From 1341cd25fac3610321e4f5efdcaa85f2cfb8a460 Mon Sep 17 00:00:00 2001 From: Daniele Carollo Date: Thu, 16 Apr 2026 13:07:48 +0000 Subject: [PATCH 1/5] Update libraries - Update falco driver, libs modules - Integrate sha1 from hash-library as replacement of openSSL - Fix user/group fetching and filter out containerized processes - Disable container functionalities not available anymore OOTB from Falco - Adjust falco lib calls Signed-off-by: Daniele Carollo --- .gitmodules | 3 + Dockerfile.alpine | 1 - Makefile | 2 +- makefile.manifest.inc | 11 +- modules/Makefile | 29 ++- modules/falco | 2 +- modules/falco-driver | 2 +- modules/falco-libs | 2 +- modules/falco-libs.x86_64.mri | 80 -------- modules/hash-library | 1 + src/collector/Makefile | 3 +- src/libs/containercontext.cpp | 293 ++++++++++++++---------------- src/libs/containercontext.h | 2 +- src/libs/filecontext.cpp | 5 +- src/libs/fileeventprocessor.cpp | 4 +- src/libs/fileflowprocessor.cpp | 5 +- src/libs/k8seventprocessor.cpp | 2 +- src/libs/libsysflow-musl.mri | 1 + src/libs/libsysflow.mri | 1 + src/libs/networkflowprocessor.cpp | 2 +- src/libs/processcontext.cpp | 64 +++++-- src/libs/sysflowcontext.cpp | 12 +- src/libs/sysflowexception.h | 1 + src/libs/sysflowprocessor.cpp | 5 +- src/libs/utils.cpp | 118 +++++++++++- src/libs/utils.h | 2 +- 26 files changed, 346 insertions(+), 307 deletions(-) create mode 160000 modules/hash-library diff --git a/.gitmodules b/.gitmodules index f374fe2c..1eec13ec 100644 --- a/.gitmodules +++ b/.gitmodules @@ -34,3 +34,6 @@ [submodule "modules/elf"] path = modules/elf url = https://github.com/arachsys/libelf.git +[submodule "modules/hash-library"] + path = modules/hash-library + url = https://github.com/stbrumme/hash-library.git diff --git a/Dockerfile.alpine b/Dockerfile.alpine index 165c8080..995b8199 100644 --- a/Dockerfile.alpine +++ b/Dockerfile.alpine @@ -77,4 +77,3 @@ COPY ./docker-entry-ubi.sh /usr/local/sysflow/modules/bin/ RUN cd /build/modules && \ make INSTALL_PATH=${INSTALL_PATH} ARCH=${ARCH} MUSL=1 MAKE_JOBS=${MAKE_JOBS} install && \ make clean && rm -rf /build/modules - diff --git a/Makefile b/Makefile index a4a96d75..2ca2e98a 100644 --- a/Makefile +++ b/Makefile @@ -128,7 +128,7 @@ docker-driver-build: .PHONY: docker-driver-build/musl docker-driver-build/musl: - ( DOCKER_BUILDKIT=1 docker build --no-cache --build-arg ALPINE_VER=${ALPINE_VERSION} --build-arg UBI_VER=${UBI_VERSION} --build-arg FALCO_VER=${FALCO_VERSION} --build-arg FALCOCTL_VERSION=${FALCOCTL_VERSION} --build-arg FALCO_LIBS_VER=${FALCO_LIBS_VERSION} --build-arg FALCO_LIBS_DRIVER_VER=${FALCO_LIBS_DRIVER_VERSION} --target driver -t sysflowtelemetry/alpine:driver-${FALCO_LIBS_VERSION}-${FALCO_VERSION}-${UBI_VERSION} -f Dockerfile.driver.alpine.amd64 . ) + ( DOCKER_BUILDKIT=1 docker build --no-cache --build-arg ALPINE_VER=${ALPINE_VERSION} --build-arg UBI_VER=${UBI_VERSION} --build-arg FALCO_VER=${FALCO_VERSION} --build-arg FALCOCTL_VERSION=${FALCOCTL_VERSION} --build-arg FALCO_LIBS_VER=${FALCO_LIBS_VERSION} --build-arg FALCO_LIBS_DRIVER_VER=${FALCO_LIBS_DRIVER_VERSION} --target driver -t sysflowtelemetry/alpine:driver-${FALCO_LIBS_VERSION}-${FALCO_VERSION}-${ALPINE_VERSION} -f Dockerfile.driver.alpine.amd64 . ) .PHONY: docker-libs-build docker-libs-build: diff --git a/makefile.manifest.inc b/makefile.manifest.inc index 80220e39..d8a19e1a 100644 --- a/makefile.manifest.inc +++ b/makefile.manifest.inc @@ -16,12 +16,12 @@ # See the License for the specific language governing permissions and # limitations under the License. -SYSFLOW_VERSION?=0.8.0 +SYSFLOW_VERSION?=0.9.0-dev SYSFLOW_BUILD_NUMBER?=1 -FALCO_VERSION=0.40.0 -FALCO_LIBS_VERSION=0.20.0 -FALCO_LIBS_DRIVER_VERSION=8.0.0+driver -FALCOCTL_VERSION=0.11.0 +FALCO_VERSION=0.43.0 +FALCO_LIBS_VERSION=0.23.2 +FALCO_LIBS_DRIVER_VERSION=9.1.0+driver +FALCOCTL_VERSION=0.12.2 AVRO_VERSION=release-1.11.0 ELF_VERSION=v0.189 GLOG_VERSION=v0.6.0 @@ -32,3 +32,4 @@ XXHASH_VERSION=v0.8.2 SPARSE_VERSION=sparsehash-2.0.4 ALPINE_VERSION=3.18.3 UBI_VERSION=9.4-1214.1729773476 +HASH_LIBRARY=hash_library_v8 \ No newline at end of file diff --git a/modules/Makefile b/modules/Makefile index c7cca5b6..ad533f86 100644 --- a/modules/Makefile +++ b/modules/Makefile @@ -50,6 +50,7 @@ endif cd filesystem && git fetch origin && git checkout $(GHCFS_VERSION) cd sparsehash && git fetch origin && git checkout $(SPARSE_VERSION) cd xxHash && git fetch origin && git checkout $(XXHASH_VERSION) + cd hash-library && git fetch origin && git checkout $(HASH_LIBRARY) # libelf is a pre-requisite for libs build .PHONY: modules @@ -61,7 +62,8 @@ modules: elf/package \ glog/package \ snappy/package \ xxhash/package \ - sparsehash/package + sparsehash/package \ + hash-library/package .PHONY: install install: modules \ @@ -74,7 +76,8 @@ install: modules \ snappy/install \ dkms-rh/install \ xxhash/install \ - sparsehash/install + sparsehash/install \ + hash-library/install .PHONY: falcolibs/package falcolibs/package: @@ -101,18 +104,15 @@ falcolibs/package: -DCMD_MAKE="make -j${MAKE_JOBS}" \ ${MUSL_FLAG} ../. && make -j${MAKE_JOBS} && \ mkdir -p include && mkdir -p lib && mkdir -p bin && \ - mkdir -p include/curl && cp curl-prefix/src/curl/include/curl/*.h include/curl && \ mkdir -p include/driver && cp driver/src/*h include/driver && cp ../driver/*h include/driver && \ mkdir -p include/userspace/libsinsp && cp ../userspace/libsinsp/*.h include/userspace/libsinsp && \ mkdir -p include/userspace/libsinsp/sinsp_filter_transformers && cp ../userspace/libsinsp/sinsp_filter_transformers/*.h include/userspace/libsinsp/sinsp_filter_transformers/ && \ - mkdir -p include/userspace/libsinsp/container_engine && cp ../userspace/libsinsp/container_engine/*.h include/userspace/libsinsp/container_engine/ && \ mkdir -p include/userspace/libsinsp/filter && cp ../userspace/libsinsp/filter/*.h include/userspace/libsinsp/filter/ && \ mkdir -p include/userspace/libsinsp/events && cp ../userspace/libsinsp/events/*.h include/userspace/libsinsp/events/ && \ mkdir -p include/userspace/libsinsp/state && cp ../userspace/libsinsp/state/*.h include/userspace/libsinsp/state/ && \ mkdir -p include/userspace/plugin && cp ../userspace/plugin/*.h include/userspace/plugin/ && \ mkdir -p include/userspace/libscap && cd .. && find userspace/libscap -name '*.h' -exec cp -r --parents '{}' build/include \; && cd build && \ cp libscap/*.h include/userspace/libscap && \ - mkdir -p include/openssl && cp openssl-prefix/src/openssl/include/openssl/*.h include/openssl && \ cp -r tbb-prefix/src/tbb/include/tbb include/ && \ cp -r tbb-prefix/src/tbb/include/oneapi include/ && \ cp uthash-prefix/src/uthash/src/*.h include/ && \ @@ -123,27 +123,16 @@ falcolibs/package: cp tbb-prefix/src/tbb/lib_release/libtbb.a lib/ && \ cp jsoncpp-prefix/src/lib/libjsoncpp.a lib/ && \ cp -r jsoncpp-prefix/src/include/json include/ && \ - cp -r c-ares-prefix/src/c-ares/include/*.h include/ && \ cp libpman/*.a lib/ && \ cp libsinsp/*.a lib/ && \ find libscap -name '*.a' -exec cp '{}' lib \; && \ cp ../../falco/docker/driver-loader-buster/docker-entrypoint.sh bin/ && \ cp re2-prefix/build/libre2.a lib/ && \ - cp grpc-prefix/src/grpc/*.a lib/ && \ - find grpc-prefix/src/grpc/third_party/abseil-cpp -name '*.a' -exec cp '{}' lib \; && \ - cp c-ares-prefix/src/c-ares/lib/libcares.a lib/ && \ - cp curl-prefix/src/curl/lib/.libs/libcurl.a lib/ && \ - cp openssl-prefix/src/openssl/target/lib/*.a lib/ && \ cp zlib-prefix/src/zlib/libz.a lib/libz.a ifeq ($(BUNDLE_FALCO_LIBS), 1) cp -r falco-libs/build/lib falco-libs/build/bundle cp falco-libs.$(ARCH).mri falco-libs/build/bundle cd falco-libs/build/bundle && \ - mv libgrpc++.a libgrpcpp.a && \ - mv libgrpc++_alts.a libgrpcpp_alts.a && \ - mv libgrpc++_error_details.a libgrpcpp_error_details.a && \ - mv libgrpc++_reflection.a libgrpcpp_reflection.a && \ - mv libgrpc++_unsecure.a libgrpcpp_unsecure.a && \ ar -M m_name) - (*cont)->cont.name = container->m_name; - (*cont)->cont.image = container->m_image + ":" + container->m_imagetag; - (*cont)->cont.id = container->m_id; - (*cont)->cont.imageid = container->m_imageid; - (*cont)->cont.type = static_cast(container->m_type); - (*cont)->cont.privileged = container->m_privileged; +void ContainerContext::setContainer(ContainerObj **cont) { + // SF_DEBUG(m_logger, "Setting container info. Name: " << container->m_name) + // (*cont)->cont.name = container->m_name; + // (*cont)->cont.image = container->m_image + ":" + container->m_imagetag; + // (*cont)->cont.id = container->m_id; + // (*cont)->cont.imageid = container->m_imageid; + // (*cont)->cont.type = static_cast(container->m_type); + // (*cont)->cont.privileged = container->m_privileged; } ContainerContext::ContainerContext(context::SysFlowContext *cxt, @@ -48,181 +47,157 @@ ContainerContext::~ContainerContext() { clearAllContainers(); } ContainerObj *ContainerContext::createContainer(sinsp_threadinfo *ti) { - if (ti->m_container_id.empty()) { - return nullptr; - } - - const sinsp_container_info::ptr_t container = - m_cxt->getInspector()->m_container_manager.get_container( - ti->m_container_id); - if (!container) { - SF_DEBUG(m_logger, "Thread has container id, but no container object. ID: " - << ti->m_container_id) - auto *cont = new ContainerObj(); - cont->cont.name = INCOMPLETE; - cont->cont.image = INCOMPLETE_IMAGE; - cont->cont.id = ti->m_container_id; - cont->incomplete = true; - return cont; - } - - auto *cont = new ContainerObj(); - setContainer(&cont, container); - if (cont->cont.name.compare(INCOMPLETE) == 0 || - cont->cont.image.compare(INCOMPLETE_IMAGE) == 0) { - cont->incomplete = true; - } - - if (m_cxt->isK8sEnabled()) { - std::shared_ptr pod = m_k8sCxt->getPod(ti); - if (pod != nullptr) { - SF_DEBUG(m_logger, "Setting pod id to " << pod->pod.id - << " for container " - << ti->m_container_id) - cont->cont.podId.set_string(pod->pod.id); - pod->refs++; - } else { - cont->cont.podId.set_null(); - } - } - - return cont; + // std::string container_id = m_cxt->getInspector()->m_plugin_tables.get_container_id(*ti); + + // if (container_id.empty()) { + // return nullptr; + // } + + // auto *cont = new ContainerObj(); + // cont->cont.id = container_id; + // cont->cont.name = INCOMPLETE; + // cont->cont.image = INCOMPLETE_IMAGE; + // cont->incomplete = true; + // return cont; + return nullptr; } ContainerObj *ContainerContext::getContainer(const std::string &id) { - ContainerTable::iterator cont = m_containers.find(id); - if (cont != m_containers.end()) { - return cont->second; - } + // ContainerTable::iterator cont = m_containers.find(id); + // if (cont != m_containers.end()) { + // return cont->second; + // } return nullptr; } bool ContainerContext::exportContainer(const std::string &id) { bool exprt = false; - ContainerTable::iterator cont = m_containers.find(id); - if (cont != m_containers.end()) { - if (m_cxt->isK8sEnabled() && !cont->second->cont.podId.is_null()) { - m_k8sCxt->exportPod(cont->second->cont.podId.get_string()); - } - if (!cont->second->written) { - m_writer->writeContainer(&(cont->second->cont)); - cont->second->written = true; - exprt = true; - } - } + // ContainerTable::iterator cont = m_containers.find(id); + // if (cont != m_containers.end()) { + // if (m_cxt->isK8sEnabled() && !cont->second->cont.podId.is_null()) { + // m_k8sCxt->exportPod(cont->second->cont.podId.get_string()); + // } + // if (!cont->second->written) { + // m_writer->writeContainer(&(cont->second->cont)); + // cont->second->written = true; + // exprt = true; + // } + // } return exprt; } int ContainerContext::derefContainer(const std::string &id) { int result = 0; - ContainerTable::iterator cont = m_containers.find(id); - if (cont != m_containers.end()) { - cont->second->refs--; - result = cont->second->refs; - } + // ContainerTable::iterator cont = m_containers.find(id); + // if (cont != m_containers.end()) { + // cont->second->refs--; + // result = cont->second->refs; + // } return result; } ContainerObj *ContainerContext::getContainer(sinsp_threadinfo *ti) { - if (ti->m_container_id.empty()) { - return nullptr; - } - - ContainerObj *ct = nullptr; - ContainerTable::iterator cont = m_containers.find(ti->m_container_id); - if (cont != m_containers.end()) { - if (cont->second->written && !cont->second->incomplete) { - return cont->second; - } - - const sinsp_container_info::ptr_t container = - m_cxt->getInspector()->m_container_manager.get_container( - ti->m_container_id); - if (!container) { - // m_containers.erase(cont); - // delete cont->second; - return cont->second; - } - - if (cont->second->written && cont->second->incomplete) { - SF_DEBUG(m_logger, - "Container is written and includes name: " << container->m_name); - if (container->m_name.compare(INCOMPLETE) == 0 || - container->m_image.compare(INCOMPLETE) == 0) { - return cont->second; - } else { - cont->second->incomplete = false; - } - } - - ct = cont->second; - setContainer(&ct, container); - } - - if (ct == nullptr) { - ct = createContainer(ti); - } else { - if (m_cxt->isK8sEnabled()) { - reupPod(ti, ct); - } - } - - if (ct == nullptr) { - return nullptr; - } - - m_containers[ct->cont.id] = ct; - m_writer->writeContainer(&(ct->cont)); - ct->written = true; - - return ct; + // if (ti->m_container_id.empty()) { + // return nullptr; + // } + + // ContainerObj *ct = nullptr; + // ContainerTable::iterator cont = m_containers.find(ti->m_container_id); + // if (cont != m_containers.end()) { + // if (cont->second->written && !cont->second->incomplete) { + // return cont->second; + // } + + // const sinsp_container_info::ptr_t container = + // m_cxt->getInspector()->m_container_manager.get_container( + // ti->m_container_id); + // if (!container) { + // // m_containers.erase(cont); + // // delete cont->second; + // return cont->second; + // } + + // if (cont->second->written && cont->second->incomplete) { + // SF_DEBUG(m_logger, + // "Container is written and includes name: " << container->m_name); + // if (container->m_name.compare(INCOMPLETE) == 0 || + // container->m_image.compare(INCOMPLETE) == 0) { + // return cont->second; + // } else { + // cont->second->incomplete = false; + // } + // } + + // ct = cont->second; + // // setContainer(&ct, container); + // } + + // if (ct == nullptr) { + // ct = createContainer(ti); + // } else { + // if (m_cxt->isK8sEnabled()) { + // reupPod(ti, ct); + // } + // } + + // if (ct == nullptr) { + // return nullptr; + // } + + // m_containers[ct->cont.id] = ct; + // m_writer->writeContainer(&(ct->cont)); + // ct->written = true; + + // return ct; + return nullptr; } void ContainerContext::reupPod(sinsp_threadinfo *ti, ContainerObj *cont) { - if (!m_cxt->isK8sEnabled()) { - return; - } - - std::string podId = ""; - if (!cont->cont.podId.is_null()) { - podId = cont->cont.podId.get_string(); - } - - if (!podId.empty()) { - auto pod1 = m_k8sCxt->getPod(podId); - if (pod1 != nullptr) { - pod1->refs--; - } - } - - auto pod = m_k8sCxt->getPod(ti); - if (pod != nullptr) { - cont->cont.podId.set_string(pod->pod.id); - pod->refs++; - } else { - cont->cont.podId.set_null(); - } + // if (!m_cxt->isK8sEnabled()) { + // return; + // } + + // std::string podId = ""; + // if (!cont->cont.podId.is_null()) { + // podId = cont->cont.podId.get_string(); + // } + + // if (!podId.empty()) { + // auto pod1 = m_k8sCxt->getPod(podId); + // if (pod1 != nullptr) { + // pod1->refs--; + // } + // } + + // auto pod = m_k8sCxt->getPod(ti); + // if (pod != nullptr) { + // cont->cont.podId.set_string(pod->pod.id); + // pod->refs++; + // } else { + // cont->cont.podId.set_null(); + // } + return; } void ContainerContext::clearContainers() { - for (ContainerTable::iterator it = m_containers.begin(); - it != m_containers.end(); ++it) { - if (it->second->refs == 0) { - if (m_cxt->isK8sEnabled() && !it->second->cont.podId.is_null()) { - m_k8sCxt->derefPod(it->second->cont.podId.get_string()); - } - m_containers.erase(it); - delete it->second; - } else { - it->second->written = false; - } - } + // for (ContainerTable::iterator it = m_containers.begin(); + // it != m_containers.end(); ++it) { + // if (it->second->refs == 0) { + // if (m_cxt->isK8sEnabled() && !it->second->cont.podId.is_null()) { + // m_k8sCxt->derefPod(it->second->cont.podId.get_string()); + // } + // m_containers.erase(it); + // delete it->second; + // } else { + // it->second->written = false; + // } + // } } void ContainerContext::clearAllContainers() { - for (ContainerTable::iterator it = m_containers.begin(); - it != m_containers.end(); ++it) { - delete it->second; - } + // for (ContainerTable::iterator it = m_containers.begin(); + // it != m_containers.end(); ++it) { + // delete it->second; + // } } diff --git a/src/libs/containercontext.h b/src/libs/containercontext.h index 0a904cb0..9795989f 100644 --- a/src/libs/containercontext.h +++ b/src/libs/containercontext.h @@ -39,7 +39,7 @@ class ContainerContext { writer::SysFlowWriter *m_writer; sfk8s::K8sContext *m_k8sCxt; ContainerObj *createContainer(sinsp_threadinfo *ti); - void setContainer(ContainerObj **cont, sinsp_container_info::ptr_t container); + void setContainer(ContainerObj **cont); void reupPod(sinsp_threadinfo *ti, ContainerObj *cont); public: diff --git a/src/libs/filecontext.cpp b/src/libs/filecontext.cpp index 9053cd1e..38902f59 100644 --- a/src/libs/filecontext.cpp +++ b/src/libs/filecontext.cpp @@ -64,8 +64,9 @@ FileObj *FileContext::getFile(sinsp_evt *ev, const std::string &path, sinsp_threadinfo *ti = ev->get_thread_info(); created = true; std::string key; - key.reserve(ti->m_container_id.length() + path.length()); - key += ti->m_container_id; + std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); + key.reserve(container_id.length() + path.length()); + key += container_id; key += path; FileTable::iterator f = m_files.find(key); FileObj *file = nullptr; diff --git a/src/libs/fileeventprocessor.cpp b/src/libs/fileeventprocessor.cpp index 498ae4c7..46cef62a 100644 --- a/src/libs/fileeventprocessor.cpp +++ b/src/libs/fileeventprocessor.cpp @@ -127,8 +127,8 @@ int FileEventProcessor::writeFileEvent(sinsp_evt *ev, OpFlags flag) { if (IS_AT_SC(ev->get_type())) { const sinsp_evt_param *pinfo; pinfo = ev->get_param(1); - assert(pinfo->m_len == sizeof(int64_t)); - const int64_t dirfd = *reinterpret_cast(pinfo->m_val); + assert(pinfo->len() == sizeof(int64_t)); + const int64_t dirfd = *reinterpret_cast(pinfo->data()); fileName = utils::getAbsolutePath(ti, dirfd, fileName); } else { fileName = utils::getAbsolutePath(ti, fileName); diff --git a/src/libs/fileflowprocessor.cpp b/src/libs/fileflowprocessor.cpp index e2ad64ac..abc7e59a 100644 --- a/src/libs/fileflowprocessor.cpp +++ b/src/libs/fileflowprocessor.cpp @@ -244,10 +244,11 @@ int FileFlowProcessor::handleFileFlowEvent(sinsp_evt *ev, OpFlags flag) { return createConsumerRecord(ev, proc, file, flag, fdinfo, fd); } FileFlowObj *ff = nullptr; + std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); std::string flowkey; - flowkey.reserve(ti->m_container_id.length() + fdinfo->m_name.length() + 32); + flowkey.reserve(container_id.length() + fdinfo->m_name.length() + 32); flowkey += fdinfo->m_name; - flowkey += ti->m_container_id; + flowkey += container_id; flowkey.append(utils::itoa(ti->m_tid, 10)); flowkey.append(utils::itoa(fd, 10)); diff --git a/src/libs/k8seventprocessor.cpp b/src/libs/k8seventprocessor.cpp index e8e4a20e..7f5808d2 100644 --- a/src/libs/k8seventprocessor.cpp +++ b/src/libs/k8seventprocessor.cpp @@ -104,7 +104,7 @@ int K8sEventProcessor::handleK8sEvent(sinsp_evt *ev) { int res = 1; const sinsp_evt_param *parinfo = ev->get_param(0); - std::string payload(parinfo->m_val, parinfo->m_len); + std::string payload(parinfo->data(), parinfo->len()); m_k8sEvt.message = payload; m_k8sEvt.ts = ev->get_ts(); diff --git a/src/libs/libsysflow-musl.mri b/src/libs/libsysflow-musl.mri index 6d18f605..004f6fa7 100644 --- a/src/libs/libsysflow-musl.mri +++ b/src/libs/libsysflow-musl.mri @@ -3,6 +3,7 @@ addlib /usr/local/sysflow/lib/libsysflow.a addlib /usr/local/sysflow/modules/lib/falcosecurity/libs.a addlib /usr/local/sysflow/modules/lib/libavrocpp_s.a addlib /usr/local/sysflow/modules/lib/libxxhash.a +addlib /usr/local/sysflow/modules/lib/sha1.a addlib /usr/lib/libboost_iostreams.a addlib /usr/local/lib/libsnappy.a addlib /usr/local/lib/libglog.a diff --git a/src/libs/libsysflow.mri b/src/libs/libsysflow.mri index a24b1d86..e049ac68 100644 --- a/src/libs/libsysflow.mri +++ b/src/libs/libsysflow.mri @@ -3,6 +3,7 @@ addlib /usr/local/sysflow/lib/libsysflow.a addlib /usr/local/sysflow/modules/lib/falcosecurity/libs.a addlib /usr/local/sysflow/modules/lib/libavrocpp_s.a addlib /usr/local/sysflow/modules/lib/libxxhash.a +addlib /usr/local/sysflow/modules/lib/sha1.a addlib /usr/lib64/libboost_iostreams.a addlib /usr/local/lib64/libsnappy.a addlib /usr/local/lib64/libglog.a diff --git a/src/libs/networkflowprocessor.cpp b/src/libs/networkflowprocessor.cpp index 8e5f51c8..9badd6c5 100644 --- a/src/libs/networkflowprocessor.cpp +++ b/src/libs/networkflowprocessor.cpp @@ -213,7 +213,7 @@ int NetworkFlowProcessor::handleNetFlowEvent(sinsp_evt *ev, OpFlags flag) { SF_DEBUG(m_logger, proc->proc.exe << " " << ipv4tuple_to_string( - &(fdinfo->m_sockinfo.m_ipv4info), false) + fdinfo->m_sockinfo.m_ipv4info, false) << " Proto: " << getProtocol(fdinfo->get_l4proto()) << " Server: " << fdinfo->is_role_server() << " Client: " << fdinfo->is_role_client() << " " diff --git a/src/libs/processcontext.cpp b/src/libs/processcontext.cpp index 1d64ccc8..133733d6 100644 --- a/src/libs/processcontext.cpp +++ b/src/libs/processcontext.cpp @@ -65,7 +65,8 @@ ProcessObj *ProcessContext::createProcess(sinsp_threadinfo *ti, sinsp_evt *ev, p->proc.cwd = mainthread->get_cwd(); p->proc.env = mainthread->get_env(); p->proc.tty = mainthread->m_tty; - sinsp_threadinfo *parent = mainthread->get_parent_thread(); + + sinsp_threadinfo *parent = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mainthread); if (parent != nullptr) { OID poid; @@ -124,10 +125,26 @@ ProcessObj *ProcessContext::createProcess(sinsp_threadinfo *ti, sinsp_evt *ev, } i++; } - p->proc.uid = static_cast(mainthread->get_user()->uid); - p->proc.gid = static_cast(mainthread->get_group()->gid); - p->proc.userName = mainthread->get_user()->name; - p->proc.groupName = mainthread->get_group()->name; + + std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); + + p->proc.uid = static_cast(mainthread->m_uid); + p->proc.gid = static_cast(mainthread->m_gid); + + scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user(container_id, p->proc.uid); + if (user_info != nullptr){ + p->proc.userName = user_info->name; + }else{ + p->proc.userName = ""; + } + + scap_groupinfo *group_info = ev->get_inspector()->m_usergroup_manager->get_group(container_id, p->proc.gid); + if (group_info != nullptr){ + p->proc.groupName = group_info->name; + }else{ + p->proc.groupName = ""; + } + ContainerObj *cont = m_containerCxt->getContainer(ti); if (cont != nullptr) { p->proc.containerId.set_string(cont->cont.id); @@ -222,11 +239,15 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, key.hpid = mt->m_pid; created = true; + std::string mt_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mt); + std::string ti_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); + + SF_DEBUG(m_logger, "Get process - PID: " << mt->m_pid << " ts: " << mt->m_clone_ts << " Exepath: " << mt->m_exepath << " Exe: " - << mt->m_exe << " MTCI " << mt->m_container_id - << " TICI: " << ti->m_container_id) + << mt->m_exe << " MTCI " << mt_container_id + << " TICI: " << ti_container_id) ProcessTable::iterator proc = m_procs.find(&key); ProcessObj *process = nullptr; if (proc != m_procs.end()) { @@ -256,7 +277,8 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, processes.push_back(process); sinsp_threadinfo *ct = mt; - mt = mt->get_parent_thread(); + + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); while (mt != nullptr && mt->m_tid != -1) { if (!mt->is_main_thread()) { @@ -267,7 +289,7 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, } if (mt->m_clone_ts == 0 && mt->m_pid == 0) { ct = mt; - mt = mt->get_parent_thread(); + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); continue; } key.createTS = mt->m_clone_ts; @@ -305,7 +327,7 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, parent->children.insert(processes.back()->proc.oid); processes.push_back(parent); ct = mt; - mt = mt->get_parent_thread(); + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); } if (mt == nullptr && ct->m_ptid != -1) { @@ -408,10 +430,24 @@ void ProcessContext::updateProcess(Process *proc, sinsp_evt *ev, i++; } - proc->uid = static_cast(mainthread->get_user()->uid); - proc->gid = static_cast(mainthread->get_group()->gid); - proc->userName = mainthread->get_user()->name; - proc->groupName = mainthread->get_group()->name; + std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); + + proc->uid = static_cast(mainthread->m_uid); + proc->gid = static_cast(mainthread->m_gid); + + scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user(container_id, proc->uid); + if (user_info != nullptr){ + proc->userName = user_info->name; + }else{ + proc->userName = ""; + } + + scap_groupinfo *group_info = ev->get_inspector()->m_usergroup_manager->get_group(container_id, proc->gid); + if (group_info != nullptr){ + proc->groupName = group_info->name; + }else{ + proc->groupName = ""; + } } void ProcessContext::clearProcesses() { diff --git a/src/libs/sysflowcontext.cpp b/src/libs/sysflowcontext.cpp index 0025c2e4..13328d2e 100644 --- a/src/libs/sysflowcontext.cpp +++ b/src/libs/sysflowcontext.cpp @@ -45,13 +45,13 @@ SysFlowContext::SysFlowContext(SysFlowConfig *config) m_inspector->set_filter(config->falcoFilter); } - if (!config->criPath.empty()) { - m_inspector->set_cri_socket_path(config->criPath); - } + // if (!config->criPath.empty()) { + // m_inspector->set_cri_socket_path(config->criPath); + // } - if (config->criTO > 0) { - m_inspector->set_cri_timeout(config->criTO); - } + // if (config->criTO > 0) { + // m_inspector->set_cri_timeout(config->criTO); + // } const char *envP = std::getenv(DRIVER_LOG); if ((envP != nullptr && strcmp(envP, "1") == 0) || diff --git a/src/libs/sysflowexception.h b/src/libs/sysflowexception.h index 287efa4e..fa302d69 100644 --- a/src/libs/sysflowexception.h +++ b/src/libs/sysflowexception.h @@ -22,6 +22,7 @@ #include #include +#include namespace sfexception { diff --git a/src/libs/sysflowprocessor.cpp b/src/libs/sysflowprocessor.cpp index a760497c..f4191c82 100644 --- a/src/libs/sysflowprocessor.cpp +++ b/src/libs/sysflowprocessor.cpp @@ -188,7 +188,10 @@ int SysFlowProcessor::run() { m_processCxt->checkForDeletion(); checkAndRotateFile(); - if (m_cxt->isFilterContainers() && !utils::isInContainer(ev)) { + if (m_cxt->isFilterContainers() && utils::isInContainer(ev)) { + // Suppress further events for this thread + int64_t tid = ev->get_tid(); + m_cxt->getInspector()->suppress_events_tid(tid); continue; } diff --git a/src/libs/utils.cpp b/src/libs/utils.cpp index 82f8d5d1..e5035628 100644 --- a/src/libs/utils.cpp +++ b/src/libs/utils.cpp @@ -22,6 +22,7 @@ #include "logger.h" #include "sysflow/avsc_sysflow5.hh" #include "sysflowcontext.h" +#include "sha1.h" static NFKey s_nfdelkey; static NFKey s_nfemptykey; @@ -31,6 +32,98 @@ static OID s_oidemptykey; CREATE_LOGGER_2("sysflow.utils"); +namespace { + +const size_t CONTAINER_ID_LENGTH = 64; + +/** + * @brief A pattern to match cgroup paths against + */ +struct cgroup_layout { + const char *prefix; + const char *suffix; +}; + +/** + * @brief Aggregated cgroup layout containing all known container runtime patterns + */ +constexpr const cgroup_layout ALL_RUNC_CGROUP_LAYOUTS[] = { + // CRI patterns + {"/crio-", ""}, // non-systemd cri-o + {"/cri-containerd-", ".scope"}, // systemd containerd + {"/crio-", ".scope"}, // systemd cri-o + {":cri-containerd:", ""}, // containerd without "SystemdCgroup = true" + {"/docker-", ".scope"}, // systemd