<def-group>
    <definition class="compliance" id="audit_delete_failed_ppc64le" version="1">
      <metadata>
        <title>Configure auditing of unsuccessful file deletions (ppc64le)</title>
        
    <affected family="unix">
    <platform>Ubuntu 22.04</platform>
    </affected>
        <description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules</description>
    </metadata>
      <criteria>
          <criterion comment="Check contents of file" test_ref="audit_delete_failed_ppc64le_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" />
      </criteria>
    </definition>

    <ind:textfilecontent54_test check="all" check_existence="all_exist"
    comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules is exactly what is defined in rule description"
    id="audit_delete_failed_ppc64le_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" version="1">
      <ind:object object_ref="audit_delete_failed_ppc64le_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" />
      <ind:state state_ref="audit_delete_failed_ppc64le_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" />
    </ind:textfilecontent54_test>

    <ind:textfilecontent54_object id="audit_delete_failed_ppc64le_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" version="1">
      <ind:behaviors singleline="true" multiline="false" />
      <ind:filepath>/etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules</ind:filepath>
      <ind:pattern operation="pattern match">^.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>

    <ind:textfilecontent54_state id="audit_delete_failed_ppc64le_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules" version="1">
      <ind:text operation="equals">## Unsuccessful file delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid>=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid>=1000 -F auid!=unset -F key=unsuccessful-delete
</ind:text>
    </ind:textfilecontent54_state>

  </def-group>