Hello, Richard,

 

We would like to thank you for implementing such a long-awaited feature like filtering audit events by exe name. We want to use this functionality on our systems (RHEL 6.4, kernel 2.6.32-358.11.1, audit-2.2-2) as soon as possible. Could you please provide some additional explanations of the use of your patch:

 

1. What kernel version is the patch proposed to be applied to? How much  will it take to see the one in the upstream? (just your estimations)

2. Will the upcoming updates of 2.6.32 kernel include the patch? If not, do we have any technical restrictions for backporting (on our own) this patch to our old kernel?


Sincerely,
Vitaly Isaev
software engineer
ITS Ltd., Moscow, Russia