From: Lev Stipakov <lstipakov@gmail.com>
To: linux-audit@redhat.com
Subject: syscall - "comm" field truncated
Date: Wed, 6 Apr 2016 16:53:50 +0300 [thread overview]
Message-ID: <ne34de$drk$1@ger.gmane.org> (raw)
Hello,
Sometimes audit of "execve" syscall generates events with truncated
"comm" values, for example:
type=SYSCALL msg=audit(1459950426.152:1097081): arch=c000003e syscall=59
success=yes exit=0 a0=35bae3e a1=1bc0cf0 a2=2b09280 a3=58c items=2
ppid=2183 pid=26566 auid=4294967295 uid=1001 gid=1001 euid=1001
suid=1001 fsuid=1001 egid=1001 sgid=1001 fsgid=1001 tty=(none)
ses=4294967295 comm="gnome-calculato" exe="/usr/bin/gnome-calculator"
Why "comm" is "gnome-calculato" and not "/usr/bin/gnome-calculator" ?
Same for Firefiox:
type=SYSCALL msg=audit(1459950158.667:1092149): arch=c000003e syscall=59
success=yes exit=0 a0=7f913ed1ddf0 a1=7f9144819be0 a2=7f9173f14400
a3=786f666572696600 items=2 ppid=26165 pid=26247 auid=4294967295
uid=1001 gid=1001 euid=1001 suid=1001 fsuid=1001 egid=1001 sgid=1001
fsgid=1001 tty=(none) ses=4294967295 comm="plugin-containe"
exe="/usr/lib/firefox/plugin-container"
comm is "plugin-containe" and not "plugin-container".
Audit version is 2.4.2-1ubuntu1.
-Lev
next reply other threads:[~2016-04-06 13:54 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-04-06 13:53 Lev Stipakov [this message]
2016-04-06 14:05 ` syscall - "comm" field truncated Paul Moore
2016-04-06 14:37 ` Steve Grubb
2016-04-06 15:21 ` Richard Guy Briggs
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='ne34de$drk$1@ger.gmane.org' \
--to=lstipakov@gmail.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox