From: Paul Moore <pmoore@redhat.com>
To: Richard Guy Briggs <rgb@redhat.com>
Cc: linux-security-module@vger.kernel.org, selinux@tycho.nsa.gov,
linux-audit@redhat.com, linux-kernel@vger.kernel.org,
eparis@redhat.com, sgrubb@redhat.com
Subject: Re: [PATCH] selinux: services: cleanup orphan keywords in audit log text
Date: Mon, 22 Sep 2014 17:11:09 -0400 [thread overview]
Message-ID: <2323471.BcNNgvtlxN@sifl> (raw)
In-Reply-To: <516208b0d38331b8a3318918814e4e321c5117d9.1411086286.git.rgb@redhat.com>
On Thursday, September 18, 2014 08:47:48 PM Richard Guy Briggs wrote:
> Restructure to keyword=value pairs without spaces. Drop superfluous words
> in text. Make invalid_context a keyword. Change result= keyword to
> seresult=.
>
> Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
> ---
> security/selinux/ss/services.c | 14 ++++++++------
> 1 files changed, 8 insertions(+), 6 deletions(-)
Applied with a minor rewrite to the subject line.
> diff --git a/security/selinux/ss/services.c b/security/selinux/ss/services.c
> index 4bca494..e822910 100644
> --- a/security/selinux/ss/services.c
> +++ b/security/selinux/ss/services.c
> @@ -728,7 +728,7 @@ static int security_validtrans_handle_fail(struct
> context *ocontext, if (context_struct_to_string(tcontext, &t, &tlen))
> goto out;
> audit_log(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR,
> - "security_validate_transition: denied for"
> + "op=security_validate_transition seresult=denied"
> " oldcontext=%s newcontext=%s taskcontext=%s tclass=%s",
> o, n, t, sym_name(&policydb, SYM_CLASSES, tclass-1));
> out:
> @@ -877,7 +877,7 @@ int security_bounded_transition(u32 old_sid, u32
> new_sid) audit_log(current->audit_context,
> GFP_ATOMIC, AUDIT_SELINUX_ERR,
> "op=security_bounded_transition "
> - "result=denied "
> + "seresult=denied "
> "oldcontext=%s newcontext=%s",
> old_name, new_name);
> }
> @@ -1351,8 +1351,8 @@ static int compute_sid_handle_invalid_context(
> if (context_struct_to_string(newcontext, &n, &nlen))
> goto out;
> audit_log(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR,
> - "security_compute_sid: invalid context %s"
> - " for scontext=%s"
> + "op=security_compute_sid invalid_context=%s"
> + " scontext=%s"
> " tcontext=%s"
> " tclass=%s",
> n, s, t, sym_name(&policydb, SYM_CLASSES, tclass-1));
> @@ -2584,8 +2584,10 @@ int security_sid_mls_copy(u32 sid, u32 mls_sid, u32
> *new_sid) rc = convert_context_handle_invalid_context(&newcon);
> if (rc) {
> if (!context_struct_to_string(&newcon, &s, &len)) {
> - audit_log(current->audit_context, GFP_ATOMIC,
AUDIT_SELINUX_ERR,
> - "security_sid_mls_copy: invalid context %s", s);
> + audit_log(current->audit_context,
> + GFP_ATOMIC, AUDIT_SELINUX_ERR,
> + "op=security_sid_mls_copy "
> + "invalid_context=%s", s);
> kfree(s);
> }
> goto out_unlock;
--
paul moore
security and virtualization @ redhat
prev parent reply other threads:[~2014-09-22 21:11 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-09-19 0:47 [PATCH] selinux: services: cleanup orphan keywords in audit log text Richard Guy Briggs
2014-09-22 21:11 ` Paul Moore [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2323471.BcNNgvtlxN@sifl \
--to=pmoore@redhat.com \
--cc=eparis@redhat.com \
--cc=linux-audit@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=rgb@redhat.com \
--cc=selinux@tycho.nsa.gov \
--cc=sgrubb@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox