Skip to content

Conversation

@bleggett
Copy link
Collaborator

@bleggett bleggett commented Feb 2, 2026

In the latest release of Falco (0.43), the eBPF syscall hooks were refactored to only hook syscall exit events, thereby avoiding some of the gross state machine stuff where the code previously needed to watch for enter AND exit events for the same thread and do cross-correlation/enrichment from both.

Mirror that here, as that's considerably less gross and simplifies our logic as well.

Note that this changes means all latency fields, which previously measured latency between syscall enter and exit, now are no-ops that return 0. This is also the current Falco default for modern_bpf.

@bleggett bleggett force-pushed the bleggett/fix-extract branch from be7a520 to 55069cc Compare February 2, 2026 21:08
@bleggett bleggett enabled auto-merge (squash) February 2, 2026 21:16
@bleggett bleggett closed this Feb 2, 2026
auto-merge was automatically disabled February 2, 2026 23:10

Pull request was closed

@bleggett bleggett reopened this Feb 2, 2026
@bleggett bleggett enabled auto-merge (squash) February 2, 2026 23:10
@bleggett bleggett merged commit 7a1c685 into main Feb 2, 2026
5 of 9 checks passed
@bleggett bleggett deleted the bleggett/fix-extract branch February 2, 2026 23:12
This was referenced Feb 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants