All of lore.kernel.org
 help / color / mirror / Atom feed
* USER_AVC vs USER_MAC_POLICY_LOAD ?
@ 2008-03-26 12:44 Steve Grubb
  2008-03-26 13:26 ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: Steve Grubb @ 2008-03-26 12:44 UTC (permalink / raw)
  To: selinux

Hi,

Lately dbus has taken to sending this again:

localhost  dbus: Can't send to audit system: USER_AVC avc:  received 
policyload notice (seqno=2) : exe="?" (sauid=81, hostname=?, addr=?, 
terminal=?)

This is clearly not an AVC - which is an access control decision. This is a 
policy load - something entirely different. The audit system wants to have 1 
type = 1 meaning. We need to be able to differentiate information flow 
decisions from everything else.

I will be releasing an update to the audit system this week. I can add 
USER_MAC_POLICY_LOAD type to libaudit.h if that would help solve the problem. 
This does beg the question, though, do we really want these events being 
recorded? If so, I think we should use an appropriate type and not USER_AVC.

Thanks,
-Steve

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2008-03-26 14:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-03-26 12:44 USER_AVC vs USER_MAC_POLICY_LOAD ? Steve Grubb
2008-03-26 13:26 ` Stephen Smalley
2008-03-26 14:05   ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.