The audit "context" and when to expect it.

Casey Schaufler casey at schaufler-ca.com
Fri May 29 17:59:09 UTC 2020


What does a NULL audit context (e.g. ab->cxt == NULL) tell
me about the status of the audit buffer? It seems like it should
be telling me that the audit buffer is being created for some
purpose unrelated to the current task. And yet there are places
where information is pulled from the current task even when
the cxt is NULL.






More information about the Linux-audit mailing list