Home
last modified time | relevance | path

Searched refs:krule (Results 1 – 8 of 8) sorted by relevance

/linux-4.1.27/kernel/
Daudit_watch.c189 int audit_to_watch(struct audit_krule *krule, char *path, int len, u32 op) in audit_to_watch() argument
197 krule->listnr != AUDIT_FILTER_EXIT || in audit_to_watch()
199 krule->inode_f || krule->watch || krule->tree) in audit_to_watch()
207 krule->watch = watch; in audit_to_watch()
376 static void audit_add_to_parent(struct audit_krule *krule, in audit_add_to_parent() argument
379 struct audit_watch *w, *watch = krule->watch; in audit_add_to_parent()
395 krule->watch = watch = w; in audit_add_to_parent()
405 list_add(&krule->rlist, &watch->rules); in audit_add_to_parent()
410 int audit_add_watch(struct audit_krule *krule, struct list_head **list) in audit_add_watch() argument
412 struct audit_watch *watch = krule->watch; in audit_add_watch()
[all …]
Dauditfilter.c162 static inline int audit_to_inode(struct audit_krule *krule, in audit_to_inode() argument
165 if (krule->listnr != AUDIT_FILTER_EXIT || in audit_to_inode()
166 krule->inode_f || krule->watch || krule->tree || in audit_to_inode()
170 krule->inode_f = f; in audit_to_inode()
572 static struct audit_rule_data *audit_krule_to_data(struct audit_krule *krule) in audit_krule_to_data() argument
578 data = kmalloc(sizeof(*data) + krule->buflen, GFP_KERNEL); in audit_krule_to_data()
583 data->flags = krule->flags | krule->listnr; in audit_krule_to_data()
584 data->action = krule->action; in audit_krule_to_data()
585 data->field_count = krule->field_count; in audit_krule_to_data()
588 struct audit_field *f = &krule->fields[i]; in audit_krule_to_data()
[all …]
Daudit.h267 extern int audit_to_watch(struct audit_krule *krule, char *path, int len, u32 op);
268 extern int audit_add_watch(struct audit_krule *krule, struct list_head **list);
269 extern void audit_remove_watch_rule(struct audit_krule *krule);
/linux-4.1.27/security/selinux/include/
Daudit.h62 int selinux_audit_rule_known(struct audit_krule *krule);
/linux-4.1.27/include/linux/
Dsecurity.h1753 int (*audit_rule_known) (struct audit_krule *krule);
3138 int security_audit_rule_known(struct audit_krule *krule);
3151 static inline int security_audit_rule_known(struct audit_krule *krule) in security_audit_rule_known() argument
/linux-4.1.27/security/
Dsecurity.c1475 int security_audit_rule_known(struct audit_krule *krule) in security_audit_rule_known() argument
1477 return security_ops->audit_rule_known(krule); in security_audit_rule_known()
Dcapability.c924 static int cap_audit_rule_known(struct audit_krule *krule) in cap_audit_rule_known() argument
/linux-4.1.27/security/smack/
Dsmack_lsm.c4120 static int smack_audit_rule_known(struct audit_krule *krule) in smack_audit_rule_known() argument
4125 for (i = 0; i < krule->field_count; i++) { in smack_audit_rule_known()
4126 f = &krule->fields[i]; in smack_audit_rule_known()