trace_kprobe: Could not probe notrace function register_ftrace_functiongrep <имя функции> /sys/kernel/debug/tracing/available_filter_functionsroot@k8s-sn:~# grep security_file_permission
/sys/kernel/debug/tracing/available_filter_functions security_file_permissiongrep <имя функции> /proc/kallsymsroot@k8s-sn:~# grep security_file_permission /proc/kallsyms ffffffffa7749c50 T security_file_permission ffffffffa89624f8 r ksymtab_security_file_permission ffffffffa8979b79 r kstrtabns_security_file_permission ffffffffa8981d0d r kstrtab_security_file_permission
ffffffffa8eb9cfc r BTF_ID func security_file_permission 611882apiVersion: cilium.io/v1alpha1 kind: TracingPolicyapiVersion: cilium.io/v1alpha1 kind: TracingPolicyNamespacedmetadata:
name: "test-policy" namespace: "default"spec:
options:
- name: "disable-kprobe-multi" value: "1"spec:
podSelector: matchLabels:
app: "test-pod-debian"spec:
podSelector: matchExpressions:
key: "app" operator: "In" value:
"test-pod-debian"
"test-pod-ubuntu"spec:
podSelector: matchExpressions:
key: "app" operator: "NotIn" value:
"test-pod-debian"
"test-pod-ubuntu"spec:
podSelector: matchExpressions:
key: "app" operator: "Exist"spec:
podSelector: matchExpressions:
key: "app"
operator: "DoesNotExist"spec:
containerSelector: matchExpressions:
key: "name" operator: "In" value:
"db"
"nginx"spec:
containerSelector: matchExpressions:
key: "name" operator: "NotIn" value:
"db"
"nginx"
spec:
lists:
name: "dups" type: "syscalls" values:
"sys_dup"
"sys_dup2" enforcers:
calls:
"list:dups" tracepoints:
subsystem: "raw_syscalls" event: "sys_enter"
args:
index: 4
type: "syscall64" selectors:
matchArgs:
index: 0 operator: "InMap" values:
"list:dups" matchBinaries:
operator: "In" values:
"/usr/bin/bash" matchActions:
action: "NotifyEnforcer" argSig: 9