Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion pkg/security/ebpf/c/include/helpers/span_nodejs.h
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ static int __attribute__((always_inline)) otel_nodejs_record_ptr(
// holds the record pointer directly. Unlike the wrapper, the record is a
// byte buffer the writer allocates: nothing says it is aligned.
u64 record = 0;
if (otel_v8_read_word(otel_v8_untag(value) + v8->js_object_record_offset, &record)) {
if (otel_v8_read_word(otel_v8_untag(value) + nctx->record_slot_offset, &record)) {
return 0;
}
// Cleared when the isolate is torn down.
Expand Down
6 changes: 3 additions & 3 deletions pkg/security/ebpf/c/include/structs/span_context.h
Original file line number Diff line number Diff line change
Expand Up @@ -126,8 +126,7 @@ struct otel_v8_layout_t {
u16 tagged_size; // width of a tagged word; only 8 is supported
u16 js_map_table_offset; // JSMap -> backing OrderedHashMap
u16 ordered_hash_map_header_size; // header before the OrderedHashMap fields
u16 js_object_record_offset; // JSObject -> internal field 0, the record pointer
u16 _pad[4];
u16 _pad[5];
};

// OTel TLS registration for a process, written once by user space after
Expand All @@ -148,7 +147,8 @@ struct otel_nodejs_ctx_t {
u64 cped_slot; // isolate slot holding the live AsyncContextFrame
u64 als_handle; // handle to the AsyncLocalStorage the frame is keyed by
u32 als_identity_hash; // its identity hash, which picks a single bucket
u32 _pad;
u8 record_slot_offset; // JSObject -> internal field 0, the record pointer
u8 _pad[3];
u64 undefined_addr; // this isolate's undefined, i.e. "no context here"
};

Expand Down
5 changes: 1 addition & 4 deletions pkg/security/resolvers/process/otel_tls.go
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,6 @@ type otelV8Layout struct {
taggedSize uint16
jsMapTableOffset uint16
orderedHashMapHeaderSize uint16
jsObjectRecordOffset uint16
}

// otelNodeJSSchemaVersion is one schema version the Node.js writer may
Expand All @@ -90,7 +89,6 @@ var otelNodeJSSchemaVersions = []otelNodeJSSchemaVersion{
taggedSize: otelSupportedTaggedSize,
jsMapTableOffset: 0x18,
orderedHashMapHeaderSize: 0x10,
jsObjectRecordOffset: 0x18,
},
},
}
Expand Down Expand Up @@ -165,8 +163,7 @@ func serializeOTelTLSValue(res otelTLSResolution) []byte {
binary.NativeEndian.PutUint16(buf[32:34], res.v8.taggedSize)
binary.NativeEndian.PutUint16(buf[34:36], res.v8.jsMapTableOffset)
binary.NativeEndian.PutUint16(buf[36:38], res.v8.orderedHashMapHeaderSize)
binary.NativeEndian.PutUint16(buf[38:40], res.v8.jsObjectRecordOffset)
// buf[40:48] is otel_v8_layout_t._pad, intentionally left zero.
// buf[38:48] is otel_v8_layout_t._pad, intentionally left zero.
return buf
}

Expand Down
15 changes: 5 additions & 10 deletions pkg/security/tests/syscall_tester/c/otel_nodejs_common.h
Original file line number Diff line number Diff line change
Expand Up @@ -30,10 +30,8 @@
#include "otel_process_ctx_common.h"
#include "otel_tls_common.h"

// --- V8 layout, as the writer publishes it in its process context ---
// --- V8 layout the nodejs_v1 schema implies ---

#define OTEL_NODEJS_TAGGED_SIZE 8
#define OTEL_NODEJS_JS_MAP_TABLE_OFFSET 0x18
#define OTEL_NODEJS_OHM_HEADER_SIZE 0x10
#define OTEL_NODEJS_JS_OBJECT_RECORD_OFFSET 24

Expand All @@ -58,7 +56,8 @@ struct otel_thread_ctx_nodejs {
uint64_t cped_slot;
uint64_t als_handle;
int32_t als_identity_hash;
int32_t _pad;
uint8_t record_slot_offset;
uint8_t _pad[3];
uint64_t undefined_addr;
};

Expand Down Expand Up @@ -168,6 +167,7 @@ static inline void otel_nodejs_build(struct otel_nodejs_graph *g, enum otel_node
g->discovery.cped_slot = (uint64_t)(uintptr_t)&g->cped;
g->discovery.als_handle = (uint64_t)(uintptr_t)&g->als_slot;
g->discovery.als_identity_hash = OTEL_NODEJS_ALS_HASH;
g->discovery.record_slot_offset = OTEL_NODEJS_JS_OBJECT_RECORD_OFFSET;
g->discovery.undefined_addr = g->undefined;
}

Expand All @@ -185,16 +185,11 @@ static const char *const otel_nodejs_attribute_keys[] = {
};

// otel_nodejs_encode_process_ctx writes the process context payload of a Node.js
// writer: the schema its records follow, the key names their attributes select,
// and the V8 layout the reader walks them with.
// writer: the schema its records follow and the key names their attributes select.
static inline size_t otel_nodejs_encode_process_ctx(uint8_t *out) {
size_t off = otel_pb_string_attribute(out, "threadlocal.schema_version", "nodejs_v1_dev");
off += otel_pb_string_array_attribute(out + off, "threadlocal.attribute_key_map", otel_nodejs_attribute_keys,
sizeof(otel_nodejs_attribute_keys) / sizeof(otel_nodejs_attribute_keys[0]));
off += otel_pb_int_attribute(out + off, "threadlocal.tagged_size", OTEL_NODEJS_TAGGED_SIZE);
off += otel_pb_int_attribute(out + off, "threadlocal.js_map_table_offset", OTEL_NODEJS_JS_MAP_TABLE_OFFSET);
off += otel_pb_int_attribute(out + off, "threadlocal.ordered_hash_map_header_size", OTEL_NODEJS_OHM_HEADER_SIZE);
off += otel_pb_int_attribute(out + off, "threadlocal.js_object_record_offset", OTEL_NODEJS_JS_OBJECT_RECORD_OFFSET);
return off;
}

Expand Down
13 changes: 0 additions & 13 deletions pkg/security/tests/syscall_tester/c/otel_process_ctx_common.h
Original file line number Diff line number Diff line change
Expand Up @@ -45,11 +45,9 @@ struct otel_process_ctx_header {
#define OTEL_PB_KV_KEY 1
#define OTEL_PB_KV_VALUE 2
#define OTEL_PB_ANY_STRING 1
#define OTEL_PB_ANY_INT 3
#define OTEL_PB_ANY_ARRAY 5
#define OTEL_PB_ARRAY_VALUES 1

#define OTEL_PB_WIRE_VARINT 0
#define OTEL_PB_WIRE_BYTES 2

static inline size_t otel_pb_varint(uint8_t *out, uint64_t value) {
Expand Down Expand Up @@ -80,11 +78,6 @@ static inline size_t otel_pb_string_value(uint8_t *out, const char *value) {
return otel_pb_bytes(out, OTEL_PB_ANY_STRING, value, strlen(value));
}

static inline size_t otel_pb_int_value(uint8_t *out, int64_t value) {
size_t off = otel_pb_tag(out, OTEL_PB_ANY_INT, OTEL_PB_WIRE_VARINT);
return off + otel_pb_varint(out + off, (uint64_t)value);
}

// Appends one KeyValue of the extra attributes, its value already encoded as an
// AnyValue in `value`.
static inline size_t otel_pb_attribute(uint8_t *out, const char *key, const uint8_t *value, size_t value_len) {
Expand All @@ -100,12 +93,6 @@ static inline size_t otel_pb_string_attribute(uint8_t *out, const char *key, con
return otel_pb_attribute(out, key, any, any_len);
}

static inline size_t otel_pb_int_attribute(uint8_t *out, const char *key, int64_t value) {
uint8_t any[32];
size_t any_len = otel_pb_int_value(any, value);
return otel_pb_attribute(out, key, any, any_len);
}

static inline size_t otel_pb_string_array_attribute(uint8_t *out, const char *key, const char *const *values,
size_t count) {
uint8_t array[512];
Expand Down
Loading