Coverage Report

Created: 2026-09-06 07:25

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/suricata8/src/log-flush.c
Line
Count
Source
1
/* Copyright (C) 2026 Open Information Security Foundation
2
 *
3
 * You can copy, redistribute or modify this Program under the terms of
4
 * the GNU General Public License version 2 as published by the Free
5
 * Software Foundation.
6
 *
7
 * This program is distributed in the hope that it will be useful,
8
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
10
 * GNU General Public License for more details.
11
 *
12
 * You should have received a copy of the GNU General Public License
13
 * version 2 along with this program; if not, write to the Free Software
14
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
 * 02110-1301, USA.
16
 */
17
18
/**
19
 * \file
20
 *
21
 * \author Jeff Lucovsky <jlucovsky@oisf.net>
22
 */
23
24
#include "suricata-common.h"
25
#include "suricata.h"
26
#include "log-flush.h"
27
#include "util-logopenfile.h"
28
#include "tm-threads.h"
29
#include "conf.h"
30
#include "conf-yaml-loader.h"
31
#include "util-privs.h"
32
#include "util-logopenfile.h"
33
34
int OutputFlushInterval(void)
35
8
{
36
8
    intmax_t output_flush_interval = 0;
37
8
    if (SCConfGetInt("heartbeat.output-flush-interval", &output_flush_interval) == 0) {
38
8
        output_flush_interval = 0;
39
8
    }
40
8
    if (output_flush_interval < 0 || output_flush_interval > 60) {
41
0
        SCLogConfig("flush_interval must be 0 or less than 60; using 0");
42
0
        output_flush_interval = 0;
43
0
    }
44
45
8
    return (int)output_flush_interval;
46
8
}
47
48
static void *LogFlusherWakeupThread(void *arg)
49
0
{
50
0
    int output_flush_interval = OutputFlushInterval();
51
    /* This was checked by the logic creating this thread */
52
0
    BUG_ON(output_flush_interval == 0);
53
54
0
    SCLogConfig("Using output-flush-interval of %d seconds", output_flush_interval);
55
    /*
56
     * Calculate the number of sleep intervals based on the output flush interval. This is necessary
57
     * because this thread pauses a fixed amount of time to react to shutdown situations more
58
     * quickly.
59
     */
60
0
    const int log_flush_sleep_time = 500; /* milliseconds */
61
0
    const int flush_wait_count = (1000 * output_flush_interval) / log_flush_sleep_time;
62
63
0
    ThreadVars *tv_local = (ThreadVars *)arg;
64
0
    SCSetThreadName(tv_local->name);
65
66
0
    if (tv_local->thread_setup_flags != 0)
67
0
        TmThreadSetupOptions(tv_local);
68
69
    /* Set the threads capability */
70
0
    tv_local->cap_flags = 0;
71
0
    SCDropCaps(tv_local);
72
73
0
    TmThreadsSetFlag(tv_local, THV_INIT_DONE | THV_RUNNING);
74
75
0
    int wait_count = 0;
76
0
    uint64_t worker_flush_count = 0;
77
0
    bool run = TmThreadsWaitForUnpause(tv_local);
78
0
    while (run) {
79
0
        SleepMsec(log_flush_sleep_time);
80
81
0
        if (++wait_count == flush_wait_count) {
82
0
            worker_flush_count++;
83
0
            LogFileFlushAll();
84
0
            wait_count = 0;
85
0
        }
86
87
0
        if (TmThreadsCheckFlag(tv_local, THV_KILL)) {
88
0
            break;
89
0
        }
90
0
    }
91
92
0
    TmThreadsSetFlag(tv_local, THV_RUNNING_DONE);
93
0
    TmThreadWaitForFlag(tv_local, THV_DEINIT);
94
0
    TmThreadsSetFlag(tv_local, THV_CLOSED);
95
0
    SCLogInfo("%s: initiated %" PRIu64 " flushes", tv_local->name, worker_flush_count);
96
0
    return NULL;
97
0
}
98
99
void LogFlushThreads(void)
100
0
{
101
0
    if (0 == OutputFlushInterval()) {
102
0
        SCLogConfig("log flusher thread not used with heartbeat.output-flush-interval of 0");
103
0
        return;
104
0
    }
105
106
0
    ThreadVars *tv_log_flush =
107
0
            TmThreadCreateMgmtThread(thread_name_heartbeat, LogFlusherWakeupThread, 1);
108
0
    if (!tv_log_flush || (TmThreadSpawn(tv_log_flush) != 0)) {
109
        FatalError("Unable to create and start log flush thread");
110
0
    }
111
0
}