diff options
Diffstat (limited to 'plugins/popen.c')
| -rw-r--r-- | plugins/popen.c | 322 |
1 files changed, 165 insertions, 157 deletions
diff --git a/plugins/popen.c b/plugins/popen.c index 54e63bc5..c596d1e0 100644 --- a/plugins/popen.c +++ b/plugins/popen.c | |||
| @@ -1,294 +1,302 @@ | |||
| 1 | /***************************************************************************** | 1 | /***************************************************************************** |
| 2 | * | 2 | * |
| 3 | * Monitoring Plugins popen | 3 | * Monitoring Plugins popen |
| 4 | * | 4 | * |
| 5 | * License: GPL | 5 | * License: GPL |
| 6 | * Copyright (c) 2005-2007 Monitoring Plugins Development Team | 6 | * Copyright (c) 2005-2024 Monitoring Plugins Development Team |
| 7 | * | 7 | * |
| 8 | * Description: | 8 | * Description: |
| 9 | * | 9 | * |
| 10 | * A safe alternative to popen | 10 | * A safe alternative to popen |
| 11 | * | 11 | * |
| 12 | * Provides spopen and spclose | 12 | * Provides spopen and spclose |
| 13 | * | 13 | * |
| 14 | * FILE * spopen(const char *); | 14 | * FILE * spopen(const char *); |
| 15 | * int spclose(FILE *); | 15 | * int spclose(FILE *); |
| 16 | * | 16 | * |
| 17 | * Code taken with little modification from "Advanced Programming for the Unix | 17 | * Code taken with little modification from "Advanced Programming for the Unix |
| 18 | * Environment" by W. Richard Stevens | 18 | * Environment" by W. Richard Stevens |
| 19 | * | 19 | * |
| 20 | * This is considered safe in that no shell is spawned, and the environment | 20 | * This is considered safe in that no shell is spawned, and the environment |
| 21 | * and path passed to the exec'd program are essentially empty. (popen create | 21 | * and path passed to the exec'd program are essentially empty. (popen create |
| 22 | * a shell and passes the environment to it). | 22 | * a shell and passes the environment to it). |
| 23 | * | 23 | * |
| 24 | * | 24 | * |
| 25 | * This program is free software: you can redistribute it and/or modify | 25 | * This program is free software: you can redistribute it and/or modify |
| 26 | * it under the terms of the GNU General Public License as published by | 26 | * it under the terms of the GNU General Public License as published by |
| 27 | * the Free Software Foundation, either version 3 of the License, or | 27 | * the Free Software Foundation, either version 3 of the License, or |
| 28 | * (at your option) any later version. | 28 | * (at your option) any later version. |
| 29 | * | 29 | * |
| 30 | * This program is distributed in the hope that it will be useful, | 30 | * This program is distributed in the hope that it will be useful, |
| 31 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | 31 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 32 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | 32 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 33 | * GNU General Public License for more details. | 33 | * GNU General Public License for more details. |
| 34 | * | 34 | * |
| 35 | * You should have received a copy of the GNU General Public License | 35 | * You should have received a copy of the GNU General Public License |
| 36 | * along with this program. If not, see <http://www.gnu.org/licenses/>. | 36 | * along with this program. If not, see <http://www.gnu.org/licenses/>. |
| 37 | * | 37 | * |
| 38 | * | 38 | * |
| 39 | *****************************************************************************/ | 39 | *****************************************************************************/ |
| 40 | 40 | ||
| 41 | #include "./common.h" | 41 | #include "./common.h" |
| 42 | #include "./utils.h" | 42 | #include "./utils.h" |
| 43 | #include "../lib/maxfd.h" | ||
| 44 | 43 | ||
| 45 | /* extern so plugin has pid to kill exec'd process on timeouts */ | 44 | /* extern so plugin has pid to kill exec'd process on timeouts */ |
| 46 | extern pid_t *childpid; | 45 | extern pid_t *childpid; |
| 47 | extern int *child_stderr_array; | 46 | extern int *child_stderr_array; |
| 48 | extern FILE *child_process; | 47 | extern FILE *child_process; |
| 49 | 48 | ||
| 50 | FILE *spopen (const char *); | 49 | FILE *spopen(const char * /*cmdstring*/); |
| 51 | int spclose (FILE *); | 50 | int spclose(FILE * /*fp*/); |
| 52 | #ifdef REDHAT_SPOPEN_ERROR | 51 | #ifdef REDHAT_SPOPEN_ERROR |
| 53 | void popen_sigchld_handler (int); | 52 | void popen_sigchld_handler(int); |
| 54 | #endif | 53 | #endif |
| 55 | void popen_timeout_alarm_handler (int); | 54 | void popen_timeout_alarm_handler(int /*signo*/); |
| 56 | 55 | ||
| 57 | #include <stdarg.h> /* ANSI C header file */ | 56 | #include <stdarg.h> /* ANSI C header file */ |
| 58 | #include <fcntl.h> | 57 | #include <fcntl.h> |
| 59 | 58 | ||
| 60 | #include <limits.h> | 59 | #include <limits.h> |
| 61 | #include <sys/resource.h> | 60 | #include <sys/resource.h> |
| 62 | 61 | ||
| 63 | #ifdef HAVE_SYS_WAIT_H | 62 | #ifdef HAVE_SYS_WAIT_H |
| 64 | #include <sys/wait.h> | 63 | # include <sys/wait.h> |
| 65 | #endif | 64 | #endif |
| 66 | 65 | ||
| 67 | #ifndef WEXITSTATUS | 66 | #ifndef WEXITSTATUS |
| 68 | # define WEXITSTATUS(stat_val) ((unsigned)(stat_val) >> 8) | 67 | # define WEXITSTATUS(stat_val) ((unsigned)(stat_val) >> 8) |
| 69 | #endif | 68 | #endif |
| 70 | 69 | ||
| 71 | #ifndef WIFEXITED | 70 | #ifndef WIFEXITED |
| 72 | # define WIFEXITED(stat_val) (((stat_val) & 255) == 0) | 71 | # define WIFEXITED(stat_val) (((stat_val) & 255) == 0) |
| 73 | #endif | 72 | #endif |
| 74 | 73 | ||
| 75 | /* 4.3BSD Reno <signal.h> doesn't define SIG_ERR */ | 74 | /* 4.3BSD Reno <signal.h> doesn't define SIG_ERR */ |
| 76 | #if defined(SIG_IGN) && !defined(SIG_ERR) | 75 | #if defined(SIG_IGN) && !defined(SIG_ERR) |
| 77 | #define SIG_ERR ((Sigfunc *)-1) | 76 | # define SIG_ERR ((Sigfunc *)-1) |
| 78 | #endif | 77 | #endif |
| 79 | 78 | ||
| 80 | 79 | char *pname = NULL; /* caller can set this from argv[0] */ | |
| 81 | char *pname = NULL; /* caller can set this from argv[0] */ | ||
| 82 | 80 | ||
| 83 | #ifdef REDHAT_SPOPEN_ERROR | 81 | #ifdef REDHAT_SPOPEN_ERROR |
| 84 | static volatile int childtermd = 0; | 82 | static volatile int childtermd = 0; |
| 85 | #endif | 83 | #endif |
| 86 | 84 | ||
| 87 | FILE * | 85 | FILE *spopen(const char *cmdstring) { |
| 88 | spopen (const char *cmdstring) | 86 | #ifdef RLIMIT_CORE |
| 89 | { | ||
| 90 | char *env[2]; | ||
| 91 | char *cmd = NULL; | ||
| 92 | char **argv = NULL; | ||
| 93 | char *str, *tmp; | ||
| 94 | int argc; | ||
| 95 | |||
| 96 | int i = 0, pfd[2], pfderr[2]; | ||
| 97 | pid_t pid; | ||
| 98 | |||
| 99 | #ifdef RLIMIT_CORE | ||
| 100 | /* do not leave core files */ | 87 | /* do not leave core files */ |
| 101 | struct rlimit limit; | 88 | struct rlimit limit; |
| 102 | getrlimit (RLIMIT_CORE, &limit); | 89 | getrlimit(RLIMIT_CORE, &limit); |
| 103 | limit.rlim_cur = 0; | 90 | limit.rlim_cur = 0; |
| 104 | setrlimit (RLIMIT_CORE, &limit); | 91 | setrlimit(RLIMIT_CORE, &limit); |
| 105 | #endif | 92 | #endif |
| 106 | 93 | ||
| 94 | char *env[2]; | ||
| 107 | env[0] = strdup("LC_ALL=C"); | 95 | env[0] = strdup("LC_ALL=C"); |
| 108 | env[1] = NULL; | 96 | env[1] = NULL; |
| 109 | 97 | ||
| 110 | /* if no command was passed, return with no error */ | 98 | /* if no command was passed, return with no error */ |
| 111 | if (cmdstring == NULL) | 99 | if (cmdstring == NULL) { |
| 112 | return (NULL); | 100 | return (NULL); |
| 101 | } | ||
| 113 | 102 | ||
| 103 | char *cmd = NULL; | ||
| 114 | /* make copy of command string so strtok() doesn't silently modify it */ | 104 | /* make copy of command string so strtok() doesn't silently modify it */ |
| 115 | /* (the calling program may want to access it later) */ | 105 | /* (the calling program may want to access it later) */ |
| 116 | cmd = malloc (strlen (cmdstring) + 1); | 106 | cmd = malloc(strlen(cmdstring) + 1); |
| 117 | if (cmd == NULL) | 107 | if (cmd == NULL) { |
| 118 | return NULL; | 108 | return NULL; |
| 119 | strcpy (cmd, cmdstring); | 109 | } |
| 110 | strcpy(cmd, cmdstring); | ||
| 120 | 111 | ||
| 121 | /* This is not a shell, so we don't handle "???" */ | 112 | /* This is not a shell, so we don't handle "???" */ |
| 122 | if (strstr (cmdstring, "\"")) | 113 | if (strstr(cmdstring, "\"")) { |
| 123 | return NULL; | 114 | return NULL; |
| 115 | } | ||
| 124 | 116 | ||
| 125 | /* allow single quotes, but only if non-whitesapce doesn't occur on both sides */ | 117 | /* allow single quotes, but only if non-whitesapce doesn't occur on both sides */ |
| 126 | if (strstr (cmdstring, " ' ") || strstr (cmdstring, "'''")) | 118 | if (strstr(cmdstring, " ' ") || strstr(cmdstring, "'''")) { |
| 127 | return NULL; | 119 | return NULL; |
| 120 | } | ||
| 128 | 121 | ||
| 122 | int argc; | ||
| 123 | char **argv = NULL; | ||
| 129 | /* there cannot be more args than characters */ | 124 | /* there cannot be more args than characters */ |
| 130 | argc = strlen (cmdstring) + 1; /* add 1 for NULL termination */ | 125 | argc = strlen(cmdstring) + 1; /* add 1 for NULL termination */ |
| 131 | argv = malloc (sizeof(char*)*argc); | 126 | argv = malloc(sizeof(char *) * argc); |
| 132 | 127 | ||
| 133 | if (argv == NULL) { | 128 | if (argv == NULL) { |
| 134 | printf ("%s\n", _("Could not malloc argv array in popen()")); | 129 | printf("%s\n", _("Could not malloc argv array in popen()")); |
| 135 | return NULL; | 130 | return NULL; |
| 136 | } | 131 | } |
| 137 | 132 | ||
| 133 | int i = 0; | ||
| 134 | char *str; | ||
| 138 | /* loop to get arguments to command */ | 135 | /* loop to get arguments to command */ |
| 139 | while (cmd) { | 136 | while (cmd) { |
| 140 | str = cmd; | 137 | str = cmd; |
| 141 | str += strspn (str, " \t\r\n"); /* trim any leading whitespace */ | 138 | str += strspn(str, " \t\r\n"); /* trim any leading whitespace */ |
| 142 | 139 | ||
| 143 | if (i >= argc - 2) { | 140 | if (i >= argc - 2) { |
| 144 | printf ("%s\n",_("CRITICAL - You need more args!!!")); | 141 | printf("%s\n", _("CRITICAL - You need more args!!!")); |
| 145 | return (NULL); | 142 | return (NULL); |
| 146 | } | 143 | } |
| 147 | 144 | ||
| 148 | if (strstr (str, "'") == str) { /* handle SIMPLE quoted strings */ | 145 | if (strstr(str, "'") == str) { /* handle SIMPLE quoted strings */ |
| 149 | str++; | 146 | str++; |
| 150 | if (!strstr (str, "'")) | 147 | if (!strstr(str, "'")) { |
| 151 | return NULL; /* balanced? */ | 148 | return NULL; /* balanced? */ |
| 152 | cmd = 1 + strstr (str, "'"); | 149 | } |
| 153 | str[strcspn (str, "'")] = 0; | 150 | cmd = 1 + strstr(str, "'"); |
| 154 | } | 151 | str[strcspn(str, "'")] = 0; |
| 155 | else if (strcspn(str,"'") < strcspn (str, " \t\r\n")) { | 152 | } else if (strcspn(str, "'") < strcspn(str, " \t\r\n")) { |
| 156 | /* handle --option='foo bar' strings */ | 153 | /* handle --option='foo bar' strings */ |
| 157 | tmp = str + strcspn(str, "'") + 1; | 154 | char *tmp = str + strcspn(str, "'") + 1; |
| 158 | if (!strstr (tmp, "'")) | 155 | if (!strstr(tmp, "'")) { |
| 159 | return NULL; /* balanced? */ | 156 | return NULL; /* balanced? */ |
| 160 | tmp += strcspn(tmp,"'") + 1; | 157 | } |
| 158 | tmp += strcspn(tmp, "'") + 1; | ||
| 161 | *tmp = 0; | 159 | *tmp = 0; |
| 162 | cmd = tmp + 1; | 160 | cmd = tmp + 1; |
| 163 | } else { | 161 | } else { |
| 164 | if (strpbrk (str, " \t\r\n")) { | 162 | if (strpbrk(str, " \t\r\n")) { |
| 165 | cmd = 1 + strpbrk (str, " \t\r\n"); | 163 | cmd = 1 + strpbrk(str, " \t\r\n"); |
| 166 | str[strcspn (str, " \t\r\n")] = 0; | 164 | str[strcspn(str, " \t\r\n")] = 0; |
| 167 | } | 165 | } else { |
| 168 | else { | ||
| 169 | cmd = NULL; | 166 | cmd = NULL; |
| 170 | } | 167 | } |
| 171 | } | 168 | } |
| 172 | 169 | ||
| 173 | if (cmd && strlen (cmd) == strspn (cmd, " \t\r\n")) | 170 | if (cmd && strlen(cmd) == strspn(cmd, " \t\r\n")) { |
| 174 | cmd = NULL; | 171 | cmd = NULL; |
| 172 | } | ||
| 175 | 173 | ||
| 176 | argv[i++] = str; | 174 | argv[i++] = str; |
| 177 | |||
| 178 | } | 175 | } |
| 179 | argv[i] = NULL; | 176 | argv[i] = NULL; |
| 180 | 177 | ||
| 181 | long maxfd = mp_open_max(); | 178 | long maxfd = mp_open_max(); |
| 182 | 179 | ||
| 183 | if (childpid == NULL) { /* first time through */ | 180 | if (childpid == NULL) { /* first time through */ |
| 184 | if ((childpid = calloc ((size_t)maxfd, sizeof (pid_t))) == NULL) | 181 | if ((childpid = calloc((size_t)maxfd, sizeof(pid_t))) == NULL) { |
| 185 | return (NULL); | 182 | return (NULL); |
| 183 | } | ||
| 186 | } | 184 | } |
| 187 | 185 | ||
| 188 | if (child_stderr_array == NULL) { /* first time through */ | 186 | if (child_stderr_array == NULL) { /* first time through */ |
| 189 | if ((child_stderr_array = calloc ((size_t)maxfd, sizeof (int))) == NULL) | 187 | if ((child_stderr_array = calloc((size_t)maxfd, sizeof(int))) == NULL) { |
