2005-04-29 16:23:29 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-03-01 22:01:11 +02:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-29 16:23:29 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
|
|
|
|
|
2015-02-22 18:20:09 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-06-06 14:37:37 -07:00
|
|
|
|
2011-07-26 16:09:06 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2011-05-23 14:51:41 -04:00
|
|
|
|
include cleanup: Update gfp.h and slab.h includes to prepare for breaking implicit slab.h inclusion from percpu.h
percpu.h is included by sched.h and module.h and thus ends up being
included when building most .c files. percpu.h includes slab.h which
in turn includes gfp.h making everything defined by the two files
universally available and complicating inclusion dependencies.
percpu.h -> slab.h dependency is about to be removed. Prepare for
this change by updating users of gfp and slab facilities include those
headers directly instead of assuming availability. As this conversion
needs to touch large number of source files, the following script is
used as the basis of conversion.
http://userweb.kernel.org/~tj/misc/slabh-sweep.py
The script does the followings.
* Scan files for gfp and slab usages and update includes such that
only the necessary includes are there. ie. if only gfp is used,
gfp.h, if slab is used, slab.h.
* When the script inserts a new include, it looks at the include
blocks and try to put the new include such that its order conforms
to its surrounding. It's put in the include block which contains
core kernel includes, in the same order that the rest are ordered -
alphabetical, Christmas tree, rev-Xmas-tree or at the end if there
doesn't seem to be any matching order.
* If the script can't find a place to put a new include (mostly
because the file doesn't have fitting include block), it prints out
an error message indicating which .h file needs to be added to the
file.
The conversion was done in the following steps.
1. The initial automatic conversion of all .c files updated slightly
over 4000 files, deleting around 700 includes and adding ~480 gfp.h
and ~3000 slab.h inclusions. The script emitted errors for ~400
files.
2. Each error was manually checked. Some didn't need the inclusion,
some needed manual addition while adding it to implementation .h or
embedding .c file was more appropriate for others. This step added
inclusions to around 150 files.
3. The script was run again and the output was compared to the edits
from #2 to make sure no file was left behind.
4. Several build tests were done and a couple of problems were fixed.
e.g. lib/decompress_*.c used malloc/free() wrappers around slab
APIs requiring slab.h to be added manually.
5. The script was run on all .h files but without automatically
editing them as sprinkling gfp.h and slab.h inclusions around .h
files could easily lead to inclusion dependency hell. Most gfp.h
inclusion directives were ignored as stuff from gfp.h was usually
wildly available and often used in preprocessor macros. Each
slab.h inclusion directive was examined and added manually as
necessary.
6. percpu.h was updated not to include slab.h.
7. Build test were done on the following configurations and failures
were fixed. CONFIG_GCOV_KERNEL was turned off for all tests (as my
distributed build env didn't work with gcov compiles) and a few
more options had to be turned off depending on archs to make things
build (like ipr on powerpc/64 which failed due to missing writeq).
* x86 and x86_64 UP and SMP allmodconfig and a custom test config.
* powerpc and powerpc64 SMP allmodconfig
* sparc and sparc64 SMP allmodconfig
* ia64 SMP allmodconfig
* s390 SMP allmodconfig
* alpha SMP allmodconfig
* um on x86_64 SMP allmodconfig
8. percpu.h modifications were reverted so that it could be applied as
a separate patch and serve as bisection point.
Given the fact that I had only a couple of failures from tests on step
6, I'm fairly confident about the coverage of this conversion patch.
If there is a breakage, it's likely to be something in one of the arch
headers which should be easily discoverable easily on most builds of
the specific arch.
Signed-off-by: Tejun Heo <tj@kernel.org>
Guess-its-ok-by: Christoph Lameter <cl@linux-foundation.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Lee Schermerhorn <Lee.Schermerhorn@hp.com>
2010-03-24 17:04:11 +09:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
|
|
|
|
|
2013-05-03 14:03:50 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-02-07 12:05:27 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2011-06-30 13:31:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-12-06 20:34:23 -08:00
|
|
|
|
2012-09-10 23:20:20 -07:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2006-03-10 18:14:06 -06:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2011-01-18 06:48:12 +01:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
audit: netlink socket can be auto-bound to pid other than current->pid (v2)
From: Pavel Emelyanov <xemul@openvz.org>
This patch is based on the one from Thomas.
The kauditd_thread() calls the netlink_unicast() and passes
the audit_pid to it. The audit_pid, in turn, is received from
the user space and the tool (I've checked the audit v1.6.9)
uses getpid() to pass one in the kernel. Besides, this tool
doesn't bind the netlink socket to this id, but simply creates
it allowing the kernel to auto-bind one.
That's the preamble.
The problem is that netlink_autobind() _does_not_ guarantees
that the socket will be auto-bound to the current pid. Instead
it uses the current pid as a hint to start looking for a free
id. So, in case of conflict, the audit messages can be sent
to a wrong socket. This can happen (it's unlikely, but can be)
in case some task opens more than one netlink sockets and then
the audit one starts - in this case the audit's pid can be busy
and its socket will be bound to another id.
The proposal is to introduce an audit_nlk_pid in audit subsys,
that will point to the netlink socket to send packets to. It
will most often be equal to audit_pid. The socket id can be
got from the skb's netlink CB right in the audit_receive_msg.
The audit_nlk_pid reset to 0 is not required, since all the
decisions are taken based on audit_pid value only.
Later, if the audit tools will bind the socket themselves, the
kernel will have to provide a way to setup the audit_nlk_pid
as well.
A good side effect of this patch is that audit_pid can later
be converted to struct pid, as it is not longer safe to use
pid_t-s in the presence of pid namespaces. But audit code still
uses the tgid from task_struct in the audit_signal_info and in
the audit_filter_syscall.
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: Pavel Emelyanov <xemul@openvz.org>
Acked-by: Eric Paris <eparis@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-03-20 15:39:41 -07:00
|
|
|
|
|
|
|
|
|
2012-09-07 20:12:54 +00:00
|
|
|
|
|
|
|
|
|
audit: netlink socket can be auto-bound to pid other than current->pid (v2)
From: Pavel Emelyanov <xemul@openvz.org>
This patch is based on the one from Thomas.
The kauditd_thread() calls the netlink_unicast() and passes
the audit_pid to it. The audit_pid, in turn, is received from
the user space and the tool (I've checked the audit v1.6.9)
uses getpid() to pass one in the kernel. Besides, this tool
doesn't bind the netlink socket to this id, but simply creates
it allowing the kernel to auto-bind one.
That's the preamble.
The problem is that netlink_autobind() _does_not_ guarantees
that the socket will be auto-bound to the current pid. Instead
it uses the current pid as a hint to start looking for a free
id. So, in case of conflict, the audit messages can be sent
to a wrong socket. This can happen (it's unlikely, but can be)
in case some task opens more than one netlink sockets and then
the audit one starts - in this case the audit's pid can be busy
and its socket will be bound to another id.
The proposal is to introduce an audit_nlk_pid in audit subsys,
that will point to the netlink socket to send packets to. It
will most often be equal to audit_pid. The socket id can be
got from the skb's netlink CB right in the audit_receive_msg.
The audit_nlk_pid reset to 0 is not required, since all the
decisions are taken based on audit_pid value only.
Later, if the audit tools will bind the socket themselves, the
kernel will have to provide a way to setup the audit_nlk_pid
as well.
A good side effect of this patch is that audit_pid can later
be converted to struct pid, as it is not longer safe to use
pid_t-s in the presence of pid namespaces. But audit code still
uses the tgid from task_struct in the audit_signal_info and in
the audit_filter_syscall.
Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: Pavel Emelyanov <xemul@openvz.org>
Acked-by: Eric Paris <eparis@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
2008-03-20 15:39:41 -07:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-10-22 13:28:49 -04:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2013-09-12 23:03:51 -04:00
|
|
|
|
2015-02-23 15:37:59 -05:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
2012-02-07 16:53:48 -08:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-05-26 10:59:28 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
|
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-23 14:26:00 -04:00
|
|
|
|
2013-05-24 09:18:04 -04:00
|
|
|
|
2013-05-23 14:26:00 -04:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
2009-06-24 00:02:38 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-10-21 03:22:03 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2014-02-28 10:49:05 -08:00
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2005-05-13 18:17:42 +01:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2005-05-13 18:17:42 +01:00
|
|
|
|
|
|
|
|
|
2005-11-03 17:15:16 +00:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-23 22:55:05 -05:00
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2008-02-21 15:53:05 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-23 22:55:05 -05:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2008-01-23 22:55:05 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2008-04-18 10:09:25 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
2006-04-01 18:29:34 -05:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2013-01-11 14:32:07 -08:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2013-04-30 09:53:34 -04:00
|
|
|
|
2013-04-19 15:00:33 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
|
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2006-04-01 18:29:34 -05:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
|
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2006-04-01 18:29:34 -05:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2013-09-18 11:55:12 -04:00
|
|
|
|
|
|
|
|
|
2015-02-23 15:37:59 -05:00
|
|
|
|
2013-09-18 11:55:12 -04:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2008-01-08 17:38:31 -05:00
|
|
|
|
2015-03-11 14:08:19 -04:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-08 17:38:31 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-04-01 18:29:34 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-10-22 13:28:49 -04:00
|
|
|
|
|
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2014-03-05 16:29:55 -05:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
audit: try harder to send to auditd upon netlink failure
There are several reports of the kernel losing contact with auditd when
it is, in fact, still running. When this happens, kernel syslogs show:
"audit: *NO* daemon at audit_pid=<pid>"
although auditd is still running, and is apparently happy, listening on
the netlink socket. The pid in the "*NO* daemon" message matches the pid
of the running auditd process. Restarting auditd solves this.
The problem appears to happen randomly, and doesn't seem to be strongly
correlated to the rate of audit events being logged. The problem
happens fairly regularly (every few days), but not yet reproduced to
order.
On production kernels, BUG_ON() is a no-op, so any error will trigger
this.
Commit 34eab0a7cd45 ("audit: prevent an older auditd shutdown from
orphaning a newer auditd startup") eliminates one possible cause. This
isn't the case here, since the PID in the error message and the PID of
the running auditd match.
The primary expected cause of error here is -ECONNREFUSED when the audit
daemon goes away, when netlink_getsockbyportid() can't find the auditd
portid entry in the netlink audit table (or there is no receive
function). If -EPERM is returned, that situation isn't likely to be
resolved in a timely fashion without administrator intervention. In
both cases, reset the audit_pid. This does not rule out a race
condition. SELinux is expected to return zero since this isn't an INET
or INET6 socket. Other LSMs may have other return codes. Log the error
code for better diagnosis in the future.
In the case of -ENOMEM, the situation could be temporary, based on local
or general availability of buffers. -EAGAIN should never happen since
the netlink audit (kernel) socket is set to MAX_SCHEDULE_TIMEOUT.
-ERESTARTSYS and -EINTR are not expected since this kernel thread is not
expected to receive signals. In these cases (or any other unexpected
ones for now), report the error and re-schedule the thread, retrying up
to 5 times.
v2:
Removed BUG_ON().
Moved comma in pr_*() statements.
Removed audit_strerror() text.
Reported-by: Vipin Rathor <v.rathor@gmail.com>
Reported-by: <ctcard@hotmail.com>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
[PM: applied rgb's fixup patch to correct audit_log_lost() format issues]
Signed-off-by: Paul Moore <pmoore@redhat.com>
2015-11-04 08:23:50 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
2012-09-07 20:12:54 +00:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
audit: try harder to send to auditd upon netlink failure
There are several reports of the kernel losing contact with auditd when
it is, in fact, still running. When this happens, kernel syslogs show:
"audit: *NO* daemon at audit_pid=<pid>"
although auditd is still running, and is apparently happy, listening on
the netlink socket. The pid in the "*NO* daemon" message matches the pid
of the running auditd process. Restarting auditd solves this.
The problem appears to happen randomly, and doesn't seem to be strongly
correlated to the rate of audit events being logged. The problem
happens fairly regularly (every few days), but not yet reproduced to
order.
On production kernels, BUG_ON() is a no-op, so any error will trigger
this.
Commit 34eab0a7cd45 ("audit: prevent an older auditd shutdown from
orphaning a newer auditd startup") eliminates one possible cause. This
isn't the case here, since the PID in the error message and the PID of
the running auditd match.
The primary expected cause of error here is -ECONNREFUSED when the audit
daemon goes away, when netlink_getsockbyportid() can't find the auditd
portid entry in the netlink audit table (or there is no receive
function). If -EPERM is returned, that situation isn't likely to be
resolved in a timely fashion without administrator intervention. In
both cases, reset the audit_pid. This does not rule out a race
condition. SELinux is expected to return zero since this isn't an INET
or INET6 socket. Other LSMs may have other return codes. Log the error
code for better diagnosis in the future.
In the case of -ENOMEM, the situation could be temporary, based on local
or general availability of buffers. -EAGAIN should never happen since
the netlink audit (kernel) socket is set to MAX_SCHEDULE_TIMEOUT.
-ERESTARTSYS and -EINTR are not expected since this kernel thread is not
expected to receive signals. In these cases (or any other unexpected
ones for now), report the error and re-schedule the thread, retrying up
to 5 times.
v2:
Removed BUG_ON().
Moved comma in pr_*() statements.
Removed audit_strerror() text.
Reported-by: Vipin Rathor <v.rathor@gmail.com>
Reported-by: <ctcard@hotmail.com>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
[PM: applied rgb's fixup patch to correct audit_log_lost() format issues]
Signed-off-by: Paul Moore <pmoore@redhat.com>
2015-11-04 08:23:50 -05:00
|
|
|
|
|
|
|
|
|
2013-11-26 18:49:12 -05:00
|
|
|
|
audit: try harder to send to auditd upon netlink failure
There are several reports of the kernel losing contact with auditd when
it is, in fact, still running. When this happens, kernel syslogs show:
"audit: *NO* daemon at audit_pid=<pid>"
although auditd is still running, and is apparently happy, listening on
the netlink socket. The pid in the "*NO* daemon" message matches the pid
of the running auditd process. Restarting auditd solves this.
The problem appears to happen randomly, and doesn't seem to be strongly
correlated to the rate of audit events being logged. The problem
happens fairly regularly (every few days), but not yet reproduced to
order.
On production kernels, BUG_ON() is a no-op, so any error will trigger
this.
Commit 34eab0a7cd45 ("audit: prevent an older auditd shutdown from
orphaning a newer auditd startup") eliminates one possible cause. This
isn't the case here, since the PID in the error message and the PID of
the running auditd match.
The primary expected cause of error here is -ECONNREFUSED when the audit
daemon goes away, when netlink_getsockbyportid() can't find the auditd
portid entry in the netlink audit table (or there is no receive
function). If -EPERM is returned, that situation isn't likely to be
resolved in a timely fashion without administrator intervention. In
both cases, reset the audit_pid. This does not rule out a race
condition. SELinux is expected to return zero since this isn't an INET
or INET6 socket. Other LSMs may have other return codes. Log the error
code for better diagnosis in the future.
In the case of -ENOMEM, the situation could be temporary, based on local
or general availability of buffers. -EAGAIN should never happen since
the netlink audit (kernel) socket is set to MAX_SCHEDULE_TIMEOUT.
-ERESTARTSYS and -EINTR are not expected since this kernel thread is not
expected to receive signals. In these cases (or any other unexpected
ones for now), report the error and re-schedule the thread, retrying up
to 5 times.
v2:
Removed BUG_ON().
Moved comma in pr_*() statements.
Removed audit_strerror() text.
Reported-by: Vipin Rathor <v.rathor@gmail.com>
Reported-by: <ctcard@hotmail.com>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
[PM: applied rgb's fixup patch to correct audit_log_lost() format issues]
Signed-off-by: Paul Moore <pmoore@redhat.com>
2015-11-04 08:23:50 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-26 18:49:12 -05:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2010-07-20 06:45:56 +00:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-18 23:09:27 -05:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:58 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-18 23:09:27 -05:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-12-18 23:09:27 -05:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
2013-01-24 13:15:10 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-24 13:15:10 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-01-13 09:18:55 -05:00
|
|
|
|
2013-01-24 13:15:10 -05:00
|
|
|
|
|
|
|
|
|
2006-01-08 01:02:17 -08:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2007-07-17 04:03:35 -07:00
|
|
|
|
2006-10-06 00:43:48 -07:00
|
|
|
|
2013-01-24 13:15:11 -05:00
|
|
|
|
|
|
|
|
|
2013-01-24 13:15:10 -05:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2013-09-16 11:11:12 -04:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2016-01-13 09:18:54 -05:00
|
|
|
|
|
|
|
|
|
2013-09-16 11:11:12 -04:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
|
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
2013-01-24 13:15:11 -05:00
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2014-10-02 12:22:51 +02:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2006-10-06 00:43:48 -07:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
|
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-02-03 17:25:33 -08:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
|
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
2014-02-03 17:25:33 -08:00
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2010-10-20 17:23:50 -07:00
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
|
|
|
|
|
2006-05-22 01:09:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-02-03 17:25:33 -08:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2014-02-03 17:25:33 -08:00
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2014-03-08 15:31:54 -08:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
|
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-05-14 16:11:48 -07:00
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2008-04-18 10:11:04 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-05-14 16:11:48 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-06-27 13:26:11 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-08-16 00:04:46 -04:00
|
|
|
|
2014-03-30 19:07:54 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-12 12:38:53 -07:00
|
|
|
|
2014-03-30 19:07:54 -04:00
|
|
|
|
2012-09-10 23:20:20 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-18 19:16:36 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
2013-04-18 19:16:36 -04:00
|
|
|
|
|
|
|
|
|
2006-02-07 12:05:27 -05:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
|
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
2013-08-16 00:04:46 -04:00
|
|
|
|
|
|
|
|
|
2015-02-23 15:38:00 -05:00
|
|
|
|
2013-08-16 00:04:46 -04:00
|
|
|
|
|
|
|
|
|
2014-04-23 14:29:27 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-05-21 00:18:37 +01:00
|
|
|
|
2007-05-08 00:29:20 -07:00
|
|
|
|
|
|
|
|
|
2014-04-23 14:29:27 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-11-04 08:23:52 -05:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2013-12-11 13:52:26 -05:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2013-07-25 18:02:55 -07:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2015-11-04 08:23:52 -05:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-11 14:32:07 -08:00
|
|
|
|
2015-11-04 08:23:52 -05:00
|
|
|
|
2013-12-11 13:52:26 -05:00
|
|
|
|
2013-04-30 09:53:34 -04:00
|
|
|
|
2013-04-19 15:00:33 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
|
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-08-24 20:37:52 -04:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-01 19:34:43 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
2014-01-07 13:08:41 -05:00
|
|
|
|
2014-10-30 11:22:53 -04:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-06-03 22:05:10 +02:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-01 19:34:44 +08:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-05-13 18:17:42 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2006-06-27 13:26:11 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2013-04-29 15:05:14 -07:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2013-04-29 15:05:14 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-11-17 15:51:01 -05:00
|
|
|
|
2015-02-23 15:37:59 -05:00
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-07-31 10:11:19 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
|
|
|
|
|
2008-07-31 10:11:19 +08:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
|
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
|
|
|
|
|
2013-06-21 14:47:13 -04:00
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
|
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
2016-01-25 18:04:15 -05:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2012-09-07 20:12:54 +00:00
|
|
|
|
2013-12-17 11:10:42 +08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
|
|
|
|
|
2008-07-31 10:11:19 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-18 11:55:12 -04:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
2013-09-18 11:55:12 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 16:49:28 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-11 14:08:19 -04:00
|
|
|
|
2014-01-13 16:49:28 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-18 11:55:12 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-09-18 09:32:24 -04:00
|
|
|
|
2013-05-22 12:54:49 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-21 00:18:37 +01:00
|
|
|
|
2007-05-08 00:29:20 -07:00
|
|
|
|
|
|
|
|
|
2005-06-22 14:56:47 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-06-24 16:35:46 -04:00
|
|
|
|
2013-11-25 21:57:51 -05:00
|
|
|
|
2005-06-22 14:56:47 +01:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
2016-01-09 22:55:31 -08:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-12-02 11:33:01 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2013-09-16 18:20:42 -04:00
|
|
|
|
|
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-11 11:25:00 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2009-03-19 09:52:47 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
2005-06-22 14:56:47 +01:00
|
|
|
|
2013-08-14 11:32:45 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2013-12-02 11:33:01 -05:00
|
|
|
|
2005-06-19 19:35:50 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2006-02-07 12:05:27 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-07 17:09:31 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
|
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
2007-01-19 14:39:55 -05:00
|
|
|
|
|
|
|
|
|
2013-11-20 14:01:53 -05:00
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2013-11-20 14:01:53 -05:00
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
2013-11-20 14:01:53 -05:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-27 02:39:56 -07:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-27 02:39:56 -07:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-27 02:39:56 -07:00
|
|
|
|
|
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-27 02:39:56 -07:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-19 13:23:09 -04:00
|
|
|
|
2008-01-07 18:14:19 -05:00
|
|
|
|
[PATCH] audit: watching subtrees
New kind of audit rule predicates: "object is visible in given subtree".
The part that can be sanely implemented, that is. Limitations:
* if you have hardlink from outside of tree, you'd better watch
it too (or just watch the object itself, obviously)
* if you mount something under a watched tree, tell audit
that new chunk should be added to watched subtrees
* if you umount something in a watched tree and it's still mounted
elsewhere, you will get matches on events happening there. New command
tells audit to recalculate the trees, trimming such sources of false
positives.
