Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ A per-node observability agent for Kubernetes and Linux hosts. The agent
gathers container and host metrics, logs, and L7 traffic using eBPF and
exposes them in Prometheus format.

Minimum Linux kernel: **5.8** (L7 events use a BPF ring buffer).
Minimum Linux kernel: **5.8** (L7 events use a BPF ring buffer), or a distribution kernel that backports BPF ring buffers, such as RHEL 8 (4.18).
The kernel must also be built with `CONFIG_BPF_EVENTS=y` (kprobe and tracepoint BPF programs); some embedded and vendor kernels disable it.

> This project is a fork of
Expand Down
20 changes: 10 additions & 10 deletions ebpftracer/ebpf.go

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions ebpftracer/ebpf/l7/gotls.c
Original file line number Diff line number Diff line change
Expand Up @@ -339,7 +339,7 @@ int go_crypto_tls_write_enter(struct pt_regs *ctx) {
__u64 buf_size_debug = GO_PARAM3(ctx);
bpf_printk("go_tls_write_enter: tgid=%u tls_conn=%p buf_size=%llu", pid, tls_conn_ptr_debug, buf_size_debug);

__u32 fd;
__u32 fd = 0; // RHEL 8's verifier rejects reading it uninitialized on any path
if (go_crypto_tls_get_fd_from_conn(ctx, &fd)) {
count_tls_drop_by_pid(TLS_DROP_GO_FD_UNKNOWN);
return 0;
Expand All @@ -361,7 +361,7 @@ int go_crypto_tls_read_enter(struct pt_regs *ctx) {
void* tls_conn_ptr_debug = (void*)GO_PARAM1(ctx);
bpf_printk("go_tls_read_enter: tgid=%u tls_conn=%p", tgid_debug, tls_conn_ptr_debug);

__u32 fd;
__u32 fd = 0; // RHEL 8's verifier rejects reading it uninitialized on any path
if (go_crypto_tls_get_fd_from_conn(ctx, &fd)) {
count_tls_drop_by_pid(TLS_DROP_GO_FD_UNKNOWN);
return 0;
Expand Down
20 changes: 16 additions & 4 deletions main.go
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ package main
import (
"bytes"
"context"
"errors"
"flag"
"fmt"
"log"
Expand All @@ -17,6 +18,9 @@ import (
"syscall"
"time"

"github.com/cilium/ebpf"
"github.com/cilium/ebpf/features"

"github.com/coroot/coroot-node-agent/common"
"github.com/coroot/coroot-node-agent/containers"
"github.com/coroot/coroot-node-agent/flags"
Expand Down Expand Up @@ -194,10 +198,18 @@ func main() {
}

// L7 events go through a BPF ring buffer (BPF_MAP_TYPE_RINGBUF), which
// every program variant uses and which kernels before 5.8 do not have:
// on them the programs fail to load further on, with a less clear error.
if !common.GetKernelVersion().GreaterOrEqual(common.NewVersion(5, 8, 0)) {
klog.Exitln("the minimum Linux kernel version required is 5.8 or later (BPF ring buffer)")
// every program variant uses: without it the programs fail to load
// further on, with a less clear error. Probe for the map type rather than
// checking for 5.8: RHEL 8 kernels (4.18) backport it. Kernels before
// 5.11 charge the probe's map to RLIMIT_MEMLOCK, so raise it first, as the
// tracer does before loading. Only a definite "not supported" is fatal:
// any other probe error (missing privileges) is left for the program
// loader to report.
_ = unix.Setrlimit(unix.RLIMIT_MEMLOCK, &unix.Rlimit{Cur: unix.RLIM_INFINITY, Max: unix.RLIM_INFINITY})
if err := features.HaveMapType(ebpf.RingBuf); errors.Is(err, ebpf.ErrNotSupported) {
klog.Exitf("the kernel does not support BPF ring buffers (Linux 5.8 or later, or a distribution kernel that backports them, such as RHEL 8): %s", err)
} else if err != nil {
klog.Warningf("failed to probe for BPF ring buffer support: %s", err)
}
Comment thread
mayankpande88 marked this conversation as resolved.

resolver, err := newIPResolver(hostname)
Expand Down
Loading