Re: Improve init/Kconfig help descriptions [PATCH 4/9]

From: Valdis . Kletnieks
Date: Tue Feb 19 2008 - 22:43:24 EST


On Wed, 20 Feb 2008 01:38:55 +1100, Nick Andrew said:

> + Enable an auditing infrastructure that can be used with another
> + kernel subsystem, such as Security-Enhanced Linux (SELinux),
> + which requires this option for logging of AVC messages output.
> +
> + AVC refers to Access Vector Cache, a subsystem used by SELinux
> + to improve performance of the security checking by caching
> + previous access decisions.

This paragraph can be dropped, as the reasons that SELinux denial messages
are tagged with 'avc' are mostly historical. If you want to expand on anything
in here, explain that 'AVC' messages are interesting because they indicate
some sort of security rule denial. So - if you don't enable auditing,
your security messages end up in the kernel syslog. If you enable auditing,
they end up in the audit logs. Explaining *that* clearly would be a lot
more useful than explaining what avc originally stood for.. ;)

Attachment: pgp00000.pgp
Description: PGP signature