commit audit for openSUSE:Factory
Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package audit for openSUSE:Factory checked in at 2021-12-01 20:46:08 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/audit (Old) and /work/SRC/openSUSE:Factory/.audit.new.31177 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "audit" Wed Dec 1 20:46:08 2021 rev:100 rq:934645 version:3.0.6 Changes: -------- --- /work/SRC/openSUSE:Factory/audit/audit-secondary.changes 2021-11-12 15:58:56.478556064 +0100 +++ /work/SRC/openSUSE:Factory/.audit.new.31177/audit-secondary.changes 2021-12-02 02:10:11.367589486 +0100 @@ -1,0 +2,11 @@ +Mon Nov 29 13:13:56 UTC 2021 - Fabian Vogt <fvogt@suse.com> + +- Use %autosetup +- Don't include sample rules as %doc, they're already installed + as normal files +- Fix create-augenrules-service.patch: + * auditd.service needs to require augenrules.service, + not the other way around +- Fix documentation for enable-stop-rules.patch + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ audit-secondary.spec ++++++ --- /var/tmp/diff_new_pack.Ka0ISK/_old 2021-12-02 02:10:12.215586900 +0100 +++ /var/tmp/diff_new_pack.Ka0ISK/_new 2021-12-02 02:10:12.219586888 +0100 @@ -125,18 +125,7 @@ rm -rf audisp/plugins/zos-remote/policy # we don't build prelude rm -rf audisp/plugins/prelude -%setup -q -n %{_name}-%{version} -%patch1 -p1 -%patch2 -p1 -%patch3 -p1 -%patch4 -p1 -%patch5 -p1 -%patch6 -p1 -%patch7 -p1 -%patch8 -p1 -%patch9 -p1 -%patch10 -p1 -%patch11 -p1 +%autosetup -p1 -n %{_name}-%{version} %if %{without python2} && %{with python3} # Fix python env call in tests if we only have Python3. @@ -252,7 +241,7 @@ %files -n audit %license COPYING -%doc README ChangeLog rules init.d/auditd.cron +%doc README ChangeLog init.d/auditd.cron %attr(644,root,root) %{_mandir}/man8/auditctl.8.gz %attr(644,root,root) %{_mandir}/man8/auditd.8.gz %attr(644,root,root) %{_mandir}/man8/aureport.8.gz ++++++ create-augenrules-service.patch ++++++ --- /var/tmp/diff_new_pack.Ka0ISK/_old 2021-12-02 02:10:12.295586656 +0100 +++ /var/tmp/diff_new_pack.Ka0ISK/_new 2021-12-02 02:10:12.295586656 +0100 @@ -1,10 +1,11 @@ +Index: audit-3.0.6/init.d/augenrules.service +=================================================================== --- /dev/null -+++ b/init.d/augenrules.service -@@ -0,0 +1,33 @@ ++++ audit-3.0.6/init.d/augenrules.service +@@ -0,0 +1,29 @@ +[Unit] +Description=auditd rules generation +After=auditd.service -+PartOf=auditd.service +Documentation=man:augenrules(8) + +[Service] @@ -31,12 +32,19 @@ +ProtectKernelTunables=true +ProtectKernelLogs=true +ReadWritePaths=/etc/audit -+ -+[Install] -+WantedBy=multi-user.target ---- a/init.d/auditd.service -+++ b/init.d/auditd.service -@@ -18,10 +18,8 @@ Documentation=man:auditd(8) https://gith +Index: audit-3.0.6/init.d/auditd.service +=================================================================== +--- audit-3.0.6.orig/init.d/auditd.service ++++ audit-3.0.6/init.d/auditd.service +@@ -13,15 +13,16 @@ Before=sysinit.target shutdown.target + Conflicts=shutdown.target + ConditionKernelCommandLine=!audit=0 + Documentation=man:auditd(8) https://github.com/linux-audit/audit-documentation ++Requires=augenrules.service ++# This unit clears rules on stop, so make sure that augenrules runs again ++PropagatesStopTo=augenrules.service + + [Service] Type=forking PIDFile=/run/auditd.pid ExecStart=/sbin/auditd @@ -45,11 +53,11 @@ -## NOTE: augenrules expect any rules to be added to /etc/audit/rules.d/ -ExecStartPost=-/sbin/augenrules --load +## To not use augenrules: copy this file to /etc/systemd/system/auditd.service, -+## uncomment the next line, and run "systemctl disable --now augenrules.service". ++## uncomment the next line, and comment the Requires=augenrules.service above. #ExecStartPost=-/sbin/auditctl -R /etc/audit/audit.rules - # By default we don't clear the rules on exit. To enable this, uncomment + # By default we clear the rules on exit. To disable this, comment # the next line after copying the file to /etc/systemd/system/auditd.service -@@ -42,7 +40,6 @@ ProtectClock=true +@@ -45,7 +46,6 @@ ProtectClock=true ProtectKernelTunables=true ProtectKernelLogs=true # end of automatic additions @@ -57,8 +65,10 @@ [Install] WantedBy=multi-user.target ---- a/init.d/Makefile.am -+++ b/init.d/Makefile.am +Index: audit-3.0.6/init.d/Makefile.am +=================================================================== +--- audit-3.0.6.orig/init.d/Makefile.am ++++ audit-3.0.6/init.d/Makefile.am @@ -26,7 +26,7 @@ EXTRA_DIST = auditd.init auditd.service auditd.cron libaudit.conf auditd.condrestart \ auditd.reload auditd.restart auditd.resume \ ++++++ enable-stop-rules.patch ++++++ --- /var/tmp/diff_new_pack.Ka0ISK/_old 2021-12-02 02:10:12.311586607 +0100 +++ /var/tmp/diff_new_pack.Ka0ISK/_new 2021-12-02 02:10:12.311586607 +0100 @@ -11,11 +11,16 @@ Signed-off-by: Enzo Matsumiya <ematsumiya@suse.de> ---- a/init.d/auditd.service -+++ b/init.d/auditd.service -@@ -25,7 +25,7 @@ ExecStartPost=-/sbin/augenrules --load +Index: audit-3.0.6/init.d/auditd.service +=================================================================== +--- audit-3.0.6.orig/init.d/auditd.service ++++ audit-3.0.6/init.d/auditd.service +@@ -23,9 +23,9 @@ ExecStart=/sbin/auditd + ## NOTE: augenrules expect any rules to be added to /etc/audit/rules.d/ + ExecStartPost=-/sbin/augenrules --load #ExecStartPost=-/sbin/auditctl -R /etc/audit/audit.rules - # By default we don't clear the rules on exit. To enable this, uncomment +-# By default we don't clear the rules on exit. To enable this, uncomment ++# By default we clear the rules on exit. To disable this, comment # the next line after copying the file to /etc/systemd/system/auditd.service -#ExecStopPost=/sbin/auditctl -R /etc/audit/audit-stop.rules +ExecStopPost=/sbin/auditctl -R /etc/audit/audit-stop.rules
participants (1)
-
Source-Sync