Repository navigation
fix: follow sshd-session logins in the journald ssh watcher - #27
Merged
Merged
Conversation
OpenSSH 9.8 (Debian 13) logs the Accepted line from the sshd-session helper, so a journalctl filter on _COMM=sshd alone dropped every login on those hosts. Match both _COMM values with journalctl's OR (+), keep the tail/auth.log fallback unchanged, and split source selection into sshLogSource with injected lookPath/stat so the command is testable. Add parser cases for sshd-session lines in BSD and ISO syslog framing.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On Debian 13 (OpenSSH 9.8) the session process is
sshd-session, and it is the one that logsAccepted publickey. The login watcher followedjournalctl _COMM=sshdonly, so login alerts were silently missed on every Debian 13 node while Debian 12 nodes worked. The journal follow now matches both (_COMM=sshd + _COMM=sshd-session); the auth.log tail fallback is unchanged, and the parser already accepted thesshd-sessionprogram tag.Found on the fleet today: three Debian 13 nodes produced no
ssh_loginevent for a real login, and a loopback login confirmed the line sits undersshd-sessionthere.Test plan
TestParsegains Debian 13 cases (BSD and ISO framing, IPv6 peer) and a same-textsudotag that must be rejectedTestSSHLogSourceJournalMatchesSSHDAndSessionandTestSSHLogSourceFallsBackToAuthLoggo build,go vet,gofmt -l,go test ./... -count=1all greenFollow-up outside this change: OpenSSH 10 moves pre-auth failures to
sshd-auth; accepted logins still come fromsshd-session, so alerts stay correct, but the failure counter would need+ _COMM=sshd-authon a future OpenSSH 10 host.