Skip to content

(aide) terminated abnormally with signal 11/SEGV - AIDE 0.19.3 #229

Description

@Django-BOfH

Description

If database_in = file:@@{DBDIR}/hostname.aide-database is used everything works as expected, so far so good!

BUT:
If I use remote database with database_in = http://databasehost.example.com/hids_datas/hostname.aide-database aide crashes with a segfault:

aide --check
Segmentation fault         (core dumped) aide --check

How to reproduce the issue?

  1. Build a new database with aide --init
  2. Copy the database-file to my own database-server
  3. Check aide --check against the database "local" with database_in = file:@@{DBDIR}/hostname.aide-database in /etc/aide.conf everything is fine!
  4. Check aide --check against the database "remote" with database_in = http://hostname.example.com/hids_datas/hostname.aide-database in /etc/aide.conf aide crash with an segfault!

journal shows:

Aug 28 09:23:42 hostname kernel: Code: 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa c4 41 01 ef ff 89 f8 09 f0 c1 e0 14 3d 00 00 00 f8 0f 87 25 03 00 00 c5 fe 6f 07 <c5> fd 74 0e c5 85 74 d0 c5 ed df c9 c5 fd d7 c9 ff c1 74 5d f3 0f
Aug 28 09:23:42 hostname systemd-coredump[1482444]: Process 1482440 (aide) of user 0 terminated abnormally with signal 11/SEGV, processing...
Aug 28 09:23:42 hostname systemd[1]: Started Process Core Dump (PID 1482444/UID 0).
Aug 28 09:23:42 hostname systemd-coredump[1482445]: [🡕] Process 1482440 (aide) of user 0 dumped core.
                                                     
                                                     Stack trace of thread 1482440:
                                                     #0  0x00007f28643789ef n/a (libc.so.6 + 0x1789ef)
                                                     #1  0x000056461fbc461f n/a (aide + 0x1a61f)
                                                     #2  0x000056461fbaf53b n/a (aide + 0x553b)
                                                     #3  0x00007f2864227781 n/a (libc.so.6 + 0x27781)
                                                     #4  0x00007f28642278b9 __libc_start_main (libc.so.6 + 0x278b9)
                                                     #5  0x000056461fbafbb5 n/a (aide + 0x5bb5)
                                                     
                                                     Stack trace of thread 1482441:
                                                     #0  0x00007f28642a0952 n/a (libc.so.6 + 0xa0952)
                                                     #1  0x00007f28642e4aed clock_nanosleep (libc.so.6 + 0xe4aed)
                                                     #2  0x00007f28642f0f27 __nanosleep (libc.so.6 + 0xf0f27)
                                                     #3  0x00007f28643202ea usleep (libc.so.6 + 0x1202ea)
                                                     #4  0x000056461fbc7a9b n/a (aide + 0x1da9b)
                                                     #5  0x00007f28642980a2 n/a (libc.so.6 + 0x980a2)
                                                     #6  0x00007f286432080c n/a (libc.so.6 + 0x12080c)
                                                     
                                                     Stack trace of thread 1482443:
                                                     #0  0x00007f28642a0952 n/a (libc.so.6 + 0xa0952)
                                                     #1  0x00007f2864294cd9 n/a (libc.so.6 + 0x94cd9)
                                                     #2  0x00007f2864297762 pthread_cond_timedwait (libc.so.6 + 0x97762)
                                                     #3  0x00007f286462bdb5 n/a (libcurl.so.4 + 0x95db5)
                                                     #4  0x00007f28645bc8dd n/a (libcurl.so.4 + 0x268dd)
                                                     #5  0x00007f28642980a2 n/a (libc.so.6 + 0x980a2)
                                                     #6  0x00007f286432080c n/a (libc.so.6 + 0x12080c)
                                                     
                                                     Stack trace of thread 1482442:
                                                     #0  0x00007f28642a0952 n/a (libc.so.6 + 0xa0952)
                                                     #1  0x00007f2864294cd9 n/a (libc.so.6 + 0x94cd9)
                                                     #2  0x00007f2864297762 pthread_cond_timedwait (libc.so.6 + 0x97762)
                                                     #3  0x00007f286462bdb5 n/a (libcurl.so.4 + 0x95db5)
                                                     #4  0x00007f28645bc8dd n/a (libcurl.so.4 + 0x268dd)
                                                     #5  0x00007f28642980a2 n/a (libc.so.6 + 0x980a2)
                                                     #6  0x00007f286432080c n/a (libc.so.6 + 0x12080c)
                                                     ELF object binary architecture: AMD x86-64
Aug 28 09:23:42 hostname systemd[1]: systemd-coredump@9-4098-1482444_1482445-0.service: Deactivated successfully.

Which version of AIDE are you using?

AIDE 0.19.3-2

compile-options on Arch:

# Maintainer: AlphaJack <alphajack at tuta dot io>
# Contributor: John Doe <[email protected]>
# Contributor: Lukas Jirkovsky <[email protected]>
# Contributor: Thomas S Hatch <[email protected]>
# Contributor: Daniel J Griffiths <[email protected]>
# Contributor: Tom Newsom <[email protected]>
 
pkgname="aide"
pkgver=0.19.3
pkgrel=2
pkgdesc="A file integrity checker and intrusion detection program"
arch=("x86_64" "armv7h" "aarch64")
url="https://aide.github.io/"
license=("GPL")
depends=("acl"
         "e2fsprogs"
         "libelf"
         "nettle"
         "pcre")
source=("https://github.com/aide/aide/releases/download/v$pkgver/aide-$pkgver.tar.gz"{,.asc} \
        "aide.conf"
        "aidecheck.service"
        "aidecheck.timer"
        "nettle4.patch")
b2sums=('5d52019b3690c8590678d408209619e1b257f84e66f2f5074a198e14ab78777de963a37ff7c26f505f278a313747947a101f9ac13d391417e91f6418f84adbe3'
        'SKIP'
        '2e16baf306dcbe5d5207685391bb3e77b80a8caafaeafee3094228ee19671092afc042762523663a1d5155341a5d190c5e6c355d639e1a840efddf56047c05bc'
        'fcae2514bffcfe8c2110c8b82d857f39de8c95e0d7d2788bb4945243c127c9566871606b9e4bca39034b624c7bd579f46ed88cb0b86830d6ff16ff1fbb04b081'
        'af16bbf1d69226d445820ba1e7beaba8142a19eb3120f5b58db048083d94ec22f857a28dfe403bd885aafe31b748a10ce9de759480947d4b34b29e2b1a678071'
        '7d9bf59a75d7bfd6c2462d88d746380883fd2c1a84109d5150e66a5de1a576026c31f887b7838d9137c31423df347c531da03b5f874c4486cef50bf771a6fe33')
validpgpkeys=("2BBBD30FAAB29B3253BCFBA6F6947DAB68E7B931") # Hannes von Haugwitz <[email protected]>
backup=("etc/aide.conf")
install="aide.install"
 
prepare(){
 cd "$pkgname-$pkgver"
 # nettle 4 dropped the length argument from the hash digest functions,
 # upstream fix is not in a release yet (latest is 0.19.3)
 patch -Np1 -i "$srcdir/nettle4.patch"
}
 
build(){
 cd "$pkgname-$pkgver"
 ./configure \
  --prefix="/usr" \
  --sysconfdir="/etc" \
  --with-posix-acl \
  --with-xattr \
  --with-zlib \
  --with-e2fsattrs \
  --disable-static \
  --with-curl \
  --with-nettle
 make
}
 
package(){
 cd "$pkgname-$pkgver"
 make DESTDIR="$pkgdir" install
 install -d -m 700 "$pkgdir/var/lib/aide"
 install -d -m 700 "$pkgdir/var/log/aide"
 install -D -m 600 "$srcdir/aide.conf" "$pkgdir/etc/aide.conf"
 install -D -m 644 "$srcdir/aidecheck.service" -t"$pkgdir/usr/lib/systemd/system"
 install -D -m 644 "$srcdir/aidecheck.timer"   -t "$pkgdir/usr/lib/systemd/system"
}

Package was build on ArchLinux with pikaur -S aide

How did you install AIDE?

manual build from git source

What's your operating system?

Arch-Linux

Activity

  1. Django-BOfH commented on Aug 28, 2026

    @Django-BOfH
    Author

    O.K. I've found a "solution" for me:

    If I use database_in = http://hostname.example.com/hids_datas/hostname.aide-database a aide --check crashes with an segfault!

    BUT:
    If I use database_in = http://10.0.0.89/hids_datas/hostname.aide-database a aide --check works as expected!

    name resolution is O.K.!

    dig hostname.example.com +short
    10.0.0.89
    
  2. added
    moreinfoThis issue can't be addressed until more information is provided by the submitter
    and removed on Aug 28, 2026
  3. hvhaugwitz commented on Aug 28, 2026

    @hvhaugwitz
    Member

    Thanks for your bug report.

    Unfortunately I'm unable to reproduce your issue (on Debian unstable).

    This looks very similar to your issue #182, that we discussed in detail last year.

    Can you please build aide from a clean git source directory via

    $ git clone https://github.com/aide/aide --branch v0.19.x && cd aide/
    $ sh autogen.sh && ./configure --with-curl && make
    

    Then if you can reproduce the segfault please generate a gdb backtrace, e.g. using the following command:

    $ gdb -batch -ex "run" -ex "bt" --args ./aide --check
    
  4. Django-BOfH commented on Aug 28, 2026

    @Django-BOfH
    Author
     ~/aide [v0.19.x|✔] 
    17:51 $ sh autogen.sh
    autoreconf: export WARNINGS=
    autoreconf: Entering directory '.'
    autoreconf: configure.ac: no obvious need to run autopoint
    autoreconf: running: aclocal --force 
    autoreconf: configure.ac: tracing
    autoreconf: configure.ac: not using Libtool
    autoreconf: configure.ac: not using Intltool
    autoreconf: configure.ac: not using Gtkdoc
    autoreconf: configure.ac: no need to run autopoint (confirmed)
    autoreconf: running: /usr/bin/autoconf --force
    configure.ac:19: error: undefined or overquoted macro: AC_MSG_ERROR
          If this token and others are legitimate, please use m4_pattern_allow.
          See the Autoconf documentation.
    autoreconf: error: /usr/bin/autoconf failed with exit status: 1
    
  5. hvhaugwitz commented on Aug 28, 2026

    @hvhaugwitz
    Member

    Please recheck if you have installed all build dependencies mentioned in the README.

    Do you have pkg-config installed?

  6. Django-BOfH commented on Aug 29, 2026

    @Django-BOfH
    Author

    Yepp, all build dependencies are installed, but the error-message after sh autogen.sh still exists:

    configure.ac:19: error: undefined or overquoted macro: AC_MSG_ERROR
          If this token and others are legitimate, please use m4_pattern_allow.
          See the Autoconf documentation.
    autoreconf: error: /usr/bin/autoconf failed with exit status: 1
    
  7. Django-BOfH commented on Aug 29, 2026

    @Django-BOfH
    Author

    As you can see on my first post, I build aide pkgver=0.19.3 with https://github.com/aide/aide/releases/download/v$pkgver/aide-$pkgver.tar.gz"

    With option database_in = http://vml000089.example.com/hids_datas/pml010068.aide.db and gzip_dbout = no aide crashes with a secfault:

    [root@pml010068 aide]# gdb -batch -ex "run" -ex "bt" --args aide --check
    
    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6c896c0 (LWP 1835045)]
    [New Thread 0x7ffff64886c0 (LWP 1835046)]
    [New Thread 0x7ffff5c876c0 (LWP 1835047)]
    
    Thread 1 "aide" received signal SIGSEGV, Segmentation fault.
    0x00007ffff79789ef in ?? () from /usr/lib/libc.so.6
    #0  0x00007ffff79789ef in ?? () from /usr/lib/libc.so.6
    #1  0x000055555556e61f in ?? ()
    #2  0x000055555555953b in ?? ()
    #3  0x00007ffff7827781 in ?? () from /usr/lib/libc.so.6
    #4  0x00007ffff78278b9 in __libc_start_main () from /usr/lib/libc.so.6
    #5  0x0000555555559bb5 in ?? ()
    

    With option database_in = http://10.0.0.89/hids_datas/pml010068.aide.db and gzip_dbout = no a check will run smooth and as expected!

    O.K. so far so good. Noẃ Ive changes compression with option gzip_dbout = yes and build a new database with aide--initand copied the database to the http-server.

    Now I run a check with option database_in = http://10.0.0.89/hids_datas/pml010068.aide.db and gzip_dbout = yes with:

    [root@pml010068 aide]# gdb -batch -ex "run" -ex "bt" --args aide --check
    
    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6c896c0 (LWP 1837346)]
    
    Thread 1 "aide" received signal SIGSEGV, Segmentation fault.
    0x00007ffff79789ef in ?? () from /usr/lib/libc.so.6
    #0  0x00007ffff79789ef in ?? () from /usr/lib/libc.so.6
    #1  0x000055555556e61f in ?? ()
    #2  0x000055555555953b in ?? ()
    #3  0x00007ffff7827781 in ?? () from /usr/lib/libc.so.6
    #4  0x00007ffff78278b9 in __libc_start_main () from /usr/lib/libc.so.6
    #5  0x0000555555559bb5 in ?? ()
    

    Last but not least I run a check against local database with option database_in = file:@@{DBDIR}/pml010068.aide.db and gzip_dbout = yes and now the check runs without an error or crash!

  8. hvhaugwitz commented on Aug 29, 2026

    @hvhaugwitz
    Member

    Yepp, all build dependencies are installed, but the error-message after sh autogen.sh still exists:

    configure.ac:19: error: undefined or overquoted macro: AC_MSG_ERROR
          If this token and others are legitimate, please use m4_pattern_allow.
          See the Autoconf documentation.
    autoreconf: error: /usr/bin/autoconf failed with exit status: 1
    

    I cannot reproduce this error (not even on a arch virtual machine):

    $ sudo pacman -S make autoconf automake nettle pkg-config autoconf-archive pcre git gcc bison flex
    $ git clone https://github.com/aide/aide && cd aide/
    $ sh autogen.sh && ./configure --with-curl && make
    

    Note that I checked out git master branch (so I don't have to apply the nettle4 patch manually).

  9. Django-BOfH commented on Aug 29, 2026

    @Django-BOfH
    Author

    O.K. I've reinstalled all packages, as you told me:
    $ sudo pacman -S make autoconf automake nettle pkg-config autoconf-archive pcre git gcc bison flex

    [root@pml010068 aide]# pacman -S make autoconf automake nettle pkg-config autoconf-archive pcre git gcc bison flex
    warning: make-4.4.1-3 is up to date -- reinstalling
    warning: autoconf-2.73-1 is up to date -- reinstalling
    warning: automake-1.18.1-1 is up to date -- reinstalling
    warning: nettle-4.0-1 is up to date -- reinstalling
    warning: pkgconf-3.0.5-1 is up to date -- reinstalling
    warning: pcre-8.45-5 is up to date -- reinstalling
    warning: git-2.55.0-1 is up to date -- reinstalling
    warning: gcc-16.2.1+r23+gd564253eb6c8-1 is up to date -- reinstalling
    warning: bison-3.8.2-8 is up to date -- reinstalling
    warning: flex-2.6.4-6 is up to date -- reinstalling
    resolving dependencies...
    looking for conflicting packages...
    
    Packages (11) autoconf-2.73-1  autoconf-archive-1:2024.10.16-4  automake-1.18.1-1  bison-3.8.2-8
                  flex-2.6.4-6  gcc-16.2.1+r23+gd564253eb6c8-1  git-2.55.0-1  make-4.4.1-3  nettle-4.0-1
                  pcre-8.45-5  pkgconf-3.0.5-1
    
    Total Installed Size:  268.33 MiB
    Net Upgrade Size:        2.29 MiB
    
    :: Proceed with installation? [Y/n] y
    (11/11) checking keys in keyring                             [#################################] 100%
    (11/11) checking package integrity                           [#################################] 100%
    (11/11) loading package files                                [#################################] 100%
    (11/11) checking for file conflicts                          [#################################] 100%
    (11/11) checking available disk space                        [#################################] 100%
    :: Processing package changes...
    ( 1/11) reinstalling make                                    [#################################] 100%
    ( 2/11) reinstalling autoconf                                [#################################] 100%
    ( 3/11) reinstalling automake                                [#################################] 100%
    ( 4/11) reinstalling nettle                                  [#################################] 100%
    ( 5/11) reinstalling pkgconf                                 [#################################] 100%
    ( 6/11) installing autoconf-archive                          [#################################] 100%
    Optional dependencies for autoconf-archive
        automake: macros for use with it [installed]
    ( 7/11) reinstalling pcre                                    [#################################] 100%
    ( 8/11) reinstalling git                                     [#################################] 100%
    ( 9/11) reinstalling gcc                                     [#################################] 100%
    (10/11) reinstalling bison                                   [#################################] 100%
    (11/11) reinstalling flex                                    [#################################] 100%
    :: Running post-transaction hooks...
    (1/5) Creating system user accounts...
    (2/5) Reloading system manager configuration...
    (3/5) Enqueuing marked services...
    (4/5) Arming ConditionNeedsUpdate...
    (5/5) Updating the info directory file...
    

    Then I build aide based like you told me:

    $ git clone https://github.com/aide/aide && cd aide/
    $ sh autogen.sh && ./configure --with-curl && make
    

    Then I copied my lokal /etc/aide.conf to /usr/local/etc/ with database_in = http://vml000089.example.com/hids_datas/pml010068.aide.db
    finally I run an aide check:

    [root@pml010068 aide]# gdb -batch -ex "run" -ex "bt" --args /home/django/aide/aide --check
    
    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6cd66c0 (LWP 1862928)]
    WARNING: /usr/local/etc/aide.conf:178: ignoring not compiiled-in attribute(s): acl (line: '/etc                               PERMS')
    WARNING: /usr/local/etc/aide.conf:179: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/aliases                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:180: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/at.allow                      FIPSR')
    WARNING: /usr/local/etc/aide.conf:181: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/at.deny                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:182: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/audit/                        FIPSR')
    WARNING: /usr/local/etc/aide.conf:185: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.allow                    FIPSR')
    WARNING: /usr/local/etc/aide.conf:186: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.daily/                   FIPSR')
    WARNING: /usr/local/etc/aide.conf:187: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.deny                     FIPSR')
    WARNING: /usr/local/etc/aide.conf:188: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.d/                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:189: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.hourly/                  FIPSR')
    WARNING: /usr/local/etc/aide.conf:190: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.monthly/                 FIPSR')
    WARNING: /usr/local/etc/aide.conf:191: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/crontab                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:192: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cron.weekly/                  FIPSR')
    WARNING: /usr/local/etc/aide.conf:193: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/cups                          FIPSR')
    WARNING: /usr/local/etc/aide.conf:197: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/grub/                         FIPSR')
    WARNING: /usr/local/etc/aide.conf:201: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/hosts                         FIPSR')
    WARNING: /usr/local/etc/aide.conf:202: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/inittab                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:203: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/issue                         FIPSR')
    WARNING: /usr/local/etc/aide.conf:204: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/issue.net                     FIPSR')
    WARNING: /usr/local/etc/aide.conf:205: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/ld.so.conf                    FIPSR')
    WARNING: /usr/local/etc/aide.conf:206: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/libaudit.conf                 FIPSR')
    WARNING: /usr/local/etc/aide.conf:207: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/localtime                     FIPSR')
    WARNING: /usr/local/etc/aide.conf:208: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/login.defs                    FIPSR')
    WARNING: /usr/local/etc/aide.conf:211: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/modprobe.conf                 FIPSR')
    WARNING: /usr/local/etc/aide.conf:213: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/pam.d                         FIPSR')
    WARNING: /usr/local/etc/aide.conf:215: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/postfix                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:218: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/rc.d                          FIPSR')
    WARNING: /usr/local/etc/aide.conf:219: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/resolv.conf                   DATAONLY')
    WARNING: /usr/local/etc/aide.conf:220: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/securetty                     FIPSR')
    WARNING: /usr/local/etc/aide.conf:222: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/security                      FIPSR')
    WARNING: /usr/local/etc/aide.conf:226: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/ssh/ssh_config                FIPSR')
    WARNING: /usr/local/etc/aide.conf:227: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/ssh/sshd_config               FIPSR')
    WARNING: /usr/local/etc/aide.conf:228: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/stunnel                       FIPSR')
    WARNING: /usr/local/etc/aide.conf:230: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/sysconfig                     FIPSR')
    WARNING: /usr/local/etc/aide.conf:231: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/sysctl.conf                   FIPSR')
    WARNING: /usr/local/etc/aide.conf:232: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/vsftpd.ftpusers               FIPSR')
    WARNING: /usr/local/etc/aide.conf:233: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/etc/vsftpd                        FIPSR')
    WARNING: /usr/local/etc/aide.conf:243: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/usr/sbin/stunnel                  FIPSR')
    WARNING: /usr/local/etc/aide.conf:247: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/var/log/faillog                   FIPSR')
    WARNING: /usr/local/etc/aide.conf:248: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/var/log/lastlog                   FIPSR')
    WARNING: /usr/local/etc/aide.conf:249: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/var/spool/at                      FIPSR')
    WARNING: /usr/local/etc/aide.conf:250: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/var/spool/cron/root               FIPSR')
    WARNING: /usr/local/etc/aide.conf:264: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/usr/local/bin/                    FIPSR')
    WARNING: /usr/local/etc/aide.conf:267: ignoring not compiiled-in attribute(s): acl+xattrs (line: '/usr/local/sbin/                   FIPSR')
    [New Thread 0x7ffff64b56c0 (LWP 1862929)]
    [New Thread 0x7ffff5cb46c0 (LWP 1862930)]
    [New Thread 0x7ffff54136c0 (LWP 1862931)]
    
    Thread 1 "aide" received signal SIGSEGV, Segmentation fault.
    0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #0  0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #1  0x000055555556fa5f in db_readline_file (db=0x555555593408, include_limited_entries=false) at src/db_file.c:208
    #2  0x000055555556c609 in db_readline (db=<optimized out>, include_limited_entries=<optimized out>) at src/db.c:210
    #3  0x0000555555574359 in populate_tree (tree=0x5555555936a0) at src/gen_list.c:871
    #4  0x000055555555bc61 in main (argc=2, argv=<optimized out>) at src/aide.c:883
    
    
  10. hvhaugwitz commented on Aug 29, 2026

    @hvhaugwitz
    Member
    ( 6/11) installing autoconf-archive                          [#################################] 100%
    

    autoconf-archive was missing.

    Then I copied my lokal /etc/aide.conf to /usr/local/etc/ with database_in = http://vml000089.example.com/hids_datas/pml010068.aide.db finally I run an aide check:

    Is this db compressed or not? (Note that remote compressed database is not working at the moment, see #184)

    Thread 1 "aide" received signal SIGSEGV, Segmentation fault.
    0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #0  0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #1  0x000055555556fa5f in db_readline_file (db=0x555555593408, include_limited_entries=false) at src/db_file.c:208
    #2  0x000055555556c609 in db_readline (db=<optimized out>, include_limited_entries=<optimized out>) at src/db.c:210
    #3  0x0000555555574359 in populate_tree (tree=0x5555555936a0) at src/gen_list.c:871
    #4  0x000055555555bc61 in main (argc=2, argv=<optimized out>) at src/aide.c:883
    

    Can you reduce the number of files in the database to one file (e.g. via single rule /etc/group$ R) and still reproduce the error?

  11. Django-BOfH commented on Aug 29, 2026

    @Django-BOfH
    Author

    O.K. look:

    root@vml000089:/srv/http/hids_datas# file pml010068.aide.db
    pml010068.aide.db: ASCII text
    

    The first few lines of my pimped aide.conf (for testing):
    # vim /usr/local/etc/aide.conf

    @@define DBDIR /var/lib/aide
    @@define LOGDIR /var/log/aide
    
    # The location of the database to be read.
    #database_in = http://10.0.0.89/hids_datas/pml010068.aide.db
    database_in = http://vml000089.example.com/hids_datas/pml010068.aide.db
    #database_in = file:@@{DBDIR}/pml010068.aide.db
    
    # The location of the database to be written.
    database_out = file:@@{DBDIR}/pml010068.aide.db
    
    # Whether to gzip the output to database.
    gzip_dbout = no
    
    

    Now I check against the uncompressed file on my http-server:
    [root@pml010068 aide]# gdb -batch -ex "run" -ex "bt" --args /home/django/aide/aide --check

    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6cd66c0 (LWP 1913390)]
    [New Thread 0x7ffff64c56c0 (LWP 1913391)]
    [New Thread 0x7ffff5cc46c0 (LWP 1913392)]
    
    Thread 1 "aide" received signal SIGSEGV, Segmentation fault.
    0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #0  0x00007ffff7b789ef in ?? () from /usr/lib/libc.so.6
    #1  0x000055555556fa5f in db_readline_file (db=0x555555593408, include_limited_entries=false) at src/db_file.c:208
    #2  0x000055555556c609 in db_readline (db=<optimized out>, include_limited_entries=<optimized out>) at src/db.c:210
    #3  0x0000555555574359 in populate_tree (tree=0x5555555936a0) at src/gen_list.c:871
    #4  0x000055555555bc61 in main (argc=2, argv=<optimized out>) at src/aide.c:883
    
  12. hvhaugwitz commented on Aug 29, 2026

    @hvhaugwitz
    Member

    Can you please try the following patch and report back if it fixes the segfault?

    diff --git before/src/db_file.c after/src/db_file.c
    --- before/src/db_file.c
    +++ after/src/db_file.c
    @@ -205,7 +205,10 @@ db_entry_t db_readline_file(database* db, bool include_limited_entries) {
                 default:
                     saveptr = NULL;
                     token = strtok_r(line, " ", &saveptr);
    -                if (strcmp("@@db_spec", token) == 0) {
    +                if (token == NULL) {
    +                    LOG_DB_FORMAT_LINE(LOG_LEVEL_WARNING, "skip line (no token found): '%s'", line)
    +                    break;
    +                } else if (strcmp("@@db_spec", token) == 0) {
                         if (db->fields) {
                             LOG_DB_FORMAT_LINE(LOG_LEVEL_WARNING, "skip additional '%s' line", token)
                         } else {
    
  13. Django-BOfH commented on Aug 30, 2026

    @Django-BOfH
    Author

    Can you please try the following patch and report back if it fixes the segfault?

    Logisch! ;)

    Running a check against an uncompressed database-file from remote produces:

    [root@pml010068 tmp]# gdb -batch -ex "run" -ex "bt" --args /home/django/aide_2/aide --check
    
    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6cd66c0 (LWP 2056368)]
    [New Thread 0x7ffff64c56c0 (LWP 2056369)]
    [New Thread 0x7ffff5cc46c0 (LWP 2056370)]
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:21: skip line (no token found): '  '
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:26: skip line (no token found): '  '
      ERROR: url_fgets failed for http://vml000089.example.com/hids_datas/pml010068.aide-database
    [Thread 0x7ffff64c56c0 (LWP 2056369) exited]
    [Thread 0x7ffff6cd66c0 (LWP 2056368) exited]
    [Thread 0x7ffff77ab100 (LWP 2056365) exited]
    [Thread 0x7ffff5cc46c0 (LWP 2056370) exited]
    [New process 2056365]
    [Inferior 1 (process 2056365) exited with code 022]
    No stack.
    

    Fetching the databasefile with wget:

    [root@pml010068 tmp]# wget http://vml000089.example.com/hids_datas/pml010068.aide-database
    --2026-08-30 10:40:44--  http://vml000089.example.com/hids_datas/pml010068.aide-database
    Resolving vml000089.example.com (vml000089.example.com)... 10.0.0.89, fd00::3:10:0:0:89
    Connecting to vml000089.example.com (vml000089.example.com)|10.0.0.89|:80... connected.
    HTTP request sent, awaiting response... 200 OK
    Length: 328
    Saving to: ‘pml010068.aide-database’
    
    pml010068.aide-database        100%[====================================================>]     328  --.-KB/s    in 0s      
    
    2026-08-30 10:40:44 (25.2 MB/s) - ‘pml010068.aide-database’ saved [328/328]
    
    

    Is the databasefile compressed?

    [root@pml010068 tmp]# file pml010068.aide-database
    pml010068.aide-database: ASCII text
    

    Databasefile's content is:

    [root@pml010068 tmp]# cat pml010068.aide-database
    @@begin_db
    # This file was generated by Aide, version 0.19-23-gcdf5534
    # Time of generation was 2026-08-30 10:35:52 +0200
    @@db_spec name lname perm uid gid size ctime mtime inode lcount attr sha3_256
    /etc/group 0 100644 0 0 958 1784390447 1784390447 4280856 1 8830452763581 ZAZMb5lOKKiVtkyQrFL2ilpFN/VDf22domou+mgjZHI=
    @@end_db
    
  14. hvhaugwitz commented on Aug 30, 2026

    @hvhaugwitz
    Member
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:21: skip line (no token found): '  '
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:26: skip line (no token found): '  '
      ERROR: url_fgets failed for http://vml000089.example.com/hids_datas/pml010068.aide-database
    

    Good, so the patch fixes the segfault.

    [root@pml010068 tmp]# cat pml010068.aide-database
    @@begin_db
    # This file was generated by Aide, version 0.19-23-gcdf5534
    # Time of generation was 2026-08-30 10:35:52 +0200
    @@db_spec name lname perm uid gid size ctime mtime inode lcount attr sha3_256
    /etc/group 0 100644 0 0 958 1784390447 1784390447 4280856 1 8830452763581 ZAZMb5lOKKiVtkyQrFL2ilpFN/VDf22domou+mgjZHI=
    @@end_db
    

    This doesn't add up, the database consists of 6 lines, but aide reports warnings in line 21 and 26.

    Can you run the check with --log-level debug and provide the output after INFO: read old entries from database: [...]?

  15. Django-BOfH commented on Aug 30, 2026

    @Django-BOfH
    Author

    Of course I'll do it - I do almost everything you ask me to do!

       INFO: read old entries from database: http://vml000089.example.com/hids_datas/pml010068.aide-database
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:1: skip line '<?xml' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:2: skip line '<!DOCTYPE' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:3: skip line '  "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:4: skip line '<html' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:5: skip line '<head>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:6: skip line '<title>Access' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:7: skip line '<link' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:8: skip line '<style' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:9: skip line '    body' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:10: skip line '    a:link' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:11: skip line '    p,' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:12: skip line '    span' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:13: skip line '/*]]>*/--></style>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:14: skip line '</head>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:15: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:16: skip line '<body>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:17: skip line '<h1>Access' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:18: skip line '<p>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:19: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:20: db_read_file: skip empty line
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:21: skip line (no token found): '  '
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:22: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:23: skip line '    You' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:24: skip line '    It' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:25: db_read_file: skip empty line
    WARNING: http://vml000089.example.com/hids_datas/pml010068.aide-database:26: skip line (no token found): '  '
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:27: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:28: skip line '</p>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:29: skip line '<p>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:30: skip line 'If' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:31: skip line 'the' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:32: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:33: skip line '</p>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:34: db_read_file: skip empty line
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:35: skip line '<h2>Error' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:36: skip line '<address>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:37: skip line '  <a' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:38: skip line '  <span>Apache/2.4.68' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:39: skip line '</address>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:40: skip line '</body>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:41: skip line '</html>' ('@@begin_db' not (yet) found)
      DEBUG: http://vml000089.example.com/hids_datas/pml010068.aide-database:42: db_read_file: skip empty line
      ERROR: url_fgets failed for http://vml000089.example.com/hids_datas/pml010068.aide-database
    [Thread 0x7ffff5cc46c0 (LWP 2083157) exited]
    [Thread 0x7ffff64c56c0 (LWP 2083156) exited]
    [Thread 0x7ffff77ab100 (LWP 2083152) exited]
    [Thread 0x7ffff6cd66c0 (LWP 2083155) exited]
    [New process 2083152]
    [Inferior 1 (process 2083152) exited with code 022]
    No stack.
    

    I've absolutly on idea what kind of file here is parsed! No, no, I have a strong suspicion about that!

    view-source:http://[2003:a:e0d:7603:10::89]/hids_datas/pml010068.aide-database

    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
      "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
    <html xmlns="http://www.w3.org/1999/xhtml" lang="de" xml:lang="de">
    <head>
    <title>Zugriff verweigert!</title>
    <link rev="made" href="mailto:[email protected]" />
    <style type="text/css"><!--/*--><![CDATA[/*><!--*/ 
        body { color: #000000; background-color: #FFFFFF; }
        a:link { color: #0000CC; }
        p, address {margin-left: 3em;}
        span {font-size: smaller;}
    /*]]>*/--></style>
    </head>
    
    <body>
    <h1>Zugriff verweigert!</h1>
    <p>
    
    
      
    
        Der Zugriff auf das angeforderte Objekt ist nicht möglich.
        Entweder kann es vom Server nicht gelesen werden oder es
        ist zugriffsgeschützt.
    
      
    
    </p>
    <p>
    Sofern Sie dies für eine Fehlfunktion des Servers halten,
    informieren Sie bitte den 
    <a href="mailto:[email protected]">Webmaster</a>
    hierüber.
    
    </p>
    
    <h2>Error 403</h2>
    <address>
      <a href="[/](view-source:http://[2003:a:e0d:7603:10::89]/)">[2003:a:e0d:7603:10::89]</a><br />
      <span>Apache/2.4.68 (Unix) OpenSSL/3.6.3</span>
    </address>
    </body>
    </html>
    
    
    

    Oh my God, what a total idiot I am!

    We're running dual-stack here, after all! And now that I've added not only the IPv4 but also the IPv6 network to the "required ip" entry in the Apache config for the hids_datas subdirectory, it's working perfectly with your git-version:

    $ git clone https://github.com/aide/aide && cd aide/
    $ sh autogen.sh && ./configure --with-curl && make
    

    Hannes, I'm sorry if I bothered you unnecessarily!

    [root@pml010068 tmp]# gdb -batch -ex "run" -ex "bt" --args /home/django/aide/aide --check
    
    This GDB supports auto-downloading debuginfo from the following URLs:
      <https://debuginfod.archlinux.org>
    Enable debuginfod for this session? (y or [n]) [answered N; input not from terminal]
    Debuginfod has been disabled.
    To make this setting permanent, add 'set debuginfod enabled off' to .gdbinit.
    [Thread debugging using libthread_db enabled]
    Using host libthread_db library "/usr/lib/libthread_db.so.1".
    [New Thread 0x7ffff6cd66c0 (LWP 2095088)]
    [New Thread 0x7ffff64c56c0 (LWP 2095089)]
    [New Thread 0x7ffff5cc46c0 (LWP 2095090)]
    [New Thread 0x7ffff53996c0 (LWP 2095091)]
    [Thread 0x7ffff53996c0 (LWP 2095091) exited]
    Start timestamp: 2026-08-30 14:22:53 +0200 (AIDE 0.19-23-gcdf5534)
    AIDE found NO differences between database and filesystem. Looks okay!!
    
    [Thread 0x7ffff6cd66c0 (LWP 2095088) exited]
    Number of entries:	1
    
    ---------------------------------------------------
    The attributes of the (uncompressed) database(s):
    ---------------------------------------------------
    
    http://vml000089.nausch.org/hids_datas/pml010068.aide-database
     SHA256    : kTVtFQZXBeSE3R2OgP6+4IdPZPfzOT1e
                 6Du8quMdrAs=
     SHA512    : JN+8+FOAvRN7UAi0ci1OllQd59WDm3fp
                 c0rXGaOZn9LAS2NkTXYb1Rpgzv1Wm7y4
                 EsfGbqWXtJfy4SK9xCilrQ==
     STRIBOG256: ZyJXWZ8avqOvzfxzJc8mmWXUiS1KwSr2
                 IocG+xYKQ1w=
     STRIBOG512: Tv7Y7UFopmZEM7BAnCR3bi7m5ytqsBhB
                 gcHRRKwiBc21A2+8UM8KGL60wQB/kgGa
                 VIZ3dkubplp6gmgHu80c5w==
     SHA512/256: qjiPoDRvbHU8L+eL01BmSsPLyfZOkmDl
                 j4RpAH48KNY=
     SHA3-256  : kfGX2R/yP2yOSNbgY0DpdZKpdUYWptRb
                 gYgChnE56eo=
     SHA3-512  : LxaEGjIwaMxfPzXCN2Neu1GMAuGE1voD
                 q2x6ZE0VpSf45cTZfP1+9+jlnpVF4wc/
                 oYohJrkD//boNunqB9TdbQ==
    
    
    End timestamp: 2026-08-30 14:22:53 +0200 (run time: 0m 0s)
    [Thread 0x7ffff64c56c0 (LWP 2095089) exited]
    [Thread 0x7ffff77ab100 (LWP 2095085) exited]
    [Thread 0x7ffff5cc46c0 (LWP 2095090) exited]
    [New process 2095085]
    [Inferior 1 (process 2095085) exited normally]
    No stack.
    
    
  16. added
    bugSomething isn't working
    and removed
    moreinfoThis issue can't be addressed until more information is provided by the submitter
    on Aug 30, 2026
  17. hvhaugwitz commented on Aug 30, 2026

    @hvhaugwitz
    Member

    I'm glad we solved the issue.

    I'll push the fix for the segfault to close this bug and adjust the skip line output to be more readable.

  18. added this to the 0.20 milestone on Aug 30, 2026
  19. added a commit that references this issue on Aug 31, 2026
    1103d3c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions