Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(ebpf): use correct syscall id for compat #4245

Merged
merged 1 commit into from
Aug 13, 2024

Conversation

OriGlassman
Copy link
Collaborator

1. Explain what the PR does

use correct syscall id for compat

2. Explain how to test it

./tracee

3. Other comments

@NDStrahilevitz
Copy link
Collaborator

Is this intended to resolve the wrong 0xFFFFFFFF syscalls on exit?

@OriGlassman
Copy link
Collaborator Author

Is this intended to resolve the wrong 0xFFFFFFFF syscalls on exit?

For Compat syscalls, there was no translation to the non compat id. This meant that a check like
if (sys_id == SYSCALL_SOCKETCALL) ....
was never fulfilled (since sys_id was 102, but SYSCALL_SOCKETCALL is 476. After translation, sys_id is 476 as expected).

Copy link
Collaborator

@yanivagman yanivagman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@yanivagman yanivagman merged commit 3a55305 into aquasecurity:main Aug 13, 2024
33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants