Blame


1 3e4749f7 2020-10-02 op .\" Copyright (c) 2020 Omar Polo <op@omarpolo.com>
2 3e4749f7 2020-10-02 op .\"
3 3e4749f7 2020-10-02 op .\" Permission to use, copy, modify, and distribute this software for any
4 3e4749f7 2020-10-02 op .\" purpose with or without fee is hereby granted, provided that the above
5 3e4749f7 2020-10-02 op .\" copyright notice and this permission notice appear in all copies.
6 3e4749f7 2020-10-02 op .\"
7 3e4749f7 2020-10-02 op .\" THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
8 3e4749f7 2020-10-02 op .\" WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
9 3e4749f7 2020-10-02 op .\" MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
10 3e4749f7 2020-10-02 op .\" ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
11 3e4749f7 2020-10-02 op .\" WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
12 3e4749f7 2020-10-02 op .\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
13 3e4749f7 2020-10-02 op .\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
14 3e4749f7 2020-10-02 op .Dd $Mdocdate: October 2 2020$
15 3e4749f7 2020-10-02 op .Dt GMIND 1
16 3e4749f7 2020-10-02 op .Os
17 3e4749f7 2020-10-02 op .Sh NAME
18 3e4749f7 2020-10-02 op .Nm gmid
19 fab952e1 2020-10-03 op .Nd dead simple zero configuration gemini server
20 3e4749f7 2020-10-02 op .Sh SYNOPSIS
21 3e4749f7 2020-10-02 op .Nm
22 3e4749f7 2020-10-02 op .Bk -words
23 85dff1f9 2021-01-11 op .Op Fl 6fh
24 3e4749f7 2020-10-02 op .Op Fl c Ar cert.pem
25 3e4749f7 2020-10-02 op .Op Fl d Ar docs
26 3e4749f7 2020-10-02 op .Op Fl k Ar key.pem
27 721e2325 2020-11-18 op .Op Fl p Ar port
28 0ed56567 2020-11-06 op .Op Fl x Ar cgi-bin
29 3e4749f7 2020-10-02 op .Ek
30 3e4749f7 2020-10-02 op .Sh DESCRIPTION
31 3e4749f7 2020-10-02 op .Nm
32 b9220ca4 2021-01-11 op is a simple and minimal gemini server that can serve static files and
33 b9220ca4 2021-01-11 op execute CGI scripts.
34 3e4749f7 2020-10-02 op .Pp
35 3e4749f7 2020-10-02 op .Nm
36 df6ca41d 2020-12-25 op won't serve files outside the given directory and won't follow
37 df6ca41d 2020-12-25 op symlinks.
38 6980aad6 2020-10-02 op Furthermore, on
39 6980aad6 2020-10-02 op .Ox ,
40 6980aad6 2020-10-02 op .Xr pledge 2
41 3e4749f7 2020-10-02 op and
42 6980aad6 2020-10-02 op .Xr unveil 2
43 3e4749f7 2020-10-02 op are used to ensure that
44 3e4749f7 2020-10-02 op .Nm
45 0ed56567 2020-11-06 op dosen't do anything else than read files from the given directory,
46 0ed56567 2020-11-06 op accept network connections and, optionally, execute CGI scripts.
47 3e4749f7 2020-10-02 op .Pp
48 df6ca41d 2020-12-25 op .Nm
49 df6ca41d 2020-12-25 op fully supports IRIs (Internationalized Resource Identifiers, see
50 df6ca41d 2020-12-25 op RFC3987).
51 df6ca41d 2020-12-25 op .Pp
52 3e4749f7 2020-10-02 op It should be noted that
53 3e4749f7 2020-10-02 op .Nm
54 3e4749f7 2020-10-02 op is very simple in its implementation, and so it may not be appropriate
55 0ed56567 2020-11-06 op for serving sites with lots of users.
56 0ed56567 2020-11-06 op After all, the code is single threaded and use a single process,
57 83000e2d 2020-12-21 op although it can handle multiple clients at the same time.
58 3e4749f7 2020-10-02 op .Pp
59 fab952e1 2020-10-03 op If a user request path is a directory,
60 fab952e1 2020-10-03 op .Nm
61 fab952e1 2020-10-03 op will try to serve a
62 fab952e1 2020-10-03 op .Pa index.gmi
63 fab952e1 2020-10-03 op file inside that directory.
64 fab952e1 2020-10-03 op .Pp
65 3e4749f7 2020-10-02 op The options are as follows:
66 3e4749f7 2020-10-02 op .Bl -tag -width 12m
67 85dff1f9 2021-01-11 op .It Fl 6
68 85dff1f9 2021-01-11 op Enable IPv6.
69 3e4749f7 2020-10-02 op .It Fl c Ar cert.pem
70 3e4749f7 2020-10-02 op The certificate to use, by default is
71 fab952e1 2020-10-03 op .Pa cert.pem .
