Closed pcmoore closed 7 years ago
The auditd_reset() function, used to break the kernel/auditd connection, flushes the main backlog queue to the hold queue and in doing so bypasses the multicast send in kauditd_thread.
Upstream patch posted:
Resolved via cd33f5f2cbfaadc21270f3ddac7c3c33e0a1a28c.
The auditd_reset() function, used to break the kernel/auditd connection, flushes the main backlog queue to the hold queue and in doing so bypasses the multicast send in kauditd_thread.