SIGN IN SIGN UP

Chore/retire headless proc regex in favor of opens-gadget fix -- remove band-aid from last week (#889)

* gadget(trace_open): resolve relative opens against dirfd/cwd

trace_open resolved a full path only from the descriptor a successful open
returned, so a relative open had no absolute path and a failed open had no
descriptor at all. Userspace fell back to the raw relative name, which was
then promoted to a bogus root: a process chdir'd into a directory and opening
base/<oid>/<relfile> or backup_label, or speculatively probing files that do
not exist yet, was recorded as /base/<oid>/<relfile> or /backup_label.

Carry the dirfd through to the exit probe (AT_FDCWD for open, the openat
argument otherwise) and, when the resolved path is empty and the name is
relative, join the name against its base -- the process cwd for AT_FDCWD, else
the dirfd's path -- using the existing dentry walk. This runs regardless of the
syscall return value, so failed opens resolve too. The empty-walk case in
get_path_str now returns NULL instead of a pointer into the never-cleared
per-cpu scratch buffer, and the failed-open branch clears fpath.

trace_open is vendored from IG v0.48.1 and built from source under the same
image name node-agent pins, with the builder image pinned so the build is
reproducible across ig versions. Test_43_RelativeOpenPathResolution learns a
chdir'd relative-open workload and asserts the resolved absolute paths, no
fabricated roots, and that the failed open resolves.

Resolves #874

Signed-off-by: ConstanzeTU <74674840+ConstanzeTU@users.noreply.github.com>

* utils: drop headless /proc re-rooting from NormalizePath

The gadget now resolves relative opens against their dirfd/cwd, so /proc/<pid>
paths arrive already rooted. The headlessProcRegex re-rooting was a workaround
for the raw relative names the gadget used to emit (#721) and is no longer
reachable; a numeric first path segment is now treated as a literal directory
name rather than a stripped PID. The attribution regression net for #874 is
removed with it: the tracer no longer emits the ambiguous shapes it classified.

Signed-off-by: ConstanzeTU <74674840+ConstanzeTU@users.noreply.github.com>

* addressing the review

Signed-off-by: entlein <einentlein@gmail.com>

* addressing Matthias suggestions, now rerunning the 3 side compare

Signed-off-by: entlein <einentlein@gmail.com>

---------

Signed-off-by: ConstanzeTU <74674840+ConstanzeTU@users.noreply.github.com>
Signed-off-by: entlein <einentlein@gmail.com>
Co-authored-by: ConstanzeTU <74674840+ConstanzeTU@users.noreply.github.com>
D
Duck committed
11d6036b993f3ba29f339ef531510fb2ae01a09e
Parent: cac1668
Committed by GitHub <noreply@github.com> on 8/14/2026, 8:29:56 AM