]> granicus.if.org Git - strace/blob - xlat/nl_audit_types.in
tests: check decoding of vcpu auxstr
[strace] / xlat / nl_audit_types.in
1 AUDIT_GET       1000
2 AUDIT_SET       1001
3 AUDIT_LIST      1002
4 AUDIT_ADD       1003
5 AUDIT_DEL       1004
6 AUDIT_USER      1005
7 AUDIT_LOGIN     1006
8 AUDIT_WATCH_INS 1007
9 AUDIT_WATCH_REM 1008
10 AUDIT_WATCH_LIST        1009
11 AUDIT_SIGNAL_INFO       1010
12 AUDIT_ADD_RULE  1011
13 AUDIT_DEL_RULE  1012
14 AUDIT_LIST_RULES        1013
15 AUDIT_TRIM      1014
16 AUDIT_MAKE_EQUIV        1015
17 AUDIT_TTY_GET   1016
18 AUDIT_TTY_SET   1017
19 AUDIT_SET_FEATURE       1018
20 AUDIT_GET_FEATURE       1019
21
22 AUDIT_FIRST_USER_MSG    1100
23 AUDIT_USER_AVC  1107
24 AUDIT_USER_TTY  1124
25 AUDIT_LAST_USER_MSG     1199
26
27 AUDIT_DAEMON_START      1200
28 AUDIT_DAEMON_END        1201
29 AUDIT_DAEMON_ABORT      1202
30 AUDIT_DAEMON_CONFIG     1203
31
32 AUDIT_SYSCALL   1300
33 AUDIT_FS_WATCH  1301
34 AUDIT_PATH      1302
35 AUDIT_IPC       1303
36 AUDIT_SOCKETCALL        1304
37 AUDIT_CONFIG_CHANGE     1305
38 AUDIT_SOCKADDR  1306
39 AUDIT_CWD       1307
40 AUDIT_EXECVE    1309
41 AUDIT_IPC_SET_PERM      1311
42 AUDIT_MQ_OPEN   1312
43 AUDIT_MQ_SENDRECV       1313
44 AUDIT_MQ_NOTIFY 1314
45 AUDIT_MQ_GETSETATTR     1315
46 AUDIT_KERNEL_OTHER      1316
47 AUDIT_FD_PAIR   1317
48 AUDIT_OBJ_PID   1318
49 AUDIT_TTY       1319
50 AUDIT_EOE       1320
51 AUDIT_BPRM_FCAPS        1321
52 AUDIT_CAPSET    1322
53 AUDIT_MMAP      1323
54 AUDIT_NETFILTER_PKT     1324
55 AUDIT_NETFILTER_CFG     1325
56 AUDIT_SECCOMP   1326
57 AUDIT_PROCTITLE 1327
58
59 #ifndef STRACE_WORKAROUND_FOR_AUDIT_FEATURE_CHANGE
60 # define STRACE_WORKAROUND_FOR_AUDIT_FEATURE_CHANGE
61 /*
62  * Linux kernel commit v3.15-rc1~18^2~1 has changed the value
63  * of AUDIT_FEATURE_CHANGE constant introduced by commit v3.13-rc1~19^2~20
64  * which is of course an ABI breakage that affected 3.13 and 3.14 kernel
65  * releases as well as their LTS derivatives.
66  * Linux kernel commit v3.15-rc1~18^2~1 also claims that the old value
67  * of AUDIT_FEATURE_CHANGE was ignored by userspace because of the established
68  * convention how netlink messages for the audit system are divided into blocks.
69  * Looks like the best way to handle this situation is to pretend that
70  * the old value of AUDIT_FEATURE_CHANGE didn't exist.
71  */
72 # undef AUDIT_FEATURE_CHANGE
73 #endif
74 AUDIT_FEATURE_CHANGE    1328
75
76 AUDIT_REPLACE   1329
77 AUDIT_KERN_MODULE       1330
78
79 AUDIT_AVC       1400
80 AUDIT_SELINUX_ERR       1401
81 AUDIT_AVC_PATH  1402
82 AUDIT_MAC_POLICY_LOAD   1403
83 AUDIT_MAC_STATUS        1404
84 AUDIT_MAC_CONFIG_CHANGE 1405
85 AUDIT_MAC_UNLBL_ALLOW   1406
86 AUDIT_MAC_CIPSOV4_ADD   1407
87 AUDIT_MAC_CIPSOV4_DEL   1408
88 AUDIT_MAC_MAP_ADD       1409
89 AUDIT_MAC_MAP_DEL       1410
90 AUDIT_MAC_IPSEC_ADDSA   1411
91 AUDIT_MAC_IPSEC_DELSA   1412
92 AUDIT_MAC_IPSEC_ADDSPD  1413
93 AUDIT_MAC_IPSEC_DELSPD  1414
94 AUDIT_MAC_IPSEC_EVENT   1415
95 AUDIT_MAC_UNLBL_STCADD  1416
96 AUDIT_MAC_UNLBL_STCDEL  1417
97 AUDIT_MAC_CALIPSO_ADD   1418
98 AUDIT_MAC_CALIPSO_DEL   1419
99
100 AUDIT_ANOM_PROMISCUOUS  1700
101 AUDIT_ANOM_ABEND        1701
102 AUDIT_ANOM_LINK 1702
103 AUDIT_LAST_KERN_ANOM_MSG        1799
104
105 AUDIT_INTEGRITY_DATA    1800
106 AUDIT_INTEGRITY_METADATA        1801
107 AUDIT_INTEGRITY_STATUS  1802
108 AUDIT_INTEGRITY_HASH    1803
109 AUDIT_INTEGRITY_PCR     1804
110 AUDIT_INTEGRITY_RULE    1805
111 AUDIT_INTEGRITY_EVM_XATTR       1806
112
113 AUDIT_KERNEL    2000
114
115 AUDIT_FIRST_USER_MSG2   2100
116 AUDIT_LAST_USER_MSG2    2999