mirror of
https://github.com/troglobit/finit.git
synced 2026-10-02 14:02:52 +07:00
Add support for logging security related events
This patch introduces the LOG_CONSOLE syslog facility for logging common events. In industrial applications aiming for IEC 62443 compliance the following events are central for system observability: - Change of runlevel - i.e., starting up, shutting down, upgrade, etc. Facility: console, severity: notice - Service starting Facility: console, severity: notice - Service restarting Facility: console, severity: notice - Service stopping Facility: console, severity: notice - Service failed to start Facility: console, severity: warning The use of facility console for this makes it easier to filter out when forwarding syslog messages from an embedded system to a remote log sink. Otherwise messages of facility daemon would be used, which include a lot more, and mostly irrelevant, information. Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se> Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
committed by
Joachim Nilsson
parent
a19a3c774e
commit
ca210f5431
@@ -45,7 +45,6 @@
|
||||
#define _PATH_VARRUN "/var/run/"
|
||||
#endif
|
||||
|
||||
|
||||
#define CMD_SIZE 256
|
||||
#define LINE_SIZE 1024
|
||||
#define BUF_SIZE 4096
|
||||
|
||||
@@ -26,6 +26,11 @@
|
||||
|
||||
#include <syslog.h>
|
||||
|
||||
/* Local facility, unused in GNU but available in FreeBSD or sysklogd >= 2.0 */
|
||||
#ifndef LOG_CONSOLE
|
||||
#define LOG_CONSOLE (14<<3)
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Developer error and debug messages, otherwise --> use logit() <--
|
||||
* ~~~~~~~~~~~
|
||||
|
||||
+13
-1
@@ -354,6 +354,9 @@ static int service_start(svc_t *svc)
|
||||
_d("Starting %s: %s", svc->cmd, buf);
|
||||
}
|
||||
|
||||
logit(LOG_CONSOLE | LOG_NOTICE, "Starting %s:%s, PID: %d",
|
||||
basename(svc->cmd), svc->id, pid);
|
||||
|
||||
svc->pid = pid;
|
||||
svc->start_time = jiffies();
|
||||
|
||||
@@ -404,6 +407,8 @@ static void service_kill(svc_t *svc)
|
||||
}
|
||||
|
||||
_d("%s: Sending SIGKILL to pid:%d", pid_get_name(svc->pid, NULL, 0), svc->pid);
|
||||
logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGKILL ...",
|
||||
basename(svc->cmd), svc->id, svc->pid);
|
||||
if (runlevel != 1)
|
||||
print_desc("Killing ", svc->desc);
|
||||
|
||||
@@ -453,6 +458,8 @@ static int service_stop(svc_t *svc)
|
||||
return 1;
|
||||
|
||||
_d("Sending SIGTERM to pid:%d name:%s", svc->pid, pid_get_name(svc->pid, NULL, 0));
|
||||
logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGTERM ...",
|
||||
basename(svc->cmd), svc->id, svc->pid);
|
||||
svc_set_state(svc, SVC_STOPPING_STATE);
|
||||
|
||||
if (runlevel != 1)
|
||||
@@ -502,6 +509,8 @@ static int service_restart(svc_t *svc)
|
||||
print_desc("Restarting ", svc->desc);
|
||||
|
||||
_d("Sending SIGHUP to PID %d", svc->pid);
|
||||
logit(LOG_CONSOLE | LOG_NOTICE, "Restarting %s:%s, PID: %d, sending SIGHUP ...",
|
||||
basename(svc->cmd), svc->id, svc->pid);
|
||||
rc = kill(svc->pid, SIGHUP);
|
||||
|
||||
/* Declare we're waiting for svc to re-assert/touch its pidfile */
|
||||
@@ -1023,7 +1032,8 @@ static void service_retry(svc_t *svc)
|
||||
}
|
||||
|
||||
if (*restart_cnt >= RESPAWN_MAX) {
|
||||
logit(LOG_ERR, "%s keeps crashing, not restarting", svc->cmd);
|
||||
logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s keeps crashing, not restarting.",
|
||||
basename(svc->cmd), svc->id);
|
||||
svc_crashing(svc);
|
||||
*restart_cnt = 0;
|
||||
service_step(svc);
|
||||
@@ -1033,6 +1043,8 @@ static void service_retry(svc_t *svc)
|
||||
(*restart_cnt)++;
|
||||
|
||||
_d("%s crashed, trying to start it again, attempt %d", svc->cmd, *restart_cnt);
|
||||
logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s died, restarting (%d/%d)",
|
||||
basename(svc->cmd), svc->id, *restart_cnt, RESPAWN_MAX);
|
||||
svc_unblock(svc);
|
||||
service_step(svc);
|
||||
|
||||
|
||||
@@ -150,6 +150,7 @@ restart:
|
||||
}
|
||||
|
||||
_d("Setting new runlevel --> %d <-- previous %d", runlevel, prevlevel);
|
||||
logit(LOG_CONSOLE | LOG_NOTICE, "%s, entering runlevel %d", INIT_HEADING, runlevel);
|
||||
runlevel_set(prevlevel, runlevel);
|
||||
|
||||
/* Disable login in single-user mode as well as shutdown/reboot */
|
||||
|
||||
Reference in New Issue
Block a user