On Mon, 2008-02-18 at 16:43 -0800, Todd Zullinger wrote:
Daniel B. Thurman wrote:
> 1) execstack -c /usr/lib/php/modules/pdf.so
> <nothing>
> 2) grep execstack /var/log/audit/audit.log | grep audit2allow -m myphp
                                        this > ^^^^

causes this:

> grep: invalid max count

You're calling grep rather than audit2allow as intended.  Remove the
grep after the pipe.


Ok....

I tried:

1) grep execstack /var/log/audit/audit.log | audit2allow -m myphp

module myphp 1.0;

2) semodule -i myphp.pp
semodule:  Could not read file 'myphp.pp': No such file or directory

Seems that the myphp.pp file is never created, at least I cannot
find it....