Searched refs:krule (Results 1 - 8 of 8) sorted by relevance

/linux-master/kernel/
H A Daudit_watch.c43 struct list_head rules; /* anchor for krule->rlist */
178 int audit_to_watch(struct audit_krule *krule, char *path, int len, u32 op) argument
186 (krule->listnr != AUDIT_FILTER_EXIT &&
187 krule->listnr != AUDIT_FILTER_URING_EXIT) ||
189 krule->inode_f || krule->watch || krule->tree)
196 krule->watch = watch;
365 static void audit_add_to_parent(struct audit_krule *krule, argument
368 struct audit_watch *w, *watch = krule
400 audit_add_watch(struct audit_krule *krule, struct list_head **list) argument
447 audit_remove_watch_rule(struct audit_krule *krule) argument
[all...]
H A Daudit_fsnotify.c74 struct audit_fsnotify_mark *audit_alloc_mark(struct audit_krule *krule, char *pathname, int len) argument
101 audit_mark->rule = krule;
139 void audit_remove_mark_rule(struct audit_krule *krule) argument
141 struct audit_fsnotify_mark *mark = krule->exe;
H A Daudit.h269 extern int audit_to_watch(struct audit_krule *krule, char *path, int len,
271 extern int audit_add_watch(struct audit_krule *krule, struct list_head **list);
272 extern void audit_remove_watch_rule(struct audit_krule *krule);
277 extern struct audit_fsnotify_mark *audit_alloc_mark(struct audit_krule *krule,
281 extern void audit_remove_mark_rule(struct audit_krule *krule);
H A Dauditfilter.c153 static inline int audit_to_inode(struct audit_krule *krule, argument
156 if ((krule->listnr != AUDIT_FILTER_EXIT &&
157 krule->listnr != AUDIT_FILTER_URING_EXIT) ||
158 krule->inode_f || krule->watch || krule->tree ||
162 krule->inode_f = f;
634 static struct audit_rule_data *audit_krule_to_data(struct audit_krule *krule) argument
640 data = kmalloc(struct_size(data, buf, krule->buflen), GFP_KERNEL);
645 data->flags = krule
[all...]
/linux-master/include/linux/
H A Dsecurity.h2052 int security_audit_rule_known(struct audit_krule *krule);
2064 static inline int security_audit_rule_known(struct audit_krule *krule) argument
H A Dlsm_hook_defs.h416 LSM_HOOK(int, 0, audit_rule_known, struct audit_krule *krule)
/linux-master/security/
H A Dsecurity.c5347 * @krule: audit rule
5349 * Specifies whether given @krule contains any fields related to the current
5354 int security_audit_rule_known(struct audit_krule *krule) argument
5356 return call_int_hook(audit_rule_known, krule);
/linux-master/security/smack/
H A Dsmack_lsm.c4722 * @krule: rule of interest, in Audit kernel representation format
4728 static int smack_audit_rule_known(struct audit_krule *krule) argument
4733 for (i = 0; i < krule->field_count; i++) {
4734 f = &krule->fields[i];

Completed in 243 milliseconds