72 3e4749f7 2020-10-02 op .It Fl d Ar docs
73 3e4749f7 2020-10-02 op The root directory to serve.
74 3e4749f7 2020-10-02 op .Nm
75 a5d310bc 2020-11-10 op won't serve any file that is outside that directory.
76 a5d310bc 2020-11-10 op By default is
77 0ed56567 2020-11-06 op .Pa docs .
78 d7802bb4 2020-12-02 op .It Fl f
79 d7802bb4 2020-12-02 op stays and log in the foreground, do not daemonize the process.
80 3e4749f7 2020-10-02 op .It Fl h
81 fab952e1 2020-10-03 op Print the usage and exit.
82 3e4749f7 2020-10-02 op .It Fl k Ar key.pem
83 3e4749f7 2020-10-02 op The key for the certificate, by default is
84 fab952e1 2020-10-03 op .Pa key.pem .
85 721e2325 2020-11-18 op .It Fl p Ar port
86 721e2325 2020-11-18 op The port to bind to, by default 1965.
87 0ed56567 2020-11-06 op .It Fl x Ar dir
88 0ed56567 2020-11-06 op Enable execution of CGI scripts inside the given directory (relative
89 0ed56567 2020-11-06 op to the document root.) Cannot be provided more than once.
90 3e4749f7 2020-10-02 op .El
91 72342dc9 2020-11-06 op .Sh CGI
92 0ed56567 2020-11-06 op When CGI scripts are enabled for a directory, a request for an
93 0ed56567 2020-11-06 op executable file will execute it and fed its output to the client.
94 72342dc9 2020-11-06 op .Pp
95 0ed56567 2020-11-06 op The CGI scripts will inherit the environment from
96 0ed56567 2020-11-06 op .Nm
97 0ed56567 2020-11-06 op with these additional variables set:
98 a5d310bc 2020-11-10 op .Bl -tag -width 18m
99 0ed56567 2020-11-06 op .It Ev SERVER_SOFTWARE
100 0ed56567 2020-11-06 op "gmid"
101 0ed56567 2020-11-06 op .It Ev SERVER_PORT
102 0ed56567 2020-11-06 op "1965"
103 a5d310bc 2020-11-10 op .It Ev SCRIPT_NAME
104 a5d310bc 2020-11-10 op The (public) path to the script.
105 a5d310bc 2020-11-10 op .It Ev SCRIPT_EXECUTABLE
106 a5d310bc 2020-11-10 op The full path to the executable.
107 a5d310bc 2020-11-10 op .It Ev REQUEST_URI
108 a5d310bc 2020-11-10 op The user request (without the query parameters.)
109 a5d310bc 2020-11-10 op .It Ev REQUEST_RELATIVE
110 a5d310bc 2020-11-10 op The request relative to the script.
111 0ed56567 2020-11-06 op .It Ev QUERY_STRING
112 a5d310bc 2020-11-10 op The query parameters.
113 a5d310bc 2020-11-10 op .It Ev REMOTE_HOST
114 a5d310bc 2020-11-10 op The remote IP address.
115 677afbd3 2020-12-02 op .It Ev REMOTE_ADDR
116 677afbd3 2020-12-02 op The remote IP address.
117 a5d310bc 2020-11-10 op .It Ev DOCUMENT_ROOT
118 a5d310bc 2020-11-10 op The root directory being served, the one provided with the
119 a5d310bc 2020-11-10 op .Ar d
120 a5d310bc 2020-11-10 op parameter to
121 a5d310bc 2020-11-10 op .Nm
122 677afbd3 2020-12-02 op .It Ev AUTH_TYPE
123 677afbd3 2020-12-02 op The string "Certificate" if the client used a certificate, otherwise unset.
124 677afbd3 2020-12-02 op .It Ev REMOTE_USER
125 677afbd3 2020-12-02 op The subject of the client certificate if provided, otherwise unset.
126 677afbd3 2020-12-02 op .It Ev TLS_CLIENT_ISSUER
127 677afbd3 2020-12-02 op The is the issuer of the client certificate if provided, otherwise unset.
128 677afbd3 2020-12-02 op .It Ev TLS_CLIENT_HASH
129 677afbd3 2020-12-02 op The hash of the client certificate if provided, otherwise unset.
130 677afbd3 2020-12-02 op The format is "ALGO:HASH".
131 0ed56567 2020-11-06 op .El
132 a5d310bc 2020-11-10 op .Pp
133 a5d310bc 2020-11-10 op Let's say you have a script in
134 a5d310bc 2020-11-10 op .Pa /cgi-bin/script
135 a5d310bc 2020-11-10 op and the user request is
136 a5d310bc 2020-11-10 op .Pa /cgi-bin/script/foo/bar?quux .
