Sure.
sys-usb:
Apr 10 13:12:33 sys-usb qrexec-agent[3157]: 2024-04-10 13:12:33.688 qrexec-agent[3157]: qrexec-agent-data.c:244:handle_new_process_common: executed: root:QUBESRPC qubes.USB+2-1.1 <targetvm> (pid 3159)
Apr 10 13:12:33 sys-usb qrexec-agent[3159]: PAM unable to dlopen(/usr/lib64/security/pam_sss.so): /usr/lib64/security/pam_sss.so: cannot open shared object file: No such file or directory
Apr 10 13:12:33 sys-usb qrexec-agent[3159]: PAM adding faulty module: /usr/lib64/security/pam_sss.so
Apr 10 13:12:33 sys-usb audit[3159]: USER_AUTH pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:authentication grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb audit[3159]: CRED_ACQ pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb kernel: audit: type=1100 audit(1712747553.690:294): pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:authentication grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb kernel: audit: type=1103 audit(1712747553.690:295): pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb systemd[1]: Created slice user-0.slice - User Slice of UID 0.
Apr 10 13:12:33 sys-usb systemd[1]: Starting user-runtime-dir@0.service - User Runtime Directory /run/user/0...
Apr 10 13:12:33 sys-usb systemd[1]: Finished user-runtime-dir@0.service - User Runtime Directory /run/user/0.
Apr 10 13:12:33 sys-usb audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb systemd[1]: Starting user@0.service - User Manager for UID 0...
Apr 10 13:12:33 sys-usb kernel: audit: type=1130 audit(1712747553.711:296): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb (systemd)[3161]: PAM unable to dlopen(/usr/lib64/security/pam_sss.so): /usr/lib64/security/pam_sss.so: cannot open shared object file: No such file or directory
Apr 10 13:12:33 sys-usb (systemd)[3161]: PAM adding faulty module: /usr/lib64/security/pam_sss.so
Apr 10 13:12:33 sys-usb audit[3161]: USER_ACCT pid=3161 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb kernel: audit: type=1101 audit(1712747553.714:297): pid=3161 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb kernel: audit: type=1103 audit(1712747553.714:298): pid=3161 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
Apr 10 13:12:33 sys-usb kernel: audit: type=1006 audit(1712747553.714:299): pid=3161 uid=0 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=5 res=1
Apr 10 13:12:33 sys-usb audit[3161]: CRED_ACQ pid=3161 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=1 success=yes exit=1 a0=8 a1=7fffe19bb340 a2=1 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="(systemd)" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb kernel: audit: type=1300 audit(1712747553.714:299): arch=c000003e syscall=1 success=yes exit=1 a0=8 a1=7fffe19bb340 a2=1 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="(systemd)" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb kernel: audit: type=1327 audit(1712747553.714:299): proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit[3161]: USER_START pid=3161 uid=0 auid=0 ses=5 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb (systemd)[3161]: pam_unix(systemd-user:session): session opened for user root(uid=0) by (uid=0)
Apr 10 13:12:33 sys-usb kernel: audit: type=1105 audit(1712747553.716:300): pid=3161 uid=0 auid=0 ses=5 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb audit: BPF prog-id=92 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3fb90 a2=90 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=92 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3fc70 a2=90 a3=200000008 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=93 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3fc30 a2=90 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=93 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3fc30 a2=0 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=94 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3e9c0 a2=74 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=94 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3e9c0 a2=74 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=95 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3eb30 a2=80 a3=7ffd63e3ec20 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=95 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3eb30 a2=0 a3=7ffd63e3ec20 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=96 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3f9b0 a2=80 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=96 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3f9b0 a2=0 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb kernel: audit: type=1334 audit(1712747553.724:301): prog-id=92 op=LOAD
Apr 10 13:12:33 sys-usb audit: BPF prog-id=97 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=9 a0=5 a1=7ffd63e3f730 a2=40 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=97 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=9 a1=7ffd63e3f730 a2=40 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=98 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffd63e3f070 a2=80 a3=4b items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=99 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=12 a0=5 a1=7ffd63e3f070 a2=80 a3=4b items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=98 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=b a1=9 a2=58485ffb6960 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=99 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=c a1=58485ffaf010 a2=1 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=100 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3eb30 a2=80 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=100 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3eb30 a2=0 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=101 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffd63e3f960 a2=80 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=101 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=8 a1=7ffd63e3f960 a2=0 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=102 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffd63e3f6f0 a2=80 a3=5 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=102 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=b a1=7ffd63e3f6f0 a2=0 a3=5 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=103 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffd63e3eee0 a2=80 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=103 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=b a1=7ffd63e3eee0 a2=0 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=104 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffd63e3f020 a2=80 a3=13 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=105 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=13 a0=5 a1=7ffd63e3ef20 a2=80 a3=2 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=105 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=d a1=7ffd63e3ef50 a2=0 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=106 op=LOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=321 success=yes exit=12 a0=5 a1=7ffd63e3f020 a2=80 a3=13 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=104 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=b a1=9 a2=58485ffb7ee0 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb audit: BPF prog-id=106 op=UNLOAD
Apr 10 13:12:33 sys-usb audit[3161]: SYSCALL arch=c000003e syscall=3 success=yes exit=0 a0=c a1=58485ffaf010 a2=3 a3=0 items=0 ppid=1 pid=3161 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=5 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 sys-usb audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 sys-usb systemd[3161]: Queued start job for default target default.target.
Apr 10 13:12:33 sys-usb systemd[3161]: Created slice app.slice - User Application Slice.
Apr 10 13:12:33 sys-usb systemd[3161]: grub-boot-success.timer - Mark boot as successful after the user session has run 2 minutes was skipped because of an unmet condition check (ConditionUser=!@system).
Apr 10 13:12:33 sys-usb systemd[3161]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories.
Apr 10 13:12:33 sys-usb systemd[3161]: Reached target paths.target - Paths.
Apr 10 13:12:33 sys-usb systemd[3161]: Reached target timers.target - Timers.
Apr 10 13:12:33 sys-usb systemd[3161]: Starting dbus.socket - D-Bus User Message Bus Socket...
Apr 10 13:12:33 sys-usb systemd[3161]: pulseaudio.socket - Sound System was skipped because of an unmet condition check (ConditionPathExists=/var/run/qubes-service/pulseaudio-vanilla-broken).
Apr 10 13:12:33 sys-usb systemd[3161]: Starting systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories...
Apr 10 13:12:33 sys-usb systemd[3161]: Finished systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories.
Apr 10 13:12:33 sys-usb systemd[3161]: Listening on dbus.socket - D-Bus User Message Bus Socket.
Apr 10 13:12:33 sys-usb systemd[3161]: Reached target sockets.target - Sockets.
Apr 10 13:12:33 sys-usb systemd[3161]: Reached target basic.target - Basic System.
Apr 10 13:12:33 sys-usb systemd[3161]: Reached target default.target - Main User Target.
Apr 10 13:12:33 sys-usb systemd[3161]: Startup finished in 138ms.
Apr 10 13:12:33 sys-usb systemd[1]: Started user@0.service - User Manager for UID 0.
Apr 10 13:12:33 sys-usb audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb systemd[1]: Started session-c7.scope - Session c7 of User root.
Apr 10 13:12:33 sys-usb qrexec-agent[3159]: pam_unix(qrexec:session): session opened for user root(uid=0) by (uid=0)
Apr 10 13:12:33 sys-usb audit[3159]: USER_START pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_open grantors=pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_umask,pam_lastlog acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb qubes.USB+2-1.1-<targetvm>[3201]: Invalid bus path /sys/bus/usb/devices/2-1.1
Apr 10 13:12:33 sys-usb qrexec-agent[3159]: pam_unix(qrexec:session): session closed for user root
Apr 10 13:12:33 sys-usb audit[3159]: USER_END pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_close grantors=pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_umask,pam_lastlog acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb audit[3159]: CRED_DISP pid=3159 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 sys-usb qrexec-agent[3157]: 2024-04-10 13:12:33.919 qrexec-agent[3157]: qrexec-agent-data.c:272:handle_new_process_common: pid 3159 exited with 1
Apr 10 13:12:33 sys-usb systemd[1]: session-c7.scope: Deactivated successfully.
Apr 10 13:12:43 sys-usb systemd[1]: Stopping user@0.service - User Manager for UID 0...
Apr 10 13:12:43 sys-usb systemd[3161]: Activating special unit exit.target...
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped target default.target - Main User Target.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped target basic.target - Basic System.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped target paths.target - Paths.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped target sockets.target - Sockets.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped target timers.target - Timers.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories.
Apr 10 13:12:43 sys-usb systemd[3161]: Closed dbus.socket - D-Bus User Message Bus Socket.
Apr 10 13:12:43 sys-usb systemd[3161]: Stopped systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories.
Apr 10 13:12:43 sys-usb systemd[3161]: Removed slice app.slice - User Application Slice.
Apr 10 13:12:43 sys-usb systemd[3161]: Reached target shutdown.target - Shutdown.
Apr 10 13:12:43 sys-usb systemd[3161]: Finished systemd-exit.service - Exit the Session.
Apr 10 13:12:43 sys-usb systemd[3161]: Reached target exit.target - Exit the Session.
Apr 10 13:12:43 sys-usb systemd[1]: user@0.service: Deactivated successfully.
Apr 10 13:12:43 sys-usb systemd[1]: Stopped user@0.service - User Manager for UID 0.
Apr 10 13:12:43 sys-usb audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:43 sys-usb kernel: kauditd_printk_skb: 93 callbacks suppressed
Apr 10 13:12:43 sys-usb kernel: audit: type=1131 audit(1712747563.972:335): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:43 sys-usb systemd[1]: Stopping user-runtime-dir@0.service - User Runtime Directory /run/user/0...
Apr 10 13:12:43 sys-usb systemd[1]: run-user-0.mount: Deactivated successfully.
Apr 10 13:12:43 sys-usb systemd[1]: user-runtime-dir@0.service: Deactivated successfully.
Apr 10 13:12:43 sys-usb systemd[1]: Stopped user-runtime-dir@0.service - User Runtime Directory /run/user/0.
Apr 10 13:12:43 sys-usb audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:43 sys-usb systemd[1]: Removed slice user-0.slice - User Slice of UID 0.
Apr 10 13:12:43 sys-usb kernel: audit: type=1131 audit(1712747563.988:336): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
:
Apr 10 13:12:33 <targetvm> qrexec-agent[2205]: 2024-04-10 13:12:33.460 qrexec-agent[2205]: qrexec-agent-data.c:244:handle_new_process_common: executed: root:QUBESRPC qubes.USBAttach dom0 (pid 2207)
Apr 10 13:12:33 <targetvm> qrexec-agent[2207]: PAM unable to dlopen(/usr/lib64/security/pam_sss.so): /usr/lib64/security/pam_sss.so: cannot open shared object file: No such file or directory
Apr 10 13:12:33 <targetvm> qrexec-agent[2207]: PAM adding faulty module: /usr/lib64/security/pam_sss.so
Apr 10 13:12:33 <targetvm> audit[2207]: USER_AUTH pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:authentication grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> audit[2207]: CRED_ACQ pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> kernel: audit: type=1100 audit(1712747553.463:340): pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:authentication grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> kernel: audit: type=1103 audit(1712747553.463:341): pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> systemd[1]: Created slice user-0.slice - User Slice of UID 0.
Apr 10 13:12:33 <targetvm> systemd[1]: Starting user-runtime-dir@0.service - User Runtime Directory /run/user/0...
Apr 10 13:12:33 <targetvm> systemd[1]: Finished user-runtime-dir@0.service - User Runtime Directory /run/user/0.
Apr 10 13:12:33 <targetvm> audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> kernel: audit: type=1130 audit(1712747553.479:342): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> systemd[1]: Starting user@0.service - User Manager for UID 0...
Apr 10 13:12:33 <targetvm> (systemd)[2209]: PAM unable to dlopen(/usr/lib64/security/pam_sss.so): /usr/lib64/security/pam_sss.so: cannot open shared object file: No such file or directory
Apr 10 13:12:33 <targetvm> (systemd)[2209]: PAM adding faulty module: /usr/lib64/security/pam_sss.so
Apr 10 13:12:33 <targetvm> audit[2209]: USER_ACCT pid=2209 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> audit[2209]: CRED_ACQ pid=2209 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=1 success=yes exit=1 a0=8 a1=7ffcdf92c480 a2=1 a3=0 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="(systemd)" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> kernel: audit: type=1101 audit(1712747553.482:343): pid=2209 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> kernel: audit: type=1103 audit(1712747553.482:344): pid=2209 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=? acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed'
Apr 10 13:12:33 <targetvm> kernel: audit: type=1006 audit(1712747553.482:345): pid=2209 uid=0 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=6 res=1
Apr 10 13:12:33 <targetvm> kernel: audit: type=1300 audit(1712747553.482:345): arch=c000003e syscall=1 success=yes exit=1 a0=8 a1=7ffcdf92c480 a2=1 a3=0 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="(systemd)" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> kernel: audit: type=1327 audit(1712747553.482:345): proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit[2209]: USER_START pid=2209 uid=0 auid=0 ses=6 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> (systemd)[2209]: pam_unix(systemd-user:session): session opened for user root(uid=0) by (uid=0)
Apr 10 13:12:33 <targetvm> kernel: audit: type=1105 audit(1712747553.483:346): pid=2209 uid=0 auid=0 ses=6 msg='op=PAM:session_open grantors=pam_selinux,pam_selinux,pam_loginuid,pam_keyinit,pam_namespace,pam_systemd_home,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=119 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f47a6f0 a2=90 a3=0 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=119 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=120 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f47a790 a2=90 a3=0 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=120 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=121 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f479520 a2=74 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=121 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=122 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f479690 a2=80 a3=7ffe7f479780 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=122 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=123 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f47a510 a2=80 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=123 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=124 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=9 a0=5 a1=7ffe7f47a290 a2=40 a3=0 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=124 op=UNLOAD
Apr 10 13:12:33 <targetvm> kernel: audit: type=1334 audit(1712747553.486:347): prog-id=119 op=LOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=125 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffe7f479bd0 a2=80 a3=4b items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=126 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=12 a0=5 a1=7ffe7f479bd0 a2=80 a3=4b items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=125 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=126 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=127 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f479690 a2=80 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=127 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=128 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=8 a0=5 a1=7ffe7f47a4c0 a2=80 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=128 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=129 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffe7f47a250 a2=80 a3=5 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=129 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=130 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffe7f479a40 a2=80 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=130 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=131 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=11 a0=5 a1=7ffe7f479b80 a2=80 a3=13 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=132 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=13 a0=5 a1=7ffe7f479a80 a2=80 a3=2 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=132 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=133 op=LOAD
Apr 10 13:12:33 <targetvm> audit[2209]: SYSCALL arch=c000003e syscall=321 success=yes exit=12 a0=5 a1=7ffe7f479b80 a2=80 a3=13 items=0 ppid=1 pid=2209 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=6 comm="systemd" exe="/usr/lib/systemd/systemd" key=(null)
Apr 10 13:12:33 <targetvm> audit: PROCTITLE proctitle="(systemd)"
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=131 op=UNLOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=133 op=UNLOAD
Apr 10 13:12:33 <targetvm> systemd[2209]: Queued start job for default target default.target.
Apr 10 13:12:33 <targetvm> systemd[2209]: Created slice app.slice - User Application Slice.
Apr 10 13:12:33 <targetvm> systemd[2209]: grub-boot-success.timer - Mark boot as successful after the user session has run 2 minutes was skipped because of an unmet condition check (ConditionUser=!@system).
Apr 10 13:12:33 <targetvm> systemd[2209]: Started systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories.
Apr 10 13:12:33 <targetvm> systemd[2209]: Reached target paths.target - Paths.
Apr 10 13:12:33 <targetvm> systemd[2209]: Reached target timers.target - Timers.
Apr 10 13:12:33 <targetvm> systemd[2209]: Starting dbus.socket - D-Bus User Message Bus Socket...
Apr 10 13:12:33 <targetvm> systemd[2209]: pulseaudio.socket - Sound System was skipped because of an unmet condition check (ConditionPathExists=/var/run/qubes-service/pulseaudio-vanilla-broken).
Apr 10 13:12:33 <targetvm> systemd[2209]: Starting systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories...
Apr 10 13:12:33 <targetvm> systemd[2209]: Finished systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories.
Apr 10 13:12:33 <targetvm> systemd[2209]: Listening on dbus.socket - D-Bus User Message Bus Socket.
Apr 10 13:12:33 <targetvm> systemd[2209]: Reached target sockets.target - Sockets.
Apr 10 13:12:33 <targetvm> systemd[2209]: Reached target basic.target - Basic System.
Apr 10 13:12:33 <targetvm> systemd[2209]: Reached target default.target - Main User Target.
Apr 10 13:12:33 <targetvm> systemd[2209]: Startup finished in 76ms.
Apr 10 13:12:33 <targetvm> systemd[1]: Started user@0.service - User Manager for UID 0.
Apr 10 13:12:33 <targetvm> audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> systemd[1]: Started session-c8.scope - Session c8 of User root.
Apr 10 13:12:33 <targetvm> qrexec-agent[2207]: pam_unix(qrexec:session): session opened for user root(uid=0) by (uid=0)
Apr 10 13:12:33 <targetvm> audit[2207]: USER_START pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_open grantors=pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_umask,pam_lastlog acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=134 op=LOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=135 op=LOAD
Apr 10 13:12:33 <targetvm> audit: BPF prog-id=136 op=LOAD
Apr 10 13:12:33 <targetvm> systemd[1]: Starting systemd-hostnamed.service - Hostname Service...
Apr 10 13:12:33 <targetvm> systemd[1]: Started systemd-hostnamed.service - Hostname Service.
Apr 10 13:12:33 <targetvm> audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> qrexec-agent[2207]: pam_unix(qrexec:session): session closed for user root
Apr 10 13:12:33 <targetvm> audit[2207]: USER_END pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_close grantors=pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_umask,pam_lastlog acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> audit[2207]: CRED_DISP pid=2207 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:setcred grantors=pam_rootok acct="root" exe="/usr/lib/qubes/qrexec-agent" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:33 <targetvm> qrexec-agent[2205]: 2024-04-10 13:12:33.960 qrexec-agent[2205]: qrexec-agent-data.c:272:handle_new_process_common: pid 2207 exited with 1
Apr 10 13:12:33 <targetvm> systemd[1]: session-c8.scope: Deactivated successfully.
Apr 10 13:12:44 <targetvm> systemd[1]: Stopping user@0.service - User Manager for UID 0...
Apr 10 13:12:44 <targetvm> systemd[2209]: Activating special unit exit.target...
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped target default.target - Main User Target.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped target basic.target - Basic System.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped target paths.target - Paths.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped target sockets.target - Sockets.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped target timers.target - Timers.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped systemd-tmpfiles-clean.timer - Daily Cleanup of User's Temporary Directories.
Apr 10 13:12:44 <targetvm> systemd[2209]: Closed dbus.socket - D-Bus User Message Bus Socket.
Apr 10 13:12:44 <targetvm> systemd[2209]: Stopped systemd-tmpfiles-setup.service - Create User's Volatile Files and Directories.
Apr 10 13:12:44 <targetvm> systemd[2209]: Removed slice app.slice - User Application Slice.
Apr 10 13:12:44 <targetvm> systemd[2209]: Reached target shutdown.target - Shutdown.
Apr 10 13:12:44 <targetvm> systemd[2209]: Finished systemd-exit.service - Exit the Session.
Apr 10 13:12:44 <targetvm> systemd[2209]: Reached target exit.target - Exit the Session.
Apr 10 13:12:44 <targetvm> systemd[1]: user@0.service: Deactivated successfully.
Apr 10 13:12:44 <targetvm> systemd[1]: Stopped user@0.service - User Manager for UID 0.
Apr 10 13:12:44 <targetvm> audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:44 <targetvm> kernel: kauditd_printk_skb: 67 callbacks suppressed
Apr 10 13:12:44 <targetvm> kernel: audit: type=1131 audit(1712747564.093:385): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:44 <targetvm> systemd[1]: Stopping user-runtime-dir@0.service - User Runtime Directory /run/user/0...
Apr 10 13:12:44 <targetvm> systemd[1]: run-user-0.mount: Deactivated successfully.
Apr 10 13:12:44 <targetvm> systemd[1]: user-runtime-dir@0.service: Deactivated successfully.
Apr 10 13:12:44 <targetvm> systemd[1]: Stopped user-runtime-dir@0.service - User Runtime Directory /run/user/0.
Apr 10 13:12:44 <targetvm> audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Apr 10 13:12:44 <targetvm> systemd[1]: Removed slice user-0.slice - User Slice of UID 0.
Apr 10 13:12:44 <targetvm> kernel: audit: type=1131 audit(1712747564.111:386): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=user-runtime-dir@0 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'