1*4882a593Smuzhiyun /* Copyright (c) 2016 Facebook 2*4882a593Smuzhiyun * 3*4882a593Smuzhiyun * This program is free software; you can redistribute it and/or 4*4882a593Smuzhiyun * modify it under the terms of version 2 of the GNU General Public 5*4882a593Smuzhiyun * License as published by the Free Software Foundation. 6*4882a593Smuzhiyun */ 7*4882a593Smuzhiyun #include <linux/version.h> 8*4882a593Smuzhiyun #include <linux/ptrace.h> 9*4882a593Smuzhiyun #include <uapi/linux/bpf.h> 10*4882a593Smuzhiyun #include <bpf/bpf_helpers.h> 11*4882a593Smuzhiyun #include <bpf/bpf_tracing.h> 12*4882a593Smuzhiyun 13*4882a593Smuzhiyun #define _(P) \ 14*4882a593Smuzhiyun ({ \ 15*4882a593Smuzhiyun typeof(P) val = 0; \ 16*4882a593Smuzhiyun bpf_probe_read_kernel(&val, sizeof(val), &(P)); \ 17*4882a593Smuzhiyun val; \ 18*4882a593Smuzhiyun }) 19*4882a593Smuzhiyun 20*4882a593Smuzhiyun SEC("kprobe/__set_task_comm") prog(struct pt_regs * ctx)21*4882a593Smuzhiyunint prog(struct pt_regs *ctx) 22*4882a593Smuzhiyun { 23*4882a593Smuzhiyun struct signal_struct *signal; 24*4882a593Smuzhiyun struct task_struct *tsk; 25*4882a593Smuzhiyun char oldcomm[16] = {}; 26*4882a593Smuzhiyun char newcomm[16] = {}; 27*4882a593Smuzhiyun u16 oom_score_adj; 28*4882a593Smuzhiyun u32 pid; 29*4882a593Smuzhiyun 30*4882a593Smuzhiyun tsk = (void *)PT_REGS_PARM1(ctx); 31*4882a593Smuzhiyun 32*4882a593Smuzhiyun pid = _(tsk->pid); 33*4882a593Smuzhiyun bpf_probe_read_kernel(oldcomm, sizeof(oldcomm), &tsk->comm); 34*4882a593Smuzhiyun bpf_probe_read_kernel(newcomm, sizeof(newcomm), 35*4882a593Smuzhiyun (void *)PT_REGS_PARM2(ctx)); 36*4882a593Smuzhiyun signal = _(tsk->signal); 37*4882a593Smuzhiyun oom_score_adj = _(signal->oom_score_adj); 38*4882a593Smuzhiyun return 0; 39*4882a593Smuzhiyun } 40*4882a593Smuzhiyun 41*4882a593Smuzhiyun SEC("kprobe/urandom_read") prog2(struct pt_regs * ctx)42*4882a593Smuzhiyunint prog2(struct pt_regs *ctx) 43*4882a593Smuzhiyun { 44*4882a593Smuzhiyun return 0; 45*4882a593Smuzhiyun } 46*4882a593Smuzhiyun 47*4882a593Smuzhiyun char _license[] SEC("license") = "GPL"; 48*4882a593Smuzhiyun u32 _version SEC("version") = LINUX_VERSION_CODE; 49