+
    iX                       ^ RI Ht ^ RIt^ RIt^ RIt^ RIt^ RIt^ RIt^ RI	t	^ RI
t
^ RIt^ RIt^RIHtHtHtHtHt ^RIHtHtHtHtHt ^RIHt ^RIHtHtHtHtH t  ^RI!H"t" ^RI#H$t$H%t% ^R	I&H't'H(t(  ]) R
t,^ s-R t.Rt/]P`                  Pc                  ]/R4      t2]P`                  Pg                  ]24      '       g   Rt2^t4^t5^t6^t7^t8^ t9 ! R R]:4      t; ! R R4      t< ! R R4      t= ! R R4      t> ! R R4      t? ! R R4      t@ ! R R4      tA ! R R4      tB ! R R 4      tC ! R! R"]:4      tDR#   ]* d    ]+t) Li ; i)#    )print_functionN)lib
bcc_symbolbcc_symbol_optionbcc_stacktrace_build_id_SYM_CB_TYPE)TablePerfEventArrayRingBufBPF_MAP_TYPE_QUEUEBPF_MAP_TYPE_STACK)Perf)get_online_cpusprintb_assert_is_bytes	ArgStringStrcmpRewrite)__version__)disassemble_prog
decode_map)USDTUSDTExceptioni  c                      \         # N)_num_open_probes     ./usr/lib/python3/dist-packages/bcc/__init__.py_get_num_open_probesr   ,   s    r   z/sys/kernel/debugtracingz/sys/kernel/tracingc                   2   a  ] tR t^Dt o R tR tR tRtV tR# )SymbolCachec           	         \         P                  ! V\        P                  ! R \        P                  ! \
        4      4      4      V n        R # r   )r   bcc_symcache_newctcastPOINTERr   cache)selfpids   &&r   __init__SymbolCache.__init__E   s/    ))RWWT2::.?#@AC
r   c                   \        4       pV'       d8   \        P                  ! V P                  V\        P
                  ! V4      4      pM6\        P                  ! V P                  V\        P
                  ! V4      4      pV^ 8  dp   VP                  '       dY   VP                  '       dG   RVP                  \        P                  ! VP                  \        P                  4      P                  3# RVR3# V'       d8   VP                  p\        P                  ! \        P
                  ! V4      4       MVP                  pWSP                  \        P                  ! VP                  \        P                  4      P                  3# )a  
Return a tuple of the symbol (function), its offset from the beginning
of the function, and the module in which it lies. For example:
    ("start_thread", 0x202, "/usr/lib/.../libpthread-2.24.so")
If the symbol cannot be found but we know which module it is in,
return the module name and the offset from the beginning of the
module. If we don't even know the module, return the absolute
address as the offset.
N)r   r   bcc_symcache_resolver(   r%   byref bcc_symcache_resolve_no_demanglemoduleoffsetr&   c_char_pvaluedemangle_namebcc_symbol_free_demangle_namename)r)   addrdemanglesymresname_ress   &&&   r   resolveSymbolCache.resolveI   s     l**4::tRXXc]KC66tzz479xx}FC7zzzcjjjcjj

BKK8>>@ @$%%((H--bhhsm<xxH**bggcjj"++&F&L&LMMr   c                    \        V4      p\        V4      p\        P                  ! 4       p\        P                  ! V P
                  W\        P                  ! V4      4      ^ 8  d   R# VP                  # )r   )r   r%   c_ulonglongr   bcc_symcache_resolve_namer(   r/   r4   )r)   r1   r7   r8   s   &&& r   resolve_nameSymbolCache.resolve_namef   sZ    !&)%~~((V "#$Izzr   )r(   N)	__name__
__module____qualname____firstlineno__r+   r=   rC   __static_attributes____classdictcell____classdict__s   @r   r"   r"   D   s     CN: r   r"   c                   .    ] tR t^ot^ t^t^t^t^t^t	Rt
R# )PerfTyper   N)rE   rF   rG   rH   HARDWARESOFTWARE
TRACEPOINTHW_CACHERAW
BREAKPOINTrI   r   r   r   rN   rN   o   s     HHJH
CJr   rN   c                   >    ] tR t^xt^ t^t^t^t^t^t	^t
^t^t^	tRtR# )PerfHWConfigr   N)rE   rF   rG   rH   
CPU_CYCLESINSTRUCTIONSCACHE_REFERENCESCACHE_MISSESBRANCH_INSTRUCTIONSBRANCH_MISSES
BUS_CYCLESSTALLED_CYCLES_FRONTENDSTALLED_CYCLES_BACKENDREF_CPU_CYCLESrI   r   r   r   rV   rV   x   s8    JLLMJNr   rV   c                   B    ] tR t^t^ t^t^t^t^t^t	^t
^t^t^	t^
tRtR# )PerfSWConfigr   N)rE   rF   rG   rH   	CPU_CLOCK
TASK_CLOCKPAGE_FAULTSCONTEXT_SWITCHESCPU_MIGRATIONSPAGE_FAULTS_MINPAGE_FAULTS_MAJALIGNMENT_FAULTSEMULATION_FAULTSDUMMY
BPF_OUTPUTrI   r   r   r   rb   rb      s<    IJKNOOEJr   rb   c                   z    ] tR t^t^t^t^t^t^t^ t	^@t
^tRtRtRtRtRtRtR	tR
tRtRtRtRtRtRtRtRtRtRtR# )PerfEventSampleFormatr   N   i      i   i   i    i @  i   i   i   i   i   i   i    i  @ i   i   )rE   rF   rG   rH   IPTIDTIMEADDRREAD	CALLCHAINIDCPUPERIOD	STREAM_IDrS   BRANCH_STACK	REGS_USER
STACK_USERWEIGHTDATA_SRC
IDENTIFIERTRANSACTION	REGS_INTR	PHYS_ADDRAUXCGROUPDATA_PAGE_SIZECODE_PAGE_SIZEWEIGHT_STRUCTrI   r   r   r   ro   ro      s    
BCDDDI
BCFICLIJFHJKIICFNNMr   ro   c                   j    ] tR t^t^t^t^t^t^t^t	^t
^t^	t^
t^t^t^t^t^t^t^t^t^t^t^tRtR# )BPFProgTyper   N)rE   rF   rG   rH   SOCKET_FILTERKPROBE	SCHED_CLS	SCHED_ACTrQ   XDP
PERF_EVENT
CGROUP_SKBCGROUP_SOCKLWT_INLWT_OUTLWT_XMITSOCK_OPSSK_SKBCGROUP_DEVICESK_MSGRAW_TRACEPOINTCGROUP_SOCK_ADDRCGROUP_SOCKOPTTRACINGLSMrI   r   r   r   r   r      sl    MFIIJ
CJJKFGHHFMFNNG
Cr   r   c                       ] tR t^t^ t^t^t^t^t^t	^t
^t^t^	t^
t^t^t^t^t^t^t^t^t^t^t^t^t^t^t^t^t^t^t ^t!^t"^t#^ t$^!t%^"t&^#t'^$t(^%t)^&t*Rt+R# )BPFAttachTyper   N),rE   rF   rG   rH   CGROUP_INET_INGRESSCGROUP_INET_EGRESSCGROUP_INET_SOCK_CREATECGROUP_SOCK_OPSSK_SKB_STREAM_PARSERSK_SKB_STREAM_VERDICTr   SK_MSG_VERDICTCGROUP_INET4_BINDCGROUP_INET6_BINDCGROUP_INET4_CONNECTCGROUP_INET6_CONNECTCGROUP_INET4_POST_BINDCGROUP_INET6_POST_BINDCGROUP_UDP4_SENDMSGCGROUP_UDP6_SENDMSG
LIRC_MODE2FLOW_DISSECTORCGROUP_SYSCTLCGROUP_UDP4_RECVMSGCGROUP_UDP6_RECVMSGCGROUP_GETSOCKOPTCGROUP_SETSOCKOPTTRACE_RAW_TPTRACE_FENTRYTRACE_FEXITMODIFY_RETURNLSM_MAC
TRACE_ITERCGROUP_INET4_GETPEERNAMECGROUP_INET6_GETPEERNAMECGROUP_INET4_GETSOCKNAMECGROUP_INET6_GETSOCKNAME
XDP_DEVMAPCGROUP_INET_SOCK_RELEASE
XDP_CPUMAP	SK_LOOKUPr   SK_SKB_VERDICTrI   r   r   r   r   r      s    OMNJNMLLKMGJ!!!!J!JI
CNr   r   c                   *    ] tR t^t^ t^t^t^t^tRt	R# )	XDPActionr   N)
rE   rF   rG   rH   XDP_ABORTEDXDP_DROPXDP_PASSXDP_TXXDP_REDIRECTrI   r   r   r   r   r      s    KHHFLr   r   c                   *    ] tR t^t^t^t^t^t^tRt	R# )XDPFlagsr   N)
rE   rF   rG   rH   UPDATE_IF_NOEXISTSKB_MODEDRV_MODEHW_MODEREPLACErI   r   r   r   r   r      s      HHGGr   r   c                   p
  a  ] tR tRt o ]P
                  t]P                  t]P                  t]P                  t]P                  t	]P                  t
]P                  t]P                  t]P                  t]P                  t]P                  t]P                   t]P"                  t]P$                  t]P&                  t]P(                  t]P*                  t]P,                  t]P.                  t]P0                  t]P4                  t]P6                  t]P8                  t]P:                  t]P<                  t]P@                  t!]PD                  t#]PH                  t%]PL                  t']PP                  t)]*PV                  ! R4      t,/ t-].P^                  ! 4       t0RR.RRR.RR	R
.RR.RRR./t1. ROt2^t3 ! R R]4Pj                  4      t6]4Pn                  ! RRR7      t8]8Pr                  t:]4Pv                  ]4Px                  ! ]64      .]:n=        ]>R 4       t?]>R 4       t@]AtA ! R R]B4      tC]DR 4       tE]DR 4       tFRRR^ . . RRR3	R ltG]3R ltHRR  ltIR! tJR" tKRR# ltL/ R$]4P                  bR%]4P                  bR&]4P                  bR']4P                  bR(]4P                  bR)]4P                  bR*]4Pv                  bR+]4P                  bR,]4P                  bR-]4P                  bR.]4P                  bR/]4P                  bR0]4P                  bR1]4P                  bR2]4P                  bR3]4P                  ^,          bR4]4P                  ^,          bt]]DR5 4       t^RR6 lt_R7 t`R8 taR9 tbR: tcR; td]DRR< l4       te]DR= 4       tf]DR> 4       tg]DR? 4       thR@ ti]DRA 4       tjRB tkRC tlRD tmRE tnRF toRG tpRH tqRRI ltrRRJ ltsRK ttRL tuRRM ltvRRN ltw]DRRO l4       tx]DRRP l4       ty]>RRQ l4       tz]DRRR l4       t{]DRS 4       t|]DRT 4       t}RRU lt~RRV ltRRW lt]DRX 4       t]DRY 4       t]DRZ 4       t]DR[ 4       tRR\ ltRR] ltRR^ ltRR_ ltRR` ltRRa ltRRb ltRRc lt]DRd 4       t]DRe 4       t]DRf 4       t]DRg 4       tRRh ltRi tRRj ltRk tRRl ltRRm lt]DRn 4       t]DRo 4       t]DRp 4       tRq tRRr ltRRs ltRt tRRu ltRRv ltRw tRRx ltRRy ltRRz ltRR{ lt]DR| 4       t]DRR} l4       t]DRR~ l4       t]DR 4       tR tR tR tRR ltR tRR ltRR ltRR ltR tR t]DR 4       tR tR tR tR tR tRtV tR# )BPFi  s   [^a-zA-Z0-9_]zlinux/time.htimez
linux/fs.hfsfilezlinux/blkdev.hbiorequestzlinux/slab.halloczlinux/netdevice.hsk_buff
net_devicec                   N    ] tR tRtR]P
                  3R]P
                  3.tRtR# )BPF.timespeciE  tv_sectv_nsecr   N)rE   rF   rG   rH   r%   c_long_fields_rI   r   r   r   timespecr   E  s    ryy)Iryy+ABr   r   z
librt.so.1T)	use_errnoc                >   V P                  4       pV P                  V P                  \        P                  ! V4      4      ^ 8w  d6   \        P
                  ! 4       p\        V\        P                  ! V4      4      hVP                  R,          VP                  ,           # )zmonotonic_time()
Returns the system monotonic time from clock_gettime, using the
CLOCK_MONOTONIC constant. The time returned is in nanoseconds.
g    eA)r   _clock_gettimeCLOCK_MONOTONICr%   r/   	get_errnoOSErrorosstrerrorr   r   )clsterrnos   &  r   monotonic_timeBPF.monotonic_timeL  sj     LLNc11288A;?1DLLNE%U!344xx#~		))r   c                    RpV P                   P                  4        F7  w  r4V F,  pV F#  pWV9   g   K  W29  g   K  VRV,          ,          pK%  	  K.  	  K9  	  V# )a	  
Generates #include statements automatically based on a set of
recognized types such as sk_buff and bio. The input is all the words
that appear in the BPF program, and the output is a (possibly empty)
string of #include statements, such as "#include <linux/fs.h>".
 z#include <%s>
)_auto_includesitems)r   program_wordsheadersheaderkeywordskeywordwords   &&     r   generate_auto_includesBPF.generate_auto_includesX  sZ      # 2 2 8 8 :F#)D6+@#4v#== * $ !;
 r   c                   &   a  ] tR tRt o R tRtV tR# )BPF.Functionik  c                *    Wn         W n        W0n        R # r   )bpfr7   fd)r)   r  r7   r  s   &&&&r   r+   BPF.Function.__init__l  s    HIGr   )r  r  r7   N)rE   rF   rG   rH   r+   rI   rJ   rK   s   @r   Functionr   k  s     	 	r   r  c                   V '       d   \         P                  P                  V 4      '       g   \        \        P
                  ^ ,          4      pRP                  \         P                  P                  \         P                  P                  VP                  4       4      4      V .4      p\         P                  P                  V4      '       d   Tp V # \        RV ,          4      hV # )z0If filename is invalid, search in ./ of argv[0]    /zCould not find file %s)r   pathisfiler   sysargvjoinabspathdirname	__bytes__	Exception)filenameargv0r   s   &  r   
_find_fileBPF._find_fileq  s     77>>(++!#((1+.IIrwwrwwu?P/QRT\]^77>>!$$ H  $$<x$GHHr   c                   R p\         P                  P                  V 4      w  r#V'       d   V! V 4      '       d   V #  R# \         P                  R,          P                  \         P                  4       FT  pVP                  R4      p\         P                  P                  VP                  4       V 4      pV! V4      '       g   KR  Vu # 	  R# )a\  
find_exe(bin_path)

Traverses the PATH environment variable, looking for the first
directory that contains an executable file named bin_path, and
returns the full path to that file, or None if no such file
can be found. This is meant to replace invocations of the
"which" shell utility, which doesn't have portable semantics
for skipping aliases.
c                     \         P                  P                  V 4      ;'       d&    \         P                  ! V \         P                  4      # r   )r   r  r	  accessX_OK)fpaths   &r   is_exeBPF.find_exe.<locals>.is_exe  s3    77>>%( * *		%)*r   PATH"N)r   r  splitenvironpathsepstripr  encode)bin_pathr  r  fnamer  exe_files   &     r   find_exeBPF.find_exe~  s    	* ww}}X.h    

6*00<zz#77<<x@(###O	 =
 r   r   NFc
                P   \        V4      p\        V4      p\        V4      pV'       d   V'       d   Q h\        P                  ! 4       p
V
R8X  Ed!    \        P                  ! RR.\        P
                  R7      pVP                  R4      P                  R4      p\        P                  P                  V4      '       g   Rp \        P                  ! R	R.\        P
                  R7      pTP                  R4      P                  R4      p\        P                  P                  T4      '       g   RpT'       d   TP                  R
T,           4       T'       d   TP                  R
T,           4       / V n        / V n        / V n        / V n        / V n        / V n        / V n        / V n        / V n        / V n        RV n        RV n        \2        P4                  ! V P6                  4       W@n        / V n        / V n        RV n        \@        PB                  \E        V4      ,          ! 4       p\G        V4       F  w  pp\I        \K        V4      4      VV&   K  	  V'       d+   \L        PO                  V4      p\L        PO                  V4      pV'       d/   \Q        VRR7      ;_uu_ 4       pVPS                  4       pRRR4       \@        PT                  \E        V4      ,          ! 4       p\G        V4       F-  w  pp\@        PT                  ! VPW                  4       4      VV&   K/  	  \X        PZ                  ! V\E        V4      4      pVf   \        R4      hVV,           p\X        P\                  ! VV P8                  V\E        V4      Wx4      V n        V P>                  '       g   \        RT;'       g    R,          4      hV F  pVP_                  W	4       K  	  V Pa                  4        R#   \         d   pRp Rp?EL0Rp?ii ; i  \         d   pRp Rp?ELRp?ii ; i  + '       g   i     ELl; i)a
  Create a new BPF module with the given source code.

Note:
    All fields are marked as optional, but either `src_file` or `text`
    must be supplied, and not both.

Args:
    src_file (Optional[str]): Path to a source file for the module
    hdr_file (Optional[str]): Path to a helper header file for the `src_file`
    text (Optional[str]): Contents of a source file for the module
    debug (Optional[int]): Flags used for debug prints, can be |'d together
                           See "Debug flags" for explanation
loongarch64clangz-print-file-name=include)stderrutf-8
FNgccz-Irb)modezFailed to compile BPF module %sz<text>zycan't generate USDT probe arguments; possible cause is missing pid when a probe in a shared object has multiple locations)1r   platformmachine
subprocesscheck_outputSTDOUTdecoder!  r   r  existsr  append
kprobe_fds
uprobe_fdstracepoint_fdsraw_tracepoint_fdskfunc_entry_fdskfunc_exit_fdsfmod_ret_fdslsm_fdsperf_buffersopen_perf_events_ringbuf_manager	tracefileatexitregistercleanupdebugfuncstablesr1   r%   r3   len	enumeratebytesr   r   r  openreadc_void_pget_contextr   bcc_usdt_genargsbpf_module_create_c_from_stringattach_uprobes_trace_autoload)r)   src_filehdr_filetextrH  cflagsusdt_contextsallow_rlimitdeviceattach_usdt_ignore_pidarchitectureclang_include_path_outputclang_include_path_stregcc_include_path_outputgcc_include_path_strcflags_arrayisr   	ctx_arrayusdt	usdt_textusdt_contexts   &&&&&&&&&&              r   r+   BPF.__init__  sj   " $H-#H-%X&&  '')=(/,6,C,CWNhDir|  sD  sD  -E))B)I)I')R)X)XY])^&ww~~&<==-2*-*4*A*A5JdBenxnn  +A''>'E'Eg'N'T'TUY'Z$ww~~&:;;+0( &d%;;<#d%99: "$!  " $%

c&k14f%DAqy|9L|A%~~h/H~~h/H hT**dyy{ + [[3}#558	 /GAt;;t'7'7'9:IaL 0((C4FG	 ( ) ) 4 99$:>**:FLHY:FP {{{=AUAUXVWW)L''E * 	Q  /).&/  -',$-H +**sJ   A,O ?O A,O9 /O9  PO6)O11O69PPPP%	c                    . p\        ^ \        P                  ! V P                  4      4       FD  p\        P                  ! V P                  V4      pVP                  V P                  WA4      4       KF  	  V# )zload_funcs(prog_type=KPROBE)

