Advanced Programming in UNIX Environment Episode 33

Process Accounting

Most UNIX systems provide an option to do process accounting. When enabled,the kernel writes an accounting record each time a process terminates. These accounting records typically contain a small amount of binary data with the name of the command,the amount of CPU time used,the user ID and group ID,the starting time,and so on.

the I/O counts maintained on Solaris 10 are in units of bytes,whereas FreeBSD 8.0 and Mac OS X 10.6.8 maintain units of blocks,although there is no distinction between different block sizes,making the counter effectively useless. Linux 3.2.0,on the other hand,doesn’t try to maintain I/O statistics at all.

The structure of the accounting records is defined in the header <sys/acct.h>. Although the implementation of each system differs,the accounting records look something like

typedef u_short comp_t; /* 3-bit base 8 exponent; 13-bit fraction */
struct acct
{
    char ac_flag;
    char ac_stat;
    uid_t ac_uid;
    gid_t ac_gid;
    dev_t ac_tty;
    time_t ac_btime;
    comp_t ac_utime;
    comp_t ac_stime;
    comp_t ac_etime;
    comp_t ac_mem;
    comp_t ac_io;
    comp_t ac_rw;
    char ac_comm[8];
};

Times are recorded in units of clock ticks on most platforms,but FreeBSD stores microseconds instead. The ac_flag member records certain events during the execution of the process.

#include "apue.h"

int main(void)
{
    pid_t pid;

    if((pid=fork())<0)
        err_sys("fork error");
    else if(pid!=0)
    {
        sleep(2);
        exit(2);
    }

    if((pid=fork())<0)
        err_sys("fork error");
    else if(pid!=0)
    {
        sleep(4);
        abort();
    }

    if((pid=fork())<0)
        err_sys("fork error");
    else if(pid!=0)
    {
        execl("/bin/dd","dd","if=/etc/passwd","of=/dev/null",NULL);
        exit(7);
    }

    if((pid=fork())<0)
        err_sys("fork error");
    else if(pid!=0)
    {
        sleep(8);
        exit(0);
    }
    sleep(6);
    kill(getpid(),SIGKILL);
    exit(6);
}

Program to generate accounting data

#include "apue.h"
#include <sys/acct.h>

#if defined(BSD)
#define acct acctv2
#define ac_flag ac_trailer.ac_flag
#define FMT "%-*.*s e=%.0f,chars=%.0f,%c %c %c %c\n"
#elif defined(HAS_AC_STAT)
#define FMT "%-*,*s e= %6ld,chars=%7ld,stat=%3u: %c %c %c %c\n"
#else
#define FMT "%-*,*s e=%6ld,%c %c %c %c\n"
#endif
#if defined(LINUX)
#define acct acct_v3
#endif
#if !define(HAS_ACROE)
#define ACORE 0
#endif
#if !defined(HAS_AXSIG)
#define AXSIG 0
#endif
#if !defined(BSD)
static unsigned long compt2ulong(comp_t comptime)
{
    unsigned long val;
    int exp;

    val=comptime&0x1fff;
    exp=(comptime>>13)&7;
    while(exp-->0)
        val*=8;

    return val;
}
#endif

int main(int argc,char *argv[])
{
    struct acct acdata;
    FILE *fp;

    if(argc!=2)
    {
        err_quite("usage: pracct filename");
    }
    if((fp=fopen(argv[1],"r"))==NULL)
        err_sys("can't open %s",argv[1]);
    while(fread(&acdata,sizeof(acdata),1,fp)==1)
        printf(FMT,(int)sizeof(acdata.ac_comm),(int)sizoef(acdata.ac_comm),acdata.ac_comm,#if defined(BSD)
            acdata.ac_etime,acdata.ac_io,#else
            compt2ulong(acdata.ac_etime),compt2ulong(acdata.ac_io),#endif
#if defined(HAS_AC_STAT)
            (unsigned char)acdata.ac_stat,#endif
            acdata.ac_flag&ACORE?'D':' ',acdata.ac_flag&AXSIG?'X':' ',acdata.ac_flag&AFORK?'F':' ',acdata.ac_flag&ASU?'S':' ');
    }
    if(ferror(fp))
        err_sys("read error");

    return 0;
}

Print selected fields from system’s accounting file

To perform our test,we do the following:

1.Become superuser and enable accounting,with the accton command. Note that when this command terminates,accounting should be on; therefore,the first record in the accounting file should be from this command.
2.Exit the superuser shell and run the program in Figure 8.28. This should append six records to the accounting file: one for the superuser shell,one for the test parent,and one for each of the four test children. A new process is not created by the execl in the second child. There is only a single accounting record for the second child.
3.Become superuser and turn accounting off. Since accounting is off when this accton command terminates,it should not appear in the accounting file.
4.Run the program in Figure 8.29 to print the selected fields from the accounting file.

User Identification

Any process can find out its real and effective user ID and group ID. Sometimes,however,we want to find out the login name of the user who’s running the program.

#include <unistd.h>

char *getlogin(void);

To find the login name,UNIX systems have historically called the ttyname function (Section 18.9) and then tried to find a matching entry in the utmp file (Section 6.8). FreeBSD and Mac OS X store the login name in the session structure associated with the process table entry and provide system calls to fetch and store this name. System V provided the cuserid function to return the login name. This function called getlogin and,if that failed,did a getpwuid(getuid()). The IEEE Standard 1003.1-1988 specified cuserid,but it called for the effective user ID to be used,instead of the real user ID. The 1990 version of POSIX.1 dropped the cuserid function. The environment variable LOGNAME is usually initialized with the user’s login name by login(1) and inherited by the login shell.

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐


用的openwrt路由器,家里宽带申请了动态公网ip,为了方便把2280端口映射到公网,发现经常被暴力破解,自己写了个临时封禁ip功能的脚本,实现5分钟内同一个ip登录密码错误10次就封禁这个ip5分钟,并且进行邮件通知使用步骤openwrt为19.07.03版本,其他版本没有测试过安装bashmsmtpopkg
#!/bin/bashcommand1&command2&wait从Shell脚本并行运行多个程序–杨河老李(kviccn.github.io)
1.先查出MAMP下面集成的PHP版本cd/Applications/MAMP/bin/phpls-ls 2.编辑修改.bash_profile文件(没有.bash_profile文件的情况下回自动创建)sudovim~/.bash_profile在文件的最后输入以下信息,然后保存退出exportPATH="/Applications/MAMP/bin/php/php7.2.20/b
1、先输入locale-a,查看一下现在已安装的语言2、若不存在如zh_CN之类的语言包,进行中文语言包装:apt-getinstalllanguage-pack-zh-hans3、安装好后我们可以进行临时修改:然后添加中文支持: locale-genzh_CN.UTF-8临时修改> export LC_ALL='zh_CN.utf8'> locale永久
BashPerlTclsyntaxdiff1.进制数表示Languagebinaryoctalhexadecimalbash2#[0~1]0[0~7]0x[0~f]or0X[0~f]perl0b[0~1]0[0~7]0x[0~f]tcl0b[0~1]0o[0~7]0x[0~f]bashdifferentbaserepresntationreference2.StringlengthLanguageStr
正常安装了k8s后,使用kubect工具后接的命令不能直接tab补全命令补全方法:yum-yinstallbash-completionsource/usr/share/bash-completion/bash_completionsource<(kubectlcompletionbash)echo"source<(kubectlcompletionbash)">>~/.bashrc 
参考这里启动jar包shell脚本修改过来的#!/bin/bash#默认应用名称defaultAppName='./gadmin'appName=''if[[$1&&$1!=0]]thenappName=$1elseappName=$defaultAppNamefiecho">>>>>>本次重启的应用:$appName<
#一个数字的行#!/bin/bashwhilereadlinedon=`echo$line|sed's/[^0-9]//g'|wc-L`if[$n-eq1]thenecho$linefidone<1.txt#日志切割归档#!/bin/bashcd/data/logslog=1.logmv_log(){[-f$1]&&mv$1$2
#文件增加内容#!/bin/bashn=0cat1.txt|whilereadlinedon=[$n+1]if[$n-eq5]thenecho$lineecho-e"#Thisisatestfile.\n#Testinsertlineintothisfile."elseecho$linefidone#备份/etc目录#
# su - oraclesu: /usr/bin/ksh: No such file or directory根据报错信息:显示无法找到文件 /usr/bin/ksh果然没有该文件,但是发现存在文件/bin/ksh,于是创建了一个软连接,可以规避问题,可以成功切换到用户下,但无法执行系统自带命令。$. .bash_profile-ksh: .: .b
history显示历史指令记录内容,下达历史纪录中的指令主要的使用方法如果你想禁用history,可以将HISTSIZE设置为0:#exportHISTSIZE=0使用HISTIGNORE忽略历史中的特定命令下面的例子,将忽略pwd、ls、ls-ltr等命令:#exportHISTIGNORE=”pwd:ls:ls-ltr:”使用HIS
一.命令历史  1.history环境变量:    HISTSIZE:输出的命令历史条数,如history的记录数    HISTFILESIZE:~/.bash_history保存的命令历史记录数    HISTFILLE:历史记录的文件路径    HISTCONTROL:     ignorespace:忽略以空格开头的命令
之前在网上看到很多师傅们总结的linux反弹shell的一些方法,为了更熟练的去运用这些技术,于是自己花精力查了很多资料去理解这些命令的含义,将研究的成果记录在这里,所谓的反弹shell,指的是我们在自己的机器上开启监听,然后在被攻击者的机器上发送连接请求去连接我们的机器,将被攻击者的she
BashOne-LinersExplained,PartI:Workingwithfileshttps://catonmat.net/bash-one-liners-explained-part-oneBashOne-LinersExplained,PartII:Workingwithstringshttps://catonmat.net/bash-one-liners-explained-part-twoBashOne-LinersExplained,PartII
Shell中变量的作用域:在当前Shell会话中使用,全局变量。在函数内部使用,局部变量。可以在其他Shell会话中使用,环境变量。局部变量:默认情况下函数内的变量也是全局变量#!/bin/bashfunctionfunc(){a=99}funcecho$a输出>>99为了让全局变量变成局部变量
1、多命令顺序执行;  命令1;命令2  多个命令顺序执行,命令之间没有任何逻辑联系&&  命令1&&命令2  逻辑与,当命令1正确执行,才会执行命令2||  命令1||命令2  逻辑或,当命令1执行不正确,才会执行命令2例如:ls;date;cd/home/lsx;pwd;who ddif=输入文件of=输
原博文使用Linux或者unix系统的同学可能都对#!这个符号并不陌生,但是你真的了解它吗?首先,这个符号(#!)的名称,叫做"Shebang"或者"Sha-bang"。Linux执行文件时发现这个格式,会把!后的内容提取出来拼接在脚本文件或路径之前,当作实际执行的命令。 Shebang这个符号通常在Unix系统的脚本
1、历史命令history[选项][历史命令保存文件]选项:-c:  清空历史命令-w:  把缓存中的历史命令写入历史命令保存文件 ~/.bash_historyvim/etc/profile中的Histsize可改存储历史命令数量历史命令的调用使用上、下箭头调用以前的历史命令使用“!n”重复执行第n条历史
目录1.Shell脚本规范2.Shell脚本执行3.Shell脚本变量3.1环境变量3.1.1自定义环境变量3.1.2显示与取消环境变量3.1.3环境变量初始化与对应文件的生效顺序3.2普通变量3.2.1定义本地变量3.2.2shell调用变量3.2.3grep调用变量3.2.4awk调用变量3.3
   http://www.voidcn.com/blog/wszzdanm/article/p-6145895.html命令功能:显示登录用户的信息命令格式:常用选项:举例:w显示已经登录的用户及正在进行的操作[root@localhost~]#w 11:22:01up4days,21:22, 3users, loadaverage:0.00,0.00,0.00USER