iPXE
syslogs.c
Go to the documentation of this file.
00001 /*
00002  * Copyright (C) 2012 Michael Brown <mbrown@fensystems.co.uk>.
00003  *
00004  * This program is free software; you can redistribute it and/or
00005  * modify it under the terms of the GNU General Public License as
00006  * published by the Free Software Foundation; either version 2 of the
00007  * License, or any later version.
00008  *
00009  * This program is distributed in the hope that it will be useful, but
00010  * WITHOUT ANY WARRANTY; without even the implied warranty of
00011  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
00012  * General Public License for more details.
00013  *
00014  * You should have received a copy of the GNU General Public License
00015  * along with this program; if not, write to the Free Software
00016  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
00017  * 02110-1301, USA.
00018  *
00019  * You can also choose to distribute this program under the terms of
00020  * the Unmodified Binary Distribution Licence (as given in the file
00021  * COPYING.UBDL), provided that you have satisfied its requirements.
00022  */
00023 
00024 FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL );
00025 
00026 /** @file
00027  *
00028  * Encrypted syslog protocol
00029  *
00030  */
00031 
00032 #include <stdint.h>
00033 #include <stdlib.h>
00034 #include <byteswap.h>
00035 #include <ipxe/xfer.h>
00036 #include <ipxe/open.h>
00037 #include <ipxe/tcpip.h>
00038 #include <ipxe/dhcp.h>
00039 #include <ipxe/settings.h>
00040 #include <ipxe/console.h>
00041 #include <ipxe/lineconsole.h>
00042 #include <ipxe/tls.h>
00043 #include <ipxe/syslog.h>
00044 #include <config/console.h>
00045 
00046 /* Set default console usage if applicable */
00047 #if ! ( defined ( CONSOLE_SYSLOGS ) && CONSOLE_EXPLICIT ( CONSOLE_SYSLOGS ) )
00048 #undef CONSOLE_SYSLOGS
00049 #define CONSOLE_SYSLOGS ( CONSOLE_USAGE_ALL & ~CONSOLE_USAGE_TUI )
00050 #endif
00051 
00052 struct console_driver syslogs_console __console_driver;
00053 
00054 /** The encrypted syslog server */
00055 static struct sockaddr_tcpip logserver = {
00056         .st_port = htons ( SYSLOG_PORT ),
00057 };
00058 
00059 /**
00060  * Handle encrypted syslog TLS interface close
00061  *
00062  * @v intf              Interface
00063  * @v rc                Reason for close
00064  */
00065 static void syslogs_close ( struct interface *intf __unused, int rc ) {
00066 
00067         DBG ( "SYSLOGS console disconnected: %s\n", strerror ( rc ) );
00068 }
00069 
00070 /**
00071  * Handle encrypted syslog TLS interface window change
00072  *
00073  * @v intf              Interface
00074  */
00075 static void syslogs_window_changed ( struct interface *intf ) {
00076 
00077         /* Mark console as enabled when window first opens, indicating
00078          * that TLS negotiation is complete.  (Do not disable console
00079          * when window closes again, since TCP will close the window
00080          * whenever there is unACKed data.)
00081          */
00082         if ( xfer_window ( intf ) ) {
00083                 if ( syslogs_console.disabled )
00084                         DBG ( "SYSLOGS console connected\n" );
00085                 syslogs_console.disabled = 0;
00086         }
00087 }
00088 
00089 /** Encrypted syslog TLS interface operations */
00090 static struct interface_operation syslogs_operations[] = {
00091         INTF_OP ( xfer_window_changed, struct interface *,
00092                   syslogs_window_changed ),
00093         INTF_OP ( intf_close, struct interface *, syslogs_close ),
00094 };
00095 
00096 /** Encrypted syslog TLS interface descriptor */
00097 static struct interface_descriptor syslogs_desc =
00098         INTF_DESC_PURE ( syslogs_operations );
00099 
00100 /** The encrypted syslog TLS interface */
00101 static struct interface syslogs = INTF_INIT ( syslogs_desc );
00102 
00103 /******************************************************************************
00104  *
00105  * Console driver
00106  *
00107  ******************************************************************************
00108  */
00109 
00110 /** Encrypted syslog line buffer */
00111 static char syslogs_buffer[SYSLOG_BUFSIZE];
00112 
00113 /** Encrypted syslog severity */
00114 static unsigned int syslogs_severity = SYSLOG_DEFAULT_SEVERITY;
00115 
00116 /**
00117  * Handle ANSI set encrypted syslog priority (private sequence)
00118  *
00119  * @v ctx               ANSI escape sequence context
00120  * @v count             Parameter count
00121  * @v params            List of graphic rendition aspects
00122  */
00123 static void syslogs_handle_priority ( struct ansiesc_context *ctx __unused,
00124                                       unsigned int count __unused,
00125                                       int params[] ) {
00126         if ( params[0] >= 0 ) {
00127                 syslogs_severity = params[0];
00128         } else {
00129                 syslogs_severity = SYSLOG_DEFAULT_SEVERITY;
00130         }
00131 }
00132 
00133 /** Encrypted syslog ANSI escape sequence handlers */
00134 static struct ansiesc_handler syslogs_handlers[] = {
00135         { ANSIESC_LOG_PRIORITY, syslogs_handle_priority },
00136         { 0, NULL }
00137 };
00138 
00139 /** Encrypted syslog line console */
00140 static struct line_console syslogs_line = {
00141         .buffer = syslogs_buffer,
00142         .len = sizeof ( syslogs_buffer ),
00143         .ctx = {
00144                 .handlers = syslogs_handlers,
00145         },
00146 };
00147 
00148 /** Encrypted syslog recursion marker */
00149 static int syslogs_entered;
00150 
00151 /**
00152  * Print a character to encrypted syslog console
00153  *
00154  * @v character         Character to be printed
00155  */
00156 static void syslogs_putchar ( int character ) {
00157         int rc;
00158 
00159         /* Ignore if we are already mid-logging */
00160         if ( syslogs_entered )
00161                 return;
00162 
00163         /* Fill line buffer */
00164         if ( line_putchar ( &syslogs_line, character ) == 0 )
00165                 return;
00166 
00167         /* Guard against re-entry */
00168         syslogs_entered = 1;
00169 
00170         /* Send log message */
00171         if ( ( rc = syslog_send ( &syslogs, syslogs_severity,
00172                                   syslogs_buffer, "\n" ) ) != 0 ) {
00173                 DBG ( "SYSLOGS could not send log message: %s\n",
00174                       strerror ( rc ) );
00175         }
00176 
00177         /* Clear re-entry flag */
00178         syslogs_entered = 0;
00179 }
00180 
00181 /** Encrypted syslog console driver */
00182 struct console_driver syslogs_console __console_driver = {
00183         .putchar = syslogs_putchar,
00184         .disabled = CONSOLE_DISABLED,
00185         .usage = CONSOLE_SYSLOGS,
00186 };
00187 
00188 /******************************************************************************
00189  *
00190  * Settings
00191  *
00192  ******************************************************************************
00193  */
00194 
00195 /** Encrypted syslog server setting */
00196 const struct setting syslogs_setting __setting ( SETTING_MISC, syslogs ) = {
00197         .name = "syslogs",
00198         .description = "Encrypted syslog server",
00199         .tag = DHCP_EB_SYSLOGS_SERVER,
00200         .type = &setting_type_string,
00201 };
00202 
00203 /**
00204  * Apply encrypted syslog settings
00205  *
00206  * @ret rc              Return status code
00207  */
00208 static int apply_syslogs_settings ( void ) {
00209         static char *old_server;
00210         char *server;
00211         struct interface *socket;
00212         int rc;
00213 
00214         /* Fetch log server */
00215         fetch_string_setting_copy ( NULL, &syslogs_setting, &server );
00216 
00217         /* Do nothing unless log server has changed */
00218         if ( ( ( server == NULL ) && ( old_server == NULL ) ) ||
00219              ( ( server != NULL ) && ( old_server != NULL ) &&
00220                ( strcmp ( server, old_server ) == 0 ) ) ) {
00221                 rc = 0;
00222                 goto out_no_change;
00223         }
00224         free ( old_server );
00225         old_server = NULL;
00226 
00227         /* Reset encrypted syslog connection */
00228         syslogs_console.disabled = CONSOLE_DISABLED;
00229         intf_restart ( &syslogs, 0 );
00230 
00231         /* Do nothing unless we have a log server */
00232         if ( ! server ) {
00233                 DBG ( "SYSLOGS has no log server\n" );
00234                 rc = 0;
00235                 goto out_no_server;
00236         }
00237 
00238         /* Add TLS filter */
00239         if ( ( rc = add_tls ( &syslogs, server, &socket ) ) != 0 ) {
00240                 DBG ( "SYSLOGS cannot create TLS filter: %s\n",
00241                       strerror ( rc ) );
00242                 goto err_add_tls;
00243         }
00244 
00245         /* Connect to log server */
00246         if ( ( rc = xfer_open_named_socket ( socket, SOCK_STREAM,
00247                                              (( struct sockaddr *) &logserver ),
00248                                              server, NULL ) ) != 0 ) {
00249                 DBG ( "SYSLOGS cannot connect to log server: %s\n",
00250                       strerror ( rc ) );
00251                 goto err_open_named_socket;
00252         }
00253         DBG ( "SYSLOGS using log server %s\n", server );
00254 
00255         /* Record log server */
00256         old_server = server;
00257         server = NULL;
00258 
00259         /* Success */
00260         rc = 0;
00261 
00262  err_open_named_socket:
00263  err_add_tls:
00264  out_no_server:
00265  out_no_change:
00266         free ( server );
00267         return rc;
00268 }
00269 
00270 /** Encrypted syslog settings applicator */
00271 struct settings_applicator syslogs_applicator __settings_applicator = {
00272         .apply = apply_syslogs_settings,
00273 };