2 13b2bc37 2022-10-23 stsp * Copyright (c) 2022 Stefan Sperling <stsp@openbsd.org>
3 13b2bc37 2022-10-23 stsp * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
4 13b2bc37 2022-10-23 stsp * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
5 13b2bc37 2022-10-23 stsp * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
6 13b2bc37 2022-10-23 stsp * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
7 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Markus Friedl. All rights reserved.
8 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
9 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Theo de Raadt. All rights reserved.
11 13b2bc37 2022-10-23 stsp * Permission to use, copy, modify, and distribute this software for any
12 13b2bc37 2022-10-23 stsp * purpose with or without fee is hereby granted, provided that the above
13 13b2bc37 2022-10-23 stsp * copyright notice and this permission notice appear in all copies.
15 13b2bc37 2022-10-23 stsp * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
16 13b2bc37 2022-10-23 stsp * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
17 13b2bc37 2022-10-23 stsp * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
18 13b2bc37 2022-10-23 stsp * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
19 13b2bc37 2022-10-23 stsp * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
20 13b2bc37 2022-10-23 stsp * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
21 13b2bc37 2022-10-23 stsp * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
25 13b2bc37 2022-10-23 stsp #include <sys/time.h>
26 13b2bc37 2022-10-23 stsp #include <sys/types.h>
27 13b2bc37 2022-10-23 stsp #include <sys/queue.h>
28 13b2bc37 2022-10-23 stsp #include <sys/stat.h>
30 13b2bc37 2022-10-23 stsp #include <ctype.h>
31 13b2bc37 2022-10-23 stsp #include <err.h>
32 13b2bc37 2022-10-23 stsp #include <errno.h>
33 13b2bc37 2022-10-23 stsp #include <event.h>
34 13b2bc37 2022-10-23 stsp #include <imsg.h>
35 13b2bc37 2022-10-23 stsp #include <limits.h>
36 13b2bc37 2022-10-23 stsp #include <sha1.h>
37 13b2bc37 2022-10-23 stsp #include <stdarg.h>
38 13b2bc37 2022-10-23 stsp #include <stdlib.h>
39 13b2bc37 2022-10-23 stsp #include <stdio.h>
40 13b2bc37 2022-10-23 stsp #include <string.h>
41 13b2bc37 2022-10-23 stsp #include <syslog.h>
42 13b2bc37 2022-10-23 stsp #include <unistd.h>
44 13b2bc37 2022-10-23 stsp #include "got_error.h"
45 13b2bc37 2022-10-23 stsp #include "got_path.h"
47 13b2bc37 2022-10-23 stsp #include "log.h"
48 13b2bc37 2022-10-23 stsp #include "gotd.h"
50 13b2bc37 2022-10-23 stsp TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
51 13b2bc37 2022-10-23 stsp static struct file {
52 13b2bc37 2022-10-23 stsp TAILQ_ENTRY(file) entry;
53 13b2bc37 2022-10-23 stsp FILE *stream;
58 13b2bc37 2022-10-23 stsp struct file *newfile(const char *, int);
59 13b2bc37 2022-10-23 stsp static void closefile(struct file *);
60 13b2bc37 2022-10-23 stsp int check_file_secrecy(int, const char *);
61 13b2bc37 2022-10-23 stsp int yyparse(void);
62 13b2bc37 2022-10-23 stsp int yylex(void);
63 13b2bc37 2022-10-23 stsp int yyerror(const char *, ...)
