Bug 1257650 - Rebase audit package
Summary: Rebase audit package
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: audit
Version: 6.7
Hardware: All
OS: Linux
high
medium
Target Milestone: rc
: ---
Assignee: Steve Grubb
QA Contact: Ondrej Moriš
Robert Krátký
URL:
Whiteboard:
: 1266143 1327286 (view as bug list)
Depends On:
Blocks: 1271982
TreeView+ depends on / blocked
 
Reported: 2015-08-27 14:33 UTC by Steve Grubb
Modified: 2019-11-14 06:54 UTC (History)
11 users (show)

Fixed In Version: audit-2.4.5-1.el6
Doc Type: Rebase: Bug Fixes and Enhancements
Doc Text:
_audit_ rebased to version 2.4.5 The _audit_ package, which provides the user-space utilities for storing and searching the audit records generated by the *audit* subsystem in the Linux kernel, has been rebased to version 2.4.5. This update includes enhanced event interpretation facilities that provide more system-call names and arguments to make the understanding of events easier. This update also has an important behavior change in the way that *auditd* records events to disk. If you are using either `data` or `sync` modes for the *flush* setting in *auditd.conf*, you will see a performance decrease in *auditd's* ability to log events. This is because it was previously not properly informing the kernel that full synchronous writes should be used. This was corrected, which has improved the reliability of the operation, but this has come at the expense of performance. If the performance drop is not tolerable, the *flush* setting should be changed to `incremental` and the *freq* setting will control how often *auditd* instructs the kernel to synchronize all records to disk. A *freq* setting of `100` should give good performance while making sure that new records are flushed to disk periodically.
Clone Of:
Environment:
Last Closed: 2016-05-11 00:02:00 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:0867 normal SHIPPED_LIVE audit bug fix update 2016-05-10 22:46:58 UTC

Description Steve Grubb 2015-08-27 14:33:40 UTC
Description of problem:
The audit package on RHEL6 hasn't been updated since 2.3.7. There are many bugfixes and enhancements as well as CVE-2015-5186 that needs to be put into rhel6. This bz would encompass all of the other bz proposed and accepted for rhel6.8.

Version-Release number of selected component (if applicable):
2.3.7

Comment 1 Steve Grubb 2015-09-24 15:21:12 UTC
*** Bug 1266143 has been marked as a duplicate of this bug. ***

Comment 25 Robert Krátký 2016-02-26 15:27:27 UTC
Hi Steve,

This bug was flagged as requiring a Release Note. Could you please fill out the Doc Text field? I'll edit it into a RN and make sure it gets published.

Thank you.

Comment 26 Robert Krátký 2016-03-03 09:06:12 UTC
Thanks, Steve.

Comment 27 Ondrej Moriš 2016-04-10 20:54:02 UTC
Successfully verified, I tried to verify as much as possible from changelog [1] between version 2.3.7 and 2.4.5. Both Sanity and Regression testing passed.

[1] https://people.redhat.com/sgrubb/audit/ChangeLog

Comment 28 Steve Grubb 2016-04-18 16:44:10 UTC
*** Bug 1327286 has been marked as a duplicate of this bug. ***

Comment 30 errata-xmlrpc 2016-05-11 00:02:00 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-0867.html


Note You need to log in before you can comment on or make changes to this bug.