xref: /onnv-gate/usr/src/lib/auditd_plugins/syslog/sysplugin.h (revision 0:68f95e015346)
1*0Sstevel@tonic-gate /*
2*0Sstevel@tonic-gate  * CDDL HEADER START
3*0Sstevel@tonic-gate  *
4*0Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5*0Sstevel@tonic-gate  * Common Development and Distribution License, Version 1.0 only
6*0Sstevel@tonic-gate  * (the "License").  You may not use this file except in compliance
7*0Sstevel@tonic-gate  * with the License.
8*0Sstevel@tonic-gate  *
9*0Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10*0Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
11*0Sstevel@tonic-gate  * See the License for the specific language governing permissions
12*0Sstevel@tonic-gate  * and limitations under the License.
13*0Sstevel@tonic-gate  *
14*0Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
15*0Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
16*0Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
17*0Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
18*0Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
19*0Sstevel@tonic-gate  *
20*0Sstevel@tonic-gate  * CDDL HEADER END
21*0Sstevel@tonic-gate  */
22*0Sstevel@tonic-gate /*
23*0Sstevel@tonic-gate  * Copyright 2003 Sun Microsystems, Inc.  All rights reserved.
24*0Sstevel@tonic-gate  * Use is subject to license terms.
25*0Sstevel@tonic-gate  */
26*0Sstevel@tonic-gate 
27*0Sstevel@tonic-gate #ifndef	_SYSPLUGIN_H
28*0Sstevel@tonic-gate #define	_SYSPLUGIN_H
29*0Sstevel@tonic-gate 
30*0Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
31*0Sstevel@tonic-gate 
32*0Sstevel@tonic-gate #ifdef __cplusplus
33*0Sstevel@tonic-gate extern "C" {
34*0Sstevel@tonic-gate #endif
35*0Sstevel@tonic-gate 
36*0Sstevel@tonic-gate #include <sys/types.h>
37*0Sstevel@tonic-gate #include <bsm/audit.h>
38*0Sstevel@tonic-gate 
39*0Sstevel@tonic-gate struct selected_fields {
40*0Sstevel@tonic-gate 	/* from header token */
41*0Sstevel@tonic-gate 	au_event_t	sf_eventid;	/* 0 if no value */
42*0Sstevel@tonic-gate 	uint32_t	sf_reclen;	/* 0 if no value */
43*0Sstevel@tonic-gate 
44*0Sstevel@tonic-gate 	/* from exit or return token */
45*0Sstevel@tonic-gate 	int		sf_pass;	/* 0 no value, -1 fail, 1 pass */
46*0Sstevel@tonic-gate 
47*0Sstevel@tonic-gate 	/* from subject token */
48*0Sstevel@tonic-gate 	uint32_t	sf_asid;	/* 0 no value */
49*0Sstevel@tonic-gate 	uid_t		sf_auid;	/* -2 no value, > -1 otherwise */
50*0Sstevel@tonic-gate 	uid_t		sf_euid;	/* -2 no value, > -1 otherwise */
51*0Sstevel@tonic-gate 	gid_t		sf_egid;	/* -2 no value, > -1 otherwise */
52*0Sstevel@tonic-gate 	au_tid_addr_t	sf_tid;		/* tid.at_type = 0 no value */
53*0Sstevel@tonic-gate 
54*0Sstevel@tonic-gate 	/* from process token */
55*0Sstevel@tonic-gate 	uid_t		sf_pauid;	/* -2 no value */
56*0Sstevel@tonic-gate 	uid_t		sf_peuid;	/* -2 no value */
57*0Sstevel@tonic-gate 
58*0Sstevel@tonic-gate 	/* data that may be truncated goes after this point */
59*0Sstevel@tonic-gate 
60*0Sstevel@tonic-gate 	/* from uauth token */
61*0Sstevel@tonic-gate 	size_t		sf_uauthlen;
62*0Sstevel@tonic-gate 	char		*sf_uauth;	/* NULL no value */
63*0Sstevel@tonic-gate 
64*0Sstevel@tonic-gate 	/* from text token */
65*0Sstevel@tonic-gate 	size_t		sf_textlen;
66*0Sstevel@tonic-gate 	char		*sf_text;	/* NULL no value */
67*0Sstevel@tonic-gate 
68*0Sstevel@tonic-gate 	/* from path and atpath token */
69*0Sstevel@tonic-gate 	size_t		sf_pathlen;
70*0Sstevel@tonic-gate 	char		*sf_path;		/* NULL no value */
71*0Sstevel@tonic-gate 	size_t		sf_atpathlen;
72*0Sstevel@tonic-gate 	char		*sf_atpath;	/* NULL no value */
73*0Sstevel@tonic-gate 
74*0Sstevel@tonic-gate 	/* from sequence token */
75*0Sstevel@tonic-gate 	int32_t		sf_sequence;	/* -1 no value */
76*0Sstevel@tonic-gate 
77*0Sstevel@tonic-gate 	/* from zonename token */
78*0Sstevel@tonic-gate 	size_t		sf_zonelen;
79*0Sstevel@tonic-gate 	char		*sf_zonename;	/* NULL no value */
80*0Sstevel@tonic-gate };
81*0Sstevel@tonic-gate typedef struct selected_fields tosyslog_t;
82*0Sstevel@tonic-gate 
83*0Sstevel@tonic-gate 
84*0Sstevel@tonic-gate #ifdef __cplusplus
85*0Sstevel@tonic-gate }
86*0Sstevel@tonic-gate #endif
87*0Sstevel@tonic-gate 
88*0Sstevel@tonic-gate #endif	/* _SYSPLUGIN_H */
89