Received: by 2002:ac0:bc90:0:0:0:0:0 with SMTP id a16csp5745899img; Wed, 27 Mar 2019 14:31:52 -0700 (PDT) X-Google-Smtp-Source: APXvYqwMUqLtvKr9ggRoGzwKi4AtM6279V/5AkYHm40Jkg40jw1l3CKvRX/exrAFv42XKghImlof X-Received: by 2002:a62:5543:: with SMTP id j64mr37423520pfb.105.1553722312486; Wed, 27 Mar 2019 14:31:52 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1553722312; cv=none; d=google.com; s=arc-20160816; b=xHU2Xy/t3d9mPQQ7LqRzeE8zzB2oIhqpE8iPZDezHX0Uycqm1rI6wKxirIyhEpKbP5 98b3D65VmK9RcEuLAtW/NS0tzSUrHTs5jAyNkqQPl97OZpuyCoQLzkwqkOV00Q+FamKK wGa1KHe+W4sSnyFM+J4zvceXGICnzDNoLE+YGVtAC9JNz2seug2YKqo1qH/DGlK1VKaR GKMLrxPFI3y85Y6/QUl5TNCAfh3jmgmWzmsjEkDcRPY2FK8tucD7DsF8K2wJF4YOAXG/ gdCxNZhgMO2J+KB3RdUsnpvq4HOfXvnpt97wg1Wa5IU0xiWmBOYqJPYJyDjAsnSEwnye RrLA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version; bh=JCxnMapnujBLhv3W4a2O/ybJVO1nPLBLzENy+BoBkzI=; b=w/fE1E55qmbKFb8syIE5lKKJEROsxQIPim6hvs7uvo3zz14IQHo9HLzNBIf+laKN9C MiIgyvZWwDkfn1yhTomZKukvTzEQGGNvg32KW1nFUD1OSthaQWkEAgUxgvGGILJAehy3 ctu5/nqfrCTTZN+Js1SVE0GSaX0ElVMc+NB0mp7qflRFthTdDqpT8fcSCH1ZYF0mknDP jUGuoJS5FNa8sGprlEVrWHS5cQ0mOLWFH4t/hMOGbCqnDhGl3HG3akkDY7fPhkFX4ttT qHG8iXx0YGfK6u1RFQtR3AOS1TX4yq1POruPy9avY4I1EXpYp9ocpoH+85nWGKnzA30q gZ0A== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id e11si19520959pgk.524.2019.03.27.14.31.35; Wed, 27 Mar 2019 14:31:52 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726136AbfC0Va6 (ORCPT + 99 others); Wed, 27 Mar 2019 17:30:58 -0400 Received: from mail-oi1-f196.google.com ([209.85.167.196]:34165 "EHLO mail-oi1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726195AbfC0Va6 (ORCPT ); Wed, 27 Mar 2019 17:30:58 -0400 Received: by mail-oi1-f196.google.com with SMTP id v10so9773218oib.1 for ; Wed, 27 Mar 2019 14:30:58 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=JCxnMapnujBLhv3W4a2O/ybJVO1nPLBLzENy+BoBkzI=; b=CYqhl0kcfwmo/KKVY0YZp4mo3ggX1YGJ7rMFZ7Oxd2HAUtlOQy05VfO2Qvd1XzQ6yr Td98CXnrD1Iu1fjDbquG+HzArq4GmYe+ifuht2E6w/zVN72EXmWTX8JXr4N5QPfDrjPI jrZc22dUQZESaXI2TvBcTWH30CjZzjx5pLE8TanRVegqLIqux4HXenTiJFM3B6+cNJVJ uxNC151vxKOI5g1HGa+PH24GPGf3a+6YervItd8U1BT4npqmGmtSzFb95FpoF2ehJfxM X1h30JwmP8MZvDFh6wZvufLYEDWqUpdN2thspRh4Ul6EknC9Ehsao5UO8OZH+5ZlLtiD abcQ== X-Gm-Message-State: APjAAAUWaiQ3UNgifCnghPQv+zIoqhXBZU4nbzO94hXyGfTbWKYM82GY MI1yyUNdZTPI8FyaeUqOi76qwqStsgajjjlHOoSLcA== X-Received: by 2002:aca:5747:: with SMTP id l68mr21554750oib.103.1553722257766; Wed, 27 Mar 2019 14:30:57 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Ondrej Mosnacek Date: Wed, 27 Mar 2019 22:30:46 +0100 Message-ID: Subject: Re: [PATCH ghak90 V5 07/10] audit: add containerid support for user records To: Richard Guy Briggs Cc: containers@lists.linux-foundation.org, linux-api@vger.kernel.org, Linux-Audit Mailing List , linux-fsdevel@vger.kernel.org, LKML , netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, Paul Moore , Steve Grubb , David Howells , Simo Sorce , Eric Paris , "Serge E. Hallyn" , "Eric W . Biederman" , nhorman@tuxdriver.com Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Mar 15, 2019 at 7:34 PM Richard Guy Briggs wrote: > Add audit container identifier auxiliary record to user event standalone > records. > > Signed-off-by: Richard Guy Briggs Reviewed-by: Ondrej Mosnacek > --- > kernel/audit.c | 13 ++++++------- > 1 file changed, 6 insertions(+), 7 deletions(-) > > diff --git a/kernel/audit.c b/kernel/audit.c > index cfa659b3f6c4..cf448599ef34 100644 > --- a/kernel/audit.c > +++ b/kernel/audit.c > @@ -1142,12 +1142,6 @@ static void audit_log_common_recv_msg(struct audit_context *context, > audit_log_task_context(*ab); > } > > -static inline void audit_log_user_recv_msg(struct audit_buffer **ab, > - u16 msg_type) > -{ > - audit_log_common_recv_msg(NULL, ab, msg_type); > -} > - > int is_audit_feature_set(int i) > { > return af.features & AUDIT_FEATURE_TO_MASK(i); > @@ -1409,13 +1403,16 @@ static int audit_receive_msg(struct sk_buff *skb, struct nlmsghdr *nlh) > > err = audit_filter(msg_type, AUDIT_FILTER_USER); > if (err == 1) { /* match or error */ > + struct audit_context *context; > + > err = 0; > if (msg_type == AUDIT_USER_TTY) { > err = tty_audit_push(); > if (err) > break; > } > - audit_log_user_recv_msg(&ab, msg_type); > + context = audit_alloc_local(GFP_KERNEL); > + audit_log_common_recv_msg(context, &ab, msg_type); > if (msg_type != AUDIT_USER_TTY) > audit_log_format(ab, " msg='%.*s'", > AUDIT_MESSAGE_TEXT_MAX, > @@ -1431,6 +1428,8 @@ static int audit_receive_msg(struct sk_buff *skb, struct nlmsghdr *nlh) > audit_log_n_untrustedstring(ab, data, size); > } > audit_log_end(ab); > + audit_log_contid(context, audit_get_contid(current)); > + audit_free_context(context); > } > break; > case AUDIT_ADD_RULE: > -- > 1.8.3.1 > -- Ondrej Mosnacek Software Engineer, Security Technologies Red Hat, Inc.