What's Changed
- Added child's mnt ns id into monitor list if it's in a new mnt namespace during behavior modeling.
- Return directly when the behavior data is too large.
- Added a debug flag to control whether to generate the debug files for behavior modeling.
- Added the
disallow-load-all-bpf-prog
rule for Seccomp enforcer to prohibit loading any types of eBPF programs. - Fixed: Create varmor-classifier-svc service in the namespace where varmor is installed
Full Changelog: v0.6.1...v0.6.2