Hi, This is a patch set Eric Paris and I have been working on to add a restricted capability read-only netlink multicast socket to kaudit to enable userspace clients such as systemd to consume audit logs, in addition to the bidirectional auditd userspace client.
Currently, auditd has the CAP_AUDIT_CONTROL and CAP_AUDIT_WRITE capabilities (bot uses CAP_NET_ADMIN). The CAP_AUDIT_READ capability will be added for use by read-only AUDIT_NLGRP_READLOG multicast group clients to the kaudit subsystem. https://bugzilla.redhat.com/show_bug.cgi?id=887992 Feedback please! Richard Guy Briggs (6): audit: refactor hold queue flush audit: flatten kauditd_thread wait queue code audit: move kaudit thread start from auditd registration to kaudit init netlink: add send and receive capability requirement and capability flags audit: add the first netlink multicast socket group audit: send multicast messages only if there are listeners include/linux/netlink.h | 4 + include/uapi/linux/audit.h | 8 ++ include/uapi/linux/capability.h | 5 +- kernel/audit.c | 142 +++++++++++++++++++++++++----------- net/netlink/af_netlink.c | 35 +++++++-- security/selinux/include/classmap.h | 2 +- 6 files changed, 144 insertions(+), 52 deletions(-) -- 1.8.0.2 -- Linux-audit mailing list Linux-audit@redhat.com https://www.redhat.com/mailman/listinfo/linux-audit