summaryrefslogtreecommitdiffstats
path: root/plugins/popen.c
diff options
context:
space:
mode:
Diffstat (limited to 'plugins/popen.c')
-rw-r--r--plugins/popen.c322
1 files changed, 165 insertions, 157 deletions
diff --git a/plugins/popen.c b/plugins/popen.c
index 54e63bc5..c596d1e0 100644
--- a/plugins/popen.c
+++ b/plugins/popen.c
@@ -1,294 +1,302 @@
1/***************************************************************************** 1/*****************************************************************************
2* 2 *
3* Monitoring Plugins popen 3 * Monitoring Plugins popen
4* 4 *
5* License: GPL 5 * License: GPL
6* Copyright (c) 2005-2007 Monitoring Plugins Development Team 6 * Copyright (c) 2005-2024 Monitoring Plugins Development Team
7* 7 *
8* Description: 8 * Description:
9* 9 *
10* A safe alternative to popen 10 * A safe alternative to popen
11* 11 *
12* Provides spopen and spclose 12 * Provides spopen and spclose
13* 13 *
14* FILE * spopen(const char *); 14 * FILE * spopen(const char *);
15* int spclose(FILE *); 15 * int spclose(FILE *);
16* 16 *
17* Code taken with little modification from "Advanced Programming for the Unix 17 * Code taken with little modification from "Advanced Programming for the Unix
18* Environment" by W. Richard Stevens 18 * Environment" by W. Richard Stevens
19* 19 *
20* This is considered safe in that no shell is spawned, and the environment 20 * This is considered safe in that no shell is spawned, and the environment
21* and path passed to the exec'd program are essentially empty. (popen create 21 * and path passed to the exec'd program are essentially empty. (popen create
22* a shell and passes the environment to it). 22 * a shell and passes the environment to it).
23* 23 *
24* 24 *
25* This program is free software: you can redistribute it and/or modify 25 * This program is free software: you can redistribute it and/or modify
26* it under the terms of the GNU General Public License as published by 26 * it under the terms of the GNU General Public License as published by
27* the Free Software Foundation, either version 3 of the License, or 27 * the Free Software Foundation, either version 3 of the License, or
28* (at your option) any later version. 28 * (at your option) any later version.
29* 29 *
30* This program is distributed in the hope that it will be useful, 30 * This program is distributed in the hope that it will be useful,
31* but WITHOUT ANY WARRANTY; without even the implied warranty of 31 * but WITHOUT ANY WARRANTY; without even the implied warranty of
32* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 32 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
33* GNU General Public License for more details. 33 * GNU General Public License for more details.
34* 34 *
35* You should have received a copy of the GNU General Public License 35 * You should have received a copy of the GNU General Public License
36* along with this program. If not, see <http://www.gnu.org/licenses/>. 36 * along with this program. If not, see <http://www.gnu.org/licenses/>.
37* 37 *
38* 38 *
39*****************************************************************************/ 39 *****************************************************************************/
40 40
41#include "./common.h" 41#include "./common.h"
42#include "./utils.h" 42#include "./utils.h"
43#include "../lib/maxfd.h"
44 43
45/* extern so plugin has pid to kill exec'd process on timeouts */ 44/* extern so plugin has pid to kill exec'd process on timeouts */
46extern pid_t *childpid; 45extern pid_t *childpid;
47extern int *child_stderr_array; 46extern int *child_stderr_array;
48extern FILE *child_process; 47extern FILE *child_process;
49 48
50FILE *spopen (const char *); 49FILE *spopen(const char * /*cmdstring*/);
51int spclose (FILE *); 50int spclose(FILE * /*fp*/);
52#ifdef REDHAT_SPOPEN_ERROR 51#ifdef REDHAT_SPOPEN_ERROR
53void popen_sigchld_handler (int); 52void popen_sigchld_handler(int);
54#endif 53#endif
55void popen_timeout_alarm_handler (int); 54void popen_timeout_alarm_handler(int /*signo*/);
56 55
57#include <stdarg.h> /* ANSI C header file */ 56#include <stdarg.h> /* ANSI C header file */
58#include <fcntl.h> 57#include <fcntl.h>
59 58
60#include <limits.h> 59#include <limits.h>
61#include <sys/resource.h> 60#include <sys/resource.h>
62 61
63#ifdef HAVE_SYS_WAIT_H 62#ifdef HAVE_SYS_WAIT_H
64#include <sys/wait.h> 63# include <sys/wait.h>
65#endif 64#endif
66 65
67#ifndef WEXITSTATUS 66#ifndef WEXITSTATUS
68# define WEXITSTATUS(stat_val) ((unsigned)(stat_val) >> 8) 67# define WEXITSTATUS(stat_val) ((unsigned)(stat_val) >> 8)
69#endif 68#endif
70 69
71#ifndef WIFEXITED 70#ifndef WIFEXITED
72# define WIFEXITED(stat_val) (((stat_val) & 255) == 0) 71# define WIFEXITED(stat_val) (((stat_val) & 255) == 0)
73#endif 72#endif
74 73
75/* 4.3BSD Reno <signal.h> doesn't define SIG_ERR */ 74/* 4.3BSD Reno <signal.h> doesn't define SIG_ERR */
76#if defined(SIG_IGN) && !defined(SIG_ERR) 75#if defined(SIG_IGN) && !defined(SIG_ERR)
77#define SIG_ERR ((Sigfunc *)-1) 76# define SIG_ERR ((Sigfunc *)-1)
78#endif 77#endif
79 78
80 79char *pname = NULL; /* caller can set this from argv[0] */
81char *pname = NULL; /* caller can set this from argv[0] */
82 80
83#ifdef REDHAT_SPOPEN_ERROR 81#ifdef REDHAT_SPOPEN_ERROR
84static volatile int childtermd = 0; 82static volatile int childtermd = 0;
85#endif 83#endif
86 84
87FILE * 85FILE *spopen(const char *cmdstring) {
88spopen (const char *cmdstring) 86#ifdef RLIMIT_CORE
89{
90 char *env[2];
91 char *cmd = NULL;
92 char **argv = NULL;
93 char *str, *tmp;
94 int argc;
95
96 int i = 0, pfd[2], pfderr[2];
97 pid_t pid;
98
99#ifdef RLIMIT_CORE
100 /* do not leave core files */ 87 /* do not leave core files */
101 struct rlimit limit; 88 struct rlimit limit;
102 getrlimit (RLIMIT_CORE, &limit); 89 getrlimit(RLIMIT_CORE, &limit);
103 limit.rlim_cur = 0; 90 limit.rlim_cur = 0;
104 setrlimit (RLIMIT_CORE, &limit); 91 setrlimit(RLIMIT_CORE, &limit);
105#endif 92#endif
106 93
94 char *env[2];
107 env[0] = strdup("LC_ALL=C"); 95 env[0] = strdup("LC_ALL=C");
108 env[1] = NULL; 96 env[1] = NULL;
109 97
110 /* if no command was passed, return with no error */ 98 /* if no command was passed, return with no error */
111 if (cmdstring == NULL) 99 if (cmdstring == NULL) {
112 return (NULL); 100 return (NULL);
101 }
113 102
103 char *cmd = NULL;
114 /* make copy of command string so strtok() doesn't silently modify it */ 104 /* make copy of command string so strtok() doesn't silently modify it */
115 /* (the calling program may want to access it later) */ 105 /* (the calling program may want to access it later) */
116 cmd = malloc (strlen (cmdstring) + 1); 106 cmd = malloc(strlen(cmdstring) + 1);
117 if (cmd == NULL) 107 if (cmd == NULL) {
118 return NULL; 108 return NULL;
119 strcpy (cmd, cmdstring); 109 }
110 strcpy(cmd, cmdstring);
120 111
121 /* This is not a shell, so we don't handle "???" */ 112 /* This is not a shell, so we don't handle "???" */
122 if (strstr (cmdstring, "\"")) 113 if (strstr(cmdstring, "\"")) {
123 return NULL; 114 return NULL;
115 }
124 116
125 /* allow single quotes, but only if non-whitesapce doesn't occur on both sides */ 117 /* allow single quotes, but only if non-whitesapce doesn't occur on both sides */
126 if (strstr (cmdstring, " ' ") || strstr (cmdstring, "'''")) 118 if (strstr(cmdstring, " ' ") || strstr(cmdstring, "'''")) {
127 return NULL; 119 return NULL;
120 }
128 121
122 int argc;
123 char **argv = NULL;
129 /* there cannot be more args than characters */ 124 /* there cannot be more args than characters */
130 argc = strlen (cmdstring) + 1; /* add 1 for NULL termination */ 125 argc = strlen(cmdstring) + 1; /* add 1 for NULL termination */
131 argv = malloc (sizeof(char*)*argc); 126 argv = malloc(sizeof(char *) * argc);
132 127
133 if (argv == NULL) { 128 if (argv == NULL) {
134 printf ("%s\n", _("Could not malloc argv array in popen()")); 129 printf("%s\n", _("Could not malloc argv array in popen()"));
135 return NULL; 130 return NULL;
136 } 131 }
137 132
133 int i = 0;
134 char *str;
138 /* loop to get arguments to command */ 135 /* loop to get arguments to command */
139 while (cmd) { 136 while (cmd) {
140 str = cmd; 137 str = cmd;
141 str += strspn (str, " \t\r\n"); /* trim any leading whitespace */ 138 str += strspn(str, " \t\r\n"); /* trim any leading whitespace */
142 139
143 if (i >= argc - 2) { 140 if (i >= argc - 2) {
144 printf ("%s\n",_("CRITICAL - You need more args!!!")); 141 printf("%s\n", _("CRITICAL - You need more args!!!"));
145 return (NULL); 142 return (NULL);
146 } 143 }
147 144
148 if (strstr (str, "'") == str) { /* handle SIMPLE quoted strings */ 145 if (strstr(str, "'") == str) { /* handle SIMPLE quoted strings */
149 str++; 146 str++;
150 if (!strstr (str, "'")) 147 if (!strstr(str, "'")) {
151 return NULL; /* balanced? */ 148 return NULL; /* balanced? */
152 cmd = 1 + strstr (str, "'"); 149 }
153 str[strcspn (str, "'")] = 0; 150 cmd = 1 + strstr(str, "'");
154 } 151 str[strcspn(str, "'")] = 0;
155 else if (strcspn(str,"'") < strcspn (str, " \t\r\n")) { 152 } else if (strcspn(str, "'") < strcspn(str, " \t\r\n")) {
156 /* handle --option='foo bar' strings */ 153 /* handle --option='foo bar' strings */
157 tmp = str + strcspn(str, "'") + 1; 154 char *tmp = str + strcspn(str, "'") + 1;
158 if (!strstr (tmp, "'")) 155 if (!strstr(tmp, "'")) {
159 return NULL; /* balanced? */ 156 return NULL; /* balanced? */
160 tmp += strcspn(tmp,"'") + 1; 157 }
158 tmp += strcspn(tmp, "'") + 1;
161 *tmp = 0; 159 *tmp = 0;
162 cmd = tmp + 1; 160 cmd = tmp + 1;
163 } else { 161 } else {
164 if (strpbrk (str, " \t\r\n")) { 162 if (strpbrk(str, " \t\r\n")) {
165 cmd = 1 + strpbrk (str, " \t\r\n"); 163 cmd = 1 + strpbrk(str, " \t\r\n");
166 str[strcspn (str, " \t\r\n")] = 0; 164 str[strcspn(str, " \t\r\n")] = 0;
167 } 165 } else {
168 else {
169 cmd = NULL; 166 cmd = NULL;
170 } 167 }
171 } 168 }
172 169
173 if (cmd && strlen (cmd) == strspn (cmd, " \t\r\n")) 170 if (cmd && strlen(cmd) == strspn(cmd, " \t\r\n")) {
174 cmd = NULL; 171 cmd = NULL;
172 }
175 173
176 argv[i++] = str; 174 argv[i++] = str;
177
178 } 175 }
179 argv[i] = NULL; 176 argv[i] = NULL;
180 177
181 long maxfd = mp_open_max(); 178 long maxfd = mp_open_max();
182 179
183 if (childpid == NULL) { /* first time through */ 180 if (childpid == NULL) { /* first time through */
184 if ((childpid = calloc ((size_t)maxfd, sizeof (pid_t))) == NULL) 181 if ((childpid = calloc((size_t)maxfd, sizeof(pid_t))) == NULL) {
185 return (NULL); 182 return (NULL);
183 }
186 } 184 }
187 185
188 if (child_stderr_array == NULL) { /* first time through */ 186 if (child_stderr_array == NULL) { /* first time through */
189 if ((child_stderr_array = calloc ((size_t)maxfd, sizeof (int))) == NULL) 187 if ((child_stderr_array = calloc((size_t)maxfd, sizeof(int))) == NULL) {
190 return (NULL); 188 return (NULL);
189 }
191 } 190 }
192 191
193 if (pipe (pfd) < 0) 192 int pfd[2];
194 return (NULL); /* errno set by pipe() */ 193 if (pipe(pfd) < 0) {
194 return (NULL); /* errno set by pipe() */
195 }
195 196
196 if (pipe (pfderr) < 0) 197 int pfderr[2];
197 return (NULL); /* errno set by pipe() */ 198 if (pipe(pfderr) < 0) {
199 return (NULL); /* errno set by pipe() */
200 }
198 201
199#ifdef REDHAT_SPOPEN_ERROR 202#ifdef REDHAT_SPOPEN_ERROR
200 if (signal (SIGCHLD, popen_sigchld_handler) == SIG_ERR) { 203 if (signal(SIGCHLD, popen_sigchld_handler) == SIG_ERR) {
201 usage4 (_("Cannot catch SIGCHLD")); 204 usage4(_("Cannot catch SIGCHLD"));
202 } 205 }
203#endif 206#endif
204 207
205 if ((pid = fork ()) < 0) 208 pid_t pid;
206 return (NULL); /* errno set by fork() */ 209 if ((pid = fork()) < 0) {
207 else if (pid == 0) { /* child */ 210 return (NULL); /* errno set by fork() */
208 close (pfd[0]); 211 }
212
213 if (pid == 0) { /* child */
214 close(pfd[0]);
209 if (pfd[1] != STDOUT_FILENO) { 215 if (pfd[1] != STDOUT_FILENO) {
210 dup2 (pfd[1], STDOUT_FILENO); 216 dup2(pfd[1], STDOUT_FILENO);
211 close (pfd[1]); 217 close(pfd[1]);
212 } 218 }
213 close (pfderr[0]); 219 close(pfderr[0]);
214 if (pfderr[1] != STDERR_FILENO) { 220 if (pfderr[1] != STDERR_FILENO) {
215 dup2 (pfderr[1], STDERR_FILENO); 221 dup2(pfderr[1], STDERR_FILENO);
216 close (pfderr[1]); 222 close(pfderr[1]);
217 } 223 }
218 /* close all descriptors in childpid[] */ 224 /* close all descriptors in childpid[] */
219 for (i = 0; i < maxfd; i++) 225 for (i = 0; i < maxfd; i++) {
220 if (childpid[i] > 0) 226 if (childpid[i] > 0) {
221 close (i); 227 close(i);
228 }
229 }
222 230
223 execve (argv[0], argv, env); 231 execve(argv[0], argv, env);
224 _exit (0); 232 _exit(0);
225 } 233 }
226 234
227 close (pfd[1]); /* parent */ 235 close(pfd[1]); /* parent */
