Skip to content

Commit 42d05f2

Browse files
Song ChenNobody
Song Chen
authored and
Nobody
committed
sample: bpf: syscall_tp_kern: add dfd before filename
When i was writing my eBPF program, i copied some pieces of code from syscall_tp, syscall_tp_kern only records how many files are opened, but mine needs to print file name.I reused struct syscalls_enter_open_args, which is defined as: struct syscalls_enter_open_args { unsigned long long unused; long syscall_nr; long filename_ptr; long flags; long mode; }; I tried to use filename_ptr, but it's not the pointer of filename, flags turns out to be the pointer I'm looking for, there might be something missed in the struct. I read the ftrace log, found the missed one is dfd, which is supposed to be placed in between syscall_nr and filename_ptr. Actually syscall_tp has nothing to do with dfd, it can run anyway without it, but it's better to have it to make it a better eBPF sample, especially to new eBPF programmers, then i fixed it. Signed-off-by: Song Chen <[email protected]>
1 parent 40aa19b commit 42d05f2

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

samples/bpf/syscall_tp_kern.c

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
struct syscalls_enter_open_args {
88
unsigned long long unused;
99
long syscall_nr;
10+
long dfd_ptr;
1011
long filename_ptr;
1112
long flags;
1213
long mode;

0 commit comments

Comments
 (0)