kernel.function("sys_statfs") {
name = "statfs"
path_uaddr = $path
- buf_uaddr
+ buf_uaddr = $buf
}
probe kernel.syscall.statfs.return =
kernel.function("sys_statfs").return {
probe kernel.syscall.getresgid16 =
kernel.function("sys_getresgid") {
name = "getresgid16"
- ruid_uaddr = $ruid
- euid_uaddr = $euid
- suid_uaddr = $suid
+ rgid_uaddr = $rgid
+ egid_uaddr = $egid
+ sgid_uaddr = $sgid
}
probe kernel.syscall.getresgid16.return =
kernel.function("sys_getresgid").return {
semid = $semid
semnum = $semnum
cmd = $cmd
- arg = $arg
+ //arg = $arg
}
probe kernel.syscall.semctl.return =
kernel.function("sys_semctl").return {
* unsigned long bus,
* unsigned long dfn)
*/
+/*
probe kernel.syscall.pciconfig_iobase =
kernel.function("sys_pciconfig_iobase") {
name = "pciconfig_iobase"
kernel.function("sys_pciconfig_iobase").return {
name = "pciconfig_iobase.return"
}
+*/
# pciconfig_read___________________________________
/*
* asmlinkage int
* unsigned char *buf)
* { return 0; }
*/
+/*
probe kernel.syscall.pciconfig_read =
kernel.function("sys_pciconfig_read") {
name = "pciconfig_read"
kernel.function("sys_pciconfig_read").return {
name = "pciconfig_read.return"
}
+*/
# pciconfig_write__________________________________
/*
* asmlinkage int
* unsigned long len,
* unsigned char *buf)
*/
+/*
probe kernel.syscall.pciconfig_write =
kernel.function("sys_pciconfig_write") {
name = "pciconfig_write"
kernel.function("sys_pciconfig_write").return {
name = "pciconfig_write.return"
}
+*/
# prctl____________________________________________
/*
* asmlinkage long
name = "add_key"
type_uaddr = $_type
description_auddr = $_description
- payload_uaddr = $payload
+ payload_uaddr = $_payload
plen = $plen
ringid = $ringid
}
probe kernel.syscall.execve =
kernel.function("sys_execve") {
name = "execve"
- regs = $regs
+ //regs = $regs
}
probe kernel.syscall.execve.return =
kernel.function("sys_execve").return {
kernel.function("do_fork") {
name = "clone"
clone_flags = $clone_flags
- start_stack = $start_stack
+ //start_stack = $start_stack
regs_uaddr = $regs
stack_size = $stack_size
parent_tid_uaddr = $parent_tidptr
kernel.function("do_fork") {
name = "fork"
clone_flags = $clone_flags
- start_stack = $start_stack
+ //start_stack = $start_stack
regs_uaddr = $regs
stack_size = $stack_size
parent_tid_uaddr = $parent_tidptr
kernel.function("do_fork") {
name = "vfork"
clone_flags = $clone_flags
- start_stack = $start_stack
+ //start_stack = $start_stack
regs_uaddr = $regs
stack_size = $stack_size
parent_tid_uaddr = $parent_tidptr