]> git.baikalelectronics.ru Git - kernel.git/commit
audit: add subj creds to NETFILTER_CFG record to
authorRichard Guy Briggs <rgb@redhat.com>
Wed, 20 May 2020 18:47:13 +0000 (14:47 -0400)
committerPaul Moore <paul@paul-moore.com>
Wed, 20 May 2020 22:09:19 +0000 (18:09 -0400)
commit9d44a121c5a79bc8a9d67c058456bd52a83c79e7
tree22fd18898abcca33af451a2f653e486c5f677539
parent0090c1edebf464f34629e14ae03d764cca7e0a3b
audit: add subj creds to NETFILTER_CFG record to

Some table unregister actions seem to be initiated by the kernel to
garbage collect unused tables that are not initiated by any userspace
actions.  It was found to be necessary to add the subject credentials to
cover this case to reveal the source of these actions.  A sample record:

The uid, auid, tty, ses and exe fields have not been included since they
are in the SYSCALL record and contain nothing useful in the non-user
context.

Here are two sample orphaned records:

  type=NETFILTER_CFG msg=audit(2020-05-20 12:14:36.505:5) : table=filter family=ipv4 entries=0 op=register pid=1 subj=kernel comm=swapper/0

  type=NETFILTER_CFG msg=audit(2020-05-20 12:15:27.701:301) : table=nat family=bridge entries=0 op=unregister pid=30 subj=system_u:system_r:kernel_t:s0 comm=kworker/u4:1

Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
kernel/auditsc.c