Not upstream yet*/.
User's account locked by admin */.
User's account unlocked by admin */.
Add syscall rule -- deprecated */.
User space group added */.
Add syscall filtering rule */.
User space user account added */.
Generate audit record if rule matches */.
Process ended abnormally */.
Access of file or dir.
Adding an acct.
AMTU failure.
Crypto system test failure.
Deleting an acct.
Execution of file.
Suspicious use of file links */.
Login attempted to watched acct.
Failed login limit reached.
Login from forbidden location.
Max concurrent sessions reached.
Login attempted at bad time.
Max DAC failures reached.
Max MAC failures reached.
Make an executable.
Changing an acct.
Device changed promiscuous mode */.
RBAC self test failure.
RBAC file Tegrity failure.
User became root.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
AUDIT_ARCH_OPENRISC = (EM_OPENRISC) AUDIT_ARCH_PARISC = (EM_PARISC) AUDIT_ARCH_PARISC64 = (EM_PARISC | __AUDIT_ARCH_64BIT).
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
SE Linux avc denial or grant */.
dentry, vfsmount pair from avc */.
No description provided by the author
No description provided by the author
No description provided by the author
Information about fcaps increasing perms */.
Record showing argument to sys_capset */.
User space group ID changed */.
Changed user ID supplemental data */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
Field Comparing Constants.
No description provided by the author
Audit system configuration change */.
User space credential acquired */.
User space credential disposed */.
User space credential refreshed */.
Fail decrypt,encrypt,randomiz */.
Record parameters related to IKE SA */.
Record parameters related to IPSEC SA */.
Create,delete,negotiate */.
Logged in as crypto officer */.
Logged out from crypto */.
Crypto attribute change */.
Crypto replay detected */.
Record parameters set during TLS session establishment */.
Crypto test results */.
Current working directory */.
User space DAC check results */.
Auditd accepted remote connection */.
Auditd closed remote connection */.
Daemon config change */.
Auditd should reconfigure */.
Auditd should resume logging */.
Auditd should rotate logs */.
Delete syscall rule -- deprecated */.
User space group deleted */.
Delete syscall filtering rule */.
User space user account deleted */.
Device was allocated */.
Device was deallocated */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
End of multi-record event */.
No description provided by the author
No description provided by the author
No description provided by the author
execve arguments */.
No description provided by the author
No description provided by the author
No description provided by the author
Failure-to-log actions */.
audit record for pipe/socketpair */.
audit log listing feature changes */.
No description provided by the author
No description provided by the author
Apply rule at syscall entry */.
No description provided by the author
Apply rule at syscall exit */.
Mask to get actual filter */.
Mask to prepend actual filter */.
Apply rule at task creation (not syscall) */.
Apply rule at audit_log_start */.
This value means filter is unset */.
Apply rule to user-generated messages */.
Apply rule to file system watches */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
First user space message */.
No description provided by the author
Filesystem relabeled */.
No description provided by the author
No description provided by the author
Get status */.
Get which features are enabled */.
No description provided by the author
No description provided by the author
No description provided by the author
Authentication for group password */.
Group acct password or pin changed */.
Group account attr was modified */.
No description provided by the author
Data integrity verification */.
No description provided by the author
integrity HASH type */.
Metadata integrity verification.
PCR invalidation msgs */.
Policy rule */.
integrity enable status */.
IPC record */.
IPC new permissions record type */.
Asynchronous audit record.
For use by 3rd party modules */.
Object's level was changed */.
Admin is overriding a label */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
AUDIT_FIRST_EVENT 1300 */TODO: libaudit define this as AUDIT_FIRST_EVENT but audit.h differently.
AUDIT_FIRST_KERN_ANOM_MSG auditConstant = 1700.
No description provided by the author
No description provided by the author
No description provided by the author
Last user space message */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
List syscall rules -- deprecated */.
List syscall filtering rules */.
Define the login id and information */.
No description provided by the author
No description provided by the author
User space MAC decision results */.
NetLabel: add CIPSOv4 DOI entry */.
NetLabel: del CIPSOv4 DOI entry */.
Changes to booleans */.
Not used */.
Not used */.
Not used */.
Not used */.
