.. | .. |
---|
7 | 7 | #include <linux/version.h> |
---|
8 | 8 | #include <linux/ptrace.h> |
---|
9 | 9 | #include <uapi/linux/bpf.h> |
---|
10 | | -#include "bpf_helpers.h" |
---|
| 10 | +#include <bpf/bpf_helpers.h> |
---|
| 11 | +#include <bpf/bpf_tracing.h> |
---|
11 | 12 | |
---|
12 | | -#define _(P) ({typeof(P) val = 0; bpf_probe_read(&val, sizeof(val), &P); val;}) |
---|
| 13 | +#define _(P) \ |
---|
| 14 | + ({ \ |
---|
| 15 | + typeof(P) val = 0; \ |
---|
| 16 | + bpf_probe_read_kernel(&val, sizeof(val), &(P)); \ |
---|
| 17 | + val; \ |
---|
| 18 | + }) |
---|
13 | 19 | |
---|
14 | 20 | SEC("kprobe/__set_task_comm") |
---|
15 | 21 | int prog(struct pt_regs *ctx) |
---|
.. | .. |
---|
24 | 30 | tsk = (void *)PT_REGS_PARM1(ctx); |
---|
25 | 31 | |
---|
26 | 32 | pid = _(tsk->pid); |
---|
27 | | - bpf_probe_read(oldcomm, sizeof(oldcomm), &tsk->comm); |
---|
28 | | - bpf_probe_read(newcomm, sizeof(newcomm), (void *)PT_REGS_PARM2(ctx)); |
---|
| 33 | + bpf_probe_read_kernel(oldcomm, sizeof(oldcomm), &tsk->comm); |
---|
| 34 | + bpf_probe_read_kernel(newcomm, sizeof(newcomm), |
---|
| 35 | + (void *)PT_REGS_PARM2(ctx)); |
---|
29 | 36 | signal = _(tsk->signal); |
---|
30 | 37 | oom_score_adj = _(signal->oom_score_adj); |
---|
31 | 38 | return 0; |
---|