From e099f840d29e87f235cb9adcc4afe82f1a3d332f Mon Sep 17 00:00:00 2001 From: malmert Date: Sat, 7 Mar 2026 11:02:45 +0100 Subject: [PATCH] kprobe log fix --- backend/src/utilities/ebpf_bridge_events.py | 33 +++++++++++++++++++-- 1 file changed, 31 insertions(+), 2 deletions(-) diff --git a/backend/src/utilities/ebpf_bridge_events.py b/backend/src/utilities/ebpf_bridge_events.py index 7c8cbab..5305618 100644 --- a/backend/src/utilities/ebpf_bridge_events.py +++ b/backend/src/utilities/ebpf_bridge_events.py @@ -8,6 +8,7 @@ import ctypes as ct import hashlib import ipaddress import json +import os import signal import socket import sys @@ -395,13 +396,41 @@ def _emit_event(cpu: int, data: int, size: int) -> None: def _attach_kprobe_first(bpf: BPF, symbols: list[str], fn_name: str) -> str: - for symbol in symbols: + supported = _supported_kprobe_symbols(symbols) + if not supported: + raise RuntimeError(f"No supported kprobe symbols found for {fn_name}: {symbols}") + + for symbol in supported: try: bpf.attach_kprobe(event=symbol, fn_name=fn_name) return symbol except Exception: continue - raise RuntimeError(f"Failed to attach {fn_name} to any of {symbols}") + raise RuntimeError(f"Failed to attach {fn_name} to any of {supported}") + + +def _supported_kprobe_symbols(symbols: list[str]) -> list[str]: + try: + available = set() + for symbol in symbols: + for candidate in BPF.get_kprobe_functions(symbol.encode()): + decoded = candidate.decode("utf-8", "replace") + if decoded == symbol: + available.add(symbol) + if available: + return [symbol for symbol in symbols if symbol in available] + except Exception: + pass + + if os.path.exists("/proc/kallsyms"): + try: + with open("/proc/kallsyms", "r", encoding="utf-8", errors="replace") as handle: + names = {line.rsplit(" ", 1)[-1].strip() for line in handle} + return [symbol for symbol in symbols if symbol in names] + except Exception: + pass + + return symbols def _attach_egress_probe(bpf: BPF) -> str: