Thread (5 messages) 5 messages, 2 authors, 2006-12-01

Re: [PATCH 1/1] additional ipsec audit patch

From: Joy Latten <hidden>
Date: 2006-11-30 23:58:09

On Wed, 2006-11-29 at 19:32 -0500, James Morris wrote:
On Wed, 29 Nov 2006, James Morris wrote:
quoted
On Wed, 29 Nov 2006, Joy Latten wrote:
quoted
This patch disables auditing in ipsec when CONFIG_AUDITSYSCALL is
disabled in the kernel. 

This patch also includes a bug fix for xfrm_state.c as a result of
original ipsec audit patch.

Let me know if it looks ok.

Also, the last patch contains no Signed-off-by: line, please resend.
And, what is the testing status of these patches?
I ran a stress test overnight using labeled ipsec on a patched lspp55 kernel 
using racoon last week.

The additional patch to xfrm_state.c was my fault when rebasing to
2.6.19-rc6 to send upstream. I plan to run an ipv4 and ipv6 stress test
tonight and tomorrow using labeled ipsec with auditing enabled on the
lspp56 kernel, which contains ipsec audit patch, to ensure no regression
has occurred. I can also run an ipv4 and ipv6 stress tests
with regular ipsec over the weekend for further ensurance.   

I compiled and did unit test with SELINUX disabled, AUDITSYSCALL
disabled, and with both enabled. 

regards,
Joy
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help