Skip to content

Commit

Permalink
Revert "libaudit: limit to 5 selinux denials per sec"
Browse files Browse the repository at this point in the history
The shamu instabilities continued even after throttling SELinux denials
to 5/second. 5 denials per second is too low when doing device bringup,
and there have been some complaints about lost SELinux denials. See,
for example, http://comments.gmane.org/gmane.comp.security.selinux/21941

Bring the limit back up to 20/second to prevent dropping too many
denials on the floor.

This reverts commit a15db51.

(cherrypick of commit 9667a66)

Change-Id: I05e85cce0a792d05aa557fcc614c0fc019c15014
  • Loading branch information
nickkral committed May 11, 2015
1 parent a51d8b9 commit 6de7a06
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion logd/libaudit.c
Original file line number Diff line number Diff line change
Expand Up @@ -177,7 +177,7 @@ int audit_setup(int fd, uint32_t pid)
*/
status.pid = pid;
status.mask = AUDIT_STATUS_PID | AUDIT_STATUS_RATE_LIMIT;
status.rate_limit = 5; // audit entries per second
status.rate_limit = 20; // audit entries per second

/* Let the kernel know this pid will be registering for audit events */
rc = audit_send(fd, AUDIT_SET, &status, sizeof(status));
Expand Down

0 comments on commit 6de7a06

Please sign in to comment.