/
usr
/
include
/
linux
/
/usr/include/linux
mkdir
upload
Name
Size
Mode
Actions
byteorder/
-
0755
rm
can/
-
0755
rm
dvb/
-
0755
rm
hdlc/
-
0755
rm
isdn/
-
0755
rm
netfilter/
-
0755
rm
netfilter_arp/
-
0755
rm
netfilter_bridge/
-
0755
rm
netfilter_ipv4/
-
0755
rm
netfilter_ipv6/
-
0755
rm
nfsd/
-
0755
rm
raid/
-
0755
rm
spi/
-
0755
rm
sunrpc/
-
0755
rm
tc_act/
-
0755
rm
tc_ematch/
-
0755
rm
usb/
-
0755
rm
wimax/
-
0755
rm
a.out.h
7319
0644
edit
dl
rm
acct.h
3490
0644
edit
dl
rm
adb.h
1077
0644
edit
dl
rm
adfs_fs.h
856
0644
edit
dl
rm
affs_hardblocks.h
1481
0644
edit
dl
rm
agpgart.h
3925
0644
edit
dl
rm
aio_abi.h
3112
0644
edit
dl
rm
apm_bios.h
3544
0644
edit
dl
rm
arcfb.h
150
0644
edit
dl
rm
atalk.h
927
0644
edit
dl
rm
atm.h
7806
0644
edit
dl
rm
atmapi.h
889
0644
edit
dl
rm
atmarp.h
1233
0644
edit
dl
rm
atmbr2684.h
3208
0644
edit
dl
rm
atmclip.h
513
0644
edit
dl
rm
atmdev.h
7593
0644
edit
dl
rm
atmioc.h
1583
0644
edit
dl
rm
atmlec.h
2561
0644
edit
dl
rm
atmmpc.h
4163
0644
edit
dl
rm
atmppp.h
576
0644
edit
dl
rm
atmsap.h
4907
0644
edit
dl
rm
atmsvc.h
1790
0644
edit
dl
rm
atm_eni.h
585
0644
edit
dl
rm
atm_he.h
343
0644
edit
dl
rm
atm_idt77105.h
892
0644
edit
dl
rm
atm_nicstar.h
1215
0644
edit
dl
rm
atm_tcp.h
1537
0644
edit
dl
rm
atm_zatm.h
1606
0644
edit
dl
rm
audit.h
15880
0644
edit
dl
rm
auto_fs.h
2346
0644
edit
dl
rm
auto_fs4.h
4131
0644
edit
dl
rm
auxvec.h
1384
0644
edit
dl
rm
ax25.h
2752
0644
edit
dl
rm
b1lli.h
1654
0644
edit
dl
rm
baycom.h
820
0644
edit
dl
rm
bfs_fs.h
1830
0644
edit
dl
rm
binfmts.h
565
0644
edit
dl
rm
blkpg.h
1598
0644
edit
dl
rm
blktrace_api.h
4473
0644
edit
dl
rm
blk_types.h
7106
0644
edit
dl
rm
bpqether.h
952
0644
edit
dl
rm
bsg.h
2385
0644
edit
dl
rm
can.h
3326
0644
edit
dl
rm
capability.h
10589
0644
edit
dl
rm
capi.h
3057
0644
edit
dl
rm
cciss_ioctl.h
5824
0644
edit
dl
rm
cdk.h
12770
0644
edit
dl
rm
cdrom.h
28129
0644
edit
dl
rm
cgroupstats.h
2155
0644
edit
dl
rm
chio.h
5280
0644
edit
dl
rm
cm4000_cs.h
1718
0644
edit
dl
rm
cn_proc.h
2715
0644
edit
dl
rm
coda.h
17487
0644
edit
dl
rm
coda_psdev.h
679
0644
edit
dl
rm
coff.h
12413
0644
edit
dl
rm
comstats.h
3120
0644
edit
dl
rm
connector.h
2129
0644
edit
dl
rm
const.h
682
0644
edit
dl
rm
cramfs_fs.h
2930
0644
edit
dl
rm
cuda.h
769
0644
edit
dl
rm
cyclades.h
17045
0644
edit
dl
rm
cycx_cfm.h
2926
0644
edit
dl
rm
dcbnl.h
22120
0644
edit
dl
rm
dccp.h
5800
0644
edit
dl
rm
dlm.h
2529
0644
edit
dl
rm
dlmconstants.h
5013
0644
edit
dl
rm
dlm_device.h
2480
0644
edit
dl
rm
dlm_netlink.h
1064
0644
edit
dl
rm
dlm_plock.h
806
0644
edit
dl
rm
dm-ioctl.h
10668
0644
edit
dl
rm
dm-log-userspace.h
15173
0644
edit
dl
rm
dn.h
4527
0644
edit
dl
rm
dqblk_xfs.h
6952
0644
edit
dl
rm
edd.h
5544
0644
edit
dl
rm
efs_fs_sb.h
2164
0644
edit
dl
rm
elf-em.h
1834
0644
edit
dl
rm
elf-fdpic.h
2557
0644
edit
dl
rm
elf.h
11236
0644
edit
dl
rm
elfcore.h
2932
0644
edit
dl
rm
errno.h
79
0644
edit
dl
rm
errqueue.h
443
0644
edit
dl
rm
ethtool.h
34166
0644
edit
dl
rm
eventpoll.h
1353
0644
edit
dl
rm
ext2_fs.h
18802
0644
edit
dl
rm
fadvise.h
855
0644
edit
dl
rm
falloc.h
293
0644
edit
dl
rm
fb.h
16016
0644
edit
dl
rm
fcntl.h
1607
0644
edit
dl
rm
fd.h
11563
0644
edit
dl
rm
fdreg.h
5355
0644
edit
dl
rm
fib_rules.h
1459
0644
edit
dl
rm
fiemap.h
2548
0644
edit
dl
rm
filter.h
3534
0644
edit
dl
rm
firewire-cdev.h
25053
0644
edit
dl
rm
firewire-constants.h
1975
0644
edit
dl
rm
flat.h
2085
0644
edit
dl
rm
fs.h
18910
0644
edit
dl
rm
fuse.h
11441
0644
edit
dl
rm
futex.h
4909
0644
edit
dl
rm
gameport.h
816
0644
edit
dl
rm
generic_serial.h
895
0644
edit
dl
rm
genetlink.h
1683
0644
edit
dl
rm
gen_stats.h
1304
0644
edit
dl
rm
gfs2_ondisk.h
11814
0644
edit
dl
rm
gigaset_dev.h
981
0644
edit
dl
rm
hayesesp.h
230
0644
edit
dl
rm
hdlc.h
574
0644
edit
dl
rm
hdlcdrv.h
2845
0644
edit
dl
rm
hdreg.h
22640
0644
edit
dl
rm
hid.h
1824
0644
edit
dl
rm
hiddev.h
6265
0644
edit
dl
rm
hidraw.h
1217
0644
edit
dl
rm
hpet.h
686
0644
edit
dl
rm
hysdn_if.h
1319
0644
edit
dl
rm
i2c-dev.h
2403
0644
edit
dl
rm
i2c.h
6631
0644
edit
dl
rm
i2o-dev.h
11488
0644
edit
dl
rm
i8k.h
1438
0644
edit
dl
rm
icmp.h
2892
0644
edit
dl
rm
icmpv6.h
3831
0644
edit
dl
rm
if.h
8673
0644
edit
dl
rm
if_addr.h
1456
0644
edit
dl
rm
if_addrlabel.h
658
0644
edit
dl
rm
if_arcnet.h
3718
0644
edit
dl
rm
if_arp.h
6109
0644
edit
dl
rm
if_bonding.h
4076
0644
edit
dl
rm
if_bridge.h
3810
0644
edit
dl
rm
if_cablemodem.h
910
0644
edit
dl
rm
if_ec.h
901
0644
edit
dl
rm
if_eql.h
1284
0644
edit
dl
rm
if_ether.h
6539
0644
edit
dl
rm
if_fc.h
1674
0644
edit
dl
rm
if_fddi.h
3700
0644
edit
dl
rm
if_frad.h
2940
0644
edit
dl
rm
if_hippi.h
4175
0644
edit
dl
rm
if_infiniband.h
1145
0644
edit
dl
rm
if_link.h
12078
0644
edit
dl
rm
if_ltalk.h
125
0644
edit
dl
rm
if_packet.h
3530
0644
edit
dl
rm
if_phonet.h
337
0644
edit
dl
rm
if_plip.h
596
0644
edit
dl
rm
if_ppp.h
6938
0644
edit
dl
rm
if_pppol2tp.h
1983
0644
edit
dl
rm
if_pppox.h
3772
0644
edit
dl
rm
if_slip.h
809
0644
edit
dl
rm
if_strip.h
700
0644
edit
dl
rm
if_tr.h
3199
0644
edit
dl
rm
if_tun.h
3014
0644
edit
dl
rm
if_tunnel.h
1459
0644
edit
dl
rm
if_vlan.h
1708
0644
edit
dl
rm
igmp.h
2928
0644
edit
dl
rm
in.h
9203
0644
edit
dl
rm
in6.h
7495
0644
edit
dl
rm
inet_diag.h
2453
0644
edit
dl
rm
inotify.h
2838
0644
edit
dl
rm
input.h
27594
0644
edit
dl
rm
in_route.h
873
0644
edit
dl
rm
ioctl.h
100
0644
edit
dl
rm
ip.h
3555
0644
edit
dl
rm
ip6_tunnel.h
1073
0644
edit
dl
rm
ipc.h
2038
0644
edit
dl
rm
ipmi.h
16543
0644
edit
dl
rm
ipmi_msgdefs.h
4477
0644
edit
dl
rm
ipsec.h
884
0644
edit
dl
rm
ipv6.h
2892
0644
edit
dl
rm
ipv6_route.h
1614
0644
edit
dl
rm
ipx.h
1824
0644
edit
dl
rm
ip_vs.h
12583
0644
edit
dl
rm
irda.h
7651
0644
edit
dl
rm
irqnr.h
93
0644
edit
dl
rm
isdn.h
5687
0644
edit
dl
rm
isdnif.h
2306
0644
edit
dl
rm
isdn_divertif.h
1038
0644
edit
dl
rm
isdn_ppp.h
1859
0644
edit
dl
rm
iso_fs.h
6439
0644
edit
dl
rm
ivtv.h
2726
0644
edit
dl
rm
ivtvfb.h
1143
0644
edit
dl
rm
ixjuser.h
25116
0644
edit
dl
rm
jffs2.h
6949
0644
edit
dl
rm
joystick.h
3587
0644
edit
dl
rm
kd.h
6169
0644
edit
dl
rm
kdev_t.h
298
0644
edit
dl
rm
kernel.h
2457
0644
edit
dl
rm
kernelcapi.h
959
0644
edit
dl
rm
keyboard.h
12695
0644
edit
dl
rm
keyctl.h
2984
0644
edit
dl
rm
kvm.h
20681
0644
edit
dl
rm
kvm_para.h
564
0644
edit
dl
rm
libc-compat.h
3540
0644
edit
dl
rm
limits.h
874
0644
edit
dl
rm
llc.h
2835
0644
edit
dl
rm
loop.h
2189
0644
edit
dl
rm
lp.h
3794
0644
edit
dl
rm
magic.h
2292
0644
edit
dl
rm
major.h
4655
0644
edit
dl
rm
map_to_7segment.h
7187
0644
edit
dl
rm
matroxfb.h
1429
0644
edit
dl
rm
mempolicy.h
2052
0644
edit
dl
rm
meye.h
2544
0644
edit
dl
rm
mii.h
7950
0644
edit
dl
rm
minix_fs.h
2059
0644
edit
dl
rm
mman.h
230
0644
edit
dl
rm
mmtimer.h
2054
0644
edit
dl
rm
mqueue.h
2055
0644
edit
dl
rm
mroute.h
3813
0644
edit
dl
rm
mroute6.h
3991
0644
edit
dl
rm
msdos_fs.h
5839
0644
edit
dl
rm
msg.h
2539
0644
edit
dl
rm
mtio.h
8080
0644
edit
dl
rm
nbd.h
1958
0644
edit
dl
rm
ncp.h
5055
0644
edit
dl
rm
ncp_fs.h
3354
0644
edit
dl
rm
ncp_mount.h
2112
0644
edit
dl
rm
ncp_no.h
651
0644
edit
dl
rm
neighbour.h
4060
0644
edit
dl
rm
net.h
2021
0644
edit
dl
rm
netdevice.h
1771
0644
edit
dl
rm
netfilter.h
1546
0644
edit
dl
rm
netfilter_arp.h
380
0644
edit
dl
rm
netfilter_bridge.h
735
0644
edit
dl
rm
netfilter_decnet.h
1872
0644
edit
dl
rm
netfilter_ipv4.h
2032
0644
edit
dl
rm
netfilter_ipv6.h
2050
0644
edit
dl
rm
netlink.h
4969
0644
edit
dl
rm
netrom.h
719
0644
edit
dl
rm
net_dropmon.h
1091
0644
edit
dl
rm
net_tstamp.h
3468
0644
edit
dl
rm
nfs.h
4351
0644
edit
dl
rm
nfs2.h
1405
0644
edit
dl
rm
nfs3.h
2207
0644
edit
dl
rm
nfs4.h
5763
0644
edit
dl
rm
nfs4_mount.h
1869
0644
edit
dl
rm
nfsacl.h
577
0644
edit
dl
rm
nfs_fs.h
1552
0644
edit
dl
rm
nfs_idmap.h
2238
0644
edit
dl
rm
nfs_mount.h
3200
0644
edit
dl
rm
nl80211.h
192354
0644
edit
dl
rm
nubus.h
8366
0644
edit
dl
rm
nvram.h
470
0644
edit
dl
rm
n_r3964.h
2349
0644
edit
dl
rm
oom.h
456
0644
edit
dl
rm
param.h
78
0644
edit
dl
rm
parport.h
3644
0644
edit
dl
rm
patchkey.h
831
0644
edit
dl
rm
pci.h
1485
0644
edit
dl
rm
pci_regs.h
37975
0644
edit
dl
rm
perf_event.h
21849
0644
edit
dl
rm
personality.h
1998
0644
edit
dl
rm
pfkeyv2.h
10147
0644
edit
dl
rm
pg.h
2282
0644
edit
dl
rm
phantom.h
1590
0644
edit
dl
rm
phonet.h
4349
0644
edit
dl
rm
pktcdvd.h
2623
0644
edit
dl
rm
pkt_cls.h
9293
0644
edit
dl
rm
pkt_sched.h
10887
0644
edit
dl
rm
pmu.h
5187
0644
edit
dl
rm
poll.h
96
0644
edit
dl
rm
posix_types.h
1270
0644
edit
dl
rm
ppdev.h
3147
0644
edit
dl
rm
ppp-comp.h
6516
0644
edit
dl
rm
ppp_defs.h
6461
0644
edit
dl
rm
pps.h
3939
0644
edit
dl
rm
prctl.h
4972
0644
edit
dl
rm
ptp_clock.h
3496
0644
edit
dl
rm
ptrace.h
2290
0644
edit
dl
rm
qnx4_fs.h
2265
0644
edit
dl
rm
qnxtypes.h
561
0644
edit
dl
rm
quota.h
5723
0644
edit
dl
rm
radeonfb.h
297
0644
edit
dl
rm
random.h
1085
0644
edit
dl
rm
raw.h
302
0644
edit
dl
rm
reboot.h
1280
0644
edit
dl
rm
reiserfs_fs.h
907
0644
edit
dl
rm
reiserfs_xattr.h
465
0644
edit
dl
rm
resource.h
2087
0644
edit
dl
rm
rfkill.h
3384
0644
edit
dl
rm
romfs_fs.h
1127
0644
edit
dl
rm
rose.h
2100
0644
edit
dl
rm
route.h
2269
0644
edit
dl
rm
rtc.h
3696
0644
edit
dl
rm
rtnetlink.h
15335
0644
edit
dl
rm
scc.h
4543
0644
edit
dl
rm
sched.h
2096
0644
edit
dl
rm
screen_info.h
2202
0644
edit
dl
rm
sdla.h
2837
0644
edit
dl
rm
selinux_netlink.h
1132
0644
edit
dl
rm
sem.h
3666
0644
edit
dl
rm
serial.h
6780
0644
edit
dl
rm
serial_core.h
4024
0644
edit
dl
rm
serial_reg.h
13245
0644
edit
dl
rm
serio.h
1688
0644
edit
dl
rm
shm.h
2187
0644
edit
dl
rm
signal.h
129
0644
edit
dl
rm
signalfd.h
1096
0644
edit
dl
rm
smb.h
1209
0644
edit
dl
rm
smbno.h
14520
0644
edit
dl
rm
smb_fs.h
535
0644
edit
dl
rm
smb_mount.h
468
0644
edit
dl
rm
snmp.h
11157
0644
edit
dl
rm
socket.h
738
0644
edit
dl
rm
sockios.h
5967
0644
edit
dl
rm
som.h
5480
0644
edit
dl
rm
sonet.h
2207
0644
edit
dl
rm
sonypi.h
5136
0644
edit
dl
rm
sound.h
1099
0644
edit
dl
rm
soundcard.h
46019
0644
edit
dl
rm
stat.h
1005
0644
edit
dl
rm
stddef.h
633
0644
edit
dl
rm
string.h
175
0644
edit
dl
rm
suspend_ioctls.h
1368
0644
edit
dl
rm
swab.h
6292
0644
edit
dl
rm
synclink.h
8695
0644
edit
dl
rm
sysctl.h
26495
0644
edit
dl
rm
taskstats.h
6947
0644
edit
dl
rm
tcp.h
5205
0644
edit
dl
rm
telephony.h
9051
0644
edit
dl
rm
termios.h
544
0644
edit
dl
rm
time.h
1736
0644
edit
dl
rm
times.h
215
0644
edit
dl
rm
timex.h
6221
0644
edit
dl
rm
tiocl.h
1666
0644
edit
dl
rm
tipc.h
5910
0644
edit
dl
rm
tipc_config.h
15370
0644
edit
dl
rm
toshiba.h
1284
0644
edit
dl
rm
tty.h
128
0644
edit
dl
rm
types.h
991
0644
edit
dl
rm
udf_fs_i.h
634
0644
edit
dl
rm
udp.h
1166
0644
edit
dl
rm
uinput.h
5125
0644
edit
dl
rm
uio.h
648
0644
edit
dl
rm
ultrasound.h
4499
0644
edit
dl
rm
un.h
203
0644
edit
dl
rm
unistd.h
157
0644
edit
dl
rm
usbdevice_fs.h
5340
0644
edit
dl
rm
utime.h
152
0644
edit
dl
rm
utsname.h
606
0644
edit
dl
rm
uuid.h
1769
0644
edit
dl
rm
version.h
281
0644
edit
dl
rm
veth.h
474
0644
edit
dl
rm
vhost.h
4566
0644
edit
dl
rm
videodev.h
10513
0644
edit
dl
rm
videodev2.h
66071
0644
edit
dl
rm
videotext.h
4242
0644
edit
dl
rm
virtio_9p.h
351
0644
edit
dl
rm
virtio_balloon.h
1255
0644
edit
dl
rm
virtio_blk.h
2981
0644
edit
dl
rm
virtio_config.h
1284
0644
edit
dl
rm
virtio_console.h
1406
0644
edit
dl
rm
virtio_ids.h
545
0644
edit
dl
rm
virtio_net.h
7026
0644
edit
dl
rm
virtio_pci.h
2263
0644
edit
dl
rm
virtio_ring.h
4489
0644
edit
dl
rm
virtio_rng.h
265
0644
edit
dl
rm
vt.h
3070
0644
edit
dl
rm
wait.h
580
0644
edit
dl
rm
wanrouter.h
17836
0644
edit
dl
rm
watchdog.h
2400
0644
edit
dl
rm
wimax.h
8370
0644
edit
dl
rm
wireless.h
42653
0644
edit
dl
rm
x25.h
3418
0644
edit
dl
rm
xattr.h
646
0644
edit
dl
rm
xfrm.h
10558
0644
edit
dl
rm
Edit:
/usr/include/linux/audit.h
(15880B)
/* audit.h -- Auditing support * * Copyright 2003-2004 Red Hat Inc., Durham, North Carolina. * All Rights Reserved. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, write to the Free Software * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA * * Written by Rickard E. (Rik) Faith <faith@redhat.com> * */ #ifndef _LINUX_AUDIT_H_ #define _LINUX_AUDIT_H_ #include <linux/types.h> #include <linux/elf-em.h> #include <linux/ptrace.h> /* The netlink messages for the audit system is divided into blocks: * 1000 - 1099 are for commanding the audit system * 1100 - 1199 user space trusted application messages * 1200 - 1299 messages internal to the audit daemon * 1300 - 1399 audit event messages * 1400 - 1499 SE Linux use * 1500 - 1599 kernel LSPP events * 1600 - 1699 kernel crypto events * 1700 - 1799 kernel anomaly records * 1800 - 1899 kernel integrity events * 1900 - 1999 future kernel use * 2000 is for otherwise unclassified kernel audit messages (legacy) * 2001 - 2099 unused (kernel) * 2100 - 2199 user space anomaly records * 2200 - 2299 user space actions taken in response to anomalies * 2300 - 2399 user space generated LSPP events * 2400 - 2499 user space crypto events * 2500 - 2999 future user space (maybe integrity labels and related events) * * Messages from 1000-1199 are bi-directional. 1200-1299 & 2100 - 2999 are * exclusively user space. 1300-2099 is kernel --> user space * communication. */ #define AUDIT_GET 1000 /* Get status */ #define AUDIT_SET 1001 /* Set status (enable/disable/auditd) */ #define AUDIT_LIST 1002 /* List syscall rules -- deprecated */ #define AUDIT_ADD 1003 /* Add syscall rule -- deprecated */ #define AUDIT_DEL 1004 /* Delete syscall rule -- deprecated */ #define AUDIT_USER 1005 /* Message from userspace -- deprecated */ #define AUDIT_LOGIN 1006 /* Define the login id and information */ #define AUDIT_WATCH_INS 1007 /* Insert file/dir watch entry */ #define AUDIT_WATCH_REM 1008 /* Remove file/dir watch entry */ #define AUDIT_WATCH_LIST 1009 /* List all file/dir watches */ #define AUDIT_SIGNAL_INFO 1010 /* Get info about sender of signal to auditd */ #define AUDIT_ADD_RULE 1011 /* Add syscall filtering rule */ #define AUDIT_DEL_RULE 1012 /* Delete syscall filtering rule */ #define AUDIT_LIST_RULES 1013 /* List syscall filtering rules */ #define AUDIT_TRIM 1014 /* Trim junk from watched tree */ #define AUDIT_MAKE_EQUIV 1015 /* Append to watched tree */ #define AUDIT_TTY_GET 1016 /* Get TTY auditing status */ #define AUDIT_TTY_SET 1017 /* Set TTY auditing status */ #define AUDIT_FIRST_USER_MSG 1100 /* Userspace messages mostly uninteresting to kernel */ #define AUDIT_USER_AVC 1107 /* We filter this differently */ #define AUDIT_USER_TTY 1124 /* Non-ICANON TTY input meaning */ #define AUDIT_LAST_USER_MSG 1199 #define AUDIT_FIRST_USER_MSG2 2100 /* More user space messages */ #define AUDIT_LAST_USER_MSG2 2999 #define AUDIT_DAEMON_START 1200 /* Daemon startup record */ #define AUDIT_DAEMON_END 1201 /* Daemon normal stop record */ #define AUDIT_DAEMON_ABORT 1202 /* Daemon error stop record */ #define AUDIT_DAEMON_CONFIG 1203 /* Daemon config change */ #define AUDIT_SYSCALL 1300 /* Syscall event */ /* #define AUDIT_FS_WATCH 1301 * Deprecated */ #define AUDIT_PATH 1302 /* Filename path information */ #define AUDIT_IPC 1303 /* IPC record */ #define AUDIT_SOCKETCALL 1304 /* sys_socketcall arguments */ #define AUDIT_CONFIG_CHANGE 1305 /* Audit system configuration change */ #define AUDIT_SOCKADDR 1306 /* sockaddr copied as syscall arg */ #define AUDIT_CWD 1307 /* Current working directory */ #define AUDIT_EXECVE 1309 /* execve arguments */ #define AUDIT_IPC_SET_PERM 1311 /* IPC new permissions record type */ #define AUDIT_MQ_OPEN 1312 /* POSIX MQ open record type */ #define AUDIT_MQ_SENDRECV 1313 /* POSIX MQ send/receive record type */ #define AUDIT_MQ_NOTIFY 1314 /* POSIX MQ notify record type */ #define AUDIT_MQ_GETSETATTR 1315 /* POSIX MQ get/set attribute record type */ #define AUDIT_KERNEL_OTHER 1316 /* For use by 3rd party modules */ #define AUDIT_FD_PAIR 1317 /* audit record for pipe/socketpair */ #define AUDIT_OBJ_PID 1318 /* ptrace target */ #define AUDIT_TTY 1319 /* Input on an administrative TTY */ #define AUDIT_EOE 1320 /* End of multi-record event */ #define AUDIT_BPRM_FCAPS 1321 /* Information about fcaps increasing perms */ #define AUDIT_CAPSET 1322 /* Record showing argument to sys_capset */ #define AUDIT_MMAP 1323 /* Record showing descriptor and flags in mmap */ #define AUDIT_NETFILTER_PKT 1324 /* Packets traversing netfilter chains */ #define AUDIT_NETFILTER_CFG 1325 /* Netfilter chain modifications */ #define AUDIT_AVC 1400 /* SE Linux avc denial or grant */ #define AUDIT_SELINUX_ERR 1401 /* Internal SE Linux Errors */ #define AUDIT_AVC_PATH 1402 /* dentry, vfsmount pair from avc */ #define AUDIT_MAC_POLICY_LOAD 1403 /* Policy file load */ #define AUDIT_MAC_STATUS 1404 /* Changed enforcing,permissive,off */ #define AUDIT_MAC_CONFIG_CHANGE 1405 /* Changes to booleans */ #define