SIGN IN SIGN UP

fix(seccomp): drop unrecognized syscall numbers instead of recording "unknown" (#916)

* fix(seccomp): drop unrecognized syscall numbers instead of recording "unknown"

decodeSyscalls recorded any syscall number it could not resolve under the
literal name "unknown". That name flows into the container profile, is
merged into the application profile, and ends up in generated seccomp
profiles, where "unknown" is not a valid syscall name.

Skip the entry and log the number instead, so profiles only ever contain
names the kernel can match.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Docs-exempt: bug fix, no documented behavior changes
Signed-off-by: Rotem Refael <rotem@armosec.io>

* refactor(seccomp): log skipped syscall numbers once per decode

Review follow-up. decodeSyscalls runs for every tracer event, so logging
per unresolved number could emit many lines per container every fetch
interval. Collect the numbers and log them in one line instead, and drop
a confusing magic expression in the test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Docs-exempt: logging only, no behavioral change
Signed-off-by: Rotem Refael <rotem@armosec.io>

---------

Signed-off-by: Rotem Refael <rotem@armosec.io>
R
Rotem Refael committed
39ac104f65f42dce004584843f45012b2a6814b6
Parent: 68fd3a1
Committed by GitHub <noreply@github.com> on 8/24/2026, 1:41:55 PM