4 ms·
From the bpftrace tutorial, I would have expected the one-liner bpftrace -e 'tracepoint:syscalls:sys_enter_open { printf("%d %s\n", pid, str(args->filename
by lower 8y ago
From the bpftrace tutorial, I would have expected the one-liner
bpftrace -e 'tracepoint:syscalls:sys_enter_open { printf("%d %s\n", pid, str(args->filename)); }'
to show me all open calls as they happen. I would have expected to see an open when I cat a file, for example. But trying the one-liner, I only see a few opens of files in /proc.
Can anyone explain what's happening?
- danobi 8y agoIt actually turns out most of the calls are `openat(2)`. I had the same question initially.
- livueta 8y ago(don't have access to a linux box I can test this on at the moment, so sorry for the stupid question) In DTrace, you can specify a probe like syscall::*open*:entry / / { } to grab open(2), openat(2), etc. Does eBPF allow wildcards in probe specifications?
- lower 8y agoYou can do bpftrace -e 'tracepoint:syscalls:sys_enter_open* { printf("%d\n", pid); }' but then you can't access the arguments of the different probes uniformly, i.e. bpftrace -e 'tracepoint:syscalls:sys_enter_open* { printf("%d %s\n", pid, str(args->filename)); }' does not work. You can do it like this: bpftrace -e 'tracepoint:syscalls:sys_enter_open { printf("%d %s\n", pid, str(args->filename)); } tracepoint:syscalls:sys_enter_openat { printf("%d %s\n", pid, str(args->filename)); }' This is a bit awkward, but it seems that this will be fixed: https://github.com/iovisor/bpftrace/issues/132 https://github.com/iovisor/bpftrace/issues/132