Commit 6a2bceec authored by Amy Griffis's avatar Amy Griffis Committed by Al Viro


Clear AUDIT_FILTER_PREPEND flag after adding rule to list.  This
fixes three problems when a rule is added with the -A syntax:

    - auditctl displays filter list as "(null)"
    - the rule cannot be removed using -d
    - a duplicate rule can be added with -a
Signed-off-by: default avatarAmy Griffis <>
Signed-off-by: default avatarAl Viro <>
parent 0a73dccc
......@@ -1083,6 +1083,7 @@ static inline int audit_add_rule(struct audit_entry *entry,
if (entry->rule.flags & AUDIT_FILTER_PREPEND) {
list_add_rcu(&entry->list, list);
entry->rule.flags &= ~AUDIT_FILTER_PREPEND;
} else {
list_add_tail_rcu(&entry->list, list);
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment