Question about system call coverage #3165
Replies: 2 comments 1 reply
-
The list of events not only include system calls events, but many other events that we have (e.g. network events and signature events). Which system calls you think are missing in these lists? |
Beta Was this translation helpful? Give feedback.
-
For the trace data obtained by tracee, what is the time unit of the following two fields?
|
Beta Was this translation helpful? Give feedback.
-
Tracee shows (./dist/tracee -l) a total of 446 system calls for tracing.
However, from the linux kernel source code (5.10), the arm version of the kernel provides 406 system calls, see the table (syscall.tbl). X86 provides 388 (5.10).
After comparison, there are 52 arm (5.10) system calls that are not in the tracee (0.13.1) system call list provided by your team. Whether the comprehensiveness of the trace data obtained by using tracee will be affected.
Beta Was this translation helpful? Give feedback.
All reactions