Re: [PATCH 3/4] AUDIT: audit when fcaps increase the permitted or inheritable capabilities

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eric Paris
Date: Wednesday, October 29, 2008 - 2:58 pm

On Wed, 2008-10-22 at 21:13 -0700, Andrew G. Morgan wrote:

So what did you two agree on for when to collect fcaps type information?
Any time bprm->cap_post_exec_permitted is non-zero?


The syscall record (rather than this auxilary fcaps record) will
indicate that the syscall failed.  it says something like success=no.

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 0/4] Audit support for file capabilities, Eric Paris, (Mon Oct 20, 3:25 pm)
Re: [PATCH 1/4] CAPABILITIES: add cpu endian vfs caps stru ..., Andrew G. Morgan, (Mon Oct 20, 10:50 pm)
Re: [PATCH 3/4] AUDIT: audit when fcaps increase the permi ..., Andrew G. Morgan, (Mon Oct 20, 10:53 pm)
Re: [PATCH 3/4] AUDIT: audit when fcaps increase the permi ..., Eric Paris, (Wed Oct 29, 2:58 pm)