Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #247177 > unrolled thread
| Started by | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| First post | 2022-04-11 04:10 +0200 |
| Last post | 2022-04-12 01:00 +0200 |
| Articles | 6 — 2 participants |
Back to article view | Back to linux.debian.user
Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-11 04:10 +0200
Re: Strange syslog behaviour [Solved] David Wright <deblis@lionunicorn.co.uk> - 2022-04-11 05:50 +0200
Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-11 06:10 +0200
Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-12 00:40 +0200
Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-12 01:10 +0200
Re: Strange syslog behaviour [Solved] David Wright <deblis@lionunicorn.co.uk> - 2022-04-12 01:00 +0200
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-04-11 04:10 +0200 |
| Subject | Strange syslog behaviour [Solved] |
| Message-ID | <EaRF7-7Vqm-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
I have systems (armbian) that had anomalous behaviour. This included sometimes writing to /var/log/syslog.1 rather than to /var/log/syslog (which was created, but zero size) Additionally the logrotate was happening daily or twice daily when seemingly configured for weekly rotates Anyway long story short, at some stage some package updates must have written an extra file into /etc/logrotate.d that had duplicate entries to the normal files. This was interpreted by the logrotate process as well as the intended files such as /etc/logrotated.d/rsyslog On one system this unexpected file was called rsyslog.dpkg-old on another system it was rsyslog.dpkg-dist Removing these files ( but not /etc/logrotate.d/dpkg ) now has a correctly configured log rotation -- Jeremy
[toc] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2022-04-11 05:50 +0200 |
| Message-ID | <EaTdT-7Wly-3@gated-at.bofh.it> |
| In reply to | #247177 |
On Mon 11 Apr 2022 at 10:07:53 (+0800), Jeremy Ardley wrote: > I have systems (armbian) that had anomalous behaviour. > > This included sometimes writing to /var/log/syslog.1 rather than to > /var/log/syslog (which was created, but zero size) > > Additionally the logrotate was happening daily or twice daily when > seemingly configured for weekly rotates > > Anyway long story short, at some stage some package updates must have > written an extra file into /etc/logrotate.d that had duplicate entries > to the normal files. > > This was interpreted by the logrotate process as well as the intended > files such as /etc/logrotated.d/rsyslog So presumably one instance was still writing to /var/log/syslog when the other one rotated it and created a new one. > On one system this unexpected file was called rsyslog.dpkg-old on > another system it was rsyslog.dpkg-dist Should we assume that you know how these files came to be present, ie that rsyslog had been modified, after which, during upgrading, apt had been given the responses "keep the old one" (Debian's new version becomes ….dpkg-dist) and "replace by the new one (your old version is renamed ….dpkg-old). > Removing these files ( but not /etc/logrotate.d/dpkg ) now has a > correctly configured log rotation There are tabooext and taboopat directives for ignoring files in logrotated.d, and I would have thought it reasonable to exclude these sorts of housekeeping files by default, because they're very likely to contain some duplication. I would file a bug against logrotate. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-04-11 06:10 +0200 |
| Message-ID | <EaTxf-7WHe-1@gated-at.bofh.it> |
| In reply to | #247181 |
[Multipart message — attachments visible in raw view] — view raw
On 11/4/22 11:46 am, David Wright wrote: > > There are tabooext and taboopat directives for ignoring files in > logrotated.d, and I would have thought it reasonable to exclude > these sorts of housekeeping files by default, because they're very > likely to contain some duplication. I would file a bug against > logrotate. > Keywords tabooext and taboopat don't appear in /etc/* I did get a hit in binary file /usr/sbin/rsyslogd Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-04-12 00:40 +0200 |
| Message-ID | <EbaRs-874Z-5@gated-at.bofh.it> |
| In reply to | #247183 |
[Multipart message — attachments visible in raw view] — view raw
On 11/4/22 12:00 pm, Jeremy Ardley wrote: > On 11/4/22 11:46 am, David Wright wrote: >> >> There are tabooext and taboopat directives for ignoring files in >> logrotated.d, and I would have thought it reasonable to exclude >> these sorts of housekeeping files by default, because they're very >> likely to contain some duplication. I would file a bug against >> logrotate. >> > Keywords tabooext and taboopat don't appear in /etc/* > > I did get a hit in binary file /usr/sbin/rsyslogd > > Further to resolving the problem, on one system I ran logrotate --debug /etc/logrotate.conf And discovered that /etc/logrotate.d/inetutils-syslogd was also being loaded. It had duplicates of many entries in /etc/logrotate.d/rsyslog I have no idea why inetutils did this. I recall inetutils also did some other bad stuff I had to disable. All I wanted was ping but I got a world of hurt as well! -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2022-04-12 01:10 +0200 |
| Message-ID | <Ebbkt-87u2-3@gated-at.bofh.it> |
| In reply to | #247199 |
[Multipart message — attachments visible in raw view] — view raw
On 12/4/22 6:38 am, Jeremy Ardley wrote: > > And discovered that /etc/logrotate.d/inetutils-syslogd was also being > loaded. It had duplicates of many entries in /etc/logrotate.d/rsyslog > > All I wanted was ping _traceroute_ but I got a world of hurt as well! > *this* seems likely to solve the problems on that machine and still keep traceroute rm -f /etc/logrotate.d/inetutils-syslogd systemctl stop inetutils-syslogd.service systemctl disable inetutils-syslogd.service systemctl mask inetutils-syslogd.service systemctl stop inetutils-inetd.service systemctl disable inetutils-inetd.service systemctl mask inetutils-inetd.service -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2022-04-12 01:00 +0200 |
| Message-ID | <EbbaN-87bx-7@gated-at.bofh.it> |
| In reply to | #247183 |
On Mon 11 Apr 2022 at 12:00:38 (+0800), Jeremy Ardley wrote: > On 11/4/22 11:46 am, David Wright wrote: > > > > There are tabooext and taboopat directives for ignoring files in > > logrotated.d, and I would have thought it reasonable to exclude > > these sorts of housekeeping files by default, because they're very > > likely to contain some duplication. I would file a bug against > > logrotate. > > > Keywords tabooext and taboopat don't appear in /etc/* Looking further into this, I see that tabooext has a sizeable default list of excluded extensions, and this list is built into logrotate, so a tabooext directive doesn't have to be specified in logrotate.conf. The default includes the two extensions you mentioned. The tabooext list can be appended to, but can also be overwritten if the necessary + is forgotten. Can we assume you haven't done that? > I did get a hit in binary file /usr/sbin/rsyslogd If you mean rsyslogd and not logrotate, that's presumably in the ≥testing version (ie not buster or bullseye). $ strings /usr/sbin/rsyslogd | grep -n -e dpkg -e rpm -e ucf $ strings /usr/sbin/logrotate | grep -n -e dpkg -e rpm -e ucf 982:.dpkg-bak 983:.dpkg-del 984:.dpkg-dist 985:.dpkg-new 986:.dpkg-old 987:.dpkg-tmp 989:.rpmnew 990:.rpmorig 991:.rpmsave 993:.ucf-dist 994:.ucf-new 995:.ucf-old $ Cheers, David.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web