From f02ef88edf617245cbd33813561b46ccadcabfb3 Mon Sep 17 00:00:00 2001 From: Leah Neukirchen Date: Sat, 30 Nov 2019 23:36:34 +0100 Subject: extrace-bpf: don't lose first event --- extrace-bpf | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extrace-bpf b/extrace-bpf index 4658cc7..d72f847 100755 --- a/extrace-bpf +++ b/extrace-bpf @@ -6,6 +6,9 @@ require 'etc' # TODO: -p / cmd... (how?) BPF = <<'EOF' +BEGIN { + printf("SEP2\n"); +} tracepoint:syscalls:sys_enter_execve { printf("%ld +%d %d", elapsed, pid, uid); join(args->argv, "SEP1"); -- cgit 1.4.1