diff --git a/README.TXT b/README.TXT index d11de7d..c2deaeb 100644 --- a/README.TXT +++ b/README.TXT @@ -2,7 +2,7 @@ Quality of service module for Apache Web Server. http://mod-qos.sourceforge.net/ - Copyright (C) 2023 Pascal Buchbinder + Copyright (C) 2025 Pascal Buchbinder Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE file distributed with diff --git a/apache2/mod_qos.c b/apache2/mod_qos.c index cef1cf9..7175e51 100644 --- a/apache2/mod_qos.c +++ b/apache2/mod_qos.c @@ -20,7 +20,7 @@ * See http://mod-qos.sourceforge.net/ for further * details and to obtain the latest version of this module. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -42,8 +42,8 @@ /************************************************************************ * Version ***********************************************************************/ -static const char revision[] = "$Id: mod_qos.c 2706 2023-05-16 19:52:59Z pbuchbinder $"; -static const char g_revision[] = "11.74"; +static const char revision[] = "$Id: mod_qos.c 2724 2025-01-03 15:05:21Z pbuchbinder $"; +static const char g_revision[] = "11.76"; /************************************************************************ * Includes @@ -1984,6 +1984,20 @@ static const char *qos_forwardedfor_fromSSL(request_rec *r) { return NULL; } +static const char *qos_forwardedfor_fromUserAgentIP(request_rec *r) { + const char *useragent_ip = NULL; +#if (AP_SERVER_MINORVERSION_NUMBER == 4) && (AP_SERVER_PATCHLEVEL_NUMBER > 18) + useragent_ip = r->useragent_ip; +#endif + if(QS_ISDEBUG(r->server)) { + ap_log_rerror(APLOG_MARK, APLOG_DEBUG, 0, r, + QOS_LOGD_PFX"fromUserAgentIP() USERAGENT_IP=%s, id=%s", + useragent_ip == NULL ? "null" : useragent_ip, + qos_unique_id(r, NULL)); + } + return useragent_ip; +} + static const char *qos_pseudoip(request_rec *r, const char *header) { const char *forwardedfor = NULL; if(strcmp("SSL_CLIENT_S_DN", header) == 0) { @@ -1998,13 +2012,14 @@ static const char *qos_pseudoip(request_rec *r, const char *header) { } static const char *qos_forwardedfor(request_rec *r, const char *header) { - const char *forwardedfor = NULL; if(header[0] == '#') { - forwardedfor = qos_pseudoip(r, &header[1]); + if(strcmp("USERAGENT_IP", &header[1]) == 0) { + return qos_forwardedfor_fromUserAgentIP(r); + } + return qos_pseudoip(r, &header[1]); } else { - forwardedfor = qos_forwardedfor_fromHeader(r, header); + return qos_forwardedfor_fromHeader(r, header); } - return forwardedfor; } /** @@ -3434,6 +3449,7 @@ static int qos_return_error_andclose(conn_rec *connection, apr_socket_t *socket) if(c->cs) { c->cs->state = CONN_STATE_LINGER; } + apr_table_setn(c->notes, "short-lingering-close", "1"); apr_table_set(c->notes, QS_CONN_ABORT, QS_CONN_ABORT); if (m_forced_close == 0) { return DECLINED; @@ -8704,6 +8720,7 @@ static int qos_pre_connection(conn_rec *connection, void *skt) { if(c->cs) { c->cs->state = CONN_STATE_LINGER; } + apr_table_setn(c->notes, "short-lingering-close", "1"); apr_table_set(c->notes, QS_CONN_ABORT, QS_CONN_ABORT); if (m_forced_close == 0) { ret = DECLINED; diff --git a/apache2/mod_qos.h b/apache2/mod_qos.h index 3372abe..4606439 100644 --- a/apache2/mod_qos.h +++ b/apache2/mod_qos.h @@ -15,7 +15,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with diff --git a/doc/CHANGES.txt b/doc/CHANGES.txt index 5fd53bc..9c83dab 100644 --- a/doc/CHANGES.txt +++ b/doc/CHANGES.txt @@ -1,12 +1,27 @@ +Version 11.76 + + - Setting connection note short-lingering-close when aborting connection (to + improve connection close behavior when using MPM event). + + - Removes outdated utilities from the distribution package: qsfilter2, + qspng, qsrotate, qssign, qstail, qshead, qsgrep, qsexec, qscheck, qslogger, + and qsdt. + +Version 11.75 + + - QS_ClientIpFromHeader supports other modules (e.g. mod_remoteip) setting + a client address to the request record when using the special header + name #USERAGENT_IP. + Version 11.74 -- Fixed: Potential counter overflow for early event detection - (increment before block) or log only mode. + - Fixed: Potential counter overflow for early event detection + (increment before block) or log only mode. Version 11.73 - This release introduces support of the PCRE2 (10.x) library in place of - the now end-of-life PCRE version 1 (8.x) API. + This release introduces support of the PCRE2 (10.x) library in place of + the now end-of-life PCRE version 1 (8.x) API. - Removes PCRE API dependency from mod_qos.c. The module no longer has an explicit dependency to the PCRE library but uses ap_pregcomp(), diff --git a/doc/MESSAGES.txt b/doc/MESSAGES.txt index 3afdb29..8385a5e 100644 --- a/doc/MESSAGES.txt +++ b/doc/MESSAGES.txt @@ -1,4 +1,4 @@ -mod_qos version 11.74 +mod_qos version 11.76 mod_qos(001): QS_ClientEventLimitCount directives can't be added/removed by graceful restart. A server restart is required to apply the new configuration! mod_qos(002): failed to create shared memory (ACT)(%s): %s (%lu bytes) mod_qos(002): failed to create shared memory (client control)(%s): %s (%d bytes) diff --git a/doc/glossary.html b/doc/glossary.html index 66ddc49..1c74fce 100644 --- a/doc/glossary.html +++ b/doc/glossary.html @@ -32,7 +32,7 @@ See http://mod-qos.sourceforge.net/ for further details. - Copyright (C) 2023 Pascal Buchbinder + Copyright (C) 2025 Pascal Buchbinder Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE file distributed with @@ -598,6 +598,6 @@ You can use the spreadsheet program of your choice to process the output:<br><br </table> <br> <hr> -<SMALL><SMALL>© 2023, Pascal Buchbinder</SMALL></SMALL> +<SMALL><SMALL>© 2024, Pascal Buchbinder</SMALL></SMALL> </body> </html> diff --git a/doc/headerfilterrules.txt b/doc/headerfilterrules.txt index 58d4d5c..deba4d0 100644 --- a/doc/headerfilterrules.txt +++ b/doc/headerfilterrules.txt @@ -94,4 +94,4 @@ QS_ResponseHeaderFilter rules: name=X-Frame-Options, action=drop, size=4000, pattern=^[\x20-\xFF]*$ name=X-XSS-Protection, action=drop, size=4000, pattern=^[\x20-\xFF]*$ -mod_qos 11.74 +mod_qos 11.76 diff --git a/doc/index.html b/doc/index.html index 839d364..71baeae 100644 --- a/doc/index.html +++ b/doc/index.html @@ -34,7 +34,7 @@ See http://mod-qos.sourceforge.net/ for further details. - Copyright (C) 2023 Pascal Buchbinder + Copyright (C) 2025 Pascal Buchbinder Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE file distributed with @@ -248,7 +248,7 @@ server's modules directory. <table border="0" cellspacing="5" cellpadding="10" width="100%"> <tr><td bgcolor="#E2EDE2"> <pre> -cd mod_qos-11.74/apache2 +cd mod_qos-11.76/apache2 apxs -i -c mod_qos.c -lcrypto -lpcre2-8 cd ../.. </pre> @@ -320,11 +320,11 @@ within the format string used by the <a href="#QSLog"><code>QSLog</code></a> dir The <a href="#utilities">support tools</a> may be built (at least on some Linux platforms) using the GNU autotools. Some of these utilities require third-party libraries such as apr, apr-util, PCRE2, -libpng, and OpenSSL. +and OpenSSL. <table border="0" cellspacing="5" cellpadding="10" width="100%"> <tr><td bgcolor="#E2EDE2"> <pre> -cd mod_qos-11.74/tools +cd mod_qos-11.76/tools ./configure make </pre> @@ -946,10 +946,6 @@ that has occurred during a request. <syntax>QS_Country</syntax><br> ISO 3166 country code of client IPv4 address. Only available if the <a href="#QS_ClientGeoCountryDB">geographical database</a> file has been loaded.<br> -<small><i>Note: You may use the <code>QS_ClientIpFromHeader <header></code> -directive to override the client's IP address based on the value within the defined -HTTP request header (e.g., X-Forwarded-For) instead of taking the IP address of -the client which has opened the TCP connection.</i></small> </li> <!--<li> <syntax>QS_RuleId</syntax><br> @@ -1431,8 +1427,6 @@ pattern are allowed. If a <code>QS_PermitUri</code> pattern has been defined and the request does not match any rule, the request is denied. All rules must define the same action. pcre is case sensitive. -You may use the <code><a href="qsfilter2.1.html">qsfilter2</a></code> -utility to generate rules based on access log files. </li> <li> <a name="QS_DenyInheritanceOff"></a> @@ -1567,10 +1561,7 @@ be deflated (compressed data) using <tr><td bgcolor="#E2EDE2"> Sample configuration:<br><a name="qsfiltersample"></a> <pre> -# configure the audit log writing the request body data to a file -# (use this log to generate allow list rules using <a href="qsfilter2.1.html">qsfilter2</a> -# when <a href="#QS_PermitUriBody">QS_PermitUriBody</a> has been enabled) -# format: +# optional audit log writing the request body data to a file, format: # %h: # The remote host (used to filter by IP address). # %>s: @@ -1578,7 +1569,7 @@ Sample configuration:<br><a name="qsfiltersample"></a> # %{qos-loc}n # The matching Location to generate the rules for. # %{qos-path}n%{qos-query}n -# The request data required by qsfilter2 to generate rules. +# The request data to define rules. CustomLog logs/qsaudit_log "%h %>s %{qos-loc}n %{qos-path}n%{qos-query}n" # enable json parser @@ -1862,7 +1853,7 @@ survives graceful server restart. The maximum value is 10'000'000. Defines the allowed number of <a href="glossary.html#concurrency">concurrent</a> requests coming from the same client source IP address having the <code><a href="#QS_EventRequest">QS_EventRequest</a></code> variable set.<br> -<small><i>Note: You may use the <code>QS_ClientIpFromHeader <header></code> +<small><i>Note: You may use the <a href="#QS_ClientIpFromHeader"><code>QS_ClientIpFromHeader</code></a> directive to override the client's IP address based on the value within the defined HTTP request header (e.g., X-Forwarded-For) instead of taking the IP address of the client which has opened the TCP connection.</i></small> @@ -1913,17 +1904,10 @@ this limitation are denied for the specified time (blocked at request level). <b <ul> <li>The value of the variable defines the penalty points by which the counters are increased. Default (empty or non-numeric value) is 1 (increment per request).</li> -<li><a name="QS_ClientIpFromHeader"></a> -You may use the <code>QS_ClientIpFromHeader <header></code> +<li>You may use the <a href="#QS_ClientIpFromHeader"><code>QS_ClientIpFromHeader</code></a> directive to determine the client's IP address based on the defined HTTP request header (e.g., X-Forwarded-For) instead of taking the IP address -of the client which has opened the TCP connection. The header must only -contain a single IP address.<br> -You might also use a pseudo IP address by creating a hash from the -header's value if you prefix the header name by a '#', -e.g. <code>#Authorization</code> to use the HTTP basic auth header. -as the pseudo IP address. The special name <code>#SSL_CLIENT_S_DN</code> -creates a pseudo IP from the SSL client certificate's subject and issuer DN. +of the client which has opened the TCP connection. </li> <li>The current value of this counter is stored within the variable suffixed by <code><a href="#_Counter">_Counter</a></code>, e.g. <code>QS_Limit_Counter</code> for further @@ -1953,7 +1937,7 @@ if you want to enforce a rule under certain conditions only.</li> variable set if they are coming from the same IP address.<br> <small><i>Notes: <ul> -<li>You may use the <code>QS_ClientIpFromHeader <header></code> directive to +<li>You may use the <a href="#QS_ClientIpFromHeader"><code>QS_ClientIpFromHeader</code></a> directive to override the client's IP address based on the value within the defined HTTP request header (e.g., X-Forwarded-For) instead of taking the IP address of the client which has opened the TCP connection. @@ -2037,7 +2021,7 @@ Double quoted ISO 3166 country code, e.g. "FR" for France. </ul> The <a href="#QS_Country"><code>QS_Country</code></a> variable contains the country code for the client's IP address. <br> -<small><i>Note: You may use the <code>QS_ClientIpFromHeader <header></code> directive to +<small><i>Note: You may use the <a href="#QS_ClientIpFromHeader"><code>QS_ClientIpFromHeader</code></a> directive to override the client's IP address based on the value within the defined HTTP request header (e.g., X-Forwarded-For) instead of taking the IP address of the client which has opened the TCP connection to evaluate this variable.</i></small> @@ -2053,6 +2037,30 @@ Uses the geographical database loaded by <br>Clients whose IP can't be mapped to a country code can be excluded from the limitation by configuring the 'excludeUnknown' argument. </li> +<li> +<a name="QS_ClientIpFromHeader"></a> +<syntax>QS_ClientIpFromHeader <header></syntax><br> +The <code>QS_ClientIpFromHeader <header></code> directive can be used +to determine the client's IP address based on the defined HTTP +request header (e.g., X-Forwarded-For) instead of taking the IP address +of the client which has opened the TCP connection. The header must only +contain a single IP address.<br> +It can used for the following directives: + <a href="#QS_ClientEventRequestLimit"><code>QS_ClientEventRequestLimit</code></a>, + <a href="#QS_ClientEventLimitCount"><code>QS_ClientEventLimitCount</code></a>, + <a href="#QS_ClientSerialize"><code>QS_ClientSerialize</code></a>, and + <a href="#QS_ClientGeoCountryDB"><code>QS_ClientGeoCountryDB</code></a>.<br> +Notes:<ul> +<li>You might also use a pseudo IP address by creating a hash from the +header's value if you prefix the header name by a '#', +e.g. <code>#Authorization</code> to use the HTTP basic auth header.</li> +<li>The special name <code>#SSL_CLIENT_S_DN</code> creates a pseudo +IP from the SSL client certificate's subject and issuer DN.</li> +<li>If the remote address information has been overridden by another module such as +<a href="https://httpd.apache.org/docs/current/mod/mod_remoteip.html#remoteipheader">mod_remoteip <img src="images/link.png"/></a>, +and you want to use this, use the special name <code>#USERAGENT_IP</code> (available with Apache 2.4.19 and newer).</li> +</ul> +</li> </ul> <table border="0" cellspacing="5" cellpadding="10" width="100%"> @@ -2408,51 +2416,20 @@ verify the status of the client. Example: <br/> <p> mod_qos provides optional tools for log data processing and analysis: <ul> -<a name="qsdt"></a> -<li><syntax><a href="qsdt.1.html">qsdt</a></syntax><br>Simple tool -to measure the elapse time between related log messages.</li> -<a name="qsexec"></a> -<li><syntax><a href="qsexec.1.html">qsexec</a></syntax><br>Command execution -triggered by patterns within log files.</li> -<a name="qsfilter2"></a> -<li><syntax><a href="qsfilter2.1.html">qsfilter2</a></syntax><br> -Rule generator. Creates <code><a href="#filter">QS_Permit*</a></code> directives and rule patterns -from audit log files.</li> <a name="qsgeo"></a> <li><syntax><a href="qsgeo.1.html">qsgeo</a></syntax><br>Adds the country code for the client IP address within a log file.</li> -<a name="qsgrep"></a> -<li><syntax><a href="qsgrep.1.html">qsgrep</a></syntax><br>Searches a file for a -pattern and prints the data in a new format.</li> <a name="qslog"></a> <li><syntax><a href="qslog.1.html">qslog</a></syntax><br>A real time <code><a href="http://httpd.apache.org/docs/current/mod/mod_log_config.html">TransferLog/CustomLog <img src="images/link.png"/></a></code> data analyzer. It reads the per request log data from stdin and generates statistic records every minute.</li> -<a name="qslogger"></a> -<li><syntax><a href="qslogger.1.html">qslogger</a></syntax><br>Shell command -interface to the syslog(3) system log module.</li> -<a name="qspng"></a> -<li><syntax><a href="qspng.1.html">qspng</a></syntax><br>Creates graphics (png -images) from the output of <code>qslog</code>.</li> <a name="qsre"></a> <li><syntax><a href="qsre.1.html">qsre</a></syntax><br>Regular expression (pcre) pattern match test tool.</li> <a name="qsrespeed"></a> <li><syntax><a href="qsrespeed.1.html">qsrespeed</a></syntax><br>Compares the expected processing time per regular expression.</li> -<a name="qsrotate"></a> -<li><syntax><a href="qsrotate.1.html">qsrotate</a></syntax><br>Log rotation tool -similar to Apache's <code>rotatelogs</code>.</li> -<a name="qssign"></a> -<li><syntax><a href="qssign.1.html">qssign</a></syntax><br>A log data integrity -check tool. It reads log data from stdin (pipe) and writes the signed data -to stdout adding a sequence number and signature to ever log line.<br> -<a href="https://sourceforge.net/p/mod-qos/source/HEAD/tree/trunk/tools/logstash-filter-qssign/lib/logstash/filters/qssign.rb?format=raw"><code>qssign.rb</code></a> is a <a href="http://www.logstash.net/">Logstash <img src="images/link.png"/></a> filter -plugin which may be used to verify the signatures of log messages in real time.</li> -<a name="qstail"></a> -<li><syntax><a href="qstail.1.html">qstail</a></syntax><br>Shows the end of a log -file beginning at a defined pattern.</li> </ul> </p> @@ -2746,6 +2723,6 @@ KeepAliveTimeout 2 </table> <br> <hr> -<small><small>© 2007-2023, Pascal Buchbinder - mod_qos version 11.74</small></small> +<small><small>© 2007-2025, Pascal Buchbinder - mod_qos version 11.76</small></small> </body> </html> diff --git a/doc/qsdt.1.html b/doc/qsdt.1.html deleted file mode 100644 index 3dbafad..0000000 --- a/doc/qsdt.1.html +++ /dev/null @@ -1,85 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSDT</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSDT</H1> -Section: qsdt man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qsdt calculates the elapsed time between two related log messages. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qsdt [-t <regex>] -i <regex> -s <regex> -e <regex> [-v] [<path>] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qsdt is a simple tool to search two different messages in a log file and calculates the elapsed time between these lines. The two log messages need a common identifier such an unique request id (UNIQUE_ID), a thread id, or a transaction code. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-t <regex> <DD> -Defines a pattern (regular expression) matching the log line's timestamp. The pattern must include two sub-expressions, one matching hours, minutes and seconds the other matching the milliseconds. Default pattern is ([0-9]{2}:[0-9]{2}:[0-9]{2})[.,]([0-9]{3}) -<DT>-i <regex> <DD> -Pattern (regular expression) matching the identifier which the two messages have in common. The sub-expression defines the part which needs to be extracted from the matching string. Note: You can also use the start (-s) and end (-e) pattern to define the sub-expression matching this identifier. -<DT>-s <regex> <DD> -Defines the pattern (regular expression or literal string) identifying the first (start) of the two messages. -<DT>-e <regex> <DD> -Defines the pattern (regular expression or literal string) identifying the second (end) of the two messages. -<DT>-v <DD> -Verbose mode. -<DT><path> <DD> -Defines the input file to process. qsdt reads from from standard input if this parameter is omitted. -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -Sample command line arguments: -<P> -<BR> -i ' ([a-z0-9]+) [A-Z]+ ' -s 'Received Request' -e 'Received Response' -<P> -<BR> matching those sample log messages: -<BR> 2018-03-12 16:34:08.653 threadid23 INFO Received Request -<BR> 2018-03-13 16:35:09.891 threadid23 DEBUG MessageHandler Received Response -<P> -<A NAME="lbAG"> </A> -<H2>NOTE</H2> - -The four patterns (t,i,s,e) are concatenated into two search patterns: -<BR> first (start): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[s ] -<BR> second (end): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[e ] -<P> -And the three sub-expression are used to extract the timestamp and the unique identifier that the start and end message have in common. This means that you could specify the sub-expression for the unique identifier in the start (-s) or end (-e) pattern alternatively, e.g. in case the identifier is at the end of the log line. -<A NAME="lbAH"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAI"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">NOTE</A><DD> -<DT><A HREF="#lbAH">SEE ALSO</A><DD> -<DT><A HREF="#lbAI">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qsexec.1.html b/doc/qsexec.1.html deleted file mode 100644 index d9d0490..0000000 --- a/doc/qsexec.1.html +++ /dev/null @@ -1,72 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSEXEC</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSEXEC</H1> -Section: qsexec man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qsexec - parses the data received via stdin and executes the defined command on a pattern match. -<P> -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qsexec -e <pattern> [-t <number>:<sec>] [-c <pattern> [<command string>]] [-p] [-u <user>] <command string> -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qsexec reads log lines from stdin and searches for the defined pattern. It executes the defined command string on pattern match. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-e <pattern> <DD> -Specifies the search pattern causing an event which shall trigger the command. -<DT>-t <number>:<sec> <DD> -Defines the number of pattern match within the the defined number of seconds in order to trigger the command execution. By default, every pattern match causes a command execution. -<DT>-c <pattern> [<command string>] <DD> -Pattern which clears the event counter. Executes optionally a command if an event command has been executed before. -<DT>-p <DD> -Writes data also to stdout (for piped logging). -<DT>-u <name> <DD> -Become another user, e.g. www-data. -<DT><command string> <DD> -Defines the event command string where $0-$9 are substituted by the submatches of the regular expression. -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -Executes the deny.sh script providing the IP address of the client causing a mod_qos(031) messages whenever the log message appears 10 times within at most one minute: -<BR> ErrorLog "|/usr/bin/qsexec -e \'mod_qos\(031\).*, c=([0-9a-zA-Z:.]*)\' -t 10:60 \'/usr/local/bin/deny.sh $1\'" -<P> -<A NAME="lbAG"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAH"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">SEE ALSO</A><DD> -<DT><A HREF="#lbAH">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qsfilter2.1.html b/doc/qsfilter2.1.html deleted file mode 100644 index dd4aa06..0000000 --- a/doc/qsfilter2.1.html +++ /dev/null @@ -1,127 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSFILTER2</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSFILTER2</H1> -Section: qsfilter2 man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qsfilter2 - an utility to generate mod_qos request line rules out from existing access/audit log data. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qsfilter2 -i <path> [-c <path>] [-d <num>] [-h] [-b <num>] [-p|-s|-m|-o] [-l <len>] [-n] [-e] [-u 'uni'] [-k <prefix>] [-t] [-f <path>] [-v 0|1|2] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2><p><img src="qsfilter2_process.gif" alt="overview"></p> - -mod_qos implements a request filter which validates each request line. The module supports both, negative and positive security model. The QS_Deny* directives are used to specify request line patterns which are not allowed to access the server (negative security model / deny list). These rules are used to restrict access to certain resources which should not be available to users or to protect the server from malicious patterns. The QS_Permit* rules implement a positive security model (allow list). These directives are used to define allowed request line patterns. Request which do not match any of these patterns are not allowed to access the server. -<P> -qsfilter2 is an audit log analyzer used to generate filter rules (perl compatible regular expressions) which may be used by mod_qos to deny access for suspect requests (QS_PermitUri rules). It parses existing audit log files in order to generate request patterns covering all allowed requests. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-i <path> <DD> -Input file containing request URIs. The URIs for this file have to be extracted from the servers access logs. Each line of the input file contains a request URI consisting of a path and and query. -<BR> Example: -<BR> /aaa/index.do -<BR> /aaa/edit?image=1.jpg -<BR> /aaa/image/1.jpg -<BR> /aaa/view?page=1 -<BR> /aaa/edit?document=1 -<P> -These access log data must include current request URIs but also request lines from previous rule generation steps. It must also include request lines which cover manually generated rules. You may use the 'qos-path' and 'qos-query' variables to create an audit log containing all request data (path and query/body data). Example: 'CustomLog audit_log %{qos-path}n%{qos-query}n'. See also <A HREF="http://mod-qos.sourceforge.net#qsfiltersample">http://mod-qos.sourceforge.net#qsfiltersample</A> about the module settings. -<DT>-c <path> <DD> -mod_qos configuration file defining QS_DenyRequestLine and QS_PermitUri directives. qsfilter2 generates rules from access log data automatically. Manually generated rules (QS_PermitUri) may be provided from this file. Note: each manual rule must be represented by a request URI in the input data (-i) in order to make sure not to be deleted by the rule optimisation algorithm. QS_Deny* rules from this file are used to filter request lines which should not be used for allow list rule generation. -<BR> Example: -<BR> # manually defined allow list rule: -<BR> QS_PermitUri +view deny "^[/a-zA-Z0-9]+/view\?(page=[0-9]+)?$" -<BR> # filter unwanted request line patterns: -<BR> QS_DenyRequestLine +printable deny ".*[\x00-\x19].*" -<P> -<P> -<DT>-d <num> <DD> -Depth (sub locations) of the path string which is defined as a literal string. Default is 1. -<DT>-h <DD> -Always use a string representing the handler name in the path even the url does not have a query. See also -d option. -<DT>-b <num> <DD> -Replaces url pattern by the regular expression when detecting a base64/hex encoded string. Detecting sensibility is defined by a numeric value. You should use values higher than 5 (default) or 0 to disable this function. -<DT>-p <DD> -Represents query by pcre only (no literal strings). -<DT>-s <DD> -Uses one single pcre for the whole query string. -<DT>-m <DD> -Uses one pcre for multiple query values (recommended mode). -<DT>-o <DD> -Does not care the order of query parameters. -<DT>-l <len> <DD> -Outsizes the query length by the defined length ({0,size+len}), default is 10. -<DT>-n <DD> -Disables redundant rules elimination. -<DT>-e <DD> -Exit on error. -<DT>-u 'uni' <DD> -Enables additional decoding methods. Use the same settings as you have used for the QS_Decoding directive. -<DT>-k <prefix> <DD> -Prefix used to generate rule identifiers (QSF by default). -<DT>-t <DD> -Calculates the maximal latency per request (worst case) using the generated rules. -<DT>-f <path> <DD> -Filters the input by the provided path (prefix) only processing matching lines. -<DT>-v <level> <DD> -Verbose mode. (0=silent, 1=rule source, 2=detailed). Default is 1. Don't use rules you haven't checked the request data used to generate it! Level 1 is highly recommended (as long as you don't have created the log data using your own web crawler). -</DL> -<A NAME="lbAF"> </A> -<H2>OUTPUT</H2> - -The output of qsfilter2 is written to stdout. The output contains the generated QS_PermitUri directives but also information about the source which has been used to generate these rules. It is very important to check the validity of each request line which has been used to calculate the QS_PermitUri rules. Each request line which has been used to generate a new rule is shown in the output prefixed by "ADD line <line number>:". These request lines should be stored and reused at any later rule generation (add them to the URI input file). The subsequent line shows the generated rule. At the end of data processing a list of all generated QS_PermitUri rules is shown. These directives may be used withn the configuration file used by mod_qos. -<A NAME="lbAG"> </A> -<H2>EXAMPLE</H2> - -<BR> qsfilter2 -i loc.txt -c httpd.conf -m -e -<BR> ... -<BR> # ADD line 1: /aaa/index.do -<BR> # 003 ^(/[a-zA-Z0-9\-_]+)+[/]?\.?[a-zA-Z]{0,4}$ -<BR> # ADD line 3: /aaa/view?page=1 -<BR> # --- ^[/a-zA-Z0-9]+/view\?(page=[0-9]+)?$ -<BR> # ADD line 4: /aaa/edit?document=1 -<BR> # 004 ^[/a-zA-Z]+/edit\?((document)(=[0-9]*)*[&]?)*$ -<BR> # ADD line 5: /aaa/edit?image=1.jpg -<BR> # 005 ^[/a-zA-Z]+/edit\?((image)(=[0-9\.a-zA-Z]*)*[&]?)*$ -<BR> ... -<BR> QS_PermitUri +QSF001 deny "^[/a-zA-Z]+/edit\?((document|image)(=[0-9\.a-zA-Z]*)*[&]?)*$" -<BR> QS_PermitUri +QSF002 deny "^[/a-zA-Z0-9]+/view\?(page=[0-9]+)?$" -<BR> QS_PermitUri +QSF003 deny "^(/[a-zA-Z0-9\-_]+)+[/]?\.?[a-zA-Z]{0,4}$" -<P> -<A NAME="lbAH"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAI"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">OUTPUT</A><DD> -<DT><A HREF="#lbAG">EXAMPLE</A><DD> -<DT><A HREF="#lbAH">SEE ALSO</A><DD> -<DT><A HREF="#lbAI">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qsgeo.1.html b/doc/qsgeo.1.html index 33487ab..7875a7d 100644 --- a/doc/qsgeo.1.html +++ b/doc/qsgeo.1.html @@ -5,7 +5,7 @@ <META name='author' content='Pascal Buchbinder' /> </HEAD><BODY> <H1>QSGEO</H1> -Section: qsgeo man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> +Section: qsgeo man page (1)<BR>Updated: January 2025<BR><A HREF="#index">Index</A> <A HREF="index.html#utilities">Return to Main Contents</A><HR> <P> @@ -53,7 +53,7 @@ Resolving a single IP address: <A NAME="lbAG"> </A> <H2>SEE ALSO</H2> -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) +<A HREF="qslog.1.html">qslog</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1) <A NAME="lbAH"> </A> <H2>AUTHOR</H2> diff --git a/doc/qsgrep.1.html b/doc/qsgrep.1.html deleted file mode 100644 index 6dd5552..0000000 --- a/doc/qsgrep.1.html +++ /dev/null @@ -1,67 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSGREP</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSGREP</H1> -Section: qsgrep man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qsgrep - prints matching patterns within a file. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qsgrep -e <pattern> -o <sub string> [<path>] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qsgrep is a simple tool to search patterns within files. It uses regular expressions to find patterns and prints the submatches within a pre-defined format string. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-e <pattern> <DD> -Specifies the search pattern. -<DT>-o <string> <DD> -Defines the output string where $0-$9 are substituted by the submatches of the regular expression. -<DT><path> <DD> -Defines the input file to process. qsgrep reads from from standard input if this parameter is omitted. -<P> -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -Shows the IP addresses of clients causing mod_qos(031) messages): -<P> -<BR> qsgrep -e 'mod_qos\(031\).*, c=([a-zA-Z0-9:.]*)' -o 'ip=$1' error_log -<P> -<A NAME="lbAG"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAH"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">SEE ALSO</A><DD> -<DT><A HREF="#lbAH">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qshead.1.html b/doc/qshead.1.html deleted file mode 100644 index 5ef66d0..0000000 --- a/doc/qshead.1.html +++ /dev/null @@ -1,54 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSHEAD</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSHEAD</H1> -Section: qshead man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qshead - an utility reading from stdin and printing all lines to stdout until reaching the defined pattern. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qshead -p <pattern> -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qshead reads lines from stdin and prints them to stdout until a line contains the specified pattern (literal string). -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-p <pattern> <DD> -Search pattern (literal string). -</DL> -<A NAME="lbAF"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1) <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAG"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">SEE ALSO</A><DD> -<DT><A HREF="#lbAG">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qslog.1.html b/doc/qslog.1.html index 349bf22..8a520e0 100644 --- a/doc/qslog.1.html +++ b/doc/qslog.1.html @@ -5,7 +5,7 @@ <META name='author' content='Pascal Buchbinder' /> </HEAD><BODY> <H1>QSLOG</H1> -Section: qslog man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> +Section: qslog man page (1)<BR>Updated: January 2025<BR><A HREF="#index">Index</A> <A HREF="index.html#utilities">Return to Main Contents</A><HR> <P> @@ -121,7 +121,7 @@ Post processing: <A NAME="lbAH"> </A> <H2>SEE ALSO</H2> -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) +<A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1) <A NAME="lbAI"> </A> <H2>AUTHOR</H2> diff --git a/doc/qslogger.1.html b/doc/qslogger.1.html deleted file mode 100644 index 81029e9..0000000 --- a/doc/qslogger.1.html +++ /dev/null @@ -1,75 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSLOGGER</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSLOGGER</H1> -Section: qslogger man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qslogger - another shell command interface to the system log module (syslog). -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qslogger [-t <tag>] [-f <facility>] [-l <level>] [-x <prefix>] [-r <expression>] [-d <level>] [-u <name>] [-p] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -Use this utility to forward log messages to the systems syslog facility, e.g., to forward the messages to a remote host. It reads data from stdin. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<P> -<DL COMPACT> -<DT>-t <tag> <DD> -Defines the tag name which shall be used to define the origin of the messages, e.g. 'httpd'. -<DT>-f <facility> <DD> -Defines the syslog facility. Default is 'daemon'. -<DT>-u <name> <DD> -Becomes another user, e.g. www-data. -<DT>-l <level> <DD> -Defines the minimal severity a message must have in order to be forwarded. Default is 'DEBUG' (forwarding everything). -<DT>-x <prefix> <DD> -Allows you to add a prefix (literal string) to every message. -<DT>-r <expression> <DD> -Specifies a regular expression which shall be used to determine the severity (syslog level) for each log line. The default pattern '^\[[0-9a-zA-Z :]+\] \[([a-z]+)\] ' can be used for Apache error log messages but you may configure your own pattern matching other log formats. Use brackets to define the pattern enclosing the severity string. Default level (if severity can't be determined) is defined by the option '-d' (see below). -<DT>-d <level> <DD> -The default severity if the specified pattern (-r) does not match and the message's severity can't be determined. Default is 'NOTICE'. -<DT>-p <DD> -Writes data also to stdout (for piped logging). -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -<BR> ErrorLog "|/usr/bin/qslogger -t apache -f local7" -<P> -<A NAME="lbAG"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAH"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">SEE ALSO</A><DD> -<DT><A HREF="#lbAH">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qspng.1.html b/doc/qspng.1.html deleted file mode 100644 index a27b74d..0000000 --- a/doc/qspng.1.html +++ /dev/null @@ -1,58 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSPNG</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSPNG</H1> -Section: qspng man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qspng - an utility to draw a png graph from <A HREF="qslog.1.html">qslog</A>(1) output data. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qspng -i <stat_log_file> -p <parameter> -o <out_file> [-10] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qspng is a tool to generate png (portable network graphics) raster images files from semicolon separated data generated by the qslog utility. It reads up to the first 1440 entries (24 hours) and prints a graph using the values defined by the 'parameter' name. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-i <stats_log_file> <DD> -Input file to read data from. -<DT>-p <parameter> <DD> -Parameter name, e.g. r/s or usr. -<DT>-o <out_file> <DD> -Output file name, e.g. stat.png. -</DL> -<A NAME="lbAF"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAG"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">SEE ALSO</A><DD> -<DT><A HREF="#lbAG">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qsre.1.html b/doc/qsre.1.html index 39753ba..41f58c3 100644 --- a/doc/qsre.1.html +++ b/doc/qsre.1.html @@ -5,7 +5,7 @@ <META name='author' content='Pascal Buchbinder' /> </HEAD><BODY> <H1>QSRE</H1> -Section: qsre man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> +Section: qsre man page (1)<BR>Updated: January 2025<BR><A HREF="#index">Index</A> <A HREF="index.html#utilities">Return to Main Contents</A><HR> <P> @@ -33,7 +33,7 @@ The second argument either defines a regular expression or a path to a file cont <A NAME="lbAF"> </A> <H2>SEE ALSO</H2> -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) +<A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1) <A NAME="lbAG"> </A> <H2>AUTHOR</H2> diff --git a/doc/qsrespeed.1.html b/doc/qsrespeed.1.html index 4a5b4d9..298bbe6 100644 --- a/doc/qsrespeed.1.html +++ b/doc/qsrespeed.1.html @@ -5,7 +5,7 @@ <META name='author' content='Pascal Buchbinder' /> </HEAD><BODY> <H1>QSRESPEED</H1> -Section: qsrespeed man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> +Section: qsrespeed man page (1)<BR>Updated: January 2025<BR><A HREF="#index">Index</A> <A HREF="index.html#utilities">Return to Main Contents</A><HR> <P> @@ -31,7 +31,7 @@ Defines the input file to process. The file consists a list of (separated by a n <A NAME="lbAF"> </A> <H2>SEE ALSO</H2> -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) +<A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qsre.1.html">qsre</A>(1) <A NAME="lbAG"> </A> <H2>AUTHOR</H2> diff --git a/doc/qsrotate.1.html b/doc/qsrotate.1.html deleted file mode 100644 index faa787a..0000000 --- a/doc/qsrotate.1.html +++ /dev/null @@ -1,86 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSROTATE</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSROTATE</H1> -Section: qsrotate man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qsrotate - a log rotation tool (similar to Apache's rotatelogs). -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qsrotate -o <file> [-s <sec> [-t <hours>]] [-b <bytes>] [-f] [-z] [-g <num>] [-u <name>] [-m <mask>] [-p] [-d] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qsrotate reads from stdin (piped log) and writes the data to the provided file rotating the file after the specified time. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-o <file> <DD> -Output log file to write the data to (use an absolute path). -<DT>-s <sec> <DD> -Rotation interval in seconds, default are 86400 seconds. -<DT>-t <hours> <DD> -Offset to UTC (enables also DST support), default is 0. -<DT>-b <bytes> <DD> -File size limitation (default/max. are 2147352576 bytes, min. are 1048576 bytes). -<DT>-f <DD> -Forced log rotation at the specified interval even no data is written. -<DT>-z <DD> -Compress (gzip) the rotated file. -<DT>-g <num> <DD> -Generations (number of files to keep). -<DT>-u <name> <DD> -Become another user, e.g. www-data. -m <mask> -File permission which is either 600, 640, 660 (default) or 664. -<DT>-p <DD> -Writes data also to stdout (for piped logging). -d -Line-by-line data reading prefixing every line with a timestamp. -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -<BR> TransferLog "|/usr/bin/qsrotate -f -z -g 3 -o /var/log/apache/access.log -s 86400" -<P> -The name of the rotated file will be /dest/filee.YYYYmmddHHMMSS where YYYYmmddHHMMSS is the system time at which the data has been rotated. -<A NAME="lbAG"> </A> -<H2>NOTE</H2> - -<BR> - Each qsrotate instance must use an individual file. -<BR> - You may trigger a file rotation manually by sending the signal USR1 -to the process. -<A NAME="lbAH"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qssign.1.html">qssign</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAI"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">NOTE</A><DD> -<DT><A HREF="#lbAH">SEE ALSO</A><DD> -<DT><A HREF="#lbAI">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qssign.1.html b/doc/qssign.1.html deleted file mode 100644 index 8c434ff..0000000 --- a/doc/qssign.1.html +++ /dev/null @@ -1,79 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSSIGN</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSSIGN</H1> -Section: qssign man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qssign - an utility to sign and verify the integrity of log data. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qssign -s|S <secret> [-e] [-v] [-u <name>] [-f <regex>] [-a 'sha1'|'sha256'] -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qssign is a log data integrity check tool. It reads log data from stdin (pipe) and writes the data to stdout adding a sequence number and signature to ever log line. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-s <secret> <DD> -Passphrase used to calculate signature. -<DT>-S <program> <DD> -Specifies a program which writes the passphrase to stdout. -<DT>-e <DD> -Writes start/end marker when starting/stopping data signing. -<DT>-v <DD> -Verification mode checking the integrity of signed data. -<DT>-u <name> <DD> -Becomes another user, e.g. www-data. -<DT>-f <regex> <DD> -Filter pattern (case sensitive regular expression) for messages which do not need to be signed. -<DT>-a 'sha1'|'sha256' <DD> -Specifies the algorithm to use. Default is sha1. -</DL> -<A NAME="lbAF"> </A> -<H2>EXAMPLE</H2> - -Sign: -<P> -<BR> TransferLog "|/usr/bin/qssign -s password -e |/usr/bin/qsrotate -o /var/log/apache/access.log" -<P> -<P> -Verify: -<P> -<BR> cat access.log | qssign -s password -v -<P> -<A NAME="lbAG"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qstail.1.html">qstail</A>(1) -<A NAME="lbAH"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">EXAMPLE</A><DD> -<DT><A HREF="#lbAG">SEE ALSO</A><DD> -<DT><A HREF="#lbAH">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/doc/qstail.1.html b/doc/qstail.1.html deleted file mode 100644 index cb2cbbf..0000000 --- a/doc/qstail.1.html +++ /dev/null @@ -1,56 +0,0 @@ - -<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> -<HTML><HEAD><TITLE>Man page of QSTAIL</TITLE> -<META name='KeyWords' content='Quality of Service, QoS, Apache Web Server, Web application security, WAF, Open Source Software, Security, Proxy'/> -<META name='author' content='Pascal Buchbinder' /> -</HEAD><BODY> -<H1>QSTAIL</H1> -Section: qstail man page (1)<BR>Updated: May 2023<BR><A HREF="#index">Index</A> -<A HREF="index.html#utilities">Return to Main Contents</A><HR> - -<P> -<A NAME="lbAB"> </A> -<H2>NAME</H2> - -qstail - an utility printing the end of a log file starting at the specified pattern. -<A NAME="lbAC"> </A> -<H2>SYNOPSIS</H2> - -qstail -i <path> -p <pattern> -<A NAME="lbAD"> </A> -<H2>DESCRIPTION</H2> - -qstail shows the end of a log file beginning with the line containing the specified pattern. This may be used to show all lines which has been written after a certain event (e.g., server restart) or time stamp. -<A NAME="lbAE"> </A> -<H2>OPTIONS</H2> - -<DL COMPACT> -<DT>-i <path> <DD> -Input file to read the data from. -<DT>-p <pattern> <DD> -Search pattern (literal string). -</DL> -<A NAME="lbAF"> </A> -<H2>SEE ALSO</H2> - -<A HREF="qsdt.1.html">qsdt</A>(1), <A HREF="qsexec.1.html">qsexec</A>(1), <A HREF="qsfilter2.1.html">qsfilter2</A>(1), <A HREF="qsgeo.1.html">qsgeo</A>(1), <A HREF="qsgrep.1.html">qsgrep</A>(1), <A HREF="qshead.1.html">qshead</A>(1), <A HREF="qslog.1.html">qslog</A>(1), <A HREF="qslogger.1.html">qslogger</A>(1), <A HREF="qspng.1.html">qspng</A>(1), <A HREF="qsre.1.html">qsre</A>(1), <A HREF="qsrespeed.1.html">qsrespeed</A>(1), <A HREF="qsrotate.1.html">qsrotate</A>(1), <A HREF="qssign.1.html">qssign</A>(1) -<A NAME="lbAG"> </A> -<H2>AUTHOR</H2> - -Pascal Buchbinder, <A HREF="http://mod-qos.sourceforge.net/">http://mod-qos.sourceforge.net/</A> -<P> - -<HR> -<A NAME="index"> </A><H2>Index</H2> -<DL> -<DT><A HREF="#lbAB">NAME</A><DD> -<DT><A HREF="#lbAC">SYNOPSIS</A><DD> -<DT><A HREF="#lbAD">DESCRIPTION</A><DD> -<DT><A HREF="#lbAE">OPTIONS</A><DD> -<DT><A HREF="#lbAF">SEE ALSO</A><DD> -<DT><A HREF="#lbAG">AUTHOR</A><DD> -</DL> -<HR> - -</BODY> -</HTML> diff --git a/tools/Makefile.in b/tools/Makefile.in index dc39b39..b0401ce 100644 --- a/tools/Makefile.in +++ b/tools/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.15 from Makefile.am. +# Makefile.in generated by automake 1.16.3 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2014 Free Software Foundation, Inc. +# Copyright (C) 1994-2020 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -132,9 +132,9 @@ am__recursive_targets = \ $(RECURSIVE_CLEAN_TARGETS) \ $(am__extra_recursive_targets) AM_RECURSIVE_TARGETS = $(am__recursive_targets:-recursive=) TAGS CTAGS \ - cscope distdir dist dist-all distcheck -am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) \ - $(LISP)config.h.in + cscope distdir distdir-am dist dist-all distcheck +am__tagged_files = $(HEADERS) $(SOURCES) $(TAGS_FILES) $(LISP) \ + config.h.in # Read a list of newline-separated strings from the standard input, # and print each of them once, without duplicates. Input order is # *not* preserved. @@ -195,6 +195,8 @@ am__relativize = \ DIST_ARCHIVES = $(distdir).tar.gz GZIP_ENV = --best DIST_TARGETS = dist-gzip +# Exists only to be overridden by the user if desired. +AM_DISTCHECK_DVI_TARGET = dvi distuninstallcheck_listfiles = find . -type f -print am__distuninstallcheck_listfiles = $(distuninstallcheck_listfiles) \ | sed 's|^\./|$(prefix)/|' | grep -v '$(infodir)/dir$$' @@ -314,8 +316,8 @@ Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status echo ' $(SHELL) ./config.status'; \ $(SHELL) ./config.status;; \ *) \ - echo ' cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__depfiles_maybe)'; \ - cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__depfiles_maybe);; \ + echo ' cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__maybe_remake_depfiles)'; \ + cd $(top_builddir) && $(SHELL) ./config.status $@ $(am__maybe_remake_depfiles);; \ esac; $(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES) @@ -448,7 +450,10 @@ distclean-tags: -rm -f TAGS ID GTAGS GRTAGS GSYMS GPATH tags -rm -f cscope.out cscope.in.out cscope.po.out cscope.files -distdir: $(DISTFILES) +distdir: $(BUILT_SOURCES) + $(MAKE) $(AM_MAKEFLAGS) distdir-am + +distdir-am: $(DISTFILES) $(am__remove_distdir) test -d "$(distdir)" || mkdir "$(distdir)" @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ @@ -513,7 +518,7 @@ distdir: $(DISTFILES) ! -type d ! -perm -444 -exec $(install_sh) -c -m a+r {} {} \; \ || chmod -R a+r "$(distdir)" dist-gzip: distdir - tardir=$(distdir) && $(am__tar) | GZIP=$(GZIP_ENV) gzip -c >$(distdir).tar.gz + tardir=$(distdir) && $(am__tar) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).tar.gz $(am__post_remove_distdir) dist-bzip2: distdir @@ -528,6 +533,10 @@ dist-xz: distdir tardir=$(distdir) && $(am__tar) | XZ_OPT=$${XZ_OPT--e} xz -c >$(distdir).tar.xz $(am__post_remove_distdir) +dist-zstd: distdir + tardir=$(distdir) && $(am__tar) | zstd -c $${ZSTD_CLEVEL-$${ZSTD_OPT--19}} >$(distdir).tar.zst + $(am__post_remove_distdir) + dist-tarZ: distdir @echo WARNING: "Support for distribution archives compressed with" \ "legacy program 'compress' is deprecated." >&2 @@ -539,7 +548,7 @@ dist-shar: distdir @echo WARNING: "Support for shar distribution archives is" \ "deprecated." >&2 @echo WARNING: "It will be removed altogether in Automake 2.0" >&2 - shar $(distdir) | GZIP=$(GZIP_ENV) gzip -c >$(distdir).shar.gz + shar $(distdir) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).shar.gz $(am__post_remove_distdir) dist-zip: distdir @@ -557,7 +566,7 @@ dist dist-all: distcheck: dist case '$(DIST_ARCHIVES)' in \ *.tar.gz*) \ - GZIP=$(GZIP_ENV) gzip -dc $(distdir).tar.gz | $(am__untar) ;;\ + eval GZIP= gzip $(GZIP_ENV) -dc $(distdir).tar.gz | $(am__untar) ;;\ *.tar.bz2*) \ bzip2 -dc $(distdir).tar.bz2 | $(am__untar) ;;\ *.tar.lz*) \ @@ -567,9 +576,11 @@ distcheck: dist *.tar.Z*) \ uncompress -c $(distdir).tar.Z | $(am__untar) ;;\ *.shar.gz*) \ - GZIP=$(GZIP_ENV) gzip -dc $(distdir).shar.gz | unshar ;;\ + eval GZIP= gzip $(GZIP_ENV) -dc $(distdir).shar.gz | unshar ;;\ *.zip*) \ unzip $(distdir).zip ;;\ + *.tar.zst*) \ + zstd -dc $(distdir).tar.zst | $(am__untar) ;;\ esac chmod -R a-w $(distdir) chmod u+w $(distdir) @@ -585,7 +596,7 @@ distcheck: dist $(DISTCHECK_CONFIGURE_FLAGS) \ --srcdir=../.. --prefix="$$dc_install_base" \ && $(MAKE) $(AM_MAKEFLAGS) \ - && $(MAKE) $(AM_MAKEFLAGS) dvi \ + && $(MAKE) $(AM_MAKEFLAGS) $(AM_DISTCHECK_DVI_TARGET) \ && $(MAKE) $(AM_MAKEFLAGS) check \ && $(MAKE) $(AM_MAKEFLAGS) install \ && $(MAKE) $(AM_MAKEFLAGS) installcheck \ @@ -746,7 +757,7 @@ uninstall-am: am--refresh check check-am clean clean-cscope clean-generic \ cscope cscopelist-am ctags ctags-am dist dist-all dist-bzip2 \ dist-gzip dist-lzip dist-shar dist-tarZ dist-xz dist-zip \ - distcheck distclean distclean-generic distclean-hdr \ + dist-zstd distcheck distclean distclean-generic distclean-hdr \ distclean-tags distcleancheck distdir distuninstallcheck dvi \ dvi-am html html-am info info-am install install-am \ install-data install-data-am install-dvi install-dvi-am \ diff --git a/tools/configure b/tools/configure index 1dd7bb3..c23be8e 100755 --- a/tools/configure +++ b/tools/configure @@ -1,6 +1,6 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.69 for mod_qos 9.0. +# Generated by GNU Autoconf 2.69 for mod_qos 11. # # Report bugs to <pbuchbinder@users.sourceforge.net>. # @@ -580,12 +580,12 @@ MAKEFLAGS= # Identity of this package. PACKAGE_NAME='mod_qos' PACKAGE_TARNAME='mod_qos' -PACKAGE_VERSION='9.0' -PACKAGE_STRING='mod_qos 9.0' +PACKAGE_VERSION='11' +PACKAGE_STRING='mod_qos 11' PACKAGE_BUGREPORT='pbuchbinder@users.sourceforge.net' PACKAGE_URL='' -ac_unique_file="src/qscheck.c" +ac_unique_file="src/qslog.c" # Factoring default headers for most tests. ac_includes_default="\ #include <stdio.h> @@ -636,7 +636,6 @@ am__nodep AMDEPBACKSLASH AMDEP_FALSE AMDEP_TRUE -am__quote am__include DEPDIR OBJEXT @@ -711,7 +710,8 @@ PACKAGE_VERSION PACKAGE_TARNAME PACKAGE_NAME PATH_SEPARATOR -SHELL' +SHELL +am__quote' ac_subst_files='' ac_user_opts=' enable_option_checking @@ -1285,7 +1285,7 @@ if test "$ac_init_help" = "long"; then # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -\`configure' configures mod_qos 9.0 to adapt to many kinds of systems. +\`configure' configures mod_qos 11 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1352,7 +1352,7 @@ fi if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of mod_qos 9.0:";; + short | recursive ) echo "Configuration of mod_qos 11:";; esac cat <<\_ACEOF @@ -1455,7 +1455,7 @@ fi test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -mod_qos configure 9.0 +mod_qos configure 11 generated by GNU Autoconf 2.69 Copyright (C) 2012 Free Software Foundation, Inc. @@ -1878,7 +1878,7 @@ cat >config.log <<_ACEOF This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by mod_qos $as_me 9.0, which was +It was created by mod_qos $as_me 11, which was generated by GNU Autoconf 2.69. Invocation command line was $ $0 $@ @@ -2227,7 +2227,7 @@ ac_compiler_gnu=$ac_cv_c_compiler_gnu -am__api_version='1.15' +am__api_version='1.16' ac_aux_dir= for ac_dir in "$srcdir" "$srcdir/.." "$srcdir/../.."; do @@ -2432,12 +2432,7 @@ program_transform_name=`$as_echo "$program_transform_name" | sed "$ac_script"` am_aux_dir=`cd "$ac_aux_dir" && pwd` if test x"${MISSING+set}" != xset; then - case $am_aux_dir in - *\ * | *\ *) - MISSING="\${SHELL} \"$am_aux_dir/missing\"" ;; - *) - MISSING="\${SHELL} $am_aux_dir/missing" ;; - esac + MISSING="\${SHELL} '$am_aux_dir/missing'" fi # Use eval to expand $SHELL if eval "$MISSING --is-lightweight"; then @@ -2742,7 +2737,7 @@ fi # Define the identity of the package. PACKAGE='mod_qos' - VERSION='9.0' + VERSION='11' cat >>confdefs.h <<_ACEOF @@ -2772,8 +2767,8 @@ MAKEINFO=${MAKEINFO-"${am_missing_run}makeinfo"} # For better backward compatibility. To be removed once Automake 1.9.x # dies out for good. For more background, see: -# <http://lists.gnu.org/archive/html/automake/2012-07/msg00001.html> -# <http://lists.gnu.org/archive/html/automake/2012-07/msg00014.html> +# <https://lists.gnu.org/archive/html/automake/2012-07/msg00001.html> +# <https://lists.gnu.org/archive/html/automake/2012-07/msg00014.html> mkdir_p='$(MKDIR_P)' # We need awk for the "check" target (and possibly the TAP driver). The @@ -2824,7 +2819,7 @@ END Aborting the configuration process, to ensure you take notice of the issue. You can download and install GNU coreutils to get an 'rm' implementation -that behaves properly: <http://www.gnu.org/software/coreutils/>. +that behaves properly: <https://www.gnu.org/software/coreutils/>. If you want to complete the configuration process using your problematic 'rm' anyway, export the environment variable ACCEPT_INFERIOR_RM_PROGRAM @@ -3690,45 +3685,45 @@ DEPDIR="${am__leading_dot}deps" ac_config_commands="$ac_config_commands depfiles" - -am_make=${MAKE-make} -cat > confinc << 'END' +{ $as_echo "$as_me:${as_lineno-$LINENO}: checking whether ${MAKE-make} supports the include directive" >&5 +$as_echo_n "checking whether ${MAKE-make} supports the include directive... " >&6; } +cat > confinc.mk << 'END' am__doit: - @echo this is the am__doit target + @echo this is the am__doit target >confinc.out .PHONY: am__doit END -# If we don't find an include directive, just comment out the code. -{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for style of include used by $am_make" >&5 -$as_echo_n "checking for style of include used by $am_make... " >&6; } am__include="#" am__quote= -_am_result=none -# First try GNU make style include. -echo "include confinc" > confmf -# Ignore all kinds of additional output from 'make'. -case `$am_make -s -f confmf 2> /dev/null` in #( -*the\ am__doit\ target*) - am__include=include - am__quote= - _am_result=GNU - ;; -esac -# Now try BSD make style include. -if test "$am__include" = "#"; then - echo '.include "confinc"' > confmf - case `$am_make -s -f confmf 2> /dev/null` in #( - *the\ am__doit\ target*) - am__include=.include - am__quote="\"" - _am_result=BSD +# BSD make does it like this. +echo '.include "confinc.mk" # ignored' > confmf.BSD +# Other make implementations (GNU, Solaris 10, AIX) do it like this. +echo 'include confinc.mk # ignored' > confmf.GNU +_am_result=no +for s in GNU BSD; do + { echo "$as_me:$LINENO: ${MAKE-make} -f confmf.$s && cat confinc.out" >&5 + (${MAKE-make} -f confmf.$s && cat confinc.out) >&5 2>&5 + ac_status=$? + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } + case $?:`cat confinc.out 2>/dev/null` in #( + '0:this is the am__doit target') : + case $s in #( + BSD) : + am__include='.include' am__quote='"' ;; #( + *) : + am__include='include' am__quote='' ;; +esac ;; #( + *) : ;; - esac -fi - - -{ $as_echo "$as_me:${as_lineno-$LINENO}: result: $_am_result" >&5 -$as_echo "$_am_result" >&6; } -rm -f confinc confmf +esac + if test "$am__include" != "#"; then + _am_result="yes ($s style)" + break + fi +done +rm -f confinc.* confmf.* +{ $as_echo "$as_me:${as_lineno-$LINENO}: result: ${_am_result}" >&5 +$as_echo "${_am_result}" >&6; } # Check whether --enable-dependency-tracking was given. if test "${enable_dependency_tracking+set}" = set; then : @@ -5258,7 +5253,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1 # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by mod_qos $as_me 9.0, which was +This file was extended by mod_qos $as_me 11, which was generated by GNU Autoconf 2.69. Invocation command line was CONFIG_FILES = $CONFIG_FILES @@ -5324,7 +5319,7 @@ _ACEOF cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_config="`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`" ac_cs_version="\\ -mod_qos config.status 9.0 +mod_qos config.status 11 configured by $0, generated by GNU Autoconf 2.69, with options \\"\$ac_cs_config\\" @@ -5443,7 +5438,7 @@ cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 # # INIT-COMMANDS # -AMDEP_TRUE="$AMDEP_TRUE" ac_aux_dir="$ac_aux_dir" +AMDEP_TRUE="$AMDEP_TRUE" MAKE="${MAKE-make}" _ACEOF @@ -6056,29 +6051,35 @@ $as_echo "$as_me: executing $ac_file commands" >&6;} # Older Autoconf quotes --file arguments for eval, but not when files # are listed without --file. Let's play safe and only enable the eval # if we detect the quoting. - case $CONFIG_FILES in - *\'*) eval set x "$CONFIG_FILES" ;; - *) set x $CONFIG_FILES ;; - esac + # TODO: see whether this extra hack can be removed once we start + # requiring Autoconf 2.70 or later. + case $CONFIG_FILES in #( + *\'*) : + eval set x "$CONFIG_FILES" ;; #( + *) : + set x $CONFIG_FILES ;; #( + *) : + ;; +esac shift - for mf + # Used to flag and report bootstrapping failures. + am_rc=0 + for am_mf do # Strip MF so we end up with the name of the file. - mf=`echo "$mf" | sed -e 's/:.*$//'` - # Check whether this is an Automake generated Makefile or not. - # We used to match only the files named 'Makefile.in', but - # some people rename them; so instead we look at the file content. - # Grep'ing the first line is not enough: some people post-process - # each Makefile.in and add a new line on top of each file to say so. - # Grep'ing the whole file is not good either: AIX grep has a line + am_mf=`$as_echo "$am_mf" | sed -e 's/:.*$//'` + # Check whether this is an Automake generated Makefile which includes + # dependency-tracking related rules and includes. + # Grep'ing the whole file directly is not great: AIX grep has a line # limit of 2048, but all sed's we know have understand at least 4000. - if sed -n 's,^#.*generated by automake.*,X,p' "$mf" | grep X >/dev/null 2>&1; then - dirpart=`$as_dirname -- "$mf" || -$as_expr X"$mf" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$mf" : 'X\(//\)[^/]' \| \ - X"$mf" : 'X\(//\)$' \| \ - X"$mf" : 'X\(/\)' \| . 2>/dev/null || -$as_echo X"$mf" | + sed -n 's,^am--depfiles:.*,X,p' "$am_mf" | grep X >/dev/null 2>&1 \ + || continue + am_dirpart=`$as_dirname -- "$am_mf" || +$as_expr X"$am_mf" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ + X"$am_mf" : 'X\(//\)[^/]' \| \ + X"$am_mf" : 'X\(//\)$' \| \ + X"$am_mf" : 'X\(/\)' \| . 2>/dev/null || +$as_echo X"$am_mf" | sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ s//\1/ q @@ -6096,53 +6097,50 @@ $as_echo X"$mf" | q } s/.*/./; q'` - else - continue - fi - # Extract the definition of DEPDIR, am__include, and am__quote - # from the Makefile without running 'make'. - DEPDIR=`sed -n 's/^DEPDIR = //p' < "$mf"` - test -z "$DEPDIR" && continue - am__include=`sed -n 's/^am__include = //p' < "$mf"` - test -z "$am__include" && continue - am__quote=`sed -n 's/^am__quote = //p' < "$mf"` - # Find all dependency output files, they are included files with - # $(DEPDIR) in their names. We invoke sed twice because it is the - # simplest approach to changing $(DEPDIR) to its actual value in the - # expansion. - for file in `sed -n " - s/^$am__include $am__quote\(.*(DEPDIR).*\)$am__quote"'$/\1/p' <"$mf" | \ - sed -e 's/\$(DEPDIR)/'"$DEPDIR"'/g'`; do - # Make sure the directory exists. - test -f "$dirpart/$file" && continue - fdir=`$as_dirname -- "$file" || -$as_expr X"$file" : 'X\(.*[^/]\)//*[^/][^/]*/*$' \| \ - X"$file" : 'X\(//\)[^/]' \| \ - X"$file" : 'X\(//\)$' \| \ - X"$file" : 'X\(/\)' \| . 2>/dev/null || -$as_echo X"$file" | - sed '/^X\(.*[^/]\)\/\/*[^/][^/]*\/*$/{ + am_filepart=`$as_basename -- "$am_mf" || +$as_expr X/"$am_mf" : '.*/\([^/][^/]*\)/*$' \| \ + X"$am_mf" : 'X\(//\)$' \| \ + X"$am_mf" : 'X\(/\)' \| . 2>/dev/null || +$as_echo X/"$am_mf" | + sed '/^.*\/\([^/][^/]*\)\/*$/{ s//\1/ q } - /^X\(\/\/\)[^/].*/{ + /^X\/\(\/\/\)$/{ s//\1/ q } - /^X\(\/\/\)$/{ - s//\1/ - q - } - /^X\(\/\).*/{ + /^X\/\(\/\).*/{ s//\1/ q } s/.*/./; q'` - as_dir=$dirpart/$fdir; as_fn_mkdir_p - # echo "creating $dirpart/$file" - echo '# dummy' > "$dirpart/$file" - done + { echo "$as_me:$LINENO: cd "$am_dirpart" \ + && sed -e '/# am--include-marker/d' "$am_filepart" \ + | $MAKE -f - am--depfiles" >&5 + (cd "$am_dirpart" \ + && sed -e '/# am--include-marker/d' "$am_filepart" \ + | $MAKE -f - am--depfiles) >&5 2>&5 + ac_status=$? + echo "$as_me:$LINENO: \$? = $ac_status" >&5 + (exit $ac_status); } || am_rc=$? done + if test $am_rc -ne 0; then + { { $as_echo "$as_me:${as_lineno-$LINENO}: error: in \`$ac_pwd':" >&5 +$as_echo "$as_me: error: in \`$ac_pwd':" >&2;} +as_fn_error $? "Something went wrong bootstrapping makefile fragments + for automatic dependency tracking. If GNU make was not used, consider + re-running the configure script with MAKE=\"gmake\" (or whatever is + necessary). You can also try re-running configure with the + '--disable-dependency-tracking' option to at least be able to build + the package (albeit without support for automatic dependency tracking). +See \`config.log' for more details" "$LINENO" 5; } + fi + { am_dirpart=; unset am_dirpart;} + { am_filepart=; unset am_filepart;} + { am_mf=; unset am_mf;} + { am_rc=; unset am_rc;} + rm -f conftest-deps.mk } ;; diff --git a/tools/configure.ac b/tools/configure.ac index d98628d..9595715 100644 --- a/tools/configure.ac +++ b/tools/configure.ac @@ -2,8 +2,8 @@ # Process this file with autoconf to produce a configure script. AC_PREREQ([2.50]) -AC_INIT(mod_qos, 9.0, pbuchbinder@users.sourceforge.net) -AC_CONFIG_SRCDIR([src/qscheck.c]) +AC_INIT(mod_qos, 11, pbuchbinder@users.sourceforge.net) +AC_CONFIG_SRCDIR([src/qslog.c]) AM_INIT_AUTOMAKE AM_CONFIG_HEADER([config.h]) diff --git a/tools/depcomp b/tools/depcomp index fc98710..6b39162 100755 --- a/tools/depcomp +++ b/tools/depcomp @@ -1,9 +1,9 @@ #! /bin/sh # depcomp - compile a program generating dependencies as side-effects -scriptversion=2013-05-30.07; # UTC +scriptversion=2018-03-07.03; # UTC -# Copyright (C) 1999-2014 Free Software Foundation, Inc. +# Copyright (C) 1999-2020 Free Software Foundation, Inc. # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by @@ -16,7 +16,7 @@ scriptversion=2013-05-30.07; # UTC # GNU General Public License for more details. # You should have received a copy of the GNU General Public License -# along with this program. If not, see <http://www.gnu.org/licenses/>. +# along with this program. If not, see <https://www.gnu.org/licenses/>. # As a special exception to the GNU General Public License, if you # distribute this file as part of a program that contains a @@ -783,9 +783,9 @@ exit 0 # Local Variables: # mode: shell-script # sh-indentation: 2 -# eval: (add-hook 'write-file-hooks 'time-stamp) +# eval: (add-hook 'before-save-hook 'time-stamp) # time-stamp-start: "scriptversion=" # time-stamp-format: "%:y-%02m-%02d.%02H" -# time-stamp-time-zone: "UTC" +# time-stamp-time-zone: "UTC0" # time-stamp-end: "; # UTC" # End: diff --git a/tools/install-sh b/tools/install-sh index 59990a1..ec298b5 100755 --- a/tools/install-sh +++ b/tools/install-sh @@ -1,7 +1,7 @@ #!/bin/sh # install - install a program, script, or datafile -scriptversion=2014-09-12.12; # UTC +scriptversion=2020-11-14.01; # UTC # This originates from X11R5 (mit/util/scripts/install.sh), which was # later released in X11R6 (xc/config/util/install.sh) with the @@ -69,6 +69,11 @@ posix_mkdir= # Desired mode of installed file. mode=0755 +# Create dirs (including intermediate dirs) using mode 755. +# This is like GNU 'install' as of coreutils 8.32 (2020). +mkdir_umask=22 + +backupsuffix= chgrpcmd= chmodcmd=$chmodprog chowncmd= @@ -99,18 +104,28 @@ Options: --version display version info and exit. -c (ignored) - -C install only if different (preserve the last data modification time) + -C install only if different (preserve data modification time) -d create directories instead of installing files. -g GROUP $chgrpprog installed files to GROUP. -m MODE $chmodprog installed files to MODE. -o USER $chownprog installed files to USER. + -p pass -p to $cpprog. -s $stripprog installed files. + -S SUFFIX attempt to back up existing files, with suffix SUFFIX. -t DIRECTORY install into DIRECTORY. -T report an error if DSTFILE is a directory. Environment variables override the default commands: CHGRPPROG CHMODPROG CHOWNPROG CMPPROG CPPROG MKDIRPROG MVPROG RMPROG STRIPPROG + +By default, rm is invoked with -f; when overridden with RMPROG, +it's up to you to specify -f if you want it. + +If -S is not specified, no backups are attempted. + +Email bug reports to bug-automake@gnu.org. +Automake home page: https://www.gnu.org/software/automake/ " while test $# -ne 0; do @@ -137,8 +152,13 @@ while test $# -ne 0; do -o) chowncmd="$chownprog $2" shift;; + -p) cpprog="$cpprog -p";; + -s) stripcmd=$stripprog;; + -S) backupsuffix="$2" + shift;; + -t) is_target_a_directory=always dst_arg=$2 @@ -255,6 +275,10 @@ do dstdir=$dst test -d "$dstdir" dstdir_status=$? + # Don't chown directories that already exist. + if test $dstdir_status = 0; then + chowncmd="" + fi else # Waiting for this to be detected by the "$cpprog $src $dsttmp" command @@ -271,15 +295,18 @@ do fi dst=$dst_arg - # If destination is a directory, append the input filename; won't work - # if double slashes aren't ignored. + # If destination is a directory, append the input filename. if test -d "$dst"; then if test "$is_target_a_directory" = never; then echo "$0: $dst_arg: Is a directory" >&2 exit 1 fi dstdir=$dst - dst=$dstdir/`basename "$src"` + dstbase=`basename "$src"` + case $dst in + */) dst=$dst$dstbase;; + *) dst=$dst/$dstbase;; + esac dstdir_status=0 else dstdir=`dirname "$dst"` @@ -288,27 +315,16 @@ do fi fi + case $dstdir in + */) dstdirslash=$dstdir;; + *) dstdirslash=$dstdir/;; + esac + obsolete_mkdir_used=false if test $dstdir_status != 0; then case $posix_mkdir in '') - # Create intermediate dirs using mode 755 as modified by the umask. - # This is like FreeBSD 'install' as of 1997-10-28. - umask=`umask` - case $stripcmd.$umask in - # Optimize common cases. - *[2367][2367]) mkdir_umask=$umask;; - .*0[02][02] | .[02][02] | .