Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1550210
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions |
| Date | 2017-01-03 22:30 +0100 |
| Message-ID | <sVEOB-3FK-11@gated-at.bofh.it> (permalink) |
| References | (3 earlier) <sVDzc-2TT-19@gated-at.bofh.it> <sVEbU-3aT-23@gated-at.bofh.it> <sVEvg-3xp-49@gated-at.bofh.it> <sVEvh-3xp-73@gated-at.bofh.it> <sVEEW-3Cx-25@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Tue, Jan 3, 2017 at 1:13 PM, Paul Moore <paul@paul-moore.com> wrote: > On Tue, Jan 3, 2017 at 4:03 PM, Kees Cook <keescook@chromium.org> wrote: >> On Tue, Jan 3, 2017 at 12:54 PM, Paul Moore <paul@paul-moore.com> wrote: >>> On Tue, Jan 3, 2017 at 3:44 PM, Kees Cook <keescook@chromium.org> wrote: >>>> I still wonder, though, isn't there a way to use auditctl to get all >>>> the seccomp messages you need? >>> >>> Not all of the seccomp actions are currently logged, that's one of the >>> problems (and the biggest at the moment). >> >> Well... sort of. It all gets passed around, but the logic isn't very >> obvious (or at least I always have to go look it up). > > Last time I checked SECCOMP_RET_ALLOW wasn't logged (as well as at > least one other action, but I can't remember which off the top of my > head)? Sure, but if you're using audit, you don't need RET_ALLOW to be logged because you'll get a full syscall log entry. Logging RET_ALLOW is redundant and provides no new information, it seems to me. -Kees -- Kees Cook Nexus Security
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
[PATCH 1/2] seccomp: Allow for auditing functionality specific to return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
[PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:00 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Steve Grubb <sgrubb@redhat.com> - 2017-01-02 18:30 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Tyler Hicks <tyhicks@canonical.com> - 2017-01-02 18:50 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Steve Grubb <sgrubb@redhat.com> - 2017-01-02 20:00 +0100
Re: [PATCH 2/2] seccomp: Audit SECCOMP_RET_ERRNO actions with errno values Paul Moore <paul@paul-moore.com> - 2017-01-03 00:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-02 23:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Andy Lutomirski <luto@amacapital.net> - 2017-01-03 07:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 20:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-03 14:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 21:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 21:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Steve Grubb <sgrubb@redhat.com> - 2017-01-03 22:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:20 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:30 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Paul Moore <paul@paul-moore.com> - 2017-01-03 22:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-03 22:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-04 03:20 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Richard Guy Briggs <rgb@redhat.com> - 2017-01-04 05:50 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Kees Cook <keescook@chromium.org> - 2017-01-04 07:40 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-04 03:10 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Andy Lutomirski <luto@kernel.org> - 2017-01-03 07:00 +0100
Re: [PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions Tyler Hicks <tyhicks@canonical.com> - 2017-01-03 15:00 +0100
csiph-web