From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: audit-2.2.1 released
Date: Fri, 23 Mar 2012 09:26:07 -0400 [thread overview]
Message-ID: <201203230926.07478.sgrubb@redhat.com> (raw)
Hi,
I've just released a new version of the audit daemon. It can be downloaded
from http://people.redhat.com/sgrubb/audit. It will also be in rawhide
soon. The ChangeLog is:
- Add more interpretations in auparse for syscall parameters
- Add some interpretations to ausearch for syscall parameters
- In ausearch/report and auparse, allocate extra space for node names
- Update syscall tables for the 3.3.0 kernel
- Update libev to 4.0.4
- Reduce the size of some applications
- In auditctl, check usage against euid rather than uid
As I mentioned in another email, one of the best features of this release is
that for ausearch a little over 40 common syscalls can now have some of their
arguments interpreted. This means that if you are doing an investigation and you
needed to know what flags was being passed, it will now tell you. If the
arguments to the syscall involve uid's or gid's, they are now resolves to the
account name. Also in the interpreted mode, a 0x is prefixed to all syscall
arguments that are not interpreted as a visual reminder that the numbers are in
hex.
This also contains an important bug fix where all records of a single event could
not be grouped if the records contained a node name that was modest or large in
size. All other changes in this release are self explanatory.
Please let me know if you run across any problems with this release.
-Steve
reply other threads:[~2012-03-23 13:26 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201203230926.07478.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox