D7net
Home
Console
Upload
information
Create File
Create Folder
About
Tools
:
/
sbin
/
Filename :
statsnoop.bt
back
Copy
#!/usr/bin/env bpftrace // statsnoop Trace stat() syscalls. // For Linux, uses bpftrace and eBPF. // // This traces the tracepoints for statfs(), statx(), newstat(), and // newlstat(). These aren't the only the stat syscalls: if you are missing // activity, you may need to add more variants. // // Example of usage: // // # ./statsnoop.bt // Attaching 9 probes... // Tracing stat syscalls... Hit Ctrl-C to end. // PID COMM ERR PATH // 27835 bash 0 . // 27835 bash 2 /usr/local/sbin/iconfig // 27835 bash 2 /usr/local/bin/iconfig // 27835 bash 2 /usr/sbin/iconfig // 27835 bash 2 /usr/bin/iconfig // 27835 bash 2 /sbin/iconfig // 27835 bash 2 /bin/iconfig // 27835 bash 2 /usr/games/iconfig // 27835 bash 2 /usr/local/games/iconfig // 27835 bash 2 /snap/bin/iconfig // 27835 bash 2 /apps/python/bin/iconfig // 30573 command-not-fou 2 /usr/bin/Modules/Setup // 30573 command-not-fou 2 /usr/bin/lib/python3.5/os.py // 30573 command-not-fou 2 /usr/bin/lib/python3.5/os.pyc // 30573 command-not-fou 0 /usr/lib/python3.5/os.py // 30573 command-not-fou 2 /usr/bin/pybuilddir.txt // 30573 command-not-fou 2 /usr/bin/lib/python3.5/lib-dynload // 30573 command-not-fou 0 /usr/lib/python3.5/lib-dynload // 30573 command-not-fou 2 /usr/lib/python35.zip // 30573 command-not-fou 0 /usr/lib // 30573 command-not-fou 2 /usr/lib/python35.zip // 30573 command-not-fou 0 /usr/lib/python3.5/ // 30573 command-not-fou 0 /usr/lib/python3.5/ // 30573 command-not-fou 0 /usr/lib/python3.5/ // 30573 command-not-fou 2 /usr/lib/python3.5/encodings/__init__.cpython-35m-x86_64-linux- // 30573 command-not-fou 2 /usr/lib/python3.5/encodings/__init__.abi3.so // 30573 command-not-fou 2 /usr/lib/python3.5/encodings/__init__.so // 30573 command-not-fou 0 /usr/lib/python3.5/encodings/__init__.py // 30573 command-not-fou 0 /usr/lib/python3.5/encodings/__init__.py // // This output has caught me mistyping a command in another shell, "iconfig" // instead of "ifconfig". The first several lines show the bash shell searching // the $PATH (why is games in my $PATH??), and failing to find it (ERR == 2 is // file not found). Then, a "command-not-found" program executes (the name is // truncated to 16 characters in the COMM field, including the NULL), which // begins the process of searching for and suggesting a package. ie, this: // // # iconfig // The program 'iconfig' is currently not installed. You can install it by typing: // apt install ipmiutil // // statsnoop can be used for general debugging, to see what file information has // been requested, and whether those files exist. It can be used as a companion // to opensnoop, which shows what files were actually opened. // // This is a bpftrace version of the bcc tool of the same name. // The bcc version provides options to customize the output. // // Copyright 2018 Netflix, Inc. // // 08-Sep-2018 Brendan Gregg Created this. config = { missing_probes = warn; } BEGIN { printf("Tracing stat syscalls... Hit Ctrl-C to end.\n"); printf("%-6s %-16s %3s %s\n", "PID", "COMM", "ERR", "PATH"); } tracepoint:syscalls:sys_enter_statfs { @filename[tid] = args.pathname; } tracepoint:syscalls:sys_enter_statx, tracepoint:syscalls:sys_enter_newstat, tracepoint:syscalls:sys_enter_newlstat { @filename[tid] = args.filename; } tracepoint:syscalls:sys_exit_statfs, tracepoint:syscalls:sys_exit_statx, tracepoint:syscalls:sys_exit_newstat, tracepoint:syscalls:sys_exit_newlstat /@filename[tid]/ { $ret = args.ret; $errno = ($ret >= 0) ? 0 : (-$ret); printf("%-6d %-16s %3d %s\n", pid, comm, $errno, str(@filename[tid])); delete(@filename, tid); } END { clear(@filename); }