-
Notifications
You must be signed in to change notification settings - Fork 1.2k
/
model.go
640 lines (528 loc) · 23 KB
/
model.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
// Unless explicitly stated otherwise all files in this repository are licensed
// under the Apache License Version 2.0.
// This product includes software developed at Datadog (https://www.datadoghq.com/).
// Copyright 2016-present Datadog, Inc.
//go:generate go run github.com/DataDog/datadog-agent/pkg/security/secl/compiler/generators/accessors -mock -output accessors.go
//go:generate go run github.com/DataDog/datadog-agent/pkg/security/secl/compiler/generators/accessors -tags linux -output ../../probe/accessors.go
//go:generate go run github.com/DataDog/datadog-agent/pkg/security/secl/compiler/generators/accessors -tags linux -doc -output ../../../../docs/cloud-workload-security/secl.json
package model
import (
"fmt"
"path"
"path/filepath"
"regexp"
"strings"
"syscall"
"time"
"unsafe"
"github.com/pkg/errors"
"github.com/DataDog/datadog-agent/pkg/security/secl/compiler/eval"
)
// Model describes the data model for the runtime security agent events
type Model struct{}
// NewEvent returns a new Event
func (m *Model) NewEvent() eval.Event {
return &Event{}
}
// ValidateField validates the value of a field
func (m *Model) ValidateField(field eval.Field, fieldValue eval.FieldValue) error {
// check that all path are absolute
if strings.HasSuffix(field, "path") {
// do not support regular expression on path, currently unable to support discarder for regex value
if fieldValue.Type == eval.RegexpValueType {
return fmt.Errorf("regexp not supported on path `%s`", field)
}
if value, ok := fieldValue.Value.(string); ok {
errAbs := fmt.Errorf("invalid path `%s`, all the path have to be absolute", value)
errDepth := fmt.Errorf("invalid path `%s`, path depths have to be shorter than %d", value, MaxPathDepth)
errSegment := fmt.Errorf("invalid path `%s`, each segment of a path must be shorter than %d", value, MaxSegmentLength)
if value != path.Clean(value) {
return errAbs
}
if value == "*" {
return errAbs
}
if !filepath.IsAbs(value) && len(value) > 0 && value[0] != '*' {
return errAbs
}
if matched, err := regexp.Match(`^~`, []byte(value)); err != nil || matched {
return errAbs
}
// check resolution limitations
segments := strings.Split(value, "/")
if len(segments) > MaxPathDepth {
return errDepth
}
for _, segment := range segments {
if segment == ".." {
return errAbs
}
if len(segment) > MaxSegmentLength {
return errSegment
}
}
}
}
switch field {
case "event.retval":
if value := fieldValue.Value; value != -int(syscall.EPERM) && value != -int(syscall.EACCES) {
return errors.New("return value can only be tested against EPERM or EACCES")
}
}
return nil
}
// ChmodEvent represents a chmod event
type ChmodEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Mode uint32 `field:"file.destination.mode" field:"file.destination.rights"` // New mode/rights of the chmod-ed file
}
// ChownEvent represents a chown event
type ChownEvent struct {
SyscallEvent
File FileEvent `field:"file"`
UID uint32 `field:"file.destination.uid"` // New UID of the chown-ed file's owner
User string `field:"file.destination.user,ResolveChownUID"` // New user of the chown-ed file's owner
GID uint32 `field:"file.destination.gid"` // New GID of the chown-ed file's owner
Group string `field:"file.destination.group,ResolveChownGID"` // New group of the chown-ed file's owner
}
// ContainerContext holds the container context of an event
type ContainerContext struct {
ID string `field:"id,ResolveContainerID"` // ID of the container
Tags []string `field:"tags,ResolveContainerTags:9999"` // Tags of the container
}
// Event represents an event sent from the kernel
// genaccessors
type Event struct {
ID string `field:"-"`
Type uint64 `field:"-"`
TimestampRaw uint64 `field:"-"`
Timestamp time.Time `field:"timestamp"` // Timestamp of the event
ProcessContext ProcessContext `field:"process" event:"*"`
SpanContext SpanContext `field:"-"`
ContainerContext ContainerContext `field:"container"`
Chmod ChmodEvent `field:"chmod" event:"chmod"` // [7.27] [File] A file’s permissions were changed
