2 * collectd - src/procevent.c
4 * Permission is hereby granted, free of charge, to any person obtaining a
5 * copy of this software and associated documentation files (the "Software"),
6 * to deal in the Software without restriction, including without limitation
7 * the rights to use, copy, modify, merge, publish, distribute, sublicense,
8 * and/or sell copies of the Software, and to permit persons to whom the
9 * Software is furnished to do so, subject to the following conditions:
11 * The above copyright notice and this permission notice shall be included in
12 * all copies or substantial portions of the Software.
14 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
15 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
16 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
17 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
18 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
19 * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
20 * DEALINGS IN THE SOFTWARE.
24 * Andrew Bays <abays at redhat.com>
31 #include "utils_complain.h"
38 #include <sys/socket.h>
42 #include <linux/cn_proc.h>
43 #include <linux/connector.h>
44 #include <linux/netlink.h>
45 #include <linux/rtnetlink.h>
51 #include <yajl/yajl_common.h>
52 #include <yajl/yajl_gen.h>
53 #if HAVE_YAJL_YAJL_VERSION_H
54 #include <yajl/yajl_version.h>
56 #if defined(YAJL_MAJOR) && (YAJL_MAJOR > 1)
57 #define HAVE_YAJL_V2 1
60 #define PROCEVENT_EXITED 0
61 #define PROCEVENT_STARTED 1
62 #define PROCEVENT_FIELDS 4 // pid, status, extra, timestamp
64 #define PROCDIR "/proc"
65 #define PROCEVENT_REGEX_MATCHES 1
67 #define PROCEVENT_DOMAIN_FIELD "domain"
68 #define PROCEVENT_DOMAIN_VALUE "fault"
69 #define PROCEVENT_EVENT_ID_FIELD "eventId"
70 #define PROCEVENT_EVENT_NAME_FIELD "eventName"
71 #define PROCEVENT_EVENT_NAME_DOWN_VALUE "down"
72 #define PROCEVENT_EVENT_NAME_UP_VALUE "up"
73 #define PROCEVENT_LAST_EPOCH_MICROSEC_FIELD "lastEpochMicrosec"
74 #define PROCEVENT_PRIORITY_FIELD "priority"
75 #define PROCEVENT_PRIORITY_VALUE "high"
76 #define PROCEVENT_REPORTING_ENTITY_NAME_FIELD "reportingEntityName"
77 #define PROCEVENT_REPORTING_ENTITY_NAME_VALUE "collectd procevent plugin"
78 #define PROCEVENT_SEQUENCE_FIELD "sequence"
79 #define PROCEVENT_SEQUENCE_VALUE "0"
80 #define PROCEVENT_SOURCE_NAME_FIELD "sourceName"
81 #define PROCEVENT_START_EPOCH_MICROSEC_FIELD "startEpochMicrosec"
82 #define PROCEVENT_VERSION_FIELD "version"
83 #define PROCEVENT_VERSION_VALUE "1.0"
85 #define PROCEVENT_ALARM_CONDITION_FIELD "alarmCondition"
86 #define PROCEVENT_ALARM_INTERFACE_A_FIELD "alarmInterfaceA"
87 #define PROCEVENT_EVENT_SEVERITY_FIELD "eventSeverity"
88 #define PROCEVENT_EVENT_SEVERITY_CRITICAL_VALUE "CRITICAL"
89 #define PROCEVENT_EVENT_SEVERITY_NORMAL_VALUE "NORMAL"
90 #define PROCEVENT_EVENT_SOURCE_TYPE_FIELD "eventSourceType"
91 #define PROCEVENT_EVENT_SOURCE_TYPE_VALUE "process"
92 #define PROCEVENT_FAULT_FIELDS_FIELD "faultFields"
93 #define PROCEVENT_FAULT_FIELDS_VERSION_FIELD "faultFieldsVersion"
94 #define PROCEVENT_FAULT_FIELDS_VERSION_VALUE "1.0"
95 #define PROCEVENT_SPECIFIC_PROBLEM_FIELD "specificProblem"
96 #define PROCEVENT_SPECIFIC_PROBLEM_DOWN_VALUE "down"
97 #define PROCEVENT_SPECIFIC_PROBLEM_UP_VALUE "up"
98 #define PROCEVENT_VF_STATUS_FIELD "vfStatus"
99 #define PROCEVENT_VF_STATUS_CRITICAL_VALUE "Ready to terminate"
100 #define PROCEVENT_VF_STATUS_NORMAL_VALUE "Active"
110 long long unsigned int **buffer;
113 struct processlist_s {
117 regex_t process_regex_obj;
122 struct processlist_s *next;
124 typedef struct processlist_s processlist_t;
130 static int procevent_thread_loop = 0;
131 static int procevent_thread_error = 0;
132 static pthread_t procevent_thread_id;
133 static pthread_mutex_t procevent_lock = PTHREAD_MUTEX_INITIALIZER;
134 static pthread_cond_t procevent_cond = PTHREAD_COND_INITIALIZER;
135 static pthread_mutex_t procevent_list_lock = PTHREAD_MUTEX_INITIALIZER;
136 static int nl_sock = -1;
137 static int buffer_length;
138 static circbuf_t ring;
139 static processlist_t *processlist_head = NULL;
140 static int event_id = 0;
142 static const char *config_keys[] = {"BufferLength", "Process", "RegexProcess"};
143 static int config_keys_num = STATIC_ARRAY_SIZE(config_keys);
149 static int gen_message_payload(int state, int pid, char *process,
150 long long unsigned int timestamp, char **buf) {
151 const unsigned char *buf2;
153 char json_str[DATA_MAX_NAME_LEN];
155 #if !defined(HAVE_YAJL_V2)
156 yajl_gen_config conf = {};
163 g = yajl_gen_alloc(NULL);
164 yajl_gen_config(g, yajl_gen_beautify, 0);
167 g = yajl_gen_alloc(&conf, NULL);
172 // *** BEGIN common event header ***
174 if (yajl_gen_map_open(g) != yajl_gen_status_ok)
178 if (yajl_gen_string(g, (u_char *)PROCEVENT_DOMAIN_FIELD,
179 strlen(PROCEVENT_DOMAIN_FIELD)) != yajl_gen_status_ok)
182 if (yajl_gen_string(g, (u_char *)PROCEVENT_DOMAIN_VALUE,
183 strlen(PROCEVENT_DOMAIN_VALUE)) != yajl_gen_status_ok)
187 if (yajl_gen_string(g, (u_char *)PROCEVENT_EVENT_ID_FIELD,
188 strlen(PROCEVENT_EVENT_ID_FIELD)) != yajl_gen_status_ok)
191 event_id = event_id + 1;
192 int event_id_len = sizeof(char) * sizeof(int) * 4 + 1;
193 memset(json_str, '\0', DATA_MAX_NAME_LEN);
194 snprintf(json_str, event_id_len, "%d", event_id);
196 if (yajl_gen_number(g, json_str, strlen(json_str)) != yajl_gen_status_ok) {
201 if (yajl_gen_string(g, (u_char *)PROCEVENT_EVENT_NAME_FIELD,
202 strlen(PROCEVENT_EVENT_NAME_FIELD)) != yajl_gen_status_ok)
205 int event_name_len = 0;
206 event_name_len = event_name_len + (sizeof(char) * sizeof(int) * 4); // pid
207 event_name_len = event_name_len + strlen(process); // process name
208 event_name_len = event_name_len + (state == 0 ? 4 : 2); // "down" or "up"
209 event_name_len = event_name_len +
210 13; // "process", 3 spaces, 2 parentheses and null-terminator
211 memset(json_str, '\0', DATA_MAX_NAME_LEN);
212 snprintf(json_str, event_name_len, "process %s (%d) %s", process, pid,
213 (state == 0 ? PROCEVENT_EVENT_NAME_DOWN_VALUE
214 : PROCEVENT_EVENT_NAME_UP_VALUE));
216 if (yajl_gen_string(g, (u_char *)json_str, strlen(json_str)) !=
217 yajl_gen_status_ok) {
222 if (yajl_gen_string(g, (u_char *)PROCEVENT_LAST_EPOCH_MICROSEC_FIELD,
223 strlen(PROCEVENT_LAST_EPOCH_MICROSEC_FIELD)) !=
227 int last_epoch_microsec_len =
228 sizeof(char) * sizeof(long long unsigned int) * 4 + 1;
229 memset(json_str, '\0', DATA_MAX_NAME_LEN);
230 snprintf(json_str, last_epoch_microsec_len, "%llu",
231 (long long unsigned int)CDTIME_T_TO_US(cdtime()));
233 if (yajl_gen_number(g, json_str, strlen(json_str)) != yajl_gen_status_ok) {
238 if (yajl_gen_string(g, (u_char *)PROCEVENT_PRIORITY_FIELD,
239 strlen(PROCEVENT_PRIORITY_FIELD)) != yajl_gen_status_ok)
242 if (yajl_gen_string(g, (u_char *)PROCEVENT_PRIORITY_VALUE,
243 strlen(PROCEVENT_PRIORITY_VALUE)) != yajl_gen_status_ok)
246 // reportingEntityName
247 if (yajl_gen_string(g, (u_char *)PROCEVENT_REPORTING_ENTITY_NAME_FIELD,
248 strlen(PROCEVENT_REPORTING_ENTITY_NAME_FIELD)) !=
252 if (yajl_gen_string(g, (u_char *)PROCEVENT_REPORTING_ENTITY_NAME_VALUE,
253 strlen(PROCEVENT_REPORTING_ENTITY_NAME_VALUE)) !=
258 if (yajl_gen_string(g, (u_char *)PROCEVENT_SEQUENCE_FIELD,
259 strlen(PROCEVENT_SEQUENCE_FIELD)) != yajl_gen_status_ok)
262 if (yajl_gen_number(g, PROCEVENT_SEQUENCE_VALUE,
263 strlen(PROCEVENT_SEQUENCE_VALUE)) != yajl_gen_status_ok)
267 if (yajl_gen_string(g, (u_char *)PROCEVENT_SOURCE_NAME_FIELD,
268 strlen(PROCEVENT_SOURCE_NAME_FIELD)) !=
272 if (yajl_gen_string(g, (u_char *)process, strlen(process)) !=
276 // startEpochMicrosec
277 if (yajl_gen_string(g, (u_char *)PROCEVENT_START_EPOCH_MICROSEC_FIELD,
278 strlen(PROCEVENT_START_EPOCH_MICROSEC_FIELD)) !=
282 int start_epoch_microsec_len =
283 sizeof(char) * sizeof(long long unsigned int) * 4 + 1;
284 memset(json_str, '\0', DATA_MAX_NAME_LEN);
285 snprintf(json_str, start_epoch_microsec_len, "%llu",
286 (long long unsigned int)timestamp);
288 if (yajl_gen_number(g, json_str, strlen(json_str)) != yajl_gen_status_ok) {
293 if (yajl_gen_string(g, (u_char *)PROCEVENT_VERSION_FIELD,
294 strlen(PROCEVENT_VERSION_FIELD)) != yajl_gen_status_ok)
297 if (yajl_gen_number(g, PROCEVENT_VERSION_VALUE,
298 strlen(PROCEVENT_VERSION_VALUE)) != yajl_gen_status_ok)
301 // *** END common event header ***
303 // *** BEGIN fault fields ***
305 if (yajl_gen_string(g, (u_char *)PROCEVENT_FAULT_FIELDS_FIELD,
306 strlen(PROCEVENT_FAULT_FIELDS_FIELD)) !=
310 if (yajl_gen_map_open(g) != yajl_gen_status_ok)
314 if (yajl_gen_string(g, (u_char *)PROCEVENT_ALARM_CONDITION_FIELD,
315 strlen(PROCEVENT_ALARM_CONDITION_FIELD)) !=
319 int alarm_condition_len = 0;
320 alarm_condition_len =
321 alarm_condition_len + (sizeof(char) * sizeof(int) * 4); // pid
322 alarm_condition_len = alarm_condition_len + strlen(process); // process name
323 alarm_condition_len =
324 alarm_condition_len + 25; // "process", "state", "change", 4 spaces, 2
325 // parentheses and null-terminator
326 memset(json_str, '\0', DATA_MAX_NAME_LEN);
327 snprintf(json_str, alarm_condition_len, "process %s (%d) state change",
330 if (yajl_gen_string(g, (u_char *)json_str, strlen(json_str)) !=
331 yajl_gen_status_ok) {
336 if (yajl_gen_string(g, (u_char *)PROCEVENT_ALARM_INTERFACE_A_FIELD,
337 strlen(PROCEVENT_ALARM_INTERFACE_A_FIELD)) !=
341 if (yajl_gen_string(g, (u_char *)process, strlen(process)) !=
346 if (yajl_gen_string(g, (u_char *)PROCEVENT_EVENT_SEVERITY_FIELD,
347 strlen(PROCEVENT_EVENT_SEVERITY_FIELD)) !=
352 g, (u_char *)(state == 0 ? PROCEVENT_EVENT_SEVERITY_CRITICAL_VALUE
353 : PROCEVENT_EVENT_SEVERITY_NORMAL_VALUE),
354 strlen((state == 0 ? PROCEVENT_EVENT_SEVERITY_CRITICAL_VALUE
355 : PROCEVENT_EVENT_SEVERITY_NORMAL_VALUE))) !=
360 if (yajl_gen_string(g, (u_char *)PROCEVENT_EVENT_SOURCE_TYPE_FIELD,
361 strlen(PROCEVENT_EVENT_SOURCE_TYPE_FIELD)) !=
365 if (yajl_gen_string(g, (u_char *)PROCEVENT_EVENT_SOURCE_TYPE_VALUE,
366 strlen(PROCEVENT_EVENT_SOURCE_TYPE_VALUE)) !=
370 // faultFieldsVersion
371 if (yajl_gen_string(g, (u_char *)PROCEVENT_FAULT_FIELDS_VERSION_FIELD,
372 strlen(PROCEVENT_FAULT_FIELDS_VERSION_FIELD)) !=
376 if (yajl_gen_number(g, PROCEVENT_FAULT_FIELDS_VERSION_VALUE,
377 strlen(PROCEVENT_FAULT_FIELDS_VERSION_VALUE)) !=
382 if (yajl_gen_string(g, (u_char *)PROCEVENT_SPECIFIC_PROBLEM_FIELD,
383 strlen(PROCEVENT_SPECIFIC_PROBLEM_FIELD)) !=
387 int specific_problem_len = 0;
388 specific_problem_len =
389 specific_problem_len + (sizeof(char) * sizeof(int) * 4); // pid
390 specific_problem_len = specific_problem_len + strlen(process); // process name
391 specific_problem_len =
392 specific_problem_len + (state == 0 ? 4 : 2); // "down" or "up"
393 specific_problem_len =
394 specific_problem_len +
395 13; // "process", 3 spaces, 2 parentheses and null-terminator
396 memset(json_str, '\0', DATA_MAX_NAME_LEN);
397 snprintf(json_str, specific_problem_len, "process %s (%d) %s", process, pid,
398 (state == 0 ? PROCEVENT_SPECIFIC_PROBLEM_DOWN_VALUE
399 : PROCEVENT_SPECIFIC_PROBLEM_UP_VALUE));
401 if (yajl_gen_string(g, (u_char *)json_str, strlen(json_str)) !=
402 yajl_gen_status_ok) {
407 if (yajl_gen_string(g, (u_char *)PROCEVENT_VF_STATUS_FIELD,
408 strlen(PROCEVENT_VF_STATUS_FIELD)) != yajl_gen_status_ok)
412 g, (u_char *)(state == 0 ? PROCEVENT_VF_STATUS_CRITICAL_VALUE
413 : PROCEVENT_VF_STATUS_NORMAL_VALUE),
414 strlen((state == 0 ? PROCEVENT_VF_STATUS_CRITICAL_VALUE
415 : PROCEVENT_VF_STATUS_NORMAL_VALUE))) !=
419 if (yajl_gen_map_close(g) != yajl_gen_status_ok)
422 // *** END fault fields ***
424 if (yajl_gen_map_close(g) != yajl_gen_status_ok)
427 if (yajl_gen_get_buf(g, &buf2, &len) != yajl_gen_status_ok)
430 *buf = malloc(strlen((char *)buf2) + 1);
432 sstrncpy(*buf, (char *)buf2, strlen((char *)buf2) + 1);
440 ERROR("procevent plugin: gen_message_payload failed to generate JSON");
444 // Does /proc/<pid>/comm contain a process name we are interested in?
445 static processlist_t *process_check(int pid) {
446 int len, is_match, status, retval;
449 char buffer[BUFSIZE];
450 regmatch_t matches[PROCEVENT_REGEX_MATCHES];
452 len = snprintf(file, sizeof(file), PROCDIR "/%d/comm", pid);
454 if ((len < 0) || (len >= BUFSIZE)) {
455 WARNING("procevent process_check: process name too large");
459 if (NULL == (fh = fopen(file, "r"))) {
460 // No /proc/<pid>/comm for this pid, just ignore
461 DEBUG("procevent plugin: no comm file available for pid %d", pid);
465 retval = fscanf(fh, "%[^\n]", buffer);
468 WARNING("procevent process_check: unable to read comm file for pid %d",
474 // Go through the processlist linked list and look for the process name
475 // in /proc/<pid>/comm. If found:
476 // 1. If pl->pid is -1, then set pl->pid to <pid>
477 // 2. If pl->pid is not -1, then another <process name> process was already
478 // found. If <pid> == pl->pid, this is an old match, so do nothing.
479 // If the <pid> is different, however, make a new processlist_t and
480 // associate <pid> with it (with the same process name as the existing).
483 pthread_mutex_lock(&procevent_list_lock);
486 processlist_t *match = NULL;
488 for (pl = processlist_head; pl != NULL; pl = pl->next) {
489 if (pl->is_regex != 0) {
490 is_match = (regexec(&pl->process_regex_obj, buffer,
491 PROCEVENT_REGEX_MATCHES, matches, 0) == 0
495 is_match = (strcmp(buffer, pl->process) == 0 ? 1 : 0);
499 DEBUG("procevent plugin: process %d name match (pattern: %s) for %s", pid,
500 (pl->is_regex == 0 ? pl->process : pl->process_regex), buffer);
502 if (pl->is_regex == 1) {
503 // If this is a regex name, copy the actual process name into the object
504 // for cleaner log reporting
506 if (pl->process != NULL)
508 pl->process = strdup(buffer);
509 if (pl->process == NULL) {
511 ERROR("procevent plugin: strdup failed during process_check: %s",
512 sstrerror(errno, errbuf, sizeof(errbuf)));
513 pthread_mutex_unlock(&procevent_list_lock);
518 if (pl->pid == pid) {
519 // this is a match, and we've already stored the exact pid/name combo
522 } else if (pl->pid == -1) {
523 // this is a match, and we've found a candidate processlist_t to store
524 // this new pid/name combo
528 } else if (pl->pid != -1) {
529 // this is a match, but another instance of this process has already
530 // claimed this pid/name combo,
538 if (match != NULL && match->pid != -1 && match->pid != pid) {
539 // if there was a match but the associated processlist_t object already
540 // contained a pid/name combo,
541 // then make a new one and add it to the linked list
544 "procevent plugin: allocating new processlist_t object for PID %d (%s)",
545 pid, match->process);
551 pl2 = malloc(sizeof(*pl2));
554 ERROR("procevent plugin: malloc failed during process_check: %s",
555 sstrerror(errno, errbuf, sizeof(errbuf)));
556 pthread_mutex_unlock(&procevent_list_lock);
560 process = strdup(match->process);
561 if (process == NULL) {
564 ERROR("procevent plugin: strdup failed during process_check: %s",
565 sstrerror(errno, errbuf, sizeof(errbuf)));
566 pthread_mutex_unlock(&procevent_list_lock);
570 if (match->is_regex == 1) {
573 regcomp(&pl2->process_regex_obj, match->process_regex, REG_EXTENDED);
578 ERROR("procevent plugin: invalid regular expression: %s",
579 match->process_regex);
583 process_regex = strdup(match->process_regex);
584 if (process_regex == NULL) {
588 ERROR("procevent plugin: strdup failed during process_check: %s",
589 sstrerror(errno, errbuf, sizeof(errbuf)));
593 pl2->process_regex = process_regex;
596 pl2->process = process;
598 pl2->next = processlist_head;
599 processlist_head = pl2;
604 pthread_mutex_unlock(&procevent_list_lock);
614 // Does our map have this PID or name?
615 static processlist_t *process_map_check(int pid, char *process) {
618 pthread_mutex_lock(&procevent_list_lock);
620 for (pl = processlist_head; pl != NULL; pl = pl->next) {
622 int match_process = 0;
630 if (process != NULL) {
631 if (strcmp(pl->process, process) == 0)
635 if (pid > 0 && process == NULL && match_pid == 1)
637 else if (pid < 0 && process != NULL && match_process == 1)
639 else if (pid > 0 && process != NULL && match_pid == 1 && match_process == 1)
643 pthread_mutex_unlock(&procevent_list_lock);
648 pthread_mutex_unlock(&procevent_list_lock);
653 static int process_map_refresh(void) {
657 proc = opendir(PROCDIR);
660 ERROR("procevent plugin: fopen (%s): %s", PROCDIR,
661 sstrerror(errno, errbuf, sizeof(errbuf)));
675 dent = readdir(proc);
679 if (errno == 0) /* end of directory */
682 ERROR("procevent plugin: failed to read directory %s: %s", PROCDIR,
683 sstrerror(errno, errbuf, sizeof(errbuf)));
688 if (dent->d_name[0] == '.')
691 len = snprintf(file, sizeof(file), PROCDIR "/%s", dent->d_name);
692 if ((len < 0) || (len >= BUFSIZE))
695 status = stat(file, &statbuf);
698 WARNING("procevent plugin: stat (%s) failed: %s", file,
699 sstrerror(errno, errbuf, sizeof(errbuf)));
703 if (!S_ISDIR(statbuf.st_mode))
706 len = snprintf(file, sizeof(file), PROCDIR "/%s/comm", dent->d_name);
707 if ((len < 0) || (len >= BUFSIZE))
712 for (int i = 0; i < strlen(dent->d_name); i++) {
713 if (!isdigit(dent->d_name[i])) {
722 // Check if we need to store this pid/name combo in our processlist_t linked
724 int this_pid = atoi(dent->d_name);
725 processlist_t *pl = process_check(this_pid);
728 DEBUG("procevent plugin: process map refreshed for PID %d and name %s",
729 this_pid, pl->process);
737 static int nl_connect() {
739 struct sockaddr_nl sa_nl;
741 nl_sock = socket(PF_NETLINK, SOCK_DGRAM, NETLINK_CONNECTOR);
743 ERROR("procevent plugin: socket open failed.");
747 sa_nl.nl_family = AF_NETLINK;
748 sa_nl.nl_groups = CN_IDX_PROC;
749 sa_nl.nl_pid = getpid();
751 rc = bind(nl_sock, (struct sockaddr *)&sa_nl, sizeof(sa_nl));
753 ERROR("procevent plugin: socket bind failed.");
761 static int set_proc_ev_listen(bool enable) {
763 struct __attribute__((aligned(NLMSG_ALIGNTO))) {
764 struct nlmsghdr nl_hdr;
765 struct __attribute__((__packed__)) {
766 struct cn_msg cn_msg;
767 enum proc_cn_mcast_op cn_mcast;
771 memset(&nlcn_msg, 0, sizeof(nlcn_msg));
772 nlcn_msg.nl_hdr.nlmsg_len = sizeof(nlcn_msg);
773 nlcn_msg.nl_hdr.nlmsg_pid = getpid();
774 nlcn_msg.nl_hdr.nlmsg_type = NLMSG_DONE;
776 nlcn_msg.cn_msg.id.idx = CN_IDX_PROC;
777 nlcn_msg.cn_msg.id.val = CN_VAL_PROC;
778 nlcn_msg.cn_msg.len = sizeof(enum proc_cn_mcast_op);
780 nlcn_msg.cn_mcast = enable ? PROC_CN_MCAST_LISTEN : PROC_CN_MCAST_IGNORE;
782 rc = send(nl_sock, &nlcn_msg, sizeof(nlcn_msg), 0);
784 ERROR("procevent plugin: subscribing to netlink process events failed.");
791 static int read_event() {
795 int proc_status = -1;
797 struct __attribute__((aligned(NLMSG_ALIGNTO))) {
798 struct nlmsghdr nl_hdr;
799 struct __attribute__((__packed__)) {
800 struct cn_msg cn_msg;
801 struct proc_event proc_ev;
808 status = recv(nl_sock, &nlcn_msg, sizeof(nlcn_msg), 0);
812 } else if (status == -1) {
813 if (errno != EINTR) {
814 ERROR("procevent plugin: socket receive error: %d", errno);
819 switch (nlcn_msg.proc_ev.what) {
820 case PROC_EVENT_NONE:
821 case PROC_EVENT_FORK:
824 // Not of interest in current version
826 case PROC_EVENT_EXEC:
827 proc_status = PROCEVENT_STARTED;
828 proc_id = nlcn_msg.proc_ev.event_data.exec.process_pid;
830 case PROC_EVENT_EXIT:
831 proc_id = nlcn_msg.proc_ev.event_data.exit.process_pid;
832 proc_status = PROCEVENT_EXITED;
833 proc_extra = nlcn_msg.proc_ev.event_data.exit.exit_code;
839 // If we're interested in this process status event, place the event
840 // in the ring buffer for consumption by the main polling thread.
842 if (proc_status != -1) {
843 pthread_mutex_unlock(&procevent_lock);
845 int next = ring.head + 1;
846 if (next >= ring.maxLen)
849 if (next == ring.tail) {
850 WARNING("procevent plugin: ring buffer full");
852 DEBUG("procevent plugin: Process %d status is now %s at %llu", proc_id,
853 (proc_status == PROCEVENT_EXITED ? "EXITED" : "STARTED"),
854 (long long unsigned int)CDTIME_T_TO_US(cdtime()));
856 if (proc_status == PROCEVENT_EXITED) {
857 ring.buffer[ring.head][0] = proc_id;
858 ring.buffer[ring.head][1] = proc_status;
859 ring.buffer[ring.head][2] = proc_extra;
860 ring.buffer[ring.head][3] =
861 (long long unsigned int)CDTIME_T_TO_US(cdtime());
863 ring.buffer[ring.head][0] = proc_id;
864 ring.buffer[ring.head][1] = proc_status;
865 ring.buffer[ring.head][2] = 0;
866 ring.buffer[ring.head][3] =
867 (long long unsigned int)CDTIME_T_TO_US(cdtime());
873 pthread_mutex_unlock(&procevent_lock);
879 static void *procevent_thread(void *arg) /* {{{ */
881 pthread_mutex_lock(&procevent_lock);
883 while (procevent_thread_loop > 0) {
886 pthread_mutex_unlock(&procevent_lock);
890 status = read_event();
892 pthread_mutex_lock(&procevent_lock);
895 procevent_thread_error = 1;
899 if (procevent_thread_loop <= 0)
901 } /* while (procevent_thread_loop > 0) */
903 pthread_mutex_unlock(&procevent_lock);
906 } /* }}} void *procevent_thread */
908 static int start_thread(void) /* {{{ */
912 pthread_mutex_lock(&procevent_lock);
914 if (procevent_thread_loop != 0) {
915 pthread_mutex_unlock(&procevent_lock);
920 status = nl_connect();
925 status = set_proc_ev_listen(true);
930 DEBUG("procevent plugin: socket created and bound");
932 procevent_thread_loop = 1;
933 procevent_thread_error = 0;
935 status = plugin_thread_create(&procevent_thread_id, /* attr = */ NULL,
937 /* arg = */ (void *)0, "procevent");
939 procevent_thread_loop = 0;
940 ERROR("procevent plugin: Starting thread failed.");
941 pthread_mutex_unlock(&procevent_lock);
945 pthread_mutex_unlock(&procevent_lock);
947 } /* }}} int start_thread */
949 static int stop_thread(int shutdown) /* {{{ */
954 status = close(nl_sock);
956 ERROR("procevent plugin: failed to close socket %d: %d (%s)", nl_sock,
957 status, strerror(errno));
963 pthread_mutex_lock(&procevent_lock);
965 if (procevent_thread_loop == 0) {
966 pthread_mutex_unlock(&procevent_lock);
970 procevent_thread_loop = 0;
971 pthread_cond_broadcast(&procevent_cond);
972 pthread_mutex_unlock(&procevent_lock);
975 // Calling pthread_cancel here in
976 // the case of a shutdown just assures that the thread is
977 // gone and that the process has been fully terminated.
979 DEBUG("procevent plugin: Canceling thread for process shutdown");
981 status = pthread_cancel(procevent_thread_id);
984 ERROR("procevent plugin: Unable to cancel thread: %d", status);
988 status = pthread_join(procevent_thread_id, /* return = */ NULL);
990 ERROR("procevent plugin: Stopping thread failed.");
995 pthread_mutex_lock(&procevent_lock);
996 memset(&procevent_thread_id, 0, sizeof(procevent_thread_id));
997 procevent_thread_error = 0;
998 pthread_mutex_unlock(&procevent_lock);
1000 DEBUG("procevent plugin: Finished requesting stop of thread");
1003 } /* }}} int stop_thread */
1005 static int procevent_init(void) /* {{{ */
1009 if (processlist_head == NULL) {
1010 NOTICE("procevent plugin: No processes have been configured.");
1016 ring.maxLen = buffer_length;
1017 ring.buffer = (long long unsigned int **)malloc(
1018 buffer_length * sizeof(long long unsigned int *));
1020 for (int i = 0; i < buffer_length; i++) {
1021 ring.buffer[i] = (long long unsigned int *)malloc(
1022 PROCEVENT_FIELDS * sizeof(long long unsigned int));
1025 status = process_map_refresh();
1028 ERROR("procevent plugin: Initial process mapping failed.");
1032 return (start_thread());
1033 } /* }}} int procevent_init */
1035 static int procevent_config(const char *key, const char *value) /* {{{ */
1039 if (strcasecmp(key, "BufferLength") == 0) {
1040 buffer_length = atoi(value);
1041 } else if (strcasecmp(key, "Process") == 0 ||
1042 strcasecmp(key, "RegexProcess") == 0) {
1046 char *process_regex;
1048 pl = malloc(sizeof(*pl));
1051 ERROR("procevent plugin: malloc failed during procevent_config: %s",
1052 sstrerror(errno, errbuf, sizeof(errbuf)));
1056 process = strdup(value);
1057 if (process == NULL) {
1060 ERROR("procevent plugin: strdup failed during procevent_config: %s",
1061 sstrerror(errno, errbuf, sizeof(errbuf)));
1065 if (strcasecmp(key, "RegexProcess") == 0) {
1067 status = regcomp(&pl->process_regex_obj, value, REG_EXTENDED);
1072 ERROR("procevent plugin: invalid regular expression: %s", value);
1076 process_regex = strdup(value);
1077 if (process_regex == NULL) {
1081 ERROR("procevent plugin: strdup failed during procevent_config: %s",
1082 sstrerror(errno, errbuf, sizeof(errbuf)));
1086 pl->process_regex = process_regex;
1091 pl->process = process;
1093 pl->next = processlist_head;
1094 processlist_head = pl;
1100 } /* }}} int procevent_config */
1102 static void procevent_dispatch_notification(int pid, const char *type, /* {{{ */
1103 gauge_t value, char *process,
1104 long long unsigned int timestamp) {
1106 notification_t n = {NOTIF_FAILURE, cdtime(), "", "", "procevent", "", "", "",
1110 n.severity = NOTIF_OKAY;
1112 char hostname[1024];
1113 gethostname(hostname, sizeof(hostname));
1115 sstrncpy(n.host, hostname, sizeof(n.host));
1116 sstrncpy(n.plugin_instance, process, sizeof(n.plugin_instance));
1117 sstrncpy(n.type, "gauge", sizeof(n.type));
1118 sstrncpy(n.type_instance, "process_status", sizeof(n.type_instance));
1120 gen_message_payload(value, pid, process, timestamp, &buf);
1122 notification_meta_t *m = calloc(1, sizeof(*m));
1127 ERROR("procevent plugin: unable to allocate metadata: %s",
1128 sstrerror(errno, errbuf, sizeof(errbuf)));
1132 sstrncpy(m->name, "ves", sizeof(m->name));
1133 m->nm_value.nm_string = sstrdup(buf);
1134 m->type = NM_TYPE_STRING;
1137 DEBUG("procevent plugin: notification message: %s",
1138 n.meta->nm_value.nm_string);
1140 DEBUG("procevent plugin: dispatching state %d for PID %d (%s)", (int)value,
1143 plugin_dispatch_notification(&n);
1144 plugin_notification_meta_free(n.meta);
1146 // malloc'd in gen_message_payload
1151 static int procevent_read(void) /* {{{ */
1153 if (procevent_thread_error != 0) {
1155 "procevent plugin: The interface thread had a problem. Restarting it.");
1162 } /* if (procevent_thread_error != 0) */
1164 pthread_mutex_lock(&procevent_lock);
1166 while (ring.head != ring.tail) {
1167 int next = ring.tail + 1;
1169 if (next >= ring.maxLen)
1172 if (ring.buffer[ring.tail][1] == PROCEVENT_EXITED) {
1173 processlist_t *pl = process_map_check(ring.buffer[ring.tail][0], NULL);
1176 // This process is of interest to us, so publish its EXITED status
1177 procevent_dispatch_notification(ring.buffer[ring.tail][0], "gauge",
1178 ring.buffer[ring.tail][1], pl->process,
1179 ring.buffer[ring.tail][3]);
1180 DEBUG("procevent plugin: PID %d (%s) EXITED, removing PID from process "
1182 pl->pid, pl->process);
1185 } else if (ring.buffer[ring.tail][1] == PROCEVENT_STARTED) {
1186 // a new process has started, so check if we should monitor it
1187 processlist_t *pl = process_check(ring.buffer[ring.tail][0]);
1190 // This process is of interest to us, so publish its STARTED status
1191 procevent_dispatch_notification(ring.buffer[ring.tail][0], "gauge",
1192 ring.buffer[ring.tail][1], pl->process,
1193 ring.buffer[ring.tail][3]);
1195 "procevent plugin: PID %d (%s) STARTED, adding PID to process list",
1196 pl->pid, pl->process);
1203 pthread_mutex_unlock(&procevent_lock);
1206 } /* }}} int procevent_read */
1208 static int procevent_shutdown(void) /* {{{ */
1212 DEBUG("procevent plugin: Shutting down thread.");
1214 if (stop_thread(1) < 0)
1217 for (int i = 0; i < buffer_length; i++) {
1218 free(ring.buffer[i]);
1223 pl = processlist_head;
1224 while (pl != NULL) {
1225 processlist_t *pl_next;
1229 if (pl->is_regex == 1) {
1230 sfree(pl->process_regex);
1231 regfree(&pl->process_regex_obj);
1241 } /* }}} int procevent_shutdown */
1243 void module_register(void) {
1244 plugin_register_config("procevent", procevent_config, config_keys,
1246 plugin_register_init("procevent", procevent_init);
1247 plugin_register_read("procevent", procevent_read);
1248 plugin_register_shutdown("procevent", procevent_shutdown);
1249 } /* void module_register */