Stop Ftrace Recording with trace-cmd stop

trace-cmd stop pauses new writes to the Ftrace ring buffer without discarding what it already holds. It leaves the captured data ready for inspection or extraction, and steers you away from the classic mistake of reaching for reset when you only meant to pause recording. The examples use trace-cmd 3.2.0 from the installed Ubuntu package trace-cmd 3.2-1ubuntu2.

Allow about ten minutes. You need a shell, an existing Ftrace session started with trace-cmd start or another tracing workflow, and enough privilege to access the kernel tracing files. Stopping tracing is service-disrupting for anyone using that tracing session, so check ownership before you run the command.

1. Confirm the Installed Command

Start with a read-only check of the executable and its built-in usage:

$ command -v trace-cmd
/usr/bin/trace-cmd
$ trace-cmd --version
trace-cmd version 3.2.0 (not-a-git-repo)
$ trace-cmd stop --help
 trace-cmd stop [-B buf [-B buf]..] [-a] [-t]

The command is a subcommand, so the form is trace-cmd stop, not a separate trace-cmd-stop executable. The installed help also confirms the three stop-specific options.

Checkpoint: If command -v points somewhere unexpected, stop here and check your package or PATH. Do not diagnose a tracing session using a different trace-cmd installation from the one that started it.

2. Stop the Default Top-Level Buffer

For a normal session with no named buffer instances, run:

$ sudo trace-cmd stop
$ printf 'stop status: %s\n' "$?"
stop status: 0

The command normally prints no success message. Status 0 means the stop command completed; the meaningful effect is that Ftrace stops updating the selected ring buffer. sudo is an example, not a universal requirement: if your account can access the tracing files, omit it. If an unprivileged invocation reports permission denied, retry with the privilege appropriate to the host rather than changing file permissions.

Warning: Stopping the buffer does not turn off the tracer itself. Tracing can still impose overhead after the buffer stops accepting new records. This distinction matters on a busy host: the command preserves a useful capture, but it is not a full performance rollback.

3. Keep the Captured Data First

Once recording is stopped, preserve the buffer before experimenting. The trace-cmd workflow provides extract for pulling the data into a trace.dat file:

$ sudo trace-cmd extract -o /path/to/trace.dat
$ printf 'extract status: %s\n' "$?"
extract status: 0

Replace /path/to/trace.dat with a new destination that has enough space. Do not overwrite an existing capture until you have checked it. The exact report content depends on the events and options that were active when the trace started.

Checkpoint: Confirm that the destination exists and is non-empty:

$ test -s /path/to/trace.dat && printf '%s\n' 'trace.dat is ready to report'
trace.dat is ready to report

If extraction fails, keep the tracing state unchanged while you investigate the error. Do not jump to reset as a recovery step: reset clears the recorded ring-buffer data.

4. Stop Named Buffer Instances Deliberately

Systems with multiple Ftrace buffers need an explicit scope. Use -B once for each named buffer you want to stop:

$ sudo trace-cmd stop -B BUFFER_NAME
$ printf 'stop status: %s\n' "$?"
stop status: 0

Replace BUFFER_NAME with the exact instance name configured on your host. This stops that buffer only: it does not stop other buffer instances, and it does not stop the top-level buffer when -B is present.

To stop all existing buffer instances, excluding the top-level buffer, use -a:

$ sudo trace-cmd stop -a
$ printf 'stop status: %s\n' "$?"
stop status: 0

To include the top-level buffer in either scoped form, add -t:

$ sudo trace-cmd stop -a -t
$ printf 'stop status: %s\n' "$?"
stop status: 0

Tip: These options are easy to misread. -a means all buffer instances, but not the top-level instance; -t adds the top-level instance. If you only want one instance, do not use -a.

5. Resume or Finish Safely

A stop is reversible while the tracing setup is still available. To resume recording after a deliberate pause, use the companion command:

$ sudo trace-cmd restart
$ printf 'restart status: %s\n' "$?"
restart status: 0

restart resumes recording after a previous stop. Treat it as a state change and confirm that resuming is wanted before running it, especially when another operator asked you to freeze a capture.

Warning: Do not use trace-cmd reset merely to silence tracing. Reset disables Ftrace tracing and clears the data in the ring buffers, so it is destructive to an unextracted capture. Use it only after the data has been extracted or deliberately discarded:

$ sudo trace-cmd reset
$ printf 'reset status: %s\n' "$?"
reset status: 0

There is no undo command for data cleared by reset. Your recovery is an earlier trace.dat copy or a new trace.

6. Handle the Common Failure Modes

Done means