blob: a6b8dc3adf52e9e9f400e16623d01b0d476ec40d [file] [log] [blame]
Willy Tarreaubaaee002006-06-26 02:48:02 +02001/*
Willy Tarreaua5357cd2021-05-09 06:14:25 +02002 * HAProxy : High Availability-enabled HTTP/TCP proxy
Willy Tarreau421ed392021-01-06 17:41:32 +01003 * Copyright 2000-2021 Willy Tarreau <willy@haproxy.org>.
Willy Tarreaubaaee002006-06-26 02:48:02 +02004 *
5 * This program is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU General Public License
7 * as published by the Free Software Foundation; either version
8 * 2 of the License, or (at your option) any later version.
9 *
Ilya Shipitsin46a030c2020-07-05 16:36:08 +050010 * Please refer to RFC7230 - RFC7235 information about HTTP protocol, and
11 * RFC6265 for information about cookies usage. More generally, the IETF HTTP
Willy Tarreaubaaee002006-06-26 02:48:02 +020012 * Working Group's web site should be consulted for protocol related changes :
13 *
14 * http://ftp.ics.uci.edu/pub/ietf/http/
15 *
16 * Pending bugs (may be not fixed because never reproduced) :
17 * - solaris only : sometimes, an HTTP proxy with only a dispatch address causes
18 * the proxy to terminate (no core) if the client breaks the connection during
19 * the response. Seen on 1.1.8pre4, but never reproduced. May not be related to
20 * the snprintf() bug since requests were simple (GET / HTTP/1.0), but may be
21 * related to missing setsid() (fixed in 1.1.15)
22 * - a proxy with an invalid config will prevent the startup even if disabled.
23 *
24 * ChangeLog has moved to the CHANGELOG file.
25 *
Willy Tarreaubaaee002006-06-26 02:48:02 +020026 */
27
David Carlier7ece0962015-12-08 21:43:09 +000028#define _GNU_SOURCE
Willy Tarreaubaaee002006-06-26 02:48:02 +020029#include <stdio.h>
30#include <stdlib.h>
31#include <unistd.h>
32#include <string.h>
33#include <ctype.h>
Maxime de Roucy379d9c72016-05-13 23:52:56 +020034#include <dirent.h>
Maxime de Roucy379d9c72016-05-13 23:52:56 +020035#include <sys/stat.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020036#include <sys/time.h>
37#include <sys/types.h>
38#include <sys/socket.h>
39#include <netinet/tcp.h>
40#include <netinet/in.h>
41#include <arpa/inet.h>
42#include <netdb.h>
43#include <fcntl.h>
44#include <errno.h>
45#include <signal.h>
46#include <stdarg.h>
47#include <sys/resource.h>
Tim Duesterhusdfad6a42020-04-18 16:02:47 +020048#include <sys/utsname.h>
Marc-Antoine Perennou992709b2013-02-12 10:53:52 +010049#include <sys/wait.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +020050#include <time.h>
51#include <syslog.h>
Michael Schererab012dd2013-01-12 18:35:19 +010052#include <grp.h>
Willy Tarreaud10385a2021-10-06 22:22:40 +020053
Willy Tarreau5e03dfa2021-10-06 22:53:51 +020054#ifdef USE_THREAD
55#include <pthread.h>
56#endif
57
Willy Tarreaufc6c0322012-11-16 16:12:27 +010058#ifdef USE_CPU_AFFINITY
Willy Tarreaufc6c0322012-11-16 16:12:27 +010059#include <sched.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000060#if defined(__FreeBSD__) || defined(__DragonFly__)
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +020061#include <sys/param.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000062#ifdef __FreeBSD__
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +020063#include <sys/cpuset.h>
David Carlier42d9e5a2018-11-12 16:22:19 +000064#endif
David Carlier5e4c8e22019-09-13 05:12:58 +010065#endif
Willy Tarreaufc6c0322012-11-16 16:12:27 +010066#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +020067
Willy Tarreau636848a2019-04-15 19:38:50 +020068#if defined(USE_PRCTL)
69#include <sys/prctl.h>
70#endif
71
devnexen@gmail.com21185972021-08-21 09:13:10 +010072#if defined(USE_PROCCTL)
73#include <sys/procctl.h>
74#endif
75
Willy Tarreaubaaee002006-06-26 02:48:02 +020076#ifdef DEBUG_FULL
77#include <assert.h>
78#endif
Tim Duesterhusd6942c82017-11-20 15:58:35 +010079#if defined(USE_SYSTEMD)
80#include <systemd/sd-daemon.h>
81#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +020082
Willy Tarreau6c3a6812020-03-06 18:57:15 +010083#include <import/sha1.h>
84
Willy Tarreaub2551052020-06-09 09:07:15 +020085#include <haproxy/acl.h>
Amaury Denoyelle68fd7e42021-03-25 17:15:52 +010086#include <haproxy/action.h>
Willy Tarreaub2551052020-06-09 09:07:15 +020087#include <haproxy/activity.h>
88#include <haproxy/api.h>
89#include <haproxy/arg.h>
90#include <haproxy/auth.h>
Willy Tarreau8d366972020-05-27 16:10:29 +020091#include <haproxy/base64.h>
Willy Tarreaub2551052020-06-09 09:07:15 +020092#include <haproxy/capture-t.h>
Willy Tarreau66243b42021-07-16 15:39:28 +020093#include <haproxy/cfgcond.h>
Amaury Denoyelle5a6926d2021-03-30 17:34:24 +020094#include <haproxy/cfgdiag.h>
Willy Tarreau6be78492020-06-05 00:00:29 +020095#include <haproxy/cfgparse.h>
Willy Tarreauc13ed532020-06-02 10:22:45 +020096#include <haproxy/chunk.h>
Willy Tarreau83487a82020-06-04 20:19:54 +020097#include <haproxy/cli.h>
Willy Tarreau55542642021-10-08 09:33:24 +020098#include <haproxy/clock.h>
Willy Tarreau7ea393d2020-06-04 18:02:10 +020099#include <haproxy/connection.h>
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +0200100#ifdef USE_CPU_AFFINITY
Amaury Denoyelle982fb532021-04-21 18:39:58 +0200101#include <haproxy/cpuset.h>
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +0200102#endif
Willy Tarreaueb92deb2020-06-04 10:53:16 +0200103#include <haproxy/dns.h>
Willy Tarreau2741c8c2020-06-02 11:28:02 +0200104#include <haproxy/dynbuf.h>
Willy Tarreau8d366972020-05-27 16:10:29 +0200105#include <haproxy/errors.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200106#include <haproxy/fd.h>
Willy Tarreauc7babd82020-06-04 21:29:29 +0200107#include <haproxy/filters.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200108#include <haproxy/global.h>
Willy Tarreau86416052020-06-04 09:20:54 +0200109#include <haproxy/hlua.h>
Willy Tarreauc761f842020-06-04 11:40:28 +0200110#include <haproxy/http_rules.h>
Willy Tarreau853b2972020-05-27 18:01:47 +0200111#include <haproxy/list.h>
Willy Tarreau213e9902020-06-04 14:58:24 +0200112#include <haproxy/listener.h>
Willy Tarreauaeed4a82020-06-04 22:01:04 +0200113#include <haproxy/log.h>
Willy Tarreaub5abe5b2020-06-04 14:07:37 +0200114#include <haproxy/mworker.h>
Willy Tarreau7a00efb2020-06-02 17:02:59 +0200115#include <haproxy/namespace.h>
Willy Tarreau6131d6a2020-06-02 16:48:09 +0200116#include <haproxy/net_helper.h>
Willy Tarreau6019fab2020-05-27 16:26:00 +0200117#include <haproxy/openssl-compat.h>
Willy Tarreau225a90a2020-06-04 15:06:28 +0200118#include <haproxy/pattern.h>
Willy Tarreau3c2a7c22020-06-04 18:38:21 +0200119#include <haproxy/peers.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200120#include <haproxy/pool.h>
121#include <haproxy/protocol.h>
Willy Tarreaubf3b06b2020-08-26 10:23:40 +0200122#include <haproxy/proto_tcp.h>
Willy Tarreaua264d962020-06-04 22:29:18 +0200123#include <haproxy/proxy.h>
Willy Tarreau7cd8b6e2020-06-02 17:32:26 +0200124#include <haproxy/regex.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200125#include <haproxy/sample.h>
Willy Tarreau1e56f922020-06-04 23:20:13 +0200126#include <haproxy/server.h>
Willy Tarreau48d25b32020-06-04 18:58:52 +0200127#include <haproxy/session.h>
Willy Tarreau3727a8a2020-06-04 17:37:26 +0200128#include <haproxy/signal.h>
Willy Tarreau063d47d2020-08-28 16:29:53 +0200129#include <haproxy/sock.h>
Willy Tarreau25140cc2020-08-28 15:40:33 +0200130#include <haproxy/sock_inet.h>
Willy Tarreau209108d2020-06-04 20:30:20 +0200131#include <haproxy/ssl_sock.h>
Amaury Denoyelleee63d4b2020-10-05 11:49:42 +0200132#include <haproxy/stats-t.h>
Willy Tarreaudfd3de82020-06-04 23:46:14 +0200133#include <haproxy/stream.h>
Willy Tarreaucea0e1b2020-06-04 17:25:40 +0200134#include <haproxy/task.h>
Willy Tarreau3f567e42020-05-28 15:29:19 +0200135#include <haproxy/thread.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200136#include <haproxy/time.h>
137#include <haproxy/tools.h>
138#include <haproxy/uri_auth-t.h>
Willy Tarreaua1718922020-06-04 16:25:31 +0200139#include <haproxy/vars.h>
Willy Tarreaub2551052020-06-09 09:07:15 +0200140#include <haproxy/version.h>
Willy Tarreaubaaee002006-06-26 02:48:02 +0200141
Willy Tarreaubaaee002006-06-26 02:48:02 +0200142
Willy Tarreau7b5654f2019-03-29 21:30:17 +0100143/* array of init calls for older platforms */
144DECLARE_INIT_STAGES;
145
Willy Tarreauf4596402021-04-10 16:53:05 +0200146/* create a read_mostly section to hold variables which are accessed a lot
147 * but which almost never change. The purpose is to isolate them in their
148 * own cache lines where they don't risk to be perturbated by write accesses
149 * to neighbor variables. We need to create an empty aligned variable for
150 * this. The fact that the variable is of size zero means that it will be
151 * eliminated at link time if no other variable uses it, but alignment will
152 * be respected.
153 */
154empty_t __read_mostly_align HA_SECTION("read_mostly") ALIGNED(64);
155
Willy Tarreauf0d3b732021-05-06 16:30:32 +0200156#ifdef BUILD_FEATURES
157const char *build_features = BUILD_FEATURES;
158#else
159const char *build_features = "";
160#endif
161
Willy Tarreau477ecd82010-01-03 21:12:30 +0100162/* list of config files */
163static struct list cfg_cfgfiles = LIST_HEAD_INIT(cfg_cfgfiles);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200164int pid; /* current process id */
165
Willy Tarreauf8ea00e2020-03-12 17:24:53 +0100166volatile unsigned long sleeping_thread_mask = 0; /* Threads that are about to sleep in poll() */
Willy Tarreau4b3f27b2020-03-12 17:28:01 +0100167volatile unsigned long stopping_thread_mask = 0; /* Threads acknowledged stopping */
Willy Tarreauf8ea00e2020-03-12 17:24:53 +0100168
Willy Tarreaubaaee002006-06-26 02:48:02 +0200169/* global options */
170struct global global = {
Cyril Bonté203ec5a2017-03-23 22:44:13 +0100171 .hard_stop_after = TICK_ETERNITY,
Amaury Denoyelle0f50cb92021-03-26 18:50:33 +0100172 .numa_cpu_mapping = 1,
Willy Tarreau149ab772019-01-26 14:27:06 +0100173 .nbthread = 0,
William Lallemand5f232402012-04-05 18:02:55 +0200174 .req_count = 0,
William Lallemand0f99e342011-10-12 17:50:54 +0200175 .logsrvs = LIST_HEAD_INIT(global.logsrvs),
William Lallemand9d5f5482012-11-07 16:12:57 +0100176 .maxzlibmem = 0,
William Lallemandd85f9172012-11-09 17:05:39 +0100177 .comp_rate_lim = 0,
Emeric Brun850efd52014-01-29 12:24:34 +0100178 .ssl_server_verify = SSL_SERVER_VERIFY_REQUIRED,
Emeric Bruned760922010-10-22 17:59:25 +0200179 .unix_bind = {
180 .ux = {
181 .uid = -1,
182 .gid = -1,
183 .mode = 0,
184 }
185 },
Willy Tarreau27a674e2009-08-17 07:23:33 +0200186 .tune = {
Willy Tarreau7ac908b2019-02-27 12:02:18 +0100187 .options = GTUNE_LISTENER_MQ,
Willy Tarreauc77d3642018-12-12 06:19:42 +0100188 .bufsize = (BUFSIZE + 2*sizeof(void *) - 1) & -(2*sizeof(void *)),
Christopher Faulet546c4692020-01-22 14:31:21 +0100189 .maxrewrite = MAXREWRITE,
Willy Tarreaua24adf02014-11-27 01:11:56 +0100190 .reserved_bufs = RESERVED_BUFS,
Willy Tarreauf3045d22015-04-29 16:24:50 +0200191 .pattern_cache = DEFAULT_PAT_LRU_SIZE,
Olivier Houchard88698d92019-04-16 19:07:22 +0200192 .pool_low_ratio = 20,
193 .pool_high_ratio = 25,
Christopher Faulet41ba36f2019-07-19 09:36:45 +0200194 .max_http_hdr = MAX_HTTP_HDR,
Emeric Brunfc32aca2012-09-03 12:10:29 +0200195#ifdef USE_OPENSSL
Emeric Brun46635772012-11-14 11:32:56 +0100196 .sslcachesize = SSLCACHESIZE,
Emeric Brunfc32aca2012-09-03 12:10:29 +0200197#endif
William Lallemandf3747832012-11-09 12:33:10 +0100198 .comp_maxlevel = 1,
Willy Tarreau7e312732014-02-12 16:35:14 +0100199#ifdef DEFAULT_IDLE_TIMER
200 .idle_timer = DEFAULT_IDLE_TIMER,
201#else
202 .idle_timer = 1000, /* 1 second */
203#endif
Willy Tarreau27a674e2009-08-17 07:23:33 +0200204 },
Emeric Brun76d88952012-10-05 15:47:31 +0200205#ifdef USE_OPENSSL
206#ifdef DEFAULT_MAXSSLCONN
Willy Tarreau403edff2012-09-06 11:58:37 +0200207 .maxsslconn = DEFAULT_MAXSSLCONN,
208#endif
Emeric Brun76d88952012-10-05 15:47:31 +0200209#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +0200210 /* others NULL OK */
211};
212
213/*********************************************************************/
214
215int stopping; /* non zero means stopping in progress */
Cyril Bonté203ec5a2017-03-23 22:44:13 +0100216int killed; /* non zero means a hard-stop is triggered */
Willy Tarreauaf7ad002010-08-31 15:39:26 +0200217int jobs = 0; /* number of active jobs (conns, listeners, active tasks, ...) */
William Lallemanda7199262018-11-16 16:57:20 +0100218int unstoppable_jobs = 0; /* number of active jobs that can't be stopped during a soft stop */
Willy Tarreau199ad242018-11-05 16:31:22 +0100219int active_peers = 0; /* number of active peers (connection attempts and connected) */
Willy Tarreau2d372c22018-11-05 17:12:27 +0100220int connected_peers = 0; /* number of connected peers (verified ones) */
Willy Tarreaubaaee002006-06-26 02:48:02 +0200221
Ilya Shipitsin46a030c2020-07-05 16:36:08 +0500222/* Here we store information about the pids of the processes we may pause
Willy Tarreaubaaee002006-06-26 02:48:02 +0200223 * or kill. We will send them a signal every 10 ms until we can bind to all
224 * our ports. With 200 retries, that's about 2 seconds.
225 */
226#define MAX_START_RETRIES 200
Willy Tarreaubaaee002006-06-26 02:48:02 +0200227static int *oldpids = NULL;
228static int oldpids_sig; /* use USR1 or TERM */
229
Olivier Houchardf73629d2017-04-05 22:33:04 +0200230/* Path to the unix socket we use to retrieve listener sockets from the old process */
231static const char *old_unixsocket;
232
William Lallemand85b0bd92017-06-01 17:38:53 +0200233static char *cur_unixsocket = NULL;
234
William Lallemandcb11fd22017-06-01 17:38:52 +0200235int atexit_flag = 0;
236
Willy Tarreaubb545b42010-08-25 12:58:59 +0200237int nb_oldpids = 0;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200238const int zero = 0;
239const int one = 1;
Alexandre Cassen87ea5482007-10-11 20:48:58 +0200240const struct linger nolinger = { .l_onoff = 1, .l_linger = 0 };
Willy Tarreaubaaee002006-06-26 02:48:02 +0200241
Willy Tarreau1d21e0a2010-03-12 21:58:54 +0100242char hostname[MAX_HOSTNAME_LEN];
Dragan Dosen4f014152020-06-18 16:56:47 +0200243char *localpeer = NULL;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200244
William Lallemand00417412020-06-05 14:08:41 +0200245static char **old_argv = NULL; /* previous argv but cleaned up */
William Lallemand73b85e72017-06-01 17:38:51 +0200246
William Lallemandbc193052018-09-11 10:06:26 +0200247struct list proc_list = LIST_HEAD_INIT(proc_list);
248
249int master = 0; /* 1 if in master, 0 if in child */
Willy Tarreaubf696402019-03-01 10:09:28 +0100250unsigned int rlim_fd_cur_at_boot = 0;
251unsigned int rlim_fd_max_at_boot = 0;
William Lallemandbc193052018-09-11 10:06:26 +0200252
Willy Tarreau6c3a6812020-03-06 18:57:15 +0100253/* per-boot randomness */
254unsigned char boot_seed[20]; /* per-boot random seed (160 bits initially) */
255
Willy Tarreau43ab05b2021-09-28 09:43:11 +0200256/* takes the thread config in argument or NULL for any thread */
William Lallemandb3f2be32018-09-11 10:06:18 +0200257static void *run_thread_poll_loop(void *data);
258
Willy Tarreauff055502014-04-28 22:27:06 +0200259/* bitfield of a few warnings to emit just once (WARN_*) */
260unsigned int warned = 0;
261
Amaury Denoyelle484454d2021-05-05 16:18:45 +0200262/* set if experimental features have been used for the current process */
263static unsigned int tainted = 0;
264
Amaury Denoyelled2e53cd2021-05-06 16:21:39 +0200265unsigned int experimental_directives_allowed = 0;
266
267int check_kw_experimental(struct cfg_keyword *kw, const char *file, int linenum,
268 char **errmsg)
269{
270 if (kw->flags & KWF_EXPERIMENTAL) {
271 if (!experimental_directives_allowed) {
Amaury Denoyelle86c1d0f2021-05-07 15:07:21 +0200272 memprintf(errmsg, "parsing [%s:%d] : '%s' directive is experimental, must be allowed via a global 'expose-experimental-directives'",
Amaury Denoyelled2e53cd2021-05-06 16:21:39 +0200273 file, linenum, kw->kw);
274 return 1;
275 }
276 mark_tainted(TAINTED_CONFIG_EXP_KW_DECLARED);
277 }
278
279 return 0;
280}
281
William Lallemande7361152018-10-26 14:47:36 +0200282/* master CLI configuration (-S flag) */
283struct list mworker_cli_conf = LIST_HEAD_INIT(mworker_cli_conf);
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100284
285/* These are strings to be reported in the output of "haproxy -vv". They may
286 * either be constants (in which case must_free must be zero) or dynamically
287 * allocated strings to pass to free() on exit, and in this case must_free
288 * must be non-zero.
289 */
290struct list build_opts_list = LIST_HEAD_INIT(build_opts_list);
291struct build_opts_str {
292 struct list list;
293 const char *str;
294 int must_free;
295};
296
Willy Tarreaubaaee002006-06-26 02:48:02 +0200297/*********************************************************************/
298/* general purpose functions ***************************************/
299/*********************************************************************/
300
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100301/* used to register some build option strings at boot. Set must_free to
302 * non-zero if the string must be freed upon exit.
303 */
304void hap_register_build_opts(const char *str, int must_free)
305{
306 struct build_opts_str *b;
307
308 b = calloc(1, sizeof(*b));
309 if (!b) {
310 fprintf(stderr, "out of memory\n");
311 exit(1);
312 }
313 b->str = str;
314 b->must_free = must_free;
Willy Tarreau2b718102021-04-21 07:32:39 +0200315 LIST_APPEND(&build_opts_list, &b->list);
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100316}
317
Willy Tarreaua43dfda2021-05-06 07:43:35 +0200318#define VERSION_MAX_ELTS 7
319
320/* This function splits an haproxy version string into an array of integers.
321 * The syntax of the supported version string is the following:
322 *
323 * <a>[.<b>[.<c>[.<d>]]][-{dev,pre,rc}<f>][-*][-<g>]
324 *
325 * This validates for example:
326 * 1.2.1-pre2, 1.2.1, 1.2.10.1, 1.3.16-rc1, 1.4-dev3, 1.5-dev18, 1.5-dev18-43
327 * 2.4-dev18-f6818d-20
328 *
329 * The result is set in a array of <VERSION_MAX_ELTS> elements. Each letter has
330 * one fixed place in the array. The tags take a numeric value called <e> which
331 * defaults to 3. "dev" is 1, "rc" and "pre" are 2. Numbers not encountered are
332 * considered as zero (henxe 1.5 and 1.5.0 are the same).
333 *
334 * The resulting values are:
335 * 1.2.1-pre2 1, 2, 1, 0, 2, 2, 0
336 * 1.2.1 1, 2, 1, 0, 3, 0, 0
337 * 1.2.10.1 1, 2, 10, 1, 3, 0, 0
338 * 1.3.16-rc1 1, 3, 16, 0, 2, 1, 0
339 * 1.4-dev3 1, 4, 0, 0, 1, 3, 0
340 * 1.5-dev18 1, 5, 0, 0, 1, 18, 0
341 * 1.5-dev18-43 1, 5, 0, 0, 1, 18, 43
342 * 2.4-dev18-f6818d-20 2, 4, 0, 0, 1, 18, 20
343 *
344 * The function returns non-zero if the conversion succeeded, or zero if it
345 * failed.
346 */
347int split_version(const char *version, unsigned int *value)
348{
349 const char *p, *s;
350 char *error;
351 int nelts;
352
353 /* Initialize array with zeroes */
354 for (nelts = 0; nelts < VERSION_MAX_ELTS; nelts++)
355 value[nelts] = 0;
356 value[4] = 3;
357
358 p = version;
359
360 /* If the version number is empty, return false */
361 if (*p == '\0')
362 return 0;
363
364 /* Convert first number <a> */
365 value[0] = strtol(p, &error, 10);
366 p = error + 1;
367 if (*error == '\0')
368 return 1;
369 if (*error == '-')
370 goto split_version_tag;
371 if (*error != '.')
372 return 0;
373
374 /* Convert first number <b> */
375 value[1] = strtol(p, &error, 10);
376 p = error + 1;
377 if (*error == '\0')
378 return 1;
379 if (*error == '-')
380 goto split_version_tag;
381 if (*error != '.')
382 return 0;
383
384 /* Convert first number <c> */
385 value[2] = strtol(p, &error, 10);
386 p = error + 1;
387 if (*error == '\0')
388 return 1;
389 if (*error == '-')
390 goto split_version_tag;
391 if (*error != '.')
392 return 0;
393
394 /* Convert first number <d> */
395 value[3] = strtol(p, &error, 10);
396 p = error + 1;
397 if (*error == '\0')
398 return 1;
399 if (*error != '-')
400 return 0;
401
402 split_version_tag:
403 /* Check for commit number */
404 if (*p >= '0' && *p <= '9')
405 goto split_version_commit;
406
407 /* Read tag */
408 if (strncmp(p, "dev", 3) == 0) { value[4] = 1; p += 3; }
409 else if (strncmp(p, "rc", 2) == 0) { value[4] = 2; p += 2; }
410 else if (strncmp(p, "pre", 3) == 0) { value[4] = 2; p += 3; }
411 else
412 goto split_version_commit;
413
414 /* Convert tag number */
415 value[5] = strtol(p, &error, 10);
416 p = error + 1;
417 if (*error == '\0')
418 return 1;
419 if (*error != '-')
420 return 0;
421
422 split_version_commit:
423 /* Search the last "-" */
424 s = strrchr(p, '-');
425 if (s) {
426 s++;
427 if (*s == '\0')
428 return 0;
429 value[6] = strtol(s, &error, 10);
430 if (*error != '\0')
431 value[6] = 0;
432 return 1;
433 }
434
435 /* convert the version */
436 value[6] = strtol(p, &error, 10);
437 if (*error != '\0')
438 value[6] = 0;
439
440 return 1;
441}
442
443/* This function compares the current haproxy version with an arbitrary version
444 * string. It returns:
445 * -1 : the version in argument is older than the current haproxy version
446 * 0 : the version in argument is the same as the current haproxy version
447 * 1 : the version in argument is newer than the current haproxy version
448 *
449 * Or some errors:
450 * -2 : the current haproxy version is not parsable
451 * -3 : the version in argument is not parsable
452 */
453int compare_current_version(const char *version)
454{
455 unsigned int loc[VERSION_MAX_ELTS];
456 unsigned int mod[VERSION_MAX_ELTS];
457 int i;
458
459 /* split versions */
460 if (!split_version(haproxy_version, loc))
461 return -2;
462 if (!split_version(version, mod))
463 return -3;
464
465 /* compare versions */
466 for (i = 0; i < VERSION_MAX_ELTS; i++) {
467 if (mod[i] < loc[i])
468 return -1;
469 else if (mod[i] > loc[i])
470 return 1;
471 }
472 return 0;
473}
474
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100475static void display_version()
Willy Tarreaubaaee002006-06-26 02:48:02 +0200476{
Tim Duesterhusdfad6a42020-04-18 16:02:47 +0200477 struct utsname utsname;
478
Willy Tarreaua5357cd2021-05-09 06:14:25 +0200479 printf("HAProxy version %s %s - https://haproxy.org/\n"
Willy Tarreau08dd2022019-11-21 18:07:30 +0100480 PRODUCT_STATUS "\n", haproxy_version, haproxy_date);
Willy Tarreau47479eb2019-11-21 18:48:20 +0100481
482 if (strlen(PRODUCT_URL_BUGS) > 0) {
483 char base_version[20];
484 int dots = 0;
485 char *del;
486
487 /* only retrieve the base version without distro-specific extensions */
488 for (del = haproxy_version; *del; del++) {
489 if (*del == '.')
490 dots++;
491 else if (*del < '0' || *del > '9')
492 break;
493 }
494
495 strlcpy2(base_version, haproxy_version, del - haproxy_version + 1);
496 if (dots < 2)
497 printf("Known bugs: https://github.com/haproxy/haproxy/issues?q=is:issue+is:open\n");
498 else
499 printf("Known bugs: " PRODUCT_URL_BUGS "\n", base_version);
500 }
Tim Duesterhusdfad6a42020-04-18 16:02:47 +0200501
502 if (uname(&utsname) == 0) {
503 printf("Running on: %s %s %s %s\n", utsname.sysname, utsname.release, utsname.version, utsname.machine);
504 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200505}
506
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100507static void display_build_opts()
Willy Tarreau7b066db2007-12-02 11:28:59 +0100508{
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100509 struct build_opts_str *item;
510
Willy Tarreau7b066db2007-12-02 11:28:59 +0100511 printf("Build options :"
512#ifdef BUILD_TARGET
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100513 "\n TARGET = " BUILD_TARGET
Willy Tarreau7b066db2007-12-02 11:28:59 +0100514#endif
515#ifdef BUILD_CPU
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100516 "\n CPU = " BUILD_CPU
Willy Tarreau7b066db2007-12-02 11:28:59 +0100517#endif
518#ifdef BUILD_CC
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100519 "\n CC = " BUILD_CC
520#endif
521#ifdef BUILD_CFLAGS
522 "\n CFLAGS = " BUILD_CFLAGS
Willy Tarreau7b066db2007-12-02 11:28:59 +0100523#endif
Willy Tarreau9f2b7302008-01-02 20:48:34 +0100524#ifdef BUILD_OPTIONS
525 "\n OPTIONS = " BUILD_OPTIONS
Willy Tarreau7b066db2007-12-02 11:28:59 +0100526#endif
Tim Duesterhusc8d19702020-11-21 18:07:59 +0100527#ifdef BUILD_DEBUG
528 "\n DEBUG = " BUILD_DEBUG
529#endif
Willy Tarreau7728ed32019-03-27 13:20:08 +0100530#ifdef BUILD_FEATURES
531 "\n\nFeature list : " BUILD_FEATURES
532#endif
Willy Tarreau27a674e2009-08-17 07:23:33 +0200533 "\n\nDefault settings :"
Willy Tarreauca783d42019-03-13 10:03:07 +0100534 "\n bufsize = %d, maxrewrite = %d, maxpollevents = %d"
Willy Tarreau27a674e2009-08-17 07:23:33 +0200535 "\n\n",
Willy Tarreauca783d42019-03-13 10:03:07 +0100536 BUFSIZE, MAXREWRITE, MAX_POLL_EVENTS);
Willy Tarreaube5b6852009-10-03 18:57:08 +0200537
Willy Tarreaucdb737e2016-12-21 18:43:10 +0100538 list_for_each_entry(item, &build_opts_list, list) {
539 puts(item->str);
540 }
541
Krzysztof Piotr Oledzki96105042010-01-29 17:50:44 +0100542 putchar('\n');
543
Willy Tarreaube5b6852009-10-03 18:57:08 +0200544 list_pollers(stdout);
545 putchar('\n');
Christopher Faulet98d9fe22018-04-10 14:37:32 +0200546 list_mux_proto(stdout);
547 putchar('\n');
Willy Tarreau679bba12019-03-19 08:08:10 +0100548 list_services(stdout);
549 putchar('\n');
Christopher Fauletb3f4e142016-03-07 12:46:38 +0100550 list_filters(stdout);
551 putchar('\n');
Willy Tarreau7b066db2007-12-02 11:28:59 +0100552}
553
Willy Tarreaubaaee002006-06-26 02:48:02 +0200554/*
555 * This function prints the command line usage and exits
556 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100557static void usage(char *name)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200558{
559 display_version();
560 fprintf(stderr,
Maxime de Roucy379d9c72016-05-13 23:52:56 +0200561 "Usage : %s [-f <cfgfile|cfgdir>]* [ -vdV"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200562 "D ] [ -n <maxconn> ] [ -N <maxpconn> ]\n"
Willy Tarreaua088d312015-10-08 11:58:48 +0200563 " [ -p <pidfile> ] [ -m <max megs> ] [ -C <dir> ] [-- <cfgfile>*]\n"
Willy Tarreau7b066db2007-12-02 11:28:59 +0100564 " -v displays version ; -vv shows known build options.\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200565 " -d enters debug mode ; -db only disables background mode.\n"
Willy Tarreau6e064432012-05-08 15:40:42 +0200566 " -dM[<byte>] poisons memory with <byte> (defaults to 0x50)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200567 " -V enters verbose mode (disables quiet mode)\n"
Willy Tarreau576132e2011-09-10 19:26:56 +0200568 " -D goes daemon ; -C changes to <dir> before loading files.\n"
William Lallemand095ba4c2017-06-01 17:38:50 +0200569 " -W master-worker mode.\n"
Tim Duesterhusd6942c82017-11-20 15:58:35 +0100570#if defined(USE_SYSTEMD)
571 " -Ws master-worker mode with systemd notify support.\n"
572#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +0200573 " -q quiet mode : don't display messages\n"
Willy Tarreau5d01a632009-06-22 16:02:30 +0200574 " -c check mode : only check config files and exit\n"
Maximilian Maderfc0cceb2021-06-06 00:50:22 +0200575 " -cc check condition : evaluate a condition and exit\n"
Willy Tarreauca783d42019-03-13 10:03:07 +0100576 " -n sets the maximum total # of connections (uses ulimit -n)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200577 " -m limits the usable amount of memory (in MB)\n"
578 " -N sets the default, per-proxy maximum # of connections (%d)\n"
Emeric Brun2b920a12010-09-23 18:30:22 +0200579 " -L set local peer name (default to hostname)\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200580 " -p writes pids of all children to this file\n"
Willy Tarreaue5733232019-05-22 19:24:06 +0200581#if defined(USE_EPOLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200582 " -de disables epoll() usage even when available\n"
583#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200584#if defined(USE_KQUEUE)
Willy Tarreau1e63130a2007-04-09 12:03:06 +0200585 " -dk disables kqueue() usage even when available\n"
586#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200587#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +0000588 " -dv disables event ports usage even when available\n"
589#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200590#if defined(USE_POLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200591 " -dp disables poll() usage even when available\n"
592#endif
Willy Tarreaue5733232019-05-22 19:24:06 +0200593#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +0100594 " -dS disables splice usage (broken on old kernels)\n"
595#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +0200596#if defined(USE_GETADDRINFO)
597 " -dG disables getaddrinfo() usage\n"
598#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +0000599#if defined(SO_REUSEPORT)
600 " -dR disables SO_REUSEPORT usage\n"
601#endif
Willy Tarreau3eed10e2016-11-07 21:03:16 +0100602 " -dr ignores server address resolution failures\n"
Emeric Brun850efd52014-01-29 12:24:34 +0100603 " -dV disables SSL verify on servers side\n"
Willy Tarreau3eb10b82020-04-15 16:42:39 +0200604 " -dW fails if any warning is emitted\n"
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +0200605 " -dD diagnostic mode : warn about suspicious configuration statements\n"
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +0200606 " -sf/-st [pid ]* finishes/terminates old pids.\n"
Olivier Houchardf73629d2017-04-05 22:33:04 +0200607 " -x <unix_socket> get listening sockets from a unix socket\n"
William Lallemand63329e32019-06-13 17:03:37 +0200608 " -S <bind>[,<bind options>...] new master CLI\n"
Willy Tarreaubaaee002006-06-26 02:48:02 +0200609 "\n",
Willy Tarreauca783d42019-03-13 10:03:07 +0100610 name, cfg_maxpconn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200611 exit(1);
612}
613
614
615
616/*********************************************************************/
617/* more specific functions ***************************************/
618/*********************************************************************/
619
William Lallemand73b85e72017-06-01 17:38:51 +0200620/* sends the signal <sig> to all pids found in <oldpids>. Returns the number of
621 * pids the signal was correctly delivered to.
622 */
William Lallemande25473c2019-04-01 11:29:56 +0200623int tell_old_pids(int sig)
William Lallemand73b85e72017-06-01 17:38:51 +0200624{
625 int p;
626 int ret = 0;
627 for (p = 0; p < nb_oldpids; p++)
628 if (kill(oldpids[p], sig) == 0)
629 ret++;
630 return ret;
631}
632
William Lallemand75ea0a02017-11-15 19:02:58 +0100633/*
William Lallemand73b85e72017-06-01 17:38:51 +0200634 * remove a pid forom the olpid array and decrease nb_oldpids
635 * return 1 pid was found otherwise return 0
636 */
637
638int delete_oldpid(int pid)
639{
640 int i;
641
642 for (i = 0; i < nb_oldpids; i++) {
643 if (oldpids[i] == pid) {
644 oldpids[i] = oldpids[nb_oldpids - 1];
645 oldpids[nb_oldpids - 1] = 0;
646 nb_oldpids--;
647 return 1;
648 }
649 }
650 return 0;
651}
652
William Lallemand85b0bd92017-06-01 17:38:53 +0200653
654static void get_cur_unixsocket()
655{
656 /* if -x was used, try to update the stat socket if not available anymore */
Willy Tarreau4975d142021-03-13 11:00:33 +0100657 if (global.cli_fe) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200658 struct bind_conf *bind_conf;
659
660 /* pass through all stats socket */
Willy Tarreau4975d142021-03-13 11:00:33 +0100661 list_for_each_entry(bind_conf, &global.cli_fe->conf.bind, by_fe) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200662 struct listener *l;
663
664 list_for_each_entry(l, &bind_conf->listeners, by_bind) {
665
Willy Tarreau37159062020-08-27 07:48:42 +0200666 if (l->rx.addr.ss_family == AF_UNIX &&
William Lallemand85b0bd92017-06-01 17:38:53 +0200667 (bind_conf->level & ACCESS_FD_LISTENERS)) {
668 const struct sockaddr_un *un;
669
Willy Tarreau37159062020-08-27 07:48:42 +0200670 un = (struct sockaddr_un *)&l->rx.addr;
William Lallemand85b0bd92017-06-01 17:38:53 +0200671 /* priority to old_unixsocket */
672 if (!cur_unixsocket) {
673 cur_unixsocket = strdup(un->sun_path);
674 } else {
Tim Duesterhuse5ff1412021-01-02 22:31:53 +0100675 if (old_unixsocket && strcmp(un->sun_path, old_unixsocket) == 0) {
William Lallemand85b0bd92017-06-01 17:38:53 +0200676 free(cur_unixsocket);
677 cur_unixsocket = strdup(old_unixsocket);
678 return;
679 }
680 }
681 }
682 }
683 }
684 }
685 if (!cur_unixsocket && old_unixsocket)
686 cur_unixsocket = strdup(old_unixsocket);
687}
688
William Lallemand73b85e72017-06-01 17:38:51 +0200689/*
690 * When called, this function reexec haproxy with -sf followed by current
Joseph Herlant03420902018-11-15 10:41:50 -0800691 * children PIDs and possibly old children PIDs if they didn't leave yet.
William Lallemand73b85e72017-06-01 17:38:51 +0200692 */
William Lallemandfab0fdc2021-11-09 18:01:22 +0100693static void mworker_reexec()
William Lallemand73b85e72017-06-01 17:38:51 +0200694{
William Lallemand00417412020-06-05 14:08:41 +0200695 char **next_argv = NULL;
696 int old_argc = 0; /* previous number of argument */
William Lallemand73b85e72017-06-01 17:38:51 +0200697 int next_argc = 0;
William Lallemand00417412020-06-05 14:08:41 +0200698 int i = 0;
William Lallemand73b85e72017-06-01 17:38:51 +0200699 char *msg = NULL;
Willy Tarreau8dca1952019-03-01 10:21:55 +0100700 struct rlimit limit;
William Lallemand7c756a82018-11-26 11:53:40 +0100701 struct per_thread_deinit_fct *ptdf;
William Lallemand73b85e72017-06-01 17:38:51 +0200702
703 mworker_block_signals();
Tim Duesterhusd6942c82017-11-20 15:58:35 +0100704#if defined(USE_SYSTEMD)
705 if (global.tune.options & GTUNE_USE_SYSTEMD)
706 sd_notify(0, "RELOADING=1");
707#endif
William Lallemand73b85e72017-06-01 17:38:51 +0200708 setenv("HAPROXY_MWORKER_REEXEC", "1", 1);
709
William Lallemandbc193052018-09-11 10:06:26 +0200710 mworker_proc_list_to_env(); /* put the children description in the env */
711
William Lallemand7c756a82018-11-26 11:53:40 +0100712 /* during the reload we must ensure that every FDs that can't be
713 * reuse (ie those that are not referenced in the proc_list)
714 * are closed or they will leak. */
715
716 /* close the listeners FD */
717 mworker_cli_proxy_stop();
William Lallemand16866672019-06-24 17:40:48 +0200718
719 if (getenv("HAPROXY_MWORKER_WAIT_ONLY") == NULL) {
720 /* close the poller FD and the thread waker pipe FD */
721 list_for_each_entry(ptdf, &per_thread_deinit_list, list)
722 ptdf->fct();
723 if (fdtab)
724 deinit_pollers();
725 }
Ilya Shipitsin98a9e1b2021-02-19 23:42:53 +0500726#ifdef HAVE_SSL_RAND_KEEP_RANDOM_DEVICES_OPEN
William Lallemand5fdb5b32019-10-15 14:04:08 +0200727 /* close random device FDs */
728 RAND_keep_random_devices_open(0);
Rob Allen56996da2019-05-03 09:11:32 +0100729#endif
William Lallemand7c756a82018-11-26 11:53:40 +0100730
Willy Tarreau8dca1952019-03-01 10:21:55 +0100731 /* restore the initial FD limits */
732 limit.rlim_cur = rlim_fd_cur_at_boot;
733 limit.rlim_max = rlim_fd_max_at_boot;
734 if (setrlimit(RLIMIT_NOFILE, &limit) == -1) {
735 getrlimit(RLIMIT_NOFILE, &limit);
736 ha_warning("Failed to restore initial FD limits (cur=%u max=%u), using cur=%u max=%u\n",
737 rlim_fd_cur_at_boot, rlim_fd_max_at_boot,
738 (unsigned int)limit.rlim_cur, (unsigned int)limit.rlim_max);
739 }
740
William Lallemand73b85e72017-06-01 17:38:51 +0200741 /* compute length */
William Lallemand00417412020-06-05 14:08:41 +0200742 while (old_argv[old_argc])
743 old_argc++;
William Lallemand73b85e72017-06-01 17:38:51 +0200744
William Lallemand85b0bd92017-06-01 17:38:53 +0200745 /* 1 for haproxy -sf, 2 for -x /socket */
William Lallemandaba7f8b2021-04-21 16:55:34 +0200746 next_argv = calloc(old_argc + 1 + 2 + mworker_child_nb() + 1,
Tim Duesterhuse52b6e52020-09-12 20:26:43 +0200747 sizeof(*next_argv));
William Lallemand73b85e72017-06-01 17:38:51 +0200748 if (next_argv == NULL)
749 goto alloc_error;
750
William Lallemand00417412020-06-05 14:08:41 +0200751 /* copy the program name */
752 next_argv[next_argc++] = old_argv[0];
753
754 /* insert the new options just after argv[0] in case we have a -- */
755
William Lallemand73b85e72017-06-01 17:38:51 +0200756 /* add -sf <PID>* to argv */
William Lallemand3f128872019-04-01 11:29:59 +0200757 if (mworker_child_nb() > 0) {
758 struct mworker_proc *child;
759
William Lallemand73b85e72017-06-01 17:38:51 +0200760 next_argv[next_argc++] = "-sf";
William Lallemand3f128872019-04-01 11:29:59 +0200761
762 list_for_each_entry(child, &proc_list, list) {
William Lallemand677e2f22019-11-19 17:04:18 +0100763 if (!(child->options & (PROC_O_TYPE_WORKER|PROC_O_TYPE_PROG)) || child->pid <= -1 )
William Lallemand3f128872019-04-01 11:29:59 +0200764 continue;
William Lallemand00417412020-06-05 14:08:41 +0200765 if ((next_argv[next_argc++] = memprintf(&msg, "%d", child->pid)) == NULL)
William Lallemand73b85e72017-06-01 17:38:51 +0200766 goto alloc_error;
767 msg = NULL;
768 }
769 }
William Lallemand2bf6d622017-06-20 11:20:23 +0200770 /* add the -x option with the stat socket */
William Lallemand85b0bd92017-06-01 17:38:53 +0200771 if (cur_unixsocket) {
William Lallemand2bf6d622017-06-20 11:20:23 +0200772 next_argv[next_argc++] = "-x";
773 next_argv[next_argc++] = (char *)cur_unixsocket;
William Lallemand85b0bd92017-06-01 17:38:53 +0200774 }
775
William Lallemand00417412020-06-05 14:08:41 +0200776 /* copy the previous options */
777 for (i = 1; i < old_argc; i++)
778 next_argv[next_argc++] = old_argv[i];
779
Willy Tarreaue0d86e22019-08-26 10:37:39 +0200780 signal(SIGPROF, SIG_IGN);
Tim Duesterhus0436ab72017-11-12 17:39:18 +0100781 execvp(next_argv[0], next_argv);
Christopher Faulet767a84b2017-11-24 16:50:31 +0100782 ha_warning("Failed to reexecute the master process [%d]: %s\n", pid, strerror(errno));
Willy Tarreau61cfdf42021-02-20 10:46:51 +0100783 ha_free(&next_argv);
William Lallemand722d4ca2017-11-15 19:02:55 +0100784 return;
785
William Lallemand73b85e72017-06-01 17:38:51 +0200786alloc_error:
Willy Tarreau61cfdf42021-02-20 10:46:51 +0100787 ha_free(&next_argv);
Joseph Herlant07a08342018-11-15 10:43:05 -0800788 ha_warning("Failed to reexecute the master process [%d]: Cannot allocate memory\n", pid);
William Lallemand73b85e72017-06-01 17:38:51 +0200789 return;
790}
791
William Lallemandfab0fdc2021-11-09 18:01:22 +0100792/* reexec haproxy in waitmode */
793static void mworker_reexec_waitmode()
794{
795 setenv("HAPROXY_MWORKER_WAIT_ONLY", "1", 1);
796 mworker_reexec();
797}
798
799/* reload haproxy and emit a warning */
800void mworker_reload()
801{
William Lallemandad221f42021-11-09 18:43:59 +0100802 struct mworker_proc *child;
803
William Lallemand836bda22021-11-09 18:16:47 +0100804 ha_notice("Reloading HAProxy\n");
William Lallemandad221f42021-11-09 18:43:59 +0100805
806 /* increment the number of reloads */
807 list_for_each_entry(child, &proc_list, list) {
808 child->reloads++;
809 }
810
William Lallemandfab0fdc2021-11-09 18:01:22 +0100811 mworker_reexec();
812}
813
William Lallemandb3f2be32018-09-11 10:06:18 +0200814static void mworker_loop()
815{
816
817#if defined(USE_SYSTEMD)
818 if (global.tune.options & GTUNE_USE_SYSTEMD)
819 sd_notifyf(0, "READY=1\nMAINPID=%lu", (unsigned long)getpid());
820#endif
Willy Tarreaud83b6c12019-04-18 11:31:36 +0200821 /* Busy polling makes no sense in the master :-) */
822 global.tune.options &= ~GTUNE_BUSY_POLLING;
William Lallemandb3f2be32018-09-11 10:06:18 +0200823
William Lallemandbc193052018-09-11 10:06:26 +0200824
Willy Tarreaud26c9f92019-12-11 14:24:07 +0100825 signal_unregister(SIGTTIN);
826 signal_unregister(SIGTTOU);
William Lallemand0564d412018-11-20 17:36:53 +0100827 signal_unregister(SIGUSR1);
828 signal_unregister(SIGHUP);
829 signal_unregister(SIGQUIT);
830
William Lallemandb3f2be32018-09-11 10:06:18 +0200831 signal_register_fct(SIGTERM, mworker_catch_sigterm, SIGTERM);
832 signal_register_fct(SIGUSR1, mworker_catch_sigterm, SIGUSR1);
Willy Tarreaud26c9f92019-12-11 14:24:07 +0100833 signal_register_fct(SIGTTIN, mworker_broadcast_signal, SIGTTIN);
834 signal_register_fct(SIGTTOU, mworker_broadcast_signal, SIGTTOU);
William Lallemandb3f2be32018-09-11 10:06:18 +0200835 signal_register_fct(SIGINT, mworker_catch_sigterm, SIGINT);
836 signal_register_fct(SIGHUP, mworker_catch_sighup, SIGHUP);
837 signal_register_fct(SIGUSR2, mworker_catch_sighup, SIGUSR2);
838 signal_register_fct(SIGCHLD, mworker_catch_sigchld, SIGCHLD);
839
840 mworker_unblock_signals();
841 mworker_cleanlisteners();
William Lallemand27f3fa52018-12-06 14:05:20 +0100842 mworker_cleantasks();
William Lallemandb3f2be32018-09-11 10:06:18 +0200843
William Lallemandbc193052018-09-11 10:06:26 +0200844 mworker_catch_sigchld(NULL); /* ensure we clean the children in case
845 some SIGCHLD were lost */
846
William Lallemandb3f2be32018-09-11 10:06:18 +0200847 global.nbthread = 1;
William Lallemandb3f2be32018-09-11 10:06:18 +0200848
William Lallemand2672eb92018-12-14 15:52:39 +0100849#ifdef USE_THREAD
850 tid_bit = 1;
851 all_threads_mask = 1;
852#endif
853
William Lallemandb3f2be32018-09-11 10:06:18 +0200854 jobs++; /* this is the "master" job, we want to take care of the
855 signals even if there is no listener so the poll loop don't
856 leave */
857
858 fork_poller();
Willy Tarreau43ab05b2021-09-28 09:43:11 +0200859 run_thread_poll_loop(NULL);
William Lallemandb3f2be32018-09-11 10:06:18 +0200860}
William Lallemandcb11fd22017-06-01 17:38:52 +0200861
862/*
863 * Reexec the process in failure mode, instead of exiting
864 */
865void reexec_on_failure()
866{
867 if (!atexit_flag)
868 return;
William Lallemandfab0fdc2021-11-09 18:01:22 +0100869 usermsgs_clr(NULL);
William Lallemand836bda22021-11-09 18:16:47 +0100870 ha_warning("Loading failure!\n");
William Lallemandfab0fdc2021-11-09 18:01:22 +0100871 mworker_reexec_waitmode();
William Lallemandcb11fd22017-06-01 17:38:52 +0200872}
William Lallemand73b85e72017-06-01 17:38:51 +0200873
874
875/*
Willy Tarreaud0807c32010-08-27 18:26:11 +0200876 * upon SIGUSR1, let's have a soft stop. Note that soft_stop() broadcasts
877 * a signal zero to all subscribers. This means that it's as easy as
878 * subscribing to signal 0 to get informed about an imminent shutdown.
Willy Tarreaubaaee002006-06-26 02:48:02 +0200879 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100880static void sig_soft_stop(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200881{
882 soft_stop();
Willy Tarreau24f4efa2010-08-27 17:56:48 +0200883 signal_unregister_handler(sh);
Willy Tarreaubafbe012017-11-24 17:34:44 +0100884 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200885}
886
887/*
888 * upon SIGTTOU, we pause everything
889 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100890static void sig_pause(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200891{
Willy Tarreau775e0012020-09-24 16:36:26 +0200892 if (protocol_pause_all() & ERR_FATAL) {
893 const char *msg = "Some proxies refused to pause, performing soft stop now.\n";
Willy Tarreau0a002df2020-10-09 19:26:27 +0200894 ha_warning("%s", msg);
895 send_log(NULL, LOG_WARNING, "%s", msg);
Willy Tarreau775e0012020-09-24 16:36:26 +0200896 soft_stop();
897 }
Willy Tarreaubafbe012017-11-24 17:34:44 +0100898 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200899}
900
901/*
902 * upon SIGTTIN, let's have a soft stop.
903 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100904static void sig_listen(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200905{
Willy Tarreau775e0012020-09-24 16:36:26 +0200906 if (protocol_resume_all() & ERR_FATAL) {
907 const char *msg = "Some proxies refused to resume, probably due to a conflict on a listening port. You may want to try again after the conflicting application is stopped, otherwise a restart might be needed to resume safe operations.\n";
Willy Tarreau0a002df2020-10-09 19:26:27 +0200908 ha_warning("%s", msg);
909 send_log(NULL, LOG_WARNING, "%s", msg);
Willy Tarreau775e0012020-09-24 16:36:26 +0200910 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200911}
912
913/*
914 * this function dumps every server's state when the process receives SIGHUP.
915 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100916static void sig_dump_state(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200917{
Olivier Houchardfbc74e82017-11-24 16:54:05 +0100918 struct proxy *p = proxies_list;
Willy Tarreaubaaee002006-06-26 02:48:02 +0200919
Christopher Faulet767a84b2017-11-24 16:50:31 +0100920 ha_warning("SIGHUP received, dumping servers states.\n");
Willy Tarreaubaaee002006-06-26 02:48:02 +0200921 while (p) {
922 struct server *s = p->srv;
923
924 send_log(p, LOG_NOTICE, "SIGHUP received, dumping servers states for proxy %s.\n", p->id);
925 while (s) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100926 chunk_printf(&trash,
927 "SIGHUP: Server %s/%s is %s. Conn: %d act, %d pend, %lld tot.",
928 p->id, s->id,
Emeric Brun52a91d32017-08-31 14:41:55 +0200929 (s->cur_state != SRV_ST_STOPPED) ? "UP" : "DOWN",
Willy Tarreaua0570452021-06-18 09:30:30 +0200930 s->cur_sess, s->queue.length, s->counters.cum_sess);
Willy Tarreau843b7cb2018-07-13 10:54:26 +0200931 ha_warning("%s\n", trash.area);
932 send_log(p, LOG_NOTICE, "%s\n", trash.area);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200933 s = s->next;
934 }
935
Willy Tarreau5fcc8f12007-09-17 11:27:09 +0200936 /* FIXME: those info are a bit outdated. We should be able to distinguish between FE and BE. */
937 if (!p->srv) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100938 chunk_printf(&trash,
939 "SIGHUP: Proxy %s has no servers. Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
940 p->id,
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200941 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreau5fcc8f12007-09-17 11:27:09 +0200942 } else if (p->srv_act == 0) {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100943 chunk_printf(&trash,
944 "SIGHUP: Proxy %s %s ! Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
945 p->id,
946 (p->srv_bck) ? "is running on backup servers" : "has no server available",
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200947 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200948 } else {
Willy Tarreau19d14ef2012-10-29 16:51:55 +0100949 chunk_printf(&trash,
950 "SIGHUP: Proxy %s has %d active servers and %d backup servers available."
951 " Conn: act(FE+BE): %d+%d, %d pend (%d unass), tot(FE+BE): %lld+%lld.",
952 p->id, p->srv_act, p->srv_bck,
Willy Tarreau7f3c1df2021-06-18 09:22:21 +0200953 p->feconn, p->beconn, p->totpend, p->queue.length, p->fe_counters.cum_conn, p->be_counters.cum_conn);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200954 }
Willy Tarreau843b7cb2018-07-13 10:54:26 +0200955 ha_warning("%s\n", trash.area);
956 send_log(p, LOG_NOTICE, "%s\n", trash.area);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200957
958 p = p->next;
959 }
Willy Tarreaubaaee002006-06-26 02:48:02 +0200960}
961
Willy Tarreau1b5af7c2016-12-21 18:19:57 +0100962static void dump(struct sig_handler *sh)
Willy Tarreaubaaee002006-06-26 02:48:02 +0200963{
Willy Tarreauc6ca1a02007-05-13 19:43:47 +0200964 /* dump memory usage then free everything possible */
965 dump_pools();
Willy Tarreaubafbe012017-11-24 17:34:44 +0100966 pool_gc(NULL);
Willy Tarreaubaaee002006-06-26 02:48:02 +0200967}
968
William Lallemande1340412017-12-28 16:09:36 +0100969/*
970 * This function dup2 the stdio FDs (0,1,2) with <fd>, then closes <fd>
971 * If <fd> < 0, it opens /dev/null and use it to dup
972 *
973 * In the case of chrooting, you have to open /dev/null before the chroot, and
974 * pass the <fd> to this function
975 */
976static void stdio_quiet(int fd)
977{
978 if (fd < 0)
979 fd = open("/dev/null", O_RDWR, 0);
980
981 if (fd > -1) {
982 fclose(stdin);
983 fclose(stdout);
984 fclose(stderr);
985
986 dup2(fd, 0);
987 dup2(fd, 1);
988 dup2(fd, 2);
989 if (fd > 2)
990 close(fd);
991 return;
992 }
993
994 ha_alert("Cannot open /dev/null\n");
995 exit(EXIT_FAILURE);
996}
997
998
Joseph Herlant03420902018-11-15 10:41:50 -0800999/* This function checks if cfg_cfgfiles contains directories.
1000 * If it finds one, it adds all the files (and only files) it contains
1001 * in cfg_cfgfiles in place of the directory (and removes the directory).
1002 * It adds the files in lexical order.
1003 * It adds only files with .cfg extension.
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001004 * It doesn't add files with name starting with '.'
1005 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +01001006static void cfgfiles_expand_directories(void)
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001007{
1008 struct wordlist *wl, *wlb;
1009 char *err = NULL;
1010
1011 list_for_each_entry_safe(wl, wlb, &cfg_cfgfiles, list) {
1012 struct stat file_stat;
1013 struct dirent **dir_entries = NULL;
1014 int dir_entries_nb;
1015 int dir_entries_it;
1016
1017 if (stat(wl->s, &file_stat)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001018 ha_alert("Cannot open configuration file/directory %s : %s\n",
1019 wl->s,
1020 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001021 exit(1);
1022 }
1023
1024 if (!S_ISDIR(file_stat.st_mode))
1025 continue;
1026
1027 /* from this point wl->s is a directory */
1028
1029 dir_entries_nb = scandir(wl->s, &dir_entries, NULL, alphasort);
1030 if (dir_entries_nb < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001031 ha_alert("Cannot open configuration directory %s : %s\n",
1032 wl->s,
1033 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001034 exit(1);
1035 }
1036
1037 /* for each element in the directory wl->s */
1038 for (dir_entries_it = 0; dir_entries_it < dir_entries_nb; dir_entries_it++) {
1039 struct dirent *dir_entry = dir_entries[dir_entries_it];
1040 char *filename = NULL;
1041 char *d_name_cfgext = strstr(dir_entry->d_name, ".cfg");
1042
1043 /* don't add filename that begin with .
Joseph Herlant03420902018-11-15 10:41:50 -08001044 * only add filename with .cfg extension
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001045 */
1046 if (dir_entry->d_name[0] == '.' ||
1047 !(d_name_cfgext && d_name_cfgext[4] == '\0'))
1048 goto next_dir_entry;
1049
1050 if (!memprintf(&filename, "%s/%s", wl->s, dir_entry->d_name)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001051 ha_alert("Cannot load configuration files %s : out of memory.\n",
1052 filename);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001053 exit(1);
1054 }
1055
1056 if (stat(filename, &file_stat)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001057 ha_alert("Cannot open configuration file %s : %s\n",
1058 wl->s,
1059 strerror(errno));
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001060 exit(1);
1061 }
1062
1063 /* don't add anything else than regular file in cfg_cfgfiles
1064 * this way we avoid loops
1065 */
1066 if (!S_ISREG(file_stat.st_mode))
1067 goto next_dir_entry;
1068
1069 if (!list_append_word(&wl->list, filename, &err)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001070 ha_alert("Cannot load configuration files %s : %s\n",
1071 filename,
1072 err);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001073 exit(1);
1074 }
1075
1076next_dir_entry:
1077 free(filename);
1078 free(dir_entry);
1079 }
1080
1081 free(dir_entries);
1082
1083 /* remove the current directory (wl) from cfg_cfgfiles */
1084 free(wl->s);
Willy Tarreau2b718102021-04-21 07:32:39 +02001085 LIST_DELETE(&wl->list);
Maxime de Roucy379d9c72016-05-13 23:52:56 +02001086 free(wl);
1087 }
1088
1089 free(err);
1090}
1091
Willy Tarreaubaaee002006-06-26 02:48:02 +02001092/*
William Lallemand73b85e72017-06-01 17:38:51 +02001093 * copy and cleanup the current argv
William Lallemanddf6c5a82020-06-04 17:40:23 +02001094 * Remove the -sf /-st / -x parameters
William Lallemand73b85e72017-06-01 17:38:51 +02001095 * Return an allocated copy of argv
1096 */
1097
1098static char **copy_argv(int argc, char **argv)
1099{
William Lallemanddf6c5a82020-06-04 17:40:23 +02001100 char **newargv, **retargv;
William Lallemand73b85e72017-06-01 17:38:51 +02001101
Tim Duesterhuse52b6e52020-09-12 20:26:43 +02001102 newargv = calloc(argc + 2, sizeof(*newargv));
William Lallemand73b85e72017-06-01 17:38:51 +02001103 if (newargv == NULL) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001104 ha_warning("Cannot allocate memory\n");
William Lallemand73b85e72017-06-01 17:38:51 +02001105 return NULL;
1106 }
William Lallemanddf6c5a82020-06-04 17:40:23 +02001107 retargv = newargv;
William Lallemand73b85e72017-06-01 17:38:51 +02001108
William Lallemanddf6c5a82020-06-04 17:40:23 +02001109 /* first copy argv[0] */
1110 *newargv++ = *argv++;
1111 argc--;
1112
1113 while (argc > 0) {
1114 if (**argv != '-') {
1115 /* non options are copied but will fail in the argument parser */
1116 *newargv++ = *argv++;
1117 argc--;
1118
1119 } else {
1120 char *flag;
1121
1122 flag = *argv + 1;
1123
1124 if (flag[0] == '-' && flag[1] == 0) {
1125 /* "--\0" copy every arguments till the end of argv */
1126 *newargv++ = *argv++;
1127 argc--;
1128
1129 while (argc > 0) {
1130 *newargv++ = *argv++;
1131 argc--;
1132 }
1133 } else {
1134 switch (*flag) {
1135 case 's':
1136 /* -sf / -st and their parameters are ignored */
1137 if (flag[1] == 'f' || flag[1] == 't') {
1138 argc--;
1139 argv++;
1140 /* The list can't contain a negative value since the only
1141 way to know the end of this list is by looking for the
1142 next option or the end of the options */
1143 while (argc > 0 && argv[0][0] != '-') {
1144 argc--;
1145 argv++;
1146 }
William Lallemand398da622020-09-02 16:12:23 +02001147 } else {
1148 argc--;
1149 argv++;
1150
William Lallemanddf6c5a82020-06-04 17:40:23 +02001151 }
1152 break;
1153
1154 case 'x':
1155 /* this option and its parameter are ignored */
1156 argc--;
1157 argv++;
1158 if (argc > 0) {
1159 argc--;
1160 argv++;
1161 }
1162 break;
1163
1164 case 'C':
1165 case 'n':
1166 case 'm':
1167 case 'N':
1168 case 'L':
1169 case 'f':
1170 case 'p':
1171 case 'S':
1172 /* these options have only 1 parameter which must be copied and can start with a '-' */
1173 *newargv++ = *argv++;
1174 argc--;
1175 if (argc == 0)
1176 goto error;
1177 *newargv++ = *argv++;
1178 argc--;
1179 break;
1180 default:
1181 /* for other options just copy them without parameters, this is also done
1182 * for options like "--foo", but this will fail in the argument parser.
1183 * */
1184 *newargv++ = *argv++;
1185 argc--;
1186 break;
1187 }
William Lallemand73b85e72017-06-01 17:38:51 +02001188 }
1189 }
William Lallemand73b85e72017-06-01 17:38:51 +02001190 }
William Lallemand2bf6d622017-06-20 11:20:23 +02001191
William Lallemanddf6c5a82020-06-04 17:40:23 +02001192 return retargv;
1193
1194error:
1195 free(retargv);
1196 return NULL;
William Lallemand73b85e72017-06-01 17:38:51 +02001197}
1198
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001199
1200/* Performs basic random seed initialization. The main issue with this is that
1201 * srandom_r() only takes 32 bits and purposely provides a reproducible sequence,
1202 * which means that there will only be 4 billion possible random sequences once
1203 * srandom() is called, regardless of the internal state. Not calling it is
1204 * even worse as we'll always produce the same randoms sequences. What we do
1205 * here is to create an initial sequence from various entropy sources, hash it
1206 * using SHA1 and keep the resulting 160 bits available globally.
1207 *
1208 * We initialize the current process with the first 32 bits before starting the
1209 * polling loop, where all this will be changed to have process specific and
1210 * thread specific sequences.
Willy Tarreau52bf8392020-03-08 00:42:37 +01001211 *
1212 * Before starting threads, it's still possible to call random() as srandom()
1213 * is initialized from this, but after threads and/or processes are started,
1214 * only ha_random() is expected to be used to guarantee distinct sequences.
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001215 */
1216static void ha_random_boot(char *const *argv)
1217{
1218 unsigned char message[256];
1219 unsigned char *m = message;
1220 struct timeval tv;
1221 blk_SHA_CTX ctx;
1222 unsigned long l;
1223 int fd;
1224 int i;
1225
1226 /* start with current time as pseudo-random seed */
1227 gettimeofday(&tv, NULL);
1228 write_u32(m, tv.tv_sec); m += 4;
1229 write_u32(m, tv.tv_usec); m += 4;
1230
1231 /* PID and PPID add some OS-based randomness */
1232 write_u16(m, getpid()); m += 2;
1233 write_u16(m, getppid()); m += 2;
1234
1235 /* take up to 160 bits bytes from /dev/urandom if available (non-blocking) */
1236 fd = open("/dev/urandom", O_RDONLY);
1237 if (fd >= 0) {
1238 i = read(fd, m, 20);
1239 if (i > 0)
1240 m += i;
1241 close(fd);
1242 }
1243
1244 /* take up to 160 bits bytes from openssl (non-blocking) */
1245#ifdef USE_OPENSSL
1246 if (RAND_bytes(m, 20) == 1)
1247 m += 20;
1248#endif
1249
1250 /* take 160 bits from existing random in case it was already initialized */
1251 for (i = 0; i < 5; i++) {
1252 write_u32(m, random());
1253 m += 4;
1254 }
1255
1256 /* stack address (benefit form operating system's ASLR) */
1257 l = (unsigned long)&m;
1258 memcpy(m, &l, sizeof(l)); m += sizeof(l);
1259
1260 /* argv address (benefit form operating system's ASLR) */
1261 l = (unsigned long)&argv;
1262 memcpy(m, &l, sizeof(l)); m += sizeof(l);
1263
1264 /* use tv_usec again after all the operations above */
1265 gettimeofday(&tv, NULL);
1266 write_u32(m, tv.tv_usec); m += 4;
1267
1268 /*
1269 * At this point, ~84-92 bytes have been used
1270 */
1271
1272 /* finish with the hostname */
1273 strncpy((char *)m, hostname, message + sizeof(message) - m);
1274 m += strlen(hostname);
1275
1276 /* total message length */
1277 l = m - message;
1278
1279 memset(&ctx, 0, sizeof(ctx));
1280 blk_SHA1_Init(&ctx);
1281 blk_SHA1_Update(&ctx, message, l);
1282 blk_SHA1_Final(boot_seed, &ctx);
1283
1284 srandom(read_u32(boot_seed));
Willy Tarreau52bf8392020-03-08 00:42:37 +01001285 ha_random_seed(boot_seed, sizeof(boot_seed));
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001286}
1287
Willy Tarreau5a023f02019-03-01 14:19:31 +01001288/* considers splicing proxies' maxconn, computes the ideal global.maxpipes
1289 * setting, and returns it. It may return -1 meaning "unlimited" if some
1290 * unlimited proxies have been found and the global.maxconn value is not yet
1291 * set. It may also return a value greater than maxconn if it's not yet set.
1292 * Note that a value of zero means there is no need for pipes. -1 is never
1293 * returned if global.maxconn is valid.
1294 */
1295static int compute_ideal_maxpipes()
1296{
1297 struct proxy *cur;
1298 int nbfe = 0, nbbe = 0;
1299 int unlimited = 0;
1300 int pipes;
1301 int max;
1302
1303 for (cur = proxies_list; cur; cur = cur->next) {
1304 if (cur->options2 & (PR_O2_SPLIC_ANY)) {
1305 if (cur->cap & PR_CAP_FE) {
1306 max = cur->maxconn;
1307 nbfe += max;
1308 if (!max) {
1309 unlimited = 1;
1310 break;
1311 }
1312 }
1313 if (cur->cap & PR_CAP_BE) {
1314 max = cur->fullconn ? cur->fullconn : global.maxconn;
1315 nbbe += max;
1316 if (!max) {
1317 unlimited = 1;
1318 break;
1319 }
1320 }
1321 }
1322 }
1323
1324 pipes = MAX(nbfe, nbbe);
1325 if (global.maxconn) {
1326 if (pipes > global.maxconn || unlimited)
1327 pipes = global.maxconn;
1328 } else if (unlimited) {
1329 pipes = -1;
1330 }
1331
1332 return pipes >= 4 ? pipes / 4 : pipes;
1333}
1334
Willy Tarreauac350932019-03-01 15:43:14 +01001335/* considers global.maxsocks, global.maxpipes, async engines, SSL frontends and
1336 * rlimits and computes an ideal maxconn. It's meant to be called only when
1337 * maxsock contains the sum of listening FDs, before it is updated based on
Willy Tarreaudf23c0c2019-03-13 10:10:49 +01001338 * maxconn and pipes. If there are not enough FDs left, DEFAULT_MAXCONN (by
1339 * default 100) is returned as it is expected that it will even run on tight
1340 * environments, and will maintain compatibility with previous packages that
1341 * used to rely on this value as the default one. The system will emit a
1342 * warning indicating how many FDs are missing anyway if needed.
Willy Tarreauac350932019-03-01 15:43:14 +01001343 */
1344static int compute_ideal_maxconn()
1345{
1346 int ssl_sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
1347 int engine_fds = global.ssl_used_async_engines * ssl_sides;
1348 int pipes = compute_ideal_maxpipes();
Willy Tarreaub1beaa32020-03-06 10:25:31 +01001349 int remain = MAX(rlim_fd_cur_at_boot, rlim_fd_max_at_boot);
Willy Tarreauac350932019-03-01 15:43:14 +01001350 int maxconn;
1351
1352 /* we have to take into account these elements :
1353 * - number of engine_fds, which inflates the number of FD needed per
1354 * connection by this number.
1355 * - number of pipes per connection on average : for the unlimited
1356 * case, this is 0.5 pipe FDs per connection, otherwise it's a
1357 * fixed value of 2*pipes.
1358 * - two FDs per connection
1359 */
1360
1361 /* subtract listeners and checks */
1362 remain -= global.maxsock;
1363
Willy Tarreau3f200852019-03-14 19:13:17 +01001364 /* one epoll_fd/kqueue_fd per thread */
1365 remain -= global.nbthread;
1366
1367 /* one wake-up pipe (2 fd) per thread */
1368 remain -= 2 * global.nbthread;
1369
Willy Tarreauac350932019-03-01 15:43:14 +01001370 /* Fixed pipes values : we only subtract them if they're not larger
1371 * than the remaining FDs because pipes are optional.
1372 */
1373 if (pipes >= 0 && pipes * 2 < remain)
1374 remain -= pipes * 2;
1375
1376 if (pipes < 0) {
1377 /* maxsock = maxconn * 2 + maxconn/4 * 2 + maxconn * engine_fds.
1378 * = maxconn * (2 + 0.5 + engine_fds)
1379 * = maxconn * (4 + 1 + 2*engine_fds) / 2
1380 */
1381 maxconn = 2 * remain / (5 + 2 * engine_fds);
1382 } else {
1383 /* maxsock = maxconn * 2 + maxconn * engine_fds.
1384 * = maxconn * (2 + engine_fds)
1385 */
1386 maxconn = remain / (2 + engine_fds);
1387 }
1388
Willy Tarreaudf23c0c2019-03-13 10:10:49 +01001389 return MAX(maxconn, DEFAULT_MAXCONN);
Willy Tarreauac350932019-03-01 15:43:14 +01001390}
1391
Willy Tarreaua409f302020-03-10 17:08:53 +01001392/* computes the estimated maxsock value for the given maxconn based on the
1393 * possibly set global.maxpipes and existing partial global.maxsock. It may
1394 * temporarily change global.maxconn for the time needed to propagate the
1395 * computations, and will reset it.
1396 */
1397static int compute_ideal_maxsock(int maxconn)
1398{
1399 int maxpipes = global.maxpipes;
1400 int maxsock = global.maxsock;
1401
1402
1403 if (!maxpipes) {
1404 int old_maxconn = global.maxconn;
1405
1406 global.maxconn = maxconn;
1407 maxpipes = compute_ideal_maxpipes();
1408 global.maxconn = old_maxconn;
1409 }
1410
1411 maxsock += maxconn * 2; /* each connection needs two sockets */
1412 maxsock += maxpipes * 2; /* each pipe needs two FDs */
1413 maxsock += global.nbthread; /* one epoll_fd/kqueue_fd per thread */
1414 maxsock += 2 * global.nbthread; /* one wake-up pipe (2 fd) per thread */
1415
1416 /* compute fd used by async engines */
1417 if (global.ssl_used_async_engines) {
1418 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
1419
1420 maxsock += maxconn * sides * global.ssl_used_async_engines;
1421 }
1422 return maxsock;
1423}
1424
Thayne McCombs8f0cc5c2021-01-07 21:35:52 -07001425/* Tests if it is possible to set the current process's RLIMIT_NOFILE to
Willy Tarreau304e17e2020-03-10 17:54:54 +01001426 * <maxsock>, then sets it back to the previous value. Returns non-zero if the
1427 * value is accepted, non-zero otherwise. This is used to determine if an
1428 * automatic limit may be applied or not. When it is not, the caller knows that
1429 * the highest we can do is the rlim_max at boot. In case of error, we return
1430 * that the setting is possible, so that we defer the error processing to the
1431 * final stage in charge of enforcing this.
1432 */
1433static int check_if_maxsock_permitted(int maxsock)
1434{
1435 struct rlimit orig_limit, test_limit;
1436 int ret;
1437
1438 if (getrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1439 return 1;
1440
1441 /* don't go further if we can't even set to what we have */
1442 if (setrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1443 return 1;
1444
1445 test_limit.rlim_max = MAX(maxsock, orig_limit.rlim_max);
1446 test_limit.rlim_cur = test_limit.rlim_max;
1447 ret = setrlimit(RLIMIT_NOFILE, &test_limit);
1448
1449 if (setrlimit(RLIMIT_NOFILE, &orig_limit) != 0)
1450 return 1;
1451
1452 return ret == 0;
1453}
1454
Amaury Denoyelle484454d2021-05-05 16:18:45 +02001455void mark_tainted(const enum tainted_flags flag)
1456{
1457 HA_ATOMIC_OR(&tainted, flag);
1458}
1459
1460unsigned int get_tainted()
1461{
1462 int tainted_state;
1463 HA_ATOMIC_STORE(&tainted_state, tainted);
1464 return tainted_state;
1465}
Willy Tarreau304e17e2020-03-10 17:54:54 +01001466
William Lallemand73b85e72017-06-01 17:38:51 +02001467/*
Willy Tarreaubaaee002006-06-26 02:48:02 +02001468 * This function initializes all the necessary variables. It only returns
1469 * if everything is OK. If something fails, it exits.
1470 */
Willy Tarreau1b5af7c2016-12-21 18:19:57 +01001471static void init(int argc, char **argv)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001472{
Willy Tarreaubaaee002006-06-26 02:48:02 +02001473 int arg_mode = 0; /* MODE_DEBUG, ... */
Willy Tarreaubaaee002006-06-26 02:48:02 +02001474 char *tmp;
1475 char *cfg_pidfile = NULL;
Willy Tarreau058e9072009-07-20 09:30:05 +02001476 int err_code = 0;
Maxime de Roucy0f503922016-05-13 23:52:55 +02001477 char *err_msg = NULL;
Willy Tarreau477ecd82010-01-03 21:12:30 +01001478 struct wordlist *wl;
Kevinm48936af2010-12-22 16:08:21 +00001479 char *progname;
Willy Tarreau576132e2011-09-10 19:26:56 +02001480 char *change_dir = NULL;
Christopher Fauletd7c91962015-04-30 11:48:27 +02001481 struct proxy *px;
Willy Tarreaue6945732016-12-21 19:57:00 +01001482 struct post_check_fct *pcf;
Willy Tarreauac350932019-03-01 15:43:14 +01001483 int ideal_maxconn;
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001484 char *check_condition = NULL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001485
Christopher Faulete3a5e352017-10-24 13:53:54 +02001486 global.mode = MODE_STARTING;
William Lallemand00417412020-06-05 14:08:41 +02001487 old_argv = copy_argv(argc, argv);
1488 if (!old_argv) {
William Lallemanddf6c5a82020-06-04 17:40:23 +02001489 ha_alert("failed to copy argv.\n");
1490 exit(1);
1491 }
William Lallemand73b85e72017-06-01 17:38:51 +02001492
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001493 if (!init_trash_buffers(1)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001494 ha_alert("failed to initialize trash buffers.\n");
Christopher Faulet748919a2017-07-26 14:59:46 +02001495 exit(1);
1496 }
David du Colombier7af46052012-05-16 14:16:48 +02001497
Emeric Brun2b920a12010-09-23 18:30:22 +02001498 /* NB: POSIX does not make it mandatory for gethostname() to NULL-terminate
1499 * the string in case of truncation, and at least FreeBSD appears not to do
1500 * it.
1501 */
1502 memset(hostname, 0, sizeof(hostname));
1503 gethostname(hostname, sizeof(hostname) - 1);
Dragan Dosen4f014152020-06-18 16:56:47 +02001504
1505 if ((localpeer = strdup(hostname)) == NULL) {
1506 ha_alert("Cannot allocate memory for local peer.\n");
1507 exit(EXIT_FAILURE);
1508 }
William Lallemanddaf4cd22018-04-17 16:46:13 +02001509 setenv("HAPROXY_LOCALPEER", localpeer, 1);
Emeric Brun2b920a12010-09-23 18:30:22 +02001510
William Lallemand24c928c2020-01-14 17:58:18 +01001511 /* we were in mworker mode, we should restart in mworker mode */
1512 if (getenv("HAPROXY_MWORKER_REEXEC") != NULL)
1513 global.mode |= MODE_MWORKER;
1514
Willy Tarreaubaaee002006-06-26 02:48:02 +02001515 /*
1516 * Initialize the previously static variables.
1517 */
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001518
Willy Tarreau173d9952018-01-26 21:48:23 +01001519 totalconn = actconn = listeners = stopping = 0;
Cyril Bonté203ec5a2017-03-23 22:44:13 +01001520 killed = 0;
Christopher Fauletcd7879a2017-10-27 13:53:47 +02001521
Willy Tarreaubaaee002006-06-26 02:48:02 +02001522
1523#ifdef HAPROXY_MEMMAX
Willy Tarreau70060452015-12-14 12:46:07 +01001524 global.rlimit_memmax_all = HAPROXY_MEMMAX;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001525#endif
1526
Benoit GARNIERb413c2a2016-03-27 11:08:03 +02001527 tzset();
Willy Tarreau55542642021-10-08 09:33:24 +02001528 clock_init_process_date();
Willy Tarreaubaaee002006-06-26 02:48:02 +02001529 start_date = now;
1530
Willy Tarreau6c3a6812020-03-06 18:57:15 +01001531 ha_random_boot(argv);
Willy Tarreau84310e22014-02-14 11:59:04 +01001532
Willy Tarreau8ed669b2013-01-11 15:49:37 +01001533 if (init_acl() != 0)
1534 exit(1);
Willy Tarreaub6b3df32018-11-26 16:31:20 +01001535
Amaury Denoyellec593bcd2021-05-19 15:35:29 +02001536#ifdef USE_OPENSSL
1537 /* Initialize the random generator.
1538 * Must be called before chroot for access to /dev/urandom
1539 */
1540 if (!ssl_initialize_random()) {
1541 ha_alert("OpenSSL random data generator initialization failed.\n");
1542 exit(1);
1543 }
1544#endif
1545
Thierry FOURNIER6f1fd482015-01-23 14:06:13 +01001546 /* Initialise lua. */
1547 hlua_init();
Thierry FOURNIER6f1fd482015-01-23 14:06:13 +01001548
Christopher Fauletff2613e2016-11-09 11:36:17 +01001549 /* Initialize process vars */
Willy Tarreaub7bfcb32021-08-31 08:13:25 +02001550 vars_init_head(&proc_vars, SCOPE_PROC);
Christopher Fauletff2613e2016-11-09 11:36:17 +01001551
Willy Tarreau43b78992009-01-25 15:42:27 +01001552 global.tune.options |= GTUNE_USE_SELECT; /* select() is always available */
Willy Tarreaue5733232019-05-22 19:24:06 +02001553#if defined(USE_POLL)
Willy Tarreau43b78992009-01-25 15:42:27 +01001554 global.tune.options |= GTUNE_USE_POLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001555#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001556#if defined(USE_EPOLL)
Willy Tarreau43b78992009-01-25 15:42:27 +01001557 global.tune.options |= GTUNE_USE_EPOLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001558#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001559#if defined(USE_KQUEUE)
Willy Tarreau43b78992009-01-25 15:42:27 +01001560 global.tune.options |= GTUNE_USE_KQUEUE;
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001561#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001562#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00001563 global.tune.options |= GTUNE_USE_EVPORTS;
1564#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001565#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +01001566 global.tune.options |= GTUNE_USE_SPLICE;
1567#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +02001568#if defined(USE_GETADDRINFO)
1569 global.tune.options |= GTUNE_USE_GAI;
1570#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +00001571#if defined(SO_REUSEPORT)
1572 global.tune.options |= GTUNE_USE_REUSEPORT;
1573#endif
Willy Tarreau76cc6992020-07-01 18:49:24 +02001574#ifdef USE_THREAD
1575 global.tune.options |= GTUNE_IDLE_POOL_SHARED;
1576#endif
William Dauchya5194602020-03-28 19:29:58 +01001577 global.tune.options |= GTUNE_STRICT_LIMITS;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001578
1579 pid = getpid();
1580 progname = *argv;
1581 while ((tmp = strchr(progname, '/')) != NULL)
1582 progname = tmp + 1;
1583
Kevinm48936af2010-12-22 16:08:21 +00001584 /* the process name is used for the logs only */
Eric Salama7cea6062020-10-02 11:58:19 +02001585 chunk_initlen(&global.log_tag, strdup(progname), strlen(progname), strlen(progname));
1586 if (b_orig(&global.log_tag) == NULL) {
1587 chunk_destroy(&global.log_tag);
1588 ha_alert("Cannot allocate memory for log_tag.\n");
1589 exit(EXIT_FAILURE);
1590 }
Kevinm48936af2010-12-22 16:08:21 +00001591
Willy Tarreaubaaee002006-06-26 02:48:02 +02001592 argc--; argv++;
1593 while (argc > 0) {
1594 char *flag;
1595
1596 if (**argv == '-') {
1597 flag = *argv+1;
1598
1599 /* 1 arg */
1600 if (*flag == 'v') {
1601 display_version();
Willy Tarreau7b066db2007-12-02 11:28:59 +01001602 if (flag[1] == 'v') /* -vv */
1603 display_build_opts();
Willy Tarreaubaaee002006-06-26 02:48:02 +02001604 exit(0);
1605 }
Willy Tarreaue5733232019-05-22 19:24:06 +02001606#if defined(USE_EPOLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001607 else if (*flag == 'd' && flag[1] == 'e')
Willy Tarreau43b78992009-01-25 15:42:27 +01001608 global.tune.options &= ~GTUNE_USE_EPOLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001609#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001610#if defined(USE_POLL)
Willy Tarreaubaaee002006-06-26 02:48:02 +02001611 else if (*flag == 'd' && flag[1] == 'p')
Willy Tarreau43b78992009-01-25 15:42:27 +01001612 global.tune.options &= ~GTUNE_USE_POLL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001613#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001614#if defined(USE_KQUEUE)
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001615 else if (*flag == 'd' && flag[1] == 'k')
Willy Tarreau43b78992009-01-25 15:42:27 +01001616 global.tune.options &= ~GTUNE_USE_KQUEUE;
Willy Tarreau1e63130a2007-04-09 12:03:06 +02001617#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001618#if defined(USE_EVPORTS)
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00001619 else if (*flag == 'd' && flag[1] == 'v')
1620 global.tune.options &= ~GTUNE_USE_EVPORTS;
1621#endif
Willy Tarreaue5733232019-05-22 19:24:06 +02001622#if defined(USE_LINUX_SPLICE)
Willy Tarreau3ab68cf2009-01-25 16:03:28 +01001623 else if (*flag == 'd' && flag[1] == 'S')
1624 global.tune.options &= ~GTUNE_USE_SPLICE;
1625#endif
Nenad Merdanovic88afe032014-04-14 15:56:58 +02001626#if defined(USE_GETADDRINFO)
1627 else if (*flag == 'd' && flag[1] == 'G')
1628 global.tune.options &= ~GTUNE_USE_GAI;
1629#endif
Lukas Tribusa0bcbdc2016-09-12 21:42:20 +00001630#if defined(SO_REUSEPORT)
1631 else if (*flag == 'd' && flag[1] == 'R')
1632 global.tune.options &= ~GTUNE_USE_REUSEPORT;
1633#endif
Emeric Brun850efd52014-01-29 12:24:34 +01001634 else if (*flag == 'd' && flag[1] == 'V')
1635 global.ssl_server_verify = SSL_SERVER_VERIFY_NONE;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001636 else if (*flag == 'V')
1637 arg_mode |= MODE_VERBOSE;
1638 else if (*flag == 'd' && flag[1] == 'b')
1639 arg_mode |= MODE_FOREGROUND;
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +02001640 else if (*flag == 'd' && flag[1] == 'D')
1641 arg_mode |= MODE_DIAG;
Willy Tarreau3eb10b82020-04-15 16:42:39 +02001642 else if (*flag == 'd' && flag[1] == 'W')
1643 arg_mode |= MODE_ZERO_WARNING;
Willy Tarreau6e064432012-05-08 15:40:42 +02001644 else if (*flag == 'd' && flag[1] == 'M')
1645 mem_poison_byte = flag[2] ? strtol(flag + 2, NULL, 0) : 'P';
Willy Tarreau3eed10e2016-11-07 21:03:16 +01001646 else if (*flag == 'd' && flag[1] == 'r')
1647 global.tune.options |= GTUNE_RESOLVE_DONTFAIL;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001648 else if (*flag == 'd')
1649 arg_mode |= MODE_DEBUG;
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001650 else if (*flag == 'c' && flag[1] == 'c') {
1651 arg_mode |= MODE_CHECK_CONDITION;
1652 argv++;
1653 argc--;
1654 check_condition = *argv;
1655 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001656 else if (*flag == 'c')
1657 arg_mode |= MODE_CHECK;
William Lallemand095ba4c2017-06-01 17:38:50 +02001658 else if (*flag == 'D')
Willy Tarreau6bde87b2009-05-18 16:29:51 +02001659 arg_mode |= MODE_DAEMON;
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001660 else if (*flag == 'W' && flag[1] == 's') {
Lukas Tribusf46bf952017-11-21 12:39:34 +01001661 arg_mode |= MODE_MWORKER | MODE_FOREGROUND;
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001662#if defined(USE_SYSTEMD)
1663 global.tune.options |= GTUNE_USE_SYSTEMD;
1664#else
Christopher Faulet767a84b2017-11-24 16:50:31 +01001665 ha_alert("master-worker mode with systemd support (-Ws) requested, but not compiled. Use master-worker mode (-W) if you are not using Type=notify in your unit file or recompile with USE_SYSTEMD=1.\n\n");
Tim Duesterhusd6942c82017-11-20 15:58:35 +01001666 usage(progname);
1667#endif
1668 }
William Lallemand095ba4c2017-06-01 17:38:50 +02001669 else if (*flag == 'W')
1670 arg_mode |= MODE_MWORKER;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001671 else if (*flag == 'q')
1672 arg_mode |= MODE_QUIET;
Olivier Houchardf73629d2017-04-05 22:33:04 +02001673 else if (*flag == 'x') {
William Lallemand4f71d302020-06-04 23:41:29 +02001674 if (argc <= 1) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001675 ha_alert("Unix socket path expected with the -x flag\n\n");
William Lallemand45eff442017-06-19 15:57:55 +02001676 usage(progname);
Olivier Houchardf73629d2017-04-05 22:33:04 +02001677 }
William Lallemand4fc09692017-06-19 16:37:19 +02001678 if (old_unixsocket)
Christopher Faulet767a84b2017-11-24 16:50:31 +01001679 ha_warning("-x option already set, overwriting the value\n");
Olivier Houchardf73629d2017-04-05 22:33:04 +02001680 old_unixsocket = argv[1];
William Lallemand4fc09692017-06-19 16:37:19 +02001681
Olivier Houchardf73629d2017-04-05 22:33:04 +02001682 argv++;
1683 argc--;
1684 }
William Lallemande7361152018-10-26 14:47:36 +02001685 else if (*flag == 'S') {
1686 struct wordlist *c;
1687
William Lallemanda6b32492020-06-04 23:49:20 +02001688 if (argc <= 1) {
William Lallemande7361152018-10-26 14:47:36 +02001689 ha_alert("Socket and optional bind parameters expected with the -S flag\n");
1690 usage(progname);
1691 }
1692 if ((c = malloc(sizeof(*c))) == NULL || (c->s = strdup(argv[1])) == NULL) {
1693 ha_alert("Cannot allocate memory\n");
1694 exit(EXIT_FAILURE);
1695 }
Willy Tarreau2b718102021-04-21 07:32:39 +02001696 LIST_INSERT(&mworker_cli_conf, &c->list);
William Lallemande7361152018-10-26 14:47:36 +02001697
1698 argv++;
1699 argc--;
1700 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001701 else if (*flag == 's' && (flag[1] == 'f' || flag[1] == 't')) {
1702 /* list of pids to finish ('f') or terminate ('t') */
1703
1704 if (flag[1] == 'f')
1705 oldpids_sig = SIGUSR1; /* finish then exit */
1706 else
1707 oldpids_sig = SIGTERM; /* terminate immediately */
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001708 while (argc > 1 && argv[1][0] != '-') {
Chris Lane236062f2018-02-05 23:15:44 +00001709 char * endptr = NULL;
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001710 oldpids = realloc(oldpids, (nb_oldpids + 1) * sizeof(int));
1711 if (!oldpids) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001712 ha_alert("Cannot allocate old pid : out of memory.\n");
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001713 exit(1);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001714 }
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001715 argc--; argv++;
Chris Lane236062f2018-02-05 23:15:44 +00001716 errno = 0;
1717 oldpids[nb_oldpids] = strtol(*argv, &endptr, 10);
1718 if (errno) {
1719 ha_alert("-%2s option: failed to parse {%s}: %s\n",
1720 flag,
1721 *argv, strerror(errno));
1722 exit(1);
1723 } else if (endptr && strlen(endptr)) {
Willy Tarreau90807112020-02-25 08:16:33 +01001724 while (isspace((unsigned char)*endptr)) endptr++;
Aurélien Nephtali39b89882018-02-17 20:53:11 +01001725 if (*endptr != 0) {
Chris Lane236062f2018-02-05 23:15:44 +00001726 ha_alert("-%2s option: some bytes unconsumed in PID list {%s}\n",
1727 flag, endptr);
1728 exit(1);
Aurélien Nephtali39b89882018-02-17 20:53:11 +01001729 }
Chris Lane236062f2018-02-05 23:15:44 +00001730 }
Willy Tarreauc6ca1aa2015-10-08 11:32:32 +02001731 if (oldpids[nb_oldpids] <= 0)
1732 usage(progname);
1733 nb_oldpids++;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001734 }
1735 }
Willy Tarreaua088d312015-10-08 11:58:48 +02001736 else if (flag[0] == '-' && flag[1] == 0) { /* "--" */
1737 /* now that's a cfgfile list */
1738 argv++; argc--;
1739 while (argc > 0) {
Maxime de Roucy0f503922016-05-13 23:52:55 +02001740 if (!list_append_word(&cfg_cfgfiles, *argv, &err_msg)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001741 ha_alert("Cannot load configuration file/directory %s : %s\n",
1742 *argv,
1743 err_msg);
Willy Tarreaua088d312015-10-08 11:58:48 +02001744 exit(1);
1745 }
Willy Tarreaua088d312015-10-08 11:58:48 +02001746 argv++; argc--;
1747 }
1748 break;
1749 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02001750 else { /* >=2 args */
1751 argv++; argc--;
1752 if (argc == 0)
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001753 usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001754
1755 switch (*flag) {
Willy Tarreau576132e2011-09-10 19:26:56 +02001756 case 'C' : change_dir = *argv; break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001757 case 'n' : cfg_maxconn = atol(*argv); break;
Willy Tarreau70060452015-12-14 12:46:07 +01001758 case 'm' : global.rlimit_memmax_all = atol(*argv); break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001759 case 'N' : cfg_maxpconn = atol(*argv); break;
William Lallemanddaf4cd22018-04-17 16:46:13 +02001760 case 'L' :
Dragan Dosen4f014152020-06-18 16:56:47 +02001761 free(localpeer);
1762 if ((localpeer = strdup(*argv)) == NULL) {
1763 ha_alert("Cannot allocate memory for local peer.\n");
1764 exit(EXIT_FAILURE);
1765 }
William Lallemanddaf4cd22018-04-17 16:46:13 +02001766 setenv("HAPROXY_LOCALPEER", localpeer, 1);
Dragan Dosen13cd54c2020-06-18 18:24:05 +02001767 global.localpeer_cmdline = 1;
William Lallemanddaf4cd22018-04-17 16:46:13 +02001768 break;
Willy Tarreau5d01a632009-06-22 16:02:30 +02001769 case 'f' :
Maxime de Roucy0f503922016-05-13 23:52:55 +02001770 if (!list_append_word(&cfg_cfgfiles, *argv, &err_msg)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001771 ha_alert("Cannot load configuration file/directory %s : %s\n",
1772 *argv,
1773 err_msg);
Willy Tarreau5d01a632009-06-22 16:02:30 +02001774 exit(1);
1775 }
Willy Tarreau5d01a632009-06-22 16:02:30 +02001776 break;
Willy Tarreaubaaee002006-06-26 02:48:02 +02001777 case 'p' : cfg_pidfile = *argv; break;
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001778 default: usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001779 }
1780 }
1781 }
1782 else
Willy Tarreau3bafcdc2011-09-10 19:20:23 +02001783 usage(progname);
Willy Tarreaubaaee002006-06-26 02:48:02 +02001784 argv++; argc--;
1785 }
1786
Christopher Faulete3a5e352017-10-24 13:53:54 +02001787 global.mode |= (arg_mode & (MODE_DAEMON | MODE_MWORKER | MODE_FOREGROUND | MODE_VERBOSE
Amaury Denoyelle7b01a8d2021-03-29 10:29:07 +02001788 | MODE_QUIET | MODE_CHECK | MODE_DEBUG | MODE_ZERO_WARNING
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001789 | MODE_DIAG | MODE_CHECK_CONDITION));
Willy Tarreaubaaee002006-06-26 02:48:02 +02001790
William Lallemand944e6192018-11-21 15:48:31 +01001791 if (getenv("HAPROXY_MWORKER_WAIT_ONLY")) {
William Lallemandcb11fd22017-06-01 17:38:52 +02001792 unsetenv("HAPROXY_MWORKER_WAIT_ONLY");
William Lallemand944e6192018-11-21 15:48:31 +01001793 global.mode |= MODE_MWORKER_WAIT;
1794 global.mode &= ~MODE_MWORKER;
William Lallemandcb11fd22017-06-01 17:38:52 +02001795 }
1796
Willy Tarreau26146192021-07-21 10:01:36 +02001797 if ((global.mode & (MODE_MWORKER | MODE_CHECK | MODE_CHECK_CONDITION)) == MODE_MWORKER &&
1798 (getenv("HAPROXY_MWORKER_REEXEC") != NULL)) {
William Lallemandcb11fd22017-06-01 17:38:52 +02001799 atexit_flag = 1;
1800 atexit(reexec_on_failure);
1801 }
1802
Willy Tarreau576132e2011-09-10 19:26:56 +02001803 if (change_dir && chdir(change_dir) < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01001804 ha_alert("Could not change to directory %s : %s\n", change_dir, strerror(errno));
Willy Tarreau576132e2011-09-10 19:26:56 +02001805 exit(1);
1806 }
1807
Willy Tarreaubaaee002006-06-26 02:48:02 +02001808 global.maxsock = 10; /* reserve 10 fds ; will be incremented by socket eaters */
Willy Tarreau915e1eb2009-06-22 15:48:36 +02001809
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001810#ifdef USE_CPU_AFFINITY
1811 {
1812 int i;
Willy Tarreau44ea6312021-06-15 08:57:56 +02001813 ha_cpuset_zero(&cpu_map.proc);
1814 ha_cpuset_zero(&cpu_map.proc_t1);
Willy Tarreau26f42a02021-05-14 08:26:38 +02001815 for (i = 0; i < MAX_THREADS; ++i) {
Amaury Denoyellefc6ac532021-04-27 10:46:36 +02001816 ha_cpuset_zero(&cpu_map.thread[i]);
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001817 }
Amaury Denoyelle982fb532021-04-21 18:39:58 +02001818 }
Amaury Denoyellea6f9c5d2021-04-23 16:58:08 +02001819#endif
Amaury Denoyelle982fb532021-04-21 18:39:58 +02001820
Amaury Denoyelle11124302021-06-04 18:22:08 +02001821 usermsgs_clr("config");
1822
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001823 if (global.mode & MODE_CHECK_CONDITION) {
1824 int result;
1825
1826 uint32_t err;
1827 const char *errptr;
1828 char *errmsg = NULL;
1829
1830 char *args[MAX_LINE_ARGS+1];
1831 int arg = sizeof(args) / sizeof(*args);
1832 size_t outlen = strlen(check_condition) + 1;
Willy Tarreauc8194c32021-07-16 16:38:58 +02001833 char *w;
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001834
1835 err = parse_line(check_condition, check_condition, &outlen, args, &arg,
Willy Tarreaua87e7822021-07-16 19:14:54 +02001836 PARSE_OPT_ENV | PARSE_OPT_WORD_EXPAND | PARSE_OPT_DQUOTE | PARSE_OPT_SQUOTE | PARSE_OPT_BKSLASH,
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001837 &errptr);
1838
1839 if (err & PARSE_ERR_QUOTE) {
1840 ha_alert("Syntax Error in condition: Unmatched quote.\n");
1841 exit(2);
1842 }
1843
1844 if (err & PARSE_ERR_HEX) {
1845 ha_alert("Syntax Error in condition: Truncated or invalid hexadecimal sequence.\n");
1846 exit(2);
1847 }
1848
1849 if (err & (PARSE_ERR_TOOLARGE|PARSE_ERR_OVERLAP)) {
1850 ha_alert("Error in condition: Line too long.\n");
1851 exit(2);
1852 }
1853
Willy Tarreauc8194c32021-07-16 16:38:58 +02001854 if (err & PARSE_ERR_TOOMANY) {
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001855 ha_alert("Error in condition: Too many words.\n");
1856 exit(2);
1857 }
1858
1859 if (err) {
1860 ha_alert("Unhandled error in condition, please report this to the developers.\n");
1861 exit(2);
1862 }
1863
Willy Tarreauc8194c32021-07-16 16:38:58 +02001864 /* remerge all words into a single expression */
1865 for (w = *args; (w += strlen(w)) < check_condition + outlen - 1; *w = ' ')
1866 ;
1867
Maximilian Maderfc0cceb2021-06-06 00:50:22 +02001868 result = cfg_eval_condition(args, &errmsg, &errptr);
1869
1870 if (result < 0) {
1871 if (errmsg)
1872 ha_alert("Failed to evaluate condition: %s\n", errmsg);
1873
1874 exit(2);
1875 }
1876
1877 exit(result ? 0 : 1);
1878 }
1879
William Lallemand944e6192018-11-21 15:48:31 +01001880 /* in wait mode, we don't try to read the configuration files */
1881 if (!(global.mode & MODE_MWORKER_WAIT)) {
Christopher Faulet4e366822021-01-12 18:57:38 +01001882 char *env_cfgfiles = NULL;
1883 int env_err = 0;
Willy Tarreauc4382422009-12-06 13:10:44 +01001884
William Lallemand944e6192018-11-21 15:48:31 +01001885 /* handle cfgfiles that are actually directories */
1886 cfgfiles_expand_directories();
1887
1888 if (LIST_ISEMPTY(&cfg_cfgfiles))
1889 usage(progname);
1890
1891
1892 list_for_each_entry(wl, &cfg_cfgfiles, list) {
1893 int ret;
1894
Christopher Faulet4e366822021-01-12 18:57:38 +01001895 if (env_err == 0) {
1896 if (!memprintf(&env_cfgfiles, "%s%s%s",
1897 (env_cfgfiles ? env_cfgfiles : ""),
1898 (env_cfgfiles ? ";" : ""), wl->s))
1899 env_err = 1;
1900 }
William Lallemand7b302d82019-05-20 11:15:37 +02001901
William Lallemand944e6192018-11-21 15:48:31 +01001902 ret = readcfgfile(wl->s);
1903 if (ret == -1) {
1904 ha_alert("Could not open configuration file %s : %s\n",
1905 wl->s, strerror(errno));
Christopher Faulet4e366822021-01-12 18:57:38 +01001906 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001907 exit(1);
1908 }
1909 if (ret & (ERR_ABORT|ERR_FATAL))
1910 ha_alert("Error(s) found in configuration file : %s\n", wl->s);
1911 err_code |= ret;
Christopher Faulet4e366822021-01-12 18:57:38 +01001912 if (err_code & ERR_ABORT) {
1913 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001914 exit(1);
Christopher Faulet4e366822021-01-12 18:57:38 +01001915 }
Willy Tarreauc4382422009-12-06 13:10:44 +01001916 }
Krzysztof Oledzkib304dc72007-10-14 23:40:01 +02001917
William Lallemand944e6192018-11-21 15:48:31 +01001918 /* do not try to resolve arguments nor to spot inconsistencies when
1919 * the configuration contains fatal errors caused by files not found
1920 * or failed memory allocations.
1921 */
1922 if (err_code & (ERR_ABORT|ERR_FATAL)) {
1923 ha_alert("Fatal errors found in configuration.\n");
Christopher Faulet4e366822021-01-12 18:57:38 +01001924 free(env_cfgfiles);
William Lallemand944e6192018-11-21 15:48:31 +01001925 exit(1);
1926 }
Christopher Faulet4e366822021-01-12 18:57:38 +01001927 if (env_err) {
1928 ha_alert("Could not allocate memory for HAPROXY_CFGFILES env variable\n");
1929 exit(1);
1930 }
1931 setenv("HAPROXY_CFGFILES", env_cfgfiles, 1);
1932 free(env_cfgfiles);
William Lallemand7b302d82019-05-20 11:15:37 +02001933
Willy Tarreaub83dc3d2017-04-19 11:24:07 +02001934 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001935 if (global.mode & MODE_MWORKER) {
William Lallemand16dd1b32018-11-19 18:46:18 +01001936 struct mworker_proc *tmproc;
1937
William Lallemand482f9a92019-04-12 16:15:00 +02001938 setenv("HAPROXY_MWORKER", "1", 1);
1939
William Lallemand16dd1b32018-11-19 18:46:18 +01001940 if (getenv("HAPROXY_MWORKER_REEXEC") == NULL) {
1941
William Lallemandf3a86832019-04-01 11:29:58 +02001942 tmproc = calloc(1, sizeof(*tmproc));
William Lallemand16dd1b32018-11-19 18:46:18 +01001943 if (!tmproc) {
1944 ha_alert("Cannot allocate process structures.\n");
1945 exit(EXIT_FAILURE);
1946 }
William Lallemand8f7069a2019-04-12 16:09:23 +02001947 tmproc->options |= PROC_O_TYPE_MASTER; /* master */
William Lallemand16dd1b32018-11-19 18:46:18 +01001948 tmproc->reloads = 0;
William Lallemand16dd1b32018-11-19 18:46:18 +01001949 tmproc->pid = pid;
1950 tmproc->timestamp = start_date.tv_sec;
1951 tmproc->ipc_fd[0] = -1;
1952 tmproc->ipc_fd[1] = -1;
1953
1954 proc_self = tmproc;
1955
Willy Tarreau2b718102021-04-21 07:32:39 +02001956 LIST_APPEND(&proc_list, &tmproc->list);
William Lallemand16dd1b32018-11-19 18:46:18 +01001957 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001958
Willy Tarreau6185a032021-06-15 08:02:06 +02001959 tmproc = calloc(1, sizeof(*tmproc));
1960 if (!tmproc) {
1961 ha_alert("Cannot allocate process structures.\n");
1962 exit(EXIT_FAILURE);
1963 }
William Lallemandce83b4a2018-10-26 14:47:30 +02001964
Willy Tarreau6185a032021-06-15 08:02:06 +02001965 tmproc->options |= PROC_O_TYPE_WORKER; /* worker */
1966 tmproc->pid = -1;
1967 tmproc->reloads = 0;
1968 tmproc->timestamp = -1;
Willy Tarreau6185a032021-06-15 08:02:06 +02001969 tmproc->ipc_fd[0] = -1;
1970 tmproc->ipc_fd[1] = -1;
William Lallemandce83b4a2018-10-26 14:47:30 +02001971
Willy Tarreau6185a032021-06-15 08:02:06 +02001972 if (mworker_cli_sockpair_new(tmproc, 0) < 0) {
1973 exit(EXIT_FAILURE);
William Lallemandce83b4a2018-10-26 14:47:30 +02001974 }
Willy Tarreau6185a032021-06-15 08:02:06 +02001975
1976 LIST_APPEND(&proc_list, &tmproc->list);
William Lallemand944e6192018-11-21 15:48:31 +01001977 }
1978 if (global.mode & (MODE_MWORKER|MODE_MWORKER_WAIT)) {
1979 struct wordlist *it, *c;
1980
Remi Tricot-Le Breton1f4fa902021-05-19 10:45:12 +02001981 /* get the info of the children in the env */
1982 if (mworker_env_to_proc_list() < 0) {
1983 exit(EXIT_FAILURE);
1984 }
William Lallemande7361152018-10-26 14:47:36 +02001985
William Lallemand550db6d2018-11-06 17:37:12 +01001986 if (!LIST_ISEMPTY(&mworker_cli_conf)) {
William Lallemande7361152018-10-26 14:47:36 +02001987
William Lallemand550db6d2018-11-06 17:37:12 +01001988 if (mworker_cli_proxy_create() < 0) {
William Lallemande7361152018-10-26 14:47:36 +02001989 ha_alert("Can't create the master's CLI.\n");
1990 exit(EXIT_FAILURE);
1991 }
William Lallemande7361152018-10-26 14:47:36 +02001992
William Lallemand550db6d2018-11-06 17:37:12 +01001993 list_for_each_entry_safe(c, it, &mworker_cli_conf, list) {
1994
1995 if (mworker_cli_proxy_new_listener(c->s) < 0) {
1996 ha_alert("Can't create the master's CLI.\n");
1997 exit(EXIT_FAILURE);
1998 }
Willy Tarreau2b718102021-04-21 07:32:39 +02001999 LIST_DELETE(&c->list);
William Lallemand550db6d2018-11-06 17:37:12 +01002000 free(c->s);
2001 free(c);
2002 }
2003 }
William Lallemandce83b4a2018-10-26 14:47:30 +02002004 }
2005
Eric Salama5ba83352021-03-16 15:11:17 +01002006 if (!LIST_ISEMPTY(&mworker_cli_conf) && !(arg_mode & MODE_MWORKER)) {
2007 ha_warning("a master CLI socket was defined, but master-worker mode (-W) is not enabled.\n");
2008 }
2009
Christopher Faulet27c8d202021-10-13 09:50:53 +02002010 /* destroy unreferenced defaults proxies */
2011 proxy_destroy_all_unref_defaults();
2012
Willy Tarreaue90904d2021-02-12 14:08:31 +01002013
Willy Tarreaubb925012009-07-23 13:36:36 +02002014 err_code |= check_config_validity();
Christopher Fauletc1692962019-08-12 09:51:07 +02002015 for (px = proxies_list; px; px = px->next) {
2016 struct server *srv;
2017 struct post_proxy_check_fct *ppcf;
2018 struct post_server_check_fct *pscf;
2019
Christopher Fauletdfd10ab2021-10-06 14:24:19 +02002020 if (px->flags & (PR_FL_DISABLED|PR_FL_STOPPED))
Christopher Fauletd5bd8242020-11-02 16:20:13 +01002021 continue;
2022
Christopher Fauletc1692962019-08-12 09:51:07 +02002023 list_for_each_entry(pscf, &post_server_check_list, list) {
2024 for (srv = px->srv; srv; srv = srv->next)
2025 err_code |= pscf->fct(srv);
2026 }
2027 list_for_each_entry(ppcf, &post_proxy_check_list, list)
2028 err_code |= ppcf->fct(px);
2029 }
Willy Tarreaubb925012009-07-23 13:36:36 +02002030 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002031 ha_alert("Fatal errors found in configuration.\n");
Willy Tarreau915e1eb2009-06-22 15:48:36 +02002032 exit(1);
2033 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02002034
Carl Henrik Lundef91ac192020-02-27 16:45:50 +01002035 err_code |= pattern_finalize_config();
2036 if (err_code & (ERR_ABORT|ERR_FATAL)) {
2037 ha_alert("Failed to finalize pattern config.\n");
2038 exit(1);
2039 }
Willy Tarreau0f936722019-04-11 14:47:08 +02002040
Willy Tarreau79c9bdf2021-07-17 12:31:08 +02002041 if (global.rlimit_memmax_all)
2042 global.rlimit_memmax = global.rlimit_memmax_all;
2043
Willy Tarreaue5733232019-05-22 19:24:06 +02002044#ifdef USE_NS
KOVACS Krisztianb3e54fe2014-11-17 15:11:45 +01002045 err_code |= netns_init();
2046 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002047 ha_alert("Failed to initialize namespace support.\n");
KOVACS Krisztianb3e54fe2014-11-17 15:11:45 +01002048 exit(1);
2049 }
2050#endif
2051
Baptiste Assmann4215d7d2016-11-02 15:33:15 +01002052 /* Apply server states */
2053 apply_server_state();
2054
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002055 for (px = proxies_list; px; px = px->next)
Baptiste Assmann4215d7d2016-11-02 15:33:15 +01002056 srv_compute_all_admin_states(px);
2057
Baptiste Assmann83cbaa52016-11-02 15:34:05 +01002058 /* Apply servers' configured address */
2059 err_code |= srv_init_addr();
2060 if (err_code & (ERR_ABORT|ERR_FATAL)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002061 ha_alert("Failed to initialize server(s) addr.\n");
Baptiste Assmann83cbaa52016-11-02 15:34:05 +01002062 exit(1);
2063 }
2064
Willy Tarreau3eb10b82020-04-15 16:42:39 +02002065 if (warned & WARN_ANY && global.mode & MODE_ZERO_WARNING) {
2066 ha_alert("Some warnings were found and 'zero-warning' is set. Aborting.\n");
2067 exit(1);
2068 }
2069
Willy Tarreaubaaee002006-06-26 02:48:02 +02002070 if (global.mode & MODE_CHECK) {
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002071 struct peers *pr;
2072 struct proxy *px;
2073
Willy Tarreaubebd2122020-04-15 16:06:11 +02002074 if (warned & WARN_ANY)
2075 qfprintf(stdout, "Warnings were found.\n");
2076
Frédéric Lécailleed2b4a62017-07-13 09:07:09 +02002077 for (pr = cfg_peers; pr; pr = pr->next)
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002078 if (pr->peers_fe)
2079 break;
2080
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002081 for (px = proxies_list; px; px = px->next)
Christopher Fauletdfd10ab2021-10-06 14:24:19 +02002082 if (!(px->flags & (PR_FL_DISABLED|PR_FL_STOPPED)) && px->li_all)
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002083 break;
2084
Emeric Brunbc5c8212021-08-13 09:32:50 +02002085 if (!px) {
2086 /* We may only have log-forward section */
2087 for (px = cfg_log_forward; px; px = px->next)
Christopher Fauletdfd10ab2021-10-06 14:24:19 +02002088 if (!(px->flags & (PR_FL_DISABLED|PR_FL_STOPPED)) && px->li_all)
Emeric Brunbc5c8212021-08-13 09:32:50 +02002089 break;
2090 }
2091
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002092 if (pr || px) {
2093 /* At least one peer or one listener has been found */
2094 qfprintf(stdout, "Configuration file is valid\n");
Tim Duesterhus0a3b43d2020-06-14 00:37:42 +02002095 deinit_and_exit(0);
Willy Tarreau8b15ba12012-02-02 17:48:18 +01002096 }
2097 qfprintf(stdout, "Configuration file has no error but will not start (no listener) => exit(2).\n");
2098 exit(2);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002099 }
Willy Tarreaue9b26022011-08-01 20:57:55 +02002100
Amaury Denoyelle5a6926d2021-03-30 17:34:24 +02002101 if (global.mode & MODE_DIAG) {
2102 cfg_run_diagnostics();
2103 }
2104
Willy Tarreau8263d2b2012-08-28 00:06:31 +02002105 /* now we know the buffer size, we can initialize the channels and buffers */
Willy Tarreau9b28e032012-10-12 23:49:43 +02002106 init_buffer();
Willy Tarreau8280d642009-09-23 23:37:52 +02002107
Willy Tarreaue6945732016-12-21 19:57:00 +01002108 list_for_each_entry(pcf, &post_check_list, list) {
2109 err_code |= pcf->fct();
2110 if (err_code & (ERR_ABORT|ERR_FATAL))
2111 exit(1);
2112 }
2113
Willy Tarreaubaaee002006-06-26 02:48:02 +02002114 if (cfg_maxconn > 0)
2115 global.maxconn = cfg_maxconn;
2116
Willy Tarreau4975d142021-03-13 11:00:33 +01002117 if (global.cli_fe)
2118 global.maxsock += global.cli_fe->maxconn;
Willy Tarreau8d687d82019-03-01 09:39:42 +01002119
2120 if (cfg_peers) {
2121 /* peers also need to bypass global maxconn */
2122 struct peers *p = cfg_peers;
2123
2124 for (p = cfg_peers; p; p = p->next)
2125 if (p->peers_fe)
2126 global.maxsock += p->peers_fe->maxconn;
2127 }
2128
Willy Tarreaubaaee002006-06-26 02:48:02 +02002129 if (cfg_pidfile) {
Willy Tarreaua534fea2008-08-03 12:19:50 +02002130 free(global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002131 global.pidfile = strdup(cfg_pidfile);
2132 }
2133
Willy Tarreaud0256482015-01-15 21:45:22 +01002134 /* Now we want to compute the maxconn and possibly maxsslconn values.
Willy Tarreauac350932019-03-01 15:43:14 +01002135 * It's a bit tricky. Maxconn defaults to the pre-computed value based
2136 * on rlim_fd_cur and the number of FDs in use due to the configuration,
2137 * and maxsslconn defaults to DEFAULT_MAXSSLCONN. On top of that we can
2138 * enforce a lower limit based on memmax.
Willy Tarreaud0256482015-01-15 21:45:22 +01002139 *
2140 * If memmax is set, then it depends on which values are set. If
2141 * maxsslconn is set, we use memmax to determine how many cleartext
2142 * connections may be added, and set maxconn to the sum of the two.
2143 * If maxconn is set and not maxsslconn, maxsslconn is computed from
2144 * the remaining amount of memory between memmax and the cleartext
2145 * connections. If neither are set, then it is considered that all
2146 * connections are SSL-capable, and maxconn is computed based on this,
2147 * then maxsslconn accordingly. We need to know if SSL is used on the
2148 * frontends, backends, or both, because when it's used on both sides,
2149 * we need twice the value for maxsslconn, but we only count the
2150 * handshake once since it is not performed on the two sides at the
2151 * same time (frontend-side is terminated before backend-side begins).
2152 * The SSL stack is supposed to have filled ssl_session_cost and
Willy Tarreau474b96a2015-01-28 19:03:21 +01002153 * ssl_handshake_cost during its initialization. In any case, if
2154 * SYSTEM_MAXCONN is set, we still enforce it as an upper limit for
2155 * maxconn in order to protect the system.
Willy Tarreaud0256482015-01-15 21:45:22 +01002156 */
Willy Tarreauac350932019-03-01 15:43:14 +01002157 ideal_maxconn = compute_ideal_maxconn();
2158
Willy Tarreaud0256482015-01-15 21:45:22 +01002159 if (!global.rlimit_memmax) {
2160 if (global.maxconn == 0) {
Willy Tarreauac350932019-03-01 15:43:14 +01002161 global.maxconn = ideal_maxconn;
Willy Tarreaud0256482015-01-15 21:45:22 +01002162 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2163 fprintf(stderr, "Note: setting global.maxconn to %d.\n", global.maxconn);
2164 }
2165 }
2166#ifdef USE_OPENSSL
2167 else if (!global.maxconn && !global.maxsslconn &&
2168 (global.ssl_used_frontend || global.ssl_used_backend)) {
2169 /* memmax is set, compute everything automatically. Here we want
2170 * to ensure that all SSL connections will be served. We take
2171 * care of the number of sides where SSL is used, and consider
2172 * the worst case : SSL used on both sides and doing a handshake
2173 * simultaneously. Note that we can't have more than maxconn
2174 * handshakes at a time by definition, so for the worst case of
2175 * two SSL conns per connection, we count a single handshake.
2176 */
2177 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2178 int64_t mem = global.rlimit_memmax * 1048576ULL;
Willy Tarreau304e17e2020-03-10 17:54:54 +01002179 int retried = 0;
Willy Tarreaud0256482015-01-15 21:45:22 +01002180
2181 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2182 mem -= global.maxzlibmem;
2183 mem = mem * MEM_USABLE_RATIO;
2184
Willy Tarreau304e17e2020-03-10 17:54:54 +01002185 /* Principle: we test once to set maxconn according to the free
2186 * memory. If it results in values the system rejects, we try a
2187 * second time by respecting rlim_fd_max. If it fails again, we
2188 * go back to the initial value and will let the final code
2189 * dealing with rlimit report the error. That's up to 3 attempts.
2190 */
2191 do {
2192 global.maxconn = mem /
2193 ((STREAM_MAX_COST + 2 * global.tune.bufsize) + // stream + 2 buffers per stream
2194 sides * global.ssl_session_max_cost + // SSL buffers, one per side
2195 global.ssl_handshake_max_cost); // 1 handshake per connection max
Willy Tarreaud0256482015-01-15 21:45:22 +01002196
Willy Tarreau304e17e2020-03-10 17:54:54 +01002197 if (retried == 1)
2198 global.maxconn = MIN(global.maxconn, ideal_maxconn);
2199 global.maxconn = round_2dig(global.maxconn);
Willy Tarreau474b96a2015-01-28 19:03:21 +01002200#ifdef SYSTEM_MAXCONN
Willy Tarreau304e17e2020-03-10 17:54:54 +01002201 if (global.maxconn > SYSTEM_MAXCONN)
2202 global.maxconn = SYSTEM_MAXCONN;
Willy Tarreau474b96a2015-01-28 19:03:21 +01002203#endif /* SYSTEM_MAXCONN */
Willy Tarreau304e17e2020-03-10 17:54:54 +01002204 global.maxsslconn = sides * global.maxconn;
2205
2206 if (check_if_maxsock_permitted(compute_ideal_maxsock(global.maxconn)))
2207 break;
2208 } while (retried++ < 2);
2209
Willy Tarreaud0256482015-01-15 21:45:22 +01002210 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2211 fprintf(stderr, "Note: setting global.maxconn to %d and global.maxsslconn to %d.\n",
2212 global.maxconn, global.maxsslconn);
2213 }
2214 else if (!global.maxsslconn &&
2215 (global.ssl_used_frontend || global.ssl_used_backend)) {
2216 /* memmax and maxconn are known, compute maxsslconn automatically.
2217 * maxsslconn being forced, we don't know how many of it will be
2218 * on each side if both sides are being used. The worst case is
2219 * when all connections use only one SSL instance because
2220 * handshakes may be on two sides at the same time.
2221 */
2222 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2223 int64_t mem = global.rlimit_memmax * 1048576ULL;
2224 int64_t sslmem;
2225
2226 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2227 mem -= global.maxzlibmem;
2228 mem = mem * MEM_USABLE_RATIO;
2229
Willy Tarreau87b09662015-04-03 00:22:06 +02002230 sslmem = mem - global.maxconn * (int64_t)(STREAM_MAX_COST + 2 * global.tune.bufsize);
Willy Tarreaud0256482015-01-15 21:45:22 +01002231 global.maxsslconn = sslmem / (global.ssl_session_max_cost + global.ssl_handshake_max_cost);
2232 global.maxsslconn = round_2dig(global.maxsslconn);
2233
2234 if (sslmem <= 0 || global.maxsslconn < sides) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002235 ha_alert("Cannot compute the automatic maxsslconn because global.maxconn is already too "
2236 "high for the global.memmax value (%d MB). The absolute maximum possible value "
2237 "without SSL is %d, but %d was found and SSL is in use.\n",
2238 global.rlimit_memmax,
2239 (int)(mem / (STREAM_MAX_COST + 2 * global.tune.bufsize)),
2240 global.maxconn);
Willy Tarreaud0256482015-01-15 21:45:22 +01002241 exit(1);
2242 }
2243
2244 if (global.maxsslconn > sides * global.maxconn)
2245 global.maxsslconn = sides * global.maxconn;
2246
2247 if (global.mode & (MODE_VERBOSE|MODE_DEBUG))
2248 fprintf(stderr, "Note: setting global.maxsslconn to %d\n", global.maxsslconn);
2249 }
2250#endif
2251 else if (!global.maxconn) {
2252 /* memmax and maxsslconn are known/unused, compute maxconn automatically */
2253 int sides = !!global.ssl_used_frontend + !!global.ssl_used_backend;
2254 int64_t mem = global.rlimit_memmax * 1048576ULL;
2255 int64_t clearmem;
Willy Tarreau304e17e2020-03-10 17:54:54 +01002256 int retried = 0;
Willy Tarreaud0256482015-01-15 21:45:22 +01002257
2258 if (global.ssl_used_frontend || global.ssl_used_backend)
2259 mem -= global.tune.sslcachesize * 200; // about 200 bytes per SSL cache entry
2260
2261 mem -= global.maxzlibmem;
2262 mem = mem * MEM_USABLE_RATIO;
2263
2264 clearmem = mem;
2265 if (sides)
2266 clearmem -= (global.ssl_session_max_cost + global.ssl_handshake_max_cost) * (int64_t)global.maxsslconn;
2267
Willy Tarreau304e17e2020-03-10 17:54:54 +01002268 /* Principle: we test once to set maxconn according to the free
2269 * memory. If it results in values the system rejects, we try a
2270 * second time by respecting rlim_fd_max. If it fails again, we
2271 * go back to the initial value and will let the final code
2272 * dealing with rlimit report the error. That's up to 3 attempts.
2273 */
2274 do {
2275 global.maxconn = clearmem / (STREAM_MAX_COST + 2 * global.tune.bufsize);
2276 if (retried == 1)
2277 global.maxconn = MIN(global.maxconn, ideal_maxconn);
2278 global.maxconn = round_2dig(global.maxconn);
Willy Tarreau474b96a2015-01-28 19:03:21 +01002279#ifdef SYSTEM_MAXCONN
Willy Tarreau304e17e2020-03-10 17:54:54 +01002280 if (global.maxconn > SYSTEM_MAXCONN)
2281 global.maxconn = SYSTEM_MAXCONN;
Willy Tarreau474b96a2015-01-28 19:03:21 +01002282#endif /* SYSTEM_MAXCONN */
Willy Tarreaud0256482015-01-15 21:45:22 +01002283
Willy Tarreau304e17e2020-03-10 17:54:54 +01002284 if (clearmem <= 0 || !global.maxconn) {
2285 ha_alert("Cannot compute the automatic maxconn because global.maxsslconn is already too "
2286 "high for the global.memmax value (%d MB). The absolute maximum possible value "
2287 "is %d, but %d was found.\n",
2288 global.rlimit_memmax,
Christopher Faulet767a84b2017-11-24 16:50:31 +01002289 (int)(mem / (global.ssl_session_max_cost + global.ssl_handshake_max_cost)),
Willy Tarreau304e17e2020-03-10 17:54:54 +01002290 global.maxsslconn);
2291 exit(1);
2292 }
2293
2294 if (check_if_maxsock_permitted(compute_ideal_maxsock(global.maxconn)))
2295 break;
2296 } while (retried++ < 2);
Willy Tarreaud0256482015-01-15 21:45:22 +01002297
2298 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
2299 if (sides && global.maxsslconn > sides * global.maxconn) {
2300 fprintf(stderr, "Note: global.maxsslconn is forced to %d which causes global.maxconn "
2301 "to be limited to %d. Better reduce global.maxsslconn to get more "
2302 "room for extra connections.\n", global.maxsslconn, global.maxconn);
2303 }
2304 fprintf(stderr, "Note: setting global.maxconn to %d\n", global.maxconn);
2305 }
Willy Tarreau66aa61f2009-01-18 21:44:07 +01002306 }
2307
Willy Tarreaua409f302020-03-10 17:08:53 +01002308 global.maxsock = compute_ideal_maxsock(global.maxconn);
2309 global.hardmaxconn = global.maxconn;
Willy Tarreaua4818db2020-06-19 16:20:59 +02002310 if (!global.maxpipes)
2311 global.maxpipes = compute_ideal_maxpipes();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002312
Olivier Houchard88698d92019-04-16 19:07:22 +02002313 /* update connection pool thresholds */
2314 global.tune.pool_low_count = ((long long)global.maxsock * global.tune.pool_low_ratio + 99) / 100;
2315 global.tune.pool_high_count = ((long long)global.maxsock * global.tune.pool_high_ratio + 99) / 100;
2316
Willy Tarreauc8d5b952019-02-27 17:25:52 +01002317 proxy_adjust_all_maxconn();
2318
Willy Tarreau1db37712007-06-03 17:16:49 +02002319 if (global.tune.maxpollevents <= 0)
2320 global.tune.maxpollevents = MAX_POLL_EVENTS;
2321
Willy Tarreau060a7612021-03-10 11:06:26 +01002322 if (global.tune.runqueue_depth <= 0) {
2323 /* tests on various thread counts from 1 to 64 have shown an
2324 * optimal queue depth following roughly 1/sqrt(threads).
2325 */
2326 int s = my_flsl(global.nbthread);
2327 s += (global.nbthread / s); // roughly twice the sqrt.
2328 global.tune.runqueue_depth = RUNQUEUE_DEPTH * 2 / s;
2329 }
Olivier Houchard1599b802018-05-24 18:59:04 +02002330
Willy Tarreau6f4a82c2009-03-21 20:43:57 +01002331 if (global.tune.recv_enough == 0)
2332 global.tune.recv_enough = MIN_RECV_AT_ONCE_ENOUGH;
2333
Willy Tarreau27a674e2009-08-17 07:23:33 +02002334 if (global.tune.maxrewrite >= global.tune.bufsize / 2)
2335 global.tune.maxrewrite = global.tune.bufsize / 2;
2336
Amaury Denoyelle11124302021-06-04 18:22:08 +02002337 usermsgs_clr(NULL);
2338
Willy Tarreaubaaee002006-06-26 02:48:02 +02002339 if (arg_mode & (MODE_DEBUG | MODE_FOREGROUND)) {
2340 /* command line debug mode inhibits configuration mode */
William Lallemand095ba4c2017-06-01 17:38:50 +02002341 global.mode &= ~(MODE_DAEMON | MODE_QUIET);
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002342 global.mode |= (arg_mode & (MODE_DEBUG | MODE_FOREGROUND));
2343 }
2344
William Lallemand095ba4c2017-06-01 17:38:50 +02002345 if (arg_mode & MODE_DAEMON) {
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002346 /* command line daemon mode inhibits foreground and debug modes mode */
2347 global.mode &= ~(MODE_DEBUG | MODE_FOREGROUND);
William Lallemand095ba4c2017-06-01 17:38:50 +02002348 global.mode |= arg_mode & MODE_DAEMON;
Willy Tarreaubaaee002006-06-26 02:48:02 +02002349 }
Willy Tarreau772f0dd2012-10-26 16:04:28 +02002350
2351 global.mode |= (arg_mode & (MODE_QUIET | MODE_VERBOSE));
Willy Tarreaubaaee002006-06-26 02:48:02 +02002352
William Lallemand095ba4c2017-06-01 17:38:50 +02002353 if ((global.mode & MODE_DEBUG) && (global.mode & (MODE_DAEMON | MODE_QUIET))) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002354 ha_warning("<debug> mode incompatible with <quiet> and <daemon>. Keeping <debug> only.\n");
William Lallemand095ba4c2017-06-01 17:38:50 +02002355 global.mode &= ~(MODE_DAEMON | MODE_QUIET);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002356 }
2357
Christopher Fauletbe0faa22017-08-29 15:37:10 +02002358 if (global.nbthread < 1)
2359 global.nbthread = 1;
2360
Christopher Faulet3ef26392017-08-29 16:46:57 +02002361 /* Realloc trash buffers because global.tune.bufsize may have changed */
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002362 if (!init_trash_buffers(0)) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002363 ha_alert("failed to initialize trash buffers.\n");
Christopher Faulet3ef26392017-08-29 16:46:57 +02002364 exit(1);
2365 }
2366
Christopher Faulet96d44832017-11-14 22:02:30 +01002367 if (!init_log_buffers()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002368 ha_alert("failed to initialize log buffers.\n");
Christopher Faulet96d44832017-11-14 22:02:30 +01002369 exit(1);
2370 }
2371
Willy Tarreauef1d1f82007-04-16 00:25:25 +02002372 /*
2373 * Note: we could register external pollers here.
2374 * Built-in pollers have been registered before main().
2375 */
Willy Tarreau4f60f162007-04-08 16:39:58 +02002376
Willy Tarreau43b78992009-01-25 15:42:27 +01002377 if (!(global.tune.options & GTUNE_USE_KQUEUE))
Willy Tarreau1e63130a2007-04-09 12:03:06 +02002378 disable_poller("kqueue");
2379
Emmanuel Hocdet0ba4f482019-04-08 16:53:32 +00002380 if (!(global.tune.options & GTUNE_USE_EVPORTS))
2381 disable_poller("evports");
2382
Willy Tarreau43b78992009-01-25 15:42:27 +01002383 if (!(global.tune.options & GTUNE_USE_EPOLL))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002384 disable_poller("epoll");
2385
Willy Tarreau43b78992009-01-25 15:42:27 +01002386 if (!(global.tune.options & GTUNE_USE_POLL))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002387 disable_poller("poll");
2388
Willy Tarreau43b78992009-01-25 15:42:27 +01002389 if (!(global.tune.options & GTUNE_USE_SELECT))
Willy Tarreau4f60f162007-04-08 16:39:58 +02002390 disable_poller("select");
2391
2392 /* Note: we could disable any poller by name here */
2393
Christopher Fauletb3f4e142016-03-07 12:46:38 +01002394 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
Willy Tarreau2ff76222007-04-09 19:29:56 +02002395 list_pollers(stderr);
Christopher Fauletb3f4e142016-03-07 12:46:38 +01002396 fprintf(stderr, "\n");
2397 list_filters(stderr);
2398 }
Willy Tarreau2ff76222007-04-09 19:29:56 +02002399
Willy Tarreau4f60f162007-04-08 16:39:58 +02002400 if (!init_pollers()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002401 ha_alert("No polling mechanism available.\n"
2402 " It is likely that haproxy was built with TARGET=generic and that FD_SETSIZE\n"
2403 " is too low on this platform to support maxconn and the number of listeners\n"
2404 " and servers. You should rebuild haproxy specifying your system using TARGET=\n"
2405 " in order to support other polling systems (poll, epoll, kqueue) or reduce the\n"
2406 " global maxconn setting to accommodate the system's limitation. For reference,\n"
2407 " FD_SETSIZE=%d on this system, global.maxconn=%d resulting in a maximum of\n"
2408 " %d file descriptors. You should thus reduce global.maxconn by %d. Also,\n"
2409 " check build settings using 'haproxy -vv'.\n\n",
2410 FD_SETSIZE, global.maxconn, global.maxsock, (global.maxsock + 1 - FD_SETSIZE) / 2);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002411 exit(1);
2412 }
Willy Tarreau2ff76222007-04-09 19:29:56 +02002413 if (global.mode & (MODE_VERBOSE|MODE_DEBUG)) {
2414 printf("Using %s() as the polling mechanism.\n", cur_poller.name);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002415 }
2416
Krzysztof Piotr Oledzki48cb2ae2009-10-02 22:51:14 +02002417 if (!global.node)
2418 global.node = strdup(hostname);
2419
Willy Tarreau02b092f2020-10-07 18:36:54 +02002420 /* stop disabled proxies */
2421 for (px = proxies_list; px; px = px->next) {
Christopher Fauletdfd10ab2021-10-06 14:24:19 +02002422 if (px->flags & (PR_FL_DISABLED|PR_FL_STOPPED))
Willy Tarreau02b092f2020-10-07 18:36:54 +02002423 stop_proxy(px);
2424 }
2425
Thierry FOURNIERa4a0f3d2015-01-23 12:08:30 +01002426 if (!hlua_post_init())
2427 exit(1);
Thomas Holmes6abded42015-05-12 16:23:58 +01002428
Maxime de Roucy0f503922016-05-13 23:52:55 +02002429 free(err_msg);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002430}
2431
Cyril Bonté203ec5a2017-03-23 22:44:13 +01002432void deinit(void)
Willy Tarreaubaaee002006-06-26 02:48:02 +02002433{
Olivier Houchardfbc74e82017-11-24 16:54:05 +01002434 struct proxy *p = proxies_list, *p0;
Willy Tarreaudeb9ed82010-01-03 21:03:22 +01002435 struct wordlist *wl, *wlb;
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002436 struct uri_auth *uap, *ua = NULL;
William Lallemand0f99e342011-10-12 17:50:54 +02002437 struct logsrv *log, *logb;
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002438 struct build_opts_str *bol, *bolb;
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002439 struct post_deinit_fct *pdf, *pdfb;
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002440 struct proxy_deinit_fct *pxdf, *pxdfb;
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002441 struct server_deinit_fct *srvdf, *srvdfb;
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002442 struct per_thread_init_fct *tif, *tifb;
2443 struct per_thread_deinit_fct *tdf, *tdfb;
2444 struct per_thread_alloc_fct *taf, *tafb;
2445 struct per_thread_free_fct *tff, *tffb;
Tim Duesterhus34bef072020-07-04 11:49:50 +02002446 struct post_server_check_fct *pscf, *pscfb;
Tim Duesterhusfc854942020-09-10 19:46:42 +02002447 struct post_check_fct *pcf, *pcfb;
Tim Duesterhus53508d62020-09-10 19:46:40 +02002448 struct post_proxy_check_fct *ppcf, *ppcfb;
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002449 int cur_fd;
2450
2451 /* At this point the listeners state is weird:
2452 * - most listeners are still bound and referenced in their protocol
2453 * - some might be zombies that are not in their proto anymore, but
2454 * still appear in their proxy's listeners with a valid FD.
2455 * - some might be stopped and still appear in their proxy as FD #-1
2456 * - among all of them, some might be inherited hence shared and we're
2457 * not allowed to pause them or whatever, we must just close them.
2458 * - finally some are not listeners (pipes, logs, stdout, etc) and
2459 * must be left intact.
2460 *
2461 * The safe way to proceed is to unbind (and close) whatever is not yet
2462 * unbound so that no more receiver/listener remains alive. Then close
2463 * remaining listener FDs, which correspond to zombie listeners (those
2464 * belonging to disabled proxies that were in another process).
2465 * objt_listener() would be cleaner here but not converted yet.
2466 */
2467 protocol_unbind_all();
2468
2469 for (cur_fd = 0; cur_fd < global.maxsock; cur_fd++) {
Willy Tarreau1a3770c2020-10-14 12:13:51 +02002470 if (!fdtab || !fdtab[cur_fd].owner)
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002471 continue;
2472
Willy Tarreaua74cb382020-10-15 21:29:49 +02002473 if (fdtab[cur_fd].iocb == &sock_accept_iocb) {
Willy Tarreauae7bc4a2020-09-23 16:46:22 +02002474 struct listener *l = fdtab[cur_fd].owner;
2475
2476 BUG_ON(l->state != LI_INIT);
2477 unbind_listener(l);
2478 }
2479 }
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002480
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002481 deinit_signals();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002482 while (p) {
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002483 /* build a list of unique uri_auths */
2484 if (!ua)
2485 ua = p->uri_auth;
2486 else {
2487 /* check if p->uri_auth is unique */
2488 for (uap = ua; uap; uap=uap->next)
2489 if (uap == p->uri_auth)
2490 break;
2491
Willy Tarreauaccc4e12008-06-24 11:14:45 +02002492 if (!uap && p->uri_auth) {
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002493 /* add it, if it is */
2494 p->uri_auth->next = ua;
2495 ua = p->uri_auth;
2496 }
William Lallemand0f99e342011-10-12 17:50:54 +02002497 }
2498
Willy Tarreau4d2d0982007-05-14 00:39:29 +02002499 p0 = p;
Willy Tarreaubaaee002006-06-26 02:48:02 +02002500 p = p->next;
Amaury Denoyelle27fefa12021-03-24 16:13:20 +01002501 free_proxy(p0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002502 }/* end while(p) */
Willy Tarreaudd815982007-10-16 12:25:14 +02002503
Christopher Faulet27c8d202021-10-13 09:50:53 +02002504 /* destroy all referenced defaults proxies */
2505 proxy_destroy_all_unref_defaults();
2506
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002507 while (ua) {
Tim Duesterhus00f00cf2020-09-10 19:46:38 +02002508 struct stat_scope *scope, *scopep;
2509
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002510 uap = ua;
2511 ua = ua->next;
2512
Willy Tarreaua534fea2008-08-03 12:19:50 +02002513 free(uap->uri_prefix);
2514 free(uap->auth_realm);
Krzysztof Piotr Oledzki48cb2ae2009-10-02 22:51:14 +02002515 free(uap->node);
2516 free(uap->desc);
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002517
Krzysztof Piotr Oledzki8c8bd452010-01-29 19:29:32 +01002518 userlist_free(uap->userlist);
Amaury Denoyelle68fd7e42021-03-25 17:15:52 +01002519 free_act_rules(&uap->http_req_rules);
Krzysztof Piotr Oledzki8c8bd452010-01-29 19:29:32 +01002520
Tim Duesterhus00f00cf2020-09-10 19:46:38 +02002521 scope = uap->scope;
2522 while (scope) {
2523 scopep = scope;
2524 scope = scope->next;
2525
2526 free(scopep->px_id);
2527 free(scopep);
2528 }
2529
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002530 free(uap);
2531 }
2532
Krzysztof Piotr Oledzki96105042010-01-29 17:50:44 +01002533 userlist_free(userlist);
2534
David Carlier834cb2e2015-09-25 12:02:25 +01002535 cfg_unregister_sections();
2536
Christopher Faulet0132d062017-07-26 15:33:35 +02002537 deinit_log_buffers();
David Carlier834cb2e2015-09-25 12:02:25 +01002538
Willy Tarreau05554e62016-12-21 20:46:26 +01002539 list_for_each_entry(pdf, &post_deinit_list, list)
2540 pdf->fct();
2541
Willy Tarreau61cfdf42021-02-20 10:46:51 +01002542 ha_free(&global.log_send_hostname);
Dragan Dosen43885c72015-10-01 13:18:13 +02002543 chunk_destroy(&global.log_tag);
Willy Tarreau61cfdf42021-02-20 10:46:51 +01002544 ha_free(&global.chroot);
2545 ha_free(&global.pidfile);
2546 ha_free(&global.node);
2547 ha_free(&global.desc);
2548 ha_free(&oldpids);
2549 ha_free(&old_argv);
2550 ha_free(&localpeer);
2551 ha_free(&global.server_state_base);
2552 ha_free(&global.server_state_file);
Olivier Houchard3f795f72019-04-17 22:51:06 +02002553 task_destroy(idle_conn_task);
Olivier Houchard9ea5d362019-02-14 18:29:09 +01002554 idle_conn_task = NULL;
Krzysztof Piotr Oledzki8001d612008-05-31 13:53:23 +02002555
William Lallemand0f99e342011-10-12 17:50:54 +02002556 list_for_each_entry_safe(log, logb, &global.logsrvs, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002557 LIST_DELETE(&log->list);
Amaury Denoyelled688e012021-04-20 17:05:47 +02002558 free(log->conf.file);
William Lallemand0f99e342011-10-12 17:50:54 +02002559 free(log);
2560 }
Willy Tarreau477ecd82010-01-03 21:12:30 +01002561 list_for_each_entry_safe(wl, wlb, &cfg_cfgfiles, list) {
Maxime de Roucy0f503922016-05-13 23:52:55 +02002562 free(wl->s);
Willy Tarreau2b718102021-04-21 07:32:39 +02002563 LIST_DELETE(&wl->list);
Willy Tarreau477ecd82010-01-03 21:12:30 +01002564 free(wl);
2565 }
2566
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002567 list_for_each_entry_safe(bol, bolb, &build_opts_list, list) {
2568 if (bol->must_free)
2569 free((void *)bol->str);
Willy Tarreau2b718102021-04-21 07:32:39 +02002570 LIST_DELETE(&bol->list);
Willy Tarreaucdb737e2016-12-21 18:43:10 +01002571 free(bol);
2572 }
2573
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002574 list_for_each_entry_safe(pxdf, pxdfb, &proxy_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002575 LIST_DELETE(&pxdf->list);
Tim Duesterhus17e363f2020-07-04 11:49:47 +02002576 free(pxdf);
2577 }
2578
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002579 list_for_each_entry_safe(pdf, pdfb, &post_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002580 LIST_DELETE(&pdf->list);
Tim Duesterhusfdf904a2020-07-04 11:49:48 +02002581 free(pdf);
2582 }
2583
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002584 list_for_each_entry_safe(srvdf, srvdfb, &server_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002585 LIST_DELETE(&srvdf->list);
Tim Duesterhus0837eb12020-07-04 11:49:49 +02002586 free(srvdf);
2587 }
2588
Tim Duesterhusfc854942020-09-10 19:46:42 +02002589 list_for_each_entry_safe(pcf, pcfb, &post_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002590 LIST_DELETE(&pcf->list);
Tim Duesterhusfc854942020-09-10 19:46:42 +02002591 free(pcf);
2592 }
2593
Tim Duesterhus34bef072020-07-04 11:49:50 +02002594 list_for_each_entry_safe(pscf, pscfb, &post_server_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002595 LIST_DELETE(&pscf->list);
Tim Duesterhus34bef072020-07-04 11:49:50 +02002596 free(pscf);
2597 }
2598
Tim Duesterhus53508d62020-09-10 19:46:40 +02002599 list_for_each_entry_safe(ppcf, ppcfb, &post_proxy_check_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002600 LIST_DELETE(&ppcf->list);
Tim Duesterhus53508d62020-09-10 19:46:40 +02002601 free(ppcf);
2602 }
2603
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002604 list_for_each_entry_safe(tif, tifb, &per_thread_init_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002605 LIST_DELETE(&tif->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002606 free(tif);
2607 }
2608
2609 list_for_each_entry_safe(tdf, tdfb, &per_thread_deinit_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002610 LIST_DELETE(&tdf->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002611 free(tdf);
2612 }
2613
2614 list_for_each_entry_safe(taf, tafb, &per_thread_alloc_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002615 LIST_DELETE(&taf->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002616 free(taf);
2617 }
2618
2619 list_for_each_entry_safe(tff, tffb, &per_thread_free_list, list) {
Willy Tarreau2b718102021-04-21 07:32:39 +02002620 LIST_DELETE(&tff->list);
Tim Duesterhusf0c25d22020-09-10 19:46:41 +02002621 free(tff);
2622 }
2623
Willy Tarreaucfc4f242021-05-08 11:41:28 +02002624 vars_prune(&proc_vars, NULL, NULL);
Willy Tarreau2455ceb2018-11-26 15:57:34 +01002625 pool_destroy_all();
Krzysztof Piotr Oledzkia643baf2008-05-29 23:53:44 +02002626 deinit_pollers();
Willy Tarreaubaaee002006-06-26 02:48:02 +02002627} /* end deinit() */
2628
Willy Tarreauf3ca5a02020-06-15 18:43:46 +02002629__attribute__((noreturn)) void deinit_and_exit(int status)
Tim Duesterhus26540552020-06-14 00:37:41 +02002630{
Amaury Denoyelle7afa5c12021-08-09 15:02:56 +02002631 global.mode |= MODE_STOPPING;
Tim Duesterhus26540552020-06-14 00:37:41 +02002632 deinit();
2633 exit(status);
2634}
William Lallemand72160322018-11-06 17:37:16 +01002635
Willy Tarreau918ff602011-07-25 16:33:49 +02002636/* Runs the polling loop */
Willy Tarreau3ebd55e2020-03-03 14:59:56 +01002637void run_poll_loop()
Willy Tarreau4f60f162007-04-08 16:39:58 +02002638{
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002639 int next, wake;
Willy Tarreau4f60f162007-04-08 16:39:58 +02002640
Willy Tarreau55542642021-10-08 09:33:24 +02002641 clock_update_date(0,1);
Willy Tarreau4f60f162007-04-08 16:39:58 +02002642 while (1) {
Willy Tarreauc49ba522019-12-11 08:12:23 +01002643 wake_expired_tasks();
2644
William Lallemand1aab50b2018-06-07 09:46:01 +02002645 /* check if we caught some signals and process them in the
2646 first thread */
Willy Tarreaua7ad4ae2020-06-19 12:06:34 +02002647 if (signal_queue_len && tid == 0) {
2648 activity[tid].wake_signal++;
William Lallemand1aab50b2018-06-07 09:46:01 +02002649 signal_process_queue();
Willy Tarreaua7ad4ae2020-06-19 12:06:34 +02002650 }
2651
2652 /* Process a few tasks */
2653 process_runnable_tasks();
Willy Tarreau29857942009-05-10 09:01:21 +02002654
Willy Tarreau7067b3a2019-06-02 11:11:29 +02002655 /* also stop if we failed to cleanly stop all tasks */
2656 if (killed > 1)
2657 break;
2658
Willy Tarreau10146c92015-04-13 20:44:19 +02002659 /* expire immediately if events are pending */
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002660 wake = 1;
Olivier Houchard305d5ab2019-07-24 18:07:06 +02002661 if (thread_has_tasks())
Willy Tarreaud80cb4e2018-01-20 19:30:13 +01002662 activity[tid].wake_tasks++;
Olivier Houchard79321b92018-07-26 17:55:11 +02002663 else {
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002664 _HA_ATOMIC_OR(&sleeping_thread_mask, tid_bit);
2665 __ha_barrier_atomic_store();
Willy Tarreau95abd5b2020-03-23 09:33:32 +01002666 if (thread_has_tasks()) {
Olivier Houchard79321b92018-07-26 17:55:11 +02002667 activity[tid].wake_tasks++;
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002668 _HA_ATOMIC_AND(&sleeping_thread_mask, ~tid_bit);
Olivier Houchard79321b92018-07-26 17:55:11 +02002669 } else
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002670 wake = 0;
Olivier Houchard79321b92018-07-26 17:55:11 +02002671 }
Willy Tarreau10146c92015-04-13 20:44:19 +02002672
Willy Tarreau4f46a352020-03-23 09:27:28 +01002673 if (!wake) {
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002674 int i;
2675
2676 if (stopping) {
Ilya Shipitsin3df59892021-05-10 12:50:00 +05002677 /* stop muxes before acknowledging stopping */
Amaury Denoyelled3a88c12021-05-03 10:47:51 +02002678 if (!(stopping_thread_mask & tid_bit)) {
2679 task_wakeup(mux_stopping_data[tid].task, TASK_WOKEN_OTHER);
2680 wake = 1;
2681 }
2682
Willy Tarreau1db42732021-04-06 11:44:07 +02002683 if (_HA_ATOMIC_OR_FETCH(&stopping_thread_mask, tid_bit) == tid_bit) {
Willy Tarreaud6455742020-05-13 14:30:25 +02002684 /* notify all threads that stopping was just set */
2685 for (i = 0; i < global.nbthread; i++)
Willy Tarreau369a2ef2020-06-29 19:23:19 +02002686 if (((all_threads_mask & ~stopping_thread_mask) >> i) & 1)
Willy Tarreaud6455742020-05-13 14:30:25 +02002687 wake_thread(i);
2688 }
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002689 }
Willy Tarreau4f46a352020-03-23 09:27:28 +01002690
2691 /* stop when there's nothing left to do */
2692 if ((jobs - unstoppable_jobs) == 0 &&
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002693 (stopping_thread_mask & all_threads_mask) == all_threads_mask) {
2694 /* wake all threads waiting on jobs==0 */
2695 for (i = 0; i < global.nbthread; i++)
2696 if (((all_threads_mask & ~tid_bit) >> i) & 1)
2697 wake_thread(i);
Willy Tarreau4f46a352020-03-23 09:27:28 +01002698 break;
Willy Tarreaud7a6b2f2020-05-13 13:51:01 +02002699 }
Willy Tarreau4f46a352020-03-23 09:27:28 +01002700 }
2701
Willy Tarreauc49ba522019-12-11 08:12:23 +01002702 /* If we have to sleep, measure how long */
2703 next = wake ? TICK_ETERNITY : next_timer_expiry();
2704
Willy Tarreau58b458d2008-06-29 22:40:23 +02002705 /* The poller will ensure it returns around <next> */
Willy Tarreau2ae84e42019-05-28 16:44:05 +02002706 cur_poller.poll(&cur_poller, next, wake);
Emeric Brun64cc49c2017-10-03 14:46:45 +02002707
Willy Tarreaud80cb4e2018-01-20 19:30:13 +01002708 activity[tid].loops++;
Willy Tarreau4f60f162007-04-08 16:39:58 +02002709 }
2710}
2711
Christopher Faulet1d17c102017-08-29 15:38:48 +02002712static void *run_thread_poll_loop(void *data)
2713{
Willy Tarreau082b6282019-05-22 14:42:12 +02002714 struct per_thread_alloc_fct *ptaf;
Christopher Faulet1d17c102017-08-29 15:38:48 +02002715 struct per_thread_init_fct *ptif;
2716 struct per_thread_deinit_fct *ptdf;
Willy Tarreau082b6282019-05-22 14:42:12 +02002717 struct per_thread_free_fct *ptff;
Willy Tarreau34a150c2019-06-11 09:16:41 +02002718 static int init_left = 0;
Willy Tarreauaf613e82020-06-05 08:40:51 +02002719 __decl_thread(static pthread_mutex_t init_mutex = PTHREAD_MUTEX_INITIALIZER);
2720 __decl_thread(static pthread_cond_t init_cond = PTHREAD_COND_INITIALIZER);
Christopher Faulet1d17c102017-08-29 15:38:48 +02002721
Willy Tarreau43ab05b2021-09-28 09:43:11 +02002722 ha_set_thread(data);
Willy Tarreaufb641d72021-09-28 10:15:47 +02002723 set_thread_cpu_affinity();
Willy Tarreau44c58da2021-10-08 12:27:54 +02002724 clock_set_local_source();
Willy Tarreau91e6df02019-05-03 17:21:18 +02002725
Willy Tarreau6ec902a2019-06-07 14:41:11 +02002726 /* Now, initialize one thread init at a time. This is better since
2727 * some init code is a bit tricky and may release global resources
2728 * after reallocating them locally. This will also ensure there is
2729 * no race on file descriptors allocation.
2730 */
Willy Tarreau34a150c2019-06-11 09:16:41 +02002731#ifdef USE_THREAD
2732 pthread_mutex_lock(&init_mutex);
2733#endif
2734 /* The first thread must set the number of threads left */
2735 if (!init_left)
2736 init_left = global.nbthread;
2737 init_left--;
Willy Tarreau91e6df02019-05-03 17:21:18 +02002738
Willy Tarreau55542642021-10-08 09:33:24 +02002739 clock_init_thread_date();
Christopher Faulet1d17c102017-08-29 15:38:48 +02002740
Willy Tarreau082b6282019-05-22 14:42:12 +02002741 /* per-thread alloc calls performed here are not allowed to snoop on
2742 * other threads, so they are free to initialize at their own rhythm
2743 * as long as they act as if they were alone. None of them may rely
2744 * on resources initialized by the other ones.
2745 */
2746 list_for_each_entry(ptaf, &per_thread_alloc_list, list) {
2747 if (!ptaf->fct()) {
2748 ha_alert("failed to allocate resources for thread %u.\n", tid);
Willy Tarreaub3c4a8f2021-07-22 14:42:32 +02002749#ifdef USE_THREAD
jenny-cheung048368e2021-07-18 16:40:57 +08002750 pthread_mutex_unlock(&init_mutex);
Willy Tarreaub3c4a8f2021-07-22 14:42:32 +02002751#endif
Willy Tarreau082b6282019-05-22 14:42:12 +02002752 exit(1);
2753 }
2754 }
2755
Willy Tarreau3078e9f2019-05-20 10:50:43 +02002756 /* per-thread init calls performed here are not allowed to snoop on
2757 * other threads, so they are free to initialize at their own rhythm
2758 * as long as they act as if they were alone.
2759 */
Christopher Faulet1d17c102017-08-29 15:38:48 +02002760 list_for_each_entry(ptif, &per_thread_init_list, list) {
2761 if (!ptif->fct()) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002762 ha_alert("failed to initialize thread %u.\n", tid);
Willy Tarreaub3c4a8f2021-07-22 14:42:32 +02002763#ifdef USE_THREAD
jenny-cheung048368e2021-07-18 16:40:57 +08002764 pthread_mutex_unlock(&init_mutex);
Willy Tarreaub3c4a8f2021-07-22 14:42:32 +02002765#endif
Christopher Faulet1d17c102017-08-29 15:38:48 +02002766 exit(1);
2767 }
2768 }
2769
Willy Tarreau71092822019-06-10 09:51:04 +02002770 /* enabling protocols will result in fd_insert() calls to be performed,
2771 * we want all threads to have already allocated their local fd tables
Willy Tarreau34a150c2019-06-11 09:16:41 +02002772 * before doing so, thus only the last thread does it.
Willy Tarreau71092822019-06-10 09:51:04 +02002773 */
Willy Tarreau34a150c2019-06-11 09:16:41 +02002774 if (init_left == 0)
Willy Tarreaue4d7c9d2019-06-10 10:14:52 +02002775 protocol_enable_all();
Willy Tarreau6ec902a2019-06-07 14:41:11 +02002776
Willy Tarreau34a150c2019-06-11 09:16:41 +02002777#ifdef USE_THREAD
2778 pthread_cond_broadcast(&init_cond);
2779 pthread_mutex_unlock(&init_mutex);
2780
2781 /* now wait for other threads to finish starting */
2782 pthread_mutex_lock(&init_mutex);
2783 while (init_left)
2784 pthread_cond_wait(&init_cond, &init_mutex);
2785 pthread_mutex_unlock(&init_mutex);
2786#endif
Willy Tarreau3078e9f2019-05-20 10:50:43 +02002787
Willy Tarreaua45a8b52019-12-06 16:31:45 +01002788#if defined(PR_SET_NO_NEW_PRIVS) && defined(USE_PRCTL)
2789 /* Let's refrain from using setuid executables. This way the impact of
2790 * an eventual vulnerability in a library remains limited. It may
2791 * impact external checks but who cares about them anyway ? In the
2792 * worst case it's possible to disable the option. Obviously we do this
2793 * in workers only. We can't hard-fail on this one as it really is
2794 * implementation dependent though we're interested in feedback, hence
2795 * the warning.
2796 */
2797 if (!(global.tune.options & GTUNE_INSECURE_SETUID) && !master) {
2798 static int warn_fail;
Willy Tarreau18515722021-04-06 11:57:41 +02002799 if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) == -1 && !_HA_ATOMIC_FETCH_ADD(&warn_fail, 1)) {
Willy Tarreaua45a8b52019-12-06 16:31:45 +01002800 ha_warning("Failed to disable setuid, please report to developers with detailed "
2801 "information about your operating system. You can silence this warning "
2802 "by adding 'insecure-setuid-wanted' in the 'global' section.\n");
2803 }
2804 }
2805#endif
2806
Willy Tarreaud96f1122019-12-03 07:07:36 +01002807#if defined(RLIMIT_NPROC)
2808 /* all threads have started, it's now time to prevent any new thread
2809 * or process from starting. Obviously we do this in workers only. We
2810 * can't hard-fail on this one as it really is implementation dependent
2811 * though we're interested in feedback, hence the warning.
2812 */
2813 if (!(global.tune.options & GTUNE_INSECURE_FORK) && !master) {
2814 struct rlimit limit = { .rlim_cur = 0, .rlim_max = 0 };
2815 static int warn_fail;
2816
Willy Tarreau18515722021-04-06 11:57:41 +02002817 if (setrlimit(RLIMIT_NPROC, &limit) == -1 && !_HA_ATOMIC_FETCH_ADD(&warn_fail, 1)) {
Willy Tarreaud96f1122019-12-03 07:07:36 +01002818 ha_warning("Failed to disable forks, please report to developers with detailed "
2819 "information about your operating system. You can silence this warning "
2820 "by adding 'insecure-fork-wanted' in the 'global' section.\n");
2821 }
2822 }
2823#endif
Christopher Faulet1d17c102017-08-29 15:38:48 +02002824 run_poll_loop();
2825
2826 list_for_each_entry(ptdf, &per_thread_deinit_list, list)
2827 ptdf->fct();
2828
Willy Tarreau082b6282019-05-22 14:42:12 +02002829 list_for_each_entry(ptff, &per_thread_free_list, list)
2830 ptff->fct();
2831
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002832#ifdef USE_THREAD
Olivier Houchardb23a61f2019-03-08 18:51:17 +01002833 _HA_ATOMIC_AND(&all_threads_mask, ~tid_bit);
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002834 if (tid > 0)
2835 pthread_exit(NULL);
Christopher Faulet1d17c102017-08-29 15:38:48 +02002836#endif
Christopher Fauletcd7879a2017-10-27 13:53:47 +02002837 return NULL;
2838}
Christopher Faulet1d17c102017-08-29 15:38:48 +02002839
William Dauchyf9af9d72019-11-17 15:47:16 +01002840/* set uid/gid depending on global settings */
2841static void set_identity(const char *program_name)
2842{
2843 if (global.gid) {
2844 if (getgroups(0, NULL) > 0 && setgroups(0, NULL) == -1)
2845 ha_warning("[%s.main()] Failed to drop supplementary groups. Using 'gid'/'group'"
2846 " without 'uid'/'user' is generally useless.\n", program_name);
2847
2848 if (setgid(global.gid) == -1) {
2849 ha_alert("[%s.main()] Cannot set gid %d.\n", program_name, global.gid);
2850 protocol_unbind_all();
2851 exit(1);
2852 }
2853 }
2854
2855 if (global.uid && setuid(global.uid) == -1) {
2856 ha_alert("[%s.main()] Cannot set uid %d.\n", program_name, global.uid);
2857 protocol_unbind_all();
2858 exit(1);
2859 }
2860}
2861
Willy Tarreaubaaee002006-06-26 02:48:02 +02002862int main(int argc, char **argv)
2863{
2864 int err, retry;
2865 struct rlimit limit;
Willy Tarreau269ab312012-09-05 08:02:48 +02002866 int pidfd = -1;
Willy Tarreau1335da32021-07-14 17:54:01 +02002867 int intovf = (unsigned char)argc + 1; /* let the compiler know it's strictly positive */
2868
2869 /* Catch forced CFLAGS that miss 2-complement integer overflow */
2870 if (intovf + 0x7FFFFFFF >= intovf) {
2871 fprintf(stderr,
2872 "FATAL ERROR: invalid code detected -- cannot go further, please recompile!\n"
2873 "The source code was miscompiled by the compiler, which usually indicates that\n"
2874 "some of the CFLAGS needed to work around overzealous compiler optimizations\n"
2875 "were overwritten at build time. Please do not force CFLAGS, and read Makefile\n"
2876 "and INSTALL files to decide on the best way to pass your local build options.\n"
2877 "\nBuild options :"
2878#ifdef BUILD_TARGET
2879 "\n TARGET = " BUILD_TARGET
2880#endif
2881#ifdef BUILD_CPU
2882 "\n CPU = " BUILD_CPU
2883#endif
2884#ifdef BUILD_CC
2885 "\n CC = " BUILD_CC
2886#endif
2887#ifdef BUILD_CFLAGS
2888 "\n CFLAGS = " BUILD_CFLAGS
2889#endif
2890#ifdef BUILD_OPTIONS
2891 "\n OPTIONS = " BUILD_OPTIONS
2892#endif
2893#ifdef BUILD_DEBUG
2894 "\n DEBUG = " BUILD_DEBUG
2895#endif
2896 "\n\n");
2897 return 1;
2898 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02002899
Olivier Houchard5fa300d2018-02-03 15:15:21 +01002900 setvbuf(stdout, NULL, _IONBF, 0);
Willy Tarreau5794fb02018-11-25 18:43:29 +01002901
Willy Tarreaubf696402019-03-01 10:09:28 +01002902 /* take a copy of initial limits before we possibly change them */
2903 getrlimit(RLIMIT_NOFILE, &limit);
Willy Tarreau2bd0f812020-10-13 15:36:08 +02002904
2905 if (limit.rlim_max == RLIM_INFINITY)
2906 limit.rlim_max = limit.rlim_cur;
Willy Tarreaubf696402019-03-01 10:09:28 +01002907 rlim_fd_cur_at_boot = limit.rlim_cur;
2908 rlim_fd_max_at_boot = limit.rlim_max;
2909
Willy Tarreau5794fb02018-11-25 18:43:29 +01002910 /* process all initcalls in order of potential dependency */
2911 RUN_INITCALLS(STG_PREPARE);
2912 RUN_INITCALLS(STG_LOCK);
2913 RUN_INITCALLS(STG_ALLOC);
2914 RUN_INITCALLS(STG_POOL);
2915 RUN_INITCALLS(STG_REGISTER);
2916 RUN_INITCALLS(STG_INIT);
2917
Emeric Bruncf20bf12010-10-22 16:06:11 +02002918 init(argc, argv);
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002919 signal_register_fct(SIGQUIT, dump, SIGQUIT);
2920 signal_register_fct(SIGUSR1, sig_soft_stop, SIGUSR1);
2921 signal_register_fct(SIGHUP, sig_dump_state, SIGHUP);
William Lallemand73b85e72017-06-01 17:38:51 +02002922 signal_register_fct(SIGUSR2, NULL, 0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002923
Willy Tarreaue437c442010-03-17 18:02:46 +01002924 /* Always catch SIGPIPE even on platforms which define MSG_NOSIGNAL.
2925 * Some recent FreeBSD setups report broken pipes, and MSG_NOSIGNAL
2926 * was defined there, so let's stay on the safe side.
Willy Tarreaubaaee002006-06-26 02:48:02 +02002927 */
Willy Tarreau24f4efa2010-08-27 17:56:48 +02002928 signal_register_fct(SIGPIPE, NULL, 0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02002929
Willy Tarreaudc23a922011-02-16 11:10:36 +01002930 /* ulimits */
2931 if (!global.rlimit_nofile)
2932 global.rlimit_nofile = global.maxsock;
2933
2934 if (global.rlimit_nofile) {
Willy Tarreaue5cfdac2019-03-01 10:32:05 +01002935 limit.rlim_cur = global.rlimit_nofile;
2936 limit.rlim_max = MAX(rlim_fd_max_at_boot, limit.rlim_cur);
2937
Willy Tarreaudc23a922011-02-16 11:10:36 +01002938 if (setrlimit(RLIMIT_NOFILE, &limit) == -1) {
Willy Tarreauef635472016-06-21 11:48:18 +02002939 getrlimit(RLIMIT_NOFILE, &limit);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002940 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2941 ha_alert("[%s.main()] Cannot raise FD limit to %d, limit is %d.\n",
2942 argv[0], global.rlimit_nofile, (int)limit.rlim_cur);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002943 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002944 }
2945 else {
2946 /* try to set it to the max possible at least */
2947 limit.rlim_cur = limit.rlim_max;
2948 if (setrlimit(RLIMIT_NOFILE, &limit) != -1)
2949 getrlimit(RLIMIT_NOFILE, &limit);
Willy Tarreau164dd0b2016-06-21 11:51:59 +02002950
William Dauchya5194602020-03-28 19:29:58 +01002951 ha_warning("[%s.main()] Cannot raise FD limit to %d, limit is %d.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002952 argv[0], global.rlimit_nofile, (int)limit.rlim_cur);
2953 global.rlimit_nofile = limit.rlim_cur;
2954 }
Willy Tarreaudc23a922011-02-16 11:10:36 +01002955 }
2956 }
2957
2958 if (global.rlimit_memmax) {
2959 limit.rlim_cur = limit.rlim_max =
Willy Tarreau70060452015-12-14 12:46:07 +01002960 global.rlimit_memmax * 1048576ULL;
Willy Tarreaudc23a922011-02-16 11:10:36 +01002961#ifdef RLIMIT_AS
2962 if (setrlimit(RLIMIT_AS, &limit) == -1) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01002963 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2964 ha_alert("[%s.main()] Cannot fix MEM limit to %d megs.\n",
2965 argv[0], global.rlimit_memmax);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002966 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002967 }
2968 else
William Dauchya5194602020-03-28 19:29:58 +01002969 ha_warning("[%s.main()] Cannot fix MEM limit to %d megs.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002970 argv[0], global.rlimit_memmax);
Willy Tarreaudc23a922011-02-16 11:10:36 +01002971 }
2972#else
2973 if (setrlimit(RLIMIT_DATA, &limit) == -1) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01002974 if (global.tune.options & GTUNE_STRICT_LIMITS) {
2975 ha_alert("[%s.main()] Cannot fix MEM limit to %d megs.\n",
2976 argv[0], global.rlimit_memmax);
Jerome Magnin50f757c2021-01-12 20:19:38 +01002977 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01002978 }
2979 else
William Dauchya5194602020-03-28 19:29:58 +01002980 ha_warning("[%s.main()] Cannot fix MEM limit to %d megs.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01002981 argv[0], global.rlimit_memmax);
Willy Tarreaudc23a922011-02-16 11:10:36 +01002982 }
2983#endif
2984 }
2985
Olivier Houchardf73629d2017-04-05 22:33:04 +02002986 if (old_unixsocket) {
William Lallemand85b0bd92017-06-01 17:38:53 +02002987 if (strcmp("/dev/null", old_unixsocket) != 0) {
Willy Tarreau42961742020-08-28 18:42:45 +02002988 if (sock_get_old_sockets(old_unixsocket) != 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01002989 ha_alert("Failed to get the sockets from the old process!\n");
William Lallemand85b0bd92017-06-01 17:38:53 +02002990 if (!(global.mode & MODE_MWORKER))
2991 exit(1);
2992 }
Olivier Houchardf73629d2017-04-05 22:33:04 +02002993 }
2994 }
William Lallemand85b0bd92017-06-01 17:38:53 +02002995 get_cur_unixsocket();
2996
Willy Tarreaubaaee002006-06-26 02:48:02 +02002997 /* We will loop at most 100 times with 10 ms delay each time.
2998 * That's at most 1 second. We only send a signal to old pids
2999 * if we cannot grab at least one port.
3000 */
3001 retry = MAX_START_RETRIES;
3002 err = ERR_NONE;
3003 while (retry >= 0) {
3004 struct timeval w;
Willy Tarreaue91bff22020-09-02 11:11:43 +02003005 err = protocol_bind_all(retry == 0 || nb_oldpids == 0);
Willy Tarreaue13e9252007-12-20 23:05:50 +01003006 /* exit the loop on no error or fatal error */
3007 if ((err & (ERR_RETRYABLE|ERR_FATAL)) != ERR_RETRYABLE)
Willy Tarreaubaaee002006-06-26 02:48:02 +02003008 break;
Willy Tarreaubb545b42010-08-25 12:58:59 +02003009 if (nb_oldpids == 0 || retry == 0)
Willy Tarreaubaaee002006-06-26 02:48:02 +02003010 break;
3011
3012 /* FIXME-20060514: Solaris and OpenBSD do not support shutdown() on
3013 * listening sockets. So on those platforms, it would be wiser to
3014 * simply send SIGUSR1, which will not be undoable.
3015 */
Willy Tarreaubb545b42010-08-25 12:58:59 +02003016 if (tell_old_pids(SIGTTOU) == 0) {
3017 /* no need to wait if we can't contact old pids */
3018 retry = 0;
3019 continue;
3020 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003021 /* give some time to old processes to stop listening */
3022 w.tv_sec = 0;
3023 w.tv_usec = 10*1000;
3024 select(0, NULL, NULL, NULL, &w);
3025 retry--;
3026 }
3027
Willy Tarreaue91bff22020-09-02 11:11:43 +02003028 /* Note: protocol_bind_all() sends an alert when it fails. */
Willy Tarreau0a3b9d92009-02-04 17:05:23 +01003029 if ((err & ~ERR_WARN) != ERR_NONE) {
Willy Tarreaue91bff22020-09-02 11:11:43 +02003030 ha_alert("[%s.main()] Some protocols failed to start their listeners! Exiting.\n", argv[0]);
Willy Tarreauf68da462009-06-09 14:36:00 +02003031 if (retry != MAX_START_RETRIES && nb_oldpids) {
3032 protocol_unbind_all(); /* cleanup everything we can */
Willy Tarreaubaaee002006-06-26 02:48:02 +02003033 tell_old_pids(SIGTTIN);
Willy Tarreauf68da462009-06-09 14:36:00 +02003034 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003035 exit(1);
3036 }
3037
William Lallemand944e6192018-11-21 15:48:31 +01003038 if (!(global.mode & MODE_MWORKER_WAIT) && listeners == 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003039 ha_alert("[%s.main()] No enabled listener found (check for 'bind' directives) ! Exiting.\n", argv[0]);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003040 /* Note: we don't have to send anything to the old pids because we
3041 * never stopped them. */
3042 exit(1);
3043 }
3044
Willy Tarreaue91bff22020-09-02 11:11:43 +02003045 /* Ok, all listeners should now be bound, close any leftover sockets
Olivier Houchardf73629d2017-04-05 22:33:04 +02003046 * the previous process gave us, we don't need them anymore
3047 */
3048 while (xfer_sock_list != NULL) {
3049 struct xfer_sock_list *tmpxfer = xfer_sock_list->next;
3050 close(xfer_sock_list->fd);
3051 free(xfer_sock_list->iface);
3052 free(xfer_sock_list->namespace);
3053 free(xfer_sock_list);
3054 xfer_sock_list = tmpxfer;
3055 }
Willy Tarreaudd815982007-10-16 12:25:14 +02003056
Willy Tarreaubaaee002006-06-26 02:48:02 +02003057 /* prepare pause/play signals */
Willy Tarreau24f4efa2010-08-27 17:56:48 +02003058 signal_register_fct(SIGTTOU, sig_pause, SIGTTOU);
3059 signal_register_fct(SIGTTIN, sig_listen, SIGTTIN);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003060
Willy Tarreaubaaee002006-06-26 02:48:02 +02003061 /* MODE_QUIET can inhibit alerts and warnings below this line */
3062
PiBa-NL149a81a2017-12-25 21:03:31 +01003063 if (getenv("HAPROXY_MWORKER_REEXEC") != NULL) {
3064 /* either stdin/out/err are already closed or should stay as they are. */
3065 if ((global.mode & MODE_DAEMON)) {
3066 /* daemon mode re-executing, stdin/stdout/stderr are already closed so keep quiet */
3067 global.mode &= ~MODE_VERBOSE;
3068 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
3069 }
3070 } else {
3071 if ((global.mode & MODE_QUIET) && !(global.mode & MODE_VERBOSE)) {
3072 /* detach from the tty */
William Lallemande1340412017-12-28 16:09:36 +01003073 stdio_quiet(-1);
PiBa-NL149a81a2017-12-25 21:03:31 +01003074 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003075 }
3076
3077 /* open log & pid files before the chroot */
William Lallemand80293002017-11-06 11:00:03 +01003078 if ((global.mode & MODE_DAEMON || global.mode & MODE_MWORKER) && global.pidfile != NULL) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003079 unlink(global.pidfile);
3080 pidfd = open(global.pidfile, O_CREAT | O_WRONLY | O_TRUNC, 0644);
3081 if (pidfd < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003082 ha_alert("[%s.main()] Cannot create pidfile %s\n", argv[0], global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003083 if (nb_oldpids)
3084 tell_old_pids(SIGTTIN);
Willy Tarreaudd815982007-10-16 12:25:14 +02003085 protocol_unbind_all();
Willy Tarreaubaaee002006-06-26 02:48:02 +02003086 exit(1);
3087 }
Willy Tarreaubaaee002006-06-26 02:48:02 +02003088 }
3089
Willy Tarreaub38651a2007-03-24 17:24:39 +01003090 if ((global.last_checks & LSTCHK_NETADM) && global.uid) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003091 ha_alert("[%s.main()] Some configuration options require full privileges, so global.uid cannot be changed.\n"
3092 "", argv[0]);
Willy Tarreaudd815982007-10-16 12:25:14 +02003093 protocol_unbind_all();
Willy Tarreaub38651a2007-03-24 17:24:39 +01003094 exit(1);
3095 }
3096
Jackie Tapia749f74c2020-07-22 18:59:40 -05003097 /* If the user is not root, we'll still let them try the configuration
3098 * but we inform them that unexpected behaviour may occur.
