2 881a9dd9 2021-01-16 op * Copyright (c) 2021 Omar Polo <op@omarpolo.com>
4 881a9dd9 2021-01-16 op * Permission to use, copy, modify, and distribute this software for any
5 881a9dd9 2021-01-16 op * purpose with or without fee is hereby granted, provided that the above
6 881a9dd9 2021-01-16 op * copyright notice and this permission notice appear in all copies.
8 881a9dd9 2021-01-16 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 881a9dd9 2021-01-16 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 881a9dd9 2021-01-16 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 881a9dd9 2021-01-16 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 881a9dd9 2021-01-16 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 881a9dd9 2021-01-16 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 881a9dd9 2021-01-16 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 52418c8d 2021-02-12 op #include "gmid.h"
19 8ad1c570 2021-05-09 op #include <sys/un.h>
21 881a9dd9 2021-01-16 op #include <err.h>
22 881a9dd9 2021-01-16 op #include <errno.h>
24 2c3e53da 2021-03-03 op #include <event.h>
25 881a9dd9 2021-01-16 op #include <fcntl.h>
26 2fafa2d2 2021-02-01 op #include <libgen.h>
27 2fafa2d2 2021-02-01 op #include <limits.h>
28 881a9dd9 2021-01-16 op #include <signal.h>
29 2fafa2d2 2021-02-01 op #include <stdarg.h>
30 881a9dd9 2021-01-16 op #include <string.h>
32 bc99d868 2021-03-19 op static void handle_imsg_cgi_req(struct imsgbuf*, struct imsg*, size_t);
33 8ad1c570 2021-05-09 op static void handle_imsg_fcgi_req(struct imsgbuf*, struct imsg*, size_t);
34 72b033ef 2021-12-29 op static void handle_imsg_conn_req(struct imsgbuf *, struct imsg *, size_t);
35 bc99d868 2021-03-19 op static void handle_imsg_quit(struct imsgbuf*, struct imsg*, size_t);
36 bc99d868 2021-03-19 op static void handle_dispatch_imsg(int, short, void*);
38 bc99d868 2021-03-19 op static imsg_handlerfn *handlers[] = {
39 8ad1c570 2021-05-09 op [IMSG_FCGI_REQ] = handle_imsg_fcgi_req,
40 bc99d868 2021-03-19 op [IMSG_CGI_REQ] = handle_imsg_cgi_req,
41 72b033ef 2021-12-29 op [IMSG_CONN_REQ] = handle_imsg_conn_req,
42 bc99d868 2021-03-19 op [IMSG_QUIT] = handle_imsg_quit,
45 881a9dd9 2021-01-16 op static inline void
46 881a9dd9 2021-01-16 op safe_setenv(const char *name, const char *val)
48 881a9dd9 2021-01-16 op if (val == NULL)
50 881a9dd9 2021-01-16 op setenv(name, val, 1);
54 2fafa2d2 2021-02-01 op xasprintf(const char *fmt, ...)
