3 ################################################################################
6 # A parser for Privoxy log messages. For incomplete documentation run
7 # perldoc privoxy-log-parser(.pl), for fancy screenshots see:
9 # https://www.fabiankeil.de/sourcecode/privoxy-log-parser/
12 # - LOG_LEVEL_CGI, LOG_LEVEL_ERROR, LOG_LEVEL_WRITE content highlighting
13 # - create fancy statistics
14 # - grep through Privoxy sources to find unsupported log messages
15 # - hunt down substitutions that match content from variables which
16 # can contain stuff like ()?'[]
17 # - replace $h{'foo'} with h('foo') where possible
18 # - hunt down XXX comments instead of just creating them
19 # - add example log lines for every regex and mark them up for
21 # - Handle incomplete input without Perl warning about undefined variables.
22 # - Use generic highlighting function that takes a regex and the
24 # - Add --compress and --decompress options.
26 # Copyright (c) 2007-2021 Fabian Keil <fk@fabiankeil.de>
28 # Permission to use, copy, modify, and distribute this software for any
29 # purpose with or without fee is hereby granted, provided that the above
30 # copyright notice and this permission notice appear in all copies.
32 # THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
33 # WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
34 # MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
35 # ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
36 # WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
37 # ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
38 # OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
39 ################################################################################
46 PRIVOXY_LOG_PARSER_VERSION => '0.9.2',
47 # Feel free to mess with these ...
48 DEFAULT_BACKGROUND => 'black', # Choose registered colour (like 'black')
49 DEFAULT_TEXT_COLOUR => 'white', # Choose registered colour (like 'black')
50 HEADER_DEFAULT_COLOUR => 'yellow',
51 REGISTER_HEADERS_WITH_THE_SAME_COLOUR => 1,
53 CLI_OPTION_DEFAULT_TO_HTML_OUTPUT => 0,
54 CLI_OPTION_TITLE => 'Privoxy-Log-Parser in da house',
55 CLI_OPTION_KEEP_DATE => 0,
56 CLI_OPTION_NO_EMBEDDED_CSS => 0,
57 CLI_OPTION_NO_MSECS => 0,
58 CLI_OPTION_NO_SYNTAX_HIGHLIGHTING => 0,
59 CLI_OPTION_SHORTEN_THREAD_IDS => 0,
60 CLI_OPTION_SHOW_INEFFECTIVE_FILTERS => 0,
61 CLI_OPTION_STATISTICS => 0,
62 CLI_OPTION_STRICT_CHECKS => 0,
63 CLI_OPTION_UNBREAK_LINES_ONLY => 0,
64 CLI_OPTION_URL_STATISTICS_THRESHOLD => 0,
65 CLI_OPTION_HOST_STATISTICS_THRESHOLD => 0,
66 CLI_OPTION_SHOW_COMPLETE_REQUEST_DISTRIBUTION => 0,
68 SUPPRESS_SUCCEEDED_FILTER_ADDITIONS => 1,
70 SHOW_FILTER_READIN_IN => 0,
71 SUPPRESS_EMPTY_LINES => 1,
72 SUPPRESS_SUCCESSFUL_CONNECTIONS => 1,
73 SUPPRESS_GIF_NOT_CHANGED => 1,
74 SUPPRESS_NEED_TO_DE_CHUNK_FIRST => 1,
76 DEBUG_HEADER_REGISTERING => 0,
77 DEBUG_HEADER_HIGHLIGHTING => 0,
80 DEBUG_SUPPRESS_LOG_MESSAGES => 0,
82 PUNISH_MISSING_LOG_KNOWLEDGE_WITH_DEATH => 0,
83 PUNISH_MISSING_HIGHLIGHT_KNOWLEDGE_WITH_DEATH => 1,
85 LOG_UNPARSED_LINES_TO_EXTRA_FILE => 0,
86 ERROR_LOG_FILE => '/var/log/privoxy-log-parser',
88 # You better leave these alone unless you know what you're doing.
89 COLOUR_RESET => "\033[0;0m",
93 # For performance reasons, these are global.
96 my %req; # request data from previous lines
101 my $thread_colour_index = 0;
102 my $header_colour_index = 0;
103 my $time_colour_index = 0;
105 my $no_special_header_highlighting;
108 my $header_highlight_regex = '';
110 my $html_output_mode;
112 my $no_msecs_mode; # XXX: should probably be removed
113 my $shorten_thread_ids;
116 sub prepare_our_stuff() {
118 # Syntax Higlight hash
120 'red', 'green', 'brown', 'blue', 'purple', 'cyan',
121 'light_gray', 'light_red', 'light_green', 'yellow',
122 'light_blue', 'pink', 'light_cyan', 'white'
129 Filter => 'purple', # XXX: Used?
130 'Re-Filter' => 'purple',
132 Request => 'light_cyan',
134 CGI => 'light_green',
136 Error => 'light_red',
138 'Fatal error' => 'light_red',
139 'Gif-Deanimate' => 'blue',
141 Writing => 'light_green',
142 Received => 'yellow',
144 # ----------------------
147 request_ => 'brown', # host+path but no protocol
148 'ip-address' => 'yellow',
151 Truncation => 'light_red',
153 Timestamp => 'brown',
154 Crunching => 'light_red',
155 crunched => 'light_red',
156 'Request-Line' => 'pink',
158 destination => 'yellow',
159 'http-version' => 'pink',
160 'crunch-pattern' => 'pink',
165 'program-name' => 'cyan',
168 warning => 'light_red',
169 debug => 'light_red',
173 'status-message' => 'light_cyan',
174 'status-code' => 'yellow',
175 'invalid-request' => 'light_red',
177 error => 'light_red',
178 'rewritten-URL' => 'light_red',
179 'pcrs-delimiter' => 'light_red',
180 'ignored' => 'light_red',
181 'action-bits-update' => 'light_red',
182 'http-downgrade' => 'light_red',
183 'configuration-line' => 'red',
184 'content-type' => 'yellow',
185 'HOST' => HEADER_DEFAULT_COLOUR,
190 # Header colours need their own hash so the keys can be accessed properly
192 # Prefilled with headers that should not appear with default header colours
193 Cookie => 'light_red',
194 'Set-Cookie' => 'light_red',
195 Warning => 'light_red',
196 Default => HEADER_DEFAULT_COLOUR,
199 # Crunch reasons need their own hash as well
201 'Unsupported HTTP feature' => 'light_red',
202 Blocked => 'light_red',
203 Untrusted => 'light_red',
204 Redirected => 'green',
205 'CGI Call' => 'white',
206 'DNS failure' => 'red',
207 'Forwarding failed' => 'light_red',
208 'Connection failure' => 'light_red',
209 'Out of memory (may mask other reasons)' => 'light_red',
210 'No reason recorded' => 'light_red',
213 @time_colours = ('white', 'light_gray');
215 # Translate highlight strings into highlight code
216 prepare_highlight_hash(\%header_colours);
217 prepare_highlight_hash(\%reason_colours);
218 prepare_highlight_hash(\%h);
219 prepare_colour_array(\@all_colours);
220 prepare_colour_array(\@time_colours);
227 ###############################################################
228 # Takes a colour string and returns an ANSI escape sequence
229 # (unless --no-syntax-highlighting is used).
230 # XXX: The Rolling Stones reference has to go.
231 ###############################################################
235 return "" if cli_option_is_set('no-syntax-highlighting');
277 my $bg_code = get_background();
279 our $default = default_colours();
281 if (defined($text{$colour})) {
282 $colour_code = ESCAPE;
283 $colour_code .= $text{$colour};
285 $colour_code .= $light{$colour} ? "1" : "2";
287 $colour_code .= $bg_code;
289 debug_message $colour . " is \'" . $colour_code . $colour . $default . "\'" if DEBUG_PAINT_IT;
291 } elsif ($colour =~ /reset/) {
293 $colour_code = default_colours();
297 die "What's $colour supposed to mean?\n";
303 sub get_semantic_html_markup($) {
304 ###############################################################
305 # Takes a string and returns a span element
306 ###############################################################
311 if ($type =~ /Standard/) {
315 $code = '<span title="' . $type . '" class="' . $type . '">';
321 sub cli_option_is_set($) {
324 my $cli_option = shift;
326 die "Unknown CLI option: $cli_option" unless defined $cli_options{$cli_option};
328 return $cli_options{$cli_option};
331 sub get_html_title() {
334 return $cli_options{'title'};
338 sub init_css_colours() {
346 purple => "F06", # XXX: wrong
347 cyan => "F09", # XXX: wrong
352 light_green => "33F",
361 sub get_css_colour($) {
366 die "What's $colour supposed to mean?\n" unless defined($css_colours{$colour});
368 return '#' . $css_colours{$colour};
371 sub get_css_line($) {
376 $css_line .= '.' . lc($class) . ' {'; # XXX: lc() shouldn't be necessary
377 die "What's $class supposed to mean?\n" unless defined($h_colours{$class});
378 $css_line .= 'color:' . get_css_colour($h_colours{$class}) . ';';
379 $css_line .= 'background-color:' . get_css_colour(DEFAULT_BACKGROUND) . ';';
380 $css_line .= '}' . "\n";
385 sub get_css_line_for_colour($) {
390 $css_line .= '.' . lc($colour) . ' {'; # XXX: lc() shouldn't be necessary
391 $css_line .= 'color:' . get_css_colour($colour) . ';';
392 $css_line .= 'background-color:' . get_css_colour(DEFAULT_BACKGROUND) . ';';
393 $css_line .= '}' . "\n";
398 # XXX: Wrong solution
399 sub get_missing_css_lines() {
403 $css_line .= '.' . 'default' . ' {';
404 $css_line .= 'color:' . HEADER_DEFAULT_COLOUR . ';';
405 $css_line .= 'background-color:' . get_css_colour(DEFAULT_BACKGROUND) . ';';
406 $css_line .= '}' . "\n";
413 our %css_colours; #XXX: Wrong solution
417 $css .= '.privoxy-log {';
418 $css .= 'color:' . get_css_colour(DEFAULT_TEXT_COLOUR) . ';';
419 $css .= 'background-color:' . get_css_colour(DEFAULT_BACKGROUND) . ';';
422 foreach my $key (keys %h_colours) {
424 next if ($h_colours{$key} =~ m/reset/); #XXX: Wrong solution.
425 $css .= get_css_line($key);
429 foreach my $colour (keys %css_colours) {
431 $css .= get_css_line_for_colour($colour);
435 $css .= get_missing_css_lines(); #XXX: Wrong solution
444 if (cli_option_is_set('html-output')) {
446 my $title = get_html_title();
448 $intro .= '<html><head>';
449 $intro .= '<title>' . $title . '</title>';
450 $intro .= '<style>' . get_css() . '</style>' unless cli_option_is_set('no-embedded-css');
451 $intro .= '</head><body>';
452 $intro .= '<h1>' . $title . '</h1><p class="privoxy-log">';
462 if (cli_option_is_set('html-output')) {
464 $outro = '</p></body></html>';
471 return cli_option_is_set('html-output') ? "<br>\n" : "\n";
474 sub get_colour_html_markup($) {
475 ###############################################################
476 # Takes a colour string a span element. XXX: WHAT?
477 # XXX: This function shouldn't be necessary, the
478 # markup should always be semantically correct.
479 ###############################################################
484 if ($type =~ /Standard/) {
487 $code = '<span class="' . lc($type) . '">';
493 sub default_colours() {
496 return reset_colours();
503 sub reset_colours() {
504 return ESCAPE . "0m";
507 sub set_background($) {
523 if (defined($backgrounds{$colour})) {
524 $bg_code = $backgrounds{$colour};
526 die "Invalid background colour: " . $colour;
530 sub get_background() {
534 sub prepare_highlight_hash($) {
537 foreach my $key (keys %$ref) {
538 $$ref{$key} = $html_output_mode ?
539 get_semantic_html_markup($key) :
540 paint_it($$ref{$key});
544 sub prepare_colour_array($) {
547 foreach my $i (0 ... @$ref - 1) {
548 $$ref[$i] = $html_output_mode ?
549 get_colour_html_markup($$ref[$i]) :
554 sub found_unknown_content($) {
559 return unless cli_option_is_set('strict-checks');
561 return if ($unknown =~ /\[too long, truncated\]$/);
563 $message = "found_unknown_content: Don't know how to highlight: ";
564 # Break line so the log file can later be parsed as Privoxy log file again
565 $message .= '"' . $unknown . '"' . " in:\n";
566 $message .= $req{$t}{'log-message'};
567 debug_message($message);
568 log_parse_error($req{$t}{'log-message'});
570 die "Unworthy content parser" if PUNISH_MISSING_LOG_KNOWLEDGE_WITH_DEATH;
573 sub log_parse_error($) {
577 if (LOG_UNPARSED_LINES_TO_EXTRA_FILE) {
578 open(my $errorlog_fd, ">>", ERROR_LOG_FILE) || die "Writing " . ERROR_LOG_FILE . " failed";
579 print $errorlog_fd $message;
584 sub debug_message(@) {
587 print $h{'debug'} . "@message" . $h{'Standard'} . "\n";
590 ################################################################################
591 # highlighter functions that aren't loglevel-specific
592 ################################################################################
596 # Get highlight marker
597 my $highlight = shift; # XXX: Stupid name;
601 if (defined($highlight)) {
603 $result = $h{$highlight};
607 $message = "h: Don't recognize highlighter $highlight.";
608 debug_message($message);
609 log_parser_error($message);
610 die "Unworthy highlighter function" if PUNISH_MISSING_HIGHLIGHT_KNOWLEDGE_WITH_DEATH;
616 sub highlight_known_headers($) {
620 debug_message("Searching $content for things to highlight.") if DEBUG_HEADER_HIGHLIGHTING;
622 if ($content =~ m/(?<=\s)($header_highlight_regex):/) {
624 $content =~ s@(?<=[\s|'])($header)(?=:)@$header_colours{$header}$1$h{'Standard'}@ig;
625 debug_message("Highlighted '$header' in '$content'") if DEBUG_HEADER_HIGHLIGHTING;
631 sub highlight_matched_request_line($$) {
633 my $result = shift; # XXX: Stupid name;
635 if ($result =~ m@(.*)($regex)(.*)@) {
636 $result = $1 . highlight_request_line($2) . $3
641 sub highlight_request_line($) {
644 my ($method, $url, $http_version);
646 #GET http://images.sourceforge.net/sfx/icon_warning.gif HTTP/1.1
647 if ($rl =~ m/Invalid request/) {
649 $rl = h('invalid-request') . $rl . h('Standard');
651 } elsif ($rl =~ m/^([-\w]+) (.*) (HTTP\/\d+\.\d+)/) {
653 # XXX: might not match in case of HTTP method fuzzing.
654 # XXX: save these: ($method, $path, $http_version) = ($1, $2, $3);
655 $rl =~ s@^(\w+)@$h{'method'}$1$h{'Standard'}@;
656 if ($rl =~ /http:\/\//) {
657 $rl = highlight_matched_url($rl, '[^\s]*(?=\sHTTP)');
659 $rl = highlight_matched_pattern($rl, 'request_', '[^\s]*(?=\sHTTP)');
662 $rl =~ s@(HTTP\/\d\.\d)$@$h{'http-version'}$1$h{'Standard'}@;
664 } elsif ($rl =~ m/\.\.\. \[too long, truncated\]$/) {
666 $rl =~ s@^(\w+)@$h{'method'}$1$h{'Standard'}@;
667 $rl = highlight_matched_url($rl, '[^\s]*(?=\.\.\.)');
669 } elsif ($rl =~ m/^ $/) {
671 $rl = h('error') . "No request line specified!" . h('Standard');
675 debug_message ("Can't parse request line: $rl");
682 sub highlight_response_line($) {
685 my ($http_version, $status_code, $status_message);
690 # TODO: Mark different status codes differently
692 if ($rl =~ m/((?:HTTP\/\d\.\d|ICY)) (\d+) (.*)/) {
693 ($http_version, $status_code, $status_message) = ($1, $2, $3);
695 debug_message ("Can't parse response line: $rl") and die 'Fix this';
698 # Rebuild highlighted
700 $rl .= h('http-version') . $http_version . h('Standard');
702 $rl .= h('status-code') . $status_code . h('Standard');
704 $rl .= h('status-message') . $status_message . h('Standard');
709 sub highlight_matched_url($$) {
711 my $result = shift; # XXX: Stupid name;
714 #print "Got $result, regex ($regex)\n";
716 if ($result =~ m@(.*?)($regex)(.*)@) {
717 $result = $1 . highlight_url($2) . $3;
718 #print "Now the result is $result\n";
724 sub highlight_matched_host($$) {
726 my ($result, $regex) = @_; # XXX: result ist stupid name;
728 if ($result =~ m@(.*?)($regex)(.*)@) {
729 $result = $1 . $h{host} . $2 . $h{Standard} . $3;
735 sub highlight_matched_pattern($$$) {
737 my $result = shift; # XXX: Stupid name;
741 die "Unknown key $key" unless defined $h{$key};
743 if ($result =~ m@(.*?)($regex)(.*)@) {
744 $result = $1 . h($key) . $2 . h('Standard') . $3;
750 sub highlight_matched_path($$) {
752 my $result = shift; # XXX: Stupid name;
755 if ($result =~ m@(.*?)($regex)(.*)@) {
756 $result = $1 . h('path') . $2 . h('Standard') . $3;
762 sub highlight_url($) {
766 if ($html_output_mode) {
768 $url = '<a href="' . $url . '">' . $url . '</a>';
772 $url = h('URL') . $url . h('Standard');
779 sub update_header_highlight_regex($) {
782 my $headers = join ('|', keys %header_colours);
784 $header_highlight_regex = qr/$headers/;
785 print "Registering '$header'\n" if DEBUG_HEADER_HIGHLIGHTING;
788 ################################################################################
789 # loglevel-specific highlighter functions
790 ################################################################################
792 sub handle_loglevel_header($) {
796 if ($c =~ /^scan:/) {
798 if ($c =~ m/^scan: ([^: ]+):/) {
800 # Register new headers
801 # scan: Accept: image/png,image/*;q=0.8,*/*;q=0.5
803 if (!defined($header_colours{$header}) and $header =~ /^[\d\w-]*$/) {
804 debug_message "Registering previously unknown header $1" if DEBUG_HEADER_REGISTERING;
806 if (REGISTER_HEADERS_WITH_THE_SAME_COLOUR) {
807 $header_colours{$header} = $header_colours{'Default'};
809 $header_colours{$header} = $all_colours[$header_colour_index % @all_colours];
810 $header_colour_index++;
812 update_header_highlight_regex($header);
815 } elsif ($c =~ m/^(scan: )(\w+ .+ HTTP\/\d\.\d)/) {
817 # scan: GET http://p.p/ HTTP/1.1
818 $c = $1 . highlight_request_line($2);
820 } elsif ($c =~ m/^(scan: )((?:HTTP\/\d\.\d|ICY) (\d+) (.*))/) {
822 # scan: HTTP/1.1 200 OK
823 $req{$t}{'response_line'} = $2;
824 $req{$t}{'status_code'} = $3;
825 $req{$t}{'status_message'} = $4;
826 $c = $1 . highlight_response_line($req{$t}{'response_line'});
829 } elsif ($c =~ m/^Crunching (?:server|client) header: .* \(contains: ([^\)]*)\)/) {
831 # Crunching server header: Set-Cookie: trac_form_token=d5308c34e16d15e9e301a456; (contains: Cookie:)
832 $c =~ s@(?<=contains: )($1)@$h{'crunch-pattern'}$1$h{'Standard'}@;
833 $c =~ s@(Crunching)@$h{$1}$1$h{'Standard'}@;
835 } elsif ($c =~ m/^New host is: ([^\s]*)\./) {
837 # New host is: trac.vidalia-project.net. Crunching Referer: http://www.vidalia-project.net/!
838 $c = highlight_matched_host($c, '(?<=New host is: )[^\s]+(?=\.)');
839 $c = highlight_matched_url($c, '(?<=Crunching Referer: )[^\s!]+');
841 } elsif ($c =~ m/^Text mode enabled by force. (Take cover)!/) {
843 # Text mode enabled by force. Take cover!
844 $c =~ s@($1)@$h{'warning'}$1$h{'Standard'}@;
846 } elsif ($c =~ m/^(New HTTP Request-Line: )(.*)/) {
848 # New HTTP Request-Line: GET http://www.privoxy.org/ HTTP/1.1
849 $c = $1 . highlight_request_line($2);
851 } elsif ($c =~ m/^Adjust(ed)? Content-Length to \d+/) {
853 # Adjusted Content-Length to 2132
854 # Adjust Content-Length to 33533
855 $c =~ s@(?<=Content-Length to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
856 $c = highlight_known_headers($c);
858 } elsif ($c =~ m/^Destination extracted from "Host:" header. New request URL:/) {
860 # Destination extracted from "Host:" header. New request URL: http://www.cccmz.de/~ridcully/blog/
861 $c = highlight_matched_url($c, '(?<=New request URL: ).*');
863 } elsif ($c =~ m/^Couldn\'t parse:/) {
865 # XXX: These should probable be logged with LOG_LEVEL_ERROR
866 # Couldn't parse: If-Modified-Since: Wed, 21 Mar 2007 16:34:50 GMT (crunching!)
867 # Couldn't parse: at, 24 Mar 2007 13:46:21 GMT in If-Modified-Since: Sat, 24 Mar 2007 13:46:21 GMT (crunching!)
868 $c =~ s@^(Couldn\'t parse)@$h{'error'}$1$h{'Standard'}@;
870 } elsif ($c =~ /^Tagger \'([^\']*)\' added tag \'([^\']*)\'/ or
871 $c =~ m/^Adding tag \'([^\']*)\' created by header tagger \'([^\']*)\'/) {
873 # Adding tag 'GET request' created by header tagger 'method-man' (XXX: no longer used)
874 # Tagger 'revalidation' added tag 'REVALIDATION-REQUEST'. No action bit update necessary.
875 # Tagger 'revalidation' added tag 'REVALIDATION-REQUEST'. Action bits updated accordingly.
877 # XXX: Save tag and tagger
879 $c =~ s@(?<=^Tagger \')([^\']*)@$h{'tagger'}$1$h{'Standard'}@;
880 $c =~ s@(?<=added tag \')([^\']*)@$h{'tag'}$1$h{'Standard'}@;
881 $c =~ s@(?<=Action bits )(updated)@$h{'action-bits-update'}$1$h{'Standard'}@;
882 $no_special_header_highlighting = 1;
884 } elsif ($c =~ /^Tagger \'([^\']*)\' didn['']t add tag \'([^\']*)\'/) {
886 # Tagger 'revalidation' didn't add tag 'REVALIDATION-REQUEST'. Tag already present
887 # XXX: Save tag and tagger
889 $c =~ s@(?<=^Tagger \')([^\']*)@$h{'tag'}$1$h{'Standard'}@;
890 $c =~ s@(?<=didn['']t add tag \')([^\']*)@$h{'tagger'}$1$h{'Standard'}@;
892 } elsif ($c =~ m/^(?:scan:|Randomiz|addh:|Adding:|Removing:|Referer:|Modified:|Accept-Language header|[Cc]ookie)/
893 or $c =~ m/^(Text mode is already enabled|Denied request with NULL byte|Replaced:|add-unique:)/
894 or $c =~ m/^(Crunched (incoming|outgoing) cookie|Suppressed offer|Accepted the client)/
895 or $c =~ m/^(addh-unique|Referer forged to)/
896 or $c =~ m/^Downgraded answer to HTTP\/1.0/
897 or $c =~ m/^Parameter: \+hide-referrer\{[^\}]*\} is a bad idea, but I don\'t care./
898 or $c =~ m/^Referer (?:overwritten|replaced) with: Referer: / #XXX: should this be highlighted?
899 or $c =~ m/^Referer crunched!/
900 or $c =~ m/^crunched x-forwarded-for!/
901 or $c =~ m/^crunched From!/
902 or $c =~ m/^ modified$/
903 or $c =~ m/^Content filtering is enabled. Crunching:/
904 or $c =~ m/^force-text-mode overruled the client/
905 or $c =~ m/^Server time in the future\./
906 or $c =~ m/^content-disposition header crunched and replaced with:/i
907 or $c =~ m/^Reducing white space in /
908 or $c =~ m/^Ignoring single quote in /
909 or $c =~ m/^Converting tab to space in /
910 or $c =~ m/A HTTP\/1\.1 response without/
911 or $c =~ m/Disabled filter mode on behalf of the client/
912 or $c =~ m/Keeping the (?:server|client) header /
913 or $c =~ m/Content modified with no Content-Length header set/
914 or $c =~ m/^Appended client IP address to/
915 or $c =~ m/^Removing 'Connection: close' to imply keep-alive./
916 or $c =~ m/^keep-alive support is disabled/
917 or $c =~ m/^Continue hack in da house/
918 or $c =~ m/^Merged multiple header lines to:/
919 or $c =~ m/^Added header: /
920 or $c =~ m/^Enlisting (?:sorted|left-over) header/
921 or $c =~ m/^Multiple Content-Type headers detected. Removing and ignoring: Content-Type:/
924 # XXX: Some of these may need highlighting
926 # Modified: User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; pl-PL; rv:1.8.1.1) Gecko/20070214 Firefox/2.0.0.1
927 # Accept-Language header crunched and replaced with: Accept-Language: pl-pl
928 # cookie 'Set-Cookie: eZSessionCookie=07bfec287c197440d299f81580593c3d; \
929 # expires=Thursday, 12-Apr-07 15:16:18 GMT; path=/' send by \
930 # http://wirres.net/article/articleview/4265/1/6/ appears to be using time format 1 (XXX: gone with the wind)
931 # Cookie rewritten to a temporary one: Set-Cookie: NSC_gffe-iuuq-mc-wtfswfs=8efb33a53660;path=/
932 # Text mode is already enabled
933 # Denied request with NULL byte(s) turned into line break(s)
934 # Replaced: 'Connection: Yo, home to Bel Air' with 'Connection: close'
935 # addh-unique: Host: people.freebsd.org
936 # Suppressed offer to compress content
937 # Crunched incoming cookie -- yum!
938 # Accepted the client's request to fetch without filtering.
939 # Crunched outgoing cookie: Cookie: PREF=ID=6cf0abd347b30262:TM=1173357617:LM=1173357617:S=jZypyyJ7LPiwFi1_
940 # addh-unique: Host: subkeys.pgp.net:11371
941 # Referer forged to: Referer: http://10.0.0.1/
942 # Downgraded answer to HTTP/1.0
943 # Parameter: +hide-referrer{pille-palle} is a bad idea, but I don't care.
944 # Referer overwritten with: Referer: pille-palle
945 # Referer replaced with: Referer: pille-palle
946 # crunched x-forwarded-for!
948 # modified # XXX: pretty stupid log message
949 # Content filtering is enabled. Crunching: 'Range: 1234-5678' to prevent range-mismatch problems
950 # force-text-mode overruled the client's request to fetch without filtering!
951 # Server time in the future.
952 # content-disposition header crunched and replaced with: content-disposition: filename=baz
953 # Content-Disposition header crunched and replaced with: content-disposition: filename=baz
954 # Reducing white space in 'X-LWS-Test: "This is quoted" this is not "this is " but " this again is not'
955 # Ignoring single quote in 'X-LWS-Test: "This is quoted" this is not "this is " but " this again is not'
956 # Converting tab to space in 'X-LWS-Test: "This is quoted" this is not "this is " but "\
958 # A HTTP/1.1 response without Connection header implies keep-alive.
959 # Disabled filter mode on behalf of the client.
960 # Keeping the server header 'Connection: keep-alive' around.
961 # Keeping the client header 'Connection: close' around. The connection will not be kept alive.
962 # Keeping the client header 'Connection: keep-alive' around. The connection will be kept alive if possible.
963 # Content modified with no Content-Length header set. Creating a fake one for adjustment later on.
964 # Appended client IP address to X-Forwarded-For: 10.0.0.2, 10.0.0.1
965 # Removing 'Connection: close' to imply keep-alive.
966 # keep-alive support is disabled. Crunching: Keep-Alive: 300.
967 # Continue hack in da house.
968 # Merged multiple header lines to: 'X-FORWARDED-PROTO: http X-HOST: 127.0.0.1'
969 # Added header: Content-Encoding: deflate
970 # Enlisting sorted header User-Agent: Mozilla/5.0 (X11; SunOS i86pc; rv:10.0.3) Gecko/20100101 Firefox/10.0.3
971 # Enlisting left-over header Connection: close
972 # Multiple Content-Type headers detected. Removing and ignoring: Content-Type: text/html
974 } elsif ($c =~ m/^scanning headers for:/) {
976 return '' unless SHOW_SCAN_INTRO;
978 } elsif ($c =~ m/^[Cc]runch(ing|ed)|crumble crunched:/) {
979 # crunched User-Agent!
980 # Crunching: Content-Encoding: gzip
982 $c =~ s@(Crunching|crunched)@$h{$1}$1$h{'Standard'}@;
984 } elsif ($c =~ m/^Offending request data with NULL bytes turned into \'°\' characters:/) {
986 # Offending request data with NULL bytes turned into '°' characters: °°n°°(°°°
988 $c = h('warning') . $c . h('Standard');
990 } elsif ($c =~ m/^(Transforming \")(.*?)(\" to \")(.*?)(\")/) {
992 # Transforming "Proxy-Authenticate: Basic realm="Correos Proxy Server"" to\
993 # "Proxy-Authenticate: Basic realm="Correos Proxy Server""
995 $c =~ s@(?<=^Transforming \")(.*)(?=\" to)@$h{'Header'}$1$h{'Standard'}@;
996 $c =~ s@(?<=to \")(.*)(?=\")@$h{'Header'}$1$h{'Standard'}@;
998 } elsif ($c =~ m/^Removing empty header/) {
1000 # Removing empty header
1003 } elsif ($c =~ m/^Content-Type: .* not replaced/) {
1005 # Content-Type: application/octet-stream not replaced. It doesn't look like text.\
1006 # Enable force-text-mode if you know what you're doing.
1007 # XXX: Could highlight more here.
1008 $c =~ s@(?<=^Content-Type: )(.*)(?= not replaced)@$h{'content-type'}$1$h{'Standard'}@;
1010 } elsif ($c =~ m/^(Server|Client) keep-alive timeout is/) {
1012 # Server keep-alive timeout is 5. Sticking with 10.
1013 # Client keep-alive timeout is 20. Sticking with 10.
1015 $c =~ s@(?<=timeout is )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1016 $c =~ s@(?<=Sticking with )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1018 } elsif ($c =~ m/^Reducing keep-alive timeout/) {
1020 # Reducing keep-alive timeout from 60 to 10.
1022 $c =~ s@(?<= from )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1023 $c =~ s@(?<= to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1025 } elsif ($c =~ m/^Killed all-caps Host header line: HOST:/) {
1027 # Killed all-caps Host header line: HOST: bestproxydb.com
1028 $c = highlight_matched_host($c, '(?<=HOST: )[^\s]+');
1029 $c = highlight_matched_pattern($c, 'HOST', 'HOST');
1033 found_unknown_content($c);
1037 unless ($c =~ m/^Transforming/) {
1038 $c = highlight_known_headers($c) unless $no_special_header_highlighting;
1044 sub handle_loglevel_re_filter($) {
1046 my $content = shift;
1050 if ($c =~ m/^(?:re_)?filtering ([^\s]+) \(size (\d+)\) with (?:filter )?\'?([^\s]+?)\'? produced (\d+) hits \(new size (\d+)\)/) {
1052 # XXX: only the second version gets highlighted properly.
1053 # re_filtering www.lfk.de/favicon.ico (size 209) with filter untrackable-hulk produced 0 hits (new size 209).
1054 # filtering aci.blogg.de/ (size 37988) with 'blogg.de' produced 3 hits (new size 38057)
1055 $req{$t}{'content_source'} = $1;
1056 $req{$t}{'content_size'} = $2;
1057 $req{$t}{'content_filter'} = $3;
1058 $req{$t}{'content_hits'} = $4;
1059 $req{$t}{'new_content_size'} = $5;
1060 $req{$t}{'content_size_change'} = $req{$t}{'new_content_size'} - $req{$t}{'content_size'};
1061 #return '' if ($req{$t}{'content_hits'} == 0 && !cli_option_is_set('show-ineffective-filters'));
1062 if ($req{$t}{'content_hits'} == 0 and
1063 not (cli_option_is_set('show-ineffective-filters')
1064 or ($req{$t}{'content_filter'} =~ m/^privoxy-filter-test$/))) {
1068 $c =~ s@(?<=\(size )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1069 $c =~ s@(?<=\(new size )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1070 $c =~ s@(?<=produced )(\d+)(?= hits)@$h{'Number'}$1$h{'Standard'}@;
1072 $c =~ s@([^\s]+?)(\'? produced)@$h{'filter'}$1$h{'Standard'}$2@;
1073 $c = highlight_matched_host($c, '(?<=filtering )[^\s]+');
1076 $c .= "(" . $h{'Number'};
1077 $c .= "+" if ($req{$t}{'content_size_change'} >= 0);
1078 $c .= $req{$t}{'content_size_change'} . $h{'Standard'} . ")";
1081 } elsif ($c =~ /\.{3}$/
1082 and $c =~ m/^(?:re_)?filtering \'?(.*?)\'? \(size (\d*)\) with (?:filter )?\'?([^\s]*?)\'? ?\.{3}$/) {
1084 # Used by Privoxy 3.0.5 and 3.0.6:
1086 # Used by Privoxy 3.0.7:
1087 # filtering 'Connection: close' (size 17) with 'generic-content-ads' ...
1089 $req{$t}{'filtered_header'} = $1;
1090 $req{$t}{'old_header_size'} = $2;
1091 $req{$t}{'header_filter_name'} = $3;
1093 unless (cli_option_is_set('show-ineffective-filters') or
1094 $req{$t}{'header_filter_name'} =~ m/^privoxy-filter-test$/) {
1097 $content =~ s@(?<=\(size )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1098 $content =~ s@($req{$t}{'header_filter_name'})@$h{'filter'}$1$h{'Standard'}@;
1100 } elsif ($c =~ m/^ ?\.\.\. ?produced (\d*) hits \(new size (\d*)\)\./) {
1102 # ...produced 0 hits (new size 23).
1103 #... produced 1 hits (new size 54).
1105 $req{$t}{'header_filter_hits'} = $1;
1106 $req{$t}{'new_header_size'} = $2;
1108 unless (cli_option_is_set('show-ineffective-filters') or
1109 (defined($req{$t}{'header_filter_name'}) and
1110 $req{$t}{'header_filter_name'} =~ m/^privoxy-filter-test$/)) {
1112 if ($req{$t}{'header_filter_hits'} == 0 and
1113 not (defined($req{$t}{'header_filter_name'}) and
1114 $req{$t}{'header_filter_name'} =~ m/^privoxy-filter-test$/)) {
1117 # Reformat including information from the intro
1118 $c = "'" . h('filter') . $req{$t}{'header_filter_name'} . h('Standard') . "'";
1120 # XXX: Hide behind constant, it may be interesting if LOG_LEVEL_HEADER isn't enabled as well.
1121 # $c .= $req{$t}{'filtered_header'} . " ";
1122 $c .= h('Number') . $req{$t}{'header_filter_hits'}. h('Standard');
1123 $c .= ($req{$t}{'header_filter_hits'} == 1) ? " time, " : " times, ";
1125 if ($req{$t}{'old_header_size'} != $req{$t}{'new_header_size'}) {
1127 $c .= "changing size from ";
1128 $c .= h('Number') . $req{$t}{'old_header_size'} . h('Standard');
1130 $c .= h('Number') . $req{$t}{'new_header_size'} . h('Standard');
1135 $c .= "keeping the size at " . $req{$t}{'old_header_size'};
1139 # Highlight from last line (XXX: What?)
1140 # $c =~ s@(?<=produced )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1141 # $c =~ s@($req{$t}{'header_filter_name'})@$h{'filter'}$1$h{'Standard'}@;
1146 $c =~ s@(?<=produced )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1147 $c =~ s@(?<=new size )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1152 } elsif ($c =~ m/^(Tagger|Filter) ([^\s]*) has empty joblist. Nothing to do./) {
1154 # Filter privoxy-filter-test has empty joblist. Nothing to do.
1155 # Tagger variable-test has empty joblist. Nothing to do.
1157 $content =~ s@(?<=$1 )([^\s]*)@$h{'filter'}$1$h{'Standard'}@;
1159 } elsif ($c =~ m/^De-chunking successful. Shrunk from (\d+) to (\d+)/) {
1161 $req{$t}{'chunked-size'} = $1;
1162 $req{$t}{'dechunked-size'} = $2;
1163 $req{$t}{'dechunk-change'} = $req{$t}{'dechunked-size'} - $req{$t}{'chunked-size'};
1165 $content .= " (" . h('Number') . $req{$t}{'dechunk-change'} . h('Standard') . ")";
1167 $content =~ s@(?<=from )($req{$t}{'chunked-size'})@$h{'Number'}$1$h{'Standard'}@;
1168 $content =~ s@(?<=to )($req{$t}{'dechunked-size'})@$h{'Number'}$1$h{'Standard'}@;
1170 } elsif ($c =~ m/^Decompression successful. Old size: (\d+), new size: (\d+)./) {
1172 # Decompression successful. Old size: 670, new size: 1166.
1174 $req{$t}{'size-compressed'} = $1;
1175 $req{$t}{'size-decompressed'} = $2;
1176 $req{$t}{'decompression-gain'} = $req{$t}{'size-decompressed'} - $req{$t}{'size-compressed'};
1178 $content =~ s@(?<=Old size: )($req{$t}{'size-compressed'})@$h{'Number'}$1$h{'Standard'}@;
1179 $content =~ s@(?<=new size: )($req{$t}{'size-decompressed'})@$h{'Number'}$1$h{'Standard'}@;
1181 # XXX: Create sub get_percentage()
1182 if ($req{$t}{'size-decompressed'}) {
1183 $req{$t}{'decompression-gain-percent'} =
1184 $req{$t}{'decompression-gain'} / $req{$t}{'size-decompressed'} * 100;
1186 $content .= " (saved: ";
1187 #$content .= h('Number') . $req{$t}{'decompression-gain'} . h('Standard');
1189 $content .= h('Number') . sprintf("%.2f%%", $req{$t}{'decompression-gain-percent'}) . h('Standard');
1193 } elsif ($c =~ m/^(Need to de-chunk first)/) {
1195 # Need to de-chunk first
1196 return '' if SUPPRESS_NEED_TO_DE_CHUNK_FIRST;
1198 } elsif ($c =~ m/^(Adding (?:dynamic )?re_filter job)/) {
1200 return '' if (SUPPRESS_SUCCEEDED_FILTER_ADDITIONS && m/succeeded/);
1202 # Adding re_filter job ...
1203 # Adding dynamic re_filter job s@^(?:\w*)\s+.*\s+HTTP/\d\.\d\s*@IP-ADDRESS: $origin@D\
1204 # to filter client-ip-address succeeded.
1206 } elsif ($c =~ m/^Compressed content from /) {
1208 # Compressed content from 29258 to 8630 bytes. Compression level: 3
1209 $content =~ s@(?<=from )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1210 $content =~ s@(?<=to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1211 $content =~ s@(?<=level: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1213 } elsif ($c =~ m/^Reading in filter/) {
1215 return '' unless SHOW_FILTER_READIN_IN;
1217 } elsif ($c =~ m/^Decompression didn't result/) {
1219 # Decompression didn't result in any content.
1221 # Nothing to highlight.
1225 found_unknown_content($content);
1232 sub handle_loglevel_tagging($) {
1236 if ($c =~ /^Tagger \'([^\']*)\' added tag \'([^\']*)\'/ or
1237 $c =~ m/^Adding tag \'([^\']*)\' created by header tagger \'([^\']*)\'/) {
1239 # Adding tag 'GET request' created by header tagger 'method-man' (XXX: no longer used)
1240 # Tagger 'revalidation' added tag 'REVALIDATION-REQUEST'. No action bit update necessary.
1241 # Tagger 'revalidation' added tag 'REVALIDATION-REQUEST'. Action bits updated accordingly.
1243 # XXX: Save tag and tagger
1245 $c =~ s@(?<=^Tagger \')([^\']*)@$h{'tagger'}$1$h{'Standard'}@;
1246 $c =~ s@(?<=added tag \')([^\']*)@$h{'tag'}$1$h{'Standard'}@;
1247 $c =~ s@(?<=Action bits )(updated)@$h{'action-bits-update'}$1$h{'Standard'}@;
1252 sub handle_loglevel_redirect($) {
1256 if ($c =~ m/^Decoding "([^""]*)"/) {
1258 $req{$t}{'original-destination'} = $1;
1259 $c = highlight_matched_path($c, '(?<=Decoding ")[^"]*');
1262 } elsif ($c =~ m/^Checking/) {
1264 # Checking /_ylt=A0geu.Z76BRGR9k/**http://search.yahoo.com/search?p=view+odb+presentation+on+freebsd\
1265 # &ei=UTF-8&xargs=0&pstart=1&fr=moz2&b=11 for redirects.
1267 # TODO: Change colour if really url-decoded
1268 $req{$t}{'decoded-original-destination'} = $1;
1269 $c = highlight_matched_path($c, '(?<=Checking ")[^"]*');
1272 } elsif ($c =~ m/^pcrs command "([^""]*)" changed /) {
1274 # pcrs command "s@&from=rss@@" changed \
1275 # "http://it.slashdot.org/article.pl?sid=07/03/02/1657247&from=rss"\
1276 # to "http://it.slashdot.org/article.pl?sid=07/03/02/1657247" (1 hit).
1277 $c =~ s@(?<=pcrs command )"([^""]*)"@$h{'filter'}$1$h{'Standard'}@;
1278 $c = highlight_matched_url($c, '(?<=changed ")[^""]*');
1279 $c =~ s@(?<=changed )"([^""]*)"@$1@; # Remove quotes
1280 $c = highlight_matched_url($c, '(?<=to ")[^""]*');
1281 $c =~ s@(?<=to )"([^""]*)"@$1@; # Remove quotes
1282 $c =~ s@(\d+)(?= hits?)@$h{'hits'}$1$h{'Standard'}@;
1284 } elsif ($c =~ m/^pcrs command "([^""]*)" didn\'t change/) {
1286 # pcrs command "s@^http://([^.]+?)/?$@http://www.bing.com/search?q=$1@" didn't \
1287 # change "http://www.example.org/".
1288 $c =~ s@(?<=pcrs command )"([^""]*)"@$h{'filter'}$1$h{'Standard'}@;
1289 $c = highlight_matched_url($c, '(?<=change ")[^""]*');
1291 } elsif ($c =~ m/(^New URL is: )(.*)/) {
1293 # New URL is: http://it.slashdot.org/article.pl?sid=07/03/04/1511210
1294 # XXX: Use URL highlighter
1296 $c = $1 . h('rewritten-URL') . $2 . h('Standard');
1298 } elsif ($c =~ m/No pcrs command recognized, assuming that/) {
1299 # No pcrs command recognized, assuming that "http://config.privoxy.org/user-manual/favicon.png"\
1300 # is already properly formatted.
1301 # XXX: assume the same?
1302 $c = highlight_matched_url($c, '(?<=assuming that \")[^"]*');
1304 } elsif ($c =~ m/^Percent-encoding redirect/) {
1306 # Percent-encoding redirect URL: http://www.example.org/\x02
1307 $c = highlight_matched_url($c, '(?<=redirect URL: ).*');
1309 } elsif ($c =~ m/^Rewrite detected:/) {
1311 # Rewrite detected: GET http://10.0.0.2:88/blah.txt HTTP/1.1
1312 # Rewrite detected: GET https://www.electrobsd.org/CommonJS/ajax/libs/jquery/3.4.1/jquery.min.js HTTP/1.1
1313 $c = highlight_matched_request_line($c, '(?<=^Rewrite detected: ).*');
1315 } elsif ($c =~ m/^Rewritten request line results in downgrade to http/) {
1317 # Rewritten request line results in downgrade to http
1318 $c =~ s@(downgrade)@$h{'http-downgrade'}$1$h{'Standard'}@;
1322 found_unknown_content($c);
1329 sub handle_loglevel_gif_deanimate($) {
1331 my $content = shift;
1333 if ($content =~ m/Success! GIF shrunk from (\d+) bytes to (\d+)\./) {
1335 my $bytes_from = $1;
1337 # Gif-Deanimate: Success! GIF shrunk from 205 bytes to 133.
1338 $content =~ s@$bytes_from@$h{'Number'}$bytes_from$h{'Standard'}@;
1339 # XXX: Do we need g in case of ($1 == $2)?
1340 $content =~ s@$bytes_to@$h{'Number'}$bytes_to$h{'Standard'}@;
1342 } elsif ($content =~ m/GIF (not) changed/) {
1344 # Gif-Deanimate: GIF not changed.
1345 return '' if SUPPRESS_GIF_NOT_CHANGED;
1346 $content =~ s@($1)@$h{'not'}$1$h{'Standard'}@;
1348 } elsif ($content =~ m/^failed! \(gif parsing\)/) {
1350 # failed! (gif parsing)
1351 # XXX: Replace this error message with something less stupid
1352 $content =~ s@(failed!)@$h{'error'}$1$h{'Standard'}@;
1354 } elsif ($content =~ m/^Need to de-chunk first/) {
1356 # Need to de-chunk first
1357 return '' if SUPPRESS_NEED_TO_DE_CHUNK_FIRST;
1359 } elsif ($content =~ m/^(?:No GIF header found|failed while parsing)/) {
1361 # No GIF header found (XXX: Did I ever commit this?)
1362 # failed while parsing 195 134747048 (XXX: never committed)
1364 # Ignore these for now
1368 found_unknown_content($content);
1375 sub handle_loglevel_request($) {
1377 my $content = shift;
1379 if ($content =~ m/crunch! /) {
1381 # config.privoxy.org/send-stylesheet crunch! (CGI Call)
1383 # Highlight crunch reasons
1384 foreach my $reason (keys %reason_colours) {
1385 $content =~ s@\(($reason)\)@$reason_colours{$reason}($1)$h{'Standard'}@g;
1387 # Highlight request URL domain and ditch 'crunch!'
1388 $content = highlight_matched_pattern($content, 'request_', '[^ ]*(?= crunch!)');
1389 $content =~ s@ crunch!@@;
1391 } elsif ($content =~ m/\[too long, truncated\]$/) {
1393 # config.privoxy.org/edit-actions-submit?f=3&v=1176116716&s=7&Submit=Submit[...]&filter... [too long, truncated]
1394 $content = highlight_matched_pattern($content, 'request_', '^.*(?=\.\.\. \[too long, truncated\]$)');
1396 } elsif ($content =~ m/(.*)/) { # XXX: Pretty stupid
1398 # trac.vidalia-project.net/wiki/Volunteer?format=txt
1399 $content = h('request_') . $content . h('Standard');
1403 found_unknown_content($content);
1410 sub handle_loglevel_crunch($) {
1412 my $content = shift;
1414 # Highlight crunch reason
1415 foreach my $reason (keys %reason_colours) {
1416 $content =~ s@($reason)@$reason_colours{$reason}$1$h{'Standard'}@g;
1419 if ($content =~ m/\[too long, truncated\]$/) {
1421 # Blocked: config.privoxy.org/edit-actions-submit?f=3&v=1176116716&s=7&Submit=Submit\
1422 # [...]&filter... [too long, truncated]
1423 $content = highlight_matched_pattern($content, 'request_', '^.*(?=\.\.\. \[too long, truncated\]$)');
1427 # Blocked: http://ads.example.org/
1428 $content = highlight_matched_pattern($content, 'request_', '(?<=: ).*');
1434 sub handle_loglevel_connect($) {
1438 if ($c =~ m/^via [^\s]+ to: [^\s]+/) {
1440 # Connect: via 10.0.0.1:8123 to: www.example.org.noconnect
1442 $c = highlight_matched_host($c, '(?<=via )[^\s]+');
1443 $c = highlight_matched_host($c, '(?<=to: )[^\s]+');
1445 } elsif ($c =~ m/^connect to: .* failed: .*/) {
1447 # connect to: www.example.org.noconnect failed: Operation not permitted
1449 $c = highlight_matched_host($c, '(?<=connect to: )[^\s]+');
1451 $c =~ s@(?<=failed: )(.*)@$h{'error'}$1$h{'Standard'}@;
1453 } elsif ($c =~ m/^to ([^\s]*)( successful)?$/) {
1455 # Connect: to www.nzherald.co.nz successful
1456 # Connect: to archiv.radiotux.de
1458 return '' if SUPPRESS_SUCCESSFUL_CONNECTIONS;
1459 $c = highlight_matched_host($c, '(?<=to )[^\s]+');
1461 } elsif ($c =~ m/^to ([^\s]*)$/) {
1463 # Connect: to lists.sourceforge.net:443
1465 $c = highlight_matched_host($c, '(?<=to )[^\s]+');
1467 } elsif ($c =~ m/^[Aa]ccepted connection from .*/ or
1471 # Accepted connection from 10.0.0.1 on socket 5
1472 # Privoxy between 3.0.20 and 3.0.6:
1473 # accepted connection from 10.0.0.1( on socket 5)?
1474 # Privoxy 3.0.6 and earlier just say:
1476 $c = highlight_matched_host($c, '(?<=connection from )[^ ]*');
1477 $c = highlight_matched_pattern($c, 'Number', '(?<=socket )\d+');
1479 } elsif ($c =~ m/^Closing client socket/) {
1481 # Closing client socket 5. Keep-alive: 0, Socket alive: 1. Data available: 0.
1482 # Privoxy 3.0.20 and later
1483 # Closing client socket 8. Keep-alive: 1. Socket alive: 0. Data available: 0. \
1484 # Configuration file change detected: 0. Requests received: 11.
1486 $c = highlight_matched_pattern($c, 'Number', '(?<=socket )\d+');
1487 $c = highlight_matched_pattern($c, 'Number', '(?<=Keep-alive: )\d+');
1488 $c = highlight_matched_pattern($c, 'Number', '(?<=Socket alive: )\d+');
1489 $c = highlight_matched_pattern($c, 'Number', '(?<=available: )\d+');
1490 $c = highlight_matched_pattern($c, 'Number', '(?<=detected: )\d+');
1491 $c = highlight_matched_pattern($c, 'Number', '(?<=received: )\d+');
1493 } elsif ($c =~ m/^write header to: .* failed:/) {
1495 # write header to: 10.0.0.1 failed: Broken pipe
1497 $c = highlight_matched_host($c, '(?<=write header to: )[^\s]*');
1498 $c =~ s@(?<=failed: )(.*)@$h{'Error'}$1$h{'Standard'}@;
1500 } elsif ($c =~ m/^write header to client failed:/) {
1502 # write header to client failed: Broken pipe
1504 $c =~ s@(?<=failed: )(.*)@$h{'Error'}$1$h{'Standard'}@;
1506 } elsif ($c =~ m/^socks4_connect:/) {
1508 # socks4_connect: SOCKS request rejected or failed.
1509 $c =~ s@(?<=socks4_connect: )(.*)@$h{'Error'}$1$h{'Standard'}@;
1511 } elsif ($c =~ m/^Listening for new connections/ or
1512 $c =~ m/^accept connection/) {
1514 # Privoxy versions above 3.0.6 say:
1515 # Listening for new connections ...
1516 # earlier versions say:
1517 # accept connection ...
1520 } elsif ($c =~ m/^accept failed:/) {
1522 $c =~ s@(?<=accept failed: )(.*)@$h{'Error'}$1$h{'Standard'}@;
1524 } elsif ($c =~ m/^Overriding forwarding settings/) {
1526 # Overriding forwarding settings based on 'forward 10.0.0.1:8123'
1527 $c =~ s@(?<=based on \')(.*)(?=\')@$h{'configuration-line'}$1$h{'Standard'}@;
1529 } elsif ($c =~ m/^Denying suspicious CONNECT request from/) {
1531 # Denying suspicious CONNECT request from 10.0.0.1
1532 $c = highlight_matched_host($c, '(?<=from )[^\s]+'); # XXX: not an URL
1534 } elsif ($c =~ m/^socks5_connect:/) {
1536 $c =~ s@(?<=socks5_connect: )(.*)@$h{'error'}$1$h{'Standard'}@;
1538 } elsif ($c =~ m/^Created new connection to/) {
1540 # Created new connection to www.privoxy.org:80 on socket 11.
1541 $c = highlight_matched_host($c, '(?<=connection to )[^\s]+');
1542 $c =~ s@(?<=on socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1544 } elsif ($c =~ m/^Found reusable socket/) {
1546 # Found reusable socket 9 for www.privoxy.org:80 in slot 0.
