Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <unistd.h>
50 #include "proc.h"
51 #include "gotwebd.h"
52 #include "got_sockaddr.h"
54 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
55 static struct file {
56 TAILQ_ENTRY(file) entry;
57 FILE *stream;
58 char *name;
59 int lineno;
60 int errors;
61 } *file;
62 struct file *newfile(const char *, int);
63 static void closefile(struct file *);
64 int check_file_secrecy(int, const char *);
65 int yyparse(void);
66 int yylex(void);
67 int yyerror(const char *, ...)
68 __attribute__((__format__ (printf, 1, 2)))
69 __attribute__((__nonnull__ (1)));
70 int kw_cmp(const void *, const void *);
71 int lookup(char *);
72 int lgetc(int);
73 int lungetc(int);
74 int findeol(void);
76 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
77 struct sym {
78 TAILQ_ENTRY(sym) entry;
79 int used;
80 int persist;
81 char *nam;
82 char *val;
83 };
85 int symset(const char *, const char *, int);
86 char *symget(const char *);
88 static int errors;
90 static struct gotwebd *gotwebd;
91 static struct server *new_srv;
92 static struct server *conf_new_server(const char *);
93 int getservice(const char *);
94 int n;
96 int get_addrs(const char *, struct addresslist *, in_port_t);
97 struct address *host_v4(const char *);
98 struct address *host_v6(const char *);
99 int host_dns(const char *, struct addresslist *,
100 int, in_port_t, const char *, int);
101 int host_if(const char *, struct addresslist *,
102 int, in_port_t, const char *, int);
103 int host(const char *, struct addresslist *,
104 int, in_port_t, const char *, int);
105 int is_if_in_group(const char *, const char *);
107 typedef struct {
108 union {
109 long long number;
110 char *string;
111 in_port_t port;
112 } v;
113 int lineno;
114 } YYSTYPE;
116 %}
118 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
119 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
120 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
121 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK FCGI_SOCKET
122 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS
124 %token <v.string> STRING
125 %type <v.port> fcgiport
126 %token <v.number> NUMBER
127 %type <v.number> boolean
129 %%
131 grammar :
132 | grammar '\n'
133 | grammar main '\n'
134 | grammar server '\n'
137 boolean : STRING {
138 if (strcasecmp($1, "1") == 0 ||
139 strcasecmp($1, "yes") == 0 ||
140 strcasecmp($1, "on") == 0)
141 $$ = 1;
142 else if (strcasecmp($1, "0") == 0 ||
143 strcasecmp($1, "off") == 0 ||
144 strcasecmp($1, "no") == 0)
145 $$ = 0;
146 else {
147 yyerror("invalid boolean value '%s'", $1);
148 free($1);
149 YYERROR;
151 free($1);
153 | ON { $$ = 1; }
154 | NUMBER { $$ = $1; }
157 fcgiport : NUMBER {
158 if ($1 <= 0 || $1 > (int)USHRT_MAX) {
159 yyerror("invalid port: %lld", $1);
160 YYERROR;
162 $$ = htons($1);
164 | STRING {
165 int val;
167 if ((val = getservice($1)) == -1) {
168 yyerror("invalid port: %s", $1);
169 free($1);
170 YYERROR;
172 free($1);
174 $$ = val;
178 main : PREFORK NUMBER {
179 gotwebd->prefork_gotwebd = $2;
181 | CHROOT STRING {
182 n = strlcpy(gotwebd->httpd_chroot, $2,
183 sizeof(gotwebd->httpd_chroot));
184 if (n >= sizeof(gotwebd->httpd_chroot)) {
185 yyerror("%s: httpd_chroot truncated", __func__);
186 free($2);
187 YYERROR;
189 free($2);
191 | FCGI_SOCKET boolean {
192 gotwebd->fcgi_socket = $2;
194 | FCGI_SOCKET boolean {
195 gotwebd->fcgi_socket = $2;
196 } '{' optnl socketopts4 '}'
197 | UNIX_SOCKET boolean {
198 gotwebd->unix_socket = $2;
200 | UNIX_SOCKET_NAME STRING {
201 n = snprintf(gotwebd->unix_socket_name,
202 sizeof(gotwebd->unix_socket_name), "%s%s",
203 strlen(gotwebd->httpd_chroot) ?
204 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
205 if (n < 0 ||
206 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
207 yyerror("%s: unix_socket_name truncated",
208 __func__);
209 free($2);
210 YYERROR;
212 free($2);
216 server : SERVER STRING {
217 struct server *srv;
219 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
220 if (strcmp(srv->name, $2) == 0) {
221 yyerror("server name exists '%s'", $2);
222 free($2);
223 YYERROR;
227 new_srv = conf_new_server($2);
228 if (new_srv->fcgi_socket)
229 if (get_addrs(new_srv->fcgi_socket_bind,
230 &new_srv->al,
231 new_srv->fcgi_socket_port) == -1) {
232 yyerror("could not get tcp iface "
233 "addrs");
234 YYERROR;
236 log_debug("adding server %s", $2);
237 free($2);
239 | SERVER STRING {
240 struct server *srv;
242 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
243 if (strcmp(srv->name, $2) == 0) {
244 yyerror("server name exists '%s'", $2);
245 free($2);
246 YYERROR;
250 new_srv = conf_new_server($2);
251 log_debug("adding server %s", $2);
252 free($2);
253 } '{' optnl serveropts2 '}' {
254 if (new_srv->fcgi_socket) {
255 if (get_addrs(new_srv->fcgi_socket_bind,
256 &new_srv->al, new_srv->fcgi_socket_port)
257 == -1) {
258 yyerror("could not get tcp iface addr");
259 YYERROR;
265 serveropts1 : REPOS_PATH STRING {
266 n = strlcpy(new_srv->repos_path, $2,
267 sizeof(new_srv->repos_path));
268 if (n >= sizeof(new_srv->repos_path)) {
269 yyerror("%s: repos_path truncated", __func__);
270 free($2);
271 YYERROR;
273 free($2);
275 | SITE_NAME STRING {
276 n = strlcpy(new_srv->site_name, $2,
277 sizeof(new_srv->site_name));
278 if (n >= sizeof(new_srv->site_name)) {
279 yyerror("%s: site_name truncated", __func__);
280 free($2);
281 YYERROR;
283 free($2);
285 | SITE_OWNER STRING {
286 n = strlcpy(new_srv->site_owner, $2,
287 sizeof(new_srv->site_owner));
288 if (n >= sizeof(new_srv->site_owner)) {
289 yyerror("%s: site_owner truncated", __func__);
290 free($2);
291 YYERROR;
293 free($2);
295 | SITE_LINK STRING {
296 n = strlcpy(new_srv->site_link, $2,
297 sizeof(new_srv->site_link));
298 if (n >= sizeof(new_srv->site_link)) {
299 yyerror("%s: site_link truncated", __func__);
300 free($2);
301 YYERROR;
303 free($2);
305 | LOGO STRING {
306 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
307 if (n >= sizeof(new_srv->logo)) {
308 yyerror("%s: logo truncated", __func__);
309 free($2);
310 YYERROR;
312 free($2);
314 | LOGO_URL STRING {
315 n = strlcpy(new_srv->logo_url, $2,
316 sizeof(new_srv->logo_url));
317 if (n >= sizeof(new_srv->logo_url)) {
318 yyerror("%s: logo_url truncated", __func__);
319 free($2);
320 YYERROR;
322 free($2);
324 | CUSTOM_CSS STRING {
325 n = strlcpy(new_srv->custom_css, $2,
326 sizeof(new_srv->custom_css));
327 if (n >= sizeof(new_srv->custom_css)) {
328 yyerror("%s: custom_css truncated", __func__);
329 free($2);
330 YYERROR;
332 free($2);
334 | MAX_REPOS NUMBER {
335 if ($2 > 0)
336 new_srv->max_repos = $2;
338 | SHOW_SITE_OWNER boolean {
339 new_srv->show_site_owner = $2;
341 | SHOW_REPO_OWNER boolean {
342 new_srv->show_repo_owner = $2;
344 | SHOW_REPO_AGE boolean {
345 new_srv->show_repo_age = $2;
347 | SHOW_REPO_DESCRIPTION boolean {
348 new_srv->show_repo_description = $2;
350 | SHOW_REPO_CLONEURL boolean {
351 new_srv->show_repo_cloneurl = $2;
353 | MAX_REPOS_DISPLAY NUMBER {
354 new_srv->max_repos_display = $2;
356 | MAX_COMMITS_DISPLAY NUMBER {
357 if ($2 > 0)
358 new_srv->max_commits_display = $2;
360 | FCGI_SOCKET boolean {
361 new_srv->fcgi_socket = $2;
363 | FCGI_SOCKET boolean {
364 new_srv->fcgi_socket = $2;
365 } '{' optnl socketopts2 '}'
366 | UNIX_SOCKET boolean {
367 new_srv->unix_socket = $2;
369 | UNIX_SOCKET_NAME STRING {
370 n = snprintf(new_srv->unix_socket_name,
371 sizeof(new_srv->unix_socket_name), "%s%s",
372 strlen(gotwebd->httpd_chroot) ?
