[8.19](backport #45950) Fix file_integrity kprobe filters, use BTF values where possible#46065
[8.19](backport #45950) Fix file_integrity kprobe filters, use BTF values where possible#46065mergify[bot] wants to merge 6 commits into8.19from
Conversation
) * fix FIM kprobe filters * linter * add extra checks to BTF logic, clarify docs * clean up loop (cherry picked from commit 9773649) # Conflicts: # NOTICE.txt # go.mod # go.sum
|
Cherry-pick of 9773649 has failed: To fix up this pull request, you can check it out locally. See documentation: https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/reviewing-changes-in-pull-requests/checking-out-pull-requests-locally |
|
Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform) |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
7 similar comments
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
@fearful-symmetry could you please resolve the conflicts? |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
4 similar comments
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request is now in conflicts. Could you fix it? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
@nfritts @fearful-symmetry could you please make sure this is reviewed / fixed? |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
1 similar comment
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
@nfritts / @fearful-symmetry FF is tomorrow so if we want this in the next 8.19 release, we should take care of merging that one soon. |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
9 similar comments
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
|
Sorry about that, looks like it got lost during the holidays |
|
This pull request has not been merged yet. Could you please review and merge it @fearful-symmetry? 🙏 |
Proposed commit message
See #45897
This fixes a bug in recent kernels where a change to the
fsnotify_data_typeenum broke the kprobe filters, which were hard-coding the enum values. This changes the kprobe setup so we use the BTF values for thefsnotify_data_typeenum where possible, and only fall back to hard-coding the data type values on older kernels.Checklist
CHANGELOG.next.asciidocorCHANGELOG-developer.next.asciidoc.Related issues
fsnotify_data_type#45897This is an automatic backport of pull request #45950 done by [Mergify](https://mergify.com).