From 2d8d978d82073e0320d0980e65a7e232c428ab39 Mon Sep 17 00:00:00 2001 From: Gitea Date: Wed, 6 Jul 2022 13:58:36 +0200 Subject: [PATCH] committing changes in /etc after apt run Package changes: +aide-common 0.17.3-4+deb11u1 all +altermime 0.3.10-12 amd64 +bsd-mailx 8.1.2-0.20180807cvs-2 amd64 +dovecot-core 1:2.3.13+dfsg1-2 amd64 +libdbd-mysql-perl 4.050-3+b1 amd64 +logwatch 7.5.5-1 all +postfix 3.5.6-1+b1 amd64 +postfix-mysql 3.5.6-1+b1 amd64 +postfix-pcre 3.5.6-1+b1 amd64 +postfix-sqlite 3.5.6-1+b1 amd64 --- .etckeeper | 205 ++++- aide/aide.conf | 189 ++++ aide/aide.conf.d/10_aide_constants | 2 + aide/aide.conf.d/10_aide_distribution | 20 + aide/aide.conf.d/10_aide_hostname | 28 + aide/aide.conf.d/10_aide_logext | 8 + aide/aide.conf.d/10_aide_machineid | 10 + aide/aide.conf.d/10_aide_prevyear | 3 + aide/aide.conf.d/10_aide_run | 10 + aide/aide.conf.d/10_aide_year | 16 + aide/aide.conf.d/20_aide_run_systemd-journald | 8 + aide/aide.conf.d/21_aide_run_agetty | 1 + aide/aide.conf.d/30_aide_apache2 | 5 + aide/aide.conf.d/30_aide_bind9 | 19 + aide/aide.conf.d/30_inn2_vars | 10 + aide/aide.conf.d/31_aide_acpid | 6 + aide/aide.conf.d/31_aide_adjtime | 1 + aide/aide.conf.d/31_aide_aide | 11 + aide/aide.conf.d/31_aide_alsa | 1 + aide/aide.conf.d/31_aide_amanda-client | 9 + aide/aide.conf.d/31_aide_amanda-server | 119 +++ aide/aide.conf.d/31_aide_amavisd-new | 13 + aide/aide.conf.d/31_aide_anacron | 2 + aide/aide.conf.d/31_aide_anubis | 1 + aide/aide.conf.d/31_aide_apache2 | 19 + aide/aide.conf.d/31_aide_apcupsd | 3 + aide/aide.conf.d/31_aide_apt | 103 +++ aide/aide.conf.d/31_aide_apt-cacher-ng | 58 ++ aide/aide.conf.d/31_aide_apt-listbugs | 2 + aide/aide.conf.d/31_aide_apt-listchanges | 1 + aide/aide.conf.d/31_aide_apt-show-versions | 2 + aide/aide.conf.d/31_aide_aptitude | 13 + aide/aide.conf.d/31_aide_at | 2 + aide/aide.conf.d/31_aide_atop | 10 + aide/aide.conf.d/31_aide_avahi-daemon | 3 + aide/aide.conf.d/31_aide_bind9 | 18 + aide/aide.conf.d/31_aide_boinc-client | 16 + aide/aide.conf.d/31_aide_borgbackup | 12 + aide/aide.conf.d/31_aide_btmp | 2 + aide/aide.conf.d/31_aide_cereal | 19 + aide/aide.conf.d/31_aide_checksecurity | 6 + aide/aide.conf.d/31_aide_chrony | 2 + aide/aide.conf.d/31_aide_clamav | 8 + aide/aide.conf.d/31_aide_clamav-freshclam | 12 + .../31_aide_clamav-unofficial-sigs | 15 + aide/aide.conf.d/31_aide_console-log | 3 + aide/aide.conf.d/31_aide_console-setup | 2 + aide/aide.conf.d/31_aide_courier-authlib | 2 + aide/aide.conf.d/31_aide_cracklib-runtime | 1 + aide/aide.conf.d/31_aide_cron | 1 + aide/aide.conf.d/31_aide_cron-apt | 16 + aide/aide.conf.d/31_aide_cups | 25 + aide/aide.conf.d/31_aide_dbus | 2 + aide/aide.conf.d/31_aide_dcc-common | 2 + aide/aide.conf.d/31_aide_ddclient | 2 + aide/aide.conf.d/31_aide_debconf | 2 + aide/aide.conf.d/31_aide_debsecan | 2 + aide/aide.conf.d/31_aide_dehydrated | 17 + aide/aide.conf.d/31_aide_dev | 25 + aide/aide.conf.d/31_aide_dlocate | 2 + aide/aide.conf.d/31_aide_dmeventd | 1 + aide/aide.conf.d/31_aide_dokuwiki | 6 + aide/aide.conf.d/31_aide_dovecot | 11 + aide/aide.conf.d/31_aide_dpkg | 17 + aide/aide.conf.d/31_aide_e2fsprogs | 1 + aide/aide.conf.d/31_aide_etckeeper | 5 + aide/aide.conf.d/31_aide_exim4 | 12 + aide/aide.conf.d/31_aide_exim4_exiscan | 5 + aide/aide.conf.d/31_aide_exim4_logs | 10 + aide/aide.conf.d/31_aide_fail2ban | 7 + aide/aide.conf.d/31_aide_fake-hwclock | 2 + aide/aide.conf.d/31_aide_fcron | 3 + aide/aide.conf.d/31_aide_findutils | 2 + aide/aide.conf.d/31_aide_gnupg | 1 + aide/aide.conf.d/31_aide_hald | 2 + aide/aide.conf.d/31_aide_haproxy | 5 + aide/aide.conf.d/31_aide_hapsd | 1 + aide/aide.conf.d/31_aide_icinga2 | 21 + aide/aide.conf.d/31_aide_ifplugd | 2 + aide/aide.conf.d/31_aide_ifupdown | 1 + aide/aide.conf.d/31_aide_inetd | 1 + aide/aide.conf.d/31_aide_initramfs-tools | 6 + aide/aide.conf.d/31_aide_initscripts | 9 + aide/aide.conf.d/31_aide_inn2 | 25 + aide/aide.conf.d/31_aide_ippl | 2 + aide/aide.conf.d/31_aide_isc-dhcp-client | 5 + aide/aide.conf.d/31_aide_isc-dhcp-server | 3 + aide/aide.conf.d/31_aide_kerberos | 6 + aide/aide.conf.d/31_aide_laptop-mode-tools | 3 + aide/aide.conf.d/31_aide_lastlog | 1 + .../31_aide_libapache2-mod-fastcgi | 2 + aide/aide.conf.d/31_aide_libvirt-bin | 24 + aide/aide.conf.d/31_aide_lighttpd | 10 + aide/aide.conf.d/31_aide_lldpd | 3 + aide/aide.conf.d/31_aide_locales | 2 + aide/aide.conf.d/31_aide_logcheck | 2 + aide/aide.conf.d/31_aide_logrotate | 4 + aide/aide.conf.d/31_aide_lpd | 3 + aide/aide.conf.d/31_aide_lvm2 | 6 + aide/aide.conf.d/31_aide_mail | 2 + aide/aide.conf.d/31_aide_mailman | 26 + aide/aide.conf.d/31_aide_man | 7 + aide/aide.conf.d/31_aide_mdadm | 3 + aide/aide.conf.d/31_aide_mini-buildd | 15 + aide/aide.conf.d/31_aide_mlocate | 4 + aide/aide.conf.d/31_aide_modules | 1 + aide/aide.conf.d/31_aide_munin | 69 ++ aide/aide.conf.d/31_aide_munin-nodes | 23 + aide/aide.conf.d/31_aide_mysql-server | 9 + aide/aide.conf.d/31_aide_needrestart | 1 + aide/aide.conf.d/31_aide_network | 2 + aide/aide.conf.d/31_aide_network-manager | 4 + aide/aide.conf.d/31_aide_nfs | 8 + aide/aide.conf.d/31_aide_nrpe | 2 + aide/aide.conf.d/31_aide_nscd | 3 + aide/aide.conf.d/31_aide_nslcd | 2 + aide/aide.conf.d/31_aide_ntp-server | 6 + aide/aide.conf.d/31_aide_openvpn | 1 + aide/aide.conf.d/31_aide_openvpn-server | 6 + aide/aide.conf.d/31_aide_opie-server | 1 + aide/aide.conf.d/31_aide_pam_motd | 1 + aide/aide.conf.d/31_aide_pcscd | 2 + aide/aide.conf.d/31_aide_php-common | 4 + aide/aide.conf.d/31_aide_php-fpm | 6 + aide/aide.conf.d/31_aide_php7 | 3 + aide/aide.conf.d/31_aide_pm-utils | 1 + aide/aide.conf.d/31_aide_portmap | 2 + aide/aide.conf.d/31_aide_postfix | 40 + aide/aide.conf.d/31_aide_postfix-cluebringer | 2 + aide/aide.conf.d/31_aide_postgresql | 23 + aide/aide.conf.d/31_aide_postgrey | 4 + aide/aide.conf.d/31_aide_privoxy | 1 + aide/aide.conf.d/31_aide_proftpd | 4 + aide/aide.conf.d/31_aide_resolvconf | 5 + aide/aide.conf.d/31_aide_rkhunter | 8 + aide/aide.conf.d/31_aide_rngd | 1 + aide/aide.conf.d/31_aide_root-dotfiles | 4 + aide/aide.conf.d/31_aide_rsnapshot | 4 + aide/aide.conf.d/31_aide_rsyslog | 9 + aide/aide.conf.d/31_aide_run_systemd_netif | 3 + aide/aide.conf.d/31_aide_run_systemd_resolve | 2 + aide/aide.conf.d/31_aide_run_tmpfiles | 2 + aide/aide.conf.d/31_aide_runuser | 13 + aide/aide.conf.d/31_aide_samba | 19 + aide/aide.conf.d/31_aide_saslauthd | 4 + aide/aide.conf.d/31_aide_screen | 5 + aide/aide.conf.d/31_aide_slapd | 10 + aide/aide.conf.d/31_aide_slrn | 1 + aide/aide.conf.d/31_aide_smartmontools | 4 + aide/aide.conf.d/31_aide_smokeping | 10 + aide/aide.conf.d/31_aide_sniproxy | 6 + aide/aide.conf.d/31_aide_snmpd | 3 + aide/aide.conf.d/31_aide_spamassassin | 22 + aide/aide.conf.d/31_aide_spampd | 2 + aide/aide.conf.d/31_aide_squid | 4 + aide/aide.conf.d/31_aide_ssh-agent | 2 + aide/aide.conf.d/31_aide_ssh-server | 2 + aide/aide.conf.d/31_aide_sshd | 2 + aide/aide.conf.d/31_aide_sudo | 5 + aide/aide.conf.d/31_aide_svn-server | 18 + aide/aide.conf.d/31_aide_syslog-ng | 4 + aide/aide.conf.d/31_aide_systemd | 44 + aide/aide.conf.d/31_aide_systemd-cron | 2 + aide/aide.conf.d/31_aide_systemd-journald | 16 + aide/aide.conf.d/31_aide_systemd-machined | 1 + aide/aide.conf.d/31_aide_systemd-networkd | 5 + aide/aide.conf.d/31_aide_systemd-resolved | 3 + aide/aide.conf.d/31_aide_systemd_journal | 15 + aide/aide.conf.d/31_aide_systemd_sessions | 4 + aide/aide.conf.d/31_aide_tiger | 15 + aide/aide.conf.d/31_aide_torrus | 33 + aide/aide.conf.d/31_aide_trac | 15 + aide/aide.conf.d/31_aide_tt-rss | 7 + aide/aide.conf.d/31_aide_udev | 75 ++ aide/aide.conf.d/31_aide_unbound | 3 + aide/aide.conf.d/31_aide_util-linux | 3 + aide/aide.conf.d/31_aide_utmp | 1 + aide/aide.conf.d/31_aide_vpnc | 1 + aide/aide.conf.d/31_aide_vsftpd | 2 + aide/aide.conf.d/31_aide_webalizer | 6 + aide/aide.conf.d/31_aide_wpasupplicant | 11 + aide/aide.conf.d/31_aide_wtmp | 2 + aide/aide.conf.d/31_aide_x11-common | 1 + aide/aide.conf.d/31_aide_x11-xkb-utils | 1 + aide/aide.conf.d/31_aide_xdm | 3 + aide/aide.conf.d/31_aide_xe-guest-utilities | 3 + aide/aide.conf.d/31_aide_xinetd | 1 + aide/aide.conf.d/70_aide_dev | 17 + aide/aide.conf.d/70_aide_etc | 1 + aide/aide.conf.d/70_aide_proc_sys | 3 + aide/aide.conf.d/70_aide_run | 5 + aide/aide.conf.d/70_aide_tmp | 3 + aide/aide.conf.d/70_aide_var | 2 + aide/aide.conf.d/99_aide_root | 3 + aide/aide.settings.d/10_aide_sourceslist | 12 + aide/aide.settings.d/31_aide_apt_settings | 4 + .../31_aide_svn-server_settings | 3 + aide/aide.settings.d/31_aide_torrus_settings | 4 + aide/aide.settings.d/31_aide_trac_settings | 3 + aliases.db | Bin 0 -> 12288 bytes alternatives/Mail | 1 + alternatives/Mail.1.gz | 1 + alternatives/mail | 1 + alternatives/mail.1.gz | 1 + alternatives/mailx | 1 + alternatives/mailx.1.gz | 1 + cron.daily/00logwatch | 10 + cron.daily/aide | 845 ++++++++++++++++++ default/aide | 109 +++ mail.rc | 2 + rc0.d/K01postfix | 1 + rc1.d/K01postfix | 1 + rc2.d/S01postfix | 1 + rc3.d/S01postfix | 1 + rc4.d/S01postfix | 1 + rc5.d/S01postfix | 1 + rc6.d/K01postfix | 1 + .../multi-user.target.wants/postfix.service | 1 + 218 files changed, 3132 insertions(+), 2 deletions(-) create mode 100644 aide/aide.conf create mode 100644 aide/aide.conf.d/10_aide_constants create mode 100755 aide/aide.conf.d/10_aide_distribution create mode 100755 aide/aide.conf.d/10_aide_hostname create mode 100644 aide/aide.conf.d/10_aide_logext create mode 100755 aide/aide.conf.d/10_aide_machineid create mode 100755 aide/aide.conf.d/10_aide_prevyear create mode 100644 aide/aide.conf.d/10_aide_run create mode 100755 aide/aide.conf.d/10_aide_year create mode 100755 aide/aide.conf.d/20_aide_run_systemd-journald create mode 100644 aide/aide.conf.d/21_aide_run_agetty create mode 100755 aide/aide.conf.d/30_aide_apache2 create mode 100755 aide/aide.conf.d/30_aide_bind9 create mode 100755 aide/aide.conf.d/30_inn2_vars create mode 100644 aide/aide.conf.d/31_aide_acpid create mode 100644 aide/aide.conf.d/31_aide_adjtime create mode 100644 aide/aide.conf.d/31_aide_aide create mode 100644 aide/aide.conf.d/31_aide_alsa create mode 100644 aide/aide.conf.d/31_aide_amanda-client create mode 100755 aide/aide.conf.d/31_aide_amanda-server create mode 100644 aide/aide.conf.d/31_aide_amavisd-new create mode 100644 aide/aide.conf.d/31_aide_anacron create mode 100644 aide/aide.conf.d/31_aide_anubis create mode 100644 aide/aide.conf.d/31_aide_apache2 create mode 100644 aide/aide.conf.d/31_aide_apcupsd create mode 100755 aide/aide.conf.d/31_aide_apt create mode 100644 aide/aide.conf.d/31_aide_apt-cacher-ng create mode 100644 aide/aide.conf.d/31_aide_apt-listbugs create mode 100644 aide/aide.conf.d/31_aide_apt-listchanges create mode 100644 aide/aide.conf.d/31_aide_apt-show-versions create mode 100644 aide/aide.conf.d/31_aide_aptitude create mode 100644 aide/aide.conf.d/31_aide_at create mode 100644 aide/aide.conf.d/31_aide_atop create mode 100644 aide/aide.conf.d/31_aide_avahi-daemon create mode 100644 aide/aide.conf.d/31_aide_bind9 create mode 100644 aide/aide.conf.d/31_aide_boinc-client create mode 100644 aide/aide.conf.d/31_aide_borgbackup create mode 100644 aide/aide.conf.d/31_aide_btmp create mode 100644 aide/aide.conf.d/31_aide_cereal create mode 100644 aide/aide.conf.d/31_aide_checksecurity create mode 100644 aide/aide.conf.d/31_aide_chrony create mode 100644 aide/aide.conf.d/31_aide_clamav create mode 100644 aide/aide.conf.d/31_aide_clamav-freshclam create mode 100644 aide/aide.conf.d/31_aide_clamav-unofficial-sigs create mode 100644 aide/aide.conf.d/31_aide_console-log create mode 100644 aide/aide.conf.d/31_aide_console-setup create mode 100644 aide/aide.conf.d/31_aide_courier-authlib create mode 100644 aide/aide.conf.d/31_aide_cracklib-runtime create mode 100644 aide/aide.conf.d/31_aide_cron create mode 100644 aide/aide.conf.d/31_aide_cron-apt create mode 100644 aide/aide.conf.d/31_aide_cups create mode 100644 aide/aide.conf.d/31_aide_dbus create mode 100644 aide/aide.conf.d/31_aide_dcc-common create mode 100644 aide/aide.conf.d/31_aide_ddclient create mode 100644 aide/aide.conf.d/31_aide_debconf create mode 100644 aide/aide.conf.d/31_aide_debsecan create mode 100644 aide/aide.conf.d/31_aide_dehydrated create mode 100644 aide/aide.conf.d/31_aide_dev create mode 100644 aide/aide.conf.d/31_aide_dlocate create mode 100644 aide/aide.conf.d/31_aide_dmeventd create mode 100644 aide/aide.conf.d/31_aide_dokuwiki create mode 100644 aide/aide.conf.d/31_aide_dovecot create mode 100644 aide/aide.conf.d/31_aide_dpkg create mode 100644 aide/aide.conf.d/31_aide_e2fsprogs create mode 100644 aide/aide.conf.d/31_aide_etckeeper create mode 100644 aide/aide.conf.d/31_aide_exim4 create mode 100644 aide/aide.conf.d/31_aide_exim4_exiscan create mode 100644 aide/aide.conf.d/31_aide_exim4_logs create mode 100644 aide/aide.conf.d/31_aide_fail2ban create mode 100644 aide/aide.conf.d/31_aide_fake-hwclock create mode 100644 aide/aide.conf.d/31_aide_fcron create mode 100644 aide/aide.conf.d/31_aide_findutils create mode 100644 aide/aide.conf.d/31_aide_gnupg create mode 100644 aide/aide.conf.d/31_aide_hald create mode 100644 aide/aide.conf.d/31_aide_haproxy create mode 100644 aide/aide.conf.d/31_aide_hapsd create mode 100644 aide/aide.conf.d/31_aide_icinga2 create mode 100644 aide/aide.conf.d/31_aide_ifplugd create mode 100644 aide/aide.conf.d/31_aide_ifupdown create mode 100644 aide/aide.conf.d/31_aide_inetd create mode 100644 aide/aide.conf.d/31_aide_initramfs-tools create mode 100644 aide/aide.conf.d/31_aide_initscripts create mode 100644 aide/aide.conf.d/31_aide_inn2 create mode 100644 aide/aide.conf.d/31_aide_ippl create mode 100644 aide/aide.conf.d/31_aide_isc-dhcp-client create mode 100644 aide/aide.conf.d/31_aide_isc-dhcp-server create mode 100644 aide/aide.conf.d/31_aide_kerberos create mode 100644 aide/aide.conf.d/31_aide_laptop-mode-tools create mode 100644 aide/aide.conf.d/31_aide_lastlog create mode 100644 aide/aide.conf.d/31_aide_libapache2-mod-fastcgi create mode 100644 aide/aide.conf.d/31_aide_libvirt-bin create mode 100644 aide/aide.conf.d/31_aide_lighttpd create mode 100644 aide/aide.conf.d/31_aide_lldpd create mode 100644 aide/aide.conf.d/31_aide_locales create mode 100644 aide/aide.conf.d/31_aide_logcheck create mode 100644 aide/aide.conf.d/31_aide_logrotate create mode 100644 aide/aide.conf.d/31_aide_lpd create mode 100644 aide/aide.conf.d/31_aide_lvm2 create mode 100644 aide/aide.conf.d/31_aide_mail create mode 100644 aide/aide.conf.d/31_aide_mailman create mode 100644 aide/aide.conf.d/31_aide_man create mode 100644 aide/aide.conf.d/31_aide_mdadm create mode 100644 aide/aide.conf.d/31_aide_mini-buildd create mode 100644 aide/aide.conf.d/31_aide_mlocate create mode 100644 aide/aide.conf.d/31_aide_modules create mode 100644 aide/aide.conf.d/31_aide_munin create mode 100755 aide/aide.conf.d/31_aide_munin-nodes create mode 100644 aide/aide.conf.d/31_aide_mysql-server create mode 100644 aide/aide.conf.d/31_aide_needrestart create mode 100644 aide/aide.conf.d/31_aide_network create mode 100644 aide/aide.conf.d/31_aide_network-manager create mode 100644 aide/aide.conf.d/31_aide_nfs create mode 100644 aide/aide.conf.d/31_aide_nrpe create mode 100644 aide/aide.conf.d/31_aide_nscd create mode 100644 aide/aide.conf.d/31_aide_nslcd create mode 100644 aide/aide.conf.d/31_aide_ntp-server create mode 100644 aide/aide.conf.d/31_aide_openvpn create mode 100644 aide/aide.conf.d/31_aide_openvpn-server create mode 100644 aide/aide.conf.d/31_aide_opie-server create mode 100644 aide/aide.conf.d/31_aide_pam_motd create mode 100644 aide/aide.conf.d/31_aide_pcscd create mode 100644 aide/aide.conf.d/31_aide_php-common create mode 100644 aide/aide.conf.d/31_aide_php-fpm create mode 100644 aide/aide.conf.d/31_aide_php7 create mode 100644 aide/aide.conf.d/31_aide_pm-utils create mode 100644 aide/aide.conf.d/31_aide_portmap create mode 100644 aide/aide.conf.d/31_aide_postfix create mode 100644 aide/aide.conf.d/31_aide_postfix-cluebringer create mode 100644 aide/aide.conf.d/31_aide_postgresql create mode 100644 aide/aide.conf.d/31_aide_postgrey create mode 100644 aide/aide.conf.d/31_aide_privoxy create mode 100644 aide/aide.conf.d/31_aide_proftpd create mode 100644 aide/aide.conf.d/31_aide_resolvconf create mode 100644 aide/aide.conf.d/31_aide_rkhunter create mode 100644 aide/aide.conf.d/31_aide_rngd create mode 100644 aide/aide.conf.d/31_aide_root-dotfiles create mode 100644 aide/aide.conf.d/31_aide_rsnapshot create mode 100644 aide/aide.conf.d/31_aide_rsyslog create mode 100644 aide/aide.conf.d/31_aide_run_systemd_netif create mode 100644 aide/aide.conf.d/31_aide_run_systemd_resolve create mode 100644 aide/aide.conf.d/31_aide_run_tmpfiles create mode 100644 aide/aide.conf.d/31_aide_runuser create mode 100644 aide/aide.conf.d/31_aide_samba create mode 100644 aide/aide.conf.d/31_aide_saslauthd create mode 100644 aide/aide.conf.d/31_aide_screen create mode 100644 aide/aide.conf.d/31_aide_slapd create mode 100644 aide/aide.conf.d/31_aide_slrn create mode 100644 aide/aide.conf.d/31_aide_smartmontools create mode 100644 aide/aide.conf.d/31_aide_smokeping create mode 100644 aide/aide.conf.d/31_aide_sniproxy create mode 100644 aide/aide.conf.d/31_aide_snmpd create mode 100644 aide/aide.conf.d/31_aide_spamassassin create mode 100644 aide/aide.conf.d/31_aide_spampd create mode 100644 aide/aide.conf.d/31_aide_squid create mode 100644 aide/aide.conf.d/31_aide_ssh-agent create mode 100644 aide/aide.conf.d/31_aide_ssh-server create mode 100644 aide/aide.conf.d/31_aide_sshd create mode 100644 aide/aide.conf.d/31_aide_sudo create mode 100755 aide/aide.conf.d/31_aide_svn-server create mode 100644 aide/aide.conf.d/31_aide_syslog-ng create mode 100644 aide/aide.conf.d/31_aide_systemd create mode 100644 aide/aide.conf.d/31_aide_systemd-cron create mode 100644 aide/aide.conf.d/31_aide_systemd-journald create mode 100644 aide/aide.conf.d/31_aide_systemd-machined create mode 100644 aide/aide.conf.d/31_aide_systemd-networkd create mode 100644 aide/aide.conf.d/31_aide_systemd-resolved create mode 100644 aide/aide.conf.d/31_aide_systemd_journal create mode 100644 aide/aide.conf.d/31_aide_systemd_sessions create mode 100644 aide/aide.conf.d/31_aide_tiger create mode 100755 aide/aide.conf.d/31_aide_torrus create mode 100755 aide/aide.conf.d/31_aide_trac create mode 100644 aide/aide.conf.d/31_aide_tt-rss create mode 100644 aide/aide.conf.d/31_aide_udev create mode 100644 aide/aide.conf.d/31_aide_unbound create mode 100644 aide/aide.conf.d/31_aide_util-linux create mode 100644 aide/aide.conf.d/31_aide_utmp create mode 100644 aide/aide.conf.d/31_aide_vpnc create mode 100644 aide/aide.conf.d/31_aide_vsftpd create mode 100644 aide/aide.conf.d/31_aide_webalizer create mode 100644 aide/aide.conf.d/31_aide_wpasupplicant create mode 100644 aide/aide.conf.d/31_aide_wtmp create mode 100644 aide/aide.conf.d/31_aide_x11-common create mode 100644 aide/aide.conf.d/31_aide_x11-xkb-utils create mode 100644 aide/aide.conf.d/31_aide_xdm create mode 100644 aide/aide.conf.d/31_aide_xe-guest-utilities create mode 100644 aide/aide.conf.d/31_aide_xinetd create mode 100644 aide/aide.conf.d/70_aide_dev create mode 100644 aide/aide.conf.d/70_aide_etc create mode 100644 aide/aide.conf.d/70_aide_proc_sys create mode 100644 aide/aide.conf.d/70_aide_run create mode 100644 aide/aide.conf.d/70_aide_tmp create mode 100644 aide/aide.conf.d/70_aide_var create mode 100644 aide/aide.conf.d/99_aide_root create mode 100755 aide/aide.settings.d/10_aide_sourceslist create mode 100755 aide/aide.settings.d/31_aide_apt_settings create mode 100755 aide/aide.settings.d/31_aide_svn-server_settings create mode 100755 aide/aide.settings.d/31_aide_torrus_settings create mode 100755 aide/aide.settings.d/31_aide_trac_settings create mode 100644 aliases.db create mode 120000 alternatives/Mail create mode 120000 alternatives/Mail.1.gz create mode 120000 alternatives/mail create mode 120000 alternatives/mail.1.gz create mode 120000 alternatives/mailx create mode 120000 alternatives/mailx.1.gz create mode 100755 cron.daily/00logwatch create mode 100755 cron.daily/aide create mode 100644 default/aide create mode 100644 mail.rc create mode 120000 rc0.d/K01postfix create mode 120000 rc1.d/K01postfix create mode 120000 rc2.d/S01postfix create mode 120000 rc3.d/S01postfix create mode 120000 rc4.d/S01postfix create mode 120000 rc5.d/S01postfix create mode 120000 rc6.d/K01postfix create mode 120000 systemd/system/multi-user.target.wants/postfix.service diff --git a/.etckeeper b/.etckeeper index 365e817c..0ac852b8 100755 --- a/.etckeeper +++ b/.etckeeper @@ -1,8 +1,6 @@ # Generated by etckeeper. Do not edit. mkdir -p './X11/xkb' -mkdir -p './aide/aide.conf.d' -mkdir -p './aide/aide.settings.d' mkdir -p './apache2/mods-available' mkdir -p './apm/event.d' mkdir -p './apparmor.d/disable' @@ -79,9 +77,208 @@ maybe chmod 0644 'X11/Xsession.d/90gpg-agent' maybe chmod 0755 'X11/xkb' maybe chmod 0644 'adduser.conf' maybe chmod 0755 'aide' +maybe chmod 0644 'aide/aide.conf' maybe chmod 0755 'aide/aide.conf.d' +maybe chmod 0644 'aide/aide.conf.d/10_aide_constants' +maybe chmod 0755 'aide/aide.conf.d/10_aide_distribution' +maybe chmod 0755 'aide/aide.conf.d/10_aide_hostname' +maybe chmod 0644 'aide/aide.conf.d/10_aide_logext' +maybe chmod 0755 'aide/aide.conf.d/10_aide_machineid' +maybe chmod 0755 'aide/aide.conf.d/10_aide_prevyear' +maybe chmod 0644 'aide/aide.conf.d/10_aide_run' +maybe chmod 0755 'aide/aide.conf.d/10_aide_year' +maybe chmod 0755 'aide/aide.conf.d/20_aide_run_systemd-journald' +maybe chmod 0644 'aide/aide.conf.d/21_aide_run_agetty' +maybe chmod 0755 'aide/aide.conf.d/30_aide_apache2' +maybe chmod 0755 'aide/aide.conf.d/30_aide_bind9' +maybe chmod 0755 'aide/aide.conf.d/30_inn2_vars' +maybe chmod 0644 'aide/aide.conf.d/31_aide_acpid' +maybe chmod 0644 'aide/aide.conf.d/31_aide_adjtime' +maybe chmod 0644 'aide/aide.conf.d/31_aide_aide' +maybe chmod 0644 'aide/aide.conf.d/31_aide_alsa' +maybe chmod 0644 'aide/aide.conf.d/31_aide_amanda-client' +maybe chmod 0755 'aide/aide.conf.d/31_aide_amanda-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_amavisd-new' +maybe chmod 0644 'aide/aide.conf.d/31_aide_anacron' +maybe chmod 0644 'aide/aide.conf.d/31_aide_anubis' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apache2' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apcupsd' +maybe chmod 0755 'aide/aide.conf.d/31_aide_apt' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-cacher-ng' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listbugs' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listchanges' +maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-show-versions' +maybe chmod 0644 'aide/aide.conf.d/31_aide_aptitude' +maybe chmod 0644 'aide/aide.conf.d/31_aide_at' +maybe chmod 0644 'aide/aide.conf.d/31_aide_atop' +maybe chmod 0644 'aide/aide.conf.d/31_aide_avahi-daemon' +maybe chmod 0644 'aide/aide.conf.d/31_aide_bind9' +maybe chmod 0644 'aide/aide.conf.d/31_aide_boinc-client' +maybe chmod 0644 'aide/aide.conf.d/31_aide_borgbackup' +maybe chmod 0644 'aide/aide.conf.d/31_aide_btmp' +maybe chmod 0644 'aide/aide.conf.d/31_aide_cereal' +maybe chmod 0644 'aide/aide.conf.d/31_aide_checksecurity' +maybe chmod 0644 'aide/aide.conf.d/31_aide_chrony' +maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav' +maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-freshclam' +maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-unofficial-sigs' +maybe chmod 0644 'aide/aide.conf.d/31_aide_console-log' +maybe chmod 0644 'aide/aide.conf.d/31_aide_console-setup' +maybe chmod 0644 'aide/aide.conf.d/31_aide_courier-authlib' +maybe chmod 0644 'aide/aide.conf.d/31_aide_cracklib-runtime' +maybe chmod 0644 'aide/aide.conf.d/31_aide_cron' +maybe chmod 0644 'aide/aide.conf.d/31_aide_cron-apt' +maybe chmod 0644 'aide/aide.conf.d/31_aide_cups' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dbus' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dcc-common' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ddclient' +maybe chmod 0644 'aide/aide.conf.d/31_aide_debconf' +maybe chmod 0644 'aide/aide.conf.d/31_aide_debsecan' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dehydrated' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dev' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dlocate' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dmeventd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dokuwiki' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dovecot' +maybe chmod 0644 'aide/aide.conf.d/31_aide_dpkg' +maybe chmod 0644 'aide/aide.conf.d/31_aide_e2fsprogs' +maybe chmod 0644 'aide/aide.conf.d/31_aide_etckeeper' +maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4' +maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4_exiscan' +maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4_logs' +maybe chmod 0644 'aide/aide.conf.d/31_aide_fail2ban' +maybe chmod 0644 'aide/aide.conf.d/31_aide_fake-hwclock' +maybe chmod 0644 'aide/aide.conf.d/31_aide_fcron' +maybe chmod 0644 'aide/aide.conf.d/31_aide_findutils' +maybe chmod 0644 'aide/aide.conf.d/31_aide_gnupg' +maybe chmod 0644 'aide/aide.conf.d/31_aide_hald' +maybe chmod 0644 'aide/aide.conf.d/31_aide_haproxy' +maybe chmod 0644 'aide/aide.conf.d/31_aide_hapsd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_icinga2' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ifplugd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ifupdown' +maybe chmod 0644 'aide/aide.conf.d/31_aide_inetd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_initramfs-tools' +maybe chmod 0644 'aide/aide.conf.d/31_aide_initscripts' +maybe chmod 0644 'aide/aide.conf.d/31_aide_inn2' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ippl' +maybe chmod 0644 'aide/aide.conf.d/31_aide_isc-dhcp-client' +maybe chmod 0644 'aide/aide.conf.d/31_aide_isc-dhcp-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_kerberos' +maybe chmod 0644 'aide/aide.conf.d/31_aide_laptop-mode-tools' +maybe chmod 0644 'aide/aide.conf.d/31_aide_lastlog' +maybe chmod 0644 'aide/aide.conf.d/31_aide_libapache2-mod-fastcgi' +maybe chmod 0644 'aide/aide.conf.d/31_aide_libvirt-bin' +maybe chmod 0644 'aide/aide.conf.d/31_aide_lighttpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_lldpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_locales' +maybe chmod 0644 'aide/aide.conf.d/31_aide_logcheck' +maybe chmod 0644 'aide/aide.conf.d/31_aide_logrotate' +maybe chmod 0644 'aide/aide.conf.d/31_aide_lpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_lvm2' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mail' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mailman' +maybe chmod 0644 'aide/aide.conf.d/31_aide_man' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mdadm' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mini-buildd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mlocate' +maybe chmod 0644 'aide/aide.conf.d/31_aide_modules' +maybe chmod 0644 'aide/aide.conf.d/31_aide_munin' +maybe chmod 0755 'aide/aide.conf.d/31_aide_munin-nodes' +maybe chmod 0644 'aide/aide.conf.d/31_aide_mysql-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_needrestart' +maybe chmod 0644 'aide/aide.conf.d/31_aide_network' +maybe chmod 0644 'aide/aide.conf.d/31_aide_network-manager' +maybe chmod 0644 'aide/aide.conf.d/31_aide_nfs' +maybe chmod 0644 'aide/aide.conf.d/31_aide_nrpe' +maybe chmod 0644 'aide/aide.conf.d/31_aide_nscd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_nslcd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ntp-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_openvpn' +maybe chmod 0644 'aide/aide.conf.d/31_aide_openvpn-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_opie-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_pam_motd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_pcscd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_php-common' +maybe chmod 0644 'aide/aide.conf.d/31_aide_php-fpm' +maybe chmod 0644 'aide/aide.conf.d/31_aide_php7' +maybe chmod 0644 'aide/aide.conf.d/31_aide_pm-utils' +maybe chmod 0644 'aide/aide.conf.d/31_aide_portmap' +maybe chmod 0644 'aide/aide.conf.d/31_aide_postfix' +maybe chmod 0644 'aide/aide.conf.d/31_aide_postfix-cluebringer' +maybe chmod 0644 'aide/aide.conf.d/31_aide_postgresql' +maybe chmod 0644 'aide/aide.conf.d/31_aide_postgrey' +maybe chmod 0644 'aide/aide.conf.d/31_aide_privoxy' +maybe chmod 0644 'aide/aide.conf.d/31_aide_proftpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_resolvconf' +maybe chmod 0644 'aide/aide.conf.d/31_aide_rkhunter' +maybe chmod 0644 'aide/aide.conf.d/31_aide_rngd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_root-dotfiles' +maybe chmod 0644 'aide/aide.conf.d/31_aide_rsnapshot' +maybe chmod 0644 'aide/aide.conf.d/31_aide_rsyslog' +maybe chmod 0644 'aide/aide.conf.d/31_aide_run_systemd_netif' +maybe chmod 0644 'aide/aide.conf.d/31_aide_run_systemd_resolve' +maybe chmod 0644 'aide/aide.conf.d/31_aide_run_tmpfiles' +maybe chmod 0644 'aide/aide.conf.d/31_aide_runuser' +maybe chmod 0644 'aide/aide.conf.d/31_aide_samba' +maybe chmod 0644 'aide/aide.conf.d/31_aide_saslauthd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_screen' +maybe chmod 0644 'aide/aide.conf.d/31_aide_slapd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_slrn' +maybe chmod 0644 'aide/aide.conf.d/31_aide_smartmontools' +maybe chmod 0644 'aide/aide.conf.d/31_aide_smokeping' +maybe chmod 0644 'aide/aide.conf.d/31_aide_sniproxy' +maybe chmod 0644 'aide/aide.conf.d/31_aide_snmpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_spamassassin' +maybe chmod 0644 'aide/aide.conf.d/31_aide_spampd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_squid' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-agent' +maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_sshd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_sudo' +maybe chmod 0755 'aide/aide.conf.d/31_aide_svn-server' +maybe chmod 0644 'aide/aide.conf.d/31_aide_syslog-ng' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-cron' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-journald' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-machined' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-networkd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-resolved' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd_journal' +maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd_sessions' +maybe chmod 0644 'aide/aide.conf.d/31_aide_tiger' +maybe chmod 0755 'aide/aide.conf.d/31_aide_torrus' +maybe chmod 0755 'aide/aide.conf.d/31_aide_trac' +maybe chmod 0644 'aide/aide.conf.d/31_aide_tt-rss' +maybe chmod 0644 'aide/aide.conf.d/31_aide_udev' +maybe chmod 0644 'aide/aide.conf.d/31_aide_unbound' +maybe chmod 0644 'aide/aide.conf.d/31_aide_util-linux' +maybe chmod 0644 'aide/aide.conf.d/31_aide_utmp' +maybe chmod 0644 'aide/aide.conf.d/31_aide_vpnc' +maybe chmod 0644 'aide/aide.conf.d/31_aide_vsftpd' +maybe chmod 0644 'aide/aide.conf.d/31_aide_webalizer' +maybe chmod 0644 'aide/aide.conf.d/31_aide_wpasupplicant' +maybe chmod 0644 'aide/aide.conf.d/31_aide_wtmp' +maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-common' +maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-xkb-utils' +maybe chmod 0644 'aide/aide.conf.d/31_aide_xdm' +maybe chmod 0644 'aide/aide.conf.d/31_aide_xe-guest-utilities' +maybe chmod 0644 'aide/aide.conf.d/31_aide_xinetd' +maybe chmod 0644 'aide/aide.conf.d/70_aide_dev' +maybe chmod 0644 'aide/aide.conf.d/70_aide_etc' +maybe chmod 0644 'aide/aide.conf.d/70_aide_proc_sys' +maybe chmod 0644 'aide/aide.conf.d/70_aide_run' +maybe chmod 0644 'aide/aide.conf.d/70_aide_tmp' +maybe chmod 0644 'aide/aide.conf.d/70_aide_var' +maybe chmod 0644 'aide/aide.conf.d/99_aide_root' maybe chmod 0755 'aide/aide.settings.d' +maybe chmod 0755 'aide/aide.settings.d/10_aide_sourceslist' +maybe chmod 0755 'aide/aide.settings.d/31_aide_apt_settings' +maybe chmod 0755 'aide/aide.settings.d/31_aide_svn-server_settings' +maybe chmod 0755 'aide/aide.settings.d/31_aide_torrus_settings' +maybe chmod 0755 'aide/aide.settings.d/31_aide_trac_settings' maybe chmod 0644 'aliases' +maybe chmod 0644 'aliases.db' maybe chmod 0755 'alternatives' maybe chmod 0644 'alternatives/README' maybe chmod 0755 'amavis' @@ -414,6 +611,8 @@ maybe chmod 0644 'cron.d/kernel' maybe chmod 0644 'cron.d/php' maybe chmod 0755 'cron.daily' maybe chmod 0644 'cron.daily/.placeholder' +maybe chmod 0755 'cron.daily/00logwatch' +maybe chmod 0755 'cron.daily/aide' maybe chmod 0755 'cron.daily/apt-compat' maybe chmod 0755 'cron.daily/chkrootkit' maybe chmod 0755 'cron.daily/dpkg' @@ -441,6 +640,7 @@ maybe chmod 0755 'dbus-1/system.d' maybe chmod 0644 'debconf.conf' maybe chmod 0644 'debian_version' maybe chmod 0755 'default' +maybe chmod 0644 'default/aide' maybe chmod 0644 'default/amavisd-snmp-subagent' maybe chmod 0644 'default/console-setup' maybe chmod 0644 'default/cron' @@ -3621,6 +3821,7 @@ maybe chmod 0444 'machine-id' maybe chmod 0644 'magic' maybe chmod 0644 'magic.mime' maybe chmod 0755 'mail' +maybe chmod 0644 'mail.rc' maybe chmod 0755 'mail/m4' maybe chmod 0644 'mail/m4/opendkim.m4' maybe chmod 0644 'mailcap' diff --git a/aide/aide.conf b/aide/aide.conf new file mode 100644 index 00000000..e47918ac --- /dev/null +++ b/aide/aide.conf @@ -0,0 +1,189 @@ +# AIDE conf + +# set environment for executable config files included by x_include +@@x_include_setenv UPAC_settingsd /etc/aide/aide.settings.d + +# The daily cron job depends on these paths +database_in=file:/var/lib/aide/aide.db +database_out=file:/var/lib/aide/aide.db.new +database_new=file:/var/lib/aide/aide.db.new +gzip_dbout=yes + +# Set to no to disable report_summarize_changes option. +report_summarize_changes=yes + +# Set to no to disable grouping of files in report. +report_grouped=yes + +# Set verbosity of aide run and reports +log_level=warning +report_level=changed_attributes + +# Set to yes to print the checksums in the report in hex format +report_base16 = no + +# if you want to sacrifice security for speed, remove some of these +# checksums. +Checksums = sha256+sha512+rmd160+haval+gost+crc32+tiger+whirlpool + +# The checksums of the databases to be printed in the report +# Set to 'E' to disable. +database_attrs = Checksums + +# check permissions, owner, group and file type +OwnerMode = p+u+g+ftype + +# Check size and block count +Size = s+b + +# Files that stay static +InodeData = OwnerMode+n+i+Size+l+X +StaticFile = m+c+Checksums + +# Files that stay static but are copied to a ram disk on startup +# (causing different inode) +RamdiskData = InodeData-i + +# Check everything +Full = InodeData+StaticFile + +# Files that change their mtimes or ctimes but not their contents +VarTime = InodeData+Checksums + +# Files that are recreated regularly but do not change their contents +VarInode = VarTime-i + +# Files that change their contents during system operation +VarFile = OwnerMode+n+l+X + +# Directories that change their contents during system operation +VarDir = OwnerMode+n+i+X + +# Directories that are recreated regularly and change their contents +VarDirInode = OwnerMode+n+X + +# Directories that change their mtimes or ctimes but not their contents +VarDirTime = InodeData + +# Logs are special: they are continously written to, may be compressed +# have their file name changed in different, mutually incompatibly ways +# and apprear and vanish at will. Handling this is a a complex and error- +# prone issue. +# +# This is best broken down in a number of small tasks: +# +# +# (A) +# While a live log is being written to, it doesn't change its mode and +# inode and its size only increases. +# +# (B) +# When a live log is rotated for the first time, it should not change +# its mode, may change its inode, and its size decreases. The size +# decrease may not be noticed by aide if the file had size x at the last +# aide run, was rotated in the mean time and was written to so that it +# had a size > x at the next aide run. +# +# (C) +# When a log is compressed, this looks to aide like the uncompressed +# file vanished (or was replaced by another file) and the compressed +# file appeared out of the blue. There is (currently) no way to +# associate the (gone) uncompressed file's contents with the (new) +# compressed file's contents +# +# (D) +# The actual log rotation may rename foo.{x}.bar to foo.{x+1}.bar without +# changing the other properties of the file +# +# (E) +# If only a given number of log generations is to be kept, foo.{y}.bar may +# vanish, but usually only when no foo.{z}.bar exists for z>y. +# +# (F) +# The set of files foo.{x}.bar to foo.{y}.bar is called a "log series" +# in aide terms, with the lowest x being called the "LoSerMember" element +# and the highest y being called the "HiSerMember" element, and the z +# with x/dev/null | awk '{print "@@define " $1 " " $2}' FS="=" + diff --git a/aide/aide.conf.d/10_aide_logext b/aide/aide.conf.d/10_aide_logext new file mode 100644 index 00000000..00be9be1 --- /dev/null +++ b/aide/aide.conf.d/10_aide_logext @@ -0,0 +1,8 @@ +# this variable is pulled in to places where logs are rotated +# if you have modified your log rotation mechanisms to use different +# comprssion tools, you can change the extension here. +# This changes the behavior for all aide rules, so if you have +# only changed part of your log rotation mechanisms, you still +# need to touch the respective rules. + +@@define LOGEXT gz diff --git a/aide/aide.conf.d/10_aide_machineid b/aide/aide.conf.d/10_aide_machineid new file mode 100755 index 00000000..1ad1419e --- /dev/null +++ b/aide/aide.conf.d/10_aide_machineid @@ -0,0 +1,10 @@ +#!/bin/bash + +MIDFILE="/etc/machine-id" +MACHINEID="0000000000000000000" +if [ -r "$MIDFILE" ]; then + MACHINEID="$(head -n1 /etc/machine-id)" +fi + +printf "@@define MACHINEID %s\\n" "$MACHINEID" + diff --git a/aide/aide.conf.d/10_aide_prevyear b/aide/aide.conf.d/10_aide_prevyear new file mode 100755 index 00000000..c77a8e29 --- /dev/null +++ b/aide/aide.conf.d/10_aide_prevyear @@ -0,0 +1,3 @@ +#!/bin/sh + +echo "@@define PREVYEAR4D $(date +%Y --date="last year")" diff --git a/aide/aide.conf.d/10_aide_run b/aide/aide.conf.d/10_aide_run new file mode 100644 index 00000000..d1bfd185 --- /dev/null +++ b/aide/aide.conf.d/10_aide_run @@ -0,0 +1,10 @@ +# Please note: always remove leading and trailing slashes in path macros +# var/run -> run +@@ifndef RUN +@@define RUN run +@@endif +# var/lock -> run/lock +@@ifndef RUNLOCK +@@define RUNLOCK run/lock +@@endif + diff --git a/aide/aide.conf.d/10_aide_year b/aide/aide.conf.d/10_aide_year new file mode 100755 index 00000000..a2e77466 --- /dev/null +++ b/aide/aide.conf.d/10_aide_year @@ -0,0 +1,16 @@ +#!/bin/sh + +printf "@@define YEAR4D %s\\n" "$(date +%Y)" +printf "@@define LASTYEAR4D %s\\n" "$(date +%Y --date='last year')" + +# this will generate a lot of alarms on January 1st. If you want +# to sleep in on New Year, consider using the following code snippet +# which, in January, generates a regexp that matches both the current +# year and the previous year. This should prevent aide reports to be +# generated on the New Year. It is assumed that the aide database will +# be regenerated at least once in January. +#if [ "$(date +%m)" = "01" ]; then +# printf "@@define YEAR4D (%s|%s)\\n" "$(date +%Y)" "$(date +%Y --date='last year')" +#else +# printf "@@define YEAR4D %s\\n" "$(date +%Y)" +#fi diff --git a/aide/aide.conf.d/20_aide_run_systemd-journald b/aide/aide.conf.d/20_aide_run_systemd-journald new file mode 100755 index 00000000..756b1765 --- /dev/null +++ b/aide/aide.conf.d/20_aide_run_systemd-journald @@ -0,0 +1,8 @@ +#!/bin/bash + +if [ -d "/var/log/journal" ]; then + printf "@@define SYSTEMD_JOURNAL var/log/journal\\n" +else + printf "@@define SYSTEMD_JOURNAL @@{RUN}/log/journal\\n" +fi + diff --git a/aide/aide.conf.d/21_aide_run_agetty b/aide/aide.conf.d/21_aide_run_agetty new file mode 100644 index 00000000..98413c2f --- /dev/null +++ b/aide/aide.conf.d/21_aide_run_agetty @@ -0,0 +1 @@ +/@@{RUN}/agetty\\.reload$ f VarFile diff --git a/aide/aide.conf.d/30_aide_apache2 b/aide/aide.conf.d/30_aide_apache2 new file mode 100755 index 00000000..4535e295 --- /dev/null +++ b/aide/aide.conf.d/30_aide_apache2 @@ -0,0 +1,5 @@ +#!/bin/bash + +if [ -e /etc/apache2/mods-enabled/suexec.load ]; then + echo "@@define APACHE2_SUEXEC 1" +fi diff --git a/aide/aide.conf.d/30_aide_bind9 b/aide/aide.conf.d/30_aide_bind9 new file mode 100755 index 00000000..ca7defca --- /dev/null +++ b/aide/aide.conf.d/30_aide_bind9 @@ -0,0 +1,19 @@ +#! /bin/bash +# this script automatically sets the BINDCHROOT variable to the +# directory that bind chroots to via configuration in +# /etc/default/bind9. This is only going to work if your /etc/default/bind9 +# is not too modified. +# +# If you want to use this magic, just uncomment it. +# You can also manually set the chroot directory in a non-executable +# file: @@define BINDCHROOT /var/cache/bind + +# # Automagically extract chroot directory +# . /etc/default/bind9 +# set $OPTIONS +# for i in $@;do +# if [ "$1" == "-t" ] +# then echo "@@define BINDCHROOT $2"; break +# else shift +# fi +# done diff --git a/aide/aide.conf.d/30_inn2_vars b/aide/aide.conf.d/30_inn2_vars new file mode 100755 index 00000000..26c5b8f9 --- /dev/null +++ b/aide/aide.conf.d/30_inn2_vars @@ -0,0 +1,10 @@ +#!/bin/bash + +if [ -e /etc/news/innfeed.conf ]; then + echo -n "@@define INN2_INNFEED_OUTFEEDS (" +< /etc/news/innfeed.conf \ + sed -n '/^[[:space:]]*peer[[:space:]]\+/{s/^[[:space:]]*peer[[:space:]]\+\([-.[:alnum:]]\+\).*/\1/;p;}' | \ + tr '\n' '|' |\ + sed 's/|$/)/' + echo +fi diff --git a/aide/aide.conf.d/31_aide_acpid b/aide/aide.conf.d/31_aide_acpid new file mode 100644 index 00000000..8b8c7099 --- /dev/null +++ b/aide/aide.conf.d/31_aide_acpid @@ -0,0 +1,6 @@ +/var/log/acpid$ f Log +/var/log/acpid\\.1$ f LowLog +/var/log/acpid\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/acpid\\.3\\.@@{LOGEXT}$ f SerMemberLog +/var/log/acpid\\.4\\.@@{LOGEXT}$ f HiSerMemberLog +/@@{RUN}/acpid\\.(socket|pid)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_adjtime b/aide/aide.conf.d/31_aide_adjtime new file mode 100644 index 00000000..0f42261c --- /dev/null +++ b/aide/aide.conf.d/31_aide_adjtime @@ -0,0 +1 @@ +/etc/adjtime$ f VarFile diff --git a/aide/aide.conf.d/31_aide_aide b/aide/aide.conf.d/31_aide_aide new file mode 100644 index 00000000..205f7c9e --- /dev/null +++ b/aide/aide.conf.d/31_aide_aide @@ -0,0 +1,11 @@ +/var/lib/aide/aide\\.db(\\.new)?$ f VarFile +/var/lib/aide$ d VarDir +/var/log/aide/aide\\.log(\\.0)?$ f LowLog +/var/log/aide/aide\\.log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/aide/aide\\.log\\.[2-5]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/aide/aide\\.log\\.6\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log/aide$ d VarDir +/@@{RUN}/aide$ d VarDirInode +!/@@{RUN}/aide/cron\\.daily\\.lock$ f +!/var/tmp/aide\\.cron\\.daily$ d +!/var/tmp/aide\\.cron\\.daily/((error|a(run|err))log|mailfile)$ f diff --git a/aide/aide.conf.d/31_aide_alsa b/aide/aide.conf.d/31_aide_alsa new file mode 100644 index 00000000..b1bea386 --- /dev/null +++ b/aide/aide.conf.d/31_aide_alsa @@ -0,0 +1 @@ +/var/lib/alsa/asound\\.state$ f VarFile diff --git a/aide/aide.conf.d/31_aide_amanda-client b/aide/aide.conf.d/31_aide_amanda-client new file mode 100644 index 00000000..8ade0d7e --- /dev/null +++ b/aide/aide.conf.d/31_aide_amanda-client @@ -0,0 +1,9 @@ +@@define AMANDALOG var/log/amanda + +/var/lib/dumpdates$ f VarFile +!/@@{AMANDALOG}/amandad/amandad\\.@@{YEAR4D}[0-9]{10}\\.debug$ f +/@@{AMANDALOG}/(amandad|client)$ d VarDir +@@ifdef AMANDABACKUPSET +/@@{AMANDALOG}/client/@@{AMANDABACKUPSET}$ d VarDir +@@endif +!/@@{AMANDALOG}/client/[^/]+/(sendsize|killpgrp|sendbackup|selfcheck)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f diff --git a/aide/aide.conf.d/31_aide_amanda-server b/aide/aide.conf.d/31_aide_amanda-server new file mode 100755 index 00000000..57507795 --- /dev/null +++ b/aide/aide.conf.d/31_aide_amanda-server @@ -0,0 +1,119 @@ +#!/bin/bash + +# this is not consistently generating restricted rules. If you have +# an amanda host, please help by adding the appropriate restrictions + +MULTILINEDLE=0 + +skip_multiline_dle() { + if [ "$MULTILINEDLE" = "0" ]; then + if echo "${rest}" | grep -q '{'; then + MULTILINEDLE=1 + fi + return 1 + elif echo "${host} ${dev} ${rest}" | grep -q '}'; then + MULTILINEDLE=0 + fi + return 0 +} + +if ! [ -d "/etc/amanda" ]; then + exit 0 +fi +for configfile in $(find /etc/amanda -name amanda.conf ! -path '/etc/amanda/template.d*' | tr ' +' ' '); do + config="$(dirname "${configfile}")" + cd "${config}" || exit 1 + CONF="${config##*/}" + AMANDA_TAPEDEV="$(amgetconf "${CONF}" tapedev)" + AMANDA_TAPEDEV="${AMANDA_TAPEDEV#file:/}" + if [ -d "${AMANDA_TAPEDEV}" ]; then + print "@@define AMANDA_TAPEDEV %s\\n" "${AMANDA_TAPEDEV}" + #shellcheck disable=SC2044 + for slot in $(find /"${AMANDA_TAPEDEV}" -type d -regex '.*/slot[0-9]+' -printf "%P\\n"); do + if [ -f "disklist" ]; then + while read -r host dev rest; do + if echo "${host}" | grep -qE '^(#.*)?$'; then continue; fi + #shellcheck disable=SC2001 + dev="$(echo "${dev}" | sed 's|/|_|g')" + if ! skip_multiline_dle; then + printf "!/@@{AMANDA_TAPEDEV}/%s/[0-9]{5}[-\\.]%s\\.%s\\.[0123]$" "${slot}" "${host}" "${dev}" + fi + done < disklist + MULTILINEDLE=0 + fi + printf "/@@{AMANDA_TAPEDEV}/%s/00000[-\\.]%s-%03d$ f VarFile\\n" "${slot}" "${CONF}" "${slot#slot}" + printf "!/@@{AMANDA_TAPEDEV}/%s/[0-9]{5}[-\\.]TAPEEND$\\n" "${slot}" + printf "/@@{AMANDA_TAPEDEV}/%s$ d VarDir\\n" "${slot}" + done + printf "/@@{AMANDA_TAPEDEV}/(data|info)$ f VarFile\\n" + printf "/@@{AMANDA_TAPEDEV}$ d VarDir\\n" + fi + AMANDA_LOGDIR="$(amgetconf "${CONF}" logdir)" + AMANDA_LOGDIR="${AMANDA_LOGDIR#/}" + if [ -n "$AMANDA_LOGDIR" ]; then + printf "@@define AMANDA_LOGDIR %s\\n" "${AMANDA_LOGDIR}" + printf "/@@{AMANDA_LOGDIR}/log\\.@@{YEAR4D}[0-9]{4}\\.0$ f LowDELog\\n" + printf "/@@{AMANDA_LOGDIR}/oldlog/log\\.@@{YEAR4D}[0-9]{4}\\.0$ f SerMemberDELog\\n" + printf "/@@{AMANDA_LOGDIR}/amdump\\.1$ f LoSerMemberLog\\n" + printf "/@@{AMANDA_LOGDIR}/amdump\\.[2-8]$ f SerMemberLog\\n" + printf "/@@{AMANDA_LOGDIR}/amdump\\.9$ f HiSerMemberLog\\n" + printf "/@@{AMANDA_LOGDIR}(/oldlog)?$ d VarDir\\n" + fi + AMANDA_INDEXDIR="$(amgetconf "${CONF}" indexdir)" + AMANDA_INDEXDIR="${AMANDA_INDEXDIR#/}" + if [ -n "${AMANDA_INDEXDIR}" ]; then + printf "@@define AMANDA_INDEXDIR %s\\n" "${AMANDA_INDEXDIR}" + if [ -f "disklist" ]; then + while read -r host dev rest; do + if echo "${host}" | grep -q '^\\(#.*\\)\\?$'; then continue; fi + dev="$(echo "${dev}" | sed 's|[/:]|_|g;s|\\"||g')" + if ! skip_multiline_dle; then + printf "!/@@{AMANDA_INDEXDIR}/%s/%s/@@{YEAR4D}[0-9]{4}_[0123]\\.gz$ f\\n" "${host}" "${dev}" + printf "/@@{AMANDA_INDEXDIR}/%s/%s$ d VarDir\\n" "${host}" "${dev}" + fi + done < disklist + MULTILINEDLE=0 + fi + fi + AMANDA_CHANGERFILE="$(amgetconf "${CONF}" changerfile)" + AMANDA_CHANGERDIR="${AMANDA_CHANGERFILE%changer}" + AMANDA_CHANGERDIR="${AMANDA_CHANGERDIR#/}" + if [ -n "${AMANDA_CHANGERDIR}" ]; then + printf "@@define AMANDA_CHANGERDIR %s\\n" "${AMANDA_CHANGERDIR}" + printf "/@@{AMANDA_CHANGERDIR}/(changer-(access|clean|slot)|tapelist(\\.yesterday)?)$ f VarFile\\n" + printf "/@@{AMANDA_CHANGERDIR}$ d VarDir\\n" + fi + AMANDA_INFOFILE="$(amgetconf "${CONF}" infofile)" + AMANDA_INFOFILE="${AMANDA_INFOFILE#/}" + if [ -n "${AMANDA_INFOFILE}" ]; then + printf "@@define AMANDA_INFOFILE %s\\n" "${AMANDA_INFOFILE}" + if [ -f "disklist" ]; then + while read -r host dev rest; do + if echo "${host}" | grep -qE '^(#.*)?$'; then continue; fi + #shellcheck disable=SC2001 + dev="$(echo "${dev}" | sed 's|[/:]|_|g;s|\"||g')" + if ! skip_multiline_dle; then + printf "/@@{AMANDA_INFOFILE}/%s/%s/info$ f VarFile\\n" "${host}" "${dev}" + printf "/@@{AMANDA_INFOFILE}/%s/%s$ d VarDir\\n" "${host}" "${dev}" + fi + done < disklist + MULTILINEDLE=0 + fi + fi + # this is hardcoded since amgetconf refuses to deliver diskdir + AMANDA_HOLDING="srv/amanda/holding" + if [ -n "$AMANDA_HOLDING" ]; then + printf "/%s$ d VarDir\\n" "${AMANDA_HOLDING}" + fi + printf "@@define AMANDALOG var/log/amanda/server/%s\\n" "${CONF}" + printf "!/@@{AMANDALOG}/(amcheck|amlogroll|amreport|amtrm(idx|log)|chunker|driver|dumper|planner|taper)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f\\n" + printf "!/@@{AMANDALOG}/(chunker|dumper)\\.@@{YEAR4D}[0-9]{13}\\.debug$ f\\n" + printf "/@@{AMANDALOG}$ d VarDir\\n" + printf "/var/log/amanda/server$ d VarDir\\n" +done + +printf "@@define AMANDALOG var/log/amanda/amandad\\n" +printf "!/@@{AMANDALOG}/(amandad)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f\\n" +printf "/@@{AMANDALOG}$ d VarDir\\n" +printf "/tmp/amanda$ d VarDir\\n" diff --git a/aide/aide.conf.d/31_aide_amavisd-new b/aide/aide.conf.d/31_aide_amavisd-new new file mode 100644 index 00000000..4adeaafc --- /dev/null +++ b/aide/aide.conf.d/31_aide_amavisd-new @@ -0,0 +1,13 @@ +/@@{RUN}/amavis/amavisd.(lock|pid)$ f VarFile +/@@{RUN}/amavis$ d VarDirInode +/var/lib/amavis$ d VarDir +/var/lib/amavis/tmp$ d VarDir +!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}$ d +!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}/(email\\.txt|parts)$ f +/var/lib/amavis/amavisd.sock$ s VarInode +/var/lib/amavis/db$ d VarDir +/var/lib/amavis/db/__db.[0-9]{3}$ f VarFile +/var/lib/amavis/db/(cache(-expiry)?|snmp|nanny)\\.db$ f VarFile +/var/lib/amavis/.spamassassin$ d VarDir +/var/lib/amavis/.spamassassin/bayes_(toks|seen)$ f VarFile +/var/lib/amavis/.spamassassin/auto-whitelist$ f VarFile diff --git a/aide/aide.conf.d/31_aide_anacron b/aide/aide.conf.d/31_aide_anacron new file mode 100644 index 00000000..79ef32f2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_anacron @@ -0,0 +1,2 @@ +/var/spool/anacron/cron\\.(monthly|weekly|daily)$ f VarFile +/var/lib/systemd/timers/stamp-anacron\\.timer$ f VarFile diff --git a/aide/aide.conf.d/31_aide_anubis b/aide/aide.conf.d/31_aide_anubis new file mode 100644 index 00000000..6c37ef95 --- /dev/null +++ b/aide/aide.conf.d/31_aide_anubis @@ -0,0 +1 @@ +/@@{RUN}/anubis\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_apache2 b/aide/aide.conf.d/31_aide_apache2 new file mode 100644 index 00000000..036229b1 --- /dev/null +++ b/aide/aide.conf.d/31_aide_apache2 @@ -0,0 +1,19 @@ +# you can define your own APACHE2_LOGS regex in an earlier file, +# overriding the defaults given here +@@ifndef APACHE2_LOGS +@@ifdef APACHE2_SUEXEC +@@define APACHE2_LOGS (access|error|suexec) +@@else +@@define APACHE2_LOGS (access|error) +@@endif +@@endif +/var/log/apache2/@@{APACHE2_LOGS}\\.log$ f Log +/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.1$ f LowLog +/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.([3-9]|[1-4][0-9]|5[0-1])\\.@@{LOGEXT}$ f SerMemberLog +/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.52\\.@@{LOGEXT}$ f HiSerMemberLog + +/@@{RUN}/apache2/apache2\\.pid$ f VarFile +/@@{RUN}/apache2/ssl_scache$ f VarFile +/var/log/apache2$ d VarDir +/@@{RUN}/apache2$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_apcupsd b/aide/aide.conf.d/31_aide_apcupsd new file mode 100644 index 00000000..196021a0 --- /dev/null +++ b/aide/aide.conf.d/31_aide_apcupsd @@ -0,0 +1,3 @@ +/var/log/apcupsd\\.events$ f Log +/@@{RUN}/apcupsd\\.pid$ f VarFile +/@@{RUNLOCK}/LCK\\.\\.$ f VarFile diff --git a/aide/aide.conf.d/31_aide_apt b/aide/aide.conf.d/31_aide_apt new file mode 100755 index 00000000..7f087d11 --- /dev/null +++ b/aide/aide.conf.d/31_aide_apt @@ -0,0 +1,103 @@ +#!/bin/bash + +#shellcheck disable=SC2154 +if [ -x "$UPAC_settingsd/10_aide_sourceslist" ]; then + #shellcheck disable=SC1090 + . "$UPAC_settingsd/10_aide_sourceslist" +fi +VARDIR="var/lib/apt" +LISTSDIR="$VARDIR/lists" +CACHEDIR="var/cache/apt" +ARCHIVESDIR="$CACHEDIR/archives" +SYSTEMDDIR="var/lib/systemd/timers" +LOGDIR="var/log/apt" +IGNORE_ARCHIVES="" +IGNORE_FRQCHG="" + +if [ -r "$UPAC_settingsd/31_aide_apt_settings" ]; then + # pull in configuration + #shellcheck disable=SC1090 + . "$UPAC_settingsd/31_aide_apt_settings" +fi + +printf "@@define APT_TRANSLATIONS (ca|cs|da|de|de_DE|en|eo|es|eu|fi|fr|hr|hu|id|it|ja|km|ko|nb|nl|pl|pt|pt_BR|ro|ru|sk|sr|sv|uk|vi|zh|zh_CN|zh_TW)\\n" +printf "@@define APT_ARCH (@@{ARCH}|all)\\n" + +RE="^\\(deb\\|deb-src\\)[[:space:]]\\+\\(\\(\\[[^]]\\+\\]\\)[[:space:]]\\+\\)\\?\\([^[:space:]]\\+\\)[[:space:]]\\+\\([^[:space:]]\\+\\)[[:space:]]\\+\\(.*\\)$" +#shellcheck disable=SC2086 +cat ${SOURCESLIST} /dev/null | sed 's/ #.*$//' | while read -r line; do + deb="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\1/;p;}")" + uri="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\4/;p;}")" + dist="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\5/;p;}")" + comp="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\6/;p;}")" + #shellcheck disable=SC2001 + PROTOCOL="$(echo "${uri}" | sed 's|\([^:]\+\).*|\1|')" + if echo "${PROTOCOL}" | grep -qE '(https?|ftp)'; then + HOST="$(echo "${uri}" | sed -e 's|.*//\([-_.[:alnum:]]\+\).*|\1|' -e 's|\.|\\\\.|g')" + HOSTPATH="$(echo "${uri}" | sed -e 's|.*//[^/[:space:]]\+/\?||;s|/$||;s|/|_|g;s|^\(.\+\)$|_\1|' -e 's|\.|\\\\.|g')" + dist="${dist//\//_}" + if [ -n "${DEBUG}" ]; then + echo "${line}" | sed -n "/^deb/{s/${RE}/1: \\1, 2: \\2, 3: \\3, 4: \\4, 5: \\5, 6: \\6/;p;}" + printf "# deb: %s\\n" "${deb}" + printf "# uri %s\\n" "${uri}" + printf "# dist: %s\\n" "${dist}" + printf "# comp: %s\\n" "${comp}" + printf "# HOST %s\\n" "${HOST}" + printf "# HOSTPATH %s\\n" "${HOSTPATH}" + fi + if [ "$deb" = "deb" ]; then + for c in $comp; do + printf "/%s/%s%s_dists_%s_%s_binary-@@{APT_ARCH}_Packages(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}" + printf "/%s/%s%s_dists_%s_%s_Contents-@@{APT_ARCH}((\\\\\\\\.diff_Index|\\\\\\\\.lz4))?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}" + printf "@@ifdef FOREIGN_ARCHES\\n" + printf "/%s/%s%s_dists_%s_%s_binary-@@{FOREIGN_ARCHES}_Packages(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}" + printf "@@endif\\n" + printf "/%s/%s%s_dists_%s_(InRelease|Release(\\\\\\\\.gpg)?)$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" + printf "/%s/%s%s_dists_%s_%s_i18n_Translation-@@{APT_TRANSLATIONS}(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}" + done + printf "!/%s/partial/%s%s_dists_%s_Release\\\\\\\\.gpg\\\\\\\\.reverify$ f\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" + elif [ "$deb" = "deb-src" ]; then + for c in $comp; do + printf "/%s/%s%s_dists_%s_%s_source_Sources(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}" + printf "/%s/%s%s_dists_%s_(InRelease|Release(\\\\\\\\.gpg)?)$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" + done + fi + else + : # other protocols are not supported. If you feel like they should + : # please give a good reason and probably a patch. + fi + printf "\\n\\n" +done + +printf "/%s(/(auxfiles|partial))?$ d VarDir\\n" "${LISTSDIR}" +printf "/%s/lock$ f VarFile\\n" "${LISTSDIR}" +printf "/%s/periodic/(download-upgradeable|update)-stamp$ f VarTime\\n" "${VARDIR}" +printf "/%s/(daily_lock|extended_states)$ f VarFile\\n" "${VARDIR}" +printf "/%s$ d VarDir\\n" "${VARDIR}" +printf "\\n" +printf "/%s/stamp-apt-daily(-upgrade)?\\\\\\\\.timer$ f VarFile\\n" "${SYSTEMDDIR}" +printf "\\n" +printf "/%s/(term|history)\\\\\\\\.log$ f Log\\n" "${LOGDIR}" +printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.1\\\\\\\\.@@{LOGEXT}$ f LoSerMemberLog\\n" "${LOGDIR}" +printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.([2-9]|1[0-1])\\\\\\\\.@@{LOGEXT}$ f SerMemberLog\\n" "${LOGDIR}" +printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.12\\\\\\\\.@@{LOGEXT}$ f HiSerMemberLog\\n" "${LOGDIR}" +printf "/%s/eipp\\\\\\\\.log\\\\\\\\.xz$ f VarFile\\n" "${LOGDIR}" +printf "/%s$ d VarDir\\n" "${LOGDIR}" +printf "\\n" +printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.0$ f LowLog\\n" +printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.1\\\\\\\\.@@{LOGEXT}$ f LoSerMemberLog\\n" +printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.[2345]\\\\\\\\.@@{LOGEXT}$ f SerMemberLog\\n" +printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.6\\\\\\\\.@@{LOGEXT}$ f HiSerMemberLog\\n" + +if [ "$IGNORE_ARCHIVES" = "yes" ]; then + printf "!/%s/[-[:alnum:]%%\.~_+]+_@@{APT_ARCH}\\\\\\\\.deb$ f\\n" "${ARCHIVESDIR}" + printf "@@ifdef FOREIGN_ARCHES\\n" + printf "!/%s/[-[:alnum:]%%\.~_+]+_@@{FOREIGN_ARCHES}\\\\\\\\.deb$ f\\n" "${ARCHIVESDIR}" + printf "@@endif\\n" +fi + +if [ "$IGNORE_FRQCHG" = "yes" ]; then + printf "/%s(/partial|/lock)?$ d VarDir\\n" "${ARCHIVESDIR}" + printf "!/%s/(src)?pkgcache\\\\\\\\.bin$ f\\n" "${CACHEDIR}" + printf "/%s$ d VarDir\\n" "${CACHEDIR}" +fi diff --git a/aide/aide.conf.d/31_aide_apt-cacher-ng b/aide/aide.conf.d/31_aide_apt-cacher-ng new file mode 100644 index 00000000..d12f9a8b --- /dev/null +++ b/aide/aide.conf.d/31_aide_apt-cacher-ng @@ -0,0 +1,58 @@ +@@define ACNGCACHE var/cache/apt-cacher-ng +@@define ACNGDEB (zg20150|debian(security)?) +@@define ACNGDISTS @@{ACNGDEB}/dists/(bullseye|(buster|stable)(-updates)?|experimental|jessie|sid|stretch(-updates)?|unstable|testing|(bullseye|buster|jessie|stretch|sid)-zg-((un)?stable|testing|experimental))(/updates)? +@@define ACNGMNC (main|contrib|non-free)(/dep11)? +@@define ACNGARCHS (armhf|amd64|i386|all) +@@define ACNGDATENR 20[12][[:digit:]]-[[:digit:]]{2}-[[:digit:]]{2}-[[:digit:]]{4}\\.[[:digit:]]{2} +@@define ACNGDTNR (@@{ACNGDATENR}|T-@@{ACNGDATENR}-F-@@{ACNGDATENR}) + +/@@{ACNGCACHE}$ d VarDir +/@@{ACNGCACHE}/_actmp$ d VarDir +/@@{ACNGCACHE}/_actmp/(combined\\.diff|patch\\.(base|result))$ f VarFile +/@@{ACNGCACHE}/_(exfail_cnt|expending_(damaged|dat))$ f VarFile +/@@{ACNGCACHE}/_xstore/qstats/[a-z]$ d VarDir +!/@@{ACNGCACHE}/_xstore/qstats/([a-z]/)?156[0-9]{7}\\.[0-9]{5,6}$ l +/@@{ACNGCACHE}/_xstore/rsnap/@@{ACNGDISTS}(/@@{ACNGMNC}/binary-@@{ACNGARCHS})?$ d VarDir +!/@@{ACNGCACHE}/_xstore/rsnap/@@{ACNGDISTS}(/@@{ACNGMNC}/binary-@@{ACNGARCHS})?/[[:digit:]]{22,25}$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/(In)?Release(\\.gpg)?(\\.head)?$ f VarFile +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Release(\\.head)?$ f VarFile +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}(/by-hash)?$ d VarDir-n +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/by-hash/SHA256$ d +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources(\\.xz)?(\\.head)?$ f VarFile +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(source|i18n|(Contents|binary)-@@{ACNGARCHS}\\.diff)$ d VarDir +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(Contents-@@{ACNGARCHS}\\.gz)(\\.head)?$ f VarFile +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(debian-installer/)?(binary-@@{ACNGARCHS})/(Packages(\\.(bz2|xz))?)(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de|en)\\.diff$ d VarDir +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(Contents-@@{ACNGARCHS}|Sources\\.diff)$ d VarDir +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de(_DE)?|en)\\.(bz2|xz)(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de|en)(\\.diff)?/Index(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/Index(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Packages(\\.diff)?/Index(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources\\.diff/Index(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff(/by-hash)?$ d VarDir-n +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/by-hash/SHA256$ d +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}(/Packages\\.diff)?(/by-hash)?$ d VarDir-n +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}(/Packages\\.diff)?/by-hash/SHA256$ d +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Packages\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/(Packages\\.diff/)?by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?(/by-hash)?$ d VarDir-n +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?/by-hash/SHA256$ d +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(en)\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f +/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?(/by-hash)?$ d VarDir-n +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?/by-hash/SHA256$ d +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}(/(lib)?[a-z](/[-a-z0-9+\\.]+)?)?$ d +!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}/(lib)?[a-z]/[-+[:alnum:]\\.]+/[-+[:alnum:]\\.]+_[-+~[:alnum:]\\.]+_@@{ACNGARCHS}\\.deb(\\.head)?$ f +!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}/(lib)?[a-z]/[-+[:alnum:]\\.]+/[-+[:alnum:]\\.]+_[-+~[:alnum:]\\.]+\\.(dsc|(debian|orig)\\.tar\\.(gz|xz))(\\.asc)?(\\.head)?$ f + +@@define LOGDIR var/log/apt-cacher-ng +/@@{LOGDIR}$ d VarDir +!/@@{LOGDIR}/maint_[[:digit:]]+\\.log\\.html$ f +/@@{LOGDIR}/apt-cacher\\.(log|err)$ f Log +!/@@{LOGDIR}/apt-cacher\\.(log|err)-@@{YEAR4D}[[:digit:]]{4}$ f + diff --git a/aide/aide.conf.d/31_aide_apt-listbugs b/aide/aide.conf.d/31_aide_apt-listbugs new file mode 100644 index 00000000..003b198a --- /dev/null +++ b/aide/aide.conf.d/31_aide_apt-listbugs @@ -0,0 +1,2 @@ +!/var/cache/apt-listbugs/%2Findices%2Findex.db-(critical|grave|serious)\\.gz$ f +/var/cache/apt-listbugs$ d VarDir diff --git a/aide/aide.conf.d/31_aide_apt-listchanges b/aide/aide.conf.d/31_aide_apt-listchanges new file mode 100644 index 00000000..8dea45d7 --- /dev/null +++ b/aide/aide.conf.d/31_aide_apt-listchanges @@ -0,0 +1 @@ +/var/lib/apt/listchanges\\.db$ f VarFile diff --git a/aide/aide.conf.d/31_aide_apt-show-versions b/aide/aide.conf.d/31_aide_apt-show-versions new file mode 100644 index 00000000..6f99d9ea --- /dev/null +++ b/aide/aide.conf.d/31_aide_apt-show-versions @@ -0,0 +1,2 @@ +/var/cache/apt-show-versions/(files|ipackages|apackages)$ f VarFile +/var/cache/apt-show-versions$ d VarDir diff --git a/aide/aide.conf.d/31_aide_aptitude b/aide/aide.conf.d/31_aide_aptitude new file mode 100644 index 00000000..c4df51d9 --- /dev/null +++ b/aide/aide.conf.d/31_aide_aptitude @@ -0,0 +1,13 @@ +/var/log/aptitude$ d Log +/var/log/aptitude\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/aptitude\\.[2-5]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/aptitude\\.6\\.@@{LOGEXT}$ f HiSerMemberLog +/var/backups/aptitude\\.pkgstates\\.0$ f LowLog +/var/backups/aptitude\\.pkgstates\\.1\\.gz$ f LoSerMemberLog +/var/backups/aptitude\\.pkgstates\\.[2345]\\.gz$ f SerMemberLog +/var/backups/aptitude\\.pkgstates\\.6\\.gz$ f HiSerMemberLog +/var/lib/aptitude/pkgstates(\\.old)?$ f VarFile +/var/lib/aptitude$ d VarDir +!/@@{RUNLOCK}/aptitude$ f +/root/\\.(aptitude|debtags)$ d VarDir +/root/\\.aptitude/config$ f VarFile diff --git a/aide/aide.conf.d/31_aide_at b/aide/aide.conf.d/31_aide_at new file mode 100644 index 00000000..31142b5e --- /dev/null +++ b/aide/aide.conf.d/31_aide_at @@ -0,0 +1,2 @@ +/var/spool/cron/at(spool|jobs)$ d VarDir +/@@{RUN}/atd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_atop b/aide/aide.conf.d/31_aide_atop new file mode 100644 index 00000000..81d6e6d5 --- /dev/null +++ b/aide/aide.conf.d/31_aide_atop @@ -0,0 +1,10 @@ +/var/log/atop$ d VarDirInode +!/var/log/atop/(atop_@@{YEAR4D}[[:digit:]]{4}|daily\\.log)$ f +/var/log/atop/dummy_(after|before)$ f VarFile +/@@{RUN}/atop$ d VarDir +/@@{RUN}/atop/atop\\.acct$ f VarFile +/@@{RUN}/pacct_shadow\\.d$ d VarDirInode +!/@@{RUN}/pacct_shadow\\.d/[0-9]{10}\\.paf$ f +/@@{RUN}/pacct_shadow\\.d/current$ f VarFile +/@@{RUN}/pacct_source$ f VarFile +/@@{RUN}/atop(acctd)?\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_avahi-daemon b/aide/aide.conf.d/31_aide_avahi-daemon new file mode 100644 index 00000000..423b5b6e --- /dev/null +++ b/aide/aide.conf.d/31_aide_avahi-daemon @@ -0,0 +1,3 @@ +/@@{RUN}/avahi-daemon$ d VarDirInode +/@@{RUN}/avahi-daemon/pid$ f VarFile +!/@@{RUN}/avahi-daemon/socket$ s diff --git a/aide/aide.conf.d/31_aide_bind9 b/aide/aide.conf.d/31_aide_bind9 new file mode 100644 index 00000000..9cd03821 --- /dev/null +++ b/aide/aide.conf.d/31_aide_bind9 @@ -0,0 +1,18 @@ +@@ifdef BINDCHROOT +/@@{BINDCHROOT}/dev/log$ f LowLog +/@@{BINDCHROOT}/dev$ d VarDir +@@endif +/@@{BINDCHROOT}@@{RUN}/named/(session\\.key|named\\.pid)$ f VarFile +/@@{BINDCHROOT}@@{RUN}/named$ d VarDirInode +/@@{BINDCHROOT}var/cache/bind$ d VarDir +/@@{BINDCHROOT}var/cache/bind/[-[:alnum:].]+$ f VarFile + +@@ifdef BIND_SLAVE_DIRS +@@ifdef BIND_SLAVE_PATHS +/@@{BINDCHROOT}var/cache/bind/slave/@@{BIND_SLAVE_DIRS}$ d VarDir +/@@{BINDCHROOT}var/cache/bind/slave/@@{BIND_SLAVE_PATHS}$ f VarFile +@@endif +@@endif + + + diff --git a/aide/aide.conf.d/31_aide_boinc-client b/aide/aide.conf.d/31_aide_boinc-client new file mode 100644 index 00000000..3524bcf1 --- /dev/null +++ b/aide/aide.conf.d/31_aide_boinc-client @@ -0,0 +1,16 @@ +/var/lib/boinc-client$ d VarDir +/var/lib/boinc-client/(get_current_version|global_prefs|daily_xfer_history|client_state(_prev)?)\\.xml$ f VarFile +/var/lib/boinc-client/(time_stats_log|do_fp)$ f VarFile +/var/lib/boinc-client/lookup_website\\.html$ f VarFile +/var/lib/boinc-client/std(err|out)dae\\.txt$ f VarFile + +# Add rules for your projects. Example: seti@home +#/var/lib/boinc-client/job_log_setiathome\\.berkeley\\.edu\\.txt$ f VarFile +#/var/lib/boinc-client/master_setiathome\\.berkeley\\.edu\\.xml$ f VarFile +#/var/lib/boinc-client/projects/setiathome\\.berkeley\\.edu$ d VarDir +#/var/lib/boinc-client/projects/setiathome\\.berkeley\\.edu/\\.*$ f VarFile+ANF+ARF +#/var/lib/boinc-client/sched_reply_setiathome\\.berkeley\\.edu\\.xml$ f VarFile +#/var/lib/boinc-client/sched_request_setiathome\\.berkeley\\.edu\\.xml$ f VarFile +#/var/lib/boinc-client/slots/[[:digit:]]+$ d VarDir +#/var/lib/boinc-client/slots/[[:digit:]]+/\\.*$ f VarFile+ANF+ARF +#/var/lib/boinc-client/statistics_setiathome\\.berkeley\\.edu\\.xml$ f VarFile diff --git a/aide/aide.conf.d/31_aide_borgbackup b/aide/aide.conf.d/31_aide_borgbackup new file mode 100644 index 00000000..bbb10047 --- /dev/null +++ b/aide/aide.conf.d/31_aide_borgbackup @@ -0,0 +1,12 @@ +@@define BORGCACHE root/\\.cache/borg +@@define BORGCONFIG root/\\.config/borg +/@@{BORGCACHE}(/(keys|security))?$ d VarDir +!/@@{BORGCACHE}/[[:xdigit:]]{64}$ d +!/@@{BORGCACHE}/[[:xdigit:]]{64}/(README|chunks|config|files|lock\\.roster)$ f +!/@@{BORGCACHE}/[[:xdigit:]]{64}/(chunks\\.archive\\.d|lock\\.exclusive|txn\\.active)$ d +!/@@{BORGCACHE}/[[:xdigit:]]{64}/lock\\.exclusive/@@{{HOSTNAME}}\\.[[:digit:]]+\\-0$ f +!/@@{BORGCACHE}/[[:xdigit:]]{64}/txn.active/(chunks|config|files)$ f +#!/@@{BORGCACHE}/keys/--_@@{HOSTNAME}\\.[[:digit:]]$ f +!/@@{BORGCONFIG}/security/[[:xdigit:]]{64}$ d +!/@@{BORGCONFIG}/security/[[:xdigit:]]{64}/(key-type|location|manifest-timestamp|nonce|tam_required)$ f + diff --git a/aide/aide.conf.d/31_aide_btmp b/aide/aide.conf.d/31_aide_btmp new file mode 100644 index 00000000..4f747359 --- /dev/null +++ b/aide/aide.conf.d/31_aide_btmp @@ -0,0 +1,2 @@ +/var/log/btmp$ f Log +/var/log/btmp\\.1$ f LowLog diff --git a/aide/aide.conf.d/31_aide_cereal b/aide/aide.conf.d/31_aide_cereal new file mode 100644 index 00000000..49f8cea8 --- /dev/null +++ b/aide/aide.conf.d/31_aide_cereal @@ -0,0 +1,19 @@ +# replace CEREALSESS with a regexp matching your session names +#@@define CEREALSESS (session|session) +#@@define CEREALDEVICES (ttyS0) +@@ifdef CEREALSESS +!/@@{RUN}/screen/S-@@{CEREALSESS}$ d +!/@@{RUN}/screen/S-@@{CEREALSESS}/[[:digit:]]+\\.cereal:@@{CEREALSESS}$ s +/var/lib/cereal/sessions/@@{CEREALSESS}/socket$ p VarFile +/var/lib/cereal/sessions/@@{CEREALSESS}(/log/main)?$ d VarDir +/var/lib/cereal/sessions/@@{CEREALSESS}/log/main/current$ f VarFile +!/var/lib/cereal/sessions/@@{CEREALSESS}/log/main/@40000000[[:xdigit:]]{16}\\.s$ f +/var/lib/cereal/sessions/@@{CEREALSESS}/(log/)?supervise$ d VarDir +/var/lib/cereal/sessions/@@{CEREALSESS}/(log/)?supervise/(control|pid|stat(us)?)$ f VarFile +@@endif + +@@ifdef CEREALDEVICES +/@@{RUN}/lock/LCK\\.\\.@@{CEREALDEVICES}$ f VarFile +!/dev/@@{CEREALDEVICES}$ l +@@endif + diff --git a/aide/aide.conf.d/31_aide_checksecurity b/aide/aide.conf.d/31_aide_checksecurity new file mode 100644 index 00000000..2ec9fc65 --- /dev/null +++ b/aide/aide.conf.d/31_aide_checksecurity @@ -0,0 +1,6 @@ +/var/log/setuid/setuid.changes$ f Log +/var/log/setuid/setuid.changes\\.1$ f LoSerMemberLog +/var/log/setuid/setuid.changes\\.[2-9]$ f SerMemberLog +/var/log/setuid/setuid.changes\\.10$ f HiSerMemberLog +/var/log/setuid/setuid.(today|yesterday)$ f VarFile +/var/log/setuid$ d VarDir diff --git a/aide/aide.conf.d/31_aide_chrony b/aide/aide.conf.d/31_aide_chrony new file mode 100644 index 00000000..a523f6df --- /dev/null +++ b/aide/aide.conf.d/31_aide_chrony @@ -0,0 +1,2 @@ +/var/lib/chrony$ d VarDir +/var/lib/chrony/chrony\\.drift$ f VarFile diff --git a/aide/aide.conf.d/31_aide_clamav b/aide/aide.conf.d/31_aide_clamav new file mode 100644 index 00000000..dbf06668 --- /dev/null +++ b/aide/aide.conf.d/31_aide_clamav @@ -0,0 +1,8 @@ +/var/log/clamav/clamav\\.log$ f Log +/var/log/clamav/clamav\\.log\\.1$ f LowLog +/var/log/clamav/clamav\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/clamav/clamav\\.log\\.([3-9]|1[0-1])\\.@@{LOGEXT}$ f SerMemberLog +/var/log/clamav/clamav\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog +/@@{RUN}/clamav/clamd\\.(ctl|pid)$ f VarFile +/var/log/clamav$ d VarDir +/@@{RUN}/clamav$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_clamav-freshclam b/aide/aide.conf.d/31_aide_clamav-freshclam new file mode 100644 index 00000000..5913468b --- /dev/null +++ b/aide/aide.conf.d/31_aide_clamav-freshclam @@ -0,0 +1,12 @@ +/var/lib/clamav$ d VarDir +/var/lib/clamav/(scam|junk)\\.ndb$ f VarFile +/var/log/clamav/freshclam\\.log$ f Log +/var/log/clamav/freshclam\\.log\\.1$ f LowLog +/var/log/clamav/freshclam\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/clamav/freshclam\\.log\\.([3-9]|1[0-1])\\.@@{LOGEXT}$ f SerMemberLog +/var/log/clamav/freshclam\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog +/var/lib/clamav/(safebrowsing|bytecode)\\.cld$ f VarFile +/var/lib/clamav/daily\\.inc/daily\\.(info|[nmhp]db)$ f VarFile +/var/lib/clamav/daily\\.cld$ f VarFile +/var/lib/clamav/mirrors.dat$ f VarFile +/@@{RUN}/clamav/freshclam\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_clamav-unofficial-sigs b/aide/aide.conf.d/31_aide_clamav-unofficial-sigs new file mode 100644 index 00000000..abe07faa --- /dev/null +++ b/aide/aide.conf.d/31_aide_clamav-unofficial-sigs @@ -0,0 +1,15 @@ +!/var/lib/clamav-unofficial-sigs/pid/clamav-unofficial-sigs\\.pid$ f +/var/lib/clamav$ d VarDir +/var/lib/clamav/\\.wget-hsts$ f VarFile +/var/lib/clamav/(blurl|jurlbl|phish(tank)?|porcupine|winnow_malware_links)\\.ndb$ f VarFile +/var/lib/clamav/(foxhole_filename)\\.cdb$ f VarFile +/var/lib/clamav/(porcupine)\\.hsb$ f VarFile +/var/lib/clamav/(safebrowsing)\\.cld$ f VarFile +/var/lib/clamav-unofficial-sigs(/(configs|dbs-(add|lmd|mbl|si|ss|yara)|gpg-key|pid))?$ d VarDir +/var/lib/clamav-unofficial-sigs/configs/(ss-include-dbs|current-dbs|last-(linuxmalwaredetect|ss|yararulesproject)-update|purge)\\.txt$ f VarFile +/var/lib/clamav-unofficial-sigs/dbs-lmd/rfxn\\.[hn]db$ f VarFile +/var/lib/clamav-unofficial-sigs/dbs-ss/(blurl|bofhland_(cracked|malware|phishing)_URL|bofhland_malware_attach|junk|jurlbl|phish(tank)?|porcupine|rogue|winnow(\\.attachments|_bad_cw|_extended_malware|_malware(_links)?)|scam|spamimg|foxhole_filename)\\.(ndb|hdb|hsb|cdb|yara)(\\.sig)?$ f VarFile +/var/lib/clamav-unofficial-sigs/dbs-ss/sigwhitelist\\.ign2(\\.sig)?$ f VarFile +/var/lib/clamav-unofficial-sigs/dbs-yara/(EK_(Angler|Blackhole|BleedingLife|Crimepack|Eleonore|Fragus|Phoenix|Sakura|ZeroAcces|Zerox88|Zeus)|antidebug_antivm)\\.(yar)$ f VarFile +/var/lib/clamav/(rogue|winnow_(extended_)?malware|bofhland_(malware|cracked|phishing)_URL|spaming|rfxn)\\.(ndb|hdb)$ f VarFile +/var/log/clamav/clamav-unofficial-sigs\\.log$ f Log diff --git a/aide/aide.conf.d/31_aide_console-log b/aide/aide.conf.d/31_aide_console-log new file mode 100644 index 00000000..a659adc2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_console-log @@ -0,0 +1,3 @@ +/@@{RUN}/console-log(/Debian-console-log)?$ d VarDirInode +/@@{RUN}/console-log/Debian-console-log/(8-_-_var_-_log_-_exim4_-_mainlog|9-_-_var_-_log_-_syslog_-_syslog)$ f VarFile +/@@{RUN}/console-log/Debian-console-log/(8-_-_var_-_log_-_exim4_-_mai|9-_-_var_-_log_-_syslog_-_sy).clientpid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_console-setup b/aide/aide.conf.d/31_aide_console-setup new file mode 100644 index 00000000..3f27397f --- /dev/null +++ b/aide/aide.conf.d/31_aide_console-setup @@ -0,0 +1,2 @@ +/@@{RUN}/console-setup$ d VarDirInode +/@@{RUN}/console-setup/(boot_completed|font-loaded)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_courier-authlib b/aide/aide.conf.d/31_aide_courier-authlib new file mode 100644 index 00000000..d897a360 --- /dev/null +++ b/aide/aide.conf.d/31_aide_courier-authlib @@ -0,0 +1,2 @@ +/@@{RUN}/courier/authdaemon/(pid|pid\\.lock|socket)$ f VarFile +/@@{RUN}/courier(/authdaemon)?$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_cracklib-runtime b/aide/aide.conf.d/31_aide_cracklib-runtime new file mode 100644 index 00000000..1d4f9f69 --- /dev/null +++ b/aide/aide.conf.d/31_aide_cracklib-runtime @@ -0,0 +1 @@ +/var/cache/cracklib/cracklib_dict\\.(hwm|pw(d|i))$ f VarFile diff --git a/aide/aide.conf.d/31_aide_cron b/aide/aide.conf.d/31_aide_cron new file mode 100644 index 00000000..436716e2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_cron @@ -0,0 +1 @@ +/@@{RUN}/crond\\.(pid|reboot)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_cron-apt b/aide/aide.conf.d/31_aide_cron-apt new file mode 100644 index 00000000..5daf6e78 --- /dev/null +++ b/aide/aide.conf.d/31_aide_cron-apt @@ -0,0 +1,16 @@ +@@ifndef CRON_APT_EXTRACONFIGS +@@define CRON_APT_EXTRACONFIGS +@@endif + +/var/lib/cron-apt/_-_etc_-_cron-apt_-_config(@@{CRON_APT_EXTRACONFIGS})?/mailchanges/(0-update-|3-download-)[[:xdigit:]]{32}$ f VarFile +!/var/lib/cron-apt/lockfile$ f +/var/lib/cron-apt$ d VarDir +!/tmp/cron-apt\\.[[:alnum:]]{6}$ d +!/tmp/cron-apt\\.[[:alnum:]]{6}/((action|run)(error|log|mail|syslog)|initlog|temp)$ f +/var/log/cron-apt/log$ f FreqRotLog +/var/log/cron-apt/log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/cron-apt/log\\.[234]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/cron-apt/log\\.5\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log/cron-apt$ d VarDir +!/var/log/cron-apt/lastfullmessage$ f + diff --git a/aide/aide.conf.d/31_aide_cups b/aide/aide.conf.d/31_aide_cups new file mode 100644 index 00000000..bea6bffe --- /dev/null +++ b/aide/aide.conf.d/31_aide_cups @@ -0,0 +1,25 @@ +@@define CUPS_LOGS (access|error|page|cups-pdf) + +/var/(cache|spool)/cups$ d VarDir +/var/cache/cups/job\\.cache(\\.O)?$ f VarFile +/var/cache/cups/@@{IP4ADDRESS}\\.snmp$ f VarTime + +!/var/spool/cups/c[[:digit:]]{5}$ f +!/var/spool/cups/d[[:digit:]]{5}-001$ f +!/var/spool/cups/tmp/cups-dbus-notifier-lockfile$ f +/var/spool/cups(/tmp)?$ d VarDir + +/@@{RUN}/cups/certs/0$ f VarFile +/@@{RUN}/cups/printcap$ f VarFile +/@@{RUN}/cups/cups\\.sock$ s VarFile +/@@{RUN}/cups(/certs)?$ d VarDirInode + +/etc/cups$ d VarDir +/etc/cups/(printers|subscriptions)\\.conf(\\.O)?$ f VarFile + +/var/log/cups/@@{CUPS_LOGS}_log$ f Log +/var/log/cups/@@{CUPS_LOGS}_log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/cups/@@{CUPS_LOGS}_log\\.[2-6]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/cups/@@{CUPS_LOGS}_log\\.7\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log/cups$ d VarDir + diff --git a/aide/aide.conf.d/31_aide_dbus b/aide/aide.conf.d/31_aide_dbus new file mode 100644 index 00000000..073a08a8 --- /dev/null +++ b/aide/aide.conf.d/31_aide_dbus @@ -0,0 +1,2 @@ +!/@@{RUN}/dbus/system_bus_socket$ s +/@@{RUN}/dbus$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_dcc-common b/aide/aide.conf.d/31_aide_dcc-common new file mode 100644 index 00000000..3f299251 --- /dev/null +++ b/aide/aide.conf.d/31_aide_dcc-common @@ -0,0 +1,2 @@ +/var/lib/dcc/map$ f VarFile +/var/lib/dcc$ d VarDir diff --git a/aide/aide.conf.d/31_aide_ddclient b/aide/aide.conf.d/31_aide_ddclient new file mode 100644 index 00000000..06adef2c --- /dev/null +++ b/aide/aide.conf.d/31_aide_ddclient @@ -0,0 +1,2 @@ +/var/cache/ddclient/ddclient\\.cache$ f VarFile +/@@{RUN}/ddclient\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_debconf b/aide/aide.conf.d/31_aide_debconf new file mode 100644 index 00000000..ae8d1d00 --- /dev/null +++ b/aide/aide.conf.d/31_aide_debconf @@ -0,0 +1,2 @@ +/var/cache/debconf/(config|templates)\\.dat(-old)?$ f VarFile +/var/cache/debconf$ d VarDir diff --git a/aide/aide.conf.d/31_aide_debsecan b/aide/aide.conf.d/31_aide_debsecan new file mode 100644 index 00000000..f0efae0a --- /dev/null +++ b/aide/aide.conf.d/31_aide_debsecan @@ -0,0 +1,2 @@ +/var/lib/debsecan/history$ f VarFile +/var/lib/debsecan$ d VarDir diff --git a/aide/aide.conf.d/31_aide_dehydrated b/aide/aide.conf.d/31_aide_dehydrated new file mode 100644 index 00000000..b09c1e5f --- /dev/null +++ b/aide/aide.conf.d/31_aide_dehydrated @@ -0,0 +1,17 @@ +# this rule becomes active one DEHYDDOMAINS is defined. set it to a regexp matching +# your domains using dehydrated + +@@ifdef DEHYDDOMAINS +@@define DEHYDRE (cert|chain|combined|fullchain|privkey) +/var/lib/dehydrated$ d VarDir +/var/lib/dehydrated/accounts/[[:alnum:]]{63}$ d VarDir +/var/lib/dehydrated/accounts/[[:alnum:]]{63}/account_id\\.json$ f VarFile +/var/lib/dehydrated/chains$ d VarDir +/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}$ d VarDir +!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/@@{DEHYDRE}-[[:digit:]]+\\.pem$ f +!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/@@{DEHYDRE}\\.pem$ l +!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/combined\\.pem$ f +!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/(cert)-[[:digit:]]+\\.csr$ f +!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/(cert)\\.csr$ l +/var/lib/dehydrated(/acme-challenges)?$ d VarDir +@@endif diff --git a/aide/aide.conf.d/31_aide_dev b/aide/aide.conf.d/31_aide_dev new file mode 100644 index 00000000..38a10fab --- /dev/null +++ b/aide/aide.conf.d/31_aide_dev @@ -0,0 +1,25 @@ +# this is a preliminary paranoid rule from a local installation. Feel free to submit +# patches that may make the rule suitable for your installation + +@@define MAJMIN [[:digit:]]+:[[:digit:]]+ +/dev$ d VarDirInode +/dev/(block|char|mapper|shm)$ d VarDirInode-s +!/dev/(block|char)/@@{MAJMIN}$ l +/dev/bus/usb/00[1234]$ d VarDirInode +!/dev/bus/usb/00[1234]/0[01][[:digit:]]$ c +/dev/disk/by-id$ d VarDirInode +!/dev/disk/by-id/(dm-name-[-[:alnum:]_]+)$ l +!/dev/disk/by-id/(dm-uuid-[-[:alnum:]]+)$ l +!/dev/disk/by-label/[-[:lower:]]+$ l +!/dev/disk/by-uuid/[[:xdigit:]]{8}-([[:xdigit:]]{4}-){3}[[:xdigit:]]{12}$ l +!/dev/dm-[[:digit:]]+$ b +!/dev/mapper/[-[:alnum:]_]+$ l +!/dev/serial/by-id/usb-[-[:alnum:]_\\.]+-port0$ l +!/dev/serial/by-path/pci-0000:0000:12\\.0-usb-[[:digit:]:\\.]+-port0$ l +!/dev/serial/by-path/platform-1c1[4c]000\\.usb-usb-[-[:digit:]:\\.]+port0$ l +!/dev/shm/spice\\.[[:digit:]]+$ f +!/dev/tap[[:digit:]]+ c + +!/dev/@@{HOSTNAME}/[-[:lower:][:digit:]_]+$ l +!/dev/@@{HOSTNAME}_r/[-[:lower:][:digit:]_]+$ l + diff --git a/aide/aide.conf.d/31_aide_dlocate b/aide/aide.conf.d/31_aide_dlocate new file mode 100644 index 00000000..3c14819d --- /dev/null +++ b/aide/aide.conf.d/31_aide_dlocate @@ -0,0 +1,2 @@ +/var/lib/dlocate/(dpkg-list|dlocate(db)?(\\.old|\\.stamps)?)$ f VarFile +/var/lib/dlocate$ d VarDir diff --git a/aide/aide.conf.d/31_aide_dmeventd b/aide/aide.conf.d/31_aide_dmeventd new file mode 100644 index 00000000..f79cbeef --- /dev/null +++ b/aide/aide.conf.d/31_aide_dmeventd @@ -0,0 +1 @@ +!/@@{RUN}/dmeventd-(client|server)$ p diff --git a/aide/aide.conf.d/31_aide_dokuwiki b/aide/aide.conf.d/31_aide_dokuwiki new file mode 100644 index 00000000..84c7a7f7 --- /dev/null +++ b/aide/aide.conf.d/31_aide_dokuwiki @@ -0,0 +1,6 @@ +/var/lib/dokuwiki/data/cache/[0-9a-f]/[0-9a-f]{32}\\.(feed|i|xhtml)$ f VarFile +/var/lib/dokuwiki/data/(changes\\.log|(index|word)\\.idx)$ f VarFile +/var/lib/dokuwiki/data/meta/([a-z]+\\.indexed|_dokuwiki\\.changes)$ f VarFile +/var/lib/dokuwiki/data/meta$ d VarDir +/var/lib/dokuwiki/data/pages/[a-z]+\\.txt$ f VarFile +/var/lib/dokuwiki/data/(attic|cache|locks|pages)$ d VarDir diff --git a/aide/aide.conf.d/31_aide_dovecot b/aide/aide.conf.d/31_aide_dovecot new file mode 100644 index 00000000..0e407018 --- /dev/null +++ b/aide/aide.conf.d/31_aide_dovecot @@ -0,0 +1,11 @@ +/var/lib/dovecot$ d VarDir +/var/lib/dovecot/(instances|mounts|ssl-parameters\\.dat)$ f VarFile + +/@@{RUN}/dovecot(/(login|empty))?$ d VarDirInode +/@@{RUN}/dovecot/(auth-token-secret\.dat|auth-worker\\.[0-9]{4}|master\\.pid)$ f VarFile +/@@{RUN}/dovecot/login/(default|dns-client|imap|ipc-proxy|login|pop3|ssl-params)$ f VarFile +/@@{RUN}/dovecot/auth-worker\\.[0-9]{4}$ f VarFile +/@@{RUN}/dovecot/anvil(-auth-penalty)?$ f VarFile +/@@{RUN}/dovecot/auth-(client|login|master|userdb|worker)$ f VarFile +/@@{RUN}/dovecot/(config|dict|director-(admin|userdb)|dns-client|indexer(-worker)?|ipc|log-errors|mounts|replicat(oon-notify(-fifo)?|or)|stats(-mail)?)$ f VarFile +/@@{RUN}/dovecot/dovecot.conf$ l VarInode diff --git a/aide/aide.conf.d/31_aide_dpkg b/aide/aide.conf.d/31_aide_dpkg new file mode 100644 index 00000000..3848ba80 --- /dev/null +++ b/aide/aide.conf.d/31_aide_dpkg @@ -0,0 +1,17 @@ +@@define DPKG_LOGS (alternatives|dpkg)\\.log +@@define DPKG_BACKUPS (alternatives\\.tar|dpkg\\.(status|diversions|statoverride|arch)) +/var/lib/dpkg/(available|status)(-old)?$ f VarFile +/var/lib/dpkg/status\\.yesterday(\\.[0-9]*)?(\\.gz)?$ f VarFile +/var/lib/dpkg/triggers/Lock$ f VarFile +/var/lib/dpkg(/(info|updates))?$ d VarDir +/var/lib/dpkg/lock$ f VarFile +/var/log/@@{DPKG_LOGS}$ f Log +/var/log/@@{DPKG_LOGS}\\.1$ f LowLog +/var/log/@@{DPKG_LOGS}\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/@@{DPKG_LOGS}\\.([3-9]|1[01])\\.@@{LOGEXT}$ f SerMemberLog +/var/log/@@{DPKG_LOGS}\\.12\\.@@{LOGEXT}$ f HiSerMemberLog +/var/backups/@@{DPKG_BACKUPS}\\.0$ f LowLog +/var/backups/@@{DPKG_BACKUPS}\\.1\\.gz$ f LoSerMemberLog +/var/backups/@@{DPKG_BACKUPS}\\.[2345]\\.gz$ f SerMemberLog +/var/backups/@@{DPKG_BACKUPS}\\.6\\.gz$ f HiSerMemberLog + diff --git a/aide/aide.conf.d/31_aide_e2fsprogs b/aide/aide.conf.d/31_aide_e2fsprogs new file mode 100644 index 00000000..2d5be7e3 --- /dev/null +++ b/aide/aide.conf.d/31_aide_e2fsprogs @@ -0,0 +1 @@ +/var/lib/systemd/timers/stamp-e2scrub_all\\.timer$ f VarFile diff --git a/aide/aide.conf.d/31_aide_etckeeper b/aide/aide.conf.d/31_aide_etckeeper new file mode 100644 index 00000000..95f45311 --- /dev/null +++ b/aide/aide.conf.d/31_aide_etckeeper @@ -0,0 +1,5 @@ +/etc/\\.etckeeper$ f VarFile +/etc/\\.git(/refs/heads)?$ d VarDir +/etc/\\.git/(index|logs/HEAD|(logs/)?refs/heads/master|COMMIT_EDITMSG)$ f VarFile +/etc/.git/objects/[[:xdigit:]]{2}$ d VarDir +!/etc/.git/objects/[[:xdigit:]]{2}/[[:xdigit:]]{38}$ f diff --git a/aide/aide.conf.d/31_aide_exim4 b/aide/aide.conf.d/31_aide_exim4 new file mode 100644 index 00000000..28004e88 --- /dev/null +++ b/aide/aide.conf.d/31_aide_exim4 @@ -0,0 +1,12 @@ +/var/spool/exim4/gnutls-params$ f VarFile +/var/spool/exim4/db/(wait-remote_smtp(_smarthost)?|retry|callout)$ f VarFile +!/var/spool/exim4/input/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}-[DHJ]$ f +!/var/spool/exim4/msglog/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}$ f +!/var/spool/exim4/gnutls-params$ f +!/var/spool/exim4/\\.rnd$ f +/var/spool/exim4(/(input|msglog|scan))?$ d VarDir +/var/lib/exim4/config\\.autogenerated$ f VarFile +/@@{RUN}/exim4/exim\\.pid$ f VarFile +/var/lib/exim4$ d VarDir +/@@{RUN}/exim4$ d VarDirInode +/var/lib/systemd/timers/stamp-exim4-base\\.timer$ f VarFile diff --git a/aide/aide.conf.d/31_aide_exim4_exiscan b/aide/aide.conf.d/31_aide_exim4_exiscan new file mode 100644 index 00000000..481ea089 --- /dev/null +++ b/aide/aide.conf.d/31_aide_exim4_exiscan @@ -0,0 +1,5 @@ +@@define EXIM_MSGID [[:lower:][:digit:]]{6}-[[:alnum:]]{6}-[[:upper:][:digit:]]{2} +/var/spool/exim4/scan$ d VarDir +!/var/spool/exim4/scan/@@{EXIM_MSGID}$ d +!/var/spool/exim4/scan/@@{EXIM_MSGID}/@@{EXIM_MSGID}(-00000|\.eml)$ f + diff --git a/aide/aide.conf.d/31_aide_exim4_logs b/aide/aide.conf.d/31_aide_exim4_logs new file mode 100644 index 00000000..28c43c39 --- /dev/null +++ b/aide/aide.conf.d/31_aide_exim4_logs @@ -0,0 +1,10 @@ +# if your host frequently produces paniclog entries (this happens if +# spam or virus scanners are in use), set +# @@define EXIM4_LOGS (main|reject|panic) +@@define EXIM4_LOGS (main|reject) +/var/log/exim4/@@{EXIM4_LOGS}log$ f Log +/var/log/exim4/@@{EXIM4_LOGS}log\\.1$ f LowLog +/var/log/exim4/@@{EXIM4_LOGS}log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/exim4/@@{EXIM4_LOGS}log\\.[3-9]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/exim4/@@{EXIM4_LOGS}log\\.10\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log/exim4$ d VarDir diff --git a/aide/aide.conf.d/31_aide_fail2ban b/aide/aide.conf.d/31_aide_fail2ban new file mode 100644 index 00000000..d0155e8f --- /dev/null +++ b/aide/aide.conf.d/31_aide_fail2ban @@ -0,0 +1,7 @@ +/var/log/fail2ban\\.log$ f Log +/var/log/fail2ban\\.log\\.1$ f LowLog +/var/log/fail2ban\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/fail2ban\\.log\\.3\\.@@{LOGEXT}$ f SerMemberLog +/var/log/fail2ban\\.log\\.4\\.@@{LOGEXT}$ f HiSerMemberLog +/@@{RUN}/fail2ban/fail2ban\\.(sock|pid)$ f VarFile +/@@{RUN}/fail2ban$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_fake-hwclock b/aide/aide.conf.d/31_aide_fake-hwclock new file mode 100644 index 00000000..1fa5c21d --- /dev/null +++ b/aide/aide.conf.d/31_aide_fake-hwclock @@ -0,0 +1,2 @@ +/etc/fake-hwclock\\.data$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_fcron b/aide/aide.conf.d/31_aide_fcron new file mode 100644 index 00000000..274266a5 --- /dev/null +++ b/aide/aide.conf.d/31_aide_fcron @@ -0,0 +1,3 @@ +/@@{RUN}/fcron\\.(pid|fifo)$ f VarFile +/var/spool/fcron/systab$ f VarFile +/var/spool/fcron$ d VarDir diff --git a/aide/aide.conf.d/31_aide_findutils b/aide/aide.conf.d/31_aide_findutils new file mode 100644 index 00000000..93616ef9 --- /dev/null +++ b/aide/aide.conf.d/31_aide_findutils @@ -0,0 +1,2 @@ +/var/cache/locate/locatedb$ f VarFile +/var/cache/locate$ d VarDir diff --git a/aide/aide.conf.d/31_aide_gnupg b/aide/aide.conf.d/31_aide_gnupg new file mode 100644 index 00000000..3c66dde8 --- /dev/null +++ b/aide/aide.conf.d/31_aide_gnupg @@ -0,0 +1 @@ +!/@@{RUN}/user/[0-9]+/gnupg(/S.(dirmngr|gpg-agent(\\.(browser|extra|ssh))?|scdaemon))?$ s diff --git a/aide/aide.conf.d/31_aide_hald b/aide/aide.conf.d/31_aide_hald new file mode 100644 index 00000000..ad769739 --- /dev/null +++ b/aide/aide.conf.d/31_aide_hald @@ -0,0 +1,2 @@ +/@@{RUN}/hald/hald\\.pid$ f VarFile +/@@{RUN}/hald$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_haproxy b/aide/aide.conf.d/31_aide_haproxy new file mode 100644 index 00000000..d706f58c --- /dev/null +++ b/aide/aide.conf.d/31_aide_haproxy @@ -0,0 +1,5 @@ +/var/log/haproxy\\.log$ f Log +/var/log/haproxy\\.log\\.1$ f LowLog +/var/log/haproxy\\.log\\.2.@@{LOGEXT}$ f LoSerMemberLog +/var/log/haproxy\\.log\\.[345678].@@{LOGEXT}$ f SerMemberLog +/var/log/haproxy\\.log\\.9.@@{LOGEXT}$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_hapsd b/aide/aide.conf.d/31_aide_hapsd new file mode 100644 index 00000000..c0744a9e --- /dev/null +++ b/aide/aide.conf.d/31_aide_hapsd @@ -0,0 +1 @@ +/@@{RUN}/hdapsd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_icinga2 b/aide/aide.conf.d/31_aide_icinga2 new file mode 100644 index 00000000..ad9a6c1a --- /dev/null +++ b/aide/aide.conf.d/31_aide_icinga2 @@ -0,0 +1,21 @@ +@@define VCI var/cache/icinga2 +@@define VLII var/lib/icinga2 +@@define VLOI var/log/icinga2 + +/@@{VCI}$ d VarDir +/@@{VCI}/(objects\\.cache|status\\.dat)$ f VarFile +/@@{VLII}$ d VarDir +/@@{VLII}/(icinga2\\.state|modified-attributes\\.conf)$ f VarFile +/@@{VLII}/api/packages/_api/[[:xdigit:]]{8}-[[:xdigit:]]{4]-[[:xdigit:]]{4}-[[:xdigit:]]{4}-[[:xdigit:]]{12}/conf.d/(comments|downtimes)$ d VarDir +/@@{VLOI}/compat(/archives)?$ d VarDir +/@@{VLOI}/compat/icinga\\.log$ Log +!/@@{VLOI}/compat/archives/icinga-[[:digit:]]{2}-[[:digit:]]{2}-[[:digit:]]{4}-[[:digit:]]{2}\\.log$ f +/@@{VLOI}/default/access\\.log$ Log +/@@{VLOI}$ d VarDir +/@@{VLOI}/icinga2\\.log$ Log +/@@{VLOI}/icinga2\\.log\\.1$ f LowLog +/@@{VLOI}/icinga2\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/@@{VLOI}/icinga2\\.log\\.[3456]\\.@@{LOGEXT}$ f SerMemberLog +/@@{VLOI}/icinga2\\.log\\.7\\.@@{LOGEXT}$ f HiSerMemberLog +!/tmp/FileCache_icingaweb$ d +!/tmp/FileCache_icingaweb/icinga-[0-9a-f]{8}-[0-9a-f]{8}-[0-9a-f]{8}\\.min\\.js$ f diff --git a/aide/aide.conf.d/31_aide_ifplugd b/aide/aide.conf.d/31_aide_ifplugd new file mode 100644 index 00000000..a6e5b800 --- /dev/null +++ b/aide/aide.conf.d/31_aide_ifplugd @@ -0,0 +1,2 @@ +@@define INTERFACES eth0 +/@@{RUN}/ifplugd\\.@@{INTERFACES}\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_ifupdown b/aide/aide.conf.d/31_aide_ifupdown new file mode 100644 index 00000000..e7de436e --- /dev/null +++ b/aide/aide.conf.d/31_aide_ifupdown @@ -0,0 +1 @@ +/@@{RUN}/network/ifstate$ f VarFile diff --git a/aide/aide.conf.d/31_aide_inetd b/aide/aide.conf.d/31_aide_inetd new file mode 100644 index 00000000..9518bf57 --- /dev/null +++ b/aide/aide.conf.d/31_aide_inetd @@ -0,0 +1 @@ +/@@{RUN}/inetd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_initramfs-tools b/aide/aide.conf.d/31_aide_initramfs-tools new file mode 100644 index 00000000..14d06227 --- /dev/null +++ b/aide/aide.conf.d/31_aide_initramfs-tools @@ -0,0 +1,6 @@ +# this can be improved by giving a list of disk and dm device nodes +/@@{RUN}/(fsck|initramfs)$ d VarDirInode +/@@{RUN}/initramfs/fsck(\\.log|-(root|usr))$ f VarFile +/@@{RUN}/fsck/[vs]d[abc]$ f VarFile +/@@{RUN}/dm-[[:digit:]]+\\.lock$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_initscripts b/aide/aide.conf.d/31_aide_initscripts new file mode 100644 index 00000000..9bb2b7b2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_initscripts @@ -0,0 +1,9 @@ +/var/lib/urandom/random-seed$ f VarFile +/var/lib/(urandom|initscripts)$ d VarDir +/var/log/dmesg$ f Log +/var/log/dmesg\\.0$ f LowLog +/var/log/dmesg\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/dmesg\\.[23]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/dmesg\\.4\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log/fsck/check(root|fs)$ f VarFile +/@@{RUN}/motd$ f VarFile diff --git a/aide/aide.conf.d/31_aide_inn2 b/aide/aide.conf.d/31_aide_inn2 new file mode 100644 index 00000000..60cacb07 --- /dev/null +++ b/aide/aide.conf.d/31_aide_inn2 @@ -0,0 +1,25 @@ +@@define NEWSLOGS (errlog|expire\\.log|news(\\.crit|\\.err|\\.notice)?|rc\\.news|sendsys\\.log|unwanted\\.log|inn_status\\.html|innfeed\\.status|expire\\.(lastlowmark|list)) +@@define OLDLOGS (active|errlog|expire\\.log|news(\\.crit|\\.err|\\.notice)?|sendsys\\.log|unwanted\\.log) + +!/var/lib/news/history(\\.(dir|hash|index))?$ f +/var/lib/news/(active(\\.old)?|newsgroups|\\.news\\.daily)$ f VarFile + +!/var/spool/news/articles(/[-a-z0-9+]+)+$ f +/var/spool/news/overview/group\\.index$ f VarFile +!/var/spool/news/overview(/[a-z0-9])+/[-\\.a-z0-9+]+\\.(IDX|DAT)$ f +/var/spool/news/overview(/[a-z0-9])+$ d VarDir +!/var/spool/news/articles/control/(newgroup|checkgroups|rmgroup)/[0-9]*$ f +/var/spool/news/innfeed/@@{INN2_INNFEED_OUTFEEDS}\\.(lock|output|input)$ f VarFile +!/var/spool/news/innfeed/innfeed-dropped\\.A[0-9]{6}$ f +/var/spool/news/innfeed$ d VarDir +/var/spool/news/incoming(/tmp)?$ d VarDir + +/@@{RUN}/news/(control|(innd|innfeed|innwatch)\\.pid|innwatch\\.time|LOCK\\.innwatch|nntpin)$ f VarFile +/@@{RUN}/news$ d VarDirInode + +/var/log/news/path/inpaths\\.[0-9]{10}$ f VarFile+ANF +/var/log/news/@@{NEWSLOGS}$ f VarFile +/var/log/news/OLD/(expire\\.log\\.0|unwanted\\.log)$ f VarFile +/var/log/news/OLD/@@{OLDLOGS}\\.1\\.gz$ f LoSerMemberLog +/var/log/news/OLD/@@{OLDLOGS}\\.[0-9]+\\.gz$ f SerMemberLog +/var/log/news(/(path|OLD))?$ d VarDir diff --git a/aide/aide.conf.d/31_aide_ippl b/aide/aide.conf.d/31_aide_ippl new file mode 100644 index 00000000..6f0f7c85 --- /dev/null +++ b/aide/aide.conf.d/31_aide_ippl @@ -0,0 +1,2 @@ +/@@{RUN}/ippl/ippl.(pid|conf)$ f VarFile +/@@{RUN}/ippl$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_isc-dhcp-client b/aide/aide.conf.d/31_aide_isc-dhcp-client new file mode 100644 index 00000000..e21ec9f1 --- /dev/null +++ b/aide/aide.conf.d/31_aide_isc-dhcp-client @@ -0,0 +1,5 @@ +# @@define ISCDHCLIENTIFACE eth0 +@@ifdef ISCDHCLIENTIFACE +/@@{RUN}/dhclient\\.@@{ISCDHCLIENTIFACE}\\.pid$ f VarFile +/var/lib/dhcp/dhclient\\.@@{ISCDHCLIENTIFACE}\\.leases$ f VarFile +@@endif diff --git a/aide/aide.conf.d/31_aide_isc-dhcp-server b/aide/aide.conf.d/31_aide_isc-dhcp-server new file mode 100644 index 00000000..f9e079d1 --- /dev/null +++ b/aide/aide.conf.d/31_aide_isc-dhcp-server @@ -0,0 +1,3 @@ +/@@{RUN}/dhcpd\\.pid$ f VarFile +/var/lib/dhcp/dhcpd6?.leases~?$ f VarFile +/var/lib/dhcp$ d VarDir diff --git a/aide/aide.conf.d/31_aide_kerberos b/aide/aide.conf.d/31_aide_kerberos new file mode 100644 index 00000000..c633f1b2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_kerberos @@ -0,0 +1,6 @@ +/var/tmp/krb5kdc_rcache$ f VarFile +/var/tmp/(nfs|host)_[0-9]+$ f VarFile +/tmp/krb5cc_machine_[A-Z.]+$ f VarFile +!/tmp/krb5cc_[0-9]+_[[:alnum:]]+$ f +/var/lib/krb5kdc/principal$ f VarFile+s+b+i +/var/lib/krb5kdc/principal\\.ok$ f VarTime diff --git a/aide/aide.conf.d/31_aide_laptop-mode-tools b/aide/aide.conf.d/31_aide_laptop-mode-tools new file mode 100644 index 00000000..21847596 --- /dev/null +++ b/aide/aide.conf.d/31_aide_laptop-mode-tools @@ -0,0 +1,3 @@ +/@@{RUN}/laptop-mode-tools/(state(-brightness-command)?|enabled|start-stop-undo-actions|nolm-mountopts)$ f VarFile +/@@{RUN}/laptop-mode-tools$ d VarDirInode +/@@{RUNLOCK}/lmt-(req|invoc)\\.lock$ f VarInode diff --git a/aide/aide.conf.d/31_aide_lastlog b/aide/aide.conf.d/31_aide_lastlog new file mode 100644 index 00000000..2bc14817 --- /dev/null +++ b/aide/aide.conf.d/31_aide_lastlog @@ -0,0 +1 @@ +/var/log/lastlog$ f Log diff --git a/aide/aide.conf.d/31_aide_libapache2-mod-fastcgi b/aide/aide.conf.d/31_aide_libapache2-mod-fastcgi new file mode 100644 index 00000000..2cca739d --- /dev/null +++ b/aide/aide.conf.d/31_aide_libapache2-mod-fastcgi @@ -0,0 +1,2 @@ +/var/lib/apache2/fcgid/sock$ d VarDir +!/var/lib/apache2/fcgid/sock/[0-9]{5}\\.[0-9]$ s diff --git a/aide/aide.conf.d/31_aide_libvirt-bin b/aide/aide.conf.d/31_aide_libvirt-bin new file mode 100644 index 00000000..17c8b737 --- /dev/null +++ b/aide/aide.conf.d/31_aide_libvirt-bin @@ -0,0 +1,24 @@ +@@ifndef LIBVIRT_QEMU_GUESTS +@@define LIBVIRT_QEMU_GUESTS () +@@endif +/var/lib/libvirt$ d VarDir +/var/(lib|cache)/libvirt/qemu$ d VarDir-n +/var/lib/libvirt/qemu/(channel(/target)?|dump|nvram|save|snapshot)$ d VarDir-n +!/var/lib/libvirt/qemu(/channel/target)?/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}$ d +!/var/lib/libvirt/qemu/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}/master-key\\.aes$ f +!/var/lib/libvirt/qemu(/channel/target)?/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}/(monitor\\.sock|org\\.qemu\\.guest_agent\\.0)$ s +/var/log/libvirt$ d VarDir +/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log$ f Log +/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.1$ f LowLog +/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.3\\.@@{LOGEXT}$ f SerMemberLog +/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.4\\.@@{LOGEXT}$ f HiSerMemberLog +/@@{RUN}/(libvirtd|virtlogd)\\.pid$ f VarFile +/@@{RUN}/libvirt(/(qemu|uml-guest))?$ d VarDirInode +/@@{RUN}/libvirt/(hostdevmgr|lxc|network|storage)$ d VarDirInode +/@@{RUN}/libvirt/network/nwfilter\\.leases$ f VarFile +/@@{RUN}/libvirt/network/br[[:digit:]]{1,3}\\.xml$ f VarFile +/@@{RUN}/libvirt/(libvirt-(admin-sock|sock(-ro)?)|virt(lock|log)d-sock)$ s VarFile +!/@@{RUN}/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.(pid|xml)$ f +/@@{RUNLOCK}/libvirt-guests$ f VarDirInode + diff --git a/aide/aide.conf.d/31_aide_lighttpd b/aide/aide.conf.d/31_aide_lighttpd new file mode 100644 index 00000000..cb39363d --- /dev/null +++ b/aide/aide.conf.d/31_aide_lighttpd @@ -0,0 +1,10 @@ +@@define LIGHTTP_LOGS (access|error|tls-access) +/var/log/lighttpd$ d VarDir +/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log$ f Log +/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.1$ f LowLog +/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.([3-9]|10|11)\\.@@{LOGEXT}$ f SerMemberLog +/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog + +/@@{RUN}/lighttpd\\.pid$ f VarFile +/@@{RUN}/lighttpd$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_lldpd b/aide/aide.conf.d/31_aide_lldpd new file mode 100644 index 00000000..fcc997ea --- /dev/null +++ b/aide/aide.conf.d/31_aide_lldpd @@ -0,0 +1,3 @@ +/@@{RUN}/lldpd(/etc)?$ d VarDirInode +/@@{RUN}/lldpd/etc/localtime$ f VarFile +!/@@{RUN}/lldpd\\.socket$ s diff --git a/aide/aide.conf.d/31_aide_locales b/aide/aide.conf.d/31_aide_locales new file mode 100644 index 00000000..98b55e64 --- /dev/null +++ b/aide/aide.conf.d/31_aide_locales @@ -0,0 +1,2 @@ +/usr/lib/locale$ d VarDir +/usr/lib/locale/locale-archive$ f VarFile diff --git a/aide/aide.conf.d/31_aide_logcheck b/aide/aide.conf.d/31_aide_logcheck new file mode 100644 index 00000000..701fc585 --- /dev/null +++ b/aide/aide.conf.d/31_aide_logcheck @@ -0,0 +1,2 @@ +/@@{RUN}/lock/logcheck$ d VarDir +/var/lib/logcheck/offset\\.[[:alnum:]\\.]+$ f VarFile diff --git a/aide/aide.conf.d/31_aide_logrotate b/aide/aide.conf.d/31_aide_logrotate new file mode 100644 index 00000000..a33c009a --- /dev/null +++ b/aide/aide.conf.d/31_aide_logrotate @@ -0,0 +1,4 @@ +/var/lib/logrotate$ d VarDir +/var/lib/logrotate/status$ f VarFile +/var/lib/systemd/timers/stamp-logrotate\\.timer$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_lpd b/aide/aide.conf.d/31_aide_lpd new file mode 100644 index 00000000..3e3a563b --- /dev/null +++ b/aide/aide.conf.d/31_aide_lpd @@ -0,0 +1,3 @@ +/@@{RUN}/lpd\\.pid$ f VarFile +/var/spool/lpd$ d VarDir +/var/spool/lpd/lpd\\.lock$ f VarFile diff --git a/aide/aide.conf.d/31_aide_lvm2 b/aide/aide.conf.d/31_aide_lvm2 new file mode 100644 index 00000000..1b72a60d --- /dev/null +++ b/aide/aide.conf.d/31_aide_lvm2 @@ -0,0 +1,6 @@ +/@@{RUNLOCK}/lvm$ d VarDirInode +/@@{RUN}/lvm/(new)?hints$ f VarFile +/@@{RUN}/lvm(/((lvs|pvs)_online|pvs_lookup))?$ d VarDirInode +/@@{RUN}/lvm/pvs_online/[[:alnum:]]{32}$ f VarFile +!/@@{RUN}/lvm/lvm(etad|polld)\\.socket$ s +/@@{RUN}/lvmetad\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_mail b/aide/aide.conf.d/31_aide_mail new file mode 100644 index 00000000..6a2ee8bd --- /dev/null +++ b/aide/aide.conf.d/31_aide_mail @@ -0,0 +1,2 @@ +/var/mail/[a-z0-9]+$ f VarFile +/var/mail$ d VarDir diff --git a/aide/aide.conf.d/31_aide_mailman b/aide/aide.conf.d/31_aide_mailman new file mode 100644 index 00000000..2069dde2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_mailman @@ -0,0 +1,26 @@ +# set this variable to enable the rules +#@@define MAILMAN_LISTS (list1|list2) +@@define VL_MAILMAN var/lib/mailman +@@define VL_MAILMAN_ARCHIVES @@{VL_MAILMAN}/archives/private +@@define MAILMAN_MONTH (January|February|March|April|May|June|July|August|September|October|November|December) + +@@ifdef MAILMAN_LISTS +/@@{VL_MAILMAN}/lists/@@{MAILMAN_LISTS}$ d VarDir +/@@{VL_MAILMAN}/lists/@@{MAILMAN_LISTS}/pending\\.pck$ f VarFile-u +/@@{VL_MAILMAN}/lists/@@{MAILMAN_LISTS}/config\\.pck(\\.last)?$ f VarFile-u +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}(\\.mbox)?$ d VarDir +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}\\.mbox/@@{MAILMAN_LISTS}\\.mbox$ f VarFile +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/@@{YEAR4D}-@@{MAILMAN_MONTH}$ d VarDir+ANF +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/(database|digest\\.mbox|index\\.html|(pending|pipermail)\\.pck)$ f VarFile +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/@@{YEAR4D}-@@{MAILMAN_MONTH}\\.txt(\\.gz)?$ f VarFile+ANF +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/(attachments|database)$ d VarDir-n +/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/attachments/@@{YEAR4D}[[:digit:]]{4}/[[:xdigit:]]{8}$ d VarDir-n +!/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/attachments/@@{YEAR4D}[[:digit:]]{4}(/[[:xdigit:]]{8})?$ d +!/@@{VL_MAILMAN_ARCHIVES}/@@{MAILMAN_LISTS}/attachments/@@{YEAR4D}[[:digit:]]{4}/[[:xdigit:]]{8}/attachment\\.htm$ f +@@endif +!/@@{RUN}/lock/mailman/master-qrunner\\.@@{HOSTNAME}}\\.[[:digit:]]+$ f +/@@{RUN}/mailman$ d VarDir +/@@{RUN}/mailman/mailman\\.pid$ f VarFile +/@@{RUN}/lock/mailman$ d VarDir +@@define MAILMAN_LOGS (bounce|error|mischief|post|qrunner|security|smtp(-failure)?|subscribe|vette) +/var/log/mailman/@@{MAILMAN_LOGS}$ f Log diff --git a/aide/aide.conf.d/31_aide_man b/aide/aide.conf.d/31_aide_man new file mode 100644 index 00000000..c99e6903 --- /dev/null +++ b/aide/aide.conf.d/31_aide_man @@ -0,0 +1,7 @@ +/var/lib/systemd/timers/stamp-man-db\\.timer$ f VarFile + +@@define LANGS (ca|cs|da|de(\\.UTF-8)?|en|es(\\.UTF-8)?|fi|fr(\\.(ISO8859-1|UTF-8))?|gl|hr|hu|id|it(\\.(ISO8859-1|UTF-8))?|ja(\\.UTF-8)?|jp|ko|nl|pl(\\.(UTF-8|ISO8859-2))?|pt(_BR)?|ro|ru|sv|sk|sl|sr|tr|vi|uk|zh(_(CH|CN|TW))?) + +/var/cache/man(/@@{LANGS})?$ d VarDir +/var/cache/man(/@@{LANGS})?/(CACHEDIR\\.TAG|index\\.db)$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_mdadm b/aide/aide.conf.d/31_aide_mdadm new file mode 100644 index 00000000..8f2dd048 --- /dev/null +++ b/aide/aide.conf.d/31_aide_mdadm @@ -0,0 +1,3 @@ +/@@{RUN}/mdadm/(monitor|autorebuild)\\.pid$ f VarFile +/@@{RUN}/mdadm/m(ap|d[0-9]+-uevent)$ f VarInode +/@@{RUN}/mdadm$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_mini-buildd b/aide/aide.conf.d/31_aide_mini-buildd new file mode 100644 index 00000000..b10fb3c4 --- /dev/null +++ b/aide/aide.conf.d/31_aide_mini-buildd @@ -0,0 +1,15 @@ +# this rule becomes active once MBD_CHROOTS is set to a regexp matching +# the chroots that your mini-buildd instances covers + +@@ifdef MBD_CHROOTS +/var/lib/mini-buildd(/(var/tmp|zg/db))?$ d VarDir +/var/lib/mini-buildd/config\\.sqlite$ f VarFile +/var/lib/mini-buildd/zg/db/version$ f VarFile +/var/lib/mini-buildd/var/log/(access|daemon)\\.log$ f Log +!/var/lib/mini-buildd/var/tmp/tmp[[:alnum:]]{5}$ d +/var/lib/mini-buildd/var/tmp/tmp{[:alnum]]{5}/S\\.gpg-agent(|\\.browser|\\.extra|\\.ssh)?$ s +!/var/lib/mini-buildd/var/tmp/tmp[[:alnum:]]{5}/private-keys-v1\\.d$ d +!/var/lib/mini-buildd/var/tmp/tmp{[:alnum]]{5}/(trustdb\\.gpg|pubring.kbx~?)$ f +!/var/lib/mini-buildd/var/chroots(-libdir)?/@@{MBD_CHROOTS}$ d +@@endif + diff --git a/aide/aide.conf.d/31_aide_mlocate b/aide/aide.conf.d/31_aide_mlocate new file mode 100644 index 00000000..45a10a0d --- /dev/null +++ b/aide/aide.conf.d/31_aide_mlocate @@ -0,0 +1,4 @@ +/var/lib/mlocate/mlocate\\.db$ f VarFile +/var/lib/mlocate$ d VarDir +/var/lib/systemd/timers/stamp-mlocate\\.timer$ f VarFile +!/@@{RUN}/mlocate\\.daily\\.lock$ f diff --git a/aide/aide.conf.d/31_aide_modules b/aide/aide.conf.d/31_aide_modules new file mode 100644 index 00000000..e2252b1c --- /dev/null +++ b/aide/aide.conf.d/31_aide_modules @@ -0,0 +1 @@ +/lib/modules/[-0-9\\.]*/modules\\.dep$ f VarFile diff --git a/aide/aide.conf.d/31_aide_munin b/aide/aide.conf.d/31_aide_munin new file mode 100644 index 00000000..5590a10b --- /dev/null +++ b/aide/aide.conf.d/31_aide_munin @@ -0,0 +1,69 @@ +# all four variables need to be defined to active this rule +#@@define MUNIN_DOMAINS undefined +#@@define MUNIN_HOSTS undefined +#@@define MUNIN_DISKDEVS undefined +#@@define MUNIN_DISKS undefined + +@@ifdef MUNIN_DOMAINS +@@ifdef MUNIN_HOSTS +@@ifdef MUNIN_DISKDEVS +@@ifdef MUNIN_DISKS +/@@{RUN}/munin$ d VarDir +!/@@{RUN}/munin/munin-master-processmanager-[[:digit:]]+\\.sock$ s +!/@@{RUN}/munin/munin-(update|@@{MUNIN_DOMAINS}-@@{MUNIN_HOSTS})\\.lock$ f +/var/cache/munin/www/static$ d VarDir +/var/cache/munin/www/static/((definitions|dynazoom)\\.html|favicon\\.ico|(formatdate|querystring|zoom)\\.js|logo(-h)?\\.png|style(-1\\.2|-new)?\\.css)$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}$ d VarDir +/var/cache/munin/www/(disk|exim|munin|network|processes|sensors|system|time)-(day|month|week|year)\\.html$ f VarFile +@@define MUNIN_LOCAL (cpu|df|df_inode|entropy|exim_mail(queue|stats)|forks|fw_packets|http_loadtime|if(_err)?_eth0|interrupts|iostat(_ios)?|irqstats|load|memory|munin_stats|ntp_kernel_(err|pll_freq|pll_off)|ntp_offset|open_(files|inodes)|proc_pri|processes|swap|threads|uptime|users|vmstat) +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/diskstats_(iops|latency|throughput|utilization)$ d VarDir +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/diskstats_(iops|latency|throughput|utilization)/@@{MUNIN_DISKDEVS}(\\.html|-(day|week|month|year)\\.png)$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/diskstats_(iops|latency|throughput|utilization)(\\.html|-(day|week|month|year)\\.png)$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/mysql_(bytes|(slow)?queries|threads)(\\.html|-(day|week|month|year)\\.png)$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/(acpi|netstat)(\\.html|-(day|week|month|year)\\.png)$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}(/@@{MUNIN_HOSTS}/diskstats_(iops|latency|throughput|utilization))?/index\\.html$ f VarFile +/var/cache/munin/www/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/@@{MUNIN_LOCAL}(\\.html|-(day|month|week|year)\\.png)$ f VarFile +/var/cache/munin/www/(@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}/)?(index|problems)\\.html$ f VarFile +/var/lib/munin$ d VarDir +/var/lib/munin/graphs$ f VarFile +/var/lib/munin/(state-@@{MUNIN_DOMAINS}-@@{MUNIN_HOSTS}|datafile|limits|htmlconf)(\\.storable)?$ f VarFile +/var/lib/munin/munin-(graph|update)\\.stats$ f VarFile +/var/lib/munin-node/plugin-state/(munin|nobody)$ d VarDir +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-(forks-forks|swap-swap_(in|out))-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-entropy-entropy-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-cpu-(guest|idle|iowait|irq|nice|softirq|steal|system|user)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-(load-load|threads-threads|uptime-uptime)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-df(_inode)?-(_dev|@@{MUNIN_DISKS})-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-diskstats_iops-@@{MUNIN_DISKDEVS}[_-](avg(rd|wr)rqsz|(rd|wr)io)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-diskstats_(latency)-@@{MUNIN_DISKDEVS}[-_](avg(rd|wr)?wait|svctm)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-diskstats_(throughput)-@@{MUNIN_DISKDEVS}[-_]((rd|wr)bytes)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-diskstats_(utilization)-@@{MUNIN_DISKDEVS}[-_](util)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-exim_mail(queue-(frozen|mails)-g|stats-(completed|received|rejected)-d)\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-fw_packets-(forwarded|received)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-if_err_eth0-(collisions|rcvd|rxdrop|trans|txdrop)-c\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-if_eth0-(down|up)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-interrupts-(ctx|intr)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-iostat-dev[[:digit:]]+_[[:digit:]]{1,2}_(read|write)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-iostat_ios-dev[[:digit:]]+_[[:digit:]]{1,2}_[rw]time-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-irqstats-i([[:digit:]]+|CAL|DFR|ERR|HYP|IWI|LOC|MCE|MCP|MIS|NMI|NPI|PIN|PIW|PMI|RES|RTR|SPU|THR|TLB|TRM)-d\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-memory-(active|apps|buffers|cached|committed|free|inactive|mapped|page_tables|shmem|slab|swap|swap_cache|vmalloc_used)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-munin_stats-(graph|html|limits|update)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-ntp_(kernel_(err-ntp_err|pll_(freq|off)-ntp_pll_(freq|off)))-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-ntp_offset-(delay|jitter|offset)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-open_(files-used|inodes-(max|used))-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-proc_pri-(high|locked|low)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-processes-(dead|idle|paging|processes|runnable|sleeping|stopped|uninterruptible|zombie)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-users-(X|other|pts|pty|tty)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-vmstat-(sleep|wait)-g\\.rrd$ f VarFile +/var/lib/munin/@@{MUNIN_DOMAINS}/@@{MUNIN_HOSTS}-http_loadtime-http___localhost_-g\\.rrd$ f VarFile +@@endif +@@endif +@@endif +@@endif + +/var/lib/munin-node/plugin-state/munin/munin_stats-::ffff:127\\.0\\.0\\.1$ f VarFile +/var/lib/munin-node/plugin-state/nobody/(disk|exim_mail)stats-::ffff:127\\.0\\.0\\.1$ f VarFile +/var/lib/munin-node/plugin-state/nobody/iostat-ios\\.state$ f VarFile + +/var/log/munin/munin-(html|limits|node|update)\\.log$ f Log + diff --git a/aide/aide.conf.d/31_aide_munin-nodes b/aide/aide.conf.d/31_aide_munin-nodes new file mode 100755 index 00000000..c250b055 --- /dev/null +++ b/aide/aide.conf.d/31_aide_munin-nodes @@ -0,0 +1,23 @@ +#!/bin/sh +# +# generate aide exclude patterns for all nodes listed in $MUNINCONF + +MUNINCONF=/etc/munin/munin.conf + +[ -e $MUNINCONF ] || exit 0 + +HOSTS=$(grep '^\[[[:alnum:]:.]\+\]' $MUNINCONF | tr -d '[]') + +escape_dots() +{ + echo "$1" | sed 's/\./\\\\./g' +} + +for HOST in $HOSTS; do + DOMAIN=$(escape_dots "${HOST#*.}") + DHOST=$(escape_dots "${HOST}") + + printf "/var/cache/munin/www/%s/(index\\.html|%s/[-_[:alnum:]]+\\.(png|html))$ f VarFile" "${DOMAIN}\\n" "${DHOST}" + printf "/var/lib/munin/%s/%s-.*\\.rrd$ f VarFile" "${DOMAIN}" "${DHOST}\\n" + printf "/@@{RUN}/munin/munin-(update|datafile|%s-%s|limits)\\.lock$ f VarFile\\n" "${DOMAIN}" "${DHOST}" +done diff --git a/aide/aide.conf.d/31_aide_mysql-server b/aide/aide.conf.d/31_aide_mysql-server new file mode 100644 index 00000000..83f3fd8f --- /dev/null +++ b/aide/aide.conf.d/31_aide_mysql-server @@ -0,0 +1,9 @@ +/var/(lib|log)/mysql$ d VarDir +/var/lib/mysql/mysql$ d VarDir +/var/lib/mysql/mysql/(general|slow)_log\\.(CSM|CSV|frm)$ f VarFile +/var/lib/mysql/(ibdata1|ib_logfile[01])$ f VarFile +/var/log/mysql/mysql-bin\\.index$ f VarFile +!/var/log/mysql/mysql-bin\\.[0-9]{3}$ d +!/var/log/mysql/mysql-bin\\.[0-9]{6}$ d +/@@{RUN}/mysqld/mysqld\\.(sock|pid)$ f VarFile +/@@{RUN}/mysqld$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_needrestart b/aide/aide.conf.d/31_aide_needrestart new file mode 100644 index 00000000..f61f7634 --- /dev/null +++ b/aide/aide.conf.d/31_aide_needrestart @@ -0,0 +1 @@ +!/@@{RUN}/needrestart$ d diff --git a/aide/aide.conf.d/31_aide_network b/aide/aide.conf.d/31_aide_network new file mode 100644 index 00000000..beb6c43f --- /dev/null +++ b/aide/aide.conf.d/31_aide_network @@ -0,0 +1,2 @@ +/@@{RUN}/network$ d VarDirInode +/@@{RUN}/network/ifstate$ f VarInode diff --git a/aide/aide.conf.d/31_aide_network-manager b/aide/aide.conf.d/31_aide_network-manager new file mode 100644 index 00000000..1cbc4e94 --- /dev/null +++ b/aide/aide.conf.d/31_aide_network-manager @@ -0,0 +1,4 @@ +/@@{RUN}/NetworkManager(/devices)?$ d VarDirInode +/@@{RUN}/NetworkManager/resolv\\.conf$ f VarFile +/var/lib/NetworkManager$ d VarDir +/var/lib/NetworkManager/(NetworkManager\\.state|timestamps)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_nfs b/aide/aide.conf.d/31_aide_nfs new file mode 100644 index 00000000..6578b395 --- /dev/null +++ b/aide/aide.conf.d/31_aide_nfs @@ -0,0 +1,8 @@ +/@@{RUN}/(rpc\\.statd|sm-notify)\\.pid$ f VarFile +/var/lib/nfs/state$ f VarFile +/var/lib/nfs/etab$ f VarInode +/var/lib/nfs/rpc_pipefs/nfs/clnt[0-9]/(info|krb5|idmap)$ f VarTime +/var/lib/nfs/rpc_pipefs/nfs/clnt[0-9]$ d VarDir +/var/lib/nfs/rpc_pipefs/(statd|portmap|nfs|mount|lockd)$ d VarDir +/var/lib/nfs/rpc_pipefs$ d VarDirInode +/var/lib/nfs(/v4recovery)?$ d VarDir diff --git a/aide/aide.conf.d/31_aide_nrpe b/aide/aide.conf.d/31_aide_nrpe new file mode 100644 index 00000000..e9992c78 --- /dev/null +++ b/aide/aide.conf.d/31_aide_nrpe @@ -0,0 +1,2 @@ +/@@{RUN}/nagios/nrpe\\.pid$ f VarFile +/@@{RUN}/nagios$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_nscd b/aide/aide.conf.d/31_aide_nscd new file mode 100644 index 00000000..b63e6fa9 --- /dev/null +++ b/aide/aide.conf.d/31_aide_nscd @@ -0,0 +1,3 @@ +/var/cache/nscd/(passwd|group|services)$ f VarFile +/@@{RUN}/nscd/(socket|nscd\\.pid)$ f VarFile +/@@{RUN}/nscd$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_nslcd b/aide/aide.conf.d/31_aide_nslcd new file mode 100644 index 00000000..15c308fa --- /dev/null +++ b/aide/aide.conf.d/31_aide_nslcd @@ -0,0 +1,2 @@ +/@@{RUN}/nslcd/(socket|nslcd\\.pid)$ f VarFile +/@@{RUN}/nslcd$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_ntp-server b/aide/aide.conf.d/31_aide_ntp-server new file mode 100644 index 00000000..f4e6a57b --- /dev/null +++ b/aide/aide.conf.d/31_aide_ntp-server @@ -0,0 +1,6 @@ +/var/lib/ntp/ntp\\.drift$ f VarFile +/var/lib/ntp$ d VarDir +!/var/log/ntpstats/peerstats(\\.[0-9]{8})? f +!/var/log/ntpstats/loopstats(\\.[0-9]{8})? f +/var/log/ntpstats$ d VarDir +/@@{RUN}/ntpd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_openvpn b/aide/aide.conf.d/31_aide_openvpn new file mode 100644 index 00000000..b996297e --- /dev/null +++ b/aide/aide.conf.d/31_aide_openvpn @@ -0,0 +1 @@ +/@@{RUN}/openvpn/client\\.status$ f VarFile diff --git a/aide/aide.conf.d/31_aide_openvpn-server b/aide/aide.conf.d/31_aide_openvpn-server new file mode 100644 index 00000000..49f6d2a7 --- /dev/null +++ b/aide/aide.conf.d/31_aide_openvpn-server @@ -0,0 +1,6 @@ +/etc/openvpn/ipp\\.txt$ f VarFile +!/(var/)?tmp/systemd-private-[[:xdigit:]]{32}-openvpn@server\\.service-[[:alnum:]]{6}$ d +!/(var/)?tmp/systemd-private-[[:xdigit:]]{32}-openvpn@server\\.service-[[:alnum:]]{6}/tmp$ d +/@@{RUN}/openvpn$ d VarDir +/@@{RUN}/openvpn/server\\.(pid|status)$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_opie-server b/aide/aide.conf.d/31_aide_opie-server new file mode 100644 index 00000000..19438594 --- /dev/null +++ b/aide/aide.conf.d/31_aide_opie-server @@ -0,0 +1 @@ +/etc/opiekeys$ f VarFile diff --git a/aide/aide.conf.d/31_aide_pam_motd b/aide/aide.conf.d/31_aide_pam_motd new file mode 100644 index 00000000..96564da9 --- /dev/null +++ b/aide/aide.conf.d/31_aide_pam_motd @@ -0,0 +1 @@ +!/@@{RUN}/motd\\.dynamic$ f diff --git a/aide/aide.conf.d/31_aide_pcscd b/aide/aide.conf.d/31_aide_pcscd new file mode 100644 index 00000000..6728634d --- /dev/null +++ b/aide/aide.conf.d/31_aide_pcscd @@ -0,0 +1,2 @@ +/@@{RUN}/pcscd/pcscd\\.(pub|comm|pid)$ f VarFile +/@@{RUN}/pcscd(/pcscd\\.events)?$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_php-common b/aide/aide.conf.d/31_aide_php-common new file mode 100644 index 00000000..7bd5b6da --- /dev/null +++ b/aide/aide.conf.d/31_aide_php-common @@ -0,0 +1,4 @@ +/var/lib/systemd/timers/stamp-phpsessionclean\\.timer$ f VarFile +/var/lib/php/sessions$ d VarDir +!/var/lib/php/sessions/sess_[[:digit:][:lower:]]{26}$ f +!/var/lib/php/sessions/sess_[[:xdigit:]]{32}$ f diff --git a/aide/aide.conf.d/31_aide_php-fpm b/aide/aide.conf.d/31_aide_php-fpm new file mode 100644 index 00000000..06ffb502 --- /dev/null +++ b/aide/aide.conf.d/31_aide_php-fpm @@ -0,0 +1,6 @@ +@@define PHPFPMLOGS var/log/php7\\.3-fpm\\.log +/@@{PHPFPMLOGS}$ f FreqRotLog +/@@{PHPFPMLOGS}\\.1$ f LowLog +/@@{PHPFPMLOGS}\\.2\\.gz$ f LoSerMemberLog +/@@{PHPFPMLOGS}\\.([3456789]|1[01])\\.gz$ f SerMemberLog +/@@{PHPFPMLOGS}\\.12\\.gz$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_php7 b/aide/aide.conf.d/31_aide_php7 new file mode 100644 index 00000000..a6654c3e --- /dev/null +++ b/aide/aide.conf.d/31_aide_php7 @@ -0,0 +1,3 @@ +/var/lib/php/sessions$ d VarDir +/var/lib/php/sessions/sess_[0-9a-z]{26}$ f VarFile+ANF+ARF +/var/lib/php/sessions/sess_[0-9a-z]{32}$ f VarFile+ANF+ARF diff --git a/aide/aide.conf.d/31_aide_pm-utils b/aide/aide.conf.d/31_aide_pm-utils new file mode 100644 index 00000000..ae396ecf --- /dev/null +++ b/aide/aide.conf.d/31_aide_pm-utils @@ -0,0 +1 @@ +/@@{RUN}/pm-utils/(pm-(suspend|powersave)(/storage)?|locks)$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_portmap b/aide/aide.conf.d/31_aide_portmap new file mode 100644 index 00000000..b8e13f44 --- /dev/null +++ b/aide/aide.conf.d/31_aide_portmap @@ -0,0 +1,2 @@ +/@@{RUN}/portmap(\\.pid|_mapping)$ f VarFile +/@@{RUN}/sendsigs\\.omit\\.d/portmap$ f VarInode diff --git a/aide/aide.conf.d/31_aide_postfix b/aide/aide.conf.d/31_aide_postfix new file mode 100644 index 00000000..bb70bbde --- /dev/null +++ b/aide/aide.conf.d/31_aide_postfix @@ -0,0 +1,40 @@ +@@ifndef POSTFIX_QUEUE_DIRECTORY +@@define POSTFIX_QUEUE_DIRECTORY var/spool/postfix +@@endif +@@ifndef POSTFIX_DATA_DIRECTORY +@@define POSTFIX_DATA_DIRECTORY var/lib/postfix +@@endif +@@ifndef POSTFIX_SPOOL_DIRECTORY +@@define POSTFIX_SPOOL_DIRECTORY var/mail +@@endif + +/@@{POSTFIX_DATA_DIRECTORY}/(master.lock|prng_exch|smtpd?_scache\\.db)$ f VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/dev$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/dev/u?random$ c VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/etc(/ssl(/certs)?)?$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/etc/(hosts|localtime|nsswitch.conf|resolv.conf|services)$ f VarFile +/@@{POSTFIX_QUEUE_DIRECTORY}/etc/ssl/certs/ca-certificates.crt$ f VarTime + +/@@{POSTFIX_QUEUE_DIRECTORY}/lib(/@@{DEB_HOST_GNU_TYPE})?$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/lib/@@{DEB_HOST_GNU_TYPE}/lib[_a-z0-9\\.-]+\\.so(\\.[0-9])?$ f VarInode + +/@@{POSTFIX_QUEUE_DIRECTORY}/usr(/lib(/zoneinfo)?)?$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/usr/lib/zoneinfo/localtime$ f VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/pid/master.pid$ f VarFile +/@@{POSTFIX_QUEUE_DIRECTORY}/pid/(inet|unix)\\..*$ f VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/private$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/private/(anvil|bounce|bsmtp|defer|discard|error|ifmail|lmtp|local|mail(drop|man)|proxymap|relay|retry|rewrite|scache|scalemail-backend|smtp(-amavis)?|tlsmgr|trace|uucp|verify|virtual)$ f VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/public$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/public/(cleanup|flush|pickup|qmgr|showq)$ f VarFile + +/@@{POSTFIX_QUEUE_DIRECTORY}/(active|corrupt|defer(red)?|hold|saved|bounce|flush|incoming|maildrop|trace)$ d VarDir +/@@{POSTFIX_QUEUE_DIRECTORY}/defer(red)?/[A-F0-9]$ d VarDir + +!/@@{POSTFIX_QUEUE_DIRECTORY}/(active|corrupt|hold|saved|bounce|flush|incoming|maildrop|trace)/[A-F0-9]{10}$ f +!/@@{POSTFIX_QUEUE_DIRECTORY}/defer(red)?/[A-F0-9]/[A-F0-9]{10}$ f + diff --git a/aide/aide.conf.d/31_aide_postfix-cluebringer b/aide/aide.conf.d/31_aide_postfix-cluebringer new file mode 100644 index 00000000..7b86d802 --- /dev/null +++ b/aide/aide.conf.d/31_aide_postfix-cluebringer @@ -0,0 +1,2 @@ +/@@{RUN}/cluebringer/cbpolicyd.pid$ f VarFile +/@@{RUN}/cluebringer d VarDirInode diff --git a/aide/aide.conf.d/31_aide_postgresql b/aide/aide.conf.d/31_aide_postgresql new file mode 100644 index 00000000..845b3400 --- /dev/null +++ b/aide/aide.conf.d/31_aide_postgresql @@ -0,0 +1,23 @@ +!/@@{RUN}/postgresql/\\.s\\.PGSQL\\.5432$ s +!/@@{RUN}/postgresql/\\.s\\.PGSQL\\.5432\\.lock$ f +/@@{RUN}/postgresql/11-main\\.pg_stat_tmp$ d VarDir +!/@@{RUN}/postgresql/11-main\\.pg_stat_tmp/(db_[[:digit:]]+|global)\\.stat$ f +/var/lib/postgresql/11/main/base/[[:digit:]]{5,6}$ d VarDir +!/var/lib/postgresql/11/main/base/[[:digit:]]{5,6}/[[:digit:]]{4,6}$ f +/var/lib/postgresql/11/main/base/[[:digit:]]{5,6}/([[:digit:]]{4,6}(_(fsm|vm))|pg_internal\\.init)$ f VarFile +/var/lib/postgresql/11/main/(global|pg_(logical|subtrans|wal|xact))$ d VarDir +/var/lib/postgresql/11/main/global/pg_(control|internal\\.init)$ f VarFile +/var/lib/postgresql/11/main/global/[[:digit:]]{4}$ f VarFile +/var/lib/postgresql/11/main/pg_logical/replorigin_checkpoint$ f VarFile +/var/lib/postgresql/11/main/pg_multixact/offsets/0000$ f VarFile +!/var/lib/postgresql/11/main/pg_subtrans/[[:xdigit:]]{4}$ f +!/var/lib/postgresql/11/main/pg_wal/[[:xdigit:]]{24}$ f +/var/lib/postgresql/11/main/pg_xact/00[0-2][[:xdigit:]]$ f VarFile + +/var/log/postgresql$ d VarDir +/var/log/postgresql/postgresql-11-main\\.log$ f Log +/var/log/postgresql/postgresql-11-main\\.log\\.1$ f LowLog +/var/log/postgresql/postgresql-11-main\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/postgresql/postgresql-11-main\\.log\\.[3456789]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/postgresql/postgresql-11-main\\.log\\.10\\.@@{LOGEXT}$ f HiSerMemberLog + diff --git a/aide/aide.conf.d/31_aide_postgrey b/aide/aide.conf.d/31_aide_postgrey new file mode 100644 index 00000000..257c6006 --- /dev/null +++ b/aide/aide.conf.d/31_aide_postgrey @@ -0,0 +1,4 @@ +/var/lib/postgrey$ d VarDir +/var/lib/postgrey/postgrey(|lock)\\.db$ f VarFile +/var/lib/postgrey/log\\.[0-9]{10}$ f VarFile +/var/lib/postgrey/__db\\.[0-9]{3}$ f VarFile diff --git a/aide/aide.conf.d/31_aide_privoxy b/aide/aide.conf.d/31_aide_privoxy new file mode 100644 index 00000000..9cd81636 --- /dev/null +++ b/aide/aide.conf.d/31_aide_privoxy @@ -0,0 +1 @@ +/var/log/privoxy/logfile$ f Log diff --git a/aide/aide.conf.d/31_aide_proftpd b/aide/aide.conf.d/31_aide_proftpd new file mode 100644 index 00000000..e2153269 --- /dev/null +++ b/aide/aide.conf.d/31_aide_proftpd @@ -0,0 +1,4 @@ +/var/log/proftpd/proftpd(_(access|auth|xfer))?\\.log$ f Log +/@@{RUN}/proftpd/proftpd\\.(delay|pid|scoreboard)$ f VarFile +/var/log/proftpd$ d VarDir +/@@{RUN}/proftpd$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_resolvconf b/aide/aide.conf.d/31_aide_resolvconf new file mode 100644 index 00000000..cc7cf01e --- /dev/null +++ b/aide/aide.conf.d/31_aide_resolvconf @@ -0,0 +1,5 @@ +/etc/resolv\\.conf$ f VarFile +/@@{RUN}/resolvconf/interface/(wlan|eth)[0-9]+(\\.(dhclient|inet))?$ f VarFile +/@@{RUN}/resolvconf/enable-updates$ f VarFile +/@@{RUN}/resolvconf/resolv\\.conf$ f VarFile +/@@{RUN}/resolvconf(/interface)?$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_rkhunter b/aide/aide.conf.d/31_aide_rkhunter new file mode 100644 index 00000000..7a84c5f6 --- /dev/null +++ b/aide/aide.conf.d/31_aide_rkhunter @@ -0,0 +1,8 @@ +/var/lib/rkhunter/db/(mirrors|rkhunter_prop_list)\\.dat$ f VarTime +/var/lib/rkhunter/tmp/(group|passwd)$ f VarFile +/var/lib/rkhunter/(db|tmp)$ d VarDir +/var/log/rkhunter\\.log$ f Log +/var/log/rkhunter\\.log\\.1$ f LowLog +/var/log/rkhunter\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/rkhunter\\.log\\.3\\.@@{LOGEXT}$ f SerMemberLog +/var/log/rkhunter\\.log\\.4\\.@@{LOGEXT}$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_rngd b/aide/aide.conf.d/31_aide_rngd new file mode 100644 index 00000000..3b356d7c --- /dev/null +++ b/aide/aide.conf.d/31_aide_rngd @@ -0,0 +1 @@ +/@@{RUN}/rngd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_root-dotfiles b/aide/aide.conf.d/31_aide_root-dotfiles new file mode 100644 index 00000000..c080b110 --- /dev/null +++ b/aide/aide.conf.d/31_aide_root-dotfiles @@ -0,0 +1,4 @@ +#/root/\\.bash_history$ f VarFile +#/root/\\.lesshst$ f VarFile +#/root/\\.viminfo$ f VarFile +#/root$ d VarDir diff --git a/aide/aide.conf.d/31_aide_rsnapshot b/aide/aide.conf.d/31_aide_rsnapshot new file mode 100644 index 00000000..66a004b5 --- /dev/null +++ b/aide/aide.conf.d/31_aide_rsnapshot @@ -0,0 +1,4 @@ +/var/log/rsnapshot\\.log$ f Log +/var/log/rsnapshot\\.log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/rsnapshot\\.log\\.[2-5]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/rsnapshot\\.log\\.6\\.@@{LOGEXT}$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_rsyslog b/aide/aide.conf.d/31_aide_rsyslog new file mode 100644 index 00000000..228830b6 --- /dev/null +++ b/aide/aide.conf.d/31_aide_rsyslog @@ -0,0 +1,9 @@ +@@define LOGFILES4R (syslog|messages|debug|(cron|lpr|auth|daemon|kern|user)\\.log|mail\\.(log|err|warn|info)) +/var/log/@@{LOGFILES4R}$ f Log +/var/log/@@{LOGFILES4R}\\.1$ f LowLog +/var/log/@@{LOGFILES4R}\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/@@{LOGFILES4R}\\.3\\.@@{LOGEXT}$ f SerMemberLog +/var/log/@@{LOGFILES4R}\\.4\\.@@{LOGEXT}$ f HiSerMemberLog +/var/log$ d VarDir +/@@{RUN}/rsyslogd.pid$ f VarFile +/@@{RUN}/sendsigs\\.omit\\.d/rsyslog$ f VarInode diff --git a/aide/aide.conf.d/31_aide_run_systemd_netif b/aide/aide.conf.d/31_aide_run_systemd_netif new file mode 100644 index 00000000..dafbda12 --- /dev/null +++ b/aide/aide.conf.d/31_aide_run_systemd_netif @@ -0,0 +1,3 @@ +/@@{RUN}/systemd/netif(/(links|lldp|leases))?$ d VarDir +/@@{RUN}/systemd/netif/state$ f VarFile +/@@{RUN}/systemd/netif/(links|lldp|leases)/[0-9]{1,2}$ f VarFile diff --git a/aide/aide.conf.d/31_aide_run_systemd_resolve b/aide/aide.conf.d/31_aide_run_systemd_resolve new file mode 100644 index 00000000..101e47fc --- /dev/null +++ b/aide/aide.conf.d/31_aide_run_systemd_resolve @@ -0,0 +1,2 @@ +/@@{RUN}/systemd/resolve$ d VarDir +/@@{RUN}/systemd/resolve/resolv\\.conf$ f VarFile diff --git a/aide/aide.conf.d/31_aide_run_tmpfiles b/aide/aide.conf.d/31_aide_run_tmpfiles new file mode 100644 index 00000000..c16f488b --- /dev/null +++ b/aide/aide.conf.d/31_aide_run_tmpfiles @@ -0,0 +1,2 @@ +/@@{RUN}/tmpfiles\\.d$ d VarDirInode +/@@{RUN}/tmpfiles\\.d/static-nodes\\.conf$ f VarInode diff --git a/aide/aide.conf.d/31_aide_runuser b/aide/aide.conf.d/31_aide_runuser new file mode 100644 index 00000000..d58707d1 --- /dev/null +++ b/aide/aide.conf.d/31_aide_runuser @@ -0,0 +1,13 @@ +/@@{RUN}/user$ d VarDirInode-n +!/@@{RUN}/user/[0-9]+(/(gnupg|systemd))?$ d +!/@@{RUN}/user/[0-9]+/gnupg/S\\.(dirmngr|gpg-agent(\\.(browser|extra|ssh))?)$ s +!/@@{RUN}/user/[0-9]+/gnupg/d\\.[0-9a-z]{24}$ d +!/@@{RUN}/user/[0-9]+/(bus|systemd/(notify|private))$ s +!/@@{RUN}/user/[0-9]+/systemd/(transient|units)$ d +!/@@{RUN}/user/[0-9]+/systemd/inaccessible$ d +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/blk$ b +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/chr$ c +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/dir$ d +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/fifo$ p +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/reg$ +!/@@{RUN}/user/[0-9]+/systemd/inaccessible/sock$ s diff --git a/aide/aide.conf.d/31_aide_samba b/aide/aide.conf.d/31_aide_samba new file mode 100644 index 00000000..2a8abe5d --- /dev/null +++ b/aide/aide.conf.d/31_aide_samba @@ -0,0 +1,19 @@ +/@@{RUN}/samba/(smbd_clientupd|leases|names|printer_list|serverid|smbXsrv_((open|session|tcon|version)_global))\\.tdb$ f VarFile +!/@@{RUN}/samba/(smbd_cleanupd|smbXsrv_((client)_global))\\.tdb$ f +/@@{RUN}/samba/smbd\\.pid$ f VarFile +/@@{RUN}/samba/(msg\\.lock|nmbd)$ d VarDirInode +/run/samba/msg.lock/[[:digit:]]+$ f VarFile +/@@{RUN}/samba/(ncalrpc(/np)?)$ d VarDirInode +!/@@{RUN}/samba/ncalrpc/np/spoolss$ s +/@@{RUN}/samba/nmbd/unexpected$ s VarFile +!/@@{RUN}/samba/namelist\\.debug$ f +/var/cache/samba$ d VarDir +/var/cache/samba/(browse\\.dat|gencache\\.tdb)$ f VarFile +/var/log/samba$ d VarDir +/var/log/samba/log\\.[sn]mbd$ f Log +/var/log/samba/log\\.[sn]mbd\\.1$ f LowLog +/var/log/samba/log\\.[sn]mbd\\.2.@@{LOGEXT}$ f LoSerMemberLog +/var/log/samba/log\\.[sn]mbd\\.[23456]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/samba/log\\.[sn]mbd\\.7.@@{LOGEXT}$ f HiSerMemberLog +/var/lib/samba/private/msg\\.sock$ d VarDir +!/var/lib/samba/private/msg\\.sock/[[:digit:]]+$ s diff --git a/aide/aide.conf.d/31_aide_saslauthd b/aide/aide.conf.d/31_aide_saslauthd new file mode 100644 index 00000000..8bcd123b --- /dev/null +++ b/aide/aide.conf.d/31_aide_saslauthd @@ -0,0 +1,4 @@ +/@@{RUN}/saslauthd$ d VarDirInode +/@@{RUN}/saslauthd/cache.(flock|mmap)$ f VarFile +/@@{RUN}/saslauthd/mux(\\.accept)?$ f VarFile +/@@{RUN}/saslauthd/saslauthd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_screen b/aide/aide.conf.d/31_aide_screen new file mode 100644 index 00000000..f9d410c0 --- /dev/null +++ b/aide/aide.conf.d/31_aide_screen @@ -0,0 +1,5 @@ +@@define SCREEN_ALLOWED_USERS ([[:alnum:]]+) +/@@{RUN}/screen$ d VarDirInode-n +!/@@{RUN}/screen/S-@@{SCREEN_ALLOWED_USERS}$ d +!/@@{RUN}/screen/S-@@{SCREEN_ALLOWED_USERS}/[[:digit:]]+.([[:alnum:]]+|pts-[[:digit:]]+\\.@@{HOSTNAME})$ s + diff --git a/aide/aide.conf.d/31_aide_slapd b/aide/aide.conf.d/31_aide_slapd new file mode 100644 index 00000000..6ba9f59f --- /dev/null +++ b/aide/aide.conf.d/31_aide_slapd @@ -0,0 +1,10 @@ +/var/lib/ldap/[[:alnum:]]+\\.bdb$ f VarTime +/var/lib/ldap/__db\\.00[1-5]+$ f VarFile +/var/lib/ldap/log\\.0000000001$ f VarFile +/var/lib/ldap/alock$ f VarFile +/var/lib/ldap$ d VarDir + +/@@{RUN}/ldapi$ f VarInode +/@@{RUN}/slapd/slapd\\.args$ f VarInode +/@@{RUN}/slapd/slapd\\.pid$ f VarFile +/@@{RUN}/slapd$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_slrn b/aide/aide.conf.d/31_aide_slrn new file mode 100644 index 00000000..9761bbef --- /dev/null +++ b/aide/aide.conf.d/31_aide_slrn @@ -0,0 +1 @@ +/var/lib/slrn/newsgroups\\.dsc$ f VarFile diff --git a/aide/aide.conf.d/31_aide_smartmontools b/aide/aide.conf.d/31_aide_smartmontools new file mode 100644 index 00000000..d88b8d91 --- /dev/null +++ b/aide/aide.conf.d/31_aide_smartmontools @@ -0,0 +1,4 @@ +/@@{RUN}/smartd\\.pid$ f VarFile +/var/lib/smartmontools/smartd\\.[-_[:alnum:]]+\\.ata\\.state~?$ f VarFile +/var/lib/smartmontools/attrlog\\.[-_[:alnum:]]+\\.ata\\.csv$ f VarFile +/var/lib/smartmontools$ d VarDir diff --git a/aide/aide.conf.d/31_aide_smokeping b/aide/aide.conf.d/31_aide_smokeping new file mode 100644 index 00000000..dd2c552b --- /dev/null +++ b/aide/aide.conf.d/31_aide_smokeping @@ -0,0 +1,10 @@ +@@define VLS var/lib/smokeping +@@define VCS var/cache/smokeping +/@@{VLS}/Local/LocalMachine\\.rrd$ f VarFile +/@@{VLS}/__sortercache$ d VarDir +/@@{VLS}/__sortercache/data\\.FPing6?\\.storable$ f VarFile +/@@{VLS}/images/[-a-z0-9_]+/[-a-z0-9_]+_(last_(10800?|31104000|86400)|mini)\\.png$ f VarFile +/@@{VLS}/[a-z-]+(/[-a-z0-9_]+)?/[-a-z0-9_]+(_[0-9a-f_]+)?\\.rrd$ f VarFile +/@@{VCS}/images/__navcache$ d VarDir +!/@@{VCS}/images/__navcache/[[:digit:]]{13,15}_[[:digit:]]{10}_[[:digit:]]{10}\\.png$ f + diff --git a/aide/aide.conf.d/31_aide_sniproxy b/aide/aide.conf.d/31_aide_sniproxy new file mode 100644 index 00000000..98c9016f --- /dev/null +++ b/aide/aide.conf.d/31_aide_sniproxy @@ -0,0 +1,6 @@ +@@define SNIPROXY_LOG var/log/sniproxy/https?_access\\.log +/@@{SNIPROXY_LOG}$ f FreqRotLog +/@@{SNIPROXY_LOG}\\.1$ f LowLog +/@@{SNIPROXY_LOG}\\.2\\.@@{LOGEXT}$ f LoSerMemberLog +/@@{SNIPROXY_LOG}\\.[345678]\\.@@{LOGEXT}$ f SerMemberLog +/@@{SNIPROXY_LOG}\\.9\\.@@{LOGEXT}$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_snmpd b/aide/aide.conf.d/31_aide_snmpd new file mode 100644 index 00000000..4f1de8a4 --- /dev/null +++ b/aide/aide.conf.d/31_aide_snmpd @@ -0,0 +1,3 @@ +/var/lib/snmp/snmpd\\.conf$ f VarFile +/var/lib/snmp$ d VarDir +/@@{RUN}/snmpd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_spamassassin b/aide/aide.conf.d/31_aide_spamassassin new file mode 100644 index 00000000..0ac23334 --- /dev/null +++ b/aide/aide.conf.d/31_aide_spamassassin @@ -0,0 +1,22 @@ +/@@{RUN}/spamd\\.pid$ f VarFile +/var/spool/spamassassin/bayes$ d VarDir +/var/spool/spamassassin/bayes/bayes_(journal|seen|toks)$ f VarFile +!/var/spool/spamassassin/bayes/bayes\\.lock(\\.@@{FQDN}\\.[[:digit:]]+)?$ f +/var/lib/spamassassin/sa-update-keys$ d VarDir +@@define SABASE var/lib/spamassassin/3.004002 +@@define SAUPDATES @@{SABASE}/updates_spamassassin_org +/@@{SABASE}$ d VarDir +/@@{SAUPDATES}$ d VarDir +/@@{SAUPDATES}\\.cf$ f VarFile +/@@{SAUPDATES}/local\\.cf$ f VarFile +/@@{SAUPDATES}/10_(default_prefs|hasbase)\\.cf$ f VarFile +/@@{SAUPDATES}/20_(advance_fee|aux_tlds|body_tests|compensate|dnsbl_tests|drugs|dynrdns|fake_helo_tests|freemail(|_domains|_mailcom_domains)|head_tests|html_tests|imageinfo|mailspike|meta_tests|net_tests|pdfinfo|phrases|porn|ratware|uri_tests|vbounce)\\.cf$ f VarFile +/@@{SAUPDATES}/23_(bayes)\\.cf$ f VarFile +/@@{SAUPDATES}/25_(accessdb|antivirus|asn|dcc|dkim|dnswl|hashcash|pyzor|razor2|replace|spf|textcat|uribl)\\.cf$ f VarFile +/@@{SAUPDATES}/30_(text_(de|fr|it|nl|pl|pt_br))\\.cf$ f VarFile +/@@{SAUPDATES}/50_(scores)\\.cf$ f VarFile +/@@{SAUPDATES}/60_(adsp_override_dkim|awl|bayes_stopwords|shortcircuit|txrep|whitelist(|_auth|_dkim|_spf|_subject))\\.cf$ f VarFile +/@@{SAUPDATES}/72_(active|scores)\\.cf$ f VarFile +/@@{SAUPDATES}/73_(sandbox_manual_scores)\\.cf$ f VarFile +/@@{SAUPDATES}/STATISTICS-set[0123]-72_scores\\.cf\\.txt$ f VarFile +/@@{SAUPDATES}/(languages|regression_tests\\.cf|sa-update-pubkey\\.txt|user_prefs\\.template)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_spampd b/aide/aide.conf.d/31_aide_spampd new file mode 100644 index 00000000..8d2acb12 --- /dev/null +++ b/aide/aide.conf.d/31_aide_spampd @@ -0,0 +1,2 @@ +/var/cache/spampd$ d VarDir +/@@{RUN}/spampd.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_squid b/aide/aide.conf.d/31_aide_squid new file mode 100644 index 00000000..77301453 --- /dev/null +++ b/aide/aide.conf.d/31_aide_squid @@ -0,0 +1,4 @@ +!/var/spool/squid/[0-9A-F]{2}/[0-9A-F]{2}/[0-9A-F]{8} f +/var/spool/squid/(netdb_state|swap.state(.last-clean)?)$ f VarFile +/var/spool/squid/[0-9A-F]{2}(/[0-9A-F]{2})?$ d VarDir +/var/log/squid/(access|store)\\.log$ f Log diff --git a/aide/aide.conf.d/31_aide_ssh-agent b/aide/aide.conf.d/31_aide_ssh-agent new file mode 100644 index 00000000..8733257b --- /dev/null +++ b/aide/aide.conf.d/31_aide_ssh-agent @@ -0,0 +1,2 @@ +!/tmp/ssh-[[:alnum:]]{10}$ d +!/tmp/ssh-[[:alnum:]]{10}/agent\\.[[:digit:]]+$ s diff --git a/aide/aide.conf.d/31_aide_ssh-server b/aide/aide.conf.d/31_aide_ssh-server new file mode 100644 index 00000000..d5b01599 --- /dev/null +++ b/aide/aide.conf.d/31_aide_ssh-server @@ -0,0 +1,2 @@ +/@@{RUN}/sshd.pid$ f VarFile +/@@{RUN}/sshd$ d VarFile diff --git a/aide/aide.conf.d/31_aide_sshd b/aide/aide.conf.d/31_aide_sshd new file mode 100644 index 00000000..7f4fa2a2 --- /dev/null +++ b/aide/aide.conf.d/31_aide_sshd @@ -0,0 +1,2 @@ +!/@@{RUN}/sshd$ d + diff --git a/aide/aide.conf.d/31_aide_sudo b/aide/aide.conf.d/31_aide_sudo new file mode 100644 index 00000000..e321077a --- /dev/null +++ b/aide/aide.conf.d/31_aide_sudo @@ -0,0 +1,5 @@ +@@define SUDO_ALLOWED_USERS ([[:alnum:]]+) + +@@define SUDO_STATE_DIR @@{RUN}/sudo +/@@{SUDO_STATE_DIR}(/ts)?$ d VarDirInode +!/@@{SUDO_STATE_DIR}/ts/@@{SUDO_ALLOWED_USERS}$ f diff --git a/aide/aide.conf.d/31_aide_svn-server b/aide/aide.conf.d/31_aide_svn-server new file mode 100755 index 00000000..90d10df7 --- /dev/null +++ b/aide/aide.conf.d/31_aide_svn-server @@ -0,0 +1,18 @@ +#!/bin/bash + +SVN_REPOS="" + +#shellcheck disable=SC2154 +if [ -r "$UPAC_settingsd/31_aide_svn-server_settings" ]; then + # pull in configuration + #shellcheck disable=SC1090 + . "$UPAC_settingsd/31_aide_svn-server_settings" +fi + +for svnpath in $SVN_REPOS; do + [ -d "${svnpath}" ] || exit 1 + svnpath="${svnpath//\./\\\\.}" + printf "%sdb/(txn-)?current$ f VarFile\\n" "${svnpath}" + printf "%sdb/rev(prop)?s/0/[0-9]+$ f Full+ANF\\n" "${svnpath}" + printf "%s(db(/(txn-protorevs|transactions|rev(prop)?s/0))?|dav/activities\\.d)$ d VarDir\\n" "${svnpath}" +done diff --git a/aide/aide.conf.d/31_aide_syslog-ng b/aide/aide.conf.d/31_aide_syslog-ng new file mode 100644 index 00000000..f06e499e --- /dev/null +++ b/aide/aide.conf.d/31_aide_syslog-ng @@ -0,0 +1,4 @@ +/@@{RUN}/syslog-ng$ d VarDirInode +/@@{RUN}/syslog-ng\\.pid$ f VarFile +/var/lib/syslog-ng$ d VarDir +/var/lib/syslog-ng/syslog-ng.(ctl|persist)$ f VarFile diff --git a/aide/aide.conf.d/31_aide_systemd b/aide/aide.conf.d/31_aide_systemd new file mode 100644 index 00000000..f099a5fb --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd @@ -0,0 +1,44 @@ +@@define RUNSYSD @@{RUN}/systemd + +!/@@{RUN}/initctl$ p +!/@@{RUNSYSD}/initctl$ d +!/@@{RUNSYSD}/initctl/fifo$ p +/@@{RUNSYSD}$ d VarDir +!/@@{RUNSYSD}/fsck\\.progress$ s +!/@@{RUNSYSD}/cgroups-agent$ s +!/@@{RUNSYSD}(/(machines|resolve|seats|sessions|shutdown|system|transient|users|ask-password|generator(\\.late)?))?$ d +!/@@{RUNSYSD}/ask-password-block$ d +!/@@{RUNSYSD}/ask-password-block/[[:digit:]]+:[[:digit:]]$ p +!/@@{RUNSYSD}/generator(\\.late)?/[^/]+\\.(requires|wants)$ d +!/@@{RUNSYSD}/generator(\\.late)?(/[^/]+\\.(requires|wants))?/[-\\\\_[:alnum:]@\\.]+\\.(swap|service|mount|sh|timer)$ l +!/@@{RUNSYSD}/generator(\\.late)?(/[^/]+\\.(requires|wants))?/[-\\\\_[:alnum:]@\\.]+\\.(swap|service|mount|sh|timer)$ f +!/@@{RUNSYSD}/inaccessible$ d +!/@@{RUNSYSD}/inaccessible/blk$ b +!/@@{RUNSYSD}/inaccessible/chr$ c +!/@@{RUNSYSD}/inaccessible/dir$ d +!/@@{RUNSYSD}/inaccessible/fifo$ p +!/@@{RUNSYSD}/inaccessible/reg$ f +!/@@{RUNSYSD}/inaccessible/sock$ s +!/@@{RUNSYSD}/inhibit$ d +/@@{RUNSYSD}/inhibit/[12]$ f VarFile +/@@{RUNSYSD}/inhibit/[12]\\.ref$ p +!/@@{RUNSYSD}/io\\.system\\.ManagedOOM$ s +!/@@{RUNSYSD}/(notify|private)$ s +!/@@{RUNSYSD}/resolve/resolv\\.conf$ f +!/@@{RUNSYSD}/seats/seat0$ f +!/@@{RUNSYSD}/sessions/c?[[:digit:]]+$ f +!/@@{RUNSYSD}/sessions/c?[[:digit:]]+\\.ref$ p +!/@@{RUNSYSD}/show-status$ f +!/@@{RUNSYSD}/transient/session-c[0-9]+\\.scope$ f +!/@@{RUNSYSD}/transient/user-[0-9]+\\.slice$ f +/@@{RUNSYSD}/unit-root$ d VarDirInode +/@@{RUNSYSD}/units$ d VarDirInode +!/@@{RUNSYSD}/units/invocation:(session-c?[0-9]+\\.scope|[-\\\\@:[:alnum:]]+\\.service|([-[:alnum:]]+|\\\\x2d)+\\.(mount|swap))$ l +/@@{RUNSYSD}/userdb$ d VarDirInode +/@@{RUNSYSD}/userdb/io\\.systemd\\.(DynamicUser|Machine)$ s VarFile +/@@{RUN}/tmpfiles\\.d/kmod\\.conf$ f VarFile +/@@{RUN}/credentials$ d VarDirInode +!/(var/)?tmp/systemd-private-[[:xdigit:]]{32}-[-[:alnum:]]+\\.service-[[:alnum:]]{6}$ d +!/(var/)?tmp/systemd-private-[[:xdigit:]]{32}-[-[:alnum:]]+\\.service-[[:alnum:]]{6}/tmp$ d +!/var/lib/systemd/random-seed$ f + diff --git a/aide/aide.conf.d/31_aide_systemd-cron b/aide/aide.conf.d/31_aide_systemd-cron new file mode 100644 index 00000000..f856c92a --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd-cron @@ -0,0 +1,2 @@ +/var/lib/systemd/timers/stamp-cron-daily\\.timer$ f VarFile +/run/systemd/use_run_parts$ f VarFile diff --git a/aide/aide.conf.d/31_aide_systemd-journald b/aide/aide.conf.d/31_aide_systemd-journald new file mode 100644 index 00000000..bc812603 --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd-journald @@ -0,0 +1,16 @@ +!/@@{RUN}/systemd/journal$ d +!/@@{RUN}/systemd/journal/(dev-log|socket|stdout|syslog)$ s +!/@@{RUN}/systemd/journal/flushed$ f +/@@{RUN}/systemd/journal/kernel-seqnum$ f VarFile +!/@@{RUN}/systemd/journal/streams$ d +!/@@{RUN}/systemd/journal/io\\.systemd\\.journal$ s +!/@@{RUN}/systemd/journal/streams/[[:digit:]]:[[:digit:]]+$ f +/@@{SYSTEMD_JOURNAL}?$ d VarDirInode +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}$ d VarDirInode +# system\.journal changes acls after reboot (rw->rwx) (see #934284) +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/(system|user-[[:digit:]]+)\\.journal$ f VarFile +!/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/(system|user-[[:digit:]]+)@[[:xdigit:]]{32}-[[:xdigit:]]{16}-[[:xdigit:]]{16}\\.journal$ f +@@ifdef SYSTEMD_JOURNAL_EXTRA +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/@@{SYSTEMD_JOURNAL_EXTRA}\\.journal$ f VarFile +@@endif + diff --git a/aide/aide.conf.d/31_aide_systemd-machined b/aide/aide.conf.d/31_aide_systemd-machined new file mode 100644 index 00000000..06abac86 --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd-machined @@ -0,0 +1 @@ +!/run/systemd/userdb/io\\.systemd\\.Machine$ s diff --git a/aide/aide.conf.d/31_aide_systemd-networkd b/aide/aide.conf.d/31_aide_systemd-networkd new file mode 100644 index 00000000..6ff1dbe0 --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd-networkd @@ -0,0 +1,5 @@ + +@@define RUNNETWD @@{RUN}/systemd +!/@@{RUNNETWD}/netif(/(leases|links|lldp))?$ d +!/@@{RUNNETWD}/netif/(leases|links|lldp)/[[:digit:]]{1,2}$ f +!/@@{RUNNETWD}/netif/state$ f diff --git a/aide/aide.conf.d/31_aide_systemd-resolved b/aide/aide.conf.d/31_aide_systemd-resolved new file mode 100644 index 00000000..d0b6728d --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd-resolved @@ -0,0 +1,3 @@ +/@@{RUN}/systemd/resolve/stub-resolv\\.conf$ f VarFile +!/@@{RUN}/systemd/resolve/io\\.systemd\\.Resolve$ s + diff --git a/aide/aide.conf.d/31_aide_systemd_journal b/aide/aide.conf.d/31_aide_systemd_journal new file mode 100644 index 00000000..4ce67b5c --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd_journal @@ -0,0 +1,15 @@ +!/@@{RUN}/systemd/journal$ d +!/@@{RUN}/systemd/journal/(dev-log|socket|stdout|syslog)$ s +!/@@{RUN}/systemd/journal/flushed$ f +/@@{RUN}/systemd/journal/kernel-seqnum$ f VarFile +!/@@{RUN}/systemd/journal/streams$ d +!/@@{RUN}/systemd/journal/io\\.systemd\\.journal$ s +!/@@{RUN}/systemd/journal/streams/[[:digit:]]:[[:digit:]]+$ f +/run/log(/journal)?$ d VarDirInode +/@@{SYSTEMD_JOURNAL}$ d VarDirInode +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}$ d VarDirInode +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/(system|user-[[:digit:]]+)\\.journal$ f VarFile +!/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/(system|user-[[:digit:]]+)@[[:xdigit:]]{32}-[[:xdigit:]]{16}-[[:xdigit:]]{16}\\.journal$ f +@@ifdef ALLOWED_EXTRA_JOURNALS +/@@{SYSTEMD_JOURNAL}/@@{MACHINEID}/@@{ALLOWED_EXTRA_JOURNALS}\\.journal$ f VarFile +@@endif diff --git a/aide/aide.conf.d/31_aide_systemd_sessions b/aide/aide.conf.d/31_aide_systemd_sessions new file mode 100644 index 00000000..295a700b --- /dev/null +++ b/aide/aide.conf.d/31_aide_systemd_sessions @@ -0,0 +1,4 @@ +/@@{RUN}/systemd/(sessions|transient|users)$ d VarDir +!/@@{RUN}/systemd/sessions/[0-9]+(\\.ref)?$ p +!/@@{RUN}/systemd/transient/session-[0-9]+\\.scope$ f +!/@@{RUN}/systemd/users/[0-9]+$ f diff --git a/aide/aide.conf.d/31_aide_tiger b/aide/aide.conf.d/31_aide_tiger new file mode 100644 index 00000000..c5481881 --- /dev/null +++ b/aide/aide.conf.d/31_aide_tiger @@ -0,0 +1,15 @@ +@@define TIGER_LOGS (check_(accounts|group|netrc|passwdformat|passwd|perms|rhosts|system|aliases|exports|inetd|printcap|anonftp|path|crontabs|tcpd|services|ftpusers|umask|exrc|embedded|devices)|find_files) +/var/log/tiger/@@{TIGER_LOGS}\\.out\\.1$ f LoSerMemberLog +/var/log/tiger/@@{TIGER_LOGS}\\.out\\.[2-9]$ f SerMemberLog +/var/log/tiger/@@{TIGER_LOGS}\\.out\\.10$ f HiSerMemberLog + +@@define TIGER_8LOGS (logfiles|rootkit|root|rootdir|runprocs|known) +/var/log/tiger/check_@@{TIGER_8LOGS}\\.out\\.[123]$ f LoSerMemberLog +/var/log/tiger/check_@@{TIGER_8LOGS}\\.out\\.[4-7]$ f SerMemberLog +/var/log/tiger/check_@@{TIGER_8LOGS}\\.out\\.(8|9|10)$ f HiSerMemberLog + +/var/log/tiger/check_listeningprocs\\.out\\.([1-9]|10)$ f FreqRotLog + +/var/log/tiger$ d VarDir + +/var/lib/tiger/work$ d VarDir diff --git a/aide/aide.conf.d/31_aide_torrus b/aide/aide.conf.d/31_aide_torrus new file mode 100755 index 00000000..13ff4e06 --- /dev/null +++ b/aide/aide.conf.d/31_aide_torrus @@ -0,0 +1,33 @@ +#!/bin/bash + +if ! [ -d /var/lib/torrus ]; then + exit 0 +fi + +find /var/lib/torrus/collector_rrd -name '*.rrd' | \ + sed 's/^\(.*\)/\1$ f VarFile/' + +TORRUS_TREES="" +#shellcheck disable=SC2154 +if [ -r "$UPAC_settingsd/31_aide_torrus_settings" ]; then + # pull in configuration + #shellcheck disable=SC1090 + . "$UPAC_settingsd/31_aide_torrus_settings" +fi + +for tree in $TORRUS_TREES; do + printf "@@define TORRUS_TREE %s\\n" "${tree}" + printf "/var/lib/torrus/db/sub/@@{TORRUS_TREE}/(config_readers|nodepcache_1|scheduler_stats)\\.db$ f VarFile\\n" + printf "/var/log/torrus/collector\\.