#include <sys/kern_event.h>

sys/kern_event.h

@header kern_event.h This header defines in-kernel functions for generating kernel events as well as functions for receiving kernel events using a kernel event socket.
includes: sys/appleapiopts.h, sys/ioccom.h, sys/sys_domain.h
23 macros · 3 structs

macroSYS_KERN_EVENT_H

#define SYS_KERN_EVENT_H 

macroKEV_SNDSPACE

#define KEV_SNDSPACE (4 * 1024)

macroKEV_RECVSPACE

#define KEV_RECVSPACE (32 * 1024)

macroKEV_ANY_VENDOR

#define KEV_ANY_VENDOR 0

macroKEV_ANY_CLASS

#define KEV_ANY_CLASS 0

macroKEV_ANY_SUBCLASS

#define KEV_ANY_SUBCLASS 0

macroKEV_VENDOR_APPLE

@defined KEV_VENDOR_APPLE @discussion Apple generated kernel events use the hard coded vendor code value of 1. Third party kernel events use a dynamically allocated vendor code. The vendor code can be found using the SIOCGKEVVENDOR ioctl.
#define KEV_VENDOR_APPLE 1

macroKEV_NETWORK_CLASS

@defined KEV_NETWORK_CLASS @discussion Network kernel event class.
#define KEV_NETWORK_CLASS 1

macroKEV_IOKIT_CLASS

@defined KEV_IOKIT_CLASS @discussion IOKit kernel event class.
#define KEV_IOKIT_CLASS 2

macroKEV_SYSTEM_CLASS

@defined KEV_SYSTEM_CLASS @discussion System kernel event class.
#define KEV_SYSTEM_CLASS 3

macroKEV_APPLESHARE_CLASS

@defined KEV_APPLESHARE_CLASS @discussion AppleShare kernel event class.
#define KEV_APPLESHARE_CLASS 4

macroKEV_FIREWALL_CLASS

@defined KEV_FIREWALL_CLASS @discussion Firewall kernel event class.
#define KEV_FIREWALL_CLASS 5

macroKEV_IEEE80211_CLASS

@defined KEV_IEEE80211_CLASS @discussion IEEE 802.11 kernel event class.
#define KEV_IEEE80211_CLASS 6

macroKEV_NKE_CLASS

@defined KEV_NKE_CLASS @discussion NKE kernel event class.
#define KEV_NKE_CLASS 7

macroKEV_NKE_ALF_SUBCLASS

#define KEV_NKE_ALF_SUBCLASS 1

macroKEV_NKE_ALF_STATE_CHANGED

#define KEV_NKE_ALF_STATE_CHANGED 1

macroXNU_KERN_EVENT_DATA_SIZE

#define XNU_KERN_EVENT_DATA_SIZE 1

structkern_event_msg

@struct kern_event_msg @discussion This structure is prepended to all kernel events. This structure is used to determine the format of the remainder of the kernel event. This structure will appear on all messages received on a kernel event socket. To post a kernel event, a slightly different structure is used. @field total_size Total size of the kernel event message including the header. @field vendor_code The vendor code indicates which vendor generated the kernel event. This gives every vendor a unique set of classes and subclasses to use. Use the SIOCGKEVVENDOR ioctl to look up vendor codes for vendors other than Apple. Apple uses KEV_VENDOR_APPLE. @field kev_class The class of the kernel event. @field kev_subclass The subclass of the kernel event. @field id Monotonically increasing value. @field event_code The event code. @field event_data Any additional data about this event. Format will depend on the vendor_code, kev_class, kev_subclass, and event_code. The length of the event_data can be determined using total_size - KEV_MSG_HEADER_SIZE.
size 28, align 4
u_int32_ttotal_sizeSize of entire event msg
u_int32_tvendor_codeFor non-Apple extensibility
u_int32_tkev_classLayer of event source
u_int32_tkev_subclassComponent within layer
u_int32_tidMonotonically increasing value
u_int32_tevent_codeunique code
u_int32_t[1]event_dataOne or more data words

macroKEV_MSG_HEADER_SIZE

@defined KEV_MSG_HEADER_SIZE @discussion Size of the header portion of the kern_event_msg structure. This accounts for everything right up to event_data. The size of the data can be found by subtracting KEV_MSG_HEADER_SIZE from the total size from the kern_event_msg.
#define KEV_MSG_HEADER_SIZE (offsetof(struct kern_event_msg, event_data[0]))

structkev_request

@struct kev_request @discussion This structure is used with the SIOCSKEVFILT and SIOCGKEVFILT to set and get the control filter setting for a kernel control socket. @field total_size Total size of the kernel event message including the header. @field vendor_code All kernel events that don't match this vendor code will be ignored. KEV_ANY_VENDOR can be used to receive kernel events with any vendor code. @field kev_class All kernel events that don't match this class will be ignored. KEV_ANY_CLASS can be used to receive kernel events with any class. @field kev_subclass All kernel events that don't match this subclass will be ignored. KEV_ANY_SUBCLASS can be used to receive kernel events with any subclass.
size 12, align 4
u_int32_tvendor_code
u_int32_tkev_class
u_int32_tkev_subclass

macroKEV_VENDOR_CODE_MAX_STR_LEN

@defined KEV_VENDOR_CODE_MAX_STR_LEN @discussion This define sets the maximum length of a string that can be used to identify a vendor or kext when looking up a vendor code.
#define KEV_VENDOR_CODE_MAX_STR_LEN 200

structkev_vendor_code

@struct kev_vendor_code @discussion This structure is used with the SIOCGKEVVENDOR ioctl to convert from a string identifying a kext or vendor, in the form of a bundle identifier, to a vendor code. @field vendor_code After making the SIOCGKEVVENDOR ioctl call, this will be filled in with the vendor code if there is one. @field vendor_string A bundle style identifier.
size 204, align 4
u_int32_tvendor_code
char[200]vendor_string

macroSIOCGKEVID

@defined SIOCGKEVID @discussion Retrieve the current event id. Each event generated will have a new id. The next event to be generated will have an id of id+1.
#define SIOCGKEVID _IOR('e', 1, u_int32_t)

macroSIOCSKEVFILT

@defined SIOCSKEVFILT @discussion Set the kernel event filter for this socket. Kernel events not matching this filter will not be received on this socket.
#define SIOCSKEVFILT _IOW('e', 2, struct kev_request)

macroSIOCGKEVFILT

@defined SIOCGKEVFILT @discussion Retrieve the kernel event filter for this socket. Kernel events not matching this filter will not be received on this socket.
#define SIOCGKEVFILT _IOR('e', 3, struct kev_request)

macroSIOCGKEVVENDOR

@defined SIOCGKEVVENDOR @discussion Lookup the vendor code for the specified vendor. ENOENT will be returned if a vendor code for that vendor string does not exist.
#define SIOCGKEVVENDOR _IOWR('e', 4, struct kev_vendor_code)