Learn EBPF Tracing: Tutorial and Examples
brendangregg.com
brendangregg.com
Last three times I tried to install bcc/bpftrace on my Debian boxes, I failed to do so. The situation has not changed for over a year. I'm not the only one:
https://github.com/iovisor/bcc/issues/678
You don’t need to build it from source yourself. The LLVM people build and host packages for Debian and Ubuntu in package repos that anyone can install from.
Instructions here: https://apt.llvm.org/
bpftrace -e 'tracepoint:syscalls:sys_enter_open { printf("%d %s\n", pid, str(args->filename)); }'
to show me all open calls as they happen. I would have expected to see an open when I cat a file, for example. But trying the one-liner, I only see a few opens of files in /proc.Can anyone explain what's happening?
In DTrace, you can specify a probe like
syscall::*open*:entry / / { }
to grab open(2), openat(2), etc. Does eBPF allow wildcards in probe specifications? bpftrace -e 'tracepoint:syscalls:sys_enter_open* { printf("%d\n", pid); }'
but then you can't access the arguments of the different probes uniformly, i.e. bpftrace -e 'tracepoint:syscalls:sys_enter_open* { printf("%d %s\n", pid, str(args->filename)); }'
does not work.You can do it like this:
bpftrace -e 'tracepoint:syscalls:sys_enter_open { printf("%d %s\n", pid, str(args->filename)); } tracepoint:syscalls:sys_enter_openat { printf("%d %s\n", pid, str(args->filename)); }'
This is a bit awkward, but it seems that this will be fixed: https://github.com/iovisor/bpftrace/issues/132[0] https://media.ccc.de/v/35c3-9532-kernel_tracing_with_ebpf
You can use Let's Encrypt, it's free. It makes me not want to listen to what's supposed to be their wisdom on networking matters if they can't even get that right.
Does that really need downvoting into oblivion?
Maybe he'll fix it if someone points it out to him.