Thread (58 messages) 58 messages, 5 authors, 2025-01-16

Re: [PATCH v4 28/30] audit,landlock: Add AUDIT_EXE_LANDLOCK_DENY rule type

From: Paul Moore <paul@paul-moore.com>
Date: 2025-01-15 23:53:10
Also in: lkml

On Jan  8, 2025 =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= [off-list ref] wrote:
Landlock manages a set of standalone security policies, which can be
loaded by any process.  Because a sandbox policy may contain errors and
can lead to log spam, we need a way to exclude some of them.  It is
simple and it makes sense to identify Landlock domains (i.e. security
policies) per binary path that loaded such policy.

Add a new AUDIT_EXE_LANDLOCK_DENY rule type to enables system
administrator to filter logs according to the origin or the security
policy responsible for a denial.
For reasons similar to why I didn't want to expose the audit timestamp
to users outside of audit, I'm not very enthusiastic about expanding
the audit filtering code at this point in time.

I'm not saying "no" exactly, just "not right now".


--
paul-moore.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help