xref: /openbsd-src/regress/usr.sbin/syslogd/Client.pm (revision 46035553bfdd96e63c94e32da0210227ec2e3cf1)
1#	$OpenBSD: Client.pm,v 1.14 2020/11/06 03:26:18 bluhm Exp $
2
3# Copyright (c) 2010-2020 Alexander Bluhm <bluhm@openbsd.org>
4#
5# Permission to use, copy, modify, and distribute this software for any
6# purpose with or without fee is hereby granted, provided that the above
7# copyright notice and this permission notice appear in all copies.
8#
9# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16
17use strict;
18use warnings;
19
20package Client;
21use parent 'Proc';
22use Carp;
23use Socket;
24use Socket6;
25use IO::Socket;
26use IO::Socket::INET6;
27use IO::Socket::SSL;
28use Sys::Syslog qw(:standard :extended :macros);
29
30sub new {
31	my $class = shift;
32	my %args = @_;
33	$args{ktracepid} = "ktrace" if $args{ktrace};
34	$args{ktracepid} = $ENV{KTRACE} if $ENV{KTRACE};
35	$args{ktracefile} ||= "client.ktrace";
36	$args{logfile} ||= "client.log";
37	$args{up} ||= "Openlog";
38	my $self = Proc::new($class, %args);
39	if (defined($self->{connectdomain})) {
40		$self->{connectproto} ||= "udp";
41	}
42	return $self;
43}
44
45sub child {
46	my $self = shift;
47
48	# TLS 1.3 writes multiple messages without acknowledgement.
49	# If the other side closes early, we want broken pipe error.
50	$SIG{PIPE} = 'IGNORE' if defined($self->{connectdomain}) &&
51	    $self->{connectproto} eq "tls";
52
53	if (defined($self->{connectdomain}) &&
54	    $self->{connectdomain} ne "sendsyslog") {
55		my $cs;
56		if ($self->{connectdomain} == AF_UNIX) {
57			$cs = IO::Socket::UNIX->new(
58			    Type => SOCK_DGRAM,
59			    Peer => $self->{connectpath} || "/dev/log",
60			) or die ref($self), " socket unix failed: $!";
61			$cs->setsockopt(SOL_SOCKET, SO_SNDBUF, 10000)
62			    or die ref($self), " setsockopt failed: $!";
63		} else {
64			$SSL_ERROR = "";
65			my $iosocket = $self->{connectproto} eq "tls" ?
66			    "IO::Socket::SSL" : "IO::Socket::INET6";
67			my $proto = $self->{connectproto};
68			$proto = "tcp" if $proto eq "tls";
69			$cs = $iosocket->new(
70			    Proto               => $proto,
71			    Domain              => $self->{connectdomain},
72			    PeerAddr            => $self->{connectaddr},
73			    PeerPort            => $self->{connectport},
74			    $self->{sslcert} ?
75				(SSL_cert_file => $self->{sslcert}) : (),
76			    $self->{sslkey} ?
77				(SSL_key_file => $self->{sslkey}) : (),
78			    $self->{sslca} ?
79				(SSL_ca_file => $self->{sslca}) : (),
80			    SSL_verify_mode     => ($self->{sslca} ?
81				SSL_VERIFY_PEER : SSL_VERIFY_NONE),
82			    $self->{sslversion} ?
83				(SSL_version => $self->{sslversion}) : (),
84			    $self->{sslciphers} ?
85				(SSL_cipher_list => $self->{sslciphers}) : (),
86			) or die ref($self), " $iosocket socket connect ".
87			    "failed: $!,$SSL_ERROR";
88			if ($self->{sndbuf}) {
89				setsockopt($cs, SOL_SOCKET, SO_SNDBUF,
90				    pack('i', $self->{sndbuf})) or die
91				    ref($self), " set SO_SNDBUF failed: $!";
92			}
93			if ($self->{rcvbuf}) {
94				setsockopt($cs, SOL_SOCKET, SO_RCVBUF,
95				    pack('i', $self->{rcvbuf})) or die
96				    ref($self), " set SO_RCVBUF failed: $!";
97			}
98			print STDERR "connect sock: ",$cs->sockhost()," ",
99			    $cs->sockport(),"\n";
100			print STDERR "connect peer: ",$cs->peerhost()," ",
101			    $cs->peerport(),"\n";
102			if ($self->{connectproto} eq "tls") {
103				print STDERR "ssl version: ",
104				    $cs->get_sslversion(),"\n";
105				print STDERR "ssl cipher: ",
106				    $cs->get_cipher(),"\n";
107				print STDERR "ssl issuer: ",
108				    $cs->peer_certificate('issuer'),"\n";
109				print STDERR "ssl subject: ",
110				    $cs->peer_certificate('subject'),"\n";
111				print STDERR "ssl cn: ",
112				    $cs->peer_certificate('cn'),"\n";
113			}
114		}
115
116		IO::Handle::flush(\*STDOUT);
117		*STDIN = *STDOUT = $self->{cs} = $cs;
118		select(STDOUT);
119	}
120
121	if ($self->{logsock}) {
122		setlogsock($self->{logsock})
123		    or die ref($self), " setlogsock failed: $!";
124	}
125	# we take LOG_UUCP as it is not used nowadays
126	openlog("syslogd-regress", "perror,pid", LOG_UUCP);
127}
128
1291;
130