Skip to content
Commit efaffd6e authored by Eric Paris's avatar Eric Paris Committed by Al Viro
Browse files

audit: allow matching on obj_uid



Allow syscall exit filter matching based on the uid of the owner of an
inode used in a syscall.  aka:

auditctl -a always,exit -S open -F obj_uid=0 -F perm=wa

Signed-off-by: default avatarEric Paris <eparis@redhat.com>
parent 6422e78d
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment