#!/usr/bin/python3
# coding=utf-8
from __future__ import print_function
from bcc import BPF
#from bcc import bcc
from time import sleep
# define BPF program
import os
bpf_program = """
#include <uapi/linux/ptrace.h>
struct key_t{
u64 pid;
};
BPF_HASH2(counts, struct key_t);
int trace_function(struct pt_regs *ctx) {
u64 zero = 0, *val, pid;
pid = bpf_get_current_pid_tgid() >> 32;
struct key_t key = {};
key.pid = pid;
val = counts.lookup_or_init(&key, &zero);
if (val) {
(*val)++;
}
return 0;
}
"""
def pid_to_comm(pid):
try:
comm = open("/proc/%s/comm" % pid, "r").read().rstrip()
return comm
except IOError:
return str(pid)
# load BPF
trace_path="/sys/kernel/debug/tracing/events"
key_list=os.listdir("/sys/kernel/debug/tracing/events")
for i in key_list:
if os.path.isdir("/sys/kernel/debug/tracing/events/"+str(i)):
print(i)
print("---------------------------------------------------------\n")
trace_key=input("选择你的trace对象:")
event_list=os.listdir("/sys/kernel/debug/tracing/events/"+str(trace_key))
for i in event_list:
if os.path.isdir("/sys/kernel/debug/tracing/events/"+str(trace_key)+"/"+str(i)):
print(i)
print("---------------------------------------------------------\n")
trace_event=input("选择你的trace事件:")
trace_p=str(trace_key)+":"+str(trace_event)
b = BPF(text=bpf_program)
b.attach_tracepoint(tp=trace_p, fn_name="trace_function")
# header
print("Tracing kfree_skb... Ctrl-C to end.")
print("%-10s %-12s %-10s" % ("进程号", "进程名", "调用次数"))
while 1:
sleep(1)
for k, v in sorted(b["counts"].items(),key = lambda counts: counts[1].value):
print("%-10d %-12s %-10d" % (k.pid, pid_to_comm(k.pid), v.value))
print("----------------------------------------------------------\n")
bpf tracepoint脚本
最新推荐文章于 2024-03-16 09:43:08 发布