Open System Services Programmer's Guide
Table 37 OSS Function Calls Audited When Used With Audited Filesets (continued)
Attributes or Actions AuditedOSS Function
The values of the OSS user ID, group ID, and file mode before and after the call.chown()
Use on files in the /G directory is also audited.
fchown()
lchown()
For AF_UNIX sockets, the values of the OSS user ID and group ID. Only audited beginning
with the J06.15 and H06.26 RVUs.
connect()
For all files, the value of the file mode, the OSS user ID, the group ID, and rdev.creat()
For regular files, the value of the open flags.
creat64()
The value of the OSS user ID and group ID.Use on files in the /G directory is also audited.execl()
execle()
execlp()
execv()
execve()
execvp()
The value of the OSS user ID and group ID.fork()
The signal sent, the real OSS user ID and effective OSS user ID of the sender, the OSS
process ID or process group ID, the process handle, and the saved set OSS user ID of the
target process.
kill()
If the target process is a member of a process group, the audit information is logged for
all the processes affected by the call when those processes can be determined.
The name and the link count of the linked-to file, and the new filename.link()
The value of the file mode, the OSS user ID, the group ID, and rdev.mkdir()
The value of the file mode, the OSS user ID, the group ID, and rdev.mkfifo()
The value of the file mode, the OSS user ID, the group ID, and rdev.mknod()
The value of the open flags and the value of the file mode before and after the call.open()
Use on files in the /G directory is also audited.
open64()
The value of the open flags and the value of the file mode before and after the call.opendir()
The old and new pathname values.rename()
For a link count of zero, the value of the file mode, the OSS user ID, the group ID, the
mtime, ctime, size, and rdev.
rmdir()
For a link count that is not zero, the value of the link count after the call.
The value of the file privilege attribute before and after the call. Use on files in the /G
directory is also audited.
setfilepriv()
The value of the real, effective, and saved-set group ID before and after the call.setgid()
The value of the process-group ID before and after the call.setpgid()
The value of the process-group ID before and after the call.setpgrp()
The value of the real, effective, and saved-set OSS group ID before and after the callsetregid()
The value of the process-group ID before and after the call.setsid()
The value of the real, effective, and saved-set OSS user ID before and after the call.setreuid()
The value of the real, effective, and saved-set OSS user ID before and after the call.setuid()
The contents of the symbolic link and the value of the file mode, the OSS user ID, the group
ID, and rdev.
symlink()
254 Managing OSS Security










