[Aide] Capturing changes in directory but a privileged subdirectory

Hannes von Haugwitz hannes at vonhaugwitz.com
Tue Jun 7 07:28:36 EEST 2016


Hello John,

On Mon, Jun 06, 2016 at 10:23:31PM -0500, John Kristoff wrote:
> I'm using 0.16b1 on a Linux machiine and trying to do something like
> this in an aide.conf:
> 
>   /boot  R
>   !/boot/lost\+found
> 
> I'm initializing the database and running as an unprivileged user.  I'm
> struggling to figure out how to exclude the priviledged (root only)
> lost+found directories (and others like it) from being accessed by AIDE,
> because I'm getting errors like this:
> 
>   open_dir(): Permission denied: /boot/lost+found

I can reproduce your issue; it seems to be a bug at a first glance. I'll
look into it and report back.

Best regards

Hannes


More information about the Aide mailing list