Signed-off-by: Richard Guy Briggs <rgb(a)redhat.com>
---
auparse/normalize.c | 1 +
auparse/normalize_record_map.h | 1 +
2 files changed, 2 insertions(+)
diff --git a/auparse/normalize.c b/auparse/normalize.c
index 0ccabc5e397e..55943263f4a4 100644
--- a/auparse/normalize.c
+++ b/auparse/normalize.c
@@ -1037,6 +1037,7 @@ static const char *normalize_determine_evkind(int type)
case AUDIT_SOCKADDR ... AUDIT_MQ_GETSETATTR:
case AUDIT_FD_PAIR ... AUDIT_OBJ_PID:
case AUDIT_BPRM_FCAPS ... AUDIT_NETFILTER_PKT:
+ case AUDIT_URINGOP:
kind = NORM_EVTYPE_AUDIT_RULE;
break;
case AUDIT_FANOTIFY:
diff --git a/auparse/normalize_record_map.h b/auparse/normalize_record_map.h
index 395eac05e0e3..75f555f2b612 100644
--- a/auparse/normalize_record_map.h
+++ b/auparse/normalize_record_map.h
@@ -87,6 +87,7 @@ _S(AUDIT_FANOTIFY, "accessed-policy-controlled-file")
//_S(AUDIT_BPF, "")
//_S(AUDIT_EVENT_LISTENER, "")
//_S(AUDIT_OPENAT2, "")
+_S(AUDIT_URINGOP, "io_uring-operation")
_S(AUDIT_AVC, "accessed-mac-policy-controlled-object")
_S(AUDIT_MAC_POLICY_LOAD, "loaded-selinux-policy")
_S(AUDIT_MAC_STATUS, "changed-selinux-enforcement-to")
--
2.27.0