Re: [PATCH v2] audit: log nftables configuration change events once per table

2021-03-23 Thread Richard Guy Briggs
On 2021-03-22 23:57, Pablo Neira Ayuso wrote: > On Mon, Mar 22, 2021 at 04:49:04PM -0400, Richard Guy Briggs wrote: > > diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c > > index c1eb5cdb3033..42ba44890523 100644 > > --- a/net/netfilter/nf_tables_api.c > > +++

Re: [PATCH v2] audit: log nftables configuration change events once per table

2021-03-22 Thread Pablo Neira Ayuso
On Mon, Mar 22, 2021 at 04:49:04PM -0400, Richard Guy Briggs wrote: > diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c > index c1eb5cdb3033..42ba44890523 100644 > --- a/net/netfilter/nf_tables_api.c > +++ b/net/netfilter/nf_tables_api.c [...] > @@ -8006,12 +7938,47 @@

[PATCH v2] audit: log nftables configuration change events once per table

2021-03-22 Thread Richard Guy Briggs
Reduce logging of nftables events to a level similar to iptables. Restore the table field to list the table, adding the generation. Indicate the op as the most significant operation in the event. A couple of sample events: type=PROCTITLE msg=audit(2021-03-18 09:30:49.801:143) :