Skip to content

[rsyslog]: Rebind docker0 listener for bridged containers - #29863

Merged
yejianquan merged 1 commit into
sonic-net:masterfrom
augusdn:augusdn/fix-rsyslog-docker0-rebind-20260930
Oct 1, 2026
Merged

yejianquan merged 1 commit into
sonic-net:masterfrom
augusdn:augusdn/fix-rsyslog-docker0-rebind-20260930

Conversation

@augusdn

@augusdn augusdn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Why I did it

Bridge-networked containers can lose host syslog delivery after boot even though the generated rsyslog configuration contains the docker0 listener.

The unchanged-config path already restarts rsyslog on multi-ASIC platforms, but single-ASIC platforms with bridged syslog features only receive SIGHUP. If rsyslog started before docker0 was ready, HUP reopens log files without creating the missing listener. The missing transport also hides otherwise correctly generated critical-process alerts.

This extends the existing recovery in #27548 to single-ASIC bridged containers.

Work item tracking
  • Microsoft ADO (number only): 39424743

How I did it

Restart rsyslog when an unchanged configuration either belongs to a multi-ASIC platform or includes a populated docker0_ip.

The changed-config/first-boot path and existing multi-ASIC restart behavior are unchanged. Single-ASIC configurations without a docker0 listener retain the HUP optimization. No supervisor event-matching logic or syslog error filters are changed.

How to verify it

  1. With a bridge-networked syslog feature configured, run the configuration script after docker0 is present. Verify the host RELP listener is bound on docker0 as well as loopback.
  2. Verify a logger message from the bridged container reaches host syslog.
  3. Run the critical-process monitoring test with normal recovery and unchanged alert assertions.
  4. Verify unchanged single-ASIC loopback-only configurations still use HUP, while multi-ASIC and changed configurations still restart.

Which release branch to backport (provide reason below if selected)

  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511
  • 202512
  • 202605
  • 202608

The 202605 branch has the same unchanged-config recovery gap. It can prevent DHCP-container logs and critical-process alerts from reaching the host after boot.

Tracking issue/work item for backport/cherry-pick request: ADO 39424743
Failure type: boot/service lifecycle regression.

Tested branch

  • master
  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511
  • 202512
  • 202605
  • 202608
  • N/A

Test result

202605 physical hardware: Nokia 7215 T1/mx, a 202605-based validation image containing this change, retry 0.

Testplan ID: 6abc862c7e3e869aeda52722

  • Pretest: 11 passed / 3 skipped.
  • test_monitoring_critical_processes: 1 passed, no failure/error/skip.
  • Posttest: 5 passed.
  • Overall: 17 passed / 3 skipped / 0 failures / 0 errors.
  • Original logs contain both dhcpservd and kea-dhcp4 missing-process alerts and confirm that the full expected alert set was found.
  • Database recovery, critical services and BGP postchecks completed; YANG validation and core/config differential checks passed.

Exact source/image provenance is retained in the validation record referenced by the Testplan ID above. This is focused validation, not complete release qualification or proof that every separate RELP lifecycle signature is resolved.

Public-master script validation: Bash syntax and a mocked exact-script matrix passed for unchanged single-ASIC loopback-only, single-ASIC bridged, multi-ASIC, and multi-ASIC bridged configurations. The baseline fails the single-ASIC bridged regression; the patch passes all four cases.

No complete master-image hardware run is claimed; the master checkbox is intentionally left unchecked pending normal PR CI/base-branch validation.

Description for the changelog

Rebind the host docker0 syslog listener for single-ASIC bridge-networked containers when the generated configuration is unchanged.

Link to config_db schema for YANG module changes

N/A. No schema change.

Restart rsyslog when an unchanged configuration binds docker0, including single-ASIC platforms with bridge-networked syslog features.

Copilot-Session: 34eb71c5-7544-40bc-b232-bdcaf4887237
Signed-off-by: Augustine Lee <augustinelee@microsoft.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@augusdn
augusdn marked this pull request as ready for review October 1, 2026 04:33
@augusdn
augusdn requested a review from lguohan as a code owner October 1, 2026 04:33
Copilot AI balanced review requested due to automatic review settings October 1, 2026 04:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused condition correctly addresses listener rebinding while preserving existing behavior elsewhere.

Review effort: Balanced
Findings: None

What changed in this PR

Ensures rsyslog rebinds docker0 listeners for bridge-networked containers on single-ASIC systems.

Changes:

  • Restarts rsyslog when docker0_ip is populated.
  • Preserves SIGHUP for loopback-only single-ASIC configurations.
File Description
files/​image_config/​rsyslog/​rsyslog-config.sh Extends unchanged-config restart logic to docker0 listeners.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@yejianquan yejianquan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@yejianquan
yejianquan merged commit 65f82ef into sonic-net:master Oct 1, 2026
32 checks passed
@mssonicbld

Copy link
Copy Markdown
Collaborator

Cherry-pick PR to 202605: #29913

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants