2 .\" Copyright (c) 2007 Apple Inc. All rights reserved.
4 .\" @APPLE_LICENSE_HEADER_START@
6 .\" This file contains Original Code and/or Modifications of Original Code
7 .\" as defined in and that are subject to the Apple Public Source License
8 .\" Version 2.0 (the 'License'). You may not use this file except in
9 .\" compliance with the License. Please obtain a copy of the License at
10 .\" http://www.opensource.apple.com/apsl/ and read it before using this
13 .\" The Original Code and all software distributed under the License are
14 .\" distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 .\" EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 .\" INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 .\" FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 .\" Please see the License for the specific language governing rights and
19 .\" limitations under the License.
21 .\" @APPLE_LICENSE_HEADER_END@
28 .Nd submit a record to the kernel for auditing
30 .Fd #include <bsm/audit.h>
32 .Fn audit "const void * record" "int length"
36 function submits a record to the kernel for inclusion in the global audit
37 trail. The record must already be in BSM format. To protect the integrity
38 of the audit trail, this system call must be made with sufficient privileges.
40 can be used to create and manipulate BSM data.
42 is the length in bytes of the BSM record and
46 Upon successful completion a value of 0 is returned.
47 Otherwise, a value of -1 is returned and
49 is set to indicate the error.
54 system call will fail if:
58 is greater than MAX_AUDIT_RECORD_SIZE, less than zero, greater than the
59 internal buffer size, or the record fails verification.
62 The security auditing service is not available.
65 The call was made with insufficient privileges to complete.
78 function call first appeared in Mac OS X 10.3 (Panther).