summaryrefslogtreecommitdiffstats
path: root/kernel
diff options
context:
space:
mode:
authorEric Paris <eparis@redhat.com>2012-01-03 20:23:08 +0100
committerAl Viro <viro@zeniv.linux.org.uk>2012-01-17 22:17:02 +0100
commitc9fe685f7a17a0ee8bf3fbe51e40b1c8b8e65896 (patch)
tree510a09bc02c5dccb7ef83c88f2a00546b17e2c17 /kernel
parentaudit: complex interfield comparison helper (diff)
downloadlinux-c9fe685f7a17a0ee8bf3fbe51e40b1c8b8e65896.tar.xz
linux-c9fe685f7a17a0ee8bf3fbe51e40b1c8b8e65896.zip
audit: allow interfield comparison between gid and ogid
Allow audit rules to compare the gid of the running task to the gid of the inode in question. Signed-off-by: Eric Paris <eparis@redhat.com>
Diffstat (limited to 'kernel')
-rw-r--r--kernel/auditsc.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/kernel/auditsc.c b/kernel/auditsc.c
index b12cc32fe377..861c7b9c565a 100644
--- a/kernel/auditsc.c
+++ b/kernel/auditsc.c
@@ -474,6 +474,8 @@ static int audit_compare_id(uid_t uid1,
uid_t uid2;
int rc;
+ BUILD_BUG_ON(sizeof(uid_t) != sizeof(gid_t));
+
if (name) {
addr = (unsigned long)name;
addr += name_offset;
@@ -510,6 +512,10 @@ static int audit_field_compare(struct task_struct *tsk,
return audit_compare_id(cred->uid,
name, offsetof(struct audit_names, uid),
f, ctx);
+ case AUDIT_COMPARE_GID_TO_OBJ_GID:
+ return audit_compare_id(cred->gid,
+ name, offsetof(struct audit_names, gid),
+ f, ctx);
default:
WARN(1, "Missing AUDIT_COMPARE define. Report as a bug\n");
return 0;