| 190 | return (NULL); | 188 | return (NULL); |
| 189 | } | ||
| 191 | } | 190 | } |
| 192 | 191 | ||
| 193 | if (pipe (pfd) < 0) | 192 | int pfd[2]; |
| 194 | return (NULL); /* errno set by pipe() */ | 193 | if (pipe(pfd) < 0) { |
| 194 | return (NULL); /* errno set by pipe() */ | ||
| 195 | } | ||
| 195 | 196 | ||
| 196 | if (pipe (pfderr) < 0) | 197 | int pfderr[2]; |
| 197 | return (NULL); /* errno set by pipe() */ | 198 | if (pipe(pfderr) < 0) { |
| 199 | return (NULL); /* errno set by pipe() */ | ||
| 200 | } | ||
| 198 | 201 | ||
| 199 | #ifdef REDHAT_SPOPEN_ERROR | 202 | #ifdef REDHAT_SPOPEN_ERROR |
| 200 | if (signal (SIGCHLD, popen_sigchld_handler) == SIG_ERR) { | 203 | if (signal(SIGCHLD, popen_sigchld_handler) == SIG_ERR) { |
| 201 | usage4 (_("Cannot catch SIGCHLD")); | 204 | usage4(_("Cannot catch SIGCHLD")); |
| 202 | } | 205 | } |
| 203 | #endif | 206 | #endif |
| 204 | 207 | ||
| 205 | if ((pid = fork ()) < 0) | 208 | pid_t pid; |
| 206 | return (NULL); /* errno set by fork() */ | 209 | if ((pid = fork()) < 0) { |
| 207 | else if (pid == 0) { /* child */ | 210 | return (NULL); /* errno set by fork() */ |
| 208 | close (pfd[0]); | 211 | } |
| 212 | |||
| 213 | if (pid == 0) { /* child */ | ||
| 214 | close(pfd[0]); | ||
| 209 | if (pfd[1] != STDOUT_FILENO) { | 215 | if (pfd[1] != STDOUT_FILENO) { |
| 210 | dup2 (pfd[1], STDOUT_FILENO); | 216 | dup2(pfd[1], STDOUT_FILENO); |
| 211 | close (pfd[1]); | 217 | close(pfd[1]); |
| 212 | } | 218 | } |
| 213 | close (pfderr[0]); | 219 | close(pfderr[0]); |
| 214 | if (pfderr[1] != STDERR_FILENO) { | 220 | if (pfderr[1] != STDERR_FILENO) { |
| 215 | dup2 (pfderr[1], STDERR_FILENO); | 221 | dup2(pfderr[1], STDERR_FILENO); |
| 216 | close (pfderr[1]); | 222 | close(pfderr[1]); |
| 217 | } | 223 | } |
| 218 | /* close all descriptors in childpid[] */ | 224 | /* close all descriptors in childpid[] */ |
| 219 | for (i = 0; i < maxfd; i++) | 225 | for (i = 0; i < maxfd; i++) { |
| 220 | if (childpid[i] > 0) | 226 | if (childpid[i] > 0) { |
| 221 | close (i); | 227 | close(i); |
| 228 | } | ||
| 229 | } | ||
| 222 | 230 | ||
| 223 | execve (argv[0], argv, env); | 231 | execve(argv[0], argv, env); |
| 224 | _exit (0); | 232 | _exit(0); |
| 225 | } | 233 | } |
| 226 | 234 | ||
| 227 | close (pfd[1]); /* parent */ | 235 | close(pfd[1]); /* parent */ |
| 228 | if ((child_process = fdopen (pfd[0], "r")) == NULL) | 236 | if ((child_process = fdopen(pfd[0], "r")) == NULL) { |
| 229 | return (NULL); | 237 | return (NULL); |
| 230 | close (pfderr[1]); | 238 | } |
| 239 | close(pfderr[1]); | ||
| 231 | 240 | ||
| 232 | childpid[fileno (child_process)] = pid; /* remember child pid for this fd */ | 241 | childpid[fileno(child_process)] = pid; /* remember child pid for this fd */ |
| 233 | child_stderr_array[fileno (child_process)] = pfderr[0]; /* remember STDERR */ | 242 | child_stderr_array[fileno(child_process)] = pfderr[0]; /* remember STDERR */ |
| 234 | return (child_process); | 243 | return (child_process); |
| 235 | } | 244 | } |
| 236 | 245 | ||
| 237 | int | 246 | int spclose(FILE *fp) { |
| 238 | spclose (FILE * fp) | 247 | if (childpid == NULL) { |
| 239 | { | 248 | return (1); /* popen() has never been called */ |
| 240 | int fd, status; | 249 | } |
| 241 | pid_t pid; | ||
| 242 | |||
| 243 | if (childpid == NULL) | ||
| 244 | return (1); /* popen() has never been called */ | ||
| 245 | 250 | ||
| 246 | fd = fileno (fp); | 251 | pid_t pid; |
| 247 | if ((pid = childpid[fd]) == 0) | 252 | int fd = fileno(fp); |
| 248 | return (1); /* fp wasn't opened by popen() */ | 253 | if ((pid = childpid[fd]) == 0) { |
| 254 | return (1); /* fp wasn't opened by popen() */ | ||
| 255 | } | ||
| 249 | 256 | ||
| 250 | childpid[fd] = 0; | 257 | childpid[fd] = 0; |
| 251 | if (fclose (fp) == EOF) | 258 | if (fclose(fp) == EOF) { |
| 252 | return (1); | 259 | return (1); |
| 260 | } | ||
| 253 | 261 | ||
| 254 | #ifdef REDHAT_SPOPEN_ERROR | 262 | #ifdef REDHAT_SPOPEN_ERROR |
| 255 | while (!childtermd); /* wait until SIGCHLD */ | 263 | while (!childtermd) |
| 264 | ; /* wait until SIGCHLD */ | ||
| 256 | #endif | 265 | #endif |
| 257 | 266 | ||
| 258 | while (waitpid (pid, &status, 0) < 0) | 267 | int status; |
| 259 | if (errno != EINTR) | 268 | while (waitpid(pid, &status, 0) < 0) { |
| 260 | return (1); /* error other than EINTR from waitpid() */ | 269 | if (errno != EINTR) { |
| 270 | return (1); /* error other than EINTR from waitpid() */ | ||
| 271 | } | ||
| 272 | } | ||
| 261 | 273 | ||
| 262 | if (WIFEXITED (status)) | 274 | if (WIFEXITED(status)) { |
| 263 | return (WEXITSTATUS (status)); /* return child's termination status */ | 275 | return (WEXITSTATUS(status)); /* return child's termination status */ |
| 276 | } | ||
| 264 | 277 | ||
| 265 | return (1); | 278 | return (1); |
| 266 | } | 279 | } |
| 267 | 280 | ||
| 268 | #ifdef REDHAT_SPOPEN_ERROR | 281 | #ifdef REDHAT_SPOPEN_ERROR |
| 269 | void | 282 | void popen_sigchld_handler(int signo) { |
| 270 | popen_sigchld_handler (int signo) | 283 | if (signo == SIGCHLD) { |
| 271 | { | ||
| 272 | if (signo == SIGCHLD) | ||
| 273 | childtermd = 1; | 284 | childtermd = 1; |
| 285 | } | ||
| 274 | } | 286 | } |
| 275 | #endif | 287 | #endif |
| 276 | 288 | ||
| 277 | void | 289 | void popen_timeout_alarm_handler(int signo) { |
| 278 | popen_timeout_alarm_handler (int signo) | ||
| 279 | { | ||
| 280 | int fh; | ||
| 281 | if (signo == SIGALRM) { | 290 | if (signo == SIGALRM) { |
| 282 | if (child_process != NULL) { | 291 | if (child_process != NULL) { |
| 283 | fh=fileno (child_process); | 292 | int fh = fileno(child_process); |
| 284 | if(fh >= 0){ | 293 | if (fh >= 0) { |
| 285 | kill (childpid[fh], SIGKILL); | 294 | kill(childpid[fh], SIGKILL); |
| 286 | } | 295 | } |
| 287 | printf (_("CRITICAL - Plugin timed out after %d seconds\n"), | 296 | printf(_("CRITICAL - Plugin timed out after %d seconds\n"), timeout_interval); |
| 288 | timeout_interval); | ||
| 289 | } else { | 297 | } else { |
| 290 | printf ("%s\n", _("CRITICAL - popen timeout received, but no child process")); | 298 | printf("%s\n", _("CRITICAL - popen timeout received, but no child process")); |
| 291 | } | 299 | } |
| 292 | exit (STATE_CRITICAL); | 300 | exit(STATE_CRITICAL); |
| 293 | } | 301 | } |
| 294 | } | 302 | } |
