Bug 1257650

Summary: Rebase audit package
Product: Red Hat Enterprise Linux 6 Reporter: Steve Grubb <sgrubb>
Component: auditAssignee: Steve Grubb <sgrubb>
Status: CLOSED ERRATA QA Contact: Ondrej Moriš <omoris>
Severity: medium Docs Contact: Robert Krátký <rkratky>
Priority: high    
Version: 6.7CC: bryanlharris, ksrot, mtessun, omoris, pmoore, pvrabec, qe-baseos-security, rkratky, salmy, sgrubb, ssekidde
Target Milestone: rcKeywords: Rebase
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: audit-2.4.5-1.el6 Doc Type: Rebase: Bug Fixes and Enhancements
Doc Text:
_audit_ rebased to version 2.4.5 The _audit_ package, which provides the user-space utilities for storing and searching the audit records generated by the *audit* subsystem in the Linux kernel, has been rebased to version 2.4.5. This update includes enhanced event interpretation facilities that provide more system-call names and arguments to make the understanding of events easier. This update also has an important behavior change in the way that *auditd* records events to disk. If you are using either `data` or `sync` modes for the *flush* setting in *auditd.conf*, you will see a performance decrease in *auditd's* ability to log events. This is because it was previously not properly informing the kernel that full synchronous writes should be used. This was corrected, which has improved the reliability of the operation, but this has come at the expense of performance. If the performance drop is not tolerable, the *flush* setting should be changed to `incremental` and the *freq* setting will control how often *auditd* instructs the kernel to synchronize all records to disk. A *freq* setting of `100` should give good performance while making sure that new records are flushed to disk periodically.
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-05-11 00:02:00 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1271982    

Description Steve Grubb 2015-08-27 14:33:40 UTC
Description of problem:
The audit package on RHEL6 hasn't been updated since 2.3.7. There are many bugfixes and enhancements as well as CVE-2015-5186 that needs to be put into rhel6. This bz would encompass all of the other bz proposed and accepted for rhel6.8.

Version-Release number of selected component (if applicable):
2.3.7

Comment 1 Steve Grubb 2015-09-24 15:21:12 UTC
*** Bug 1266143 has been marked as a duplicate of this bug. ***

Comment 25 Robert Krátký 2016-02-26 15:27:27 UTC
Hi Steve,

This bug was flagged as requiring a Release Note. Could you please fill out the Doc Text field? I'll edit it into a RN and make sure it gets published.

Thank you.

Comment 26 Robert Krátký 2016-03-03 09:06:12 UTC
Thanks, Steve.

Comment 27 Ondrej Moriš 2016-04-10 20:54:02 UTC
Successfully verified, I tried to verify as much as possible from changelog [1] between version 2.3.7 and 2.4.5. Both Sanity and Regression testing passed.

[1] https://people.redhat.com/sgrubb/audit/ChangeLog

Comment 28 Steve Grubb 2016-04-18 16:44:10 UTC
*** Bug 1327286 has been marked as a duplicate of this bug. ***

Comment 30 errata-xmlrpc 2016-05-11 00:02:00 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-0867.html