linux-audit
Thread
Date
Earlier messages
Later messages
Messages by Thread
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Steve Grubb
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Steve Grubb
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Steve Grubb
Re: [RFC PATCH v2 0/9] Add LSM access controls and auditing to io_uring
Richard Guy Briggs
audit-3.0.5 released
Steve Grubb
Re: [PATCH v7 0/5] IMA: restrict the accepted digest algorithms for the security.ima xattr
Mimi Zohar
Re: [PATCH v7 0/5] IMA: restrict the accepted digest algorithms for the security.ima xattr
Steve Grubb
Re: [PATCH v7 0/5] IMA: restrict the accepted digest algorithms for the security.ima xattr
Steve Grubb
BUG: segfault on systemctl auditd stop
Brown, Thomas
Re: BUG: segfault on systemctl auditd stop
Steve Grubb
audit-3.0.4 released
Steve Grubb
[PATCH RFC] audit-userspace: support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS
Casey Schaufler
Re: [PATCH RFC] audit-userspace: support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS
Steve Grubb
Re: [PATCH RFC] audit-userspace: support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS
Casey Schaufler
last restart of auditd - in EPOCH time
warron.french
Re: last restart of auditd - in EPOCH time
Steve Grubb
Re: last restart of auditd - in EPOCH time
warron.french
[PATCH] kernel/auditsc: remove unused header file
Hui Su
Re: [PATCH] kernel/auditsc: remove unused header file
Paul Moore
[PATCH v28 00/25] LSM: Module stacking for AppArmor
Casey Schaufler
[PATCH v28 01/25] LSM: Infrastructure management of the sock security
Casey Schaufler
[PATCH v28 00/25] LSM: Module stacking for AppArmor
Casey Schaufler
[PATCH v28 01/25] LSM: Infrastructure management of the sock security
Casey Schaufler
[PATCH v28 02/25] LSM: Add the lsmblob data structure.
Casey Schaufler
[PATCH v28 03/25] LSM: provide lsm name and id slot mappings
Casey Schaufler
[PATCH v28 04/25] IMA: avoid label collisions with stacked LSMs
Casey Schaufler
[PATCH v28 05/25] LSM: Use lsmblob in security_audit_rule_match
Casey Schaufler
[PATCH v28 06/25] LSM: Use lsmblob in security_kernel_act_as
Casey Schaufler
[PATCH v28 07/25] LSM: Use lsmblob in security_secctx_to_secid
Casey Schaufler
[PATCH v28 08/25] LSM: Use lsmblob in security_secid_to_secctx
Casey Schaufler
[PATCH v28 09/25] LSM: Use lsmblob in security_ipc_getsecid
Casey Schaufler
[PATCH v28 10/25] LSM: Use lsmblob in security_task_getsecid
Casey Schaufler
[PATCH v28 11/25] LSM: Use lsmblob in security_inode_getsecid
Casey Schaufler
[PATCH v28 12/25] LSM: Use lsmblob in security_cred_getsecid
Casey Schaufler
Re: [PATCH v28 12/25] LSM: Use lsmblob in security_cred_getsecid
kernel test robot
[PATCH v28 13/25] IMA: Change internal interfaces to use lsmblobs
Casey Schaufler
[PATCH v28 14/25] LSM: Specify which LSM to display
Casey Schaufler
[PATCH v28 15/25] LSM: Ensure the correct LSM context releaser
Casey Schaufler
[PATCH v28 16/25] LSM: Use lsmcontext in security_secid_to_secctx
Casey Schaufler
[PATCH v28 17/25] LSM: Use lsmcontext in security_inode_getsecctx
Casey Schaufler
[PATCH v28 18/25] LSM: security_secid_to_secctx in netlink netfilter
Casey Schaufler
[PATCH v28 19/25] NET: Store LSM netlabel data in a lsmblob
Casey Schaufler
[PATCH v28 20/25] LSM: Verify LSM display sanity in binder
Casey Schaufler
[PATCH v28 21/25] audit: support non-syscall auxiliary records
Casey Schaufler
Re: [PATCH v28 21/25] audit: support non-syscall auxiliary records
kernel test robot
[PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
kernel test robot
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v28 22/25] Audit: Add record for multiple process LSM attributes
Paul Moore
[PATCH v28 23/25] Audit: Add record for multiple object LSM attributes
Casey Schaufler
[PATCH v28 24/25] LSM: Add /proc attr entry for full LSM context
Casey Schaufler
[PATCH v28 25/25] AppArmor: Remove the exclusive flag
Casey Schaufler
Memory Leak in Audisp-Plugin
Shashank Akula
Re: Memory Leak in Audisp-Plugin
Steve Grubb
Re: Memory Leak in Audisp-Plugin
Steve Grubb
[PATCH] Audit: fix coding style
mayuming77
Re: [PATCH] Audit: fix coding style
Paul Moore
audit 3.0.3 released
Steve Grubb
Re: audit 3.0.3 released
Steve Grubb
auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Steve Grubb
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Steve Grubb
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Steve Grubb
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Rakesh Kumar
Re: auditd not logging proper log.
Steve Grubb
The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Wieprecht, Karen M.
Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Steve Grubb
Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
warron.french
Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Richard Guy Briggs
Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
warron.french
RE: [EXT] Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Wieprecht, Karen M.
RE: [EXT] Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Wieprecht, Karen M.
Re: The format of password change audit events seems to have changed, Can you confirm the correct record type ?
Steve Grubb
Bad Rule?
warron.french
Re: Bad Rule?
Steve Grubb
Re: Bad Rule?
warron.french
Re: Bad Rule?
Richard Guy Briggs
Re: Bad Rule?
warron.french
Re: Bad Rule?
Steve Grubb
Re: Bad Rule?
warron.french
[GIT PULL] Audit patches for v5.14
Paul Moore
Re: [GIT PULL] Audit patches for v5.14
pr-tracker-bot
AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Thomas Weißschuh
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Paul Moore
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Thomas Weißschuh
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Paul Moore
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Thomas Weißschuh
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Paul Moore
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Thomas Weißschuh
Re: AUDIT_ARCH_ and __NR_syscall constants for seccomp filters
Paul Moore
auditd process memory leak
宋建昌
Duplicate Rule situation
warron.french
Re: Duplicate Rule situation
Richard Guy Briggs
Internal commands track in AuditD
Muthamilan Sargunaanandan
Re: Internal commands track in AuditD
Richard Guy Briggs
Re: Internal commands track in AuditD
Steve Grubb
Adding support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS to userspace.
Casey Schaufler
Re: Adding support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS to userspace.
Steve Grubb
Re: Adding support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS to userspace.
Casey Schaufler
Re: Adding support for MAC_TASK_CONTEXTS and MAC_OBJ_CONTEXTS to userspace.
Steve Grubb
[PATCH v27 00/25] LSM: Module stacking for AppArmor
Casey Schaufler
[PATCH v27 01/25] LSM: Infrastructure management of the sock security
Casey Schaufler
[PATCH v27 02/25] LSM: Add the lsmblob data structure.
Casey Schaufler
[PATCH v27 03/25] LSM: provide lsm name and id slot mappings
Casey Schaufler
[PATCH v27 04/25] IMA: avoid label collisions with stacked LSMs
Casey Schaufler
[PATCH v27 05/25] LSM: Use lsmblob in security_audit_rule_match
Casey Schaufler
[PATCH v27 09/25] LSM: Use lsmblob in security_ipc_getsecid
Casey Schaufler
[PATCH v27 08/25] LSM: Use lsmblob in security_secid_to_secctx
Casey Schaufler
[PATCH v27 06/25] LSM: Use lsmblob in security_kernel_act_as
Casey Schaufler
[PATCH v27 07/25] LSM: Use lsmblob in security_secctx_to_secid
Casey Schaufler
[PATCH v27 10/25] LSM: Use lsmblob in security_task_getsecid
Casey Schaufler
[PATCH v27 11/25] LSM: Use lsmblob in security_inode_getsecid
Casey Schaufler
[PATCH v27 12/25] LSM: Use lsmblob in security_cred_getsecid
Casey Schaufler
[PATCH v27 14/25] LSM: Specify which LSM to display
Casey Schaufler
[PATCH v27 13/25] IMA: Change internal interfaces to use lsmblobs
Casey Schaufler
[PATCH v27 15/25] LSM: Ensure the correct LSM context releaser
Casey Schaufler
[PATCH v27 16/25] LSM: Use lsmcontext in security_secid_to_secctx
Casey Schaufler
[PATCH v27 17/25] LSM: Use lsmcontext in security_inode_getsecctx
Casey Schaufler
[PATCH v27 18/25] LSM: security_secid_to_secctx in netlink netfilter
Casey Schaufler
[PATCH v27 19/25] NET: Store LSM netlabel data in a lsmblob
Casey Schaufler
[PATCH v27 21/25] audit: add support for non-syscall auxiliary records
Casey Schaufler
Re: [PATCH v27 21/25] audit: add support for non-syscall auxiliary records
kernel test robot
Re: [PATCH v27 21/25] audit: add support for non-syscall auxiliary records
kernel test robot
[PATCH v27 20/25] LSM: Verify LSM display sanity in binder
Casey Schaufler
[PATCH v27 22/25] Audit: Add record for multiple process LSM attributes
Casey Schaufler
Re: [PATCH v27 22/25] Audit: Add record for multiple process LSM attributes
kernel test robot
Re: [PATCH v27 22/25] Audit: Add record for multiple process LSM attributes
kernel test robot
[PATCH v27 25/25] AppArmor: Remove the exclusive flag
Casey Schaufler
[PATCH v27 23/25] Audit: Add record for multiple object LSM attributes
Casey Schaufler
[PATCH v27 24/25] LSM: Add /proc attr entry for full LSM context
Casey Schaufler
audit 3.0.2 released
Steve Grubb
[PATCH v2 0/1] audit: remove trailing spaces and tabs
Zhen Lei
[PATCH v2 1/1] audit: remove trailing spaces and tabs
Zhen Lei
Re: [PATCH v2 1/1] audit: remove trailing spaces and tabs
Richard Guy Briggs
Re: [PATCH v2 1/1] audit: remove trailing spaces and tabs
Paul Moore
[PATCH 1/1] audit: remove trailing spaces and tabs
Zhen Lei
Re: [PATCH 1/1] audit: remove trailing spaces and tabs
Richard Guy Briggs
Re: [PATCH 1/1] audit: remove trailing spaces and tabs
Leizhen (ThunderTown)
[PATCH -next] audit: Use list_move instead of list_del/list_add
Baokun Li
Re: [PATCH -next] audit: Use list_move instead of list_del/list_add
Richard Guy Briggs
Re: [PATCH -next] audit: Use list_move instead of list_del/list_add
Paul Moore
Unhelpful events
Steve Grubb
Re: Unhelpful events
Richard Guy Briggs
Re: Unhelpful events
Steve Grubb
Re: Unhelpful events
Richard Guy Briggs
Current problematic cases with immutable loginuid
Andreas Hasenack
Re: Current problematic cases with immutable loginuid
Richard Guy Briggs
[RFC PATCH] audit: reduce the number of kauditd_thread wakeups
Paul Moore
Re: [RFC PATCH] audit: reduce the number of kauditd_thread wakeups
Richard Guy Briggs
Re: [RFC PATCH] audit: reduce the number of kauditd_thread wakeups
Paul Moore
[PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Sergey Nazarov
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Richard Guy Briggs
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Paul Moore
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Sergey Nazarov
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Paul Moore
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Richard Guy Briggs
Re: [PATCH] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Paul Moore
[PATCH v2] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Sergey Nazarov
Re: [PATCH v2] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Richard Guy Briggs
Re: [PATCH v2] audit: Rename enum audit_state constants to avoid AUDIT_DISABLED redefinition
Paul Moore
Replacing file watch (-w) with syscall
Andreas Hasenack
Re: Replacing file watch (-w) with syscall
Steve Grubb
Re: Replacing file watch (-w) with syscall
Richard Guy Briggs
Re: Replacing file watch (-w) with syscall
Andreas Hasenack
[RFC PATCH 0/9] Add LSM access controls and auditing to io_uring
Paul Moore
[RFC PATCH 1/9] audit: prepare audit_context for use in calling contexts beyond syscalls
Paul Moore
Earlier messages
Later messages