iovisor/bcc

update killsnoop to use tracepoints

Aperta

#3592 aperta il 27 ago 2021

 (7 commenti) (0 reazioni) (1 assegnatario)C (4072 fork)batch import
help wanted

Metriche repository

Star
 (22.626 stelle)
Metriche merge PR
 (Merge medio 12g 6h) (12 PR mergiate in 30 g)

Descrizione

This is a request for help.

I wrote killsnoop back in 2015 before tracepoint support, and so I kprobe'd sys_kill(). It still does some derivation of that. But now there's a report it no longer works on Linux 5.11: https://github.com/iovisor/bcc/pull/3572#issuecomment-900357032 CC @chenhengqi

Can someone please update killsnoop (both Python and libbpf-tools) to use tracepoints instead of kprobes (if it works as expected). All of these:

  syscalls:sys_enter_kill                            [Tracepoint event]
  syscalls:sys_enter_tgkill                          [Tracepoint event]
  syscalls:sys_enter_tkill                           [Tracepoint event]
  syscalls:sys_exit_kill                             [Tracepoint event]
  syscalls:sys_exit_tgkill                           [Tracepoint event]
  syscalls:sys_exit_tkill                            [Tracepoint event]

Guida contributor