Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1550118
| From | Paul Moore <paul@paul-moore.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions |
| Date | 2017-01-03 20:40 +0100 |
| Message-ID | <sVD69-2ux-23@gated-at.bofh.it> (permalink) |
| References | <sVe7M-1hm-25@gated-at.bofh.it> <sVjAu-5dr-49@gated-at.bofh.it> <sVqiB-1KJ-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Tue, Jan 3, 2017 at 12:56 AM, Andy Lutomirski <luto@amacapital.net> wrote: > On Mon, Jan 2, 2017 at 2:47 PM, Paul Moore <paul@paul-moore.com> wrote: >> On Mon, Jan 2, 2017 at 11:53 AM, Tyler Hicks <tyhicks@canonical.com> wrote: >>> This patch set creates the basis for auditing information specific to a given >>> seccomp return action and then starts auditing SECCOMP_RET_ERRNO return >>> actions. The audit messages for SECCOMP_RET_ERRNO return actions include the >>> errno value that will be returned to userspace. >> >> I'm replying to this patchset posting because it his my inbox first, >> but my comments here apply to both this patchset and the other >> seccomp/audit patchset you posted. >> >> In my experience, we have two or three problems (the count varies >> depending on perspective) when it comes to seccomp filter reporting: >> >> 1. Inability to log all filter actions. >> 2. Inability to selectively enable filtering; e.g. devs want noisy >> logging, users want relative quiet. >> 3. Consistent behavior with audit enabled and disabled. >> >> My current thinking - forgive me, this has been kicking around in my >> head for the better part of six months (longer?) and I haven't >> attempted to code it up - is to create a sysctl knob for a system wide >> seccomp logging threshold that would be applied to the high 16-bits of >> *every* triggered action: if the action was at/below the threshold a >> record would be emitted, otherwise silence. This should resolve >> problems #1 and #2, and the code should be relatively straightforward >> and small. >> >> As part of the code above, I expect that all seccomp logging would get >> routed through a single logging function (sort of like a better >> implementation of the existing audit_seccomp()) that would check the >> threshold and trigger the logging if needed. This function could be >> augmented to check for CONFIG_AUDIT and in the case where audit was >> not built into the kernel, a simple printk could be used to log the >> seccomp event; solving problem #3. > > Would this not be doable with a seccomp tracepoint and a BPF filter? One of the motivations for the above idea is to make it easier for admins/users to customize the seccomp logging on their own systems, it's not just to make devs lives easier. I feel okay providing guidance to an admin/user the involves setting a sysctl variable, I can't say the same about asking them to write their own BPF ;) -- paul moore www.paul-moore.com
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
[PATCH 1/2] seccomp: Allow for auditing functionality specific to return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
[PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Steve Grubb <sgrubb@redhat.com> - 2017-01-02 18:30 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:50 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Steve Grubb <sgrubb@redhat.com> - 2017-01-02 20:00 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Paul Moore <paul@paul-moore.com> - 2017-01-03 00:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-02 23:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Andy Lutomirski <luto@amacapital.net> - 2017-01-03 07:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 20:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-03 14:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 21:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 21:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Steve Grubb <sgrubb@redhat.com> - 2017-01-03 22:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:20 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:30 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-04 03:20 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Richard Guy Briggs <rgb@redhat.com> - 2017-01-04 05:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-04 07:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-04 03:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Andy Lutomirski <luto@kernel.org> - 2017-01-03 07:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-03 15:00 +0100
csiph-web