Closed chenliu1993 closed 1 month ago
ei @chenliu1993 thank you for reporting! I will try to reproduce it!
Thank you so much!
I've reproduced the issue and I confirm that the one you reported is a valid repro! thank you for this! I'm working on a solution!
Hi @Andreagit97 , sry to ping, but do we have plan for putting this fix in 0.38.2 (if falco has plan) or 0.39.x?
hi @chenliu1993 ! Yes, this fix will be shipped in Falco 0.38.2 :)
hi @chenliu1993 ! Yes, this fix will be shipped in Falco 0.38.2 :)
That would be much helpful! we are using falco to do security things. Thanks for quick fix!
The new driver version is now released with Falco 0.38.2 🎉
Describe the bug
I am using falco 0.38 with -o
engine.kind=kmod
to run on redhat. but whenever there is a package management process start ed inside other containers likeapt-get
ordnf
will cause node crashes and reboot.How to reproduce it
first run falco with
and then run something like docker run --name=sysstat -it public.ecr.aws/docker/library/rockylinux:9.3.20231119-minimal microdnf install net-tools the process will get stuck at ... Installing: systemd-pam;252-32.el9_4;x86_64;baseos Installing: systemd;252-32.el9_4;x86_64;baseos .... actually node is rebooted. . A crash report would generate:
Expected behaviour
Should work same as modern_ebpf mode
Screenshots
Environment
Additional context