From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 9CEC3C433F5 for ; Sun, 3 Apr 2022 23:58:01 +0000 (UTC) Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-563-mlUlvxKMPvKtGmQPF4sTvw-1; Sun, 03 Apr 2022 19:57:59 -0400 X-MC-Unique: mlUlvxKMPvKtGmQPF4sTvw-1 Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.rdu2.redhat.com [10.11.54.5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 6093485A5A8; Sun, 3 Apr 2022 23:57:57 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com [10.30.29.100]) by smtp.corp.redhat.com (Postfix) with ESMTP id 92E052D463; Sun, 3 Apr 2022 23:57:54 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (localhost [IPv6:::1]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 4CCC11940363; Sun, 3 Apr 2022 23:57:54 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx08.intmail.prod.int.rdu2.redhat.com [10.11.54.8]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id BA5B11947BBE for ; Sat, 2 Apr 2022 08:06:20 +0000 (UTC) Received: by smtp.corp.redhat.com (Postfix) id 99545C44B1C; Sat, 2 Apr 2022 08:06:20 +0000 (UTC) Received: from mimecast-mx02.redhat.com (mimecast01.extmail.prod.ext.rdu2.redhat.com [10.11.55.17]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 9535AC44B1A for ; Sat, 2 Apr 2022 08:06:20 +0000 (UTC) Received: from us-smtp-1.mimecast.com (us-smtp-delivery-1.mimecast.com [207.211.31.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 7A28B85A5BC for ; Sat, 2 Apr 2022 08:06:20 +0000 (UTC) Received: from mail-qt1-f175.google.com (mail-qt1-f175.google.com [209.85.160.175]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-643-OiHvH5_lMQCw0zIbhRpAOA-1; Sat, 02 Apr 2022 04:06:17 -0400 X-MC-Unique: OiHvH5_lMQCw0zIbhRpAOA-1 Received: by mail-qt1-f175.google.com with SMTP id 10so3936123qtz.11; Sat, 02 Apr 2022 01:06:16 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:message-id:date:from:to:cc:subject:references :mime-version:content-disposition:in-reply-to; bh=Ws4yj3fg0ILxPJj/9lrXi9irg5Vwgnd7Bl7EJpCplb4=; b=A7CeyOeSvVTGcXJRGrX5t/AyxdLLXU9OZUDycJbDX+EeigxBv9nt00iwCATTJpj/TM /mcM6zQbD3DnO+DHFmHLzveTaOaldRYy0hHKQfHuOqtyBWFok2kovjH8GTSRLEqtWLoI WWpk31/ZsHlFNUZkpmsUsdP+yMDdmdSsC72hdRXRSm5zoDPoWOd6FeTVMXJ5B/pab3L3 l5t5gS8EZPDbvINHz+0L4EhlSbbPbuu/AididmJ5xuGhQK4u9AIRHkcZaMxr02/XhLHe vRObMKfrcWk0g3eKq92StfR2PaC3r2LFrOC/dRwcKv6JRIRVENUWYSEJZ1+mfEwG8a7z Lp7A== X-Gm-Message-State: AOAM530rSVnxyPfBxYhyuK3Kbp2y9hB9BNn4ZEMM/74Dy3xQrInrszc1 gjQHwB+gC7thI3ejEBuzNdE= X-Google-Smtp-Source: ABdhPJyX0KLPAV81ICD7wf3I9EYTnSX2te3tj1vy9I/A89gg4uPLy5O1QfHEMAvC6OHVTG0b/Owvtg== X-Received: by 2002:ac8:5702:0:b0:2e1:ec8a:917a with SMTP id 2-20020ac85702000000b002e1ec8a917amr11061065qtw.682.1648886776230; Sat, 02 Apr 2022 01:06:16 -0700 (PDT) Received: from localhost ([193.203.214.57]) by smtp.gmail.com with ESMTPSA id g21-20020ac85815000000b002e06e2623a7sm3431644qtg.0.2022.04.02.01.06.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 02 Apr 2022 01:06:15 -0700 (PDT) Message-ID: <624803f7.1c69fb81.972da.2dd0@mx.google.com> X-Google-Original-Message-ID: <20220402080612.GA2412487@cgel.zte@gmail.com> Date: Sat, 2 Apr 2022 08:06:12 +0000 From: CGEL To: Paul Moore Subject: Re: [PATCH] audit: do a quick exit when syscall number is invalid References: <20220326094654.2361956-1-yang.yang29@zte.com.cn> <62465bf3.1c69fb81.d5424.365e@mx.google.com> <2777189.mvXUDI8C0e@x2> MIME-Version: 1.0 In-Reply-To: X-Mimecast-Impersonation-Protect: Policy=CLT - Impersonation Protection Definition; Similar Internal Domain=false; Similar Monitored External Domain=false; Custom External Domain=false; Mimecast External Domain=false; Newly Observed Domain=false; Internal User Name=false; Custom Display Name List=false; Reply-to Address Mismatch=false; Targeted Threat Dictionary=false; Mimecast Threat Dictionary=false; Custom Threat Dictionary=false X-Scanned-By: MIMEDefang 2.85 on 10.11.54.8 X-Mailman-Approved-At: Sun, 03 Apr 2022 23:57:53 +0000 X-BeenThere: linux-audit@redhat.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux Audit Discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: kbuild-all@lists.01.org, Zeal Robot , linux-kernel@vger.kernel.org, eparis@redhat.com, dai.shixin@zte.com.cn, Yang Yang , linux-audit@redhat.com, ink@jurassic.park.msu.ru, huang.junhua@zte.com.cn, guo.xiaofeng@zte.com.cn, mattst88@gmail.com Errors-To: linux-audit-bounces@redhat.com Sender: "Linux-audit" X-Scanned-By: MIMEDefang 2.79 on 10.11.54.5 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=linux-audit-bounces@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Disposition: inline Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit On Fri, Apr 01, 2022 at 10:16:45AM -0400, Paul Moore wrote: > On Fri, Apr 1, 2022 at 9:39 AM Steve Grubb wrote: > > > > On Thursday, March 31, 2022 9:57:05 PM EDT CGEL wrote: > > > On Thu, Mar 31, 2022 at 10:16:23AM -0400, Paul Moore wrote: > > > > On Wed, Mar 30, 2022 at 10:29 PM CGEL wrote: > > > > > On Wed, Mar 30, 2022 at 10:48:12AM -0400, Paul Moore wrote: > > > > > > If audit is not generating SYSCALL records, even for invalid/ENOSYS > > > > > > syscalls, I would consider that a bug which should be fixed. > > > > > > > > > > If we fix this bug, do you think audit invalid/ENOSYS syscalls better > > > > > be forcible or be a rule that can be configure? I think configure is > > > > > better. > > > > > > > > It isn't clear to me exactly what you are asking, but I would expect > > > > the existing audit syscall filtering mechanism to work regardless if > > > > the syscall is valid or not. > > > > > > Thanks, I try to make it more clear. We found that auditctl would only > > > set rule with syscall number (>=0 && <2047) ... > > That is exactly why I wrote the warning below in my response ... > I think the question is more clear now. 1) libaudit.c wants to forbid setting invalid syscall, but inconsistent Currently way(>=0 && <2047) is inconsistent, syscall with number 2000 and syscall with number 3000 are both invalid syscall. But 2000 can be set by auditctl, and 3000 cannot be set by auditctl. A better way to do this forbidden is to use __NR_syscalls(asm-generic/unistd.h). 2) if libaudit.c do the right forbidden, kernel better ignore invalid syscall See this patch. If we want audit invalid syscall as you said before. libaudit.c should not do the forbidden, auditctl should allow setting syscall rule with 'any' number. So do you think we should fix libaudit.c? > > > > Beware that there are some limitations > > > > to the audit syscall filter, which are unfortunately baked into the > > > > current design/implementation, which may affect this to some extent. > > -- > paul-moore.com -- Linux-audit mailing list Linux-audit@redhat.com https://listman.redhat.com/mailman/listinfo/linux-audit