Read absolute path for binary execution for matchBinaries #1741
Labels
area/bpf
This is related to BPF code
kind/enhancement
This improves or streamlines existing functionality
This is a followup of #1731.
[For matchBinaries] the binary path is just the arg passed to execve and thus can be a relative path (this explains many of the users issues). A future patch is needed to read the absolute path of the task_struct (as we do on userspace side with /proc to fill the initial state of the execve_map) to make this feature complete.
Might be useful: #90.
The text was updated successfully, but these errors were encountered: