Linux Kernel  3.7.1
auditfilter.c File Reference
#include <linux/kernel.h>
#include <linux/audit.h>
#include <linux/kthread.h>
#include <linux/mutex.h>
#include <linux/fs.h>
#include <linux/namei.h>
#include <linux/netlink.h>
#include <linux/sched.h>
#include <linux/slab.h>
#include <linux/security.h>
#include "audit.h"

 DEFINE_MUTEX (audit_filter_mutex)
void audit_free_rule_rcu (struct rcu_head *head)
charaudit_unpack_string (void **bufp, size_t *remain, size_t len)
int __init audit_register_class (int class, unsigned *list)
int audit_match_class (int class, unsigned syscall)
struct audit_entryaudit_dupe_rule (struct audit_krule *old)
int audit_receive_filter (int type, int pid, int seq, void *data, size_t datasz, kuid_t loginuid, u32 sessionid, u32 sid)
int audit_comparator (u32 left, u32 op, u32 right)
int audit_uid_comparator (kuid_t left, u32 op, kuid_t right)
int audit_gid_comparator (kgid_t left, u32 op, kgid_t right)
int parent_len (const char *path)
int audit_compare_dname_path (const char *dname, const char *path, int parentlen)
int audit_filter_user (void)
int audit_filter_type (int type)
int audit_update_lsm_rules (void)


struct list_head audit_filter_list [AUDIT_NR_FILTERS]

Function Documentation

int audit_comparator ( u32  left,
u32  op,
u32  right 

int audit_compare_dname_path ( const char dname,
const char path,
int  parentlen 

audit_compare_dname_path - compare given dentry name with last component in given path. Return of 0 indicates a match. : dentry name that we're comparing : full pathname that we're comparing : length of the parent if known. Passing in AUDIT_NAME_FULL here indicates that we must compute this value.

struct audit_entry* audit_dupe_rule ( struct audit_krule old)

int audit_filter_type ( int  type)

int audit_filter_user ( void  )

void audit_free_rule_rcu ( struct rcu_head head)

int audit_gid_comparator ( kgid_t  left,
u32  op,
kgid_t  right 

int audit_match_class ( int  class,
unsigned  syscall 

int audit_receive_filter ( int  type,
int  pid,
int  seq,
void data,
size_t  datasz,
kuid_t  loginuid,
u32  sessionid,
u32  sid 

audit_receive_filter - apply all rules to the specified message type : audit message type : target pid for netlink audit messages : target uid for netlink audit messages : netlink audit message sequence (serial) number : payload data : size of payload data : loginuid of sender : sessionid for netlink audit message : SE Linux Security ID of sender

int __init audit_register_class ( int  class,
unsigned *  list 

int audit_uid_comparator ( kuid_t  left,
u32  op,
kuid_t  right 

char* audit_unpack_string ( void **  bufp,
size_t remain,
size_t  len 

int audit_update_lsm_rules ( void  )

DEFINE_MUTEX ( audit_filter_mutex  )
int parent_len ( const char path)

parent_len - find the length of the parent portion of a pathname : pathname of which to determine length

Variable Documentation

struct list_head audit_filter_list[AUDIT_NR_FILTERS]