audit_event revision 185573
11558Srgrimes# 21558Srgrimes# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_event#30 $ 31558Srgrimes# $FreeBSD: head/contrib/openbsm/etc/audit_event 185573 2008-12-02 23:26:43Z rwatson $ 41558Srgrimes# 51558Srgrimes# The mapping between event identifiers and values is also hard-coded in 61558Srgrimes# audit_kevents.h and audit_uevents.h, so changes must occur in both places, 71558Srgrimes# and programs, such as the kernel, may need to be recompiled to recognize 81558Srgrimes# those changes. It is advisable not to change the numbering or naming of 91558Srgrimes# kernel audit events. 101558Srgrimes# 111558Srgrimes0:AUE_NULL:indir system call:no 121558Srgrimes1:AUE_EXIT:exit(2):pc 131558Srgrimes2:AUE_FORK:fork(2):pc 141558Srgrimes3:AUE_OPEN:open(2) - attr only:fa 151558Srgrimes4:AUE_CREAT:creat(2):fc 161558Srgrimes5:AUE_LINK:link(2):fc 171558Srgrimes6:AUE_UNLINK:unlink(2):fd 181558Srgrimes7:AUE_EXEC:exec(2):pc,ex 191558Srgrimes8:AUE_CHDIR:chdir(2):pc 201558Srgrimes9:AUE_MKNOD:mknod(2):fc 211558Srgrimes10:AUE_CHMOD:chmod(2):fm 221558Srgrimes11:AUE_CHOWN:chown(2):fm 231558Srgrimes12:AUE_UMOUNT:umount(2) - old version:ad 241558Srgrimes13:AUE_JUNK:junk:no 251558Srgrimes14:AUE_ACCESS:access(2):fa 261558Srgrimes15:AUE_KILL:kill(2):pc 271558Srgrimes16:AUE_STAT:stat(2):fa 281558Srgrimes17:AUE_LSTAT:lstat(2):fa 291558Srgrimes18:AUE_ACCT:acct(2):ad 301558Srgrimes19:AUE_MCTL:mctl(2):no 311558Srgrimes20:AUE_REBOOT:reboot(2):ad 321558Srgrimes21:AUE_SYMLINK:symlink(2):fc 331558Srgrimes22:AUE_READLINK:readlink(2):fr 341558Srgrimes23:AUE_EXECVE:execve(2):pc,ex 351558Srgrimes24:AUE_CHROOT:chroot(2):pc 361558Srgrimes25:AUE_VFORK:vfork(2):pc 371558Srgrimes26:AUE_SETGROUPS:setgroups(2):pc 3837663Scharnier27:AUE_SETPGRP:setpgrp(2):pc 391558Srgrimes28:AUE_SWAPON:swapon(2):ad 401558Srgrimes29:AUE_SETHOSTNAME:sethostname(2):ad 412999Swollman30:AUE_FCNTL:fcntl(2):fm 421558Srgrimes31:AUE_SETPRIORITY:setpriority(2):pc 431558Srgrimes32:AUE_CONNECT:connect(2):nt 4437663Scharnier33:AUE_ACCEPT:accept(2):nt 4537663Scharnier34:AUE_BIND:bind(2):nt 4637663Scharnier35:AUE_SETSOCKOPT:setsockopt(2):nt 472999Swollman36:AUE_VTRACE:vtrace(2):pc 4850476Speter37:AUE_SETTIMEOFDAY:settimeofday(2):ad 492999Swollman38:AUE_FCHOWN:fchown(2):fm 501558Srgrimes39:AUE_FCHMOD:fchmod(2):fm 511558Srgrimes40:AUE_SETREUID:setreuid(2):pc 521558Srgrimes41:AUE_SETREGID:setregid(2):pc 5374462Salfred42:AUE_RENAME:rename(2):fc,fd 541558Srgrimes43:AUE_TRUNCATE:truncate(2):fw 551558Srgrimes44:AUE_FTRUNCATE:ftruncate(2):fw 5624330Sguido45:AUE_FLOCK:flock(2):fm 571558Srgrimes46:AUE_SHUTDOWN:shutdown(2):nt 581558Srgrimes47:AUE_MKDIR:mkdir(2):fc 591558Srgrimes48:AUE_RMDIR:rmdir(2):fd 6074462Salfred49:AUE_UTIMES:utimes(2):fm 6174462Salfred50:AUE_ADJTIME:adjtime(2):ad 621558Srgrimes51:AUE_SETRLIMIT:setrlimit(2):pc 639336Sdfr52:AUE_KILLPG:killpg(2):pc 6483653Speter53:AUE_NFS_SVC:nfs_svc(2):ad 6523681Speter54:AUE_STATFS:statfs(2):fa 6677162Sru55:AUE_FSTATFS:fstatfs(2):fa 6777223Sru56:AUE_UNMOUNT:unmount(2):ad 6823681Speter57:AUE_ASYNC_DAEMON:async_daemon(2):ad 691558Srgrimes58:AUE_NFS_GETFH:nfs_getfh(2):ad 701558Srgrimes59:AUE_SETDOMAINNAME:setdomainname(2):ad 711558Srgrimes60:AUE_QUOTACTL:quotactl(2):ad 721558Srgrimes61:AUE_EXPORTFS:exportfs(2):ad 7337663Scharnier62:AUE_MOUNT:mount(2):ad 741558Srgrimes63:AUE_SEMSYS:semsys(2):ip 751558Srgrimes64:AUE_MSGSYS:msgsys(2):ip 761558Srgrimes65:AUE_SHMSYS:shmsys(2):ip 771558Srgrimes66:AUE_BSMSYS:bsmsys(2):ad 781558Srgrimes67:AUE_RFSSYS:rfssys(2):ad 791558Srgrimes68:AUE_FCHDIR:fchdir(2):pc 801558Srgrimes69:AUE_FCHROOT:fchroot(2):pc 811558Srgrimes70:AUE_VPIXSYS:vpixsys(2):no 821558Srgrimes71:AUE_PATHCONF:pathconf(2):fa 831558Srgrimes72:AUE_OPEN_R:open(2) - read:fr 841558Srgrimes73:AUE_OPEN_RC:open(2) - read,creat:fc,fr,fa,fm 851558Srgrimes74:AUE_OPEN_RT:open(2) - read,trunc:fd,fr,fa,fm 861558Srgrimes75:AUE_OPEN_RTC:open(2) - read,creat,trunc:fc,fd,fr,fa,fm 871558Srgrimes76:AUE_OPEN_W:open(2) - write:fw 881558Srgrimes77:AUE_OPEN_WC:open(2) - write,creat:fc,fw,fa,fm 8974462Salfred78:AUE_OPEN_WT:open(2) - write,trunc:fd,fw,fa,fm 9074462Salfred79:AUE_OPEN_WTC:open(2) - write,creat,trunc:fc,fd,fw,fa,fm 9174462Salfred80:AUE_OPEN_RW:open(2) - read,write:fr,fw 9274462Salfred81:AUE_OPEN_RWC:open(2) - read,write,creat:fc,fw,fr,fa,fm 931558Srgrimes82:AUE_OPEN_RWT:open(2) - read,write,trunc:fd,fr,fw,fa,fm 941558Srgrimes83:AUE_OPEN_RWTC:open(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm 951558Srgrimes84:AUE_MSGCTL:msgctl(2) - illegal command:ip 961558Srgrimes85:AUE_MSGCTL_RMID:msgctl(2) - IPC_RMID command:ip 971558Srgrimes86:AUE_MSGCTL_SET:msgctl(2) - IPC_SET command:ip 981558Srgrimes87:AUE_MSGCTL_STAT:msgctl(2) - IPC_STAT command:ip 991558Srgrimes88:AUE_MSGGET:msgget(2):ip 1001558Srgrimes89:AUE_MSGRCV:msgrcv(2):ip 1011558Srgrimes90:AUE_MSGSND:msgsnd(2):ip 1021558Srgrimes91:AUE_SHMCTL:shmctl(2) - illegal command:ip 1031558Srgrimes92:AUE_SHMCTL_RMID:shmctl(2) - IPC_RMID command:ip 1041558Srgrimes93:AUE_SHMCTL_SET:shmctl(2) - IPC_SET command:ip 1051558Srgrimes94:AUE_SHMCTL_STAT:shmctl(2) - IPC_STAT command:ip 1061558Srgrimes95:AUE_SHMGET:shmget(2):ip 1071558Srgrimes96:AUE_SHMAT:shmat(2):ip 1081558Srgrimes97:AUE_SHMDT:shmdt(2):ip 1091558Srgrimes98:AUE_SEMCTL:semctl(2) - illegal command:ip 1101558Srgrimes99:AUE_SEMCTL_RMID:semctl(2) - IPC_RMID command:ip 1119336Sdfr100:AUE_SEMCTL_SET:semctl(2) - IPC_SET command:ip 1121558Srgrimes101:AUE_SEMCTL_STAT:semctl(2) - IPC_STAT command:ip 1131558Srgrimes102:AUE_SEMCTL_GETNCNT:semctl(2) - GETNCNT command:ip 1141558Srgrimes103:AUE_SEMCTL_GETPID:semctl(2) - GETPID command:ip 1151558Srgrimes104:AUE_SEMCTL_GETVAL:semctl(2) - GETVAL command:ip 1161558Srgrimes105:AUE_SEMCTL_GETALL:semctl(2) - GETALL command:ip 1171558Srgrimes106:AUE_SEMCTL_GETZCNT:semctl(2) - GETZCNT command:ip 1181558Srgrimes107:AUE_SEMCTL_SETVAL:semctl(2) - SETVAL command:ip 1191558Srgrimes108:AUE_SEMCTL_SETALL:semctl(2) - SETALL command:ip 12027447Sdfr109:AUE_SEMGET:semget(2):ip 1211558Srgrimes110:AUE_SEMOP:semop(2):ip 1221558Srgrimes111:AUE_CORE:process dumped core:fc 1231558Srgrimes112:AUE_CLOSE:close(2):cl 1241558Srgrimes113:AUE_SYSTEMBOOT:system booted:na 1251558Srgrimes114:AUE_ASYNC_DAEMON_EXIT:async_daemon(2) exited:ad 12674462Salfred115:AUE_NFSSVC_EXIT:nfssvc(2) exited:ad 12775801Siedowse128:AUE_WRITEL:writel(2):no 12842144Sdfr129:AUE_WRITEVL:writevl(2):no 1291558Srgrimes130:AUE_GETAUID:getauid(2):ad 1301558Srgrimes131:AUE_SETAUID:setauid(2):ad 1311558Srgrimes132:AUE_GETAUDIT:getaudit(2):ad 13274462Salfred133:AUE_SETAUDIT:setaudit(2):ad 1331558Srgrimes134:AUE_GETUSERAUDIT:getuseraudit(2):ad 1341558Srgrimes135:AUE_SETUSERAUDIT:setuseraudit(2):ad 1351558Srgrimes136:AUE_AUDITSVC:auditsvc(2):ad 1361558Srgrimes137:AUE_AUDITUSER:audituser(2):ad 1371558Srgrimes138:AUE_AUDITON:auditon(2):ad 1381558Srgrimes139:AUE_AUDITON_GTERMID:auditon(2) - GETTERMID command:ad 1391558Srgrimes140:AUE_AUDITON_STERMID:auditon(2) - SETTERMID command:ad 1401558Srgrimes141:AUE_AUDITON_GPOLICY:auditon(2) - GPOLICY command:ad 1411558Srgrimes142:AUE_AUDITON_SPOLICY:auditon(2) - SPOLICY command:ad 1421558Srgrimes143:AUE_AUDITON_GESTATE:auditon(2) - GESTATE command:ad 1431558Srgrimes144:AUE_AUDITON_SESTATE:auditon(2) - SESTATE command:ad 1441558Srgrimes145:AUE_AUDITON_GQCTRL:auditon(2) - GQCTRL command:ad 14575641Siedowse146:AUE_AUDITON_SQCTRL:auditon(2) - SQCTRL command:ad 1467401Swpaul147:AUE_GETKERNSTATE:getkernstate(2):ad 1471558Srgrimes148:AUE_SETKERNSTATE:setkernstate(2):ad 1481558Srgrimes149:AUE_GETPORTAUDIT:getportaudit(2):ad 1499336Sdfr150:AUE_AUDITSTAT:auditstat(2):ad 1501558Srgrimes151:AUE_REVOKE:revoke(2):cl 1511558Srgrimes152:AUE_MAC:Solaris AUE_MAC:no 1521558Srgrimes153:AUE_ENTERPROM:enter prom:ad 1531558Srgrimes154:AUE_EXITPROM:exit prom:ad 1549336Sdfr155:AUE_IFLOAT:Solaris AUE_IFLOAT:no 1559336Sdfr156:AUE_PFLOAT:Solaris AUE_PFLOAT:no 1569336Sdfr157:AUE_UPRIV:Solaris AUE_UPRIV:no 1579336Sdfr158:AUE_IOCTL:ioctl(2):io 1589336Sdfr173:AUE_ONESIDE:one-sided session record:nt 1599336Sdfr174:AUE_MSGGETL:msggetl(2):ip 1601558Srgrimes175:AUE_MSGRCVL:msgrcvl(2):ip 1611558Srgrimes176:AUE_MSGSNDL:msgsndl(2):ip 1621558Srgrimes177:AUE_SEMGETL:semgetl(2):ip 1639336Sdfr178:AUE_SHMGETL:shmgetl(2):ip 1641558Srgrimes183:AUE_SOCKET:socket(2):nt 1651558Srgrimes184:AUE_SENDTO:sendto(2):nt 1661558Srgrimes185:AUE_PIPE:pipe(2):ip 16775801Siedowse186:AUE_SOCKETPAIR:socketpair(2):nt 16874462Salfred187:AUE_SEND:send(2):nt 16975635Siedowse188:AUE_SENDMSG:sendmsg(2):nt 1701558Srgrimes189:AUE_RECV:recv(2):nt 1711558Srgrimes190:AUE_RECVMSG:recvmsg(2):nt 17272650Sgreen191:AUE_RECVFROM:recvfrom(2):nt 1731558Srgrimes192:AUE_READ:read(2):no 17472650Sgreen193:AUE_GETDENTS:getdents(2):no 1751558Srgrimes194:AUE_LSEEK:lseek(2):no 1761558Srgrimes195:AUE_WRITE:write(2):no 1771558Srgrimes196:AUE_WRITEV:writev(2):no 1781558Srgrimes197:AUE_NFS:nfs server:ad 1791558Srgrimes198:AUE_READV:readv(2):no 1801558Srgrimes199:AUE_OSTAT:Solaris old stat(2):fa 1811558Srgrimes200:AUE_SETUID:setuid(2):pc 1827401Swpaul201:AUE_STIME:old stime(2):ad 1831558Srgrimes202:AUE_UTIME:old utime(2):fm 1841558Srgrimes203:AUE_NICE:old nice(2):pc 1851558Srgrimes204:AUE_OSETPGRP:Solaris old setpgrp(2):pc 1861558Srgrimes205:AUE_SETGID:setgid(2):pc 1871558Srgrimes206:AUE_READL:readl(2):no 1881558Srgrimes207:AUE_READVL:readvl(2):no 1891558Srgrimes209:AUE_DUP2:dup2(2):no 1901558Srgrimes210:AUE_MMAP:mmap(2):no 19175754Siedowse211:AUE_AUDIT:audit(2):ot 19275801Siedowse212:AUE_PRIOCNTLSYS:Solaris priocntlsys(2):pc 1931558Srgrimes213:AUE_MUNMAP:munmap(2):cl 1941558Srgrimes214:AUE_SETEGID:setegid(2):pc 1951558Srgrimes215:AUE_SETEUID:seteuid(2):pc 19672650Sgreen216:AUE_PUTMSG:putmsg(2):nt 1971558Srgrimes217:AUE_GETMSG:getmsg(2):nt 19875801Siedowse218:AUE_PUTPMSG:putpmsg(2):nt 19975801Siedowse219:AUE_GETPMSG:getpmsg(2):nt 20075801Siedowse220:AUE_AUDITSYS:audit system calls place holder:no 20174462Salfred221:AUE_AUDITON_GETKMASK:auditon(2) - get kernel mask:ad 20237663Scharnier222:AUE_AUDITON_SETKMASK:auditon(2) - set kernel mask:ad 2031558Srgrimes223:AUE_AUDITON_GETCWD:auditon(2) - get cwd:ad 2041558Srgrimes224:AUE_AUDITON_GETCAR:auditon(2) - get car:ad 2059336Sdfr225:AUE_AUDITON_GETSTAT:auditon(2) - get audit statistics:ad 2061558Srgrimes226:AUE_AUDITON_SETSTAT:auditon(2) - reset audit statistics:ad 20774462Salfred227:AUE_AUDITON_SETUMASK:auditon(2) - set mask per uid:ad 2081558Srgrimes228:AUE_AUDITON_SETSMASK:auditon(2) - set mask per session ID:ad 2091558Srgrimes229:AUE_AUDITON_GETCOND:auditon(2) - get audit state:ad 2101558Srgrimes230:AUE_AUDITON_SETCOND:auditon(2) - set audit state:ad 2111558Srgrimes231:AUE_AUDITON_GETCLASS:auditon(2) - get event class:ad 2121558Srgrimes232:AUE_AUDITON_SETCLASS:auditon(2) - set event class:ad 21372650Sgreen233:AUE_UTSSYS:utssys(2) - fusers:ad 21491354Sdd234:AUE_STATVFS:statvfs(2):fa 21572650Sgreen235:AUE_XSTAT:xstat(2):fa 2161558Srgrimes236:AUE_LXSTAT:lxstat(2):fa 21772650Sgreen237:AUE_LCHOWN:lchown(2):fm 21872650Sgreen238:AUE_MEMCNTL:memcntl(2):ot 2191558Srgrimes239:AUE_SYSINFO:sysinfo(2):ad 22025087Sdfr240:AUE_XMKNOD:xmknod(2):fc 2219336Sdfr241:AUE_FORK1:fork1(2):pc 2229336Sdfr242:AUE_MODCTL:modctl(2) system call place holder:no 22331705Sguido243:AUE_MODLOAD:modctl(2) - load module:ad 22475754Siedowse244:AUE_MODUNLOAD:modctl(2) - unload module:ad 22574462Salfred245:AUE_MODCONFIG:modctl(2) - configure module:ad 2261558Srgrimes246:AUE_MODADDMAJ:modctl(2) - bind module:ad 22774462Salfred247:AUE_SOCKACCEPT:getmsg-accept:nt 22874462Salfred248:AUE_SOCKCONNECT:putmsg-connect:nt 22974462Salfred249:AUE_SOCKSEND:putmsg-send:nt 23074462Salfred250:AUE_SOCKRECEIVE:getmsg-receive:nt 23174462Salfred251:AUE_ACLSET:acl(2) - SETACL comand:fm 23274462Salfred252:AUE_FACLSET:facl(2) - SETACL command:fm 23374462Salfred253:AUE_DOORFS:doorfs(2) - system call place holder:no 23474462Salfred254:AUE_DOORFS_DOOR_CALL:doorfs(2) - DOOR_CALL:ip 23575801Siedowse255:AUE_DOORFS_DOOR_RETURN:doorfs(2) - DOOR_RETURN:ip 2361558Srgrimes256:AUE_DOORFS_DOOR_CREATE:doorfs(2) - DOOR_CREATE:ip 2371558Srgrimes257:AUE_DOORFS_DOOR_REVOKE:doorfs(2) - DOOR_REVOKE:ip 23883653Speter258:AUE_DOORFS_DOOR_INFO:doorfs(2) - DOOR_INFO:ip 2391558Srgrimes259:AUE_DOORFS_DOOR_CRED:doorfs(2) - DOOR_CRED:ip 2401558Srgrimes260:AUE_DOORFS_DOOR_BIND:doorfs(2) - DOOR_BIND:ip 2411558Srgrimes261:AUE_DOORFS_DOOR_UNBIND:doorfs(2) - DOOR_UNBIND:ip 24275801Siedowse262:AUE_P_ONLINE:p_online(2):ad 24374462Salfred263:AUE_PROCESSOR_BIND:processor_bind(2):ad 2441558Srgrimes264:AUE_INST_SYNC:inst_sync(2):ad 2451558Srgrimes265:AUE_SOCKCONFIG:configure socket:nt 2461558Srgrimes266:AUE_SETAUDIT_ADDR:setaudit_addr(2):ad 24781911Skris267:AUE_GETAUDIT_ADDR:getaudit_addr(2):ad 2481558Srgrimes268:AUE_UMOUNT2:Solaris umount(2):ad 2491558Srgrimes269:AUE_FSAT:fsat(2) - place holder:no 2501558Srgrimes270:AUE_OPENAT_R:openat(2) - read:fr 2511558Srgrimes271:AUE_OPENAT_RC:openat(2) - read,creat:fc,fr,fa,fm 2521558Srgrimes272:AUE_OPENAT_RT:openat(2) - read,trunc:fd,fr,fa,fm 2531558Srgrimes273:AUE_OPENAT_RTC:openat(2) - read,creat,trunc:fc,fd,fr,fa,fm 2541558Srgrimes274:AUE_OPENAT_W:openat(2) - write:fw 2551558Srgrimes275:AUE_OPENAT_WC:openat(2) - write,creat:fc,fw,fa,fm 2561558Srgrimes276:AUE_OPENAT_WT:openat(2) - write,trunc:fd,fw,fa,fm 2571558Srgrimes277:AUE_OPENAT_WTC:openat(2) - write,creat,trunc:fc,fd,fw,fa,fm 2581558Srgrimes278:AUE_OPENAT_RW:openat(2) - read,write:fr,fw 2591558Srgrimes279:AUE_OPENAT_RWC:openat(2) - read,write,create:fc,fw,fr,fa,fm 2601558Srgrimes280:AUE_OPENAT_RWTC:openat(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm 2611558Srgrimes282:AUE_RENAMEAT:renameat(2):fc,fd 2621558Srgrimes283:AUE_FSTATAT:fstatat(2):fa 2631558Srgrimes284:AUE_FCHOWNAT:fchownat(2):fm 2641558Srgrimes285:AUE_FUTIMESAT:futimesat(2):fm 26575754Siedowse286:AUE_UNLINKAT:unlinkat(2):fd 26674462Salfred287:AUE_CLOCK_SETTIME:clock_settime(2):ad 26774462Salfred288:AUE_NTP_ADJTIME:ntp_adjtime(2):ad 26874462Salfred289:AUE_SETPPRIV:setppriv(2):pc 26974462Salfred290:AUE_MODDEVPLCY:modctl(2) - configure device policy:ad 27074462Salfred291:AUE_MODADDPRIV:modctl(2) - configure additional privilege:ad 27183687Speter292:AUE_CRYPTOADM:kernel cryptographic framework:ad 2721558Srgrimes293:AUE_CONFIGKSSL:configure kernel SSL:ad 27375635Siedowse294:AUE_BRANDSYS:brandsys(2):ot 27475635Siedowse295:AUE_PF_POLICY_ADDRULE:Add IPsec policy rule:ad 27575635Siedowse296:AUE_PF_POLICY_DELRULE:Delete IPsec policy rule:ad 27674462Salfred297:AUE_PF_POLICY_CLONE:Clone IPsec policy:ad 27774462Salfred298:AUE_PF_POLICY_FLIP:Flip IPsec policy:ad 27874462Salfred299:AUE_PF_POLICY_FLUSH:Flush IPsec policy rules:ad 27974462Salfred300:AUE_PF_POLICY_ALGS:Update IPsec algorithms:ad 28074462Salfred301:AUE_PORTFS:portfs:fa 28174462Salfred# 28274462Salfred# What follows are deprecated Darwin event numbers that may soon^H^H^H^Hnow 28374462Salfred# conflict with Solaris events. 28474462Salfred# 28574462Salfred301:AUE_DARWIN_GETFSSTAT:getfsstat(2):fa 28674462Salfred302:AUE_DARWIN_PTRACE:ptrace(2):pc 28783687Speter303:AUE_DARWIN_CHFLAGS:chflags(2):fm 28883687Speter304:AUE_DARWIN_FCHFLAGS:fchflags(2):fm 28983687Speter305:AUE_DARWIN_PROFILE:profil(2):pc 29083687Speter306:AUE_DARWIN_KTRACE:ktrace(2):pc 2912999Swollman307:AUE_DARWIN_SETLOGIN:setlogin(2):pc 2922999Swollman308:AUE_DARWIN_REBOOT:reboot(2):ad 29331665Sguido309:AUE_DARWIN_REVOKE:revoke(2):cl 2941558Srgrimes310:AUE_DARWIN_UMASK:umask(2):pc 29525087Sdfr311:AUE_DARWIN_MPROTECT:mprotect(2):fm 29625087Sdfr312:AUE_DARWIN_SETPRIORITY:setpriority(2):pc,ot 29725087Sdfr313:AUE_DARWIN_SETTIMEOFDAY:settimeofday(2):ad 2989336Sdfr314:AUE_DARWIN_FLOCK:flock(2):fm 2999336Sdfr315:AUE_DARWIN_MKFIFO:mkfifo(2):fc 3009336Sdfr316:AUE_DARWIN_POLL:poll(2):no 3019336Sdfr317:AUE_DARWIN_SOCKETPAIR:socketpair(2):nt 3029336Sdfr318:AUE_DARWIN_FUTIMES:futimes(2):fm 3039336Sdfr319:AUE_DARWIN_SETSID:setsid(2):pc 3048688Sphk320:AUE_DARWIN_SETPRIVEXEC:setprivexec(2):pc 3058688Sphk321:AUE_DARWIN_NFSSVC:nfssvc(2):ad 3068688Sphk322:AUE_DARWIN_GETFH:getfh(2):fa 30731656Sguido323:AUE_DARWIN_QUOTACTL:quotactl(2):ad 30831656Sguido324:AUE_DARWIN_ADDPROFILE:system call:pc 30931656Sguido325:AUE_DARWIN_KDEBUGTRACE:system call:pc 3101558Srgrimes326:AUE_DARWIN_FSTAT:fstat(2):fa 31137663Scharnier327:AUE_DARWIN_FPATHCONF:fpathconf(2):fa 3121558Srgrimes328:AUE_DARWIN_GETDIRENTRIES:getdirentries(2):no 3131558Srgrimes329:AUE_DARWIN_TRUNCATE:truncate(2):fw 3141558Srgrimes330:AUE_DARWIN_FTRUNCATE:ftruncate(2):fw 3151558Srgrimes331:AUE_DARWIN_SYSCTL:sysctl(3):ad 3161558Srgrimes332:AUE_DARWIN_MLOCK:mlock(2):pc 3171558Srgrimes333:AUE_DARWIN_MUNLOCK:munlock(2):pc 3181558Srgrimes334:AUE_DARWIN_UNDELETE:undelete(2):fm 3191558Srgrimes335:AUE_DARWIN_GETATTRLIST:getattrlist():fa 3201558Srgrimes336:AUE_DARWIN_SETATTRLIST:setattrlist():fm 3211558Srgrimes337:AUE_DARWIN_GETDIRENTRIESATTR:getdirentriesattr():fa 3221558Srgrimes338:AUE_DARWIN_EXCHANGEDATA:exchangedata():fw 3231558Srgrimes339:AUE_DARWIN_SEARCHFS:searchfs():fa 3241558Srgrimes340:AUE_DARWIN_MINHERIT:minherit(2):pc 32537663Scharnier341:AUE_DARWIN_SEMCONFIG:semconfig():ip 3261558Srgrimes342:AUE_DARWIN_SEMOPEN:sem_open(2):ip 3271558Srgrimes343:AUE_DARWIN_SEMCLOSE:sem_close(2):ip 32837663Scharnier344:AUE_DARWIN_SEMUNLINK:sem_unlink(2):ip 3291558Srgrimes345:AUE_DARWIN_SHMOPEN:shm_open(2):ip 3301558Srgrimes346:AUE_DARWIN_SHMUNLINK:shm_unlink(2):ip 33137663Scharnier347:AUE_DARWIN_LOADSHFILE:load_shared_file():fr 3321558Srgrimes348:AUE_DARWIN_RESETSHFILE:reset_shared_file():ot 3331558Srgrimes349:AUE_DARWIN_NEWSYSTEMSHREG:new_system_share_regions():ot 3341558Srgrimes350:AUE_DARWIN_PTHREADKILL:pthread_kill(2):pc 3351558Srgrimes351:AUE_DARWIN_PTHREADSIGMASK:pthread_sigmask(2):pc 3361558Srgrimes352:AUE_DARWIN_AUDITCTL:auditctl(2):ad 33775754Siedowse353:AUE_DARWIN_RFORK:rfork(2):pc 33874462Salfred354:AUE_DARWIN_LCHMOD:lchmod(2):fm 3391558Srgrimes355:AUE_DARWIN_SWAPOFF:swapoff(2):ad 3401558Srgrimes356:AUE_DARWIN_INITPROCESS:init_process():pc 3411558Srgrimes357:AUE_DARWIN_MAPFD:map_fd():fa 3421558Srgrimes358:AUE_DARWIN_TASKFORPID:task_for_pid():pc 3431558Srgrimes359:AUE_DARWIN_PIDFORTASK:pid_for_task():pc 3441558Srgrimes360:AUE_DARWIN_SYSCTL_NONADMIN:sysctl() - non-admin:ot 34574462Salfred361:AUE_DARWIN_COPYFILE:copyfile():fr,fw 34674462Salfred# 34774462Salfred# OpenBSM-specific kernel events. 34874462Salfred# 34974791Salfred43001:AUE_GETFSSTAT:getfsstat(2):fa 35074791Salfred43002:AUE_PTRACE:ptrace(2):pc 35174791Salfred43003:AUE_CHFLAGS:chflags(2):fm 35274791Salfred43004:AUE_FCHFLAGS:fchflags(2):fm 35374462Salfred43005:AUE_PROFILE:profil(2):pc 35474462Salfred43006:AUE_KTRACE:ktrace(2):pc 35574462Salfred43007:AUE_SETLOGIN:setlogin(2):pc 35674462Salfred43008:AUE_OPENBSM_REVOKE:revoke(2):cl 35774462Salfred43009:AUE_UMASK:umask(2):pc 35874462Salfred43010:AUE_MPROTECT:mprotect(2):fm 35974462Salfred43011:AUE_MKFIFO:mkfifo(2):fc 36074462Salfred43012:AUE_POLL:poll(2):no 36174462Salfred43013:AUE_FUTIMES:futimes(2):fm 36274462Salfred43014:AUE_SETSID:setsid(2):pc 36374462Salfred43015:AUE_SETPRIVEXEC:setprivexec(2):pc 36474462Salfred43016:AUE_ADDPROFILE:system call:pc 36574462Salfred43017:AUE_KDEBUGTRACE:system call:pc 36674462Salfred43018:AUE_OPENBSM_FSTAT:fstat(2):fa 36774462Salfred43019:AUE_FPATHCONF:fpathconf(2):fa 36874462Salfred43020:AUE_GETDIRENTRIES:getdirentries(2):no 36974462Salfred43021:AUE_SYSCTL:sysctl(3):ot 37074462Salfred43022:AUE_MLOCK:mlock(2):pc 37174462Salfred43023:AUE_MUNLOCK:munlock(2):pc 37274791Salfred43024:AUE_UNDELETE:undelete(2):fm 37374791Salfred43025:AUE_GETATTRLIST:getattrlist():fa 37424759Sguido43026:AUE_SETATTRLIST:setattrlist():fm 37583687Speter43027:AUE_GETDIRENTRIESATTR:getdirentriesattr():fa 37683687Speter43028:AUE_EXCHANGEDATA:exchangedata():fw 37783687Speter43029:AUE_SEARCHFS:searchfs():fa 37824759Sguido43030:AUE_MINHERIT:minherit(2):pc 37924759Sguido43031:AUE_SEMCONFIG:semconfig():ip 38024759Sguido43032:AUE_SEMOPEN:sem_open(2):ip 38124330Sguido43033:AUE_SEMCLOSE:sem_close(2):ip 3829202Srgrimes43034:AUE_SEMUNLINK:sem_unlink(2):ip 3839202Srgrimes43035:AUE_SHMOPEN:shm_open(2):ip 38437663Scharnier43036:AUE_SHMUNLINK:shm_unlink(2):ip 3851558Srgrimes43037:AUE_LOADSHFILE:load_shared_file():fr 3861558Srgrimes43038:AUE_RESETSHFILE:reset_shared_file():ot 38774462Salfred43039:AUE_NEWSYSTEMSHREG:new_system_share_regions():ot 38874462Salfred43040:AUE_PTHREADKILL:pthread_kill(2):pc 38974462Salfred43041:AUE_PTHREADSIGMASK:pthread_sigmask(2):pc 39074462Salfred43042:AUE_AUDITCTL:auditctl(2):ad 39174462Salfred43043:AUE_RFORK:rfork(2):pc 39274462Salfred43044:AUE_LCHMOD:lchmod(2):fm 39374462Salfred43045:AUE_SWAPOFF:swapoff(2):ad 39474462Salfred43046:AUE_INITPROCESS:init_process():pc 39574462Salfred43047:AUE_MAPFD:map_fd():fa 39674462Salfred43048:AUE_TASKFORPID:task_for_pid():pc 39774462Salfred43049:AUE_PIDFORTASK:pid_for_task():pc 39874462Salfred43050:AUE_SYSCTL_NONADMIN:sysctl() - non-admin:ot 39974462Salfred43051:AUE_COPYFILE:copyfile(2):fr,fw 40074462Salfred43052:AUE_LUTIMES:lutimes(2):fm 40174462Salfred43053:AUE_LCHFLAGS:lchflags(2):fm 40274462Salfred43054:AUE_SENDFILE:sendfile(2):nt 40374462Salfred43055:AUE_USELIB:uselib(2):fa 40474462Salfred43056:AUE_GETRESUID:getresuid(2):pc 40574462Salfred43057:AUE_SETRESUID:setresuid(2):pc 40674462Salfred43058:AUE_GETRESGID:getresgid(2):pc 40774462Salfred43059:AUE_SETRESGID:setresgid(2):pc 40874462Salfred43060:AUE_WAIT4:wait4(2):pc 40974462Salfred43061:AUE_LGETFH:lgetfh(2):fa 41074462Salfred43062:AUE_FHSTATFS:fhstatfs(2):fa 41174462Salfred43063:AUE_FHOPEN:fhopen(2):fa 41274462Salfred43064:AUE_FHSTAT:fhstat(2):fa 41374462Salfred43065:AUE_JAIL:jail(2):pc 41474462Salfred43066:AUE_EACCESS:eaccess(2):fa 41574462Salfred43067:AUE_KQUEUE:kqueue(2):no 41674462Salfred43068:AUE_KEVENT:kevent(2):no 41774462Salfred43069:AUE_FSYNC:fsync(2):fm 41874462Salfred43070:AUE_NMOUNT:nmount(2):ad 41974462Salfred43071:AUE_BDFLUSH:bdflush(2):ad 42074462Salfred43072:AUE_SETFSUID:setfsuid(2):ot 42174462Salfred43073:AUE_SETFSGID:setfsgid(2):ot 42274462Salfred43074:AUE_PERSONALITY:personality(2):pc 42374462Salfred43075:AUE_SCHED_GETSCHEDULER:getscheduler(2):ad 42474462Salfred43076:AUE_SCHED_SETSCHEDULER:setscheduler(2):ad 42574462Salfred43077:AUE_PRCTL:prctl(2):pc 42674462Salfred43078:AUE_GETCWD:getcwd(2):pc 42774462Salfred43079:AUE_CAPGET:capget(2):pc 42874791Salfred43080:AUE_CAPSET:capset(2):pc 42974462Salfred43081:AUE_PIVOT_ROOT:pivot_root(2):pc 43074462Salfred43082:AUE_RTPRIO::rtprio(2):pc 43174462Salfred43083:AUE_SCHED_GETPARAM:sched_getparam(2):ad 43274462Salfred43084:AUE_SCHED_SETPARAM:sched_setparam(2):ad 43374462Salfred43085:AUE_SCHED_GET_PRIORITY_MAX:sched_get_priority_max(2):ad 43474462Salfred43086:AUE_SCHED_GET_PRIORITY_MIN:sched_get_priority_min(2):ad 43574462Salfred43087:AUE_SCHED_RR_GET_INTERVAL:sched_rr_get_interval(2):ad 43674462Salfred43088:AUE_ACL_GET_FILE:acl_get_file(2):fa 