[WIP] feat: extend string data filtering to LSM related events #4590
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
1. Explain what the PR does
68b5feb test: external triggers for integration
db02b57 feat(ebpf): extend string data filtering for LSM events
7a42ae3 feat: allow different field names
68b5feb test: external triggers for integration
db02b57 feat(ebpf): extend string data filtering for LSM events
7a42ae3 feat: allow different field names
2. Explain how to test it
3. Other comments
This PR only focus on LSM hooks and the related tests.
part of #4432
pathname
5
pathname
1
(already present)pathname
3
path
map_name
pathname
4
file_name
pathname
4
linkpath
3
pathname
2
(already present)pathname
5
old_path
3
name
pathname
pathname
5
comm: event: data: trace event security_file_open set in multiple policies using multiple filter types
comm: event: data: trace event security_mmap_file using multiple filter types
event: data: trace event security_inode_symlink, security_inode_rename and security_inode_unlink using data filter
event: data: trace event security_kernel_read_file and security_kernel_post_read_file using data filter
comm: event: data: trace event security_bprm_check, shared_object_loaded and security_file_mprotect using data filter