Re: Sycall Rules vs Watch Rules

Amjad Gabbar <[email protected]> Fri, 29 Sep 2023 11:39:51 -0500
Newsgroups com.redhat.linux-audit
Message-ID <CAJcJf=Ss2Fz3932cE+Fxf4rGMUrbNOPEZ1i3xAQmz_x+XbVbGg@mail.gmail.com>
--===============7640820996097210896==
Content-Type: multipart/alternative; boundary="000000000000760def0606821366"

--000000000000760def0606821366
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Sounds good. I will test this out.

Regards
Ali Adnan

On Thu, Sep 28, 2023 at 11:30 AM Steve Grubb <[email protected]> wrote:

> On Thursday, September 28, 2023 11:53:26 AM EDT Steve Grubb wrote:
> > On Thursday, September 21, 2023 4:02:49 PM EDT Amjad Gabbar wrote:
> > > > The best solution would be a kernel modification so that there are =
no
> > > > mismatched lists.
> > >
> > > I agree as well....This would be the cleanest solution. This would al=
so
> > > solve the userspace problem of maintaining different lists which can
> get
> > > out of hand fairly quickly.
> >
> > After looking into this, a kernel patch would also not work well. It ha=
s
> to
> > be arch specific
> >
> > > > I guess we can warn on that to rewrite in syscall notation.
> > >
> > > We certainly should. I think the user should know that there is a
> > > performance cost associated with watches and we should explicitly
> mention
> > > how it can be optimized in the manpages also. The reason being I am
> > > pretty sure, numerous users/repos still do make use of the -w notatio=
n
> > > and we do want to let them know the issue here. We also need to make
> > > quite a few changes to the manpages also regarding this. Because,
> > > initially even I was  very confused when reading the man pages and
> seeing
> > > the actual implementation of and results were not quite in sync.
> >
> > I have made the changes to the master and audit-3.1-maint branches.
> Please
> > everyone concerned give them tests. The short of it is that if you use
> the
> > '- w' notation for watches, it will remain the same and slower.
>
> Actually, ths is the one that draws the warning to urge people to migrate=
.
>
> > If you use
> > the syscall notation without "-F arch", you will get a warning that it
> > cannot be optimized without adding "-Farch".
>
> Actually, you won't in order to preserve intentional behavior.
>
> > If you add "-F arch", you
> > will possibly need one for both arches which means doubling the rules. =
If
> > you do not want to double the rules, you might place a syscall rule for
> > any 32 system call (21-no32bit.rules). Or you can leave it as is and no=
t
> > care. The sample rules and all man pages have been updated.
>
> I should have provided an example of what this means. If you have this ki=
nd
> of rule:
>
> -w /etc/shadow -p wa -k shadow
>
> And when applied draws a warning:
>
> # auditctl -w /etc/shadow -p wa -k shadow
> Old style watch rules are slower
>
> It should be rewritten as
>
> -a always,exit -F arch=3Db64 -F path=3D/etc/shadow -F perm=3Dwa -F key=3D=
shadow
>
> Then it looks like this when loaded:
>
> #auditctl -l
> -a always,exit -F arch=3Db64 -S
> open,bind,truncate,ftruncate,rename,mkdir,rmdir,creat,link,unlink,symlink=
,chmod,fchmod,chown,fchown,lchown,mknod,acct,swapon,quotactl,setxattr,lsetx=
attr,fsetxattr,removexattr,lremovexattr,fremovexattr,openat,mkdirat,mknodat=
,fchownat,unlinkat,renameat,linkat,symlinkat,fchmodat,fallocate,renameat2,o=
penat2
> -F path=3D/etc/shadow -F perm=3Dwa -F key=3Dshadow
>
> And to delete  the rule,
> auditctl -d always,exit -F arch=3Db64 -F path=3D/etc/shadow -F perm=3Dwa =
-F
> key=3Dshadow
>
> or the long way
>
> auditctl -d always,exit -F arch=3Db64 -S
> open,bind,truncate,ftruncate,rename,mkdir,rmdir,creat,link,unlink,symlink=
,chmod,fchmod,chown,fchown,lchown,mknod,acct,swapon,quotactl,setxattr,lsetx=
attr,fsetxattr,removexattr,lremovexattr,fremovexattr,openat,mkdirat,mknodat=
,fchownat,unlinkat,renameat,linkat,symlinkat,fchmodat,fallocate,renameat2,o=
penat2
> -F path=3D/etc/shadow -F perm=3Dwa -F key=3Dshadow
>
> Hopefully this is clearer what the change is.
>
> -Steve
>
>
>
>

--000000000000760def0606821366
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Sounds good. I will test this out.</div><div dir=3D"auto"=
><br></div><div dir=3D"auto">Regards</div><div dir=3D"auto">Ali Adnan</div>=
<div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">O=
n Thu, Sep 28, 2023 at 11:30 AM Steve Grubb &lt;<a href=3D"mailto:sgrubb@re=
dhat.com">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-le=
ft:1ex">On Thursday, September 28, 2023 11:53:26 AM EDT Steve Grubb wrote:<=
br>
&gt; On Thursday, September 21, 2023 4:02:49 PM EDT Amjad Gabbar wrote:<br>
&gt; &gt; &gt; The best solution would be a kernel modification so that the=
re are no<br>
&gt; &gt; &gt; mismatched lists.<br>
&gt; &gt; <br>
&gt; &gt; I agree as well....This would be the cleanest solution. This woul=
d also<br>
&gt; &gt; solve the userspace problem of maintaining different lists which =
can get<br>
&gt; &gt; out of hand fairly quickly.<br>
&gt; <br>
&gt; After looking into this, a kernel patch would also not work well. It h=
as to<br>
&gt; be arch specific<br>
&gt; <br>
&gt; &gt; &gt; I guess we can warn on that to rewrite in syscall notation.<=
br>
&gt; &gt; <br>
&gt; &gt; We certainly should. I think the user should know that there is a=
<br>
&gt; &gt; performance cost associated with watches and we should explicitly=
 mention<br>
&gt; &gt; how it can be optimized in the manpages also. The reason being I =
am<br>
&gt; &gt; pretty sure, numerous users/repos still do make use of the -w not=
ation<br>
&gt; &gt; and we do want to let them know the issue here. We also need to m=
ake<br>
&gt; &gt; quite a few changes to the manpages also regarding this. Because,=
<br>
&gt; &gt; initially even I was=C2=A0 very confused when reading the man pag=
es and seeing<br>
&gt; &gt; the actual implementation of and results were not quite in sync.<=
br>
&gt; <br>
&gt; I have made the changes to the master and audit-3.1-maint branches. Pl=
ease<br>
&gt; everyone concerned give them tests. The short of it is that if you use=
 the<br>
&gt; &#39;- w&#39; notation for watches, it will remain the same and slower=
.<br>
<br>
Actually, ths is the one that draws the warning to urge people to migrate.<=
br>
<br>
&gt; If you use<br>
&gt; the syscall notation without &quot;-F arch&quot;, you will get a warni=
ng that it<br>
&gt; cannot be optimized without adding &quot;-Farch&quot;.<br>
<br>
Actually, you won&#39;t in order to preserve intentional behavior.<br>
<br>
&gt; If you add &quot;-F arch&quot;, you<br>
&gt; will possibly need one for both arches which means doubling the rules.=
 If<br>
&gt; you do not want to double the rules, you might place a syscall rule fo=
r<br>
&gt; any 32 system call (21-no32bit.rules). Or you can leave it as is and n=
ot<br>
&gt; care. The sample rules and all man pages have been updated.<br>
<br>
I should have provided an example of what this means. If you have this kind=
<br>
of rule:<br>
<br>
-w /etc/shadow -p wa -k shadow<br>
<br>
And when applied draws a warning:<br>
<br>
# auditctl -w /etc/shadow -p wa -k shadow<br>
Old style watch rules are slower<br>
<br>
It should be rewritten as<br>
<br>
-a always,exit -F arch=3Db64 -F path=3D/etc/shadow -F perm=3Dwa -F key=3Dsh=
adow<br>
<br>
Then it looks like this when loaded:<br>
<br>
#auditctl -l<br>
-a always,exit -F arch=3Db64 -S open,bind,truncate,ftruncate,rename,mkdir,r=
mdir,creat,link,unlink,symlink,chmod,fchmod,chown,fchown,lchown,mknod,acct,=
swapon,quotactl,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremo=
vexattr,openat,mkdirat,mknodat,fchownat,unlinkat,renameat,linkat,symlinkat,=
fchmodat,fallocate,renameat2,openat2 -F path=3D/etc/shadow -F perm=3Dwa -F =
key=3Dshadow<br>
<br>
And to delete=C2=A0 the rule, <br>
auditctl -d always,exit -F arch=3Db64 -F path=3D/etc/shadow -F perm=3Dwa -F=
 key=3Dshadow<br>
<br>
or the long way<br>
<br>
auditctl -d always,exit -F arch=3Db64 -S open,bind,truncate,ftruncate,renam=
e,mkdir,rmdir,creat,link,unlink,symlink,chmod,fchmod,chown,fchown,lchown,mk=
nod,acct,swapon,quotactl,setxattr,lsetxattr,fsetxattr,removexattr,lremovexa=
ttr,fremovexattr,openat,mkdirat,mknodat,fchownat,unlinkat,renameat,linkat,s=
ymlinkat,fchmodat,fallocate,renameat2,openat2 -F path=3D/etc/shadow -F perm=
=3Dwa -F key=3Dshadow<br>
<br>
Hopefully this is clearer what the change is.<br>
<br>
-Steve<br>
<br>
<br>
<br>
</blockquote></div></div>

--000000000000760def0606821366--

--===============7640820996097210896==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
Linux-audit mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/linux-audit

--===============7640820996097210896==--