Note that it's _not_ about path - if something mounted in several places
(multiple mount, bindings, different namespaces, etc.), the match does
_not_ depend on which one we are using for access.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2007-07-22 08:04:18 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
2009-09-23 13:46:00 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
|
|
|
|
|
2009-09-23 13:46:00 -04:00
|
|
|
|
|
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
|
|
|
|
|
2012-02-07 16:53:48 -08:00
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
2009-09-23 13:46:00 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
|
|
|
|
|
2006-05-25 10:19:47 -04:00
|
|
|
|
2005-05-06 12:38:39 +01:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
|
|
|
|
|
2016-01-09 22:55:33 -08:00
|
|
|
|
2012-09-10 23:43:14 -07:00
|
|
|
|
2016-01-09 22:55:33 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-09-10 23:43:14 -07:00
|
|
|
|
2014-02-28 19:44:55 -08:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-15 11:29:02 -05:00
|
|
|
|
|
|
|
|
|
2016-01-09 22:55:33 -08:00
|
|
|
|
2014-01-13 21:12:34 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-15 11:29:02 -05:00
|
|
|
|
2016-01-09 22:55:33 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 21:12:34 -05:00
|
|
|
|
2016-01-09 22:55:33 -08:00
|
|
|
|
|
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
2013-11-15 11:29:02 -05:00
|
|
|
|
2014-01-13 21:16:59 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-11-15 11:29:02 -05:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2005-05-03 14:55:09 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
2013-03-27 06:49:06 +00:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-03-27 06:49:06 +00:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2013-03-28 23:31:29 +02:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-10-10 21:15:29 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
2007-10-10 21:15:29 -07:00
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:56 -04:00
|
|
|
|
2014-12-23 21:00:06 +01:00
|
|
|
|
2014-04-22 21:31:56 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2012-06-29 06:15:21 +00:00
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:56 -04:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
2012-06-29 06:15:21 +00:00
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-12-17 11:10:41 +08:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2013-12-17 11:10:41 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-03-24 00:16:19 +05:30
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
|
|
|
|
|
2013-07-16 13:18:45 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-01-08 17:38:31 -05:00
|
|
|
|
2006-03-10 18:14:06 -06:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
[PATCH] audit: path-based rules
In this implementation, audit registers inotify watches on the parent
directories of paths specified in audit rules. When audit's inotify
event handler is called, it updates any affected rules based on the
filesystem event. If the parent directory is renamed, removed, or its
filesystem is unmounted, audit removes all rules referencing that
inotify watch.
To keep things simple, this implementation limits location-based
auditing to the directory entries in an existing directory. Given
a path-based rule for /foo/bar/passwd, the following table applies:
passwd modified -- audit event logged
passwd replaced -- audit event logged, rules list updated
bar renamed -- rule removed
foo renamed -- untracked, meaning that the rule now applies to
the new location
Audit users typically want to have many rules referencing filesystem
objects, which can significantly impact filtering performance. This
patch also adds an inode-number-based rule hash to mitigate this
situation.
The patch is relative to the audit git tree:
http://kernel.org/git/?p=linux/kernel/git/viro/audit-current.git;a=summary
and uses the inotify kernel API:
http://lkml.org/lkml/2006/6/1/145
Signed-off-by: Amy Griffis <amy.griffis@hp.com>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
2006-04-07 16:55:56 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2013-10-31 14:31:01 +08:00
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
2006-03-31 02:30:33 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-09-17 12:34:52 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2013-09-17 12:34:52 -04:00
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2013-09-17 12:34:52 -04:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:13 -08:00
|
|
|
|
|
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
2013-09-17 12:34:52 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-01-13 09:18:55 -05:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2006-04-27 16:45:14 -05:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2006-04-27 16:45:14 -05:00
|
|
|
|
|
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2006-04-27 16:45:14 -05:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-13 18:17:42 +01:00
|
|
|
|
2005-10-07 07:46:04 +01:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-13 18:17:42 +01:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:59:57 +01:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2012-06-26 21:45:21 -07:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
|
|
|
|
|
2014-06-13 18:22:00 -04:00
|
|
|
|
2005-07-15 12:56:03 +01:00
|
|
|
|
2014-06-13 18:22:00 -04:00
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
|
|
|
|
|
2007-10-18 03:06:10 -07:00
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
|
|
|
|
|
2008-12-06 01:05:50 -05:00
