/src/sudo/lib/iolog/iolog_timing.c
Line | Count | Source |
1 | | /* |
2 | | * SPDX-License-Identifier: ISC |
3 | | * |
4 | | * Copyright (c) 2009-2020 Todd C. Miller <Todd.Miller@sudo.ws> |
5 | | * |
6 | | * Permission to use, copy, modify, and distribute this software for any |
7 | | * purpose with or without fee is hereby granted, provided that the above |
8 | | * copyright notice and this permission notice appear in all copies. |
9 | | * |
10 | | * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES |
11 | | * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF |
12 | | * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR |
13 | | * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES |
14 | | * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN |
15 | | * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF |
16 | | * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. |
17 | | */ |
18 | | |
19 | | #include <config.h> |
20 | | |
21 | | #include <stdio.h> |
22 | | #include <stdlib.h> |
23 | | #ifdef HAVE_STDBOOL_H |
24 | | # include <stdbool.h> |
25 | | #else |
26 | | # include <compat/stdbool.h> |
27 | | #endif /* HAVE_STDBOOL_H */ |
28 | | #include <string.h> |
29 | | #include <signal.h> |
30 | | #include <unistd.h> |
31 | | #include <ctype.h> |
32 | | #include <errno.h> |
33 | | #include <limits.h> |
34 | | #include <fcntl.h> |
35 | | #include <time.h> |
36 | | |
37 | | #include <sudo_compat.h> |
38 | | #include <sudo_debug.h> |
39 | | #include <sudo_eventlog.h> |
40 | | #include <sudo_fatal.h> |
41 | | #include <sudo_gettext.h> |
42 | | #include <sudo_iolog.h> |
43 | | #include <sudo_util.h> |
44 | | |
45 | | void |
46 | | iolog_adjust_delay(struct timespec *delay, struct timespec *max_delay, |
47 | | double scale_factor) |
48 | 0 | { |
49 | 0 | debug_decl(iolog_adjust_delay, SUDO_DEBUG_UTIL); |
50 | | |
51 | | /* Avoid division by zero or negative delays. */ |
52 | 0 | if (scale_factor <= 0.0) { |
53 | 0 | sudo_timespecclear(delay); |
54 | 0 | debug_return; |
55 | 0 | } |
56 | | |
57 | 0 | if (scale_factor != 1.0) { |
58 | | /* Order is important: we don't want to double the remainder. */ |
59 | 0 | const double seconds = (double)delay->tv_sec / scale_factor; |
60 | 0 | const double nseconds = (double)delay->tv_nsec / scale_factor; |
61 | 0 | delay->tv_sec = (time_t)seconds; |
62 | 0 | delay->tv_nsec = (long)nseconds; |
63 | 0 | delay->tv_nsec += (long)((seconds - (double)delay->tv_sec) * 1000000000); |
64 | 0 | while (delay->tv_nsec >= 1000000000) { |
65 | 0 | delay->tv_sec++; |
66 | 0 | delay->tv_nsec -= 1000000000; |
67 | 0 | } |
68 | 0 | } |
69 | | |
70 | | /* Clamp to max delay. */ |
71 | 0 | if (max_delay != NULL) { |
72 | 0 | if (sudo_timespeccmp(delay, max_delay, >)) { |
73 | 0 | delay->tv_sec = max_delay->tv_sec; |
74 | 0 | delay->tv_nsec = max_delay->tv_nsec; |
75 | 0 | } |
76 | 0 | } |
77 | |
|
78 | 0 | debug_return; |
79 | 0 | } |
80 | | |
81 | | /* |
82 | | * Parse the delay as seconds and nanoseconds: %lld.%09ld |
83 | | * Sudo used to write this as a double, but since timing data is logged |
84 | | * in the C locale this may not match the current locale. |
85 | | */ |
86 | | char * |
87 | | iolog_parse_delay(const char *cp, struct timespec *delay, |
88 | | const char *decimal_point) |
89 | 4.13k | { |
90 | 4.13k | char numbuf[STRLEN_MAX_SIGNED(long long) + 1]; |
91 | 4.13k | const char *errstr, *ep; |
92 | 4.13k | long long llval; |
93 | 4.13k | size_t len; |
94 | 4.13k | debug_decl(iolog_parse_delay, SUDO_DEBUG_UTIL); |
95 | | |
96 | | /* Parse seconds (whole number portion). */ |
97 | 10.6k | for (ep = cp; isdigit((unsigned char)*ep); ep++) |
98 | 10.6k | continue; |
