forked from osquery/osquery
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add flipType, isTypeEnter, isTypeExit for the systemcall event types (o…
…squery#5416) Summary: Pull Request resolved: osquery#5416 To able to invert type from enter to exit and determine if type is exit or enter. Part of a linux tracing system, blueprint: [osquery#5218](osquery#5218) Reviewed By: SAlexandru Differential Revision: D13761673 fbshipit-source-id: 2bf668219fd996d9d5b67e0e1ccf5c1161a41481
- Loading branch information
1 parent
8871a1a
commit 344fbed
Showing
3 changed files
with
85 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -20,6 +20,7 @@ osquery_cxx_test( | |
LINUX, | ||
[ | ||
"ebpf_tracepoint.cpp", | ||
"syscall_event.cpp", | ||
], | ||
), | ||
], | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,71 @@ | ||
/** | ||
* Copyright (c) 2014-present, Facebook, Inc. | ||
* All rights reserved. | ||
* | ||
* This source code is licensed under both the Apache 2.0 license (found in the | ||
* LICENSE file in the root directory of this source tree) and the GPLv2 (found | ||
* in the COPYING file in the root directory of this source tree). | ||
* You may select, at your option, one of the above-listed licenses. | ||
*/ | ||
|
||
#include <gtest/gtest.h> | ||
|
||
#include <osquery/events/linux/probes/syscall_event.h> | ||
|
||
namespace osquery { | ||
namespace { | ||
|
||
class SyscallsTracepointTests : public testing::Test {}; | ||
|
||
template <events::syscall::Type enter, events::syscall::Type exit> | ||
void checkEventPair() { | ||
static_assert(enter == events::syscall::flipType(exit), | ||
"flipType have to flip Exit to Enter"); | ||
static_assert(exit == events::syscall::flipType(enter), | ||
"flipType have to flip Enter to Exit"); | ||
static_assert( | ||
enter == events::syscall::flipType(events::syscall::flipType(enter)), | ||
"flipType applied twice to Enter have to return exactly the same Enter"); | ||
static_assert( | ||
exit == events::syscall::flipType(events::syscall::flipType(exit)), | ||
"flipType applied twice to Exit have to return exactly the same Exit"); | ||
} | ||
|
||
TEST_F(SyscallsTracepointTests, SyscallEvent_flipType) { | ||
checkEventPair<events::syscall::Type::KillEnter, | ||
events::syscall::Type::KillExit>(); | ||
checkEventPair<events::syscall::Type::SetuidEnter, | ||
events::syscall::Type::SetuidExit>(); | ||
static_assert(events::syscall::Type::Unknown == | ||
events::syscall::flipType(events::syscall::Type::Unknown), | ||
"syscall::Type::Unknown could not be fliped"); | ||
} | ||
|
||
TEST_F(SyscallsTracepointTests, SyscallEvent_isTypeExit) { | ||
static_assert(events::syscall::isTypeExit(events::syscall::Type::KillExit), | ||
""); | ||
static_assert(events::syscall::isTypeExit(events::syscall::Type::SetuidExit), | ||
""); | ||
static_assert(!events::syscall::isTypeExit(events::syscall::Type::Unknown), | ||
""); | ||
static_assert( | ||
!events::syscall::isTypeExit(events::syscall::Type::SetuidEnter), ""); | ||
static_assert( | ||
!events::syscall::isTypeExit(events::syscall::Type::SetuidEnter), ""); | ||
} | ||
|
||
TEST_F(SyscallsTracepointTests, SyscallEvent_isTypeEnter) { | ||
static_assert(!events::syscall::isTypeEnter(events::syscall::Type::KillExit), | ||
""); | ||
static_assert( | ||
!events::syscall::isTypeEnter(events::syscall::Type::SetuidExit), ""); | ||
static_assert(!events::syscall::isTypeEnter(events::syscall::Type::Unknown), | ||
""); | ||
static_assert( | ||
events::syscall::isTypeEnter(events::syscall::Type::SetuidEnter), ""); | ||
static_assert( | ||
events::syscall::isTypeEnter(events::syscall::Type::SetuidEnter), ""); | ||
} | ||
|
||
} // namespace | ||
} // namespace osquery |