Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include "got_compat.h"
26 #include <sys/ioctl.h>
27 #include <sys/types.h>
28 #include <sys/queue.h>
29 #include <sys/socket.h>
30 #include <sys/stat.h>
32 #include <net/if.h>
33 #include <netinet/in.h>
35 #include <arpa/inet.h>
37 #include <ctype.h>
38 #include <err.h>
39 #include <errno.h>
40 #include <event.h>
41 #include <ifaddrs.h>
42 #include <limits.h>
43 #include <netdb.h>
44 #include <stdarg.h>
45 #include <stdlib.h>
46 #include <stdio.h>
47 #include <string.h>
48 #include <syslog.h>
49 #include <unistd.h>
51 #include "got_sockaddr.h"
52 #include "got_reference.h"
54 #include "proc.h"
55 #include "gotwebd.h"
57 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
58 static struct file {
59 TAILQ_ENTRY(file) entry;
60 FILE *stream;
61 char *name;
62 int lineno;
63 int errors;
64 } *file;
65 struct file *newfile(const char *, int);
66 static void closefile(struct file *);
67 int check_file_secrecy(int, const char *);
68 int yyparse(void);
69 int yylex(void);
70 int yyerror(const char *, ...)
71 __attribute__((__format__ (printf, 1, 2)))
72 __attribute__((__nonnull__ (1)));
73 int kw_cmp(const void *, const void *);
74 int lookup(char *);
75 int lgetc(int);
76 int lungetc(int);
77 int findeol(void);
79 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
80 struct sym {
81 TAILQ_ENTRY(sym) entry;
82 int used;
83 int persist;
84 char *nam;
85 char *val;
86 };
88 int symset(const char *, const char *, int);
89 char *symget(const char *);
91 static int errors;
93 static struct gotwebd *gotwebd;
94 static struct server *new_srv;
95 static struct server *conf_new_server(const char *);
96 int getservice(const char *);
97 int n;
99 int get_addrs(const char *, struct server *, in_port_t);
100 int addr_dup_check(struct addresslist *, struct address *,
101 const char *, const char *);
102 int add_addr(struct server *, struct address *);
103 int host(const char *, struct server *,
104 int, in_port_t, const char *, int);
105 int host_if(const char *, struct server *,
106 int, in_port_t, const char *, int);
107 int is_if_in_group(const char *, const char *);
109 typedef struct {
110 union {
111 long long number;
112 char *string;
113 in_port_t port;
114 } v;
115 int lineno;
116 } YYSTYPE;
118 %}
120 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
121 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
122 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
123 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
124 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
126 %token <v.string> STRING
127 %type <v.port> fcgiport
128 %token <v.number> NUMBER
129 %type <v.number> boolean
131 %%
133 grammar : /* empty */
134 | grammar '\n'
135 | grammar varset '\n'
136 | grammar main '\n'
137 | grammar server '\n'
138 | grammar error '\n' { file->errors++; }
141 varset : STRING '=' STRING {
142 char *s = $1;
143 while (*s++) {
144 if (isspace((unsigned char)*s)) {
145 yyerror("macro name cannot contain "
146 "whitespace");
147 free($1);
148 free($3);
149 YYERROR;
152 if (symset($1, $3, 0) == -1)
153 fatal("cannot store variable");
154 free($1);
155 free($3);
159 boolean : STRING {
160 if (strcasecmp($1, "1") == 0 ||
161 strcasecmp($1, "yes") == 0 ||
162 strcasecmp($1, "on") == 0)
163 $$ = 1;
164 else if (strcasecmp($1, "0") == 0 ||
165 strcasecmp($1, "off") == 0 ||
166 strcasecmp($1, "no") == 0)
167 $$ = 0;
168 else {
169 yyerror("invalid boolean value '%s'", $1);
170 free($1);
171 YYERROR;
173 free($1);
175 | ON { $$ = 1; }
176 | NUMBER { $$ = $1; }
179 fcgiport : PORT NUMBER {
180 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
181 yyerror("invalid port: %lld", $2);
182 YYERROR;
184 $$ = $2;
186 | PORT STRING {
187 int val;
189 if ((val = getservice($2)) == -1) {
190 yyerror("invalid port: %s", $2);
191 free($2);
192 YYERROR;
194 free($2);
196 $$ = val;
200 main : PREFORK NUMBER {
201 gotwebd->prefork_gotwebd = $2;
203 | CHROOT STRING {
204 n = strlcpy(gotwebd->httpd_chroot, $2,
205 sizeof(gotwebd->httpd_chroot));
206 if (n >= sizeof(gotwebd->httpd_chroot)) {
207 yyerror("%s: httpd_chroot truncated", __func__);
208 free($2);
209 YYERROR;
211 free($2);
213 | UNIX_SOCKET boolean {
214 gotwebd->unix_socket = $2;
216 | UNIX_SOCKET_NAME STRING {
217 n = snprintf(gotwebd->unix_socket_name,
218 sizeof(gotwebd->unix_socket_name), "%s%s",
219 strlen(gotwebd->httpd_chroot) ?
220 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
221 if (n < 0 ||
222 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
223 yyerror("%s: unix_socket_name truncated",
224 __func__);
225 free($2);
226 YYERROR;
228 free($2);
232 server : SERVER STRING {
233 struct server *srv;
235 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
236 if (strcmp(srv->name, $2) == 0) {
237 yyerror("server name exists '%s'", $2);
238 free($2);
239 YYERROR;
243 new_srv = conf_new_server($2);
244 log_debug("adding server %s", $2);
245 free($2);
247 | SERVER STRING {
248 struct server *srv;
250 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
251 if (strcmp(srv->name, $2) == 0) {
252 yyerror("server name exists '%s'", $2);
253 free($2);
254 YYERROR;
258 new_srv = conf_new_server($2);
259 log_debug("adding server %s", $2);
260 free($2);
261 } '{' optnl serveropts2 '}' {
265 serveropts1 : REPOS_PATH STRING {
266 n = strlcpy(new_srv->repos_path, $2,
267 sizeof(new_srv->repos_path));
268 if (n >= sizeof(new_srv->repos_path)) {
269 yyerror("%s: repos_path truncated", __func__);
270 free($2);
271 YYERROR;
273 free($2);
275 | SITE_NAME STRING {
276 n = strlcpy(new_srv->site_name, $2,
277 sizeof(new_srv->site_name));
278 if (n >= sizeof(new_srv->site_name)) {
279 yyerror("%s: site_name truncated", __func__);
280 free($2);
281 YYERROR;
283 free($2);
285 | SITE_OWNER STRING {
286 n = strlcpy(new_srv->site_owner, $2,
287 sizeof(new_srv->site_owner));
288 if (n >= sizeof(new_srv->site_owner)) {
289 yyerror("%s: site_owner truncated", __func__);
290 free($2);
291 YYERROR;
293 free($2);
295 | SITE_LINK STRING {
296 n = strlcpy(new_srv->site_link, $2,
297 sizeof(new_srv->site_link));
298 if (n >= sizeof(new_srv->site_link)) {
299 yyerror("%s: site_link truncated", __func__);
300 free($2);
301 YYERROR;
303 free($2);
305 | LOGO STRING {
306 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
307 if (n >= sizeof(new_srv->logo)) {
308 yyerror("%s: logo truncated", __func__);
309 free($2);
310 YYERROR;
312 free($2);
314 | LOGO_URL STRING {
315 n = strlcpy(new_srv->logo_url, $2,
316 sizeof(new_srv->logo_url));
317 if (n >= sizeof(new_srv->logo_url)) {
318 yyerror("%s: logo_url truncated", __func__);
319 free($2);
320 YYERROR;
322 free($2);
324 | CUSTOM_CSS STRING {
325 n = strlcpy(new_srv->custom_css, $2,
326 sizeof(new_srv->custom_css));
327 if (n >= sizeof(new_srv->custom_css)) {
328 yyerror("%s: custom_css truncated", __func__);
329 free($2);
330 YYERROR;
332 free($2);
334 | LISTEN ON STRING fcgiport {
335 if (get_addrs($3, new_srv, $4) == -1) {
336 yyerror("could not get addrs");
337 YYERROR;
339 new_srv->fcgi_socket = 1;
341 | LISTEN ON SOCKET STRING {
342 if (!strcasecmp($4, "off") ||
343 !strcasecmp($4, "no")) {
344 new_srv->unix_socket = 0;
345 free($4);
346 YYACCEPT;
349 new_srv->unix_socket = 1;
351 n = snprintf(new_srv->unix_socket_name,
352 sizeof(new_srv->unix_socket_name), "%s%s",
353 strlen(gotwebd->httpd_chroot) ?
354 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $4);
355 if (n < 0 ||
356 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
357 yyerror("%s: unix_socket_name truncated",
358 __func__);
359 free($4);
360 YYERROR;
362 free($4);
364 | MAX_REPOS NUMBER {
365 if ($2 > 0)
366 new_srv->max_repos = $2;
368 | SHOW_SITE_OWNER boolean {
369 new_srv->show_site_owner = $2;
371 | SHOW_REPO_OWNER boolean {
372 new_srv->show_repo_owner = $2;
374 | SHOW_REPO_AGE boolean {
375 new_srv->show_repo_age = $2;
377 | SHOW_REPO_DESCRIPTION boolean {
378 new_srv->show_repo_description = $2;
380 | SHOW_REPO_CLONEURL boolean {
381 new_srv->show_repo_cloneurl = $2;
383 | RESPECT_EXPORTOK boolean {
384 new_srv->respect_exportok = $2;
386 | MAX_REPOS_DISPLAY NUMBER {
387 new_srv->max_repos_display = $2;
389 | MAX_COMMITS_DISPLAY NUMBER {
390 if ($2 > 0)
391 new_srv->max_commits_display = $2;
395 serveropts2 : serveropts2 serveropts1 nl
396 | serveropts1 optnl
399 nl : '\n' optnl
402 optnl : '\n' optnl /* zero or more newlines */
403 | /* empty */
406 %%
408 struct keywords {
409 const char *k_name;
410 int k_val;
411 };
413 int
414 yyerror(const char *fmt, ...)
416 va_list ap;
417 char *msg;
419 file->errors++;
420 va_start(ap, fmt);
421 if (vasprintf(&msg, fmt, ap) == -1)
422 fatalx("yyerror vasprintf");
423 va_end(ap);
424 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
425 free(msg);
426 return (0);
429 int
430 kw_cmp(const void *k, const void *e)
432 return (strcmp(k, ((const struct keywords *)e)->k_name));
435 int
436 lookup(char *s)
438 /* This has to be sorted always. */
439 static const struct keywords keywords[] = {
440 { "chroot", CHROOT },
441 { "custom_css", CUSTOM_CSS },
442 { "listen", LISTEN },
443 { "logo", LOGO },
444 { "logo_url", LOGO_URL },
445 { "max_commits_display", MAX_COMMITS_DISPLAY },
446 { "max_repos", MAX_REPOS },
447 { "max_repos_display", MAX_REPOS_DISPLAY },
448 { "on", ON },
449 { "port", PORT },
450 { "prefork", PREFORK },
451 { "repos_path", REPOS_PATH },
452 { "respect_exportok", RESPECT_EXPORTOK },
453 { "server", SERVER },
454 { "show_repo_age", SHOW_REPO_AGE },
455 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
456 { "show_repo_description", SHOW_REPO_DESCRIPTION },
457 { "show_repo_owner", SHOW_REPO_OWNER },
458 { "show_site_owner", SHOW_SITE_OWNER },
459 { "site_link", SITE_LINK },
460 { "site_name", SITE_NAME },
461 { "site_owner", SITE_OWNER },
462 { "socket", SOCKET },
463 { "unix_socket", UNIX_SOCKET },
464 { "unix_socket_name", UNIX_SOCKET_NAME },
465 };
466 const struct keywords *p;
468 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
469 sizeof(keywords[0]), kw_cmp);
471 if (p)
472 return (p->k_val);
473 else
474 return (STRING);
477 #define MAXPUSHBACK 128
479 unsigned char *parsebuf;
480 int parseindex;
481 unsigned char pushback_buffer[MAXPUSHBACK];
482 int pushback_index = 0;
484 int
485 lgetc(int quotec)
487 int c, next;
489 if (parsebuf) {
490 /* Read character from the parsebuffer instead of input. */
491 if (parseindex >= 0) {
492 c = parsebuf[parseindex++];
493 if (c != '\0')
494 return (c);
495 parsebuf = NULL;
496 } else
497 parseindex++;
500 if (pushback_index)
501 return (pushback_buffer[--pushback_index]);
503 if (quotec) {
504 c = getc(file->stream);
505 if (c == EOF)
506 yyerror("reached end of file while parsing "
507 "quoted string");
508 return (c);
511 c = getc(file->stream);
512 while (c == '\\') {
513 next = getc(file->stream);
514 if (next != '\n') {
515 c = next;
516 break;
518 yylval.lineno = file->lineno;
519 file->lineno++;
520 c = getc(file->stream);
523 return (c);
526 int
527 lungetc(int c)
529 if (c == EOF)
530 return (EOF);
531 if (parsebuf) {
532 parseindex--;
533 if (parseindex >= 0)
534 return (c);
536 if (pushback_index < MAXPUSHBACK-1)
537 return (pushback_buffer[pushback_index++] = c);
538 else
539 return (EOF);
542 int
543 findeol(void)
545 int c;
547 parsebuf = NULL;
549 /* Skip to either EOF or the first real EOL. */
550 while (1) {
551 if (pushback_index)
552 c = pushback_buffer[--pushback_index];
553 else
554 c = lgetc(0);
555 if (c == '\n') {
556 file->lineno++;
557 break;
559 if (c == EOF)
560 break;
562 return (ERROR);
565 int
566 yylex(void)
568 unsigned char buf[8096];
569 unsigned char *p, *val;
570 int quotec, next, c;
571 int token;
573 top:
574 p = buf;
575 c = lgetc(0);
576 while (c == ' ' || c == '\t')
577 c = lgetc(0); /* nothing */
579 yylval.lineno = file->lineno;
580 if (c == '#') {
581 c = lgetc(0);
582 while (c != '\n' && c != EOF)
583 c = lgetc(0); /* nothing */
585 if (c == '$' && parsebuf == NULL) {
586 while (1) {
587 c = lgetc(0);
588 if (c == EOF)
589 return (0);
591 if (p + 1 >= buf + sizeof(buf) - 1) {
592 yyerror("string too long");
593 return (findeol());
595 if (isalnum(c) || c == '_') {
596 *p++ = c;
597 continue;
599 *p = '\0';
600 lungetc(c);
601 break;
603 val = symget(buf);
604 if (val == NULL) {
605 yyerror("macro '%s' not defined", buf);
606 return (findeol());
608 parsebuf = val;
609 parseindex = 0;
610 goto top;
613 switch (c) {
614 case '\'':
615 case '"':
616 quotec = c;
617 while (1) {
618 c = lgetc(quotec);
619 if (c == EOF)
620 return (0);
621 if (c == '\n') {
622 file->lineno++;
623 continue;
624 } else if (c == '\\') {
625 next = lgetc(quotec);
626 if (next == EOF)
627 return (0);
628 if (next == quotec || c == ' ' || c == '\t')
629 c = next;
630 else if (next == '\n') {
631 file->lineno++;
632 continue;
633 } else
634 lungetc(next);
635 } else if (c == quotec) {
636 *p = '\0';
637 break;
638 } else if (c == '\0') {
639 yyerror("syntax error");
640 return (findeol());
642 if (p + 1 >= buf + sizeof(buf) - 1) {
643 yyerror("string too long");
644 return (findeol());
646 *p++ = c;
648 yylval.v.string = strdup(buf);
649 if (yylval.v.string == NULL)
650 err(1, "yylex: strdup");
651 return (STRING);
654 #define allowed_to_end_number(x) \
655 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
657 if (c == '-' || isdigit(c)) {
658 do {
659 *p++ = c;
660 if ((unsigned)(p-buf) >= sizeof(buf)) {
661 yyerror("string too long");
662 return (findeol());
664 c = lgetc(0);
665 } while (c != EOF && isdigit(c));
666 lungetc(c);
667 if (p == buf + 1 && buf[0] == '-')
668 goto nodigits;
669 if (c == EOF || allowed_to_end_number(c)) {
670 const char *errstr = NULL;
672 *p = '\0';
673 yylval.v.number = strtonum(buf, LLONG_MIN,
674 LLONG_MAX, &errstr);
675 if (errstr) {
676 yyerror("\"%s\" invalid number: %s",
677 buf, errstr);
678 return (findeol());
680 return (NUMBER);
681 } else {
682 nodigits:
683 while (p > buf + 1)
684 lungetc(*--p);
685 c = *--p;
686 if (c == '-')
687 return (c);
691 #define allowed_in_string(x) \
692 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
693 x != '{' && x != '}' && \
694 x != '!' && x != '=' && x != '#' && \
695 x != ','))
697 if (isalnum(c) || c == ':' || c == '_') {
698 do {
699 *p++ = c;
700 if ((unsigned)(p-buf) >= sizeof(buf)) {
701 yyerror("string too long");
702 return (findeol());
704 c = lgetc(0);
705 } while (c != EOF && (allowed_in_string(c)));
706 lungetc(c);
707 *p = '\0';
708 token = lookup(buf);
709 if (token == STRING) {
710 yylval.v.string = strdup(buf);
711 if (yylval.v.string == NULL)
712 err(1, "yylex: strdup");
714 return (token);
716 if (c == '\n') {
717 yylval.lineno = file->lineno;
718 file->lineno++;
720 if (c == EOF)
721 return (0);
722 return (c);
725 int
726 check_file_secrecy(int fd, const char *fname)
728 struct stat st;
730 if (fstat(fd, &st)) {
731 log_warn("cannot stat %s", fname);
732 return (-1);
734 if (st.st_uid != 0 && st.st_uid != getuid()) {
735 log_warnx("%s: owner not root or current user", fname);
736 return (-1);
738 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
739 log_warnx("%s: group writable or world read/writable", fname);
740 return (-1);
742 return (0);
745 struct file *
746 newfile(const char *name, int secret)
748 struct file *nfile;
750 nfile = calloc(1, sizeof(struct file));
751 if (nfile == NULL) {
752 log_warn("calloc");
753 return (NULL);
755 nfile->name = strdup(name);
756 if (nfile->name == NULL) {
757 log_warn("strdup");
758 free(nfile);
759 return (NULL);
761 nfile->stream = fopen(nfile->name, "r");
762 if (nfile->stream == NULL) {
763 /* no warning, we don't require a conf file */
764 free(nfile->name);
765 free(nfile);
766 return (NULL);
767 } else if (secret &&
768 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
769 fclose(nfile->stream);
770 free(nfile->name);
771 free(nfile);
772 return (NULL);
774 nfile->lineno = 1;
775 return (nfile);
778 static void
779 closefile(struct file *xfile)
781 fclose(xfile->stream);
782 free(xfile->name);
783 free(xfile);
786 static void
787 add_default_server(void)
789 new_srv = conf_new_server(D_SITENAME);
790 log_debug("%s: adding default server %s", __func__, D_SITENAME);
793 int
794 parse_config(const char *filename, struct gotwebd *env)
796 struct sym *sym, *next;
798 if (config_init(env) == -1)
799 fatalx("failed to initialize configuration");
801 gotwebd = env;
803 file = newfile(filename, 0);
804 if (file == NULL) {
805 add_default_server();
806 sockets_parse_sockets(env);
807 /* just return, as we don't require a conf file */
808 return (0);
811 yyparse();
812 errors = file->errors;
813 closefile(file);
815 /* Free macros and check which have not been used. */
816 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
817 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
818 fprintf(stderr, "warning: macro '%s' not used\n",
819 sym->nam);
820 if (!sym->persist) {
821 free(sym->nam);
822 free(sym->val);
823 TAILQ_REMOVE(&symhead, sym, entry);
824 free(sym);
828 if (errors)
829 return (-1);
831 /* just add default server if no config specified */
832 if (gotwebd->server_cnt == 0)
833 add_default_server();
835 /* setup our listening sockets */
836 sockets_parse_sockets(env);
838 return (0);
841 struct server *
842 conf_new_server(const char *name)
844 struct server *srv = NULL;
846 srv = calloc(1, sizeof(*srv));
847 if (srv == NULL)
848 fatalx("%s: calloc", __func__);
850 n = strlcpy(srv->name, name, sizeof(srv->name));
851 if (n >= sizeof(srv->name))
852 fatalx("%s: strlcpy", __func__);
853 n = snprintf(srv->unix_socket_name,
854 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
855 D_UNIX_SOCKET);
856 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
857 fatalx("%s: snprintf", __func__);
858 n = strlcpy(srv->repos_path, D_GOTPATH,
859 sizeof(srv->repos_path));
860 if (n >= sizeof(srv->repos_path))
861 fatalx("%s: strlcpy", __func__);
862 n = strlcpy(srv->site_name, D_SITENAME,
863 sizeof(srv->site_name));
864 if (n >= sizeof(srv->site_name))
865 fatalx("%s: strlcpy", __func__);
866 n = strlcpy(srv->site_owner, D_SITEOWNER,
867 sizeof(srv->site_owner));
868 if (n >= sizeof(srv->site_owner))
869 fatalx("%s: strlcpy", __func__);
870 n = strlcpy(srv->site_link, D_SITELINK,
871 sizeof(srv->site_link));
872 if (n >= sizeof(srv->site_link))
873 fatalx("%s: strlcpy", __func__);
874 n = strlcpy(srv->logo, D_GOTLOGO,
875 sizeof(srv->logo));
876 if (n >= sizeof(srv->logo))
877 fatalx("%s: strlcpy", __func__);
878 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
879 if (n >= sizeof(srv->logo_url))
880 fatalx("%s: strlcpy", __func__);
881 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
882 if (n >= sizeof(srv->custom_css))
883 fatalx("%s: strlcpy", __func__);
885 srv->show_site_owner = D_SHOWSOWNER;
886 srv->show_repo_owner = D_SHOWROWNER;
887 srv->show_repo_age = D_SHOWAGE;
888 srv->show_repo_description = D_SHOWDESC;
889 srv->show_repo_cloneurl = D_SHOWURL;
890 srv->respect_exportok = D_RESPECTEXPORTOK;
892 srv->max_repos_display = D_MAXREPODISP;
893 srv->max_commits_display = D_MAXCOMMITDISP;
894 srv->max_repos = D_MAXREPO;
896 srv->unix_socket = 1;
897 srv->fcgi_socket = 0;
899 TAILQ_INIT(&srv->al);
900 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
901 gotwebd->server_cnt++;
903 return srv;
904 };
906 int
907 symset(const char *nam, const char *val, int persist)
909 struct sym *sym;
911 TAILQ_FOREACH(sym, &symhead, entry) {
912 if (strcmp(nam, sym->nam) == 0)
913 break;
916 if (sym != NULL) {
917 if (sym->persist == 1)
918 return (0);
919 else {
920 free(sym->nam);
921 free(sym->val);
922 TAILQ_REMOVE(&symhead, sym, entry);
923 free(sym);
926 sym = calloc(1, sizeof(*sym));
927 if (sym == NULL)
928 return (-1);
930 sym->nam = strdup(nam);
931 if (sym->nam == NULL) {
932 free(sym);
933 return (-1);
935 sym->val = strdup(val);
936 if (sym->val == NULL) {
937 free(sym->nam);
938 free(sym);
939 return (-1);
941 sym->used = 0;
942 sym->persist = persist;
943 TAILQ_INSERT_TAIL(&symhead, sym, entry);
944 return (0);
947 int
948 cmdline_symset(char *s)
950 char *sym, *val;
951 int ret;
953 val = strrchr(s, '=');
954 if (val == NULL)
955 return (-1);
957 sym = strndup(s, val - s);
958 if (sym == NULL)
959 fatal("%s: strndup", __func__);
961 ret = symset(sym, val + 1, 1);
962 free(sym);
964 return (ret);
967 char *
968 symget(const char *nam)
970 struct sym *sym;
972 TAILQ_FOREACH(sym, &symhead, entry) {
973 if (strcmp(nam, sym->nam) == 0) {
974 sym->used = 1;
975 return (sym->val);
978 return (NULL);
981 int
982 getservice(const char *n)
984 struct servent *s;
985 const char *errstr;
986 long long llval;
988 llval = strtonum(n, 0, UINT16_MAX, &errstr);
989 if (errstr) {
990 s = getservbyname(n, "tcp");
991 if (s == NULL)
992 s = getservbyname(n, "udp");
993 if (s == NULL)
994 return (-1);
995 return ntohs(s->s_port);
998 return (unsigned short)llval;
1001 int
1002 host(const char *s, struct server *new_srv, int max,
1003 in_port_t port, const char *ifname, int ipproto)
1005 struct addrinfo hints, *res0, *res;
1006 int error, cnt = 0;
1007 struct sockaddr_in *sain;
1008 struct sockaddr_in6 *sin6;
1009 struct address *h;