[02]) mkdir_umask=22;; - - *[0-7]) - mkdir_umask=`expr $umask + 22 \ - - $umask % 100 % 40 + $umask % 20 \ - - $umask % 10 % 4 + $umask % 2 - `;; - *) mkdir_umask=$umask,go-w;; - esac - # With -d, create the new directory with the user-specified mode. # Otherwise, rely on $mkdir_umask. if test -n "$dir_arg"; then @@ -318,50 +334,49 @@ do fi posix_mkdir=false - case $umask in - *[123567][0-7][0-7]) - # POSIX mkdir -p sets u+wx bits regardless of umask, which - # is incompatible with FreeBSD 'install' when (umask & 300) != 0. - ;; - *) - # $RANDOM is not portable (e.g. dash); use it when possible to - # lower collision chance - tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ - trap 'ret=$?; rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" 2>/dev/null; exit $ret' 0 + # The $RANDOM variable is not portable (e.g., dash). Use it + # here however when possible just to lower collision chance. + tmpdir=${TMPDIR-/tmp}/ins$RANDOM-$$ - # As "mkdir -p" follows symlinks and we work in /tmp possibly; so - # create the $tmpdir first (and fail if unsuccessful) to make sure - # that nobody tries to guess the $tmpdir name. - if (umask $mkdir_umask && - $mkdirprog $mkdir_mode "$tmpdir" && - exec $mkdirprog $mkdir_mode -p -- "$tmpdir/a/b") >/dev/null 2>&1 - then - if test -z "$dir_arg" || { - # Check for POSIX incompatibilities with -m. - # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or - # other-writable bit of parent directory when it shouldn't. - # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. - test_tmpdir="$tmpdir/a" - ls_ld_tmpdir=`ls -ld "$test_tmpdir"` - case $ls_ld_tmpdir in - d????-?r-*) different_mode=700;; - d????-?--*) different_mode=755;; - *) false;; - esac && - $mkdirprog -m$different_mode -p -- "$test_tmpdir" && { - ls_ld_tmpdir_1=`ls -ld "$test_tmpdir"` - test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" - } - } - then posix_mkdir=: - fi - rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" - else - # Remove any dirs left behind by ancient mkdir implementations. - rmdir ./$mkdir_mode ./-p ./-- "$tmpdir" 2>/dev/null - fi - trap '' 0;; - esac;; + trap ' + ret=$? + rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" 2>/dev/null + exit $ret + ' 0 + + # Because "mkdir -p" follows existing symlinks and we likely work + # directly in world-writeable /tmp, make sure that the '$tmpdir' + # directory is successfully created first before we actually test + # 'mkdir -p'. + if (umask $mkdir_umask && + $mkdirprog $mkdir_mode "$tmpdir" && + exec $mkdirprog $mkdir_mode -p -- "$tmpdir/a/b") >/dev/null 2>&1 + then + if test -z "$dir_arg" || { + # Check for POSIX incompatibilities with -m. + # HP-UX 11.23 and IRIX 6.5 mkdir -m -p sets group- or + # other-writable bit of parent directory when it shouldn't. + # FreeBSD 6.1 mkdir -m -p sets mode of existing directory. + test_tmpdir="$tmpdir/a" + ls_ld_tmpdir=`ls -ld "$test_tmpdir"` + case $ls_ld_tmpdir in + d????-?r-*) different_mode=700;; + d????-?--*) different_mode=755;; + *) false;; + esac && + $mkdirprog -m$different_mode -p -- "$test_tmpdir" && { + ls_ld_tmpdir_1=`ls -ld "$test_tmpdir"` + test "$ls_ld_tmpdir" = "$ls_ld_tmpdir_1" + } + } + then posix_mkdir=: + fi + rmdir "$tmpdir/a/b" "$tmpdir/a" "$tmpdir" + else + # Remove any dirs left behind by ancient mkdir implementations. + rmdir ./$mkdir_mode ./-p ./-- "$tmpdir" 2>/dev/null + fi + trap '' 0;; esac if @@ -372,7 +387,7 @@ do then : else - # The umask is ridiculous, or mkdir does not conform to POSIX, + # mkdir does not conform to POSIX, # or it failed possibly due to a race condition. Create the # directory the slow way, step by step, checking for races as we go. @@ -401,7 +416,7 @@ do prefixes= else if $posix_mkdir; then - (umask=$mkdir_umask && + (umask $mkdir_umask && $doit_exec $mkdirprog $mkdir_mode -p -- "$dstdir") && break # Don't fail if two instances are running concurrently. test -d "$prefix" || exit 1 @@ -434,14 +449,25 @@ do else # Make a couple of temp file names in the proper directory. - dsttmp=$dstdir/_inst.$$_ - rmtmp=$dstdir/_rm.$$_ + dsttmp=${dstdirslash}_inst.$$_ + rmtmp=${dstdirslash}_rm.$$_ # Trap to clean up those temp files at exit. trap 'ret=$?; rm -f "$dsttmp" "$rmtmp" && exit $ret' 0 # Copy the file name to the temp name. - (umask $cp_umask && $doit_exec $cpprog "$src" "$dsttmp") && + (umask $cp_umask && + { test -z "$stripcmd" || { + # Create $dsttmp read-write so that cp doesn't create it read-only, + # which would cause strip to fail. + if test -z "$doit"; then + : >"$dsttmp" # No need to fork-exec 'touch'. + else + $doit touch "$dsttmp" + fi + } + } && + $doit_exec $cpprog "$src" "$dsttmp") && # and set any options; do chmod last to preserve setuid bits. # @@ -467,6 +493,13 @@ do then rm -f "$dsttmp" else + # If $backupsuffix is set, and the file being installed + # already exists, attempt a backup. Don't worry if it fails, + # e.g., if mv doesn't support -f. + if test -n "$backupsuffix" && test -f "$dst"; then + $doit $mvcmd -f "$dst" "$dst$backupsuffix" 2>/dev/null + fi + # Rename the file to the real destination. $doit $mvcmd -f "$dsttmp" "$dst" 2>/dev/null || @@ -481,9 +514,9 @@ do # file should still install successfully. { test ! -f "$dst" || - $doit $rmcmd -f "$dst" 2>/dev/null || + $doit $rmcmd "$dst" 2>/dev/null || { $doit $mvcmd -f "$dst" "$rmtmp" 2>/dev/null && - { $doit $rmcmd -f "$rmtmp" 2>/dev/null; :; } + { $doit $rmcmd "$rmtmp" 2>/dev/null; :; } } || { echo "$0: cannot unlink or rename $dst" >&2 (exit 1); exit 1 @@ -500,9 +533,9 @@ do done # Local variables: -# eval: (add-hook 'write-file-hooks 'time-stamp) +# eval: (add-hook 'before-save-hook 'time-stamp) # time-stamp-start: "scriptversion=" # time-stamp-format: "%:y-%02m-%02d.%02H" -# time-stamp-time-zone: "UTC" +# time-stamp-time-zone: "UTC0" # time-stamp-end: "; # UTC" # End: diff --git a/tools/man1/mod_qos.1 b/tools/man1/mod_qos.1 index 7095625..e89b718 100644 --- a/tools/man1/mod_qos.1 +++ b/tools/man1/mod_qos.1 @@ -1,4 +1,4 @@ -.TH MOD_QOS 1 "May 2023" "mod_qos Apache Module" "mod_qos" +.TH MOD_QOS 1 "January 2025" "mod_qos Apache Module" "mod_qos" .SH NAME mod_qos \- quality of service module for the Apache Web server .SH DESCRIPTION diff --git a/tools/man1/qsdt.1 b/tools/man1/qsdt.1 deleted file mode 100644 index ed58005..0000000 --- a/tools/man1/qsdt.1 +++ /dev/null @@ -1,46 +0,0 @@ -.TH QSDT 1 "May 2023" "mod_qos utilities 11.74" "qsdt man page" - -.SH NAME -qsdt calculates the elapsed time between two related log messages. -.SH SYNOPSIS -qsdt [\-t <regex>] \-i <regex> \-s <regex> \-e <regex> [\-v] [<path>] -.SH DESCRIPTION -qsdt is a simple tool to search two different messages in a log file and calculates the elapsed time between these lines. The two log messages need a common identifier such an unique request id (UNIQUE_ID), a thread id, or a transaction code. -.SH OPTIONS -.TP -\-t <regex> -Defines a pattern (regular expression) matching the log line's timestamp. The pattern must include two sub\-expressions, one matching hours, minutes and seconds the other matching the milliseconds. Default pattern is ([0\-9]{2}:[0\-9]{2}:[0\-9]{2})[.,]([0\-9]{3}) -.TP -\-i <regex> -Pattern (regular expression) matching the identifier which the two messages have in common. The sub\-expression defines the part which needs to be extracted from the matching string. Note: You can also use the start (\-s) and end (\-e) pattern to define the sub\-expression matching this identifier. -.TP -\-s <regex> -Defines the pattern (regular expression or literal string) identifying the first (start) of the two messages. -.TP -\-e <regex> -Defines the pattern (regular expression or literal string) identifying the second (end) of the two messages. -.TP -\-v -Verbose mode. -.TP -<path> -Defines the input file to process. qsdt reads from from standard input if this parameter is omitted. -.SH EXAMPLE -Sample command line arguments: - - \-i ' ([a\-z0\-9]+) [A\-Z]+ ' \-s 'Received Request' \-e 'Received Response' - - matching those sample log messages: - 2018\-03\-12 16:34:08.653 threadid23 INFO Received Request - 2018\-03\-13 16:35:09.891 threadid23 DEBUG MessageHandler Received Response - -.SH NOTE -The four patterns (t,i,s,e) are concatenated into two search patterns: - first (start): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[s ] - second (end): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[e ] - -And the three sub\-expression are used to extract the timestamp and the unique identifier that the start and end message have in common. This means that you could specify the sub\-expression for the unique identifier in the start (\-s) or end (\-e) pattern alternatively, e.g. in case the identifier is at the end of the log line. -.SH SEE ALSO -qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsexec.1 b/tools/man1/qsexec.1 deleted file mode 100644 index 0ae6030..0000000 --- a/tools/man1/qsexec.1 +++ /dev/null @@ -1,36 +0,0 @@ -.TH QSEXEC 1 "May 2023" "mod_qos utilities 11.74" "qsexec man page - -.SH NAME -qsexec \- parses the data received via stdin and executes the defined command on a pattern match. - -.SH SYNOPSIS -qsexec \-e <pattern> [\-t <number>:<sec>] [\-c <pattern> [<command string>]] [\-p] [\-u <user>] <command string> -.SH DESCRIPTION -qsexec reads log lines from stdin and searches for the defined pattern. It executes the defined command string on pattern match. -.SH OPTIONS -.TP -\-e <pattern> -Specifies the search pattern causing an event which shall trigger the command. -.TP -\-t <number>:<sec> -Defines the number of pattern match within the the defined number of seconds in order to trigger the command execution. By default, every pattern match causes a command execution. -.TP -\-c <pattern> [<command string>] -Pattern which clears the event counter. Executes optionally a command if an event command has been executed before. -.TP -\-p -Writes data also to stdout (for piped logging). -.TP -\-u <name> -Become another user, e.g. www\-data. -.TP -<command string> -Defines the event command string where $0\-$9 are substituted by the submatches of the regular expression. -.SH EXAMPLE -Executes the deny.sh script providing the IP address of the client causing a mod_qos(031) messages whenever the log message appears 10 times within at most one minute: - ErrorLog "|/usr/bin/qsexec \-e \\'mod_qos\\(031\\).*, c=([0\-9a\-zA\-Z:.]*)\\' \-t 10:60 \\'/usr/local/bin/deny.sh $1\\'" - -.SH SEE ALSO -qsdt(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsfilter2.1 b/tools/man1/qsfilter2.1 deleted file mode 100644 index 8ec845b..0000000 --- a/tools/man1/qsfilter2.1 +++ /dev/null @@ -1,99 +0,0 @@ -.TH QSFILTER2 1 "May 2023" "mod_qos utilities 11.74" "qsfilter2 man page" - -.SH NAME -qsfilter2 \- an utility to generate mod_qos request line rules out from existing access/audit log data. -.SH SYNOPSIS -qsfilter2 \-i <path> [\-c <path>] [\-d <num>] [\-h] [\-b <num>] [\-p|\-s|\-m|\-o] [\-l <len>] [\-n] [\-e] [\-u 'uni'] [\-k <prefix>] [\-t] [\-f <path>] [\-v 0|1|2] -.SH DESCRIPTION -mod_qos implements a request filter which validates each request line. The module supports both, negative and positive security model. The QS_Deny* directives are used to specify request line patterns which are not allowed to access the server (negative security model / deny list). These rules are used to restrict access to certain resources which should not be available to users or to protect the server from malicious patterns. The QS_Permit* rules implement a positive security model (allow list). These directives are used to define allowed request line patterns. Request which do not match any of these patterns are not allowed to access the server. - -qsfilter2 is an audit log analyzer used to generate filter rules (perl compatible regular expressions) which may be used by mod_qos to deny access for suspect requests (QS_PermitUri rules). It parses existing audit log files in order to generate request patterns covering all allowed requests. -.SH OPTIONS -.TP -\-i <path> -Input file containing request URIs. The URIs for this file have to be extracted from the servers access logs. Each line of the input file contains a request URI consisting of a path and and query. - Example: - /aaa/index.do - /aaa/edit?image=1.jpg - /aaa/image/1.jpg - /aaa/view?page=1 - /aaa/edit?document=1 - -These access log data must include current request URIs but also request lines from previous rule generation steps. It must also include request lines which cover manually generated rules. You may use the 'qos\-path' and 'qos\-query' variables to create an audit log containing all request data (path and query/body data). Example: 'CustomLog audit_log %{qos\-path}n%{qos\-query}n'. See also http://mod\-qos.sourceforge.net#qsfiltersample about the module settings. -.TP -\-c <path> -mod_qos configuration file defining QS_DenyRequestLine and QS_PermitUri directives. qsfilter2 generates rules from access log data automatically. Manually generated rules (QS_PermitUri) may be provided from this file. Note: each manual rule must be represented by a request URI in the input data (\-i) in order to make sure not to be deleted by the rule optimisation algorithm. QS_Deny* rules from this file are used to filter request lines which should not be used for allow list rule generation. - Example: - # manually defined allow list rule: - QS_PermitUri +view deny "^[/a\-zA\-Z0\-9]+/view\\?(page=[0\-9]+)?$" - # filter unwanted request line patterns: - QS_DenyRequestLine +printable deny ".*[\\x00\-\\x19].*" - - -.TP -\-d <num> -Depth (sub locations) of the path string which is defined as a literal string. Default is 1. -.TP -\-h -Always use a string representing the handler name in the path even the url does not have a query. See also \-d option. -.TP -\-b <num> -Replaces url pattern by the regular expression when detecting a base64/hex encoded string. Detecting sensibility is defined by a numeric value. You should use values higher than 5 (default) or 0 to disable this function. -.TP -\-p -Represents query by pcre only (no literal strings). -.TP -\-s -Uses one single pcre for the whole query string. -.TP -\-m -Uses one pcre for multiple query values (recommended mode). -.TP -\-o -Does not care the order of query parameters. -.TP -\-l <len> -Outsizes the query length by the defined length ({0,size+len}), default is 10. -.TP -\-n -Disables redundant rules elimination. -.TP -\-e -Exit on error. -.TP -\-u 'uni' -Enables additional decoding methods. Use the same settings as you have used for the QS_Decoding directive. -.TP -\-k <prefix> -Prefix used to generate rule identifiers (QSF by default). -.TP -\-t -Calculates the maximal latency per request (worst case) using the generated rules. -.TP -\-f <path> -Filters the input by the provided path (prefix) only processing matching lines. -.TP -\-v <level> -Verbose mode. (0=silent, 1=rule source, 2=detailed). Default is 1. Don't use rules you haven't checked the request data used to generate it! Level 1 is highly recommended (as long as you don't have created the log data using your own web crawler). -.SH OUTPUT -The output of qsfilter2 is written to stdout. The output contains the generated QS_PermitUri directives but also information about the source which has been used to generate these rules. It is very important to check the validity of each request line which has been used to calculate the QS_PermitUri rules. Each request line which has been used to generate a new rule is shown in the output prefixed by "ADD line <line number>:". These request lines should be stored and reused at any later rule generation (add them to the URI input file). The subsequent line shows the generated rule. At the end of data processing a list of all generated QS_PermitUri rules is shown. These directives may be used withn the configuration file used by mod_qos. -.SH EXAMPLE - qsfilter2 \-i loc.txt \-c httpd.conf \-m \-e - ... - # ADD line 1: /aaa/index.do - # 003 ^(/[a\-zA\-Z0\-9\\\-_]+)+[/]?\\.?[a\-zA\-Z]{0,4}$ - # ADD line 3: /aaa/view?page=1 - # \-\-\- ^[/a\-zA\-Z0\-9]+/view\\?(page=[0\-9]+)?$ - # ADD line 4: /aaa/edit?document=1 - # 004 ^[/a\-zA\-Z]+/edit\\?((document)(=[0\-9]*)*[&]?)*$ - # ADD line 5: /aaa/edit?image=1.jpg - # 005 ^[/a\-zA\-Z]+/edit\\?((image)(=[0\-9\\.a\-zA\-Z]*)*[&]?)*$ - ... - QS_PermitUri +QSF001 deny "^[/a\-zA\-Z]+/edit\\?((document|image)(=[0\-9\\.a\-zA\-Z]*)*[&]?)*$" - QS_PermitUri +QSF002 deny "^[/a\-zA\-Z0\-9]+/view\\?(page=[0\-9]+)?$" - QS_PermitUri +QSF003 deny "^(/[a\-zA\-Z0\-9\\\-_]+)+[/]?\\.?[a\-zA\-Z]{0,4}$" - -.SH SEE ALSO -qsdt(1), qsexec(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsgeo.1 b/tools/man1/qsgeo.1 index 9c0e1be..06f7228 100644 --- a/tools/man1/qsgeo.1 +++ b/tools/man1/qsgeo.1 @@ -1,4 +1,4 @@ -.TH QSGEO 1 "May 2023" "mod_qos utilities 11.74" "qsgeo man page" +.TH QSGEO 1 "January 2025" "mod_qos utilities 11.76" "qsgeo man page" .SH NAME qsgeo \- an utility to lookup a client's country code. @@ -34,6 +34,6 @@ Resolving a single IP address: qsgeo \-d GeoIPCountryWhois.csv \-ip 192.84.12.23 .SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) +qslog(1), qsre(1), qsrespeed(1) .SH AUTHOR Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsgrep.1 b/tools/man1/qsgrep.1 deleted file mode 100644 index 5bba3d9..0000000 --- a/tools/man1/qsgrep.1 +++ /dev/null @@ -1,28 +0,0 @@ -.TH QSGREP 1 "May 2023" "mod_qos utilities 11.74" "qsgrep man page" - -.SH NAME -qsgrep \- prints matching patterns within a file. -.SH SYNOPSIS -qsgrep \-e <pattern> \-o <sub string> [<path>] -.SH DESCRIPTION -qsgrep is a simple tool to search patterns within files. It uses regular expressions to find patterns and prints the submatches within a pre\-defined format string. -.SH OPTIONS -.TP -\-e <pattern> -Specifies the search pattern. -.TP -\-o <string> -Defines the output string where $0\-$9 are substituted by the submatches of the regular expression. -.TP -<path> -Defines the input file to process. qsgrep reads from from standard input if this parameter is omitted. - -.SH EXAMPLE -Shows the IP addresses of clients causing mod_qos(031) messages): - - qsgrep \-e 'mod_qos\\(031\\).*, c=([a\-zA\-Z0\-9:.]*)' \-o 'ip=$1' error_log - -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qshead.1 b/tools/man1/qshead.1 deleted file mode 100644 index b7956a8..0000000 --- a/tools/man1/qshead.1 +++ /dev/null @@ -1,16 +0,0 @@ -.TH QSHEAD 1 "May 2023" "mod_qos utilities 11.74" "qshead man page" - -.SH NAME -qshead \- an utility reading from stdin and printing all lines to stdout until reaching the defined pattern. -.SH SYNOPSIS -qshead \-p <pattern> -.SH DESCRIPTION -qshead reads lines from stdin and prints them to stdout until a line contains the specified pattern (literal string). -.SH OPTIONS -.TP -\-p <pattern> -Search pattern (literal string). -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1) qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qslog.1 b/tools/man1/qslog.1 index 140a8a8..631c7b4 100644 --- a/tools/man1/qslog.1 +++ b/tools/man1/qslog.1 @@ -1,4 +1,4 @@ -.TH QSLOG 1 "May 2023" "mod_qos utilities 11.74" "qslog man page" +.TH QSLOG 1 "January 2025" "mod_qos utilities 11.76" "qslog man page" .SH NAME qslog \- collects request statistics from access log data. @@ -104,6 +104,6 @@ Post processing: cat access.log | qslog \-f ..IRSB.T \-o stat.csv \-p .SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) +qsgeo(1), qsre(1), qsrespeed(1) .SH AUTHOR Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qslogger.1 b/tools/man1/qslogger.1 deleted file mode 100644 index 8c8961f..0000000 --- a/tools/man1/qslogger.1 +++ /dev/null @@ -1,41 +0,0 @@ -.TH QSLOGGER 1 "May 2023" "mod_qos utilities 11.74" "qslogger man page" - -.SH NAME -qslogger \- another shell command interface to the system log module (syslog). -.SH SYNOPSIS -qslogger [\-t <tag>] [\-f <facility>] [\-l <level>] [\-x <prefix>] [\-r <expression>] [\-d <level>] [\-u <name>] [\-p] -.SH DESCRIPTION -Use this utility to forward log messages to the systems syslog facility, e.g., to forward the messages to a remote host. It reads data from stdin. -.SH OPTIONS - -.TP -\-t <tag> -Defines the tag name which shall be used to define the origin of the messages, e.g. 'httpd'. -.TP -\-f <facility> -Defines the syslog facility. Default is 'daemon'. -.TP -\-u <name> -Becomes another user, e.g. www\-data. -.TP -\-l <level> -Defines the minimal severity a message must have in order to be forwarded. Default is 'DEBUG' (forwarding everything). -.TP -\-x <prefix> -Allows you to add a prefix (literal string) to every message. -.TP -\-r <expression> -Specifies a regular expression which shall be used to determine the severity (syslog level) for each log line. The default pattern '^\\[[0\-9a\-zA\-Z :]+\\] \\[([a\-z]+)\\] ' can be used for Apache error log messages but you may configure your own pattern matching other log formats. Use brackets to define the pattern enclosing the severity string. Default level (if severity can't be determined) is defined by the option '\-d' (see below). -.TP -\-d <level> -The default severity if the specified pattern (\-r) does not match and the message's severity can't be determined. Default is 'NOTICE'. -.TP -\-p -Writes data also to stdout (for piped logging). -.SH EXAMPLE - ErrorLog "|/usr/bin/qslogger \-t apache \-f local7" - -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qspng.1 b/tools/man1/qspng.1 deleted file mode 100644 index d3ff0c4..0000000 --- a/tools/man1/qspng.1 +++ /dev/null @@ -1,22 +0,0 @@ -.TH QSPNG 1 "May 2023" "mod_qos utilities 11.74" "qspng man page" - -.SH NAME -qspng \- an utility to draw a png graph from qslog(1) output data. -.SH SYNOPSIS -qspng \-i <stat_log_file> \-p <parameter> \-o <out_file> [\-10] -.SH DESCRIPTION -qspng is a tool to generate png (portable network graphics) raster images files from semicolon separated data generated by the qslog utility. It reads up to the first 1440 entries (24 hours) and prints a graph using the values defined by the 'parameter' name. -.SH OPTIONS -.TP -\-i <stats_log_file> -Input file to read data from. -.TP -\-p <parameter> -Parameter name, e.g. r/s or usr. -.TP -\-o <out_file> -Output file name, e.g. stat.png. -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslogger(1), qslog(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsre.1 b/tools/man1/qsre.1 index b011661..4f3cf76 100644 --- a/tools/man1/qsre.1 +++ b/tools/man1/qsre.1 @@ -1,4 +1,4 @@ -.TH QSRE 1 "May 2023" "mod_qos utilities 11.74" "qsre man page" +.TH QSRE 1 "January 2025" "mod_qos utilities 11.76" "qsre man page" .SH NAME qsre matches a regular expression against test strings. @@ -14,6 +14,6 @@ The first argument either defines a single test string of a path to a file conta <pcre>|<path> The second argument either defines a regular expression or a path to a file containing the expression. .SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1) +qsgeo(1), qslog(1), qsrespeed(1) .SH AUTHOR Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsrespeed.1 b/tools/man1/qsrespeed.1 index 15207a8..f675ff4 100644 --- a/tools/man1/qsrespeed.1 +++ b/tools/man1/qsrespeed.1 @@ -1,4 +1,4 @@ -.TH QSRESPEED 1 "May 2023" "mod_qos utilities 11.74" "qsrespeed man page" +.TH QSRESPEED 1 "January 2025" "mod_qos utilities 11.76" "qsrespeed man page" .SH NAME Tool to compare / estimate the processing time for (Perl\-compatible) regular expressions (PCRE). @@ -11,6 +11,6 @@ qsrespeed loads regular expressions from the provided file and matches them agai <path> Defines the input file to process. The file consists a list of (separated by a newline character) regular expressions to test .SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrotate(1), qssign(1), qstail(1) +qsgeo(1), qslog(1), qsre(1) .SH AUTHOR Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qsrotate.1 b/tools/man1/qsrotate.1 deleted file mode 100644 index 754e8f4..0000000 --- a/tools/man1/qsrotate.1 +++ /dev/null @@ -1,50 +0,0 @@ -.TH QSROTATE 1 "May 2023" "mod_qos utilities 11.74" "qsrotate man page" - -.SH NAME -qsrotate \- a log rotation tool (similar to Apache's rotatelogs). -.SH SYNOPSIS -qsrotate \-o <file> [\-s <sec> [\-t <hours>]] [\-b <bytes>] [\-f] [\-z] [\-g <num>] [\-u <name>] [\-m <mask>] [\-p] [\-d] -.SH DESCRIPTION -qsrotate reads from stdin (piped log) and writes the data to the provided file rotating the file after the specified time. -.SH OPTIONS -.TP -\-o <file> -Output log file to write the data to (use an absolute path). -.TP -\-s <sec> -Rotation interval in seconds, default are 86400 seconds. -.TP -\-t <hours> -Offset to UTC (enables also DST support), default is 0. -.TP -\-b <bytes> -File size limitation (default/max. are 2147352576 bytes, min. are 1048576 bytes). -.TP -\-f -Forced log rotation at the specified interval even no data is written. -.TP -\-z -Compress (gzip) the rotated file. -.TP -\-g <num> -Generations (number of files to keep). -.TP -\-u <name> -Become another user, e.g. www\-data. \-m <mask> -File permission which is either 600, 640, 660 (default) or 664. -.TP -\-p -Writes data also to stdout (for piped logging). \-d -Line\-by\-line data reading prefixing every line with a timestamp. -.SH EXAMPLE - TransferLog "|/usr/bin/qsrotate \-f \-z \-g 3 \-o /var/log/apache/access.log \-s 86400" - -The name of the rotated file will be /dest/filee.YYYYmmddHHMMSS where YYYYmmddHHMMSS is the system time at which the data has been rotated. -.SH NOTE - \- Each qsrotate instance must use an individual file. - \- You may trigger a file rotation manually by sending the signal USR1 -to the process. -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qsre(1), qsrespeed(1), qspng(1), qssign(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qssign.1 b/tools/man1/qssign.1 deleted file mode 100644 index ec3ed8d..0000000 --- a/tools/man1/qssign.1 +++ /dev/null @@ -1,44 +0,0 @@ -.TH QSSIGN 1 "May 2023" "mod_qos utilities 11.74" "qssign man page" - -.SH NAME -qssign \- an utility to sign and verify the integrity of log data. -.SH SYNOPSIS -qssign \-s|S <secret> [\-e] [\-v] [\-u <name>] [\-f <regex>] [\-a 'sha1'|'sha256'] -.SH DESCRIPTION -qssign is a log data integrity check tool. It reads log data from stdin (pipe) and writes the data to stdout adding a sequence number and signature to ever log line. -.SH OPTIONS -.TP -\-s <secret> -Passphrase used to calculate signature. -.TP -\-S <program> -Specifies a program which writes the passphrase to stdout. -.TP -\-e -Writes start/end marker when starting/stopping data signing. -.TP -\-v -Verification mode checking the integrity of signed data. -.TP -\-u <name> -Becomes another user, e.g. www\-data. -.TP -\-f <regex> -Filter pattern (case sensitive regular expression) for messages which do not need to be signed. -.TP -\-a 'sha1'|'sha256' -Specifies the algorithm to use. Default is sha1. -.SH EXAMPLE -Sign: - - TransferLog "|/usr/bin/qssign \-s password \-e |/usr/bin/qsrotate \-o /var/log/apache/access.log" - - -Verify: - - cat access.log | qssign \-s password \-v - -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qstail(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/man1/qstail.1 b/tools/man1/qstail.1 deleted file mode 100644 index 0755c0e..0000000 --- a/tools/man1/qstail.1 +++ /dev/null @@ -1,19 +0,0 @@ -.TH QSTAIL 1 "May 2023" "mod_qos utilities 11.74" "qstail man page" - -.SH NAME -qstail \- an utility printing the end of a log file starting at the specified pattern. -.SH SYNOPSIS -qstail \-i <path> \-p <pattern> -.SH DESCRIPTION -qstail shows the end of a log file beginning with the line containing the specified pattern. This may be used to show all lines which has been written after a certain event (e.g., server restart) or time stamp. -.SH OPTIONS -.TP -\-i <path> -Input file to read the data from. -.TP -\-p <pattern> -Search pattern (literal string). -.SH SEE ALSO -qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1) -.SH AUTHOR -Pascal Buchbinder, http://mod-qos.sourceforge.net/ diff --git a/tools/missing b/tools/missing index f62bbae..8d0eaad 100755 --- a/tools/missing +++ b/tools/missing @@ -1,9 +1,9 @@ #! /bin/sh # Common wrapper for a few potentially missing GNU programs. -scriptversion=2013-10-28.13; # UTC +scriptversion=2018-03-07.03; # UTC -# Copyright (C) 1996-2014 Free Software Foundation, Inc. +# Copyright (C) 1996-2020 Free Software Foundation, Inc. # Originally written by Fran,cois Pinard <pinard@iro.umontreal.ca>, 1996. # This program is free software; you can redistribute it and/or modify @@ -17,7 +17,7 @@ scriptversion=2013-10-28.13; # UTC # GNU General Public License for more details. # You should have received a copy of the GNU General Public License -# along with this program. If not, see <http://www.gnu.org/licenses/>. +# along with this program. If not, see <https://www.gnu.org/licenses/>. # As a special exception to the GNU General Public License, if you # distribute this file as part of a program that contains a @@ -101,9 +101,9 @@ else exit $st fi -perl_URL=http://www.perl.org/ -flex_URL=http://flex.sourceforge.net/ -gnu_software_URL=http://www.gnu.org/software +perl_URL=https://www.perl.org/ +flex_URL=https://github.com/westes/flex +gnu_software_URL=https://www.gnu.org/software program_details () { @@ -207,9 +207,9 @@ give_advice "$1" | sed -e '1s/^/WARNING: /' \ exit $st # Local variables: -# eval: (add-hook 'write-file-hooks 'time-stamp) +# eval: (add-hook 'before-save-hook 'time-stamp) # time-stamp-start: "scriptversion=" # time-stamp-format: "%:y-%02m-%02d.%02H" -# time-stamp-time-zone: "UTC" +# time-stamp-time-zone: "UTC0" # time-stamp-end: "; # UTC" # End: diff --git a/tools/src/Makefile.am b/tools/src/Makefile.am index 489a69a..00b047e 100644 --- a/tools/src/Makefile.am +++ b/tools/src/Makefile.am @@ -1,46 +1,13 @@ # $Id: Makefile.am 2486 2018-09-03 20:22:17Z pbuchbinder $ -bin_PROGRAMS=qsfilter2 qslog qspng qsrotate qssign qstail qshead qsgrep qsexec qscheck qsgeo qslogger qsdt qsrespeed qsre - -qsfilter2_SOURCES= \ - qsfilter2.c qs_util.c +bin_PROGRAMS=qslog qsgeo qsrespeed qsre qslog_SOURCES= \ qslog.c qs_util.c -qspng_SOURCES= \ - qspng.c qs_util.c - -qsrotate_SOURCES= \ - qsrotate.c qs_util.c - -qssign_SOURCES= \ - qssign.c qs_util.c qs_apo.c - -qstail_SOURCES= \ - qstail.c qs_util.c - -qshead_SOURCES= \ - qshead.c qs_util.c - -qsgrep_SOURCES= \ - qsgrep.c qs_util.c - -qsexec_SOURCES= \ - qsexec.c qs_util.c - -qscheck_SOURCES= \ - qscheck.c qs_util.c - qsgeo_SOURCES= \ qsgeo.c qs_util.c -qslogger_SOURCES= \ - qslogger.c qs_util.c - -qsdt_SOURCES= \ - qsdt.c qs_util.c - qsrespeed_SOURCES= \ qsrespeed.c qs_util.c diff --git a/tools/src/Makefile.in b/tools/src/Makefile.in index 18daa12..b4a9422 100644 --- a/tools/src/Makefile.in +++ b/tools/src/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.15 from Makefile.am. +# Makefile.in generated by automake 1.16.3 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2014 Free Software Foundation, Inc. +# Copyright (C) 1994-2020 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -88,11 +88,8 @@ POST_INSTALL = : NORMAL_UNINSTALL = : PRE_UNINSTALL = : POST_UNINSTALL = : -bin_PROGRAMS = qsfilter2$(EXEEXT) qslog$(EXEEXT) qspng$(EXEEXT) \ - qsrotate$(EXEEXT) qssign$(EXEEXT) qstail$(EXEEXT) \ - qshead$(EXEEXT) qsgrep$(EXEEXT) qsexec$(EXEEXT) \ - qscheck$(EXEEXT) qsgeo$(EXEEXT) qslogger$(EXEEXT) \ - qsdt$(EXEEXT) qsrespeed$(EXEEXT) qsre$(EXEEXT) +bin_PROGRAMS = qslog$(EXEEXT) qsgeo$(EXEEXT) qsrespeed$(EXEEXT) \ + qsre$(EXEEXT) subdir = src ACLOCAL_M4 = $(top_srcdir)/aclocal.m4 am__aclocal_m4_deps = $(top_srcdir)/configure.ac @@ -105,52 +102,18 @@ CONFIG_CLEAN_FILES = CONFIG_CLEAN_VPATH_FILES = am__installdirs = "$(DESTDIR)$(bindir)" PROGRAMS = $(bin_PROGRAMS) -am_qscheck_OBJECTS = qscheck.$(OBJEXT) qs_util.$(OBJEXT) -qscheck_OBJECTS = $(am_qscheck_OBJECTS) -qscheck_LDADD = $(LDADD) -am_qsdt_OBJECTS = qsdt.$(OBJEXT) qs_util.$(OBJEXT) -qsdt_OBJECTS = $(am_qsdt_OBJECTS) -qsdt_LDADD = $(LDADD) -am_qsexec_OBJECTS = qsexec.$(OBJEXT) qs_util.$(OBJEXT) -qsexec_OBJECTS = $(am_qsexec_OBJECTS) -qsexec_LDADD = $(LDADD) -am_qsfilter2_OBJECTS = qsfilter2.$(OBJEXT) qs_util.$(OBJEXT) -qsfilter2_OBJECTS = $(am_qsfilter2_OBJECTS) -qsfilter2_LDADD = $(LDADD) am_qsgeo_OBJECTS = qsgeo.$(OBJEXT) qs_util.$(OBJEXT) qsgeo_OBJECTS = $(am_qsgeo_OBJECTS) qsgeo_LDADD = $(LDADD) -am_qsgrep_OBJECTS = qsgrep.$(OBJEXT) qs_util.$(OBJEXT) -qsgrep_OBJECTS = $(am_qsgrep_OBJECTS) -qsgrep_LDADD = $(LDADD) -am_qshead_OBJECTS = qshead.$(OBJEXT) qs_util.$(OBJEXT) -qshead_OBJECTS = $(am_qshead_OBJECTS) -qshead_LDADD = $(LDADD) am_qslog_OBJECTS = qslog.$(OBJEXT) qs_util.$(OBJEXT) qslog_OBJECTS = $(am_qslog_OBJECTS) qslog_LDADD = $(LDADD) -am_qslogger_OBJECTS = qslogger.$(OBJEXT) qs_util.$(OBJEXT) -qslogger_OBJECTS = $(am_qslogger_OBJECTS) -qslogger_LDADD = $(LDADD) -am_qspng_OBJECTS = qspng.$(OBJEXT) qs_util.$(OBJEXT) -qspng_OBJECTS = $(am_qspng_OBJECTS) -qspng_LDADD = $(LDADD) am_qsre_OBJECTS = qsre.$(OBJEXT) qs_util.$(OBJEXT) qsre_OBJECTS = $(am_qsre_OBJECTS) qsre_LDADD = $(LDADD) am_qsrespeed_OBJECTS = qsrespeed.$(OBJEXT) qs_util.$(OBJEXT) qsrespeed_OBJECTS = $(am_qsrespeed_OBJECTS) qsrespeed_LDADD = $(LDADD) -am_qsrotate_OBJECTS = qsrotate.$(OBJEXT) qs_util.$(OBJEXT) -qsrotate_OBJECTS = $(am_qsrotate_OBJECTS) -qsrotate_LDADD = $(LDADD) -am_qssign_OBJECTS = qssign.$(OBJEXT) qs_util.$(OBJEXT) \ - qs_apo.$(OBJEXT) -qssign_OBJECTS = $(am_qssign_OBJECTS) -qssign_LDADD = $(LDADD) -am_qstail_OBJECTS = qstail.$(OBJEXT) qs_util.$(OBJEXT) -qstail_OBJECTS = $(am_qstail_OBJECTS) -qstail_LDADD = $(LDADD) AM_V_P = $(am__v_P_@AM_V@) am__v_P_ = $(am__v_P_@AM_DEFAULT_V@) am__v_P_0 = false @@ -165,7 +128,10 @@ am__v_at_0 = @ am__v_at_1 = DEFAULT_INCLUDES = -I.