From: Steve Grubb <sgrubb@redhat.com>
To: Eric Paris <eparis@redhat.com>
Cc: linux-audit@redhat.com
Subject: Re: max size of execve records
Date: Mon, 15 Oct 2007 09:53:13 -0400 [thread overview]
Message-ID: <200710150953.13970.sgrubb@redhat.com> (raw)
In-Reply-To: <1192218750.3196.33.camel@localhost.localdomain>
On Friday 12 October 2007 15:52:30 Eric Paris wrote:
> If the argument is binary/has control characters it gets logged in hex,
> which means each char in the execve argument lists gets turned into 2
> characters in the audit message.
Yep.
> Do we see a problem dropping the execve record size down to 3500?
Why not go to 3900? 3500 is just as arbitrary as 3900 but requires more
records for large amounts of args. Also, can't you track the allocations more
closely so that if there are no args with a space (or special character) in
it, you can send a full 8k?
-Steve
prev parent reply other threads:[~2007-10-15 13:53 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-10-12 19:52 max size of execve records Eric Paris
2007-10-15 13:53 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200710150953.13970.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=eparis@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox