|
From: Dean N. <di...@ti...> - 2003-08-20 06:58:53
|
[... I am still using the 08-08-i686-SMP version...] I [finally] noticed that I was not receiving any messages from IPTables about dropped packets (my firewall.rules file is setup to log most packets that are dropped). So, I started looking around... I noticed that reloading (/etc/init.d/syslog reload) would "cure" the problem, so I determine that everything is probably properly configured. So, I kept digging... I then noticed that the syslog daemon was logging the fact that is was restarting as part of the load. I was able to determine that this happened when Postfix was started. After the syslog daemon was restarted, I no longer received IPTables messages. Looking over /etc/init.d/jail, I found out that it does a /etc/init.d/syslog reload! So, I figured this was the "source" of my problem! Looking over /etc/init.d/syslog, I reviewed the reload code. I became suspicious of the hack that was in there to handle the killing of the klogd daemon. To very that this was indeed the problem, I made two changes: o I removed the entire logic used to kill the klogd daemon and instead inserted a "killproc klogd" command. o For the restart of klogd, I changed it to read "loadproc klogd -c $KERNEL_LOGLEVEL". Now, everything works! [The first bug report.] I presume that some of the problem is related to the fact that the previous method of killing the daemon did not properly cleanup the file /var/run/klogd.pid - but I could be wrong. And, while I was reviewing /etc/init.d/syslog, I noticed that it was still using the "old" 0.5 reference for the jail area (checking for /jail/$A/... so as to remove them from syslog-ng.conf). These statements are probably harmless (as the current system has /etc/init.d/jail ADDING entries to the syslog-ng.conf file - thus the reload). [The 1/2 of a bug report] Dean Nedelman TimeLord Consulting |