMT_MMAP:
+                               /*
+                                * mmap
+                                */
+                               clen += printf(" F=%-3d  ", (int)ti->arg1);
+
+                               if (event->arg1) {
+                                       clen += printf("[%3d]  ", (int)event->arg1);
+                               } else {
+                                       user_addr = (((off_t)(unsigned int)(ti->arg2)) << 32) | (unsigned int)(ti->arg3);
+
+                                       clen += clip_64bit("A=", user_addr);
+
+                                       offset_reassembled = (((off_t)(unsigned int)(ti->arg6)) << 32) | (unsigned int)(ti->arg7);
+
+                                       clen += clip_64bit("O=", offset_reassembled);
+
+                                       user_size = (((off_t)(unsigned int)(ti->arg4)) << 32) | (unsigned int)(ti->arg5);
+
+                                       clen += printf("B=0x%-16qx", user_size);
+
+                                       clen += printf(" <");
+
+                                       if (ti->arg8 & PROT_READ)
+                                               clen += printf("READ");
+
+                                       if (ti->arg8 & PROT_WRITE)
+                                               clen += printf("|WRITE");
+
+                                       if (ti->arg8 & PROT_EXEC)
+                                               clen += printf("|EXEC");
+
+                                       clen += printf(">");
+                               }
+
+                               break;
+
+                       case FMT_TRUNC:
+                       case FMT_FTRUNC:
+                               /*
+                                * ftruncate, truncate
+                                */
+                               if (format == FMT_FTRUNC)
+                                       clen += printf(" F=%-3d", (int)ti->arg1);
+                               else
+                                       clen += printf("      ");
+
+                               if (event->arg1)
+                                       clen += printf("[%3d]", (int)event->arg1);
+
+#ifdef __ppc__
+                               offset_reassembled = (((off_t)(unsigned int)(ti->arg2)) << 32) | (unsigned int)(ti->arg3);
+#else
+                               offset_reassembled = (((off_t)(unsigned int)(ti->arg3)) << 32) | (unsigned int)(ti->arg2);
+#endif
+                               clen += clip_64bit("  O=", offset_reassembled);
+
+                               nopadding = 1;
+                               break;
+
+                       case FMT_FCHFLAGS:
+                       case FMT_CHFLAGS:
+                       {
+                               /*
+                                * fchflags, chflags
+                                */
+                               int mlen = 0;
+
+                               if (format == FMT_FCHFLAGS) {
+                                       if (event->arg1)
+                                               clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                                       else
+                                               clen += printf(" F=%-3d", (int)ti->arg1);
+                               } else {
+                                       if (event->arg1)
+                                               clen += printf(" [%3d] ", (int)event->arg1);
+                               }
+
+                               buf[mlen++] = ' ';
+                               buf[mlen++] = '<';
+
+                               if (ti->arg2 & UF_NODUMP)
+                                       mlen += sprintf(&buf[mlen], "UF_NODUMP | ");
+                               if (ti->arg2 & UF_IMMUTABLE)
+                                       mlen += sprintf(&buf[mlen], "UF_IMMUTABLE | ");
+                               if (ti->arg2 & UF_APPEND)
+                                       mlen += sprintf(&buf[mlen], "UF_APPEND | ");
+                               if (ti->arg2 & UF_OPAQUE)
+                                       mlen += sprintf(&buf[mlen], "UF_OPAQUE | ");
+                               if (ti->arg2 & SF_ARCHIVED)
+                                       mlen += sprintf(&buf[mlen], "SF_ARCHIVED | ");
+                               if (ti->arg2 & SF_IMMUTABLE)
+                                       mlen += sprintf(&buf[mlen], "SF_IMMUTABLE | ");
+                               if (ti->arg2 & SF_APPEND)
+                                       mlen += sprintf(&buf[mlen], "SF_APPEND | ");
+
+                               if (ti->arg2 == 0)
+                                       mlen += sprintf(&buf[mlen], "CLEAR_ALL_FLAGS | ");
+                               else if (ti->arg2 & ~(UF_NODUMP | UF_IMMUTABLE | UF_APPEND | SF_ARCHIVED | SF_IMMUTABLE | SF_APPEND))
+                                       mlen += sprintf(&buf[mlen], "UNKNOWN | ");
+
+                               if (mlen >= 3)
+                                       mlen -= 3;
+
+                               buf[mlen++] = '>';
+                               buf[mlen] = '\0';
+
+                               if (mlen < 19) {
+                                       memset(&buf[mlen], ' ', 19 - mlen);
+                                       mlen = 19;
+                                       buf[mlen] = '\0';
+                               }
+
+                               clen += printf("%s", buf);
+
+                               nopadding = 1;
+                               break;
+                       }
+
+                       case FMT_UMASK:
+                       case FMT_FCHMOD:
+                       case FMT_FCHMOD_EXT:
+                       case FMT_CHMOD:
+                       case FMT_CHMOD_EXT:
+                       case FMT_CHMODAT:
+                       {
+                               /*
+                                * fchmod, fchmod_extended, chmod, chmod_extended
+                                */
+                               unsigned long mode;
+
+                               if (format == FMT_FCHMOD || format == FMT_FCHMOD_EXT) {
+                                       if (event->arg1)
+                                               clen += printf(" F=%-3d[%3d] ", (int)ti->arg1, (int)event->arg1);
+                                       else
+                                               clen += printf(" F=%-3d ", (int)ti->arg1);
+                               } else {
+                                       if (event->arg1)
+                                               clen += printf(" [%3d] ", (int)event->arg1);
+                                       else
+                                               clen += printf(" ");
+                               }
+
+                               if (format == FMT_UMASK)
+                                       mode = ti->arg1;
+                               else if (format == FMT_FCHMOD || format == FMT_CHMOD || format == FMT_CHMODAT)
+                                       mode = ti->arg2;
+                               else
+                                       mode = ti->arg4;
+
+                               get_mode_string(mode, &buf[0]);
+
+                               if (event->arg1 == 0)
+                                       clen += printf("<%s>      ", buf);
+                               else
+                                       clen += printf("<%s>", buf);
+                               break;
+                       }
+
+                       case FMT_ACCESS:
+                       {
+                               /*
+                                * access
+                                */
+                               char mode[5];
+
+                               memset(mode, '_', 4);
+                               mode[4] = '\0';
+
+                               if (ti->arg2 & R_OK)
+                                       mode[0] = 'R';
+                               if (ti->arg2 & W_OK)
+                                       mode[1] = 'W';
+                               if (ti->arg2 & X_OK)
+                                       mode[2] = 'X';
+                               if (ti->arg2 == F_OK)
+                                       mode[3] = 'F';
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d] (%s)   ", (int)event->arg1, mode);
+                               else
+                                       clen += printf("            (%s)   ", mode);
+
+                               nopadding = 1;
+                               break;
+                       }
+
+                       case FMT_MOUNT:
+                       {
+                               if (event->arg1)
+                                       clen += printf("      [%3d] <FLGS=0x%lx> ", (int)event->arg1, ti->arg3);
+                               else
+                                       clen += printf("     <FLGS=0x%lx> ", ti->arg3);
+
+                               nopadding = 1;
+                               break;
+                       }
+
+                       case FMT_UNMOUNT:
+                       {
+                               char *mountflag;
+
+                               if (ti->arg2 & MNT_FORCE)
+                                       mountflag = "<FORCE>";
+                               else
+                                       mountflag = "";
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d] %s  ", (int)event->arg1, mountflag);
+                               else
+                                       clen += printf("     %s         ", mountflag);
+
+                               nopadding = 1;
+                               break;
+                       }
+
+                       case FMT_OPEN:
+                               clen += print_open(event, ti->arg2);
+                               nopadding = 1;
+                               break;
+
+                       case FMT_OPENAT:
+                               clen += print_open(event, ti->arg3);
+                               nopadding = 1;
+                               break;
+
+                       case FMT_SOCKET:
+                       {
+                               /*
+                                * socket
+                                *
+                                */
+                               char *domain;
+                               char *type;
+
+                               switch (ti->arg1) {
+                                       case AF_UNIX:
+                                               domain = "AF_UNIX";
+                                               break;
+
+                                       case AF_INET:
+                                               domain = "AF_INET";
+                                               break;
+
+                                       case AF_ISO:
+                                               domain = "AF_ISO";
+                                               break;
+
+                                       case AF_NS:
+                                               domain = "AF_NS";
+                                               break;
+
+                                       case AF_IMPLINK:
+                                               domain = "AF_IMPLINK";
+                                               break;
+
+                                       default:
+                                               domain = "UNKNOWN";
+                                               break;
+                               }
+
+                               switch (ti->arg2) {
+                                       case SOCK_STREAM:
+                                               type = "SOCK_STREAM";
+                                               break;
+                                       case SOCK_DGRAM:
+                                               type = "SOCK_DGRAM";
+                                               break;
+                                       case SOCK_RAW:
+                                               type = "SOCK_RAW";
+                                               break;
+                                       default:
+                                               type = "UNKNOWN";
+                                               break;
+                               }
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d] <%s, %s, 0x%lx>", (int)event->arg1, domain, type, ti->arg3);
+                               else
+                                       clen += printf(" F=%-3d      <%s, %s, 0x%lx>", (int)event->arg2, domain, type, ti->arg3);
+
+                               break;
+                       }
+
+                       case FMT_AIO_FSYNC:
+                       {
+                               /*
+                                * aio_fsync            [errno]   AIOCBP   OP
+                                */
+                               char *op;
+
+                               if (ti->arg1 == O_SYNC || ti->arg1 == 0)
+                                       op = "AIO_FSYNC";
+#if O_DSYNC
+                               else if (ti->arg1 == O_DSYNC)
+                                       op = "AIO_DSYNC";
+#endif
+                               else
+                                       op = "UNKNOWN";
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d] P=0x%8.8lx  <%s>", (int)event->arg1, ti->arg2, op);
+                               else
+                                       clen += printf("            P=0x%8.8lx  <%s>", ti->arg2, op);
+
+                               break;
+                       }
+
+                       case FMT_AIO_RETURN:
+                               /*
+                                * aio_return           [errno]   AIOCBP   IOSIZE
+                                */
+                               if (event->arg1)
+                                       clen += printf("      [%3d] P=0x%8.8lx", (int)event->arg1, ti->arg1);
+                               else
+                                       clen += printf("            P=0x%8.8lx  B=0x%-8lx", ti->arg1, event->arg2);
+
+                               break;
+
+                       case FMT_AIO_SUSPEND:
+                               /*
+                                * aio_suspend          [errno]   NENTS
+                                */
+                               if (event->arg1)
+                                       clen += printf("      [%3d] N=%d", (int)event->arg1, (int)ti->arg2);
+                               else
+                                       clen += printf("            N=%d", (int)ti->arg2);
+
+                               break;
+
+                       case FMT_AIO_CANCEL:
+                               /*
+                                * aio_cancel           [errno]   FD or AIOCBP (if non-null)
+                                */
+                               if (ti->arg2) {
+                                       if (event->arg1)
+                                               clen += printf("      [%3d] P=0x%8.8lx", (int)event->arg1, ti->arg2);
+                                       else
+                                               clen += printf("            P=0x%8.8lx", ti->arg2);
+                               } else {
+                                       if (event->arg1)
+                                               clen += printf(" F=%-3d[%3d]", (int)ti->arg1, (int)event->arg1);
+                                       else
+                                               clen += printf(" F=%-3d", (int)ti->arg1);
+                               }
+
+                               break;
+
+                       case FMT_AIO:
+                               /*
+                                * aio_error, aio_read, aio_write       [errno]  AIOCBP
+                                */
+                               if (event->arg1)
+                                       clen += printf("      [%3d] P=0x%8.8lx", (int)event->arg1, ti->arg1);
+                               else
+                                       clen += printf("            P=0x%8.8lx", ti->arg1);
+
+                               break;
+
+                       case FMT_LIO_LISTIO: {
+                               /*
+                                * lio_listio           [errno]   NENTS  MODE
+                                */
+                               char *op;
+
+                               if (ti->arg1 == LIO_NOWAIT)
+                                       op = "LIO_NOWAIT";
+                               else if (ti->arg1 == LIO_WAIT)
+                                       op = "LIO_WAIT";
+                               else
+                                       op = "UNKNOWN";
+
+                               if (event->arg1)
+                                       clen += printf("      [%3d] N=%d  <%s>", (int)event->arg1, (int)ti->arg3, op);
+                               else
+                                       clen += printf("            N=%d  <%s>", (int)ti->arg3, op);
+
+                               break;
+                       }
+               }
        }
-    }
-  
-    if (!map)
-    {
-        /* If reach here, then this is a new thread and 
-        * there are no invalid entries to reuse
-        * Double the size of the thread map table.
+
+       /*
+        * Calculate space available to print pathname
         */
+       if (columns > MAXCOLS || wideflag)
+               clen = columns - (clen + 14 + 20 + 11);
+       else
+               clen = columns - (clen + 14 + 12);
+
+       if (!nopadding)
+               clen -= 3;
+
+       if (framework_name) {
+               len = sprintf(&buf[0], " %s %s ", framework_type, framework_name);
+       } else if (*pathname != '\0') {
+               switch(format) {
+                       case FMT_AT:
+                       case FMT_OPENAT:
+                       case FMT_CHMODAT:
+                               len = sprintf(&buf[0], " [%d]/%s ", (int)ti->arg1, pathname);
+                               break;
+                       case FMT_RENAMEAT:
+                               len = sprintf(&buf[0], " [%d]/%s ", (int)ti->arg3, pathname);
+                               break;
+                       default:
+                               len = sprintf(&buf[0], " %s ", pathname);
+               }
 
-        n = total_threads * 2;
-       mapptr = (kd_threadmap *) realloc(mapptr, n * sizeof(kd_threadmap));
-       bzero(&mapptr[total_threads], total_threads*sizeof(kd_threadmap));
-       map = &mapptr[total_threads];
+               if (format == FMT_MOUNT && ti->pathname2[0] != '\0') {
+                       int     len2;
 
-       if ((filter_mode & (NETWORK_FILTER | FILESYS_FILTER)) && fdmapptr)
-       {
-           fdmapptr = (fd_threadmap *)realloc(fdmapptr, n * sizeof(fd_threadmap));
-           bzero(&fdmapptr[total_threads], total_threads*sizeof(fd_threadmap));
-           fdmap = &fdmapptr[total_threads];       
+                       memset(&buf[len], ' ', 2);
+
+                       len2 = sprintf(&buf[len+2], " %s ", ti->pathname2);
+                       len = len + 2 + len2;
+               }
+       } else {
+               len = 0;
        }
-       
-       total_threads = n;
-    }
-
-    map->valid = 1;
-    map->thread = thread;
-    /*
-      The trace entry that returns the command name will hold
-      at most, MAXCOMLEN chars, and in that case, is not
-      guaranteed to be null terminated.
-    */
-    (void)strncpy (map->command, command, MAXCOMLEN);
-    map->command[MAXCOMLEN] = '\0';
-
-    if (fdmap)
-    {
-       fdmap->fd_valid = 1;
-       fdmap->fd_thread = thread;
-       if (fdmap->fd_setptr)
-       {
-           free(fdmap->fd_setptr);
-           fdmap->fd_setptr = (unsigned long *)0;
+
+       if (clen > len) {
+               /*
+                * Add null padding if column length
+                * is wider than the pathname length.
+                */
+               memset(&buf[len], ' ', clen - len);
+               buf[clen] = '\0';
+
+               pathname = buf;
+       } else if (clen == len) {
+               pathname = buf;
+       } else if ((clen > 0) && (clen < len)) {
+               /*
+                * This prints the tail end of the pathname
+                */
+               buf[len-clen] = ' ';
+
+               pathname = &buf[len - clen];
+       } else {
+               pathname = "";
        }
-       fdmap->fd_setsize = 0;
-    }
 
-    if (pid == 0 || pid == 1)
-       return;
-    else if (!strncmp(map->command, "LaunchCFMA", 10))
-       (void)get_real_command_name(pid, map->command, sizeof(map->command));
+       /*
+        * fudge some additional system call overhead
+        * that currently isn't tracked... this also
+        * insures that we see a minimum of 1 us for
+        * an elapsed time
+        */
+       usecs = (mach_to_nano(now - stime) + (NSEC_PER_USEC - 1)) / NSEC_PER_USEC;
+       secs = usecs / USEC_PER_SEC;
+       usecs -= secs * USEC_PER_SEC;
+
+       if (!nopadding)
+               p1 = "   ";
+       else
+               p1 = "";
+
+       if (waited)
+               p2 = " W";
+       else
+               p2 = "  ";
+
+       if (columns > MAXCOLS || wideflag)
+               printf("%s%s %3llu.%06llu%s %s.%lu\n", p1, pathname, secs, usecs, p2, command_name, threadid);
+       else
+               printf("%s%s %3llu.%06llu%s %-12.12s\n", p1, pathname, secs, usecs, p2, command_name);
+
+       if (!RAW_flag)
+               fflush(stdout);
 }
 
+#pragma mark metadata info hash routines
 
-kd_threadmap *find_thread_map(int thread)
+#define VN_HASH_SIZE   16384
+#define VN_HASH_MASK   (VN_HASH_SIZE - 1)
+
+typedef struct meta_info {
+       struct meta_info *m_next;
+       uint64_t m_blkno;
+       char m_name[MAXPATHLEN];
+} *meta_info_t;
+
+meta_info_t m_info_hash[VN_HASH_SIZE];
+
+void
+meta_add_name(uint64_t blockno, const char *pathname)
 {
-    int i;
-    kd_threadmap *map;
-
-    if (!mapptr)
-        return((kd_threadmap *)0);
-
-    for (i = 0; i < total_threads; i++)
-    {
-        map = &mapptr[i];
-       if (map->valid && ((int)map->thread == thread))
-       {
-           return(map);
+       meta_info_t     mi;
+       int hashid;
+
+       hashid = blockno & VN_HASH_MASK;
+
+       for (mi = m_info_hash[hashid]; mi; mi = mi->m_next) {
+               if (mi->m_blkno == blockno)
+                       break;
        }
-    }
-    return ((kd_threadmap *)0);
-}
 
-fd_threadmap *find_fd_thread_map(int thread)
-{
-    int i;
-    fd_threadmap *fdmap = 0;
-
-    if (!fdmapptr)
-        return((fd_threadmap *)0);
-
-    for (i = 0; i < total_threads; i++)
-    {
-        fdmap = &fdmapptr[i];
-       if (fdmap->fd_valid && ((int)fdmap->fd_thread == thread))
-       {
-           return(fdmap);
+       if (mi == NULL) {
+               mi = malloc(sizeof (struct meta_info));
+
+               mi->m_next = m_info_hash[hashid];
+               m_info_hash[hashid] = mi;
+               mi->m_blkno = blockno;
        }
-    }
-    return ((fd_threadmap *)0);
-}
 
+       strncpy(mi->m_name, pathname, sizeof (mi->m_name));
+}
 
-void
-kill_thread_map(int thread)
+const char *
+meta_find_name(uint64_t blockno)
 {
-    kd_threadmap *map;
-    fd_threadmap *fdmap;
-
-    if ((map = find_thread_map(thread))) {
-        map->valid = 0;
-       map->thread = 0;
-       map->command[0] = '\0';
-    }
-
-    if ((filter_mode & (NETWORK_FILTER | FILESYS_FILTER)))
-    {
-       if ((fdmap = find_fd_thread_map(thread)))
-       {
-           fdmap->fd_valid = 0;
-           fdmap->fd_thread = 0;
-           if (fdmap->fd_setptr)
-           {
-               free (fdmap->fd_setptr);
-               fdmap->fd_setptr = (unsigned long *)0;
-           }
-           fdmap->fd_setsize = 0;
-       }       
-    }
+       meta_info_t     mi;
+       int             hashid;
+
+       hashid = blockno & VN_HASH_MASK;
+
+       for (mi = m_info_hash[hashid]; mi; mi = mi->m_next) {
+               if (mi->m_blkno == blockno)
+                       return mi->m_name;
+       }
+
+       return "";
 }
 
 void
-argtopid(str)
-        char *str;
+meta_delete_all(void)
 {
-        char *cp;
-        int ret;
+       meta_info_t mi, next;
        int i;
 
-        ret = (int)strtol(str, &cp, 10);
-        if (cp == str || *cp) {
-         /* Assume this is a command string and find matching pids */
-               if (!kp_buffer)
-                       find_proc_names();
-
-               for (i=0; i < kp_nentries && num_of_pids < (MAX_PIDS - 1); i++) {
-                     if(kp_buffer[i].kp_proc.p_stat == 0)
-                         continue;
-                     else {
-                         if(!strcmp(str, kp_buffer[i].kp_proc.p_comm))
-                           pids[num_of_pids++] = kp_buffer[i].kp_proc.p_pid;
-                     }
+       for (i = 0; i < HASH_MASK; i++) {
+               for (mi = m_info_hash[i]; mi; mi = next) {
+                       next = mi->m_next;
+
+                       free(mi);
                }
-       }
-       else if (num_of_pids < (MAX_PIDS - 1))
-               pids[num_of_pids++] = ret;
 
-        return;
+               m_info_hash[i] = NULL;
+       }
 }
 
+#pragma mark event ("thread info") routines
+
+th_info_t th_info_hash[HASH_SIZE];
+th_info_t th_info_freelist;
 
+static th_info_t
+add_event(ktrace_event_t event, int type)
+{
+       th_info_t ti;
+       int hashid;
+       unsigned long eventid;
 
-char *lookup_name(unsigned long addr) 
-{       
-        register int i;
-       register int start, last;
+       if ((ti = th_info_freelist))
+               th_info_freelist = ti->next;
+       else
+               ti = malloc(sizeof (struct th_info));
 
+       bzero(ti, sizeof (struct th_info));
 
-       if (numFrameworks == 0 || addr < frameworkInfo[0].address || addr > frameworkInfo[numFrameworks].address)
-               return (0);
+       hashid = event->threadid & HASH_MASK;
 
-       start = 0;
-       last  = numFrameworks;
+       ti->next = th_info_hash[hashid];
+       th_info_hash[hashid] = ti;
 
-       for (i = numFrameworks / 2; i >= 0 && i < numFrameworks; ) {
+       eventid = event->debugid & KDBG_EVENTID_MASK;
 
-               if (addr >= frameworkInfo[i].address && addr < frameworkInfo[i+1].address)
-                       return(frameworkInfo[i].name);
+       if (eventid == BSC_execve || eventid == BSC_posix_spawn) {
+               const char *command;
 
-               if (addr >= frameworkInfo[i].address) {
-                       start = i;
-                       i = start + ((last - i) / 2);
-               } else {
-                       last = i;
-                       i = start + ((i - start) / 2);
-               }
+               command = ktrace_get_execname_for_thread(s, event->threadid);
+
+               if (!command)
+                       command = "";
+
+               strncpy(ti->command, command, sizeof (ti->command));
+               ti->command[MAXCOMLEN] = '\0';
        }
-       return (0);
-}
 
+       ti->thread = event->threadid;
+       ti->type = type;
 
-/*
- * Comparison routines for sorting
- */
-static int compareFrameworkAddress(const void  *aa, const void *bb)
+       return ti;
+}
+
+th_info_t
+event_find(uintptr_t thread, int type)
 {
-    LibraryInfo *a = (LibraryInfo *)aa;
-    LibraryInfo *b = (LibraryInfo *)bb;
+       th_info_t ti;
+       int hashid;
 
-    if (a->address < b->address) return -1;
-    if (a->address == b->address) return 0;
-    return 1;
-}
+       hashid = thread & HASH_MASK;
 
+       for (ti = th_info_hash[hashid]; ti; ti = ti->next) {
+               if (ti->thread == thread) {
+                       if (type == ti->type)
+                               return ti;
 
-int scanline(char *inputstring,char **argv)
-{
-     int n = 0;
-     char **ap = argv, *p, *val;  
-
-     for (p = inputstring; p != NULL; ) 
-     {
-        while ((val = strsep(&p, " \t")) != NULL && *val == '\0');
-        *ap++ = val;
-        n++; 
-     }
-     *ap = 0;
-     return n;
-}
+                       if (type == 0)
+                               return ti;
+               }
+       }
 
