Compare commits
96 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3edd89e06c | ||
|
|
deb7659149 | ||
|
|
8770ba82df | ||
|
|
06ff53b9e1 | ||
|
|
848f0a1142 | ||
|
|
752b97d2f5 | ||
|
|
6e2902bbf5 | ||
|
|
8a0d7614d6 | ||
|
|
b80cab473a | ||
|
|
b019afff9a | ||
|
|
cb8e5c624a | ||
|
|
ae8648a288 | ||
|
|
9279438445 | ||
|
|
1064c4ef0e | ||
|
|
546fde3d35 | ||
|
|
21c818925f | ||
|
|
9e24c81c59 | ||
|
|
10928b1307 | ||
|
|
5d881b524c | ||
|
|
4a1805d718 | ||
|
|
ba510f5b7c | ||
|
|
738d1ddec5 | ||
|
|
2189965d83 | ||
|
|
1e6869a681 | ||
|
|
eb3dcaa1b2 | ||
|
|
3f11b7ff78 | ||
|
|
de23c1e0c8 | ||
|
|
a2d2f9d9e8 | ||
|
|
e050f5c5b5 | ||
|
|
4cca27d51d | ||
|
|
c5f5013b30 | ||
|
|
0dd4435c2e | ||
|
|
0927f2c9f8 | ||
|
|
88e628e1aa | ||
|
|
c929974881 | ||
|
|
2e07e95fe6 | ||
|
|
00eb7785d3 | ||
|
|
cee335df7d | ||
|
|
8b6dfc7653 | ||
|
|
c61f1049a4 | ||
|
|
5f15cb8d9b | ||
|
|
e45f631e5f | ||
|
|
e74591073c | ||
|
|
061666c54f | ||
|
|
81c2ffa0f1 | ||
|
|
43871ce157 | ||
|
|
44085845eb | ||
|
|
a01e46b838 | ||
|
|
ffb46075f3 | ||
|
|
20fd06e404 | ||
|
|
ae606bed23 | ||
|
|
ad5200aa8c | ||
|
|
6ad07b6b5a | ||
|
|
a5c99cffb1 | ||
|
|
d8cfafacf9 | ||
|
|
70ab8c4473 | ||
|
|
95788bcbec | ||
|
|
595d2133f9 | ||
|
|
480dbb3683 | ||
|
|
b183776247 |
||
|
|
bbfc785ba0 |
||
|
|
21122641c3 |
||
|
|
db636a778d | ||
|
|
cec45294af |
||
|
|
4c239ab2d7 | ||
|
|
8018b8f96b | ||
|
|
3182f1fac5 | ||
|
|
de231b0757 | ||
|
|
503cb6d5f4 | ||
|
|
7c1121d2ca | ||
|
|
f4d39b1b7f | ||
|
|
3df0efa102 | ||
|
|
171f93954f | ||
|
|
1e0113c19c | ||
|
|
93891a13b6 | ||
|
|
80cfa3c0d1 | ||
|
|
1b8033b79b | ||
|
|
e181ced3f7 | ||
|
|
899c7759e6 | ||
|
|
f2ed0514cf | ||
|
|
11b816ac4b | ||
|
|
1da1042ba2 | ||
|
|
1f79054ddc | ||
|
|
afac6d778b | ||
|
|
af881d48de | ||
|
|
c0f7639d4e | ||
|
|
a84ea235e6 | ||
|
|
1819224242 | ||
|
|
fc767e39a3 | ||
|
|
a650d796f5 | ||
|
|
be25acbf0d | ||
|
|
db2e016bcc | ||
|
|
12d390f706 | ||
|
|
eeabf38246 | ||
|
|
d9aa2e8050 | ||
|
|
04e176ec44 |
14 changed files with 910 additions and 329 deletions
1
.fmf/version
Normal file
1
.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
|||
1
|
||||
52
.gitignore
vendored
52
.gitignore
vendored
|
|
@ -51,3 +51,55 @@ rsyslog-4.6.3.tar.gz
|
|||
/rsyslog-8.32.0.tar.gz
|
||||
/rsyslog-doc-8.34.0.tar.gz
|
||||
/rsyslog-8.34.0.tar.gz
|
||||
/rsyslog-8.35.0.tar.gz
|
||||
/rsyslog-doc-8.35.0.tar.gz
|
||||
/rsyslog-8.36.0.tar.gz
|
||||
/rsyslog-doc-8.36.0.tar.gz
|
||||
/rsyslog-8.37.0.tar.gz
|
||||
/rsyslog-doc-8.37.0.tar.gz
|
||||
/rsyslog-8.38.0.tar.gz
|
||||
/rsyslog-doc-8.38.0.tar.gz
|
||||
/rsyslog-8.39.0.tar.gz
|
||||
/rsyslog-doc-8.39.0.tar.gz
|
||||
/rsyslog-8.1904.0.tar.gz
|
||||
/rsyslog-doc-8.1904.0.tar.gz
|
||||
/rsyslog-8.1907.0.tar.gz
|
||||
/rsyslog-doc-8.1907.0.tar.gz
|
||||
/rsyslog-8.1910.0.tar.gz
|
||||
/rsyslog-doc-8.1910.0.tar.gz
|
||||
/rsyslog-8.1911.0.tar.gz
|
||||
/rsyslog-doc-8.1911.0.tar.gz
|
||||
/rsyslog-8.2001.0.tar.gz
|
||||
/rsyslog-doc-8.2001.0.tar.gz
|
||||
/rsyslog-8.2002.0.tar.gz
|
||||
/rsyslog-doc-8.2002.0.tar.gz
|
||||
/rsyslog-8.2008.0.tar.gz
|
||||
/rsyslog-doc-8.2008.0.tar.gz
|
||||
/rsyslog-8.2010.0.tar.gz
|
||||
/rsyslog-doc-8.2010.0.tar.gz
|
||||
/qpid-proton-0.31.0.tar.gz
|
||||
/rsyslog-8.2102.0.tar.gz
|
||||
/rsyslog-doc-8.2102.0.tar.gz
|
||||
/qpid-proton-0.34.0.tar.gz
|
||||
/rsyslog-8.2204.0.tar.gz
|
||||
/rsyslog-doc-8.2204.0.tar.gz
|
||||
/rsyslog-8.2210.0.tar.gz
|
||||
/rsyslog-doc-8.2210.0.tar.gz
|
||||
/rsyslog-8.2306.0.tar.gz
|
||||
/rsyslog-doc-8.2306.0.tar.gz
|
||||
/rsyslog-8.2308.0.tar.gz
|
||||
/rsyslog-doc-8.2308.0.tar.gz
|
||||
/qpid-proton-0.39.0.tar.gz
|
||||
/rsyslog-8.2310.0.tar.gz
|
||||
/rsyslog-doc-8.2310.0.tar.gz
|
||||
/rsyslog-8.2312.0.tar.gz
|
||||
/rsyslog-doc-8.2312.0.tar.gz
|
||||
/rsyslog-8.2408.0.tar.gz
|
||||
/rsyslog-doc-8.2408.0.tar.gz
|
||||
/rsyslog-8.2412.0.tar.gz
|
||||
/rsyslog-doc-8.2412.0.tar.gz
|
||||
/rsyslog-8.2506.0.tar.gz
|
||||
/rsyslog-doc-8.2506.0.tar.gz
|
||||
/rsyslog-8.2508.0.tar.gz
|
||||
/qpid-proton-0.40.0.tar.gz
|
||||
/rsyslog-8.2510.0.tar.gz
|
||||
|
|
|
|||
6
plans/main.fmf
Normal file
6
plans/main.fmf
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
summary: Run all tests
|
||||
execute:
|
||||
how: tmt
|
||||
discover:
|
||||
how: fmf
|
||||
|
||||
|
|
@ -1,65 +0,0 @@
|
|||
From fa7d98b0cb0512d84355e3aafdc5a3e366842f2a Mon Sep 17 00:00:00 2001
|
||||
From: Radovan Sroka <rsroka@redhat.com>
|
||||
Date: Mon, 21 Nov 2016 13:38:18 +0100
|
||||
Subject: [PATCH 2/4] Rebased from: Patch2:
|
||||
rsyslog-7.2.1-msg_c_nonoverwrite_merge.patch
|
||||
|
||||
Resolves:
|
||||
no adressed bugzila
|
||||
---
|
||||
runtime/msg.c | 25 +++++++++++++++++++++++--
|
||||
1 file changed, 23 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/runtime/msg.c b/runtime/msg.c
|
||||
index f6e017b..5430331 100644
|
||||
--- a/runtime/msg.c
|
||||
+++ b/runtime/msg.c
|
||||
@@ -4632,6 +4632,27 @@ finalize_it:
|
||||
RETiRet;
|
||||
}
|
||||
|
||||
+static rsRetVal jsonMerge(struct json_object *existing, struct json_object *json);
|
||||
+
|
||||
+static rsRetVal
|
||||
+jsonMergeNonOverwrite(struct json_object *existing, struct json_object *json)
|
||||
+{
|
||||
+ DEFiRet;
|
||||
+
|
||||
+ struct json_object_iterator it = json_object_iter_begin(existing);
|
||||
+ struct json_object_iterator itEnd = json_object_iter_end(existing);
|
||||
+ while (!json_object_iter_equal(&it, &itEnd)) {
|
||||
+ json_object_object_add(json, json_object_iter_peek_name(&it),
|
||||
+ json_object_get(json_object_iter_peek_value(&it)));
|
||||
+ json_object_iter_next(&it);
|
||||
+ }
|
||||
+
|
||||
+ CHKiRet(jsonMerge(existing, json));
|
||||
+finalize_it:
|
||||
+ RETiRet;
|
||||
+}
|
||||
+
|
||||
+
|
||||
static rsRetVal
|
||||
jsonMerge(struct json_object *existing, struct json_object *json)
|
||||
{
|
||||
@@ -4714,7 +4735,7 @@ msgAddJSON(msg_t * const pM, uchar *name, struct json_object *json, int force_re
|
||||
if(*pjroot == NULL)
|
||||
*pjroot = json;
|
||||
else
|
||||
- CHKiRet(jsonMerge(*pjroot, json));
|
||||
+ CHKiRet(jsonMergeNonOverwrite(*pjroot, json));
|
||||
} else {
|
||||
if(*pjroot == NULL) {
|
||||
/* now we need a root obj */
|
||||
@@ -4742,7 +4763,7 @@ msgAddJSON(msg_t * const pM, uchar *name, struct json_object *json, int force_re
|
||||
json_object_object_add(parent, (char*)leaf, json);
|
||||
} else {
|
||||
if(json_object_get_type(json) == json_type_object) {
|
||||
- CHKiRet(jsonMerge(*pjroot, json));
|
||||
+ CHKiRet(jsonMergeNonOverwrite(*pjroot, json));
|
||||
} else {
|
||||
/* TODO: improve the code below, however, the current
|
||||
* state is not really bad */
|
||||
--
|
||||
2.7.4
|
||||
|
||||
|
|
@ -1,14 +0,0 @@
|
|||
diff -up rsyslog-7.4.1/rsyslog.service.in.orig rsyslog-7.4.1/rsyslog.service.in
|
||||
--- rsyslog-7.4.1/rsyslog.service.in.orig 2013-06-17 15:28:54.430023493 +0200
|
||||
+++ rsyslog-7.4.1/rsyslog.service.in 2013-06-17 15:30:05.874378084 +0200
|
||||
@@ -6,7 +6,9 @@ Requires=syslog.socket
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
-ExecStart=@sbindir@/rsyslogd -n -iNONE
|
||||
+EnvironmentFile=-/etc/sysconfig/rsyslog
|
||||
+ExecStart=@sbindir@/rsyslogd -n $SYSLOGD_OPTIONS
|
||||
+UMask=0066
|
||||
StandardOutput=null
|
||||
Restart=on-failure
|
||||
|
||||
33
rsyslog.conf
33
rsyslog.conf
|
|
@ -4,15 +4,29 @@
|
|||
# or latest version online at http://www.rsyslog.com/doc/rsyslog_conf.html
|
||||
# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html
|
||||
|
||||
#### GLOBAL DIRECTIVES ####
|
||||
|
||||
# Where to place auxiliary files
|
||||
global(workDirectory="/var/lib/rsyslog")
|
||||
|
||||
#### MODULES ####
|
||||
|
||||
module(load="imuxsock" # provides support for local system logging (e.g. via logger command)
|
||||
# Use default timestamp format
|
||||
module(load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat")
|
||||
|
||||
module(load="imuxsock" # provides support for local system logging (e.g. via logger command)
|
||||
SysSock.Use="off") # Turn off message reception via local log socket;
|
||||
# local messages are retrieved through imjournal now.
|
||||
module(load="imjournal" # provides access to the systemd journal
|
||||
# local messages are retrieved through imjournal now.
|
||||
module(load="imjournal" # provides access to the systemd journal
|
||||
FileCreateMode="0600" # Quiet warning and ensure privacy
|
||||
UsePid="system" # PID nummber is retrieved as the ID of the process the journal entry originates from
|
||||
StateFile="imjournal.state") # File to store the position in the journal
|
||||
|
||||
# Include all config files in /etc/rsyslog.d/
|
||||
include(file="/etc/rsyslog.d/*.conf" mode="optional")
|
||||
|
||||
#module(load="imklog") # reads kernel messages (the same are read from journald)
|
||||
#module(load"immark") # provides --MARK-- message capability
|
||||
#module(load="immark") # provides --MARK-- message capability
|
||||
|
||||
# Provides UDP syslog reception
|
||||
# for parameters see http://www.rsyslog.com/doc/imudp.html
|
||||
|
|
@ -24,17 +38,6 @@ module(load="imjournal" # provides access to the systemd journal
|
|||
#module(load="imtcp") # needs to be done just once
|
||||
#input(type="imtcp" port="514")
|
||||
|
||||
#### GLOBAL DIRECTIVES ####
|
||||
|
||||
# Where to place auxiliary files
|
||||
global(workDirectory="/var/lib/rsyslog")
|
||||
|
||||
# Use default timestamp format
|
||||
module(load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat")
|
||||
|
||||
# Include all config files in /etc/rsyslog.d/
|
||||
include(file="/etc/rsyslog.d/*.conf" mode="optional")
|
||||
|
||||
#### RULES ####
|
||||
|
||||
# Log all kernel messages to the console.
|
||||
|
|
|
|||
|
|
@ -7,6 +7,6 @@
|
|||
missingok
|
||||
sharedscripts
|
||||
postrotate
|
||||
/usr/bin/systemctl kill -s HUP rsyslog.service >/dev/null 2>&1 || true
|
||||
/usr/bin/systemctl reload rsyslog.service >/dev/null 2>&1 || true
|
||||
endscript
|
||||
}
|
||||
|
|
|
|||
37
rsyslog.service
Normal file
37
rsyslog.service
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
[Unit]
|
||||
Description=System Logging Service
|
||||
;Requires=syslog.socket
|
||||
Documentation=man:rsyslogd(8)
|
||||
Documentation=https://www.rsyslog.com/doc/
|
||||
Wants=network.target network-online.target
|
||||
After=network.target network-online.target
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
EnvironmentFile=-/etc/sysconfig/rsyslog
|
||||
ExecStart=/usr/sbin/rsyslogd -n $SYSLOGD_OPTIONS
|
||||
ExecReload=/usr/bin/kill -HUP $MAINPID
|
||||
UMask=0066
|
||||
StandardOutput=null
|
||||
Restart=on-failure
|
||||
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
|
||||
RestrictNamespaces=net
|
||||
NoNewPrivileges=yes
|
||||
ProtectControlGroups=yes
|
||||
ProtectHome=read-only
|
||||
ProtectKernelModules=yes
|
||||
ProtectKernelTunables=yes
|
||||
RestrictSUIDSGID=yes
|
||||
SystemCallArchitectures=native
|
||||
SystemCallFilter=~@clock @debug @module @raw-io @reboot @swap @cpu-emulation @obsolete
