[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20160410024152.GG9407@two.firstfloor.org>
Date: Sat, 9 Apr 2016 19:41:53 -0700
From: Andi Kleen <andi@...stfloor.org>
To: Paul Moore <paul@...l-moore.com>
Cc: Andi Kleen <andi@...stfloor.org>, Eric Paris <eparis@...hat.com>,
linux-kernel@...r.kernel.org, Andi Kleen <ak@...ux.intel.com>
Subject: Re: [PATCH] Don't audit SECCOMP_KILL/RET_ERRNO when syscall auditing
is disabled
> What kernel version are you using? I believe we fixed that in Linux
> 4.5 with the following:
This is 4.6-rc2.
>
> commit 96368701e1c89057bbf39222e965161c68a85b4b
> From: Paul Moore <pmoore@...hat.com>
> Date: Wed, 13 Jan 2016 10:18:55 -0400 (09:18 -0500)
>
> audit: force seccomp event logging to honor the audit_enabled flag
No you didn't fix it because audit_enabled is always enabled by systemd
for user space auditing, see the original description of my patch.
-Andi
Powered by blists - more mailing lists