docker in cri-dockerd scenario + // Podman patterns + {"/libpod-", ".scope"}, // podman + {"/libpod-", ".scope/container"}, // podman + {"/libpod-", ""}, // non-systemd podman, e.g. on alpine + {nullptr, nullptr} +}; + +/** + * Check if cgroup ends with . + */ +static bool match_one_container_id(const std::string &cgroup, + const std::string &prefix, + const std::string &suffix) { + // Single pass: find suffix first (from end), then validate prefix position + size_t end_pos = cgroup.rfind(suffix); + + // Isn't this supposed to always be the last character? + if(end_pos == std::string::npos) { + return false; + } + + // Calculate expected start position and validate prefix + if(end_pos < prefix.size()) { + return false; + } + size_t start_pos = cgroup.rfind(prefix, end_pos - 1); + if(start_pos == std::string::npos) { + return false; + } + start_pos += prefix.size(); + + // Fast character validation using lookup instead of find_first_not_of + if(end_pos - start_pos == CONTAINER_ID_LENGTH) { + bool all_valid = true; + for(size_t i = start_pos; i < end_pos && all_valid; ++i) { + unsigned char c = cgroup[i]; + all_valid = (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F'); + } + if(all_valid) { + return true; + } + } + + return false; +} + +static bool match_container_id(const std::string &cgroup, + const cgroup_layout *layout) { + for(size_t i = 0; layout[i].prefix && layout[i].suffix; ++i) { + if(match_one_container_id(cgroup, layout[i].prefix, layout[i].suffix)) { + return true; + } + } + + return false; +} + +static bool matches_runc_cgroups(const sinsp_threadinfo *tinfo, + const cgroup_layout *layout) { + for(const auto &it : tinfo->cgroups()) { + if(match_container_id(it.second, layout)) { + return true; + } + } + + return false; +} + +} // anonymous namespace + void initKeys() { s_nfdelkey.ip1 = 1; s_nfdelkey.ip2 = 1; @@ -48,10 +141,12 @@ void initKeys() { } void utils::generateFOID(const std::string &key, FOID *foid) { - SHA1(reinterpret_cast(key.c_str()), key.size(), - foid->begin()); + SHA1 sha1; + sha1.add(reinterpret_cast(key.c_str()), key.size()); + sha1.getHash(foid->data()); } + NFKey *utils::getNFEmptyKey() { if (!s_keysinit) { initKeys(); @@ -106,7 +201,12 @@ std::string utils::getGroupName(context::SysFlowContext *cxt, bool utils::isInContainer(sinsp_evt *ev) { sinsp_threadinfo *ti = ev->get_thread_info(); - return !ti->m_container_id.empty(); + if (ti == NULL) { + return false; + } + + // Check against all known container runtime patterns + return matches_runc_cgroups(ti, ALL_RUNC_CGROUP_LAYOUTS); } time_t utils::getExportTime(context::SysFlowContext *cxt) { @@ -127,7 +227,7 @@ int64_t utils::getSyscallResult(sinsp_evt *ev) { case PT_FD: case PT_INT64: case PT_INT32: - res = *reinterpret_cast(p->m_val); + res = *reinterpret_cast(p->data()); break; default: SF_DEBUG(m_logger, "Syscall result not of type pid! Type: " @@ -168,7 +268,7 @@ int64_t utils::getIntParam(sinsp_evt *ev, std::string pname) { case PT_FLAGS16: case PT_FLAGS32: { const sinsp_evt_param *p = ev->get_param(i); - return *reinterpret_cast(p->m_val); + return *reinterpret_cast(p->data()); } default: return 0; @@ -251,7 +351,7 @@ std::string utils::getPath(sinsp_evt *ev, const std::string ¶Name) { const sinsp_evt_param *p = ev->get_param(i); if (param->type == PT_FSPATH || param->type == PT_CHARBUF || param->type == PT_FSRELPATH) { - path = std::string(p->m_val, p->m_len); + path = std::string(p->data(), p->len()); SF_DEBUG(m_logger, "getPath: Param '" << name << "'s value is " << path); sanitize_string(path); } @@ -271,8 +371,8 @@ int64_t utils::getFD(sinsp_evt *ev, const std::string ¶Name) { } const sinsp_evt_param *p = ev->get_param(i); if (param->type == PT_FD) { - assert(p->m_len == sizeof(int64_t)); - fd = (*reinterpret_cast(p->m_val)); + assert(p->len() == sizeof(int64_t)); + fd = (*reinterpret_cast(p->data())); } break; } @@ -343,4 +443,4 @@ std::string utils::getAbsolutePath(sinsp_threadinfo *ti, p = utils::getCanonicalPath(p); } return p.string(); -} +} \ No newline at end of file diff --git a/src/libs/utils.h b/src/libs/utils.h index ec0f2e17..d2bb9aa9 100644 --- a/src/libs/utils.h +++ b/src/libs/utils.h @@ -28,7 +28,6 @@ #include #include #include -#include #include #include #include @@ -123,5 +122,6 @@ inline char *itoa(int val, int base) { } return &buf[i + 1]; } + } // namespace utils #endif From 5d99ce3149b996e7b692feb4cffa5cfb019b4685 Mon Sep 17 00:00:00 2001 From: Daniele Carollo Date: Thu, 16 Apr 2026 13:21:11 +0000 Subject: [PATCH 2/5] fix unneccesary changes Signed-off-by: Daniele Carollo --- Dockerfile.alpine | 1 + src/libs/processcontext.cpp | 7 +-- src/libs/sysflowexception.h | 1 - src/libs/utils.cpp | 118 ++++++++++++++++++------------------ src/libs/utils.h | 1 - 5 files changed, 63 insertions(+), 65 deletions(-) diff --git a/Dockerfile.alpine b/Dockerfile.alpine index 995b8199..165c8080 100644 --- a/Dockerfile.alpine +++ b/Dockerfile.alpine @@ -77,3 +77,4 @@ COPY ./docker-entry-ubi.sh /usr/local/sysflow/modules/bin/ RUN cd /build/modules && \ make INSTALL_PATH=${INSTALL_PATH} ARCH=${ARCH} MUSL=1 MAKE_JOBS=${MAKE_JOBS} install && \ make clean && rm -rf /build/modules + diff --git a/src/libs/processcontext.cpp b/src/libs/processcontext.cpp index 133733d6..563a5ad9 100644 --- a/src/libs/processcontext.cpp +++ b/src/libs/processcontext.cpp @@ -66,7 +66,7 @@ ProcessObj *ProcessContext::createProcess(sinsp_threadinfo *ti, sinsp_evt *ev, p->proc.env = mainthread->get_env(); p->proc.tty = mainthread->m_tty; - sinsp_threadinfo *parent = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mainthread); + sinsp_threadinfo *parent = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mainthread); if (parent != nullptr) { OID poid; @@ -242,7 +242,6 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, std::string mt_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mt); std::string ti_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); - SF_DEBUG(m_logger, "Get process - PID: " << mt->m_pid << " ts: " << mt->m_clone_ts << " Exepath: " << mt->m_exepath << " Exe: " @@ -278,7 +277,7 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, sinsp_threadinfo *ct = mt; - mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); while (mt != nullptr && mt->m_tid != -1) { if (!mt->is_main_thread()) { @@ -327,7 +326,7 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, parent->children.insert(processes.back()->proc.oid); processes.push_back(parent); ct = mt; - mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); } if (mt == nullptr && ct->m_ptid != -1) { diff --git a/src/libs/sysflowexception.h b/src/libs/sysflowexception.h index fa302d69..287efa4e 100644 --- a/src/libs/sysflowexception.h +++ b/src/libs/sysflowexception.h @@ -22,7 +22,6 @@ #include #include -#include namespace sfexception { diff --git a/src/libs/utils.cpp b/src/libs/utils.cpp index e5035628..8c22d60a 100644 --- a/src/libs/utils.cpp +++ b/src/libs/utils.cpp @@ -40,25 +40,25 @@ const size_t