Is xfence now able to monitor changes made to inode?

Hi F-Secure dev team, thanks for making such a great App, however I found some issues related to command "mv".
Here are the steps:
- switch to "strict mode" and set a watch rule for folder "foo"
- use command "mv", moving files inside folder "foo" to $TMPDIR (located under /private/var/folders/, which is not included in the xfence's watch list.)
- Result: files are moved without a dialog
I think the root cause is, mv makes changes to inode instead of file data, and if the "DEST" isn't watched by xfence, then this could happen.
BR.
Best Answer
-
ArthurVal Posts: 70 F-Secure Employee
Hello!
A small update. We've identified the root cause of this behavior.
We indeed have support for handling of this operating system event type on DeepGuard (XFENCE) side. However, due to a bug on the implementation side only the target location is currently evaluated (in this case the temporary directory which is not included in monitoring). We are now adding evaluation of source that is being manipulated in this case and validating the fix internally. It will be included in the next FS Protection release.
We appreciate you reporting the issue to us and helping us improve the quality of the feature and making it more secure!
Best regards, Arthur
R&D Team
1 1Like
Answers
Hello!
Thanks for the report! We will investigate it and will get back to you as soon as we have any results to share.
Best regards, Arthur
Mac R&D Team
Hello!
Many many thanks ❤️ . Can't wait to try it out!
Best regards.