public inbox for cgroups@vger.kernel.org
 help / color / mirror / Atom feed
From: ebiederm@xmission.com (Eric W. Biederman)
To: Topi Miettinen <toiwoton@gmail.com>
Cc: linux-kernel@vger.kernel.org, mladek@suse.com, luto@kernel.org,
	serge@hallyn.com, keescook@chromium.org,
	Paul Moore <paul@paul-moore.com>, Eric Paris <eparis@redhat.com>,
	Tejun Heo <tj@kernel.org>, Li Zefan <lizefan@huawei.com>,
	Johannes Weiner <hannes@cmpxchg.org>,
	Serge Hallyn <serge.hallyn@canonical.com>,
	"moderated list:AUDIT SUBSYSTEM" <linux-audit@redhat.com>,
	"open list:CONTROL GROUP CGROUP" <cgroups@vger.kernel.org>,
	"open list:CAPABILITIES" <linux-security-module@vger.kernel.org>
Subject: Re: [PATCH] capabilities: audit capability use
Date: Mon, 11 Jul 2016 16:57:03 -0500	[thread overview]
Message-ID: <87vb0bbzyo.fsf@x220.int.ebiederm.org> (raw)
In-Reply-To: <1468235672-3745-1-git-send-email-toiwoton@gmail.com> (Topi Miettinen's message of "Mon, 11 Jul 2016 14:14:31 +0300")

Topi Miettinen <toiwoton@gmail.com> writes:

> There are many basic ways to control processes, including capabilities,
> cgroups and resource limits. However, there are far fewer ways to find
> out useful values for the limits, except blind trial and error.
>
> Currently, there is no way to know which capabilities are actually used.
> Even the source code is only implicit, in-depth knowledge of each
> capability must be used when analyzing a program to judge which
> capabilities the program will exercise.
>
> Generate an audit message at system call exit, when capabilities are used.
> This can then be used to configure capability sets for services by a
> software developer, maintainer or system administrator.
>
> Test case demonstrating basic capability monitoring with the new
> message types 1330 and 1331 and how the cgroups are displayed (boot to
> rdshell):

You totally miss the interactions with the user namespace so this won't
give you the information you are aiming for.

Eric

  parent reply	other threads:[~2016-07-11 21:57 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-07-11 11:14 [PATCH] capabilities: audit capability use Topi Miettinen
     [not found] ` <1468235672-3745-1-git-send-email-toiwoton-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2016-07-11 15:25   ` Serge E. Hallyn
     [not found]     ` <20160711152543.GA17459-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2016-07-11 16:05       ` Topi Miettinen
     [not found]         ` <0355f70f-8356-f685-d37d-ba28668363a1-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2016-07-11 19:28           ` Topi Miettinen
2016-07-11 17:09   ` Tejun Heo
2016-07-11 19:47     ` Topi Miettinen
     [not found]       ` <683cdbb9-c414-07c7-16d3-41c4138ddf8d-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2016-07-12 14:59         ` Tejun Heo
     [not found]           ` <20160712145936.GH3190-piEFEHQLUPpN0TnZuCh8vA@public.gmane.org>
2016-07-13  6:52             ` Topi Miettinen
2016-07-11 21:57 ` Eric W. Biederman [this message]
     [not found]   ` <87vb0bbzyo.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2016-07-12  8:54     ` Topi Miettinen
2016-07-12 13:16       ` Eric W. Biederman
2016-07-12 22:00         ` Paul Moore
     [not found]         ` <878tx79et8.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2016-07-13  7:30           ` Topi Miettinen
2016-07-12 21:56 ` Paul Moore
  -- strict thread matches above, loose matches on Subject: below --
2016-07-03 15:08 [PATCH] capabilities: add capability cgroup controller Topi Miettinen
     [not found] ` <218f2bef-5e5e-89c4-154b-24dc49c82c31-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2016-07-03 16:13   ` [PATCH] capabilities: audit capability use kbuild test robot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87vb0bbzyo.fsf@x220.int.ebiederm.org \
    --to=ebiederm@xmission.com \
    --cc=cgroups@vger.kernel.org \
    --cc=eparis@redhat.com \
    --cc=hannes@cmpxchg.org \
    --cc=keescook@chromium.org \
    --cc=linux-audit@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=lizefan@huawei.com \
    --cc=luto@kernel.org \
    --cc=mladek@suse.com \
    --cc=paul@paul-moore.com \
    --cc=serge.hallyn@canonical.com \
    --cc=serge@hallyn.com \
    --cc=tj@kernel.org \
    --cc=toiwoton@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox