Compare commits

...
Sign in to create a new pull request.

37 commits

Author SHA1 Message Date
Attila Lakatos
3edd89e06c Add mmleefparse module to base package 2025-10-20 09:47:39 +02:00
Attila Lakatos
deb7659149 Rebase to 8.2510.0
Resolves: rhbz#2404131
imjournal open error handling fix
Resolves: rhbz#2375742
2025-10-20 09:25:46 +02:00
Attila Lakatos
8770ba82df Rebase to 8.2508.0
Resolves: rhbz#2392918
2025-09-05 08:31:56 +02:00
Fedora Release Engineering
06ff53b9e1 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 12:09:59 +00:00
Attila Lakatos
848f0a1142 Fix broken omamqp1 module build 2025-06-12 10:41:42 +02:00
Attila Lakatos
752b97d2f5 Add back accidentally removed patch 2025-06-12 09:16:25 +02:00
Attila Lakatos
6e2902bbf5 Fix building without openssl engines 2025-06-12 08:53:31 +02:00
Attila Lakatos
8a0d7614d6 Rebase to 8.2506.0V
Resolves: rhbz#2347628
2025-06-12 08:19:32 +02:00
Cropi
b80cab473a Fix build problem by making gnu23 compatible 2025-01-21 11:32:37 +01:00
Fedora Release Engineering
b019afff9a Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-18 22:49:26 +00:00
Cropi
cb8e5c624a Add UsePid option to imjournal 2024-12-05 10:36:21 +01:00
Cropi
ae8648a288 Disable openssl engines support 2024-12-05 09:57:42 +01:00
Cropi
9279438445 Harden service file 2024-12-05 09:54:15 +01:00
Cropi
1064c4ef0e Rebase to 8.2412.0
Resolves: rhbz#2320050
2024-12-05 09:53:46 +01:00
Cropi
546fde3d35 Rebuild package
Resolves: rhzb#2316361
2024-10-04 09:13:00 +02:00
alakatos
21c818925f Replace gcry crypto driver with ossl 2024-08-21 14:15:06 +02:00
alakatos
9e24c81c59 Remove dependency on libgcrypt 2024-08-21 14:04:07 +02:00
alakatos
10928b1307 Rebase to 8.2408.0
Resolves: rhbz#2266329
Resolves: rhbz#2301246
Resolves: rhbz#2305398
2024-08-21 14:00:22 +02:00
Gordon Messmer
5d881b524c Examine the server process GOT for signs of tampering. 2024-08-06 15:34:08 -07:00
Gordon Messmer
4a1805d718 openssl engine-related files have been moved to a sub-package, which rsyslog currently requires. 2024-08-01 15:17:12 -07:00
Fedora Release Engineering
ba510f5b7c Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-19 18:55:07 +00:00
Orion Poplawski
738d1ddec5 Explicitly set imjournal FileCreateMode to quiet warning 2024-05-29 16:53:35 -06:00
Kevin Fenzi
2189965d83 rebuild for hiredis soname bump 2024-05-11 15:44:22 -07:00
alakatos
1e6869a681 Rebase to 8.2312.0
resolves: rhbz#2232275
2024-02-12 16:17:01 +01:00
Fedora Release Engineering
eb3dcaa1b2 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-26 16:26:43 +00:00
Fedora Release Engineering
3f11b7ff78 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-22 12:10:48 +00:00
Dominique Martinet
de23c1e0c8 obsolete rsyslog-logrotate 2024-01-08 08:51:56 +01:00
alakatos
a2d2f9d9e8 Move rsyslog related logrotate config to the base package
In the past, the logrotate script was part of the base package, but
it has been moved to a separate package to reduce base package
dependencies. It turned out to be a bad idea, because in some cases
the logrotate subpackage was not installed and the logrotate config
was missing. This turned off rotation of important logs, thus some logs
could grow into extremely large files .
2024-01-04 13:36:14 +01:00
alakatos
e050f5c5b5 Rebase to 8.2310.0
resolves: rhbz#2232275
2023-10-10 10:25:32 +02:00
alakatos
4cca27d51d Rebase to 8.2308.0 2023-08-25 08:57:22 +02:00
Stewart Smith
c5f5013b30 Add mmtaghostname module
It appears that some people are finding use for this rsyslog module, and
it doesn't add any more build-dependencies for rsyslog.

Add it as a bcond to make a more minimal rsyslog possible, as well as
keeping the pattern of having all of these as options.

Fixes: https://github.com/amazonlinux/amazon-linux-2023/issues/122
2023-08-16 17:35:29 +00:00
Fedora Release Engineering
0dd4435c2e Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-21 17:11:09 +00:00
Yaroslav Fedevych
0927f2c9f8 Specify qpid-proton's source as full URL to fix isolated builds
The way qpid-proton's sources are specified, any automated build outside of RH infrastructure will fail as it won't know where to get them from. This makes the source a proper URL.
2023-07-15 08:10:43 +00:00
alakatos
88e628e1aa rebase to 8.2306.0
resolves: rhbz#2151339
  resolves: rhbz#2151092
2023-06-21 08:53:23 +02:00
alakatos
c929974881 Fix deprecated %patchN 2023-05-31 10:23:51 +02:00
alakatos
2e07e95fe6 Update License tag for SPDX 2023-05-31 10:22:06 +02:00
Todd Zullinger
00eb7785d3 Use systemctl reload in logrotate script
In 5f74814 (Use systemctl for sending SIGHUP to the service,
2015-06-29), a direct call to `kill` was replaced with `systemctl kill`.

This can be simplified using `systemctl reload` instead.  Doing so also
resolves an issue when `POSIXLY_CORRECT` is set (rhbz#2124488).
2023-05-14 12:26:05 -04:00
14 changed files with 231 additions and 397 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

18
.gitignore vendored
View file

@ -85,3 +85,21 @@ rsyslog-4.6.3.tar.gz
/rsyslog-doc-8.2204.0.tar.gz
/rsyslog-8.2210.0.tar.gz
/rsyslog-doc-8.2210.0.tar.gz
/rsyslog-8.2306.0.tar.gz
/rsyslog-doc-8.2306.0.tar.gz
/rsyslog-8.2308.0.tar.gz
/rsyslog-doc-8.2308.0.tar.gz
/qpid-proton-0.39.0.tar.gz
/rsyslog-8.2310.0.tar.gz
/rsyslog-doc-8.2310.0.tar.gz
/rsyslog-8.2312.0.tar.gz
/rsyslog-doc-8.2312.0.tar.gz
/rsyslog-8.2408.0.tar.gz
/rsyslog-doc-8.2408.0.tar.gz
/rsyslog-8.2412.0.tar.gz
/rsyslog-doc-8.2412.0.tar.gz
/rsyslog-8.2506.0.tar.gz
/rsyslog-doc-8.2506.0.tar.gz
/rsyslog-8.2508.0.tar.gz
/qpid-proton-0.40.0.tar.gz
/rsyslog-8.2510.0.tar.gz

View file

@ -1,83 +0,0 @@
diff -up ./qpid-proton-0.34.0/c/src/ssl/openssl.c.orig ./qpid-proton-0.34.0/c/src/ssl/openssl.c
--- ./qpid-proton-0.34.0/c/src/ssl/openssl.c.orig 2021-06-01 09:29:27.976842727 +0200
+++ ./qpid-proton-0.34.0/c/src/ssl/openssl.c 2021-06-01 09:31:05.232015887 +0200
@@ -353,65 +353,6 @@ static int verify_callback(int preverify
return preverify_ok;
}
-// This was introduced in v1.1
-#if OPENSSL_VERSION_NUMBER < 0x10100000
-int DH_set0_pqg(DH *dh, BIGNUM *p, BIGNUM *q, BIGNUM *g)
-{
- dh->p = p;
- dh->q = q;
- dh->g = g;
- return 1;
-}
-#endif
-
-// this code was generated using the command:
-// "openssl dhparam -C -2 2048"
-static DH *get_dh2048(void)
-{
- static const unsigned char dhp_2048[]={
- 0xAE,0xF7,0xE9,0x66,0x26,0x7A,0xAC,0x0A,0x6F,0x1E,0xCD,0x81,
- 0xBD,0x0A,0x10,0x7E,0xFA,0x2C,0xF5,0x2D,0x98,0xD4,0xE7,0xD9,
- 0xE4,0x04,0x8B,0x06,0x85,0xF2,0x0B,0xA3,0x90,0x15,0x56,0x0C,
- 0x8B,0xBE,0xF8,0x48,0xBB,0x29,0x63,0x75,0x12,0x48,0x9D,0x7E,
- 0x7C,0x24,0xB4,0x3A,0x38,0x7E,0x97,0x3C,0x77,0x95,0xB0,0xA2,
- 0x72,0xB6,0xE9,0xD8,0xB8,0xFA,0x09,0x1B,0xDC,0xB3,0x80,0x6E,
- 0x32,0x0A,0xDA,0xBB,0xE8,0x43,0x88,0x5B,0xAB,0xC3,0xB2,0x44,
- 0xE1,0x95,0x85,0x0A,0x0D,0x13,0xE2,0x02,0x1E,0x96,0x44,0xCF,
- 0xA0,0xD8,0x46,0x32,0x68,0x63,0x7F,0x68,0xB3,0x37,0x52,0xCE,
- 0x3A,0x4E,0x48,0x08,0x7F,0xD5,0x53,0x00,0x59,0xA8,0x2C,0xCB,
- 0x51,0x64,0x3D,0x5F,0xEF,0x0E,0x5F,0xE6,0xAF,0xD9,0x1E,0xA2,
- 0x35,0x64,0x37,0xD7,0x4C,0xC9,0x24,0xFD,0x2F,0x75,0xBB,0x3A,
- 0x15,0x82,0x76,0x4D,0xC2,0x8B,0x1E,0xB9,0x4B,0xA1,0x33,0xCF,
- 0xAA,0x3B,0x7C,0xC2,0x50,0x60,0x6F,0x45,0x69,0xD3,0x6B,0x88,
- 0x34,0x9B,0xE4,0xF8,0xC6,0xC7,0x5F,0x10,0xA1,0xBA,0x01,0x8C,
- 0xDA,0xD1,0xA3,0x59,0x9C,0x97,0xEA,0xC3,0xF6,0x02,0x55,0x5C,
- 0x92,0x1A,0x39,0x67,0x17,0xE2,0x9B,0x27,0x8D,0xE8,0x5C,0xE9,
- 0xA5,0x94,0xBB,0x7E,0x16,0x6F,0x53,0x5A,0x6D,0xD8,0x03,0xC2,
- 0xAC,0x7A,0xCD,0x22,0x98,0x8E,0x33,0x2A,0xDE,0xAB,0x12,0xC0,
- 0x0B,0x7C,0x0C,0x20,0x70,0xD9,0x0B,0xAE,0x0B,0x2F,0x20,0x9B,
- 0xA4,0xED,0xFD,0x49,0x0B,0xE3,0x4A,0xF6,0x28,0xB3,0x98,0xB0,
- 0x23,0x1C,0x09,0x33,
- };
- static const unsigned char dhg_2048[]={
- 0x02,
- };
- DH *dh = DH_new();
- BIGNUM *dhp_bn, *dhg_bn;
-
- if (dh == NULL)
- return NULL;
- dhp_bn = BN_bin2bn(dhp_2048, sizeof (dhp_2048), NULL);
- dhg_bn = BN_bin2bn(dhg_2048, sizeof (dhg_2048), NULL);
- if (dhp_bn == NULL || dhg_bn == NULL
- || !DH_set0_pqg(dh, dhp_bn, NULL, dhg_bn)) {
- DH_free(dh);
- BN_free(dhp_bn);
- BN_free(dhg_bn);
- return NULL;
- }
- return dh;
-}
-
typedef struct {
char *id;
SSL_SESSION *session;
@@ -542,13 +483,6 @@ static bool pni_init_ssl_domain( pn_ssl_
domain->default_seclevel = SSL_CTX_get_security_level(domain->ctx);
# endif
- DH *dh = get_dh2048();
- if (dh) {
- SSL_CTX_set_tmp_dh(domain->ctx, dh);
- DH_free(dh);
- SSL_CTX_set_options(domain->ctx, SSL_OP_SINGLE_DH_USE);
- }
-
return true;
}

6
plans/main.fmf Normal file
View file

@ -0,0 +1,6 @@
summary: Run all tests
execute:
how: tmt
discover:
how: fmf

View file

@ -1,261 +0,0 @@
diff --git a/configure.ac b/configure.ac
index 9f73a708d0..958c26245e 100644
--- a/configure.ac
+++ b/configure.ac
@@ -377,6 +377,28 @@ AC_ARG_ENABLE(fmhash,
[enable_fmhash=yes]
)
+AC_ARG_ENABLE(libcap-ng,
+ [AS_HELP_STRING([--enable-libcap-ng],[Enable dropping capabilities to only the necessary set @<:@default=no@:>@])],
+ [case "${enableval}" in
+ yes) enable_libcapng="yes" ;;
+ no) enable_libcapng="no" ;;
+ *) AC_MSG_ERROR(bad value ${enableval} for --enable_libcapng) ;;
+ esac],
+ [enable_libcapng=no]
+)
+
+if test "$enable_libcapng" = "yes"; then
+ PKG_CHECK_MODULES(
+ [LIBCAPNG],
+ [libcap-ng >= 0.8.2],
+ [AC_DEFINE([ENABLE_LIBCAPNG], [1], [Indicator that libcap-ng is present])],
+ [AC_MSG_ERROR(libcap-ng is not present.)]
+ )
+ CFLAGS="$CFLAGS $LIBCAPNG_CFLAGS"
+ LIBS="$LIBS $LIBCAPNG_LIBS"
+fi
+
+
AC_ARG_ENABLE(fmhash-xxhash,
[AS_HELP_STRING([--enable-fmhash-xxhash],[Enable xxhash in fmhash support @<:@default=no@:>@])],
[case "${enableval}" in
@@ -2820,6 +2842,8 @@ echo " liblogging-stdlog support enabled: $enable_liblogging_stdlog"
echo " libsystemd enabled: $enable_libsystemd"
echo " kafka static linking enabled: $enable_kafka_static"
echo " atomic operations enabled: $enable_atomic_operations"
+echo " libcap-ng support enabled: $enable_libcapng"
+
echo
echo "---{ input plugins }---"
if test "$unamestr" != "AIX"; then
diff --git a/runtime/debug.c b/runtime/debug.c
index a655bc2e4e..6e6c9fd38f 100644
--- a/runtime/debug.c
+++ b/runtime/debug.c
@@ -250,7 +250,7 @@ r_dbgoprint( const char *srcname, obj_t *pObj, const char *fmt, ...)
if(!(Debug && debugging_on))
return;
-
+
if(!checkDbgFile(srcname)) {
return;
}
@@ -435,7 +435,7 @@ rsRetVal dbgClassInit(void)
{
rsRetVal iRet; /* do not use DEFiRet, as this makes calls into the debug system! */
-
+
(void) pthread_key_create(&keyThrdName, dbgThrdNameDestruct);
/* while we try not to use any of the real rsyslog code (to avoid infinite loops), we
diff --git a/runtime/modules.c b/runtime/modules.c
index 810b2e9b52..b39bd9f066 100644
--- a/runtime/modules.c
+++ b/runtime/modules.c
@@ -595,7 +595,7 @@ doModInit(pModInit_t modInit, uchar *name, void *pModHdlr, modInfo_t **pNewModul
CHKiRet((*pNew->modQueryEtryPt)((uchar*)"getKeepType", &modGetKeepType));
CHKiRet((*modGetKeepType)(&pNew->eKeepType));
dbgprintf("module %s of type %d being loaded (keepType=%d).\n", name, pNew->eType, pNew->eKeepType);
-
+
/* OK, we know we can successfully work with the module. So we now fill the
* rest of the data elements. First we load the interfaces common to all
* module types.
@@ -1242,7 +1242,7 @@ Load(uchar *const pModName, const sbool bConfLoad, struct nvlst *const lst)
}
iLoadCnt++;
-
+
} while(pModHdlr == NULL && *pModName != '/' && pModDirNext);
if(load_err_msg != NULL) {
@@ -1323,7 +1323,7 @@ modulesProcessCnf(struct cnfobj *o)
cnfModName = (uchar*)es_str2cstr(pvals[typeIdx].val.d.estr, NULL);
iRet = Load(cnfModName, 1, o->nvlst);
-
+
finalize_it:
free(cnfModName);
cnfparamvalsDestruct(pvals, &pblk);
diff --git a/runtime/rsconf.c b/runtime/rsconf.c
index 4620ff8d13..de2a21b406 100644
--- a/runtime/rsconf.c
+++ b/runtime/rsconf.c
@@ -34,6 +34,10 @@
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/socket.h>
+#ifdef ENABLE_LIBCAPNG
+ #include <cap-ng.h>
+#endif
+
#include "rsyslog.h"
#include "obj.h"
@@ -656,6 +660,7 @@ rsRetVal doDropPrivGid(rsconf_t *cnf)
uchar szBuf[1024];
DEFiRet;
+#ifndef ENABLE_LIBCAPNG
if(!cnf->globals.gidDropPrivKeepSupplemental) {
res = setgroups(0, NULL); /* remove all supplemental group IDs */
if(res) {
@@ -668,9 +673,19 @@ rsRetVal doDropPrivGid(rsconf_t *cnf)
res = setgid(cnf->globals.gidDropPriv);
if(res) {
LogError(errno, RS_RET_ERR_DROP_PRIV,
- "could not set requested group id %d", cnf->globals.gidDropPriv);
+ "could not set requested group id %d via setgid()", cnf->globals.gidDropPriv);
ABORT_FINALIZE(RS_RET_ERR_DROP_PRIV);
}
+#else
+ int capng_flags = cnf->globals.gidDropPrivKeepSupplemental ? CAPNG_NO_FLAG : CAPNG_DROP_SUPP_GRP;
+ res = capng_change_id(-1, cnf->globals.gidDropPriv, capng_flags);
+ if (res) {
+ LogError(0, RS_RET_LIBCAPNG_ERR,
+ "could not set requested group id %d via capng_change_id()", cnf->globals.gidDropPriv);
+ ABORT_FINALIZE(RS_RET_LIBCAPNG_ERR);
+ }
+#endif
+
DBGPRINTF("setgid(%d): %d\n", cnf->globals.gidDropPriv, res);
snprintf((char*)szBuf, sizeof(szBuf), "rsyslogd's groupid changed to %d",
cnf->globals.gidDropPriv);
@@ -705,12 +720,18 @@ static void doDropPrivUid(rsconf_t *cnf)
cnf->globals.uidDropPriv);
}
+#ifndef ENABLE_LIBCAPNG
res = setuid(cnf->globals.uidDropPriv);
+#else
+ int capng_flags = cnf->globals.gidDropPrivKeepSupplemental ? CAPNG_NO_FLAG : CAPNG_DROP_SUPP_GRP;
+ res = capng_change_id(cnf->globals.uidDropPriv, -1, capng_flags);
+#endif
if(res) {
/* if we can not set the userid, this is fatal, so let's unconditionally abort */
perror("could not set requested userid");
exit(1);
}
+
DBGPRINTF("setuid(%d): %d\n", cnf->globals.uidDropPriv, res);
snprintf((char*)szBuf, sizeof(szBuf), "rsyslogd's userid changed to %d", cnf->globals.uidDropPriv);
logmsgInternal(NO_ERRCODE, LOG_SYSLOG|LOG_INFO, szBuf, 0);
@@ -739,6 +760,29 @@ dropPrivileges(rsconf_t *cnf)
cnf->globals.uidDropPriv);
}
+#ifdef ENABLE_LIBCAPNG
+ /* In case privileges were dropped, do not allow bypassing
+ * file read, write, and execute permission checks
+ */
+ if (cnf->globals.gidDropPriv != 0 || cnf->globals.uidDropPriv != 0) {
+ int capng_rc;
+ if ((capng_rc = capng_update(CAPNG_DROP, CAPNG_EFFECTIVE|CAPNG_PERMITTED, CAP_DAC_OVERRIDE)) != 0) {
+ LogError(0, RS_RET_LIBCAPNG_ERR,
+ "could not update the internal posix capabilities settings "
+ "based on the options passed to it, capng_update=%d\n", capng_rc);
+ exit(-1);
+ }
+
+ if ((capng_rc = capng_apply(CAPNG_SELECT_BOTH)) != 0) {
+ LogError(0, RS_RET_LIBCAPNG_ERR,
+ "could not transfer the specified internal posix capabilities "
+ "settings to the kernel, capng_apply=%d\n", capng_rc);
+ exit(-1);
+ }
+ }
+
+#endif
+
finalize_it:
RETiRet;
}
diff --git a/runtime/rsyslog.h b/runtime/rsyslog.h
index 908e5e7b73..01616d8f7d 100644
--- a/runtime/rsyslog.h
+++ b/runtime/rsyslog.h
@@ -604,6 +604,7 @@ enum rsRetVal_ /** return value. All methods return this if not specified oth
RS_RET_REDIS_ERROR = -2452, /**< redis-specific error. See message foe details. */
RS_RET_REDIS_AUTH_FAILED = -2453, /**< redis authentication failure */
RS_RET_FAUP_INIT_OPTIONS_FAILED = -2454, /**< could not initialize faup options */
+ RS_RET_LIBCAPNG_ERR = -2455, /**< error during dropping the capabilities */
/* RainerScript error messages (range 1000.. 1999) */
RS_RET_SYSVAR_NOT_FOUND = 1001, /**< system variable could not be found (maybe misspelled) */
diff --git a/tools/rsyslogd.c b/tools/rsyslogd.c
index 31b91a1bd1..77d814b482 100644
--- a/tools/rsyslogd.c
+++ b/tools/rsyslogd.c
@@ -37,6 +37,9 @@
#ifdef HAVE_LIBSYSTEMD
# include <systemd/sd-daemon.h>
#endif
+#ifdef ENABLE_LIBCAPNG
+ #include <cap-ng.h>
+#endif
#include "rsyslog.h"
#include "wti.h"
@@ -2167,6 +2170,46 @@ main(int argc, char **argv)
fjson_global_do_case_sensitive_comparison(0);
dbgClassInit();
+
+#ifdef ENABLE_LIBCAPNG
+ /*
+ * Drop capabilities to the necessary set
+ */
+ int capng_rc;
+ capng_clear(CAPNG_SELECT_BOTH);
+
+ if ((capng_rc = capng_updatev(CAPNG_ADD, CAPNG_EFFECTIVE|CAPNG_PERMITTED,
+ CAP_BLOCK_SUSPEND,
+ CAP_CHOWN,
+ CAP_IPC_LOCK,
+ CAP_LEASE,
+ CAP_NET_ADMIN,
+ CAP_NET_BIND_SERVICE,
+ CAP_DAC_OVERRIDE,
+ CAP_SETGID,
+ CAP_SETUID,
+ CAP_SETPCAP,
+ CAP_SYS_ADMIN,
+ CAP_SYS_CHROOT,
+ CAP_SYS_RESOURCE,
+ CAP_SYSLOG,
+ -1
+ )) != 0) {
+ LogError(0, RS_RET_LIBCAPNG_ERR,
+ "could not update the internal posix capabilities settings "
+ "based on the options passed to it, capng_updatev=%d\n", capng_rc);
+ exit(-1);
+ }
+
+ if ((capng_rc = capng_apply(CAPNG_SELECT_BOTH)) != 0) {
+ LogError(0, RS_RET_LIBCAPNG_ERR,
+ "could not transfer the specified internal posix capabilities "
+ "settings to the kernel, capng_apply=%d\n", capng_rc);
+ exit(-1);
+ }
+ DBGPRINTF("Capabilities were dropped successfully\n");
+#endif
+
initAll(argc, argv);
#ifdef HAVE_LIBSYSTEMD
sd_notify(0, "READY=1");

