I compiled the AIDE package under Arch with the 'with-curl' option.
# Maintainer: AlphaJack <alphajack at tuta dot io>
# Contributor: John Doe <[email protected]>
# Contributor: Lukas Jirkovsky <[email protected]>
# Contributor: Thomas S Hatch <[email protected]>
# Contributor: Daniel J Griffiths <[email protected]>
# Contributor: Tom Newsom <[email protected]>
pkgname="aide"
pkgver=0.18.8
pkgrel=1
pkgdesc="A file integrity checker and intrusion detection program"
arch=("x86_64" "armv7h" "aarch64")
url="https://aide.github.io/"
license=("GPL")
depends=("acl"
"e2fsprogs"
"libelf"
"mhash"
"pcre")
source=("https://github.com/aide/aide/releases/download/v$pkgver/aide-$pkgver.tar.gz"{,.asc} \
"aide.conf"
"aidecheck.service"
"aidecheck.timer")
b2sums=('a3b7efca89d0be99614e423a983fb0a3413f1cbdbc370b54f755e6dae8bb7f5612921ba998fd6db9248ae739
'SKIP'
'2e16baf306dcbe5d5207685391bb3e77b80a8caafaeafee3094228ee19671092afc042762523663a1d515534
'fcae2514bffcfe8c2110c8b82d857f39de8c95e0d7d2788bb4945243c127c9566871606b9e4bca39034b624c
'af16bbf1d69226d445820ba1e7beaba8142a19eb3120f5b58db048083d94ec22f857a28dfe403bd885aafe31
validpgpkeys=("2BBBD30FAAB29B3253BCFBA6F6947DAB68E7B931") # Hannes von Haugwitz <hannes@vonhaugwi
backup=("etc/aide.conf")
install="aide.install"
build(){
cd "$pkgname-$pkgver"
./configure \
--prefix="/usr" \
--sysconfdir="/etc" \
--with-posix-acl \
--with-xattr \
--with-zlib \
--with-e2fsattrs \
--with-curl \
--disable-static
make
}
My aide.conf in my reference-environment is this here:
@@define DBDIR /var/lib/aide
@@define LOGDIR /var/log/aide
database_in=http://10.0.0.40/local/@@{HOSTNAME}.aide.db.gz
database_out=file:@@{DBDIR}/@@{HOSTNAME}.aide.db.new.gz
gzip_dbout=yes
log_level=warning
report_level=changed_attributes
report_url=stdout
report_url=syslog:LOG_AUTH
EVERYTHING = R+sha256+sha512
NORMAL = p+i+l+n+u+g+s+m+c+sha256
DIR = p+i+n+u+g+acl+xattrs
PERMS = p+i+u+g+acl
LOG = >
FIPSR = p+i+n+u+g+s+m+c+acl+xattrs+sha256
LSPP = FIPSR+sha512
DATAONLY = p+n+u+g+s+acl+xattrs+sha256
!/etc/.*~
!/etc/mtab
!/usr/src
!/usr/tmp
!/var/lib/pacman/.*
!/var/cache/.*
!/var/log/.*
!/var/log/aide.log
!/var/run/.*
!/var/spool/.*
/etc PERMS
/etc/aliases FIPSR
/etc/at.allow FIPSR
/etc/at.deny FIPSR
/etc/audit/ FIPSR
/etc/bash_completion.d/ NORMAL
/etc/bashrc NORMAL
/etc/cron.allow FIPSR
/etc/cron.daily/ FIPSR
/etc/cron.deny FIPSR
/etc/cron.d/ FIPSR
/etc/cron.hourly/ FIPSR
/etc/cron.monthly/ FIPSR
/etc/crontab FIPSR
/etc/cron.weekly/ FIPSR
/etc/cups FIPSR
/etc/exports NORMAL
/etc/fstab NORMAL
/etc/group NORMAL
/etc/grub/ FIPSR
/etc/gshadow NORMAL
/etc/hosts.allow NORMAL
/etc/hosts.deny NORMAL
/etc/hosts FIPSR
/etc/inittab FIPSR
/etc/issue FIPSR
/etc/issue.net FIPSR
/etc/ld.so.conf FIPSR
/etc/libaudit.conf FIPSR
/etc/localtime FIPSR
/etc/login.defs FIPSR
/etc/login.defs NORMAL
/etc/logrotate.d NORMAL
/etc/modprobe.conf FIPSR
/etc/nscd.conf NORMAL
/etc/pam.d FIPSR
/etc/passwd NORMAL
/etc/postfix FIPSR
/etc/profile.d/ NORMAL
/etc/profile NORMAL
/etc/rc.d FIPSR
/etc/resolv.conf DATAONLY
/etc/securetty FIPSR
/etc/securetty NORMAL
/etc/security FIPSR
/etc/security/opasswd NORMAL
/etc/shadow NORMAL
/etc/skel NORMAL
/etc/ssh/ssh_config FIPSR
/etc/ssh/sshd_config FIPSR
/etc/stunnel FIPSR
/etc/sudoers NORMAL
/etc/sysconfig FIPSR
/etc/sysctl.conf FIPSR
/etc/vsftpd.ftpusers FIPSR
/etc/vsftpd FIPSR
/etc/X11/ NORMAL
/etc/zlogin NORMAL
/etc/zlogout NORMAL
/etc/zprofile NORMAL
/etc/zshrc NORMAL
/usr NORMAL
/usr/sbin/stunnel FIPSR
/var/log/faillog FIPSR
/var/log/lastlog FIPSR
/var/spool/at FIPSR
/var/spool/cron/root FIPSR
/boot NORMAL
/bin NORMAL
/lib NORMAL
/lib64 NORMAL
/opt NORMAL
/root NORMAL
aide -v shows me:
Compile-time options:
use pcre2: mandatory
use pthread: yes
use zlib compression: yes
use POSIX ACLs: yes
use SELinux: no
use xattr: yes
use POSIX 1003.1e capabilities: no
use e2fsattrs: yes
use cURL: yes
use Mhash: no
use GNU crypto library: yes
use Linux Auditing Framework: no
use locale: no
syslog ident: aide
syslog logopt: LOG_CONS
syslog priority: LOG_NOTICE
default syslog facility: LOG_LOCAL0
Default config values:
config file: /etc/aide.conf
database_in: file:/etc/aide.db
database_out: file:/etc/aide.db.new
Available compiled-in attributes:
acl: yes
xattrs: yes
selinux: no
e2fsattrs: yes
caps: no
Available hashsum attributes:
md5: yes
sha1: yes
sha256: yes
sha512: yes
rmd160: yes
tiger: yes
crc32: yes
crc32b: no
haval: no
whirlpool: yes
gost: yes
stribog256: yes
stribog512: yes
Default compound groups:
R: l+p+u+g+s+c+m+i+n+md5+acl+xattrs+ftype+e2fsattrs
L: l+p+u+g+i+n+acl+xattrs+ftype+e2fsattrs
>: l+p+u+g+s+i+n+acl+xattrs+ftype+e2fsattrs+growing
H: md5+sha1+rmd160+tiger+crc32+gost+sha256+sha512+whirlpool+stribog256+stribog512
X: acl+xattrs+e2fsattrs
If I try to check local filesystem against a remote aide.database, it crashes with a segemntation fault afte ~ 2 seconds.
journal shows:
Feb 15 14:22:19 pml010074 sudo[164009]: pam_unix(sudo:session): session opened for user root(uid=0) by django(uid=1000)
Feb 15 14:22:20 pml010074 kernel: aide[164016]: segfault at 8 ip 000070da54a7bbae sp 00007fffe66df960 error 4 in libc.so.6[88bae,70da54a17000+171000] likely on CPU 1 (core 0, socket 0)
Feb 15 14:22:20 pml010074 kernel: Code: 85 8f 00 00 00 55 48 89 e5 41 54 53 48 89 fb 48 83 ec 10 48 8b bf 88 00 00 00 80 3d 7b 75 16 00 00 64 4c 8b 24 25 10 00 00 00 <48> 8b 57 08 75 6c 49 39 d4 0f 84 a3 00 00 00 31 c0 ba 01 00 00 00
Feb 15 14:22:20 pml010074 systemd-coredump[164020]: Process 164016 (aide) of user 0 terminated abnormally with signal 11/SEGV, processing...
Feb 15 14:22:20 pml010074 systemd[1]: Started Process Core Dump (PID 164020/UID 0).
Feb 15 14:22:20 pml010074 systemd[1]: Started Pass systemd-coredump journal entries to relevant user for potential DrKonqi handling.
Feb 15 14:22:20 pml010074 systemd-coredump[164021]: Resource limits disable core dumping for process 164016 (aide).
Feb 15 14:22:20 pml010074 systemd-coredump[164021]: [🡕] Process 164016 (aide) of user 0 terminated abnormally without generating a coredump.
Feb 15 14:22:20 pml010074 systemd[1]: [email protected]: Deactivated successfully.
Feb 15 14:22:20 pml010074 sudo[164009]: pam_unix(sudo:session): session closed for user root
Feb 15 14:22:20 pml010074 drkonqi-coredump-processor[164022]: Entry doesn't look like a dump. This may have been a vaccum run. Nothing to process.
Feb 15 14:22:20 pml010074 drkonqi-coredump-processor[164022]: "/usr/bin/aide" 164016 ""
Feb 15 14:22:20 pml010074 drkonqi-coredump-processor[164022]: The socket path doesn't exist @ "/run/user/0/drkonqi-coredump-launcher"
Feb 15 14:22:20 pml010074 systemd[1]: [email protected]: Deactivated successfully.```
So why does the aide process die shortly after the check starts?
I compiled the AIDE package under Arch with the 'with-curl' option.
My aide.conf in my reference-environment is this here:
aide -v shows me:
If I try to check local filesystem against a remote aide.database, it crashes with a segemntation fault afte ~ 2 seconds.
journal shows: