Documentation ¶
Overview ¶
Package kfilefields provides functions to read kernel "struct file" fields against a file descriptor.
This is done:
- without using bpf iterators in order to work on old kernels.
- without comparing pids from userspace and ebpf in order to work from different pid namespaces.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ReadFOpForFdType ¶
ReadFOpForFdType uses ebpf to read the f_op pointer from the kernel "struct file" associated with the given fd type.
func ReadPrivateDataFromFd ¶
ReadPrivateDataFromFd uses ebpf to read the private_data pointer from the kernel "struct file" associated with the given fd.
Types ¶
Click to show internal directories.
Click to hide internal directories.