3 ms·
Have you looked into using eBPF instead of writing a kernel module? http://ebpf.io http://ebpf.io for some more insights. At the very least, it'll provide som
by warybeary 6y ago
Have you looked into using eBPF instead of writing a kernel module?
http://ebpf.io http://ebpf.io for some more insights.
At the very least, it'll provide some useful tooling for you to debug problems in kernel-space.
- ksml 6y agoI hadn't considered this! Can eBPF be used to access arbitrary kernel data structures, though?
- warybeary 6y agoYes (to a degree) :) Check out https://github.com/iovisor/bpftrace https://github.com/iovisor/bpftrace and the example tools/ for a taste. You'll likely want to play with kprobes/kretprobes.
- ksml 6y agoThis is really interesting; I hadn't realized it was so capable/general. I'll look into this. Thanks for the references!
- deleted 6y ago[deleted]
- lathiat 6y agoYou should also check out bpftrace which is a specific DSL to write both the kernel and userspace part in one language - rather than the mixed python/C approach people mostly took before that. And you can output things potentially as text or json for parsing. https://github.com/iovisor/bpftrace https://github.com/iovisor/bpftrace I would also strongly recommend Brendan Greggs book: http://www.brendangregg.com/bpf-performance-tools-book.html http://www.brendangregg.com/bpf-performance-tools-book.html