selftest/Samba4: make use of get_cmd_env_vars() to setup all relevant env variables
[samba.git] / source3 / modules / vfs_audit.c
index 24bc1e8db5f8767ebac5ebc5c7ced9e2dcbc0157..2b01a6a8d91ff35b336d2cc528b4ecb12db306fa 100644 (file)
 static int audit_syslog_facility(vfs_handle_struct *handle)
 {
        static const struct enum_list enum_log_facilities[] = {
-               { LOG_USER, "USER" },
-               { LOG_LOCAL0, "LOCAL0" },
-               { LOG_LOCAL1, "LOCAL1" },
-               { LOG_LOCAL2, "LOCAL2" },
-               { LOG_LOCAL3, "LOCAL3" },
-               { LOG_LOCAL4, "LOCAL4" },
-               { LOG_LOCAL5, "LOCAL5" },
-               { LOG_LOCAL6, "LOCAL6" },
-               { LOG_LOCAL7, "LOCAL7" },
-               { -1, NULL}
+#ifdef LOG_AUTH
+               { LOG_AUTH,             "AUTH" },
+#endif
+#ifdef LOG_AUTHPRIV
+               { LOG_AUTHPRIV,         "AUTHPRIV" },
+#endif
+#ifdef LOG_AUDIT
+               { LOG_AUDIT,            "AUDIT" },
+#endif
+#ifdef LOG_CONSOLE
+               { LOG_CONSOLE,          "CONSOLE" },
+#endif
+#ifdef LOG_CRON
+               { LOG_CRON,             "CRON" },
+#endif
+#ifdef LOG_DAEMON
+               { LOG_DAEMON,           "DAEMON" },
+#endif
+#ifdef LOG_FTP
+               { LOG_FTP,              "FTP" },
+#endif
+#ifdef LOG_INSTALL
+               { LOG_INSTALL,          "INSTALL" },
+#endif
+#ifdef LOG_KERN
+               { LOG_KERN,             "KERN" },
+#endif
+#ifdef LOG_LAUNCHD
+               { LOG_LAUNCHD,          "LAUNCHD" },
+#endif
+#ifdef LOG_LFMT
+               { LOG_LFMT,             "LFMT" },
+#endif
+#ifdef LOG_LPR
+               { LOG_LPR,              "LPR" },
+#endif
+#ifdef LOG_MAIL
+               { LOG_MAIL,             "MAIL" },
+#endif
+#ifdef LOG_MEGASAFE
+               { LOG_MEGASAFE,         "MEGASAFE" },
+#endif
+#ifdef LOG_NETINFO
+               { LOG_NETINFO,          "NETINFO" },
+#endif
+#ifdef LOG_NEWS
+               { LOG_NEWS,             "NEWS" },
+#endif
+#ifdef LOG_NFACILITIES
+               { LOG_NFACILITIES,      "NFACILITIES" },
+#endif
+#ifdef LOG_NTP
+               { LOG_NTP,              "NTP" },
+#endif
+#ifdef LOG_RAS
+               { LOG_RAS,              "RAS" },
+#endif
+#ifdef LOG_REMOTEAUTH
+               { LOG_REMOTEAUTH,       "REMOTEAUTH" },
+#endif
+#ifdef LOG_SECURITY
+               { LOG_SECURITY,         "SECURITY" },
+#endif
+#ifdef LOG_SYSLOG
+               { LOG_SYSLOG,           "SYSLOG" },
+#endif
+#ifdef LOG_USER
+               { LOG_USER,             "USER" },
+#endif
+#ifdef LOG_UUCP
+               { LOG_UUCP,             "UUCP" },
+#endif
+               { LOG_LOCAL0,           "LOCAL0" },
+               { LOG_LOCAL1,           "LOCAL1" },
+               { LOG_LOCAL2,           "LOCAL2" },
+               { LOG_LOCAL3,           "LOCAL3" },
+               { LOG_LOCAL4,           "LOCAL4" },
+               { LOG_LOCAL5,           "LOCAL5" },
+               { LOG_LOCAL6,           "LOCAL6" },
+               { LOG_LOCAL7,           "LOCAL7" },
+               { -1,                   NULL }
        };
 
        int facility;
@@ -64,7 +135,7 @@ static int audit_syslog_priority(vfs_handle_struct *handle)
                { LOG_NOTICE, "NOTICE" },
                { LOG_INFO, "INFO" },
                { LOG_DEBUG, "DEBUG" },
-               { -1, NULL}
+               { -1, NULL }
        };
 
        int priority;
@@ -106,65 +177,51 @@ static void audit_disconnect(vfs_handle_struct *handle)
        return;
 }
 
-static DIR *audit_opendir(vfs_handle_struct *handle,
-                       const struct smb_filename *smb_fname,
-                       const char *mask,
-                       uint32_t attr)
-{
-       DIR *result;
-       
-       result = SMB_VFS_NEXT_OPENDIR(handle, smb_fname, mask, attr);
-
-       syslog(audit_syslog_priority(handle), "opendir %s %s%s\n",
-              smb_fname->base_name,
-              (result == NULL) ? "failed: " : "",
-              (result == NULL) ? strerror(errno) : "");
-
-       return result;
-}
-
-static int audit_mkdir(vfs_handle_struct *handle,
+static int audit_mkdirat(vfs_handle_struct *handle,
+               struct files_struct *dirfsp,
                const struct smb_filename *smb_fname,
                mode_t mode)
 {
+       struct smb_filename *full_fname = NULL;
        int result;
-       
-       result = SMB_VFS_NEXT_MKDIR(handle, smb_fname, mode);
-       
-       syslog(audit_syslog_priority(handle), "mkdir %s %s%s\n", 
-              smb_fname->base_name,
-              (result < 0) ? "failed: " : "",
-              (result < 0) ? strerror(errno) : "");
-
-       return result;
-}
 
-static int audit_rmdir(vfs_handle_struct *handle,
-               const struct smb_filename *smb_fname)
-{
-       int result;
+       full_fname = full_path_from_dirfsp_atname(talloc_tos(),
+                                                 dirfsp,
+                                                 smb_fname);
+       if (full_fname == NULL) {
+               errno = ENOMEM;
+               return -1;
+       }
 
-       result = SMB_VFS_NEXT_RMDIR(handle, smb_fname);
+       result = SMB_VFS_NEXT_MKDIRAT(handle,
+                       dirfsp,
+                       smb_fname,
+                       mode);
 
-       syslog(audit_syslog_priority(handle), "rmdir %s %s%s\n", 
-              smb_fname->base_name,
+       syslog(audit_syslog_priority(handle), "mkdirat %s %s%s\n",
+              full_fname->base_name,
               (result < 0) ? "failed: " : "",
               (result < 0) ? strerror(errno) : "");
 
+       TALLOC_FREE(full_fname);
        return result;
 }
 
-static int audit_open(vfs_handle_struct *handle,
-                     struct smb_filename *smb_fname, files_struct *fsp,
-                     int flags, mode_t mode)
+static int audit_openat(vfs_handle_struct *handle,
+                       const struct files_struct *dirfsp,
+                       const struct smb_filename *smb_fname,
+                       struct files_struct *fsp,
+                       const struct vfs_open_how *how)
 {
        int result;
 
-       result = SMB_VFS_NEXT_OPEN(handle, smb_fname, fsp, flags, mode);
+       result = SMB_VFS_NEXT_OPENAT(handle, dirfsp, smb_fname, fsp, how);
 
-       syslog(audit_syslog_priority(handle), "open %s (fd %d) %s%s%s\n", 
-              smb_fname->base_name, result,
-              ((flags & O_WRONLY) || (flags & O_RDWR)) ? "for writing " : "", 
+       syslog(audit_syslog_priority(handle),
+              "openat %s (fd %d) %s%s%s\n",
+              fsp_str_dbg(fsp), result,
+              ((how->flags & O_WRONLY) || (how->flags & O_RDWR)) ?
+              "for writing " : "",
               (result < 0) ? "failed: " : "",
               (result < 0) ? strerror(errno) : "");
 
@@ -178,58 +235,90 @@ static int audit_close(vfs_handle_struct *handle, files_struct *fsp)
        result = SMB_VFS_NEXT_CLOSE(handle, fsp);
 
        syslog(audit_syslog_priority(handle), "close fd %d %s%s\n",
-              fsp->fh->fd,
+              fsp_get_pathref_fd(fsp),
               (result < 0) ? "failed: " : "",
               (result < 0) ? strerror(errno) : "");
 
        return result;
 }
 
-static int audit_rename(vfs_handle_struct *handle,
+static int audit_renameat(vfs_handle_struct *handle,
+                       files_struct *srcfsp,
                        const struct smb_filename *smb_fname_src,
+                       files_struct *dstfsp,
                        const struct smb_filename *smb_fname_dst)
 {
+       struct smb_filename *full_fname_src = NULL;
+       struct smb_filename *full_fname_dst = NULL;
        int result;
+       int saved_errno = 0;
+
+       full_fname_src = full_path_from_dirfsp_atname(talloc_tos(),
+                                                 srcfsp,
+                                                 smb_fname_src);
+       if (full_fname_src == NULL) {
+               errno = ENOMEM;
+               return -1;
+       }
+       full_fname_dst = full_path_from_dirfsp_atname(talloc_tos(),
+                                                 dstfsp,
+                                                 smb_fname_dst);
+       if (full_fname_dst == NULL) {
+               TALLOC_FREE(full_fname_src);
+               errno = ENOMEM;
+               return -1;
+       }
+       result = SMB_VFS_NEXT_RENAMEAT(handle,
+                       srcfsp,
+                       smb_fname_src,
+                       dstfsp,
+                       smb_fname_dst);
+       if (result == -1) {
+               saved_errno = errno;
+       }
 
-       result = SMB_VFS_NEXT_RENAME(handle, smb_fname_src, smb_fname_dst);
-
-       syslog(audit_syslog_priority(handle), "rename %s -> %s %s%s\n",
-              smb_fname_src->base_name,
-              smb_fname_dst->base_name,
+       syslog(audit_syslog_priority(handle), "renameat %s -> %s %s%s\n",
+              full_fname_src->base_name,
+              full_fname_dst->base_name,
               (result < 0) ? "failed: " : "",
               (result < 0) ? strerror(errno) : "");
 
-       return result;    
-}
+       TALLOC_FREE(full_fname_src);
+       TALLOC_FREE(full_fname_dst);
 
-static int audit_unlink(vfs_handle_struct *handle,
-                       const struct smb_filename *smb_fname)
-{
-       int result;
-
-       result = SMB_VFS_NEXT_UNLINK(handle, smb_fname);
-
-       syslog(audit_syslog_priority(handle), "unlink %s %s%s\n",
-              smb_fname->base_name,
-              (result < 0) ? "failed: " : "",
-              (result < 0) ? strerror(errno) : "");
+       if (saved_errno != 0) {
+               errno = saved_errno;
+       }
 
        return result;
 }
 
-static int audit_chmod(vfs_handle_struct *handle,
+static int audit_unlinkat(vfs_handle_struct *handle,
+                       struct files_struct *dirfsp,
                        const struct smb_filename *smb_fname,
-                       mode_t mode)
+                       int flags)
 {
+       struct smb_filename *full_fname = NULL;
        int result;
 
-       result = SMB_VFS_NEXT_CHMOD(handle, smb_fname, mode);
+       full_fname = full_path_from_dirfsp_atname(talloc_tos(),
+                                                 dirfsp,
+                                                 smb_fname);
+       if (full_fname == NULL) {
+               return -1;
+       }
+
+       result = SMB_VFS_NEXT_UNLINKAT(handle,
+                       dirfsp,
+                       smb_fname,
+                       flags);
 
-       syslog(audit_syslog_priority(handle), "chmod %s mode 0x%x %s%s\n",
-              smb_fname->base_name, mode,
+       syslog(audit_syslog_priority(handle), "unlinkat %s %s%s\n",
+              full_fname->base_name,
               (result < 0) ? "failed: " : "",
               (result < 0) ? strerror(errno) : "");
 
+       TALLOC_FREE(full_fname);
        return result;
 }
 
@@ -250,14 +339,11 @@ static int audit_fchmod(vfs_handle_struct *handle, files_struct *fsp, mode_t mod
 static struct vfs_fn_pointers vfs_audit_fns = {
        .connect_fn = audit_connect,
        .disconnect_fn = audit_disconnect,
-       .opendir_fn = audit_opendir,
-       .mkdir_fn = audit_mkdir,
-       .rmdir_fn = audit_rmdir,
-       .open_fn = audit_open,
+       .mkdirat_fn = audit_mkdirat,
+       .openat_fn = audit_openat,
        .close_fn = audit_close,
-       .rename_fn = audit_rename,
-       .unlink_fn = audit_unlink,
-       .chmod_fn = audit_chmod,
+       .renameat_fn = audit_renameat,
+       .unlinkat_fn = audit_unlinkat,
        .fchmod_fn = audit_fchmod,
 };