• D
    bpf: Emit audit messages upon successful prog load and unload · bae141f5
    Daniel Borkmann 提交于
    Allow for audit messages to be emitted upon BPF program load and
    unload for having a timeline of events. The load itself is in
    syscall context, so additional info about the process initiating
    the BPF prog creation can be logged and later directly correlated
    to the unload event.
    
    The only info really needed from BPF side is the globally unique
    prog ID where then audit user space tooling can query / dump all
    info needed about the specific BPF program right upon load event
    and enrich the record, thus these changes needed here can be kept
    small and non-intrusive to the core.
    
    Raw example output:
    
      # auditctl -D
      # auditctl -a always,exit -F arch=x86_64 -S bpf
      # ausearch --start recent -m 1334
      ...
      ----
      time->Wed Nov 27 16:04:13 2019
      type=PROCTITLE msg=audit(1574867053.120:84664): proctitle="./bpf"
      type=SYSCALL msg=audit(1574867053.120:84664): arch=c000003e syscall=321   \
        success=yes exit=3 a0=5 a1=7ffea484fbe0 a2=70 a3=0 items=0 ppid=7477    \
        pid=12698 auid=1001 uid=1001 gid=1001 euid=1001 suid=1001 fsuid=1001    \
        egid=1001 sgid=1001 fsgid=1001 tty=pts2 ses=4 comm="bpf"                \
        exe="/home/jolsa/auditd/audit-testsuite/tests/bpf/bpf"                  \
        subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null)
      type=UNKNOWN[1334] msg=audit(1574867053.120:84664): prog-id=76 op=LOAD
      ----
      time->Wed Nov 27 16:04:13 2019
      type=UNKNOWN[1334] msg=audit(1574867053.120:84665): prog-id=76 op=UNLOAD
      ...
    Signed-off-by: NDaniel Borkmann <daniel@iogearbox.net>
    Co-developed-by: NJiri Olsa <jolsa@kernel.org>
    Signed-off-by: NJiri Olsa <jolsa@kernel.org>
    Acked-by: NPaul Moore <paul@paul-moore.com>
    Link: https://lore.kernel.org/bpf/20191206214934.11319-1-jolsa@kernel.org
    bae141f5
audit.h 20.4 KB