43774462Salfred43089:AUE_ACL_SET_FILE:acl_set_file(2):fm 43874462Salfred43090:AUE_ACL_GET_FD:acl_get_fd(2):fa 43974462Salfred43091:AUE_ACL_SET_FD:acl_set_fd(2):fm 44074462Salfred43092:AUE_ACL_DELETE_FILE:acl_delete_file(2):fm 44174462Salfred43093:AUE_ACL_DELETE_FD:acl_delete_fd(2):fm 44274462Salfred43094:AUE_ACL_CHECK_FILE:acl_aclcheck_file(2):fa 44374462Salfred43095:AUE_ACL_CHECK_FD:acl_aclcheck_fd(2):fa 44474462Salfred43096:AUE_ACL_GET_LINK:acl_get_link(2):fa 44574462Salfred43097:AUE_ACL_SET_LINK:acl_set_link(2):fm 44674462Salfred43098:AUE_ACL_DELETE_LINK:acl_delete_link(2):fm 44774462Salfred43099:AUE_ACL_CHECK_LINK:acl_aclcheck_link(2):fa 44874791Salfred43100:AUE_SYSARCH:sysarch(2):ot 44974462Salfred43101:AUE_EXTATTRCTL:extattrctl(2):fm 45074462Salfred43102:AUE_EXTATTR_GET_FILE:extattr_get_file(2):fa 45174462Salfred43103:AUE_EXTATTR_SET_FILE:extattr_set_file(2):fm 45274462Salfred43104:AUE_EXTATTR_LIST_FILE:extattr_list_file(2):fa 45374462Salfred43105:AUE_EXTATTR_DELETE_FILE:extattr_delete_file(2):fm 45474462Salfred43106:AUE_EXTATTR_GET_FD:extattr_get_fd(2):fa 45574462Salfred43107:AUE_EXTATTR_SET_FD:extattr_set_fd(2):fm 45674462Salfred43108:AUE_EXTATTR_LIST_FD:extattr_list_fd(2):fa 45774462Salfred43109:AUE_EXTATTR_DELETE_FD:extattr_delete_fd(2):fm 45874462Salfred43110:AUE_EXTATTR_GET_LINK:extattr_get_link(2):fa 45974462Salfred43111:AUE_EXTATTR_SET_LINK:extattr_set_link(2):fm 46074462Salfred43112:AUE_EXTATTR_LIST_LINK:extattr_list_link(2):fa 46174462Salfred43113:AUE_EXTATTR_DELETE_LINK:extattr_delete_link(2):fm 46274462Salfred43114:AUE_KENV:kenv(8):ad 46374462Salfred43115:AUE_JAIL_ATTACH:jail_attach(2):ad 46474462Salfred43116:AUE_SYSCTL_WRITE:sysctl(3):ad 46574462Salfred43117:AUE_IOPERM:linux ioperm:ad 46674462Salfred43118:AUE_READDIR:readdir(3):no 46774462Salfred43119:AUE_IOPL:linux iopl:ad 46874462Salfred43120:AUE_VM86:linux vm86:pc 46974462Salfred43121:AUE_MAC_GET_PROC:mac_get_proc(2):pc 47074462Salfred43122:AUE_MAC_SET_PROC:mac_set_proc(2):pc 4711558Srgrimes43123:AUE_MAC_GET_FD:mac_get_fd(2):fa 4721558Srgrimes43124:AUE_MAC_GET_FILE:mac_get_file(2):fa 47375754Siedowse43125:AUE_MAC_SET_FD:mac_set_fd(2):fm 47475754Siedowse43126:AUE_MAC_SET_FILE:mac_set_file(2):fm 47575754Siedowse43127:AUE_MAC_SYSCALL:mac_syscall(2):ad 47675754Siedowse43128:AUE_MAC_GET_PID:mac_get_pid(2):pc 47775754Siedowse43129:AUE_MAC_GET_LINK:mac_get_link(2):fa 47875754Siedowse43130:AUE_MAC_SET_LINK:mac_set_link(2):fm 47975754Siedowse43131:AUE_MAC_EXECVE:mac_exeve(2):ex,pc 48075754Siedowse43132:AUE_GETPATH_FROMFD:getpath_fromfd(2):fa 48175754Siedowse43133:AUE_GETPATH_FROMADDR:getpath_fromaddr(2):fa 48275754Siedowse43134:AUE_MQ_OPEN:mq_open(2):ip 48375754Siedowse43135:AUE_MQ_SETATTR:mq_setattr(2):ip 48475754Siedowse43136:AUE_MQ_TIMEDRECEIVE:mq_timedreceive(2):ip 48575754Siedowse43137:AUE_MQ_TIMEDSEND:mq_timedsend(2):ip 48675754Siedowse43138:AUE_MQ_NOTIFY:mq_notify(2):ip 48775754Siedowse43139:AUE_MQ_UNLINK:mq_unlink(2):ip 48875754Siedowse43140:AUE_LISTEN:listen(2):nt 48975754Siedowse43141:AUE_MLOCKALL:mlockall(2):pc 49075754Siedowse43142:AUE_MUNLOCKALL:munlockall(2):pc 49175754Siedowse43143:AUE_CLOSEFROM:closefrom(2):cl 49275754Siedowse43144:AUE_FEXECVE:fexecve(2):pc,ex 4931558Srgrimes43145:AUE_FACCESSAT:faccessat(2):fa 4941558Srgrimes43146:AUE_FCHMODAT:fchmodat(2):fm 49537663Scharnier43147:AUE_LINKAT:linkat(2):fc 49637663Scharnier43148:AUE_MKDIRAT:mkdirat(2):fc 49737663Scharnier43149:AUE_MKFIFOAT:mkfifoat(2):fc 49837663Scharnier43150:AUE_MKNODAT:mknodat(2):fc 49937663Scharnier43151:AUE_READLINKAT:readlinkat(2):fr 50037663Scharnier43152:AUE_SYMLINKAT:symlinkat(2):fc 50137663Scharnier43153:AUE_MAC_GETFSSTAT:mac_getfsstat(2):fa 50237663Scharnier43154:AUE_MAC_GET_MOUNT:mac_get_mount(2):fa 5031558Srgrimes43155:AUE_MAC_GET_LCID:mac_get_lcid(2):pc 5041558Srgrimes43156:AUE_MAC_GET_LCTX:mac_get_lctx(2):pc 5051558Srgrimes43157:AUE_MAC_SET_LCTX:mac_set_lctx(2):pc 5061558Srgrimes43158:AUE_MAC_MOUNT:mac_mount(2):ad 5071558Srgrimes43159:AUE_GETLCID:getlcid(2):pc 5081558Srgrimes43160:AUE_SETLCID:setlcid(2):pc 5091558Srgrimes43161:AUE_TASKNAMEFORPID:taskname_for_pid():pc 5101558Srgrimes43162:AUE_ACCESS_EXTENDED:access_extended(2):fa 5111558Srgrimes43163:AUE_CHMOD_EXTENDED:chmod_extended(2):fm 5121558Srgrimes43164:AUE_FCHMOD_EXTENDED:fchmod_extended(2):fm 5139336Sdfr43165:AUE_FSTAT_EXTENDED:fstat_extended(2):fa 5141558Srgrimes43166:AUE_LSTAT_EXTENDED:lstat_extended(2):fa 5151558Srgrimes43167:AUE_MKDIR_EXTENDED:mkdir_extended(2):fc 51674462Salfred43168:AUE_MKFIFO_EXTENDED:mkfifo_extended(2):fc 51774462Salfred43169:AUE_OPEN_EXTENDED:open_extended(2) - attr only:fa 51874462Salfred43170:AUE_OPEN_EXTENDED_R:open_extended(2) - read:fr 51974462Salfred43171:AUE_OPEN_EXTENDED_RC:open_extended(2) - read,creat:fc,fr,fa,fm 5209336Sdfr43172:AUE_OPEN_EXTENDED_RT:open_extended(2) - read,trunc:fd,fr,fa,fm 52123681Speter43173:AUE_OPEN_EXTENDED_RTC:open_extended(2) - read,creat,trunc:fc,fd,fr,fa,fm 52228911Sguido43174:AUE_OPEN_EXTENDED_W:open_extended(2) - write:fw 5239336Sdfr43175:AUE_OPEN_EXTENDED_WC:open_extended(2) - write,creat:fc,fw,fa,fm 5241558Srgrimes43176:AUE_OPEN_EXTENDED_WT:open_extended(2) - write,trunc:fd,fw,fa,fm 5259336Sdfr43177:AUE_OPEN_EXTENDED_WTC:open_extended(2) - write,creat,trunc:fc,fd,fw,fa,fm 5269336Sdfr43178:AUE_OPEN_EXTENDED_RW:open_extended(2) - read,write:fr,fw 52774462Salfred43179:AUE_OPEN_EXTENDED_RWC:open_extended(2) - read,write,creat:fc,fw,fr,fa,fm 52874462Salfred43180:AUE_OPEN_EXTENDED_RWT:open_extended(2) - read,write,trunc:fd,fr,fw,fa,fm 52974462Salfred43181:AUE_OPEN_EXTENDED_RWTC:open_extended(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm 53075635Siedowse43182:AUE_STAT_EXTENDED:stat_extended(2):fa 53174462Salfred43183:AUE_UMASK_EXTENDED:umask_extended(2):pc 53274462Salfred43184:AUE_OPENAT:openat(2) - attr only:fa 53375635Siedowse43185:AUE_POSIX_OPENPT:posix_openpt(2):ip 53474462Salfred43186:AUE_CAP_NEW:cap_new(2):fm 53574462Salfred43187:AUE_CAP_GETRIGHTS:cap_getrights(2):fm 53674462Salfred43188:AUE_CAP_ENTER:cap_enter(2):pc 53774462Salfred43189:AUE_CAP_GETMODE:cap_getmode(2):pc 53874462Salfred# 53974462Salfred# User space system events. 54074462Salfred# 54174462Salfred6152:AUE_login:login - local:lo 54274462Salfred6153:AUE_logout:logout - local:lo 54374462Salfred6159:AUE_su:su(1):lo 5441558Srgrimes6160:AUE_halt:system halt:ad 5451558Srgrimes6168:AUE_shutdown:system shutdown:ad 5461558Srgrimes6171:AUE_audit_startup:audit startup:ad 54737663Scharnier6172:AUE_audit_shutdown:audit shutdown:ad 5481558Srgrimes6207:AUE_create_user:create user:ad 5491558Srgrimes6208:AUE_modify_user:modify user:ad 5509336Sdfr6209:AUE_delete_user:delete user:ad 55131656Sguido6210:AUE_disable_user:disable user:ad 55231656Sguido6211:AUE_enable_user::ad 55374462Salfred6300:AUE_sudo:sudo(1):ad 5541558Srgrimes6501:AUE_modify_password:modify password:ad 5551558Srgrimes6511:AUE_create_group:create group:ad 5561558Srgrimes6512:AUE_delete_group:delete group:ad 5571558Srgrimes6513:AUE_modify_group:modify group:ad 55831656Sguido6514:AUE_add_to_group:add to group:ad 55974462Salfred6515:AUE_remove_from_group:remove from group:ad 5601558Srgrimes6521:AUE_revoke_obj:revoke object priv:fm 5611558Srgrimes6600:AUE_lw_login:loginwindow login:lo 5621558Srgrimes6601:AUE_lw_logout:loginwindow logout:lo 5631558Srgrimes7000:AUE_auth_user:user authentication:ad 5641558Srgrimes7001:AUE_ssconn:SecSrvr connection setup:ad 5651558Srgrimes7002:AUE_ssauthorize:SecSrvr AuthEngine:ad 5669336Sdfr7003:AUE_ssauthint:SecSrvr authinternal mech:ad 5679336Sdfr32800:AUE_openssh:OpenSSH login:lo 5681558Srgrimes