public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH ghak8 ALT4 V4 0/3] audit: show more information for entries with anonymous parents
@ 2018-02-12  5:02 Richard Guy Briggs
  2018-02-12  5:02 ` [PATCH ghak8 ALT4 V4 1/3] audit: show partial pathname " Richard Guy Briggs
                   ` (3 more replies)
  0 siblings, 4 replies; 11+ messages in thread
From: Richard Guy Briggs @ 2018-02-12  5:02 UTC (permalink / raw)
  To: Linux-Audit Mailing List, LKML
  Cc: Paul Moore, Eric Paris, Steve Grubb, Richard Guy Briggs

More than one filesystem was causing hundreds to thousands of null PATH
records to be associated with the *init_module SYSCALL records on a few
modules with corresponding audit syscall rules.

This patchset adds extra information to those PATH records to provide
insight into what is generating them, including a partial pathname,
fstype field, and two new filetypes that indicate the pathname isn't
anchored at the root of the task's root filesystem.

Richard Guy Briggs (3):
  audit: show partial pathname for entries with anonymous parents
  audit: append new fstype field for anonymous PATH records
  audit: add new filetypes CREATE_ANON and PARENT_ANON

 include/linux/audit.h | 10 ++++++----
 kernel/audit.c        | 41 ++++++++++++++++++++++++++++++++++++++++-
 kernel/audit.h        |  1 +
 kernel/auditsc.c      | 12 ++++++++++--
 4 files changed, 57 insertions(+), 7 deletions(-)

-- 
1.8.3.1

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2018-02-16 18:29 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-02-12  5:02 [PATCH ghak8 ALT4 V4 0/3] audit: show more information for entries with anonymous parents Richard Guy Briggs
2018-02-12  5:02 ` [PATCH ghak8 ALT4 V4 1/3] audit: show partial pathname " Richard Guy Briggs
2018-02-15 23:07   ` Steve Grubb
2018-02-15 23:19     ` Richard Guy Briggs
2018-02-16  6:30       ` Richard Guy Briggs
2018-02-16  6:00     ` Richard Guy Briggs
2018-02-12  5:02 ` [PATCH ghak8 ALT4 V4 2/3] audit: append new fstype field for anonymous PATH records Richard Guy Briggs
2018-02-12  5:02 ` [PATCH ghak8 ALT4 V4 3/3] audit: add new filetypes CREATE_ANON and PARENT_ANON Richard Guy Briggs
2018-02-15 22:15 ` [PATCH ghak8 ALT4 V4 0/3] audit: show more information for entries with anonymous parents Paul Moore
2018-02-16  8:23   ` Richard Guy Briggs
2018-02-16 18:29     ` Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox