File audit.changes of Package audit
1202
1
-------------------------------------------------------------------
2
Mon Jun 1 17:30:49 UTC 2020 - Enzo Matsumiya <ematsumiya@suse.com>
3
4
- Fix specfile to require libauparse0 and libaudit1 after splitting
5
audit-libs (bsc#1172295)
6
7
-------------------------------------------------------------------
8
Sat Nov 4 21:12:09 UTC 2017 - aavindraa@gmail.com
9
10
- Update to version 2.8.1 release (includes 2.8 and 2.7.8 changes)
11
* many features added to auparse_normalize
12
* cli option added to auditd and audispd for setting config dir
13
* in auditd, restore the umask after creating a log file
14
* option added to auditd for skipping email verification
15
- Full changelog: http://people.redhat.com/sgrubb/audit/ChangeLog
16
17
-------------------------------------------------------------------
18
Mon Jul 24 13:59:06 UTC 2017 - jengelh@inai.de
19
20
- Rectify RPM groups, diversify descriptions.
21
- Remove mentions of static libraries because they are not built.
22
23
-------------------------------------------------------------------
24
Tue Jul 18 18:32:56 UTC 2017 - tonyj@suse.com
25
26
- Update to version 2.7.7 release
27
Changelog: https://people.redhat.com/sgrubb/audit/ChangeLog
28
29
-------------------------------------------------------------------
30
Sat Apr 2 18:14:51 UTC 2016 - tchvatal@suse.com
31
32
- Create folder for the m4 file from previous commit to avoid install
33
failure
34
35
-------------------------------------------------------------------
36
Fri Apr 1 14:15:58 UTC 2016 - tchvatal@suse.com
37
38
- Version update to 2.5 release
39
- Refresh two patches and README to contain SUSE and not SuSE
40
* audit-allow-manual-stop.patch
41
* audit-plugins-path.patch
42
- Cleanup with spec-cleaner and do not use subshells but rather use
43
-C parameter of make
44
- Install m4 file to the devel package
45
46
-------------------------------------------------------------------
47
Wed Dec 2 12:14:38 UTC 2015 - p.drouand@gmail.com
48
49
- Do not depend on insserv nor fillup; the package provides
50
neither sysconfig nor sysvinit files
51
52
-------------------------------------------------------------------
53
Fri Aug 21 18:58:18 UTC 2015 - tonyj@suse.com
54
55
- Update to version 2.4.4 (bsc#941922, CVE-2015-5186)
56
- Remove patch 'audit-no_m4_dir.patch'
57
(added Fri Apr 26 11:14:39 UTC 2013 by mmeister@suse.com)
58
No idea what earlier 'automake' build error this was trying to fix but
59
it broke the handling of "--without-libcap-ng". Anyways, no build error
60
occurs now and m4 path is also needed in v2.4.4 to find ax_prog_cc_for_build
61
- Require pkgconfig for build
62
63
Changelog 2.4.4
64
- Fix linked list correctness in ausearch/report
65
- Add more cross compile fixups (Clayton Shotwell)
66
- Update auparse python bindings
67
- Update libev to 4.20
68
- Fix CVE-2015-5186 Audit: log terminal emulator escape sequences handling
69
70
Changelog 2.4.3
71
- Add python3 support for libaudit
72
- Cleanup automake warnings
73
- Add AuParser_search_add_timestamp_item_ex to python bindings
74
- Add AuParser_get_type_name to python bindings
75
- Correct processing of obj_gid in auditctl (Aleksander Zdyb)
76
- Make plugin config file parsing more robust for long lines (#1235457)
77
- Make auditctl status print lost field as unsigned number
78
- Add interpretation mode for auditctl -s
79
- Add python3 support to auparse library
80
- Make --enable-zos-remote a build time configuration option (Clayton Shotwell)
81
- Updates for cross compiling (Clayton Shotwell)
82
- Add MAC_CHECK audit event type
83
- Add libauparse pkgconfig file (Aleksander Zdyb)
84
85
Changelog 2.4.2
86
- Ausearch should parse exe field in SECCOMP events
87
- Improve output for short mode interpretations in auparse
88
- Add CRYPTO_IKE_SA and CRYPTO_IPSEC_SA events
89
- If auditctl is reading rules from a file, send messages to syslog (#1144252)
90
- Correct lookup of ppc64le when determining machine type
91
- Increase time buffer for wide character numbers in ausearch/report (#1200314)
92
- In aureport, add USER_TTY events to tty report
93
- In audispd, limit reporting of queue full messages (#1203810)
94
- In auditctl, don't segfault when invalid options passed (#1206516)
95
- In autrace, remove some older unimplemented syscalls for aarch64 (#1185892)
96
- In auditctl, correct lookup of aarch64 in arch field (#1186313)
97
- Update lookup tables for 4.1 kernel
98
99
-------------------------------------------------------------------
100
Mon Nov 24 14:55:22 UTC 2014 - mq@suse.cz
101
102
- Update to version 2.4.1
103
104
Changelog 2.4.1
105
- Make python3 support easier
106
- Add support for ppc64le (Tony Jones)
107
- Add some translations for a1 of ioctl system calls
108
- Add command & virtualization reports to aureport
109
- Update aureport config report for new events
110
- Add account modification summary report to aureport
111
- Add GRP_MGMT and GRP_CHAUTHTOK event types
112
- Correct aureport account change reports
113
- Add integrity event report to aureport
114
- Add config change summary report to aureport
115
- Adjust some syslogging level settings in audispd
116
- Improve parsing performance in everything
117
- When ausearch outputs a line, use the previously parsed values (Burn Alting)
118
- Improve searching and interpreting groups in events
119
- Fully interpret the proctitle field in auparse
120
- Correct libaudit and auditctl support for kernel features
121
- Add support for backlog_time_wait setting via auditctl
122
- Update syscall tables for the 3.18 kernel
123
- Ignore DNS failure for email validation in auditd (#1138674)
124
- Allow rotate as action for space_left and disk_full in auditd.conf
125
- Correct login summary report of aureport
126
- Auditctl syscalls can be comma separated list now
127
- Update rules for new subsystems and capabilities
128
129
- Drop patch audit-add-ppc64le-mach-support.patch (already upstream)
130
131
-------------------------------------------------------------------
132
Tue Sep 2 17:33:11 UTC 2014 - tonyj@suse.com
133
134
- Update to version 2.4
135
136
Changelog 2.4
137
- Optionally parse loginuids, (e)uids, & (e)gids in ausearch/report
138
- In auvirt, anomaly events don't have uuid (#1111448)
139
- Fix category handling in various records (#1120286)
140
- Fix ausearch handling of session id on 32 bit systems
141
- Set systemd startup to wait until systemd-tmpfiles-setup.service (#1097314)
142
- Interpret a0 of socketcall and ipccall syscalls
143
- Add pkgconfig file for libaudit
144
- Add go language bindings for limited use of libaudit
145
- Fix ausearch handling of exit code on 32 bit systems