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-01-11 14:32:11 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
2013-01-11 14:32:11 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-04 16:44:02 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
2016-04-04 16:44:02 -04:00
|
|
|
|
|
|
|
|
|
2013-09-16 10:45:59 -04:00
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
2013-01-11 14:32:11 -08:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-10-21 03:22:03 -04:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-10 11:02:39 -08:00
|
|
|
|
2013-12-05 16:15:23 +09:00
|
|
|
|
|
|
|
|
|
2005-07-02 14:08:48 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-11-05 12:47:09 -05:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2016-06-24 16:35:46 -04:00
|
|
|
|
2005-11-03 16:12:36 +00:00
|
|
|
|
|
|
|
|
|
2015-11-06 16:28:21 -08:00
|
|
|
|
2016-01-13 09:15:19 -05:00
|
|
|
|
2015-11-06 16:28:21 -08:00
|
|
|
|
2013-12-05 16:15:23 +09:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-11-06 16:28:21 -08:00
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
|
|
|
|
|
2013-09-16 10:45:59 -04:00
|
|
|
|
2014-01-13 15:42:16 -05:00
|
|
|
|
2013-09-16 10:45:59 -04:00
|
|
|
|
2013-09-24 15:27:42 -07:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2008-01-23 22:55:05 -05:00
|
|
|
|
2014-01-14 10:33:12 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 14:55:56 +01:00
|
|
|
|
2016-01-13 09:15:18 -05:00
|
|
|
|
2005-07-02 14:08:48 +01:00
|
|
|
|
2005-05-19 14:55:56 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-01-13 09:15:18 -05:00
|
|
|
|
2015-02-23 15:38:00 -05:00
|
|
|
|
2013-09-12 23:03:51 -04:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-21 21:08:09 +01:00
|
|
|
|
2005-05-11 10:54:05 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-10 18:56:08 +01:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
2008-01-28 20:47:09 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
2008-01-28 20:47:09 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
2005-05-10 18:58:51 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:53 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-10 18:56:08 +01:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-10 18:58:51 +01:00
|
|
|
|
2007-04-19 20:29:13 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2012-01-08 22:44:29 +01:00
|
|
|
|
2007-04-19 20:29:13 -07:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
|
|
|
|
|
2012-01-08 22:44:29 +01:00
|
|
|
|
|
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2005-04-29 15:54:44 +01:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-09-07 17:03:02 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-04-29 15:54:44 +01:00
|
|
|
|
2007-04-19 20:29:13 -07:00
|
|
|
|
2014-01-13 23:31:27 -08:00
|
|
|
|
|
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
|
|
|
|
|
2005-04-29 15:54:44 +01:00
|
|
|
|
|
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
|
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-09-07 17:03:02 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-04-19 20:29:13 -07:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
|
|
|
|
|
2008-03-28 14:15:56 -07:00
|
|
|
|
|
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
2015-11-04 08:23:51 -05:00
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
|
|
|
|
|
2009-03-19 09:48:27 -04:00
|
|
|
|
2008-07-23 00:06:13 +03:00
|
|
|
|
2015-11-04 08:23:51 -05:00
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
2015-11-04 08:23:51 -05:00
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2008-03-28 14:15:56 -07:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
|
|
|
|
|
2005-04-29 15:54:44 +01:00
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
2005-04-29 15:54:44 +01:00
|
|
|
|
|
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Audit: add TTY input auditing
Add TTY input auditing, used to audit system administrator's actions. This is
required by various security standards such as DCID 6/3 and PCI to provide
non-repudiation of administrator's actions and to allow a review of past
actions if the administrator seems to overstep their duties or if the system
becomes misconfigured for unknown reasons. These requirements do not make it
necessary to audit TTY output as well.
Compared to an user-space keylogger, this approach records TTY input using the
audit subsystem, correlated with other audit events, and it is completely
transparent to the user-space application (e.g. the console ioctls still
work).
TTY input auditing works on a higher level than auditing all system calls
within the session, which would produce an overwhelming amount of mostly
useless audit events.
Add an "audit_tty" attribute, inherited across fork (). Data read from TTYs
by process with the attribute is sent to the audit subsystem by the kernel.
The audit netlink interface is extended to allow modifying the audit_tty
attribute, and to allow sending explanatory audit events from user-space (for
example, a shell might send an event containing the final command, after the
interactive command-line editing and history expansion is performed, which
might be difficult to decipher from the TTY input alone).
Because the "audit_tty" attribute is inherited across fork (), it would be set
e.g. for sshd restarted within an audited session. To prevent this, the
audit_tty attribute is cleared when a process with no open TTY file
descriptors (e.g. after daemon startup) opens a TTY.
See https://www.redhat.com/archives/linux-audit/2007-June/msg00000.html for a
more detailed rationale document for an older version of this patch.
[akpm@linux-foundation.org: build fix]
Signed-off-by: Miloslav Trmac <mitr@redhat.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Paul Fulghum <paulkf@microgate.com>
Cc: Casey Schaufler <casey@schaufler-ca.com>
Cc: Steve Grubb <sgrubb@redhat.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2007-07-15 23:40:56 -07:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
2008-01-07 14:31:58 -05:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
2008-04-18 10:12:59 -04:00
|
|
|
|
2006-06-08 23:19:31 -04:00
|
|
|
|
|
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2012-03-14 21:48:20 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-02-14 19:38:33 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-06 15:54:17 +01:00
|
|
|
|
2012-01-06 14:07:10 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2008-02-14 19:38:33 -08:00
|
|
|
|
|
|
|
|
|
2009-03-10 18:00:14 -04:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2008-02-14 19:38:44 -08:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
|
|
|
|
|
2009-03-10 18:00:14 -04:00
|
|
|
|
2007-10-18 03:06:10 -07:00
|
|
|
|
2005-05-19 10:24:22 +01:00
|
|
|
|
2008-02-14 19:38:33 -08:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2013-04-30 09:53:34 -04:00
|
|
|
|
|
|
|
|
|
2013-11-27 17:35:17 -05:00
|
|
|
|
2013-04-30 09:53:34 -04:00
|
|
|
|
|
|
|
|
|
2013-09-18 11:17:43 -04:00
|
|
|
|
2013-04-30 09:53:34 -04:00
|
|
|
|
|
|
|
|
|
2009-06-11 14:31:37 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-07-23 15:36:26 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-05-26 11:02:48 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-12-24 11:09:39 -05:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-09-08 13:34:59 -07:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-05-08 10:32:23 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-02-22 18:20:00 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-02-22 18:20:09 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-02-22 18:20:00 -08:00
|
|
|
|
2015-02-22 18:20:09 -08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-02-22 18:20:00 -08:00
|
|
|
|
|
|
|
|
|
2016-06-28 12:07:50 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-03-15 18:42:34 -04:00
|
|
|
|
2016-04-21 14:14:01 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-21 14:14:01 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
2013-12-10 22:10:41 -05:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
2013-07-15 10:23:11 -04:00
|
|
|
|
2013-12-10 22:10:41 -05:00
|
|
|
|
2013-12-11 13:52:26 -05:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2016-04-21 14:14:01 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
2014-03-15 18:42:34 -04:00
|
|
|
|
2015-02-22 18:20:00 -08:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
|
|
|
|
|
2015-05-23 10:40:27 +05:30
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
|
|
|
|
|
2012-10-04 19:57:31 -04:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2015-03-17 22:26:21 +00:00
|
|
|
|
2013-04-30 15:30:32 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2012-07-25 17:29:08 -07:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-02-21 16:59:22 -05:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
audit: set nlmsg_len for multicast messages.
Report:
Looking at your example code in
http://people.redhat.com/rbriggs/audit-multicast-listen/audit-multicast-listen.c,
it seems that nlmsg_len field in the received messages is supposed to
contain the length of the header + payload, but it is always set to the
size of the header only, i.e. 16. The example program works, because
the printf format specifies the minimum width, not "precision", so it
simply prints out the payload until the first zero byte. This isn't too
much of a problem, but precludes the use of recvmmsg, iiuc?
(gdb) p *(struct nlmsghdr*)nlh
$14 = {nlmsg_len = 16, nlmsg_type = 1100, nlmsg_flags = 0, nlmsg_seq = 0, nlmsg_pid = 9910}
The only time nlmsg_len would have been updated was at audit_buffer_alloc()
inside audit_log_start() and never updated after. It should arguably be done
in audit_log_vformat(), but would be more efficient in audit_log_end().
Reported-by: Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
2014-08-21 13:40:41 -04:00
|
|
|
|
2014-12-18 23:09:27 -05:00
|
|
|
|
2014-04-22 21:31:57 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
audit: set nlmsg_len for multicast messages.
Report:
Looking at your example code in
http://people.redhat.com/rbriggs/audit-multicast-listen/audit-multicast-listen.c,
it seems that nlmsg_len field in the received messages is supposed to
contain the length of the header + payload, but it is always set to the
size of the header only, i.e. 16. The example program works, because
the printf format specifies the minimum width, not "precision", so it
simply prints out the payload until the first zero byte. This isn't too
much of a problem, but precludes the use of recvmmsg, iiuc?
(gdb) p *(struct nlmsghdr*)nlh
$14 = {nlmsg_len = 16, nlmsg_type = 1100, nlmsg_flags = 0, nlmsg_seq = 0, nlmsg_pid = 9910}
The only time nlmsg_len would have been updated was at audit_buffer_alloc()
inside audit_log_start() and never updated after. It should arguably be done
in audit_log_vformat(), but would be more efficient in audit_log_end().
Reported-by: Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
2014-08-21 13:40:41 -04:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
2009-06-11 14:31:35 -04:00
|
|
|
|
2005-05-19 10:56:58 +01:00
|
|
|
|
2008-04-18 10:02:28 -04:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2005-05-06 15:53:34 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
2005-09-13 12:47:11 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2007-10-18 03:06:10 -07:00
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2005-06-22 15:04:33 +01:00
|
|
|
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-03-09 00:33:47 +01:00
|
|
|
|
2011-06-30 13:31:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2006-03-09 00:33:47 +01:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|