Linuxãµã¼ãã®é害対å¿ã§ç¤¾å ã§ä¼çµ±çã«ä½¿ããã¦ãããã¯ããã¯ãI/Oã§å®å ¨ã«ãããã¯ãã¦ãããã¤ã³ããç¹å®ãããã¦ãã¦ã
- åé¡å¯¾å¿ã®ãããæªããããã»ã¹ãstraceãã¦ã¿ã
- read(2)ãwrite(2)ã§ãããã¯ãã¦ãããã¨ãçºè¦ãã
- read(2)ãwrite(2)ãconnect(2)ã®å¼æ°ã«ã¯ãã¡ã¤ã«ãã£ã¹ã¯ãªãã¿çªå·ãã¿ãã
- ããã»ã¹IDã¨ãã¡ã¤ã«ãã£ã¹ã¯ãªãã¿çªå·ã使ã£ã¦ã/proc/
/fd/ ã®ä¸èº«ãã¿ãã¨ãã½ã±ããI/Oã§åºãã£ã¦ããå ´åã¯ã½ã±ããçªå·ãçºè¦ã§ãã - netstat ããã½ã±ããçªå·ã§grepãã¦æ¥ç¶å ãçºè¦ãã
[y_uuki@hogehoge ~]$ sudo strace -p 10471 Process 10471 attached - interrupt to quit read(58, <unfinished ...> Process 10471 detached [y_uuki@hogehoge ~]$ sudo readlink /proc/10471/fd/58 socket:[1148032788] [y_uuki@hogehoge ~]$ netstat -ane | grep 1148032788 tcp 0 0 10.0.0.10:44566 10.0.0.11:3306 ESTABLISHED 48 1148032788
IPã¢ãã¬ã¹ 10.0.0.11 ã«å¯¾ãã3306çªãã¼ã(MySQL)ã®æ¥ç¶ã§è©°ã¾ã£ã¦ãããã¨ããããã
社å
ã®wikiã«ããã¨ã10å¹´ãããåãã使ããã¦ãããç¾å¨ã®ã¡ã³ãã¼ã¯ /proc
ãç´æ¥è¦ãã«ãstraceãã¦ããlsof -i -a -p <pid>
ãªã©ã使ã£ã¦ãããããããªãã
networking - How do I find out more about socket files in /proc/fd? - Unix & Linux Stack Exchange