fix(seccomp): drop unrecognized syscall numbers instead of recording "unknown" (#916)
* fix(seccomp): drop unrecognized syscall numbers instead of recording "unknown" decodeSyscalls recorded any syscall number it could not resolve under the literal name "unknown". That name flows into the container profile, is merged into the application profile, and ends up in generated seccomp profiles, where "unknown" is not a valid syscall name. Skip the entry and log the number instead, so profiles only ever contain names the kernel can match. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Docs-exempt: bug fix, no documented behavior changes Signed-off-by: Rotem Refael <rotem@armosec.io> * refactor(seccomp): log skipped syscall numbers once per decode Review follow-up. decodeSyscalls runs for every tracer event, so logging per unresolved number could emit many lines per container every fetch interval. Collect the numbers and log them in one line instead, and drop a confusing magic expression in the test. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Docs-exempt: logging only, no behavioral change Signed-off-by: Rotem Refael <rotem@armosec.io> --------- Signed-off-by: Rotem Refael <rotem@armosec.io>
R
Rotem Refael committed
39ac104f65f42dce004584843f45012b2a6814b6
Parent: 68fd3a1
Committed by GitHub <noreply@github.com>
on 8/24/2026, 1:41:55 PM