I'm using ptrace to trace the syscalls of a process. After forking the process, I use PTRACE_TRACEME to start trace the the process. The code looks like this:
while (true) {
int status;
int gotPid;
gotPid = waitpid(pid, &status, 0);
if (WIFEXITED(status) || WIFSIGNALED(status)) {
break;
}
if (WIFSTOPPED(status)) {
handleTrace();
}
}
Then there is the handleTrace function, which looks like this.
long syscall;
syscall = ptrace(PTRACE_PEEKUSER,
pid, 8 * ORIG_RAX, NULL);
// do something with the syscall
// continue program
ptrace(PTRACE_SYSCALL, pid, NULL, NULL);
This is all good, but if the program forks (or creates a new thread) I also want to trace the child processes the traced process creates (and also the threads created by the process). I know that it can be done using PTRACE_O_TRACEFORK, PTRACE_O_TRACEVFORK and PTRACE_O_TRACECLONE, but from the man documentation, it is very hard to figure out how exactly it is done. I need some examples on this.
Edit:
I found a similar question here: How to ptrace a multi-threaded application? I tried it with the following code. This code tracks the system calls of the started process and it is supposed to track the forked processes too. It is run after a fork() in the parent process (the child calls a PTRACE_TRACEME and an exec()).
Edit2:
I made some more modifications on the code, with some more progress.
long orig_eax;
int status;
int numPrograms = 1;
while(1) {
int pid;
CHECK_ERROR_VALUE(pid = waitpid(-1, &status, __WALL));
std::cout << pid << ": Got event." <