Open amstrnad opened 7 years ago
I wonder if this is because we are auditing full information on last close (i.e., when the file-descriptor layer notifies the underlying object of close()
) and not on other closes. Close is, of course, a poor indicator of whether I/O might continue on some objects -- e.g., due to mmap()
. But we can do better than we are doing without too much trouble. I'll take a pass at improving that and we can see how comfortable we are with the results.
@alsz, Is this still an issue?
When auditing close syscalls, occasionally the only file information included is the file descriptor.