On 8/18/2021 5:47 PM, Paul Moore wrote: > ... > I just spent a few minutes tracing the code paths up from audit > through netlink and then through the socket layer and I'm not seeing > anything obvious where the path differs from any other syscall; > current->audit_context *should* be valid just like any other syscall. > However, I do have to ask, are you only seeing these audit records > with a current->audit_context equal to NULL during early boot?
Nope. Sorry. -- Linux-audit mailing list [email protected] https://listman.redhat.com/mailman/listinfo/linux-audit
