Skip to content

Commit

Permalink
pkg/encoder: add custom printers for open and openat
Browse files Browse the repository at this point in the history
Rename the output for fd_install to fd_install instead of open and
change the default emoji for unrecognized symbols since previous emoji
was shifting alignment.

Signed-off-by: Mahe Tardy <mahe.tardy@gmail.com>
  • Loading branch information
mtardy committed Apr 11, 2023
1 parent 30c81f2 commit ab91a47
Show file tree
Hide file tree
Showing 2 changed files with 18 additions and 3 deletions.
18 changes: 16 additions & 2 deletions pkg/encoder/encoder.go
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,21 @@ func (p *CompactEncoder) EventToString(response *tetragon.GetEventsResponse) (st
file = p.Colorer.Cyan.Sprint(kprobe.Args[1].GetFileArg().Path)
}
return CapTrailorPrinter(fmt.Sprintf("%s %s %s", event, processInfo, file), caps), nil
case "__x64_sys_close":
case "sys_openat":
event := p.Colorer.Blue.Sprintf("📬️ %-7s", "openat")
file := ""
if len(kprobe.Args) > 1 && kprobe.Args[1] != nil {
file = p.Colorer.Cyan.Sprint(kprobe.Args[1].GetStringArg())
}
return CapTrailorPrinter(fmt.Sprintf("%s %s %s", event, processInfo, file), caps), nil
case "sys_open":
event := p.Colorer.Blue.Sprintf("📬️ %-7s", "open")
file := ""
if len(kprobe.Args) > 1 && kprobe.Args[1] != nil {
file = p.Colorer.Cyan.Sprint(kprobe.Args[1].GetStringArg())
}
return CapTrailorPrinter(fmt.Sprintf("%s %s %s", event, processInfo, file), caps), nil
case "sys_close":
event := p.Colorer.Blue.Sprintf("📪 %-7s", "close")
file := ""
if len(kprobe.Args) > 0 && kprobe.Args[0] != nil && kprobe.Args[0].GetFileArg() != nil {
Expand Down Expand Up @@ -294,7 +308,7 @@ func (p *CompactEncoder) EventToString(response *tetragon.GetEventsResponse) (st
}
return CapTrailorPrinter(fmt.Sprintf("%s %s %s", event, processInfo, attr), caps), nil
default:
event := p.Colorer.Blue.Sprintf("⁉️ %-7s", "syscall")
event := p.Colorer.Blue.Sprintf(" %-7s", "syscall")
return CapTrailorPrinter(fmt.Sprintf("%s %s %s", event, processInfo, kprobe.FunctionName), caps), nil
}
case *tetragon.GetEventsResponse_ProcessTracepoint:
Expand Down
3 changes: 2 additions & 1 deletion pkg/encoder/encoder_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -146,7 +146,8 @@ func TestCompactEncoder_KprobeEventToString(t *testing.T) {
},
})
assert.NoError(t, err)
assert.Equal(t, "⁉️ syscall kube-system/tetragon /usr/bin/curl unhandled_function", result)
assert.Equal(t, "❓ syscall kube-system/tetragon /usr/bin/curl unhandled_function", result)

}

func TestCompactEncoder_KprobeOpenEventToString(t *testing.T) {
Expand Down

0 comments on commit ab91a47

Please sign in to comment.