Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
saagarjha
2y ago
0 comments
Share
Ok but you can like put a tracepoint on read/write and peek at what’s going through those, no?
0 comments
default
newest
oldest
madog
2y ago
Nope. Tracepoint eBPF programs require root to load always. For eBPF you select a program type, and that limits what you can do (aka what helper functions are available to you) and what privileges are required.
tptacek
2y ago
I have no idea, because every system I've ever worked on has disabled unprivileged eBPF.
j
/
k
navigate · click thread line to collapse