About this project

SolidSyslog is a structured syslog client library aimed at embedded and industrial devices. It implements RFC 5424 structured syslog, with UDP (RFC 5426) and TCP (RFC 6587) transports; TLS per RFC 5425 is supplied by the platform, so any TLS library can plug in behind the same Stream vtable. TLS is not a core dependency, and Core carries no reference to a TLS library. The stated purpose is to give shipping embedded products the security audit trail expected under the EU Cyber Resilience Act and IEC 62443, as a component you add rather than a redesign. Resource footprint, as published by the project: about +5 KB flash and 1.9 KB RAM for a valid timestamped RFC 5424 record on the wire; about +16.4 KB flash and 36.3 KB RAM for the full path including store-and-forward, device identity, mutual TLS and AES-GCM encryption at rest, mainly TLS buffers. These figures are described as what the library adds to a device already running FreeRTOS, lwIP, FatFs and Mbed TLS, measured on a Cortex-M3 under QEMU. Two worked integrations are published as separate repositories, one consumed with CMake and one with Make, with each stage as a single commit. Design characteristics: - C99, no dynamic memory allocation; instances live in a library-internal static pool sized at compile time - Transport-agnostic: UDP, TCP, TLS, or a custom transport - Buffer-agnostic: PassthroughBuffer (direct send), a portable CircularBuffer (mutex-injected ring), POSIX message queue, or custom - MISRA C:2012 informed Capabilities include RFC 5424 structured formatting over UDP, TCP and TLS/mutual TLS; asynchronous buffering; rotating block store-and-forward; and at-rest record protection using CRC-16 for accidental corruption, or keyed HMAC-SHA256 / AES-256-GCM where a local attacker is in scope. The project maps IEC 62443 audit-logging controls in a dedicated guide. Every platform dependency - TCP/IP stack, TLS library, filesystem, OS primitives, clock - is injected through a vtable, so porting means filling roles rather than editing Core. Platform packs ship for hosted and embedded targets; hosted targets are supported as development, test and edge/gateway hosts. TLS revocation (CRL/OCSP) is not performed by the library; enforcement depends on the configured TLS backend and platform. Architecture: OO-in-C. Platform dependencies and optional features are vtable roles injected at setup and composed at link time, so unwired features are dropped by the linker rather than excluded by the preprocessor; Core's implementation contains no feature conditionals. Public headers are split by audience: application code includes SolidSyslog.h, while setup code includes SolidSyslogConfig.h plus one header per wired component. A Null object stands in for any unfilled role. Testing uses BDD-driven binaries, one per target configuration, on host and under QEMU, each exercising the library end to end against a real syslog server. Documentation is hosted at docs.cososo.co.uk/solid-syslog, organised into Core, Integrate, Platforms, Compliance, API reference and Maintaining sections, including a hardening path, build integration guide, porting guide, RFC compliance matrix, threat model and CRA/IEC 62443 guides. Vulnerability reporting is via SECURITY.md. Licensing is source-available under three alternatives: PolyForm Internal Use 1.0.0 (free for evaluation and development inside any organisation), PolyForm Noncommercial 1.0.0 (free for hobby, charitable, educational, public research and government use, including redistribution), and a commercial licence required when supplying, selling or distributing a commercial product, device, firmware or service containing the library.