elastic / elastic/go-libaudit

Refactor to better handle write `ENOBUF`, blocking writes, and other IO Issues

Open
#173 0 comments 0 reactions 0 assignees View on GitHub
Team:Security-Linux Platform
Dominant language
Go
Stars
162
Forks
74
PR merge metrics
No merged PRs in 30d

Description

Recently, we've seen a lot of similar issues related to how we're handing read/write behavior:

https://github.com/elastic/beats/issues/26031
https://github.com/elastic/beats/pull/42933
https://github.com/elastic/go-libaudit/issues/160
https://github.com/elastic/go-libaudit/issues/125

I suspect a lot of these issues are related, and perhaps stem from some read/write behavior that's causing some problems. In particular:

- Writes should be non-blocking; if a write returns EAGAIN or a similar error, the underlying logic can handle that naturally in a read/write loop
- We need to handle ENOBUFS correctly; instead of hard-returning an error, we need to deal with the problem (netlink buffer has filled up, we need to resend our request) cleanly.
- Instead of a sleep/read loop when we're reading from the socket, we need to poll and wait for new data. This may also cut down on ENOBUFS issues.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.