Skip to content

Add default node filter policy #124

@tfjmp

Description

@tfjmp

Adding the following line: prov_policy.prov_node_filter = ENT_INODE_UNKNOWN & ENT_INODE_DIRECTORY & ENT_INODE_DIRECTORY & ENT_ENV; here

pr_info("Provenance: capture at boot on.");
should work.

It should be added when whole provenance capture is selected in the kernel config option.

Needs to be implemented and tested.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions