diff options
Diffstat (limited to 'examples/VFS/audit.c')
-rw-r--r-- | examples/VFS/audit.c | 130 |
1 files changed, 111 insertions, 19 deletions
diff --git a/examples/VFS/audit.c b/examples/VFS/audit.c index ce2aa52250e..aad483c295a 100644 --- a/examples/VFS/audit.c +++ b/examples/VFS/audit.c @@ -47,16 +47,19 @@ /* Function prototypes */ -int audit_connect(struct connection_struct *conn, char *svc, char *user); +int audit_connect(struct connection_struct *conn, const char *svc, const char *user); void audit_disconnect(struct connection_struct *conn); -DIR *audit_opendir(struct connection_struct *conn, char *fname); -int audit_mkdir(struct connection_struct *conn, char *path, mode_t mode); -int audit_rmdir(struct connection_struct *conn, char *path); -int audit_open(struct connection_struct *conn, char *fname, int flags, mode_t mode); +DIR *audit_opendir(struct connection_struct *conn, const char *fname); +int audit_mkdir(struct connection_struct *conn, const char *path, mode_t mode); +int audit_rmdir(struct connection_struct *conn, const char *path); +int audit_open(struct connection_struct *conn, const char *fname, int flags, mode_t mode); int audit_close(struct files_struct *fsp, int fd); -int audit_rename(struct connection_struct *conn, char *old, char *new); -int audit_unlink(struct connection_struct *conn, char *path); -int audit_chmod(struct connection_struct *conn, char *path, mode_t mode); +int audit_rename(struct connection_struct *conn, const char *old, const char *new); +int audit_unlink(struct connection_struct *conn, const char *path); +int audit_chmod(struct connection_struct *conn, const char *path, mode_t mode); +int audit_chmod_acl(struct connection_struct *conn, const char *name, mode_t mode); +int audit_fchmod(struct files_struct *fsp, int fd, mode_t mode); +int audit_fchmod_acl(struct files_struct *fsp, int fd, mode_t mode); /* VFS operations */ @@ -92,32 +95,86 @@ struct vfs_ops audit_ops = { NULL, /* lstat */ audit_unlink, audit_chmod, + audit_fchmod, NULL, /* chown */ + NULL, /* fchown */ NULL, /* chdir */ NULL, /* getwd */ NULL, /* utime */ NULL, /* ftruncate */ NULL, /* lock */ + NULL, /* symlink */ + NULL, /* readlink */ + NULL, /* link */ + NULL, /* mknod */ + NULL, /* realpath */ NULL, /* fget_nt_acl */ NULL, /* get_nt_acl */ NULL, /* fset_nt_acl */ - NULL /* set_nt_acl */ + NULL, /* set_nt_acl */ + + audit_chmod_acl, /* chmod_acl */ + audit_fchmod_acl, /* fchmod_acl */ + + NULL, /* sys_acl_get_entry */ + NULL, /* sys_acl_get_tag_type */ + NULL, /* sys_acl_get_permset */ + NULL, /*sys_acl_get_qualifier */ + NULL, /* sys_acl_get_file */ + NULL, /* sys_acl_get_fd */ + NULL, /* sys_acl_clear_perms */ + NULL, /* sys_acl_add_perm */ + NULL, /* sys_acl_to_text */ + NULL, /* sys_acl_init */ + NULL, /* sys_acl_create_entry */ + NULL, /* sys_acl_set_tag_type */ + NULL, /* sys_acl_set_qualifier */ + NULL, /* sys_acl_set_permset */ + NULL, /* sys_acl_valid */ + NULL, /* sys_acl_set_file */ + NULL, /* sys_acl_set_fd */ + NULL, /* sys_acl_delete_def_file */ + NULL, /* sys_acl_get_perm */ + NULL, /* sys_acl_free_text */ + NULL, /* sys_acl_free_acl */ + NULL /* sys_acl_free_qualifier */ }; /* VFS initialisation function. Return initialised vfs_ops structure back to SAMBA. */ -BOOL vfs_init(connection_struct *conn) +struct vfs_ops *vfs_init(int *vfs_version, struct vfs_ops *def_vfs_ops) { + struct vfs_ops tmp_ops; + + *vfs_version = SMB_VFS_INTERFACE_VERSION; + memcpy(&tmp_ops, def_vfs_ops, sizeof(struct vfs_ops)); + + tmp_ops.connect = audit_connect; + tmp_ops.disconnect = audit_disconnect; + tmp_ops.opendir = audit_opendir; + tmp_ops.mkdir = audit_mkdir; + tmp_ops.rmdir = audit_rmdir; + tmp_ops.open = audit_open; + tmp_ops.close = audit_close; + tmp_ops.rename = audit_rename; + tmp_ops.unlink = audit_unlink; + tmp_ops.chmod = audit_chmod; + tmp_ops.chmod_acl = audit_chmod_acl; + tmp_ops.fchmod = audit_fchmod; + tmp_ops.fchmod_acl = audit_fchmod_acl; + + memcpy(&audit_ops, &tmp_ops, sizeof(struct vfs_ops)); + openlog("smbd_audit", LOG_PID, SYSLOG_FACILITY); syslog(SYSLOG_PRIORITY, "VFS_INIT: vfs_ops loaded\n"); - return True; + return &audit_ops; } /* Implementation of vfs_ops. Pass everything on to the default operation but log event first. */ -int audit_connect(struct connection_struct *conn, char *svc, char *user) +int audit_connect(struct connection_struct *conn, const char *svc, const char *user) { syslog(SYSLOG_PRIORITY, "connect to service %s by user %s\n", svc, user); @@ -131,7 +188,7 @@ void audit_disconnect(struct connection_struct *conn) default_vfs_ops.disconnect(conn); } -DIR *audit_opendir(struct connection_struct *conn, char *fname) +DIR *audit_opendir(struct connection_struct *conn, const char *fname) { DIR *result = default_vfs_ops.opendir(conn, fname); @@ -143,7 +200,7 @@ DIR *audit_opendir(struct connection_struct *conn, char *fname) return result; } -int audit_mkdir(struct connection_struct *conn, char *path, mode_t mode) +int audit_mkdir(struct connection_struct *conn, const char *path, mode_t mode) { int result = default_vfs_ops.mkdir(conn, path, mode); @@ -155,7 +212,7 @@ int audit_mkdir(struct connection_struct *conn, char *path, mode_t mode) return result; } -int audit_rmdir(struct connection_struct *conn, char *path) +int audit_rmdir(struct connection_struct *conn, const char *path) { int result = default_vfs_ops.rmdir(conn, path); @@ -167,7 +224,7 @@ int audit_rmdir(struct connection_struct *conn, char *path) return result; } -int audit_open(struct connection_struct *conn, char *fname, int flags, mode_t mode) +int audit_open(struct connection_struct *conn, const char *fname, int flags, mode_t mode) { int result = default_vfs_ops.open(conn, fname, flags, mode); @@ -192,7 +249,7 @@ int audit_close(struct files_struct *fsp, int fd) return result; } -int audit_rename(struct connection_struct *conn, char *old, char *new) +int audit_rename(struct connection_struct *conn, const char *old, const char *new) { int result = default_vfs_ops.rename(conn, old, new); @@ -204,7 +261,7 @@ int audit_rename(struct connection_struct *conn, char *old, char *new) return result; } -int audit_unlink(struct connection_struct *conn, char *path) +int audit_unlink(struct connection_struct *conn, const char *path) { int result = default_vfs_ops.unlink(conn, path); @@ -216,7 +273,7 @@ int audit_unlink(struct connection_struct *conn, char *path) return result; } -int audit_chmod(struct connection_struct *conn, char *path, mode_t mode) +int audit_chmod(struct connection_struct *conn, const char *path, mode_t mode) { int result = default_vfs_ops.chmod(conn, path, mode); @@ -228,3 +285,38 @@ int audit_chmod(struct connection_struct *conn, char *path, mode_t mode) return result; } +int audit_chmod_acl(struct connection_struct *conn, const char *path, mode_t mode) +{ + int result = default_vfs_ops.chmod_acl(conn, path, mode); + + syslog(SYSLOG_PRIORITY, "chmod_acl %s mode 0x%x %s%s\n", + path, mode, + (result < 0) ? "failed: " : "", + (result < 0) ? strerror(errno) : ""); + + return result; +} + +int audit_fchmod(struct files_struct *fsp, int fd, mode_t mode) +{ + int result = default_vfs_ops.fchmod(fsp, fd, mode); + + syslog(SYSLOG_PRIORITY, "fchmod %s mode 0x%x %s%s\n", + fsp->fsp_name, mode, + (result < 0) ? "failed: " : "", + (result < 0) ? strerror(errno) : ""); + + return result; +} + +int audit_fchmod_acl(struct files_struct *fsp, int fd, mode_t mode) +{ + int result = default_vfs_ops.fchmod_acl(fsp, fd, mode); + + syslog(SYSLOG_PRIORITY, "fchmod_acl %s mode 0x%x %s%s\n", + fsp->fsp_name, mode, + (result < 0) ? "failed: " : "", + (result < 0) ? strerror(errno) : ""); + + return result; +} |