Search Results for: error 0

ChangeLog for 4.2.0 (v4-stable)

Version 4.2.0 [v4-stable] (rgerhards), 2009-06-23

  • bugfix: light and full delay watermarks had invalid values, badly affecting performance for delayable inputs
  • bugfix: compile problems in im3195
  • imported all patches from 3.22.1 as of today (see below):
    • bugfix: invalid error message issued if $inlcudeConfig was on an empty set of files (e.g. *.conf, where none such files existed) thanks to Michael Biebl for reporting this bug
    • bugfix: when run in foreground (but not in debug mode), a debug message (“DoDie called”) was emitted at shutdown. Removed. thanks to Michael Biebl for reporting this bug
    • bugfix: some garbagge was emitted to stderr on shutdown. This garbage consisted of file names, which were written during startup (key point: not a pointer error) thanks to Michael Biebl for reporting this bug
    • bugfix: startup and shutdown message were emitted to stdout
      thanks to Michael Biebl for reporting this bug
    • bugfix: error messages were not emitted to stderr in forked mode (stderr and stdo are now kept open across forks)
    • bugfix: internal messages were emitted to whatever file had fd2 when rsyslogd ran in forked mode (as usual!) Thanks to varmojfekoj for the patch
    • small enhancement: config validation run now exits with code 1 if an error is detected. This change is considered important but small enough to apply it directly to the stable version. [But it is a border case, the change requires more code than I had hoped. Thus I have NOT tried to actually catch all cases, this is left for the current devel releases, if necessary]
    • bugfix: light and full delay watermarks had invalid values, badly affecting performance for delayable inputs
    • bugfix: potential segfault issue when multiple $UDPServerRun directives are specified. Thanks to Michael Biebl for helping to debug this one.
    • relaxed GnuTLS version requirement to 1.4.0 after confirmation from the field that this version is sufficient
    • bugfix: parser did not properly handle empty structured data

As a reminder:

Version 4.1.0 [DEVEL] (rgerhards), 2008-11-18

********************************* WARNING *********************************
This version has a slightly different on-disk format for message entries.
As a consequence, old queue files being read by this version may have
an invalid output timestamp, which could result to some malfunction inside
the output driver. It is recommended to drain queues with the previous
version before switching to this one.
********************************* WARNING *********************************
  • greatly enhanced performance when compared to v3.
  • added configuration directive “HUPisRestart” which enables to configure
    HUP to be either a full restart or “just” a leightweight way to
    close open files.
  • enhanced legacy syslog parser to detect year if part of the timestamp
    the format is based on what Cisco devices seem to emit.
  • added a setting “$OptimizeForUniprocessor” to enable users to turn off
    pthread_yield calls which are counter-productive on multiprocessor
    machines (but have been shown to be useful on uniprocessors)
  • reordered imudp processing. Message parsing is now done as part of main
    message queue worker processing (was part of the input thread)
    This should also improve performance, as potentially more work is
    done in parallel.
  • bugfix: compressed syslog messages could be slightly mis-uncompressed
    if the last byte of the compressed record was a NUL
  • added $UDPServerTimeRequery option which enables to work with
    less acurate timestamps in favor of performance. This enables querying
    of the time only every n-th time if imudp is running in the tight
    receive loop (aka receiving messsages at a high rate)
  • doc bugfix: queue doc had wrong parameter name for setting controlling
    worker thread shutdown period
  • restructured rsyslog.conf documentation
  • bugfix: memory leak in ompgsql
    Thanks to Ken for providing the patch

ChangeLog for 4.1.6 (devel)

Version 4.1.6 [DEVEL] (rgerhards), 2009-04-07

  • added new “csv” property replacer options to enable simple creation of CSV-formatted outputs (format from RFC4180 is used)
  • implemented function support in RainerScript. That means the engine parses and compile functions, as well as executes a few build-in ones. Dynamic loading and registration of functions is not yet supported – but we now have a good foundation to do that later on.
  • implemented the strlen() RainerScript function
  • added a template output module
  • added -T rsyslogd command line option, enables to specify a directory where to chroot() into on startup. This is NOT a security feature but introduced to support testing. Thus, -T does not make sure chroot() is used in a secure way. (may be removed later)
  • added omstdout module for testing purposes. Spits out all messages to stdout – no config option, no other features
  • added a parser testing suite (still needs to be extended, but a good start)
  • modified $ModLoad statement so that for modules whom’s name starts with
    a dot, no path is prepended (this enables relative-pathes and should not break any valid current config)

  • fixed a bug that caused action retries not to work correctly situation was only cleared by a restart
  • bugfix: closed dynafile was potentially never written until another dynafile name was generated – potential loss of messages
  • improved omfile so that it properly suspends itself if there is an i/o or file name generation error. This enables it to be used with the full high availability features of rsyslog’s engine
  • bugfix: fixed some segaults on Solaris, where vsprintf() does not check for NULL pointers
  • improved performance of regexp-based filters. Thanks to Arnaud Cornet for providing the idea and initial patch.
  • added a new way how output plugins may be passed parameters. This is more effcient for some outputs. They new can receive fields not only as a single string but rather in an array where each string is seperated.
  • added (some) developer documentation for output plugin interface
  • bugfix: potential abort with DA queue after high watermark is reached There exists a race condition that can lead to a segfault. Thanks go to vbernetr, who performed the analysis and provided patch, which I only tweaked a very little bit.
  • bugfix: imtcp did incorrectly parse hostname/tag Thanks to Luis Fernando Muñoz Mejías for the patch.

$AllowedSender not honored

A primitive way of access control is offered in rsyslog via the $AllowedSender configuration directive. It permits the operator to specify hosts from which messages are being accepted. If the directive is not specified, messages from all hosts are accepted. If it is, the set is limited to those senders that match the configured criteria (this can be network addresses or host name). Access control can be configured for UDP- based and TCP-based protocols independently.

Note that this directive may be used to simplify firewall setup, where the firewall permits incoming traffic from all remote machines on the port in question. Then rsyslog ACLs are used to control who is actually permitted. The down-side of this approach is that the packets reach rsyslog and any vulnerability in it can be exploited. Please note that UDP addresses can easily be spoofed (though thankfully not as easy any longer on the public Internet thanks to more careful configuration on most ISP’s side). So an IP-based access control does not work very well for UDP (neither at the firewall nor at the rsyslog level – but the firewall may have more options at hand, given its comparatively broad knowledge of the perimeter). Continue reading “$AllowedSender not honored”

ChangeLog for 3.18.4 (v3-stable)

Version 3.18.4 (rgerhards), 2008-09-18

  • bugfix: order-of magnitude issue with base-10 size definitions
    in config file parser. Could lead to invalid sizes, constraints
    etc for e.g. queue files and any other object whose size was specified
    in base-10 entities. Did not apply to binary entities. Thanks to
    RB for finding this bug and providing a patch.

  • bugfix: action was not called when system time was set backwards
    (until the previous time was reached again). There are still some
    side-effects when time is rolled back (A time rollback is really a bad
    thing to do, ideally the OS should issue pseudo time (like NetWare did)
    when the user tries to roll back time). Thanks to varmojfekoj for this
    patch.

  • doc bugfix: rsyslog.conf man page improved and minor nit fixed
    thanks to Lukas Kuklinek for the patch.

  • bugfix: error code -2025 was used for two different errors. queue full
    is now -2074 and -2025 is unique again. (did cause no real problem
    except for troubleshooting)

  • bugfix: default discard severity was incorrectly set to 4, which lead
    to discard-on-queue-full to be enabled by default. That could cause
    message loss where non was expected. The default has now been changed
    to the correct value of 8, which disables the functionality. This
    problem applied both to the main message queue and the action queues.
    Thanks to Raoul Bhatia for pointing out this problem.

  • bugfix: option value for legacy -a option could not be specified,
    resulting in strange operations. Thanks to Marius Tomaschewski
    for the patch.

  • bugfix: colon after date should be ignored, but was not. This has
    now been corrected. Required change to the internal ParseTIMESTAMP3164()
    interface.

ChangeLog for 3.21.1 (devel)

Version 3.21.1 [DEVEL] (rgerhards), 2008-07-30

  • bugfix: no error was reported if the target of a $IncludeConfig
    could not be accessed.

  • added testbed for common config errors
  • enhanced config file checking – no active actions are detected
  • added -N rsyslogd command line option for a config validation run
    (which does not execute actual syslogd code and does not interfere
    with a running instance)

  • somewhat improved emergency configuration. It is now also selected
    if the config contains no active actions

  • rsyslogd error messages are now reported to stderr by default. can be
    turned off by the new “$ErrorMessagesToStderr off” directive

Thanks to HKS for suggesting the new features.

Scroll to top