Bug 2235827

Summary: Backport kernel audit enhancements and fixes up to upstream v6.6
Product: Red Hat Enterprise Linux 9 Reporter: Richard Guy Briggs <rbriggs>
Component: kernelAssignee: Ricardo Robaina <rrobaina>
kernel sub component: Audit QA Contact: Kernel General QE <kernel-general-qe>
Status: CLOSED MIGRATED Docs Contact:
Severity: medium    
Priority: medium CC: denli, rrobaina
Version: 9.4Keywords: MigratedToJIRA, Triaged
Target Milestone: rcFlags: pm-rhel: mirror+
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-09-25 21:05:53 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Richard Guy Briggs 2023-08-29 20:23:54 UTC
Backport selected trivial fixes, cleanups, and enhancements from upstream up to version 6.3. This will help make Audit functionality more stable, bring useful enhancements/fixes downstream, and ease future backports.

Tentative list of upstream commits (in apply order):

TBA

Comment 1 Richard Guy Briggs 2023-09-01 16:08:50 UTC
Initial patch list, will need to be updated as additions are made upstream.

on v6.5 (in v6.6-rc1?) from net: git://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git
check with Florian Westphal <fwestpha>
        2023-08-30  {kuba}      2023-08-30  {kuba}      4e60de1e4769  Merge tag 'nf-23-08-31' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf
        2023-08-29  {phil}      2023-08-31  {pablo}     [bugfix] 7e9be1124dbe  netfilter: nf_tables: Audit log setelem reset
                Fixes: 079cd633219d7 ("netfilter: nf_tables: Introduce NFT_MSG_GETSETELEM_RESET")
        2023-08-29  {phil}      2023-08-31  {pablo}     [bugfix] ea078ae9108e  netfilter: nf_tables: Audit log rule reset
                Fixes: 8daa8fde3fc3f ("netfilter: nf_tables: Introduce NFT_MSG_GETRULE_RESET")

on v6.5-rc1 (in v6.6-rc1?) from audit/next git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit.git
        2023-08-16  {atulpant.linux}    2023-08-15  {paul}     [cleaup] b1a0f64cc65e  audit: move trailing statements to next line
        2023-08-16  {atulpant.linux}    2023-08-15  {paul}     [cleaup] 22cde1012f6a  audit: cleanup function braces and assignment-in-if-condition
        2023-08-16  {atulpant.linux}    2023-08-15  {paul}     [cleaup] 62acadda115a  audit: add space before parenthesis and around '=', "==", and '<'
        2023-08-08  {cuigaosheng1}      2023-08-08  {paul}     [bugfix] b59bc6e37237  audit: fix possible soft lockup in __audit_inode_child()
                Fixes: 5195d8e217a7 ("audit: dynamically allocate audit_names when not enough space is in the names array")
        2023-07-21  {xiujianfeng}       2023-07-21  {paul}     [bugfix] bf98354280bf  audit: correct audit_filter_inodes() definition
                Fixes: 0590b9335a1c ("fixing audit rule ordering mess, part 1")
        2023-07-20  {xiujianfeng}       2023-07-20  {paul}     [cleanup] be4187faa8a4  audit: include security.h unconditionally

Comment 2 RHEL Program Management 2023-09-25 20:11:56 UTC
Issue migration from Bugzilla to Jira is in process at this time. This will be the last message in Jira copied from the Bugzilla bug.

Comment 3 RHEL Program Management 2023-09-25 21:05:53 UTC
This BZ has been automatically migrated to the issues.redhat.com Red Hat Issue Tracker. All future work related to this report will be managed there.

Due to differences in account names between systems, some fields were not replicated.  Be sure to add yourself to Jira issue's "Watchers" field to continue receiving updates and add others to the "Need Info From" field to continue requesting information.

To find the migrated issue, look in the "Links" section for a direct link to the new issue location. The issue key will have an icon of 2 footprints next to it, and begin with "RHEL-" followed by an integer.  You can also find this issue by visiting https://issues.redhat.com/issues/?jql= and searching the "Bugzilla Bug" field for this BZ's number, e.g. a search like:

"Bugzilla Bug" = 1234567

In the event you have trouble locating or viewing this issue, you can file an issue by sending mail to rh-issues. You can also visit https://access.redhat.com/articles/7032570 for general account information.