From Victor.Nelson@sun.com Mon Sep 15 11:26:43 2008
Date: Mon, 15 Sep 2008 11:30:37 -0700
From: Victor Nelson <Victor.Nelson@sun.com>
Subject: Re: Audit contract for NWAM Picea
To: Gary Winiger <gww@eng.sun.com>
Cc: Craig.Payne@sun.com, james.d.carlson@east.sun.com, gww@marduk.eng.sun.com
Content-transfer-encoding: 7BIT
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)

I approve.  (Sorry, I thought I had already sent such an email, but it 
seems I hadn't.)

Victor

From Craig.Payne@sun.com Mon Sep  8 11:01:09 2008
Date: Mon, 08 Sep 2008 11:04:55 -0700
From: Craig Payne <Craig.Payne@sun.com>
Subject: Re: Audit contract for NWAM Picea
To: Gary Winiger <gww@eng.sun.com>
Cc: Victor.Nelson@sun.com, james.d.carlson@east.sun.com,
	gww@marduk.eng.sun.com
Content-transfer-encoding: 7BIT
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)

Approved.

cap

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
@(#)contract	1.8 @(#) /shared/sac/arc/ARC-Templates/contract [1.8 06/12/06]

	CONTRACT ALLOWING/REQUIRING SPECIAL ARRANGEMENTS FOR INTERFACES

0.  Number: PSARC/2000/517-17

1.  This contract is between
	a SUPPLIER of INTERFACES and
	a CONSUMER of those INTERFACES,
    both of whom are entities within Sun Microsystems, Incorporated.

2.  The SUPPLIER (definer and/or implementor) is identified by the following:
    Product or Bundle:		Solaris Audit
    Consolidation:		ON
    Department or Group:	Solaris Security
    Bugster Product/Category/SubCategory: solaris/c2_bsm/other
    Responsible Manager:	Craig Payne

3.  The CONSUMER is identified by the following:
    Product or Bundle:		Solaris
    Consolidation:		ON
    Department or Group:	Solaris Networking
    Bugster Product/Category/SubCategory: solaris/network/config
    Responsible Manager:	Victor Nelson

4.  The INTERFACES are:
    A. The Project Private header files <bsm/adt.h> and <bsm/adt_event.h>
    B. The Project Private adt.h interfaces and symbols:
	adt_start_session(, NULL, 0);
	adt_set_from_ucred(, , ADT_NEW);
	adt_end_session();
	adt_alloc_event();
	adt_free_event();
	adt_put_event(, [ADT_SUCCESS for success | ADT_FAIL for error],
	    [ADT_SUCCESS for success | ADT_FAIL_VALUE_AUTH for error]);
    C. The Project Private adt_event.h audit events and symbols:
	ADT_nwam_attach
	    with required char * member auth_used
	ADT_nwam_detach
	    AUE_generic_basic instance	

5.  The ARC controlling these INTERFACES is: PSARC

6.  The CASE describing (Exporting) these INTERFACES is: 2000/517 and 2003/397

7.  The following SPECIAL ARRANGEMENTS are made which modify the rules
    imposed by the stability levels listed in section 4 above:
 
_N_ 7a. Although the stability level doesn't normally restrict it,
        SUPPLIER promises to only modify INTERFACES in an incompatible
	way as follows:

_N_ 7b. Although the stability level doesn't normally allow it, CONSUMER will
        expose INTERFACES to a PARTNER, which is external to Sun, namely:
		Name of Company:
		Name of Department or Group within Company:
		Responsible Manager:

_N_ 7c. Although the stability level doesn't normally allow it, CONSUMER will
        import INTERFACES from a separate consolidation.

_N_ 7d. If SUPPLIER decides to change (including replace or remove) any
	portion of the INTERFACES, SUPPLIER will notify CONSUMER of the
	proposed new version, no later than the application for ARC
	approval of the new version.
	If SUPPLIER and CONSUMER are contained in the same consolidation,
	they have the option of arranging for simultaneous conversion
	to the new interfaces.  If this is not possible, or if they are
	not in the same consolidation, then SUPPLIER will either make best
	effort to work with CONSUMER so that CONSUMER can detect which
	version of INTERFACES is being supplied, or else SUPPLIER will
	make best effort to supply both old and new versions of
	INTERFACES.
	If SUPPLIER cannot make both versions of INTERFACES available,
	and SUPPLIER and CONSUMER cannot devise a method whereby
	CONSUMER can detect which version of INTERFACES is being
	supplied, and the old version of CONSUMER will not run with the
	new version of SUPPLIER, then either the EOL process must be
	followed by SUPPLIER, or else a major release of SUPPLIER will
	be required, or the change will not be allowed.

8. If CONSUMER requires changes in INTERFACES, SUPPLIER will make
   best effort to accommodate such changes, which shall then be
   treated in accordance with paragraph 7 above.

9. Notwithstanding paragraphs 7 and 8, a change to any portion
   of the INTERFACES shall be regarded as a completely new set of
   INTERFACES which require both ARC approval and execution of
   a new contract.

10. SUPPLIER and CONSUMER agree that evolution of INTERFACES shall be
    handled as follows:

    SUPPLIER will notify CONSUMER of changes that may affect the CONSUMER
    not less than two ON consolidation builds before the changes are
    integrated.
    CONSUMER may request changes to the INTERFACES by filing RFEs using
    the Bugster Product/Category/SubCategory specified in paragraph 2.
    The SUPPLIER will review the CONSUMER's RFEs based on their priority
    and severity and either accept them in the normal queue of work or notify
    the CONSUMER through the normal Bugster process that the request has been
    rejected and rationale for the rejection.

11. SUPPLIER and CONSUMER agree that INTERFACES will be supported as
    follows:

    The CONSUMER may submit bugs against the interfaces using the Bugster
    Product/Category/SubCategory specified in paragraph 2.  The SUPPLIER
    will fix bugs based on their priority and severity.

12. SUPPLIER and CONSUMER agree that INTERFACES will be documented as
    follows:

    In the supplied <bsm/adt.h> and <bsm/adt_event.h> header files and
    in the case directory:

    PSARC/2000/517/latest.docs/*3BSM

13. SUPPLIER and CONSUMER agree that changes to the INTERFACES will be
    tested as follows:

    The SUPPLIER will do initial unit testing.  The CONSUMER will create
    an audit trail or trails with each of the audit events generated.
    The CONSUMER will provide the output from bsmrecord(1M) for each
    audit event defined in paragraph 4 C.
    The SUPPLIER will verify the audit records are correctly generated.
    The SUPPLIER will verify the bsmrecord output is correctly generated.

14. SUPPLIER and CONSUMER agree that this contract can be terminated as
    follows:

    By agreement of both parties.

15. This contract is not valid until "signed" via agreement from the
    SUPPLIER and CONSUMER, and approved by the ARC CASE referenced by
    this contract.  E-mail agreement to the contract should be archived
    in the mail archive of CASE; verbal agreement to the contract
    should be noted in the meeting minutes.  This contract remains
    valid until superseded or invalidated.

For SUPPLIER:	Craig Payne	Date:  8 Sept 2008
For CONSUMER:	Victor Nelson	Date: 15 Sept 2008
For ARC:	Gary Winiger	Date: 15 Sept 2008

    A copy of this contract shall be deposited in the CASE directory as
    "contract-17" or in a "contracts" subdirectory.

16. (Not to be filled in until superseded or invalidated.)
    This contract was superseded or invalidated by CASE:
    For ARC:			Date:
