fix: update test with latest libs fix #60
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Test
TestFalco_Legacy_NonSudoSetuid
was affected by the bug reported here falcosecurity/libs#1923. A thread with vtid=-1 was considered as a container thread and for this reason, we didn't match the rule because of this conditioncontainer and not user.name in ("<NA>","N/A","")
. The user is NA and before the fix, we were considered in a container.Now with the fix, we are no longer in a container so the rule correctly triggers. Full rule output with addition of
thread.vtid
andthread.tid