From ca210f54310d496382821b7e24fc2c49af5320f2 Mon Sep 17 00:00:00 2001 From: Jonas Holmberg Date: Tue, 26 Nov 2019 17:09:41 +0100 Subject: [PATCH] Add support for logging security related events This patch introduces the LOG_CONSOLE syslog facility for logging common events. In industrial applications aiming for IEC 62443 compliance the following events are central for system observability: - Change of runlevel - i.e., starting up, shutting down, upgrade, etc. Facility: console, severity: notice - Service starting Facility: console, severity: notice - Service restarting Facility: console, severity: notice - Service stopping Facility: console, severity: notice - Service failed to start Facility: console, severity: warning The use of facility console for this makes it easier to filter out when forwarding syslog messages from an embedded system to a remote log sink. Otherwise messages of facility daemon would be used, which include a lot more, and mostly irrelevant, information. Signed-off-by: Jonas Holmberg Signed-off-by: Joachim Nilsson --- src/finit.h | 1 - src/log.h | 5 +++++ src/service.c | 14 +++++++++++++- src/sm.c | 1 + 4 files changed, 19 insertions(+), 2 deletions(-) diff --git a/src/finit.h b/src/finit.h index afb39726..f41765f6 100644 --- a/src/finit.h +++ b/src/finit.h @@ -45,7 +45,6 @@ #define _PATH_VARRUN "/var/run/" #endif - #define CMD_SIZE 256 #define LINE_SIZE 1024 #define BUF_SIZE 4096 diff --git a/src/log.h b/src/log.h index 38754ab5..4c0c4c57 100644 --- a/src/log.h +++ b/src/log.h @@ -26,6 +26,11 @@ #include +/* Local facility, unused in GNU but available in FreeBSD or sysklogd >= 2.0 */ +#ifndef LOG_CONSOLE +#define LOG_CONSOLE (14<<3) +#endif + /* * Developer error and debug messages, otherwise --> use logit() <-- * ~~~~~~~~~~~ diff --git a/src/service.c b/src/service.c index eebd44ab..6ef37981 100644 --- a/src/service.c +++ b/src/service.c @@ -354,6 +354,9 @@ static int service_start(svc_t *svc) _d("Starting %s: %s", svc->cmd, buf); } + logit(LOG_CONSOLE | LOG_NOTICE, "Starting %s:%s, PID: %d", + basename(svc->cmd), svc->id, pid); + svc->pid = pid; svc->start_time = jiffies(); @@ -404,6 +407,8 @@ static void service_kill(svc_t *svc) } _d("%s: Sending SIGKILL to pid:%d", pid_get_name(svc->pid, NULL, 0), svc->pid); + logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGKILL ...", + basename(svc->cmd), svc->id, svc->pid); if (runlevel != 1) print_desc("Killing ", svc->desc); @@ -453,6 +458,8 @@ static int service_stop(svc_t *svc) return 1; _d("Sending SIGTERM to pid:%d name:%s", svc->pid, pid_get_name(svc->pid, NULL, 0)); + logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGTERM ...", + basename(svc->cmd), svc->id, svc->pid); svc_set_state(svc, SVC_STOPPING_STATE); if (runlevel != 1) @@ -502,6 +509,8 @@ static int service_restart(svc_t *svc) print_desc("Restarting ", svc->desc); _d("Sending SIGHUP to PID %d", svc->pid); + logit(LOG_CONSOLE | LOG_NOTICE, "Restarting %s:%s, PID: %d, sending SIGHUP ...", + basename(svc->cmd), svc->id, svc->pid); rc = kill(svc->pid, SIGHUP); /* Declare we're waiting for svc to re-assert/touch its pidfile */ @@ -1023,7 +1032,8 @@ static void service_retry(svc_t *svc) } if (*restart_cnt >= RESPAWN_MAX) { - logit(LOG_ERR, "%s keeps crashing, not restarting", svc->cmd); + logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s keeps crashing, not restarting.", + basename(svc->cmd), svc->id); svc_crashing(svc); *restart_cnt = 0; service_step(svc); @@ -1033,6 +1043,8 @@ static void service_retry(svc_t *svc) (*restart_cnt)++; _d("%s crashed, trying to start it again, attempt %d", svc->cmd, *restart_cnt); + logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s died, restarting (%d/%d)", + basename(svc->cmd), svc->id, *restart_cnt, RESPAWN_MAX); svc_unblock(svc); service_step(svc); diff --git a/src/sm.c b/src/sm.c index c67a9276..a18e0885 100644 --- a/src/sm.c +++ b/src/sm.c @@ -150,6 +150,7 @@ restart: } _d("Setting new runlevel --> %d <-- previous %d", runlevel, prevlevel); + logit(LOG_CONSOLE | LOG_NOTICE, "%s, entering runlevel %d", INIT_HEADING, runlevel); runlevel_set(prevlevel, runlevel); /* Disable login in single-user mode as well as shutdown/reboot */