99 | 4.13k | len = (size_t)(ep - cp); |
100 | 4.13k | if (len >= sizeof(numbuf)) { |
101 | 9 | sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO, |
102 | 9 | "%s: number of seconds is too large", cp); |
103 | 9 | debug_return_ptr(NULL); |
104 | 9 | } |
105 | 4.12k | memcpy(numbuf, cp, len); |
106 | 4.12k | numbuf[len] = '\0'; |
107 | 4.12k | delay->tv_sec = (time_t)sudo_strtonum(numbuf, 0, TIME_T_MAX, &errstr); |
108 | 4.12k | if (errstr != NULL) { |
109 | 76 | sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO, |
110 | 76 | "%s: number of seconds is %s", numbuf, errstr); |
111 | 76 | debug_return_ptr(NULL); |
112 | 76 | } |
113 | | |
114 | | /* Radix may be in user's locale for sudo < 1.7.4 so accept that too. */ |
115 | 4.04k | if (*ep != '.' && *ep != *decimal_point) { |
116 | 3.26k | if (*ep == '\0' || isspace((unsigned char)*ep)) { |
117 | | /* No fractional part. */ |
118 | 3.25k | delay->tv_nsec = 0; |
119 | 3.25k | goto done; |
120 | 3.25k | } |
121 | 3.26k | sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO, |
122 | 16 | "invalid characters after seconds: %s", ep); |
123 | 16 | debug_return_ptr(NULL); |
124 | 16 | } |
125 | 778 | cp = ep + 1; |
126 | | |
127 | | /* Parse fractional part, we may read more precision than we can store. */ |
128 | 6.28k | for (ep = cp; isdigit((unsigned char)*ep); ep++) |
129 | 6.28k | continue; |
130 | 778 | len = (size_t)(ep - cp); |
131 | 778 | if (len >= sizeof(numbuf)) { |
132 | 5 | sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO, |
133 | 5 | "%s: number of nanoseconds is too large", cp); |
134 | 5 | debug_return_ptr(NULL); |
135 | 5 | } |
136 | 773 | memcpy(numbuf, cp, len); |
137 | 773 | numbuf[len] = '\0'; |
138 | 773 | llval = sudo_strtonum(numbuf, 0, LLONG_MAX, &errstr); |
139 | 773 | if (errstr != NULL) { |
140 | 9 | sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO, |
141 | 9 | "%s: number of nanoseconds is %s", numbuf, errstr); |
142 | 9 | debug_return_ptr(NULL); |
143 | 9 | } |
144 | | |
145 | | /* Adjust fractional part to nanosecond precision. */ |
146 | 764 | if (len < 9) { |
147 | | /* Convert to nanosecond precision. */ |
148 | 2.74k | do { |
149 | 2.74k | llval *= 10; |
150 | 2.74k | } while (++len < 9); |
151 | 416 | } else if (len > 9) { |
152 | | /* Clamp to nanoseconds. */ |
153 | 459 | do { |
154 | 459 | llval /= 10; |
155 | 459 | } while (--len > 9); |
156 | 222 | } |
157 | 764 | delay->tv_nsec = (long)llval; |
158 | | |
159 | 4.01k | done: |
160 | | /* Advance to the next field. */ |
161 | 4.01k | while (isspace((unsigned char)*ep)) |
162 | 4.00k | ep++; |
163 | | |
164 | 4.01k | debug_return_str((char *)ep); |
165 | 4.01k | } |
166 | | |
167 | | /* |
168 | | * Parse a timing line, which is formatted as: |
169 | | * IO_EVENT_TTYOUT sleep_time num_bytes |
170 | | * IO_EVENT_WINSIZE sleep_time lines cols |
171 | | * IO_EVENT_SUSPEND sleep_time signo |
172 | | * Where type is IO_EVENT_*, sleep_time is the number of seconds to sleep |
173 | | * before writing the data and num_bytes is the number of bytes to output. |
174 | | * Returns true on success and false on failure. |
175 | | */ |
176 | | bool |
177 | | iolog_parse_timing(const char *line, struct timing_closure *timing) |
178 | 4.27k | { |
179 | 4.27k | unsigned long ulval; |
180 | 4.27k | char *cp, *ep; |
181 | 4.27k | debug_decl(iolog_parse_timing, SUDO_DEBUG_UTIL); |
182 | | |
183 | | /* Clear iolog descriptor. */ |
184 | 4.27k | timing->iol = NULL; |
185 | | |
186 | | /* Parse event type. */ |
187 | 4.27k | ulval = strtoul(line, &ep, 10); |
188 | 4.27k | if (ep == line || !isspace((unsigned char) *ep)) |
189 | 10 | goto bad; |
190 | 4.26k | if (ulval == IO_EVENT_TTYOUT_1_8_7) { |
