es kam zwei mal vor, dass mein Debian stable Server ohne mein Zutun rebootet wurde. Es war kein Benutzer. Das Wichtigste ist wohl die Meldung exiting on signal 15. aus der messages. Doch was hat den Reboot verursacht? "last -d10" zB. sagt vom letzten Reboot:
Code: Alles auswählen
reboot system boot 0.0.0.0 Thu Feb 23 07:01 - 08:46 (01:44)
Auf der Kiste läuft eine weiteres Debian stable 64bit unter KVM. Die zwei 500GB Platten sind ein Softraid. Kernel ist ein Eigenbau mit grsecurity.
Habt ihr eine Idee?
Hier noch die 3 wichtigsten Logs aus der Zeitspanne kurz vor und nach dem Reboot.
Code: Alles auswählen
/var/log/kern.log
Feb 23 06:55:06 SERVER kernel: [778713.746224] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.136 DST=xxx.xxx.xxx.211 LEN=56 TOS=0x00 PREC=0x00 TTL=114 ID=
46662 DF PROTO=ICMP TYPE=3 CODE=3 [SRC=xxx.xxx.xxx.211 DST=xxx.xxx.xxx.136 LEN=64 TOS=0x00 PREC=0x00 TTL=228 ID=53948 DF PROTO=UDP SPT=24103 DPT=53 LEN=44 ]
Feb 23 06:56:14 SERVER kernel: [778781.856540] kvm [18308]: vcpu0, guest rIP: 0xffffffff812d637c unhandled rdmsr: 0xc001100d
Feb 23 06:58:26 SERVER kernel: [778913.677768] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.48 DST=xxx.xxx.xxx.211 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=41
548 DF PROTO=TCP SPT=57986 DPT=636 WINDOW=0 RES=0x00 RST URGP=0
Feb 23 06:58:26 SERVER kernel: [778913.715352] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.48 DST=xxx.xxx.xxx.211 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=41
549 DF PROTO=TCP SPT=57986 DPT=636 WINDOW=0 RES=0x00 RST URGP=0
Feb 23 06:59:05 SERVER kernel: [778952.808767] QNX4 filesystem 0.2.3 registered.
Feb 23 06:59:05 SERVER kernel: [778953.027079] fuse init (API version 7.25)
Feb 23 07:02:00 SERVER kernel: [ 0.000000] Linux version 4.8.8-grsec-dasc (root@SERVER.de) (gcc version 4.9.2 (Debian 4.9.2-10) ) #1 SMP Thu Nov 17 14:54:21 CET 2016
Feb 23 07:02:00 SERVER kernel: [ 0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.8.8-grsec-dasc root=UUID=ee00fd20-dd9f-4957-920f-b24cf214aa10 ro vconsole.keymap=de-latin1 co
nsole=tty0 console=ttyS0,57600
Feb 23 07:02:00 SERVER kernel: [ 0.000000] x86/fpu: Legacy x87 FPU detected.
Feb 23 07:02:00 SERVER kernel: [ 0.000000] x86/fpu: Using 'eager' FPU context switches.
Feb 23 07:02:00 SERVER kernel: [ 0.000000] e820: BIOS-provided physical RAM map:
Feb 23 07:02:00 SERVER kernel: [ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009efff] usable
Code: Alles auswählen
/var/log/syslog
Feb 23 06:57:01 SERVER postfix/qmgr[1501]: 98F67E80918: removed
Feb 23 06:58:26 SERVER kernel: [778913.677768] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.48 DST=xxx.xxx.xxx.211 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=41548 DF PROTO=TCP SPT=57986 DPT=636 WINDOW=0 RES=0x00 RST URGP=0
Feb 23 06:58:26 SERVER kernel: [778913.715352] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.48 DST=xxx.xxx.xxx.211 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=41549 DF PROTO=TCP SPT=57986 DPT=636 WINDOW=0 RES=0x00 RST URGP=0
Feb 23 06:59:05 SERVER kernel: [778952.808767] QNX4 filesystem 0.2.3 registered.
Feb 23 06:59:05 SERVER kernel: [778953.027079] fuse init (API version 7.25)
Feb 23 06:59:05 SERVER systemd[1]: Mounting FUSE Control File System...
Feb 23 06:59:05 SERVER systemd[1]: Mounted FUSE Control File System.
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda1: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda2: is active swap
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda3: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb1: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb2: is active swap
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb3: part of software raid array
Feb 23 06:59:08 SERVER systemd[1]: Started Synchronise Hardware Clock to System Clock.
Feb 23 06:59:08 SERVER systemd[1]: Stopping Session 4681 of user daniel.
Feb 23 06:59:08 SERVER systemd[1]: Stopping Session 3 of user daniel.
Feb 23 06:59:08 SERVER systemd[1]: Stopping system-systemd\x2dfsck.slice.
Feb 23 06:59:08 SERVER systemd[1]: Removed slice system-systemd\x2dfsck.slice.
Feb 23 06:59:08 SERVER systemd[1]: Stopping Virtual Machine and Container Registration Service...
Feb 23 06:59:08 SERVER systemd[1]: Stopping User Manager for UID 1002...
Feb 23 06:59:08 SERVER systemd[1]: Stopping Mail Transport Agent.
Feb 23 06:59:08 SERVER systemd[1]: Stopped target Mail Transport Agent.
Feb 23 06:59:08 SERVER systemd[1]: Stopping Graphical Interface.
Feb 23 06:59:08 SERVER systemd[1]: Stopped target Graphical Interface.
Feb 23 06:59:08 SERVER systemd[1]: Stopping Entropy daemon using the HAVEGE algorithm...
Feb 23 06:59:08 SERVER systemd[1]: Stopping Multi-User System.
Feb 23 06:59:08 SERVER systemd[1]: Stopped target Multi-User System.
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: Start/stop sysstat's sadc...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: Firewall fuer ip-v4...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: daemon to balance interrupts for SMP systems...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: Starts or stops the xinetd daemon....
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: Apache2 web server...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: Postfix Mail Transport Agent...
Feb 23 06:59:08 SERVER systemd[1]: Stopping LSB: coturn TURN Server...
Feb 23 06:59:09 SERVER systemd[1]: Stopping LSB: Start/stop fail2ban...
Feb 23 06:59:09 SERVER systemd[1]: Stopping LSB: Start NTP daemon...
Feb 23 06:59:09 SERVER systemd[1]: Stopping LSB: SNMP agents...
Feb 23 06:59:09 SERVER systemd[1]: Stopping Suspend Active Libvirt Guests...
Feb 23 06:59:09 SERVER systemd[1]: Stopping Regular background program processing daemon...
Feb 23 06:59:09 SERVER systemd[1]: Stopping vnStat network traffic monitor...
Feb 23 06:59:09 SERVER systemd[1]: Stopping Self Monitoring and Reporting Technology (SMART) Daemon...
Code: Alles auswählen
/var/log/messages
Feb 23 06:58:26 rigel kernel: [778913.715352] IN=eth0 OUT= MAC=00.00.00.00.00.00.00.00.00.00dc:03:08:00 SRC=xxx.xxx.xxx.48 DST=xxx.xxx.xxx.211 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=41549 DF PROTO=TCP SPT=57986 DPT=636 WINDOW=0 RES=0x00 RST URGP=0
Feb 23 06:59:05 SERVER kernel: [778952.808767] QNX4 filesystem 0.2.3 registered.
Feb 23 06:59:05 SERVER kernel: [778953.027079] fuse init (API version 7.25)
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda1: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda2: is active swap
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sda3: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb1: part of software raid array
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb2: is active swap
Feb 23 06:59:06 SERVER os-prober: debug: /dev/sdb3: part of software raid array
Feb 23 06:59:12 SERVER rsyslogd: [origin software="rsyslogd" swVersion="8.4.2" x-pid="721" x-info="http://www.rsyslog.com"] exiting on signal 15.
Feb 23 07:02:00 SERVER rsyslogd: [origin software="rsyslogd" swVersion="8.4.2" x-pid="723" x-info="http://www.rsyslog.com"] start
Feb 23 07:02:00 SERVER kernel: [ 0.000000] Linux version 4.8.8-grsec-dasc (root@SERVER.de) (gcc version 4.9.2 (Debian 4.9.2-10) ) #1 SMP Thu Nov 17 14:54:21 CET 2016
Feb 23 07:02:00 SERVER kernel: [ 0.000000] Command line: BOOT_IMAGE=/vmlinuz-4.8.8-grsec-dasc root=UUID=ee00fd20-dd9f-4957-920f-b24cf214aa10 ro vconsole.keymap=de-latin1 console=tty0 console=ttyS0,57600
Feb 23 07:02:00 SERVER kernel: [ 0.000000] x86/fpu: Legacy x87 FPU detected.
Feb 23 07:02:00 SERVER kernel: [ 0.000000] x86/fpu: Using 'eager' FPU context switches.
Feb 23 07:02:00 SERVER kernel: [ 0.000000] e820: BIOS-provided physical RAM map:
Feb 23 07:02:00 SERVER kernel: [ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009efff] usable
Feb 23 07:02:00 SERVER kernel: [ 0.000000] BIOS-e820: [mem 0x000000000009f000-0x000000000009ffff] reserved
Feb 23 07:02:00 SERVER kernel: [ 0.000000] BIOS-e820: [mem 0x00000000000e4000-0x00000000000fffff] reserved
Feb 23 07:02:00 SERVER kernel: [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000ddfaffff] usable