Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Auditbeat] Cherry-pick #10796 to 6.7: Package dataset: Make librpm code compatible across CentOS 6.x, 7.x, and Fedora 29 #10907

Merged
merged 1 commit into from
Feb 25, 2019

Conversation

cwurm
Copy link
Contributor

@cwurm cwurm commented Feb 22, 2019

Cherry-pick of PR #10796 to 6.7 branch. Original message:

Librpm version 4.14.2.1 on Fedora 29 no longer contains the headerGetEntry method we are currently using. It was deprecated and then removed in version 4.14 (rpm-software-management/rpm@c68fa9a).

Also, the much older version 4.8.0 of librpm on CentOS 6.10 (Final) does not yet contain newer data structures for tags like rpm_tag_t/rpmTag/rpmTagVal.

This PR makes two changes that should allow this code to work on all three distros (CentOS 6.x, 7.x, Fedora 29 - and hopefully anything in between):

  1. Use headerGetString/headerGetNumber instead of headerGetEntry.
  2. Use int32_t instead of rpm_tag_t/rpmTag/rpmTagVal. Luckily, this seems to work on all three distros. I'd prefer something like a typedef, but unfortunately, C99 does not allow repeating a typedef (C11 does) and so backporting them is not easily possible.

It also makes the code more lenient with errors during data collection: Only when no package name can be found do we return an error.

Together with #10694 this will hopefully allow RPM package collection to work well.

…S 6.x, 7.x, and Fedora 29 (elastic#10796)

Librpm version 4.14.2.1 on Fedora 29 no longer contains the `headerGetEntry` method we are currently using. It was deprecated and then removed in version 4.14 (rpm-software-management/rpm@c68fa9a).

Also, the much older version 4.8.0 of librpm on CentOS 6.10 (Final) does not yet contain newer data structures for tags like `rpm_tag_t/rpmTag/rpmTagVal`.

This PR makes two changes that should allow this code to work on all three distros (CentOS 6.x, 7.x, Fedora 29 - and hopefully anything in between):

1. Use `headerGetString/headerGetNumber` instead of `headerGetEntry`.
2. Use `int32_t` instead of `rpm_tag_t/rpmTag/rpmTagVal`. Luckily, this seems to work on all three distros. I'd prefer something like a typedef, but unfortunately, C99 does not allow repeating a typedef (C11 does) and so backporting them is not easily possible.

It also makes the code more lenient with errors during data collection: Only when no package name can be found do we return an error.

Together with elastic#10694 this will hopefully allow RPM package collection to work well.

(cherry picked from commit e7ea5d7)
@cwurm cwurm changed the title Cherry-pick #10796 to 6.7: [Auditbeat] Package dataset: Make librpm code compatible across CentOS 6.x, 7.x, and Fedora 29 [Auditbeat] Cherry-pick #10796 to 6.7: Package dataset: Make librpm code compatible across CentOS 6.x, 7.x, and Fedora 29 Feb 22, 2019
@elasticmachine
Copy link
Collaborator

Pinging @elastic/secops

@cwurm cwurm merged commit da41f72 into elastic:6.7 Feb 25, 2019
@cwurm cwurm deleted the backport_10796_6.7 branch February 25, 2019 21:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants