84f8c77a42
- Add a new "qsize" parameter in audit_control and the getacqsize(3) API to query it, allowing to set the kernel's maximum audit queue length. - Add support to push a mapping between audit event names and event numbers into the kernel (where supported) using new A_GETEVENT and A_SETEVENT auditon(2) operations. - Add audit event identifiers for a number of new (and not-so-new) FreeBSD system calls including those for asynchronous I/O, thread management, SCTP, jails, multi-FIB support, and misc. POSIX interfaces such as posix_fallocate(2) and posix_fadvise(2). - On operating systems supporting Capsicum, auditreduce(1) and praudit(1) now run sandboxed. - Empty "flags" and "naflags" fields are now permitted in audit_control(5). Many thanks to Christian Brueffer for producing the OpenBSM release and importing/tagging it in the vendor branch. This release will allow improved auditing of a range of new FreeBSD functionality, as well as non-traditional events (e.g., fine-grained I/O auditing) not required by the Orange Book or Common Criteria. Obtained from: TrustedBSD Project Sponsored by: DARPA, AFRL MFC after: 3 weeks |
||
---|---|---|
.. | ||
au_class.3 | ||
au_control.3 | ||
au_domain.3 | ||
au_errno.3 | ||
au_event.3 | ||
au_fcntl_cmd.3 | ||
au_free_token.3 | ||
au_io.3 | ||
au_mask.3 | ||
au_notify.3 | ||
au_open.3 | ||
au_socket_type.3 | ||
au_token.3 | ||
au_user.3 | ||
audit_submit.3 | ||
bsm_audit.c | ||
bsm_class.c | ||
bsm_control.c | ||
bsm_domain.c | ||
bsm_errno.c | ||
bsm_event.c | ||
bsm_fcntl.c | ||
bsm_flags.c | ||
bsm_io.c | ||
bsm_mask.c | ||
bsm_notify.c | ||
bsm_socket_type.c | ||
bsm_token.c | ||
bsm_user.c | ||
bsm_wrappers.c | ||
libbsm.3 | ||
Makefile.am | ||
Makefile.in |