Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1254959
| From | Paul Moore <paul@paul-moore.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: Should audit_seccomp check audit_enabled? |
| Date | 2015-10-23 21:40 +0200 |
| Message-ID | <qmQlX-2ya-5@gated-at.bofh.it> (permalink) |
| References | <qmNeq-6xZ-13@gated-at.bofh.it> <qmO0O-7In-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, Oct 23, 2015 at 1:01 PM, Kees Cook <keescook@chromium.org> wrote: > On Fri, Oct 23, 2015 at 9:19 AM, Andy Lutomirski <luto@amacapital.net> wrote: >> I would argue that, if auditing is off, audit_seccomp shouldn't do >> anything. After all, unlike e.g. selinux, seccomp is not a systemwide >> policy, and seccomp signals might be ordinary behavior that's internal >> to the seccomp-using application. IOW, for people with audit compiled >> in and subscribed by journald but switched off, I think that the >> records shouldn't be emitted. >> >> If you agree, I can send the two-line patch. > > I think signr==0 states (which I would identify as "intended > behavior") don't need to be reported under any situation, but audit > folks wanted to keep it around. Wearing my libseccomp hat, I would like some logging when the seccomp filter triggers a result other than allow. I don't care if this is via audit or printk(), I just want some notification. If we go the printk route and people really don't want to see anything in their logs, I suppose we could always add a sysctl knob to turn off the message completely (we would still need to do whatever audit records are required, see below). Wearing my audit hat, I want to make sure we tick off all the right boxes for the various certifications that people care about. Steve Grubb has commented on what he needs in the past, although I'm not sure it was on-list, so I'll ask him to repeat it here. -- paul moore www.paul-moore.com -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Should audit_seccomp check audit_enabled? Andy Lutomirski <luto@amacapital.net> - 2015-10-23 18:20 +0200
Re: Should audit_seccomp check audit_enabled? Kees Cook <keescook@chromium.org> - 2015-10-23 19:10 +0200
Re: Should audit_seccomp check audit_enabled? Paul Moore <paul@paul-moore.com> - 2015-10-23 21:40 +0200
Re: Should audit_seccomp check audit_enabled? Steve Grubb <sgrubb@redhat.com> - 2015-10-23 23:00 +0200
Re: Should audit_seccomp check audit_enabled? Paul Moore <paul@paul-moore.com> - 2015-10-23 23:00 +0200
Re: Should audit_seccomp check audit_enabled? Andy Lutomirski <luto@amacapital.net> - 2015-10-23 23:10 +0200
Re: Should audit_seccomp check audit_enabled? Andy Lutomirski <luto@amacapital.net> - 2015-10-23 23:10 +0200
Re: Should audit_seccomp check audit_enabled? Andy Lutomirski <luto@amacapital.net> - 2015-10-23 23:30 +0200
Re: Should audit_seccomp check audit_enabled? Paul Moore <paul@paul-moore.com> - 2015-10-24 04:30 +0200
Re: Should audit_seccomp check audit_enabled? Kees Cook <keescook@chromium.org> - 2015-10-23 23:30 +0200
Re: Should audit_seccomp check audit_enabled? Richard Guy Briggs <rgb@redhat.com> - 2015-10-23 21:20 +0200
csiph-web