tripwire and device numbers

Mike Tancsa mike at sentex.net
Fri Mar 5 12:48:13 UTC 2010


At 06:59 AM 3/5/2010, Dag-Erling Smørgrav wrote:
>"Poul-Henning Kamp" <phk at phk.freebsd.dk> writes:
> > Mike Tancsa <mike at sentex.net> writes:
> > > While getting a box ready for deployment, I noticed on two
> > > occasions, I would get some exception reports flagging all files as
> > > the underlying device number through reboots had changed.  Is this
> > > "normal" for Tripwire and FreeBSD ? (RELENG_7)
> > Yes, device numbers in freebsd carry no meaning, unless it is a compat
> > /dev directory to boot ancient systems (SunOS, very old FreeBSD etc)
> > diskless.
> >
> > In general, tripwire should ignore devfs and possibly all pseudo-fs
> > mount-points.
>
>Nothing to do with devfs; IIUC, tripwire is complaining about st.st_dev
>on regular files and directories.

Correct. It was upset by just regular files and 
directories on regular file systems in /usr/bin /sbin etc.

         ---Mike

>DES
>--
>Dag-Erling Smørgrav - des at des.no

--------------------------------------------------------------------
Mike Tancsa,                                      tel +1 519 651 3400
Sentex Communications,                            mike at sentex.net
Providing Internet since 1994                    www.sentex.net
Cambridge, Ontario Canada                         www.sentex.net/mike



More information about the freebsd-security mailing list