【问题标题】:insmod: ERROR: could not insert module kprobe_example.ko: Operation not permittedinsmod:错误:无法插入模块 kprobe_example.ko:不允许操作
【发布时间】:2016-09-19 07:06:32
【问题描述】:

我指的是: http://www-users.cs.umn.edu/~boutcher/kprobes/kprobes.txt.html 了解 kprobe。我使用了文档中给出的 kprobe_example.c。

我使用 makefile 编译它(代码取自同一文档)

我收到编译错误,因为我的内核版本是 4.2,并且在 struct pt_regs 中更改了一些字段。所以我用 ip 替换了 eip,用 kprobe_example.c 中的标志替换了 eflag,即https://gist.github.com/murlee417/87c2eb43a6afa1954b05404a07813e81。然后就可以编译成功了。

现在,作为 root 用户,我做到了:

#insmod kprobe_example.ko

我得到了:

insmod: ERROR: could not insert module kprobe_example.ko: Operation not permitted

我的消息缓冲区有:

#dmesg  
[ 4537.478408] Couldn't find do_fork to plant kprobe

请帮我解决这个错误并让 insmod 工作。

【问题讨论】:

  • I got compilation errors because my kernel version is 4.2 and some fields were changed in struct pt_regs. - 不仅改变了单个结构。 Definition of function do_fork 依赖于配置宏 HAVE_COPY_THREAD_TLS。可能,这个宏是为你的情况定义的(检查内核构建目录中的.config 文件),所以这个函数根本不存在。如果是这种情况,只需更改要探测的函数的名称即可。

标签: c linux-kernel fork insmod kprobe


【解决方案1】:

在 x86 中,do_fork() 被称为sys_fork(),所以修改代码如下

/* For each probe you need to allocate a kprobe structure */
static struct kprobe kp = {
    //.symbol_name  = "do_fork",
    .symbol_name    = "sys_fork",
};

【讨论】:

    猜你喜欢
    • 2020-12-06
    • 2022-06-24
    • 2016-06-27
    • 2015-01-15
    • 2016-03-26
    • 2022-12-30
    • 2013-03-28
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多