public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Question about setting watches in auto-mounted directories in RHEL 5.2
@ 2008-11-21 16:59 Taylor_Tad
  2008-11-30 14:15 ` Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Taylor_Tad @ 2008-11-21 16:59 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 824 bytes --]

I'd like to set a file system watch so that any activity in an
auto-mounted directory is audited.  It looks like just setting a watch
on a parent directory isn't sufficient.  For example, if I have
directory path  /dir1/dir2 and auto-mount something at
/dir1/dir2/mount-dir, setting a file system watch on /dir1/dir2 doesn't
detect activity in the auto-mounted subtree.  Looking at the auditctl
man page, it looks like I'd have to issue a command like "/sbin/auditctl
-q /dir1/dir2/mount-dir,/dir1/dir2" to tell the kernel to watch the
newly mounted file system as well.  Unfortunately, auto-mounts are,
well, automatic, so there's no one to issue that command.

 

Am I missing a better way to accomplish this goal?  Is my understanding
wrong?  Any help would be appreciated.  Thanks,

 

--Tad Taylor


[-- Attachment #1.2: Type: text/html, Size: 2665 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2008-11-30 17:17 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-11-21 16:59 Question about setting watches in auto-mounted directories in RHEL 5.2 Taylor_Tad
2008-11-30 14:15 ` Steve Grubb
2008-11-30 15:11   ` Alexander Viro
2008-11-30 15:47     ` Steve Grubb
2008-11-30 17:17       ` Alexander Viro

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox