]> Git Repo - linux.git/commit - security/selinux/hooks.c
SELinux: Convert avc_audit to use lsm_audit.h
authorThomas Liu <[email protected]>
Tue, 14 Jul 2009 16:14:09 +0000 (12:14 -0400)
committerJames Morris <[email protected]>
Sun, 16 Aug 2009 22:37:18 +0000 (08:37 +1000)
commit2bf49690325b62480a42f7afed5e9f164173c570
treebc8525f6a45ea3ffaed9449084df7644bcd4e3c2
parentf322abf83feddc3c37c3a91794e0c5aece4af18e
SELinux: Convert avc_audit to use lsm_audit.h

Convert avc_audit in security/selinux/avc.c to use lsm_audit.h,
for better maintainability.

 - changed selinux to use common_audit_data instead of
    avc_audit_data
 - eliminated code in avc.c and used code from lsm_audit.h instead.

Had to add a LSM_AUDIT_NO_AUDIT to lsm_audit.h so that avc_audit
can call common_lsm_audit and do the pre and post callbacks without
doing the actual dump.  This makes it so that the patched version
behaves the same way as the unpatched version.

Also added a denied field to the selinux_audit_data private space,
once again to make it so that the patched version behaves like the
unpatched.

I've tested and confirmed that AVCs look the same before and after
this patch.

Signed-off-by: Thomas Liu <[email protected]>
Acked-by: Stephen Smalley <[email protected]>
Signed-off-by: James Morris <[email protected]>
include/linux/lsm_audit.h
security/Makefile
security/lsm_audit.c
security/selinux/avc.c
security/selinux/hooks.c
security/selinux/include/avc.h
security/selinux/include/netlabel.h
security/selinux/include/xfrm.h
security/selinux/netlabel.c
security/selinux/xfrm.c
This page took 0.056947 seconds and 4 git commands to generate.