Merge logparser: adding support for comm in capability events

In order to act on capability denials, we need to parse comm.

Signed-off-by: Maxime Bélair <maxime.belair@canonical.com>

MR: https://gitlab.com/apparmor/apparmor/-/merge_requests/1294
Approved-by: John Johansen <john@jjmx.net>
Merged-by: John Johansen <john@jjmx.net>
This commit is contained in:
John Johansen 2024-08-12 22:43:55 +00:00
commit 055d0f80b5
2 changed files with 3 additions and 0 deletions

View file

@ -238,6 +238,8 @@ class ReadLog:
case 'io_uring':
ev['peer_profile'] = event.peer_profile
case 'capability':
ev['comm'] = event.comm
if not ev['time']:
ev['time'] = int(time.time())

View file

@ -138,6 +138,7 @@ class CapabilityTest(AATest):
'active_hat': None,
'pid': 15454,
'task': 0,
'comm': 'ping',
'attr': None,
'name2': None,
'name': 'net_raw',