Re: [PATCH ghak90 V7 20/21] audit: add capcontid to set contid outside init_user_ns

2019-10-30 Thread Paul Moore
On Thu, Oct 24, 2019 at 5:00 PM Richard Guy Briggs wrote: > Here's the note I had from that meeting: > > - Eric raised the issue that using /proc is likely to get more and more > hoary due to mount namespaces and suggested that we use a netlink > audit message (or a new syscall) to set the audit

Re: [PATCH ghak90 V7 14/21] audit: contid check descendancy and nesting

2019-10-30 Thread Paul Moore
On Thu, Oct 24, 2019 at 6:08 PM Richard Guy Briggs wrote: > On 2019-10-10 20:40, Paul Moore wrote: > > On Wed, Sep 18, 2019 at 9:26 PM Richard Guy Briggs wrote: > > > ?fixup! audit: convert to contid list to check for orch/engine ownership > > > > ? > > > > > Require the target task to be a desce

Re: [PATCH ghak90 V7 20/21] audit: add capcontid to set contid outside init_user_ns

2019-10-30 Thread Richard Guy Briggs
On 2019-10-30 16:27, Paul Moore wrote: > On Thu, Oct 24, 2019 at 5:00 PM Richard Guy Briggs wrote: > > Here's the note I had from that meeting: > > > > - Eric raised the issue that using /proc is likely to get more and more > > hoary due to mount namespaces and suggested that we use a netlink >