Skip to content

Instantly share code, notes, and snippets.

Created July 24, 2020 09:50
What would you like to do?
BCC script to trace openat
#!/usr/bin/env python3
from bcc import BPF
b = BPF(text="""
TRACEPOINT_PROBE(syscalls, sys_enter_openat) {
bpf_trace_printk("sys_enter_openat mode:%ld filename:%s (%ld)\\n", args->mode, args->filename, args->filename);
return 0;
while 1:
(task, pid, cpu, flags, ts, msg) = b.trace_fields()
except ValueError:
print("%-18.9f %-16s %-6d %s" % (ts, task, pid, msg))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment