From 0f48dc75aa96065ce62a300ff7822b8bca65141a Mon Sep 17 00:00:00 2001 From: rwatson Date: Sun, 8 Feb 2009 14:24:35 +0000 Subject: Audit AUE_MAC_EXECVE; currently just the standard AUE_EXECVE arguments and not the label. Obtained from: TrustedBSD Project Sponsored by: Apple, Inc. MFC after: 1 week --- sys/security/audit/audit_bsm.c | 1 + 1 file changed, 1 insertion(+) (limited to 'sys/security') diff --git a/sys/security/audit/audit_bsm.c b/sys/security/audit/audit_bsm.c index c4acf16..3326961 100644 --- a/sys/security/audit/audit_bsm.c +++ b/sys/security/audit/audit_bsm.c @@ -791,6 +791,7 @@ kaudit_to_bsm(struct kaudit_record *kar, struct au_record **pau) /* FALLTHROUGH */ case AUE_EXECVE: + case AUE_MAC_EXECVE: if (ARG_IS_VALID(kar, ARG_ARGV)) { tok = au_to_exec_args(ar->ar_arg_argv, ar->ar_arg_argc); -- cgit v1.1