Home | History | Annotate | Download | only in syscall
      1 /*
      2  * CDDL HEADER START
      3  *
      4  * The contents of this file are subject to the terms of the
      5  * Common Development and Distribution License (the "License").
      6  * You may not use this file except in compliance with the License.
      7  *
      8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
      9  * or http://www.opensolaris.org/os/licensing.
     10  * See the License for the specific language governing permissions
     11  * and limitations under the License.
     12  *
     13  * When distributing Covered Code, include this CDDL HEADER in each
     14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
     15  * If applicable, add the following below this CDDL HEADER, with the
     16  * fields enclosed by brackets "[]" replaced with your own identifying
     17  * information: Portions Copyright [yyyy] [name of copyright owner]
     18  *
     19  * CDDL HEADER END
     20  */
     21 /*
     22  * Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
     23  * Use is subject to license terms.
     24  */
     25 
     26 #include <sys/systm.h>
     27 #include <sys/errno.h>
     28 #include <sys/policy.h>
     29 
     30 #include <c2/audit.h>
     31 
     32 /*ARGSUSED1*/
     33 int
     34 auditsys(struct auditcalls *uap, rval_t *rvp)
     35 {
     36 	int err;
     37 
     38 	/*
     39 	 * this ugly hack is because auditsys returns
     40 	 * 0 for all cases except audit_active == 0
     41 	 * and uap->code  == BSM_AUDITCTL || default)
     42 	 */
     43 
     44 	if (!audit_active)
     45 		return (ENOTSUP);
     46 
     47 	switch (uap->code) {
     48 	case BSM_GETAUID:
     49 	case BSM_SETAUID:
     50 	case BSM_GETAUDIT:
     51 	case BSM_SETAUDIT:
     52 	case BSM_AUDIT:
     53 		return (0);
     54 	case BSM_AUDITCTL:
     55 		if ((int)uap->a1 == A_GETCOND)
     56 			err = secpolicy_audit_getattr(CRED());
     57 		else
     58 			/* FALLTHROUGH */
     59 	default:
     60 		/* Return a different error when not privileged */
     61 		err = secpolicy_audit_config(CRED());
     62 		if (err == 0)
     63 			return (EINVAL);
     64 		else
     65 			return (err);
     66 	}
     67 }
     68