Bug 634303

Summary: audit filtering on selinux label of userspace audit messages
Product: Red Hat Enterprise Linux 6 Reporter: Eric Paris <eparis>
Component: kernelAssignee: Eric Paris <eparis>
Status: CLOSED ERRATA QA Contact: Red Hat Kernel QE team <kernel-qe>
Severity: medium Docs Contact:
Priority: low    
Version: 6.1   
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: kernel-2.6.32-91.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 667405 (view as bug list) Environment:
Last Closed: 2011-05-19 12:38:13 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 667405    

Description Eric Paris 2010-09-15 18:43:46 UTC
Add support so the kernel can filter userspace audit messages based on the SELinux label of the process sending the message.  This is needed to support filtering of sVirt audit messages.

Comment 2 Eric Paris 2010-09-27 16:05:33 UTC
Posted to internal list for review potentially for 6.1

Comment 3 RHEL Program Management 2010-11-19 17:40:40 UTC
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux maintenance release. Product Management has 
requested further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed 
products. This request is not yet committed for inclusion in an Update release.

Comment 4 Aristeu Rozanski 2010-12-15 16:05:15 UTC
Patch(es) available on kernel-2.6.32-91.el6

Comment 8 errata-xmlrpc 2011-05-19 12:38:13 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2011-0542.html