Bug 141314 - standard audit configuration can causes silent system hangs and does not match documentation
Summary: standard audit configuration can causes silent system hangs and does not matc...
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: laus
Version: 3.0
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Jason Vas Dias
QA Contact: Jay Turner
Depends On:
TreeView+ depends on / blocked
Reported: 2004-11-30 11:07 UTC by Martin Poole
Modified: 2015-01-08 00:08 UTC (History)
1 user (show)

Clone Of:
Last Closed: 2005-05-20 03:25:53 UTC

Attachments (Terms of Use)
patch against /etc/audit/audit.conf (598 bytes, patch)
2004-11-30 11:09 UTC, Martin Poole
no flags Details | Diff

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2005:219 normal SHIPPED_LIVE laus bug fix update 2005-05-19 04:00:00 UTC

Description Martin Poole 2004-11-30 11:07:14 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.5)
Gecko/20041107 Firefox/1.0

Description of problem:
The standard configuration for auditing can cause silent hangs of a
machine if the audit system encounters errors because it only goes
into suspend mode and produces no diagnostics to indicate that it has
done so.

This does not match the man page which states 

 "When auditd encounters an error while writing to a file, or if the 
bin mode  notify command fails, it enters error mode. The default
action is to log a message to the system log, and suspend the audit

Since a system that silently hangs is less than helpful for diagnostic
purposes it makes sense to ensure that auditing generates some diagnostic.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.install a system

Expected Results:  standard audit configuration should produce a
diagnostic message on error.

Additional info:

Comment 1 Martin Poole 2004-11-30 11:09:56 UTC
Created attachment 107614 [details]
patch against /etc/audit/audit.conf

Diff to standard /etc/audit/audit.conf to provide a diagnostic if the audit
daemon encounters an error.

Comment 2 Charlie Bennett 2005-02-01 21:57:04 UTC
applied to CVS for testing, Thanks

Comment 3 Jason Vas Dias 2005-02-24 18:05:58 UTC
This bug is now fixed in laus-0.1-67RHEL3, which should be in 
RHEL-3-U5, and which meanwhile can be downloaded from:

Comment 4 Dennis Gregorovic 2005-05-20 03:25:53 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.


Comment 5 Need Real Name 2005-09-11 05:58:11 UTC
I'm getting "silent system hangs" - reproduceable after about a week of 
uptime. /sbin/auditd is the cause (killing this - providing a root shell 
session is available to do so from - corrects the hang.  Re-running re-
introduces the hang immediately.)  Nothing is getting logged anywhere, no 
matter how I set up the configuration files.

There should probably never be any situation allowed where something is 
permitted to lock up a system without any message of any kind getting logged 
anyplace - not even if the admin doesn't want the message logged.

I've got 40gigs free disc etc.

Note You need to log in before you can comment on or make changes to this bug.