Netdev List
 help / color / mirror / Atom feed
From: Joy Latten <latten@austin.ibm.com>
To: James Morris <jmorris@namei.org>
Cc: netdev@vger.kernel.org, davem@davemloft.net,
	herbert@gondor.apana.org.au, sgrubb@redhat.com
Subject: Re: [PATCH 1/1] additional ipsec audit patch
Date: Thu, 30 Nov 2006 17:44:36 -0600	[thread overview]
Message-ID: <1164930276.17737.530.camel@faith.austin.ibm.com> (raw)
In-Reply-To: <XMMS.LNX.4.64.0611291932200.28199@d.namei>

On Wed, 2006-11-29 at 19:32 -0500, James Morris wrote:
> On Wed, 29 Nov 2006, James Morris wrote:
> 
> > On Wed, 29 Nov 2006, Joy Latten wrote:
> > 
> > > This patch disables auditing in ipsec when CONFIG_AUDITSYSCALL is
> > > disabled in the kernel. 
> > > 
> > > This patch also includes a bug fix for xfrm_state.c as a result of
> > > original ipsec audit patch.
> > > 
> > > Let me know if it looks ok.
> > 
> > 
> > Also, the last patch contains no Signed-off-by: line, please resend.
> 
> And, what is the testing status of these patches?
> 
I ran a stress test overnight using labeled ipsec on a patched lspp55 kernel 
using racoon last week.

The additional patch to xfrm_state.c was my fault when rebasing to
2.6.19-rc6 to send upstream. I plan to run an ipv4 and ipv6 stress test
tonight and tomorrow using labeled ipsec with auditing enabled on the
lspp56 kernel, which contains ipsec audit patch, to ensure no regression
has occurred. I can also run an ipv4 and ipv6 stress tests
with regular ipsec over the weekend for further ensurance.   

I compiled and did unit test with SELINUX disabled, AUDITSYSCALL
disabled, and with both enabled. 

regards,
Joy

  reply	other threads:[~2006-11-30 23:58 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-11-29 23:48 [PATCH 1/1] additional ipsec audit patch Joy Latten
2006-11-30  0:30 ` James Morris
2006-11-30  0:32   ` James Morris
2006-11-30 23:44     ` Joy Latten [this message]
2006-12-01  0:03       ` James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1164930276.17737.530.camel@faith.austin.ibm.com \
    --to=latten@austin.ibm.com \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=jmorris@namei.org \
    --cc=netdev@vger.kernel.org \
    --cc=sgrubb@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox