mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
Delete /cloud/gvisor/sandbox/sentry/gofer/opened_write_execute_file metric
This metric is replaced by /cloud/gvisor/sandbox/sentry/suspicious_operations metric with field value opened_write_execute_file. PiperOrigin-RevId: 374509823
This commit is contained in:
committed by
gVisor bot
parent
8ff6694e54
commit
e4984f8539
@@ -92,7 +92,6 @@ func NewFile(ctx context.Context, dirent *fs.Dirent, name string, flags fs.FileF
|
||||
}
|
||||
if flags.Write {
|
||||
if err := dirent.Inode.CheckPermission(ctx, fs.PermMask{Execute: true}); err == nil {
|
||||
fsmetric.GoferOpensWX.Increment()
|
||||
metric.SuspiciousOperationsMetric.Increment("opened_write_execute_file")
|
||||
log.Warningf("Opened a writable executable: %q", name)
|
||||
}
|
||||
|
||||
@@ -60,7 +60,6 @@ func newRegularFileFD(mnt *vfs.Mount, d *dentry, flags uint32) (*regularFileFD,
|
||||
return nil, err
|
||||
}
|
||||
if fd.vfsfd.IsWritable() && (atomic.LoadUint32(&d.mode)&0111 != 0) {
|
||||
fsmetric.GoferOpensWX.Increment()
|
||||
metric.SuspiciousOperationsMetric.Increment("opened_write_execute_file")
|
||||
}
|
||||
if atomic.LoadInt32(&d.mmapFD) >= 0 {
|
||||
|
||||
@@ -101,7 +101,6 @@ func newSpecialFileFD(h handle, mnt *vfs.Mount, d *dentry, flags uint32) (*speci
|
||||
d.fs.specialFileFDs[fd] = struct{}{}
|
||||
d.fs.syncMu.Unlock()
|
||||
if fd.vfsfd.IsWritable() && (atomic.LoadUint32(&d.mode)&0111 != 0) {
|
||||
fsmetric.GoferOpensWX.Increment()
|
||||
metric.SuspiciousOperationsMetric.Increment("opened_write_execute_file")
|
||||
}
|
||||
if h.fd >= 0 {
|
||||
|
||||
@@ -42,7 +42,6 @@ var (
|
||||
|
||||
// Metrics that only apply to fs/gofer and fsimpl/gofer.
|
||||
var (
|
||||
GoferOpensWX = metric.MustCreateNewUint64Metric("/gofer/opened_write_execute_file", true /* sync */, "Number of times a executable file was opened writably from a gofer.")
|
||||
GoferOpens9P = metric.MustCreateNewUint64Metric("/gofer/opens_9p", false /* sync */, "Number of times a file was opened from a gofer and did not have a host file descriptor.")
|
||||
GoferOpensHost = metric.MustCreateNewUint64Metric("/gofer/opens_host", false /* sync */, "Number of times a file was opened from a gofer and did have a host file descriptor.")
|
||||
GoferReads9P = metric.MustCreateNewUint64Metric("/gofer/reads_9p", false /* sync */, "Number of 9P file reads from a gofer.")
|
||||
|
||||
Reference in New Issue
Block a user