Audit an IPSec event */.
NetLabel: add LSM domain mapping */.
NetLabel: del LSM domain mapping */.
Policy file load */.
Changed enforcing,permissive,off */.
NetLabel: allow unlabeled traffic */.
NetLabel: add a static label */.
NetLabel: del a static label */.
Append to watched tree */.
No description provided by the author
No description provided by the author
Record showing descriptor and flags in mmap */.
POSIX MQ get/set attribute record type */.
POSIX MQ notify record type */.
POSIX MQ open record type */.
POSIX MQ send/receive record type */.
No description provided by the author
Netfilter chain modifications */.
Packets traversing netfilter chains */.
Do not build context if rule matches */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
ptrace target */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
Filename path information */.
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
No description provided by the author
Rule fields */ These are useful when checking the
* task structure at task creation time
* (AUDIT_PER_TASK).
Build context if rule matches */.
No description provided by the author
Proctitle emit event */.
User acct was locked */.
User acct locked for time */.
Acct locked from remote access*/.
User acct unlocked from time */.
Alert email was sent */.
Anomaly not reacted to */.
Execute a script */.
take the system down */.
Kill program */.
Set an SE Linux boolean */.
Go to single user mode */.
Terminate session */.
Terminal was locked */.
Admin assigned user to role */.
Admin modified a role */.
Admin removed user from role */.
Secure Computing event */.
internal SE Linux Errors */.
Service (daemon) start */.
Service (daemon) stop */.
Set status (enable/disable/auditd) */.
Turn an audit feature on or off */.
No description provided by the author
Get info about sender of signal to auditd */.
sockaddr copied as syscall arg */.
sys_socketcall arguments */.
No description provided by the author
Status symbols */ Mask values */.
No description provided by the author
No description provided by the author
No description provided by the author
security label clearance label */.
security label role */.
security label sensitivity label */.
security label type */.
security label user */.
No description provided by the author
No description provided by the author
Syscall event */.
System boot */.
System runlevel change */.
System shutdown */.
Used for test success messages */.
No description provided by the author
Trim junk from watched tree */.
Trusted app msg - freestyle text */.
Input on an administrative TTY */.
Get TTY auditing status */.
Set TTY auditing status */.
No description provided by the author
Message from userspace -- deprecated */.
User space acct change */.
User space authentication */.
User space avc message */.
User space acct attr changed */.
User shell command and args */.
User space session end */.
User space acct state err */.
Object exported with label */.
User space user has logged in */.
User space user has logged out */.
Change made to MAC policy */.
Userspc daemon loaded policy */.
User space acct management */.
User changed to a new role */.
SE Linux user space error */.
User space session start */.
Non-ICANON TTY input meaning */.
Object exported without label */.
User space system config change */.
Start, Pause, Stop VM */.
Binding of label to VM */.
Resource assignment */.
No description provided by the author
Insert file/dir watch entry */.
List all file/dir watches */.
Remove file/dir watch entry */.
No description provided by the author
Perhaps disused */.
No description provided by the author
No description provided by the author
No description provided by the author
ARM 64 bit */.
* This is an interim value that we will use until the committee comes
* up with a final number.
ARM 32 bit */.
Atmel AVR32 */.
ADI Blackfin Processor */.
Axis Communications 32-bit embedded processor */.
Bogus old m32r magic number, used by old tools.
Also Panasonic/MEI MN10300, AM33 */.
Bogus old v850 magic number, used by old tools.
Fujitsu FR-V */.
HP/Intel IA-64 */.
No description provided by the author
Renesas M32R */.
MIPS R3000 (officially, big-endian only) */.
MIPS R3000 little-endian */.
MIPS R4000 big-endian */.
Panasonic/MEI MN10300, AM33 */.
Temporary Solution need to add linux/elf-em.h.
HPPA */.
PowerPC */.
PowerPC64 */.
IBM S/390 */.
This is the old interim value for S/390 architecture */.
SuperH */.
No description provided by the author
Sun's "v8plus" */.
SPARC v9 64-bit */.
Cell BE SPU */.
TI C6X DSPs */.
NEC v850 */.
AMD x86-64 */.
No description provided by the author
No description provided by the author