Skip to content

fix: follow sshd-session logins in the journald ssh watcher - #27

Merged
lr00rl merged 1 commit into
integrationfrom
feat/ssh-login-sshd-session
Sep 5, 2026
Merged

lr00rl merged 1 commit into
integrationfrom
feat/ssh-login-sshd-session

Conversation

@lr00rl

@lr00rl lr00rl commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Summary

On Debian 13 (OpenSSH 9.8) the session process is sshd-session, and it is the one that logs Accepted publickey. The login watcher followed journalctl _COMM=sshd only, so login alerts were silently missed on every Debian 13 node while Debian 12 nodes worked. The journal follow now matches both (_COMM=sshd + _COMM=sshd-session); the auth.log tail fallback is unchanged, and the parser already accepted the sshd-session program tag.

Found on the fleet today: three Debian 13 nodes produced no ssh_login event for a real login, and a loopback login confirmed the line sits under sshd-session there.

Test plan

  • TestParse gains Debian 13 cases (BSD and ISO framing, IPv6 peer) and a same-text sudo tag that must be rejected
  • TestSSHLogSourceJournalMatchesSSHDAndSession and TestSSHLogSourceFallsBackToAuthLog
  • go build, go vet, gofmt -l, go test ./... -count=1 all green

Follow-up outside this change: OpenSSH 10 moves pre-auth failures to sshd-auth; accepted logins still come from sshd-session, so alerts stay correct, but the failure counter would need + _COMM=sshd-auth on a future OpenSSH 10 host.

OpenSSH 9.8 (Debian 13) logs the Accepted line from the sshd-session
helper, so a journalctl filter on _COMM=sshd alone dropped every login
on those hosts. Match both _COMM values with journalctl's OR (+), keep
the tail/auth.log fallback unchanged, and split source selection into
sshLogSource with injected lookPath/stat so the command is testable.
Add parser cases for sshd-session lines in BSD and ISO syslog framing.
@lr00rl
lr00rl merged commit 5a81e75 into integration Sep 5, 2026
1 check passed
@lr00rl
lr00rl deleted the feat/ssh-login-sshd-session branch September 5, 2026 04:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant