cvs commit: src/contrib/openbsm HISTORY TODO VERSION configure src/contrib/openbsm/bin/audit audit.c src/contrib/openbsm/bin/auditd audit_warn.c auditd.8 auditd.c auditd.h src/contrib/openbsm/bin/auditreduce auditreduce.1 ...

From: Robert Watson <>
Date: Fri, 29 Sep 2006 22:41:55 +0000 (UTC)
rwatson     2006-09-29 22:41:55 UTC

  FreeBSD src repository

  Modified files:        (Branch: RELENG_6)
    contrib/openbsm      HISTORY TODO VERSION configure 
    contrib/openbsm/bin/audit audit.c 
    contrib/openbsm/bin/auditd audit_warn.c auditd.8 auditd.c 
    contrib/openbsm/bin/auditreduce auditreduce.1 auditreduce.c 
    contrib/openbsm/bsm  libbsm.h 
    contrib/openbsm/config config.h 
    contrib/openbsm/etc  audit_control audit_event 
    contrib/openbsm/libbsm au_control.3 au_open.3 bsm_control.c 
                           bsm_io.c bsm_token.c libbsm.3 
    contrib/openbsm/man  audit_control.5 auditon.2 
    contrib/openbsm/tools audump.c 
  Added files:           (Branch: RELENG_6)
    contrib/openbsm/compat strlcat.h 
    contrib/openbsm/test/reference arg32_record arg32_token 
                                   data_record data_token 
                                   file_record file_token 
                                   header32_token in_addr_record 
                                   in_addr_token ip_record 
                                   ip_token ipc_record ipc_token 
                                   iport_record iport_token 
                                   opaque_record opaque_token 
                                   path_record path_token 
                                   return32_record return32_token 
                                   seq_record seq_token 
                                   text_record text_token 
    contrib/openbsm/test/samples execve-long-args.trail 
  Merge OpenBSM 1.0 alpha 12 from HEAD to RELENG_6, which includes a broad
  range of bug fixes made as a result of reports on 6.x, as well as some
  minor enhancements:
  OpenBSM 1.0 alpha 12
  - Correct bug in auditreduce which prevented the -c option from working
    correctly when the user specifies to process successful or failed events.
    The problem stemmed from not having access to the return token at the time
    the initial preselection occurred, but now a second preselection process
    occurs while processing the return token.
  - getacfilesz(3) API added to read new audit_control(5) filesz setting,
    which auditd(8) now sets the kernel audit trail rotation size to.
  - auditreduce(1) now uses stdin if no file names are specified on the command
    line; this was the documented behavior previously, but it was not
    implemented.  Be more specific in auditreduce(1)'s examples section about
    what might be done with the output of auditreduce.
  - Add audit_warn(5) closefile event so that administrators can hook
    termination of an audit trail file.  For example, this might be used to
    compress the trail file after it is closed.
  - auditreduce(1) now uses regular expressions for pathname matching. Users can
    now supply one or more (comma delimited) regular expressions for searching
    the pathnames. If one of the regular expressions is prefixed with a tilde
    (~), and a path matches, it will be excluded from the search results.
  OpenBSM 1.0 alpha 11
  - Reclassify certain read/write operations as having no class rather than the
    fr/fw class; our default classes audit intent (open) not operations (read,
  - Introduce AUE_SYSCTL_WRITE event so that BSD/Darwin systems can audit reads
    and writes of sysctls as separate events.  Add additional kernel
    environment and jail events for FreeBSD.
    (issued by the user audit(8) tool) and AUDIT_TRIGGER_ROTATE_KERNEL (issued
    by the kernel audit implementation) so that they can be distinguished.
  - Disable rate limiting of rotate requests; as the kernel doesn't retransmit
    a dropped request, the log file will otherwise grow indefinitely if the
    trigger is dropped.
  - Improve auditd debugging output.
  - Fix a number of threading related bugs in audit_control file reading
  - Add APIs au_poltostr() and au_strtopol() to convert between text
    representations of audit_control policy flags and the flags passed to
    auditon(A_SETPOLICY) and retrieved from auditon(A_GETPOLICY).
  - Add API getacpol() to return the 'policy:' entry from audit_control, an
    extension to the Solaris file format to allow specification of policy
    persistent flags.
  - Update audump to print the audit_control policy field.
