mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Richard Guy Briggs <rgb@redhat.com>
To: containers@lists.linux-foundation.org,
	Linux-Audit Mailing List <linux-audit@redhat.com>,
	LKML <linux-kernel@vger.kernel.org>
Cc: eparis@parisplace.org, Steve Grubb <sgrubb@redhat.com>,
	omosnace@redhat.com, Paul Moore <paul@paul-moore.com>,
	nhorman@redhat.com, dwalsh@redhat.com, mpatel@redhat.com,
	Richard Guy Briggs <rgb@redhat.com>
Subject: [PATCH ghau51/ghau40 v8 09/14] contid: interpret correctly CONTAINER_ID contid field csv
Date: Tue, 31 Dec 2019 14:58:16 -0500	[thread overview]
Message-ID: <1577822301-19760-10-git-send-email-rgb@redhat.com> (raw)
In-Reply-To: <1577822301-19760-1-git-send-email-rgb@redhat.com>

The CONTAINER_ID record contid field can contain comma-separated values
when accompanying a NETFILTER_PKT record.  Records appeared interpreted
as such:

Wrong:
	CONTAINER_ID msg=audit(2019-04-10 13:20:18.746:1690) : contid=777 666,333
Right:
	CONTAINER_ID msg=audit(2019-04-10 13:20:18.746:1690) : contid=777,666,333

Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
---
 src/ausearch-report.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/src/ausearch-report.c b/src/ausearch-report.c
index 416c2b13fa6a..82fa9579f972 100644
--- a/src/ausearch-report.c
+++ b/src/ausearch-report.c
@@ -279,7 +279,7 @@ no_print:
 			if (str && val && (str < val)) {
 			// Value side  has commas and another field exists
 			// Known: LABEL_LEVEL_CHANGE banners=none,none
-			// Known: ROLL_ASSIGN new-role=r,r
+			// Known: ROLE_ASSIGN new-role=r,r
 			// Known: any MAC LABEL can potentially have commas
 				int ftype = auparse_interp_adjust_type(n->type,
 								name, val);
@@ -293,9 +293,11 @@ no_print:
 			} else if (str && (val == NULL)) {
 			// Goes all the way to the end. Done parsing
 			// Known: MCS context in PATH rec obj=u:r:t:s0:c2,c7
+			// Known: CONTAINER_ID contid can be a comma-separated list
 				int ftype = auparse_interp_adjust_type(n->type,
 								name, ptr);
-				if (ftype == AUPARSE_TYPE_MAC_LABEL)
+				if (ftype == AUPARSE_TYPE_MAC_LABEL
+				    || ftype == AUPARSE_TYPE_CONTID)
 					str = NULL;
 				else {
 					*str++ = 0;
-- 
1.8.3.1


  parent reply	other threads:[~2019-12-31 19:59 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-12-31 19:58 [PATCH ghau51/ghau40 v8 00/14] add support for audit container identifier Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 01/14] AUDIT_CONTAINER_OP message type basic support Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 02/14] AUDIT_CONTAINER_ID " Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 03/14] auditctl: add support for AUDIT_CONTID filter Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 04/14] add ausearch containerid support Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 05/14] start normalization " Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 06/14] libaudit: add support to get the task audit container identifier Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 07/14] signal_info: only print context if it is available Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 08/14] add support for audit_signal_info2 Richard Guy Briggs
2019-12-31 19:58 ` Richard Guy Briggs [this message]
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 10/14] ausearch: convert contid to comma/carrat-sep list Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 11/14] ausearch: convert contid to comma/carrat-sep cnode/clist Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 12/14] auditctl: add a config parameter to limit the contid nesting depth Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 13/14] auditctl: add a config parameter to limit the contid netns count Richard Guy Briggs
2019-12-31 19:58 ` [PATCH ghau51/ghau40 v8 14/14] libaudit: add support to get and set capcontid on a task Richard Guy Briggs

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1577822301-19760-10-git-send-email-rgb@redhat.com \
    --to=rgb@redhat.com \
    --cc=containers@lists.linux-foundation.org \
    --cc=dwalsh@redhat.com \
    --cc=eparis@parisplace.org \
    --cc=linux-audit@redhat.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mpatel@redhat.com \
    --cc=nhorman@redhat.com \
    --cc=omosnace@redhat.com \
    --cc=paul@paul-moore.com \
    --cc=sgrubb@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®