Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions .agents/skills/cws-btfhub-sync/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
---
name: cws-btfhub-sync
description: Sync CWS BTFHub constants after adding a new constantfetch offset, so pre-BTF kernels can resolve it. Use when KMT secagent jobs log "failed to fetch constant for <name>".
allowed-tools: Read, Grep, Bash, AskUserQuestion
model: sonnet
Comment on lines +1 to +5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Add the missing skill contract details

Scores: Description 20/25, Writing philosophy 18/25, Structure/progressive disclosure 23/25, Output/examples 12/25, total 73/100; overall recommendation: Approve with suggestions. Top improvements: declare an owning team in the skill metadata/body, since every AI artifact needs an owner; add prerequisites and an explicit success checklist/output shape, such as authenticated gh, current branch pushed, generated PR found, constants file changed, and source PR closed; make the wait example actually background-safe or include how to capture the run id, because the current copied command still runs a foreground polling loop despite warning against foreground waits.

Useful? React with 👍 / 👎.

---

# Syncing CWS BTFHub constants

A new `appendOffsetofRequest` in `probe_ebpf.go` resolves via BTF on modern kernels, but
pre-BTF kernels read the offset from the checked-in, arch-split constants:

- `pkg/security/probe/constantfetch/constants_amd64.json`
- `pkg/security/probe/constantfetch/constants_arm64.json`

These predate your change and so lack the new entry. Regenerating them is the fix.

## Run it

```bash
gh workflow run cws-btfhub-sync.yml --ref main -f base_branch=<your-feature-branch>
```

**The trap:** `--ref` selects the workflow *definition* — keep it `main`. `base_branch` is the
ref the generate and combine jobs check out, **and** the base of the PR it opens. Leave
`base_branch` at its `main` default and the generator never sees your new offset requests: the
sync yields an empty diff and it looks like btfhub simply lacks the offsets.

Before running, confirm the failing distros are covered by the `cone` matrix in
`.github/workflows/cws-btfhub-sync.yml`.

## Wait for it

It is a ~15-job matrix and takes tens of minutes. Poll it from a **background** shell so the
wait costs nothing and you get re-invoked on exit:

```bash
until [ "$(gh run view <run-id> --json status -q .status)" = completed ]; do sleep 60; done
gh run view <run-id> --json conclusion -q .conclusion
```

Do not run `gh run watch` in the foreground (it outlives the tool timeout) and do not chain
short `sleep`s in the main loop. When the notification arrives, carry straight on to *Land it*
in the same turn — this is one task, not a hand-off.

## Land it

On success the workflow opens a PR titled `CWS: sync BTFHub constants` from a
`cws/constants-sync-*` branch, targeting your branch:

```bash
gh pr list --search "CWS: sync BTFHub constants" --state open --json number,headRefName,url
```

Cherry-pick its commit onto your branch, push, then **close** the PR. Confirm the picked
commit touches `btfhub/constants.json` and that your new offset names appear in the diff.
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@
/.agents/skills/locate-config-setting/SKILL.md @DataDog/fleet-automation
/.agents/skills/create-runtime-setting/SKILL.md @DataDog/agent-runtimes @DataDog/fleet-automation
/.agents/skills/create-runtime-setting/SKILL.md @DataDog/agent-runtimes @DataDog/fleet-automation
/.agents/skills/cws-btfhub-sync/ @DataDog/agent-security
/.agents/skills/cws-iouring-coverage/ @DataDog/agent-security
/.agents/skills/explain-lading-config @DataDog/single-machine-performance
/.agents/skills/injector-dev @Datadog/container-platform
Expand Down
Loading