If you'd like to test your patch out I have a userland fork of audit you can use (https://github.com/nwhusted/AuditdAndroid). For various reasons we gutted the networking implementation in userland and shoved audisp's AF_Unix plugin where auditd's networking should be (don't ask). Only auditd and auditctl will compile (the other programs have certain GNU/libc stuff that I didn't write bridge-code for), but that should be more then enough to run through some logging on Android.
At some point I'll have time to go back and make a robust port of audit as Google has started (hopefully) getting there stuff together and turning bionic from a piece of junk into something usable.
Cheers,
Nathaniel
So I ported the initial "audit: implement generic feature setting and retrieving" to Android as well as rebased my patch ontop. Since I didn't author the original patch, I just wanted to keep you abreast of where it was going.https://android-review.googlesource.com/#/c/60880/
--
Respectfully,
William C Roberts
--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit