Bug 1651761

Summary: Rebase audit package to 2.8.5 to pick up bug fixes
Product: Red Hat Enterprise Linux 7 Reporter: Steve Grubb <sgrubb>
Component: auditAssignee: Steve Grubb <sgrubb>
Status: CLOSED ERRATA QA Contact: Ondrej Moriš <omoris>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.6CC: mthacker, omoris, pvrabec
Target Milestone: rcKeywords: Rebase
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: audit-2.8.5-2.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-06 13:03:45 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Steve Grubb 2018-11-20 17:40:07 UTC
Description of problem:
There are a number of bugs that have been found and fixed on the maintenance branch of audit-2.8 that should be picked up to avoid problems. These include:

- Mark netlabel events as simple events so that get processed quicker
- When audispd is reconfiguring, only SIGHUP plugins with valid pid (#1614833)
- Add 30-ospp-v42.rules to meet new Common Criteria requirements
- In aureport, fix segfault in file report
- Add auparse_normalizer support for labeled networking events
- Fix memory leak in audisp-remote plugin when using krb5 transport. (#1622194)
- Event aging is off by a second
- In ausearch/auparse, correct event ordering to process oldest first
- auparse_reset was not clearing everything it should
- In ausearch/report, lightly parse selinux portion of USER_AVC events

Comment 3 Steve Grubb 2019-03-01 21:56:49 UTC
audit-2.8.5 was released and built in Fedora.

Comment 4 Steve Grubb 2019-03-05 18:05:43 UTC
audit-2.8.5-1.el7 was built to address this issue.

Comment 6 Steve Grubb 2019-03-27 15:18:23 UTC
A memory leak in libauparse was reported upstream. Respinning to pick up this important fix.

Comment 7 Steve Grubb 2019-03-27 16:51:59 UTC
audit-2.8.5-2.el7 was created to pickup this important bug fix.

Comment 8 Ondrej Moriš 2019-06-12 11:11:59 UTC
Successfully verified.

(In reply to Steve Grubb from comment #0)
> Description of problem:
> There are a number of bugs that have been found and fixed on the maintenance
> branch of audit-2.8 that should be picked up to avoid problems. These
> include:
> 
> - When audispd is reconfiguring, only SIGHUP plugins with valid pid
> (#1614833)

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1614833#c15.

> - In aureport, fix segfault in file report

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1705376#c5

> - Fix memory leak in audisp-remote plugin when using krb5 transport.
> (#1622194)

Verified - https://bugzilla.redhat.com/show_bug.cgi?id=1622194#c8.

The following changes were tested SanityOnly (ie. complete Sanity and Regression testing):

> - Add 30-ospp-v42.rules to meet new Common Criteria requirements
> - Mark netlabel events as simple events so that get processed quicker
> - Add auparse_normalizer support for labeled networking events
> - Event aging is off by a second
> - In ausearch/auparse, correct event ordering to process oldest first
> - auparse_reset was not clearing everything it should
> - In ausearch/report, lightly parse selinux portion of USER_AVC events
> - A memory leak in libauparse

Comment 10 errata-xmlrpc 2019-08-06 13:03:45 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:2191