59 2fafa2d2 2021-02-01 op va_start(ap, fmt);
60 2fafa2d2 2021-02-01 op if (vasprintf(&s, fmt, ap) == -1)
68 9f006a21 2021-02-07 op do_exec(const char *ex, const char *spath, char *query)
70 9f006a21 2021-02-07 op char **argv, buf[PATH_MAX], *sname, *t;
73 3841a369 2021-04-20 op /* restore the default handlers */
74 3841a369 2021-04-20 op signal(SIGPIPE, SIG_DFL);
75 3841a369 2021-04-20 op signal(SIGCHLD, SIG_DFL);
76 3841a369 2021-04-20 op signal(SIGHUP, SIG_DFL);
77 3841a369 2021-04-20 op signal(SIGINT, SIG_DFL);
78 3841a369 2021-04-20 op signal(SIGTERM, SIG_DFL);
80 9f006a21 2021-02-07 op strlcpy(buf, spath, sizeof(buf));
81 9f006a21 2021-02-07 op sname = basename(buf);
83 9f006a21 2021-02-07 op if (query == NULL || strchr(query, '=') != NULL) {
84 9f006a21 2021-02-07 op if ((argv = calloc(2, sizeof(char*))) == NULL)
85 9f006a21 2021-02-07 op err(1, "calloc");
86 9f006a21 2021-02-07 op argv[0] = sname;
87 9f006a21 2021-02-07 op execvp(ex, argv);
88 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
93 9f006a21 2021-02-07 op for (t = query ;; t++, n++) {
94 9f006a21 2021-02-07 op if ((t = strchr(t, '+')) == NULL)
98 9f006a21 2021-02-07 op if ((argv = calloc(n+2, sizeof(char*))) == NULL)
99 9f006a21 2021-02-07 op err(1, "calloc");
101 9f006a21 2021-02-07 op argv[0] = sname;
102 9f006a21 2021-02-07 op for (i = 0; i < n; ++i) {
103 9f006a21 2021-02-07 op t = strchr(query, '+');
104 9f006a21 2021-02-07 op if (t != NULL)
106 9f006a21 2021-02-07 op argv[i+1] = pct_decode_str(query);
110 9f006a21 2021-02-07 op execvp(ex, argv);
111 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
114 b63e30ff 2021-02-07 op static inline void
115 b63e30ff 2021-02-07 op setenv_time(const char *var, time_t t)
117 b63e30ff 2021-02-07 op char timebuf[21];
118 b63e30ff 2021-02-07 op struct tm tminfo;
123 b63e30ff 2021-02-07 op strftime(timebuf, sizeof(timebuf), "%FT%TZ",
124 b63e30ff 2021-02-07 op gmtime_r(&t, &tminfo));
125 b63e30ff 2021-02-07 op setenv(var, timebuf, 1);
128 881a9dd9 2021-01-16 op /* fd or -1 on error */
130 fdea6aa0 2021-04-30 op launch_cgi(struct iri *iri, struct cgireq *req, struct vhost *vhost,
131 fdea6aa0 2021-04-30 op struct location *loc)
133 ea976e87 2021-07-06 op int p[2], errp[2]; /* read end, write end */
135 403c4220 2021-10-02 op if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, p) == -1)
137 403c4220 2021-10-02 op if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, errp) == -1)
140 881a9dd9 2021-01-16 op switch (fork()) {
142 e7c6502b 2021-07-08 op log_err(NULL, "fork failed: %s", strerror(errno));
145 e7c6502b 2021-07-08 op close(errp[0]);
146 e7c6502b 2021-07-08 op close(errp[1]);
149 881a9dd9 2021-01-16 op case 0: { /* child */
150 2fafa2d2 2021-02-01 op char *ex, *pwd;
151 2fafa2d2 2021-02-01 op char iribuf[GEMINI_URL_LEN];
152 2fafa2d2 2021-02-01 op char path[PATH_MAX];
153 9cc630aa 2021-04-28 op struct envlist *e;
156 881a9dd9 2021-01-16 op if (dup2(p[1], 1) == -1)
157 881a9dd9 2021-01-16 op goto childerr;
159 ea976e87 2021-07-06 op close(errp[0]);
160 ea976e87 2021-07-06 op if (dup2(errp[1], 2) == -1)
161 ea976e87 2021-07-06 op goto childerr;
163 fdea6aa0 2021-04-30 op ex = xasprintf("%s/%s", loc->dir, req->spath);
165 2fafa2d2 2021-02-01 op serialize_iri(iri, iribuf, sizeof(iribuf));
167 881a9dd9 2021-01-16 op safe_setenv("GATEWAY_INTERFACE", "CGI/1.1");
168 fdea6aa0 2021-04-30 op safe_setenv("GEMINI_DOCUMENT_ROOT", loc->dir);
169 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_SCRIPT_FILENAME",
170 fdea6aa0 2021-04-30 op xasprintf("%s/%s", loc->dir, req->spath));
171 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL", iribuf);
173 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
174 bc99d868 2021-03-19 op strlcat(path, req->spath, sizeof(path));
175 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL_PATH", path);
177 bc99d868 2021-03-19 op if (*req->relpath != '\0') {
178 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
179 bc99d868 2021-03-19 op strlcat(path, req->relpath, sizeof(path));
180 2fafa2d2 2021-02-01 op safe_setenv("PATH_INFO", path);
182 fdea6aa0 2021-04-30 op strlcpy(path, loc->dir, sizeof(path));
183 2fafa2d2 2021-02-01 op strlcat(path, "/", sizeof(path));
184 bc99d868 2021-03-19 op strlcat(path, req->relpath, sizeof(path));
185 2fafa2d2 2021-02-01 op safe_setenv("PATH_TRANSLATED", path);
188 2fafa2d2 2021-02-01 op safe_setenv("QUERY_STRING", iri->query);
189 bc99d868 2021-03-19 op safe_setenv("REMOTE_ADDR", req->addr);
190 bc99d868 2021-03-19 op safe_setenv("REMOTE_HOST", req->addr);
191 2fafa2d2 2021-02-01 op safe_setenv("REQUEST_METHOD", "");
193 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
194 bc99d868 2021-03-19 op strlcat(path, req->spath, sizeof(path));
195 2fafa2d2 2021-02-01 op safe_setenv("SCRIPT_NAME", path);
197 2fafa2d2 2021-02-01 op safe_setenv("SERVER_NAME", iri->host);
199 2fafa2d2 2021-02-01 op snprintf(path, sizeof(path), "%d", conf.port);
200 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PORT", path);
202 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PROTOCOL", "GEMINI");
203 ce2c9edb 2021-05-15 op safe_setenv("SERVER_SOFTWARE", GMID_VERSION);
205 bc99d868 2021-03-19 op if (*req->subject != '\0')
206 881a9dd9 2021-01-16 op safe_setenv("AUTH_TYPE", "Certificate");
208 3e541809 2021-02-01 op safe_setenv("AUTH_TYPE", "");
210 bc99d868 2021-03-19 op safe_setenv("REMOTE_USER", req->subject);
211 bc99d868 2021-03-19 op safe_setenv("TLS_CLIENT_ISSUER", req->issuer);
212 bc99d868 2021-03-19 op safe_setenv("TLS_CLIENT_HASH", req->hash);
213 89541eee 2021-04-13 op safe_setenv("TLS_VERSION", req->version);
214 89541eee 2021-04-13 op safe_setenv("TLS_CIPHER", req->cipher);
216 89541eee 2021-04-13 op snprintf(path, sizeof(path), "%d", req->cipher_strength);
217 89541eee 2021-04-13 op safe_setenv("TLS_CIPHER_STRENGTH", path);
