Auditing Io_uring
lwn.net
lwn.net
Why can't the auditors explicitly state what needs to be auditable about io_uring? Instead of guessing and debating.
> Axboe pointed out that read and write operations are not audited when they are initiated through the older asynchronous I/O system calls. "In the past two decades, I take it that hasn't been a concern?"
And then there are the 20 years of Linux kernel history that show "audit features" being ineffective, wasteful and little more than a checklist feature.
wuh?? Audit features are used at tons of companies for data collection/ security.
Turning on and adding some "proper" filters on the audit subsystem won us the first spot in a CTF, as the early markers that "something is up" turned out to be excellent.
But if all you do with it is pipe it to your log server and ignore it? Well, then it's not really going to help you, and is only a checkbox item.
I feel that much of this disparaging on various "checklist" items is crappy half-assed semi-elitism. Checklists are _amazing_ tools for preventing accidents in many industries, everything from surgery to trains and flight use them with great success.
So why can't information security professionals use them without being derided by others in the business? Perhaps the same reason as doctors insisted that hand washing was time consuming and unnecessary, or the financial institutes that insist that oversight and auditing is unnecessary.
Seems a perfectly sensible half way point - and consistent with other IO mechanisms.
This is such a stark difference from the big tech company I work at where there are checklists from the security, privacy, performance, and maintenance teams that have to be satisfied before features can be launched.
These are already being used in many places to monitor/audit execution points not otherwise instrumented, so it's just a logical extension.
I've worked on systems that have auditing turned on. They usually have to be upsized by quite a bit to accomplish the same work. And the info generated is practically useless.
I suppose if it were a completely uninteresting feature it wouldn't end up enabled in most distros' kernel configs.
Instead of singling out a single person, I think it's more accurate to say the security community in general dropped the ball by not bringing concerns earlier to the maintainer who performed the merge(s).