forked from bpftrace/bpftrace
-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathkillsnoop.bt
executable file
·39 lines (36 loc) · 873 Bytes
/
killsnoop.bt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
#!/usr/bin/env bpftrace
/*
* killsnoop Trace signals issued by the kill() syscall.
* For Linux, uses bpftrace and eBPF.
*
* USAGE: killsnoop.bt
*
* Also a basic example of bpftrace.
*
* This is a bpftrace version of the bcc tool of the same name.
*
* Copyright 2018 Netflix, Inc.
* Licensed under the Apache License, Version 2.0 (the "License")
*
* 07-Sep-2018 Brendan Gregg Created this.
*/
BEGIN
{
printf("Tracing kill() signals... Hit Ctrl-C to end.\n");
printf("%-15s %7s %-16s %4s %6s %s\n",
"TIME", "PID", "COMM", "SIG", "TPID", "RESULT");
}
tracepoint:syscalls:sys_enter_kill
{
@tpid[tid] = args.pid;
@tsig[tid] = args.sig;
}
tracepoint:syscalls:sys_exit_kill
/@tpid[tid]/
{
printf("%-15s %7d %-16s %4d %6d %6d\n",
strftime("%H:%M:%S.%f", nsecs),
pid, comm, @tsig[tid], @tpid[tid], args.ret);
delete(@tpid, tid);
delete(@tsig, tid);
}