public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Kernel patches needed
@ 2013-05-09 13:26 Steve Grubb
  2013-05-13  1:18 ` Eric Paris
  0 siblings, 1 reply; 2+ messages in thread
From: Steve Grubb @ 2013-05-09 13:26 UTC (permalink / raw)
  To: linux-audit

Hi,

I was just doing some validation work to make sure the newly converted 
ausearch is producing the exact same output as it used to...and found a couple 
items that needs patching.

1) AUDIT_TTY events are not recording a subject field.
2) AVC records can sometimes have dev="md1". The dev field is documented as 
being the numeric device number. Cases like this should be changed to 
"devname" which can be encoded.
3) We might need a supplemental record for *setxattr. The flags field is the 
fifth argument and not recorded anywhere.

Thanks,
-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-05-13  1:18 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-05-09 13:26 Kernel patches needed Steve Grubb
2013-05-13  1:18 ` Eric Paris

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox