audit: implement all object interfield comparisons

This completes the matrix of interfield comparisons between uid/gid
information for the current task and the uid/gid information for inodes.
aka I can audit based on differences between the euid of the process and
the uid of fs objects.

Signed-off-by: Peter Moody <pmoody@google.com>
Signed-off-by: Eric Paris <eparis@redhat.com>
This commit is contained in:
Peter Moody
2011-12-13 16:17:51 -08:00
committed by Al Viro
parent c9fe685f7a
commit 4a6633ed08
2 changed files with 38 additions and 1 deletions

View File

@ -508,6 +508,7 @@ static int audit_field_compare(struct task_struct *tsk,
struct audit_names *name)
{
switch (f->val) {
/* process to file object comparisons */
case AUDIT_COMPARE_UID_TO_OBJ_UID:
return audit_compare_id(cred->uid,
name, offsetof(struct audit_names, uid),
@ -516,6 +517,34 @@ static int audit_field_compare(struct task_struct *tsk,
return audit_compare_id(cred->gid,
name, offsetof(struct audit_names, gid),
f, ctx);
case AUDIT_COMPARE_EUID_TO_OBJ_UID:
return audit_compare_id(cred->euid,
name, offsetof(struct audit_names, uid),
f, ctx);
case AUDIT_COMPARE_EGID_TO_OBJ_GID:
return audit_compare_id(cred->egid,
name, offsetof(struct audit_names, gid),
f, ctx);
case AUDIT_COMPARE_AUID_TO_OBJ_UID:
return audit_compare_id(tsk->loginuid,
name, offsetof(struct audit_names, uid),
f, ctx);
case AUDIT_COMPARE_SUID_TO_OBJ_UID:
return audit_compare_id(cred->suid,
name, offsetof(struct audit_names, uid),
f, ctx);
case AUDIT_COMPARE_SGID_TO_OBJ_GID:
return audit_compare_id(cred->sgid,
name, offsetof(struct audit_names, gid),
f, ctx);
case AUDIT_COMPARE_FSUID_TO_OBJ_UID:
return audit_compare_id(cred->fsuid,
name, offsetof(struct audit_names, uid),
f, ctx);
case AUDIT_COMPARE_FSGID_TO_OBJ_GID:
return audit_compare_id(cred->fsgid,
name, offsetof(struct audit_names, gid),
f, ctx);
default:
WARN(1, "Missing AUDIT_COMPARE define. Report as a bug\n");
return 0;