* ANOM_ABEND events are missing
@ 2017-07-26 15:33 Steve Grubb
2017-07-26 22:27 ` Paul Moore
0 siblings, 1 reply; 2+ messages in thread
From: Steve Grubb @ 2017-07-26 15:33 UTC (permalink / raw)
To: linux-audit
Hello Richard & Paul,
I have been noticing something lately. I have applications that crash and I
get a notification from abrtd but when I go looking, there is no matching
ANOM_ABEND records. This is one a 4.11.11 kernel.
The purpose of the ANOM_ABEND record is to indicate that a program has crashed
and receieved a SIGSEGV or any other signal that results in termination. By
any chance has something changed where our hook is placed? I also can't tell
you when this started, I have a feeling this has been happening for over a
year.
-Steve
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: ANOM_ABEND events are missing
2017-07-26 15:33 ANOM_ABEND events are missing Steve Grubb
@ 2017-07-26 22:27 ` Paul Moore
0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2017-07-26 22:27 UTC (permalink / raw)
To: Steve Grubb; +Cc: linux-audit
On Wed, Jul 26, 2017 at 11:33 AM, Steve Grubb <sgrubb@redhat.com> wrote:
> Hello Richard & Paul,
>
> I have been noticing something lately. I have applications that crash and I
> get a notification from abrtd but when I go looking, there is no matching
> ANOM_ABEND records. This is one a 4.11.11 kernel.
>
> The purpose of the ANOM_ABEND record is to indicate that a program has crashed
> and receieved a SIGSEGV or any other signal that results in termination. By
> any chance has something changed where our hook is placed? I also can't tell
> you when this started, I have a feeling this has been happening for over a
> year.
I know we talked about this a bit offline, but for the sake of the
list and anyone else who may be experiencing this: a reproducer would
be extremely helpful ... and when I say a reproducer, I'm not talking
about a process that crashes, that is easy enough, I'm talking about a
reliable procedure that results in a program crash which is not logged
via audit.
--
paul moore
www.paul-moore.com
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-07-26 22:27 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-07-26 15:33 ANOM_ABEND events are missing Steve Grubb
2017-07-26 22:27 ` Paul Moore
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.