Skip to content

tracefs: discover mount via /proc/self/mountinfo#2004

Open
yoav-orca wants to merge 1 commit into
cilium:mainfrom
yoav-orca:feat/mountinfo-tracefs
Open

tracefs: discover mount via /proc/self/mountinfo#2004
yoav-orca wants to merge 1 commit into
cilium:mainfrom
yoav-orca:feat/mountinfo-tracefs

Conversation

@yoav-orca
Copy link
Copy Markdown

Lift the BPFFS mountinfo parser out of internal/sys into a new internal/mountinfo package, parameterized by filesystem type, and reuse it in internal/tracefs.

Tracefs auto-detection now consults /proc/self/mountinfo first: any tracefs mount is accepted regardless of its path, and a debugfs mount with an existing tracing/ subdirectory is used as a fallback. The hardcoded /sys/kernel/{tracing,debug/tracing} probe via statfs remains as a last-resort fallback for environments where mountinfo is unavailable, and to keep behavior identical on kernels that predate tracefs being lifted out of debugfs (Linux 4.1).

This removes the need for callers in containerized environments to bind-mount tracefs at the kernel-canonical paths just to make cilium/ebpf find it.

Closes #2000

@yoav-orca yoav-orca requested a review from a team as a code owner May 8, 2026 11:54
Lift the BPFFS mountinfo parser out of internal/sys into a new
internal/mountinfo package, parameterized by filesystem type, and reuse
it in internal/tracefs.

Tracefs auto-detection now consults /proc/self/mountinfo first: any
tracefs mount is accepted regardless of its path, and a debugfs mount
with an existing tracing/ subdirectory is used as a fallback. The
hardcoded /sys/kernel/{tracing,debug/tracing} probe via statfs remains
as a last-resort fallback for environments where mountinfo is
unavailable, and to keep behavior identical on kernels that predate
tracefs being lifted out of debugfs (Linux 4.1).

This removes the need for callers in containerized environments to
bind-mount tracefs at the kernel-canonical paths just to make
cilium/ebpf find it. internal/sys/token.go shrinks accordingly:
parseBPFFSMounts, readBPFFSMounts, and the unescape helper now live in
the new package and are tested there.

Closes cilium#2000

Signed-off-by: Yoav Alon <yoav@orca.security>
@yoav-orca yoav-orca force-pushed the feat/mountinfo-tracefs branch from 20dcdb3 to 02c30d5 Compare May 8, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

link: configurable tracefs path for /host-style container layouts

1 participant