file system auditing, zany timezone issues, design document, etc, etc

Timothy R. Chavez tinytim at us.ibm.com
Mon Apr 25 18:27:30 UTC 2005


Hello,

First and foremost I want to apologize for the zany timezone issues I've
been having -- probably would have helped to have /etc/localtime, eh?
Having to reconstruct the root filesystem from a lost+found because it's
faster then redoing a gentoo stage1 isn't fun ;-) Anyway, hoping that
that's fixed (and hoping I never have to relive the experience ;-)).

So yeah... I was asked to wait until after tommorow's meeting to submit
to LKML, which is just as-well.  That gives you all a little time to
test it :-) J/K -- But, really, it would be nice if some people just
tried to patch/install the kernel and play with auditctl -w/-W for a
couple minutes and respond with yay or nay.

Just to get a bearing of where I'm at and what I'm thinking.  I'm hoping
that by the end of next week:

* auditfs RFC on LKML 
* FVT testcases will be completed
* intial design document drafted

Perhaps, we could also merge auditfs into BK or git-audit (or whatever
it'll be called) as well by next week.

Thanks.

-tim





More information about the Linux-audit mailing list