Skip to content

test(drivers/syscall_exit/execveat_x): fix comm assertion#2702

Merged
poiana merged 1 commit intofalcosecurity:masterfrom
ekoops:ekoops/fix-execveat-driver-test
Oct 24, 2025
Merged

test(drivers/syscall_exit/execveat_x): fix comm assertion#2702
poiana merged 1 commit intofalcosecurity:masterfrom
ekoops:ekoops/fix-execveat-driver-test

Conversation

@ekoops
Copy link
Copy Markdown
Contributor

@ekoops ekoops commented Oct 23, 2025

What type of PR is this?

Uncomment one (or more) /kind <> lines:

/kind bug

/kind cleanup

/kind design

/kind documentation

/kind failing-test

/kind test

/kind feature

/kind sync

Any specific area of the project related to this PR?

Uncomment one (or more) /area <> lines:

/area API-version

/area build

/area CI

/area driver-kmod

/area driver-bpf

/area driver-modern-bpf

/area libscap-engine-bpf

/area libscap-engine-gvisor

/area libscap-engine-kmod

/area libscap-engine-modern-bpf

/area libscap-engine-nodriver

/area libscap-engine-noop

/area libscap-engine-source-plugin

/area libscap-engine-savefile

/area libscap

/area libpman

/area libsinsp

/area tests

/area proposals

Does this PR require a change in the driver versions?

/version driver-API-version-major

/version driver-API-version-minor

/version driver-API-version-patch

/version driver-SCHEMA-version-major

/version driver-SCHEMA-version-minor

/version driver-SCHEMA-version-patch

What this PR does / why we need it:

SyscallExit.execveatX_execve_exit_comm_equal_to_fd test asserts the comm parameter value among the others. For kernel versions lower than 6.14, if the AT_EMPTY_PATH flag is specified while invoking execveat, the comm value is expected to be set to the dirfd numeric value. Starting from 6.14 (torvalds/linux@543841d), this strange behaviour has been fixed, and the exact same execveat
invocation results in the comm value to be correctly set to the dentry's filename value. For this reason, this PR patches the test code to account for both scenarios while testing for the comm parameter to match the expectation.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?:

NONE

@codecov
Copy link
Copy Markdown

codecov bot commented Oct 23, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.62%. Comparing base (2b0684c) to head (3560b2a).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #2702   +/-   ##
=======================================
  Coverage   77.62%   77.62%           
=======================================
  Files         294      294           
  Lines       31951    31951           
  Branches     4716     4716           
=======================================
  Hits        24802    24802           
  Misses       7149     7149           
Flag Coverage Δ
libsinsp 77.62% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ekoops
Copy link
Copy Markdown
Contributor Author

ekoops commented Oct 23, 2025

/hold for further investigation.

`SyscallExit.execveatX_execve_exit_comm_equal_to_fd` test asserts the
`comm` parameter value among the others. For kernel versions lower
than 6.14, if the `AT_EMPTY_PATH` flag is specified while invoking
execveat, the comm value is expected to be set to the dirfd numeric
value. Starting from 6.14 (
torvalds/linux@543841d
), this strange behaviour has been fixed, and the exact same execveat
invocation results in the comm value to be correctly set to the
dentry's filename value. For this reason, account for both scenarios
while testing for the `comm` parameter to match the expectation.

Signed-off-by: Leonardo Di Giovanna <leonardodigiovanna1@gmail.com>
@ekoops ekoops force-pushed the ekoops/fix-execveat-driver-test branch from 645b916 to 3560b2a Compare October 23, 2025 14:22
@poiana poiana added size/M and removed size/XS labels Oct 23, 2025
@ekoops
Copy link
Copy Markdown
Contributor Author

ekoops commented Oct 23, 2025

Updated PR description with new findings

Copy link
Copy Markdown
Contributor

@irozzo-1A irozzo-1A left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
Just a nit, but it's your call

@github-project-automation github-project-automation bot moved this from Todo to In progress in Falco Roadmap Oct 23, 2025
@poiana
Copy link
Copy Markdown
Contributor

poiana commented Oct 23, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ekoops, irozzo-1A

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ekoops
Copy link
Copy Markdown
Contributor Author

ekoops commented Oct 24, 2025

/hold cancel

@poiana poiana merged commit e5cd113 into falcosecurity:master Oct 24, 2025
46 of 47 checks passed
@github-project-automation github-project-automation bot moved this from In progress to Done in Falco Roadmap Oct 24, 2025
@ekoops ekoops deleted the ekoops/fix-execveat-driver-test branch October 24, 2025 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants