audit_64.c 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182
  1. #include <linux/init.h>
  2. #include <linux/types.h>
  3. #include <linux/audit.h>
  4. #include <asm/unistd.h>
  5. static unsigned dir_class[] = {
  6. #include <asm-generic/audit_dir_write.h>
  7. ~0U
  8. };
  9. static unsigned read_class[] = {
  10. #include <asm-generic/audit_read.h>
  11. ~0U
  12. };
  13. static unsigned write_class[] = {
  14. #include <asm-generic/audit_write.h>
  15. ~0U
  16. };
  17. static unsigned chattr_class[] = {
  18. #include <asm-generic/audit_change_attr.h>
  19. ~0U
  20. };
  21. static unsigned signal_class[] = {
  22. #include <asm-generic/audit_signal.h>
  23. ~0U
  24. };
  25. int audit_classify_arch(int arch)
  26. {
  27. #ifdef CONFIG_IA32_EMULATION
  28. if (arch == AUDIT_ARCH_I386)
  29. return 1;
  30. #endif
  31. return 0;
  32. }
  33. int audit_classify_syscall(int abi, unsigned syscall)
  34. {
  35. #ifdef CONFIG_IA32_EMULATION
  36. extern int ia32_classify_syscall(unsigned);
  37. if (abi == AUDIT_ARCH_I386)
  38. return ia32_classify_syscall(syscall);
  39. #endif
  40. switch(syscall) {
  41. case __NR_open:
  42. return 2;
  43. case __NR_openat:
  44. return 3;
  45. case __NR_execve:
  46. return 5;
  47. default:
  48. return 0;
  49. }
  50. }
  51. static int __init audit_classes_init(void)
  52. {
  53. #ifdef CONFIG_IA32_EMULATION
  54. extern __u32 ia32_dir_class[];
  55. extern __u32 ia32_write_class[];
  56. extern __u32 ia32_read_class[];
  57. extern __u32 ia32_chattr_class[];
  58. extern __u32 ia32_signal_class[];
  59. audit_register_class(AUDIT_CLASS_WRITE_32, ia32_write_class);
  60. audit_register_class(AUDIT_CLASS_READ_32, ia32_read_class);
  61. audit_register_class(AUDIT_CLASS_DIR_WRITE_32, ia32_dir_class);
  62. audit_register_class(AUDIT_CLASS_CHATTR_32, ia32_chattr_class);
  63. audit_register_class(AUDIT_CLASS_SIGNAL_32, ia32_signal_class);
  64. #endif
  65. audit_register_class(AUDIT_CLASS_WRITE, write_class);
  66. audit_register_class(AUDIT_CLASS_READ, read_class);
  67. audit_register_class(AUDIT_CLASS_DIR_WRITE, dir_class);
  68. audit_register_class(AUDIT_CLASS_CHATTR, chattr_class);
  69. audit_register_class(AUDIT_CLASS_SIGNAL, signal_class);
  70. return 0;
  71. }
  72. __initcall(audit_classes_init);