All of lore.kernel.org
 help / color / mirror / Atom feed
* ANOM_ABEND events are missing
@ 2017-07-26 15:33 Steve Grubb
  2017-07-26 22:27 ` Paul Moore
  0 siblings, 1 reply; 2+ messages in thread
From: Steve Grubb @ 2017-07-26 15:33 UTC (permalink / raw)
  To: linux-audit

Hello Richard & Paul,

I have been noticing something lately. I have applications that crash and I 
get a notification from abrtd but when I go looking, there is no matching 
ANOM_ABEND records. This is one a 4.11.11 kernel.

The purpose of the ANOM_ABEND record is to indicate that a program has crashed 
and receieved a SIGSEGV or any other signal that results in termination. By 
any chance has something changed where our hook is placed? I also can't tell 
you when this started, I have a feeling this has been happening for over a 
year.

-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: ANOM_ABEND events are missing
  2017-07-26 15:33 ANOM_ABEND events are missing Steve Grubb
@ 2017-07-26 22:27 ` Paul Moore
  0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2017-07-26 22:27 UTC (permalink / raw)
  To: Steve Grubb; +Cc: linux-audit

On Wed, Jul 26, 2017 at 11:33 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> Hello Richard & Paul,
>
> I have been noticing something lately. I have applications that crash and I
> get a notification from abrtd but when I go looking, there is no matching
> ANOM_ABEND records. This is one a 4.11.11 kernel.
>
> The purpose of the ANOM_ABEND record is to indicate that a program has crashed
> and receieved a SIGSEGV or any other signal that results in termination. By
> any chance has something changed where our hook is placed? I also can't tell
> you when this started, I have a feeling this has been happening for over a
> year.

I know we talked about this a bit offline, but for the sake of the
list and anyone else who may be experiencing this: a reproducer would
be extremely helpful ... and when I say a reproducer, I'm not talking
about a process that crashes, that is easy enough, I'm talking about a
reliable procedure that results in a program crash which is not logged
via audit.

-- 
paul moore
www.paul-moore.com

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-07-26 22:27 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-07-26 15:33 ANOM_ABEND events are missing Steve Grubb
2017-07-26 22:27 ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.