linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
 messages from 2019-09-19 01:22:38 to 2019-11-29 20:08:17 UTC [more...]

[PATCH] kernel: audit.c: Add __rcu notation to RCU pointer
 2019-11-29 20:08 UTC  (6+ messages)

[PATCH v2] kernel: audit.c: Add __rcu notation to RCU pointer
 2019-11-28 15:32 UTC 

[RFC] bpf: Emit audit messages upon successful prog load and unload
 2019-11-28  9:18 UTC  (2+ messages)

[RFC PATCH v2] security,lockdown,selinux: implement SELinux lockdown
 2019-11-27 17:22 UTC  (2+ messages)

[GIT PULL] Audit patches for v5.5
 2019-11-26 21:33 UTC 

Security audit rules
 2019-11-26  5:23 UTC  (7+ messages)

[PATCH] bpf: emit audit messages upon successful prog load and unload
 2019-11-25 18:38 UTC  (13+ messages)

[PATCH AUTOSEL 4.9 04/13] audit_get_nd(): don't unlock parent too early
 2019-11-22 19:49 UTC 

[PATCH AUTOSEL 4.14 06/21] audit_get_nd(): don't unlock parent too early
 2019-11-22 19:49 UTC 

[PATCH AUTOSEL 4.19 06/25] audit_get_nd(): don't unlock parent too early
 2019-11-22 19:48 UTC 

Auditd SYSCALL argument decoding
 2019-11-20 12:24 UTC  (4+ messages)

[PATCH v11 00/25] LSM: Module stacking for AppArmor
 2019-11-19 18:03 UTC  (12+ messages)
  ` [PATCH v11 03/25] LSM: Use lsmblob in security_audit_rule_match
  ` [PATCH v11 07/25] LSM: Use lsmblob in security_secid_to_secctx
  ` [PATCH v11 08/25] LSM: Use lsmblob in security_ipc_getsecid
  ` [PATCH v11 09/25] LSM: Use lsmblob in security_task_getsecid
  ` [PATCH v11 10/25] LSM: Use lsmblob in security_inode_getsecid
  ` [PATCH v11 11/25] LSM: Use lsmblob in security_cred_getsecid
  ` [PATCH v11 14/25] LSM: Ensure the correct LSM context releaser
  ` [PATCH v11 15/25] LSM: Use lsmcontext in security_secid_to_secctx
  ` [PATCH v11 21/25] Audit: Add subj_LSM fields when necessary
  ` [PATCH v11 22/25] Audit: Include object data for all security modules
  ` [PATCH v11 23/25] NET: Add SO_PEERCONTEXT for multiple LSMs

[PATCH 07/25] LSM: Use lsmblob in security_secid_to_secctx
 2019-11-13  0:09 UTC  (3+ messages)
` [PATCH 14/25] LSM: Ensure the correct LSM context releaser
` [PATCH 15/25] LSM: Use lsmcontext in security_secid_to_secctx

Not seeing access denied audit messages in restricted subdirectories
 2019-11-10 15:48 UTC  (5+ messages)

[PATCH ghak90 V7 00/21] audit: implement container identifier
 2019-11-08 18:26 UTC  (61+ messages)
` [PATCH ghak90 V7 04/21] audit: convert to contid list to check for orch/engine ownership
` [PATCH ghak90 V7 05/21] audit: log drop of contid on exit of last task
` [PATCH ghak90 V7 06/21] audit: contid limit of 32k imposed to avoid DoS
` [PATCH ghak90 V7 08/21] audit: add contid support for signalling the audit daemon
` [PATCH ghak90 V7 12/21] audit: add support for containerid to network namespaces
` [PATCH ghak90 V7 13/21] audit: NETFILTER_PKT: record each container ID associated with a netNS
` [PATCH ghak90 V7 14/21] audit: contid check descendancy and nesting
` [PATCH ghak90 V7 15/21] sched: pull task_is_descendant into kernel/sched/core.c
` [PATCH ghak90 V7 16/21] audit: add support for contid set/get by netlink
` [PATCH ghak90 V7 17/21] audit: add support for loginuid/sessionid "
` [PATCH ghak90 V7 18/21] audit: track container nesting
` [PATCH ghak90 V7 20/21] audit: add capcontid to set contid outside init_user_ns
` [PATCH ghak90 V7 21/21] audit: add proc interface for capcontid

RHEL 8 audit rules
 2019-11-06 16:49 UTC  (2+ messages)

ntp audit spew
 2019-11-05  0:45 UTC  (25+ messages)
  ` [PATCH] audit: set context->dummy even when audit is off

[RFC] audit support for BPF notification
 2019-11-05  0:18 UTC  (12+ messages)

Audit-3.0 alpha9 available
 2019-11-04 20:32 UTC 

"echo" not logged in auditd
 2019-10-30  1:04 UTC  (3+ messages)

[PATCH] Fix 100% CPU usage (again) due to log rotate
 2019-10-28 22:53 UTC  (2+ messages)

[PATCH] audit: remove redundant condition check in kauditd_thread()
 2019-10-25 15:54 UTC  (4+ messages)

[PATCH v10 21/25] Audit: Add subj_LSM fields when necessary
 2019-10-24 21:41 UTC  (2+ messages)
  ` [PATCH v10 22/25] Audit: Include object data for all security modules

[PATCH] kernel: convert switch/case fallthrough comments to fallthrough;
 2019-10-24  3:39 UTC  (4+ messages)
` [Kgdb-bugreport] "

shadow: what uid to log?
 2019-10-23 16:20 UTC  (2+ messages)

New field seen in audit.log
 2019-10-18 15:49 UTC  (3+ messages)

New field seen in audit.log
 2019-10-16 20:15 UTC  (3+ messages)

[PATCH v3] audit: Report suspicious O_CREAT usage
 2019-10-03 18:29 UTC  (2+ messages)

[PATCH v2] audit: Report suspicious O_CREAT usage
 2019-10-02 21:12 UTC  (2+ messages)

[PATCH] audit: Report suspicious O_CREAT usage
 2019-10-01  5:37 UTC  (9+ messages)

[PATCH] audit_set_pid: add wmode to man page
 2019-10-01  4:27 UTC 

[PATCH 0/2] Fix perltidy on Travis CI
 2019-09-24 22:18 UTC  (3+ messages)
` [PATCH 1/2] audit-testsuite: use our own version of perltidy in the Travis CI tests
` [PATCH 2/2] audit-testsuite: fix the style according to ./tools/check-syntax

[PATCH ghau51/ghau40 v7 00/12] add support for audit container identifier
 2019-09-20 16:12 UTC  (15+ messages)
` [PATCH ghau51/ghau40 v7 01/12] AUDIT_CONTAINER_OP message type basic support
` [PATCH ghau51/ghau40 v7 02/12] AUDIT_CONTAINER_ID "
` [PATCH ghau51/ghau40 v7 03/12] auditctl: add support for AUDIT_CONTID filter
` [PATCH ghau51/ghau40 v7 04/12] add ausearch containerid support
` [PATCH ghau51/ghau40 v7 05/12] start normalization "
` [PATCH ghau51/ghau40 v7 06/12] libaudit: add support to get the task audit container identifier
` [PATCH ghau51/ghau40 v7 07/12] signal_info: only print context if it is available
` [PATCH ghau51/ghau40 v7 08/12] add support for audit_signal_info2
` [PATCH ghau51/ghau40 v7 09/12] contid: interpret correctly CONTAINER_ID contid field csv
` [PATCH ghau51/ghau40 v7 10/12] contid: switch from /proc to netlink
` [PATCH ghau51/ghau40 v7 11/12] loginuid/sessionid: "
` [PATCH ghau51/ghau40 v7 12/12] libaudit: add support to get and set capcontid on a task

[PATCH][RFC] audit: set wait time to zero when audit failed
 2019-09-19 14:04 UTC  (13+ messages)
  ` 答复: "


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).