From 7e612564be64e0f3e28cbecfb1f0f8a77402fdeb Mon Sep 17 00:00:00 2001 From: rwatson Date: Mon, 29 Oct 2007 18:43:05 +0000 Subject: Resolve conflicts from import of OpenBSM 1.0: maintain $FreeBSD$ tags in /etc/security audit configuration files. --- contrib/openbsm/etc/audit_class | 4 +--- contrib/openbsm/etc/audit_event | 10 ++++++++-- 2 files changed, 9 insertions(+), 5 deletions(-) (limited to 'contrib/openbsm') diff --git a/contrib/openbsm/etc/audit_class b/contrib/openbsm/etc/audit_class index f65ae41..068d2fc 100644 --- a/contrib/openbsm/etc/audit_class +++ b/contrib/openbsm/etc/audit_class @@ -1,9 +1,7 @@ # -# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_class#4 $ +# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_class#5 $ # $FreeBSD$ # -# This file must match audit.h -# 0x00000000:no:invalid class 0x00000001:fr:file read 0x00000002:fw:file write diff --git a/contrib/openbsm/etc/audit_event b/contrib/openbsm/etc/audit_event index 2c8d57d..2b11824 100644 --- a/contrib/openbsm/etc/audit_event +++ b/contrib/openbsm/etc/audit_event @@ -1,7 +1,13 @@ # -# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_event#25 $ +# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_event#26 $ # $FreeBSD$ # +# The mapping between event identifiers and values is also hard-codedd in +# audit_kevents.h and audit_uevents.h, so changes must occur in both places, +# and programs, such as the kernel, may need to be recompiled to recognize +# those changes. It is advisable not to change the numbering or naming of +# kernel audit events. +# 0:AUE_NULL:indir system call:no 1:AUE_EXIT:exit(2):pc 2:AUE_FORK:fork(2):pc @@ -438,7 +444,7 @@ 43097:AUE_ACL_SET_LINK:acl_set_link(2):fm 43098:AUE_ACL_DELETE_LINK:acl_delete_link(2):fm 43099:AUE_ACL_CHECK_LINK:acl_aclcheck_link(2):fa -43100:AUE_SYSARCH:sysarch(2):na +43100:AUE_SYSARCH:sysarch(2):ot 43101:AUE_EXTATTRCTL:extattrctl(2):fm 43102:AUE_EXTATTR_GET_FILE:extattr_get_file(2):fa 43103:AUE_EXTATTR_SET_FILE:extattr_set_file(2):fm -- cgit v1.1