Chown ChownEvent `field:"chown" event:"chown"` // [7.27] [File] A file’s owner was changed
Open OpenEvent `field:"open" event:"open"` // [7.27] [File] A file was opened
Mkdir MkdirEvent `field:"mkdir" event:"mkdir"` // [7.27] [File] A directory was created
Rmdir RmdirEvent `field:"rmdir" event:"rmdir"` // [7.27] [File] A directory was removed
Rename RenameEvent `field:"rename" event:"rename"` // [7.27] [File] A file/directory was renamed
Unlink UnlinkEvent `field:"unlink" event:"unlink"` // [7.27] [File] A file was deleted
Utimes UtimesEvent `field:"utimes" event:"utimes"` // [7.27] [File] Change file access/modification times
Link LinkEvent `field:"link" event:"link"` // [7.27] [File] Create a new name/alias for a file
SetXAttr SetXAttrEvent `field:"setxattr" event:"setxattr"` // [7.27] [File] Set exteneded attributes
RemoveXAttr SetXAttrEvent `field:"removexattr" event:"removexattr"` // [7.27] [File] Remove extended attributes
Exec ExecEvent `field:"exec" event:"exec"` // [7.27] [Process] A process was executed or forked
SetUID SetuidEvent `field:"setuid" event:"setuid"` // [7.27] [Process] A process changed its effective uid
SetGID SetgidEvent `field:"setgid" event:"setgid"` // [7.27] [Process] A process changed its effective gid
Capset CapsetEvent `field:"capset" event:"capset"` // [7.27] [Process] A process changed its capacity set
SELinux SELinuxEvent `field:"selinux" event:"selinux"` // [7.30] [Kernel] An SELinux operation was run
BPF BPFEvent `field:"bpf" event:"bpf"` // [7.33] [Kernel] A BPF command was executed
PTrace PTraceEvent `field:"ptrace" event:"ptrace"` // [7.34] [Kernel] [Experimental] A ptrace command was executed
MMap MMapEvent `field:"mmap" event:"mmap"` // [7.34] [Kernel] [Experimental] A mmap command was executed
MProtect MProtectEvent `field:"mprotect" event:"mprotect"` // [7.34] [Kernel] [Experimental] A mprotect command was executed
Mount MountEvent `field:"-"`
Umount UmountEvent `field:"-"`
InvalidateDentry InvalidateDentryEvent `field:"-"`
ArgsEnvs ArgsEnvsEvent `field:"-"`
MountReleased MountReleasedEvent `field:"-"`
}
// GetType returns the event type
func (e *Event) GetType() string {
return EventType(e.Type).String()
}
// GetEventType returns the event type of the event
func (e *Event) GetEventType() EventType {
return EventType(e.Type)
}
// GetTags returns the list of tags specific to this event
func (e *Event) GetTags() []string {
tags := []string{"type:" + e.GetType()}
// should already be resolved at this stage
if len(e.ContainerContext.Tags) > 0 {
tags = append(tags, e.ContainerContext.Tags...)
}
return tags
}
// GetPointer return an unsafe.Pointer of the Event
func (e *Event) GetPointer() unsafe.Pointer {
return unsafe.Pointer(e)
}
// SetuidEvent represents a setuid event
type SetuidEvent struct {
UID uint32 `field:"uid"` // New UID of the process
User string `field:"user,ResolveSetuidUser"` // New user of the process
EUID uint32 `field:"euid"` // New effective UID of the process
EUser string `field:"euser,ResolveSetuidEUser"` // New effective user of the process
FSUID uint32 `field:"fsuid"` // New FileSystem UID of the process
FSUser string `field:"fsuser,ResolveSetuidFSUser"` // New FileSystem user of the process
}
// SetgidEvent represents a setgid event
type SetgidEvent struct {
GID uint32 `field:"gid"` // New GID of the process
Group string `field:"group,ResolveSetgidGroup"` // New group of the process
EGID uint32 `field:"egid"` // New effective GID of the process
EGroup string `field:"egroup,ResolveSetgidEGroup"` // New effective group of the process
FSGID uint32 `field:"fsgid"` // New FileSystem GID of the process
FSGroup string `field:"fsgroup,ResolveSetgidFSGroup"` // New FileSystem group of the process
}
// CapsetEvent represents a capset event
type CapsetEvent struct {
CapEffective uint64 `field:"cap_effective"` // Effective capability set of the process
CapPermitted uint64 `field:"cap_permitted"` // Permitted capability set of the process
}
// Credentials represents the kernel credentials of a process
type Credentials struct {
UID uint32 `field:"uid"` // UID of the process
GID uint32 `field:"gid"` // GID of the process
User string `field:"user"` // User of the process
Group string `field:"group"` // Group of the process
EUID uint32 `field:"euid"` // Effective UID of the process
EGID uint32 `field:"egid"` // Effective GID of the process
EUser string `field:"euser"` // Effective user of the process
EGroup string `field:"egroup"` // Effective group of the process
FSUID uint32 `field:"fsuid"` // FileSystem-uid of the process
FSGID uint32 `field:"fsgid"` // FileSystem-gid of the process
FSUser string `field:"fsuser"` // FileSystem-user of the process
FSGroup string `field:"fsgroup"` // FileSystem-group of the process
CapEffective uint64 `field:"cap_effective"` // Effective capability set of the process
CapPermitted uint64 `field:"cap_permitted"` // Permitted capability set of the process
}
// GetPathResolutionError returns the path resolution error as a string if there is one
func (e *Process) GetPathResolutionError() string {
if e.PathResolutionError != nil {
return e.PathResolutionError.Error()
}
return ""
}
// Process represents a process
type Process struct {
// proc_cache_t
FileFields FileFields `field:"file"`
Pid uint32 `field:"pid"` // Process ID of the process (also called thread group ID)
Tid uint32 `field:"tid"` // Thread ID of the thread
PathnameStr string `field:"file.path"` // Path of the process executable
BasenameStr string `field:"file.name"` // Basename of the path of the process executable
Filesystem string `field:"file.filesystem"` // FileSystem of the process executable
PathResolutionError error `field:"-"`
ContainerID string `field:"container.id"` // Container ID
TTYName string `field:"tty_name"` // Name of the TTY associated with the process
Comm string `field:"comm"` // Comm attribute of the process
// pid_cache_t
ForkTime time.Time `field:"-"`
ExitTime time.Time `field:"-"`
ExecTime time.Time `field:"-"`
CreatedAt uint64 `field:"created_at,ResolveProcessCreatedAt"` // Timestamp of the creation of the process
Cookie uint32 `field:"cookie"` // Cookie of the process
PPid uint32 `field:"ppid"` // Parent process ID
// credentials_t section of pid_cache_t
Credentials
ArgsID uint32 `field:"-"`
EnvsID uint32 `field:"-"`
ArgsEntry *ArgsEntry `field:"-"`
EnvsEntry *EnvsEntry `field:"-"`
// defined to generate accessors, ArgsTruncated and EnvsTruncated are used during by unmarshaller
Argv0 string `field:"argv0,ResolveProcessArgv0:100"` // First argument of the process
Args string `field:"args,ResolveProcessArgs:100"` // Arguments of the process (as a string)
Argv []string `field:"argv,ResolveProcessArgv:100" field:"args_flags,ResolveProcessArgsFlags" field:"args_options,ResolveProcessArgsOptions"` // Arguments of the process (as an array)
ArgsTruncated bool `field:"args_truncated,ResolveProcessArgsTruncated"` // Indicator of arguments truncation
Envs []string `field:"envs,ResolveProcessEnvs:100"` // Environment variables of the process
EnvsTruncated bool `field:"envs_truncated,ResolveProcessEnvsTruncated"` // Indicator of environment variables truncation
// cache version
ScrubbedArgvResolved bool `field:"-"`
ScrubbedArgv []string `field:"-"`
ScrubbedArgsTruncated bool `field:"-"`
}
// SpanContext describes a span context
type SpanContext struct {
SpanID uint64 `field:"_"`
TraceID uint64 `field:"_"`
}
// ExecEvent represents a exec event
type ExecEvent struct {
Process
}
// FileFields holds the information required to identify a file
type FileFields struct {
UID uint32 `field:"uid"` // UID of the file's owner
User string `field:"user,ResolveFileFieldsUser"` // User of the file's owner
GID uint32 `field:"gid"` // GID of the file's owner
Group string `field:"group,ResolveFileFieldsGroup"` // Group of the file's owner
Mode uint16 `field:"mode" field:"rights,ResolveRights"` // Mode/rights of the file
CTime uint64 `field:"change_time"` // Change time of the file
MTime uint64 `field:"modification_time"` // Modification time of the file
MountID uint32 `field:"mount_id"` // Mount ID of the file
Inode uint64 `field:"inode"` // Inode of the file
InUpperLayer bool `field:"in_upper_layer,ResolveFileFieldsInUpperLayer"` // Indicator of the file layer, in an OverlayFS for example
NLink uint32 `field:"-"`
PathID uint32 `field:"-"`
Flags int32 `field:"-"`
}
// HasHardLinks returns whether the file has hardlink
func (f *FileFields) HasHardLinks() bool {
return f.NLink > 1
}
// GetInLowerLayer returns whether a file is in a lower layer
func (f *FileFields) GetInLowerLayer() bool {
return f.Flags&LowerLayer != 0
}
// GetInUpperLayer returns whether a file is in the upper layer
func (f *FileFields) GetInUpperLayer() bool {
return f.Flags&UpperLayer != 0
}
// FileEvent is the common file event type
type FileEvent struct {
FileFields
PathnameStr string `field:"path,ResolveFilePath"` // File's path
BasenameStr string `field:"name,ResolveFileBasename"` // File's basename
Filesytem string `field:"filesystem,ResolveFileFilesystem"` // File's filesystem
PathResolutionError error `field:"-"`
}
// GetPathResolutionError returns the path resolution error as a string if there is one
func (e *FileEvent) GetPathResolutionError() string {
if e.PathResolutionError != nil {
return e.PathResolutionError.Error()
}
return ""
}
// InvalidateDentryEvent defines a invalidate dentry event
type InvalidateDentryEvent struct {
Inode uint64
MountID uint32
DiscarderRevision uint32
}
// MountReleasedEvent defines a mount released event
type MountReleasedEvent struct {
MountID uint32
DiscarderRevision uint32
}
// LinkEvent represents a link event
type LinkEvent struct {
SyscallEvent
Source FileEvent `field:"file"`
Target FileEvent `field:"file.destination"`
}
// MkdirEvent represents a mkdir event
type MkdirEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Mode uint32 `field:"file.destination.mode" field:"file.destination.rights"` // Mode/rights of the new directory
}
// ArgsEnvsEvent defines a args/envs event
type ArgsEnvsEvent struct {
ArgsEnvs
}
// MountEvent represents a mount event
type MountEvent struct {
SyscallEvent
MountID uint32
GroupID uint32
Device uint32
ParentMountID uint32
ParentInode uint64
FSType string
MountPointStr string
MountPointPathResolutionError error
RootMountID uint32
RootInode uint64
RootStr string
RootPathResolutionError error
FSTypeRaw [16]byte
}
// GetFSType returns the filesystem type of the mountpoint
func (m *MountEvent) GetFSType() string {
return m.FSType
}
// IsOverlayFS returns whether it is an overlay fs
func (m *MountEvent) IsOverlayFS() bool {
return m.GetFSType() == "overlay"
}
// GetRootPathResolutionError returns the root path resolution error as a string if there is one
func (m *MountEvent) GetRootPathResolutionError() string {
if m.RootPathResolutionError != nil {
return m.RootPathResolutionError.Error()
}
return ""
}
// GetMountPointPathResolutionError returns the mount point path resolution error as a string if there is one
func (m *MountEvent) GetMountPointPathResolutionError() string {
if m.MountPointPathResolutionError != nil {
return m.MountPointPathResolutionError.Error()
}
return ""
}
// OpenEvent represents an open event
type OpenEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Flags uint32 `field:"flags"` // Flags used when opening the file
Mode uint32 `field:"file.destination.mode"` // Mode of the created file
}
// SELinuxEventKind represents the event kind for SELinux events
type SELinuxEventKind uint32
const (
// SELinuxBoolChangeEventKind represents SELinux boolean change events
SELinuxBoolChangeEventKind SELinuxEventKind = iota
// SELinuxStatusChangeEventKind represents SELinux status change events
SELinuxStatusChangeEventKind
// SELinuxBoolCommitEventKind represents SELinux boolean commit events
SELinuxBoolCommitEventKind
)
// SELinuxEvent represents a selinux event
type SELinuxEvent struct {
File FileEvent `field:"-"`
EventKind SELinuxEventKind `field:"-"`
BoolName string `field:"bool.name,ResolveSELinuxBoolName"` // SELinux boolean name
BoolChangeValue string `field:"bool.state"` // SELinux boolean new value
BoolCommitValue bool `field:"bool_commit.state"` // Indicator of a SELinux boolean commit operation
EnforceStatus string `field:"enforce.status"` // SELinux enforcement status (one of "enforcing", "permissive", "disabled"")
}
var zeroProcessContext ProcessContext
// ProcessCacheEntry this struct holds process context kept in the process tree
type ProcessCacheEntry struct {
ProcessContext
refCount uint64 `field:"-"`
onRelease func(_ *ProcessCacheEntry) `field:"-"`
}
// Reset the entry
func (e *ProcessCacheEntry) Reset() {
e.ProcessContext = zeroProcessContext
e.refCount = 0
}
// Retain increment ref counter
func (e *ProcessCacheEntry) Retain() {
e.refCount++
}
// Release decrement and eventually release the entry
func (e *ProcessCacheEntry) Release() {
e.refCount--
if e.refCount > 0 {
return
}
if e.onRelease != nil {
e.onRelease(e)
}
}
// NewProcessCacheEntry returns a new process cache entry
func NewProcessCacheEntry(onRelease func(_ *ProcessCacheEntry)) *ProcessCacheEntry {
return &ProcessCacheEntry{
onRelease: onRelease,
}
}
// ProcessAncestorsIterator defines an iterator of ancestors
type ProcessAncestorsIterator struct {
prev *ProcessCacheEntry
}
// Front returns the first element
func (it *ProcessAncestorsIterator) Front(ctx *eval.Context) unsafe.Pointer {
if front := (*Event)(ctx.Object).ProcessContext.Ancestor; front != nil {
it.prev = front
return unsafe.Pointer(front)
}
return nil
}
// Next returns the next element
func (it *ProcessAncestorsIterator) Next() unsafe.Pointer {
if next := it.prev.Ancestor; next != nil {
it.prev = next
return unsafe.Pointer(next)
}
return nil
}
// ProcessContext holds the process context of an event
type ProcessContext struct {
Process
Ancestor *ProcessCacheEntry `field:"ancestors,,ProcessAncestorsIterator"`
}
// RenameEvent represents a rename event
type RenameEvent struct {
SyscallEvent
Old FileEvent `field:"file"`
New FileEvent `field:"file.destination"`
DiscarderRevision uint32 `field:"-"`
}
// RmdirEvent represents a rmdir event
type RmdirEvent struct {
SyscallEvent
File FileEvent `field:"file"`
DiscarderRevision uint32 `field:"-"`
}
// SetXAttrEvent represents an extended attributes event
type SetXAttrEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Namespace string `field:"file.destination.namespace,ResolveXAttrNamespace"` // Namespace of the extended attribute
Name string `field:"file.destination.name,ResolveXAttrName"` // Name of the extended attribute
NameRaw [200]byte
}
// SyscallEvent contains common fields for all the event
type SyscallEvent struct {
Retval int64 `field:"retval"` // Return value of the syscall
}
// UnlinkEvent represents an unlink event
type UnlinkEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Flags uint32 `field:"-"`
DiscarderRevision uint32 `field:"-"`
}
// UmountEvent represents an umount event
type UmountEvent struct {
SyscallEvent
MountID uint32
}
// UtimesEvent represents a utime event
type UtimesEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Atime time.Time `field:"-"`
Mtime time.Time `field:"-"`
}
// BPFEvent represents a BPF event
type BPFEvent struct {
SyscallEvent
Map BPFMap `field:"map"` // eBPF map involved in the BPF command
Program BPFProgram `field:"prog"` // eBPF program involved in the BPF command
Cmd uint32 `field:"cmd"` // BPF command name
}
// BPFMap represents a BPF map
type BPFMap struct {
ID uint32 `field:"-"` // ID of the eBPF map
Type uint32 `field:"type"` // Type of the eBPF map
Name string `field:"-"` // Name of the eBPF map
}
// BPFProgram represents a BPF program
type BPFProgram struct {
ID uint32 `field:"-"` // ID of the eBPF program
Type uint32 `field:"type"` // Type of the eBPF program
AttachType uint32 `field:"attach_type"` // Attach type of the eBPF program
Helpers []uint32 `field:"-,ResolveHelpers"` // eBPF helpers used by the eBPF program
Name string `field:"-"` // Name of the eBPF program
}
// PTraceEvent represents a ptrace event
type PTraceEvent struct {
SyscallEvent
Request uint32 `field:"request"`
PID uint32 `field:"-"`
Address uint64 `field:"-"`
Tracee ProcessContext `field:"tracee"`
TraceeProcessCacheEntry *ProcessCacheEntry `field:"-"`
}
// MMapEvent represents a mmap event
type MMapEvent struct {
SyscallEvent
File FileEvent `field:"file"`
Addr uint64 `field:"-"`
Offset uint64 `field:"-"`
Len uint32 `field:"-"`
Protection int `field:"protection"`
Flags int `field:"flags"`
}
// MProtectEvent represents a mprotect event
type MProtectEvent struct {
SyscallEvent
VMStart uint64 `field:"-"`
VMEnd uint64 `field:"-"`
VMProtection int `field:"vm_protection"`
ReqProtection int `field:"req_protection"`
}