Hi,
The latest audit daemon is available at
http://people.redhat.com/sgrubb/audit
The changes include:
- Lots of code cleanups
- Added write_pid function to auditd
- Added audit_log to libaudit
- Don't check file length in foreground mode of auditd
- Added *if_enabled functions to send messages only if audit system is enabled
- If syscall name is unknown when printing rules, use the syscall number
- Rework the build system to produce singly threaded public libraries
- Create a multithreaded version of libaudit for the audit daemon's use
Please check this version over and report any problems.
Thanks,
-Steve Grubb