最快的ebpf开发环境搭建方式

环境搭建

启动容器

bash 复制代码
sudo docker run --rm -it --privileged \
  -v /lib/modules:/lib/modules:ro \
  -v /sys:/sys:ro \
  -v /usr/src:/usr/src:ro \
  alpine:3.12

安装依赖

bash 复制代码
sed -i 's/dl-cdn.alpinelinux.org/mirrors.tuna.tsinghua.edu.cn/g' /etc/apk/repositories

apk add bcc-tools bcc-doc

测试

hello.c

cpp 复制代码
int hello_world(void *ctx)
{
	bpf_trace_printk("Hello, World");
	return 0;
}

hello.py

python 复制代码
from bcc import BPF

b = BPF(src_file="hello.c")
b.attach_kprobe(event="do_sys_openat2", fn_name="hello_world")

b.trace_print()

执行,可看到打印出了hello world

bash 复制代码
/ # python3 hello.py 

In file included from <built-in>:2:
In file included from /virtual/include/bcc/bpf.h:12:
In file included from include/linux/types.h:6:
In file included from include/uapi/linux/types.h:14:
In file included from ./include/uapi/linux/posix_types.h:5:
In file included from include/linux/stddef.h:5:
In file included from include/uapi/linux/stddef.h:5:
In file included from include/linux/compiler_types.h:90:
include/linux/compiler-clang.h:41:9: warning: '__HAVE_BUILTIN_BSWAP32__' macro redefined [-Wmacro-redefined]
#define __HAVE_BUILTIN_BSWAP32__
        ^
<command line>:4:9: note: previous definition is here
#define __HAVE_BUILTIN_BSWAP32__ 1
        ^
In file included from <built-in>:2:
In file included from /virtual/include/bcc/bpf.h:12:
In file included from include/linux/types.h:6:
In file included from include/uapi/linux/types.h:14:
In file included from ./include/uapi/linux/posix_types.h:5:
In file included from include/linux/stddef.h:5:
In file included from include/uapi/linux/stddef.h:5:
In file included from include/linux/compiler_types.h:90:
include/linux/compiler-clang.h:42:9: warning: '__HAVE_BUILTIN_BSWAP64__' macro redefined [-Wmacro-redefined]
#define __HAVE_BUILTIN_BSWAP64__
        ^
<command line>:5:9: note: previous definition is here
#define __HAVE_BUILTIN_BSWAP64__ 1
        ^
In file included from <built-in>:2:
In file included from /virtual/include/bcc/bpf.h:12:
In file included from include/linux/types.h:6:
In file included from include/uapi/linux/types.h:14:
In file included from ./include/uapi/linux/posix_types.h:5:
In file included from include/linux/stddef.h:5:
In file included from include/uapi/linux/stddef.h:5:
In file included from include/linux/compiler_types.h:90:
include/linux/compiler-clang.h:43:9: warning: '__HAVE_BUILTIN_BSWAP16__' macro redefined [-Wmacro-redefined]
#define __HAVE_BUILTIN_BSWAP16__
        ^
<command line>:3:9: note: previous definition is here
#define __HAVE_BUILTIN_BSWAP16__ 1
        ^
3 warnings generated.
b'         python3-1056231 [005] d..31 1056012.574165: bpf_trace_printk: Hello, World'
b'         python3-1056231 [005] d..31 1056012.574277: bpf_trace_printk: Hello, World'
b'         python3-1056231 [005] d..31 1056012.574734: bpf_trace_printk: Hello, World'
b'           <...>-1059946 [006] d..31 1056300.636287: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673240: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673277: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673287: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673648: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673666: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673676: bpf_trace_printk: Hello, World'
b'           <...>-6346    [001] d..31 1056300.673685: bpf_trace_printk: Hello, World'
相关推荐
mounter6255 天前
突破单点限制:BPF 多跟踪点高效附加机制与新 ftrace 架构解析
linux·ebpf·linux kernel·kernel·ftrace
mounter6257 天前
深度解析 eBPF LSM:如何利用 eBPF 构建安全的 Linux 内核纵深防御体系
linux·安全·ebpf·linux kernel·kernel
mounter62514 天前
认识 Tetragon:基于 eBPF 的安全监控与强制执行工具
linux·ebpf·cve·kernel
mounter62521 天前
高性能网络技术演进与创新探索:RDMA、eBPF/XDP 深度解析及 LSF/MM/BPF 2023 专题演讲
linux·ebpf·linux kernel·kernel·rdma·xdp
REDcker1 个月前
基于 eBPF 的网络可观测:协议栈路径与 sk_buff
linux·服务器·网络·php·ebpf·bpf
REDcker1 个月前
eBPF 运行时架构:Verifier、JIT、Map 与加载流程
linux·内核·ebpf·bpf
mounter6251 个月前
质检员与超能引擎的碰撞:KASAN 护航 eBPF JIT 的技术演进与安全抉择
linux·ebpf·linux kernel·kernel·kasan
mounter6251 个月前
走向长时运行:引入协程(Coroutines),打破 BPF 程序的“一堂到底”限制
linux·ebpf·kernel
hbugs0011 个月前
PNETLab vs EVE-NG Pro 流量洞察功能底层架构技术白皮书
网络·架构·eve-ng·bpf·流量洞察
hbugs0011 个月前
BPF 表达式检查器:一款免费开源的 Wireshark 捕获过滤器语法检查与可视化构建工具
网络·测试工具·开源·eve-ng·bpf