Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
auparse: do not interpret fE as a capability field
The file effective capability is a boolean. It is being interpreted as the capability "chown" by auparse. Just print its raw value. An example from an execve syscall: type=BPRM_FCAPS msg=audit(03/07/2017 17:29:56.494:969) : fver=2 fp=sys_admin fi=none fe=chown old_pp=none old_pi=none old_pe=none new_pp=sys_admin new_pi=none new_pe=sys_admin Fixed: type=BPRM_FCAPS msg=audit(03/07/2017 17:29:56.494:969) : fver=2 fp=sys_admin fi=none fe=1 old_pp=none old_pi=none old_pe=none new_pp=sys_admin new_pi=none new_pe=sys_admin See: #18 Signed-off-by: Richard Guy Briggs <rgb@redhat.com>
- Loading branch information