All of lore.kernel.org
 help / color / mirror / Atom feed
From: Michael C Thompson <thompsmc@us.ibm.com>
To: Michael C Thompson <thompsmc@us.ibm.com>
Cc: linux-audit@redhat.com
Subject: Re: audit 1.2.2 released
Date: Tue, 23 May 2006 17:20:16 -0500	[thread overview]
Message-ID: <44738AA0.50006@us.ibm.com> (raw)
In-Reply-To: <4473374C.8030902@us.ibm.com>

Michael C Thompson wrote:
> Steve Grubb wrote:
>> On Tuesday 16 May 2006 13:23, Steve Grubb wrote:
>>> AFAICT, there are 2 places where an access decision is made,
>>> audit_netlink_ok in kernel/audit.c. And the other place is
>>> selinux_nlmsg_lookup in  security/selinux/nlmsgtab.c. I think you'd 
>>> want to
>>> patch your kernel to  printk its access decision results in both of 
>>> those
>>> functions. That should tell us something about what's going on.
>>
>> Mike,
>>
>> Did you ever patch your kernel to get more info or did this problem go 
>> away in the latest kernel (lspp.26)?
> 
> I have tested this on the 26 and 27 kernel and am still experiencing the 
> problem. I'm working on tracking it down now.

This is definately not an SELinux issue. I don't know enough about the 
audit_reply structure to fully understand what is happening. This is 
what I know:

socket_has_perm returns 0, and netlink_recvmsg does definitely get hit. 
The error is getting packaged up in the body of the netlink message, but 
I don't know where to begin looking for this, nor do I have the time to 
continue looking.

If you have any possible fixes, I'll gladly test them, but currently, 
I'm at a loss for time and can't continue.

Thanks,
Mike

  reply	other threads:[~2006-05-23 22:20 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-05-12 21:26 audit 1.2.2 released Steve Grubb
2006-05-15 19:57 ` Michael C Thompson
2006-05-15 20:04   ` Steve Grubb
2006-05-15 20:14     ` Michael C Thompson
2006-05-16 14:53       ` Michael C Thompson
2006-05-16 15:23         ` Steve Grubb
2006-05-16 16:08           ` Michael C Thompson
2006-05-16 16:28             ` Steve Grubb
2006-05-16 15:34         ` Steve Grubb
2006-05-16 15:53           ` Linda Knippers
2006-05-16 17:23             ` Steve Grubb
2006-05-16 20:38               ` Michael C Thompson
2006-05-16 21:49                 ` Steve Grubb
2006-05-16 22:31                   ` Valdis.Kletnieks
2006-05-17 10:25                     ` Steve Grubb
2006-05-22 17:31               ` Steve Grubb
2006-05-22 19:15                 ` Xin Zhao
2006-05-22 19:24                   ` Steve Grubb
2006-05-22 19:37                     ` Xin Zhao
2006-05-22 19:47                       ` Steve Grubb
2006-05-22 20:15                         ` Xin Zhao
2006-05-23  6:56                       ` Amy Griffis
2006-05-23  3:43                         ` Xin Zhao
2006-05-23 15:11                           ` Steve Grubb
2006-05-23 16:24                 ` Michael C Thompson
2006-05-23 22:20                   ` Michael C Thompson [this message]
2006-05-23 23:05                     ` Linda Knippers
2006-05-24 19:44                       ` Michael C Thompson
2006-05-24 20:58                         ` James Antill
2006-05-25 13:48                           ` Michael C Thompson
2006-05-25 15:16                             ` James Antill
2006-05-25 15:22                               ` Michael C Thompson
2006-05-25 15:40                                 ` James Antill
2006-05-24 13:04                     ` Steve Grubb
2006-05-24 20:30                       ` Michael C Thompson
2006-05-17 15:32 ` Michael C Thompson
2006-05-17 15:45   ` Michael C Thompson
2006-05-17 21:12 ` Michael C Thompson
2006-05-17 21:23   ` Steve Grubb
2006-05-17 21:43     ` Michael C Thompson
2006-05-17 21:55       ` Steve Grubb
  -- strict thread matches above, loose matches on Subject: below --
2006-05-25 15:50 Chad Hanson
2006-05-26 16:05 ` Darrel Goeddel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=44738AA0.50006@us.ibm.com \
    --to=thompsmc@us.ibm.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.