[Apparmor-dev] [RFR] kernel fix for missing audit type

John Johansen jjohansen at suse.de
Fri Sep 14 07:47:48 MDT 2007


On Fri, Sep 07, 2007 at 09:48:40PM -0700, Steve Beattie wrote:
> On Wed, Sep 05, 2007 at 03:33:18PM -0700, John Johansen wrote:
> > The second is a hopefully temporary patch to apparmor that mimicks
> > the first by outputting the type field directly.  This results
> > in audit messages getting 2 type fields 1 with a name and 1 with
> > a number.
> 
> This patch adds support to the logparsing library for the type=15xx
> flags when events come through the audit subsystem. It also fixes the
> case where the audit daemon has not been configured with apparmor
> support and the events are reported as type=UNKNOWN[15xx].
> 
> Support needs to still be added for events coming through syslog.

looks good to me, please apply
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://forge.novell.com/pipermail/apparmor-dev/attachments/20070914/33550d1f/attachment.pgp


More information about the Apparmor-dev mailing list