[PATCH v2 3/4] seccomp: Audit attempts to modify the actions_logged sysctl
James Morris
jmorris at namei.org
Wed May 2 21:17:37 UTC 2018
On Wed, 2 May 2018, Tyler Hicks wrote:
> type=CONFIG_CHANGE msg=audit(1525275325.613:142): op=seccomp-logging
> actions=kill_process,kill_thread,errno,trace,log
> old-actions=kill_process,kill_thread,errno,trace,log res=1
>
> No audit records are generated when reading the actions_logged sysctl.
>
> Suggested-by: Steve Grubb <sgrubb at redhat.com>
> Signed-off-by: Tyler Hicks <tyhicks at canonical.com>
Reviewed-by: James Morris <james.morris at microsoft.com>
--
James Morris
<jmorris at namei.org>
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
More information about the Linux-security-module-archive
mailing list