Files
kernel/include/linux
Amy Griffis 5adc8a6adc [PATCH] add rule filterkey
Add support for a rule key, which can be used to tie audit records to audit
rules.  This is useful when a watched file is accessed through a link or
symlink, as well as for general audit log analysis.

Because this patch uses a string key instead of an integer key, there is a bit
of extra overhead to do the kstrdup() when a rule fires.  However, we're also
allocating memory for the audit record buffer, so it's probably not that
significant.  I went ahead with a string key because it seems more
user-friendly.

Note that the user must ensure that filterkeys are unique.  The kernel only
checks for duplicate rules.

Signed-off-by: Amy Griffis <amy.griffis@hpd.com>
2006-07-01 05:43:06 -04:00
..
2006-07-01 05:43:06 -04:00
2006-06-27 17:32:38 -07:00
2006-03-28 09:16:05 -08:00
2006-06-26 09:58:36 -07:00
2006-05-08 16:32:05 -07:00
2006-06-08 15:14:23 -07:00
2006-06-23 02:07:36 -07:00
2006-03-31 12:18:54 -08:00
2006-06-30 18:20:44 +02:00
2006-06-25 10:01:19 -07:00
2006-03-26 08:56:56 -08:00
2006-06-26 09:58:34 -07:00
2006-06-27 17:32:47 -07:00
2006-06-26 01:51:23 -04:00
2006-06-20 20:24:58 -07:00
2006-06-21 12:40:49 -07:00
2006-06-23 07:43:08 -07:00
2006-06-27 01:24:15 -04:00
2006-06-05 12:29:17 -07:00
2006-06-25 10:01:13 -07:00
2006-06-29 16:58:06 -07:00
2006-06-25 06:27:31 -04:00
2006-06-25 10:01:09 -07:00
2006-06-22 15:05:56 -07:00
2006-03-27 08:44:48 -08:00
2006-05-04 06:55:12 +02:00
2006-06-28 15:54:27 -07:00
2006-06-23 07:42:49 -07:00
2006-06-25 10:01:06 -07:00
2006-06-25 10:01:06 -07:00
2006-06-25 10:01:14 -07:00
2006-06-30 11:25:38 -07:00
2006-06-27 17:32:47 -07:00
2006-06-17 21:29:55 -07:00
2006-04-02 00:08:05 -05:00
2006-06-30 14:12:10 -07:00
2006-06-30 11:25:37 -07:00
2006-03-28 09:16:05 -08:00
2006-06-23 07:43:06 -07:00
2006-06-27 17:32:47 -07:00
2006-06-26 10:51:09 -07:00
2006-03-31 12:18:56 -08:00
2006-06-30 18:25:18 +02:00
2006-06-30 11:25:36 -07:00