Received: by 2002:a05:6a10:6d10:0:0:0:0 with SMTP id gq16csp895798pxb; Fri, 22 Apr 2022 13:41:43 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyf1nvSl5gQFc9qfH30D11IcayWCjnVSzUKcz9v5CIeZGXUM8FNvKML9AF4GuztMZTNcekn X-Received: by 2002:a05:6a00:330a:b0:50a:cac1:7986 with SMTP id cq10-20020a056a00330a00b0050acac17986mr6842615pfb.4.1650660103039; Fri, 22 Apr 2022 13:41:43 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1650660103; cv=none; d=google.com; s=arc-20160816; b=kFLsv6n3WaQCHLenvZDXd8aHt07eHXLPnplPM8vnYvVwv7rTF2aFcxgUM8JgbRE/1w pCOqb0QJWC7YJS9g1RwO0bC/4g3J9rcnIp5Qv9cqP5GBCK/wT0BGIt2SJ2MKNFiWro+O ArI+Rve8hR9Y4vHxvN3Z5v0/m+OGFQkcFjPSv+ovrp9d5zOvN8wznFoSUP8dU6xbF61V yGd+03g9S2W6xNs4c+wUcTqVtYLf1jtxugdId6N6VnpjxIaELX7AEj7oB8gRHzfJjhBF 54zj4aGcPwTgU/78WV5s2rV7Ii+PYaPylhqeVvDl/rBLjnTT56EPvlir6dsYFDX/Dj1M 9ycg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=hbhKna1yAX3vL1E68yszR6PG2CBxYv3cVCcWr9+en7c=; b=psD+14decobLphI/lSiA4mFu9HmUABEM8jHMv7bSFnaPGRaFZa478KTIL4wzxul9DS acld3AaRXYCdZSvIm/BTJTfx4TQDUSZPS+k7PdS2ARuMKyNgaY8GZ1eMhuiKGPgcvmx2 JEJruN5KsunZTLH8uC0R8QluoMqBGnwoVzSemlFnb5VLMyaiQfvjS1PnLKFK+cJXCV8e up+g5pCK8Dl3w4PxPC/c73npHa3682LUwkPhoBCSIA6I4BhgWYMODZ1Kw/5jxFlTyjIE 8zz6hUwV8wOGVnqc+uFRKC+0GykFjKtOMWyRUZsH4TzC5UIsN+Yug16ig4UarLFc7YcZ uwpA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@paul-moore-com.20210112.gappssmtp.com header.s=20210112 header.b=7pOr70f1; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [2620:137:e000::1:18]) by mx.google.com with ESMTPS id 206-20020a6302d7000000b003aa618cb173si9788205pgc.793.2022.04.22.13.41.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 22 Apr 2022 13:41:43 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) client-ip=2620:137:e000::1:18; Authentication-Results: mx.google.com; dkim=pass header.i=@paul-moore-com.20210112.gappssmtp.com header.s=20210112 header.b=7pOr70f1; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 153C915C3BD; Fri, 22 Apr 2022 12:27:32 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1447838AbiDVQbz (ORCPT + 99 others); Fri, 22 Apr 2022 12:31:55 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60318 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1447970AbiDVQbr (ORCPT ); Fri, 22 Apr 2022 12:31:47 -0400 Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [IPv6:2a00:1450:4864:20::42f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 455975EDF6 for ; Fri, 22 Apr 2022 09:28:53 -0700 (PDT) Received: by mail-wr1-x42f.google.com with SMTP id e2so5541417wrh.7 for ; Fri, 22 Apr 2022 09:28:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore-com.20210112.gappssmtp.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=hbhKna1yAX3vL1E68yszR6PG2CBxYv3cVCcWr9+en7c=; b=7pOr70f1owMTZgrc7ZCZvQuy2xFgEp4/XmgBMO93KqqgRaYiQIh8bdSPLZwt0jODo+ bBlgmobXCg9pEqpdOvdJ6YVb45HdL35/QQUQlLjYCXAtPblQoN3qdhtC3sGE1WlvxHYJ pS2YQu6hjBVXPZQ5bQ+efylVhIH7DD3AwUOH9UIyc8qx5VUvso55SYllvwwgPiMMJ/1A NdcYXcnahGzRIKhQzdfb9mTKYTqXo0G92f/g+MSflbszqK3REqJTRjdHn3EzgbkJROQ8 /sfBJ7MYDiv5Q2qq5GgFhqKTLWT990JMOEhJ+rPUoQIham/09g24ShjgPFvIT03OjzJu A10A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=hbhKna1yAX3vL1E68yszR6PG2CBxYv3cVCcWr9+en7c=; b=Kz65TbdCbUA1DupPo1C+gp2z9QeEmedcxv88VlCwJ8+iiqYvqZHM74tQuGTOZAkoli hSGYQhXtWQ4YqTQdCoue+YZ3j7eDVUsFzrVfBTynxxecDoLvQ5opk/vkr6h7eoekhKR5 opMTYpBjOLg511Anwh9r/F5Go31lxl8YOZfe/VPAd0U3ia3eE1zE40DmTVZ/Wl+dR2tx MYXn4oDGh1MDDvAxTdTC5BkKzPgaWJEJ+BlRAgkJOEQjk2r4q1wSLqA5zIZZwGgi3nYV sNRIHW9wyvT9H4Ju8sxq5eenJgWFgy04EwCK+q5LAVJdO6VFjqCCu1HqUX6dr5Rj5iwG jBQQ== X-Gm-Message-State: AOAM533dLngzLp3fUB2mIF36a0FEIL6RlA3FMZLxDX9WM+AhE6rTUCJx 5iRKV/ZEL0oeXXwGRVd+pTEomTCzDNFfCkfAAq6R X-Received: by 2002:a5d:5847:0:b0:20a:ae08:8d42 with SMTP id i7-20020a5d5847000000b0020aae088d42mr4315402wrf.650.1650644931675; Fri, 22 Apr 2022 09:28:51 -0700 (PDT) MIME-Version: 1.0 References: <20220418145945.38797-1-casey@schaufler-ca.com> <20220418145945.38797-27-casey@schaufler-ca.com> In-Reply-To: <20220418145945.38797-27-casey@schaufler-ca.com> From: Paul Moore Date: Fri, 22 Apr 2022 12:28:40 -0400 Message-ID: Subject: Re: [PATCH v35 26/29] Audit: Add record for multiple task security contexts To: Casey Schaufler Cc: casey.schaufler@intel.com, jmorris@namei.org, linux-security-module@vger.kernel.org, selinux@vger.kernel.org, linux-audit@redhat.com, keescook@chromium.org, john.johansen@canonical.com, penguin-kernel@i-love.sakura.ne.jp, stephen.smalley.work@gmail.com, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RDNS_NONE, SPF_HELO_NONE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Apr 18, 2022 at 11:12 AM Casey Schaufler wrote: > > Create a new audit record AUDIT_MAC_TASK_CONTEXTS. > An example of the MAC_TASK_CONTEXTS (1420) record is: > > type=MAC_TASK_CONTEXTS[1420] > msg=audit(1600880931.832:113) > subj_apparmor=unconfined > subj_smack=_ > > When an audit event includes a AUDIT_MAC_TASK_CONTEXTS record > the "subj=" field in other records in the event will be "subj=?". > An AUDIT_MAC_TASK_CONTEXTS record is supplied when the system has > multiple security modules that may make access decisions based > on a subject security context. > > Functions are created to manage the skb list in the audit_buffer. > > Signed-off-by: Casey Schaufler > --- > include/uapi/linux/audit.h | 1 + > kernel/audit.c | 93 +++++++++++++++++++++++++++++++++++--- > 2 files changed, 88 insertions(+), 6 deletions(-) The audit_buffer_aux_new() and audit_buffer_aux_end() belong in patch 25/29, but otherwise this looks okay. Acked-by: Paul Moore -- paul-moore.com