From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C75E1C77B7A for ; Wed, 24 May 2023 10:38:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1684924694; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=SIoFsWb6C09y/NSY6NFkRDIRjnGa9ATxw2JUgFE8anY=; b=da/t/djyerX4oxtGpOzkUzyuwNHQ8xDIeGlkVJ+tyQ+uS49A4FtQkpyH26WqvfxxiHMqid Ab9L8/KoIyEmtr2vNr/ECN7v1DMP/r9YGhK22FWVb2tAfjXBrWR4dFROGCmtUg8PqyVrEk egsMnmEo0DsNQBGQ/kj9P0j3eb9l9/w= Received: from mimecast-mx02.redhat.com (mx3-rdu2.redhat.com [66.187.233.73]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-164-2WL-fOt7PMuE3OZmi3A3ng-1; Wed, 24 May 2023 06:38:11 -0400 X-MC-Unique: 2WL-fOt7PMuE3OZmi3A3ng-1 Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.rdu2.redhat.com [10.11.54.5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 179941C0336F; Wed, 24 May 2023 10:38:10 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (unknown [10.30.29.100]) by smtp.corp.redhat.com (Postfix) with ESMTP id 7B3EC9D7A; Wed, 24 May 2023 10:38:08 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (localhost [IPv6:::1]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 495D819465A8; Wed, 24 May 2023 10:38:08 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx09.intmail.prod.int.rdu2.redhat.com [10.11.54.9]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 2E01419465A0 for ; Wed, 24 May 2023 10:38:07 +0000 (UTC) Received: by smtp.corp.redhat.com (Postfix) id 126DF400F17; Wed, 24 May 2023 10:38:07 +0000 (UTC) Received: from mimecast-mx02.redhat.com (mimecast07.extmail.prod.ext.rdu2.redhat.com [10.11.55.23]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 0A5B9492B00 for ; Wed, 24 May 2023 10:38:07 +0000 (UTC) Received: from us-smtp-inbound-1.mimecast.com (us-smtp-delivery-1.mimecast.com [207.211.31.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id E145A3C14AAB for ; Wed, 24 May 2023 10:38:06 +0000 (UTC) Received: from mail-lf1-f43.google.com (mail-lf1-f43.google.com [209.85.167.43]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-363-njYRHGC1Mhyf5Bph1M6wtQ-1; Wed, 24 May 2023 06:38:05 -0400 X-MC-Unique: njYRHGC1Mhyf5Bph1M6wtQ-1 Received: by mail-lf1-f43.google.com with SMTP id 2adb3069b0e04-4f004cc54f4so730392e87.3 for ; Wed, 24 May 2023 03:38:04 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1684924683; x=1687516683; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=8aIc+W4jRozyQKjGPCOdblhKfCTo6UqCtNr9GJSvrD0=; b=FPTBL9xsAWqnb7WCTZdOqt4mXI9MYSm7ixgugIdYx0uvSAVIwcOPiikHR3fJkApKi1 s+xU+POfuer7/hU04XhzqfBs2C+M6h2jnPN1aoS45NXtabH8MlGWymRuylcAGDYHOYGh jEMYJ0roqctahpWOjmQIjQPENcQjzBzwxdcM3sDKjxZRHt4wlempBr1R7i9z5PO1Fm07 zhJAWIobjCXuAh7rITScAGVpmlu1f8I72zJ/fbZw2SyxQVVrWoZj7rj+ksLpM1G6Zq23 yM7LP9jhU6dHf/gu21+Mosfxy4m2IIOHnWeQfI15ShfxA34ruAEY6lkCAsQ6Lf51Uu6R Bnjg== X-Gm-Message-State: AC+VfDyQDRTokjkYkU0QNelQzUS1ASBU3gJfLe+AXFvSxWygOSM9rz7y cYF5SB8BKwhvZNvnzYbDLCo= X-Google-Smtp-Source: ACHHUZ7g7cPceUMikyYVFWz/WlBSc4fZEWypRDBoGCo+aCDkVp8a3751hHLICOTYJfkAW8YcXV1isQ== X-Received: by 2002:a05:6512:489:b0:4f2:7c91:93f with SMTP id v9-20020a056512048900b004f27c91093fmr5649928lfq.21.1684924683061; Wed, 24 May 2023 03:38:03 -0700 (PDT) Received: from [192.168.0.31] ([94.242.171.185]) by smtp.gmail.com with ESMTPSA id z4-20020ac25de4000000b004efee5841b9sm1656965lfq.290.2023.05.24.03.38.02 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 24 May 2023 03:38:02 -0700 (PDT) Message-ID: <8406cb9d-0654-b41c-64f9-01aba486b849@gmail.com> Date: Wed, 24 May 2023 13:38:01 +0300 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0 Subject: Re: Can AUDIT_LIST_RULES causes kthreadd-spam? To: Tetsuo Handa References: <9ae2c1df-1f20-a40b-35ed-1dc76b122a4f@I-love.SAKURA.ne.jp> <415a4871-4d84-a31f-5417-e850a98bbffd@I-love.SAKURA.ne.jp> <7c4caf66-a0ae-4999-172e-437d6cfc8ff3@gmail.com> <0e748195-d3ba-88c5-1b1e-5a9c447bea57@I-love.SAKURA.ne.jp> From: Rinat Gadelshin In-Reply-To: X-Mimecast-Impersonation-Protect: Policy=CLT - Impersonation Protection Definition; Similar Internal Domain=false; Similar Monitored External Domain=false; Custom External Domain=false; Mimecast External Domain=false; Newly Observed Domain=false; Internal User Name=false; Custom Display Name List=false; Reply-to Address Mismatch=false; Targeted Threat Dictionary=false; Mimecast Threat Dictionary=false; Custom Threat Dictionary=false X-Scanned-By: MIMEDefang 3.1 on 10.11.54.9 X-BeenThere: linux-audit@redhat.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Linux Audit Discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: audit@vger.kernel.org, linux-audit@redhat.com Errors-To: linux-audit-bounces@redhat.com Sender: "Linux-audit" X-Scanned-By: MIMEDefang 3.1 on 10.11.54.5 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: gmail.com Content-Language: en-US, ru-RU Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="us-ascii"; Format="flowed" Hi Tetsuo. Sorry for my log absence. The kthread-spam problem has gone when I've switched to using unicast-netlink connection (like auditd does). Do we need to make another test with the additional pr_info() ? On 10.05.2023 16:30, Tetsuo Handa wrote: > On 2023/05/10 21:12, Rinat Gadelshin wrote: >>> Please try to find who is calling audit_send_reply_thread for many times. >>> >> I've rebuilt the kernel with 'dump stack()'. > Oops, I thought dump_stack() shows pid and comm name, but > it is dump_stack_print_info() that shows pid and comm name. > >> As far as I can see, it's the exit of `sendto` syscall. >> It seems that the kernel just creates a new kthreadd for each sendto syscall. >> But I think that I'm wrong and just missing something. > Yes, sendto() on netlink socket calls netlink_sendmsg(). > For some reason, audit_send_reply() is called for many times. > audit_send_reply() is called by audit_receive_msg() for the following types. > > AUDIT_GET > AUDIT_SIGNAL_INFO > AUDIT_TTY_GET > AUDIT_GET_FEATURE > > Would you re-caputure with > > - dump_stack(); > + pr_info("%s %s:%d type=%d\n", __func__, current->comm, current->pid, type); > > ? > > Regardless of the result of re-caputure, it seems there is no switch that can > prevent audit_send_reply() from calling kthread_run(audit_send_reply_thread). > > But since kthreadd runs with PID=2 and PPID=0, you might be able to use > PID=2 and/or PPID=0 in your rules in order to let kernel audit subsystem > ignore kthreadd. (I can't test because I haven't found how to reproduce > audit_receive_msg() in my environment...) > > # cat /proc/2/status > Name: kthreadd > Umask: 0000 > State: S (sleeping) > Tgid: 2 > Ngid: 0 > Pid: 2 > PPid: 0 > -- Linux-audit mailing list Linux-audit@redhat.com https://listman.redhat.com/mailman/listinfo/linux-audit