On Wed, 2004-12-15 at 12:48, Mounir Bsaibes wrote:
So what is a better solution, just kill the process?
I have changed the subject of this reply to make it more meaningful to
this discussion and to separate it from the audit in vfs discussion.
There may not be any local process associated with the event, e.g.
SELinux can generate audit data during processing of received packets.
--
Stephen Smalley <sds(a)epoch.ncsc.mil>
National Security Agency