  - Update auditd to read the audit_control policy field and set the kernel
    policy to match it when configuring/reconfiguring.  Remove the -s and -h
    arguments as these policies are now set via the configuration file.  If a
    policy line is not found in the configuration file, continue with the
    current default of setting AUDIT_CNT.
  - Fix bugs in the parsing of large execve(2) arguments and environmental
    variable tokens; increase maximum parsed argument and variable count.
  - configure now detects strlcat(), used by policy-related functions.
  - Reference token and record sample files added to test tree.
  Approved by:    re (kensmith)
  Revision     Changes    Path  +56 -1     src/contrib/openbsm/HISTORY  +3 -1      src/contrib/openbsm/TODO  +1 -1      src/contrib/openbsm/VERSION  +2 -2      src/contrib/openbsm/bin/audit/audit.c  +16 -1     src/contrib/openbsm/bin/auditd/audit_warn.c  +14 -8     src/contrib/openbsm/bin/auditd/auditd.8  +101 -42   src/contrib/openbsm/bin/auditd/auditd.c  +4 -2      src/contrib/openbsm/bin/auditd/auditd.h  +36 -7     src/contrib/openbsm/bin/auditreduce/auditreduce.1  +103 -17   src/contrib/openbsm/bin/auditreduce/auditreduce.c  +8 -1      src/contrib/openbsm/bin/auditreduce/auditreduce.h  +22 -7     src/contrib/openbsm/bsm/libbsm.h  +66 -0     src/contrib/openbsm/compat/strlcat.h (new)      +7 -4      src/contrib/openbsm/config/config.h  +3 -0      src/contrib/openbsm/config/  +13 -12    src/contrib/openbsm/configure  +3 -3      src/contrib/openbsm/      +4 -2      src/contrib/openbsm/etc/audit_control      +14 -7     src/contrib/openbsm/etc/audit_event  +47 -4     src/contrib/openbsm/libbsm/au_control.3  +6 -4      src/contrib/openbsm/libbsm/au_open.3  +310 -69   src/contrib/openbsm/libbsm/bsm_control.c  +10 -4     src/contrib/openbsm/libbsm/bsm_io.c  +1 -2      src/contrib/openbsm/libbsm/bsm_token.c  +12 -4     src/contrib/openbsm/libbsm/libbsm.3  +69 -2     src/contrib/openbsm/man/audit_control.5  +2 -2      src/contrib/openbsm/man/auditon.2  +2 -0      src/contrib/openbsm/test/reference/arg32_record (new)  +1 -0      src/contrib/openbsm/test/reference/arg32_token (new)  +3 -0      src/contrib/openbsm/test/reference/data_record (new)  +2 -0      src/contrib/openbsm/test/reference/data_token (new)  +2 -0      src/contrib/openbsm/test/reference/file_record (new)  +1 -0      src/contrib/openbsm/test/reference/file_token (new)  +2 -0      src/contrib/openbsm/test/reference/header32_token (new)  +2 -0      src/contrib/openbsm/test/reference/in_addr_record (new)  +1 -0      src/contrib/openbsm/test/reference/in_addr_token (new)  +2 -0      src/contrib/openbsm/test/reference/ip_record (new)  +1 -0      src/contrib/openbsm/test/reference/ip_token (new)  +2 -0      src/contrib/openbsm/test/reference/ipc_record (new)  +1 -0      src/contrib/openbsm/test/reference/ipc_token (new)  +2 -0      src/contrib/openbsm/test/reference/iport_record (new)  +1 -0      src/contrib/openbsm/test/reference/iport_token (new)  +2 -0      src/contrib/openbsm/test/reference/opaque_record (new)  +1 -0      src/contrib/openbsm/test/reference/opaque_token (new)  +2 -0      src/contrib/openbsm/test/reference/path_record (new)  +1 -0      src/contrib/openbsm/test/reference/path_token (new)  +2 -0      src/contrib/openbsm/test/reference/process32_record (new)  +1 -0      src/contrib/openbsm/test/reference/process32_token (new)  +2 -0      src/contrib/openbsm/test/reference/process32ex_record (new)  +1 -0      src/contrib/openbsm/test/reference/process32ex_token (new)  +2 -0      src/contrib/openbsm/test/reference/return32_record (new)  +1 -0      src/contrib/openbsm/test/reference/return32_token (new)  +2 -0      src/contrib/openbsm/test/reference/seq_record (new)  +1 -0      src/contrib/openbsm/test/reference/seq_token (new)  +2 -0      src/contrib/openbsm/test/reference/subject32_record (new)  +1 -0      src/contrib/openbsm/test/reference/subject32_token (new)  +2 -0      src/contrib/openbsm/test/reference/subject32ex_record (new)  +1 -0      src/contrib/openbsm/test/reference/subject32ex_token-IPv4 (new)  +1 -0      src/contrib/openbsm/test/reference/subject32ex_token-IPv6 (new)  +2 -0      src/contrib/openbsm/test/reference/text_record (new)  +1 -0      src/contrib/openbsm/test/reference/text_token (new)  +1 -0      src/contrib/openbsm/test/reference/trailer_token (new)  +2 -0      src/contrib/openbsm/test/samples/execve-long-args.trail (new)  +13 -3     src/contrib/openbsm/tools/audump.c
Received on Fri Sep 29 2006 - 22:41:56 UTC