Audit still active even with disabled service

i’ve disabled the annoying audit-service because it’s spamming the dmesg-queue but even with disabled service it still spams up the queue.
what’s wrong with this os ?

     Loaded: loaded (/usr/lib/systemd/system/auditd.service; disabled; vendor preset: disabled)
     Active: inactive (dead)
       Docs: man:auditd(8)
             https://github.com/linux-audit/audit-documentation

From Audit framework - ArchWiki

Note: In order to disable audit completely and suppress audit messages from appearing in journal you may set audit=0 as kernel parameter and/or mask systemd-journald-audit.socket .

2 Likes

i remember, i already did that and updated grub. here’s my grub

GRUB_DEFAULT=saved
GRUB_TIMEOUT=10
GRUB_TIMEOUT_STYLE=hidden
GRUB_DISTRIBUTOR="Manjaro"
GRUB_CMDLINE_LINUX_DEFAULT="apparmor=1 security=apparmor usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0 btusb.enable_autosuspend=n udev.log_priority=3"
GRUB_CMDLINE_LINUX="video=LVDS-0:d video=LVDS-1:d video=eDP-1-1:d VGA-0:e VGA-1:e video=HDMI-0:e"
GRUB_CMDLINE_LINUX="audit=0"
GRUB_CMDLINE_LINUX="psmouse.synaptics_intertouch=1"



# If you want to enable the save default function, uncomment the following
# line, and set GRUB_DEFAULT to saved.
GRUB_SAVEDEFAULT=true

# Preload both GPT and MBR modules so that they are not missed
GRUB_PRELOAD_MODULES="part_gpt part_msdos"

# Uncomment to enable booting from LUKS encrypted devices
#GRUB_ENABLE_CRYPTODISK=y

# Uncomment to use basic console
GRUB_TERMINAL_INPUT=console

# Uncomment to disable graphical terminal
#GRUB_TERMINAL_OUTPUT=console

# The resolution used on graphical terminal
# note that you can use only modes which your graphic card supports via VBE
# you can see them in real GRUB with the command 'videoinfo'
GRUB_GFXMODE=auto

# Uncomment to allow the kernel use the same resolution used by grub
GRUB_GFXPAYLOAD_LINUX=keep

# Uncomment if you want GRUB to pass to the Linux kernel the old parameter
# format "root=/dev/xxx" instead of "root=/dev/disk/by-uuid/xxx"
#GRUB_DISABLE_LINUX_UUID=true

# Uncomment to disable generation of recovery mode menu entries
GRUB_DISABLE_RECOVERY=true

# Uncomment and set to the desired menu colors.  Used by normal and wallpaper
# modes only.  Entries specified as foreground/background.
GRUB_COLOR_NORMAL="light-gray/black"
GRUB_COLOR_HIGHLIGHT="green/black"

# Uncomment one of them for the gfx desired, a image background or a gfxtheme
#GRUB_BACKGROUND="/usr/share/grub/background.png"
GRUB_THEME="/usr/share/grub/themes/manjaro/theme.txt"

# Uncomment to get a beep at GRUB start
#GRUB_INIT_TUNE="480 440 1"

# Uncomment this option to enable os-prober execution in the grub-mkconfig command
GRUB_DISABLE_OS_PROBER=false

and here’s my inxi

System:
  Kernel: 5.16.14-1-MANJARO x86_64 bits: 64 compiler: gcc v: 11.2.0
    parameters: BOOT_IMAGE=/boot/vmlinuz-5.16-x86_64
    root=UUID=f18f88bc-4ad6-4f4d-85b7-9892387693dc rw
    psmouse.synaptics_intertouch=1 apparmor=1 security=apparmor
    usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0
    btusb.enable_autosuspend=n udev.log_priority=3
  Desktop: KDE Plasma 5.24.3 tk: Qt 5.15.3 wm: kwin_x11 vt: 1 dm: SDDM
    Distro: Manjaro Linux base: Arch Linux
Machine:
  Type: Laptop System: Acer product: Predator PH317-52 v: V1.19
    serial: <superuser required>
  Mobo: CFL model: Sienna_CFS v: V1.19 serial: <superuser required>
    UEFI: Insyde v: 1.19 date: 07/13/2018
Battery:
  ID-1: BAT1 charge: 46.4 Wh (100.0%) condition: 46.4/48.9 Wh (94.9%)
    volts: 16.9 min: 15.2 model: LG PABAS0241231 type: Li-ion serial: <filter>
    status: Full
  Device-1: hid-58:1f:aa:ec:10:cf-battery model: Siegberts Maus serial: N/A
    charge: N/A status: Discharging
CPU:
  Info: model: Intel Core i5-8300H bits: 64 type: MT MCP arch: Coffee Lake
    family: 6 model-id: 0x9E (158) stepping: 0xA (10) microcode: 0xEC
  Topology: cpus: 1x cores: 4 tpc: 2 threads: 8 smt: enabled cache:
    L1: 256 KiB desc: d-4x32 KiB; i-4x32 KiB L2: 1024 KiB desc: 4x256 KiB
    L3: 8 MiB desc: 1x8 MiB
  Speed (MHz): avg: 3990 high: 4000 min/max: 800/4000 scaling:
    driver: intel_pstate governor: performance cores: 1: 3989 2: 3988 3: 3995
    4: 3973 5: 4000 6: 3991 7: 4000 8: 3984 bogomips: 36812
  Flags: avx avx2 ht lm nx pae sse sse2 sse3 sse4_1 sse4_2 ssse3 vmx
  Vulnerabilities:
  Type: itlb_multihit status: KVM: VMX disabled
  Type: l1tf
    mitigation: PTE Inversion; VMX: conditional cache flushes, SMT vulnerable
  Type: mds mitigation: Clear CPU buffers; SMT vulnerable
  Type: meltdown mitigation: PTI
  Type: spec_store_bypass
    mitigation: Speculative Store Bypass disabled via prctl
  Type: spectre_v1
    mitigation: usercopy/swapgs barriers and __user pointer sanitization
  Type: spectre_v2 mitigation: Retpolines, IBPB: conditional, IBRS_FW,
    STIBP: conditional, RSB filling
  Type: srbds mitigation: Microcode
  Type: tsx_async_abort status: Not affected
Graphics:
  Device-1: Intel CoffeeLake-H GT2 [UHD Graphics 630]
    vendor: Acer Incorporated ALI driver: i915 v: kernel ports: active: eDP-1
    empty: none bus-ID: 00:02.0 chip-ID: 8086:3e9b class-ID: 0300
  Device-2: NVIDIA GP107M [GeForce GTX 1050 Ti Mobile]
    vendor: Acer Incorporated ALI driver: nvidia v: 510.54
    alternate: nouveau,nvidia_drm pcie: gen: 3 speed: 8 GT/s lanes: 16 ports:
    active: none off: HDMI-A-1 empty: none bus-ID: 01:00.0 chip-ID: 10de:1c8c
    class-ID: 0300
  Device-3: Realtek HD WebCam type: USB driver: uvcvideo bus-ID: 1-5:3
    chip-ID: 0bda:5621 class-ID: 0e02 serial: <filter>
  Display: x11 server: X.Org v: 1.21.1.3 compositor: kwin_x11 driver: X:
    loaded: modesetting,nvidia gpu: i915 display-ID: :0 screens: 1
  Screen-1: 0 s-res: 4412x1440 s-dpi: 96 s-size: 1166x380mm (45.9x15.0")
    s-diag: 1226mm (48.3")
  Monitor-1: HDMI-0 pos: primary,left res: 2560x1440 hz: 60 dpi: 105
    size: 621x341mm (24.4x13.4") diag: 708mm (27.9")
  Monitor-2: eDP-1-1 pos: right res: 1680x1050 hz: 60 dpi: 112
    size: 381x214mm (15.0x8.4") diag: 437mm (17.2")
  OpenGL: renderer: NVIDIA GeForce GTX 1050 Ti/PCIe/SSE2
    v: 4.6.0 NVIDIA 510.54 direct render: Yes
Audio:
  Device-1: Intel Cannon Lake PCH cAVS vendor: Acer Incorporated ALI
    driver: snd_hda_intel v: kernel
    alternate: snd_soc_skl,snd_sof_pci_intel_cnl bus-ID: 00:1f.3
    chip-ID: 8086:a348 class-ID: 0403
  Device-2: NVIDIA GP107GL High Definition Audio
    vendor: Acer Incorporated ALI driver: snd_hda_intel v: kernel pcie: gen: 3
    speed: 8 GT/s lanes: 16 bus-ID: 01:00.1 chip-ID: 10de:0fb9 class-ID: 0403
  Sound Server-1: ALSA v: k5.16.14-1-MANJARO running: yes
  Sound Server-2: JACK v: 1.9.20 running: no
  Sound Server-3: PulseAudio v: 15.0 running: no
  Sound Server-4: PipeWire v: 0.3.48 running: yes
Drives:
  Local Storage: total: 953.88 GiB used: 300.76 GiB (31.5%)
  SMART Message: Unable to run smartctl. Root privileges required.
  ID-1: /dev/nvme0n1 maj-min: 259:0 vendor: Samsung
    model: SSD 970 PRO 512GB size: 476.94 GiB block-size: physical: 512 B
    logical: 512 B speed: 31.6 Gb/s lanes: 4 type: SSD serial: <filter>
    rev: 1B2QEXP7 temp: 52.9 C scheme: GPT
  ID-2: /dev/sda maj-min: 8:0 vendor: SK Hynix model: HFS512G39TND-N210A
    size: 476.94 GiB block-size: physical: 4096 B logical: 512 B
    speed: 6.0 Gb/s type: SSD serial: <filter> rev: 1P10 scheme: GPT
Partition:
  ID-1: / raw-size: 476.64 GiB size: 468.16 GiB (98.22%)
    used: 135.06 GiB (28.8%) fs: ext4 dev: /dev/nvme0n1p2 maj-min: 259:2
  ID-2: /boot/efi raw-size: 300 MiB size: 299.4 MiB (99.80%)
    used: 280 KiB (0.1%) fs: vfat dev: /dev/nvme0n1p1 maj-min: 259:1
Swap:
  Alert: No swap data was found.
Sensors:
  System Temperatures: cpu: 66.0 C pch: 64.0 C mobo: N/A gpu: nvidia
    temp: 55 C
  Fan Speeds (RPM): N/A
Info:
  Processes: 270 Uptime: 3h 18m wakeups: 3 Memory: 31.2 GiB
  used: 20.5 GiB (65.7%) Init: systemd v: 250 tool: systemctl Compilers:
  gcc: 11.2.0 clang: 13.0.1 Packages: pacman: 1653 lib: 470 Shell: Bash
  v: 5.1.16 running-in: konsole inxi: 3.3.13

but you’re right what the heck is going on ? the parameter isn’t loaded

[    0.000000] microcode: microcode updated early to revision 0xec, date = 2021-04-28
[    0.000000] Linux version 5.16.14-1-MANJARO (builduser@fv-az121-163) (gcc (GCC) 11.2.0, GNU ld (GNU Binutils) 2.38) #1 SMP PREEMPT Fri Mar 11 14:12:18 UTC 2022
[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.16-x86_64 root=UUID=f18f88bc-4ad6-4f4d-85b7-9892387693dc rw psmouse.synaptics_intertouch=1 apparmor=1 security=apparmor usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0 btusb.enable_autosuspend=n udev.log_priority=3
[    0.000000] x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers'
[    0.000000] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers'
[    0.000000] x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers'
[    0.000000] x86/fpu: Supporting XSAVE feature 0x008: 'MPX bounds registers'
[    0.000000] x86/fpu: Supporting XSAVE feature 0x010: 'MPX CSR'
[    0.000000] x86/fpu: xstate_offset[2]:  576, xstate_sizes[2]:  256
[    0.000000] x86/fpu: xstate_offset[3]:  832, xstate_sizes[3]:   64
[    0.000000] x86/fpu: xstate_offset[4]:  896, xstate_sizes[4]:   64
[    0.000000] x86/fpu: Enabled xstate features 0x1f, context size is 960 bytes, using 'compacted' format.
...
....
...
[    0.162146] DMA: preallocated 4096 KiB GFP_KERNEL pool for atomic allocations
[    0.162146] DMA: preallocated 4096 KiB GFP_KERNEL|GFP_DMA pool for atomic allocations
[    0.162218] DMA: preallocated 4096 KiB GFP_KERNEL|GFP_DMA32 pool for atomic allocations
[    0.162228] audit: initializing netlink subsys (disabled)
[    0.162240] audit: type=2000 audit(1647368273.036:1): state=initialized audit_enabled=0 res=1

as you can see at boot

[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.16-x86_64 root=UUID=f18f88bc-4ad6-4f4d-85b7-9892387693dc rw psmouse.synaptics_intertouch=1 apparmor=1 security=apparmor usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0 btusb.enable_autosuspend=n udev.log_priority=3

how can this be ?

Can you try adding that parameter to GRUB_CMDLINE_LINUX_DEFAULT instead of GRUB_CMDLINE_LINUX.

Also try these commands:

systemctl stop systemd-journald-audit.socket 
systemctl disable systemd-journald-audit.socket

i’ll try, meanwhile i did a additional
sudo update-grub and sudo mkinitio -P but nothing changed, the parameter is still not accepted

[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.16-x86_64 root=UUID=f18f88bc-4ad6-4f4d-85b7-9892387693dc rw psmouse.synaptics_intertouch=1 apparmor=1 security=apparmor usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0 btusb.enable_autosuspend=n udev.log_priority=3

Did you miss this part above? :wink:

There’s a reason why the Arch wiki suggests to also mask the socket service. Sockets can be active even if the corresponding services are disabled and will start services on demand.

1 Like

think this did the trick

[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.16-x86_64 root=UUID=f18f88bc-4ad6-4f4d-85b7-9892387693dc rw psmouse.synaptics_intertouch=1 apparmor=1 security=apparmor usbcore.autosuspend=-1 nvidia-drm.modeset=1 video=HDMI-0 btusb.enable_autosuspend=n udev.log_priority=3 audit=0

actual there is no further spam inside dmesg after placing the parameter to the GRUB_CMDLINE_LINUX_DEFAULT line. but why doesn’t it work in a GRUB_CMDLINE_LINUX line-parameter instruction ? it’s useless to place it in there and that’s new to me.
Thanks for your help @ishaan2479 and @Yochanan

Thanks for this advice. I’ll write it right between my to ears and do a notie at my todo-list not t forget it ever again.

There really should be no difference booting normally.

GRUB_CMDLINE_LINUX_DEFAULT is only used in normal mode while GRUB_CMDLINE_LINUX is used in normal and recovery mode. See https://unix.stackexchange.com/questions/440961/grub-cmdline-linux-default-vs-grub-cmdline-linux


In the future, please edit your previous post if the option is available rather that posting twice in a row.

that was my impression too but there must be some difference because now it’s blocked as it should be. very curious.
and yes i have to read the editing notes how to create this side by side view, i didn’t knew that it’s possible.

P.S.: i also masked that spamming-service that no one on earth needs nor wants.

Remember: these lines do not add to GRUB_CMDLINE_LINUX but replace its value. Effectively you’re only using/applying the last one

GRUB_CMDLINE_LINUX="psmouse.synaptics_intertouch=1"
1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.