/
ringbuf_output.py
executable file
·53 lines (37 loc) · 1.02 KB
/
ringbuf_output.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
#!/usr/bin/python3
import sys
import time
from bcc import BPF
src = r"""
BPF_RINGBUF_OUTPUT(buffer, 1 << 4);
struct event {
char filename[16];
int dfd;
int flags;
int mode;
};
TRACEPOINT_PROBE(syscalls, sys_enter_openat) {
int zero = 0;
struct event event = {};
bpf_probe_read_user_str(event.filename, sizeof(event.filename), args->filename);
event.dfd = args->dfd;
event.flags = args->flags;
event.mode = args->mode;
buffer.ringbuf_output(&event, sizeof(event), 0);
return 0;
}
"""
b = BPF(text=src)
def callback(ctx, data, size):
event = b['buffer'].event(data)
print("%-16s %10d %10d %10d" % (event.filename.decode('utf-8'), event.dfd, event.flags, event.mode))
b['buffer'].open_ring_buffer(callback)
print("Printing openat() calls, ctrl-c to exit.")
print("%-16s %10s %10s %10s" % ("FILENAME", "DIR_FD", "FLAGS", "MODE"))
try:
while 1:
b.ring_buffer_poll()
# or b.ring_buffer_consume()
time.sleep(0.5)
except KeyboardInterrupt:
sys.exit()