已开启
[sync] PR-41: adapt file ebpf for kernel 6.6 #42
AtomGit-Bot创建于 2025年3月7日
[sync] PR-41: adapt file ebpf for kernel 6.6 #42
已开启
共 2 个文件变更+93-2
| @@ -0,0 +1,87 @@ | |||
| 1 | +From 12f2a608cc1c519786befadd3195316968a5ca28 Mon Sep 17 00:00:00 2001 | ||
| 2 | +From: zgzxx <zhangguangzhi3@huawei.com> | ||
| 3 | +Date: Thu, 19 Sep 2024 10:36:59 +0800 | ||
| 4 | +Subject: [PATCH] adapt file ebpf for kernel 6.6 | ||
| 5 | + | ||
| 6 | +--- | ||
| 7 | + observer_agent/ebpf/CMakeLists.txt | 2 +- | ||
| 8 | + observer_agent/ebpf/file_ebpf/CMakeLists.txt | 2 +- | ||
| 9 | + observer_agent/ebpf/file_ebpf/file_fentry.bpf.c | 14 ++++++++------ | ||
| 10 | + 3 files changed, 10 insertions(+), 8 deletions(-) | ||
| 11 | + | ||
| 12 | +diff --git a/observer_agent/ebpf/CMakeLists.txt b/observer_agent/ebpf/CMakeLists.txt | ||
| 13 | +index a5c9bbe..d400c01 100644 | ||
| 14 | +--- a/observer_agent/ebpf/CMakeLists.txt | ||
| 15 | ++++ b/observer_agent/ebpf/CMakeLists.txt | ||
| 16 | + project(ebpf) | ||
| 17 | + add_subdirectory(file_ebpf) | ||
| 18 | + add_custom_target(ebpf | ||
| 19 | + COMMAND mkdir -p ${CMAKE_CURRENT_BINARY_DIR}/.output | ||
| 20 | +- COMMAND bpftool btf dump file /sys/kernel/btf/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h | ||
| 21 | ++ COMMAND bpftool btf dump file /usr/lib/debug/lib/modules/`uname -r`/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h | ||
| 22 | + COMMAND clang -g -O2 -target bpf -D__TARGET_ARCH_x86 -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -c ${CMAKE_CURRENT_SOURCE_DIR}/fentry.bpf.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.bpf.o | ||
| 23 | + COMMAND bpftool gen skeleton ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.bpf.o > ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.skel.h | ||
| 24 | + COMMAND cc -g -Wall -fPIC -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -I${CMAKE_CURRENT_SOURCE_DIR} -c ${CMAKE_CURRENT_SOURCE_DIR}/fentry.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.o | ||
| 25 | +diff --git a/observer_agent/ebpf/file_ebpf/CMakeLists.txt b/observer_agent/ebpf/file_ebpf/CMakeLists.txt | ||
| 26 | +index e9e073a..b8939df 100644 | ||
| 27 | +--- a/observer_agent/ebpf/file_ebpf/CMakeLists.txt | ||
| 28 | ++++ b/observer_agent/ebpf/file_ebpf/CMakeLists.txt | ||
| 29 | + cmake_minimum_required(VERSION 3.22) | ||
| 30 | + project(file_ebpf) | ||
| 31 | + add_custom_target(file_ebpf | ||
| 32 | + COMMAND mkdir -p ${CMAKE_CURRENT_BINARY_DIR}/.output | ||
| 33 | +- COMMAND bpftool btf dump file /sys/kernel/btf/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h | ||
| 34 | ++ COMMAND bpftool btf dump file /usr/lib/debug/lib/modules/`uname -r`/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h | ||
| 35 | + COMMAND clang -g -O2 -target bpf -D__TARGET_ARCH_x86 -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -c ${CMAKE_CURRENT_SOURCE_DIR}/file_fentry.bpf.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.bpf.o | ||
| 36 | + COMMAND bpftool gen skeleton ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.bpf.o > ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.skel.h | ||
| 37 | + COMMAND cc -g -Wall -fPIC -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -I${CMAKE_CURRENT_SOURCE_DIR} -c ${CMAKE_CURRENT_SOURCE_DIR}/file_fentry.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.o | ||
| 38 | +diff --git a/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c b/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c | ||
| 39 | +index 941b785..b3ef041 100644 | ||
| 40 | +--- a/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c | ||
| 41 | ++++ b/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c | ||
| 42 | + int BPF_PROG(fexit_vfs_write, struct file *file, const char *buf, size_t count, | ||
| 43 | + } | ||
| 44 | + | ||
| 45 | + SEC("fexit/vfs_unlink") | ||
| 46 | +-int BPF_PROG(fexit_vfs_unlink, struct inode *dir, struct dentry *dentry, struct inode **delegated_inode, int ret) | ||
| 47 | ++int BPF_PROG(fexit_vfs_unlink, struct mnt_idmap *idmap, struct inode *dir, struct dentry *dentry, struct inode **delegated_inode, int ret) | ||
| 48 | + { | ||
| 49 | + struct ebpf_event *e = NULL; | ||
| 50 | + | ||
| 51 | + int BPF_PROG(fexit_chown_common, const struct path *path, uid_t user, gid_t grou | ||
| 52 | + } | ||
| 53 | + | ||
| 54 | + SEC("fentry/__vfs_setxattr_noperm") | ||
| 55 | +-int BPF_PROG(fentry__vfs_setxattr_noperm, struct dentry *dentry, const char *name, const void *value, size_t size, int flags) | ||
| 56 | ++int BPF_PROG(fentry__vfs_setxattr_noperm, struct mnt_idmap *idmap, struct dentry *dentry, const char *name, const void *value, size_t size, int flags) | ||
| 57 | + { | ||
| 58 | + struct ebpf_event *e = NULL; | ||
| 59 | + | ||
| 60 | + int BPF_PROG(fentry__vfs_setxattr_noperm, struct dentry *dentry, const char *nam | ||
| 61 | + } | ||
| 62 | + | ||
| 63 | + SEC("fentry/__vfs_removexattr_locked") | ||
| 64 | +-int BPF_PROG(fentry__vfs_removexattr_locked, struct dentry *dentry, const char *name, struct inode **delegated_inode) | ||
| 65 | ++int BPF_PROG(fentry__vfs_removexattr_locked, struct mnt_idmap *idmap, struct dentry *dentry, const char *name, struct inode **delegated_inode) | ||
| 66 | + { | ||
| 67 | + struct ebpf_event *e = NULL; | ||
| 68 | + | ||
| 69 | + int BPF_PROG(fentry__vfs_removexattr_locked, struct dentry *dentry, const char * | ||
| 70 | + } | ||
| 71 | + | ||
| 72 | + SEC("fentry/vfs_rename") | ||
| 73 | +-int BPF_PROG(fentry_vfs_rename, struct inode *old_dir, struct dentry *old_dentry, | ||
| 74 | +- struct inode *new_dir, struct dentry *new_dentry, struct inode **delegated_inode, | ||
| 75 | +- unsigned int flags) | ||
| 76 | ++int BPF_PROG(fentry_vfs_rename, struct renamedata *rd) | ||
| 77 | + { | ||
| 78 | ++ if (!rd) | ||
| 79 | ++ return 0; | ||
| 80 | ++ struct dentry *old_dentry = rd->old_dentry; | ||
| 81 | ++ struct dentry *new_dentry = rd->new_dentry; | ||
| 82 | + struct ebpf_event *e = NULL; | ||
| 83 | + char name[] = "rename"; | ||
| 84 | + | ||
| 85 | +-- | ||
| 86 | +2.33.0 | ||
| 87 | + | ||
| @@ -5,12 +5,12 @@ | |||
| 5 | Name : secDetector | 5 | Name : secDetector |
| 6 | Summary : OS Security Intrusion Detection System | 6 | Summary : OS Security Intrusion Detection System |
| 7 | Version : 1.0 | 7 | Version : 1.0 |
| 8 | -Release : 14 | 8 | +Release : 15 |
| 9 | License : GPL-2.0 | 9 | License : GPL-2.0 |
| 10 | Source0 : %{name}-v%{version}.tar.gz | 10 | Source0 : %{name}-v%{version}.tar.gz |
| 11 | BuildRequires: kernel-devel kernel-headers | 11 | BuildRequires: kernel-devel kernel-headers |
| 12 | BuildRequires: gcc gcc-c++ clang cmake make | 12 | BuildRequires: gcc gcc-c++ clang cmake make |
| 13 | -BuildRequires: libbpf-devel bpftool | 13 | +BuildRequires: libbpf-devel bpftool uname-build-checks kernel-debuginfo |
| 14 | BuildRequires: grpc-devel grpc-plugins protobuf-devel c-ares-devel libuuid-devel | 14 | BuildRequires: grpc-devel grpc-plugins protobuf-devel c-ares-devel libuuid-devel |
| 15 | Requires : kernel | 15 | Requires : kernel |
| 16 | Requires : protobuf grpc libuuid libbpf | 16 | Requires : protobuf grpc libuuid libbpf |
| @@ -47,6 +47,7 @@ Patch0030: Backport-fix-the-memory-leak-in-collect-unit.patch | |||
| 47 | Patch0031: Backport-fix-memory-leak-in-program_action.patch | 47 | Patch0031: Backport-fix-memory-leak-in-program_action.patch |
| 48 | Patch0032: Backport-bug-fix-memory-leak-in-sc-analyze-unit.patch | 48 | Patch0032: Backport-bug-fix-memory-leak-in-sc-analyze-unit.patch |
| 49 | Patch0033: Backport-fix-6.x-kernel-compile-error.patch | 49 | Patch0033: Backport-fix-6.x-kernel-compile-error.patch |
| 50 | +Patch0034: Backport-adapt-file-ebpf-for-kernel-6.6.patch | ||
| 50 | 51 | ||
| 51 | %description | 52 | %description |
| 52 | OS Security Intrusion Detection System | 53 | OS Security Intrusion Detection System |
| @@ -120,6 +121,9 @@ rm -rf %{buildroot} | |||
| 120 | %attr(0644,root,root) /usr/include/secDetector/secDetector_topic.h | 121 | %attr(0644,root,root) /usr/include/secDetector/secDetector_topic.h |
| 121 | 122 | ||
| 122 | %changelog | 123 | %changelog |
| 124 | +* Fri Mar 7 2025 zcfsite <zhchf2010@126.com> 1.0-15 | ||
| 125 | +- backport patch to adapt file ebpf for kernel 6.6 | ||
| 126 | + | ||
| 123 | * Tue Feb 20 2024 hurricane618 <hurricane618@hotmail.com> 1.0-14 | 127 | * Tue Feb 20 2024 hurricane618 <hurricane618@hotmail.com> 1.0-14 |
| 124 | - backport patch to fix compile error in v6.6 kernel | 128 | - backport patch to fix compile error in v6.6 kernel |
| 125 | 129 | ||