Using CO:RE to Achieve Portable Tracee eBPF Code
ID: 0af33522-d7a0-5f05-87fb-6591f30f913f
STIX ID: report--0af33522-d7a0-5f05-87fb-6591f30f913f
Feed Name: Aqua Security Blog
This blog details how the Tracee runtime security tool adopted libbpf's CO:RE to handle kernel structure changes across Linux versions: the team committed a generated vmlinux.h, updated their READ_KERN macro to use bpf_core_read (with associated un-nesting changes), maintained missing system macro headers, mitigated verifier and BPF stack-size issues, and implemented a distribution approach that embeds a CO:RE-enabled BPF object while falling back to kernel-specific objects when needed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
