Re: [PATCHv2 7/8] audit: also audit cgroup ACL permissions

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 03/09/2011 08:26 AM, Daniel P. Berrange wrote:
> On Tue, Mar 08, 2011 at 10:13:49PM -0700, Eric Blake wrote:
>> * src/qemu/qemu_audit.h (qemuAuditCgroupMajor)
>> (qemuAuditCgroupPath): Add parameter.
>> * src/qemu/qemu_audit.c (qemuAuditCgroupMajor)
>> (qemuAuditCgroupPath): Add 'acl=rwm' to cgroup audit entries.
>> * src/qemu/qemu_cgroup.c: Update clients.
>> * src/qemu/qemu_driver.c (qemudDomainSaveFlag): Likewise.
>> ---
>>
>> v2: new patch; perhaps patch should be floated before patch 2, and
>> then this patch squashed into patch 2, so that I'm only touching
>> qemuAuditCgroupPath once?
> 
> I don't think it hugely matters.
> 
>>  src/qemu/qemu_audit.c  |   12 ++++++++----
>>  src/qemu/qemu_audit.h  |    2 ++
>>  src/qemu/qemu_cgroup.c |   15 ++++++++-------
>>  src/qemu/qemu_driver.c |    6 +++---
>>  4 files changed, 21 insertions(+), 14 deletions(-)
> 
> ACK, unless it needs some changes based on my two comments to
> the previous patch about certain RWM vs RW usage.

It needed a tweak ("rw" vs. "rwm").  I've applied patches 1-3 and 5-7,
and will be doing a PATCHv3 for patch 4, 8, and other followups for
auditing network devices after I finish more testing.

-- 
Eric Blake   eblake@xxxxxxxxxx    +1-801-349-2682
Libvirt virtualization library http://libvirt.org

Attachment: signature.asc
Description: OpenPGP digital signature

--
libvir-list mailing list
libvir-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/libvir-list

[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Fedora Tools]