Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1262869
| From | Richard Guy Briggs <rgb@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [RFC PATCH 1/7] audit: don't needlessly reset valid wait time |
| Date | 2015-11-05 04:20 +0100 |
| Message-ID | <qrjfH-16l-3@gated-at.bofh.it> (permalink) |
| References | <qmtfH-2HW-1@gated-at.bofh.it> <qmtfI-2HW-31@gated-at.bofh.it> <qrflM-6Yk-19@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 15/11/04, Paul Moore wrote: > On Thursday, October 22, 2015 02:53:14 PM Richard Guy Briggs wrote: > > After auditd has recovered from an overflowed queue, the first process > > that doesn't use reserves to make it through the queue checks should > > reset the audit backlog wait time to the configured value. After that, > > there is no need to keep resetting it. > > > > Signed-off-by: Richard Guy Briggs <rgb@redhat.com> > > --- > > kernel/audit.c | 2 +- > > 1 files changed, 1 insertions(+), 1 deletions(-) > > > > diff --git a/kernel/audit.c b/kernel/audit.c > > index a72ad37..daefd81 100644 > > --- a/kernel/audit.c > > +++ b/kernel/audit.c > > @@ -1403,7 +1403,7 @@ struct audit_buffer *audit_log_start(struct > > audit_context *ctx, gfp_t gfp_mask, return NULL; > > } > > > > - if (!reserve) > > + if (!reserve && !audit_backlog_wait_time) > > audit_backlog_wait_time = audit_backlog_wait_time_master; > > > > ab = audit_buffer_alloc(ctx, gfp_mask, type); > > This looks fine to me, I'm going to add it to audit#next-queue. > > Also, can you think of a good reason why "audit_backlog_wait_overflow" exists? > I'm going to replace it with the simple "audit_backlog_wait_time = 0;" unless > you can think of a solid reason not to do so. It seems much more obvious and > readable to me. That goes back to ac4cec44, DWMW, July 2005. Best answer I can come up with is that it labels magic values and puts them up front at the top of the file. I'd suggest instead replacing it with a macro. I don't have an significant objection to just assigning zero where you suggest. > paul moore - RGB -- Richard Guy Briggs <rbriggs@redhat.com> Senior Software Engineer, Kernel Security, AMER ENG Base Operating Systems, Red Hat Remote, Ottawa, Canada Voice: +1.647.777.2635, Internal: (81) 32635, Alt: +1.613.693.0684x3545 -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [RFC PATCH 1/7] audit: don't needlessly reset valid wait time Paul Moore <paul@paul-moore.com> - 2015-11-05 00:10 +0100
Re: [RFC PATCH 1/7] audit: don't needlessly reset valid wait time Richard Guy Briggs <rgb@redhat.com> - 2015-11-05 04:20 +0100
Re: [RFC PATCH 1/7] audit: don't needlessly reset valid wait time Paul Moore <paul@paul-moore.com> - 2015-11-05 16:20 +0100
csiph-web