1011 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1012 return (cnt);
1014 memset(&hints, 0, sizeof(hints));
1015 hints.ai_family = AF_UNSPEC;
1016 hints.ai_socktype = SOCK_STREAM; /* DUMMY */
1017 hints.ai_flags = AI_ADDRCONFIG;
1018 error = getaddrinfo(s, NULL, &hints, &res0);
1019 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1020 return (0);
1021 if (error) {
1022 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1023 gai_strerror(error));
1024 return (-1);
1027 for (res = res0; res && cnt < max; res = res->ai_next) {
1028 if (res->ai_family != AF_INET &&
1029 res->ai_family != AF_INET6)
1030 continue;
1031 if ((h = calloc(1, sizeof(*h))) == NULL)
1032 fatal(__func__);
1034 if (port)
1035 h->port = port;
1036 if (ifname != NULL) {
1037 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1038 sizeof(h->ifname)) {
1039 log_warnx("%s: interface name truncated",
1040 __func__);
1041 freeaddrinfo(res0);
1042 free(h);
1043 return (-1);
1046 if (ipproto != -1)
1047 h->ipproto = ipproto;
1048 h->ss.ss_family = res->ai_family;
1050 if (res->ai_family == AF_INET) {
1051 struct sockaddr_in *ra;
1052 sain = (struct sockaddr_in *)&h->ss;
1053 ra = (struct sockaddr_in *)res->ai_addr;
1054 got_sockaddr_inet_init(sain, &ra->sin_addr);
1055 } else {
1056 struct sockaddr_in6 *ra;
1057 sin6 = (struct sockaddr_in6 *)&h->ss;
1058 ra = (struct sockaddr_in6 *)res->ai_addr;
1059 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1062 if (add_addr(new_srv, h))
1063 return -1;
1064 cnt++;
1066 if (cnt == max && res) {
1067 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1068 s, max);
1070 freeaddrinfo(res0);
1071 return (cnt);
1074 int
1075 host_if(const char *s, struct server *new_srv, int max,
1076 in_port_t port, const char *ifname, int ipproto)
1078 struct ifaddrs *ifap, *p;
1079 struct sockaddr_in *sain;
1080 struct sockaddr_in6 *sin6;
1081 struct address *h;
1082 int cnt = 0, af;
1084 if (getifaddrs(&ifap) == -1)
1085 fatal("getifaddrs");
1087 /* First search for IPv4 addresses */
1088 af = AF_INET;
1090 nextaf:
1091 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1092 if (p->ifa_addr == NULL ||
1093 p->ifa_addr->sa_family != af ||
1094 (strcmp(s, p->ifa_name) != 0 &&
1095 !is_if_in_group(p->ifa_name, s)))
1096 continue;
1097 if ((h = calloc(1, sizeof(*h))) == NULL)
1098 fatal("calloc");
1100 if (port)
1101 h->port = port;
1102 if (ifname != NULL) {
1103 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1104 sizeof(h->ifname)) {
1105 log_warnx("%s: interface name truncated",
1106 __func__);
1107 free(h);
1108 freeifaddrs(ifap);
1109 return (-1);
1112 if (ipproto != -1)
1113 h->ipproto = ipproto;
1114 h->ss.ss_family = af;
1116 if (af == AF_INET) {
1117 struct sockaddr_in *ra;
1118 sain = (struct sockaddr_in *)&h->ss;
1119 ra = (struct sockaddr_in *)p->ifa_addr;
1120 got_sockaddr_inet_init(sain, &ra->sin_addr);
1121 } else {
1122 struct sockaddr_in6 *ra;
1123 sin6 = (struct sockaddr_in6 *)&h->ss;
1124 ra = (struct sockaddr_in6 *)p->ifa_addr;
1125 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1126 ra->sin6_scope_id);
1129 if (add_addr(new_srv, h))
1130 return -1;
1131 cnt++;
1133 if (af == AF_INET) {
1134 /* Next search for IPv6 addresses */
1135 af = AF_INET6;
1136 goto nextaf;
1139 if (cnt > max) {
1140 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1141 s, max);
1143 freeifaddrs(ifap);
1144 return (cnt);
1147 int
1148 is_if_in_group(const char *ifname, const char *groupname)
1150 /* TA: Check this... */
1151 #ifdef HAVE_STRUCT_IFGROUPREQ
1152 unsigned int len;
1153 struct ifgroupreq ifgr;
1154 struct ifg_req *ifg;
1155 int s;
1156 int ret = 0;
1158 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1159 err(1, "socket");
1161 memset(&ifgr, 0, sizeof(ifgr));
1162 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1163 err(1, "IFNAMSIZ");
1164 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1165 if (errno == EINVAL || errno == ENOTTY)
1166 goto end;
1167 err(1, "SIOCGIFGROUP");
1170 len = ifgr.ifgr_len;
1171 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1172 sizeof(struct ifg_req));
1173 if (ifgr.ifgr_groups == NULL)
1174 err(1, "getifgroups");
1175 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1176 err(1, "SIOCGIFGROUP");
1178 ifg = ifgr.ifgr_groups;
1179 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1180 len -= sizeof(struct ifg_req);
1181 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1182 ret = 1;
1183 break;
1186 free(ifgr.ifgr_groups);
1188 end:
1189 close(s);
1190 return (ret);
1191 #else
1192 return (0);
1193 #endif
1196 int
1197 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1199 if (strcmp("", addr) == 0) {
1200 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1201 -1) <= 0) {
1202 yyerror("invalid listen ip: %s",
1203 "127.0.0.1");
1204 return (-1);
1206 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1207 yyerror("invalid listen ip: %s", "::1");
1208 return (-1);
1210 } else {
1211 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1212 -1) <= 0) {
1213 yyerror("invalid listen ip: %s", addr);
1214 return (-1);
1217 return (0);
1220 int
1221 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1222 const char *other_srv)
1224 struct address *a;
1225 void *ia;
1226 char buf[INET6_ADDRSTRLEN];
1227 const char *addrstr;
1229 TAILQ_FOREACH(a, al, entry) {
1230 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1231 a->port != h->port)
1232 continue;
1234 switch (h->ss.ss_family) {
1235 case AF_INET:
1236 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1237 break;
1238 case AF_INET6:
1239 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1240 break;
1241 default:
1242 yyerror("unknown address family: %d", h->ss.ss_family);
1243 return -1;
1245 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1246 if (addrstr) {
1247 if (other_srv) {
1248 yyerror("server %s: duplicate fcgi listen "
1249 "address %s:%d, already used by server %s",
1250 new_srv, addrstr, h->port, other_srv);
1251 } else {
1252 log_warnx("server: %s: duplicate fcgi listen "
1253 "address %s:%d", new_srv, addrstr, h->port);
1255 } else {
1256 if (other_srv) {
1257 yyerror("server: %s: duplicate fcgi listen "
1258 "address, already used by server %s",
1259 new_srv, other_srv);
1260 } else {
1261 log_warnx("server %s: duplicate fcgi listen "
1262 "address", new_srv);
1266 return -1;
1269 return 0;
1272 int
1273 add_addr(struct server *new_srv, struct address *h)
1275 struct server *srv;
1277 /* Address cannot be shared between different servers. */
1278 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1279 if (srv == new_srv)
1280 continue;
1281 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1282 return -1;
1285 /* Tolerate duplicate address lines within the scope of a server. */
1286 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1287 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1288 else
1289 free(h);
1291 return 0;