As much as I'd like to be on a more current kernel, the open_by_handle_at
syscall seems to have been introduced in 2.6.39, per para 1.9 of:
http://kernelnewbies.org/Linux_2_6_39
I removed it from my local copy of:
https://fedorahosted.org/audit/browser/trunk/contrib/stig.rules
My old RHEL 5 boxes are easily confused with this new-fangled stuff! :)
Is there a plan to have a RHEL 5 and RHEL 6 version of the stig.rules?
Leam
--
Mind on a Mission <
http://leamhall.blogspot.com/>