2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
50 #include "got_reference.h"
54 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
56 TAILQ_ENTRY(file) entry;
62 struct file *newfile(const char *, int);
63 static void closefile(struct file *);
64 int check_file_secrecy(int, const char *);
67 int yyerror(const char *, ...)
68 __attribute__((__format__ (printf, 1, 2)))
69 __attribute__((__nonnull__ (1)));
70 int kw_cmp(const void *, const void *);
76 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
78 TAILQ_ENTRY(sym) entry;
85 int symset(const char *, const char *, int);
86 char *symget(const char *);
90 static struct gotwebd *gotwebd;
91 static struct server *new_srv;
92 static struct server *conf_new_server(const char *);
93 int getservice(const char *);
96 int get_addrs(const char *, const char *, struct server *);
97 int addr_dup_check(struct addresslist *, struct address *,
98 const char *, const char *);
99 int add_addr(struct server *, struct address *);
111 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
112 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
113 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
114 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
115 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
116 %token SUMMARY_COMMITS_DISPLAY SUMMARY_TAGS_DISPLAY
118 %token <v.string> STRING
119 %token <v.number> NUMBER
120 %type <v.number> boolean
121 %type <v.string> listen_addr
125 grammar : /* empty */
127 | grammar varset '\n'
129 | grammar server '\n'
130 | grammar error '\n' { file->errors++; }
133 varset : STRING '=' STRING {
136 if (isspace((unsigned char)*s)) {
137 yyerror("macro name cannot contain "
144 if (symset($1, $3, 0) == -1)
145 fatal("cannot store variable");
152 if (strcasecmp($1, "1") == 0 ||
153 strcasecmp($1, "on") == 0)
155 else if (strcasecmp($1, "0") == 0 ||
156 strcasecmp($1, "off") == 0)
159 yyerror("invalid boolean value '%s'", $1);
167 if ($1 != 0 && $1 != 1) {
168 yyerror("invalid boolean value '%lld'", $1);
175 listen_addr : '*' { $$ = NULL; }
179 main : PREFORK NUMBER {
180 if ($2 <= 0 || $2 > PROC_MAX_INSTANCES) {
181 yyerror("prefork is %s: %lld",
182 $2 <= 0 ? "too small" : "too large", $2);
185 gotwebd->prefork_gotwebd = $2;
189 yyerror("chroot path can't be an empty"
195 n = strlcpy(gotwebd->httpd_chroot, $2,
196 sizeof(gotwebd->httpd_chroot));
197 if (n >= sizeof(gotwebd->httpd_chroot)) {
198 yyerror("%s: httpd_chroot truncated", __func__);
204 | UNIX_SOCKET boolean {
205 gotwebd->unix_socket = $2;
207 | UNIX_SOCKET_NAME STRING {
208 n = snprintf(gotwebd->unix_socket_name,
209 sizeof(gotwebd->unix_socket_name), "%s%s",
210 gotwebd->httpd_chroot, $2);
212 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
213 yyerror("%s: unix_socket_name truncated",
222 server : SERVER STRING {
225 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
226 if (strcmp(srv->name, $2) == 0) {
227 yyerror("server name exists '%s'", $2);
233 new_srv = conf_new_server($2);
234 log_debug("adding server %s", $2);
240 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
241 if (strcmp(srv->name, $2) == 0) {
242 yyerror("server name exists '%s'", $2);
248 new_srv = conf_new_server($2);
249 log_debug("adding server %s", $2);
251 } '{' optnl serveropts2 '}' {
255 serveropts1 : REPOS_PATH STRING {
256 n = strlcpy(new_srv->repos_path, $2,
257 sizeof(new_srv->repos_path));
258 if (n >= sizeof(new_srv->repos_path)) {
259 yyerror("%s: repos_path truncated", __func__);
266 n = strlcpy(new_srv->site_name, $2,
267 sizeof(new_srv->site_name));
268 if (n >= sizeof(new_srv->site_name)) {
269 yyerror("%s: site_name truncated", __func__);
275 | SITE_OWNER STRING {
276 n = strlcpy(new_srv->site_owner, $2,
277 sizeof(new_srv->site_owner));
278 if (n >= sizeof(new_srv->site_owner)) {
279 yyerror("%s: site_owner truncated", __func__);
286 n = strlcpy(new_srv->site_link, $2,
287 sizeof(new_srv->site_link));
288 if (n >= sizeof(new_srv->site_link)) {
289 yyerror("%s: site_link truncated", __func__);
296 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
297 if (n >= sizeof(new_srv->logo)) {
298 yyerror("%s: logo truncated", __func__);
305 n = strlcpy(new_srv->logo_url, $2,
306 sizeof(new_srv->logo_url));
307 if (n >= sizeof(new_srv->logo_url)) {
308 yyerror("%s: logo_url truncated", __func__);
314 | CUSTOM_CSS STRING {
315 n = strlcpy(new_srv->custom_css, $2,
316 sizeof(new_srv->custom_css));
317 if (n >= sizeof(new_srv->custom_css)) {
318 yyerror("%s: custom_css truncated", __func__);
324 | LISTEN ON listen_addr PORT STRING {
325 if (get_addrs($3, $5, new_srv) == -1) {
326 yyerror("could not get addrs");
331 new_srv->fcgi_socket = 1;
333 | LISTEN ON listen_addr PORT NUMBER {
337 n = snprintf(portno, sizeof(portno), "%lld",
339 if (n < 0 || (size_t)n >= sizeof(portno))
340 fatalx("port number too long: %lld",
343 if (get_addrs($3, portno, new_srv) == -1) {
344 yyerror("could not get addrs");
348 new_srv->fcgi_socket = 1;
350 | LISTEN ON SOCKET STRING {
351 if (strcasecmp($4, "off") == 0) {
352 new_srv->unix_socket = 0;
357 new_srv->unix_socket = 1;
359 n = snprintf(new_srv->unix_socket_name,
360 sizeof(new_srv->unix_socket_name), "%s%s",
361 gotwebd->httpd_chroot, $4);
363 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
364 yyerror("%s: unix_socket_name truncated",
373 yyerror("max_repos is too small: %lld", $2);
376 new_srv->max_repos = $2;
378 | SHOW_SITE_OWNER boolean {
379 new_srv->show_site_owner = $2;
381 | SHOW_REPO_OWNER boolean {
382 new_srv->show_repo_owner = $2;
384 | SHOW_REPO_AGE boolean {
385 new_srv->show_repo_age = $2;
387 | SHOW_REPO_DESCRIPTION boolean {
388 new_srv->show_repo_description = $2;
390 | SHOW_REPO_CLONEURL boolean {
391 new_srv->show_repo_cloneurl = $2;
393 | RESPECT_EXPORTOK boolean {
394 new_srv->respect_exportok = $2;
396 | MAX_REPOS_DISPLAY NUMBER {
398 yyerror("max_repos_display is too small: %lld",
402 new_srv->max_repos_display = $2;
404 | MAX_COMMITS_DISPLAY NUMBER {
406 yyerror("max_commits_display is too small:"
410 new_srv->max_commits_display = $2;
412 | SUMMARY_COMMITS_DISPLAY NUMBER {
414 yyerror("summary_commits_display is too small:"
418 new_srv->summary_commits_display = $2;
420 | SUMMARY_TAGS_DISPLAY NUMBER {
422 yyerror("summary_tags_display is too small:"
426 new_srv->summary_tags_display = $2;
430 serveropts2 : serveropts2 serveropts1 nl
437 optnl : '\n' optnl /* zero or more newlines */
449 yyerror(const char *fmt, ...)
456 if (vasprintf(&msg, fmt, ap) == -1)
457 fatalx("yyerror vasprintf");
459 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
465 kw_cmp(const void *k, const void *e)
467 return (strcmp(k, ((const struct keywords *)e)->k_name));
473 /* This has to be sorted always. */
474 static const struct keywords keywords[] = {
475 { "chroot", CHROOT },
476 { "custom_css", CUSTOM_CSS },
477 { "listen", LISTEN },
479 { "logo_url", LOGO_URL },
480 { "max_commits_display", MAX_COMMITS_DISPLAY },
481 { "max_repos", MAX_REPOS },
482 { "max_repos_display", MAX_REPOS_DISPLAY },
485 { "prefork", PREFORK },
486 { "repos_path", REPOS_PATH },
487 { "respect_exportok", RESPECT_EXPORTOK },
488 { "server", SERVER },
489 { "show_repo_age", SHOW_REPO_AGE },
490 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
491 { "show_repo_description", SHOW_REPO_DESCRIPTION },
492 { "show_repo_owner", SHOW_REPO_OWNER },
493 { "show_site_owner", SHOW_SITE_OWNER },
494 { "site_link", SITE_LINK },
495 { "site_name", SITE_NAME },
496 { "site_owner", SITE_OWNER },
497 { "socket", SOCKET },
498 { "summary_commits_display", SUMMARY_COMMITS_DISPLAY },
499 { "summary_tags_display", SUMMARY_TAGS_DISPLAY },
500 { "unix_socket", UNIX_SOCKET },
501 { "unix_socket_name", UNIX_SOCKET_NAME },
503 const struct keywords *p;
505 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
506 sizeof(keywords[0]), kw_cmp);
514 #define MAXPUSHBACK 128
516 unsigned char *parsebuf;
518 unsigned char pushback_buffer[MAXPUSHBACK];
519 int pushback_index = 0;
527 /* Read character from the parsebuffer instead of input. */
528 if (parseindex >= 0) {
529 c = parsebuf[parseindex++];
538 return (pushback_buffer[--pushback_index]);
541 c = getc(file->stream);
543 yyerror("reached end of file while parsing "
548 c = getc(file->stream);
550 next = getc(file->stream);
555 yylval.lineno = file->lineno;
557 c = getc(file->stream);
573 if (pushback_index < MAXPUSHBACK-1)
574 return (pushback_buffer[pushback_index++] = c);
586 /* Skip to either EOF or the first real EOL. */
589 c = pushback_buffer[--pushback_index];
605 unsigned char buf[8096];
606 unsigned char *p, *val;
613 while (c == ' ' || c == '\t')
614 c = lgetc(0); /* nothing */
616 yylval.lineno = file->lineno;
619 while (c != '\n' && c != EOF)
620 c = lgetc(0); /* nothing */
622 if (c == '$' && parsebuf == NULL) {
628 if (p + 1 >= buf + sizeof(buf) - 1) {
629 yyerror("string too long");
632 if (isalnum(c) || c == '_') {
642 yyerror("macro '%s' not defined", buf);
661 } else if (c == '\\') {
662 next = lgetc(quotec);
665 if (next == quotec || c == ' ' || c == '\t')
667 else if (next == '\n') {
672 } else if (c == quotec) {
675 } else if (c == '\0') {
676 yyerror("syntax error");
679 if (p + 1 >= buf + sizeof(buf) - 1) {
680 yyerror("string too long");
685 yylval.v.string = strdup(buf);
686 if (yylval.v.string == NULL)
687 err(1, "yylex: strdup");
691 #define allowed_to_end_number(x) \
692 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
694 if (c == '-' || isdigit(c)) {
697 if ((unsigned)(p-buf) >= sizeof(buf)) {
698 yyerror("string too long");
702 } while (c != EOF && isdigit(c));
704 if (p == buf + 1 && buf[0] == '-')
706 if (c == EOF || allowed_to_end_number(c)) {
707 const char *errstr = NULL;
710 yylval.v.number = strtonum(buf, LLONG_MIN,
713 yyerror("\"%s\" invalid number: %s",
728 #define allowed_in_string(x) \
729 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
730 x != '{' && x != '}' && \
731 x != '!' && x != '=' && x != '#' && \
734 if (isalnum(c) || c == ':' || c == '_') {
737 if ((unsigned)(p-buf) >= sizeof(buf)) {
738 yyerror("string too long");
742 } while (c != EOF && (allowed_in_string(c)));
746 if (token == STRING) {
747 yylval.v.string = strdup(buf);
748 if (yylval.v.string == NULL)
749 err(1, "yylex: strdup");
754 yylval.lineno = file->lineno;
763 check_file_secrecy(int fd, const char *fname)
767 if (fstat(fd, &st)) {
768 log_warn("cannot stat %s", fname);
771 if (st.st_uid != 0 && st.st_uid != getuid()) {
772 log_warnx("%s: owner not root or current user", fname);
775 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
776 log_warnx("%s: group writable or world read/writable", fname);
783 newfile(const char *name, int secret)
787 nfile = calloc(1, sizeof(struct file));
792 nfile->name = strdup(name);
793 if (nfile->name == NULL) {
798 nfile->stream = fopen(nfile->name, "r");
799 if (nfile->stream == NULL) {
800 /* no warning, we don't require a conf file */
805 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
806 fclose(nfile->stream);
816 closefile(struct file *xfile)
818 fclose(xfile->stream);
824 add_default_server(void)
826 new_srv = conf_new_server(D_SITENAME);
827 log_debug("%s: adding default server %s", __func__, D_SITENAME);
831 parse_config(const char *filename, struct gotwebd *env)
833 struct sym *sym, *next;
835 if (config_init(env) == -1)
836 fatalx("failed to initialize configuration");
840 file = newfile(filename, 0);
842 add_default_server();
843 sockets_parse_sockets(env);
844 /* just return, as we don't require a conf file */
849 errors = file->errors;
852 /* Free macros and check which have not been used. */
853 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
854 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
855 fprintf(stderr, "warning: macro '%s' not used\n",
860 TAILQ_REMOVE(&symhead, sym, entry);
868 /* just add default server if no config specified */
869 if (gotwebd->server_cnt == 0)
870 add_default_server();
872 /* setup our listening sockets */
873 sockets_parse_sockets(env);
879 conf_new_server(const char *name)
881 struct server *srv = NULL;
883 srv = calloc(1, sizeof(*srv));
885 fatalx("%s: calloc", __func__);
887 n = strlcpy(srv->name, name, sizeof(srv->name));
888 if (n >= sizeof(srv->name))
889 fatalx("%s: strlcpy", __func__);
890 n = snprintf(srv->unix_socket_name,
891 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
893 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
894 fatalx("%s: snprintf", __func__);
895 n = strlcpy(srv->repos_path, D_GOTPATH,
896 sizeof(srv->repos_path));
897 if (n >= sizeof(srv->repos_path))
898 fatalx("%s: strlcpy", __func__);
899 n = strlcpy(srv->site_name, D_SITENAME,
900 sizeof(srv->site_name));
901 if (n >= sizeof(srv->site_name))
902 fatalx("%s: strlcpy", __func__);
903 n = strlcpy(srv->site_owner, D_SITEOWNER,
904 sizeof(srv->site_owner));
905 if (n >= sizeof(srv->site_owner))
906 fatalx("%s: strlcpy", __func__);
907 n = strlcpy(srv->site_link, D_SITELINK,
908 sizeof(srv->site_link));
909 if (n >= sizeof(srv->site_link))
910 fatalx("%s: strlcpy", __func__);
911 n = strlcpy(srv->logo, D_GOTLOGO,
913 if (n >= sizeof(srv->logo))
914 fatalx("%s: strlcpy", __func__);
915 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
916 if (n >= sizeof(srv->logo_url))
917 fatalx("%s: strlcpy", __func__);
918 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
919 if (n >= sizeof(srv->custom_css))
920 fatalx("%s: strlcpy", __func__);
922 srv->show_site_owner = D_SHOWSOWNER;
923 srv->show_repo_owner = D_SHOWROWNER;
924 srv->show_repo_age = D_SHOWAGE;
925 srv->show_repo_description = D_SHOWDESC;
926 srv->show_repo_cloneurl = D_SHOWURL;
927 srv->respect_exportok = D_RESPECTEXPORTOK;
929 srv->max_repos_display = D_MAXREPODISP;
930 srv->max_commits_display = D_MAXCOMMITDISP;
931 srv->summary_commits_display = D_MAXSLCOMMDISP;
932 srv->summary_tags_display = D_MAXSLTAGDISP;
933 srv->max_repos = D_MAXREPO;
935 srv->unix_socket = 1;
936 srv->fcgi_socket = 0;
938 TAILQ_INIT(&srv->al);
939 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
940 gotwebd->server_cnt++;
946 symset(const char *nam, const char *val, int persist)
950 TAILQ_FOREACH(sym, &symhead, entry) {
951 if (strcmp(nam, sym->nam) == 0)
956 if (sym->persist == 1)
961 TAILQ_REMOVE(&symhead, sym, entry);
965 sym = calloc(1, sizeof(*sym));
969 sym->nam = strdup(nam);
970 if (sym->nam == NULL) {
974 sym->val = strdup(val);
975 if (sym->val == NULL) {
981 sym->persist = persist;
982 TAILQ_INSERT_TAIL(&symhead, sym, entry);
987 cmdline_symset(char *s)
992 val = strrchr(s, '=');
996 sym = strndup(s, val - s);
998 fatal("%s: strndup", __func__);
1000 ret = symset(sym, val + 1, 1);
1007 symget(const char *nam)
1011 TAILQ_FOREACH(sym, &symhead, entry) {
1012 if (strcmp(nam, sym->nam) == 0) {
1021 get_addrs(const char *hostname, const char *servname, struct server *new_srv)
1023 struct addrinfo hints, *res0, *res;
1025 struct sockaddr_in *sin;
1026 struct sockaddr_in6 *sin6;
1029 memset(&hints, 0, sizeof(hints));
1030 hints.ai_family = AF_UNSPEC;
1031 hints.ai_socktype = SOCK_STREAM;
1032 hints.ai_flags = AI_PASSIVE | AI_ADDRCONFIG;
1033 error = getaddrinfo(hostname, servname, &hints, &res0);
1035 log_warnx("%s: could not parse \"%s:%s\": %s", __func__,
1036 hostname, servname, gai_strerror(error));
1040 for (res = res0; res; res = res->ai_next) {
1041 if ((h = calloc(1, sizeof(*h))) == NULL)
1044 if (hostname == NULL) {
1045 strlcpy(h->ifname, "*", sizeof(h->ifname));
1047 if (strlcpy(h->ifname, hostname, sizeof(h->ifname)) >=
1048 sizeof(h->ifname)) {
1049 log_warnx("%s: address truncated: %s",
1050 __func__, hostname);
1057 h->ai_family = res->ai_family;
1058 h->ai_socktype = res->ai_socktype;
1059 h->ai_protocol = res->ai_protocol;
1060 memcpy(&h->ss, res->ai_addr, res->ai_addrlen);
1061 h->slen = res->ai_addrlen;
1063 switch (res->ai_family) {
1065 sin = (struct sockaddr_in *)res->ai_addr;
1066 h->port = ntohs(sin->sin_port);
1069 sin6 = (struct sockaddr_in6 *)res->ai_addr;
1070 h->port = ntohs(sin6->sin6_port);
1073 fatalx("unknown address family %d", res->ai_family);
1076 if (add_addr(new_srv, h))
1084 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1085 const char *other_srv)
1089 char buf[INET6_ADDRSTRLEN];
1090 const char *addrstr;
1092 TAILQ_FOREACH(a, al, entry) {
1093 if (a->ai_family != h->ai_family ||
1094 a->ai_socktype != h->ai_socktype ||
1095 a->ai_protocol != h->ai_protocol ||
1096 a->slen != h->slen ||
1097 memcmp(&a->ss, &h->ss, a->slen) != 0)
1100 switch (h->ss.ss_family) {
1102 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1105 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1108 yyerror("unknown address family: %d", h->ss.ss_family);
1111 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1114 yyerror("server %s: duplicate fcgi listen "
1115 "address %s:%d, already used by server %s",
1116 new_srv, addrstr, h->port, other_srv);
1118 log_warnx("server: %s: duplicate fcgi listen "
1119 "address %s:%d", new_srv, addrstr, h->port);
1123 yyerror("server: %s: duplicate fcgi listen "
1124 "address, already used by server %s",
1125 new_srv, other_srv);
1127 log_warnx("server %s: duplicate fcgi listen "
1128 "address", new_srv);
1139 add_addr(struct server *new_srv, struct address *h)
1143 /* Address cannot be shared between different servers. */
1144 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1147 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1151 /* Tolerate duplicate address lines within the scope of a server. */
1152 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1153 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);