Skip to content

Attribute gated sessions in correlate via the backend port - #50

Merged
kilo666mj merged 1 commit into
mainfrom
correlate-backend-port
Sep 27, 2026
Merged

kilo666mj merged 1 commit into
mainfrom
correlate-backend-port

Conversation

@kilo666mj

Copy link
Copy Markdown
Owner

Why

Behind sshgate, sshd logs every session as from 127.0.0.1 port N, so correlate's client-IP match found nothing for gated sessions — on hosts where sshd listens only on loopback, that is every session. v0.6.0 added the CONNECTED ... local=127.0.0.1:N line that makes the join possible (#48).

What

  • --gate-log (default /var/log/syslog, where rsyslog copies sshgate's journal on Debian): read the fingerprint's CONNECTED lines.
  • Loopback sshd lines are joined to the CONNECTED line with the same host and port nearest in time within --join-window (default 10s), and reported with the client address from the gate and SOURCE gate:<port>. Ports are reused, so nearest-within-window, and host must match when both lines carry one.
  • Lines from a real client address keep the existing IP match near first/last seen (SOURCE direct).
  • A missing gate log warns on stderr and falls back to direct matching.
  • Fix: the user for for invalid user <name> lines was reported as user.
  • First tests for correlate (correlate_test.go); docs updated.

Testing

  • go test -race ./..., go vet, golangci-lint v2.14.0 clean.
  • Disabling the port join makes the join tests fail.
  • Ran the new binary on mx against a copy of the live database with the real auth.log and syslog: 599 CONNECTED lines for the macbook fingerprint; gated sshd-session logins were attributed to the real client address (before: no matches).

🤖 Generated with Claude Code

Behind sshgate, sshd logs every session as `from 127.0.0.1 port N`, so
correlate's client-IP match found nothing. correlate now reads sshgate's
CONNECTED lines for the fingerprint (--gate-log, default /var/log/syslog)
and joins each loopback sshd line to the one with the same host and port
nearest in time within --join-window (10s), reporting the client address
with SOURCE gate:<port>. Lines from a real client address keep the
existing IP match near first/last seen (SOURCE direct). A missing gate log
warns and falls back.

Also fixes the user shown for "for invalid user <name>" lines, which was
"user".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kilo666mj
kilo666mj merged commit a9ab14a into main Sep 27, 2026
7 checks passed
@kilo666mj
kilo666mj deleted the correlate-backend-port branch September 27, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant