[Logcheck-commits] Frédéric Brière : i.d.s/kernel: added IPv6 support to "Treason uncloaked!" rule

Frédéric Brière fbriere-guest at alioth.debian.org
Thu Feb 18 00:16:35 UTC 2010


Module: logcheck
Branch: master
Commit: b520832855c2e9eec7a02ac9a0de415220417e43
URL:    http://git.debian.org/?p=logcheck/logcheck.git;a=commit;h=b520832855c2e9eec7a02ac9a0de415220417e43

Author: Frédéric Brière <fbriere at fbriere.net>
Date:   Wed Feb 17 19:12:27 2010 -0500

i.d.s/kernel: added IPv6 support to "Treason uncloaked!" rule

---

 debian/changelog                       |    4 ++++
 rulefiles/linux/ignore.d.server/kernel |    2 +-
 2 files changed, 5 insertions(+), 1 deletions(-)

diff --git a/debian/changelog b/debian/changelog
index cd40808..261047a 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -32,6 +32,10 @@ logcheck (1.3.7) UNRELEASED; urgency=low
     - added rule to ignore various sieve messages (stored mail, forwards,
       vacation replies and discards)
 
+  [ Frédéric Brière ]
+  * ignore.d.server/kernel:
+    - added IPv6 support to "Treason uncloaked!" rule (closes: #546004)
+
  -- Hannes von Haugwitz <hannes at vonhaugwitz.com>  Sun, 31 Jan 2010 20:13:27 +0100
 
 logcheck (1.3.6) unstable; urgency=low
diff --git a/rulefiles/linux/ignore.d.server/kernel b/rulefiles/linux/ignore.d.server/kernel
index 3fb1100..070d3bb 100644
--- a/rulefiles/linux/ignore.d.server/kernel
+++ b/rulefiles/linux/ignore.d.server/kernel
@@ -27,7 +27,7 @@
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? PCI: Setting latency timer of device [[:alnum:]:.]+ to [[:digit:]]+$
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? SCSI device [[:alnum:]]+: drive cache: write (through|back)$
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? SCSI subsystem initialized$
-^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? TCP: Treason uncloaked! Peer [.[:digit:]]{7,15}:[[:digit:]]{1,5}/[[:digit:]]{1,5} shrinks window [[:digit:]]+:[[:digit:]]+\. Repaired\.$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? TCP: Treason uncloaked! Peer [:.[:xdigit:]]+:[[:digit:]]{1,5}/[[:digit:]]{1,5} shrinks window [[:digit:]]+:[[:digit:]]+\. Repaired\.$
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? XFS mounting filesystem [[:alnum:]]+$
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? [[:alnum:][:space:]]+: probe of [:.[:xdigit:]]+ failed with error [-[:digit:]]+$
 ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel:( \[ *[[:digit:]]+\.[[:digit:]]+\])? [[:alnum:]]+: link up\.$




More information about the Logcheck-commits mailing list