4 ms·
I hadn't considered this! Can eBPF be used to access arbitrary kernel data structures, though?
by ksml 6y ago
I hadn't considered this! Can eBPF be used to access arbitrary kernel data structures, though?
- warybeary 6y agoYes (to a degree) :) Check out https://github.com/iovisor/bpftrace https://github.com/iovisor/bpftrace and the example tools/ for a taste. You'll likely want to play with kprobes/kretprobes.
- ksml 6y agoThis is really interesting; I hadn't realized it was so capable/general. I'll look into this. Thanks for the references!
- deleted 6y ago[deleted]
- lathiat 6y agoYou should also check out bpftrace which is a specific DSL to write both the kernel and userspace part in one language - rather than the mixed python/C approach people mostly took before that. And you can output things potentially as text or json for parsing. https://github.com/iovisor/bpftrace https://github.com/iovisor/bpftrace I would also strongly recommend Brendan Greggs book: http://www.brendangregg.com/bpf-performance-tools-book.html http://www.brendangregg.com/bpf-performance-tools-book.html