xref: /illumos-gate/usr/src/uts/common/syscall/auditsys.c (revision 8b80e8cb6855118d46f605e91b5ed4ce83417395)
1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://www.opensolaris.org/os/licensing.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright 2008 Sun Microsystems, Inc.  All rights reserved.
23  * Use is subject to license terms.
24  */
25 
26 #pragma ident	"%Z%%M%	%I%	%E% SMI"
27 
28 #include <sys/systm.h>
29 #include <sys/errno.h>
30 #include <sys/policy.h>
31 
32 #include <c2/audit.h>
33 
34 /*ARGSUSED1*/
35 int
36 auditsys(struct auditcalls *uap, rval_t *rvp)
37 {
38 	int err;
39 
40 	/*
41 	 * this ugly hack is because auditsys returns 0 for
42 	 * all cases except audit_active == 0 and
43 	 * uap->code  == BSM_AUDITCTRL || BSM_AUDITON || default)
44 	 */
45 
46 	if (!audit_active)
47 		return (ENOTSUP);
48 
49 	switch (uap->code) {
50 	case BSM_GETAUID:
51 	case BSM_SETAUID:
52 	case BSM_GETAUDIT:
53 	case BSM_SETAUDIT:
54 	case BSM_AUDIT:
55 		return (0);
56 	case BSM_AUDITCTL:
57 	case BSM_AUDITON:
58 		if ((int)uap->a1 == A_GETCOND)
59 			err = secpolicy_audit_getattr(CRED());
60 		else
61 			/* FALLTHROUGH */
62 	default:
63 		/* Return a different error when not privileged */
64 		err = secpolicy_audit_config(CRED());
65 		if (err == 0)
66 			return (EINVAL);
67 		else
68 			return (err);
69 	}
70 }
71