This commit is contained in:
ocfox
2023-03-09 03:40:30 +00:00
parent a54b88ce20
commit 184e1c7eb3
121 changed files with 24872 additions and 0 deletions

7
4-opensnoop/.gitignore vendored Normal file
View File

@@ -0,0 +1,7 @@
.vscode
package.json
eunomia-exporter
ecli
*.bpf.o
*.skel.json
*.skel.yaml

271
4-opensnoop/index.html Normal file

File diff suppressed because one or more lines are too long

View File

@@ -0,0 +1,21 @@
#include <vmlinux.h>
#include <bpf/bpf_helpers.h>
/// @description "Process ID to trace"
const volatile int pid_target = 0;
SEC("tracepoint/syscalls/sys_enter_openat")
int tracepoint__syscalls__sys_enter_openat(struct trace_event_raw_sys_enter* ctx)
{
u64 id = bpf_get_current_pid_tgid();
u32 pid = id;
if (pid_target && pid_target != pid)
return false;
// Use bpf_printk to print the process information
bpf_printk("Process ID: %d enter sys openat\n", pid);
return 0;
}
/// "Trace open family syscalls."
char LICENSE[] SEC("license") = "GPL";