Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[QUESTIONS] Ask us anything Falco + eBPF re the underlying driver technology (please file regular bug reports separately) #2869

Open
incertum opened this issue Oct 13, 2023 · 7 comments
Assignees
Milestone

Comments

@incertum
Copy link
Contributor

incertum commented Oct 13, 2023

What to document

We are happy to answer questions related to Falco + eBPF you may have.

The purpose of this issue is to answer questions about the underlying kernel driver technology maintained in Falco's libs repository (https://github.com/falcosecurity/libs).

Please file regular bug reports separately. Do not use this issue for bug reports or error message reports.

@incertum
Copy link
Contributor Author

@guidemetothemoon and @nikimanoledaki We are happy to take any eBPF question here asynchronously that concerns the collaboration with the Green Reviews WG.

CC @Andreagit97 @FedeDP

@Andreagit97 Andreagit97 added this to the TBD milestone Oct 13, 2023
@Andreagit97 Andreagit97 self-assigned this Oct 13, 2023
@EdikAndriasyan
Copy link

EdikAndriasyan commented Oct 16, 2023

Edit (@incertum ): @EdikAndriasyan I have updated the issue description to clarify what this issue was created for (my apologies). For regular Falco bugs or issues, let's use separate tickets.


Hey, I am deploying Falco in GKE cluster(v1.24) with helm chart(3.7.1). Using ebpf module and deploying Falco as DaemonSet. I am getting this error in Falco logs.

`-- BEGIN PROG LOAD LOG --
processed 43798 insns (limit 1000000) max_states_per_insn 1 total_states 4061 peak_states 4061 mark_read 1921

-- END PROG LOAD LOG --
Mon Oct 16 09:06:37 2023: An error occurred in an event source, forcing termination...
Mon Oct 16 09:06:37 2023: Closing event source 'syscall'
Events detected: 0
Rule counts by severity:
Triggered rules by rule name:
Error: libscap: bpf_load_program() event=raw_tracepoint/filler/sys_procexit_e: Operation not permitted`

@incertum incertum changed the title Ask us anything Falco + eBPF Ask us anything Falco + eBPF re the underlying driver technology (please file regular bug reports separately) Oct 16, 2023
@Andreagit97
Copy link
Member

ei @EdikAndriasyan thank you for reporting! this is more a failure than a question, I will answer here #2874

@Andreagit97 Andreagit97 changed the title Ask us anything Falco + eBPF re the underlying driver technology (please file regular bug reports separately) [QUESTIONS] Ask us anything Falco + eBPF re the underlying driver technology (please file regular bug reports separately) Oct 16, 2023
@poiana
Copy link

poiana commented Jan 14, 2024

Issues go stale after 90d of inactivity.

Mark the issue as fresh with /remove-lifecycle stale.

Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle stale

@Andreagit97
Copy link
Member

/remove-lifecycle stale

@poiana
Copy link

poiana commented Apr 14, 2024

Issues go stale after 90d of inactivity.

Mark the issue as fresh with /remove-lifecycle stale.

Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle stale

@Andreagit97
Copy link
Member

/remove-lifecycle stale

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants