2 881a9dd9 2021-01-16 op * Copyright (c) 2021 Omar Polo <op@omarpolo.com>
4 881a9dd9 2021-01-16 op * Permission to use, copy, modify, and distribute this software for any
5 881a9dd9 2021-01-16 op * purpose with or without fee is hereby granted, provided that the above
6 881a9dd9 2021-01-16 op * copyright notice and this permission notice appear in all copies.
8 881a9dd9 2021-01-16 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 881a9dd9 2021-01-16 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 881a9dd9 2021-01-16 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 881a9dd9 2021-01-16 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 881a9dd9 2021-01-16 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 881a9dd9 2021-01-16 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 881a9dd9 2021-01-16 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 52418c8d 2021-02-12 op #include "gmid.h"
19 881a9dd9 2021-01-16 op #include <err.h>
20 881a9dd9 2021-01-16 op #include <errno.h>
22 2c3e53da 2021-03-03 op #include <event.h>
23 881a9dd9 2021-01-16 op #include <fcntl.h>
24 2fafa2d2 2021-02-01 op #include <libgen.h>
25 2fafa2d2 2021-02-01 op #include <limits.h>
26 881a9dd9 2021-01-16 op #include <signal.h>
27 2fafa2d2 2021-02-01 op #include <stdarg.h>
28 881a9dd9 2021-01-16 op #include <string.h>
30 bc99d868 2021-03-19 op static void handle_imsg_cgi_req(struct imsgbuf*, struct imsg*, size_t);
31 bc99d868 2021-03-19 op static void handle_imsg_quit(struct imsgbuf*, struct imsg*, size_t);
32 bc99d868 2021-03-19 op static void handle_dispatch_imsg(int, short, void*);
34 bc99d868 2021-03-19 op static imsg_handlerfn *handlers[] = {
35 bc99d868 2021-03-19 op [IMSG_CGI_REQ] = handle_imsg_cgi_req,
36 bc99d868 2021-03-19 op [IMSG_QUIT] = handle_imsg_quit,
39 881a9dd9 2021-01-16 op static inline void
40 881a9dd9 2021-01-16 op safe_setenv(const char *name, const char *val)
42 881a9dd9 2021-01-16 op if (val == NULL)
44 881a9dd9 2021-01-16 op setenv(name, val, 1);
48 2fafa2d2 2021-02-01 op xasprintf(const char *fmt, ...)
53 2fafa2d2 2021-02-01 op va_start(ap, fmt);
54 2fafa2d2 2021-02-01 op if (vasprintf(&s, fmt, ap) == -1)
62 9f006a21 2021-02-07 op do_exec(const char *ex, const char *spath, char *query)
64 9f006a21 2021-02-07 op char **argv, buf[PATH_MAX], *sname, *t;
67 9f006a21 2021-02-07 op strlcpy(buf, spath, sizeof(buf));
68 9f006a21 2021-02-07 op sname = basename(buf);
70 9f006a21 2021-02-07 op if (query == NULL || strchr(query, '=') != NULL) {
71 9f006a21 2021-02-07 op if ((argv = calloc(2, sizeof(char*))) == NULL)
72 9f006a21 2021-02-07 op err(1, "calloc");
73 9f006a21 2021-02-07 op argv[0] = sname;
74 9f006a21 2021-02-07 op execvp(ex, argv);
75 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
80 9f006a21 2021-02-07 op for (t = query ;; t++, n++) {
81 9f006a21 2021-02-07 op if ((t = strchr(t, '+')) == NULL)
85 9f006a21 2021-02-07 op if ((argv = calloc(n+2, sizeof(char*))) == NULL)
86 9f006a21 2021-02-07 op err(1, "calloc");
88 9f006a21 2021-02-07 op argv[0] = sname;
89 9f006a21 2021-02-07 op for (i = 0; i < n; ++i) {
90 9f006a21 2021-02-07 op t = strchr(query, '+');
91 9f006a21 2021-02-07 op if (t != NULL)
93 9f006a21 2021-02-07 op argv[i+1] = pct_decode_str(query);
97 9f006a21 2021-02-07 op execvp(ex, argv);
98 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