373 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
374 if (n < 0 ||
375 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
376 yyerror("%s: unix_socket_name truncated",
377 __func__);
378 free($2);
379 YYERROR;
381 free($2);
385 serveropts2 : serveropts2 serveropts1 nl
386 | serveropts1 optnl
389 socketopts1 : LISTEN ON STRING {
390 n = strlcpy(new_srv->fcgi_socket_bind, $3,
391 sizeof(new_srv->fcgi_socket_bind));
392 if (n >= sizeof(new_srv->fcgi_socket_bind)) {
393 yyerror("%s: fcgi_socket_bind truncated",
394 __func__);
395 free($3);
396 YYERROR;
398 free($3);
400 | PORT fcgiport {
401 struct server *srv;
403 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
404 if (srv->fcgi_socket_port == $2) {
405 yyerror("port already assigned");
406 YYERROR;
409 new_srv->fcgi_socket_port = $2;
413 socketopts2 : socketopts2 socketopts1 nl
414 | socketopts1 optnl
417 socketopts3 : LISTEN ON STRING {
418 n = strlcpy(gotwebd->fcgi_socket_bind, $3,
419 sizeof(gotwebd->fcgi_socket_bind));
420 if (n >= sizeof(gotwebd->fcgi_socket_bind)) {
421 yyerror("%s: fcgi_socket_bind truncated",
422 __func__);
423 free($3);
424 YYERROR;
426 free($3);
428 | PORT fcgiport {
429 gotwebd->fcgi_socket_port = $2;
433 socketopts4 : socketopts4 socketopts3 nl
434 | socketopts3 optnl
437 nl : '\n' optnl
440 optnl : '\n' optnl /* zero or more newlines */
441 | /* empty */
444 %%
446 struct keywords {
447 const char *k_name;
448 int k_val;
449 };
451 int
452 yyerror(const char *fmt, ...)
454 va_list ap;
455 char *msg;
457 file->errors++;
458 va_start(ap, fmt);
459 if (vasprintf(&msg, fmt, ap) == -1)
460 fatalx("yyerror vasprintf");
461 va_end(ap);
462 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
463 free(msg);
464 return (0);
467 int
468 kw_cmp(const void *k, const void *e)
470 return (strcmp(k, ((const struct keywords *)e)->k_name));
473 int
474 lookup(char *s)
476 /* This has to be sorted always. */
477 static const struct keywords keywords[] = {
478 { "chroot", CHROOT },
479 { "custom_css", CUSTOM_CSS },
480 { "fcgi_socket", FCGI_SOCKET },
481 { "listen", LISTEN },
482 { "logo", LOGO },
483 { "logo_url" , LOGO_URL },
484 { "max_commits_display", MAX_COMMITS_DISPLAY },
485 { "max_repos", MAX_REPOS },
486 { "max_repos_display", MAX_REPOS_DISPLAY },
487 { "on", ON },
488 { "port", PORT },
489 { "prefork", PREFORK },
490 { "repos_path", REPOS_PATH },
491 { "server", SERVER },
492 { "show_repo_age", SHOW_REPO_AGE },
493 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
494 { "show_repo_description", SHOW_REPO_DESCRIPTION },
495 { "show_repo_owner", SHOW_REPO_OWNER },
496 { "show_site_owner", SHOW_SITE_OWNER },
497 { "site_link", SITE_LINK },
498 { "site_name", SITE_NAME },
499 { "site_owner", SITE_OWNER },
500 { "unix_socket", UNIX_SOCKET },
501 { "unix_socket_name", UNIX_SOCKET_NAME },
502 };
503 const struct keywords *p;
505 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
506 sizeof(keywords[0]), kw_cmp);
508 if (p)
509 return (p->k_val);
510 else
511 return (STRING);
514 #define MAXPUSHBACK 128
516 unsigned char *parsebuf;
517 int parseindex;
518 unsigned char pushback_buffer[MAXPUSHBACK];
519 int pushback_index = 0;
521 int
522 lgetc(int quotec)
524 int c, next;
526 if (parsebuf) {
527 /* Read character from the parsebuffer instead of input. */
528 if (parseindex >= 0) {
529 c = parsebuf[parseindex++];
530 if (c != '\0')
531 return (c);
532 parsebuf = NULL;
533 } else
534 parseindex++;
537 if (pushback_index)
538 return (pushback_buffer[--pushback_index]);
540 if (quotec) {
541 c = getc(file->stream);
542 if (c == EOF)
543 yyerror("reached end of file while parsing "
544 "quoted string");
545 return (c);
548 c = getc(file->stream);
549 while (c == '\\') {
550 next = getc(file->stream);
551 if (next != '\n') {
552 c = next;
553 break;
555 yylval.lineno = file->lineno;
556 file->lineno++;
557 c = getc(file->stream);
560 return (c);
563 int
564 lungetc(int c)
566 if (c == EOF)
567 return (EOF);
568 if (parsebuf) {
569 parseindex--;
570 if (parseindex >= 0)
571 return (c);
573 if (pushback_index < MAXPUSHBACK-1)
574 return (pushback_buffer[pushback_index++] = c);
575 else
576 return (EOF);
579 int
580 findeol(void)
582 int c;
584 parsebuf = NULL;
586 /* Skip to either EOF or the first real EOL. */
587 while (1) {
588 if (pushback_index)
589 c = pushback_buffer[--pushback_index];
590 else
591 c = lgetc(0);
592 if (c == '\n') {
593 file->lineno++;
594 break;
596 if (c == EOF)
597 break;
599 return (ERROR);
602 int
603 yylex(void)
605 unsigned char buf[8096];
606 unsigned char *p, *val;
607 int quotec, next, c;
608 int token;
610 top:
611 p = buf;
612 c = lgetc(0);
613 while (c == ' ' || c == '\t')
614 c = lgetc(0); /* nothing */
616 yylval.lineno = file->lineno;
617 if (c == '#') {
618 c = lgetc(0);
619 while (c != '\n' && c != EOF)
620 c = lgetc(0); /* nothing */
622 if (c == '$' && parsebuf == NULL) {
623 while (1) {
624 c = lgetc(0);
625 if (c == EOF)
626 return (0);
628 if (p + 1 >= buf + sizeof(buf) - 1) {
629 yyerror("string too long");
630 return (findeol());
632 if (isalnum(c) || c == '_') {
633 *p++ = c;
634 continue;
636 *p = '\0';
637 lungetc(c);
638 break;
640 val = symget(buf);
641 if (val == NULL) {
642 yyerror("macro '%s' not defined", buf);
643 return (findeol());
645 parsebuf = val;
646 parseindex = 0;
647 goto top;
650 switch (c) {
651 case '\'':
652 case '"':
653 quotec = c;
654 while (1) {
655 c = lgetc(quotec);
656 if (c == EOF)
657 return (0);
658 if (c == '\n') {
659 file->lineno++;
660 continue;
661 } else if (c == '\\') {
662 next = lgetc(quotec);
663 if (next == EOF)
664 return (0);
665 if (next == quotec || c == ' ' || c == '\t')
666 c = next;
667 else if (next == '\n') {
668 file->lineno++;
669 continue;
670 } else
671 lungetc(next);
672 } else if (c == quotec) {
673 *p = '\0';
674 break;
675 } else if (c == '\0') {
676 yyerror("syntax error");
677 return (findeol());
679 if (p + 1 >= buf + sizeof(buf) - 1) {
680 yyerror("string too long");
681 return (findeol());
683 *p++ = c;
685 yylval.v.string = strdup(buf);
686 if (yylval.v.string == NULL)
687 err(1, "yylex: strdup");
688 return (STRING);
691 #define allowed_to_end_number(x) \
692 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
694 if (c == '-' || isdigit(c)) {
695 do {
696 *p++ = c;
697 if ((unsigned)(p-buf) >= sizeof(buf)) {
698 yyerror("string too long");
699 return (findeol());
701 c = lgetc(0);
702 } while (c != EOF && isdigit(c));
703 lungetc(c);
704 if (p == buf + 1 && buf[0] == '-')
705 goto nodigits;
706 if (c == EOF || allowed_to_end_number(c)) {
707 const char *errstr = NULL;
709 *p = '\0';
710 yylval.v.number = strtonum(buf, LLONG_MIN,
711 LLONG_MAX, &errstr);
712 if (errstr) {
713 yyerror("\"%s\" invalid number: %s",
714 buf, errstr);
715 return (findeol());
717 return (NUMBER);
718 } else {
719 nodigits:
720 while (p > buf + 1)
721 lungetc(*--p);
722 c = *--p;
723 if (c == '-')
724 return (c);
728 #define allowed_in_string(x) \
729 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
730 x != '{' && x != '}' && \
731 x != '!' && x != '=' && x != '#' && \
732 x != ','))
734 if (isalnum(c) || c == ':' || c == '_') {
735 do {
736 *p++ = c;
737 if ((unsigned)(p-buf) >= sizeof(buf)) {
738 yyerror("string too long");
739 return (findeol());
741 c = lgetc(0);
742 } while (c != EOF && (allowed_in_string(c)));
743 lungetc(c);
744 *p = '\0';
745 token = lookup(buf);
746 if (token == STRING) {
747 yylval.v.string = strdup(buf);
748 if (yylval.v.string == NULL)
749 err(1, "yylex: strdup");
751 return (token);
753 if (c == '\n') {
754 yylval.lineno = file->lineno;
755 file->lineno++;
757 if (c == EOF)
758 return (0);
759 return (c);
762 int
763 check_file_secrecy(int fd, const char *fname)
765 struct stat st;
767 if (fstat(fd, &st)) {
768 log_warn("cannot stat %s", fname);
769 return (-1);
771 if (st.st_uid != 0 && st.st_uid != getuid()) {
772 log_warnx("%s: owner not root or current user", fname);
773 return (-1);
775 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
776 log_warnx("%s: group writable or world read/writable", fname);
777 return (-1);
779 return (0);
782 struct file *
783 newfile(const char *name, int secret)
785 struct file *nfile;
787 nfile = calloc(1, sizeof(struct file));
788 if (nfile == NULL) {
789 log_warn("calloc");
790 return (NULL);
792 nfile->name = strdup(name);
793 if (nfile->name == NULL) {
794 log_warn("strdup");
795 free(nfile);
796 return (NULL);
798 nfile->stream = fopen(nfile->name, "r");
799 if (nfile->stream == NULL) {
800 /* no warning, we don't require a conf file */
801 free(nfile->name);
802 free(nfile);
803 return (NULL);
804 } else if (secret &&
805 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
806 fclose(nfile->stream);
807 free(nfile->name);
808 free(nfile);
809 return (NULL);
811 nfile->lineno = 1;
812 return (nfile);
815 static void
816 closefile(struct file *xfile)
818 fclose(xfile->stream);
819 free(xfile->name);
820 free(xfile);
823 static void
824 add_default_server(void)
826 new_srv = conf_new_server(D_SITENAME);
827 log_debug("%s: adding default server %s", __func__, D_SITENAME);
830 int
831 parse_config(const char *filename, struct gotwebd *env)
833 struct sym *sym, *next;
835 if (config_init(env) == -1)
836 fatalx("failed to initialize configuration");
838 gotwebd = env;
840 file = newfile(filename, 0);
841 if (file == NULL) {
842 add_default_server();
843 sockets_parse_sockets(env);
844 /* just return, as we don't require a conf file */
845 return (0);
848 yyparse();
849 errors = file->errors;
850 closefile(file);
852 /* Free macros and check which have not been used. */
853 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
854 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
855 fprintf(stderr, "warning: macro '%s' not used\n",
856 sym->nam);
857 if (!sym->persist) {
858 free(sym->nam);
859 free(sym->val);
860 TAILQ_REMOVE(&symhead, sym, entry);
861 free(sym);
865 if (errors)
866 return (-1);
868 /* just add default server if no config specified */
869 if (gotwebd->server_cnt == 0)
870 add_default_server();
872 /* setup our listening sockets */
873 sockets_parse_sockets(env);
875 return (0);
878 struct server *
879 conf_new_server(const char *name)
881 struct server *srv = NULL;
882 int val;
884 srv = calloc(1, sizeof(*srv));
885 if (srv == NULL)
886 fatalx("%s: calloc", __func__);
888 n = strlcpy(srv->name, name, sizeof(srv->name));
889 if (n >= sizeof(srv->name))
890 fatalx("%s: strlcpy", __func__);
891 n = snprintf(srv->unix_socket_name,
892 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
893 D_UNIX_SOCKET);
894 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
895 fatalx("%s: snprintf", __func__);
896 n = strlcpy(srv->repos_path, D_GOTPATH,
897 sizeof(srv->repos_path));
898 if (n >= sizeof(srv->repos_path))
899 fatalx("%s: strlcpy", __func__);
900 n = strlcpy(srv->site_name, D_SITENAME,
901 sizeof(srv->site_name));
902 if (n >= sizeof(srv->site_name))
903 fatalx("%s: strlcpy", __func__);
904 n = strlcpy(srv->site_owner, D_SITEOWNER,
905 sizeof(srv->site_owner));
906 if (n >= sizeof(srv->site_owner))
907 fatalx("%s: strlcpy", __func__);
908 n = strlcpy(srv->site_link, D_SITELINK,
909 sizeof(srv->site_link));
910 if (n >= sizeof(srv->site_link))
911 fatalx("%s: strlcpy", __func__);
912 n = strlcpy(srv->logo, D_GOTLOGO,
913 sizeof(srv->logo));
914 if (n >= sizeof(srv->logo))
915 fatalx("%s: strlcpy", __func__);
916 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
917 if (n >= sizeof(srv->logo_url))
918 fatalx("%s: strlcpy", __func__);
919 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
920 if (n >= sizeof(srv->custom_css))
921 fatalx("%s: strlcpy", __func__);
923 val = getservice(D_FCGI_PORT);
924 srv->fcgi_socket_port = gotwebd->fcgi_socket_port ?
925 gotwebd->fcgi_socket_port: htons(val);
927 srv->show_site_owner = D_SHOWSOWNER;
928 srv->show_repo_owner = D_SHOWROWNER;
929 srv->show_repo_age = D_SHOWAGE;
930 srv->show_repo_description = D_SHOWDESC;
931 srv->show_repo_cloneurl = D_SHOWURL;
933 srv->max_repos_display = D_MAXREPODISP;
934 srv->max_commits_display = D_MAXCOMMITDISP;
935 srv->max_repos = D_MAXREPO;
937 srv->unix_socket = 1;
938 srv->fcgi_socket = gotwebd->fcgi_socket ? gotwebd->fcgi_socket : 0;
940 TAILQ_INIT(&srv->al);
941 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
942 gotwebd->server_cnt++;
944 return srv;
945 };
947 int
948 symset(const char *nam, const char *val, int persist)
950 struct sym *sym;
952 TAILQ_FOREACH(sym, &symhead, entry) {
953 if (strcmp(nam, sym->nam) == 0)
954 break;
957 if (sym != NULL) {
958 if (sym->persist == 1)
959 return (0);
960 else {
961 free(sym->nam);
962 free(sym->val);
963 TAILQ_REMOVE(&symhead, sym, entry);
964 free(sym);
967 sym = calloc(1, sizeof(*sym));
968 if (sym == NULL)
969 return (-1);
971 sym->nam = strdup(nam);
972 if (sym->nam == NULL) {
973 free(sym);
974 return (-1);
976 sym->val = strdup(val);
977 if (sym->val == NULL) {
978 free(sym->nam);
979 free(sym);
980 return (-1);
982 sym->used = 0;
983 sym->persist = persist;
984 TAILQ_INSERT_TAIL(&symhead, sym, entry);
985 return (0);
988 int
989 cmdline_symset(char *s)
991 char *sym, *val;
992 int ret;
993 size_t len;
995 val = strrchr(s, '=');
996 if (val == NULL)
997 return (-1);
999 len = strlen(s) - strlen(val) + 1;
1000 sym = malloc(len);
1001 if (sym == NULL)
1002 fatal("%s: malloc", __func__);
1004 memcpy(&sym, s, len);
1006 ret = symset(sym, val + 1, 1);
1007 free(sym);
1009 return (ret);
1012 char *
1013 symget(const char *nam)
1015 struct sym *sym;
1017 TAILQ_FOREACH(sym, &symhead, entry) {
1018 if (strcmp(nam, sym->nam) == 0) {
1019 sym->used = 1;
1020 return (sym->val);
1023 return (NULL);
1026 int
1027 getservice(const char *n)
1029 struct servent *s;
1030 const char *errstr;
1031 long long llval;
1033 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1034 if (errstr) {
1035 s = getservbyname(n, "tcp");
1036 if (s == NULL)
1037 s = getservbyname(n, "udp");
1038 if (s == NULL)
1039 return (-1);
1040 return (s->s_port);
1043 return (htons((unsigned short)llval));
1046 struct address *
1047 host_v4(const char *s)
1049 struct in_addr ina;
1050 struct sockaddr_in *sain;
1051 struct address *h;
1053 memset(&ina, 0, sizeof(ina));
1054 if (inet_pton(AF_INET, s, &ina) != 1)
1055 return (NULL);
1057 if ((h = calloc(1, sizeof(*h))) == NULL)
1058 fatal(__func__);
1059 sain = (struct sockaddr_in *)&h->ss;
1060 got_sockaddr_inet_init(sain, &ina);
1061 if (sain->sin_addr.s_addr == INADDR_ANY)
1062 h->prefixlen = 0; /* 0.0.0.0 address */
1063 else
1064 h->prefixlen = -1; /* host address */
1065 return (h);
1068 struct address *
1069 host_v6(const char *s)
1071 struct addrinfo hints, *res;
1072 struct sockaddr_in6 *sa_in6, *ra;
1073 struct address *h = NULL;
1075 memset(&hints, 0, sizeof(hints));
1076 hints.ai_family = AF_INET6;
1077 hints.ai_socktype = SOCK_DGRAM; /* dummy */
1078 hints.ai_flags = AI_NUMERICHOST;
1079 if (getaddrinfo(s, "0", &hints, &res) == 0) {
1080 if ((h = calloc(1, sizeof(*h))) == NULL)
1081 fatal(__func__);
1082 sa_in6 = (struct sockaddr_in6 *)&h->ss;
1083 ra = (struct sockaddr_in6 *)res->ai_addr;
1084 got_sockaddr_inet6_init(sa_in6, &ra->sin6_addr,
1085 ra->sin6_scope_id);
1086 if (memcmp(&sa_in6->sin6_addr, &in6addr_any,
1087 sizeof(sa_in6->sin6_addr)) == 0)
1088 h->prefixlen = 0; /* any address */
1089 else
1090 h->prefixlen = -1; /* host address */
1091 freeaddrinfo(res);
1094 return (h);
1097 int
1098 host_dns(const char *s, struct addresslist *al, int max,
1099 in_port_t port, const char *ifname, int ipproto)
1101 struct addrinfo hints, *res0, *res;
1102 int error, cnt = 0;
1103 struct sockaddr_in *sain;
1104 struct sockaddr_in6 *sin6;
1105 struct address *h;
1107 if ((cnt = host_if(s, al, max, port, ifname, ipproto)) != 0)
1108 return (cnt);
1110 memset(&hints, 0, sizeof(hints));
1111 hints.ai_family = PF_UNSPEC;
1112 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1113 hints.ai_flags = AI_ADDRCONFIG;
1114 error = getaddrinfo(s, NULL, &hints, &res0);
1115 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1116 return (0);
1117 if (error) {
1118 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1119 gai_strerror(error));
1120 return (-1);
1123 for (res = res0; res && cnt < max; res = res->ai_next) {
1124 if (res->ai_family != AF_INET &&
1125 res->ai_family != AF_INET6)
1126 continue;
1127 if ((h = calloc(1, sizeof(*h))) == NULL)
1128 fatal(__func__);
1130 if (port)
1131 h->port = port;
1132 if (ifname != NULL) {
1133 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1134 sizeof(h->ifname)) {
1135 log_warnx("%s: interface name truncated",
1136 __func__);
1137 freeaddrinfo(res0);
1138 free(h);
1139 return (-1);
1142 if (ipproto != -1)
1143 h->ipproto = ipproto;
1144 h->ss.ss_family = res->ai_family;
1145 h->prefixlen = -1; /* host address */
1147 if (res->ai_family == AF_INET) {
1148 struct sockaddr_in *ra;
1149 sain = (struct sockaddr_in *)&h->ss;
1150 ra = (struct sockaddr_in *)res->ai_addr;
1151 got_sockaddr_inet_init(sain, &ra->sin_addr);
1152 } else {
1153 struct sockaddr_in6 *ra;
1154 sin6 = (struct sockaddr_in6 *)&h->ss;
1155 ra = (struct sockaddr_in6 *)res->ai_addr;
1156 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1159 TAILQ_INSERT_HEAD(al, h, entry);
1160 cnt++;
1162 if (cnt == max && res) {
1163 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1164 s, max);
1166 freeaddrinfo(res0);
1167 return (cnt);
1170 int
1171 host_if(const char *s, struct addresslist *al, int max,
1172 in_port_t port, const char *ifname, int ipproto)
1174 struct ifaddrs *ifap, *p;
1175 struct sockaddr_in *sain;
1176 struct sockaddr_in6 *sin6;
1177 struct address *h;
1178 int cnt = 0, af;
1180 if (getifaddrs(&ifap) == -1)
1181 fatal("getifaddrs");
1183 /* First search for IPv4 addresses */
1184 af = AF_INET;
1186 nextaf:
1187 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1188 if (p->ifa_addr == NULL ||
1189 p->ifa_addr->sa_family != af ||
1190 (strcmp(s, p->ifa_name) != 0 &&
1191 !is_if_in_group(p->ifa_name, s)))
1192 continue;
1193 if ((h = calloc(1, sizeof(*h))) == NULL)
1194 fatal("calloc");
1196 if (port)
1197 h->port = port;
1198 if (ifname != NULL) {
1199 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1200 sizeof(h->ifname)) {
1201 log_warnx("%s: interface name truncated",
1202 __func__);
1203 free(h);
1204 freeifaddrs(ifap);
1205 return (-1);
1208 if (ipproto != -1)
1209 h->ipproto = ipproto;
1210 h->ss.ss_family = af;
1211 h->prefixlen = -1; /* host address */
1213 if (af == AF_INET) {
1214 struct sockaddr_in *ra;
1215 sain = (struct sockaddr_in *)&h->ss;
1216 ra = (struct sockaddr_in *)p->ifa_addr;
1217 got_sockaddr_inet_init(sain, &ra->sin_addr);
1218 } else {
1219 struct sockaddr_in6 *ra;
1220 sin6 = (struct sockaddr_in6 *)&h->ss;
1221 ra = (struct sockaddr_in6 *)p->ifa_addr;
1222 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1223 ra->sin6_scope_id);
1226 TAILQ_INSERT_HEAD(al, h, entry);
1227 cnt++;
1229 if (af == AF_INET) {
1230 /* Next search for IPv6 addresses */
1231 af = AF_INET6;
1232 goto nextaf;
1235 if (cnt > max) {
1236 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1237 s, max);
1239 freeifaddrs(ifap);
1240 return (cnt);
1243 int
1244 host(const char *s, struct addresslist *al, int max,
1245 in_port_t port, const char *ifname, int ipproto)
1247 struct address *h;
1249 h = host_v4(s);
1251 /* IPv6 address? */
1252 if (h == NULL)
1253 h = host_v6(s);
1255 if (h != NULL) {
1256 if (port)
1257 h->port = port;
1258 if (ifname != NULL) {
1259 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1260 sizeof(h->ifname)) {
1261 log_warnx("%s: interface name truncated",
1262 __func__);
1263 free(h);
1264 return (-1);
1267 if (ipproto != -1)
1268 h->ipproto = ipproto;
1270 TAILQ_INSERT_HEAD(al, h, entry);
1271 return (1);
1274 return (host_dns(s, al, max, port, ifname, ipproto));
1277 int
1278 is_if_in_group(const char *ifname, const char *groupname)
1280 unsigned int len;
1281 struct ifgroupreq ifgr;
1282 struct ifg_req *ifg;
1283 int s;
1284 int ret = 0;
1286 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1287 err(1, "socket");
1289 memset(&ifgr, 0, sizeof(ifgr));
1290 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1291 err(1, "IFNAMSIZ");
1292 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1293 if (errno == EINVAL || errno == ENOTTY)
1294 goto end;
1295 err(1, "SIOCGIFGROUP");
1298 len = ifgr.ifgr_len;
1299 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1300 sizeof(struct ifg_req));
1301 if (ifgr.ifgr_groups == NULL)
1302 err(1, "getifgroups");
1303 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1304 err(1, "SIOCGIFGROUP");
1306 ifg = ifgr.ifgr_groups;
1307 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1308 len -= sizeof(struct ifg_req);
1309 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1310 ret = 1;
1311 break;
1314 free(ifgr.ifgr_groups);
1316 end:
1317 close(s);
1318 return (ret);
1321 int
1322 get_addrs(const char *addr, struct addresslist *al, in_port_t port)
1324 if (strcmp("", addr) == 0) {
1325 if (host("0.0.0.0", al, 1, port, "0.0.0.0", -1) <= 0) {
1326 yyerror("invalid listen ip: %s",
1327 "0.0.0.0");
1328 return (-1);
1330 if (host("::", al, 1, port, "::", -1) <= 0) {
1331 yyerror("invalid listen ip: %s", "::");
1332 return (-1);
1334 } else {
1335 if (host(addr, al, GOTWEBD_MAXIFACE, port, addr,
1336 -1) <= 0) {
1337 yyerror("invalid listen ip: %s", addr);
1338 return (-1);
1341 return (0);