|
Re: [PATCH] LSM hooks for audit: msg#00043linux.kernel.lsm
Serge Hallyn wrote: Sorry, on a second look I notice the descriptions in security.h are farThanks for the description. Note that the audit code (kernel/audit.c and kernel/auditsc.c) is in theOk. It took me a while to track down the audit code in question: if one googles for "linux audit" one gets a lot of diverse hits, and this one has few discerning names. I assume that this is the one you are referring to http://people.redhat.com/faith/audit/readme.txt So from what I've read, it seems that the above hooks are audit-specific, but only with respect to Rik Faith's audit patch that is now in the mainline kernel. IMHO, hooks that are audit-specific to a *module* would be fugly, but that is not the case here; these hooks are just specific to the new audit capabilities of the kernel. I.e. they are hooking the audit facility in exactly the same way that other hooks mediate e.g. inode access. So I'm ok with the architecture of this patch. Thanks, Crispin -- Crispin Cowan, Ph.D. http://immunix.com/~crispin/ CTO, Immunix http://immunix.com |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: [PATCH] LSM hooks for audit: 00043, Stephen Smalley |
|---|---|
| Next by Date: | Re: [PATCH] LSM hooks for audit: 00043, Serge Hallyn |
| Previous by Thread: | Re: [PATCH] LSM hooks for auditi: 00043, Stephen Smalley |
| Next by Thread: | Re: [PATCH] LSM hooks for audit: 00043, James Morris |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |