Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
freebsd
GitHub Repository: freebsd/freebsd-src
Path: blob/main/sys/bsm/audit_internal.h
39475 views
1
/*-
2
* SPDX-License-Identifier: BSD-3-Clause
3
*
4
* Copyright (c) 2005-2008 Apple Inc.
5
* Copyright (c) 2005 SPARTA, Inc.
6
* All rights reserved.
7
*
8
* This code was developed in part by Robert N. M. Watson, Senior Principal
9
* Scientist, SPARTA, Inc.
10
*
11
* Redistribution and use in source and binary forms, with or without
12
* modification, are permitted provided that the following conditions
13
* are met:
14
*
15
* 1. Redistributions of source code must retain the above copyright
16
* notice, this list of conditions and the following disclaimer.
17
* 2. Redistributions in binary form must reproduce the above copyright
18
* notice, this list of conditions and the following disclaimer in the
19
* documentation and/or other materials provided with the distribution.
20
* 3. Neither the name of Apple Inc. ("Apple") nor the names of
21
* its contributors may be used to endorse or promote products derived
22
* from this software without specific prior written permission.
23
*
24
* THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
25
* EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
26
* WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
27
* DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
28
* DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
29
* (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
30
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
31
* ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
32
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
33
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34
*/
35
36
#ifndef _AUDIT_INTERNAL_H
37
#define _AUDIT_INTERNAL_H
38
39
#if defined(__linux__) && !defined(__unused)
40
#define __unused
41
#endif
42
43
/*
44
* audit_internal.h contains private interfaces that are shared by user space
45
* and the kernel for the purposes of assembling audit records. Applications
46
* should not include this file or use the APIs found within, or it may be
47
* broken with future releases of OpenBSM, which may delete, modify, or
48
* otherwise break these interfaces or the assumptions they rely on.
49
*/
50
struct au_token {
51
u_char *t_data;
52
size_t len;
53
TAILQ_ENTRY(au_token) tokens;
54
};
55
56
struct au_record {
57
char used; /* Record currently in use? */
58
int desc; /* Descriptor for record. */
59
TAILQ_HEAD(, au_token) token_q; /* Queue of BSM tokens. */
60
u_char *data;
61
size_t len;
62
LIST_ENTRY(au_record) au_rec_q;
63
};
64
typedef struct au_record au_record_t;
65
66
67
/*
68
* We could determined the header and trailer sizes by defining appropriate
69
* structures. We hold off that approach until we have a consistent way of
70
* using structures for all tokens. This is not straightforward since these
71
* token structures may contain pointers of whose contents we do not know the
72
* size (e.g text tokens).
73
*/
74
#define AUDIT_HEADER_EX_SIZE(a) ((a)->ai_termid.at_type+18+sizeof(u_int32_t))
75
#define AUDIT_HEADER_SIZE 18
76
#define MAX_AUDIT_HEADER_SIZE (5*sizeof(u_int32_t)+18)
77
#define AUDIT_TRAILER_SIZE 7
78
79
/*
80
* BSM token streams store fields in big endian byte order, so as to be
81
* portable; when encoding and decoding, we must convert byte orders for
82
* typed values.
83
*/
84
#define ADD_U_CHAR(loc, val) \
85
do { \
86
*(loc) = (val); \
87
(loc) += sizeof(u_char); \
88
} while(0)
89
90
91
#define ADD_U_INT16(loc, val) \
92
do { \
93
be16enc((loc), (val)); \
94
(loc) += sizeof(u_int16_t); \
95
} while(0)
96
97
#define ADD_U_INT32(loc, val) \
98
do { \
99
be32enc((loc), (val)); \
100
(loc) += sizeof(u_int32_t); \
101
} while(0)
102
103
#define ADD_U_INT64(loc, val) \
104
do { \
105
be64enc((loc), (val)); \
106
(loc) += sizeof(u_int64_t); \
107
} while(0)
108
109
#define ADD_MEM(loc, data, size) \
110
do { \
111
memcpy((loc), (data), (size)); \
112
(loc) += size; \
113
} while(0)
114
115
#define ADD_STRING(loc, data, size) ADD_MEM(loc, data, size)
116
117
#endif /* !_AUDIT_INTERNAL_H_ */
118
119