Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <unistd.h>
50 #include "got_sockaddr.h"
51 #include "got_reference.h"
53 #include "proc.h"
54 #include "gotwebd.h"
56 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
57 static struct file {
58 TAILQ_ENTRY(file) entry;
59 FILE *stream;
60 char *name;
61 int lineno;
62 int errors;
63 } *file;
64 struct file *newfile(const char *, int);
65 static void closefile(struct file *);
66 int check_file_secrecy(int, const char *);
67 int yyparse(void);
68 int yylex(void);
69 int yyerror(const char *, ...)
70 __attribute__((__format__ (printf, 1, 2)))
71 __attribute__((__nonnull__ (1)));
72 int kw_cmp(const void *, const void *);
73 int lookup(char *);
74 int lgetc(int);
75 int lungetc(int);
76 int findeol(void);
78 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
79 struct sym {
80 TAILQ_ENTRY(sym) entry;
81 int used;
82 int persist;
83 char *nam;
84 char *val;
85 };
87 int symset(const char *, const char *, int);
88 char *symget(const char *);
90 static int errors;
92 static struct gotwebd *gotwebd;
93 static struct server *new_srv;
94 static struct server *conf_new_server(const char *);
95 int getservice(const char *);
96 int n;
98 int get_addrs(const char *, struct server *, in_port_t);
99 int addr_dup_check(struct addresslist *, struct address *,
100 const char *, const char *);
101 int add_addr(struct server *, struct address *);
102 int host(const char *, struct server *,
103 int, in_port_t, const char *, int);
104 int host_if(const char *, struct server *,
105 int, in_port_t, const char *, int);
106 int is_if_in_group(const char *, const char *);
108 typedef struct {
109 union {
110 long long number;
111 char *string;
112 in_port_t port;
113 } v;
114 int lineno;
115 } YYSTYPE;
117 %}
119 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
120 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
121 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
122 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
123 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
125 %token <v.string> STRING
126 %type <v.port> fcgiport
127 %token <v.number> NUMBER
128 %type <v.number> boolean
130 %%
132 grammar : /* empty */
133 | grammar '\n'
134 | grammar varset '\n'
135 | grammar main '\n'
136 | grammar server '\n'
137 | grammar error '\n' { file->errors++; }
140 varset : STRING '=' STRING {
141 char *s = $1;
142 while (*s++) {
143 if (isspace((unsigned char)*s)) {
144 yyerror("macro name cannot contain "
145 "whitespace");
146 free($1);
147 free($3);
148 YYERROR;
151 if (symset($1, $3, 0) == -1)
152 fatal("cannot store variable");
153 free($1);
154 free($3);
158 boolean : STRING {
159 if (strcasecmp($1, "1") == 0 ||
160 strcasecmp($1, "on") == 0)
161 $$ = 1;
162 else if (strcasecmp($1, "0") == 0 ||
163 strcasecmp($1, "off") == 0)
164 $$ = 0;
165 else {
166 yyerror("invalid boolean value '%s'", $1);
167 free($1);
168 YYERROR;
170 free($1);
172 | ON { $$ = 1; }
173 | NUMBER {
174 if ($1 != 0 && $1 != 1) {
175 yyerror("invalid boolean value '%lld'", $1);
176 YYERROR;
178 $$ = $1;
182 fcgiport : PORT NUMBER {
183 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
184 yyerror("invalid port: %lld", $2);
185 YYERROR;
187 $$ = $2;
189 | PORT STRING {
190 int val;
192 if ((val = getservice($2)) == -1) {
193 yyerror("invalid port: %s", $2);
194 free($2);
195 YYERROR;
197 free($2);
199 $$ = val;
203 main : PREFORK NUMBER {
204 if ($2 <= 0 || $2 > PROC_MAX_INSTANCES) {
205 yyerror("prefork is %s: %lld",
206 $2 <= 0 ? "too small" : "too large", $2);
207 YYERROR;
209 gotwebd->prefork_gotwebd = $2;
211 | CHROOT STRING {
212 if (*$2 == '\0') {
213 yyerror("chroot path can't be an empty"
214 " string");
215 free($2);
216 YYERROR;
219 n = strlcpy(gotwebd->httpd_chroot, $2,
220 sizeof(gotwebd->httpd_chroot));
221 if (n >= sizeof(gotwebd->httpd_chroot)) {
222 yyerror("%s: httpd_chroot truncated", __func__);
223 free($2);
224 YYERROR;
226 free($2);
228 | UNIX_SOCKET boolean {
229 gotwebd->unix_socket = $2;
231 | UNIX_SOCKET_NAME STRING {
232 n = snprintf(gotwebd->unix_socket_name,
233 sizeof(gotwebd->unix_socket_name), "%s%s",
234 gotwebd->httpd_chroot, $2);
235 if (n < 0 ||
236 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
237 yyerror("%s: unix_socket_name truncated",
238 __func__);
239 free($2);
240 YYERROR;
242 free($2);
246 server : SERVER STRING {
247 struct server *srv;
249 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
250 if (strcmp(srv->name, $2) == 0) {
251 yyerror("server name exists '%s'", $2);
252 free($2);
253 YYERROR;
257 new_srv = conf_new_server($2);
258 log_debug("adding server %s", $2);
259 free($2);
261 | SERVER STRING {
262 struct server *srv;
264 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
265 if (strcmp(srv->name, $2) == 0) {
266 yyerror("server name exists '%s'", $2);
267 free($2);
268 YYERROR;
272 new_srv = conf_new_server($2);
273 log_debug("adding server %s", $2);
274 free($2);
275 } '{' optnl serveropts2 '}' {
279 serveropts1 : REPOS_PATH STRING {
280 n = strlcpy(new_srv->repos_path, $2,
281 sizeof(new_srv->repos_path));
282 if (n >= sizeof(new_srv->repos_path)) {
283 yyerror("%s: repos_path truncated", __func__);
284 free($2);
285 YYERROR;
287 free($2);
289 | SITE_NAME STRING {
290 n = strlcpy(new_srv->site_name, $2,
291 sizeof(new_srv->site_name));
292 if (n >= sizeof(new_srv->site_name)) {
293 yyerror("%s: site_name truncated", __func__);
294 free($2);
295 YYERROR;
297 free($2);
299 | SITE_OWNER STRING {
300 n = strlcpy(new_srv->site_owner, $2,
301 sizeof(new_srv->site_owner));
302 if (n >= sizeof(new_srv->site_owner)) {
303 yyerror("%s: site_owner truncated", __func__);
304 free($2);
305 YYERROR;
307 free($2);
309 | SITE_LINK STRING {
310 n = strlcpy(new_srv->site_link, $2,
311 sizeof(new_srv->site_link));
312 if (n >= sizeof(new_srv->site_link)) {
313 yyerror("%s: site_link truncated", __func__);
314 free($2);
315 YYERROR;
317 free($2);
319 | LOGO STRING {
320 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
321 if (n >= sizeof(new_srv->logo)) {
322 yyerror("%s: logo truncated", __func__);
323 free($2);
324 YYERROR;
326 free($2);
328 | LOGO_URL STRING {
329 n = strlcpy(new_srv->logo_url, $2,
330 sizeof(new_srv->logo_url));
331 if (n >= sizeof(new_srv->logo_url)) {
332 yyerror("%s: logo_url truncated", __func__);
333 free($2);
334 YYERROR;
336 free($2);
338 | CUSTOM_CSS STRING {
339 n = strlcpy(new_srv->custom_css, $2,
340 sizeof(new_srv->custom_css));
341 if (n >= sizeof(new_srv->custom_css)) {
342 yyerror("%s: custom_css truncated", __func__);
343 free($2);
344 YYERROR;
346 free($2);
348 | LISTEN ON STRING fcgiport {
349 if (get_addrs($3, new_srv, $4) == -1) {
350 yyerror("could not get addrs");
351 YYERROR;
353 new_srv->fcgi_socket = 1;
355 | LISTEN ON SOCKET STRING {
356 if (strcasecmp($4, "off") == 0) {
357 new_srv->unix_socket = 0;
358 free($4);
359 YYACCEPT;
362 new_srv->unix_socket = 1;
364 n = snprintf(new_srv->unix_socket_name,
365 sizeof(new_srv->unix_socket_name), "%s%s",
366 gotwebd->httpd_chroot, $4);
367 if (n < 0 ||
368 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
369 yyerror("%s: unix_socket_name truncated",
370 __func__);
371 free($4);
372 YYERROR;
374 free($4);
376 | MAX_REPOS NUMBER {
377 if ($2 <= 0) {
378 yyerror("max_repos is too small: %lld", $2);
379 YYERROR;
381 new_srv->max_repos = $2;
383 | SHOW_SITE_OWNER boolean {
384 new_srv->show_site_owner = $2;
386 | SHOW_REPO_OWNER boolean {
387 new_srv->show_repo_owner = $2;
389 | SHOW_REPO_AGE boolean {
390 new_srv->show_repo_age = $2;
392 | SHOW_REPO_DESCRIPTION boolean {
393 new_srv->show_repo_description = $2;
395 | SHOW_REPO_CLONEURL boolean {
396 new_srv->show_repo_cloneurl = $2;
398 | RESPECT_EXPORTOK boolean {
399 new_srv->respect_exportok = $2;
401 | MAX_REPOS_DISPLAY NUMBER {
402 if ($2 < 0) {
403 yyerror("max_repos_display is too small: %lld",
404 $2);
405 YYERROR;
407 new_srv->max_repos_display = $2;
409 | MAX_COMMITS_DISPLAY NUMBER {
410 if ($2 <= 1) {
411 yyerror("max_commits_display is too small:"
412 " %lld", $2);
413 YYERROR;
415 new_srv->max_commits_display = $2;
419 serveropts2 : serveropts2 serveropts1 nl
420 | serveropts1 optnl
423 nl : '\n' optnl
426 optnl : '\n' optnl /* zero or more newlines */
427 | /* empty */
430 %%
432 struct keywords {
433 const char *k_name;
434 int k_val;
435 };
437 int
438 yyerror(const char *fmt, ...)
440 va_list ap;
441 char *msg;
443 file->errors++;
444 va_start(ap, fmt);
445 if (vasprintf(&msg, fmt, ap) == -1)
446 fatalx("yyerror vasprintf");
447 va_end(ap);
448 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
449 free(msg);
450 return (0);
453 int
454 kw_cmp(const void *k, const void *e)
456 return (strcmp(k, ((const struct keywords *)e)->k_name));
459 int
460 lookup(char *s)
462 /* This has to be sorted always. */
463 static const struct keywords keywords[] = {
464 { "chroot", CHROOT },
465 { "custom_css", CUSTOM_CSS },
466 { "listen", LISTEN },
467 { "logo", LOGO },
468 { "logo_url", LOGO_URL },
469 { "max_commits_display", MAX_COMMITS_DISPLAY },
470 { "max_repos", MAX_REPOS },
471 { "max_repos_display", MAX_REPOS_DISPLAY },
472 { "on", ON },
473 { "port", PORT },
474 { "prefork", PREFORK },
475 { "repos_path", REPOS_PATH },
476 { "respect_exportok", RESPECT_EXPORTOK },
477 { "server", SERVER },
478 { "show_repo_age", SHOW_REPO_AGE },
479 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
480 { "show_repo_description", SHOW_REPO_DESCRIPTION },
481 { "show_repo_owner", SHOW_REPO_OWNER },
482 { "show_site_owner", SHOW_SITE_OWNER },
483 { "site_link", SITE_LINK },
484 { "site_name", SITE_NAME },
485 { "site_owner", SITE_OWNER },
486 { "socket", SOCKET },
487 { "unix_socket", UNIX_SOCKET },
488 { "unix_socket_name", UNIX_SOCKET_NAME },
489 };
490 const struct keywords *p;
492 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
493 sizeof(keywords[0]), kw_cmp);
495 if (p)
496 return (p->k_val);
497 else
498 return (STRING);
501 #define MAXPUSHBACK 128
503 unsigned char *parsebuf;
504 int parseindex;
505 unsigned char pushback_buffer[MAXPUSHBACK];
506 int pushback_index = 0;
508 int
509 lgetc(int quotec)
511 int c, next;
513 if (parsebuf) {
514 /* Read character from the parsebuffer instead of input. */
515 if (parseindex >= 0) {
516 c = parsebuf[parseindex++];
517 if (c != '\0')
518 return (c);
519 parsebuf = NULL;
520 } else
521 parseindex++;
524 if (pushback_index)
525 return (pushback_buffer[--pushback_index]);
527 if (quotec) {
528 c = getc(file->stream);
529 if (c == EOF)
530 yyerror("reached end of file while parsing "
531 "quoted string");
532 return (c);
535 c = getc(file->stream);
536 while (c == '\\') {
537 next = getc(file->stream);
538 if (next != '\n') {
539 c = next;
540 break;
542 yylval.lineno = file->lineno;
543 file->lineno++;
544 c = getc(file->stream);
547 return (c);
550 int
551 lungetc(int c)
553 if (c == EOF)
554 return (EOF);
555 if (parsebuf) {
556 parseindex--;
557 if (parseindex >= 0)
558 return (c);
560 if (pushback_index < MAXPUSHBACK-1)
561 return (pushback_buffer[pushback_index++] = c);
562 else
563 return (EOF);
566 int
567 findeol(void)
569 int c;
571 parsebuf = NULL;
573 /* Skip to either EOF or the first real EOL. */
574 while (1) {
575 if (pushback_index)
576 c = pushback_buffer[--pushback_index];
577 else
578 c = lgetc(0);
579 if (c == '\n') {
580 file->lineno++;
581 break;
583 if (c == EOF)
584 break;
586 return (ERROR);
589 int
590 yylex(void)
592 unsigned char buf[8096];
593 unsigned char *p, *val;
594 int quotec, next, c;
595 int token;
597 top:
598 p = buf;
599 c = lgetc(0);
600 while (c == ' ' || c == '\t')
601 c = lgetc(0); /* nothing */
603 yylval.lineno = file->lineno;
604 if (c == '#') {
605 c = lgetc(0);
606 while (c != '\n' && c != EOF)
607 c = lgetc(0); /* nothing */
609 if (c == '$' && parsebuf == NULL) {
610 while (1) {
611 c = lgetc(0);
612 if (c == EOF)
613 return (0);
615 if (p + 1 >= buf + sizeof(buf) - 1) {
616 yyerror("string too long");
617 return (findeol());
619 if (isalnum(c) || c == '_') {
620 *p++ = c;
621 continue;
623 *p = '\0';
624 lungetc(c);
625 break;
627 val = symget(buf);
628 if (val == NULL) {
629 yyerror("macro '%s' not defined", buf);
630 return (findeol());
632 parsebuf = val;
633 parseindex = 0;
634 goto top;
637 switch (c) {
638 case '\'':
639 case '"':
640 quotec = c;
641 while (1) {
642 c = lgetc(quotec);
643 if (c == EOF)
644 return (0);
645 if (c == '\n') {
646 file->lineno++;
647 continue;
648 } else if (c == '\\') {
649 next = lgetc(quotec);
650 if (next == EOF)
651 return (0);
652 if (next == quotec || c == ' ' || c == '\t')
653 c = next;
654 else if (next == '\n') {
655 file->lineno++;
656 continue;
657 } else
658 lungetc(next);
659 } else if (c == quotec) {
660 *p = '\0';
661 break;
662 } else if (c == '\0') {
663 yyerror("syntax error");
664 return (findeol());
666 if (p + 1 >= buf + sizeof(buf) - 1) {
667 yyerror("string too long");
668 return (findeol());
670 *p++ = c;
672 yylval.v.string = strdup(buf);
673 if (yylval.v.string == NULL)
674 err(1, "yylex: strdup");
675 return (STRING);
678 #define allowed_to_end_number(x) \
679 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
681 if (c == '-' || isdigit(c)) {
682 do {
683 *p++ = c;
684 if ((unsigned)(p-buf) >= sizeof(buf)) {
685 yyerror("string too long");
686 return (findeol());
688 c = lgetc(0);
689 } while (c != EOF && isdigit(c));
690 lungetc(c);
691 if (p == buf + 1 && buf[0] == '-')
692 goto nodigits;
693 if (c == EOF || allowed_to_end_number(c)) {
694 const char *errstr = NULL;
696 *p = '\0';
697 yylval.v.number = strtonum(buf, LLONG_MIN,
698 LLONG_MAX, &errstr);
699 if (errstr) {
700 yyerror("\"%s\" invalid number: %s",
701 buf, errstr);
702 return (findeol());
704 return (NUMBER);
705 } else {
706 nodigits:
707 while (p > buf + 1)
708 lungetc(*--p);
709 c = *--p;
710 if (c == '-')
711 return (c);
715 #define allowed_in_string(x) \
716 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
717 x != '{' && x != '}' && \
718 x != '!' && x != '=' && x != '#' && \
719 x != ','))
721 if (isalnum(c) || c == ':' || c == '_') {
722 do {
723 *p++ = c;
724 if ((unsigned)(p-buf) >= sizeof(buf)) {
725 yyerror("string too long");
726 return (findeol());
728 c = lgetc(0);
729 } while (c != EOF && (allowed_in_string(c)));
730 lungetc(c);
731 *p = '\0';
732 token = lookup(buf);
733 if (token == STRING) {
734 yylval.v.string = strdup(buf);
735 if (yylval.v.string == NULL)
736 err(1, "yylex: strdup");
738 return (token);
740 if (c == '\n') {
741 yylval.lineno = file->lineno;
742 file->lineno++;
744 if (c == EOF)
745 return (0);
746 return (c);
749 int
750 check_file_secrecy(int fd, const char *fname)
752 struct stat st;
754 if (fstat(fd, &st)) {
755 log_warn("cannot stat %s", fname);
756 return (-1);
758 if (st.st_uid != 0 && st.st_uid != getuid()) {
759 log_warnx("%s: owner not root or current user", fname);
760 return (-1);
762 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
763 log_warnx("%s: group writable or world read/writable", fname);
764 return (-1);
766 return (0);
769 struct file *
770 newfile(const char *name, int secret)
772 struct file *nfile;
774 nfile = calloc(1, sizeof(struct file));
775 if (nfile == NULL) {
776 log_warn("calloc");
777 return (NULL);
779 nfile->name = strdup(name);
780 if (nfile->name == NULL) {
781 log_warn("strdup");
782 free(nfile);
783 return (NULL);
785 nfile->stream = fopen(nfile->name, "r");
786 if (nfile->stream == NULL) {
787 /* no warning, we don't require a conf file */
788 free(nfile->name);
789 free(nfile);
790 return (NULL);
791 } else if (secret &&
792 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
793 fclose(nfile->stream);
794 free(nfile->name);
795 free(nfile);
796 return (NULL);
798 nfile->lineno = 1;
799 return (nfile);
802 static void
803 closefile(struct file *xfile)
805 fclose(xfile->stream);
806 free(xfile->name);
807 free(xfile);
810 static void
811 add_default_server(void)
813 new_srv = conf_new_server(D_SITENAME);
814 log_debug("%s: adding default server %s", __func__, D_SITENAME);
817 int
818 parse_config(const char *filename, struct gotwebd *env)
820 struct sym *sym, *next;
822 if (config_init(env) == -1)
823 fatalx("failed to initialize configuration");
825 gotwebd = env;
827 file = newfile(filename, 0);
828 if (file == NULL) {
829 add_default_server();
830 sockets_parse_sockets(env);
831 /* just return, as we don't require a conf file */
832 return (0);
835 yyparse();
836 errors = file->errors;
837 closefile(file);
839 /* Free macros and check which have not been used. */
840 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
841 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
842 fprintf(stderr, "warning: macro '%s' not used\n",
843 sym->nam);
844 if (!sym->persist) {
845 free(sym->nam);
846 free(sym->val);
847 TAILQ_REMOVE(&symhead, sym, entry);
848 free(sym);
852 if (errors)
853 return (-1);
855 /* just add default server if no config specified */
856 if (gotwebd->server_cnt == 0)
857 add_default_server();
859 /* setup our listening sockets */
860 sockets_parse_sockets(env);
862 return (0);
865 struct server *
866 conf_new_server(const char *name)
868 struct server *srv = NULL;
870 srv = calloc(1, sizeof(*srv));
871 if (srv == NULL)
872 fatalx("%s: calloc", __func__);
874 n = strlcpy(srv->name, name, sizeof(srv->name));
875 if (n >= sizeof(srv->name))
876 fatalx("%s: strlcpy", __func__);
877 n = snprintf(srv->unix_socket_name,
