diff options
author | Eric Paris <eparis@redhat.com> | 2012-01-03 14:23:07 -0500 |
---|---|---|
committer | Al Viro <viro@zeniv.linux.org.uk> | 2012-01-17 16:16:59 -0500 |
commit | efaffd6e4417860c67576ac760dd6e8bbd15f006 (patch) | |
tree | a59ee886b609bbf761fb75744e5e468264c67ab5 /include/linux/audit.h | |
parent | 6422e78de6880c66a82af512d9bd0c85eb62e661 (diff) |
audit: allow matching on obj_uid
Allow syscall exit filter matching based on the uid of the owner of an
inode used in a syscall. aka:
auditctl -a always,exit -S open -F obj_uid=0 -F perm=wa
Signed-off-by: Eric Paris <eparis@redhat.com>
Diffstat (limited to 'include/linux/audit.h')
-rw-r--r-- | include/linux/audit.h | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/include/linux/audit.h b/include/linux/audit.h index 67b66c37a254..55cb3daaf474 100644 --- a/include/linux/audit.h +++ b/include/linux/audit.h | |||
@@ -223,6 +223,7 @@ | |||
223 | #define AUDIT_PERM 106 | 223 | #define AUDIT_PERM 106 |
224 | #define AUDIT_DIR 107 | 224 | #define AUDIT_DIR 107 |
225 | #define AUDIT_FILETYPE 108 | 225 | #define AUDIT_FILETYPE 108 |
226 | #define AUDIT_OBJ_UID 109 | ||
226 | 227 | ||
227 | #define AUDIT_ARG0 200 | 228 | #define AUDIT_ARG0 200 |
228 | #define AUDIT_ARG1 (AUDIT_ARG0+1) | 229 | #define AUDIT_ARG1 (AUDIT_ARG0+1) |