public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: audit 2.6.7 released
Date: Sun, 11 Sep 2016 12:01:17 -0400	[thread overview]
Message-ID: <2098726.LselAvMJSq@x2> (raw)

Hello,

I've just released a new version of the audit daemon. It can be downloaded 
from http://people.redhat.com/sgrubb/audit. It will also be in rawhide
soon. The ChangeLog is:

- Non-active log files should be read only
- In augenrules, restore the selinux context if restorecon is installed
- Update gitignore file and remove ltmain.sh (Richard Guy Briggs)
- Replace Group Separator with whitespace in syslog audispd plugin
- In auditd, check for euid rather than capabilities when local_events = no
- If events are piped from ausearch to audisp-remote, flush queue when done
- In auditctl, correct handling of -F key so that key is not part of value
- In auparse, move static variables to auparse_state_t

This update is probably the last of the 2.6 series. New development will begin 
aiming new features towards a future 2.7 release. 

This update fixes the file permissions on non-active logs. Augenrules now 
restores the selinux context of the rules file. This is only an issue for MLS 
systems. The Group Separator used in enriched events has been replaced by a 
whitespace character for syslog.

When auditd is run from some containers that does not support audit 
collection, it also runs auditd unprivileged. This makes auditd fail so it 
switches to doing euid checks for this scenario.

It was also found that the very last record was not being sent when a file was 
cat'ed into audisp-remote for remote collection. It now handles this 
correctly.

And it was found that a bug was introduced in the 2.6.6 release where support 
for multi-keys was fixed. It was also sending the field name into the kernel 
when doing syscall rules with keys.

Please let me know if you run across any problems with this release.

-Steve

                 reply	other threads:[~2016-09-11 16:01 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2098726.LselAvMJSq@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox