From mboxrd@z Thu Jan 1 00:00:00 1970 From: LC Bruzenak Subject: Re: ausearch results differ with "-i" flag Date: Wed, 17 Mar 2010 14:15:30 -0500 Message-ID: <1268853330.7162.45.camel@lcb> References: <1268777906.30348.202.camel@lcb> <201003171303.16873.sgrubb@redhat.com> <4BA12442.6030206@redhat.com> <201003171457.08511.sgrubb@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <201003171457.08511.sgrubb@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Wed, 2010-03-17 at 14:57 -0400, Steve Grubb wrote: > > > What happened to the position that changing audit output from the > kernel was > > verboten? > > This particular avc originates from user space. The application needs > to follow the rules correctly so it doesn't mess up the logs. User space, yes, but from the Xorg server. Because X controls accesses internally it apparently audits stuff using the USER_AVC in this way. My confusion is that I thought any freetext should be allowed inside the "msg=" field and not interpreted by ausearch. I remember a while back though you told me why this can happen...so I need to look back and see. I suspect because the parse libs work as I think and the ausearch/aureport doesn't use those.?. Thx, LCB. -- LC (Lenny) Bruzenak lenny@magitekltd.com