Bug 727524

Summary: The ALLOWPROCDELFILE option does not work
Product: [Fedora] Fedora Reporter: John Horne <john.horne>
Component: rkhunterAssignee: Kevin Fenzi <kevin>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 15CC: kevin
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rkhunter-1.3.8-9.fc16 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-08-17 01:05:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Patch to fix ALLOWPROCDELFILE option. none

Description John Horne 2011-08-02 11:35:39 UTC
Created attachment 516302 [details]
Patch to fix ALLOWPROCDELFILE option.

Description of problem:
In rkhunter 1.3.8 there is a bug preventing the ALLOWPROCDELFILE configuration option from working.

Version-Release number of selected component (if applicable):
1.3.8-8

How reproducible:
Problem only exists if processes are using deleted files.

Steps to Reproduce:
1. Run test 'deleted_files'.
2. If warnings are shown, then whitelist the reported filenames.
3.
  
Actual results:
The whitelisting has no effect.

Expected results:
The whitelisting should prevent warnings being displayed.

Additional info:
Patch attached.
The problem was discussed on the 'rkhunter-users' mailing list: http://sourceforge.net/mailarchive/forum.php?thread_name=1312277471.2698.0.camel%40jhorne&forum_name=rkhunter-users

Comment 1 Fedora Update System 2011-08-05 23:04:34 UTC
rkhunter-1.3.8-9.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/rkhunter-1.3.8-9.fc16

Comment 2 Fedora Update System 2011-08-05 23:09:28 UTC
rkhunter-1.3.8-9.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/rkhunter-1.3.8-9.fc15

Comment 3 Fedora Update System 2011-08-08 20:48:39 UTC
Package rkhunter-1.3.8-9.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing rkhunter-1.3.8-9.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/rkhunter-1.3.8-9.fc16
then log in and leave karma (feedback).

Comment 4 Fedora Update System 2011-08-17 01:04:58 UTC
rkhunter-1.3.8-9.fc15 has been pushed to the Fedora 15 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2011-08-22 14:47:06 UTC
rkhunter-1.3.8-9.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.