[PATCH] LSPP audit enablement: storing selinux ocontext and scontext

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Tue Sep 27 05:57:21 UTC 2005


On Mon, 26 Sep 2005 16:28:39 EDT, Steve Grubb said:

> 1500 - 1599 kernel LSPP events
> 1700 - 1799 kernel crypto events
> 1800 - 1999 future kernel use (maybe integrity labels and related events)
< and so on..>

Am I the only one who thinks "100 entries will be enough" sounds suspiciously
like "640K should be enough for anybody"?  Do we either have a way to
guarantee that it will be enough (go with pseudo-fractional entries
a la '1701 subtype 1, 2, 3, 1702 subtype 1..8, 1703 subtype 1..934, etc',
or a way to expand it, keeping in mind forward/backward combatibility issues)?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/linux-audit/attachments/20050927/2c14a895/attachment.sig>


More information about the Linux-audit mailing list