1 #!/bin/sh 2 # SPDX-License-Identifier: GPL-2.0 3 # description: Kprobe event user-memory access 4 # requires: kprobe_events '$arg<N>':README 5 6 grep -A10 "fetcharg:" README | grep -q 'ustring' || exit_unsupported 7 grep -A10 "fetcharg:" README | grep -q '\[u\]<offset>' || exit_unsupported 8 9 :;: "user-memory access syntax and ustring working on user memory";: 10 echo 'p:myevent do_sys_open path=+0($arg2):ustring path2=+u0($arg2):string' \ 11 > kprobe_events 12 echo 'p:myevent2 do_sys_openat2 path=+0($arg2):ustring path2=+u0($arg2):string' \ 13 >> kprobe_events 14 15 grep myevent kprobe_events | \ 16 grep -q 'path=+0($arg2):ustring path2=+u0($arg2):string' 17 echo 1 > events/kprobes/myevent/enable 18 echo 1 > events/kprobes/myevent2/enable 19 echo > /dev/null 20 echo 0 > events/kprobes/myevent/enable 21 echo 0 > events/kprobes/myevent2/enable 22 23 grep myevent trace | grep -q 'path="/dev/null" path2="/dev/null"' 24 25 :;: "user-memory access syntax and ustring not working with kernel memory";: 26 echo 'p:myevent vfs_symlink path=+0($arg3):ustring path2=+u0($arg3):string' \ 27 > kprobe_events 28 echo 1 > events/kprobes/myevent/enable 29 ln -s foo $TMPDIR/bar 30 echo 0 > events/kprobes/myevent/enable 31 32 grep myevent trace | grep -q 'path=(fault) path2=(fault)' 33 34 exit 0
Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.