Blame


1 3e4749f7 2020-10-02 op .\" Copyright (c) 2020 Omar Polo <op@omarpolo.com>
2 3e4749f7 2020-10-02 op .\"
3 3e4749f7 2020-10-02 op .\" Permission to use, copy, modify, and distribute this software for any
4 3e4749f7 2020-10-02 op .\" purpose with or without fee is hereby granted, provided that the above
5 3e4749f7 2020-10-02 op .\" copyright notice and this permission notice appear in all copies.
6 3e4749f7 2020-10-02 op .\"
7 3e4749f7 2020-10-02 op .\" THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
8 3e4749f7 2020-10-02 op .\" WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
9 3e4749f7 2020-10-02 op .\" MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
10 3e4749f7 2020-10-02 op .\" ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
11 3e4749f7 2020-10-02 op .\" WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
12 3e4749f7 2020-10-02 op .\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
13 3e4749f7 2020-10-02 op .\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
14 3e4749f7 2020-10-02 op .Dd $Mdocdate: October 2 2020$
15 3e4749f7 2020-10-02 op .Dt GMIND 1
16 3e4749f7 2020-10-02 op .Os
17 3e4749f7 2020-10-02 op .Sh NAME
18 3e4749f7 2020-10-02 op .Nm gmid
19 fab952e1 2020-10-03 op .Nd dead simple zero configuration gemini server
20 3e4749f7 2020-10-02 op .Sh SYNOPSIS
21 3e4749f7 2020-10-02 op .Nm
22 3e4749f7 2020-10-02 op .Bk -words
23 d7802bb4 2020-12-02 op .Op Fl fh
24 3e4749f7 2020-10-02 op .Op Fl c Ar cert.pem
25 3e4749f7 2020-10-02 op .Op Fl d Ar docs
26 3e4749f7 2020-10-02 op .Op Fl k Ar key.pem
27 721e2325 2020-11-18 op .Op Fl p Ar port
28 0ed56567 2020-11-06 op .Op Fl x Ar cgi-bin
29 3e4749f7 2020-10-02 op .Ek
30 3e4749f7 2020-10-02 op .Sh DESCRIPTION
31 3e4749f7 2020-10-02 op .Nm
32 0ed56567 2020-11-06 op is a very simple and minimal gemini server that can serve static files
33 0ed56567 2020-11-06 op and execute CGI scripts.
34 3e4749f7 2020-10-02 op .Pp
35 3e4749f7 2020-10-02 op .Nm
36 df6ca41d 2020-12-25 op won't serve files outside the given directory and won't follow
37 df6ca41d 2020-12-25 op symlinks.
38 6980aad6 2020-10-02 op Furthermore, on
39 6980aad6 2020-10-02 op .Ox ,
40 6980aad6 2020-10-02 op .Xr pledge 2
41 3e4749f7 2020-10-02 op and
42 6980aad6 2020-10-02 op .Xr unveil 2
43 3e4749f7 2020-10-02 op are used to ensure that
44 3e4749f7 2020-10-02 op .Nm
45 0ed56567 2020-11-06 op dosen't do anything else than read files from the given directory,
46 0ed56567 2020-11-06 op accept network connections and, optionally, execute CGI scripts.
47 3e4749f7 2020-10-02 op .Pp
48 df6ca41d 2020-12-25 op .Nm
49 df6ca41d 2020-12-25 op fully supports IRIs (Internationalized Resource Identifiers, see
50 df6ca41d 2020-12-25 op RFC3987).
51 df6ca41d 2020-12-25 op .Pp
52 3e4749f7 2020-10-02 op It should be noted that
53 3e4749f7 2020-10-02 op .Nm
54 3e4749f7 2020-10-02 op is very simple in its implementation, and so it may not be appropriate
55 0ed56567 2020-11-06 op for serving sites with lots of users.
56 0ed56567 2020-11-06 op After all, the code is single threaded and use a single process,
57 83000e2d 2020-12-21 op although it can handle multiple clients at the same time.
58 3e4749f7 2020-10-02 op .Pp
59 fab952e1 2020-10-03 op If a user request path is a directory,
60 fab952e1 2020-10-03 op .Nm
61 fab952e1 2020-10-03 op will try to serve a
62 fab952e1 2020-10-03 op .Pa index.gmi
63 fab952e1 2020-10-03 op file inside that directory.
64 fab952e1 2020-10-03 op .Pp
65 3e4749f7 2020-10-02 op The options are as follows:
66 3e4749f7 2020-10-02 op .Bl -tag -width 12m
67 3e4749f7 2020-10-02 op .It Fl c Ar cert.pem
68 3e4749f7 2020-10-02 op The certificate to use, by default is
69 fab952e1 2020-10-03 op .Pa cert.pem .
70 3e4749f7 2020-10-02 op .It Fl d Ar docs
71 3e4749f7 2020-10-02 op The root directory to serve.
72 3e4749f7 2020-10-02 op .Nm
73 a5d310bc 2020-11-10 op won't serve any file that is outside that directory.
74 a5d310bc 2020-11-10 op By default is
75 0ed56567 2020-11-06 op .Pa docs .
76 d7802bb4 2020-12-02 op .It Fl f
77 d7802bb4 2020-12-02 op stays and log in the foreground, do not daemonize the process.
78 3e4749f7 2020-10-02 op .It Fl h
79 fab952e1 2020-10-03 op Print the usage and exit.
80 3e4749f7 2020-10-02 op .It Fl k Ar key.pem
81 3e4749f7 2020-10-02 op The key for the certificate, by default is
82 fab952e1 2020-10-03 op .Pa key.pem .
83 721e2325 2020-11-18 op .It Fl p Ar port
84 721e2325 2020-11-18 op The port to bind to, by default 1965.
85 0ed56567 2020-11-06 op .It Fl x Ar dir
86 0ed56567 2020-11-06 op Enable execution of CGI scripts inside the given directory (relative
87 0ed56567 2020-11-06 op to the document root.) Cannot be provided more than once.
88 3e4749f7 2020-10-02 op .El
89 72342dc9 2020-11-06 op .Sh CGI
90 0ed56567 2020-11-06 op When CGI scripts are enabled for a directory, a request for an
91 0ed56567 2020-11-06 op executable file will execute it and fed its output to the client.
92 72342dc9 2020-11-06 op .Pp
93 0ed56567 2020-11-06 op The CGI scripts will inherit the environment from
94 0ed56567 2020-11-06 op .Nm
95 0ed56567 2020-11-06 op with these additional variables set:
96 a5d310bc 2020-11-10 op .Bl -tag -width 18m
97 0ed56567 2020-11-06 op .It Ev SERVER_SOFTWARE
98 0ed56567 2020-11-06 op "gmid"
99 0ed56567 2020-11-06 op .It Ev SERVER_PORT
100 0ed56567 2020-11-06 op "1965"
101 a5d310bc 2020-11-10 op .It Ev SCRIPT_NAME
102 a5d310bc 2020-11-10 op The (public) path to the script.
103 a5d310bc 2020-11-10 op .It Ev SCRIPT_EXECUTABLE
104 a5d310bc 2020-11-10 op The full path to the executable.
105 a5d310bc 2020-11-10 op .It Ev REQUEST_URI
106 a5d310bc 2020-11-10 op The user request (without the query parameters.)
107 a5d310bc 2020-11-10 op .It Ev REQUEST_RELATIVE
108 a5d310bc 2020-11-10 op The request relative to the script.
109 0ed56567 2020-11-06 op .It Ev QUERY_STRING
110 a5d310bc 2020-11-10 op The query parameters.
111 a5d310bc 2020-11-10 op .It Ev REMOTE_HOST
112 a5d310bc 2020-11-10 op The remote IP address.
113 677afbd3 2020-12-02 op .It Ev REMOTE_ADDR
114 677afbd3 2020-12-02 op The remote IP address.
115 a5d310bc 2020-11-10 op .It Ev DOCUMENT_ROOT
116 a5d310bc 2020-11-10 op The root directory being served, the one provided with the
117 a5d310bc 2020-11-10 op .Ar d
118 a5d310bc 2020-11-10 op parameter to
119 a5d310bc 2020-11-10 op .Nm
120 677afbd3 2020-12-02 op .It Ev AUTH_TYPE
121 677afbd3 2020-12-02 op The string "Certificate" if the client used a certificate, otherwise unset.
122 677afbd3 2020-12-02 op .It Ev REMOTE_USER
123 677afbd3 2020-12-02 op The subject of the client certificate if provided, otherwise unset.
124 677afbd3 2020-12-02 op .It Ev TLS_CLIENT_ISSUER
125 677afbd3 2020-12-02 op The is the issuer of the client certificate if provided, otherwise unset.
126 677afbd3 2020-12-02 op .It Ev TLS_CLIENT_HASH
127 677afbd3 2020-12-02 op The hash of the client certificate if provided, otherwise unset.
128 677afbd3 2020-12-02 op The format is "ALGO:HASH".
129 0ed56567 2020-11-06 op .El
130 a5d310bc 2020-11-10 op .Pp
131 a5d310bc 2020-11-10 op Let's say you have a script in
132 a5d310bc 2020-11-10 op .Pa /cgi-bin/script
133 a5d310bc 2020-11-10 op and the user request is
134 a5d310bc 2020-11-10 op .Pa /cgi-bin/script/foo/bar?quux .
