Getting the program name in audit messages

Stephen Smalley sds at tycho.nsa.gov
Fri Apr 1 20:07:10 UTC 2005


On Fri, 2005-04-01 at 20:51 +0100, David Woodhouse wrote:
> On Fri, 2005-04-01 at 14:24 -0500, Stephen Smalley wrote:
> > It just means that we keep the diff for auditsc.c as is, and drop the
> > diff for avc.c, i.e. we add comm and exe logging to the syscall auditing
> > but leave exe logging unmodified in the avc.  Which I think is what
> > David Woodhouse did already for his kernel since he wasn't sure about
> > the avc change.
> 
> It is. Since it's now purely an audit patch, should I put it into the BK
> tree?

IMHO, yes.

-- 
Stephen Smalley <sds at tycho.nsa.gov>
National Security Agency




More information about the Linux-audit mailing list