Load all functions in this BPF module with the given type.
Returns a list of the function handles.)ranger   bpf_num_functionsr1   bpf_function_namer8  	load_func)r)   	prog_typefnsre  	func_names   &&   r   
load_funcsBPF.load_funcs  s[     q#//<=A--dkk1=IJJt~~i;< > 
r   c                   \        V4      pWP                  9   d   V P                  V,          # \        P                  ! V P                  V4      '       g   \        R V,          4      h^ pV P                  \        ,          '       d   ^pMV P                  \        ,          '       d   ^p\        P                  ! V P                  W!\        P                  ! V P                  V4      \        P                  ! V P                  V4      \        P                  ! V P                  4      \        P                  ! V P                  4      VR^ W44      pV^ 8  d   \        P                  ! V P                  4       \         P"                  ! 4       \$        P&                  8X  d   \        R4      h\(        P*                  ! \         P"                  ! 4       4      p\        RV: RV: 24      h\,        P/                  WV4      pWP                  V&   V# )Unknown program %sNz!Need super-user privileges to runzFailed to load BPF program : )r   rI  r   bpf_function_startr1   r  rH  DEBUG_BPF_REGISTER_STATE	DEBUG_BPFbcc_func_loadbpf_function_sizebpf_module_licensebpf_module_kern_versionrE  rF  	donothingr%   r   r   EPERMr   r   r   r  )	r)   rs  rq  r\  attach_type	log_levelr  errstrfns	   &&&&&    r   rp  BPF.load_func  sm   $Y/	

"::i((%%dkk9==09<==	JJ111Ijj9$$It{{I&&t{{I>%%dkk9=&&t{{3++DKK84F9 6OODNN+||~, CDD[[0F&0 1 1 \\$2. "

9	r   c                :   \        V4      p\        P                  ! V P                  V4      '       g   \	        RV,          4      h\        P                  ! V P                  V4      p\        P
                  ! V P                  V4      p\        P                  ! W#4      # )zB
Return the eBPF bytecodes for the specified function as a string
rw  )r   r   ry  r1   r  r}  r%   	string_at)r)   rs  startsizes   &&  r   	dump_funcBPF.dump_func2  sq     %Y/	%%dkk9==09<==''Y?%%dkk9=||E((r   c                :    V P                  V4      p\        W4      # r   )r  r   )r)   rs  bpfstrs   && r   disassemble_funcBPF.disassemble_func>  s    	*	22r   c                    W,          p\         P                  ! V P                  VP                  4      p\	        WWBR 7      # ))sizeinfo)r   bpf_table_type_idr1   map_idr   )r)   
table_namer  	table_obj
table_types   &&&  r   decode_tableBPF.decode_tableB  s3    $	**4;;	8H8HI
*OOr   _Boolcharwchar_tzunsigned charshortzunsigned shortintzunsigned intlongzunsigned longz	long longzunsigned long longfloatdoublezlong double__int128zunsigned __int128c           
     (   \        V \        4      '       d   \        P                  V ,          # . p. pV ^,           EF  p\	        V4      ^8X  d7   VP                  V^ ,          \        P                  V^,          4      34       KJ  \	        V4      ^8X  Ed   \        V^,          \        4      '       dL   VP                  V^ ,          \        P                  V^,          4      V^,          ^ ,          ,          34       K  \        V^,          \        4      '       d@   VP                  V^ ,          \        P                  V^,          4      V^,          34       EK  \        V^,          \        4      '       d   V^,          R8X  g   V^,          R8X  g   V^,          R8X  d]   V^ ,          pVR8X  d$   R\	        V4      ,          pVP                  V4       VP                  V\        P                  V4      34       EK  \        R\        V4      ,          4      h\        R\        V4      ,          4      h	  \        P                  pRp\	        V 4      ^8  d_   V ^,          R8X  d   \        P                  pM?V ^,          R8X  d   \        P                  pM V ^,          R8X  d   \        P                  pRpV'       d-   \        \        V ^ ,          4      V3\        V^VR	7      4      pV# \        \        V ^ ,          4      V3\        VVR
7      4      pV# )   unionstructstruct_packedr   z__anon%dzFailed to decode type %sFT)_anonymous__pack_r   )r  r   )
isinstance
basestringr   	str2ctyperK  r8  _decode_table_typelistr  r  strr%   	StructureUniontypedict)descanonfieldsr   r7   base	is_packedr   s   &       r   r  BPF._decode_table_typeZ  sO   dJ''==&&aA1v{qtS%;%;AaD%ABCQ1adD))MM1Q4)?)?!)E!Q)O"PQ!c**MM1Q4)?)?!)Eqt"LM!j11!(AaDI,=! 00Q4Drz)CI5D)MM4)?)?)B"CD#$>Q$GHH :SV CDD' ( ||	t9q=Aw("xxaI%||a,,|| 	s47|dWdtA/! "C
 
 s47|dWdt/! "C
r   c           
     ,   \        V4      p\        P                  ! V P                  V4      p\        P                  ! V P                  V4      p\        P
                  ! V P                  V4      \        \        39   pV^ 8  d   \        hV'       g|   V'       gt   \        P                  ! V P                  V4      P                  R4      pV'       g   \        RV,          4      h\        P                  \        P                  ! V4      4      pV'       gt   \        P                   ! V P                  V4      P                  R4      p	V	'       g   \        RV,          4      h\        P                  \        P                  ! V	4      4      p\#        WWbW1VR7      # )r   r,  z$Failed to load BPF Table %s key descz%Failed to load BPF Table %s leaf desc)reducer)r   r   bpf_table_idr1   bpf_table_fdr  r   r   KeyErrorbpf_table_key_descr6  r  r   r  jsonloadsbpf_table_leaf_descr	   )
r)   r7   keytypeleaftyper  r  map_fdis_queuestackkey_desc	leaf_descs
   &&&&&     r   	get_tableBPF.get_table  s   %!!$++t4!!$++t4--dkk6BGY[mFnnA:N}--dkk4@GGPH F MNN,,TZZ-ABG//TBII'RI G$ NOO--djj.CDHT6HGTTr   c                    WP                   9  d   V P                  V4      V P                   V&   V P                   V,          # r   )rJ  r  r)   keys   &&r   __getitem__BPF.__getitem__  s2    kk!#~~c2DKK{{3r   c                "    W P                   V&   R # r   rJ  )r)   r  leafs   &&&r   __setitem__BPF.__setitem__  s    Cr   c                ,    \        V P                  4      # r   )rK  rJ  r)   s   &r   __len__BPF.__len__  s    4;;r   c                     V P                   V R # r   r  r  s   &&r   __delitem__BPF.__delitem__  s    KKr   c                6    V P                   P                  4       # r   )rJ  __iter__r  s   &r   r  BPF.__iter__  s    {{##%%r   c                   \        V \        P                  4      '       g   \        R 4      h\        P
                  ! V P                  WV4      pV^ 8  d1   \        RP                  V\        P                  ! V) 4      4      4      hR# )"arg 1 must be of type BPF.Functionz7Failed to attach BPF function with attach_type {0}: {1}N)
r  r   r  r  r   bpf_prog_attachr  formatr   r   )r  attachable_fdr  flagsr;   s   &&&& r   attach_funcBPF.attach_func  sn    "cll++@AA!!"%%UK7 ''-vk2;;t;L'MO O r   c                   \        V \        P                  4      '       g   \        R 4      h\        P
                  ! V P                  W4      pV^ 8  d1   \        RP                  V\        P                  ! V) 4      4      4      hR# )r  z7Failed to detach BPF function with attach_type {0}: {1}N)
r  r   r  r  r   bpf_prog_detach2r  r  r   r   )r  r  r  r;   s   &&& r   detach_funcBPF.detach_func  sl    "cll++@AA""255-E7 ''-vk2;;t;L'MO O r   c                   \        V4      p\        V \        P                  4      '       g   \	        R 4      h\
        P                  ! V4      pV^ 8  d=   \        P                  ! \        P                  ! 4       4      p\	        RV: RV: 24      h\
        P                  ! W P                  4      pV^ 8  d=   \        P                  ! \        P                  ! 4       4      p\	        RV: RV: 24      hW n        R# )r  zFailed to open raw device rx  Failed to attach BPF to device N)r   r  r   r  r  r   bpf_open_raw_sockr   r   r%   r   bpf_attach_socketr  sock)r  devr  r  r;   s   &&   r   attach_raw_socketBPF.attach_raw_socket  s    s#"cll++@AA$$S)!8[[0F#vNOO##D%%07[[0FF$ % %r   c           	     f   R \         ,          p \        VR4      ;_uu_ 4       p\        V Uu. uF'  q3P                  4       P	                  4       ^,          NK)  	  up4      pRRR4       R\         ,          p \        TR4      ;_uu_ 4       p\        T Uu. uF'  q3P                  4       P	                  4       ^ ,          NK)  	  up4      pRRR4       . p	^ p
^ p\        RR4      ;_uu_ 4       pT EF^  pTP                  4       P	                  4       R,          w  rT
^ 8X  d   TR8X  d   ^p
K=  MT
^8X  d   TR8X  d   ^p
KP  T^ 8X  d   TR8X  d   ^pKb  TR	8X  d   ^pKm  MT^8X  d   TR	8X  d   ^pK  TP                  R
4      '       d   K  TP                  R4      '       g   TP                  R4      '       d   K  TP                  R4      '       d   K  \        P                  ! RT4      '       d   EK  TP                  4       R9   g   EK  \        P                  ! Y4      '       g   EK9  TX9  g   EKC  TX9   g   EKM  T	P                  T4       EKa  	  RRR4       \        T	4      # u upi   + '       g   i     EL; i  \
         d8   pTP                  \        P                  8w  d   Th\        . 4      p Rp?ELQRp?ii ; iu upi   + '       g   i     EL; i  \
         d8   pTP                  \        P                  8w  d   Th\        . 4      p Rp?ELGRp?ii ; i  + '       g   i     L; i)z%s/kprobes/blacklistr/  Nz%%s/tracing/available_filter_functions/proc/kallsyms:r     Ns   __init_begins
   __init_ends   __irqentry_text_starts   __irqentry_text_ends
   _kbl_addr_s   __perfs   perf_s   __SCT__s   ^.*\.cold(\.\d+)?$)   t   w)DEBUGFSrN  setrstripr  IOErrorr   r  
startswithrematchlower	fullmatchr8  )event_reblacklist_fileblacklist_fline	blacklistra  avail_filter_fileavail_filter_favail_filterrr  in_init_sectionin_irq_section
avail_filer   r  s   &              r   get_kprobe_functionsBPF.get_kprobe_functions  s   /'9	 nd++{k Rkd!4!4!6q!9!9k RS	 , DgM	#'..."#XKKM$7$7$9!$<$<#XY / "D))Z"++---/4 #a'_,*+  - %)]**+ "Q&55)*  55)*  6 $q(33)*
 ==// ]]9--x1H1H ]]:..XX4b99GGI-2<<3M3M)+l*JJrNa # *d 3xK !S ,++ 	 ww%++%BI	  $Y /.. 	#ww%++%r7L	# *)s   I= 
I)-I$I)!I= 7K 
K-KK	K +BL L L 5L L -L L 'L 1L ;L $I))I:	4I= :I= =J?,J::J?KK	K K L&,LL L0	c                d    \         V,           \        P                  4       8  d   \        R 4      hR# )z/Number of open probes would exceed global quotaN)r   r   get_probe_limitr  )r)   num_new_probess   &&r   _check_probe_quotaBPF._check_probe_quota  s*    n,s/B/B/DDMNN Er   c                     \         P                  P                  R 4      p V '       d"   V P                  4       '       d   \	        V 4      # \
        # )BCC_PROBE_LIMIT)r   r  getisdigitr  _default_probe_limit)env_probe_limits    r   r  BPF.get_probe_limit  s7    **..):;6688''''r   c                    WP                   9  d   / V P                   V&   W0P                   V,          V&   \        ^,          sR# r  Nr9  r   )r)   ev_namefn_namer  s   &&&&r   _add_kprobe_fdBPF._add_kprobe_fd'  s6    //)')DOOG$,. )Ar   c                H    V P                   V,          V \        ^,          sR# r  r  )r)   r  r  s   &&&r   _del_kprobe_fdBPF._del_kprobe_fd.  s    OOG$W-Ar   c                <    W P                   V&   \        ^,          sR# r  r:  r   )r)   r7   r  s   &&&r   _add_uprobe_fdBPF._add_uprobe_fd3  s     "Ar   c                :    V P                   V \        ^,          sR# r  r%  r)   r7   s   &&r   _del_uprobe_fdBPF._del_uprobe_fd8  s    OOD!Ar   c                    V P                    F$  pV P                  R V,          4      R8w  g   K"  Vu # 	  V P                   ^ ,          # )s   %sbpfr@   )_syscall_prefixesksymname)r)   prefixs   & r   get_syscall_prefixBPF.get_syscall_prefix@  s@    ,,F}}X./25 - %%a((r   c                F    \        V4      pV P                  4       V,           # r   )r   r0  r)  s   &&r   get_syscall_fnnameBPF.get_syscall_fnnameI  s     %&&(4//r   c                    \        V4      pV P                   F9  pVP                  V4      '       g   K  V P                  V\	        V4      R  4      u # 	  V# r   )r   r-  r  r3  rK  )r)   r7   r/  s   && r   fix_syscall_fnnameBPF.fix_syscall_fnnameP  sN    %,,Fv&&..tCKL/ABB - r   c                   \        V4      p\        V4      p\        V4      pV'       d   \        P                  V4      pV P                  \	        V4      4       ^ p. pV F  p V P                  WR7       K  	  V\	        V4      8X  d$   \        RV: RRP                  V4      : R24      hR# V P                  ^4       V P                  V\        P                  4      p	RVP                  RR	4      P                  R
R	4      ,           p
\        P                  ! V	P                  ^ WV^ 4      pV^ 8  d   \        RV: RV: R24      hV P                  WV4       V #    T^,          pTP                  T4        EK  ; i)r   eventr  Failed to attach BPF program z to kprobe /K, it's not traceable (either non-existing, inlined, or marked as "notrace")N   p_   +   _   .)r   r   r  r  rK  attach_kprober8  r  r  rp  r   replacer   bpf_attach_kprober  r  )r)   r:  	event_offr  r  matchesfailedprobesr  r  r  r  s   &&&&&       r   rB  BPF.attach_kprobeW  sX    '"7+#H- ..x8G##CL1FF(&&T&C   W%!(#((6*:!< = = "^^GSZZ0%--d3;;D$GG""255!WYJ6$e- . . 	Gb1%(aKFMM$''s   #EE;c                   \        V4      p\        V4      p\        V4      pV'       dl   \        P                  V4      p^ p. pV F  p V P                  WVR7       K  	  V\        V4      8X  d$   \        RV: RRP                  V4      : R24      hR# V P                  ^4       V P                  V\        P                  4      p	RVP                  RR	4      P                  R
R	4      ,           p
\        P                  ! V	P                  ^W^ V4      pV^ 8  d   \        RV: RV: R24      hV P                  WV4       V #    T^,          pTP	                  T4        EK  ; i)r   )r:  r  	maxactiver;  z to kretprobe r<  r=  N   r_r?  r@  rA  )r   r   r  attach_kretprober8  rK  r  r  r  rp  r   rC  r   rD  r  r  )r)   r:  r  r  rK  rF  rG  rH  r  r  r  r  s   &&&&&       r   rM  BPF.attach_kretprobey  sM    '"7+#H- ..x8GFF())4= * ?   W%!(#((6*:!< = = "^^GSZZ0%--d3;;D$GG""255!WQ	J6$e- . . 	Gb1%(aKFMM$''s   	EE"c                    \        V4      p\        V P                  V,          P                  4       4      pV F  pV P	                  W4       K  	  R # r   )r   r  r9  keysdetach_kprobe_event_by_fn)r)   r  fn_namesr  s   &&  r   detach_kprobe_eventBPF.detach_kprobe_event  s@    "7+05578G**7<  r   c                   \        V4      p\        V4      pWP                  9  d   \        R V,          4      h\        P                  ! V P                  V,          V,          4      pV^ 8  d   \        R4      hV P                  W4       \        V P                  V,          4      ^ 8X  d+   \        P                  ! V4      pV^ 8  d   \        R4      hR# R# )zKprobe %s is not attachedzFailed to close kprobe FDz Failed to detach BPF from kprobeN)r   r9  r  r   bpf_close_perf_event_fdr"  rK  bpf_detach_kprobe)r)   r  r  r;   s   &&& r   rQ  BPF.detach_kprobe_event_by_fn  s    "7+"7+//)7'ABB))$//'*B7*KL7788G-tw'(A-''0CQw BCC  .r   c                    \        V4      pR VP                  RR4      P                  RR4      ,           pV'       d   \        V4      pV P                  W24       R# V P                  V4       R# )r>  r?  r@  rA  Nr   rC  rQ  rS  r)   r:  r  r  s   &&& r   detach_kprobeBPF.detach_kprobe  W     '%--d3;;D$GG&w/G**7<$$W-r   c                    \        V4      pR VP                  RR4      P                  RR4      ,           pV'       d   \        V4      pV P                  W24       R# V P                  V4       R# )rL  r?  r@  rA  NrZ  r[  s   &&& r   detach_kretprobeBPF.detach_kretprobe  r^  r   c                ~   \        V 4      p \        V\        P                  4      '       g   \	        R4      h\
        P                  ! WP                  V4      pV^ 8  d_   \        P                  ! 4       pV\        P                  8X  d   \	        R4      h\        P                  ! V4      p\	        RV : RV: 24      hR# )zT
This function attaches a BPF function to a device on the device
driver level (XDP)
r  r  rx  NzMInternal error while attaching BPF to device, try increasing the debug level!)r   r  r   r  r  r   bpf_attach_xdpr  r%   r   r   EBADMSGr   r   )r  r  r  r;   err_nor  s   &&&   r   
attach_xdpBPF.attach_xdp  s     s#"cll++@AA  eeU37\\^F& !7 8 8 V,"F!, - - r   c                    \        V 4      p \        P                  ! V RV4      pV^ 8  d=   \        P                  ! \
        P                  ! 4       4      p\        RV : RV: 24      hR# )zW
This function removes any BPF function from a device on the
device driver level (XDP)
z!Failed to detach BPF from device rx  Nr@   )r   r   rc  r   r   r%   r   r  )r  r  r;   r  s   &&  r   
remove_xdpBPF.remove_xdp  sY     s#  b%07[[0F"F, - - r   c                h   \        V4      p\        V4      p\        4       pVR8X  d   ^ MTp\        P                  ! YT;'       g    ^ V\        P
                  ! R\        P                  ! \        4      4      \        P                  ! V4      4      ^ 8  d0   \        RVP                  4       : RVP                  4       : 24      hVP                  V,           p\        P
                  ! VP                  \        P                  4      P                  p	\        P                  ! VP                  4       W3# )r  Nz&could not determine address of symbol z in r@   )r   r   r   bcc_resolve_symnamer%   r&   r'   r   r/   r  r6  r2   r1   r3   r4   bcc_procutils_free)
r   r1   symnamer8   r*   sym_offr:   c_pidnew_addrmodule_paths
   &&&&&&    r   _check_path_symbolBPF._check_path_symbol  s    !&)"7+lBYC""KKCGGD"**%678HHSM	

  &~~/B C C::'ggcjj"++6<<szz*$$r   c                &   \        V 4      p V'       d   \        P                  ! W4      pM\        P                  ! V ^ 4      pV'       g   R# \        P
                  ! V\        P                  4      P                  p\        P                  ! V4       V# )a  
Find the full path to the shared library whose name starts with "lib{libname}".

If non-zero pid is given, search only the shared libraries mapped by the process with this pid.
Otherwise, search the global ldconfig cache at /etc/ld.so.cache.

Examples:
    BPF.find_library(b"c", pid=12345)  # returns b"/usr/lib/x86_64-linux-gnu/libc.so.6"
    BPF.find_library(b"pthread")       # returns b"/lib/x86_64-linux-gnu/libpthread.so.0"
    BPF.find_library(b"nonexistent")   # returns None
N)	r   r   !bcc_procutils_which_so_in_processbcc_procutils_which_sor%   r&   r3   r4   rm  )libnamer*   r;   libpaths   &&  r   find_libraryBPF.find_library  sf     #7+77EC,,Wa8C''#r{{+11s#r   c                   . p\         P                  P                  \        R 4      p\         P                  ! V4       EF  p\         P                  P                  W#4      p\         P                  P                  V4      '       g   KJ  \         P                  ! V4       F  p\         P                  P                  WE4      p\         P                  P                  V4      '       g   KI  V: RV: 2p\        P                  ! V P                  4       V4      '       g   K  VP                  VP                  4       4       K  	  EK  	  V# )events:)r   r  r  TRACEFSlistdirisdirr  r  r6  r8  r"  )tp_reresults
events_dircategorycat_dirr:  evt_dirtps   &       r   get_tracepointsBPF.get_tracepoints  s    WW\\'84


:.Hggll:8G77==))G,'',,w677==))%-u5Bxx33ryy{3 -	 / r   c                    \         P                  P                  \        R W4      p\         P                  P	                  V4      # )r}  )r   r  r  r  r  )r  r:  r  s   && r   tracepoint_existsBPF.tracepoint_exists  s+    '',,w(Bww}}W%%r   c                   \        V4      p\        V4      p\        V4      pV'       d1   \        P                  V4       F  pV P                  WR7       K  	  R# V P	                  V\        P
                  4      pVP                  R4      w  rV\        P                  ! VP                  WV4      pV^ 8  d   \        RV: RV: 24      hWpP                  V&   V # )aO  attach_tracepoint(tp="", tp_re="", fn_name="")

Run the bpf function denoted by fn_name every time the kernel tracepoint
specified by 'tp' is hit. The optional parameters pid, cpu, and group_fd
can be used to filter the probe. The tracepoint specification is simply
the tracepoint category and the tracepoint name, separated by a colon.
For example: sched:sched_switch, syscalls:sys_enter_bind, etc.

Instead of a tracepoint name, a regular expression can be provided in
tp_re. The program will then attach to tracepoints that match the
provided regular expression.

To obtain a list of kernel tracepoints, use the tplist tool or cat the
file /sys/kernel/debug/tracing/available_events.

Examples:
    BPF(text).attach_tracepoint(tp="sched:sched_switch", fn_name="on_switch")
    BPF(text).attach_tracepoint(tp_re="sched:.*", fn_name="on_switch")
r  r  N   :r;  z to tracepoint )r   r   r  attach_tracepointrp  rQ   r  r   bpf_attach_tracepointr  r  r;  )r)   r  r  r  r  tp_categorytp_namer  s   &&&&    r   r  BPF.attach_tracepoint"  s    * b! '"7+))%0&&"&> 1^^GS^^4!#$&&ruukC6$b* + +"$Br   c                8   \        V4      pWP                  9   d   \        RV,          4      h\        V4      pV P                  V\        P
                  4      p\        P                  ! VP                  V4      pV^ 8  d   \        R4      hW@P                  V&   V # )a|  attach_raw_tracepoint(self, tp=b"", fn_name=b"")

Run the bpf function denoted by fn_name every time the kernel tracepoint
specified by 'tp' is hit. The bpf function should be loaded as a
RAW_TRACEPOINT type. The fn_name is the kernel tracepoint name,
e.g., sched_switch, sys_enter_bind, etc.

Examples:
    BPF(text).attach_raw_tracepoint(tp="sched_switch", fn_name="on_switch")
z#Raw tracepoint %s has been attachedz&Failed to attach BPF to raw tracepoint)	r   r<  r  rp  r   r   r   bpf_attach_raw_tracepointr  )r)   r  r  r  r  s   &&&  r   attach_raw_tracepointBPF.attach_raw_tracepointH  s     b!(((ABFGG"7+^^GS%7%78**255"56DEE&(#r   c                    \        V4      pWP                  9  d   \        RV,          4      h\        P                  ! V P                  V,          4       V P                  V R# )zdetach_raw_tracepoint(tp="")

Stop running the bpf function that is attached to the kernel tracepoint
specified by 'tp'.

Example: bpf.detach_raw_tracepoint("sched_switch")
z!Raw tracepoint %s is not attachedN)r   r<  r  r   close)r)   r  s   &&r   detach_raw_tracepointBPF.detach_raw_tracepoint`  sP     b!,,,?"DEE
((,-##B'r   c                D    VP                  V 4      '       g	   W,           pV# r   )r  )r/  r7   s   &&r   
add_prefixBPF.add_prefixo  s    v&&=Dr   c                     \         P                  ! 4       R 8w  d   R# \        P                  ! 4       '       g   R# \        P                  R4      R8w  d   R# R# )x86_64Fbpf_trampoline_link_progTr@   )r1  r2  r   bpf_has_kernel_btfr   r.  r   r   r   support_kfuncBPF.support_kfuncu  sB     )%%''<<23r9r   c                 x    \         P                  ! 4       '       g   R # \        P                  R4      R8w  d   R# R # )Fs   bpf_lsm_bpfTr@   )r   r  r   r.  r   r   r   support_lsmBPF.support_lsm  s+    %%''<<'2-r   c                 4    \         P                  R R4      ^8H  # )bpf_attach_typeBPF_MODIFY_RETURN)r   kernel_enum_has_valr   r   r   support_fmod_retBPF.support_fmod_ret  s     &&'8:MNRSSSr   c                    \        V4      p\        P                  R V4      pWP                  9  d   \	        RV,          4      h\
        P                  ! V P                  V,          4       V P                  V R# )   kfunc__z$Kernel entry func %s is not attachedN)r   r   r  r=  r  r   r  r)   r  s   &&r   detach_kfuncBPF.detach_kfunc  s^    "7+..W5...BWLMM
%%g./  )r   c                    \        V4      p\        P                  R V4      pWP                  9  d   \	        RV,          4      h\
        P                  ! V P                  V,          4       V P                  V R# )
   kmod_ret__z Fmod_ret func %s is not attachedN)r   r   r  r?  r  r   r  r  s   &&r   detach_fmod_retBPF.detach_fmod_ret  s^    "7+..8+++>HII
""7+,g&r   c                    \        V4      p\        P                  R V4      pWP                  9  d   \	        RV,          4      h\
        P                  ! V P                  V,          4       V P                  V R# )
   kretfunc__z#Kernel exit func %s is not attachedN)r   r   r  r>  r  r   r  r  s   &&r   detach_kretfuncBPF.detach_kretfunc  s^    "7+..8---AGKLL
$$W-.(r   c                L   \        V4      p\        P                  R V4      pWP                  9   d   \	        RV,          4      hV P                  V\        P                  4      p\        P                  ! VP                  4      pV^ 8  d   \	        R4      hW0P                  V&   V # )r  z&Kernel entry func %s has been attachedz)Failed to attach BPF to entry kernel func)
r   r   r  r=  r  rp  r   r   bpf_attach_kfuncr  r)   r  r  r  s   &&  r   attach_kfuncBPF.attach_kfunc  s    "7+..W5***DwNOO^^GS[[1!!"%%(6GHH(*W%r   c                L   \        V4      p\        P                  R V4      pWP                  9   d   \	        RV,          4      hV P                  V\        P                  4      p\        P                  ! VP                  4      pV^ 8  d   \	        R4      hW0P                  V&   V # )r  z"Fmod_ret func %s has been attachedz,Failed to attach BPF to fmod_ret kernel func)
r   r   r  r?  r  rp  r   r   r  r  r  s   &&  r   attach_fmod_retBPF.attach_fmod_ret  s    "7+..8'''@7JKK^^GS[[1!!"%%(6JKK%''"r   c                L   \        V4      p\        P                  R V4      pWP                  9   d   \	        RV,          4      hV P                  V\        P                  4      p\        P                  ! VP                  4      pV^ 8  d   \	        R4      hW0P                  V&   V # )r  z%Kernel exit func %s has been attachedz(Failed to attach BPF to exit kernel func)
r   r   r  r>  r  rp  r   r   r  r  r  s   &&  r   attach_kretfuncBPF.attach_kretfunc  s    "7+..8)))CgMNN^^GS[[1!!"%%(6FGG')G$r   c                    \        V4      p\        P                  R V4      pWP                  9  d   \	        RV,          4      h\
        P                  ! V P                  V,          4       V P                  V R# )   lsm__zLSM %s is not attachedN)r   r   r  r@  r  r   r  r  s   &&r   
detach_lsmBPF.detach_lsm  sX    "7+..73,,&4w>??
g&'LL!r   c                L   \        V4      p\        P                  R V4      pWP                  9   d   \	        RV,          4      hV P                  V\        P                  4      p\        P                  ! VP                  4      pV^ 8  d   \	        R4      hW0P                  V&   V # )r  zLSM %s has been attachedzFailed to attach LSM)
r   r   r  r@  r  rp  r   r   bpf_attach_lsmr  r  s   &&  r   
attach_lsmBPF.attach_lsm  s    "7+..73ll"6@AA^^GSWW-&6233 "Wr   c                 r    \         P                  R 4      R8w  g   \         P                  R4      R8w  d   R# R# )bpf_find_raw_tracepointbpf_get_raw_tracepointTFr@   )r   r.  r   r   r   support_raw_tracepointBPF.support_raw_tracepoint  s.     <<12b8<<01R7r   c                    R p \        V 4      ;_uu_ 4       pV FP  pVP                  4       P                  R^4      w   r4VP                  R4      ^ ,          pVR8X  g   KG   RRR4       R# 	   RRR4       R#   + '       g   i     R# ; i)r   	bpf_trace_modulesNTF)rN  r  r  )kallsymssymsr  _r7   s        r    support_raw_tracepoint_in_module$BPF.support_raw_tracepoint_in_module  so     $(^^t#{{}223:Azz$'*.. ^
  ^^^s   AA8 A8+A88B		c                Z    \        V 4      p \        V4      p\        P                  ! W4      # r   )r   r   kernel_struct_has_field)struct_name
field_names   &&r   r  BPF.kernel_struct_has_field  s'    &{3%j1
**;CCr   c                Z    \        V 4      p \        V4      p\        P                  ! W4      # r   )r   r   r  )	enum_name
value_names   &&r   r  BPF.kernel_enum_has_val  s'    $Y/	%j1
&&y==r   c                b   \        V4      pWP                  9  d   \        RV,          4      h\        P                  ! V P                  V,          4      pV^ 8  d   \        R4      hVP                  R4      w  r4\        P                  ! W44      pV^ 8  d   \        R4      hV P                  V R# )zdetach_tracepoint(tp="")

Stop running a bpf function that is attached to the kernel tracepoint
specified by 'tp'.

Example: bpf.detach_tracepoint("sched:sched_switch")
zTracepoint %s is not attachedz$Failed to detach BPF from tracepointr  N)r   r;  r  r   rV  r  bpf_detach_tracepoint)r)   r  r;   r  r  s   &&   r   detach_tracepointBPF.detach_tracepoint  s     b!(((;b@AA))$*=*=b*AB7BCC!#$''=7BCC#r   c	           
     ^    \         P                  ! WVWEWgV4      p	V	^ 8  d   \        R4      hV	# )r   z"Failed to attach BPF to perf event)r   bpf_attach_perf_eventr  )
r)   progfdev_type	ev_configsample_periodsample_freqr*   cpugroup_fdr;   s
   &&&&&&&&& r   _attach_perf_eventBPF._attach_perf_event#  s6    ''Ch@7@AA
r   c	                4   \        V4      pV P                  V\        P                  4      p	/ p
V^ 8  d#   V P	                  V	P
                  WWEWgV4      W&   M2\        4        F$  pV P	                  V	P
                  WWEWkV4      W&   K&  	  WP                  W3&   R# r   N)r   rp  r   r   r  r  r   rB  )r)   r  r  r  r  r  r*   r  r  r  r;   re  s   &&&&&&&&&   r   attach_perf_eventBPF.attach_perf_event+  s    "7+^^GS^^4!8..ruug!(DCH %&00%CHF ' 7:w23r   c                    \         P                  ! V\        P                  ! V4      VWE^ 4      pV^ 8  d   \	        R4      hV# )r   z&Failed to attach BPF to perf raw event)r   bpf_attach_perf_event_rawr%   r/   r  )r)   r  attrr*   r  r  r;   s   &&&&&& r   _attach_perf_event_rawBPF._attach_perf_event_raw9  s=    ++FBHHTNCq"7DEE
r   c                Z   \        V4      pV P                  V\        P                  4      p/ pV^ 8  d"   V P	                  VP
                  VW4V4      Wt&   M1\        4        F#  pV P	                  VP
                  VW8V4      Wx&   K%  	  WpP                  VP                  VP                  3&   R# r  )
r   rp  r   r   r  r  r   rB  r  config)	r)   r  r  r*   r  r  r  r;   re  s	   &&&&&&   r   attach_perf_event_rawBPF.attach_perf_event_raw@  s    "7+^^GS^^4!822255$h(CH %&44RUUD* ' ;>tyy$++67r   c                4    V P                   W3,          p^ pTP	                  4        F#  p\
        P                  ! T4      ;'       g    TpK%  	  T^ 8w  d   \        R4      hT P                   Y3 R#   \         d    \        R P                  Y4      4      hi ; i)z)Perf event type {} config {} not attachedz$Failed to detach BPF from perf eventN)rB  r  r  r  valuesr   rV  )r)   r  r  fdsr;   r  s   &&&   r   detach_perf_eventBPF.detach_perf_eventM  s    	%''(<=C
 **,B--b188SC !8BCC!!7"67  	%GNN$ % %	%s   A1 1&Bc                r    \        \        P                  W4       U Uu. uF  w  rV NK	  	  upp 4      # u upp i r   r  r    get_user_functions_and_addresses)r7   sym_rer  s   && r   get_user_functionsBPF.get_user_functions[  sA    88FHF 'dDFH I 	I H   3
c                r    \        \        P                  W4       UUu. uF  w  r#VNK	  	  upp4      # u uppi )a  
We are returning addresses here instead of symbol names because it
turns out that the same name may appear multiple times with different
addresses, and the same address may appear multiple times with the same
name. We can't attach a uprobe to the same address more than once, so
it makes sense to return the unique set of addresses that are mapped to
a symbol that matches the provided regular expression.
r	  )r7   r  r  addresss   &&  r   get_user_addressesBPF.get_user_addresses`  sC     88FHF !-GFH I 	I Hr  c                   aa \        V 4      p \        S4      o. oVV3R  lp\        P                  ! V \        V4      4      pV^ 8  d   \	        RW03,          4      hS# )c                 j   < T p\         P                  ! SV4      '       d   SP                  W!34       ^ # r   )r  r  r8  )sym_namer8   dname	addressesr  s   && r   sym_cb4BPF.get_user_functions_and_addresses.<locals>.sym_cbr  s,    Exx&&  %/r   z"Error %d enumerating symbols in %s)r   r   bcc_foreach_function_symbolr   r  )r7   r  r  r;   r  s   &f  @r   r
  $BPF.get_user_functions_and_addressesm  sZ    %!&)		 --dL4HI7@C;NOOr   c                   VR8X  dC   RWP                   P                  R\        P                  P	                  V4      4      V3,          # RWP                   P                  R\        P                  P	                  V4      4      W43,          # )r  s
   %s_%s_0x%xr@  s   %s_%s_0x%x_%dr@   )_probe_replsubr   r  basename)r)   r/  r  r8   r*   s   &&&&&r   _get_uprobe_evnameBPF._get_uprobe_evname}  ss    "9 F,<,<,@,@rwwGWGWX\G],^`d#eee $v/?/?/C/CD"''JZJZ[_J`/acg&mmmr   c                   V^ 8  g   Q hVe   V^ 8X  g   Q R4       h\        V4      p\        V4      p\        V4      p\        V4      pV'       dN   \        P                  W4      pV P                  \	        V4      4       V F  p	V P                  WWVR7       K  	  R# \        P                  WWFV4      w  rV P                  ^4       V P                  V\        P                  4      pV P                  RWV4      p\        P                  ! VP                  ^ WWF4      pV^ 8  d   \        R4      hV P                  W4       V # )ac  attach_uprobe(name="", sym="", sym_re="", addr=None, fn_name=""
                 pid=-1, sym_off=0)

Run the bpf function denoted by fn_name every time the symbol sym in
the library or binary 'name' is encountered. Optional parameters pid,
cpu, and group_fd can be used to filter the probe.

If sym_off is given, attach uprobe to offset within the symbol.

The real address addr may be supplied in place of sym, in which case sym
must be set to its default value. If the file is a non-PIE executable,
addr must be a virtual address, otherwise it must be an offset relative
to the file load address.

Instead of a symbol name, a regular expression can be provided in
sym_re. The uprobe will then attach to symbols that match the provided
regular expression.

Libraries can be given in the name argument without the lib prefix, or
with the full path (/usr/lib/...). Binaries can be given only with the
full path (/bin/sh). If a PID is given, the uprobe will attach to the
version of the library used by the process.

Example: BPF(text).attach_uprobe("c", "malloc")
         BPF(text).attach_uprobe("/usr/bin/python", "main")
Nz!offset with addr is not supportedr7   r8   r  r*      pzFailed to attach BPF to uprobe)r   r   r  r  rK  attach_uprobers  rp  r   r!  r   bpf_attach_uprober  r  r&  )r)   r7   r:   r  r8   r  r*   ro  r  sym_addrr  r  r  r  s   &&&&&&&&      r   r&  BPF.attach_uprobe  s(   : !||a<D!DD<%s#!&)"7+..t<I##C	N3%""+2 # = & --dGL"^^GSZZ0))$C@""255!WDF6<==G(r   c                   \        V4      p\        V4      p\        V4      p\        V4      pV'       d2   \        P                  W4       F  pV P                  WWVR7       K  	  R# \        P	                  WWF4      w  rV P                  ^4       V P                  V\        P                  4      p	V P                  RWV4      p
\        P                  ! V	P                  ^WWF4      pV^ 8  d   \        R4      hV P                  W4       V # )a  attach_uretprobe(name="", sym="", sym_re="", addr=None, fn_name=""
                    pid=-1)

Run the bpf function denoted by fn_name every time the symbol sym in
the library or binary 'name' finishes execution. See attach_uprobe for
meaning of additional parameters.
r$  N   rz!Failed to attach BPF to uretprobe)r   r   r  attach_uretprobers  r  rp  r   r!  r   r'  r  r  r&  )r)   r7   r:   r  r8   r  r*   r(  r  r  r  r  s   &&&&&&&     r   r,  BPF.attach_uretprobe  s      %s#!&)"7+224@%%4.5 & @ A --dC"^^GSZZ0))$C@""255!WDF6?@@G(r   c                .   WP                   9  d   \        R V,          4      h\        P                  ! V P                   V,          4      pV^ 8  d   \        R4      h\        P                  ! V4      pV^ 8  d   \        R4      hV P                  V4       R# )zUprobe %s is not attachedz Failed to detach BPF from uprobeN)r:  r  r   rV  bpf_detach_uprober*  )r)   r  r;   s   && r   detach_uprobe_eventBPF.detach_uprobe_event  sz    //)7'ABB))$//'*BC7>??##G,7>??G$r   c                    \        V4      p\        V4      p\        P                  WW4V4      w  rcV P                  RWcV4      pV P	                  V4       R# )zdetach_uprobe(name="", sym="", addr=None, pid=-1)

Stop running a bpf function that is attached to symbol 'sym' in library
or binary 'name'.
r%  Nr   r   rs  r!  r0  )r)   r7   r:   r8   r*   ro  r  r  s   &&&&&&  r   detach_uprobeBPF.detach_uprobe  sP      %s#--dGL))$C@  )r   c                    \        V4      p\        V4      p\        P                  WW44      w  rSV P                  RWSV4      pV P	                  V4       R# )zdetach_uretprobe(name="", sym="", addr=None, pid=-1)

Stop running a bpf function that is attached to symbol 'sym' in library
or binary 'name'.
r+  Nr3  )r)   r7   r:   r8   r*   r  r  s   &&&&&  r   detach_uretprobeBPF.detach_uretprobe  sN      %s#--dC))$C@  )r   c                >   \        ^ \        P                  ! V P                  4      4       EFm  p\        P                  ! V P                  V4      pVP                  R4      '       dV   V P                  V\        P                  4      pV P                  V P                  VR,          4      VP                  R7       K  VP                  R4      '       dV   V P                  V\        P                  4      pV P                  V P                  VR,          4      VP                  R7       K  VP                  R4      '       dh   V P                  V\        P                  4      pVP                  \        R4      R P                  RR	4      pV P!                  WCP                  R
7       EK{  VP                  R4      '       dX   V P                  V\        P"                  4      pVP                  \        R4      R pV P%                  WCP                  R
7       EK  VP                  R4      '       d   V P'                  VR7       EK  VP                  R4      '       d   V P)                  VR7       EKA  VP                  R4      '       g   EK[  V P+                  VR7       EKp  	  R# )r   s   kprobe__:   NNr9  s   kretprobe__:   NNs   tracepoint__Ns   __r  r  s   raw_tracepoint__r  )r  r  r  )rm  r   rn  r1   ro  r  rp  r   r   rB  r6  r7   rM  rQ   rK  rC  r  r   r  r  r  r  )r)   re  rs  r  r  s   &    r   rU  BPF._trace_autoload  s   q#//<=A--dkk1=I##K00^^Iszz:""11)B-@GG # % %%n55^^Iszz:%%11)C.AGG & % %%o66^^Is~~>WWS123;;E4H&&"gg&>%%&9::^^Is/A/ABWWS!4567**b''*B%%j11!!)!4%%m44$$Y$7%%h//	23 >r   c                z   V P                   '       g   \        R\        ,          R4      V n         V'       d{   V P                   P                  4       p\        P                  ! V\        P
                  4      p\        P                  ! V\        P                  V\        P                  ,          4       V P                   # )zGtrace_open(nonblocking=False)

Open the trace_pipe if not already open
z%s/trace_piper/  )	rD  rN  r  filenofcntlF_GETFLF_SETFLr   
O_NONBLOCK)r)   nonblockingr  fls   &&  r   
trace_openBPF.trace_open   sp    
 ~~~!/G";TBDN^^**,[[U]]3BrBMM/AB~~r   c                    V P                  V4      pV'       g   V'       d   R# VP                  R4      '       d   K=  VR,          P                  4       pVR,          pVP                  R4      p VRV P	                  4       w  rVrxT^R pY$^,           R pTP                  R4      p
Y*^,           R p T\        T4      \        T4      T\        T4      T3#   \
         d   p	 Rp	?	K  Rp	?	ii ; i  \
         d   p	Ru Rp	?	# Rp	?	ii ; i)	ztrace_fields(nonblocking=False)

Read from the kernel debug trace pipe and return a tuple of the
fields (task, pid, cpu, flags, timestamp, msg) or None if no
line was read (nonblocking=True)
Ns   CPU::N   N:   NNr  )NNNNNNr@   )Unknownr   r   rJ  g        rJ  )trace_readliner  lstripfindr  r  r  r  )r)   rC  r  taskts_endr*   r  r  tsra  sym_endmsgs   &&          r   trace_fieldsBPF.trace_fields-  s    &&{3DK);w''9##%D9DYYt_F&*7Fm&9&9&;#% a)C 
$DiioG{|$CDc#hC%rCHH    DCCDs0   0C 3"C/ C,'C,/D:D;DDc                    V P                  V4      pRp VP                  R4      P                  4       pV#   \         d     T# i ; i)ztrace_readline(nonblocking=False)

Read from the kernel debug trace pipe and return one line
If nonblocking is False, this will block until ctrl-C is pressed.
Nrq   )rE  readliner  r  )r)   rC  tracer  s   &&  r   rK  BPF.trace_readlineP  sS     ,	>>$'..0D   		s   6 AAc                     V'       d.   V P                  RR7      pV'       g   K%  VP                  ! V!  pMV P                  RR7      p\        V4       \        P
                  P                  4        Ks  )ztrace_print(self, fmt=None)

Read from the kernel debug trace pipe and print on stdout.
If fmt is specified, apply as a format string to the output. See
trace_fields for the members of the tuple
example: trace_print(fmt="pid {1}, msg = {5}")
F)rC  )rS  r  rK  printr
  stdoutflush)r)   fmtr  r  s   &&  r   trace_printBPF.trace_print`  sZ     **u*=xzz6***u*=$KJJr   c                    V ^ 8  d
   V R8w  d   Rp V \         P                  9   g   \        V 4      \         P                  V &   \         P                  V ,          # )z_sym_cache(pid)

Returns a symbol cache for the specified PID.
The kernel symbol cache is accessed by providing any PID less than zero.
r@   )r   _sym_cachesr"   )r*   s   &r   
_sym_cacheBPF._sym_caches  sD     7sbyCcoo%#.s#3COOC s##r   c                D   \        \        V 4      4      pVP                  R4      R8w  Edi   \        4       p\	        4       pV P
                  Vn        V P                  Vn        V P                  VP                  n        \        P                  ! \        P                  \        P                  ! V4      \        P                  ! V4      4      pV^ 8  dr   VP                  '       dZ   VP                  '       dH   RVP                  \        P                   ! VP                  \        P"                  4      P$                  rp	M~RT Rrp	MxVP&                  VP                  \        P                   ! VP                  \        P"                  4      P$                  rp	M'\        P)                  V4      P+                  W4      w  rpV'       d   V	e
   RV
,          MRp
T	;'       g    Rp	W,           p	V'       d+   Ve'   R\,        P.                  P1                  V4      ,          MRpW,           # )a)  sym(addr, pid, show_module=False, show_offset=False)

Translate a memory address into a function name for a pid, which is
returned. When show_module is True, the module name is also included.
When show_offset is True, the instruction offset as a hexadecimal
number is also included in the string.

A pid of less than zero will access the kernel symbol cache.

Example output when both show_module and show_offset are True:
    "start_thread+0x202 [libpthread-2.24.so]"

Example output when both show_module and show_offset are False:
    "start_thread"
bpf_stack_build_idNs   +0x%xr   s	   [unknown]s    [%s]r@   )r  r  rM  r   r   statusbuild_idr2   ur   bcc_buildsymcache_resolver   
_bsymcacher%   r/   r1   r&   r3   r4   r7   rb  r=   r   r  r   )r8   r*   show_moduleshow_offsetr9   
typeofaddrr:   br;   r7   r2   r1   s   &&&&&       r   r:   BPF.sym  s   ( d_
??/0B6#%'![[!(}}!*{{!##*--cnn.0hhqk.0hhsm=# 1Wzzzcjjj$(#**

BKK8>> !d& '+D$FdF$'HHcjj$&GGCJJ$D$J$J !D& "%!4!<!<T!L
$&1d6FF"C##|}v1 BGG,,V447: 	}r   c                2    \         P                  V RWR4      # )an  ksym(addr)

Translate a kernel memory address into a kernel function name, which is
returned. When show_module is True, the module name ("kernel") is also
included. When show_offset is true, the instruction offset as a
hexadecimal number is also included in the string.

Example output when both show_module and show_offset are True:
    "default_idle+0x0 [kernel]"
Fr@   )r   r:   )r8   rk  rl  s   &&&r   ksymBPF.ksym  s     wwtR5AAr   c                L    \         P                  R4      P                  RV 4      # )zksymname(name)

Translate a kernel name into an address. This is the reverse of
ksym. Returns -1 when the function name is unknown.Nr@   )r   rb  rC   )r7   s   &r   r.  BPF.ksymname  s      ~~b!..tT::r   c                ,    \        V P                  4      # )znum_open_kprobes()

Get the number of open K[ret]probes. Can be useful for scenarios where
event_re is used while attaching and detaching probes.
)rK  r9  r  s   &r   num_open_kprobesBPF.num_open_kprobes  s     4??##r   c                ,    \        V P                  4      # )z9num_open_uprobes()

Get the number of open U[ret]probes.
)rK  r:  r  s   &r   num_open_uprobesBPF.num_open_uprobes  s    
 4??##r   c                ,    \        V P                  4      # )z<num_open_tracepoints()

Get the number of open tracepoints.
)rK  r;  r  s   &r   num_open_tracepointsBPF.num_open_tracepoints  s    
 4&&''r   c                   \         P                  \        V P                  4      ,          ! 4       p\	        V P                  P                  4       4       F	  w  r4WBV&   K  	  \        P                  ! \        V4      W!4       R# )zperf_buffer_poll(self)

Poll from all open perf ring buffers, calling the callback that was
provided when calling open_perf_buffer for each entry.
N)r%   rP  rK  rA  rL  r  r   perf_reader_poll)r)   timeoutreadersre  vs   &&   r   perf_buffer_pollBPF.perf_buffer_poll  s[     ;;T%6%6!77:d//6689DAAJ :S\7<r   c                   \         P                  \        V P                  4      ,          ! 4       p\	        V P                  P                  4       4       F	  w  r#W1V&   K  	  \        P                  ! \        V4      V4       R# )zperf_buffer_consume(self)

Consume all open perf buffers, regardless of whether or not
they currently contain events data. Necessary to catch 'remainder'
events when wakeup_events > 1 is set in open_perf_buffer
N)r%   rP  rK  rA  rL  r  r   perf_reader_consume)r)   r  re  r  s   &   r   perf_buffer_consumeBPF.perf_buffer_consume  s[     ;;T%6%6!77:d//6689DAAJ :Gg6r   c                (    V P                  V4       R# )z=kprobe_poll(self)

Deprecated. Use perf_buffer_poll instead.
N)r  r)   r  s   &&r   kprobe_pollBPF.kprobe_poll  s    
 	g&r   c                   V P                   '       g<   \        P                  ! WV4      V n         V P                   '       g   \        R 4      hR# \        P                  ! V P                   WV4      pV^ 8  d   \        R 4      hR# )zCould not open ring bufferN)rC  r   bpf_new_ringbufr  bpf_add_ringbuf)r)   r  r  ctxrets   &&&& r   _open_ring_bufferBPF._open_ring_buffer  st    $$$$'$7$7C$HD!((( <== ) %%d&;&;VMCQw <== r   c                    V P                   '       g   \        R4      h\        P                  ! V P                   V4       R# )zring_buffer_poll(self)

Poll from all open ringbuf buffers, calling the callback that was
provided when calling open_ring_buffer for each entry.
No ring buffers to pollN)rC  r  r   bpf_poll_ringbufr  s   &&r   ring_buffer_pollBPF.ring_buffer_poll  s2     $$$566T22G<r   c                    V P                   '       g   \        R4      h\        P                  ! V P                   4       R# )a  ring_buffer_consume(self)

Consume all open ringbuf buffers, regardless of whether or not
they currently contain events data. This is best for use cases
where low latency is desired, but it can impact performance.
If you are unsure, use ring_buffer_poll instead.
r  N)rC  r  r   bpf_consume_ringbufr  s   &r   ring_buffer_consumeBPF.ring_buffer_consume  s0     $$$566 5 56r   c                ,    \         P                  ! 4       # r   )r   bcc_free_memoryr  s   &r   free_bcc_memoryBPF.free_bcc_memory  s    ""$$r   c                     \         P                  ! \        P                  V P	                  4       4       R#   \
         d'   p\        R\        T4      ,           4        Rp?R# Rp?ii ; i)z<add_module(modname)

Add a library or exe to buildsym cache
z&Error adding module to build sym cacheN)r   bcc_buildsymcache_add_moduler   rj  r"  r  rZ  r  )modnamera  s   & r   
add_moduleBPF.add_module  sG    ?((9IJ ?6s1v=>>?s   37 A(A##A(c                    R# )zthe do nothing exit handlerNr   r  s   &r   r  BPF.donothing)  s    r   c                .   \        V P                  P                  4       4       F2  w  r\        P                  ! VP
                  4       V P                  V K4  	  V P                  '       d*   \        P                  ! V P                  4       RV n        R# R# )z^close(self)

Closes all associated files descriptors. Attached BPF programs are not
detached.
N)	r  rI  r   r   r  r  r1   r   bpf_module_destroy)r)   r7   r  s   &  r   r  	BPF.close-  sf     TZZ--/0HDHHRUUO

4  1 ;;;""4;;/DK r   c                   \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                  P                  4       4       F  w  rV P                  V4       K  	  \        V P                   P                  4       4       F  w  rV P#                  V4       K  	  \        V P$                  P'                  4       4      pV F9  p\)        V P$                  V,          \*        4      '       g   K,  V P$                  V K;  	  \        V P,                  P'                  4       4       F  w  rVV P/                  WV4       K  	  V P0                  '       d"   V P0                  P3                  4        R V n        V P3                  4        V P4                  '       d*   \6        P8                  ! V P4                  4       R V n        R # R # r   )r  r9  r   rS  r:  r0  r;  r  r<  r  r=  r  r>  r  r@  r  r?  r  rJ  rP  r  r
   rB  r  rD  r  rC  r   bpf_free_ringbuf)r)   kr  
table_keysr  r  r  s   &      r   rG  BPF.cleanup:  s9   ..01DA$$Q' 2..01DA$$Q' 2,,2245DA""1% 6006689DA&&q) :--3356DAa  7,,2245DA  # 6++-.DAOOA /**0023DA  # 4 $++**,-
C$++c*N;;KK$  %))>)>)C)C)E$F W""76 %G>>>NN  "!DN

      !6!67$(D! !r   c                    V # r   r   r  s   &r   	__enter__BPF.__enter___  s    r   c                &    V P                  4        R # r   )rG  )r)   exc_typeexc_valexc_tbs   &&&&r   __exit__BPF.__exit__b  s    r   )rC  rH  r?  rI  r=  r>  r9  r@  r1   rB  rA  r<  rJ  rD  r;  r:  )s   sys_s
   __x64_sys_s   __x32_compat_sys_s   __ia32_compat_sys_s   __arm64_sys_s   __s390x_sys_s   __s390_sys_s   __riscv_sys_)Nr@   )F)NNNr  )r   r   r   r   )r   r   r   r   r   )r   r   r   )r   r   )r   )r@   r@   r   r   r   r@   r@   r@   )r@   r   r@   r@   r@   )r@   r@   )r   r   r   Nr   r@   r   )r   r   r   Nr   r@   )r   r   Nr@   r   )r   r   Nr@   )FFT)FF)r@   )rE   rF   rG   rH   r   r   r   r   r   rQ   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   XDP_FLAGS_UPDATE_IF_NOEXISTr   XDP_FLAGS_SKB_MODEr   XDP_FLAGS_DRV_MODEr   XDP_FLAGS_HW_MODEr   XDP_FLAGS_REPLACEr  compiler  ra  r   bcc_buildsymcache_newrj  r   r-  r   r%   r  r   CDLL_librtclock_gettimer   c_intr'   argtypesclassmethodr   r   r	   objectr  staticmethodr  r&  r+   rt  rp  r  r  r  c_boolc_charc_wcharc_ubytec_shortc_ushortc_uintr   c_ulong
c_longlongrA   c_floatc_doublec_longdoublec_int64c_uint64r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r"  r&  r*  r0  r3  r6  rB  rM  rS  rQ  r\  r`  rf  ri  rs  rz  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r  r
  r!  r&  r,  r0  r4  r7  rU  rE  rS  rK  r^  rb  r:   rq  r.  rv  ry  r|  r  r  r  r  r  r  r  r  r  r  rG  r  r  rI   rJ   rK   s   @r   r   r     sL      --MF%%I%%I''J
//C''J''J))KF!!G##H##HF--MF //N"33!!G
//C''K!!H!!HF))L"*"<"<!**!** (( (( **-.KK**,J 	tVn5),	i6N	 OC2<< C WW\T2F))N!xxH)=>N	* 	*    E6  
 
  8 !$cARd4#(hT $* @
)3P
")) 	BJJ 	"**	
 	"** 	2;; 	 	 	 	"** 	bmm 	r~~ 	"** 	2;; 	  	RZZ!^!" 	bkkAo#I& ) )VU& 
  & O O O O   I IVO
 ( (

)0 D D=D.. - -& 
- 
- % %$  .   & &$L0(  
 	 	   T T
*') "   	 	 D D
 > >
$*:>8 I I 
I 
I  n7r@	%**38!DF & 
$ 
$ . .` B B ; ;$$(	=
7'>=
7% ? ?*#)J r   r   )E
__future__r   rE  ctypesr%   r?  r  r   r  r   r
  r1  r3  libbccr   r   r   r   r   tabler	   r
   r   r   r   perfr   utilsr   r   r   r   r   versionr   disassemblerr   r   rh  r   r   r  	NameErrorr  r  r   r   r  r  r  r  r7  DEBUG_LLVM_IRr{  DEBUG_PREPROCESSORDEBUG_SOURCErz  	DEBUG_BTFr  r"   rN   rV   rb   ro   r   r   r   r   r   r   r   r   <module>r     s9   &     	 	  
   ] ] Y Y  V V   6 %    
'',,w	
*	ww~~g#G
 	  	)& )V    8 0( (T  `& `}  Js   6D4 4	E ?E 