878 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
879 D_UNIX_SOCKET);
880 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
881 fatalx("%s: snprintf", __func__);
882 n = strlcpy(srv->repos_path, D_GOTPATH,
883 sizeof(srv->repos_path));
884 if (n >= sizeof(srv->repos_path))
885 fatalx("%s: strlcpy", __func__);
886 n = strlcpy(srv->site_name, D_SITENAME,
887 sizeof(srv->site_name));
888 if (n >= sizeof(srv->site_name))
889 fatalx("%s: strlcpy", __func__);
890 n = strlcpy(srv->site_owner, D_SITEOWNER,
891 sizeof(srv->site_owner));
892 if (n >= sizeof(srv->site_owner))
893 fatalx("%s: strlcpy", __func__);
894 n = strlcpy(srv->site_link, D_SITELINK,
895 sizeof(srv->site_link));
896 if (n >= sizeof(srv->site_link))
897 fatalx("%s: strlcpy", __func__);
898 n = strlcpy(srv->logo, D_GOTLOGO,
899 sizeof(srv->logo));
900 if (n >= sizeof(srv->logo))
901 fatalx("%s: strlcpy", __func__);
902 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
903 if (n >= sizeof(srv->logo_url))
904 fatalx("%s: strlcpy", __func__);
905 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
906 if (n >= sizeof(srv->custom_css))
907 fatalx("%s: strlcpy", __func__);
909 srv->show_site_owner = D_SHOWSOWNER;
910 srv->show_repo_owner = D_SHOWROWNER;
911 srv->show_repo_age = D_SHOWAGE;
912 srv->show_repo_description = D_SHOWDESC;
913 srv->show_repo_cloneurl = D_SHOWURL;
914 srv->respect_exportok = D_RESPECTEXPORTOK;
916 srv->max_repos_display = D_MAXREPODISP;
917 srv->max_commits_display = D_MAXCOMMITDISP;
918 srv->max_repos = D_MAXREPO;
920 srv->unix_socket = 1;
921 srv->fcgi_socket = 0;
923 TAILQ_INIT(&srv->al);
924 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
925 gotwebd->server_cnt++;
927 return srv;
928 };
930 int
931 symset(const char *nam, const char *val, int persist)
933 struct sym *sym;
935 TAILQ_FOREACH(sym, &symhead, entry) {
936 if (strcmp(nam, sym->nam) == 0)
937 break;
940 if (sym != NULL) {
941 if (sym->persist == 1)
942 return (0);
943 else {
944 free(sym->nam);
945 free(sym->val);
946 TAILQ_REMOVE(&symhead, sym, entry);
947 free(sym);
950 sym = calloc(1, sizeof(*sym));
951 if (sym == NULL)
952 return (-1);
954 sym->nam = strdup(nam);
955 if (sym->nam == NULL) {
956 free(sym);
957 return (-1);
959 sym->val = strdup(val);
960 if (sym->val == NULL) {
961 free(sym->nam);
962 free(sym);
963 return (-1);
965 sym->used = 0;
966 sym->persist = persist;
967 TAILQ_INSERT_TAIL(&symhead, sym, entry);
968 return (0);
971 int
972 cmdline_symset(char *s)
974 char *sym, *val;
975 int ret;
977 val = strrchr(s, '=');
978 if (val == NULL)
979 return (-1);
981 sym = strndup(s, val - s);
982 if (sym == NULL)
983 fatal("%s: strndup", __func__);
985 ret = symset(sym, val + 1, 1);
986 free(sym);
988 return (ret);
991 char *
992 symget(const char *nam)
994 struct sym *sym;
996 TAILQ_FOREACH(sym, &symhead, entry) {
997 if (strcmp(nam, sym->nam) == 0) {
998 sym->used = 1;
999 return (sym->val);
1002 return (NULL);
1005 int
1006 getservice(const char *n)
1008 struct servent *s;
1009 const char *errstr;
1010 long long llval;
1012 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1013 if (errstr) {
1014 s = getservbyname(n, "tcp");
1015 if (s == NULL)
1016 s = getservbyname(n, "udp");
1017 if (s == NULL)
1018 return (-1);
1019 return ntohs(s->s_port);
1022 return (unsigned short)llval;
1025 int
1026 host(const char *s, struct server *new_srv, int max,
1027 in_port_t port, const char *ifname, int ipproto)
1029 struct addrinfo hints, *res0, *res;
1030 int error, cnt = 0;
1031 struct sockaddr_in *sain;
1032 struct sockaddr_in6 *sin6;
1033 struct address *h;
1035 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1036 return (cnt);
1038 memset(&hints, 0, sizeof(hints));
1039 hints.ai_family = AF_UNSPEC;
1040 hints.ai_socktype = SOCK_STREAM; /* DUMMY */
1041 hints.ai_flags = AI_ADDRCONFIG;
1042 error = getaddrinfo(s, NULL, &hints, &res0);
1043 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1044 return (0);
1045 if (error) {
1046 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1047 gai_strerror(error));
1048 return (-1);
1051 for (res = res0; res && cnt < max; res = res->ai_next) {
1052 if (res->ai_family != AF_INET &&
1053 res->ai_family != AF_INET6)
1054 continue;
1055 if ((h = calloc(1, sizeof(*h))) == NULL)
1056 fatal(__func__);
1058 if (port)
1059 h->port = port;
1060 if (ifname != NULL) {
1061 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1062 sizeof(h->ifname)) {
1063 log_warnx("%s: interface name truncated",
1064 __func__);
1065 freeaddrinfo(res0);
1066 free(h);
1067 return (-1);
1070 if (ipproto != -1)
1071 h->ipproto = ipproto;
1072 h->ss.ss_family = res->ai_family;
1074 if (res->ai_family == AF_INET) {
1075 struct sockaddr_in *ra;
1076 sain = (struct sockaddr_in *)&h->ss;
1077 ra = (struct sockaddr_in *)res->ai_addr;
1078 got_sockaddr_inet_init(sain, &ra->sin_addr);
1079 } else {
1080 struct sockaddr_in6 *ra;
1081 sin6 = (struct sockaddr_in6 *)&h->ss;
1082 ra = (struct sockaddr_in6 *)res->ai_addr;
1083 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1086 if (add_addr(new_srv, h))
1087 return -1;
1088 cnt++;
1090 if (cnt == max && res) {
1091 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1092 s, max);
1094 freeaddrinfo(res0);
1095 return (cnt);
1098 int
1099 host_if(const char *s, struct server *new_srv, int max,
1100 in_port_t port, const char *ifname, int ipproto)
1102 struct ifaddrs *ifap, *p;
1103 struct sockaddr_in *sain;
1104 struct sockaddr_in6 *sin6;
1105 struct address *h;
1106 int cnt = 0, af;
1108 if (getifaddrs(&ifap) == -1)
1109 fatal("getifaddrs");
1111 /* First search for IPv4 addresses */
1112 af = AF_INET;
1114 nextaf:
1115 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1116 if (p->ifa_addr == NULL ||
1117 p->ifa_addr->sa_family != af ||
1118 (strcmp(s, p->ifa_name) != 0 &&
1119 !is_if_in_group(p->ifa_name, s)))
1120 continue;
1121 if ((h = calloc(1, sizeof(*h))) == NULL)
1122 fatal("calloc");
1124 if (port)
1125 h->port = port;
1126 if (ifname != NULL) {
1127 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1128 sizeof(h->ifname)) {
1129 log_warnx("%s: interface name truncated",
1130 __func__);
1131 free(h);
1132 freeifaddrs(ifap);
1133 return (-1);
1136 if (ipproto != -1)
1137 h->ipproto = ipproto;
1138 h->ss.ss_family = af;
1140 if (af == AF_INET) {
1141 struct sockaddr_in *ra;
1142 sain = (struct sockaddr_in *)&h->ss;
1143 ra = (struct sockaddr_in *)p->ifa_addr;
1144 got_sockaddr_inet_init(sain, &ra->sin_addr);
1145 } else {
1146 struct sockaddr_in6 *ra;
1147 sin6 = (struct sockaddr_in6 *)&h->ss;
1148 ra = (struct sockaddr_in6 *)p->ifa_addr;
1149 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1150 ra->sin6_scope_id);
1153 if (add_addr(new_srv, h))
1154 return -1;
1155 cnt++;
1157 if (af == AF_INET) {
1158 /* Next search for IPv6 addresses */
1159 af = AF_INET6;
1160 goto nextaf;
1163 if (cnt > max) {
1164 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1165 s, max);
