Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <unistd.h>
50 #include "got_sockaddr.h"
51 #include "got_reference.h"
53 #include "proc.h"
54 #include "gotwebd.h"
56 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
57 static struct file {
58 TAILQ_ENTRY(file) entry;
59 FILE *stream;
60 char *name;
61 int lineno;
62 int errors;
63 } *file;
64 struct file *newfile(const char *, int);
65 static void closefile(struct file *);
66 int check_file_secrecy(int, const char *);
67 int yyparse(void);
68 int yylex(void);
69 int yyerror(const char *, ...)
70 __attribute__((__format__ (printf, 1, 2)))
71 __attribute__((__nonnull__ (1)));
72 int kw_cmp(const void *, const void *);
73 int lookup(char *);
74 int lgetc(int);
75 int lungetc(int);
76 int findeol(void);
78 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
79 struct sym {
80 TAILQ_ENTRY(sym) entry;
81 int used;
82 int persist;
83 char *nam;
84 char *val;
85 };
87 int symset(const char *, const char *, int);
88 char *symget(const char *);
90 static int errors;
92 static struct gotwebd *gotwebd;
93 static struct server *new_srv;
94 static struct server *conf_new_server(const char *);
95 int getservice(const char *);
96 int n;
98 int get_addrs(const char *, struct server *, in_port_t);
99 int addr_dup_check(struct addresslist *, struct address *,
100 const char *, const char *);
101 int add_addr(struct server *, struct address *);
102 int host(const char *, struct server *,
103 int, in_port_t, const char *, int);
104 int host_if(const char *, struct server *,
105 int, in_port_t, const char *, int);
106 int is_if_in_group(const char *, const char *);
108 typedef struct {
109 union {
110 long long number;
111 char *string;
112 in_port_t port;
113 } v;
114 int lineno;
115 } YYSTYPE;
117 %}
119 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
120 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
121 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
122 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
123 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
125 %token <v.string> STRING
126 %type <v.port> fcgiport
127 %token <v.number> NUMBER
128 %type <v.number> boolean
130 %%
132 grammar : /* empty */
133 | grammar '\n'
134 | grammar varset '\n'
135 | grammar main '\n'
136 | grammar server '\n'
137 | grammar error '\n' { file->errors++; }
140 varset : STRING '=' STRING {
141 char *s = $1;
142 while (*s++) {
143 if (isspace((unsigned char)*s)) {
144 yyerror("macro name cannot contain "
145 "whitespace");
146 free($1);
147 free($3);
148 YYERROR;
151 if (symset($1, $3, 0) == -1)
152 fatal("cannot store variable");
153 free($1);
154 free($3);
158 boolean : STRING {
159 if (strcasecmp($1, "1") == 0 ||
160 strcasecmp($1, "yes") == 0 ||
161 strcasecmp($1, "on") == 0)
162 $$ = 1;
163 else if (strcasecmp($1, "0") == 0 ||
164 strcasecmp($1, "off") == 0 ||
165 strcasecmp($1, "no") == 0)
166 $$ = 0;
167 else {
168 yyerror("invalid boolean value '%s'", $1);
169 free($1);
170 YYERROR;
172 free($1);
174 | ON { $$ = 1; }
175 | NUMBER { $$ = $1; }
178 fcgiport : PORT NUMBER {
179 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
180 yyerror("invalid port: %lld", $2);
181 YYERROR;
183 $$ = $2;
185 | PORT STRING {
186 int val;
188 if ((val = getservice($2)) == -1) {
189 yyerror("invalid port: %s", $2);
190 free($2);
191 YYERROR;
193 free($2);
195 $$ = val;
199 main : PREFORK NUMBER {
200 gotwebd->prefork_gotwebd = $2;
202 | CHROOT STRING {
203 n = strlcpy(gotwebd->httpd_chroot, $2,
204 sizeof(gotwebd->httpd_chroot));
205 if (n >= sizeof(gotwebd->httpd_chroot)) {
206 yyerror("%s: httpd_chroot truncated", __func__);
207 free($2);
208 YYERROR;
210 free($2);
212 | UNIX_SOCKET boolean {
213 gotwebd->unix_socket = $2;
215 | UNIX_SOCKET_NAME STRING {
216 n = snprintf(gotwebd->unix_socket_name,
217 sizeof(gotwebd->unix_socket_name), "%s%s",
218 strlen(gotwebd->httpd_chroot) ?
219 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
220 if (n < 0 ||
221 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
222 yyerror("%s: unix_socket_name truncated",
223 __func__);
224 free($2);
225 YYERROR;
227 free($2);
231 server : SERVER STRING {
232 struct server *srv;
234 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
235 if (strcmp(srv->name, $2) == 0) {
236 yyerror("server name exists '%s'", $2);
237 free($2);
238 YYERROR;
242 new_srv = conf_new_server($2);
243 log_debug("adding server %s", $2);
244 free($2);
246 | SERVER STRING {
247 struct server *srv;
249 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
250 if (strcmp(srv->name, $2) == 0) {
251 yyerror("server name exists '%s'", $2);
252 free($2);
253 YYERROR;
257 new_srv = conf_new_server($2);
258 log_debug("adding server %s", $2);
259 free($2);
260 } '{' optnl serveropts2 '}' {
264 serveropts1 : REPOS_PATH STRING {
265 n = strlcpy(new_srv->repos_path, $2,
266 sizeof(new_srv->repos_path));
267 if (n >= sizeof(new_srv->repos_path)) {
268 yyerror("%s: repos_path truncated", __func__);
269 free($2);
270 YYERROR;
272 free($2);
274 | SITE_NAME STRING {
275 n = strlcpy(new_srv->site_name, $2,
276 sizeof(new_srv->site_name));
277 if (n >= sizeof(new_srv->site_name)) {
278 yyerror("%s: site_name truncated", __func__);
279 free($2);
280 YYERROR;
282 free($2);
284 | SITE_OWNER STRING {
285 n = strlcpy(new_srv->site_owner, $2,
286 sizeof(new_srv->site_owner));
287 if (n >= sizeof(new_srv->site_owner)) {
288 yyerror("%s: site_owner truncated", __func__);
289 free($2);
290 YYERROR;
292 free($2);
294 | SITE_LINK STRING {
295 n = strlcpy(new_srv->site_link, $2,
296 sizeof(new_srv->site_link));
297 if (n >= sizeof(new_srv->site_link)) {
298 yyerror("%s: site_link truncated", __func__);
299 free($2);
300 YYERROR;
302 free($2);
304 | LOGO STRING {
305 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
306 if (n >= sizeof(new_srv->logo)) {
307 yyerror("%s: logo truncated", __func__);
308 free($2);
309 YYERROR;
311 free($2);
313 | LOGO_URL STRING {
314 n = strlcpy(new_srv->logo_url, $2,
315 sizeof(new_srv->logo_url));
316 if (n >= sizeof(new_srv->logo_url)) {
317 yyerror("%s: logo_url truncated", __func__);
318 free($2);
319 YYERROR;
321 free($2);
323 | CUSTOM_CSS STRING {
324 n = strlcpy(new_srv->custom_css, $2,
325 sizeof(new_srv->custom_css));
326 if (n >= sizeof(new_srv->custom_css)) {
327 yyerror("%s: custom_css truncated", __func__);
328 free($2);
329 YYERROR;
331 free($2);
333 | LISTEN ON STRING fcgiport {
334 if (get_addrs($3, new_srv, $4) == -1) {
335 yyerror("could not get addrs");
336 YYERROR;
338 new_srv->fcgi_socket = 1;
340 | LISTEN ON SOCKET STRING {
341 if (!strcasecmp($4, "off") ||
342 !strcasecmp($4, "no")) {
343 new_srv->unix_socket = 0;
344 free($4);
345 YYACCEPT;
348 new_srv->unix_socket = 1;
350 n = snprintf(new_srv->unix_socket_name,
351 sizeof(new_srv->unix_socket_name), "%s%s",
352 strlen(gotwebd->httpd_chroot) ?
353 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $4);
354 if (n < 0 ||
355 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
356 yyerror("%s: unix_socket_name truncated",
357 __func__);
358 free($4);
359 YYERROR;
361 free($4);
363 | MAX_REPOS NUMBER {
364 if ($2 > 0)
365 new_srv->max_repos = $2;
367 | SHOW_SITE_OWNER boolean {
368 new_srv->show_site_owner = $2;
370 | SHOW_REPO_OWNER boolean {
371 new_srv->show_repo_owner = $2;
373 | SHOW_REPO_AGE boolean {
374 new_srv->show_repo_age = $2;
376 | SHOW_REPO_DESCRIPTION boolean {
377 new_srv->show_repo_description = $2;
379 | SHOW_REPO_CLONEURL boolean {
380 new_srv->show_repo_cloneurl = $2;
382 | RESPECT_EXPORTOK boolean {
383 new_srv->respect_exportok = $2;
385 | MAX_REPOS_DISPLAY NUMBER {
386 new_srv->max_repos_display = $2;
388 | MAX_COMMITS_DISPLAY NUMBER {
389 if ($2 > 0)
390 new_srv->max_commits_display = $2;
394 serveropts2 : serveropts2 serveropts1 nl
395 | serveropts1 optnl
398 nl : '\n' optnl
401 optnl : '\n' optnl /* zero or more newlines */
402 | /* empty */
405 %%
407 struct keywords {
408 const char *k_name;
409 int k_val;
410 };
412 int
413 yyerror(const char *fmt, ...)
415 va_list ap;
416 char *msg;
418 file->errors++;
419 va_start(ap, fmt);
420 if (vasprintf(&msg, fmt, ap) == -1)
421 fatalx("yyerror vasprintf");
422 va_end(ap);
423 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
424 free(msg);
425 return (0);
428 int
429 kw_cmp(const void *k, const void *e)
431 return (strcmp(k, ((const struct keywords *)e)->k_name));
434 int
435 lookup(char *s)
437 /* This has to be sorted always. */
438 static const struct keywords keywords[] = {
439 { "chroot", CHROOT },
440 { "custom_css", CUSTOM_CSS },
441 { "listen", LISTEN },
442 { "logo", LOGO },
443 { "logo_url", LOGO_URL },
444 { "max_commits_display", MAX_COMMITS_DISPLAY },
445 { "max_repos", MAX_REPOS },
446 { "max_repos_display", MAX_REPOS_DISPLAY },
447 { "on", ON },
448 { "port", PORT },
449 { "prefork", PREFORK },
450 { "repos_path", REPOS_PATH },
451 { "respect_exportok", RESPECT_EXPORTOK },
452 { "server", SERVER },
453 { "show_repo_age", SHOW_REPO_AGE },
454 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
455 { "show_repo_description", SHOW_REPO_DESCRIPTION },
456 { "show_repo_owner", SHOW_REPO_OWNER },
457 { "show_site_owner", SHOW_SITE_OWNER },
458 { "site_link", SITE_LINK },
459 { "site_name", SITE_NAME },
460 { "site_owner", SITE_OWNER },
461 { "socket", SOCKET },
462 { "unix_socket", UNIX_SOCKET },
463 { "unix_socket_name", UNIX_SOCKET_NAME },
464 };
465 const struct keywords *p;
467 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
468 sizeof(keywords[0]), kw_cmp);
470 if (p)
471 return (p->k_val);
472 else
473 return (STRING);
476 #define MAXPUSHBACK 128
478 unsigned char *parsebuf;
479 int parseindex;
480 unsigned char pushback_buffer[MAXPUSHBACK];
481 int pushback_index = 0;
483 int
484 lgetc(int quotec)
486 int c, next;
488 if (parsebuf) {
489 /* Read character from the parsebuffer instead of input. */
490 if (parseindex >= 0) {
491 c = parsebuf[parseindex++];
492 if (c != '\0')
493 return (c);
494 parsebuf = NULL;
495 } else
496 parseindex++;
499 if (pushback_index)
500 return (pushback_buffer[--pushback_index]);
502 if (quotec) {
503 c = getc(file->stream);
504 if (c == EOF)
505 yyerror("reached end of file while parsing "
506 "quoted string");
507 return (c);
510 c = getc(file->stream);
511 while (c == '\\') {
512 next = getc(file->stream);
513 if (next != '\n') {
514 c = next;
515 break;
517 yylval.lineno = file->lineno;
518 file->lineno++;
519 c = getc(file->stream);
522 return (c);
525 int
526 lungetc(int c)
528 if (c == EOF)
529 return (EOF);
530 if (parsebuf) {
531 parseindex--;
532 if (parseindex >= 0)
533 return (c);
535 if (pushback_index < MAXPUSHBACK-1)
536 return (pushback_buffer[pushback_index++] = c);
537 else
538 return (EOF);
541 int
542 findeol(void)
544 int c;
546 parsebuf = NULL;
548 /* Skip to either EOF or the first real EOL. */
549 while (1) {
550 if (pushback_index)
551 c = pushback_buffer[--pushback_index];
552 else
553 c = lgetc(0);
554 if (c == '\n') {
555 file->lineno++;
556 break;
558 if (c == EOF)
559 break;
561 return (ERROR);
564 int
565 yylex(void)
567 unsigned char buf[8096];
568 unsigned char *p, *val;
569 int quotec, next, c;
570 int token;
572 top:
573 p = buf;
574 c = lgetc(0);
575 while (c == ' ' || c == '\t')
576 c = lgetc(0); /* nothing */
578 yylval.lineno = file->lineno;
579 if (c == '#') {
580 c = lgetc(0);
581 while (c != '\n' && c != EOF)
582 c = lgetc(0); /* nothing */
584 if (c == '$' && parsebuf == NULL) {
585 while (1) {
586 c = lgetc(0);
587 if (c == EOF)
588 return (0);
590 if (p + 1 >= buf + sizeof(buf) - 1) {
591 yyerror("string too long");
592 return (findeol());
594 if (isalnum(c) || c == '_') {
595 *p++ = c;
596 continue;
598 *p = '\0';
599 lungetc(c);
600 break;
602 val = symget(buf);
603 if (val == NULL) {
604 yyerror("macro '%s' not defined", buf);
605 return (findeol());
607 parsebuf = val;
608 parseindex = 0;
609 goto top;
612 switch (c) {
613 case '\'':
614 case '"':
615 quotec = c;
616 while (1) {
617 c = lgetc(quotec);
618 if (c == EOF)
619 return (0);
620 if (c == '\n') {
621 file->lineno++;
622 continue;
623 } else if (c == '\\') {
624 next = lgetc(quotec);
625 if (next == EOF)
626 return (0);
627 if (next == quotec || c == ' ' || c == '\t')
628 c = next;
629 else if (next == '\n') {
630 file->lineno++;
631 continue;
632 } else
633 lungetc(next);
634 } else if (c == quotec) {
635 *p = '\0';
636 break;
637 } else if (c == '\0') {
638 yyerror("syntax error");
639 return (findeol());
641 if (p + 1 >= buf + sizeof(buf) - 1) {
642 yyerror("string too long");
643 return (findeol());
645 *p++ = c;
647 yylval.v.string = strdup(buf);
648 if (yylval.v.string == NULL)
649 err(1, "yylex: strdup");
650 return (STRING);
653 #define allowed_to_end_number(x) \
654 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
656 if (c == '-' || isdigit(c)) {
657 do {
658 *p++ = c;
659 if ((unsigned)(p-buf) >= sizeof(buf)) {
660 yyerror("string too long");
661 return (findeol());
663 c = lgetc(0);
664 } while (c != EOF && isdigit(c));
665 lungetc(c);
666 if (p == buf + 1 && buf[0] == '-')
667 goto nodigits;
668 if (c == EOF || allowed_to_end_number(c)) {
669 const char *errstr = NULL;
671 *p = '\0';
672 yylval.v.number = strtonum(buf, LLONG_MIN,
673 LLONG_MAX, &errstr);
674 if (errstr) {
675 yyerror("\"%s\" invalid number: %s",
676 buf, errstr);
677 return (findeol());
679 return (NUMBER);
680 } else {
681 nodigits:
682 while (p > buf + 1)
683 lungetc(*--p);
684 c = *--p;
685 if (c == '-')
686 return (c);
690 #define allowed_in_string(x) \
691 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
692 x != '{' && x != '}' && \
693 x != '!' && x != '=' && x != '#' && \
694 x != ','))
696 if (isalnum(c) || c == ':' || c == '_') {
697 do {
