audit-kernel icon indicating copy to clipboard operation
audit-kernel copied to clipboard

RFE: add a method to filter audit events based on audit container identifier

Open rgbriggs opened this issue 7 years ago • 10 comments

Add a method to filter audit events based on audit container identifier.

Add a u64 field AUDIT_CONTID to be able to specify an audit container identifier to be used to filter audit events.

Depends: https://github.com/linux-audit/audit-kernel/issues/90 Depends: https://github.com/linux-audit/audit-userspace/issues/40 See: https://github.com/linux-audit/audit-kernel/wiki/RFE-Audit-Container-ID

rgbriggs avatar Jun 01 '18 15:06 rgbriggs

Posted v3 kernel patchset upstream: https://www.redhat.com/archives/linux-audit/2018-June/msg00048.html https://lkml.org/lkml/2018/6/6/609

rgbriggs avatar Jun 06 '18 17:06 rgbriggs

posted v4 kernel patchset upstream: https://www.redhat.com/archives/linux-audit/2018-July/msg00178.html https://lkml.org/lkml/2018/7/31/855

rgbriggs avatar Jul 31 '18 20:07 rgbriggs

Test case v1 PR: https://github.com/linux-audit/audit-testsuite/pull/83

rgbriggs avatar Apr 10 '19 21:04 rgbriggs

2019-09-18: post v7: https://www.redhat.com/archives/linux-audit/2019-September/msg00016.html https://lkml.org/lkml/2019/9/18/1112

rgbriggs avatar Sep 19 '19 18:09 rgbriggs

V8 post: https://lkml.org/lkml/2019/12/31/229 https://lore.kernel.org/lkml/[email protected]/T/#t https://www.redhat.com/archives/linux-audit/2019-December/msg00049.html latest testsuite pr: https://githu.com/linux-audit/audit-testsuite/pull/91 The code is also posted at: git://toccata2.tricolour.ca/linux-2.6-rgb.git ghak90-audit-containerID.v8

rgbriggs avatar Dec 31 '19 21:12 rgbriggs

Post v9 kernel: https://www.redhat.com/archives/linux-audit/2020-June/msg00108.html https://lkml.org/lkml/2020/6/27/205

Post v9 userspace: https://www.redhat.com/archives/linux-audit/2020-June/msg00122.html

rgbriggs avatar Jun 27 '20 15:06 rgbriggs

2020-12-21 post v10 kernel https://www.redhat.com/archives/linux-audit/2020-December/msg00047.html https://lkml.org/lkml/2020/12/21/338 post v10 user https://www.redhat.com/archives/linux-audit/2020-December/msg00059.html https://lkml.org/lkml/2020/12/21/361 This was quickly addressed by the upstream kernel audit maintainer that ACKs on the first patch were questionable, which I acknowledged as being out of date triggering another version.

rgbriggs avatar Jan 12 '21 16:01 rgbriggs

post v11 kernel https://www.redhat.com/archives/linux-audit/2021-January/msg00007.html https://lkml.org/lkml/2021/1/12/818

rgbriggs avatar Jan 12 '21 16:01 rgbriggs

was this ever mainelined?

khimaros avatar Jun 19 '21 15:06 khimaros

This is ongoing work.

pcmoore avatar Jun 21 '21 13:06 pcmoore