Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
kprobes for every tap, an alert wording fix, and a README
What's in this PR
taps: hook tcp_sendmsg/tcp_recvmsg with kprobes(bb4c86a). The socket tap iskprobe/tcp_sendmsg,kprobe/tcp_recvmsgandkretprobe/tcp_recvmsg; every TLS tap'speer_sendmsg/peer_recvmsgare kprobes too. fentry cannot attach on arm64 before 6.4 (AWS Graviton on Amazon Linux 2023 runs 6.1), and a kprobe attaches everywhere. The return probe takesskfrom the per-thread stash, the stash slot is cleared at entry, andactive_readsis anLRU_HASH, so a return the kretprobe pool skips can never copy from a stale buffer.alerts: name a stopped local port only next to a served API's failure(592a915). Found while capturing the README samples: a third party's unrelated 503 was getting "shop-payments stopped listening" attached to it.docs: README. CLI variant, personas debugging → SRE → DevOps (confirmed by Necco). No license section or badge: the repo is staying private and not open source for now.Kernel matrix on
kprobes: green on 6.1, 6.6, 6.12, 6.18, 7.2 and bpf-next. Attach and capture run by hand on arm64 6.1 (Debian 12) and 6.12 (Debian 13).✅ Reviewer action items
yeet loginlink on a test host, connect Slack at yeet.cx/settings, pick a channel, run--test-alert. The README describes what--test-alertdoes; a real post has not been made yet.<img>is commented out. A--discoverrun on the shop test box is the recording.demo/directory with the shop workload used for every sample, so "Try it without real traffic" can point at it instead ofpython3 -m http.server.About description
105 characters, no em-dash, leads with the definition's category.
Topic tags
How the flagged claims were resolved
kernel.bpf_stats_enabled=1: 16.3 ms of probe run time in 120 s (~0.014% of a core;on_sendmsg~2.1 µs,on_recvmsg_*~0.8 µs), stated as excluding kprobe firing cost.urllib, curl, and Node 20fetch(Debian's package, links systemlibssl; 8/8 calls read, from a process started after apiwatch). Ruby, PHP, nginx and Deno/Bun claims removed.unit remove→unit add→ start runs the new code; a--devservice picks it up on restart. Both written in.yeet service restart apiwatchand the"signedIn":truecheck.--test-alertyeet.alert; prints why and exits non-zero on failure, which is verified signed-out). The live post is the open item above./sys/kernel/btf/vmlinux,grepof the kernel config).Limits stated in the README that are new to the corpus
--portsthe socket tap copies every TCP call and the JS discards non-HTTP, which contradicts the corpus's canonical overhead answer; the README says so and points busy hosts at--ports.grpc-statustrailers) are not alerts; deferred to grpcsnoop.tcp_recvmsgconcurrency some reads are skipped, never miswritten.--ports.yeet findings worth an issue
yeet service unit add -I gh:...clones without runningmake, so an eBPF tool restart-loops on a missing.bpf.o, andyeet service startblocks while it does. The README's recipe builds first.yeet run .never builds a local directory, only remote sources. Covered in the FAQ.yeet service unit removeon a running service fails silently in a script; the followingunit addthen says "Unit 'watch' is taken". Stopping first works.Handoff