public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* audit-2.1.3 released
@ 2011-08-15 18:10 Steve Grubb
  2011-08-16  9:56 ` Mr Dash Four
  0 siblings, 1 reply; 3+ messages in thread
From: Steve Grubb @ 2011-08-15 18:10 UTC (permalink / raw)
  To: linux-audit

Hi,

I've just released a new version of the audit daemon. It can be downloaded 
from http://people.redhat.com/sgrubb/audit. It will also be in rawhide  
soon. The ChangeLog is:

- Fix parsing of EXECVE records to not escape argc field
- If auditd's disk is full, send the right reason to client (#715315)
- Add CAP_WAKE_ALARM to interpretations
- Some updates to audisp-remote's remote-fgets function (Mirek Trmac)
- Add detection of TTY events to audisp-prelude (Matteo Sessa)
- Updated syscall tables for the 3.0 kernel
- Update linker flags for better relro support
- Make default size of logs bigger (#727310)
- Extract obj from NETFILTER_PKT events
- Disable 2 kerberos config options in audisp-remote.conf

This update is mostly parser and remote logging fixes. The syscall table was also 
updated for the 3.0 kernel and the resulting files were hardened further with gcc 
linker flags.

Please let me know if you run across any problems with this release.

-Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: audit-2.1.3 released
  2011-08-15 18:10 audit-2.1.3 released Steve Grubb
@ 2011-08-16  9:56 ` Mr Dash Four
  2011-08-16 12:03   ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Mr Dash Four @ 2011-08-16  9:56 UTC (permalink / raw)
  To: Steve Grubb; +Cc: linux-audit


> - Extract obj from NETFILTER_PKT events
>   
Would this allow filtering with ausearch/aureport based on the obj value 
(something which was impossible until now)?

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: audit-2.1.3 released
  2011-08-16  9:56 ` Mr Dash Four
@ 2011-08-16 12:03   ` Steve Grubb
  0 siblings, 0 replies; 3+ messages in thread
From: Steve Grubb @ 2011-08-16 12:03 UTC (permalink / raw)
  To: Mr Dash Four; +Cc: linux-audit

On Tuesday, August 16, 2011 05:56:41 AM Mr Dash Four wrote:
> > - Extract obj from NETFILTER_PKT events
> 
> Would this allow filtering with ausearch/aureport based on the obj value 
> (something which was impossible until now)?

That is the intent.

-Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2011-08-16 12:03 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-08-15 18:10 audit-2.1.3 released Steve Grubb
2011-08-16  9:56 ` Mr Dash Four
2011-08-16 12:03   ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox