blob: de13aba0542106c752f30024f4a1994f14bf7021 [file] [log] [blame]
Willy Tarreaubaaee002006-06-26 02:48:02 +02001/*
Willy Tarreaua5357cd2021-05-09 06:14:25 +02002 * HAProxy : High Availability-enabled HTTP/TCP proxy
Willy Tarreau421ed392021-01-06 17:41:32 +01003 * Copyright 2000-2021 Willy Tarreau <willy@haproxy.org>.
Willy Tarreaubaaee002006-06-26 02:48:02 +02004 *
5 * This program is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU General Public License
7 * as published by the Free Software Foundation; either version
8 * 2 of the License, or (at your option) any later version.
9 *
Ilya Shipitsin46a030c2020-07-05 16:36:08 +050010 * Please refer to RFC7230 - RFC7235 information about HTTP protocol, and
11 * RFC6265 for information about cookies usage. More generally, the IETF HTTP
Willy Tarreaubaaee002006-06-26 02:48:02 +020012 * Working Group's web site should be consulted for protocol related changes :
13 *
14 * http://ftp.ics.uci.edu/pub/ietf/http/
15 *
16 * Pending bugs (may be not fixed because never reproduced) :
17 * - solaris only : sometimes, an HTTP proxy with only a dispatch address causes
18 * the proxy to terminate (no core) if the client breaks the connection during
19 * the response. Seen on 1.1.8pre4, but never reproduced. May not be related to
20 * the snprintf() bug since requests were simple (GET / HTTP/1.0), but may be
21 * related to missing setsid() (fixed in 1.1.15)
22 * - a proxy with an invalid config will prevent the startup even if disabled.
23 *
24 * ChangeLog has moved to the CHANGELOG file.
25 *
Willy Tarreaubaaee002006-06-26 02:48:02 +020026 */
27
David Carlier7ece0962015-12-08 21:43:09 +000028#define _GNU_SOURCE
Willy Tarreaubaaee002006-06-26 02:48:02 +020029#include <stdio.h>
30#include <stdlib.h>
31#include <unistd.h>
32#include <string.h>
33#include <ctype.h>
Maxime de Roucy379d9c72016-05-13 23:52:56 +020034#include <dirent.h>
Maxime de Roucy379d9c72016-05-13 23:52:56 +020035#include <sys/stat.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020036#include <sys/time.h>
37#include <sys/types.h>
38#include <sys/socket.h>
39#include <netinet/tcp.h>
40#include <netinet/in.h>
41#include <arpa/inet.h>
42#include <netdb.h>
43#include <fcntl.h>
44#include <errno.h>
45#include <signal.h>
46#include <stdarg.h>
47#include <sys/resource.h>
Tim Duesterhusdfad6a42020-04-18 16:02:47 +020048#include <sys/utsname.h>
Marc-Antoine Perennou992709b2013-02-12 10:53:52 +010049#include <sys/wait.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020050#include <time.h>
51#include <syslog.h>
Michael Schererab012dd2013-01-12 18:35:19 +010052#include <grp.h>
Willy Tarreaufc6c0322012-11-16 16:12:27 +010053#ifdef USE_CPU_AFFINITY
Willy Tarreaufc6c0322012-11-16 16:12:27 +010054#include <sched.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000055#if defined(__FreeBSD__) || defined(__DragonFly__)
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +020056#include <sys/param.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000057#ifdef __FreeBSD__
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +020058#include <sys/cpuset.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000059#endif
David Carlier6d5c8412017-11-29 11:02:32 +000060#include <pthread_np.h>
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +020061#endif
David Carlier5e4c8e22019-09-13 05:12:58 +010062#ifdef __APPLE__
63#include <mach/mach_types.h>
64#include <mach/thread_act.h>
65#include <mach/thread_policy.h>
66#endif
Willy Tarreaufc6c0322012-11-16 16:12:27 +010067#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +020068
Willy Tarreau636848a2019-04-15 19:38:50 +020069#if defined(USE_PRCTL)
70#include <sys/prctl.h>
71#endif
72
Willy Tarreaubaaee002006-06-26 02:48:02 +020073#ifdef DEBUG_FULL
74#include <assert.h>
75#endif
Tim Duesterhusd6942c82017-11-20 15:58:35 +010076#if defined(USE_SYSTEMD)
77#include <systemd/sd-daemon.h>
78#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +020079
Willy Tarreau6c3a6812020-03-06 18:57:15 +010080#include <import/sha1.h>
81
Willy Tarreaub2551052020-06-09 09:07:15 +020082#include <haproxy/acl.h>
Amaury Denoyelle68fd7e42021-03-25 17:15:52 +010083#include <haproxy/action.h>
Willy Tarreaub2551052020-06-09 09:07:15 +020084#include <haproxy/activity.h>
85#include <haproxy/api.h>
86#include <haproxy/arg.h>
87#include <haproxy/auth.h>
Willy Tarreau8d366972020-05-27 16:10:29 +020088#include <haproxy/base64.h>
Willy Tarreaub2551052020-06-09 09:07:15 +020089#include <haproxy/capture-t.h>
Amaury Denoyelle5a6926d2021-03-30 17:34:24 +020090#include <haproxy/cfgdiag.h>
Willy Tarreau6be78492020-06-05 00:00:29 +020091#include <haproxy/cfgparse.h>
Willy Tarreauc13ed532020-06-02 10:22:45 +020092#include <haproxy/chunk.h>
Willy Tarreau83487a82020-06-04 20:19:54 +020093#include <haproxy/cli.h>
Willy Tarreau7ea393d2020-06-04 18:02:10 +020094#include <haproxy/connection.h>
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +020095#ifdef USE_CPU_AFFINITY
Amaury Denoyelle982fb532021-04-21 18:39:58 +020096#include <haproxy/cpuset.h>
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +020097#endif
Willy Tarreaueb92deb2020-06-04 10:53:16 +020098#include <haproxy/dns.h>
Willy Tarreau2741c8c2020-06-02 11:28:02 +020099#include <haproxy/dynbuf.h>
Willy Tarreau8d366972020-05-27 16:10:29 +0200100#include <haproxy/errors.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200101#include <haproxy/fd.h>
Willy Tarreauc7babd82020-06-04 21:29:29 +0200102#include <haproxy/filters.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200103#include <haproxy/global.h>
Willy Tarreau86416052020-06-04 09:20:54 +0200104#include <haproxy/hlua.h>
Willy Tarreauc761f842020-06-04 11:40:28 +0200105#include <haproxy/http_rules.h>
Willy Tarreau853b2972020-05-27 18:01:47 +0200106#include <haproxy/list.h>
Willy Tarreau213e9902020-06-04 14:58:24 +0200107#include <haproxy/listener.h>
Willy Tarreauaeed4a82020-06-04 22:01:04 +0200108#include <haproxy/log.h>
Willy Tarreaub5abe5b2020-06-04 14:07:37 +0200109#include <haproxy/mworker.h>
Willy Tarreau7a00efb2020-06-02 17:02:59 +0200110#include <haproxy/namespace.h>
Willy Tarreau6131d6a2020-06-02 16:48:09 +0200111#include <haproxy/net_helper.h>
Willy Tarreau6019fab2020-05-27 16:26:00 +0200112#include <haproxy/openssl-compat.h>
Willy Tarreau225a90a2020-06-04 15:06:28 +0200113#include <haproxy/pattern.h>
Willy Tarreau3c2a7c22020-06-04 18:38:21 +0200114#include <haproxy/peers.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200115#include <haproxy/pool.h>
116#include <haproxy/protocol.h>
Willy Tarreaubf3b06b2020-08-26 10:23:40 +0200117#include <haproxy/proto_tcp.h>
Willy Tarreaua264d962020-06-04 22:29:18 +0200118#include <haproxy/proxy.h>
Willy Tarreau7cd8b6e2020-06-02 17:32:26 +0200119#include <haproxy/regex.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200120#include <haproxy/sample.h>
Willy Tarreau1e56f922020-06-04 23:20:13 +0200121#include <haproxy/server.h>
Willy Tarreau48d25b32020-06-04 18:58:52 +0200122#include <haproxy/session.h>
Willy Tarreau3727a8a2020-06-04 17:37:26 +0200123#include <haproxy/signal.h>
Willy Tarreau063d47d2020-08-28 16:29:53 +0200124#include <haproxy/sock.h>
Willy Tarreau25140cc2020-08-28 15:40:33 +0200125#include <haproxy/sock_inet.h>
Willy Tarreau209108d2020-06-04 20:30:20 +0200126#include <haproxy/ssl_sock.h>
Amaury Denoyelleee63d4b2020-10-05 11:49:42 +0200127#include <haproxy/stats-t.h>
Willy Tarreaudfd3de82020-06-04 23:46:14 +0200128#include <haproxy/stream.h>
Willy Tarreaucea0e1b2020-06-04 17:25:40 +0200129#include <haproxy/task.h>
Willy Tarreau3f567e42020-05-28 15:29:19 +0200130#include <haproxy/thread.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200131#include <haproxy/time.h>
132#include <haproxy/tools.h>
133#include <haproxy/uri_auth-t.h>
Willy Tarreaua1718922020-06-04 16:25:31 +0200134#include <haproxy/vars.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200135#include <haproxy/version.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +0200136
Willy Tarreaubaaee002006-06-26 02:48:02 +0200137
Willy Tarreau7b5654f2019-03-29 21:30:17 +0100138/* array of init calls for older platforms */
139DECLARE_INIT_STAGES;
140
Willy Tarreauf4596402021-04-10 16:53:05 +0200141/* create a read_mostly section to hold variables which are accessed a lot
142 * but which almost never change. The purpose is to isolate them in their
143 * own cache lines where they don't risk to be perturbated by write accesses
144 * to neighbor variables. We need to create an empty aligned variable for
145 * this. The fact that the variable is of size zero means that it will be
146 * eliminated at link time if no other variable uses it, but alignment will
147 * be respected.
148 */
149empty_t __read_mostly_align HA_SECTION("read_mostly") ALIGNED(64);
150
Willy Tarreauf0d3b732021-05-06 16:30:32 +0200151#ifdef BUILD_FEATURES
152const char *build_features = BUILD_FEATURES;
153#else
154const char *build_features = "";
155#endif
156
Willy Tarreau477ecd82010-01-03 21:12:30 +0100157/* list of config files */
158static struct list cfg_cfgfiles = LIST_HEAD_INIT(cfg_cfgfiles);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200159int pid; /* current process id */
160
Willy Tarreauf8ea00e2020-03-12 17:24:53 +0100161volatile unsigned long sleeping_thread_mask = 0; /* Threads that are about to sleep in poll() */
Willy Tarreau4b3f27b2020-03-12 17:28:01 +0100162volatile unsigned long stopping_thread_mask = 0; /* Threads acknowledged stopping */
Willy Tarreauf8ea00e2020-03-12 17:24:53 +0100163
Willy Tarreaubaaee002006-06-26 02:48:02 +0200164/* global options */
165struct global global = {
Cyril Bonté203ec5a2017-03-23 22:44:13 +0100166 .hard_stop_after = TICK_ETERNITY,
Amaury Denoyelle0f50cb92021-03-26 18:50:33 +0100167 .numa_cpu_mapping = 1,
Willy Tarreau149ab772019-01-26 14:27:06 +0100168 .nbthread = 0,
William Lallemand5f232402012-04-05 18:02:55 +0200169 .req_count = 0,
William Lallemand0f99e342011-10-12 17:50:54 +0200170 .logsrvs = LIST_HEAD_INIT(global.logsrvs),
William Lallemand9d5f5482012-11-07 16:12:57 +0100171 .maxzlibmem = 0,
William Lallemandd85f9172012-11-09 17:05:39 +0100172 .comp_rate_lim = 0,
Emeric Brun850efd52014-01-29 12:24:34 +0100173 .ssl_server_verify = SSL_SERVER_VERIFY_REQUIRED,
Emeric Bruned760922010-10-22 17:59:25 +0200174 .unix_bind = {
175 .ux = {
176 .uid = -1,
177 .gid = -1,
178 .mode = 0,
179 }
180 },
Willy Tarreau27a674e2009-08-17 07:23:33 +0200181 .tune = {
Willy Tarreau7ac908b2019-02-27 12:02:18 +0100182 .options = GTUNE_LISTENER_MQ,
Willy Tarreauc77d3642018-12-12 06:19:42 +0100183 .bufsize = (BUFSIZE + 2*sizeof(void *) - 1) & -(2*sizeof(void *)),
Christopher Faulet546c4692020-01-22 14:31:21 +0100184 .maxrewrite = MAXREWRITE,
Willy Tarreaua24adf02014-11-27 01:11:56 +0100185 .reserved_bufs = RESERVED_BUFS,
Willy Tarreauf3045d22015-04-29 16:24:50 +0200186 .pattern_cache = DEFAULT_PAT_LRU_SIZE,
Olivier Houchard88698d92019-04-16 19:07:22 +0200187 .pool_low_ratio = 20,
188 .pool_high_ratio = 25,
Christopher Faulet41ba36f2019-07-19 09:36:45 +0200189 .max_http_hdr = MAX_HTTP_HDR,
Emeric Brunfc32aca2012-09-03 12:10:29 +0200190#ifdef USE_OPENSSL
Emeric Brun46635772012-11-14 11:32:56 +0100191 .sslcachesize = SSLCACHESIZE,
Emeric Brunfc32aca2012-09-03 12:10:29 +0200192#endif
William Lallemandf3747832012-11-09 12:33:10 +0100193 .comp_maxlevel = 1,
Willy Tarreau7e312732014-02-12 16:35:14 +0100194#ifdef DEFAULT_IDLE_TIMER
195 .idle_timer = DEFAULT_IDLE_TIMER,
196#else
197 .idle_timer = 1000, /* 1 second */
198#endif
Willy Tarreau27a674e2009-08-17 07:23:33 +0200199 },
Emeric Brun76d88952012-10-05 15:47:31 +0200200#ifdef USE_OPENSSL
201#ifdef DEFAULT_MAXSSLCONN
Willy Tarreau403edff2012-09-06 11:58:37 +0200202 .maxsslconn = DEFAULT_MAXSSLCONN,
203#endif
Emeric Brun76d88952012-10-05 15:47:31 +0200204#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +0200205 /* others NULL OK */
206};
207
208/*********************************************************************/
209
210int stopping; /* non zero means stopping in progress */
Cyril Bonté203ec5a2017-03-23 22:44:13 +0100211int killed; /* non zero means a hard-stop is triggered */
Willy Tarreauaf7ad002010-08-31 15:39:26 +0200212int jobs = 0; /* number of active jobs (conns, listeners, active tasks, ...) */
William Lallemanda7199262018-11-16 16:57:20 +0100213int unstoppable_jobs = 0; /* number of active jobs that can't be stopped during a soft stop */
Willy Tarreau199ad242018-11-05 16:31:22 +0100214int active_peers = 0; /* number of active peers (connection attempts and connected) */
Willy Tarreau2d372c22018-11-05 17:12:27 +0100215int connected_peers = 0; /* number of connected peers (verified ones) */
Willy Tarreaubaaee002006-06-26 02:48:02 +0200216
Ilya Shipitsin46a030c2020-07-05 16:36:08 +0500217/* Here we store information about the pids of the processes we may pause
Willy Tarreaubaaee002006-06-26 02:48:02 +0200218 * or kill. We will send them a signal every 10 ms until we can bind to all
219 * our ports. With 200 retries, that's about 2 seconds.
220 */
221#define MAX_START_RETRIES 200
Willy Tarreaubaaee002006-06-26 02:48:02 +0200222static int *oldpids = NULL;
223static int oldpids_sig; /* use USR1 or TERM */
224
Olivier Houchardf73629d2017-04-05 22:33:04 +0200225/* Path to the unix socket we use to retrieve listener sockets from the old process */
226static const char *old_unixsocket;
227
William Lallemand85b0bd92017-06-01 17:38:53 +0200228static char *cur_unixsocket = NULL;
229
William Lallemandcb11fd22017-06-01 17:38:52 +0200230int atexit_flag = 0;
231
Willy Tarreaubb545b42010-08-25 12:58:59 +0200232int nb_oldpids = 0;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200233const int zero = 0;
234const int one = 1;
Alexandre Cassen87ea5482007-10-11 20:48:58 +0200235const struct linger nolinger = { .l_onoff = 1, .l_linger = 0 };
Willy Tarreaubaaee002006-06-26 02:48:02 +0200236
Willy Tarreau1d21e0a2010-03-12 21:58:54 +0100237char hostname[MAX_HOSTNAME_LEN];
Dragan Dosen4f014152020-06-18 16:56:47 +0200238char *localpeer = NULL;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200239
William Lallemand00417412020-06-05 14:08:41 +0200240static char **old_argv = NULL; /* previous argv but cleaned up */
William Lallemand73b85e72017-06-01 17:38:51 +0200241
William Lallemandbc193052018-09-11 10:06:26 +0200242struct list proc_list = LIST_HEAD_INIT(proc_list);
243
244int master = 0; /* 1 if in master, 0 if in child */
Willy Tarreaubf696402019-03-01 10:09:28 +0100245unsigned int rlim_fd_cur_at_boot = 0;
246unsigned int rlim_fd_max_at_boot = 0;
William Lallemandbc193052018-09-11 10:06:26 +0200247
Willy Tarreau6c3a6812020-03-06 18:57:15 +0100248/* per-boot randomness */
249unsigned char boot_seed[20]; /* per-boot random seed (160 bits initially) */
250
William Lallemandb3f2be32018-09-11 10:06:18 +0200251static void *run_thread_poll_loop(void *data);
252
Willy Tarreauff055502014-04-28 22:27:06 +0200253/* bitfield of a few warnings to emit just once (WARN_*) */
254unsigned int warned = 0;
255
Amaury Denoyelle484454d2021-05-05 16:18:45 +0200256/* set if experimental features have been used for the current process */
257static unsigned int tainted = 0;
258
Amaury Denoyelled2e53cd2021-05-06 16:21:39 +0200259unsigned int experimental_directives_allowed = 0;
260
261int check_kw_experimental(struct cfg_keyword *kw, const char *file, int linenum,
262 char **errmsg)
263{
264 if (kw->flags & KWF_EXPERIMENTAL) {
265 if (!experimental_directives_allowed) {
Amaury Denoyelle86c1d0f2021-05-07 15:07:21 +0200266 memprintf(errmsg, "parsing [%s:%d] : '%s' directive is experimental, must be allowed via a global 'expose-experimental-directives'",
Amaury Denoyelled2e53cd2021-05-06 16:21:39 +0200267 file, linenum, kw->kw);
268 return 1;
269 }
270 mark_tainted(TAINTED_CONFIG_EXP_KW_DECLARED);
271 }
272
273 return 0;
274}
275
William Lallemande7361152018-10-26 14:47:36 +0200276/* master CLI configuration (-S flag) */
277struct list mworker_cli_conf = LIST_HEAD_INIT(mworker_cli_conf);
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100278
279/* These are strings to be reported in the output of "haproxy -vv". They may
280 * either be constants (in which case must_free must be zero) or dynamically
281 * allocated strings to pass to free() on exit, and in this case must_free
282 * must be non-zero.
283 */
284struct list build_opts_list = LIST_HEAD_INIT(build_opts_list);
285struct build_opts_str {
286 struct list list;
287 const char *str;
288 int must_free;
289};
290
Willy Tarreaubaaee002006-06-26 02:48:02 +0200291/*********************************************************************/
292/* general purpose functions ***************************************/
293/*********************************************************************/
294
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100295/* used to register some build option strings at boot. Set must_free to
296 * non-zero if the string must be freed upon exit.
297 */
298void hap_register_build_opts(const char *str, int must_free)
299{
300 struct build_opts_str *b;
301
302 b = calloc(1, sizeof(*b));
303 if (!b) {
304 fprintf(stderr, "out of memory\n");
305 exit(1);
306 }
307 b->str = str;
308 b->must_free = must_free;
Willy Tarreau2b718102021-04-21 07:32:39 +0200309 LIST_APPEND(&build_opts_list, &b->list);
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100310}
311
Willy Tarreaua43dfda2021-05-06 07:43:35 +0200312#define VERSION_MAX_ELTS 7
313
314/* This function splits an haproxy version string into an array of integers.
315 * The syntax of the supported version string is the following:
316 *
317 * <a>[.<b>[.<c>[.<d>]]][-{dev,pre,rc}<f>][-*][-<g>]
318 *
319 * This validates for example:
320 * 1.2.1-pre2, 1.2.1, 1.2.10.1, 1.3.16-rc1, 1.4-dev3, 1.5-dev18, 1.5-dev18-43
321 * 2.4-dev18-f6818d-20
322 *
323 * The result is set in a array of <VERSION_MAX_ELTS> elements. Each letter has
324 * one fixed place in the array. The tags take a numeric value called <e> which
325 * defaults to 3. "dev" is 1, "rc" and "pre" are 2. Numbers not encountered are
326 * considered as zero (henxe 1.5 and 1.5.0 are the same).
327 *
328 * The resulting values are:
329 * 1.2.1-pre2 1, 2, 1, 0, 2, 2, 0
330 * 1.2.1 1, 2, 1, 0, 3, 0, 0
331 * 1.2.10.1 1, 2, 10, 1, 3, 0, 0
332 * 1.3.16-rc1 1, 3, 16, 0, 2, 1, 0
333 * 1.4-dev3 1, 4, 0, 0, 1, 3, 0
334 * 1.5-dev18 1, 5, 0, 0, 1, 18, 0
335 * 1.5-dev18-43 1, 5, 0, 0, 1, 18, 43
336 * 2.4-dev18-f6818d-20 2, 4, 0, 0, 1, 18, 20
337 *
338 * The function returns non-zero if the conversion succeeded, or zero if it
339 * failed.
340 */
341int split_version(const char *version, unsigned int *value)
342{
343 const char *p, *s;
344 char *error;
345 int nelts;
346
347 /* Initialize array with zeroes */
348 for (nelts = 0; nelts < VERSION_MAX_ELTS; nelts++)
349 value[nelts] = 0;
350 value[4] = 3;
351
352 p = version;
353
354 /* If the version number is empty, return false */
355 if (*p == '\0')
356 return 0;
357
358 /* Convert first number <a> */
359 value[0] = strtol(p, &error, 10);
360 p = error + 1;
361 if (*error == '\0')
362 return 1;
363 if (*error == '-')
364 goto split_version_tag;
365 if (*error != '.')
366 return 0;
367
368 /* Convert first number <b> */
369 value[1] = strtol(p, &error, 10);
370 p = error + 1;
371 if (*error == '\0')
372 return 1;
373 if (*error == '-')
374 goto split_version_tag;
375 if (*error != '.')
376 return 0;
377
378 /* Convert first number <c> */
379 value[2] = strtol(p, &error, 10);
380 p = error + 1;
381 if (*error == '\0')
382 return 1;
383 if (*error == '-')
384 goto split_version_tag;
385 if (*error != '.')
386 return 0;
387
388 /* Convert first number <d> */
389 value[3] = strtol(p, &error, 10);
390 p = error + 1;
391 if (*error == '\0')
392 return 1;
393 if (*error != '-')
394 return 0;
395
396 split_version_tag:
397 /* Check for commit number */
398 if (*p >= '0' && *p <= '9')
399 goto split_version_commit;
400
401 /* Read tag */
402 if (strncmp(p, "dev", 3) == 0) { value[4] = 1; p += 3; }
403 else if (strncmp(p, "rc", 2) == 0) { value[4] = 2; p += 2; }
404 else if (strncmp(p, "pre", 3) == 0) { value[4] = 2; p += 3; }
405 else
406 goto split_version_commit;
407
408 /* Convert tag number */
409 value[5] = strtol(p, &error, 10);
410 p = error + 1;
411 if (*error == '\0')
412 return 1;
413 if (*error != '-')
414 return 0;
415
416 split_version_commit:
417 /* Search the last "-" */
418 s = strrchr(p, '-');
419 if (s) {
420 s++;
421 if (*s == '\0')
422 return 0;
423 value[6] = strtol(s, &error, 10);
424 if (*error != '\0')
425 value[6] = 0;
426 return 1;
427 }
428
429 /* convert the version */
430 value[6] = strtol(p, &error, 10);
431 if (*error != '\0')
432 value[6] = 0;
433
434 return 1;
435}
436
437/* This function compares the current haproxy version with an arbitrary version
438 * string. It returns:
439 * -1 : the version in argument is older than the current haproxy version
440 * 0 : the version in argument is the same as the current haproxy version
441 * 1 : the version in argument is newer than the current haproxy version
442 *
443 * Or some errors:
444 * -2 : the current haproxy version is not parsable
445 * -3 : the version in argument is not parsable
446 */
447int compare_current_version(const char *version)
448{
449 unsigned int loc[VERSION_MAX_ELTS];
450 unsigned int mod[VERSION_MAX_ELTS];
451 int i;
452
453 /* split versions */
454 if (!split_version(haproxy_version, loc))
455 return -2;
456 if (!split_version(version, mod))
457 return -3;
458
459 /* compare versions */
460 for (i = 0; i < VERSION_MAX_ELTS; i++) {
461 if (mod[i] < loc[i])
462 return -1;
463 else if (mod[i] > loc[i])
464 return 1;
465 }
466 return 0;
467}
468
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100469static void display_version()
Willy Tarreaubaaee002006-06-26 02:48:02 +0200470{
Tim Duesterhusdfad6a42020-04-18 16:02:47 +0200471 struct utsname utsname;
472
Willy Tarreaua5357cd2021-05-09 06:14:25 +0200473 printf("HAProxy version %s %s - https://haproxy.org/\n"
Willy Tarreau08dd2022019-11-21 18:07:30 +0100474 PRODUCT_STATUS "\n", haproxy_version, haproxy_date);
Willy Tarreau47479eb2019-11-21 18:48:20 +0100475
476 if (strlen(PRODUCT_URL_BUGS) > 0) {
477 char base_version[20];
478 int dots = 0;
479 char *del;
480
481 /* only retrieve the base version without distro-specific extensions */
482 for (del = haproxy_version; *del; del++) {
483 if (*del == '.')
484 dots++;
485 else if (*del < '0' || *del > '9')
486 break;
487 }
488
489 strlcpy2(base_version, haproxy_version, del - haproxy_version + 1);
490 if (dots < 2)
491 printf("Known bugs: https://github.com/haproxy/haproxy/issues?q=is:issue+is:open\n");
492 else
493 printf("Known bugs: " PRODUCT_URL_BUGS "\n", base_version);
494 }
Tim Duesterhusdfad6a42020-04-18 16:02:47 +0200495
496 if (uname(&utsname) == 0) {
497 printf("Running on: %s %s %s %s\n", utsname.sysname, utsname.release, utsname.version, utsname.machine);
498 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200499}
500
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100501static void display_build_opts()
Willy Tarreau7b066db2007-12-02 11:28:59 +0100502{
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100503 struct build_opts_str *item;
504
Willy Tarreau7b066db2007-12-02 11:28:59 +0100505 printf("Build options :"
506#ifdef BUILD_TARGET
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100507 "\n TARGET = " BUILD_TARGET
Willy Tarreau7b066db2007-12-02 11:28:59 +0100508#endif
509#ifdef BUILD_CPU
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100510 "\n CPU = " BUILD_CPU
Willy Tarreau7b066db2007-12-02 11:28:59 +0100511#endif
512#ifdef BUILD_CC
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100513 "\n CC = " BUILD_CC
514#endif
515#ifdef BUILD_CFLAGS
516 "\n CFLAGS = " BUILD_CFLAGS
Willy Tarreau7b066db2007-12-02 11:28:59 +0100517#endif
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100518#ifdef BUILD_OPTIONS
519 "\n OPTIONS = " BUILD_OPTIONS
Willy Tarreau7b066db2007-12-02 11:28:59 +0100520#endif
Tim Duesterhusc8d19702020-11-21 18:07:59 +0100521#ifdef BUILD_DEBUG
522 "\n DEBUG = " BUILD_DEBUG
523#endif
Willy Tarreau7728ed32019-03-27 13:20:08 +0100524#ifdef BUILD_FEATURES
525 "\n\nFeature list : " BUILD_FEATURES
526#endif
Willy Tarreau27a674e2009-08-17 07:23:33 +0200527 "\n\nDefault settings :"
Willy Tarreauca783d42019-03-13 10:03:07 +0100528 "\n bufsize = %d, maxrewrite = %d, maxpollevents = %d"
Willy Tarreau27a674e2009-08-17 07:23:33 +0200529 "\n\n",
Willy Tarreauca783d42019-03-13 10:03:07 +0100530 BUFSIZE, MAXREWRITE, MAX_POLL_EVENTS);
Willy Tarreaube5b6852009-10-03 18:57:08 +0200531
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100532 list_for_each_entry(item, &build_opts_list, list) {
533 puts(item->str);
534 }
535
Krzysztof Piotr Oledzki96105042010-01-29 17:50:44 +0100536 putchar('\n');
537
Willy Tarreaube5b6852009-10-03 18:57:08 +0200538 list_pollers(stdout);
539 putchar('\n');
Christopher Faulet98d9fe22018-04-10 14:37:32 +0200540 list_mux_proto(stdout);
541 putchar('\n');
Willy Tarreau679bba12019-03-19 08:08:10 +0100542 list_services(stdout);
543 putchar('\n');
Christopher Fauletb3f4e142016-03-07 12:46:38 +0100544 list_filters(stdout);
545 putchar('\n');
Willy Tarreau7b066db2007-12-02 11:28:59 +0100546}
547
Willy Tarreaubaaee002006-06-26 02:48:02 +0200548/*
549 * This function prints the command line usage and exits
550 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100551static void usage(char *name)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200552{
553 display_version();
554 fprintf(stderr,
Maxime de Roucy379d9c72016-05-13 23:52:56 +0200555 "Usage : %s [-f <cfgfile|cfgdir>]* [ -vdV"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200556 "D ] [ -n <maxconn> ] [ -N <maxpconn> ]\n"
Willy Tarreaua088d312015-10-08 11:58:48 +0200557 " [ -p <pidfile> ] [ -m <max megs> ] [ -C <dir> ] [-- <cfgfile>*]\n"
Willy Tarreau7b066db2007-12-02 11:28:59 +0100558 " -v displays version ; -vv shows known build options.\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200559 " -d enters debug mode ; -db only disables background mode.\n"
Willy Tarreau6e064432012-05-08 15:40:42 +0200560 " -dM[<byte>] poisons memory with <byte> (defaults to 0x50)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200561 " -V enters verbose mode (disables quiet mode)\n"
Willy Tarreau576132e2011-09-10 19:26:56 +0200562 " -D goes daemon ; -C changes to <dir> before loading files.\n"
William Lallemand095ba4c2017-06-01 17:38:50 +0200563 " -W master-worker mode.\n"
Tim Duesterhusd6942c82017-11-20 15:58:35 +0100564#if defined(USE_SYSTEMD)
565 " -Ws master-worker mode with systemd notify support.\n"
566#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +0200567 " -q quiet mode : don't display messages\n"
Willy Tarreau5d01a632009-06-22 16:02:30 +0200568 " -c check mode : only check config files and exit\n"
Maximilian Maderfc0cceb2021-06-06 00:50:22 +0200569 " -cc check condition : evaluate a condition and exit\n"
Willy Tarreauca783d42019-03-13 10:03:07 +0100570 " -n sets the maximum total # of connections (uses ulimit -n)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200571 " -m limits the usable amount of memory (in MB)\n"
572 " -N sets the default, per-proxy maximum # of connections (%d)\n"
Emeric Brun2b920a12010-09-23 18:30:22 +0200573 " -L set local peer name (default to hostname)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200574 " -p writes pids of all children to this file\n"
Willy Tarreaue5733232019-05-22 19:24:06 +0200575#if defined(USE_EPOLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200576 " -de disables epoll() usage even when available\n"
577#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200578#if defined(USE_KQUEUE)
Willy Tarreau1e63130a2007-04-09 12:03:06 +0200579 " -dk disables kqueue() usage even when available\n"
580#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200581#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +0000582 " -dv disables event ports usage even when available\n"
583#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200584#if defined(USE_POLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200585 " -dp disables poll() usage even when available\n"
586#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200587#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +0100588 " -dS disables splice usage (broken on old kernels)\n"
589#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +0200590#if defined(USE_GETADDRINFO)
591 " -dG disables getaddrinfo() usage\n"
592#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +0000593#if defined(SO_REUSEPORT)
594 " -dR disables SO_REUSEPORT usage\n"
595#endif
Willy Tarreau3eed10e2016-11-07 21:03:16 +0100596 " -dr ignores server address resolution failures\n"
Emeric Brun850efd52014-01-29 12:24:34 +0100597 " -dV disables SSL verify on servers side\n"
Willy Tarreau3eb10b82020-04-15 16:42:39 +0200598 " -dW fails if any warning is emitted\n"
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +0200599 " -dD diagnostic mode : warn about suspicious configuration statements\n"
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +0200600 " -sf/-st [pid ]* finishes/terminates old pids.\n"
Olivier Houchardf73629d2017-04-05 22:33:04 +0200601 " -x <unix_socket> get listening sockets from a unix socket\n"
William Lallemand63329e32019-06-13 17:03:37 +0200602 " -S <bind>[,<bind options>...] new master CLI\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200603 "\n",
Willy Tarreauca783d42019-03-13 10:03:07 +0100604 name, cfg_maxpconn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200605 exit(1);
606}
607
608
609
610/*********************************************************************/
611/* more specific functions ***************************************/
612/*********************************************************************/
613
William Lallemand73b85e72017-06-01 17:38:51 +0200614/* sends the signal <sig> to all pids found in <oldpids>. Returns the number of
615 * pids the signal was correctly delivered to.
616 */
William Lallemande25473c2019-04-01 11:29:56 +0200617int tell_old_pids(int sig)
William Lallemand73b85e72017-06-01 17:38:51 +0200618{
619 int p;
620 int ret = 0;
621 for (p = 0; p < nb_oldpids; p++)
622 if (kill(oldpids[p], sig) == 0)
623 ret++;
624 return ret;
625}
626
William Lallemand75ea0a02017-11-15 19:02:58 +0100627/*
William Lallemand73b85e72017-06-01 17:38:51 +0200628 * remove a pid forom the olpid array and decrease nb_oldpids
629 * return 1 pid was found otherwise return 0
630 */
631
632int delete_oldpid(int pid)
633{
634 int i;
635
636 for (i = 0; i < nb_oldpids; i++) {
637 if (oldpids[i] == pid) {
638 oldpids[i] = oldpids[nb_oldpids - 1];
639 oldpids[nb_oldpids - 1] = 0;
640 nb_oldpids--;
641 return 1;
642 }
643 }
644 return 0;
645}
646
William Lallemand85b0bd92017-06-01 17:38:53 +0200647
648static void get_cur_unixsocket()
649{
650 /* if -x was used, try to update the stat socket if not available anymore */
Willy Tarreau4975d142021-03-13 11:00:33 +0100651 if (global.cli_fe) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200652 struct bind_conf *bind_conf;
653
654 /* pass through all stats socket */
Willy Tarreau4975d142021-03-13 11:00:33 +0100655 list_for_each_entry(bind_conf, &global.cli_fe->conf.bind, by_fe) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200656 struct listener *l;
657
658 list_for_each_entry(l, &bind_conf->listeners, by_bind) {
659
Willy Tarreau37159062020-08-27 07:48:42 +0200660 if (l->rx.addr.ss_family == AF_UNIX &&
William Lallemand85b0bd92017-06-01 17:38:53 +0200661 (bind_conf->level & ACCESS_FD_LISTENERS)) {
662 const struct sockaddr_un *un;
663
Willy Tarreau37159062020-08-27 07:48:42 +0200664 un = (struct sockaddr_un *)&l->rx.addr;
William Lallemand85b0bd92017-06-01 17:38:53 +0200665 /* priority to old_unixsocket */
666 if (!cur_unixsocket) {
667 cur_unixsocket = strdup(un->sun_path);
668 } else {
Tim Duesterhuse5ff1412021-01-02 22:31:53 +0100669 if (old_unixsocket && strcmp(un->sun_path, old_unixsocket) == 0) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200670 free(cur_unixsocket);
671 cur_unixsocket = strdup(old_unixsocket);
672 return;
673 }
674 }
675 }
676 }
677 }
678 }
679 if (!cur_unixsocket && old_unixsocket)
680 cur_unixsocket = strdup(old_unixsocket);
681}
682
William Lallemand73b85e72017-06-01 17:38:51 +0200683/*
684 * When called, this function reexec haproxy with -sf followed by current
Joseph Herlant03420902018-11-15 10:41:50 -0800685 * children PIDs and possibly old children PIDs if they didn't leave yet.
William Lallemand73b85e72017-06-01 17:38:51 +0200686 */
William Lallemanda57b7e32018-12-14 21:11:31 +0100687void mworker_reload()
William Lallemand73b85e72017-06-01 17:38:51 +0200688{
William Lallemand00417412020-06-05 14:08:41 +0200689 char **next_argv = NULL;
690 int old_argc = 0; /* previous number of argument */
William Lallemand73b85e72017-06-01 17:38:51 +0200691 int next_argc = 0;
William Lallemand00417412020-06-05 14:08:41 +0200692 int i = 0;
William Lallemand73b85e72017-06-01 17:38:51 +0200693 char *msg = NULL;
Willy Tarreau8dca1952019-03-01 10:21:55 +0100694 struct rlimit limit;
William Lallemand7c756a82018-11-26 11:53:40 +0100695 struct per_thread_deinit_fct *ptdf;
William Lallemand73b85e72017-06-01 17:38:51 +0200696
697 mworker_block_signals();
Tim Duesterhusd6942c82017-11-20 15:58:35 +0100698#if defined(USE_SYSTEMD)
699 if (global.tune.options & GTUNE_USE_SYSTEMD)
700 sd_notify(0, "RELOADING=1");
701#endif
William Lallemand73b85e72017-06-01 17:38:51 +0200702 setenv("HAPROXY_MWORKER_REEXEC", "1", 1);
703
William Lallemandbc193052018-09-11 10:06:26 +0200704 mworker_proc_list_to_env(); /* put the children description in the env */
705
William Lallemand7c756a82018-11-26 11:53:40 +0100706 /* during the reload we must ensure that every FDs that can't be
707 * reuse (ie those that are not referenced in the proc_list)
708 * are closed or they will leak. */
709
710 /* close the listeners FD */
711 mworker_cli_proxy_stop();
William Lallemand16866672019-06-24 17:40:48 +0200712
713 if (getenv("HAPROXY_MWORKER_WAIT_ONLY") == NULL) {
714 /* close the poller FD and the thread waker pipe FD */
715 list_for_each_entry(ptdf, &per_thread_deinit_list, list)
716 ptdf->fct();
717 if (fdtab)
718 deinit_pollers();
719 }
Ilya Shipitsin98a9e1b2021-02-19 23:42:53 +0500720#ifdef HAVE_SSL_RAND_KEEP_RANDOM_DEVICES_OPEN
William Lallemand5fdb5b32019-10-15 14:04:08 +0200721 /* close random device FDs */
722 RAND_keep_random_devices_open(0);
Rob Allen56996da2019-05-03 09:11:32 +0100723#endif
William Lallemand7c756a82018-11-26 11:53:40 +0100724
Willy Tarreau8dca1952019-03-01 10:21:55 +0100725 /* restore the initial FD limits */
726 limit.rlim_cur = rlim_fd_cur_at_boot;
727 limit.rlim_max = rlim_fd_max_at_boot;
728 if (setrlimit(RLIMIT_NOFILE, &limit) == -1) {
729 getrlimit(RLIMIT_NOFILE, &limit);
730 ha_warning("Failed to restore initial FD limits (cur=%u max=%u), using cur=%u max=%u\n",
731 rlim_fd_cur_at_boot, rlim_fd_max_at_boot,
732 (unsigned int)limit.rlim_cur, (unsigned int)limit.rlim_max);
733 }
734
William Lallemand73b85e72017-06-01 17:38:51 +0200735 /* compute length */
William Lallemand00417412020-06-05 14:08:41 +0200736 while (old_argv[old_argc])
737 old_argc++;
William Lallemand73b85e72017-06-01 17:38:51 +0200738
William Lallemand85b0bd92017-06-01 17:38:53 +0200739 /* 1 for haproxy -sf, 2 for -x /socket */
William Lallemandaba7f8b2021-04-21 16:55:34 +0200740 next_argv = calloc(old_argc + 1 + 2 + mworker_child_nb() + 1,
Tim Duesterhuse52b6e52020-09-12 20:26:43 +0200741 sizeof(*next_argv));
William Lallemand73b85e72017-06-01 17:38:51 +0200742 if (next_argv == NULL)
743 goto alloc_error;
744
William Lallemand00417412020-06-05 14:08:41 +0200745 /* copy the program name */
746 next_argv[next_argc++] = old_argv[0];
747
748 /* insert the new options just after argv[0] in case we have a -- */
749
William Lallemand73b85e72017-06-01 17:38:51 +0200750 /* add -sf <PID>* to argv */
William Lallemand3f128872019-04-01 11:29:59 +0200751 if (mworker_child_nb() > 0) {
752 struct mworker_proc *child;
753
William Lallemand73b85e72017-06-01 17:38:51 +0200754 next_argv[next_argc++] = "-sf";
William Lallemand3f128872019-04-01 11:29:59 +0200755
756 list_for_each_entry(child, &proc_list, list) {
William Lallemand677e2f22019-11-19 17:04:18 +0100757 if (!(child->options & (PROC_O_TYPE_WORKER|PROC_O_TYPE_PROG)) || child->pid <= -1 )
William Lallemand3f128872019-04-01 11:29:59 +0200758 continue;
William Lallemand00417412020-06-05 14:08:41 +0200759 if ((next_argv[next_argc++] = memprintf(&msg, "%d", child->pid)) == NULL)
William Lallemand73b85e72017-06-01 17:38:51 +0200760 goto alloc_error;
761 msg = NULL;
762 }
763 }
William Lallemand2bf6d622017-06-20 11:20:23 +0200764 /* add the -x option with the stat socket */
William Lallemand85b0bd92017-06-01 17:38:53 +0200765 if (cur_unixsocket) {
William Lallemand2bf6d622017-06-20 11:20:23 +0200766 next_argv[next_argc++] = "-x";
767 next_argv[next_argc++] = (char *)cur_unixsocket;
William Lallemand85b0bd92017-06-01 17:38:53 +0200768 }
769
William Lallemand00417412020-06-05 14:08:41 +0200770 /* copy the previous options */
771 for (i = 1; i < old_argc; i++)
772 next_argv[next_argc++] = old_argv[i];
773
Christopher Faulet767a84b2017-11-24 16:50:31 +0100774 ha_warning("Reexecuting Master process\n");
Willy Tarreaue0d86e22019-08-26 10:37:39 +0200775 signal(SIGPROF, SIG_IGN);
Tim Duesterhus0436ab72017-11-12 17:39:18 +0100776 execvp(next_argv[0], next_argv);
William Lallemand73b85e72017-06-01 17:38:51 +0200777
Christopher Faulet767a84b2017-11-24 16:50:31 +0100778 ha_warning("Failed to reexecute the master process [%d]: %s\n", pid, strerror(errno));
Willy Tarreau61cfdf42021-02-20 10:46:51 +0100779 ha_free(&next_argv);
William Lallemand722d4ca2017-11-15 19:02:55 +0100780 return;
781
William Lallemand73b85e72017-06-01 17:38:51 +0200782alloc_error:
Willy Tarreau61cfdf42021-02-20 10:46:51 +0100783 ha_free(&next_argv);
Joseph Herlant07a08342018-11-15 10:43:05 -0800784 ha_warning("Failed to reexecute the master process [%d]: Cannot allocate memory\n", pid);
William Lallemand73b85e72017-06-01 17:38:51 +0200785 return;
786}
787
William Lallemandb3f2be32018-09-11 10:06:18 +0200788static void mworker_loop()
789{
790
791#if defined(USE_SYSTEMD)
792 if (global.tune.options & GTUNE_USE_SYSTEMD)
793 sd_notifyf(0, "READY=1\nMAINPID=%lu", (unsigned long)getpid());
794#endif
Willy Tarreaud83b6c12019-04-18 11:31:36 +0200795 /* Busy polling makes no sense in the master :-) */
796 global.tune.options &= ~GTUNE_BUSY_POLLING;
William Lallemandb3f2be32018-09-11 10:06:18 +0200797
William Lallemandbc193052018-09-11 10:06:26 +0200798 master = 1;
799
Willy Tarreaud26c9f92019-12-11 14:24:07 +0100800 signal_unregister(SIGTTIN);
801 signal_unregister(SIGTTOU);
William Lallemand0564d412018-11-20 17:36:53 +0100802 signal_unregister(SIGUSR1);
803 signal_unregister(SIGHUP);
804 signal_unregister(SIGQUIT);
805
William Lallemandb3f2be32018-09-11 10:06:18 +0200806 signal_register_fct(SIGTERM, mworker_catch_sigterm, SIGTERM);
807 signal_register_fct(SIGUSR1, mworker_catch_sigterm, SIGUSR1);
Willy Tarreaud26c9f92019-12-11 14:24:07 +0100808 signal_register_fct(SIGTTIN, mworker_broadcast_signal, SIGTTIN);
809 signal_register_fct(SIGTTOU, mworker_broadcast_signal, SIGTTOU);
William Lallemandb3f2be32018-09-11 10:06:18 +0200810 signal_register_fct(SIGINT, mworker_catch_sigterm, SIGINT);
811 signal_register_fct(SIGHUP, mworker_catch_sighup, SIGHUP);
812 signal_register_fct(SIGUSR2, mworker_catch_sighup, SIGUSR2);
813 signal_register_fct(SIGCHLD, mworker_catch_sigchld, SIGCHLD);
814
815 mworker_unblock_signals();
816 mworker_cleanlisteners();
William Lallemand27f3fa52018-12-06 14:05:20 +0100817 mworker_cleantasks();
William Lallemandb3f2be32018-09-11 10:06:18 +0200818
William Lallemandbc193052018-09-11 10:06:26 +0200819 mworker_catch_sigchld(NULL); /* ensure we clean the children in case
820 some SIGCHLD were lost */
821
William Lallemandb3f2be32018-09-11 10:06:18 +0200822 global.nbthread = 1;
William Lallemandb3f2be32018-09-11 10:06:18 +0200823
William Lallemand2672eb92018-12-14 15:52:39 +0100824#ifdef USE_THREAD
825 tid_bit = 1;
826 all_threads_mask = 1;
827#endif
828
William Lallemandb3f2be32018-09-11 10:06:18 +0200829 jobs++; /* this is the "master" job, we want to take care of the
830 signals even if there is no listener so the poll loop don't
831 leave */
832
833 fork_poller();
Willy Tarreaub4f7cc32019-05-03 09:27:30 +0200834 run_thread_poll_loop(0);
William Lallemandb3f2be32018-09-11 10:06:18 +0200835}
William Lallemandcb11fd22017-06-01 17:38:52 +0200836
837/*
838 * Reexec the process in failure mode, instead of exiting
839 */
840void reexec_on_failure()
841{
842 if (!atexit_flag)
843 return;
844
845 setenv("HAPROXY_MWORKER_WAIT_ONLY", "1", 1);
846
Christopher Faulet767a84b2017-11-24 16:50:31 +0100847 ha_warning("Reexecuting Master process in waitpid mode\n");
William Lallemandcb11fd22017-06-01 17:38:52 +0200848 mworker_reload();
William Lallemandcb11fd22017-06-01 17:38:52 +0200849}
William Lallemand73b85e72017-06-01 17:38:51 +0200850
851
852/*
Willy Tarreaud0807c32010-08-27 18:26:11 +0200853 * upon SIGUSR1, let's have a soft stop. Note that soft_stop() broadcasts
854 * a signal zero to all subscribers. This means that it's as easy as
855 * subscribing to signal 0 to get informed about an imminent shutdown.
Willy Tarreaubaaee002006-06-26 02:48:02 +0200856 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100857static void sig_soft_stop(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200858{
859 soft_stop();
Willy Tarreau24f4efa2010-08-27 17:56:48 +0200860 signal_unregister_handler(sh);
Willy Tarreaubafbe012017-11-24 17:34:44 +0100861 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200862}
863
864/*
865 * upon SIGTTOU, we pause everything
866 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100867static void sig_pause(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200868{
Willy Tarreau775e0012020-09-24 16:36:26 +0200869 if (protocol_pause_all() & ERR_FATAL) {
870 const char *msg = "Some proxies refused to pause, performing soft stop now.\n";
Willy Tarreau0a002df2020-10-09 19:26:27 +0200871 ha_warning("%s", msg);
872 send_log(NULL, LOG_WARNING, "%s", msg);
Willy Tarreau775e0012020-09-24 16:36:26 +0200873 soft_stop();
874 }
Willy Tarreaubafbe012017-11-24 17:34:44 +0100875 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200876}
877
878/*
879 * upon SIGTTIN, let's have a soft stop.
880 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100881static void sig_listen(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200882{
Willy Tarreau775e0012020-09-24 16:36:26 +0200883 if (protocol_resume_all() & ERR_FATAL) {
884 const char *msg = "Some proxies refused to resume, probably due to a conflict on a listening port. You may want to try again after the conflicting application is stopped, otherwise a restart might be needed to resume safe operations.\n";
Willy Tarreau0a002df2020-10-09 19:26:27 +0200885 ha_warning("%s", msg);
886 send_log(NULL, LOG_WARNING, "%s", msg);
Willy Tarreau775e0012020-09-24 16:36:26 +0200887 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200888}
889
890/*
891 * this function dumps every server's state when the process receives SIGHUP.
892 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100893static void sig_dump_state(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200894{
Olivier Houchardfbc74e82017-11-24 16:54:05 +0100895 struct proxy *p = proxies_list;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200896
Christopher Faulet767a84b2017-11-24 16:50:31 +0100897 ha_warning("SIGHUP received, dumping servers states.\n");
Willy Tarreaubaaee002006-06-26 02:48:02 +0200898 while (p) {
899 struct server *s = p->srv;
900
901 send_log(p, LOG_NOTICE, "SIGHUP received, dumping servers states for proxy %s.\n", p->id);
902 while (s) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100903 chunk_printf(&trash,
904 "SIGHUP: Server %s/%s is %s. Conn: %d act, %d pend, %lld tot.",
905 p->id, s->id,
Emeric Brun52a91d32017-08-31 14:41:55 +0200906 (s->cur_state != SRV_ST_STOPPED) ? "UP" : "DOWN",
Willy Tarreaua0570452021-06-18 09:30:30 +0200907 s->cur_sess, s->queue.length, s->counters.cum_sess);
Willy Tarreau843b7cb2018-07-13 10:54:26 +0200908 ha_warning("%s\n", trash.area);
909 send_log(p, LOG_NOTICE, "%s\n", trash.area);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200910 s = s->next;
911 }
912
Willy Tarreau5fcc8f12007-09-17 11:27:09 +0200913 /* FIXME: those info are a bit outdated. We should be able to distinguish between FE and BE. */
914 if (!p->srv) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100915 chunk_printf(&trash,
916 "SIGHUP: Proxy %s has no servers. Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
917 p->id,
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200918 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreau5fcc8f12007-09-17 11:27:09 +0200919 } else if (p->srv_act == 0) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100920 chunk_printf(&trash,
921 "SIGHUP: Proxy %s %s ! Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
922 p->id,
923 (p->srv_bck) ? "is running on backup servers" : "has no server available",
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200924 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200925 } else {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100926 chunk_printf(&trash,
927 "SIGHUP: Proxy %s has %d active servers and %d backup servers available."
928 " Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
929 p->id, p->srv_act, p->srv_bck,
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200930 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200931 }
Willy Tarreau843b7cb2018-07-13 10:54:26 +0200932 ha_warning("%s\n", trash.area);
933 send_log(p, LOG_NOTICE, "%s\n", trash.area);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200934
935 p = p->next;
936 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200937}
938
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100939static void dump(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200940{
Willy Tarreauc6ca1a02007-05-13 19:43:47 +0200941 /* dump memory usage then free everything possible */
942 dump_pools();
Willy Tarreaubafbe012017-11-24 17:34:44 +0100943 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200944}
945
William Lallemande1340412017-12-28 16:09:36 +0100946/*
947 * This function dup2 the stdio FDs (0,1,2) with <fd>, then closes <fd>
948 * If <fd> < 0, it opens /dev/null and use it to dup
949 *
950 * In the case of chrooting, you have to open /dev/null before the chroot, and
951 * pass the <fd> to this function
952 */
953static void stdio_quiet(int fd)
954{
955 if (fd < 0)
956 fd = open("/dev/null", O_RDWR, 0);
957
958 if (fd > -1) {
959 fclose(stdin);
960 fclose(stdout);
961 fclose(stderr);
962
963 dup2(fd, 0);
964 dup2(fd, 1);
965 dup2(fd, 2);
966 if (fd > 2)
967 close(fd);
968 return;
969 }
970
971 ha_alert("Cannot open /dev/null\n");
972 exit(EXIT_FAILURE);
973}
974
975
Joseph Herlant03420902018-11-15 10:41:50 -0800976/* This function checks if cfg_cfgfiles contains directories.
977 * If it finds one, it adds all the files (and only files) it contains
978 * in cfg_cfgfiles in place of the directory (and removes the directory).
979 * It adds the files in lexical order.
980 * It adds only files with .cfg extension.
Maxime de Roucy379d9c72016-05-13 23:52:56 +0200981 * It doesn't add files with name starting with '.'
982 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100983static void cfgfiles_expand_directories(void)
Maxime de Roucy379d9c72016-05-13 23:52:56 +0200984{
985 struct wordlist *wl, *wlb;
986 char *err = NULL;
987
988 list_for_each_entry_safe(wl, wlb, &cfg_cfgfiles, list) {
989 struct stat file_stat;
990 struct dirent **dir_entries = NULL;
991 int dir_entries_nb;
992 int dir_entries_it;
993
994 if (stat(wl->s, &file_stat)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +0100995 ha_alert("Cannot open configuration file/directory %s : %s\n",
996 wl->s,
997 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +0200998 exit(1);
999 }
1000
1001 if (!S_ISDIR(file_stat.st_mode))
1002 continue;
1003
1004 /* from this point wl->s is a directory */
1005
1006 dir_entries_nb = scandir(wl->s, &dir_entries, NULL, alphasort);
1007 if (dir_entries_nb < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001008 ha_alert("Cannot open configuration directory %s : %s\n",
1009 wl->s,
1010 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001011 exit(1);
1012 }
1013
1014 /* for each element in the directory wl->s */
1015 for (dir_entries_it = 0; dir_entries_it < dir_entries_nb; dir_entries_it++) {
1016 struct dirent *dir_entry = dir_entries[dir_entries_it];
1017 char *filename = NULL;
1018 char *d_name_cfgext = strstr(dir_entry->d_name, ".cfg");
1019
1020 /* don't add filename that begin with .
Joseph Herlant03420902018-11-15 10:41:50 -08001021 * only add filename with .cfg extension
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001022 */
1023 if (dir_entry->d_name[0] == '.' ||
1024 !(d_name_cfgext && d_name_cfgext[4] == '\0'))
1025 goto next_dir_entry;
1026
1027 if (!memprintf(&filename, "%s/%s", wl->s, dir_entry->d_name)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001028 ha_alert("Cannot load configuration files %s : out of memory.\n",
1029 filename);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001030 exit(1);
1031 }
1032
1033 if (stat(filename, &file_stat)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001034 ha_alert("Cannot open configuration file %s : %s\n",
1035 wl->s,
1036 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001037 exit(1);
1038 }
1039
1040 /* don't add anything else than regular file in cfg_cfgfiles
1041 * this way we avoid loops
1042 */
1043 if (!S_ISREG(file_stat.st_mode))
1044 goto next_dir_entry;
1045
1046 if (!list_append_word(&wl->list, filename, &err)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001047 ha_alert("Cannot load configuration files %s : %s\n",
1048 filename,
1049 err);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001050 exit(1);
1051 }
1052
1053next_dir_entry:
1054 free(filename);
1055 free(dir_entry);
1056 }
1057
1058 free(dir_entries);
1059
1060 /* remove the current directory (wl) from cfg_cfgfiles */
1061 free(wl->s);
Willy Tarreau2b718102021-04-21 07:32:39 +02001062 LIST_DELETE(&wl->list);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001063 free(wl);
1064 }
1065
1066 free(err);
1067}
1068
Willy Tarreaubaaee002006-06-26 02:48:02 +02001069/*
William Lallemand73b85e72017-06-01 17:38:51 +02001070 * copy and cleanup the current argv
William Lallemanddf6c5a82020-06-04 17:40:23 +02001071 * Remove the -sf /-st / -x parameters
William Lallemand73b85e72017-06-01 17:38:51 +02001072 * Return an allocated copy of argv
1073 */
1074
1075static char **copy_argv(int argc, char **argv)
1076{
William Lallemanddf6c5a82020-06-04 17:40:23 +02001077 char **newargv, **retargv;
William Lallemand73b85e72017-06-01 17:38:51 +02001078
Tim Duesterhuse52b6e52020-09-12 20:26:43 +02001079 newargv = calloc(argc + 2, sizeof(*newargv));
William Lallemand73b85e72017-06-01 17:38:51 +02001080 if (newargv == NULL) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001081 ha_warning("Cannot allocate memory\n");
William Lallemand73b85e72017-06-01 17:38:51 +02001082 return NULL;
1083 }
William Lallemanddf6c5a82020-06-04 17:40:23 +02001084 retargv = newargv;
William Lallemand73b85e72017-06-01 17:38:51 +02001085
William Lallemanddf6c5a82020-06-04 17:40:23 +02001086 /* first copy argv[0] */
1087 *newargv++ = *argv++;
1088 argc--;
1089
1090 while (argc > 0) {
1091 if (**argv != '-') {
1092 /* non options are copied but will fail in the argument parser */
1093 *newargv++ = *argv++;
1094 argc--;
1095
1096 } else {
1097 char *flag;
1098
1099 flag = *argv + 1;
1100
1101 if (flag[0] == '-' && flag[1] == 0) {
1102 /* "--\0" copy every arguments till the end of argv */
1103 *newargv++ = *argv++;
1104 argc--;
1105
1106 while (argc > 0) {
1107 *newargv++ = *argv++;
1108 argc--;
1109 }
1110 } else {
1111 switch (*flag) {
1112 case 's':
1113 /* -sf / -st and their parameters are ignored */
1114 if (flag[1] == 'f' || flag[1] == 't') {
1115 argc--;
1116 argv++;
1117 /* The list can't contain a negative value since the only
1118 way to know the end of this list is by looking for the
1119 next option or the end of the options */
1120 while (argc > 0 && argv[0][0] != '-') {
1121 argc--;
1122 argv++;
1123 }
William Lallemand398da622020-09-02 16:12:23 +02001124 } else {
1125 argc--;
1126 argv++;
1127
William Lallemanddf6c5a82020-06-04 17:40:23 +02001128 }
1129 break;
1130
1131 case 'x':
1132 /* this option and its parameter are ignored */
1133 argc--;
1134 argv++;
1135 if (argc > 0) {
1136 argc--;
1137 argv++;
1138 }
1139 break;
1140
1141 case 'C':
1142 case 'n':
1143 case 'm':
1144 case 'N':
1145 case 'L':
1146 case 'f':
1147 case 'p':
1148 case 'S':
1149 /* these options have only 1 parameter which must be copied and can start with a '-' */
1150 *newargv++ = *argv++;
1151 argc--;
1152 if (argc == 0)
1153 goto error;
1154 *newargv++ = *argv++;
1155 argc--;
1156 break;
1157 default:
1158 /* for other options just copy them without parameters, this is also done
1159 * for options like "--foo", but this will fail in the argument parser.
1160 * */
1161 *newargv++ = *argv++;
1162 argc--;
1163 break;
1164 }
William Lallemand73b85e72017-06-01 17:38:51 +02001165 }
1166 }
William Lallemand73b85e72017-06-01 17:38:51 +02001167 }
William Lallemand2bf6d622017-06-20 11:20:23 +02001168
William Lallemanddf6c5a82020-06-04 17:40:23 +02001169 return retargv;
1170
1171error:
1172 free(retargv);
1173 return NULL;
William Lallemand73b85e72017-06-01 17:38:51 +02001174}
1175
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001176
1177/* Performs basic random seed initialization. The main issue with this is that
1178 * srandom_r() only takes 32 bits and purposely provides a reproducible sequence,
1179 * which means that there will only be 4 billion possible random sequences once
1180 * srandom() is called, regardless of the internal state. Not calling it is
1181 * even worse as we'll always produce the same randoms sequences. What we do
1182 * here is to create an initial sequence from various entropy sources, hash it
1183 * using SHA1 and keep the resulting 160 bits available globally.
1184 *
1185 * We initialize the current process with the first 32 bits before starting the
1186 * polling loop, where all this will be changed to have process specific and
1187 * thread specific sequences.
Willy Tarreau52bf8392020-03-08 00:42:37 +01001188 *
1189 * Before starting threads, it's still possible to call random() as srandom()
1190 * is initialized from this, but after threads and/or processes are started,
1191 * only ha_random() is expected to be used to guarantee distinct sequences.
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001192 */
1193static void ha_random_boot(char *const *argv)
1194{
1195 unsigned char message[256];
1196 unsigned char *m = message;
1197 struct timeval tv;
1198 blk_SHA_CTX ctx;
1199 unsigned long l;
1200 int fd;
1201 int i;
1202
1203 /* start with current time as pseudo-random seed */
1204 gettimeofday(&tv, NULL);
1205 write_u32(m, tv.tv_sec); m += 4;
1206 write_u32(m, tv.tv_usec); m += 4;
1207
1208 /* PID and PPID add some OS-based randomness */
1209 write_u16(m, getpid()); m += 2;
1210 write_u16(m, getppid()); m += 2;
1211
1212 /* take up to 160 bits bytes from /dev/urandom if available (non-blocking) */
1213 fd = open("/dev/urandom", O_RDONLY);
1214 if (fd >= 0) {
1215 i = read(fd, m, 20);
1216 if (i > 0)
1217 m += i;
1218 close(fd);
1219 }
1220
1221 /* take up to 160 bits bytes from openssl (non-blocking) */
1222#ifdef USE_OPENSSL
1223 if (RAND_bytes(m, 20) == 1)
1224 m += 20;
1225#endif
1226
1227 /* take 160 bits from existing random in case it was already initialized */
1228 for (i = 0; i < 5; i++) {
1229 write_u32(m, random());
1230 m += 4;
1231 }
1232
1233 /* stack address (benefit form operating system's ASLR) */
1234 l = (unsigned long)&m;
1235 memcpy(m, &l, sizeof(l)); m += sizeof(l);
1236
1237 /* argv address (benefit form operating system's ASLR) */
1238 l = (unsigned long)&argv;
1239 memcpy(m, &l, sizeof(l)); m += sizeof(l);
1240
1241 /* use tv_usec again after all the operations above */
1242 gettimeofday(&tv, NULL);
1243 write_u32(m, tv.tv_usec); m += 4;
1244
1245 /*
1246 * At this point, ~84-92 bytes have been used
1247 */
1248
1249 /* finish with the hostname */
1250 strncpy((char *)m, hostname, message + sizeof(message) - m);
1251 m += strlen(hostname);
1252
1253 /* total message length */
1254 l = m - message;
1255
1256 memset(&ctx, 0, sizeof(ctx));
1257 blk_SHA1_Init(&ctx);
1258 blk_SHA1_Update(&ctx, message, l);
1259 blk_SHA1_Final(boot_seed, &ctx);
1260
1261 srandom(read_u32(boot_seed));
Willy Tarreau52bf8392020-03-08 00:42:37 +01001262 ha_random_seed(boot_seed, sizeof(boot_seed));
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001263}
1264
Willy Tarreau5a023f02019-03-01 14:19:31 +01001265/* considers splicing proxies' maxconn, computes the ideal global.maxpipes
1266 * setting, and returns it. It may return -1 meaning "unlimited" if some
1267 * unlimited proxies have been found and the global.maxconn value is not yet
1268 * set. It may also return a value greater than maxconn if it's not yet set.
1269 * Note that a value of zero means there is no need for pipes. -1 is never
1270 * returned if global.maxconn is valid.
1271 */
1272static int compute_ideal_maxpipes()
1273{
1274 struct proxy *cur;
1275 int nbfe = 0, nbbe = 0;
1276 int unlimited = 0;
1277 int pipes;
1278 int max;
1279
1280 for (cur = proxies_list; cur; cur = cur->next) {
1281 if (cur->options2 & (PR_O2_SPLIC_ANY)) {
1282 if (cur->cap & PR_CAP_FE) {
1283 max = cur->maxconn;
1284 nbfe += max;
1285 if (!max) {
1286 unlimited = 1;
1287 break;
1288 }
1289 }
1290 if (cur->cap & PR_CAP_BE) {
1291 max = cur->fullconn ? cur->fullconn : global.maxconn;
1292 nbbe += max;
1293 if (!max) {
1294 unlimited = 1;
1295 break;
1296 }
1297 }
1298 }
1299 }
1300
1301 pipes = MAX(nbfe, nbbe);
1302 if (global.maxconn) {
1303 if (pipes > global.maxconn || unlimited)
1304 pipes = global.maxconn;
1305 } else if (unlimited) {
1306 pipes = -1;
1307 }
1308
1309 return pipes >= 4 ? pipes / 4 : pipes;
1310}
1311
Willy Tarreauac350932019-03-01 15:43:14 +01001312/* considers global.maxsocks, global.maxpipes, async engines, SSL frontends and
1313 * rlimits and computes an ideal maxconn. It's meant to be called only when
1314 * maxsock contains the sum of listening FDs, before it is updated based on
Willy Tarreaudf23c0c2019-03-13 10:10:49 +01001315 * maxconn and pipes. If there are not enough FDs left, DEFAULT_MAXCONN (by
1316 * default 100) is returned as it is expected that it will even run on tight
1317 * environments, and will maintain compatibility with previous packages that
1318 * used to rely on this value as the default one. The system will emit a
1319 * warning indicating how many FDs are missing anyway if needed.
Willy Tarreauac350932019-03-01 15:43:14 +01001320 */
1321static int compute_ideal_maxconn()
1322{
1323 int ssl_sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
1324 int engine_fds = global.ssl_used_async_engines * ssl_sides;
1325 int pipes = compute_ideal_maxpipes();
Willy Tarreaub1beaa32020-03-06 10:25:31 +01001326 int remain = MAX(rlim_fd_cur_at_boot, rlim_fd_max_at_boot);
Willy Tarreauac350932019-03-01 15:43:14 +01001327 int maxconn;
1328
1329 /* we have to take into account these elements :
1330 * - number of engine_fds, which inflates the number of FD needed per
1331 * connection by this number.
1332 * - number of pipes per connection on average : for the unlimited
1333 * case, this is 0.5 pipe FDs per connection, otherwise it's a
1334 * fixed value of 2*pipes.
1335 * - two FDs per connection
1336 */
1337
1338 /* subtract listeners and checks */
1339 remain -= global.maxsock;
1340
Willy Tarreau3f200852019-03-14 19:13:17 +01001341 /* one epoll_fd/kqueue_fd per thread */
1342 remain -= global.nbthread;
1343
1344 /* one wake-up pipe (2 fd) per thread */
1345 remain -= 2 * global.nbthread;
1346
Willy Tarreauac350932019-03-01 15:43:14 +01001347 /* Fixed pipes values : we only subtract them if they're not larger
1348 * than the remaining FDs because pipes are optional.
1349 */
1350 if (pipes >= 0 && pipes * 2 < remain)
1351 remain -= pipes * 2;
1352
1353 if (pipes < 0) {
1354 /* maxsock = maxconn * 2 + maxconn/4 * 2 + maxconn * engine_fds.
1355 * = maxconn * (2 + 0.5 + engine_fds)
1356 * = maxconn * (4 + 1 + 2*engine_fds) / 2
1357 */
1358 maxconn = 2 * remain / (5 + 2 * engine_fds);
1359 } else {
1360 /* maxsock = maxconn * 2 + maxconn * engine_fds.
1361 * = maxconn * (2 + engine_fds)
1362 */
1363 maxconn = remain / (2 + engine_fds);
1364 }
1365
Willy Tarreaudf23c0c2019-03-13 10:10:49 +01001366 return MAX(maxconn, DEFAULT_MAXCONN);
Willy Tarreauac350932019-03-01 15:43:14 +01001367}
1368
Willy Tarreaua409f302020-03-10 17:08:53 +01001369/* computes the estimated maxsock value for the given maxconn based on the
1370 * possibly set global.maxpipes and existing partial global.maxsock. It may
1371 * temporarily change global.maxconn for the time needed to propagate the
1372 * computations, and will reset it.
1373 */
1374static int compute_ideal_maxsock(int maxconn)
1375{
1376 int maxpipes = global.maxpipes;
1377 int maxsock = global.maxsock;
1378
1379
1380 if (!maxpipes) {
1381 int old_maxconn = global.maxconn;
1382
1383 global.maxconn = maxconn;
1384 maxpipes = compute_ideal_maxpipes();
1385 global.maxconn = old_maxconn;
1386 }
1387
1388 maxsock += maxconn * 2; /* each connection needs two sockets */
1389 maxsock += maxpipes * 2; /* each pipe needs two FDs */
1390 maxsock += global.nbthread; /* one epoll_fd/kqueue_fd per thread */
1391 maxsock += 2 * global.nbthread; /* one wake-up pipe (2 fd) per thread */
1392
1393 /* compute fd used by async engines */
1394 if (global.ssl_used_async_engines) {
1395 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
1396
1397 maxsock += maxconn * sides * global.ssl_used_async_engines;
1398 }
1399 return maxsock;
1400}
1401
Thayne McCombs8f0cc5c2021-01-07 21:35:52 -07001402/* Tests if it is possible to set the current process's RLIMIT_NOFILE to
Willy Tarreau304e17e2020-03-10 17:54:54 +01001403 * <maxsock>, then sets it back to the previous value. Returns non-zero if the
1404 * value is accepted, non-zero otherwise. This is used to determine if an
1405 * automatic limit may be applied or not. When it is not, the caller knows that
1406 * the highest we can do is the rlim_max at boot. In case of error, we return
1407 * that the setting is possible, so that we defer the error processing to the
1408 * final stage in charge of enforcing this.
1409 */
1410static int check_if_maxsock_permitted(int maxsock)
1411{
1412 struct rlimit orig_limit, test_limit;
1413 int ret;
1414
1415 if (getrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1416 return 1;
1417
1418 /* don't go further if we can't even set to what we have */
1419 if (setrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1420 return 1;
1421
1422 test_limit.rlim_max = MAX(maxsock, orig_limit.rlim_max);
1423 test_limit.rlim_cur = test_limit.rlim_max;
1424 ret = setrlimit(RLIMIT_NOFILE, &test_limit);
1425
1426 if (setrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1427 return 1;
1428
1429 return ret == 0;
1430}
1431
Amaury Denoyelle484454d2021-05-05 16:18:45 +02001432void mark_tainted(const enum tainted_flags flag)
1433{
1434 HA_ATOMIC_OR(&tainted, flag);
1435}
1436
1437unsigned int get_tainted()
1438{
1439 int tainted_state;
1440 HA_ATOMIC_STORE(&tainted_state, tainted);
1441 return tainted_state;
1442}
Willy Tarreau304e17e2020-03-10 17:54:54 +01001443
William Lallemand73b85e72017-06-01 17:38:51 +02001444/*
Willy Tarreaubaaee002006-06-26 02:48:02 +02001445 * This function initializes all the necessary variables. It only returns
1446 * if everything is OK. If something fails, it exits.
1447 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +01001448static void init(int argc, char **argv)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001449{
Willy Tarreaubaaee002006-06-26 02:48:02 +02001450 int arg_mode = 0; /* MODE_DEBUG, ... */
Willy Tarreaubaaee002006-06-26 02:48:02 +02001451 char *tmp;
1452 char *cfg_pidfile = NULL;
Willy Tarreau058e9072009-07-20 09:30:05 +02001453 int err_code = 0;
Maxime de Roucy0f503922016-05-13 23:52:55 +02001454 char *err_msg = NULL;
Willy Tarreau477ecd82010-01-03 21:12:30 +01001455 struct wordlist *wl;
Kevinm48936af2010-12-22 16:08:21 +00001456 char *progname;
Willy Tarreau576132e2011-09-10 19:26:56 +02001457 char *change_dir = NULL;
Christopher Fauletd7c91962015-04-30 11:48:27 +02001458 struct proxy *px;
Willy Tarreaue6945732016-12-21 19:57:00 +01001459 struct post_check_fct *pcf;
Willy Tarreauac350932019-03-01 15:43:14 +01001460 int ideal_maxconn;
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001461 char *check_condition = NULL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001462
Christopher Faulete3a5e352017-10-24 13:53:54 +02001463 global.mode = MODE_STARTING;
William Lallemand00417412020-06-05 14:08:41 +02001464 old_argv = copy_argv(argc, argv);
1465 if (!old_argv) {
William Lallemanddf6c5a82020-06-04 17:40:23 +02001466 ha_alert("failed to copy argv.\n");
1467 exit(1);
1468 }
William Lallemand73b85e72017-06-01 17:38:51 +02001469
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001470 if (!init_trash_buffers(1)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001471 ha_alert("failed to initialize trash buffers.\n");
Christopher Faulet748919a2017-07-26 14:59:46 +02001472 exit(1);
1473 }
David du Colombier7af46052012-05-16 14:16:48 +02001474
Emeric Brun2b920a12010-09-23 18:30:22 +02001475 /* NB: POSIX does not make it mandatory for gethostname() to NULL-terminate
1476 * the string in case of truncation, and at least FreeBSD appears not to do
1477 * it.
1478 */
1479 memset(hostname, 0, sizeof(hostname));
1480 gethostname(hostname, sizeof(hostname) - 1);
Dragan Dosen4f014152020-06-18 16:56:47 +02001481
1482 if ((localpeer = strdup(hostname)) == NULL) {
1483 ha_alert("Cannot allocate memory for local peer.\n");
1484 exit(EXIT_FAILURE);
1485 }
William Lallemanddaf4cd22018-04-17 16:46:13 +02001486 setenv("HAPROXY_LOCALPEER", localpeer, 1);
Emeric Brun2b920a12010-09-23 18:30:22 +02001487
William Lallemand24c928c2020-01-14 17:58:18 +01001488 /* we were in mworker mode, we should restart in mworker mode */
1489 if (getenv("HAPROXY_MWORKER_REEXEC") != NULL)
1490 global.mode |= MODE_MWORKER;
1491
Willy Tarreaubaaee002006-06-26 02:48:02 +02001492 /*
1493 * Initialize the previously static variables.
1494 */
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001495
Willy Tarreau173d9952018-01-26 21:48:23 +01001496 totalconn = actconn = listeners = stopping = 0;
Cyril Bonté203ec5a2017-03-23 22:44:13 +01001497 killed = 0;
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001498
Willy Tarreaubaaee002006-06-26 02:48:02 +02001499
1500#ifdef HAPROXY_MEMMAX
Willy Tarreau70060452015-12-14 12:46:07 +01001501 global.rlimit_memmax_all = HAPROXY_MEMMAX;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001502#endif
1503
Benoit GARNIERb413c2a2016-03-27 11:08:03 +02001504 tzset();
Willy Tarreauc4c80fb2021-04-11 15:00:34 +02001505 tv_init_process_date();
Willy Tarreaubaaee002006-06-26 02:48:02 +02001506 start_date = now;
1507
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001508 ha_random_boot(argv);
Willy Tarreau84310e22014-02-14 11:59:04 +01001509
Willy Tarreau8ed669b2013-01-11 15:49:37 +01001510 if (init_acl() != 0)
1511 exit(1);
Willy Tarreaub6b3df32018-11-26 16:31:20 +01001512
Amaury Denoyellec593bcd2021-05-19 15:35:29 +02001513#ifdef USE_OPENSSL
1514 /* Initialize the random generator.
1515 * Must be called before chroot for access to /dev/urandom
1516 */
1517 if (!ssl_initialize_random()) {
1518 ha_alert("OpenSSL random data generator initialization failed.\n");
1519 exit(1);
1520 }
1521#endif
1522
Thierry FOURNIER6f1fd482015-01-23 14:06:13 +01001523 /* Initialise lua. */
1524 hlua_init();
Thierry FOURNIER6f1fd482015-01-23 14:06:13 +01001525
Christopher Fauletff2613e2016-11-09 11:36:17 +01001526 /* Initialize process vars */
Willy Tarreaucfc4f242021-05-08 11:41:28 +02001527 vars_init(&proc_vars, SCOPE_PROC);
Christopher Fauletff2613e2016-11-09 11:36:17 +01001528
Willy Tarreau43b78992009-01-25 15:42:27 +01001529 global.tune.options |= GTUNE_USE_SELECT; /* select() is always available */
Willy Tarreaue5733232019-05-22 19:24:06 +02001530#if defined(USE_POLL)
Willy Tarreau43b78992009-01-25 15:42:27 +01001531 global.tune.options |= GTUNE_USE_POLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001532#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001533#if defined(USE_EPOLL)
Willy Tarreau43b78992009-01-25 15:42:27 +01001534 global.tune.options |= GTUNE_USE_EPOLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001535#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001536#if defined(USE_KQUEUE)
Willy Tarreau43b78992009-01-25 15:42:27 +01001537 global.tune.options |= GTUNE_USE_KQUEUE;
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001538#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001539#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00001540 global.tune.options |= GTUNE_USE_EVPORTS;
1541#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001542#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +01001543 global.tune.options |= GTUNE_USE_SPLICE;
1544#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +02001545#if defined(USE_GETADDRINFO)
1546 global.tune.options |= GTUNE_USE_GAI;
1547#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +00001548#if defined(SO_REUSEPORT)
1549 global.tune.options |= GTUNE_USE_REUSEPORT;
1550#endif
Willy Tarreau76cc6992020-07-01 18:49:24 +02001551#ifdef USE_THREAD
1552 global.tune.options |= GTUNE_IDLE_POOL_SHARED;
1553#endif
William Dauchya5194602020-03-28 19:29:58 +01001554 global.tune.options |= GTUNE_STRICT_LIMITS;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001555
1556 pid = getpid();
1557 progname = *argv;
1558 while ((tmp = strchr(progname, '/')) != NULL)
1559 progname = tmp + 1;
1560
Kevinm48936af2010-12-22 16:08:21 +00001561 /* the process name is used for the logs only */
Eric Salama7cea6062020-10-02 11:58:19 +02001562 chunk_initlen(&global.log_tag, strdup(progname), strlen(progname), strlen(progname));
1563 if (b_orig(&global.log_tag) == NULL) {
1564 chunk_destroy(&global.log_tag);
1565 ha_alert("Cannot allocate memory for log_tag.\n");
1566 exit(EXIT_FAILURE);
1567 }
Kevinm48936af2010-12-22 16:08:21 +00001568
Willy Tarreaubaaee002006-06-26 02:48:02 +02001569 argc--; argv++;
1570 while (argc > 0) {
1571 char *flag;
1572
1573 if (**argv == '-') {
1574 flag = *argv+1;
1575
1576 /* 1 arg */
1577 if (*flag == 'v') {
1578 display_version();
Willy Tarreau7b066db2007-12-02 11:28:59 +01001579 if (flag[1] == 'v') /* -vv */
1580 display_build_opts();
Willy Tarreaubaaee002006-06-26 02:48:02 +02001581 exit(0);
1582 }
Willy Tarreaue5733232019-05-22 19:24:06 +02001583#if defined(USE_EPOLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001584 else if (*flag == 'd' && flag[1] == 'e')
Willy Tarreau43b78992009-01-25 15:42:27 +01001585 global.tune.options &= ~GTUNE_USE_EPOLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001586#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001587#if defined(USE_POLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001588 else if (*flag == 'd' && flag[1] == 'p')
Willy Tarreau43b78992009-01-25 15:42:27 +01001589 global.tune.options &= ~GTUNE_USE_POLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001590#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001591#if defined(USE_KQUEUE)
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001592 else if (*flag == 'd' && flag[1] == 'k')
Willy Tarreau43b78992009-01-25 15:42:27 +01001593 global.tune.options &= ~GTUNE_USE_KQUEUE;
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001594#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001595#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00001596 else if (*flag == 'd' && flag[1] == 'v')
1597 global.tune.options &= ~GTUNE_USE_EVPORTS;
1598#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001599#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +01001600 else if (*flag == 'd' && flag[1] == 'S')
1601 global.tune.options &= ~GTUNE_USE_SPLICE;
1602#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +02001603#if defined(USE_GETADDRINFO)
1604 else if (*flag == 'd' && flag[1] == 'G')
1605 global.tune.options &= ~GTUNE_USE_GAI;
1606#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +00001607#if defined(SO_REUSEPORT)
1608 else if (*flag == 'd' && flag[1] == 'R')
1609 global.tune.options &= ~GTUNE_USE_REUSEPORT;
1610#endif
Emeric Brun850efd52014-01-29 12:24:34 +01001611 else if (*flag == 'd' && flag[1] == 'V')
1612 global.ssl_server_verify = SSL_SERVER_VERIFY_NONE;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001613 else if (*flag == 'V')
1614 arg_mode |= MODE_VERBOSE;
1615 else if (*flag == 'd' && flag[1] == 'b')
1616 arg_mode |= MODE_FOREGROUND;
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +02001617 else if (*flag == 'd' && flag[1] == 'D')
1618 arg_mode |= MODE_DIAG;
Willy Tarreau3eb10b82020-04-15 16:42:39 +02001619 else if (*flag == 'd' && flag[1] == 'W')
1620 arg_mode |= MODE_ZERO_WARNING;
Willy Tarreau6e064432012-05-08 15:40:42 +02001621 else if (*flag == 'd' && flag[1] == 'M')
1622 mem_poison_byte = flag[2] ? strtol(flag + 2, NULL, 0) : 'P';
Willy Tarreau3eed10e2016-11-07 21:03:16 +01001623 else if (*flag == 'd' && flag[1] == 'r')
1624 global.tune.options |= GTUNE_RESOLVE_DONTFAIL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001625 else if (*flag == 'd')
1626 arg_mode |= MODE_DEBUG;
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001627 else if (*flag == 'c' && flag[1] == 'c') {
1628 arg_mode |= MODE_CHECK_CONDITION;
1629 argv++;
1630 argc--;
1631 check_condition = *argv;
1632 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001633 else if (*flag == 'c')
1634 arg_mode |= MODE_CHECK;
William Lallemand095ba4c2017-06-01 17:38:50 +02001635 else if (*flag == 'D')
Willy Tarreau6bde87b2009-05-18 16:29:51 +02001636 arg_mode |= MODE_DAEMON;
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001637 else if (*flag == 'W' && flag[1] == 's') {
Lukas Tribusf46bf952017-11-21 12:39:34 +01001638 arg_mode |= MODE_MWORKER | MODE_FOREGROUND;
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001639#if defined(USE_SYSTEMD)
1640 global.tune.options |= GTUNE_USE_SYSTEMD;
1641#else
Christopher Faulet767a84b2017-11-24 16:50:31 +01001642 ha_alert("master-worker mode with systemd support (-Ws) requested, but not compiled. Use master-worker mode (-W) if you are not using Type=notify in your unit file or recompile with USE_SYSTEMD=1.\n\n");
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001643 usage(progname);
1644#endif
1645 }
William Lallemand095ba4c2017-06-01 17:38:50 +02001646 else if (*flag == 'W')
1647 arg_mode |= MODE_MWORKER;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001648 else if (*flag == 'q')
1649 arg_mode |= MODE_QUIET;
Olivier Houchardf73629d2017-04-05 22:33:04 +02001650 else if (*flag == 'x') {
William Lallemand4f71d302020-06-04 23:41:29 +02001651 if (argc <= 1) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001652 ha_alert("Unix socket path expected with the -x flag\n\n");
William Lallemand45eff442017-06-19 15:57:55 +02001653 usage(progname);
Olivier Houchardf73629d2017-04-05 22:33:04 +02001654 }
William Lallemand4fc09692017-06-19 16:37:19 +02001655 if (old_unixsocket)
Christopher Faulet767a84b2017-11-24 16:50:31 +01001656 ha_warning("-x option already set, overwriting the value\n");
Olivier Houchardf73629d2017-04-05 22:33:04 +02001657 old_unixsocket = argv[1];
William Lallemand4fc09692017-06-19 16:37:19 +02001658
Olivier Houchardf73629d2017-04-05 22:33:04 +02001659 argv++;
1660 argc--;
1661 }
William Lallemande7361152018-10-26 14:47:36 +02001662 else if (*flag == 'S') {
1663 struct wordlist *c;
1664
William Lallemanda6b32492020-06-04 23:49:20 +02001665 if (argc <= 1) {
William Lallemande7361152018-10-26 14:47:36 +02001666 ha_alert("Socket and optional bind parameters expected with the -S flag\n");
1667 usage(progname);
1668 }
1669 if ((c = malloc(sizeof(*c))) == NULL || (c->s = strdup(argv[1])) == NULL) {
1670 ha_alert("Cannot allocate memory\n");
1671 exit(EXIT_FAILURE);
1672 }
Willy Tarreau2b718102021-04-21 07:32:39 +02001673 LIST_INSERT(&mworker_cli_conf, &c->list);
William Lallemande7361152018-10-26 14:47:36 +02001674
1675 argv++;
1676 argc--;
1677 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001678 else if (*flag == 's' && (flag[1] == 'f' || flag[1] == 't')) {
1679 /* list of pids to finish ('f') or terminate ('t') */
1680
1681 if (flag[1] == 'f')
1682 oldpids_sig = SIGUSR1; /* finish then exit */
1683 else
1684 oldpids_sig = SIGTERM; /* terminate immediately */
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001685 while (argc > 1 && argv[1][0] != '-') {
Chris Lane236062f2018-02-05 23:15:44 +00001686 char * endptr = NULL;
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001687 oldpids = realloc(oldpids, (nb_oldpids + 1) * sizeof(int));
1688 if (!oldpids) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001689 ha_alert("Cannot allocate old pid : out of memory.\n");
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001690 exit(1);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001691 }
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001692 argc--; argv++;
Chris Lane236062f2018-02-05 23:15:44 +00001693 errno = 0;
1694 oldpids[nb_oldpids] = strtol(*argv, &endptr, 10);
1695 if (errno) {
1696 ha_alert("-%2s option: failed to parse {%s}: %s\n",
1697 flag,
1698 *argv, strerror(errno));
1699 exit(1);
1700 } else if (endptr && strlen(endptr)) {
Willy Tarreau90807112020-02-25 08:16:33 +01001701 while (isspace((unsigned char)*endptr)) endptr++;
Aurélien Nephtali39b89882018-02-17 20:53:11 +01001702 if (*endptr != 0) {
Chris Lane236062f2018-02-05 23:15:44 +00001703 ha_alert("-%2s option: some bytes unconsumed in PID list {%s}\n",
1704 flag, endptr);
1705 exit(1);
Aurélien Nephtali39b89882018-02-17 20:53:11 +01001706 }
Chris Lane236062f2018-02-05 23:15:44 +00001707 }
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001708 if (oldpids[nb_oldpids] <= 0)
1709 usage(progname);
1710 nb_oldpids++;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001711 }
1712 }
Willy Tarreaua088d312015-10-08 11:58:48 +02001713 else if (flag[0] == '-' && flag[1] == 0) { /* "--" */
1714 /* now that's a cfgfile list */
1715 argv++; argc--;
1716 while (argc > 0) {
Maxime de Roucy0f503922016-05-13 23:52:55 +02001717 if (!list_append_word(&cfg_cfgfiles, *argv, &err_msg)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001718 ha_alert("Cannot load configuration file/directory %s : %s\n",
1719 *argv,
1720 err_msg);
Willy Tarreaua088d312015-10-08 11:58:48 +02001721 exit(1);
1722 }
Willy Tarreaua088d312015-10-08 11:58:48 +02001723 argv++; argc--;
1724 }
1725 break;
1726 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001727 else { /* >=2 args */
1728 argv++; argc--;
1729 if (argc == 0)
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001730 usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001731
1732 switch (*flag) {
Willy Tarreau576132e2011-09-10 19:26:56 +02001733 case 'C' : change_dir = *argv; break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001734 case 'n' : cfg_maxconn = atol(*argv); break;
Willy Tarreau70060452015-12-14 12:46:07 +01001735 case 'm' : global.rlimit_memmax_all = atol(*argv); break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001736 case 'N' : cfg_maxpconn = atol(*argv); break;
William Lallemanddaf4cd22018-04-17 16:46:13 +02001737 case 'L' :
Dragan Dosen4f014152020-06-18 16:56:47 +02001738 free(localpeer);
1739 if ((localpeer = strdup(*argv)) == NULL) {
1740 ha_alert("Cannot allocate memory for local peer.\n");
1741 exit(EXIT_FAILURE);
1742 }
William Lallemanddaf4cd22018-04-17 16:46:13 +02001743 setenv("HAPROXY_LOCALPEER", localpeer, 1);
Dragan Dosen13cd54c2020-06-18 18:24:05 +02001744 global.localpeer_cmdline = 1;
William Lallemanddaf4cd22018-04-17 16:46:13 +02001745 break;
Willy Tarreau5d01a632009-06-22 16:02:30 +02001746 case 'f' :
Maxime de Roucy0f503922016-05-13 23:52:55 +02001747 if (!list_append_word(&cfg_cfgfiles, *argv, &err_msg)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001748 ha_alert("Cannot load configuration file/directory %s : %s\n",
1749 *argv,
1750 err_msg);
Willy Tarreau5d01a632009-06-22 16:02:30 +02001751 exit(1);
1752 }
Willy Tarreau5d01a632009-06-22 16:02:30 +02001753 break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001754 case 'p' : cfg_pidfile = *argv; break;
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001755 default: usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001756 }
1757 }
1758 }
1759 else
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001760 usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001761 argv++; argc--;
1762 }
1763
Christopher Faulete3a5e352017-10-24 13:53:54 +02001764 global.mode |= (arg_mode & (MODE_DAEMON | MODE_MWORKER | MODE_FOREGROUND | MODE_VERBOSE
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +02001765 | MODE_QUIET | MODE_CHECK | MODE_DEBUG | MODE_ZERO_WARNING
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001766 | MODE_DIAG | MODE_CHECK_CONDITION));
Willy Tarreaubaaee002006-06-26 02:48:02 +02001767
William Lallemand944e6192018-11-21 15:48:31 +01001768 if (getenv("HAPROXY_MWORKER_WAIT_ONLY")) {
William Lallemandcb11fd22017-06-01 17:38:52 +02001769 unsetenv("HAPROXY_MWORKER_WAIT_ONLY");
William Lallemand944e6192018-11-21 15:48:31 +01001770 global.mode |= MODE_MWORKER_WAIT;
1771 global.mode &= ~MODE_MWORKER;
William Lallemandcb11fd22017-06-01 17:38:52 +02001772 }
1773
1774 if ((global.mode & MODE_MWORKER) && (getenv("HAPROXY_MWORKER_REEXEC") != NULL)) {
1775 atexit_flag = 1;
1776 atexit(reexec_on_failure);
1777 }
1778
Willy Tarreau576132e2011-09-10 19:26:56 +02001779 if (change_dir && chdir(change_dir) < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001780 ha_alert("Could not change to directory %s : %s\n", change_dir, strerror(errno));
Willy Tarreau576132e2011-09-10 19:26:56 +02001781 exit(1);
1782 }
1783
Willy Tarreaubaaee002006-06-26 02:48:02 +02001784 global.maxsock = 10; /* reserve 10 fds ; will be incremented by socket eaters */
Willy Tarreau915e1eb2009-06-22 15:48:36 +02001785
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001786#ifdef USE_CPU_AFFINITY
1787 {
1788 int i;
Willy Tarreau44ea6312021-06-15 08:57:56 +02001789 ha_cpuset_zero(&cpu_map.proc);
1790 ha_cpuset_zero(&cpu_map.proc_t1);
Willy Tarreau26f42a02021-05-14 08:26:38 +02001791 for (i = 0; i < MAX_THREADS; ++i) {
Amaury Denoyellefc6ac532021-04-27 10:46:36 +02001792 ha_cpuset_zero(&cpu_map.thread[i]);
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001793 }
Amaury Denoyelle982fb532021-04-21 18:39:58 +02001794 }
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001795#endif
Amaury Denoyelle982fb532021-04-21 18:39:58 +02001796
Amaury Denoyelle11124302021-06-04 18:22:08 +02001797 usermsgs_clr("config");
1798
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001799 if (global.mode & MODE_CHECK_CONDITION) {
1800 int result;
1801
1802 uint32_t err;
1803 const char *errptr;
1804 char *errmsg = NULL;
1805
1806 char *args[MAX_LINE_ARGS+1];
1807 int arg = sizeof(args) / sizeof(*args);
1808 size_t outlen = strlen(check_condition) + 1;
1809
1810 err = parse_line(check_condition, check_condition, &outlen, args, &arg,
1811 PARSE_OPT_DQUOTE | PARSE_OPT_SQUOTE | PARSE_OPT_BKSLASH,
1812 &errptr);
1813
1814 if (err & PARSE_ERR_QUOTE) {
1815 ha_alert("Syntax Error in condition: Unmatched quote.\n");
1816 exit(2);
1817 }
1818
1819 if (err & PARSE_ERR_HEX) {
1820 ha_alert("Syntax Error in condition: Truncated or invalid hexadecimal sequence.\n");
1821 exit(2);
1822 }
1823
1824 if (err & (PARSE_ERR_TOOLARGE|PARSE_ERR_OVERLAP)) {
1825 ha_alert("Error in condition: Line too long.\n");
1826 exit(2);
1827 }
1828
1829 if (err & PARSE_ERR_TOOMANY) {
1830 ha_alert("Error in condition: Too many words.\n");
1831 exit(2);
1832 }
1833
1834 if (err) {
1835 ha_alert("Unhandled error in condition, please report this to the developers.\n");
1836 exit(2);
1837 }
1838
1839 result = cfg_eval_condition(args, &errmsg, &errptr);
1840
1841 if (result < 0) {
1842 if (errmsg)
1843 ha_alert("Failed to evaluate condition: %s\n", errmsg);
1844
1845 exit(2);
1846 }
1847
1848 exit(result ? 0 : 1);
1849 }
1850
William Lallemand944e6192018-11-21 15:48:31 +01001851 /* in wait mode, we don't try to read the configuration files */
1852 if (!(global.mode & MODE_MWORKER_WAIT)) {
Christopher Faulet4e366822021-01-12 18:57:38 +01001853 char *env_cfgfiles = NULL;
1854 int env_err = 0;
Willy Tarreauc4382422009-12-06 13:10:44 +01001855
William Lallemand944e6192018-11-21 15:48:31 +01001856 /* handle cfgfiles that are actually directories */
1857 cfgfiles_expand_directories();
1858
1859 if (LIST_ISEMPTY(&cfg_cfgfiles))
1860 usage(progname);
1861
1862
1863 list_for_each_entry(wl, &cfg_cfgfiles, list) {
1864 int ret;
1865
Christopher Faulet4e366822021-01-12 18:57:38 +01001866 if (env_err == 0) {
1867 if (!memprintf(&env_cfgfiles, "%s%s%s",
1868 (env_cfgfiles ? env_cfgfiles : ""),
1869 (env_cfgfiles ? ";" : ""), wl->s))
1870 env_err = 1;
1871 }
William Lallemand7b302d82019-05-20 11:15:37 +02001872
William Lallemand944e6192018-11-21 15:48:31 +01001873 ret = readcfgfile(wl->s);
1874 if (ret == -1) {
1875 ha_alert("Could not open configuration file %s : %s\n",
1876 wl->s, strerror(errno));
Christopher Faulet4e366822021-01-12 18:57:38 +01001877 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001878 exit(1);
1879 }
1880 if (ret & (ERR_ABORT|ERR_FATAL))
1881 ha_alert("Error(s) found in configuration file : %s\n", wl->s);
1882 err_code |= ret;
Christopher Faulet4e366822021-01-12 18:57:38 +01001883 if (err_code & ERR_ABORT) {
1884 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001885 exit(1);
Christopher Faulet4e366822021-01-12 18:57:38 +01001886 }
Willy Tarreauc4382422009-12-06 13:10:44 +01001887 }
Krzysztof Oledzkib304dc72007-10-14 23:40:01 +02001888
William Lallemand944e6192018-11-21 15:48:31 +01001889 /* do not try to resolve arguments nor to spot inconsistencies when
1890 * the configuration contains fatal errors caused by files not found
1891 * or failed memory allocations.