@am__isrc@ -I$(top_builddir) depcomp = $(SHELL) $(top_srcdir)/depcomp -am__depfiles_maybe = depfiles +am__maybe_remake_depfiles = depfiles +am__depfiles_remade = ./$(DEPDIR)/qs_util.Po ./$(DEPDIR)/qsgeo.Po \ + ./$(DEPDIR)/qslog.Po ./$(DEPDIR)/qsre.Po \ + ./$(DEPDIR)/qsrespeed.Po am__mv = mv -f COMPILE = $(CC) $(DEFS) $(DEFAULT_INCLUDES) $(INCLUDES) $(AM_CPPFLAGS) \ $(CPPFLAGS) $(AM_CFLAGS) $(CFLAGS) @@ -179,16 +145,10 @@ AM_V_CCLD = $(am__v_CCLD_@AM_V@) am__v_CCLD_ = $(am__v_CCLD_@AM_DEFAULT_V@) am__v_CCLD_0 = @echo " CCLD " $@; am__v_CCLD_1 = -SOURCES = $(qscheck_SOURCES) $(qsdt_SOURCES) $(qsexec_SOURCES) \ - $(qsfilter2_SOURCES) $(qsgeo_SOURCES) $(qsgrep_SOURCES) \ - $(qshead_SOURCES) $(qslog_SOURCES) $(qslogger_SOURCES) \ - $(qspng_SOURCES) $(qsre_SOURCES) $(qsrespeed_SOURCES) \ - $(qsrotate_SOURCES) $(qssign_SOURCES) $(qstail_SOURCES) -DIST_SOURCES = $(qscheck_SOURCES) $(qsdt_SOURCES) $(qsexec_SOURCES) \ - $(qsfilter2_SOURCES) $(qsgeo_SOURCES) $(qsgrep_SOURCES) \ - $(qshead_SOURCES) $(qslog_SOURCES) $(qslogger_SOURCES) \ - $(qspng_SOURCES) $(qsre_SOURCES) $(qsrespeed_SOURCES) \ - $(qsrotate_SOURCES) $(qssign_SOURCES) $(qstail_SOURCES) +SOURCES = $(qsgeo_SOURCES) $(qslog_SOURCES) $(qsre_SOURCES) \ + $(qsrespeed_SOURCES) +DIST_SOURCES = $(qsgeo_SOURCES) $(qslog_SOURCES) $(qsre_SOURCES) \ + $(qsrespeed_SOURCES) am__can_run_installinfo = \ case $$AM_UPDATE_INFO_DIR in \ n|no|NO) false;; \ @@ -303,45 +263,12 @@ target_alias = @target_alias@ top_build_prefix = @top_build_prefix@ top_builddir = @top_builddir@ top_srcdir = @top_srcdir@ -qsfilter2_SOURCES = \ - qsfilter2.c qs_util.c - qslog_SOURCES = \ qslog.c qs_util.c -qspng_SOURCES = \ - qspng.c qs_util.c - -qsrotate_SOURCES = \ - qsrotate.c qs_util.c - -qssign_SOURCES = \ - qssign.c qs_util.c qs_apo.c - -qstail_SOURCES = \ - qstail.c qs_util.c - -qshead_SOURCES = \ - qshead.c qs_util.c - -qsgrep_SOURCES = \ - qsgrep.c qs_util.c - -qsexec_SOURCES = \ - qsexec.c qs_util.c - -qscheck_SOURCES = \ - qscheck.c qs_util.c - qsgeo_SOURCES = \ qsgeo.c qs_util.c -qslogger_SOURCES = \ - qslogger.c qs_util.c - -qsdt_SOURCES = \ - qsdt.c qs_util.c - qsrespeed_SOURCES = \ qsrespeed.c qs_util.c @@ -369,8 +296,8 @@ Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status *config.status*) \ cd $(top_builddir) && $(MAKE) $(AM_MAKEFLAGS) am--refresh;; \ *) \ - echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe)'; \ - cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__depfiles_maybe);; \ + echo ' cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__maybe_remake_depfiles)'; \ + cd $(top_builddir) && $(SHELL) ./config.status $(subdir)/$@ $(am__maybe_remake_depfiles);; \ esac; $(top_builddir)/config.status: $(top_srcdir)/configure $(CONFIG_STATUS_DEPENDENCIES) @@ -424,46 +351,14 @@ uninstall-binPROGRAMS: clean-binPROGRAMS: -test -z "$(bin_PROGRAMS)" || rm -f $(bin_PROGRAMS) -qscheck$(EXEEXT): $(qscheck_OBJECTS) $(qscheck_DEPENDENCIES) $(EXTRA_qscheck_DEPENDENCIES) - @rm -f qscheck$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qscheck_OBJECTS) $(qscheck_LDADD) $(LIBS) - -qsdt$(EXEEXT): $(qsdt_OBJECTS) $(qsdt_DEPENDENCIES) $(EXTRA_qsdt_DEPENDENCIES) - @rm -f qsdt$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qsdt_OBJECTS) $(qsdt_LDADD) $(LIBS) - -qsexec$(EXEEXT): $(qsexec_OBJECTS) $(qsexec_DEPENDENCIES) $(EXTRA_qsexec_DEPENDENCIES) - @rm -f qsexec$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qsexec_OBJECTS) $(qsexec_LDADD) $(LIBS) - -qsfilter2$(EXEEXT): $(qsfilter2_OBJECTS) $(qsfilter2_DEPENDENCIES) $(EXTRA_qsfilter2_DEPENDENCIES) - @rm -f qsfilter2$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qsfilter2_OBJECTS) $(qsfilter2_LDADD) $(LIBS) - qsgeo$(EXEEXT): $(qsgeo_OBJECTS) $(qsgeo_DEPENDENCIES) $(EXTRA_qsgeo_DEPENDENCIES) @rm -f qsgeo$(EXEEXT) $(AM_V_CCLD)$(LINK) $(qsgeo_OBJECTS) $(qsgeo_LDADD) $(LIBS) -qsgrep$(EXEEXT): $(qsgrep_OBJECTS) $(qsgrep_DEPENDENCIES) $(EXTRA_qsgrep_DEPENDENCIES) - @rm -f qsgrep$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qsgrep_OBJECTS) $(qsgrep_LDADD) $(LIBS) - -qshead$(EXEEXT): $(qshead_OBJECTS) $(qshead_DEPENDENCIES) $(EXTRA_qshead_DEPENDENCIES) - @rm -f qshead$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qshead_OBJECTS) $(qshead_LDADD) $(LIBS) - qslog$(EXEEXT): $(qslog_OBJECTS) $(qslog_DEPENDENCIES) $(EXTRA_qslog_DEPENDENCIES) @rm -f qslog$(EXEEXT) $(AM_V_CCLD)$(LINK) $(qslog_OBJECTS) $(qslog_LDADD) $(LIBS) -qslogger$(EXEEXT): $(qslogger_OBJECTS) $(qslogger_DEPENDENCIES) $(EXTRA_qslogger_DEPENDENCIES) - @rm -f qslogger$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qslogger_OBJECTS) $(qslogger_LDADD) $(LIBS) - -qspng$(EXEEXT): $(qspng_OBJECTS) $(qspng_DEPENDENCIES) $(EXTRA_qspng_DEPENDENCIES) - @rm -f qspng$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qspng_OBJECTS) $(qspng_LDADD) $(LIBS) - qsre$(EXEEXT): $(qsre_OBJECTS) $(qsre_DEPENDENCIES) $(EXTRA_qsre_DEPENDENCIES) @rm -f qsre$(EXEEXT) $(AM_V_CCLD)$(LINK) $(qsre_OBJECTS) $(qsre_LDADD) $(LIBS) @@ -472,41 +367,23 @@ qsrespeed$(EXEEXT): $(qsrespeed_OBJECTS) $(qsrespeed_DEPENDENCIES) $(EXTRA_qsres @rm -f qsrespeed$(EXEEXT) $(AM_V_CCLD)$(LINK) $(qsrespeed_OBJECTS) $(qsrespeed_LDADD) $(LIBS) -qsrotate$(EXEEXT): $(qsrotate_OBJECTS) $(qsrotate_DEPENDENCIES) $(EXTRA_qsrotate_DEPENDENCIES) - @rm -f qsrotate$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qsrotate_OBJECTS) $(qsrotate_LDADD) $(LIBS) - -qssign$(EXEEXT): $(qssign_OBJECTS) $(qssign_DEPENDENCIES) $(EXTRA_qssign_DEPENDENCIES) - @rm -f qssign$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qssign_OBJECTS) $(qssign_LDADD) $(LIBS) - -qstail$(EXEEXT): $(qstail_OBJECTS) $(qstail_DEPENDENCIES) $(EXTRA_qstail_DEPENDENCIES) - @rm -f qstail$(EXEEXT) - $(AM_V_CCLD)$(LINK) $(qstail_OBJECTS) $(qstail_LDADD) $(LIBS) - mostlyclean-compile: -rm -f *.$(OBJEXT) distclean-compile: -rm -f *.tab.c -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qs_apo.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qs_util.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qscheck.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsdt.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsexec.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsfilter2.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsgeo.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsgrep.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qshead.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qslog.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qslogger.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qspng.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsre.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsrespeed.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsrotate.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qssign.Po@am__quote@ -@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qstail.Po@am__quote@ +@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qs_util.Po@am__quote@ # am--include-marker +@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsgeo.Po@am__quote@ # am--include-marker +@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qslog.Po@am__quote@ # am--include-marker +@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsre.Po@am__quote@ # am--include-marker +@AMDEP_TRUE@@am__include@ @am__quote@./$(DEPDIR)/qsrespeed.Po@am__quote@ # am--include-marker + +$(am__depfiles_remade): + @$(MKDIR_P) $(@D) + @echo '# dummy' >$@-t && $(am__mv) $@-t $@ + +am--depfiles: $(am__depfiles_remade) .c.o: @am__fastdepCC_TRUE@ $(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $< @@ -574,7 +451,10 @@ cscopelist-am: $(am__tagged_files) distclean-tags: -rm -f TAGS ID GTAGS GRTAGS GSYMS GPATH tags -distdir: $(DISTFILES) +distdir: $(BUILT_SOURCES) + $(MAKE) $(AM_MAKEFLAGS) distdir-am + +distdir-am: $(DISTFILES) @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ list='$(DISTFILES)'; \ @@ -646,7 +526,11 @@ clean: clean-am clean-am: clean-binPROGRAMS clean-generic mostlyclean-am distclean: distclean-am - -rm -rf ./$(DEPDIR) + -rm -f ./$(DEPDIR)/qs_util.Po + -rm -f ./$(DEPDIR)/qsgeo.Po + -rm -f ./$(DEPDIR)/qslog.Po + -rm -f ./$(DEPDIR)/qsre.Po + -rm -f ./$(DEPDIR)/qsrespeed.Po -rm -f Makefile distclean-am: clean-am distclean-compile distclean-generic \ distclean-tags @@ -692,7 +576,11 @@ install-ps-am: installcheck-am: maintainer-clean: maintainer-clean-am - -rm -rf ./$(DEPDIR) + -rm -f ./$(DEPDIR)/qs_util.Po + -rm -f ./$(DEPDIR)/qsgeo.Po + -rm -f ./$(DEPDIR)/qslog.Po + -rm -f ./$(DEPDIR)/qsre.Po + -rm -f ./$(DEPDIR)/qsrespeed.Po -rm -f Makefile maintainer-clean-am: distclean-am maintainer-clean-generic @@ -712,7 +600,7 @@ uninstall-am: uninstall-binPROGRAMS .MAKE: install-am install-strip -.PHONY: CTAGS GTAGS TAGS all all-am check check-am clean \ +.PHONY: CTAGS GTAGS TAGS all all-am am--depfiles check check-am clean \ clean-binPROGRAMS clean-generic cscopelist-am ctags ctags-am \ distclean distclean-compile distclean-generic distclean-tags \ distdir dvi dvi-am html html-am info info-am install \ diff --git a/tools/src/char.h b/tools/src/char.h index a703691..405a370 100644 --- a/tools/src/char.h +++ b/tools/src/char.h @@ -4,7 +4,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with diff --git a/tools/src/qs_apo.c b/tools/src/qs_apo.c deleted file mode 100644 index 67f4027..0000000 --- a/tools/src/qs_apo.c +++ /dev/null @@ -1,135 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qs_apo.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <pthread.h> -#include <stdlib.h> -#include <string.h> -#include <ctype.h> -#include <stdarg.h> -#include <fcntl.h> -#include <dirent.h> -#include <unistd.h> -#include <errno.h> -#include <pwd.h> - -/* apr/apr-util */ -#include <apr.h> -#include <apr_base64.h> -#include <apr_pools.h> -#include <apr_strings.h> -#include <apr_thread_proc.h> -#include <apr_file_io.h> -#include <apr_time.h> - -#include "qs_util.h" -#include "qs_apo.h" - -static apr_table_t *qs_args(apr_pool_t *pool, const char *line) { - char *last = apr_pstrdup(pool, line); - apr_table_t* table = apr_table_make(pool, 10); - char *val; - while((val = apr_strtok(NULL, " ", &last))) { - apr_table_addn(table, val, ""); - } - return table; -} - -static void qs_failedexec(const char *msg, const char *cmd, apr_status_t status) { - char buf[MAX_LINE]; - apr_strerror(status, buf, sizeof(buf)); - fprintf(stderr, "ERROR %s '%s': '%s'\n", msg, cmd, buf); - exit(1); -} - -/** - * Reads a passphrase using the defined passphrase getter (executes - * the program and reads the passphras from stdout). - * - * @param pool To allocate memory - * @param prg Path of the program to exectue - * @return The passphrase - */ -char *qs_readpwd(apr_pool_t *pool, const char *prg) { - apr_status_t status; - apr_proc_t proc; - const char **args; - apr_table_entry_t *entry; - char *last; - char *copy = apr_pstrdup(pool, prg); - char *cmd = apr_strtok(copy, " ", &last); - apr_table_t *a = qs_args(pool, prg); - int i; - apr_procattr_t *attr; - apr_size_t len = MAX_LINE; - char *buf = apr_pcalloc(pool, len); - - args = apr_pcalloc(pool, (apr_table_elts(a)->nelts + 1) * sizeof(const char *)); - entry = (apr_table_entry_t *) apr_table_elts(a)->elts; - for(i = 0; i < apr_table_elts(a)->nelts; i++) { - args[i] = entry[i].key; - } - args[i] = NULL; - - if(cmd == NULL) { - qs_failedexec("can't read password, invalid executable", prg, APR_EGENERAL); - } - if((status = apr_procattr_create(&attr, pool)) != APR_SUCCESS) { - qs_failedexec("while reading password from executable", prg, status); - } - if((status = apr_procattr_cmdtype_set(attr, APR_PROGRAM_PATH)) != APR_SUCCESS) { - qs_failedexec("while reading password from executable", prg, status); - } - if((status = apr_procattr_detach_set(attr, 0)) != APR_SUCCESS) { - qs_failedexec("while reading password from executable", prg, status); - } - if((status = apr_procattr_io_set(attr, APR_FULL_BLOCK, APR_FULL_BLOCK, APR_NO_PIPE)) != APR_SUCCESS) { - qs_failedexec("while reading password from executable", prg, status); - } - if((status = apr_proc_create(&proc, cmd, args, NULL, attr, pool)) != APR_SUCCESS) { - qs_failedexec("could not execute program", prg, status); - } else { - char *e; - status = apr_proc_wait(&proc, NULL, NULL, APR_WAIT); - if(status != APR_CHILD_DONE && status != APR_SUCCESS) { - qs_failedexec("while reading password from executable", prg, status); - } - status = apr_file_read(proc.out, buf, &len); - if(status != APR_SUCCESS) { - qs_failedexec("failed to read password from program", prg, status); - } - e = buf; - while(e && e[0]) { - if((e[0] == LF) || (e[0] == CR)) { - e[0] = '\0'; - } else { - e++; - } - } - } - return buf; -} diff --git a/tools/src/qs_apo.h b/tools/src/qs_apo.h deleted file mode 100644 index 4316571..0000000 --- a/tools/src/qs_apo.h +++ /dev/null @@ -1,31 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -#ifndef QS_APO_H -#define QS_APO_H - -char *qs_readpwd(apr_pool_t *pool, const char *prg); - -#endif diff --git a/tools/src/qs_util.c b/tools/src/qs_util.c index ddf1e89..9a557a3 100644 --- a/tools/src/qs_util.c +++ b/tools/src/qs_util.c @@ -4,7 +4,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with diff --git a/tools/src/qs_util.h b/tools/src/qs_util.h index fa0bc1c..09abeab 100644 --- a/tools/src/qs_util.h +++ b/tools/src/qs_util.h @@ -4,7 +4,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -29,8 +29,8 @@ /* ---------------------------------- * version info * ---------------------------------- */ -static const char man_version[] = "11.74"; -static const char man_date[] = "May 2023"; +static const char man_version[] = "11.76"; +static const char man_date[] = "January 2025"; /* ---------------------------------- * definitions diff --git a/tools/src/qscheck.c b/tools/src/qscheck.c deleted file mode 100644 index 4b75c36..0000000 --- a/tools/src/qscheck.c +++ /dev/null @@ -1,413 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * qscheck.c: Monitor testing tcp connectivity to servers used by mod_proxy. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qscheck.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <stdlib.h> -#include <string.h> -#include <netdb.h> -#include <sys/types.h> -#include <sys/socket.h> -#include <unistd.h> -#include <fcntl.h> -#include <ctype.h> -#include <arpa/inet.h> - -#include "qs_util.h" - -//#include <config.h> - -#define CR 13 -#define LF 10 -#define QS_TIMEOUT 2 -#define QS_PROXYP "proxypass " -#define QS_PROXYP_TAB "proxypass\t" -#define QS_PROXYPR "proxypassreverse " -#define QS_PROXYPR_TAB "proxypassreverse\t" -#define QS_PROXYR "proxyremote " -#define QS_PROXYR_TAB "proxyremote\t" -#define QS_INCLUDE "nclude " -#define QS_INCLUDE_TAB "nclude\t" -#define QS_SERVERROOT "ServerRoot " -#define QS_SERVERROOT_TAB "ServerRoot\t" - -static int m_verbose = 0; -static char ServerRoot[1024]; -static char *checkedHosts = NULL; - -/** - * Prints usage text - */ -static void usage(char *cmd) { - printf("\n"); - printf("Monitor program testing the TCP connectivity to servers.\n"); - printf("\n"); - printf("Usage: %s -c <httpd.conf> [-v]\n", cmd); - printf("\n"); - printf("Verifies the connectivity to the server referred either\n"); - printf("by the ProxyPass, ProxyPassReverse, or ProxyReverse\n"); - printf("directive used by mod_proxy.\n"); - printf("\n"); - printf("You may alternatively use \"%s -i <hostname>:<port>\" if\n", cmd); - printf("you want to check the TCP connectivity to a single host.\n"); - printf("\n"); - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - exit(1); -} - -/** - * Opens a tcp connection - */ -static int ping(unsigned long address, int port) { - int status = 0; - struct sockaddr_in addr; - int skt; - addr.sin_addr.s_addr = address; - addr.sin_port = htons(port); - addr.sin_family = PF_INET; - skt = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP); - if(skt != -1) { - int sflags = fcntl(skt,F_GETFL,0); - if(sflags >=0) { - /* set non blocking socket */ - if(fcntl(skt,F_SETFL,sflags|O_NONBLOCK) >=0) { - /* this connect returns immediately */ - int ret = connect(skt, (struct sockaddr*)&addr, sizeof(struct sockaddr_in)); - if(fcntl(skt,F_SETFL,sflags) >=0) { - socklen_t lon = sizeof(int); - int valopt; - fd_set fd_w; - struct timeval tme; - tme.tv_sec = QS_TIMEOUT; - tme.tv_usec = 0; - FD_ZERO(&fd_w); - FD_SET(skt, &fd_w); - /* select returns -1 on timeout, else 1 (connected or refused) */ - if(select(FD_SETSIZE, NULL, &fd_w, NULL, &tme) > 0) { - /* check the status of the socket in order to distinguish between - connected or refused */ - if(getsockopt(skt, SOL_SOCKET, SO_ERROR, (void*)(&valopt), &lon) >= 0) { - if(!valopt) { - /* UP ! */ - status = 1; - } - } - } - } - } - } - } - return status; -} - -/** - * resolves host address - */ -static unsigned long getAddress(const char *hostname) { - int ip = 1; - int i = 0; - unsigned long address = 0L; - struct hostent *hoste; - for(i = 0; i < (int) strlen(hostname); i++) { - if((!isdigit((int) hostname[i])) && (hostname[i] != '.')) { - ip = 0; - break; - } - } - if (ip) { - address = inet_addr(hostname); - if(address == -1) { - return 0L; - } - } else { - hoste = gethostbyname(hostname); - if (!hoste || !hoste->h_addr_list[ 0 ]) { - /* can't resolve host name */ - return 0L; - } - address = ((struct in_addr*)hoste->h_addr_list[ 0 ])->s_addr; - } - return address; -} - -/* - * Checks a single host (parse host string, resolve address, ping). - */ -static int checkHost(const char *cmd, const char *filename, int ln, char *abs_url) { - int status = 1; - char *schema = abs_url; - char *host = NULL; - char *ports = NULL; - int port = 0; - char hp[1024]; - unsigned long address; - char *x = strstr(abs_url, "://"); - if(x == NULL) { - if(m_verbose) { - fprintf(stderr,"[%s]: ERROR, wrong syntax <%s> in %s on line %d\n", - cmd, abs_url, filename, ln); - } - return 0; - } - x[0] = '\0'; x = x + strlen("://"); - host = x; - ports = strchr(x, ':'); - if(ports != NULL) { - ports[0] = '\0'; ports++; - x = strchr(ports, '/'); - if(x == NULL) { - int i; - x = ports; - for(i=0;(x[i] != ' ') && (x[i] != '\t') && (x[i] != '\0'); i++); - x[i] = '\0'; - } else { - x[0] = '\0'; - } - port = atoi(ports); - } else { - ports = strchr(x, '/'); - if(ports == NULL) { - int i; - for(i=0;(x[i] != ' ') && (x[i] != '\t') && (x[i] != '\0'); i++); - x[i] = '\0'; - } else { - ports[0] = '\0'; - } - if(strcmp(schema, "http") == 0) { - port = 80; - } else { - port = 443; - } - } - /* check each host only once */ - snprintf(hp, sizeof(hp), "#%s:%d#", host, port); - if(checkedHosts && strstr(checkedHosts, hp) != NULL) { - /* already checked */ - return 1; - } - if(checkedHosts == NULL) { - checkedHosts = calloc(1, strlen(hp) + 1); - strcpy(checkedHosts, hp); - } else { - int pl = strlen(checkedHosts) +strlen(hp) + 1; - char *p = calloc(1, pl); - snprintf(p, pl, "%s%s", checkedHosts, hp); - free(checkedHosts); - checkedHosts = p; - } - /* resolve address */ - address = getAddress(host); - if(address == 0L) { - fprintf(stderr,"[%s]: ERROR, could not resolve hostname %s\n", cmd, host); - return -1; - } - /* check connection */ - if(ping(address, port)) { - if(m_verbose) { - printf("[%s]: %s:%d Up\n", cmd, host, port); - } - return 1; - } else { - printf("[%s]: %s:%d Down\n", cmd, host, port); - return 0; - } -} - -/** - * Open file and check every ProxyPass* or ProxyR* entry. - * - follows include ... directive - * - determines serverroot - */ -static int checkFile(const char *cmd, const char *filename) { - int status = 1; - int ln = 0; - char line[1024]; - FILE *f = fopen(filename, "r"); - if(f == NULL) { - if(ServerRoot[0] != '\0') { - char fqfile[2048]; - snprintf(fqfile, sizeof(fqfile), "%s/%s", ServerRoot, filename); - f = fopen(fqfile, "r"); - } - } - if(f == NULL) { - fprintf(stderr,"[%s]: ERROR, could not open file %s\n", cmd, filename); - return 0; - } - - while(!qs_getLinef(line, sizeof(line), f)) { - char *command = NULL; - int cmd_len = 0; - int to = 0; - while(line[to]) { - line[to] = tolower(line[to]); - to++; - } - ln++; - command = strstr(line, QS_PROXYP); - cmd_len = strlen(QS_PROXYP); - if(command == NULL) command = strstr(line, QS_PROXYP_TAB); - if(command == NULL) { - command = strstr(line, QS_PROXYPR); - cmd_len = strlen(QS_PROXYPR); - } - if(command == NULL) command = strstr(line, QS_PROXYPR_TAB); - if(command == NULL) { - command = strstr(line, QS_PROXYR); - cmd_len = strlen(QS_PROXYR); - } - if(command == NULL) command = strstr(line, QS_PROXYR_TAB); - if(command && strchr(line, '#') == 0) { - /* command = cmd url schema://host[:port]/url */ - char *abs_url = &command[cmd_len]; - int i, j; - - /* get the url */ - for(i=0;(abs_url[i] == ' ') || (abs_url[i] == '\t'); i++); - abs_url = &abs_url[i]; - - /* skip url */ - for(i=0;(abs_url[i] != ' ') && (abs_url[i] != '\t') && (abs_url[i] != '\0'); i++); - abs_url = &abs_url[i]; - - /* get schema://host[:port]/url */ - for(i=0;(abs_url[i] == ' ') || (abs_url[i] == '\t'); i++); - abs_url = &abs_url[i]; - - /* ping */ - if(abs_url && abs_url[0] != '\0' && abs_url[0] != '!') { - status = status & checkHost(cmd, filename, ln, abs_url); - } - } else { - /* include commands */ - command = strstr(line, QS_INCLUDE); - if(command == NULL) command = strstr(line, QS_INCLUDE_TAB); - if(command && strchr(line, '#') == 0) { - char *file = &command[strlen(QS_INCLUDE)]; - int i, j; - /* get the value */ - for(i=0;(file[i] == ' ') || (file[i] == '\t'); i++); - /* delete spaces at the end of the value */ - if(&file[i] != '\0') { - for(j=i+1;(file[j] != ' ') && (file[j] != '\t') && (file[j] != '\0'); j++); - file[j] = '\0'; - } - file = &file[i]; - status = status & checkFile(cmd, file); - } else { - /* server root */ - command = strstr(line, QS_SERVERROOT); - if(command == NULL) command = strstr(line, QS_SERVERROOT_TAB); - if(command && strchr(line, '#') == 0) { - char *sr = &command[strlen(QS_SERVERROOT)]; - int i, j; - /* get the value */ - for(i=0;(sr[i] == ' ') || (sr[i] == '\t'); i++); - /* delete spaces at the end of the value */ - if(&sr[i] != '\0') { - for(j=i+1;(sr[j] != ' ') && (sr[j] != '\t') && (sr[j] != '\0'); j++); - sr[j] = '\0'; - } - strcpy(ServerRoot, &sr[i]); - } - } - } - } - fclose(f); - return status; -} - -int main(int argc, char **argv) { - char *config = NULL; - char *cmd = strrchr(argv[0], '/'); - char *single = NULL; - int status = 1; - if(cmd == NULL) { - cmd = argv[0]; - } else { - cmd++; - } - ServerRoot[0] = '\0'; - while(argc >= 1) { - if(strcmp(*argv,"-c") == 0) { - if (--argc >= 1) { - config = *(++argv); - } - } else if(strcmp(*argv,"-i") == 0) { - if (--argc >= 1) { - single = *(++argv); - } - } else if(strcmp(*argv,"-v") == 0) { - m_verbose = 1; - } - argc--; - argv++; - } - if(single) { - char *hostName = single; - char *portNumber = strchr(single, ':'); - if(portNumber) { - unsigned long addr; - int prt; - portNumber[0] = '\0'; - portNumber++; - addr = getAddress(hostName); - prt = atoi(portNumber); - if(addr && prt) { - if(ping(addr, prt)) { - if(m_verbose) { - printf("[%s]: %s:%d Up\n", cmd, hostName, prt); - } - status = 1; - } else { - printf("[%s]: %s:%d Down\n", cmd, hostName, prt); - status = 0; - } - } else { - // could not resolve - fprintf(stderr,"[%s]: ERROR, unknown host/port\n", cmd); - status = 0; - } - } else { - // invalid input - fprintf(stderr,"[%s]: ERROR, invalid format\n", cmd); - status = 0; - } - } else { - if(config == NULL) { - usage(cmd); - } - status = checkFile(cmd, config); - } - if(status == 0) { - fprintf(stderr,"[%s]: ERROR, check failed\n", cmd); - exit(1); - } - printf("[%s]: OK, check successful\n", cmd); - return 0; -} diff --git a/tools/src/qsdt.c b/tools/src/qsdt.c deleted file mode 100644 index b2c9747..0000000 --- a/tools/src/qsdt.c +++ /dev/null @@ -1,336 +0,0 @@ -/** - * Utility for the quality of service module mod_qos. - * - * qsdt.c: simple tool to measure the elapse time between - * related log messages - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -#include <stdio.h> -#include <string.h> - -#include <stdlib.h> -#include <unistd.h> -#include <time.h> - -#include <sys/types.h> -#include <regex.h> - -#include <apr.h> -#include <apr_portable.h> -#include <apr_strings.h> - -#include "qs_util.h" - -#define MAX_REG_MATCH 10 - -#define TIMESTR "%H:%M:%S" -#define TIMEEX "([0-9]{2}:[0-9]{2}:[0-9]{2})[.,]([0-9]{3})" - -typedef struct { - time_t seconds; - int milliseconds; - char *id; -} entry_t; - - -static void usage(const char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s calculates the elapsed time between two related log messages.\n", cmd); - printf("\n"); - - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s [-t <regex>] -i <regex> -s <regex> -e <regex> [-v] [<path>]\n", man ? "" : "Usage: ", cmd); - printf("\n"); - - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "%s is a simple tool to search two different messages\n", cmd); - qs_man_print(man, "in a log file and calculates the elapsed time between these\n"); - qs_man_print(man, "lines. The two log messages need a common identifier such an\n"); - qs_man_print(man, "unique request id (UNIQUE_ID), a thread id, or a transaction\n"); - qs_man_print(man, "code.\n"); - printf("\n"); - - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -t <regex>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines a pattern (regular expression) matching the log line's\n"); - qs_man_print(man, " timestamp. The pattern must include two sub-expressions, one matching\n"); - qs_man_print(man, " hours, minutes and seconds the other matching the milliseconds.\n"); - qs_man_print(man, " Default pattern is "TIMEEX"\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -i <regex>\n"); - if(man) printf("\n"); - qs_man_print(man, " Pattern (regular expression) matching the identifier which the two\n"); - qs_man_print(man, " messages have in common. The sub-expression defines the part which\n"); - qs_man_print(man, " needs to be extracted from the matching string. Note: You can also\n"); - qs_man_print(man, " use the start (-s) and end (-e) pattern to define the sub-expression\n"); - qs_man_print(man, " matching this identifier.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -s <regex>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the pattern (regular expression or literal string)\n"); - qs_man_print(man, " identifying the first (start) of the two messages.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -e <regex>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the pattern (regular expression or literal string)\n"); - qs_man_print(man, " identifying the second (end) of the two messages.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -v\n"); - if(man) printf("\n"); - qs_man_print(man, " Verbose mode.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " <path>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the input file to process. %s reads from\n", cmd); - qs_man_print(man, " from standard input if this parameter is omitted.\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - printf("Sample command line arguments:\n"); - printf("\n"); - } else { - printf(" Sample arguments:\n"); - } - qs_man_println(man, " -i ' ([a-z0-9]+) [A-Z]+ ' -s 'Received Request' -e 'Received Response'\n"); - printf("\n"); - qs_man_println(man, " matching those sample log messages:\n"); - qs_man_println(man, " 2018-03-12 16:34:08.653 threadid23 INFO Received Request\n"); - qs_man_println(man, " 2018-03-13 16:35:09.891 threadid23 DEBUG MessageHandler Received Response\n"); - printf("\n"); - if(man) { - printf(".SH NOTE\n"); - } else { - printf("Notes:\n"); - } - qs_man_println(man, "The four patterns (t,i,s,e) are concatenated into two search patterns:\n"); - qs_man_println(man, " first (start): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[s ]\n"); - qs_man_println(man, " second (end): [t (HH:MM:SS)(SSS) ].*[i (id) ].*[e ]\n"); - printf("\n"); - qs_man_print(man, "And the three sub-expression are used to extract the timestamp and the\n"); - qs_man_print(man, "unique identifier that the start and end message have in common.\n"); - qs_man_print(man, "This means that you could specify the sub-expression for the unique\n"); - qs_man_print(man, "identifier in the start (-s) or end (-e) pattern alternatively, e.g. in\n"); - qs_man_print(man, "case the identifier is at the end of the log line.\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - - -int main(int argc, const char *const argv[]) { - FILE *file; - char line[MAX_LINE]; - int verbose = 0; - - const char *cmd = strrchr(argv[0], '/'); - - apr_pool_t *pool; - apr_table_t *inmsg; - - regmatch_t ma[MAX_REG_MATCH]; - regex_t pregstart; - regex_t pregend; - - const char *timeex = TIMEEX; - const char *idex = NULL; - const char *startex = NULL; - const char *endex = NULL; - const char *filename = NULL; - - char *regexStr; - - apr_app_initialize(&argc, &argv, NULL); - apr_pool_create(&pool, NULL); - inmsg = apr_table_make(pool, 100); - - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-t") == 0) { - if (--argc >= 1) { - timeex = *(++argv); - } - } else if(strcmp(*argv,"-i") == 0) { - if (--argc >= 1) { - idex = *(++argv); - } - } else if(strcmp(*argv,"-s") == 0) { - if (--argc >= 1) { - startex = *(++argv); - } - } else if(strcmp(*argv,"-e") == 0) { - if (--argc >= 1) { - endex = *(++argv); - } - } else if(strcmp(*argv,"-v") == 0) { - verbose = 1; - } else if(strcmp(*argv,"-h") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } else { - filename = *argv; - } - argc--; - argv++; - } - - if(idex == NULL || startex == NULL || endex == NULL) { - usage(cmd, 0); - } - - if(filename) { - file = fopen(filename, "r"); - if(!file) { - fprintf(stderr, "ERROR, failed to open the log file '%s'\n", filename); - exit(1); - } - } else { - file = stdin; - } - - - regexStr = apr_psprintf(pool, "%s.*%s.*%s", timeex, idex, startex); - if(verbose) { - fprintf(stderr, "start pattern: %s\n", regexStr); - } - if(regcomp(&pregstart, regexStr, REG_EXTENDED)) { - fprintf(stderr, "ERROR, could not compile %s\n", regexStr); - exit(1); - }; - regexStr = apr_psprintf(pool, "%s.*%s.*%s", timeex, idex, endex); - if(verbose) { - fprintf(stderr, "end pattern: %s\n", regexStr); - } - if(regcomp(&pregend, regexStr, REG_EXTENDED)) { - fprintf(stderr, "ERROR, could not compile %s\n", regexStr); - exit(1); - }; - - while(fgets(line, MAX_LINE-1, file) != NULL) { - char *hms; - char *ms; - char *id; - if(regexec(&pregstart, line, MAX_REG_MATCH, ma, 0) == 0) { - entry_t *entry = calloc(1, sizeof(entry_t)); - struct tm tm; - if(ma[3].rm_so == -1) { - fprintf(stderr, "ERROR, invalid regular expression (missing sub-expression in pattern)\n"); - exit(1); - } - hms = &line[ma[1].rm_so]; - ms = &line[ma[2].rm_so]; - id = &line[ma[3].rm_so]; - line[ma[1].rm_eo] = '\0'; - line[ma[2].rm_eo] = '\0'; - line[ma[3].rm_eo] = '\0'; - strptime(hms, TIMESTR, &tm); - entry->seconds = mktime(&tm); - entry->milliseconds = atoi(ms); - entry->id = calloc(strlen(id)+1, sizeof(char)); - sprintf(entry->id, "%s", id); - if(verbose) { - fprintf(stderr, "START [%s][%s][%s] %lu %d\n", - hms, ms, id, entry->seconds, entry->milliseconds); - } - apr_table_setn(inmsg, entry->id, (char *)entry); - } else if(regexec(&pregend, line, MAX_REG_MATCH, ma, 0) == 0) { - entry_t entry; - entry_t *start; - struct tm tm; - if(ma[3].rm_so == -1) { - fprintf(stderr, "ERROR, invalid regular expression (missing sub-expression in pattern)\n"); - exit(1); - } - hms = &line[ma[1].rm_so]; - ms = &line[ma[2].rm_so]; - id = &line[ma[3].rm_so]; - line[ma[1].rm_eo] = '\0'; - line[ma[2].rm_eo] = '\0'; - line[ma[3].rm_eo] = '\0'; - strptime(hms, TIMESTR, &tm); - entry.seconds = mktime(&tm); - entry.milliseconds = atoi(ms); - if(verbose) { - fprintf(stderr, "END [%s][%s][%s] %lu %d\n", - hms, ms, id, entry.seconds, entry.milliseconds); - } - start = (entry_t *)apr_table_get(inmsg, id); - if(start) { - printf("@%s %s %10lu [ms]\n", - line, - id, - (entry.seconds-start->seconds)*1000 + entry.milliseconds-start->milliseconds); - apr_table_unset(inmsg, id); - free(start->id); - free(start); - } - } - } - fclose(file); - - return 0; -} diff --git a/tools/src/qsexec.c b/tools/src/qsexec.c deleted file mode 100644 index 8a56b3e..0000000 --- a/tools/src/qsexec.c +++ /dev/null @@ -1,376 +0,0 @@ -/* -*-mode: c; indent-tabs-mode: nil; c-basic-offset: 2; -*- - */ -/** - * Command line execution utility for the quality of service module mod_qos. - * - * See http://mod-qos.sourceforge.net/ for further details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qsexec.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -/* system */ -#include <stdio.h> -#include <string.h> - -#include <stdlib.h> -#include <unistd.h> -#include <time.h> - -/* apr */ -#include <apr.h> -#include <apr_strings.h> -#include <apr_file_io.h> -#include <apr_time.h> -#include <apr_getopt.h> -#include <apr_general.h> -#include <apr_lib.h> -#include <apr_portable.h> -#include <apr_support.h> - -#define PCRE2_CODE_UNIT_WIDTH 8 -#include <pcre2.h> - -#include "qs_util.h" - -#ifndef POSIX_MALLOC_THRESHOLD -#define POSIX_MALLOC_THRESHOLD (10) -#endif - -/* same as APR_SIZE_MAX which doesn't appear until APR 1.3 */ -#define QSUTIL_SIZE_MAX (~((apr_size_t)0)) - -typedef struct { - int rm_so; - int rm_eo; -} regmatch_t; - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\n", qs_CMD(cmd), man_date, man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - printf("%s %s- parses the data received via stdin and executes the defined command on a pattern match.\n", - cmd, man ? "\\" : ""); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -e <pattern> [-t <number>:<sec>] [-c <pattern> [<command string>]]\n", man ? "" : "Usage: ", cmd); - qs_man_print(man, " [-p] [-u <user>] <command string>\n"); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "%s reads log lines from stdin and searches for the defined pattern.\n", cmd); - qs_man_print(man, "It executes the defined command string on pattern match.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -e <pattern>\n"); - if(man) printf("\n"); - qs_man_print(man, " Specifies the search pattern causing an event which shall trigger the\n"); - qs_man_print(man, " command.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -t <number>:<sec>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the number of pattern match within the the defined number of\n"); - qs_man_print(man, " seconds in order to trigger the command execution. By default, every\n"); - qs_man_print(man, " pattern match causes a command execution.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -c <pattern> [<command string>]\n"); - if(man) printf("\n"); - qs_man_print(man, " Pattern which clears the event counter. Executes optionally a command\n"); - qs_man_print(man, " if an event command has been executed before.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p\n"); - if(man) printf("\n"); - qs_man_print(man, " Writes data also to stdout (for piped logging).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -u <name>\n"); - if(man) printf("\n"); - qs_man_print(man, " Become another user, e.g. www-data.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " <command string>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the event command string where $0-$9 are substituted by the\n"); - qs_man_print(man, " submatches of the regular expression.\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - } else { - printf("Example:\n"); - } - qs_man_print(man, "Executes the deny.sh script providing the IP address of the\n"); - qs_man_print(man, "client causing a mod_qos(031) messages whenever the log message\n"); - qs_man_print(man, "appears 10 times within at most one minute:\n"); - if(man) printf("\n"); - qs_man_println(man, " ErrorLog \"|/usr/bin/%s -e \\'mod_qos\\(031\\).*, c=([0-9a-zA-Z:.]*)\\' -t 10:60 \\'/usr/local/bin/deny.sh $1\\'\"\n", cmd); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -/* - * Substitutes for $0-$9 within the matching string. - * See ap_pregsub(). - */ -char *qs_pregsub(apr_pool_t *pool, const char *input, - const char *source, size_t nmatch, - qs_regmatch_t pmatch[]) { - const char *src = input; - char *dest, *dst; - char c; - size_t no; - int len; - if(!source) { - return NULL; - } - if(!nmatch) { - return apr_pstrdup(pool, src); - } - /* First pass, find the size */ - len = 0; - while((c = *src++) != '\0') { - if(c == '&') - no = 0; - else if (c == '$' && apr_isdigit(*src)) - no = *src++ - '0'; - else - no = 10; - - if (no > 9) { /* Ordinary character. */ - if (c == '\\' && (*src == '$' || *src == '&')) - src++; - len++; - } - else if (no < nmatch && pmatch[no].rm_so < pmatch[no].rm_eo) { - if(QSUTIL_SIZE_MAX - len <= pmatch[no].rm_eo - pmatch[no].rm_so) { - fprintf(stderr, "ERROR, integer overflow or out of memory condition"); - return NULL; - } - len += pmatch[no].rm_eo - pmatch[no].rm_so; - } - - } - dest = dst = apr_pcalloc(pool, len + 1); - /* Now actually fill in the string */ - src = input; - while ((c = *src++) != '\0') { - if (c == '&') - no = 0; - else if (c == '$' && apr_isdigit(*src)) - no = *src++ - '0'; - else - no = 10; - - if (no > 9) { /* Ordinary character. */ - if (c == '\\' && (*src == '$' || *src == '&')) - c = *src++; - *dst++ = c; - } - else if (no < nmatch && pmatch[no].rm_so < pmatch[no].rm_eo) { - len = pmatch[no].rm_eo - pmatch[no].rm_so; - memcpy(dst, source + pmatch[no].rm_so, len); - dst += len; - } - } - *dst = '\0'; - return dest; -} - -int main(int argc, const char * const argv[]) { - const char *username = NULL; - int nr = 0; - char *line = calloc(1, MAX_LINE_BUFFER+1); - apr_pool_t *pool; - char *cmd = strrchr(argv[0], '/'); - const char *command = NULL; - const char *pattern = NULL; - const char *clearcommand = NULL; - const char *clearpattern = NULL; - int executed = 0; - qs_regex_t *preg; - qs_regex_t *clearpreg; - qs_regmatch_t regm[QS_MAX_REG_MATCH]; - time_t sec = 0; - int threshold = 0; - int counter = 0; - time_t countertime; - static int pass = 0; - apr_app_initialize(&argc, &argv, NULL); - apr_pool_create(&pool, NULL); - - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-e") == 0) { - if (--argc >= 1) { - pattern = *(++argv); - } - } else if(strcmp(*argv,"-u") == 0) { - if (--argc >= 1) { - username = *(++argv); - } - } else if(strcmp(*argv,"-c") == 0) { - if (--argc >= 1) { - clearpattern = *(++argv); - if (argc >=1 && *argv[0] != '-') { - clearcommand = *(++argv); - argc--; - } - } - } else if(argc >= 1 && strcmp(*argv,"-t") == 0) { - if (--argc >= 1) { - char *str = apr_pstrdup(pool, *(++argv)); - char *tme = strchr(str, ':'); - if(tme == NULL) { - fprintf(stderr,"[%s]: ERROR, invalid number:sec format\n", cmd); - exit(1); - } - tme[0] = '\0'; - tme++; - threshold = atoi(str); - sec = atol(tme); - if(threshold == 0 || sec == 0) { - fprintf(stderr,"[%s]: ERROR, invalid number:sec format\n", cmd); - exit(1); - } - } - } else if(argc >= 1 && strcmp(*argv,"-p") == 0) { - pass = 1; - } else if(strcmp(*argv,"-h") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } else { - command = *argv; - } - argc--; - argv++; - } - - if(pattern == NULL || command == NULL) { - usage(cmd, 0); - } - - qs_setuid(username, cmd); - - preg = apr_palloc(pool, sizeof(qs_regex_t)); - if(qs_regcomp(preg, pattern, PCRE2_DOTALL) != 0) { - fprintf(stderr, "ERROR, could not compile '%s'\n", pattern); - exit(1); - } - apr_pool_pre_cleanup_register(pool, preg, qs_pregfree); - if(clearpattern) { - clearpreg = apr_palloc(pool, sizeof(qs_regex_t)); - if(qs_regcomp(clearpreg, clearpattern, PCRE2_DOTALL) != 0) { - fprintf(stderr, "ERROR, could not compile '%s'\n", clearpattern); - exit(1); - } - apr_pool_pre_cleanup_register(pool, clearpattern, qs_pregfree); - } - - while(fgets(line, MAX_LINE_BUFFER, stdin) != NULL) { - size_t len; - nr++; - if(pass) { - printf("%s", line); - fflush(stdout); - } - len = strlen(line); - if(clearpattern && (qs_regexec_len(clearpreg, line, len, QS_MAX_REG_MATCH, regm, 0) >= 0)) { - apr_pool_t *subpool; - apr_pool_create(&subpool, pool); - counter = 0; - countertime = 0; - if(clearcommand && executed) { - char *replaced = qs_pregsub(subpool, clearcommand, line, QS_MAX_REG_MATCH, regm); - if(!replaced) { - fprintf(stderr, "[%s]: ERROR, failed to substitute" - " submatches '%s' in (%s)\n", cmd, clearcommand, line); - } else { - int rc = system(replaced); - } - executed = 0; - } - apr_pool_destroy(subpool); - } else if(qs_regexec_len(preg, line, len, QS_MAX_REG_MATCH, regm, 0) >= 0) { - apr_pool_t *subpool; - char *replaced; - apr_pool_create(&subpool, pool); - replaced = qs_pregsub(subpool, command, line, QS_MAX_REG_MATCH, regm); - if(!replaced) { - fprintf(stderr, "[%s]: ERROR, failed to substitute" - " submatches '%s' in (%s)\n", cmd, command, line); - } else { - counter++; - if(counter == 1) { - countertime = time(NULL); - } - if(counter >= threshold) { - if(countertime + sec >= time(NULL)) { - int rc = system(replaced); - executed = 1; - } - countertime = 0; - counter = 0; - } - } - apr_pool_destroy(subpool); - } - } - - apr_pool_destroy(pool); - return 0; -} diff --git a/tools/src/qsfilter2.c b/tools/src/qsfilter2.c deleted file mode 100644 index 603085e..0000000 --- a/tools/src/qsfilter2.c +++ /dev/null @@ -1,1826 +0,0 @@ -/* -*-mode: c; indent-tabs-mode: nil; c-basic-offset: 2; -*- - */ -/** - * Filter utilities for the quality of service module mod_qos - * used to create allow list rules for request line filters. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qsfilter2.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -/* system */ -#include <stdio.h> -#include <errno.h> -#include <string.h> - -#include <stdlib.h> -#include <unistd.h> -#include <time.h> - -/* apr */ -#include <apr.h> -#include <apr_uri.h> -#include <apr_signal.h> -#include <apr_strings.h> -#include <apr_network_io.h> -#include <apr_file_io.h> -#include <apr_time.h> -#include <apr_getopt.h> -#include <apr_general.h> -#include <apr_lib.h> -#include <apr_portable.h> -#include <apr_thread_proc.h> -#include <apr_thread_cond.h> -#include <apr_thread_mutex.h> -#include <apr_support.h> -//#include <ap_config.h> - -/* OpenSSL */ -#include <openssl/safestack.h> - -#define PCRE2_CODE_UNIT_WIDTH 8 -#include <pcre2.h> - -#include "qs_util.h" - -#define MAX_LINE 32768 -/* 2mb */ -#define MAX_BODY_BUFFER 2097152 -#define CR 13 -#define LF 10 - -typedef enum { - QS_UT_PATH, - QS_UT_QUERY -} qs_url_type_e; - -#define QS_PCRE_RESERVED "{}[]()^$.|*+?\\-" -//#define QS_PCRE_RESERVED "{}[]()^$.|*+?\"'\\-" - -/* reserved (to be escaped): {}[]()^$.|*+?\- */ -#define QS_UNRESERVED "a-zA-Z0-9-\\._~% " -#define QS_GEN ":/\\?#\\[\\]@" -#define QS_SUB "!$&'\\(\\)\\*\\+,;=" -#define QS_SUB_S "!$&\\(\\)\\*\\+,;=" - -#define QS_SIMPLE_PATH_PCRE "(/[a-zA-Z0-9\\-_]+)+[/]?\\.?[a-zA-Z]{0,4}" -#define QS_B64 "([a-z]+[a-z0-9]*[A-Z]+[A-Z0-9]*)" -#define QS_HX "([A-F0-9]*[A-F]+[0-9]+[A-F0-9]*)" - -#define QS_OVECCOUNT 3 - -/* request line detection */ -#define QOSC_REQ "(OPTIONS|GET|HEAD|POST|PUT|DELETE|TRACE|CONNECT|PROPFIND|PROPPATCH|MKCOL|COPY|MOVE|LOCK|UNLOCK|VERSION-CONTROL|REPORT|CHECKOUT|CHECKIN|UNCHECKOUT|MKWORKSPACE|UPDATE|LABEL|MERGE|BASELINE-CONTROL|MKACTIVITY|ORDERPATCH|ACL|PATCH|SEARCH|BCOPY|BDELETE|BMOVE|BPROPFIND|BPROPPATCH|NOTIFY|POLL|SUBSCRIBE|UNSUBSCRIBE|X-MS-ENUMATTS|RPC_IN_DATA|RPC_OUT_DATA) (/[\x20-\x21\x23-\xFF]*) HTTP/" - -qs_regex_t *pcre_b64; -qs_regex_t *pcre_hx; -qs_regex_t *pcre_simple_path; - -#define QOS_DEC_MODE_FLAGS_URL 0x00 -#define QOS_DEC_MODE_FLAGS_HTML 0x01 -#define QOS_DEC_MODE_FLAGS_UNI 0x02 -#define QOS_DEC_MODE_FLAGS_ANSI 0x04 - -/* global variables to store settings */ -static int m_mode = QOS_DEC_MODE_FLAGS_URL; -static int m_base64 = 5; -static int m_verbose = 1; -static int m_path_depth = 1; -static int m_redundant = 1; -static int m_query_pcre = 0; -static int m_query_multi_pcre = 0; -static int m_query_o_pcre = 0; -static int m_query_single_pcre = 0; -static int m_query_len_pcre = 10; -static int m_exit_on_error = 0; -static int m_handler = 0; -static qs_regex_t *m_req_regex = NULL; -static int m_log_req_regex = 0; -static const char *m_pfx = NULL; -static const char *m_filter = NULL; - -typedef struct { - qs_regex_t *pcre; - char *rule; - char *path; - char *query_m_string; - char *query_m_pcre; - int fragment; -} qs_rule_t; - - -/* openssl stack compare function used to sort the rules */ -int STACK_qs_cmp(const char * const *_pA, const char * const *_pB) { - qs_rule_t *pA=*(( qs_rule_t **)_pA); - qs_rule_t *pB=*(( qs_rule_t **)_pB); - return strcmp(pA->rule,pB->rule); -} - -/* compiles a pcre (exit on error) */ -static qs_regex_t *qos_pcre_compile(apr_pool_t *pool, char *pattern, int option) { - qs_regex_t *preg = apr_palloc(pool, sizeof(qs_regex_t)); - if(qs_regcomp(preg, pattern, PCRE2_DOTALL|option) != 0) { - fprintf(stderr, "ERROR, rule <%s> could not compile pcre\n", pattern); - exit(1); - } - apr_pool_pre_cleanup_register(pool, preg, qs_pregfree); - return preg; -} - -/* tries to detect base64/hex patterns (mix of upper and lower case characters) */ -static char *qos_detect_b64(char *line, int silent) { - qs_regmatch_t regm[QS_MAX_REG_MATCH]; - int rc_c = qs_regexec_len(pcre_b64, line, strlen(line), QS_MAX_REG_MATCH, regm, 0); - if(rc_c >= 0) { - if((m_verbose > 1) && !silent) printf(" B64: %.*s\n", - regm[0].rm_eo - regm[0].rm_so, &line[regm[0].rm_so]); - return &line[regm[0].rm_so]; - } - rc_c = qs_regexec_len(pcre_hx, line, strlen(line), QS_MAX_REG_MATCH, regm, 0); - if(rc_c >= 0) { - if((m_verbose > 1) && !silent) printf(" HX: %.*s\n", - regm[0].rm_eo - regm[0].rm_so, &line[regm[0].rm_so]); - return &line[regm[0].rm_so]; - } - return NULL; -} - -/* escape double quotes and backslash (to be used for Apache directive) */ -static char *qs_apache_escape(apr_pool_t *pool, const char *line) { - char *ret = apr_pcalloc(pool, strlen(line) * 4); - int i = 0; - const char *in = line; - while(in && in[0]) { - if(in[0] == '"') { - ret[i] = '\\'; - i++; - ret[i] = 'x'; - i++; - ret[i] = '2'; - i++; - ret[i] = '2'; - i++; - } else if(in[0] == '\\' && in[1] == '\\') { - ret[i] = '\\'; - i++; - ret[i] = 'x'; - i++; - ret[i] = '5'; - i++; - ret[i] = 'c'; - i++; - in++; - } else { - ret[i] = (char)in[0]; - i++; - } - in++; - } - return ret; -} - -/* escape a string in order to be used withn a pcre */ -static char *qos_escape_pcre(apr_pool_t *pool, char *line) { - int i = 0; - unsigned char prev = 0; - unsigned char *in = (unsigned char *)line; - char *ret = apr_pcalloc(pool, strlen(line) * 4); - int reti = 0; - if(strlen(line) == 0) return ""; - while(in[i]) { - if(strchr(QS_PCRE_RESERVED, in[i]) != NULL) { - if(prev && (prev == '\\')) { - /* already escaped */ - ret[reti] = in[i]; - reti++; - } else if(prev && (in[i] == '\\') && (strchr(QS_PCRE_RESERVED, in[i+1]) != NULL)) { - /* escape char */ - ret[reti] = in[i]; - reti++; - } else { - ret[reti] = '\\'; - reti++; - ret[reti] = in[i]; - reti++; - } - } else if((in[i] < ' ') || (in[i] > '~')) { - sprintf(&ret[reti], "\\x%02x", in[i]); - reti = reti + 4; - } else { - ret[reti] = in[i]; - reti++; - } - prev = in[i]; - i++; - } - return ret; -} - -/* helper for url decoding */ -static int qos_hex2c(const char *x) { - int i, ch; - ch = x[0]; - if (isdigit(ch)) { - i = ch - '0'; - }else if (isupper(ch)) { - i = ch - ('A' - 10); - } else { - i = ch - ('a' - 10); - } - i <<= 4; - - ch = x[1]; - if (isdigit(ch)) { - i += ch - '0'; - } else if (isupper(ch)) { - i += ch - ('A' - 10); - } else { - i += ch - ('a' - 10); - } - return i; -} - -static int qos_ishex(char x) { - if((x >= '0') && (x <= '9')) return 1; - if((x >= 'a') && (x <= 'f')) return 1; - if((x >= 'A') && (x <= 'F')) return 1; - return 0; -} - -/* url decoding */ -static int qos_unescaping(char *x) { - int i, j, ch; - if (x[0] == '\0') - return 0; - for (i = 0, j = 0; x[i] != '\0'; i++, j++) { - ch = x[i]; - if(ch == '%' && qos_ishex(x[i + 1]) && qos_ishex(x[i + 2])) { - ch = qos_hex2c(&x[i + 1]); - i += 2; - } else if((m_mode & QOS_DEC_MODE_FLAGS_UNI) && - ((ch == '%') || (ch == '\\')) && - ((x[i + 1] == 'u') || (x[i + 1] == 'U')) && - qos_ishex(x[i + 2]) && - qos_ishex(x[i + 3]) && - qos_ishex(x[i + 4]) && - qos_ishex(x[i + 5])) { - /* unicode %uXXXX */ - ch = qos_hex2c(&x[i + 4]); - if((ch > 0x00) && (ch < 0x5f) && - ((x[i + 2] == 'f') || (x[i + 2] == 'F')) && - ((x[i + 3] == 'f') || (x[i + 3] == 'F'))) { - ch += 0x20; - } - i += 5; - } else if (ch == '\\' && (x[i + 1] == 'x') && qos_ishex(x[i + 2]) && qos_ishex(x[i + 3])) { - ch = qos_hex2c(&x[i + 2]); - i += 3; - } else if (ch == '+') { - ch = ' '; - } - x[j] = ch; - } - x[j] = '\0'; - if(strlen(x) != j) { - fprintf(stderr, "WARNING, found escaped null char %s\n", x); - } - return j; -} - -static int qos_fgetline(char *s, int n, FILE *f) { - register int i = 0; - while (1) { - s[i] = (char) fgetc(f); - if (s[i] == CR) { - s[i] = fgetc(f); - } - if ((s[i] == 0x4) || (s[i] == LF) || (i == (n - 1))) { - s[i] = '\0'; - return (feof(f) ? 1 : 0); - } - ++i; - } -} - -/* init global pcre */ -static void qos_init_pcre(apr_pool_t *pool) { - char buf[1024]; - sprintf(buf, "%s{%d,}", QS_B64, m_base64); - pcre_b64 = qos_pcre_compile(pool, buf, 0); - sprintf(buf, "%s{%d,}", QS_HX, m_base64); - pcre_hx = qos_pcre_compile(pool, buf, 0); - pcre_simple_path = qos_pcre_compile(pool, "^"QS_SIMPLE_PATH_PCRE"$", 0); - m_req_regex = qos_pcre_compile(pool, QOSC_REQ, 0); -} - -static void usage(char *cmd, int man) { - char space[1024]; - memset(space, ' ', 1024); - space[strlen(cmd)] = '\0'; - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - an utility to generate mod_qos request line rules out from\n", - cmd); - qs_man_print(man, "existing access/audit log data.\n"); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -i <path> [-c <path>] [-d <num>] [-h] [-b <num>]\n", man ? "" : "Usage: ", cmd); - qs_man_print(man, " %s [-p|-s|-m|-o] [-l <len>] [-n] [-e] [-u 'uni']\n", space); - qs_man_print(man, " %s [-k <prefix>] [-t] [-f <path>] [-v 0|1|2]\n", space); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, " mod_qos implements a request filter which validates each request\n"); - qs_man_print(man, " line. The module supports both, negative and positive security\n"); - qs_man_print(man, " model. The QS_Deny* directives are used to specify request line\n"); - qs_man_print(man, " patterns which are not allowed to access the server (negative\n"); - qs_man_print(man, " security model / deny list). These rules are used to restrict\n"); - qs_man_print(man, " access to certain resources which should not be available to\n"); - qs_man_print(man, " users or to protect the server from malicious patterns. The\n"); - qs_man_print(man, " QS_Permit* rules implement a positive security model (allow list).\n"); - qs_man_print(man, " These directives are used to define allowed request line patterns.\n"); - qs_man_print(man, " Request which do not match any of these patterns are not allowed\n"); - qs_man_print(man, " to access the server.\n"); - if(man) printf("\n\n"); - qs_man_print(man, " %s is an audit log analyzer used to generate filter\n", cmd); - qs_man_print(man, " rules (perl compatible regular expressions) which may be used\n"); - qs_man_print(man, " by mod_qos to deny access for suspect requests (QS_PermitUri rules).\n"); - qs_man_print(man, " It parses existing audit log files in order to generate request\n"); - qs_man_print(man, " patterns covering all allowed requests.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -i <path>\n"); - if(man) printf("\n"); - qs_man_print(man, " Input file containing request URIs.\n"); - qs_man_print(man, " The URIs for this file have to be extracted from the servers\n"); - qs_man_print(man, " access logs. Each line of the input file contains a request\n"); - qs_man_print(man, " URI consisting of a path and and query.\n"); - printf("\n"); - printf(" Example:\n"); - qs_man_println(man, " /aaa/index.do\n"); - qs_man_println(man, " /aaa/edit?image=1.jpg\n"); - qs_man_println(man, " /aaa/image/1.jpg\n"); - qs_man_println(man, " /aaa/view?page=1\n"); - qs_man_println(man, " /aaa/edit?document=1\n"); - printf("\n"); - qs_man_print(man, " These access log data must include current request URIs but\n"); - qs_man_print(man, " also request lines from previous rule generation steps. It\n"); - qs_man_print(man, " must also include request lines which cover manually generated\n"); - qs_man_print(man, " rules.\n"); - qs_man_print(man, " You may use the 'qos-path' and 'qos-query' variables to create\n"); - qs_man_print(man, " an audit log containing all request data (path and query/body data).\n"); - qs_man_print(man, " Example: 'CustomLog audit_log %{qos-path}n%{qos-query}n'.\n"); - qs_man_print(man, " See also http://mod-qos.sourceforge.net#qsfiltersample about\n"); - qs_man_print(man, " the module settings.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -c <path>\n"); - if(man) printf("\n"); - qs_man_print(man, " mod_qos configuration file defining QS_DenyRequestLine and\n"); - qs_man_print(man, " QS_PermitUri directives.\n"); - qs_man_print(man, " %s generates rules from access log data automatically.\n", cmd); - qs_man_print(man, " Manually generated rules (QS_PermitUri) may be provided from\n"); - qs_man_print(man, " this file. Note: each manual rule must be represented by a\n"); - qs_man_print(man, " request URI in the input data (-i) in order to make sure not\n"); - qs_man_print(man, " to be deleted by the rule optimisation algorithm.\n"); - qs_man_print(man, " QS_Deny* rules from this file are used to filter request lines\n"); - qs_man_print(man, " which should not be used for allow list rule generation.\n"); - printf("\n"); - printf(" Example:\n"); - qs_man_println(man, " # manually defined allow list rule:\n"); - qs_man_println(man, " QS_PermitUri +view deny \"^[/a-zA-Z0-9]+/view\\?(page=[0-9]+)?$\"\n"); - qs_man_println(man, " # filter unwanted request line patterns:\n"); - qs_man_println(man, " QS_DenyRequestLine +printable deny \".*[\\x00-\\x19].*\"\n"); - printf("\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -d <num>\n"); - if(man) printf("\n"); - qs_man_print(man, " Depth (sub locations) of the path string which is defined as a\n"); - qs_man_print(man, " literal string. Default is 1.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -h\n"); - if(man) printf("\n"); - qs_man_print(man, " Always use a string representing the handler name in the path even\n"); - qs_man_print(man, " the url does not have a query. See also -d option.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -b <num>\n"); - if(man) printf("\n"); - qs_man_print(man, " Replaces url pattern by the regular expression when detecting\n"); - qs_man_print(man, " a base64/hex encoded string. Detecting sensibility is defined by a\n"); - qs_man_print(man, " numeric value. You should use values higher than 5 (default)\n"); - qs_man_print(man, " or 0 to disable this function.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p\n"); - if(man) printf("\n"); - qs_man_print(man, " Represents query by pcre only (no literal strings).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -s\n"); - if(man) printf("\n"); - qs_man_print(man, " Uses one single pcre for the whole query string.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -m\n"); - if(man) printf("\n"); - qs_man_print(man, " Uses one pcre for multiple query values (recommended mode).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -o\n"); - if(man) printf("\n"); - qs_man_print(man, " Does not care the order of query parameters.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -l <len>\n"); - if(man) printf("\n"); - qs_man_print(man, " Outsizes the query length by the defined length ({0,size+len}),\n"); - qs_man_print(man, " default is %d.\n", m_query_len_pcre); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -n\n"); - if(man) printf("\n"); - qs_man_print(man, " Disables redundant rules elimination.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -e\n"); - if(man) printf("\n"); - qs_man_print(man, " Exit on error.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -u 'uni'\n"); - if(man) printf("\n"); - qs_man_print(man, " Enables additional decoding methods. Use the same settings as you have\n"); - qs_man_print(man, " used for the QS_Decoding directive.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -k <prefix>\n"); - if(man) printf("\n"); - qs_man_print(man, " Prefix used to generate rule identifiers (QSF by default).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -t\n"); - if(man) printf("\n"); - qs_man_print(man, " Calculates the maximal latency per request (worst case) using the\n"); - qs_man_print(man, " generated rules.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -f <path>\n"); - if(man) printf("\n"); - qs_man_print(man, " Filters the input by the provided path (prefix) only processing\n"); - qs_man_print(man, " matching lines.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -v <level>\n"); - if(man) printf("\n"); - qs_man_print(man, " Verbose mode. (0=silent, 1=rule source, 2=detailed). Default is 1.\n"); - qs_man_print(man, " Don't use rules you haven't checked the request data used to\n"); - qs_man_print(man, " generate it! Level 1 is highly recommended (as long as you don't\n"); - qs_man_print(man, " have created the log data using your own web crawler).\n"); - printf("\n"); - if(man) { - printf(".SH OUTPUT\n"); - } else { - printf("Output\n"); - } - qs_man_print(man, " The output of %s is written to stdout. The output\n", cmd); - qs_man_print(man, " contains the generated QS_PermitUri directives but also\n"); - qs_man_print(man, " information about the source which has been used to generate\n"); - qs_man_print(man, " these rules. It is very important to check the validity of\n"); - qs_man_print(man, " each request line which has been used to calculate the\n"); - qs_man_print(man, " QS_PermitUri rules. Each request line which has been used to\n"); - qs_man_print(man, " generate a new rule is shown in the output prefixed by\n"); - qs_man_print(man, " \"ADD line <line number>:\". These request lines should be\n"); - qs_man_print(man, " stored and reused at any later rule generation (add them to\n"); - qs_man_print(man, " the URI input file). The subsequent line shows the generated\n"); - qs_man_print(man, " rule.\n"); - qs_man_print(man, " At the end of data processing a list of all generated\n"); - qs_man_print(man, " QS_PermitUri rules is shown. These directives may be used\n"); - qs_man_print(man, " withn the configuration file used by mod_qos.\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - } else { - printf("Sample Usage and Output\n"); - } - qs_man_println(man, " %s -i loc.txt -c httpd.conf -m -e\n", cmd); - qs_man_println(man, " ...\n"); - qs_man_println(man, " # ADD line 1: /aaa/index.do\n"); - qs_man_println(man, " # 003 ^(/[a-zA-Z0-9\\-_]+)+[/]?\\.?[a-zA-Z]{0,4}$\n"); - qs_man_println(man, " # ADD line 3: /aaa/view?page=1\n"); - qs_man_println(man, " # --- ^[/a-zA-Z0-9]+/view\\?(page=[0-9]+)?$\n"); - qs_man_println(man, " # ADD line 4: /aaa/edit?document=1\n"); - qs_man_println(man, " # 004 ^[/a-zA-Z]+/edit\\?((document)(=[0-9]*)*[&]?)*$\n"); - qs_man_println(man, " # ADD line 5: /aaa/edit?image=1.jpg\n"); - qs_man_println(man, " # 005 ^[/a-zA-Z]+/edit\\?((image)(=[0-9\\.a-zA-Z]*)*[&]?)*$\n"); - qs_man_println(man, " ...\n"); - qs_man_println(man, " QS_PermitUri +QSF001 deny \"^[/a-zA-Z]+/edit\\?((document|image)(=[0-9\\.a-zA-Z]*)*[&]?)*$\"\n"); - qs_man_println(man, " QS_PermitUri +QSF002 deny \"^[/a-zA-Z0-9]+/view\\?(page=[0-9]+)?$\"\n"); - qs_man_println(man, " QS_PermitUri +QSF003 deny \"^(/[a-zA-Z0-9\\-_]+)+[/]?\\.?[a-zA-Z]{0,4}$\"\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("mod_qos %s\n", man_version); - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -/* worker struct, used for parallel processing */ -typedef struct { - apr_pool_t *pool; - apr_table_t *rules; - apr_table_t *rules_url; - int from; - int to; -} qs_worker_t; - -/* determines, if a rule is really required */ -static apr_table_t *qos_get_used(apr_pool_t *pool, apr_table_t *rules, apr_table_t *rules_url, - int from, int to) { - apr_table_t *used = apr_table_make(pool, 1); - int j; - for(j = from; j < to; j++) { - int l; - apr_table_entry_t *linee = (apr_table_entry_t *)apr_table_elts(rules_url)->elts; - if(m_verbose) { - printf("[%d]", j); - fflush(stdout); - } - for(l = 0; l < apr_table_elts(rules_url)->nelts; l++) { - char *line = linee[l].key; - int i; - int match = 0; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - if(i != j) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - if(qs_regexec_len(rs->pcre, line, strlen(line), 0, NULL, 0) >= 0) { - match = 1; - break; - } - } - } - if(!match) { - /* no match, rule j is required */ - apr_table_add(used, entry[j].key, "+"); - } - } - } - return used; -} - -static void *qos_worker(void *argv) { - qs_worker_t *wt = argv; - return qos_get_used(wt->pool, wt->rules, wt->rules_url, wt->from, wt->to); -} - -/* get the characters used withn the string in order to define a pcre */ -static char *qos_2pcre(apr_pool_t *pool, const char *line) { - int hasA = 0; - int hasD = 0; - int hasE = 0; - int hasB = 0; - int i = 0; - unsigned char *in = (unsigned char *)line; - char *ret = apr_pcalloc(pool, strlen(line) * 6); - int reti = 0; - char *existing = ""; - if(strlen(line) == 0) return ""; - while(in[i]) { - if(isdigit(in[i])) { - if(!hasD) { - hasD = 1; - strcpy(&ret[reti], "0-9"); - reti = reti + 3; - } - } else if(isalpha(in[i])) { - if(!hasA) { - hasA = 1; - strcpy(&ret[reti], "a-zA-Z"); - reti = reti + 6; - } - } else if(in[i] == '\\') { - if(!hasE) { - hasE = 1; - strcpy(&ret[reti], "\\\\"); - reti = reti + 2; - } - } else if(in[i] == '-') { - if(!hasB) { - hasB = 1; - strcpy(&ret[reti], "\\-"); - reti = reti + 2; - } - } else if(in[i] == '\0') { - char *ck = apr_psprintf(pool, "#\\x%02x#", in[i]); - if(strstr(existing, ck) == NULL) { - sprintf(&ret[reti], "\\x%02x", in[i]); - reti = reti + 4; - existing = apr_pstrcat(pool, existing, ck, NULL); - } - } else if(strchr(ret, in[i]) == NULL) { - if(strchr(QS_PCRE_RESERVED, in[i]) != NULL) { - ret[reti] = '\\'; - reti++; - ret[reti] = in[i]; - reti++; - } else if((in[i] < ' ') || (in[i] > '~')) { - char *ck = apr_psprintf(pool, "#\\x%02x#", in[i]); - if(strstr(existing, ck) == NULL) { - sprintf(&ret[reti], "\\x%02x", in[i]); - reti = reti + 4; - existing = apr_pstrcat(pool, existing, ck, NULL); - } - } else { - ret[reti] = in[i]; - reti++; - } - } - i++; - } - if(strlen(ret) == 0) return NULL; - ret[reti] = '\0'; - return ret; -} - -/* check for the pattern "p" in "r" using the delimter "d", - returns 1 if it is in the string */ -static int qos_checkstr(apr_pool_t *pool, char *r, char *d, char *p) { - /* - * r = ..|p|.. - * r = p|... - * r = ..|p - * r = p - */ - char *check1 = apr_pstrcat(pool, d, p, d, NULL); - char *check2 = apr_pstrcat(pool, p, d, NULL); - char *check3 = apr_pstrcat(pool, d, p, NULL); - - if(strstr(r, check1) != NULL) { - return 1; - } - if(strncmp(r, check2, strlen(check2)) == 0) { - return 1; - } - if(strlen(r) > strlen(check3)) { - if((strncmp(&r[strlen(r)-strlen(check3)], check3, strlen(check3)) == 0)) { - return 1; - } - } - if(strcmp(r, p) == 0) { - return 1; - } - - return 0; -} - -/* add the string "n" to "o" using the delimiter "d" (only if not - already available */ -static char *qos_addstr(apr_pool_t *pool, char *o, char *d, char *n) { - char *p = apr_pstrdup(pool, n); - char *r = o; - if(n == NULL) return o; - while(p && p[0]) { - char *this = p; - char *next = strchr(p, d[0]); - - /* \| */ - while(next) { - if((next > this) && (next[-1] == '\\')) { - next++; - next = strchr(next, d[0]); - } else { - break; - } - } - if(next == NULL) { - p = NULL; - } else { - next[0] = '\0'; - next++; - p = next; - } - if(!qos_checkstr(pool, r, d, this)) { - r = apr_pstrcat(pool, r, d, this, NULL); - } - } - return r; -} - - -/* create a name=pcre string like this: ((s1|s2)(=[<pcre>]*)*[&]?)*" */ -static char *qos_qqs(apr_pool_t *pool, char *string, char *query_pcre, int singleEq, int hasEq, int startAmp) { - char *se = NULL; - char *s = ""; - if(startAmp) s = "[&]?"; - if(singleEq) { - se = "(=[&]?)*"; - } - if(strlen(query_pcre) > 0) { - return apr_pstrcat(pool, s, "((", string, ")(=[", qos_2pcre(pool, query_pcre), "]*)*[&]?)*", se, NULL); - } else { - if(hasEq && !singleEq) { - se = "(=[&]?)*"; - return apr_pstrcat(pool, s, "(((", string, ")[&]?)*", se, ")*", NULL); - } - return apr_pstrcat(pool, s, "((", string, ")[&]?)*", se, NULL); - } -} - -/* tries to optimize the rules by merging all query into one single pcre matching - all values */ -static void qos_query_optimization(apr_pool_t *pool, apr_table_t *rules) { - apr_table_t *delete = apr_table_make(pool, 1); - apr_table_t *checked_path = apr_table_make(pool, 1); - apr_table_t *new = apr_table_make(pool, 1); - int i, j; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - char *rule_str = entry[i].key; - qs_rule_t *r = (qs_rule_t *)entry[i].val; - if(!r->fragment && r->path && (apr_table_get(checked_path, r->path) == NULL)) { - int merged = 0; - char *query_m_string = r->query_m_string == NULL ? "" : r->query_m_string; - char *query_m_pcre = r->query_m_pcre == NULL ? "" : r->query_m_pcre; - if(m_verbose > 1) printf(" search for path %s (%s)\n", r->path, rule_str); - if(m_verbose > 1) printf(" . %s %s\n", query_m_string, query_m_pcre); - apr_table_add(checked_path, r->path, ""); - /* search for rules with the same path and delete them */ - for(j = 0; j < apr_table_elts(rules)->nelts; j++) { - if(i != j) { - qs_rule_t *n = (qs_rule_t *)entry[j].val; - if(!n->fragment && n->path && (strcmp(r->path, n->path) == 0)) { - if(m_verbose > 1) printf(" + %s %s\n", - n->query_m_string == NULL ? "-" : n->query_m_string, - n->query_m_pcre == NULL ? "-" : n->query_m_pcre); - if(strlen(query_m_string) == 0) { - query_m_string = apr_pstrcat(pool, query_m_string, n->query_m_string, NULL); - } else { - query_m_string = qos_addstr(pool, query_m_string, "|", n->query_m_string); - } - if(m_verbose > 1) printf(" > %s\n", query_m_string); - query_m_pcre = apr_pstrcat(pool, query_m_pcre, n->query_m_pcre, NULL); - apr_table_add(delete, entry[j].key, ""); - merged = 1; - } - } - } - /* update rule if merged to any */ - if(merged) { - apr_table_add(delete, entry[i].key, ""); - if(m_verbose) { - printf("# CHANGE: <%s>", rule_str); - } - { - const char *errptr = NULL; - char *rule = apr_pstrcat(pool, "^", r->path, NULL); - qs_rule_t *rs = apr_pcalloc(pool, sizeof(qs_rule_t)); - if(strlen(query_m_string) > 0) { - rule = apr_pstrcat(pool, rule, "\\?", - qos_qqs(pool, query_m_string, query_m_pcre, 0, 0, 0), NULL); - } - rule = apr_pstrcat(pool, rule, "$", NULL); - rs->pcre = qos_pcre_compile(pool, rule, 0); - rs->path = r->path; - apr_table_setn(new, rule, (char *)rs); - if(m_verbose) { - printf(" to <%s>\n", rule); - fflush(stdout); - } - } - } - } - } - entry = (apr_table_entry_t *)apr_table_elts(delete)->elts; - for(i = 0; i < apr_table_elts(delete)->nelts; i++) { - if(m_verbose) printf("# DEL rule: %s\n", entry[i].key); - apr_table_unset(rules, entry[i].key); - } - entry = (apr_table_entry_t *)apr_table_elts(new)->elts; - for(i = 0; i < apr_table_elts(new)->nelts; i++) { - apr_table_setn(rules, entry[i].key, entry[i].val); - } -} - -/* deletes rules which are not required and merge query name/value pairs */ -static void qos_delete_obsolete_rules(apr_pool_t *pool, apr_table_t *rules, apr_table_t *rules_url) { - apr_table_t *not_used = apr_table_make(pool, 1); - apr_table_t *used; - apr_table_t *used1; - pthread_attr_t *tha = NULL; - pthread_t tid; - qs_worker_t *wt = apr_pcalloc(pool, sizeof(qs_worker_t)); - - - if(m_query_multi_pcre) { - if(m_verbose) { - printf("# search for redundant rules ...\n"); - fflush(stdout); - } - qos_query_optimization(pool, rules); - if(m_verbose) printf("# "); - } else { - if(m_verbose) { - printf("# search for redundant rules "); - fflush(stdout); - } - } - - wt->pool = pool; - wt->rules = rules; - wt->rules_url = rules_url; - wt->from = apr_table_elts(rules)->nelts / 2; - wt->to = apr_table_elts(rules)->nelts; - - pthread_create(&tid, tha, qos_worker, (void *)wt); - used = qos_get_used(pool, rules, rules_url, 0, apr_table_elts(rules)->nelts / 2); - pthread_join(tid, (void *)&used1); - if(m_verbose) printf(" done\n"); - { - int i; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - if((apr_table_get(used, entry[i].key) == NULL) && - (apr_table_get(used1, entry[i].key) == NULL)) { - if(m_verbose) printf("# DEL rule (not required): %s\n", entry[i].key); - apr_table_add(not_used, entry[i].key, "-"); - } - } - entry = (apr_table_entry_t *)apr_table_elts(not_used)->elts; - for(i = 0; i < apr_table_elts(not_used)->nelts; i++) { - apr_table_unset(rules, entry[i].key); - } - } -} - -/* test if we need to create a new url (and save line if the rule is used the very - first time (rule has been read from the configuration file)) */ -static int qos_test_for_existing_rule(char *plain, char *line, apr_table_t *rules, - apr_table_t *special_rules, int line_nr, - apr_table_t *rules_url, apr_table_t *source_rules, int first) { - int i; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - if((line == 0) || (strlen(line) == 0)) return 0; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - if(qs_regexec_len(rs->pcre, line, strlen(line), 0, NULL, 0) >= 0) { - if(first && (apr_table_get(source_rules, entry[i].key) == NULL)) { - apr_table_add(source_rules, entry[i].key, ""); - apr_table_add(rules_url, line, ""); - apr_table_setn(special_rules, entry[i].key, (char *)rs); - if(m_verbose) { - printf("# ADD line %d: %s\n", line_nr, plain); - printf("# --- %s\n", entry[i].key); - } - } - if(m_verbose > 1){ - printf("LINE %d, exiting rule: %s\n", line_nr, entry[i].key); - } - return 1; - } - } - /* check for special rules */ - entry = (apr_table_entry_t *)apr_table_elts(special_rules)->elts; - for(i = 0; i < apr_table_elts(special_rules)->nelts; i++) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - if(qs_regexec_len(rs->pcre, line, strlen(line), 0, NULL, 0) >= 0) { - if(m_verbose) { - printf("# ADD line %d: %s\n", line_nr, plain); - printf("# -(S) %s\n", entry[i].key); - } - apr_table_setn(rules, entry[i].key, (char *)rs); - return 1; - } - } - return 0; -} - -/* filter lines we don't want to add to the allow list */ -static int qos_enforce_denylist(apr_table_t *rules, const char *line) { - int i; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - if((line == 0) || (strlen(line) == 0)) return 0; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - if(qs_regexec_len(rs->pcre, line, strlen(line), 0, NULL, 0) == 0) { - if(m_verbose > 1) printf(" deny list match, rule %s\n", entry[i].key); - return 1; - } - } - return 0; -} - -/* load existing rules */ -static void qos_load_rules(apr_pool_t *pool, apr_table_t *ruletable, - const char *httpdconf, const char *command, int option) { - FILE *f = fopen(httpdconf, "r"); - char line[MAX_LINE]; - if(f == NULL) { - fprintf(stderr, "ERROR, could not open %s\n", httpdconf); - exit(1); - } - while(!qos_fgetline(line, sizeof(line), f)) { - // QS_DenyRequestLine '+'|'-'<id> 'log'|'deny' <pcre> - char *p = strstr(line, command); - if(p) { - p[0] = '\0'; - p++; - } - if(p && (strchr(line, '#') == NULL)) { - p = strchr(p, ' '); - if(p) { - while(p[0] == ' ') p++; - p = strchr(p, ' '); - if(p) { - while(p[0] == ' ') p++; - p = strchr(p, ' '); - if(p) { - while(p[0] == ' ') p++; - if(m_verbose > 1) { - printf("load %s\n", p); - } - { - const char *errptr = NULL; - char *pattern; - qs_regex_t *pcre_test; - qs_rule_t *rs; - if(p[0] == '"') { - int fl = strlen(p)-2; - pattern = apr_psprintf(pool, "%.*s", fl, &p[1]); - } else { - int fl = strlen(p); - pattern = apr_psprintf(pool, "%.*s", fl, p); - } - pcre_test = qos_pcre_compile(pool, pattern, option); - rs = apr_pcalloc(pool, sizeof(qs_rule_t)); - rs->pcre = pcre_test; - apr_table_setn(ruletable, pattern, (char *)rs); - } - } - } - } - } - } - fclose(f); -} - -static void qos_load_denylist(apr_pool_t *pool, apr_table_t *denylist, const char *httpdconf) { - qos_load_rules(pool, denylist, httpdconf, "QS_DenyRequestLine", PCRE2_CASELESS); -} -static void qos_load_allowlist(apr_pool_t *pool, apr_table_t *rules, const char *httpdconf) { - qos_load_rules(pool, rules, httpdconf, "QS_PermitUri", 0); -} - -/* tries to map a base64 string to a pcre */ -static char *qos_b64_2pcre(apr_pool_t *pool, const char *line) { - char *copy = apr_pstrdup(pool, line); - char *b64 = qos_detect_b64(copy, 1); - char *st = b64; - char *ed = &b64[1]; - if(m_verbose > 1) printf(" B642pcre: %s", copy); - /* reserved: {}[]()^$.|*+?\ */ -#define QS_BX "-_$+!" - while(st[0] && (isdigit(st[0]) || isalpha(st[0]) || (strchr(QS_BX, st[0]) != NULL))) { - st--; - } - st++; - st[0] = '\0'; - while(ed[0] && (isdigit(ed[0]) || isalpha(ed[0]) || (strchr(QS_BX, ed[0]) != NULL))) { - ed++; - } - if(m_verbose > 1) printf(" %s <> %s\n", copy, ed); - return apr_pstrcat(pool, qos_escape_pcre(pool, copy), - "[a-zA-Z0-9\\-_\\$\\+!]+", - ed[0] == '\0' ? NULL : qos_escape_pcre(pool, ed), NULL); -} - - -/* maps a query string to a pairs of <string>=<pcre> or <pcre>=<pcre> */ -static char *qos_query_string_pcre(apr_pool_t *pool, const char *path) { - char *copy = apr_pstrdup(pool, path); - char *pos = copy; - char *ret = ""; - int isValue = 0; - int open = 0; - while(copy[0]) { - if((copy[0] == '=') && (copy[1] != '=') && !open) { - copy[0] = '\0'; - qos_unescaping(pos); - if(!open) { - ret = apr_pstrcat(pool, ret, "(", NULL); - open = 1; - } - if(m_query_pcre) { - if(strlen(pos) > 0) { - ret = apr_pstrcat(pool, ret, "[", qos_2pcre(pool, pos), "]+=", NULL); - } else { - ret = apr_pstrcat(pool, ret, "=", NULL); - } - } else { - ret = apr_pstrcat(pool, ret, qos_escape_pcre(pool, pos), "=", NULL); - } - open = 1; - pos = copy; - pos++; - isValue = 1; - } - if(copy[0] == '&') { - copy[0] = '\0'; - if(strlen(pos) == 0) { - ret = apr_pstrcat(pool, ret, "[&]?", NULL); - if(open) { - ret = apr_pstrcat(pool, ret, ")?", NULL); - open = 0; - } - } else { - qos_unescaping(pos); - ret = apr_psprintf(pool, "%s[%s]{0,%"APR_SIZE_T_FMT"}[&]?", ret, qos_2pcre(pool, pos), - strlen(pos) + m_query_len_pcre); - if(open) { - ret = apr_pstrcat(pool, ret, ")?", NULL); - open = 0; - } - } - pos = copy; - pos++; - isValue = 0; - } - copy++; - } - if(pos != copy) { - qos_unescaping(pos); - if(isValue) { - ret = apr_psprintf(pool, "%s[%s]{0,%"APR_SIZE_T_FMT"}[&]?", ret, qos_2pcre(pool, pos), - strlen(pos) + m_query_len_pcre); - } else { - if(!open) { - ret = apr_pstrcat(pool, "(", ret, NULL); - open = 1; - } - if(m_query_pcre) { - ret = apr_pstrcat(pool, ret, "[", qos_2pcre(pool, pos), "]+", NULL); - } else { - ret = apr_pstrcat(pool, ret, qos_escape_pcre(pool, pos), NULL); - } - } - if(open) { - ret = apr_pstrcat(pool, ret, ")?", NULL); - open = 0; - } - } - if(open) { - ret = apr_pstrcat(pool, ret, ")?", NULL); - open = 0; - } - if(m_query_pcre) { - return ret; - } else { - return ret; - /* it would be nice to use (see -o): - * ((a=b)?(c=d)?)* - * instead of: - * (a=b)?(c=d)? and (c=d)?(a=b)? - * but in this case, two rules are much faster than one - * it's probably better to use the -m option - */ - } -} - -/* maps a query string to a list of names and a single pcre for all values: - <string>|<string>=<pcre> */ -static char *qos_multi_query_string_pcre(apr_pool_t *pool, const char *path, - char **query_m_string, char **query_m_pcre) { - char *copy = apr_pstrdup(pool, path); - char *pos = copy; - char *string = ""; - char *query_pcre = ""; - int isValue = 0; - int singleEq = 0; - int hasEq = 0; - int startAmp = 0; - if(copy[0] == '&') startAmp = 1; - while(copy[0]) { - if(copy[0] == '=') hasEq = 1; - if((copy[0] == '=') && (copy[1] != '=') && !isValue) { - copy[0] = '\0'; - qos_unescaping(pos); - if(strlen(pos) > 0) { - if(strlen(string) > 0) string = apr_pstrcat(pool, string, "|", NULL); - string = apr_pstrcat(pool, string, qos_escape_pcre(pool, pos), NULL); - } else { - if((copy[1] == '&') || (copy[1] == '\0')) { - singleEq = 1; - } - } - pos = copy; - pos++; - isValue = 1; - } - if(copy[0] == '&') { - copy[0] = '\0'; - if(!isValue) { - qos_unescaping(pos); - if(strlen(string) > 0) string = apr_pstrcat(pool, string, "|", NULL); - string = apr_pstrcat(pool, string, qos_escape_pcre(pool, pos), NULL); - } else { - if(strlen(pos) != 0) { - qos_unescaping(pos); - query_pcre = apr_pstrcat(pool, query_pcre, pos, NULL); - } - } - pos = copy; - pos++; - isValue = 0; - } - copy++; - } - if(pos != copy) { - qos_unescaping(pos); - if(isValue) { - query_pcre = apr_pstrcat(pool, query_pcre, pos, NULL); - } else { - if(strlen(string) > 0) string = apr_pstrcat(pool, string, "|", NULL); - string = apr_pstrcat(pool, string, qos_escape_pcre(pool, pos), NULL); - } - } - *query_m_string = string; - *query_m_pcre = query_pcre; - return qos_qqs(pool, string, query_pcre, singleEq, hasEq, startAmp); -} - -/* maps a path to a single pcre (don't mind its length) */ -static char *qos_path_pcre(apr_pool_t *lpool, const char *path) { - char *dec = apr_pstrdup(lpool, path); - qos_unescaping(dec); - return apr_pstrcat(lpool, "[", qos_2pcre(lpool, dec), "]+", NULL); -} - -/* maps a path to <pcre>/<string> */ -static char *qos_path_pcre_string(apr_pool_t *lpool, const char *path) { - int nohandler = 0; - char *lpath = apr_pstrdup(lpool, path); - char *last; - char *str = ""; - int depth = m_path_depth; - char *rx = ""; - if(lpath[strlen(lpath)-1] == '/') { - lpath[strlen(lpath)-1] = '\0'; - nohandler = 1; - } - last = strrchr(lpath, '/'); - while(last && depth) { - qos_unescaping(last); - if(m_base64 && qos_detect_b64(last, 0)) { - str = apr_pstrcat(lpool, qos_b64_2pcre(lpool, last), str, NULL); - } else { - str = apr_pstrcat(lpool, qos_escape_pcre(lpool, last), str, NULL); - } - last[0] = '\0'; - last = strrchr(lpath, '/'); - depth--; - } - if(lpath[0]) { - qos_unescaping(lpath); - rx = apr_pstrcat(lpool, "[", qos_2pcre(lpool, lpath), "]+", NULL); - } - if(strlen(str) > 0) { - if(nohandler) { - rx = apr_pstrcat(lpool, rx, str, "[/]?", NULL); - } else { - rx = apr_pstrcat(lpool, rx, str, NULL); - } - } - return rx; -} - -static int qos_is_alnum(const char *string) { - unsigned char *in = (unsigned char *)string; - int i = 0; - if(in == NULL) return 0; - while(in[i]) { - if(!apr_isalnum(in[i])) return 0; - i++; - } - return 1; -} - -static void qos_rule_optimization(apr_pool_t *pool, apr_pool_t *lpool, - apr_table_t *rules, apr_table_t *special_rules) { - int i; - apr_table_t *new_rules = apr_table_make(pool, 5); - apr_table_t *del_rules = apr_table_make(pool, 5); - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - int hit = 0; - int j; - for(j = 0; j < apr_table_elts(rules)->nelts; j++) { - if(i != j) { - qs_rule_t *rsj = (qs_rule_t *)entry[j].val; - if(rs->query_m_string && rsj->query_m_string) { - if(strcmp(rs->query_m_string, rsj->query_m_string) == 0) { - if(strlen(entry[i].key) == strlen(entry[j].key)) { - hit++; - } - } - if(hit == 5) { - int s = 0; - int e = 0; - while(entry[i].key[s] && (entry[i].key[s] == entry[j].key[s])) s++; - e = s; - while(entry[i].key[e] && - ((entry[i].key[e] != entry[j].key[e]) || - (apr_isalnum(entry[i].key[e]) && apr_isalnum(entry[j].key[e])))) e++; - if((e > s) && - (s > 14) && - (e < strlen(entry[i].key)) && - (strstr(&entry[i].key[e], "\?") != NULL)) { - const char *errptr = NULL; - char *match = apr_psprintf(lpool, "%.*s%.*s", - e-s, &entry[i].key[s], - e-s, &entry[j].key[s]); - if(qos_is_alnum(match)) { - char *matchx = apr_psprintf(lpool, "[%s]{%d}", qos_2pcre(lpool, match), e-s); - char *new = apr_psprintf(pool, "%.*s%s%s", s, entry[i].key, matchx, &entry[i].key[e]); - qs_rule_t *rsn = apr_pcalloc(pool, sizeof(qs_rule_t)); - rsn->pcre = qos_pcre_compile(pool, new, 0); - rsn->path = rs->path; - rsn->query_m_string = rs->query_m_string; - rsn->query_m_pcre = rs->query_m_pcre; - rsn->fragment = rs->fragment; - if(m_verbose) { - printf("# CHANGE: <%s> to <%s>\n", entry[i].key, new); - fflush(stdout); - } - apr_table_setn(new_rules, new, (char *)rsn); - apr_table_addn(del_rules, entry[i].key, entry[i].val); - apr_table_addn(del_rules, entry[j].key, entry[j].val); - if(m_verbose > 1) { - if(m_verbose) printf(" [%s] [%s]\n", entry[i].key, entry[j].key); - if(m_verbose) printf(" [%s] [%s]\n", match, matchx); - } - break; - } - } - } - } - } - } - } - entry = (apr_table_entry_t *)apr_table_elts(new_rules)->elts; - for(i = 0; i < apr_table_elts(new_rules)->nelts; i++) { - apr_table_setn(rules, entry[i].key, entry[i].val); - } - entry = (apr_table_entry_t *)apr_table_elts(del_rules)->elts; - for(i = 0; i < apr_table_elts(del_rules)->nelts; i++) { - apr_table_unset(rules, entry[i].key); - } -} - -/* rules do not care the order of parameter values (makes rule processing slow) - * (id=[0-9]{0,13}[&]?)?(name=[a-zA-Z]{0,12}[&]?)? - * ((id=[0-9]{0,13}[&]?)|(name=[a-zA-Z]{0,12}[&]?))* - */ -static char *qos_post_optimization(apr_pool_t *lpool, char *query) { - int hit = 0; - char *p = query; - while(p && p[0]) { - if(strncmp(p, "[&]?)?(", 7) == 0) { - hit = 1; - p[5] = '|'; - } - p++; - } - if(hit) { - query[strlen(query)-1] = '\0'; - return apr_psprintf(lpool, "(%s)*", query); - } - return query; -} - -static void qos_auto_detect(char **raw) { - char *line = *raw; - int rc_c = -1; - if(m_req_regex) { - qs_regmatch_t regm[QS_MAX_REG_MATCH]; - /* no request line, maybe raw Apache access log? */ - rc_c = qs_regexec_len(m_req_regex, line, strlen(line), QS_MAX_REG_MATCH, regm, 0); - if(rc_c >= 0) { - char *sr = &line[regm[2].rm_so]; - sr[regm[2].rm_eo - regm[2].rm_so] = '\0'; - *raw = sr; - } - } - if(rc_c < 0) { - /* or an audit log like "%h %>s %{qos-loc}n %{qos-path}n%{qos-query}n" */ - char *pe = line; - int pi = 3; - while(pe && (pi > 0)) { - pi--; - pe = strchr(pe, ' '); - if(pe) { - pe++; - } - } - if(pe && pe[0] == '/' && (pi == 0)) { - *raw = pe; - } - } - return; -} - -/* process the input file line by line */ -static void qos_process_log(apr_pool_t *pool, apr_table_t *denylist, apr_table_t *rules, - apr_table_t *rules_url, apr_table_t *special_rules, - FILE *f, int *ln, int *dc, int first) { - char *readline = apr_pcalloc(pool, MAX_BODY_BUFFER); - int deny_count = *dc; - int line_nr = *ln; - apr_table_t *source_rules = apr_table_make(pool, 10); - int rule_optimization = 300; - while(!qos_fgetline(readline, MAX_BODY_BUFFER, f)) { - int doubleSlash = 0; - apr_uri_t parsed_uri; - apr_pool_t *lpool; - char *line = readline; - apr_pool_create(&lpool, NULL); - line_nr++; - if((strlen(line) > 1) && line[1] == '/') { - doubleSlash = 1; - line++; - } - if(line[0] != '/') { - if(!m_log_req_regex) { - m_log_req_regex = 1; - fprintf(stderr, "WARNING, line %d: " - "unexpected data format, try to detect request lines automatically\n", - line_nr); - } - qos_auto_detect(&line); - } - if(apr_uri_parse(lpool, line, &parsed_uri) != APR_SUCCESS) { - fprintf(stderr, "ERROR, could not parse uri %s\n", line); - if(m_exit_on_error) exit(1); - } - if(parsed_uri.path == NULL || (parsed_uri.path[0] != '/')) { - fprintf(stderr, "WARNING, line %d: invalid request %s\n", line_nr, line); - } else if(m_filter && parsed_uri.path && strncmp(parsed_uri.path, m_filter, strlen(m_filter)) != 0) { - // skip filtered line - } else { - char *path = NULL; - char *query = NULL; - char *query_m_string = NULL; - char *query_m_pcre = NULL; - char *fragment = NULL; - char *copy = apr_pstrdup(lpool, line); - qos_unescaping(copy); - if(qos_enforce_denylist(denylist, copy)) { - fprintf(stderr, "WARNING: deny list filter match at line %d for %s\n", - line_nr, line); - deny_count++; - } else { - if(!qos_test_for_existing_rule(line, copy, rules, special_rules, - line_nr, rules_url, source_rules, first)) { - if(m_verbose > 1) printf("LINE %d, analyse: %s\n", line_nr, line); - if(parsed_uri.query) { - if(strcmp(parsed_uri.path, "/") == 0) { - path = apr_pstrdup(lpool, "/"); - } else { - path = qos_path_pcre_string(lpool, parsed_uri.path); - } - if(m_query_single_pcre) { - char *qc = apr_pstrdup(lpool, parsed_uri.query); - qos_unescaping(qc); - query = apr_pstrcat(lpool, "[", qos_2pcre(lpool, qc), "]+", NULL); - } else { - if(!m_query_multi_pcre) { - query = qos_query_string_pcre(lpool, parsed_uri.query); - if(m_query_o_pcre) { - query = qos_post_optimization(lpool, query); - } - } else { - query = qos_multi_query_string_pcre(lpool, parsed_uri.query, - &query_m_string, &query_m_pcre); - } - } - } else { - if(strcmp(parsed_uri.path, "/") == 0) { - path = apr_pstrdup(lpool, "/"); - } else { - if(m_handler) { - path = qos_path_pcre_string(lpool, parsed_uri.path); - } else { - if(qs_regexec_len(pcre_simple_path, - parsed_uri.path, strlen(parsed_uri.path), - 0, NULL, 0) >= 0) { - path = apr_pstrdup(lpool, QS_SIMPLE_PATH_PCRE); - } else { - path = qos_path_pcre(lpool, parsed_uri.path); - } - } - } - } - if(parsed_uri.fragment) { - char *f = apr_pstrdup(lpool, parsed_uri.fragment); - if(strlen(f) > 0) { - qos_unescaping(f); - fragment = apr_pstrcat(lpool, "[", qos_2pcre(lpool, f), "]+", NULL); - } else { - fragment = apr_pstrcat(lpool, "", NULL); - } - } - if(m_verbose > 1) { - printf(" path: %s\n", parsed_uri.path); - printf(" path rule: %s\n", path); - if(query) { - printf(" query: %s\n", parsed_uri.query); - printf(" query rule: %s\n", query); - } - if(fragment) { - printf(" fragment: %s\n", parsed_uri.fragment); - printf(" fragment rule: %s\n", fragment); - } - } - { - const char *errptr = NULL; - char *rule; - qs_rule_t *rs = apr_pcalloc(pool, sizeof(qs_rule_t)); - if(doubleSlash) { - rule = apr_pstrcat(pool, "^[/]?", path, NULL); - } else { - rule = apr_pstrcat(pool, "^", path, NULL); - } - if(query) { - rule = apr_pstrcat(pool, rule, "\\?", query, NULL); - } - if(fragment) { - rule = apr_pstrcat(pool, rule, "#", fragment, NULL); - rs->fragment = 1; - } else { - rs->fragment = 0; - } - rule = apr_pstrcat(pool, rule, "$", NULL); - rs->pcre = qos_pcre_compile(pool, rule, 0); - rs->path = apr_pstrdup(pool, path); - if(m_query_multi_pcre && !fragment) { - rs->query_m_string = apr_pstrdup(pool, query_m_string); - rs->query_m_pcre = apr_pstrdup(pool, query_m_pcre); - } else { - rs->query_m_string = NULL; - rs->query_m_pcre = NULL; - } - // don't mind if extra is null - if(m_verbose) { - printf("# ADD line %d: %s\n", line_nr, line); - printf("# %.3d %s\n", apr_table_elts(rules)->nelts+1, rule); - fflush(stdout); - } - if(qs_regexec_len(rs->pcre, copy, strlen(copy), 0, NULL, 0) < 0) { - fprintf(stderr, "ERROR, rule check failed (did not match)!\n"); - fprintf(stderr, " line %d: %s\n", line_nr, line); - fprintf(stderr, " string: %s\n", copy); - fprintf(stderr, " rule: %s\n", rule); - if(m_exit_on_error) exit(1); - } else { - apr_table_add(rules_url, copy, "unescaped line"); - apr_table_add(source_rules, rule, ""); - apr_table_setn(rules, rule, (char *)rs); - } - if(apr_table_elts(rules)->nelts == 2000) { - fprintf(stderr, "ERROR, too many rules (limited to max. 2000)\n"); - if(m_exit_on_error) exit(1); - } - /* rule optimazion searching for redundant patterns (only in - conjunction with -m, -b and !-n */ - if((apr_table_elts(rules)->nelts == rule_optimization) && - m_redundant && - m_query_multi_pcre && - m_base64) { - /* got too many rules, try to find more general rules */ - if(m_verbose) { - printf("# too many rules: start rule optimization ...\n"); - fflush(stdout); - } - qos_rule_optimization(pool, lpool, rules, special_rules); - if(m_verbose) { - printf("# continue with rule generation\n"); - fflush(stdout); - } - rule_optimization = rule_optimization + 200; - } - } - } - } - } - apr_pool_destroy(lpool); - } - *dc = deny_count; - *ln = line_nr; -} - -static void qos_measurement(apr_pool_t *pool, apr_table_t *denylist, apr_table_t *rules, FILE *f, int *ln) { - char *readline = apr_pcalloc(pool, MAX_BODY_BUFFER); - int line_nr = 0; - while(!qos_fgetline(readline, MAX_BODY_BUFFER, f)) { - apr_uri_t parsed_uri; - apr_pool_t *lpool; - char *line = readline; - apr_pool_create(&lpool, NULL); - line_nr++; - if((strlen(line) > 1) && line[1] == '/') { - strcpy(line, &line[1]); - } - if(line[0] != '/') { - qos_auto_detect(&line); - } - if(apr_uri_parse(lpool, line, &parsed_uri) != APR_SUCCESS) { - fprintf(stderr, "ERROR, could parse uri %s\n", line); - if(m_exit_on_error) exit(1); - } - if(parsed_uri.path == NULL || (parsed_uri.path[0] != '/')) { - fprintf(stderr, "WARNING, line %d: invalid request %s\n", line_nr, line); - } else { - char *copy = apr_pstrdup(lpool, line); - int i; - apr_table_entry_t *entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - qos_unescaping(copy); - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - qs_rule_t *rs = (qs_rule_t *)entry[i].val; - qs_regexec_len(rs->pcre, copy, strlen(copy), 0, NULL, 0); - } - } - apr_pool_destroy(lpool); - } - *ln = line_nr; -} - -int main(int argc, const char * const argv[]) { - apr_table_entry_t *entry; - long performance = -1; - time_t start = time(NULL); - time_t end; - int line_nr = 0; - int deny_count = 0; - char *time_string; - int i, rc; - const char *access_log = NULL; - FILE *f; - apr_pool_t *pool; - apr_table_t *rules; - apr_table_t *special_rules; - apr_table_t *denylist; - apr_table_t *rules_url; - int denylist_size = 0; - int allowlist_size = 0; - char *cmd = strrchr(argv[0], '/'); - const char *httpdconf = NULL; - apr_app_initialize(&argc, &argv, NULL); - apr_pool_create(&pool, NULL); - rules = apr_table_make(pool, 10); - special_rules = apr_table_make(pool, 10); - denylist = apr_table_make(pool, 10); - rules_url = apr_table_make(pool, 10); - rc = nice(10); - if(rc == -1) { - fprintf(stderr, "ERROR, failed to change nice value: %s\n", strerror(errno)); - } - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-v") == 0) { - if (--argc >= 1) { - m_verbose = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-c") == 0) { - if (--argc >= 1) { - httpdconf = *(++argv); - } - } else if(strcmp(*argv,"-i") == 0) { - if (--argc >= 1) { - access_log = *(++argv); - } - } else if(strcmp(*argv,"-k") == 0) { - if (--argc >= 1) { - m_pfx = *(++argv); - } - } else if(strcmp(*argv,"-f") == 0) { - if (--argc >= 1) { - m_filter = *(++argv); - } - } else if(strcmp(*argv,"-d") == 0) { - if (--argc >= 1) { - m_path_depth = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-u") == 0) { - if (--argc >= 1) { - const char *coders = *(++argv); - if(strstr(coders, "uni")) { - m_mode |= QOS_DEC_MODE_FLAGS_UNI; - } - if(strstr(coders, "ansi")) { - m_mode |= QOS_DEC_MODE_FLAGS_ANSI; - } - if(strstr(coders, "html")) { - m_mode |= QOS_DEC_MODE_FLAGS_HTML; - } - } - } else if(strcmp(*argv,"-n") == 0) { - m_redundant = 0; - } else if(strcmp(*argv,"-b") == 0) { - if (--argc >= 1) { - m_base64 = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-l") == 0) { - if (--argc >= 1) { - m_query_len_pcre = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-p") == 0) { - m_query_pcre = 1; - } else if(strcmp(*argv,"-m") == 0) { - m_query_multi_pcre = 1; - } else if(strcmp(*argv,"-o") == 0) { - m_query_o_pcre = 1; - } else if(strcmp(*argv,"-s") == 0) { - m_query_single_pcre = 1; - } else if(strcmp(*argv,"-e") == 0) { - m_exit_on_error = 1; - } else if(strcmp(*argv,"-t") == 0) { - performance = 0; - } else if(strcmp(*argv,"-h") == 0) { - m_handler = 1; - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } - argc--; - argv++; - } - qos_init_pcre(pool); - - if((m_query_pcre && m_query_multi_pcre) || - (m_query_pcre && m_query_single_pcre) || - (m_query_multi_pcre && m_query_single_pcre) || - (m_query_pcre && m_query_o_pcre) || - (m_query_multi_pcre && m_query_o_pcre) || - (m_query_single_pcre && m_query_o_pcre)) { - fprintf(stderr, "ERROR, option -s,-m,-o or -p can't be used together.\n"); - exit(1); - } - - if(httpdconf) { - qos_load_denylist(pool, denylist, httpdconf); - denylist_size = apr_table_elts(denylist)->nelts; - qos_load_allowlist(pool, rules, httpdconf); - allowlist_size = apr_table_elts(rules)->nelts; - } - - if(access_log == NULL) usage(cmd, 0); - f = fopen(access_log, "r"); - if(f == NULL) { - fprintf(stderr, "ERROR, could not open input file %s\n", access_log); - exit(1); - } - qos_process_log(pool, denylist, rules, rules_url, special_rules, f, &line_nr, &deny_count, 1); - fclose(f); - - if(m_redundant) { - int xl = 0; - int y = 0; - // delete useless rules - qos_delete_obsolete_rules(pool, rules, rules_url); - // ensure, we have not deleted to many! - if(m_verbose) { - printf("# verify new rules ...\n"); - fflush(stdout); - } - // if(httpdconf) { - // qos_load_allowlist(pool, rules, httpdconf); - // } - f = fopen(access_log, "r"); - qos_process_log(pool, denylist, rules, rules_url, special_rules, f, &xl, &y, 0); - fclose(f); - } - - if(performance == 0) { - int lx = 0; - apr_time_t tv; - f = fopen(access_log, "r"); - tv = apr_time_now(); - qos_measurement(pool, denylist, rules, f, &lx); - tv = apr_time_now() - tv; - performance = apr_time_msec(tv) + (apr_time_sec(tv) * 1000); - performance = performance / lx; - fclose(f); - } - - end = time(NULL); - time_string = ctime(&end); - time_string[strlen(time_string) - 1] = '\0'; - printf("\n# --------------------------------------------------------\n"); - printf("# %s\n", time_string); - printf("# %d rules from %d access log lines\n", apr_table_elts(rules)->nelts, line_nr); - printf("# mod_qos version: %s\n", man_version); - if(performance >= 0) { - printf("# performance index (ms/req): %ld\n", performance); - } - printf("# source (-i): %s\n", access_log); - printf("# path depth (-d): %d\n", m_path_depth); - printf("# disable path only regex (-h): %s\n", m_handler == 1 ? "yes" : "no"); - printf("# base64 detection level (-b): %d\n", m_base64); - printf("# redundancy check (-n): %s\n", m_redundant == 1 ? "yes" : "no"); - printf("# pcre only for query (-p): %s\n", m_query_pcre == 1 ? "yes" : "no"); - printf("# decoding (-u): url"); - if(m_mode & QOS_DEC_MODE_FLAGS_UNI) { - printf(" uni"); - } - if(m_mode & QOS_DEC_MODE_FLAGS_HTML) { - printf(" html"); - } - if(m_mode & QOS_DEC_MODE_FLAGS_ANSI) { - printf(" ansi"); - } - printf("\n"); - printf("# one pcre for query value (-m): %s\n", m_query_multi_pcre == 1 ? "yes" : "no"); - if(m_query_o_pcre) { - printf("# ignore query order (-o): yes\n"); - } - printf("# single pcre for query (-s): %s\n", m_query_single_pcre == 1 ? "yes" : "no"); - printf("# query outsize (-l): %d\n", m_query_len_pcre); - printf("# exit on error (-e): %s\n", m_exit_on_error == 1 ? "yes" : "no"); - printf("# rule file (-c): %s\n", httpdconf == NULL ? "-" : httpdconf); - if(httpdconf) { - printf("# allow list (loaded existing rules): %d\n", allowlist_size); - printf("# deny list (loaded deny rules): %d\n", denylist_size); - printf("# deny list matches: %d\n", deny_count); - } - printf("# duration: %ld minutes\n", (end - start) / 60); - printf("# --------------------------------------------------------\n"); - - { - STACK_OF(qs_rule_t) *st = sk_new(STACK_qs_cmp); - qs_rule_t *r; - int j = 1; - entry = (apr_table_entry_t *)apr_table_elts(rules)->elts; - for(i = 0; i < apr_table_elts(rules)->nelts; i++) { - // printf("QS_PermitUri +QSF%0.3d deny \"%s\"\n", i+1, entry[i].key); - r = apr_pcalloc(pool, sizeof(qs_rule_t)); - r->rule = entry[i].key; - sk_push(st, (char *)r); - } - sk_sort(st); - i = sk_num(st); - for(; i > 0; i--) { - r = (qs_rule_t *)sk_value(st, i-1); - printf("QS_PermitUri +%s%.3d deny \"%s\"\n", - m_pfx ? m_pfx : "QSF", - j, qs_apache_escape(pool, r->rule)); - j++; - } - } - - apr_pool_destroy(pool); - return 0; -} diff --git a/tools/src/qsgeo.c b/tools/src/qsgeo.c index 0a46628..d55ed80 100644 --- a/tools/src/qsgeo.c +++ b/tools/src/qsgeo.c @@ -8,7 +8,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -239,7 +239,7 @@ static void usage(const char *cmd, int man) { printf("\n"); if(man) { printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); + printf("qslog(1), qsre(1), qsrespeed(1)\n"); printf(".SH AUTHOR\n"); printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); } else { diff --git a/tools/src/qsgrep.c b/tools/src/qsgrep.c index 5b2c654..bd56deb 100644 --- a/tools/src/qsgrep.c +++ b/tools/src/qsgrep.c @@ -7,7 +7,7 @@ * * See http://mod-qos.sourceforge.net/ for further details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with diff --git a/tools/src/qshead.c b/tools/src/qshead.c deleted file mode 100644 index 49130ad..0000000 --- a/tools/src/qshead.c +++ /dev/null @@ -1,132 +0,0 @@ -/* -*-mode: c; indent-tabs-mode: nil; c-basic-offset: 2; -*- - */ -/** - * Utilities for the quality of service module mod_qos. - * - * qshead.c: Shows the beginning of a log file stopping at the provided pattern. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qshead.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <unistd.h> -#include <string.h> -#include <stdlib.h> -#include <signal.h> - -#include "qs_util.h" - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - an utility reading from stdin and printing all" - " lines to stdout until" - " reaching the defined pattern.\n", cmd); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -p <pattern>\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, " %s reads lines from stdin and prints them to stdout until a line contains\n", cmd); - qs_man_print(man, " the specified pattern (literal string).\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -p <pattern>\n"); - if(man) printf("\n"); - qs_man_print(man, " Search pattern (literal string).\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1) qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -int main(int argc, const char * const argv[]) { - char line[32768]; - const char *pattern = NULL; - char *cmd = strrchr(argv[0], '/'); - int status = 0; - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-p") == 0) { - if (--argc >= 1) { - pattern = *(++argv); - } - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } - argc--; - argv++; - } - - if(pattern == NULL) { - usage(cmd, 0); - } - - while(fgets(line, sizeof(line), stdin) != NULL) { - printf("%s", line); - if(strstr(line, pattern)) { - return status; - } - } - return status; -} diff --git a/tools/src/qslog.c b/tools/src/qslog.c index da476f8..f23dc48 100644 --- a/tools/src/qslog.c +++ b/tools/src/qslog.c @@ -9,7 +9,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -2247,7 +2247,7 @@ static void usage(const char *cmd, int man) { printf("\n"); if(man) { printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); + printf("qsgeo(1), qsre(1), qsrespeed(1)\n"); printf(".SH AUTHOR\n"); printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); } else { diff --git a/tools/src/qslogger.c b/tools/src/qslogger.c deleted file mode 100644 index 3a8a0d8..0000000 --- a/tools/src/qslogger.c +++ /dev/null @@ -1,423 +0,0 @@ -/* -*-mode: c; indent-tabs-mode: nil; c-basic-offset: 2; -*- - */ -/** - * Utilities for the quality of service module mod_qos. - * - * qslogger.c: Piped logging forwarding log data to syslog - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qslogger.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <stdlib.h> -#include <unistd.h> -#include <string.h> -#include <time.h> -#include <sys/time.h> -#include <errno.h> -#include <regex.h> -#include <syslog.h> - -#include <apr.h> -#include <apr_lib.h> - -#include "qs_util.h" - -// [Wed Mar 28 22:40:41 2012] [warn] -#define QS_DEFAULTPATTERN "^\\[[0-9a-zA-Z :]+\\] \\[([a-z]+)\\] " - -#define QS_MAX_PATTERN_MA 2 - -static int m_default_severity = LOG_NOTICE; - -/** - * Similar to standard strstr() but case insensitive and length limitation - * (string which is not 0 terminated). - * - * @param s1 String to search in - * @param s2 Pattern to ind - * @param len Length of s1 - * @return pointer to the beginning of the substring s2 within s1, or NULL - * if the substring is not found - */ -static const char *qs_strncasestr(const char *s1, const char *s2, int len) { - const char *e1 = &s1[len-1]; - char *p1, *p2; - if (*s2 == '\0') { - /* an empty s2 */ - return((char *)s1); - } - while(1) { - for ( ; (*s1 != '\0') && (s1 <= e1) && (apr_tolower(*s1) != apr_tolower(*s2)); s1++); - if (*s1 == '\0' || s1 > e1) { - return(NULL); - } - /* found first character of s2, see if the rest matches */ - p1 = (char *)s1; - p2 = (char *)s2; - for (++p1, ++p2; (apr_tolower(*p1) == apr_tolower(*p2)) && (p1 <= e1); ++p1, ++p2) { - if((p1 > e1) && (*p2 != '\0')) { - // reached the end without match - return NULL; - } - if (*p2 == '\0') { - /* both strings ended together */ - return((char *)s1); - } - } - if (*p2 == '\0') { - /* second string ended, a match */ - break; - } - /* didn't find a match here, try starting at next character in s1 */ - s1++; - } - return((char *)s1); -} - -/** - * Rerurns the priority value - * - * @param priorityname Part of the log message to search the priority in - * @param len Length of the priority string - * @return Priority, LOG_NOTICE (see m_default_severity) if provided name is not recognized. - */ -static int qsgetprio(const char *priorityname, int len) { - int p = m_default_severity; - if(!priorityname) { - return p; - } - if(qs_strncasestr(priorityname, "alert", len)) { - p = LOG_ALERT; - } else if(qs_strncasestr(priorityname, "crit", len)) { - p = LOG_CRIT; - } else if(qs_strncasestr(priorityname, "debug", len)) { - p = LOG_DEBUG; - } else if(qs_strncasestr(priorityname, "emerg", len)) { - p = LOG_EMERG; - } else if(qs_strncasestr(priorityname, "err", len)) { - p = LOG_ERR; - } else if(qs_strncasestr(priorityname, "info", len)) { - p = LOG_INFO; - } else if(qs_strncasestr(priorityname, "notice", len)) { - p = LOG_NOTICE; - } else if(qs_strncasestr(priorityname, "panic", len)) { - p = LOG_EMERG; - } else if(qs_strncasestr(priorityname, "warn", len)) { - p = LOG_WARNING; - } - return p; -} - -/** - * Extracts the severity of the message using the provided - * regular expression and determinest the priofity using - * qsgetprio(). - * - * @param preg Regular expression to extract the severity - * @param line Log fline to extract the severity from - * @return Level or LOG_NOTICE (see m_default_severity) if level could not be determined. - */ -static int qsgetlevel(regex_t preg, const char *line) { - int level = m_default_severity; - regmatch_t ma[QS_MAX_PATTERN_MA]; - if(regexec(&preg, line, QS_MAX_PATTERN_MA, ma, 0) == 0) { - int len = ma[1].rm_eo - ma[1].rm_so; - level = qsgetprio(&line[ma[1].rm_so], len); - } - return level; -} - -/* entry within the facility table */ -typedef struct { - const char* name; - int f; -} qs_f_t; - -/** - * Table of known facilities, see sys/syslog.h. - */ -static const qs_f_t qs_facilities[] = { -#ifdef LOG_AUTHPRIV - { "authpriv", LOG_AUTHPRIV }, -#endif - { "auth", LOG_AUTH }, - { "cron", LOG_CRON }, - { "daemon", LOG_DAEMON }, -#ifdef LOG_FTP - { "ftp", LOG_FTP }, -#endif - { "kern", LOG_KERN }, - { "lpr", LOG_LPR }, - { "mail", LOG_MAIL }, - { "news", LOG_NEWS }, - { "security", LOG_AUTH }, - { "syslog", LOG_SYSLOG }, - { "user", LOG_USER }, - { "uucp", LOG_UUCP }, - { "local0", LOG_LOCAL0 }, - { "local1", LOG_LOCAL1 }, - { "local2", LOG_LOCAL2 }, - { "local3", LOG_LOCAL3 }, - { "local4", LOG_LOCAL4 }, - { "local5", LOG_LOCAL5 }, - { "local6", LOG_LOCAL6 }, - { "local7", LOG_LOCAL7 }, - { NULL, -1 } -}; - -/** - * Determines the facility (user input). - * - * @param facilityname - * @return The facility id or LOG_DAEMON if the provided - * string is unknown. - */ -static int qsgetfacility(const char *facilityname) { - int f = LOG_DAEMON; - const qs_f_t *facilities = qs_facilities; - if(!facilityname) { - return f; - } - while(facilities->name) { - if(strcasecmp(facilityname, facilities->name) == 0) { - f = facilities->f; - break; - } - facilities++; - } - return f; -} - -/** - * Usage message (or man page) - * - * @param cmd - * @param man - */ -static void usage(const char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - another shell command interface to the system log module (syslog).\n", cmd); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s [-t <tag>] [-f <facility>] [-l <level>] [-x <prefix>] [-r <expression>] [-d <level>] [-u <name>] [-p]\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "Use this utility to forward log messages to the systems syslog\n"); - qs_man_print(man, "facility, e.g., to forward the messages to a remote host.\n"); - qs_man_print(man, "It reads data from stdin.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf("\n.TP\n"); - qs_man_print(man, " -t <tag>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the tag name which shall be used to define the origin\n"); - qs_man_print(man, " of the messages, e.g. 'httpd'.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -f <facility>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the syslog facility. Default is 'daemon'.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -u <name>\n"); - if(man) printf("\n"); - qs_man_print(man, " Becomes another user, e.g. www-data.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -l <level>\n"); - if(man) printf("\n"); - qs_man_print(man, " Defines the minimal severity a message must have in order to\n"); - qs_man_print(man, " be forwarded. Default is 'DEBUG' (forwarding everything).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -x <prefix>\n"); - if(man) printf("\n"); - qs_man_print(man, " Allows you to add a prefix (literal string) to every message.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -r <expression>\n"); - if(man) printf("\n"); - qs_man_print(man, " Specifies a regular expression which shall be used to\n"); - qs_man_print(man, " determine the severity (syslog level) for each log line.\n"); - qs_man_print(man, " The default pattern '"QS_DEFAULTPATTERN"' can\n"); - qs_man_print(man, " be used for Apache error log messages but you may configure\n"); - qs_man_print(man, " your own pattern matching other log formats. Use brackets\n"); - qs_man_print(man, " to define the pattern enclosing the severity string.\n"); - qs_man_print(man, " Default level (if severity can't be determined) is defined by the\n"); - qs_man_print(man, " option '-d' (see below).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -d <level>\n"); - if(man) printf("\n"); - qs_man_print(man, " The default severity if the specified pattern (-r) does not\n"); - qs_man_print(man, " match and the message's severity can't be determined. Default\n"); - qs_man_print(man, " is 'NOTICE'.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p\n"); - if(man) printf("\n"); - qs_man_print(man, " Writes data also to stdout (for piped logging).\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - } else { - printf("Example:\n"); - } - qs_man_println(man, " ErrorLog \"|/usr/bin/%s -t apache -f local7\"\n", cmd); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -int main(int argc, const char * const argv[]) { - int line_len; - char *line = calloc(1, MAX_LINE_BUFFER+1); - const char *cmd = strrchr(argv[0], '/'); - int pass = 0; - const char *tag = NULL; - int facility = LOG_DAEMON; - int severity = LOG_DEBUG; - int level = LOG_INFO; - const char *regexpattern = QS_DEFAULTPATTERN; - const char *username = NULL; - const char *prefix = NULL; - regex_t preg; - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv, "-p") == 0) { - pass = 1; - } else if(strcmp(*argv, "-f") == 0) { - if (--argc >= 1) { - const char *facilityname = *(++argv); - facility = qsgetfacility(facilityname); - } - } else if(strcmp(*argv, "-l") == 0) { - if (--argc >= 1) { - const char *severityname = *(++argv); - severity = qsgetprio(severityname, strlen(severityname)); - } - } else if(strcmp(*argv, "-x") == 0) { - if (--argc >= 1) { - prefix = *(++argv); - } - } else if(strcmp(*argv,"-u") == 0) { /* switch user id */ - if (--argc >= 1) { - username = *(++argv); - } - } else if(strcmp(*argv, "-d") == 0) { - if (--argc >= 1) { - const char *severityname = *(++argv); - m_default_severity = qsgetprio(severityname, strlen(severityname)); - } - } else if(strcmp(*argv, "-t") == 0) { - if (--argc >= 1) { - tag = *(++argv); - } - } else if(strcmp(*argv, "-r") == 0) { - if (--argc >= 1) { - regexpattern = *(++argv); - } - } else if(strcmp(*argv,"-h") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } else { - usage(cmd, 0); - } - argc--; - argv++; - } - - if(regcomp(&preg, regexpattern, REG_EXTENDED)) { - fprintf(stderr, "[%s] failed to compile pattern %s", cmd, regexpattern); - exit(1); - } - - qs_setuid(username, cmd); - - openlog(tag ? tag : getlogin(), 0, facility); - - // start reading from stdin - while(fgets(line, MAX_LINE_BUFFER, stdin) != NULL) { - line_len = strlen(line) - 1; - while(line_len > 0) { // cut tailing CR/LF - if(line[line_len] >= ' ') { - break; - } - line[line_len] = '\0'; - line_len--; - } - // severity is determined using the regular expression provided by the user - level = qsgetlevel(preg, line); - if(level <= severity) { - // send message - if(prefix) { - syslog(level, "%s%s", prefix, line); - } else { - syslog(level, "%s", line); - } - } - if(pass) { - printf("%s\n", line); - fflush(stdout); - } - } - free(line); - closelog(); - return 0; -} diff --git a/tools/src/qspng.c b/tools/src/qspng.c deleted file mode 100644 index 6d11f21..0000000 --- a/tools/src/qspng.c +++ /dev/null @@ -1,784 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * qspng.c: Tool to draw graph from qslog output. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qspng.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <string.h> - -#include <stdlib.h> -#include <unistd.h> -#include <png.h> - -//#include <config.h> - -#include "qs_util.h" -#include "char.h" - -#define HUGE_STRING_LEN 1024 -#define X_SAMPLE_RATE 3 -/* width */ -#define X_COUNTS 60 * 24 / X_SAMPLE_RATE // 24 hours, every 3th sample -/* height */ -#define Y_COUNTS 100 -/* border */ -#define XY_BORDER 20 - -typedef struct { - const char* param; - const char* name; - int r; - int g; - int b; -} qs_png_elt_t; - -/* known graph types */ -static const qs_png_elt_t qs_png_elts[] = { - { "r/s", "requests per second", 20, 30, 130, }, - { "req", "requests per minute", 20, 30, 130, }, - { "b/s", "bytes per second (out)", 30, 45, 130 }, - { "ib/s", "bytes per second (in)", 30, 45, 125 }, - { "esco", "established connections per minute", 40, 95, 140 }, - { "av", "average response time", 40, 95, 140 }, - { "avms", "average response time in milliseconds", 45, 95, 135 }, - { "0-49ms", "requests duration 0-49ms", 45, 100, 180 }, - { "50-99ms", "requests duration 50-99ms", 45, 100, 180 }, - { "100-499ms", "requests duration 100-499ms", 45, 100, 180 }, - { "500-999ms", "requests duration 500-999ms", 45, 100, 180 }, - { "<1s", "requests faster than 1 second", 35, 95, 180 }, - { "1s", "requests faster or equal than 1 second", 35, 90, 180 }, - { "2s", "requests with 2 seconds response time", 30, 85, 180 }, - { "3s", "requests with 3 seconds response time", 25, 90, 180 }, - { "4s", "requests with 4 seconds response time", 25, 95, 180 }, - { "5s", "requests with 5 seconds response time", 15, 90, 180 }, - { ">5s","requests slower than 5 seconds", 35, 90, 185 }, - { "1xx","requests with HTTP status 1xx", 50, 70, 150 }, - { "2xx","requests with HTTP status 2xx", 50, 70, 150 }, - { "3xx","requests with HTTP status 3xx", 50, 70, 150 }, - { "4xx","requests with HTTP status 4xx", 50, 70, 150 }, - { "5xx","requests with HTTP status 5xx", 50, 70, 150 }, - { "ip", "IP addresses", 55, 60, 150 }, - { "usr","active users", 55, 66, 150 }, - { "qV", "created VIP sessions", 55, 50, 155 }, - { "qS", "session pass", 55, 75, 160 }, - { "qD", "access denied", 55, 70, 170 }, - { "qK", "connection closed", 55, 60, 145 }, - { "qT", "dynamic keep-alive", 55, 55, 153 }, - { "qL", "slow down", 55, 65, 140 }, - { "qA", "connection aborts", 55, 50, 175 }, - { "qs", "serialization", 55, 40, 175 }, - { "qu", "start user tracking", 55, 45, 175 }, - { "sl", "system load", 25, 60, 175 }, - { "m", "free memory", 35, 90, 185 }, - { NULL, NULL, 0, 0, 0 } -}; - -typedef struct qs_png_conf_st { - char *path; - char *param; -} qs_png_conf; - - -/************************************************************************ - * Functions - ***********************************************************************/ - -/** - * Read the stat_log data line by line - * - * @param s IN buffer to store line to - * @param n IN buffer size - * @param f IN file descriptor - * - * @return 1 on EOF, else 0 - */ -static int qs_png_getline(char *s, int n, FILE *f) { - register int i = 0; - while (1) { - s[i] = (char) fgetc(f); - if (s[i] == CR) { - s[i] = fgetc(f); - } - if ((s[i] == 0x4) || (s[i] == LF) || (i == (n - 1))) { - s[i] = '\0'; - return (feof(f) ? 1 : 0); - } - ++i; - } -} - -/* png io callback (should write to buff/bio/bucket when using in apache) */ -void lp_write_data(png_structp png_ptr, png_bytep data, png_size_t length) { - FILE *f = png_get_io_ptr(png_ptr); - fwrite(data, length, 1, f); -} - -/* png io callback (not used) */ -void lp_flush_data(png_structp png_ptr) { - png_get_io_ptr(png_ptr); - fprintf(stderr, "flush\n"); -} - -/** - * Writes a single char to the graph - * - * @param x IN x position - * @param y IN y position - * @param row_pointers IN start pointer (0/0) - * @param n IN char to write - */ -static void qs_png_write_char(int x, int y, png_bytep *row_pointers, char n) { - int ix, iy; - int *f = &s_X[0][0]; - switch(n) { - case 'a': f = &s_a[0][0]; break; - case 'b': f = &s_b[0][0]; break; - case 'c': f = &s_c[0][0]; break; - case 'd': f = &s_d[0][0]; break; - case 'e': f = &s_e[0][0]; break; - case 'f': f = &s_f[0][0]; break; - case 'g': f = &s_g[0][0]; break; - case 'h': f = &s_h[0][0]; break; - case 'i': f = &s_i[0][0]; break; - case 'j': f = &s_j[0][0]; break; - case 'k': f = &s_k[0][0]; break; - case 'l': f = &s_l[0][0]; break; - case 'm': f = &s_m[0][0]; break; - case 'n': f = &s_n[0][0]; break; - case 'o': f = &s_o[0][0]; break; - case 'p': f = &s_p[0][0]; break; - case 'q': f = &s_q[0][0]; break; - case 'r': f = &s_r[0][0]; break; - case 's': f = &s_s[0][0]; break; - case 't': f = &s_t[0][0]; break; - case 'u': f = &s_u[0][0]; break; - case 'v': f = &s_v[0][0]; break; - case 'w': f = &s_w[0][0]; break; - case 'x': f = &s_x[0][0]; break; - case 'y': f = &s_y[0][0]; break; - case 'z': f = &s_z[0][0]; break; - case ' ': f = &s_SP[0][0]; break; - case '_': f = &s_US[0][0]; break; - case '(': f = &s_BRO[0][0]; break; - case ')': f = &s_BRC[0][0]; break; - case '<': f = &s_LT[0][0]; break; - case '>': f = &s_GT[0][0]; break; - case '-': f = &s_MI[0][0]; break; - case '/': f = &s_SL[0][0]; break; - case ';': f = &s_SC[0][0]; break; - case ',': f = &s_CM[0][0]; break; - case ':': f = &s_CO[0][0]; break; - case '.': f = &s_DT[0][0]; break; - case '\'': f = &s_SQ[0][0]; break; - case 'A': f = &s_a[0][0]; break; - case 'B': f = &s_b[0][0]; break; - case 'C': f = &s_c[0][0]; break; - case 'D': f = &s_d[0][0]; break; - case 'E': f = &s_e[0][0]; break; - case 'F': f = &s_f[0][0]; break; - case 'G': f = &s_g[0][0]; break; - case 'H': f = &s_h[0][0]; break; - case 'I': f = &s_i[0][0]; break; - case 'J': f = &s_j[0][0]; break; - case 'K': f = &s_k[0][0]; break; - case 'L': f = &s_l[0][0]; break; - case 'M': f = &s_M[0][0]; break; - case 'N': f = &s_n[0][0]; break; - case 'O': f = &s_o[0][0]; break; - case 'P': f = &s_p[0][0]; break; - case 'Q': f = &s_q[0][0]; break; - case 'R': f = &s_r[0][0]; break; - case 'S': f = &s_s[0][0]; break; - case 'T': f = &s_t[0][0]; break; - case 'U': f = &s_u[0][0]; break; - case 'V': f = &s_v[0][0]; break; - case 'W': f = &s_w[0][0]; break; - case 'X': f = &s_x[0][0]; break; - case 'Y': f = &s_y[0][0]; break; - case 'Z': f = &s_z[0][0]; break; - case '0': f = &s_0[0][0]; break; - case '1': f = &s_1[0][0]; break; - case '2': f = &s_2[0][0]; break; - case '3': f = &s_3[0][0]; break; - case '4': f = &s_4[0][0]; break; - case '5': f = &s_5[0][0]; break; - case '6': f = &s_6[0][0]; break; - case '7': f = &s_7[0][0]; break; - case '8': f = &s_8[0][0]; break; - case '9': f = &s_9[0][0]; break; - } - /* print the char matrix */ - for(iy = 0; iy < S_H_MAX; iy++) { - png_byte* row = row_pointers[y+iy]; - for(ix = 0; ix < S_W_MAX; ix++) { - png_byte* ptr = &(row[(x+ix)*4]); - if(f[iy*S_W_MAX + ix] == 1) { - /* foreground */ - ptr[0] = 0; - ptr[1] = 0; - ptr[2] = 0; - } else { - /* background */ - ptr[0] = 250; - ptr[1] = 250; - ptr[2] = 255; - } - } - } -} - -/** - * Writes a single digit 0..9. - * You should normally use either qs_png_write_int() or qs_png_write_int(). - * - * @param x IN x position - * @param y IN y position - * @param row_pointers IN start pointer (0/0) - * @param n IN number to write - */ -static void qs_png_write_digit(int x, int y, png_bytep *row_pointers, int n) { - char f = 'X'; - if(n == 0) f = '0'; - if(n == 1) f = '1'; - if(n == 2) f = '2'; - if(n == 3) f = '3'; - if(n == 4) f = '4'; - if(n == 5) f = '5'; - if(n == 6) f = '6'; - if(n == 7) f = '7'; - if(n == 8) f = '8'; - if(n == 9) f = '9'; - qs_png_write_char(x, y, row_pointers, f); -} - -/** - * Writes a string to the graph. - * - * @param x IN x position - * @param y IN y position - * @param row_pointers IN start pointer (0/0) - * @param n IN string to write - */ -static void qs_png_write_string(int x, int y, png_bytep *row_pointers, const char *n) { - int i = 0; - int offset = 0; - while(n[i] != '\0') { - qs_png_write_char(x+offset, y, row_pointers, n[i]); - i++; - offset = offset + S_W_MAX; - } -} - -/** - * Writes a number (int) to the graph (1:1). - * - * @param x IN x position - * @param y IN y position - * @param row_pointers IN start pointer (0/0) - * @param n IN number to write - */ -static void qs_png_write_int(int x, int y, png_bytep *row_pointers, int n) { - char num_str[HUGE_STRING_LEN]; - snprintf(num_str, sizeof(num_str), "%d", n); - qs_png_write_string(x, y, row_pointers, num_str); -} - -/** - * Writes a number (long) to the graph using k,M for big numbers. - * - * @param x IN x position - * @param y IN y position - * @param row_pointers IN start pointer (0/0) - * @param n IN string to write - */ -static void qs_png_write_long(int x, int y, png_bytep *row_pointers, long n) { - char num_str[HUGE_STRING_LEN]; - snprintf(num_str, sizeof(num_str), "%ld", n); - if(n >= 1000) { - snprintf(num_str, sizeof(num_str), "%ldk", n/1000); - } - if(n >= 1000000) { - snprintf(num_str, sizeof(num_str), "%ldM", n/1000000); - } - qs_png_write_string(x, y, row_pointers, num_str); -} - -/** - * Labels the graph (min,max,title). - * - * @param width IN size (x axis) of the graph - * @param height IN size (y axis) of the graph - * @param border IN border size around the graph - * @param row_pointers IN start pointer (0/0) - * @param max IN max y value - * @param name IN title - */ -static void qs_png_label(int width, int height, int border, - png_bytep *row_pointers, long max, - const char *name) { - /* MAX */ - int i; - int step = height/5; - int c = 5; - for(i = 0; i < height; i = i + step) { - qs_png_write_long(1, border - (S_W_MAX/2) + i, row_pointers, max/5*c); - c--; - } - - /* MIN */ - qs_png_write_int(1, height + border - (S_W_MAX/2), row_pointers, 0); - - /* title */ - { - char buf[HUGE_STRING_LEN]; - snprintf(buf, sizeof(buf), "%s", name); - qs_png_write_string(XY_BORDER, XY_BORDER/2-S_H_MAX/2, row_pointers, buf); - } - -} - -static void lp_init(int width, int height, int border, png_bytep **start) { - png_bytep *row_pointers; - int b_width = width + (2 * border); - int b_height = height + (2 * border); - int x, y; - - /* alloc memory */ - row_pointers = (png_bytep*) malloc(sizeof(png_bytep) * b_height); - for(y=0; y<b_height; y++) { - row_pointers[y] = (png_byte*) malloc(b_width * 4); - } - - /* background */ - for(y=0; y<b_height; y++) { - png_byte* row = row_pointers[y]; - for(x=0; x<b_width; x++) { - png_byte* ptr = &(row[x*4]); - ptr[0] = 250; - ptr[1] = 250; - ptr[2] = 255; - ptr[3] = 250; - } - } - for(y=border; y<b_height-border; y++) { - png_byte* row = row_pointers[y]; - for(x=border; x<b_width-border; x++) { - png_byte* ptr = &(row[x*4]); - ptr[0] = 245; - ptr[1] = 245; - ptr[2] = 250; - } - } - *start = row_pointers; -} - -/** - * "Main" png function: - * - reads the data from the file - * - draws the curve - * - labels the x axis - * - * @param width IN size (x axis) of the graph - * @param height IN size (y axis) of the graph - * @param border IN border size around the graph - * @param row_pointers IN start pointer (0/0) - * @param stat_log IN file descriptor to the input file - * @param name IN title - * @param c_r IN color red (0..255) - * @param c_g IN color green (0..255) - * @param c_b IN color blue (0..255) - */ -static long qs_png_draw(int width, int height, int border, - png_bytep *row_pointers, FILE *stat_log, const char *name, - int c_r, int c_g, int c_b) { - int x, y; - long req[width]; // values - long max_req[width]; // values - int hours[width]; // time marks on x axis - long tmp[X_SAMPLE_RATE]; // used to build average over multiple samples - int sample = 1; // sample rate counter (1 to X_SAMPLE_RATE) - - int i = 0; - char line[HUGE_STRING_LEN]; - - long peak = 0; // max of all values - double scale = 1; // scaling factor (height x scale = unit) - - int hour = -1; // detect "new" hour - char date_str[32] = ""; // string storing the first day (if fist value is at 00h) - - long ret; - for(x=0; x<width; x++) hours[x] = 0; - /* reads the file and resample measure points to width of the graph */ - while(!qs_png_getline(line, sizeof(line), stat_log) && i < width) { - char *p = strstr(line, name); - req[i] = 0; - max_req[i] = 0; - if(p && ((p - line) > 8)) { - char *e; - p=p+strlen(name); - e = strchr(p,';'); - if(e) e[0] = '\0'; - e = strchr(p, '.'); /** sl uses fp value */ - if(e) e[0] = '\0'; - tmp[sample-1] = atol(p); - } else { - tmp[sample-1] = 0; - } - /* hour (stat_log time format: %d.%m.%Y %H:%M:%S (19 char)) */ - p = strchr(line, ';'); - if(p && (p-line == 19 )) { - p = p - 6; - p[0] = '\0'; - p = p - 2; - hours[i] = atoi(p); - } - /* use the defined sample rate */ - if(sample == X_SAMPLE_RATE) { - int j; - int max_value = 0; - for(j = 0; j < X_SAMPLE_RATE; j++) { - req[i] = req[i] + tmp[j]; - if(max_value < tmp[j]) { - max_value = tmp[j]; - } - } - max_req[i] = max_value; - if(max_req[i] > peak) peak = max_req[i]; - /* build average */ - req[i] = req[i] / X_SAMPLE_RATE; - sample = 1; - i++; - /* and store the current date (%d.%m.%Y (10 char)) if the - first value is at 00h */ - if(hours[i] == 0 && i == 1) { - p = strchr(line, ' '); - if(p && (p-line == 10)) { - p[0] = '\0'; - strcpy(date_str, line); - } - } - } else { - sample++; - } - } - /* calculate y axis scaling (1:1 are height pixels) */ - if(peak < 10) { - scale = 0.1; - } else { - while((peak / scale) > height) { - if(scale < 8) { - scale = scale * 2; - } else { - if(scale == 8) { - scale = 10; - } else { - scale = scale * 10; - } - } - } - } - - /* draw the curve */ - for(x=0; x<i; x++) { - /* max */ - for(y=0; y<(max_req[x]/scale); y++) { - png_byte* row = row_pointers[height-y-1+border]; - png_byte* ptr = &(row[x*4+(4*border)]); - ptr[0] = c_r + 75; - ptr[1] = c_g + 75; - ptr[2] = c_b + 75; - } - /* average */ - for(y=0; y<(req[x]/scale); y++) { - png_byte* row = row_pointers[height-y-1+border]; - png_byte* ptr = &(row[x*4+(4*border)]); - ptr[0] = c_r; - ptr[1] = c_g; - ptr[2] = c_b; - } - /* label the x axis */ - if(hour != hours[x]) { - hour = hours[x]; - for(y=0; y<(height); y=y+3) { - png_byte* row = row_pointers[y+border]; - png_byte* ptr = &(row[x*4+(4*border)]); - ptr[0] = 50; - ptr[1] = 50; - ptr[2] = 50; - } - if(hour%2 == 0) { - qs_png_write_digit(x-S_W_MAX+border, height + border + 1, row_pointers, hour/10); - qs_png_write_digit(x-S_W_MAX+border+S_W_MAX, height + border + 1, row_pointers, hour%10); - qs_png_write_char(x-S_W_MAX+border+2*S_W_MAX, height + border + 1, row_pointers, 'h'); - } - } - } - - /* print date */ - qs_png_write_string(border, height+border+2+S_H_MAX, row_pointers, date_str); - - /* horizontal lines every 1/4 height */ - for(y=(height/5); y<height; y=y+height/5) { - png_byte* row = row_pointers[y+border]; - for(x=0; x<i; x=x+3) { - png_byte* ptr = &(row[x*4+(4*border)]); - ptr[0] = 50; - ptr[1] = 50; - ptr[2] = 50; - } - } - - ret = scale * height; - return ret; -} - - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - qs_man_print(man, "%s - an utility to draw a png graph from qslog(1) output data.\n", cmd); - } else { - qs_man_print(man, "Utility to draw a png graph from qslog output data.\n"); - } - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -i <stat_log_file> -p <parameter> -o <out_file> [-10]\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "%s is a tool to generate png (portable network graphics)\n", cmd); - qs_man_print(man, "raster images files from semicolon separated data generated by the\n"); - qs_man_print(man, "qslog utility. It reads up to the first 1440 entries (24 hours)\n"); - qs_man_print(man, "and prints a graph using the values defined by the 'parameter' \n"); - qs_man_print(man, "name.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -i <stats_log_file>\n"); - if(man) printf("\n"); - qs_man_print(man, " Input file to read data from.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p <parameter>\n"); - if(man) printf("\n"); - qs_man_print(man, " Parameter name, e.g. r/s or usr.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -o <out_file>\n"); - if(man) printf("\n"); - qs_man_print(man, " Output file name, e.g. stat.png.\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslogger(1), qslog(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("\n"); - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -int main(int argc, char **argv) { - int y; - int width, height, b_width, b_height; - png_byte color_type; - png_byte bit_depth; - - int scale; - - png_structp png_ptr; - png_infop info_ptr; - - png_bytep *row_pointers; - - char *infile = NULL; - FILE *f; - FILE *stat_log; - - char *cmd = strrchr(argv[0], '/'); - const char *param = NULL; - const char *name = ""; - char *out = NULL; - int c_r = 20; - int c_g = 50; - int c_b = 175; - const qs_png_elt_t* elt; - - if(cmd == NULL) { - cmd = argv[0]; - } else { - cmd++; - } - - while(argc >= 1) { - if(strcmp(*argv,"-i") == 0) { - if (--argc >= 1) { - infile = *(++argv); - } - } else if(strcmp(*argv,"-p") == 0) { - if (--argc >= 1) { - param = *(++argv); - name = param; - } - } else if(strcmp(*argv,"-o") == 0) { - if (--argc >= 1) { - out = *(++argv); - } - } else if(strcmp(*argv,"-h") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } - argc--; - argv++; - } - - - if(infile == NULL || param == NULL || out == NULL) usage(cmd, 0); - for(elt = qs_png_elts; elt->param != NULL ; ++elt) { - if(strcmp(elt->param, param) == 0) { - name = elt->name; - c_r = elt->r; - c_g = elt->g; - c_b = elt->b; - } - } - - stat_log = fopen(infile, "r"); - if(stat_log == NULL) { - fprintf(stderr,"[%s]: ERROR, could not open input file <%s>\n", cmd, infile); - exit(1); - } - - f = fopen(out, "wb"); - if(f == NULL) { - fprintf(stderr,"[%s]: ERROR, could not open output file <%s>\n", cmd, out); - exit(1); - } - - png_ptr = png_create_write_struct(PNG_LIBPNG_VER_STRING, NULL, NULL, NULL); - if(png_ptr == NULL) { - fprintf(stderr,"[%s]: ERROR, could not create png struct\n", cmd); - exit(1); - } - info_ptr = png_create_info_struct(png_ptr); - if(info_ptr == NULL) { - fprintf(stderr,"[%s]: ERROR, could not create png information struct\n", cmd); - exit(1); - } - if(setjmp(png_jmpbuf(png_ptr))) { - fprintf(stderr,"[%s]: ERROR, could not init png struct\n", cmd); - exit(1); - } - png_set_write_fn(png_ptr, f, lp_write_data, NULL); - - /* write header */ - if(setjmp(png_jmpbuf(png_ptr))) { - fprintf(stderr,"[%s]: ERROR, could not write png header\n", cmd); - exit(1); - } - - color_type = PNG_COLOR_TYPE_RGB_ALPHA; - bit_depth = 8; - width = X_COUNTS; - height = Y_COUNTS; - b_width = width + (2 * XY_BORDER); - b_height = height + (2 * XY_BORDER); - - png_set_IHDR(png_ptr, info_ptr, - b_width, b_height, - bit_depth, - color_type, - PNG_INTERLACE_NONE, - PNG_COMPRESSION_TYPE_BASE, PNG_FILTER_TYPE_BASE); - png_write_info(png_ptr, info_ptr); - - /* write bytes */ - if(setjmp(png_jmpbuf(png_ptr))) { - fprintf(stderr,"[%s]: ERROR, could not write png data\n", cmd); - exit(1); - } - - /* alloc and background */ - lp_init(width, height, XY_BORDER, &row_pointers); - - /* paint */ - { - char buf[HUGE_STRING_LEN]; - snprintf(buf, sizeof(buf), ";%s;", param); - scale = qs_png_draw(width, height, XY_BORDER, row_pointers, - stat_log, buf, c_r, c_g, c_b); - } - - /* min/max/title label */ - qs_png_label(width, height, XY_BORDER, row_pointers, scale, - name); - - - /* done, write image */ - png_write_image(png_ptr, row_pointers); - /* end write */ - if(setjmp(png_jmpbuf(png_ptr))) { - fprintf(stderr,"[%s]: ERROR, could not write png data\n", cmd); - exit(1); - } - png_write_end(png_ptr, NULL); - - /* cleanup heap allocation */ - for(y=0; y<height; y++) { - free(row_pointers[y]); - } - free(row_pointers); - - fclose(f); - fclose(stat_log); - return 0; -} diff --git a/tools/src/qsre.c b/tools/src/qsre.c index 53187b8..77a834a 100644 --- a/tools/src/qsre.c +++ b/tools/src/qsre.c @@ -4,7 +4,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -101,7 +101,7 @@ static void usage(const char *cmd, int man) { if(man) { printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsrespeed(1), qsrotate(1), qssign(1), qstail(1)\n"); + printf("qsgeo(1), qslog(1), qsrespeed(1)\n"); printf(".SH AUTHOR\n"); printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); } else { diff --git a/tools/src/qsrespeed.c b/tools/src/qsrespeed.c index dc949f1..2bd08ee 100644 --- a/tools/src/qsrespeed.c +++ b/tools/src/qsrespeed.c @@ -7,7 +7,7 @@ * See http://mod-qos.sourceforge.net/ for further * details. * - * Copyright (C) 2023 Pascal Buchbinder + * Copyright (C) 2025 Pascal Buchbinder * * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with @@ -102,7 +102,7 @@ static void usage(const char *cmd, int man) { if(man) { printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrotate(1), qssign(1), qstail(1)\n"); + printf("qsgeo(1), qslog(1), qsre(1)\n"); printf(".SH AUTHOR\n"); printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); } else { diff --git a/tools/src/qsrotate.c b/tools/src/qsrotate.c deleted file mode 100644 index 213a2e4..0000000 --- a/tools/src/qsrotate.c +++ /dev/null @@ -1,522 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * qsrotate.c: Log rotation tool. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - * - */ - -static const char revision[] = "$Id: qsrotate.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <string.h> - -#include <errno.h> -#include <fcntl.h> -#include <dirent.h> - -#include <stdlib.h> -#include <unistd.h> - -#include <pthread.h> - -#include <time.h> -#include <zlib.h> - -#include <signal.h> -#include <sys/types.h> -#include <sys/wait.h> -#include <sys/stat.h> - -#include "qs_util.h" - -#define HUGE_STR 1024 - -//yyyy-mm-dd<sp>hh-mm-ss<sp> -#define TME_STR_LEN 20 - -/* global variables used by main and support thread */ -static int m_force_rotation = 0; -static time_t m_tLogEnd = 0; -static time_t m_tRotation = 86400; /* default are 24h */ -static int m_nLogFD = -1; -static int m_generations = -1; -static mode_t m_mode = 0660; -static char *m_file_name = NULL; -static long m_messages = 0; -static char *m_cmd = NULL; -static int m_compress = 0; -static int m_stdout = 0; -static int m_timestamp = 0; -static char time_string[TME_STR_LEN]; -static long m_counter = 0; -static long m_limit = 2147483648 - (128 * 1024); -static int m_offset = 0; -static int m_offset_enabled = 0; - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - a log rotation tool (similar to Apache's rotatelogs).\n", cmd); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -o <file> [-s <sec> [-t <hours>]] [-b <bytes>] [-f] [-z] [-g <num>] [-u <name>] [-m <mask>] [-p] [-d]\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "%s reads from stdin (piped log) and writes the data to the provided\n", cmd); - qs_man_print(man, "file rotating the file after the specified time.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -o <file>\n"); - if(man) printf("\n"); - qs_man_print(man, " Output log file to write the data to (use an absolute path).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -s <sec>\n"); - if(man) printf("\n"); - qs_man_print(man, " Rotation interval in seconds, default are 86400 seconds.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -t <hours>\n"); - if(man) printf("\n"); - qs_man_print(man, " Offset to UTC (enables also DST support), default is 0.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -b <bytes>\n"); - if(man) printf("\n"); - qs_man_print(man, " File size limitation (default/max. are %ld bytes, min. are 1048576 bytes).\n", m_limit); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -f\n"); - if(man) printf("\n"); - qs_man_print(man, " Forced log rotation at the specified interval even no data is written.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -z\n"); - if(man) printf("\n"); - qs_man_print(man, " Compress (gzip) the rotated file.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -g <num>\n"); - if(man) printf("\n"); - qs_man_print(man, " Generations (number of files to keep).\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -u <name>\n"); - if(man) printf("\n"); - qs_man_print(man, " Become another user, e.g. www-data.\n"); - qs_man_print(man, " -m <mask>\n"); - if(man) printf("\n"); - qs_man_print(man, " File permission which is either 600, 640, 660 (default) or 664.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p\n"); - if(man) printf("\n"); - qs_man_print(man, " Writes data also to stdout (for piped logging).\n"); - qs_man_print(man, " -d\n"); - if(man) printf("\n"); - qs_man_print(man, " Line-by-line data reading prefixing every line with a timestamp.\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - } else { - printf("Example:\n"); - } - qs_man_println(man, " TransferLog \"|/usr/bin/%s -f -z -g 3 -o /var/log/apache/access.log -s 86400\"\n", cmd); - printf("\n"); - qs_man_print(man, "The name of the rotated file will be /dest/filee.YYYYmmddHHMMSS\n"); - qs_man_print(man, "where YYYYmmddHHMMSS is the system time at which the data has been\n"); - qs_man_print(man, "rotated.\n"); - printf("\n"); - if(man) { - printf(".SH NOTE\n"); - } else { - printf("Notes:\n"); - } - qs_man_println(man, " - Each %s instance must use an individual file.\n", cmd); - qs_man_println(man, " - You may trigger a file rotation manually by sending the signal USR1\n"); - qs_man_print(man, " to the process.\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qsre(1), qsrespeed(1), qspng(1), qssign(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -static time_t get_now() { - time_t now = time(NULL); - if(m_offset_enabled) { - struct tm lcl = *localtime(&now); - if(lcl.tm_isdst) { - now += 3600; - } - now += m_offset; - } - return now; -} - -static int openFile(const char *cmd, const char *file_name) { - int m_nLogFD = open(file_name, O_WRONLY | O_CREAT | O_APPEND, m_mode); - /* error while opening log file */ - if(m_nLogFD < 0) { - fprintf(stderr,"[%s]: ERROR, failed to open file <%s>\n", cmd, file_name); - } - return m_nLogFD; -} - -/** - * Compress method called by a child process (forked) - * used to compress the rotated file. - * - * @param cmd Command name (used when logging errors) - * @param arch Path to the file to compress. File gets renamed to <arch>.gz - */ -static void compressThread(const char *cmd, const char *arch) { - gzFile *outfp; - int infp; - char dest[HUGE_STR+20]; - char buf[HUGE_STR]; - int len; - snprintf(dest, sizeof(dest), "%s.gz", arch); - /* low prio */ - if(nice(10) == -1) { - fprintf(stderr, "[%s]: WARNING, failed to change nice value: %s\n", cmd, strerror(errno)); - } - if((infp = open(arch, O_RDONLY)) == -1) { - /* failed to open file, can't compress it */ - fprintf(stderr,"[%s]: ERROR, could not open file for compression <%s>\n", cmd, arch); - return; - } - if((outfp = gzopen(dest,"wb")) == NULL) { - fprintf(stderr,"[%s]: ERROR, could not open file for compression <%s>\n", cmd, dest); - close(infp); - return; - } - chmod(dest, m_mode); - while((len = read(infp, buf, sizeof(buf))) > 0) { - gzwrite(outfp, buf, len); - } - gzclose(outfp); - close(infp); - /* done, delete the old file */ - unlink(arch); -} - -void sigchild(int signo) { - pid_t pid; - int stat; - while((pid=waitpid(-1,&stat,WNOHANG)) > 0) { - } -} - -void writeTimestamp() { - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - strftime(time_string, TME_STR_LEN, "%Y-%m-%d %H:%M:%S ", ptr); - write(m_nLogFD, time_string, TME_STR_LEN); -} - -/** - * Rotates a file - * - * @param cmd Command name to be used in log messages - * @param now - * @param file_name Name of the file to rotate (rename) - * @param messages Number of lines/buffers which had been read - */ -static void rotate(const char *cmd, time_t now, - const char *file_name, long *messages) { - int rc; - char arch[HUGE_STR+20]; - char tmb[20]; - struct tm *ptr = localtime(&now); - strftime(tmb, sizeof(tmb), "%Y%m%d%H%M%S", ptr); - snprintf(arch, sizeof(arch), "%s.%s", file_name, tmb); - - /* set next rotation time */ - m_tLogEnd = ((now / m_tRotation) * m_tRotation) + m_tRotation; - // reset byte counter - m_counter = 0; - - /* rename current file */ - if(m_nLogFD >= 0) { - close(m_nLogFD); - rename(file_name, arch); - } - - /* open new file */ - m_nLogFD = openFile(cmd, file_name); - if(m_nLogFD < 0) { - /* opening a new file has failed! - try to reopen and clear the last file */ - char msg[HUGE_STR]; - snprintf(msg, sizeof(msg), "ERROR while writing to file, %ld messages lost\n", *messages); - fprintf(stderr,"[%s]: ERROR, while writing to file <%s>\n", cmd, file_name); - rename(arch, file_name); - m_nLogFD = openFile(cmd, file_name); - if(m_nLogFD > 0) { - rc = ftruncate(m_nLogFD, 0); - rc = write(m_nLogFD, msg, strlen(msg)); - } - } else { - *messages = 0; - if(m_compress || (m_generations != -1)) { - signal(SIGCHLD,sigchild); - if(fork() == 0) { - if(m_compress) { - compressThread(cmd, arch); - } - if(m_generations != -1) { - qs_deleteOldFiles(file_name, m_generations); - } - exit(0); - } - } - } -} - -/** - * Separate thread which initiates file rotation even no - * log data is written. - * - * @param argv (not used) - */ -static void *forcedRotationThread(void *argv) { - time_t now; - time_t n; - while(1) { - qs_csLock(); - now = get_now(); - if(now > m_tLogEnd) { - rotate(m_cmd, now, m_file_name, &m_messages); - } - qs_csUnLock(); - now = get_now(); - n = 1 + m_tLogEnd - now; - sleep(n); - } - return NULL; -} - -void handle_signal1(int signal) { - rotate(m_cmd, get_now(), m_file_name, &m_messages); - return; -} - -int main(int argc, char **argv) { - char *username = NULL; - int rc; - char *buf; - int nRead, nWrite; - time_t now; - struct stat st; - long sizeLimit = 0; - - pthread_attr_t *tha = NULL; - pthread_t tid; - struct sigaction sa; - - char *cmd = strrchr(argv[0], '/'); - - sa.sa_handler = &handle_signal1; - sa.sa_flags = SA_RESTART; - - if(cmd == NULL) { - cmd = argv[0]; - } else { - cmd++; - } - m_cmd = calloc(1, strlen(cmd)+1); - strcpy(m_cmd, cmd); // copy as we can't pass it when forking - - while(argc >= 1) { - if(strcmp(*argv,"-o") == 0) { - if (--argc >= 1) { - m_file_name = *(++argv); - } - } else if(strcmp(*argv,"-u") == 0) { - if (--argc >= 1) { - username = *(++argv); - } - } else if(strcmp(*argv,"-s") == 0) { - if (--argc >= 1) { - m_tRotation = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-t") == 0) { - if (--argc >= 1) { - m_offset = atoi(*(++argv)); - m_offset = m_offset * 3600; - m_offset_enabled = 1; - } - } else if(strcmp(*argv,"-g") == 0) { - if (--argc >= 1) { - m_generations = atoi(*(++argv)); - } - } else if(strcmp(*argv,"-b") == 0) { - if (--argc >= 1) { - sizeLimit = atol(*(++argv)); - } - } else if(strcmp(*argv,"-m") == 0) { - if (--argc >= 1) { - int mode = atoi(*(++argv)); - if(mode == 600) { - m_mode = 0600; - } else if(mode == 640) { - m_mode = 0640; - } else if(mode == 660) { - m_mode = 0660; - } else if(mode == 664) { - m_mode = 0664; - } - } - } else if(strcmp(*argv,"-z") == 0) { - m_compress = 1; - } else if(strcmp(*argv,"-p") == 0) { - m_stdout = 1; - } else if(strcmp(*argv,"-d") == 0) { - m_timestamp = 1; - memset(time_string, 32, TME_STR_LEN); - } else if(strcmp(*argv,"-f") == 0) { - m_force_rotation = 1; - } else if(strcmp(*argv,"-h") == 0) { - usage(m_cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(m_cmd, 0); - } else if(strcmp(*argv,"-?") == 0) { - usage(m_cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(m_cmd, 1); - } - - argc--; - argv++; - } - - if(m_file_name == NULL) usage(m_cmd, 0); - if(sizeLimit > 0 && sizeLimit < m_limit && sizeLimit >= (1024 * 1024)) { - m_limit = sizeLimit; - } else if(sizeLimit > 0 && sizeLimit < (1024 * 1024)) { - m_limit = 1024 * 1024; - } - - if(stat(m_file_name, &st) == 0) { - m_counter = st.st_size; - } - - sigaction(SIGUSR1, &sa, NULL); - qs_setuid(username, m_cmd); - - /* set next rotation time */ - now = get_now(); - m_tLogEnd = ((now / m_tRotation) * m_tRotation) + m_tRotation; - /* open file */ - m_nLogFD = openFile(m_cmd, m_file_name); - if(m_nLogFD < 0) { - /* startup did not success */ - exit(2); - } - - if(m_force_rotation) { - qs_csInitLock(); - pthread_create(&tid, tha, forcedRotationThread, NULL); - } - - buf = calloc(1, MAX_LINE_BUFFER+1); - for(;;) { - if(m_timestamp) { - // low perf line-by-line read - if(fgets(buf, MAX_LINE_BUFFER, stdin) == NULL) { - exit(3); - } else { - nRead = strlen(buf); - if(m_force_rotation) { - qs_csLock(); // >@CTR1 - } - m_counter += (nRead + TME_STR_LEN); - now = get_now(); - writeTimestamp(); - nWrite = write(m_nLogFD, buf, nRead); - } - } else { - // normal/fast buffer read/process - nRead = read(0, buf, MAX_LINE_BUFFER); - if(nRead == 0) exit(3); - if(nRead < 0) if(errno != EINTR) exit(4); - if(m_force_rotation) { - qs_csLock(); // >@CTR1 - } - m_counter += nRead; - now = get_now(); - /* write data if we have a file handle (else continue but drop log data, - re-try to open the file at next rotation time) */ - if(m_nLogFD >= 0) { - do { - nWrite = write(m_nLogFD, buf, nRead); - if(m_stdout) { - printf("%.*s", nRead, buf); - } - } while (nWrite < 0 && errno == EINTR); - } - m_messages++; - if(nWrite != nRead) { - if(m_nLogFD >= 0) { - char msg[HUGE_STR]; - snprintf(msg, sizeof(msg), "ERROR while writing to file, %ld messages lost\n", m_messages); - /* error while writing data, try to delete the old file and continue ... */ - rc = ftruncate(m_nLogFD, 0); - rc = write(m_nLogFD, msg, strlen(msg)); - m_messages = 0; - } - } - } - // end buffer or line read - if((now > m_tLogEnd) || (m_counter > m_limit)) { - /* rotate! */ - rotate(m_cmd, now, m_file_name, &m_messages); - } - if(m_force_rotation) { - qs_csUnLock(); // <@CTR1 - } - } - memset(buf, 0, MAX_LINE_BUFFER); - free(buf); - return 0; -} diff --git a/tools/src/qssign.c b/tools/src/qssign.c deleted file mode 100644 index 6ea7021..0000000 --- a/tools/src/qssign.c +++ /dev/null @@ -1,799 +0,0 @@ -/** - * Utilities for the quality of service module mod_qos. - * - * qssign.c: Log data signing tool to ensure data integrity. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -static const char revision[] = "$Id: qssign.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <unistd.h> -#include <string.h> -#include <stdlib.h> -#include <regex.h> -#include <signal.h> - -/* openssl */ -#include <openssl/evp.h> -#include <openssl/hmac.h> - -/* apr/apr-util */ -#define QS_USEAPR 1 -#include <apr.h> -#include <apr_base64.h> -#include <apr_pools.h> -#include <apr_strings.h> -#include <apr_thread_proc.h> -#include <apr_file_io.h> -#include <apr_time.h> - -#define PCRE2_CODE_UNIT_WIDTH 8 -#include <pcre2.h> - -#include "qs_util.h" -#include "qs_apo.h" - -#define SEQDIG "12" -#define QS_END "qssign---end-of-data" -#define QS_START "qssign---------start" - -static const char *m_start_fmt = ""; -static const char *m_end_fmt = ""; -static long m_nr = 1; -static int m_logend = 0; -static void (*m_end)(const char *, int) = NULL; -static int m_end_pos = 0; -static const char *m_sec = NULL; -static const EVP_MD *m_evp; -static qs_regex_t *m_filter = NULL; - -typedef struct { - const char* start_fmt; - const char* end_fmt; - const char* pattern; - const char* test; -} qos_p_t; - -#define severity "[A-Z]+" - -static const qos_p_t pattern[] = { - { - "%s | INFO | "QS_START, - "%s | INFO | "QS_END, - "^[0-9]{4}[-][0-9]{2}[-][0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}[ ]+[|][ ]+"severity"[ ]+[|][ ]+[a-zA-Z0-9]+", - "2010-04-14 20:18:37,464 | INFO | org.hibernate.cfg.Configuration" - }, - { - "%s INFO "QS_START, - "%s INFO "QS_END, - "^[0-9]{4}[-][0-9]{2}[-][0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}[ ]+"severity"[ ]+", - "2011-08-30 07:27:22,738 INFO loginId='test'" - }, - { - "%s qssign start INFO "QS_START, - "%s qssign end INFO "QS_END, - "^[0-9]{4}[-][0-9]{2}[-][0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}[ ]+[a-zA-Z0-9\\.-]+[ ]+[a-zA-Z0-9\\.-]+[ ]+"severity"[ ]+", - "2011-09-01 07:37:17,275 main org.apache.catalina.startup.Catalina INFO Server" - }, - { - "%s INFO "QS_START, - "%s INFO "QS_END, - "^[0-9]{4}[-][0-9]{2}[-][0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2},[0-9]{3}[ ]+", - "2011-08-30 07:27:22,738 " - }, - { NULL, NULL, NULL } -}; - -/** - * Writes the signed log line to stdout. - * - * @param line Data to sign - * @param line_size Length of the data - * @param sec Secret - * @param sec_len Length of the secret - */ -static void qs_write(char *line, int line_size, const char *sec, int sec_len) { -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX hmac; - HMAC_CTX *hmac_p = &hmac; -#else - HMAC_CTX *hmac_p; -#endif - unsigned char data[HMAC_MAX_MD_CBLOCK]; - unsigned int len; - char *m; - int data_len; - sprintf(&line[strlen(line)], " %."SEQDIG"ld", m_nr); -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX_init(hmac_p); -#else - hmac_p = HMAC_CTX_new(); -#endif - HMAC_Init_ex(hmac_p, sec, sec_len, m_evp, NULL); - HMAC_Update(hmac_p, (const unsigned char *)line, strlen(line)); - HMAC_Final(hmac_p, data, &len); -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX_cleanup(hmac_p); -#else - HMAC_CTX_free(hmac_p); -#endif - m = calloc(1, apr_base64_encode_len(len) + 1); - data_len = apr_base64_encode(m, (char *)data, len); - m[data_len] = '\0'; - printf("%s#%s\n", line, m); - fflush(stdout); - free(m); - m_nr++; - return; -} - -/* - * [Fri Dec 03 07:37:40 2010] [notice] ......... - */ -static void qs_end_apache_err(const char *sec, int start) { - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - strftime(time_string, sizeof(time_string), "%a %b %d %H:%M:%S %Y", ptr); - if(start) { - sprintf(line, "[%s] [notice] "QS_START, time_string); - } else { - sprintf(line, "[%s] [notice] "QS_END, time_string); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -/* - * 12.12.12.12 - - [03/Dec/2010:07:36:51 +0100] ............... - */ -static void qs_end_apache_acc(const char *sec, int start) { - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - char sign; - int timz; - apr_time_exp_t xt; - apr_time_exp_lt(&xt, apr_time_now()); - timz = xt.tm_gmtoff; - if(timz < 0) { - timz = -timz; - sign = '-'; - } else { - sign = '+'; - } - strftime(time_string, sizeof(time_string), "%d/%b/%Y:%H:%M:%S", ptr); - if(start) { - sprintf(line, "0.0.0.0 - - [%s %c%.2d%.2d] "QS_START, time_string, sign, timz / (60*60), (timz % (60*60)) / 60); - } else { - sprintf(line, "0.0.0.0 - - [%s %c%.2d%.2d] "QS_END, time_string, sign, timz / (60*60), (timz % (60*60)) / 60); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -/* - * 2010 12 03 17:00:30.425 qssign end 0.0 5-NOTICE: .............. - */ -static void qs_end_nj(const char *sec, int start) { - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - char buf[1024]; - int i; - for(i = 0; i < m_end_pos; i++) { - buf[i] = ' '; - } - buf[i] = '\0'; - strftime(time_string, sizeof(time_string), "%Y %m %d %H:%M:%S.000", ptr); - if(start) { - sprintf(line, "%s qssign start 0.0%s 5-NOTICE: "QS_START, time_string, buf); - } else { - sprintf(line, "%s qssign end 0.0%s 5-NOTICE: "QS_END, time_string, buf); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -/* - * 2010-04-14 20:18:37,464 ... (using m_fmt) - */ -static void qs_end_lj(const char *sec, int start) { - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - strftime(time_string, sizeof(time_string), "%Y-%m-%d %H:%M:%S,000", ptr); - if(start) { - sprintf(line, m_start_fmt, time_string); - } else { - sprintf(line, m_end_fmt, time_string); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -/* - * Dec 6 04:00:06 localhost kernel: - */ -static void qs_end_lx(const char *sec, int start) { - char hostname[1024]; - int len = sizeof(hostname); - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - strftime(time_string, sizeof(time_string), "%b %e %H:%M:%S", ptr); - if(gethostname(hostname, len) != 0) { - hostname[0] = '-'; - hostname[1] = '\0'; - } - if(start) { - sprintf(line, "%s %s qssign: "QS_START, time_string, hostname); - } else { - sprintf(line, "%s %s qssign: "QS_END, time_string, hostname); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -/* - * 2013/11/13 17:38:41 [error] 6577#0: *1 open() - */ -static void qs_end_ngx(const char *sec, int start) { - int sec_len = strlen(sec); - char line[MAX_LINE]; - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = sizeof(line) - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - char time_string[1024]; - time_t tm = time(NULL); - struct tm *ptr = localtime(&tm); - strftime(time_string, sizeof(time_string), "%Y/%m/%d %H:%M:%S", ptr); - if(start) { - sprintf(line, "%s [notice] 0#0: "QS_END, time_string); - } else { - sprintf(line, "%s [notice] 0#0: "QS_END, time_string); - } - qs_write(line, line_size, sec, sec_len); - return; -} - -void qs_signal_exit(int e) { - if(m_logend && (m_end != NULL)) { - m_end(m_sec, 0); - } - exit(0); -} - -/** - * Tries to find out a suitable log line format which is used - * to log sign end messages (so let the verifier known, that the - * data ends nothing has been cut off). - * - * Sets the format to global variables. - * - * known pattern - * - [Fri Dec 03 07:37:40 2010] [notice] ......... - * - 12.12.12.12 - - [03/Dec/2010:07:36:51 +0100] ............... - * - 2010 12 03 17:00:30.425 qssign end 0.0 5-NOTICE: .............. - * 46 <- var -> 63 71 - * - Dec 6 04:00:06 localhost kernel: - * - some 2010-12-03 17:00:30,425 ... - * - * @param s - */ -static void qs_set_format(char *s) { - regex_t r_apache_err; - regex_t r_apache_acc; - regex_t r_nj; - regex_t r_lx; - regex_t r_ngx; - if(regcomp(&r_apache_err, - "^\\[[a-zA-Z]{3} [a-zA-Z]{3} [0-9]+ [0-9]+:[0-9]+:[0-9]+ [0-9]+\\] \\[[a-zA-Z]+\\] ", - REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (err)\n"); - exit(1); - } - if(regcomp(&r_apache_acc, - "^[0-9.]+ [a-zA-Z0-9\\@_\\.\\-]+ [a-zA-Z0-9\\@_\\.\\-]+ \\[[0-9]+/[a-zA-Z]{3}/[0-9:]+[0-9\\+ ]+\\] ", - REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (acc)\n"); - exit(1); - } - if(regcomp(&r_nj, - "^[0-9]{4} [0-9]{2} [0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2}\\.[0-9]{3} [a-zA-Z0-9]+[ ]+.*[A-Z]+[ ]*:", - REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (nj)\n"); - exit(1); - } - if(regcomp(&r_lx, - "^[a-zA-Z]{3}[ ]+[0-9]+[ ]+[0-9]{2}:[0-9]{2}:[0-9]{2}[ ]+[a-zA-Z0-9_\\.\\-]+[ ]+[a-zA-Z0-9_\\.\\-]+:", - REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (lx)\n"); - exit(1); - } - if(regcomp(&r_ngx, - "^[0-9]{4}/[0-9]{2}/[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2} \\[[a-z]+\\] [0-9]+#[0-9]+: ", - REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (ngx)\n"); - exit(1); - } - - - if(regexec(&r_apache_err, s, 0, NULL, 0) == 0) { - m_end = &qs_end_apache_err; - } else if(regexec(&r_apache_acc, s, 0, NULL, 0) == 0) { - m_end = &qs_end_apache_acc; - } else if(regexec(&r_nj, s, 0, NULL, 0) == 0) { - char *dp = strstr(s, ": "); - if(dp) { - /* calculate the "var" size, see comment above */ - m_end_pos = dp - s - 47 - 8 - 3; - if((m_end_pos < 0) || (m_end_pos > 1000)) { - m_end_pos = 0; - } - } - m_end = &qs_end_nj; - } else if(regexec(&r_lx, s, 0, NULL, 0) == 0) { - m_end = &qs_end_lx; - } else if(regexec(&r_ngx, s, 0, NULL, 0) == 0) { - m_end = &qs_end_ngx; - } - // search within the generic yyyy-mm-dd hh-mm-ss,mmm patterns - if(!m_end) { - const qos_p_t *p = pattern; - while(p->end_fmt) { - regex_t r_j; - if(regcomp(&r_j, p->pattern, REG_EXTENDED) != 0) { - fprintf(stderr, "failed to compile regex (%s)\n", p->pattern); - exit(1); - } - if(regexec(&r_j, s, 0, NULL, 0) == 0) { - m_start_fmt = p->start_fmt; - m_end_fmt = p->end_fmt; - m_end = &qs_end_lj; - break; - } - p++; - } - } - /* default (apache error log format) */ - if(m_end == NULL) { - m_end = &qs_end_apache_err; - } - return; -} - -/** - * Process the data from stdin. - * - * @param sec Passphrase - */ -static void qs_sign(const char *sec) { - int sec_len = strlen(sec); - char *line = calloc(1, MAX_LINE_BUFFER+1); - int dig = atoi(SEQDIG); - /* <data> ' ' <sequence number> '#' <hmac>*/ - int line_size = MAX_LINE_BUFFER - 1 - dig - 1 - (2*HMAC_MAX_MD_CBLOCK) - 1; - int line_len; - while(fgets(line, MAX_LINE_BUFFER, stdin) != NULL) { - line_len = strlen(line) - 1; - while(line_len > 0) { // cut tailing CR/LF - if(line[line_len] >= ' ') { - break; - } - line[line_len] = '\0'; - line_len--; - } - if(m_logend && (m_end == NULL)) { - qs_set_format(line); - m_end(m_sec, 1); - } - if(m_filter != NULL && qs_regexec_len(m_filter, line, line_len, 0, NULL, 0) >= 0) { - printf("%s\n", line); - fflush(stdout); - } else { - qs_write(line, line_size, sec, sec_len); - } - } - return; -} - -static int isSpecialLine(const char *line, const char *marker) { - char *se_marker = strstr(line, marker); - if(se_marker != NULL) { - /* QS_END/START + " " + SEQDIG */ - int sz = strlen(marker) + 1 + atoi(SEQDIG); - if(sz == (strlen(line) - (se_marker - line))) { - return 1; - } - } - return 0; -} - -static long qs_verify(const char *sec) { - int end_seen = 0; - int sec_len = strlen(sec); - long err = 0; // errors - long lineNumber = 0; // line number of the file / input data - char *line = calloc(1, MAX_LINE_BUFFER+1); - int line_size = MAX_LINE_BUFFER; - int line_len; - m_nr = -1; // expected sequence number (start with any) - long nr_alt = -1; // alternatively expected sequence number (if a line was injected) - long nr_alt_lineNumber = -1; - long nr_usr1_lineNumber = -1; // we may have lines written by a prev. qssign binary (while graceful restart) - while(fgets(line, line_size, stdin) != NULL) { - int valid = 0; - long msgSeqNr = 0; - int isOldProcess = 0; -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX hmac; - HMAC_CTX *hmac_p = &hmac; -#else - HMAC_CTX *hmac_p; -#endif - unsigned char data[HMAC_MAX_MD_CBLOCK]; - unsigned int len; - char *m; - int data_len; - char *sig; - char *seq; - line_len = strlen(line) - 1; - while(line_len > 0) { // cut tailing CR/LF - if(line[line_len] >= ' ') { - break; - } - line[line_len] = '\0'; - line_len--; - } - sig = strrchr(line, '#'); - seq = strrchr(line, ' '); - lineNumber++; - if(seq && sig) { - sig[0] = '\0'; - sig++; - /* verify hmac */ -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX_init(hmac_p); -#else - hmac_p = HMAC_CTX_new(); -#endif - HMAC_Init_ex(hmac_p, sec, sec_len, m_evp, NULL); - HMAC_Update(hmac_p, (const unsigned char *)line, strlen(line)); - HMAC_Final(hmac_p, data, &len); -#if OPENSSL_VERSION_NUMBER < 0x10100000L - HMAC_CTX_cleanup(hmac_p); -#else - HMAC_CTX_free(hmac_p); -#endif - m = calloc(1, apr_base64_encode_len(len) + 1); - data_len = apr_base64_encode(m, (char *)data, len); - m[data_len] = '\0'; - if(strcmp(m, sig) != 0) { - err++; - fprintf(stderr, "ERROR on line %ld: invalid signature\n", lineNumber); - /* message may be modified/corrupt or inserted: next line may have - the next sequence number (modified) or the same (inserted) */ - nr_alt = m_nr + 1; - nr_alt_lineNumber = lineNumber + 1; - } else { - valid = 1; - } - free(m); - /* verify sequence */ - seq++; - msgSeqNr = atol(seq); - if(msgSeqNr == 0) { - err++; - fprintf(stderr, "ERROR on line %ld: invalid sequence\n", lineNumber); - } else { - if(m_nr != -1) { - if(lineNumber == nr_alt_lineNumber) { - // last line was modified - if(m_nr != msgSeqNr) { - // and therefore, we also accept the next sequence number - m_nr = nr_alt; - } - nr_alt = -1; - nr_alt_lineNumber = -1; - } - if(valid && isSpecialLine(line, QS_START)) { - // new start line (graceful restart) - // we expect now msg number 1 - // but still acept the old until we get the end marker - nr_usr1_lineNumber = m_nr; - m_nr = 1; - } - if(valid && nr_usr1_lineNumber == msgSeqNr) { - // msg from old process is okay... - nr_usr1_lineNumber++; - isOldProcess = 1; - } else { - if(m_nr != msgSeqNr) { - if(msgSeqNr == 1) { - if(!end_seen) { - err++; - fprintf(stderr, "ERROR on line %ld: wrong sequence, server restart? (expect %."SEQDIG"ld)\n", - lineNumber, m_nr); - } - } else { - err++; - fprintf(stderr, "ERROR on line %ld: wrong sequence (expect %."SEQDIG"ld)\n", lineNumber, m_nr); - } - } else { - // well done - this is the sequence number we expect - } - } - } else if(m_logend) { - // log should (if not rotated) start with message 1 - if(msgSeqNr != 1) { - fprintf(stderr, "NOTICE: log starts with sequence %."SEQDIG"ld, log rotation?" - " (expect %."SEQDIG"d)\n", msgSeqNr, 1); - } - } - if(valid && !isOldProcess) { - // adjust - m_nr = msgSeqNr; - } - } - } else { - err++; - fprintf(stderr, "ERROR on line %ld: missing signature/sequence\n", lineNumber); - } - end_seen = 0; - if(valid) { - if(!isOldProcess) { - m_nr++; - } - if(isSpecialLine(line, QS_END)) { - if(nr_usr1_lineNumber == -1) { - end_seen = 1; - } else { - nr_usr1_lineNumber = -1; // no more messages from an old process - } - } - } - } - if(m_logend && !end_seen) { - fprintf(stderr, "NOTICE: no end marker seen, log rotation? (expect %."SEQDIG"ld)\n", m_nr); - } - return err; -} - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - an utility to sign and verify the integrity of log data.\n", cmd); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -s|S <secret> [-e] [-v] [-u <name>] [-f <regex>] [-a 'sha1'|'sha256']\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, "%s is a log data integrity check tool. It reads log data\n", cmd); - qs_man_print(man, "from stdin (pipe) and writes the data to stdout adding a sequence\n"); - qs_man_print(man, "number and signature to ever log line.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -s <secret>\n"); - if(man) printf("\n"); - qs_man_print(man, " Passphrase used to calculate signature.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -S <program>\n"); - if(man) printf("\n"); - qs_man_print(man, " Specifies a program which writes the passphrase to stdout.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -e\n"); - if(man) printf("\n"); - qs_man_print(man, " Writes start/end marker when starting/stopping data signing.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -v\n"); - if(man) printf("\n"); - qs_man_print(man, " Verification mode checking the integrity of signed data.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -u <name>\n"); - if(man) printf("\n"); - qs_man_print(man, " Becomes another user, e.g. www-data.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -f <regex>\n"); - if(man) printf("\n"); - qs_man_print(man, " Filter pattern (case sensitive regular expression) for messages\n"); - qs_man_print(man, " which do not need to be signed.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -a 'sha1'|'sha256'\n"); - if(man) printf("\n"); - qs_man_print(man, " Specifies the algorithm to use. Default is sha1.\n"); - printf("\n"); - if(man) { - printf(".SH EXAMPLE\n"); - printf("Sign:\n"); - printf("\n"); - } else { - printf("Example (sign):\n"); - } - qs_man_println(man, " TransferLog \"|/usr/bin/%s -s password -e |/usr/bin/qsrotate -o /var/log/apache/access.log\"\n", cmd); - printf("\n"); - if(man) { - printf("\n"); - printf("Verify:\n"); - printf("\n"); - } else { - qs_man_print(man, "Example (verify):\n"); - } - qs_man_println(man, " cat access.log | %s -s password -v\n", cmd); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qstail(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -int main(int argc, const char * const argv[]) { - apr_pool_t *pool; - int verify = 0; - char *cmd = strrchr(argv[0], '/'); - const char *username = NULL; - const char *filter = NULL; - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - apr_app_initialize(&argc, &argv, NULL); - apr_pool_create(&pool, NULL); - m_evp = EVP_sha1(); - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-s") == 0) { - if (--argc >= 1) { - m_sec = *(++argv); - } - } else if(strcmp(*argv,"-S") == 0) { - if (--argc >= 1) { - m_sec = qs_readpwd(pool, *(++argv)); - } - } else if(strcmp(*argv,"-v") == 0) { - verify = 1; - } else if(strcmp(*argv,"-e") == 0) { - m_logend = 1; - } else if(strcmp(*argv,"-u") == 0) { /* switch user id */ - if (--argc >= 1) { - username = *(++argv); - } - } else if(strcmp(*argv,"-f") == 0) { /* filter */ - if (--argc >= 1) { - filter = *(++argv); - } - } else if(strcmp(*argv,"-a") == 0) { /* set alg */ - if (--argc >= 1) { - const char *alg = *(++argv); - if(strcasecmp(alg, "SHA256") == 0) { - m_evp = EVP_sha256(); - } else if(strcasecmp(alg, "SHA1") != 0) { - m_evp = NULL; - } - } else { - m_evp = NULL; - } - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } - argc--; - argv++; - } - - if(filter != NULL) { - m_filter = apr_palloc(pool, sizeof(qs_regex_t)); - if(qs_regcomp(m_filter, filter, 0) != 0) { - fprintf(stderr, "failed to compile filter pattern <%s>\n", filter); - exit(1); - } - apr_pool_pre_cleanup_register(pool, m_filter, qs_pregfree); - } - - if(m_evp == NULL) { - usage(cmd, 0); - } - - if(m_sec == NULL) { - usage(cmd, 0); - } - - qs_setuid(username, cmd); - - if(verify) { - long err = qs_verify(m_sec); - if(err != 0) { - return 1; - } - } else { - if(m_logend) { - signal(SIGTERM, qs_signal_exit); - } - qs_sign(m_sec); - if(m_logend && (m_end != NULL)) { - m_end(m_sec, 0); - } - } - - apr_pool_destroy(pool); - return 0; -} diff --git a/tools/src/qstail.c b/tools/src/qstail.c deleted file mode 100644 index 3d535e2..0000000 --- a/tools/src/qstail.c +++ /dev/null @@ -1,237 +0,0 @@ -/* -*-mode: c; indent-tabs-mode: nil; c-basic-offset: 2; -*- - */ -/** - * Utilities for the quality of service module mod_qos. - * - * qstail.c: Shows the end of a log file beginning at the - * provided pattern. - * - * See http://mod-qos.sourceforge.net/ for further - * details. - * - * Copyright (C) 2023 Pascal Buchbinder - * - * Licensed to the Apache Software Foundation (ASF) under one or more - * contributor license agreements. See the NOTICE file distributed with - * this work for additional information regarding copyright ownership. - * The ASF licenses this file to You under the Apache License, Version 2.0 - * (the "License"); you may not use this file except in compliance with - * the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ - -static const char revision[] = "$Id: qstail.c 2654 2022-05-13 09:12:42Z pbuchbinder $"; - -#include <stdio.h> -#include <unistd.h> -#include <string.h> -#include <stdlib.h> -#include <signal.h> - -#include "qs_util.h" - -#define BUFFER 2048 - -static void usage(char *cmd, int man) { - if(man) { - //.TH [name of program] [section number] [center footer] [left footer] [center header] - printf(".TH %s 1 \"%s\" \"mod_qos utilities %s\" \"%s man page\"\n", qs_CMD(cmd), man_date, - man_version, cmd); - } - printf("\n"); - if(man) { - printf(".SH NAME\n"); - } - qs_man_print(man, "%s - an utility printing the end of a log file" - " starting at the specified pattern.\n", cmd); - printf("\n"); - if(man) { - printf(".SH SYNOPSIS\n"); - } - qs_man_print(man, "%s%s -i <path> -p <pattern>\n", man ? "" : "Usage: ", cmd); - printf("\n"); - if(man) { - printf(".SH DESCRIPTION\n"); - } else { - printf("Summary\n"); - } - qs_man_print(man, " %s shows the end of a log file beginning with the line containing the\n", cmd); - qs_man_print(man, " specified pattern. This may be used to show all lines which has been written\n"); - qs_man_print(man, " after a certain event (e.g., server restart) or time stamp.\n"); - printf("\n"); - if(man) { - printf(".SH OPTIONS\n"); - } else { - printf("Options\n"); - } - if(man) printf(".TP\n"); - qs_man_print(man, " -i <path>\n"); - if(man) printf("\n"); - qs_man_print(man, " Input file to read the data from.\n"); - if(man) printf("\n.TP\n"); - qs_man_print(man, " -p <pattern>\n"); - if(man) printf("\n"); - qs_man_print(man, " Search pattern (literal string).\n"); - printf("\n"); - if(man) { - printf(".SH SEE ALSO\n"); - printf("qsdt(1), qsexec(1), qsfilter2(1), qsgeo(1), qsgrep(1), qshead(1), qslog(1), qslogger(1), qspng(1), qsre(1), qsrespeed(1), qsrotate(1), qssign(1)\n"); - printf(".SH AUTHOR\n"); - printf("Pascal Buchbinder, http://mod-qos.sourceforge.net/\n"); - } else { - printf("See http://mod-qos.sourceforge.net/ for further details.\n"); - } - if(man) { - exit(0); - } else { - exit(1); - } -} - -/* search the beginning of the line starting at the provided position */ -static void qs_readline(long pos, FILE *f) { - size_t len; - long startpos = pos - BUFFER + 1; - long readlen = BUFFER; - char line[readlen + 1]; - if(startpos < 0) { - // we are at the beginning of the file - startpos = 0; - readlen = pos + 1; - } - fseek(f, startpos, SEEK_SET); - len = fread(&line, 1, readlen, f); - if(len > 0) { - char *s = &line[len-1]; - line[len] = '\0'; - while((s >= line) && (s[0] != CR) && (s[0] != LF)) { - s--; - } - if((s[0] == CR) || (s[0] == LF)) { - s++; - } - printf("%s", s); - } -} - -static int qs_tail(const char *cmd, FILE *f, const char *pattern) { - char *cont = NULL; - long search_win_len = (strlen(pattern) * 2) + 32; - char line[search_win_len + 10]; - long pos = 0; - size_t len; - char *startpattern = NULL; - fseek(f, 0L, SEEK_END); - pos = ftell(f); - while(pos > search_win_len) { - int offset = 0; - pos = pos - (search_win_len/2); - fseek(f, pos, SEEK_SET); - len = fread(&line, 1, search_win_len, f); - if(len <= 0) { - /* pattern not found / reached end */ - return 1; - } - line[len] = '\0'; - if((startpattern = strstr(line, pattern)) != NULL) { - int containsend = 0; - char *s = startpattern; - char *end; - offset = startpattern - line; - /* search the beginning of the line */ - while((s > line) && (s[0] != CR) && (s[0] != LF)) { - s--; - } - if((s[0] != CR) && (s[0] != LF)) { - // beginning of the line not in the buffer - qs_readline(pos, f); - } - s++; - end = startpattern; - /* search the end of the line */ - while((offset < search_win_len) && end[0] && end[0] != CR && end[0] != LF) { - end++; - offset++; - } - /* print the line containing the pattern */ - if((end[0] == CR) || (end[0] == LF)) { - end[0] = '\0'; - printf("%s\n", s); - containsend = 1; - } else { - printf("%s", s); - } - fseek(f, pos + offset, SEEK_SET); - if(containsend) { - // skip the line at the current position - cont = fgets(line, sizeof(line), f); - } else { - cont = line; - } - if(cont) { - while(fgets(line, sizeof(line), f) != NULL) { - printf("%s", line); - } - } - return 0; - } - } - return 1; -} - -int main(int argc, const char * const argv[]) { - FILE *f; - const char *filename = NULL; - const char *pattern = NULL; - char *cmd = strrchr(argv[0], '/'); - int status = 0; - if(cmd == NULL) { - cmd = (char *)argv[0]; - } else { - cmd++; - } - - argc--; - argv++; - while(argc >= 1) { - if(strcmp(*argv,"-i") == 0) { - if (--argc >= 1) { - filename = *(++argv); - } - } else if(strcmp(*argv,"-p") == 0) { - if (--argc >= 1) { - pattern = *(++argv); - } - } else if(strcmp(*argv,"-?") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"-help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--help") == 0) { - usage(cmd, 0); - } else if(strcmp(*argv,"--man") == 0) { - usage(cmd, 1); - } - argc--; - argv++; - } - - if(filename == NULL || pattern == NULL) { - usage(cmd, 0); - } - if((f = fopen(filename, "r")) == NULL) { - fprintf(stderr, "[%s]: ERROR, could not open file '%s'\n", cmd, filename); - exit(1); - } - - status = qs_tail(cmd, f, pattern); - - fclose(f); - return status; -}