audit: add exclude filter extension to feature bitmap
Add to the audit feature bitmap to indicate availability of the extension of the exclude filter to include PID, UID, AUID, GID, SUBJ_*. RFE: add additional fields for use in audit filter exclude rules https://github.com/linux-audit/audit-kernel/issues/5 Signed-off-by: Richard Guy Briggs <rgb@redhat.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
This commit is contained in:

committed by
Paul Moore

parent
fa2bea2f5c
commit
7ff89ac608
@@ -327,9 +327,11 @@ enum {
|
|||||||
#define AUDIT_FEATURE_BITMAP_BACKLOG_LIMIT 0x00000001
|
#define AUDIT_FEATURE_BITMAP_BACKLOG_LIMIT 0x00000001
|
||||||
#define AUDIT_FEATURE_BITMAP_BACKLOG_WAIT_TIME 0x00000002
|
#define AUDIT_FEATURE_BITMAP_BACKLOG_WAIT_TIME 0x00000002
|
||||||
#define AUDIT_FEATURE_BITMAP_EXECUTABLE_PATH 0x00000004
|
#define AUDIT_FEATURE_BITMAP_EXECUTABLE_PATH 0x00000004
|
||||||
|
#define AUDIT_FEATURE_BITMAP_EXCLUDE_EXTEND 0x00000008
|
||||||
#define AUDIT_FEATURE_BITMAP_ALL (AUDIT_FEATURE_BITMAP_BACKLOG_LIMIT | \
|
#define AUDIT_FEATURE_BITMAP_ALL (AUDIT_FEATURE_BITMAP_BACKLOG_LIMIT | \
|
||||||
AUDIT_FEATURE_BITMAP_BACKLOG_WAIT_TIME | \
|
AUDIT_FEATURE_BITMAP_BACKLOG_WAIT_TIME | \
|
||||||
AUDIT_FEATURE_BITMAP_EXECUTABLE_PATH)
|
AUDIT_FEATURE_BITMAP_EXECUTABLE_PATH | \
|
||||||
|
AUDIT_FEATURE_BITMAP_EXCLUDE_EXTEND)
|
||||||
|
|
||||||
/* deprecated: AUDIT_VERSION_* */
|
/* deprecated: AUDIT_VERSION_* */
|
||||||
#define AUDIT_VERSION_LATEST AUDIT_FEATURE_BITMAP_ALL
|
#define AUDIT_VERSION_LATEST AUDIT_FEATURE_BITMAP_ALL
|
||||||
|
Reference in New Issue
Block a user