1167 freeifaddrs(ifap);
1168 return (cnt);
1171 int
1172 is_if_in_group(const char *ifname, const char *groupname)
1174 unsigned int len;
1175 struct ifgroupreq ifgr;
1176 struct ifg_req *ifg;
1177 int s;
1178 int ret = 0;
1180 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1181 err(1, "socket");
1183 memset(&ifgr, 0, sizeof(ifgr));
1184 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1185 err(1, "IFNAMSIZ");
1186 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1187 if (errno == EINVAL || errno == ENOTTY)
1188 goto end;
1189 err(1, "SIOCGIFGROUP");
1192 len = ifgr.ifgr_len;
1193 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1194 sizeof(struct ifg_req));
1195 if (ifgr.ifgr_groups == NULL)
1196 err(1, "getifgroups");
1197 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1198 err(1, "SIOCGIFGROUP");
1200 ifg = ifgr.ifgr_groups;
1201 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1202 len -= sizeof(struct ifg_req);
1203 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1204 ret = 1;
1205 break;
1208 free(ifgr.ifgr_groups);
1210 end:
1211 close(s);
1212 return (ret);
1215 int
1216 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1218 if (strcmp("", addr) == 0) {
1219 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1220 -1) <= 0) {
1221 yyerror("invalid listen ip: %s",
1222 "127.0.0.1");
1223 return (-1);
1225 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1226 yyerror("invalid listen ip: %s", "::1");
1227 return (-1);
1229 } else {
1230 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1231 -1) <= 0) {
1232 yyerror("invalid listen ip: %s", addr);
1233 return (-1);
1236 return (0);
1239 int
1240 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1241 const char *other_srv)
1243 struct address *a;
1244 void *ia;
1245 char buf[INET6_ADDRSTRLEN];
1246 const char *addrstr;
1248 TAILQ_FOREACH(a, al, entry) {
1249 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1250 a->port != h->port)
1251 continue;
1253 switch (h->ss.ss_family) {
1254 case AF_INET:
1255 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1256 break;
1257 case AF_INET6:
1258 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1259 break;
1260 default:
1261 yyerror("unknown address family: %d", h->ss.ss_family);
1262 return -1;
1264 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1265 if (addrstr) {
1266 if (other_srv) {
1267 yyerror("server %s: duplicate fcgi listen "
1268 "address %s:%d, already used by server %s",
1269 new_srv, addrstr, h->port, other_srv);
1270 } else {
1271 log_warnx("server: %s: duplicate fcgi listen "
1272 "address %s:%d", new_srv, addrstr, h->port);
1274 } else {
1275 if (other_srv) {
1276 yyerror("server: %s: duplicate fcgi listen "
1277 "address, already used by server %s",
1278 new_srv, other_srv);
1279 } else {
1280 log_warnx("server %s: duplicate fcgi listen "
1281 "address", new_srv);
1285 return -1;
1288 return 0;
1291 int
1292 add_addr(struct server *new_srv, struct address *h)
1294 struct server *srv;
1296 /* Address cannot be shared between different servers. */
1297 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1298 if (srv == new_srv)
1299 continue;
1300 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1301 return -1;
1304 /* Tolerate duplicate address lines within the scope of a server. */
1305 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1306 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1307 else
1308 free(h);
1310 return 0;