function::task_ancestry
名称
function::task_ancestry — The ancestry of the given task
Synopsis
task_ancestry:string(task:long,with_time:long)
Arguments
task
- task_struct pointer
with_time
- set to 1 to also print the start time of processes (given as a delta from boot time)
Description
Return the ancestry of the given task in the form of “grandparent_process=>parent_process=>process”.