CONTAINER_ID_LENGTH = 64; * @brief A pattern to match cgroup paths against */ struct cgroup_layout { - const char *prefix; - const char *suffix; + const char *prefix; + const char *suffix; }; /** * @brief Aggregated cgroup layout containing all known container runtime patterns */ constexpr const cgroup_layout ALL_RUNC_CGROUP_LAYOUTS[] = { - // CRI patterns - {"/crio-", ""}, // non-systemd cri-o - {"/cri-containerd-", ".scope"}, // systemd containerd - {"/crio-", ".scope"}, // systemd cri-o - {":cri-containerd:", ""}, // containerd without "SystemdCgroup = true" - {"/docker-", ".scope"}, // systemd docker in cri-dockerd scenario - // Podman patterns - {"/libpod-", ".scope"}, // podman - {"/libpod-", ".scope/container"}, // podman - {"/libpod-", ""}, // non-systemd podman, e.g. on alpine - {nullptr, nullptr} + // CRI patterns + {"/crio-", ""}, // non-systemd cri-o + {"/cri-containerd-", ".scope"}, // systemd containerd + {"/crio-", ".scope"}, // systemd cri-o + {":cri-containerd:", ""}, // containerd without "SystemdCgroup = true" + {"/docker-", ".scope"}, // systemd docker in cri-dockerd scenario + // Podman patterns + {"/libpod-", ".scope"}, // podman + {"/libpod-", ".scope/container"}, // podman + {"/libpod-", ""}, // non-systemd podman, e.g. on alpine + {nullptr, nullptr} }; /** @@ -67,59 +67,59 @@ constexpr const cgroup_layout ALL_RUNC_CGROUP_LAYOUTS[] = { static bool match_one_container_id(const std::string &cgroup, const std::string &prefix, const std::string &suffix) { - // Single pass: find suffix first (from end), then validate prefix position - size_t end_pos = cgroup.rfind(suffix); - - // Isn't this supposed to always be the last character? - if(end_pos == std::string::npos) { - return false; - } - - // Calculate expected start position and validate prefix - if(end_pos < prefix.size()) { - return false; - } - size_t start_pos = cgroup.rfind(prefix, end_pos - 1); - if(start_pos == std::string::npos) { - return false; - } - start_pos += prefix.size(); - - // Fast character validation using lookup instead of find_first_not_of - if(end_pos - start_pos == CONTAINER_ID_LENGTH) { - bool all_valid = true; - for(size_t i = start_pos; i < end_pos && all_valid; ++i) { - unsigned char c = cgroup[i]; - all_valid = (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F'); - } - if(all_valid) { - return true; - } - } - - return false; + // Single pass: find suffix first (from end), then validate prefix position + size_t end_pos = cgroup.rfind(suffix); + + // Isn't this supposed to always be the last character? + if(end_pos == std::string::npos) { + return false; + } + + // Calculate expected start position and validate prefix + if(end_pos < prefix.size()) { + return false; + } + size_t start_pos = cgroup.rfind(prefix, end_pos - 1); + if(start_pos == std::string::npos) { + return false; + } + start_pos += prefix.size(); + + // Fast character validation using lookup instead of find_first_not_of + if(end_pos - start_pos == CONTAINER_ID_LENGTH) { + bool all_valid = true; + for(size_t i = start_pos; i < end_pos && all_valid; ++i) { + unsigned char c = cgroup[i]; + all_valid = (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F'); + } + if(all_valid) { + return true; + } + } + + return false; } static bool match_container_id(const std::string &cgroup, const cgroup_layout *layout) { - for(size_t i = 0; layout[i].prefix && layout[i].suffix; ++i) { - if(match_one_container_id(cgroup, layout[i].prefix, layout[i].suffix)) { - return true; - } - } + for(size_t i = 0; layout[i].prefix && layout[i].suffix; ++i) { + if(match_one_container_id(cgroup, layout[i].prefix, layout[i].suffix)) { + return true; + } + } - return false; + return false; } static bool matches_runc_cgroups(const sinsp_threadinfo *tinfo, const cgroup_layout *layout) { - for(const auto &it : tinfo->cgroups()) { - if(match_container_id(it.second, layout)) { - return true; - } - } + for(const auto &it : tinfo->cgroups()) { + if(match_container_id(it.second, layout)) { + return true; + } + } - return false; + return false; } } // anonymous namespace @@ -141,9 +141,9 @@ void initKeys() { } void utils::generateFOID(const std::string &key, FOID *foid) { - SHA1 sha1; - sha1.add(reinterpret_cast(key.c_str()), key.size()); - sha1.getHash(foid->data()); + SHA1 sha1; + sha1.add(reinterpret_cast(key.c_str()), key.size()); + sha1.getHash(foid->data()); } diff --git a/src/libs/utils.h b/src/libs/utils.h index d2bb9aa9..58749662 100644 --- a/src/libs/utils.h +++ b/src/libs/utils.h @@ -122,6 +122,5 @@ inline char *itoa(int val, int base) { } return &buf[i + 1]; } - } // namespace utils #endif From d755f04257d213ac6d0c028f7a425a70683406c3 Mon Sep 17 00:00:00 2001 From: Frederico Araujo Date: Wed, 29 Jul 2026 23:34:09 -0400 Subject: [PATCH 3/5] style: apply clang-format to src/libs Signed-off-by: Frederico Araujo --- src/libs/containercontext.cpp | 6 ++-- src/libs/filecontext.cpp | 3 +- src/libs/fileflowprocessor.cpp | 3 +- src/libs/networkflowprocessor.cpp | 19 +++++------ src/libs/processcontext.cpp | 57 ++++++++++++++++++------------- src/libs/utils.cpp | 56 +++++++++++++++--------------- 6 files changed, 79 insertions(+), 65 deletions(-) diff --git a/src/libs/containercontext.cpp b/src/libs/containercontext.cpp index ecc0a6db..488514d7 100644 --- a/src/libs/containercontext.cpp +++ b/src/libs/containercontext.cpp @@ -47,7 +47,8 @@ ContainerContext::~ContainerContext() { clearAllContainers(); } ContainerObj *ContainerContext::createContainer(sinsp_threadinfo *ti) { - // std::string container_id = m_cxt->getInspector()->m_plugin_tables.get_container_id(*ti); + // std::string container_id = + // m_cxt->getInspector()->m_plugin_tables.get_container_id(*ti); // if (container_id.empty()) { // return nullptr; @@ -120,7 +121,8 @@ ContainerObj *ContainerContext::getContainer(sinsp_threadinfo *ti) { // if (cont->second->written && cont->second->incomplete) { // SF_DEBUG(m_logger, - // "Container is written and includes name: " << container->m_name); + // "Container is written and includes name: " << + // container->m_name); // if (container->m_name.compare(INCOMPLETE) == 0 || // container->m_image.compare(INCOMPLETE) == 0) { // return cont->second; diff --git a/src/libs/filecontext.cpp b/src/libs/filecontext.cpp index 38902f59..1397ebcc 100644 --- a/src/libs/filecontext.cpp +++ b/src/libs/filecontext.cpp @@ -64,7 +64,8 @@ FileObj *FileContext::getFile(sinsp_evt *ev, const std::string &path, sinsp_threadinfo *ti = ev->get_thread_info(); created = true; std::string key; - std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); + std::string container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*ti); key.reserve(container_id.length() + path.length()); key += container_id; key += path; diff --git a/src/libs/fileflowprocessor.cpp b/src/libs/fileflowprocessor.cpp index abc7e59a..192c1c02 100644 --- a/src/libs/fileflowprocessor.cpp +++ b/src/libs/fileflowprocessor.cpp @@ -244,7 +244,8 @@ int FileFlowProcessor::handleFileFlowEvent(sinsp_evt *ev, OpFlags flag) { return createConsumerRecord(ev, proc, file, flag, fdinfo, fd); } FileFlowObj *ff = nullptr; - std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); + std::string container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*ti); std::string flowkey; flowkey.reserve(container_id.length() + fdinfo->m_name.length() + 32); flowkey += fdinfo->m_name; diff --git a/src/libs/networkflowprocessor.cpp b/src/libs/networkflowprocessor.cpp index 9badd6c5..1764e9c8 100644 --- a/src/libs/networkflowprocessor.cpp +++ b/src/libs/networkflowprocessor.cpp @@ -210,16 +210,15 @@ int NetworkFlowProcessor::handleNetFlowEvent(sinsp_evt *ev, OpFlags flag) { nf = nfi->second; } - SF_DEBUG(m_logger, proc->proc.exe - << " " - << ipv4tuple_to_string( - fdinfo->m_sockinfo.m_ipv4info, false) - << " Proto: " << getProtocol(fdinfo->get_l4proto()) - << " Server: " << fdinfo->is_role_server() - << " Client: " << fdinfo->is_role_client() << " " - << ev->get_name() << " " << proc->proc.oid.hpid << " " - << proc->proc.oid.createTS << " " << ti->m_tid << " " - << ev->get_fd_num()); + SF_DEBUG( + m_logger, proc->proc.exe + << " " + << ipv4tuple_to_string(fdinfo->m_sockinfo.m_ipv4info, false) + << " Proto: " << getProtocol(fdinfo->get_l4proto()) + << " Server: " << fdinfo->is_role_server() << " Client: " + << fdinfo->is_role_client() << " " << ev->get_name() << " " + << proc->proc.oid.hpid << " " << proc->proc.oid.createTS + << " " << ti->m_tid << " " << ev->get_fd_num()); if (nf == nullptr) { SF_DEBUG(m_logger, "Processing as new flow!"); diff --git a/src/libs/processcontext.cpp b/src/libs/processcontext.cpp index 563a5ad9..bc82b568 100644 --- a/src/libs/processcontext.cpp +++ b/src/libs/processcontext.cpp @@ -66,7 +66,8 @@ ProcessObj *ProcessContext::createProcess(sinsp_threadinfo *ti, sinsp_evt *ev, p->proc.env = mainthread->get_env(); p->proc.tty = mainthread->m_tty; - sinsp_threadinfo *parent = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mainthread); + sinsp_threadinfo *parent = + ev->get_inspector()->m_thread_manager->get_ancestor_process(*mainthread); if (parent != nullptr) { OID poid; @@ -126,22 +127,26 @@ ProcessObj *ProcessContext::createProcess(sinsp_threadinfo *ti, sinsp_evt *ev, i++; } - std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); + std::string container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); p->proc.uid = static_cast(mainthread->m_uid); p->proc.gid = static_cast(mainthread->m_gid); - scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user(container_id, p->proc.uid); - if (user_info != nullptr){ + scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user( + container_id, p->proc.uid); + if (user_info != nullptr) { p->proc.userName = user_info->name; - }else{ + } else { p->proc.userName = ""; } - scap_groupinfo *group_info = ev->get_inspector()->m_usergroup_manager->get_group(container_id, p->proc.gid); - if (group_info != nullptr){ + scap_groupinfo *group_info = + ev->get_inspector()->m_usergroup_manager->get_group(container_id, + p->proc.gid); + if (group_info != nullptr) { p->proc.groupName = group_info->name; - }else{ + } else { p->proc.groupName = ""; } @@ -239,14 +244,16 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, key.hpid = mt->m_pid; created = true; - std::string mt_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mt); - std::string ti_container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*ti); + std::string mt_container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*mt); + std::string ti_container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*ti); - SF_DEBUG(m_logger, - "Get process - PID: " << mt->m_pid << " ts: " << mt->m_clone_ts - << " Exepath: " << mt->m_exepath << " Exe: " - << mt->m_exe << " MTCI " << mt_container_id - << " TICI: " << ti_container_id) + SF_DEBUG(m_logger, "Get process - PID: " + << mt->m_pid << " ts: " << mt->m_clone_ts + << " Exepath: " << mt->m_exepath + << " Exe: " << mt->m_exe << " MTCI " << mt_container_id + << " TICI: " << ti_container_id) ProcessTable::iterator proc = m_procs.find(&key); ProcessObj *process = nullptr; if (proc != m_procs.end()) { @@ -288,7 +295,7 @@ ProcessObj *ProcessContext::getProcess(sinsp_evt *ev, SFObjectState state, } if (mt->m_clone_ts == 0 && mt->m_pid == 0) { ct = mt; - mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); + mt = ev->get_inspector()->m_thread_manager->get_ancestor_process(*mt); continue; } key.createTS = mt->m_clone_ts; @@ -429,22 +436,26 @@ void ProcessContext::updateProcess(Process *proc, sinsp_evt *ev, i++; } - std::string container_id = ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); + std::string container_id = + ev->get_inspector()->m_plugin_tables.get_container_id(*mainthread); proc->uid = static_cast(mainthread->m_uid); proc->gid = static_cast(mainthread->m_gid); - scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user(container_id, proc->uid); - if (user_info != nullptr){ + scap_userinfo *user_info = ev->get_inspector()->m_usergroup_manager->get_user( + container_id, proc->uid); + if (user_info != nullptr) { proc->userName = user_info->name; - }else{ + } else { proc->userName = ""; } - scap_groupinfo *group_info = ev->get_inspector()->m_usergroup_manager->get_group(container_id, proc->gid); - if (group_info != nullptr){ + scap_groupinfo *group_info = + ev->get_inspector()->m_usergroup_manager->get_group(container_id, + proc->gid); + if (group_info != nullptr) { proc->groupName = group_info->name; - }else{ + } else { proc->groupName = ""; } } diff --git a/src/libs/utils.cpp b/src/libs/utils.cpp index 8c22d60a..76a934a0 100644 --- a/src/libs/utils.cpp +++ b/src/libs/utils.cpp @@ -20,9 +20,9 @@ #include "utils.h" #include "datatypes.h" #include "logger.h" +#include "sha1.h" #include "sysflow/avsc_sysflow5.hh" #include "sysflowcontext.h" -#include "sha1.h" static NFKey s_nfdelkey; static NFKey s_nfemptykey; @@ -45,21 +45,21 @@ struct cgroup_layout { }; /** - * @brief Aggregated cgroup layout containing all known container runtime patterns + * @brief Aggregated cgroup layout containing all known container runtime + * patterns */ constexpr const cgroup_layout ALL_RUNC_CGROUP_LAYOUTS[] = { - // CRI patterns - {"/crio-", ""}, // non-systemd cri-o - {"/cri-containerd-", ".scope"}, // systemd containerd - {"/crio-", ".scope"}, // systemd cri-o - {":cri-containerd:", ""}, // containerd without "SystemdCgroup = true" - {"/docker-", ".scope"}, // systemd docker in cri-dockerd scenario - // Podman patterns - {"/libpod-", ".scope"}, // podman - {"/libpod-", ".scope/container"}, // podman - {"/libpod-", ""}, // non-systemd podman, e.g. on alpine - {nullptr, nullptr} -}; + // CRI patterns + {"/crio-", ""}, // non-systemd cri-o + {"/cri-containerd-", ".scope"}, // systemd containerd + {"/crio-", ".scope"}, // systemd cri-o + {":cri-containerd:", ""}, // containerd without "SystemdCgroup = true" + {"/docker-", ".scope"}, // systemd docker in cri-dockerd scenario + // Podman patterns + {"/libpod-", ".scope"}, // podman + {"/libpod-", ".scope/container"}, // podman + {"/libpod-", ""}, // non-systemd podman, e.g. on alpine + {nullptr, nullptr}}; /** * Check if cgroup ends with . @@ -71,28 +71,29 @@ static bool match_one_container_id(const std::string &cgroup, size_t end_pos = cgroup.rfind(suffix); // Isn't this supposed to always be the last character? - if(end_pos == std::string::npos) { + if (end_pos == std::string::npos) { return false; } // Calculate expected start position and validate prefix - if(end_pos < prefix.size()) { + if (end_pos < prefix.size()) { return false; } size_t start_pos = cgroup.rfind(prefix, end_pos - 1); - if(start_pos == std::string::npos) { + if (start_pos == std::string::npos) { return false; } start_pos += prefix.size(); // Fast character validation using lookup instead of find_first_not_of - if(end_pos - start_pos == CONTAINER_ID_LENGTH) { + if (end_pos - start_pos == CONTAINER_ID_LENGTH) { bool all_valid = true; - for(size_t i = start_pos; i < end_pos && all_valid; ++i) { + for (size_t i = start_pos; i < end_pos && all_valid; ++i) { unsigned char c = cgroup[i]; - all_valid = (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F'); + all_valid = (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || + (c >= 'A' && c <= 'F'); } - if(all_valid) { + if (all_valid) { return true; } } @@ -102,8 +103,8 @@ static bool match_one_container_id(const std::string &cgroup, static bool match_container_id(const std::string &cgroup, const cgroup_layout *layout) { - for(size_t i = 0; layout[i].prefix && layout[i].suffix; ++i) { - if(match_one_container_id(cgroup, layout[i].prefix, layout[i].suffix)) { + for (size_t i = 0; layout[i].prefix && layout[i].suffix; ++i) { + if (match_one_container_id(cgroup, layout[i].prefix, layout[i].suffix)) { return true; } } @@ -113,8 +114,8 @@ static bool match_container_id(const std::string &cgroup, static bool matches_runc_cgroups(const sinsp_threadinfo *tinfo, const cgroup_layout *layout) { - for(const auto &it : tinfo->cgroups()) { - if(match_container_id(it.second, layout)) { + for (const auto &it : tinfo->cgroups()) { + if (match_container_id(it.second, layout)) { return true; } } @@ -122,7 +123,7 @@ static bool matches_runc_cgroups(const sinsp_threadinfo *tinfo, return false; } -} // anonymous namespace +} // anonymous namespace void initKeys() { s_nfdelkey.ip1 = 1; @@ -142,11 +143,10 @@ void initKeys() { void utils::generateFOID(const std::string &key, FOID *foid) { SHA1 sha1; - sha1.add(reinterpret_cast(key.c_str()), key.size()); + sha1.add(reinterpret_cast(key.c_str()), key.size()); sha1.getHash(foid->data()); } - NFKey *utils::getNFEmptyKey() { if (!s_keysinit) { initKeys(); From f08e5f342ec1276ff19f620c623f117676997b0c Mon Sep 17 00:00:00 2001 From: Frederico Araujo Date: Thu, 30 Jul 2026 00:08:16 -0400 Subject: [PATCH 4/5] fix: drop protobuf and gvisor engine removed in falco-libs 0.23.2 Signed-off-by: Frederico Araujo --- modules/Makefile | 3 --- modules/falco-libs.x86_64.mri | 1 - src/collector/Makefile | 2 +- 3 files changed, 1 insertion(+), 5 deletions(-) diff --git a/modules/Makefile b/modules/Makefile index ad533f86..2c17eef1 100644 --- a/modules/Makefile +++ b/modules/Makefile @@ -116,10 +116,7 @@ falcolibs/package: cp -r tbb-prefix/src/tbb/include/tbb include/ && \ cp -r tbb-prefix/src/tbb/include/oneapi include/ && \ cp uthash-prefix/src/uthash/src/*.h include/ && \ - cp -r protobuf-prefix/src/protobuf/target/include/google include/ && \ cp libbpf-prefix/src/libbpf-build/build/*.a lib/ && \ - cp protobuf-prefix/src/protobuf/target/lib/libprotobuf.a lib && \ - cp protobuf-prefix/src/protobuf/target/lib/libprotoc.a lib && \ cp tbb-prefix/src/tbb/lib_release/libtbb.a lib/ && \ cp jsoncpp-prefix/src/lib/libjsoncpp.a lib/ && \ cp -r jsoncpp-prefix/src/include/json include/ && \ diff --git a/modules/falco-libs.x86_64.mri b/modules/falco-libs.x86_64.mri index ed4dfb86..e58ac575 100644 --- a/modules/falco-libs.x86_64.mri +++ b/modules/falco-libs.x86_64.mri @@ -2,7 +2,6 @@ create libs.a addlib libdriver_event_schema.a addlib libscap.a addlib libscap_engine_bpf.a -addlib libscap_engine_gvisor.a addlib libscap_engine_kmod.a addlib libscap_engine_nodriver.a addlib libscap_engine_noop.a diff --git a/src/collector/Makefile b/src/collector/Makefile index 295db877..8830081a 100644 --- a/src/collector/Makefile +++ b/src/collector/Makefile @@ -55,7 +55,7 @@ MUSL ?= 0 # Compiler options CXX = g++ -LIBS = ../libs/libsysflow_with_deps.a -lstdc++ -lz -lpthread -lm -ldl -lre2 -lprotobuf -lstdc++fs -lelf +LIBS = ../libs/libsysflow_with_deps.a -lstdc++ -lz -lpthread -lm -ldl -lre2 -lstdc++fs -lelf MUSLFLAGS = -Os LDFLAGS = $(LIBS) -L$(FALCOLIBPREFIX)/ -L$(AVRLIBPREFIX)/ -L/usr/lib/ CFLAGS = -std=c++17 -Wall -I.. -I../libs/ -I/usr/local/include/ -I/usr/include/ \ From 595c726d72d20634dc81f88bd330803a696823a3 Mon Sep 17 00:00:00 2001 From: Frederico Araujo Date: Thu, 30 Jul 2026 01:02:53 -0400 Subject: [PATCH 5/5] Revert "fix: drop protobuf and gvisor engine removed in falco-libs 0.23.2" This reverts commit f08e5f342ec1276ff19f620c623f117676997b0c. Signed-off-by: Frederico Araujo --- modules/Makefile | 3 +++ modules/falco-libs.x86_64.mri | 1 + src/collector/Makefile | 2 +- 3 files changed, 5 insertions(+), 1 deletion(-) diff --git a/modules/Makefile b/modules/Makefile index 2c17eef1..ad533f86 100644 --- a/modules/Makefile +++ b/modules/Makefile @@ -116,7 +116,10 @@ falcolibs/package: cp -r tbb-prefix/src/tbb/include/tbb include/ && \ cp -r tbb-prefix/src/tbb/include/oneapi include/ && \ cp uthash-prefix/src/uthash/src/*.h include/ && \ + cp -r protobuf-prefix/src/protobuf/target/include/google include/ && \ cp libbpf-prefix/src/libbpf-build/build/*.a lib/ && \ + cp protobuf-prefix/src/protobuf/target/lib/libprotobuf.a lib && \ + cp protobuf-prefix/src/protobuf/target/lib/libprotoc.a lib && \ cp tbb-prefix/src/tbb/lib_release/libtbb.a lib/ && \ cp jsoncpp-prefix/src/lib/libjsoncpp.a lib/ && \ cp -r jsoncpp-prefix/src/include/json include/ && \ diff --git a/modules/falco-libs.x86_64.mri b/modules/falco-libs.x86_64.mri index e58ac575..ed4dfb86 100644 --- a/modules/falco-libs.x86_64.mri +++ b/modules/falco-libs.x86_64.mri @@ -2,6 +2,7 @@ create libs.a addlib libdriver_event_schema.a addlib libscap.a addlib libscap_engine_bpf.a +addlib libscap_engine_gvisor.a addlib libscap_engine_kmod.a addlib libscap_engine_nodriver.a addlib libscap_engine_noop.a diff --git a/src/collector/Makefile b/src/collector/Makefile index 8830081a..295db877 100644 --- a/src/collector/Makefile +++ b/src/collector/Makefile @@ -55,7 +55,7 @@ MUSL ?= 0 # Compiler options CXX = g++ -LIBS = ../libs/libsysflow_with_deps.a -lstdc++ -lz -lpthread -lm -ldl -lre2 -lstdc++fs -lelf +LIBS = ../libs/libsysflow_with_deps.a -lstdc++ -lz -lpthread -lm -ldl -lre2 -lprotobuf -lstdc++fs -lelf MUSLFLAGS = -Os LDFLAGS = $(LIBS) -L$(FALCOLIBPREFIX)/ -L$(AVRLIBPREFIX)/ -L/usr/lib/ CFLAGS = -std=c++17 -Wall -I.. -I../libs/ -I/usr/local/include/ -I/usr/include/ \