Package: dpkg
Version: 1.19.7
Severity: wishlist
Usertags: audit

Hi,

It would be nice if dpkg was logging audit events when packages are
installed/updated/removed/...

The type of the message is AUDIT_SOFTWARE_UPDATE, the content is not
documented, AFAICS, the messages look something like:

  op=install sw="ntpdate-4.2.6p5-25.el7_3.2.x86_64" sw_type=rpm key_enforce=0 
gpg_res=0 root_dir="/"

rpm is already doing that, and the code is available at 
https://github.com/rpm-software-management/rpm/blob/master/plugins/audit.c

Kind regards,

Laurent Bigonville

-- Package-specific info:
System tainted due to merged-usr-via-symlinks.

-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 
'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.19.0-5-amd64 (SMP w/8 CPU cores)
Kernel taint flags: TAINT_FIRMWARE_WORKAROUND
Locale: LANG=fr_BE.UTF-8, LC_CTYPE=fr_BE.UTF-8 (charmap=UTF-8), 
LANGUAGE=fr_BE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: SELinux: enabled - Mode: Permissive - Policy name: refpolicy

Versions of packages dpkg depends on:
ii  libbz2-1.0   1.0.6-9.1
ii  libc6        2.28-10
ii  liblzma5     5.2.4-1
ii  libselinux1  2.9-2
ii  tar          1.30+dfsg-6
ii  zlib1g       1:1.2.11.dfsg-1

dpkg recommends no packages.

Versions of packages dpkg suggests:
ii  apt            1.8.2
pn  debsig-verify  <none>

-- no debconf information

Reply via email to