Re: IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Jens Axboe
On 1/19/24 10:54 AM, Paul Moore wrote: > On Fri, Jan 19, 2024 at 12:41?PM Jens Axboe wrote: >> On 1/19/24 10:20 AM, Paul Moore wrote: >>> On Fri, Jan 19, 2024 at 12:02?PM Jens Axboe wrote: On 1/19/24 9:33 AM, Paul Moore wrote: > Hello all, > > I just noticed the recent addition

Re: IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Paul Moore
On Fri, Jan 19, 2024 at 12:41 PM Jens Axboe wrote: > On 1/19/24 10:20 AM, Paul Moore wrote: > > On Fri, Jan 19, 2024 at 12:02?PM Jens Axboe wrote: > >> On 1/19/24 9:33 AM, Paul Moore wrote: > >>> Hello all, > >>> > >>> I just noticed the recent addition of IORING_OP_FIXED_FD_INSTALL and I > >>>

Re: IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Jens Axboe
On 1/19/24 10:20 AM, Paul Moore wrote: > On Fri, Jan 19, 2024 at 12:02?PM Jens Axboe wrote: >> >> On 1/19/24 9:33 AM, Paul Moore wrote: >>> Hello all, >>> >>> I just noticed the recent addition of IORING_OP_FIXED_FD_INSTALL and I >>> see that it is currently written to skip the io_uring auditing.

Re: IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Paul Moore
On Fri, Jan 19, 2024 at 12:02 PM Jens Axboe wrote: > > On 1/19/24 9:33 AM, Paul Moore wrote: > > Hello all, > > > > I just noticed the recent addition of IORING_OP_FIXED_FD_INSTALL and I > > see that it is currently written to skip the io_uring auditing. > > Assuming I'm understanding the patch

Re: IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Jens Axboe
On 1/19/24 9:33 AM, Paul Moore wrote: > Hello all, > > I just noticed the recent addition of IORING_OP_FIXED_FD_INSTALL and I > see that it is currently written to skip the io_uring auditing. > Assuming I'm understanding the patch correctly, and I'll admit that > I've only looked at it for a

IORING_OP_FIXED_FD_INSTALL and audit/LSM interactions

2024-01-19 Thread Paul Moore
Hello all, I just noticed the recent addition of IORING_OP_FIXED_FD_INSTALL and I see that it is currently written to skip the io_uring auditing. Assuming I'm understanding the patch correctly, and I'll admit that I've only looked at it for a short time today, my gut feeling is that we want to