Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- syscall::open:entry
- /pid == $1 /
- {
- printf("%s(%s)", probefunc, copyinstr(arg0));
- }
- syscall::open:return
- /pid == $1 /
- {
- printf("\t\t = %d\n", arg1);
- }
- syscall::close:entry
- /pid == $1 /
- {
- printf("%s(%d)\n", probefunc, arg0);
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement