• S
    [PATCH] audit config lockdown · 6a01b07f
    Steve Grubb 提交于
    The following patch adds a new mode to the audit system. It uses the
    audit_enabled config option to introduce the idea of audit enabled, but
    configuration is immutable. Any attempt to change the configuration
    while in this mode is audited. To change the audit rules, you'd need to
    reboot the machine.
    
    To use this option, you'd need a modified version of auditctl and use "-e 2".
    This is intended to go at the end of the audit.rules file for people that
    want an immutable configuration.
    
    This patch also adds "res=" to a number of configuration commands that did not
    have it before.
    Signed-off-by: NSteve Grubb <sgrubb@redhat.com>
    Signed-off-by: NAl Viro <viro@zeniv.linux.org.uk>
    6a01b07f
audit.c 34.3 KB