228 if ((child_process = fdopen (pfd[0], "r")) == NULL) 236 if ((child_process = fdopen(pfd[0], "r")) == NULL) {
229 return (NULL); 237 return (NULL);
230 close (pfderr[1]); 238 }
239 close(pfderr[1]);
231 240
232 childpid[fileno (child_process)] = pid; /* remember child pid for this fd */ 241 childpid[fileno(child_process)] = pid; /* remember child pid for this fd */
233 child_stderr_array[fileno (child_process)] = pfderr[0]; /* remember STDERR */ 242 child_stderr_array[fileno(child_process)] = pfderr[0]; /* remember STDERR */
234 return (child_process); 243 return (child_process);
235} 244}
236 245
237int 246int spclose(FILE *fp) {
238spclose (FILE * fp) 247 if (childpid == NULL) {
239{ 248 return (1); /* popen() has never been called */
240 int fd, status; 249 }
241 pid_t pid;
242
243 if (childpid == NULL)
244 return (1); /* popen() has never been called */
245 250
246 fd = fileno (fp); 251 pid_t pid;
247 if ((pid = childpid[fd]) == 0) 252 int fd = fileno(fp);
248 return (1); /* fp wasn't opened by popen() */ 253 if ((pid = childpid[fd]) == 0) {
254 return (1); /* fp wasn't opened by popen() */
255 }
249 256
250 childpid[fd] = 0; 257 childpid[fd] = 0;
251 if (fclose (fp) == EOF) 258 if (fclose(fp) == EOF) {
252 return (1); 259 return (1);
260 }
253 261
254#ifdef REDHAT_SPOPEN_ERROR 262#ifdef REDHAT_SPOPEN_ERROR
255 while (!childtermd); /* wait until SIGCHLD */ 263 while (!childtermd)
264 ; /* wait until SIGCHLD */
256#endif 265#endif
257 266
258 while (waitpid (pid, &status, 0) < 0) 267 int status;
259 if (errno != EINTR) 268 while (waitpid(pid, &status, 0) < 0) {
260 return (1); /* error other than EINTR from waitpid() */ 269 if (errno != EINTR) {
270 return (1); /* error other than EINTR from waitpid() */
271 }
272 }
261 273
262 if (WIFEXITED (status)) 274 if (WIFEXITED(status)) {
263 return (WEXITSTATUS (status)); /* return child's termination status */ 275 return (WEXITSTATUS(status)); /* return child's termination status */
276 }
264 277
265 return (1); 278 return (1);
266} 279}
267 280
268#ifdef REDHAT_SPOPEN_ERROR 281#ifdef REDHAT_SPOPEN_ERROR
269void 282void popen_sigchld_handler(int signo) {
270popen_sigchld_handler (int signo) 283 if (signo == SIGCHLD) {
271{
272 if (signo == SIGCHLD)
273 childtermd = 1; 284 childtermd = 1;
285 }
274} 286}
275#endif 287#endif
276 288
277void 289void popen_timeout_alarm_handler(int signo) {
278popen_timeout_alarm_handler (int signo)
279{
280 int fh;
281 if (signo == SIGALRM) { 290 if (signo == SIGALRM) {
282 if (child_process != NULL) { 291 if (child_process != NULL) {
283 fh=fileno (child_process); 292 int fh = fileno(child_process);
284 if(fh >= 0){ 293 if (fh >= 0) {
285 kill (childpid[fh], SIGKILL); 294 kill(childpid[fh], SIGKILL);
286 } 295 }
287 printf (_("CRITICAL - Plugin timed out after %d seconds\n"), 296 printf(_("CRITICAL - Plugin timed out after %d seconds\n"), timeout_interval);
288 timeout_interval);
289 } else { 297 } else {
290 printf ("%s\n", _("CRITICAL - popen timeout received, but no child process")); 298 printf("%s\n", _("CRITICAL - popen timeout received, but no child process"));
291 } 299 }
292 exit (STATE_CRITICAL); 300 exit(STATE_CRITICAL);
293 } 301 }
294} 302}