Commit 42f355ef authored by Richard Guy Briggs's avatar Richard Guy Briggs Committed by Paul Moore

audit: replace magic audit syscall class numbers with macros

Replace audit syscall class magic numbers with macros.

This required putting the macros into new header file
include/linux/audit_arch.h since the syscall macros were
included for both 64 bit and 32 bit in any compat code, causing
redefinition warnings.

Link: https://lore.kernel.org/r/2300b1083a32aade7ae7efb95826e8f3f260b1df.1621363275.git.rgb@redhat.comSigned-off-by: default avatarRichard Guy Briggs <rgb@redhat.com>
Acked-by: default avatarChristian Brauner <christian.brauner@ubuntu.com>
[PM: renamed header to audit_arch.h after consulting with Richard]
Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
parent 8e71168e
...@@ -3113,6 +3113,7 @@ W: https://github.com/linux-audit ...@@ -3113,6 +3113,7 @@ W: https://github.com/linux-audit
T: git git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit.git T: git git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/audit.git
F: include/asm-generic/audit_*.h F: include/asm-generic/audit_*.h
F: include/linux/audit.h F: include/linux/audit.h
F: include/linux/audit_arch.h
F: include/uapi/linux/audit.h F: include/uapi/linux/audit.h
F: kernel/audit* F: kernel/audit*
F: lib/*audit.c F: lib/*audit.c
......
...@@ -37,13 +37,13 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -37,13 +37,13 @@ int audit_classify_syscall(int abi, unsigned syscall)
{ {
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
...@@ -38,13 +38,13 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -38,13 +38,13 @@ int audit_classify_syscall(int abi, unsigned syscall)
{ {
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
...@@ -47,13 +47,13 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -47,13 +47,13 @@ int audit_classify_syscall(int abi, unsigned syscall)
#endif #endif
switch (syscall) { switch (syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#include <linux/audit_arch.h>
#include <asm/unistd.h> #include <asm/unistd.h>
unsigned int parisc32_dir_class[] = { unsigned int parisc32_dir_class[] = {
...@@ -30,12 +31,12 @@ int parisc32_classify_syscall(unsigned syscall) ...@@ -30,12 +31,12 @@ int parisc32_classify_syscall(unsigned syscall)
{ {
switch (syscall) { switch (syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
...@@ -47,15 +47,15 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -47,15 +47,15 @@ int audit_classify_syscall(int abi, unsigned syscall)
#endif #endif
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#undef __powerpc64__ #undef __powerpc64__
#include <linux/audit_arch.h>
#include <asm/unistd.h> #include <asm/unistd.h>
unsigned ppc32_dir_class[] = { unsigned ppc32_dir_class[] = {
...@@ -31,14 +32,14 @@ int ppc32_classify_syscall(unsigned syscall) ...@@ -31,14 +32,14 @@ int ppc32_classify_syscall(unsigned syscall)
{ {
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
...@@ -47,15 +47,15 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -47,15 +47,15 @@ int audit_classify_syscall(int abi, unsigned syscall)
#endif #endif
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#undef __s390x__ #undef __s390x__
#include <linux/audit_arch.h>
#include <asm/unistd.h> #include <asm/unistd.h>
#include "audit.h" #include "audit.h"
...@@ -32,14 +33,14 @@ int s390_classify_syscall(unsigned syscall) ...@@ -32,14 +33,14 @@ int s390_classify_syscall(unsigned syscall)
{ {
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
...@@ -48,15 +48,15 @@ int audit_classify_syscall(int abi, unsigned int syscall) ...@@ -48,15 +48,15 @@ int audit_classify_syscall(int abi, unsigned int syscall)
#endif #endif
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#define __32bit_syscall_numbers__ #define __32bit_syscall_numbers__
#include <linux/audit_arch.h>
#include <asm/unistd.h> #include <asm/unistd.h>
#include "kernel.h" #include "kernel.h"
...@@ -32,14 +33,14 @@ int sparc32_classify_syscall(unsigned int syscall) ...@@ -32,14 +33,14 @@ int sparc32_classify_syscall(unsigned int syscall)
{ {
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#include <linux/audit_arch.h>
#include <asm/unistd_32.h> #include <asm/unistd_32.h>
#include <asm/audit.h> #include <asm/audit.h>
...@@ -31,15 +32,15 @@ int ia32_classify_syscall(unsigned syscall) ...@@ -31,15 +32,15 @@ int ia32_classify_syscall(unsigned syscall)
{ {
switch (syscall) { switch (syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
case __NR_execve: case __NR_execve:
case __NR_execveat: case __NR_execveat:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
...@@ -47,14 +47,14 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -47,14 +47,14 @@ int audit_classify_syscall(int abi, unsigned syscall)
#endif #endif
switch(syscall) { switch(syscall) {
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
case __NR_execve: case __NR_execve:
case __NR_execveat: case __NR_execveat:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
...@@ -11,6 +11,7 @@ ...@@ -11,6 +11,7 @@
#include <linux/sched.h> #include <linux/sched.h>
#include <linux/ptrace.h> #include <linux/ptrace.h>
#include <linux/audit_arch.h>
#include <uapi/linux/audit.h> #include <uapi/linux/audit.h>
#include <uapi/linux/netfilter/nf_tables.h> #include <uapi/linux/netfilter/nf_tables.h>
......
/* SPDX-License-Identifier: GPL-2.0-or-later */
/* audit_arch.h -- Arch layer specific support for audit
*
* Copyright 2021 Red Hat Inc., Durham, North Carolina.
* All Rights Reserved.
*
* Author: Richard Guy Briggs <rgb@redhat.com>
*/
#ifndef _LINUX_AUDIT_ARCH_H_
#define _LINUX_AUDIT_ARCH_H_
enum auditsc_class_t {
AUDITSC_NATIVE = 0,
AUDITSC_COMPAT,
AUDITSC_OPEN,
AUDITSC_OPENAT,
AUDITSC_SOCKETCALL,
AUDITSC_EXECVE,
AUDITSC_NVALS /* count */
};
#endif
...@@ -153,7 +153,7 @@ static int audit_match_perm(struct audit_context *ctx, int mask) ...@@ -153,7 +153,7 @@ static int audit_match_perm(struct audit_context *ctx, int mask)
n = ctx->major; n = ctx->major;
switch (audit_classify_syscall(ctx->arch, n)) { switch (audit_classify_syscall(ctx->arch, n)) {
case 0: /* native */ case AUDITSC_NATIVE:
if ((mask & AUDIT_PERM_WRITE) && if ((mask & AUDIT_PERM_WRITE) &&
audit_match_class(AUDIT_CLASS_WRITE, n)) audit_match_class(AUDIT_CLASS_WRITE, n))
return 1; return 1;
...@@ -164,7 +164,7 @@ static int audit_match_perm(struct audit_context *ctx, int mask) ...@@ -164,7 +164,7 @@ static int audit_match_perm(struct audit_context *ctx, int mask)
audit_match_class(AUDIT_CLASS_CHATTR, n)) audit_match_class(AUDIT_CLASS_CHATTR, n))
return 1; return 1;
return 0; return 0;
case 1: /* 32bit on biarch */ case AUDITSC_COMPAT: /* 32bit on biarch */
if ((mask & AUDIT_PERM_WRITE) && if ((mask & AUDIT_PERM_WRITE) &&
audit_match_class(AUDIT_CLASS_WRITE_32, n)) audit_match_class(AUDIT_CLASS_WRITE_32, n))
return 1; return 1;
...@@ -175,13 +175,13 @@ static int audit_match_perm(struct audit_context *ctx, int mask) ...@@ -175,13 +175,13 @@ static int audit_match_perm(struct audit_context *ctx, int mask)
audit_match_class(AUDIT_CLASS_CHATTR_32, n)) audit_match_class(AUDIT_CLASS_CHATTR_32, n))
return 1; return 1;
return 0; return 0;
case 2: /* open */ case AUDITSC_OPEN:
return mask & ACC_MODE(ctx->argv[1]); return mask & ACC_MODE(ctx->argv[1]);
case 3: /* openat */ case AUDITSC_OPENAT:
return mask & ACC_MODE(ctx->argv[2]); return mask & ACC_MODE(ctx->argv[2]);
case 4: /* socketcall */ case AUDITSC_SOCKETCALL:
return ((mask & AUDIT_PERM_WRITE) && ctx->argv[0] == SYS_BIND); return ((mask & AUDIT_PERM_WRITE) && ctx->argv[0] == SYS_BIND);
case 5: /* execve */ case AUDITSC_EXECVE:
return mask & AUDIT_PERM_EXEC; return mask & AUDIT_PERM_EXEC;
default: default:
return 0; return 0;
......
...@@ -45,23 +45,23 @@ int audit_classify_syscall(int abi, unsigned syscall) ...@@ -45,23 +45,23 @@ int audit_classify_syscall(int abi, unsigned syscall)
switch(syscall) { switch(syscall) {
#ifdef __NR_open #ifdef __NR_open
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
#endif #endif
#ifdef __NR_openat #ifdef __NR_openat
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
#endif #endif
#ifdef __NR_socketcall #ifdef __NR_socketcall
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
#endif #endif
#ifdef __NR_execveat #ifdef __NR_execveat
case __NR_execveat: case __NR_execveat:
#endif #endif
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 0; return AUDITSC_NATIVE;
} }
} }
......
// SPDX-License-Identifier: GPL-2.0 // SPDX-License-Identifier: GPL-2.0
#include <linux/init.h> #include <linux/init.h>
#include <linux/types.h> #include <linux/types.h>
#include <linux/audit_arch.h>
#include <asm/unistd32.h> #include <asm/unistd32.h>
unsigned compat_dir_class[] = { unsigned compat_dir_class[] = {
...@@ -33,19 +34,19 @@ int audit_classify_compat_syscall(int abi, unsigned syscall) ...@@ -33,19 +34,19 @@ int audit_classify_compat_syscall(int abi, unsigned syscall)
switch (syscall) { switch (syscall) {
#ifdef __NR_open #ifdef __NR_open
case __NR_open: case __NR_open:
return 2; return AUDITSC_OPEN;
#endif #endif
#ifdef __NR_openat #ifdef __NR_openat
case __NR_openat: case __NR_openat:
return 3; return AUDITSC_OPENAT;
#endif #endif
#ifdef __NR_socketcall #ifdef __NR_socketcall
case __NR_socketcall: case __NR_socketcall:
return 4; return AUDITSC_SOCKETCALL;
#endif #endif
case __NR_execve: case __NR_execve:
return 5; return AUDITSC_EXECVE;
default: default:
return 1; return AUDITSC_COMPAT;
} }
} }
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment