128 Character limit on proctitle field?

"Wieprecht, Karen M." <[email protected]> Fri, 15 Sep 2023 16:15:12 +0000
Newsgroups com.redhat.linux-audit
Message-ID <[email protected]>
--===============0881015176276008567==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_"

--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

All,

We're working with Docker and podman, and I'm working on parsing the audit =
data we get to flag prohibited and missing command options based on STIG gu=
idelines.   I normally extract the proctitle from the raw auditd data , but=
 these commands are very long with sometimes 23 or more command line parame=
ters ,  and I noticed that all of the auditd proctitle data for the lengthi=
er commands is being cut off at 128 characters.

I'm bringing this up  for two reasons:

     One,  not everyone working with this data may realize that there seems=
 to be a character limit,
     and second, if this is by chance a bug as opposed to intentional,  the=
n I'm hoping we can get a fix cooking for it?

In the meantime,  I may be able to work around this by piecing together the=
 full command from the "a#=3D "  fields, but it would be much easier if pro=
ctitle wasn't cut off after 128 chars.

Thanks, any info you can share would be much appreciated,

Karen Wieprecht

--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
=09{font-family:"Cambria Math";
=09panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0in;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:#0563C1;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:#954F72;
=09text-decoration:underline;}
span.EmailStyle17
=09{mso-style-type:personal-compose;
=09font-family:"Calibri",sans-serif;
=09color:windowtext;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-family:"Calibri",sans-serif;}
@page WordSection1
=09{size:8.5in 11.0in;
=09margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
=09{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">All,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">We&#8217;re working with Docker and podman, and I&#8=
217;m working on parsing the audit data we get to flag prohibited and missi=
ng command options based on STIG guidelines.&nbsp;&nbsp; I normally extract=
 the proctitle from the raw auditd data , but these commands
 are very long with sometimes 23 or more command line parameters ,&nbsp; an=
d I noticed that all of the auditd proctitle data for the lengthier command=
s is being cut off at 128 characters.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I&#8217;m bringing this up &nbsp;for two reasons:&nb=
sp;&nbsp; <o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">&nbsp;&nbsp;&nbsp;&nbsp; One,&nbsp; not everyone wor=
king with this data may realize that there seems to be a character limit,&n=
bsp;
<o:p></o:p></p>
<p class=3D"MsoNormal">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;and second, if this is=
 by chance a bug as opposed to intentional,&nbsp; then I&#8217;m hoping we =
can get a fix cooking for it?
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">In the meantime,&nbsp; I may be able to work around =
this by piecing together the full command from the &#8220;a#=3D &#8220; &nb=
sp;fields, but it would be much easier if proctitle wasn&#8217;t cut off af=
ter 128 chars.&nbsp;
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Thanks, any info you can share would be much appreci=
ated,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Karen Wieprecht &nbsp;&nbsp;<o:p></o:p></p>
</div>
</body>
</html>

--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_--

--===============0881015176276008567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
Linux-audit mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/linux-audit

--===============0881015176276008567==--