698 *p++ = c;
699 if ((unsigned)(p-buf) >= sizeof(buf)) {
700 yyerror("string too long");
701 return (findeol());
703 c = lgetc(0);
704 } while (c != EOF && (allowed_in_string(c)));
705 lungetc(c);
706 *p = '\0';
707 token = lookup(buf);
708 if (token == STRING) {
709 yylval.v.string = strdup(buf);
710 if (yylval.v.string == NULL)
711 err(1, "yylex: strdup");
713 return (token);
715 if (c == '\n') {
716 yylval.lineno = file->lineno;
717 file->lineno++;
719 if (c == EOF)
720 return (0);
721 return (c);
724 int
725 check_file_secrecy(int fd, const char *fname)
727 struct stat st;
729 if (fstat(fd, &st)) {
730 log_warn("cannot stat %s", fname);
731 return (-1);
733 if (st.st_uid != 0 && st.st_uid != getuid()) {
734 log_warnx("%s: owner not root or current user", fname);
735 return (-1);
737 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
738 log_warnx("%s: group writable or world read/writable", fname);
739 return (-1);
741 return (0);
744 struct file *
745 newfile(const char *name, int secret)
747 struct file *nfile;
749 nfile = calloc(1, sizeof(struct file));
750 if (nfile == NULL) {
751 log_warn("calloc");
752 return (NULL);
754 nfile->name = strdup(name);
755 if (nfile->name == NULL) {
756 log_warn("strdup");
757 free(nfile);
758 return (NULL);
760 nfile->stream = fopen(nfile->name, "r");
761 if (nfile->stream == NULL) {
762 /* no warning, we don't require a conf file */
763 free(nfile->name);
764 free(nfile);
765 return (NULL);
766 } else if (secret &&
767 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
768 fclose(nfile->stream);
769 free(nfile->name);
770 free(nfile);
771 return (NULL);
773 nfile->lineno = 1;
774 return (nfile);
777 static void
778 closefile(struct file *xfile)
780 fclose(xfile->stream);
781 free(xfile->name);
782 free(xfile);
785 static void
786 add_default_server(void)
788 new_srv = conf_new_server(D_SITENAME);
789 log_debug("%s: adding default server %s", __func__, D_SITENAME);
792 int
793 parse_config(const char *filename, struct gotwebd *env)
795 struct sym *sym, *next;
797 if (config_init(env) == -1)
798 fatalx("failed to initialize configuration");
800 gotwebd = env;
802 file = newfile(filename, 0);
803 if (file == NULL) {
804 add_default_server();
805 sockets_parse_sockets(env);
806 /* just return, as we don't require a conf file */
807 return (0);
810 yyparse();
811 errors = file->errors;
812 closefile(file);
814 /* Free macros and check which have not been used. */
815 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
816 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
817 fprintf(stderr, "warning: macro '%s' not used\n",
818 sym->nam);
819 if (!sym->persist) {
820 free(sym->nam);
821 free(sym->val);
822 TAILQ_REMOVE(&symhead, sym, entry);
823 free(sym);
827 if (errors)
828 return (-1);
830 /* just add default server if no config specified */
831 if (gotwebd->server_cnt == 0)
832 add_default_server();
834 /* setup our listening sockets */
835 sockets_parse_sockets(env);
837 return (0);
840 struct server *
841 conf_new_server(const char *name)
843 struct server *srv = NULL;
845 srv = calloc(1, sizeof(*srv));
846 if (srv == NULL)
847 fatalx("%s: calloc", __func__);
849 n = strlcpy(srv->name, name, sizeof(srv->name));
850 if (n >= sizeof(srv->name))
851 fatalx("%s: strlcpy", __func__);
852 n = snprintf(srv->unix_socket_name,
853 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
854 D_UNIX_SOCKET);
855 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
856 fatalx("%s: snprintf", __func__);
857 n = strlcpy(srv->repos_path, D_GOTPATH,
858 sizeof(srv->repos_path));
859 if (n >= sizeof(srv->repos_path))
860 fatalx("%s: strlcpy", __func__);
861 n = strlcpy(srv->site_name, D_SITENAME,
862 sizeof(srv->site_name));
863 if (n >= sizeof(srv->site_name))
864 fatalx("%s: strlcpy", __func__);
865 n = strlcpy(srv->site_owner, D_SITEOWNER,
866 sizeof(srv->site_owner));
867 if (n >= sizeof(srv->site_owner))
868 fatalx("%s: strlcpy", __func__);
869 n = strlcpy(srv->site_link, D_SITELINK,
870 sizeof(srv->site_link));
871 if (n >= sizeof(srv->site_link))
872 fatalx("%s: strlcpy", __func__);
873 n = strlcpy(srv->logo, D_GOTLOGO,
874 sizeof(srv->logo));
875 if (n >= sizeof(srv->logo))
876 fatalx("%s: strlcpy", __func__);
877 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
878 if (n >= sizeof(srv->logo_url))
879 fatalx("%s: strlcpy", __func__);
880 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
881 if (n >= sizeof(srv->custom_css))
882 fatalx("%s: strlcpy", __func__);
884 srv->show_site_owner = D_SHOWSOWNER;
885 srv->show_repo_owner = D_SHOWROWNER;
886 srv->show_repo_age = D_SHOWAGE;
887 srv->show_repo_description = D_SHOWDESC;
888 srv->show_repo_cloneurl = D_SHOWURL;
889 srv->respect_exportok = D_RESPECTEXPORTOK;
891 srv->max_repos_display = D_MAXREPODISP;
892 srv->max_commits_display = D_MAXCOMMITDISP;
893 srv->max_repos = D_MAXREPO;
895 srv->unix_socket = 1;
896 srv->fcgi_socket = 0;
898 TAILQ_INIT(&srv->al);
899 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
900 gotwebd->server_cnt++;
902 return srv;
903 };
905 int
906 symset(const char *nam, const char *val, int persist)
908 struct sym *sym;
910 TAILQ_FOREACH(sym, &symhead, entry) {
911 if (strcmp(nam, sym->nam) == 0)
912 break;
915 if (sym != NULL) {
916 if (sym->persist == 1)
917 return (0);
918 else {
919 free(sym->nam);
920 free(sym->val);
921 TAILQ_REMOVE(&symhead, sym, entry);
922 free(sym);
925 sym = calloc(1, sizeof(*sym));
926 if (sym == NULL)
927 return (-1);
929 sym->nam = strdup(nam);
930 if (sym->nam == NULL) {
931 free(sym);
932 return (-1);
934 sym->val = strdup(val);
935 if (sym->val == NULL) {
936 free(sym->nam);
937 free(sym);
938 return (-1);
940 sym->used = 0;
941 sym->persist = persist;
942 TAILQ_INSERT_TAIL(&symhead, sym, entry);
943 return (0);
946 int
947 cmdline_symset(char *s)
949 char *sym, *val;
950 int ret;
952 val = strrchr(s, '=');
953 if (val == NULL)
954 return (-1);
956 sym = strndup(s, val - s);
957 if (sym == NULL)
958 fatal("%s: strndup", __func__);
960 ret = symset(sym, val + 1, 1);
961 free(sym);
963 return (ret);
966 char *
967 symget(const char *nam)
969 struct sym *sym;
971 TAILQ_FOREACH(sym, &symhead, entry) {
972 if (strcmp(nam, sym->nam) == 0) {
973 sym->used = 1;
974 return (sym->val);
977 return (NULL);
980 int
981 getservice(const char *n)
983 struct servent *s;
984 const char *errstr;
985 long long llval;
987 llval = strtonum(n, 0, UINT16_MAX, &errstr);
988 if (errstr) {
989 s = getservbyname(n, "tcp");
990 if (s == NULL)
991 s = getservbyname(n, "udp");
992 if (s == NULL)
993 return (-1);
994 return ntohs(s->s_port);
997 return (unsigned short)llval;
1000 int
1001 host(const char *s, struct server *new_srv, int max,
1002 in_port_t port, const char *ifname, int ipproto)
1004 struct addrinfo hints, *res0, *res;
1005 int error, cnt = 0;
1006 struct sockaddr_in *sain;
1007 struct sockaddr_in6 *sin6;
1008 struct address *h;
1010 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1011 return (cnt);
1013 memset(&hints, 0, sizeof(hints));
1014 hints.ai_family = PF_UNSPEC;
1015 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1016 hints.ai_flags = AI_ADDRCONFIG;
1017 error = getaddrinfo(s, NULL, &hints, &res0);
1018 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1019 return (0);
1020 if (error) {
1021 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1022 gai_strerror(error));
1023 return (-1);
1026 for (res = res0; res && cnt < max; res = res->ai_next) {
1027 if (res->ai_family != AF_INET &&
1028 res->ai_family != AF_INET6)
1029 continue;
1030 if ((h = calloc(1, sizeof(*h))) == NULL)
1031 fatal(__func__);
1033 if (port)
1034 h->port = port;
1035 if (ifname != NULL) {
1036 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1037 sizeof(h->ifname)) {
1038 log_warnx("%s: interface name truncated",
1039 __func__);
1040 freeaddrinfo(res0);
1041 free(h);
1042 return (-1);
1045 if (ipproto != -1)
1046 h->ipproto = ipproto;
1047 h->ss.ss_family = res->ai_family;
1049 if (res->ai_family == AF_INET) {
1050 struct sockaddr_in *ra;
1051 sain = (struct sockaddr_in *)&h->ss;
1052 ra = (struct sockaddr_in *)res->ai_addr;
1053 got_sockaddr_inet_init(sain, &ra->sin_addr);
1054 } else {
1055 struct sockaddr_in6 *ra;
1056 sin6 = (struct sockaddr_in6 *)&h->ss;
1057 ra = (struct sockaddr_in6 *)res->ai_addr;
1058 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1061 if (add_addr(new_srv, h))
1062 return -1;
1063 cnt++;
1065 if (cnt == max && res) {
1066 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1067 s, max);
1069 freeaddrinfo(res0);
1070 return (cnt);
1073 int
1074 host_if(const char *s, struct server *new_srv, int max,
1075 in_port_t port, const char *ifname, int ipproto)
1077 struct ifaddrs *ifap, *p;
1078 struct sockaddr_in *sain;
1079 struct sockaddr_in6 *sin6;
1080 struct address *h;
1081 int cnt = 0, af;
1083 if (getifaddrs(&ifap) == -1)
1084 fatal("getifaddrs");
1086 /* First search for IPv4 addresses */
1087 af = AF_INET;
1089 nextaf:
1090 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1091 if (p->ifa_addr == NULL ||
1092 p->ifa_addr->sa_family != af ||
1093 (strcmp(s, p->ifa_name) != 0 &&
1094 !is_if_in_group(p->ifa_name, s)))
1095 continue;
1096 if ((h = calloc(1, sizeof(*h))) == NULL)
1097 fatal("calloc");
1099 if (port)
1100 h->port = port;
1101 if (ifname != NULL) {
1102 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1103 sizeof(h->ifname)) {
1104 log_warnx("%s: interface name truncated",
1105 __func__);
1106 free(h);
1107 freeifaddrs(ifap);
1108 return (-1);
1111 if (ipproto != -1)
1112 h->ipproto = ipproto;
1113 h->ss.ss_family = af;
1115 if (af == AF_INET) {
1116 struct sockaddr_in *ra;
1117 sain = (struct sockaddr_in *)&h->ss;
1118 ra = (struct sockaddr_in *)p->ifa_addr;
1119 got_sockaddr_inet_init(sain, &ra->sin_addr);
1120 } else {
1121 struct sockaddr_in6 *ra;
1122 sin6 = (struct sockaddr_in6 *)&h->ss;
1123 ra = (struct sockaddr_in6 *)p->ifa_addr;
1124 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1125 ra->sin6_scope_id);
1128 if (add_addr(new_srv, h))
1129 return -1;
1130 cnt++;
1132 if (af == AF_INET) {
1133 /* Next search for IPv6 addresses */
1134 af = AF_INET6;
1135 goto nextaf;
1138 if (cnt > max) {
1139 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1140 s, max);
1142 freeifaddrs(ifap);
1143 return (cnt);
1146 int
1147 is_if_in_group(const char *ifname, const char *groupname)
1149 unsigned int len;
1150 struct ifgroupreq ifgr;
1151 struct ifg_req *ifg;
1152 int s;
1153 int ret = 0;
1155 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1156 err(1, "socket");
1158 memset(&ifgr, 0, sizeof(ifgr));
1159 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1160 err(1, "IFNAMSIZ");
1161 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1162 if (errno == EINVAL || errno == ENOTTY)
1163 goto end;
1164 err(1, "SIOCGIFGROUP");
1167 len = ifgr.ifgr_len;
1168 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1169 sizeof(struct ifg_req));
1170 if (ifgr.ifgr_groups == NULL)
1171 err(1, "getifgroups");
1172 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1173 err(1, "SIOCGIFGROUP");
1175 ifg = ifgr.ifgr_groups;
1176 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1177 len -= sizeof(struct ifg_req);
1178 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1179 ret = 1;
1180 break;
1183 free(ifgr.ifgr_groups);
1185 end:
1186 close(s);
1187 return (ret);
1190 int
1191 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1193 if (strcmp("", addr) == 0) {
1194 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1195 -1) <= 0) {
1196 yyerror("invalid listen ip: %s",
1197 "127.0.0.1");
1198 return (-1);
1200 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1201 yyerror("invalid listen ip: %s", "::1");
1202 return (-1);
1204 } else {
1205 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1206 -1) <= 0) {
1207 yyerror("invalid listen ip: %s", addr);
1208 return (-1);
1211 return (0);
1214 int
1215 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1216 const char *other_srv)
1218 struct address *a;
1219 void *ia;
1220 char buf[INET6_ADDRSTRLEN];
1221 const char *addrstr;
1223 TAILQ_FOREACH(a, al, entry) {
1224 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1225 a->port != h->port)
1226 continue;
1228 switch (h->ss.ss_family) {
1229 case AF_INET:
1230 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1231 break;
1232 case AF_INET6:
1233 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1234 break;
1235 default:
1236 yyerror("unknown address family: %d", h->ss.ss_family);
1237 return -1;
1239 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1240 if (addrstr) {
1241 if (other_srv) {
1242 yyerror("server %s: duplicate fcgi listen "
1243 "address %s:%d, already used by server %s",
1244 new_srv, addrstr, h->port, other_srv);
1245 } else {
1246 log_warnx("server: %s: duplicate fcgi listen "
1247 "address %s:%d", new_srv, addrstr, h->port);
1249 } else {
1250 if (other_srv) {
1251 yyerror("server: %s: duplicate fcgi listen "
1252 "address, already used by server %s",
1253 new_srv, other_srv);
1254 } else {
1255 log_warnx("server %s: duplicate fcgi listen "
1256 "address", new_srv);
1260 return -1;
1263 return 0;
1266 int
1267 add_addr(struct server *new_srv, struct address *h)
1269 struct server *srv;
1271 /* Address cannot be shared between different servers. */
1272 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1273 if (srv == new_srv)
1274 continue;
1275 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1276 return -1;
1279 /* Tolerate duplicate address lines within the scope of a server. */
1280 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1281 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1282 else
1283 free(h);
1285 return 0;