101 b63e30ff 2021-02-07 op static inline void
102 b63e30ff 2021-02-07 op setenv_time(const char *var, time_t t)
104 b63e30ff 2021-02-07 op char timebuf[21];
105 b63e30ff 2021-02-07 op struct tm tminfo;
110 b63e30ff 2021-02-07 op strftime(timebuf, sizeof(timebuf), "%FT%TZ",
111 b63e30ff 2021-02-07 op gmtime_r(&t, &tminfo));
112 b63e30ff 2021-02-07 op setenv(var, timebuf, 1);
115 881a9dd9 2021-01-16 op /* fd or -1 on error */
117 bc99d868 2021-03-19 op launch_cgi(struct iri *iri, struct cgireq *req, struct vhost *vhost)
119 881a9dd9 2021-01-16 op int p[2]; /* read end, write end */
121 52053e1a 2021-02-06 op if (pipe(p) == -1)
124 881a9dd9 2021-01-16 op switch (fork()) {
128 881a9dd9 2021-01-16 op case 0: { /* child */
129 2fafa2d2 2021-02-01 op char *ex, *pwd;
130 2fafa2d2 2021-02-01 op char iribuf[GEMINI_URL_LEN];
131 2fafa2d2 2021-02-01 op char path[PATH_MAX];
134 881a9dd9 2021-01-16 op if (dup2(p[1], 1) == -1)
135 881a9dd9 2021-01-16 op goto childerr;
137 bc99d868 2021-03-19 op ex = xasprintf("%s/%s", vhost->dir, req->spath);
139 2fafa2d2 2021-02-01 op serialize_iri(iri, iribuf, sizeof(iribuf));
141 881a9dd9 2021-01-16 op safe_setenv("GATEWAY_INTERFACE", "CGI/1.1");
142 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_DOCUMENT_ROOT", vhost->dir);
143 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_SCRIPT_FILENAME",
144 bc99d868 2021-03-19 op xasprintf("%s/%s", vhost->dir, req->spath));
145 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL", iribuf);
147 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
148 bc99d868 2021-03-19 op strlcat(path, req->spath, sizeof(path));
149 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL_PATH", path);
151 bc99d868 2021-03-19 op if (*req->relpath != '\0') {
152 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
153 bc99d868 2021-03-19 op strlcat(path, req->relpath, sizeof(path));
154 2fafa2d2 2021-02-01 op safe_setenv("PATH_INFO", path);
156 2fafa2d2 2021-02-01 op strlcpy(path, vhost->dir, sizeof(path));
157 2fafa2d2 2021-02-01 op strlcat(path, "/", sizeof(path));
158 bc99d868 2021-03-19 op strlcat(path, req->relpath, sizeof(path));
159 2fafa2d2 2021-02-01 op safe_setenv("PATH_TRANSLATED", path);
162 2fafa2d2 2021-02-01 op safe_setenv("QUERY_STRING", iri->query);
163 bc99d868 2021-03-19 op safe_setenv("REMOTE_ADDR", req->addr);
164 bc99d868 2021-03-19 op safe_setenv("REMOTE_HOST", req->addr);
165 2fafa2d2 2021-02-01 op safe_setenv("REQUEST_METHOD", "");
167 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
168 bc99d868 2021-03-19 op strlcat(path, req->spath, sizeof(path));
169 2fafa2d2 2021-02-01 op safe_setenv("SCRIPT_NAME", path);
171 2fafa2d2 2021-02-01 op safe_setenv("SERVER_NAME", iri->host);
173 2fafa2d2 2021-02-01 op snprintf(path, sizeof(path), "%d", conf.port);
174 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PORT", path);
176 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PROTOCOL", "GEMINI");
177 c8249bad 2021-03-20 op safe_setenv("SERVER_SOFTWARE", "gmid/1.6");
179 bc99d868 2021-03-19 op if (*req->subject != '\0')
180 881a9dd9 2021-01-16 op safe_setenv("AUTH_TYPE", "Certificate");
182 3e541809 2021-02-01 op safe_setenv("AUTH_TYPE", "");
184 bc99d868 2021-03-19 op safe_setenv("REMOTE_USER", req->subject);
185 bc99d868 2021-03-19 op safe_setenv("TLS_CLIENT_ISSUER", req->issuer);