1892 */
1893 if (err_code & (ERR_ABORT|ERR_FATAL)) {
1894 ha_alert("Fatal errors found in configuration.\n");
Christopher Faulet4e366822021-01-12 18:57:38 +01001895 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001896 exit(1);
1897 }
Christopher Faulet4e366822021-01-12 18:57:38 +01001898 if (env_err) {
1899 ha_alert("Could not allocate memory for HAPROXY_CFGFILES env variable\n");
1900 exit(1);
1901 }
1902 setenv("HAPROXY_CFGFILES", env_cfgfiles, 1);
1903 free(env_cfgfiles);
William Lallemand7b302d82019-05-20 11:15:37 +02001904
Willy Tarreaub83dc3d2017-04-19 11:24:07 +02001905 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001906 if (global.mode & MODE_MWORKER) {
William Lallemand16dd1b32018-11-19 18:46:18 +01001907 struct mworker_proc *tmproc;
1908
William Lallemand482f9a92019-04-12 16:15:00 +02001909 setenv("HAPROXY_MWORKER", "1", 1);
1910
William Lallemand16dd1b32018-11-19 18:46:18 +01001911 if (getenv("HAPROXY_MWORKER_REEXEC") == NULL) {
1912
William Lallemandf3a86832019-04-01 11:29:58 +02001913 tmproc = calloc(1, sizeof(*tmproc));
William Lallemand16dd1b32018-11-19 18:46:18 +01001914 if (!tmproc) {
1915 ha_alert("Cannot allocate process structures.\n");
1916 exit(EXIT_FAILURE);
1917 }
William Lallemand8f7069a2019-04-12 16:09:23 +02001918 tmproc->options |= PROC_O_TYPE_MASTER; /* master */
William Lallemand16dd1b32018-11-19 18:46:18 +01001919 tmproc->reloads = 0;
William Lallemand16dd1b32018-11-19 18:46:18 +01001920 tmproc->pid = pid;
1921 tmproc->timestamp = start_date.tv_sec;
1922 tmproc->ipc_fd[0] = -1;
1923 tmproc->ipc_fd[1] = -1;
1924
1925 proc_self = tmproc;
1926
Willy Tarreau2b718102021-04-21 07:32:39 +02001927 LIST_APPEND(&proc_list, &tmproc->list);
William Lallemand16dd1b32018-11-19 18:46:18 +01001928 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001929
Willy Tarreau6185a032021-06-15 08:02:06 +02001930 tmproc = calloc(1, sizeof(*tmproc));
1931 if (!tmproc) {
1932 ha_alert("Cannot allocate process structures.\n");
1933 exit(EXIT_FAILURE);
1934 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001935
Willy Tarreau6185a032021-06-15 08:02:06 +02001936 tmproc->options |= PROC_O_TYPE_WORKER; /* worker */
1937 tmproc->pid = -1;
1938 tmproc->reloads = 0;
1939 tmproc->timestamp = -1;
Willy Tarreau6185a032021-06-15 08:02:06 +02001940 tmproc->ipc_fd[0] = -1;
1941 tmproc->ipc_fd[1] = -1;
William Lallemandce83b4a2018-10-26 14:47:30 +02001942
Willy Tarreau6185a032021-06-15 08:02:06 +02001943 if (mworker_cli_sockpair_new(tmproc, 0) < 0) {
1944 exit(EXIT_FAILURE);
William Lallemandce83b4a2018-10-26 14:47:30 +02001945 }
Willy Tarreau6185a032021-06-15 08:02:06 +02001946
1947 LIST_APPEND(&proc_list, &tmproc->list);
William Lallemand944e6192018-11-21 15:48:31 +01001948 }
1949 if (global.mode & (MODE_MWORKER|MODE_MWORKER_WAIT)) {
1950 struct wordlist *it, *c;
1951
Remi Tricot-Le Breton1f4fa902021-05-19 10:45:12 +02001952 /* get the info of the children in the env */
1953 if (mworker_env_to_proc_list() < 0) {
1954 exit(EXIT_FAILURE);
1955 }
William Lallemande7361152018-10-26 14:47:36 +02001956
William Lallemand550db6d2018-11-06 17:37:12 +01001957 if (!LIST_ISEMPTY(&mworker_cli_conf)) {
William Lallemande7361152018-10-26 14:47:36 +02001958
William Lallemand550db6d2018-11-06 17:37:12 +01001959 if (mworker_cli_proxy_create() < 0) {
William Lallemande7361152018-10-26 14:47:36 +02001960 ha_alert("Can't create the master's CLI.\n");
1961 exit(EXIT_FAILURE);
1962 }
William Lallemande7361152018-10-26 14:47:36 +02001963
William Lallemand550db6d2018-11-06 17:37:12 +01001964 list_for_each_entry_safe(c, it, &mworker_cli_conf, list) {
1965
1966 if (mworker_cli_proxy_new_listener(c->s) < 0) {
1967 ha_alert("Can't create the master's CLI.\n");
1968 exit(EXIT_FAILURE);
1969 }
Willy Tarreau2b718102021-04-21 07:32:39 +02001970 LIST_DELETE(&c->list);
William Lallemand550db6d2018-11-06 17:37:12 +01001971 free(c->s);
1972 free(c);
1973 }
1974 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001975 }
1976
Eric Salama5ba83352021-03-16 15:11:17 +01001977 if (!LIST_ISEMPTY(&mworker_cli_conf) && !(arg_mode & MODE_MWORKER)) {
1978 ha_warning("a master CLI socket was defined, but master-worker mode (-W) is not enabled.\n");
1979 }
1980
Willy Tarreaue90904d2021-02-12 14:08:31 +01001981 /* defaults sections are not needed anymore */
1982 proxy_destroy_all_defaults();
1983
Willy Tarreaubb925012009-07-23 13:36:36 +02001984 err_code |= check_config_validity();
Christopher Fauletc1692962019-08-12 09:51:07 +02001985 for (px = proxies_list; px; px = px->next) {
1986 struct server *srv;
1987 struct post_proxy_check_fct *ppcf;
1988 struct post_server_check_fct *pscf;
1989
Christopher Fauletd5bd8242020-11-02 16:20:13 +01001990 if (px->disabled)
1991 continue;
1992
Christopher Fauletc1692962019-08-12 09:51:07 +02001993 list_for_each_entry(pscf, &post_server_check_list, list) {
1994 for (srv = px->srv; srv; srv = srv->next)
1995 err_code |= pscf->fct(srv);
1996 }
1997 list_for_each_entry(ppcf, &post_proxy_check_list, list)
1998 err_code |= ppcf->fct(px);
1999 }
Willy Tarreaubb925012009-07-23 13:36:36 +02002000 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002001 ha_alert("Fatal errors found in configuration.\n");
Willy Tarreau915e1eb2009-06-22 15:48:36 +02002002 exit(1);
2003 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02002004
Carl Henrik Lundef91ac192020-02-27 16:45:50 +01002005 err_code |= pattern_finalize_config();
2006 if (err_code & (ERR_ABORT|ERR_FATAL)) {
2007 ha_alert("Failed to finalize pattern config.\n");
2008 exit(1);
2009 }
Willy Tarreau0f936722019-04-11 14:47:08 +02002010
Willy Tarreaue5733232019-05-22 19:24:06 +02002011#ifdef USE_NS
KOVACS Krisztianb3e54fe2014-11-17 15:11:45 +01002012 err_code |= netns_init();
2013 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002014 ha_alert("Failed to initialize namespace support.\n");
KOVACS Krisztianb3e54fe2014-11-17 15:11:45 +01002015 exit(1);
2016 }
2017#endif
2018
Baptiste Assmann4215d7d2016-11-02 15:33:15 +01002019 /* Apply server states */
2020 apply_server_state();
2021
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002022 for (px = proxies_list; px; px = px->next)
Baptiste Assmann4215d7d2016-11-02 15:33:15 +01002023 srv_compute_all_admin_states(px);
2024
Baptiste Assmann83cbaa52016-11-02 15:34:05 +01002025 /* Apply servers' configured address */
2026 err_code |= srv_init_addr();
2027 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002028 ha_alert("Failed to initialize server(s) addr.\n");
Baptiste Assmann83cbaa52016-11-02 15:34:05 +01002029 exit(1);
2030 }
2031
Willy Tarreau3eb10b82020-04-15 16:42:39 +02002032 if (warned & WARN_ANY && global.mode & MODE_ZERO_WARNING) {
2033 ha_alert("Some warnings were found and 'zero-warning' is set. Aborting.\n");
2034 exit(1);
2035 }
2036
Willy Tarreaubaaee002006-06-26 02:48:02 +02002037 if (global.mode & MODE_CHECK) {
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002038 struct peers *pr;
2039 struct proxy *px;
2040
Willy Tarreaubebd2122020-04-15 16:06:11 +02002041 if (warned & WARN_ANY)
2042 qfprintf(stdout, "Warnings were found.\n");
2043
Frédéric Lécailleed2b4a62017-07-13 09:07:09 +02002044 for (pr = cfg_peers; pr; pr = pr->next)
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002045 if (pr->peers_fe)
2046 break;
2047
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002048 for (px = proxies_list; px; px = px->next)
Willy Tarreauc3914d42020-09-24 08:39:22 +02002049 if (!px->disabled && px->li_all)
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002050 break;
2051
2052 if (pr || px) {
2053 /* At least one peer or one listener has been found */
2054 qfprintf(stdout, "Configuration file is valid\n");
Tim Duesterhus0a3b43d2020-06-14 00:37:42 +02002055 deinit_and_exit(0);
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002056 }
2057 qfprintf(stdout, "Configuration file has no error but will not start (no listener) => exit(2).\n");
2058 exit(2);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002059 }
Willy Tarreaue9b26022011-08-01 20:57:55 +02002060
Amaury Denoyelle5a6926d2021-03-30 17:34:24 +02002061 if (global.mode & MODE_DIAG) {
2062 cfg_run_diagnostics();
2063 }
2064
Willy Tarreau8263d2b2012-08-28 00:06:31 +02002065 /* now we know the buffer size, we can initialize the channels and buffers */
Willy Tarreau9b28e032012-10-12 23:49:43 +02002066 init_buffer();
Willy Tarreau8280d642009-09-23 23:37:52 +02002067
Willy Tarreaue6945732016-12-21 19:57:00 +01002068 list_for_each_entry(pcf, &post_check_list, list) {
2069 err_code |= pcf->fct();
2070 if (err_code & (ERR_ABORT|ERR_FATAL))
2071 exit(1);
2072 }
2073
Willy Tarreaubaaee002006-06-26 02:48:02 +02002074 if (cfg_maxconn > 0)
2075 global.maxconn = cfg_maxconn;
2076
Willy Tarreau4975d142021-03-13 11:00:33 +01002077 if (global.cli_fe)
2078 global.maxsock += global.cli_fe->maxconn;
Willy Tarreau8d687d82019-03-01 09:39:42 +01002079
2080 if (cfg_peers) {
2081 /* peers also need to bypass global maxconn */
2082 struct peers *p = cfg_peers;
2083
2084 for (p = cfg_peers; p; p = p->next)
2085 if (p->peers_fe)
2086 global.maxsock += p->peers_fe->maxconn;
2087 }
2088
Willy Tarreaubaaee002006-06-26 02:48:02 +02002089 if (cfg_pidfile) {
Willy Tarreaua534fea2008-08-03 12:19:50 +02002090 free(global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002091 global.pidfile = strdup(cfg_pidfile);
2092 }
2093
Willy Tarreaud0256482015-01-15 21:45:22 +01002094 /* Now we want to compute the maxconn and possibly maxsslconn values.
Willy Tarreauac350932019-03-01 15:43:14 +01002095 * It's a bit tricky. Maxconn defaults to the pre-computed value based
2096 * on rlim_fd_cur and the number of FDs in use due to the configuration,
2097 * and maxsslconn defaults to DEFAULT_MAXSSLCONN. On top of that we can
2098 * enforce a lower limit based on memmax.
Willy Tarreaud0256482015-01-15 21:45:22 +01002099 *
2100 * If memmax is set, then it depends on which values are set. If
2101 * maxsslconn is set, we use memmax to determine how many cleartext
2102 * connections may be added, and set maxconn to the sum of the two.
2103 * If maxconn is set and not maxsslconn, maxsslconn is computed from
2104 * the remaining amount of memory between memmax and the cleartext
2105 * connections. If neither are set, then it is considered that all
2106 * connections are SSL-capable, and maxconn is computed based on this,
2107 * then maxsslconn accordingly. We need to know if SSL is used on the
2108 * frontends, backends, or both, because when it's used on both sides,
2109 * we need twice the value for maxsslconn, but we only count the
2110 * handshake once since it is not performed on the two sides at the
2111 * same time (frontend-side is terminated before backend-side begins).
2112 * The SSL stack is supposed to have filled ssl_session_cost and
Willy Tarreau474b96a2015-01-28 19:03:21 +01002113 * ssl_handshake_cost during its initialization. In any case, if
2114 * SYSTEM_MAXCONN is set, we still enforce it as an upper limit for
2115 * maxconn in order to protect the system.
Willy Tarreaud0256482015-01-15 21:45:22 +01002116 */
Willy Tarreauac350932019-03-01 15:43:14 +01002117 ideal_maxconn = compute_ideal_maxconn();
2118
Willy Tarreaud0256482015-01-15 21:45:22 +01002119 if (!global.rlimit_memmax) {
2120 if (global.maxconn == 0) {
Willy Tarreauac350932019-03-01 15:43:14 +01002121 global.maxconn = ideal_maxconn;
Willy Tarreaud0256482015-01-15 21:45:22 +01002122 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2123 fprintf(stderr, "Note: setting global.maxconn to %d.\n", global.maxconn);
2124 }
2125 }
2126#ifdef USE_OPENSSL
2127 else if (!global.maxconn && !global.maxsslconn &&
2128 (global.ssl_used_frontend || global.ssl_used_backend)) {
2129 /* memmax is set, compute everything automatically. Here we want
2130 * to ensure that all SSL connections will be served. We take
2131 * care of the number of sides where SSL is used, and consider
2132 * the worst case : SSL used on both sides and doing a handshake
2133 * simultaneously. Note that we can't have more than maxconn
2134 * handshakes at a time by definition, so for the worst case of
2135 * two SSL conns per connection, we count a single handshake.
2136 */
2137 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2138 int64_t mem = global.rlimit_memmax * 1048576ULL;
Willy Tarreau304e17e2020-03-10 17:54:54 +01002139 int retried = 0;
Willy Tarreaud0256482015-01-15 21:45:22 +01002140
2141 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2142 mem -= global.maxzlibmem;
2143 mem = mem * MEM_USABLE_RATIO;
2144
Willy Tarreau304e17e2020-03-10 17:54:54 +01002145 /* Principle: we test once to set maxconn according to the free
2146 * memory. If it results in values the system rejects, we try a
2147 * second time by respecting rlim_fd_max. If it fails again, we
2148 * go back to the initial value and will let the final code
2149 * dealing with rlimit report the error. That's up to 3 attempts.
2150 */
2151 do {
2152 global.maxconn = mem /
2153 ((STREAM_MAX_COST + 2 * global.tune.bufsize) + // stream + 2 buffers per stream
2154 sides * global.ssl_session_max_cost + // SSL buffers, one per side
2155 global.ssl_handshake_max_cost); // 1 handshake per connection max
Willy Tarreaud0256482015-01-15 21:45:22 +01002156
Willy Tarreau304e17e2020-03-10 17:54:54 +01002157 if (retried == 1)
2158 global.maxconn = MIN(global.maxconn, ideal_maxconn);
2159 global.maxconn = round_2dig(global.maxconn);
Willy Tarreau474b96a2015-01-28 19:03:21 +01002160#ifdef SYSTEM_MAXCONN
Willy Tarreau304e17e2020-03-10 17:54:54 +01002161 if (global.maxconn > SYSTEM_MAXCONN)
2162 global.maxconn = SYSTEM_MAXCONN;
Willy Tarreau474b96a2015-01-28 19:03:21 +01002163#endif /* SYSTEM_MAXCONN */
Willy Tarreau304e17e2020-03-10 17:54:54 +01002164 global.maxsslconn = sides * global.maxconn;
2165
2166 if (check_if_maxsock_permitted(compute_ideal_maxsock(global.maxconn)))
2167 break;
2168 } while (retried++ < 2);
2169
Willy Tarreaud0256482015-01-15 21:45:22 +01002170 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2171 fprintf(stderr, "Note: setting global.maxconn to %d and global.maxsslconn to %d.\n",
2172 global.maxconn, global.maxsslconn);
2173 }
2174 else if (!global.maxsslconn &&
2175 (global.ssl_used_frontend || global.ssl_used_backend)) {
2176 /* memmax and maxconn are known, compute maxsslconn automatically.
2177 * maxsslconn being forced, we don't know how many of it will be
2178 * on each side if both sides are being used. The worst case is
2179 * when all connections use only one SSL instance because
2180 * handshakes may be on two sides at the same time.
2181 */
2182 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2183 int64_t mem = global.rlimit_memmax * 1048576ULL;
2184 int64_t sslmem;
2185
2186 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2187 mem -= global.maxzlibmem;
2188 mem = mem * MEM_USABLE_RATIO;
2189
Willy Tarreau87b09662015-04-03 00:22:06 +02002190 sslmem = mem - global.maxconn * (int64_t)(STREAM_MAX_COST + 2 * global.tune.bufsize);
Willy Tarreaud0256482015-01-15 21:45:22 +01002191 global.maxsslconn = sslmem / (global.ssl_session_max_cost + global.ssl_handshake_max_cost);
2192 global.maxsslconn = round_2dig(global.maxsslconn);
2193
2194 if (sslmem <= 0 || global.maxsslconn < sides) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002195 ha_alert("Cannot compute the automatic maxsslconn because global.maxconn is already too "
2196 "high for the global.memmax value (%d MB). The absolute maximum possible value "
2197 "without SSL is %d, but %d was found and SSL is in use.\n",
2198 global.rlimit_memmax,
2199 (int)(mem / (STREAM_MAX_COST + 2 * global.tune.bufsize)),
2200 global.maxconn);
Willy Tarreaud0256482015-01-15 21:45:22 +01002201 exit(1);
2202 }
2203
2204 if (global.maxsslconn > sides * global.maxconn)
2205 global.maxsslconn = sides * global.maxconn;
2206
2207 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2208 fprintf(stderr, "Note: setting global.maxsslconn to %d\n", global.maxsslconn);
2209 }
2210#endif
2211 else if (!global.maxconn) {
2212 /* memmax and maxsslconn are known/unused, compute maxconn automatically */
2213 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2214 int64_t mem = global.rlimit_memmax * 1048576ULL;
2215 int64_t clearmem;
Willy Tarreau304e17e2020-03-10 17:54:54 +01002216 int retried = 0;
Willy Tarreaud0256482015-01-15 21:45:22 +01002217
2218 if (global.ssl_used_frontend || global.ssl_used_backend)
2219 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2220
2221 mem -= global.maxzlibmem;
2222 mem = mem * MEM_USABLE_RATIO;
2223
2224 clearmem = mem;
2225 if (sides)
2226 clearmem -= (global.ssl_session_max_cost + global.ssl_handshake_max_cost) * (int64_t)global.maxsslconn;
2227
Willy Tarreau304e17e2020-03-10 17:54:54 +01002228 /* Principle: we test once to set maxconn according to the free
2229 * memory. If it results in values the system rejects, we try a
2230 * second time by respecting rlim_fd_max. If it fails again, we
2231 * go back to the initial value and will let the final code
2232 * dealing with rlimit report the error. That's up to 3 attempts.
2233 */
2234 do {
2235 global.maxconn = clearmem / (STREAM_MAX_COST + 2 * global.tune.bufsize);
2236 if (retried == 1)
2237 global.maxconn = MIN(global.maxconn, ideal_maxconn);
2238 global.maxconn = round_2dig(global.maxconn);
Willy Tarreau474b96a2015-01-28 19:03:21 +01002239#ifdef SYSTEM_MAXCONN
Willy Tarreau304e17e2020-03-10 17:54:54 +01002240 if (global.maxconn > SYSTEM_MAXCONN)
2241 global.maxconn = SYSTEM_MAXCONN;
Willy Tarreau474b96a2015-01-28 19:03:21 +01002242#endif /* SYSTEM_MAXCONN */
Willy Tarreaud0256482015-01-15 21:45:22 +01002243
Willy Tarreau304e17e2020-03-10 17:54:54 +01002244 if (clearmem <= 0 || !global.maxconn) {
2245 ha_alert("Cannot compute the automatic maxconn because global.maxsslconn is already too "
2246 "high for the global.memmax value (%d MB). The absolute maximum possible value "
2247 "is %d, but %d was found.\n",
2248 global.rlimit_memmax,
Christopher Faulet767a84b2017-11-24 16:50:31 +01002249 (int)(mem / (global.ssl_session_max_cost + global.ssl_handshake_max_cost)),
Willy Tarreau304e17e2020-03-10 17:54:54 +01002250 global.maxsslconn);
2251 exit(1);
2252 }
2253
2254 if (check_if_maxsock_permitted(compute_ideal_maxsock(global.maxconn)))
2255 break;
2256 } while (retried++ < 2);
Willy Tarreaud0256482015-01-15 21:45:22 +01002257
2258 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
2259 if (sides && global.maxsslconn > sides * global.maxconn) {
2260 fprintf(stderr, "Note: global.maxsslconn is forced to %d which causes global.maxconn "
2261 "to be limited to %d. Better reduce global.maxsslconn to get more "
2262 "room for extra connections.\n", global.maxsslconn, global.maxconn);
2263 }
2264 fprintf(stderr, "Note: setting global.maxconn to %d\n", global.maxconn);
2265 }
Willy Tarreau66aa61f2009-01-18 21:44:07 +01002266 }
2267
Willy Tarreaua409f302020-03-10 17:08:53 +01002268 global.maxsock = compute_ideal_maxsock(global.maxconn);
2269 global.hardmaxconn = global.maxconn;
Willy Tarreaua4818db2020-06-19 16:20:59 +02002270 if (!global.maxpipes)
2271 global.maxpipes = compute_ideal_maxpipes();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002272
Olivier Houchard88698d92019-04-16 19:07:22 +02002273 /* update connection pool thresholds */
2274 global.tune.pool_low_count = ((long long)global.maxsock * global.tune.pool_low_ratio + 99) / 100;
2275 global.tune.pool_high_count = ((long long)global.maxsock * global.tune.pool_high_ratio + 99) / 100;
2276
Willy Tarreauc8d5b952019-02-27 17:25:52 +01002277 proxy_adjust_all_maxconn();
2278
Willy Tarreau1db37712007-06-03 17:16:49 +02002279 if (global.tune.maxpollevents <= 0)
2280 global.tune.maxpollevents = MAX_POLL_EVENTS;
2281
Willy Tarreau060a7612021-03-10 11:06:26 +01002282 if (global.tune.runqueue_depth <= 0) {
2283 /* tests on various thread counts from 1 to 64 have shown an
2284 * optimal queue depth following roughly 1/sqrt(threads).
2285 */
2286 int s = my_flsl(global.nbthread);
2287 s += (global.nbthread / s); // roughly twice the sqrt.
2288 global.tune.runqueue_depth = RUNQUEUE_DEPTH * 2 / s;
2289 }
Olivier Houchard1599b802018-05-24 18:59:04 +02002290
Willy Tarreau6f4a82c2009-03-21 20:43:57 +01002291 if (global.tune.recv_enough == 0)
2292 global.tune.recv_enough = MIN_RECV_AT_ONCE_ENOUGH;
2293
Willy Tarreau27a674e2009-08-17 07:23:33 +02002294 if (global.tune.maxrewrite >= global.tune.bufsize / 2)
2295 global.tune.maxrewrite = global.tune.bufsize / 2;
2296
Amaury Denoyelle11124302021-06-04 18:22:08 +02002297 usermsgs_clr(NULL);
2298
Willy Tarreaubaaee002006-06-26 02:48:02 +02002299 if (arg_mode & (MODE_DEBUG | MODE_FOREGROUND)) {
2300 /* command line debug mode inhibits configuration mode */
William Lallemand095ba4c2017-06-01 17:38:50 +02002301 global.mode &= ~(MODE_DAEMON | MODE_QUIET);
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002302 global.mode |= (arg_mode & (MODE_DEBUG | MODE_FOREGROUND));
2303 }
2304
William Lallemand095ba4c2017-06-01 17:38:50 +02002305 if (arg_mode & MODE_DAEMON) {
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002306 /* command line daemon mode inhibits foreground and debug modes mode */
2307 global.mode &= ~(MODE_DEBUG | MODE_FOREGROUND);
William Lallemand095ba4c2017-06-01 17:38:50 +02002308 global.mode |= arg_mode & MODE_DAEMON;
Willy Tarreaubaaee002006-06-26 02:48:02 +02002309 }
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002310
2311 global.mode |= (arg_mode & (MODE_QUIET | MODE_VERBOSE));
Willy Tarreaubaaee002006-06-26 02:48:02 +02002312
William Lallemand095ba4c2017-06-01 17:38:50 +02002313 if ((global.mode & MODE_DEBUG) && (global.mode & (MODE_DAEMON | MODE_QUIET))) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002314 ha_warning("<debug> mode incompatible with <quiet> and <daemon>. Keeping <debug> only.\n");
William Lallemand095ba4c2017-06-01 17:38:50 +02002315 global.mode &= ~(MODE_DAEMON | MODE_QUIET);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002316 }
2317
Christopher Fauletbe0faa22017-08-29 15:37:10 +02002318 if (global.nbthread < 1)
2319 global.nbthread = 1;
2320
Christopher Faulet3ef26392017-08-29 16:46:57 +02002321 /* Realloc trash buffers because global.tune.bufsize may have changed */
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002322 if (!init_trash_buffers(0)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002323 ha_alert("failed to initialize trash buffers.\n");
Christopher Faulet3ef26392017-08-29 16:46:57 +02002324 exit(1);
2325 }
2326
Christopher Faulet96d44832017-11-14 22:02:30 +01002327 if (!init_log_buffers()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002328 ha_alert("failed to initialize log buffers.\n");
Christopher Faulet96d44832017-11-14 22:02:30 +01002329 exit(1);
2330 }
2331
Willy Tarreauef1d1f82007-04-16 00:25:25 +02002332 /*
2333 * Note: we could register external pollers here.
2334 * Built-in pollers have been registered before main().
2335 */
Willy Tarreau4f60f162007-04-08 16:39:58 +02002336
Willy Tarreau43b78992009-01-25 15:42:27 +01002337 if (!(global.tune.options & GTUNE_USE_KQUEUE))
Willy Tarreau1e63130a2007-04-09 12:03:06 +02002338 disable_poller("kqueue");
2339
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00002340 if (!(global.tune.options & GTUNE_USE_EVPORTS))
2341 disable_poller("evports");
2342
Willy Tarreau43b78992009-01-25 15:42:27 +01002343 if (!(global.tune.options & GTUNE_USE_EPOLL))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002344 disable_poller("epoll");
2345
Willy Tarreau43b78992009-01-25 15:42:27 +01002346 if (!(global.tune.options & GTUNE_USE_POLL))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002347 disable_poller("poll");
2348
Willy Tarreau43b78992009-01-25 15:42:27 +01002349 if (!(global.tune.options & GTUNE_USE_SELECT))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002350 disable_poller("select");
2351
2352 /* Note: we could disable any poller by name here */
2353
Christopher Fauletb3f4e142016-03-07 12:46:38 +01002354 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
Willy Tarreau2ff76222007-04-09 19:29:56 +02002355 list_pollers(stderr);
Christopher Fauletb3f4e142016-03-07 12:46:38 +01002356 fprintf(stderr, "\n");
2357 list_filters(stderr);
2358 }
Willy Tarreau2ff76222007-04-09 19:29:56 +02002359
Willy Tarreau4f60f162007-04-08 16:39:58 +02002360 if (!init_pollers()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002361 ha_alert("No polling mechanism available.\n"
2362 " It is likely that haproxy was built with TARGET=generic and that FD_SETSIZE\n"
2363 " is too low on this platform to support maxconn and the number of listeners\n"
2364 " and servers. You should rebuild haproxy specifying your system using TARGET=\n"
2365 " in order to support other polling systems (poll, epoll, kqueue) or reduce the\n"
2366 " global maxconn setting to accommodate the system's limitation. For reference,\n"
2367 " FD_SETSIZE=%d on this system, global.maxconn=%d resulting in a maximum of\n"
2368 " %d file descriptors. You should thus reduce global.maxconn by %d. Also,\n"
2369 " check build settings using 'haproxy -vv'.\n\n",
2370 FD_SETSIZE, global.maxconn, global.maxsock, (global.maxsock + 1 - FD_SETSIZE) / 2);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002371 exit(1);
2372 }
Willy Tarreau2ff76222007-04-09 19:29:56 +02002373 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
2374 printf("Using %s() as the polling mechanism.\n", cur_poller.name);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002375 }
2376
Krzysztof Piotr Oledzki48cb2ae2009-10-02 22:51:14 +02002377 if (!global.node)
2378 global.node = strdup(hostname);
2379
Willy Tarreau02b092f2020-10-07 18:36:54 +02002380 /* stop disabled proxies */
2381 for (px = proxies_list; px; px = px->next) {
Willy Tarreauc3914d42020-09-24 08:39:22 +02002382 if (px->disabled)
Willy Tarreau02b092f2020-10-07 18:36:54 +02002383 stop_proxy(px);
2384 }
2385
Thierry FOURNIERa4a0f3d2015-01-23 12:08:30 +01002386 if (!hlua_post_init())
2387 exit(1);
Thomas Holmes6abded42015-05-12 16:23:58 +01002388
Maxime de Roucy0f503922016-05-13 23:52:55 +02002389 free(err_msg);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002390}
2391
Cyril Bonté203ec5a2017-03-23 22:44:13 +01002392void deinit(void)
Willy Tarreaubaaee002006-06-26 02:48:02 +02002393{
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002394 struct proxy *p = proxies_list, *p0;
Willy Tarreaudeb9ed82010-01-03 21:03:22 +01002395 struct wordlist *wl, *wlb;
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002396 struct uri_auth *uap, *ua = NULL;
William Lallemand0f99e342011-10-12 17:50:54 +02002397 struct logsrv *log, *logb;
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002398 struct build_opts_str *bol, *bolb;
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002399 struct post_deinit_fct *pdf, *pdfb;
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002400 struct proxy_deinit_fct *pxdf, *pxdfb;
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002401 struct server_deinit_fct *srvdf, *srvdfb;
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002402 struct per_thread_init_fct *tif, *tifb;
2403 struct per_thread_deinit_fct *tdf, *tdfb;
2404 struct per_thread_alloc_fct *taf, *tafb;
2405 struct per_thread_free_fct *tff, *tffb;
Tim Duesterhus34bef072020-07-04 11:49:50 +02002406 struct post_server_check_fct *pscf, *pscfb;
Tim Duesterhusfc854942020-09-10 19:46:42 +02002407 struct post_check_fct *pcf, *pcfb;
Tim Duesterhus53508d62020-09-10 19:46:40 +02002408 struct post_proxy_check_fct *ppcf, *ppcfb;
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002409 int cur_fd;
2410
2411 /* At this point the listeners state is weird:
2412 * - most listeners are still bound and referenced in their protocol
2413 * - some might be zombies that are not in their proto anymore, but
2414 * still appear in their proxy's listeners with a valid FD.
2415 * - some might be stopped and still appear in their proxy as FD #-1
2416 * - among all of them, some might be inherited hence shared and we're
2417 * not allowed to pause them or whatever, we must just close them.
2418 * - finally some are not listeners (pipes, logs, stdout, etc) and
2419 * must be left intact.
2420 *
2421 * The safe way to proceed is to unbind (and close) whatever is not yet
2422 * unbound so that no more receiver/listener remains alive. Then close
2423 * remaining listener FDs, which correspond to zombie listeners (those
2424 * belonging to disabled proxies that were in another process).
2425 * objt_listener() would be cleaner here but not converted yet.
2426 */
2427 protocol_unbind_all();
2428
2429 for (cur_fd = 0; cur_fd < global.maxsock; cur_fd++) {
Willy Tarreau1a3770c2020-10-14 12:13:51 +02002430 if (!fdtab || !fdtab[cur_fd].owner)
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002431 continue;
2432
Willy Tarreaua74cb382020-10-15 21:29:49 +02002433 if (fdtab[cur_fd].iocb == &sock_accept_iocb) {
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002434 struct listener *l = fdtab[cur_fd].owner;
2435
2436 BUG_ON(l->state != LI_INIT);
2437 unbind_listener(l);
2438 }
2439 }
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002440
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002441 deinit_signals();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002442 while (p) {
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002443 /* build a list of unique uri_auths */
2444 if (!ua)
2445 ua = p->uri_auth;
2446 else {
2447 /* check if p->uri_auth is unique */
2448 for (uap = ua; uap; uap=uap->next)
2449 if (uap == p->uri_auth)
2450 break;
2451
Willy Tarreauaccc4e12008-06-24 11:14:45 +02002452 if (!uap && p->uri_auth) {
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002453 /* add it, if it is */
2454 p->uri_auth->next = ua;
2455 ua = p->uri_auth;
2456 }
William Lallemand0f99e342011-10-12 17:50:54 +02002457 }
2458
Willy Tarreau4d2d0982007-05-14 00:39:29 +02002459 p0 = p;
Willy Tarreaubaaee002006-06-26 02:48:02 +02002460 p = p->next;
Amaury Denoyelle27fefa12021-03-24 16:13:20 +01002461 free_proxy(p0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002462 }/* end while(p) */
Willy Tarreaudd815982007-10-16 12:25:14 +02002463
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002464 while (ua) {
Tim Duesterhus00f00cf2020-09-10 19:46:38 +02002465 struct stat_scope *scope, *scopep;
2466
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002467 uap = ua;
2468 ua = ua->next;
2469
Willy Tarreaua534fea2008-08-03 12:19:50 +02002470 free(uap->uri_prefix);
2471 free(uap->auth_realm);
Krzysztof Piotr Oledzki48cb2ae2009-10-02 22:51:14 +02002472 free(uap->node);
2473 free(uap->desc);
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002474
Krzysztof Piotr Oledzki8c8bd452010-01-29 19:29:32 +01002475 userlist_free(uap->userlist);
Amaury Denoyelle68fd7e42021-03-25 17:15:52 +01002476 free_act_rules(&uap->http_req_rules);
Krzysztof Piotr Oledzki8c8bd452010-01-29 19:29:32 +01002477
Tim Duesterhus00f00cf2020-09-10 19:46:38 +02002478 scope = uap->scope;
2479 while (scope) {
2480 scopep = scope;
2481 scope = scope->next;
2482
2483 free(scopep->px_id);
2484 free(scopep);
2485 }
2486
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002487 free(uap);
2488 }
2489
Krzysztof Piotr Oledzki96105042010-01-29 17:50:44 +01002490 userlist_free(userlist);
2491
David Carlier834cb2e2015-09-25 12:02:25 +01002492 cfg_unregister_sections();
2493
Christopher Faulet0132d062017-07-26 15:33:35 +02002494 deinit_log_buffers();
David Carlier834cb2e2015-09-25 12:02:25 +01002495
Willy Tarreau05554e62016-12-21 20:46:26 +01002496 list_for_each_entry(pdf, &post_deinit_list, list)
2497 pdf->fct();
2498
Willy Tarreau61cfdf42021-02-20 10:46:51 +01002499 ha_free(&global.log_send_hostname);
Dragan Dosen43885c72015-10-01 13:18:13 +02002500 chunk_destroy(&global.log_tag);
Willy Tarreau61cfdf42021-02-20 10:46:51 +01002501 ha_free(&global.chroot);
2502 ha_free(&global.pidfile);
2503 ha_free(&global.node);
2504 ha_free(&global.desc);
2505 ha_free(&oldpids);
2506 ha_free(&old_argv);
2507 ha_free(&localpeer);
2508 ha_free(&global.server_state_base);
2509 ha_free(&global.server_state_file);
Olivier Houchard3f795f72019-04-17 22:51:06 +02002510 task_destroy(idle_conn_task);
Olivier Houchard9ea5d362019-02-14 18:29:09 +01002511 idle_conn_task = NULL;
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002512
William Lallemand0f99e342011-10-12 17:50:54 +02002513 list_for_each_entry_safe(log, logb, &global.logsrvs, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002514 LIST_DELETE(&log->list);
Amaury Denoyelled688e012021-04-20 17:05:47 +02002515 free(log->conf.file);
William Lallemand0f99e342011-10-12 17:50:54 +02002516 free(log);
2517 }
Willy Tarreau477ecd82010-01-03 21:12:30 +01002518 list_for_each_entry_safe(wl, wlb, &cfg_cfgfiles, list) {
Maxime de Roucy0f503922016-05-13 23:52:55 +02002519 free(wl->s);
Willy Tarreau2b718102021-04-21 07:32:39 +02002520 LIST_DELETE(&wl->list);
Willy Tarreau477ecd82010-01-03 21:12:30 +01002521 free(wl);
2522 }
2523
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002524 list_for_each_entry_safe(bol, bolb, &build_opts_list, list) {
2525 if (bol->must_free)
2526 free((void *)bol->str);
Willy Tarreau2b718102021-04-21 07:32:39 +02002527 LIST_DELETE(&bol->list);
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002528 free(bol);
2529 }
2530
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002531 list_for_each_entry_safe(pxdf, pxdfb, &proxy_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002532 LIST_DELETE(&pxdf->list);
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002533 free(pxdf);
2534 }
2535
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002536 list_for_each_entry_safe(pdf, pdfb, &post_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002537 LIST_DELETE(&pdf->list);
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002538 free(pdf);
2539 }
2540
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002541 list_for_each_entry_safe(srvdf, srvdfb, &server_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002542 LIST_DELETE(&srvdf->list);
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002543 free(srvdf);
2544 }
2545
Tim Duesterhusfc854942020-09-10 19:46:42 +02002546 list_for_each_entry_safe(pcf, pcfb, &post_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002547 LIST_DELETE(&pcf->list);
Tim Duesterhusfc854942020-09-10 19:46:42 +02002548 free(pcf);
2549 }
2550
Tim Duesterhus34bef072020-07-04 11:49:50 +02002551 list_for_each_entry_safe(pscf, pscfb, &post_server_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002552 LIST_DELETE(&pscf->list);
Tim Duesterhus34bef072020-07-04 11:49:50 +02002553 free(pscf);
2554 }
2555
Tim Duesterhus53508d62020-09-10 19:46:40 +02002556 list_for_each_entry_safe(ppcf, ppcfb, &post_proxy_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002557 LIST_DELETE(&ppcf->list);
Tim Duesterhus53508d62020-09-10 19:46:40 +02002558 free(ppcf);
2559 }
2560
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002561 list_for_each_entry_safe(tif, tifb, &per_thread_init_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002562 LIST_DELETE(&tif->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002563 free(tif);
2564 }
2565
2566 list_for_each_entry_safe(tdf, tdfb, &per_thread_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002567 LIST_DELETE(&tdf->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002568 free(tdf);
2569 }
2570
2571 list_for_each_entry_safe(taf, tafb, &per_thread_alloc_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002572 LIST_DELETE(&taf->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002573 free(taf);
2574 }
2575
2576 list_for_each_entry_safe(tff, tffb, &per_thread_free_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002577 LIST_DELETE(&tff->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002578 free(tff);
2579 }
2580
Willy Tarreaucfc4f242021-05-08 11:41:28 +02002581 vars_prune(&proc_vars, NULL, NULL);
Willy Tarreau2455ceb2018-11-26 15:57:34 +01002582 pool_destroy_all();
Krzysztof Piotr Oledzkia643baf2008-05-29 23:53:44 +02002583 deinit_pollers();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002584} /* end deinit() */
2585
Willy Tarreauf3ca5a02020-06-15 18:43:46 +02002586__attribute__((noreturn)) void deinit_and_exit(int status)
Tim Duesterhus26540552020-06-14 00:37:41 +02002587{
2588 deinit();
2589 exit(status);
2590}
William Lallemand72160322018-11-06 17:37:16 +01002591
Amaury Denoyelled3a88c12021-05-03 10:47:51 +02002592/* Handler of the task of mux_stopping_data.
2593 * Called on soft-stop.
2594 */
2595struct task *mux_stopping_process(struct task *t, void *ctx, unsigned int state)
2596{
2597 struct connection *conn, *back;
2598
2599 list_for_each_entry_safe(conn, back, &mux_stopping_data[tid].list, stopping_list) {
2600 if (conn->mux && conn->mux->wake)
2601 conn->mux->wake(conn);
2602 }
2603
2604 return t;
2605}
2606
Willy Tarreau918ff602011-07-25 16:33:49 +02002607/* Runs the polling loop */
Willy Tarreau3ebd55e2020-03-03 14:59:56 +01002608void run_poll_loop()
Willy Tarreau4f60f162007-04-08 16:39:58 +02002609{
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002610 int next, wake;
Willy Tarreau4f60f162007-04-08 16:39:58 +02002611
Amaury Denoyelled3a88c12021-05-03 10:47:51 +02002612 /* allocates the thread bound mux_stopping_data task */
2613 mux_stopping_data[tid].task = task_new(tid_bit);
2614 mux_stopping_data[tid].task->process = mux_stopping_process;
2615 LIST_INIT(&mux_stopping_data[tid].list);
2616
Willy Tarreaub0b37bc2008-06-23 14:00:57 +02002617 tv_update_date(0,1);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002618 while (1) {
Willy Tarreauc49ba522019-12-11 08:12:23 +01002619 wake_expired_tasks();
2620
William Lallemand1aab50b2018-06-07 09:46:01 +02002621 /* check if we caught some signals and process them in the
2622 first thread */
Willy Tarreaua7ad4ae2020-06-19 12:06:34 +02002623 if (signal_queue_len && tid == 0) {
2624 activity[tid].wake_signal++;
William Lallemand1aab50b2018-06-07 09:46:01 +02002625 signal_process_queue();
Willy Tarreaua7ad4ae2020-06-19 12:06:34 +02002626 }
2627
2628 /* Process a few tasks */
2629 process_runnable_tasks();
Willy Tarreau29857942009-05-10 09:01:21 +02002630
Willy Tarreau7067b3a2019-06-02 11:11:29 +02002631 /* also stop if we failed to cleanly stop all tasks */
2632 if (killed > 1)
2633 break;
2634
Willy Tarreau10146c92015-04-13 20:44:19 +02002635 /* expire immediately if events are pending */
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002636 wake = 1;
Olivier Houchard305d5ab2019-07-24 18:07:06 +02002637 if (thread_has_tasks())
Willy Tarreaud80cb4e2018-01-20 19:30:13 +01002638 activity[tid].wake_tasks++;
Olivier Houchard79321b92018-07-26 17:55:11 +02002639 else {
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002640 _HA_ATOMIC_OR(&sleeping_thread_mask, tid_bit);
2641 __ha_barrier_atomic_store();
Willy Tarreau95abd5b2020-03-23 09:33:32 +01002642 if (thread_has_tasks()) {
Olivier Houchard79321b92018-07-26 17:55:11 +02002643 activity[tid].wake_tasks++;
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002644 _HA_ATOMIC_AND(&sleeping_thread_mask, ~tid_bit);
Olivier Houchard79321b92018-07-26 17:55:11 +02002645 } else
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002646 wake = 0;
Olivier Houchard79321b92018-07-26 17:55:11 +02002647 }
Willy Tarreau10146c92015-04-13 20:44:19 +02002648
Willy Tarreau4f46a352020-03-23 09:27:28 +01002649 if (!wake) {
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002650 int i;
2651
2652 if (stopping) {
Ilya Shipitsin3df59892021-05-10 12:50:00 +05002653 /* stop muxes before acknowledging stopping */
Amaury Denoyelled3a88c12021-05-03 10:47:51 +02002654 if (!(stopping_thread_mask & tid_bit)) {
2655 task_wakeup(mux_stopping_data[tid].task, TASK_WOKEN_OTHER);
2656 wake = 1;
2657 }
2658
Willy Tarreau1db42732021-04-06 11:44:07 +02002659 if (_HA_ATOMIC_OR_FETCH(&stopping_thread_mask, tid_bit) == tid_bit) {
Willy Tarreaud6455742020-05-13 14:30:25 +02002660 /* notify all threads that stopping was just set */
2661 for (i = 0; i < global.nbthread; i++)
Willy Tarreau369a2ef2020-06-29 19:23:19 +02002662 if (((all_threads_mask & ~stopping_thread_mask) >> i) & 1)
Willy Tarreaud6455742020-05-13 14:30:25 +02002663 wake_thread(i);
2664 }
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002665 }
Willy Tarreau4f46a352020-03-23 09:27:28 +01002666
2667 /* stop when there's nothing left to do */
2668 if ((jobs - unstoppable_jobs) == 0 &&
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002669 (stopping_thread_mask & all_threads_mask) == all_threads_mask) {
2670 /* wake all threads waiting on jobs==0 */
2671 for (i = 0; i < global.nbthread; i++)
2672 if (((all_threads_mask & ~tid_bit) >> i) & 1)
2673 wake_thread(i);
Willy Tarreau4f46a352020-03-23 09:27:28 +01002674 break;
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002675 }
Willy Tarreau4f46a352020-03-23 09:27:28 +01002676 }
2677
Willy Tarreauc49ba522019-12-11 08:12:23 +01002678 /* If we have to sleep, measure how long */
2679 next = wake ? TICK_ETERNITY : next_timer_expiry();
2680
Willy Tarreau58b458d2008-06-29 22:40:23 +02002681 /* The poller will ensure it returns around <next> */
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002682 cur_poller.poll(&cur_poller, next, wake);
Emeric Brun64cc49c2017-10-03 14:46:45 +02002683
Willy Tarreaud80cb4e2018-01-20 19:30:13 +01002684 activity[tid].loops++;
Willy Tarreau4f60f162007-04-08 16:39:58 +02002685 }
Amaury Denoyelled3a88c12021-05-03 10:47:51 +02002686
2687 task_destroy(mux_stopping_data[tid].task);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002688}
2689
Christopher Faulet1d17c102017-08-29 15:38:48 +02002690static void *run_thread_poll_loop(void *data)
2691{
Willy Tarreau082b6282019-05-22 14:42:12 +02002692 struct per_thread_alloc_fct *ptaf;
Christopher Faulet1d17c102017-08-29 15:38:48 +02002693 struct per_thread_init_fct *ptif;
2694 struct per_thread_deinit_fct *ptdf;
Willy Tarreau082b6282019-05-22 14:42:12 +02002695 struct per_thread_free_fct *ptff;
Willy Tarreau34a150c2019-06-11 09:16:41 +02002696 static int init_left = 0;
Willy Tarreauaf613e82020-06-05 08:40:51 +02002697 __decl_thread(static pthread_mutex_t init_mutex = PTHREAD_MUTEX_INITIALIZER);
2698 __decl_thread(static pthread_cond_t init_cond = PTHREAD_COND_INITIALIZER);
Christopher Faulet1d17c102017-08-29 15:38:48 +02002699
Willy Tarreaub4f7cc32019-05-03 09:27:30 +02002700 ha_set_tid((unsigned long)data);
Willy Tarreaud022e9c2019-09-24 08:25:15 +02002701 sched = &task_per_thread[tid];
Willy Tarreau91e6df02019-05-03 17:21:18 +02002702
Willy Tarreauf6178242019-05-21 19:46:58 +02002703#if (_POSIX_TIMERS > 0) && defined(_POSIX_THREAD_CPUTIME)
Willy Tarreau91e6df02019-05-03 17:21:18 +02002704#ifdef USE_THREAD
Willy Tarreau8323a372019-05-20 18:57:53 +02002705 pthread_getcpuclockid(pthread_self(), &ti->clock_id);
Willy Tarreau624dcbf2019-05-20 20:23:06 +02002706#else
Willy Tarreau8323a372019-05-20 18:57:53 +02002707 ti->clock_id = CLOCK_THREAD_CPUTIME_ID;
Willy Tarreau91e6df02019-05-03 17:21:18 +02002708#endif
Willy Tarreau663fda42019-05-21 15:14:08 +02002709#endif
Willy Tarreau6ec902a2019-06-07 14:41:11 +02002710 /* Now, initialize one thread init at a time. This is better since
2711 * some init code is a bit tricky and may release global resources
2712 * after reallocating them locally. This will also ensure there is
2713 * no race on file descriptors allocation.
2714 */
Willy Tarreau34a150c2019-06-11 09:16:41 +02002715#ifdef USE_THREAD
2716 pthread_mutex_lock(&init_mutex);
2717#endif
2718 /* The first thread must set the number of threads left */
2719 if (!init_left)
2720 init_left = global.nbthread;
2721 init_left--;
Willy Tarreau91e6df02019-05-03 17:21:18 +02002722
Willy Tarreauc4c80fb2021-04-11 15:00:34 +02002723 tv_init_thread_date();
Christopher Faulet1d17c102017-08-29 15:38:48 +02002724
Willy Tarreau082b6282019-05-22 14:42:12 +02002725 /* per-thread alloc calls performed here are not allowed to snoop on
2726 * other threads, so they are free to initialize at their own rhythm
2727 * as long as they act as if they were alone. None of them may rely
2728 * on resources initialized by the other ones.
2729 */
2730 list_for_each_entry(ptaf, &per_thread_alloc_list, list) {
2731 if (!ptaf->fct()) {
2732 ha_alert("failed to allocate resources for thread %u.\n", tid);
2733 exit(1);
2734 }
2735 }
2736
Willy Tarreau3078e9f2019-05-20 10:50:43 +02002737 /* per-thread init calls performed here are not allowed to snoop on
2738 * other threads, so they are free to initialize at their own rhythm
2739 * as long as they act as if they were alone.
2740 */
Christopher Faulet1d17c102017-08-29 15:38:48 +02002741 list_for_each_entry(ptif, &per_thread_init_list, list) {
2742 if (!ptif->fct()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002743 ha_alert("failed to initialize thread %u.\n", tid);
Christopher Faulet1d17c102017-08-29 15:38:48 +02002744 exit(1);
2745 }
2746 }
2747
Willy Tarreau71092822019-06-10 09:51:04 +02002748 /* enabling protocols will result in fd_insert() calls to be performed,
2749 * we want all threads to have already allocated their local fd tables
Willy Tarreau34a150c2019-06-11 09:16:41 +02002750 * before doing so, thus only the last thread does it.
Willy Tarreau71092822019-06-10 09:51:04 +02002751 */
Willy Tarreau34a150c2019-06-11 09:16:41 +02002752 if (init_left == 0)
Willy Tarreaue4d7c9d2019-06-10 10:14:52 +02002753 protocol_enable_all();
Willy Tarreau6ec902a2019-06-07 14:41:11 +02002754
Willy Tarreau34a150c2019-06-11 09:16:41 +02002755#ifdef USE_THREAD
2756 pthread_cond_broadcast(&init_cond);
2757 pthread_mutex_unlock(&init_mutex);
2758
2759 /* now wait for other threads to finish starting */
2760 pthread_mutex_lock(&init_mutex);
2761 while (init_left)
2762 pthread_cond_wait(&init_cond, &init_mutex);
2763 pthread_mutex_unlock(&init_mutex);
2764#endif
Willy Tarreau3078e9f2019-05-20 10:50:43 +02002765
Willy Tarreaua45a8b52019-12-06 16:31:45 +01002766#if defined(PR_SET_NO_NEW_PRIVS) && defined(USE_PRCTL)
2767 /* Let's refrain from using setuid executables. This way the impact of
2768 * an eventual vulnerability in a library remains limited. It may
2769 * impact external checks but who cares about them anyway ? In the
2770 * worst case it's possible to disable the option. Obviously we do this
2771 * in workers only. We can't hard-fail on this one as it really is
2772 * implementation dependent though we're interested in feedback, hence
2773 * the warning.
2774 */
2775 if (!(global.tune.options & GTUNE_INSECURE_SETUID) && !master) {
2776 static int warn_fail;
Willy Tarreau18515722021-04-06 11:57:41 +02002777 if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) == -1 && !_HA_ATOMIC_FETCH_ADD(&warn_fail, 1)) {
Willy Tarreaua45a8b52019-12-06 16:31:45 +01002778 ha_warning("Failed to disable setuid, please report to developers with detailed "
2779 "information about your operating system. You can silence this warning "
2780 "by adding 'insecure-setuid-wanted' in the 'global' section.\n");
2781 }
2782 }
2783#endif
2784
Willy Tarreaud96f1122019-12-03 07:07:36 +01002785#if defined(RLIMIT_NPROC)
2786 /* all threads have started, it's now time to prevent any new thread
2787 * or process from starting. Obviously we do this in workers only. We
2788 * can't hard-fail on this one as it really is implementation dependent
2789 * though we're interested in feedback, hence the warning.
2790 */
2791 if (!(global.tune.options & GTUNE_INSECURE_FORK) && !master) {
2792 struct rlimit limit = { .rlim_cur = 0, .rlim_max = 0 };
2793 static int warn_fail;
2794
Willy Tarreau18515722021-04-06 11:57:41 +02002795 if (setrlimit(RLIMIT_NPROC, &limit) == -1 && !_HA_ATOMIC_FETCH_ADD(&warn_fail, 1)) {
Willy Tarreaud96f1122019-12-03 07:07:36 +01002796 ha_warning("Failed to disable forks, please report to developers with detailed "
2797 "information about your operating system. You can silence this warning "
2798 "by adding 'insecure-fork-wanted' in the 'global' section.\n");
2799 }
2800 }
2801#endif
Christopher Faulet1d17c102017-08-29 15:38:48 +02002802 run_poll_loop();
2803
2804 list_for_each_entry(ptdf, &per_thread_deinit_list, list)
2805 ptdf->fct();
2806
Willy Tarreau082b6282019-05-22 14:42:12 +02002807 list_for_each_entry(ptff, &per_thread_free_list, list)
2808 ptff->fct();
2809
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002810#ifdef USE_THREAD
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002811 _HA_ATOMIC_AND(&all_threads_mask, ~tid_bit);
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002812 if (tid > 0)
2813 pthread_exit(NULL);
Christopher Faulet1d17c102017-08-29 15:38:48 +02002814#endif
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002815 return NULL;
2816}
Christopher Faulet1d17c102017-08-29 15:38:48 +02002817
William Dauchyf9af9d72019-11-17 15:47:16 +01002818/* set uid/gid depending on global settings */
2819static void set_identity(const char *program_name)
2820{
2821 if (global.gid) {
2822 if (getgroups(0, NULL) > 0 && setgroups(0, NULL) == -1)
2823 ha_warning("[%s.main()] Failed to drop supplementary groups. Using 'gid'/'group'"
2824 " without 'uid'/'user' is generally useless.\n", program_name);
2825
2826 if (setgid(global.gid) == -1) {
2827 ha_alert("[%s.main()] Cannot set gid %d.\n", program_name, global.gid);
2828 protocol_unbind_all();
2829 exit(1);
2830 }
2831 }
2832
2833 if (global.uid && setuid(global.uid) == -1) {
2834 ha_alert("[%s.main()] Cannot set uid %d.\n", program_name, global.uid);
2835 protocol_unbind_all();
2836 exit(1);
2837 }
2838}
2839
Willy Tarreaubaaee002006-06-26 02:48:02 +02002840int main(int argc, char **argv)
2841{
2842 int err, retry;
2843 struct rlimit limit;
Willy Tarreau269ab312012-09-05 08:02:48 +02002844 int pidfd = -1;
Willy Tarreaubaaee002006-06-26 02:48:02 +02002845
Olivier Houchard5fa300d2018-02-03 15:15:21 +01002846 setvbuf(stdout, NULL, _IONBF, 0);
Willy Tarreau5794fb02018-11-25 18:43:29 +01002847
Willy Tarreaubf696402019-03-01 10:09:28 +01002848 /* take a copy of initial limits before we possibly change them */
2849 getrlimit(RLIMIT_NOFILE, &limit);
Willy Tarreau2bd0f812020-10-13 15:36:08 +02002850
2851 if (limit.rlim_max == RLIM_INFINITY)
2852 limit.rlim_max = limit.rlim_cur;
Willy Tarreaubf696402019-03-01 10:09:28 +01002853 rlim_fd_cur_at_boot = limit.rlim_cur;
2854 rlim_fd_max_at_boot = limit.rlim_max;
2855
Willy Tarreau5794fb02018-11-25 18:43:29 +01002856 /* process all initcalls in order of potential dependency */
2857 RUN_INITCALLS(STG_PREPARE);
2858 RUN_INITCALLS(STG_LOCK);
2859 RUN_INITCALLS(STG_ALLOC);
2860 RUN_INITCALLS(STG_POOL);
2861 RUN_INITCALLS(STG_REGISTER);
2862 RUN_INITCALLS(STG_INIT);
2863
Emeric Bruncf20bf12010-10-22 16:06:11 +02002864 init(argc, argv);
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002865 signal_register_fct(SIGQUIT, dump, SIGQUIT);
2866 signal_register_fct(SIGUSR1, sig_soft_stop, SIGUSR1);
2867 signal_register_fct(SIGHUP, sig_dump_state, SIGHUP);
William Lallemand73b85e72017-06-01 17:38:51 +02002868 signal_register_fct(SIGUSR2, NULL, 0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002869
Willy Tarreaue437c442010-03-17 18:02:46 +01002870 /* Always catch SIGPIPE even on platforms which define MSG_NOSIGNAL.
2871 * Some recent FreeBSD setups report broken pipes, and MSG_NOSIGNAL
2872 * was defined there, so let's stay on the safe side.
Willy Tarreaubaaee002006-06-26 02:48:02 +02002873 */
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002874 signal_register_fct(SIGPIPE, NULL, 0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002875
Willy Tarreaudc23a922011-02-16 11:10:36 +01002876 /* ulimits */
2877 if (!global.rlimit_nofile)
2878 global.rlimit_nofile = global.maxsock;
2879
2880 if (global.rlimit_nofile) {
Willy Tarreaue5cfdac2019-03-01 10:32:05 +01002881 limit.rlim_cur = global.rlimit_nofile;
2882 limit.rlim_max = MAX(rlim_fd_max_at_boot, limit.rlim_cur);
2883
Willy Tarreaudc23a922011-02-16 11:10:36 +01002884 if (setrlimit(RLIMIT_NOFILE, &limit) == -1) {
Willy Tarreauef635472016-06-21 11:48:18 +02002885 getrlimit(RLIMIT_NOFILE, &limit);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002886 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2887 ha_alert("[%s.main()] Cannot raise FD limit to %d, limit is %d.\n",
2888 argv[0], global.rlimit_nofile, (int)limit.rlim_cur);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002889 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002890 }
2891 else {
2892 /* try to set it to the max possible at least */
2893 limit.rlim_cur = limit.rlim_max;
2894 if (setrlimit(RLIMIT_NOFILE, &limit) != -1)
2895 getrlimit(RLIMIT_NOFILE, &limit);
Willy Tarreau164dd0b2016-06-21 11:51:59 +02002896
William Dauchya5194602020-03-28 19:29:58 +01002897 ha_warning("[%s.main()] Cannot raise FD limit to %d, limit is %d.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002898 argv[0], global.rlimit_nofile, (int)limit.rlim_cur);
2899 global.rlimit_nofile = limit.rlim_cur;
2900 }
Willy Tarreaudc23a922011-02-16 11:10:36 +01002901 }
2902 }
2903
2904 if (global.rlimit_memmax) {
2905 limit.rlim_cur = limit.rlim_max =
Willy Tarreau70060452015-12-14 12:46:07 +01002906 global.rlimit_memmax * 1048576ULL;
Willy Tarreaudc23a922011-02-16 11:10:36 +01002907#ifdef RLIMIT_AS
2908 if (setrlimit(RLIMIT_AS, &limit) == -1) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01002909 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2910 ha_alert("[%s.main()] Cannot fix MEM limit to %d megs.\n",
2911 argv[0], global.rlimit_memmax);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002912 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002913 }
2914 else
William Dauchya5194602020-03-28 19:29:58 +01002915 ha_warning("[%s.main()] Cannot fix MEM limit to %d megs.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002916 argv[0], global.rlimit_memmax);
Willy Tarreaudc23a922011-02-16 11:10:36 +01002917 }
2918#else
2919 if (setrlimit(RLIMIT_DATA, &limit) == -1) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01002920 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2921 ha_alert("[%s.main()] Cannot fix MEM limit to %d megs.\n",
2922 argv[0], global.rlimit_memmax);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002923 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002924 }
2925 else
William Dauchya5194602020-03-28 19:29:58 +01002926 ha_warning("[%s.main()] Cannot fix MEM limit to %d megs.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002927 argv[0], global.rlimit_memmax);
Willy Tarreaudc23a922011-02-16 11:10:36 +01002928 }
2929#endif
2930 }
2931
Olivier Houchardf73629d2017-04-05 22:33:04 +02002932 if (old_unixsocket) {
William Lallemand85b0bd92017-06-01 17:38:53 +02002933 if (strcmp("/dev/null", old_unixsocket) != 0) {
Willy Tarreau42961742020-08-28 18:42:45 +02002934 if (sock_get_old_sockets(old_unixsocket) != 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002935 ha_alert("Failed to get the sockets from the old process!\n");
William Lallemand85b0bd92017-06-01 17:38:53 +02002936 if (!(global.mode & MODE_MWORKER))
2937 exit(1);
2938 }
Olivier Houchardf73629d2017-04-05 22:33:04 +02002939 }
2940 }
William Lallemand85b0bd92017-06-01 17:38:53 +02002941 get_cur_unixsocket();
2942
Willy Tarreaubaaee002006-06-26 02:48:02 +02002943 /* We will loop at most 100 times with 10 ms delay each time.
2944 * That's at most 1 second. We only send a signal to old pids
2945 * if we cannot grab at least one port.
2946 */
2947 retry = MAX_START_RETRIES;
2948 err = ERR_NONE;
2949 while (retry >= 0) {
2950 struct timeval w;
Willy Tarreaue91bff22020-09-02 11:11:43 +02002951 err = protocol_bind_all(retry == 0 || nb_oldpids == 0);
Willy Tarreaue13e9252007-12-20 23:05:50 +01002952 /* exit the loop on no error or fatal error */
2953 if ((err & (ERR_RETRYABLE|ERR_FATAL)) != ERR_RETRYABLE)
Willy Tarreaubaaee002006-06-26 02:48:02 +02002954 break;
Willy Tarreaubb545b42010-08-25 12:58:59 +02002955 if (nb_oldpids == 0 || retry == 0)
Willy Tarreaubaaee002006-06-26 02:48:02 +02002956 break;
2957
2958 /* FIXME-20060514: Solaris and OpenBSD do not support shutdown() on
2959 * listening sockets. So on those platforms, it would be wiser to
2960 * simply send SIGUSR1, which will not be undoable.
2961 */
Willy Tarreaubb545b42010-08-25 12:58:59 +02002962 if (tell_old_pids(SIGTTOU) == 0) {
2963 /* no need to wait if we can't contact old pids */
2964 retry = 0;
2965 continue;
2966 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02002967 /* give some time to old processes to stop listening */
2968 w.tv_sec = 0;
2969 w.tv_usec = 10*1000;
2970 select(0, NULL, NULL, NULL, &w);
2971 retry--;
2972 }
2973
Willy Tarreaue91bff22020-09-02 11:11:43 +02002974 /* Note: protocol_bind_all() sends an alert when it fails. */
Willy Tarreau0a3b9d92009-02-04 17:05:23 +01002975 if ((err & ~ERR_WARN) != ERR_NONE) {
Willy Tarreaue91bff22020-09-02 11:11:43 +02002976 ha_alert("[%s.main()] Some protocols failed to start their listeners! Exiting.\n", argv[0]);
Willy Tarreauf68da462009-06-09 14:36:00 +02002977 if (retry != MAX_START_RETRIES && nb_oldpids) {
2978 protocol_unbind_all(); /* cleanup everything we can */
Willy Tarreaubaaee002006-06-26 02:48:02 +02002979 tell_old_pids(SIGTTIN);
Willy Tarreauf68da462009-06-09 14:36:00 +02002980 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02002981 exit(1);
2982 }
2983
William Lallemand944e6192018-11-21 15:48:31 +01002984 if (!(global.mode & MODE_MWORKER_WAIT) && listeners == 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002985 ha_alert("[%s.main()] No enabled listener found (check for 'bind' directives) ! Exiting.\n", argv[0]);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002986 /* Note: we don't have to send anything to the old pids because we
2987 * never stopped them. */
2988 exit(1);
2989 }
2990
Willy Tarreaue91bff22020-09-02 11:11:43 +02002991 /* Ok, all listeners should now be bound, close any leftover sockets
Olivier Houchardf73629d2017-04-05 22:33:04 +02002992 * the previous process gave us, we don't need them anymore
2993 */
2994 while (xfer_sock_list != NULL) {
2995 struct xfer_sock_list *tmpxfer = xfer_sock_list->next;
2996 close(xfer_sock_list->fd);
2997 free(xfer_sock_list->iface);
2998 free(xfer_sock_list->namespace);
2999 free(xfer_sock_list);
3000 xfer_sock_list = tmpxfer;
3001 }
Willy Tarreaudd815982007-10-16 12:25:14 +02003002
Willy Tarreaubaaee002006-06-26 02:48:02 +02003003 /* prepare pause/play signals */
Willy Tarreau24f4efa2010-08-27 17:56:48 +02003004 signal_register_fct(SIGTTOU, sig_pause, SIGTTOU);
3005 signal_register_fct(SIGTTIN, sig_listen, SIGTTIN);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003006
Willy Tarreaubaaee002006-06-26 02:48:02 +02003007 /* MODE_QUIET can inhibit alerts and warnings below this line */
3008
PiBa-NL149a81a2017-12-25 21:03:31 +01003009 if (getenv("HAPROXY_MWORKER_REEXEC") != NULL) {
3010 /* either stdin/out/err are already closed or should stay as they are. */
3011 if ((global.mode & MODE_DAEMON)) {
3012 /* daemon mode re-executing, stdin/stdout/stderr are already closed so keep quiet */
3013 global.mode &= ~MODE_VERBOSE;
3014 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
3015 }
3016 } else {
3017 if ((global.mode & MODE_QUIET) && !(global.mode & MODE_VERBOSE)) {
3018 /* detach from the tty */
William Lallemande1340412017-12-28 16:09:36 +01003019 stdio_quiet(-1);
PiBa-NL149a81a2017-12-25 21:03:31 +01003020 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003021 }
3022
3023 /* open log & pid files before the chroot */
William Lallemand80293002017-11-06 11:00:03 +01003024 if ((global.mode & MODE_DAEMON || global.mode & MODE_MWORKER) && global.pidfile != NULL) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003025 unlink(global.pidfile);
3026 pidfd = open(global.pidfile, O_CREAT | O_WRONLY | O_TRUNC, 0644);
3027 if (pidfd < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003028 ha_alert("[%s.main()] Cannot create pidfile %s\n", argv[0], global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003029 if (nb_oldpids)
3030 tell_old_pids(SIGTTIN);
Willy Tarreaudd815982007-10-16 12:25:14 +02003031 protocol_unbind_all();
Willy Tarreaubaaee002006-06-26 02:48:02 +02003032 exit(1);
3033 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003034 }
3035
Willy Tarreaub38651a2007-03-24 17:24:39 +01003036 if ((global.last_checks & LSTCHK_NETADM) && global.uid) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003037 ha_alert("[%s.main()] Some configuration options require full privileges, so global.uid cannot be changed.\n"
3038 "", argv[0]);
Willy Tarreaudd815982007-10-16 12:25:14 +02003039 protocol_unbind_all();
Willy Tarreaub38651a2007-03-24 17:24:39 +01003040 exit(1);
3041 }
3042
Jackie Tapia749f74c2020-07-22 18:59:40 -05003043 /* If the user is not root, we'll still let them try the configuration
3044 * but we inform them that unexpected behaviour may occur.
Willy Tarreau4e30ed72009-02-04 18:02:48 +01003045 */
3046 if ((global.last_checks & LSTCHK_NETADM) && getuid())
Christopher Faulet767a84b2017-11-24 16:50:31 +01003047 ha_warning("[%s.main()] Some options which require full privileges"
3048 " might not work well.\n"
3049 "", argv[0]);
Willy Tarreau4e30ed72009-02-04 18:02:48 +01003050
William Lallemand095ba4c2017-06-01 17:38:50 +02003051 if ((global.mode & (MODE_MWORKER|MODE_DAEMON)) == 0) {
3052
3053 /* chroot if needed */
3054 if (global.chroot != NULL) {
3055 if (chroot(global.chroot) == -1 || chdir("/") == -1) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003056 ha_alert("[%s.main()] Cannot chroot(%s).\n", argv[0], global.chroot);
William Lallemand095ba4c2017-06-01 17:38:50 +02003057 if (nb_oldpids)
3058 tell_old_pids(SIGTTIN);
3059 protocol_unbind_all();
3060 exit(1);
3061 }
Willy Tarreauf223cc02007-10-15 18:57:08 +02003062 }
Willy Tarreauf223cc02007-10-15 18:57:08 +02003063 }
3064
William Lallemand944e6192018-11-21 15:48:31 +01003065 if (nb_oldpids && !(global.mode & MODE_MWORKER_WAIT))
Willy Tarreaubb545b42010-08-25 12:58:59 +02003066 nb_oldpids = tell_old_pids(oldpids_sig);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003067
William Lallemand27edc4b2019-05-07 17:49:33 +02003068 /* send a SIGTERM to workers who have a too high reloads number */
3069 if ((global.mode & MODE_MWORKER) && !(global.mode & MODE_MWORKER_WAIT))
3070 mworker_kill_max_reloads(SIGTERM);
3071
Willy Tarreaubaaee002006-06-26 02:48:02 +02003072 /* Note that any error at this stage will be fatal because we will not
3073 * be able to restart the old pids.
3074 */
3075
William Dauchyf9af9d72019-11-17 15:47:16 +01003076 if ((global.mode & (MODE_MWORKER | MODE_DAEMON)) == 0)
3077 set_identity(argv[0]);
Willy Tarreau636848a2019-04-15 19:38:50 +02003078
Willy Tarreaubaaee002006-06-26 02:48:02 +02003079 /* check ulimits */
3080 limit.rlim_cur = limit.rlim_max = 0;
3081 getrlimit(RLIMIT_NOFILE, &limit);
3082 if (limit.rlim_cur < global.maxsock) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01003083 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3084 ha_alert("[%s.main()] FD limit (%d) too low for maxconn=%d/maxsock=%d. "
3085 "Please raise 'ulimit-n' to %d or more to avoid any trouble.\n",
3086 argv[0], (int)limit.rlim_cur, global.maxconn, global.maxsock,
3087 global.maxsock);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003088 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01003089 }
3090 else
3091 ha_alert("[%s.main()] FD limit (%d) too low for maxconn=%d/maxsock=%d. "
William Dauchya5194602020-03-28 19:29:58 +01003092 "Please raise 'ulimit-n' to %d or more to avoid any trouble.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01003093 argv[0], (int)limit.rlim_cur, global.maxconn, global.maxsock,
3094 global.maxsock);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003095 }
3096
William Lallemand944e6192018-11-21 15:48:31 +01003097 if (global.mode & (MODE_DAEMON | MODE_MWORKER | MODE_MWORKER_WAIT)) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003098 int ret = 0;
Willy Tarreaud67ff342021-06-15 07:58:09 +02003099 int in_parent = 0;
William Lallemande1340412017-12-28 16:09:36 +01003100 int devnullfd = -1;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003101
William Lallemand095ba4c2017-06-01 17:38:50 +02003102 /*
3103 * if daemon + mworker: must fork here to let a master
3104 * process live in background before forking children
3105 */
William Lallemand73b85e72017-06-01 17:38:51 +02003106
3107 if ((getenv("HAPROXY_MWORKER_REEXEC") == NULL)
3108 && (global.mode & MODE_MWORKER)
3109 && (global.mode & MODE_DAEMON)) {
William Lallemand095ba4c2017-06-01 17:38:50 +02003110 ret = fork();
3111 if (ret < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003112 ha_alert("[%s.main()] Cannot fork.\n", argv[0]);
William Lallemand095ba4c2017-06-01 17:38:50 +02003113 protocol_unbind_all();
3114 exit(1); /* there has been an error */
William Lallemandbfd8eb52018-07-04 15:31:23 +02003115 } else if (ret > 0) { /* parent leave to daemonize */
William Lallemand095ba4c2017-06-01 17:38:50 +02003116 exit(0);
William Lallemandbfd8eb52018-07-04 15:31:23 +02003117 } else /* change the process group ID in the child (master process) */
3118 setsid();
William Lallemand095ba4c2017-06-01 17:38:50 +02003119 }
William Lallemande20b6a62017-06-01 17:38:55 +02003120
William Lallemande20b6a62017-06-01 17:38:55 +02003121
William Lallemanddeed7802017-11-06 11:00:04 +01003122 /* if in master-worker mode, write the PID of the father */
3123 if (global.mode & MODE_MWORKER) {
3124 char pidstr[100];
Willy Tarreau76a80c72019-06-22 07:41:38 +02003125 snprintf(pidstr, sizeof(pidstr), "%d\n", (int)getpid());
Willy Tarreau46ec48b2018-01-23 19:20:19 +01003126 if (pidfd >= 0)
Willy Tarreau2e8ab6b2020-03-14 11:03:20 +01003127 DISGUISE(write(pidfd, pidstr, strlen(pidstr)));
William Lallemanddeed7802017-11-06 11:00:04 +01003128 }
3129
Willy Tarreaubaaee002006-06-26 02:48:02 +02003130 /* the father launches the required number of processes */
William Lallemand944e6192018-11-21 15:48:31 +01003131 if (!(global.mode & MODE_MWORKER_WAIT)) {
William Lallemand9a1ee7a2019-04-01 11:30:02 +02003132 if (global.mode & MODE_MWORKER)
3133 mworker_ext_launch_all();
Willy Tarreaud67ff342021-06-15 07:58:09 +02003134
3135 ret = fork();
3136 if (ret < 0) {
3137 ha_alert("[%s.main()] Cannot fork.\n", argv[0]);
3138 protocol_unbind_all();
3139 exit(1); /* there has been an error */
3140 }
3141 else if (ret == 0) { /* child breaks here */
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003142 ha_random_jump96(1);
Willy Tarreaud67ff342021-06-15 07:58:09 +02003143 }
3144 else { /* parent here */
3145 in_parent = 1;
3146
William Lallemand944e6192018-11-21 15:48:31 +01003147 if (pidfd >= 0 && !(global.mode & MODE_MWORKER)) {
3148 char pidstr[100];
3149 snprintf(pidstr, sizeof(pidstr), "%d\n", ret);
Willy Tarreau2e8ab6b2020-03-14 11:03:20 +01003150 DISGUISE(write(pidfd, pidstr, strlen(pidstr)));
William Lallemand944e6192018-11-21 15:48:31 +01003151 }
3152 if (global.mode & MODE_MWORKER) {
3153 struct mworker_proc *child;
William Lallemandce83b4a2018-10-26 14:47:30 +02003154
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003155 ha_notice("New worker #%d (%d) forked\n", 1, ret);
William Lallemand944e6192018-11-21 15:48:31 +01003156 /* find the right mworker_proc */
3157 list_for_each_entry(child, &proc_list, list) {
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003158 if (child->reloads == 0 && child->options & PROC_O_TYPE_WORKER) {
William Lallemand944e6192018-11-21 15:48:31 +01003159 child->timestamp = now.tv_sec;
3160 child->pid = ret;
William Lallemand1dc69632019-06-12 19:11:33 +02003161 child->version = strdup(haproxy_version);
William Lallemand944e6192018-11-21 15:48:31 +01003162 break;
3163 }
William Lallemandce83b4a2018-10-26 14:47:30 +02003164 }
3165 }
William Lallemand944e6192018-11-21 15:48:31 +01003166 }
Willy Tarreaud67ff342021-06-15 07:58:09 +02003167
William Lallemand944e6192018-11-21 15:48:31 +01003168 } else {
3169 /* wait mode */
Willy Tarreaud67ff342021-06-15 07:58:09 +02003170 in_parent = 1;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003171 }
Willy Tarreaufc6c0322012-11-16 16:12:27 +01003172
3173#ifdef USE_CPU_AFFINITY
Willy Tarreau44ea6312021-06-15 08:57:56 +02003174 if (!in_parent && ha_cpuset_count(&cpu_map.proc)) { /* only do this if the process has a CPU map */
Olivier Houchard97148f62017-08-16 17:29:11 +02003175
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003176#ifdef __FreeBSD__
Willy Tarreau44ea6312021-06-15 08:57:56 +02003177 struct hap_cpuset *set = &cpu_map.proc;
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003178 ret = cpuset_setaffinity(CPU_LEVEL_WHICH, CPU_WHICH_PID, -1, sizeof(set->cpuset), &set->cpuset);
David Carlier2d0493a2020-12-02 21:14:51 +00003179#elif defined(__linux__) || defined(__DragonFly__)
Willy Tarreau44ea6312021-06-15 08:57:56 +02003180 struct hap_cpuset *set = &cpu_map.proc;
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003181 sched_setaffinity(0, sizeof(set->cpuset), &set->cpuset);
Willy Tarreaufc6c0322012-11-16 16:12:27 +01003182#endif
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003183 }
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +02003184#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +02003185 /* close the pidfile both in children and father */
Willy Tarreau269ab312012-09-05 08:02:48 +02003186 if (pidfd >= 0) {
3187 //lseek(pidfd, 0, SEEK_SET); /* debug: emulate eglibc bug */
3188 close(pidfd);
3189 }
Willy Tarreaud137dd32010-08-25 12:49:05 +02003190
3191 /* We won't ever use this anymore */
Willy Tarreau61cfdf42021-02-20 10:46:51 +01003192 ha_free(&global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003193
Willy Tarreaud67ff342021-06-15 07:58:09 +02003194 if (in_parent) {
William Lallemand944e6192018-11-21 15:48:31 +01003195 if (global.mode & (MODE_MWORKER|MODE_MWORKER_WAIT)) {
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003196
3197 if ((!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE)) &&
3198 (global.mode & MODE_DAEMON)) {
3199 /* detach from the tty, this is required to properly daemonize. */
William Lallemande1340412017-12-28 16:09:36 +01003200 if ((getenv("HAPROXY_MWORKER_REEXEC") == NULL))
3201 stdio_quiet(-1);
3202
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003203 global.mode &= ~MODE_VERBOSE;
3204 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003205 }
3206
William Lallemandb3f2be32018-09-11 10:06:18 +02003207 mworker_loop();
William Lallemand1499b9b2017-06-07 15:04:47 +02003208 /* should never get there */
3209 exit(EXIT_FAILURE);
Willy Tarreauedaff0a2015-05-01 17:01:08 +02003210 }
William Lallemandcf4e4962017-06-08 19:05:48 +02003211#if defined(USE_OPENSSL) && !defined(OPENSSL_NO_DH)
Grant Zhang872f9c22017-01-21 01:10:18 +00003212 ssl_free_dh();
3213#endif
William Lallemand1499b9b2017-06-07 15:04:47 +02003214 exit(0); /* parent must leave */
Willy Tarreauedaff0a2015-05-01 17:01:08 +02003215 }
3216
William Lallemandcb11fd22017-06-01 17:38:52 +02003217 /* child must never use the atexit function */
3218 atexit_flag = 0;
3219
William Lallemandbc193052018-09-11 10:06:26 +02003220 /* close useless master sockets */
3221 if (global.mode & MODE_MWORKER) {
3222 struct mworker_proc *child, *it;
3223 master = 0;
3224
William Lallemand309dc9a2018-10-26 14:47:45 +02003225 mworker_cli_proxy_stop();
3226
William Lallemandbc193052018-09-11 10:06:26 +02003227 /* free proc struct of other processes */
3228 list_for_each_entry_safe(child, it, &proc_list, list) {
William Lallemandce83b4a2018-10-26 14:47:30 +02003229 /* close the FD of the master side for all
3230 * workers, we don't need to close the worker
3231 * side of other workers since it's done with
3232 * the bind_proc */
Tim Duesterhus742e0f92018-11-25 20:03:39 +01003233 if (child->ipc_fd[0] >= 0)
3234 close(child->ipc_fd[0]);
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003235 if (child->options & PROC_O_TYPE_WORKER &&
William Lallemandce83b4a2018-10-26 14:47:30 +02003236 child->reloads == 0) {
3237 /* keep this struct if this is our pid */
3238 proc_self = child;
William Lallemandbc193052018-09-11 10:06:26 +02003239 continue;
William Lallemandce83b4a2018-10-26 14:47:30 +02003240 }
Willy Tarreau2b718102021-04-21 07:32:39 +02003241 LIST_DELETE(&child->list);
Tim Duesterhus9b7a9762019-05-16 20:23:22 +02003242 mworker_free_child(child);
3243 child = NULL;
William Lallemandbc193052018-09-11 10:06:26 +02003244 }
3245 }
Willy Tarreau1605c7a2018-01-23 19:01:49 +01003246
William Lallemande1340412017-12-28 16:09:36 +01003247 if (!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE)) {
3248 devnullfd = open("/dev/null", O_RDWR, 0);
3249 if (devnullfd < 0) {
3250 ha_alert("Cannot open /dev/null\n");
3251 exit(EXIT_FAILURE);
3252 }
3253 }
3254
William Lallemand095ba4c2017-06-01 17:38:50 +02003255 /* Must chroot and setgid/setuid in the children */
3256 /* chroot if needed */
3257 if (global.chroot != NULL) {
3258 if (chroot(global.chroot) == -1 || chdir("/") == -1) {
Willy Tarreaue34cf282021-06-15 08:59:19 +02003259 ha_alert("[%s.main()] Cannot chroot(%s).\n", argv[0], global.chroot);
William Lallemand095ba4c2017-06-01 17:38:50 +02003260 if (nb_oldpids)
3261 tell_old_pids(SIGTTIN);
3262 protocol_unbind_all();
3263 exit(1);
3264 }
3265 }
3266
Willy Tarreau61cfdf42021-02-20 10:46:51 +01003267 ha_free(&global.chroot);
William Dauchyf9af9d72019-11-17 15:47:16 +01003268 set_identity(argv[0]);
William Lallemand095ba4c2017-06-01 17:38:50 +02003269
William Lallemand7f80eb22017-05-26 18:19:55 +02003270 /* pass through every cli socket, and check if it's bound to
3271 * the current process and if it exposes listeners sockets.
3272 * Caution: the GTUNE_SOCKET_TRANSFER is now set after the fork.
3273 * */
3274
Willy Tarreau4975d142021-03-13 11:00:33 +01003275 if (global.cli_fe) {
William Lallemand7f80eb22017-05-26 18:19:55 +02003276 struct bind_conf *bind_conf;
3277
Willy Tarreau4975d142021-03-13 11:00:33 +01003278 list_for_each_entry(bind_conf, &global.cli_fe->conf.bind, by_fe) {
William Lallemand7f80eb22017-05-26 18:19:55 +02003279 if (bind_conf->level & ACCESS_FD_LISTENERS) {
Willy Tarreau72faef32021-06-15 08:36:30 +02003280 global.tune.options |= GTUNE_SOCKET_TRANSFER;
3281 break;
William Lallemand7f80eb22017-05-26 18:19:55 +02003282 }
3283 }
Willy Tarreauf83d3fe2015-05-01 19:13:41 +02003284 }
3285
William Lallemand2e8fad92018-11-13 16:18:23 +01003286 /*
3287 * This is only done in daemon mode because we might want the
3288 * logs on stdout in mworker mode. If we're NOT in QUIET mode,
3289 * we should now close the 3 first FDs to ensure that we can
3290 * detach from the TTY. We MUST NOT do it in other cases since
3291 * it would have already be done, and 0-2 would have been
3292 * affected to listening sockets
Willy Tarreaubaaee002006-06-26 02:48:02 +02003293 */
William Lallemand2e8fad92018-11-13 16:18:23 +01003294 if ((global.mode & MODE_DAEMON) &&
3295 (!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE))) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003296 /* detach from the tty */
William Lallemande1340412017-12-28 16:09:36 +01003297 stdio_quiet(devnullfd);
Willy Tarreau106cb762008-11-16 07:40:34 +01003298 global.mode &= ~MODE_VERBOSE;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003299 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
3300 }
3301 pid = getpid(); /* update child's pid */
William Lallemandbfd8eb52018-07-04 15:31:23 +02003302 if (!(global.mode & MODE_MWORKER)) /* in mworker mode we don't want a new pgid for the children */
3303 setsid();
Willy Tarreau2ff76222007-04-09 19:29:56 +02003304 fork_poller();
Willy Tarreaubaaee002006-06-26 02:48:02 +02003305 }
3306
William Dauchye039f262019-11-17 15:47:15 +01003307 /* try our best to re-enable core dumps depending on system capabilities.
3308 * What is addressed here :
3309 * - remove file size limits
3310 * - remove core size limits
3311 * - mark the process dumpable again if it lost it due to user/group
3312 */
3313 if (global.tune.options & GTUNE_SET_DUMPABLE) {
3314 limit.rlim_cur = limit.rlim_max = RLIM_INFINITY;
3315
3316#if defined(RLIMIT_FSIZE)
3317 if (setrlimit(RLIMIT_FSIZE, &limit) == -1) {
3318 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3319 ha_alert("[%s.main()] Failed to set the raise the maximum "
3320 "file size.\n", argv[0]);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003321 exit(1);
William Dauchye039f262019-11-17 15:47:15 +01003322 }
3323 else
3324 ha_warning("[%s.main()] Failed to set the raise the maximum "
William Dauchya5194602020-03-28 19:29:58 +01003325 "file size.\n", argv[0]);
William Dauchye039f262019-11-17 15:47:15 +01003326 }
3327#endif
3328
3329#if defined(RLIMIT_CORE)
3330 if (setrlimit(RLIMIT_CORE, &limit) == -1) {
3331 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3332 ha_alert("[%s.main()] Failed to set the raise the core "
3333 "dump size.\n", argv[0]);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003334 exit(1);
William Dauchye039f262019-11-17 15:47:15 +01003335 }
3336 else
3337 ha_warning("[%s.main()] Failed to set the raise the core "
William Dauchya5194602020-03-28 19:29:58 +01003338 "dump size.\n", argv[0]);
William Dauchye039f262019-11-17 15:47:15 +01003339 }
3340#endif
3341
3342#if defined(USE_PRCTL)
3343 if (prctl(PR_SET_DUMPABLE, 1, 0, 0, 0) == -1)
3344 ha_warning("[%s.main()] Failed to set the dumpable flag, "
3345 "no core will be dumped.\n", argv[0]);
3346#endif
3347 }
3348
Christopher Faulete3a5e352017-10-24 13:53:54 +02003349 global.mode &= ~MODE_STARTING;
Amaury Denoyelle6af81f82021-05-27 15:45:28 +02003350 reset_usermsgs_ctx();
3351
Willy Tarreau4f60f162007-04-08 16:39:58 +02003352 /*
3353 * That's it : the central polling loop. Run until we stop.
3354 */
Christopher Faulet1d17c102017-08-29 15:38:48 +02003355#ifdef USE_THREAD
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003356 {
William Lallemand1aab50b2018-06-07 09:46:01 +02003357 sigset_t blocked_sig, old_sig;
Willy Tarreauc40efc12019-05-03 09:22:44 +02003358 int i;
3359
William Lallemand1aab50b2018-06-07 09:46:01 +02003360 /* ensure the signals will be blocked in every thread */
3361 sigfillset(&blocked_sig);
3362 sigdelset(&blocked_sig, SIGPROF);
3363 sigdelset(&blocked_sig, SIGBUS);
3364 sigdelset(&blocked_sig, SIGFPE);
3365 sigdelset(&blocked_sig, SIGILL);
3366 sigdelset(&blocked_sig, SIGSEGV);
3367 pthread_sigmask(SIG_SETMASK, &blocked_sig, &old_sig);
3368
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003369 /* Create nbthread-1 thread. The first thread is the current process */
David Carliera92c5ce2019-09-13 05:03:12 +01003370 ha_thread_info[0].pthread = pthread_self();
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003371 for (i = 1; i < global.nbthread; i++)
David Carliera92c5ce2019-09-13 05:03:12 +01003372 pthread_create(&ha_thread_info[i].pthread, NULL, &run_thread_poll_loop, (void *)(long)i);
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003373
Christopher Faulet62519022017-10-16 15:49:32 +02003374#ifdef USE_CPU_AFFINITY
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003375 /* Now the CPU affinity for all threads */
Amaury Denoyelleaf02c572021-04-15 16:29:58 +02003376
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003377 for (i = 0; i < global.nbthread; i++) {
Willy Tarreau44ea6312021-06-15 08:57:56 +02003378 if (ha_cpuset_count(&cpu_map.proc))
3379 ha_cpuset_and(&cpu_map.thread[i], &cpu_map.proc);
Christopher Faulet62519022017-10-16 15:49:32 +02003380
Willy Tarreau421f02e2018-01-20 18:19:22 +01003381 if (i < MAX_THREADS && /* only the first 32/64 threads may be pinned */
Amaury Denoyellefc6ac532021-04-27 10:46:36 +02003382 ha_cpuset_count(&cpu_map.thread[i])) {/* only do this if the thread has a THREAD map */
David Carlier5e4c8e22019-09-13 05:12:58 +01003383#if defined(__APPLE__)
3384 int j;
Amaury Denoyelle8f685c12021-04-27 16:45:29 +02003385 unsigned long set = cpu_map.thread[i].cpuset;
David Carlier5e4c8e22019-09-13 05:12:58 +01003386
Amaury Denoyelle8f685c12021-04-27 16:45:29 +02003387 while ((j = ffsl(set)) > 0) {
David Carlier5e4c8e22019-09-13 05:12:58 +01003388 thread_affinity_policy_data_t cpu_set = { j - 1 };
3389 thread_port_t mthread = pthread_mach_thread_np(ha_thread_info[i].pthread);
3390 thread_policy_set(mthread, THREAD_AFFINITY_POLICY, (thread_policy_t)&cpu_set, 1);
Amaury Denoyelle8f685c12021-04-27 16:45:29 +02003391 set &= ~(1UL << (j - 1));
David Carlier5e4c8e22019-09-13 05:12:58 +01003392 }
3393#else
Amaury Denoyellefc6ac532021-04-27 10:46:36 +02003394 struct hap_cpuset *set = &cpu_map.thread[i];
David Carliera92c5ce2019-09-13 05:03:12 +01003395 pthread_setaffinity_np(ha_thread_info[i].pthread,
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003396 sizeof(set->cpuset), &set->cpuset);
David Carlier5e4c8e22019-09-13 05:12:58 +01003397#endif
Olivier Houchard829aa242017-12-01 18:19:43 +01003398 }
Christopher Faulet1d17c102017-08-29 15:38:48 +02003399 }
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003400#endif /* !USE_CPU_AFFINITY */
3401
William Lallemand1aab50b2018-06-07 09:46:01 +02003402 /* when multithreading we need to let only the thread 0 handle the signals */
William Lallemandd3801c12018-09-11 10:06:23 +02003403 haproxy_unblock_signals();
William Lallemand1aab50b2018-06-07 09:46:01 +02003404
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003405 /* Finally, start the poll loop for the first thread */
Willy Tarreaub4f7cc32019-05-03 09:27:30 +02003406 run_thread_poll_loop(0);
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003407
3408 /* Wait the end of other threads */
3409 for (i = 1; i < global.nbthread; i++)
David Carliera92c5ce2019-09-13 05:03:12 +01003410 pthread_join(ha_thread_info[i].pthread, NULL);
Christopher Faulet1d17c102017-08-29 15:38:48 +02003411
Christopher Fauletb79a94c2017-05-30 15:34:30 +02003412#if defined(DEBUG_THREAD) || defined(DEBUG_FULL)
3413 show_lock_stats();
3414#endif
Christopher Faulet1d17c102017-08-29 15:38:48 +02003415 }
Christopher Fauletcd7879a2017-10-27 13:53:47 +02003416#else /* ! USE_THREAD */
William Lallemandd3801c12018-09-11 10:06:23 +02003417 haproxy_unblock_signals();
Willy Tarreaub4f7cc32019-05-03 09:27:30 +02003418 run_thread_poll_loop(0);
Christopher Faulet62519022017-10-16 15:49:32 +02003419#endif
Christopher Faulet1d17c102017-08-29 15:38:48 +02003420
Tim Duesterhus0a3b43d2020-06-14 00:37:42 +02003421 deinit_and_exit(0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003422}
3423
Willy Tarreaubaaee002006-06-26 02:48:02 +02003424/*
3425 * Local variables:
3426 * c-indent-level: 8
3427 * c-basic-offset: 8
3428 * End:
3429 */