Log shell-commands and used files. Snapshot executed scripts. Fully automatic.
--rfile
, --take-from-rfile
and --rhash
to simplify
queries for read files with similar names 3914aff74ccc5ea25df4d147a83632d6ba7a2a3fssh localhost echo foo
)
can now be enabled/disabled on demand for the kernel-module backend.
The fanotify-backend now double-checks this case for correct usage.
See README-shell-integration for detailsshournal -e
, preservation of suid-cleared variables for the fanotify-
shell-integration, deduplicated code for the shell-integration-scripts,
more meaningful stack traces, etc.