From df5afa4fcd9725380f94ca6476248d4cc24f889a Mon Sep 17 00:00:00 2001 From: Ashlee Young Date: Sun, 29 Nov 2015 08:22:13 -0800 Subject: v2.4.4 audit sources Change-Id: I9315a7408817db51edf084fb4d27fbb492785084 Signed-off-by: Ashlee Young --- framework/src/audit/docs/audit_set_failure.3 | 38 ++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 framework/src/audit/docs/audit_set_failure.3 (limited to 'framework/src/audit/docs/audit_set_failure.3') diff --git a/framework/src/audit/docs/audit_set_failure.3 b/framework/src/audit/docs/audit_set_failure.3 new file mode 100644 index 00000000..cf526f03 --- /dev/null +++ b/framework/src/audit/docs/audit_set_failure.3 @@ -0,0 +1,38 @@ +.TH "AUDIT_SET_FAILURE" "3" "June 2015" "Red Hat" "Linux Audit API" +.SH NAME +audit_set_failure \- Set audit failure flag +.SH "SYNOPSIS" + +.B #include +.sp +int audit_set_failure(int fd, int failure); + +.SH "DESCRIPTION" + +audit_set_failure sets the action that the kernel will perform when the backlog limit is reached or when it encounters an error and cannot proceed. Possible values are: + +.TP +0 - AUDIT_FAIL_SILENT +Do nothing, report nothing, skip logging the record and continue. + +.TP +1 - AUDIT_FAIL_PRINTK [default] +Log the audit record using printk which will cause subsequent events to get written to syslog. + +.TP +2 - AUDIT_FAIL_PANIC +Call the panic function. This would be used to prevent use of the machine upon loss of audit events. + +.SH "RETURN VALUE" + +The return value is <= 0 on error, otherwise it is the netlink sequence id number. This function can have any error that sendto would encounter. + +.SH "SEE ALSO" + +.BR audit_set_backlog (3), +.BR audit_open (3), +.BR auditd (8), +.BR auditctl (8). + +.SH AUTHOR +Steve Grubb -- cgit 1.2.3-korg