1*7c478bd9Sstevel@tonic-gate /* 2*7c478bd9Sstevel@tonic-gate * CDDL HEADER START 3*7c478bd9Sstevel@tonic-gate * 4*7c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5*7c478bd9Sstevel@tonic-gate * Common Development and Distribution License, Version 1.0 only 6*7c478bd9Sstevel@tonic-gate * (the "License"). You may not use this file except in compliance 7*7c478bd9Sstevel@tonic-gate * with the License. 8*7c478bd9Sstevel@tonic-gate * 9*7c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 10*7c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 11*7c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 12*7c478bd9Sstevel@tonic-gate * and limitations under the License. 13*7c478bd9Sstevel@tonic-gate * 14*7c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 15*7c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 16*7c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 17*7c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 18*7c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 19*7c478bd9Sstevel@tonic-gate * 20*7c478bd9Sstevel@tonic-gate * CDDL HEADER END 21*7c478bd9Sstevel@tonic-gate */ 22*7c478bd9Sstevel@tonic-gate /* 23*7c478bd9Sstevel@tonic-gate * Copyright 1994,2002-2003 Sun Microsystems, Inc. All rights reserved. 24*7c478bd9Sstevel@tonic-gate * Use is subject to license terms. 25*7c478bd9Sstevel@tonic-gate */ 26*7c478bd9Sstevel@tonic-gate 27*7c478bd9Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 28*7c478bd9Sstevel@tonic-gate 29*7c478bd9Sstevel@tonic-gate #include <sys/systm.h> 30*7c478bd9Sstevel@tonic-gate #include <sys/errno.h> 31*7c478bd9Sstevel@tonic-gate #include <sys/policy.h> 32*7c478bd9Sstevel@tonic-gate 33*7c478bd9Sstevel@tonic-gate #include <c2/audit.h> 34*7c478bd9Sstevel@tonic-gate 35*7c478bd9Sstevel@tonic-gate /*ARGSUSED1*/ 36*7c478bd9Sstevel@tonic-gate int 37*7c478bd9Sstevel@tonic-gate auditsys(struct auditcalls *uap, rval_t *rvp) 38*7c478bd9Sstevel@tonic-gate { 39*7c478bd9Sstevel@tonic-gate int err; 40*7c478bd9Sstevel@tonic-gate 41*7c478bd9Sstevel@tonic-gate /* 42*7c478bd9Sstevel@tonic-gate * this ugly hack is because auditsys returns 0 for 43*7c478bd9Sstevel@tonic-gate * all cases except audit_active == 0 and 44*7c478bd9Sstevel@tonic-gate * uap->code == BSM_AUDITCTRL || BSM_AUDITON || default) 45*7c478bd9Sstevel@tonic-gate */ 46*7c478bd9Sstevel@tonic-gate 47*7c478bd9Sstevel@tonic-gate switch (uap->code) { 48*7c478bd9Sstevel@tonic-gate case BSM_GETAUID: 49*7c478bd9Sstevel@tonic-gate case BSM_SETAUID: 50*7c478bd9Sstevel@tonic-gate case BSM_GETAUDIT: 51*7c478bd9Sstevel@tonic-gate case BSM_SETAUDIT: 52*7c478bd9Sstevel@tonic-gate case BSM_AUDIT: 53*7c478bd9Sstevel@tonic-gate case BSM_AUDITSVC: 54*7c478bd9Sstevel@tonic-gate return (0); 55*7c478bd9Sstevel@tonic-gate case BSM_AUDITCTL: 56*7c478bd9Sstevel@tonic-gate case BSM_AUDITON: 57*7c478bd9Sstevel@tonic-gate if ((int)uap->a1 == A_GETCOND) 58*7c478bd9Sstevel@tonic-gate err = secpolicy_audit_getattr(CRED()); 59*7c478bd9Sstevel@tonic-gate else 60*7c478bd9Sstevel@tonic-gate /* FALLTHROUGH */ 61*7c478bd9Sstevel@tonic-gate default: 62*7c478bd9Sstevel@tonic-gate /* Return a different error when not privileged */ 63*7c478bd9Sstevel@tonic-gate err = secpolicy_audit_config(CRED()); 64*7c478bd9Sstevel@tonic-gate if (err == 0) 65*7c478bd9Sstevel@tonic-gate return (EINVAL); 66*7c478bd9Sstevel@tonic-gate else 67*7c478bd9Sstevel@tonic-gate return (err); 68*7c478bd9Sstevel@tonic-gate } 69*7c478bd9Sstevel@tonic-gate } 70