linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* CONFIG_CHANGE record formats
@ 2018-03-22  8:42 Richard Guy Briggs
  2018-03-23  8:20 ` Richard Guy Briggs
  2018-03-30 17:20 ` Steve Grubb
  0 siblings, 2 replies; 7+ messages in thread
From: Richard Guy Briggs @ 2018-03-22  8:42 UTC (permalink / raw)
  To: Steve Grubb, Linux-Audit Mailing List

Hi Steve, Paul,

Looking at some AUDIT_CONFIG_CHANGE record formats, a couple of things
stand out as potential problems:

For ADD_RULE and DEL_RULE case when audit_enabled is in the AUDIT_LOCKED
state, it just outputs "audit_enabled=2 res=0" to indicate locked and
failure, but doesn't appear to actually give the normal "op=<mumble>" to
indicate a rule change was attempted and refused due to immutability of
the rule set.  Will this be a problem for the parser, and should an
attempted rule change be logged as such?

The other is AUDIT_TTY_SET that has non-standard old-* and new-* fields,
but since there are two, I think it is unavoidable and can't be fixed.

Another is that other than a change to the enabled status and maybe
auditd PID changes, every other config change should not be logged if
audit is disabled.  Furthermore, if CONFFIG_CHANGE records are to be
accompanied by syscall records, they should obey audit_dummy_context()
to avoid unaccompanied records.  Does this reasoning make sense?


- RGB

--
Richard Guy Briggs <rgb@redhat.com>
Sr. S/W Engineer, Kernel Security, Base Operating Systems
Remote, Ottawa, Red Hat Canada
IRC: rgb, SunRaycer
Voice: +1.647.777.2635, Internal: (81) 32635

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2018-03-30 17:20 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-03-22  8:42 CONFIG_CHANGE record formats Richard Guy Briggs
2018-03-23  8:20 ` Richard Guy Briggs
2018-03-23 21:48   ` Paul Moore
2018-03-30  9:26     ` Richard Guy Briggs
2018-03-30 12:35       ` Paul Moore
2018-03-30 15:07         ` Richard Guy Briggs
2018-03-30 17:20 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).