From mboxrd@z Thu Jan 1 00:00:00 1970 From: Richard Guy Briggs Subject: Re: [PATCH 1/7] audit: implement generic feature setting and retrieving Date: Thu, 30 May 2013 13:20:56 -0400 Message-ID: <20130530172056.GA7727@madcap2.tricolour.ca> References: <1369411910-13777-1-git-send-email-eparis@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Content-Disposition: inline In-Reply-To: <1369411910-13777-1-git-send-email-eparis@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Eric Paris Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Fri, May 24, 2013 at 12:11:44PM -0400, Eric Paris wrote: > The audit_status structure was not designed with extensibility in mind. > Define a new AUDIT_SET_FEATURE message type which takes a new structure > of bits where things can be enabled/disabled/locked one at a time. This > structure should be able to grow in the future while maintaining forward > and backward compatibility (based loosly on the ideas from capabilities > and prctl) > > This does not actually add any features, but is just infrastructure to > allow new on/off types of audit system features. This is the sort of infrastructure that occured to me for the audit_tty_status structure, when I implemented the password logging switch... > Signed-off-by: Eric Paris - RGB -- Richard Guy Briggs Senior Software Engineer Kernel Security AMER ENG Base Operating Systems Remote, Ottawa, Canada Voice: 1.647.777.2635 Internal: (81) 32635