Add PCI address validation to generate_if_map - #735
Merged
Merged
Conversation
added 2 commits
September 17, 2026 22:26
Running setup.sh and compiling Gatekeeper during development creates several binaries, build artifacts, and runtime configuration files that are untracked by git. Add the following patterns to .gitignore to keep the repository clean: - *.bpf: compiled BPF programs in bpf/ and lua/bpf/ - build/: Gatekeeper compilation output directory - generate_if_map: interface-to-PCI mapping generator binary - gkctl/gkctl: Gatekeeper control client binary - lua/bpf/: directory holding installed BPF programs - lua/if_map.lua: generated interface-to-PCI mapping file
Virtual network interfaces such as Linux bridges (e.g. br0, lxcbr0) do not have a physical PCI bus address. When queried with ETHTOOL_GDRVINFO, the kernel bridge driver reports "N/A" for bus_info, and other virtual devices may fail the SIOCETHTOOL ioctl entirely. This previously caused non-PCI entries to be emitted into the interface map Lua file. Validate the bus information using sscanf to ensure it matches the PCI domain:bus:dev.func format. When an interface fails the ioctl or does not have a valid PCI address, report it to stderr and omit it from the generated mapping.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add PCI address validation to the mapping and update .gitignore to exclude build artifacts.