On Mon, Jul 13, 2020 at 7:09 PM Casey Schaufler <[email protected]> wrote:
> ... but it does appear that I could switch to using your audit_alloc_local().

In my opinion, linking the audit container ID and LSM stacking
patchsets would seem like a very big mistake, especially since the
consolidation you are describing could be done after the fact without
any disruption to the kernel/userspace interface.  I would strongly
encourage both patchsets to remain self-contained if at all possible
so as to not jeopardize each other.

-- 
paul moore
www.paul-moore.com

--
Linux-audit mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/linux-audit

Reply via email to