Advertisement
Guest User

Untitled

a guest
Oct 14th, 2016
167
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 28.04 KB | None | 0 0
  1. ArchCelsum:etc ArchCelsum$ cat security/*
  2. #
  3. # $P4: //depot/projects/trustedbsd/openbsm/etc/audit_class#6 $
  4. #
  5. 0x00000000:no:invalid class
  6. 0x00000001:fr:file read
  7. 0x00000002:fw:file write
  8. 0x00000004:fa:file attribute access
  9. 0x00000008:fm:file attribute modify
  10. 0x00000010:fc:file create
  11. 0x00000020:fd:file delete
  12. 0x00000040:cl:file close
  13. 0x00000080:pc:process
  14. 0x00000100:nt:network
  15. 0x00000200:ip:ipc
  16. 0x00000400:na:non attributable
  17. 0x00000800:ad:administrative
  18. 0x00001000:lo:login_logout
  19. 0x00002000:aa:authentication and authorization
  20. 0x00004000:ap:application
  21. 0x20000000:io:ioctl
  22. 0x40000000:ex:exec
  23. 0x80000000:ot:miscellaneous
  24. 0xffffffff:all:all flags set
  25. cat: security/audit_control: Permission denied
  26. #
  27. # $P4: //depot/projects/trustedbsd/openbsm/etc/audit_event#41 $
  28. #
  29. # The mapping between event identifiers and values is also hard-coded in
  30. # audit_kevents.h and audit_uevents.h, so changes must occur in both places,
  31. # and programs, such as the kernel, may need to be recompiled to recognize
  32. # those changes. It is advisable not to change the numbering or naming of
  33. # kernel audit events.
  34. #
  35. # Allocation of BSM event identifier ranges:
  36. #
  37. # 0 Reserved and invalid
  38. # 1 - 2047 Reserved for Solaris kernel events
  39. # 2048 - 5999 Reserved and unallocated
  40. # 6000 - 9999 Reserved for Solaris user events
  41. # 10000 - 32767 Reserved and unallocated
  42. # 32768 - 65535 Available for third party applications
  43. #
  44. # Of the third party range, OpenBSM allocates from the following ranges:
  45. #
  46. # 43000 - 44999 Reserved for OpenBSM kernel events
  47. # 45000 - 46999 Reserved for OpenBSM application events
  48. #
  49. 0:AUE_NULL:indir system call:no
  50. 1:AUE_EXIT:exit(2):pc
  51. 2:AUE_FORK:fork(2):pc
  52. 3:AUE_OPEN:open(2) - attr only:fa
  53. 4:AUE_CREAT:creat(2):fc
  54. 5:AUE_LINK:link(2):fc
  55. 6:AUE_UNLINK:unlink(2):fd
  56. 7:AUE_EXEC:exec(2):pc,ex
  57. 8:AUE_CHDIR:chdir(2):pc
  58. 9:AUE_MKNOD:mknod(2):fc
  59. 10:AUE_CHMOD:chmod(2):fm
  60. 11:AUE_CHOWN:chown(2):fm
  61. 12:AUE_UMOUNT:umount(2) - old version:ad
  62. 13:AUE_JUNK:junk:no
  63. 14:AUE_ACCESS:access(2):fa
  64. 15:AUE_KILL:kill(2):pc
  65. 16:AUE_STAT:stat(2):fa
  66. 17:AUE_LSTAT:lstat(2):fa
  67. 18:AUE_ACCT:acct(2):ad
  68. 19:AUE_MCTL:mctl(2):no
  69. 20:AUE_REBOOT:reboot(2):ad
  70. 21:AUE_SYMLINK:symlink(2):fc
  71. 22:AUE_READLINK:readlink(2):fr
  72. 23:AUE_EXECVE:execve(2):pc,ex
  73. 24:AUE_CHROOT:chroot(2):pc
  74. 25:AUE_VFORK:vfork(2):pc
  75. 26:AUE_SETGROUPS:setgroups(2):pc
  76. 27:AUE_SETPGRP:setpgrp(2):pc
  77. 28:AUE_SWAPON:swapon(2):ad
  78. 29:AUE_SETHOSTNAME:sethostname(2):ad
  79. 30:AUE_FCNTL:fcntl(2):fm
  80. 31:AUE_SETPRIORITY:setpriority(2):pc
  81. 32:AUE_CONNECT:connect(2):nt
  82. 33:AUE_ACCEPT:accept(2):nt
  83. 34:AUE_BIND:bind(2):nt
  84. 35:AUE_SETSOCKOPT:setsockopt(2):nt
  85. 36:AUE_VTRACE:vtrace(2):pc
  86. 37:AUE_SETTIMEOFDAY:settimeofday(2):ad
  87. 38:AUE_FCHOWN:fchown(2):fm
  88. 39:AUE_FCHMOD:fchmod(2):fm
  89. 40:AUE_SETREUID:setreuid(2):pc
  90. 41:AUE_SETREGID:setregid(2):pc
  91. 42:AUE_RENAME:rename(2):fc,fd
  92. 43:AUE_TRUNCATE:truncate(2):fw
  93. 44:AUE_FTRUNCATE:ftruncate(2):fw
  94. 45:AUE_FLOCK:flock(2):fm
  95. 46:AUE_SHUTDOWN:shutdown(2):nt
  96. 47:AUE_MKDIR:mkdir(2):fc
  97. 48:AUE_RMDIR:rmdir(2):fd
  98. 49:AUE_UTIMES:utimes(2):fm
  99. 50:AUE_ADJTIME:adjtime(2):ad
  100. 51:AUE_SETRLIMIT:setrlimit(2):pc
  101. 52:AUE_KILLPG:killpg(2):pc
  102. 53:AUE_NFS_SVC:nfs_svc(2):ad
  103. 54:AUE_STATFS:statfs(2):fa
  104. 55:AUE_FSTATFS:fstatfs(2):fa
  105. 56:AUE_UNMOUNT:unmount(2):ad
  106. 57:AUE_ASYNC_DAEMON:async_daemon(2):ad
  107. 58:AUE_NFS_GETFH:nfs_getfh(2):ad
  108. 59:AUE_SETDOMAINNAME:setdomainname(2):ad
  109. 60:AUE_QUOTACTL:quotactl(2):ad
  110. 61:AUE_EXPORTFS:exportfs(2):ad
  111. 62:AUE_MOUNT:mount(2):ad
  112. 63:AUE_SEMSYS:semsys(2):ip
  113. 64:AUE_MSGSYS:msgsys(2):ip
  114. 65:AUE_SHMSYS:shmsys(2):ip
  115. 66:AUE_BSMSYS:bsmsys(2):ad
  116. 67:AUE_RFSSYS:rfssys(2):ad
  117. 68:AUE_FCHDIR:fchdir(2):pc
  118. 69:AUE_FCHROOT:fchroot(2):pc
  119. 70:AUE_VPIXSYS:vpixsys(2):no
  120. 71:AUE_PATHCONF:pathconf(2):fa
  121. 72:AUE_OPEN_R:open(2) - read:fr
  122. 73:AUE_OPEN_RC:open(2) - read,creat:fc,fr,fa,fm
  123. 74:AUE_OPEN_RT:open(2) - read,trunc:fd,fr,fa,fm
  124. 75:AUE_OPEN_RTC:open(2) - read,creat,trunc:fc,fd,fr,fa,fm
  125. 76:AUE_OPEN_W:open(2) - write:fw
  126. 77:AUE_OPEN_WC:open(2) - write,creat:fc,fw,fa,fm
  127. 78:AUE_OPEN_WT:open(2) - write,trunc:fd,fw,fa,fm
  128. 79:AUE_OPEN_WTC:open(2) - write,creat,trunc:fc,fd,fw,fa,fm
  129. 80:AUE_OPEN_RW:open(2) - read,write:fr,fw
  130. 81:AUE_OPEN_RWC:open(2) - read,write,creat:fc,fw,fr,fa,fm
  131. 82:AUE_OPEN_RWT:open(2) - read,write,trunc:fd,fr,fw,fa,fm
  132. 83:AUE_OPEN_RWTC:open(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
  133. 84:AUE_MSGCTL:msgctl(2) - illegal command:ip
  134. 85:AUE_MSGCTL_RMID:msgctl(2) - IPC_RMID command:ip
  135. 86:AUE_MSGCTL_SET:msgctl(2) - IPC_SET command:ip
  136. 87:AUE_MSGCTL_STAT:msgctl(2) - IPC_STAT command:ip
  137. 88:AUE_MSGGET:msgget(2):ip
  138. 89:AUE_MSGRCV:msgrcv(2):ip
  139. 90:AUE_MSGSND:msgsnd(2):ip
  140. 91:AUE_SHMCTL:shmctl(2) - illegal command:ip
  141. 92:AUE_SHMCTL_RMID:shmctl(2) - IPC_RMID command:ip
  142. 93:AUE_SHMCTL_SET:shmctl(2) - IPC_SET command:ip
  143. 94:AUE_SHMCTL_STAT:shmctl(2) - IPC_STAT command:ip
  144. 95:AUE_SHMGET:shmget(2):ip
  145. 96:AUE_SHMAT:shmat(2):ip
  146. 97:AUE_SHMDT:shmdt(2):ip
  147. 98:AUE_SEMCTL:semctl(2) - illegal command:ip
  148. 99:AUE_SEMCTL_RMID:semctl(2) - IPC_RMID command:ip
  149. 100:AUE_SEMCTL_SET:semctl(2) - IPC_SET command:ip
  150. 101:AUE_SEMCTL_STAT:semctl(2) - IPC_STAT command:ip
  151. 102:AUE_SEMCTL_GETNCNT:semctl(2) - GETNCNT command:ip
  152. 103:AUE_SEMCTL_GETPID:semctl(2) - GETPID command:ip
  153. 104:AUE_SEMCTL_GETVAL:semctl(2) - GETVAL command:ip
  154. 105:AUE_SEMCTL_GETALL:semctl(2) - GETALL command:ip
  155. 106:AUE_SEMCTL_GETZCNT:semctl(2) - GETZCNT command:ip
  156. 107:AUE_SEMCTL_SETVAL:semctl(2) - SETVAL command:ip
  157. 108:AUE_SEMCTL_SETALL:semctl(2) - SETALL command:ip
  158. 109:AUE_SEMGET:semget(2):ip
  159. 110:AUE_SEMOP:semop(2):ip
  160. 111:AUE_CORE:process dumped core:fc
  161. 112:AUE_CLOSE:close(2):cl
  162. 113:AUE_SYSTEMBOOT:system booted:na
  163. 114:AUE_ASYNC_DAEMON_EXIT:async_daemon(2) exited:ad
  164. 115:AUE_NFSSVC_EXIT:nfssvc(2) exited:ad
  165. 128:AUE_WRITEL:writel(2):no
  166. 129:AUE_WRITEVL:writevl(2):no
  167. 130:AUE_GETAUID:getauid(2):ad
  168. 131:AUE_SETAUID:setauid(2):ad
  169. 132:AUE_GETAUDIT:getaudit(2):ad
  170. 133:AUE_SETAUDIT:setaudit(2):ad
  171. 134:AUE_GETUSERAUDIT:getuseraudit(2):ad
  172. 135:AUE_SETUSERAUDIT:setuseraudit(2):ad
  173. 136:AUE_AUDITSVC:auditsvc(2):ad
  174. 137:AUE_AUDITUSER:audituser(2):ad
  175. 138:AUE_AUDITON:auditon(2):ad
  176. 139:AUE_AUDITON_GTERMID:auditon(2) - GETTERMID command:ad
  177. 140:AUE_AUDITON_STERMID:auditon(2) - SETTERMID command:ad
  178. 141:AUE_AUDITON_GPOLICY:auditon(2) - GPOLICY command:ad
  179. 142:AUE_AUDITON_SPOLICY:auditon(2) - SPOLICY command:ad
  180. 143:AUE_AUDITON_GESTATE:auditon(2) - GESTATE command:ad
  181. 144:AUE_AUDITON_SESTATE:auditon(2) - SESTATE command:ad
  182. 145:AUE_AUDITON_GQCTRL:auditon(2) - GQCTRL command:ad
  183. 146:AUE_AUDITON_SQCTRL:auditon(2) - SQCTRL command:ad
  184. 147:AUE_GETKERNSTATE:getkernstate(2):ad
  185. 148:AUE_SETKERNSTATE:setkernstate(2):ad
  186. 149:AUE_GETPORTAUDIT:getportaudit(2):ad
  187. 150:AUE_AUDITSTAT:auditstat(2):ad
  188. 151:AUE_REVOKE:revoke(2):cl
  189. 152:AUE_MAC:Solaris AUE_MAC:no
  190. 153:AUE_ENTERPROM:enter prom:ad
  191. 154:AUE_EXITPROM:exit prom:ad
  192. 155:AUE_IFLOAT:Solaris AUE_IFLOAT:no
  193. 156:AUE_PFLOAT:Solaris AUE_PFLOAT:no
  194. 157:AUE_UPRIV:Solaris AUE_UPRIV:no
  195. 158:AUE_IOCTL:ioctl(2):io
  196. 173:AUE_ONESIDE:one-sided session record:nt
  197. 174:AUE_MSGGETL:msggetl(2):ip
  198. 175:AUE_MSGRCVL:msgrcvl(2):ip
  199. 176:AUE_MSGSNDL:msgsndl(2):ip
  200. 177:AUE_SEMGETL:semgetl(2):ip
  201. 178:AUE_SHMGETL:shmgetl(2):ip
  202. 183:AUE_SOCKET:socket(2):nt
  203. 184:AUE_SENDTO:sendto(2):nt
  204. 185:AUE_PIPE:pipe(2):ip
  205. 186:AUE_SOCKETPAIR:socketpair(2):nt
  206. 187:AUE_SEND:send(2):nt
  207. 188:AUE_SENDMSG:sendmsg(2):nt
  208. 189:AUE_RECV:recv(2):nt
  209. 190:AUE_RECVMSG:recvmsg(2):nt
  210. 191:AUE_RECVFROM:recvfrom(2):nt
  211. 192:AUE_READ:read(2):no
  212. 193:AUE_GETDENTS:getdents(2):no
  213. 194:AUE_LSEEK:lseek(2):no
  214. 195:AUE_WRITE:write(2):no
  215. 196:AUE_WRITEV:writev(2):no
  216. 197:AUE_NFS:nfs server:ad
  217. 198:AUE_READV:readv(2):no
  218. 199:AUE_OSTAT:Solaris old stat(2):fa
  219. 200:AUE_SETUID:setuid(2):pc
  220. 201:AUE_STIME:old stime(2):ad
  221. 202:AUE_UTIME:old utime(2):fm
  222. 203:AUE_NICE:old nice(2):pc
  223. 204:AUE_OSETPGRP:Solaris old setpgrp(2):pc
  224. 205:AUE_SETGID:setgid(2):pc
  225. 206:AUE_READL:readl(2):no
  226. 207:AUE_READVL:readvl(2):no
  227. 208:AUE_FSTAT:fstat(2):fa
  228. 209:AUE_DUP2:dup2(2):no
  229. 210:AUE_MMAP:mmap(2):no
  230. 211:AUE_AUDIT:audit(2):ot
  231. 212:AUE_PRIOCNTLSYS:Solaris priocntlsys(2):pc
  232. 213:AUE_MUNMAP:munmap(2):cl
  233. 214:AUE_SETEGID:setegid(2):pc
  234. 215:AUE_SETEUID:seteuid(2):pc
  235. 216:AUE_PUTMSG:putmsg(2):nt
  236. 217:AUE_GETMSG:getmsg(2):nt
  237. 218:AUE_PUTPMSG:putpmsg(2):nt
  238. 219:AUE_GETPMSG:getpmsg(2):nt
  239. 220:AUE_AUDITSYS:audit system calls place holder:no
  240. 221:AUE_AUDITON_GETKMASK:auditon(2) - get kernel mask:ad
  241. 222:AUE_AUDITON_SETKMASK:auditon(2) - set kernel mask:ad
  242. 223:AUE_AUDITON_GETCWD:auditon(2) - get cwd:ad
  243. 224:AUE_AUDITON_GETCAR:auditon(2) - get car:ad
  244. 225:AUE_AUDITON_GETSTAT:auditon(2) - get audit statistics:ad
  245. 226:AUE_AUDITON_SETSTAT:auditon(2) - reset audit statistics:ad
  246. 227:AUE_AUDITON_SETUMASK:auditon(2) - set mask per uid:ad
  247. 228:AUE_AUDITON_SETSMASK:auditon(2) - set mask per session ID:ad
  248. 229:AUE_AUDITON_GETCOND:auditon(2) - get audit state:ad
  249. 230:AUE_AUDITON_SETCOND:auditon(2) - set audit state:ad
  250. 231:AUE_AUDITON_GETCLASS:auditon(2) - get event class:ad
  251. 232:AUE_AUDITON_SETCLASS:auditon(2) - set event class:ad
  252. 233:AUE_UTSSYS:utssys(2) - fusers:ad
  253. 234:AUE_STATVFS:statvfs(2):fa
  254. 235:AUE_XSTAT:xstat(2):fa
  255. 236:AUE_LXSTAT:lxstat(2):fa
  256. 237:AUE_LCHOWN:lchown(2):fm
  257. 238:AUE_MEMCNTL:memcntl(2):ot
  258. 239:AUE_SYSINFO:sysinfo(2):ad
  259. 240:AUE_XMKNOD:xmknod(2):fc
  260. 241:AUE_FORK1:fork1(2):pc
  261. 242:AUE_MODCTL:modctl(2) system call place holder:no
  262. 243:AUE_MODLOAD:modctl(2) - load module:ad
  263. 244:AUE_MODUNLOAD:modctl(2) - unload module:ad
  264. 245:AUE_MODCONFIG:modctl(2) - configure module:ad
  265. 246:AUE_MODADDMAJ:modctl(2) - bind module:ad
  266. 247:AUE_SOCKACCEPT:getmsg-accept:nt
  267. 248:AUE_SOCKCONNECT:putmsg-connect:nt
  268. 249:AUE_SOCKSEND:putmsg-send:nt
  269. 250:AUE_SOCKRECEIVE:getmsg-receive:nt
  270. 251:AUE_ACLSET:acl(2) - SETACL comand:fm
  271. 252:AUE_FACLSET:facl(2) - SETACL command:fm
  272. 253:AUE_DOORFS:doorfs(2) - system call place holder:no
  273. 254:AUE_DOORFS_DOOR_CALL:doorfs(2) - DOOR_CALL:ip
  274. 255:AUE_DOORFS_DOOR_RETURN:doorfs(2) - DOOR_RETURN:ip
  275. 256:AUE_DOORFS_DOOR_CREATE:doorfs(2) - DOOR_CREATE:ip
  276. 257:AUE_DOORFS_DOOR_REVOKE:doorfs(2) - DOOR_REVOKE:ip
  277. 258:AUE_DOORFS_DOOR_INFO:doorfs(2) - DOOR_INFO:ip
  278. 259:AUE_DOORFS_DOOR_CRED:doorfs(2) - DOOR_CRED:ip
  279. 260:AUE_DOORFS_DOOR_BIND:doorfs(2) - DOOR_BIND:ip
  280. 261:AUE_DOORFS_DOOR_UNBIND:doorfs(2) - DOOR_UNBIND:ip
  281. 262:AUE_P_ONLINE:p_online(2):ad
  282. 263:AUE_PROCESSOR_BIND:processor_bind(2):ad
  283. 264:AUE_INST_SYNC:inst_sync(2):ad
  284. 265:AUE_SOCKCONFIG:configure socket:nt
  285. 266:AUE_SETAUDIT_ADDR:setaudit_addr(2):ad
  286. 267:AUE_GETAUDIT_ADDR:getaudit_addr(2):ad
  287. 268:AUE_UMOUNT2:Solaris umount(2):ad
  288. 269:AUE_FSAT:fsat(2) - place holder:no
  289. 270:AUE_OPENAT_R:openat(2) - read:fr
  290. 271:AUE_OPENAT_RC:openat(2) - read,creat:fc,fr,fa,fm
  291. 272:AUE_OPENAT_RT:openat(2) - read,trunc:fd,fr,fa,fm
  292. 273:AUE_OPENAT_RTC:openat(2) - read,creat,trunc:fc,fd,fr,fa,fm
  293. 274:AUE_OPENAT_W:openat(2) - write:fw
  294. 275:AUE_OPENAT_WC:openat(2) - write,creat:fc,fw,fa,fm
  295. 276:AUE_OPENAT_WT:openat(2) - write,trunc:fd,fw,fa,fm
  296. 277:AUE_OPENAT_WTC:openat(2) - write,creat,trunc:fc,fd,fw,fa,fm
  297. 278:AUE_OPENAT_RW:openat(2) - read,write:fr,fw
  298. 279:AUE_OPENAT_RWC:openat(2) - read,write,create:fc,fw,fr,fa,fm
  299. 280:AUE_OPENAT_RWT:openat(2) - read,write,trunc:fd,fw,fr,fa,fm
  300. 281:AUE_OPENAT_RWTC:openat(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
  301. 282:AUE_RENAMEAT:renameat(2):fc,fd
  302. 283:AUE_FSTATAT:fstatat(2):fa
  303. 284:AUE_FCHOWNAT:fchownat(2):fm
  304. 285:AUE_FUTIMESAT:futimesat(2):fm
  305. 286:AUE_UNLINKAT:unlinkat(2):fd
  306. 287:AUE_CLOCK_SETTIME:clock_settime(2):ad
  307. 288:AUE_NTP_ADJTIME:ntp_adjtime(2):ad
  308. 289:AUE_SETPPRIV:setppriv(2):pc
  309. 290:AUE_MODDEVPLCY:modctl(2) - configure device policy:ad
  310. 291:AUE_MODADDPRIV:modctl(2) - configure additional privilege:ad
  311. 292:AUE_CRYPTOADM:kernel cryptographic framework:ad
  312. 293:AUE_CONFIGKSSL:configure kernel SSL:ad
  313. 294:AUE_BRANDSYS:brandsys(2):ot
  314. 295:AUE_PF_POLICY_ADDRULE:Add IPsec policy rule:ad
  315. 296:AUE_PF_POLICY_DELRULE:Delete IPsec policy rule:ad
  316. 297:AUE_PF_POLICY_CLONE:Clone IPsec policy:ad
  317. 298:AUE_PF_POLICY_FLIP:Flip IPsec policy:ad
  318. 299:AUE_PF_POLICY_FLUSH:Flush IPsec policy rules:ad
  319. 300:AUE_PF_POLICY_ALGS:Update IPsec algorithms:ad
  320. 301:AUE_PORTFS:portfs:fa
  321. #
  322. # What follows are deprecated Darwin event numbers that may soon^H^H^H^Hnow
  323. # conflict with Solaris events.
  324. #
  325. 301:AUE_DARWIN_GETFSSTAT:getfsstat(2):fa
  326. 302:AUE_DARWIN_PTRACE:ptrace(2):pc
  327. 303:AUE_DARWIN_CHFLAGS:chflags(2):fm
  328. 304:AUE_DARWIN_FCHFLAGS:fchflags(2):fm
  329. 305:AUE_DARWIN_PROFILE:profil(2):pc
  330. 306:AUE_DARWIN_KTRACE:ktrace(2):pc
  331. 307:AUE_DARWIN_SETLOGIN:setlogin(2):pc
  332. 308:AUE_DARWIN_REBOOT:reboot(2):ad
  333. 309:AUE_DARWIN_REVOKE:revoke(2):cl
  334. 310:AUE_DARWIN_UMASK:umask(2):pc
  335. 311:AUE_DARWIN_MPROTECT:mprotect(2):fm
  336. 312:AUE_DARWIN_SETPRIORITY:setpriority(2):pc,ot
  337. 313:AUE_DARWIN_SETTIMEOFDAY:settimeofday(2):ad
  338. 314:AUE_DARWIN_FLOCK:flock(2):fm
  339. 315:AUE_DARWIN_MKFIFO:mkfifo(2):fc
  340. 316:AUE_DARWIN_POLL:poll(2):no
  341. 317:AUE_DARWIN_SOCKETPAIR:socketpair(2):nt
  342. 318:AUE_DARWIN_FUTIMES:futimes(2):fm
  343. 319:AUE_DARWIN_SETSID:setsid(2):pc
  344. 320:AUE_DARWIN_SETPRIVEXEC:setprivexec(2):pc
  345. 321:AUE_DARWIN_NFSSVC:nfssvc(2):ad
  346. 322:AUE_DARWIN_GETFH:getfh(2):fa
  347. 323:AUE_DARWIN_QUOTACTL:quotactl(2):ad
  348. 324:AUE_DARWIN_ADDPROFILE:add_profil():pc
  349. 325:AUE_DARWIN_KDEBUGTRACE:kdebug_trace():pc
  350. 326:AUE_DARWIN_FSTAT:fstat(2):fa
  351. 327:AUE_DARWIN_FPATHCONF:fpathconf(2):fa
  352. 328:AUE_DARWIN_GETDIRENTRIES:getdirentries(2):no
  353. 329:AUE_DARWIN_TRUNCATE:truncate(2):fw
  354. 330:AUE_DARWIN_FTRUNCATE:ftruncate(2):fw
  355. 331:AUE_DARWIN_SYSCTL:sysctl(3):ad
  356. 332:AUE_DARWIN_MLOCK:mlock(2):pc
  357. 333:AUE_DARWIN_MUNLOCK:munlock(2):pc
  358. 334:AUE_DARWIN_UNDELETE:undelete(2):fm
  359. 335:AUE_DARWIN_GETATTRLIST:getattrlist():fa
  360. 336:AUE_DARWIN_SETATTRLIST:setattrlist():fm
  361. 337:AUE_DARWIN_GETDIRENTRIESATTR:getdirentriesattr():fa
  362. 338:AUE_DARWIN_EXCHANGEDATA:exchangedata():fw
  363. 339:AUE_DARWIN_SEARCHFS:searchfs():fa
  364. 340:AUE_DARWIN_MINHERIT:minherit(2):pc
  365. 341:AUE_DARWIN_SEMCONFIG:semconfig():ip
  366. 342:AUE_DARWIN_SEMOPEN:sem_open(2):ip
  367. 343:AUE_DARWIN_SEMCLOSE:sem_close(2):ip
  368. 344:AUE_DARWIN_SEMUNLINK:sem_unlink(2):ip
  369. 345:AUE_DARWIN_SHMOPEN:shm_open(2):ip
  370. 346:AUE_DARWIN_SHMUNLINK:shm_unlink(2):ip
  371. 347:AUE_DARWIN_LOADSHFILE:load_shared_file():fr
  372. 348:AUE_DARWIN_RESETSHFILE:reset_shared_file():ot
  373. 349:AUE_DARWIN_NEWSYSTEMSHREG:new_system_share_regions():ot
  374. 350:AUE_DARWIN_PTHREADKILL:pthread_kill(2):pc
  375. 351:AUE_DARWIN_PTHREADSIGMASK:pthread_sigmask(2):pc
  376. 352:AUE_DARWIN_AUDITCTL:auditctl(2):ad
  377. 353:AUE_DARWIN_RFORK:rfork(2):pc
  378. 354:AUE_DARWIN_LCHMOD:lchmod(2):fm
  379. 355:AUE_DARWIN_SWAPOFF:swapoff(2):ad
  380. 356:AUE_DARWIN_INITPROCESS:init_process():pc
  381. 357:AUE_DARWIN_MAPFD:map_fd():fa
  382. 358:AUE_DARWIN_TASKFORPID:task_for_pid():pc
  383. 359:AUE_DARWIN_PIDFORTASK:pid_for_task():pc
  384. 360:AUE_DARWIN_SYSCTL_NONADMIN:sysctl() - non-admin:ot
  385. 361:AUE_DARWIN_COPYFILE:copyfile():fr,fw
  386. #
  387. # OpenBSM-specific kernel events.
  388. #
  389. 43001:AUE_GETFSSTAT:getfsstat(2):fa
  390. 43002:AUE_PTRACE:ptrace(2):pc
  391. 43003:AUE_CHFLAGS:chflags(2):fm
  392. 43004:AUE_FCHFLAGS:fchflags(2):fm
  393. 43005:AUE_PROFILE:profil(2):pc
  394. 43006:AUE_KTRACE:ktrace(2):pc
  395. 43007:AUE_SETLOGIN:setlogin(2):pc
  396. 43008:AUE_OPENBSM_REVOKE:revoke(2):cl
  397. 43009:AUE_UMASK:umask(2):pc
  398. 43010:AUE_MPROTECT:mprotect(2):fm
  399. 43011:AUE_MKFIFO:mkfifo(2):fc
  400. 43012:AUE_POLL:poll(2):no
  401. 43013:AUE_FUTIMES:futimes(2):fm
  402. 43014:AUE_SETSID:setsid(2):pc
  403. 43015:AUE_SETPRIVEXEC:setprivexec(2):pc
  404. 43016:AUE_ADDPROFILE:add_profil():pc
  405. 43017:AUE_KDEBUGTRACE:kdebug_trace():pc
  406. 43018:AUE_OPENBSM_FSTAT:fstat(2):fa
  407. 43019:AUE_FPATHCONF:fpathconf(2):fa
  408. 43020:AUE_GETDIRENTRIES:getdirentries(2):no
  409. 43021:AUE_SYSCTL:sysctl(3):ot
  410. 43022:AUE_MLOCK:mlock(2):pc
  411. 43023:AUE_MUNLOCK:munlock(2):pc
  412. 43024:AUE_UNDELETE:undelete(2):fm
  413. 43025:AUE_GETATTRLIST:getattrlist():fa
  414. 43026:AUE_SETATTRLIST:setattrlist():fm
  415. 43027:AUE_GETDIRENTRIESATTR:getdirentriesattr():fa
  416. 43028:AUE_EXCHANGEDATA:exchangedata():fw
  417. 43029:AUE_SEARCHFS:searchfs():fa
  418. 43030:AUE_MINHERIT:minherit(2):pc
  419. 43031:AUE_SEMCONFIG:semconfig():ip
  420. 43032:AUE_SEMOPEN:sem_open(2):ip
  421. 43033:AUE_SEMCLOSE:sem_close(2):ip
  422. 43034:AUE_SEMUNLINK:sem_unlink(2):ip
  423. 43035:AUE_SHMOPEN:shm_open(2):ip
  424. 43036:AUE_SHMUNLINK:shm_unlink(2):ip
  425. 43037:AUE_LOADSHFILE:load_shared_file():fr
  426. 43038:AUE_RESETSHFILE:reset_shared_file():ot
  427. 43039:AUE_NEWSYSTEMSHREG:new_system_share_regions():ot
  428. 43040:AUE_PTHREADKILL:pthread_kill(2):pc
  429. 43041:AUE_PTHREADSIGMASK:pthread_sigmask(2):pc
  430. 43042:AUE_AUDITCTL:auditctl(2):ad
  431. 43043:AUE_RFORK:rfork(2):pc
  432. 43044:AUE_LCHMOD:lchmod(2):fm
  433. 43045:AUE_SWAPOFF:swapoff(2):ad
  434. 43046:AUE_INITPROCESS:init_process():pc
  435. 43047:AUE_MAPFD:map_fd():fa
  436. 43048:AUE_TASKFORPID:task_for_pid():pc
  437. 43049:AUE_PIDFORTASK:pid_for_task():pc
  438. 43050:AUE_SYSCTL_NONADMIN:sysctl() - non-admin:ot
  439. 43051:AUE_COPYFILE:copyfile(2):fr,fw
  440. 43052:AUE_LUTIMES:lutimes(2):fm
  441. 43053:AUE_LCHFLAGS:lchflags(2):fm
  442. 43054:AUE_SENDFILE:sendfile(2):nt
  443. 43055:AUE_USELIB:uselib(2):fa
  444. 43056:AUE_GETRESUID:getresuid(2):pc
  445. 43057:AUE_SETRESUID:setresuid(2):pc
  446. 43058:AUE_GETRESGID:getresgid(2):pc
  447. 43059:AUE_SETRESGID:setresgid(2):pc
  448. 43060:AUE_WAIT4:wait4(2):pc
  449. 43061:AUE_LGETFH:lgetfh(2):fa
  450. 43062:AUE_FHSTATFS:fhstatfs(2):fa
  451. 43063:AUE_FHOPEN:fhopen(2):fa
  452. 43064:AUE_FHSTAT:fhstat(2):fa
  453. 43065:AUE_JAIL:jail(2):pc
  454. 43066:AUE_EACCESS:eaccess(2):fa
  455. 43067:AUE_KQUEUE:kqueue(2):no
  456. 43068:AUE_KEVENT:kevent(2):no
  457. 43069:AUE_FSYNC:fsync(2):fm
  458. 43070:AUE_NMOUNT:nmount(2):ad
  459. 43071:AUE_BDFLUSH:bdflush(2):ad
  460. 43072:AUE_SETFSUID:setfsuid(2):ot
  461. 43073:AUE_SETFSGID:setfsgid(2):ot
  462. 43074:AUE_PERSONALITY:personality(2):pc
  463. 43075:AUE_SCHED_GETSCHEDULER:getscheduler(2):ad
  464. 43076:AUE_SCHED_SETSCHEDULER:setscheduler(2):ad
  465. 43077:AUE_PRCTL:prctl(2):pc
  466. 43078:AUE_GETCWD:getcwd(2):pc
  467. 43079:AUE_CAPGET:capget(2):pc
  468. 43080:AUE_CAPSET:capset(2):pc
  469. 43081:AUE_PIVOT_ROOT:pivot_root(2):pc
  470. 43082:AUE_RTPRIO::rtprio(2):pc
  471. 43083:AUE_SCHED_GETPARAM:sched_getparam(2):ad
  472. 43084:AUE_SCHED_SETPARAM:sched_setparam(2):ad
  473. 43085:AUE_SCHED_GET_PRIORITY_MAX:sched_get_priority_max(2):ad
  474. 43086:AUE_SCHED_GET_PRIORITY_MIN:sched_get_priority_min(2):ad
  475. 43087:AUE_SCHED_RR_GET_INTERVAL:sched_rr_get_interval(2):ad
  476. 43088:AUE_ACL_GET_FILE:acl_get_file(2):fa
  477. 43089:AUE_ACL_SET_FILE:acl_set_file(2):fm
  478. 43090:AUE_ACL_GET_FD:acl_get_fd(2):fa
  479. 43091:AUE_ACL_SET_FD:acl_set_fd(2):fm
  480. 43092:AUE_ACL_DELETE_FILE:acl_delete_file(2):fm
  481. 43093:AUE_ACL_DELETE_FD:acl_delete_fd(2):fm
  482. 43094:AUE_ACL_CHECK_FILE:acl_aclcheck_file(2):fa
  483. 43095:AUE_ACL_CHECK_FD:acl_aclcheck_fd(2):fa
