Accurate, low-overhead per process bandwidth monitoring in 40 lines of bpftrace
gcardone.net
gcardone.net
https://blog.habets.se/2020/08/Measuring-USB-with-bpftrace.h...
It would break too many tools that depend on exact internal function names existing.
Anyway, other dynamic tracing frameworks like SystemTap or LTTng have been using tracepoints, kprobes, and kretprobes for over fifteen years now. Refactoring kernel code isn't going to suddenly become impossible just because of tools new tools like bpftrace.
iptables -I OUTPUT -m owner --uid-owner <UID> -j DROP
ip6tables -I OUTPUT -m owner --uid-owner <UID> -j DROP # bpftrace socktraf.bt
12.12-160: syntax error, unexpected struct