Thread (5 messages) 5 messages, 3 authors, 2019-03-27

Re: [PATCH ghak109 V2] audit: link integrity evm_write_xattrs record to syscall event

From: Paul Moore <paul@paul-moore.com>
Date: 2019-03-27 22:14:40
Also in: linux-integrity, lkml

On Wed, Mar 27, 2019 at 11:05 AM Mimi Zohar [off-list ref] wrote:
On Tue, 2019-03-26 at 19:58 -0400, Paul Moore wrote:
quoted
On Tue, Mar 26, 2019 at 4:40 PM Mimi Zohar [off-list ref] wrote:
quoted
Hi Richard, Paul,

On Tue, 2019-03-26 at 14:49 -0400, Richard Guy Briggs wrote:
quoted
In commit fa516b66a1bf ("EVM: Allow runtime modification of the set of
verified xattrs"), the call to audit_log_start() is missing a context to
link it to an audit event. Since this event is in user context, add
the process' syscall context to the record.

In addition, the orphaned keyword "locked" appears in the record.
Normalize this by changing it to logging the locking string "." as any
other user input in the "xattr=" field.

Please see the github issue
https://github.com/linux-audit/audit-kernel/issues/109

Signed-off-by: Richard Guy Briggs <redacted>
Acked-by: Mimi Zohar <zohar@linux.ibm.com>

Paul, were you planning on upstreaming this patch?
Yep, unless you would rather do it?
No, that's fine. Thanks!
Merged into audit/next, thanks all.

-- 
paul moore
www.paul-moore.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help