From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paul Moore Subject: Missing audit information in xfrm_audit_common_policyinfo()? Date: Wed, 21 Nov 2007 16:34:31 -0500 Message-ID: <200711211634.31499.paul.moore@hp.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Received: from mx3.redhat.com (mx3.redhat.com [172.16.48.32]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id lALLZICg016447 for ; Wed, 21 Nov 2007 16:35:18 -0500 Received: from g4t0017.houston.hp.com (g4t0017.houston.hp.com [15.201.24.20]) by mx3.redhat.com (8.13.1/8.13.1) with ESMTP id lALLYfh7012310 for ; Wed, 21 Nov 2007 16:34:41 -0500 Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com, netdev@vger.kernel.org, Joy Latten List-Id: linux-audit@redhat.com I just noticed that the IPsec auditing code does not appear to audit the netmask for the selector source and destination addresses in xfrm_audit_common_policyinfo(). Before I threw a patch together I thought I would check to see if there was a reason for this that I am missing ... -- paul moore linux security @ hp