Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1418966

Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps

From Deepa Dinamani <deepa.kernel@gmail.com>
Newsgroups linux.kernel
Subject Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps
Date 2016-06-10 02:50 +0200
Message-ID <rIiO6-5IZ-7@gated-at.bofh.it> (permalink)
References <rI0o9-1PH-9@gated-at.bofh.it> <rI0o9-1PH-15@gated-at.bofh.it> <rI9hM-7C2-25@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Thu, Jun 9, 2016 at 7:31 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> On Wednesday, June 08, 2016 10:05:01 PM Deepa Dinamani wrote:
>> Audit timestamps are recorded in string format into
>> an audit buffer for a given context.
>> These mark the entry timestamps for the syscalls.
>> Use y2038 safe struct timespec64 to represent the times.
>> The log strings can handle this transition as strings can
>> hold upto 1024 characters.
>
> Have you tested this with ausearch or any audit utilities? As an aside, a time
> stamp that is up to 1024 characters long is terribly wasteful considering how
> many events we get.

/* AUDIT_BUFSIZ is the size of the temporary buffer used for formatting
 * audit records.  Since printk uses a 1024 byte buffer, this buffer
 * should be at least that large. */
#define AUDIT_BUFSIZ 1024

The commit text is pointing out that the reserve space ensured in each
call to audit_log_vformat is already much more than is needed by this
call from audit_log_start.

Also, since struct timespec64 is already the same as struct timespec
on 64-bit systems, there is really no functional change except on
32-bit machines.

Let me know if you want me to try it out on a 32-bit system.

-Deepa

Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

[PATCH 17/21] audit: Use timespec64 to represent audit timestamps Deepa Dinamani <deepa.kernel@gmail.com> - 2016-06-09 07:10 +0200
  Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Steve Grubb <sgrubb@redhat.com> - 2016-06-09 16:40 +0200
    Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Richard Guy Briggs <rgb@redhat.com> - 2016-06-10 02:00 +0200
      Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Steve Grubb <sgrubb@redhat.com> - 2016-06-10 02:30 +0200
        Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Richard Guy Briggs <rgb@redhat.com> - 2016-06-10 03:50 +0200
    Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Deepa Dinamani <deepa.kernel@gmail.com> - 2016-06-10 02:50 +0200

csiph-web