View file

@ -18,6 +18,8 @@ module(load="imuxsock" # provides support for local system logging (e.g. via
SysSock.Use="off") # Turn off message reception via local log socket;
# local messages are retrieved through imjournal now.
module(load="imjournal" # provides access to the systemd journal
FileCreateMode="0600" # Quiet warning and ensure privacy
UsePid="system" # PID nummber is retrieved as the ID of the process the journal entry originates from
StateFile="imjournal.state") # File to store the position in the journal
# Include all config files in /etc/rsyslog.d/

View file

@ -7,6 +7,6 @@
missingok
sharedscripts
postrotate
/usr/bin/systemctl kill -s HUP rsyslog.service >/dev/null 2>&1 || true
/usr/bin/systemctl reload rsyslog.service >/dev/null 2>&1 || true
endscript
}

View file

@ -3,6 +3,8 @@ Description=System Logging Service
;Requires=syslog.socket
Documentation=man:rsyslogd(8)
Documentation=https://www.rsyslog.com/doc/
Wants=network.target network-online.target
After=network.target network-online.target
[Service]
Type=notify
@ -12,6 +14,19 @@ ExecReload=/usr/bin/kill -HUP $MAINPID
UMask=0066
StandardOutput=null
Restart=on-failure
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
RestrictNamespaces=net
NoNewPrivileges=yes
ProtectControlGroups=yes
ProtectHome=read-only
ProtectKernelModules=yes
ProtectKernelTunables=yes
RestrictSUIDSGID=yes
SystemCallArchitectures=native
SystemCallFilter=~@clock @debug @module @raw-io @reboot @swap @cpu-emulation @obsolete
LockPersonality=yes
MemoryDenyWriteExecute=yes
# Increase the default a bit in order to allow many simultaneous
# files to be monitored, we might need a lot of fds.

