2017-09-18 12:43:55 +00:00
|
|
|
/*
|
|
|
|
* Action management functions.
|
|
|
|
*
|
|
|
|
* Copyright 2017 HAProxy Technologies, Christopher Faulet <cfaulet@haproxy.com>
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version
|
|
|
|
* 2 of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2020-06-04 08:15:32 +00:00
|
|
|
#include <haproxy/action.h>
|
2020-05-27 10:58:42 +00:00
|
|
|
#include <haproxy/api.h>
|
2020-06-05 15:27:29 +00:00
|
|
|
#include <haproxy/errors.h>
|
2020-06-09 07:07:15 +00:00
|
|
|
#include <haproxy/list.h>
|
2020-06-04 09:29:21 +00:00
|
|
|
#include <haproxy/obj_type.h>
|
2020-06-02 07:38:52 +00:00
|
|
|
#include <haproxy/pool.h>
|
2020-06-04 20:29:18 +00:00
|
|
|
#include <haproxy/proxy.h>
|
2020-06-09 07:07:15 +00:00
|
|
|
#include <haproxy/stick_table.h>
|
2020-06-04 15:25:40 +00:00
|
|
|
#include <haproxy/task.h>
|
2020-06-03 16:09:46 +00:00
|
|
|
#include <haproxy/tools.h>
|
2017-09-18 12:43:55 +00:00
|
|
|
|
|
|
|
|
2019-12-18 08:20:16 +00:00
|
|
|
/* Find and check the target table used by an action track-sc*. This
|
2017-09-18 12:43:55 +00:00
|
|
|
* function should be called during the configuration validity check.
|
|
|
|
*
|
|
|
|
* The function returns 1 in success case, otherwise, it returns 0 and err is
|
|
|
|
* filled.
|
|
|
|
*/
|
|
|
|
int check_trk_action(struct act_rule *rule, struct proxy *px, char **err)
|
|
|
|
{
|
2019-03-14 06:07:41 +00:00
|
|
|
struct stktable *target;
|
2017-09-18 12:43:55 +00:00
|
|
|
|
|
|
|
if (rule->arg.trk_ctr.table.n)
|
2019-03-14 06:07:41 +00:00
|
|
|
target = stktable_find_by_name(rule->arg.trk_ctr.table.n);
|
2017-09-18 12:43:55 +00:00
|
|
|
else
|
2019-03-14 06:07:41 +00:00
|
|
|
target = px->table;
|
2017-09-18 12:43:55 +00:00
|
|
|
|
|
|
|
if (!target) {
|
|
|
|
memprintf(err, "unable to find table '%s' referenced by track-sc%d",
|
2019-03-14 06:07:41 +00:00
|
|
|
rule->arg.trk_ctr.table.n ? rule->arg.trk_ctr.table.n : px->id,
|
2019-12-18 08:20:16 +00:00
|
|
|
rule->action);
|
2017-09-18 12:43:55 +00:00
|
|
|
return 0;
|
|
|
|
}
|
2019-03-14 06:07:41 +00:00
|
|
|
|
|
|
|
if (!stktable_compatible_sample(rule->arg.trk_ctr.expr, target->type)) {
|
2017-09-18 12:43:55 +00:00
|
|
|
memprintf(err, "stick-table '%s' uses a type incompatible with the 'track-sc%d' rule",
|
|
|
|
rule->arg.trk_ctr.table.n ? rule->arg.trk_ctr.table.n : px->id,
|
2019-12-18 08:20:16 +00:00
|
|
|
rule->action);
|
2017-09-18 12:43:55 +00:00
|
|
|
return 0;
|
|
|
|
}
|
2019-03-14 06:07:41 +00:00
|
|
|
else if (target->proxy && (px->bind_proc & ~target->proxy->bind_proc)) {
|
2019-02-05 10:38:38 +00:00
|
|
|
memprintf(err, "stick-table '%s' referenced by 'track-sc%d' rule not present on all processes covered by proxy '%s'",
|
2019-12-18 08:20:16 +00:00
|
|
|
target->id, rule->action, px->id);
|
2019-02-05 10:38:38 +00:00
|
|
|
return 0;
|
|
|
|
}
|
2017-09-18 12:43:55 +00:00
|
|
|
else {
|
2019-08-07 07:28:39 +00:00
|
|
|
if (!in_proxies_list(target->proxies_list, px)) {
|
2019-03-19 13:55:01 +00:00
|
|
|
px->next_stkt_ref = target->proxies_list;
|
|
|
|
target->proxies_list = px;
|
|
|
|
}
|
2017-09-18 12:43:55 +00:00
|
|
|
free(rule->arg.trk_ctr.table.n);
|
2019-03-14 06:07:41 +00:00
|
|
|
rule->arg.trk_ctr.table.t = target;
|
2017-09-18 12:43:55 +00:00
|
|
|
/* Note: if we decide to enhance the track-sc syntax, we may be
|
|
|
|
* able to pass a list of counters to track and allocate them
|
|
|
|
* right here using stktable_alloc_data_type().
|
|
|
|
*/
|
|
|
|
}
|
2019-12-18 08:20:16 +00:00
|
|
|
|
|
|
|
if (rule->from == ACT_F_TCP_REQ_CNT && (px->cap & PR_CAP_FE) && !px->tcp_req.inspect_delay &&
|
|
|
|
!(rule->arg.trk_ctr.expr->fetch->val & SMP_VAL_FE_SES_ACC)) {
|
|
|
|
ha_warning("config : %s '%s' : a 'tcp-request content track-sc*' rule explicitly depending on request"
|
|
|
|
" contents without any 'tcp-request inspect-delay' setting."
|
|
|
|
" This means that this rule will randomly find its contents. This can be fixed by"
|
|
|
|
" setting the tcp-request inspect-delay.\n",
|
|
|
|
proxy_type_str(px), px->id);
|
|
|
|
}
|
|
|
|
|
2017-09-18 12:43:55 +00:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
2019-12-19 16:27:03 +00:00
|
|
|
/* check a capture rule. This function should be called during the configuration
|
|
|
|
* validity check.
|
|
|
|
*
|
|
|
|
* The function returns 1 in success case, otherwise, it returns 0 and err is
|
|
|
|
* filled.
|
|
|
|
*/
|
|
|
|
int check_capture(struct act_rule *rule, struct proxy *px, char **err)
|
|
|
|
{
|
|
|
|
if (rule->from == ACT_F_TCP_REQ_CNT && (px->cap & PR_CAP_FE) && !px->tcp_req.inspect_delay &&
|
|
|
|
!(rule->arg.trk_ctr.expr->fetch->val & SMP_VAL_FE_SES_ACC)) {
|
|
|
|
ha_warning("config : %s '%s' : a 'tcp-request capture' rule explicitly depending on request"
|
|
|
|
" contents without any 'tcp-request inspect-delay' setting."
|
|
|
|
" This means that this rule will randomly find its contents. This can be fixed by"
|
|
|
|
" setting the tcp-request inspect-delay.\n",
|
|
|
|
proxy_type_str(px), px->id);
|
|
|
|
}
|
|
|
|
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
2019-01-21 07:34:50 +00:00
|
|
|
int act_resolution_cb(struct dns_requester *requester, struct dns_nameserver *nameserver)
|
|
|
|
{
|
|
|
|
struct stream *stream;
|
|
|
|
|
|
|
|
if (requester->resolution == NULL)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
stream = objt_stream(requester->owner);
|
|
|
|
if (stream == NULL)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
task_wakeup(stream->task, TASK_WOKEN_MSG);
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
int act_resolution_error_cb(struct dns_requester *requester, int error_code)
|
|
|
|
{
|
|
|
|
struct stream *stream;
|
|
|
|
|
|
|
|
if (requester->resolution == NULL)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
stream = objt_stream(requester->owner);
|
|
|
|
if (stream == NULL)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
task_wakeup(stream->task, TASK_WOKEN_MSG);
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|