1548 # Found reusable socket 8 for www.privoxy.org:80 in slot 2.\
1549 # Timestamp made 0 seconds ago. Timeout: 1. Latency: 0.
1550 $c =~ s@(?<=Found reusable socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1551 $c = highlight_matched_host($c, '(?<=for )[^\s]+');
1552 $c =~ s@(?<=in slot )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1553 $c =~ s@(?<=made )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1554 $c =~ s@(?<=Timeout: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1555 $c =~ s@(?<=Latency: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1557 } elsif ($c =~ m/^Marking open socket/) {
1559 # Marking open socket 9 for www.privoxy.org:80 in slot 0 as unused.
1560 $c =~ s@(?<=Marking open socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1561 $c = highlight_matched_host($c, '(?<=for )[^\s]+');
1562 $c =~ s@(?<=in slot )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1564 } elsif ($c =~ m/^No reusable/) {
1566 # No reusable socket for addons.mozilla.org:443 found. Opening a new one.
1567 $c = highlight_matched_host($c, '(?<=for )[^\s]+');
1569 } elsif ($c =~ m/^(Remembering|Forgetting) socket/) {
1571 # Remembering socket 13 for www.privoxy.org:80 in slot 0.
1572 # Forgetting socket 38 for www.privoxy.org:80 in slot 5.
1574 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1575 $c = highlight_matched_host($c, '(?<=for )[^\s]+');
1576 $c =~ s@(?<=in slot )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1578 } elsif ($c =~ m/^Socket/) {
1580 # Socket 16 already forgotten or never remembered.
1581 $c =~ s@(?<=Socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1583 } elsif ($c =~ m/^The connection to/) {
1585 # The connection to www.privoxy.org:80 in slot 6 timed out. Closing socket 19. Timeout is: 61.
1587 # The connection to 1.bp.blogspot.com:80 in slot 0 timed out. Closing socket 5.\
1588 # Timeout is: 1. Assumed latency: 4.
1589 # The connection to 10.0.0.1:80 in slot 0 is no longer usable. Closing socket 4.
1590 $c = highlight_matched_host($c, '(?<=connection to )[^\s]+');
1591 $c =~ s@(?<=in slot )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1592 $c =~ s@(?<=Closing socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1593 $c =~ s@(?<=Timeout is: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1594 $c =~ s@(?<=Assumed latency: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1596 } elsif ($c =~ m/^Stopped waiting for the request line/ or
1597 $c =~ m/^No request line on socket \d received in time/ or
1598 $c =~ m/^The client side of the connection on socket \d/) {
1600 # Stopped waiting for the request line. Timeout: 121.
1601 # Privoxy 3.0.19 and later:
1602 # No request line on socket 5 received in time. Timeout: 1.
1603 # The client side of the connection on socket 5 got closed \
1604 # without sending a complete request line.
1605 $c =~ s@(?<=Timeout: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1606 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1608 } elsif ($c =~ m/^Waiting for \d/) {
1610 # Waiting for 1 connections to timeout.
1611 $c =~ s@(?<=^Waiting for )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1613 } elsif ($c =~ m/^Initialized/) {
1615 # Initialized 20 socket slots.
1616 $c =~ s@(?<=Initialized )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1618 } elsif ($c =~ m/^Done reading from server/) {
1620 # Done reading from server. Expected content length: 24892. \
1621 # Actual content length: 24892. Most recently received: 4412.
1623 # Done reading from server. Expected content length: 24892. \
1624 # Actual content length: 24892. Bytes most recently read: 4412.
1625 # Done reading from server. Content length: 6018 as expected. \
1626 # Bytes most recently read: 294.
1627 $c =~ s@(?<=ontent length: )(\d+)@$h{'Number'}$1$h{'Standard'}@g;
1628 $c =~ s@(?<=received: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1629 $c =~ s@(?<=read: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1631 } elsif ($c =~ m/^Continuing buffering (?:server )?headers/) {
1633 # Continuing buffering headers. byte_count: 19. header_offset: 517. len: 536.
1634 $c =~ s@(?<=byte_count: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1635 $c =~ s@(?<=header_offset: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1636 $c =~ s@(?<=len: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1637 # 3.0.15 up to 3.0.19:
1638 # Continuing buffering headers. Bytes most recently read: 498.
1639 $c =~ s@(?<=read: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1641 # Continuing buffering server headers from socket 5. Bytes most recently read: 498.
1642 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1644 } elsif ($c =~ m/^Received \d+ bytes while/) {
1646 # Received 206 bytes while expecting 12103.
1647 $c =~ s@(?<=Received )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1648 $c =~ s@(?<=expecting )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1650 } elsif ($c =~ m/^(Rejecting c|C)onnection from/) {
1652 # Connection from 81.163.28.218 dropped due to ACL
1653 # Rejecting connection from 178.63.152.227. Maximum number of connections reached.
1654 # Connection from 192.168.2.1 on 127.0.1.1:8118 (socket 3) dropped due to ACL
1655 $c = highlight_matched_host($c, '(?<=onnection from )[\d.:]+');
1656 $c = highlight_matched_host($c, '(?<=on )[\d.:]+');
1657 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1659 } elsif ($c =~ m/^(?:Reusing|Closing) server socket / or
1660 $c =~ m/^No additional client request/) {
1662 # Reusing server socket 4. Opened for 10.0.0.1.
1663 # Closing server socket 2. Opened for 10.0.0.1.
1664 # No additional client request received in time. \
1665 # Closing server socket 4, initially opened for 10.0.0.1.
1666 # No additional client request received in time on socket 29.
1667 # Privoxy 3.0.20 and later
1668 # Reusing server socket 7 connected to www.privoxy.org. Total requests: 2.
1669 # Closing server socket 6 connected to d.asset.soup.io. Keep-alive: 0.\
1670 # Tainted: 1. Socket alive: 1. Timeout: 60. Configuration file change detected: 0.
1671 # Reusing server socket 35 connected to nl.wikipedia.org. Requests already sent: 5.
1673 $c =~ s@(?<= socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1674 $c = highlight_matched_host($c, '(?<=for )[^\s]+(?=\.)');
1675 $c = highlight_matched_host($c, '(?<=connected to )[^\s]+(?=\.)');
1676 for my $number_pattern ('requests', 'Keep-alive', 'Tainted', ' alive', 'Timeout', 'detected') {
1677 $c = highlight_matched_pattern($c, 'Number', '(?<='. $number_pattern . ': )\d+');
1679 $c =~ s@(?<=already sent: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1681 } elsif ($c =~ m/^Connected to /) {
1683 # Connected to tor-jail[10.0.0.2]:9050.
1685 $c = highlight_matched_host($c, '(?<=\[)[^\]]+');
1686 $c = highlight_matched_host($c, '(?<=Connected to )[^\[\s]+');
1687 $c =~ s@(?<=\]:)(\d+)@$h{'Number'}$1$h{'Standard'}@;
1689 } elsif ($c =~ m/^Could not connect to /) {
1691 # Could not connect to [10.0.0.1]:80.
1693 $c = highlight_matched_host($c, '(?<=\[)[^\]]+');
1694 $c =~ s@(?<=\]:)(\d+)@$h{'Number'}$1$h{'Standard'}@;
1696 } elsif ($c =~ m/^Waiting for the next client request/ or
1697 $c =~ m/^The connection on server socket/ or
1698 $c =~ m/^Client request (?:\d+ )?(?:arrived in time|has been pipelined) /) {
1700 # Waiting for the next client request on socket 3. Keeping the server \
1701 # socket 12 to a.fsdn.com open.
1702 # The connection on server socket 6 to upload.wikimedia.org isn't reusable. Closing.
1703 # Privoxy 3.0.20 and later:
1704 # Client request 4 arrived in time on socket 7.
1705 # Used by Privoxy 3.0.18 and 3.0.19:
1706 # Client request arrived in time on socket 21.
1707 # Used by earlier version:
1708 # Client request arrived in time or the client closed the connection on socket 12.
1709 # Client request 8 has been pipelined on socket 7 and the socket is still alive.
1711 $c =~ s@(?<=request )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1712 $c =~ s@(?<=on socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1713 $c =~ s@(?<=server socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1714 $c = highlight_matched_host($c, '(?<=to )[^\s]+');
1716 } elsif ($c =~ m/^Marking the server socket/) {
1718 # Marking the server socket 7 tainted.
1720 $c =~ s@(?<=server socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1722 } elsif ($c =~ m/^Reduced expected bytes to /) {
1724 # Reduced expected bytes to 0 to account for the 1542 ones we already got.
1725 $c =~ s@(?<=bytes to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1726 $c =~ s@(?<=for the )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1728 } elsif ($c =~ m/^The client closed socket /) {
1730 # The client closed socket 2 while the server socket 4 is still open.
1731 $c =~ s@(?<=closed socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1732 $c =~ s@(?<=server socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1734 } elsif ($c =~ m/^Expected client content length set /) {
1736 # Expected client content length set to 667325411 after reading 4999 bytes.
1737 $c =~ s@(?<=set to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1738 $c =~ s@(?<=reading )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1740 } elsif ($c =~ m/^Reducing expected bytes to /) {
1742 # Reducing expected bytes to 0. Marking the server socket tainted after throwing 4 bytes away.
1743 $c =~ s@(?<=bytes to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1744 $c =~ s@(?<=after throwing )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1746 } elsif ($c =~ m/^Waiting for up to /) {
1748 # Waiting for up to 4999 bytes from the client.
1749 $c =~ s@(?<=up to )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1751 } elsif ($c =~ m/^Optimistically sending /) {
1753 # Optimistically sending 318 bytes of client headers intended for www.privoxy.org
1754 $c =~ s@(?<=sending )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1755 $c = highlight_matched_host($c, '(?<=for )[^\s]+');
1757 } elsif ($c =~ m/^Stopping to watch the client socket/) {
1759 # Stopping to watch the client socket. There's already another request waiting.
1760 # Privoxy 3.0.20 and later:
1761 # Stopping to watch the client socket 5. There's already another request waiting.
1762 $c =~ s@(?<=client socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1764 } elsif ($c =~ m/^Drained \d+ bytes before closing/) {
1766 # Drained 180 bytes before closing socket 6
1767 $c =~ s@(?<=Drained )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1768 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1770 } elsif ($c =~ m/^Tainting client socket/ or
1771 $c =~ m/^Failed to shutdown socket/) {
1773 # Tainting client socket 7 due to unread data.
1774 # Failed to shutdown socket 11: Connection reset by peer
1776 $c =~ s@(?<=socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1778 } elsif ($c =~ m/^Shifting \d+ pipelined bytes/) {
1780 # Shifting 360 pipelined bytes by 360 bytes
1781 $c =~ s@(?<=Shifting )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1782 $c =~ s@(?<=by )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1784 } elsif ($c =~ m/^Flushed (\d+) bytes of request body while expecting (\d+)/) {
1786 # Flushed 30 bytes of request body while expecting 30
1787 $c =~ s@(?<=Flushed )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1788 $c =~ s@(?<=expecting )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1790 } elsif ($c =~ m/^Performing the TLS\/SSL handshake with client. Hash of host:/) {
1792 # Performing the TLS/SSL handshake with client. Hash of host: bab5296b25e256c7b06b92b17b56bcae
1793 $c = highlight_matched_host($c, '(?<=Hash of host: ).+');
1795 } elsif ($c =~ m/^Forwarding \d+ bytes of encrypted POST data/) {
1797 # Forwarding 1954 bytes of encrypted POST data
1798 $c =~ s@(?<=Forwarding )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1800 } elsif ($c =~ m/^Forwarded the last \d+ bytes/) {
1802 # Forwarded the last 1954 bytes
1803 $c =~ s@(?<=the last )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1805 } elsif ($c =~ m/^Waiting for the next client connection. Currently active threads:/) {
1807 # Waiting for the next client connection. Currently active threads: 30
1808 $c =~ s@(?<=threads: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1810 } elsif ($c =~ m/^Data arrived in time on client socket/) {
1812 # Data arrived in time on client socket 6. Requests so far: 3
1813 $c =~ s@(?<=client socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1814 $c =~ s@(?<=Requests so far: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1816 } elsif ($c =~ m/^Dropping the client connection on socket/) {
1818 # Dropping the client connection on socket 71. The server connection has not been established yet.
1819 $c =~ s@(?<=on socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1821 } elsif ($c =~ m/^The client socket \d+ has become unusable while the server/) {
1823 # The client socket 16 has become unusable while the server socket 24 is still open.
1824 $c =~ s@(?<=client socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1825 $c =~ s@(?<=server socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1827 } elsif ($c =~ m/^The last \d+ bytes of the request body have been read/) {
1829 # The last 12078 bytes of the request body have been read
1830 $c =~ s@(?<=The last )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1832 } elsif ($c =~ m/^Looks like we / or
1833 $c =~ m/^Unsetting keep-alive flag/ or
1834 $c =~ m/^No connections to wait/ or
1835 $c =~ m/^Complete client request received/ or
1836 $c =~ m/^Possible pipeline attempt detected./ or
1837 $c =~ m/^POST request detected. The connection will not be kept alive./ or
1838 $c =~ m/^The server still wants to talk, but the client hung up on us./ or
1839 $c =~ m/^The server didn't specify how long the connection will stay open/ or
1840 $c =~ m/^There might be a request body. The connection will not be kept alive/ or
1841 $c =~ m/^There better be a request body./ or
1842 $c =~ m/^Done reading from the client\.$/) {
1844 # Looks like we reached the end of the last chunk. We better stop reading.