135 a5d310bc 2020-11-10 op Then
136 a5d310bc 2020-11-10 op .Ev SCRIPT_NAME
137 a5d310bc 2020-11-10 op will be
138 a5d310bc 2020-11-10 op .Pa /cgi-bin/script ,
139 a5d310bc 2020-11-10 op .Ev SCRIPT_EXECUTABLE
140 a5d310bc 2020-11-10 op will be
141 a5d310bc 2020-11-10 op .Pa $DOCUMENT_ROOT/cgi-bin/script ,
142 a5d310bc 2020-11-10 op .Ev REQUEST_URI
143 a5d310bc 2020-11-10 op will be
144 a5d310bc 2020-11-10 op .Pa /cgi-bin/script/foo/bar ,
145 a5d310bc 2020-11-10 op .Ev REQUEST_RELATIVE
146 a5d310bc 2020-11-10 op will be
147 a5d310bc 2020-11-10 op .Pa foo/bar and
148 a5d310bc 2020-11-10 op .Ev QUERY_STRING
149 a5d310bc 2020-11-10 op will be
150 a5d310bc 2020-11-10 op .Ar quux .
151 3e4749f7 2020-10-02 op .Sh EXAMPLES
152 3e4749f7 2020-10-02 op To quickly getting started
153 6980aad6 2020-10-02 op .Bd -literal -offset indent
154 3e4749f7 2020-10-02 op $ # generate a cert and a key
155 3e4749f7 2020-10-02 op $ openssl req -x509 -newkey rsa:4096 -keyout key.pem \\
156 3e4749f7 2020-10-02 op -out cert.pem -days 365 -nodes
157 3e4749f7 2020-10-02 op $ mkdir docs
158 3e4749f7 2020-10-02 op $ cat <<EOF > docs/index.gmi
159 3e4749f7 2020-10-02 op # Hello world
160 3e4749f7 2020-10-02 op test paragraph...
161 3e4749f7 2020-10-02 op EOF
162 3e4749f7 2020-10-02 op $ gmid -c cert.pem -k key.pem -d docs
163 6980aad6 2020-10-02 op .Ed
164 3e4749f7 2020-10-02 op .Pp
165 0ed56567 2020-11-06 op Now you can visit gemini://localhost/ with your preferred gemini
166 0ed56567 2020-11-06 op client.
167 0ed56567 2020-11-06 op .Pp
168 0ed56567 2020-11-06 op To add some CGI scripts, assuming a setup similar to the previous
169 0ed56567 2020-11-06 op example, you can
170 0ed56567 2020-11-06 op .Bd -literal -offset indent
171 0ed56567 2020-11-06 op $ mkdir docs/cgi-bin
172 0ed56567 2020-11-06 op $ cat <<EOF > docs/cgi-bin/hello-world
173 0ed56567 2020-11-06 op #!/bin/sh
174 0ed56567 2020-11-06 op printf "20 text/plain\\r\\n"
175 0ed56567 2020-11-06 op echo "hello world!"
176 0ed56567 2020-11-06 op EOF
177 0ed56567 2020-11-06 op $ gmid -x cgi-bin
178 0ed56567 2020-11-06 op .Ed
179 0ed56567 2020-11-06 op .Pp
180 0ed56567 2020-11-06 op Note that the argument to the
181 0ed56567 2020-11-06 op .Fl x
182 0ed56567 2020-11-06 op option is
183 0ed56567 2020-11-06 op .Pa cgi-bin
184 0ed56567 2020-11-06 op and not
185 0ed56567 2020-11-06 op .Pa docs/cgi-bin ,
186 a5d310bc 2020-11-10 op since it's relative to the document root.
187 ef04b551 2021-01-09 op .Sh ACKNOWLEDGEMENTS
188 ef04b551 2021-01-09 op .Nm
189 ef04b551 2021-01-09 op uses the "Flexible and Economical" UTF-8 decoder written by
190 ef04b551 2021-01-09 op .An Bjoern Hoehrmann .
191 3e4749f7 2020-10-02 op .Sh CAVEATS
192 3e4749f7 2020-10-02 op .Bl -bullet
193 3e4749f7 2020-10-02 op .It
194 fab952e1 2020-10-03 op it doesn't support virtual hosts: the host part of the request URL is
195 3e4749f7 2020-10-02 op completely ignored.
196 043acc97 2020-12-25 op .It
197 043acc97 2020-12-25 op a %2F sequence in the path part is indistinguishable from a literal
198 043acc97 2020-12-25 op slash: this is not RFC3986-compliant.
199 00781742 2020-12-25 op .It
200 00781742 2020-12-25 op a %00 sequence either in the path or in the query part is treated as
201 00781742 2020-12-25 op invalid character and thus rejected.
202 3e4749f7 2020-10-02 op .El