函数逻辑报告 |
Source Code:kernel\audit_watch.c |
Create Date:2022-07-27 12:32:31 |
| Last Modify:2020-03-17 17:15:07 | Copyright©Brick |
| 首页 | 函数Tree |
| 注解内核,赢得工具 | 下载SCCT | English |
函数名称:Update inode info in audit rules based on filesystem event.
函数原型:static void audit_update_watch(struct audit_parent *parent, const struct qstr *dname, dev_t dev, unsigned long ino, unsigned invalidating)
返回类型:void
参数:
| 类型 | 参数 | 名称 |
|---|---|---|
| struct audit_parent * | parent | |
| const struct qstr * | dname | |
| dev_t | dev | |
| unsigned long | ino | |
| unsigned | invalidating |
| 252 | mutex_lock( & audit_filter_mutex) |
| 267 | nwatch等于Duplicate the given audit watch. The new watch's rules list is initialized* to an empty list and wlist is undefined. |
| 268 | 如果是错误则 |
| 270 | audit_panic("error updating watch, skipping") |
| 271 | 返回 |
| 274 | associated inode number 等于ino |
| 279 | 删除链表项 |
| 280 | 删除不需要重新初始化的列表项 |
| 283 | 如果是错误则 |
| 284 | 删除链表项 |
| 285 | audit_panic("error updating watch, removing") |
| 286 | 否则 |
| 287 | h等于audit_hash_ino((u32)ino) |
| 294 | audit_put_watch( associated watch ) |
| 295 | audit_get_watch(nwatch) |
| 296 | associated watch 等于nwatch |
| 297 | 添加链表项 |
| 298 | 添加RCU保护项 |
| 299 | 更新链表项 |
| 302 | 如果exe则 |
| 305 | audit_watch_log_rule_change(r, owatch, "updated_rules") |
| 310 | audit_remove_watch(owatch) |
| 311 | 转到:add_watch_to_parent |
| 314 | 返回 |
| 316 | add_watch_to_parent : |
| 317 | 添加链表项 |
| 319 | 返回 |
| 名称 | 描述 |
|---|---|
| audit_watch_handle_event | Update watch data in audit rules based on fsnotify events. |
| 源代码转换工具 开放的插件接口 | X |
|---|---|
| 支持:c/c++/esqlc/java Oracle/Informix/Mysql 插件可实现:逻辑报告 代码生成和批量转换代码 |