219 bc99d868 2021-03-19 op setenv_time("TLS_CLIENT_NOT_AFTER", req->notafter);
220 bc99d868 2021-03-19 op setenv_time("TLS_CLIENT_NOT_BEFORE", req->notbefore);
222 9cc630aa 2021-04-28 op TAILQ_FOREACH(e, &vhost->env, envs) {
223 9cc630aa 2021-04-28 op safe_setenv(e->name, e->value);
226 9f006a21 2021-02-07 op strlcpy(path, ex, sizeof(path));
228 2fafa2d2 2021-02-01 op pwd = dirname(path);
229 2fafa2d2 2021-02-01 op if (chdir(pwd)) {
230 2fafa2d2 2021-02-01 op warn("chdir");
231 2fafa2d2 2021-02-01 op goto childerr;
234 bc99d868 2021-03-19 op do_exec(ex, req->spath, iri->query);
235 881a9dd9 2021-01-16 op goto childerr;
240 e7c6502b 2021-07-08 op close(errp[0]);
241 ea976e87 2021-07-06 op close(errp[1]);
242 52053e1a 2021-02-06 op mark_nonblock(p[0]);
247 881a9dd9 2021-01-16 op dprintf(p[1], "%d internal server error\r\n", TEMP_FAILURE);
251 b8e64ccd 2021-03-31 op static struct vhost *
252 b8e64ccd 2021-03-31 op host_nth(size_t n)
254 b8e64ccd 2021-03-31 op struct vhost *h;
256 b8e64ccd 2021-03-31 op TAILQ_FOREACH(h, &hosts, vhosts) {
265 fdea6aa0 2021-04-30 op static struct location *
266 fdea6aa0 2021-04-30 op loc_nth(struct vhost *vhost, size_t n)
268 fdea6aa0 2021-04-30 op struct location *loc;
270 fdea6aa0 2021-04-30 op TAILQ_FOREACH(loc, &vhost->locations, locations) {
280 bc99d868 2021-03-19 op handle_imsg_cgi_req(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
282 b8e64ccd 2021-03-31 op struct vhost *h;
283 fdea6aa0 2021-04-30 op struct location *l;
284 b8e64ccd 2021-03-31 op struct cgireq req;
285 b8e64ccd 2021-03-31 op struct iri iri;
288 bc99d868 2021-03-19 op if (datalen != sizeof(req))
291 6084a9a5 2022-03-27 op memcpy(&req, imsg->data, sizeof(req));
293 bc99d868 2021-03-19 op iri.schema = req.iri_schema_off + req.buf;
294 bc99d868 2021-03-19 op iri.host = req.iri_host_off + req.buf;
295 bc99d868 2021-03-19 op iri.port = req.iri_port_off + req.buf;
296 bc99d868 2021-03-19 op iri.path = req.iri_path_off + req.buf;
297 bc99d868 2021-03-19 op iri.query = req.iri_query_off + req.buf;
298 bc99d868 2021-03-19 op iri.fragment = req.iri_fragment_off + req.buf;
300 bc99d868 2021-03-19 op /* patch the query, otherwise do_exec will always pass "" as
301 bc99d868 2021-03-19 op * first argument to the script. */
302 bc99d868 2021-03-19 op if (*iri.query == '\0')
303 bc99d868 2021-03-19 op iri.query = NULL;
305 b8e64ccd 2021-03-31 op if ((h = host_nth(req.host_off)) == NULL)
308 1feaf2a6 2021-05-15 op if ((l = loc_nth(h, req.loc_off)) == NULL)
311 fdea6aa0 2021-04-30 op fd = launch_cgi(&iri, &req, h, l);
312 bc99d868 2021-03-19 op imsg_compose(ibuf, IMSG_CGI_RES, imsg->hdr.peerid, 0, fd, NULL, 0);
313 bc99d868 2021-03-19 op imsg_flush(ibuf);
317 8ad1c570 2021-05-09 op fcgi_open_prog(struct fcgi *f)
324 2e2e189b 2021-07-08 op if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, s) == -1)
325 8ad1c570 2021-05-09 op err(1, "socketpair");
327 8ad1c570 2021-05-09 op switch (p = fork()) {
329 8ad1c570 2021-05-09 op err(1, "fork");
332 8ad1c570 2021-05-09 op if (dup2(s[1], 0) == -1)
333 8ad1c570 2021-05-09 op err(1, "dup2");
334 8ad1c570 2021-05-09 op execl(f->prog, f->prog, NULL);
335 8ad1c570 2021-05-09 op err(1, "execl %s", f->prog);
343 8ad1c570 2021-05-09 op fcgi_open_sock(struct fcgi *f)
345 8ad1c570 2021-05-09 op struct sockaddr_un addr;
348 8ad1c570 2021-05-09 op if ((fd = socket(AF_UNIX, SOCK_STREAM, 0)) == -1) {
349 8ad1c570 2021-05-09 op log_err(NULL, "socket: %s", strerror(errno));
353 8ad1c570 2021-05-09 op memset(&addr, 0, sizeof(addr));
354 8ad1c570 2021-05-09 op addr.sun_family = AF_UNIX;
355 8ad1c570 2021-05-09 op strlcpy(addr.sun_path, f->path, sizeof(addr.sun_path));
357 8ad1c570 2021-05-09 op if (connect(fd, (struct sockaddr*)&addr, sizeof(addr)) == -1) {
358 8ad1c570 2021-05-09 op log_warn(NULL, "failed to connect to %s: %s", f->path,
359 8ad1c570 2021-05-09 op strerror(errno));
368 8ad1c570 2021-05-09 op fcgi_open_conn(struct fcgi *f)
370 8ad1c570 2021-05-09 op struct addrinfo hints, *servinfo, *p;
373 8ad1c570 2021-05-09 op memset(&hints, 0, sizeof(hints));
374 8ad1c570 2021-05-09 op hints.ai_family = AF_UNSPEC;
375 8ad1c570 2021-05-09 op hints.ai_socktype = SOCK_STREAM;
376 8ad1c570 2021-05-09 op hints.ai_flags = AI_ADDRCONFIG;
378 8ad1c570 2021-05-09 op if ((r = getaddrinfo(f->path, f->port, &hints, &servinfo)) != 0) {
379 8ad1c570 2021-05-09 op log_warn(NULL, "getaddrinfo %s:%s: %s", f->path, f->port,
380 8ad1c570 2021-05-09 op gai_strerror(r));
384 8ad1c570 2021-05-09 op for (p = servinfo; p != NULL; p = p->ai_next) {
385 8ad1c570 2021-05-09 op sock = socket(p->ai_family, p->ai_socktype, p->ai_protocol);
386 8ad1c570 2021-05-09 op if (sock == -1)
388 8ad1c570 2021-05-09 op if (connect(sock, p->ai_addr, p->ai_addrlen) == -1) {
395 8ad1c570 2021-05-09 op if (p == NULL) {
396 8ad1c570 2021-05-09 op log_warn(NULL, "couldn't connect to %s:%s", f->path, f->port);
400 8ad1c570 2021-05-09 op freeaddrinfo(servinfo);
405 8ad1c570 2021-05-09 op handle_imsg_fcgi_req(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
407 8ad1c570 2021-05-09 op struct fcgi *f;
410 8ad1c570 2021-05-09 op if (datalen != sizeof(id))
412 6084a9a5 2022-03-27 op memcpy(&id, imsg->data, sizeof(id));
414 8ad1c570 2021-05-09 op if (id > FCGI_MAX || (fcgi[id].path == NULL && fcgi[id].prog == NULL))
417 8ad1c570 2021-05-09 op f = &fcgi[id];
418 8ad1c570 2021-05-09 op if (f->prog != NULL)
419 8ad1c570 2021-05-09 op fd = fcgi_open_prog(f);
420 8ad1c570 2021-05-09 op else if (f->port != NULL)
421 8ad1c570 2021-05-09 op fd = fcgi_open_conn(f);
423 8ad1c570 2021-05-09 op fd = fcgi_open_sock(f);
425 4cd25209 2021-10-07 op imsg_compose(ibuf, IMSG_FCGI_FD, imsg->hdr.peerid, 0, fd, NULL, 0);
426 72b033ef 2021-12-29 op imsg_flush(ibuf);
430 72b033ef 2021-12-29 op handle_imsg_conn_req(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
432 72b033ef 2021-12-29 op struct addrinfo hints, *res, *res0;
433 72b033ef 2021-12-29 op struct connreq req;
436 72b033ef 2021-12-29 op if (datalen != sizeof(req))
438 72b033ef 2021-12-29 op memcpy(&req, imsg->data, sizeof(req));
439 72b033ef 2021-12-29 op req.flag = 0;
441 72b033ef 2021-12-29 op memset(&hints, 0, sizeof(hints));
442 72b033ef 2021-12-29 op hints.ai_family = AF_UNSPEC;
443 72b033ef 2021-12-29 op hints.ai_socktype = SOCK_STREAM;
445 72b033ef 2021-12-29 op /* XXX: do this asynchronously if possible */
446 72b033ef 2021-12-29 op r = getaddrinfo(req.host, req.port, &hints, &res0);
447 72b033ef 2021-12-29 op if (r != 0) {
448 72b033ef 2021-12-29 op log_warn(NULL, "getaddrinfo(\"%s\", \"%s\"): %s",
449 72b033ef 2021-12-29 op req.host, req.port, gai_strerror(r));
453 72b033ef 2021-12-29 op for (res = res0; res; res = res->ai_next) {
454 72b033ef 2021-12-29 op sock = socket(res->ai_family, res->ai_socktype,
455 72b033ef 2021-12-29 op res->ai_protocol);
456 72b033ef 2021-12-29 op if (sock == -1)
459 72b033ef 2021-12-29 op if (connect(sock, res->ai_addr, res->ai_addrlen) == -1) {
468 72b033ef 2021-12-29 op freeaddrinfo(res0);
470 72b033ef 2021-12-29 op if (sock == -1) {
471 72b033ef 2021-12-29 op log_warn(NULL, "can't connect to %s:%s", req.host,
476 72b033ef 2021-12-29 op imsg_compose(ibuf, IMSG_CONN_FD, imsg->hdr.peerid, 0, sock, NULL, 0);
477 8ad1c570 2021-05-09 op imsg_flush(ibuf);
481 72b033ef 2021-12-29 op imsg_compose(ibuf, IMSG_CONN_FD, imsg->hdr.peerid, 0, -1, NULL, 0);
482 72b033ef 2021-12-29 op imsg_flush(ibuf);
486 bc99d868 2021-03-19 op handle_imsg_quit(struct imsgbuf *ibuf, struct imsg *imsg, size_t datalen)
490 bc99d868 2021-03-19 op for (i = 0; i < conf.prefork; ++i) {
491 bc99d868 2021-03-19 op imsg_compose(&servibuf[i], IMSG_QUIT, 0, 0, -1, NULL, 0);
492 bc99d868 2021-03-19 op imsg_flush(&exibuf);
493 bc99d868 2021-03-19 op close(servibuf[i].fd);
496 bc99d868 2021-03-19 op event_loopbreak();
500 bc99d868 2021-03-19 op handle_dispatch_imsg(int fd, short ev, void *d)
502 bc99d868 2021-03-19 op struct imsgbuf *ibuf = d;
503 bc99d868 2021-03-19 op dispatch_imsg(ibuf, handlers, sizeof(handlers));
507 bc99d868 2021-03-19 op executor_main(struct imsgbuf *ibuf)
509 bc99d868 2021-03-19 op struct event evs[PROC_MAX], imsgev;
512 2c3e53da 2021-03-03 op event_init();
514 bc99d868 2021-03-19 op if (ibuf != NULL) {
515 bc99d868 2021-03-19 op event_set(&imsgev, ibuf->fd, EV_READ | EV_PERSIST,
516 bc99d868 2021-03-19 op handle_dispatch_imsg, ibuf);
517 bc99d868 2021-03-19 op event_add(&imsgev, NULL);
520 2c3e53da 2021-03-03 op for (i = 0; i < conf.prefork; ++i) {
521 bc99d868 2021-03-19 op event_set(&evs[i], servibuf[i].fd, EV_READ | EV_PERSIST,
522 bc99d868 2021-03-19 op handle_dispatch_imsg, &servibuf[i]);
523 2c3e53da 2021-03-03 op event_add(&evs[i], NULL);
526 62e001b0 2021-03-20 op sandbox_executor_process();
528 2c3e53da 2021-03-03 op event_dispatch();