Grafana Provisioning 中设置提交作者和主题
当前是 Grafana v13.1,设置好 Provisioning 后,默认提交作者和提交内容都一言难尽,还会固定添加 Grafana-saved-by
虽然 WebUI 中输入框只支持单行的,不过可以绕过 UI:Grafana 13.1 的 Git Sync Repository 本身是 CRD,官方支持用 gcx resources edit repository/<REPOSITORY_NAME> 修改 Repository 配置:
"spec": {
"commit": {
"signerEmail": "314952158+kokomi-grafana[bot]@users.noreply.github.com",
"signerName": "Kokomi Grafana",
"signerIsAuthor": true,
"singleResourceMessageTemplate": "{{action}} {{resourceKind}}: {{title}}\n\nGrafana-saved-by: {{userName}} ({{userLogin}})\nCo-Authored-By: {{userName}} \u003c{{userEmail}}\u003e"
},
},- 在
appendSavedByTrailer()有个判断,如果模板里自己已经写了Grafana-saved-by: ...Grafana 就不会再追加一次。 - Email 的构成见 使用 GitHub App 以 Bot 身份创建属于 AI Agent 的提交
- 目前 v13.1.0 Author 还不好改 Git Sync: Commit author remains noreply@grafana.com when custom signer identity is configured · Issue #129908 · grafana/grafana,目前固定为
Grafana <noreply@grafana.com>,倒是有个还未上线的 Provisioning: Attribute Git Sync commits to the acting user by amalavet · Pull Request #127983 · grafana/grafana 功能可以试试
v13.2 修复了单行文本的问题
题目的 print_disassembly 不打印地址反而是内存内容
在解 Microarchitecture Exploitation - Prefetch Peek 时会显示传入的 shellcode 反编译后的内容,这部分定义在二进制的 print_disassembly() 中,依赖了 capstone。
正常来讲会输出这样的
This challenge is about to execute the following shellcode:
Address | Bytes | Instructions
------------------------------------------------------------------------------------------
0x0000013333370000 | 49 b9 00 00 00 00 00 01 00 00 | movabs r9, 0x10000000000
0x000001333337000a | 49 c7 c4 00 00 01 00 | mov r12, 0x10000
0x0000013333370011 | bf 00 00 00 00 | mov edi, 0
0x0000013333370016 | b8 3c 00 00 00 | mov eax, 0x3c
0x000001333337001b | 0f 05 | syscall但这次,我为了快速迭代,在本地 ArchLinux 搭建了个运行环境,说是搭建,也就是把文件复制过来本地运行。
跑起来却输出这样:
This challenge is about to execute the following shellcode:
Address | Bytes | Instructions
------------------------------------------------------------------------------------------
0x00000000b949000a | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6d 6f 76 61 62 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 72 39 2c 20 30 78 31 30 30 30 30 30 30 30 30 30 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc 01 00 00 00 00 00 00 0a 00 37 33 33 01 00 00 07 00 49 c7 c4 00 00 01 00 00 00 00 00 00 00 00 00 00 | 000000000
0x0000000000000000 | |
0x0000000000000000 | |
0x000000726f780000 | | r15d, r15d
0x0000000000000000 | |这里的 Address 看上去就是上面的 Bytes 部分。
通过把 dojo 里的 /lib/libcapstone.so.5 复制到本地,并用 LD_LIBRARY_PATH="$(pwd)" ./babyarch_prefetchpeek 运行(注意程序不能有 setuid bit),验证 dojo 版本的可以正常运行。
分析是 print_disassembly() 寻找地址的指令偏移量不对,两边版本有差异。