)]}'
{
  "commit": "0f6001102eea86effb540d6282e266d86ce123e6",
  "tree": "1e5573981861e7238bc0e70e56ded08c6b42c60d",
  "parents": [
    "bfcfbad7cabda03b61379b3a5665f5475213efc6"
  ],
  "author": {
    "name": "eyalron",
    "email": "eyalron@google.com",
    "time": "Tue Sep 15 01:18:57 2026 +0000"
  },
  "committer": {
    "name": "Mo Elbadry",
    "email": "elbadrym@google.com",
    "time": "Fri Sep 18 09:17:04 2026 -0700"
  },
  "message": "rsyslog: fix imjournal ratelimiter data race\n\nimjournal keeps one module-global ratelimiter but runs one reader thread\nper journal: every configured input() plus the implicit listener that\nactivateCnf() unconditionally adds via addListner(NULL, ...). All of\nthem call ratelimitAddMsg() on that single object, yet the module\nnever calls ratelimitSetThreadSafe(), so bThreadSafe stays 0 and\nevery lock in runtime/ratelimit.c is skipped.\n\nWith $RepeatedMsgReduction disabled this only races on scalar counters\nin withinRatelimit() and merely yields imprecise numbers. Enabling the\ndirective additionally activates doLastMessageRepeatedNTimes(), which\nmutates the shared ratelimit-\u003epMsg pointer: one thread can free that\nmessage in msgDestruct() while another is still dereferencing it in the\nduplicate comparison. Message refcounts are atomic, so the count itself\ndoes not tear, but nothing protects the pointer, and the result is a\nuse-after-free.\n\nThis is not fixed upstream: rsyslog master still never calls\nratelimitSetThreadSafe() from imjournal and still gates all locking on\nbThreadSafe, so an uprev does not help.\n\nratelimitSetNoTimeCache() already calls pthread_mutex_init() on the same\nmutex, so no extra initialisation is needed. The duplicate init inside\nratelimitSetThreadSafe() is harmless because runInput() runs before any\nreader thread is spawned.\n\nNeeded before $RepeatedMsgReduction can be enabled; see the\ngbmc-internal change enabling it in meta-google-gbmc/.../client.conf.\n\nTested: built for an armv7l gBMC target and deployed the patched\nimjournal.so to a test BMC. The plugin loads cleanly (no undefined\nsymbols, both in:imjournal threads present) and duplicate suppression\nstill works -- 6 identical messages are reported as \"message repeated\n11 times\", the expected 2N-1 for two readers sharing one ratelimiter.\n\nCrash reproduction, 6000-message rounds with $RepeatedMsgReduction on:\n\n  unpatched, 24000 messages: 3 SIGSEGV, coredumps, rsyslog.service\n      \"Main process exited, code\u003dkilled, status\u003d11/SEGV\"\n  unpatched, RMR off, 28000 messages: 0 crashes\n  patched, 48000 messages over two runs: 0 crashes, 0 restarts,\n      0 coredumps\n\nBMC restored to its original imjournal.so and config after each run\n(md5 match, service active).\n\nFusion-Link: fusion2 N/A\nGoogle-Bug-Id: 561749907\nChange-Id: Ibc687516f5fc3fa897ba362eefae034a67c3c97f\nSigned-off-by: Eyal Ron \u003ceyalron@google.com\u003e\nTAG\u003dagy\nCONV\u003d31661fa9-028b-493b-8dec-1c801e2b0023\n",
  "tree_diff": [
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "3efbae8e7324289c1befead09a5f555bc7f8f9d2",
      "new_mode": 33188,
      "new_path": "recipes-extended/rsyslog/rsyslog/0004-imjournal-make-the-shared-ratelimiter-thread-safe.patch"
    },
    {
      "type": "modify",
      "old_id": "da5568ac5921c000b4059dad2a895f9857c8f4c5",
      "old_mode": 33188,
      "old_path": "recipes-extended/rsyslog/rsyslog_%.bbappend",
      "new_id": "142635aaf01ddef1d825f48e8103bc301dcb29b8",
      "new_mode": 33188,
      "new_path": "recipes-extended/rsyslog/rsyslog_%.bbappend"
    }
  ]
}
