The server_audit plugin doesn't consider proxy users when deciding whether to log an event based on server_audit_excl_users/server_audit_incl_users. This means that it doesn't work well with PAM user mapping:
https://mariadb.com/kb/en/library/user-and-group-mapping-with-pam/
It looks like the do_log_user() function might need to be extended to have two arguments--an original user and a proxy user.
https://github.com/MariaDB/server/blob/mariadb-10.4.4/plugin/server_audit/server_audit.c#L1479
https://github.com/MariaDB/server/blob/mariadb-10.4.4/plugin/server_audit/server_audit.c#L2025
https://github.com/MariaDB/server/blob/mariadb-10.4.4/plugin/server_audit/server_audit.c#L2041
https://github.com/MariaDB/server/blob/mariadb-10.4.4/plugin/server_audit/server_audit.c#L2555
For example, let's say that we are excluding the dba user from auditing:
MariaDB [(none)]> SHOW GLOBAL VARIABLES LIKE 'server_audit_%_users';
|
+-------------------------+-------+
|
| Variable_name | Value |
|
+-------------------------+-------+
|
| server_audit_excl_users | dba |
|
| server_audit_incl_users | |
|
+-------------------------+-------+
|
2 rows in set (0.00 sec)
|
And let's say that I log in as the bob PAM user who is mapped to the dba user:
[ec2-user@ip-172-30-0-249 ~]$ mysql -u bob
|
[mariadb] Password:
|
Welcome to the MariaDB monitor. Commands end with ; or \g.
|
Your MariaDB connection id is 16
|
Server version: 10.1.39-MariaDB MariaDB Server
|
|
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
|
|
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
|
|
MariaDB [(none)]> SELECT USER(), CURRENT_USER();
|
+---------------+----------------+
|
| USER() | CURRENT_USER() |
|
+---------------+----------------+
|
| bob@localhost | dba@% |
|
+---------------+----------------+
|
1 row in set (0.00 sec)
|
|
MariaDB [(none)]> SELECT 1;
|
+---+
|
| 1 |
|
+---+
|
| 1 |
|
+---+
|
1 row in set (0.00 sec)
|
|
MariaDB [(none)]> \q
|
Bye
|
This user's events will still be logged to the audit log:
20190511 22:57:01,ip-172-30-0-249.us-west-2.compute.internal,bob,localhost,16,0,CONNECT,,,0
|
20190511 22:57:01,ip-172-30-0-249.us-west-2.compute.internal,bob,localhost,16,36,QUERY,,'select @@version_comment limit 1',0
|
20190511 22:57:03,ip-172-30-0-249.us-west-2.compute.internal,bob,localhost,16,37,QUERY,,'SELECT USER(), CURRENT_USER()',0
|
20190511 22:57:08,ip-172-30-0-249.us-west-2.compute.internal,bob,localhost,16,38,QUERY,,'SELECT 1',0
|
20190511 22:57:10,ip-172-30-0-249.us-west-2.compute.internal,bob,localhost,16,0,DISCONNECT,,,0
|
This is because the server_audit plugin doesn't check the proxy user name against server_audit_excl_users/server_audit_incl_users. The plugin only checks the original user name.
To actually exclude this user from auditing, we would have to add the "bob" user name to server_audit_excl_users.
{"report":{"fcp":646.2999999523163,"ttfb":164.5,"pageVisibility":"visible","entityId":75973,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"7e2d6684-33c1-40e1-8460-dbc0e90c3e94","navigationType":0,"readyForUser":713.6999998092651,"redirectCount":0,"resourceLoadedEnd":806.2999999523163,"resourceLoadedStart":169.89999985694885,"resourceTiming":[{"duration":6,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":169.89999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":169.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":175.89999985694885,"responseStart":0,"secureConnectionStart":0},{"duration":5.900000095367432,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":170.19999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":170.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":176.09999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":62.59999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":170.29999995231628,"connectEnd":170.29999995231628,"connectStart":170.29999995231628,"domainLookupEnd":170.29999995231628,"domainLookupStart":170.29999995231628,"fetchStart":170.29999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":170.29999995231628,"responseEnd":232.89999985694885,"responseStart":232.89999985694885,"secureConnectionStart":170.29999995231628},{"duration":139.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":170.39999985694885,"connectEnd":170.39999985694885,"connectStart":170.39999985694885,"domainLookupEnd":170.39999985694885,"domainLookupStart":170.39999985694885,"fetchStart":170.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":170.39999985694885,"responseEnd":310.2999999523163,"responseStart":310.2999999523163,"secureConnectionStart":170.39999985694885},{"duration":143.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":170.5,"connectEnd":170.5,"connectStart":170.5,"domainLookupEnd":170.5,"domainLookupStart":170.5,"fetchStart":170.5,"redirectEnd":0,"redirectStart":0,"requestStart":170.5,"responseEnd":314,"responseStart":314,"secureConnectionStart":170.5},{"duration":143.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":170.59999990463257,"connectEnd":170.59999990463257,"connectStart":170.59999990463257,"domainLookupEnd":170.59999990463257,"domainLookupStart":170.59999990463257,"fetchStart":170.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":170.59999990463257,"responseEnd":314.5,"responseStart":314.5,"secureConnectionStart":170.59999990463257},{"duration":144.10000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":170.69999980926514,"connectEnd":170.69999980926514,"connectStart":170.69999980926514,"domainLookupEnd":170.69999980926514,"domainLookupStart":170.69999980926514,"fetchStart":170.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":170.69999980926514,"responseEnd":314.7999999523163,"responseStart":314.7999999523163,"secureConnectionStart":170.69999980926514},{"duration":144.39999985694885,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":170.79999995231628,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":170.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":315.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":144.79999995231628,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":170.89999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":170.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":315.69999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":144.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":170.89999985694885,"connectEnd":170.89999985694885,"connectStart":170.89999985694885,"domainLookupEnd":170.89999985694885,"domainLookupStart":170.89999985694885,"fetchStart":170.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":170.89999985694885,"responseEnd":315.2999999523163,"responseStart":315.2999999523163,"secureConnectionStart":170.89999985694885},{"duration":144.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":171.09999990463257,"connectEnd":171.09999990463257,"connectStart":171.09999990463257,"domainLookupEnd":171.09999990463257,"domainLookupStart":171.09999990463257,"fetchStart":171.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":171.09999990463257,"responseEnd":315.89999985694885,"responseStart":315.89999985694885,"secureConnectionStart":171.09999990463257},{"duration":557.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":176.69999980926514,"connectEnd":176.69999980926514,"connectStart":176.69999980926514,"domainLookupEnd":176.69999980926514,"domainLookupStart":176.69999980926514,"fetchStart":176.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":176.69999980926514,"responseEnd":734.5999999046326,"responseStart":734.5999999046326,"secureConnectionStart":176.69999980926514},{"duration":560.0999999046326,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":176.79999995231628,"connectEnd":176.79999995231628,"connectStart":176.79999995231628,"domainLookupEnd":176.79999995231628,"domainLookupStart":176.79999995231628,"fetchStart":176.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":176.79999995231628,"responseEnd":736.8999998569489,"responseStart":736.8999998569489,"secureConnectionStart":176.79999995231628},{"duration":287.90000009536743,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":448.19999980926514,"connectEnd":448.19999980926514,"connectStart":448.19999980926514,"domainLookupEnd":448.19999980926514,"domainLookupStart":448.19999980926514,"fetchStart":448.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":448.19999980926514,"responseEnd":736.0999999046326,"responseStart":736.0999999046326,"secureConnectionStart":448.19999980926514},{"duration":114.20000004768372,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":624.8999998569489,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":624.8999998569489,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":739.0999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":28.100000143051147,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":772.6999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":772.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":800.7999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":27.799999952316284,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":773.5,"connectEnd":773.5,"connectStart":773.5,"domainLookupEnd":773.5,"domainLookupStart":773.5,"fetchStart":773.5,"redirectEnd":0,"redirectStart":0,"requestStart":773.5,"responseEnd":801.2999999523163,"responseStart":801.2999999523163,"secureConnectionStart":773.5},{"duration":32.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/f51ef5507eea4c158f257c66c93b2a3f-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":773.8999998569489,"connectEnd":773.8999998569489,"connectStart":773.8999998569489,"domainLookupEnd":773.8999998569489,"domainLookupStart":773.8999998569489,"fetchStart":773.8999998569489,"redirectEnd":0,"redirectStart":0,"requestStart":773.8999998569489,"responseEnd":806.2999999523163,"responseStart":806.2999999523163,"secureConnectionStart":773.8999998569489}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":20,"responseStart":165,"responseEnd":173,"domLoading":168,"domInteractive":848,"domContentLoadedEventStart":848,"domContentLoadedEventEnd":896,"domComplete":1394,"loadEventStart":1394,"loadEventEnd":1396,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":813.1999998092651},{"name":"bigPipe.sidebar-id.end","time":814},{"name":"bigPipe.activity-panel-pipe-id.start","time":814.1999998092651},{"name":"bigPipe.activity-panel-pipe-id.end","time":816.5999999046326},{"name":"activityTabFullyLoaded","time":905.8999998569489}],"measures":[],"correlationId":"90b5803ce5f2ae","effectiveType":"4g","downlink":9.1,"rtt":0,"serverDuration":87,"dbReadsTimeInMs":22,"dbConnsTimeInMs":30,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}