已开启
[sync] PR-41: adapt file ebpf for kernel 6.6 #42
AtomGit-Bot创建于 2025年3月7日
[sync] PR-41: adapt file ebpf for kernel 6.6 #42
已开启
AtomGit-Bot创建于 2025年3月7日
共 2 个文件变更+93-2
@@ -0,0 +1,87 @@
1+From 12f2a608cc1c519786befadd3195316968a5ca28 Mon Sep 17 00:00:00 2001
2+From: zgzxx <zhangguangzhi3@huawei.com>
3+Date: Thu, 19 Sep 2024 10:36:59 +0800
4+Subject: [PATCH] adapt file ebpf for kernel 6.6
5+ 
6+---
7+ observer_agent/ebpf/CMakeLists.txt | 2 +-
8+ observer_agent/ebpf/file_ebpf/CMakeLists.txt | 2 +-
9+ observer_agent/ebpf/file_ebpf/file_fentry.bpf.c | 14 ++++++++------
10+ 3 files changed, 10 insertions(+), 8 deletions(-)
11+ 
12+diff --git a/observer_agent/ebpf/CMakeLists.txt b/observer_agent/ebpf/CMakeLists.txt
13+index a5c9bbe..d400c01 100644
14+--- a/observer_agent/ebpf/CMakeLists.txt
15++++ b/observer_agent/ebpf/CMakeLists.txt
16+@@ -3,7 +3,7 @@ project(ebpf)
17+ add_subdirectory(file_ebpf)
18+ add_custom_target(ebpf
19+ COMMAND mkdir -p ${CMAKE_CURRENT_BINARY_DIR}/.output
20+- COMMAND bpftool btf dump file /sys/kernel/btf/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h
21++ COMMAND bpftool btf dump file /usr/lib/debug/lib/modules/`uname -r`/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h
22+ COMMAND clang -g -O2 -target bpf -D__TARGET_ARCH_x86 -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -c ${CMAKE_CURRENT_SOURCE_DIR}/fentry.bpf.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.bpf.o
23+ COMMAND bpftool gen skeleton ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.bpf.o > ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.skel.h
24+ COMMAND cc -g -Wall -fPIC -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -I${CMAKE_CURRENT_SOURCE_DIR} -c ${CMAKE_CURRENT_SOURCE_DIR}/fentry.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/fentry.o
25+diff --git a/observer_agent/ebpf/file_ebpf/CMakeLists.txt b/observer_agent/ebpf/file_ebpf/CMakeLists.txt
26+index e9e073a..b8939df 100644
27+--- a/observer_agent/ebpf/file_ebpf/CMakeLists.txt
28++++ b/observer_agent/ebpf/file_ebpf/CMakeLists.txt
29+@@ -4,7 +4,7 @@ cmake_minimum_required(VERSION 3.22)
30+ project(file_ebpf)
31+ add_custom_target(file_ebpf
32+ COMMAND mkdir -p ${CMAKE_CURRENT_BINARY_DIR}/.output
33+- COMMAND bpftool btf dump file /sys/kernel/btf/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h
34++ COMMAND bpftool btf dump file /usr/lib/debug/lib/modules/`uname -r`/vmlinux format c > ${CMAKE_CURRENT_BINARY_DIR}/.output/vmlinux.h
35+ COMMAND clang -g -O2 -target bpf -D__TARGET_ARCH_x86 -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -c ${CMAKE_CURRENT_SOURCE_DIR}/file_fentry.bpf.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.bpf.o
36+ COMMAND bpftool gen skeleton ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.bpf.o > ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.skel.h
37+ COMMAND cc -g -Wall -fPIC -I${CMAKE_SOURCE_DIR}/include -I${CMAKE_CURRENT_BINARY_DIR}/.output -I${CMAKE_CURRENT_SOURCE_DIR} -c ${CMAKE_CURRENT_SOURCE_DIR}/file_fentry.c -o ${CMAKE_CURRENT_BINARY_DIR}/.output/file_fentry.o
38+diff --git a/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c b/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c
39+index 941b785..b3ef041 100644
40+--- a/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c
41++++ b/observer_agent/ebpf/file_ebpf/file_fentry.bpf.c
42+@@ -178,7 +178,7 @@ int BPF_PROG(fexit_vfs_write, struct file *file, const char *buf, size_t count,
43+ }
44+
45+ SEC("fexit/vfs_unlink")
46+-int BPF_PROG(fexit_vfs_unlink, struct inode *dir, struct dentry *dentry, struct inode **delegated_inode, int ret)
47++int BPF_PROG(fexit_vfs_unlink, struct mnt_idmap *idmap, struct inode *dir, struct dentry *dentry, struct inode **delegated_inode, int ret)
48+ {
49+ struct ebpf_event *e = NULL;
50+
51+@@ -287,7 +287,7 @@ int BPF_PROG(fexit_chown_common, const struct path *path, uid_t user, gid_t grou
52+ }
53+
54+ SEC("fentry/__vfs_setxattr_noperm")
55+-int BPF_PROG(fentry__vfs_setxattr_noperm, struct dentry *dentry, const char *name, const void *value, size_t size, int flags)
56++int BPF_PROG(fentry__vfs_setxattr_noperm, struct mnt_idmap *idmap, struct dentry *dentry, const char *name, const void *value, size_t size, int flags)
57+ {
58+ struct ebpf_event *e = NULL;
59+
60+@@ -307,7 +307,7 @@ int BPF_PROG(fentry__vfs_setxattr_noperm, struct dentry *dentry, const char *nam
61+ }
62+
63+ SEC("fentry/__vfs_removexattr_locked")
64+-int BPF_PROG(fentry__vfs_removexattr_locked, struct dentry *dentry, const char *name, struct inode **delegated_inode)
65++int BPF_PROG(fentry__vfs_removexattr_locked, struct mnt_idmap *idmap, struct dentry *dentry, const char *name, struct inode **delegated_inode)
66+ {
67+ struct ebpf_event *e = NULL;
68+
69+@@ -327,10 +327,12 @@ int BPF_PROG(fentry__vfs_removexattr_locked, struct dentry *dentry, const char *
70+ }
71+
72+ SEC("fentry/vfs_rename")
73+-int BPF_PROG(fentry_vfs_rename, struct inode *old_dir, struct dentry *old_dentry,
74+- struct inode *new_dir, struct dentry *new_dentry, struct inode **delegated_inode,
75+- unsigned int flags)
76++int BPF_PROG(fentry_vfs_rename, struct renamedata *rd)
77+ {
78++ if (!rd)
79++ return 0;
80++ struct dentry *old_dentry = rd->old_dentry;
81++ struct dentry *new_dentry = rd->new_dentry;
82+ struct ebpf_event *e = NULL;
83+ char name[] = "rename";
84+
85+--
86+2.33.0
87+ 
@@ -5,12 +5,12 @@
5Name : secDetector5Name : secDetector
6Summary : OS Security Intrusion Detection System6Summary : OS Security Intrusion Detection System
7Version : 1.07Version : 1.0
8-Release : 148+Release : 15
9License : GPL-2.09License : GPL-2.0
10Source0 : %{name}-v%{version}.tar.gz10Source0 : %{name}-v%{version}.tar.gz
11BuildRequires: kernel-devel kernel-headers11BuildRequires: kernel-devel kernel-headers
12BuildRequires: gcc gcc-c++ clang cmake make12BuildRequires: gcc gcc-c++ clang cmake make
13-BuildRequires: libbpf-devel bpftool 13+BuildRequires: libbpf-devel bpftool uname-build-checks kernel-debuginfo
14BuildRequires: grpc-devel grpc-plugins protobuf-devel c-ares-devel libuuid-devel14BuildRequires: grpc-devel grpc-plugins protobuf-devel c-ares-devel libuuid-devel
15Requires : kernel15Requires : kernel
16Requires : protobuf grpc libuuid libbpf16Requires : protobuf grpc libuuid libbpf
@@ -47,6 +47,7 @@ Patch0030: Backport-fix-the-memory-leak-in-collect-unit.patch
47Patch0031: Backport-fix-memory-leak-in-program_action.patch47Patch0031: Backport-fix-memory-leak-in-program_action.patch
48Patch0032: Backport-bug-fix-memory-leak-in-sc-analyze-unit.patch48Patch0032: Backport-bug-fix-memory-leak-in-sc-analyze-unit.patch
49Patch0033: Backport-fix-6.x-kernel-compile-error.patch49Patch0033: Backport-fix-6.x-kernel-compile-error.patch
50+Patch0034: Backport-adapt-file-ebpf-for-kernel-6.6.patch
50 51 
51%description52%description
52OS Security Intrusion Detection System53OS Security Intrusion Detection System
@@ -120,6 +121,9 @@ rm -rf %{buildroot}
120%attr(0644,root,root) /usr/include/secDetector/secDetector_topic.h121%attr(0644,root,root) /usr/include/secDetector/secDetector_topic.h
121 122 
122%changelog123%changelog
124+* Fri Mar 7 2025 zcfsite <zhchf2010@126.com> 1.0-15
125+- backport patch to adapt file ebpf for kernel 6.6
126+ 
123* Tue Feb 20 2024 hurricane618 <hurricane618@hotmail.com> 1.0-14127* Tue Feb 20 2024 hurricane618 <hurricane618@hotmail.com> 1.0-14
124- backport patch to fix compile error in v6.6 kernel128- backport patch to fix compile error in v6.6 kernel
125 129