sophos / talpa

Talpa Kernel file access interception modules
GNU General Public License v2.0
17 stars 11 forks source link

Added TALPA_ALLOW_NOCACHE response #26

Closed akshaynikam closed 2 years ago

akshaynikam commented 2 years ago

Added a new response as TALPA_ALLOW_NOCACHE, which can be used by vetting controller for the events which are not required to be cached.

akshaynikam commented 2 years ago

25

akshaynikam commented 2 years ago

Let's move TALPA_ALLOW_NOCACHE at the end, otherwise it would disturb the enum sequence

Done

akshaynikam commented 2 years ago

@paperclip Can you please help in reviewing this PR?

paperclip commented 2 years ago

Hi, as I said on the ticket, Sophos is retiring Sophos Anti-Virus for Linux, to be replaced with Sophos Protection for Linux, which only uses fanotify.

We won't be working on talpa any more. We stopped trying to get it working on future kernels around 5.13 (5.11?) time.

Also I don't think we can merge external contributions to Talpa, since it would make the Copyright situation complicated. I recommend you fork Talpa and use it from there.