Skip to main content

OriginRecord

Struct OriginRecord 

Source
#[repr(C)]
pub struct OriginRecord { pub version: u32, pub pid: u32, pub ts_boot_ns: u64, pub comm: [u8; 16], pub creator_uid: u32, pub _pad: u32, pub creator_path: [u8; 256], pub landing_filename: [u8; 256], }
Expand description

Provenance record. Carried in the security.bpf.linprov.origin xattr and in the INODE_MARKS storage map.

Filled in stages:

  • BPF file_open writes version, pid, ts_boot_ns, comm, creator_uid, and landing_filename (the path where the file was first written, via bpf_d_path).
  • Userspace, on the corresponding ringbuf event, reads /proc/$pid/exe and overwrites the xattr with the augmented record (creator_path filled).

creator_path may be all-zeros if the creator process exited before userspace got to it. Allowlist rules keyed on creator_process won’t match such records, but other dims still do.

Fields§

§version: u32§pid: u32§ts_boot_ns: u64§comm: [u8; 16]§creator_uid: u32§_pad: u32§creator_path: [u8; 256]§landing_filename: [u8; 256]

Trait Implementations§

Source§

impl Clone for OriginRecord

Source§

fn clone(&self) -> OriginRecord

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for OriginRecord

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.