• C
    selinux: log anon inode class name · c29722fa
    Christian Göttsche 提交于
    Log the anonymous inode class name in the security hook
    inode_init_security_anon.  This name is the key for name based type
    transitions on the anon_inode security class on creation.  Example:
    
        type=AVC msg=audit(02/16/22 22:02:50.585:216) : avc:  granted \
            { create } for  pid=2136 comm=mariadbd anonclass=[io_uring] \
            scontext=system_u:system_r:mysqld_t:s0 \
            tcontext=system_u:system_r:mysqld_iouring_t:s0 tclass=anon_inode
    
    Add a new LSM audit data type holding the inode and the class name.
    Signed-off-by: NChristian Göttsche <cgzones@googlemail.com>
    [PM: adjusted 'anonclass' to be a trusted string, cgzones approved]
    Signed-off-by: NPaul Moore <paul@paul-moore.com>
    c29722fa
lsm_audit.h 2.9 KB