Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <unistd.h>
50 #include "proc.h"
51 #include "gotwebd.h"
52 #include "got_sockaddr.h"
54 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
55 static struct file {
56 TAILQ_ENTRY(file) entry;
57 FILE *stream;
58 char *name;
59 int lineno;
60 int errors;
61 } *file;
62 struct file *newfile(const char *, int);
63 static void closefile(struct file *);
64 int check_file_secrecy(int, const char *);
65 int yyparse(void);
66 int yylex(void);
67 int yyerror(const char *, ...)
68 __attribute__((__format__ (printf, 1, 2)))
69 __attribute__((__nonnull__ (1)));
70 int kw_cmp(const void *, const void *);
71 int lookup(char *);
72 int lgetc(int);
73 int lungetc(int);
74 int findeol(void);
76 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
77 struct sym {
78 TAILQ_ENTRY(sym) entry;
79 int used;
80 int persist;
81 char *nam;
82 char *val;
83 };
85 int symset(const char *, const char *, int);
86 char *symget(const char *);
88 static int errors;
90 static struct gotwebd *gotwebd;
91 static struct server *new_srv;
92 static struct server *conf_new_server(const char *);
93 int getservice(const char *);
94 int n;
96 int get_addrs(const char *, struct server *, in_port_t);
97 int addr_dup_check(struct addresslist *, struct address *,
98 const char *, const char *);
99 int add_addr(struct server *, struct address *);
100 struct address *host_v4(const char *);
101 struct address *host_v6(const char *);
102 int host_dns(const char *, struct server *,
103 int, in_port_t, const char *, int);
104 int host_if(const char *, struct server *,
105 int, in_port_t, const char *, int);
106 int host(const char *, struct server *,
107 int, in_port_t, const char *, int);
108 int is_if_in_group(const char *, const char *);
110 typedef struct {
111 union {
112 long long number;
113 char *string;
114 in_port_t port;
115 } v;
116 int lineno;
117 } YYSTYPE;
119 %}
121 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
122 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
123 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
124 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
125 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
127 %token <v.string> STRING
128 %type <v.port> fcgiport
129 %token <v.number> NUMBER
130 %type <v.number> boolean
132 %%
134 grammar : /* empty */
135 | grammar '\n'
136 | grammar varset '\n'
137 | grammar main '\n'
138 | grammar server '\n'
139 | grammar error '\n' { file->errors++; }
142 varset : STRING '=' STRING {
143 char *s = $1;
144 while (*s++) {
145 if (isspace((unsigned char)*s)) {
146 yyerror("macro name cannot contain "
147 "whitespace");
148 free($1);
149 free($3);
150 YYERROR;
153 if (symset($1, $3, 0) == -1)
154 fatal("cannot store variable");
155 free($1);
156 free($3);
160 boolean : STRING {
161 if (strcasecmp($1, "1") == 0 ||
162 strcasecmp($1, "yes") == 0 ||
163 strcasecmp($1, "on") == 0)
164 $$ = 1;
165 else if (strcasecmp($1, "0") == 0 ||
166 strcasecmp($1, "off") == 0 ||
167 strcasecmp($1, "no") == 0)
168 $$ = 0;
169 else {
170 yyerror("invalid boolean value '%s'", $1);
171 free($1);
172 YYERROR;
174 free($1);
176 | ON { $$ = 1; }
177 | NUMBER { $$ = $1; }
180 fcgiport : PORT NUMBER {
181 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
182 yyerror("invalid port: %lld", $2);
183 YYERROR;
185 $$ = $2;
187 | PORT STRING {
188 int val;
190 if ((val = getservice($2)) == -1) {
191 yyerror("invalid port: %s", $2);
192 free($2);
193 YYERROR;
195 free($2);
197 $$ = val;
201 main : PREFORK NUMBER {
202 gotwebd->prefork_gotwebd = $2;
204 | CHROOT STRING {
205 n = strlcpy(gotwebd->httpd_chroot, $2,
206 sizeof(gotwebd->httpd_chroot));
207 if (n >= sizeof(gotwebd->httpd_chroot)) {
208 yyerror("%s: httpd_chroot truncated", __func__);
209 free($2);
210 YYERROR;
212 free($2);
214 | UNIX_SOCKET boolean {
215 gotwebd->unix_socket = $2;
217 | UNIX_SOCKET_NAME STRING {
218 n = snprintf(gotwebd->unix_socket_name,
219 sizeof(gotwebd->unix_socket_name), "%s%s",
220 strlen(gotwebd->httpd_chroot) ?
221 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
222 if (n < 0 ||
223 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
224 yyerror("%s: unix_socket_name truncated",
225 __func__);
226 free($2);
227 YYERROR;
229 free($2);
233 server : SERVER STRING {
234 struct server *srv;
236 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
237 if (strcmp(srv->name, $2) == 0) {
238 yyerror("server name exists '%s'", $2);
239 free($2);
240 YYERROR;
244 new_srv = conf_new_server($2);
245 log_debug("adding server %s", $2);
246 free($2);
248 | SERVER STRING {
249 struct server *srv;
251 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
252 if (strcmp(srv->name, $2) == 0) {
253 yyerror("server name exists '%s'", $2);
254 free($2);
255 YYERROR;
259 new_srv = conf_new_server($2);
260 log_debug("adding server %s", $2);
261 free($2);
262 } '{' optnl serveropts2 '}' {
266 serveropts1 : REPOS_PATH STRING {
267 n = strlcpy(new_srv->repos_path, $2,
268 sizeof(new_srv->repos_path));
269 if (n >= sizeof(new_srv->repos_path)) {
270 yyerror("%s: repos_path truncated", __func__);
271 free($2);
272 YYERROR;
274 free($2);
276 | SITE_NAME STRING {
277 n = strlcpy(new_srv->site_name, $2,
278 sizeof(new_srv->site_name));
279 if (n >= sizeof(new_srv->site_name)) {
280 yyerror("%s: site_name truncated", __func__);
281 free($2);
282 YYERROR;
284 free($2);
286 | SITE_OWNER STRING {
287 n = strlcpy(new_srv->site_owner, $2,
288 sizeof(new_srv->site_owner));
289 if (n >= sizeof(new_srv->site_owner)) {
290 yyerror("%s: site_owner truncated", __func__);
291 free($2);
292 YYERROR;
294 free($2);
296 | SITE_LINK STRING {
297 n = strlcpy(new_srv->site_link, $2,
298 sizeof(new_srv->site_link));
299 if (n >= sizeof(new_srv->site_link)) {
300 yyerror("%s: site_link truncated", __func__);
301 free($2);
302 YYERROR;
304 free($2);
306 | LOGO STRING {
307 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
308 if (n >= sizeof(new_srv->logo)) {
309 yyerror("%s: logo truncated", __func__);
310 free($2);
311 YYERROR;
313 free($2);
315 | LOGO_URL STRING {
316 n = strlcpy(new_srv->logo_url, $2,
317 sizeof(new_srv->logo_url));
318 if (n >= sizeof(new_srv->logo_url)) {
319 yyerror("%s: logo_url truncated", __func__);
320 free($2);
321 YYERROR;
323 free($2);
325 | CUSTOM_CSS STRING {
326 n = strlcpy(new_srv->custom_css, $2,
327 sizeof(new_srv->custom_css));
328 if (n >= sizeof(new_srv->custom_css)) {
329 yyerror("%s: custom_css truncated", __func__);
330 free($2);
331 YYERROR;
333 free($2);
335 | LISTEN ON STRING fcgiport {
336 if (get_addrs($3, new_srv, $4) == -1) {
337 yyerror("could not get addrs");
338 YYERROR;
340 new_srv->fcgi_socket = 1;
342 | LISTEN ON SOCKET STRING {
343 if (!strcasecmp($4, "off") ||
344 !strcasecmp($4, "no")) {
345 new_srv->unix_socket = 0;
346 free($4);
347 YYACCEPT;
350 new_srv->unix_socket = 1;
352 n = snprintf(new_srv->unix_socket_name,
353 sizeof(new_srv->unix_socket_name), "%s%s",
354 strlen(gotwebd->httpd_chroot) ?
355 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $4);
356 if (n < 0 ||
357 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
358 yyerror("%s: unix_socket_name truncated",
359 __func__);
360 free($4);
361 YYERROR;
363 free($4);
365 | MAX_REPOS NUMBER {
366 if ($2 > 0)
367 new_srv->max_repos = $2;
369 | SHOW_SITE_OWNER boolean {
370 new_srv->show_site_owner = $2;
372 | SHOW_REPO_OWNER boolean {
373 new_srv->show_repo_owner = $2;
375 | SHOW_REPO_AGE boolean {
376 new_srv->show_repo_age = $2;
378 | SHOW_REPO_DESCRIPTION boolean {
379 new_srv->show_repo_description = $2;
381 | SHOW_REPO_CLONEURL boolean {
382 new_srv->show_repo_cloneurl = $2;
384 | RESPECT_EXPORTOK boolean {
385 new_srv->respect_exportok = $2;
387 | MAX_REPOS_DISPLAY NUMBER {
388 new_srv->max_repos_display = $2;
390 | MAX_COMMITS_DISPLAY NUMBER {
391 if ($2 > 0)
392 new_srv->max_commits_display = $2;
396 serveropts2 : serveropts2 serveropts1 nl
397 | serveropts1 optnl
400 nl : '\n' optnl
403 optnl : '\n' optnl /* zero or more newlines */
404 | /* empty */
407 %%
409 struct keywords {
410 const char *k_name;
411 int k_val;
412 };
414 int
415 yyerror(const char *fmt, ...)
417 va_list ap;
418 char *msg;
420 file->errors++;
421 va_start(ap, fmt);
422 if (vasprintf(&msg, fmt, ap) == -1)
423 fatalx("yyerror vasprintf");
424 va_end(ap);
425 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
426 free(msg);
427 return (0);
430 int
431 kw_cmp(const void *k, const void *e)
433 return (strcmp(k, ((const struct keywords *)e)->k_name));
436 int
437 lookup(char *s)
439 /* This has to be sorted always. */
440 static const struct keywords keywords[] = {
441 { "chroot", CHROOT },
442 { "custom_css", CUSTOM_CSS },
443 { "listen", LISTEN },
444 { "logo", LOGO },
445 { "logo_url", LOGO_URL },
446 { "max_commits_display", MAX_COMMITS_DISPLAY },
447 { "max_repos", MAX_REPOS },
448 { "max_repos_display", MAX_REPOS_DISPLAY },
449 { "on", ON },
450 { "port", PORT },
451 { "prefork", PREFORK },
452 { "repos_path", REPOS_PATH },
453 { "respect_exportok", RESPECT_EXPORTOK },
454 { "server", SERVER },
455 { "show_repo_age", SHOW_REPO_AGE },
456 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
457 { "show_repo_description", SHOW_REPO_DESCRIPTION },
458 { "show_repo_owner", SHOW_REPO_OWNER },
459 { "show_site_owner", SHOW_SITE_OWNER },
460 { "site_link", SITE_LINK },
461 { "site_name", SITE_NAME },
462 { "site_owner", SITE_OWNER },
463 { "socket", SOCKET },
464 { "unix_socket", UNIX_SOCKET },
465 { "unix_socket_name", UNIX_SOCKET_NAME },
466 };
467 const struct keywords *p;
469 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
470 sizeof(keywords[0]), kw_cmp);
472 if (p)
473 return (p->k_val);
474 else
475 return (STRING);
478 #define MAXPUSHBACK 128
480 unsigned char *parsebuf;
481 int parseindex;
482 unsigned char pushback_buffer[MAXPUSHBACK];
483 int pushback_index = 0;
485 int
486 lgetc(int quotec)
488 int c, next;
490 if (parsebuf) {
491 /* Read character from the parsebuffer instead of input. */
492 if (parseindex >= 0) {
493 c = parsebuf[parseindex++];
494 if (c != '\0')
495 return (c);
496 parsebuf = NULL;
497 } else
498 parseindex++;
501 if (pushback_index)
502 return (pushback_buffer[--pushback_index]);
504 if (quotec) {
505 c = getc(file->stream);
506 if (c == EOF)
507 yyerror("reached end of file while parsing "
508 "quoted string");
509 return (c);
512 c = getc(file->stream);
513 while (c == '\\') {
514 next = getc(file->stream);
515 if (next != '\n') {
516 c = next;
517 break;
519 yylval.lineno = file->lineno;
520 file->lineno++;
521 c = getc(file->stream);
524 return (c);
527 int
528 lungetc(int c)
530 if (c == EOF)
531 return (EOF);
532 if (parsebuf) {
533 parseindex--;
534 if (parseindex >= 0)
535 return (c);
537 if (pushback_index < MAXPUSHBACK-1)
538 return (pushback_buffer[pushback_index++] = c);
539 else
540 return (EOF);
543 int
544 findeol(void)
546 int c;
548 parsebuf = NULL;
550 /* Skip to either EOF or the first real EOL. */
551 while (1) {
552 if (pushback_index)
553 c = pushback_buffer[--pushback_index];
554 else
555 c = lgetc(0);
556 if (c == '\n') {
557 file->lineno++;
558 break;
560 if (c == EOF)
561 break;
563 return (ERROR);
566 int
567 yylex(void)
569 unsigned char buf[8096];
570 unsigned char *p, *val;
571 int quotec, next, c;
572 int token;
574 top:
575 p = buf;
576 c = lgetc(0);
577 while (c == ' ' || c == '\t')
578 c = lgetc(0); /* nothing */
580 yylval.lineno = file->lineno;
581 if (c == '#') {
582 c = lgetc(0);
583 while (c != '\n' && c != EOF)
584 c = lgetc(0); /* nothing */
586 if (c == '$' && parsebuf == NULL) {
587 while (1) {
588 c = lgetc(0);
589 if (c == EOF)
590 return (0);
592 if (p + 1 >= buf + sizeof(buf) - 1) {
593 yyerror("string too long");
594 return (findeol());
596 if (isalnum(c) || c == '_') {
597 *p++ = c;
598 continue;
600 *p = '\0';
601 lungetc(c);
602 break;
604 val = symget(buf);
605 if (val == NULL) {
606 yyerror("macro '%s' not defined", buf);
607 return (findeol());
609 parsebuf = val;
610 parseindex = 0;
611 goto top;
614 switch (c) {
615 case '\'':
616 case '"':
617 quotec = c;
618 while (1) {
619 c = lgetc(quotec);
620 if (c == EOF)
621 return (0);
622 if (c == '\n') {
623 file->lineno++;
624 continue;
625 } else if (c == '\\') {
626 next = lgetc(quotec);
627 if (next == EOF)
628 return (0);
629 if (next == quotec || c == ' ' || c == '\t')
630 c = next;
631 else if (next == '\n') {
632 file->lineno++;
633 continue;
634 } else
635 lungetc(next);
636 } else if (c == quotec) {
637 *p = '\0';
638 break;
639 } else if (c == '\0') {
640 yyerror("syntax error");
641 return (findeol());
643 if (p + 1 >= buf + sizeof(buf) - 1) {
644 yyerror("string too long");
645 return (findeol());
647 *p++ = c;
649 yylval.v.string = strdup(buf);
650 if (yylval.v.string == NULL)
651 err(1, "yylex: strdup");
652 return (STRING);
655 #define allowed_to_end_number(x) \
656 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
658 if (c == '-' || isdigit(c)) {
659 do {
660 *p++ = c;
661 if ((unsigned)(p-buf) >= sizeof(buf)) {
662 yyerror("string too long");
663 return (findeol());
665 c = lgetc(0);
666 } while (c != EOF && isdigit(c));
667 lungetc(c);
668 if (p == buf + 1 && buf[0] == '-')
669 goto nodigits;
670 if (c == EOF || allowed_to_end_number(c)) {
671 const char *errstr = NULL;
673 *p = '\0';
674 yylval.v.number = strtonum(buf, LLONG_MIN,
675 LLONG_MAX, &errstr);
676 if (errstr) {
677 yyerror("\"%s\" invalid number: %s",
678 buf, errstr);
679 return (findeol());
681 return (NUMBER);
682 } else {
683 nodigits:
684 while (p > buf + 1)
685 lungetc(*--p);
686 c = *--p;
687 if (c == '-')
688 return (c);
692 #define allowed_in_string(x) \
693 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
694 x != '{' && x != '}' && \
695 x != '!' && x != '=' && x != '#' && \
696 x != ','))
698 if (isalnum(c) || c == ':' || c == '_') {
699 do {
700 *p++ = c;
701 if ((unsigned)(p-buf) >= sizeof(buf)) {
702 yyerror("string too long");
703 return (findeol());
705 c = lgetc(0);
706 } while (c != EOF && (allowed_in_string(c)));
707 lungetc(c);
708 *p = '\0';
709 token = lookup(buf);
710 if (token == STRING) {
711 yylval.v.string = strdup(buf);
712 if (yylval.v.string == NULL)
713 err(1, "yylex: strdup");
715 return (token);
717 if (c == '\n') {
718 yylval.lineno = file->lineno;
719 file->lineno++;
721 if (c == EOF)
722 return (0);
723 return (c);
726 int
727 check_file_secrecy(int fd, const char *fname)
729 struct stat st;
731 if (fstat(fd, &st)) {
732 log_warn("cannot stat %s", fname);
733 return (-1);
735 if (st.st_uid != 0 && st.st_uid != getuid()) {
736 log_warnx("%s: owner not root or current user", fname);
737 return (-1);
739 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
740 log_warnx("%s: group writable or world read/writable", fname);
741 return (-1);
743 return (0);
746 struct file *
747 newfile(const char *name, int secret)
749 struct file *nfile;
751 nfile = calloc(1, sizeof(struct file));
752 if (nfile == NULL) {
753 log_warn("calloc");
754 return (NULL);
756 nfile->name = strdup(name);
757 if (nfile->name == NULL) {
758 log_warn("strdup");
759 free(nfile);
760 return (NULL);
762 nfile->stream = fopen(nfile->name, "r");
763 if (nfile->stream == NULL) {
764 /* no warning, we don't require a conf file */
765 free(nfile->name);
766 free(nfile);
767 return (NULL);
768 } else if (secret &&
769 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
770 fclose(nfile->stream);
771 free(nfile->name);
772 free(nfile);
773 return (NULL);
775 nfile->lineno = 1;
776 return (nfile);
779 static void
780 closefile(struct file *xfile)
782 fclose(xfile->stream);
783 free(xfile->name);
784 free(xfile);
787 static void
788 add_default_server(void)
790 new_srv = conf_new_server(D_SITENAME);
791 log_debug("%s: adding default server %s", __func__, D_SITENAME);
794 int
795 parse_config(const char *filename, struct gotwebd *env)
797 struct sym *sym, *next;
799 if (config_init(env) == -1)
800 fatalx("failed to initialize configuration");
802 gotwebd = env;
804 file = newfile(filename, 0);
805 if (file == NULL) {
806 add_default_server();
807 sockets_parse_sockets(env);
808 /* just return, as we don't require a conf file */
809 return (0);
812 yyparse();
813 errors = file->errors;
814 closefile(file);
816 /* Free macros and check which have not been used. */
817 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
818 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
819 fprintf(stderr, "warning: macro '%s' not used\n",
820 sym->nam);
821 if (!sym->persist) {
822 free(sym->nam);
823 free(sym->val);
824 TAILQ_REMOVE(&symhead, sym, entry);
825 free(sym);
829 if (errors)
830 return (-1);
832 /* just add default server if no config specified */
833 if (gotwebd->server_cnt == 0)
834 add_default_server();
836 /* setup our listening sockets */
837 sockets_parse_sockets(env);
839 return (0);
842 struct server *
843 conf_new_server(const char *name)
845 struct server *srv = NULL;
847 srv = calloc(1, sizeof(*srv));
848 if (srv == NULL)
849 fatalx("%s: calloc", __func__);
851 n = strlcpy(srv->name, name, sizeof(srv->name));
852 if (n >= sizeof(srv->name))
853 fatalx("%s: strlcpy", __func__);
854 n = snprintf(srv->unix_socket_name,
855 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
856 D_UNIX_SOCKET);
857 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
858 fatalx("%s: snprintf", __func__);
859 n = strlcpy(srv->repos_path, D_GOTPATH,
860 sizeof(srv->repos_path));
861 if (n >= sizeof(srv->repos_path))
862 fatalx("%s: strlcpy", __func__);
863 n = strlcpy(srv->site_name, D_SITENAME,
864 sizeof(srv->site_name));
865 if (n >= sizeof(srv->site_name))
866 fatalx("%s: strlcpy", __func__);
867 n = strlcpy(srv->site_owner, D_SITEOWNER,
868 sizeof(srv->site_owner));
869 if (n >= sizeof(srv->site_owner))
870 fatalx("%s: strlcpy", __func__);
871 n = strlcpy(srv->site_link, D_SITELINK,
872 sizeof(srv->site_link));
873 if (n >= sizeof(srv->site_link))
874 fatalx("%s: strlcpy", __func__);
875 n = strlcpy(srv->logo, D_GOTLOGO,
876 sizeof(srv->logo));
877 if (n >= sizeof(srv->logo))
878 fatalx("%s: strlcpy", __func__);
879 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
880 if (n >= sizeof(srv->logo_url))
881 fatalx("%s: strlcpy", __func__);
882 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
883 if (n >= sizeof(srv->custom_css))
884 fatalx("%s: strlcpy", __func__);
886 srv->show_site_owner = D_SHOWSOWNER;
887 srv->show_repo_owner = D_SHOWROWNER;
888 srv->show_repo_age = D_SHOWAGE;
889 srv->show_repo_description = D_SHOWDESC;
890 srv->show_repo_cloneurl = D_SHOWURL;
891 srv->respect_exportok = D_RESPECTEXPORTOK;
893 srv->max_repos_display = D_MAXREPODISP;
894 srv->max_commits_display = D_MAXCOMMITDISP;
895 srv->max_repos = D_MAXREPO;
897 srv->unix_socket = 1;
898 srv->fcgi_socket = 0;
900 TAILQ_INIT(&srv->al);
901 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
902 gotwebd->server_cnt++;
904 return srv;
905 };
907 int
908 symset(const char *nam, const char *val, int persist)
910 struct sym *sym;
912 TAILQ_FOREACH(sym, &symhead, entry) {
913 if (strcmp(nam, sym->nam) == 0)
914 break;
917 if (sym != NULL) {
918 if (sym->persist == 1)
919 return (0);
920 else {
921 free(sym->nam);
922 free(sym->val);
923 TAILQ_REMOVE(&symhead, sym, entry);
924 free(sym);
927 sym = calloc(1, sizeof(*sym));
928 if (sym == NULL)
929 return (-1);
931 sym->nam = strdup(nam);
932 if (sym->nam == NULL) {
933 free(sym);
934 return (-1);
936 sym->val = strdup(val);
937 if (sym->val == NULL) {
938 free(sym->nam);
939 free(sym);
940 return (-1);
942 sym->used = 0;
943 sym->persist = persist;
944 TAILQ_INSERT_TAIL(&symhead, sym, entry);
945 return (0);
948 int
949 cmdline_symset(char *s)
951 char *sym, *val;
952 int ret;
954 val = strrchr(s, '=');
955 if (val == NULL)
956 return (-1);
958 sym = strndup(s, val - s);
959 if (sym == NULL)
960 fatal("%s: strndup", __func__);
962 ret = symset(sym, val + 1, 1);
963 free(sym);
965 return (ret);
968 char *
969 symget(const char *nam)
971 struct sym *sym;
973 TAILQ_FOREACH(sym, &symhead, entry) {
974 if (strcmp(nam, sym->nam) == 0) {
975 sym->used = 1;
976 return (sym->val);
979 return (NULL);
982 int
983 getservice(const char *n)
985 struct servent *s;
986 const char *errstr;
987 long long llval;
989 llval = strtonum(n, 0, UINT16_MAX, &errstr);
990 if (errstr) {
991 s = getservbyname(n, "tcp");
992 if (s == NULL)
993 s = getservbyname(n, "udp");
994 if (s == NULL)
995 return (-1);
996 return ntohs(s->s_port);
999 return (unsigned short)llval;
1002 struct address *
1003 host_v4(const char *s)
1005 struct in_addr ina;
1006 struct sockaddr_in *sain;
1007 struct address *h;
1009 memset(&ina, 0, sizeof(ina));
1010 if (inet_pton(AF_INET, s, &ina) != 1)
1011 return (NULL);
1013 if ((h = calloc(1, sizeof(*h))) == NULL)
1014 fatal(__func__);
1015 sain = (struct sockaddr_in *)&h->ss;
1016 got_sockaddr_inet_init(sain, &ina);
1017 if (sain->sin_addr.s_addr == INADDR_ANY)
1018 h->prefixlen = 0; /* 0.0.0.0 address */
1019 else
1020 h->prefixlen = -1; /* host address */
1021 return (h);
1024 struct address *
1025 host_v6(const char *s)
1027 struct addrinfo hints, *res;
1028 struct sockaddr_in6 *sa_in6, *ra;
1029 struct address *h = NULL;
1031 memset(&hints, 0, sizeof(hints));
1032 hints.ai_family = AF_INET6;
1033 hints.ai_socktype = SOCK_DGRAM; /* dummy */
1034 hints.ai_flags = AI_NUMERICHOST;
1035 if (getaddrinfo(s, "0", &hints, &res) == 0) {
1036 if ((h = calloc(1, sizeof(*h))) == NULL)
1037 fatal(__func__);
1038 sa_in6 = (struct sockaddr_in6 *)&h->ss;
1039 ra = (struct sockaddr_in6 *)res->ai_addr;
1040 got_sockaddr_inet6_init(sa_in6, &ra->sin6_addr,
1041 ra->sin6_scope_id);
1042 if (memcmp(&sa_in6->sin6_addr, &in6addr_any,
1043 sizeof(sa_in6->sin6_addr)) == 0)
1044 h->prefixlen = 0; /* any address */
1045 else
1046 h->prefixlen = -1; /* host address */
1047 freeaddrinfo(res);
1050 return (h);
1053 int
1054 host_dns(const char *s, struct server *new_srv, int max,
1055 in_port_t port, const char *ifname, int ipproto)
1057 struct addrinfo hints, *res0, *res;
1058 int error, cnt = 0;
1059 struct sockaddr_in *sain;
1060 struct sockaddr_in6 *sin6;
1061 struct address *h;
1063 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1064 return (cnt);
1066 memset(&hints, 0, sizeof(hints));
1067 hints.ai_family = PF_UNSPEC;
1068 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1069 hints.ai_flags = AI_ADDRCONFIG;
1070 error = getaddrinfo(s, NULL, &hints, &res0);
1071 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1072 return (0);
1073 if (error) {
1074 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1075 gai_strerror(error));
1076 return (-1);
1079 for (res = res0; res && cnt < max; res = res->ai_next) {
1080 if (res->ai_family != AF_INET &&
1081 res->ai_family != AF_INET6)
1082 continue;
1083 if ((h = calloc(1, sizeof(*h))) == NULL)
1084 fatal(__func__);
1086 if (port)
1087 h->port = port;
1088 if (ifname != NULL) {
1089 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1090 sizeof(h->ifname)) {
1091 log_warnx("%s: interface name truncated",
1092 __func__);
1093 freeaddrinfo(res0);
1094 free(h);
1095 return (-1);
1098 if (ipproto != -1)
1099 h->ipproto = ipproto;
1100 h->ss.ss_family = res->ai_family;
1101 h->prefixlen = -1; /* host address */
1103 if (res->ai_family == AF_INET) {
1104 struct sockaddr_in *ra;
1105 sain = (struct sockaddr_in *)&h->ss;
1106 ra = (struct sockaddr_in *)res->ai_addr;
1107 got_sockaddr_inet_init(sain, &ra->sin_addr);
1108 } else {
1109 struct sockaddr_in6 *ra;
1110 sin6 = (struct sockaddr_in6 *)&h->ss;
1111 ra = (struct sockaddr_in6 *)res->ai_addr;
1112 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1115 if (add_addr(new_srv, h))
1116 return -1;
1117 cnt++;
1119 if (cnt == max && res) {
1120 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1121 s, max);
1123 freeaddrinfo(res0);
1124 return (cnt);
1127 int
1128 host_if(const char *s, struct server *new_srv, int max,
1129 in_port_t port, const char *ifname, int ipproto)
1131 struct ifaddrs *ifap, *p;
1132 struct sockaddr_in *sain;
1133 struct sockaddr_in6 *sin6;
1134 struct address *h;
1135 int cnt = 0, af;
1137 if (getifaddrs(&ifap) == -1)
1138 fatal("getifaddrs");
1140 /* First search for IPv4 addresses */
1141 af = AF_INET;
1143 nextaf:
1144 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1145 if (p->ifa_addr == NULL ||
1146 p->ifa_addr->sa_family != af ||
1147 (strcmp(s, p->ifa_name) != 0 &&
1148 !is_if_in_group(p->ifa_name, s)))
1149 continue;
1150 if ((h = calloc(1, sizeof(*h))) == NULL)
1151 fatal("calloc");
1153 if (port)
1154 h->port = port;
1155 if (ifname != NULL) {
1156 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1157 sizeof(h->ifname)) {
1158 log_warnx("%s: interface name truncated",
1159 __func__);
1160 free(h);
1161 freeifaddrs(ifap);
1162 return (-1);
1165 if (ipproto != -1)
1166 h->ipproto = ipproto;
1167 h->ss.ss_family = af;
1168 h->prefixlen = -1; /* host address */
1170 if (af == AF_INET) {
1171 struct sockaddr_in *ra;
1172 sain = (struct sockaddr_in *)&h->ss;
1173 ra = (struct sockaddr_in *)p->ifa_addr;
1174 got_sockaddr_inet_init(sain, &ra->sin_addr);
1175 } else {
1176 struct sockaddr_in6 *ra;
1177 sin6 = (struct sockaddr_in6 *)&h->ss;
1178 ra = (struct sockaddr_in6 *)p->ifa_addr;
1179 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1180 ra->sin6_scope_id);
1183 if (add_addr(new_srv, h))
1184 return -1;
1185 cnt++;
1187 if (af == AF_INET) {
1188 /* Next search for IPv6 addresses */
1189 af = AF_INET6;
1190 goto nextaf;
1193 if (cnt > max) {
1194 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1195 s, max);
1197 freeifaddrs(ifap);
1198 return (cnt);
1201 int
1202 host(const char *s, struct server *new_srv, int max,
1203 in_port_t port, const char *ifname, int ipproto)
1205 struct address *h;
1207 h = host_v4(s);
1209 /* IPv6 address? */
1210 if (h == NULL)
1211 h = host_v6(s);
1213 if (h != NULL) {
1214 if (port)
1215 h->port = port;
1216 if (ifname != NULL) {
