From: Steve Grubb <sgrubb@redhat.com>
To: Matthew Booth <mbooth@redhat.com>
Cc: linux-audit@redhat.com
Subject: Re: Events lost with dispatcher
Date: Wed, 7 Apr 2010 09:00:41 -0400 [thread overview]
Message-ID: <201004070900.41900.sgrubb@redhat.com> (raw)
In-Reply-To: <4BBC7E18.7080004@redhat.com>
On Wednesday 07 April 2010 08:44:08 am Matthew Booth wrote:
> On 31/03/10 20:56, Steve Grubb wrote:
> > Wait, you are writing a dispatcher...are you boosting your priority above
> > auditd? If not, you should probably increase it by at least 4. Your
> > dispatcher has to stay ahead of auditd.
>
> On a related note, has there been any more thought about loading
> dispatchers into auditd itself as dynamic libraries?
Its been in the official TODO file for about 7-8 months. There just isn't any
time for me to work on it right now or for a few more months.
> This would solve this problem,
This particular problem turned out to be a bad Ubuntu kernel. Everything works
as advertised when he switched to Fedora.
> and also the issue of accidentally writing a rule which is
> triggered by a dispatcher, causing a DOS.
-Steve
prev parent reply other threads:[~2010-04-07 13:00 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-03-31 19:07 Events lost with dispatcher Vishwanath Venkatesan
2010-03-31 19:26 ` Steve Grubb
2010-03-31 19:32 ` Vishwanath Venkatesan
2010-03-31 19:48 ` Steve Grubb
2010-03-31 19:56 ` Steve Grubb
2010-04-07 12:44 ` Matthew Booth
2010-04-07 13:00 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201004070900.41900.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
--cc=mbooth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.