Unlocking eBPF power
devopsspiral.com
devopsspiral.com
https://github.com/devopsspiral/ebpf-bt-unlock/blob/master/b...
As BTF (BPF Type Format) becomes the default in kernels, this short tool will become even shorter: the "( struct hci_dev *) arg0" cast won't be necessary as the kernel will already know what type arg0 is. So line 9 can be skipped.
I see a lot of people start with other BPF tracers that made sense years ago as we hadn't built bpftrace yet. It'll really save you a lot of time to look at bpftrace first and then others only if need be. bpftrace is installed by default on all cloud instances at Netflix and other companies: it's the go-to tool for whipping up custom tracing programs.
Cool to see this spinoff from SysDig evolve into a fully funded cloud native product ;)
#!/snap/bin/bpftrace
#include <net/bluetooth/bluetooth.h>
#include <net/bluetooth/hci_core.h>
kprobe:mgmt_device_found
{
$dev=( struct hci_dev *) arg0;
printf("%s\n", $dev->name);
}
AFAIK that's way beyond Falco's capabilities.If you are interested in eBPF, consider attending the eBPF summit [0] on Oct 28-29. Community driven, free and virtual. I've spotted half a dozen "getting started with eBPF" type talks in the proposals already and we will select several of them.
Besides that, both eBPF maintainers, Brendan Gregg, as well as Cilium & Falco developers will speak. Definitely worth considering if you want to learn more about eBPF.
Edit: it is the Berkeley Packet Filter.
""" eBPF is a functionality of linux kernel that allows lightweight execution of user code as a response to kernel events. The events could be hardware/software events, tracing events both static (compiled into code) and dynamic (attached in runtime), etc. The code itself is limited in a sense that it is guaranteed to finish (no loops) and is verified before loading into kernel. """
Thanks for pointing this out!
A little while after that, eBPF stopped being an acronym and started being the actual name. It, as I understand it, no longer stands for "Extended Berkeley Packet Filter".
I thought they had something against Berkeley / BSD.
1 -https://en.wikipedia.org/wiki/Extended_Backus%E2%80%93Naur_f...
I’d think for something kernel-related you want to use tools provided by the same package-tree as the kernel itself.
>Just remember that the script showed in this article was created for educational purposes (just for fun) and it shouldn’t be used in places where you are exposed to anybody that could reach your keyboard. This is mainly because of the fact that your Bluetooth MAC becomes effectively password to your system, and despite of techniques that hides Bluetooth MAC it should be treated as public information. It works ok when using it at home, during pandemic, when the only hackers nearby are 2 and 6 years old and mostly using brute-force keyboard attacks, not Bluetooth MAC spoofing.
For BCC and bpftrace I personally think the documentation is actually quite good.
What it is, is badly documented. If you can't work out how to use it from scratch you probably don't know what you want to use it for, if that makes sense.
The actual VM makes quite a lot of sense, you just have to read a lot of kernel samples and txt documentation to work out how to do it properly.