On 06/20/2013 11:02 AM, Gao feng wrote:
If we don't tie audit to user namespace, there is still one
problem.
One more problem. some audit messages are generated by some net subsystem
such as netfilter. If we don't tie audit to user namespace, we have no
idea where these audit messages should go. there is no relationship between
net namespace and audit namespace while we can get user namespace through
net user namespace.