146
- Fix bug in aureport string linked list handling
147
- Document week-ago time setting in ausearch/report man page
148
- Update tables for 3.16 kernel
149
- In aulast, on bad logins only record user_login proof and use it
150
- Add libaudit API for kernel features
151
- If audit=0 on kernel cmnd line, skip systemd activation (Cristian RodrÕguez)
152
- Add checkpoint --start option to ausearch (Burn Alting)
153
- Fix arch matching in ausearch
154
- Add --loginuid-immutable option to auditctl
155
- Fix memory leak in auditd when log_format is set to NOLOG
156
- Update auditctl to display features in the status command
157
- Add ausearch_add_timestamp_item_ex() to auparse
158
159
Changelog 2.3.7
160
- Limit number of options in a rule in libaudit
161
- Auditctl cannot load rule with lots of syscalls (#1089713)
162
- In ausearch, fix checkpointing when inode is reused by new log (Burn Alting)
163
- Add PROCTITLE and FEATURE_CHANGE event types
164
165
-------------------------------------------------------------------
166
Tue Sep 2 17:33:11 UTC 2014 - tonyj@suse.com
167
168
- Add support for ppc64le (bnc#891861)
169
New patch: audit-add-ppc64le-mach-support.patch
170
171
-------------------------------------------------------------------
172
Tue Apr 15 00:50:50 UTC 2014 - tonyj@suse.com
173
174
- Update to version 2.3.6
175
176
Changelog 2.3.6
177
- Add an option to auditctl to interpret a0 - a3 of syscall rules when listing
178
- Improve ARM and AARCH64 support (AKASHI Takahiro)
179
- Add ausearch --checkpoint feature (Burn Alting)
180
- Add --arch option to ausearch
181
- Improve too long config line in audispd, auditd, and auparse (#1071580)
182
- Fix aulast to accept the new AUDIT_LOGIN record format
183
- Remove clear_config symbol in auparse
184
185
Changelog 2.3.5
186
- In CRYPTO_KEY_USER events, do not interpret the 'fp' field
187
- Change formatting of rules listing in auditctl to look like audit.rules
188
- Change auditctl to do all netlink comm and then print rules
189
- Add a debug option to ausearch to find skipped events
190
- Parse subject, auid, and ses in LOGIN events (3.14 kernel changed format)
191
- In auditd, when shifting logs, ignore the num_logs setting (#950158)
192
- Allow passing a directory as the input file for ausearch/report (LC Bruzenak)
193
- Interpret syscall fields in SECCOMP events
194
- Increase a couple buffers to handle longer input
195
196
Changelog 2.3.4
197
- Parse path in CONFIG_CHANGE events
198
- In audisp-remote, fix retry logic for temporary network failures
199
- In auparse, add get_type_name function
200
- Add --no-config command option to aureport
201
- Fix interpretting MCS seliunx contexts in ausearch (#970675)
202
- In auparse, classify selinux contexts as MAC_LABEL field type
203
- In ausearch/report parse vm-ctx and img-ctx as selinux labels
204
- Update translation tables for the 3.14 kernel
205
206
-------------------------------------------------------------------
207
Tue Feb 4 00:05:38 UTC 2014 - tonyj@suse.com
208
209
- Update to version 2.3.3
210
211
Changelog 2.3.3
212
- Documentation updates
213
- Add AUDIT_USER_MAC_CONFIG_CHANGE event for MAC policy changes
214
- Update interpreting scheduler policy names
215
- Update automake files to automake-1.13.4
216
- Remove CAP_COMPROMISE_KERNEL interpretation
217
- Parse name field in AVC's (#1049916)
218
- Add missing typedef for auparse_type_t enumeration (#1053424)
219
- Fix parsing encoded filenames in records
220
- Parse SECCOMP events
221
222
-------------------------------------------------------------------
223
Tue Nov 26 18:26:57 UTC 2013 - tonyj@suse.com
224
225
- Update to version 2.3.2
226
227
Changelog 2.3.2
228
- Put RefuseManualStop in the right systemd section (#969345)
229
- Add legacy restart scripts for systemd support
230
- Add more syscall argument interpretations
231
- Add 'unset' keyword for uid & gid values in auditctl
232
- In ausearch, parse obj in IPC records
233
- In ausearch, parse subj in DAEMON_ROTATE records
234
- Fix interpretation of MQ_OPEN and MQ_NOTIFY events
235
- In auditd, restart dispatcher on SIGHUP if it had previously exited
236
- In audispd, exit when no active plugins are detected on reconfigure
237
- In audispd, clear signal mask set by libev so that SIGHUP works again
238
- In audispd, track binary plugins and restart if binary was updated
239
- In audispd, make sure we send signals to the correct process
240
- In auditd, clear signal mask when spawning any child process
241
- In audispd, make builtin plugins respond to SIGHUP
242
- In auparse, interpret mode flags of open syscall if O_CREAT is passed
243
- In audisp-remote, don't make address lookup always a permanent failure
244
- In audisp-remote, remove EOE events more efficiently
245
- In auditd, log the reason when email account is not valid
246
- In audisp-remote, change default remote_ending action to reconnect
247
- Add support for Aarch64 processors
248
249
Changelog 2.3.1
250
- Rearrange auditd setting enabled and pid to avoid a race (#910568)
251
- Interpret the ocomm field from OBJ_PID records
252
- Fix missing 'then' statement in sysvinit script
253
- Switch ausearch to use libauparse for interpretting fields
254
- In libauparse, interpret prctl arg0, sched_setscheduler arg1
255
- In auparse, check source_list isn't NULL when opening next file (Liequan Che)
256
- In libauparse, interpret send* flags argument
257
- In libauparse, interpret level and name options for set/getsockopt
258
- In ausearch/report, don't flush events until last file (Burn Alting)
259
- Don't use systemctl to stop the audit daemon
260
261
Changelog 2.3
262
- The clone(2) man page is really clone(3), fix interpretation of clone syscall
263
- Add systemd support for reload (#901533)
264
- Allow -F msgtype on the user filter
265
- Add legacy support for resuming logging under systemd (#830780)
266
- Add legacy support for rotating logs under systemd (#916611)
267
- In auditd, collect SIGUSR2 info for DAEMON_RESUME events
268
- Updated man pages
269
- Update libev to 4.15
270
- Update syscall tables for 3.9 kernel
271
- Interpret MQ_OPEN events
272
- Add augenrules support (Burn Alting)
273
- Consume less stack sending audit events
274
275
-------------------------------------------------------------------
276
Fri Jun 28 09:30:54 UTC 2013 - coolo@suse.com
277
278
- remove libcap-ng too from audit.spec as it's only needed for plugins
279
(and libcap-ng itself needs python to build bindings)
280
281
-------------------------------------------------------------------
282
Thu Jun 27 15:15:07 UTC 2013 - tonyj@suse.com
283
284
- Eliminate build cycles. audit.spec now builds only libs/devel.
285
Remainder (including daemon) built from audit-secondary.spec
286
287
-------------------------------------------------------------------
288
Fri Apr 26 11:14:39 UTC 2013 - mmeister@suse.com
289
290
- audit-no_m4_dir.patch: Removed AC_CONFIG_MACRO_DIR([m4]) from
291
configure.ac to fix build with new automake
292
293
-------------------------------------------------------------------
294
Mon Mar 25 17:25:31 UTC 2013 - crrodriguez@opensuse.org
295
296
- --with-libcap-ng=yes has no effect if libcap-ng is not
297
buildrequired and the lack of those requires causes a broken
298
configure script after autoreconf add pkgconfig(libcap-ng)
299
to both audit and audit-secondary, cap-ng is actually only
300
use in the latter.
301
302
-------------------------------------------------------------------
303
Mon Mar 25 16:58:10 UTC 2013 - crrodriguez@opensuse.org
304
305
- Version 2.2.3
306
- Code cleanups
307
- In spec file, don't own lib64/audit
308
- Update man pages
309
- Aureport no longer reads auditd.conf when stdin is used
310
- Don't let systemd kill auditd if auditctl errors out
311
- Update syscall table for 3.7 and 3.8 kernels
312
- Add interpretation for setns and unshare syscalls
313
- Code cleanup (Tyler Hicks)
314
- Documentation cleanups (Laurent Bigonville)
315
- Add dirfd interpretation to the *at functions
316
- Add termination signal to clone flags interpretation
317
- Update stig.rules
318
- In auditctl, when listing rules don't print numeric value of dir fields
319
- Add support for rng resource type in auvirt
320
- Fix aulast bad login output (#922508)
321
- In ausearch, allow negative numbers for session and auid searches
322
- In audisp-remote, if disk_full_action is stop then stop sending (#908977)
323
324
-------------------------------------------------------------------
325
Fri Mar 22 19:35:47 UTC 2013 - crrodriguez@opensuse.org
326
327
- remove sysvinit scripts.
328
329
-------------------------------------------------------------------
330
Wed Jan 30 23:19:33 UTC 2013 - crrodriguez@opensuse.org
331
332
- remove old tarball and update -secondary spec
333
334
-------------------------------------------------------------------
335
Wed Jan 30 23:12:19 UTC 2013 - crrodriguez@opensuse.org
336
337
- Audit 2.2.2 , the purpose of this update is too add compatibility
338
with systemd for 12.3
339
- In auditd, tcp_max_per_addr was allowing 1 more connection than specified
340
- In ausearch, fix matching of object records
341
- Auditctl was returning -1 when listing rules filtered on a key field
342
- Add interpretations for CAP_BLOCK_SUSPEND and CAP_COMPROMISE_KERNEL
343
- Add armv5tejl, armv5tel, armv6l and armv7l machine types (Nathaniel Husted)
344
- Updates for the 3.6 kernel
345
- Add auparse_feed_has_data function to libauparse
346
- Update audisp-prelude to use auparse_feed_has_data
347
- Add support to conditionally build auditd network listener (Tyler Hicks)
348
- In auditd, reset a flag after receiving USR1 signal info when rotating logs
349
- Add optional systemd init script support
350
- Add support for SECCOMP event type
351
- Don't interpret aN_len field in EXECVE records (#869555)
352
- In audisp-remote, do better job of draining queue
353
- Fix capability parsing in ausearch/auparse
354
- Interpret BPRM_FCAPS capability fields
355
- Add ANOM_LINK event type
356
357
-------------------------------------------------------------------
358
Tue Jan 22 12:34:00 UTC 2013 - jengelh@inai.de
359
360
- Executing autoreconf requires autoconf
361
362
-------------------------------------------------------------------
363
Fri Oct 12 12:51:13 UTC 2012 - coolo@suse.com
364
365
- update to 2.2.1, upstream changelog:
366
2.2.1
367
- Add more interpretations in auparse for syscall parameters
368
- Add some interpretations to ausearch for syscall parameters
369
- In ausearch/report and auparse, allocate extra space for node names
370
- Update syscall tables for the 3.3.0 kernel
371
- Update libev to 4.0.4
372
- Reduce the size of some applications
373
- In auditctl, check usage against euid rather than uid
374
375
2.2
376
- Correct all rules for clock_settime
377
- Fix possible segfault in auparse library
378
- Handle malformed socket addresses better
379
- Improve performance in audit_log_user_message()
380
- Improve performance in writing to the log file in auditd
381
- Syscall update for accept4 and recvmmsg
382
- Update autrace resource usage mode syscall list
383
- Improved sample rules for recent syscalls
384
- Add some debug info to audisp-remote startup and shutdown
385
- Make compiling with Python optional
386
- In auditd, if disk_error_action is ignore, don't syslog anything
387
- Fix some memory leaks
388
- If audispd is stopping, don't restart children
389
- Add support in auditctl for shell escaped filenames (Alexander)
390
- Add search support for virt events (Marcelo Cerri)
391
- Update interpretation tables
392
- Sync auparse's auditd config parser with auditd's parser
393
- In ausearch, also use cwd fields in file name searchs
394
- In ausearch, parse cwd in USER_CMD events
395
- In ausearch, correct parsing of uid in user space events
396
- In ausearch, update parsing of integrity events
397
- Apply some text cleanups from Debian (Russell Coker)
398
- In auditd, relax some permission checks for external apps
399
- Add ROLE_MODIFY event type
400
- In auditctl, new -c option to continue through bad rules but with failed exit
401
- Add auvirt program to do special reporting on virt events (Marcelo Cerri)
402
- Add interfield comparison support to auditctl (Peter Moody)
403
- Update auparse type intepretation for apparmor (Marcelo Cerri)
404
- Increase tcp_max_per_addr maximum to 1024.
405
- remove audit-no_python.patch, there is a configure switch for that now
406
- remove prereq on sysvinit
407
408
-------------------------------------------------------------------
409
Tue Feb 28 21:55:39 UTC 2012 - tonyj@suse.com
410
411
- Update to version 2.1.3, upstream changelog:
412
- 2.1.3
413
- Fix parsing of EXECVE records to not escape argc field
414
- If auditd's disk is full, send the right reason to client (#715315)
415
- Add CAP_WAKE_ALARM to interpretations
416
- Some updates to audisp-remote's remote-fgets function (Mirek Trmac)
417
- Add detection of TTY events to audisp-prelude (Matteo Sessa)
418
- Updated syscall tables for the 3.0 kernel
419
- Update linker flags for better relro support
420
- Make default size of logs bigger (#727310)
421
- Extract obj from NETFILTER_PKT events
422
- Disable 2 kerberos config options in audisp-remote.conf
423
- 2.1.2
424
- In ausearch/report, fix a segfault caused by MAC_POLICY_LOAD records
425
- In ausearch/report, add and update parsers
426
- In auditd, cleanup DAEMON_ACCEPT and DAEMON_CLOSE addr fields
427
- In ausearch/report, parse addr field of DAEMON_ACCEPT & DAEMON_CLOSE records
428
- In auditd, move startup success to after events are registered
429
- If auditd shutsdown due to failed tcp init, write a DAEMON_ABORT event
430
- Update auditd to avoid the oom killer in new kernels (Andreas Jaeger)
431
- Parse and interpret NETFILTER_PKT events correctly
432
- Return error if auditctl -l fails (#709345)
433
- In audisp-remote, replace glibc's fgets with custom implementation
434
435
-------------------------------------------------------------------
436
Fri Sep 30 20:07:43 UTC 2011 - coolo@suse.com
437
438
- add libtool as buildrequire to make the spec file more reliable
439
440
-------------------------------------------------------------------
441
Sat Sep 17 13:38:24 UTC 2011 - jengelh@medozas.de
442
443
- Remove redundant tags/sections from specfile
444
- Add audit-devel to baselibs
445
446
-------------------------------------------------------------------
447
Wed May 11 09:39:35 CEST 2011 - meissner@suse.de
448
449
- Adjust license of libaudit and libauparse to be
450
LGPLv2.1 or later.
451
452
-------------------------------------------------------------------
453
Wed Apr 27 00:04:23 UTC 2011 - tonyj@novell.com
454
455
- Update to version 2.1.1, upstream changelog:
456
- 2.1.1
457
- When ausearch is interpretting, output "as is" if no = is found
458
- Correct socket setup in remote logging
459
- Adjusted a couple default settings for remote logging and init script
460
- Audispd was not marking restarted plugins as active
461
- Audisp-remote should keep a capability if local_port < 1024
462
- When audispd restarts plugin, send event in its preferred format
463
- In audisp-remote, make all I/O asynchronous
464
- In audisp-remote, add sigusr1 handler to dump internal state
465
- Fix autrace to use correct syscalls on s390 and s390x systems
466
- Add shutdown syscall to remote logging teardowns
467
- Correct autrace rule for 32 bits systems
468
469
2.1
470
- Update auditctl man page for new field on user filter
471
- Fix crash in aulast when auid is foreign to the system
472
- Code cleanups
473
- Add store and forward model to audispd-remote (Mirek Trmac)
474
- Free memory on failed startups in audisp-prelude
475
- Fix memory leak in aureport
476
- Fix parsing state problem in libauparse
477
- Improve the robustness of libaudit field encoding functions
478
- Update capability tables
479
- In auditd, make failure action config checking consistent
480
- In auditd, check that NULL is not being passed to safe_exec
481
- In audisp-remote, overflow_action wasn't suspending if that action was chosen
482
- Update interpretations for virt events
483
- Improve remote logging warning and error messages
484
- Add interpretations for netfilter events
485
486
2.0.6
487
- ausearch/report performance improvements
488
- Synchronize all sample syscall rules to use action,list
489
- If program name provided to audit_log_acct_message, escape it
490
- Fix man page for the audit_encode_nv_string function (#647131)
491
- If value is NULL, don't segfault (#647128)
492
- Fix simple event parsing to not assume session id can't be last (Peng Haitao)
493
- Add support for new mmap audit event type
494
- Add ability for audispd syslog plugin to choose facility local0-7 (#593340)
495
- Fix autrace to use correct syscalls on i386 systems (Peng Haitao)
496
- On startup and reconfig, check for excess logs and unlink them
497
- Add a couple missing parser debug messages
498
- Fix error output resolving numeric address and update man page
499
- Add netfilter event types
500
- Fix spelling error in audit.rules man page (#667845)
501
- Improve warning in auditctl regarding immutable mode (#654883)
502
- Update syscall tables for the 2.6.37 kernel
503
- In ausearch, allow searching for auid -1
504
- Add queue overflow_action to audisp-remote to control queue overflows
505
- Update sample rules for new syscalls and packages
506
507
-------------------------------------------------------------------
508
Mon Feb 21 10:33:40 UTC 2011 - aj@suse.de
509
510
- Fix value of oom_score_adj.
511
512
-------------------------------------------------------------------
513
Tue Dec 7 21:17:24 UTC 2010 - coolo@novell.com
514
515
- prereq init script syslog
516
517
-------------------------------------------------------------------
518
Sun Nov 7 23:00:15 UTC 2010 - cristian.rodriguez@opensuse.org
519
520
- use full RELRO.
521
522
-------------------------------------------------------------------
523
Tue Sep 28 22:41:14 UTC 2010 - tonyj@novell.com
524
525
- Update to version 2.0.5 (drop: audit-as_needed.patch)
526
- Update README-BEFORE-ADDING-PATCHES
527
528
- Upstream 2.0.5 changelog:
529
- Make auparse handle empty AUSOURCE_FILE_ARRAY correctly (Miloslav Trmač)
530
- On i386, audit rules do not work on inode's with a large number (#554553)
531
- Fix displaying of inode values to be unsigned integers when listing rules
532
- Correct Makefile install of audispd (Jason Tang)
533
- Syscall table updates for 2.6.34 kernel
534
- Add definitions for service start and stop
535
- Fix handling of ignore errors in auditctl
536
- Fix gssapi support to build with new linker options
537
- Add virtualization event types
538
- Update aureport program help and man pages to show all options
539
540
-------------------------------------------------------------------
541
Tue Sep 28 07:22:05 UTC 2010 - aj@suse.de
542
543
- Annotate patch audit-oom_score_adj.
544
545
-------------------------------------------------------------------
546
Mon Sep 27 08:47:32 UTC 2010 - aj@suse.de
547
548
- Use /proc/<pid>/oom_score_adj if available.
549
550
-------------------------------------------------------------------
551
Mon Jun 28 06:38:35 UTC 2010 - jengelh@medozas.de
552
553
- use %_smp_mflags
554
555
-------------------------------------------------------------------
556
Fri Jun 25 21:22:51 UTC 2010 - tonyj@novell.com
557
558
- Minor changes to README-BEFORE-ADDING-PATCHES file.
559
- Add this file as %source in spec
560
561
-------------------------------------------------------------------
562
Fri Jun 25 17:50:31 CEST 2010 - dmueller@suse.de
563
564
- obsolete -XXbit package
565
566
-------------------------------------------------------------------
567
Tue May 4 10:51:58 CEST 2010 - tonyj@suse.de
568
569
- Update to version 2.0.4. This is a major version update,
570
libaudit.so has changed version. There is no backward compatibility.
571
audit-libs has been split into libaudit1 and libauparse0.
572
573
- Redhat changelog for 2.0 - 2.0.4 follows:
574
* 2.0.4
575
- Make alpha processor support optional
576
- Add support for the arm eabi processor
577
- add a compatible regexp processing capability to auparse (Miloslav Trmač)
578
- Fix regression in parsing user space originating records in aureport
579
- Add tcp_max_per_addr option in auditd.conf to limit concurrent connections
580
- Rearrange shutdown of auditd to allow DAEMON_END event more time
581
582
* 2.0.3
583
- In auditd, tell libev to stop processing a connection when idle timeout
584
- In auditd, tell libev to stop processing a connection when shutting down
585
- Interpret CAPSET records in ausearch/auparse
586
587
* 2.0.2
588
- If audisp-remote plugin has a queue at exit, use non-zero exit code
589
- Fix autrace to use the exit filter
590
- In audisp-remote, add a sigchld handler
591
- In auditd, check for duplicate remote connections before accepting
592
- Remove trailing ':' if any are at the end of acct fields in ausearch
593
- Update remote logging code to do better sanity check of data
594
- Fix audisp-prelude to prefer files if multiple path records are encountered
595
- Add libaudit.conf man page
596
- In auditd, disconnect idle clients
597
598
* 2.0.1
599
- Aulast now reads daemon_start events for the kernel version of reboot
600
- Clarify the man pages for ausearch/report regarding locale and date formats
601
- Fix getloginuid for python bindings
602
- Disable the audispd af_unix plugin by default
603
- Add a couple new init script actions for LSB 3.2
604
- In audisp-remote plugin, timeout network reads (#514090)
605
- Make some error logging in audisp-remote plugin more prominent
606
- Add audit.rules man page
607
- Interpret the session field in audit events
608
609
* 2.0
610
- Remove system-config-audit
611
- Get rid of () from userspace originating events
612
- Removed old syscall rules API - not needed since 2.6.16
613
- Remove all use of the old rule structs from API
614
- Fix uninitialized variable in auditd log rotation
615
- Add libcap-ng support for audispd plugins
616
- Removed ancient defines that are part of kernel 2.6.29 headers
617
- Bump soname number for libaudit
618
- In auditctl, deprecate the entry filter and move rules to exit filter
619
- Parse integrity audit records in ausearch/report (Mimi Zohar)
620
- Updated syscall table for 2.6.31 kernel
621
- Remove support for the legacy negate syscall rule operator
622
- In auditd reset syslog warnings if disk space becomes available
623
624
-------------------------------------------------------------------
625
Sun Dec 13 15:39:09 CET 2009 - jengelh@medozas.de
626
627
- add baselibs.conf as a source
628
629
-------------------------------------------------------------------
630
Tue Nov 3 19:11:33 UTC 2009 - coolo@novell.com
631
632
- updated patches to apply with fuzz=0
633
634
-------------------------------------------------------------------
635
Mon Sep 28 16:23:29 CEST 2009 - crrodriguez@suse.de
636
637
- do not package static libraries
638
- fix -devel package dependencies
639
640
-------------------------------------------------------------------
641
Sat Jun 20 12:33:00 CEST 2009 - cmorve69@yahoo.es
642
643
- fixed build with --as-needed
644
645
-------------------------------------------------------------------
646
Fri Jun 19 10:35:46 CEST 2009 - coolo@novell.com
647
648
- disable as-needed for this package as it fails to build with it
649
650
-------------------------------------------------------------------
651
Mon May 11 17:20:28 CEST 2009 - tonyj@suse.de
652
653
- Update from 1.7.7 to 1.7.13.
654
- Redhat changelog for 1.7.8 - 1.7.13 follows:
655
* Tue Apr 21 2009 Steve Grubb <sgrubb@redhat.com> 1.7.13-1
656
- Disable libev asserts unless --with-debug passed to configure
657
- Handle kernel 2.6.29's audit = 0 boot parameter better
658
- Install audit.py file in arch specific python directory (Dan Walsh)
659
- Fix problem with negative uids in audit rules on 32 bit systems
660
- When file type is unknown, output octal for mode field (Miloslav Trmač)
661
- Update tty keystroke interpretations (Miloslav Trmač)
662
663
* Tue Feb 24 2009 Steve Grubb <sgrubb@redhat.com> 1.7.12-1
664
- Add definitions for crypto events
665
- Fix regression where msgtype couldn't be used as a range in audit rules
666
- In libaudit, extend time spent checking reply
667
- In acct events, prefer id over acct if given
668
- In aulast, try id and acct in USER_LOGIN events
669
- When in immutable mode, have auditctl tell user instead of sending rules
670
- Add option to sysconfig to disable audit system on auditd stop
671
- Add tcp_wrappers config option to auditd
672
- Aulastlog can now take input from stdin
673
- Update libaudit python bindings to throw exceptions on error
674
- Adjust formatting of TTY data in libauparse to be like ausearch/report
675
- Add more key mappings to TTY interpretations
676
- Add internal queue to audisp-remote
677
- Fix failure action code to allow executables in audisp-remote (Chu Li)
678
- Fix memory leak when NOLOG log_format option given to auditd
679
- Quieten some of the reconnect text being sent to syslog in audisp-remote
680
- Apply some libev fixups to auditd
681
- Cleanup shutdown sequence of auditd
682
- Allow auditd log rotation via SIGUSR1 when NOLOG log format option given
683
684
* Sat Jan 10 2009 Steve Grubb <sgrubb@redhat.com> 1.7.11-1
685
- Don't error out in auditd when calling setsid
686
- Reformat a couple auditd error messages (Oden Eriksson)
687
- If log rotate fails, leave the old log writable
688
- Fixed bug in setting up auditd event loop when listening
689
- Warn if on biarch machine and auditctl rules show a syscall mismatch
690
- Audisp-remote was not parsing some config options correctly
691
- In auparse, check for single key in addition to virtual keys
692
- When auditd shuts down, send AUDIT_RMW_TYPE_ENDING messages to clients
693
- Created reconnect option to remote ending setting of audisp-remote
694
695
* Sat Dec 13 2008 Steve Grubb <sgrubb@redhat.com> 1.7.10-1
696
- Fix ausearch and aureport to handle out of order events
697
- Add line-buffer option to ausearch & timeout pipe input (Tony Jones)
698
- Add support in ausearch/report for tty data
699
- In audisp-remote, allow the keyword "any" for local_port
700
- Tighten parsing for -m and -w options in auditctl
701
- Add session query hint for aulast proof
702
- Fix audisp-remote to tolerate krb5 config options when not supported
703
- Created new aureport option for tty keystroke report
704
- audispd should detect backup config files and not use them
705
- When checking for ack in netlink interface, retry on EAGAIN a few times
706
- In aureport, fix mods report to show acct acted upon
707
708
* Wed Nov 05 2008 Steve Grubb <sgrubb@redhat.com> 1.7.9-1
709
- Fix uninitialized variable in aureport causing segfault
710
- Quieten down the gssapi not supported messages
711
- Fix bug interpretting i386 logs on x86_64 machines
712
- If kernel is in immutable mode, auditd should not send enable command
713
- Fix ausearch/report recent and now time keyword lookups
714
- Created aulast program
715
- prelude plugin should pull auid for login alert from 2nd uid field
716
- Add system boot, shutdown, and run level change events
717
- Add max_restarts to audispd.conf to limit times a plugin is restarted
718
- Expand session detection in ausearch
719
720
* Wed Oct 22 2008 Steve Grubb <sgrubb@redhat.com> 1.7.8-1
721
- Interpret TTY audit data in auparse (Miloslav Trmač)
722
- Extract terminal from USER_AVC events for ausearch/report (Peng Haitao)
723
- Add USER_AVCs to aureport's avc reporting (Peng Haitao)
724
- Short circuit hostname resolution in libaudit if host is empty
725
- If log_group and user are not root, don't check dispatcher perms
726
- Fix a bug when executing "ausearch -te today PM"
727
- Add --exit search option to ausearch
728
- Fix parsing config file when kerberos is disabled
729
730
-------------------------------------------------------------------
731
732
Tue Apr 14 14:52:39 CEST 2009 - dmueller@suse.de
733
734
- refresh patches
735
736
-------------------------------------------------------------------
737
Wed Dec 10 12:34:56 CET 2008 - olh@suse.de
738
739
- use Obsoletes: -XXbit only for ppc64 to help solver during distupgrade
740
(bnc#437293)
741
742
-------------------------------------------------------------------
743
Fri Dec 5 02:30:03 CET 2008 - tonyj@suse.de
744
745
- Revision to previous fix for bnc#445353.
