Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bpf-recorder needs /sys/kernel/tracing/events/raw_syscalls/sys_enter/id
spod crashes when using the eBPF based recorder, because the container cannot access /sys/kernel/tracing/events/raw_syscalls/sys_enter/id: I0122 08:11:14.334147 9234 bpfrecorder.go:517] "Excluding mount namespace" logger="bpf-recorder" mntns=4026531841 I0122 08:11:14.335822 9234 bpfrecorder.go:534] "BPF module successfully loaded." logger="bpf-recorder" I0122 08:11:14.335896 9234 bpfrecorder.go:218] "Doing BPF start/stop self-test..." logger="bpf-recorder" I0122 08:11:14.335967 9234 bpfrecorder.go:541] "Start BPF recording: Attaching all programs..." logger="bpf-recorder" libbpf: failed to open '/sys/kernel/tracing/events/raw_syscalls/sys_enter/id': No such file or directory libbpf: failed to determine tracepoint 'raw_syscalls/sys_enter' perf event ID: No such file or directory libbpf: prog 'sys_enter': failed to create tracepoint 'raw_syscalls/sys_enter' perf event: No such file or directory I0122 08:11:14.335948 9234 bpfrecorder.go:698] "Processing bpf events" logger="bpf-recorder" E0122 08:11:14.336538 9234 main.go:240] "running security-profiles-operator" err="StartRecording self-test: attach base hooks: attach bpf program sys_enter: failed to attach program: no such file or directory" logger="setup"
- Loading branch information