audit: add refused symlink to audit_names
Audit link denied events for symlinks had duplicate PATH records rather than just updating the existing PATH record. Update the symlink's PATH record with the current dentry and inode information. See: https://github.com/linux-audit/audit-kernel/issues/21 Signed-off-by: Richard Guy Briggs <rgb@redhat.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
This commit is contained in:
parent
94b9d9b7a1
commit
ea841bafda
1 changed files with 1 additions and 0 deletions
|
|
@ -945,6 +945,7 @@ static inline int may_follow_link(struct nameidata *nd)
|
|||
if (nd->flags & LOOKUP_RCU)
|
||||
return -ECHILD;
|
||||
|
||||
audit_inode(nd->name, nd->stack[0].link.dentry, 0);
|
||||
audit_log_link_denied("follow_link");
|
||||
return -EACCES;
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue