Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #247177 > unrolled thread

Strange syslog behaviour [Solved]

Started byJeremy Ardley <jeremy@ardley.org>
First post2022-04-11 04:10 +0200
Last post2022-04-12 01:00 +0200
Articles 6 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-11 04:10 +0200
    Re: Strange syslog behaviour [Solved] David Wright <deblis@lionunicorn.co.uk> - 2022-04-11 05:50 +0200
      Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-11 06:10 +0200
        Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-12 00:40 +0200
          Re: Strange syslog behaviour [Solved] Jeremy Ardley <jeremy@ardley.org> - 2022-04-12 01:10 +0200
        Re: Strange syslog behaviour [Solved] David Wright <deblis@lionunicorn.co.uk> - 2022-04-12 01:00 +0200

#247177 — Strange syslog behaviour [Solved]

FromJeremy Ardley <jeremy@ardley.org>
Date2022-04-11 04:10 +0200
SubjectStrange syslog behaviour [Solved]
Message-ID<EaRF7-7Vqm-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

I have systems (armbian) that had anomalous behaviour.

This included sometimes writing to /var/log/syslog.1 rather than to 
/var/log/syslog (which was created, but zero size)

Additionally the logrotate was happening daily or twice daily when 
seemingly configured for weekly rotates

Anyway long story short, at some stage some package updates must have 
written an extra file into /etc/logrotate.d that had duplicate entries 
to the normal files.

This was interpreted by the logrotate process as well as the intended 
files such as /etc/logrotated.d/rsyslog

On one system this unexpected file was called rsyslog.dpkg-old on 
another system it was rsyslog.dpkg-dist

Removing these files ( but not /etc/logrotate.d/dpkg ) now has a 
correctly configured log rotation


-- 
Jeremy

[toc] | [next] | [standalone]


#247181

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2022-04-11 05:50 +0200
Message-ID<EaTdT-7Wly-3@gated-at.bofh.it>
In reply to#247177
On Mon 11 Apr 2022 at 10:07:53 (+0800), Jeremy Ardley wrote:
> I have systems (armbian) that had anomalous behaviour.
> 
> This included sometimes writing to /var/log/syslog.1 rather than to
> /var/log/syslog (which was created, but zero size)
> 
> Additionally the logrotate was happening daily or twice daily when
> seemingly configured for weekly rotates
> 
> Anyway long story short, at some stage some package updates must have
> written an extra file into /etc/logrotate.d that had duplicate entries
> to the normal files.
> 
> This was interpreted by the logrotate process as well as the intended
> files such as /etc/logrotated.d/rsyslog

So presumably one instance was still writing to /var/log/syslog
when the other one rotated it and created a new one.

> On one system this unexpected file was called rsyslog.dpkg-old on
> another system it was rsyslog.dpkg-dist

Should we assume that you know how these files came to be present,
ie that rsyslog had been modified, after which, during upgrading,
apt had been given the responses "keep the old one" (Debian's
new version becomes ….dpkg-dist) and "replace by the new one (your
old version is renamed ….dpkg-old).

> Removing these files ( but not /etc/logrotate.d/dpkg ) now has a
> correctly configured log rotation

There are tabooext and taboopat directives for ignoring files in
logrotated.d, and I would have thought it reasonable to exclude
these sorts of housekeeping files by default, because they're very
likely to contain some duplication. I would file a bug against
logrotate.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#247183

FromJeremy Ardley <jeremy@ardley.org>
Date2022-04-11 06:10 +0200
Message-ID<EaTxf-7WHe-1@gated-at.bofh.it>
In reply to#247181

[Multipart message — attachments visible in raw view] — view raw

On 11/4/22 11:46 am, David Wright wrote:
>
> There are tabooext and taboopat directives for ignoring files in
> logrotated.d, and I would have thought it reasonable to exclude
> these sorts of housekeeping files by default, because they're very
> likely to contain some duplication. I would file a bug against
> logrotate.
>
Keywords tabooext and taboopat don't appear in /etc/*

I did get a hit in binary file /usr/sbin/rsyslogd

Jeremy

[toc] | [prev] | [next] | [standalone]


#247199

FromJeremy Ardley <jeremy@ardley.org>
Date2022-04-12 00:40 +0200
Message-ID<EbaRs-874Z-5@gated-at.bofh.it>
In reply to#247183

[Multipart message — attachments visible in raw view] — view raw

On 11/4/22 12:00 pm, Jeremy Ardley wrote:
> On 11/4/22 11:46 am, David Wright wrote:
>>
>> There are tabooext and taboopat directives for ignoring files in
>> logrotated.d, and I would have thought it reasonable to exclude
>> these sorts of housekeeping files by default, because they're very
>> likely to contain some duplication. I would file a bug against
>> logrotate.
>>
> Keywords tabooext and taboopat don't appear in /etc/*
>
> I did get a hit in binary file /usr/sbin/rsyslogd
>
>
Further to resolving the problem, on one system I ran

logrotate --debug /etc/logrotate.conf

And discovered that /etc/logrotate.d/inetutils-syslogd was also being 
loaded. It had duplicates of many entries in /etc/logrotate.d/rsyslog

I have no idea why inetutils did this. I recall inetutils also did some 
other bad stuff I had to disable.

All I wanted was ping but I got a world of hurt as well!

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#247202

FromJeremy Ardley <jeremy@ardley.org>
Date2022-04-12 01:10 +0200
Message-ID<Ebbkt-87u2-3@gated-at.bofh.it>
In reply to#247199

[Multipart message — attachments visible in raw view] — view raw

On 12/4/22 6:38 am, Jeremy Ardley wrote:
>
> And discovered that /etc/logrotate.d/inetutils-syslogd was also being 
> loaded. It had duplicates of many entries in /etc/logrotate.d/rsyslog
>
> All I wanted was ping _traceroute_ but I got a world of hurt as well!
>

*this* seems likely to solve the problems on that machine and still keep 
traceroute

rm -f /etc/logrotate.d/inetutils-syslogd
systemctl stop inetutils-syslogd.service
systemctl disable inetutils-syslogd.service
systemctl mask inetutils-syslogd.service
systemctl stop inetutils-inetd.service
systemctl disable inetutils-inetd.service
systemctl mask inetutils-inetd.service

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#247201

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2022-04-12 01:00 +0200
Message-ID<EbbaN-87bx-7@gated-at.bofh.it>
In reply to#247183
On Mon 11 Apr 2022 at 12:00:38 (+0800), Jeremy Ardley wrote:
> On 11/4/22 11:46 am, David Wright wrote:
> > 
> > There are tabooext and taboopat directives for ignoring files in
> > logrotated.d, and I would have thought it reasonable to exclude
> > these sorts of housekeeping files by default, because they're very
> > likely to contain some duplication. I would file a bug against
> > logrotate.
> > 
> Keywords tabooext and taboopat don't appear in /etc/*

Looking further into this, I see that tabooext has a sizeable default
list of excluded extensions, and this list is built into logrotate, so
a tabooext directive doesn't have to be specified in logrotate.conf.
The default includes the two extensions you mentioned.

The tabooext list can be appended to, but can also be overwritten if
the necessary + is forgotten. Can we assume you haven't done that?

> I did get a hit in binary file /usr/sbin/rsyslogd

If you mean rsyslogd and not logrotate, that's presumably in the
≥testing version (ie not buster or bullseye).

$ strings /usr/sbin/rsyslogd | grep -n -e dpkg -e rpm -e ucf
$ strings /usr/sbin/logrotate | grep -n -e dpkg -e rpm -e ucf
982:.dpkg-bak
983:.dpkg-del
984:.dpkg-dist
985:.dpkg-new
986:.dpkg-old
987:.dpkg-tmp
989:.rpmnew
990:.rpmorig
991:.rpmsave
993:.ucf-dist
994:.ucf-new
995:.ucf-old
$ 

Cheers,
David.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web