1 /* SPDX-License-Identifier: LGPL-2.1+ */
7 #include <selinux/selinux.h>
10 #include "sd-daemon.h"
13 #include "alloc-util.h"
14 #include "dirent-util.h"
19 #include "journald-console.h"
20 #include "journald-context.h"
21 #include "journald-kmsg.h"
22 #include "journald-server.h"
23 #include "journald-stream.h"
24 #include "journald-syslog.h"
25 #include "journald-wall.h"
27 #include "parse-util.h"
28 #include "process-util.h"
29 #include "selinux-util.h"
30 #include "socket-util.h"
31 #include "stdio-util.h"
32 #include "string-util.h"
33 #include "syslog-util.h"
34 #include "unit-name.h"
36 #define STDOUT_STREAMS_MAX 4096
38 typedef enum StdoutStreamState
{
39 STDOUT_STREAM_IDENTIFIER
,
40 STDOUT_STREAM_UNIT_ID
,
41 STDOUT_STREAM_PRIORITY
,
42 STDOUT_STREAM_LEVEL_PREFIX
,
43 STDOUT_STREAM_FORWARD_TO_SYSLOG
,
44 STDOUT_STREAM_FORWARD_TO_KMSG
,
45 STDOUT_STREAM_FORWARD_TO_CONSOLE
,
49 /* The different types of log record terminators: a real \n was read, a NUL character was read, the maximum line length
50 * was reached, or the end of the stream was reached */
52 typedef enum LineBreak
{
61 StdoutStreamState state
;
71 bool forward_to_syslog
:1;
72 bool forward_to_kmsg
:1;
73 bool forward_to_console
:1;
76 bool in_notify_queue
:1;
82 sd_event_source
*event_source
;
86 ClientContext
*context
;
88 LIST_FIELDS(StdoutStream
, stdout_stream
);
89 LIST_FIELDS(StdoutStream
, stdout_stream_notify_queue
);
91 char id_field
[STRLEN("_STREAM_ID=") + SD_ID128_STRING_MAX
];
94 void stdout_stream_free(StdoutStream
*s
) {
101 client_context_release(s
->server
, s
->context
);
103 assert(s
->server
->n_stdout_streams
> 0);
104 s
->server
->n_stdout_streams
--;
105 LIST_REMOVE(stdout_stream
, s
->server
->stdout_streams
, s
);
107 if (s
->in_notify_queue
)
108 LIST_REMOVE(stdout_stream_notify_queue
, s
->server
->stdout_streams_notify_queue
, s
);
111 if (s
->event_source
) {
112 sd_event_source_set_enabled(s
->event_source
, SD_EVENT_OFF
);
113 s
->event_source
= sd_event_source_unref(s
->event_source
);
126 DEFINE_TRIVIAL_CLEANUP_FUNC(StdoutStream
*, stdout_stream_free
);
128 static void stdout_stream_destroy(StdoutStream
*s
) {
133 (void) unlink(s
->state_file
);
135 stdout_stream_free(s
);
138 static int stdout_stream_save(StdoutStream
*s
) {
139 _cleanup_free_
char *temp_path
= NULL
;
140 _cleanup_fclose_
FILE *f
= NULL
;
145 if (s
->state
!= STDOUT_STREAM_RUNNING
)
148 if (!s
->state_file
) {
151 r
= fstat(s
->fd
, &st
);
153 return log_warning_errno(errno
, "Failed to stat connected stream: %m");
155 /* We use device and inode numbers as identifier for the stream */
156 if (asprintf(&s
->state_file
, "/run/systemd/journal/streams/%lu:%lu", (unsigned long) st
.st_dev
, (unsigned long) st
.st_ino
) < 0)
160 mkdir_p("/run/systemd/journal/streams", 0755);
162 r
= fopen_temporary(s
->state_file
, &f
, &temp_path
);
167 "# This is private data. Do not parse\n"
170 "FORWARD_TO_SYSLOG=%i\n"
