r5sdk/r5dev/thirdparty/spdlog/sinks/win_eventlog_sink.h

261 lines
8.7 KiB
C
Raw Normal View History

2021-07-08 07:07:27 -07:00
// Copyright(c) 2015-present, Gabi Melman & spdlog contributors.
// Distributed under the MIT License (http://opensource.org/licenses/MIT)
2024-02-04 13:43:17 +01:00
// Writing to Windows Event Log requires the registry entries below to be present, with the
// following modifications:
2021-07-08 07:07:27 -07:00
// 1. <log_name> should be replaced with your log name (e.g. your application name)
2024-02-04 13:43:17 +01:00
// 2. <source_name> should be replaced with the specific source name and the key should be
// duplicated for
2021-07-08 07:07:27 -07:00
// each source used in the application
//
2024-02-04 13:43:17 +01:00
// Since typically modifications of this kind require elevation, it's better to do it as a part of
// setup procedure. The snippet below uses mscoree.dll as the message file as it exists on most of
// the Windows systems anyway and happens to contain the needed resource.
2021-07-08 07:07:27 -07:00
//
// You can also specify a custom message file if needed.
2024-02-04 13:43:17 +01:00
// Please refer to Event Log functions descriptions in MSDN for more details on custom message
// files.
2021-07-08 07:07:27 -07:00
/*---------------------------------------------------------------------------------------
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\<log_name>]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\<log_name>\<source_name>]
"TypesSupported"=dword:00000007
"EventMessageFile"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,6d,00,73,00,63,00,6f,00,72,00,65,00,65,00,2e,00,64,00,6c,00,6c,00,00,\
00
-----------------------------------------------------------------------------------------*/
#pragma once
#include <spdlog/details/null_mutex.h>
#include <spdlog/sinks/base_sink.h>
2021-07-08 07:07:27 -07:00
#include <spdlog/details/windows_include.h>
2022-01-14 15:36:51 +01:00
#include <winbase.h>
2021-07-08 07:07:27 -07:00
#include <mutex>
#include <string>
#include <vector>
namespace spdlog {
namespace sinks {
namespace win_eventlog {
namespace internal {
2024-02-04 13:43:17 +01:00
struct local_alloc_t {
HLOCAL hlocal_;
SPDLOG_CONSTEXPR local_alloc_t() SPDLOG_NOEXCEPT : hlocal_(nullptr) {}
local_alloc_t(local_alloc_t const &) = delete;
local_alloc_t &operator=(local_alloc_t const &) = delete;
2024-02-04 13:43:17 +01:00
~local_alloc_t() SPDLOG_NOEXCEPT {
if (hlocal_) {
LocalFree(hlocal_);
}
}
};
2021-07-08 07:07:27 -07:00
/** Windows error */
2024-02-04 13:43:17 +01:00
struct win32_error : public spdlog_ex {
2021-07-08 07:07:27 -07:00
/** Formats an error report line: "user-message: error-code (system message)" */
2024-02-04 13:43:17 +01:00
static std::string format(std::string const &user_message, DWORD error_code = GetLastError()) {
2021-07-08 07:07:27 -07:00
std::string system_message;
local_alloc_t format_message_result{};
2021-07-08 07:07:27 -07:00
auto format_message_succeeded =
2024-02-04 13:43:17 +01:00
::FormatMessageA(FORMAT_MESSAGE_ALLOCATE_BUFFER | FORMAT_MESSAGE_FROM_SYSTEM |
FORMAT_MESSAGE_IGNORE_INSERTS,
nullptr, error_code, MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT),
(LPSTR)&format_message_result.hlocal_, 0, nullptr);
2021-07-08 07:07:27 -07:00
2024-02-04 13:43:17 +01:00
if (format_message_succeeded && format_message_result.hlocal_) {
system_message = fmt_lib::format(" ({})", (LPSTR)format_message_result.hlocal_);
2021-07-08 07:07:27 -07:00
}
return fmt_lib::format("{}: {}{}", user_message, error_code, system_message);
2021-07-08 07:07:27 -07:00
}
explicit win32_error(std::string const &func_name, DWORD error = GetLastError())
2024-02-04 13:43:17 +01:00
: spdlog_ex(format(func_name, error)) {}
2021-07-08 07:07:27 -07:00
};
/** Wrapper for security identifiers (SID) on Windows */
2024-02-04 13:43:17 +01:00
struct sid_t {
2021-07-08 07:07:27 -07:00
std::vector<char> buffer_;
public:
sid_t() {}
/** creates a wrapped SID copy */
2024-02-04 13:43:17 +01:00
static sid_t duplicate_sid(PSID psid) {
if (!::IsValidSid(psid)) {
2021-07-08 07:07:27 -07:00
throw_spdlog_ex("sid_t::sid_t(): invalid SID received");
}
auto const sid_length{::GetLengthSid(psid)};
sid_t result;
result.buffer_.resize(sid_length);
2024-02-04 13:43:17 +01:00
if (!::CopySid(sid_length, (PSID)result.as_sid(), psid)) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(win32_error("CopySid"));
}
return result;
}
/** Retrieves pointer to the internal buffer contents as SID* */
2024-02-04 13:43:17 +01:00
SID *as_sid() const { return buffer_.empty() ? nullptr : (SID *)buffer_.data(); }
2021-07-08 07:07:27 -07:00
/** Get SID for the current user */
2024-02-04 13:43:17 +01:00
static sid_t get_current_user_sid() {
2021-07-08 07:07:27 -07:00
/* create and init RAII holder for process token */
2024-02-04 13:43:17 +01:00
struct process_token_t {
2021-07-08 07:07:27 -07:00
HANDLE token_handle_ = INVALID_HANDLE_VALUE;
2024-02-04 13:43:17 +01:00
explicit process_token_t(HANDLE process) {
if (!::OpenProcessToken(process, TOKEN_QUERY, &token_handle_)) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(win32_error("OpenProcessToken"));
}
}
2024-02-04 13:43:17 +01:00
~process_token_t() { ::CloseHandle(token_handle_); }
2021-07-08 07:07:27 -07:00
2024-02-04 13:43:17 +01:00
} current_process_token(
::GetCurrentProcess()); // GetCurrentProcess returns pseudohandle, no leak here!
2021-07-08 07:07:27 -07:00
2024-02-04 13:43:17 +01:00
// Get the required size, this is expected to fail with ERROR_INSUFFICIENT_BUFFER and return
// the token size
2021-07-08 07:07:27 -07:00
DWORD tusize = 0;
2024-02-04 13:43:17 +01:00
if (::GetTokenInformation(current_process_token.token_handle_, TokenUser, NULL, 0,
&tusize)) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(win32_error("GetTokenInformation should fail"));
}
// get user token
std::vector<unsigned char> buffer(static_cast<size_t>(tusize));
2024-02-04 13:43:17 +01:00
if (!::GetTokenInformation(current_process_token.token_handle_, TokenUser,
(LPVOID)buffer.data(), tusize, &tusize)) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(win32_error("GetTokenInformation"));
}
// create a wrapper of the SID data as stored in the user token
return sid_t::duplicate_sid(((TOKEN_USER *)buffer.data())->User.Sid);
}
};
2024-02-04 13:43:17 +01:00
struct eventlog {
static WORD get_event_type(details::log_msg const &msg) {
switch (msg.level) {
case level::trace:
case level::debug:
return EVENTLOG_SUCCESS;
case level::info:
return EVENTLOG_INFORMATION_TYPE;
case level::warn:
return EVENTLOG_WARNING_TYPE;
case level::err:
case level::critical:
case level::off:
return EVENTLOG_ERROR_TYPE;
default:
return EVENTLOG_INFORMATION_TYPE;
2021-07-08 07:07:27 -07:00
}
}
2024-02-04 13:43:17 +01:00
static WORD get_event_category(details::log_msg const &msg) { return (WORD)msg.level; }
2021-07-08 07:07:27 -07:00
};
2024-02-04 13:43:17 +01:00
} // namespace internal
2021-07-08 07:07:27 -07:00
/*
* Windows Event Log sink
*/
2024-02-04 13:43:17 +01:00
template <typename Mutex>
class win_eventlog_sink : public base_sink<Mutex> {
2021-07-08 07:07:27 -07:00
private:
HANDLE hEventLog_{NULL};
internal::sid_t current_user_sid_;
std::string source_;
2023-09-17 20:37:44 +02:00
DWORD event_id_;
2021-07-08 07:07:27 -07:00
2024-02-04 13:43:17 +01:00
HANDLE event_log_handle() {
if (!hEventLog_) {
2021-07-08 07:07:27 -07:00
hEventLog_ = ::RegisterEventSourceA(nullptr, source_.c_str());
2024-02-04 13:43:17 +01:00
if (!hEventLog_ || hEventLog_ == (HANDLE)ERROR_ACCESS_DENIED) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(internal::win32_error("RegisterEventSource"));
}
}
return hEventLog_;
}
protected:
2024-02-04 13:43:17 +01:00
void sink_it_(const details::log_msg &msg) override {
2021-07-08 07:07:27 -07:00
using namespace internal;
bool succeeded;
memory_buf_t formatted;
base_sink<Mutex>::formatter_->format(msg, formatted);
formatted.push_back('\0');
#ifdef SPDLOG_WCHAR_TO_UTF8_SUPPORT
wmemory_buf_t buf;
details::os::utf8_to_wstrbuf(string_view_t(formatted.data(), formatted.size()), buf);
LPCWSTR lp_wstr = buf.data();
2024-02-04 13:43:17 +01:00
succeeded = static_cast<bool>(::ReportEventW(
event_log_handle(), eventlog::get_event_type(msg), eventlog::get_event_category(msg),
2023-09-17 20:37:44 +02:00
event_id_, current_user_sid_.as_sid(), 1, 0, &lp_wstr, nullptr));
2021-07-08 07:07:27 -07:00
#else
LPCSTR lp_str = formatted.data();
2024-02-04 13:43:17 +01:00
succeeded = static_cast<bool>(::ReportEventA(
event_log_handle(), eventlog::get_event_type(msg), eventlog::get_event_category(msg),
2023-09-17 20:37:44 +02:00
event_id_, current_user_sid_.as_sid(), 1, 0, &lp_str, nullptr));
2021-07-08 07:07:27 -07:00
#endif
2024-02-04 13:43:17 +01:00
if (!succeeded) {
2021-07-08 07:07:27 -07:00
SPDLOG_THROW(win32_error("ReportEvent"));
}
}
void flush_() override {}
public:
2024-02-04 13:43:17 +01:00
win_eventlog_sink(std::string const &source,
DWORD event_id = 1000 /* according to mscoree.dll */)
: source_(source),
event_id_(event_id) {
try {
2021-07-08 07:07:27 -07:00
current_user_sid_ = internal::sid_t::get_current_user_sid();
2024-02-04 13:43:17 +01:00
} catch (...) {
// get_current_user_sid() is unlikely to fail and if it does, we can still proceed
// without current_user_sid but in the event log the record will have no user name
2021-07-08 07:07:27 -07:00
}
}
2024-02-04 13:43:17 +01:00
~win_eventlog_sink() {
if (hEventLog_) DeregisterEventSource(hEventLog_);
2021-07-08 07:07:27 -07:00
}
};
2024-02-04 13:43:17 +01:00
} // namespace win_eventlog
2021-07-08 07:07:27 -07:00
using win_eventlog_sink_mt = win_eventlog::win_eventlog_sink<std::mutex>;
using win_eventlog_sink_st = win_eventlog::win_eventlog_sink<details::null_mutex>;
2024-02-04 13:43:17 +01:00
} // namespace sinks
} // namespace spdlog