AUDIT_MAC_UNLBL_ALLOW 1406 /* NetLabel: allow unlabeled traffic */ #define AUDIT_MAC_CIPSOV4_ADD 1407 /* NetLabel: add CIPSOv4 DOI entry */ #define AUDIT_MAC_CIPSOV4_DEL 1408 /* NetLabel: del CIPSOv4 DOI entry */ #define AUDIT_MAC_MAP_ADD 1409 /* NetLabel: add LSM domain mapping */ #define AUDIT_MAC_MAP_DEL 1410 /* NetLabel: del LSM domain mapping */ #define AUDIT_MAC_IPSEC_ADDSA 1411 /* Not used */ #define AUDIT_MAC_IPSEC_DELSA 1412 /* Not used */ #define AUDIT_MAC_IPSEC_ADDSPD 1413 /* Not used */ #define AUDIT_MAC_IPSEC_DELSPD 1414 /* Not used */ #define AUDIT_MAC_IPSEC_EVENT 1415 /* Audit an IPSec event */ #define AUDIT_MAC_UNLBL_STCADD 1416 /* NetLabel: add a static label */ #define AUDIT_MAC_UNLBL_STCDEL 1417 /* NetLabel: del a static label */ #define AUDIT_FIRST_KERN_ANOM_MSG 1700 #define AUDIT_LAST_KERN_ANOM_MSG 1799 #define AUDIT_ANOM_PROMISCUOUS 1700 /* Device changed promiscuous mode */ #define AUDIT_ANOM_ABEND 1701 /* Process ended abnormally */ #define AUDIT_INTEGRITY_DATA 1800 /* Data integrity verification */ #define AUDIT_INTEGRITY_METADATA 1801 /* Metadata integrity verification */ #define AUDIT_INTEGRITY_STATUS 1802 /* Integrity enable status */ #define AUDIT_INTEGRITY_HASH 1803 /* Integrity HASH type */ #define AUDIT_INTEGRITY_PCR 1804 /* PCR invalidation msgs */ #define AUDIT_INTEGRITY_RULE 1805 /* policy rule */ #define AUDIT_KERNEL 2000 /* Asynchronous audit record. NOT A REQUEST. */ /* Rule flags */ #define AUDIT_FILTER_USER 0x00 /* Apply rule to user-generated messages */ #define AUDIT_FILTER_TASK 0x01 /* Apply rule at task creation (not syscall) */ #define AUDIT_FILTER_ENTRY 0x02 /* Apply rule at syscall entry */ #define AUDIT_FILTER_WATCH 0x03 /* Apply rule to file system watches */ #define AUDIT_FILTER_EXIT 0x04 /* Apply rule at syscall exit */ #define AUDIT_FILTER_TYPE 0x05 /* Apply rule at audit_log_start */ #define AUDIT_NR_FILTERS 6 #define AUDIT_FILTER_PREPEND 0x10 /* Prepend to front of list */ /* Rule actions */ #define AUDIT_NEVER 0 /* Do not build context if rule matches */ #define AUDIT_POSSIBLE 1 /* Build context if rule matches */ #define AUDIT_ALWAYS 2 /* Generate audit record if rule matches */ /* Rule structure sizes -- if these change, different AUDIT_ADD and * AUDIT_LIST commands must be implemented. */ #define AUDIT_MAX_FIELDS 64 #define AUDIT_MAX_KEY_LEN 256 #define AUDIT_BITMASK_SIZE 64 #define AUDIT_WORD(nr) ((__u32)((nr)/32)) #define AUDIT_BIT(nr) (1 << ((nr) - AUDIT_WORD(nr)*32)) #define AUDIT_SYSCALL_CLASSES 16 #define AUDIT_CLASS_DIR_WRITE 0 #define AUDIT_CLASS_DIR_WRITE_32 1 #define AUDIT_CLASS_CHATTR 2 #define AUDIT_CLASS_CHATTR_32 3 #define AUDIT_CLASS_READ 4 #define AUDIT_CLASS_READ_32 5 #define AUDIT_CLASS_WRITE 6 #define AUDIT_CLASS_WRITE_32 7 #define AUDIT_CLASS_SIGNAL 8 #define AUDIT_CLASS_SIGNAL_32 9 /* This bitmask is used to validate user input. It represents all bits that * are currently used in an audit field constant understood by the kernel. * If you are adding a new #define AUDIT_<whatever>, please ensure that * AUDIT_UNUSED_BITS is updated if need be. */ #define AUDIT_UNUSED_BITS 0x07FFFC00 /* AUDIT_FIELD_COMPARE rule list */ #define AUDIT_COMPARE_UID_TO_OBJ_UID 1 #define AUDIT_COMPARE_GID_TO_OBJ_GID 2 #define AUDIT_COMPARE_EUID_TO_OBJ_UID 3 #define AUDIT_COMPARE_EGID_TO_OBJ_GID 4 #define AUDIT_COMPARE_AUID_TO_OBJ_UID 5 #define AUDIT_COMPARE_SUID_TO_OBJ_UID 6 #define AUDIT_COMPARE_SGID_TO_OBJ_GID 7 #define AUDIT_COMPARE_FSUID_TO_OBJ_UID 8 #define AUDIT_COMPARE_FSGID_TO_OBJ_GID 9 #define AUDIT_COMPARE_UID_TO_AUID 10 #define AUDIT_COMPARE_UID_TO_EUID 11 #define AUDIT_COMPARE_UID_TO_FSUID 12 #define AUDIT_COMPARE_UID_TO_SUID 13 #define AUDIT_COMPARE_AUID_TO_FSUID 14 #define AUDIT_COMPARE_AUID_TO_SUID 15 #define AUDIT_COMPARE_AUID_TO_EUID 16 #define AUDIT_COMPARE_EUID_TO_SUID 17 #define AUDIT_COMPARE_EUID_TO_FSUID 18 #define AUDIT_COMPARE_SUID_TO_FSUID 19 #define AUDIT_COMPARE_GID_TO_EGID 20 #define AUDIT_COMPARE_GID_TO_FSGID 21 #define AUDIT_COMPARE_GID_TO_SGID 22 #define AUDIT_COMPARE_EGID_TO_FSGID 23 #define AUDIT_COMPARE_EGID_TO_SGID 24 #define AUDIT_COMPARE_SGID_TO_FSGID 25 #define AUDIT_MAX_FIELD_COMPARE AUDIT_COMPARE_SGID_TO_FSGID /* Rule fields */ /* These are useful when checking the * task structure at task creation time * (AUDIT_PER_TASK). */ #define AUDIT_PID 0 #define AUDIT_UID 1 #define AUDIT_EUID 2 #define AUDIT_SUID 3 #define AUDIT_FSUID 4 #define AUDIT_GID 5 #define AUDIT_EGID 6 #define AUDIT_SGID 7 #define AUDIT_FSGID 8 #define AUDIT_LOGINUID 9 #define AUDIT_PERS 10 #define AUDIT_ARCH 11 #define AUDIT_MSGTYPE 12 #define AUDIT_SUBJ_USER 13 /* security label user */ #define AUDIT_SUBJ_ROLE 14 /* security label role */ #define AUDIT_SUBJ_TYPE 15 /* security label type */ #define AUDIT_SUBJ_SEN 16 /* security label sensitivity label */ #define AUDIT_SUBJ_CLR 17 /* security label clearance label */ #define AUDIT_PPID 18 #define AUDIT_OBJ_USER 19 #define AUDIT_OBJ_ROLE 20 #define AUDIT_OBJ_TYPE 21 #define AUDIT_OBJ_LEV_LOW 22 #define AUDIT_OBJ_LEV_HIGH 23 /* These are ONLY useful when checking * at syscall exit time (AUDIT_AT_EXIT). */ #define AUDIT_DEVMAJOR 100 #define AUDIT_DEVMINOR 101 #define AUDIT_INODE 102 #define AUDIT_EXIT 103 #define AUDIT_SUCCESS 104 /* exit >= 0; value ignored */ #define AUDIT_WATCH 105 #define AUDIT_PERM 106 #define AUDIT_DIR 107 #define AUDIT_FILETYPE 108 #define AUDIT_OBJ_UID 109 #define AUDIT_OBJ_GID 110 #define AUDIT_FIELD_COMPARE 111 #define AUDIT_ARG0 200 #define AUDIT_ARG1 (AUDIT_ARG0+1) #define AUDIT_ARG2 (AUDIT_ARG0+2) #define AUDIT_ARG3 (AUDIT_ARG0+3) #define AUDIT_FILTERKEY 210 #define AUDIT_NEGATE 0x80000000 /* These are the supported operators. * 4 2 1 8 * = > < ? * ---------- * 0 0 0 0 00 nonsense * 0 0 0 1 08 & bit mask * 0 0 1 0 10 < * 0 1 0 0 20 > * 0 1 1 0 30 != * 1 0 0 0 40 = * 1 0 0 1 48 &= bit test * 1 0 1 0 50 <= * 1 1 0 0 60 >= * 1 1 1 1 78 all operators */ #define AUDIT_BIT_MASK 0x08000000 #define AUDIT_LESS_THAN 0x10000000 #define AUDIT_GREATER_THAN 0x20000000 #define AUDIT_NOT_EQUAL 0x30000000 #define AUDIT_EQUAL 0x40000000 #define AUDIT_BIT_TEST (AUDIT_BIT_MASK|AUDIT_EQUAL) #define AUDIT_LESS_THAN_OR_EQUAL (AUDIT_LESS_THAN|AUDIT_EQUAL) #define AUDIT_GREATER_THAN_OR_EQUAL (AUDIT_GREATER_THAN|AUDIT_EQUAL) #define AUDIT_OPERATORS (AUDIT_EQUAL|AUDIT_NOT_EQUAL|AUDIT_BIT_MASK) enum { Audit_equal, Audit_not_equal, Audit_bitmask, Audit_bittest, Audit_lt, Audit_gt, Audit_le, Audit_ge, Audit_bad }; /* Status symbols */ /* Mask values */ #define AUDIT_STATUS_ENABLED 0x0001 #define AUDIT_STATUS_FAILURE 0x0002 #define AUDIT_STATUS_PID 0x0004 #define AUDIT_STATUS_RATE_LIMIT 0x0008 #define AUDIT_STATUS_BACKLOG_LIMIT 0x0010 /* Failure-to-log actions */ #define AUDIT_FAIL_SILENT 0 #define AUDIT_FAIL_PRINTK 1 #define AUDIT_FAIL_PANIC 2 /* distinguish syscall tables */ #define __AUDIT_ARCH_64BIT 0x80000000 #define __AUDIT_ARCH_LE 0x40000000 #define AUDIT_ARCH_ALPHA (EM_ALPHA|__AUDIT_ARCH_64BIT|__AUDIT_ARCH_LE) #define AUDIT_ARCH_ARM (EM_ARM|__AUDIT_ARCH_LE) #define AUDIT_ARCH_ARMEB (EM_ARM) #define AUDIT_ARCH_CRIS (EM_CRIS|__AUDIT_ARCH_LE) #define AUDIT_ARCH_FRV (EM_FRV) #define AUDIT_ARCH_H8300 (EM_H8_300) #define AUDIT_ARCH_I386 (EM_386|__AUDIT_ARCH_LE) #define AUDIT_ARCH_IA64 (EM_IA_64|__AUDIT_ARCH_64BIT|__AUDIT_ARCH_LE) #define AUDIT_ARCH_M32R (EM_M32R) #define AUDIT_ARCH_M68K (EM_68K) #define AUDIT_ARCH_MIPS (EM_MIPS) #define AUDIT_ARCH_MIPSEL (EM_MIPS|__AUDIT_ARCH_LE) #define AUDIT_ARCH_MIPS64 (EM_MIPS|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_MIPSEL64 (EM_MIPS|__AUDIT_ARCH_64BIT|__AUDIT_ARCH_LE) #define AUDIT_ARCH_PARISC (EM_PARISC) #define AUDIT_ARCH_PARISC64 (EM_PARISC|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_PPC (EM_PPC) #define AUDIT_ARCH_PPC64 (EM_PPC64|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_S390 (EM_S390) #define AUDIT_ARCH_S390X (EM_S390|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_SH (EM_SH) #define AUDIT_ARCH_SHEL (EM_SH|__AUDIT_ARCH_LE) #define AUDIT_ARCH_SH64 (EM_SH|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_SHEL64 (EM_SH|__AUDIT_ARCH_64BIT|__AUDIT_ARCH_LE) #define AUDIT_ARCH_SPARC (EM_SPARC) #define AUDIT_ARCH_SPARC64 (EM_SPARCV9|__AUDIT_ARCH_64BIT) #define AUDIT_ARCH_X86_64 (EM_X86_64|__AUDIT_ARCH_64BIT|__AUDIT_ARCH_LE) #define AUDIT_PERM_EXEC 1 #define AUDIT_PERM_WRITE 2 #define AUDIT_PERM_READ 4 #define AUDIT_PERM_ATTR 8 struct audit_status { __u32 mask; /* Bit mask for valid entries */ __u32 enabled; /* 1 = enabled, 0 = disabled */ __u32 failure; /* Failure-to-log action */ __u32 pid; /* pid of auditd process */ __u32 rate_limit; /* messages rate limit (per second) */ __u32 backlog_limit; /* waiting messages limit */ __u32 lost; /* messages lost */ __u32 backlog; /* messages waiting in queue */ }; struct audit_tty_status { __u32 enabled; /* 1 = enabled, 0 = disabled */ __u32 log_passwd; /* 1 = enabled, 0 = disabled */ }; /* audit_rule_data supports filter rules with both integer and string * fields. It corresponds with AUDIT_ADD_RULE, AUDIT_DEL_RULE and * AUDIT_LIST_RULES requests. */ struct audit_rule_data { __u32 flags; /* AUDIT_PER_{TASK,CALL}, AUDIT_PREPEND */ __u32 action; /* AUDIT_NEVER, AUDIT_POSSIBLE, AUDIT_ALWAYS */ __u32 field_count; __u32 mask[AUDIT_BITMASK_SIZE]; /* syscall(s) affected */ __u32 fields[AUDIT_MAX_FIELDS]; __u32 values[AUDIT_MAX_FIELDS]; __u32 fieldflags[AUDIT_MAX_FIELDS]; __u32 buflen; /* total length of string fields */ char buf[0]; /* string fields buffer */ }; /* audit_rule is supported to maintain backward compatibility with * userspace. It supports integer fields only and corresponds to * AUDIT_ADD, AUDIT_DEL and AUDIT_LIST requests. */ struct audit_rule { /* for AUDIT_LIST, AUDIT_ADD, and AUDIT_DEL */ __u32 flags; /* AUDIT_PER_{TASK,CALL}, AUDIT_PREPEND */ __u32 action; /* AUDIT_NEVER, AUDIT_POSSIBLE, AUDIT_ALWAYS */ __u32 field_count; __u32 mask[AUDIT_BITMASK_SIZE]; __u32 fields[AUDIT_MAX_FIELDS]; __u32 values[AUDIT_MAX_FIELDS]; }; #endif
Save
cmd:
run