)]}'
{
  "commit": "e68b75a027bb94066576139ee33676264f867b87",
  "tree": "2c31f59a4abe9d7bb3cb75fdf3b57772feeeb6f6",
  "parents": [
    "3fc689e96c0c90b6fede5946d6c31075e9464f69"
  ],
  "author": {
    "name": "Eric Paris",
    "email": "eparis@redhat.com",
    "time": "Tue Nov 11 21:48:22 2008 +1100"
  },
  "committer": {
    "name": "James Morris",
    "email": "jmorris@namei.org",
    "time": "Tue Nov 11 21:48:22 2008 +1100"
  },
  "message": "When the capset syscall is used it is not possible for audit to record the\nactual capbilities being added/removed.  This patch adds a new record type\nwhich emits the target pid and the eff, inh, and perm cap sets.\n\nexample output if you audit capset syscalls would be:\n\ntype\u003dSYSCALL msg\u003daudit(1225743140.465:76): arch\u003dc000003e syscall\u003d126 success\u003dyes exit\u003d0 a0\u003d17f2014 a1\u003d17f201c a2\u003d80000000 a3\u003d7fff2ab7f060 items\u003d0 ppid\u003d2160 pid\u003d2223 auid\u003d0 uid\u003d0 gid\u003d0 euid\u003d0 suid\u003d0 fsuid\u003d0 egid\u003d0 sgid\u003d0 fsgid\u003d0 tty\u003dpts0 ses\u003d1 comm\u003d\"setcap\" exe\u003d\"/usr/sbin/setcap\" subj\u003dunconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key\u003d(null)\ntype\u003dUNKNOWN[1322] msg\u003daudit(1225743140.465:76): pid\u003d0 cap_pi\u003dffffffffffffffff cap_pp\u003dffffffffffffffff cap_pe\u003dffffffffffffffff\n\nSigned-off-by: Eric Paris \u003ceparis@redhat.com\u003e\nAcked-by: Serge Hallyn \u003cserue@us.ibm.com\u003e\nSigned-off-by: James Morris \u003cjmorris@namei.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "8cfb9feb2a051af93439cfea6f190428ac4ead0e",
      "old_mode": 33188,
      "old_path": "include/linux/audit.h",
      "new_id": "6fbebac7b1bf38c00dd14cacd7259686809b7d2d",
      "new_mode": 33188,
      "new_path": "include/linux/audit.h"
    },
    {
      "type": "modify",
      "old_id": "3229cd4206f5a5e940596d5d13cdc1b47a6b53f5",
      "old_mode": 33188,
      "old_path": "kernel/auditsc.c",
      "new_id": "cef34235b362cb1e2ad4c3c30ce7198adf1c6c7f",
      "new_mode": 33188,
      "new_path": "kernel/auditsc.c"
    },
    {
      "type": "modify",
      "old_id": "e13a68535ad5d8587e1ea4c84233cdf4b65f519b",
      "old_mode": 33188,
      "old_path": "kernel/capability.c",
      "new_id": "19f9eda8997530489bc499908d1934488d740b5e",
      "new_mode": 33188,
      "new_path": "kernel/capability.c"
    }
  ]
}
