From mboxrd@z Thu Jan 1 00:00:00 1970 From: Amy Griffis Subject: [PATCH 0/2] signal audit (v3) Date: Thu, 29 Mar 2007 17:59:46 -0400 Message-ID: <20070329215946.GA17830@fc.hp.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Return-path: Received: from mx2.redhat.com (mx2.redhat.com [10.255.15.25]) by int-mx2.corp.redhat.com (8.13.1/8.13.1) with ESMTP id l2TM2H99015775 for ; Thu, 29 Mar 2007 18:02:17 -0400 Received: from atlrel8.hp.com (atlrel8.hp.com [156.153.255.206]) by mx2.redhat.com (8.13.1/8.13.1) with ESMTP id l2TM2GEJ011656 for ; Thu, 29 Mar 2007 18:02:16 -0400 Received: from smtp1.fc.hp.com (smtp1.fc.hp.com [15.15.136.127]) by atlrel8.hp.com (Postfix) with ESMTP id 76D3E36752 for ; Thu, 29 Mar 2007 18:02:13 -0400 (EDT) Received: from ldl.fc.hp.com (ldl.fc.hp.com [15.11.146.30]) by smtp1.fc.hp.com (Postfix) with ESMTP id 805B81341AC for ; Thu, 29 Mar 2007 22:01:42 +0000 (UTC) Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com Several changes since last version: - use arch rule field to determine which signal class to check, check both if arch is unspecified - don't check AUDIT_CLASS_SIGNAL_32 if it doesn't exist - group target pids in aux structs (initially 16) - on syscall exit, initialize context's aux ptrs for re-use - don't convert sid to string until we log a record Applies on top of ptrace patch.