Commit graph

135 commits

Author SHA1 Message Date
Fedora Release Engineering
3b76bcd11a Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild 2026-01-16 03:31:38 +00:00
Cropi
9a67d750d4 Adjust default config to avoid false positives in /etc 2025-10-16 09:46:00 +02:00
Cropi
c4ba6e2926 Add explanatory comment for /boot/grub2/grubenv exclusion
Document why /boot/grub2/grubenv is excluded from AIDE monitoring.  The
file's timestamp gets modified continuously due to the "boot_success"
implementation, which would cause unnecessary noise in security
monitoring reports.
Do not monitor link count in /var/log/journal
2025-10-09 09:42:32 +02:00
Cropi
8479fabb2f Accomodate for constantly changing log files
Many log files constantly change, especially if those are rotated.
Many of those files have changing xattrs, e2fsattrs, caps and acl(s).
So let's not monitor them, unless there will be many false positives.
2025-09-24 08:16:59 +02:00
Cropi
307529a587 Do not monitor acl on /var/log/journal 2025-09-23 14:59:21 +02:00
Cropi
5634fe3236 Adjust ordering of /root files 2025-09-23 12:17:43 +02:00
Cropi
2ed6802a1a Do not include mtime/ctime in regular files 2025-09-23 11:51:37 +02:00
Cropi
32855bb235 Update LOG in config file 2025-09-23 11:08:10 +02:00
Attila Lakatos
e8239e55d5 Merge #9 Add .rpmlintrc file 2025-09-23 07:46:52 +00:00
Cropi
c9baefb299 Add .rpmlintrc file 2025-09-23 09:36:35 +02:00
Cropi
d25ee9c764 Adjust /var/log/journal monitoring in default config file
By default, log files are expected to grow but persistent journal files are not handled correctly. The persistent journal is stored in /var/log/journal, hence fall into LOG rule.Unfortunately since some version of Fedora, the journal files get an extended attribute user.crtime_usec which updates when the file rotates.
Make sure to leave this out from the report.
2025-09-23 08:23:48 +02:00
Cropi
9566357ccc Remove deprecated config file /etc/nscd.conf
https://fedoraproject.org/wiki/Changes/RemoveNSCD
2025-09-17 11:29:15 +02:00
Cropi
8a1c97dba1 Replace ntp with chrony config files 2025-09-17 11:28:32 +02:00
Attila Lakatos
18145fe46d Merge #7 Modernize aide configuration file 2025-09-09 09:26:01 +00:00
Cropi
9201249285 Refactor aide.conf 2025-09-09 10:23:07 +02:00
Cropi
7aad76e824 Rebase to 0.19.2
Resolves: rhbz#2389391
Resolves: rhbz#2389389
CVE-2025-54389
CVE-2025-54409
2025-08-20 08:33:36 +02:00
Cropi
c19980c40c aide.conf: update (special) attributes section 2025-08-07 10:34:35 +02:00
Cropi
aa4fd80a61 aide.conf: correct report_url possible values 2025-08-07 10:34:29 +02:00
Cropi
faf0f7484f aide.conf: add missing fields to config (added since 0.17) 2025-08-07 10:34:08 +02:00
Cropi
8e0d851b93 cry: use nettle instead of gcrypt 2025-08-05 12:13:17 +02:00
Cropi
d45509d296 Rebase to 0.19.1 2025-08-05 11:38:04 +02:00
Cropi
f3c128e1ec spec: standardize source file reference syntax
Use consistent %{SOURCE#} macro syntax throughout the spec file
instead of mixing %{S:#} and %{SOURCE#} formats. This improves
readability and follows RPM packaging best practices.
2025-08-05 11:26:43 +02:00
Cropi
7b39911f4e Simplify URL handling 2025-08-05 11:23:42 +02:00
Fedora Release Engineering
4750c5ce8a Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-23 16:50:19 +00:00
Adam Williamson
3073404dcd Remove confusing and broken patch (#2346091)
Jian Peng noticed that this patch has multiple errors that cause
compilation to fail if it is applied. We did not notice because,
as the package stands, the patch is applied "normally" (by
%autosetup) and then immediately reverted (by the patch -R call)
before compilation occurs. So it's a confusing no-op.

Let's just remove it to avoid future confusion. If somebody wants
to re-add a fixed version of it, please ensure it works correctly
and the reason for its inclusion is documented in the spec file.
2025-02-24 14:48:55 -08:00
Patrik Koncity
c1f9cbad75 Add tmt CI 2025-01-31 10:50:52 +00:00
Fedora Release Engineering
204ac42bba Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-16 10:44:20 +00:00
Sandro Bonazzola
b3964ed95f Update aide to 0.18.8
- Update aide to 0.18.8
- Resolves fedora#2306506
- GPG verify source tarball
- Update project URL
- Remove unused patches
- Enable check phase during the build
- Require logrotate

Signed-off-by: Sandro Bonazzola <sbonazzo@redhat.com>
2024-12-04 14:06:36 +01:00
Fedora Release Engineering
ae0fb53e0d Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-17 16:44:18 +00:00
Radovan Sroka
a003ad04cf Fix verbose option
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2024-02-12 18:24:40 +01:00
Fedora Release Engineering
772571371f Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-22 22:47:57 +00:00
Fedora Release Engineering
e45ae0f104 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-19 12:26:41 +00:00
Radovan Sroka
a6083587f1 Rebase to 0.18.6
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2023-10-24 16:57:43 +02:00
Fedora Release Engineering
9d5d4a95e0 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-19 13:01:53 +00:00
Radovan Sroka
929cb09177
Updated aide.conf
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2023-06-21 14:25:29 +02:00
Radovan Sroka
1f9083fa05
Rebase to 1.18.4
- aide-0.18.4 is available
Resolves: rhbz#1910486
- Please port your pcre dependency to pcre2. Pcre has been deprecated
Resolves: rhbz#2128267

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2023-06-21 13:39:40 +02:00
Radovan Sroka
921cd675f0
- migrated to SPDX license
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2023-06-13 11:42:24 +02:00
Radovan Sroka
9d06054a81
- migrated to SPDX license
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2023-06-13 11:09:19 +02:00
Fedora Release Engineering
74f7f613ed Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-18 21:30:40 +00:00
Florian Weimer
2681d69152 Apply upstream patches to port configure to C99
Related to:

  <https://fedoraproject.org/wiki/Changes/PortingToModernC>
  <https://fedoraproject.org/wiki/Toolchain/PortingToModernC>
2022-11-25 12:02:26 +01:00
Fedora Release Engineering
3a3995cf3c Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-20 20:33:16 +00:00
Fedora Release Engineering
be7632bd59 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-01-19 21:02:08 +00:00
Fedora Release Engineering
262fe302ed - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-21 17:21:48 +00:00
Fedora Release Engineering
3e791cb9ee - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-21 12:26:29 +00:00
Fedora Release Engineering
0ddcbdc00e - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-25 23:54:23 +00:00
Fedora Release Engineering
894a715cea - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-31 23:52:02 +00:00
Fedora Release Engineering
300f8f187a - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-27 11:50:41 +00:00
Radovan Sroka
063fd0ec37
AIDE breaks when setting report_ignore_e2fsattrs
Resolves: rhbz#1850276

Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2020-06-24 11:57:32 +02:00
Fedora Release Engineering
2aa2897559 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-28 11:19:48 +00:00
Radovan Sroka
8998ee351b Backport some patches
Resolves: rhbz#1717140
2019-07-31 14:30:19 +02:00