Skip to content

Add process_vm_access attempt fields for Linux process events - #800

Draft
Aegrah wants to merge 1 commit into
mainfrom
aegrah/process-vm-access-v2
Draft

Aegrah wants to merge 1 commit into
mainfrom
aegrah/process-vm-access-v2

Conversation

@Aegrah

@Aegrah Aegrah commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Summary

Supersedes #787. Describe Linux process_vm_access attempts without treating the first remote vector as the entire request. Add signed syscall return, requested PID and caller namespace, flags, target resolution, snapshot validity/status and conditional capacities. Actual transferred bytes are nonnegative; errors are separate. Raw unsigned syscall arguments use unsigned_long mappings.

User metadata is a bounded entry snapshot and may race kernel import. Resolved host identity is absent when lookup was not reached; target lifetime uses CLOCK_MONOTONIC. Documentation and generated mappings follow the same contract.

Issue: https://github.com/elastic/endpoint-dev/issues/21204

Validation

Preflight: 20260916-pva-v2-release-final. Fleet acceptance: 20260916T172021Z-process-vm-access, accepted build endpoint-9.4.2-5564d77d41a8132d (Stack/Agent/Endpoint 9.4.2). Main integration was validated separately. Full persona-volume gate explicitly waived by the user; no production-volume claim.

Sequential make clean && make all passes on main and the 9.4 acceptance lineage. Endpoint combined schemas are regenerated from these inputs. EAF validates event schema and documentation.

Companions: elastic/quark#428 · https://github.com/elastic/endpoint-dev/pull/22027

Separate signed syscall results from transferred bytes and errors. Make resolved host identity conditional; record raw caller-namespace arguments and vector snapshot validity, completeness, and requested-capacity estimates. Generated schema and documentation were rebuilt from their source definitions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant