All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH ghak81 RFC V2 0/5] audit: group task params
@ 2018-05-13  1:58 ` Richard Guy Briggs
  0 siblings, 0 replies; 30+ messages in thread
From: Richard Guy Briggs @ 2018-05-13  1:58 UTC (permalink / raw)
  To: Linux-Audit Mailing List, LKML,
	Linux NetDev Upstream Mailing List, Netfilter Devel List,
	Linux Security Module list, Integrity Measurement Architecture,
	SElinux list
  Cc: Eric Paris, Paul Moore, Steve Grubb, Ingo Molnar, David Howells,
	Richard Guy Briggs

Group the audit parameters for each task into one structure.
In particular, remove the loginuid and sessionid values and the audit
context pointer from the task structure, replacing them with an audit
task information structure to contain them.  Use access functions to
access audit values.

Note:  Use static allocation of the audit task information structure
initially.  Dynamic allocation was considered and attempted, but isn't
ready yet.  Static allocation has the limitation that future audit task
information structure changes would cause a visible change to the rest
of the kernel, whereas dynamic allocation would mostly hide any future
changes.

The first four access normalization patches could stand alone.

Passes audit-testsuite.

Changelog:
v2
- p2/5: add audit header to init/init_task.c to quiet kbuildbot
- audit_signal_info(): fetch loginuid once
- remove task_struct from audit_context() param list
- remove extra task_struct local vars
- do nothing on request to set audit context when audit is disabled

Richard Guy Briggs (5):
  audit: normalize loginuid read access
  audit: convert sessionid unset to a macro
  audit: use inline function to get audit context
  audit: use inline function to set audit context
  audit: collect audit task parameters

 MAINTAINERS                          |  2 +-
 include/linux/audit.h                | 28 ++++++++---
 include/linux/audit_task.h           | 31 ++++++++++++
 include/linux/sched.h                |  6 +--
 include/net/xfrm.h                   |  4 +-
 include/uapi/linux/audit.h           |  1 +
 init/init_task.c                     |  8 ++-
 kernel/audit.c                       |  6 +--
 kernel/audit_watch.c                 |  2 +-
 kernel/auditsc.c                     | 97 +++++++++++++++++-------------------
 kernel/fork.c                        |  2 +-
 net/bridge/netfilter/ebtables.c      |  2 +-
 net/core/dev.c                       |  2 +-
 net/netfilter/x_tables.c             |  2 +-
 net/netlabel/netlabel_user.c         |  2 +-
 security/integrity/ima/ima_api.c     |  2 +-
 security/integrity/integrity_audit.c |  2 +-
 security/lsm_audit.c                 |  2 +-
 security/selinux/hooks.c             |  4 +-
 security/selinux/selinuxfs.c         |  6 +--
 security/selinux/ss/services.c       | 12 ++---
 21 files changed, 133 insertions(+), 90 deletions(-)
 create mode 100644 include/linux/audit_task.h

-- 
1.8.3.1

^ permalink raw reply	[flat|nested] 30+ messages in thread

end of thread, other threads:[~2018-05-15  3:28 UTC | newest]

Thread overview: 30+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-05-13  1:58 [PATCH ghak81 RFC V2 0/5] audit: group task params Richard Guy Briggs
2018-05-13  1:58 ` Richard Guy Briggs
2018-05-13  1:58 ` [PATCH ghak81 RFC V2 1/5] audit: normalize loginuid read access Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-14 19:52   ` Paul Moore
2018-05-14 19:52     ` Paul Moore
2018-05-14 20:16     ` Richard Guy Briggs
2018-05-13  1:58 ` [PATCH ghak81 RFC V2 2/5] audit: convert sessionid unset to a macro Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-14 20:15   ` Paul Moore
2018-05-14 20:15     ` Paul Moore
2018-05-13  1:58 ` [PATCH ghak81 RFC V2 3/5] audit: use inline function to get audit context Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-14 21:44   ` Paul Moore
2018-05-14 21:44     ` Paul Moore
2018-05-15  3:05     ` Richard Guy Briggs
2018-05-15  3:05       ` Richard Guy Briggs
2018-05-15  3:28       ` Richard Guy Briggs
2018-05-15  3:28         ` Richard Guy Briggs
2018-05-13  1:58 ` [PATCH ghak81 RFC V2 4/5] audit: use inline function to set " Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-14 21:51   ` Paul Moore
2018-05-14 21:51     ` Paul Moore
2018-05-13  1:58 ` [PATCH ghak81 RFC V2 5/5] audit: collect audit task parameters Richard Guy Briggs
2018-05-13  1:58   ` Richard Guy Briggs
2018-05-14 21:54   ` Paul Moore
2018-05-14 21:54     ` Paul Moore
2018-05-15  1:20     ` Richard Guy Briggs
2018-05-15  1:35       ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.