All of lore.kernel.org
 help / color / mirror / Atom feed
From: Richard Weinberger <richard@sigma-star.at>
To: Paul Moore <paul@paul-moore.com>
Cc: Richard Weinberger <richard@nod.at>,
	upstream@sigma-star.at, netfilter-devel@vger.kernel.org,
	coreteam@netfilter.org, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org, pabeni@redhat.com, kuba@kernel.org,
	edumazet@google.com, davem@davemloft.net, kadlec@netfilter.org,
	pablo@netfilter.org, rgb@redhat.com, upstream+net@sigma-star.at,
	audit@vger.kernel.org, linux-security-module@vger.kernel.org
Subject: Re: [PATCH] netfilter: Record uid and gid in xt_AUDIT
Date: Thu, 10 Oct 2024 22:40:22 +0200	[thread overview]
Message-ID: <5924990.Vcsy2DjxtS@somecomputer> (raw)
In-Reply-To: <CAHC9VhRDZVJbhCbVkfs8NC=vAx-QdQwX_jMq51xzoTxFuxSXLg@mail.gmail.com>

Am Donnerstag, 10. Oktober 2024, 21:09:31 CEST schrieb Paul Moore:
> However, as part of that commit we also dropped a number of fields
> because it wasn't clear that anyone cared about them and if we were
> going to (re)normalize the NETFILTER_PKT record we figured it would be
> best to start small and re-add fields as needed to satisfy user
> requirements.  I'm working under the assumption that if you've taken
> the time to draft a patch and test it, you have a legitimate need :)

I'm currently exploring ways to log reliable what users/containers
create what network connections.
So, netfilter+conntrack+xt_AUDIT seemed legit to me.

Thanks,
//richard

-- 
​​​​​sigma star gmbh | Eduard-Bodem-Gasse 6, 6020 Innsbruck, AUT
UID/VAT Nr: ATU 66964118 | FN: 374287y



      reply	other threads:[~2024-10-10 20:40 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-10-09 20:32 [PATCH] netfilter: Record uid and gid in xt_AUDIT Richard Weinberger
2024-10-09 21:33 ` Florian Westphal
2024-10-09 21:46   ` Paul Moore
2024-10-09 22:34     ` Florian Westphal
2024-10-10  2:02       ` Paul Moore
2024-10-10 17:59         ` Florian Westphal
2024-10-10 19:13           ` Paul Moore
2024-10-10  6:27   ` Richard Weinberger
2024-10-10 13:48     ` Florian Westphal
2024-10-10 13:53       ` Jan Engelhardt
2024-10-10 20:09       ` Richard Weinberger
2024-10-11  1:27         ` Florian Westphal
2024-10-11 13:12           ` Richard Weinberger
2024-10-09 22:02 ` Paul Moore
2024-10-10  6:24   ` Richard Weinberger
2024-10-10 19:09     ` Paul Moore
2024-10-10 20:40       ` Richard Weinberger [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5924990.Vcsy2DjxtS@somecomputer \
    --to=richard@sigma-star.at \
    --cc=audit@vger.kernel.org \
    --cc=coreteam@netfilter.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kadlec@netfilter.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=pablo@netfilter.org \
    --cc=paul@paul-moore.com \
    --cc=rgb@redhat.com \
    --cc=richard@nod.at \
    --cc=upstream+net@sigma-star.at \
    --cc=upstream@sigma-star.at \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.