From owner-freebsd-security@FreeBSD.ORG Thu Mar 4 19:53:15 2010 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 050D81065670 for ; Thu, 4 Mar 2010 19:53:15 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (pyroxene.sentex.ca [199.212.134.18]) by mx1.freebsd.org (Postfix) with ESMTP id C847A8FC08 for ; Thu, 4 Mar 2010 19:53:14 +0000 (UTC) Received: from mdt-xp.sentex.net (simeon.sentex.ca [192.168.43.27]) by lava.sentex.ca (8.14.3/8.14.3) with ESMTP id o24JrDhi038522 for ; Thu, 4 Mar 2010 14:53:13 -0500 (EST) (envelope-from mike@sentex.net) Message-Id: <201003041953.o24JrDhi038522@lava.sentex.ca> X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Thu, 04 Mar 2010 14:53:24 -0500 To: freebsd-security@freebsd.org From: Mike Tancsa Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed Subject: tripwire and device numbers X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 04 Mar 2010 19:53:15 -0000 While getting a box ready for deployment, I noticed on two occasions, I would get some exception reports flagging all files as the underlying device number through reboots had changed. Is this "normal" for Tripwire and FreeBSD ? (RELENG_7) The file system is on da0 at twa0 bus 0 target 0 lun 0 da0: Fixed Direct Access SCSI-5 device da0: 100.000MB/s transfers da0: 238408MB (488259584 512 byte sectors: 255H 63S/T 30392C) SMP: AP CPU #1 Launched! eg. Rule Name: Local files (/usr/local/sbin) Severity Level: 66 ------------------------------------------------------------------------------- ---------------------------------------- Modified Objects: 10 ---------------------------------------- Modified object name: /usr/local/sbin Property: Expected Observed ------------- ----------- ----------- Object Type Directory Directory * Device Number 92 98 Inode Number 2637949 2637949 Mode drwxr-xr-x drwxr-xr-x Num Links 2 2 UID root (0) root (0) GID wheel (0) wheel (0) Size 512 512 Modify Time Wed Mar 3 15:24:02 2010 Wed Mar 3 15:24:02 2010 Blocks 4 4 ---Mike -------------------------------------------------------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet since 1994 www.sentex.net Cambridge, Ontario Canada www.sentex.net/mike