Every tenth call to auditwarnlog(), check that the audit_warn(5) script
exists and is executable by us. If it is, execute it as previously;
otherwise, fall back to calling syslog(3) directly.
Additionally, if we choose to use the script and fail, also log the
original message to syslogd, not just the fact that we failed to log.
We could record the result of trying to execute the script, but that
would require pausing while it runs (or at least until the execve(2)
call has completed).
Retesting every tenth call is a little clunky but avoids having to
restart or signal auditd(8) to force it to notice a change in
availability, or adding a command-line option and / or modifying the
audit_control(5) syntax to let the user express a preference.
MFC after: 1 week
Sponsored by: Klara, Inc.
Sponsored by: Qualys, Inc.