SIGN IN SIGN UP

fix(node-agent): fix ContainerProfile size accounting in ReportSyscall and ReportNetworkEvent (#882)

* fix(containerprofile): make MaxTsProfileSize account bytes consistently

ReportSyscall added mapset.Append's return (element count, 0 or 1) straight
into the byte-size accumulator, so syscalls contributed ~nothing toward
MaxTsProfileSize. ReportNetworkEvent also sized only the raw NetworkEvent,
missing the Identifier/DNS/selector fields createNetworkNeighbor adds at
serialization - both let the pre-send estimate undercount, so profiles kept
growing past storage's own cap instead of flushing early.

Fixes #870.

Signed-off-by: aryanghai12 <aryanghai1205@gmail.com>

* fix(containerprofile): derive networkNeighborExpansionEstimate from documented bounds

The flat 256-byte surcharge was an unjustified guess: RFC 1035's max DNS name
(253 bytes) alone, stored twice in DNS/DNSNames, already exceeds it before
counting the Identifier, Ports entry, or selector maps createNetworkNeighbor
adds at serialization. Replace it with a value computed from each field's
documented worst case (sha256-hex identifier, RFC 1035 DNS name, exact
NamespaceSelector shape, a generously budgeted PodSelector label count), and
add tests that run the real createNetworkNeighbor path against a max-length
DNS name and a populated selector payload to confirm the estimate covers it.

Signed-off-by: aryanghai12 <aryanghai1205@gmail.com>

* fix(containerprofile): scope network neighbor size estimate to the actual serialization branch

The flat surcharge summed every createNetworkNeighbor branch onto every event,
overcounting by 6-20x and making ProfileRequiresSplit the normal path instead
of a rare backstop. Charge only the branch Destination.Kind actually takes:
Ports/NamespaceSelector are computed exactly from data already on the event,
PodSelector charges only the map-wrapping delta over what's already counted
via Destination.PodLabels, and DNS/Service-selector budgets apply only on
their respective branches. Drop LFX_AGENT_SANDBOX_PREP.md from .gitignore
(moved to .git/info/exclude) and restore the file's trailing newline.

Signed-off-by: aryanghai12 <aryanghai1205@gmail.com>

---------

Signed-off-by: aryanghai12 <aryanghai1205@gmail.com>
A
Aryan Ghai committed
7c657b357c18dce3f9a8a4552a669aaac5c3d31e
Parent: 61d695f
Committed by GitHub <noreply@github.com> on 8/7/2026, 5:56:49 AM