summaryrefslogtreecommitdiffstats
path: root/logd/tests/Android.mk
diff options
context:
space:
mode:
authorMark Salyzyn <salyzyn@google.com>2017-01-03 14:00:19 -0800
committerMark Salyzyn <salyzyn@google.com>2017-01-04 14:46:58 -0800
commit247d682fe1b0dd4c8f149b7f5c89c546df17873a (patch)
treed11ddcf98311274cb4612f41b506ebbc9c0b4a3b /logd/tests/Android.mk
parentfe05f1cde4fd812bbb20a39d37ee7be6b95402c3 (diff)
downloadcore-247d682fe1b0dd4c8f149b7f5c89c546df17873a.tar.gz
core-247d682fe1b0dd4c8f149b7f5c89c546df17873a.tar.bz2
core-247d682fe1b0dd4c8f149b7f5c89c546df17873a.zip
logd: sepolicy dynamic rate limiting
Processing overhead for selinux violation messages is costly. We want to deal with bursts of violations, but we have no intent of allowing that sustained burst to go unabated as there is a cost of processing and battery usage. Tunables in libaudit.h are: AUDIT_RATE_LIMIT_DEFAULT 20 /* acceptable burst rate */ AUDIT_RATE_LIMIT_BURST_DURATION 10 /* number of seconds of burst */ AUDIT_RATE_LIMIT_MAX 5 /* acceptable sustained rate */ Since we can only asymptotically handle DEFAULT rate, we set an upper threshold of half way between the MAX and DEFAULT rate. Default kernel audit subsystem message rate is set to 20 a second. If sepolicy exceeds 125 violation messages over up to ten seconds (>=~12/s), tell kernel audit subsystem to drop the rate to 5 messages a second. If rate drops below 50 messages over the past ten seconds (<5/s), tell kernel it is ok to increase the burst rate back to 20 messages a second. Test: gTest logd-unit-tests --gtest_filter=logd.sepolicy_rate_limiter_* Bug: 27878170 Change-Id: I843f8dcfbb3ecfbbe94a4865ea332c858e3be7f2
Diffstat (limited to 'logd/tests/Android.mk')
-rw-r--r--logd/tests/Android.mk5
1 files changed, 4 insertions, 1 deletions
diff --git a/logd/tests/Android.mk b/logd/tests/Android.mk
index 808087a9b..c05399336 100644
--- a/logd/tests/Android.mk
+++ b/logd/tests/Android.mk
@@ -27,12 +27,15 @@ test_tags := tests
# Unit tests.
# -----------------------------------------------------------------------------
+event_flag := -DAUDITD_LOG_TAG=1003 -DCHATTY_LOG_TAG=1004
+
test_c_flags := \
-fstack-protector-all \
-g \
-Wall -Wextra \
-Werror \
-fno-builtin \
+ $(event_flag)
test_src_files := \
logd_test.cpp
@@ -43,6 +46,6 @@ include $(CLEAR_VARS)
LOCAL_MODULE := $(test_module_prefix)unit-tests
LOCAL_MODULE_TAGS := $(test_tags)
LOCAL_CFLAGS += $(test_c_flags)
-LOCAL_SHARED_LIBRARIES := libbase libcutils liblog
+LOCAL_SHARED_LIBRARIES := libbase libcutils liblog libselinux
LOCAL_SRC_FILES := $(test_src_files)
include $(BUILD_NATIVE_TEST)