Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <imsg.h>
41 #include <limits.h>
42 #include <netdb.h>
43 #include <stdarg.h>
44 #include <stdlib.h>
45 #include <stdio.h>
46 #include <string.h>
47 #include <syslog.h>
48 #include <unistd.h>
50 #include "got_sockaddr.h"
51 #include "got_reference.h"
53 #include "proc.h"
54 #include "gotwebd.h"
56 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
57 static struct file {
58 TAILQ_ENTRY(file) entry;
59 FILE *stream;
60 char *name;
61 int lineno;
62 int errors;
63 } *file;
64 struct file *newfile(const char *, int);
65 static void closefile(struct file *);
66 int check_file_secrecy(int, const char *);
67 int yyparse(void);
68 int yylex(void);
69 int yyerror(const char *, ...)
70 __attribute__((__format__ (printf, 1, 2)))
71 __attribute__((__nonnull__ (1)));
72 int kw_cmp(const void *, const void *);
73 int lookup(char *);
74 int lgetc(int);
75 int lungetc(int);
76 int findeol(void);
78 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
79 struct sym {
80 TAILQ_ENTRY(sym) entry;
81 int used;
82 int persist;
83 char *nam;
84 char *val;
85 };
87 int symset(const char *, const char *, int);
88 char *symget(const char *);
90 static int errors;
92 static struct gotwebd *gotwebd;
93 static struct server *new_srv;
94 static struct server *conf_new_server(const char *);
95 int getservice(const char *);
96 int n;
98 int get_addrs(const char *, struct server *, in_port_t);
99 int addr_dup_check(struct addresslist *, struct address *,
100 const char *, const char *);
101 int add_addr(struct server *, struct address *);
102 struct address *host_v4(const char *);
103 struct address *host_v6(const char *);
104 int host_dns(const char *, struct server *,
105 int, in_port_t, const char *, int);
106 int host_if(const char *, struct server *,
107 int, in_port_t, const char *, int);
108 int host(const char *, struct server *,
109 int, in_port_t, const char *, int);
110 int is_if_in_group(const char *, const char *);
112 typedef struct {
113 union {
114 long long number;
115 char *string;
116 in_port_t port;
117 } v;
118 int lineno;
119 } YYSTYPE;
121 %}
123 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
124 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
125 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
126 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
127 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
129 %token <v.string> STRING
130 %type <v.port> fcgiport
131 %token <v.number> NUMBER
132 %type <v.number> boolean
134 %%
136 grammar : /* empty */
137 | grammar '\n'
138 | grammar varset '\n'
139 | grammar main '\n'
140 | grammar server '\n'
141 | grammar error '\n' { file->errors++; }
144 varset : STRING '=' STRING {
145 char *s = $1;
146 while (*s++) {
147 if (isspace((unsigned char)*s)) {
148 yyerror("macro name cannot contain "
149 "whitespace");
150 free($1);
151 free($3);
152 YYERROR;
155 if (symset($1, $3, 0) == -1)
156 fatal("cannot store variable");
157 free($1);
158 free($3);
162 boolean : STRING {
163 if (strcasecmp($1, "1") == 0 ||
164 strcasecmp($1, "yes") == 0 ||
165 strcasecmp($1, "on") == 0)
166 $$ = 1;
167 else if (strcasecmp($1, "0") == 0 ||
168 strcasecmp($1, "off") == 0 ||
169 strcasecmp($1, "no") == 0)
170 $$ = 0;
171 else {
172 yyerror("invalid boolean value '%s'", $1);
173 free($1);
174 YYERROR;
176 free($1);
178 | ON { $$ = 1; }
179 | NUMBER { $$ = $1; }
182 fcgiport : PORT NUMBER {
183 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
184 yyerror("invalid port: %lld", $2);
185 YYERROR;
187 $$ = $2;
189 | PORT STRING {
190 int val;
192 if ((val = getservice($2)) == -1) {
193 yyerror("invalid port: %s", $2);
194 free($2);
195 YYERROR;
197 free($2);
199 $$ = val;
203 main : PREFORK NUMBER {
204 gotwebd->prefork_gotwebd = $2;
206 | CHROOT STRING {
207 n = strlcpy(gotwebd->httpd_chroot, $2,
208 sizeof(gotwebd->httpd_chroot));
209 if (n >= sizeof(gotwebd->httpd_chroot)) {
210 yyerror("%s: httpd_chroot truncated", __func__);
211 free($2);
212 YYERROR;
214 free($2);
216 | UNIX_SOCKET boolean {
217 gotwebd->unix_socket = $2;
219 | UNIX_SOCKET_NAME STRING {
220 n = snprintf(gotwebd->unix_socket_name,
221 sizeof(gotwebd->unix_socket_name), "%s%s",
222 strlen(gotwebd->httpd_chroot) ?
223 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
224 if (n < 0 ||
225 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
226 yyerror("%s: unix_socket_name truncated",
227 __func__);
228 free($2);
229 YYERROR;
231 free($2);
235 server : SERVER STRING {
236 struct server *srv;
238 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
239 if (strcmp(srv->name, $2) == 0) {
240 yyerror("server name exists '%s'", $2);
241 free($2);
242 YYERROR;
246 new_srv = conf_new_server($2);
247 log_debug("adding server %s", $2);
248 free($2);
250 | SERVER STRING {
251 struct server *srv;
253 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
254 if (strcmp(srv->name, $2) == 0) {
255 yyerror("server name exists '%s'", $2);
256 free($2);
257 YYERROR;
261 new_srv = conf_new_server($2);
262 log_debug("adding server %s", $2);
263 free($2);
264 } '{' optnl serveropts2 '}' {
268 serveropts1 : REPOS_PATH STRING {
269 n = strlcpy(new_srv->repos_path, $2,
270 sizeof(new_srv->repos_path));
271 if (n >= sizeof(new_srv->repos_path)) {
272 yyerror("%s: repos_path truncated", __func__);
273 free($2);
274 YYERROR;
276 free($2);
278 | SITE_NAME STRING {
279 n = strlcpy(new_srv->site_name, $2,
280 sizeof(new_srv->site_name));
281 if (n >= sizeof(new_srv->site_name)) {
282 yyerror("%s: site_name truncated", __func__);
283 free($2);
284 YYERROR;
286 free($2);
288 | SITE_OWNER STRING {
289 n = strlcpy(new_srv->site_owner, $2,
290 sizeof(new_srv->site_owner));
291 if (n >= sizeof(new_srv->site_owner)) {
292 yyerror("%s: site_owner truncated", __func__);
293 free($2);
294 YYERROR;
296 free($2);
298 | SITE_LINK STRING {
299 n = strlcpy(new_srv->site_link, $2,
300 sizeof(new_srv->site_link));
301 if (n >= sizeof(new_srv->site_link)) {
302 yyerror("%s: site_link truncated", __func__);
303 free($2);
304 YYERROR;
306 free($2);
308 | LOGO STRING {
309 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
310 if (n >= sizeof(new_srv->logo)) {
311 yyerror("%s: logo truncated", __func__);
312 free($2);
313 YYERROR;
315 free($2);
317 | LOGO_URL STRING {
318 n = strlcpy(new_srv->logo_url, $2,
319 sizeof(new_srv->logo_url));
320 if (n >= sizeof(new_srv->logo_url)) {
321 yyerror("%s: logo_url truncated", __func__);
322 free($2);
323 YYERROR;
325 free($2);
327 | CUSTOM_CSS STRING {
328 n = strlcpy(new_srv->custom_css, $2,
329 sizeof(new_srv->custom_css));
330 if (n >= sizeof(new_srv->custom_css)) {
331 yyerror("%s: custom_css truncated", __func__);
332 free($2);
333 YYERROR;
335 free($2);
337 | LISTEN ON STRING fcgiport {
338 if (get_addrs($3, new_srv, $4) == -1) {
339 yyerror("could not get addrs");
340 YYERROR;
342 new_srv->fcgi_socket = 1;
344 | LISTEN ON SOCKET STRING {
345 if (!strcasecmp($4, "off") ||
346 !strcasecmp($4, "no")) {
347 new_srv->unix_socket = 0;
348 free($4);
349 YYACCEPT;
352 new_srv->unix_socket = 1;
354 n = snprintf(new_srv->unix_socket_name,
355 sizeof(new_srv->unix_socket_name), "%s%s",
356 strlen(gotwebd->httpd_chroot) ?
357 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $4);
358 if (n < 0 ||
359 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
360 yyerror("%s: unix_socket_name truncated",
361 __func__);
362 free($4);
363 YYERROR;
365 free($4);
367 | MAX_REPOS NUMBER {
368 if ($2 > 0)
369 new_srv->max_repos = $2;
371 | SHOW_SITE_OWNER boolean {
372 new_srv->show_site_owner = $2;
374 | SHOW_REPO_OWNER boolean {
375 new_srv->show_repo_owner = $2;
377 | SHOW_REPO_AGE boolean {
378 new_srv->show_repo_age = $2;
380 | SHOW_REPO_DESCRIPTION boolean {
381 new_srv->show_repo_description = $2;
383 | SHOW_REPO_CLONEURL boolean {
384 new_srv->show_repo_cloneurl = $2;
386 | RESPECT_EXPORTOK boolean {
387 new_srv->respect_exportok = $2;
389 | MAX_REPOS_DISPLAY NUMBER {
390 new_srv->max_repos_display = $2;
392 | MAX_COMMITS_DISPLAY NUMBER {
393 if ($2 > 0)
394 new_srv->max_commits_display = $2;
398 serveropts2 : serveropts2 serveropts1 nl
399 | serveropts1 optnl
402 nl : '\n' optnl
405 optnl : '\n' optnl /* zero or more newlines */
406 | /* empty */
409 %%
411 struct keywords {
412 const char *k_name;
413 int k_val;
414 };
416 int
417 yyerror(const char *fmt, ...)
419 va_list ap;
420 char *msg;
422 file->errors++;
423 va_start(ap, fmt);
424 if (vasprintf(&msg, fmt, ap) == -1)
425 fatalx("yyerror vasprintf");
426 va_end(ap);
427 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
428 free(msg);
429 return (0);
432 int
433 kw_cmp(const void *k, const void *e)
435 return (strcmp(k, ((const struct keywords *)e)->k_name));
438 int
439 lookup(char *s)
441 /* This has to be sorted always. */
442 static const struct keywords keywords[] = {
443 { "chroot", CHROOT },
444 { "custom_css", CUSTOM_CSS },
445 { "listen", LISTEN },
446 { "logo", LOGO },
447 { "logo_url", LOGO_URL },
448 { "max_commits_display", MAX_COMMITS_DISPLAY },
449 { "max_repos", MAX_REPOS },
450 { "max_repos_display", MAX_REPOS_DISPLAY },
451 { "on", ON },
452 { "port", PORT },
453 { "prefork", PREFORK },
454 { "repos_path", REPOS_PATH },
455 { "respect_exportok", RESPECT_EXPORTOK },
456 { "server", SERVER },
457 { "show_repo_age", SHOW_REPO_AGE },
458 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
459 { "show_repo_description", SHOW_REPO_DESCRIPTION },
460 { "show_repo_owner", SHOW_REPO_OWNER },
461 { "show_site_owner", SHOW_SITE_OWNER },
462 { "site_link", SITE_LINK },
463 { "site_name", SITE_NAME },
464 { "site_owner", SITE_OWNER },
465 { "socket", SOCKET },
466 { "unix_socket", UNIX_SOCKET },
467 { "unix_socket_name", UNIX_SOCKET_NAME },
468 };
469 const struct keywords *p;
471 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
472 sizeof(keywords[0]), kw_cmp);
474 if (p)
475 return (p->k_val);
476 else
477 return (STRING);
480 #define MAXPUSHBACK 128
482 unsigned char *parsebuf;
483 int parseindex;
484 unsigned char pushback_buffer[MAXPUSHBACK];
485 int pushback_index = 0;
487 int
488 lgetc(int quotec)
490 int c, next;
492 if (parsebuf) {
493 /* Read character from the parsebuffer instead of input. */
494 if (parseindex >= 0) {
495 c = parsebuf[parseindex++];
496 if (c != '\0')
497 return (c);
498 parsebuf = NULL;
499 } else
500 parseindex++;
503 if (pushback_index)
504 return (pushback_buffer[--pushback_index]);
506 if (quotec) {
507 c = getc(file->stream);
508 if (c == EOF)
509 yyerror("reached end of file while parsing "
510 "quoted string");
511 return (c);
514 c = getc(file->stream);
515 while (c == '\\') {
516 next = getc(file->stream);
517 if (next != '\n') {
518 c = next;
519 break;
521 yylval.lineno = file->lineno;
522 file->lineno++;
523 c = getc(file->stream);
526 return (c);
529 int
530 lungetc(int c)
532 if (c == EOF)
533 return (EOF);
534 if (parsebuf) {
535 parseindex--;
536 if (parseindex >= 0)
537 return (c);
539 if (pushback_index < MAXPUSHBACK-1)
540 return (pushback_buffer[pushback_index++] = c);
541 else
542 return (EOF);
545 int
546 findeol(void)
548 int c;
550 parsebuf = NULL;
552 /* Skip to either EOF or the first real EOL. */
553 while (1) {
554 if (pushback_index)
555 c = pushback_buffer[--pushback_index];
556 else
557 c = lgetc(0);
558 if (c == '\n') {
559 file->lineno++;
560 break;
562 if (c == EOF)
563 break;
565 return (ERROR);
568 int
569 yylex(void)
571 unsigned char buf[8096];
572 unsigned char *p, *val;
573 int quotec, next, c;
574 int token;
576 top:
577 p = buf;
578 c = lgetc(0);
579 while (c == ' ' || c == '\t')
580 c = lgetc(0); /* nothing */
582 yylval.lineno = file->lineno;
583 if (c == '#') {
584 c = lgetc(0);
585 while (c != '\n' && c != EOF)
586 c = lgetc(0); /* nothing */
588 if (c == '$' && parsebuf == NULL) {
589 while (1) {
590 c = lgetc(0);
591 if (c == EOF)
592 return (0);
594 if (p + 1 >= buf + sizeof(buf) - 1) {
595 yyerror("string too long");
596 return (findeol());
598 if (isalnum(c) || c == '_') {
599 *p++ = c;
600 continue;
602 *p = '\0';
603 lungetc(c);
604 break;
606 val = symget(buf);
607 if (val == NULL) {
608 yyerror("macro '%s' not defined", buf);
609 return (findeol());
611 parsebuf = val;
612 parseindex = 0;
613 goto top;
616 switch (c) {
617 case '\'':
618 case '"':
619 quotec = c;
620 while (1) {
621 c = lgetc(quotec);
622 if (c == EOF)
623 return (0);
624 if (c == '\n') {
625 file->lineno++;
626 continue;
627 } else if (c == '\\') {
628 next = lgetc(quotec);
629 if (next == EOF)
630 return (0);
631 if (next == quotec || c == ' ' || c == '\t')
632 c = next;
633 else if (next == '\n') {
634 file->lineno++;
635 continue;
636 } else
637 lungetc(next);
638 } else if (c == quotec) {
639 *p = '\0';
640 break;
641 } else if (c == '\0') {
642 yyerror("syntax error");
643 return (findeol());
645 if (p + 1 >= buf + sizeof(buf) - 1) {
646 yyerror("string too long");
647 return (findeol());
649 *p++ = c;
651 yylval.v.string = strdup(buf);
652 if (yylval.v.string == NULL)
653 err(1, "yylex: strdup");
654 return (STRING);
657 #define allowed_to_end_number(x) \
658 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
660 if (c == '-' || isdigit(c)) {
661 do {
662 *p++ = c;
663 if ((unsigned)(p-buf) >= sizeof(buf)) {
664 yyerror("string too long");
665 return (findeol());
667 c = lgetc(0);
668 } while (c != EOF && isdigit(c));
669 lungetc(c);
670 if (p == buf + 1 && buf[0] == '-')
671 goto nodigits;
672 if (c == EOF || allowed_to_end_number(c)) {
673 const char *errstr = NULL;
675 *p = '\0';
676 yylval.v.number = strtonum(buf, LLONG_MIN,
677 LLONG_MAX, &errstr);
678 if (errstr) {
679 yyerror("\"%s\" invalid number: %s",
680 buf, errstr);
681 return (findeol());
683 return (NUMBER);
684 } else {
685 nodigits:
686 while (p > buf + 1)
687 lungetc(*--p);
688 c = *--p;
689 if (c == '-')
690 return (c);
694 #define allowed_in_string(x) \
695 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
696 x != '{' && x != '}' && \
697 x != '!' && x != '=' && x != '#' && \
698 x != ','))
700 if (isalnum(c) || c == ':' || c == '_') {
701 do {
702 *p++ = c;
703 if ((unsigned)(p-buf) >= sizeof(buf)) {
704 yyerror("string too long");
705 return (findeol());
707 c = lgetc(0);
708 } while (c != EOF && (allowed_in_string(c)));
709 lungetc(c);
710 *p = '\0';
711 token = lookup(buf);
712 if (token == STRING) {
713 yylval.v.string = strdup(buf);
714 if (yylval.v.string == NULL)
715 err(1, "yylex: strdup");
717 return (token);
719 if (c == '\n') {
720 yylval.lineno = file->lineno;
721 file->lineno++;
723 if (c == EOF)
724 return (0);
725 return (c);
728 int
729 check_file_secrecy(int fd, const char *fname)
731 struct stat st;
733 if (fstat(fd, &st)) {
734 log_warn("cannot stat %s", fname);
735 return (-1);
737 if (st.st_uid != 0 && st.st_uid != getuid()) {
738 log_warnx("%s: owner not root or current user", fname);
739 return (-1);
741 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
742 log_warnx("%s: group writable or world read/writable", fname);
743 return (-1);
745 return (0);
748 struct file *
749 newfile(const char *name, int secret)
751 struct file *nfile;
753 nfile = calloc(1, sizeof(struct file));
754 if (nfile == NULL) {
755 log_warn("calloc");
756 return (NULL);
758 nfile->name = strdup(name);
759 if (nfile->name == NULL) {
760 log_warn("strdup");
761 free(nfile);
762 return (NULL);
764 nfile->stream = fopen(nfile->name, "r");
765 if (nfile->stream == NULL) {
766 /* no warning, we don't require a conf file */
767 free(nfile->name);
768 free(nfile);
769 return (NULL);
770 } else if (secret &&
771 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
772 fclose(nfile->stream);
773 free(nfile->name);
774 free(nfile);
775 return (NULL);
777 nfile->lineno = 1;
778 return (nfile);
781 static void
782 closefile(struct file *xfile)
784 fclose(xfile->stream);
785 free(xfile->name);
786 free(xfile);
789 static void
790 add_default_server(void)
792 new_srv = conf_new_server(D_SITENAME);
793 log_debug("%s: adding default server %s", __func__, D_SITENAME);
796 int
797 parse_config(const char *filename, struct gotwebd *env)
799 struct sym *sym, *next;
801 if (config_init(env) == -1)
802 fatalx("failed to initialize configuration");
804 gotwebd = env;
806 file = newfile(filename, 0);
807 if (file == NULL) {
808 add_default_server();
809 sockets_parse_sockets(env);
810 /* just return, as we don't require a conf file */
811 return (0);
814 yyparse();
815 errors = file->errors;
816 closefile(file);
818 /* Free macros and check which have not been used. */
819 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
820 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
821 fprintf(stderr, "warning: macro '%s' not used\n",
822 sym->nam);
823 if (!sym->persist) {
824 free(sym->nam);
825 free(sym->val);
826 TAILQ_REMOVE(&symhead, sym, entry);
827 free(sym);
831 if (errors)
832 return (-1);
834 /* just add default server if no config specified */
835 if (gotwebd->server_cnt == 0)
836 add_default_server();
838 /* setup our listening sockets */
839 sockets_parse_sockets(env);
841 return (0);
844 struct server *
845 conf_new_server(const char *name)
847 struct server *srv = NULL;
849 srv = calloc(1, sizeof(*srv));
850 if (srv == NULL)
851 fatalx("%s: calloc", __func__);
853 n = strlcpy(srv->name, name, sizeof(srv->name));
854 if (n >= sizeof(srv->name))
855 fatalx("%s: strlcpy", __func__);
856 n = snprintf(srv->unix_socket_name,
857 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
858 D_UNIX_SOCKET);
859 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
860 fatalx("%s: snprintf", __func__);
861 n = strlcpy(srv->repos_path, D_GOTPATH,
862 sizeof(srv->repos_path));
863 if (n >= sizeof(srv->repos_path))
864 fatalx("%s: strlcpy", __func__);
865 n = strlcpy(srv->site_name, D_SITENAME,
866 sizeof(srv->site_name));
867 if (n >= sizeof(srv->site_name))
868 fatalx("%s: strlcpy", __func__);
869 n = strlcpy(srv->site_owner, D_SITEOWNER,
870 sizeof(srv->site_owner));
871 if (n >= sizeof(srv->site_owner))
872 fatalx("%s: strlcpy", __func__);
873 n = strlcpy(srv->site_link, D_SITELINK,
874 sizeof(srv->site_link));
875 if (n >= sizeof(srv->site_link))
876 fatalx("%s: strlcpy", __func__);
877 n = strlcpy(srv->logo, D_GOTLOGO,
878 sizeof(srv->logo));
879 if (n >= sizeof(srv->logo))
880 fatalx("%s: strlcpy", __func__);
881 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
882 if (n >= sizeof(srv->logo_url))
883 fatalx("%s: strlcpy", __func__);
884 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
885 if (n >= sizeof(srv->custom_css))
886 fatalx("%s: strlcpy", __func__);
888 srv->show_site_owner = D_SHOWSOWNER;
889 srv->show_repo_owner = D_SHOWROWNER;
890 srv->show_repo_age = D_SHOWAGE;
891 srv->show_repo_description = D_SHOWDESC;
892 srv->show_repo_cloneurl = D_SHOWURL;
893 srv->respect_exportok = D_RESPECTEXPORTOK;
895 srv->max_repos_display = D_MAXREPODISP;
896 srv->max_commits_display = D_MAXCOMMITDISP;
897 srv->max_repos = D_MAXREPO;
899 srv->unix_socket = 1;
900 srv->fcgi_socket = 0;
902 TAILQ_INIT(&srv->al);
903 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
904 gotwebd->server_cnt++;
906 return srv;
907 };
909 int
910 symset(const char *nam, const char *val, int persist)
912 struct sym *sym;
914 TAILQ_FOREACH(sym, &symhead, entry) {
915 if (strcmp(nam, sym->nam) == 0)
916 break;
919 if (sym != NULL) {
920 if (sym->persist == 1)
921 return (0);
922 else {
923 free(sym->nam);
924 free(sym->val);
925 TAILQ_REMOVE(&symhead, sym, entry);
926 free(sym);
929 sym = calloc(1, sizeof(*sym));
930 if (sym == NULL)
931 return (-1);
933 sym->nam = strdup(nam);
934 if (sym->nam == NULL) {
935 free(sym);
936 return (-1);
938 sym->val = strdup(val);
939 if (sym->val == NULL) {
940 free(sym->nam);
941 free(sym);
942 return (-1);
944 sym->used = 0;
945 sym->persist = persist;
946 TAILQ_INSERT_TAIL(&symhead, sym, entry);
947 return (0);
950 int
951 cmdline_symset(char *s)
953 char *sym, *val;
954 int ret;
956 val = strrchr(s, '=');
957 if (val == NULL)
958 return (-1);
960 sym = strndup(s, val - s);
961 if (sym == NULL)
962 fatal("%s: strndup", __func__);
964 ret = symset(sym, val + 1, 1);
965 free(sym);
967 return (ret);
970 char *
971 symget(const char *nam)
973 struct sym *sym;
975 TAILQ_FOREACH(sym, &symhead, entry) {
976 if (strcmp(nam, sym->nam) == 0) {
977 sym->used = 1;
978 return (sym->val);
981 return (NULL);
984 int
985 getservice(const char *n)
987 struct servent *s;
988 const char *errstr;
989 long long llval;
991 llval = strtonum(n, 0, UINT16_MAX, &errstr);
992 if (errstr) {
993 s = getservbyname(n, "tcp");
994 if (s == NULL)
995 s = getservbyname(n, "udp");
996 if (s == NULL)
997 return (-1);
998 return ntohs(s->s_port);
1001 return (unsigned short)llval;
1004 struct address *
1005 host_v4(const char *s)
1007 struct in_addr ina;
1008 struct sockaddr_in *sain;
1009 struct address *h;
1011 memset(&ina, 0, sizeof(ina));
1012 if (inet_pton(AF_INET, s, &ina) != 1)
1013 return (NULL);
1015 if ((h = calloc(1, sizeof(*h))) == NULL)
1016 fatal(__func__);
1017 sain = (struct sockaddr_in *)&h->ss;
1018 got_sockaddr_inet_init(sain, &ina);
1019 if (sain->sin_addr.s_addr == INADDR_ANY)
1020 h->prefixlen = 0; /* 0.0.0.0 address */
1021 else
1022 h->prefixlen = -1; /* host address */
1023 return (h);
1026 struct address *
1027 host_v6(const char *s)
1029 struct addrinfo hints, *res;
1030 struct sockaddr_in6 *sa_in6, *ra;
1031 struct address *h = NULL;
1033 memset(&hints, 0, sizeof(hints));
1034 hints.ai_family = AF_INET6;
1035 hints.ai_socktype = SOCK_DGRAM; /* dummy */
1036 hints.ai_flags = AI_NUMERICHOST;
1037 if (getaddrinfo(s, "0", &hints, &res) == 0) {
1038 if ((h = calloc(1, sizeof(*h))) == NULL)
1039 fatal(__func__);
1040 sa_in6 = (struct sockaddr_in6 *)&h->ss;
1041 ra = (struct sockaddr_in6 *)res->ai_addr;
1042 got_sockaddr_inet6_init(sa_in6, &ra->sin6_addr,
1043 ra->sin6_scope_id);
1044 if (memcmp(&sa_in6->sin6_addr, &in6addr_any,
1045 sizeof(sa_in6->sin6_addr)) == 0)
1046 h->prefixlen = 0; /* any address */
1047 else
1048 h->prefixlen = -1; /* host address */
1049 freeaddrinfo(res);
1052 return (h);
1055 int
1056 host_dns(const char *s, struct server *new_srv, int max,
1057 in_port_t port, const char *ifname, int ipproto)
1059 struct addrinfo hints, *res0, *res;
1060 int error, cnt = 0;
1061 struct sockaddr_in *sain;
1062 struct sockaddr_in6 *sin6;
1063 struct address *h;
1065 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1066 return (cnt);
1068 memset(&hints, 0, sizeof(hints));
1069 hints.ai_family = PF_UNSPEC;
1070 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1071 hints.ai_flags = AI_ADDRCONFIG;
1072 error = getaddrinfo(s, NULL, &hints, &res0);
1073 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1074 return (0);
1075 if (error) {
1076 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1077 gai_strerror(error));
1078 return (-1);
1081 for (res = res0; res && cnt < max; res = res->ai_next) {
1082 if (res->ai_family != AF_INET &&
1083 res->ai_family != AF_INET6)
1084 continue;
1085 if ((h = calloc(1, sizeof(*h))) == NULL)
1086 fatal(__func__);
1088 if (port)
1089 h->port = port;
1090 if (ifname != NULL) {
1091 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1092 sizeof(h->ifname)) {
1093 log_warnx("%s: interface name truncated",
1094 __func__);
1095 freeaddrinfo(res0);
1096 free(h);
1097 return (-1);
1100 if (ipproto != -1)
1101 h->ipproto = ipproto;
1102 h->ss.ss_family = res->ai_family;
1103 h->prefixlen = -1; /* host address */
1105 if (res->ai_family == AF_INET) {
1106 struct sockaddr_in *ra;
1107 sain = (struct sockaddr_in *)&h->ss;
1108 ra = (struct sockaddr_in *)res->ai_addr;
1109 got_sockaddr_inet_init(sain, &ra->sin_addr);
1110 } else {
1111 struct sockaddr_in6 *ra;
1112 sin6 = (struct sockaddr_in6 *)&h->ss;
1113 ra = (struct sockaddr_in6 *)res->ai_addr;
1114 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1117 if (add_addr(new_srv, h))
1118 return -1;
1119 cnt++;
1121 if (cnt == max && res) {
1122 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1123 s, max);
1125 freeaddrinfo(res0);
1126 return (cnt);
1129 int
1130 host_if(const char *s, struct server *new_srv, int max,
1131 in_port_t port, const char *ifname, int ipproto)
1133 struct ifaddrs *ifap, *p;
1134 struct sockaddr_in *sain;
1135 struct sockaddr_in6 *sin6;
1136 struct address *h;
1137 int cnt = 0, af;
1139 if (getifaddrs(&ifap) == -1)
1140 fatal("getifaddrs");
1142 /* First search for IPv4 addresses */
1143 af = AF_INET;
1145 nextaf:
1146 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1147 if (p->ifa_addr == NULL ||
1148 p->ifa_addr->sa_family != af ||
1149 (strcmp(s, p->ifa_name) != 0 &&
1150 !is_if_in_group(p->ifa_name, s)))
1151 continue;
1152 if ((h = calloc(1, sizeof(*h))) == NULL)
1153 fatal("calloc");
1155 if (port)
1156 h->port = port;
1157 if (ifname != NULL) {
1158 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1159 sizeof(h->ifname)) {
1160 log_warnx("%s: interface name truncated",
1161 __func__);
1162 free(h);
1163 freeifaddrs(ifap);
1164 return (-1);
1167 if (ipproto != -1)
1168 h->ipproto = ipproto;
1169 h->ss.ss_family = af;
1170 h->prefixlen = -1; /* host address */
1172 if (af == AF_INET) {
1173 struct sockaddr_in *ra;
1174 sain = (struct sockaddr_in *)&h->ss;
1175 ra = (struct sockaddr_in *)p->ifa_addr;
1176 got_sockaddr_inet_init(sain, &ra->sin_addr);
1177 } else {
1178 struct sockaddr_in6 *ra;
1179 sin6 = (struct sockaddr_in6 *)&h->ss;
1180 ra = (struct sockaddr_in6 *)p->ifa_addr;
1181 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1182 ra->sin6_scope_id);
1185 if (add_addr(new_srv, h))
1186 return -1;
1187 cnt++;
1189 if (af == AF_INET) {
1190 /* Next search for IPv6 addresses */
1191 af = AF_INET6;
1192 goto nextaf;
1195 if (cnt > max) {
1196 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1197 s, max);
1199 freeifaddrs(ifap);
1200 return (cnt);
1203 int
1204 host(const char *s, struct server *new_srv, int max,
1205 in_port_t port, const char *ifname, int ipproto)
1207 struct address *h;
1209 h = host_v4(s);
1211 /* IPv6 address? */
1212 if (h == NULL)
1213 h = host_v6(s);
1215 if (h != NULL) {
1216 if (port)
1217 h->port = port;
1218 if (ifname != NULL) {
1219 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1220 sizeof(h->ifname)) {
1221 log_warnx("%s: interface name truncated",
1222 __func__);
1223 free(h);
1224 return (-1);
1227 if (ipproto != -1)
1228 h->ipproto = ipproto;
1230 if (add_addr(new_srv, h))
1231 return -1;
1232 return (1);
1235 return (host_dns(s, new_srv, max, port, ifname, ipproto));
1238 int
1239 is_if_in_group(const char *ifname, const char *groupname)
1241 unsigned int len;
1242 struct ifgroupreq ifgr;
1243 struct ifg_req *ifg;
1244 int s;
1245 int ret = 0;
1247 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1248 err(1, "socket");
1250 memset(&ifgr, 0, sizeof(ifgr));
1251 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1252 err(1, "IFNAMSIZ");
1253 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1254 if (errno == EINVAL || errno == ENOTTY)
1255 goto end;
1256 err(1, "SIOCGIFGROUP");
1259 len = ifgr.ifgr_len;
1260 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1261 sizeof(struct ifg_req));
1262 if (ifgr.ifgr_groups == NULL)
1263 err(1, "getifgroups");
1264 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1265 err(1, "SIOCGIFGROUP");
1267 ifg = ifgr.ifgr_groups;
1268 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1269 len -= sizeof(struct ifg_req);
1270 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1271 ret = 1;
1272 break;
1275 free(ifgr.ifgr_groups);
1277 end:
1278 close(s);
1279 return (ret);
1282 int
1283 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1285 if (strcmp("", addr) == 0) {
1286 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1287 -1) <= 0) {
1288 yyerror("invalid listen ip: %s",
1289 "127.0.0.1");
1290 return (-1);
1292 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1293 yyerror("invalid listen ip: %s", "::1");
1294 return (-1);
1296 } else {
1297 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1298 -1) <= 0) {
1299 yyerror("invalid listen ip: %s", addr);
1300 return (-1);
1303 return (0);
1306 int
1307 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1308 const char *other_srv)
1310 struct address *a;
1311 void *ia;
1312 char buf[INET6_ADDRSTRLEN];
1313 const char *addrstr;
1315 TAILQ_FOREACH(a, al, entry) {
1316 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1317 a->port != h->port)
1318 continue;
1320 switch (h->ss.ss_family) {
1321 case AF_INET:
1322 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1323 break;
1324 case AF_INET6:
1325 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1326 break;
1327 default:
1328 yyerror("unknown address family: %d", h->ss.ss_family);
1329 return -1;
1331 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1332 if (addrstr) {
1333 if (other_srv) {
1334 yyerror("server %s: duplicate fcgi listen "
1335 "address %s:%d, already used by server %s",
1336 new_srv, addrstr, h->port, other_srv);
1337 } else {
1338 log_warnx("server: %s: duplicate fcgi listen "
1339 "address %s:%d", new_srv, addrstr, h->port);
1341 } else {
1342 if (other_srv) {
1343 yyerror("server: %s: duplicate fcgi listen "
1344 "address, already used by server %s",
1345 new_srv, other_srv);
1346 } else {
1347 log_warnx("server %s: duplicate fcgi listen "
1348 "address", new_srv);
1352 return -1;
1355 return 0;
1358 int
1359 add_addr(struct server *new_srv, struct address *h)
1361 struct server *srv;
1363 /* Address cannot be shared between different servers. */
1364 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1365 if (srv == new_srv)
1366 continue;
1367 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1368 return -1;
1371 /* Tolerate duplicate address lines within the scope of a server. */
1372 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1373 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1374 else
1375 free(h);
1377 return 0;