eBPF
When sudo apt install bpftool
doesn't work
| # For latest build follow below link
# https://github.com/libbpf/bpftool/releases
wget https://github.com/libbpf/bpftool/releases/download/v7.5.0/bpftool-v7.5.0-amd64.tar.gz
tar xf bpftool*
chmod +x ./bpftool
./bpftool
|
for loading program
| sudo mount -t bpf bpffs /sys/fs/bpf
sudo bpftool prog load ./sample.o /sys/fs/bpf/sample
|
for bpf_printk()
logs
| # to clear previous logs
sudo echo > /sys/kernel/debug/tracing/trace
# print logs
sudo cat /sys/kernel/debug/tracing/trace_pipe
# for k8s-debug pod
echo > /host/sys/kernel/debug/tracing/trace
cat /host/sys/kernel/debug/tracing/trace_pipe
|
for ebpf-lsm & kprobe-override status
| # for ebpf-lsm
cat /sys/kernel/security/lsm
# for override
cat /boot/config-`uname -r` | grep CONFIG_BPF_KPROBE_OVERRIDE
|