NAME | SYNOPSIS | DESCRIPTION | RETURN VALUES | ERRORS | SUMMARY OF TRUSTED SOLARIS CHANGES | SEE ALSO
#include <sys/param.h> #include <bsm/audit.h>int auditsvc(int fd, int limit);
The auditsvc() function specifies the audit log file to the kernel. The kernel writes audit records to this file until an exceptional condition occurs and then the call returns. The fd argument is a file descriptor that identifies the audit file. Applications should open this file for writing before calling auditsvc().
The limit argument specifies the number of free blocks that must be available in the audit file system, and causes auditsvc() to return when the free disk space on the audit filesystem drops below this limit. Thus, the invoking program can take action to avoid running out of disk space.
The auditsvc() function does not return until one of the following conditions occurs:
The process receives a signal that is not blocked or ignored.
An error is encountered writing to the audit log file.
The minimum free space (as specified by limit), has been reached.
A process must have PRIV_SYS_AUDIT
in its set of effective privileges in order to execute this call successfully.
The auditsvc() function returns only on an error.
The auditsvc() function will fail if:
The descriptor referred to a stream, was marked for System V-style non-blocking I/O, and no data could be written immediately.
The fd argument is not a valid descriptor open for writing.
A second process attempted to perform this call.
An attempt was made to write a file that exceeds the process's file size limit or the maximum file size.
The call is forced to terminate prematurely due to the arrival of a signal whose SV_INTERRUPT bit in sv_flags is set (see sigvec(3UCB)). The signal(3C) function sets this bit for any signal it catches.
Auditing is disabled. See auditon(2).
fd does not refer to a file of an appropriate type. Regular files are always appropriate.
An I/O error occurred while reading from or writing to the file system.
The user's quota of disk blocks on the file system containing the file has been exhausted; audit filesystem space is below the specified limit; or there is no free space remaining on the file system containing the file.
A hangup occurred on the stream being written to.
The process did not have the proper privilege in its effective set.
The file was marked for 4.2 BSD-style non-blocking I/O, and no data could be written immediately.
This functionality is active only if auditing is enabled. By default, auditing is enabled in the Trusted Solaris environment. See Trusted Solaris Audit Administration for more information.
A process must have PRIV_SYS_AUDIT
in its set of effective privileges in order to execute this call successfully.
NAME | SYNOPSIS | DESCRIPTION | RETURN VALUES | ERRORS | SUMMARY OF TRUSTED SOLARIS CHANGES | SEE ALSO