Function report |
Source Code:kernel\audit_watch.c |
Create Date:2022-07-28 11:29:10 |
| Last Modify:2020-03-17 17:15:07 | Copyright©Brick |
| home page | Tree |
| Annotation kernel can get tool activity | Download SCCT | Chinese |
Name:Update inode info in audit rules based on filesystem event.
Proto:static void audit_update_watch(struct audit_parent *parent, const struct qstr *dname, dev_t dev, unsigned long ino, unsigned invalidating)
Type:void
Parameter:
| Type | Parameter | Name |
|---|---|---|
| struct audit_parent * | parent | |
| const struct qstr * | dname | |
| dev_t | dev | |
| unsigned long | ino | |
| unsigned | invalidating |
| 252 | mutex_lock( & audit_filter_mutex) |
| 267 | nwatch = Duplicate the given audit watch. The new watch's rules list is initialized* to an empty list and wlist is undefined. |
| 270 | audit_panic("error updating watch, skipping") |
| 271 | Return |
| 274 | associated inode number = ino |
| 285 | audit_panic("error updating watch, removing") |
| 286 | Else |
| 287 | h = audit_hash_ino((u32)ino) |
| 294 | audit_put_watch( associated watch ) |
| 295 | audit_get_watch(nwatch) |
| 296 | associated watch = nwatch |
| 302 | If exe Then |
| 305 | audit_watch_log_rule_change(r, owatch, "updated_rules") |
| 310 | audit_remove_watch(owatch) |
| 311 | Go to add_watch_to_parent |
| 314 | Return |
| 316 | add_watch_to_parent : |
| 319 | Return |
| Name | Describe |
|---|---|
| audit_watch_handle_event | Update watch data in audit rules based on fsnotify events. |
| Source code conversion tool public plug-in interface | X |
|---|---|
| Support c/c++/esqlc/java Oracle/Informix/Mysql Plug-in can realize: logical Report Code generation and batch code conversion |