falco: Falco won't start on 0.36 - /sys/devices/system/cpu/cpu8/online: No such file or directory
Describe the bug
Since upgrading to 0.36 today - Falco won’t start with the following:
/sys/devices/system/cpu/cpu8/online: No such file or directory
How to reproduce it
Upgrade to release 0.36 from 0.35
Expected behaviour
Falco starts
Screenshots
N/A
Environment
- Falco version: 0.36
- System info:
- Cloud provider or hardware configuration: ESXi VM
- OS: Ubuntu 20.04.6
- Kernel:
5.4.0-163-generic #180-Ubuntu SMP Tue Sep 5 13:21:23 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
- Installation method: Helm/K3s
Additional context
About this issue
- Original URL
- State: closed
- Created 9 months ago
- Comments: 65 (35 by maintainers)
Wohoo, it’s running… forgot to override the driver installer image
During the community call an hour ago we proposed a patch release 0.36.1 for Falco that will surely cover this issue 😃 expect it in a couple of weeks!
no its not working
Awesome, I’ll remove the image override from the Flux HelmRelease when I get home and report back if there’s any issues.
Thank you very much for testing it!
@Andreagit97 thanks for the suggestion but I am experiencing this issue on an older kernel version (4.x).
I am so happy about this! So, I’ll come back and close this issue as solved once the libs PR is merged and libs are bumped on Falco master 😃 At least, then you’ll have Falco development images with working bpf engine!
I think this is good, I just bind mounted the file in one of the nodes🤣
Unfortunately not; for that, we would need to merge the libs PR and then merge the libs bump PR in Falco 😦 But i would love to test the fix before merging it in libs, and there we need your help ahah Thank you very much!
No container? 😥 I’ll try to work around it later.
It’s the same - cat /sys/devices/system/cpu/possible is 0-127 🤯
The patch is ready: https://github.com/falcosecurity/libs/pull/1373 Still, i’d love to understand what’s going on here 😄
🤯
At least if it didn’t work in the previous version I’d suspect something else, kernel upgrade for example. It doesn’t help that this seems to work in previous version and not this one.
Let me know what else I could try.
I’m just rolling back to the previous version for now
Here it is
It is not starting on any node, and they’ve not had any core count changed lately. I’ve even rebooted one node to make sure it’s not reboot related.
I think so; it seems like a way for the vm to allow increasing number of online cpus (ie: CPUs made available to the vm) without the need to reboot. I think Falco is not able to correctly manage this situation at the moment. Fact is, i don’t get how could Falco 0.35.1 work in the very same situation.
Yes, when using modern eBPF
When using old eBPF, the error is
Error: can't open /sys/devices/system/cpu/cpu8/online: No such file or directoryThanks for picking it up @FedeDP I forgot to mention - eBPF