dump process stack and heap memory
Usage: ffdump -o <OUTPUT FILE> -p <PID>
print the strings of printable characters in process stack and heap
Usage: ffstrings <PID>
change files access time and modify time
Usage: ffutime <FILE NAME> <yyyy-MM-dd HH:mm:ss>
change process heap memory
Usage: memchg -p <PID> -f <ORIGIN STR> -t <TARGET STR>
tracing kernel functions invocation
Usage:
-
integrate
fftrace.h -
update code with
ff_trace_on()andff_trace_offwhich you need to trace.
Hint: you need to insure /sys/kernel/debug directory exist. if not, execute mount -t debugfs nodev /sys/kernel/debug at first