Files
fips/packaging/freebsd/fips.newsyslog
T
Johnathan Corgan ad021fab5e Rotate the FreeBSD daemon log with newsyslog
The FreeBSD package wrote the daemon's output to /var/log/fips.log and
never rotated it, so the log grew without bound. Ship a newsyslog entry
in /usr/local/etc/newsyslog.conf.d, which the stock newsyslog.conf
includes: five bzip2-compressed generations of 1000 KB, mode 600 to
match the file daemon(8) creates.

An entry alone would not work, because daemon(8) keeps the -o file open
and reopens it on SIGHUP only when started with -H, and only the
supervisor handles that signal. The rc script now starts daemon(8) with
-H and records the supervisor's pid in /var/run/fips/daemon.pid, which
is the pid file the entry signals. The child pidfile that rc.subr uses
for stop and status is unchanged.

Add a lib test that checks the rc script, the newsyslog entry and the
package staging agree on the log path, the signalled pid file and the
installed location.

The FreeBSD package smoke install now also confirms the stock newsyslog
configuration picks up the shipped entry, starts the daemon, forces a
rotation of its log, and checks that daemon(8) closes the rotated file
and holds the new one open. This exercises the SIGHUP reopen that the
static check of the packaging files cannot.
2026-09-23 19:52:29 +00:00

14 lines
799 B
Plaintext

# newsyslog(8) rotation for the FIPS daemon log. Installed as
# /usr/local/etc/newsyslog.conf.d/fips.conf, which the stock
# /etc/newsyslog.conf includes.
#
# 5 generations, rotate at 1000 KB, bzip2-compressed (J), created if
# missing (C), mode 600 as daemon(8) itself creates the log. The pid file
# is the daemon(8) supervisor's (-P in the rc script), not the fips
# process's: newsyslog sends it SIGHUP after the rename, and the rc script
# starts daemon(8) with -H, which reopens the log on that signal. Without
# -H the daemon keeps writing into the rotated file. Covers the default
# fips_logfile only.
# logfilename [owner:group] mode count size when flags [/pid_file] [sig_num]
/var/log/fips.log 600 5 1000 * JC /var/run/fips/daemon.pid