746
These should go into SLES11 RC1.
747
1) Add --line-buffered option to limit when stdout is flushed (performance).
748
2) Testing found a related bug where (if input is a pipe) the last logical
749
record would permanently be queued waiting for a subsequent record indicating
750
end of the previous. This subsequent record may never arrive. Timer is
751
now run causing this record to be flushed if no new record arrives within
752
timeout. This fix is upstream also.
753
754
-------------------------------------------------------------------
755
Fri Nov 21 08:45:03 CET 2008 - tonyj@suse.de
756
757
- Force ausearch to flush stdout if pipe (bnc#445353)
758
759
-------------------------------------------------------------------
760
Thu Oct 30 12:34:56 CET 2008 - olh@suse.de
761
762
- obsolete old -XXbit packages (bnc#437293)
763
764
-------------------------------------------------------------------
765
Fri Sep 26 23:27:59 CEST 2008 - tonyj@suse.de
766
767
- Update from 1.7.4 to 1.7.7. GSS support disabled for present
768
- Redhat changelog for 1.7.5 - 1.7.7 follows:
769
* Wed Sep 11 2008 Steve Grubb <sgrubb@redhat.com> 1.7.7-1
770
- Bug fixes for gss code in remote logging (DJ Delorie)
771
- Fix ausearch -i to keep the node field in the output
772
- ausyscall now does strstr match on syscall names
773
- Makefile cleanup (Philipp Hahn)
774
- Add watched syscall support to audisp-prelude
775
- Use the right define for tcp_wrappers in auditd
776
- Expose encoding API for fields being logged from user space
777
778
* Wed Sep 11 2008 Steve Grubb <sgrubb@redhat.com> 1.7.6-1
779
- Update event record list and aureport classifications (Yu Zhiguo/Peng Haitao)
780
- Add subject to audit daemon events (Chu Li)
781
- Fix parsing of acct & exe fields in user records (Peng Haitao)
782
- Make client error handling in audisp-remote robust (DJ Delorie)
783
- Add tcp_wrappers support for auditd
784
- Updated syscall tables for 2.6.27 kernel
785
- Add heartbeat exchange to remote logging protocol (DJ Delorie)
786
- Audit connect/disconnect of remote clients
787
- In ausearch, collect pid from AVC records (Peng Haitao)
788
- Add auparse_get_field_type function to describe field's contents
789
- Add GSS/Kerberos encryption to the remote protocol (DJ Delorie)
790
791
* Mon Aug 25 2008 Steve Grubb <sgrubb@redhat.com> 1.7.5-1
792
- Update system-config-audit to 0.4.8
793
- Whole lot of bug fixes - see ChangeLog for details
794
- Reimplement auditd main loop using libev
795
- Add TCP listener to auditd to receive remote events
796
797
-------------------------------------------------------------------
798
Tue Aug 5 03:13:56 CEST 2008 - tonyj@suse.de
799
800
- Remove audit rules on audit stop (bnc#409093)
801
802
-------------------------------------------------------------------
803
Wed Jun 25 01:50:54 CEST 2008 - tonyj@suse.de
804
805
- Update from 1.7.2 to 1.7.4
806
- Redhat changelog for 1.7.3 - 1.7.4 follows:
807
* Mon May 19 2008 Steve Grubb <sgrubb@redhat.com> 1.7.4-1
808
- Fix interpreting of keys in syscall records
809
- Interpret audit rule config change list fields
810
- Don't error on name=(null) PATH records in ausearch/report
811
- Add key report to aureport
812
- Fix --end today to be now
813
- Added python bindings for auparse_goto_record_num
814
- Update system-config-audit to 0.4.7 (Miloslav Trmac)
815
- Add support for the filetype field option in auditctl
816
- In audispd boost priority after starting children
817
818
* Fri May 09 2008 Steve Grubb <sgrubb@redhat.com> 1.7.3-1
819
- Fix path processing in AVC records.
820
- auparse_find_field_next() wasn't resetting field ptr going to next record.
821
- auparse_find_field() wasn't checking current field before iterating
822
- cleanup some string handling in audisp-prelude plugin
823
- Update auditctl man page
824
- Fix output of keys in ausearch interpretted mode
825
- Fix ausearch/report --start now to not be reset to midnight
826
- Added auparse_goto_record_num function
827
- Prelude plugin now uses auparse_goto_record_num to avoid skipping a record
828
- audispd now has a priority boost config option
829
- Look for laddr in avcs reported via prelude
830
- Detect page 0 mmaps and alert via prelude
831
832
- Update from 1.6.8 to 1.7.2
833
- Complete fix for BNC# 378725
834
- Redhat changelog for 1.6.9-1.7.2 follows:
835
* Wed Apr 09 2008 Steve Grubb <sgrubb@redhat.com> 1.7.2-1
836
- gen_table.c now includes IPC defines to avoid glibc-headers wild goose chase
837
- ausyscall program added for cross referencing syscall name and number info
838
- Add login session ID search capability to ausearch
839
840
* Tue Apr 08 2008 Steve Grubb <sgrubb@redhat.com> 1.7.1-1
841
- Remove LSB headers info for init scripts
842
- Fix buffer overflow in audit_log_user_command, again (#438840)
843
- Fix memory leak in EOE code in auditd (#440075)
844
- In auditctl, don't use new operators in legacy rule format
845
- Made a couple corrections in alpha & x86_64 syscall tables (Miloslav Trmac)
846
- Add example STIG rules file
847
- Add string table lookup performance improvement patch (Miloslav Trmac)
848
- auparse_find_field_next performance improvement
849
850
* Sun Mar 30 2008 Steve Grubb <sgrubb@redhat.com> 1.7-1
851
- Improve input error handling in audispd
852
- Improve end of event detection in auparse library
853
- Improve handling of abstract namespaces
854
- Add test mode for prelude plugin
855
- Handle user space avcs in prelude plugin
856
- Audit event serial number now recorded in idmef alert
857
- Add --just-one option to ausearch
858
- Fix watched account login detection for some failed login attempts
859
- Couple fixups in audit logging functions (Miloslav Trmac)
860
- Add support in auditctl for virtual keys
861
- Added new type for user space MAC policy load events
862
- auparse_find_field_next was not iterating correctly, fixed it
863
- Add idmef alerts for access or execution of watched file
864
- Fix buffer overflow in audit_log_user_command
865
- Add basic remote logging plugin - only sends & no flow control
866
- Update ausearch with interpret fixes from auparse
867
868
* Sun Mar 09 2008 Steve Grubb <sgrubb@redhat.com> 1.6.9-1
869
- Apply hidden attribute cleanup patch (Miloslav Trmac)
870
- Apply auparse expression interface patch (Miloslav Trmac)
871
- Fix potential memleak in audit event dispatcher
872
- Change default audispd queue depth to 80
873
- Update system-config-audit to version 0.4.6 (Miloslav Trmac)
874
- audisp-prelude alerts now controlled by config file
875
- Updated syscall table for 2.6.25 kernel
876
- Apply patch correcting acct field being misencoded (Miloslav Trmac)
877
- Added watched account login detection for prelude plugin
878
879
-------------------------------------------------------------------
880
Wed Apr 23 14:17:17 CEST 2008 - tonyj@suse.de
881
882
- Fix for bnc#378725 VUL-0: audit buffer overflow
883
884
-------------------------------------------------------------------
885
Thu Apr 10 12:54:45 CEST 2008 - ro@suse.de
886
887
- added baselibs.conf file to build xxbit packages
888
for multilib support
889
890
-------------------------------------------------------------------
891
Wed Mar 26 21:29:38 CET 2008 - tonyj@suse.de
892
893
- Update from 1.6.2 to 1.6.8.
894
- Move audisp-plugins to new secondary spec (along with existing
895
python libs).
896
- Redhat changelog follows:
897
898
* Thu Feb 14 2008 Steve Grubb <sgrubb@redhat.com> 1.6.8-1
899
- Update for gcc 4.3
900
- Cleanup descriptors in audispd before running plugin
901
- Fix 'recent' keyword for aureport/search
902
- Fix SE Linux policy for zos_remote plugin
903
- Add event type for group password authentication attempts
904
- Couple of updates to the translation tables
905
- Add detection of failed group authentication to audisp-prelude
906
907
* Thu Jan 31 2008 Steve Grubb <sgrubb@redhat.com> 1.6.7-1
908
- In ausearch/report, prefer -if to stdin
909
- In ausearch/report, add new command line option --input-logs (#428860)
910
- Updated audisp-prelude based on feedback from prelude-devel
911
- Added prelude alert for promiscuous socket being opened
912
- Added prelude alert for SE Linux policy enforcement changes
913
- Added prelude alerts for Forbidden Login Locations and Time
914
- Applied patch to auparse fixing error handling of searching by
915
interpreted value (Miloslav Trmac)
916
917
* Sat Jan 19 2008 Steve Grubb <sgrubb@redhat.com> 1.6.6-1
918
- Add prelude IDS plugin for IDMEF alerts
919
- Add --user option to aulastlog command
920
- Use desktop-file-install for system-config-audit
921
922
* Mon Jan 07 2008 Steve Grubb <sgrubb@redhat.com> 1.6.5-1
923
- Add more errno strings for exit codes in auditctl
924
- Fix config parser to allow either 0640 or 0600 for audit logs (#427062)
925
- Check for audit log being writable by owner in auditd
926
- If auditd logging was suspended, it can be resumed with SIGUSR2 (#251639)
927
- Updated CAPP, LSPP, and NISPOM rules for new capabilities
928
- Added aulastlog utility
929
930
* Sat Dec 29 2007 Steve Grubb <sgrubb@redhat.com> 1.6.4-1
931
- fchmod of log file was on wrong variable (#426934)
932
- Allow use of errno strings for exit codes in audit rules
933
934
* Thu Dec 27 2007 Steve Grubb <sgrubb@redhat.com> 1.6.3-1
935
- Add kernel release string to DEAMON_START events
936
- Fix keep_logs when num_logs option disabled (#325561)
937
- Fix auparse to handle node fields for syscall records
938
- Update system-config-audit to version 0.4.5 (Miloslav Trmac)
939
- Add keyword week-ago to aureport & ausearch start/end times
940
- Fix audit log permissions on rotate. If group is root 0400, otherwise 0440
941
- Add RACF zos remote audispd plugin (Klaus Kiwi)
942
- Add event queue overflow action to audispd
943
944
-------------------------------------------------------------------
945
Tue Mar 18 14:43:11 CET 2008 - schwab@suse.de
946
947
- Use autoreconf.
948
949
-------------------------------------------------------------------
950
Wed Oct 31 07:08:38 CET 2007 - tonyj@suse.de
951
952
- Incorporate 1 more Redhat fixe post 1.6.2
953
- Go back to 10.2 behaviour wrt to starting in disabled state.
954
This time using patch submitted upstream, fix for #Bug 333739
955
956
-------------------------------------------------------------------
957
Wed Oct 10 23:18:24 CEST 2007 - tonyj@suse.de
958
959
- Upgrade to 1.6.2
960
Plus two bugs discovered in Fedora, will be fixed in 1.6.3
961
962
-------------------------------------------------------------------
963
Wed Jul 25 01:13:09 CEST 2007 - tonyj@suse.de
964
965
- Upgrade to 1.5.5
966
Correct bug in audit_make_equivalent function (Al Viro)
967
Local: add AppArmor audit ID (upstream in 1.5.6)
968
don't build RedHat system-config-audit
969
970
-------------------------------------------------------------------
971
Thu Jul 12 01:38:36 CEST 2007 - tonyj@suse.de
972
973
- Upgrade to 1.5.4
974
Add feed interface to auparse library (John Dennis)
975
Apply patch to libauparse for unresolved symbols (#241178)
976
Apply patch to add line numbers for file events in libauparse (John Dennis)
977
Change seresults to seresult in libauparse (John Dennis)
978
Add unit32_t definition to swig (#244210)
979
Add support for directory auditing
980
Update acct field to be escaped
981
- Fix for #280487 "%ghost /var/log/audit/audit.log will remove the logfile"
982
983
-------------------------------------------------------------------
984
Mon May 7 11:24:29 CEST 2007 - rguenther@suse.de
985
986
- Drop pkg-config BuildRequires introduced by last change.
987
988
-------------------------------------------------------------------
989
Wed May 2 19:08:53 CEST 2007 - tonyj@suse.de
990
991
- Upgrade to 1.5.3. Drop AUDITD_DISABLE_CONTEXTS from audit sysconfig
992
993
-------------------------------------------------------------------
994
Wed Nov 29 02:46:08 CET 2006 - tonyj@suse.de
995
996
- Upgrade to 1.2.9 (drop several patches which are now upstream)
997
- Move to using /etc/audit directory for config files
998
999
-------------------------------------------------------------------
1000
Thu Aug 31 22:57:52 CEST 2006 - tonyj@suse.de
1001
1002
- Upgrade to 1.2.6-1
1003
1004
-------------------------------------------------------------------
1005
Sat Aug 26 09:01:50 CEST 2006 - olh@suse.de
1006
1007
- do not define __KERNEL__ in userland apps
1008
- remove unused sys/syscall.h include
1009
1010
-------------------------------------------------------------------
1011
Wed Aug 16 15:42:58 CEST 2006 - cthiel@suse.de
1012
1013
- split audit into audit and audit-libs-python
1014
1015
-------------------------------------------------------------------
1016
Fri May 5 21:05:40 CEST 2006 - sbeattie@suse.de
1017
1018
- disable syscall audit context creation by default #172154
1019
1020
-------------------------------------------------------------------
1021
Mon Mar 20 16:18:29 CET 2006 - meissner@suse.de
1022
1023
- Do not print a misleading errormessage when audit
1024
is not compiled into the kernel. #152733
1025
1026
-------------------------------------------------------------------
1027
Mon Mar 6 14:21:06 CET 2006 - meissner@suse.de
1028
1029
- On kernels without auditing, which report ECONNREFUSED,
1030
do not output stuff to stderr on startup. #152733
1031
1032
-------------------------------------------------------------------
1033
Sat Feb 25 09:55:48 CET 2006 - kukuk@suse.de
1034
1035
- Fix moving of devel libraries, don't install .la file
1036
1037
-------------------------------------------------------------------
1038
Wed Feb 22 15:10:44 CET 2006 - meissner@suse.de
1039
1040
- moved libaudit.so symlink to /usr/lib and to -devel package,
1041
as requested by Thorsten.
1042
1043
-------------------------------------------------------------------
1044
Fri Feb 17 19:56:14 CET 2006 - meissner@suse.de
1045
1046
- check sendto() return against -1 (error with errno set).
1047
1048
-------------------------------------------------------------------
1049
Wed Jan 25 21:34:31 CET 2006 - mls@suse.de
1050
1051
- converted neededforbuild to BuildRequires
1052
1053
-------------------------------------------------------------------
1054
Wed Jan 25 12:09:31 CET 2006 - ro@suse.de
1055
1056
- fix fillup call since filename != packagename
1057
1058
-------------------------------------------------------------------
1059
Tue Jan 24 19:01:52 CET 2006 - ro@suse.de
1060
1061
- do not skip fillup in postinstall
1062
1063
-------------------------------------------------------------------
1064
Mon Jan 23 08:54:33 CET 2006 - dreynolds@suse.de
1065
1066
- Modified inssrv macro args to enable on boot
1067
1068
-------------------------------------------------------------------
1069
Wed Jan 18 21:33:21 CET 2006 - tonyj@suse.de
1070
1071
- Add support for AppArmor (submitted upstream for 1.1.4)
1072
1073
-------------------------------------------------------------------
1074
Fri Jan 13 11:35:57 CET 2006 - meissner@suse.de
1075
1076
- Updated to 1.1.3.
1077
- Moved audispd to /usr/sbin since it uses /usr/lib/libstdc++
1078
- Updated sysconfig snippet.
1079
1080
-------------------------------------------------------------------
1081
Tue Nov 8 11:32:45 CET 2005 - meissner@suse.de
1082
1083
- upgraded to 1.0.12.
1084
1085
-------------------------------------------------------------------
1086
Fri Nov 4 12:41:35 CET 2005 - kukuk@suse.de
1087
1088
- Update to 1.0.9.
1089
1090
-------------------------------------------------------------------
1091
Wed Oct 12 17:24:55 CEST 2005 - meissner@suse.de
1092
1093
- upgraded to 1.0.6. ptrdift patch now solved upstream.
1094
1095
-------------------------------------------------------------------
1096
Wed Oct 5 15:17:05 CEST 2005 - meissner@suse.de
1097
1098
- Upgraded to 1.0.5
1099
1100
-------------------------------------------------------------------
1101
Wed Oct 5 12:00:38 CEST 2005 - dmueller@suse.de
1102
1103
- add norootforbuild
1104
1105
-------------------------------------------------------------------
1106
Mon Sep 26 11:40:27 CEST 2005 - meissner@suse.de
1107
1108
- Upgraded to 1.0.4.
1109
- Make rate & backlog 32 bit unsigned int in auditctl
1110
- In auditctl, if -F arch is given with -t option, don't require list
1111
- Update auditd man page
1112
- Add size check to audit_send
1113
- Update message for audit_open failure when kernel doesn't support audit
1114
1115
-------------------------------------------------------------------
1116
Tue Aug 23 14:07:44 CEST 2005 - meissner@suse.de
1117
1118
- Upgraded to 1.0.3 bugfix release:
1119
- adjust file perms of newly created log file in auditd
1120
- fix 2 memory leaks and an out of bounds access in auditd
1121
- fix case where auditd was closing netlink descriptor too early
1122
- fix watch rules not to take field arguments in auditctl
1123
- fix bug where inode, devmajor, devminor, exit, and success fields in auditctl
1124
rules were not getting the correct value stored
1125
1126
-------------------------------------------------------------------
1127
Wed Aug 17 14:19:29 CEST 2005 - meissner@suse.de
1128
1129
- Added /var/log/audit directory and ghost audit.log #105131
1130
1131
-------------------------------------------------------------------
1132
Wed Aug 10 13:37:56 CEST 2005 - meissner@suse.de
1133
1134
- Upgraded to 1.0.2
1135
1136
-------------------------------------------------------------------
1137
Thu Aug 4 11:20:00 CEST 2005 - meissner@suse.de
1138
1139
- Upgraded to 1.0.1.
1140
1141
-------------------------------------------------------------------
1142
Mon Jul 11 14:47:38 CEST 2005 - meissner@suse.de
1143
1144
- Update to version 0.9.16.
1145
1146
-------------------------------------------------------------------
1147
Tue Jun 21 08:38:17 CEST 2005 - meissner@suse.de
1148
1149
- Update to version 0.9.10.
1150
1151
-------------------------------------------------------------------
1152
Fri Jun 17 11:21:42 CEST 2005 - meissner@suse.de
1153
1154
- Update to version 0.9.7.
1155
1156
-------------------------------------------------------------------
1157
Thu Jun 16 14:51:48 CEST 2005 - kukuk@suse.de
1158
1159
- Update to version 0.9.5
1160
1161
-------------------------------------------------------------------
1162
Tue Jun 14 01:30:20 CEST 2005 - ro@suse.de
1163
1164
- make it build with current includes
1165
1166
-------------------------------------------------------------------
1167
Tue May 31 14:15:30 CEST 2005 - meissner@suse.de
1168
1169
- Upgraded to 0.9.
1170
1171
-------------------------------------------------------------------
1172
Fri May 13 13:08:41 CEST 2005 - meissner@suse.de
1173
1174
- upgraded to 0.6.8
1175
1176
-------------------------------------------------------------------
1177
Tue Apr 19 10:39:54 CEST 2005 - meissner@suse.de
1178
1179
- Upgraded to 0.6.11.
1180
1181
-------------------------------------------------------------------
1182
Fri Apr 15 17:52:43 CEST 2005 - pth@suse.de
1183
1184
- Make libaudit.h define pgoff_t by itself.
1185
- Fix a minor warning.
1186
1187
-------------------------------------------------------------------
1188
Wed Mar 30 17:58:32 CEST 2005 - meissner@suse.de
1189
1190
- Upgraded to 0.6.9.
1191
1192
-------------------------------------------------------------------
1193
Fri Mar 4 11:23:29 CET 2005 - meissner@suse.de
1194
1195
- Upgraded to 0.6.5.
1196
1197
-------------------------------------------------------------------
1198
Thu Mar 3 14:59:36 CET 2005 - meissner@suse.de
1199
1200
- initial package of auditd for new kernel auditing system.
1201
1202