public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Loulwa Salem <loulwas@us.ibm.com>
To: Steve Grubb <sgrubb@redhat.com>
Cc: linux-audit@redhat.com
Subject: Re: Problem with audit
Date: Fri, 21 Apr 2006 10:30:49 -0500	[thread overview]
Message-ID: <4448FAA9.4040907@us.ibm.com> (raw)
In-Reply-To: <200604211101.07115.sgrubb@redhat.com>

[-- Attachment #1: Type: text/plain, Size: 185 bytes --]

Steve Grubb wrote:

> I guess not. Can you send me an strace output during the problem. FWIW, it 
> works fine on my machine.

sure .. I'm attaching the strace output.

Thanks,
-Loulwa

[-- Attachment #2: trace-bad.txt --]
[-- Type: text/plain, Size: 3624 bytes --]

[root@xracer2 ~]# strace auditctl -l
execve("/sbin/auditctl", ["auditctl", "-l"], [/* 22 vars */]) = 0
brk(0)                                  = 0x514000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaaab000
uname({sys="Linux", node="xracer2.ltc.austin.ibm.com", ...}) = 0
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
open("/etc/ld.so.cache", O_RDONLY)      = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=78437, ...}) = 0
mmap(NULL, 78437, PROT_READ, MAP_PRIVATE, 3, 0) = 0x2aaaaaaac000
close(3)                                = 0
open("/lib64/libpthread.so.0", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360W\300"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=115944, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac0000
mmap(0x38bec00000, 1131368, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x38bec00000
mprotect(0x38bec10000, 1044480, PROT_NONE) = 0
mmap(0x38bed0f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xf000) = 0x38bed0f000
mmap(0x38bed11000, 13160, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x38bed11000
close(3)                                = 0
open("/lib64/libc.so.6", O_RDONLY)      = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 \321\341"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1580600, ...}) = 0
mmap(0x38bae00000, 2334888, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x38bae00000
mprotect(0x38baf32000, 1044480, PROT_NONE) = 0
mmap(0x38bb031000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x131000) = 0x38bb031000
mmap(0x38bb036000, 16552, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x38bb036000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac1000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2aaaaaac2000
arch_prctl(ARCH_SET_FS, 0x2aaaaaac1870) = 0
mprotect(0x38bed0f000, 4096, PROT_READ) = 0
mprotect(0x38bb031000, 16384, PROT_READ) = 0
mprotect(0x38bad19000, 4096, PROT_READ) = 0
munmap(0x2aaaaaaac000, 78437)           = 0
set_tid_address(0x2aaaaaac1900)         = 2301
rt_sigaction(SIGRTMIN, {0x38bec053b0, [], SA_RESTORER|SA_SIGINFO, 0x38bec0cce0}, NULL, 8) = 0
rt_sigaction(SIGRT_1, {0x38bec05310, [], SA_RESTORER|SA_RESTART|SA_SIGINFO, 0x38bec0cce0}, NULL, 8) = 0
rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
getrlimit(RLIMIT_STACK, {rlim_cur=10240*1024, rlim_max=RLIM_INFINITY}) = 0
_sysctl({{CTL_KERN, KERN_VERSION}, 2, 0x7fffde654ce0, 35, (nil), 0}) = 0
getuid()                                = 0
socket(PF_NETLINK, SOCK_RAW, 9)         = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
sendto(3, "\20\0\0\0\365\3\5\0\1\0\0\0\0\0\0\0", 16, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 16
poll([{fd=3, events=POLLIN, revents=POLLIN}], 1, 100) = 1
recvfrom(3, "$\0\0\0\2\0\0\0\1\0\0\0\375\10\0\0\377\377\377\377\20\0"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36
recvfrom(3, "$\0\0\0\2\0\0\0\1\0\0\0\375\10\0\0\377\377\377\377\20\0"..., 8476, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36
write(2, "Error sending rule list request "..., 57Error sending rule list request (Operation not permitted)) = 57
write(2, "\n", 1
)                       = 1
close(3)                                = 0
exit_group(0)                           = ?
Process 2301 detached
[root@xracer2 ~]#

[-- Attachment #3: Type: text/plain, Size: 0 bytes --]



  reply	other threads:[~2006-04-21 15:30 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-04-20 23:06 Problem with audit Loulwa Salem
2006-04-20 23:12 ` Steve Grubb
2006-04-20 23:26   ` Loulwa Salem
2006-04-21 11:07     ` Steve Grubb
2006-04-21 14:27       ` Loulwa Salem
2006-04-21 15:01         ` Steve Grubb
2006-04-21 15:30           ` Loulwa Salem [this message]
2006-04-21 19:48             ` Steve Grubb
2006-04-21 14:37       ` Loulwa Salem

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4448FAA9.4040907@us.ibm.com \
    --to=loulwas@us.ibm.com \
    --cc=linux-audit@redhat.com \
    --cc=sgrubb@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox