[PATCH v2 3/4] seccomp: Audit attempts to modify the actions_logged sysctl

James Morris jmorris at namei.org
Wed May 2 21:17:37 UTC 2018


On Wed, 2 May 2018, Tyler Hicks wrote:

>  type=CONFIG_CHANGE msg=audit(1525275325.613:142): op=seccomp-logging
>  actions=kill_process,kill_thread,errno,trace,log
>  old-actions=kill_process,kill_thread,errno,trace,log res=1
> 
> No audit records are generated when reading the actions_logged sysctl.
> 
> Suggested-by: Steve Grubb <sgrubb at redhat.com>
> Signed-off-by: Tyler Hicks <tyhicks at canonical.com>


Reviewed-by: James Morris <james.morris at microsoft.com>

-- 
James Morris
<jmorris at namei.org>

--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html



More information about the Linux-security-module-archive mailing list