Expand description
1-1 mapping of all flags that fanotify.h has
Constants
Compare [
fanotify_event_metadata.vers] to verify
that the structures returned at run time match the
structures defined at compile time. In case of a
mismatch, the application should abandon trying to use the
fanotify file descriptor.Create an event when a file or directory (but see BUGS) is
accessed (read).
An application wants to read a file or directory, for
example using read(2)
or readdir(2). The reader must
write a response (as described below) that determines
whether the permission to access the filesystem object
shall be granted.
Allow the file operation.
FAN_ALL_CLASS_BITSDeprecated
FAN_ALL_EVENTSDeprecated
FAN_ALL_INIT_FLAGSDeprecated
FAN_ALL_MARK_FLAGSDeprecated
FAN_ALL_OUTGOING_EVENTSDeprecated
FAN_ALL_PERM_EVENTSDeprecated
Create an event when the metadata for a file or directory
has changed. An fanotify group that identifies filesystem
objects by file handles is required.
Bit mask to create audit record for result
This value allows the receipt of events notifying that a
file has been accessed and events for permission decisions
if a file may be accessed. It is intended for event
listeners that need to access files when they already
contain their final content. This notification class
might be used by malware detection programs, for example.
This is the default value. It does not need to be
specified. This value only allows the receipt of events
notifying that a file has been accessed. Permission
decisions before the file is accessed are not possible.
This value allows the receipt of events notifying that a
file has been accessed and events for permission decisions
if a file may be accessed. It is intended for event
listeners that need to access files before they contain
their final data. This notification class might be used
by hierarchical storage managers, for example.
Set the close-on-exec flag (
FD_CLOEXEC) on the new file
descriptor. See the description of the O_CLOEXEC flag in
open(2).Convenience macro - A file is closed (
FAN_CLOSE_WRITE|FAN_CLOSE_NOWRITE).Create an event when a read-only file or directory is
closed.
Create an event when a writable file is closed.
A child file or directory was created in a watched parent.
A child file or directory was deleted in a watched parent.
A watched file or directory was deleted.
Deny the file operation.
Enable generation of audit log records about access
mediation performed by permission events. The permission
event response has to be marked with the
FAN_AUDIT flag
for an audit log record to be generated.Events for the immediate children of marked directories
shall be created. The flag has no effect when marking
mounts and filesystems. Note that events are not
generated for children of the subdirectories of marked
directories. More specifically, the directory entry
modification events
FAN_CREATE, FAN_DELETE,
FAN_MOVED_FROM, and FAN_MOVED_TO are not generated for any
entry modifications performed inside subdirectories of
marked directories. Note that the events FAN_DELETE_SELF
and FAN_MOVE_SELF are not generated for children of marked
directories. To monitor complete directory trees it is
necessary to mark the relevant mount or filesystem.Represents filesystem error
The events in mask will be added to the mark mask (or to
the ignore mask). mask must be nonempty or the error
EINVAL will occur.If pathname is a symbolic link, mark the link itself,
rather than the file to which it refers. (By default,
fanotify_mark() dereferences pathname if it is a symbolic
link.)Mark the filesystem specified by pathname. The filesystem
containing pathname will be marked. All the contained
files and directories of the filesystem from any mount
point will be monitored.
Remove either all marks for filesystems, all marks for
mounts, or all marks for directories and files from the
fanotify group. If flags contains
FAN_MARK_MOUNT, all
marks for mounts are removed from the group. If flags
contains FAN_MARK_FILESYSTEM, all marks for filesystems
are removed from the group. Otherwise, all marks for
directories and files are removed. No flag other than,
and at most one of, the flags FAN_MARK_MOUNT or
FAN_MARK_FILESYSTEM can be used in conjunction with
FAN_MARK_FLUSH. mask is ignored.This bit is mutually exclusive with
FAN_MARK_IGNORED_MASK bit.
When using FAN_MARK_IGNORE for the first time, mark starts using
independent event flags in ignore mask. After that, trying to
update the ignore mask with the old FAN_MARK_IGNORED_MASK API
will result in EEXIST error.The events in mask shall be added to or removed from the
ignore mask.
The ignore mask shall survive modify events. If this flag
is not set, the ignore mask is cleared when a modify event
occurs for the ignored file or directory.
Convenience macro -
FAN_MARK_IGNORE requires FAN_MARK_IGNORED_SURV_MODIFY
for non-inode mark types.Mark the mount specified by pathname. If pathname is not
itself a mount point, the mount containing pathname will
be marked. All directories, subdirectories, and the
contained files of the mount will be monitored. The
events which require that filesystem objects are
identified by file handles, such as
FAN_CREATE,
FAN_ATTRIB, FAN_MOVE, and FAN_DELETE_SELF, cannot be
provided as a mask when flags contains FAN_MARK_MOUNT.
Attempting to do so will result in the error EINVAL being
returned.If the filesystem object to be marked is not a directory,
the error
ENOTDIR shall be raised.The events in argument mask will be removed from the mark
mask (or from the ignore mask). mask must be nonempty or
the error
EINVAL will occur.Create an event when a file is modified (write).
Convenience macro - A file or directory has been moved
(
FAN_MOVED_FROM|FAN_MOVED_TO).Create an event when a file or directory has been moved
from a marked parent directory. An fanotify group that
identifies filesystem objects by file handles is required.
A file or directory has been moved to a watched parent
directory.
A watched file or directory was moved.
Indicates a queue overflow.
Create events for directories—for example, when
opendir(3),
readdir(3)
(but see BUGS), and
closedir(3) are
called. Without this flag, events are created only for
files. In the context of directory entry events, such as
FAN_CREATE, FAN_DELETE, FAN_MOVED_FROM, and FAN_MOVED_TO,
specifying the flag FAN_ONDIR is required in order to
create events when subdirectory entries are modified
(i.e., mkdir(2)/
rmdir(2)).Create an event when a file or directory is opened.
A file was opened with the intent to be executed. See
NOTES in fanotify_mark(2) for additional details.
An application wants to open a file for execution. The
reader must write a response that determines whether the
permission to open the filesystem object for execution
shall be granted. See NOTES in
fanotify_mark(2) for
additional details.
Create an event when a permission to open a file or
directory is requested. An fanotify file descriptor
created with
FAN_CLASS_PRE_CONTENT or FAN_CLASS_CONTENT is
required.The event queue exceeded the limit of 16384 entries. This
limit can be overridden by specifying the
FAN_UNLIMITED_QUEUE flag when calling fanotify_init().Create an event when a file is renamed.
Convenience macro -
FAN_REPORT_NAME requires FAN_REPORT_DIR_FIDConvenience macro -
FAN_REPORT_TARGET_FID requires all other FID flags
(FAN_REPORT_DFID_NAME, FAN_REPORT_FID , FAN_REPORT_TARGET_FID)Remove the limit of 8192 marks. Use of this flag requires
the
CAP_SYS_ADMIN capability.Remove the limit of 16384 events for the event queue. Use
of this flag requires the
CAP_SYS_ADMIN capability.