Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <tls.h>
49 #include <unistd.h>
51 #include "proc.h"
52 #include "gotwebd.h"
54 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
55 static struct file {
56 TAILQ_ENTRY(file) entry;
57 FILE *stream;
58 char *name;
59 int lineno;
60 int errors;
61 } *file;
62 struct file *newfile(const char *, int);
63 static void closefile(struct file *);
64 int check_file_secrecy(int, const char *);
65 int yyparse(void);
66 int yylex(void);
67 int yyerror(const char *, ...)
68 __attribute__((__format__ (printf, 1, 2)))
69 __attribute__((__nonnull__ (1)));
70 int kw_cmp(const void *, const void *);
71 int lookup(char *);
72 int lgetc(int);
73 int lungetc(int);
74 int findeol(void);
76 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
77 struct sym {
78 TAILQ_ENTRY(sym) entry;
79 int used;
80 int persist;
81 char *nam;
82 char *val;
83 };
85 int symset(const char *, const char *, int);
86 char *symget(const char *);
88 static int errors;
90 static struct gotwebd *gotwebd;
91 static struct server *new_srv;
92 static struct server *conf_new_server(const char *);
93 int getservice(const char *);
94 int n;
96 int get_addrs(const char *, struct addresslist *, in_port_t);
97 struct address *host_v4(const char *);
98 struct address *host_v6(const char *);
99 int host_dns(const char *, struct addresslist *,
100 int, in_port_t, const char *, int);
101 int host_if(const char *, struct addresslist *,
102 int, in_port_t, const char *, int);
103 int host(const char *, struct addresslist *,
104 int, in_port_t, const char *, int);
105 int is_if_in_group(const char *, const char *);
107 typedef struct {
108 union {
109 long long number;
110 char *string;
111 in_port_t port;
112 } v;
113 int lineno;
114 } YYSTYPE;
116 %}
118 %token BIND INTERFACE WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
119 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
120 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
121 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK FCGI_SOCKET
122 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS
124 %token <v.string> STRING
125 %type <v.port> fcgiport
126 %token <v.number> NUMBER
127 %type <v.number> boolean
129 %%
131 grammar :
132 | grammar '\n'
133 | grammar main '\n'
134 | grammar server '\n'
137 boolean : STRING {
138 if (strcasecmp($1, "1") == 0 ||
139 strcasecmp($1, "yes") == 0 ||
140 strcasecmp($1, "on") == 0)
141 $$ = 1;
142 else if (strcasecmp($1, "0") == 0 ||
143 strcasecmp($1, "off") == 0 ||
144 strcasecmp($1, "no") == 0)
145 $$ = 0;
146 else {
147 yyerror("invalid boolean value '%s'", $1);
148 free($1);
149 YYERROR;
151 free($1);
153 | ON { $$ = 1; }
154 | NUMBER { $$ = $1; }
157 fcgiport : NUMBER {
158 if ($1 <= 0 || $1 > (int)USHRT_MAX) {
159 yyerror("invalid port: %lld", $1);
160 YYERROR;
162 $$ = htons($1);
164 | STRING {
165 int val;
167 if ((val = getservice($1)) == -1) {
168 yyerror("invalid port: %s", $1);
169 free($1);
170 YYERROR;
172 free($1);
174 $$ = val;
178 main : PREFORK NUMBER {
179 gotwebd->prefork_gotwebd = $2;
181 | CHROOT STRING {
182 n = strlcpy(gotwebd->httpd_chroot, $2,
183 sizeof(gotwebd->httpd_chroot));
184 if (n >= sizeof(gotwebd->httpd_chroot)) {
185 yyerror("%s: httpd_chroot truncated", __func__);
186 free($2);
187 YYERROR;
189 free($2);
191 | FCGI_SOCKET boolean {
192 gotwebd->fcgi_socket = $2;
194 | FCGI_SOCKET boolean {
195 gotwebd->fcgi_socket = $2;
196 } '{' optnl socketopts4 '}'
197 | UNIX_SOCKET boolean {
198 gotwebd->unix_socket = $2;
200 | UNIX_SOCKET_NAME STRING {
201 n = snprintf(gotwebd->unix_socket_name,
202 sizeof(gotwebd->unix_socket_name), "%s%s",
203 strlen(gotwebd->httpd_chroot) ?
204 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
205 if (n < 0) {
206 yyerror("%s: unix_socket_name truncated",
207 __func__);
208 free($2);
209 YYERROR;
211 free($2);
215 server : SERVER STRING {
216 struct server *srv;
218 TAILQ_FOREACH(srv, gotwebd->servers, entry) {
219 if (strcmp(srv->name, $2) == 0) {
220 yyerror("server name exists '%s'", $2);
221 free($2);
222 YYERROR;
226 new_srv = conf_new_server($2);
227 if (new_srv->fcgi_socket)
228 if (get_addrs(new_srv->fcgi_socket_bind,
229 new_srv->al,
230 new_srv->fcgi_socket_port) == -1) {
231 yyerror("could not get tcp iface "
232 "addrs");
233 YYERROR;
235 log_debug("adding server %s", $2);
236 free($2);
238 | SERVER STRING {
239 struct server *srv;
241 TAILQ_FOREACH(srv, gotwebd->servers, entry) {
242 if (strcmp(srv->name, $2) == 0) {
243 yyerror("server name exists '%s'", $2);
244 free($2);
245 YYERROR;
249 new_srv = conf_new_server($2);
250 log_debug("adding server %s", $2);
251 free($2);
252 } '{' optnl serveropts2 '}' {
253 if (get_addrs(new_srv->fcgi_socket_bind,
254 new_srv->al, new_srv->fcgi_socket_port) == -1) {
255 yyerror("could not get tcp iface addrs");
256 YYERROR;
261 serveropts1 : REPOS_PATH STRING {
262 n = strlcpy(new_srv->repos_path, $2,
263 sizeof(new_srv->repos_path));
264 if (n >= sizeof(new_srv->repos_path)) {
265 yyerror("%s: repos_path truncated", __func__);
266 free($2);
267 YYERROR;
269 free($2);
271 | SITE_NAME STRING {
272 n = strlcpy(new_srv->site_name, $2,
273 sizeof(new_srv->site_name));
274 if (n >= sizeof(new_srv->site_name)) {
275 yyerror("%s: site_name truncated", __func__);
276 free($2);
277 YYERROR;
279 free($2);
281 | SITE_OWNER STRING {
282 n = strlcpy(new_srv->site_owner, $2,
283 sizeof(new_srv->site_owner));
284 if (n >= sizeof(new_srv->site_owner)) {
285 yyerror("%s: site_owner truncated", __func__);
286 free($2);
287 YYERROR;
289 free($2);
291 | SITE_LINK STRING {
292 n = strlcpy(new_srv->site_link, $2,
293 sizeof(new_srv->site_link));
294 if (n >= sizeof(new_srv->site_link)) {
295 yyerror("%s: site_link truncated", __func__);
296 free($2);
297 YYERROR;
299 free($2);
301 | LOGO STRING {
302 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
303 if (n >= sizeof(new_srv->logo)) {
304 yyerror("%s: logo truncated", __func__);
305 free($2);
306 YYERROR;
308 free($2);
310 | LOGO_URL STRING {
311 n = strlcpy(new_srv->logo_url, $2,
312 sizeof(new_srv->logo_url));
313 if (n >= sizeof(new_srv->logo_url)) {
314 yyerror("%s: logo_url truncated", __func__);
315 free($2);
316 YYERROR;
318 free($2);
320 | CUSTOM_CSS STRING {
321 n = strlcpy(new_srv->custom_css, $2,
322 sizeof(new_srv->custom_css));
323 if (n >= sizeof(new_srv->custom_css)) {
324 yyerror("%s: custom_css truncated", __func__);
325 free($2);
326 YYERROR;
328 free($2);
330 | MAX_REPOS NUMBER {
331 if ($2 > 0)
332 new_srv->max_repos = $2;
334 | SHOW_SITE_OWNER boolean {
335 new_srv->show_site_owner = $2;
337 | SHOW_REPO_OWNER boolean {
338 new_srv->show_repo_owner = $2;
340 | SHOW_REPO_AGE boolean {
341 new_srv->show_repo_age = $2;
343 | SHOW_REPO_DESCRIPTION boolean {
344 new_srv->show_repo_description = $2;
346 | SHOW_REPO_CLONEURL boolean {
347 new_srv->show_repo_cloneurl = $2;
349 | MAX_REPOS_DISPLAY NUMBER {
350 new_srv->max_repos_display = $2;
352 | MAX_COMMITS_DISPLAY NUMBER {
353 if ($2 > 0)
354 new_srv->max_commits_display = $2;
356 | FCGI_SOCKET boolean {
357 new_srv->fcgi_socket = $2;
359 | FCGI_SOCKET boolean {
360 new_srv->fcgi_socket = $2;
361 } '{' optnl socketopts2 '}'
362 | UNIX_SOCKET boolean {
363 new_srv->unix_socket = $2;
365 | UNIX_SOCKET_NAME STRING {
366 n = snprintf(new_srv->unix_socket_name,
367 sizeof(new_srv->unix_socket_name), "%s%s",
368 strlen(gotwebd->httpd_chroot) ?
369 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
370 if (n < 0) {
371 yyerror("%s: unix_socket_name truncated",
372 __func__);
373 free($2);
374 YYERROR;
376 free($2);
380 serveropts2 : serveropts2 serveropts1 nl
381 | serveropts1 optnl
384 socketopts1 : BIND INTERFACE STRING {
385 n = strlcpy(new_srv->fcgi_socket_bind, $3,
386 sizeof(new_srv->fcgi_socket_bind));
387 if (n >= sizeof(new_srv->fcgi_socket_bind)) {
388 yyerror("%s: fcgi_socket_bind truncated",
389 __func__);
390 free($3);
391 YYERROR;
393 free($3);
395 | PORT fcgiport {
396 struct server *srv;
398 TAILQ_FOREACH(srv, gotwebd->servers, entry) {
399 if (srv->fcgi_socket_port == $2) {
400 yyerror("port already assigned");
401 YYERROR;
404 new_srv->fcgi_socket_port = $2;
408 socketopts2 : socketopts2 socketopts1 nl
409 | socketopts1 optnl
412 socketopts3 : BIND INTERFACE STRING {
413 n = strlcpy(gotwebd->fcgi_socket_bind, $3,
414 sizeof(gotwebd->fcgi_socket_bind));
415 if (n >= sizeof(gotwebd->fcgi_socket_bind)) {
416 yyerror("%s: fcgi_socket_bind truncated",
417 __func__);
418 free($3);
419 YYERROR;
421 free($3);
423 | PORT fcgiport {
424 gotwebd->fcgi_socket_port = $2;
428 socketopts4 : socketopts4 socketopts3 nl
429 | socketopts3 optnl
432 nl : '\n' optnl
435 optnl : '\n' optnl /* zero or more newlines */
436 | /* empty */
439 %%
441 struct keywords {
442 const char *k_name;
443 int k_val;
444 };
446 int
447 yyerror(const char *fmt, ...)
449 va_list ap;
450 char *msg;
452 file->errors++;
453 va_start(ap, fmt);
454 if (vasprintf(&msg, fmt, ap) == -1)
455 fatalx("yyerror vasprintf");
456 va_end(ap);
457 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
458 free(msg);
459 return (0);
462 int
463 kw_cmp(const void *k, const void *e)
465 return (strcmp(k, ((const struct keywords *)e)->k_name));
468 int
469 lookup(char *s)
471 /* This has to be sorted always. */
472 static const struct keywords keywords[] = {
473 { "bind", BIND },
474 { "chroot", CHROOT },
475 { "custom_css", CUSTOM_CSS },
476 { "fcgi_socket", FCGI_SOCKET },
477 { "interface", INTERFACE },
478 { "logo", LOGO },
479 { "logo_url" , LOGO_URL },
480 { "max_commits_display", MAX_COMMITS_DISPLAY },
481 { "max_repos", MAX_REPOS },
482 { "max_repos_display", MAX_REPOS_DISPLAY },
483 { "port", PORT },
484 { "prefork", PREFORK },
485 { "repos_path", REPOS_PATH },
486 { "server", SERVER },
487 { "show_repo_age", SHOW_REPO_AGE },
488 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
489 { "show_repo_description", SHOW_REPO_DESCRIPTION },
490 { "show_repo_owner", SHOW_REPO_OWNER },
491 { "show_site_owner", SHOW_SITE_OWNER },
492 { "site_link", SITE_LINK },
493 { "site_name", SITE_NAME },
494 { "site_owner", SITE_OWNER },
495 { "unix_socket", UNIX_SOCKET },
496 { "unix_socket_name", UNIX_SOCKET_NAME },
497 };
498 const struct keywords *p;
500 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
501 sizeof(keywords[0]), kw_cmp);
503 if (p)
504 return (p->k_val);
505 else
506 return (STRING);
509 #define MAXPUSHBACK 128
511 unsigned char *parsebuf;
512 int parseindex;
513 unsigned char pushback_buffer[MAXPUSHBACK];
514 int pushback_index = 0;
516 int
517 lgetc(int quotec)
519 int c, next;
521 if (parsebuf) {
522 /* Read character from the parsebuffer instead of input. */
523 if (parseindex >= 0) {
524 c = parsebuf[parseindex++];
525 if (c != '\0')
526 return (c);
527 parsebuf = NULL;
528 } else
529 parseindex++;
532 if (pushback_index)
533 return (pushback_buffer[--pushback_index]);
535 if (quotec) {
536 c = getc(file->stream);
537 if (c == EOF)
538 yyerror("reached end of file while parsing "
539 "quoted string");
540 return (c);
543 c = getc(file->stream);
544 while (c == '\\') {
545 next = getc(file->stream);
546 if (next != '\n') {
547 c = next;
548 break;
550 yylval.lineno = file->lineno;
551 file->lineno++;
552 c = getc(file->stream);
555 return (c);
558 int
559 lungetc(int c)
561 if (c == EOF)
562 return (EOF);
563 if (parsebuf) {
564 parseindex--;
565 if (parseindex >= 0)
566 return (c);
568 if (pushback_index < MAXPUSHBACK-1)
569 return (pushback_buffer[pushback_index++] = c);
570 else
571 return (EOF);
574 int
575 findeol(void)
577 int c;
579 parsebuf = NULL;
581 /* Skip to either EOF or the first real EOL. */
582 while (1) {
583 if (pushback_index)
584 c = pushback_buffer[--pushback_index];
585 else
586 c = lgetc(0);
587 if (c == '\n') {
588 file->lineno++;
589 break;
591 if (c == EOF)
592 break;
594 return (ERROR);
597 int
598 yylex(void)
600 unsigned char buf[8096];
601 unsigned char *p, *val;
602 int quotec, next, c;
603 int token;
605 top:
606 p = buf;
607 c = lgetc(0);
608 while (c == ' ' || c == '\t')
609 c = lgetc(0); /* nothing */
611 yylval.lineno = file->lineno;
612 if (c == '#') {
613 c = lgetc(0);
614 while (c != '\n' && c != EOF)
615 c = lgetc(0); /* nothing */
617 if (c == '$' && parsebuf == NULL) {
618 while (1) {
619 c = lgetc(0);
620 if (c == EOF)
621 return (0);
623 if (p + 1 >= buf + sizeof(buf) - 1) {
624 yyerror("string too long");
625 return (findeol());
627 if (isalnum(c) || c == '_') {
628 *p++ = c;
629 continue;
631 *p = '\0';
632 lungetc(c);
633 break;
635 val = symget(buf);
636 if (val == NULL) {
637 yyerror("macro '%s' not defined", buf);
638 return (findeol());
640 parsebuf = val;
641 parseindex = 0;
642 goto top;
645 switch (c) {
646 case '\'':
647 case '"':
648 quotec = c;
649 while (1) {
650 c = lgetc(quotec);
651 if (c == EOF)
652 return (0);
653 if (c == '\n') {
654 file->lineno++;
655 continue;
656 } else if (c == '\\') {
657 next = lgetc(quotec);
658 if (next == EOF)
659 return (0);
660 if (next == quotec || c == ' ' || c == '\t')
661 c = next;
662 else if (next == '\n') {
663 file->lineno++;
664 continue;
665 } else
666 lungetc(next);
667 } else if (c == quotec) {
668 *p = '\0';
669 break;
670 } else if (c == '\0') {
671 yyerror("syntax error");
672 return (findeol());
674 if (p + 1 >= buf + sizeof(buf) - 1) {
675 yyerror("string too long");
676 return (findeol());
678 *p++ = c;
680 yylval.v.string = strdup(buf);
681 if (yylval.v.string == NULL)
682 err(1, "yylex: strdup");
683 return (STRING);
686 #define allowed_to_end_number(x) \
687 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
689 if (c == '-' || isdigit(c)) {
690 do {
691 *p++ = c;
692 if ((unsigned)(p-buf) >= sizeof(buf)) {
693 yyerror("string too long");
694 return (findeol());
696 c = lgetc(0);
697 } while (c != EOF && isdigit(c));
698 lungetc(c);
699 if (p == buf + 1 && buf[0] == '-')
700 goto nodigits;
701 if (c == EOF || allowed_to_end_number(c)) {
702 const char *errstr = NULL;
704 *p = '\0';
705 yylval.v.number = strtonum(buf, LLONG_MIN,
706 LLONG_MAX, &errstr);
707 if (errstr) {
708 yyerror("\"%s\" invalid number: %s",
709 buf, errstr);
710 return (findeol());
712 return (NUMBER);
713 } else {
714 nodigits:
715 while (p > buf + 1)
716 lungetc(*--p);
717 c = *--p;
718 if (c == '-')
719 return (c);
723 #define allowed_in_string(x) \
724 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
725 x != '{' && x != '}' && \
726 x != '!' && x != '=' && x != '#' && \
727 x != ','))
729 if (isalnum(c) || c == ':' || c == '_') {
730 do {
731 *p++ = c;
732 if ((unsigned)(p-buf) >= sizeof(buf)) {
733 yyerror("string too long");
734 return (findeol());
736 c = lgetc(0);
737 } while (c != EOF && (allowed_in_string(c)));
738 lungetc(c);
739 *p = '\0';
740 token = lookup(buf);
741 if (token == STRING) {
742 yylval.v.string = strdup(buf);
743 if (yylval.v.string == NULL)
744 err(1, "yylex: strdup");
746 return (token);
748 if (c == '\n') {
749 yylval.lineno = file->lineno;
750 file->lineno++;
752 if (c == EOF)
753 return (0);
754 return (c);
757 int
758 check_file_secrecy(int fd, const char *fname)
760 struct stat st;
762 if (fstat(fd, &st)) {
763 log_warn("cannot stat %s", fname);
764 return (-1);
766 if (st.st_uid != 0 && st.st_uid != getuid()) {
767 log_warnx("%s: owner not root or current user", fname);
768 return (-1);
770 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
771 log_warnx("%s: group writable or world read/writable", fname);
772 return (-1);
774 return (0);
777 struct file *
778 newfile(const char *name, int secret)
780 struct file *nfile;
782 nfile = calloc(1, sizeof(struct file));
783 if (nfile == NULL) {
784 log_warn("calloc");
785 return (NULL);
787 nfile->name = strdup(name);
788 if (nfile->name == NULL) {
789 log_warn("strdup");
790 free(nfile);
791 return (NULL);
793 nfile->stream = fopen(nfile->name, "r");
794 if (nfile->stream == NULL) {
795 /* no warning, we don't require a conf file */
796 free(nfile->name);
797 free(nfile);
798 return (NULL);
799 } else if (secret &&
800 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
801 fclose(nfile->stream);
802 free(nfile->name);
803 free(nfile);
804 return (NULL);
806 nfile->lineno = 1;
807 return (nfile);
810 static void
811 closefile(struct file *xfile)
813 fclose(xfile->stream);
814 free(xfile->name);
815 free(xfile);
818 int
819 parse_config(const char *filename, struct gotwebd *env)
821 struct sym *sym, *next;
823 file = newfile(filename, 0);
824 if (file == NULL)
825 /* just return, as we don't require a conf file */
826 return (0);
828 if (config_init(env) == -1)
829 fatalx("failed to initialize configuration");
831 gotwebd = env;
833 yyparse();
834 errors = file->errors;
835 closefile(file);
837 /* Free macros and check which have not been used. */
838 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
839 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
840 fprintf(stderr, "warning: macro '%s' not used\n",
841 sym->nam);
842 if (!sym->persist) {
843 free(sym->nam);
844 free(sym->val);
845 TAILQ_REMOVE(&symhead, sym, entry);
846 free(sym);
850 if (errors)
851 return (-1);
853 /* just add default server if no config specified */
854 if (gotwebd->server_cnt == 0) {
855 new_srv = conf_new_server(D_SITENAME);
856 log_debug("%s: adding default server %s", __func__, D_SITENAME);
859 /* setup our listening sockets */
860 sockets_parse_sockets(env);
862 return (0);
865 struct server *
866 conf_new_server(const char *name)
868 struct server *srv = NULL;
869 int val;
871 srv = calloc(1, sizeof(*srv));
872 if (srv == NULL)
873 fatalx("%s: calloc", __func__);
875 n = strlcpy(srv->name, name, sizeof(srv->name));
876 if (n >= sizeof(srv->name))
877 fatalx("%s: strlcpy", __func__);
878 n = snprintf(srv->unix_socket_name,
879 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
880 D_UNIX_SOCKET);
881 if (n < 0)
882 fatalx("%s: snprintf", __func__);
883 n = strlcpy(srv->repos_path, D_GOTPATH,
884 sizeof(srv->repos_path));
885 if (n >= sizeof(srv->repos_path))
886 fatalx("%s: strlcpy", __func__);
887 n = strlcpy(srv->site_name, D_SITENAME,
888 sizeof(srv->site_name));
889 if (n >= sizeof(srv->site_name))
890 fatalx("%s: strlcpy", __func__);
891 n = strlcpy(srv->site_owner, D_SITEOWNER,
892 sizeof(srv->site_owner));
893 if (n >= sizeof(srv->site_owner))
894 fatalx("%s: strlcpy", __func__);
895 n = strlcpy(srv->site_link, D_SITELINK,
896 sizeof(srv->site_link));
897 if (n >= sizeof(srv->site_link))
898 fatalx("%s: strlcpy", __func__);
899 n = strlcpy(srv->logo, D_GOTLOGO,
900 sizeof(srv->logo));
901 if (n >= sizeof(srv->logo))
902 fatalx("%s: strlcpy", __func__);
903 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
904 if (n >= sizeof(srv->logo_url))
905 fatalx("%s: strlcpy", __func__);
906 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
907 if (n >= sizeof(srv->custom_css))
908 fatalx("%s: strlcpy", __func__);
910 val = getservice(D_FCGI_PORT);
911 srv->fcgi_socket_port = gotwebd->fcgi_socket_port ?
912 gotwebd->fcgi_socket_port: htons(val);
914 srv->show_site_owner = D_SHOWSOWNER;
915 srv->show_repo_owner = D_SHOWROWNER;
916 srv->show_repo_age = D_SHOWAGE;
917 srv->show_repo_description = D_SHOWDESC;
918 srv->show_repo_cloneurl = D_SHOWURL;
920 srv->max_repos_display = D_MAXREPODISP;
921 srv->max_commits_display = D_MAXCOMMITDISP;
922 srv->max_repos = D_MAXREPO;
924 srv->unix_socket = 1;
925 srv->fcgi_socket = gotwebd->fcgi_socket ? gotwebd->fcgi_socket : 0;
927 if ((srv->al = calloc(1, sizeof(*srv->al))) == NULL)
928 fatalx("%s: calloc", __func__);
930 TAILQ_INIT(srv->al);
931 TAILQ_INSERT_TAIL(gotwebd->servers, srv, entry);
932 gotwebd->server_cnt++;
934 return srv;
935 };
937 int
938 symset(const char *nam, const char *val, int persist)
940 struct sym *sym;
942 TAILQ_FOREACH(sym, &symhead, entry) {
943 if (strcmp(nam, sym->nam) == 0)
944 break;
947 if (sym != NULL) {
948 if (sym->persist == 1)
949 return (0);
950 else {
951 free(sym->nam);
952 free(sym->val);
953 TAILQ_REMOVE(&symhead, sym, entry);
954 free(sym);
957 sym = calloc(1, sizeof(*sym));
958 if (sym == NULL)
959 return (-1);
961 sym->nam = strdup(nam);
962 if (sym->nam == NULL) {
963 free(sym);
964 return (-1);
966 sym->val = strdup(val);
967 if (sym->val == NULL) {
968 free(sym->nam);
969 free(sym);
970 return (-1);
972 sym->used = 0;
973 sym->persist = persist;
974 TAILQ_INSERT_TAIL(&symhead, sym, entry);
975 return (0);
978 int
979 cmdline_symset(char *s)
981 char *sym, *val;
982 int ret;
983 size_t len;
985 val = strrchr(s, '=');
986 if (val == NULL)
987 return (-1);
989 len = strlen(s) - strlen(val) + 1;
990 sym = malloc(len);
991 if (sym == NULL)
992 fatal("%s: malloc", __func__);
994 memcpy(&sym, s, len);
996 ret = symset(sym, val + 1, 1);
997 free(sym);
999 return (ret);
1002 char *
1003 symget(const char *nam)
1005 struct sym *sym;
1007 TAILQ_FOREACH(sym, &symhead, entry) {
1008 if (strcmp(nam, sym->nam) == 0) {
1009 sym->used = 1;
1010 return (sym->val);
1013 return (NULL);
1016 int
1017 getservice(const char *n)
1019 struct servent *s;
1020 const char *errstr;
1021 long long llval;
1023 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1024 if (errstr) {
1025 s = getservbyname(n, "tcp");
1026 if (s == NULL)
1027 s = getservbyname(n, "udp");
1028 if (s == NULL)
1029 return (-1);
1030 return (s->s_port);
1033 return (htons((unsigned short)llval));
1036 struct address *
1037 host_v4(const char *s)
1039 struct in_addr ina;
1040 struct sockaddr_in *sain;
1041 struct address *h;
1043 memset(&ina, 0, sizeof(ina));
1044 if (inet_pton(AF_INET, s, &ina) != 1)
1045 return (NULL);
1047 if ((h = calloc(1, sizeof(*h))) == NULL)
1048 fatal(__func__);
1049 sain = (struct sockaddr_in *)&h->ss;
1050 sain->sin_len = sizeof(struct sockaddr_in);
1051 sain->sin_family = AF_INET;
1052 sain->sin_addr.s_addr = ina.s_addr;
1053 if (sain->sin_addr.s_addr == INADDR_ANY)
1054 h->prefixlen = 0; /* 0.0.0.0 address */
1055 else
1056 h->prefixlen = -1; /* host address */
1057 return (h);
1060 struct address *
1061 host_v6(const char *s)
1063 struct addrinfo hints, *res;
1064 struct sockaddr_in6 *sa_in6;
1065 struct address *h = NULL;
1067 memset(&hints, 0, sizeof(hints));
1068 hints.ai_family = AF_INET6;
1069 hints.ai_socktype = SOCK_DGRAM; /* dummy */
1070 hints.ai_flags = AI_NUMERICHOST;
1071 if (getaddrinfo(s, "0", &hints, &res) == 0) {
1072 if ((h = calloc(1, sizeof(*h))) == NULL)
1073 fatal(__func__);
1074 sa_in6 = (struct sockaddr_in6 *)&h->ss;
1075 sa_in6->sin6_len = sizeof(struct sockaddr_in6);
1076 sa_in6->sin6_family = AF_INET6;
1077 memcpy(&sa_in6->sin6_addr,
1078 &((struct sockaddr_in6 *)res->ai_addr)->sin6_addr,
1079 sizeof(sa_in6->sin6_addr));
1080 sa_in6->sin6_scope_id =
1081 ((struct sockaddr_in6 *)res->ai_addr)->sin6_scope_id;
1082 if (memcmp(&sa_in6->sin6_addr, &in6addr_any,
1083 sizeof(sa_in6->sin6_addr)) == 0)
1084 h->prefixlen = 0; /* any address */
1085 else
1086 h->prefixlen = -1; /* host address */
1087 freeaddrinfo(res);
1090 return (h);
1093 int
1094 host_dns(const char *s, struct addresslist *al, int max,
1095 in_port_t port, const char *ifname, int ipproto)
1097 struct addrinfo hints, *res0, *res;
1098 int error, cnt = 0;
1099 struct sockaddr_in *sain;
1100 struct sockaddr_in6 *sin6;
1101 struct address *h;
1103 if ((cnt = host_if(s, al, max, port, ifname, ipproto)) != 0)
1104 return (cnt);
1106 memset(&hints, 0, sizeof(hints));
1107 hints.ai_family = PF_UNSPEC;
1108 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1109 hints.ai_flags = AI_ADDRCONFIG;
1110 error = getaddrinfo(s, NULL, &hints, &res0);
1111 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1112 return (0);
1113 if (error) {
1114 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1115 gai_strerror(error));
1116 return (-1);
1119 for (res = res0; res && cnt < max; res = res->ai_next) {
1120 if (res->ai_family != AF_INET &&
1121 res->ai_family != AF_INET6)
1122 continue;
1123 if ((h = calloc(1, sizeof(*h))) == NULL)
1124 fatal(__func__);
1126 if (port)
1127 h->port = port;
1128 if (ifname != NULL) {
1129 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1130 sizeof(h->ifname)) {
1131 log_warnx("%s: interface name truncated",
1132 __func__);
1133 freeaddrinfo(res0);
1134 free(h);
1135 return (-1);
1138 if (ipproto != -1)
1139 h->ipproto = ipproto;
1140 h->ss.ss_family = res->ai_family;
1141 h->prefixlen = -1; /* host address */
1143 if (res->ai_family == AF_INET) {
1144 sain = (struct sockaddr_in *)&h->ss;
1145 sain->sin_len = sizeof(struct sockaddr_in);
1146 sain->sin_addr.s_addr = ((struct sockaddr_in *)
1147 res->ai_addr)->sin_addr.s_addr;
1148 } else {
1149 sin6 = (struct sockaddr_in6 *)&h->ss;
1150 sin6->sin6_len = sizeof(struct sockaddr_in6);
1151 memcpy(&sin6->sin6_addr, &((struct sockaddr_in6 *)
1152 res->ai_addr)->sin6_addr, sizeof(struct in6_addr));
1155 TAILQ_INSERT_HEAD(al, h, entry);
1156 cnt++;
1158 if (cnt == max && res) {
1159 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1160 s, max);
1162 freeaddrinfo(res0);
1163 return (cnt);
1166 int
1167 host_if(const char *s, struct addresslist *al, int max,
1168 in_port_t port, const char *ifname, int ipproto)
1170 struct ifaddrs *ifap, *p;
1171 struct sockaddr_in *sain;
1172 struct sockaddr_in6 *sin6;
1173 struct address *h;
1174 int cnt = 0, af;
1176 if (getifaddrs(&ifap) == -1)
1177 fatal("getifaddrs");
1179 /* First search for IPv4 addresses */
1180 af = AF_INET;
1182 nextaf:
1183 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1184 if (p->ifa_addr == NULL ||
1185 p->ifa_addr->sa_family != af ||
1186 (strcmp(s, p->ifa_name) != 0 &&
1187 !is_if_in_group(p->ifa_name, s)))
1188 continue;
1189 if ((h = calloc(1, sizeof(*h))) == NULL)
1190 fatal("calloc");
1192 if (port)
1193 h->port = port;
1194 if (ifname != NULL) {
1195 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1196 sizeof(h->ifname)) {
1197 log_warnx("%s: interface name truncated",
1198 __func__);
1199 free(h);
1200 freeifaddrs(ifap);
1201 return (-1);
1204 if (ipproto != -1)
1205 h->ipproto = ipproto;
1206 h->ss.ss_family = af;
1207 h->prefixlen = -1; /* host address */
1209 if (af == AF_INET) {
1210 sain = (struct sockaddr_in *)&h->ss;
1211 sain->sin_len = sizeof(struct sockaddr_in);
1212 sain->sin_addr.s_addr = ((struct sockaddr_in *)
1213 p->ifa_addr)->sin_addr.s_addr;
1214 } else {
1215 sin6 = (struct sockaddr_in6 *)&h->ss;
1216 sin6->sin6_len = sizeof(struct sockaddr_in6);
1217 memcpy(&sin6->sin6_addr, &((struct sockaddr_in6 *)
1218 p->ifa_addr)->sin6_addr, sizeof(struct in6_addr));
1219 sin6->sin6_scope_id = ((struct sockaddr_in6 *)
1220 p->ifa_addr)->sin6_scope_id;
1223 TAILQ_INSERT_HEAD(al, h, entry);
1224 cnt++;
1226 if (af == AF_INET) {
1227 /* Next search for IPv6 addresses */
1228 af = AF_INET6;
1229 goto nextaf;
1232 if (cnt > max) {
1233 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1234 s, max);
1236 freeifaddrs(ifap);
1237 return (cnt);
1240 int
1241 host(const char *s, struct addresslist *al, int max,
1242 in_port_t port, const char *ifname, int ipproto)
1244 struct address *h;
1246 h = host_v4(s);
1248 /* IPv6 address? */
1249 if (h == NULL)
1250 h = host_v6(s);
1252 if (h != NULL) {
1253 if (port)
1254 h->port = port;
1255 if (ifname != NULL) {
1256 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1257 sizeof(h->ifname)) {
1258 log_warnx("%s: interface name truncated",
1259 __func__);
1260 free(h);
1261 return (-1);
1264 if (ipproto != -1)
1265 h->ipproto = ipproto;
1267 TAILQ_INSERT_HEAD(al, h, entry);
1268 return (1);
1271 return (host_dns(s, al, max, port, ifname, ipproto));
1274 int
1275 is_if_in_group(const char *ifname, const char *groupname)
1277 unsigned int len;
1278 struct ifgroupreq ifgr;
1279 struct ifg_req *ifg;
1280 int s;
1281 int ret = 0;
1283 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1284 err(1, "socket");
1286 memset(&ifgr, 0, sizeof(ifgr));
1287 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1288 err(1, "IFNAMSIZ");
1289 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1290 if (errno == EINVAL || errno == ENOTTY)
1291 goto end;
1292 err(1, "SIOCGIFGROUP");
1295 len = ifgr.ifgr_len;
1296 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1297 sizeof(struct ifg_req));
1298 if (ifgr.ifgr_groups == NULL)
1299 err(1, "getifgroups");
1300 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1301 err(1, "SIOCGIFGROUP");
1303 ifg = ifgr.ifgr_groups;
1304 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1305 len -= sizeof(struct ifg_req);
1306 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1307 ret = 1;
1308 break;
1311 free(ifgr.ifgr_groups);
1313 end:
1314 close(s);
1315 return (ret);
1318 int
1319 get_addrs(const char *addr, struct addresslist *al, in_port_t port)
1321 if (strcmp("", addr) == 0) {
1322 if (host("0.0.0.0", al, 1, port, "0.0.0.0", -1) <= 0) {
1323 yyerror("invalid listen ip: %s",
1324 "0.0.0.0");
1325 return (-1);
1327 if (host("::", al, 1, port, "::", -1) <= 0) {
1328 yyerror("invalid listen ip: %s", "::");
1329 return (-1);
1331 } else {
1332 if (host(addr, al, GOTWEBD_MAXIFACE, port, addr,
1333 -1) <= 0) {
1334 yyerror("invalid listen ip: %s", addr);
1335 return (-1);
1338 return (0);