Relevant issue for more info : https://github.com/iovisor/bcc/issues/748

--
Suchakra

On Mon, Nov 21, 2016 at 7:21 PM, Alexei Starovoitov via iovisor-dev
<[email protected]> wrote:
> On Sat, Nov 19, 2016 at 9:45 AM, Mazhar Naqvi via iovisor-dev
> <[email protected]> wrote:
>> Hi,
>>
>>
>> I am trying to attach my function to a tracepoint. I followed brendangregg's
>> script "urandomread.py" and modified it to attach to
>> syscalls:sys_enters_socket but the program gives me an error.
>>
>>
>> Here's a code snippet I am using:
>>
>>
>> b = BPF(text="""
>> TRACEPOINT_PROBE(syscalls, sys_enter_socket) {
>>     bpf_trace_printk("Hello\\n");
>>     return 0;
>> };
>> """)
>>
>> Can anyone point out what I am doing wrong? The script seems to work fine
>> for raw_syscalls:sys_enter but not for the one mentioned above.
>>
>> Why is ebpf unable to attach to syscalls:sys_enter_socket event? Thanks in
>> advance.
>
> from the kernel point of view syscalls are not tracepoints, so
> tracepoint+bpf support doesn't cover them.
> For now please use kprobe on sys_* function as a workaround.
> Thanks
> _______________________________________________
> iovisor-dev mailing list
> [email protected]
> https://lists.iovisor.org/mailman/listinfo/iovisor-dev
_______________________________________________
iovisor-dev mailing list
[email protected]
https://lists.iovisor.org/mailman/listinfo/iovisor-dev

Reply via email to