On Mon, Jul 13, 2020 at 7:09 PM Casey Schaufler <[email protected]> wrote: > ... but it does appear that I could switch to using your audit_alloc_local().
In my opinion, linking the audit container ID and LSM stacking patchsets would seem like a very big mistake, especially since the consolidation you are describing could be done after the fact without any disruption to the kernel/userspace interface. I would strongly encourage both patchsets to remain self-contained if at all possible so as to not jeopardize each other. -- paul moore www.paul-moore.com -- Linux-audit mailing list [email protected] https://www.redhat.com/mailman/listinfo/linux-audit