  484. 43096:AUE_ACL_GET_LINK:acl_get_link(2):fa
  485. 43097:AUE_ACL_SET_LINK:acl_set_link(2):fm
  486. 43098:AUE_ACL_DELETE_LINK:acl_delete_link(2):fm
  487. 43099:AUE_ACL_CHECK_LINK:acl_aclcheck_link(2):fa
  488. 43100:AUE_SYSARCH:sysarch(2):ot
  489. 43101:AUE_EXTATTRCTL:extattrctl(2):fm
  490. 43102:AUE_EXTATTR_GET_FILE:extattr_get_file(2):fa
  491. 43103:AUE_EXTATTR_SET_FILE:extattr_set_file(2):fm
  492. 43104:AUE_EXTATTR_LIST_FILE:extattr_list_file(2):fa
  493. 43105:AUE_EXTATTR_DELETE_FILE:extattr_delete_file(2):fm
  494. 43106:AUE_EXTATTR_GET_FD:extattr_get_fd(2):fa
  495. 43107:AUE_EXTATTR_SET_FD:extattr_set_fd(2):fm
  496. 43108:AUE_EXTATTR_LIST_FD:extattr_list_fd(2):fa
  497. 43109:AUE_EXTATTR_DELETE_FD:extattr_delete_fd(2):fm
  498. 43110:AUE_EXTATTR_GET_LINK:extattr_get_link(2):fa
  499. 43111:AUE_EXTATTR_SET_LINK:extattr_set_link(2):fm
  500. 43112:AUE_EXTATTR_LIST_LINK:extattr_list_link(2):fa
  501. 43113:AUE_EXTATTR_DELETE_LINK:extattr_delete_link(2):fm
  502. 43114:AUE_KENV:kenv(8):ad
  503. 43115:AUE_JAIL_ATTACH:jail_attach(2):ad
  504. 43116:AUE_SYSCTL_WRITE:sysctl(3):ad
  505. 43117:AUE_IOPERM:linux ioperm:ad
  506. 43118:AUE_READDIR:readdir(3):no
  507. 43119:AUE_IOPL:linux iopl:ad
  508. 43120:AUE_VM86:linux vm86:pc
  509. 43121:AUE_MAC_GET_PROC:mac_get_proc(2):pc
  510. 43122:AUE_MAC_SET_PROC:mac_set_proc(2):pc
  511. 43123:AUE_MAC_GET_FD:mac_get_fd(2):fa
  512. 43124:AUE_MAC_GET_FILE:mac_get_file(2):fa
  513. 43125:AUE_MAC_SET_FD:mac_set_fd(2):fm
  514. 43126:AUE_MAC_SET_FILE:mac_set_file(2):fm
  515. 43127:AUE_MAC_SYSCALL:mac_syscall(2):ad
  516. 43128:AUE_MAC_GET_PID:mac_get_pid(2):pc
  517. 43129:AUE_MAC_GET_LINK:mac_get_link(2):fa
  518. 43130:AUE_MAC_SET_LINK:mac_set_link(2):fm
  519. 43131:AUE_MAC_EXECVE:mac_execve(2):ex,pc
  520. 43132:AUE_GETPATH_FROMFD:getpath_fromfd(2):fa
  521. 43133:AUE_GETPATH_FROMADDR:getpath_fromaddr(2):fa
  522. 43134:AUE_MQ_OPEN:mq_open(2):ip
  523. 43135:AUE_MQ_SETATTR:mq_setattr(2):ip
  524. 43136:AUE_MQ_TIMEDRECEIVE:mq_timedreceive(2):ip
  525. 43137:AUE_MQ_TIMEDSEND:mq_timedsend(2):ip
  526. 43138:AUE_MQ_NOTIFY:mq_notify(2):ip
  527. 43139:AUE_MQ_UNLINK:mq_unlink(2):ip
  528. 43140:AUE_LISTEN:listen(2):nt
  529. 43141:AUE_MLOCKALL:mlockall(2):pc
  530. 43142:AUE_MUNLOCKALL:munlockall(2):pc
  531. 43143:AUE_CLOSEFROM:closefrom(2):cl
  532. 43144:AUE_FEXECVE:fexecve(2):pc,ex
  533. 43145:AUE_FACCESSAT:faccessat(2):fa
  534. 43146:AUE_FCHMODAT:fchmodat(2):fm
  535. 43147:AUE_LINKAT:linkat(2):fc
  536. 43148:AUE_MKDIRAT:mkdirat(2):fc
  537. 43149:AUE_MKFIFOAT:mkfifoat(2):fc
  538. 43150:AUE_MKNODAT:mknodat(2):fc
  539. 43151:AUE_READLINKAT:readlinkat(2):fr
  540. 43152:AUE_SYMLINKAT:symlinkat(2):fc
  541. 43153:AUE_MAC_GETFSSTAT:mac_getfsstat(2):fa
  542. 43154:AUE_MAC_GET_MOUNT:mac_get_mount(2):fa
  543. 43155:AUE_MAC_GET_LCID:mac_get_lcid(2):pc
  544. 43156:AUE_MAC_GET_LCTX:mac_get_lctx(2):pc
  545. 43157:AUE_MAC_SET_LCTX:mac_set_lctx(2):pc
  546. 43158:AUE_MAC_MOUNT:mac_mount(2):ad
  547. 43159:AUE_GETLCID:getlcid(2):pc
  548. 43160:AUE_SETLCID:setlcid(2):pc
  549. 43161:AUE_TASKNAMEFORPID:taskname_for_pid():pc
  550. 43162:AUE_ACCESS_EXTENDED:access_extended(2):fa
  551. 43163:AUE_CHMOD_EXTENDED:chmod_extended(2):fm
  552. 43164:AUE_FCHMOD_EXTENDED:fchmod_extended(2):fm
  553. 43165:AUE_FSTAT_EXTENDED:fstat_extended(2):fa
  554. 43166:AUE_LSTAT_EXTENDED:lstat_extended(2):fa
  555. 43167:AUE_MKDIR_EXTENDED:mkdir_extended(2):fc
  556. 43168:AUE_MKFIFO_EXTENDED:mkfifo_extended(2):fc
  557. 43169:AUE_OPEN_EXTENDED:open_extended(2) - attr only:fa
  558. 43170:AUE_OPEN_EXTENDED_R:open_extended(2) - read:fr
  559. 43171:AUE_OPEN_EXTENDED_RC:open_extended(2) - read,creat:fc,fr,fa,fm
  560. 43172:AUE_OPEN_EXTENDED_RT:open_extended(2) - read,trunc:fd,fr,fa,fm
  561. 43173:AUE_OPEN_EXTENDED_RTC:open_extended(2) - read,creat,trunc:fc,fd,fr,fa,fm
  562. 43174:AUE_OPEN_EXTENDED_W:open_extended(2) - write:fw
  563. 43175:AUE_OPEN_EXTENDED_WC:open_extended(2) - write,creat:fc,fw,fa,fm
  564. 43176:AUE_OPEN_EXTENDED_WT:open_extended(2) - write,trunc:fd,fw,fa,fm
  565. 43177:AUE_OPEN_EXTENDED_WTC:open_extended(2) - write,creat,trunc:fc,fd,fw,fa,fm
  566. 43178:AUE_OPEN_EXTENDED_RW:open_extended(2) - read,write:fr,fw
  567. 43179:AUE_OPEN_EXTENDED_RWC:open_extended(2) - read,write,creat:fc,fw,fr,fa,fm
  568. 43180:AUE_OPEN_EXTENDED_RWT:open_extended(2) - read,write,trunc:fd,fr,fw,fa,fm
  569. 43181:AUE_OPEN_EXTENDED_RWTC:open_extended(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
  570. 43182:AUE_STAT_EXTENDED:stat_extended(2):fa
  571. 43183:AUE_UMASK_EXTENDED:umask_extended(2):pc
  572. 43184:AUE_OPENAT:openat(2) - attr only:fa
  573. 43185:AUE_POSIX_OPENPT:posix_openpt(2):ip
  574. 43186:AUE_CAP_NEW:cap_new(2):fm
  575. 43187:AUE_CAP_GETRIGHTS:cap_getrights(2):fm
  576. 43188:AUE_CAP_ENTER:cap_enter(2):pc
  577. 43189:AUE_CAP_GETMODE:cap_getmode(2):pc
  578. 43190:AUE_POSIX_SPAWN:posix_spawn(2):pc
  579. 43191:AUE_FSGETPATH:fsgetpath(2):ot
  580. 43192:AUE_PREAD:pread(2):no
  581. 43193:AUE_PWRITE:pwrite(2):no
  582. 43194:AUE_FSCTL:fsctl():fm
  583. 43195:AUE_FFSCTL:ffsctl():fm
  584. 43196:AUE_LPATHCONF:lpathconf(2):fa
  585. 43197:AUE_PDFORK:pdfork(2):pc
  586. 43198:AUE_PDKILL:pdkill(2):pc
  587. 43199:AUE_PDGETPID:pdgetpid(2):pc
  588. 43200:AUE_PDWAIT:pdwait(2):pc
  589. #
  590. 44901:AUE_SESSION_START:session start:aa
  591. 44902:AUE_SESSION_UPDATE:session update:aa
  592. 44903:AUE_SESSION_END:session end:aa
  593. 44904:AUE_SESSION_CLOSE:session close:aa
  594. #
  595. # Solaris userspace events.
  596. #
  597. 6144:AUE_at_create:at-create atjob:ad
  598. 6145:AUE_at_delete:at-delete atjob (at or atrm):ad
  599. 6146:AUE_at_perm:at-permission:no
  600. 6147:AUE_cron_invoke:cron-invoke:ad
  601. 6148:AUE_crontab_create:crontab-crontab created:ad
  602. 6149:AUE_crontab_delete:crontab-crontab deleted:ad
  603. 6150:AUE_crontab_perm:crontab-permission:no
  604. 6151:AUE_inetd_connect:inetd connection:na
  605. 6152:AUE_login:login - local:lo
  606. 6153:AUE_logout:logout - local:lo
  607. 6154:AUE_telnet:login - telnet:lo
  608. 6155:AUE_rlogin:login - rlogin:lo
  609. 6156:AUE_mountd_mount:mount:na
  610. 6157:AUE_mountd_umount:unmount:na
  611. 6158:AUE_rshd:rsh access:lo
  612. 6159:AUE_su:su(1):lo
  613. 6160:AUE_halt:system halt:ad
  614. 6161:AUE_reboot:system reboot:ad
  615. 6162:AUE_rexecd:rexecd:lo
  616. 6163:AUE_passwd:passwd:lo
  617. 6164:AUE_rexd:rexd:lo
  618. 6165:AUE_ftpd:ftp access:lo
  619. 6166:AUE_init:init:lo
  620. 6167:AUE_uadmin:uadmin:no
  621. 6168:AUE_shutdown:system shutdown:ad
  622. 6168:AUE_poweroff:system poweroff:ad
  623. 6170:AUE_crontab_mod:crontab-modify:ad
  624. 6171:AUE_ftpd_logout:ftp logout:lo
  625. 6172:AUE_ssh:login - ssh:lo
  626. 6173:AUE_role_login:role login:lo
  627. 6180:AUE_prof_cmd: profile command:ad
  628. 6181:AUE_filesystem_add:add filesystem:ad
  629. 6182:AUE_filesystem_delete:delete filesystem:ad
  630. 6183:AUE_filesystem_modify:modify filesystem:ad
  631. 6200:AUE_allocate_succ:allocate-device success:ot
  632. 6201:AUE_allocate_fail:allocate-device failure:ot
  633. 6202:AUE_deallocate_succ:deallocate-device success:ot
  634. 6203:AUE_deallocate_fail:deallocate-device failure:ot
  635. 6204:AUE_listdevice_succ:allocate-list devices success:ot
  636. 6205:AUE_listdevice_fail:allocate-list devices failure:ot
  637. 6207:AUE_create_user:create user:ad
  638. 6208:AUE_modify_user:modify user:ad
  639. 6209:AUE_delete_user:delete user:ad
  640. 6210:AUE_disable_user:disable user:ad
  641. 6211:AUE_enable_user:enable user:ad
  642. 6212:AUE_newgrp_login:newgrp login:lo
  643. 6213:AUE_admin_authenticate:admin login:lo
  644. 6214:AUE_kadmind_auth:authenticated kadmind request:ua
  645. 6215:AUE_kadmind_unauth:unauthenticated kadmind req:ua
  646. 6216:AUE_krb5kdc_as_req:kdc authentication svc request:ap
  647. 6217:AUE_krb5kdc_tgs_req:kdc tkt-grant svc request:ap
  648. 6218:AUE_krb5kdc_tgs_req_2ndtktmm:kdc tgs 2ndtkt mismtch:ap
  649. 6219:AUE_krb5kdc_tgs_req_alt_tgt:kdc tgs issue alt tgt:ap
  650. #
  651. # Historic Darwin use of low event numbering space, which collided with the
  652. # Solaris event space. Now obsoleted and new, higher, event numbers assigned
  653. # to make it easier to interpret Solaris events using the OpenBSM tools.
  654. #
  655. 6171:AUE_DARWIN_audit_startup:audit startup:ad
  656. 6172:AUE_DARWIN_audit_shutdown:audit shutdown:ad
  657. 6300:AUE_DARWIN_sudo:sudo(1):ad
  658. 6501:AUE_DARWIN_modify_password:modify password:ad
  659. 6511:AUE_DARWIN_create_group:create group:ad
  660. 6512:AUE_DARWIN_delete_group:delete group:ad
  661. 6513:AUE_DARWIN_modify_group:modify group:ad
  662. 6514:AUE_DARWIN_add_to_group:add to group:ad
  663. 6515:AUE_DARWIN_remove_from_group:remove from group:ad
  664. 6521:AUE_DARWIN_revoke_obj:revoke object priv:fm
  665. 6600:AUE_DARWIN_lw_login:loginwindow login:lo
  666. 6601:AUE_DARWIN_lw_logout:loginwindow logout:lo
  667. 7000:AUE_DARWIN_auth_user:user authentication:aa
  668. 7001:AUE_DARWIN_ssconn:SecSrvr connection setup:aa
  669. 7002:AUE_DARWIN_ssauthorize:SecSrvr AuthEngine:aa
  670. 7003:AUE_DARWIN_ssauthint:SecSrvr authinternal mech:aa
  671. #
  672. # Historic/third-party application allocations of event identifiers.
  673. #
  674. 32800:AUE_openssh:OpenSSH login:lo
  675.  
  676. 43201:AUE_GETATTRLISTBULK:getattrlistbulk(2):fa
  677. 43202:AUE_GETATTRLISTAT:getattrlistat(2):fa
  678. 43203:AUE_OPENBYID: openbyid(2) - attr only:fa
  679. 43204:AUE_OPENBYID_R:openbyid(2) - read:fr
  680. 43205:AUE_OPENBYID_RT:openbyid(2) - read,trunc:fd,fr,fa,fm
  681. 43206:AUE_OPENBYID_W:openbyid(2) - write:fw
  682. 43207:AUE_OPENBYID_WT:openbyid(2) - write,trunc:fd,fw,fa,fm
  683. 43208:AUE_OPENBYID_RW:openbyid(2) - read,write:fr,fw
  684. 43209:AUE_OPENBYID_RWT:openbyid(2) - read,write,trunc:fd,fr,fw,fa,fm
  685. #
  686. # OpenBSM-managed application event space.
  687. #
  688. 45000:AUE_audit_startup:audit startup:ad
  689. 45001:AUE_audit_shutdown:audit shutdown:ad
  690. 45014:AUE_modify_password:modify password:ad
  691. 45015:AUE_create_group:create group:ad
  692. 45016:AUE_delete_group:delete group:ad
  693. 45017:AUE_modify_group:modify group:ad
  694. 45018:AUE_add_to_group:add to group:ad
  695. 45019:AUE_remove_from_group:remove from group:ad
  696. 45020:AUE_revoke_obj:revoke object priv:fm
  697. 45021:AUE_lw_login:loginwindow login:lo
  698. 45022:AUE_lw_logout:loginwindow logout:lo
  699. 45023:AUE_auth_user:user authentication:aa
  700. 45024:AUE_ssconn:SecSrvr connection setup:aa
  701. 45025:AUE_ssauthorize:SecSrvr AuthEngine:aa
  702. 45026:AUE_ssauthint:SecSrvr authinternal mech:aa
  703. 45027:AUE_calife:Calife:ad
  704. 45028:AUE_sudo:sudo(1):aa
  705. 45029:AUE_audit_recovery:audit crash recovery:ad
  706. 45030:AUE_ssauthmech:SecSrvr AuthMechanism:aa
  707. 45031:AUE_sec_assessment:Security Assessment:aa
  708. cat: security/audit_user: Permission denied
  709. #!/bin/sh
  710. #
  711. # $P4: //depot/projects/trustedbsd/openbsm/etc/audit_warn#3 $
  712. #
  713. # command-line arguments are in the form:
  714. # <warning type> [optional argument] [optional flags]
  715. #
  716. # where the warning type may be:
  717. #
  718. # allhard All audit trail volumes are over the hard limit.
  719. # allsoft All audit trail volumes are over the soft limit.
  720. # auditoff Auditing has been disabled by someone other than auditd.
  721. # closefile The given trail file has been closed so it is now safe
  722. # to post-proccess.
  723. # ebusy The auditd is already running.
  724. # getacdir The audit trail directory couldn't be parsed from audit_control.
  725. # hardlimit The given trail volume is over the hard limit.
  726. # nostart Auditing could not be started.
  727. # postsigterm There was a problem shutting down auditd.
  728. # soft The given trail volume is over the soft limit.
  729. # tmpfile The temporary audit trail file already exist.
  730. # expired The given trail file expired and was removed.
  731. #
  732. # and where the optional flags may be:
  733. #
  734. # --will-sleep The system is planning to go to sleep.
  735.  
  736. argument=""
  737. willsleep=0
  738. type=$1
  739. shift
  740.  
  741. while [ $# -ge 1 ]; do
  742. case $1 in
  743. --will-sleep) willsleep=1 ;;
  744. *) argument=$1 ;;
  745. esac
  746. shift
  747. done
  748.  
  749. # Don't log audit warning events when the system is about to sleep.
  750. if [ $willsleep -eq 0 ]; then
  751. logger -p security.warning "audit warning: $type $argument"
  752. fi
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement