2 a555e0d6 2022-07-04 op * Copyright (c) 2020, 2021, 2022 Omar Polo <op@omarpolo.com>
4 3e4749f7 2020-10-02 op * Permission to use, copy, modify, and distribute this software for any
5 3e4749f7 2020-10-02 op * purpose with or without fee is hereby granted, provided that the above
6 3e4749f7 2020-10-02 op * copyright notice and this permission notice appear in all copies.
8 3e4749f7 2020-10-02 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 3e4749f7 2020-10-02 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 3e4749f7 2020-10-02 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 3e4749f7 2020-10-02 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 3e4749f7 2020-10-02 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 3e4749f7 2020-10-02 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 3e4749f7 2020-10-02 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 52418c8d 2021-02-12 op #include "gmid.h"
19 8443bff7 2021-01-25 op #include <sys/stat.h>
21 592fd624 2020-10-07 op #include <errno.h>
22 3e4749f7 2020-10-02 op #include <fcntl.h>
23 5777923b 2021-06-29 op #include <getopt.h>
24 0046c1fe 2023-06-06 op #include <locale.h>
25 7e1df73d 2021-03-31 op #include <libgen.h>
26 bcf5d929 2021-02-01 op #include <limits.h>
27 c9e97a6e 2022-12-24 op #include <grp.h>
28 ae08ec7d 2021-01-25 op #include <pwd.h>
29 0cf902af 2020-11-03 op #include <signal.h>
30 3e4749f7 2020-10-02 op #include <string.h>
31 eae52ad4 2023-06-06 op #include <syslog.h>
33 eae52ad4 2023-06-06 op #include "log.h"
34 c26f2460 2023-06-08 op #include "proc.h"
36 c26f2460 2023-06-08 op #ifndef nitems
37 c26f2460 2023-06-08 op #define nitems(_a) (sizeof((_a)) / sizeof((_a)[0]))
40 c26f2460 2023-06-08 op static int main_configure(struct conf *);
41 c26f2460 2023-06-08 op static void main_configure_done(struct conf *);
42 c26f2460 2023-06-08 op static void main_reload(struct conf *);
43 c26f2460 2023-06-08 op static void main_sig_handler(int, short, void *);
44 c26f2460 2023-06-08 op static int main_dispatch_server(int, struct privsep_proc *, struct imsg *);
45 86693a33 2023-06-11 op static int main_dispatch_crypto(int, struct privsep_proc *, struct imsg *);
46 c26f2460 2023-06-08 op static int main_dispatch_logger(int, struct privsep_proc *, struct imsg *);
47 c26f2460 2023-06-08 op static void __dead main_shutdown(struct conf *);
48 5af19830 2023-06-09 op static void main_print_conf(struct conf *);
50 c26f2460 2023-06-08 op static struct privsep_proc procs[] = {
51 c26f2460 2023-06-08 op { "server", PROC_SERVER, main_dispatch_server, server },
52 86693a33 2023-06-11 op { "crypto", PROC_CRYPTO, main_dispatch_crypto, crypto },
53 c26f2460 2023-06-08 op { "logger", PROC_LOGGER, main_dispatch_logger, logger },
56 7fff8aa6 2023-06-09 op static const char *opts = "c:D:fI:hnP:T:U:VvX:";
58 e5d82d94 2022-03-19 op static const struct option longopts[] = {
59 5777923b 2021-06-29 op {"help", no_argument, NULL, 'h'},
60 5777923b 2021-06-29 op {"version", no_argument, NULL, 'V'},
61 5777923b 2021-06-29 op {NULL, 0, NULL, 0},
64 bc99d868 2021-03-19 op int sock4, sock6;
65 c26f2460 2023-06-08 op int privsep_process;
66 c26f2460 2023-06-08 op int pidfd = -1;
68 ca84625a 2023-06-08 op int debug, verbose;
70 32fbc478 2022-09-08 op const char *config_path = "/etc/gmid.conf";
71 32fbc478 2022-09-08 op const char *pidfile;
76 3abf91b0 2021-02-07 op fprintf(stderr,
77 0be2a537 2021-06-29 op "Version: " GMID_STRING "\n"
78 0ac785a6 2023-06-05 op "Usage: %s [-fnv] [-c config] [-D macro=value] [-P pidfile]\n",
79 9327bc04 2021-06-29 op getprogname());
82 47b0ff10 2023-06-08 op /* used by the server process, defined here so gg can provide its own impl. */
84 47b0ff10 2023-06-08 op log_request(struct client *c, char *meta, size_t l)
86 af1dab18 2023-06-09 op struct conf *conf = c->conf;
87 47b0ff10 2023-06-08 op char hbuf[NI_MAXHOST], sbuf[NI_MAXSERV], b[GEMINI_URL_LEN];
89 47b0ff10 2023-06-08 op const char *t;
93 47b0ff10 2023-06-08 op len = sizeof(c->addr);
94 47b0ff10 2023-06-08 op ec = getnameinfo((struct sockaddr*)&c->addr, len,
95 47b0ff10 2023-06-08 op hbuf, sizeof(hbuf),
96 47b0ff10 2023-06-08 op sbuf, sizeof(sbuf),
97 47b0ff10 2023-06-08 op NI_NUMERICHOST | NI_NUMERICSERV);
99 47b0ff10 2023-06-08 op fatalx("getnameinfo: %s", gai_strerror(ec));
101 47b0ff10 2023-06-08 op if (c->iri.schema != NULL) {
102 47b0ff10 2023-06-08 op /* serialize the IRI */
103 47b0ff10 2023-06-08 op strlcpy(b, c->iri.schema, sizeof(b));
104 47b0ff10 2023-06-08 op strlcat(b, "://", sizeof(b));
106 47b0ff10 2023-06-08 op /* log the decoded host name, but if it was invalid
107 47b0ff10 2023-06-08 op * use the raw one. */
108 47b0ff10 2023-06-08 op if (*c->domain != '\0')
109 47b0ff10 2023-06-08 op strlcat(b, c->domain, sizeof(b));
111 47b0ff10 2023-06-08 op strlcat(b, c->iri.host, sizeof(b));
113 47b0ff10 2023-06-08 op if (*c->iri.path != '/')
114 47b0ff10 2023-06-08 op strlcat(b, "/", sizeof(b));
115 47b0ff10 2023-06-08 op strlcat(b, c->iri.path, sizeof(b)); /* TODO: sanitize UTF8 */
116 47b0ff10 2023-06-08 op if (*c->iri.query != '\0') { /* TODO: sanitize UTF8 */
117 47b0ff10 2023-06-08 op strlcat(b, "?", sizeof(b));
118 47b0ff10 2023-06-08 op strlcat(b, c->iri.query, sizeof(b));
121 47b0ff10 2023-06-08 op if ((t = c->req) == NULL)
123 47b0ff10 2023-06-08 op strlcpy(b, t, sizeof(b));
126 47b0ff10 2023-06-08 op if ((t = memchr(meta, '\r', l)) == NULL)
127 47b0ff10 2023-06-08 op t = meta + len;
129 47b0ff10 2023-06-08 op ec = asprintf(&fmted, "%s:%s GET %s %.*s", hbuf, sbuf, b,
130 47b0ff10 2023-06-08 op (int)(t-meta), meta);
131 47b0ff10 2023-06-08 op if (ec == -1)
132 792f302a 2023-06-09 op fatal("asprintf");
134 af1dab18 2023-06-09 op proc_compose(conf->ps, PROC_LOGGER, IMSG_LOG_REQUEST,
135 47b0ff10 2023-06-08 op fmted, ec + 1);
141 419a4235 2021-04-28 op write_pidfile(const char *pidfile)
143 419a4235 2021-04-28 op struct flock lock;
146 419a4235 2021-04-28 op if (pidfile == NULL)
149 419a4235 2021-04-28 op if ((fd = open(pidfile, O_WRONLY|O_CREAT|O_CLOEXEC, 0600)) == -1)
150 df5058c9 2023-06-05 op fatal("can't open pidfile %s", pidfile);
152 419a4235 2021-04-28 op lock.l_start = 0;
153 419a4235 2021-04-28 op lock.l_len = 0;
154 419a4235 2021-04-28 op lock.l_type = F_WRLCK;
155 419a4235 2021-04-28 op lock.l_whence = SEEK_SET;
157 419a4235 2021-04-28 op if (fcntl(fd, F_SETLK, &lock) == -1)
158 df5058c9 2023-06-05 op fatalx("can't lock %s, gmid is already running?", pidfile);
160 419a4235 2021-04-28 op if (ftruncate(fd, 0) == -1)
161 df5058c9 2023-06-05 op fatal("ftruncate %s", pidfile);
163 419a4235 2021-04-28 op dprintf(fd, "%d\n", getpid());
169 8d6ae384 2021-01-24 op main(int argc, char **argv)
171 af1dab18 2023-06-09 op struct conf *conf;
