From owner-freebsd-security@FreeBSD.ORG Fri Mar 5 12:48:13 2010 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2B730106564A for ; Fri, 5 Mar 2010 12:48:13 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (pyroxene.sentex.ca [199.212.134.18]) by mx1.freebsd.org (Postfix) with ESMTP id ED6F68FC1C for ; Fri, 5 Mar 2010 12:48:12 +0000 (UTC) Received: from mdt-xp.sentex.net (simeon.sentex.ca [192.168.43.27]) by lava.sentex.ca (8.14.3/8.14.3) with ESMTP id o25Cm9Bd044380; Fri, 5 Mar 2010 07:48:09 -0500 (EST) (envelope-from mike@sentex.net) Message-Id: <201003051248.o25Cm9Bd044380@lava.sentex.ca> X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Fri, 05 Mar 2010 07:48:20 -0500 To: Dag-Erling =?iso-8859-1?Q?Sm=C3=B8rgrav?= , "Poul-Henning Kamp" From: Mike Tancsa In-Reply-To: <863a0f569g.fsf@ds4.des.no> References: <3402.1267736139@critter.freebsd.dk> <863a0f569g.fsf@ds4.des.no> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1"; format=flowed Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: tripwire and device numbers X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 05 Mar 2010 12:48:13 -0000 At 06:59 AM 3/5/2010, Dag-Erling Sm=C3=B8rgrav wrote: >"Poul-Henning Kamp" writes: > > Mike Tancsa writes: > > > While getting a box ready for deployment, I noticed on two > > > occasions, I would get some exception reports flagging all files as > > > the underlying device number through reboots had changed. Is this > > > "normal" for Tripwire and FreeBSD ? (RELENG_7) > > Yes, device numbers in freebsd carry no meaning, unless it is a compat > > /dev directory to boot ancient systems (SunOS, very old FreeBSD etc) > > diskless. > > > > In general, tripwire should ignore devfs and possibly all pseudo-fs > > mount-points. > >Nothing to do with devfs; IIUC, tripwire is complaining about st.st_dev >on regular files and directories. Correct. It was upset by just regular files and=20 directories on regular file systems in /usr/bin /sbin etc. ---Mike >DES >-- >Dag-Erling Sm=C3=B8rgrav - des@des.no -------------------------------------------------------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet since 1994 www.sentex.net Cambridge, Ontario Canada www.sentex.net/mike