From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tyler Hicks Subject: Re: Limiting SECCOMP audit events Date: Thu, 14 Dec 2017 09:04:48 -0600 Message-ID: <36cd827f-201c-8f76-2883-ecd930cbb1f4@canonical.com> References: <58203247.sCqcla2mis@x2> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============5913319243330256340==" Return-path: In-Reply-To: <58203247.sCqcla2mis@x2> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb , Linux Audit List-Id: linux-audit@redhat.com This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5913319243330256340== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="UraUXeI7xGdDnSgue5b15hAcbTHjwHRAA" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --UraUXeI7xGdDnSgue5b15hAcbTHjwHRAA Content-Type: multipart/mixed; boundary="70NBL8VU9P77ELFrtPC4tCJbxjKH3WCQk"; protected-headers="v1" From: Tyler Hicks To: Steve Grubb , Linux Audit Cc: Kees Cook , Paul Moore Message-ID: <36cd827f-201c-8f76-2883-ecd930cbb1f4@canonical.com> Subject: Re: Limiting SECCOMP audit events References: <58203247.sCqcla2mis@x2> In-Reply-To: <58203247.sCqcla2mis@x2> --70NBL8VU9P77ELFrtPC4tCJbxjKH3WCQk Content-Type: text/plain; charset=windows-1252 Content-Language: en-US Content-Transfer-Encoding: quoted-printable On 12/13/2017 05:58 PM, Steve Grubb wrote: > Hello, >=20 > =A0 >=20 > Over the last month, the amount of seccomp events in audit logs is > sky-rocketing. I have over a million events in the last 2 days. Most of= > this is generated by firefox and qt webkit. >=20 > =A0 >=20 > I am wondering if the audit package should ship a file for >=20 > =A0 >=20 > /usr/lib/sysctl.d/60-auditd.conf >=20 > =A0 >=20 > wherein it has >=20 > =A0 >=20 > kernel.seccomp.actions_logged =3D kill_process kill_thread errno I agree with Kees here. IMO, you only want "kill_process kill_thread" which is the default. > Also, has anyone verified this sysctl is filtering audit events? Even > with the above, I have over a million events on a 4.14.3 kernel. Firefo= x > alone is generating over 50,000 events per hour. Yes. I tested it a lot as the changes were being upstreamed and again when I backported the changes to Ubuntu releases 17.10, 17.04, and 16.04 LTS. Those kernels have been released for a month and a half now and I haven't heard of any issues. I'll install a Fedora VM and see if I can determine what's happening. Tyler >=20 > =A0 >=20 > Thanks, >=20 > -Steve >=20 --70NBL8VU9P77ELFrtPC4tCJbxjKH3WCQk-- --UraUXeI7xGdDnSgue5b15hAcbTHjwHRAA Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJaMpMQAAoJENaSAD2qAscKspgQAJHe2TiSh4cFdVwZWvLue/0H 53Xc1SBslgroqU/iHyRMBqfkTF4legSfXGRjHxQOVir58rOiOi8NLZN/NS0AhKgH WDyjZcEEOjISvQUYlSIZ0vdZS3J2YujPYa5yxiT3WwyhT5DCJrVfkBBNyP8MCLCh w2bWtHOd/uFkQ4mALmQRF6b4ugoWtEUByrPaCQErNpjz+I1220/UCLKzQwQ35GbB 7nSijRtk3Z5UYhVUhmUehhRGiZioR4RnUvnsXwbWLXxUc6UrptDtD6fvgYWBcgHW p/JjBUPVYinHuhw5/l+HGkryM5eKLBd3ytJtLS87GUeNWb7XKyRusrmxeByTp2q7 C7hrfU2OlnZKIkAHit6qSFh/Smoip/wdfQJAXH/cJit7rz2wrVQb9bEuu+ZJuapa zOR9aTSZ3tjOW3zMbXKuHmFv8+uLXpYjE+/pvZ/kummOSehXnTQfZPeEZPYOp9rI 4744pxmDKDbtuZOnaAR9K7Qs1sMAP9KW+cyLaaZxW2ypSV/So4QUgMj5EpT2u+sj T8dv8/ZY8fLTcH3eKDoXFJDMfVC5ujsiXSBlbmEMuQh4v+RQgyvmowCMJurKluL4 2gkIsxFDciK7E7ln1Y5Gfnpmj7i462GgQcwOUsO2IwfBjGFSz3lc8VwkBg5pV0jQ NvVJx4gvcK/eg6oOrt/I =xgqk -----END PGP SIGNATURE----- --UraUXeI7xGdDnSgue5b15hAcbTHjwHRAA-- --===============5913319243330256340== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============5913319243330256340==--