• Michael Weiß's avatar
    dm: introduce audit event module for device mapper · 2cc1ae48
    Michael Weiß authored
    To be able to send auditing events to user space, we introduce a
    generic dm-audit module. It provides helper functions to emit audit
    events through the kernel audit subsystem. We claim the
    AUDIT_DM_CTRL type=1336 and AUDIT_DM_EVENT type=1337 out of the
    audit event messages range in the corresponding userspace api in
    'include/uapi/linux/audit.h' for those events.
    
    AUDIT_DM_CTRL is used to provide information about creation and
    destruction of device mapper targets which are triggered by user space
    admin control actions.
    AUDIT_DM_EVENT is used to provide information about actual errors
    during operation of the mapped device, showing e.g. integrity
    violations in audit log.
    
    Following commits to device mapper targets actually will make use of
    this to emit those events in relevant cases.
    
    The audit logs look like this if executing the following simple test:
    
     # dd if=/dev/zero of=test.img bs=1M count=1024
     # losetup -f test.img
     # integritysetup -vD format --integrity sha256 -t 32 /dev/loop0
     # integritysetup open -D /dev/loop0 --integrity sha256 integritytest
     # integritysetup status integritytest
     # integritysetup close integritytest
     # integritysetup open -D /dev/loop0 --integrity sha256 integritytest
     # integritysetup status integritytest
     # dd if=/dev/urandom of=/dev/loop0 bs=512 count=1 seek=100000
     # dd if=/dev/mapper/integritytest of=/dev/null
    
    -------------------------
    audit.log from auditd
    
    type=UNKNOWN[1336] msg=audit(1630425039.363:184): module=integrity
    op=ctr ppid=3807 pid=3819 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    type=UNKNOWN[1336] msg=audit(1630425039.471:185): module=integrity
    op=dtr ppid=3807 pid=3819 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    type=UNKNOWN[1336] msg=audit(1630425039.611:186): module=integrity
    op=ctr ppid=3807 pid=3819 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    type=UNKNOWN[1336] msg=audit(1630425054.475:187): module=integrity
    op=dtr ppid=3807 pid=3819 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    
    type=UNKNOWN[1336] msg=audit(1630425073.171:191): module=integrity
    op=ctr ppid=3807 pid=3883 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    
    type=UNKNOWN[1336] msg=audit(1630425087.239:192): module=integrity
    op=dtr ppid=3807 pid=3902 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    
    type=UNKNOWN[1336] msg=audit(1630425093.755:193): module=integrity
    op=ctr ppid=3807 pid=3906 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0
    egid=0 sgid=0 fsgid=0 tty=pts2 ses=3 comm="integritysetup"
    exe="/sbin/integritysetup" subj==unconfined dev=254:3
    error_msg='success' res=1
    
    type=UNKNOWN[1337] msg=audit(1630425112.119:194): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:195): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:196): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:197): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:198): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:199): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:200): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:201): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:202): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    type=UNKNOWN[1337] msg=audit(1630425112.119:203): module=integrity
    op=integrity-checksum dev=254:3 sector=77480 res=0
    Signed-off-by: default avatarMichael Weiß <michael.weiss@aisec.fraunhofer.de>
    Signed-off-by: Paul Moore <paul@paul-moore.com> # fix audit.h numbering
    Signed-off-by: default avatarMike Snitzer <snitzer@redhat.com>
    2cc1ae48
Makefile 3.78 KB