Pin: Building Customized Program Analysis Tools with Dynamic Instrumentation
Chi-Keung Luk Robert Cohn Robert Muth Harish Patil Artur Klauser Geoff Lowney
Steven Wallace Vijay Janapa Reddi y Kim Hazelwood
Intel Corporation yUniversity of Colorado
Website http rogue colorado edu Pin Email pin project intel com
Abstract 1. Introduction Robust and powerful software instrumentation tools are essential As software complexity increases, instrumentation—a technique for program analysis tasks such as profiling, performance evalu- for inserting extra code into an application to observe its behavior— ation, and bug detection. To meet this need, we have developed is becoming more important. Instrumentation can be performed at a new instrumentation system called Pin. Our goals are to pro- various stages: in the source code, at compile time, post link time, vide easy-to-use, portable, transparent, and efficient instrumenta- or at run time. Pin is a software system that performs run-time tion. Instrumentation tools (called Pintools) are written in C/C++ binary instrumentation of Linux applications. using Pin’s rich API. Pin follows the model of ATOM, allowing the The goal of Pin is to provide an instrumentation platform for tool writer to analyze an application at the instruction level with- building a wide variety of program analysis tools for multiple archi- out the need for detailed knowledge of the underlying instruction tectures. As a result, the design emphasizes ease-of-use, portabil- set. The API is designed to be architecture independent whenever ity, transparency, efficiency, and robustness. This paper describes possible, making Pintools source compatible across different archi- the design of Pin and shows how it provides these features. tectures. However, a Pintool can access architecture-specific details Pin’s instrumentation is easy to use. Its user model is similar when necessary. Instrumentation with Pin is mostly transparent as to the popular ATOM [30] API, which allows a tool to insert calls the application and Pintool observe the application’s original, unin- to instrumentation at arbitrary locations in the executable. Users strumented behavior. Pin uses dynamic compilation to instrument do not need to manually inline instructions or save and restore executables while they are running. For efficiency, Pin uses sev- state. Pin provides a rich API that abstracts away the underlying eral techniques, including inlining, register re-allocation, liveness instruction set idiosyncrasies, making it possible to write portable analysis, and instruction scheduling to optimize instrumentation. instrumentation tools. The Pin distribution includes many sample This fully automated approach delivers significantly better instru- architecture-independent Pintools including profilers, cache simu- mentation performance than similar tools. For example, Pin is 3.3x lators, trace analyzers, and memory bug checkers. The API also faster than Valgrind and 2x faster than DynamoRIO for basic-block allows access to architecture-specific information. counting. To illustrate Pin’s versatility, we describe two Pintools Pin provides efficient instrumentation by using a just-in-time in daily use to analyze production software. Pin is publicly avail- (JIT) compiler to insert and optimize code. In addition to some able for Linux platforms on four architectures: IA32 (32-bit x86), standard techniques for dynamic instrumentation systems includ- EM64T (64-bit x86), ItaniumR , and ARM. In the ten months since ing code caching and trace linking, Pin implements register re- Pin 2 was released in July 2004, there have been over 3000 down- allocation, inlining, liveness analysis, and instruction scheduling to loads from its website. optimize jitted code. This fully automated approach distinguishes Pin from most other instrumentation tools which require the user’s Categories and Subject Descriptors D.2.5 [Software Engineer- assistance to boost performance. For example, Valgrind [22] re- ing]: Testing and Debugging-code inspections and walk-throughs, lies on the tool writer to insert special operations in their in- debugging aids, tracing; D.3.4 [Programming Languages]: Processors- termediate representation in order to perform inlining; similarly compilers, incremental compilers DynamoRIO [6] requires the tool writer to manually inline and save/restore application registers. General Terms Languages, Performance, Experimentation Another feature that makes Pin efficient is process attaching Keywords Instrumentation, program analysis tools, dynamic com- and detaching. Like a debugger, Pin can attach to a process, in- pilation strument it, collect profiles, and eventually detach. The application only incurs instrumentation overhead during the period that Pin is attached. The ability to attach and detach is a necessity for the in- strumentation of large, long-running applications. Pin’s JIT-based instrumentation defers code discovery until run time, allowing Pin to be more robust than systems that use static Permission to make digital or hard copies of all or part of this work for personal or instrumentation or code patching. Pin can seamlessly handle mixed classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation code and data, variable-length instructions, statically unknown in- on the first page. To copy otherwise, to republish, to post on servers or to redistribute direct jump targets, dynamically loaded libraries, and dynamically to lists, requires prior specific permission and/or a fee. generated code.
PLDI’05 June 12Ð15,2005,Chicago,Illinois,USA. Pin preserves the original application behavior by providing in- Copyright c 2005 ACM 1-59593-080-9/05/0006 $5.00. strumentation transparency. The application observes the same ad-
dresses (both instruction and data) and same values (both register