lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <D9FFE20C522965449E182ACE73889AEB48681EB1@irsmsx105.ger.corp.intel.com>
Date:   Fri, 10 Mar 2017 13:49:20 +0000
From:   "Dorau, Lukasz" <lukasz.dorau@...el.com>
To:     Alexei Starovoitov <ast@...nel.org>,
        "netdev@...r.kernel.org" <netdev@...r.kernel.org>,
        "linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
        "linux-trace-users-owner@...r.kernel.org" 
        <linux-trace-users-owner@...r.kernel.org>,
        Steven Rostedt <rostedt@...dmis.org>,
        Ingo Molnar <mingo@...hat.com>
CC:     "Jelinek, Sarah" <sarah.jelinek@...el.com>,
        "Slusarz, Marcin" <marcin.slusarz@...el.com>,
        "Chernookyi, Vitalii" <vitalii.chernookyi@...el.com>,
        "Buella, Gabor" <gabor.buella@...el.com>,
        "Lebioda, Pawel" <pawel.lebioda@...el.com>,
        "goldshtn@...il.com" <goldshtn@...il.com>,
        "bgregg@...flix.com" <bgregg@...flix.com>
Subject: Cannot attach BPF to tracepoints

Hi,

I cannot attach BPF to tracepoints.

I used bcc's (https://github.com/iovisor/bcc) trace.py tool:
https://github.com/iovisor/bcc/blob/master/tools/trace.py
to test this issue:

# /usr/share/bcc/tools/trace t:syscalls:sys_enter_open
ioctl(PERF_EVENT_IOC_SET_BPF): Invalid argument
Failed to attach BPF to tracepoint

# /usr/share/bcc/tools/trace t:syscalls:sys_exit_open
ioctl(PERF_EVENT_IOC_SET_BPF): Invalid argument
Failed to attach BPF to tracepoint

However it is possible to attach BPF to raw tracepoints:
# /usr/share/bcc/tools/trace t:raw_syscalls:sys_enter
# /usr/share/bcc/tools/trace t:raw_syscalls:sys_exit

and to kprobes:
# /usr/share/bcc/tools/trace 'sys_open "%s", arg1'
# /usr/share/bcc/tools/trace 'r::sys_open "%s", arg1'

Can it be a bug in BPF code?

Regards,
Lukasz


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