Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1619510
| Path | csiph.com!eternal-september.org!feeder.eternal-september.org!news.unit0.net!news.panservice.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | Paul Moore <paul@paul-moore.com> |
| Newsgroups | linux.kernel |
| Subject | Re: audit regressions in 4.11 |
| Date | Sun, 09 Apr 2017 17:50:01 +0200 |
| Message-ID | <tungd-4Fb-7@gated-at.bofh.it> (permalink) |
| References | <tuboJ-5M0-1@gated-at.bofh.it> <tukV4-3gS-1@gated-at.bofh.it> <tumk9-43z-3@gated-at.bofh.it> |
| X-Original-To | Seth Forshee <seth.forshee@canonical.com> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=YC01N6Z2dQcJn3L4mw320MqxYw4eaqcQ5uDkcftxuHI=; b=ncA9XEZHhOp7lS9QSO8vOU0X3D+hp+oBdM1bcp2eYR+N6awskTjxPJ5nIFMQg4UYDD zh5HIgGO3x2BsSY3KS7j+OLN2qEkD0mBqHej+bR2mnwYwVKEnW9ykdn867rzk1JqgH/O TOYvQT+bc4KbQBvX3AeMdl14s3ITorhGAWzEnXmVBWbXXZhGoA0dJt0LTmGsjLoxQOO+ bytBJesC1M28/0+vBw1a0gp9Qbf4BhMMgjpvhKIOWwrvw0BRWW0w7nxNF2BM62YimvLC ocrOxQFkwa6BOZAL05s40YJ+f4OFETsLPJtuxQwBAOoSPqA3IM9uMX8PrEGvaxnoAONz 89dw== |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=YC01N6Z2dQcJn3L4mw320MqxYw4eaqcQ5uDkcftxuHI=; b=EigaI0h9PazxSfgsMePEkKkuPQQMEpIVnD8JoRD4NzCeViaA9tB1XeAn7dA0qs0upi /JG9tN0hle+rj2y82mG9kUKifphrccX7MytcmlUEHt+vNjSZ0yYHl3pWfy52Wz0bw2i7 nwn2m0dHuzziGCEimcLbc15XYBi3TCRSu6Lh9L6ML1dHzHZrGJLZCQitCwgMFgiP/rMC kTKF/iicZ23uckbVJB0n4F4RMGz4R8zQP+dguq+KrtUboW56aGDQAWEeLaCBLxyCF5pB we54uioJ9tgBIfENKNPcvmxtYU/jvqglLjIwkgcjteX/OSeFRqIo2YJATJOt68Y5OUup hzmQ== |
| X-Gm-Message-State | AFeK/H32VXNcJzl2I6B9eeXKDYPotN8VW2s+G8my9C9ojsSGLoswKIqW5ZLPmbgyXUhEwtxRZv7CxOn7MulPVQ== |
| X-Received | by 10.31.228.193 with SMTP id b184mr23435694vkh.77.1491752616841; Sun, 09 Apr 2017 08:43:36 -0700 (PDT) |
| MIME-Version | 1.0 |
| X-Originating-IP | [108.49.102.27] |
| Content-Type | text/plain; charset=UTF-8 |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 52 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | Eric Paris <eparis@redhat.com>, linux-audit@redhat.com, linux-kernel@vger.kernel.org |
| X-Original-Date | Sun, 9 Apr 2017 11:43:36 -0400 |
| X-Original-Message-ID | <CAHC9VhQbSwxAskTvsbOaqo72ComdyZcpp8vKXiuJvgGi7JAdEA@mail.gmail.com> |
| X-Original-References | <20170409030220.GA33027@ubuntu-hedt> <CAHC9VhQU5QEEVVvj9reG_oVQvFV2UmJwstHQCLbyfUBTA56tRQ@mail.gmail.com> <20170409144009.GA44106@ubuntu-hedt> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1619510 |
Show key headers only | View raw
On Sun, Apr 9, 2017 at 10:40 AM, Seth Forshee <seth.forshee@canonical.com> wrote: > On Sun, Apr 09, 2017 at 09:14:03AM -0400, Paul Moore wrote: >> On Sat, Apr 8, 2017 at 11:02 PM, Seth Forshee >> <seth.forshee@canonical.com> wrote: >> > I've observed audit regressions in 4.11-rc when not using a userspace >> > audit daemon. The most obvious issue is that audit messages are not >> > appearing in dmesg anymore. If a sufficient number of audit messages are >> > generated the kernel will also start invoking the OOM killer. >> > >> > It looks like previously, when there's no auditd in userspace kauditd >> > would call kauditd_hold_skb(), which prints the message using printk and >> > either frees the skb or queues it (with a limit on the number of queued >> > skb's by default). >> > >> > Since 5b52330bbfe6 "audit: fix auditd/kernel connection state tracking" >> > when there's no auditd kauditd will instead use the retry queue, which >> > has no limit. But it will not process the retry queue when there's no >> > auditd, so messages pile up there indefinitely. >> >> Hi Seth, >> >> Thanks for the report. Let me play with this and think on it for a >> bit, but looking at the code again I think the issue is that we check >> to see if auditd is connected at the top of the kauditd_thread() loop >> and if it isn't we skip right to the main_queue label and bypass the >> hold/retry queue processing which has the logic to ensure the retry >> queue is managed correctly. My initial thinking is that the fix is to >> check and see if auditd is connected in kauditd_retry_skb(), if it >> isn't we skip the retry queue and call kauditd_hold_skb(), if auditd >> is connected we add the record to the retry queue (what we currently >> do). > > Yeah, my first thought was to make this change: > > kauditd_send_queue(sk, portid, &audit_queue, 1, > kauditd_send_multicast_skb, > - kauditd_retry_skb); > + sk ? kauditd_retry_skb : kauditd_hold_skb); > > However some scenarios could result in unbounded queueing on the hold > queue as well, so I'm not sure if that's quite enough. At the moment I think I'd prefer to put the auditd check inside kauditd_retry_skb() itself, but you've got the basic idea. Keep in mind that kauditd_hold_skb() already has the logic inside itself to prevent the hold queue from growing out of control. -- paul moore www.paul-moore.com
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
audit regressions in 4.11 Seth Forshee <seth.forshee@canonical.com> - 2017-04-09 05:10 +0200
Re: audit regressions in 4.11 Paul Moore <paul@paul-moore.com> - 2017-04-09 15:20 +0200
Re: audit regressions in 4.11 Seth Forshee <seth.forshee@canonical.com> - 2017-04-09 16:50 +0200
Re: audit regressions in 4.11 Paul Moore <paul@paul-moore.com> - 2017-04-09 17:50 +0200
csiph-web