Closed Andreagit97 closed 2 months ago
LGTM label has been added.
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: Andreagit97, LucaGuerra
The full list of commands accepted by this bot can be found here.
The pull request process is described here
Test
TestFalco_Legacy_NonSudoSetuid
was affected by the bug reported here https://github.com/falcosecurity/libs/pull/1923. A thread with vtid=-1 was considered as a container thread and for this reason, we didn't match the rule because of this conditioncontainer and not user.name in ("<NA>","N/A","")
. The user is NA and before the fix, we were considered in a container.Now with the fix, we are no longer in a container so the rule correctly triggers. Full rule output with addition of
thread.vtid
andthread.tid