函数逻辑报告 |
Source Code:kernel\auditfilter.c |
Create Date:2022-07-27 12:28:16 |
| Last Modify:2020-03-12 14:18:49 | Copyright©Brick |
| 首页 | 函数Tree |
| 注解内核,赢得工具 | 下载SCCT | English |
函数名称:Duplicate an audit rule. This will be a deep copy with the exception* of the watch - that pointer is carried over. The LSM specific fields* will be updated in the copy. The point is to be able to replace the old
函数原型:struct audit_entry *audit_dupe_rule(struct audit_krule *old)
返回类型:struct audit_entry
参数:
| 类型 | 参数 | 名称 |
|---|---|---|
| struct audit_krule * | old |
| 813 | fcount等于field_count |
| 817 | err等于0 |
| 820 | 如果此条件成立可能性小(为编译器优化)(!entry)则返回:错误号 |
| 833 | field_count等于field_count |
| 849 | 当:type恒等于security label user |
| 850 | 当:type恒等于security label role |
| 851 | 当:type恒等于security label type |
| 854 | 当:type恒等于AUDIT_OBJ_USER |
| 855 | 当:type恒等于AUDIT_OBJ_ROLE |
| 856 | 当:type恒等于AUDIT_OBJ_TYPE |
| 857 | 当:type恒等于AUDIT_OBJ_LEV_LOW |
| 858 | 当:type恒等于AUDIT_OBJ_LEV_HIGH |
| 861 | 退出 |
| 862 | 当:type恒等于AUDIT_FILTERKEY |
| 863 | fk等于kstrdup( ties events to rules , GFP_KERNEL) |
| 864 | 如果此条件成立可能性小(为编译器优化)(!fk)则err等于负ENOMEM |
| 866 | 否则 ties events to rules 等于fk |
| 868 | 退出 |
| 870 | err等于audit_dupe_exe(new, old) |
| 871 | 退出 |
| 873 | 如果err则 |
| 881 | 如果 associated watch 则 |
| 883 | associated watch 等于 associated watch |
| 886 | 返回:entry |
| 名称 | 描述 |
|---|---|
| update_lsm_rule | |
| audit_update_watch | Update inode info in audit rules based on filesystem event. |
| 源代码转换工具 开放的插件接口 | X |
|---|---|
| 支持:c/c++/esqlc/java Oracle/Informix/Mysql 插件可实现:逻辑报告 代码生成和批量转换代码 |