audit: allow matching on obj_uid
Allow syscall exit filter matching based on the uid of the owner of an inode used in a syscall. aka: auditctl -a always,exit -S open -F obj_uid=0 -F perm=wa Signed-off-by: Eric Paris <eparis@redhat.com>
This commit is contained in:
@@ -461,6 +461,7 @@ static struct audit_entry *audit_data_to_entry(struct audit_rule_data *data,
|
||||
case AUDIT_ARG1:
|
||||
case AUDIT_ARG2:
|
||||
case AUDIT_ARG3:
|
||||
case AUDIT_OBJ_UID:
|
||||
break;
|
||||
case AUDIT_ARCH:
|
||||
entry->rule.arch_f = f;
|
||||
|
Reference in New Issue
Block a user