From: Steve Grubb <sgrubb@redhat.com>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Steve G <linux_4ever@yahoo.com>,
Eamon Walsh <ewalsh@tycho.nsa.gov>,
Daniel J Walsh <dwalsh@redhat.com>,
SE Linux <selinux@tycho.nsa.gov>,
Eric Paris <eparis@parisplace.org>
Subject: Re: Permissive mode for xace is broken.
Date: Mon, 24 Mar 2008 16:28:41 -0400 [thread overview]
Message-ID: <200803241628.41673.sgrubb@redhat.com> (raw)
In-Reply-To: <1206388745.3302.88.camel@moss-spartans.epoch.ncsc.mil>
On Monday 24 March 2008 15:59:05 Stephen Smalley wrote:
> > SE Linux is the only user of the audit system that does not follow the
> > name=value standard. Would you (and the community) really be willing to
> > convert selinux over to that if we have the API for it? Do you have any
> > suggestions about how you'd like to see the new API implemented?
>
> When the topic last came up on list, we weren't opposed to converting to
> the name=value model, just cautious about not breaking userspace in the
> process.
Sure. Completely understandable.
> As I recall, we even agreed on field names for the avc fields during the
> prior thread. But no one followed up with actual patches to make it
> happen.
On the audit side, I implemented what we agreed on. It creates 2 fake names
for use with values (seresult & seperm). At some point, I would recommend
that the tools experiment with switching over to the auparse library. If that
happens, then we can change the actual format since auparse is already
providing the illusion of name=value for all of selinux.
I recommend experimenting with switching over for a couple other reasons. At
some point we'll start zipping the logs. That will break existing tools
unless they are gzip aware. And people have been talking about adding
database support for audit records. If people store events that way, we'll
have auparse updated to extract events. Its yet another hurdle for the tools
doing their own parsing.
This isn't likely to happen for another month or two so there is time to
experiment. What I am concerned about right now, though, is what to do about
user space AVCs since that is needing some work. :)
-Steve
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2008-03-24 20:28 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-24 15:55 Permissive mode for xace is broken Steve G
2008-03-24 19:59 ` Stephen Smalley
2008-03-24 20:28 ` Steve Grubb [this message]
2008-03-27 20:08 ` Eamon Walsh
-- strict thread matches above, loose matches on Subject: below --
2008-02-25 14:09 Daniel J Walsh
2008-02-25 14:12 ` Stephen Smalley
2008-02-25 14:24 ` Stephen Smalley
2008-02-25 14:48 ` Daniel J Walsh
2008-02-25 18:49 ` Stephen Smalley
2008-02-25 19:28 ` Daniel J Walsh
2008-02-25 20:12 ` Daniel J Walsh
2008-02-25 22:04 ` Eamon Walsh
2008-02-25 20:33 ` Eamon Walsh
2008-02-26 1:12 ` Eamon Walsh
2008-02-26 12:59 ` Stephen Smalley
2008-02-26 13:09 ` Daniel J Walsh
2008-02-27 2:31 ` Eamon Walsh
[not found] ` <FD5B0C7C-60A9-46F4-8986-A8EB31BABDC8@nall.com>
2008-02-27 3:46 ` Eamon Walsh
2008-02-28 18:48 ` Eamon Walsh
2008-02-28 18:51 ` Stephen Smalley
2008-02-28 19:00 ` Daniel J Walsh
2008-02-28 21:17 ` Steve Grubb
2008-02-28 21:34 ` Daniel J Walsh
2008-02-29 1:58 ` Eamon Walsh
2008-02-29 2:02 ` Eamon Walsh
2008-03-17 20:11 ` Steve Grubb
2008-03-20 3:56 ` Eamon Walsh
2008-02-26 14:34 ` Daniel J Walsh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200803241628.41673.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=dwalsh@redhat.com \
--cc=eparis@parisplace.org \
--cc=ewalsh@tycho.nsa.gov \
--cc=linux_4ever@yahoo.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.