+       return NULL;
+}
 
-int ReadSegAddrTable()
+void
+event_delete(th_info_t ti_to_delete)
 {
-    char buf[1024];
-
-    FILE *fd;
-    unsigned long frameworkAddress, frameworkDataAddress, previousFrameworkAddress;
-    char frameworkName[256];
-    char *tokens[64];
-    int  ntokens;
-    char *substring,*ptr;
-    int  founddylib = 0;
-
-
-    bzero(buf, sizeof(buf));
-    bzero(tokens, sizeof(tokens));
-    
-    numFrameworks = 0;
-
-    if ((fd = fopen(seg_addr_table, "r")) == 0)
-    {
-        return 0;
-    }
-    fgets(buf, 1023, fd);
-
-    if (*buf == '#')
-    {
-        founddylib = 0;
-        frameworkName[0] = 0;
-        previousFrameworkAddress = 0;
-
-        while (fgets(buf, 1023, fd) && numFrameworks < (MAXINDEX - 2))
-        {
-           /*
-            * Get rid of EOL
-            */
-           buf[strlen(buf)-1] = 0;
-
-           if (strncmp(buf, "# dyld:", 7) == 0) {
-               /*
-                * the next line in the file will contain info about dyld
-                */
-               founddylib = 1;
-               continue;
-           }
-           /*
-            * This is a split library line: parse it into 3 tokens
-            */
-           ntokens = scanline(buf, tokens);
-
-           if (ntokens < 3)
-               continue;
-
-           frameworkAddress     = strtoul(tokens[0], 0, 16);
-           frameworkDataAddress = strtoul(tokens[1], 0, 16);
-
-           if (founddylib) {
-               /*
-                * dyld entry is of a different form from the std split library
-                * it consists of a base address and a size instead of a code
-                * and data base address
-                */
-               frameworkInfo[numFrameworks].address   = frameworkAddress;
-               frameworkInfo[numFrameworks+1].address = frameworkAddress + frameworkDataAddress;
-
-               frameworkInfo[numFrameworks].name   = (char *)"dylib";
-               frameworkInfo[numFrameworks+1].name = (char *)0;
-
-               numFrameworks += 2;
-               founddylib = 0;
-
-               continue;
-           }  
-
-           /*
-            * Make sure that we have 2 addresses and a path
-            */
-           if (!frameworkAddress)
-               continue;
-           if (!frameworkDataAddress)
-               continue;
-           if (*tokens[2] != '/')
-               continue;
-           if (frameworkAddress == previousFrameworkAddress) 
-               continue;
-           previousFrameworkAddress = frameworkAddress;
-
-            /*
-            * Extract lib name from path name
-            */
-           if ((substring = strrchr(tokens[2], '.')))
-           {           
-               /*
-                * There is a ".": name is whatever is between the "/" around the "." 
-                */
-             while ( *substring != '/') {                  /* find "/" before "." */
-                   substring--;
+       th_info_t       ti;
+       th_info_t       ti_prev;
+       int             hashid;
+
+       hashid = ti_to_delete->thread & HASH_MASK;
+
+       if ((ti = th_info_hash[hashid])) {
+               if (ti == ti_to_delete)
+                       th_info_hash[hashid] = ti->next;
+               else {
+                       ti_prev = ti;
+
+                       for (ti = ti->next; ti; ti = ti->next) {
+                               if (ti == ti_to_delete) {
+                                       ti_prev->next = ti->next;
+                                       break;
+                               }
+                               ti_prev = ti;
+                       }
                }
-               substring++;
-               strcpy(frameworkName, substring);           /* copy path from "/" */
-               substring = frameworkName;
-
-               while ( *substring != '/' && *substring)    /* find "/" after "." and stop string there */
-                   substring++;
-               *substring = 0;
-           }
-           else 
-           {
-               /*
-                * No ".": take segment after last "/"
-                */
-               ptr = tokens[2];
-               substring = ptr;
-
-               while (*ptr) 
-               {
-                   if (*ptr == '/')
-                       substring = ptr + 1;
-                   ptr++;
+               if (ti) {
+                       ti->next = th_info_freelist;
+                       th_info_freelist = ti;
                }
-               strcpy(frameworkName, substring);
-           }
-           frameworkInfo[numFrameworks].address   = frameworkAddress;
-           frameworkInfo[numFrameworks+1].address = frameworkDataAddress;
+       }
+}
 
-           frameworkInfo[numFrameworks].name = (char *)malloc(strlen(frameworkName) + 1);
-           strcpy(frameworkInfo[numFrameworks].name, frameworkName);
-           frameworkInfo[numFrameworks+1].name = frameworkInfo[numFrameworks].name;
+void
+event_delete_all(void)
+{
+       th_info_t       ti = 0;
+       th_info_t       ti_next = 0;
+       int             i;
 
-           numFrameworks += 2;
-        }
-    }
-    frameworkInfo[numFrameworks].address = frameworkInfo[numFrameworks - 1].address + 0x800000;
-    frameworkInfo[numFrameworks].name = (char *)0;
+       for (i = 0; i < HASH_SIZE; i++) {
 
-    fclose(fd);
+               for (ti = th_info_hash[i]; ti; ti = ti_next) {
+                       ti_next = ti->next;
+                       ti->next = th_info_freelist;
+                       th_info_freelist = ti;
+               }
+               th_info_hash[i] = 0;
+       }
+}
 
-    qsort(frameworkInfo, numFrameworks, sizeof(LibraryInfo), compareFrameworkAddress);
+void
+event_enter(int type, ktrace_event_t event)
+{
+       th_info_t ti;
 
-    return 1;
-}
+#if DEBUG
+       int index;
+       bool found;
 
+       found = false;
 
-struct diskio *insert_diskio(int type, int bp, int dev, int blkno, int io_size, int thread, double curtime)
-{
-    register struct diskio *dio;
-    register kd_threadmap  *map;
-    
-    if ((dio = free_diskios))
-        free_diskios = dio->next;
-    else {
-        if ((dio = (struct diskio *)malloc(sizeof(struct diskio))) == NULL)
-            return (NULL);
-    }
-    dio->prev = NULL;
-    
-    dio->type = type;
-    dio->bp = bp;
-    dio->dev = dev;
-    dio->blkno = blkno;
-    dio->iosize = io_size;
-    dio->issued_time = curtime;
-    dio->issuing_thread = thread;
-    
-    if ((map = find_thread_map(thread)))
-    {
-        strncpy(dio->issuing_command, map->command, MAXCOMLEN);
-       dio->issuing_command[MAXCOMLEN-1] = '\0';
-    }
-    else
-        strcpy(dio->issuing_command, "");
-    
-    dio->next = busy_diskios;
-    if (dio->next)
-        dio->next->prev = dio;
-    busy_diskios = dio;
-
-    return (dio);
+       switch (type) {
+               case P_CS_SYNC_DISK:
+               case MACH_pageout:
+               case MACH_vmfault:
+               case MSC_map_fd:
+               case SPEC_ioctl:
+               case Throttled:
+               case HFS_update:
+                       found = true;
+       }
+
+       if ((type & CSC_MASK) == BSC_BASE) {
+               if ((index = BSC_INDEX(type)) < MAX_BSD_SYSCALL && bsd_syscalls[index].sc_name)
+                       found = true;
+       }
+
+       assert(found);
+#endif /* DEBUG */
+
+       if ((ti = add_event(event, type)) == NULL)
+               return;
+
+       ti->stime  = event->timestamp;
+       ti->arg1   = event->arg1;
+       ti->arg2   = event->arg2;
+       ti->arg3   = event->arg3;
+       ti->arg4   = event->arg4;
 }
 
+void
+event_exit(char *sc_name, int type, ktrace_event_t event, int format)
+{
+       th_info_t ti;
+       pid_t pid;
+
+       if ((ti = event_find(event->threadid, type)) == NULL)
+               return;
+
+       pid = ktrace_get_pid_for_thread(s, event->threadid);
+
+       if (check_filter_mode(pid, ti, type, (int)event->arg1, (int)event->arg2, sc_name)) {
+               const char *pathname;
+
+               pathname = NULL;
+
+               /* most things are just interested in the first lookup */
+               if (ti->pathname[0] != '\0')
+                       pathname = ti->pathname;
+
+               if (!pathname)
+                       pathname = "";
+
+               format_print(ti, sc_name, event, type, format, event->timestamp, ti->stime, ti->waited, pathname, NULL);
+       }
+
+       event_delete(ti);
+}
 