Willy Tarreau4e30ed72009-02-04 18:02:48 +01003099 */
3100 if ((global.last_checks & LSTCHK_NETADM) && getuid())
Christopher Faulet767a84b2017-11-24 16:50:31 +01003101 ha_warning("[%s.main()] Some options which require full privileges"
3102 " might not work well.\n"
3103 "", argv[0]);
Willy Tarreau4e30ed72009-02-04 18:02:48 +01003104
William Lallemand095ba4c2017-06-01 17:38:50 +02003105 if ((global.mode & (MODE_MWORKER|MODE_DAEMON)) == 0) {
3106
3107 /* chroot if needed */
3108 if (global.chroot != NULL) {
3109 if (chroot(global.chroot) == -1 || chdir("/") == -1) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003110 ha_alert("[%s.main()] Cannot chroot(%s).\n", argv[0], global.chroot);
William Lallemand095ba4c2017-06-01 17:38:50 +02003111 if (nb_oldpids)
3112 tell_old_pids(SIGTTIN);
3113 protocol_unbind_all();
3114 exit(1);
3115 }
Willy Tarreauf223cc02007-10-15 18:57:08 +02003116 }
Willy Tarreauf223cc02007-10-15 18:57:08 +02003117 }
3118
William Lallemand944e6192018-11-21 15:48:31 +01003119 if (nb_oldpids && !(global.mode & MODE_MWORKER_WAIT))
Willy Tarreaubb545b42010-08-25 12:58:59 +02003120 nb_oldpids = tell_old_pids(oldpids_sig);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003121
William Lallemand27edc4b2019-05-07 17:49:33 +02003122 /* send a SIGTERM to workers who have a too high reloads number */
3123 if ((global.mode & MODE_MWORKER) && !(global.mode & MODE_MWORKER_WAIT))
3124 mworker_kill_max_reloads(SIGTERM);
3125
Willy Tarreaubaaee002006-06-26 02:48:02 +02003126 /* Note that any error at this stage will be fatal because we will not
3127 * be able to restart the old pids.
3128 */
3129
William Dauchyf9af9d72019-11-17 15:47:16 +01003130 if ((global.mode & (MODE_MWORKER | MODE_DAEMON)) == 0)
3131 set_identity(argv[0]);
Willy Tarreau636848a2019-04-15 19:38:50 +02003132
Willy Tarreaubaaee002006-06-26 02:48:02 +02003133 /* check ulimits */
3134 limit.rlim_cur = limit.rlim_max = 0;
3135 getrlimit(RLIMIT_NOFILE, &limit);
3136 if (limit.rlim_cur < global.maxsock) {
William Dauchy0fec3ab2019-10-27 20:08:11 +01003137 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3138 ha_alert("[%s.main()] FD limit (%d) too low for maxconn=%d/maxsock=%d. "
3139 "Please raise 'ulimit-n' to %d or more to avoid any trouble.\n",
3140 argv[0], (int)limit.rlim_cur, global.maxconn, global.maxsock,
3141 global.maxsock);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003142 exit(1);
William Dauchy0fec3ab2019-10-27 20:08:11 +01003143 }
3144 else
3145 ha_alert("[%s.main()] FD limit (%d) too low for maxconn=%d/maxsock=%d. "
William Dauchya5194602020-03-28 19:29:58 +01003146 "Please raise 'ulimit-n' to %d or more to avoid any trouble.\n",
William Dauchy0fec3ab2019-10-27 20:08:11 +01003147 argv[0], (int)limit.rlim_cur, global.maxconn, global.maxsock,
3148 global.maxsock);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003149 }
3150
William Lallemand944e6192018-11-21 15:48:31 +01003151 if (global.mode & (MODE_DAEMON | MODE_MWORKER | MODE_MWORKER_WAIT)) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003152 int ret = 0;
Willy Tarreaud67ff342021-06-15 07:58:09 +02003153 int in_parent = 0;
William Lallemande1340412017-12-28 16:09:36 +01003154 int devnullfd = -1;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003155
William Lallemand095ba4c2017-06-01 17:38:50 +02003156 /*
3157 * if daemon + mworker: must fork here to let a master
3158 * process live in background before forking children
3159 */
William Lallemand73b85e72017-06-01 17:38:51 +02003160
3161 if ((getenv("HAPROXY_MWORKER_REEXEC") == NULL)
3162 && (global.mode & MODE_MWORKER)
3163 && (global.mode & MODE_DAEMON)) {
William Lallemand095ba4c2017-06-01 17:38:50 +02003164 ret = fork();
3165 if (ret < 0) {
Christopher Faulet767a84b2017-11-24 16:50:31 +01003166 ha_alert("[%s.main()] Cannot fork.\n", argv[0]);
William Lallemand095ba4c2017-06-01 17:38:50 +02003167 protocol_unbind_all();
3168 exit(1); /* there has been an error */
William Lallemandbfd8eb52018-07-04 15:31:23 +02003169 } else if (ret > 0) { /* parent leave to daemonize */
William Lallemand095ba4c2017-06-01 17:38:50 +02003170 exit(0);
William Lallemandbfd8eb52018-07-04 15:31:23 +02003171 } else /* change the process group ID in the child (master process) */
3172 setsid();
William Lallemand095ba4c2017-06-01 17:38:50 +02003173 }
William Lallemande20b6a62017-06-01 17:38:55 +02003174
William Lallemande20b6a62017-06-01 17:38:55 +02003175
William Lallemanddeed7802017-11-06 11:00:04 +01003176 /* if in master-worker mode, write the PID of the father */
3177 if (global.mode & MODE_MWORKER) {
3178 char pidstr[100];
Willy Tarreau76a80c72019-06-22 07:41:38 +02003179 snprintf(pidstr, sizeof(pidstr), "%d\n", (int)getpid());
Willy Tarreau46ec48b2018-01-23 19:20:19 +01003180 if (pidfd >= 0)
Willy Tarreau2e8ab6b2020-03-14 11:03:20 +01003181 DISGUISE(write(pidfd, pidstr, strlen(pidstr)));
William Lallemanddeed7802017-11-06 11:00:04 +01003182 }
3183
Willy Tarreaubaaee002006-06-26 02:48:02 +02003184 /* the father launches the required number of processes */
William Lallemand944e6192018-11-21 15:48:31 +01003185 if (!(global.mode & MODE_MWORKER_WAIT)) {
William Lallemand9a1ee7a2019-04-01 11:30:02 +02003186 if (global.mode & MODE_MWORKER)
3187 mworker_ext_launch_all();
Willy Tarreaud67ff342021-06-15 07:58:09 +02003188
3189 ret = fork();
3190 if (ret < 0) {
3191 ha_alert("[%s.main()] Cannot fork.\n", argv[0]);
3192 protocol_unbind_all();
3193 exit(1); /* there has been an error */
3194 }
3195 else if (ret == 0) { /* child breaks here */
Willy Tarreau3c032f22021-07-21 10:17:02 +02003196 /* This one must not be exported, it's internal! */
3197 unsetenv("HAPROXY_MWORKER_REEXEC");
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003198 ha_random_jump96(1);
Willy Tarreaud67ff342021-06-15 07:58:09 +02003199 }
3200 else { /* parent here */
3201 in_parent = 1;
3202
William Lallemand944e6192018-11-21 15:48:31 +01003203 if (pidfd >= 0 && !(global.mode & MODE_MWORKER)) {
3204 char pidstr[100];
3205 snprintf(pidstr, sizeof(pidstr), "%d\n", ret);
Willy Tarreau2e8ab6b2020-03-14 11:03:20 +01003206 DISGUISE(write(pidfd, pidstr, strlen(pidstr)));
William Lallemand944e6192018-11-21 15:48:31 +01003207 }
3208 if (global.mode & MODE_MWORKER) {
3209 struct mworker_proc *child;
William Lallemandce83b4a2018-10-26 14:47:30 +02003210
William Lallemand5d71a6b2021-11-09 15:25:31 +01003211 ha_notice("New worker (%d) forked\n", ret);
William Lallemand944e6192018-11-21 15:48:31 +01003212 /* find the right mworker_proc */
3213 list_for_each_entry(child, &proc_list, list) {
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003214 if (child->reloads == 0 && child->options & PROC_O_TYPE_WORKER) {
William Lallemand944e6192018-11-21 15:48:31 +01003215 child->timestamp = now.tv_sec;
3216 child->pid = ret;
William Lallemand1dc69632019-06-12 19:11:33 +02003217 child->version = strdup(haproxy_version);
William Lallemand944e6192018-11-21 15:48:31 +01003218 break;
3219 }
William Lallemandce83b4a2018-10-26 14:47:30 +02003220 }
3221 }
William Lallemand944e6192018-11-21 15:48:31 +01003222 }
Willy Tarreaud67ff342021-06-15 07:58:09 +02003223
William Lallemand944e6192018-11-21 15:48:31 +01003224 } else {
3225 /* wait mode */
Willy Tarreaud67ff342021-06-15 07:58:09 +02003226 in_parent = 1;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003227 }
Willy Tarreaufc6c0322012-11-16 16:12:27 +01003228
3229#ifdef USE_CPU_AFFINITY
Willy Tarreau44ea6312021-06-15 08:57:56 +02003230 if (!in_parent && ha_cpuset_count(&cpu_map.proc)) { /* only do this if the process has a CPU map */
Olivier Houchard97148f62017-08-16 17:29:11 +02003231
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003232#ifdef __FreeBSD__
Willy Tarreau44ea6312021-06-15 08:57:56 +02003233 struct hap_cpuset *set = &cpu_map.proc;
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003234 ret = cpuset_setaffinity(CPU_LEVEL_WHICH, CPU_WHICH_PID, -1, sizeof(set->cpuset), &set->cpuset);
David Carlier2d0493a2020-12-02 21:14:51 +00003235#elif defined(__linux__) || defined(__DragonFly__)
Willy Tarreau44ea6312021-06-15 08:57:56 +02003236 struct hap_cpuset *set = &cpu_map.proc;
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003237 sched_setaffinity(0, sizeof(set->cpuset), &set->cpuset);
Willy Tarreaufc6c0322012-11-16 16:12:27 +01003238#endif
Amaury Denoyelle982fb532021-04-21 18:39:58 +02003239 }
Pieter Baauwcaa6a1b2015-09-17 21:26:40 +02003240#endif
Willy Tarreaubaaee002006-06-26 02:48:02 +02003241 /* close the pidfile both in children and father */
Willy Tarreau269ab312012-09-05 08:02:48 +02003242 if (pidfd >= 0) {
3243 //lseek(pidfd, 0, SEEK_SET); /* debug: emulate eglibc bug */
3244 close(pidfd);
3245 }
Willy Tarreaud137dd32010-08-25 12:49:05 +02003246
3247 /* We won't ever use this anymore */
Willy Tarreau61cfdf42021-02-20 10:46:51 +01003248 ha_free(&global.pidfile);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003249
Willy Tarreaud67ff342021-06-15 07:58:09 +02003250 if (in_parent) {
William Lallemand944e6192018-11-21 15:48:31 +01003251 if (global.mode & (MODE_MWORKER|MODE_MWORKER_WAIT)) {
William Lallemandfab0fdc2021-11-09 18:01:22 +01003252 master = 1;
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003253
3254 if ((!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE)) &&
3255 (global.mode & MODE_DAEMON)) {
3256 /* detach from the tty, this is required to properly daemonize. */
William Lallemande1340412017-12-28 16:09:36 +01003257 if ((getenv("HAPROXY_MWORKER_REEXEC") == NULL))
3258 stdio_quiet(-1);
3259
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003260 global.mode &= ~MODE_VERBOSE;
3261 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
PiBa-NLbaf6ea42017-11-28 23:26:08 +01003262 }
3263
William Lallemandfab0fdc2021-11-09 18:01:22 +01003264 if (global.mode & MODE_MWORKER_WAIT) {
3265 /* only the wait mode handles the master CLI */
3266 mworker_loop();
3267 } else {
3268
3269 /* if not in wait mode, reload in wait mode to free the memory */
William Lallemand836bda22021-11-09 18:16:47 +01003270 ha_notice("Loading success.\n");
William Lallemandfab0fdc2021-11-09 18:01:22 +01003271 mworker_reexec_waitmode();
3272 }
William Lallemand1499b9b2017-06-07 15:04:47 +02003273 /* should never get there */
3274 exit(EXIT_FAILURE);
Willy Tarreauedaff0a2015-05-01 17:01:08 +02003275 }
William Lallemandcf4e4962017-06-08 19:05:48 +02003276#if defined(USE_OPENSSL) && !defined(OPENSSL_NO_DH)
Grant Zhang872f9c22017-01-21 01:10:18 +00003277 ssl_free_dh();
3278#endif
William Lallemand1499b9b2017-06-07 15:04:47 +02003279 exit(0); /* parent must leave */
Willy Tarreauedaff0a2015-05-01 17:01:08 +02003280 }
3281
William Lallemandcb11fd22017-06-01 17:38:52 +02003282 /* child must never use the atexit function */
3283 atexit_flag = 0;
3284
William Lallemandbc193052018-09-11 10:06:26 +02003285 /* close useless master sockets */
3286 if (global.mode & MODE_MWORKER) {
3287 struct mworker_proc *child, *it;
3288 master = 0;
3289
William Lallemand309dc9a2018-10-26 14:47:45 +02003290 mworker_cli_proxy_stop();
3291
William Lallemandbc193052018-09-11 10:06:26 +02003292 /* free proc struct of other processes */
3293 list_for_each_entry_safe(child, it, &proc_list, list) {
William Lallemandce83b4a2018-10-26 14:47:30 +02003294 /* close the FD of the master side for all
3295 * workers, we don't need to close the worker
3296 * side of other workers since it's done with
3297 * the bind_proc */
Tim Duesterhus742e0f92018-11-25 20:03:39 +01003298 if (child->ipc_fd[0] >= 0)
3299 close(child->ipc_fd[0]);
Willy Tarreaue8422bf2021-06-15 09:08:18 +02003300 if (child->options & PROC_O_TYPE_WORKER &&
William Lallemandce83b4a2018-10-26 14:47:30 +02003301 child->reloads == 0) {
3302 /* keep this struct if this is our pid */
3303 proc_self = child;
William Lallemandbc193052018-09-11 10:06:26 +02003304 continue;
William Lallemandce83b4a2018-10-26 14:47:30 +02003305 }
Willy Tarreau2b718102021-04-21 07:32:39 +02003306 LIST_DELETE(&child->list);
Tim Duesterhus9b7a9762019-05-16 20:23:22 +02003307 mworker_free_child(child);
3308 child = NULL;
William Lallemandbc193052018-09-11 10:06:26 +02003309 }
3310 }
Willy Tarreau1605c7a2018-01-23 19:01:49 +01003311
William Lallemande1340412017-12-28 16:09:36 +01003312 if (!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE)) {
3313 devnullfd = open("/dev/null", O_RDWR, 0);
3314 if (devnullfd < 0) {
3315 ha_alert("Cannot open /dev/null\n");
3316 exit(EXIT_FAILURE);
3317 }
3318 }
3319
William Lallemand095ba4c2017-06-01 17:38:50 +02003320 /* Must chroot and setgid/setuid in the children */
3321 /* chroot if needed */
3322 if (global.chroot != NULL) {
3323 if (chroot(global.chroot) == -1 || chdir("/") == -1) {
Willy Tarreaue34cf282021-06-15 08:59:19 +02003324 ha_alert("[%s.main()] Cannot chroot(%s).\n", argv[0], global.chroot);
William Lallemand095ba4c2017-06-01 17:38:50 +02003325 if (nb_oldpids)
3326 tell_old_pids(SIGTTIN);
3327 protocol_unbind_all();
3328 exit(1);
3329 }
3330 }
3331
Willy Tarreau61cfdf42021-02-20 10:46:51 +01003332 ha_free(&global.chroot);
William Dauchyf9af9d72019-11-17 15:47:16 +01003333 set_identity(argv[0]);
William Lallemand095ba4c2017-06-01 17:38:50 +02003334
William Lallemand7f80eb22017-05-26 18:19:55 +02003335 /* pass through every cli socket, and check if it's bound to
3336 * the current process and if it exposes listeners sockets.
3337 * Caution: the GTUNE_SOCKET_TRANSFER is now set after the fork.
3338 * */
3339
Willy Tarreau4975d142021-03-13 11:00:33 +01003340 if (global.cli_fe) {
William Lallemand7f80eb22017-05-26 18:19:55 +02003341 struct bind_conf *bind_conf;
3342
Willy Tarreau4975d142021-03-13 11:00:33 +01003343 list_for_each_entry(bind_conf, &global.cli_fe->conf.bind, by_fe) {
William Lallemand7f80eb22017-05-26 18:19:55 +02003344 if (bind_conf->level & ACCESS_FD_LISTENERS) {
Willy Tarreau72faef32021-06-15 08:36:30 +02003345 global.tune.options |= GTUNE_SOCKET_TRANSFER;
3346 break;
William Lallemand7f80eb22017-05-26 18:19:55 +02003347 }
3348 }
Willy Tarreauf83d3fe2015-05-01 19:13:41 +02003349 }
3350
William Lallemand2e8fad92018-11-13 16:18:23 +01003351 /*
3352 * This is only done in daemon mode because we might want the
3353 * logs on stdout in mworker mode. If we're NOT in QUIET mode,
3354 * we should now close the 3 first FDs to ensure that we can
3355 * detach from the TTY. We MUST NOT do it in other cases since
3356 * it would have already be done, and 0-2 would have been
3357 * affected to listening sockets
Willy Tarreaubaaee002006-06-26 02:48:02 +02003358 */
William Lallemand2e8fad92018-11-13 16:18:23 +01003359 if ((global.mode & MODE_DAEMON) &&
3360 (!(global.mode & MODE_QUIET) || (global.mode & MODE_VERBOSE))) {
Willy Tarreaubaaee002006-06-26 02:48:02 +02003361 /* detach from the tty */
William Lallemande1340412017-12-28 16:09:36 +01003362 stdio_quiet(devnullfd);
Willy Tarreau106cb762008-11-16 07:40:34 +01003363 global.mode &= ~MODE_VERBOSE;
Willy Tarreaubaaee002006-06-26 02:48:02 +02003364 global.mode |= MODE_QUIET; /* ensure that we won't say anything from now */
3365 }
3366 pid = getpid(); /* update child's pid */
William Lallemandbfd8eb52018-07-04 15:31:23 +02003367 if (!(global.mode & MODE_MWORKER)) /* in mworker mode we don't want a new pgid for the children */
3368 setsid();
Willy Tarreau2ff76222007-04-09 19:29:56 +02003369 fork_poller();
Willy Tarreaubaaee002006-06-26 02:48:02 +02003370 }
3371
William Dauchye039f262019-11-17 15:47:15 +01003372 /* try our best to re-enable core dumps depending on system capabilities.
3373 * What is addressed here :
3374 * - remove file size limits
3375 * - remove core size limits
3376 * - mark the process dumpable again if it lost it due to user/group
3377 */
3378 if (global.tune.options & GTUNE_SET_DUMPABLE) {
3379 limit.rlim_cur = limit.rlim_max = RLIM_INFINITY;
3380
3381#if defined(RLIMIT_FSIZE)
3382 if (setrlimit(RLIMIT_FSIZE, &limit) == -1) {
3383 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3384 ha_alert("[%s.main()] Failed to set the raise the maximum "
3385 "file size.\n", argv[0]);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003386 exit(1);
William Dauchye039f262019-11-17 15:47:15 +01003387 }
3388 else
3389 ha_warning("[%s.main()] Failed to set the raise the maximum "
William Dauchya5194602020-03-28 19:29:58 +01003390 "file size.\n", argv[0]);
William Dauchye039f262019-11-17 15:47:15 +01003391 }
3392#endif
3393
3394#if defined(RLIMIT_CORE)
3395 if (setrlimit(RLIMIT_CORE, &limit) == -1) {
3396 if (global.tune.options & GTUNE_STRICT_LIMITS) {
3397 ha_alert("[%s.main()] Failed to set the raise the core "
3398 "dump size.\n", argv[0]);
Jerome Magnin50f757c2021-01-12 20:19:38 +01003399 exit(1);
William Dauchye039f262019-11-17 15:47:15 +01003400 }
3401 else
3402 ha_warning("[%s.main()] Failed to set the raise the core "
William Dauchya5194602020-03-28 19:29:58 +01003403 "dump size.\n", argv[0]);
William Dauchye039f262019-11-17 15:47:15 +01003404 }
3405#endif
3406
3407#if defined(USE_PRCTL)
3408 if (prctl(PR_SET_DUMPABLE, 1, 0, 0, 0) == -1)
3409 ha_warning("[%s.main()] Failed to set the dumpable flag, "
3410 "no core will be dumped.\n", argv[0]);
devnexen@gmail.com21185972021-08-21 09:13:10 +01003411#elif defined(USE_PROCCTL)
Willy Tarreau28345c62021-10-08 15:55:13 +02003412 {
3413 int traceable = PROC_TRACE_CTL_ENABLE;
3414 if (procctl(P_PID, getpid(), PROC_TRACE_CTL, &traceable) == -1)
3415 ha_warning("[%s.main()] Failed to set the traceable flag, "
3416 "no core will be dumped.\n", argv[0]);
3417 }
William Dauchye039f262019-11-17 15:47:15 +01003418#endif
3419 }
3420
Christopher Faulete3a5e352017-10-24 13:53:54 +02003421 global.mode &= ~MODE_STARTING;
Amaury Denoyelle6af81f82021-05-27 15:45:28 +02003422 reset_usermsgs_ctx();
3423
Willy Tarreau2d5d4e02021-09-28 10:36:57 +02003424 /* start threads 2 and above */
Willy Tarreaud10385a2021-10-06 22:22:40 +02003425 setup_extra_threads(&run_thread_poll_loop);
William Lallemand1aab50b2018-06-07 09:46:01 +02003426
Willy Tarreau2d5d4e02021-09-28 10:36:57 +02003427 /* when multithreading we need to let only the thread 0 handle the signals */
William Lallemandd3801c12018-09-11 10:06:23 +02003428 haproxy_unblock_signals();
Willy Tarreau2d5d4e02021-09-28 10:36:57 +02003429
3430 /* Finally, start the poll loop for the first thread */
Willy Tarreau43ab05b2021-09-28 09:43:11 +02003431 run_thread_poll_loop(&ha_thread_info[0]);
Willy Tarreau2d5d4e02021-09-28 10:36:57 +02003432
3433 /* wait for all threads to terminate */
3434 wait_for_threads_completion();
Christopher Faulet1d17c102017-08-29 15:38:48 +02003435
Tim Duesterhus0a3b43d2020-06-14 00:37:42 +02003436 deinit_and_exit(0);
Willy Tarreaubaaee002006-06-26 02:48:02 +02003437}
3438
Willy Tarreaubaaee002006-06-26 02:48:02 +02003439/*
3440 * Local variables:
3441 * c-indent-level: 8
3442 * c-basic-offset: 8
3443 * End:
3444 */