Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1418966
| From | Deepa Dinamani <deepa.kernel@gmail.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps |
| Date | 2016-06-10 02:50 +0200 |
| Message-ID | <rIiO6-5IZ-7@gated-at.bofh.it> (permalink) |
| References | <rI0o9-1PH-9@gated-at.bofh.it> <rI0o9-1PH-15@gated-at.bofh.it> <rI9hM-7C2-25@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Thu, Jun 9, 2016 at 7:31 AM, Steve Grubb <sgrubb@redhat.com> wrote: > On Wednesday, June 08, 2016 10:05:01 PM Deepa Dinamani wrote: >> Audit timestamps are recorded in string format into >> an audit buffer for a given context. >> These mark the entry timestamps for the syscalls. >> Use y2038 safe struct timespec64 to represent the times. >> The log strings can handle this transition as strings can >> hold upto 1024 characters. > > Have you tested this with ausearch or any audit utilities? As an aside, a time > stamp that is up to 1024 characters long is terribly wasteful considering how > many events we get. /* AUDIT_BUFSIZ is the size of the temporary buffer used for formatting * audit records. Since printk uses a 1024 byte buffer, this buffer * should be at least that large. */ #define AUDIT_BUFSIZ 1024 The commit text is pointing out that the reserve space ensured in each call to audit_log_vformat is already much more than is needed by this call from audit_log_start. Also, since struct timespec64 is already the same as struct timespec on 64-bit systems, there is really no functional change except on 32-bit machines. Let me know if you want me to try it out on a 32-bit system. -Deepa
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH 17/21] audit: Use timespec64 to represent audit timestamps Deepa Dinamani <deepa.kernel@gmail.com> - 2016-06-09 07:10 +0200
Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Steve Grubb <sgrubb@redhat.com> - 2016-06-09 16:40 +0200
Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Richard Guy Briggs <rgb@redhat.com> - 2016-06-10 02:00 +0200
Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Steve Grubb <sgrubb@redhat.com> - 2016-06-10 02:30 +0200
Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Richard Guy Briggs <rgb@redhat.com> - 2016-06-10 03:50 +0200
Re: [PATCH 17/21] audit: Use timespec64 to represent audit timestamps Deepa Dinamani <deepa.kernel@gmail.com> - 2016-06-10 02:50 +0200
csiph-web