-
Copyright (c) 2005 Tom Rhodes
Copyright (c) 2005 Robert N. M. Watson
All rights reserved.

Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.

THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.

$P4: //depot/projects/trustedbsd/openbsm/man/audit.2#9 $

.Dd April 19, 2005 .Dt AUDIT 2 .Os .Sh NAME .Nm audit .Nd "commit BSM audit record to audit log" .Sh SYNOPSIS n bsm/audit.h .Ft int .Fn audit "const char *record" "u_int length" .Sh DESCRIPTION The .Fn audit system call submits a completed BSM audit record to the system audit log.

p The .Fa record argument is a pointer to the specific event to be recorded and .Fa length is the size in bytes of the data to be written. .Sh RETURN VALUES .Rv -std .Sh ERRORS The .Fn audit system call will fail and the data never written if: l -tag -width Er t Bq Er EFAULT The .Fa record argument is beyond the allocated address space of the process. t Bq Er EINVAL The token ID is invalid or .Va length is larger than .Dv MAXAUDITDATA . t Bq Er EPERM The process does not have sufficient permission to complete the operation. .El .Sh SEE ALSO .Xr auditon 2 , .Xr getaudit 2 , .Xr getaudit_addr 2 , .Xr getauid 2 , .Xr setaudit 2 , .Xr setaudit_addr 2 , .Xr setauid 2 , .Xr libbsm 3 .Sh HISTORY The OpenBSM implementation was created by McAfee Research, the security division of McAfee Inc., under contract to Apple Computer Inc. in 2004. It was subsequently adopted by the TrustedBSD Project as the foundation for the OpenBSM distribution. .Sh AUTHORS .An -nosplit This software was created by McAfee Research, the security research division of McAfee, Inc., under contract to Apple Computer Inc. Additional authors include .An Wayne Salamon , .An Robert Watson , and SPARTA Inc.

p The Basic Security Module (BSM) interface to audit records and audit event stream format were defined by Sun Microsystems.

p This manual page was written by .An Tom Rhodes Aq trhodes@FreeBSD.org . .Sh BUGS The .Fx kernel does not fully validate that the argument passed is syntactically valid BSM. Submitting invalid audit records may corrupt the audit log.