Skip to content

feat(filter): Add Linux filter fields and accessors - #731

Merged
rabbitstack merged 4 commits into
rabbitstack:linux-portfrom
mostafa:feat/linux-filter-fields
Sep 16, 2026
Merged

rabbitstack merged 4 commits into
rabbitstack:linux-portfrom
mostafa:feat/linux-filter-fields

Conversation

@mostafa

@mostafa mostafa commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

What is the purpose of this PR / why it is needed?

Makes the syscall telemetry introduced on linux-port filterable. The Linux field catalog grows from five identity fields to the full event matrix, and real accessors replace the noop stubs for the file, network, memory, and thread families.

Shared field names are reused only where the semantics match the Windows counterpart: file.path, file.name, file.extension, file.path.stem, net.dip/net.sip/net.dport/net.sport, mem.address/mem.size/mem.protection, ps.uuid, and the parent process fields. Windows-specific fields (mem.type, mem.alloc, registry.*, pe.*, handle.*, dns.*, and the deprecated kevt.* aliases) do not enter the Linux catalog and fail to compile in a filter expression. Linux-native concepts get their own names: ps.uid/ps.gid, ps.signal, ps.target.pid, ps.ptrace.request, ps.prctl.option, ps.clone.flags, file.new_path/file.dirfd/file.fd/file.flags/file.mode/file.truncated, net.family/net.path/net.fd, mem.flags/mem.fd/mem.offset/mem.target.pid, thread.tid/thread.pid, and evt.retval/evt.syscall/evt.truncated.

The deprecated kevt.* aliases move from the common catalog into the Windows platform catalog, so Windows behavior is unchanged while new Linux filters use the supported evt.* names from the start.

What type of change does this PR introduce?


/kind feature

Any specific area of the project related to this PR?


/area filters

/area tests

Special notes for the reviewer


  • Integration base is linux-port, not master.
  • File, network, and memory accessors follow enable-fileio, enable-net, and enable-mem, mirroring how the Windows constructor gates its accessors. The thread accessor is always on and only answers for thread-creating clones.
  • The evt accessor resolves evt.retval, evt.syscall, and evt.truncated through a platform hook because the backing parameter names exist only on Linux; the Windows hook is a noop, so the shared accessor compiles on both platforms.
  • file.truncated reports either truncation bit for file events, since the aux buffer holds the rename destination path there.
  • mem.protection, mem.flags, and file.flags/file.mode expose the raw bitmask/mode values captured by the eBPF programs; symbolic rendering can layer on top later without changing field identity.
  • Verified:
    • Docker Linux: go test ./pkg/filter/... ./pkg/rules/
    • Windows cross-compilation: GOOS=windows go build ./pkg/... and go vet ./pkg/filter/...
    • Tests assert compile and evaluation for every Linux event type, shared-name semantics, missing-value defaults, truncation bits, and that Windows-only and kevt.* fields are rejected at compile time.

Does this PR introduce a user-facing change?


Yes. On Linux, filter expressions and rules can now reference process, file, network, memory, and thread fields for all captured syscall events, for example fibratus run evt.name = 'connect' and net.dport = 443.

Keep deprecated kevt aliases on Windows so they never enter the Linux catalog, and register process, file, network, memory, and thread fields for the captured syscalls.
…ad fields

Wire accessors for the syscall event matrix, gate file/net/mem on the existing enable flags, and expose syscall return, number, and truncation on evt fields.
…uncation

Prove shared-name semantics, missing-value defaults, truncation bits, and that Windows-only and kevt fields cannot compile.

@rabbitstack rabbitstack left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, after addressing the changes!

Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Comment thread pkg/filter/fields/defs.go Outdated
Drop first-class truncated fields so callers inspect the truncated parameter through evt.arg.
@rabbitstack
rabbitstack merged commit 9a41dbf into rabbitstack:linux-port Sep 16, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants