From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric Paris Subject: Re: [PATCH 11/15] fixing audit rule ordering mess, part 1 Date: Wed, 17 Dec 2008 16:10:44 -0500 Message-ID: <1229548244.3384.49.camel@localhost.localdomain> References: <1229538488.3384.33.camel@localhost.localdomain> <20081217205902.GH28946@ZenIV.linux.org.uk> Mime-Version: 1.0 Content-Type: text/plain Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20081217205902.GH28946@ZenIV.linux.org.uk> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Al Viro Cc: linux-audit@redhat.com, linux-kernel@vger.kernel.org, Al Viro List-Id: linux-audit@redhat.com On Wed, 2008-12-17 at 20:59 +0000, Al Viro wrote: > On Wed, Dec 17, 2008 at 01:28:08PM -0500, Eric Paris wrote: > > > I don't see why prio is only important on AUDIT_FILTER_EXIT. Couldn't I > > end up with stupidity with entry,never ? > > > AUDIT_WATCH and AUDIT_INODE can live only on exit chain. I.e. we don't have > that problem - other chains sit on the lists of their own and there the > list ordering itself takes care of everything. Exit chain has parts in > sitting in hash instead of the primary list. Makes perfect sense. They all look good to me. -Eric