191 | | /* Sudo 1.8.7 timing files event indexes are off by two. */ |
192 | 1 | goto bad; |
193 | 1 | } |
194 | 4.26k | if (ulval >= IO_EVENT_COUNT) |
195 | 130 | goto bad; |
196 | 4.13k | timing->event = (int)ulval; |
197 | 4.13k | for (cp = ep + 1; isspace((unsigned char) *cp); cp++) |
198 | 212 | continue; |
199 | | |
200 | | /* Parse delay, returns the next field or NULL on error. */ |
201 | 4.13k | if ((cp = iolog_parse_delay(cp, &timing->delay, timing->decimal)) == NULL) |
202 | 115 | goto bad; |
203 | | |
204 | 4.01k | switch (timing->event) { |
205 | 2.18k | case IO_EVENT_SUSPEND: |
206 | | /* Signal name (no leading SIG prefix) or number. */ |
207 | 2.18k | if (str2sig(cp, &timing->u.signo) == -1) |
208 | 209 | goto bad; |
209 | 1.97k | break; |
210 | 1.97k | case IO_EVENT_WINSIZE: |
211 | 483 | ulval = strtoul(cp, &ep, 10); |
212 | 483 | if (ep == cp || !isspace((unsigned char) *ep)) |
213 | 27 | goto bad; |
214 | 456 | if (ulval > INT_MAX) |
215 | 63 | goto bad; |
216 | 393 | timing->u.winsize.lines = (int)ulval; |
217 | 393 | for (cp = ep + 1; isspace((unsigned char) *cp); cp++) |
218 | 194 | continue; |
219 | | |
220 | 393 | ulval = strtoul(cp, &ep, 10); |
221 | 393 | if (ep == cp || *ep != '\0') |
222 | 75 | goto bad; |
223 | 318 | if (ulval > INT_MAX) |
224 | 64 | goto bad; |
225 | 254 | timing->u.winsize.cols = (int)ulval; |
226 | 254 | break; |
227 | 1.34k | default: |
228 | 1.34k | errno = 0; |
229 | 1.34k | ulval = strtoul(cp, &ep, 10); |
230 | 1.34k | if (ep == cp || *ep != '\0') |
231 | 154 | goto bad; |
232 | | /* Note: assumes SIZE_MAX == ULONG_MAX */ |
233 | 1.19k | if (errno == ERANGE && ulval == ULONG_MAX) |
234 | 1 | goto bad; |
235 | | /* nbytes is also used as off_t, SIZE_MAX may be > OFF_T_MAX */ |
236 | 1.19k | if (ulval > OFF_T_MAX) { |
237 | 85 | errno = ERANGE; |
238 | 85 | goto bad; |
239 | 85 | } |
240 | 1.10k | timing->u.nbytes = (size_t)ulval; |
241 | 1.10k | break; |
242 | 4.01k | } |
243 | | |
244 | 3.33k | debug_return_bool(true); |
245 | 934 | bad: |
246 | 934 | debug_return_bool(false); |
247 | 934 | } |
248 | | |
249 | | /* |
250 | | * Read the next record from the timing file. |
251 | | * Return 0 on success, 1 on EOF and -1 on error. |
252 | | */ |
253 | | int |
254 | | iolog_read_timing_record(struct iolog_file *iol, struct timing_closure *timing) |
255 | 4.52k | { |
256 | 4.52k | char line[LINE_MAX]; |
257 | 4.52k | const char *errstr; |
258 | 4.52k | char *nl; |
259 | 4.52k | debug_decl(iolog_read_timing_record, SUDO_DEBUG_UTIL); |
260 | | |
261 | | /* Read next record from timing file. */ |
262 | 4.52k | if (iolog_gets(iol, line, sizeof(line), &errstr) == NULL) { |
263 | | /* EOF or error reading timing file, we are done. */ |
264 | 199 | if (iolog_eof(iol)) |
265 | 199 | debug_return_int(1); |
266 | 0 | sudo_warnx(U_("error reading timing file: %s"), errstr); |
267 | 0 | debug_return_int(-1); |
268 | 0 | } |
269 | | |
270 | | /* |
271 | | * All timing file records must end with a newline. |
272 | | * A missing newline may indicate a line longer than LINE_MAX. |
273 | | */ |
274 | 4.32k | nl = strchr(line, '\n'); |
275 | 4.32k | if (nl == NULL) { |
276 | 48 | goto invalid; |
277 | 48 | } |
278 | 4.27k | *nl = '\0'; |
279 | | |
280 | | /* Parse timing file record. */ |
281 | 4.27k | if (!iolog_parse_timing(line, timing)) { |
282 | 934 | goto invalid; |
283 | 934 | } |
284 | | |
285 | 3.33k | debug_return_int(0); |
286 | 982 | invalid: |
287 | | /* Truncate invalid timing file line at 128 bytes. */ |
288 | 982 | line[128] = '\0'; |
289 | 982 | sudo_warnx(U_("invalid timing file line: %s"), line); |
290 | 982 | debug_return_int(-1); |
291 | 982 | } |