Repository navigation
feat(build): Package Fibratus for Linux and complete the CLI surface - #738
Merged
rabbitstack merged 4 commits intoSep 23, 2026
Merged
Conversation
The shared default bound the API to localhost:8080, so a Linux install listened on the network before anyone asked it to. Defaulting to a socket under /var/run leaves reachability to filesystem permissions, and a TCP address still works when it is set explicitly. Windows keeps its existing default through the same platform hook the config file and rule paths already use.
rabbitstack
reviewed
Sep 23, 2026
Ships the binary, a Linux configuration, the rules, and a service unit. The BPF objects need no separate packaging because bpf2go embeds them in the binary. The unit starts as root, since attaching a syscall tracepoint reads its id from /sys/kernel/tracing and that is root-only on stock kernels. What constrains it is the bounding set, which drops everything except loading programs, attaching to tracepoints, reading other users' procfs entries, and signalling a target for the kill action. ProtectSystem is full rather than strict because strict also mounts /run read-only and the API socket lives there, and ProtectProc stays permissive because hiding other processes would silently empty ps.exe and ps.cmdline. The shipped configuration omits the Windows-only sections instead of carrying them inert, so what is in the file is what the platform reads.
The Linux Stats struct was an empty placeholder, so the command rendered a table with no rows against a sensor that publishes a dozen counters. It now carries the capture, drop, startup handover, and rule engine expvars, grouped in the order they are useful to read. Covers the endpoints the config and stats commands call over a socket and over TCP, including a socket left behind by an unclean shutdown, which would otherwise need manual cleanup before a restart. The privileged test drives the same path against a live capture, since unit tests can only prove the counters exist, not that a running sensor moves them.
Covers the package layout, running in the foreground against a filter, and the service. Notes that an idle host with rules enabled is expected to be quiet, since only matching events reach the outputs and silence otherwise reads as a broken install. Records why the unit runs as root and what the bounding set leaves it.
mostafa
force-pushed
the
feat/linux-packaging
branch
from
September 23, 2026 18:12
8270866 to
318ee22
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Completes the Linux port: distribution packages, a service unit, the command surface an operator uses to inspect a running sensor, and install docs.
Packaging
make pkgproduces a deb and an rpm through nfpm. Both carry the binary, a Linux configuration, the shipped rules, and the service unit. Nothing else needs packaging, because bpf2go embeds the BPF objects in the binary, so an install pulls in no compiler and no kernel headers./usr/bin/fibratus/etc/fibratus/fibratus.yml/etc/fibratus/rules/,rules/macros//lib/systemd/system/fibratus.service/usr/lib/...on RPM distributionsVerified by installing rather than by building: the deb on Ubuntu 24.04 and the rpm on Rocky 9, checking the installed layout, that the binary runs, that
fibratus rules validatepasses against the installed configuration, and thatsystemd-analyze verifyaccepts the unit. CI builds both and uploads them.The shipped configuration leaves out the Windows-only sections rather than carrying them inert, so what is in the file is what the platform actually reads.
Service unit
The unit starts as root on purpose. Attaching a syscall tracepoint reads its id from
/sys/kernel/tracing, which is root-only on stock distributions, so a dedicated user would need tracefs loosened first. What constrains the process is the bounding set, which drops everything except:CAP_BPFto load programs and mapsCAP_PERFMONto attach to tracepointsCAP_SYS_PTRACEto read other users'/proc/<pid>/exeandcmdlineCAP_KILL, needed only when a rule uses the kill actionTwo hardening choices are deliberate and commented in the unit.
ProtectSystem=fullrather thanstrict, because strict also mounts/runread-only and the API socket lives there. AndProtectProc=default, because hiding other processes would silently emptyps.exeandps.cmdlineinstead of failing visibly.API transport default
The shared default bound the API to
localhost:8080, so a Linux install listened on the network before anyone asked it to. It now defaults tounix:///var/run/fibratus.sock, leaving reachability to socket permissions; a TCP address still works when set explicitly. Windows keeps its existing default through the same platform hook the config file and rule paths already use.Stats
The Linux
Statsstruct was an empty placeholder, sofibratus statsrendered a table with no rows while the sensor published a dozen counters. It now carries the capture counters, the two drop counters worth alerting on, the startup handover, and the rule engine, ordered the way they are useful to read.Coverage
fibratus configandfibratus statsactually call, plus a socket left behind by an unclean shutdown, which would otherwise need manual cleanup before a restart.make test, lint,GOOS=windows go build ./..., and the documented quick-start commands run against the installed package.