More robust mechanism for getting strace events from gVisor
Open
Nobody has claimed this yet.
dynamic analysis
internal cleanup
- Dominant language
- Go
- Stars
- 912
- Forks
- 74
- PR merge metrics
- No merged PRs in 30d
Description
error: "Failed to parse openat args: AT_FDCWD /tmp/pip-install-ok6jlfy9/adafruit-circuitpython-busdevice_f20711ccac244452962292b5236c4d8f, 0x7f176abd3d40 , O_RDONLY|O_CLOEXEC, 0o0) = 0 (0x0) errno=2 (no such file or directory) (2.417µs"
Log entry:
{
"jsonPayload": {
"error": "Failed to parse openat args: AT_FDCWD /tmp/pip-install-ok6jlfy9/adafruit-circuitpython-busdevice_f20711ccac244452962292b5236c4d8f, 0x7f176abd3d40 , O_RDONLY|O_CLOEXEC, 0o0) = 0 (0x0) errno=2 (no such file or directory) (2.417µs",
"timestamp": "2022-05-03T21:57:55.238696724Z",
"caller": "strace/strace.go:264",
"message": "Failed to parse syscall"
},
"resource": {
"type": "k8s_container",
"labels": {
"namespace_name": "default",
"cluster_name": "analysis-cluster",
"project_id": "ossf-malware-analysis",
"pod_name": "workers-set-28",
"location": "us-central1-c",
"container_name": "worker"
}
},
"timestamp": "2022-05-03T21:57:55.238935409Z",
"severity": "WARNING",
"labels": {
},
"logName": "projects/ossf-malware-analysis/logs/stderr",
"sourceLocation": {
"file": "/src/internal/strace/strace.go",
"line": "264",
"function": "github.com/ossf/package-analysis/internal/strace.Parse"
},
"receiveTimestamp": "2022-05-03T21:57:56.544994861Z"
}
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at strace/strace.go:264 and inspect the Parse entry point around the reported failure. Use the logged gVisor openat event as the case to understand why parsing fails; done means the mechanism handles these strace events without emitting the shown parse error.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- devtools, operating-systems
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100