Add support for logging security related events

This patch introduces the LOG_CONSOLE syslog facility for logging common
events.  In industrial applications aiming for IEC 62443 compliance the
following events are central for system observability:

- Change of runlevel - i.e., starting up, shutting down, upgrade, etc.
  Facility: console, severity: notice
- Service starting
  Facility: console, severity: notice
- Service restarting
  Facility: console, severity: notice
- Service stopping
  Facility: console, severity: notice
- Service failed to start
  Facility: console, severity: warning

The use of facility console for this makes it easier to filter out when
forwarding syslog messages from an embedded system to a remote log sink.
Otherwise messages of facility daemon would be used, which include a lot
more, and mostly irrelevant, information.

Signed-off-by: Jonas Holmberg <jonas.holmberg@westermo.se>
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
Jonas Holmberg
2020-01-07 13:38:21 +01:00
committed by Joachim Nilsson
parent a19a3c774e
commit ca210f5431
4 changed files with 19 additions and 2 deletions
-1
View File
@@ -45,7 +45,6 @@
#define _PATH_VARRUN "/var/run/" #define _PATH_VARRUN "/var/run/"
#endif #endif
#define CMD_SIZE 256 #define CMD_SIZE 256
#define LINE_SIZE 1024 #define LINE_SIZE 1024
#define BUF_SIZE 4096 #define BUF_SIZE 4096
+5
View File
@@ -26,6 +26,11 @@
#include <syslog.h> #include <syslog.h>
/* Local facility, unused in GNU but available in FreeBSD or sysklogd >= 2.0 */
#ifndef LOG_CONSOLE
#define LOG_CONSOLE (14<<3)
#endif
/* /*
* Developer error and debug messages, otherwise --> use logit() <-- * Developer error and debug messages, otherwise --> use logit() <--
* ~~~~~~~~~~~ * ~~~~~~~~~~~
+13 -1
View File
@@ -354,6 +354,9 @@ static int service_start(svc_t *svc)
_d("Starting %s: %s", svc->cmd, buf); _d("Starting %s: %s", svc->cmd, buf);
} }
logit(LOG_CONSOLE | LOG_NOTICE, "Starting %s:%s, PID: %d",
basename(svc->cmd), svc->id, pid);
svc->pid = pid; svc->pid = pid;
svc->start_time = jiffies(); svc->start_time = jiffies();
@@ -404,6 +407,8 @@ static void service_kill(svc_t *svc)
} }
_d("%s: Sending SIGKILL to pid:%d", pid_get_name(svc->pid, NULL, 0), svc->pid); _d("%s: Sending SIGKILL to pid:%d", pid_get_name(svc->pid, NULL, 0), svc->pid);
logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGKILL ...",
basename(svc->cmd), svc->id, svc->pid);
if (runlevel != 1) if (runlevel != 1)
print_desc("Killing ", svc->desc); print_desc("Killing ", svc->desc);
@@ -453,6 +458,8 @@ static int service_stop(svc_t *svc)
return 1; return 1;
_d("Sending SIGTERM to pid:%d name:%s", svc->pid, pid_get_name(svc->pid, NULL, 0)); _d("Sending SIGTERM to pid:%d name:%s", svc->pid, pid_get_name(svc->pid, NULL, 0));
logit(LOG_CONSOLE | LOG_NOTICE, "Stopping %s:%s, PID: %d, sending SIGTERM ...",
basename(svc->cmd), svc->id, svc->pid);
svc_set_state(svc, SVC_STOPPING_STATE); svc_set_state(svc, SVC_STOPPING_STATE);
if (runlevel != 1) if (runlevel != 1)
@@ -502,6 +509,8 @@ static int service_restart(svc_t *svc)
print_desc("Restarting ", svc->desc); print_desc("Restarting ", svc->desc);
_d("Sending SIGHUP to PID %d", svc->pid); _d("Sending SIGHUP to PID %d", svc->pid);
logit(LOG_CONSOLE | LOG_NOTICE, "Restarting %s:%s, PID: %d, sending SIGHUP ...",
basename(svc->cmd), svc->id, svc->pid);
rc = kill(svc->pid, SIGHUP); rc = kill(svc->pid, SIGHUP);
/* Declare we're waiting for svc to re-assert/touch its pidfile */ /* Declare we're waiting for svc to re-assert/touch its pidfile */
@@ -1023,7 +1032,8 @@ static void service_retry(svc_t *svc)
} }
if (*restart_cnt >= RESPAWN_MAX) { if (*restart_cnt >= RESPAWN_MAX) {
logit(LOG_ERR, "%s keeps crashing, not restarting", svc->cmd); logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s keeps crashing, not restarting.",
basename(svc->cmd), svc->id);
svc_crashing(svc); svc_crashing(svc);
*restart_cnt = 0; *restart_cnt = 0;
service_step(svc); service_step(svc);
@@ -1033,6 +1043,8 @@ static void service_retry(svc_t *svc)
(*restart_cnt)++; (*restart_cnt)++;
_d("%s crashed, trying to start it again, attempt %d", svc->cmd, *restart_cnt); _d("%s crashed, trying to start it again, attempt %d", svc->cmd, *restart_cnt);
logit(LOG_CONSOLE | LOG_WARNING, "Service %s:%s died, restarting (%d/%d)",
basename(svc->cmd), svc->id, *restart_cnt, RESPAWN_MAX);
svc_unblock(svc); svc_unblock(svc);
service_step(svc); service_step(svc);
+1
View File
@@ -150,6 +150,7 @@ restart:
} }
_d("Setting new runlevel --> %d <-- previous %d", runlevel, prevlevel); _d("Setting new runlevel --> %d <-- previous %d", runlevel, prevlevel);
logit(LOG_CONSOLE | LOG_NOTICE, "%s, entering runlevel %d", INIT_HEADING, runlevel);
runlevel_set(prevlevel, runlevel); runlevel_set(prevlevel, runlevel);
/* Disable login in single-user mode as well as shutdown/reboot */ /* Disable login in single-user mode as well as shutdown/reboot */