9 Commits

3 changed files with 147 additions and 107 deletions

View File

@@ -1,59 +0,0 @@
diff -ru audit-2.8.5.orig/init.d/auditd.conf audit-2.8.5/init.d/auditd.conf
--- audit-2.8.5.orig/init.d/auditd.conf 2019-03-01 21:19:13.000000000 +0100
+++ audit-2.8.5/init.d/auditd.conf 2019-05-27 10:02:17.350769165 +0200
@@ -13,7 +13,7 @@
num_logs = 5
priority_boost = 4
disp_qos = lossy
-dispatcher = /sbin/audispd
+dispatcher = /usr/sbin/audispd
name_format = NONE
##name = mydomain
max_log_file_action = ROTATE
diff -ru audit-2.8.5.orig/init.d/auditd.cron audit-2.8.5/init.d/auditd.cron
--- audit-2.8.5.orig/init.d/auditd.cron 2019-02-04 15:26:52.000000000 +0100
+++ audit-2.8.5/init.d/auditd.cron 2019-05-27 10:02:17.350769165 +0200
@@ -5,7 +5,7 @@
# based on a cron job.
##########
-/sbin/service auditd rotate
+/usr/sbin/service auditd rotate
EXITVALUE=$?
if [ $EXITVALUE != 0 ]; then
/usr/bin/logger -t auditd "ALERT exited abnormally with [$EXITVALUE]"
diff -ru audit-2.8.5.orig/init.d/auditd.service audit-2.8.5/init.d/auditd.service
--- audit-2.8.5.orig/init.d/auditd.service 2019-03-01 21:19:13.000000000 +0100
+++ audit-2.8.5/init.d/auditd.service 2019-05-27 10:02:56.066935836 +0200
@@ -18,15 +18,15 @@
[Service]
Type=forking
PIDFile=/run/auditd.pid
-ExecStart=/sbin/auditd
+ExecStart=/usr/sbin/auditd
## To not use augenrules, copy this file to /etc/systemd/system/auditd.service
## and comment/delete the next line and uncomment the auditctl line.
## NOTE: augenrules expect any rules to be added to /etc/audit/rules.d/
-ExecStartPost=-/sbin/augenrules --load
-#ExecStartPost=-/sbin/auditctl -R /etc/audit/audit.rules
+ExecStartPost=-/usr/sbin/augenrules --load
+#ExecStartPost=-/usr/sbin/auditctl -R /etc/audit/audit.rules
# By default we don't clear the rules on exit. To enable this, uncomment
# the next line after copying the file to /etc/systemd/system/auditd.service
-#ExecStopPost=/sbin/auditctl -R /etc/audit/audit-stop.rules
+#ExecStopPost=/usr/sbin/auditctl -R /etc/audit/audit-stop.rules
[Install]
WantedBy=multi-user.target
diff -ru audit-2.8.5.orig/init.d/augenrules audit-2.8.5/init.d/augenrules
--- audit-2.8.5.orig/init.d/augenrules 2019-02-04 15:26:52.000000000 +0100
+++ audit-2.8.5/init.d/augenrules 2019-05-27 10:02:17.354769182 +0200
@@ -39,7 +39,7 @@
try_load() {
if [ $LoadRules -eq 1 ] ; then
- /sbin/auditctl -R ${DestinationFile}
+ /usr/sbin/auditctl -R ${DestinationFile}
RETVAL=$?
fi
}

83
audit-3.0-usrsbin.patch Normal file
View File

@@ -0,0 +1,83 @@
diff -ru audit-3.0.orig/init.d/auditd.cron audit-3.0/init.d/auditd.cron
--- audit-3.0.orig/init.d/auditd.cron 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/init.d/auditd.cron 2021-02-13 20:44:43.484919856 +0100
@@ -5,7 +5,7 @@
# based on a cron job.
##########
-/sbin/service auditd rotate
+/usr/sbin/service auditd rotate
EXITVALUE=$?
if [ $EXITVALUE != 0 ]; then
/usr/bin/logger -t auditd "ALERT exited abnormally with [$EXITVALUE]"
diff -ru audit-3.0.orig/init.d/auditd.service audit-3.0/init.d/auditd.service
--- audit-3.0.orig/init.d/auditd.service 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/init.d/auditd.service 2021-02-13 20:44:43.484919856 +0100
@@ -18,15 +18,15 @@
[Service]
Type=forking
PIDFile=/run/auditd.pid
-ExecStart=/sbin/auditd
+ExecStart=/usr/sbin/auditd
## To not use augenrules, copy this file to /etc/systemd/system/auditd.service
## and comment/delete the next line and uncomment the auditctl line.
## NOTE: augenrules expect any rules to be added to /etc/audit/rules.d/
-ExecStartPost=-/sbin/augenrules --load
-#ExecStartPost=-/sbin/auditctl -R /etc/audit/audit.rules
+ExecStartPost=-/usr/sbin/augenrules --load
+#ExecStartPost=-/usr/sbin/auditctl -R /etc/audit/audit.rules
# By default we don't clear the rules on exit. To enable this, uncomment
# the next line after copying the file to /etc/systemd/system/auditd.service
-#ExecStopPost=/sbin/auditctl -R /etc/audit/audit-stop.rules
+#ExecStopPost=/usr/sbin/auditctl -R /etc/audit/audit-stop.rules
### Security Settings ###
MemoryDenyWriteExecute=true
diff -ru audit-3.0.orig/init.d/augenrules audit-3.0/init.d/augenrules
--- audit-3.0.orig/init.d/augenrules 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/init.d/augenrules 2021-02-13 20:44:43.485919874 +0100
@@ -39,7 +39,7 @@
try_load() {
if [ $LoadRules -eq 1 ] ; then
- /sbin/auditctl -R ${DestinationFile}
+ /usr/sbin/auditctl -R ${DestinationFile}
RETVAL=$?
fi
}
diff -ru audit-3.0.orig/audisp/plugins/remote/au-remote.conf audit-3.0/audisp/plugins/remote/au-remote.conf
--- audit-3.0.orig/audisp/plugins/remote/au-remote.conf 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/audisp/plugins/remote/au-remote.conf 2021-02-13 21:27:18.038655845 +0100
@@ -5,7 +5,7 @@
active = no
direction = out
-path = /sbin/audisp-remote
+path = /usr/sbin/audisp-remote
type = always
#args =
format = string
diff -ru audit-3.0.orig/audisp/plugins/syslog/syslog.conf audit-3.0/audisp/plugins/syslog/syslog.conf
--- audit-3.0.orig/audisp/plugins/syslog/syslog.conf 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/audisp/plugins/syslog/syslog.conf 2021-02-13 21:27:06.886482221 +0100
@@ -8,7 +8,7 @@
active = no
direction = out
-path = /sbin/audisp-syslog
+path = /usr/sbin/audisp-syslog
type = always
args = LOG_INFO
format = string
diff -ru audit-3.0.orig/audisp/plugins/zos-remote/audispd-zos-remote.conf audit-3.0/audisp/plugins/zos-remote/audispd-zos-remote.conf
--- audit-3.0.orig/audisp/plugins/zos-remote/audispd-zos-remote.conf 2020-12-16 21:44:34.000000000 +0100
+++ audit-3.0/audisp/plugins/zos-remote/audispd-zos-remote.conf 2021-02-13 21:26:36.495010422 +0100
@@ -8,7 +8,7 @@
active = no
direction = out
-path = /sbin/audispd-zos-remote
+path = /usr/sbin/audispd-zos-remote
type = always
args = /etc/audisp/zos-remote.conf
format = string

View File

@@ -1,41 +1,26 @@
Name: audit
Version: 3.0
Version: 3.1.1
Release: 1mamba
Summary: User space tools for kernel auditing
Group: System/Tools
Vendor: openmamba
Distribution: openmamba
Packager: Silvan Calarco <silvan.calarco@mambasoft.it>
URL: https://people.redhat.com/sgrubb/audit
URL: https://people.redhat.com/sgrubb/audit/
Source: http://people.redhat.com/sgrubb/audit/%{name}-%{version}.tar.gz
Patch0: audit-2.8.5-usrsbin.patch
Patch0: audit-3.0-usrsbin.patch
Patch1: audit-2.8.4-rundir.patch
License: GPL, LGPL
## AUTOBUILDREQ-BEGIN
BuildRequires: glibc-devel
BuildRequires: libcap-ng-devel
BuildRequires: libe2fs-devel
BuildRequires: libffi-devel
BuildRequires: libgcrypt-devel
BuildRequires: libgmp-devel
BuildRequires: libgnutls-devel
BuildRequires: libgpg-error-devel
BuildRequires: libidn-devel
BuildRequires: libkrb5-devel
BuildRequires: libltdl-devel
BuildRequires: libnettle-devel
BuildRequires: libnsl-devel
BuildRequires: libopenldap-devel
BuildRequires: libopenssl-devel
BuildRequires: libp11-kit-devel
BuildRequires: libprelude-devel
BuildRequires: libpython-devel
BuildRequires: libsasl2-devel
BuildRequires: libtasn1-devel
BuildRequires: libpython3-devel
BuildRequires: libtirpc-devel
BuildRequires: libunistring-devel
BuildRequires: libwrap-devel
BuildRequires: libz-devel
## AUTOBUILDREQ-END
BuildRequires: gcc-go
BuildRequires: libgo-devel
@@ -45,9 +30,9 @@ BuildRequires: libtool
BuildRequires: swig
BuildRequires: libprelude-devel >= 5.2.0
%systemd_requires
Requires: lib%{name} = %{?epoch:%epoch:}%{version}-%{release}
Provides: audit-plugins
Obsoletes: audit-plugins < 3.0
BuildRoot: %{_tmppath}/%{name}-%{version}-root
%description
The audit package contains the user space utilities for storing and searching the audit records generate by the audit subsystem in the Linux 2.6+ kernel.
@@ -88,6 +73,7 @@ Group: Development/Libraries
Summary: Python3 bindings to %{name}
Requires: python3
Requires: lib%{name} = %{?epoch:%epoch:}%{version}-%{release}
Obsoletes: python-audit < 3.0.8
%description -n python-audit-py3
The python-audit package containts Python 3 bindings to %{name}.
@@ -107,7 +93,8 @@ The libaudit-devel package contains the header files needed for developing appli
--with-libwrap \
--enable-gssapi-krb5=yes \
--with-libcap-ng=yes \
--with-python=yes \
--with-python=no \
--with-python3=yes \
--enable-systemd=yes \
CFLAGS="%{optflags} -fcommon" \
%ifarch arm
@@ -126,12 +113,12 @@ mkdir -p %{buildroot}%{_localstatedir}/log/audit
%makeinstall \
initdir=%{_unitdir}
rm -f %{buildroot}%{python_sitearch}/_audit.a
rm -f %{buildroot}%{python_sitearch}/_audit.la
rm -f %{buildroot}%{python_sitearch}/_auparse.a
rm -f %{buildroot}%{python_sitearch}/_auparse.la
rm -f %{buildroot}%{python_sitearch}/auparse.a
rm -f %{buildroot}%{python_sitearch}/auparse.la
#rm -f %{buildroot}%{python_sitearch}/_audit.a
#rm -f %{buildroot}%{python_sitearch}/_audit.la
#rm -f %{buildroot}%{python_sitearch}/_auparse.a
#rm -f %{buildroot}%{python_sitearch}/_auparse.la
#rm -f %{buildroot}%{python_sitearch}/auparse.a
#rm -f %{buildroot}%{python_sitearch}/auparse.la
install -d -m 0755 %{buildroot}%{_sysconfdir}/audit/rules.d
@@ -142,6 +129,10 @@ make check
[ "%{buildroot}" != / ] && rm -rf "%{buildroot}"
%post
if [ $1 -gt 1 ]; then
# fix /sbin -> /usr/sbin paths on upgrade
sed -i "s|path = /sbin/|path = /usr/sbin/|" %{_sysconfdir}/audit/plugins.d/*.conf
fi
%systemd_post auditd
if [ $1 -eq 1 -o -e /etc/rc5.d/S11auditd ]; then
systemctl -q daemon-reload
@@ -185,8 +176,7 @@ find /etc/rc[0-6].d/ -type l -xtype l -exec rm -f {} \;
%{_libexecdir}/initscripts/legacy-actions/auditd/*
%attr(750,root,root) %dir %{_localstatedir}/log/audit
%attr(750,root,root) %{_sbindir}/audispd-zos-remote
%attr(750,root,root) %{_sbindir}/audisp-remote
%attr(750,root,root) %{_sbindir}/audisp-syslog
%attr(750,root,root) %{_sbindir}/audisp-*
%attr(750,root,root) %{_sbindir}/auditctl
%attr(750,root,root) %{_sbindir}/auditd
%attr(750,root,root) %{_sbindir}/augenrules
@@ -197,18 +187,15 @@ find /etc/rc[0-6].d/ -type l -xtype l -exec rm -f {} \;
%attr(755,root,root) %{_bindir}/aulastlog
%attr(755,root,root) %{_bindir}/ausyscall
%attr(750,root,root) %{_bindir}/auvirt
%ifnarch arm aarch64
%dir %{_prefix}/lib/golang/src/pkg/redhat.com/audit
%endif
%{_mandir}/man5/auditd.conf.5*
%{_mandir}/man5/ausearch-expression.5*
%{_mandir}/man5/auditd-plugins.5*
%{_mandir}/man5/zos-remote.conf.5*
%{_mandir}/man7/*.7*
%{_mandir}/man5/audisp-remote.conf.5*
%{_mandir}/man5/libaudit.conf.5*
%{_mandir}/man8/audispd-zos-remote.8*
%{_mandir}/man8/audisp-remote.8*
%{_mandir}/man8/audisp-syslog.8*
%{_mandir}/man8/audisp-*.8*
%{_mandir}/man8/auditctl.8*
%{_mandir}/man8/auditd.8*
%{_mandir}/man8/augenrules.8*
@@ -225,7 +212,7 @@ find /etc/rc[0-6].d/ -type l -xtype l -exec rm -f {} \;
%config(noreplace) %attr(640,root,root) %{_sysconfdir}/libaudit.conf
%{_libdir}/libaudit.so.*
%{_libdir}/libauparse.so.*
%{_mandir}/man5/libaudit.conf.5*
%{_libexecdir}/audit-functions
%doc AUTHORS COPYING
%files -n lib%{name}-devel
@@ -235,15 +222,14 @@ find /etc/rc[0-6].d/ -type l -xtype l -exec rm -f {} \;
%{_includedir}/libaudit.h
%{_libdir}/libaudit.so
%{_libdir}/libauparse.so
%{_libdir}/libaudit.la
%{_libdir}/libauparse.la
%{_libdir}/pkgconfig/auparse.pc
%{_libdir}/pkgconfig/audit.pc
%ifnarch arm aarch64
%ifnarch arm
%dir %{_prefix}/lib/golang/src/pkg/redhat.com/audit
%{_prefix}/lib/golang/src/pkg/redhat.com/audit/audit.go
%endif
%{_datadir}/aclocal/audit.m4
%{_mandir}/man3/*.3.gz
%{_mandir}/man3/*.3*
#%doc contrib/skeleton.c contrib/plugin
#%doc ChangeLog README THANKS TODO
@@ -252,20 +238,50 @@ find /etc/rc[0-6].d/ -type l -xtype l -exec rm -f {} \;
%{_libdir}/libaudit.a
%{_libdir}/libauparse.a
%files -n python-audit
%defattr(-,root,root)
%{python_sitearch}/_audit.*
%{python_sitearch}/audit.py*
%{python_sitearch}/auparse.*
#%files -n python-audit
#%defattr(-,root,root)
#%{python_sitearch}/_audit.*
#%{python_sitearch}/audit.py*
#%{python_sitearch}/auparse.*
%files -n python-audit-py3
%defattr(-,root,root)
%{python3_sitearch}/_audit.*
%{python3_sitearch}/audit.py
%{python3_sitearch}/__pycache__/audit.cpython-*.pyc
%{python3_sitearch}/auparse.*
%{python3_sitelib}/_audit.*
%{python3_sitelib}/audit.py
%{python3_sitelib}/__pycache__/audit.cpython-*.pyc
%{python3_sitelib}/auparse.*
%changelog
* Sat Apr 29 2023 Automatic Build System <autodist@mambasoft.it> 3.1.1-1mamba
- automatic version update by autodist
* Sun Feb 12 2023 Automatic Build System <autodist@mambasoft.it> 3.1-1mamba
- automatic version update by autodist
* Tue Aug 30 2022 Automatic Build System <autodist@mambasoft.it> 3.0.9-1mamba
- automatic version update by autodist
* Sat Apr 02 2022 Silvan Calarco <silvan.calarco@mambasoft.it> 3.0.8-1mamba
- update to 3.0.8
* Tue Jan 25 2022 Automatic Build System <autodist@mambasoft.it> 3.0.7-1mamba
- automatic version update by autodist
* Mon Nov 01 2021 Silvan Calarco <silvan.calarco@mambasoft.it> 3.0.6-2mamba
- audit: added versioned requirement for libaudit
* Sun Oct 03 2021 Automatic Build System <autodist@mambasoft.it> 3.0.6-1mamba
- automatic version update by autodist
* Tue Aug 24 2021 Automatic Build System <autodist@mambasoft.it> 3.0.5-1mamba
- automatic version update by autodist
* Sun Feb 14 2021 Automatic Build System <autodist@mambasoft.it> 3.0.1-1mamba
- automatic version update by autodist
* Sat Feb 13 2021 Silvan Calarco <silvan.calarco@mambasoft.it> 3.0-2mamba
- reapply /usr/sbin patch
* Tue Feb 09 2021 Automatic Build System <autodist@mambasoft.it> 3.0-1mamba
- automatic version update by autodist