137 a5d310bc 2020-11-10 op Then
138 a5d310bc 2020-11-10 op .Ev SCRIPT_NAME
139 a5d310bc 2020-11-10 op will be
140 b9220ca4 2021-01-11 op .Pa cgi-bin/script ,
141 a5d310bc 2020-11-10 op .Ev SCRIPT_EXECUTABLE
142 a5d310bc 2020-11-10 op will be
143 a5d310bc 2020-11-10 op .Pa $DOCUMENT_ROOT/cgi-bin/script ,
144 a5d310bc 2020-11-10 op .Ev REQUEST_URI
145 a5d310bc 2020-11-10 op will be
146 b9220ca4 2021-01-11 op .Pa cgi-bin/script/foo/bar ,
147 a5d310bc 2020-11-10 op .Ev REQUEST_RELATIVE
148 a5d310bc 2020-11-10 op will be
149 b9220ca4 2021-01-11 op .Pa foo/bar
150 b9220ca4 2021-01-11 op and
151 a5d310bc 2020-11-10 op .Ev QUERY_STRING
152 a5d310bc 2020-11-10 op will be
153 a5d310bc 2020-11-10 op .Ar quux .
154 3e4749f7 2020-10-02 op .Sh EXAMPLES
155 3e4749f7 2020-10-02 op To quickly getting started
156 6980aad6 2020-10-02 op .Bd -literal -offset indent
157 3e4749f7 2020-10-02 op $ # generate a cert and a key
158 3e4749f7 2020-10-02 op $ openssl req -x509 -newkey rsa:4096 -keyout key.pem \\
159 3e4749f7 2020-10-02 op -out cert.pem -days 365 -nodes
160 3e4749f7 2020-10-02 op $ mkdir docs
161 3e4749f7 2020-10-02 op $ cat <<EOF > docs/index.gmi
162 3e4749f7 2020-10-02 op # Hello world
163 3e4749f7 2020-10-02 op test paragraph...
164 3e4749f7 2020-10-02 op EOF
165 3e4749f7 2020-10-02 op $ gmid -c cert.pem -k key.pem -d docs
166 6980aad6 2020-10-02 op .Ed
167 3e4749f7 2020-10-02 op .Pp
168 0ed56567 2020-11-06 op Now you can visit gemini://localhost/ with your preferred gemini
169 0ed56567 2020-11-06 op client.
170 0ed56567 2020-11-06 op .Pp
171 0ed56567 2020-11-06 op To add some CGI scripts, assuming a setup similar to the previous
172 0ed56567 2020-11-06 op example, you can
173 0ed56567 2020-11-06 op .Bd -literal -offset indent
174 0ed56567 2020-11-06 op $ mkdir docs/cgi-bin
175 0ed56567 2020-11-06 op $ cat <<EOF > docs/cgi-bin/hello-world
176 0ed56567 2020-11-06 op #!/bin/sh
177 0ed56567 2020-11-06 op printf "20 text/plain\\r\\n"
178 0ed56567 2020-11-06 op echo "hello world!"
179 0ed56567 2020-11-06 op EOF
180 0ed56567 2020-11-06 op $ gmid -x cgi-bin
181 0ed56567 2020-11-06 op .Ed
182 0ed56567 2020-11-06 op .Pp
183 0ed56567 2020-11-06 op Note that the argument to the
184 0ed56567 2020-11-06 op .Fl x
185 0ed56567 2020-11-06 op option is
186 0ed56567 2020-11-06 op .Pa cgi-bin
187 0ed56567 2020-11-06 op and not
188 0ed56567 2020-11-06 op .Pa docs/cgi-bin ,
189 a5d310bc 2020-11-10 op since it's relative to the document root.
190 ef04b551 2021-01-09 op .Sh ACKNOWLEDGEMENTS
191 ef04b551 2021-01-09 op .Nm
192 ef04b551 2021-01-09 op uses the "Flexible and Economical" UTF-8 decoder written by
193 ef04b551 2021-01-09 op .An Bjoern Hoehrmann .
194 3e4749f7 2020-10-02 op .Sh CAVEATS
195 3e4749f7 2020-10-02 op .Bl -bullet
196 3e4749f7 2020-10-02 op .It
197 fab952e1 2020-10-03 op it doesn't support virtual hosts: the host part of the request URL is
198 3e4749f7 2020-10-02 op completely ignored.
199 043acc97 2020-12-25 op .It
200 043acc97 2020-12-25 op a %2F sequence in the path part is indistinguishable from a literal
201 043acc97 2020-12-25 op slash: this is not RFC3986-compliant.
202 00781742 2020-12-25 op .It
203 00781742 2020-12-25 op a %00 sequence either in the path or in the query part is treated as
204 00781742 2020-12-25 op invalid character and thus rejected.
205 3e4749f7 2020-10-02 op .El