Replace usage of libaudit function removed in v3.0.7 by carlsmedstad · Pull Request #8401 · osquery/osquery

Conversation

directionless

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not super familiar with how libaudit works -- I know osquery is (mostly), static but any chance this change extends into the whatever the underlying auditd system is?

directionless

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We talked about this in office hours today, and we think it's reasonable!

Labels