xref: /openbsd-src/regress/usr.sbin/syslogd/Client.pm (revision 1a8dbaac879b9f3335ad7fb25429ce63ac1d6bac)
1#	$OpenBSD: Client.pm,v 1.13 2020/10/16 22:46:45 bluhm Exp $
2
3# Copyright (c) 2010-2020 Alexander Bluhm <bluhm@openbsd.org>
4#
5# Permission to use, copy, modify, and distribute this software for any
6# purpose with or without fee is hereby granted, provided that the above
7# copyright notice and this permission notice appear in all copies.
8#
9# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16
17use strict;
18use warnings;
19
20package Client;
21use parent 'Proc';
22use Carp;
23use Socket;
24use Socket6;
25use IO::Socket;
26use IO::Socket::INET6;
27use IO::Socket::SSL;
28use Sys::Syslog qw(:standard :extended :macros);
29
30sub new {
31	my $class = shift;
32	my %args = @_;
33	$args{ktracepid} = "ktrace" if $args{ktrace};
34	$args{ktracepid} = $ENV{KTRACE} if $ENV{KTRACE};
35	$args{ktracefile} ||= "client.ktrace";
36	$args{logfile} ||= "client.log";
37	$args{up} ||= "Openlog";
38	my $self = Proc::new($class, %args);
39	if (defined($self->{connectdomain})) {
40		$self->{connectproto} ||= "udp";
41	}
42	return $self;
43}
44
45sub child {
46	my $self = shift;
47
48	# TLS 1.3 writes multiple messages without acknowledgement.
49	# If the other side closes early, we want broken pipe error.
50	$SIG{PIPE} = 'IGNORE' if $self->{connectproto} eq "tls";
51
52	if (defined($self->{connectdomain}) &&
53	    $self->{connectdomain} ne "sendsyslog") {
54		my $cs;
55		if ($self->{connectdomain} == AF_UNIX) {
56			$cs = IO::Socket::UNIX->new(
57			    Type => SOCK_DGRAM,
58			    Peer => $self->{connectpath} || "/dev/log",
59			) or die ref($self), " socket unix failed: $!";
60			$cs->setsockopt(SOL_SOCKET, SO_SNDBUF, 10000)
61			    or die ref($self), " setsockopt failed: $!";
62		} else {
63			$SSL_ERROR = "";
64			my $iosocket = $self->{connectproto} eq "tls" ?
65			    "IO::Socket::SSL" : "IO::Socket::INET6";
66			my $proto = $self->{connectproto};
67			$proto = "tcp" if $proto eq "tls";
68			$cs = $iosocket->new(
69			    Proto               => $proto,
70			    Domain              => $self->{connectdomain},
71			    PeerAddr            => $self->{connectaddr},
72			    PeerPort            => $self->{connectport},
73			    $self->{sslcert} ?
74				(SSL_cert_file => $self->{sslcert}) : (),
75			    $self->{sslkey} ?
76				(SSL_key_file => $self->{sslkey}) : (),
77			    $self->{sslca} ?
78				(SSL_ca_file => $self->{sslca}) : (),
79			    SSL_verify_mode     => ($self->{sslca} ?
80				SSL_VERIFY_PEER : SSL_VERIFY_NONE),
81			    $self->{sslversion} ?
82				(SSL_version => $self->{sslversion}) : (),
83			    $self->{sslciphers} ?
84				(SSL_cipher_list => $self->{sslciphers}) : (),
85			) or die ref($self), " $iosocket socket connect ".
86			    "failed: $!,$SSL_ERROR";
87			if ($self->{sndbuf}) {
88				setsockopt($cs, SOL_SOCKET, SO_SNDBUF,
89				    pack('i', $self->{sndbuf})) or die
90				    ref($self), " set SO_SNDBUF failed: $!";
91			}
92			if ($self->{rcvbuf}) {
93				setsockopt($cs, SOL_SOCKET, SO_RCVBUF,
94				    pack('i', $self->{rcvbuf})) or die
95				    ref($self), " set SO_RCVBUF failed: $!";
96			}
97			print STDERR "connect sock: ",$cs->sockhost()," ",
98			    $cs->sockport(),"\n";
99			print STDERR "connect peer: ",$cs->peerhost()," ",
100			    $cs->peerport(),"\n";
101			if ($self->{connectproto} eq "tls") {
102				print STDERR "ssl version: ",
103				    $cs->get_sslversion(),"\n";
104				print STDERR "ssl cipher: ",
105				    $cs->get_cipher(),"\n";
106				print STDERR "ssl issuer: ",
107				    $cs->peer_certificate('issuer'),"\n";
108				print STDERR "ssl subject: ",
109				    $cs->peer_certificate('subject'),"\n";
110				print STDERR "ssl cn: ",
111				    $cs->peer_certificate('cn'),"\n";
112			}
113		}
114
115		IO::Handle::flush(\*STDOUT);
116		*STDIN = *STDOUT = $self->{cs} = $cs;
117		select(STDOUT);
118	}
119
120	if ($self->{logsock}) {
121		setlogsock($self->{logsock})
122		    or die ref($self), " setlogsock failed: $!";
123	}
124	# we take LOG_UUCP as it is not used nowadays
125	openlog("syslogd-regress", "perror,pid", LOG_UUCP);
126}
127
1281;
129