[PATCH ghak64 V3] audit: add saddr_fam filter field

2019-05-09 Thread Richard Guy Briggs
Provide a method to filter out sockaddr and bind calls by network address family. Existing SOCKADDR records are listed for any network activity. Implement the AUDIT_SADDR_FAM field selector to be able to classify or limit records to specific network address families, such as AF_INET or AF_INET6.

Re: [PATCH ghak64 V2] audit: add saddr_fam filter field

2019-05-09 Thread Paul Moore
On Wed, May 8, 2019 at 9:52 PM Richard Guy Briggs wrote: > On 2019-05-08 18:05, Paul Moore wrote: > > On Wed, May 8, 2019 at 12:46 PM Richard Guy Briggs wrote: > > > > > > Provide a method to filter out sockaddr and bind calls by network > > > address family. > > > > > > Existing SOCKADDR records