Skip to content

Add process_vm_access fields for process_vm_readv/writev - #787

Closed
Aegrah wants to merge 2 commits into
mainfrom
process-vm-writev-readv-9.4
Closed

Aegrah wants to merge 2 commits into
mainfrom
process-vm-writev-readv-9.4

Conversation

@Aegrah

@Aegrah Aegrah commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Add ECS mappings for Linux process_vm_access events so Defend documents can carry
cross-process memory access details from process_vm_readv / process_vm_writev.
Fields sit under process.Ext.process_vm_access.* next to other Linux process telemetry.

Issue: https://github.com/elastic/endpoint-dev/issues/21204

  • Data stream/action: process events, event.action: process_vm_access
  • Fields: target_pid, target_start_time_ns, remote_addr, byte counts and iovec
    counts (long); operation (keyword)
  • target_pid is resolved by the kernel from the pid passed to the call, so it is a host
    PID even when the caller runs in a PID namespace and is directly comparable to
    process.pid. target_start_time_ns pairs with it so a target cannot be confused with
    an unrelated process that later reuses the same PID.
  • bytes_transferred preserves the raw syscall return value, including negative errno
    values for failed attempts
  • Generation: sequential make clean && make all; only the three
    process.Ext.process_vm_access.* fields move

Proof

  • Package generation: PASS
  • Release-aligned Fleet acceptance: 20260910T102925Z-process-vm-access (Endpoint 9.4.2),
    accepted build endpoint-9.4.2-aba0979dc8d75bb9
  • Persona volume gate: 20260910T114814Z-process-vm-access-volume on that build
    (PASS, 1h) — 0 process_vm_access documents against 91,643 documents/hour
  • Accepted documents carried event.action=process_vm_access with operation, target
    identity and byte fields

Supersedes the evidence quoted in earlier revisions of this PR: the quark side was
redesigned to resolve the target at mm_access rather than from the namespace-relative
syscall argument, and all three gates were rerun against that design.

Companion PRs

Co-authored-by: Cursor <cursoragent@cursor.com>
@Aegrah
Aegrah force-pushed the process-vm-writev-readv-9.4 branch from 1db8012 to 9ac2456 Compare August 7, 2026 18:00
@Aegrah
Aegrah changed the base branch from 9.4 to main August 7, 2026 18:00
@Aegrah
Aegrah marked this pull request as ready for review August 7, 2026 18:20
@Aegrah
Aegrah requested review from a team as code owners August 7, 2026 18:20
@Aegrah
Aegrah requested review from gergoabraham and paul-tavares and removed request for gergoabraham and paul-tavares August 7, 2026 18:20
@Aegrah
Aegrah marked this pull request as draft August 7, 2026 21:47
Adds process.Ext.process_vm_access.target_start_time_ns so a target named by
PID can be told apart from an unrelated process that later reuses that PID.

target_pid's description now records that the kernel resolves it, so it is a
host PID even when the caller runs in a PID namespace and is therefore
comparable to process.pid.

Also adds short descriptions for target_pid and bytes_transferred, whose
descriptions exceed the 120-character single-line limit.

Co-authored-by: Cursor <cursoragent@cursor.com>
@Aegrah

Aegrah commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #800. The redesign keeps the hybrid architecture (syscall result + mm_access target identity) but replaces the named syscall tracepoints with ABI-aware raw entry/exit hooks (ia32/x32 compat calls were invisible), keeps attempts rejected before target lookup, makes the iovec fields honest bounded snapshots instead of a first-vector "address/size" (a zero-length decoy first vector and a partial transfer inside one vector were both reproduced), fixes the release-branch timestamp/ring-loss accounting, adds the optional-source retry in both Endpoint watchers, and replaces the weak tests (namespace/TID identity, compat entry, permission denial, partial transfer, map pressure, cleanup). Gates: preflight 20260916-pva-v2-release-final PASS, Fleet acceptance 20260916T172021Z-process-vm-access PASS (accepted build endpoint-9.4.2-5564d77d41a8132d); the persona volume gate was explicitly waived by the owner for this round and is recorded as waived, not passed. Per the workflow rule a redesign opens new PRs instead of force-pushing a different design here; closing this one.

@Aegrah Aegrah closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant