audit.c 1.2 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162
  1. #include <linux/init.h>
  2. #include <linux/types.h>
  3. #include <linux/audit.h>
  4. #include <asm/unistd.h>
  5. static unsigned dir_class[] = {
  6. #include <asm-generic/audit_dir_write.h>
  7. ~0U
  8. };
  9. static unsigned read_class[] = {
  10. #include <asm-generic/audit_read.h>
  11. ~0U
  12. };
  13. static unsigned write_class[] = {
  14. #include <asm-generic/audit_write.h>
  15. ~0U
  16. };
  17. static unsigned chattr_class[] = {
  18. #include <asm-generic/audit_change_attr.h>
  19. ~0U
  20. };
  21. static unsigned signal_class[] = {
  22. #include <asm-generic/audit_signal.h>
  23. ~0U
  24. };
  25. int audit_classify_arch(int arch)
  26. {
  27. return 0;
  28. }
  29. int audit_classify_syscall(int abi, unsigned syscall)
  30. {
  31. switch(syscall) {
  32. case __NR_open:
  33. return AUDITSC_OPEN;
  34. case __NR_openat:
  35. return AUDITSC_OPENAT;
  36. case __NR_execve:
  37. return AUDITSC_EXECVE;
  38. case __NR_openat2:
  39. return AUDITSC_OPENAT2;
  40. default:
  41. return AUDITSC_NATIVE;
  42. }
  43. }
  44. static int __init audit_classes_init(void)
  45. {
  46. audit_register_class(AUDIT_CLASS_WRITE, write_class);
  47. audit_register_class(AUDIT_CLASS_READ, read_class);
  48. audit_register_class(AUDIT_CLASS_DIR_WRITE, dir_class);
  49. audit_register_class(AUDIT_CLASS_CHATTR, chattr_class);
  50. audit_register_class(AUDIT_CLASS_SIGNAL, signal_class);
  51. return 0;
  52. }
  53. __initcall(audit_classes_init);