xref: /openbsd/regress/usr.sbin/syslogd/Client.pm (revision d415bd75)
1#	$OpenBSD: Client.pm,v 1.16 2021/12/22 15:14:13 bluhm Exp $
2
3# Copyright (c) 2010-2021 Alexander Bluhm <bluhm@openbsd.org>
4#
5# Permission to use, copy, modify, and distribute this software for any
6# purpose with or without fee is hereby granted, provided that the above
7# copyright notice and this permission notice appear in all copies.
8#
9# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16
17use strict;
18use warnings;
19
20package Client;
21use parent 'Proc';
22use Carp;
23use Socket;
24use Socket6;
25use IO::Socket;
26use IO::Socket::SSL;
27use Sys::Syslog qw(:standard :extended :macros);
28
29sub new {
30	my $class = shift;
31	my %args = @_;
32	$args{ktracepid} = "ktrace" if $args{ktrace};
33	$args{ktracepid} = $ENV{KTRACE} if $ENV{KTRACE};
34	$args{ktracefile} ||= "client.ktrace";
35	$args{logfile} ||= "client.log";
36	$args{up} ||= "Openlog";
37	my $self = Proc::new($class, %args);
38	if (defined($self->{connectdomain})) {
39		$self->{connectproto} ||= "udp";
40	}
41	return $self;
42}
43
44sub child {
45	my $self = shift;
46
47	if ($self->{early}) {
48		my @sudo = $ENV{SUDO} ? $ENV{SUDO} : "env";
49		my @flush = (@sudo, "./logflush");
50		system(@flush);
51	}
52
53	# TLS 1.3 writes multiple messages without acknowledgement.
54	# If the other side closes early, we want broken pipe error.
55	$SIG{PIPE} = 'IGNORE' if defined($self->{connectdomain}) &&
56	    $self->{connectproto} eq "tls";
57
58	if (defined($self->{connectdomain}) &&
59	    $self->{connectdomain} ne "sendsyslog") {
60		my $cs;
61		if ($self->{connectdomain} == AF_UNIX) {
62			$cs = IO::Socket::UNIX->new(
63			    Type => SOCK_DGRAM,
64			    Peer => $self->{connectpath} || "/dev/log",
65			) or die ref($self), " socket unix failed: $!";
66			$cs->setsockopt(SOL_SOCKET, SO_SNDBUF, 10000)
67			    or die ref($self), " setsockopt failed: $!";
68		} else {
69			$SSL_ERROR = "";
70			my $iosocket = $self->{connectproto} eq "tls" ?
71			    "IO::Socket::SSL" : "IO::Socket::IP";
72			my $proto = $self->{connectproto};
73			$proto = "tcp" if $proto eq "tls";
74			$cs = $iosocket->new(
75			    Proto               => $proto,
76			    Domain              => $self->{connectdomain},
77			    PeerAddr            => $self->{connectaddr},
78			    PeerPort            => $self->{connectport},
79			    $self->{sslcert} ?
80				(SSL_cert_file => $self->{sslcert}) : (),
81			    $self->{sslkey} ?
82				(SSL_key_file => $self->{sslkey}) : (),
83			    $self->{sslca} ?
84				(SSL_ca_file => $self->{sslca}) : (),
85			    SSL_verify_mode     => ($self->{sslca} ?
86				SSL_VERIFY_PEER : SSL_VERIFY_NONE),
87			    $self->{sslversion} ?
88				(SSL_version => $self->{sslversion}) : (),
89			    $self->{sslciphers} ?
90				(SSL_cipher_list => $self->{sslciphers}) : (),
91			) or die ref($self), " $iosocket socket connect ".
92			    "failed: $!,$SSL_ERROR";
93			if ($self->{sndbuf}) {
94				setsockopt($cs, SOL_SOCKET, SO_SNDBUF,
95				    pack('i', $self->{sndbuf})) or die
96				    ref($self), " set SO_SNDBUF failed: $!";
97			}
98			if ($self->{rcvbuf}) {
99				setsockopt($cs, SOL_SOCKET, SO_RCVBUF,
100				    pack('i', $self->{rcvbuf})) or die
101				    ref($self), " set SO_RCVBUF failed: $!";
102			}
103			print STDERR "connect sock: ",$cs->sockhost()," ",
104			    $cs->sockport(),"\n";
105			print STDERR "connect peer: ",$cs->peerhost()," ",
106			    $cs->peerport(),"\n";
107			if ($self->{connectproto} eq "tls") {
108				print STDERR "ssl version: ",
109				    $cs->get_sslversion(),"\n";
110				print STDERR "ssl cipher: ",
111				    $cs->get_cipher(),"\n";
112				print STDERR "ssl issuer: ",
113				    $cs->peer_certificate('issuer'),"\n";
114				print STDERR "ssl subject: ",
115				    $cs->peer_certificate('subject'),"\n";
116				print STDERR "ssl cn: ",
117				    $cs->peer_certificate('cn'),"\n";
118			}
119		}
120
121		IO::Handle::flush(\*STDOUT);
122		*STDIN = *STDOUT = $self->{cs} = $cs;
123		select(STDOUT);
124	}
125
126	if ($self->{logsock}) {
127		setlogsock($self->{logsock})
128		    or die ref($self), " setlogsock failed: $!";
129	}
130	# we take LOG_UUCP as it is not used nowadays
131	openlog("syslogd-regress", "perror,pid", LOG_UUCP);
132}
133
1341;
135