Skip to content

entry_mutator: keep trusted fields when stripping underscores - #146

Merged
Watson1978 merged 4 commits into
masterfrom
fix-trusted-field-collision
Sep 17, 2026
Merged

Watson1978 merged 4 commits into
masterfrom
fix-trusted-field-collision

Conversation

@kenhys

@kenhys kenhys commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Journald reserves the leading underscore for trusted fields, which a client cannot forge, but a client is free to send a user field with the same name minus the underscore. With fields_strip_underscores true, both names turned into the same key.

Before:

the trusted _SYSTEMD_UNIT and a client supplied SYSTEMD_UNIT were joined into one SYSTEMD_UNIT value, so any local process could hide its own value inside trusted journal metadata.

After:

the trusted field keeps the stripped name and the user field of that name is dropped. A trusted field that field_map sends to another name does not reserve the stripped name, so nothing is lost there.

@kenhys
kenhys requested a review from Watson1978 September 16, 2026 01:51
Comment thread lib/fluent/plugin/systemd/entry_mutator.rb Outdated
kenhys and others added 4 commits September 17, 2026 11:10
Journald reserves the leading underscore for trusted fields, which a
client cannot forge, but a client is free to send a user field with
the same name minus the underscore. With `fields_strip_underscores
true`, both names turned into the same key.

Before:

the trusted `_SYSTEMD_UNIT` and a client supplied `SYSTEMD_UNIT`
were joined into one `SYSTEMD_UNIT` value, so any local process could
hide its own value inside trusted journal metadata.

After:

the trusted field keeps the stripped name and the user field of
that name is dropped. A trusted field that `field_map` sends to another
name does not reserve the stripped name, so nothing is lost there.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Co-authored-by: Shizuo Fujita <fujita@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
Signed-off-by: Kentaro Hayashi <hayashi@clear-code.com>
@Watson1978

Copy link
Copy Markdown
Contributor

Sorry, the suggestion could not carry the two lines outside the hunk, so applying it left them out.

The following changes will be solve NameError: uninitialized constant Fluent::Plugin::SystemdEntryMutator::TRUSTED_FIELDS in CI.

 require 'fluent/config/error'
+require 'systemd/journal/fields'

 module Fluent
   module Plugin
@@
-    class SystemdEntryMutator
+    class SystemdEntryMutator # rubocop:disable Metrics/ClassLength
+      TRUSTED_FIELDS = (Systemd::Journal::TRUSTED_FIELDS + Systemd::Journal::KERNEL_FIELDS).freeze
+
       Options = Struct.new(

@kenhys
kenhys force-pushed the fix-trusted-field-collision branch from 4fd0dca to f0ec906 Compare September 17, 2026 02:21
@Watson1978
Watson1978 merged commit da041fa into master Sep 17, 2026
9 checks passed
@Watson1978
Watson1978 deleted the fix-trusted-field-collision branch September 17, 2026 02:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants