Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
28 #include <sys/stat.h>
30 #include <net/if.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
35 #include <ctype.h>
36 #include <err.h>
37 #include <errno.h>
38 #include <event.h>
39 #include <ifaddrs.h>
40 #include <limits.h>
41 #include <netdb.h>
42 #include <stdarg.h>
43 #include <stdlib.h>
44 #include <stdio.h>
45 #include <string.h>
46 #include <syslog.h>
47 #include <unistd.h>
49 #include "proc.h"
50 #include "gotwebd.h"
51 #include "got_sockaddr.h"
53 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
54 static struct file {
55 TAILQ_ENTRY(file) entry;
56 FILE *stream;
57 char *name;
58 int lineno;
59 int errors;
60 } *file;
61 struct file *newfile(const char *, int);
62 static void closefile(struct file *);
63 int check_file_secrecy(int, const char *);
64 int yyparse(void);
65 int yylex(void);
66 int yyerror(const char *, ...)
67 __attribute__((__format__ (printf, 1, 2)))
68 __attribute__((__nonnull__ (1)));
69 int kw_cmp(const void *, const void *);
70 int lookup(char *);
71 int lgetc(int);
72 int lungetc(int);
73 int findeol(void);
75 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
76 struct sym {
77 TAILQ_ENTRY(sym) entry;
78 int used;
79 int persist;
80 char *nam;
81 char *val;
82 };
84 int symset(const char *, const char *, int);
85 char *symget(const char *);
87 static int errors;
89 static struct gotwebd *gotwebd;
90 static struct server *new_srv;
91 static struct server *conf_new_server(const char *);
92 int getservice(const char *);
93 int n;
95 int get_addrs(const char *, struct addresslist *, in_port_t);
96 struct address *host_v4(const char *);
97 struct address *host_v6(const char *);
98 int host_dns(const char *, struct addresslist *,
99 int, in_port_t, const char *, int);
100 int host_if(const char *, struct addresslist *,
101 int, in_port_t, const char *, int);
102 int host(const char *, struct addresslist *,
103 int, in_port_t, const char *, int);
104 int is_if_in_group(const char *, const char *);
106 typedef struct {
107 union {
108 long long number;
109 char *string;
110 in_port_t port;
111 } v;
112 int lineno;
113 } YYSTYPE;
115 %}
117 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
118 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
119 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
120 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK FCGI_SOCKET
121 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS
123 %token <v.string> STRING
124 %type <v.port> fcgiport
125 %token <v.number> NUMBER
126 %type <v.number> boolean
128 %%
130 grammar :
131 | grammar '\n'
132 | grammar main '\n'
133 | grammar server '\n'
136 boolean : STRING {
137 if (strcasecmp($1, "1") == 0 ||
138 strcasecmp($1, "yes") == 0 ||
139 strcasecmp($1, "on") == 0)
140 $$ = 1;
141 else if (strcasecmp($1, "0") == 0 ||
142 strcasecmp($1, "off") == 0 ||
143 strcasecmp($1, "no") == 0)
144 $$ = 0;
145 else {
146 yyerror("invalid boolean value '%s'", $1);
147 free($1);
148 YYERROR;
150 free($1);
152 | ON { $$ = 1; }
153 | NUMBER { $$ = $1; }
156 fcgiport : NUMBER {
157 if ($1 <= 0 || $1 > (int)USHRT_MAX) {
158 yyerror("invalid port: %lld", $1);
159 YYERROR;
161 $$ = htons($1);
163 | STRING {
164 int val;
166 if ((val = getservice($1)) == -1) {
167 yyerror("invalid port: %s", $1);
168 free($1);
169 YYERROR;
171 free($1);
173 $$ = val;
177 main : PREFORK NUMBER {
178 gotwebd->prefork_gotwebd = $2;
180 | CHROOT STRING {
181 n = strlcpy(gotwebd->httpd_chroot, $2,
182 sizeof(gotwebd->httpd_chroot));
183 if (n >= sizeof(gotwebd->httpd_chroot)) {
184 yyerror("%s: httpd_chroot truncated", __func__);
185 free($2);
186 YYERROR;
188 free($2);
190 | FCGI_SOCKET boolean {
191 gotwebd->fcgi_socket = $2;
193 | FCGI_SOCKET boolean {
194 gotwebd->fcgi_socket = $2;
195 } '{' optnl socketopts4 '}'
196 | UNIX_SOCKET boolean {
197 gotwebd->unix_socket = $2;
199 | UNIX_SOCKET_NAME STRING {
200 n = snprintf(gotwebd->unix_socket_name,
201 sizeof(gotwebd->unix_socket_name), "%s%s",
202 strlen(gotwebd->httpd_chroot) ?
