Lines Matching refs:audit
62 #include <bsm/audit.h>
65 #include <security/audit/audit.h>
66 #include <security/audit/audit_bsd.h>
67 #include <security/audit/audit_private.h>
140 * System call to allow a user space application to submit a BSM audit record
141 * to the kernel for inclusion in the audit log. This function does little
142 * verification on the audit record that is submitted.
146 * type submitted as part of the user audit data.
150 audit(proc_t p, struct audit_args *uap, __unused int32_t *retval)
171 * If there's no current audit record (audit() itself not audited)
172 * commit the user audit record.
181 * complete kernel audit record just so the user record can
212 * Attach the user audit record to the kernel audit record. Because
214 * record along with the record for this audit event.
234 * audit_syscall_exit() will free the audit record on the thread even
305 * gets to see the audit masks.
319 /* Getting one's own audit session flags requires no
738 * System calls to manage the user audit information.
895 * Syscall to manage audit files.
919 * XXX Changes API slightly. NULL path no longer disables audit but
936 * is appropriate for storing audit data, or that the caller was
938 * confidentiality policy may want to ensure that audit files are
975 audit(proc_t p, struct audit_args *uap, int32_t *retval)