• E
    audit: fix event coverage of AUDIT_ANOM_LINK · b24a30a7
    Eric Paris 提交于
    The userspace audit tools didn't like the existing formatting of the
    AUDIT_ANOM_LINK event. It needed to be expanded to emit an AUDIT_PATH
    event as well, so this implements the change. The bulk of the patch is
    moving code out of auditsc.c into audit.c and audit.h for general use.
    It expands audit_log_name to include an optional "struct path" argument
    for the simple case of just needing to report a pathname. This also
    makes
    audit_log_task_info available when syscall auditing is not enabled,
    since
    it is needed in either case for process details.
    Signed-off-by: NKees Cook <keescook@chromium.org>
    Reported-by: NSteve Grubb <sgrubb@redhat.com>
    b24a30a7
audit.c 44.7 KB