[PATCH 0/2] Begin auditing SECCOMP_RET_ERRNO return actions

Andy Lutomirski luto at kernel.org
Tue Jan 3 05:57:15 UTC 2017


On Mon, Jan 2, 2017 at 8:53 AM, Tyler Hicks <tyhicks at canonical.com> wrote:
> This patch set creates the basis for auditing information specific to a given
> seccomp return action and then starts auditing SECCOMP_RET_ERRNO return
> actions. The audit messages for SECCOMP_RET_ERRNO return actions include the
> errno value that will be returned to userspace.
>

Not that I'm opposed to the idea, but what's the intended purpose?




More information about the Linux-audit mailing list