186 bc99d868 2021-03-19 op safe_setenv("TLS_CLIENT_HASH", req->hash);
187 bc99d868 2021-03-19 op setenv_time("TLS_CLIENT_NOT_AFTER", req->notafter);
188 bc99d868 2021-03-19 op setenv_time("TLS_CLIENT_NOT_BEFORE", req->notbefore);
190 9f006a21 2021-02-07 op strlcpy(path, ex, sizeof(path));
192 2fafa2d2 2021-02-01 op pwd = dirname(path);
193 2fafa2d2 2021-02-01 op if (chdir(pwd)) {
194 2fafa2d2 2021-02-01 op warn("chdir");
195 2fafa2d2 2021-02-01 op goto childerr;
198 bc99d868 2021-03-19 op do_exec(ex, req->spath, iri->query);
199 881a9dd9 2021-01-16 op goto childerr;
204 52053e1a 2021-02-06 op mark_nonblock(p[0]);
209 881a9dd9 2021-01-16 op dprintf(p[1], "%d internal server error\r\n", TEMP_FAILURE);
214 bc99d868 2021-03-19 op handle_imsg_cgi_req(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
216 bc99d868 2021-03-19 op struct cgireq req;
217 bc99d868 2021-03-19 op struct iri iri;
220 bc99d868 2021-03-19 op if (datalen != sizeof(req))
223 bc99d868 2021-03-19 op memcpy(&req, imsg->data, datalen);
225 bc99d868 2021-03-19 op iri.schema = req.iri_schema_off + req.buf;
226 bc99d868 2021-03-19 op iri.host = req.iri_host_off + req.buf;
227 bc99d868 2021-03-19 op iri.port = req.iri_port_off + req.buf;
228 bc99d868 2021-03-19 op iri.path = req.iri_path_off + req.buf;
229 bc99d868 2021-03-19 op iri.query = req.iri_query_off + req.buf;
230 bc99d868 2021-03-19 op iri.fragment = req.iri_fragment_off + req.buf;
232 bc99d868 2021-03-19 op /* patch the query, otherwise do_exec will always pass "" as
233 bc99d868 2021-03-19 op * first argument to the script. */
234 bc99d868 2021-03-19 op if (*iri.query == '\0')
235 bc99d868 2021-03-19 op iri.query = NULL;
237 bc99d868 2021-03-19 op if (req.host_off > HOSTSLEN || hosts[req.host_off].domain == NULL)
240 bc99d868 2021-03-19 op fd = launch_cgi(&iri, &req, &hosts[req.host_off]);
241 bc99d868 2021-03-19 op imsg_compose(ibuf, IMSG_CGI_RES, imsg->hdr.peerid, 0, fd, NULL, 0);
242 bc99d868 2021-03-19 op imsg_flush(ibuf);
246 bc99d868 2021-03-19 op handle_imsg_quit(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
252 bc99d868 2021-03-19 op (void)datalen;
254 bc99d868 2021-03-19 op for (i = 0; i < conf.prefork; ++i) {
255 bc99d868 2021-03-19 op imsg_compose(&servibuf[i], IMSG_QUIT, 0, 0, -1, NULL, 0);
256 bc99d868 2021-03-19 op imsg_flush(&exibuf);
257 bc99d868 2021-03-19 op close(servibuf[i].fd);
260 bc99d868 2021-03-19 op event_loopbreak();
264 bc99d868 2021-03-19 op handle_dispatch_imsg(int fd, short ev, void *d)
266 bc99d868 2021-03-19 op struct imsgbuf *ibuf = d;
267 bc99d868 2021-03-19 op dispatch_imsg(ibuf, handlers, sizeof(handlers));
271 bc99d868 2021-03-19 op executor_main(struct imsgbuf *ibuf)
273 bc99d868 2021-03-19 op struct event evs[PROC_MAX], imsgev;
276 2c3e53da 2021-03-03 op event_init();
278 bc99d868 2021-03-19 op if (ibuf != NULL) {
279 bc99d868 2021-03-19 op event_set(&imsgev, ibuf->fd, EV_READ | EV_PERSIST,
280 bc99d868 2021-03-19 op handle_dispatch_imsg, ibuf);
281 bc99d868 2021-03-19 op event_add(&imsgev, NULL);
284 2c3e53da 2021-03-03 op for (i = 0; i < conf.prefork; ++i) {
285 bc99d868 2021-03-19 op event_set(&evs[i], servibuf[i].fd, EV_READ | EV_PERSIST,
286 bc99d868 2021-03-19 op handle_dispatch_imsg, &servibuf[i]);
287 2c3e53da 2021-03-03 op event_add(&evs[i], NULL);
290 62e001b0 2021-03-20 op sandbox_executor_process();
292 2c3e53da 2021-03-03 op event_dispatch();