M5: network collector with pid correlation - #5
Merged
Merged
Conversation
Reads the kernel's socket tables and turns changes into normalized net_connect / net_listen / net_accept events, correlated to a pid where that is possible. procnet.nim is pure parsing, which is where most of the risk lives: - Addresses are hex and LITTLE-ENDIAN PER 32-BIT WORD. 0100007F is 127.0.0.1, not 1.0.0.127. IPv6 is four little-endian words, so 2001:db8::1 is stored as B80D0120... — a whole-string reversal gets that wrong while still passing a ::1 test, so the suite tests a global address specifically. - Output is RFC 5952 canonical, so rules can match literal address strings. - State codes, ports, uid and the socket inode all parsed and tested, including malformed, truncated and header lines. network.nim diffs consecutive tables and attributes sockets to processes: - socketKey deliberately excludes state, so syn_sent -> established is one connection rather than two, and includes the inode so a reused four-tuple is correctly new. - Direction is partly inference and says so. SYN_SENT and LISTEN are facts; ESTABLISHED is a judgement based on whether the local port is also listened on. Every event carries raw.direction_basis with the reasoning, and the two knowable wrong cases are documented. - Teardown states emit nothing. Seeing FIN_WAIT first means the poll missed the connection's life, and dating the event at teardown would mislead. - Unattributed connections are still emitted, with pid UnknownId and a raw.pid_reason distinguishing 'no inode in the table' from 'cannot read another user's /proc/<pid>/fd — run as root'. The uid is still known even when the pid is not, so ownership is not lost. - /proc/*/fd is only walked when a new socket actually appeared, so a quiet interval costs nothing. 117 tests.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Milestone 5 — network collector
Stack: 4 of 6 · base
feat/m4-file-collector(PR #4) · next: M6 correlationprocnet.nim— pure parsing, where most of the risk lives0100007Fis127.0.0.1, not1.0.0.127. IPv6 is four little-endian words, so2001:db8::1is stored asB80D0120…— a whole-string reversal gets that wrong while still passing a::1test, so the suite tests a global address specifically.network.nim— diffing and pid attributionsocketKeydeliberately excludes state, sosyn_sent → establishedis one connection rather than two, and includes the inode so a reused four-tuple is correctly new.SYN_SENTandLISTENare observed facts;ESTABLISHEDis a judgement based on whether the local port is also listened on. Every event carriesraw.direction_basiswith the reasoning, and the two knowable wrong cases are documented.FIN_WAITfirst means the poll missed the connection's life; dating the event at teardown would mislead.UnknownIdand araw.pid_reasondistinguishing "no inode in the table" from "cannot read another user's/proc/<pid>/fd— run as root". The uid is still known even when the pid isn't, so ownership isn't lost./proc/*/fdis only walked when a new socket actually appeared, so a quiet interval costs nothing.Verification
117 tests (64 parsing + 53 collector), 594 total at this point, all green. Verified in an isolated worktree.