Skip to content

aide v0.19 and up doesn't (or can't) access the FreeBSD file-system anymore #208

Description

@blackfoxx79

Hi there.
After updating aide from v0.18.8 to v0.19 (and recently v0.19.2) it doesn't (or can't) access the file-system anymore.
The system is FreeBSD 15.0-RELEASE (previously 14.3).
What I found out after about 20 hours of searching the web, fiddling with the "aide.conf", cleaning everything up and (re)installing aide from scratch is this:
In this case the content of the "aide.conf" doesn't matter.
No matter if I use my customized one from v0.18.8, the .sample from v0.19.2 or even a simplyfied one for testing:

#aide.conf for testing:
database_in=file:/var/db/aide/databases/aide.db
database_out=file:/var/db/aide/databases/aide.db.new
num_workers=4
report_url=file:/var/log/aide.log
/ p+u+g+s+ftype+sha3_256

everthing ends in the same result:

check config:

blackfoxx@FASTFOXX:~ $ sudo aide -D -L info
INFO: initialize rule tree
INFO: define default attribute definitions
INFO: define default groups definitions
INFO: read command line parameters
INFO: (--config-check): config check command
INFO: (--log-level): set log level to 'info'
INFO: parse configuration
blackfoxx@FASTFOXX:~ $

initialize new database:

blackfoxx@FASTFOXX:~ $ sudo aide -i -L info
INFO: initialize rule tree
INFO: define default attribute definitions
INFO: define default groups definitions
INFO: read command line parameters
INFO: (--init): database init command
INFO: (--log-level): set log level to 'info'
INFO: parse configuration
INFO: parsed 1 config file [1114 files/s] in 0m 0.0009s
INFO: read new entries from disk (limit: '(none)', root prefix: '')
WARNING: failed to open directory '/' for reading: stat fields changed: (skipping recursion)
INFO: read 1 entry [4509 entries/s] from file system in 0m 0.0002s
INFO: write new entries to database: file:/var/db/aide/databases/aide.db.new
INFO: wrote 1 entry [6508 entries/s] to file:/var/db/aide/databases/aide.db.new in 0m 0.0002s
INFO: generate reports
INFO: exit AIDE with exit code '0'
blackfoxx@FASTFOXX:~ $

Although it creates a new database, this new db is just empty and hence useless.

I already tried some variants with the "root_prefix"-option too, but without any luck:
root_prefix=/root in aide.conf:

WARNING: failed to open directory '/root' for reading: stat fields changed: (skipping recursion)

root_prefix=/home/blackfoxx in aide.conf:

WARNING: failed to open directory '/home/blackfoxx' for reading: stat fields changed: (skipping recursion)

Now I've reached the end of my knowledge, patience and time.
Until v0.19 it worked without any issues and I don't wanna switch to another IDS.
I hope that somebody else around here can help me out of this "misery".
Thanks in advance, blackfoxx.

some additional infos:

blackfoxx@FASTFOXX:~ $ pkg info aide
aide-0.19.2
Name : aide
Version : 0.19.2
Installed on : Sun Dec 21 17:46:04 2025 CET
Origin : security/aide
Architecture : FreeBSD:15:amd64
Prefix : /usr/local
Categories : security
Licenses : GPLv2
Maintainer : [email protected]
WWW : https://aide.github.io/
Comment : File and directory integrity checker
Options :
GCRYPT : on
NETTLE : off
Shared Libs required:
libc.so.7
libe2p.so.2
libgcrypt.so.20
libm.so.5
libpcre2-8.so.0
libthr.so.3
libz.so.6
Annotations :
FreeBSD_version: 1500068
build_timestamp: 2025-12-18T12:48:21+0000
built_by : poudriere-git-3.4.4-15-g61aba751
flavor : default
port_checkout_unclean: no
port_git_hash : 216f935c17e2b4738ea231634f8160e5f7182d48
ports_top_checkout_unclean: no
ports_top_git_hash: f05f83bf9e418b2758b94eecee0176ebfc32c370
repo_type : binary
repository : FreeBSD
Flat size : 247KiB
Description :
AIDE is Advanced Intrusion Detection Environment, a file and
directory integrity checker.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions