1
Starting Test 1, iterate...
10
Starting Test 2, walk events, records, and fields...
14
type=1006(LOGIN) line=1 file=None event time: 1143146623.787:142
18
auid=4294967295 (unset)
24
type=1300(SYSCALL) line=2 file=None event time: 1143146623.875:143
25
type=SYSCALL (SYSCALL)
26
arch=c000003e (x86_64)
27
syscall=188 (setxattr)
30
a0=7fffffa9a9f0 (7fffffa9a9f0)
31
a1=3958d11333 (3958d11333)
47
exe="/bin/login" (/bin/login)
48
subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
53
type=1112(USER_LOGIN) line=3 file=None event time: 1143146623.879:146
54
type=USER_LOGIN (USER_LOGIN)
59
exe="/bin/login" (/bin/login)
67
Starting Test 3, walk events, records of 1 buffer...
70
type=1112(USER_LOGIN) line=1 file=None event time: 1143146623.879:146
74
Starting Test 4, walk events, records of 1 file...
78
type=1400(AVC) line=1 file=./test.log event time: 1170021493.977:293
80
seresult=denied (denied)
81
seperms=read,write (read,write)
83
comm="pickup" (pickup)
84
name="maildrop" (maildrop)
86
ino=14911367 (14911367)
87
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
88
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
92
type=1300(SYSCALL) line=2 file=./test.log event time: 1170021493.977:293
93
type=SYSCALL (SYSCALL)
94
arch=c000003e (x86_64)
97
exit=-13 (-13(Permission denied))
98
a0=5555665d91b0 (5555665d91b0)
99
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
100
a2=5555665d91b8 (5555665d91b8)
105
auid=4294967295 (unset)
108
euid=89 (unknown(89))
109
suid=89 (unknown(89))
110
fsuid=89 (unknown(89))
111
egid=89 (unknown(89))
112
sgid=89 (unknown(89))
113
fsgid=89 (unknown(89))
115
comm="pickup" (pickup)
116
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
117
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
121
type=1307(CWD) line=3 file=./test.log event time: 1170021493.977:293
123
cwd="/var/spool/postfix" (/var/spool/postfix)
126
type=1302(PATH) line=4 file=./test.log event time: 1170021493.977:293
129
name="maildrop" (maildrop)
130
inode=14911367 (14911367)
132
mode=040730 (dir, 730)
133
ouid=89 (unknown(89))
134
ogid=90 (unknown(90))
136
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
141
type=1101(USER_ACCT) line=5 file=./test.log event time: 1170021601.340:294
142
type=USER_ACCT (USER_ACCT)
145
auid=4294967295 (unset)
146
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
148
exe="/usr/sbin/crond" (/usr/sbin/crond)
152
res=success (success)
157
type=1103(CRED_ACQ) line=6 file=./test.log event time: 1170021601.342:295
158
type=CRED_ACQ (CRED_ACQ)
161
auid=4294967295 (unset)
162
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
164
exe="/usr/sbin/crond" (/usr/sbin/crond)
168
res=success (success)
173
type=1006(LOGIN) line=7 file=./test.log event time: 1170021601.343:296
177
auid=4294967295 (unset)
183
type=1105(USER_START) line=8 file=./test.log event time: 1170021601.344:297
184
type=USER_START (USER_START)
188
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
190
exe="/usr/sbin/crond" (/usr/sbin/crond)
194
res=success (success)
199
type=1104(CRED_DISP) line=9 file=./test.log event time: 1170021601.364:298
200
type=CRED_DISP (CRED_DISP)
204
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
206
exe="/usr/sbin/crond" (/usr/sbin/crond)
210
res=success (success)
215
type=1106(USER_END) line=10 file=./test.log event time: 1170021601.366:299
216
type=USER_END (USER_END)
220
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
222
exe="/usr/sbin/crond" (/usr/sbin/crond)
226
res=success (success)
230
Starting Test 5, walk events, records of 2 files...
234
type=1400(AVC) line=1 file=test.log event time: 1170021493.977:293
236
seresult=denied (denied)
237
seperms=read,write (read,write)
239
comm="pickup" (pickup)
240
name="maildrop" (maildrop)
242
ino=14911367 (14911367)
243
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
244
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
248
type=1300(SYSCALL) line=2 file=test.log event time: 1170021493.977:293
249
type=SYSCALL (SYSCALL)
250
arch=c000003e (x86_64)
253
exit=-13 (-13(Permission denied))
254
a0=5555665d91b0 (5555665d91b0)
255
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
256
a2=5555665d91b8 (5555665d91b8)
261
auid=4294967295 (unset)
264
euid=89 (unknown(89))
265
suid=89 (unknown(89))
266
fsuid=89 (unknown(89))
267
egid=89 (unknown(89))
268
sgid=89 (unknown(89))
269
fsgid=89 (unknown(89))
271
comm="pickup" (pickup)
272
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
273
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
277
type=1307(CWD) line=3 file=test.log event time: 1170021493.977:293
279
cwd="/var/spool/postfix" (/var/spool/postfix)
282
type=1302(PATH) line=4 file=test.log event time: 1170021493.977:293
285
name="maildrop" (maildrop)
286
inode=14911367 (14911367)
288
mode=040730 (dir, 730)
289
ouid=89 (unknown(89))
290
ogid=90 (unknown(90))
292
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
297
type=1101(USER_ACCT) line=5 file=test.log event time: 1170021601.340:294
298
type=USER_ACCT (USER_ACCT)
301
auid=4294967295 (unset)
302
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
304
exe="/usr/sbin/crond" (/usr/sbin/crond)
308
res=success (success)
313
type=1103(CRED_ACQ) line=6 file=test.log event time: 1170021601.342:295
314
type=CRED_ACQ (CRED_ACQ)
317
auid=4294967295 (unset)
318
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
320
exe="/usr/sbin/crond" (/usr/sbin/crond)
324
res=success (success)
329
type=1006(LOGIN) line=7 file=test.log event time: 1170021601.343:296
333
auid=4294967295 (unset)
339
type=1105(USER_START) line=8 file=test.log event time: 1170021601.344:297
340
type=USER_START (USER_START)
344
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
346
exe="/usr/sbin/crond" (/usr/sbin/crond)
350
res=success (success)
355
type=1104(CRED_DISP) line=9 file=test.log event time: 1170021601.364:298
356
type=CRED_DISP (CRED_DISP)
360
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
362
exe="/usr/sbin/crond" (/usr/sbin/crond)
366
res=success (success)
371
type=1106(USER_END) line=10 file=test.log event time: 1170021601.366:299
372
type=USER_END (USER_END)
376
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
378
exe="/usr/sbin/crond" (/usr/sbin/crond)
382
res=success (success)
387
type=1400(AVC) line=1 file=test2.log event time: 1170021493.977:293
389
seresult=denied (denied)
392
comm="pickup" (pickup)
393
name="maildrop" (maildrop)
395
ino=14911367 (14911367)
396
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
397
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
401
type=1300(SYSCALL) line=2 file=test2.log event time: 1170021493.977:293
402
type=SYSCALL (SYSCALL)
403
arch=c000003e (x86_64)
406
exit=-13 (-13(Permission denied))
407
a0=5555665d91b0 (5555665d91b0)
408
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
409
a2=5555665d91b8 (5555665d91b8)
414
auid=4294967295 (unset)
417
euid=89 (unknown(89))
418
suid=89 (unknown(89))
419
fsuid=89 (unknown(89))
420
egid=89 (unknown(89))
421
sgid=89 (unknown(89))
422
fsgid=89 (unknown(89))
424
comm="pickup" (pickup)
425
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
426
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
430
type=1307(CWD) line=3 file=test2.log event time: 1170021493.977:293
432
cwd="/var/spool/postfix" (/var/spool/postfix)
435
type=1302(PATH) line=4 file=test2.log event time: 1170021493.977:293
438
name="maildrop" (maildrop)
439
inode=14911367 (14911367)
441
mode=040730 (dir, 730)
442
ouid=89 (unknown(89))
443
ogid=90 (unknown(90))
445
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
450
type=1101(USER_ACCT) line=5 file=test2.log event time: 1170021601.340:294
451
type=USER_ACCT (USER_ACCT)
454
auid=4294967295 (unset)
455
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
457
exe="/usr/sbin/crond" (/usr/sbin/crond)
461
res=success (success)
466
type=1103(CRED_ACQ) line=6 file=test2.log event time: 1170021601.342:295
467
type=CRED_ACQ (CRED_ACQ)
470
auid=4294967295 (unset)
471
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
473
exe="/usr/sbin/crond" (/usr/sbin/crond)
477
res=success (success)
482
type=1006(LOGIN) line=7 file=test2.log event time: 1170021601.343:296
486
auid=4294967295 (unset)
492
type=1105(USER_START) line=8 file=test2.log event time: 1170021601.344:297
493
type=USER_START (USER_START)
497
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
499
exe="/usr/sbin/crond" (/usr/sbin/crond)
503
res=success (success)
508
type=1104(CRED_DISP) line=9 file=test2.log event time: 1170021601.364:298
509
type=CRED_DISP (CRED_DISP)
513
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
515
exe="/usr/sbin/crond" (/usr/sbin/crond)
519
res=success (success)
524
type=1106(USER_END) line=10 file=test2.log event time: 1170021601.366:299
525
type=USER_END (USER_END)
529
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
531
exe="/usr/sbin/crond" (/usr/sbin/crond)
535
res=success (success)
539
Starting Test 6, search...
540
auid = 500 not found...which is correct
541
auid exists...which is correct
542
Testing BUFFER_ARRAY, stop on field
544
Testing BUFFER_ARRAY, stop on record
546
Testing BUFFER_ARRAY, stop on event
548
Testing test.log, stop on field
549
Found auid = 4294967295
550
Testing test.log, stop on record
552
Testing test.log, stop on event
556
Starting Test 7, compound search...
557
Found type = USER_START
561
Starting Test 8, buffer feed...
565
type=1006(LOGIN) line=1 file=None event time: 1143146623.787:142
569
auid=4294967295 (unset)
575
type=1300(SYSCALL) line=2 file=None event time: 1143146623.875:143
576
type=SYSCALL (SYSCALL)
577
arch=c000003e (x86_64)
578
syscall=188 (setxattr)
581
a0=7fffffa9a9f0 (7fffffa9a9f0)
582
a1=3958d11333 (3958d11333)
598
exe="/bin/login" (/bin/login)
599
subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
604
type=1112(USER_LOGIN) line=3 file=None event time: 1143146623.879:146
605
type=USER_LOGIN (USER_LOGIN)
610
exe="/bin/login" (/bin/login)
614
res=success (success)
618
Starting Test 9, file feed...
622
type=1400(AVC) line=1 file=None event time: 1170021493.977:293
624
seresult=denied (denied)
625
seperms=read,write (read,write)
627
comm="pickup" (pickup)
628
name="maildrop" (maildrop)
630
ino=14911367 (14911367)
631
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
632
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
636
type=1300(SYSCALL) line=2 file=None event time: 1170021493.977:293
637
type=SYSCALL (SYSCALL)
638
arch=c000003e (x86_64)
641
exit=-13 (-13(Permission denied))
642
a0=5555665d91b0 (5555665d91b0)
643
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
644
a2=5555665d91b8 (5555665d91b8)
649
auid=4294967295 (unset)
652
euid=89 (unknown(89))
653
suid=89 (unknown(89))
654
fsuid=89 (unknown(89))
655
egid=89 (unknown(89))
656
sgid=89 (unknown(89))
657
fsgid=89 (unknown(89))
659
comm="pickup" (pickup)
660
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
661
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
665
type=1307(CWD) line=3 file=None event time: 1170021493.977:293
667
cwd="/var/spool/postfix" (/var/spool/postfix)
670
type=1302(PATH) line=4 file=None event time: 1170021493.977:293
673
name="maildrop" (maildrop)
674
inode=14911367 (14911367)
676
mode=040730 (dir, 730)
677
ouid=89 (unknown(89))
678
ogid=90 (unknown(90))
680
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
685
type=1101(USER_ACCT) line=5 file=None event time: 1170021601.340:294
686
type=USER_ACCT (USER_ACCT)
689
auid=4294967295 (unset)
690
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
692
exe="/usr/sbin/crond" (/usr/sbin/crond)
696
res=success (success)
701
type=1103(CRED_ACQ) line=6 file=None event time: 1170021601.342:295
702
type=CRED_ACQ (CRED_ACQ)
705
auid=4294967295 (unset)
706
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
708
exe="/usr/sbin/crond" (/usr/sbin/crond)
712
res=success (success)
717
type=1006(LOGIN) line=7 file=None event time: 1170021601.343:296
721
auid=4294967295 (unset)
727
type=1105(USER_START) line=8 file=None event time: 1170021601.344:297
728
type=USER_START (USER_START)
732
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
734
exe="/usr/sbin/crond" (/usr/sbin/crond)
738
res=success (success)
743
type=1104(CRED_DISP) line=9 file=None event time: 1170021601.364:298
744
type=CRED_DISP (CRED_DISP)
748
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
750
exe="/usr/sbin/crond" (/usr/sbin/crond)
754
res=success (success)
759
type=1106(USER_END) line=10 file=None event time: 1170021601.366:299
760
type=USER_END (USER_END)
764
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
766
exe="/usr/sbin/crond" (/usr/sbin/crond)
770
res=success (success)
774
Finished non-admin tests