Richard Guy Briggs
e2a49009ba
audit: log nftables configuration change events once per table
[ Upstream commit c520292f29b8047285bcfbc2322fa2a9bf02521a ]
Reduce logging of nftables events to a level similar to iptables.
Restore the table field to list the table, adding the generation.
Indicate the op as the most significant operation in the event.
A couple of sample events:
type=PROCTITLE msg=audit(2021-03-18 09:30:49.801:143) : proctitle=/usr/bin/python3 -s /usr/sbin/firewalld --nofork --nopid
type=SYSCALL msg=audit(2021-03-18 09:30:49.801:143) : arch=x86_64 syscall=sendmsg success=yes exit=172 a0=0x6 a1=0x7ffdcfcbe650 a2=0x0 a3=0x7ffdcfcbd52c items=0 ppid=1 pid=367 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=roo
t sgid=root fsgid=root tty=(none) ses=unset comm=firewalld exe=/usr/bin/python3.9 subj=system_u:system_r:firewalld_t:s0 key=(null)
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.801:143) : table=firewalld:2 family=ipv6 entries=1 op=nft_register_table pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.801:143) : table=firewalld:2 family=ipv4 entries=1 op=nft_register_table pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.801:143) : table=firewalld:2 family=inet entries=1 op=nft_register_table pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
type=PROCTITLE msg=audit(2021-03-18 09:30:49.839:144) : proctitle=/usr/bin/python3 -s /usr/sbin/firewalld --nofork --nopid
type=SYSCALL msg=audit(2021-03-18 09:30:49.839:144) : arch=x86_64 syscall=sendmsg success=yes exit=22792 a0=0x6 a1=0x7ffdcfcbe650 a2=0x0 a3=0x7ffdcfcbd52c items=0 ppid=1 pid=367 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=r
oot sgid=root fsgid=root tty=(none) ses=unset comm=firewalld exe=/usr/bin/python3.9 subj=system_u:system_r:firewalld_t:s0 key=(null)
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.839:144) : table=firewalld:3 family=ipv6 entries=30 op=nft_register_chain pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.839:144) : table=firewalld:3 family=ipv4 entries=30 op=nft_register_chain pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
type=NETFILTER_CFG msg=audit(2021-03-18 09:30:49.839:144) : table=firewalld:3 family=inet entries=165 op=nft_register_chain pid=367 subj=system_u:system_r:firewalld_t:s0 comm=firewalld
The issue was originally documented in
https://github.com/linux-audit/audit-kernel/issues/124
Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
Acked-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-08-25 11:38:10 +02:00
..
2021-09-15 09:50:34 +02:00
2022-08-21 15:16:26 +02:00
2021-07-31 08:16:11 +02:00
2022-07-29 17:19:07 +02:00
2021-04-07 15:00:08 +02:00
2020-10-31 12:26:30 -07:00
2022-06-22 14:13:17 +02:00
2022-05-18 10:23:42 +02:00
2022-08-21 15:16:26 +02:00
2022-08-03 12:00:52 +02:00
2021-07-14 16:56:29 +02:00
2022-07-21 21:20:13 +02:00
2021-09-22 12:27:56 +02:00
2022-07-12 16:32:16 +02:00
2022-05-25 09:17:56 +02:00
2022-08-25 11:37:57 +02:00
2022-03-08 19:09:37 +01:00
2022-08-21 15:15:52 +02:00
2021-07-28 14:35:38 +02:00
2022-05-09 09:05:02 +02:00
2020-05-23 16:56:17 -07:00
2021-12-17 10:14:41 +01:00
2021-06-03 09:00:50 +02:00
2022-02-08 18:30:37 +01:00
2022-08-21 15:16:25 +02:00
2022-08-25 11:37:59 +02:00
2021-03-07 12:34:05 +01:00
2020-07-24 15:41:54 -07:00
2022-06-14 18:32:43 +02:00
2022-06-22 14:13:15 +02:00
2022-04-27 13:53:50 +02:00
2021-02-10 09:29:14 +01:00
2022-03-28 09:57:10 +02:00
2022-08-21 15:16:25 +02:00
2021-04-14 08:42:13 +02:00
2021-12-08 09:03:23 +01:00
2022-08-03 12:00:45 +02:00
2022-01-05 12:40:32 +01:00
2022-08-25 11:38:10 +02:00
2022-04-13 21:01:00 +02:00
2022-08-25 11:38:07 +02:00
2022-01-27 10:54:03 +01:00
2022-06-09 10:21:01 +02:00
2020-06-14 01:57:21 +09:00
2022-06-29 08:59:45 +02:00
2022-04-27 13:53:50 +02:00
2022-01-11 15:25:01 +01:00
2021-03-07 12:34:07 +01:00
2021-09-03 10:09:21 +02:00
2022-08-25 11:37:49 +02:00
2020-11-12 09:18:06 +01:00
2022-08-21 15:15:51 +02:00
2022-06-09 10:21:12 +02:00
2022-08-21 15:16:26 +02:00
2022-08-03 12:00:49 +02:00
2022-07-29 17:19:16 +02:00
2021-11-18 14:04:27 +01:00
2022-08-25 11:37:56 +02:00
2021-02-07 15:37:12 +01:00
2022-07-21 21:20:14 +02:00
2022-08-03 12:00:46 +02:00
2022-06-14 18:32:40 +02:00
2022-08-25 11:37:59 +02:00
2020-10-02 19:11:11 -07:00
2022-06-09 10:21:26 +02:00
2022-04-08 14:40:30 +02:00
2022-07-12 16:32:21 +02:00
2022-07-29 17:19:12 +02:00
2021-06-18 10:00:06 +02:00
2020-06-30 15:57:34 -07:00
2020-09-30 18:01:26 -07:00
2020-05-23 16:56:17 -07:00
2021-09-18 13:40:21 +02:00