Implementing Ptrace in Rust from Scratch: Syscall Tracing Guide

Added:

Process Tracing
Ptrace Syscall
Rust Syscalls
Project Setup
Attach Loop
Read Registers
Read Memory
Final Test

Process Tracing

0:00
Playing Section
  • 1

    Introduces the goal of understanding Linux process tracing by examining syscalls.

  • 2

    Shows how to intercept system calls of an external process using utilities like strace.

  • 3

    Proposes to reimplement a small part of this functionality in Rust.

Fundamental understanding of Linux system calls (syscalls) and the boundary transition between user space and kernel space.
Intermediate knowledge of Rust programming, particularly the use of 'unsafe' Rust and FFI (Foreign Function Interface) to interact with C libraries.
Concepts of Unix process management, specifically process creation (fork/exec), process states, and signal handling.
Basic familiarity with CPU registers (such as RAX/orig_rax on x86_64 architectures) and how they store syscall numbers and arguments.
Building a fully featured debugger from scratch, incorporating software breakpoints, instruction stepping, and reading DWARF debugging symbols.
Implementing process manipulation techniques, such as system call argument modification or dynamic code injection into a target process's memory space.
Transitioning to modern, low-overhead Linux observability tools, specifically using eBPF (Extended Berkeley Packet Filter) with Rust frameworks like Aya.
Exploring system call filtering and sandboxing mechanisms, such as seccomp (Secure Computing Mode), to restrict process privileges.
4.8K views335likes32:50@0xfabaceaeOriginal Release: 2025-01-07

The ptrace system call enables one process to attach to another, observe its system calls, and read its memory and registers, which is the fundamental mechanism behind debugging tools like GDB and the strace utility; this video demonstrates implementing ptrace functionality in Rust by directly calling the ptrace syscall (number 101) and wait4 syscall (number 61) using inline assembly to trace Python's console I/O operations.