172 c26f2460 2023-06-08 op struct privsep *ps;
173 c26f2460 2023-06-08 op const char *errstr, *title = NULL;
174 7fff8aa6 2023-06-09 op const char *user = NULL, *chroot = NULL;
176 c26f2460 2023-06-08 op int ch, conftest = 0;
177 c26f2460 2023-06-08 op int proc_instance = 0;
178 c26f2460 2023-06-08 op int proc_id = PROC_PARENT;
179 c26f2460 2023-06-08 op int argc0 = argc;
181 0046c1fe 2023-06-06 op setlocale(LC_CTYPE, "");
183 eae52ad4 2023-06-06 op /* log to stderr until daemonized */
184 eae52ad4 2023-06-06 op log_init(1, LOG_DAEMON);
186 5777923b 2021-06-29 op while ((ch = getopt_long(argc, argv, opts, longopts, NULL)) != -1) {
187 3e4749f7 2020-10-02 op switch (ch) {
189 0ac785a6 2023-06-05 op config_path = absolutify_path(optarg);
192 f98e9045 2021-06-29 op if (cmdline_symset(optarg) == -1)
193 df5058c9 2023-06-05 op fatalx("could not parse macro definition: %s",
203 c26f2460 2023-06-08 op proc_instance = strtonum(optarg, 0, PROC_MAX_INSTANCES,
205 c26f2460 2023-06-08 op if (errstr != NULL)
206 c26f2460 2023-06-08 op fatalx("invalid process instance");
212 f1f13cb7 2023-06-08 op pidfile = absolutify_path(optarg);
215 c26f2460 2023-06-08 op title = optarg;
216 c26f2460 2023-06-08 op proc_id = proc_getid(procs, nitems(procs), title);
217 c26f2460 2023-06-08 op if (proc_id == PROC_MAX)
218 c26f2460 2023-06-08 op fatalx("invalid process name");
221 7fff8aa6 2023-06-09 op user = optarg;
224 fdb43a4c 2021-06-29 op puts("Version: " GMID_STRING);
230 7fff8aa6 2023-06-09 op chroot = optarg;
238 c26f2460 2023-06-08 op if (argc - optind != 0)
241 af1dab18 2023-06-09 op conf = config_new();
244 7fff8aa6 2023-06-09 op * Only the parent loads the config, the others get user and
245 7fff8aa6 2023-06-09 op * chroot via flags and the rest via imsg.
247 7fff8aa6 2023-06-09 op if (proc_id == PROC_PARENT) {
248 7fff8aa6 2023-06-09 op if (parse_conf(conf, config_path) == -1)
249 7fff8aa6 2023-06-09 op fatalx("failed to load configuration file");
250 7fff8aa6 2023-06-09 op if (*conf->chroot != '\0' && *conf->user == '\0')
251 7fff8aa6 2023-06-09 op fatalx("can't chroot without a user to switch to.");
254 7fff8aa6 2023-06-09 op strlcpy(conf->user, user, sizeof(conf->user));
256 7fff8aa6 2023-06-09 op strlcpy(conf->chroot, chroot, sizeof(conf->chroot));
259 132cae8c 2021-01-18 op if (conftest) {
260 f0a01fc7 2021-10-09 op fprintf(stderr, "config OK\n");
261 f0a01fc7 2021-10-09 op if (conftest > 1)
262 5af19830 2023-06-09 op main_print_conf(conf);
266 c26f2460 2023-06-08 op if ((ps = calloc(1, sizeof(*ps))) == NULL)
267 c26f2460 2023-06-08 op fatal("calloc");
268 af1dab18 2023-06-09 op ps->ps_env = conf;
269 af1dab18 2023-06-09 op conf->ps = ps;
270 af1dab18 2023-06-09 op if (*conf->user) {
271 c26f2460 2023-06-08 op if (geteuid())
272 c26f2460 2023-06-08 op fatalx("need root privileges");
273 af1dab18 2023-06-09 op if ((ps->ps_pw = getpwnam(conf->user)) == NULL)
274 af1dab18 2023-06-09 op fatalx("unknown user %s", conf->user);
277 af1dab18 2023-06-09 op ps->ps_instances[PROC_SERVER] = conf->prefork;
278 c26f2460 2023-06-08 op ps->ps_instance = proc_instance;
279 c26f2460 2023-06-08 op if (title != NULL)
280 c26f2460 2023-06-08 op ps->ps_title[proc_id] = title;
282 af1dab18 2023-06-09 op if (*conf->chroot != '\0') {
283 c26f2460 2023-06-08 op for (i = 0; i < nitems(procs); ++i)
284 af1dab18 2023-06-09 op procs[i].p_chroot = conf->chroot;
287 ca84625a 2023-06-08 op log_init(debug, LOG_DAEMON);
288 ca84625a 2023-06-08 op log_setverbose(verbose);
289 c26f2460 2023-06-08 op if (title != NULL)
290 c26f2460 2023-06-08 op log_procinit(title);
292 c26f2460 2023-06-08 op /* only the parent returns */
293 ca84625a 2023-06-08 op proc_init(ps, procs, nitems(procs), debug, argc0, argv, proc_id);
295 c26f2460 2023-06-08 op log_procinit("main");
296 ca84625a 2023-06-08 op if (!debug && daemon(0, 0) == -1)
297 c26f2460 2023-06-08 op fatal("daemon");
299 8e8b2e25 2021-04-28 op pidfd = write_pidfile(pidfile);
301 c26f2460 2023-06-08 op sandbox_main_process();
303 c26f2460 2023-06-08 op event_init();
305 c26f2460 2023-06-08 op signal(SIGPIPE, SIG_IGN);
307 c26f2460 2023-06-08 op signal_set(&ps->ps_evsigint, SIGINT, main_sig_handler, ps);
308 c26f2460 2023-06-08 op signal_set(&ps->ps_evsigterm, SIGTERM, main_sig_handler, ps);
309 c26f2460 2023-06-08 op signal_set(&ps->ps_evsigchld, SIGCHLD, main_sig_handler, ps);
310 c26f2460 2023-06-08 op signal_set(&ps->ps_evsighup, SIGHUP, main_sig_handler, ps);
312 c26f2460 2023-06-08 op signal_add(&ps->ps_evsigint, NULL);
313 c26f2460 2023-06-08 op signal_add(&ps->ps_evsigterm, NULL);
314 c26f2460 2023-06-08 op signal_add(&ps->ps_evsigchld, NULL);
315 c26f2460 2023-06-08 op signal_add(&ps->ps_evsighup, NULL);
317 c26f2460 2023-06-08 op proc_connect(ps);
319 af1dab18 2023-06-09 op if (main_configure(conf) == -1)
320 c26f2460 2023-06-08 op fatal("configuration failed");
322 c26f2460 2023-06-08 op event_dispatch();
323 af1dab18 2023-06-09 op main_shutdown(conf);
324 c26f2460 2023-06-08 op /* NOTREACHED */
329 c26f2460 2023-06-08 op main_configure(struct conf *conf)
331 c26f2460 2023-06-08 op struct privsep *ps = conf->ps;
333 86693a33 2023-06-11 op conf->reload = conf->prefork + 1; /* servers, crypto */
335 c26f2460 2023-06-08 op if (proc_compose(ps, PROC_SERVER, IMSG_RECONF_START, NULL, 0) == -1)
337 86693a33 2023-06-11 op if (proc_compose(ps, PROC_CRYPTO, IMSG_RECONF_START, NULL, 0) == -1)
340 e45334e6 2023-06-09 op if (config_send(conf) == -1)
343 c26f2460 2023-06-08 op if (proc_compose(ps, PROC_SERVER, IMSG_RECONF_END, NULL, 0) == -1)
345 86693a33 2023-06-11 op if (proc_compose(ps, PROC_CRYPTO, IMSG_RECONF_END, NULL, 0) == -1)
352 c26f2460 2023-06-08 op main_configure_done(struct conf *conf)
354 c26f2460 2023-06-08 op if (conf->reload == 0) {
355 c26f2460 2023-06-08 op log_warnx("configuration already done");
359 c26f2460 2023-06-08 op conf->reload--;
360 c26f2460 2023-06-08 op /* send IMSG_CTL_START? */
364 c26f2460 2023-06-08 op main_reload(struct conf *conf)
366 c26f2460 2023-06-08 op if (conf->reload) {
367 c26f2460 2023-06-08 op log_debug("%s: already in progress: %d pending",
368 c26f2460 2023-06-08 op __func__, conf->reload);
372 c26f2460 2023-06-08 op log_debug("%s: config file %s", __func__, config_path);
373 af1dab18 2023-06-09 op config_purge(conf);
375 68368f4c 2023-06-09 op if (parse_conf(conf, config_path) == -1) {
376 68368f4c 2023-06-09 op log_warnx("failed to parse the config");
380 c26f2460 2023-06-08 op main_configure(conf);
384 c26f2460 2023-06-08 op main_sig_handler(int sig, short ev, void *arg)
386 c26f2460 2023-06-08 op struct privsep *ps = arg;
389 c26f2460 2023-06-08 op * Normal signal handler rules don't apply here because libevent
390 c26f2460 2023-06-08 op * decouples for us.
393 c26f2460 2023-06-08 op switch (sig) {
395 c26f2460 2023-06-08 op if (privsep_process != PROC_PARENT)
397 c26f2460 2023-06-08 op log_info("reload requested with SIGHUP");
398 c26f2460 2023-06-08 op main_reload(ps->ps_env);
400 c26f2460 2023-06-08 op case SIGCHLD:
401 c26f2460 2023-06-08 op log_warnx("one child died, quitting");
402 c26f2460 2023-06-08 op /* fallthrough */
403 c26f2460 2023-06-08 op case SIGTERM:
405 c26f2460 2023-06-08 op main_shutdown(ps->ps_env);
408 c26f2460 2023-06-08 op fatalx("unexpected signal %d", sig);
413 c26f2460 2023-06-08 op main_dispatch_server(int fd, struct privsep_proc *p, struct imsg *imsg)
415 c26f2460 2023-06-08 op struct privsep *ps = p->p_ps;
416 c26f2460 2023-06-08 op struct conf *conf = ps->ps_env;
418 c26f2460 2023-06-08 op switch (imsg->hdr.type) {
419 c26f2460 2023-06-08 op case IMSG_RECONF_DONE:
420 c26f2460 2023-06-08 op main_configure_done(conf);
430 86693a33 2023-06-11 op main_dispatch_crypto(int fd, struct privsep_proc *p, struct imsg *imsg)
432 86693a33 2023-06-11 op struct privsep *ps = p->p_ps;
433 86693a33 2023-06-11 op struct conf *conf = ps->ps_env;
435 86693a33 2023-06-11 op switch (imsg->hdr.type) {
436 86693a33 2023-06-11 op case IMSG_RECONF_DONE:
437 86693a33 2023-06-11 op main_configure_done(conf);
447 c26f2460 2023-06-08 op main_dispatch_logger(int fd, struct privsep_proc *p, struct imsg *imsg)
449 c26f2460 2023-06-08 op struct privsep *ps = p->p_ps;
450 c26f2460 2023-06-08 op struct conf *conf = ps->ps_env;
452 c26f2460 2023-06-08 op switch (imsg->hdr.type) {
453 c26f2460 2023-06-08 op case IMSG_RECONF_DONE:
454 c26f2460 2023-06-08 op main_configure_done(conf);
463 c26f2460 2023-06-08 op static void __dead
464 c26f2460 2023-06-08 op main_shutdown(struct conf *conf)
466 c26f2460 2023-06-08 op proc_kill(conf->ps);
467 af1dab18 2023-06-09 op config_purge(conf);
468 c26f2460 2023-06-08 op free(conf->ps);
469 c26f2460 2023-06-08 op /* free(conf); */
471 c26f2460 2023-06-08 op log_info("parent terminating, pid %d", getpid());
473 8e8b2e25 2021-04-28 op if (pidfd != -1)
474 8e8b2e25 2021-04-28 op close(pidfd);
480 5af19830 2023-06-09 op main_print_conf(struct conf *conf)
482 5af19830 2023-06-09 op struct vhost *h;
483 5af19830 2023-06-09 op /* struct location *l; */
484 5af19830 2023-06-09 op /* struct envlist *e; */
485 5af19830 2023-06-09 op /* struct alist *a; */
487 5af19830 2023-06-09 op if (*conf->chroot != '\0')
488 5af19830 2023-06-09 op printf("chroot \"%s\"\n", conf->chroot);
489 5af19830 2023-06-09 op printf("ipv6 %s\n", conf->ipv6 ? "on" : "off");
490 5af19830 2023-06-09 op /* XXX: defined mimes? */
491 5af19830 2023-06-09 op printf("port %d\n", conf->port);
492 5af19830 2023-06-09 op printf("prefork %d\n", conf->prefork);
493 5af19830 2023-06-09 op /* XXX: protocols? */
494 5af19830 2023-06-09 op if (*conf->user != '\0')
495 5af19830 2023-06-09 op printf("user \"%s\"\n", conf->user);
497 5af19830 2023-06-09 op TAILQ_FOREACH(h, &conf->hosts, vhosts) {
498 5af19830 2023-06-09 op printf("\nserver \"%s\" {\n", h->domain);
499 5af19830 2023-06-09 op printf(" cert \"%s\"\n", h->cert);
500 5af19830 2023-06-09 op printf(" key \"%s\"\n", h->key);
501 5af19830 2023-06-09 op /* TODO: print locations... */
502 5af19830 2023-06-09 op printf("}\n");