login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2008
»
July
»
31
Re: [PATCH] the loginuid field should be output in all AUDIT_CONFIG_CHANGE audit messages
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: Eric Paris
Subject:
Re: [PATCH] the loginuid field should be output in all AUDIT_CONFIG_CHANGE audit messages
Date: Thursday, July 31, 2008 - 10:42 am
On Wed, 2008-07-30 at 11:40 +0800, zhangxiliang wrote:
quoted text
> In the audit message which type is "AUDIT_CONFIG_CHANGE", the output format should contain "auid" field.
shouldn't these be using the "audit_get_loginuid(current)" and if we are going to output loginuid we also should be outputting sessionid -Eric
quoted text
> > Signed-off-by: Zhang Xiliang <zhangxiliang@cn.fujitsu.com> > --- > kernel/auditfilter.c | 6 ++++-- > 1 files changed, 4 insertions(+), 2 deletions(-) > > diff --git a/kernel/auditfilter.c b/kernel/auditfilter.c > index 98c50cc..8a184f5 100644 > --- a/kernel/auditfilter.c > +++ b/kernel/auditfilter.c > @@ -1022,8 +1022,9 @@ static void audit_update_watch(struct audit_parent *parent, > struct audit_buffer *ab; > ab = audit_log_start(NULL, GFP_KERNEL, > AUDIT_CONFIG_CHANGE); > + audit_log_format(ab, "auid=%u", current->loginuid); > audit_log_format(ab, > - "op=updated rules specifying path="); > + " op=updated rules specifying path="); > audit_log_untrustedstring(ab, owatch->path); > audit_log_format(ab, " with dev=%u ino=%lu\n", > dev, ino); > @@ -1058,7 +1059,8 @@ static void audit_remove_parent_watches(struct audit_parent *parent) > struct audit_buffer *ab; > ab = audit_log_start(NULL, GFP_KERNEL, > AUDIT_CONFIG_CHANGE); > - audit_log_format(ab, "op=remove rule path="); > + audit_log_format(ab, "auid=%u", current->loginuid); > + audit_log_format(ab, " op=remove rule path="); > audit_log_untrustedstring(ab, w->path); > if (r->filterkey) { > audit_log_format(ab, " key="); > -- > 1.5.4.2 > >
--
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
[PATCH] the loginuid field should be output in all AUDIT_C ...
, zhangxiliang
, (Tue Jul 29, 8:40 pm)
Re: [PATCH] the loginuid field should be output in all AUD ...
, Eric Paris
, (Thu Jul 31, 10:42 am)
Re: [PATCH] the loginuid field should be output in all AUD ...
, zhangxiliang
, (Thu Jul 31, 6:47 pm)
Navigation
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Michael Trimarchi
Re: [PATCH] VFS: make file->f_pos access atomic on 32bit arch
Miklos Szeredi
[patch 14/15] vfs: more path_permission() conversions
Serge E. Hallyn
Re: [RFC v5][PATCH 7/8] Infrastructure for shared objects
Bernd Schmidt
Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3
Takashi Iwai
[PATCH 2/2] input: Add LED support to Synaptics device
git
:
Junio C Hamano
Re: mingw, windows, crlf/lf, and git
Eyvind Bernhardsen
Re: Where has "git ls-remote" reference pattern matching gone?
Shawn O. Pearce
Re: Switching from CVS to GIT
Todd Zullinger
Re: [PATCH 2/2] send-email: rfc2047-quote subject lines with non-ascii characters
Santi Béjar
Re: How to use git-fmt-merge-msg?
linux-netdev
:
Ramkrishna Vepa
[net-2.6 PATCH 1/10] Neterion: New driver: Driver help file
Mark Anthony
invitation / inquiry
Ingo Molnar
Re: [PATCH 08/16] dma-debug: add core checking functions
David Miller
Re: [PATCH 1/3] f_phonet: dev_kfree_skb instead of dev_kfree_skb_any in TX callback
Sascha Hauer
[PATCH 03/12] fec: do not typedef struct types
git-commits-head
:
Linux Kernel Mailing List
amba: struct device - replace bus_id with dev_name(), dev_set_name()
Linux Kernel Mailing List
MIPS: Yosemite: Convert SMP startup lock to arch spinlock.
Linux Kernel Mailing List
ARM: S5PC100: IRQ and timer
Linux Kernel Mailing List
davinci: edma: clear interrupt status for interrupt enabled channels only
Linux Kernel Mailing List
x86, mm, kprobes: fault.c, simplify notify_page_fault()
openbsd-misc
:
Daniel A. Ramaley
Re: [semi-OT] Can anyone recommend an OpenBSD-compatible colour laser printer?
Matthias Kilian
Re: can't get vesa @ 1280x800 or nv
Tobias Ulmer
Re: Problem after upgrade 4.5 to 4.6: ERR M
Philip Guenther
Re: SIGCHLD and libpthread.so
J.C. Roberts
Re: [semi-OT] Can anyone recommend an OpenBSD-compatible colour laser printer?
Colocation donated by:
Syndicate