|
||||
LockPersonality=yes
|
||||
MemoryDenyWriteExecute=yes
|
||||
|
||||
|
||||
# Increase the default a bit in order to allow many simultaneous
|
||||
# files to be monitored, we might need a lot of fds.
|
||||
LimitNOFILE=16384
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
;Alias=syslog.service
|
||||
970
rsyslog.spec
970
rsyslog.spec
File diff suppressed because it is too large
Load diff
4
sources
4
sources
|
|
@ -1,2 +1,2 @@
|
|||
SHA512 (rsyslog-doc-8.34.0.tar.gz) = edf9aa63c777624c3dc27dfd64b38893b9b4c9b56941df1d7a8c6bc3cb4cbbfb83e8c356cbefeab7c688ecb6017b66ed99931cb71b69b7c927b4743548dd40d4
|
||||
SHA512 (rsyslog-8.34.0.tar.gz) = 69eaececa2f8b98799deac8e6cb2cf635a5117da7a21cbb0b880b7df1d83c6ccf16133dab099a6e5fb865f34c2dad164a1bf1952d16ca116af3b1dd35d15065e
|
||||
SHA512 (rsyslog-8.2510.0.tar.gz) = d2e693fd8c7112e4ccc36ea6fbb19909df885e7cb2778e95c04b7c5e9db8240224decfee52308a46865b7deffcf1e31ade0104c90d84b768a4dece15e5ea190e
|
||||
SHA512 (qpid-proton-0.40.0.tar.gz) = 3e7fe56ca1423f45f71d81f5e1d6ec5f21c073cc580628e12a8dbd545a86805b7312834e0d1234dde43797633d575ed639f21a96239b217500cc0a824482aae3
|
||||
|
|
|
|||
2
tests/got-audit/got-audit.gdb
Normal file
2
tests/got-audit/got-audit.gdb
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
gef config gef.disable_color True
|
||||
got-audit --all
|
||||
10
tests/got-audit/main.fmf
Normal file
10
tests/got-audit/main.fmf
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
summary: Audit the GOT for signs of tampering
|
||||
description: |
|
||||
Pointers in the server process GOT will be checked to ensure that
|
||||
each function pointer's value is within a shared object file
|
||||
that exports a symbol of that name, and that no shared object
|
||||
files export conflicting symbols.
|
||||
contact: Gordon Messmer <gordon.messmer@gmail.com>
|
||||
require+:
|
||||
- gdb-gef # needed to test got-audit
|
||||
|
||||
41
tests/got-audit/runtest.sh
Executable file
41
tests/got-audit/runtest.sh
Executable file
|
|
@ -0,0 +1,41 @@
|
|||
#!/bin/bash
|
||||
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
|
||||
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
#
|
||||
# runtest.sh of /CoreOS/rsyslog/Sanity/got-audit
|
||||
# Description: Check pointers in the server process GOT for signs of tampering
|
||||
# Author: Gordon Messmer <gordon.messmer@gmail.com>
|
||||
#
|
||||
|
||||
# Include Beaker environment
|
||||
. /usr/share/beakerlib/beakerlib.sh || exit 1
|
||||
|
||||
rlJournalStart
|
||||
rlPhaseStartSetup
|
||||
rlServiceStart rsyslog
|
||||
rlRun "TestDir=\$(pwd)"
|
||||
rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"
|
||||
rlRun "pushd $TmpDir"
|
||||
rlRun "auditfile=\$(mktemp --tmpdir=${TmpDir})"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartTest "Run GEF got-audit"
|
||||
rlRun "SERVICE_PID=\$( systemctl show --property=MainPID rsyslog.service | cut -f2 -d= )"
|
||||
rlRun "echo SERVICE_PID is '$SERVICE_PID'"
|
||||
[ -n "$SERVICE_PID" ] || rlFail "No service pid was found"
|
||||
rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'"
|
||||
# Basic test: ensure that at least one symbol is found in libc.so,
|
||||
# to verify that the report looks plausible.
|
||||
rlAssertGrep " : /.*/libc.so" "$auditfile"
|
||||
# Ensure the got-audit did not report any errors
|
||||
rlAssertNotGrep " :: ERROR" "$auditfile"
|
||||
rlRun "cp '$auditfile' '$TMT_TEST_DATA'/got-audit.txt"
|
||||
rlPhaseEnd
|
||||
|
||||
rlPhaseStartCleanup
|
||||
rlServiceRestore rsyslog
|
||||
rlRun "popd"
|
||||
rlRun "rm -r $TmpDir" 0 "Removing tmp directory"
|
||||
rlPhaseEnd
|
||||
rlJournalPrintText
|
||||
rlJournalEnd
|
||||
2
tests/main.fmf
Normal file
2
tests/main.fmf
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
test: ./runtest.sh
|
||||
framework: beakerlib
|
||||
Loading…
Add table
Add a link
Reference in a new issue