Function report

Linux Kernel

v5.5.9

Brick Technologies Co., Ltd

Source Code:kernel\auditfilter.c Create Date:2022-07-28 11:25:27
Last Modify:2020-03-12 14:18:49 Copyright©Brick
home page Tree
Annotation kernel can get tool activityDownload SCCTChinese

Name:audit_comparator

Proto:int audit_comparator(unsigned int left, unsigned int op, unsigned int right)

Type:int

Parameter:

TypeParameterName
unsigned intleft
unsigned intop
unsigned intright
1200  Case op == Audit_equal
1201  Return left == right
1202  Case op == Audit_not_equal
1203  Return left != right
1204  Case op == Audit_lt
1205  Return left < right
1206  Case op == Audit_le
1207  Return left <= right
1208  Case op == Audit_gt
1209  Return left > right
1210  Case op == Audit_ge
1211  Return left >= right
1212  Case op == Audit_bitmask
1213  Return left & right
1214  Case op == Audit_bittest
1215  Return (left & right) == right
1216  Default
1217  Return 0
Caller
NameDescribe
audit_filter
audit_filter_rulesCompare a task_struct with an audit_rule. Return 1 on match, 0* otherwise.* If task_creation is true, this is an explicit indication that we are* filtering a task rule at task creation time. This and tsk == current are
__audit_inode__audit_inode - store the inode and device from a lookup*@name: name being audited*@dentry: dentry being audited*@flags: attributes for this particular entry
__audit_inode_child__audit_inode_child - collect inode info for created/removed objects*@parent: inode of dentry parent*@dentry: dentry being audited*@type: AUDIT_TYPE_* value that we're looking for* For syscalls that create or remove filesystem objects, audit_inode