From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f177.google.com (mail-qk1-f177.google.com [209.85.222.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 530BE1DDC0B for ; Wed, 15 Jan 2025 23:53:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736985191; cv=none; b=FiBaEUEG7NwFRtxQadXZdou8wT2QK9JVkTwOH906Z2OMRHGpWYMhweVajYwg3JP3muXNedMs17l7wT64Vj7k5ONBeSftWS3xjVX+AcifNoEfTbq3+c6c4GOfchyhZG06odZL33IPxY0niNw1yeDfaRzyLrlmZ2Gy9UDvjgpFiiY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736985191; c=relaxed/simple; bh=w1jIE9hJSQLAasM7TNhoYeU19kfzxbDAm9Fb79w17Zc=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=qYAt2mF8cU+j1d7CPba8OBmksgfLPZ98r2jn4pzZdXCSRIURV9vlOviVfEcTSZ6RensZ/ygOPZGttRB2CLQJ8fMdYCaXFtNqDyWMd6weM0bH5B+FuIrWBVYGBzhiCQY6IclzRtyF/FYAuBMZL02IHwdL6b2wdJh7/zK48vpOa04= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=eWmB2uws; arc=none smtp.client-ip=209.85.222.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="eWmB2uws" Received: by mail-qk1-f177.google.com with SMTP id af79cd13be357-7b6f0afda3fso32638785a.2 for ; Wed, 15 Jan 2025 15:53:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1736985189; x=1737589989; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :mime-version:message-id:date:from:to:cc:subject:date:message-id :reply-to; bh=bJh+T7Hv8PTpEPApQXjKvV56GIOkdSD6Exn3cyfJMsI=; b=eWmB2uwscZSkqgcsmyAUiGk8MXYioHcwTTK8Z/FmMZ9zQWk1D3ZUj66GpT9p49yyIX JS2GBqfR3fwi+MlEmz8+HKQ2jdw4Z477SDyvExFCfbR62qlZJSIgCxz7HneNl1VG0/5u i12lNmdYkOaF4suZi6ohihiP69DmdIbNkyV5S/xF58Ye7xsWDHgjXNaK79vhwpa+jrr/ fDq66xBFjVZKvIJ2sC6EXEQUdcEFAn1NCiMqIhvWSbIUxqa6XFYvOs0bZvFhWQ6F+wtO 4oj9ie3zRIP1XFrgLYt/jeCsyPDvm4LFoRJ5a4azTbfEATxnVEUn85ocvKJkOca7crY1 dMFQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736985189; x=1737589989; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :mime-version:message-id:date:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to; bh=bJh+T7Hv8PTpEPApQXjKvV56GIOkdSD6Exn3cyfJMsI=; b=SJZ/IHrx8bdejfAeD2TMuM9qC1C59VqpVNGyYVs43rakaGhe5GZ+puGw9DoiDJVIef Qk99LlKJ9sFij6hfHyAITVb2vfNWiZu/gc12RGBNrTVzrfApNqFAWmx4b4D2LfZuBwk8 0IJ/lo3iOCY5ZdNfcrXZv+iA5AETaVl6gvKVAesdYbfilnGqwEsbZCeSPOwOEa4UlsEw z0LLDgrvLBz45qFZfp/nYnj27U8Iyzs9ZwlaS7SEAFeYQG5HFzx7/UEhSY9jZzprYyrK IwkOFyseCw/NBZ5p66ulx7uBf48TVSKgJSWfh3KDO3eFXYQ3gyw6gYHSsTsTQBWFm7lv KlOQ== X-Forwarded-Encrypted: i=1; AJvYcCUDXJINMnI6CkdYOFDwuCUsgV17e857+FIs5hwmw5XRPCgkYRPMS3YonKXJlN+81R43PEY8IHxD0yUk9us=@vger.kernel.org X-Gm-Message-State: AOJu0YwMWEXbnx5lzwdNBAM9IMmwMr7GKb4/QN11Zmqg6rF/kVEeer7h 1ukEDuV7ziSfvQ+FD01pLfP8ZJh1hjcZJ06VVUKCc0nWxQkpTf7xq+tIa5CP9w== X-Gm-Gg: ASbGncvvk6PvQKp/tYU9r1ju9gTzYQuyMa9rB0j5q3JU9dO9/ZM+wm72x0ROatj+b5S tVPekC1FWqaxr5ayDfumu6E3lu0ACw3/v3AzbllMW2azOW9nYgrAnRFgZo2gY7LHjMl8hg+MdLy e3hS0XVjcAgrivfeSZ9aJQFR/A0TKmeZkVVbYZJ2bfvbXw4wGyH9DPDWK/j9L/B1qtXJaqTAxrN soITCGtYLd4R8JbHSRXShra7Q1Llo69RmyXv3yiULKL0VXYiJI= X-Google-Smtp-Source: AGHT+IGlGPvAT10vh7zR6GchXN0fLnmopYZatnQZSEGB+wWm79pzK4V/AiofLks/o3AMcVKKkQY4vw== X-Received: by 2002:a05:620a:1793:b0:7b6:c93a:7f2f with SMTP id af79cd13be357-7bcd9709142mr4501376085a.14.1736985189359; Wed, 15 Jan 2025 15:53:09 -0800 (PST) Received: from localhost ([70.22.175.108]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-7bce3515f40sm766857685a.99.2025.01.15.15.53.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jan 2025 15:53:08 -0800 (PST) Date: Wed, 15 Jan 2025 18:53:08 -0500 Message-ID: <1ac8548a7b42eaed3f4392690011eb8b@paul-moore.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20250115_1512/pstg-lib:20250114_2216/pstg-pwork:20250115_1512 From: Paul Moore To: =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= , Eric Paris , =?UTF-8?q?G=C3=BCnther=20Noack?= , "Serge E . Hallyn" Cc: =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= , Ben Scarlato , Casey Schaufler , Charles Zaffery , Daniel Burgener , Francis Laniel , James Morris , Jann Horn , Jeff Xu , Jorge Lucangeli Obes , Kees Cook , Konstantin Meskhidze , Matt Bobrowski , Mikhail Ivanov , Phil Sutter , Praveen K Paladugu , Robert Salvet , Shervin Oloumi , Song Liu , Tahera Fahimi , Tyler Hicks , audit@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org Subject: Re: [PATCH v4 28/30] audit,landlock: Add AUDIT_EXE_LANDLOCK_DENY rule type References: <20250108154338.1129069-29-mic@digikod.net> In-Reply-To: <20250108154338.1129069-29-mic@digikod.net> On Jan 8, 2025 =?UTF-8?q?Micka=C3=ABl=20Sala=C3=BCn?= wrote: > > Landlock manages a set of standalone security policies, which can be > loaded by any process. Because a sandbox policy may contain errors and > can lead to log spam, we need a way to exclude some of them. It is > simple and it makes sense to identify Landlock domains (i.e. security > policies) per binary path that loaded such policy. > > Add a new AUDIT_EXE_LANDLOCK_DENY rule type to enables system > administrator to filter logs according to the origin or the security > policy responsible for a denial. For reasons similar to why I didn't want to expose the audit timestamp to users outside of audit, I'm not very enthusiastic about expanding the audit filtering code at this point in time. I'm not saying "no" exactly, just "not right now". -- paul-moore.com