1845 # Looks like we read the end of the last chunk together with the server \
1846 # headers. We better stop reading.
1847 # Looks like we got the last chunk together with the server headers. \
1848 # We better stop reading.
1849 # Unsetting keep-alive flag.
1850 # No connections to wait for left.
1851 # Client request arrived in time or the client closed the connection.
1852 # Complete client request received
1853 # Possible pipeline attempt detected. The connection will not be \
1854 # kept alive and we will only serve the first request.
1855 # POST request detected. The connection will not be kept alive.
1856 # The server still wants to talk, but the client hung up on us.
1857 # The server didn't specify how long the connection will stay open. Assume it's only a second.
1858 # There might be a request body. The connection will not be kept alive.
1859 # Privoxy 3.0.20 and later
1860 # There better be a request body.
1861 # Done reading from the client.
1865 found_unknown_content($c);
1873 sub handle_loglevel_info($) {
1877 if ($c =~ m/^Rewrite detected:/) {
1879 # Rewrite detected: GET http://10.0.0.2:88/blah.txt HTTP/1.1
1880 $c = highlight_matched_request_line($c, '(?<=^Rewrite detected: ).*');
1882 } elsif ($c =~ m/^Decompress(ing deflated|ion didn)/ or
1883 $c =~ m/^Compressed content detected/ or
1884 $c =~ m/^SDCH-compressed content detected/ or
1887 # Decompressing deflated iob: 117
1888 # Decompression didn't result in any content.
1889 # Compressed content detected, content filtering disabled. Consider recompiling Privoxy\
1890 # with zlib support or enable the prevent-compression action.
1891 # SDCH-compressed content detected, content filtering disabled.\
1892 # Consider suppressing SDCH offers made by the client.
1893 # Tagger 'complete-url' created empty tag. Ignored.
1897 } elsif ($c =~ m/^(Re)?loading configuration file /) {
1899 # loading configuration file '/usr/local/etc/privoxy/config':
1900 # Reloading configuration file '/usr/local/etc/privoxy/config'
1901 $c =~ s@(?<=loading configuration file \')([^\']*)@$h{'file'}$1$h{'Standard'}@;
1903 } elsif ($c =~ m/^Loading (actions|filter|trust) file: /) {
1905 # Loading actions file: /usr/local/etc/privoxy/default.action
1906 # Loading filter file: /usr/local/etc/privoxy/default.filter
1907 # Loading trust file: /usr/local/etc/privoxy/trust
1909 $c =~ s@(?<= file: )(.*)$@$h{'file'}$1$h{'Standard'}@;
1911 } elsif ($c =~ m/^exiting by signal/) {
1913 # exiting by signal 15 .. bye
1914 $c =~ s@(?<=exiting by signal )(\d+)@$h{'signal'}$1$h{'Standard'}@;
1916 } elsif ($c =~ m/^Privoxy version/) {
1918 # Privoxy version 3.0.7
1919 $c =~ s@(?<=^Privoxy version )(\d+\.\d+\.\d+)$@$h{'version'}$1$h{'Standard'}@;
1921 } elsif ($c =~ m/^Program name: /) {
1923 # Program name: /usr/local/sbin/privoxy
1924 $c =~ s@(?<=Program name: )(.*)@$h{'program-name'}$1$h{'Standard'}@;
1926 } elsif ($c =~ m/^Listening on port /) {
1928 # Listening on port 8118 on IP address 10.0.0.1
1929 $c =~ s@(?<=Listening on port )(\d+)@$h{'port'}$1$h{'Standard'}@;
1930 $c =~ s@(?<=on IP address )(.*)@$h{'ip-address'}$1$h{'Standard'}@;
1932 } elsif ($c =~ m/^\(Re-\)Open(?:ing)? logfile/) {
1934 # (Re-)Open logfile /var/log/privoxy/privoxy.log
1935 $c =~ s@(?<=Open logfile )(.*)@$h{'file'}$1$h{'Standard'}@;
1937 } elsif ($c =~ m/^(Request from|Malformed server response detected)/) {
1939 # Request from 10.0.0.1 denied. limit-connect{,} doesn't allow CONNECT requests to port 443.
1940 # Request from 10.0.0.1 marked for blocking. limit-connect{,} doesn't allow CONNECT requests to port 443.
1942 # Request from 10.0.0.1 marked for blocking. limit-connect{0} doesn't allow CONNECT requests to www.example.org:443
1943 # Malformed server response detected. Downgrading to HTTP/1.0 impossible.
1945 $c =~ s@(?<=Request from )([^\s]*)@$h{'ip-address'}$1$h{'Standard'}@;
1946 $c =~ s@(denied|blocking)@$h{'warning'}$1$h{'Standard'}@;
1947 $c =~ s@(CONNECT)@$h{'method'}$1$h{'Standard'}@;
1948 $c =~ s@(?<=to port )(\d+)@$h{'port'}$1$h{'Standard'}@;
1949 $c =~ s@(?<=to )([^\s]+)@$h{'request_'}$1$h{'Standard'}@;
1951 } elsif ($c =~ m/^Status code/) {
1953 # Status code 304 implies no body.
1954 $c =~ s@(?<=Status code )(\d+)@$h{'status-code'}$1$h{'Standard'}@;
1956 } elsif ($c =~ m/^Method/) {
1958 # Method HEAD implies no body.
1959 $c =~ s@(?<=Method )([^\s]+)@$h{'method'}$1$h{'Standard'}@;
1961 } elsif ($c =~ m/^Buffer limit reached while extending /) {
1963 # Buffer limit reached while extending the buffer (iob). Needed: 4197470. Limit: 4194304
1964 $c =~ s@(?<=Needed: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1965 $c =~ s@(?<=Limit: )(\d+)@$h{'Number'}$1$h{'Standard'}@;
1967 } elsif ($c =~ m/^File modification detected: /) {
1969 # File modification detected: /usr/local/etc/privoxy/user-agent.action
1970 $c =~ s@(?<= detected: )(.*)$@$h{'file'}$1$h{'Standard'}@;
1972 } elsif ($c =~ m/^No logfile configured/ or
1973 $c =~ m/^Malformerd HTTP headers detected and MS IIS5 hack enabled/ or
1974 $c =~ m/^Invalid \"chunked\" transfer/ or
1975 $c =~ m/^Support for/ or
1976 $c =~ m/^Flushing header and buffers/ or
1977 $c =~ m/^Can not resolve/
1980 # No logfile configured. Please enable it before reporting any problems.
1981 # Malformerd HTTP headers detected and MS IIS5 hack enabled. Expect an invalid \
1982 # response or even no response at all.
1983 # No logfile configured. Logging disabled.
1984 # Invalid "chunked" transfer encoding detected and ignored.
1985 # Support for 'Connection: keep-alive' is experimental, incomplete and\
1986 # known not to work properly in some situations.
1987 # Flushing header and buffers. Stepping back from filtering.
1988 # Can not resolve doesnotexist: hostname nor servname provided, or not known
1992 found_unknown_content($c);
1999 sub handle_loglevel_cgi($) {
2003 if ($c =~ m/^Granting access to/) {
2005 #Granting access to http://config.privoxy.org/send-stylesheet, referrer http://p.p/ is trustworthy.
2007 } elsif ($c =~ m/^Substituting: s(.)/) {
2009 # Substituting: s/@else-not-FEATURE_ZLIB@.*@endif-FEATURE_ZLIB@//sigTU
2010 # XXX: prone to span several lines
2013 #$c =~ s@(?<=failed: )(.*)@$h{'error'}$1$h{'Standard'}@;
2014 $c =~ s@(?!<=\\)($delimiter)@$h{'pcrs-delimiter'}$1$h{'Standard'}@g; # XXX: Too aggressive
2015 #$c =~ s@(?!<=\\)($1)@$h{'pcrs-delimiter'}$1$h{'Standard'}@g;
2021 sub handle_loglevel_force($) {
2025 if ($c =~ m/^Ignored force prefix in request:/) {
2027 # Ignored force prefix in request: "GET http://10.0.0.1/PRIVOXY-FORCE/block HTTP/1.1"
2028 $c =~ s@^(Ignored)@$h{'ignored'}$1$h{'Standard'}@;
2029 $c = highlight_matched_request_line($c, '(?<=request: ")[^"]*');
2031 } elsif ($c =~ m/^Enforcing request:/) {
2033 # Enforcing request: "GET http://10.0.0.1/block HTTP/1.1".
2034 $c = highlight_matched_request_line($c, '(?<=request: ")[^"]*');
2038 found_unknown_content($c);
2045 sub handle_loglevel_error($) {
2049 if ($c =~ m/^(?:Empty|No) server or forwarder response received on socket \d+\./) {
2051 # Empty server or forwarder response received on socket 4.
2052 # Empty server or forwarder response received on socket 3. \
2053 # Closing client socket 15 without sending data.
2054 # Used by Privoxy 3.0.18 and later:
2055 # No server or forwarder response received on socket 8. \
2056 # Closing client socket 10 without sending data.
2058 $c =~ s@(?<=on socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
2059 $c =~ s@(?<=client socket )(\d+)@$h{'Number'}$1$h{'Standard'}@;
2061 } elsif ($c =~ m/^Didn't receive data in time:/) {
2063 # Didn't receive data in time: a.fsdn.com:443
2064 $c =~ s@(?<=in time: )(.*)@$h{'destination'}$1$h{'Standard'}@;
2067 # XXX: There are probably more messages that deserve highlighting.
2073 sub handle_loglevel_ignore($) {
2077 sub gather_loglevel_clf_stats($) {
2079 my $content = shift;
2080 my ($method, $resource, $http_version, $status_code, $size);
2084 # +0200] "GET https://www.youtube.com/watch?v=JmcA9LIIXWw HTTP/1.1" 200 68004
2085 # +0200] "VERSION-CONTROL http://p.p/ HTTP/1.1" 200 2787
2086 $content =~ m/^[+-]\d{4}\] "([^ ]+) (.+) (HTTP\/\d\.\d)" (\d+) (\d+)/;
2093 $stats{requests_clf}++;
2095 unless (defined $method) {
2096 # +0200] "Invalid request" 400 0
2097 return if ($content =~ m/^[+-]\d{4}\] "Invalid request"/);
2098 # +0100] "GET https://securepubads.g.doubleclick.net/gampad/ads?gd[...]... [too long, truncated]
2099 if ($content =~ m/\[too long, truncated\]$/) {
2100 print("Skipped LOG_LEVEL_CLF message that got truncated by Privoxy. Statistics will be inprecise.\n");
2102 print("Failed to parse: $content\n");
2106 $stats{'method'}{$method}++;
2107 if ($cli_options{'url-statistics-threshold'} != 0) {
2108 $stats{'resource'}{$resource}++;
2110 $stats{'http-version'}{$http_version}++;
2112 if ($cli_options{'host-statistics-threshold'} != 0) {
2113 $resource =~ m@(?:https?://)?([^/]+)/?@;
2114 $stats{'hosts'}{$1}++;
2116 $stats{'content-size-total'} += $size;
2117 $stats{'status-code'}{$status_code}++;
2120 sub gather_loglevel_request_stats($$) {
2128 sub gather_loglevel_crunch_stats($$) {
2135 if ($c =~ m/^Redirected:/) {
2136 # Redirected: http://www.example.org/http://p.p/
2137 $stats{'fast-redirections'}++;
2139 } elsif ($c =~ m/^Blocked:/) {
2140 # Blocked: blogger.googleusercontent.com:443
2141 $stats{'blocked'}++;
2143 } elsif ($c =~ m/^Connection timeout:/) {
2144 # Connection timeout: http://c.tile.openstreetmap.org/18/136116/87842.png
2145 $stats{'connection-timeout'}++;
2147 } elsif ($c =~ m/^Connection failure:/) {
2148 # Connection failure: http://127.0.0.1:8080/
2149 $stats{'connection-failure'}++;
2154 sub gather_loglevel_error_stats($$) {
2161 if ($c =~ m/^Empty server or forwarder response received on socket \d+./) {
2163 # Empty server or forwarder response received on socket 4.
2164 $stats{'empty-responses'}++;
2165 if ($thread_data{$thread}{'new_connection'}) {
2166 $stats{'empty-responses-on-new-connections'}++;
2168 $stats{'empty-responses-on-reused-connections'}++;
2173 sub gather_loglevel_connect_stats($$) {
2175 my ($c, $thread) = @_;
2179 if ($c =~ m/^via ([^\s]+) to: [^\s]+/) {
2181 # Connect: via 10.0.0.1:8123 to: www.example.org.noconnect
2182 $thread_data{$thread}{'forwarder'} = $1; # XXX: is this missue?
2184 } elsif ($c =~ m/^to ([^\s]*)$/) {
2186 # Connect: to lists.sourceforge.net:443
2188 $thread_data{$thread}{'forwarder'} = 'direct connection';
2190 } elsif ($c =~ m/^Created new connection to/) {
2192 # Created new connection to www.privoxy.org:80 on socket 11.
2194 $thread_data{$thread}{'new_connection'} = 1;
2196 } elsif ($c =~ m/^Reusing server socket \d./ or
2197 $c =~ m/^Found reusable socket/) {
2199 # Reusing server socket 4. Opened for 10.0.0.1.
2200 # Found reusable socket 9 for www.privoxy.org:80 in slot 0.
2202 $thread_data{$thread}{'new_connection'} = 0;
2203 $stats{'reused-connections'}++;
2205 } elsif ($c =~ m/^Closing client socket \d+. .* Requests received: (\d+)\.$/) {
2207 # Closing client socket 12. Keep-alive: 1. Socket alive: 1. Data available: 0. \
2208 # Configuration file change detected: 0. Requests received: 14.
2210 $stats{'client-requests-on-connection'}{$1}++;
2211 $stats{'closed-client-connections'}++;
2215 sub gather_loglevel_header_stats($$) {
2217 my ($c, $thread) = @_;
2221 if ($c =~ m/^A HTTP\/1\.1 response without/ or
2222 $c =~ m/^Keeping the server header 'Connection: keep-alive' around./)
2224 # A HTTP/1.1 response without Connection header implies keep-alive.
2225 # Keeping the server header 'Connection: keep-alive' around.
2226 $stats{'server-keep-alive'}++;
2235 'server-keep-alive' => 0,
2236 'reused-connections' => 0,
2237 'empty-responses' => 0,
2238 'empty-responses-on-new-connections' => 0,
2239 'empty-responses-on-reused-connections' => 0,
2240 'fast-redirections' => 0,
2242 'connection-failure' => 0,
2243 'connection-timeout' => 0,
2244 'reused-connections' => 0,
2245 'server-keep-alive' => 0,
2246 'closed-client-connections' => 0,
2247 'content-size-total' => 0,
2249 $stats{'client-requests-on-connection'}{1} = 0;
2252 sub get_percentage($$) {
2256 # If small is 0 the percentage is always 0%.
2257 # Make sure it works even if big is 0 as well.
2258 return "0.00%" if ($small eq 0);
2260 # Prevent division by zero.
2261 # XXX: Is this still supposed to be reachable?
2262 return "NaN" if ($big eq 0);
2264 return sprintf("%.2f%%", $small / $big * 100);
2271 my $new_connections = $stats{requests} - $stats{crunches} - $stats{'reused-connections'};
2272 my $client_requests_checksum = 0;
2275 if ($stats{requests_clf} && $stats{requests}
2276 && $stats{requests_clf} != $stats{requests}) {
2277 print "Inconsistent request counts: " . $stats{requests} . "/" . $stats{requests_clf} . "\n";
2280 # To get the total number of requests we can use either the number
2281 # of Common-Log-Format lines or the number of "Request:" messages.
2282 # We prefer the number of CLF lines if available because using
2283 # it works when analysing old log files from Privoxy versions before 3.0.29.
2284 # In Privoxy 3.0.28 and earlier "Request:" messages excluded
2285 # crunched messages.
2286 $requests_total = $stats{requests_clf} ? $stats{requests_clf} : $stats{requests};
2288 if ($requests_total eq 0) {
2289 print "No requests yet.\n";
2293 print "Client requests total: " . $requests_total . "\n";
2294 if ($stats{crunches}) {
2295 my $outgoing_requests = $requests_total - $stats{crunches};
2296 print "Crunches: " . $stats{crunches} . " (" .
2297 get_percentage($requests_total, $stats{crunches}) . ")\n";
2298 print "Blocks: " . $stats{'blocked'} . " (" .
2299 get_percentage($requests_total, $stats{'blocked'}) . ")\n";
2300 print "Fast redirections: " . $stats{'fast-redirections'} . " (" .
2301 get_percentage($requests_total, $stats{'fast-redirections'}) . ")\n";
2302 print "Connection timeouts: " . $stats{'connection-timeout'} . " (" .
2303 get_percentage($requests_total, $stats{'connection-timeout'}) . ")\n";
2304 print "Connection failures: " . $stats{'connection-failure'} . " (" .
2305 get_percentage($requests_total, $stats{'connection-failure'}) . ")\n";
2306 print "Outgoing requests: " . $outgoing_requests . " (" .
2307 get_percentage($requests_total, $outgoing_requests) . ")\n";
2309 print "No crunches detected. Is 'debug 1024' enabled?\n";
2312 print "Server keep-alive offers: " . $stats{'server-keep-alive'} . " (" .
2313 get_percentage($requests_total, $stats{'server-keep-alive'}) . ")\n";
2314 print "New outgoing connections: " . $new_connections . " (" .
2315 get_percentage($requests_total, $new_connections) . ")\n";
2316 print "Reused connections: " . $stats{'reused-connections'} . " (" .
2317 get_percentage($requests_total, $stats{'reused-connections'}) .
2318 "; server offers accepted: " .
2319 get_percentage($stats{'server-keep-alive'}, $stats{'reused-connections'}) . ")\n";
2320 print "Empty responses: " . $stats{'empty-responses'} . " (" .
2321 get_percentage($requests_total, $stats{'empty-responses'}) . ")\n";
2322 print "Empty responses on new connections: "
2323 . $stats{'empty-responses-on-new-connections'} . " (" .
2324 get_percentage($requests_total, $stats{'empty-responses-on-new-connections'})
2326 print "Empty responses on reused connections: " .
2327 $stats{'empty-responses-on-reused-connections'} . " (" .
2328 get_percentage($requests_total, $stats{'empty-responses-on-reused-connections'}) .
2330 print "Client connections: " . $stats{'closed-client-connections'} . "\n";
2331 if ($stats{'content-size-total'}) {
2332 print "Bytes of content transfered to the client: " . $stats{'content-size-total'} . "\n";
2334 my $lines_printed = 0;
2335 print "Client requests per connection distribution:\n";
2336 foreach my $client_requests (sort {
2337 $stats{'client-requests-on-connection'}{$b} <=> $stats{'client-requests-on-connection'}{$a}}
2338 keys %{$stats{'client-requests-on-connection'}
2341 my $count = $stats{'client-requests-on-connection'}{$client_requests};
2342 $client_requests_checksum += $count * $client_requests;
2343 if ($cli_options{'show-complete-request-distribution'} or ($lines_printed < 10)) {
2344 printf "%8d: %d\n", $count, $client_requests;
2348 unless ($cli_options{'show-complete-request-distribution'}) {
2349 printf "Enable --show-complete-request-distribution to get less common numbers as well.\n";
2351 # Due to log rotation we may not have a complete picture for all the requests
2352 printf "Improperly accounted requests: ~%d\n", abs($requests_total - $client_requests_checksum);
2354 if (exists $stats{method}) {
2355 print "Method distribution:\n";
2356 foreach my $method (sort {$stats{'method'}{$b} <=> $stats{'method'}{$a}} keys %{$stats{'method'}}) {
2357 printf "%8d : %-8s\n", $stats{'method'}{$method}, $method;
2360 print "Method distribution unknown. No CLF message parsed yet. Is 'debug 512' enabled?\n";
2362 if (exists $stats{'http-version'}) {
2363 print "Client HTTP versions:\n";
2364 foreach my $http_version (sort {$stats{'http-version'}{$b} <=> $stats{'http-version'}{$a}} keys %{$stats{'http-version'}}) {
2365 printf "%8d : %-8s\n", $stats{'http-version'}{$http_version}, $http_version;
2368 print "HTTP version distribution unknown. No CLF message parsed yet. Is 'debug 512' enabled?\n";
2370 if (exists $stats{'status-code'}) {
2371 print "HTTP status codes:\n";
2372 foreach my $status_code (sort {$stats{'status-code'}{$b} <=> $stats{'status-code'}{$a}} keys %{$stats{'status-code'}}) {
2373 printf "%8d : %-8d\n", $stats{'status-code'}{$status_code}, $status_code;
2376 print "Status code distribution unknown. No CLF message parsed yet. Is 'debug 512' enabled?\n";
2379 if ($cli_options{'url-statistics-threshold'} == 0) {
2380 print "URL statistics are disabled. Increase --url-statistics-threshold to enable them.\n";
2382 print "Requested URLs:\n";
2383 foreach my $resource (sort {$stats{'resource'}{$b} <=> $stats{'resource'}{$a}} keys %{$stats{'resource'}}) {
2384 if ($stats{'resource'}{$resource} < $cli_options{'url-statistics-threshold'}) {
2385 print "Skipped statistics for URLs below the treshold.\n";
2388 printf "%d : %s\n", $stats{'resource'}{$resource}, $resource;
2392 if ($cli_options{'host-statistics-threshold'} == 0) {
2393 print "Host statistics are disabled. Increase --host-statistics-threshold to enable them.\n";
2395 print "Requested Hosts:\n";
2396 foreach my $host (sort {$stats{'hosts'}{$b} <=> $stats{'hosts'}{$a}} keys %{$stats{'hosts'}}) {
2397 if ($stats{'hosts'}{$host} < $cli_options{'host-statistics-threshold'}) {
2398 print "Skipped statistics for Hosts below the treshold.\n";
2401 printf "%d : %s\n", $stats{'hosts'}{$host}, $host;
2407 ################################################################################
2408 # Functions that actually print stuff
2409 ################################################################################
2411 sub print_clf_message() {
2413 our ($ip, $timestamp, $request_line, $status_code, $size);
2416 return if DEBUG_SUPPRESS_LOG_MESSAGES;
2418 # Rebuild highlighted
2419 $output .= $h{'Number'} . $ip . $h{'Standard'};
2421 $output .= "[" . $h{'Timestamp'} . $timestamp . $h{'Standard'} . "]";
2423 $output .= "\"" . highlight_request_line("$request_line") . "\"";
2425 $output .= $h{'Status'} . $status_code . $h{'Standard'};
2427 $output .= $h{'Number'} . $size . $h{'Standard'};
2428 $output .= $line_end;
2433 sub print_non_clf_message($) {
2435 my $content = shift;
2436 my $date_string = $keep_date_mode ? $req{$t}{'day'} . ' ' : '';
2437 my $msec_string = $no_msecs_mode ? '' : '.' . $req{$t}{'msecs'};
2438 my $line_start = $html_output_mode ? '' : $h{"Standard"};
2440 return if DEBUG_SUPPRESS_LOG_MESSAGES;
2444 . $time_colours[$time_colour_index % 2]
2445 . $req{$t}{'time-stamp'}
2447 . $h{Standard} . " "
2448 . $thread_colours{$t}
2452 . $h{$req{$t}{'log-level'}}
2453 . $req{$t}{'log-level'}
2460 sub shorten_thread_id($) {
2462 my $thread_id = shift;
2464 our %short_thread_ids;
2467 unless (defined $short_thread_ids{$thread_id}) {
2468 $short_thread_ids{$thread_id} = sprintf "%.3d", $max_threadid++;
2471 return $short_thread_ids{$thread_id}
2476 my ($day, $time_stamp, $thread, $log_level, $content, $c, $msecs);
2478 my $last_thread = 0;
2479 my $last_timestamp = 0;
2480 my $filters_that_did_nothing;
2483 $time_colour = paint_it('white');
2485 my %log_level_handlers = (
2486 'Re-Filter' => \&handle_loglevel_re_filter,
2487 'Header' => \&handle_loglevel_header,
2488 'Connect' => \&handle_loglevel_connect,
2489 'Redirect' => \&handle_loglevel_redirect,
2490 'Request' => \&handle_loglevel_request,
2491 'Crunch' => \&handle_loglevel_crunch,
2492 'Gif-Deanimate' => \&handle_loglevel_gif_deanimate,
2493 'Info' => \&handle_loglevel_info,
2494 'CGI' => \&handle_loglevel_cgi,
2495 'Force' => \&handle_loglevel_force,
2496 'Error' => \&handle_loglevel_error,
2497 'Fatal error' => \&handle_loglevel_ignore,
2498 'Writing' => \&handle_loglevel_ignore,
2499 'Received' => \&handle_loglevel_ignore,
2500 'Tagging' => \&handle_loglevel_tagging,
2501 'Actions' => \&handle_loglevel_ignore,
2502 'Unknown log level' => \&handle_loglevel_ignore,
2507 if (m/^(\d{4}-\d{2}-\d{2}|\w{3} \d{2}) (\d\d:\d\d:\d\d)\.?(\d+)? (?:Privoxy\()?([^\)\s]*)[\)]? ([\w -]*): (.*?)\r?$/) {
2508 $thread = $t = ($shorten_thread_ids) ? shorten_thread_id($4) : $4;
2509 $req{$t}{'day'} = $day = $1;
2510 $req{$t}{'time-stamp'} = $time_stamp = $2;
2511 $req{$t}{'msecs'} = $msecs = $3 ? $3 : 0; # Only the cool kids have micro second resolution;
2512 $req{$t}{'log-level'} = $log_level = $5;
2513 $req{$t}{'content'} = $content = $c = $6;
2514 $req{$t}{'log-message'} = $_;
2515 $no_special_header_highlighting = 0;
2517 if (defined($log_level_handlers{$log_level})) {
2519 $content = $log_level_handlers{$log_level}($content);
2523 die "No handler found for log level \"$log_level\"\n";
2526 # Highlight Truncations
2527 if (length($_) > 4000) {
2528 $content =~ s@(too long, truncated)]$@$h{'Truncation'}$1$h{'Standard'}]@g;
2531 next unless $content;
2533 # Register threads to keep the colour constant
2534 if (!defined($thread_colours{$thread})) {
2535 $thread_colours{$thread} = $all_colours[$thread_colour_index % @all_colours];
2536 $thread_colour_index++;
2539 # Switch timestamp colour if timestamps differ
2540 if (($msecs ne $last_msecs) || ($time_stamp ne $last_timestamp)) {
2541 debug_message("Tick tack!") if DEBUG_TICKS;
2542 $time_colour = $time_colours[$time_colour_index % 2];
2543 $time_colour_index++;
2544 $last_msecs = $msecs;
2545 $last_timestamp = $time_stamp;
2548 $last_thread = $thread;
2550 print_non_clf_message($content);
2552 } elsif (m/^((?:\d+\.\d+\.\d+\.\d+|[:\d]+)) - - \[(.*)\] "(.*)" (\d+) (\d+)/) {
2554 # LOG_LEVEL_CLF lines look like this
2555 # 61.152.239.32 - - [04/Mar/2007:18:28:23 +0100] "GET \
2556 # http://ad.yieldmanager.com/imp?z=1&Z=120x600&s=109339&u=http%3A%2F%2Fwww.365loan.co.uk%2F&r=1\
2557 # HTTP/1.1" 403 1730
2558 our ($ip, $timestamp, $request_line, $status_code, $size) = ($1, $2, $3, $4, $5);
2560 print_clf_message();
2564 # Some Privoxy log messages span more than one line,
2565 # usually to dump lots of content that doesn't need any syntax highlighting.
