Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1257650 - Rebase audit package
Rebase audit package
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: audit (Show other bugs)
6.7
All Linux
high Severity medium
: rc
: ---
Assigned To: Steve Grubb
Ondrej Moriš
Robert Krátký
: Rebase
: 1266143 1327286 (view as bug list)
Depends On:
Blocks: 1271982
  Show dependency treegraph
 
Reported: 2015-08-27 10:33 EDT by Steve Grubb
Modified: 2016-06-20 05:00 EDT (History)
11 users (show)

See Also:
Fixed In Version: audit-2.4.5-1.el6
Doc Type: Rebase: Bug Fixes and Enhancements
Doc Text:
_audit_ rebased to version 2.4.5 The _audit_ package, which provides the user-space utilities for storing and searching the audit records generated by the *audit* subsystem in the Linux kernel, has been rebased to version 2.4.5. This update includes enhanced event interpretation facilities that provide more system-call names and arguments to make the understanding of events easier. This update also has an important behavior change in the way that *auditd* records events to disk. If you are using either `data` or `sync` modes for the *flush* setting in *auditd.conf*, you will see a performance decrease in *auditd's* ability to log events. This is because it was previously not properly informing the kernel that full synchronous writes should be used. This was corrected, which has improved the reliability of the operation, but this has come at the expense of performance. If the performance drop is not tolerable, the *flush* setting should be changed to `incremental` and the *freq* setting will control how often *auditd* instructs the kernel to synchronize all records to disk. A *freq* setting of `100` should give good performance while making sure that new records are flushed to disk periodically.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-05-10 20:02:00 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:0867 normal SHIPPED_LIVE audit bug fix update 2016-05-10 18:46:58 EDT

  None (edit)
Description Steve Grubb 2015-08-27 10:33:40 EDT
Description of problem:
The audit package on RHEL6 hasn't been updated since 2.3.7. There are many bugfixes and enhancements as well as CVE-2015-5186 that needs to be put into rhel6. This bz would encompass all of the other bz proposed and accepted for rhel6.8.

Version-Release number of selected component (if applicable):
2.3.7
Comment 1 Steve Grubb 2015-09-24 11:21:12 EDT
*** Bug 1266143 has been marked as a duplicate of this bug. ***
Comment 25 Robert Krátký 2016-02-26 10:27:27 EST
Hi Steve,

This bug was flagged as requiring a Release Note. Could you please fill out the Doc Text field? I'll edit it into a RN and make sure it gets published.

Thank you.
Comment 26 Robert Krátký 2016-03-03 04:06:12 EST
Thanks, Steve.
Comment 27 Ondrej Moriš 2016-04-10 16:54:02 EDT
Successfully verified, I tried to verify as much as possible from changelog [1] between version 2.3.7 and 2.4.5. Both Sanity and Regression testing passed.

[1] https://people.redhat.com/sgrubb/audit/ChangeLog
Comment 28 Steve Grubb 2016-04-18 12:44:10 EDT
*** Bug 1327286 has been marked as a duplicate of this bug. ***
Comment 30 errata-xmlrpc 2016-05-10 20:02:00 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-0867.html

Note You need to log in before you can comment on or make changes to this bug.