View file

@ -1,6 +1,7 @@
%define rsyslog_statedir %{_sharedstatedir}/rsyslog
%define rsyslog_pkidir %{_sysconfdir}/pki/rsyslog
%define rsyslog_docdir %{_docdir}/rsyslog
%define qpid_proton_v 0.40.0
# The following packages are not enabled on rhel:
# hiredis, libdbi, mongodb, rabbitmq
# The omamqp1 plugin is built differently as qpid-proton is not available on rhel
@ -31,25 +32,22 @@
%bcond_without pgsql
%bcond_without snmp
%bcond_without udpspoof
%bcond_without mmtaghostname
Summary: Enhanced system logging and kernel message trapping daemon
Name: rsyslog
Version: 8.2210.0
Release: 4%{?dist}
License: (GPLv3+ and ASL 2.0)
Version: 8.2510.0
Release: 1%{?dist}
License: GPL-3.0-or-later AND Apache-2.0
URL: http://www.rsyslog.com/
Source0: http://www.rsyslog.com/files/download/rsyslog/%{name}-%{version}.tar.gz
Source1: http://www.rsyslog.com/files/download/rsyslog/%{name}-doc-%{version}.tar.gz
Source2: rsyslog.conf
Source3: rsyslog.sysconfig
Source4: rsyslog.log
Source5: rsyslog.service
Source1: rsyslog.conf
Source2: rsyslog.sysconfig
Source3: rsyslog.log
Source4: rsyslog.service
# Add qpid-proton as another source, enable omamqp1 module in a
# separatae sub-package with it statically linked(see rhbz#1713427)
Source6: qpid-proton-0.34.0.tar.gz
Patch0: openssl3-compatibility.patch
Patch1: rsyslog-8.2210.0-rhbz2127403-drop-capabilities.patch
Source5: https://archive.apache.org/dist/qpid/proton/%{qpid_proton_v}/qpid-proton-%{qpid_proton_v}.tar.gz
BuildRequires: make
BuildRequires: gcc
@ -58,7 +56,6 @@ BuildRequires: automake
BuildRequires: bison
BuildRequires: dos2unix
BuildRequires: flex
BuildRequires: libgcrypt-devel
BuildRequires: libfastjson-devel >= 0.99.8
BuildRequires: libestr-devel >= 0.1.9
BuildRequires: libtool
@ -71,18 +68,15 @@ BuildRequires: systemd-rpm-macros
BuildRequires: zlib-devel
BuildRequires: libcap-ng-devel
Recommends: %{name}-logrotate = %version-%release
Recommends: logrotate
Obsoletes: rsyslog-logrotate < 8.2310.0-2
Provides: rsyslog-logrotate = %{version}-%{release}
Requires: bash >= 2.0
%{?systemd_ordering}
Provides: syslog
Obsoletes: sysklogd < 1.5-11
%package logrotate
Summary: Log rotation for rsyslog
Requires: %name = %version-%release
Requires: logrotate >= 3.5.2
%package crypto
Summary: Encryption support
Requires: %name = %version-%release
@ -113,6 +107,12 @@ Requires: %name = %version-%release
Summary: Fields extraction module
Requires: %name = %version-%release
%if %{with mmtaghostname}
%package mmtaghostname
Summary: Message modification module supporting adding tags
Requires: %name = %version-%release
%endif
%if %{with snmp}
%package mmsnmptrapd
Summary: Message modification module for snmptrapd generated messages
@ -241,9 +241,6 @@ and can be used as a drop-in replacement. Rsyslog is simple to set up, with
advanced features suitable for enterprise-class, encryption-protected syslog
relay chains.
%description logrotate
This subpackage contains the default logrotate configuration for rsyslog.
%description crypto
This package contains a module providing log file encryption and a
command line tool to process encrypted logs.
@ -272,6 +269,9 @@ advantage if a field-based log format is to be processed, like for example CEF
and either a large number of fields is needed or a specific field is used multiple
times inside filters.
%description mmtaghostname
This module provides message modification for changing or adding the host name.
%if %{with snmp}
%description mmsnmptrapd
This message modification module takes messages generated from snmptrapd and
@ -372,23 +372,14 @@ This module allows rsyslog to send messages to a RabbitMQ server.
%endif
%prep
# set up rsyslog-doc sources
%setup -q -a 1 -T -c
rm -r LICENSE README.md source build/objects.inv
mv build doc
# set up rsyslog sources
%setup -q -D
%if %{with omamqp1}
# Unpack qpid-proton
%setup -q -D -T -b 6
pushd ..
%patch0 -p1 -b .openssl-compatibility
popd
%setup -q -D -T -b 5
%endif
%patch1 -p1 -b .libcap-ng
%build
%ifarch sparc64
#sparc64 need big PIC
@ -400,19 +391,18 @@ export CFLAGS="$RPM_OPT_FLAGS -fpic"
%if %{with omamqp1}
# build the proton first
(
cd %{_builddir}/qpid-proton-0.34.0
cd %{_builddir}/qpid-proton-%{qpid_proton_v}
mkdir bld
cd bld
# Need ENABLE_FUZZ_TESTING=NO to avoid a link failure
# Find python include dir and python library from
# https://stackoverflow.com/questions/24174394/cmake-is-not-able-to-find-python-libraries
# Modern approach for Python discovery in CMake
cmake .. \
-DBUILD_BINDINGS="" \
-DBUILD_STATIC_LIBS=YES \
-DENABLE_FUZZ_TESTING=NO \
-DPYTHON_INCLUDE_DIR=$(python3 -c "from distutils.sysconfig import get_python_inc; print(get_python_inc())") \
-DPYTHON_LIBRARY=$(python3 -c "import distutils.sysconfig as sysconfig; print(sysconfig.get_config_var('LIBDIR'))") \
-DPython_FIND_STRATEGY=LOCATION \
-DPython_ROOT_DIR=/usr \
-DCMAKE_AR="/usr/bin/gcc-ar" -DCMAKE_NM="/usr/bin/gcc-nm" -DCMAKE_RANLIB="/usr/bin/gcc-ranlib"
make -j8
)
@ -462,7 +452,7 @@ autoreconf -if
--enable-omrabbitmq \
%endif
%if %{with omamqp1}
--enable-omamqp1 PROTON_LIBS="%{_builddir}/qpid-proton-0.34.0/bld/c/libqpid-proton-core-static.a %{_builddir}/qpid-proton-0.34.0/bld/c/libqpid-proton-proactor-static.a %{_builddir}/qpid-proton-0.34.0/bld/c/libqpid-proton-static.a -lssl -lsasl2 -lcrypto" PROTON_CFLAGS="-I%{_builddir}/qpid-proton-0.34.0/bld/c/include" \
--enable-omamqp1 PROTON_PROACTOR_LIBS="%{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-core-static.a %{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-proactor-static.a %{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-static.a -lssl -lsasl2 -lcrypto" PROTON_PROACTOR_CFLAGS="-I%{_builddir}/qpid-proton-%{qpid_proton_v}/c/include -I%{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/include" PROTON_LIBS="%{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-core-static.a %{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-proactor-static.a %{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/libqpid-proton-static.a -lssl -lsasl2 -lcrypto" PROTON_CFLAGS="-I%{_builddir}/qpid-proton-%{qpid_proton_v}/c/include -I%{_builddir}/qpid-proton-%{qpid_proton_v}/bld/c/include" \
%endif
--enable-elasticsearch \
--enable-generate-man-pages \
@ -491,6 +481,9 @@ autoreconf -if
--enable-mmkubernetes \
--enable-mmjsonparse \
--enable-mmnormalize \
%if %{with mmtaghostname}
--enable-mmtaghostname \
%endif
%if %{with snmp}
--enable-mmsnmptrapd \
%endif
@ -520,7 +513,9 @@ autoreconf -if
--enable-snmp \
%endif
--enable-unlimited-select \
--enable-usertools
--enable-usertools \
--disable-libgcrypt \
--enable-openssl_crypto_provider
make V=1
@ -538,10 +533,10 @@ install -d -m 700 %{buildroot}%{rsyslog_statedir}
install -d -m 700 %{buildroot}%{rsyslog_pkidir}
install -d -m 755 %{buildroot}%{rsyslog_docdir}/html
install -p -m 644 %{SOURCE2} %{buildroot}%{_sysconfdir}/rsyslog.conf
install -p -m 644 %{SOURCE3} %{buildroot}%{_sysconfdir}/sysconfig/rsyslog
install -p -m 644 %{SOURCE4} %{buildroot}%{_sysconfdir}/logrotate.d/rsyslog
install -p -m 644 %{SOURCE5} %{buildroot}%{_unitdir}/rsyslog.service
install -p -m 644 %{SOURCE1} %{buildroot}%{_sysconfdir}/rsyslog.conf
install -p -m 644 %{SOURCE2} %{buildroot}%{_sysconfdir}/sysconfig/rsyslog
install -p -m 644 %{SOURCE3} %{buildroot}%{_sysconfdir}/logrotate.d/rsyslog
install -p -m 644 %{SOURCE4} %{buildroot}%{_unitdir}/rsyslog.service
%if %{with mysql}
install -p -m 644 plugins/ommysql/createDB.sql %{buildroot}%{rsyslog_docdir}/mysql-createDB.sql
@ -580,8 +575,8 @@ done
%{!?_licensedir:%global license %%doc}
%license COPYING*
%doc AUTHORS ChangeLog README.md
%{rsyslog_docdir}
%exclude %{rsyslog_docdir}/html
%exclude %{rsyslog_docdir}/recover_qi.pl
%if %{with mysql}
%exclude %{rsyslog_docdir}/mysql-createDB.sql
%endif
@ -598,6 +593,7 @@ done
%{_unitdir}/rsyslog.service
%config(noreplace) %{_sysconfdir}/rsyslog.conf
%config(noreplace) %{_sysconfdir}/sysconfig/rsyslog
%config(noreplace) %{_sysconfdir}/logrotate.d/rsyslog
# plugins
%{_libdir}/rsyslog/fmhash.so
%{_libdir}/rsyslog/fmhttp.so
@ -620,6 +616,7 @@ done
%{_libdir}/rsyslog/mmanon.so
%{_libdir}/rsyslog/mmcount.so
%{_libdir}/rsyslog/mmexternal.so
%{_libdir}/rsyslog/mmleefparse.so
%{_libdir}/rsyslog/mmutf8fix.so
%{_libdir}/rsyslog/omhttp.so
%{_libdir}/rsyslog/omjournal.so
@ -642,16 +639,14 @@ done
%{_libdir}/rsyslog/omclickhouse.so
%endif
%files logrotate
%config(noreplace) %{_sysconfdir}/logrotate.d/rsyslog
%files crypto
%{_bindir}/rscryutil
%{_mandir}/man1/rscryutil.1.gz
%{_libdir}/rsyslog/lmcry_gcry.so
%{_libdir}/rsyslog/lmcry_ossl.so
%files doc
%doc %{rsyslog_docdir}/html
%{rsyslog_docdir}/html
%{rsyslog_docdir}/recover_qi.pl
%files elasticsearch
%{_libdir}/rsyslog/omelasticsearch.so
@ -668,6 +663,9 @@ done
%files mmnormalize
%{_libdir}/rsyslog/mmnormalize.so
%files mmtaghostname
%{_libdir}/rsyslog/mmtaghostname.so
%if %{with snmp}
%files mmsnmptrapd
%{_libdir}/rsyslog/mmsnmptrapd.so
@ -757,6 +755,90 @@ done
%changelog
* Mon Oct 20 2025 Attila Lakatos <alakatos@redhat.com> - 8.2510.0-1
- Rebase to 8.2510.0
Resolves: rhbz#2404131
- imjournal open error handling fix
Resolves: rhbz#2375742
- Add mmleefparse module to base package
* Fri Sep 05 2025 Attila Lakatos <alakatos@redhat.com> - 8.2508.0-1
- Rebase to 8.2508.0
Resolves: rhbz#2392918
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 8.2506.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Thu Jun 12 2025 Attila Lakatos <alakatos@redhat.com> - 8.2506.0-1
- Rebase to 8.2506.0
Resolves: rhbz#2347628
* Tue Jan 21 2025 Attila Lakatos <alakatos@redhat.com> - 8.2412.0-3
- Fix build problem by resolving -Wincompatible-pointer-types error
* Sat Jan 18 2025 Fedora Release Engineering <releng@fedoraproject.org> - 8.2412.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Dec 05 2024 Attila Lakatos <alakatos@redhat.com> - 8.2412.0-1
- Rebase to 8.2412.0
- Harden rsyslog service unit
- Disable openssl engines support
Resolves: rhbz#2320050
* Fri Oct 04 2024 Attila Lakatos <alakatos@redhat.com> - 8.2408.0-2
- Rebuild package
Resolves: rhbz#2316361
* Wed Aug 21 2024 Attila Lakatos <alakatos@redhat.com> - 8.2408.0-1
- Rebase to 8.2408.0
Resolves: rhbz#2266329
Resolves: rhbz#2301246
Resolves: rhbz#2305398
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 8.2312.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed May 29 2024 Orion Poplawski <orion@nwra.com> - 8.2312.0-3
- Explicitly set imjournal FileCreateMode to quiet warning
* Sat May 11 2024 Kevin Fenzi <kevin@scrye.com> - 8.2312.0-2
- rebuild for hiredis soname bump
* Mon Feb 12 2024 Attila Lakatos <alakatos@redhat.com> - 8.2312.0-1
- Rebase to 8.2312.0
resolves: rhbz#2232275
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 8.2310.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Mon Jan 22 2024 Fedora Release Engineering <releng@fedoraproject.org> - 8.2310.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Jan 04 2024 Attila Lakatos <alakatos@redhat.com> - 8.2310.0-2
- Move rsyslog related logrotate config to the base package
resolves: rhbz#2242243
* Fri Aug 25 2023 Attila Lakatos <alakatos@redhat.com> - 8.2310.0-1
- Rebase to 8.2310.0
resolves: rhbz#2232275
* Wed Aug 16 2023 Stewart Smith <trawets@amazon.com> - 8.2306.0-4
- Add mmtaghostname module as a subpackage
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 8.2306.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sat Jul 15 2023 Yaroslav Fedevych <yaroslav@fedevych.name> - 8.2306.0-2
- Specify qpid-proton's source as full URL to fix isolated builds
* Wed Jun 21 2023 Attila Lakatos <alakatos@redhat.com> - 8.2306.0-1
- rebase to 8.2306.0
resolves: rhbz#2151339
resolves: rhbz#2151092
* Wed May 10 2023 Todd Zullinger <tmz@pobox.com> - 8.2210.0-5
- Use 'systemctl reload' in logrotate script
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 8.2210.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

View file

@ -1,3 +1,2 @@
SHA512 (qpid-proton-0.34.0.tar.gz) = 0de6c3d11baeee1d69821a0f1879a61b314f14589e02ea7ed0de8814c741217fdcafdd978b4061f73bc75588886299f4ac6808021506545ec8a883f39ad54fb3
SHA512 (rsyslog-8.2210.0.tar.gz) = c665b7f7a3c5ef31c9b62b50f815cfbb52db0cbe4a06934f4f1c3cd2a56fb49c319d33857ee92ab843aa5894cac16c16b8eccdf83714f31ab57a95049c4af231
SHA512 (rsyslog-doc-8.2210.0.tar.gz) = e7847a9307a91fdf87d6cf91d2391eb75869679905b9598310c456fb3fe1864fc06dbdc649778f5b3788e47ffda0a6d89cb894258e55db441f7df7e74b0ae9f4
SHA512 (rsyslog-8.2510.0.tar.gz) = d2e693fd8c7112e4ccc36ea6fbb19909df885e7cb2778e95c04b7c5e9db8240224decfee52308a46865b7deffcf1e31ade0104c90d84b768a4dece15e5ea190e
SHA512 (qpid-proton-0.40.0.tar.gz) = 3e7fe56ca1423f45f71d81f5e1d6ec5f21c073cc580628e12a8dbd545a86805b7312834e0d1234dde43797633d575ed639f21a96239b217500cc0a824482aae3

View file

@ -0,0 +1,2 @@
gef config gef.disable_color True
got-audit --all

10
tests/got-audit/main.fmf Normal file
View file

@ -0,0 +1,10 @@
summary: Audit the GOT for signs of tampering
description: |
Pointers in the server process GOT will be checked to ensure that
each function pointer's value is within a shared object file
that exports a symbol of that name, and that no shared object
files export conflicting symbols.
contact: Gordon Messmer <gordon.messmer@gmail.com>
require+:
- gdb-gef # needed to test got-audit

41
tests/got-audit/runtest.sh Executable file
View file

@ -0,0 +1,41 @@
#!/bin/bash
# vim: dict+=/usr/share/beakerlib/dictionary.vim cpt=.,w,b,u,t,i,k
# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
# runtest.sh of /CoreOS/rsyslog/Sanity/got-audit
# Description: Check pointers in the server process GOT for signs of tampering
# Author: Gordon Messmer <gordon.messmer@gmail.com>
#
# Include Beaker environment
. /usr/share/beakerlib/beakerlib.sh || exit 1
rlJournalStart
rlPhaseStartSetup
rlServiceStart rsyslog
rlRun "TestDir=\$(pwd)"
rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory"
rlRun "pushd $TmpDir"
rlRun "auditfile=\$(mktemp --tmpdir=${TmpDir})"
rlPhaseEnd
rlPhaseStartTest "Run GEF got-audit"
rlRun "SERVICE_PID=\$( systemctl show --property=MainPID rsyslog.service | cut -f2 -d= )"
rlRun "echo SERVICE_PID is '$SERVICE_PID'"
[ -n "$SERVICE_PID" ] || rlFail "No service pid was found"
rlRun "gdb-gef --pid '$SERVICE_PID' --command='$TestDir'/got-audit.gdb --batch > '$auditfile'"
# Basic test: ensure that at least one symbol is found in libc.so,
# to verify that the report looks plausible.
rlAssertGrep " : /.*/libc.so" "$auditfile"
# Ensure the got-audit did not report any errors
rlAssertNotGrep " :: ERROR" "$auditfile"
rlRun "cp '$auditfile' '$TMT_TEST_DATA'/got-audit.txt"
rlPhaseEnd
rlPhaseStartCleanup
rlServiceRestore rsyslog
rlRun "popd"
rlRun "rm -r $TmpDir" 0 "Removing tmp directory"
rlPhaseEnd
rlJournalPrintText
rlJournalEnd

2
tests/main.fmf Normal file
View file

@ -0,0 +1,2 @@
test: ./runtest.sh
framework: beakerlib