Blame


1 881a9dd9 2021-01-16 op /*
2 881a9dd9 2021-01-16 op * Copyright (c) 2021 Omar Polo <op@omarpolo.com>
3 881a9dd9 2021-01-16 op *
4 881a9dd9 2021-01-16 op * Permission to use, copy, modify, and distribute this software for any
5 881a9dd9 2021-01-16 op * purpose with or without fee is hereby granted, provided that the above
6 881a9dd9 2021-01-16 op * copyright notice and this permission notice appear in all copies.
7 881a9dd9 2021-01-16 op *
8 881a9dd9 2021-01-16 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 881a9dd9 2021-01-16 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 881a9dd9 2021-01-16 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 881a9dd9 2021-01-16 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 881a9dd9 2021-01-16 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 881a9dd9 2021-01-16 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 881a9dd9 2021-01-16 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15 881a9dd9 2021-01-16 op */
16 52418c8d 2021-02-12 op
17 52418c8d 2021-02-12 op #include "gmid.h"
18 881a9dd9 2021-01-16 op
19 881a9dd9 2021-01-16 op #include <err.h>
20 881a9dd9 2021-01-16 op #include <errno.h>
21 881a9dd9 2021-01-16 op
22 2c3e53da 2021-03-03 op #include <event.h>
23 881a9dd9 2021-01-16 op #include <fcntl.h>
24 2fafa2d2 2021-02-01 op #include <libgen.h>
25 2fafa2d2 2021-02-01 op #include <limits.h>
26 881a9dd9 2021-01-16 op #include <signal.h>
27 2fafa2d2 2021-02-01 op #include <stdarg.h>
28 881a9dd9 2021-01-16 op #include <string.h>
29 881a9dd9 2021-01-16 op
30 881a9dd9 2021-01-16 op int
31 881a9dd9 2021-01-16 op send_string(int fd, const char *str)
32 881a9dd9 2021-01-16 op {
33 881a9dd9 2021-01-16 op ssize_t len;
34 881a9dd9 2021-01-16 op
35 881a9dd9 2021-01-16 op if (str == NULL)
36 881a9dd9 2021-01-16 op len = 0;
37 881a9dd9 2021-01-16 op else
38 881a9dd9 2021-01-16 op len = strlen(str);
39 881a9dd9 2021-01-16 op
40 881a9dd9 2021-01-16 op if (write(fd, &len, sizeof(len)) != sizeof(len))
41 881a9dd9 2021-01-16 op return 0;
42 881a9dd9 2021-01-16 op
43 881a9dd9 2021-01-16 op if (len != 0)
44 881a9dd9 2021-01-16 op if (write(fd, str, len) != len)
45 881a9dd9 2021-01-16 op return 0;
46 881a9dd9 2021-01-16 op
47 881a9dd9 2021-01-16 op return 1;
48 881a9dd9 2021-01-16 op }
49 881a9dd9 2021-01-16 op
50 881a9dd9 2021-01-16 op int
51 881a9dd9 2021-01-16 op recv_string(int fd, char **ret)
52 881a9dd9 2021-01-16 op {
53 881a9dd9 2021-01-16 op ssize_t len;
54 881a9dd9 2021-01-16 op
55 881a9dd9 2021-01-16 op if (read(fd, &len, sizeof(len)) != sizeof(len))
56 881a9dd9 2021-01-16 op return 0;
57 881a9dd9 2021-01-16 op
58 881a9dd9 2021-01-16 op if (len == 0) {
59 881a9dd9 2021-01-16 op *ret = NULL;
60 881a9dd9 2021-01-16 op return 1;
61 881a9dd9 2021-01-16 op }
62 881a9dd9 2021-01-16 op
63 881a9dd9 2021-01-16 op if ((*ret = calloc(1, len+1)) == NULL)
64 881a9dd9 2021-01-16 op return 0;
65 881a9dd9 2021-01-16 op
66 881a9dd9 2021-01-16 op if (read(fd, *ret, len) != len)
67 881a9dd9 2021-01-16 op return 0;
68 881a9dd9 2021-01-16 op return 1;
69 881a9dd9 2021-01-16 op }
70 881a9dd9 2021-01-16 op
71 881a9dd9 2021-01-16 op int
72 2fafa2d2 2021-02-01 op send_iri(int fd, struct iri *i)
73 2fafa2d2 2021-02-01 op {
74 2fafa2d2 2021-02-01 op return send_string(fd, i->schema)
75 2fafa2d2 2021-02-01 op && send_string(fd, i->host)
76 2fafa2d2 2021-02-01 op && send_string(fd, i->port)
77 2fafa2d2 2021-02-01 op && send_string(fd, i->path)
78 2fafa2d2 2021-02-01 op && send_string(fd, i->query);
79 2fafa2d2 2021-02-01 op }
80 2fafa2d2 2021-02-01 op
81 2fafa2d2 2021-02-01 op int
82 2fafa2d2 2021-02-01 op recv_iri(int fd, struct iri *i)
83 2fafa2d2 2021-02-01 op {
84 2fafa2d2 2021-02-01 op memset(i, 0, sizeof(*i));
85 2fafa2d2 2021-02-01 op
86 2fafa2d2 2021-02-01 op if (!recv_string(fd, &i->schema)
87 2fafa2d2 2021-02-01 op || !recv_string(fd, &i->host)
88 2fafa2d2 2021-02-01 op || !recv_string(fd, &i->port)
89 2fafa2d2 2021-02-01 op || !recv_string(fd, &i->path)
90 2fafa2d2 2021-02-01 op || !recv_string(fd, &i->query))
91 2fafa2d2 2021-02-01 op return 0;
92 2fafa2d2 2021-02-01 op
93 2fafa2d2 2021-02-01 op return 1;
94 2fafa2d2 2021-02-01 op }
95 2fafa2d2 2021-02-01 op
96 2fafa2d2 2021-02-01 op void
97 2fafa2d2 2021-02-01 op free_recvd_iri(struct iri *i)
98 2fafa2d2 2021-02-01 op {
99 2fafa2d2 2021-02-01 op free(i->schema);
100 2fafa2d2 2021-02-01 op free(i->host);
101 2fafa2d2 2021-02-01 op free(i->port);
102 2fafa2d2 2021-02-01 op free(i->path);
103 2fafa2d2 2021-02-01 op free(i->query);
104 2fafa2d2 2021-02-01 op }
105 2fafa2d2 2021-02-01 op
106 2fafa2d2 2021-02-01 op int
107 881a9dd9 2021-01-16 op send_vhost(int fd, struct vhost *vhost)
108 881a9dd9 2021-01-16 op {
109 881a9dd9 2021-01-16 op ssize_t n;
110 881a9dd9 2021-01-16 op
111 881a9dd9 2021-01-16 op if (vhost < hosts || vhost > hosts + HOSTSLEN)
112 881a9dd9 2021-01-16 op return 0;
113 881a9dd9 2021-01-16 op
114 78089786 2021-02-01 op n = vhost - hosts;
115 881a9dd9 2021-01-16 op return write(fd, &n, sizeof(n)) == sizeof(n);
116 881a9dd9 2021-01-16 op }
117 881a9dd9 2021-01-16 op
118 881a9dd9 2021-01-16 op int
119 881a9dd9 2021-01-16 op recv_vhost(int fd, struct vhost **vhost)
120 881a9dd9 2021-01-16 op {
121 881a9dd9 2021-01-16 op ssize_t n;
122 881a9dd9 2021-01-16 op
123 881a9dd9 2021-01-16 op if (read(fd, &n, sizeof(n)) != sizeof(n))
124 881a9dd9 2021-01-16 op return 0;
125 881a9dd9 2021-01-16 op
126 881a9dd9 2021-01-16 op if (n < 0 || n > HOSTSLEN)
127 881a9dd9 2021-01-16 op return 0;
128 881a9dd9 2021-01-16 op
129 881a9dd9 2021-01-16 op *vhost = &hosts[n];
130 881a9dd9 2021-01-16 op if ((*vhost)->domain == NULL)
131 881a9dd9 2021-01-16 op return 0;
132 881a9dd9 2021-01-16 op return 1;
133 b63e30ff 2021-02-07 op }
134 b63e30ff 2021-02-07 op
135 b63e30ff 2021-02-07 op int
136 b63e30ff 2021-02-07 op send_time(int fd, time_t t)
137 b63e30ff 2021-02-07 op {
138 b63e30ff 2021-02-07 op return write(fd, &t, sizeof(t)) == sizeof(t);
139 b63e30ff 2021-02-07 op }
140 b63e30ff 2021-02-07 op
141 b63e30ff 2021-02-07 op int
142 b63e30ff 2021-02-07 op recv_time(int fd, time_t *t)
143 b63e30ff 2021-02-07 op {
144 b63e30ff 2021-02-07 op return read(fd, t, sizeof(*t)) == sizeof(*t);
145 881a9dd9 2021-01-16 op }
146 881a9dd9 2021-01-16 op
147 881a9dd9 2021-01-16 op /* send d though fd. see /usr/src/usr.sbin/syslogd/privsep_fdpass.c
148 881a9dd9 2021-01-16 op * for an example */
149 881a9dd9 2021-01-16 op int
150 881a9dd9 2021-01-16 op send_fd(int fd, int d)
151 881a9dd9 2021-01-16 op {
152 881a9dd9 2021-01-16 op struct msghdr msg;
153 881a9dd9 2021-01-16 op union {
154 881a9dd9 2021-01-16 op struct cmsghdr hdr;
155 881a9dd9 2021-01-16 op unsigned char buf[CMSG_SPACE(sizeof(int))];
156 881a9dd9 2021-01-16 op } cmsgbuf;
157 881a9dd9 2021-01-16 op struct cmsghdr *cmsg;
158 881a9dd9 2021-01-16 op struct iovec vec;
159 881a9dd9 2021-01-16 op int result = 1;
160 881a9dd9 2021-01-16 op ssize_t n;
161 881a9dd9 2021-01-16 op
162 881a9dd9 2021-01-16 op memset(&msg, 0, sizeof(msg));
163 881a9dd9 2021-01-16 op
164 881a9dd9 2021-01-16 op if (d >= 0) {
165 881a9dd9 2021-01-16 op msg.msg_control = &cmsgbuf.buf;
166 881a9dd9 2021-01-16 op msg.msg_controllen = sizeof(cmsgbuf.buf);
167 881a9dd9 2021-01-16 op cmsg = CMSG_FIRSTHDR(&msg);
168 881a9dd9 2021-01-16 op cmsg->cmsg_len = CMSG_LEN(sizeof(int));
169 881a9dd9 2021-01-16 op cmsg->cmsg_level = SOL_SOCKET;
170 881a9dd9 2021-01-16 op cmsg->cmsg_type = SCM_RIGHTS;
171 881a9dd9 2021-01-16 op *(int*)CMSG_DATA(cmsg) = d;
172 881a9dd9 2021-01-16 op } else
173 881a9dd9 2021-01-16 op result = 0;
174 881a9dd9 2021-01-16 op
175 881a9dd9 2021-01-16 op vec.iov_base = &result;
176 881a9dd9 2021-01-16 op vec.iov_len = sizeof(int);
177 881a9dd9 2021-01-16 op msg.msg_iov = &vec;
178 881a9dd9 2021-01-16 op msg.msg_iovlen = 1;
179 881a9dd9 2021-01-16 op
180 881a9dd9 2021-01-16 op if ((n = sendmsg(fd, &msg, 0)) == -1 || n != sizeof(int)) {
181 a64959c9 2021-02-07 op log_err(NULL, "sendmsg: got %zu but wanted %zu: (errno) %s",
182 881a9dd9 2021-01-16 op n, sizeof(int), strerror(errno));
183 881a9dd9 2021-01-16 op return 0;
184 881a9dd9 2021-01-16 op }
185 881a9dd9 2021-01-16 op return 1;
186 881a9dd9 2021-01-16 op }
187 881a9dd9 2021-01-16 op
188 881a9dd9 2021-01-16 op /* receive a descriptor via fd */
189 881a9dd9 2021-01-16 op int
190 881a9dd9 2021-01-16 op recv_fd(int fd)
191 881a9dd9 2021-01-16 op {
192 881a9dd9 2021-01-16 op struct msghdr msg;
193 881a9dd9 2021-01-16 op union {
194 881a9dd9 2021-01-16 op struct cmsghdr hdr;
195 881a9dd9 2021-01-16 op char buf[CMSG_SPACE(sizeof(int))];
196 881a9dd9 2021-01-16 op } cmsgbuf;
197 881a9dd9 2021-01-16 op struct cmsghdr *cmsg;
198 881a9dd9 2021-01-16 op struct iovec vec;
199 881a9dd9 2021-01-16 op ssize_t n;
200 881a9dd9 2021-01-16 op int result;
201 881a9dd9 2021-01-16 op
202 881a9dd9 2021-01-16 op memset(&msg, 0, sizeof(msg));
203 881a9dd9 2021-01-16 op vec.iov_base = &result;
204 881a9dd9 2021-01-16 op vec.iov_len = sizeof(int);
205 881a9dd9 2021-01-16 op msg.msg_iov = &vec;
206 881a9dd9 2021-01-16 op msg.msg_iovlen = 1;
207 881a9dd9 2021-01-16 op msg.msg_control = &cmsgbuf.buf;
208 881a9dd9 2021-01-16 op msg.msg_controllen = sizeof(cmsgbuf.buf);
209 881a9dd9 2021-01-16 op
210 881a9dd9 2021-01-16 op if ((n = recvmsg(fd, &msg, 0)) != sizeof(int)) {
211 a64959c9 2021-02-07 op log_err(NULL, "read %zu bytes bu wanted %zu\n", n, sizeof(int));
212 881a9dd9 2021-01-16 op return -1;
213 881a9dd9 2021-01-16 op }
214 881a9dd9 2021-01-16 op
215 881a9dd9 2021-01-16 op if (result) {
216 881a9dd9 2021-01-16 op cmsg = CMSG_FIRSTHDR(&msg);
217 881a9dd9 2021-01-16 op if (cmsg == NULL || cmsg->cmsg_type != SCM_RIGHTS)
218 881a9dd9 2021-01-16 op return -1;
219 881a9dd9 2021-01-16 op return (*(int *)CMSG_DATA(cmsg));
220 881a9dd9 2021-01-16 op } else
221 881a9dd9 2021-01-16 op return -1;
222 881a9dd9 2021-01-16 op }
223 881a9dd9 2021-01-16 op
224 881a9dd9 2021-01-16 op static inline void
225 881a9dd9 2021-01-16 op safe_setenv(const char *name, const char *val)
226 881a9dd9 2021-01-16 op {
227 881a9dd9 2021-01-16 op if (val == NULL)
228 881a9dd9 2021-01-16 op val = "";
229 881a9dd9 2021-01-16 op setenv(name, val, 1);
230 881a9dd9 2021-01-16 op }
231 881a9dd9 2021-01-16 op
232 2fafa2d2 2021-02-01 op static char *
233 2fafa2d2 2021-02-01 op xasprintf(const char *fmt, ...)
234 2fafa2d2 2021-02-01 op {
235 2fafa2d2 2021-02-01 op va_list ap;
236 2fafa2d2 2021-02-01 op char *s;
237 2fafa2d2 2021-02-01 op
238 2fafa2d2 2021-02-01 op va_start(ap, fmt);
239 2fafa2d2 2021-02-01 op if (vasprintf(&s, fmt, ap) == -1)
240 2fafa2d2 2021-02-01 op s = NULL;
241 2fafa2d2 2021-02-01 op va_end(ap);
242 2fafa2d2 2021-02-01 op
243 2fafa2d2 2021-02-01 op return s;
244 9f006a21 2021-02-07 op }
245 9f006a21 2021-02-07 op
246 9f006a21 2021-02-07 op static void
247 9f006a21 2021-02-07 op do_exec(const char *ex, const char *spath, char *query)
248 9f006a21 2021-02-07 op {
249 9f006a21 2021-02-07 op char **argv, buf[PATH_MAX], *sname, *t;
250 9f006a21 2021-02-07 op size_t i, n;
251 9f006a21 2021-02-07 op
252 9f006a21 2021-02-07 op strlcpy(buf, spath, sizeof(buf));
253 9f006a21 2021-02-07 op sname = basename(buf);
254 9f006a21 2021-02-07 op
255 9f006a21 2021-02-07 op if (query == NULL || strchr(query, '=') != NULL) {
256 9f006a21 2021-02-07 op if ((argv = calloc(2, sizeof(char*))) == NULL)
257 9f006a21 2021-02-07 op err(1, "calloc");
258 9f006a21 2021-02-07 op argv[0] = sname;
259 9f006a21 2021-02-07 op execvp(ex, argv);
260 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
261 9f006a21 2021-02-07 op return;
262 9f006a21 2021-02-07 op }
263 9f006a21 2021-02-07 op
264 9f006a21 2021-02-07 op n = 1;
265 9f006a21 2021-02-07 op for (t = query ;; t++, n++) {
266 9f006a21 2021-02-07 op if ((t = strchr(t, '+')) == NULL)
267 9f006a21 2021-02-07 op break;
268 9f006a21 2021-02-07 op }
269 9f006a21 2021-02-07 op
270 9f006a21 2021-02-07 op if ((argv = calloc(n+2, sizeof(char*))) == NULL)
271 9f006a21 2021-02-07 op err(1, "calloc");
272 9f006a21 2021-02-07 op
273 9f006a21 2021-02-07 op argv[0] = sname;
274 9f006a21 2021-02-07 op for (i = 0; i < n; ++i) {
275 9f006a21 2021-02-07 op t = strchr(query, '+');
276 9f006a21 2021-02-07 op if (t != NULL)
277 9f006a21 2021-02-07 op *t = '\0';
278 9f006a21 2021-02-07 op argv[i+1] = pct_decode_str(query);
279 9f006a21 2021-02-07 op query = t+1;
280 9f006a21 2021-02-07 op }
281 9f006a21 2021-02-07 op
282 9f006a21 2021-02-07 op execvp(ex, argv);
283 9f006a21 2021-02-07 op warn("execvp: %s", argv[0]);
284 b63e30ff 2021-02-07 op }
285 b63e30ff 2021-02-07 op
286 b63e30ff 2021-02-07 op static inline void
287 b63e30ff 2021-02-07 op setenv_time(const char *var, time_t t)
288 b63e30ff 2021-02-07 op {
289 b63e30ff 2021-02-07 op char timebuf[21];
290 b63e30ff 2021-02-07 op struct tm tminfo;
291 b63e30ff 2021-02-07 op
292 b63e30ff 2021-02-07 op if (t == -1)
293 b63e30ff 2021-02-07 op return;
294 b63e30ff 2021-02-07 op
295 b63e30ff 2021-02-07 op strftime(timebuf, sizeof(timebuf), "%FT%TZ",
296 b63e30ff 2021-02-07 op gmtime_r(&t, &tminfo));
297 b63e30ff 2021-02-07 op setenv(var, timebuf, 1);
298 2fafa2d2 2021-02-01 op }
299 2fafa2d2 2021-02-01 op
300 881a9dd9 2021-01-16 op /* fd or -1 on error */
301 881a9dd9 2021-01-16 op static int
302 2fafa2d2 2021-02-01 op launch_cgi(struct iri *iri, const char *spath, char *relpath,
303 2fafa2d2 2021-02-01 op const char *addr, const char *ruser, const char *cissuer,
304 b63e30ff 2021-02-07 op const char *chash, time_t notbefore, time_t notafter,
305 b63e30ff 2021-02-07 op struct vhost *vhost)
306 881a9dd9 2021-01-16 op {
307 881a9dd9 2021-01-16 op int p[2]; /* read end, write end */
308 881a9dd9 2021-01-16 op
309 52053e1a 2021-02-06 op if (pipe(p) == -1)
310 881a9dd9 2021-01-16 op return -1;
311 881a9dd9 2021-01-16 op
312 881a9dd9 2021-01-16 op switch (fork()) {
313 881a9dd9 2021-01-16 op case -1:
314 881a9dd9 2021-01-16 op return -1;
315 881a9dd9 2021-01-16 op
316 881a9dd9 2021-01-16 op case 0: { /* child */
317 2fafa2d2 2021-02-01 op char *ex, *pwd;
318 2fafa2d2 2021-02-01 op char iribuf[GEMINI_URL_LEN];
319 2fafa2d2 2021-02-01 op char path[PATH_MAX];
320 881a9dd9 2021-01-16 op
321 881a9dd9 2021-01-16 op close(p[0]);
322 881a9dd9 2021-01-16 op if (dup2(p[1], 1) == -1)
323 881a9dd9 2021-01-16 op goto childerr;
324 881a9dd9 2021-01-16 op
325 2fafa2d2 2021-02-01 op ex = xasprintf("%s/%s", vhost->dir, spath);
326 881a9dd9 2021-01-16 op
327 2fafa2d2 2021-02-01 op serialize_iri(iri, iribuf, sizeof(iribuf));
328 881a9dd9 2021-01-16 op
329 881a9dd9 2021-01-16 op safe_setenv("GATEWAY_INTERFACE", "CGI/1.1");
330 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_DOCUMENT_ROOT", vhost->dir);
331 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_SCRIPT_FILENAME",
332 2fafa2d2 2021-02-01 op xasprintf("%s/%s", vhost->dir, spath));
333 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL", iribuf);
334 881a9dd9 2021-01-16 op
335 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
336 2fafa2d2 2021-02-01 op strlcat(path, spath, sizeof(path));
337 2fafa2d2 2021-02-01 op safe_setenv("GEMINI_URL_PATH", path);
338 881a9dd9 2021-01-16 op
339 2fafa2d2 2021-02-01 op if (relpath != NULL) {
340 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
341 2fafa2d2 2021-02-01 op strlcat(path, relpath, sizeof(path));
342 2fafa2d2 2021-02-01 op safe_setenv("PATH_INFO", path);
343 2fafa2d2 2021-02-01 op
344 2fafa2d2 2021-02-01 op strlcpy(path, vhost->dir, sizeof(path));
345 2fafa2d2 2021-02-01 op strlcat(path, "/", sizeof(path));
346 2fafa2d2 2021-02-01 op strlcat(path, relpath, sizeof(path));
347 2fafa2d2 2021-02-01 op safe_setenv("PATH_TRANSLATED", path);
348 2fafa2d2 2021-02-01 op }
349 2fafa2d2 2021-02-01 op
350 2fafa2d2 2021-02-01 op safe_setenv("QUERY_STRING", iri->query);
351 881a9dd9 2021-01-16 op safe_setenv("REMOTE_ADDR", addr);
352 2fafa2d2 2021-02-01 op safe_setenv("REMOTE_HOST", addr);
353 2fafa2d2 2021-02-01 op safe_setenv("REQUEST_METHOD", "");
354 881a9dd9 2021-01-16 op
355 2fafa2d2 2021-02-01 op strlcpy(path, "/", sizeof(path));
356 2fafa2d2 2021-02-01 op strlcat(path, spath, sizeof(path));
357 2fafa2d2 2021-02-01 op safe_setenv("SCRIPT_NAME", path);
358 2fafa2d2 2021-02-01 op
359 2fafa2d2 2021-02-01 op safe_setenv("SERVER_NAME", iri->host);
360 2fafa2d2 2021-02-01 op
361 2fafa2d2 2021-02-01 op snprintf(path, sizeof(path), "%d", conf.port);
362 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PORT", path);
363 2fafa2d2 2021-02-01 op
364 2fafa2d2 2021-02-01 op safe_setenv("SERVER_PROTOCOL", "GEMINI");
365 2fafa2d2 2021-02-01 op safe_setenv("SERVER_SOFTWARE", "gmid/1.5");
366 2fafa2d2 2021-02-01 op
367 3e541809 2021-02-01 op if (ruser != NULL)
368 881a9dd9 2021-01-16 op safe_setenv("AUTH_TYPE", "Certificate");
369 3e541809 2021-02-01 op else
370 3e541809 2021-02-01 op safe_setenv("AUTH_TYPE", "");
371 05748e49 2021-01-24 op
372 3e541809 2021-02-01 op safe_setenv("REMOTE_USER", ruser);
373 3e541809 2021-02-01 op safe_setenv("TLS_CLIENT_ISSUER", cissuer);
374 3e541809 2021-02-01 op safe_setenv("TLS_CLIENT_HASH", chash);
375 b63e30ff 2021-02-07 op setenv_time("TLS_CLIENT_NOT_AFTER", notafter);
376 b63e30ff 2021-02-07 op setenv_time("TLS_CLIENT_NOT_BEFORE", notbefore);
377 3e541809 2021-02-01 op
378 9f006a21 2021-02-07 op strlcpy(path, ex, sizeof(path));
379 9f006a21 2021-02-07 op
380 2fafa2d2 2021-02-01 op pwd = dirname(path);
381 2fafa2d2 2021-02-01 op if (chdir(pwd)) {
382 2fafa2d2 2021-02-01 op warn("chdir");
383 2fafa2d2 2021-02-01 op goto childerr;
384 2fafa2d2 2021-02-01 op }
385 881a9dd9 2021-01-16 op
386 9f006a21 2021-02-07 op do_exec(ex, spath, iri->query);
387 881a9dd9 2021-01-16 op goto childerr;
388 881a9dd9 2021-01-16 op }
389 881a9dd9 2021-01-16 op
390 881a9dd9 2021-01-16 op default:
391 881a9dd9 2021-01-16 op close(p[1]);
392 52053e1a 2021-02-06 op mark_nonblock(p[0]);
393 881a9dd9 2021-01-16 op return p[0];
394 881a9dd9 2021-01-16 op }
395 881a9dd9 2021-01-16 op
396 881a9dd9 2021-01-16 op childerr:
397 881a9dd9 2021-01-16 op dprintf(p[1], "%d internal server error\r\n", TEMP_FAILURE);
398 881a9dd9 2021-01-16 op _exit(1);
399 881a9dd9 2021-01-16 op }
400 881a9dd9 2021-01-16 op
401 2c3e53da 2021-03-03 op static void
402 2c3e53da 2021-03-03 op handle_fork_req(int fd, short ev, void *data)
403 881a9dd9 2021-01-16 op {
404 2fafa2d2 2021-02-01 op char *spath, *relpath, *addr, *ruser, *cissuer, *chash;
405 2c3e53da 2021-03-03 op struct vhost *vhost;
406 2fafa2d2 2021-02-01 op struct iri iri;
407 b63e30ff 2021-02-07 op time_t notbefore, notafter;
408 881a9dd9 2021-01-16 op int d;
409 2c3e53da 2021-03-03 op
410 2c3e53da 2021-03-03 op if (!recv_iri(fd, &iri)
411 2c3e53da 2021-03-03 op || !recv_string(fd, &spath)
412 2c3e53da 2021-03-03 op || !recv_string(fd, &relpath)
413 2c3e53da 2021-03-03 op || !recv_string(fd, &addr)
414 2c3e53da 2021-03-03 op || !recv_string(fd, &ruser)
415 2c3e53da 2021-03-03 op || !recv_string(fd, &cissuer)
416 2c3e53da 2021-03-03 op || !recv_string(fd, &chash)
417 2c3e53da 2021-03-03 op || !recv_time(fd, &notbefore)
418 2c3e53da 2021-03-03 op || !recv_time(fd, &notafter)
419 2c3e53da 2021-03-03 op || !recv_vhost(fd, &vhost))
420 2c3e53da 2021-03-03 op fatal("failure in handling fork request");
421 2c3e53da 2021-03-03 op
422 2c3e53da 2021-03-03 op d = launch_cgi(&iri, spath, relpath, addr, ruser, cissuer, chash,
423 2c3e53da 2021-03-03 op notbefore, notafter, vhost);
424 2c3e53da 2021-03-03 op if (!send_fd(fd, d))
425 2c3e53da 2021-03-03 op fatal("failure in sending the fd to the server: %s",
426 2c3e53da 2021-03-03 op strerror(errno));
427 2c3e53da 2021-03-03 op close(d);
428 2c3e53da 2021-03-03 op
429 2c3e53da 2021-03-03 op free_recvd_iri(&iri);
430 2c3e53da 2021-03-03 op free(spath);
431 2c3e53da 2021-03-03 op free(relpath);
432 2c3e53da 2021-03-03 op free(addr);
433 2c3e53da 2021-03-03 op free(ruser);
434 2c3e53da 2021-03-03 op free(cissuer);
435 2c3e53da 2021-03-03 op free(chash);
436 2c3e53da 2021-03-03 op }
437 2c3e53da 2021-03-03 op
438 2c3e53da 2021-03-03 op int
439 2c3e53da 2021-03-03 op executor_main(void)
440 2c3e53da 2021-03-03 op {
441 2c3e53da 2021-03-03 op struct vhost *vhost;
442 2c3e53da 2021-03-03 op struct event evs[PROC_MAX];
443 2c3e53da 2021-03-03 op int i;
444 881a9dd9 2021-01-16 op
445 881a9dd9 2021-01-16 op #ifdef __OpenBSD__
446 10782292 2021-01-25 op for (vhost = hosts; vhost->domain != NULL; ++vhost) {
447 2fafa2d2 2021-02-01 op /* r so we can chdir into the correct directory */
448 2fafa2d2 2021-02-01 op if (unveil(vhost->dir, "rx") == -1)
449 10782292 2021-01-25 op err(1, "unveil %s for domain %s",
450 10782292 2021-01-25 op vhost->dir, vhost->domain);
451 10782292 2021-01-25 op }
452 10782292 2021-01-25 op
453 2fafa2d2 2021-02-01 op /* rpath to chdir into the correct directory */
454 2fafa2d2 2021-02-01 op if (pledge("stdio rpath sendfd proc exec", NULL))
455 10782292 2021-01-25 op err(1, "pledge");
456 881a9dd9 2021-01-16 op #endif
457 881a9dd9 2021-01-16 op
458 2c3e53da 2021-03-03 op event_init();
459 881a9dd9 2021-01-16 op
460 2c3e53da 2021-03-03 op for (i = 0; i < conf.prefork; ++i) {
461 2c3e53da 2021-03-03 op event_set(&evs[i], servpipes[i], EV_READ | EV_PERSIST,
462 2c3e53da 2021-03-03 op handle_fork_req, NULL);
463 2c3e53da 2021-03-03 op event_add(&evs[i], NULL);
464 881a9dd9 2021-01-16 op }
465 881a9dd9 2021-01-16 op
466 2c3e53da 2021-03-03 op event_dispatch();
467 ca21e100 2021-02-04 op
468 881a9dd9 2021-01-16 op return 1;
469 881a9dd9 2021-01-16 op }