2566 # XXX: add mechanism to forward these lines to the right handler anyway.
2568 unless (DEBUG_SUPPRESS_LOG_MESSAGES or (SUPPRESS_EMPTY_LINES and m/^\s+$/)) {
2569 print and print get_line_end(); # unless (SUPPRESS_EMPTY_LINES and m/^\s+$/);
2577 my ($day, $time_stamp, $msecs, $thread, $log_level, $content);
2578 my $strict_checks = cli_option_is_set('strict-checks');
2579 my %log_level_handlers = (
2580 'Connect:' => \&gather_loglevel_connect_stats,
2581 'Crunch:' => \&gather_loglevel_crunch_stats,
2582 'Error:' => \&gather_loglevel_error_stats,
2583 'Header:' => \&gather_loglevel_header_stats,
2584 'Request:' => \&gather_loglevel_request_stats,
2586 my %ignored_log_levels = (
2587 'Actions:' => \&handle_loglevel_ignore,
2588 'CGI:' => \&handle_loglevel_ignore,
2589 'Fatal error:' => \&handle_loglevel_ignore,
2590 'Force:' => \&handle_loglevel_ignore,
2591 'Gif-Deanimate:' => \&handle_loglevel_ignore,
2592 'Info:' => \&handle_loglevel_ignore,
2593 'Re-Filter:' => \&handle_loglevel_ignore,
2594 'Received:' => \&handle_loglevel_ignore,
2595 'Redirect:' => \&handle_loglevel_ignore,
2596 'Unknown log level:' => \&handle_loglevel_ignore,
2597 'Writing:' => \&handle_loglevel_ignore,
2598 'Tagging:' => \&handle_loglevel_ignore,
2602 (undef, $time_stamp, $thread, $log_level, $content) = split(/ /, $_, 5);
2605 next if (not defined($log_level));
2607 if ($time_stamp eq "-") {
2609 gather_loglevel_clf_stats($content);
2611 } elsif (defined($log_level_handlers{$log_level})) {
2613 $content = $log_level_handlers{$log_level}($content, $thread);
2615 } elsif ($strict_checks and not defined($ignored_log_levels{$log_level})) {
2617 die "No handler found for: $_";
2625 sub unbreak_lines_only_loop() {
2626 my $log_messages_reached = 0;
2630 # Log level other than LOG_LEVEL_CLF?
2631 if (m/^(\d{4}-\d{2}-\d{2}|\w{3} \d{2}) (\d\d:\d\d:\d\d)\.?(\d+)? (?:Privoxy\()?([^\)\s]*)[\)]? ([\w -]*): (.*?)\r?$/ or
2633 m/^((?:\d+\.\d+\.\d+\.\d+)) - - \[(.*)\] "(.*)" (\d+) (\d+)/) {
2634 $log_messages_reached = 1;
2639 $_ = "\n". $_ if /^(?:\d+\.\d+\.\d+\.\d+)/;
2644 print "\n" unless $log_messages_reached;
2649 sub VersionMessage {
2650 my $version_message;
2652 $version_message .= 'Privoxy-Log-Parser ' . PRIVOXY_LOG_PARSER_VERSION . "\n";
2653 $version_message .= 'https://www.fabiankeil.de/sourcecode/privoxy-log-parser/' . "\n";
2655 print $version_message;
2658 sub get_cli_options() {
2660 our %cli_options = (
2661 'html-output' => CLI_OPTION_DEFAULT_TO_HTML_OUTPUT,
2662 'title' => CLI_OPTION_TITLE,
2663 'keep-date' => CLI_OPTION_KEEP_DATE,
2664 'no-syntax-highlighting' => CLI_OPTION_NO_SYNTAX_HIGHLIGHTING,
2665 'no-embedded-css' => CLI_OPTION_NO_EMBEDDED_CSS,
2666 'no-msecs' => CLI_OPTION_NO_MSECS,
2667 'shorten-thread-ids' => CLI_OPTION_SHORTEN_THREAD_IDS,
2668 'show-ineffective-filters' => CLI_OPTION_SHOW_INEFFECTIVE_FILTERS,
2669 'statistics' => CLI_OPTION_STATISTICS,
2670 'strict-checks' => CLI_OPTION_STRICT_CHECKS,
2671 'url-statistics-threshold' => CLI_OPTION_URL_STATISTICS_THRESHOLD,
2672 'unbreak-lines-only' => CLI_OPTION_UNBREAK_LINES_ONLY,
2673 'host-statistics-threshold'=> CLI_OPTION_HOST_STATISTICS_THRESHOLD,
2674 'show-complete-request-distribution' => CLI_OPTION_SHOW_COMPLETE_REQUEST_DISTRIBUTION,
2678 'html-output' => \$cli_options{'html-output'},
2679 'title' => \$cli_options{'title'},
2680 'keep-date' => \$cli_options{'keep-date'},
2681 'no-syntax-highlighting' => \$cli_options{'no-syntax-highlighting'},
2682 'no-embedded-css' => \$cli_options{'no-embedded-css'},
2683 'no-msecs' => \$cli_options{'no-msecs'},
2684 'shorten-thread-ids' => \$cli_options{'shorten-thread-ids'},
2685 'show-ineffective-filters' => \$cli_options{'show-ineffective-filters'},
2686 'statistics' => \$cli_options{'statistics'},
2687 'strict-checks' => \$cli_options{'strict-checks'},
2688 'unbreak-lines-only' => \$cli_options{'unbreak-lines-only'},
2689 'url-statistics-threshold=i'=> \$cli_options{'url-statistics-threshold'},
2690 'host-statistics-threshold=i'=> \$cli_options{'host-statistics-threshold'},
2691 'show-complete-request-distribution' => \$cli_options{'show-complete-request-distribution'},
2692 'version' => sub { VersionMessage && exit(0) },
2696 $html_output_mode = cli_option_is_set('html-output');
2697 $no_msecs_mode = cli_option_is_set('no-msecs');
2698 $keep_date_mode = cli_option_is_set('keep-date');
2699 $shorten_thread_ids = cli_option_is_set('shorten-thread-ids');
2700 $line_end = get_line_end();
2711 Options and their default values if they have any:
2712 [--host-statistics-threshold $cli_options{'host-statistics-threshold'}]
2716 [--no-syntax-highlighting]
2717 [--shorten-thread-ids]
2718 [--show-ineffective-filters]
2719 [--show-complete-request-distribution]
2721 [--unbreak-lines-only]
2722 [--url-statistics-threshold $cli_options{'url-statistics-threshold'}]
2723 [--title $cli_options{'title'}]
2725 see "perldoc $0" for more information
2731 ################################################################################
2733 ################################################################################
2737 set_background(DEFAULT_BACKGROUND);
2738 prepare_our_stuff();
2742 # XXX: should explicitly reject incompatible argument combinations
2743 if (cli_option_is_set('unbreak-lines-only')) {
2744 unbreak_lines_only_loop();
2745 } elsif (cli_option_is_set('statistics')) {
2758 B<privoxy-log-parser> - A parser and syntax-highlighter for Privoxy log messages
2762 B<privoxy-log-parser> [B<--html-output>]
2763 [B<--no-msecs>] [B<--no-syntax-higlighting>] [B<--statistics>]
2764 [B<--shorten-thread-ids>] [B<--show-ineffective-filters>]
2765 [B<--url-statistics-threshold>] [B<--version>]
2769 B<privoxy-log-parser> reads Privoxy log messages and
2771 - syntax-highlights recognized lines,
2773 - reformats some of them for easier comprehension,
2775 - filters out less useful messages, and
2777 - (in some cases) calculates additional information,
2778 like the compression ratio or how a filter affected
2781 With B<privoxy-log-parser> you should be able to increase Privoxy's log level
2782 without getting confused by the resulting amount of output. For example for
2783 "debug 64" B<privoxy-log-parser> will (by default) only show messages that
2784 affect the content. If a filter doesn't cause any hits, B<privoxy-log-parser>
2785 will hide the "filter foo caused 0 hits" message.
2789 [B<--host-statistics-threshold>] Only show the request count for a host
2790 if it's above or equal to the given threshold. If the threshold is 0, host
2791 statistics are disabled.
2793 [B<--html-output>] Use HTML and CSS for the syntax highlighting. If this option is
2794 omitted, ANSI escape sequences are used unless B<--no-syntax-highlighting> is active.
2795 This option is only intended to make embedding log excerpts in web pages easier.
2796 It does not escape any input!
2798 [B<--keep-date>] Don't remove the date when printing highlighted log messages.
2799 Useful when parsing multiple log files at once.
2801 [B<--no-msecs>] Don't expect milisecond resolution
2803 [B<--no-syntax-highlighting>] Disable syntax-highlighting. Useful when
2804 the filtered output is piped into less in which case the ANSI control
2805 codes don't work, or if the terminal itself doesn't support the control
2808 [B<--shorten-thread-ids>] Shorten the thread ids to a three-digit decimal number.
2809 Note that the mapping from thread ids to shortened ids is created at run-time
2810 and thus varies with the input.
2812 [B<--show-ineffective-filters>] Don't suppress log lines for filters
2813 that didn't modify the content.
2815 [B<--show-complete-request-distribution>] Show the complete client request
2816 distribution in the B<--statistics> output. Without this option only the
2817 ten most common numbers are shown.
2819 [B<--statistics>] Gather various statistics instead of syntax highlighting
2820 log messages. This is an experimental feature, if the results look wrong
2821 they very well might be. Also note that the results are pretty much guaranteed
2822 to be incorrect if Privoxy and Privoxy-Log-Parser aren't in sync.
2824 [B<--strict-checks>] When generating statistics, look more careful at the
2825 input data and abort if it is unexpected, even if it doesn't affect the
2826 results. Significantly slows the parsing down and is not expected to catch
2827 any problems that matter.
2828 When highlighting, print warnings in case of unknown messages which can't be
2829 properly highlighted.
2831 [B<--unbreak-lines-only>] Tries to fix lines that got messed up by a broken or
2832 interestingly configured mail client and thus are no longer recognized properly.
2833 Only fixes some breakage, but may be good enough or at least better than nothing.
2834 Doesn't do anything else, so you probably want to pipe the output into
2835 B<privoxy-log-parser> again.
2837 [B<--url-statistics-threshold>] Only show the request count for a resource
2838 if it's above or equal to the given threshold. If the threshold is 0, URL
2839 statistics are disabled.
2841 [B<--version>] Print version and exit.
2845 To monitor a log file:
2847 tail -F /usr/jails/privoxy-jail/var/log/privoxy/privoxy.log | B<privoxy-log-parser>
2849 Replace '-F' with '-f' if your tail implementation lacks '-F' support
2850 or if the log won't get rotated anyway. The log file location depends
2851 on your system (Doh!).
2853 To monitor Privoxy without having it write to a log file:
2855 privoxy --no-daemon /usr/jails/privoxy-jail/usr/local/etc/privoxy/config 2>&1 | B<privoxy-log-parser>
2857 Again, the config file location depends on your system. Output redirection
2858 depends on your shell, the above works with bourne shells.
2860 To read a processed Privoxy log file from top to bottom, letting the content
2861 scroll by slightly faster than you can read:
2863 B<privoxy-log-parser> < /usr/jails/privoxy-jail/var/log/privoxy/privoxy.log
2865 This is probably only useful to fill screens in the background of haxor movies.
2869 Syntax highlighting with ANSI escape sequences will look strange
2870 if your background color isn't black.
2872 Some messages aren't recognized yet and will not be fully highlighted.
2874 B<privoxy-log-parser> is developed with Privoxy 3.0.7 or later in mind,
2875 using earlier Privoxy versions will probably result in an increased amount
2876 of unrecognized log lines.
2878 Privoxy's log files tend to be rather large. If you use HTML
2879 highlighting some browsers can't handle them, get confused and
2880 will eventually crash because of segmentation faults or unexpected
2881 exceptions. This is a problem in the browser and not B<privoxy-log-parser>'s
2886 Many settings can't be controlled through command line options yet.
2894 Fabian Keil <fk@fabiankeil.de>