3 ms·
I hadn't considered eBPF because I needed some pretty obscure information from the kernel internals (i.e. the addresses of the `struct file`s) and I didn't real
by ksml 6y ago
I hadn't considered eBPF because I needed some pretty obscure information from the kernel internals (i.e. the addresses of the `struct file`s) and I didn't realize eBPF was as capable as it is. Another commenter suggested trying it, though, so I'm checking it out now!
I did use printk for debugging, but I (incorrectly) assumed it could block. Another commenter pointed out that this is not the case. TIL!
The gdb link looks very helpful and I'll try that next time. Thanks for linking that.
- PeterCorless 6y agoYeah, my mind immediately went to eBPF too. "But when BPF got extended, it allowed users to add code that is executed by the kernel in a safe manner in various points of its execution, not only in the network code." Read more here: https://thenewstack.io/how-io_uring-and-ebpf-will-revolutionize-programming-in-linux/ https://thenewstack.io/how-io_uring-and-ebpf-will-revolution...