171 "FORWARD_TO_KMSG=%i\n"
172 "FORWARD_TO_CONSOLE=%i\n"
176 s
->forward_to_syslog
,
178 s
->forward_to_console
,
179 s
->id_field
+ STRLEN("_STREAM_ID="));
181 if (!isempty(s
->identifier
)) {
182 _cleanup_free_
char *escaped
;
184 escaped
= cescape(s
->identifier
);
190 fprintf(f
, "IDENTIFIER=%s\n", escaped
);
193 if (!isempty(s
->unit_id
)) {
194 _cleanup_free_
char *escaped
;
196 escaped
= cescape(s
->unit_id
);
202 fprintf(f
, "UNIT=%s\n", escaped
);
205 r
= fflush_and_check(f
);
209 if (rename(temp_path
, s
->state_file
) < 0) {
214 if (!s
->fdstore
&& !s
->in_notify_queue
) {
215 LIST_PREPEND(stdout_stream_notify_queue
, s
->server
->stdout_streams_notify_queue
, s
);
216 s
->in_notify_queue
= true;
218 if (s
->server
->notify_event_source
) {
219 r
= sd_event_source_set_enabled(s
->server
->notify_event_source
, SD_EVENT_ON
);
221 log_warning_errno(r
, "Failed to enable notify event source: %m");
228 (void) unlink(s
->state_file
);
231 (void) unlink(temp_path
);
233 return log_error_errno(r
, "Failed to save stream data %s: %m", s
->state_file
);
236 static int stdout_stream_log(StdoutStream
*s
, const char *p
, LineBreak line_break
) {
239 char syslog_priority
[] = "PRIORITY=\0";
240 char syslog_facility
[STRLEN("SYSLOG_FACILITY=") + DECIMAL_STR_MAX(int) + 1];
241 _cleanup_free_
char *message
= NULL
, *syslog_identifier
= NULL
;
249 (void) client_context_maybe_refresh(s
->server
, s
->context
, NULL
, NULL
, 0, NULL
, USEC_INFINITY
);
250 else if (pid_is_valid(s
->ucred
.pid
)) {
251 r
= client_context_acquire(s
->server
, s
->ucred
.pid
, &s
->ucred
, s
->label
, strlen_ptr(s
->label
), s
->unit_id
, &s
->context
);
253 log_warning_errno(r
, "Failed to acquire client context, ignoring: %m");
256 priority
= s
->priority
;
259 syslog_parse_priority(&p
, &priority
, false);
261 if (!client_context_test_priority(s
->context
, priority
))
267 if (s
->forward_to_syslog
|| s
->server
->forward_to_syslog
)
268 server_forward_syslog(s
->server
, syslog_fixup_facility(priority
), s
->identifier
, p
, &s
->ucred
, NULL
);
270 if (s
->forward_to_kmsg
|| s
->server
->forward_to_kmsg
)
271 server_forward_kmsg(s
->server
, priority
, s
->identifier
, p
, &s
->ucred
);
273 if (s
->forward_to_console
|| s
->server
->forward_to_console
)
274 server_forward_console(s
->server
, priority
, s
->identifier
, p
, &s
->ucred
);
276 if (s
->server
->forward_to_wall
)
277 server_forward_wall(s
->server
, priority
, s
->identifier
, p
, &s
->ucred
);
279 m
= N_IOVEC_META_FIELDS
+ 7 + client_context_extra_fields_n_iovec(s
->context
);
280 iovec
= newa(struct iovec
, m
);
282 iovec
[n
++] = IOVEC_MAKE_STRING("_TRANSPORT=stdout");
283 iovec
[n
++] = IOVEC_MAKE_STRING(s
->id_field
);
285 syslog_priority
[STRLEN("PRIORITY=")] = '0' + LOG_PRI(priority
);
286 iovec
[n
++] = IOVEC_MAKE_STRING(syslog_priority
);
288 if (priority
& LOG_FACMASK
) {
289 xsprintf(syslog_facility
, "SYSLOG_FACILITY=%i", LOG_FAC(priority
));
290 iovec
[n
++] = IOVEC_MAKE_STRING(syslog_facility
);
294 syslog_identifier
= strappend("SYSLOG_IDENTIFIER=", s
->identifier
);
295 if (syslog_identifier
)
296 iovec
[n
++] = IOVEC_MAKE_STRING(syslog_identifier
);
299 if (line_break
!= LINE_BREAK_NEWLINE
) {
302 /* If this log message was generated due to an uncommon line break then mention this in the log
305 c
= line_break
== LINE_BREAK_NUL
? "_LINE_BREAK=nul" :
306 line_break
== LINE_BREAK_LINE_MAX
? "_LINE_BREAK=line-max" :
308 iovec
[n
++] = IOVEC_MAKE_STRING(c
);
311 message
= strappend("MESSAGE=", p
);
313 iovec
[n
++] = IOVEC_MAKE_STRING(message
);
315 server_dispatch_message(s
->server
, iovec
, n
, m
, s
->context
, NULL
, priority
, 0);
319 static int stdout_stream_line(StdoutStream
*s
, char *p
, LineBreak line_break
) {
329 /* line breaks by NUL, line max length or EOF are not permissible during the negotiation part of the protocol */
330 if (line_break
!= LINE_BREAK_NEWLINE
&& s
->state
!= STDOUT_STREAM_RUNNING
) {
331 log_warning("Control protocol line not properly terminated.");
337 case STDOUT_STREAM_IDENTIFIER
:
339 s
->identifier
= strdup(p
);
344 s
->state
= STDOUT_STREAM_UNIT_ID
;
347 case STDOUT_STREAM_UNIT_ID
:
348 if (s
->ucred
.uid
== 0 &&
349 unit_name_is_valid(p
, UNIT_NAME_PLAIN
|UNIT_NAME_INSTANCE
)) {
351 s
->unit_id
= strdup(p
);
356 s
->state
= STDOUT_STREAM_PRIORITY
;
359 case STDOUT_STREAM_PRIORITY
:
360 r
= safe_atoi(p
, &s
->priority
);
361 if (r
< 0 || s
->priority
< 0 || s
->priority
> 999) {
362 log_warning("Failed to parse log priority line.");
366 s
->state
= STDOUT_STREAM_LEVEL_PREFIX
;
369 case STDOUT_STREAM_LEVEL_PREFIX
:
370 r
= parse_boolean(p
);
372 log_warning("Failed to parse level prefix line.");
377 s
->state
= STDOUT_STREAM_FORWARD_TO_SYSLOG
;
380 case STDOUT_STREAM_FORWARD_TO_SYSLOG
:
381 r
= parse_boolean(p
);
383 log_warning("Failed to parse forward to syslog line.");
387 s
->forward_to_syslog
= r
;
388 s
->state
= STDOUT_STREAM_FORWARD_TO_KMSG
;
391 case STDOUT_STREAM_FORWARD_TO_KMSG
:
392 r
= parse_boolean(p
);
394 log_warning("Failed to parse copy to kmsg line.");
398 s
->forward_to_kmsg
= r
;
399 s
->state
= STDOUT_STREAM_FORWARD_TO_CONSOLE
;
402 case STDOUT_STREAM_FORWARD_TO_CONSOLE
:
403 r
= parse_boolean(p
);
405 log_warning("Failed to parse copy to console line.");
409 s
->forward_to_console
= r
;
410 s
->state
= STDOUT_STREAM_RUNNING
;
412 /* Try to save the stream, so that journald can be restarted and we can recover */
413 (void) stdout_stream_save(s
);
416 case STDOUT_STREAM_RUNNING
:
417 return stdout_stream_log(s
, orig
, line_break
);
420 assert_not_reached("Unknown stream state");
423 static int stdout_stream_scan(StdoutStream
*s
, bool force_flush
) {
431 remaining
= s
->length
;
433 /* XXX: This function does nothing if (s->length == 0) */
436 LineBreak line_break
;
440 end1
= memchr(p
, '\n', remaining
);
441 end2
= memchr(p
, 0, end1
