public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: Andy Lutomirski <luto@amacapital.net>
Cc: Oleg Nesterov <oleg@redhat.com>,
	linux-audit@redhat.com,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	Andi Kleen <andi@firstfloor.org>, Eric Paris <eparis@redhat.com>
Subject: Re: [PATCH v3] audit: Turn off TIF_SYSCALL_AUDIT when there are no rules
Date: Mon, 10 Feb 2014 12:47:21 -0500	[thread overview]
Message-ID: <6760094.oQMeiCg8QG@x2> (raw)
In-Reply-To: <CALCETrX9gb_+zW4UZZv5icCQ-3HNG7BFZOaqMPYaQfzotsZpnA@mail.gmail.com>

On Monday, February 10, 2014 09:29:19 AM Andy Lutomirski wrote:
> Grr.  Why is all this crap tied up with syscall auditing anyway?  ISTM
> it would have been a lot nicer if audit calls just immediately emitted
> audit records, completely independently of the syscall machinery.

Because the majority of people needing audit need syscall records for it to 
make any sense. The auxiliary records generally report on the object of the 
syscall. We still require information about who was doing something, what they 
were doing, and what the result was. 

Even if you just get the AVC's, you still don't know what happened. If you get 
a deny record, was it really denied? The system could have been in permissive 
mode and the syscall succeeded. You only get the real decision when you have 
syscall records.

-Steve

  reply	other threads:[~2014-02-10 17:47 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-02-08 21:06 [PATCH v3] audit: Turn off TIF_SYSCALL_AUDIT when there are no rules Andy Lutomirski
2014-02-10 16:57 ` Oleg Nesterov
2014-02-10 17:29   ` Andy Lutomirski
2014-02-10 17:47     ` Steve Grubb [this message]
2014-02-10 18:05       ` Andy Lutomirski
2014-02-10 19:01     ` Andy Lutomirski
2014-02-10 19:12       ` Steve Grubb
2014-02-10 20:04         ` Andy Lutomirski
2014-02-18 17:32           ` Eric Paris
2014-02-18 17:31       ` Eric Paris
2014-02-18 20:17 ` Eric Paris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6760094.oQMeiCg8QG@x2 \
    --to=sgrubb@redhat.com \
    --cc=andi@firstfloor.org \
    --cc=eparis@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luto@amacapital.net \
    --cc=oleg@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox