From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com, Manuel Scunthorpe <u7181-wlodsazi@yahoo.co.uk>
Subject: Re: audit 2.5.1 released
Date: Mon, 09 May 2016 10:01:26 -0400 [thread overview]
Message-ID: <2117655.doZgnVdfSe@x2> (raw)
In-Reply-To: <543804231.8112760.1462051758161.JavaMail.yahoo@mail.yahoo.com>
On Saturday, April 30, 2016 09:29:18 PM Manuel Scunthorpe wrote:
> Dear Steve,thanks for your helpful observations. I was able to modify the
> PKGBUILD and successfully build the package, and then build e4rat-lite
> which was my ultimate aim. Sadly it didn't seem to work in Arch Linux due
> to the kernel config options, e4rat-lite-collect didn't collect anything,
> complained about being unable to log anything due to a bad file descriptor
> and there was a message at boot saying Cannot open audit socket, which was
> similar to what auditctl said in the terminal. Of course it might work and
> I've got something else wrong, it doesn't look encouraging though without
> CONFIG_AUDIT enabled. But I was just looking at my Void Linux kernel
> options:CONFIG_AUDIT=y CONFIG_HAVE_ARCH_AUDITSYSCALL=y
> CONFIG_AUDITSYSCALL=y
> CONFIG_AUDIT_WATCH=y
> CONFIG_AUDIT_TREE=y
> This looks more promising so I will have to try it here instead sometime,
> although what I will have to build to fulfill the various builddeps I don't
> yet know. Would it be OK if I tried to make an 'audit' package for Void
> Linux if they want one?
Sure.
> There isn't one in the repo at present, so if I get
> a working build then I might as well share it. It could take a while to get
> to that point though, and that's assuming I can get everything to work in
> Void and don't end up using some other readahead utility altogether or
> accidentally corrupting my filesystem. But I can be happy I'm building
> audit correctly now.I will try and pass on your comments about zos servers
> and openldap-devel to the Arch packagers as I can only take credit for the
> confusion over the systemd support option in my earlier PKGBUILD.
>
> Here's my successful modified PKGBUILD with the correct checksum for 2.5.1,
> which downloads and builds cleanly:# Edit /etc/makepkg.conf: staticlibs not
> !staticlibs or they are deleted by makepkg.
>
> # $Id: PKGBUILD 146469 2015-11-10 05:04:55Z thestinger $
> # Maintainer: Daniel Micay <danielmicay@gmail.com>
> # Contributor: <kang@insecure.ws>
> # Contributor: Massimiliano Torromeo <massimiliano.torromeo@gmail.com>
> # Contributor: Connor Behan <connor.behan@gmail.com>
> # Contributor: henning mueller <henning@orgizm.net>
>
> pkgname=audit
> pkgver=2.5.1
> pkgrel=1
> pkgdesc='Userspace components of the audit framework'
> url='https://people.redhat.com/sgrubb/audit'
> arch=(i686 x86_64)
> depends=(krb5 libcap-ng)
> makedepends=(libldap swig linux-headers python)
You can drop libldap since you disable zos support below. Its harmless as is
but not necessary for the configure options below.
-Steve
> license=(GPL)
> options=(emptydirs)
> groups=('modified')
> backup=(
> etc/libaudit.conf
> etc/audit/auditd.conf
> etc/audisp/audispd.conf
> etc/audisp/audisp-remote.conf
> etc/audisp/plugins.d/af_unix.conf
> etc/audisp/plugins.d/au-remote.conf
> etc/audisp/plugins.d/syslog.conf
> )
> source=("$url/$pkgname-$pkgver.tar.gz")
> sha256sums=('3c6ec72d8c16d1e85cc2b9c260cc6440319eb294cb54ca41a7bbe9283cc9f42
> 1') install=$pkgname.install
>
> build() {
> cd $pkgname-$pkgver
> export PYTHON=/usr/bin/python3
> ./configure \
> --prefix=/usr \
> --sbindir=/usr/bin \
> --sysconfdir=/etc \
> --libexecdir=/usr/lib/audit \
> --with-python=yes \
> --enable-gssapi-krb5=yes \
> --enable-systemd=no \
> --with-libcap-ng=yes \
> --disable-zos-remote \
> --enable-static=yes
> make
> }
>
> package() {
> cd $pkgname-$pkgver
> make DESTDIR="$pkgdir" install
>
> cd "$pkgdir"
> install -d var/log/audit
> rm -rf etc/rc.d etc/sysconfig usr/lib/audit
>
> sed -ri 's|/sbin|/usr/bin|' \
> etc/audit/*.conf \
> etc/audisp/plugins.d/*.conf
next prev parent reply other threads:[~2016-05-09 14:01 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <543804231.8112760.1462051758161.JavaMail.yahoo.ref@mail.yahoo.com>
2016-04-30 21:29 ` audit 2.5.1 released Manuel Scunthorpe
2016-05-09 14:01 ` Steve Grubb [this message]
[not found] <176682998.5729077.1461811556032.JavaMail.yahoo.ref@mail.yahoo.com>
2016-04-28 2:45 ` Manuel Scunthorpe
2016-04-28 16:18 ` Steve Grubb
2016-04-13 20:01 Steve Grubb
2016-04-13 20:07 ` Warron S French
2016-04-13 20:17 ` Steve Grubb
2016-04-13 21:05 ` Warron S French
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2117655.doZgnVdfSe@x2 \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
--cc=u7181-wlodsazi@yahoo.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.