-struct diskio *complete_diskio(int bp, int io_errno, int resid, int thread, double curtime)
+void
+event_mark_thread_waited(uintptr_t thread)
 {
-    register struct diskio *dio;
-    
-    for (dio = busy_diskios; dio; dio = dio->next) {
-        if (dio->bp == bp) {
-        
-            if (dio == busy_diskios) {
-                if ((busy_diskios = dio->next))
-                    dio->next->prev = NULL;
-            } else {
-                if (dio->next)
-                    dio->next->prev = dio->prev;
-                dio->prev->next = dio->next;
-            }
-            dio->iosize -= resid;
-            dio->io_errno = io_errno;
-            dio->completed_time = curtime;
-            dio->completion_thread = thread;
-            
-           return (dio);
-        }    
-    }
-    return ((struct diskio *)0);
+       th_info_t       ti;
+       int             hashid;
+
+       hashid = thread & HASH_MASK;
+
+       for (ti = th_info_hash[hashid]; ti; ti = ti->next) {
+               if (ti->thread == thread)
+                       ti->waited = 1;
+       }
 }
 
+#pragma mark network fd set routines
+
+struct pid_fd_set {
+       struct pid_fd_set *next;
+       pid_t pid;
+       char *set;
+       size_t setsize; /* number of *bytes*, not bits */
+};
+
+struct pid_fd_set *pfs_hash[HASH_SIZE];
 
-void free_diskio(struct diskio *dio)
+static struct pid_fd_set *
+pfs_get(pid_t pid)
 {
-    dio->next = free_diskios;
-    free_diskios = dio;
+       struct pid_fd_set *pfs;
+       int hashid;
+
+       assert(pid >= 0);
+
+       hashid = pid & HASH_MASK;
+
+       for (pfs = pfs_hash[hashid]; pfs; pfs = pfs->next) {
+               if (pfs->pid == pid) {
+                       return pfs;
+               }
+       }
+
+       pfs = calloc(1, sizeof (struct pid_fd_set));
+
+       pfs->pid = pid;
+       pfs->set = NULL;
+       pfs->setsize = 0;
+       pfs->next = pfs_hash[hashid];
+       pfs_hash[hashid] = pfs;
+
+       return pfs;
 }
 
+void
+fd_clear_pid(pid_t pid)
+{
+       struct pid_fd_set *pfs, *prev;
+       int hashid;
+
+       if (pid < 0)
+               return;
+
+       hashid = pid & HASH_MASK;
+
+       pfs = pfs_hash[hashid];
+       prev = NULL;
+
+       while (pfs) {
+               if (pfs->pid == pid) {
+                       if (prev) {
+                               prev->next = pfs->next;
+                       } else {
+                               pfs_hash[hashid] = pfs->next;
+                       }
+
+                       free(pfs->set);
+                       free(pfs);
 
-void print_diskio(struct diskio *dio)
+                       break;
+               } else {
+                       prev = pfs;
+                       pfs = pfs->next;
+               }
+       }
+}
+
+void
+fd_clear_all(void)
 {
-    register char  *p;
-
-    switch (dio->type) {
-
-        case P_RdMeta:
-            p = "  RdMeta";
-            break;
-        case P_WrMeta:
-            p = "  WrMeta";
-            break;
-        case P_RdData:
-            p = "  RdData";
-            break;
-        case P_WrData:
-            p = "  WrData";
-            break;        
-        case P_PgIn:
-            p = "  PgIn";
-            break;
-        case P_PgOut:
-            p = "  PgOut";
-            break;
-        case P_RdMetaAsync:
-            p = "  RdMeta[async]";
-            break;
-        case P_WrMetaAsync:
-            p = "  WrMeta[async]";
-            break;
-        case P_RdDataAsync:
-            p = "  RdData[async]";
-            break;
-        case P_WrDataAsync:
-            p = "  WrData[async]";
-            break;        
-        case P_PgInAsync:
-            p = "  PgIn[async]";
-            break;
-        case P_PgOutAsync:
-            p = "  PgOut[async]";
-            break;
-        default:
-            p = "  ";
-           break;
-    }
-    if (check_filter_mode(NULL, dio->type,0, 0, p))
-       format_print(NULL, p, dio->issuing_thread, dio->type, 0, 0, 0, 7, dio->completed_time, dio->issued_time, 1, "", dio);
+       struct pid_fd_set *pfs, *next;
+       int i;
+
+       for (i = 0; i < HASH_SIZE; i++) {
+               for (pfs = pfs_hash[i]; pfs; pfs = next) {
+                       next = pfs->next;
+
+                       free(pfs->set);
+                       free(pfs);
+               }
+
+               pfs_hash[i] = NULL;
+       }
 }
 
+void
+fd_set_is_network(pid_t pid, unsigned long fd, bool set)
+{
+       struct pid_fd_set *pfs;
+
+       if (pid < 0)
+               return;
+       if (fd > OPEN_MAX)
+               return;
+
+       pfs = pfs_get(pid);
+
+       if (fd >= pfs->setsize * CHAR_BIT) {
+               size_t newsize;
+
+               if (!set) return;
+
+               newsize = MAX((fd + CHAR_BIT) / CHAR_BIT, 2 * pfs->setsize);
+               pfs->set = reallocf(pfs->set, newsize);
+               assert(pfs->set != NULL);
+
+               bzero(pfs->set + pfs->setsize, newsize - pfs->setsize);
+               pfs->setsize = newsize;
+       }
+
+       if (set)
+               setbit(pfs->set, fd);
+       else
+               clrbit(pfs->set, fd);
+}
 
-void cache_disk_names()
+bool
+fd_is_network(pid_t pid, unsigned long fd)
 {
-    struct stat    st;
-    DIR            *dirp = NULL;
-    struct dirent  *dir;
-    struct diskrec *dnp;
-
-
-    if ((dirp = opendir("/dev")) == NULL)
-        return;
-        
-    while ((dir = readdir(dirp)) != NULL) {
-        char nbuf[MAXPATHLEN];
-        
-        if (dir->d_namlen < 5 || strncmp("disk", dir->d_name, 4))
-            continue;
-        sprintf(nbuf, "%s/%s", "/dev", dir->d_name);
-        
-       if (stat(nbuf, &st) < 0)
-            continue;
-
-        if ((dnp = (struct diskrec *)malloc(sizeof(struct diskrec))) == NULL)
-            continue;
-            
-        if ((dnp->diskname = (char *)malloc(dir->d_namlen + 1)) == NULL) {
-            free(dnp);
-            continue;
-        }
-        strncpy(dnp->diskname, dir->d_name, dir->d_namlen);
-        dnp->diskname[dir->d_namlen] = 0;
-        dnp->dev = st.st_rdev;
-        
-        dnp->next = disk_list;
-        disk_list = dnp;
-    }
-    (void) closedir(dirp);
+       struct pid_fd_set *pfs;
+
+       if (pid < 0)
+               return false;
+
+       pfs = pfs_get(pid);
+
+       if (fd >= pfs->setsize * CHAR_BIT) {
+               return false;
+       }
+
+       return isset(pfs->set, fd);
 }
 
+#pragma mark shared region address lookup routines
+
+#define MAXINDEX 2048
+
+struct library_range {
+       uint64_t b_address;
+       uint64_t e_address;
+};
+
+struct library_info {
+       uint64_t b_address;
+       uint64_t e_address;
+       int      r_type;
+       char     *name;
+};
+
+struct library_range framework32 = {0, 0};
+struct library_range framework64 = {0, 0};
+struct library_range framework64h = {0, 0};
 
-char *find_disk_name(int dev)
+struct library_info library_infos[MAXINDEX];
+int num_libraries = 0;
+
+#define        TEXT_R          0
+#define DATA_R         1
+#define OBJC_R         2
+#define IMPORT_R       3
+#define UNICODE_R      4
+#define IMAGE_R                5
+#define LINKEDIT_R     6
+
+static void
+sort_library_addresses(void)
 {
-    struct diskrec *dnp;
-    
-    if (dev == NFS_DEV)
-        return ("NFS");
-        
-    for (dnp = disk_list; dnp; dnp = dnp->next) {
-        if (dnp->dev == dev)
-            return (dnp->diskname);
-    }
-    return ("NOTFOUND");
+       library_infos[num_libraries].b_address = library_infos[num_libraries - 1].b_address + 0x800000;
+       library_infos[num_libraries].e_address = library_infos[num_libraries].b_address;
+       library_infos[num_libraries].name = NULL;
+
+       qsort_b(library_infos, num_libraries, sizeof (struct library_info), ^int(const void *aa, const void *bb) {
+               struct library_info *a = (struct library_info *)aa;
+               struct library_info *b = (struct library_info *)bb;
+
+               if (a->b_address < b->b_address) return -1;
+               if (a->b_address == b->b_address) return 0;
+               return 1;
+       });
 }
 
-void
-fs_usage_fd_set(thread, fd)
-    unsigned int thread;
-    unsigned int fd;
+static int
+scanline(char *inputstring, char **argv, int maxtokens)
 {
-    int n;
-    fd_threadmap *fdmap;
-
-    if(!(fdmap = find_fd_thread_map(thread)))
-       return;
-
-    /* If the map is not allocated, then now is the time */
-    if (fdmap->fd_setptr == (unsigned long *)0)
-    {
-       fdmap->fd_setptr = (unsigned long *)malloc(FS_USAGE_NFDBYTES(FS_USAGE_FD_SETSIZE));
-       if (fdmap->fd_setptr)
-       {
-           fdmap->fd_setsize = FS_USAGE_FD_SETSIZE;
-           bzero(fdmap->fd_setptr,(FS_USAGE_NFDBYTES(FS_USAGE_FD_SETSIZE)));
+       int n = 0;
+       char **ap = argv, *p, *val;
+
+       for (p = inputstring; n < maxtokens && p != NULL; ) {
+               while ((val = strsep(&p, " \t")) != NULL && *val == '\0') ;
+
+               *ap++ = val;
+               n++;
        }
-       else
-           return;
-    }
-
-    /* If the map is not big enough, then reallocate it */
-    while (fdmap->fd_setsize < fd)
-    {
-       fprintf(stderr, "reallocating bitmap for threadid %d, fd = %d, setsize = %d\n",
-         thread, fd, fdmap->fd_setsize);
-       n = fdmap->fd_setsize * 2;
-       fdmap->fd_setptr = (unsigned long *)realloc(fdmap->fd_setptr, (FS_USAGE_NFDBYTES(n)));
-       bzero(&fdmap->fd_setptr[(fdmap->fd_setsize/FS_USAGE_NFDBITS)], (FS_USAGE_NFDBYTES(fdmap->fd_setsize)));
-       fdmap->fd_setsize = n;
-    }
-
-    /* set the bit */
-    fdmap->fd_setptr[fd/FS_USAGE_NFDBITS] |= (1 << ((fd) % FS_USAGE_NFDBITS));
-
-    return;
+
+       *ap = 0;
+
+       return n;
 }
 
-/*
-  Return values:
-  0 : File Descriptor bit is not set
-  1 : File Descriptor bit is set
-*/
-    
-int
-fs_usage_fd_isset(thread, fd)
-    unsigned int thread;
-    unsigned int fd;
+static int
+read_shared_cache_map(const char *path, struct library_range *lr, char *linkedit_name)
 {
-    int ret = 0;
-    fd_threadmap *fdmap;
+       uint64_t        b_address, e_address;
+       char    buf[1024];
+       char    *fnp, *fn_tofree;
+       FILE    *fd;
+       char    frameworkName[256];
+       char    *tokens[64];
+       int     ntokens;
+       int     type;
+       int     linkedit_found = 0;
+       char    *substring, *ptr;
+
+       bzero(buf, sizeof(buf));
+       bzero(tokens, sizeof(tokens));
+
+       lr->b_address = 0;
+       lr->e_address = 0;
+
+       if ((fd = fopen(path, "r")) == 0)
+               return 0;
+
+       while (fgets(buf, 1023, fd)) {
+               if (strncmp(buf, "mapping", 7))
+                       break;
+       }
+
+       buf[strlen(buf)-1] = 0;
 
-    if(!(fdmap = find_fd_thread_map(thread)))
-       return(ret);
+       frameworkName[0] = 0;
 
-    if (fdmap->fd_setptr == (unsigned long *)0)
-       return (ret);
+       for (;;) {
+               /*
+                * Extract lib name from path name
+                */
+               if ((substring = strrchr(buf, '.'))) {
+                       /*
+                        * There is a ".": name is whatever is between the "/" around the "."
+                        */
+                       while ( *substring != '/')                  /* find "/" before "." */
+                               substring--;
+
+                       substring++;
+
+                       strncpy(frameworkName, substring, 256);           /* copy path from "/" */
+                       frameworkName[255] = 0;
+                       substring = frameworkName;
+
+                       while ( *substring != '/' && *substring)    /* find "/" after "." and stop string there */
+                               substring++;
 
-    if (fd < fdmap->fd_setsize)
-       ret = fdmap->fd_setptr[fd/FS_USAGE_NFDBITS] & (1 << (fd % FS_USAGE_NFDBITS));
-    
-    return (ret);
+                       *substring = 0;
+               } else {
+                       /*
+                        * No ".": take segment after last "/"
+                        */
+                       ptr = buf;
+                       substring = ptr;
+
+                       while (*ptr)  {
+                               if (*ptr == '/')
+                                       substring = ptr + 1;
+                               ptr++;
+                       }
+
+                       strncpy(frameworkName, substring, 256);
+                       frameworkName[255] = 0;
+               }
+
+               fnp = malloc(strlen(frameworkName) + 1);
+               fn_tofree = fnp;
+               strcpy(fnp, frameworkName);
+
+               while (fgets(buf, 1023, fd) && num_libraries < (MAXINDEX - 2)) {
+                       /*
+                        * Get rid of EOL
+                        */
+                       buf[strlen(buf)-1] = 0;
+
+                       ntokens = scanline(buf, tokens, 64);
+
+                       if (ntokens < 4)
+                               continue;
+
+                       if (strncmp(tokens[0], "__TEXT", 6) == 0)
+                               type = TEXT_R;
+                       else if (strncmp(tokens[0], "__DATA", 6) == 0)
+                               type = DATA_R;
+                       else if (strncmp(tokens[0], "__OBJC", 6) == 0)
+                               type = OBJC_R;
+                       else if (strncmp(tokens[0], "__IMPORT", 8) == 0)
+                               type = IMPORT_R;
+                       else if (strncmp(tokens[0], "__UNICODE", 9) == 0)
+                               type = UNICODE_R;
+                       else if (strncmp(tokens[0], "__IMAGE", 7) == 0)
+                               type = IMAGE_R;
+                       else if (strncmp(tokens[0], "__LINKEDIT", 10) == 0)
+                               type = LINKEDIT_R;
+                       else
+                               type = -1;
+
+                       if (type == LINKEDIT_R && linkedit_found)
+                               break;
+
+                       if (type != -1) {
+                               b_address = strtoull(tokens[1], 0, 16);
+                               e_address = strtoull(tokens[3], 0, 16);
+
+                               library_infos[num_libraries].b_address  = b_address;
+                               library_infos[num_libraries].e_address  = e_address;
+                               library_infos[num_libraries].r_type     = type;
+
+                               if (type == LINKEDIT_R) {
+                                       library_infos[num_libraries].name = linkedit_name;
+                                       linkedit_found = 1;
+                               } else {
+                                       library_infos[num_libraries].name = fnp;
+                                       fn_tofree = NULL;
+                               }
+#if 0
+                               printf("%s(%d): %qx-%qx\n", frameworkInfo[numFrameworks].name, type, b_address, e_address);
+#endif
+                               if (lr->b_address == 0 || b_address < lr->b_address)
+                                       lr->b_address = b_address;
+
+                               if (lr->e_address == 0 || e_address > lr->e_address)
+                                       lr->e_address = e_address;
+
+                               num_libraries++;
+                       }
+
+                       if (type == LINKEDIT_R)
+                               break;
+               }
+
+               free(fn_tofree);
+
+               if (fgets(buf, 1023, fd) == 0)
+                       break;
+
+               buf[strlen(buf)-1] = 0;
+       }
+
+       fclose(fd);
+
+#if 0
+       printf("%s range, %qx-%qx\n", path, lr->b_address, lr->e_address);
+#endif
+       return 1;
 }
-    
+
 void
-fs_usage_fd_clear(thread, fd)
-    unsigned int thread;
-    unsigned int fd;
+init_shared_cache_mapping(void)
 {
-    fd_threadmap *map;
+       read_shared_cache_map("/var/db/dyld/dyld_shared_cache_i386.map", &framework32, "/var/db/dyld/dyld_shared_cache_i386");
+
+       if (0 == read_shared_cache_map("/var/db/dyld/dyld_shared_cache_x86_64h.map", &framework64h, "/var/db/dyld/dyld_shared_cache_x86_64h")) {
+               read_shared_cache_map("/var/db/dyld/dyld_shared_cache_x86_64.map", &framework64, "/var/db/dyld/dyld_shared_cache_x86_64");
+       }
 
-    if (!(map = find_fd_thread_map(thread)))
-       return;
+       sort_library_addresses();
+}
 
-    if (map->fd_setptr == (unsigned long *)0)
-       return;
+void
+lookup_name(uint64_t user_addr, char **type, char **name)
+{
+       int i;
+       int start, last;
+
+       static char *frameworkType[] = {
+               "<TEXT>    ",
+               "<DATA>    ",
+               "<OBJC>    ",
+               "<IMPORT>  ",
+               "<UNICODE> ",
+               "<IMAGE>   ",
+               "<LINKEDIT>",
+       };
+
+       *name = NULL;
+       *type = NULL;
+
+       if (num_libraries) {
+               if ((user_addr >= framework32.b_address && user_addr < framework32.e_address) ||
+                       (user_addr >= framework64.b_address && user_addr < framework64.e_address) ||
+                       (user_addr >= framework64h.b_address && user_addr < framework64h.e_address)) {
+
+                       start = 0;
+                       last  = num_libraries;
+
+                       for (i = num_libraries / 2; start < last; i = start + ((last - start) / 2)) {
+                               if (user_addr > library_infos[i].e_address)
+                                       start = i+1;
+                               else
+                                       last = i;
+                       }
 
-    /* clear the bit */
-    if (fd < map->fd_setsize)
-       map->fd_setptr[fd/FS_USAGE_NFDBITS] &= ~(1 << (fd % FS_USAGE_NFDBITS));
-    
-    return;
+                       if (start < num_libraries &&
+                               user_addr >= library_infos[start].b_address && user_addr < library_infos[start].e_address) {
+                               *type = frameworkType[library_infos[start].r_type];
+                               *name = library_infos[start].name;
+                       }
+               }
+       }
 }
 
+#pragma mark disk I/O tracking routines
 
-/*
- * ret = 1 means print the entry
- * ret = 0 means don't print the entry
- */
-int
-check_filter_mode(struct th_info * ti, int type, int error, int retval, char *sc_name)
+struct diskio *free_diskios = NULL;
+struct diskio *busy_diskios = NULL;
+
+struct diskio *
+diskio_start(unsigned long type, unsigned long bp, unsigned long dev,
+            unsigned long blkno, unsigned long iosize, ktrace_event_t event)
 {
-    int ret = 0;
-    int network_fd_isset = 0;
-    unsigned int fd;
-
-    if (filter_mode == DEFAULT_DO_NOT_FILTER)
-       return(1);
-
-    if (!strcmp (sc_name, "CACHE_HIT")) {
-            if (filter_mode & CACHEHIT_FILTER)
-                   /* Do not print if cachehit filter is set */
-                   return(0);
-           return (1);
-    }
-       
-    if (filter_mode & EXEC_FILTER)
-    {
-       if (!strcmp (sc_name, "execve"))
-           return(1);
-       return(0);
-    }
-    if ( !(filter_mode & (FILESYS_FILTER | NETWORK_FILTER)))
-       return(1);
-
-       
-    if (ti == (struct th_info *)0)
-    {
-       if(filter_mode & FILESYS_FILTER)
-           ret = 1;
-       else
-           ret = 0;
-       return(ret);
-    }
-
-    switch (type) {
-    case BSC_close:
-       fd = ti->arg1;
-       network_fd_isset = fs_usage_fd_isset(ti->thread, fd);
-       if (error == 0)
-       {
-           fs_usage_fd_clear(ti->thread,fd);
-       }
-       
-       if (network_fd_isset)
-       {
-           if (filter_mode & NETWORK_FILTER)
-               ret = 1;
+       const char *command;
+       struct diskio *dio;
+
+       if ((dio = free_diskios)) {
+               free_diskios = dio->next;
+       } else {
+               dio = malloc(sizeof (struct diskio));
        }
-       else if (filter_mode & FILESYS_FILTER)
-           ret = 1;
-       break;
-    case BSC_read:
-    case BSC_write:
-       /* we don't care about error in this case */
-       fd = ti->arg1;
-       network_fd_isset = fs_usage_fd_isset(ti->thread, fd);
-       if (network_fd_isset)
-       {
-           if (filter_mode & NETWORK_FILTER)
-               ret = 1;
+
+       dio->prev = NULL;
+
+       dio->type = type;
+       dio->bp = bp;
+       dio->dev = dev;
+       dio->blkno = blkno;
+       dio->iosize = iosize;
+       dio->issued_time = event->timestamp;
+       dio->issuing_thread = event->threadid;
+       dio->issuing_pid = ktrace_get_pid_for_thread(s, event->threadid);
+
+       dio->bc_info = 0x0;
+
+       command = ktrace_get_execname_for_thread(s, event->threadid);
+
+       if (!command)
+               command = "";
+
+       strncpy(dio->issuing_command, command, MAXCOMLEN);
+       dio->issuing_command[MAXCOMLEN] = '\0';
+
+       dio->next = busy_diskios;
+
+       if (dio->next)
+               dio->next->prev = dio;
+
+       busy_diskios = dio;
+
+       return dio;
+}
+
+struct diskio *
+diskio_find(unsigned long bp)
+{
+       struct diskio *dio;
+
+       for (dio = busy_diskios; dio; dio = dio->next) {
+               if (dio->bp == bp)
+                       return dio;
        }
-       else if (filter_mode & FILESYS_FILTER)
-           ret = 1;    
-       break;
-    case BSC_accept:
-    case BSC_socket:
-       fd = retval;
-       if (error == 0)
-           fs_usage_fd_set(ti->thread, fd);
-       if (filter_mode & NETWORK_FILTER)
-           ret = 1;
-       break;
-    case BSC_recvfrom:
-    case BSC_sendto:
-    case BSC_recvmsg:
-    case BSC_sendmsg:
-    case BSC_connect:
-    case BSC_bind:
-    case BSC_listen:       
-       fd = ti->arg1;
-       if (error == 0)
-           fs_usage_fd_set(ti->thread, fd);
-       if (filter_mode & NETWORK_FILTER)
-           ret = 1;
-       break;
-    case BSC_select:
-    case BSC_socketpair:
-       /* Cannot determine info about file descriptors */
-       if (filter_mode & NETWORK_FILTER)
-           ret = 1;
-       break;
-    case BSC_dup:
-    case BSC_dup2:
-       ret=0;   /* We track these cases for fd state only */
-       fd = ti->arg1;  /* oldd */
-       network_fd_isset = fs_usage_fd_isset(ti->thread, fd);
-       if (error == 0 && network_fd_isset)
-       {
-           /* then we are duping a socket descriptor */
-           fd = retval;  /* the new fd */
-           fs_usage_fd_set(ti->thread, fd);
+
+       return NULL;
+}
+
+struct diskio *
+diskio_complete(unsigned long bp, unsigned long io_errno, unsigned long resid,
+               uintptr_t thread, uint64_t curtime, struct timeval curtime_wall)
+{
+       struct diskio *dio;
+
+       if ((dio = diskio_find(bp)) == NULL) return NULL;
+
+       if (dio == busy_diskios) {
+               if ((busy_diskios = dio->next))
+                       dio->next->prev = NULL;
+       } else {
+               if (dio->next)
+                       dio->next->prev = dio->prev;
+               dio->prev->next = dio->next;
        }
-       break;
 
-    default:
-       if (filter_mode & FILESYS_FILTER)
-           ret = 1;
-       break;
-    }
+       dio->iosize -= resid;
+       dio->io_errno = io_errno;
+       dio->completed_time = curtime;
+       dio->completed_walltime = curtime_wall;
+       dio->completion_thread = thread;
 
-    return(ret);
+       return dio;
 }
 
-/*
- * Allocate a buffer that is large enough to hold the maximum arguments
- * to execve().  This is used when getting the arguments to programs
- * when we see LaunchCFMApps.  If this fails, it is not fatal, we will
- * simply not resolve the command name.
- */
+void
+diskio_free(struct diskio *dio)
+{
+       dio->next = free_diskios;
+       free_diskios = dio;
+}
 
 void
-init_arguments_buffer()
+diskio_print(struct diskio *dio)
 {
+       char  *p = NULL;
+       int   len = 0;
+       unsigned long type;
+       int   format = FMT_DISKIO;
+       char  buf[64];
+
+       type = dio->type;
+       dio->is_meta = 0;
+
+       if ((type & P_CS_Class) == P_CS_Class) {
+               switch (type) {
+                       case P_CS_ReadChunk:
+                               p = "    RdChunkCS";
+                               len = 13;
+                               format = FMT_DISKIO_CS;
+                               break;
+                       case P_CS_WriteChunk:
+                               p = "    WrChunkCS";
+                               len = 13;
+                               format = FMT_DISKIO_CS;
+                               break;
+                       case P_CS_MetaRead:
+                               p = "  RdMetaCS";
+                               len = 10;
+                               format = FMT_DISKIO_CS;
+                               break;
+                       case P_CS_MetaWrite:
+                               p = "  WrMetaCS";
+                               len = 10;
+                               format = FMT_DISKIO_CS;
+                               break;
+                       case P_CS_TransformRead:
+                               p = "  RdBgTfCS";
+                               len = 10;
+                               break;
+                       case P_CS_TransformWrite:
+                               p = "  WrBgTfCS";
+                               len = 10;
+                               break;
+                       case P_CS_MigrationRead:
+                               p = "  RdBgMigrCS";
+                               len = 12;
+                               break;
+                       case P_CS_MigrationWrite:
+                               p = "  WrBgMigrCS";
+                               len = 12;
+                               break;
+                       default:
+                               p = "  CS";
+                               len = 4;
+                               break;
+               }
+
+               strncpy(buf, p, len);
+       } else {
+               switch (type & P_DISKIO_TYPE) {
+                       case P_RdMeta:
+                               dio->is_meta = 1;
+                               p = "  RdMeta";
+                               len = 8;
+                               break;
+                       case P_WrMeta:
+                               dio->is_meta = 1;
+                               p = "  WrMeta";
+                               len = 8;
+                               break;
+                       case P_RdData:
+                               p = "  RdData";
+                               len = 8;
+                               break;
+                       case P_WrData:
+                               p = "  WrData";
+                               len = 8;
+                               break;
+                       case P_PgIn:
+                               p = "  PgIn";
+                               len = 6;
+                               break;
+                       case P_PgOut:
+                               p = "  PgOut";
+                               len = 7;
+                               break;
+                       default:
+                               p = "  ";
+                               len = 2;
+                               break;
+               }
 
-    int     mib[2];
-    size_t  size;
+               strncpy(buf, p, len);
 
-    mib[0] = CTL_KERN;
-    mib[1] = KERN_ARGMAX;
-    size = sizeof(argmax);
-    if (sysctl(mib, 2, &argmax, &size, NULL, 0) == -1)
-       return;
+               buf[len++] = '[';
 
-#if 1
-    /* Hack to avoid kernel bug. */
-    if (argmax > 8192) {
-       argmax = 8192;
-    }
-#endif
+               if (type & P_DISKIO_ASYNC)
+                       buf[len++] = 'A';
+               else
+                       buf[len++] = 'S';
+
+               if (type & P_DISKIO_NOCACHE)
+                       buf[len++] = 'N';
+
+               int tier = (type & P_DISKIO_TIER_MASK) >> P_DISKIO_TIER_SHIFT;
 
-    arguments = (char *)malloc(argmax);
-    
-    return;
+               if (tier > 0) {
+                       buf[len++] = 'T';
+                       if (tier > 0 && tier < 10)
+                               buf[len++] = '0' + tier;
+
+                       if (type & P_DISKIO_TIER_UPGRADE) {
+                               buf[len++] = 'U';
+                       }
+               }
+
+               if (type & P_DISKIO_PASSIVE)
+                       buf[len++] = 'P';
+
+               buf[len++] = ']';
+       }
+
+       buf[len] = 0;
+
+       if (check_filter_mode(-1, NULL, type, 0, 0, buf))
+               format_print(NULL, buf, NULL, type, format, dio->completed_time, dio->issued_time, 1, "", dio);
 }
 
+#pragma mark disk name routines
 
-int
-get_real_command_name(int pid, char *cbuf, int csize)
+struct diskrec {
+       struct diskrec *next;
+       char *diskname;
+       int   dev;
+};
+
+struct diskrec *disk_list = NULL;
+
+void
+cache_disk_names(void)
 {
-    /*
-     *      Get command and arguments.
-     */
-    char  *cp;
-    int             mib[4];
-    char    *command_beg, *command, *command_end;
-
-    if (cbuf == NULL) {
-       return(0);
-    }
-
-    if (arguments)
-       bzero(arguments, argmax);
-    else
-       return(0);
-
-    /*
-     * A sysctl() is made to find out the full path that the command
-     * was called with.
-     */
-    mib[0] = CTL_KERN;
-    mib[1] = KERN_PROCARGS;
-    mib[2] = pid;
-    mib[3] = 0;
-
-    if (sysctl(mib, 3, arguments, (size_t *)&argmax, NULL, 0) < 0) {
-       return(0);
-    }
-
-    /* Skip the saved exec_path. */
-    for (cp = arguments; cp < &arguments[argmax]; cp++) {
-       if (*cp == '\0') {
-           /* End of exec_path reached. */
-           break;
-       }
-    }
-    if (cp == &arguments[argmax]) {
-       return(0);
-    }
-
-    /* Skip trailing '\0' characters. */
-    for (; cp < &arguments[argmax]; cp++) {
-       if (*cp != '\0') {
-           /* Beginning of first argument reached. */
-           break;
+       struct stat    st;
+       DIR            *dirp = NULL;
+       struct dirent  *dir;
+       struct diskrec *dnp;
+
+       if ((dirp = opendir("/dev")) == NULL)
+               return;
+
+       while ((dir = readdir(dirp)) != NULL) {
+               char nbuf[MAXPATHLEN];
+
+               if (dir->d_namlen < 5 || strncmp("disk", dir->d_name, 4))
+                       continue;
+
+               snprintf(nbuf, MAXPATHLEN, "%s/%s", "/dev", dir->d_name);
+
+               if (stat(nbuf, &st) < 0)
+                       continue;
+
+               if ((dnp = malloc(sizeof(struct diskrec))) == NULL)
+                       continue;
+
+               if ((dnp->diskname = malloc(dir->d_namlen + 1)) == NULL) {
+                       free(dnp);
+                       continue;
+               }
+               strncpy(dnp->diskname, dir->d_name, dir->d_namlen);
+               dnp->diskname[dir->d_namlen] = 0;
+               dnp->dev = st.st_rdev;
+
+               dnp->next = disk_list;
+               disk_list = dnp;
        }
-    }
-    if (cp == &arguments[argmax]) {
-       return(0);
-    }
-    command_beg = cp;
-
-    /*
-     * Make sure that the command is '\0'-terminated.  This protects
-     * against malicious programs; under normal operation this never
-     * ends up being a problem..
-     */
-    for (; cp < &arguments[argmax]; cp++) {
-       if (*cp == '\0') {
-           /* End of first argument reached. */
-           break;
+
+       closedir(dirp);
+}
+
+static void
+recache_disk_names(void)
+{
+       struct diskrec *dnp, *next_dnp;
+
+       for (dnp = disk_list; dnp; dnp = next_dnp) {
+               next_dnp = dnp->next;
+
+               free(dnp->diskname);
+               free(dnp);
        }
-    }
-    if (cp == &arguments[argmax]) {
-       return(0);
-    }
-    command_end = command = cp;
-
-    /* Get the basename of command. */
-    for (command--; command >= command_beg; command--) {
-       if (*command == '/') {
-           command++;
-           break;
+
+       disk_list = NULL;
+       cache_disk_names();
+}
+
+char *
+find_disk_name(unsigned long dev)
+{
+       struct diskrec *dnp;
+       int     i;
+
+       if (dev == NFS_DEV)
+               return ("NFS");
+
+       if (dev == CS_DEV)
+               return ("CS");
+
+       for (i = 0; i < 2; i++) {
+               for (dnp = disk_list; dnp; dnp = dnp->next) {
+                       if (dnp->dev == dev)
+                               return (dnp->diskname);
+               }
+               recache_disk_names();
        }
-    }
 
-    (void) strncpy(cbuf, (char *)command, csize);
-    cbuf[csize-1] = '\0';
+       return "NOTFOUND";
+}
+
+char *
+generate_cs_disk_name(unsigned long dev, char *s)
+{
+       if (dev == -1)
+               return "UNKNOWN";
+
+       sprintf(s, "disk%lus%lu", (dev >> 16) & 0xffff, dev & 0xffff);
 
-    return(1);
+       return (s);
 }