Group system calls in audit_rules_kernel_module_loading template #14059
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Add a new parameter
syscall_groupingthat contains a list of system calls for which audit rules can be grouped together in a single audit rule.This commit also fixes missing documentation for the syscall_grouping parameter of other templates that have this parameter.
Fixes: #14055
Review Hints:
Run Contest test "/scanning/audit-rules-syscalls-grouping" with master and with this PR. For example:
Also, run automatus tests for any of the rules that use this template, eg.