> The tracepoint documentation claims that denial and lifecycle events
> expose every input needed to reproduce a verdict. Instead document how
> denial, ruleset, and domain events identify the denying policy, checked
> operation and object, and reason for denial. Direct consumers to generic
> tracepoints for additional operational context.
>
> State the reconstruction limits: IDs are boot-local, rule checks have no
> request ID, and exported records may be lost or cross-CPU reordered.
>
> Also replace the incorrect BPF_RAW_TRACEPOINT guidance with libbpf
> SEC("tp_btf/...") attachment and refer consumers to the event prototypes
> for callback argument layouts.
>
> Cc: Günther Noack <[email protected]>
> Cc: Steven Rostedt <[email protected]>
> Signed-off-by: Mickaël Salaün <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review ·
https://sashiko.dev/#/patchset/[email protected]?part=9