1 // SPDX-License-Identifier: GPL-2.0-only
3 * Copyright (C) 2008 IBM Corporation
4 * Author: Mimi Zohar <zohar@us.ibm.com>
6 * File: integrity_audit.c
7 * Audit calls for the integrity subsystem
11 #include <linux/gfp.h>
12 #include <linux/audit.h>
13 #include "integrity.h"
15 static int integrity_audit_info
;
17 /* ima_audit_setup - enable informational auditing messages */
18 static int __init
integrity_audit_setup(char *str
)
22 if (!kstrtoul(str
, 0, &audit
))
23 integrity_audit_info
= audit
? 1 : 0;
26 __setup("integrity_audit=", integrity_audit_setup
);
28 void integrity_audit_msg(int audit_msgno
, struct inode
*inode
,
29 const unsigned char *fname
, const char *op
,
30 const char *cause
, int result
, int audit_info
)
32 struct audit_buffer
*ab
;
33 char name
[TASK_COMM_LEN
];
35 if (!integrity_audit_info
&& audit_info
== 1) /* Skip info messages */
38 ab
= audit_log_start(audit_context(), GFP_KERNEL
, audit_msgno
);
39 audit_log_format(ab
, "pid=%d uid=%u auid=%u ses=%u",
41 from_kuid(&init_user_ns
, current_cred()->uid
),
42 from_kuid(&init_user_ns
, audit_get_loginuid(current
)),
43 audit_get_sessionid(current
));
44 audit_log_task_context(ab
);
45 audit_log_format(ab
, " op=%s cause=%s comm=", op
, cause
);
46 audit_log_untrustedstring(ab
, get_task_comm(name
, current
));
48 audit_log_format(ab
, " name=");
49 audit_log_untrustedstring(ab
, fname
);
52 audit_log_format(ab
, " dev=");
53 audit_log_untrustedstring(ab
, inode
->i_sb
->s_id
);
54 audit_log_format(ab
, " ino=%lu", inode
->i_ino
);
56 audit_log_format(ab
, " res=%d", !result
);