Bug 1296194 - RFE: audit the init_module syscall event
RFE: audit the init_module syscall event
Status: CLOSED DEFERRED
Product: Fedora
Classification: Fedora
Component: kernel (Show other bugs)
rawhide
Unspecified Unspecified
unspecified Severity medium
: ---
: ---
Assigned To: Paul Moore
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-06 09:57 EST by Steve Grubb
Modified: 2016-06-02 15:42 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-06-02 15:42:12 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Steve Grubb 2016-01-06 09:57:02 EST
Description of problem:
When the init_module syscall is audited, the main thing that we want is the module name. This is not recorded. Also when the debugfs module is loaded, we get 1000's of PATH records. We really don't want anything except the module name. Same thing with delete_module.

Version-Release number of selected component (if applicable):
4.2.6

Steps to Reproduce:
1. add "-a always,exit -F arch=x86_64 -S init_module -F key=mod-load" to the audit rules
2. reboot the system
3. ausearch --start today -k mod-load -i | less
Comment 2 Paul Moore 2016-06-02 15:42:12 EDT
Closing this as we are tracking upstream RFEs on GitHub now, see links in comment #1.

Note You need to log in before you can comment on or make changes to this bug.