1217 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1218 sizeof(h->ifname)) {
1219 log_warnx("%s: interface name truncated",
1220 __func__);
1221 free(h);
1222 return (-1);
1225 if (ipproto != -1)
1226 h->ipproto = ipproto;
1228 if (add_addr(new_srv, h))
1229 return -1;
1230 return (1);
1233 return (host_dns(s, new_srv, max, port, ifname, ipproto));
1236 int
1237 is_if_in_group(const char *ifname, const char *groupname)
1239 unsigned int len;
1240 struct ifgroupreq ifgr;
1241 struct ifg_req *ifg;
1242 int s;
1243 int ret = 0;
1245 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1246 err(1, "socket");
1248 memset(&ifgr, 0, sizeof(ifgr));
1249 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1250 err(1, "IFNAMSIZ");
1251 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1252 if (errno == EINVAL || errno == ENOTTY)
1253 goto end;
1254 err(1, "SIOCGIFGROUP");
1257 len = ifgr.ifgr_len;
1258 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1259 sizeof(struct ifg_req));
1260 if (ifgr.ifgr_groups == NULL)
1261 err(1, "getifgroups");
1262 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1263 err(1, "SIOCGIFGROUP");
1265 ifg = ifgr.ifgr_groups;
1266 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1267 len -= sizeof(struct ifg_req);
1268 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1269 ret = 1;
1270 break;
1273 free(ifgr.ifgr_groups);
1275 end:
1276 close(s);
1277 return (ret);
1280 int
1281 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1283 if (strcmp("", addr) == 0) {
1284 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1285 -1) <= 0) {
1286 yyerror("invalid listen ip: %s",
1287 "127.0.0.1");
1288 return (-1);
1290 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1291 yyerror("invalid listen ip: %s", "::1");
1292 return (-1);
1294 } else {
1295 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1296 -1) <= 0) {
1297 yyerror("invalid listen ip: %s", addr);
1298 return (-1);
1301 return (0);
1304 int
1305 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1306 const char *other_srv)
1308 struct address *a;
1309 void *ia;
1310 char buf[INET6_ADDRSTRLEN];
1311 const char *addrstr;
1313 TAILQ_FOREACH(a, al, entry) {
1314 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1315 a->port != h->port)
1316 continue;
1318 switch (h->ss.ss_family) {
1319 case AF_INET:
1320 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1321 break;
1322 case AF_INET6:
1323 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1324 break;
1325 default:
1326 yyerror("unknown address family: %d", h->ss.ss_family);
1327 return -1;
1329 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1330 if (addrstr) {
1331 if (other_srv) {
1332 yyerror("server %s: duplicate fcgi listen "
1333 "address %s:%d, already used by server %s",
1334 new_srv, addrstr, h->port, other_srv);
1335 } else {
1336 log_warnx("server: %s: duplicate fcgi listen "
1337 "address %s:%d", new_srv, addrstr, h->port);
1339 } else {
1340 if (other_srv) {
1341 yyerror("server: %s: duplicate fcgi listen "
1342 "address, already used by server %s",
1343 new_srv, other_srv);
1344 } else {
1345 log_warnx("server %s: duplicate fcgi listen "
1346 "address", new_srv);
1350 return -1;
1353 return 0;
1356 int
1357 add_addr(struct server *new_srv, struct address *h)
1359 struct server *srv;
1361 /* Address cannot be shared between different servers. */
1362 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1363 if (srv == new_srv)
1364 continue;
1365 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1366 return -1;
1369 /* Tolerate duplicate address lines within the scope of a server. */
1370 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1371 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1372 else
1373 free(h);
1375 return 0;