128 Character limit on proctitle field?
"Wieprecht, Karen M." <[email protected]> Fri, 15 Sep 2023 16:15:12 +0000
| Newsgroups | com.redhat.linux-audit |
|---|---|
| Message-ID | <[email protected]> |
--===============0881015176276008567==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_"
--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
All,
We're working with Docker and podman, and I'm working on parsing the audit =
data we get to flag prohibited and missing command options based on STIG gu=
idelines. I normally extract the proctitle from the raw auditd data , but=
these commands are very long with sometimes 23 or more command line parame=
ters , and I noticed that all of the auditd proctitle data for the lengthi=
er commands is being cut off at 128 characters.
I'm bringing this up for two reasons:
One, not everyone working with this data may realize that there seems=
to be a character limit,
and second, if this is by chance a bug as opposed to intentional, the=
n I'm hoping we can get a fix cooking for it?
In the meantime, I may be able to work around this by piecing together the=
full command from the "a#=3D " fields, but it would be much easier if pro=
ctitle wasn't cut off after 128 chars.
Thanks, any info you can share would be much appreciated,
Karen Wieprecht
--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
=09{font-family:"Cambria Math";
=09panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0in;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:#0563C1;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:#954F72;
=09text-decoration:underline;}
span.EmailStyle17
=09{mso-style-type:personal-compose;
=09font-family:"Calibri",sans-serif;
=09color:windowtext;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-family:"Calibri",sans-serif;}
@page WordSection1
=09{size:8.5in 11.0in;
=09margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
=09{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">All,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">We’re working with Docker and podman, and I=
217;m working on parsing the audit data we get to flag prohibited and missi=
ng command options based on STIG guidelines. I normally extract=
the proctitle from the raw auditd data , but these commands
are very long with sometimes 23 or more command line parameters , an=
d I noticed that all of the auditd proctitle data for the lengthier command=
s is being cut off at 128 characters.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">I’m bringing this up for two reasons:&nb=
sp; <o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal"> One, not everyone wor=
king with this data may realize that there seems to be a character limit,&n=
bsp;
<o:p></o:p></p>
<p class=3D"MsoNormal"> and second, if this is=
by chance a bug as opposed to intentional, then I’m hoping we =
can get a fix cooking for it?
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">In the meantime, I may be able to work around =
this by piecing together the full command from the “a#=3D “ &nb=
sp;fields, but it would be much easier if proctitle wasn’t cut off af=
ter 128 chars.
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Thanks, any info you can share would be much appreci=
ated,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Karen Wieprecht <o:p></o:p></p>
</div>
</body>
</html>
--_000_f04d10f4d94c4c2295031fee26dc8082jhuapledu_--
--===============0881015176276008567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--
Linux-audit mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/linux-audit
--===============0881015176276008567==--