203 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
204 if (n < 0 ||
205 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
206 yyerror("%s: unix_socket_name truncated",
207 __func__);
208 free($2);
209 YYERROR;
211 free($2);
215 server : SERVER STRING {
216 struct server *srv;
218 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
219 if (strcmp(srv->name, $2) == 0) {
220 yyerror("server name exists '%s'", $2);
221 free($2);
222 YYERROR;
226 new_srv = conf_new_server($2);
227 if (new_srv->fcgi_socket)
228 if (get_addrs(new_srv->fcgi_socket_bind,
229 &new_srv->al,
230 new_srv->fcgi_socket_port) == -1) {
231 yyerror("could not get tcp iface "
232 "addrs");
233 YYERROR;
235 log_debug("adding server %s", $2);
236 free($2);
238 | SERVER STRING {
239 struct server *srv;
241 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
242 if (strcmp(srv->name, $2) == 0) {
243 yyerror("server name exists '%s'", $2);
244 free($2);
245 YYERROR;
249 new_srv = conf_new_server($2);
250 log_debug("adding server %s", $2);
251 free($2);
252 } '{' optnl serveropts2 '}' {
253 if (new_srv->fcgi_socket) {
254 if (get_addrs(new_srv->fcgi_socket_bind,
255 &new_srv->al, new_srv->fcgi_socket_port)
256 == -1) {
257 yyerror("could not get tcp iface addr");
258 YYERROR;
264 serveropts1 : REPOS_PATH STRING {
265 n = strlcpy(new_srv->repos_path, $2,
266 sizeof(new_srv->repos_path));
267 if (n >= sizeof(new_srv->repos_path)) {
268 yyerror("%s: repos_path truncated", __func__);
269 free($2);
270 YYERROR;
272 free($2);
274 | SITE_NAME STRING {
275 n = strlcpy(new_srv->site_name, $2,
276 sizeof(new_srv->site_name));
277 if (n >= sizeof(new_srv->site_name)) {
278 yyerror("%s: site_name truncated", __func__);
279 free($2);
280 YYERROR;
282 free($2);
284 | SITE_OWNER STRING {
285 n = strlcpy(new_srv->site_owner, $2,
286 sizeof(new_srv->site_owner));
287 if (n >= sizeof(new_srv->site_owner)) {
288 yyerror("%s: site_owner truncated", __func__);
289 free($2);
290 YYERROR;
292 free($2);
294 | SITE_LINK STRING {
295 n = strlcpy(new_srv->site_link, $2,
296 sizeof(new_srv->site_link));
297 if (n >= sizeof(new_srv->site_link)) {
298 yyerror("%s: site_link truncated", __func__);
299 free($2);
300 YYERROR;
302 free($2);
304 | LOGO STRING {
305 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
306 if (n >= sizeof(new_srv->logo)) {
307 yyerror("%s: logo truncated", __func__);
308 free($2);
309 YYERROR;
311 free($2);
313 | LOGO_URL STRING {
314 n = strlcpy(new_srv->logo_url, $2,
315 sizeof(new_srv->logo_url));
316 if (n >= sizeof(new_srv->logo_url)) {
317 yyerror("%s: logo_url truncated", __func__);
318 free($2);
319 YYERROR;
321 free($2);
323 | CUSTOM_CSS STRING {
324 n = strlcpy(new_srv->custom_css, $2,
325 sizeof(new_srv->custom_css));
326 if (n >= sizeof(new_srv->custom_css)) {
327 yyerror("%s: custom_css truncated", __func__);
328 free($2);
329 YYERROR;
331 free($2);
333 | MAX_REPOS NUMBER {
334 if ($2 > 0)
335 new_srv->max_repos = $2;
337 | SHOW_SITE_OWNER boolean {
338 new_srv->show_site_owner = $2;
340 | SHOW_REPO_OWNER boolean {
341 new_srv->show_repo_owner = $2;
343 | SHOW_REPO_AGE boolean {
344 new_srv->show_repo_age = $2;
346 | SHOW_REPO_DESCRIPTION boolean {
347 new_srv->show_repo_description = $2;
349 | SHOW_REPO_CLONEURL boolean {
350 new_srv->show_repo_cloneurl = $2;
352 | MAX_REPOS_DISPLAY NUMBER {
353 new_srv->max_repos_display = $2;
355 | MAX_COMMITS_DISPLAY NUMBER {
356 if ($2 > 0)
357 new_srv->max_commits_display = $2;
359 | FCGI_SOCKET boolean {
360 new_srv->fcgi_socket = $2;
362 | FCGI_SOCKET boolean {
363 new_srv->fcgi_socket = $2;
364 } '{' optnl socketopts2 '}'
365 | UNIX_SOCKET boolean {
366 new_srv->unix_socket = $2;
368 | UNIX_SOCKET_NAME STRING {
369 n = snprintf(new_srv->unix_socket_name,
370 sizeof(new_srv->unix_socket_name), "%s%s",
371 strlen(gotwebd->httpd_chroot) ?
372 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
373 if (n < 0 ||
374 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
375 yyerror("%s: unix_socket_name truncated",
376 __func__);
377 free($2);
378 YYERROR;
380 free($2);
384 serveropts2 : serveropts2 serveropts1 nl
385 | serveropts1 optnl
388 socketopts1 : LISTEN ON STRING {
389 n = strlcpy(new_srv->fcgi_socket_bind, $3,
390 sizeof(new_srv->fcgi_socket_bind));
391 if (n >= sizeof(new_srv->fcgi_socket_bind)) {
392 yyerror("%s: fcgi_socket_bind truncated",
393 __func__);
394 free($3);
395 YYERROR;
397 free($3);
399 | PORT fcgiport {
400 struct server *srv;
402 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
403 if (srv->fcgi_socket_port == $2) {
404 yyerror("port already assigned");
405 YYERROR;
408 new_srv->fcgi_socket_port = $2;
412 socketopts2 : socketopts2 socketopts1 nl
413 | socketopts1 optnl
416 socketopts3 : LISTEN ON STRING {
417 n = strlcpy(gotwebd->fcgi_socket_bind, $3,
418 sizeof(gotwebd->fcgi_socket_bind));
419 if (n >= sizeof(gotwebd->fcgi_socket_bind)) {
420 yyerror("%s: fcgi_socket_bind truncated",
421 __func__);
422 free($3);
423 YYERROR;
425 free($3);
427 | PORT fcgiport {
428 gotwebd->fcgi_socket_port = $2;
432 socketopts4 : socketopts4 socketopts3 nl
433 | socketopts3 optnl
436 nl : '\n' optnl
439 optnl : '\n' optnl /* zero or more newlines */
440 | /* empty */
443 %%
445 struct keywords {
446 const char *k_name;
447 int k_val;
448 };
450 int
451 yyerror(const char *fmt, ...)
453 va_list ap;
454 char *msg;
456 file->errors++;
457 va_start(ap, fmt);
458 if (vasprintf(&msg, fmt, ap) == -1)
459 fatalx("yyerror vasprintf");
460 va_end(ap);
461 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
462 free(msg);
463 return (0);
466 int
467 kw_cmp(const void *k, const void *e)
469 return (strcmp(k, ((const struct keywords *)e)->k_name));
472 int
473 lookup(char *s)
475 /* This has to be sorted always. */
476 static const struct keywords keywords[] = {
477 { "chroot", CHROOT },
478 { "custom_css", CUSTOM_CSS },
479 { "fcgi_socket", FCGI_SOCKET },
480 { "listen", LISTEN },
481 { "logo", LOGO },
482 { "logo_url" , LOGO_URL },
483 { "max_commits_display", MAX_COMMITS_DISPLAY },
484 { "max_repos", MAX_REPOS },
485 { "max_repos_display", MAX_REPOS_DISPLAY },
486 { "on", ON },
487 { "port", PORT },
488 { "prefork", PREFORK },
489 { "repos_path", REPOS_PATH },
490 { "server", SERVER },
491 { "show_repo_age", SHOW_REPO_AGE },
492 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
493 { "show_repo_description", SHOW_REPO_DESCRIPTION },
494 { "show_repo_owner", SHOW_REPO_OWNER },
495 { "show_site_owner", SHOW_SITE_OWNER },
496 { "site_link", SITE_LINK },
497 { "site_name", SITE_NAME },
498 { "site_owner", SITE_OWNER },
499 { "unix_socket", UNIX_SOCKET },
500 { "unix_socket_name", UNIX_SOCKET_NAME },
501 };
502 const struct keywords *p;
504 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
505 sizeof(keywords[0]), kw_cmp);
507 if (p)
508 return (p->k_val);
509 else
510 return (STRING);
513 #define MAXPUSHBACK 128
515 unsigned char *parsebuf;
516 int parseindex;
517 unsigned char pushback_buffer[MAXPUSHBACK];
518 int pushback_index = 0;
520 int
521 lgetc(int quotec)
523 int c, next;
525 if (parsebuf) {
526 /* Read character from the parsebuffer instead of input. */
527 if (parseindex >= 0) {
528 c = parsebuf[parseindex++];
529 if (c != '\0')
530 return (c);
531 parsebuf = NULL;
532 } else
533 parseindex++;
536 if (pushback_index)
537 return (pushback_buffer[--pushback_index]);
539 if (quotec) {
540 c = getc(file->stream);
541 if (c == EOF)
542 yyerror("reached end of file while parsing "
543 "quoted string");
544 return (c);
547 c = getc(file->stream);
548 while (c == '\\') {
549 next = getc(file->stream);
550 if (next != '\n') {
551 c = next;
552 break;
554 yylval.lineno = file->lineno;
555 file->lineno++;
556 c = getc(file->stream);
559 return (c);
562 int
563 lungetc(int c)
565 if (c == EOF)
566 return (EOF);
567 if (parsebuf) {
568 parseindex--;
569 if (parseindex >= 0)
570 return (c);
572 if (pushback_index < MAXPUSHBACK-1)
573 return (pushback_buffer[pushback_index++] = c);
574 else
575 return (EOF);
578 int
579 findeol(void)
581 int c;
583 parsebuf = NULL;
585 /* Skip to either EOF or the first real EOL. */
586 while (1) {
587 if (pushback_index)
588 c = pushback_buffer[--pushback_index];
589 else
590 c = lgetc(0);
591 if (c == '\n') {
592 file->lineno++;
593 break;
595 if (c == EOF)
596 break;
598 return (ERROR);
601 int
602 yylex(void)
604 unsigned char buf[8096];
605 unsigned char *p, *val;
606 int quotec, next, c;
607 int token;
609 top:
610 p = buf;
611 c = lgetc(0);
612 while (c == ' ' || c == '\t')
613 c = lgetc(0); /* nothing */
615 yylval.lineno = file->lineno;
616 if (c == '#') {
617 c = lgetc(0);
618 while (c != '\n' && c != EOF)
619 c = lgetc(0); /* nothing */
621 if (c == '$' && parsebuf == NULL) {
622 while (1) {
623 c = lgetc(0);
624 if (c == EOF)
625 return (0);
627 if (p + 1 >= buf + sizeof(buf) - 1) {
628 yyerror("string too long");
629 return (findeol());
631 if (isalnum(c) || c == '_') {
632 *p++ = c;
633 continue;
635 *p = '\0';
636 lungetc(c);
637 break;
639 val = symget(buf);
640 if (val == NULL) {
641 yyerror("macro '%s' not defined", buf);
642 return (findeol());
644 parsebuf = val;
645 parseindex = 0;
646 goto top;
649 switch (c) {
650 case '\'':
651 case '"':
652 quotec = c;
653 while (1) {
654 c = lgetc(quotec);
655 if (c == EOF)
656 return (0);
657 if (c == '\n') {
658 file->lineno++;
659 continue;
660 } else if (c == '\\') {
661 next = lgetc(quotec);
662 if (next == EOF)
663 return (0);
664 if (next == quotec || c == ' ' || c == '\t')
665 c = next;
666 else if (next == '\n') {
667 file->lineno++;
668 continue;
669 } else
670 lungetc(next);
671 } else if (c == quotec) {
672 *p = '\0';
673 break;
674 } else if (c == '\0') {
675 yyerror("syntax error");
676 return (findeol());
678 if (p + 1 >= buf + sizeof(buf) - 1) {
679 yyerror("string too long");
680 return (findeol());
682 *p++ = c;
684 yylval.v.string = strdup(buf);
685 if (yylval.v.string == NULL)
686 err(1, "yylex: strdup");
687 return (STRING);
690 #define allowed_to_end_number(x) \
691 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
693 if (c == '-' || isdigit(c)) {
694 do {
695 *p++ = c;
696 if ((unsigned)(p-buf) >= sizeof(buf)) {
697 yyerror("string too long");
698 return (findeol());
700 c = lgetc(0);
701 } while (c != EOF && isdigit(c));
702 lungetc(c);
703 if (p == buf + 1 && buf[0] == '-')
704 goto nodigits;
705 if (c == EOF || allowed_to_end_number(c)) {
706 const char *errstr = NULL;
708 *p = '\0';
709 yylval.v.number = strtonum(buf, LLONG_MIN,
710 LLONG_MAX, &errstr);
711 if (errstr) {
712 yyerror("\"%s\" invalid number: %s",
713 buf, errstr);
714 return (findeol());
716 return (NUMBER);
717 } else {
718 nodigits:
719 while (p > buf + 1)
720 lungetc(*--p);
721 c = *--p;
722 if (c == '-')
723 return (c);
727 #define allowed_in_string(x) \
728 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
729 x != '{' && x != '}' && \
730 x != '!' && x != '=' && x != '#' && \
731 x != ','))
733 if (isalnum(c) || c == ':' || c == '_') {
734 do {
735 *p++ = c;
736 if ((unsigned)(p-buf) >= sizeof(buf)) {
737 yyerror("string too long");
738 return (findeol());
740 c = lgetc(0);
741 } while (c != EOF && (allowed_in_string(c)));
742 lungetc(c);
743 *p = '\0';
744 token = lookup(buf);
745 if (token == STRING) {
746 yylval.v.string = strdup(buf);
747 if (yylval.v.string == NULL)
748 err(1, "yylex: strdup");
750 return (token);
752 if (c == '\n') {
753 yylval.lineno = file->lineno;
754 file->lineno++;
756 if (c == EOF)
757 return (0);
758 return (c);
761 int
762 check_file_secrecy(int fd, const char *fname)
764 struct stat st;
766 if (fstat(fd, &st)) {
767 log_warn("cannot stat %s", fname);
768 return (-1);
770 if (st.st_uid != 0 && st.st_uid != getuid()) {
771 log_warnx("%s: owner not root or current user", fname);
772 return (-1);
774 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
775 log_warnx("%s: group writable or world read/writable", fname);
776 return (-1);
778 return (0);
781 struct file *
782 newfile(const char *name, int secret)
784 struct file *nfile;
786 nfile = calloc(1, sizeof(struct file));
787 if (nfile == NULL) {
788 log_warn("calloc");
789 return (NULL);
791 nfile->name = strdup(name);
792 if (nfile->name == NULL) {
793 log_warn("strdup");
794 free(nfile);
795 return (NULL);
797 nfile->stream = fopen(nfile->name, "r");
798 if (nfile->stream == NULL) {
799 /* no warning, we don't require a conf file */
800 free(nfile->name);
801 free(nfile);
802 return (NULL);
803 } else if (secret &&
804 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
805 fclose(nfile->stream);
806 free(nfile->name);
807 free(nfile);
808 return (NULL);
810 nfile->lineno = 1;
811 return (nfile);
814 static void
815 closefile(struct file *xfile)
817 fclose(xfile->stream);
818 free(xfile->name);
819 free(xfile);
822 static void
823 add_default_server(void)
825 new_srv = conf_new_server(D_SITENAME);
826 log_debug("%s: adding default server %s", __func__, D_SITENAME);
829 int
830 parse_config(const char *filename, struct gotwebd *env)
832 struct sym *sym, *next;
834 if (config_init(env) == -1)
835 fatalx("failed to initialize configuration");
837 gotwebd = env;
839 file = newfile(filename, 0);
840 if (file == NULL) {
841 add_default_server();
842 sockets_parse_sockets(env);
843 /* just return, as we don't require a conf file */
844 return (0);
847 yyparse();
848 errors = file->errors;
849 closefile(file);
851 /* Free macros and check which have not been used. */
852 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
853 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
854 fprintf(stderr, "warning: macro '%s' not used\n",
855 sym->nam);
856 if (!sym->persist) {
857 free(sym->nam);
858 free(sym->val);
859 TAILQ_REMOVE(&symhead, sym, entry);
860 free(sym);
864 if (errors)
865 return (-1);
867 /* just add default server if no config specified */
868 if (gotwebd->server_cnt == 0)
869 add_default_server();
871 /* setup our listening sockets */
872 sockets_parse_sockets(env);
874 return (0);
877 struct server *
878 conf_new_server(const char *name)
880 struct server *srv = NULL;
881 int val;
883 srv = calloc(1, sizeof(*srv));
884 if (srv == NULL)
885 fatalx("%s: calloc", __func__);
887 n = strlcpy(srv->name, name, sizeof(srv->name));
888 if (n >= sizeof(srv->name))
889 fatalx("%s: strlcpy", __func__);
890 n = snprintf(srv->unix_socket_name,
891 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
892 D_UNIX_SOCKET);
893 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
894 fatalx("%s: snprintf", __func__);
895 n = strlcpy(srv->repos_path, D_GOTPATH,
896 sizeof(srv->repos_path));
897 if (n >= sizeof(srv->repos_path))
898 fatalx("%s: strlcpy", __func__);
899 n = strlcpy(srv->site_name, D_SITENAME,
900 sizeof(srv->site_name));
901 if (n >= sizeof(srv->site_name))
902 fatalx("%s: strlcpy", __func__);
903 n = strlcpy(srv->site_owner, D_SITEOWNER,
904 sizeof(srv->site_owner));
905 if (n >= sizeof(srv->site_owner))
906 fatalx("%s: strlcpy", __func__);
907 n = strlcpy(srv->site_link, D_SITELINK,
908 sizeof(srv->site_link));
909 if (n >= sizeof(srv->site_link))
910 fatalx("%s: strlcpy", __func__);
911 n = strlcpy(srv->logo, D_GOTLOGO,
912 sizeof(srv->logo));
913 if (n >= sizeof(srv->logo))
914 fatalx("%s: strlcpy", __func__);
915 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
916 if (n >= sizeof(srv->logo_url))
917 fatalx("%s: strlcpy", __func__);
918 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
919 if (n >= sizeof(srv->custom_css))
920 fatalx("%s: strlcpy", __func__);
922 val = getservice(D_FCGI_PORT);
923 srv->fcgi_socket_port = gotwebd->fcgi_socket_port ?
924 gotwebd->fcgi_socket_port: htons(val);
926 srv->show_site_owner = D_SHOWSOWNER;
927 srv->show_repo_owner = D_SHOWROWNER;
928 srv->show_repo_age = D_SHOWAGE;
929 srv->show_repo_description = D_SHOWDESC;
930 srv->show_repo_cloneurl = D_SHOWURL;
932 srv->max_repos_display = D_MAXREPODISP;
933 srv->max_commits_display = D_MAXCOMMITDISP;
934 srv->max_repos = D_MAXREPO;
936 srv->unix_socket = 1;
937 srv->fcgi_socket = gotwebd->fcgi_socket ? gotwebd->fcgi_socket : 0;
939 TAILQ_INIT(&srv->al);
940 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
941 gotwebd->server_cnt++;
943 return srv;
944 };
946 int
947 symset(const char *nam, const char *val, int persist)
949 struct sym *sym;
951 TAILQ_FOREACH(sym, &symhead, entry) {
952 if (strcmp(nam, sym->nam) == 0)
953 break;
956 if (sym != NULL) {
957 if (sym->persist == 1)
958 return (0);
959 else {
960 free(sym->nam);
961 free(sym->val);
962 TAILQ_REMOVE(&symhead, sym, entry);
963 free(sym);
966 sym = calloc(1, sizeof(*sym));
967 if (sym == NULL)
968 return (-1);
970 sym->nam = strdup(nam);
971 if (sym->nam == NULL) {
972 free(sym);
973 return (-1);
975 sym->val = strdup(val);
976 if (sym->val == NULL) {
977 free(sym->nam);
978 free(sym);
979 return (-1);
981 sym->used = 0;
982 sym->persist = persist;
983 TAILQ_INSERT_TAIL(&symhead, sym, entry);
984 return (0);
987 int
988 cmdline_symset(char *s)
990 char *sym, *val;
991 int ret;
992 size_t len;
994 val = strrchr(s, '=');
995 if (val == NULL)
996 return (-1);
998 len = strlen(s) - strlen(val) + 1;
999 sym = malloc(len);
1000 if (sym == NULL)
1001 fatal("%s: malloc", __func__);
1003 memcpy(&sym, s, len);
1005 ret = symset(sym, val + 1, 1);
1006 free(sym);
1008 return (ret);
1011 char *
1012 symget(const char *nam)
1014 struct sym *sym;
1016 TAILQ_FOREACH(sym, &symhead, entry) {
1017 if (strcmp(nam, sym->nam) == 0) {
1018 sym->used = 1;
1019 return (sym->val);
1022 return (NULL);
1025 int
1026 getservice(const char *n)
1028 struct servent *s;
1029 const char *errstr;
1030 long long llval;
1032 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1033 if (errstr) {
1034 s = getservbyname(n, "tcp");
1035 if (s == NULL)
1036 s = getservbyname(n, "udp");
1037 if (s == NULL)
1038 return (-1);
1039 return (s->s_port);
1042 return (htons((unsigned short)llval));
1045 struct address *
1046 host_v4(const char *s)
1048 struct in_addr ina;
1049 struct sockaddr_in *sain;
1050 struct address *h;
1052 memset(&ina, 0, sizeof(ina));
1053 if (inet_pton(AF_INET, s, &ina) != 1)
1054 return (NULL);
1056 if ((h = calloc(1, sizeof(*h))) == NULL)
1057 fatal(__func__);
1058 sain = (struct sockaddr_in *)&h->ss;
1059 got_sockaddr_inet_init(sain, &ina);
1060 if (sain->sin_addr.s_addr == INADDR_ANY)
1061 h->prefixlen = 0; /* 0.0.0.0 address */
1062 else
1063 h->prefixlen = -1; /* host address */
1064 return (h);
1067 struct address *
1068 host_v6(const char *s)
1070 struct addrinfo hints, *res;
1071 struct sockaddr_in6 *sa_in6, *ra;
1072 struct address *h = NULL;
1074 memset(&hints, 0, sizeof(hints));
1075 hints.ai_family = AF_INET6;
1076 hints.ai_socktype = SOCK_DGRAM; /* dummy */
1077 hints.ai_flags = AI_NUMERICHOST;
1078 if (getaddrinfo(s, "0", &hints, &res) == 0) {
1079 if ((h = calloc(1, sizeof(*h))) == NULL)
1080 fatal(__func__);
1081 sa_in6 = (struct sockaddr_in6 *)&h->ss;
1082 ra = (struct sockaddr_in6 *)res->ai_addr;
1083 got_sockaddr_inet6_init(sa_in6, &ra->sin6_addr,
1084 ra->sin6_scope_id);
1085 if (memcmp(&sa_in6->sin6_addr, &in6addr_any,
1086 sizeof(sa_in6->sin6_addr)) == 0)
1087 h->prefixlen = 0; /* any address */
1088 else
1089 h->prefixlen = -1; /* host address */
1090 freeaddrinfo(res);
1093 return (h);
1096 int
1097 host_dns(const char *s, struct addresslist *al, int max,
1098 in_port_t port, const char *ifname, int ipproto)
1100 struct addrinfo hints, *res0, *res;
1101 int error, cnt = 0;
1102 struct sockaddr_in *sain;
1103 struct sockaddr_in6 *sin6;
1104 struct address *h;
1106 if ((cnt = host_if(s, al, max, port, ifname, ipproto)) != 0)
1107 return (cnt);
1109 memset(&hints, 0, sizeof(hints));
1110 hints.ai_family = PF_UNSPEC;
1111 hints.ai_socktype = SOCK_DGRAM; /* DUMMY */
1112 hints.ai_flags = AI_ADDRCONFIG;
1113 error = getaddrinfo(s, NULL, &hints, &res0);
1114 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1115 return (0);
1116 if (error) {
1117 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1118 gai_strerror(error));
1119 return (-1);
1122 for (res = res0; res && cnt < max; res = res->ai_next) {
1123 if (res->ai_family != AF_INET &&
1124 res->ai_family != AF_INET6)
1125 continue;
1126 if ((h = calloc(1, sizeof(*h))) == NULL)
1127 fatal(__func__);
1129 if (port)
1130 h->port = port;
1131 if (ifname != NULL) {
1132 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1133 sizeof(h->ifname)) {
1134 log_warnx("%s: interface name truncated",
1135 __func__);
1136 freeaddrinfo(res0);
1137 free(h);
1138 return (-1);
1141 if (ipproto != -1)
1142 h->ipproto = ipproto;
1143 h->ss.ss_family = res->ai_family;
1144 h->prefixlen = -1; /* host address */
1146 if (res->ai_family == AF_INET) {
1147 struct sockaddr_in *ra;
1148 sain = (struct sockaddr_in *)&h->ss;
1149 ra = (struct sockaddr_in *)res->ai_addr;
1150 got_sockaddr_inet_init(sain, &ra->sin_addr);
1151 } else {
1152 struct sockaddr_in6 *ra;
1153 sin6 = (struct sockaddr_in6 *)&h->ss;
1154 ra = (struct sockaddr_in6 *)res->ai_addr;
1155 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1158 TAILQ_INSERT_HEAD(al, h, entry);
1159 cnt++;
1161 if (cnt == max && res) {
1162 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1163 s, max);
1165 freeaddrinfo(res0);
1166 return (cnt);
1169 int
1170 host_if(const char *s, struct addresslist *al, int max,
1171 in_port_t port, const char *ifname, int ipproto)
1173 struct ifaddrs *ifap, *p;
1174 struct sockaddr_in *sain;
1175 struct sockaddr_in6 *sin6;
1176 struct address *h;
1177 int cnt = 0, af;
1179 if (getifaddrs(&ifap) == -1)
1180 fatal("getifaddrs");
1182 /* First search for IPv4 addresses */
1183 af = AF_INET;
1185 nextaf:
1186 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1187 if (p->ifa_addr == NULL ||
1188 p->ifa_addr->sa_family != af ||
1189 (strcmp(s, p->ifa_name) != 0 &&
1190 !is_if_in_group(p->ifa_name, s)))
1191 continue;
1192 if ((h = calloc(1, sizeof(*h))) == NULL)
1193 fatal("calloc");
1195 if (port)
1196 h->port = port;
1197 if (ifname != NULL) {
1198 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1199 sizeof(h->ifname)) {
1200 log_warnx("%s: interface name truncated",
1201 __func__);
1202 free(h);
1203 freeifaddrs(ifap);
1204 return (-1);
1207 if (ipproto != -1)
1208 h->ipproto = ipproto;
1209 h->ss.ss_family = af;
1210 h->prefixlen = -1; /* host address */
1212 if (af == AF_INET) {
1213 struct sockaddr_in *ra;
1214 sain = (struct sockaddr_in *)&h->ss;
1215 ra = (struct sockaddr_in *)p->ifa_addr;
1216 got_sockaddr_inet_init(sain, &ra->sin_addr);
1217 } else {
1218 struct sockaddr_in6 *ra;
1219 sin6 = (struct sockaddr_in6 *)&h->ss;
1220 ra = (struct sockaddr_in6 *)p->ifa_addr;
1221 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1222 ra->sin6_scope_id);
1225 TAILQ_INSERT_HEAD(al, h, entry);
1226 cnt++;
1228 if (af == AF_INET) {
1229 /* Next search for IPv6 addresses */
1230 af = AF_INET6;
1231 goto nextaf;
1234 if (cnt > max) {
1235 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1236 s, max);
1238 freeifaddrs(ifap);
1239 return (cnt);
1242 int
1243 host(const char *s, struct addresslist *al, int max,
1244 in_port_t port, const char *ifname, int ipproto)
1246 struct address *h;
1248 h = host_v4(s);
1250 /* IPv6 address? */
1251 if (h == NULL)
1252 h = host_v6(s);
1254 if (h != NULL) {
1255 if (port)
1256 h->port = port;
1257 if (ifname != NULL) {
1258 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1259 sizeof(h->ifname)) {
1260 log_warnx("%s: interface name truncated",
1261 __func__);
1262 free(h);
1263 return (-1);
1266 if (ipproto != -1)
1267 h->ipproto = ipproto;
1269 TAILQ_INSERT_HEAD(al, h, entry);
1270 return (1);
1273 return (host_dns(s, al, max, port, ifname, ipproto));
1276 int
1277 is_if_in_group(const char *ifname, const char *groupname)
1279 /* TA: Check this... */
1280 #ifdef HAVE_STRUCT_IFGROUPREQ
1281 unsigned int len;
1282 struct ifgroupreq ifgr;
1283 struct ifg_req *ifg;
1284 int s;
1285 int ret = 0;
1287 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1288 err(1, "socket");
1290 memset(&ifgr, 0, sizeof(ifgr));
1291 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1292 err(1, "IFNAMSIZ");
1293 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1294 if (errno == EINVAL || errno == ENOTTY)
1295 goto end;
1296 err(1, "SIOCGIFGROUP");
1299 len = ifgr.ifgr_len;
1300 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1301 sizeof(struct ifg_req));
1302 if (ifgr.ifgr_groups == NULL)
1303 err(1, "getifgroups");
1304 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1305 err(1, "SIOCGIFGROUP");
1307 ifg = ifgr.ifgr_groups;
1308 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1309 len -= sizeof(struct ifg_req);
1310 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1311 ret = 1;
1312 break;
1315 free(ifgr.ifgr_groups);
1317 end:
1318 close(s);
1319 return (ret);
1320 #else
1321 return (0);
1322 #endif
1325 int
1326 get_addrs(const char *addr, struct addresslist *al, in_port_t port)
1328 if (strcmp("", addr) == 0) {
1329 if (host("0.0.0.0", al, 1, port, "0.0.0.0", -1) <= 0) {
1330 yyerror("invalid listen ip: %s",
1331 "0.0.0.0");
1332 return (-1);
1334 if (host("::", al, 1, port, "::", -1) <= 0) {
1335 yyerror("invalid listen ip: %s", "::");
1336 return (-1);
1338 } else {
1339 if (host(addr, al, GOTWEBD_MAXIFACE, port, addr,
1340 -1) <= 0) {
1341 yyerror("invalid listen ip: %s", addr);
1342 return (-1);
1345 return (0);