On Tuesday, June 11, 2013 04:04:54 PM LC Bruzenak wrote:
I was playing with audit rules using keys with spaces.
Is the following expected (ignore the logic; was just testing the returns)?
# auditctl -l -k lsmod
LIST_RULES: exit,always watch=/sbin/lsmod perm=x key=lsmod kernel
LIST_RULES: exit,always watch=/bin/ping perm=x key=lsmod ping
What are you expecting? I can make it not accept keys with spaces. I don't
think putting spaces in keys is a good idea.
-Steve