Searched refs:filterkey (Results 1 – 7 of 7) sorted by relevance
/linux-4.4.14/kernel/ |
D | auditfilter.c | 104 kfree(erule->filterkey); in audit_free_rule() 541 if (entry->rule.filterkey || f->val > AUDIT_MAX_KEY_LEN) in audit_data_to_entry() 547 entry->rule.filterkey = str; in audit_data_to_entry() 643 audit_pack_string(&bufp, krule->filterkey); in audit_krule_to_data() 709 if (strcmp(a->filterkey, b->filterkey)) in audit_compare_rule() 834 fk = kstrdup(old->filterkey, GFP_KERNEL); in audit_dupe_rule() 838 new->filterkey = fk; in audit_dupe_rule() 1079 audit_log_key(ab, rule->filterkey); in audit_log_rule_change()
|
D | auditsc.c | 691 if (rule->filterkey) { in audit_filter_rules() 692 kfree(ctx->filterkey); in audit_filter_rules() 693 ctx->filterkey = kstrdup(rule->filterkey, GFP_ATOMIC); in audit_filter_rules() 718 *key = kstrdup(e->rule.filterkey, GFP_ATOMIC); in audit_filter_task() 940 context->filterkey = key; in audit_alloc() 953 kfree(context->filterkey); in audit_free_context() 1355 audit_log_key(ab, context->filterkey); in audit_log_exit() 1577 kfree(context->filterkey); in __audit_syscall_exit() 1578 context->filterkey = NULL; in __audit_syscall_exit()
|
D | audit_fsnotify.c | 139 audit_log_key(ab, rule->filterkey); in audit_mark_log_rule_change()
|
D | audit.h | 130 char *filterkey; /* key for rule that triggered record */ member
|
D | audit_watch.c | 250 audit_log_key(ab, r->filterkey); in audit_watch_log_rule_change()
|
D | audit_tree.c | 465 audit_log_key(ab, rule->filterkey); in audit_tree_log_remove_rule()
|
/linux-4.4.14/include/linux/ |
D | audit.h | 59 char *filterkey; /* ties events to rules */ member
|