committing changes in /etc after apt run
Package changes: -aide 0.17.3-4+deb11u1 amd64 -aide-common 0.17.3-4+deb11u1 all
This commit is contained in:
-203
@@ -80,207 +80,6 @@ maybe chmod 0755 'X11/Xsession.d'
|
||||
maybe chmod 0644 'X11/Xsession.d/90gpg-agent'
|
||||
maybe chmod 0755 'X11/xkb'
|
||||
maybe chmod 0644 'adduser.conf'
|
||||
maybe chmod 0755 'aide'
|
||||
maybe chmod 0644 'aide/aide.conf'
|
||||
maybe chmod 0755 'aide/aide.conf.d'
|
||||
maybe chmod 0644 'aide/aide.conf.d/10_aide_constants'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_distribution'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_hostname'
|
||||
maybe chmod 0644 'aide/aide.conf.d/10_aide_logext'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_machineid'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_prevyear'
|
||||
maybe chmod 0644 'aide/aide.conf.d/10_aide_run'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_year'
|
||||
maybe chmod 0755 'aide/aide.conf.d/20_aide_run_systemd-journald'
|
||||
maybe chmod 0644 'aide/aide.conf.d/21_aide_run_agetty'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_aide_apache2'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_aide_bind9'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_inn2_vars'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_acpid'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_adjtime'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_aide'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_alsa'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_amanda-client'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_amanda-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_amavisd-new'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_anacron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_anubis'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apache2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apcupsd'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_apt'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-cacher-ng'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listbugs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listchanges'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-show-versions'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_aptitude'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_at'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_atop'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_avahi-daemon'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_bind9'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_boinc-client'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_borgbackup'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_btmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cereal'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_checksecurity'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_chrony'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-freshclam'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-unofficial-sigs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_console-log'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_console-setup'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_courier-authlib'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cracklib-runtime'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cron-apt'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cups'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dbus'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dcc-common'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ddclient'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_debconf'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_debsecan'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dehydrated'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dev'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dlocate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dmeventd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dokuwiki'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dovecot'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dpkg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_e2fsprogs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_etckeeper'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4_exiscan'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4_logs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_fail2ban'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_fake-hwclock'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_fcron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_findutils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_gnupg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_hald'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_haproxy'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_hapsd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_icinga2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ifplugd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ifupdown'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_inetd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_initramfs-tools'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_initscripts'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_inn2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ippl'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_isc-dhcp-client'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_isc-dhcp-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_kerberos'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_laptop-mode-tools'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lastlog'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_libapache2-mod-fastcgi'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_libvirt-bin'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lighttpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lldpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_locales'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_logcheck'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_logrotate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lvm2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mail'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mailman'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_man'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mdadm'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mini-buildd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mlocate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_modules'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_munin'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_munin-nodes'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mysql-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_needrestart'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_network'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_network-manager'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nfs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nrpe'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nscd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nslcd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ntp-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_openvpn'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_openvpn-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_opie-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_pam_motd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_pcscd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_php-common'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_php-fpm'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_php7'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_pm-utils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_portmap'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postfix'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postfix-cluebringer'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postgresql'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postgrey'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_privoxy'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_proftpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_resolvconf'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rkhunter'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rngd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_root-dotfiles'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rsnapshot'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rsyslog'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_run_systemd_netif'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_run_systemd_resolve'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_run_tmpfiles'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_runuser'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_samba'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_saslauthd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_screen'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_slapd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_slrn'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_smartmontools'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_smokeping'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_sniproxy'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_snmpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_spamassassin'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_spampd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_squid'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-agent'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_sshd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_sudo'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_svn-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_syslog-ng'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-cron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-journald'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-machined'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-networkd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd-resolved'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd_journal'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_systemd_sessions'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_tiger'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_torrus'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_trac'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_tt-rss'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_udev'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_unbound'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_util-linux'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_utmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_vpnc'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_vsftpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_webalizer'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_wpasupplicant'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_wtmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-common'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-xkb-utils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xdm'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xe-guest-utilities'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xinetd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_dev'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_etc'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_proc_sys'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_run'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_tmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_var'
|
||||
maybe chmod 0644 'aide/aide.conf.d/99_aide_root'
|
||||
maybe chmod 0755 'aide/aide.settings.d'
|
||||
maybe chmod 0755 'aide/aide.settings.d/10_aide_sourceslist'
|
||||
maybe chmod 0755 'aide/aide.settings.d/31_aide_apt_settings'
|
||||
maybe chmod 0755 'aide/aide.settings.d/31_aide_svn-server_settings'
|
||||
maybe chmod 0755 'aide/aide.settings.d/31_aide_torrus_settings'
|
||||
maybe chmod 0755 'aide/aide.settings.d/31_aide_trac_settings'
|
||||
maybe chmod 0644 'aliases'
|
||||
maybe chmod 0644 'aliases.db'
|
||||
maybe chmod 0755 'alternatives'
|
||||
@@ -628,7 +427,6 @@ maybe chmod 0644 'cron.d/php'
|
||||
maybe chmod 0755 'cron.daily'
|
||||
maybe chmod 0644 'cron.daily/.placeholder'
|
||||
maybe chmod 0755 'cron.daily/00logwatch'
|
||||
maybe chmod 0755 'cron.daily/aide'
|
||||
maybe chmod 0755 'cron.daily/apt-compat'
|
||||
maybe chmod 0755 'cron.daily/chkrootkit'
|
||||
maybe chmod 0755 'cron.daily/dpkg'
|
||||
@@ -656,7 +454,6 @@ maybe chmod 0755 'dbus-1/system.d'
|
||||
maybe chmod 0644 'debconf.conf'
|
||||
maybe chmod 0644 'debian_version'
|
||||
maybe chmod 0755 'default'
|
||||
maybe chmod 0644 'default/aide'
|
||||
maybe chmod 0644 'default/amavisd-snmp-subagent'
|
||||
maybe chmod 0644 'default/console-setup'
|
||||
maybe chmod 0644 'default/cron'
|
||||
|
||||
-189
@@ -1,189 +0,0 @@
|
||||
# AIDE conf
|
||||
|
||||
# set environment for executable config files included by x_include
|
||||
@@x_include_setenv UPAC_settingsd /etc/aide/aide.settings.d
|
||||
|
||||
# The daily cron job depends on these paths
|
||||
database_in=file:/var/lib/aide/aide.db
|
||||
database_out=file:/var/lib/aide/aide.db.new
|
||||
database_new=file:/var/lib/aide/aide.db.new
|
||||
gzip_dbout=yes
|
||||
|
||||
# Set to no to disable report_summarize_changes option.
|
||||
report_summarize_changes=yes
|
||||
|
||||
# Set to no to disable grouping of files in report.
|
||||
report_grouped=yes
|
||||
|
||||
# Set verbosity of aide run and reports
|
||||
log_level=warning
|
||||
report_level=changed_attributes
|
||||
|
||||
# Set to yes to print the checksums in the report in hex format
|
||||
report_base16 = no
|
||||
|
||||
# if you want to sacrifice security for speed, remove some of these
|
||||
# checksums.
|
||||
Checksums = sha256+sha512+rmd160+haval+gost+crc32+tiger+whirlpool
|
||||
|
||||
# The checksums of the databases to be printed in the report
|
||||
# Set to 'E' to disable.
|
||||
database_attrs = Checksums
|
||||
|
||||
# check permissions, owner, group and file type
|
||||
OwnerMode = p+u+g+ftype
|
||||
|
||||
# Check size and block count
|
||||
Size = s+b
|
||||
|
||||
# Files that stay static
|
||||
InodeData = OwnerMode+n+i+Size+l+X
|
||||
StaticFile = m+c+Checksums
|
||||
|
||||
# Files that stay static but are copied to a ram disk on startup
|
||||
# (causing different inode)
|
||||
RamdiskData = InodeData-i
|
||||
|
||||
# Check everything
|
||||
Full = InodeData+StaticFile
|
||||
|
||||
# Files that change their mtimes or ctimes but not their contents
|
||||
VarTime = InodeData+Checksums
|
||||
|
||||
# Files that are recreated regularly but do not change their contents
|
||||
VarInode = VarTime-i
|
||||
|
||||
# Files that change their contents during system operation
|
||||
VarFile = OwnerMode+n+l+X
|
||||
|
||||
# Directories that change their contents during system operation
|
||||
VarDir = OwnerMode+n+i+X
|
||||
|
||||
# Directories that are recreated regularly and change their contents
|
||||
VarDirInode = OwnerMode+n+X
|
||||
|
||||
# Directories that change their mtimes or ctimes but not their contents
|
||||
VarDirTime = InodeData
|
||||
|
||||
# Logs are special: they are continously written to, may be compressed
|
||||
# have their file name changed in different, mutually incompatibly ways
|
||||
# and apprear and vanish at will. Handling this is a a complex and error-
|
||||
# prone issue.
|
||||
#
|
||||
# This is best broken down in a number of small tasks:
|
||||
#
|
||||
#
|
||||
# (A)
|
||||
# While a live log is being written to, it doesn't change its mode and
|
||||
# inode and its size only increases.
|
||||
#
|
||||
# (B)
|
||||
# When a live log is rotated for the first time, it should not change
|
||||
# its mode, may change its inode, and its size decreases. The size
|
||||
# decrease may not be noticed by aide if the file had size x at the last
|
||||
# aide run, was rotated in the mean time and was written to so that it
|
||||
# had a size > x at the next aide run.
|
||||
#
|
||||
# (C)
|
||||
# When a log is compressed, this looks to aide like the uncompressed
|
||||
# file vanished (or was replaced by another file) and the compressed
|
||||
# file appeared out of the blue. There is (currently) no way to
|
||||
# associate the (gone) uncompressed file's contents with the (new)
|
||||
# compressed file's contents
|
||||
#
|
||||
# (D)
|
||||
# The actual log rotation may rename foo.{x}.bar to foo.{x+1}.bar without
|
||||
# changing the other properties of the file
|
||||
#
|
||||
# (E)
|
||||
# If only a given number of log generations is to be kept, foo.{y}.bar may
|
||||
# vanish, but usually only when no foo.{z}.bar exists for z>y.
|
||||
#
|
||||
# (F)
|
||||
# The set of files foo.{x}.bar to foo.{y}.bar is called a "log series"
|
||||
# in aide terms, with the lowest x being called the "LoSerMember" element
|
||||
# and the highest y being called the "HiSerMember" element, and the z
|
||||
# with x<z<y simple called "SerMember". The Lo and Hi members need to
|
||||
# be special cased in aide configuration.
|
||||
#
|
||||
#
|
||||
# This is an example of the normal life of a log named foo in a logrotate
|
||||
# configuration using a configuration at it is commonly used in Debian
|
||||
# (from old to new):
|
||||
# 1 logrotate deletes HiSerMember foo.{y}.gz
|
||||
# 2 logrotate rotates SerMember foo.{z-1}.gz to foo.{z}.gz for all
|
||||
# z with 3<z<=y. This includes rotation of foo.{y-1}.gz to
|
||||
# foo.{y}.gz and foo.2.gz to foo.3.gz
|
||||
# 3 logrotate compresses foo.1 to foo.2.gz, creating LoSerMember foo.2.gz
|
||||
# 4 logrotate rotates foo to foo.1 (a simple rename)
|
||||
# 5 logrotate creates new, empty foo
|
||||
# 6 foo daemon logs to foo - foo grows in size
|
||||
#
|
||||
# we need the following rules:
|
||||
# /var/log/foo$ f Log
|
||||
# /var/log/foo$ f FreqRotLog
|
||||
# this takes care of the growing live log (step 7). The "Log" rule
|
||||
# is appropriate for logs that are not rotated daily as rotation
|
||||
# might be reported (if the file size has decreased since the last
|
||||
# aide run). For daily rotated logs, the "FreqRotLog" may be more
|
||||
# appropriate.
|
||||
# /var/log/foo\.1$ f LowLog
|
||||
# this takes care of step 5.
|
||||
# /var/log/foo\.2\.gz$ f LoSerMemberLog
|
||||
# this allows yet unknown new files to appear with a \.2\.gz extension,
|
||||
# covering step 3.
|
||||
# /var/log/foo\.[3..y-1]\.gz$ f SerMemberLog
|
||||
# this watches the log files as they wander through the Series,
|
||||
# changing only their file name but not their contents or metadata,
|
||||
# covering step 2.
|
||||
# Please note that [3..y-1] needs to be a manually crafted regexp covering
|
||||
# all numbers between 3 and y-1.
|
||||
# /var/log/foo\.y\.gz$ f HiSerMemberLog
|
||||
# finally, the last element of the Series is allowed to vanish without
|
||||
# being reported, covering step 1.
|
||||
#
|
||||
# Please note that these example rules need to be adapted to the logrotate
|
||||
# configuration for the log. Compression may be disabled or lead to a different
|
||||
# extension, the dateext option may be used, old logs might be held in a
|
||||
# different place, a log series does not necessarily need to be compressed etc.
|
||||
#
|
||||
# Please note that savelog rotates the live log to .0 and not to .1 as it
|
||||
# is logrotates (changeable) default.
|
||||
|
||||
|
||||
# Logs grow in size. Log rotation of these logs will be reported, so
|
||||
# this should only be used for logs that are not rotated daily.
|
||||
Log = OwnerMode+n+S+X
|
||||
|
||||
# Logs that are frequently rotated
|
||||
FreqRotLog = Log-S
|
||||
|
||||
# The first instance of a rotated log: After the log has stopped being
|
||||
# written to, but before rotation
|
||||
LowLog = Log-S
|
||||
|
||||
# Rotated logs change their file name but retain all their other properties
|
||||
SerMemberLog = Full+I
|
||||
|
||||
# The first instance of a compressed, rotated log: After a LowLog was
|
||||
# compressed.
|
||||
LoSerMemberLog = SerMemberLog+ANF
|
||||
|
||||
# The last instance of a compressed, rotated log: After this name, a log
|
||||
# will be removed
|
||||
HiSerMemberLog = SerMemberLog+ARF
|
||||
|
||||
# Not-yet-compressed log created by logrotate's dateext option:
|
||||
# These files appear one rotation (renamed from the live log) and are gone
|
||||
# the next rotation (being compressed)
|
||||
LowDELog = SerMemberLog+ANF+ARF
|
||||
|
||||
# Compressed log created by logrotate's dateext option: These files appear
|
||||
# once and are not touched any more.
|
||||
SerMemberDELog = Full+ANF
|
||||
|
||||
# For daemons that log to a variable file name and have the live log
|
||||
# hardlinked to a static file name
|
||||
LinkedLog = Log-n
|
||||
|
||||
@@x_include /etc/aide/aide.conf.d ^[a-zA-Z0-9_-]+$
|
||||
@@ -1,2 +0,0 @@
|
||||
@@define IP4ADDRESS (25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])(\\.(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])){3}
|
||||
@@define IP6ADDRESS ((:(:[0-9A-Fa-f]{1,4}){1,7}|::|[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,6}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,5}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,4}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,3}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,2}|::|:[0-9A-Fa-f]{1,4}(::[0-9A-Fa-f]{1,4}|::|:[0-9A-Fa-f]{1,4}(::|:[0-9A-Fa-f]{1,4}))))))))|(:(:[0-9A-Fa-f]{1,4}){0,5}|[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,4}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,3}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,2}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4})?|:[0-9A-Fa-f]{1,4}(:|:[0-9A-Fa-f]{1,4})))))):(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])(\\.(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])){3})
|
||||
@@ -1,20 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
sanitize()
|
||||
{
|
||||
sed 's/[^[:alnum:]/]/_/g'
|
||||
}
|
||||
|
||||
if [ -e "/etc/debian_version" ]; then
|
||||
printf "@@ifndef DEBIANVERSION\\n"
|
||||
printf "@@define DEBIANVERSION Debian/%s\\n" "$(head -n 1 /etc/debian_version | sanitize)"
|
||||
printf "@@endif\\n"
|
||||
fi
|
||||
if [ -x "/usr/bin/lsb_release" ]; then
|
||||
for parm in id description release codename; do
|
||||
PARM="$LSB_$(echo $parm | tr '[:lower:]' '[:upper:]')"
|
||||
printf "@@ifndef %s\\n" "${PARM}"
|
||||
printf "@@define %s %s\\n" "${PARM}" "$(/usr/bin/lsb_release --short --$parm | sanitize)"
|
||||
printf "@@endif\\n"
|
||||
done
|
||||
fi
|
||||
@@ -1,28 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
escapere()
|
||||
{
|
||||
sed 's/\./\\\\./g'
|
||||
}
|
||||
|
||||
if [ -n "$(hostname --fqdn)" ]; then
|
||||
printf "@@define FQDN %s\\n" "$(hostname --fqdn | escapere)"
|
||||
fi
|
||||
if [ -n "$(hostname)" ]; then
|
||||
printf "@@define HOSTNAME %s\\n" "$(hostname | escapere)"
|
||||
fi
|
||||
if [ -n "$(dnsdomainname)" ]; then
|
||||
printf "@@define DNSDOMAINNAME %s\\n" "$(dnsdomainname | escapere)"
|
||||
fi
|
||||
if [ -n "$(dpkg --print-architecture)" ]; then
|
||||
printf "@@define ARCH %s\\n" "$(dpkg --print-architecture)"
|
||||
fi
|
||||
if [ -n "$(dpkg --print-foreign-architectures)" ]; then
|
||||
if [ "$(dpkg --print-foreign-architectures | wc -l)" -gt 1 ]; then
|
||||
printf "@@define FOREIGN_ARCHES %s\\n" "$(dpkg --print-foreign-architectures | tr '\\n' '|' | sed 's/^/(/; s/|$/)/')"
|
||||
else
|
||||
printf "@@define FOREIGN_ARCHES %s\\n" "$(dpkg --print-foreign-architectures)"
|
||||
fi
|
||||
fi
|
||||
dpkg-architecture --host-type 2>/dev/null | awk '{print "@@define " $1 " " $2}' FS="="
|
||||
|
||||
@@ -1,8 +0,0 @@
|
||||
# this variable is pulled in to places where logs are rotated
|
||||
# if you have modified your log rotation mechanisms to use different
|
||||
# comprssion tools, you can change the extension here.
|
||||
# This changes the behavior for all aide rules, so if you have
|
||||
# only changed part of your log rotation mechanisms, you still
|
||||
# need to touch the respective rules.
|
||||
|
||||
@@define LOGEXT gz
|
||||
@@ -1,10 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
MIDFILE="/etc/machine-id"
|
||||
MACHINEID="0000000000000000000"
|
||||
if [ -r "$MIDFILE" ]; then
|
||||
MACHINEID="$(head -n1 /etc/machine-id)"
|
||||
fi
|
||||
|
||||
printf "@@define MACHINEID %s\\n" "$MACHINEID"
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
echo "@@define PREVYEAR4D $(date +%Y --date="last year")"
|
||||
@@ -1,10 +0,0 @@
|
||||
# Please note: always remove leading and trailing slashes in path macros
|
||||
# var/run -> run
|
||||
@@ifndef RUN
|
||||
@@define RUN run
|
||||
@@endif
|
||||
# var/lock -> run/lock
|
||||
@@ifndef RUNLOCK
|
||||
@@define RUNLOCK run/lock
|
||||
@@endif
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
printf "@@define YEAR4D %s\\n" "$(date +%Y)"
|
||||
printf "@@define LASTYEAR4D %s\\n" "$(date +%Y --date='last year')"
|
||||
|
||||
# this will generate a lot of alarms on January 1st. If you want
|
||||
# to sleep in on New Year, consider using the following code snippet
|
||||
# which, in January, generates a regexp that matches both the current
|
||||
# year and the previous year. This should prevent aide reports to be
|
||||
# generated on the New Year. It is assumed that the aide database will
|
||||
# be regenerated at least once in January.
|
||||
#if [ "$(date +%m)" = "01" ]; then
|
||||
# printf "@@define YEAR4D (%s|%s)\\n" "$(date +%Y)" "$(date +%Y --date='last year')"
|
||||
#else
|
||||
# printf "@@define YEAR4D %s\\n" "$(date +%Y)"
|
||||
#fi
|
||||
@@ -1,8 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ -d "/var/log/journal" ]; then
|
||||
printf "@@define SYSTEMD_JOURNAL var/log/journal\\n"
|
||||
else
|
||||
printf "@@define SYSTEMD_JOURNAL @@{RUN}/log/journal\\n"
|
||||
fi
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/agetty\\.reload$ f VarFile
|
||||
@@ -1,5 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ -e /etc/apache2/mods-enabled/suexec.load ]; then
|
||||
echo "@@define APACHE2_SUEXEC 1"
|
||||
fi
|
||||
@@ -1,19 +0,0 @@
|
||||
#! /bin/bash
|
||||
# this script automatically sets the BINDCHROOT variable to the
|
||||
# directory that bind chroots to via configuration in
|
||||
# /etc/default/bind9. This is only going to work if your /etc/default/bind9
|
||||
# is not too modified.
|
||||
#
|
||||
# If you want to use this magic, just uncomment it.
|
||||
# You can also manually set the chroot directory in a non-executable
|
||||
# file: @@define BINDCHROOT /var/cache/bind
|
||||
|
||||
# # Automagically extract chroot directory
|
||||
# . /etc/default/bind9
|
||||
# set $OPTIONS
|
||||
# for i in $@;do
|
||||
# if [ "$1" == "-t" ]
|
||||
# then echo "@@define BINDCHROOT $2"; break
|
||||
# else shift
|
||||
# fi
|
||||
# done
|
||||
@@ -1,10 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ -e /etc/news/innfeed.conf ]; then
|
||||
echo -n "@@define INN2_INNFEED_OUTFEEDS ("
|
||||
< /etc/news/innfeed.conf \
|
||||
sed -n '/^[[:space:]]*peer[[:space:]]\+/{s/^[[:space:]]*peer[[:space:]]\+\([-.[:alnum:]]\+\).*/\1/;p;}' | \
|
||||
tr '\n' '|' |\
|
||||
sed 's/|$/)/'
|
||||
echo
|
||||
fi
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/log/acpid$ f Log
|
||||
/var/log/acpid\\.1$ f LowLog
|
||||
/var/log/acpid\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/acpid\\.3\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/acpid\\.4\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/@@{RUN}/acpid\\.(socket|pid)$ f VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/etc/adjtime$ f VarFile
|
||||
@@ -1,11 +0,0 @@
|
||||
/var/lib/aide/aide\\.db(\\.new)?$ f VarFile
|
||||
/var/lib/aide$ d VarDir
|
||||
/var/log/aide/aide\\.log(\\.0)?$ f LowLog
|
||||
/var/log/aide/aide\\.log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/aide/aide\\.log\\.[2-5]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/aide/aide\\.log\\.6\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/log/aide$ d VarDir
|
||||
/@@{RUN}/aide$ d VarDirInode
|
||||
!/@@{RUN}/aide/cron\\.daily\\.lock$ f
|
||||
!/var/tmp/aide\\.cron\\.daily$ d
|
||||
!/var/tmp/aide\\.cron\\.daily/((error|a(run|err))log|mailfile)$ f
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/alsa/asound\\.state$ f VarFile
|
||||
@@ -1,9 +0,0 @@
|
||||
@@define AMANDALOG var/log/amanda
|
||||
|
||||
/var/lib/dumpdates$ f VarFile
|
||||
!/@@{AMANDALOG}/amandad/amandad\\.@@{YEAR4D}[0-9]{10}\\.debug$ f
|
||||
/@@{AMANDALOG}/(amandad|client)$ d VarDir
|
||||
@@ifdef AMANDABACKUPSET
|
||||
/@@{AMANDALOG}/client/@@{AMANDABACKUPSET}$ d VarDir
|
||||
@@endif
|
||||
!/@@{AMANDALOG}/client/[^/]+/(sendsize|killpgrp|sendbackup|selfcheck)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f
|
||||
@@ -1,119 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
# this is not consistently generating restricted rules. If you have
|
||||
# an amanda host, please help by adding the appropriate restrictions
|
||||
|
||||
MULTILINEDLE=0
|
||||
|
||||
skip_multiline_dle() {
|
||||
if [ "$MULTILINEDLE" = "0" ]; then
|
||||
if echo "${rest}" | grep -q '{'; then
|
||||
MULTILINEDLE=1
|
||||
fi
|
||||
return 1
|
||||
elif echo "${host} ${dev} ${rest}" | grep -q '}'; then
|
||||
MULTILINEDLE=0
|
||||
fi
|
||||
return 0
|
||||
}
|
||||
|
||||
if ! [ -d "/etc/amanda" ]; then
|
||||
exit 0
|
||||
fi
|
||||
for configfile in $(find /etc/amanda -name amanda.conf ! -path '/etc/amanda/template.d*' | tr '
|
||||
' ' '); do
|
||||
config="$(dirname "${configfile}")"
|
||||
cd "${config}" || exit 1
|
||||
CONF="${config##*/}"
|
||||
AMANDA_TAPEDEV="$(amgetconf "${CONF}" tapedev)"
|
||||
AMANDA_TAPEDEV="${AMANDA_TAPEDEV#file:/}"
|
||||
if [ -d "${AMANDA_TAPEDEV}" ]; then
|
||||
print "@@define AMANDA_TAPEDEV %s\\n" "${AMANDA_TAPEDEV}"
|
||||
#shellcheck disable=SC2044
|
||||
for slot in $(find /"${AMANDA_TAPEDEV}" -type d -regex '.*/slot[0-9]+' -printf "%P\\n"); do
|
||||
if [ -f "disklist" ]; then
|
||||
while read -r host dev rest; do
|
||||
if echo "${host}" | grep -qE '^(#.*)?$'; then continue; fi
|
||||
#shellcheck disable=SC2001
|
||||
dev="$(echo "${dev}" | sed 's|/|_|g')"
|
||||
if ! skip_multiline_dle; then
|
||||
printf "!/@@{AMANDA_TAPEDEV}/%s/[0-9]{5}[-\\.]%s\\.%s\\.[0123]$" "${slot}" "${host}" "${dev}"
|
||||
fi
|
||||
done < disklist
|
||||
MULTILINEDLE=0
|
||||
fi
|
||||
printf "/@@{AMANDA_TAPEDEV}/%s/00000[-\\.]%s-%03d$ f VarFile\\n" "${slot}" "${CONF}" "${slot#slot}"
|
||||
printf "!/@@{AMANDA_TAPEDEV}/%s/[0-9]{5}[-\\.]TAPEEND$\\n" "${slot}"
|
||||
printf "/@@{AMANDA_TAPEDEV}/%s$ d VarDir\\n" "${slot}"
|
||||
done
|
||||
printf "/@@{AMANDA_TAPEDEV}/(data|info)$ f VarFile\\n"
|
||||
printf "/@@{AMANDA_TAPEDEV}$ d VarDir\\n"
|
||||
fi
|
||||
AMANDA_LOGDIR="$(amgetconf "${CONF}" logdir)"
|
||||
AMANDA_LOGDIR="${AMANDA_LOGDIR#/}"
|
||||
if [ -n "$AMANDA_LOGDIR" ]; then
|
||||
printf "@@define AMANDA_LOGDIR %s\\n" "${AMANDA_LOGDIR}"
|
||||
printf "/@@{AMANDA_LOGDIR}/log\\.@@{YEAR4D}[0-9]{4}\\.0$ f LowDELog\\n"
|
||||
printf "/@@{AMANDA_LOGDIR}/oldlog/log\\.@@{YEAR4D}[0-9]{4}\\.0$ f SerMemberDELog\\n"
|
||||
printf "/@@{AMANDA_LOGDIR}/amdump\\.1$ f LoSerMemberLog\\n"
|
||||
printf "/@@{AMANDA_LOGDIR}/amdump\\.[2-8]$ f SerMemberLog\\n"
|
||||
printf "/@@{AMANDA_LOGDIR}/amdump\\.9$ f HiSerMemberLog\\n"
|
||||
printf "/@@{AMANDA_LOGDIR}(/oldlog)?$ d VarDir\\n"
|
||||
fi
|
||||
AMANDA_INDEXDIR="$(amgetconf "${CONF}" indexdir)"
|
||||
AMANDA_INDEXDIR="${AMANDA_INDEXDIR#/}"
|
||||
if [ -n "${AMANDA_INDEXDIR}" ]; then
|
||||
printf "@@define AMANDA_INDEXDIR %s\\n" "${AMANDA_INDEXDIR}"
|
||||
if [ -f "disklist" ]; then
|
||||
while read -r host dev rest; do
|
||||
if echo "${host}" | grep -q '^\\(#.*\\)\\?$'; then continue; fi
|
||||
dev="$(echo "${dev}" | sed 's|[/:]|_|g;s|\\"||g')"
|
||||
if ! skip_multiline_dle; then
|
||||
printf "!/@@{AMANDA_INDEXDIR}/%s/%s/@@{YEAR4D}[0-9]{4}_[0123]\\.gz$ f\\n" "${host}" "${dev}"
|
||||
printf "/@@{AMANDA_INDEXDIR}/%s/%s$ d VarDir\\n" "${host}" "${dev}"
|
||||
fi
|
||||
done < disklist
|
||||
MULTILINEDLE=0
|
||||
fi
|
||||
fi
|
||||
AMANDA_CHANGERFILE="$(amgetconf "${CONF}" changerfile)"
|
||||
AMANDA_CHANGERDIR="${AMANDA_CHANGERFILE%changer}"
|
||||
AMANDA_CHANGERDIR="${AMANDA_CHANGERDIR#/}"
|
||||
if [ -n "${AMANDA_CHANGERDIR}" ]; then
|
||||
printf "@@define AMANDA_CHANGERDIR %s\\n" "${AMANDA_CHANGERDIR}"
|
||||
printf "/@@{AMANDA_CHANGERDIR}/(changer-(access|clean|slot)|tapelist(\\.yesterday)?)$ f VarFile\\n"
|
||||
printf "/@@{AMANDA_CHANGERDIR}$ d VarDir\\n"
|
||||
fi
|
||||
AMANDA_INFOFILE="$(amgetconf "${CONF}" infofile)"
|
||||
AMANDA_INFOFILE="${AMANDA_INFOFILE#/}"
|
||||
if [ -n "${AMANDA_INFOFILE}" ]; then
|
||||
printf "@@define AMANDA_INFOFILE %s\\n" "${AMANDA_INFOFILE}"
|
||||
if [ -f "disklist" ]; then
|
||||
while read -r host dev rest; do
|
||||
if echo "${host}" | grep -qE '^(#.*)?$'; then continue; fi
|
||||
#shellcheck disable=SC2001
|
||||
dev="$(echo "${dev}" | sed 's|[/:]|_|g;s|\"||g')"
|
||||
if ! skip_multiline_dle; then
|
||||
printf "/@@{AMANDA_INFOFILE}/%s/%s/info$ f VarFile\\n" "${host}" "${dev}"
|
||||
printf "/@@{AMANDA_INFOFILE}/%s/%s$ d VarDir\\n" "${host}" "${dev}"
|
||||
fi
|
||||
done < disklist
|
||||
MULTILINEDLE=0
|
||||
fi
|
||||
fi
|
||||
# this is hardcoded since amgetconf refuses to deliver diskdir
|
||||
AMANDA_HOLDING="srv/amanda/holding"
|
||||
if [ -n "$AMANDA_HOLDING" ]; then
|
||||
printf "/%s$ d VarDir\\n" "${AMANDA_HOLDING}"
|
||||
fi
|
||||
printf "@@define AMANDALOG var/log/amanda/server/%s\\n" "${CONF}"
|
||||
printf "!/@@{AMANDALOG}/(amcheck|amlogroll|amreport|amtrm(idx|log)|chunker|driver|dumper|planner|taper)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f\\n"
|
||||
printf "!/@@{AMANDALOG}/(chunker|dumper)\\.@@{YEAR4D}[0-9]{13}\\.debug$ f\\n"
|
||||
printf "/@@{AMANDALOG}$ d VarDir\\n"
|
||||
printf "/var/log/amanda/server$ d VarDir\\n"
|
||||
done
|
||||
|
||||
printf "@@define AMANDALOG var/log/amanda/amandad\\n"
|
||||
printf "!/@@{AMANDALOG}/(amandad)\\.@@{YEAR4D}[0-9]{10}\\.debug$ f\\n"
|
||||
printf "/@@{AMANDALOG}$ d VarDir\\n"
|
||||
printf "/tmp/amanda$ d VarDir\\n"
|
||||
@@ -1,13 +0,0 @@
|
||||
/@@{RUN}/amavis/amavisd.(lock|pid)$ f VarFile
|
||||
/@@{RUN}/amavis$ d VarDirInode
|
||||
/var/lib/amavis$ d VarDir
|
||||
/var/lib/amavis/tmp$ d VarDir
|
||||
!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}$ d
|
||||
!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}/(email\\.txt|parts)$ f
|
||||
/var/lib/amavis/amavisd.sock$ s VarInode
|
||||
/var/lib/amavis/db$ d VarDir
|
||||
/var/lib/amavis/db/__db.[0-9]{3}$ f VarFile
|
||||
/var/lib/amavis/db/(cache(-expiry)?|snmp|nanny)\\.db$ f VarFile
|
||||
/var/lib/amavis/.spamassassin$ d VarDir
|
||||
/var/lib/amavis/.spamassassin/bayes_(toks|seen)$ f VarFile
|
||||
/var/lib/amavis/.spamassassin/auto-whitelist$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/spool/anacron/cron\\.(monthly|weekly|daily)$ f VarFile
|
||||
/var/lib/systemd/timers/stamp-anacron\\.timer$ f VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/anubis\\.pid$ f VarFile
|
||||
@@ -1,19 +0,0 @@
|
||||
# you can define your own APACHE2_LOGS regex in an earlier file,
|
||||
# overriding the defaults given here
|
||||
@@ifndef APACHE2_LOGS
|
||||
@@ifdef APACHE2_SUEXEC
|
||||
@@define APACHE2_LOGS (access|error|suexec)
|
||||
@@else
|
||||
@@define APACHE2_LOGS (access|error)
|
||||
@@endif
|
||||
@@endif
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\\.log$ f Log
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.1$ f LowLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.([3-9]|[1-4][0-9]|5[0-1])\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\\.log\\.52\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
|
||||
/@@{RUN}/apache2/apache2\\.pid$ f VarFile
|
||||
/@@{RUN}/apache2/ssl_scache$ f VarFile
|
||||
/var/log/apache2$ d VarDir
|
||||
/@@{RUN}/apache2$ d VarDirInode
|
||||
@@ -1,3 +0,0 @@
|
||||
/var/log/apcupsd\\.events$ f Log
|
||||
/@@{RUN}/apcupsd\\.pid$ f VarFile
|
||||
/@@{RUNLOCK}/LCK\\.\\.$ f VarFile
|
||||
@@ -1,103 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
#shellcheck disable=SC2154
|
||||
if [ -x "$UPAC_settingsd/10_aide_sourceslist" ]; then
|
||||
#shellcheck disable=SC1090
|
||||
. "$UPAC_settingsd/10_aide_sourceslist"
|
||||
fi
|
||||
VARDIR="var/lib/apt"
|
||||
LISTSDIR="$VARDIR/lists"
|
||||
CACHEDIR="var/cache/apt"
|
||||
ARCHIVESDIR="$CACHEDIR/archives"
|
||||
SYSTEMDDIR="var/lib/systemd/timers"
|
||||
LOGDIR="var/log/apt"
|
||||
IGNORE_ARCHIVES=""
|
||||
IGNORE_FRQCHG=""
|
||||
|
||||
if [ -r "$UPAC_settingsd/31_aide_apt_settings" ]; then
|
||||
# pull in configuration
|
||||
#shellcheck disable=SC1090
|
||||
. "$UPAC_settingsd/31_aide_apt_settings"
|
||||
fi
|
||||
|
||||
printf "@@define APT_TRANSLATIONS (ca|cs|da|de|de_DE|en|eo|es|eu|fi|fr|hr|hu|id|it|ja|km|ko|nb|nl|pl|pt|pt_BR|ro|ru|sk|sr|sv|uk|vi|zh|zh_CN|zh_TW)\\n"
|
||||
printf "@@define APT_ARCH (@@{ARCH}|all)\\n"
|
||||
|
||||
RE="^\\(deb\\|deb-src\\)[[:space:]]\\+\\(\\(\\[[^]]\\+\\]\\)[[:space:]]\\+\\)\\?\\([^[:space:]]\\+\\)[[:space:]]\\+\\([^[:space:]]\\+\\)[[:space:]]\\+\\(.*\\)$"
|
||||
#shellcheck disable=SC2086
|
||||
cat ${SOURCESLIST} /dev/null | sed 's/ #.*$//' | while read -r line; do
|
||||
deb="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\1/;p;}")"
|
||||
uri="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\4/;p;}")"
|
||||
dist="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\5/;p;}")"
|
||||
comp="$(echo "${line}" | sed -n "/^deb/{s/${RE}/\\6/;p;}")"
|
||||
#shellcheck disable=SC2001
|
||||
PROTOCOL="$(echo "${uri}" | sed 's|\([^:]\+\).*|\1|')"
|
||||
if echo "${PROTOCOL}" | grep -qE '(https?|ftp)'; then
|
||||
HOST="$(echo "${uri}" | sed -e 's|.*//\([-_.[:alnum:]]\+\).*|\1|' -e 's|\.|\\\\.|g')"
|
||||
HOSTPATH="$(echo "${uri}" | sed -e 's|.*//[^/[:space:]]\+/\?||;s|/$||;s|/|_|g;s|^\(.\+\)$|_\1|' -e 's|\.|\\\\.|g')"
|
||||
dist="${dist//\//_}"
|
||||
if [ -n "${DEBUG}" ]; then
|
||||
echo "${line}" | sed -n "/^deb/{s/${RE}/1: \\1, 2: \\2, 3: \\3, 4: \\4, 5: \\5, 6: \\6/;p;}"
|
||||
printf "# deb: %s\\n" "${deb}"
|
||||
printf "# uri %s\\n" "${uri}"
|
||||
printf "# dist: %s\\n" "${dist}"
|
||||
printf "# comp: %s\\n" "${comp}"
|
||||
printf "# HOST %s\\n" "${HOST}"
|
||||
printf "# HOSTPATH %s\\n" "${HOSTPATH}"
|
||||
fi
|
||||
if [ "$deb" = "deb" ]; then
|
||||
for c in $comp; do
|
||||
printf "/%s/%s%s_dists_%s_%s_binary-@@{APT_ARCH}_Packages(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}"
|
||||
printf "/%s/%s%s_dists_%s_%s_Contents-@@{APT_ARCH}((\\\\\\\\.diff_Index|\\\\\\\\.lz4))?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}"
|
||||
printf "@@ifdef FOREIGN_ARCHES\\n"
|
||||
printf "/%s/%s%s_dists_%s_%s_binary-@@{FOREIGN_ARCHES}_Packages(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}"
|
||||
printf "@@endif\\n"
|
||||
printf "/%s/%s%s_dists_%s_(InRelease|Release(\\\\\\\\.gpg)?)$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}"
|
||||
printf "/%s/%s%s_dists_%s_%s_i18n_Translation-@@{APT_TRANSLATIONS}(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}"
|
||||
done
|
||||
printf "!/%s/partial/%s%s_dists_%s_Release\\\\\\\\.gpg\\\\\\\\.reverify$ f\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}"
|
||||
elif [ "$deb" = "deb-src" ]; then
|
||||
for c in $comp; do
|
||||
printf "/%s/%s%s_dists_%s_%s_source_Sources(\\\\\\\\.diff_Index)?$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}" "${c}"
|
||||
printf "/%s/%s%s_dists_%s_(InRelease|Release(\\\\\\\\.gpg)?)$ f VarFile\\n" "${LISTSDIR}" "${HOST}" "${HOSTPATH}" "${dist}"
|
||||
done
|
||||
fi
|
||||
else
|
||||
: # other protocols are not supported. If you feel like they should
|
||||
: # please give a good reason and probably a patch.
|
||||
fi
|
||||
printf "\\n\\n"
|
||||
done
|
||||
|
||||
printf "/%s(/(auxfiles|partial))?$ d VarDir\\n" "${LISTSDIR}"
|
||||
printf "/%s/lock$ f VarFile\\n" "${LISTSDIR}"
|
||||
printf "/%s/periodic/(download-upgradeable|update)-stamp$ f VarTime\\n" "${VARDIR}"
|
||||
printf "/%s/(daily_lock|extended_states)$ f VarFile\\n" "${VARDIR}"
|
||||
printf "/%s$ d VarDir\\n" "${VARDIR}"
|
||||
printf "\\n"
|
||||
printf "/%s/stamp-apt-daily(-upgrade)?\\\\\\\\.timer$ f VarFile\\n" "${SYSTEMDDIR}"
|
||||
printf "\\n"
|
||||
printf "/%s/(term|history)\\\\\\\\.log$ f Log\\n" "${LOGDIR}"
|
||||
printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.1\\\\\\\\.@@{LOGEXT}$ f LoSerMemberLog\\n" "${LOGDIR}"
|
||||
printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.([2-9]|1[0-1])\\\\\\\\.@@{LOGEXT}$ f SerMemberLog\\n" "${LOGDIR}"
|
||||
printf "/%s/(term|history)\\\\\\\\.log\\\\\\\\.12\\\\\\\\.@@{LOGEXT}$ f HiSerMemberLog\\n" "${LOGDIR}"
|
||||
printf "/%s/eipp\\\\\\\\.log\\\\\\\\.xz$ f VarFile\\n" "${LOGDIR}"
|
||||
printf "/%s$ d VarDir\\n" "${LOGDIR}"
|
||||
printf "\\n"
|
||||
printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.0$ f LowLog\\n"
|
||||
printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.1\\\\\\\\.@@{LOGEXT}$ f LoSerMemberLog\\n"
|
||||
printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.[2345]\\\\\\\\.@@{LOGEXT}$ f SerMemberLog\\n"
|
||||
printf "/var/backups/apt\\\\\\\\.extended_states\\\\\\\\.6\\\\\\\\.@@{LOGEXT}$ f HiSerMemberLog\\n"
|
||||
|
||||
if [ "$IGNORE_ARCHIVES" = "yes" ]; then
|
||||
printf "!/%s/[-[:alnum:]%%\.~_+]+_@@{APT_ARCH}\\\\\\\\.deb$ f\\n" "${ARCHIVESDIR}"
|
||||
printf "@@ifdef FOREIGN_ARCHES\\n"
|
||||
printf "!/%s/[-[:alnum:]%%\.~_+]+_@@{FOREIGN_ARCHES}\\\\\\\\.deb$ f\\n" "${ARCHIVESDIR}"
|
||||
printf "@@endif\\n"
|
||||
fi
|
||||
|
||||
if [ "$IGNORE_FRQCHG" = "yes" ]; then
|
||||
printf "/%s(/partial|/lock)?$ d VarDir\\n" "${ARCHIVESDIR}"
|
||||
printf "!/%s/(src)?pkgcache\\\\\\\\.bin$ f\\n" "${CACHEDIR}"
|
||||
printf "/%s$ d VarDir\\n" "${CACHEDIR}"
|
||||
fi
|
||||
@@ -1,58 +0,0 @@
|
||||
@@define ACNGCACHE var/cache/apt-cacher-ng
|
||||
@@define ACNGDEB (zg20150|debian(security)?)
|
||||
@@define ACNGDISTS @@{ACNGDEB}/dists/(bullseye|(buster|stable)(-updates)?|experimental|jessie|sid|stretch(-updates)?|unstable|testing|(bullseye|buster|jessie|stretch|sid)-zg-((un)?stable|testing|experimental))(/updates)?
|
||||
@@define ACNGMNC (main|contrib|non-free)(/dep11)?
|
||||
@@define ACNGARCHS (armhf|amd64|i386|all)
|
||||
@@define ACNGDATENR 20[12][[:digit:]]-[[:digit:]]{2}-[[:digit:]]{2}-[[:digit:]]{4}\\.[[:digit:]]{2}
|
||||
@@define ACNGDTNR (@@{ACNGDATENR}|T-@@{ACNGDATENR}-F-@@{ACNGDATENR})
|
||||
|
||||
/@@{ACNGCACHE}$ d VarDir
|
||||
/@@{ACNGCACHE}/_actmp$ d VarDir
|
||||
/@@{ACNGCACHE}/_actmp/(combined\\.diff|patch\\.(base|result))$ f VarFile
|
||||
/@@{ACNGCACHE}/_(exfail_cnt|expending_(damaged|dat))$ f VarFile
|
||||
/@@{ACNGCACHE}/_xstore/qstats/[a-z]$ d VarDir
|
||||
!/@@{ACNGCACHE}/_xstore/qstats/([a-z]/)?156[0-9]{7}\\.[0-9]{5,6}$ l
|
||||
/@@{ACNGCACHE}/_xstore/rsnap/@@{ACNGDISTS}(/@@{ACNGMNC}/binary-@@{ACNGARCHS})?$ d VarDir
|
||||
!/@@{ACNGCACHE}/_xstore/rsnap/@@{ACNGDISTS}(/@@{ACNGMNC}/binary-@@{ACNGARCHS})?/[[:digit:]]{22,25}$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/(In)?Release(\\.gpg)?(\\.head)?$ f VarFile
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Release(\\.head)?$ f VarFile
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}(/by-hash)?$ d VarDir-n
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/by-hash/SHA256$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources(\\.xz)?(\\.head)?$ f VarFile
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(source|i18n|(Contents|binary)-@@{ACNGARCHS}\\.diff)$ d VarDir
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(Contents-@@{ACNGARCHS}\\.gz)(\\.head)?$ f VarFile
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(debian-installer/)?(binary-@@{ACNGARCHS})/(Packages(\\.(bz2|xz))?)(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de|en)\\.diff$ d VarDir
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/(Contents-@@{ACNGARCHS}|Sources\\.diff)$ d VarDir
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de(_DE)?|en)\\.(bz2|xz)(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(de|en)(\\.diff)?/Index(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/Index(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Packages(\\.diff)?/Index(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources\\.diff/Index(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff(/by-hash)?$ d VarDir-n
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/by-hash/SHA256$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/Contents-@@{ACNGARCHS}\\.diff/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}(/Packages\\.diff)?(/by-hash)?$ d VarDir-n
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}(/Packages\\.diff)?/by-hash/SHA256$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/Packages\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/binary-@@{ACNGARCHS}/(Packages\\.diff/)?by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?(/by-hash)?$ d VarDir-n
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?/by-hash/SHA256$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n/Translation-(en)\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/i18n(/Translation-(en)\\.diff)?/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f
|
||||
/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?(/by-hash)?$ d VarDir-n
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?/by-hash/SHA256$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source/Sources\\.diff/@@{ACNGDTNR}\\.gz(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDISTS}/@@{ACNGMNC}/source(/Sources\\.diff)?/by-hash/SHA256/[[:xdigit:]]{64}(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}(/(lib)?[a-z](/[-a-z0-9+\\.]+)?)?$ d
|
||||
!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}/(lib)?[a-z]/[-+[:alnum:]\\.]+/[-+[:alnum:]\\.]+_[-+~[:alnum:]\\.]+_@@{ACNGARCHS}\\.deb(\\.head)?$ f
|
||||
!/@@{ACNGCACHE}/@@{ACNGDEB}/pool(/updates)?/@@{ACNGMNC}/(lib)?[a-z]/[-+[:alnum:]\\.]+/[-+[:alnum:]\\.]+_[-+~[:alnum:]\\.]+\\.(dsc|(debian|orig)\\.tar\\.(gz|xz))(\\.asc)?(\\.head)?$ f
|
||||
|
||||
@@define LOGDIR var/log/apt-cacher-ng
|
||||
/@@{LOGDIR}$ d VarDir
|
||||
!/@@{LOGDIR}/maint_[[:digit:]]+\\.log\\.html$ f
|
||||
/@@{LOGDIR}/apt-cacher\\.(log|err)$ f Log
|
||||
!/@@{LOGDIR}/apt-cacher\\.(log|err)-@@{YEAR4D}[[:digit:]]{4}$ f
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
!/var/cache/apt-listbugs/%2Findices%2Findex.db-(critical|grave|serious)\\.gz$ f
|
||||
/var/cache/apt-listbugs$ d VarDir
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/apt/listchanges\\.db$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/apt-show-versions/(files|ipackages|apackages)$ f VarFile
|
||||
/var/cache/apt-show-versions$ d VarDir
|
||||
@@ -1,13 +0,0 @@
|
||||
/var/log/aptitude$ d Log
|
||||
/var/log/aptitude\\.1\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/aptitude\\.[2-5]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/aptitude\\.6\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/backups/aptitude\\.pkgstates\\.0$ f LowLog
|
||||
/var/backups/aptitude\\.pkgstates\\.1\\.gz$ f LoSerMemberLog
|
||||
/var/backups/aptitude\\.pkgstates\\.[2345]\\.gz$ f SerMemberLog
|
||||
/var/backups/aptitude\\.pkgstates\\.6\\.gz$ f HiSerMemberLog
|
||||
/var/lib/aptitude/pkgstates(\\.old)?$ f VarFile
|
||||
/var/lib/aptitude$ d VarDir
|
||||
!/@@{RUNLOCK}/aptitude$ f
|
||||
/root/\\.(aptitude|debtags)$ d VarDir
|
||||
/root/\\.aptitude/config$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/spool/cron/at(spool|jobs)$ d VarDir
|
||||
/@@{RUN}/atd\\.pid$ f VarFile
|
||||
@@ -1,10 +0,0 @@
|
||||
/var/log/atop$ d VarDirInode
|
||||
!/var/log/atop/(atop_@@{YEAR4D}[[:digit:]]{4}|daily\\.log)$ f
|
||||
/var/log/atop/dummy_(after|before)$ f VarFile
|
||||
/@@{RUN}/atop$ d VarDir
|
||||
/@@{RUN}/atop/atop\\.acct$ f VarFile
|
||||
/@@{RUN}/pacct_shadow\\.d$ d VarDirInode
|
||||
!/@@{RUN}/pacct_shadow\\.d/[0-9]{10}\\.paf$ f
|
||||
/@@{RUN}/pacct_shadow\\.d/current$ f VarFile
|
||||
/@@{RUN}/pacct_source$ f VarFile
|
||||
/@@{RUN}/atop(acctd)?\\.pid$ f VarFile
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/avahi-daemon$ d VarDirInode
|
||||
/@@{RUN}/avahi-daemon/pid$ f VarFile
|
||||
!/@@{RUN}/avahi-daemon/socket$ s
|
||||
@@ -1,18 +0,0 @@
|
||||
@@ifdef BINDCHROOT
|
||||
/@@{BINDCHROOT}/dev/log$ f LowLog
|
||||
/@@{BINDCHROOT}/dev$ d VarDir
|
||||
@@endif
|
||||
/@@{BINDCHROOT}@@{RUN}/named/(session\\.key|named\\.pid)$ f VarFile
|
||||
/@@{BINDCHROOT}@@{RUN}/named$ d VarDirInode
|
||||
/@@{BINDCHROOT}var/cache/bind$ d VarDir
|
||||
/@@{BINDCHROOT}var/cache/bind/[-[:alnum:].]+$ f VarFile
|
||||
|
||||
@@ifdef BIND_SLAVE_DIRS
|
||||
@@ifdef BIND_SLAVE_PATHS
|
||||
/@@{BINDCHROOT}var/cache/bind/slave/@@{BIND_SLAVE_DIRS}$ d VarDir
|
||||
/@@{BINDCHROOT}var/cache/bind/slave/@@{BIND_SLAVE_PATHS}$ f VarFile
|
||||
@@endif
|
||||
@@endif
|
||||
|
||||
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
/var/lib/boinc-client$ d VarDir
|
||||
/var/lib/boinc-client/(get_current_version|global_prefs|daily_xfer_history|client_state(_prev)?)\\.xml$ f VarFile
|
||||
/var/lib/boinc-client/(time_stats_log|do_fp)$ f VarFile
|
||||
/var/lib/boinc-client/lookup_website\\.html$ f VarFile
|
||||
/var/lib/boinc-client/std(err|out)dae\\.txt$ f VarFile
|
||||
|
||||
# Add rules for your projects. Example: seti@home
|
||||
#/var/lib/boinc-client/job_log_setiathome\\.berkeley\\.edu\\.txt$ f VarFile
|
||||
#/var/lib/boinc-client/master_setiathome\\.berkeley\\.edu\\.xml$ f VarFile
|
||||
#/var/lib/boinc-client/projects/setiathome\\.berkeley\\.edu$ d VarDir
|
||||
#/var/lib/boinc-client/projects/setiathome\\.berkeley\\.edu/\\.*$ f VarFile+ANF+ARF
|
||||
#/var/lib/boinc-client/sched_reply_setiathome\\.berkeley\\.edu\\.xml$ f VarFile
|
||||
#/var/lib/boinc-client/sched_request_setiathome\\.berkeley\\.edu\\.xml$ f VarFile
|
||||
#/var/lib/boinc-client/slots/[[:digit:]]+$ d VarDir
|
||||
#/var/lib/boinc-client/slots/[[:digit:]]+/\\.*$ f VarFile+ANF+ARF
|
||||
#/var/lib/boinc-client/statistics_setiathome\\.berkeley\\.edu\\.xml$ f VarFile
|
||||
@@ -1,12 +0,0 @@
|
||||
@@define BORGCACHE root/\\.cache/borg
|
||||
@@define BORGCONFIG root/\\.config/borg
|
||||
/@@{BORGCACHE}(/(keys|security))?$ d VarDir
|
||||
!/@@{BORGCACHE}/[[:xdigit:]]{64}$ d
|
||||
!/@@{BORGCACHE}/[[:xdigit:]]{64}/(README|chunks|config|files|lock\\.roster)$ f
|
||||
!/@@{BORGCACHE}/[[:xdigit:]]{64}/(chunks\\.archive\\.d|lock\\.exclusive|txn\\.active)$ d
|
||||
!/@@{BORGCACHE}/[[:xdigit:]]{64}/lock\\.exclusive/@@{{HOSTNAME}}\\.[[:digit:]]+\\-0$ f
|
||||
!/@@{BORGCACHE}/[[:xdigit:]]{64}/txn.active/(chunks|config|files)$ f
|
||||
#!/@@{BORGCACHE}/keys/<backhost>--<backpath>_@@{HOSTNAME}\\.[[:digit:]]$ f
|
||||
!/@@{BORGCONFIG}/security/[[:xdigit:]]{64}$ d
|
||||
!/@@{BORGCONFIG}/security/[[:xdigit:]]{64}/(key-type|location|manifest-timestamp|nonce|tam_required)$ f
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/log/btmp$ f Log
|
||||
/var/log/btmp\\.1$ f LowLog
|
||||
@@ -1,19 +0,0 @@
|
||||
# replace CEREALSESS with a regexp matching your session names
|
||||
#@@define CEREALSESS (session|session)
|
||||
#@@define CEREALDEVICES (ttyS0)
|
||||
@@ifdef CEREALSESS
|
||||
!/@@{RUN}/screen/S-@@{CEREALSESS}$ d
|
||||
!/@@{RUN}/screen/S-@@{CEREALSESS}/[[:digit:]]+\\.cereal:@@{CEREALSESS}$ s
|
||||
/var/lib/cereal/sessions/@@{CEREALSESS}/socket$ p VarFile
|
||||
/var/lib/cereal/sessions/@@{CEREALSESS}(/log/main)?$ d VarDir
|
||||
/var/lib/cereal/sessions/@@{CEREALSESS}/log/main/current$ f VarFile
|
||||
!/var/lib/cereal/sessions/@@{CEREALSESS}/log/main/@40000000[[:xdigit:]]{16}\\.s$ f
|
||||
/var/lib/cereal/sessions/@@{CEREALSESS}/(log/)?supervise$ d VarDir
|
||||
/var/lib/cereal/sessions/@@{CEREALSESS}/(log/)?supervise/(control|pid|stat(us)?)$ f VarFile
|
||||
@@endif
|
||||
|
||||
@@ifdef CEREALDEVICES
|
||||
/@@{RUN}/lock/LCK\\.\\.@@{CEREALDEVICES}$ f VarFile
|
||||
!/dev/@@{CEREALDEVICES}$ l
|
||||
@@endif
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/log/setuid/setuid.changes$ f Log
|
||||
/var/log/setuid/setuid.changes\\.1$ f LoSerMemberLog
|
||||
/var/log/setuid/setuid.changes\\.[2-9]$ f SerMemberLog
|
||||
/var/log/setuid/setuid.changes\\.10$ f HiSerMemberLog
|
||||
/var/log/setuid/setuid.(today|yesterday)$ f VarFile
|
||||
/var/log/setuid$ d VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/chrony$ d VarDir
|
||||
/var/lib/chrony/chrony\\.drift$ f VarFile
|
||||
@@ -1,8 +0,0 @@
|
||||
/var/log/clamav/clamav\\.log$ f Log
|
||||
/var/log/clamav/clamav\\.log\\.1$ f LowLog
|
||||
/var/log/clamav/clamav\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/clamav/clamav\\.log\\.([3-9]|1[0-1])\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/clamav/clamav\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/@@{RUN}/clamav/clamd\\.(ctl|pid)$ f VarFile
|
||||
/var/log/clamav$ d VarDir
|
||||
/@@{RUN}/clamav$ d VarDirInode
|
||||
@@ -1,12 +0,0 @@
|
||||
/var/lib/clamav$ d VarDir
|
||||
/var/lib/clamav/(scam|junk)\\.ndb$ f VarFile
|
||||
/var/log/clamav/freshclam\\.log$ f Log
|
||||
/var/log/clamav/freshclam\\.log\\.1$ f LowLog
|
||||
/var/log/clamav/freshclam\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/clamav/freshclam\\.log\\.([3-9]|1[0-1])\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/clamav/freshclam\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/lib/clamav/(safebrowsing|bytecode)\\.cld$ f VarFile
|
||||
/var/lib/clamav/daily\\.inc/daily\\.(info|[nmhp]db)$ f VarFile
|
||||
/var/lib/clamav/daily\\.cld$ f VarFile
|
||||
/var/lib/clamav/mirrors.dat$ f VarFile
|
||||
/@@{RUN}/clamav/freshclam\\.pid$ f VarFile
|
||||
@@ -1,15 +0,0 @@
|
||||
!/var/lib/clamav-unofficial-sigs/pid/clamav-unofficial-sigs\\.pid$ f
|
||||
/var/lib/clamav$ d VarDir
|
||||
/var/lib/clamav/\\.wget-hsts$ f VarFile
|
||||
/var/lib/clamav/(blurl|jurlbl|phish(tank)?|porcupine|winnow_malware_links)\\.ndb$ f VarFile
|
||||
/var/lib/clamav/(foxhole_filename)\\.cdb$ f VarFile
|
||||
/var/lib/clamav/(porcupine)\\.hsb$ f VarFile
|
||||
/var/lib/clamav/(safebrowsing)\\.cld$ f VarFile
|
||||
/var/lib/clamav-unofficial-sigs(/(configs|dbs-(add|lmd|mbl|si|ss|yara)|gpg-key|pid))?$ d VarDir
|
||||
/var/lib/clamav-unofficial-sigs/configs/(ss-include-dbs|current-dbs|last-(linuxmalwaredetect|ss|yararulesproject)-update|purge)\\.txt$ f VarFile
|
||||
/var/lib/clamav-unofficial-sigs/dbs-lmd/rfxn\\.[hn]db$ f VarFile
|
||||
/var/lib/clamav-unofficial-sigs/dbs-ss/(blurl|bofhland_(cracked|malware|phishing)_URL|bofhland_malware_attach|junk|jurlbl|phish(tank)?|porcupine|rogue|winnow(\\.attachments|_bad_cw|_extended_malware|_malware(_links)?)|scam|spamimg|foxhole_filename)\\.(ndb|hdb|hsb|cdb|yara)(\\.sig)?$ f VarFile
|
||||
/var/lib/clamav-unofficial-sigs/dbs-ss/sigwhitelist\\.ign2(\\.sig)?$ f VarFile
|
||||
/var/lib/clamav-unofficial-sigs/dbs-yara/(EK_(Angler|Blackhole|BleedingLife|Crimepack|Eleonore|Fragus|Phoenix|Sakura|ZeroAcces|Zerox88|Zeus)|antidebug_antivm)\\.(yar)$ f VarFile
|
||||
/var/lib/clamav/(rogue|winnow_(extended_)?malware|bofhland_(malware|cracked|phishing)_URL|spaming|rfxn)\\.(ndb|hdb)$ f VarFile
|
||||
/var/log/clamav/clamav-unofficial-sigs\\.log$ f Log
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/console-log(/Debian-console-log)?$ d VarDirInode
|
||||
/@@{RUN}/console-log/Debian-console-log/(8-_-_var_-_log_-_exim4_-_mainlog|9-_-_var_-_log_-_syslog_-_syslog)$ f VarFile
|
||||
/@@{RUN}/console-log/Debian-console-log/(8-_-_var_-_log_-_exim4_-_mai|9-_-_var_-_log_-_syslog_-_sy).clientpid$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/console-setup$ d VarDirInode
|
||||
/@@{RUN}/console-setup/(boot_completed|font-loaded)$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/courier/authdaemon/(pid|pid\\.lock|socket)$ f VarFile
|
||||
/@@{RUN}/courier(/authdaemon)?$ d VarDirInode
|
||||
@@ -1 +0,0 @@
|
||||
/var/cache/cracklib/cracklib_dict\\.(hwm|pw(d|i))$ f VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/crond\\.(pid|reboot)$ f VarFile
|
||||
@@ -1,16 +0,0 @@
|
||||
@@ifndef CRON_APT_EXTRACONFIGS
|
||||
@@define CRON_APT_EXTRACONFIGS
|
||||
@@endif
|
||||
|
||||
/var/lib/cron-apt/_-_etc_-_cron-apt_-_config(@@{CRON_APT_EXTRACONFIGS})?/mailchanges/(0-update-|3-download-)[[:xdigit:]]{32}$ f VarFile
|
||||
!/var/lib/cron-apt/lockfile$ f
|
||||
/var/lib/cron-apt$ d VarDir
|
||||
!/tmp/cron-apt\\.[[:alnum:]]{6}$ d
|
||||
!/tmp/cron-apt\\.[[:alnum:]]{6}/((action|run)(error|log|mail|syslog)|initlog|temp)$ f
|
||||
/var/log/cron-apt/log$ f FreqRotLog
|
||||
/var/log/cron-apt/log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/cron-apt/log\\.[234]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/cron-apt/log\\.5\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/log/cron-apt$ d VarDir
|
||||
!/var/log/cron-apt/lastfullmessage$ f
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
@@define CUPS_LOGS (access|error|page|cups-pdf)
|
||||
|
||||
/var/(cache|spool)/cups$ d VarDir
|
||||
/var/cache/cups/job\\.cache(\\.O)?$ f VarFile
|
||||
/var/cache/cups/@@{IP4ADDRESS}\\.snmp$ f VarTime
|
||||
|
||||
!/var/spool/cups/c[[:digit:]]{5}$ f
|
||||
!/var/spool/cups/d[[:digit:]]{5}-001$ f
|
||||
!/var/spool/cups/tmp/cups-dbus-notifier-lockfile$ f
|
||||
/var/spool/cups(/tmp)?$ d VarDir
|
||||
|
||||
/@@{RUN}/cups/certs/0$ f VarFile
|
||||
/@@{RUN}/cups/printcap$ f VarFile
|
||||
/@@{RUN}/cups/cups\\.sock$ s VarFile
|
||||
/@@{RUN}/cups(/certs)?$ d VarDirInode
|
||||
|
||||
/etc/cups$ d VarDir
|
||||
/etc/cups/(printers|subscriptions)\\.conf(\\.O)?$ f VarFile
|
||||
|
||||
/var/log/cups/@@{CUPS_LOGS}_log$ f Log
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\\.1\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\\.[2-6]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\\.7\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/log/cups$ d VarDir
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
!/@@{RUN}/dbus/system_bus_socket$ s
|
||||
/@@{RUN}/dbus$ d VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/dcc/map$ f VarFile
|
||||
/var/lib/dcc$ d VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/ddclient/ddclient\\.cache$ f VarFile
|
||||
/@@{RUN}/ddclient\\.pid$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/debconf/(config|templates)\\.dat(-old)?$ f VarFile
|
||||
/var/cache/debconf$ d VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/debsecan/history$ f VarFile
|
||||
/var/lib/debsecan$ d VarDir
|
||||
@@ -1,17 +0,0 @@
|
||||
# this rule becomes active one DEHYDDOMAINS is defined. set it to a regexp matching
|
||||
# your domains using dehydrated
|
||||
|
||||
@@ifdef DEHYDDOMAINS
|
||||
@@define DEHYDRE (cert|chain|combined|fullchain|privkey)
|
||||
/var/lib/dehydrated$ d VarDir
|
||||
/var/lib/dehydrated/accounts/[[:alnum:]]{63}$ d VarDir
|
||||
/var/lib/dehydrated/accounts/[[:alnum:]]{63}/account_id\\.json$ f VarFile
|
||||
/var/lib/dehydrated/chains$ d VarDir
|
||||
/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}$ d VarDir
|
||||
!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/@@{DEHYDRE}-[[:digit:]]+\\.pem$ f
|
||||
!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/@@{DEHYDRE}\\.pem$ l
|
||||
!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/combined\\.pem$ f
|
||||
!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/(cert)-[[:digit:]]+\\.csr$ f
|
||||
!/var/lib/dehydrated/certs/@@{DEHYDDOMAINS}/(cert)\\.csr$ l
|
||||
/var/lib/dehydrated(/acme-challenges)?$ d VarDir
|
||||
@@endif
|
||||
@@ -1,25 +0,0 @@
|
||||
# this is a preliminary paranoid rule from a local installation. Feel free to submit
|
||||
# patches that may make the rule suitable for your installation
|
||||
|
||||
@@define MAJMIN [[:digit:]]+:[[:digit:]]+
|
||||
/dev$ d VarDirInode
|
||||
/dev/(block|char|mapper|shm)$ d VarDirInode-s
|
||||
!/dev/(block|char)/@@{MAJMIN}$ l
|
||||
/dev/bus/usb/00[1234]$ d VarDirInode
|
||||
!/dev/bus/usb/00[1234]/0[01][[:digit:]]$ c
|
||||
/dev/disk/by-id$ d VarDirInode
|
||||
!/dev/disk/by-id/(dm-name-[-[:alnum:]_]+)$ l
|
||||
!/dev/disk/by-id/(dm-uuid-[-[:alnum:]]+)$ l
|
||||
!/dev/disk/by-label/[-[:lower:]]+$ l
|
||||
!/dev/disk/by-uuid/[[:xdigit:]]{8}-([[:xdigit:]]{4}-){3}[[:xdigit:]]{12}$ l
|
||||
!/dev/dm-[[:digit:]]+$ b
|
||||
!/dev/mapper/[-[:alnum:]_]+$ l
|
||||
!/dev/serial/by-id/usb-[-[:alnum:]_\\.]+-port0$ l
|
||||
!/dev/serial/by-path/pci-0000:0000:12\\.0-usb-[[:digit:]:\\.]+-port0$ l
|
||||
!/dev/serial/by-path/platform-1c1[4c]000\\.usb-usb-[-[:digit:]:\\.]+port0$ l
|
||||
!/dev/shm/spice\\.[[:digit:]]+$ f
|
||||
!/dev/tap[[:digit:]]+ c
|
||||
|
||||
!/dev/@@{HOSTNAME}/[-[:lower:][:digit:]_]+$ l
|
||||
!/dev/@@{HOSTNAME}_r/[-[:lower:][:digit:]_]+$ l
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/dlocate/(dpkg-list|dlocate(db)?(\\.old|\\.stamps)?)$ f VarFile
|
||||
/var/lib/dlocate$ d VarDir
|
||||
@@ -1 +0,0 @@
|
||||
!/@@{RUN}/dmeventd-(client|server)$ p
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/lib/dokuwiki/data/cache/[0-9a-f]/[0-9a-f]{32}\\.(feed|i|xhtml)$ f VarFile
|
||||
/var/lib/dokuwiki/data/(changes\\.log|(index|word)\\.idx)$ f VarFile
|
||||
/var/lib/dokuwiki/data/meta/([a-z]+\\.indexed|_dokuwiki\\.changes)$ f VarFile
|
||||
/var/lib/dokuwiki/data/meta$ d VarDir
|
||||
/var/lib/dokuwiki/data/pages/[a-z]+\\.txt$ f VarFile
|
||||
/var/lib/dokuwiki/data/(attic|cache|locks|pages)$ d VarDir
|
||||
@@ -1,11 +0,0 @@
|
||||
/var/lib/dovecot$ d VarDir
|
||||
/var/lib/dovecot/(instances|mounts|ssl-parameters\\.dat)$ f VarFile
|
||||
|
||||
/@@{RUN}/dovecot(/(login|empty))?$ d VarDirInode
|
||||
/@@{RUN}/dovecot/(auth-token-secret\.dat|auth-worker\\.[0-9]{4}|master\\.pid)$ f VarFile
|
||||
/@@{RUN}/dovecot/login/(default|dns-client|imap|ipc-proxy|login|pop3|ssl-params)$ f VarFile
|
||||
/@@{RUN}/dovecot/auth-worker\\.[0-9]{4}$ f VarFile
|
||||
/@@{RUN}/dovecot/anvil(-auth-penalty)?$ f VarFile
|
||||
/@@{RUN}/dovecot/auth-(client|login|master|userdb|worker)$ f VarFile
|
||||
/@@{RUN}/dovecot/(config|dict|director-(admin|userdb)|dns-client|indexer(-worker)?|ipc|log-errors|mounts|replicat(oon-notify(-fifo)?|or)|stats(-mail)?)$ f VarFile
|
||||
/@@{RUN}/dovecot/dovecot.conf$ l VarInode
|
||||
@@ -1,17 +0,0 @@
|
||||
@@define DPKG_LOGS (alternatives|dpkg)\\.log
|
||||
@@define DPKG_BACKUPS (alternatives\\.tar|dpkg\\.(status|diversions|statoverride|arch))
|
||||
/var/lib/dpkg/(available|status)(-old)?$ f VarFile
|
||||
/var/lib/dpkg/status\\.yesterday(\\.[0-9]*)?(\\.gz)?$ f VarFile
|
||||
/var/lib/dpkg/triggers/Lock$ f VarFile
|
||||
/var/lib/dpkg(/(info|updates))?$ d VarDir
|
||||
/var/lib/dpkg/lock$ f VarFile
|
||||
/var/log/@@{DPKG_LOGS}$ f Log
|
||||
/var/log/@@{DPKG_LOGS}\\.1$ f LowLog
|
||||
/var/log/@@{DPKG_LOGS}\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/@@{DPKG_LOGS}\\.([3-9]|1[01])\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/@@{DPKG_LOGS}\\.12\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/backups/@@{DPKG_BACKUPS}\\.0$ f LowLog
|
||||
/var/backups/@@{DPKG_BACKUPS}\\.1\\.gz$ f LoSerMemberLog
|
||||
/var/backups/@@{DPKG_BACKUPS}\\.[2345]\\.gz$ f SerMemberLog
|
||||
/var/backups/@@{DPKG_BACKUPS}\\.6\\.gz$ f HiSerMemberLog
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/systemd/timers/stamp-e2scrub_all\\.timer$ f VarFile
|
||||
@@ -1,5 +0,0 @@
|
||||
/etc/\\.etckeeper$ f VarFile
|
||||
/etc/\\.git(/refs/heads)?$ d VarDir
|
||||
/etc/\\.git/(index|logs/HEAD|(logs/)?refs/heads/master|COMMIT_EDITMSG)$ f VarFile
|
||||
/etc/.git/objects/[[:xdigit:]]{2}$ d VarDir
|
||||
!/etc/.git/objects/[[:xdigit:]]{2}/[[:xdigit:]]{38}$ f
|
||||
@@ -1,12 +0,0 @@
|
||||
/var/spool/exim4/gnutls-params$ f VarFile
|
||||
/var/spool/exim4/db/(wait-remote_smtp(_smarthost)?|retry|callout)$ f VarFile
|
||||
!/var/spool/exim4/input/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}-[DHJ]$ f
|
||||
!/var/spool/exim4/msglog/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}$ f
|
||||
!/var/spool/exim4/gnutls-params$ f
|
||||
!/var/spool/exim4/\\.rnd$ f
|
||||
/var/spool/exim4(/(input|msglog|scan))?$ d VarDir
|
||||
/var/lib/exim4/config\\.autogenerated$ f VarFile
|
||||
/@@{RUN}/exim4/exim\\.pid$ f VarFile
|
||||
/var/lib/exim4$ d VarDir
|
||||
/@@{RUN}/exim4$ d VarDirInode
|
||||
/var/lib/systemd/timers/stamp-exim4-base\\.timer$ f VarFile
|
||||
@@ -1,5 +0,0 @@
|
||||
@@define EXIM_MSGID [[:lower:][:digit:]]{6}-[[:alnum:]]{6}-[[:upper:][:digit:]]{2}
|
||||
/var/spool/exim4/scan$ d VarDir
|
||||
!/var/spool/exim4/scan/@@{EXIM_MSGID}$ d
|
||||
!/var/spool/exim4/scan/@@{EXIM_MSGID}/@@{EXIM_MSGID}(-00000|\.eml)$ f
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
# if your host frequently produces paniclog entries (this happens if
|
||||
# spam or virus scanners are in use), set
|
||||
# @@define EXIM4_LOGS (main|reject|panic)
|
||||
@@define EXIM4_LOGS (main|reject)
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log$ f Log
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\\.1$ f LowLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\\.[3-9]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\\.10\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/log/exim4$ d VarDir
|
||||
@@ -1,7 +0,0 @@
|
||||
/var/log/fail2ban\\.log$ f Log
|
||||
/var/log/fail2ban\\.log\\.1$ f LowLog
|
||||
/var/log/fail2ban\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/fail2ban\\.log\\.3\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/fail2ban\\.log\\.4\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/@@{RUN}/fail2ban/fail2ban\\.(sock|pid)$ f VarFile
|
||||
/@@{RUN}/fail2ban$ d VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/etc/fake-hwclock\\.data$ f VarFile
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/fcron\\.(pid|fifo)$ f VarFile
|
||||
/var/spool/fcron/systab$ f VarFile
|
||||
/var/spool/fcron$ d VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/locate/locatedb$ f VarFile
|
||||
/var/cache/locate$ d VarDir
|
||||
@@ -1 +0,0 @@
|
||||
!/@@{RUN}/user/[0-9]+/gnupg(/S.(dirmngr|gpg-agent(\\.(browser|extra|ssh))?|scdaemon))?$ s
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/hald/hald\\.pid$ f VarFile
|
||||
/@@{RUN}/hald$ d VarDirInode
|
||||
@@ -1,5 +0,0 @@
|
||||
/var/log/haproxy\\.log$ f Log
|
||||
/var/log/haproxy\\.log\\.1$ f LowLog
|
||||
/var/log/haproxy\\.log\\.2.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/haproxy\\.log\\.[345678].@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/haproxy\\.log\\.9.@@{LOGEXT}$ f HiSerMemberLog
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/hdapsd\\.pid$ f VarFile
|
||||
@@ -1,21 +0,0 @@
|
||||
@@define VCI var/cache/icinga2
|
||||
@@define VLII var/lib/icinga2
|
||||
@@define VLOI var/log/icinga2
|
||||
|
||||
/@@{VCI}$ d VarDir
|
||||
/@@{VCI}/(objects\\.cache|status\\.dat)$ f VarFile
|
||||
/@@{VLII}$ d VarDir
|
||||
/@@{VLII}/(icinga2\\.state|modified-attributes\\.conf)$ f VarFile
|
||||
/@@{VLII}/api/packages/_api/[[:xdigit:]]{8}-[[:xdigit:]]{4]-[[:xdigit:]]{4}-[[:xdigit:]]{4}-[[:xdigit:]]{12}/conf.d/(comments|downtimes)$ d VarDir
|
||||
/@@{VLOI}/compat(/archives)?$ d VarDir
|
||||
/@@{VLOI}/compat/icinga\\.log$ Log
|
||||
!/@@{VLOI}/compat/archives/icinga-[[:digit:]]{2}-[[:digit:]]{2}-[[:digit:]]{4}-[[:digit:]]{2}\\.log$ f
|
||||
/@@{VLOI}/default/access\\.log$ Log
|
||||
/@@{VLOI}$ d VarDir
|
||||
/@@{VLOI}/icinga2\\.log$ Log
|
||||
/@@{VLOI}/icinga2\\.log\\.1$ f LowLog
|
||||
/@@{VLOI}/icinga2\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/@@{VLOI}/icinga2\\.log\\.[3456]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/@@{VLOI}/icinga2\\.log\\.7\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
!/tmp/FileCache_icingaweb$ d
|
||||
!/tmp/FileCache_icingaweb/icinga-[0-9a-f]{8}-[0-9a-f]{8}-[0-9a-f]{8}\\.min\\.js$ f
|
||||
@@ -1,2 +0,0 @@
|
||||
@@define INTERFACES eth0
|
||||
/@@{RUN}/ifplugd\\.@@{INTERFACES}\\.pid$ f VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/network/ifstate$ f VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/inetd\\.pid$ f VarFile
|
||||
@@ -1,6 +0,0 @@
|
||||
# this can be improved by giving a list of disk and dm device nodes
|
||||
/@@{RUN}/(fsck|initramfs)$ d VarDirInode
|
||||
/@@{RUN}/initramfs/fsck(\\.log|-(root|usr))$ f VarFile
|
||||
/@@{RUN}/fsck/[vs]d[abc]$ f VarFile
|
||||
/@@{RUN}/dm-[[:digit:]]+\\.lock$ f VarFile
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
/var/lib/urandom/random-seed$ f VarFile
|
||||
/var/lib/(urandom|initscripts)$ d VarDir
|
||||
/var/log/dmesg$ f Log
|
||||
/var/log/dmesg\\.0$ f LowLog
|
||||
/var/log/dmesg\\.1\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/dmesg\\.[23]\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/dmesg\\.4\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/var/log/fsck/check(root|fs)$ f VarFile
|
||||
/@@{RUN}/motd$ f VarFile
|
||||
@@ -1,25 +0,0 @@
|
||||
@@define NEWSLOGS (errlog|expire\\.log|news(\\.crit|\\.err|\\.notice)?|rc\\.news|sendsys\\.log|unwanted\\.log|inn_status\\.html|innfeed\\.status|expire\\.(lastlowmark|list))
|
||||
@@define OLDLOGS (active|errlog|expire\\.log|news(\\.crit|\\.err|\\.notice)?|sendsys\\.log|unwanted\\.log)
|
||||
|
||||
!/var/lib/news/history(\\.(dir|hash|index))?$ f
|
||||
/var/lib/news/(active(\\.old)?|newsgroups|\\.news\\.daily)$ f VarFile
|
||||
|
||||
!/var/spool/news/articles(/[-a-z0-9+]+)+$ f
|
||||
/var/spool/news/overview/group\\.index$ f VarFile
|
||||
!/var/spool/news/overview(/[a-z0-9])+/[-\\.a-z0-9+]+\\.(IDX|DAT)$ f
|
||||
/var/spool/news/overview(/[a-z0-9])+$ d VarDir
|
||||
!/var/spool/news/articles/control/(newgroup|checkgroups|rmgroup)/[0-9]*$ f
|
||||
/var/spool/news/innfeed/@@{INN2_INNFEED_OUTFEEDS}\\.(lock|output|input)$ f VarFile
|
||||
!/var/spool/news/innfeed/innfeed-dropped\\.A[0-9]{6}$ f
|
||||
/var/spool/news/innfeed$ d VarDir
|
||||
/var/spool/news/incoming(/tmp)?$ d VarDir
|
||||
|
||||
/@@{RUN}/news/(control|(innd|innfeed|innwatch)\\.pid|innwatch\\.time|LOCK\\.innwatch|nntpin)$ f VarFile
|
||||
/@@{RUN}/news$ d VarDirInode
|
||||
|
||||
/var/log/news/path/inpaths\\.[0-9]{10}$ f VarFile+ANF
|
||||
/var/log/news/@@{NEWSLOGS}$ f VarFile
|
||||
/var/log/news/OLD/(expire\\.log\\.0|unwanted\\.log)$ f VarFile
|
||||
/var/log/news/OLD/@@{OLDLOGS}\\.1\\.gz$ f LoSerMemberLog
|
||||
/var/log/news/OLD/@@{OLDLOGS}\\.[0-9]+\\.gz$ f SerMemberLog
|
||||
/var/log/news(/(path|OLD))?$ d VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/ippl/ippl.(pid|conf)$ f VarFile
|
||||
/@@{RUN}/ippl$ d VarDirInode
|
||||
@@ -1,5 +0,0 @@
|
||||
# @@define ISCDHCLIENTIFACE eth0
|
||||
@@ifdef ISCDHCLIENTIFACE
|
||||
/@@{RUN}/dhclient\\.@@{ISCDHCLIENTIFACE}\\.pid$ f VarFile
|
||||
/var/lib/dhcp/dhclient\\.@@{ISCDHCLIENTIFACE}\\.leases$ f VarFile
|
||||
@@endif
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/dhcpd\\.pid$ f VarFile
|
||||
/var/lib/dhcp/dhcpd6?.leases~?$ f VarFile
|
||||
/var/lib/dhcp$ d VarDir
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/tmp/krb5kdc_rcache$ f VarFile
|
||||
/var/tmp/(nfs|host)_[0-9]+$ f VarFile
|
||||
/tmp/krb5cc_machine_[A-Z.]+$ f VarFile
|
||||
!/tmp/krb5cc_[0-9]+_[[:alnum:]]+$ f
|
||||
/var/lib/krb5kdc/principal$ f VarFile+s+b+i
|
||||
/var/lib/krb5kdc/principal\\.ok$ f VarTime
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/laptop-mode-tools/(state(-brightness-command)?|enabled|start-stop-undo-actions|nolm-mountopts)$ f VarFile
|
||||
/@@{RUN}/laptop-mode-tools$ d VarDirInode
|
||||
/@@{RUNLOCK}/lmt-(req|invoc)\\.lock$ f VarInode
|
||||
@@ -1 +0,0 @@
|
||||
/var/log/lastlog$ f Log
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/apache2/fcgid/sock$ d VarDir
|
||||
!/var/lib/apache2/fcgid/sock/[0-9]{5}\\.[0-9]$ s
|
||||
@@ -1,24 +0,0 @@
|
||||
@@ifndef LIBVIRT_QEMU_GUESTS
|
||||
@@define LIBVIRT_QEMU_GUESTS ()
|
||||
@@endif
|
||||
/var/lib/libvirt$ d VarDir
|
||||
/var/(lib|cache)/libvirt/qemu$ d VarDir-n
|
||||
/var/lib/libvirt/qemu/(channel(/target)?|dump|nvram|save|snapshot)$ d VarDir-n
|
||||
!/var/lib/libvirt/qemu(/channel/target)?/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}$ d
|
||||
!/var/lib/libvirt/qemu/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}/master-key\\.aes$ f
|
||||
!/var/lib/libvirt/qemu(/channel/target)?/domain-[[:digit:]]+-@@{LIBVIRT_QEMU_GUESTS}/(monitor\\.sock|org\\.qemu\\.guest_agent\\.0)$ s
|
||||
/var/log/libvirt$ d VarDir
|
||||
/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log$ f Log
|
||||
/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.1$ f LowLog
|
||||
/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.3\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.log\\.4\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
/@@{RUN}/(libvirtd|virtlogd)\\.pid$ f VarFile
|
||||
/@@{RUN}/libvirt(/(qemu|uml-guest))?$ d VarDirInode
|
||||
/@@{RUN}/libvirt/(hostdevmgr|lxc|network|storage)$ d VarDirInode
|
||||
/@@{RUN}/libvirt/network/nwfilter\\.leases$ f VarFile
|
||||
/@@{RUN}/libvirt/network/br[[:digit:]]{1,3}\\.xml$ f VarFile
|
||||
/@@{RUN}/libvirt/(libvirt-(admin-sock|sock(-ro)?)|virt(lock|log)d-sock)$ s VarFile
|
||||
!/@@{RUN}/libvirt/qemu/@@{LIBVIRT_QEMU_GUESTS}\\.(pid|xml)$ f
|
||||
/@@{RUNLOCK}/libvirt-guests$ f VarDirInode
|
||||
|
||||
@@ -1,10 +0,0 @@
|
||||
@@define LIGHTTP_LOGS (access|error|tls-access)
|
||||
/var/log/lighttpd$ d VarDir
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log$ f Log
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.1$ f LowLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.2\\.@@{LOGEXT}$ f LoSerMemberLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.([3-9]|10|11)\\.@@{LOGEXT}$ f SerMemberLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\\.log\\.12\\.@@{LOGEXT}$ f HiSerMemberLog
|
||||
|
||||
/@@{RUN}/lighttpd\\.pid$ f VarFile
|
||||
/@@{RUN}/lighttpd$ d VarDirInode
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/lldpd(/etc)?$ d VarDirInode
|
||||
/@@{RUN}/lldpd/etc/localtime$ f VarFile
|
||||
!/@@{RUN}/lldpd\\.socket$ s
|
||||
@@ -1,2 +0,0 @@
|
||||
/usr/lib/locale$ d VarDir
|
||||
/usr/lib/locale/locale-archive$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/lock/logcheck$ d VarDir
|
||||
/var/lib/logcheck/offset\\.[[:alnum:]\\.]+$ f VarFile
|
||||
@@ -1,4 +0,0 @@
|
||||
/var/lib/logrotate$ d VarDir
|
||||
/var/lib/logrotate/status$ f VarFile
|
||||
/var/lib/systemd/timers/stamp-logrotate\\.timer$ f VarFile
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/lpd\\.pid$ f VarFile
|
||||
/var/spool/lpd$ d VarDir
|
||||
/var/spool/lpd/lpd\\.lock$ f VarFile
|
||||
@@ -1,6 +0,0 @@
|
||||
/@@{RUNLOCK}/lvm$ d VarDirInode
|
||||
/@@{RUN}/lvm/(new)?hints$ f VarFile
|
||||
/@@{RUN}/lvm(/((lvs|pvs)_online|pvs_lookup))?$ d VarDirInode
|
||||
/@@{RUN}/lvm/pvs_online/[[:alnum:]]{32}$ f VarFile
|
||||
!/@@{RUN}/lvm/lvm(etad|polld)\\.socket$ s
|
||||
/@@{RUN}/lvmetad\\.pid$ f VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/mail/[a-z0-9]+$ f VarFile
|
||||
/var/mail$ d VarDir
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user