@@{TORRUS_TREE}_0\\.log$ f Log\\n" + printf "/@@{RUN}/torrus/collector\\.@@{TORRUS_TREE}_0\\.pid$ f VarFile\\n" +done + +printf "!/var/cache/torrus/[0-9a-f]{32}_[0-9]{5}$ f\\n" +printf "/var/lib/torrus/db/__db\\.00[1234]$ f VarFile\\n" +printf "/var/lib/torrus/db/render_cache\\.db$ f VarFile\\n" +printf "!/var/lib/torrus/session_data/store/[0-9a-f]{32}$ f\\n" +printf "!/var/lib/torrus/session_data/lock/Apache-Session-[0-9a-f]{32}\\.lock$ f\\n" +printf "/var/lib/torrus/session_data/(store|lock)$ d VarDir\\n" +printf "!/var/log/torrus/dbenv_errlog_%d$ f\\n" "$(pidof collector)" +printf "/var/log/torrus$ d VarDir\\n" +printf "/@@{RUN}/torrus$ d VarDirInode\\n" diff --git a/aide/aide.conf.d/31_aide_trac b/aide/aide.conf.d/31_aide_trac new file mode 100755 index 00000000..0994c855 --- /dev/null +++ b/aide/aide.conf.d/31_aide_trac @@ -0,0 +1,15 @@ +#!/bin/bash + +#shellcheck disable=SC2154 +if [ -r "$UPAC_settingsd/31_aide_trac_settings" ]; then + # pull in configuration + #shellcheck disable=SC1090 + . "$UPAC_settingsd/31_aide_trac_settings" +fi + +for tracpath in $TRAC_REPOS; do + [ -d "${tracpath}" ] || exit 1 + tracpath="${tracpath//\./\\\\.}" + printf "%sdb/trac\\.db$ f VarFile\\n" "${tracpath}" + printf "%sdb$ d VarDir\\n" "${tracpath}" +done diff --git a/aide/aide.conf.d/31_aide_tt-rss b/aide/aide.conf.d/31_aide_tt-rss new file mode 100644 index 00000000..a99512fc --- /dev/null +++ b/aide/aide.conf.d/31_aide_tt-rss @@ -0,0 +1,7 @@ +/var/lib/tt-rss/update_daemon.(stamp|lock)$ f VarFile +/var/lib/tt-rss$ d VarDirTime + +/var/log/tt-rss\\.log$ f Log +/var/log/tt-rss\\.log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog +/var/log/tt-rss\\.log\\.[2-6]\\.@@{LOGEXT}$ f SerMemberLog +/var/log/tt-rss\\.log\\.7\\.@@{LOGEXT}$ f HiSerMemberLog diff --git a/aide/aide.conf.d/31_aide_udev b/aide/aide.conf.d/31_aide_udev new file mode 100644 index 00000000..9a93ff56 --- /dev/null +++ b/aide/aide.conf.d/31_aide_udev @@ -0,0 +1,75 @@ +# this is a preliminary paranoid rule from a local installation. Feel free to submit +# patches that may make the rule suitable for your installation + +@@define RUNUDEVCONT [bcn][[:digit:]]+(:[[:digit:]]+)? +@@define RUNUDEVVIDEO card0-(e?DP|HDMI-A|Virtual)-[1234] +!/@@{RUN}/udev$ d +!/@@{RUN}/udev/control$ s +!/@@{RUN}/udev/(data|links|tags|watch)$ d +!/@@{RUN}/udev/data/@@{RUNUDEVCONT}$ f +!/@@{RUN}/udev/data/\\+input:input[0123456]$ f +!/@@{RUN}/udev/data/\\+module:(af_alg|algif_skcipher|configfs|dm_crypt)$ f +!/@@{RUN}/udev/data/\\+acpi:(device|LNX(CPU|[[:upper:]]{5})|(LEN|PNP|SMO)[[:xdigit:]]{4}|ACPI[[:digit:]]{4}|QEMU[[:digit:]]{4}):[0123][[:xdigit:]]$ f +!/@@{RUN}/udev/data/\\+ata_device:dev[[:digit:]]\\.[01]$ f +!/@@{RUN}/udev/data/\\+ata_link:link[[:digit:]]$ f +!/@@{RUN}/udev/data/\\+ata_port:ata[[:digit:]]$ f +!/@@{RUN}/udev/data/\\+bdi:[[:digit:]]+:[[:digit:]]+$ f +!/@@{RUN}/udev/data/\\+bus:(acpi|cec|clockevents|clocksource|container|cpu|dax|event_source|gpio|hid|i2c|machinecheck|mdio_bus|nd|node|nvmem|parport|pci(_express)?|platform|pnp|scsi|ser(ial|io)|usb(-serial)?|virtio|workqueue|xen(-backend)?)$ f +!/@@{RUN}/udev/data/\\+by_name:(etc|genroms)$ f +!/@@{RUN}/udev/data/\\+class:(ata_(device|link|port)|hwmon|leds|macvtap|mdio_bus|pps|ptp|scsi_(disk|generic)|tpm(rm)?|usbmisc|virtio-ports)$ f +!/@@{RUN}/udev/data/\\+clockevents:(broadcast|clock(event[01234567]|source0))$ f +!/@@{RUN}/udev/data/\\+clocksource:clocksource0$ f +!/@@{RUN}/udev/data/\\+container:PNP0A06:0[023]$ f +!/@@{RUN}/udev/data/\\+cpu:cpu[0123]$ f +!/@@{RUN}/udev/data/\\+dma:dma0chan[01234]$ f +!/@@{RUN}/udev/data/\\+dmi:id$ f +!/@@{RUN}/udev/data/\\+drivers:[-[:lower:][:digit:]_]+:[-[:alnum:]\ _]+$ f +!/@@{RUN}/udev/data/\\+drm:@@{RUNUDEVVIDEO}$ f +!/@@{RUN}/udev/data/\\+etc:(acpi|smbios|tpm)$ f +!/@@{RUN}/udev/data/\\+event_source:(amd_(l2|nb)|breakpoint|cpu|cstate_(core|pkg)|ibs_(fetch|op)|msr|power|software|uncore_(arb|cbox_[01]))$ f +!/@@{RUN}/udev/data/\\+graphics:fbcon$ f +!/@@{RUN}/udev/data/\\+hid:0003:[[:xdigit:]]{4}:[[:digit:]]{4}\\.000[12]$ f +!/@@{RUN}/udev/data/\\+hwmon:hwmon[01]$ f +!/@@{RUN}/udev/data/\\+i2c:(dummy|i2c-[01234])$ f +!/@@{RUN}/udev/data/\\+leds:(apu:green:[23]|input[0123]::(caps|num|scroll)lock|bananapi:green:usr)$ f +!/@@{RUN}/udev/data/\\+machinecheck:machinecheck[0123]$ f +!/@@{RUN}/udev/data/\\+mdio_bus:[[:alnum:]]+-[[:digit:]]+(:00)?$ f +!/@@{RUN}/udev/data/\\+module:[[:alnum:]_]+$ f +!/@@{RUN}/udev/data/\\+node:node0$ f +!/@@{RUN}/udev/data/\\+nvmem:cmos_nvram0$ f +!/@@{RUN}/udev/data/\\+parport:(lp\\.|parport)0$ f +!/@@{RUN}/udev/data/\\+pci:0000:0[0123d]:[01][[:xdigit:]]\\.[[:digit:]]$ f +!/@@{RUN}/udev/data/\\+pci_bus:0000:0[012345d]$ f +!/@@{RUN}/udev/data/\\+pci_express:0000:00:[01][2456c].[01234]:pcie0[01][01]$ f +!/@@{RUN}/udev/data/\\+platform:((ACPI|QEMU)000[23]|LEN0068|PNP0[18C][01][03494ACDE]):0[01]$ f +!/@@{RUN}/udev/data/\\+platform:(axp20x-(adc|gpio|pek|regulator|usb-power-supply)|alarmtimer\\.0\\.auto|coretemp\\.0|cpufreq-dt|display-engine|dock\\.[01]|efivars\\.0|Fixed\ MDIO\ bus\\.0|gmac-3v3|gpio(-keys-polled|_amd_fch)|hdmi-connector|i8042|iio_hwmon\\.0|iTCO_wdt\\.0\\.auto|leds(-gpio)?|microcode|parport_pc\\.888|pcspkr|platform-framebuffer\\.0|pmu|psci|reg-dummy|serial8250|simple-framebuffer\\.0|snd-soc-dummy|soc|sp5100-tco|sun5i-a13-gpadc-iio\\.0|timer|usb[012]-vbus|vcc(3v[03]|5v0))$ f +!/@@{RUN}/udev/data/\\+platform:((0|10000)\\.sram|1c00000\\.system-control|1c02000\\.dma-controller|1c05000\\.spi|1c0c000\\.lcd-controller|1c0d000\\.lcd-controller|1c0e000\\.video-codec|1c0f000\\.mmc|1c13000\\.usb|1c13400\\.phy|1c14000\\.usb|1c14400\\.usb|1c15000\\.crypto-engine|1c16000\\.hdmi|1c18000\\.sata|1c1c000\\.usb|1c1c400\\.usb|1c20800\\.pinctrl|1c20c00\\.timer|1c20c90\\.watchdog|1c20d00\\.rtc|1c21800\\.ir|1c22c00\\.codec|1c23800\\.eeprom|1c25000\\.rtp|1c28000\\.serial|1c28c00\\.serial|1c29c00\\.serial|1c2ac00\\.i2c|1c2b400\\.i2c|1c40000\\.gpu|1c50000\\.ethernet|1c60000\\.hstimer|1d00000\\.sram|1e00000\\.display-frontend|1e20000\\.display-frontend|1e40000\\.display-backend|1e60000\\.display-backend|7fe79000\\.framebuffer)$f +!/@@{RUN}/udev/data/\\+pnp:00:0[012345]$ f +!/@@{RUN}/udev/data/\\+powercap:intel-rapl(:0(:[01])?)?$ f +!/@@{RUN}/udev/data/\\+queues:(tx|rx)-[0123]$ f +!/@@{RUN}/udev/data/\\+scsi:([1026]:0:0:0|host[0123456]|target[0126]:0:0)$ f +!/@@{RUN}/udev/data/\\+scsi_(device|disk):[0126]:0:0:0$ f +!/@@{RUN}/udev/data/\\+scsi_host:host[0123456]$ f +!/@@{RUN}/udev/data/\\+serio:serio[012]$ f +!/@@{RUN}/udev/data/\\+sound:card0$ f +!/@@{RUN}/udev/data/\\+thermal:(cooling_device[0123]|thermal_zone[01])$ f +!/@@{RUN}/udev/data/\\+usb:[-[:digit:]\\.:]+$ f +!/@@{RUN}/udev/data/\\+usb-serial:ttyUSB[[:digit:]]$ f +!/@@{RUN}/udev/data/\\+vars:(AcpiGlobalVariable|Boot(00[[:xdigit:]]{2}|Current|OptionSupport|Order(Default)?)|Con(In|Out)(Dev)?|ConsoleLock|DIAGSPLSHSCRN|ErrOut(Dev)?|HDDPWD|Key000[012345]|LB[CL]|LBOL|(LBOP|LKOP)00[[:xdigit:]]{2}|LWO|LastBootCurrent|Lenovo((Security|System)?Config|PciResource|ScratchData)|LocalSecurityVars|MTC|MailBoxQ|MeBiosExtensionSetup|MemRestoreVariable|MemoryOverwriteRequestControl|OpromDevicePath|P(ba|wd)StatusVar|PchInit|PchS3Peim|PlatformLang(Codes)?|ProtectedBootOptions|SMBIOS(ELOG000|ELOGNUMBER|LEN|MEMSIZE)|Setup(HotKey)?|SmmS3NvsData|System|TcgSetup|Timeout|UCR)-[[:xdigit:]]{8}-([[:xdigit:]]{4}-){3}[[:xdigit:]]{12}$ f +!/@@{RUN}/udev/data/\\+virtio:virtio[012345]$ f +!/@@{RUN}/udev/data/\\+vtconsole:vtcon[01]$ f +!/@@{RUN}/udev/data/\\+workqueue:(raid5wq|writeback)$ f +!/@@{RUN}/udev/link\\.dvd$ l +!/@@{RUN}/udev/links/\\\\x2f[-[:alnum:]_]+(\\\\x2f[-[:alnum:]_\\.]+)?$ d +!/@@{RUN}/udev/links/\\\\x2f[-[:alnum:]_]+(\\\\x2f[-[:alnum:]_\\.]+)?/@@{RUNUDEVCONT}$ f +!/@@{RUN}/udev/links/\\\\x2f(disk|dri|input|serial|snd)\\\\x2fby-(id|label|partlabel|partuuid|path|uuid)\\\\x2f[^/]+$ d +!/@@{RUN}/udev/links/\\\\x2f(disk|dri|input|serial|snd)\\\\x2fby-(id|label|partlabel|partuuid|path|uuid)\\\\x2f[^/]+/@@{RUNUDEVCONT}$ f +!/@@{RUN}/udev/static_node-tags(/uaccess)?$ d +!/@@{RUN}/udev/static_node-tags/uaccess/snd\\\\x2f(seq|timer)$ l +!/@@{RUN}/udev/tags/(power-switch|(master-of-)?seat|systemd|uaccess)$ d +!/@@{RUN}/udev/tags/(power-switch|(master-of-)?seat|systemd|uaccess)/@@{RUNUDEVCONT}$ f +!/@@{RUN}/udev/tags/systemd/\\+module:(configfs|fuse)$ f +!/@@{RUN}/udev/tags/(master-of-)?seat/\\+drm:@@{RUNUDEVVIDEO}$ f +!/@@{RUN}/udev/tags/seat/(\\+input:input[[:digit:]]+|\\+leds:(bananapi:green:usr|input[[:digit:]]+::(caps|num|scroll)lock))$ f +!/@@{RUN}/udev/tags/seat/\\+sound:card0$ f +!/@@{RUN}/udev/watch/[[:digit:]]+$ l diff --git a/aide/aide.conf.d/31_aide_unbound b/aide/aide.conf.d/31_aide_unbound new file mode 100644 index 00000000..db57abff --- /dev/null +++ b/aide/aide.conf.d/31_aide_unbound @@ -0,0 +1,3 @@ +/var/lib/unbound$ d VarDir +/var/lib/unbound/root\\.key$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_util-linux b/aide/aide.conf.d/31_aide_util-linux new file mode 100644 index 00000000..0ea28008 --- /dev/null +++ b/aide/aide.conf.d/31_aide_util-linux @@ -0,0 +1,3 @@ +/@@{RUN}/(blkid|mount)$ d VarDirInode +!/@@{RUN}/blkid/blkid\\.tab(\\.old)?$ f +/var/lib/systemd/timers/stamp-fstrim\\.timer$ f VarFile diff --git a/aide/aide.conf.d/31_aide_utmp b/aide/aide.conf.d/31_aide_utmp new file mode 100644 index 00000000..2143fa30 --- /dev/null +++ b/aide/aide.conf.d/31_aide_utmp @@ -0,0 +1 @@ +/@@{RUN}/utmp$ f VarFile diff --git a/aide/aide.conf.d/31_aide_vpnc b/aide/aide.conf.d/31_aide_vpnc new file mode 100644 index 00000000..8430d77c --- /dev/null +++ b/aide/aide.conf.d/31_aide_vpnc @@ -0,0 +1 @@ +/@@{RUN}/vpnc$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_vsftpd b/aide/aide.conf.d/31_aide_vsftpd new file mode 100644 index 00000000..e941ea22 --- /dev/null +++ b/aide/aide.conf.d/31_aide_vsftpd @@ -0,0 +1,2 @@ +/@@{RUN}/vsftpd(/empty)?$ d VarDirInode +/@@{RUN}/vsftpd/vsftpd\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_webalizer b/aide/aide.conf.d/31_aide_webalizer new file mode 100644 index 00000000..474f21db --- /dev/null +++ b/aide/aide.conf.d/31_aide_webalizer @@ -0,0 +1,6 @@ +#@@define LOC_WEBSITES (www\\.a\\.example|www\\.b\\.example) +@@ifdef LOC_WEBSITES +@@define LOC_WEBALIZERFILES (index\\.html|usage\\.png|webalizer\\.(hist|current)|(ctry|daily|hourly)_usage_@@{YEAR4D}(0[1-9]|1[0-2])\\.png|usage_@@YEAR4D(0[1-9]|1[0-2])\\.html) + +/var/www/@@{LOC_WEBSITES}/stats/@@{LOC_WEBALIZERFILES}$ f VarFile +@@endif diff --git a/aide/aide.conf.d/31_aide_wpasupplicant b/aide/aide.conf.d/31_aide_wpasupplicant new file mode 100644 index 00000000..c1879973 --- /dev/null +++ b/aide/aide.conf.d/31_aide_wpasupplicant @@ -0,0 +1,11 @@ +/@@{RUN}/sendsigs\\.omit\\.d/wpasupplicant\\.wpa_(supplicant|action)\\.@@{INTERFACES}\\.pid$ f VarFile + +# if you want this rule to have effect, you need to set WPA_INTERFACES in +# an earlier file, such as 30_local_wpasupplicant. Due to the new interface +# naming, it is next to impossible to automaticaly guess which interface needs +# WPA and which doesn't. If you have an idea to automate this, please give +# a suggestion or send a patch +@@ifdef WPA_INTERFACES +/@@{RUN}/wpa_supplicant/@@{WPA_INTERFACES}$ s VarFile +/@@{RUN}/wpa_supplicant$ d VarDirInode +@@endif diff --git a/aide/aide.conf.d/31_aide_wtmp b/aide/aide.conf.d/31_aide_wtmp new file mode 100644 index 00000000..c31735ca --- /dev/null +++ b/aide/aide.conf.d/31_aide_wtmp @@ -0,0 +1,2 @@ +/var/log/wtmp$ f Log +/var/log/wtmp\\.1$ f LowLog diff --git a/aide/aide.conf.d/31_aide_x11-common b/aide/aide.conf.d/31_aide_x11-common new file mode 100644 index 00000000..7367c7b7 --- /dev/null +++ b/aide/aide.conf.d/31_aide_x11-common @@ -0,0 +1 @@ +/tmp/\\.(X11|ICE)-unix$ d VarDirInode diff --git a/aide/aide.conf.d/31_aide_x11-xkb-utils b/aide/aide.conf.d/31_aide_x11-xkb-utils new file mode 100644 index 00000000..cd5735fa --- /dev/null +++ b/aide/aide.conf.d/31_aide_x11-xkb-utils @@ -0,0 +1 @@ +/var/lib/xkb$ d VarDirTime diff --git a/aide/aide.conf.d/31_aide_xdm b/aide/aide.conf.d/31_aide_xdm new file mode 100644 index 00000000..1d6de442 --- /dev/null +++ b/aide/aide.conf.d/31_aide_xdm @@ -0,0 +1,3 @@ +!/var/lib/xdm/authdir/authfiles/A:[0-9]-[A-Za-z0-9]{6}$ f +/var/lib/xdm/authdir/authfiles$ d VarDir +/@@{RUN}/xdm\\.pid$ f VarFile diff --git a/aide/aide.conf.d/31_aide_xe-guest-utilities b/aide/aide.conf.d/31_aide_xe-guest-utilities new file mode 100644 index 00000000..ee0ecdc8 --- /dev/null +++ b/aide/aide.conf.d/31_aide_xe-guest-utilities @@ -0,0 +1,3 @@ +/var/cache/xenstore/data/(meminfo_free|updated)$ f VarFile +/var/cache/xenstore/unique-domain-id$ f VarFile + diff --git a/aide/aide.conf.d/31_aide_xinetd b/aide/aide.conf.d/31_aide_xinetd new file mode 100644 index 00000000..368197c8 --- /dev/null +++ b/aide/aide.conf.d/31_aide_xinetd @@ -0,0 +1 @@ +/@@{RUN}/xinetd.pid$ f VarFile diff --git a/aide/aide.conf.d/70_aide_dev b/aide/aide.conf.d/70_aide_dev new file mode 100644 index 00000000..0779b5b5 --- /dev/null +++ b/aide/aide.conf.d/70_aide_dev @@ -0,0 +1,17 @@ +!/dev/pts/[0-9]{1,2}$ c +/dev/pts$ d VarDir + +# reading Xattrs for some /dev nodes will cause unwanted actions, including +# - on-the-fly creation of other device nodes +# - reboots (!) +# - loading of kernel modules +/dev/(btrfs-control|loop-control|net/tun|ppp|tty[[:digit:]]+|watchdog0?|vhost-net)$ c RamdiskData-X + +# the "RamdiskData-X" is a workaround for #986332 (2021-04-03) +# if you encounter "stack smashing detected" aborts, use --log-level=rule +# find out which file causes the issue and add an appropriate -X rule. +# As soon as #986332 is fixed the -X can be removed. + +# this rule is deliberately unrestricted +/dev/ RamdiskData-X +# this should be /dev/ RamdiskData diff --git a/aide/aide.conf.d/70_aide_etc b/aide/aide.conf.d/70_aide_etc new file mode 100644 index 00000000..a7744bf8 --- /dev/null +++ b/aide/aide.conf.d/70_aide_etc @@ -0,0 +1 @@ +/etc$ d VarDir diff --git a/aide/aide.conf.d/70_aide_proc_sys b/aide/aide.conf.d/70_aide_proc_sys new file mode 100644 index 00000000..cb19f7f6 --- /dev/null +++ b/aide/aide.conf.d/70_aide_proc_sys @@ -0,0 +1,3 @@ +# these rules are deliberately unrestricted +!/proc$ +!/sys$ diff --git a/aide/aide.conf.d/70_aide_run b/aide/aide.conf.d/70_aide_run new file mode 100644 index 00000000..7ebe34b2 --- /dev/null +++ b/aide/aide.conf.d/70_aide_run @@ -0,0 +1,5 @@ +/@@{RUNLOCK}$ d VarDirInode +/@@{RUNLOCK}/subsys$ d VarDirInode +!/@@{RUN}/shm$ l +/@@{RUN}/sendsigs\\.omit\\.d$ d VarDirInode +/@@{RUN}$ d VarDirInode-n diff --git a/aide/aide.conf.d/70_aide_tmp b/aide/aide.conf.d/70_aide_tmp new file mode 100644 index 00000000..2ffed66d --- /dev/null +++ b/aide/aide.conf.d/70_aide_tmp @@ -0,0 +1,3 @@ +/tmp$ d OwnerMode+X +!/tmp/\\.(ICE|Test|X11|XIM|font)-unix$ d + diff --git a/aide/aide.conf.d/70_aide_var b/aide/aide.conf.d/70_aide_var new file mode 100644 index 00000000..87b01dc6 --- /dev/null +++ b/aide/aide.conf.d/70_aide_var @@ -0,0 +1,2 @@ +/var/(backups|log)$ d VarDir +/var/tmp$ d VarDir-n diff --git a/aide/aide.conf.d/99_aide_root b/aide/aide.conf.d/99_aide_root new file mode 100644 index 00000000..779d26e5 --- /dev/null +++ b/aide/aide.conf.d/99_aide_root @@ -0,0 +1,3 @@ +# this is the catch-all rule that includes everything that is not restricted by earlier rules +# this rule is deliberately unrestricted +/ Full diff --git a/aide/aide.settings.d/10_aide_sourceslist b/aide/aide.settings.d/10_aide_sourceslist new file mode 100755 index 00000000..4bb5764e --- /dev/null +++ b/aide/aide.settings.d/10_aide_sourceslist @@ -0,0 +1,12 @@ +#!/bin/sh + +SOURCESLIST="" +if [ -e "/etc/apt/sources.list" ]; then + SOURCESLIST="/etc/apt/sources.list" +fi + +for file in /etc/apt/sources.list.d/*; do + if [ -e "$file" ]; then + SOURCESLIST="$SOURCESLIST $file" + fi +done diff --git a/aide/aide.settings.d/31_aide_apt_settings b/aide/aide.settings.d/31_aide_apt_settings new file mode 100755 index 00000000..b02ef7b9 --- /dev/null +++ b/aide/aide.settings.d/31_aide_apt_settings @@ -0,0 +1,4 @@ +#!/bin/sh + +IGNORE_ARCHIVES="" +IGNORE_FRQCHG="" diff --git a/aide/aide.settings.d/31_aide_svn-server_settings b/aide/aide.settings.d/31_aide_svn-server_settings new file mode 100755 index 00000000..149ee96a --- /dev/null +++ b/aide/aide.settings.d/31_aide_svn-server_settings @@ -0,0 +1,3 @@ +#!/bin/sh + +SVN_REPOS="" diff --git a/aide/aide.settings.d/31_aide_torrus_settings b/aide/aide.settings.d/31_aide_torrus_settings new file mode 100755 index 00000000..3828fbb0 --- /dev/null +++ b/aide/aide.settings.d/31_aide_torrus_settings @@ -0,0 +1,4 @@ +#!/bin/sh + +TORRUS_TREES="" + diff --git a/aide/aide.settings.d/31_aide_trac_settings b/aide/aide.settings.d/31_aide_trac_settings new file mode 100755 index 00000000..97b1f072 --- /dev/null +++ b/aide/aide.settings.d/31_aide_trac_settings @@ -0,0 +1,3 @@ +#!/bin/sh + +TRAC_REPOS="" diff --git a/aliases.db b/aliases.db new file mode 100644 index 0000000000000000000000000000000000000000..ce5ef307fc74aa31dedb1d3953da3b641a334635 GIT binary patch literal 12288 zcmeI&y-LJD5Ww+Szc__suCetI4pVq%>A^)fFe-YDjbYIPg@i~FeG4lez)G&R60z_R z#22u)@C5|H-HR5N%0jgHFWJdvCfVZGEfWzD-njTct8LF1Q0*~0R#|0009ILKmdV16R4ljm*iTd z`JwOnsxSJak9w!KdZRAOKmY**5I_I{1Q0*~0R#|00D<2ZFnN}hV$QOnOl?t)a{0;} zB{sDeVp4mWw2Le`FKpgE9+`vPIO^>W!@YRB7lkJ1taXFc^-eeNl`U6^qn-X>a}f5; zhPcZQfBvua`CHPQl&2 "error determining FQDN: hostname -f does not give output" + hostname -f >&2 + exit 1 +fi + +traphandler() { + trap - INT ERR + if [ -n "${LOCKED:-}" ]; then + # we have the lock, + pidof aide | xargs --no-run-if-empty kill -9 + fi + if type -t onexit >/dev/null; then + onexit signal "$1" + else + echo "${MAILHEAD:-}" | fold --bytes --width="${MAILWIDTH:-990}" | mail -s "early termination - $MAILSUBJ" "$MAILTO" + fi + return 0 +} +trap ' traphandler INT; trap - INT ERR' INT +trap ' traphandler ERR; trap - INT ERR' ERR + +# bail if no aide binary found + +if ! [ -f "/usr/bin/aide" ] && ! [ -f "/usr/sbin/aide" ]; then + exit 0 +fi + +# default variables + +PATH="/sbin:/usr/sbin:/bin:/usr/bin" +LOGDIR="/var/log/aide" +# LOGFILE: /var/log/aide/aide.log - all logs untruncated (not temp) +LOGFILE="$LOGDIR/aide.log" +PREFIX="aide" +LOCKBASE="/run/aide" +LOCKFILE="$LOCKBASE/cron.daily.lock" + +TMPBASE="/var/tmp" +if ! [ -d "${TMPBASE}" ]; then + TMPBASE="/run/aide" +fi +TMPDIRIN="$TMPBASE/aide.cron.daily" + +USE_SAVELOG="" +if command -v savelog > /dev/null; then + USE_SAVELOG="1" +fi + +AIDEARGS="-V4" +MAILSUBJ="Daily AIDE report for $FQDN" + +BEGINSTAMP="$(date +"%Y-%m-%d %H:%M:%S")" + +# make sure $LOCKBASE exists + +if ! [ -d "$LOCKBASE" ]; then + mkdir -p $LOCKBASE + chown root:root $LOCKBASE + chmod 600 $LOCKBASE +fi + +# have /etc/default/aide override variables + +if [ -f "/etc/default/aide" ]; then + #shellcheck disable=1091 + . "/etc/default/aide" +fi + +# from here on, we're going to bail on unbound variables + +set -u + +# umask + +umask 077 + +# grep aide configuration data from aide config + +DATABASE="$(< "${CONFIG}" grep "^database_in[[:space:]]*=[[:space:]]*file:/" | head -n 1 | cut --delimiter=: --fields=2)" +DATABASE_OUT="$(< "${CONFIG}" grep "^database_out[[:space:]]*=[[:space:]]*file:/" | head -n 1 | cut --delimiter=: --fields=2)" + +< "${CONFIG}" grep -qE "^(report_)?grouped[[:space:]]*=[[:space:]]*(no|false)[[:space:]]*$" && GROUPED="false" || GROUPED="true" + +# default values + +CRON_DAILY_RUN="${CRON_DAILY_RUN:-yes}" +MAILTO="${MAILTO:-root}" +eval MAILTO="$MAILTO" +MAILWIDTH="${MAILWIDTH:-990}" +DATABASE="${DATABASE:-/var/lib/aide/aide.db}" +LINES="${LINES:-1000}" +COMMAND="${COMMAND:-check}" +COPYNEWDB="${COPYNEWDB:-no}" +QUIETREPORTS="${QUIETREPORTS:-no}" +SILENTREPORTS="${SILENTREPORTS:-no}" +TRUNCATEDETAILS="${TRUNCATEDETAILS:-no}" +FILTERUPDATES="${FILTERUPDATES:-no}" +FILTERINSTALLATIONS="${FILTERINSTALLATIONS:-no}" +CRONEXITHOOK="${CRONEXITHOOK:-}" +ONEXIT="" + +# silent implies quiet +if [ "$SILENTREPORTS" = "yes" ]; then + QUIETREPORTS="yes" +fi + +# Get the database's date +DATABASEDATE="" +if [ -f "$DATABASE" ]; then + DATABASEDATE="$(stat -c %y "$DATABASE" | sed -e "s/\\..*//")" +fi + +# Force TRUNCATEDETAILS when filter updates/installations +if [ "$FILTERUPDATES" = "yes" ] || [ "$FILTERINSTALLATIONS" = "yes" ] ; then + TRUNCATEDETAILS="yes" +fi + +# functions + +mytempfile() { + NAME="$1" + echo "$TMPDIR/$NAME" + touch "$TMPDIR/$NAME" +} + +frame() { + WIDTH=78 + STARS="*******************************************************************************" + SPACES=" " + printf "%s\\n" "${STARS:1:$WIDTH}" + while read -r line ; do + HALF="${SPACES:1:$(((WIDTH-${#line})/2))}" + LINE="$HALF$line$SPACES" + printf "*%s*\\n" "${LINE:1:$((WIDTH-2))}" + done + printf "%s\\n" "${STARS:1:$WIDTH}" +} + +onexit() { + if [ "$ONEXIT" = "running" ]; then + return 1 + fi + + ONEXIT="running" + + local LOGHEAD + local MAILHEAD + local CRONJOBERR + + CRONEXITHOOKPARM="$1" + case "$1" in + signal) + LOGHEAD="$(printf "terminated with signal %s" "$2")" + MAILHEAD="$(printf "The cron job was terminated with signal %s" "$2")" + CRONJOBERR="$2" + ;; + nodb) + LOGHEAD="$(printf "database not present.")" + MAILHEAD="$(printf "The cron job was terminated because no AIDE database is present")" + CRONJOBERR="no DB" + ;; + fatal) + LOGHEAD="$(printf "terminated by fatal error.")" + MAILHEAD="$(printf "The cron job was terminated by a fatal error.")" + CRONJOBERR="fatal" + ;; + nolock) + LOGHEAD="$(printf "terminated because lock %s could not be obtained." "$LOCKFILE")" + MAILHEAD="$(printf "The cron job was terminated because lock %s could not be obtained." "$LOCKFILE")" + CRONJOBERR="no lock" + ;; + cantmovetmp) + LOGHEAD="$(printf "terminated: Cannot move away %s." "$TMPDIRIN")" + MAILHEAD="$(printf "The cron job was terminated: Cannot move away %s." "$TMPDIRIN")" + CRONJOBERR="temp dir" + ;; + nohook) + LOGHEAD="$(printf "terminated: CRONEXITHOOK set to %s which is not executeable." "$CRONEXITHOOK")" + MAILHEAD="$(printf "The cron job was terminated: CRONEXITHOOK set to %s which is not executeable." "$CRONEXITHOOK")" + CRONJOBERR="no hook" + ;; + cantcreatetmp) + LOGHEAD="$(printf "terminated: Cannot create temporary directory %s." "$TMPDIRIN")" + MAILHEAD="$(printf "The cron job was terminated: Cannot create temporary directory %s." "$TMPDIRIN")" + CRONJOBERR="temp dir" + ;; + tmpnotours) + LOGHEAD="$(printf "terminated: Temporary directory %s has wrong owner/mode." "$TMPDIRIN")" + MAILHEAD="$(printf "The cron job was terminated: Temporary directory %s has wrong owner/mode." "$TMPDIRIN")" + CRONJOBERR="temp dir" + ;; + success) + ;; + *) + LOGHEAD="$(printf "wrong parameter (\"%s\") to onexit." "$1")" + MAILHEAD="$(printf "The cron job was terminated for unknown reasons, and a wrong parameter (\"%s\")was given to onexit." "$1")" + CRONJOBERR="unknown" + CRONEXITHOOKPARM="unknown" + ;; + esac + + if [ -z "${TMPDIR:-}" ] || [ -z "${MAILFILE:-}" ]; then + # we are being called so early that we are not yet fully initialized + # LOGHEAD goes to syslog instead of LOGFILE since we do not know + # what's up with LOGFILE + logger -t aide-cron-daily "$LOGHEAD" + if [ "$SILENTREPORTS" != "yes" ]; then + echo "$MAILHEAD" | fold --bytes --width="${MAILWIDTH}" | mail -s "premature termination - $MAILSUBJ" "$MAILTO" + fi + CRONEXITHOOKPARM="early-$CRONEXITHOOKPARM" + else + # we are being called after the cron job was properly set up. + # Do the full works. + + if [ "$USE_SAVELOG" = "1" ] || [ "$USE_SAVELOG" = "yes" ]; then + savelog -t -g adm -m 640 -u root -c 7 "$LOGFILE" > /dev/null + else + LOGFILEWDATE="${LOGFILE}-$(date +%Y%m%d-%H%M%S)" + ln -sf "$LOGFILEWDATE" "$LOGFILE" + LOGFILE="${LOGFILEWDATE}" + fi + + printf >> "$MAILFILE" \ + "This is an automated report generated by the Advanced Intrusion Detection environment on %s started at %s.\\n\\n" "$FQDN" "$BEGINSTAMP" + + printf >> "$LOGFILE" \ + "aide run on %s started at %s.\\n" "$FQDN" "$BEGINSTAMP" + + if [ -n "${LOGHEAD:-}" ]; then + printf "%s\\n" "$LOGHEAD" | frame >> "$LOGFILE" + printf "\\n" >> "$LOGFILE" + fi + if [ -n "${MAILHEAD:-}" ]; then + printf "%s\\n" "$MAILHEAD" | frame >> "$MAILFILE" + printf "\\n\\n" >> "$MAILFILE" + fi + + # report about AIDE's return value + + PRINTED="" + FIGLETTEXT="" + if [ -n "${ARETVAL:-}" ]; then + ARETEXPL="" + ARETERR="" + PREFIX="$(printf "AIDE returned with exit code %d." "$ARETVAL")" + case "$ARETVAL" in + -1) + PREFIX="" + ARETERR="the cron job was interrupted before AIDE could return an exit code." + FIGLETTEXT="${CRONJOBERR:-interrupt}" + ;; + 0) + PREFIX="AIDE returned with a zero exit code." + ARETEXPL="No changes detected!" + FIGLETTEXT="unchanged" + ;; + 1) + ARETEXPL="Added entries detected!" + FIGLETTEXT="add" + ;; + 2) + ARETEXPL="Removed entries detected!" + FIGLETTEXT="rem" + ;; + 3) + ARETEXPL="Added and removed entries detected!" + FIGLETTEXT="add rem" + ;; + 4) + ARETEXPL="Changed entries detected!" + FIGLETTEXT="chg" + ;; + 5) + ARETEXPL="Added and changed entries detected!" + FIGLETTEXT="add chg" + ;; + 6) + ARETEXPL="Removed and changed entries detected!" + FIGLETTEXT="rem chg" + ;; + 7) + ARETEXPL="Added, removed and changed entries detected!" + FIGLETTEXT="add rem chg" + ;; + 14) + ARETERR="Error writing!" + FIGLETTEXT="$ARETERR" + ;; + 15) + ARETERR="Invalid Argument!" + FIGLETTEXT="EINVAL" + ;; + 16) + ARETERR="Unimplemented function!" + FIGLETTEXT="unimplemented" + ;; + 17|255) + ARETERR="Invalid configuration!" + FIGLETTEXT="invalid config" + ;; + 18) + ARETERR="Input/Output error!" + FIGLETTEXT="EIO" + ;; + 21) + ARETERR="cannot obtain lock" + FIGLETTEXT="no lock" + ;; + 250) + ARETERR="executable aide not found" + FIGLETTEXT="no executable" + ;; + *) + ARETERR="$(printf "unknown non-zero exit value %d\\n\\n" "$ARETVAL")" + FIGLETTEXT="unknown error" + ;; + esac + if [ -n "$ARETEXPL" ]; then + printf "%s %s\\n" "$PREFIX" "$ARETEXPL" >> "$MAILFILE" + printf "%s %s\\n" "$PREFIX" "$ARETEXPL" >> "$LOGFILE" + PRINTED=1 + fi + if [ -n "$ARETERR" ]; then + printf "%s %s\\n" "$PREFIX" "$ARETERR" | frame >> "$MAILFILE" + printf "%s %s\\n" "$PREFIX" "$ARETERR" | frame >> "$LOGFILE" + PRINTED=1 + fi + unset ARETEXPL + unset ARETERR + unset PREFIX + else + ARETEXPL="ARETVAL not initialized. cron job was aborted prematurely." + ARETVAL=255 + FIGLETTEXT="abort" + printf "%s\\n" "$ARETEXPL" | frame >> "$MAILFILE" + printf "%s\\n" "$ARETEXPL" | frame >> "$LOGFILE" + PRINTED=1 + unset ARETEXPL + fi + if [ "${FIGLET:-yes}" = "yes" ] && [ -x "$(command -v figlet)" ] && [ -n "$FIGLETTEXT" ]; then + printf "\\n%s\\n\\n" "$(figlet $FIGLETTEXT)" >> "$MAILFILE" + PRINTED=1 + fi + if [ -n "$PRINTED" ]; then + printf "\\n" >> "$LOGFILE" + printf "\\n\\n" >> "$MAILFILE" + fi + unset PRINTED + + # script errors + + if [ -n "${ERRORLOG:-}" ] && [ -s "$ERRORLOG" ]; then + { + printf "script errors\\n" | frame + cat "$ERRORLOG" + printf "End of script errors\\n\\n" + } >> "$MAILFILE" + + { + printf "script errors\\n" | frame + cat "$ERRORLOG" + printf "End of script errors\\n" + } >> "$LOGFILE" + fi + + # aide post run information + + if [ -n "${POSTRUNLOG:-}" ] && [ -s "$POSTRUNLOG" ]; then + { + printf "AIDE post run information\\n" + cat "$POSTRUNLOG" + printf "End of AIDE post run information\\n\\n" + } >> "$MAILFILE" + + { + printf "AIDE post run information\\n" + cat "$POSTRUNLOG" + printf "End of AIDE post run information\\n" + } >> "$LOGFILE" + fi + + # include error log in daily report e-mail + + if [ -n "${AERRLOG:-}" ] && [ -s "$AERRLOG" ]; then + errorlines="$(wc -l "$AERRLOG" | awk '{ print $1 }')" + { + if [ "$LINES" -gt "0" ] && [ "${errorlines:=0}" -gt "$LINES" ]; then + printf "AIDE has returned many errors.\\nthe error log output has been truncated in this mail\\n" | \ + frame + printf "Error output is %d lines, truncated to %d.\\n" "$errorlines" "$LINES" + head -n "$LINES" "$AERRLOG" + printf "\\nEnd of truncated AIDE error output. The full output can be found in %s.\\n\\n" "$LOGFILE" + else + printf "Errors produced (%d lines):\\n" "$errorlines" + cat "$AERRLOG" + printf "\\nEnd of AIDE error output.\\n\\n" + fi + } >> "$MAILFILE" + { + printf "AIDE error output (%d lines):\\n" "$errorlines" + cat "$AERRLOG" + printf "End of AIDE error output\\n" + } >> "$LOGFILE" + else + printf >> "$MAILFILE" "AIDE produced no errors.\\n\\n" + printf >> "$LOGFILE" "AIDE produced no errors.\\n" + fi + + # finish log file + { + if [ -n "${ARUNLOG:-}" ] && [ -s "$ARUNLOG" ]; then + printf "AIDE output (%d lines):\\n" "$(wc -l "$ARUNLOG" | awk '{ print $1 }')" + cat "$ARUNLOG" + printf "End of AIDE output.\\n\\n" + else + printf "AIDE detected no changes.\\n\\n" + fi + + if [ -n "${DBCHECKLOG:-}" ] && [ -s "$DBCHECKLOG" ]; then + cat "$DBCHECKLOG" + fi + + ENDTIME="$(date +%s)" + + printf "End of AIDE daily cron job at %s, run time %d seconds\\n" "$(date +"%Y-%m-%d %H:%M" -d@"$ENDTIME")" "$(( ENDTIME - BEGINTIME ))" + } >> "$LOGFILE" + + LOGFILE_CHECKSUM="$(sha256sum "$LOGFILE")" + + # include de-noised log into mail + + if [ -n "${ARUNLOG:-}" ] && [ -s "$ARUNLOG" ]; then + + MAIL_MODE=0 + + # truncate details + if [ "$TRUNCATEDETAILS" = "yes" ] ; then + case "$ARETVAL" in + 4|5|6|7) + MAILTMP="$(mytempfile aidemail)" + < "$ARUNLOG" sed '/^Detailed information about changes:$/,/^The attributes of the (uncompressed) database(s):$/{/^The attributes of the (uncompressed) database(s):$/!d}' >> "$MAILTMP" + MAIL_MODE=1 + ;; + *) + MAILTMP="$ARUNLOG" + ;; + esac + + # Filter package upgrades/installations + + # Figure out where the dpkg log file is + DPKGLOG="$(< /etc/dpkg/dpkg.cfg grep "^log" | head -n 1 | cut -d ' ' -f 2)" + + if { [ "$FILTERUPDATES" = "yes" ] || [ "$FILTERINSTALLATIONS" = "yes" ] ; } && [ -s "$DPKGLOG" ]; then + + # Create a list of files modified by system updates + if [ "$FILTERUPDATES" = "yes" ] && [ "$FILTERINSTALLATIONS" = "yes" ] ; then + FILTER="install|upgrade" + elif [ "$FILTERUPDATES" = "yes" ]; then + FILTER="upgrade" + else + FILTER="install" + fi + PKG_FILE_LIST="$(mytempfile pkg_file_list)" + REGEX="^([^ ]+ [^ ]+) ($FILTER) ([^ ]+) [^ ]+ [^ ]+$" + PKGS=() + while read -r line; do + if [[ $line =~ $REGEX ]] && [[ "$DATABASEDATE" < ${BASH_REMATCH[1]} ]]; then + if dpkg-query -L "${BASH_REMATCH[3]}" > /dev/null 2>&1; then + PKGS+=("${BASH_REMATCH[3]} (${BASH_REMATCH[2]})") + dpkg-query -L "${BASH_REMATCH[3]}" | sed -e "/^$/d" -e "/\\/\\./d" >> "$PKG_FILE_LIST" + if ! ls "/var/lib/dpkg/info/${BASH_REMATCH[3]}."* >> "$PKG_FILE_LIST" 2>/dev/null; then + ls "/var/lib/dpkg/info/${BASH_REMATCH[3]%:*}."* >> "$PKG_FILE_LIST" + fi + fi + fi + done < "$DPKGLOG" + + if [ ${#PKGS[@]} -gt 0 ]; then + FILTEREDMAIL=$(mytempfile filteredmail) + MAIL_MODE=$(( MAIL_MODE + 2 )) + ADD=0; REM=0; CHG=0 + N_ADD=0; N_REM=0; N_CHG=0 + declare -a NF_ADD NF_REM NF_CHG + NF_ADD=() + NF_REM=() + NF_CHG=() + REGEX="^(changed|removed|added|[fdLDBFs?!][ :l<>=bpugamcinHAXSEC.+-]{17}): (.*)" + BACKUPIFS="$IFS" + IFS="" + while read -r line; do + if [[ $line =~ $REGEX ]] ; then + #shellcheck disable=SC2143 + [ -z "$(grep -xF "${BASH_REMATCH[2]}" "$PKG_FILE_LIST")" ] && DONTFILTER_FILE=true || DONTFILTER_FILE=false + case "${BASH_REMATCH[1]}" in + added|[fdLDBFs?]+++++++++++++++++) + ((ADD++)) || true + if $DONTFILTER_FILE; then + ((N_ADD++)) || true + if $GROUPED; then + NF_ADD[${#NF_ADD[*]}]="$line" + else + NF_CHG[${#NF_CHG[*]}]="$line" + fi + fi + ;; + removed|[fdLDBFs?]-----------------) + ((REM++)) || true + if $DONTFILTER_FILE; then + ((N_REM++)) || true + if $GROUPED; then + NF_REM[${#NF_REM[*]}]="$line" + else + NF_CHG[${#NF_CHG[*]}]="$line" + fi + fi + ;; + changed|[fdLDBFs?!]*) + ((CHG++)) || true + if $DONTFILTER_FILE; then + ((N_CHG++)) || true + NF_CHG[${#NF_CHG[*]}]="$line" + fi + ;; + *) + printf >> "$FILTEREDMAIL" "error: '%s' could not be matched, mail report is incomplete (full output can be found in %s)!! Please file a bug report against the aide-common package and include this error message.\\n" "${BASH_REMATCH[1]}" "$LOGFILE" + ;; + esac + fi + done < "$MAILTMP" + IFS=$BACKUPIFS + F_ADD=$(( ADD-N_ADD )) || true + F_REM=$(( REM-N_REM )) || true + F_CHG=$(( CHG-N_CHG )) || true + { + < "$MAILTMP" sed -n '0,/^ Total number of entries:/{p;}' + #shellcheck disable=SC2059 + { + SEPERATOR_TEMPLATE="\\n---------------------------------------------------\\n%s entries (filtered: %s):\\n---------------------------------------------------\\n\\n" + NUM_FILES_TEMPLATE=" %s entries:\\t\\t%s\\t(filtered: %s)\\n" + printf "$NUM_FILES_TEMPLATE" "Added" "$N_ADD" "$F_ADD" + printf "$NUM_FILES_TEMPLATE" "Removed" "$N_REM" "$F_REM" + printf "$NUM_FILES_TEMPLATE" "Changed" "$N_CHG" "$F_CHG" + printf "\\nThe following package changes were detected and were filtered from this mail:\\n" + printf '%s\n' "${PKGS[@]}" + if [ "$N_ADD" -eq "0" ] && [ "$N_REM" -eq "0" ] && [ "$N_CHG" -eq "0" ] ; then + printf "\\nAIDE detected no changes after filtering package changes.\\n\\n" + else + if [ "${#NF_ADD[@]}" -gt "0" ]; then + printf "$SEPERATOR_TEMPLATE" "Added" "$F_ADD" + for ((i=0;i<${#NF_ADD[@]};i++)); do printf "%s\\n" "${NF_ADD[$i]}"; done + fi + if [ "${#NF_REM[@]}" -gt "0" ]; then + printf "$SEPERATOR_TEMPLATE" "Removed" "$F_REM" + for ((i=0;i<${#NF_REM[@]};i++)); do printf "%s\\n" "${NF_REM[$i]}"; done + fi + if [ "${#NF_CHG[@]}" -gt "0" ]; then + if $GROUPED; then + printf "$SEPERATOR_TEMPLATE" "Changed" "$F_CHG" + else + if [ "$N_ADD" -gt "0" ] && [ "$N_REM" -gt "0" ] && [ "$N_CHG" -gt "0" ]; then + HEAD="Added, removed and changed" + elif [ "$N_ADD" -gt "0" ] && [ "$N_REM" -gt "0" ]; then + HEAD="Added and removed" + elif [ "$N_ADD" -gt "0" ] && [ "$N_CHG" -gt "0" ]; then + HEAD="Added and changed" + elif [ "$N_REM" -gt "0" ] && [ "$N_CHG" -gt "0" ]; then + HEAD="Removed and changed" + elif [ "$N_ADD" -gt "0" ]; then + HEAD="Added" + elif [ "$N_REM" -gt "0" ]; then + HEAD="Removed" + elif [ "$N_CHG" -gt "0" ]; then + HEAD="Changed" + fi + printf "$SEPERATOR_TEMPLATE" "$HEAD" "$((F_ADD+F_REM+F_CHG))" + fi + for ((i=0;i<${#NF_CHG[@]};i++)); do printf "%s\\n" "${NF_CHG[$i]}"; done + fi + fi + } + printf "\\n---------------------------------------------------\\n" + < "$MAILTMP" sed -n '/^The attributes of the (uncompressed) database(s):$/,$ {p;}' + } >> "$FILTEREDMAIL" + MAILTMP="$FILTEREDMAIL" + fi + fi + else + MAILTMP="$ARUNLOG" + fi + + if [ -n "${NOISE:-}" ]; then + NOISETMP="$(mytempfile aidenoise1)" + NOISETMP2="$(mytempfile aidenoise2)" + < "$MAILTMP" sed -n '1,/^Detailed information about changes:/p' | \ + grep '^\(changed\|removed\|added\|[fdLDBFs?!][ :l<>=bpugamcinCAXSE.+-]\{16\}\):' | \ + grep -v "^added: THERE WERE ALSO [0-9]\\+ FILES ADDED UNDER THIS DIRECTORY" >> "$NOISETMP2" + + { + if [ -n "$NOISE" ]; then + ##+# leaning toothpick syndrome, consider grep -E + < "$NOISETMP2" grep -v "^\\(changed\\|removed\\|added\\|[fdLDBFs?!][ :l<>=bpugamcinCAXSE.+-]\\{16\\}\\): $NOISE" >> "$NOISETMP" || true + printf "De-Noised output removes everything matching %s.\\n" "$NOISE" + fi + + if [ -s "$NOISETMP" ]; then + loglines="$(< "$NOISETMP" wc -l | awk '{ print $1 }')" + if [ "$LINES" -gt "0" ] && [ "${loglines:=0}" -gt "$LINES" ]; then + printf "AIDE has returned long output which has been truncated in this mail\\n" | \ + frame + printf "De-Noised output is %d lines, truncated to %d.\\n" "$loglines" "$LINES" + head -n "$LINES" "$NOISETMP" + printf "\\nEnd of truncated De-Noised AIDE output. The full output can be found in %s.\\nsha256sum: %s\\n\\n" "$LOGFILE" "$LOGFILE_CHECKSUM" + else + printf "De-Noised output of the daily AIDE run (%d lines):\\n" "$loglines" + cat "$NOISETMP" + printf "\\nEnd of De-Noised AIDE output.\\n\\n" + fi + else + printf "AIDE detected no changes after removing noise.\\n\\n" + fi + printf "============================================================================\\n" + } + fi + + # include non-de-noised log into mail + + { + if [ -n "${MAILTMP:-}" ] && [ -s "$MAILTMP" ]; then + loglines="$(wc -l "$MAILTMP" | awk '{ print $1 }')" + if [ "$LINES" -gt "0" ] && [ "${loglines:=0}" -gt "$LINES" ]; then + printf "AIDE has returned long output which has been truncated in this mail\\n" | \ + frame + printf "Output is %d lines, truncated to %d.\\n" "$loglines" "$LINES" + head -n "$LINES" "$MAILTMP" + printf "\\nEnd of truncated AIDE output. The full output can be found in %s.\\nsha256sum: %s\\n\\n" "$LOGFILE" "$LOGFILE_CHECKSUM" + else + printf "Output of the daily AIDE run (%d lines):\\n" "$loglines" + cat "$MAILTMP" + if [ "$MAIL_MODE" -gt "0" ] ; then + case "$MAIL_MODE" in + 1) AIDE_OUTPUT="truncated" ;; + 2) AIDE_OUTPUT="filtered" ;; + 3) AIDE_OUTPUT="truncated and filtered" ;; + esac + printf "\\nEnd of %s AIDE output.\\n\\nThe full output can be found in %s.\\nsha256sum: %s\\n\\n" "$AIDE_OUTPUT" "$LOGFILE" "$LOGFILE_CHECKSUM" + else + printf "\\nEnd of AIDE output.\\n\\n" + fi + fi + else + printf "AIDE detected no changes.\\n\\n" + fi + } >> "$MAILFILE" + else + printf >> "$MAILFILE" "funny, AIDE did not leave a log.\\n\\n" + printf >> "$LOGFILE" "funny, AIDE did not leave a log.\\n" + fi + + if [ -n "${DBCHECKLOG:-}" ] && [ -s "$DBCHECKLOG" ]; then + < "$DBCHECKLOG" cat >> "$MAILFILE" + printf >> "$MAILFILE" "\\n" + fi + + printf >> "$MAILFILE" "End of AIDE daily cron job at %s, run time %d seconds\\n" "$(date +"%Y-%m-%d %H:%M" -d@"$ENDTIME")" "$(( ENDTIME - BEGINTIME ))" + + # send mail if changes or errors were detected or quiet reports not requested + if [ "$QUIETREPORTS" != "yes" ] || [ "$ARETVAL" != "0" ] || [ "$(< "$ERRORLOG" wc -l)" -ne 0 ]; then + # do not send anything (not even error messages) if silence is requested + if [ "$SILENTREPORTS" != "yes" ]; then + < "$MAILFILE" fold --bytes --width="${MAILWIDTH}" | mail -s "$MAILSUBJ" "$MAILTO" + fi + fi + + # clean up temp files + rm -rf "$TMPDIR" + fi + + if [ -n "$CRONEXITHOOK" ] && [ -x "$CRONEXITHOOK" ]; then + $CRONEXITHOOK $CRONEXITHOOKPARM + fi + + # clear lock + if [ -n "${LOCKED:-}" ] && command -v dotlockfile >/dev/null 2>&1; then + dotlockfile -u "$LOCKFILE" || true + fi + unset LOCKED + + return 0 +} + +BEGINTIME="$(date +%s)" + +if [ "$CRON_DAILY_RUN" != "yes" ] && ! tty -s; then + exit 0 +fi + +if command -v dotlockfile >/dev/null 2>&1; then + if ! dotlockfile -p -l "$LOCKFILE"; then + onexit nolock + exit 1 + fi +else + PREERRORLOG="no dotlockfile binary in path, not checking for already running aide cron job\\n" +fi +LOCKED=yes + +# prepare temp dir +# We use invariant file names here since our work files need to be +# excluded from aide. +if [ -e "$TMPDIRIN" ]; then + # $TMPDIRIN already exists (from an aborted run, maybe?). Move + # it away. This does not cause the script to abort, but aide should + # have rules to report the new directrory appearing in $TMPBASE. + if ! NEWNAME="$(mktemp -d $TMPBASE/aide.cron.daily.old.XXXXXXXXXX)"; then + onexit cantmovetmp + exit 1 + fi + mv "$TMPDIRIN" "$NEWNAME" + unset NEWNAME +fi + +if ! mkdir -p $TMPDIRIN; then + onexit cantcreatetmp + exit 1 +fi + +if [ "$(stat --format='%a %u' "${TMPDIRIN}")" != "700 0" ]; then + onexit tmpnotours + exit 1 +fi + +# handle the case that CRONEXITHOOK does not exist or is not executeable +if [ -n "$CRONEXITHOOK" ]; then + if ! [ -x "$CRONEXITHOOK" ]; then + onexit nohook + exit 1 + fi +fi + +# we can now directly use file names inside $TMPDIR: It is only +# writeable for us (umask 077), so we're safe against symlink attacks. +TMPDIR="$TMPDIRIN" + +# now, with $TMPDIR having been created, we can use the full power of onexit. + +# ERRORLOG: Error messages from script. Gets written to $LOGFILE first +ERRORLOG="$(mytempfile errorlog)" + +if [ -n "${PREERRORLOG:-}" ]; then + printf >> "$ERRORLOG" "%s" "$PREERRORLOG" +fi +unset PREERRORLOG + +# MAILFILE: Contents gets mailed. Built and handled from inside onexit() +MAILFILE="$(mytempfile mailfile)" + +# aide return value +ARETVAL=-1 + +if [ ! -f "$DATABASE" ]; then + printf >> "$ERRORLOG" "Fatal error: The AIDE database '%s' does not exist!\\n" "$DATABASE" + printf >> "$ERRORLOG" "This may mean you haven't created it or that the initialization process is still running, or it may mean that someone has removed it.\\n" + onexit nodb + exit 1 +fi + +# code + +# re-assign current time to be more accurate about aide's real start time +BEGINSTAMP="$(date +"%Y-%m-%d %H:%M:%S")" + +# ARUNLOG: standard output of aide run +ARUNLOG="$(mytempfile arunlog)" + +# AERRLOG: standard error of aide run +AERRLOG="$(mytempfile aerrlog)" + +printf "begin timestamp %s\\n" "$BEGINSTAMP" >> "$ARUNLOG" + +aide --config="${CONFIG}" $AIDEARGS "--$COMMAND" >|"$ARUNLOG" 2>|"$AERRLOG" && ARETVAL="$?" +ARETVAL="$?" + +# POSTRUNLOG: summary of aide execution and cron job log +POSTRUNLOG="$(mytempfile postrunlog)" + +# DBCHECKLOG: Output of the database checksums +DBCHECKLOG="$(mytempfile dbchecklog)" + +# NOISETMP: completely de-noised log +# NOISETMP2: pre-filtered ARUNLOG, containing only changed, removed and added lines +NOISETMP="$(mytempfile noisetmp)" +NOISETMP2="$(mytempfile noisetmp2)" + +# find out whether we neeed to copy the new database over the old one + +COPYDB="0" +if [ "$COPYNEWDB" = "ifnochange" ] && [ "$ARETVAL" = "0" ]; then + COPYDB="1" + printf >> "$POSTRUNLOG" "no significant changes detected.\\n" +fi + +if [ "$COPYNEWDB" = "yes" ]; then + COPYDB=1 +fi + +if [ "$COPYDB" = "1" ] && [ "$COMMAND" = "update" ]; then + cp -f "$DATABASE_OUT" "$DATABASE" + printf >> "$POSTRUNLOG" "output database %s was copied to %s as requested by cron job configuration\\n" "$DATABASE_OUT" "$DATABASE" +fi + +onexit success +exit 0 + +# vim: tabstop=4 expandtab +# end of file diff --git a/default/aide b/default/aide new file mode 100644 index 00000000..92d0692b --- /dev/null +++ b/default/aide @@ -0,0 +1,109 @@ +# These settings are mainly for the wrapper scripts around aide, +# such as aideinit and /etc/cron.daily/aide + +# Main configuration file +CONFIG="/etc/aide/aide.conf" + +# Set this to no to disable daily aide runs +#CRON_DAILY_RUN=yes + +# This is used as the host name in the AIDE reports that are sent out +# via e-mail. It defaults to the output of $(hostname --fqdn), but can +# be set to arbitrary values. +# FQDN= + +# This is used as the subject for the e-mail reports. +# If your mail system only threads by subject, you might want to add +# some variable content here (for example $(date +%Y-%m-%d)). +MAILSUBJ="Daily AIDE report for $FQDN" + +# This is the email address reports get mailed to +# default is root +# This variable is expanded before it is used, so you can use variables +# here. For example, MAILTO=$FQDN-aide@domain.example will send the +# report to host.name.example-aide@domain.example is the local FQDN is +# host.name.example. +MAILTO=root + +# RFC 5322 (2.1.1) limits the maximum length of e-mail messages +# to 998. aide limits its mail messages to a slightly smaller value +# in default. If your mail system can handle messages with longer +# lines and you have very long paths on your system, set this to +# a very high value. +#MAILWIDTH=990 + +# Set this to yes to suppress mailings when no changes have been +# detected during the AIDE run and no error output was given. +#QUIETREPORTS=no + +# Set this to yes to suppress mailings under all circumstances +# This option implies QUIETREPORTS=yes +#SILENTREPORTS=no + +# Set this to no if you have figlet installed but do not want figlet +# output in your daily cron job mail +#FIGLET=yes + +# This parameter defines which AIDE command to run from the cron script. +# Sensible values are "update" and "check". +# Default is "check", ensuring backwards compatibility. +# Since "update" does not take any longer, it is recommended to use "update", +# so that a new database is created every day. The new database needs to be +# manually copied over the current one, though. +COMMAND=update + +# This parameter defines what to do with a new database created by +# COMMAND=update. It is ignored if COMMAND!=update. +# no: Do not copy new database to old database. This is the default. +# yes: Copy new database to old database. This means that changes to the +# file system are only reported once. Possibly dangerous. +# ifnochange: Copy new database to old database if no changes have +# been reported. This is needed for ANF/ARF to work reliably. +COPYNEWDB=no + +# Set this to yes to truncate the detailed changes part in the mail. The full +# output will still be listed in the log file. +TRUNCATEDETAILS=no + +# Set this to yes to suppress file changes by package and security +# updates from appearing in the e-mail report. Filtered file changes will +# still be listed in the log file. This option parses the /var/log/dpkg.log +# file and implies TRUNCATEDETAILS=yes +FILTERUPDATES=no + +# Set this to yes to suppress file changes by package installations +# from appearing in the e-mail report. Filtered file changes will still +# be listed in the log file. This option parses the /var/log/dpkg.log file and +# implies TRUNCATEDETAILS=yes. +FILTERINSTALLATIONS=no + +# This parameter defines how many lines to return per e-mail. Output longer +# than this value will be truncated in the e-mail sent out. +# Set value to "0" to disable this option. +LINES=1000 + +# This parameter gives a grep regular expression. If given, all output lines +# that _don't_ match the regexp are listed first in the script's output. This +# allows to easily remove noise from the AIDE report. +NOISE="" + +# This parameter defines which options are given to aide in the daily +# cron job. The default is "-V4". +AIDEARGS="" + +# Set this to a command that will be executed before the cron job +# exits. This can be used to postprocess the generated report. +# If the command is not in /sbin:/usr/sbin:/bin:/usr/bin (see PATH +# setting in the daily cron job), you need to give a fully qualified +# path. The script is executed before the aide lock is released. +# The hook is called with a single parameter meaning: +# signal: The cron job was terminated by a signal +# fatal: There was a fatal error +# nolock: The lock could not be obtained +# cantmovetmp: It was not possible to move away the temporary directory +# cantcreatetmp: It was not possible to create the temporary directory +# success: aide finished successfully and gave meaningful results +# unknown: onexit was called with an illegal reason (should not happen) +# If the cron job aborted before the cron job was fully set up, +# "early-" is prepended to the reason. +CRONEXITHOOK="" diff --git a/mail.rc b/mail.rc new file mode 100644 index 00000000..3fcc98d9 --- /dev/null +++ b/mail.rc @@ -0,0 +1,2 @@ +set ask askcc append dot save crt +ignore Received Message-Id Resent-Message-Id Status Mail-From Return-Path Via Delivered-To diff --git a/rc0.d/K01postfix b/rc0.d/K01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc0.d/K01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc1.d/K01postfix b/rc1.d/K01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc1.d/K01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc2.d/S01postfix b/rc2.d/S01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc2.d/S01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc3.d/S01postfix b/rc3.d/S01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc3.d/S01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc4.d/S01postfix b/rc4.d/S01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc4.d/S01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc5.d/S01postfix b/rc5.d/S01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc5.d/S01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/rc6.d/K01postfix b/rc6.d/K01postfix new file mode 120000 index 00000000..81e743ca --- /dev/null +++ b/rc6.d/K01postfix @@ -0,0 +1 @@ +../init.d/postfix \ No newline at end of file diff --git a/systemd/system/multi-user.target.wants/postfix.service b/systemd/system/multi-user.target.wants/postfix.service new file mode 120000 index 00000000..efaaa310 --- /dev/null +++ b/systemd/system/multi-user.target.wants/postfix.service @@ -0,0 +1 @@ +/lib/systemd/system/postfix.service \ No newline at end of file