Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

rsyslog_config: "Mirror syslog to flash" rule is appended again on every Apply — each line written to the boot device N times

Open Beginner friendly
#2,782 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 6 days

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
92/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
bash
Domain
devops

Research direction

Start with emhttp/plugins/dynamix/scripts/rsyslog_config, especially the flash-mirror guard around line 57. Reproduce the issue using a scratch config and repeated applies, then verify that the mirror rule remains single after multiple applies and is removed when mirroring is disabled.

Written by the indexing model from the issue text.

Description

Summary

emhttp/plugins/dynamix/scripts/rsyslog_config guards the flash-mirror rule with

grep -q '^\*\.debug \?flash$' $ETC || \
  sed -ri '/^\*\.debug .*syslog$/a*.debug ?flash' $ETC

In a basic regular expression (plain grep), \? is the GNU "optional" operator, not a literal ?. The pattern therefore matches *.debug flash / *.debug flash, never the line the sed actually writes (*.debug ?flash). The guard never succeeds, so every Apply on Settings → Syslog Server with "Mirror syslog to boot drive" = Yes appends another *.debug ?flash line, and rsyslog writes each message to /boot/logs/syslog once per line.

The result is persisted: the script copies /etc/rsyslog.conf to /boot/config/rsyslog.conf, which is loaded at boot.

Impact

A feature that the help text already says to use sparingly, because of USB wear, multiplies its own writes to the boot device. On my server the boot copy held 3 identical rules after the mirror had been enabled and the page saved a few times, so for months every syslog line was written to the flash drive 3 times. /boot/logs/syslog-previous showed every line tripled. One more Apply made it 4.

Steps to reproduce
  1. Settings → Syslog Server: set Mirror syslog to boot drive = Yes, click Apply.
  2. Click Apply again (no changes needed). Repeat once more.
  3. grep -c '^\*\.debug ?flash' /etc/rsyslog.conf /boot/config/rsyslog.conf → 3 each.
  4. logger test-$$; grep -c test-$$ /boot/logs/syslog → 3.
Proposed fix

Drop the backslash, so the ? is literal in BRE:

-  grep -q '^\*\.debug \?flash$' $ETC || \
+  grep -q '^\*\.debug ?flash$' $ETC || \

The disable branch is not affected. It uses sed -r (ERE), where \? is a literal ?, so switching the mirror off already removes every copy.

Tested against the block from current master (e331ba36c) on a scratch config, 3 applies each:

*.debug ?flash rules after 3 applies after mirror off
current 3 0
with the fix 1 0

(The $template flash guard on the line above uses a different pattern and correctly stays at 1.)

Existing installs keep their duplicates until the mirror is toggled off and on again. Optionally the script could also deduplicate the rule. Either way, users who were affected can check with the grep -c above.

Environment
  • Unraid 7.3.2 (identical line in current master, emhttp/plugins/dynamix/scripts/rsyslog_config line 57)
  • Found while moving syslog from the flash mirror to the local syslog server.
Dominant language
PHP
Stars
255
Forks
109
Avg merge
6d 3h
Merged PRs (30d)
13

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from unraid/webgui

All issues in unraid/webgui

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.