MCPcopy Create free account
hub / github.com/rabbitstack/fibratus / Open

Method Open

internal/etw/trace.go:392–405  ·  view source on GitHub ↗

Open opens an ETW trace processing handle for consuming events from an ETW real-time trace. It specifies the callbacks the consumer wants to use to receive the events or trace buffer statistics. The first callback function that receives buffer-related statistics for each buffer ETW flushes. ETW call

(consumer *Consumer, errs chan error)

Source from the content-addressed store, hash-verified

390// it delivers all the events in the buffer. The second callback function
391// that ETW calls for each event in the buffer.
392func (t *Trace) Open(consumer *Consumer, errs chan error) error {
393 t.consumer = consumer
394 t.errs = errs
395 logfile := etw.NewEventTraceLogfile(t.Name)
396 logfile.SetEventCallback(windows.NewCallback(t.processEventCallback))
397 logfile.SetBufferCallback(windows.NewCallback(t.bufferStatsCallback))
398 logfile.SetModes(etw.ProcessTraceModeRealtime | etw.ProcessTraceModeEventRecord)
399
400 t.openHandle = etw.OpenTrace(logfile)
401 if !t.openHandle.IsValid() {
402 return fmt.Errorf("unable to open %s trace: %v", t.Name, windows.GetLastError().Error())
403 }
404 return nil
405}
406
407// processEventCallback is the event callback function signature that is called each time
408// a new event is available on the session buffer. It does the heavy lifting of parsing incoming

Callers

nothing calls this directly

Calls 7

SetEventCallbackMethod · 0.95
SetBufferCallbackMethod · 0.95
SetModesMethod · 0.95
NewEventTraceLogfileFunction · 0.92
OpenTraceFunction · 0.92
IsValidMethod · 0.45
ErrorMethod · 0.45

Tested by

no test coverage detected