Skip to content

Commit

Permalink
chore: move finding event conversion to a package
Browse files Browse the repository at this point in the history
Opportunistic refactor. Logic does not relate to eBPF and does relate to
event data. Also allows importing this logic without importing eBPF
related code.
  • Loading branch information
NDStrahilevitz committed Nov 5, 2024
1 parent d0b0db3 commit 19d0ab4
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 4 deletions.
3 changes: 2 additions & 1 deletion pkg/ebpf/signature_engine.go
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ import (
"github.com/aquasecurity/tracee/pkg/containers"
"github.com/aquasecurity/tracee/pkg/dnscache"
"github.com/aquasecurity/tracee/pkg/events"
"github.com/aquasecurity/tracee/pkg/events/findings"
"github.com/aquasecurity/tracee/pkg/logger"
"github.com/aquasecurity/tracee/pkg/proctree"
"github.com/aquasecurity/tracee/pkg/signatures/engine"
Expand Down Expand Up @@ -124,7 +125,7 @@ func (t *Tracee) engineEvents(ctx context.Context, in <-chan *trace.Event) (<-ch
continue // might happen during initialization (ctrl+c seg faults)
}

event, err := FindingToEvent(finding)
event, err := findings.FindingToEvent(finding)
if err != nil {
t.handleError(err)
continue
Expand Down
2 changes: 1 addition & 1 deletion pkg/ebpf/finding.go → pkg/events/findings/findings.go
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
package ebpf
package findings

import (
"github.com/aquasecurity/tracee/pkg/errfmt"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
package ebpf
package findings_test

import (
"sort"
Expand All @@ -7,6 +7,7 @@ import (
"github.com/stretchr/testify/assert"

"github.com/aquasecurity/tracee/pkg/events"
"github.com/aquasecurity/tracee/pkg/events/findings"
"github.com/aquasecurity/tracee/types/detect"
"github.com/aquasecurity/tracee/types/protocol"
"github.com/aquasecurity/tracee/types/trace"
Expand Down Expand Up @@ -100,7 +101,7 @@ func TestFindingToEvent(t *testing.T) {
}

finding := createFakeEventAndFinding()
got, err := FindingToEvent(&finding)
got, err := findings.FindingToEvent(&finding)

assert.NoError(t, err)

Expand Down

0 comments on commit 19d0ab4

Please sign in to comment.