/kernel/ |
D | audit.c | 389 struct audit_buffer *ab; in audit_log_config_change() local 392 ab = audit_log_start(audit_context(), GFP_KERNEL, AUDIT_CONFIG_CHANGE); in audit_log_config_change() 393 if (unlikely(!ab)) in audit_log_config_change() 395 audit_log_format(ab, "op=set %s=%u old=%u ", function_name, new, old); in audit_log_config_change() 396 audit_log_session_info(ab); in audit_log_config_change() 397 rc = audit_log_task_context(ab); in audit_log_config_change() 400 audit_log_format(ab, " res=%d", allow_changes); in audit_log_config_change() 401 audit_log_end(ab); in audit_log_config_change() 1090 struct audit_buffer **ab, u16 msg_type) in audit_log_common_recv_msg() argument 1096 *ab = NULL; in audit_log_common_recv_msg() [all …]
|
D | auditsc.c | 988 struct audit_buffer *ab; in audit_log_pid_context() local 993 ab = audit_log_start(context, GFP_KERNEL, AUDIT_OBJ_PID); in audit_log_pid_context() 994 if (!ab) in audit_log_pid_context() 997 audit_log_format(ab, "opid=%d oauid=%d ouid=%d oses=%d", pid, in audit_log_pid_context() 1002 audit_log_format(ab, " obj=(none)"); in audit_log_pid_context() 1005 audit_log_format(ab, " obj=%s", ctx); in audit_log_pid_context() 1009 audit_log_format(ab, " ocomm="); in audit_log_pid_context() 1010 audit_log_untrustedstring(ab, comm); in audit_log_pid_context() 1011 audit_log_end(ab); in audit_log_pid_context() 1017 struct audit_buffer **ab) in audit_log_execve_info() argument [all …]
|
D | audit_fsnotify.c | 117 struct audit_buffer *ab; in audit_mark_log_rule_change() local 122 ab = audit_log_start(audit_context(), GFP_NOFS, AUDIT_CONFIG_CHANGE); in audit_mark_log_rule_change() 123 if (unlikely(!ab)) in audit_mark_log_rule_change() 125 audit_log_session_info(ab); in audit_mark_log_rule_change() 126 audit_log_format(ab, " op=%s path=", op); in audit_mark_log_rule_change() 127 audit_log_untrustedstring(ab, audit_mark->path); in audit_mark_log_rule_change() 128 audit_log_key(ab, rule->filterkey); in audit_mark_log_rule_change() 129 audit_log_format(ab, " list=%d res=1", rule->listnr); in audit_mark_log_rule_change() 130 audit_log_end(ab); in audit_mark_log_rule_change()
|
D | audit_watch.c | 228 struct audit_buffer *ab; in audit_watch_log_rule_change() local 232 ab = audit_log_start(audit_context(), GFP_NOFS, AUDIT_CONFIG_CHANGE); in audit_watch_log_rule_change() 233 if (!ab) in audit_watch_log_rule_change() 235 audit_log_session_info(ab); in audit_watch_log_rule_change() 236 audit_log_format(ab, "op=%s path=", op); in audit_watch_log_rule_change() 237 audit_log_untrustedstring(ab, w->path); in audit_watch_log_rule_change() 238 audit_log_key(ab, r->filterkey); in audit_watch_log_rule_change() 239 audit_log_format(ab, " list=%d res=1", r->listnr); in audit_watch_log_rule_change() 240 audit_log_end(ab); in audit_watch_log_rule_change()
|
D | audit_tree.c | 528 struct audit_buffer *ab; in audit_tree_log_remove_rule() local 532 ab = audit_log_start(context, GFP_KERNEL, AUDIT_CONFIG_CHANGE); in audit_tree_log_remove_rule() 533 if (unlikely(!ab)) in audit_tree_log_remove_rule() 535 audit_log_format(ab, "op=remove_rule dir="); in audit_tree_log_remove_rule() 536 audit_log_untrustedstring(ab, rule->tree->pathname); in audit_tree_log_remove_rule() 537 audit_log_key(ab, rule->filterkey); in audit_tree_log_remove_rule() 538 audit_log_format(ab, " list=%d res=1", rule->listnr); in audit_tree_log_remove_rule() 539 audit_log_end(ab); in audit_tree_log_remove_rule()
|
D | auditfilter.c | 1100 struct audit_buffer *ab; in audit_log_rule_change() local 1105 ab = audit_log_start(audit_context(), GFP_KERNEL, AUDIT_CONFIG_CHANGE); in audit_log_rule_change() 1106 if (!ab) in audit_log_rule_change() 1108 audit_log_session_info(ab); in audit_log_rule_change() 1109 audit_log_task_context(ab); in audit_log_rule_change() 1110 audit_log_format(ab, " op=%s", action); in audit_log_rule_change() 1111 audit_log_key(ab, rule->filterkey); in audit_log_rule_change() 1112 audit_log_format(ab, " list=%d res=%d", rule->listnr, res); in audit_log_rule_change() 1113 audit_log_end(ab); in audit_log_rule_change()
|
D | audit.h | 205 extern void audit_log_session_info(struct audit_buffer *ab); 247 extern void audit_log_d_path_exe(struct audit_buffer *ab,
|
/kernel/bpf/ |
D | syscall.c | 1644 struct audit_buffer *ab; in bpf_audit_prog() local 1652 ab = audit_log_start(ctx, GFP_ATOMIC, AUDIT_BPF); in bpf_audit_prog() 1653 if (unlikely(!ab)) in bpf_audit_prog() 1655 audit_log_format(ab, "prog-id=%u op=%s", in bpf_audit_prog() 1657 audit_log_end(ab); in bpf_audit_prog()
|