Function analysis
Symbol-based ziskemu profiling, unlocked with -S / --read-symbols. Covers Regions of Interest (top-cost functions), function-name display, the PC histogram, call-argument tracking, and the Firefox Profiler export.
The views on this page need symbols. Add -S / --read-symbols to read
the function names already present in the ELF (no instrumentation or debug
build required) — then ziskemu can attribute cost to functions, group
hot instructions, and track calls.
Regions of Interest
With symbols loaded, the report ranks the most expensive functions — its Regions of Interest (ROI).
ziskemu -e program.elf -i input.bin -X -S
| Flag | Short | Default | Description |
|---|---|---|---|
--read-symbols | -S | false | Load function names/symbols from the ELF. Required for all function-level views. |
--top-roi <N> | -T | 25 | Number of top functions to display. |
--top-roi-detail | -D | false | Detailed breakdown per top function: where its cost comes from and who calls it. |
--roi-callers <N> | -C | 10 | Number of top callers to show per function (with -D). |
--roi-filter <REGEX> | — | Mark functions whose name matches the regular expression as ROIs. | |
--top-roi-filter | false | Show only functions matching --roi-filter in the top lists. | |
--main-name <NAME> | -M | main | Name of the program's entry-point function. |
# Show only the EVM opcode implementations, top 200, by cost
ziskemu -e guest.elf -i input.bin -X -S \
--roi-filter "revm_interpreter::instructions::" --top-roi-filter -T 200
Call-stack tracking
Attributing cost to callers means reconstructing the call stack from the
executed instructions, and that heuristic can lose sync. GCC/C++
tail-recursion is the usual cause: a single machine ret unwinds
several nested self-recursive frames that were tracked as separate
calls — std::sort's __introsort_loop is the classic example.
| Flag | Default | Description |
|---|---|---|
--callstack-mode <MODE> | auto | auto resyncs on a mismatch by discarding the collapsed frames until the one that returns into the current function. strict is the original behaviour: report STACK MISMATCH DETECTED and disable call-stack tracking for the rest of the run. |
Use strict when you want to know that the stack went out of sync
rather than have it silently repaired — the caller attribution after a
resync is a best guess.
Duplicate precompile calls by call path
--duplicates-detail extends the duplicate-precompile analysis with the
call paths the repeated calls came from, which needs symbols. See
Precompile duplicates.
Function name display
Rust symbols can be long. These flags control how function names are rendered in the reports:
| Flag | Default | Description |
|---|---|---|
--compact-names <N> | 160 | Truncate displayed function names to N characters. |
--no-compact-names | false | Disable name truncation; show full names. |
PC histogram
-H / --top-histogram gives an instruction-level view: the most frequently
executed program-counter addresses, grouped into sequences and attributed
to their function when symbols are loaded. Useful for spotting hot loops.
ziskemu -e program.elf -i input.bin -X -S -H 50
The number after -H controls how many instruction groups to display;
-S is required to resolve function names.
Function-call tracking
Combine --roi-filter with --track-call-args to log the argument values
of each call to matching functions — handy for finding common parameter
patterns. Up to 8 arguments (RISC-V a0–a7) can be logged.
| Flag | Default | Description |
|---|---|---|
--roi-filter <REGEX> | — | Functions to track (required). |
--track-call-args <N> | — | Number of arguments to log per call (1–8). |
--track-separator <SEP> | ; | Separator between argument values in the output. |
--track-output-path <DIR> | . | Directory where one <function>.txt file per matched function is written. |
ziskemu -e guest.elf -i input.bin -S \
--roi-filter "hash_function" --track-call-args 4 --track-output-path ./traces
Firefox Profiler export
--profiler-output writes the run as a Firefox Profiler trace you can load
at profiler.firefox.com for interactive,
flame-graph–style analysis. Using -X -S without this flag still creates
profile.json.gz automatically.
# Compressed (recommended) or plain JSON
ziskemu -e program.elf -i input.bin -X -S --profiler-output=profile.json.gz
Putting it together
A comprehensive profiling pass — statistics, symbols, detailed callers, histogram, a focused ROI filter, and call tracking:
ziskemu -e program.elf -i input.bin \
-X -S -D \
-T 30 -C 15 -H 50 \
--roi-filter "sha256|hash" \
--track-call-args 6 --track-output-path ./profiling_data \
-m
For a guided, tutorial-style walkthrough of this workflow, see Profiling in depth.