Page MenuHomeFreeBSD

auditd: Support logging directly to syslog
Needs ReviewPublic

Authored by des on Wed, Sep 30, 1:38 PM.
Tags
None
Referenced Files
F174415841: D60172.diff
Sat, Oct 3, 1:08 AM
F174330277: D60172.id.diff
Fri, Oct 2, 11:06 AM
Unknown Object (File)
Fri, Oct 2, 6:56 AM
Unknown Object (File)
Fri, Oct 2, 4:43 AM
Unknown Object (File)
Thu, Oct 1, 1:20 AM
Unknown Object (File)
Thu, Oct 1, 1:20 AM
Unknown Object (File)
Thu, Oct 1, 1:15 AM
Unknown Object (File)
Thu, Oct 1, 12:47 AM
Subscribers

Details

Reviewers
None
Group Reviewers
Klara
Summary

Every tenth call to auditwarnlog(), check that the audit_warn(5) script
exists and is executable by us. If it is, execute it as previously;
otherwise, fall back to calling syslog(3) directly.

Additionally, if we choose to use the script and fail, also log the
original message to syslogd, not just the fact that we failed to log.

We could record the result of trying to execute the script, but that
would require pausing while it runs (or at least until the execve(2)
call has completed).

Retesting every tenth call is a little clunky but avoids having to
restart or signal auditd(8) to force it to notice a change in
availability, or adding a command-line option and / or modifying the
audit_control(5) syntax to let the user express a preference.

MFC after: 1 week
Sponsored by: Klara, Inc.
Sponsored by: Qualys, Inc.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77527
Build 74410: arc lint + arc unit