Intelligent Assistant
Chat with our virtual assistant to get answers promptly.
This module provides security audit APIs.
System capability: SystemCapability.Security.SecurityAudit
Since: 6.0.0(20)
| Name | Description |
|---|---|
| security_audit.h | Defines the security audit functions. |
| Name | Description |
|---|---|
| struct SecurityAudit_Event | Defines the audit event information. |
| struct SecurityAudit_Filter | Defines a filter. |
| struct SecurityAudit_AuthClientConfiguration | Configuration for an authentication event client. |
| Name | Description |
|---|---|
| typedef void(* SecurityAudit_Handler) (const SecurityAudit_Event *events, uint64_t count) | Defines an event processing function. |
| typedef struct SecurityAudit_AuthClient_Impl SecurityAudit_AuthClient | Defines an authentication event client. |
| typedef struct SecurityAudit_AuthClientConfiguration_Impl SecurityAudit_AuthClientConfiguration | Defines a configuration object for an authentication event client. |
| typedef struct SecurityAudit_Client_Impl SecurityAudit_Client | Defines a notification event client. |
| Name | Description |
|---|---|
| SECURITY_AUDIT_NOTIFY_EVENT_PASTEBOARD = 0x27000000, SECURITY_AUDIT_NOTIFY_EVENT_FILE = 0x1C000007, SECURITY_AUDIT_NOTIFY_EVENT_FILE_INTERCEPTED = 0x1C001100, SECURITY_AUDIT_NOTIFY_EVENT_ACCOUNT = 0x10000100, SECURITY_AUDIT_NOTIFY_EVENT_WINDOW = 0x07000000, SECURITY_AUDIT_NOTIFY_EVENT_VOLUME = 0x0F000000, SECURITY_AUDIT_NOTIFY_EVENT_PRINTER = 0x2E000000, SECURITY_AUDIT_NOTIFY_EVENT_PROCESS = 0x1C000008, SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_TRAFFIC = 0x1C00000E, SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_CONN = 0x1C00000F, SECURITY_AUDIT_NOTIFY_EVENT_CAMERA = 0x2D000000, SECURITY_AUDIT_NOTIFY_EVENT_APP = 0x10000000, SECURITY_AUDIT_NOTIFY_EVENT_EDM = 0x11000000, SECURITY_AUDIT_NOTIFY_EVENT_CERT = 0x12003000, SECURITY_AUDIT_NOTIFY_EVENT_KIA_CREATE = 0x1C00000B, SECURITY_AUDIT_NOTIFY_EVENT_KIA_READ = 0x1C000012, SECURITY_AUDIT_NOTIFY_EVENT_KIA_VARIANT = 0x1C00000C, SECURITY_AUDIT_NOTIFY_EVENT_KIA_INTERCEPT = 0x1C00000A, SECURITY_AUDIT_NOTIFY_EVENT_PERMISSION = 0x0B000000, SECURITY_AUDIT_NOTIFY_EVENT_DNS = 0x03000001, SECURITY_AUDIT_NOTIFY_EVENT_APP_INSTALL_INTERCEPTED = 0x18000100, SECURITY_AUDIT_NOTIFY_EVENT_APP_UNINSTALL_INTERCEPTED = 0x18000101, SECURITY_AUDIT_NOTIFY_EVENT_APP_UPDATE_INTERCEPTED = 0x18000102, SECURITY_AUDIT_NOTIFY_EVENT_APP_RECOVER_INTERCEPTED = 0x18000103, SECURITY_AUDIT_NOTIFY_EVENT_APP_START_INTERCEPTED = 0x18000104, SECURITY_AUDIT_NOTIFY_EVENT_USB_ACCESS_INTERCEPTED = 0x30000000, SECURITY_AUDIT_NOTIFY_EVENT_SMB_FILE_SEND = 0x0F000001, SECURITY_AUDIT_NOTIFY_EVENT_FILE_SHARE= 0x0F000002, SECURITY_AUDIT_NOTIFY_EVENT_DATA_DRAG= 0x0F000003, SECURITY_AUDIT_NOTIFY_EVENT_KIA_PRE_OPEN = 0x1C000014, SECURITY_AUDIT_NOTIFY_EVENT_HDC_DEBUG = 0x27000100, SECURITY_AUDIT_NOTIFY_EVENT_HDC_DEBUG_INTERCEPTED = 0x27000101, SECURITY_AUDIT_NOTIFY_EVENT_USER_SPACE_DATA_TRANSFER = 0x2F000000, SECURITY_AUDIT_NOTIFY_EVENT_USER_SPACE_DATA_TRANSFER_POLICY = 0x2F000001, SECURITY_AUDIT_NOTIFY_EVENT_SERIAL_PORT_ACCESS = 0x30000100, SECURITY_AUDIT_NOTIFY_EVENT_BLUETOOTH_INTERCEPTED = 0x03000200, SECURITY_AUDIT_NOTIFY_EVENT_DISC_BURNING = 0x0F000004, SECURITY_AUDIT_NOTIFY_EVENT_MEDIA_FILE_ACCESS = 0x0F000005, SECURITY_AUDIT_NOTIFY_EVENT_ACCOUNT_MANAGEMENT = 0x10000103, SECURITY_AUDIT_NOTIFY_EVENT_DEVICE_POWER_ON = 0x16000001, SECURITY_AUDIT_NOTIFY_EVENT_DEVICE_POWER_OFF = 0x16000002, SECURITY_AUDIT_NOTIFY_EVENT_AUDIO_INTERFACE_ACCESS = 0x1A000001, SECURITY_AUDIT_NOTIFY_EVENT_VIDEO_INTERFACE_ACCESS = 0x1A000002, SECURITY_AUDIT_NOTIFY_EVENT_SERIAL_PORT_INTERCEPTED = 0x30000101, SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_INTERCEPTED = 0x03000002, SECURITY_AUDIT_NOTIFY_EVENT_WIFI_INTERCEPTED = 0x03000100, SECURITY_AUDIT_NOTIFY_EVENT_PRINT_INTERCEPTED = 0x2E000001, SECURITY_AUDIT_NOTIFY_EVENT_CS_VERIFY_NULL = 0x12001081, SECURITY_AUDIT_NOTIFY_EVENT_CS_VERIFY_ABNORMAL = 0x12001082, SECURITY_AUDIT_NOTIFY_EVENT_FS_MOUNT_ABNORMAL = 0x1C001102, SECURITY_AUDIT_NOTIFY_EVENT_DRIVER_CS_ABNORMAL = 0x1C001200, SECURITY_AUDIT_NOTIFY_EVENT_DRIVER_MMAP_ABNORMAL = 0x1C001201, SECURITY_AUDIT_NOTIFY_EVENT_KERNEL_MEMORY_ABNORMAL = 0x1C001300, SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_DEBUG_ABNORMAL = 0x1C001401, SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_CRASH_ABNORMAL = 0x1C001402, SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_PRIVILEGE_ESCALATION = 0x1C001403, SECURITY_AUDIT_NOTIFY_EVENT_DLP_FILE_ACCESS = 0x0F000006, SECURITY_AUDIT_NOTIFY_EVENT_FILE_CREATE = 0x1C001104, SECURITY_AUDIT_NOTIFY_EVENT_FILE_OPEN = 0x1C001105, SECURITY_AUDIT_NOTIFY_EVENT_FILE_CLOSE = 0x1C001106, SECURITY_AUDIT_NOTIFY_EVENT_FILE_DELETE = 0x1C001107, SECURITY_AUDIT_NOTIFY_EVENT_FILE_RENAME = 0x1C001108, SECURITY_AUDIT_NOTIFY_EVENT_FILE_COPY = 0x1C001109, SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETOWNER = 0x1C00110A, SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETMODE = 0x1C00110B, SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETEXTATTR = 0x1C00110C, SECURITY_AUDIT_NOTIFY_EVENT_FILE_DELETEEXTATTR = 0x1C00110D, SECURITY_AUDIT_NOTIFY_EVENT_FILE_WRITE = 0x1C00110E } | Defines the notification event IDs. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_CREATE = 0x1C801100, SECURITY_AUDIT_AUTH_EVENT_FILE_OPEN = 0x1C801101, SECURITY_AUDIT_AUTH_EVENT_FILE_RENAME = 0x1C801102, SECURITY_AUDIT_AUTH_EVENT_FILE_DELETE = 0x1C801103, SECURITY_AUDIT_AUTH_EVENT_FILE_SETEXTATTR = 0x1C801104, SECURITY_AUDIT_AUTH_EVENT_FILE_DELETEEXTATTR = 0x1C801105, SECURITY_AUDIT_AUTH_EVENT_FILE_READ_END = 0x1C801106, SECURITY_AUDIT_AUTH_EVENT_PROCESS_EXEC = 0x1C801400 } | Defines the authentication event IDs. |
| EVENT_TYPE_EQUAL = 0x00000100, EVENT_SUBTYPE_EQUAL = 0x00000200, FILE_PATH_EQUAL = 0x00010000, FILE_PATH_PREFIX = 0x00010001, FILE_PATH_SUFFIX = 0x00010002, FILE_PATH_REGULAR = 0x00010003, PROCESS_UID_EQUAL = 0x00020000, PROCESS_PID_EQUAL = 0x00020100, PROCESS_NAME_EQUAL = 0x00020200, PROCESS_NAME_PREFIX = 0x00020201, PROCESS_NAME_SUFFIX = 0x00020202 } | Defines the filter types. |
| SecurityAudit_AuthResult { SECURITY_AUDIT_AUTH_RESULT_ALLOW = 0, SECURITY_AUDIT_AUTH_RESULT_DENY = 1 } | Defines the authentication result types. |
| Name | Description |
|---|---|
| int32_t HMS_SecurityAudit_NewClient (SecurityAudit_Client **client, SecurityAudit_Handler handler) | Creates a notification event client. |
| int32_t HMS_SecurityAudit_DeleteClient (SecurityAudit_Client *client) | Deletes a notification event client. |
| int32_t HMS_SecurityAudit_Subscribe (const SecurityAudit_Client *client, const SecurityAudit_Notify_Event *events, uint64_t count) | Subscribes to notification events. |
| int32_t HMS_SecurityAudit_Unsubscribe (const SecurityAudit_Client *client, const SecurityAudit_Notify_Event *events, uint64_t count) | Unsubscribes from notification events. |
| int32_t HMS_SecurityAudit_AddFilter (const SecurityAudit_Client *client, SecurityAudit_Notify_Event event, const SecurityAudit_Filter *filter) | Adds a filter for a notification event. |
| int32_t HMS_SecurityAudit_RemoveFilter (const SecurityAudit_Client *client, SecurityAudit_Notify_Event event, const SecurityAudit_Filter *filter) | Deletes a filter of a notification event. |
| int32_t HMS_SecurityAudit_NewAuthClient (SecurityAudit_AuthClient **client, SecurityAudit_Handler handler) | Creates an authentication event client. (The default timeout action is to allow.) |
| int32_t HMS_SecurityAudit_NewAuthClientWithConfiguration (SecurityAudit_AuthClient **outOwnedClient, SecurityAudit_Handler handler, const SecurityAudit_AuthClientConfiguration *configuration) | Creates an authentication event client. (The default authentication policy upon timeout can be configured.) |
| int32_t HMS_SecurityAudit_CreateAuthClientConfiguration (SecurityAudit_AuthClientConfiguration **outOwnedConfiguration) | Creates a configuration object for an authentication event client. |
| int32_t HMS_SecurityAudit_DestroyAuthClientConfiguration (SecurityAudit_AuthClientConfiguration *configuration) | Destroys a configuration object of an authentication event client. |
| int32_t HMS_SecurityAudit_AuthClientConfiguration_SetTimeoutAuthResult (SecurityAudit_AuthClientConfiguration *configuration, SecurityAudit_AuthResult authResult) | Sets the default authorization result upon timeout. |
| int32_t HMS_SecurityAudit_DeleteAuthClient (SecurityAudit_AuthClient *client) | Deletes an authentication event client. |
| int32_t HMS_SecurityAudit_SubscribeAuthEvent (const SecurityAudit_AuthClient *client, const SecurityAudit_Auth_Event *events, uint64_t count) | Subscribes to authentication events. |
| int32_t HMS_SecurityAudit_UnsubscribeAuthEvent (const SecurityAudit_AuthClient *client, const SecurityAudit_Auth_Event *events, uint64_t count) | Unsubscribes from authentication events. |
| int32_t HMS_SecurityAudit_AddAuthEventFilter (const SecurityAudit_AuthClient *client, SecurityAudit_Auth_Event event, const SecurityAudit_Filter *filter) | Adds a filter for an authentication event. |
| int32_t HMS_SecurityAudit_RemoveAuthEventFilter (const SecurityAudit_AuthClient *client, SecurityAudit_Auth_Event event, const SecurityAudit_Filter *filter) | Deletes a filter of an authentication event. |
| int32_t HMS_SecurityAudit_Auth (const SecurityAudit_AuthClient *client, const SecurityAudit_Event *event, SecurityAudit_AuthResult authResult) | Sets the authentication result for an audit event. |
| int32_t HMS_SecurityAudit_QueryAllProcesses(char** result) | Obtains the information about all app processes. |
| int32_t HMS_SecurityAudit_QueryProcesses(uint64_t* pids, uint64_t count, char** result) | Obtains the information about app processes with the specified PIDs. |
| int32_t HMS_SecurityAudit_AcquireCodeSign(char* path, char** outOwnedResult) | Obtains the code signature information of the file specified by the input file path. |
| int32_t HMS_SecurityAudit_AcquireAllClientsInfo (char** outOwnedResult) | Obtains information about all notification clients. |
| int32_t HMS_SecurityAudit_AcquireAllAuthClientsInfo (char** outOwnedResult) | Obtains information about all authentication clients. |
- typedef struct SecurityAudit_AuthClient_Impl SecurityAudit_AuthClient
Description
Defines an authentication event client.
Since: 6.0.0(20)
- typedef struct SecurityAudit_Client_Impl SecurityAudit_Client
Description
Defines a notification event client.
Since: 6.0.0(20)
- typedef void(* SecurityAudit_Handler) (const SecurityAudit_Event *events, uint64_t count)
Description
Defines an event processing function.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| events | Pointer to audit event information. |
| count | Number of events in the array. |
- typedef struct SecurityAudit_AuthClientConfiguration_Impl SecurityAudit_AuthClientConfiguration
Description
Defines a configuration object for an authentication event client.
Since: 26.0.0
- enum SecurityAudit_Auth_Event
Description
Defines the authentication event IDs.
System capability: SystemCapability.Security.SecurityAudit
Since: 6.0.0(20)
| Enumerated Value | Description |
|---|---|
| SECURITY_AUDIT_AUTH_EVENT_FILE_CREATE | File creation authentication event. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_OPEN | File opening authentication event. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_RENAME | File renaming authentication event. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_DELETE | File deletion authentication event. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_SETEXTATTR | Authentication event for extended file attribute setting. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_DELETEEXTATTR | Authentication event for extended file attribute deletion. |
| SECURITY_AUDIT_AUTH_EVENT_FILE_READ_END | File read completion authentication event. Since: 26.0.0 |
| SECURITY_AUDIT_AUTH_EVENT_PROCESS_EXEC | Process execution authentication event. Since: 26.0.0 |
- enum SecurityAudit_AuthResult
Description
Defines the authentication result types.
Since: 6.0.0(20)
| Enumerated Value | Description |
|---|---|
| SECURITY_AUDIT_AUTH_RESULT_ALLOW | Event allowed. |
| SECURITY_AUDIT_AUTH_RESULT_DENY | Event rejected. |
- enum SecurityAudit_FilterType
Description
Defines the filter types.
System capability: SystemCapability.Security.SecurityAudit
Since: 6.0.0(20)
| Enumerated Value | Description |
|---|---|
| EVENT_TYPE_EQUAL | Event type filter. |
| EVENT_SUBTYPE_EQUAL | Event subtype filter. |
| FILE_PATH_EQUAL | File path filter. |
| FILE_PATH_PREFIX | File path prefix filter. |
| FILE_PATH_SUFFIX | File path suffix filter. |
| FILE_PATH_REGULAR | Filtering type of the file path regular expression. Since: 26.0.0 Model restriction: This API can be used only in the stage model. |
| PROCESS_UID_EQUAL | Process UID filter. |
| PROCESS_PID_EQUAL | Process ID filter. |
| PROCESS_NAME_EQUAL | Process name filter. |
| PROCESS_NAME_PREFIX | Process name prefix filter. |
| PROCESS_NAME_SUFFIX | Process name suffix filter. |
- enum SecurityAudit_Notify_Event
Description
Defines the notification event IDs.
System capability: SystemCapability.Security.SecurityAudit
Since: 6.0.0(20)
| Enumerated Value | Description |
|---|---|
| SECURITY_AUDIT_NOTIFY_EVENT_PASTEBOARD | Clipboard copy and paste events. |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE | File event. |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_INTERCEPTED | File access rule violation event. |
| SECURITY_AUDIT_NOTIFY_EVENT_ACCOUNT | Sign-in or sign-out event. |
| SECURITY_AUDIT_NOTIFY_EVENT_WINDOW | Screenshot, screen recording, or screen projection event. |
| SECURITY_AUDIT_NOTIFY_EVENT_VOLUME | Insertion or removal event of a removable storage device. |
| SECURITY_AUDIT_NOTIFY_EVENT_PRINTER | Printer event. |
| SECURITY_AUDIT_NOTIFY_EVENT_PROCESS | Process creation or exit event. |
| SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_TRAFFIC | Network traffic event. |
| SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_CONN | Network connection event. |
| SECURITY_AUDIT_NOTIFY_EVENT_CAMERA | Camera event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP | App event. |
| SECURITY_AUDIT_NOTIFY_EVENT_EDM | Enterprise device management event. |
| SECURITY_AUDIT_NOTIFY_EVENT_CERT | Certificate operation event. |
| SECURITY_AUDIT_NOTIFY_EVENT_KIA_CREATE | KIA file creation event. |
| SECURITY_AUDIT_NOTIFY_EVENT_KIA_READ | KIA file read event. |
| SECURITY_AUDIT_NOTIFY_EVENT_KIA_VARIANT | KIA file variation event. |
| SECURITY_AUDIT_NOTIFY_EVENT_KIA_INTERCEPT | KIA file interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_PERMISSION | App permission change event. |
| SECURITY_AUDIT_NOTIFY_EVENT_DNS | DNS audit event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP_INSTALL_INTERCEPTED | App installation interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP_UNINSTALL_INTERCEPTED | App uninstallation interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP_UPDATE_INTERCEPTED | App update interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP_RECOVER_INTERCEPTED | App recovery interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_APP_START_INTERCEPTED | App startup interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_USB_ACCESS_INTERCEPTED | USB access interception event. |
| SECURITY_AUDIT_NOTIFY_EVENT_SMB_FILE_SEND | SMB (Samba) outgoing event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_KIA_PRE_OPEN | KIA file quick-open event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_HDC_DEBUG | HarmonyOS Device Connector (HDC) debugging file event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_HDC_DEBUG_INTERCEPTED | HDC debugging interception event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_USER_SPACE_DATA_TRANSFER | Multi-user space data transfer event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_USER_SPACE_DATA_TRANSFER_POLICY | Multi-user space exchange review policy event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_SERIAL_PORT_ACCESS | Serial port access audit event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_NETWORK_INTERCEPTED | Network interception event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_WIFI_INTERCEPTED | Wi-Fi interception event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_PRINT_INTERCEPTED | Print interception event. Since: 6.1.0(23) |
| SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_PRIVILEGE_ESCALATION | Process privilege escalation event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_DEBUG_ABNORMAL | Process debugging error event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_FS_MOUNT_ABNORMAL | Abnormal system directory mounting event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_PROCESS_CRASH_ABNORMAL | Process crash event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_CS_VERIFY_NULL | Unsigned app code event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_CS_VERIFY_ABNORMAL | App code signature verification error event. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_DRIVER_CS_ABNORMAL | Event indicating a driver code signature verification error. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_DRIVER_MMAP_ABNORMAL | Event indicating driver illegally mapping kernel memory. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_KERNEL_MEMORY_ABNORMAL | Event indicating kernel memory abnormal usage. Since: 6.1.1(24) |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_SHARE | File share event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_DATA_DRAG | Data drag event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_DLP_FILE_ACCESS | DLP file access event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_CREATE | File create event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_OPEN | File open event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_CLOSE | File close event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_DELETE | File delete event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_RENAME | File rename event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_COPY | File copy event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETOWNER | File owner change event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETMODE | File mode change event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_SETEXTATTR | File extended attribute setting event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_DELETEEXTATTR | File extended attribute deletion event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_FILE_WRITE | File write event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_BLUETOOTH_INTERCEPTED | Bluetooth interception event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_DISC_BURNING | Disc burning event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_MEDIA_FILE_ACCESS | Media file access event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_ACCOUNT_MANAGEMENT | Account management event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_DEVICE_POWER_ON | Device power-on event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_DEVICE_POWER_OFF | Device power-off event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_AUDIO_INTERFACE_ACCESS | Audio interface access event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_VIDEO_INTERFACE_ACCESS | Video interface access event. Since: 26.0.0 |
| SECURITY_AUDIT_NOTIFY_EVENT_SERIAL_PORT_INTERCEPTED | Serial port interception event. Since: 26.0.0 |
- int32_t HMS_SecurityAudit_AddAuthEventFilter (const SecurityAudit_AuthClient * client, SecurityAudit_Auth_Event event, const SecurityAudit_Filter * filter )
Description
Adds a filter for an authentication event.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client that has been created. |
| event | Authentication event for which a filter is to be added. |
| filter | Authentication event filter description. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of filters exceeds the upper limit, 1012000004 is returned. If the event does not support the filter condition, 1012000005 is returned.
- int32_t HMS_SecurityAudit_AddFilter (const SecurityAudit_Client * client, SecurityAudit_Notify_Event event, const SecurityAudit_Filter * filter )
Description
Adds a filter for a notification event.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Notification event client that has been created. |
| event | Event for which a filter is to be added. |
| filter | Notification event filter description. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of filters exceeds the upper limit, 1012000004 is returned. If the event does not support the filter condition, 1012000005 is returned.
- int32_t HMS_SecurityAudit_Auth (const SecurityAudit_AuthClient * client, const SecurityAudit_Event * event, SecurityAudit_AuthResult authResult )
Description
Sets the authentication result for an audit event.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client that has been created. |
| event | Audit authentication event information. |
| authResult | Authentication result. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_DeleteAuthClient (SecurityAudit_AuthClient * client)
Description
Deletes an authentication event client.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client instance to be deleted. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_DeleteClient (SecurityAudit_Client * client)
Description
Deletes a notification event client.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Client instance to be deleted. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_NewAuthClient (SecurityAudit_AuthClient ** client, SecurityAudit_Handler handler )
Description
Creates an authentication event client.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Pointer to the new authentication event client instance. A maximum of two client instances can be created for a process, and a maximum of 16 client instances can be created for a device. A maximum of 256 positive filter values and 256 negative filter values can be set for a client instance. |
| handler | Handler that processes all messages sent to the client. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of clients exceeds the system-wide upper limit, 1012000002 is returned. If the number of clients exceeds the upper limit of the current process, 1012000003 is returned.
- int32_t HMS_SecurityAudit_NewClient (SecurityAudit_Client ** client, SecurityAudit_Handler handler )
Description
Creates a notification event client.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Pointer to the new client instance. |
| handler | Handler that processes all messages sent to the client. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of clients exceeds the system-wide upper limit, 1012000002 is returned. If the number of clients exceeds the upper limit of the current process, 1012000003 is returned.
- int32_t HMS_SecurityAudit_RemoveAuthEventFilter (const SecurityAudit_AuthClient * client, SecurityAudit_Auth_Event event, const SecurityAudit_Filter * filter )
Description
Deletes a filter of an authentication event.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client that has been created. |
| event | Authentication event for which a filter is to be deleted. |
| filter | Authentication event filter description. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the event does not support the filter condition, 1012000005 is returned.
- int32_t HMS_SecurityAudit_RemoveFilter (const SecurityAudit_Client * client, SecurityAudit_Notify_Event event, const SecurityAudit_Filter * filter )
Description
Deletes a filter of a notification event.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Notification event client that has been created. |
| event | Event for which a filter is to be deleted. |
| filter | Notification event filter description. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the event does not support the filter condition, 1012000005 is returned.
- int32_t HMS_SecurityAudit_Subscribe (const SecurityAudit_Client * client, const SecurityAudit_Notify_Event * events, uint64_t count )
Description
Subscribes to notification events.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Client that subscribes to notification events. |
| events | Array of notification events to be subscribed to. |
| count | Number of notification events in the array. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_SubscribeAuthEvent (const SecurityAudit_AuthClient * client, const SecurityAudit_Auth_Event * events, uint64_t count )
Description
Subscribes to authentication events.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client that has been created. |
| events | Array of authentication events to be subscribed to. |
| count | Number of authentication events in the array. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_Unsubscribe (const SecurityAudit_Client * client, const SecurityAudit_Notify_Event * events, uint64_t count )
Description
Unsubscribes from notification events.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Client that unsubscribes from notification events. |
| events | Array of notification events to be unsubscribed from. |
| count | Number of notification events in the array. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_UnsubscribeAuthEvent (const SecurityAudit_AuthClient * client, const SecurityAudit_Auth_Event * events, uint64_t count )
Description
Unsubscribes from authentication events.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| client | Authentication event client that has been created. |
| events | Array of authentication events to be unsubscribed from. |
| count | Number of authentication events in the array. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_QueryAllProcesses(char** result)
Description
Queries the information about all app processes.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| result | Obtained app process information. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_QueryProcesses(uint64_t* pids, uint64_t count, char** result)
Description
Queries the information about app processes with the specified PIDs.
Since: 6.0.0(20)
Parameters:
| Name | Description |
|---|---|
| pids | Array of PIDs to be queried. |
| count | Number of PIDs in the array to be queried. |
| result | Obtained app process information. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of PIDs in the array to be queried exceeds the upper limit, 1012000006 is returned.
- int32_t HMS_SecurityAudit_AcquireCodeSign(char* path, char** outOwnedResult)
Description
Obtains the code signature information of the file specified by the input file path.
Model restriction: This API can be used only in the stage model.
Since: 6.1.1(24)
Parameters:
| Name | Description |
|---|---|
| path | Path of the file to be queried. |
| outOwnedResult | Code signature, which is a JSON string. Example: {"1": {}}. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the file is not found or the app does not have permission to open the file, 1012000008 is returned.
- int32_t HMS_SecurityAudit_AcquireAllClientsInfo(char** outOwnedResult)
Description
Obtains information about all notification clients.
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| outOwnedResult | Obtained information about all notification clients. |
Required permission:
ohos.permission.QUERY_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_CreateAuthClientConfiguration(SecurityAudit_AuthClientConfiguration** outOwnedConfiguration)
Description
Creates a configuration object for an authentication event client.
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| outOwnedConfiguration | Pointer to the created configuration object. |
Returns:
Function execution result. If the operations are successful, 0 is returned. If an internal error occurs, 1012000001 is returned.
Instructions:
The created configuration object needs to be released via HMS_SecurityAudit_DestroyAuthClientConfiguration.
- int32_t HMS_SecurityAudit_DestroyAuthClientConfiguration(SecurityAudit_AuthClientConfiguration* configuration)
Description
Destroys a configuration object of an authentication event client.
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| configuration | Configuration object to be destroyed. |
Returns:
Function execution result. If the operations are successful, 0 is returned.
- int32_t HMS_SecurityAudit_AuthClientConfiguration_SetTimeoutAuthResult(SecurityAudit_AuthClientConfiguration* configuration, SecurityAudit_AuthResult authResult)
Description
Sets the default authentication result upon timeout.
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| configuration | Configuration object of an authentication event client. |
| authResult | Default authorization result upon timeout. |
Returns:
Function execution result. If the operations are successful, 0 is returned. If an internal error occurs, 1012000001 is returned.
- int32_t HMS_SecurityAudit_NewAuthClientWithConfiguration(SecurityAudit_AuthClient** outOwnedClient, SecurityAudit_Handler handler, const SecurityAudit_AuthClientConfiguration* configuration)
Description
Creates an authentication event client. (The default authentication policy upon timeout can be configured.)
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| outOwnedClient | Pointer to the new authentication event client instance. |
| handler | Handler that processes all messages sent to the client. |
| configuration | Authentication event client configuration object, which is used to configure the default authentication policy upon timeout. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned. If the number of clients exceeds the system-wide upper limit, 1012000002 is returned. If the number of clients exceeds the upper limit of the current process, 1012000003 is returned. If the configuration is invalid, 1012000004 is returned.
- int32_t HMS_SecurityAudit_AcquireAllAuthClientsInfo(char** outOwnedResult)
Description
Obtains information about all authentication clients.
Since: 26.0.0
Parameters:
| Name | Description |
|---|---|
| outOwnedResult | Obtained information about all authentication clients. |
Required permission:
ohos.permission.kernel.AUTH_AUDIT_EVENT
Returns:
Function execution result. If the operations are successful, 0 is returned. If the permission verification fails, 201 is returned. If an internal error occurs, 1012000001 is returned.