vs_svc.c revision 53c110294d8b1410cabc201a52f94b03ae2ef448
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * CDDL HEADER START
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * The contents of this file are subject to the terms of the
911106dfb16696472af8c1b7b4c554a829354fa8jm * Common Development and Distribution License (the "License").
911106dfb16696472af8c1b7b4c554a829354fa8jm * You may not use this file except in compliance with the License.
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
911106dfb16696472af8c1b7b4c554a829354fa8jm * or http://www.opensolaris.org/os/licensing.
911106dfb16696472af8c1b7b4c554a829354fa8jm * See the License for the specific language governing permissions
911106dfb16696472af8c1b7b4c554a829354fa8jm * and limitations under the License.
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * When distributing Covered Code, include this CDDL HEADER in each
911106dfb16696472af8c1b7b4c554a829354fa8jm * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
911106dfb16696472af8c1b7b4c554a829354fa8jm * If applicable, add the following below this CDDL HEADER, with the
911106dfb16696472af8c1b7b4c554a829354fa8jm * fields enclosed by brackets "[]" replaced with your own identifying
911106dfb16696472af8c1b7b4c554a829354fa8jm * information: Portions Copyright [yyyy] [name of copyright owner]
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * CDDL HEADER END
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
53c110294d8b1410cabc201a52f94b03ae2ef448jm * Copyright 2008 Sun Microsystems, Inc. All rights reserved.
911106dfb16696472af8c1b7b4c554a829354fa8jm * Use is subject to license terms.
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm#pragma ident "%Z%%M% %I% %E% SMI"
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * Implementation of the "scan file" interface
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <stdio.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <stdlib.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <unistd.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <string.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <errno.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <syslog.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <sys/types.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <fcntl.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <bsm/adt.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm#include <bsm/adt_event.h>
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm#include "vs_incl.h"
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/* local functions */
911106dfb16696472af8c1b7b4c554a829354fa8jmstatic void vs_svc_vlog(char *, vs_result_t *);
911106dfb16696472af8c1b7b4c554a829354fa8jmstatic void vs_svc_audit(char *, vs_result_t *);
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * vs_svc_init, vs_svc_fini
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * Invoked on daemon load and unload
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jmvoid
911106dfb16696472af8c1b7b4c554a829354fa8jmvs_svc_init()
911106dfb16696472af8c1b7b4c554a829354fa8jm{
911106dfb16696472af8c1b7b4c554a829354fa8jm}
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jmvoid
911106dfb16696472af8c1b7b4c554a829354fa8jmvs_svc_fini()
911106dfb16696472af8c1b7b4c554a829354fa8jm{
911106dfb16696472af8c1b7b4c554a829354fa8jm}
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * vs_svc_scan_file
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * vs_svc_scan_file is responsible for:
911106dfb16696472af8c1b7b4c554a829354fa8jm * - determining if a scan is required
911106dfb16696472af8c1b7b4c554a829354fa8jm * - obtaining & releasing a scan engine connection
911106dfb16696472af8c1b7b4c554a829354fa8jm * - invoking the scan engine interface code to do the scan
911106dfb16696472af8c1b7b4c554a829354fa8jm * - retrying a failed scan (up to VS_MAX_RETRY times)
911106dfb16696472af8c1b7b4c554a829354fa8jm * - updating scan statistics
911106dfb16696472af8c1b7b4c554a829354fa8jm * - logging virus information
911106dfb16696472af8c1b7b4c554a829354fa8jm *
53c110294d8b1410cabc201a52f94b03ae2ef448jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * Returns:
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_STATUS_NO_SCAN - scan not reqd, or daemon shutting down
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_STATUS_CLEAN - scan success. File clean.
53c110294d8b1410cabc201a52f94b03ae2ef448jm * new scanstamp returned in scanstamp param.
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_STATUS_INFECTED - scan success. File infected.
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_STATUS_ERROR - scan failure either in vscand or scan engine.
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jmint
53c110294d8b1410cabc201a52f94b03ae2ef448jmvs_svc_scan_file(char *devname, char *fname, vs_attr_t *fattr, int flags,
53c110294d8b1410cabc201a52f94b03ae2ef448jm vs_scanstamp_t *scanstamp)
911106dfb16696472af8c1b7b4c554a829354fa8jm{
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_conn_t conn;
53c110294d8b1410cabc201a52f94b03ae2ef448jm int retries;
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_result_t result;
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /* initialize response scanstamp to current scanstamp value */
53c110294d8b1410cabc201a52f94b03ae2ef448jm (void) strlcpy(*scanstamp, fattr->vsa_scanstamp,
53c110294d8b1410cabc201a52f94b03ae2ef448jm sizeof (vs_scanstamp_t));
53c110294d8b1410cabc201a52f94b03ae2ef448jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /* No scan if file quarantined */
911106dfb16696472af8c1b7b4c554a829354fa8jm if (fattr->vsa_quarantined)
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_NO_SCAN);
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /* No scan if file not modified AND scanstamp is current */
53c110294d8b1410cabc201a52f94b03ae2ef448jm if ((fattr->vsa_modified == 0) &&
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_scanstamp_current(fattr->vsa_scanstamp)) {
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_NO_SCAN);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) memset(&result, 0, sizeof (vs_result_t));
911106dfb16696472af8c1b7b4c554a829354fa8jm result.vsr_rc = VS_RESULT_UNDEFINED;
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm for (retries = 0; retries <= VS_MAX_RETRY; retries++) {
911106dfb16696472af8c1b7b4c554a829354fa8jm /* identify available engine connection */
911106dfb16696472af8c1b7b4c554a829354fa8jm if (vs_eng_get(&conn, retries) != 0) {
53c110294d8b1410cabc201a52f94b03ae2ef448jm result.vsr_rc = VS_RESULT_ERROR;
911106dfb16696472af8c1b7b4c554a829354fa8jm continue;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm /* connect to engine and scan file */
53c110294d8b1410cabc201a52f94b03ae2ef448jm if (vs_eng_connect(&conn) != 0) {
53c110294d8b1410cabc201a52f94b03ae2ef448jm result.vsr_rc = VS_RESULT_SE_ERROR;
53c110294d8b1410cabc201a52f94b03ae2ef448jm } else {
911106dfb16696472af8c1b7b4c554a829354fa8jm if (vscand_get_state() == VS_STATE_SHUTDOWN) {
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_release(&conn);
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_NO_SCAN);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm (void) vs_icap_scan_file(&conn, devname, fname,
911106dfb16696472af8c1b7b4c554a829354fa8jm fattr->vsa_size, flags, &result);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm /* if no error, clear error state on engine and break */
53c110294d8b1410cabc201a52f94b03ae2ef448jm if ((result.vsr_rc != VS_RESULT_SE_ERROR) &&
53c110294d8b1410cabc201a52f94b03ae2ef448jm (result.vsr_rc != VS_RESULT_ERROR)) {
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_set_error(&conn, 0);
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_release(&conn);
911106dfb16696472af8c1b7b4c554a829354fa8jm break;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /* treat error on shutdown as scan not required */
911106dfb16696472af8c1b7b4c554a829354fa8jm if (vscand_get_state() == VS_STATE_SHUTDOWN) {
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_release(&conn);
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_NO_SCAN);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm /* set engine's error state and update engine stats */
53c110294d8b1410cabc201a52f94b03ae2ef448jm if (result.vsr_rc == VS_RESULT_SE_ERROR) {
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_set_error(&conn, 1);
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_stats_eng_err(conn.vsc_engid);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_eng_release(&conn);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm vs_stats_set(result.vsr_rc);
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /*
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_RESULT_CLEANED - file infected, cleaned data available
53c110294d8b1410cabc201a52f94b03ae2ef448jm * VS_RESULT_FORBIDDEN - file infected, no cleaned data
53c110294d8b1410cabc201a52f94b03ae2ef448jm * Log virus, write audit record and return INFECTED status
53c110294d8b1410cabc201a52f94b03ae2ef448jm */
911106dfb16696472af8c1b7b4c554a829354fa8jm if (result.vsr_rc == VS_RESULT_CLEANED ||
911106dfb16696472af8c1b7b4c554a829354fa8jm result.vsr_rc == VS_RESULT_FORBIDDEN) {
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_svc_vlog(fname, &result);
911106dfb16696472af8c1b7b4c554a829354fa8jm vs_svc_audit(fname, &result);
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_INFECTED);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm /* VS_RESULT_CLEAN - Set the scanstamp and return CLEAN status */
53c110294d8b1410cabc201a52f94b03ae2ef448jm if (result.vsr_rc == VS_RESULT_CLEAN) {
53c110294d8b1410cabc201a52f94b03ae2ef448jm (void) strlcpy(*scanstamp, result.vsr_scanstamp,
911106dfb16696472af8c1b7b4c554a829354fa8jm sizeof (vs_scanstamp_t));
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_CLEAN);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
53c110294d8b1410cabc201a52f94b03ae2ef448jm return (VS_STATUS_ERROR);
911106dfb16696472af8c1b7b4c554a829354fa8jm}
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * vs_svc_vlog
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * log details of infections detected in file
911106dfb16696472af8c1b7b4c554a829354fa8jm * If virus log is not configured or cannot be opened, use syslog.
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jmstatic void
911106dfb16696472af8c1b7b4c554a829354fa8jmvs_svc_vlog(char *filepath, vs_result_t *result)
911106dfb16696472af8c1b7b4c554a829354fa8jm{
911106dfb16696472af8c1b7b4c554a829354fa8jm FILE *fp = NULL;
911106dfb16696472af8c1b7b4c554a829354fa8jm time_t sec;
911106dfb16696472af8c1b7b4c554a829354fa8jm struct tm *timestamp;
911106dfb16696472af8c1b7b4c554a829354fa8jm char timebuf[18]; /* MM/DD/YY hh:mm:ss */
911106dfb16696472af8c1b7b4c554a829354fa8jm int i;
911106dfb16696472af8c1b7b4c554a829354fa8jm char *log;
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if ((log = vscand_viruslog()) != NULL)
911106dfb16696472af8c1b7b4c554a829354fa8jm fp = fopen(log, "a");
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (fp) {
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) time(&sec);
911106dfb16696472af8c1b7b4c554a829354fa8jm timestamp = localtime(&sec);
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) strftime(timebuf, sizeof (timebuf), "%D %T", timestamp);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (result->vsr_nviolations == 0) {
911106dfb16696472af8c1b7b4c554a829354fa8jm if (fp) {
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) fprintf(fp, "%s quarantine %s",
911106dfb16696472af8c1b7b4c554a829354fa8jm timebuf, filepath);
911106dfb16696472af8c1b7b4c554a829354fa8jm } else {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_WARNING, "quarantine %s\n", filepath);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm } else {
911106dfb16696472af8c1b7b4c554a829354fa8jm for (i = 0; i < result->vsr_nviolations; i++) {
911106dfb16696472af8c1b7b4c554a829354fa8jm if (fp) {
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) fprintf(fp, "%s quarantine %s %d - %s\n",
911106dfb16696472af8c1b7b4c554a829354fa8jm timebuf, filepath,
911106dfb16696472af8c1b7b4c554a829354fa8jm result->vsr_vrec[i].vr_id,
911106dfb16696472af8c1b7b4c554a829354fa8jm result->vsr_vrec[i].vr_desc);
911106dfb16696472af8c1b7b4c554a829354fa8jm } else {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_WARNING, "quarantine %s %d - %s\n",
911106dfb16696472af8c1b7b4c554a829354fa8jm filepath,
911106dfb16696472af8c1b7b4c554a829354fa8jm result->vsr_vrec[i].vr_id,
911106dfb16696472af8c1b7b4c554a829354fa8jm result->vsr_vrec[i].vr_desc);
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (fp)
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) fclose(fp);
911106dfb16696472af8c1b7b4c554a829354fa8jm}
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm/*
911106dfb16696472af8c1b7b4c554a829354fa8jm * vs_svc_audit
911106dfb16696472af8c1b7b4c554a829354fa8jm *
911106dfb16696472af8c1b7b4c554a829354fa8jm * Generate AUE_vscan_quarantine audit record containing name
911106dfb16696472af8c1b7b4c554a829354fa8jm * of infected file, and violation details if available.
911106dfb16696472af8c1b7b4c554a829354fa8jm */
911106dfb16696472af8c1b7b4c554a829354fa8jmstatic void
911106dfb16696472af8c1b7b4c554a829354fa8jmvs_svc_audit(char *filepath, vs_result_t *result)
911106dfb16696472af8c1b7b4c554a829354fa8jm{
911106dfb16696472af8c1b7b4c554a829354fa8jm int i;
911106dfb16696472af8c1b7b4c554a829354fa8jm char *violations[VS_MAX_VIOLATIONS];
911106dfb16696472af8c1b7b4c554a829354fa8jm char data[VS_MAX_VIOLATIONS][VS_DESCRIPTION_MAX];
911106dfb16696472af8c1b7b4c554a829354fa8jm adt_session_data_t *ah;
911106dfb16696472af8c1b7b4c554a829354fa8jm adt_termid_t *p_tid;
911106dfb16696472af8c1b7b4c554a829354fa8jm adt_event_data_t *event;
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (adt_start_session(&ah, NULL, ADT_USE_PROC_DATA)) {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_AUTH | LOG_ALERT, "adt_start_session: %m");
911106dfb16696472af8c1b7b4c554a829354fa8jm return;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (adt_load_ttyname("/dev/console", &p_tid) != 0) {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_AUTH | LOG_ALERT,
911106dfb16696472af8c1b7b4c554a829354fa8jm "adt_load_ttyname(/dev/console): %m");
911106dfb16696472af8c1b7b4c554a829354fa8jm return;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (adt_set_user(ah, ADT_NO_ATTRIB, ADT_NO_ATTRIB, ADT_NO_ATTRIB,
911106dfb16696472af8c1b7b4c554a829354fa8jm ADT_NO_ATTRIB, p_tid, ADT_NEW) != 0) {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_AUTH | LOG_ALERT, "adt_set_user(ADT_NO_ATTRIB): %m");
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) adt_end_session(ah);
911106dfb16696472af8c1b7b4c554a829354fa8jm return;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if ((event = adt_alloc_event(ah, ADT_vscan_quarantine)) == NULL) {
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_AUTH | LOG_ALERT,
911106dfb16696472af8c1b7b4c554a829354fa8jm "adt_alloc_event(ADT_vscan_quarantine)): %m");
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) adt_end_session(ah);
911106dfb16696472af8c1b7b4c554a829354fa8jm return;
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm /* populate vscan audit event */
911106dfb16696472af8c1b7b4c554a829354fa8jm event->adt_vscan_quarantine.file = filepath;
911106dfb16696472af8c1b7b4c554a829354fa8jm for (i = 0; i < result->vsr_nviolations; i++) {
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) snprintf(data[i], VS_DESCRIPTION_MAX, "%d - %s",
911106dfb16696472af8c1b7b4c554a829354fa8jm result->vsr_vrec[i].vr_id, result->vsr_vrec[i].vr_desc);
911106dfb16696472af8c1b7b4c554a829354fa8jm violations[i] = data[i];
911106dfb16696472af8c1b7b4c554a829354fa8jm }
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm event->adt_vscan_quarantine.violations = (char **)violations;
911106dfb16696472af8c1b7b4c554a829354fa8jm event->adt_vscan_quarantine.nviolations = result->vsr_nviolations;
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm if (adt_put_event(event, ADT_SUCCESS, ADT_SUCCESS))
911106dfb16696472af8c1b7b4c554a829354fa8jm syslog(LOG_AUTH | LOG_ALERT, "adt_put_event: %m");
911106dfb16696472af8c1b7b4c554a829354fa8jm
911106dfb16696472af8c1b7b4c554a829354fa8jm adt_free_event(event);
911106dfb16696472af8c1b7b4c554a829354fa8jm (void) adt_end_session(ah);
911106dfb16696472af8c1b7b4c554a829354fa8jm}