2 * Copyright (c) 2022, 2023 Omar Polo <op@omarpolo.com>
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
37 static const struct option opts[] = {
38 {"help", no_argument, NULL, 'h'},
39 {"version", no_argument, NULL, 'V'},
44 log_request(struct client *c, int code, const char *meta)
46 char b[GEMINI_URL_LEN];
47 char cntmp[64], cn[64] = "-";
50 if (c->iri.schema != NULL) {
51 /* serialize the IRI */
52 strlcpy(b, c->iri.schema, sizeof(b));
53 strlcat(b, "://", sizeof(b));
55 /* log the decoded host name, but if it was invalid
57 if (*c->domain != '\0')
58 strlcat(b, c->domain, sizeof(b));
60 strlcat(b, c->iri.host, sizeof(b));
62 if (*c->iri.path != '/')
63 strlcat(b, "/", sizeof(b));
64 strlcat(b, c->iri.path, sizeof(b)); /* TODO: sanitize UTF8 */
65 if (*c->iri.query != '\0') { /* TODO: sanitize UTF8 */
66 strlcat(b, "?", sizeof(b));
67 strlcat(b, c->iri.query, sizeof(b));
70 if ((t = c->req) == NULL)
72 strlcpy(b, t, sizeof(b));
75 if (tls_peer_cert_provided(c->ctx)) {
79 subj = tls_peer_cert_subject(c->ctx);
80 if ((n = strstr(subj, "/CN=")) != NULL) {
81 strlcpy(cntmp, subj + 4, sizeof(cntmp));
82 if ((n = strchr(cntmp, '/')) != NULL)
84 strnvis(cn, cntmp, sizeof(cn), VIS_WHITE|VIS_DQ);
88 fprintf(stderr, "%s %s %s %s %d %s\n", c->rhost, cn,
89 *c->domain == '\0' ? c->iri.host : c->domain, b, code, meta);
93 load_local_cert(struct vhost *h, const char *hostname, const char *dir)
97 if (asprintf(&cert, "%s/%s.pem", dir, hostname) == -1)
99 if (asprintf(&key, "%s/%s.key", dir, hostname) == -1)
102 if (access(cert, R_OK) == -1 || access(key, R_OK) == -1)
103 gen_certificate(hostname, cert, key);
105 h->cert = tls_load_file(cert, &h->certlen, NULL);
107 fatal("can't load %s", cert);
109 h->key = tls_load_file(key, &h->keylen, NULL);
111 fatal("can't load %s", key);
113 strlcpy(h->domain, hostname, sizeof(h->domain));
116 /* wrapper around dirname(3). dn must be PATH_MAX+1 at least. */
118 pdirname(const char *path, char *dn)
123 strlcpy(p, path, sizeof(p));
125 memmove(dn, t, strlen(t)+1);
129 mkdirs(const char *path, mode_t mode)
131 char dname[PATH_MAX+1];
133 pdirname(path, dname);
134 if (!strcmp(dname, "/"))
137 if (mkdir(path, mode) != 0 && errno != EEXIST)
138 fatal("can't mkdir %s", path);
141 /* $XDG_DATA_HOME/gemexp */
145 const char *home, *xdg;
148 if ((xdg = getenv("XDG_DATA_HOME")) == NULL) {
149 if ((home = getenv("HOME")) == NULL)
150 fatalx("XDG_DATA_HOME and HOME both empty");
151 if (asprintf(&t, "%s/.local/share/gemexp", home) == -1)
154 if (asprintf(&t, "%s/gemexp", xdg) == -1)
163 serve(struct conf *conf, const char *host, int port, const char *dir)
165 struct addrinfo hints, *res, *res0;
166 struct vhost *vh = TAILQ_FIRST(&conf->hosts);
167 struct address *addr, *acp;
168 int r, error, saved_errno, sock = -1;
169 const char *cause = NULL;
175 r = snprintf(service, sizeof(service), "%d", port);
176 if (r < 0 || (size_t)r >= sizeof(service))
179 memset(&hints, 0, sizeof(hints));
180 hints.ai_family = AF_UNSPEC;
181 hints.ai_socktype = SOCK_STREAM;
182 hints.ai_flags = AI_PASSIVE;
183 error = getaddrinfo(host, service, &hints, &res0);
185 fatalx("%s", gai_strerror(error));
186 for (res = res0; res; res = res->ai_next) {
187 sock = socket(res->ai_family, res->ai_socktype,
194 if (bind(sock, res->ai_addr, res->ai_addrlen) == -1) {
202 if (listen(sock, 5) == -1)
207 addr = xcalloc(1, sizeof(*addr));
208 addr->ai_flags = res->ai_flags;
209 addr->ai_family = res->ai_family;
210 addr->ai_socktype = res->ai_socktype;
211 addr->ai_protocol = res->ai_protocol;
212 addr->slen = res->ai_addrlen;
213 memcpy(&addr->ss, res->ai_addr, res->ai_addrlen);
217 event_set(&addr->evsock, addr->sock, EV_READ|EV_PERSIST,
218 server_accept, addr);
220 if ((addr->ctx = tls_server()) == NULL)
221 fatal("tls_server failure");
223 TAILQ_INSERT_HEAD(&conf->addrs, addr, addrs);
225 acp = xcalloc(1, sizeof(*acp));
226 memcpy(acp, addr, sizeof(*acp));
228 memset(&acp->evsock, 0, sizeof(acp->evsock));
229 TAILQ_INSERT_HEAD(&vh->addrs, addr, addrs);
236 server_init(NULL, NULL, NULL);
237 if (server_configure_done(conf) == -1)
238 fatalx("server configuration failed");
240 log_info("serving %s on port %d", dir, port);
242 log_info("quitting");
250 "Version: " GE_STRING "\n"
251 "Usage: %s [-hV] [-d certs-dir] [-H hostname] [-p port] [dir]\n",
257 main(int argc, char **argv)
261 struct location *loc;
262 const char *errstr, *certs_dir = NULL, *hostname = "localhost";
266 setlocale(LC_CTYPE, "");
268 log_init(1, LOG_DAEMON);
272 /* ge doesn't do privsep so no privsep crypto engine. */
273 conf->use_privsep_crypto = 0;
275 while ((ch = getopt_long(argc, argv, "d:H:hp:V", opts, NULL)) != -1) {
287 port = strtonum(optarg, 0, UINT16_MAX, &errstr);
289 fatalx("port number is %s: %s", errstr,
293 puts("Version: " GE_STRING);
306 /* prepare the configuration */
307 init_mime(&conf->mime);
309 if (certs_dir == NULL)
310 certs_dir = data_dir();
312 /* set up the implicit vhost and location */
313 host = xcalloc(1, sizeof(*host));
314 TAILQ_INSERT_HEAD(&conf->hosts, host, vhosts);
316 loc = xcalloc(1, sizeof(*loc));
318 TAILQ_INSERT_HEAD(&host->locations, loc, locations);
320 load_local_cert(host, hostname, certs_dir);
322 strlcpy(host->domain, "*", sizeof(host->domain));
324 strlcpy(loc->match, "*", sizeof(loc->match));
327 if (getcwd(path, sizeof(path)) == NULL)
329 strlcpy(loc->dir, path, sizeof(loc->dir));
333 tmp = absolutify_path(*argv);
334 strlcpy(loc->dir, tmp, sizeof(loc->dir));
338 /* start the server */
339 signal(SIGPIPE, SIG_IGN);
340 setproctitle("%s", loc->dir);
341 return serve(conf, hostname, port, loc->dir);