diff --git a/observation/src/filesnoop/filesnoop.bpf.c b/observation/src/filesnoop/filesnoop.bpf.c index 2a60e1fcbd8d88ae0641318f3d18e9ece90c1db7..479f0cf7d2f21386061b2379854d82e56647e8a0 100644 --- a/observation/src/filesnoop/filesnoop.bpf.c +++ b/observation/src/filesnoop/filesnoop.bpf.c @@ -17,3 +17,17 @@ const volatile int target_op = F_ALL; #define MAX_ENTRIES 1024 char target_filename[FSFILENAME_MAX] = {}; + +struct key_t { + pid_t tid; + int fd; +}; + +struct fsfilename { + char name[FSFILENAME_MAX]; +}; + +struct print_value { + struct key_t key; + struct fsfilename *filename; +};