[rsyslog]: Rebind docker0 listener for bridged containers - #29863
Merged
yejianquan merged 1 commit intoOct 1, 2026
Merged
yejianquan merged 1 commit into
yejianquan merged 1 commit into
Conversation
Restart rsyslog when an unchanged configuration binds docker0, including single-ASIC platforms with bridge-networked syslog features. Copilot-Session: 34eb71c5-7544-40bc-b232-bdcaf4887237 Signed-off-by: Augustine Lee <augustinelee@microsoft.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Collaborator
|
/azp run Azure.sonic-buildimage |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused condition correctly addresses listener rebinding while preserving existing behavior elsewhere.
Review effort: Balanced
Findings: None
What changed in this PR
Ensures rsyslog rebinds docker0 listeners for bridge-networked containers on single-ASIC systems.
Changes:
- Restarts rsyslog when
docker0_ipis populated. - Preserves SIGHUP for loopback-only single-ASIC configurations.
| File | Description |
|---|---|
files/image_config/rsyslog/rsyslog-config.sh |
Extends unchanged-config restart logic to docker0 listeners. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
2 of 20 tasks
Collaborator
|
Cherry-pick PR to 202605: #29913 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why I did it
Bridge-networked containers can lose host syslog delivery after boot even though the generated rsyslog configuration contains the docker0 listener.
The unchanged-config path already restarts rsyslog on multi-ASIC platforms, but single-ASIC platforms with bridged syslog features only receive SIGHUP. If rsyslog started before docker0 was ready, HUP reopens log files without creating the missing listener. The missing transport also hides otherwise correctly generated critical-process alerts.
This extends the existing recovery in #27548 to single-ASIC bridged containers.
Work item tracking
How I did it
Restart rsyslog when an unchanged configuration either belongs to a multi-ASIC platform or includes a populated
docker0_ip.The changed-config/first-boot path and existing multi-ASIC restart behavior are unchanged. Single-ASIC configurations without a docker0 listener retain the HUP optimization. No supervisor event-matching logic or syslog error filters are changed.
How to verify it
Which release branch to backport (provide reason below if selected)
The 202605 branch has the same unchanged-config recovery gap. It can prevent DHCP-container logs and critical-process alerts from reaching the host after boot.
Tracking issue/work item for backport/cherry-pick request: ADO 39424743
Failure type: boot/service lifecycle regression.
Tested branch
Test result
202605 physical hardware: Nokia 7215 T1/mx, a 202605-based validation image containing this change, retry 0.
Testplan ID:
6abc862c7e3e869aeda52722test_monitoring_critical_processes: 1 passed, no failure/error/skip.dhcpservdandkea-dhcp4missing-process alerts and confirm that the full expected alert set was found.Exact source/image provenance is retained in the validation record referenced by the Testplan ID above. This is focused validation, not complete release qualification or proof that every separate RELP lifecycle signature is resolved.
Public-master script validation: Bash syntax and a mocked exact-script matrix passed for unchanged single-ASIC loopback-only, single-ASIC bridged, multi-ASIC, and multi-ASIC bridged configurations. The baseline fails the single-ASIC bridged regression; the patch passes all four cases.
No complete master-image hardware run is claimed; the master checkbox is intentionally left unchecked pending normal PR CI/base-branch validation.
Description for the changelog
Rebind the host docker0 syslog listener for single-ASIC bridge-networked containers when the generated configuration is unchanged.
Link to config_db schema for YANG module changes
N/A. No schema change.