The audit subsystem allows selecting audit events based on watches for a particular behavior like writing to a file. A lot of syscalls have been added without updating the list. This patch adds 2 syscalls to the write filters: fallocate and renameat2. Signed-off-by: Steve Grubb <sgrubb@redhat.com> Reviewed-by: Richard Guy Briggs <rgb@redhat.com> [PM: cleaned up some whitespace errors] Signed-off-by: Paul Moore <paul@paul-moore.com>
24 lines
422 B
C
24 lines
422 B
C
#include <asm-generic/audit_dir_write.h>
|
|
__NR_acct,
|
|
#ifdef __NR_swapon
|
|
__NR_swapon,
|
|
#endif
|
|
__NR_quotactl,
|
|
#ifdef __NR_truncate
|
|
__NR_truncate,
|
|
#endif
|
|
#ifdef __NR_truncate64
|
|
__NR_truncate64,
|
|
#endif
|
|
#ifdef __NR_ftruncate
|
|
__NR_ftruncate,
|
|
#endif
|
|
#ifdef __NR_ftruncate64
|
|
__NR_ftruncate64,
|
|
#endif
|
|
#ifdef __NR_bind
|
|
__NR_bind, /* bind can affect fs object only in one way... */
|
|
#endif
|
|
#ifdef __NR_fallocate
|
|
__NR_fallocate,
|
|
#endif
|