<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel.git/include/linux/audit.h, branch linux-2.6.13.y</title>
<subtitle>Hosts the 0x221E linux distro kernel.
</subtitle>
<id>https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-2.6.13.y</id>
<link rel='self' href='https://git.0xinfinity.dev/distro/kernel.git/atom?h=linux-2.6.13.y'/>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/'/>
<updated>2005-07-11T02:29:45Z</updated>
<entry>
<title>[SPARC64]: Add syscall auditing support.</title>
<updated>2005-07-11T02:29:45Z</updated>
<author>
<name>David S. Miller</name>
</author>
<published>2005-07-11T02:29:45Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=f7ceba360cce9af3fbc4e5a5b1bd40b570b7021c'/>
<id>urn:sha1:f7ceba360cce9af3fbc4e5a5b1bd40b570b7021c</id>
<content type='text'>
Signed-off-by: David S. Miller &lt;davem@davemloft.net&gt;
</content>
</entry>
<entry>
<title>AUDIT: Record working directory when syscall arguments are pathnames</title>
<updated>2005-05-27T11:17:28Z</updated>
<author>
<name>David Woodhouse</name>
</author>
<published>2005-05-27T11:17:28Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=8f37d47c9bf74cb48692691086b482e315d07f40'/>
<id>urn:sha1:8f37d47c9bf74cb48692691086b482e315d07f40</id>
<content type='text'>
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>AUDIT: Assign serial number to non-syscall messages</title>
<updated>2005-05-21T20:08:09Z</updated>
<author>
<name>David Woodhouse</name>
</author>
<published>2005-05-21T20:08:09Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=bfb4496e7239c9132d732a65cdcf3d6a7431ad1a'/>
<id>urn:sha1:bfb4496e7239c9132d732a65cdcf3d6a7431ad1a</id>
<content type='text'>
Move audit_serial() into audit.c and use it to generate serial numbers 
on messages even when there is no audit context from syscall auditing.  
This allows us to disambiguate audit records when more than one is 
generated in the same millisecond.

Based on a patch by Steve Grubb after he observed the problem.

Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;

</content>
</entry>
<entry>
<title>AUDIT: Avoid sleeping function in SElinux AVC audit.</title>
<updated>2005-05-20T23:15:52Z</updated>
<author>
<name>Stephen Smalley</name>
</author>
<published>2005-05-20T23:15:52Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=011161051bbc25f7f8b7df059dbd934c534443f0'/>
<id>urn:sha1:011161051bbc25f7f8b7df059dbd934c534443f0</id>
<content type='text'>
This patch changes the SELinux AVC to defer logging of paths to the audit
framework upon syscall exit, by saving a reference to the (dentry,vfsmount)
pair in an auxiliary audit item on the current audit context for processing
by audit_log_exit.

Signed-off-by: Stephen Smalley &lt;sds@tycho.nsa.gov&gt;
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>AUDIT: Treat all user messages identically.</title>
<updated>2005-05-18T09:21:07Z</updated>
<author>
<name>David Woodhouse</name>
</author>
<published>2005-05-18T09:21:07Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=209aba03243ee42a22f8df8d08aa9963f62aec64'/>
<id>urn:sha1:209aba03243ee42a22f8df8d08aa9963f62aec64</id>
<content type='text'>
It's silly to have to add explicit entries for new userspace messages
as we invent them. Just treat all messages in the user range the same.

Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>AUDIT: Capture sys_socketcall arguments and sockaddrs </title>
<updated>2005-05-17T11:08:48Z</updated>
<author>
<name>David Woodhouse</name>
</author>
<published>2005-05-17T11:08:48Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=3ec3b2fba526ead2fa3f3d7c91924f39a0733749'/>
<id>urn:sha1:3ec3b2fba526ead2fa3f3d7c91924f39a0733749</id>
<content type='text'>
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>AUDIT: Fix some spelling errors</title>
<updated>2005-05-13T17:35:15Z</updated>
<author>
<name>Steve Grubb</name>
</author>
<published>2005-05-13T17:35:15Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=23f32d18aa589e228c5a9e12e0d0c67c9b5bcdce'/>
<id>urn:sha1:23f32d18aa589e228c5a9e12e0d0c67c9b5bcdce</id>
<content type='text'>
I'm going through the kernel code and have a patch that corrects 
several spelling errors in comments.

From: Steve Grubb &lt;sgrubb@redhat.com&gt;
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>AUDIT: Add message types to audit records</title>
<updated>2005-05-13T17:17:42Z</updated>
<author>
<name>Steve Grubb</name>
</author>
<published>2005-05-13T17:17:42Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=c04049939f88b29e235d2da217bce6e8ead44f32'/>
<id>urn:sha1:c04049939f88b29e235d2da217bce6e8ead44f32</id>
<content type='text'>
This patch adds more messages types to the audit subsystem so that audit 
analysis is quicker, intuitive, and more useful.

Signed-off-by: Steve Grubb &lt;sgrubb@redhat.com&gt;
---
I forgot one type in the big patch. I need to add one for user space 
originating SE Linux avc messages. This is used by dbus and nscd.

-Steve
---
Updated to 2.6.12-rc4-mm1.
-dwmw2

Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>Add audit_log_type</title>
<updated>2005-05-11T09:55:10Z</updated>
<author>
<name>Chris Wright</name>
</author>
<published>2005-05-11T09:55:10Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=c1b773d87eadc3972d697444127e89a7291769a2'/>
<id>urn:sha1:c1b773d87eadc3972d697444127e89a7291769a2</id>
<content type='text'>
Add audit_log_type to allow callers to specify type and pid when logging.
Convert audit_log to wrapper around audit_log_type.  Could have
converted all audit_log callers directly, but common case is default
of type AUDIT_KERNEL and pid 0.  Update audit_log_start to take type
and pid values when creating a new audit_buffer.  Move sequences that
did audit_log_start, audit_log_format, audit_set_type, audit_log_end,
to simply call audit_log_type directly.  This obsoletes audit_set_type
and audit_set_pid, so remove them.

Signed-off-by: Chris Wright &lt;chrisw@osdl.org&gt;
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
<entry>
<title>Move ifdef CONFIG_AUDITSYSCALL to header</title>
<updated>2005-05-11T09:54:05Z</updated>
<author>
<name>Chris Wright</name>
</author>
<published>2005-05-11T09:54:05Z</published>
<link rel='alternate' type='text/html' href='https://git.0xinfinity.dev/distro/kernel.git/commit/?id=197c69c6afd2deb7eec44040ff533d90d26c6161'/>
<id>urn:sha1:197c69c6afd2deb7eec44040ff533d90d26c6161</id>
<content type='text'>
Remove code conditionally dependent on CONFIG_AUDITSYSCALL from audit.c.
Move these dependencies to audit.h with the rest.

Signed-off-by: Chris Wright &lt;chrisw@osdl.org&gt;
Signed-off-by: David Woodhouse &lt;dwmw2@infradead.org&gt;
</content>
</entry>
</feed>
