audit: allow audit matching on inode gid
Much like the ability to filter audit on the uid of an inode collected, we should be able to filter on the gid of the inode. Signed-off-by: Eric Paris <eparis@redhat.com>
This commit is contained in:
@ -462,6 +462,7 @@ static struct audit_entry *audit_data_to_entry(struct audit_rule_data *data,
|
||||
case AUDIT_ARG2:
|
||||
case AUDIT_ARG3:
|
||||
case AUDIT_OBJ_UID:
|
||||
case AUDIT_OBJ_GID:
|
||||
break;
|
||||
case AUDIT_ARCH:
|
||||
entry->rule.arch_f = f;
|
||||
|
Reference in New Issue
Block a user