| /Linux-v5.15/security/ | 
| D | lsm_audit.c | 189 		audit_log_format(ab, " %s=%pI6c", name1, addr);  in print_ipv6_addr() 191 		audit_log_format(ab, " %s=%d", name2, ntohs(port));  in print_ipv6_addr() 198 		audit_log_format(ab, " %s=%pI4", name1, &addr);  in print_ipv4_addr() 200 		audit_log_format(ab, " %s=%d", name2, ntohs(port));  in print_ipv4_addr() 220 	audit_log_format(ab, " pid=%d comm=", task_tgid_nr(current));  in dump_common_audit_data() 227 		audit_log_format(ab, " key=%d ", a->u.ipc_id);  in dump_common_audit_data() 230 		audit_log_format(ab, " capability=%d ", a->u.cap);  in dump_common_audit_data() 239 			audit_log_format(ab, " dev=");  in dump_common_audit_data() 241 			audit_log_format(ab, " ino=%lu", inode->i_ino);  in dump_common_audit_data() 252 			audit_log_format(ab, " dev=");  in dump_common_audit_data() [all …] 
 | 
| /Linux-v5.15/security/apparmor/ | 
| D | mount.c | 30 		audit_log_format(ab, "ro");  in audit_mnt_flags() 32 		audit_log_format(ab, "rw");  in audit_mnt_flags() 34 		audit_log_format(ab, ", nosuid");  in audit_mnt_flags() 36 		audit_log_format(ab, ", nodev");  in audit_mnt_flags() 38 		audit_log_format(ab, ", noexec");  in audit_mnt_flags() 40 		audit_log_format(ab, ", sync");  in audit_mnt_flags() 42 		audit_log_format(ab, ", remount");  in audit_mnt_flags() 44 		audit_log_format(ab, ", mand");  in audit_mnt_flags() 46 		audit_log_format(ab, ", dirsync");  in audit_mnt_flags() 48 		audit_log_format(ab, ", noatime");  in audit_mnt_flags() [all …] 
 | 
| D | audit.c | 60 		audit_log_format(ab, "apparmor=\"%s\"",  in audit_pre() 65 		audit_log_format(ab, " operation=\"%s\"", aad(sa)->op);  in audit_pre() 69 		audit_log_format(ab, " info=\"%s\"", aad(sa)->info);  in audit_pre() 71 			audit_log_format(ab, " error=%d", aad(sa)->error);  in audit_pre() 81 				audit_log_format(ab, " namespace=");  in audit_pre() 85 			audit_log_format(ab, " profile=");  in audit_pre() 88 			audit_log_format(ab, " label=");  in audit_pre() 95 		audit_log_format(ab, " name=");  in audit_pre()
  | 
| D | ipc.c | 48 		audit_log_format(ab, " requested_mask=\"%s\"",  in audit_ptrace_cb() 52 			audit_log_format(ab, " denied_mask=\"%s\"",  in audit_ptrace_cb() 56 	audit_log_format(ab, " peer=");  in audit_ptrace_cb() 167 		audit_log_format(ab, " requested_mask=\"%s\"",  in audit_signal_cb() 170 			audit_log_format(ab, " denied_mask=\"%s\"",  in audit_signal_cb() 175 		audit_log_format(ab, "signal=unknown(%d)",  in audit_signal_cb() 178 		audit_log_format(ab, " signal=%s", sig_names[aad(sa)->signal]);  in audit_signal_cb() 180 		audit_log_format(ab, " signal=rtmin+%d",  in audit_signal_cb() 182 	audit_log_format(ab, " peer=");  in audit_signal_cb()
  | 
| D | net.c | 76 		audit_log_format(ab, " family=\"%s\"",  in audit_net_cb() 79 		audit_log_format(ab, " family=\"unknown(%d)\"",  in audit_net_cb() 82 		audit_log_format(ab, " sock_type=\"%s\"",  in audit_net_cb() 85 		audit_log_format(ab, " sock_type=\"unknown(%d)\"",  in audit_net_cb() 87 	audit_log_format(ab, " protocol=%d", aad(sa)->net.protocol);  in audit_net_cb() 90 		audit_log_format(ab, " requested_mask=");  in audit_net_cb() 95 			audit_log_format(ab, " denied_mask=");  in audit_net_cb() 101 		audit_log_format(ab, " peer=");  in audit_net_cb()
  | 
| D | lib.c | 230 			audit_log_format(ab, fmt, names[i]);  in aa_audit_perm_names() 244 	audit_log_format(ab, "\"");  in aa_audit_perm_mask() 248 		audit_log_format(ab, "%s", str);  in aa_audit_perm_mask() 250 			audit_log_format(ab, " ");  in aa_audit_perm_mask() 254 	audit_log_format(ab, "\"");  in aa_audit_perm_mask() 267 		audit_log_format(ab, " requested_mask=");  in aa_audit_perms_cb() 273 		audit_log_format(ab, "denied_mask=");  in aa_audit_perms_cb() 278 	audit_log_format(ab, " peer=");  in aa_audit_perms_cb()
  | 
| D | file.c | 53 		audit_log_format(ab, " requested_mask=\"%s\"", str);  in file_audit_cb() 58 		audit_log_format(ab, " denied_mask=\"%s\"", str);  in file_audit_cb() 61 		audit_log_format(ab, " fsuid=%d",  in file_audit_cb() 63 		audit_log_format(ab, " ouid=%d",  in file_audit_cb() 68 		audit_log_format(ab, " target=");  in file_audit_cb() 72 		audit_log_format(ab, " target=");  in file_audit_cb()
  | 
| D | resource.c | 34 	audit_log_format(ab, " rlimit=%s value=%lu",  in audit_cb() 37 		audit_log_format(ab, " peer=");  in audit_cb()
  | 
| D | capability.c | 48 	audit_log_format(ab, " capname=");  in audit_cb()
  | 
| /Linux-v5.15/security/integrity/ | 
| D | integrity_audit.c | 48 	audit_log_format(ab, "pid=%d uid=%u auid=%u ses=%u",  in integrity_audit_message() 54 	audit_log_format(ab, " op=%s cause=%s comm=", op, cause);  in integrity_audit_message() 57 		audit_log_format(ab, " name=");  in integrity_audit_message() 61 		audit_log_format(ab, " dev=");  in integrity_audit_message() 63 		audit_log_format(ab, " ino=%lu", inode->i_ino);  in integrity_audit_message() 65 	audit_log_format(ab, " res=%d errno=%d", !result, errno);  in integrity_audit_message()
  | 
| /Linux-v5.15/kernel/ | 
| D | auditsc.c | 1002 	audit_log_format(ab, "opid=%d oauid=%d ouid=%d oses=%d", pid,  in audit_log_pid_context() 1007 			audit_log_format(ab, " obj=(none)");  in audit_log_pid_context() 1010 			audit_log_format(ab, " obj=%s", ctx);  in audit_log_pid_context() 1014 	audit_log_format(ab, " ocomm=");  in audit_log_pid_context() 1058 	audit_log_format(*ab, "argc=%d", context->execve.argc);  in audit_log_execve_info() 1157 			audit_log_format(*ab, "%s", abuf);  in audit_log_execve_info() 1201 		audit_log_format(ab, " %s=0", prefix);  in audit_log_cap() 1204 	audit_log_format(ab, " %s=", prefix);  in audit_log_cap() 1206 		audit_log_format(ab, "%08x", cap->cap[CAP_LAST_U32 - i]);  in audit_log_cap() 1212 		audit_log_format(ab, " cap_fe=? cap_fver=? cap_fp=? cap_fi=?");  in audit_log_fcaps() [all …] 
 | 
| D | audit.c | 395 	audit_log_format(ab, "op=set %s=%u old=%u ", function_name, new, old);  in audit_log_config_change() 400 	audit_log_format(ab, " res=%d", allow_changes);  in audit_log_config_change() 1070 	audit_log_format(*ab, "pid=%d uid=%u ", pid, uid);  in audit_log_common_recv_msg() 1110 	audit_log_format(ab, " feature=%s old=%u new=%u old_lock=%u new_lock=%u res=%d",  in audit_log_feature_change() 1366 				audit_log_format(ab, " msg='%.*s'",  in audit_receive_msg() 1370 				audit_log_format(ab, " data=");  in audit_receive_msg() 1385 			audit_log_format(ab, " op=%s audit_enabled=%d res=0",  in audit_receive_msg() 1401 		audit_log_format(ab, " op=trim res=1");  in audit_receive_msg() 1432 		audit_log_format(ab, " op=make_equiv old=");  in audit_receive_msg() 1434 		audit_log_format(ab, " new=");  in audit_receive_msg() [all …] 
 | 
| D | audit_fsnotify.c | 125 	audit_log_format(ab, " op=%s path=", op);  in audit_mark_log_rule_change() 128 	audit_log_format(ab, " list=%d res=1", rule->listnr);  in audit_mark_log_rule_change()
  | 
| /Linux-v5.15/net/netlabel/ | 
| D | netlabel_addrlist.c | 318 		audit_log_format(audit_buf, " netif=%s", dev);  in netlbl_af4list_audit_addr() 319 	audit_log_format(audit_buf, " %s=%pI4", dir, &addr);  in netlbl_af4list_audit_addr() 326 		audit_log_format(audit_buf, " %s_prefixlen=%d", dir, mask_len);  in netlbl_af4list_audit_addr() 352 		audit_log_format(audit_buf, " netif=%s", dev);  in netlbl_af6list_audit_addr() 353 	audit_log_format(audit_buf, " %s=%pI6", dir, addr);  in netlbl_af6list_audit_addr() 365 		audit_log_format(audit_buf, " %s_prefixlen=%d", dir, mask_len);  in netlbl_af6list_audit_addr()
  | 
| D | netlabel_user.c | 97 	audit_log_format(audit_buf, "netlabel: auid=%u ses=%u",  in netlbl_audit_start_common() 105 		audit_log_format(audit_buf, " subj=%s", secctx);  in netlbl_audit_start_common()
  | 
| D | netlabel_domainhash.c | 221 		audit_log_format(audit_buf, " nlbl_domain=%s",  in netlbl_domhsh_audit_add() 246 			audit_log_format(audit_buf, " nlbl_protocol=unlbl");  in netlbl_domhsh_audit_add() 250 			audit_log_format(audit_buf,  in netlbl_domhsh_audit_add() 256 			audit_log_format(audit_buf,  in netlbl_domhsh_audit_add() 261 		audit_log_format(audit_buf, " res=%u", result == 0 ? 1 : 0);  in netlbl_domhsh_audit_add() 614 		audit_log_format(audit_buf,  in netlbl_domhsh_remove_entry()
  | 
| D | netlabel_unlabeled.c | 444 			audit_log_format(audit_buf, " sec_obj=%s", secctx);  in netlbl_unlhsh_add() 447 		audit_log_format(audit_buf, " res=%u", ret_val == 0 ? 1 : 0);  in netlbl_unlhsh_add() 499 			audit_log_format(audit_buf, " sec_obj=%s", secctx);  in netlbl_unlhsh_remove_addr4() 502 		audit_log_format(audit_buf, " res=%u", entry != NULL ? 1 : 0);  in netlbl_unlhsh_remove_addr4() 559 			audit_log_format(audit_buf, " sec_obj=%s", secctx);  in netlbl_unlhsh_remove_addr6() 562 		audit_log_format(audit_buf, " res=%u", entry != NULL ? 1 : 0);  in netlbl_unlhsh_remove_addr6() 744 		audit_log_format(audit_buf,  in netlbl_unlabel_acceptflg_set()
  | 
| /Linux-v5.15/net/netfilter/ | 
| D | xt_AUDIT.c | 40 	audit_log_format(ab, " saddr=%pI4 daddr=%pI4 proto=%hhu",  in audit_ip4() 60 	audit_log_format(ab, " saddr=%pI6c daddr=%pI6c proto=%hhu",  in audit_ip6() 78 	audit_log_format(ab, "mark=%#x", skb->mark);  in audit_tg() 100 		audit_log_format(ab, " saddr=? daddr=? proto=-1");  in audit_tg()
  | 
| D | nft_log.c | 38 	audit_log_format(ab, " saddr=%pI4 daddr=%pI4 proto=%hhu",  in audit_ip4() 58 	audit_log_format(ab, " saddr=%pI6c daddr=%pI6c proto=%hhu",  in audit_ip6() 77 	audit_log_format(ab, "mark=%#x", skb->mark);  in nft_log_eval_audit() 99 		audit_log_format(ab, " saddr=? daddr=? proto=-1");  in nft_log_eval_audit()
  | 
| /Linux-v5.15/security/selinux/ | 
| D | avc.c | 672 	audit_log_format(ab, "avc:  %s ", sad->denied ? "denied" : "granted");  in avc_audit_pre_callback() 675 		audit_log_format(ab, " null");  in avc_audit_pre_callback() 681 	audit_log_format(ab, " {");  in avc_audit_pre_callback() 686 			audit_log_format(ab, " %s", perms[i]);  in avc_audit_pre_callback() 694 		audit_log_format(ab, " 0x%x", av);  in avc_audit_pre_callback() 696 	audit_log_format(ab, " } for ");  in avc_audit_pre_callback() 719 		audit_log_format(ab, " ssid=%d", sad->ssid);  in avc_audit_post_callback() 721 		audit_log_format(ab, " scontext=%s", scontext);  in avc_audit_post_callback() 726 		audit_log_format(ab, " tsid=%d", sad->tsid);  in avc_audit_post_callback() 728 		audit_log_format(ab, " tcontext=%s", tcontext);  in avc_audit_post_callback() [all …] 
 | 
| /Linux-v5.15/security/smack/ | 
| D | smack_access.c | 315 	audit_log_format(ab, "lsm=SMACK fn=%s action=%s",  in smack_log_callback() 318 	audit_log_format(ab, " subject=");  in smack_log_callback() 320 	audit_log_format(ab, " object=");  in smack_log_callback() 323 		audit_log_format(ab, " labels_differ");  in smack_log_callback() 325 		audit_log_format(ab, " requested=%s", sad->request);  in smack_log_callback()
  | 
| /Linux-v5.15/security/integrity/evm/ | 
| D | evm_secfs.c | 222 	audit_log_format(ab, "xattr=");  in evm_write_xattrs() 267 	audit_log_format(ab, " res=0");  in evm_write_xattrs() 271 	audit_log_format(ab, " res=%d", (err < 0) ? err : 0);  in evm_write_xattrs()
  | 
| /Linux-v5.15/drivers/tty/ | 
| D | tty_audit.c | 74 		audit_log_format(ab, "%s pid=%u uid=%u auid=%u ses=%u major=%d"  in tty_audit_log() 79 		audit_log_format(ab, " data=");  in tty_audit_log()
  | 
| /Linux-v5.15/security/integrity/ima/ | 
| D | ima_api.c | 368 	audit_log_format(ab, "file=");  in ima_audit_measurement() 370 	audit_log_format(ab, " hash=\"%s:%s\"", algo_name, hash);  in ima_audit_measurement()
  | 
| /Linux-v5.15/net/xfrm/ | 
| D | xfrm_state.c | 2756 		audit_log_format(audit_buf, " sec_alg=%u sec_doi=%u sec_obj=%s",  in xfrm_audit_helper_sainfo() 2761 		audit_log_format(audit_buf, " src=%pI4 dst=%pI4",  in xfrm_audit_helper_sainfo() 2765 		audit_log_format(audit_buf, " src=%pI6 dst=%pI6",  in xfrm_audit_helper_sainfo() 2770 	audit_log_format(audit_buf, " spi=%u(0x%x)", spi, spi);  in xfrm_audit_helper_sainfo() 2782 		audit_log_format(audit_buf, " src=%pI4 dst=%pI4",  in xfrm_audit_helper_pktinfo() 2787 		audit_log_format(audit_buf,  in xfrm_audit_helper_pktinfo() 2806 	audit_log_format(audit_buf, " res=%u", result);  in xfrm_audit_state_add() 2820 	audit_log_format(audit_buf, " res=%u", result);  in xfrm_audit_state_delete() 2838 	audit_log_format(audit_buf, " spi=%u(0x%x)", spi, spi);  in xfrm_audit_state_replay_overflow() 2854 	audit_log_format(audit_buf, " spi=%u(0x%x) seqno=%u",  in xfrm_audit_state_replay() [all …] 
 |