Searched refs:krule (Results 1 – 9 of 9) sorted by relevance
/Linux-v5.15/kernel/ |
D | audit_watch.c | 178 int audit_to_watch(struct audit_krule *krule, char *path, int len, u32 op) in audit_to_watch() argument 186 krule->listnr != AUDIT_FILTER_EXIT || in audit_to_watch() 188 krule->inode_f || krule->watch || krule->tree) in audit_to_watch() 195 krule->watch = watch; in audit_to_watch() 364 static void audit_add_to_parent(struct audit_krule *krule, in audit_add_to_parent() argument 367 struct audit_watch *w, *watch = krule->watch; in audit_add_to_parent() 382 krule->watch = watch = w; in audit_add_to_parent() 394 list_add(&krule->rlist, &watch->rules); in audit_add_to_parent() 399 int audit_add_watch(struct audit_krule *krule, struct list_head **list) in audit_add_watch() argument 401 struct audit_watch *watch = krule->watch; in audit_add_watch() [all …]
|
D | auditfilter.c | 151 static inline int audit_to_inode(struct audit_krule *krule, in audit_to_inode() argument 154 if (krule->listnr != AUDIT_FILTER_EXIT || in audit_to_inode() 155 krule->inode_f || krule->watch || krule->tree || in audit_to_inode() 159 krule->inode_f = f; in audit_to_inode() 626 static struct audit_rule_data *audit_krule_to_data(struct audit_krule *krule) in audit_krule_to_data() argument 632 data = kmalloc(sizeof(*data) + krule->buflen, GFP_KERNEL); in audit_krule_to_data() 637 data->flags = krule->flags | krule->listnr; in audit_krule_to_data() 638 data->action = krule->action; in audit_krule_to_data() 639 data->field_count = krule->field_count; in audit_krule_to_data() 642 struct audit_field *f = &krule->fields[i]; in audit_krule_to_data() [all …]
|
D | audit_fsnotify.c | 74 struct audit_fsnotify_mark *audit_alloc_mark(struct audit_krule *krule, char *pathname, int len) in audit_alloc_mark() argument 101 audit_mark->rule = krule; in audit_alloc_mark() 138 void audit_remove_mark_rule(struct audit_krule *krule) in audit_remove_mark_rule() argument 140 struct audit_fsnotify_mark *mark = krule->exe; in audit_remove_mark_rule()
|
D | audit.h | 260 extern int audit_to_watch(struct audit_krule *krule, char *path, int len, 262 extern int audit_add_watch(struct audit_krule *krule, struct list_head **list); 263 extern void audit_remove_watch_rule(struct audit_krule *krule); 268 extern struct audit_fsnotify_mark *audit_alloc_mark(struct audit_krule *krule, 272 extern void audit_remove_mark_rule(struct audit_krule *krule);
|
/Linux-v5.15/security/selinux/include/ |
D | audit.h | 54 int selinux_audit_rule_known(struct audit_krule *krule);
|
/Linux-v5.15/include/linux/ |
D | security.h | 1884 int security_audit_rule_known(struct audit_krule *krule); 1896 static inline int security_audit_rule_known(struct audit_krule *krule) in security_audit_rule_known() argument
|
D | lsm_hook_defs.h | 381 LSM_HOOK(int, 0, audit_rule_known, struct audit_krule *krule)
|
/Linux-v5.15/security/ |
D | security.c | 2549 int security_audit_rule_known(struct audit_krule *krule) in security_audit_rule_known() argument 2551 return call_int_hook(audit_rule_known, 0, krule); in security_audit_rule_known()
|
/Linux-v5.15/security/smack/ |
D | smack_lsm.c | 4484 static int smack_audit_rule_known(struct audit_krule *krule) in smack_audit_rule_known() argument 4489 for (i = 0; i < krule->field_count; i++) { in smack_audit_rule_known() 4490 f = &krule->fields[i]; in smack_audit_rule_known()
|