SeeFlowerX / stackplz

基于eBPF的堆栈追踪工具
Apache License 2.0
849 stars 169 forks source link

使用pid抓取syscall,无反应 #55

Open xumingyanghello opened 1 month ago

xumingyanghello commented 1 month ago

ps -ef | grep setting

system 19849 16944 0 19:06:38 ? 00:00:51 com.android.settings

./stackplz-v3 -p 19849 -s all --nocheck

findBTFAssets btf_file=a12-5.10-arm64_min.btf [*] save maps to maps_19849.txt hook syscall count:306 ConfigMap{stackplz_pid=30461,thread_whitelist=0} uid => whitelist:[];blacklist:[] pid => whitelist:[19849];blacklist:[] tid => whitelist:[];blacklist:[] start 2 modules

使用pid抓取syscall时,无反应。 表现为可以正常启动stackplz,但是操作时,无syscall输出

SeeFlowerX commented 1 month ago

你试试普通APP看看,以及加上 --full-tname 选项