/* AUDIT_NAMES is the number of slots we reserve in the audit_context *forsavingnamesfromgetname().Ifwegetmorenameswewillallocate
* a name dynamically and also add those to the list anchored by names_list. */ #define AUDIT_NAMES 5
/* At task start time, the audit_state is set in the audit_context using aper-taskfilter.Atsyscallentry,theaudit_stateisaugmentedby
the syscall filter. */ enum audit_state {
AUDIT_STATE_DISABLED, /* Do not create per-task audit_context. *Nosyscall-specificauditrecordscan
* be generated. */
AUDIT_STATE_BUILD, /* Create the per-task audit_context, *andfillitinatsyscall *entrytime.Thismakesafull *syscallrecordavailableifsome *otherpartofthekerneldecidesit
* should be recorded. */
AUDIT_STATE_RECORD /* Create the per-task audit_context, *alwaysfillitinatsyscallentry *time,andalwayswriteouttheaudit
* record at syscall exit time. */
};
struct audit_cap_data {
kernel_cap_t permitted;
kernel_cap_t inheritable; union { unsignedint fE; /* effective bit of file cap */
kernel_cap_t effective; /* effective set of process */
};
kernel_cap_t ambient;
kuid_t rootid;
};
/* When fs/namei.c:getname() is called, we store the pointer in name and bump *therefcntintheassociatedfilenamestruct. * *Further,infs/namei.c:path_lookup()westoretheinodeanddevice.
*/ struct audit_names { struct list_head list; /* audit_context->names_list */
struct filename *name; int name_len; /* number of chars to log */ bool hidden; /* don't log this record */
struct audit_proctitle { int len; /* length of the cmdline field. */ char *value; /* the cmdline field */
};
/* The per-task audit context. */ struct audit_context { int dummy; /* must be the first element */ enum {
AUDIT_CTX_UNUSED, /* audit_context is currently unused */
AUDIT_CTX_SYSCALL, /* in use by syscall */
AUDIT_CTX_URING, /* in use by io_uring */
} context; enum audit_state state, current_state; unsignedint serial; /* serial number for record */ int major; /* syscall number */ int uring_op; /* uring operation */ struct timespec64 ctime; /* time of syscall entry */ unsignedlong argv[4]; /* syscall arguments */ long return_code;/* syscall return code */
u64 prio; int return_valid; /* return code is valid */ /* *Thenames_lististhelistofallaudit_namescollectedduringthis *syscall.ThefirstAUDIT_NAMESentriesinthenames_listwill *actuallybefromthepreallocated_namesarrayforperformance *reasons.Exceptduringallocationtheyshouldneverbereferenced *throughthepreallocated_namesarrayandshouldonlybefound/used *byrunningthenames_list.
*/ struct audit_names preallocated_names[AUDIT_NAMES]; int name_count; /* total records in names_list */ struct list_head names_list; /* struct audit_names->list anchor */ char *filterkey; /* key for rule that triggered record */ struct path pwd; struct audit_aux_data *aux; struct audit_aux_data *aux_pids; struct sockaddr_storage *sockaddr;
size_t sockaddr_len; /* Save things to print about task_struct */
pid_t ppid;
kuid_t uid, euid, suid, fsuid;
kgid_t gid, egid, sgid, fsgid; unsignedlong personality; int arch;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.