diff options
Diffstat (limited to 'include/linux/audit.h')
-rw-r--r-- | include/linux/audit.h | 19 |
1 files changed, 15 insertions, 4 deletions
diff --git a/include/linux/audit.h b/include/linux/audit.h index 2408cb77899c..fd65078e794a 100644 --- a/include/linux/audit.h +++ b/include/linux/audit.h | |||
@@ -33,11 +33,20 @@ | |||
33 | * 1200 - 1299 messages internal to the audit daemon | 33 | * 1200 - 1299 messages internal to the audit daemon |
34 | * 1300 - 1399 audit event messages | 34 | * 1300 - 1399 audit event messages |
35 | * 1400 - 1499 SE Linux use | 35 | * 1400 - 1499 SE Linux use |
36 | * 1500 - 1999 future use | 36 | * 1500 - 1599 kernel LSPP events |
37 | * 2000 is for otherwise unclassified kernel audit messages | 37 | * 1600 - 1699 kernel crypto events |
38 | * 1700 - 1999 future kernel use (maybe integrity labels and related events) | ||
39 | * 2000 is for otherwise unclassified kernel audit messages (legacy) | ||
40 | * 2001 - 2099 unused (kernel) | ||
41 | * 2100 - 2199 user space anomaly records | ||
42 | * 2200 - 2299 user space actions taken in response to anomalies | ||
43 | * 2300 - 2399 user space generated LSPP events | ||
44 | * 2400 - 2499 user space crypto events | ||
45 | * 2500 - 2999 future user space (maybe integrity labels and related events) | ||
38 | * | 46 | * |
39 | * Messages from 1000-1199 are bi-directional. 1200-1299 are exclusively user | 47 | * Messages from 1000-1199 are bi-directional. 1200-1299 & 2100 - 2999 are |
40 | * space. Anything over that is kernel --> user space communication. | 48 | * exclusively user space. 1300-2099 is kernel --> user space |
49 | * communication. | ||
41 | */ | 50 | */ |
42 | #define AUDIT_GET 1000 /* Get status */ | 51 | #define AUDIT_GET 1000 /* Get status */ |
43 | #define AUDIT_SET 1001 /* Set status (enable/disable/auditd) */ | 52 | #define AUDIT_SET 1001 /* Set status (enable/disable/auditd) */ |
@@ -54,6 +63,8 @@ | |||
54 | #define AUDIT_FIRST_USER_MSG 1100 /* Userspace messages mostly uninteresting to kernel */ | 63 | #define AUDIT_FIRST_USER_MSG 1100 /* Userspace messages mostly uninteresting to kernel */ |
55 | #define AUDIT_USER_AVC 1107 /* We filter this differently */ | 64 | #define AUDIT_USER_AVC 1107 /* We filter this differently */ |
56 | #define AUDIT_LAST_USER_MSG 1199 | 65 | #define AUDIT_LAST_USER_MSG 1199 |
66 | #define AUDIT_FIRST_USER_MSG2 2100 /* More user space messages */ | ||
67 | #define AUDIT_LAST_USER_MSG2 2999 | ||
57 | 68 | ||
58 | #define AUDIT_DAEMON_START 1200 /* Daemon startup record */ | 69 | #define AUDIT_DAEMON_START 1200 /* Daemon startup record */ |
59 | #define AUDIT_DAEMON_END 1201 /* Daemon normal stop record */ | 70 | #define AUDIT_DAEMON_END 1201 /* Daemon normal stop record */ |