xref: /openbsd-src/regress/usr.sbin/syslogd/Client.pm (revision be691f3bb6417f04a68938fadbcaee2d5795e764)
1#	$OpenBSD: Client.pm,v 1.15 2021/03/09 15:16:28 bluhm Exp $
2
3# Copyright (c) 2010-2020 Alexander Bluhm <bluhm@openbsd.org>
4#
5# Permission to use, copy, modify, and distribute this software for any
6# purpose with or without fee is hereby granted, provided that the above
7# copyright notice and this permission notice appear in all copies.
8#
9# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10# WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11# MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12# ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13# WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14# ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15# OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16
17use strict;
18use warnings;
19
20package Client;
21use parent 'Proc';
22use Carp;
23use Socket;
24use Socket6;
25use IO::Socket;
26use IO::Socket::INET6;
27use IO::Socket::SSL;
28use Sys::Syslog qw(:standard :extended :macros);
29
30sub new {
31	my $class = shift;
32	my %args = @_;
33	$args{ktracepid} = "ktrace" if $args{ktrace};
34	$args{ktracepid} = $ENV{KTRACE} if $ENV{KTRACE};
35	$args{ktracefile} ||= "client.ktrace";
36	$args{logfile} ||= "client.log";
37	$args{up} ||= "Openlog";
38	my $self = Proc::new($class, %args);
39	if (defined($self->{connectdomain})) {
40		$self->{connectproto} ||= "udp";
41	}
42	return $self;
43}
44
45sub child {
46	my $self = shift;
47
48	if ($self->{early}) {
49		my @sudo = $ENV{SUDO} ? $ENV{SUDO} : "env";
50		my @flush = (@sudo, "./logflush");
51		system(@flush);
52	}
53
54	# TLS 1.3 writes multiple messages without acknowledgement.
55	# If the other side closes early, we want broken pipe error.
56	$SIG{PIPE} = 'IGNORE' if defined($self->{connectdomain}) &&
57	    $self->{connectproto} eq "tls";
58
59	if (defined($self->{connectdomain}) &&
60	    $self->{connectdomain} ne "sendsyslog") {
61		my $cs;
62		if ($self->{connectdomain} == AF_UNIX) {
63			$cs = IO::Socket::UNIX->new(
64			    Type => SOCK_DGRAM,
65			    Peer => $self->{connectpath} || "/dev/log",
66			) or die ref($self), " socket unix failed: $!";
67			$cs->setsockopt(SOL_SOCKET, SO_SNDBUF, 10000)
68			    or die ref($self), " setsockopt failed: $!";
69		} else {
70			$SSL_ERROR = "";
71			my $iosocket = $self->{connectproto} eq "tls" ?
72			    "IO::Socket::SSL" : "IO::Socket::INET6";
73			my $proto = $self->{connectproto};
74			$proto = "tcp" if $proto eq "tls";
75			$cs = $iosocket->new(
76			    Proto               => $proto,
77			    Domain              => $self->{connectdomain},
78			    PeerAddr            => $self->{connectaddr},
79			    PeerPort            => $self->{connectport},
80			    $self->{sslcert} ?
81				(SSL_cert_file => $self->{sslcert}) : (),
82			    $self->{sslkey} ?
83				(SSL_key_file => $self->{sslkey}) : (),
84			    $self->{sslca} ?
85				(SSL_ca_file => $self->{sslca}) : (),
86			    SSL_verify_mode     => ($self->{sslca} ?
87				SSL_VERIFY_PEER : SSL_VERIFY_NONE),
88			    $self->{sslversion} ?
89				(SSL_version => $self->{sslversion}) : (),
90			    $self->{sslciphers} ?
91				(SSL_cipher_list => $self->{sslciphers}) : (),
92			) or die ref($self), " $iosocket socket connect ".
93			    "failed: $!,$SSL_ERROR";
94			if ($self->{sndbuf}) {
95				setsockopt($cs, SOL_SOCKET, SO_SNDBUF,
96				    pack('i', $self->{sndbuf})) or die
97				    ref($self), " set SO_SNDBUF failed: $!";
98			}
99			if ($self->{rcvbuf}) {
100				setsockopt($cs, SOL_SOCKET, SO_RCVBUF,
101				    pack('i', $self->{rcvbuf})) or die
102				    ref($self), " set SO_RCVBUF failed: $!";
103			}
104			print STDERR "connect sock: ",$cs->sockhost()," ",
105			    $cs->sockport(),"\n";
106			print STDERR "connect peer: ",$cs->peerhost()," ",
107			    $cs->peerport(),"\n";
108			if ($self->{connectproto} eq "tls") {
109				print STDERR "ssl version: ",
110				    $cs->get_sslversion(),"\n";
111				print STDERR "ssl cipher: ",
112				    $cs->get_cipher(),"\n";
113				print STDERR "ssl issuer: ",
114				    $cs->peer_certificate('issuer'),"\n";
115				print STDERR "ssl subject: ",
116				    $cs->peer_certificate('subject'),"\n";
117				print STDERR "ssl cn: ",
118				    $cs->peer_certificate('cn'),"\n";
119			}
120		}
121
122		IO::Handle::flush(\*STDOUT);
123		*STDIN = *STDOUT = $self->{cs} = $cs;
124		select(STDOUT);
125	}
126
127	if ($self->{logsock}) {
128		setlogsock($self->{logsock})
129		    or die ref($self), " setlogsock failed: $!";
130	}
131	# we take LOG_UUCP as it is not used nowadays
132	openlog("syslogd-regress", "perror,pid", LOG_UUCP);
133}
134
1351;
136