Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 20 additions & 7 deletions CHANGES
Original file line number Diff line number Diff line change
Expand Up @@ -207,11 +207,24 @@ Changes from 0.8 to 0.9
and friends are unaffected. Every other eBPF map except the ring buffer
is frozen after load (BPF_MAP_FREEZE, also 5.2+), so no process can
change quark's internal state through bpf(2).
o The rule DSL learned the event.scope field. Its values are container
and host. A container event comes from a process whose cgroup names
a container, a host event from a process whose cgroup does not. A
process with an unknown cgroup matches neither scope. The kprobe
backend does not report the cgroup of new processes, so on kprobe
only processes seen at start-up can match a scope. Only the last
cgroup component is parsed, nested cgroups match host. The nova
o The rule DSL learned the event.scope field, which selects events by
where the originating process runs: "container" matches processes
running inside a container, "host" matches processes running directly
on the host. A process is inside a container when the last component
of its cgroup path is a systemd scope unit created by a container
runtime, like docker-<id>.scope. Any other cgroup path is treated as
host, including nested cgroups inside a container and the flat layout
of the cgroupfs driver. Events without a process, or from a process
whose cgroup is unknown, match neither value. The KPROBE backend only
learns the cgroup of processes that existed when quark started, so events
from processes created afterwards never match either value. The NOVA
backend rejects the field with ENOTSUP.
o The rule DSL learned the pod.name and container.image fields.
pod.name matches the Kubernetes pod name of the process container.
container.image matches the full image reference of the process
container as reported by the runtime, registry and tag included, so
docker.io/library/nginx:1.25. Both accept a single * wildcard, as in
pod.name nginx-* or container.image quay.io/*. Both need container
metadata, from quark-kube-talker or the container API, a process
without a known container matches neither. The nova backend rejects
both fields with ENOTSUP.
2 changes: 2 additions & 0 deletions nova.h
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@
#define QUARK_RF_POISON (1ULL << 8)
#define QUARK_RF_FILE_EXEC_CHANGE (1ULL << 9)
#define QUARK_RF_EVENT_SCOPE (1ULL << 10)
#define QUARK_RF_POD_NAME (1ULL << 11)
#define QUARK_RF_CONTAINER_IMAGE (1ULL << 12)

enum quark_rule_scope {
QUARK_RULE_SCOPE_INVALID,
Expand Down
10 changes: 10 additions & 0 deletions nova_queue.c
Original file line number Diff line number Diff line change
Expand Up @@ -173,6 +173,16 @@ nova_rule_from_quark(struct nova_queue *nqq,
qwarn("event.scope is not supported in nova backend");
return (-1);
break;
case QUARK_RF_POD_NAME:
errno = ENOTSUP;
qwarn("pod.name is not supported in nova backend");
return (-1);
break;
case QUARK_RF_CONTAINER_IMAGE:
errno = ENOTSUP;
qwarn("container.image is not supported in nova backend");
return (-1);
break;
default:
errno = EINVAL;
qwarn("bad field->code %llu", field->code);
Expand Down
9 changes: 9 additions & 0 deletions parse.y
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ int quark_lex(YYSTYPE *, struct quark_parser_ctx *);
%token PASS DROP POISON ON ANY STRING
%token PROCESS_PID PROCESS_PPID PROCESS_UID PROCESS_GID PROCESS_SID
%token PROCESS_EXE FILE_PATH FILE_EXEC_CHANGE EVENT_SCOPE
%token POD_NAME CONTAINER_IMAGE

%%
grammar: /* empty */
Expand Down Expand Up @@ -131,6 +132,12 @@ matchfield: PROCESS_PID num_u32 {
$$.rf.id = QUARK_RULE_SCOPE_HOST;
else
ABORT("bad event scope: %s", $2.str);
} | POD_NAME STRING {
$$.rf.code = QUARK_RF_POD_NAME;
$$.rf.wild.pre = (char *)$2.str;
} | CONTAINER_IMAGE STRING {
$$.rf.code = QUARK_RF_CONTAINER_IMAGE;
$$.rf.wild.pre = (char *)$2.str;
} | POISON num_u64 {
$$.rf.code = QUARK_RF_POISON;
$$.rf.poison_tag = $2.num_u64;
Expand Down Expand Up @@ -206,6 +213,8 @@ static struct keyword {
{ "file.path", FILE_PATH },
{ "file.exec_change", FILE_EXEC_CHANGE },
{ "event.scope", EVENT_SCOPE },
{ "pod.name", POD_NAME },
{ "container.image", CONTAINER_IMAGE },
};

/*
Expand Down
58 changes: 47 additions & 11 deletions quark-mon.8
Original file line number Diff line number Diff line change
Expand Up @@ -126,20 +126,56 @@ use
.Em -
for stdin.
The
.Dq event.scope
field matches events by where the originating process runs.
.Dq event.scope container
field matches events from a process whose cgroup names a container.
The
matches events from processes running inside a container and
.Dq event.scope host
field matches events from a process whose cgroup does not name a container.
An event without a process, or from a process with an unknown cgroup,
matches neither scope.
The kprobe backend does not report the cgroup of new processes, so on
kprobe only processes that existed at start-up can match a scope.
Only a cgroup whose last component is a container scope, like
.Pa docker-<id>.scope ,
names a container.
Nested cgroups and the cgroupfs driver layout match the host scope.
matches events from processes running directly on the host.
A process is considered to be inside a container when the last component
of its cgroup path is a systemd scope unit created by a container runtime,
like
.Pa docker-<id>.scope .
Any other cgroup path is treated as host.
This includes a nested cgroup inside a container, like
.Pa docker-<id>.scope/init.scope ,
and the flat layout of the cgroupfs driver, like
.Pa /docker/<id> .
Events without a process, and events from a process whose cgroup is
unknown, match neither value.
The kprobe backend only learns the cgroup of processes that existed when
.Nm
started, so events from processes created afterwards never match either
value.
This field is not supported by the NOVA backend.
The
.Dq pod.name
field matches events from a process in a container that belongs to the
named Kubernetes pod.
A single
.Sq *
wildcard is accepted, as in
.Dq pod.name nginx-* .
The
.Dq container.image
field matches events from a process in a container whose image reference
matches the given string.
The image reference is compared as reported by the container runtime,
registry and tag included, as in
.Dq container.image docker.io/library/nginx:1.25 .
A single
.Sq *
wildcard is accepted, so
.Dq container.image */nginx:1.25
matches that image from any registry, and
.Dq container.image quay.io/*
matches every image from that registry.
Both fields require container metadata, from quark-kube-talker, see
.Fl K ,
or from the container API of the library.
An event without a process, or from a process whose container is unknown,
matches neither field.
These fields are not supported by the NOVA backend.
.It Fl T
Enable ptrace event tracing.
.It Fl t
Expand Down
Loading