diff options
author | Amy Griffis <amy.griffis@hp.com> | 2006-06-15 00:45:21 +0200 |
---|---|---|
committer | Al Viro <viro@zeniv.linux.org.uk> | 2006-07-01 11:43:06 +0200 |
commit | 5adc8a6adc91c4c85a64c75a70a619fffc924817 (patch) | |
tree | ace9af6bbc3cf711f43cfd88e834baeb6989ca3f /security/selinux | |
parent | Merge master.kernel.org:/pub/scm/linux/kernel/git/davem/sparc-2.6 (diff) | |
download | linux-5adc8a6adc91c4c85a64c75a70a619fffc924817.tar.xz linux-5adc8a6adc91c4c85a64c75a70a619fffc924817.zip |
[PATCH] add rule filterkey
Add support for a rule key, which can be used to tie audit records to audit
rules. This is useful when a watched file is accessed through a link or
symlink, as well as for general audit log analysis.
Because this patch uses a string key instead of an integer key, there is a bit
of extra overhead to do the kstrdup() when a rule fires. However, we're also
allocating memory for the audit record buffer, so it's probably not that
significant. I went ahead with a string key because it seems more
user-friendly.
Note that the user must ensure that filterkeys are unique. The kernel only
checks for duplicate rules.
Signed-off-by: Amy Griffis <amy.griffis@hpd.com>
Diffstat (limited to 'security/selinux')
0 files changed, 0 insertions, 0 deletions