Received: by 2002:a25:1506:0:0:0:0:0 with SMTP id 6csp801058ybv; Wed, 5 Feb 2020 14:59:28 -0800 (PST) X-Google-Smtp-Source: APXvYqx5vdGtJ69wkJ0HGqcNJQKY/e9XqyASpsg7i69kl68H6eJpKeUaQbqKk/9LLiTfnkDIGF6P X-Received: by 2002:a54:4010:: with SMTP id x16mr4950644oie.174.1580943568326; Wed, 05 Feb 2020 14:59:28 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1580943568; cv=none; d=google.com; s=arc-20160816; b=O6l2pVGd1gYY06oEUT8/zQ3riFmeIh81WnOMXtIkru0HVNY4xSalUp6vYHC8s1JfsI qt4S88eUjiSD5PcbW7AUh9bCmQeD1ThDZ/fKt3sC/B68rlQD6Dp4sdoOeRRdnw9sbZBf 2ztRrf6vj73MhiqNSC5ocEInbTlObE006LmkLN2lDtZNJjmRg7xwwxASYSQ8tTdywvgX tISu1/po8nDrPPP3IxiinZ9wt2rCEc4eWIJLje/4EbfWcpkxzxd6vLBuz/f2jKzL2uID P4XvXMiAtBX5M9X5yKu7JYBx8d9hei8ThabZgTmv7ffhiK4dsosG5gbKxxujm2Qe97Hs AKmw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=oUqqVzVv+zHVRjksql7Cab1+TMNFjyRWbvebZrdripg=; b=gFsNYGLMhjKq7e3CQBCYYFZepXB/FwvEUZxcLJBFHDbV/p9Mhwg+Fw0uwxTvI2IsnH YSZpQw36SvjYgyC9stSD7EhyTRz/E8u9Z5TBO5JnvQPC7ogYHA79JcJkOk6lNi9P1pEN Zqz8IYjd1VMnH4K3RBenNvbeXflODWl44dmwQWqYIrBuZkg+OE+qtXPlAAMXkvT4L4JY zGl1NvTMuyortlOXRl2gbfW56CTcy13LD3a81LvpZnPsCoIJKgmbs+13HsNGp6ysGtRN KIuDQYaUi6cY09zxCS91mYODwpcC178pyC7xRn7C7WoLTmg1AYK1rqveXtpO+ieOpzTm dHCg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@paul-moore-com.20150623.gappssmtp.com header.s=20150623 header.b=RNwHSh2u; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id b126si1053838oii.72.2020.02.05.14.59.15; Wed, 05 Feb 2020 14:59:28 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@paul-moore-com.20150623.gappssmtp.com header.s=20150623 header.b=RNwHSh2u; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727824AbgBEW6I (ORCPT + 99 others); Wed, 5 Feb 2020 17:58:08 -0500 Received: from mail-ed1-f66.google.com ([209.85.208.66]:36821 "EHLO mail-ed1-f66.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727541AbgBEW6I (ORCPT ); Wed, 5 Feb 2020 17:58:08 -0500 Received: by mail-ed1-f66.google.com with SMTP id j17so3885045edp.3 for ; Wed, 05 Feb 2020 14:58:07 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=oUqqVzVv+zHVRjksql7Cab1+TMNFjyRWbvebZrdripg=; b=RNwHSh2uWCO9tLjuX2QtbpIaLYOgempdFirtNjAkAtl2Lv53y46dHjKm71oMQgMoAC SBO8ofU2YRe0ZOpozTHfBE9dWtCVlTzEnRjLzNUNh+QWq+5N6T0J9Uh9t7t+8hTWoF+9 jIayozCNbwf0lGc0TDFHk7p+O9scR0Q58bIZ3tHbX9+KdOvZHkGiFUztFcYXe8fPt0/2 kvLAqsTBAcNWdLk5YDyo+6f1q0KuTCLHc4eVbOY0St5zcriy86UeHDmtEnvx4+TV1sc7 HJLZosR9LDytBdZEDnKXSj9vpSPq3CMMdFHusYNtVgWh70JO/sAOFoOJpbLerAjTch0Y zmRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=oUqqVzVv+zHVRjksql7Cab1+TMNFjyRWbvebZrdripg=; b=QNpxp2yNn6qbN49CCwNuAG72Lzj7cCr+J/uB4nGT3rG/n30lx6Yb4O/Bc+disb0gjt 9HF4BHR8oVHeTIQgaS1GpCod6mNmVzz00EjOe1M1Vc4XcGwLDcwpbnGBixFagZ5v/9ZQ QqP8uwxE4L+441snhHWEbiBs0fJ/Qe9kHgCRNqlyRygJdq8A5CobVFZFrh4eK7J7HizQ UKsloHM4ZGgpwZWaKSgxLzkz7QoAnAI9vzWTXzUg7dbrqp/inOVhQNL9s+vd2hFsQgu+ F9yWg3J3nt5eLhOMS033siQwwMRzgwPq+OhOHCSB4rlAzVd1GOu1Q7xOwSQpZj3Wc9gs T8OQ== X-Gm-Message-State: APjAAAX4rynOORarT+76NJldXg15ABxIQijTySxgAo1RFz3BCJnl1q53 oqOd7GJ0NS71kVrOhi4YzWGopGHXLVdhGz85UDwZ X-Received: by 2002:a17:906:9352:: with SMTP id p18mr292520ejw.95.1580943486402; Wed, 05 Feb 2020 14:58:06 -0800 (PST) MIME-Version: 1.0 References: <3665686.i1MIc9PeWa@x2> <35934535.C1y6eIYgqz@x2> In-Reply-To: <35934535.C1y6eIYgqz@x2> From: Paul Moore Date: Wed, 5 Feb 2020 17:57:55 -0500 Message-ID: Subject: Re: [PATCH ghak90 V8 13/16] audit: track container nesting To: Steve Grubb Cc: Richard Guy Briggs , containers@lists.linux-foundation.org, linux-api@vger.kernel.org, Linux-Audit Mailing List , linux-fsdevel@vger.kernel.org, LKML , netdev@vger.kernel.org, netfilter-devel@vger.kernel.org, omosnace@redhat.com, dhowells@redhat.com, simo@redhat.com, Eric Paris , Serge Hallyn , ebiederm@xmission.com, nhorman@tuxdriver.com, Dan Walsh , mpatel@redhat.com Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Feb 4, 2020 at 1:12 PM Steve Grubb wrote: > On Tuesday, February 4, 2020 10:52:36 AM EST Paul Moore wrote: > > On Tue, Feb 4, 2020 at 10:47 AM Steve Grubb wrote: > > > On Tuesday, February 4, 2020 8:19:44 AM EST Richard Guy Briggs wrote: > > > > > The established pattern is that we print -1 when its unset and "?" > > > > > when > > > > > its totalling missing. So, how could this be invalid? It should be > > > > > set > > > > > or not. That is unless its totally missing just like when we do not > > > > > run > > > > > with selinux enabled and a context just doesn't exist. > > > > > > > > Ok, so in this case it is clearly unset, so should be -1, which will be > > > > a > > > > 20-digit number when represented as an unsigned long long int. > > > > > > > > Thank you for that clarification Steve. > > > > > > It is literally a -1. ( 2 characters) > > > > Well, not as Richard has currently written the code, it is a "%llu". > > This was why I asked the question I did; if we want the "-1" here we > > probably want to special case that as I don't think we want to display > > audit container IDs as signed numbers in general. > > OK, then go with the long number, we'll fix it in the interpretation. I guess > we do the same thing for auid. As I said above, I'm okay with a special case handling for unset/"-1" in this case. -- paul moore www.paul-moore.com