Bug 204855 - [LSPP Audit] auditctl fails to reject invalid exclude rule options (-S and multiple -F)
[LSPP Audit] auditctl fails to reject invalid exclude rule options (-S and mu...
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: audit (Show other bugs)
x86_64 Linux
high Severity medium
: ---
: ---
Assigned To: Steve Grubb
Brian Brock
Depends On:
  Show dependency treegraph
Reported: 2006-08-31 17:43 EDT by IBM Bug Proxy
Modified: 2007-11-30 17:07 EST (History)
1 user (show)

See Also:
Fixed In Version: 5.0.0
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2006-10-02 10:29:43 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
IBM Linux Technology Center 26804 None None None Never

  None (edit)
Description IBM Bug Proxy 2006-08-31 17:43:02 EDT
LTC Owner is: Redhat
LTC Originator is: mcthomps@us.ibm.com

---Problem Description---
auditctl fails to reject invalid rules:
auditctl -a exclude,always -S all
auditctl -a exclude,always -F msgtype=PATH -F msgtype=CWD
Contact Information = Michael Thompson mcthomps@us.ibm.com
---uname output---
Linux oracer2.ltc.austin.ibm.com 2.6.17-1.2586.2.2.fc6.lspp.48 #1 SMP Wed Aug 30
15:51:12 EDT 2006 x86_64 x86_64 x86_64 GNU/Linux
Machine Type = x86_64
A debugger is not configured
---Steps to Reproduce---
auditctl -a exclude,always -S all
auditctl -a exclude,always -F msgtype=PATH -F msgtype=CWD

Both of these should be rejected.
---Base System Tools Component Data---
Userspace tool common name: auditctl

The userspace tool has the following bit modes: 64-bit

Userspace rpm: audit
*Additional Instructions for Michael Thompson mcthomps@us.ibm.com:
-Attach ltrace and strace of userspace application.
Comment 1 Steve Grubb 2006-09-21 14:05:12 EDT
The problem with exclude list being used for syscalls is fixed in audit-1.2.7.
The other problem is being investigated.
Comment 2 Pete Graner 2006-09-21 18:50:58 EDT
Steve pls open a new bz for the 2nd issue. Then move this one to MODIFIED and
Comment 3 Steve Grubb 2006-09-22 09:18:45 EDT
bug #207666 was opened to track progress resolving the multiple msgtype problem.
Comment 4 Jay Turner 2006-09-25 06:55:08 EDT
QE ack for 5B2.  Appears to impact 14b.
Comment 5 Jay Turner 2006-10-02 10:20:42 EDT
Fix confirmed with audit-1.2.7-2 which is included in the latest RHEL5 trees

Note You need to log in before you can comment on or make changes to this bug.