Mailing List Archive

rsyslog 1.19.5 released
Hi all,

Rsyslog 1.19.5 has been released. It is primarily targeted at fixing
rare situations in which a segfault could occur. These have not
consistently been able to reproduce in lab. Release 1.19.5 may still
have a problem or may hang where previous versions segfaulted. We are
actively looking for feedback from the field. Feature-wise, the $ModDir
config directive has been added and $ModLoad has been enhanced. We
recommend upgrading only for those that experience the problem with
earlier versions or those actively interested in helping to solve the
bug. If you experience a bug, please report it.

Changelog:

http://www.rsyslog.com/Article125.phtml

Download:

http://www.rsyslog.com/Downloads-req-getit-lid-57.phtml

As always, feedback is appreciated.

Rainer Gerhards
rsyslog 1.19.5 released [ In reply to ]
Am Freitag, den 07.09.2007, 18:14 +0200 schrieb Rainer Gerhards:
> Hi all,
>
> Rsyslog 1.19.5 has been released. It is primarily targeted at fixing
> rare situations in which a segfault could occur. These have not
> consistently been able to reproduce in lab. Release 1.19.5 may still
The way I see it everyone reporting segfaults so far has been using
RHEL5. So perhaps everybody seeing problems could comment on the
operating-system? That might ease reproducing the problem in a
test-lab.

> have a problem or may hang where previous versions segfaulted. We are
> actively looking for feedback from the field. Feature-wise, the $ModDir
> config directive has been added and $ModLoad has been enhanced. We
> recommend upgrading only for those that experience the problem with
> earlier versions or those actively interested in helping to solve the
> bug. If you experience a bug, please report it.
Crash of 1.19.5 after less than 30 minutes. Stack-trace seems to be
quite "normal", however, I've been lucky and captured some
strace-information. Not sure wheter that could be helpful.



poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "P*\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129\7in-a"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "P*\205\200\0\1\0\1\0\6\0\7\00282\003185\00213\003129
\7"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>exim[14623]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.82")}, [16]) = 165
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "\236\222\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "\236\222\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
\003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>exim[14099]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.82")}, [16]) = 243
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "\377\251\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "\377\251\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
\003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>spamd[16561]: spamd: identif"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 94
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "\202\24\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "\202\24\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>spamd[16561]: spamd: result:"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 463
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "\33\\\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "\33\\\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>exim[15976]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 143
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "I\27\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7in"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "I\27\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\003129"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "v\325\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "v\325\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<21>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
futex(0x3627949960, FUTEX_WAKE, 1) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "+\330\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "+\330\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<13>greylistd: Socket error: Bro"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 41
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "+\366\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "+\366\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<21>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "\233A\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "\233A\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
recvfrom(5, "<22>exim[14536]: 2007-09-07 18:3"..., 2047, 0,
{sa_family=AF_INET, sin_port=htons(514),
sin_addr=inet_addr("129.13.185.82")}, [16]) = 171
rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
open("/etc/hosts", O_RDONLY) = 17
fcntl(17, F_GETFD) = 0
fcntl(17, F_SETFD, FD_CLOEXEC) = 0
fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0)
= 0x2aaab4000000
read(17, "# Do not remove the following li"..., 4096) = 234
read(17, "", 4096) = 0
close(17) = 0
munmap(0x2aaab4000000, 4096) = 0
socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
connect(17, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, 28) = 0
fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
sendto(17, "M\243\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129\7i"...,
44, MSG_NOSIGNAL, NULL, 0) = 44
poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
ioctl(17, FIONREAD, [344]) = 0
recvfrom(17, "M\243\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
\00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
close(17) = 0
socket(PF_NETLINK, SOCK_RAW, 0) = 17
bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
[4294967308]) = 0
sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
{sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
\200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
groups=00000000}, msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
\0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
close(17) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
select(6, [0 4 5], [], NULL, NULL) = ? ERESTARTNOHAND (To be
restarted)
trace: ptrace(PTRACE_SYSCALL, ...): No such process
Process 22923 detached

--
CU,
Patrick.
rsyslog 1.19.5 released [ In reply to ]
On Fri, Sep 07, 2007 at 07:20:12PM +0200, Patrick von der Hagen wrote:
> Am Freitag, den 07.09.2007, 18:14 +0200 schrieb Rainer Gerhards:
> > Hi all,
> >
> > Rsyslog 1.19.5 has been released. It is primarily targeted at fixing
> > rare situations in which a segfault could occur. These have not
> > consistently been able to reproduce in lab. Release 1.19.5 may still
> The way I see it everyone reporting segfaults so far has been using
> RHEL5. So perhaps everybody seeing problems could comment on the
> operating-system? That might ease reproducing the problem in a
> test-lab.

I experience segfaults with 1.19.1 or 1.19.2 on FreeBSD, but
1.19.3 has been up for a week on end now.
rsyslog 1.19.5 released [ In reply to ]
Patrick von der Hagen wrote:
> Am Freitag, den 07.09.2007, 18:14 +0200 schrieb Rainer Gerhards:
>> Hi all,
>>
>> Rsyslog 1.19.5 has been released. It is primarily targeted at fixing
>> rare situations in which a segfault could occur. These have not
>> consistently been able to reproduce in lab. Release 1.19.5 may still
> The way I see it everyone reporting segfaults so far has been using
> RHEL5. So perhaps everybody seeing problems could comment on the
> operating-system? That might ease reproducing the problem in a
> test-lab.
>
>> have a problem or may hang where previous versions segfaulted. We are
>> actively looking for feedback from the field. Feature-wise, the $ModDir
>> config directive has been added and $ModLoad has been enhanced. We
>> recommend upgrading only for those that experience the problem with
>> earlier versions or those actively interested in helping to solve the
>> bug. If you experience a bug, please report it.
> Crash of 1.19.5 after less than 30 minutes. Stack-trace seems to be
> quite "normal", however, I've been lucky and captured some
> strace-information. Not sure wheter that could be helpful.

Thanks for the info. It will be very useful if someone can provide a
core dump for 1.19.5.
rsyslog 1.19.5 released [ In reply to ]
On 2007-09-08, Tomas Heinrich <theinric at redhat.com> wrote:
>
> Thanks for the info. It will be very useful if someone can provide a
> core dump for 1.19.5.

I haven't had the chance to upgrade yet, but any hints for how to get
a core dump if it fails ? I've tried this in the init-script:

ulimit -c unlimited
cd /var/log/syslog
echo -n $"Starting system logger (rsyslog): "
daemon rsyslogd $SYSLOGD_OPTIONS

but haven't gotten any core-dumps in any of the crashes I've had..



-jf
rsyslog 1.19.5 released [ In reply to ]
Hhmmm...

Besides a core-dump (which would definitely be useful), could those of
you experiencing this problem try to run rsyslog with debug code
enabled?

This is NOT debug mode (-d). You enable it via

./configure --enable-debug

This will generate additional debug checks in the rsyslog code. The
resulting code will probably run 5 to 10 times SLOWER than production
code. But it will catch many obscure errors and at least provide a hint
to where the problem is (at least I hope so).

If you could do that, that would be great.

Thanks,
Rainer

> -----Original Message-----
> From: rsyslog-bounces at lists.adiscon.com [mailto:rsyslog-
> bounces at lists.adiscon.com] On Behalf Of Patrick von der Hagen
> Sent: Friday, September 07, 2007 7:20 PM
> To: rsyslog-users
> Subject: Re: [rsyslog] rsyslog 1.19.5 released
>
> Am Freitag, den 07.09.2007, 18:14 +0200 schrieb Rainer Gerhards:
> > Hi all,
> >
> > Rsyslog 1.19.5 has been released. It is primarily targeted at fixing
> > rare situations in which a segfault could occur. These have not
> > consistently been able to reproduce in lab. Release 1.19.5 may still
> The way I see it everyone reporting segfaults so far has been using
> RHEL5. So perhaps everybody seeing problems could comment on the
> operating-system? That might ease reproducing the problem in a
> test-lab.
>
> > have a problem or may hang where previous versions segfaulted. We
are
> > actively looking for feedback from the field. Feature-wise, the
> $ModDir
> > config directive has been added and $ModLoad has been enhanced. We
> > recommend upgrading only for those that experience the problem with
> > earlier versions or those actively interested in helping to solve
the
> > bug. If you experience a bug, please report it.
> Crash of 1.19.5 after less than 30 minutes. Stack-trace seems to be
> quite "normal", however, I've been lucky and captured some
> strace-information. Not sure wheter that could be helpful.
>
>
>
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"P*\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129\7in-a"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "P*\205\200\0\1\0\1\0\6\0\7\00282\003185\00213\003129
> \7"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>exim[14623]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.82")}, [16]) = 165
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"\236\222\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "\236\222\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
> \003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>exim[14099]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.82")}, [16]) = 243
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"\377\251\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "\377\251\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
> \003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>spamd[16561]: spamd: identif"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 94
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
> "\202\24\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "\202\24\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \003"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>spamd[16561]: spamd: result:"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 463
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"\33\\\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "\33\\\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>exim[15976]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 143
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"I\27\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7in"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "I\27\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \003129"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"v\325\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "v\325\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<21>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> futex(0x3627949960, FUTEX_WAKE, 1) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"+\330\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "+\330\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<13>greylistd: Socket error: Bro"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 41
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"+\366\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "+\366\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<21>exim[15583]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.81")}, [16]) = 318
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"\233A\1\0\0\1\0\0\0\0\0\0\00281\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "\233A\205\200\0\1\0\1\0\6\0\7\00281\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = 1 (in [5])
> recvfrom(5, "<22>exim[14536]: 2007-09-07 18:3"..., 2047, 0,
> {sa_family=AF_INET, sin_port=htons(514),
> sin_addr=inet_addr("129.13.185.82")}, [16]) = 171
> rt_sigprocmask(SIG_BLOCK, [HUP], [], 8) = 0
> open("/etc/hosts", O_RDONLY) = 17
> fcntl(17, F_GETFD) = 0
> fcntl(17, F_SETFD, FD_CLOEXEC) = 0
> fstat(17, {st_mode=S_IFREG|0644, st_size=234, ...}) = 0
> mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1,
> 0)
> = 0x2aaab4000000
> read(17, "# Do not remove the following li"..., 4096) = 234
> read(17, "", 4096) = 0
> close(17) = 0
> munmap(0x2aaab4000000, 4096) = 0
> socket(PF_INET, SOCK_DGRAM, IPPROTO_IP) = 17
> connect(17, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, 28) = 0
> fcntl(17, F_GETFL) = 0x2 (flags O_RDWR)
> fcntl(17, F_SETFL, O_RDWR|O_NONBLOCK) = 0
> poll([{fd=17, events=POLLOUT, revents=POLLOUT}], 1, 0) = 1
> sendto(17,
"M\243\1\0\0\1\0\0\0\0\0\0\00282\003185\00213\003129\7i"...,
> 44, MSG_NOSIGNAL, NULL, 0) = 44
> poll([{fd=17, events=POLLIN, revents=POLLIN}], 1, 5000) = 1
> ioctl(17, FIONREAD, [344]) = 0
> recvfrom(17, "M\243\205\200\0\1\0\1\0\6\0\7\00282\003185\00213
> \00312"..., 1024, 0, {sa_family=AF_INET, sin_port=htons(53),
> sin_addr=inet_addr("129.13.96.2")}, [16]) = 344
> close(17) = 0
> socket(PF_NETLINK, SOCK_RAW, 0) = 17
> bind(17, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 0
> getsockname(17, {sa_family=AF_NETLINK, pid=22923, groups=00000000},
> [4294967308]) = 0
> sendto(17, "\24\0\0\0\26\0\1\3\213~\341F\0\0\0\0\0\0\0\0", 20, 0,
> {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 20
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"<\0\0\0\24\0\2\0\213~\341F\213Y\0\0\2\10
> \200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000}, msg_iov(1)=[{"@\0\0\0\24\0\2\0\213~\341F\213Y\0\0\n
> \200\200\376\1\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, 0) =
> 128
> recvmsg(17, {msg_name(12)={sa_family=AF_NETLINK, pid=0,
> groups=00000000},
> msg_iov(1)=[{"\24\0\0\0\3\0\2\0\213~\341F\213Y\0\0\0\0
> \0\0\1\0\0\0\24"..., 4096}], msg_controllen=0, msg_flags=0}, 0) = 20
> close(17) = 0
> rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
> futex(0x192fd054, 0x5 /* FUTEX_??? */, 1) = 1
> select(6, [0 4 5], [], NULL, NULL) = ? ERESTARTNOHAND (To be
> restarted)
> trace: ptrace(PTRACE_SYSCALL, ...): No such process
> Process 22923 detached
>
> --
> CU,
> Patrick.
> _______________________________________________
> rsyslog mailing list
> http://lists.adiscon.net/mailman/listinfo/rsyslog
rsyslog 1.19.5 released [ In reply to ]
Am Freitag, den 07.09.2007, 19:20 +0200 schrieb Patrick von der Hagen:
[...]
> Crash of 1.19.5 after less than 30 minutes. Stack-trace seems to be
> quite "normal", however, I've been lucky and captured some
> strace-information. Not sure wheter that could be helpful.
I compiled 1.19.5 with "--enable-debug" now and got the following
problems:

Sep 10 14:24:26 mail11 rsyslogd:could not load module
'/usr/local/lib/rsyslog/ommysql.so',
dlopen: /usr/local/lib/rsyslog/ommysql.so: cannot open shared object
file: No such file or directory
Sep 10 14:24:26 mail11 rsyslogd:the last error occured
in /etc/rsyslog.conf, line 29

No idea why it tries "/usr/local/lib", the lib has been installed to
"/lib" or "/opt/rsyslog/lib/rsyslog/". Hmmm, "/lib" is from
1.18.something, I didn't tidy up properly.

Anyway, I currently don't use logging to MySQL, so I uncommented
"$ModLoad MySQL".


Next try:
[root at mail11 log]# /opt/rsyslog/sbin/rsyslogd -r514 -d
[...]
1084229952: Lone worker is running...
1084229952: Called fprintlog, logging to builtin-file
(/home/local/log/all)
1084229952: programname filter 'rsyslogd' does not match 'spamd'
Filter: check for property 'msg' (value ' prefork: child states:
BBBBBBBIIBBBBBBB ') contains 'prefork: child states': TRUE
1084229952: Called fprintlog, logging to builtin-discardrsyslogd:
omdiscard.c:70: doAction: Assertion `ppString != ((void *)0)' failed.
Aborted


That's getting a little bit strange now, it has been caused by this
rsyslog.conf-lines:
!spamd
:msg, contains, "prefork: child states" ~


Some other crashes relate to other lines, all of them end with "~". So I
uncommented all of them.

Those problems are strange, but if those issues were related to my
"normal" rsyslog-crashes, rsyslog would not have been able to run up to
two hours and would certainly have crashed almost instantly.

It's been running for several minutes now...

--
CU,
Patrick.
rsyslog 1.19.5 released [ In reply to ]
I agree, it looks strange (very strange indeed). I am checking if it
could be related to the root cause (or just be a debug-level artifact
that slipped through - that may be the case, because discard is the only
action which does NOT have any strings at all). Anyhow, it provides me
at least another clue where to look at.

Thanks
Rainer

> -----Original Message-----
> From: rsyslog-bounces at lists.adiscon.com [mailto:rsyslog-
> bounces at lists.adiscon.com] On Behalf Of Patrick von der Hagen
> Sent: Monday, September 10, 2007 2:39 PM
> To: rsyslog-users
> Subject: Re: [rsyslog] rsyslog 1.19.5 released
>
> Am Freitag, den 07.09.2007, 19:20 +0200 schrieb Patrick von der Hagen:
> [...]
> > Crash of 1.19.5 after less than 30 minutes. Stack-trace seems to be
> > quite "normal", however, I've been lucky and captured some
> > strace-information. Not sure wheter that could be helpful.
> I compiled 1.19.5 with "--enable-debug" now and got the following
> problems:
>
> Sep 10 14:24:26 mail11 rsyslogd:could not load module
> '/usr/local/lib/rsyslog/ommysql.so',
> dlopen: /usr/local/lib/rsyslog/ommysql.so: cannot open shared object
> file: No such file or directory
> Sep 10 14:24:26 mail11 rsyslogd:the last error occured
> in /etc/rsyslog.conf, line 29
>
> No idea why it tries "/usr/local/lib", the lib has been installed to
> "/lib" or "/opt/rsyslog/lib/rsyslog/". Hmmm, "/lib" is from
> 1.18.something, I didn't tidy up properly.
>
> Anyway, I currently don't use logging to MySQL, so I uncommented
> "$ModLoad MySQL".
>
>
> Next try:
> [root at mail11 log]# /opt/rsyslog/sbin/rsyslogd -r514 -d
> [...]
> 1084229952: Lone worker is running...
> 1084229952: Called fprintlog, logging to builtin-file
> (/home/local/log/all)
> 1084229952: programname filter 'rsyslogd' does not match 'spamd'
> Filter: check for property 'msg' (value ' prefork: child states:
> BBBBBBBIIBBBBBBB ') contains 'prefork: child states': TRUE
> 1084229952: Called fprintlog, logging to builtin-discardrsyslogd:
> omdiscard.c:70: doAction: Assertion `ppString != ((void *)0)' failed.
> Aborted
>
>
> That's getting a little bit strange now, it has been caused by this
> rsyslog.conf-lines:
> !spamd
> :msg, contains, "prefork: child states" ~
>
>
> Some other crashes relate to other lines, all of them end with "~". So
> I
> uncommented all of them.
>
> Those problems are strange, but if those issues were related to my
> "normal" rsyslog-crashes, rsyslog would not have been able to run up
to
> two hours and would certainly have crashed almost instantly.
>
> It's been running for several minutes now...
>
> --
> CU,
> Patrick.
>
> _______________________________________________
> rsyslog mailing list
> http://lists.adiscon.net/mailman/listinfo/rsyslog
rsyslog 1.19.5 released [ In reply to ]
Am Montag, den 10.09.2007, 14:38 +0200 schrieb Patrick von der Hagen:
[...]
> It's been running for several minutes now...
Now I captured the "real" crash.

First, my config:
$AllowedSender UDP, 1.2.3.0/24
$AllowedSender TCP, 1.2.3.0/24
$template clamavFile,"/home/local/log/%$YEAR%/%$MONTH%/%$DAY%/%HOSTNAME
%/clamav"
$template eximFile,"/home/local/log/%$YEAR%/%$MONTH%/%$DAY%/%HOSTNAME
%/exim"
$template avFile,"/home/local/log/%$YEAR%/%$MONTH%/%$DAY%/%HOSTNAME%/av"
*.* /home/local/log/all
!rsyslogd
:programname, contains, "rsyslogd" /home/local/log/rsyslogd
!spamd
mail.* /home/local/log/mail
!clamd
local5.* ?clamavFile
!exim
*.* ?eximFile
:msg, contains, "malware detected" ?avFile


Here the output of "rsyslog -r514 -d"
Successful select, descriptor count = 1, Activity on: 1084229952:
-1431504256: 8
Called fprintlog, logging to builtin-file1084229952: (eximFile)
Filter: check for property 'msg' (value ' 2007-09-10 14:56:03
1IUio2-00054R-EA H=X (Y) [1.2.3.4] Warning: X-Spam-Status: yes,
hits=13.9, size=32842') contains 'malware detected': FALSE
1084229952: singleWorker: queue EMPTY, waiting for next message.
-1431504256: Message from inetd socket: #8, host: mailin3
-1431504256: Message length: 200, File descriptor: 8.
-1431504256: logmsg: mail.info<22>, flags 2, from 'mailin3', msg
exim[18550]: 2007-09-10 14:56:03 H=(a.b.c.d) [2.3.4.5] F=<x at y.z.1.b>
temporarily rejected RCPT <localpart at domain>: greylisted.
-1431504256: Message has legacy syslog format.
-1431504256: HOSTNAME contains invalid characters, assuming it to be a
TAG.
-1431504256: EnqueueMsg signaled condition (0)
-1431504256: 1084229952: Listening on UDP syslogd socket 7 (IPv6/port
514).
-1431504256: Lone worker is running...
1084229952: Called fprintlog, logging to builtin-file
(/home/local/log/all)
Listening on UDP syslogd socket 8 (IPv4/port 514).
-1431504256: ----------------------------------------
-1431504256: Calling select, active file descriptors (max 8): 3 7 8
1084229952: programname filter 'rsyslogd' does not match 'exim'
1084229952: programname filter 'spamd' does not match 'exim'
1084229952: programname filter 'clamd' does not match 'exim'
1084229952: Called fprintlog, logging to builtin-file (eximFile)
Filter: check for property 'msg' (value ' 2007-09-10 14:56:03 H=(domain)
[1.2.3.4] F=<sender at domainA> temporarily rejected RCPT
<recipient at domainB>: greylisted.') contains 'malware detected': FALSE
1084229952: singleWorker: queue EMPTY, waiting for next message.
-1431504256:
Successful select, descriptor count = 1, Activity on: 8
*** glibc detected *** /opt/rsyslog/sbin/rsyslogd: corrupted
double-linked list: 0x00002aaaac001230 ***
======= Backtrace: =========
/lib64/libc.so.6[0x362766cb43]
/lib64/libc.so.6[0x362766eea2]
/lib64/libc.so.6(__libc_malloc+0x7d)[0x36276706dd]
/lib64/libc.so.6[0x362765eb4a]
/lib64/libnss_files.so.2[0x2aaaaaad445a]
/lib64/libnss_files.so.2(_nss_files_gethostbyaddr_r
+0x57)[0x2aaaaaad4b47]
/lib64/libc.so.6(gethostbyaddr_r+0xf2)[0x36276e2b42]
/lib64/libc.so.6(getnameinfo+0x3ad)[0x36276eb07d]
/opt/rsyslog/sbin/rsyslogd(cvthname+0x154)[0x410e64]
/opt/rsyslog/sbin/rsyslogd[0x40bec9]
/opt/rsyslog/sbin/rsyslogd(main+0x630)[0x40c990]
/lib64/libc.so.6(__libc_start_main+0xf4)[0x362761d8a4]
/opt/rsyslog/sbin/rsyslogd[0x405899]
======= Memory map: ========
00400000-00424000 r-xp 00000000 08:03
688189 /opt/rsyslog/sbin/rsyslogd
00624000-00626000 rw-p 00024000 08:03
688189 /opt/rsyslog/sbin/rsyslogd
1c204000-1c249000 rw-p 1c204000 00:00 0
40000000-40001000 ---p 40000000 00:00 0
40001000-40a01000 rw-p 40001000 00:00 0
3627200000-362721a000 r-xp 00000000 08:03
4260124 /lib64/ld-2.5.so
3627419000-362741a000 r--p 00019000 08:03
4260124 /lib64/ld-2.5.so
362741a000-362741b000 rw-p 0001a000 08:03
4260124 /lib64/ld-2.5.so
3627600000-3627744000 r-xp 00000000 08:03
4260125 /lib64/libc-2.5.so
3627744000-3627944000 ---p 00144000 08:03
4260125 /lib64/libc-2.5.so
3627944000-3627948000 r--p 00144000 08:03
4260125 /lib64/libc-2.5.so
3627948000-3627949000 rw-p 00148000 08:03
4260125 /lib64/libc-2.5.so
3627949000-362794e000 rw-p 3627949000 00:00 0
3627e00000-3627e02000 r-xp 00000000 08:03
4260128 /lib64/libdl-2.5.so
3627e02000-3628002000 ---p 00002000 08:03
4260128 /lib64/libdl-2.5.so
3628002000-3628003000 r--p 00002000 08:03
4260128 /lib64/libdl-2.5.so
3628003000-3628004000 rw-p 00003000 08:03
4260128 /lib64/libdl-2.5.so
3628200000-3628215000 r-xp 00000000 08:03
4260022 /lib64/libpthread-2.5.so
3628215000-3628414000 ---p 00015000 08:03
4260022 /lib64/libpthread-2.5.so
3628414000-3628415000 r--p 00014000 08:03
4260022 /lib64/libpthread-2.5.so
3628415000-3628416000 rw-p 00015000 08:03
4260022 /lib64/libpthread-2.5.so
3628416000-362841a000 rw-p 3628416000 00:00 0
3628600000-3628614000 r-xp 00000000 08:03
4547586 /usr/lib64/libz.so.1.2.3
3628614000-3628813000 ---p 00014000 08:03
4547586 /usr/lib64/libz.so.1.2.3
3628813000-3628814000 rw-p 00013000 08:03
4547586 /usr/lib64/libz.so.1.2.3
362d200000-362d207000 r-xp 00000000 08:03
4260133 /lib64/librt-2.5.so
362d207000-362d407000 ---p 00007000 08:03
4260133 /lib64/librt-2.5.so
362d407000-362d408000 r--p 00007000 08:03
4260133 /lib64/librt-2.5.so
362d408000-362d409000 rw-p 00008000 08:03
4260133 /lib64/librt-2.5.so
362ee00000-362ee11000 r-xp 00000000 08:03
4260134 /lib64/libresolv-2.5.so
362ee11000-362f011000 ---p 00011000 08:03
4260134 /lib64/libresolv-2.5.so
362f011000-362f012000 r--p 00011000 08:03
4260134 /lib64/libresolv-2.5.so
362f012000-362f013000 rw-p 00012000 08:03
4260134 /lib64/libresolv-2.5.so
362f013000-362f015000 rw-p 362f013000 00:00 0
3815400000-381540d000 r-xp 00000000 08:03
4259862 /lib64/libgcc_s-4.1.1-20070105.so.1
381540d000-381560c000 ---p 0000d000 08:03
4259862 /lib64/libgcc_s-4.1.1-20070105.so.1
381560c000-381560d000 rw-p 0000c000 08:03
4259862 /libAborted



--
CU,
Patrick.
rsyslog 1.19.5 released [ In reply to ]
Am Sonntag, den 09.09.2007, 11:43 +0200 schrieb Jan-Frode Myklebust:
> On 2007-09-08, Tomas Heinrich <theinric at redhat.com> wrote:
> >
> > Thanks for the info. It will be very useful if someone can provide a
> > core dump for 1.19.5.
>
> I haven't had the chance to upgrade yet, but any hints for how to get
> a core dump if it fails ? I've tried this in the init-script:
>
> ulimit -c unlimited
> cd /var/log/syslog
> echo -n $"Starting system logger (rsyslog): "
> daemon rsyslogd $SYSLOGD_OPTIONS
>
> but haven't gotten any core-dumps in any of the crashes I've had..
Hmmm. I did "ulimit -c 50000; /opt/rsyslog/sbin/rsyslogd -r514"
yesterday evening and found a nice coredump this morning. I sent it to
Rainer a minute ago.

--
CU,
Patrick.