? (size_t) (end1
- p
) : remaining
);
444 /* We found a NUL terminator */
446 line_break
= LINE_BREAK_NUL
;
448 /* We found a \n terminator */
451 line_break
= LINE_BREAK_NEWLINE
;
452 } else if (remaining
>= s
->server
->line_max
) {
453 /* Force a line break after the maximum line length */
454 *(p
+ s
->server
->line_max
) = 0;
456 line_break
= LINE_BREAK_LINE_MAX
;
460 r
= stdout_stream_line(s
, p
, line_break
);
468 if (force_flush
&& remaining
> 0) {
470 r
= stdout_stream_line(s
, p
, LINE_BREAK_EOF
);
479 memmove(s
->buffer
, p
, remaining
);
480 s
->length
= remaining
;
486 static int stdout_stream_process(sd_event_source
*es
, int fd
, uint32_t revents
, void *userdata
) {
487 StdoutStream
*s
= userdata
;
494 if ((revents
|EPOLLIN
|EPOLLHUP
) != (EPOLLIN
|EPOLLHUP
)) {
495 log_error("Got invalid event from epoll for stdout stream: %"PRIx32
, revents
);
499 /* If the buffer is full already (discounting the extra NUL we need), add room for another 1K */
500 if (s
->length
+ 1 >= s
->allocated
) {
501 if (!GREEDY_REALLOC(s
->buffer
, s
->allocated
, s
->length
+ 1 + 1024)) {
507 /* Try to make use of the allocated buffer in full, but never read more than the configured line size. Also,
508 * always leave room for a terminating NUL we might need to add. */
509 limit
= MIN(s
->allocated
- 1, s
->server
->line_max
);
511 l
= read(s
->fd
, s
->buffer
+ s
->length
, limit
- s
->length
);
516 log_warning_errno(errno
, "Failed to read from stream: %m");
521 stdout_stream_scan(s
, true);
526 r
= stdout_stream_scan(s
, false);
533 stdout_stream_destroy(s
);
537 static int stdout_stream_install(Server
*s
, int fd
, StdoutStream
**ret
) {
538 _cleanup_(stdout_stream_freep
) StdoutStream
*stream
= NULL
;
545 r
= sd_id128_randomize(&id
);
547 return log_error_errno(r
, "Failed to generate stream ID: %m");
549 stream
= new0(StdoutStream
, 1);
554 stream
->priority
= LOG_INFO
;
556 xsprintf(stream
->id_field
, "_STREAM_ID=" SD_ID128_FORMAT_STR
, SD_ID128_FORMAT_VAL(id
));
558 r
= getpeercred(fd
, &stream
->ucred
);
560 return log_error_errno(r
, "Failed to determine peer credentials: %m");
562 if (mac_selinux_use()) {
563 r
= getpeersec(fd
, &stream
->label
);
564 if (r
< 0 && r
!= -EOPNOTSUPP
)
565 (void) log_warning_errno(r
, "Failed to determine peer security context: %m");
568 (void) shutdown(fd
, SHUT_WR
);
570 r
= sd_event_add_io(s
->event
, &stream
->event_source
, fd
, EPOLLIN
, stdout_stream_process
, stream
);
572 return log_error_errno(r
, "Failed to add stream to event loop: %m");
574 r
= sd_event_source_set_priority(stream
->event_source
, SD_EVENT_PRIORITY_NORMAL
+5);
576 return log_error_errno(r
, "Failed to adjust stdout event source priority: %m");
581 LIST_PREPEND(stdout_stream
, s
->stdout_streams
, stream
);
582 s
->n_stdout_streams
++;
592 static int stdout_stream_new(sd_event_source
*es
, int listen_fd
, uint32_t revents
, void *userdata
) {
593 _cleanup_close_
int fd
= -1;
594 Server
*s
= userdata
;
599 if (revents
!= EPOLLIN
) {
600 log_error("Got invalid event from epoll for stdout server fd: %"PRIx32
, revents
);
604 fd
= accept4(s
->stdout_fd
, NULL
, NULL
, SOCK_NONBLOCK
|SOCK_CLOEXEC
);
609 return log_error_errno(errno
, "Failed to accept stdout connection: %m");
612 if (s
->n_stdout_streams
>= STDOUT_STREAMS_MAX
) {
615 r
= getpeercred(fd
, &u
);
617 /* By closing fd here we make sure that the client won't wait too long for journald to
618 * gather all the data it adds to the error message to find out that the connection has
623 server_driver_message(s
, r
< 0 ? 0 : u
.pid
, NULL
, LOG_MESSAGE("Too many stdout streams, refusing connection."), NULL
);
627 r
= stdout_stream_install(s
, fd
, NULL
);
635 static int stdout_stream_load(StdoutStream
*stream
, const char *fname
) {
638 *level_prefix
= NULL
,
639 *forward_to_syslog
= NULL
,
640 *forward_to_kmsg
= NULL
,
641 *forward_to_console
= NULL
,
648 if (!stream
->state_file
) {
649 stream
->state_file
= strappend("/run/systemd/journal/streams/", fname
);
650 if (!stream
->state_file
)
654 r
= parse_env_file(NULL
, stream
->state_file
, NEWLINE
,
655 "PRIORITY", &priority
,
656 "LEVEL_PREFIX", &level_prefix
,
657 "FORWARD_TO_SYSLOG", &forward_to_syslog
,
658 "FORWARD_TO_KMSG", &forward_to_kmsg
,
659 "FORWARD_TO_CONSOLE", &forward_to_console
,
660 "IDENTIFIER", &stream
->identifier
,
661 "UNIT", &stream
->unit_id
,
662 "STREAM_ID", &stream_id
,
665 return log_error_errno(r
, "Failed to read: %s", stream
->state_file
);
670 p
= log_level_from_string(priority
);
672 stream
->priority
= p
;
676 r
= parse_boolean(level_prefix
);
678 stream
->level_prefix
= r
;
681 if (forward_to_syslog
) {
682 r
= parse_boolean(forward_to_syslog
);
684 stream
->forward_to_syslog
= r
;
687 if (forward_to_kmsg
) {
688 r
= parse_boolean(forward_to_kmsg
);
690 stream
->forward_to_kmsg
= r
;
693 if (forward_to_console
) {
694 r
= parse_boolean(forward_to_console
);
696 stream
->forward_to_console
= r
;
702 r
= sd_id128_from_string(stream_id
, &id
);
704 xsprintf(stream
->id_field
, "_STREAM_ID=" SD_ID128_FORMAT_STR
, SD_ID128_FORMAT_VAL(id
));
710 static int stdout_stream_restore(Server
*s
, const char *fname
, int fd
) {
711 StdoutStream
*stream
;
718 if (s
->n_stdout_streams
>= STDOUT_STREAMS_MAX
) {
719 log_warning("Too many stdout streams, refusing restoring of stream.");
723 r
= stdout_stream_install(s
, fd
, &stream
);
727 stream
->state
= STDOUT_STREAM_RUNNING
;
728 stream
->fdstore
= true;
730 /* Ignore all parsing errors */
731 (void) stdout_stream_load(stream
, fname
);
736 int server_restore_streams(Server
*s
, FDSet
*fds
) {
737 _cleanup_closedir_
DIR *d
= NULL
;
741 d
= opendir("/run/systemd/journal/streams");
746 return log_warning_errno(errno
, "Failed to enumerate /run/systemd/journal/streams: %m");
749 FOREACH_DIRENT(de
, d
, goto fail
) {
750 unsigned long st_dev
, st_ino
;
755 if (sscanf(de
->d_name
, "%lu:%lu", &st_dev
, &st_ino
) != 2)
758 FDSET_FOREACH(fd
, fds
, i
) {
761 if (fstat(fd
, &st
) < 0)
762 return log_error_errno(errno
, "Failed to stat %s: %m", de
->d_name
);
764 if (S_ISSOCK(st
.st_mode
) && st
.st_dev
== st_dev
&& st
.st_ino
== st_ino
) {
771 /* No file descriptor? Then let's delete the state file */
772 log_debug("Cannot restore stream file %s", de
->d_name
);
773 if (unlinkat(dirfd(d
), de
->d_name
, 0) < 0)
774 log_warning_errno(errno
, "Failed to remove /run/systemd/journal/streams/%s: %m",
779 fdset_remove(fds
, fd
);
781 r
= stdout_stream_restore(s
, de
->d_name
, fd
);
789 return log_error_errno(errno
, "Failed to read streams directory: %m");
792 int server_open_stdout_socket(Server
*s
) {
793 static const union sockaddr_union sa
= {
794 .un
.sun_family
= AF_UNIX
,
795 .un
.sun_path
= "/run/systemd/journal/stdout",
801 if (s
->stdout_fd
< 0) {
802 s
->stdout_fd
= socket(AF_UNIX
, SOCK_STREAM
|SOCK_CLOEXEC
|SOCK_NONBLOCK
, 0);
803 if (s
->stdout_fd
< 0)
804 return log_error_errno(errno
, "socket() failed: %m");
806 (void) sockaddr_un_unlink(&sa
.un
);
808 r
= bind(s
->stdout_fd
, &sa
.sa
, SOCKADDR_UN_LEN(sa
.un
));
810 return log_error_errno(errno
, "bind(%s) failed: %m", sa
.un
.sun_path
);
812 (void) chmod(sa
.un
.sun_path
, 0666);
814 if (listen(s
->stdout_fd
, SOMAXCONN
) < 0)
815 return log_error_errno(errno
, "listen(%s) failed: %m", sa
.un
.sun_path
);
817 (void) fd_nonblock(s
->stdout_fd
, true);
819 r
= sd_event_add_io(s
->event
, &s
->stdout_event_source
, s
->stdout_fd
, EPOLLIN
, stdout_stream_new
, s
);
821 return log_error_errno(r
, "Failed to add stdout server fd to event source: %m");
823 r
= sd_event_source_set_priority(s
->stdout_event_source
, SD_EVENT_PRIORITY_NORMAL
+5);
825 return log_error_errno(r
, "Failed to adjust priority of stdout server event source: %m");
830 void stdout_stream_send_notify(StdoutStream
*s
) {
831 struct iovec iovec
= {
832 .iov_base
= (char*) "FDSTORE=1",
833 .iov_len
= STRLEN("FDSTORE=1"),
835 struct msghdr msghdr
= {
839 struct cmsghdr
*cmsg
;
844 assert(s
->in_notify_queue
);
846 assert(s
->server
->notify_fd
>= 0);
848 /* Store the connection fd in PID 1, so that we get it passed
849 * in again on next start */
851 msghdr
.msg_controllen
= CMSG_SPACE(sizeof(int));
852 msghdr
.msg_control
= alloca0(msghdr
.msg_controllen
);
854 cmsg
= CMSG_FIRSTHDR(&msghdr
);
855 cmsg
->cmsg_level
= SOL_SOCKET
;
856 cmsg
->cmsg_type
= SCM_RIGHTS
;
857 cmsg
->cmsg_len
= CMSG_LEN(sizeof(int));
859 memcpy(CMSG_DATA(cmsg
), &s
->fd
, sizeof(int));
861 l
= sendmsg(s
->server
->notify_fd
, &msghdr
, MSG_DONTWAIT
|MSG_NOSIGNAL
);
866 log_error_errno(errno
, "Failed to send stream file descriptor to service manager: %m");
868 log_debug("Successfully sent stream file descriptor to service manager.");
872 LIST_REMOVE(stdout_stream_notify_queue
, s
->server
->stdout_streams_notify_queue
, s
);
873 s
->in_notify_queue
= false;