[PATCH 1/2] SELinux Context Label based audit filtering

Dustin Kirkland dustin.kirkland at us.ibm.com
Fri Feb 3 17:26:39 UTC 2006


On Fri, 2006-02-03 at 10:12 -0500, Stephen Smalley wrote: 
> 9) If so, the audit system then asks for contexts for the relevant SIDs
> and adds them to the audit message.  This might be an issue btw as we
> might run into an allocation failure at this point.

Actually, this "filtering" isn't determining whether or not the context
is added to the messsage...  Rather, it's determining whether or not
audit constructs the audit message at all and passes it to the audit
daemon for publication.  Maybe, you realized that already--just
clarifying though.

:-Dustin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/linux-audit/attachments/20060203/14fc0259/attachment.sig>


More information about the Linux-audit mailing list