64 13b2bc37 2022-10-23 stsp __attribute__((__format__ (printf, 1, 2)))
65 13b2bc37 2022-10-23 stsp __attribute__((__nonnull__ (1)));
66 13b2bc37 2022-10-23 stsp int kw_cmp(const void *, const void *);
67 13b2bc37 2022-10-23 stsp int lookup(char *);
68 13b2bc37 2022-10-23 stsp int lgetc(int);
69 13b2bc37 2022-10-23 stsp int lungetc(int);
70 13b2bc37 2022-10-23 stsp int findeol(void);
72 13b2bc37 2022-10-23 stsp TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
73 13b2bc37 2022-10-23 stsp struct sym {
74 13b2bc37 2022-10-23 stsp TAILQ_ENTRY(sym) entry;
76 13b2bc37 2022-10-23 stsp int persist;
81 13b2bc37 2022-10-23 stsp int symset(const char *, const char *, int);
82 13b2bc37 2022-10-23 stsp char *symget(const char *);
84 13b2bc37 2022-10-23 stsp static int errors;
86 13b2bc37 2022-10-23 stsp static struct gotd *gotd;
87 13b2bc37 2022-10-23 stsp static struct gotd_repo *new_repo;
88 13b2bc37 2022-10-23 stsp static struct gotd_repo *conf_new_repo(const char *);
89 13b2bc37 2022-10-23 stsp static enum gotd_procid gotd_proc_id;
91 13b2bc37 2022-10-23 stsp typedef struct {
93 13b2bc37 2022-10-23 stsp long long number;
94 13b2bc37 2022-10-23 stsp char *string;
101 0ccf3acb 2022-11-16 stsp %token PATH ERROR ON UNIX_SOCKET UNIX_GROUP USER REPOSITORY PERMIT DENY
103 13b2bc37 2022-10-23 stsp %token <v.string> STRING
104 13b2bc37 2022-10-23 stsp %token <v.number> NUMBER
105 13b2bc37 2022-10-23 stsp %type <v.number> boolean
110 13b2bc37 2022-10-23 stsp | grammar '\n'
111 13b2bc37 2022-10-23 stsp | grammar main '\n'
112 13b2bc37 2022-10-23 stsp | grammar repository '\n'
115 13b2bc37 2022-10-23 stsp boolean : STRING {
116 13b2bc37 2022-10-23 stsp if (strcasecmp($1, "1") == 0 ||
117 13b2bc37 2022-10-23 stsp strcasecmp($1, "yes") == 0 ||
118 13b2bc37 2022-10-23 stsp strcasecmp($1, "on") == 0)
120 13b2bc37 2022-10-23 stsp else if (strcasecmp($1, "0") == 0 ||
121 13b2bc37 2022-10-23 stsp strcasecmp($1, "off") == 0 ||
122 13b2bc37 2022-10-23 stsp strcasecmp($1, "no") == 0)
125 13b2bc37 2022-10-23 stsp yyerror("invalid boolean value '%s'", $1);
131 13b2bc37 2022-10-23 stsp | ON { $$ = 1; }
132 13b2bc37 2022-10-23 stsp | NUMBER { $$ = $1; }
135 13b2bc37 2022-10-23 stsp main : UNIX_SOCKET STRING {
136 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
137 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_socket_path, $2,
138 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) >=
139 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) {
140 13b2bc37 2022-10-23 stsp yyerror("%s: unix socket path too long",
148 13b2bc37 2022-10-23 stsp | UNIX_GROUP STRING {
149 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_group_name, $2,
150 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) >=
151 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) {
152 13b2bc37 2022-10-23 stsp yyerror("%s: unix group name too long",
159 13b2bc37 2022-10-23 stsp | USER STRING {
160 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->user_name, $2,
161 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) >=
162 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) {
163 13b2bc37 2022-10-23 stsp yyerror("%s: user name too long", __func__);
171 13b2bc37 2022-10-23 stsp repository : REPOSITORY STRING {
172 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
174 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(repo, &gotd->repos, entry) {
175 13b2bc37 2022-10-23 stsp if (strcmp(repo->name, $2) == 0) {
176 13b2bc37 2022-10-23 stsp yyerror("duplicate repository '%s'", $2);
182 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
183 13b2bc37 2022-10-23 stsp new_repo = conf_new_repo($2);
187 13b2bc37 2022-10-23 stsp | REPOSITORY STRING {
188 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
190 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(repo, &gotd->repos, entry) {
191 13b2bc37 2022-10-23 stsp if (strcmp(repo->name, $2) == 0) {
192 13b2bc37 2022-10-23 stsp yyerror("duplicate repository '%s'", $2);
198 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
199 13b2bc37 2022-10-23 stsp new_repo = conf_new_repo($2);
202 13b2bc37 2022-10-23 stsp } '{' optnl repoopts2 '}' {
206 13b2bc37 2022-10-23 stsp repoopts1 : PATH STRING {
207 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
208 13b2bc37 2022-10-23 stsp if (!got_path_is_absolute($2)) {
209 13b2bc37 2022-10-23 stsp yyerror("%s: path %s is not absolute",
210 13b2bc37 2022-10-23 stsp __func__, $2);
214 13b2bc37 2022-10-23 stsp if (strlcpy(new_repo->path, $2,
215 13b2bc37 2022-10-23 stsp sizeof(new_repo->path)) >=
216 13b2bc37 2022-10-23 stsp sizeof(new_repo->path)) {
217 13b2bc37 2022-10-23 stsp yyerror("%s: path truncated", __func__);
224 0ccf3acb 2022-11-16 stsp | PERMIT RO STRING {
225 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
226 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
227 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_PERMITTED, GOTD_AUTH_READ, $3);
230 0ccf3acb 2022-11-16 stsp | PERMIT RW STRING {
231 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
232 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
233 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_PERMITTED,
234 0ccf3acb 2022-11-16 stsp GOTD_AUTH_READ | GOTD_AUTH_WRITE, $3);
237 0ccf3acb 2022-11-16 stsp | DENY STRING {
238 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
239 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
240 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_DENIED, 0, $2);
245 13b2bc37 2022-10-23 stsp repoopts2 : repoopts2 repoopts1 nl
246 13b2bc37 2022-10-23 stsp | repoopts1 optnl
249 13b2bc37 2022-10-23 stsp nl : '\n' optnl
252 13b2bc37 2022-10-23 stsp optnl : '\n' optnl /* zero or more newlines */
253 13b2bc37 2022-10-23 stsp | /* empty */
258 13b2bc37 2022-10-23 stsp struct keywords {
259 13b2bc37 2022-10-23 stsp const char *k_name;
264 13b2bc37 2022-10-23 stsp yyerror(const char *fmt, ...)
266 13b2bc37 2022-10-23 stsp va_list ap;
269 13b2bc37 2022-10-23 stsp file->errors++;
270 13b2bc37 2022-10-23 stsp va_start(ap, fmt);
271 13b2bc37 2022-10-23 stsp if (vasprintf(&msg, fmt, ap) == -1)
272 13b2bc37 2022-10-23 stsp fatalx("yyerror vasprintf");
273 13b2bc37 2022-10-23 stsp va_end(ap);
274 13b2bc37 2022-10-23 stsp logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
276 13b2bc37 2022-10-23 stsp return (0);
280 13b2bc37 2022-10-23 stsp kw_cmp(const void *k, const void *e)
282 13b2bc37 2022-10-23 stsp return (strcmp(k, ((const struct keywords *)e)->k_name));
286 13b2bc37 2022-10-23 stsp lookup(char *s)
288 13b2bc37 2022-10-23 stsp /* This has to be sorted always. */
289 13b2bc37 2022-10-23 stsp static const struct keywords keywords[] = {
290 0ccf3acb 2022-11-16 stsp { "deny", DENY },
291 13b2bc37 2022-10-23 stsp { "on", ON },
292 13b2bc37 2022-10-23 stsp { "path", PATH },
293 0ccf3acb 2022-11-16 stsp { "permit", PERMIT },
294 13b2bc37 2022-10-23 stsp { "repository", REPOSITORY },
295 0ccf3acb 2022-11-16 stsp { "ro", RO },
296 0ccf3acb 2022-11-16 stsp { "rw", RW },
297 13b2bc37 2022-10-23 stsp { "unix_group", UNIX_GROUP },
298 13b2bc37 2022-10-23 stsp { "unix_socket", UNIX_SOCKET },
299 13b2bc37 2022-10-23 stsp { "user", USER },
301 13b2bc37 2022-10-23 stsp const struct keywords *p;
303 13b2bc37 2022-10-23 stsp p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
304 13b2bc37 2022-10-23 stsp sizeof(keywords[0]), kw_cmp);
307 13b2bc37 2022-10-23 stsp return (p->k_val);
309 13b2bc37 2022-10-23 stsp return (STRING);
312 13b2bc37 2022-10-23 stsp #define MAXPUSHBACK 128
314 13b2bc37 2022-10-23 stsp unsigned char *parsebuf;
315 13b2bc37 2022-10-23 stsp int parseindex;
316 13b2bc37 2022-10-23 stsp unsigned char pushback_buffer[MAXPUSHBACK];
317 13b2bc37 2022-10-23 stsp int pushback_index = 0;
320 13b2bc37 2022-10-23 stsp lgetc(int quotec)
322 13b2bc37 2022-10-23 stsp int c, next;
324 13b2bc37 2022-10-23 stsp if (parsebuf) {
325 13b2bc37 2022-10-23 stsp /* Read character from the parsebuffer instead of input. */
326 13b2bc37 2022-10-23 stsp if (parseindex >= 0) {
327 13b2bc37 2022-10-23 stsp c = parsebuf[parseindex++];
328 13b2bc37 2022-10-23 stsp if (c != '\0')
329 13b2bc37 2022-10-23 stsp return (c);
330 13b2bc37 2022-10-23 stsp parsebuf = NULL;
332 13b2bc37 2022-10-23 stsp parseindex++;
335 13b2bc37 2022-10-23 stsp if (pushback_index)
336 13b2bc37 2022-10-23 stsp return (pushback_buffer[--pushback_index]);
338 13b2bc37 2022-10-23 stsp if (quotec) {
339 13b2bc37 2022-10-23 stsp c = getc(file->stream);
340 13b2bc37 2022-10-23 stsp if (c == EOF)
341 13b2bc37 2022-10-23 stsp yyerror("reached end of file while parsing "
342 13b2bc37 2022-10-23 stsp "quoted string");
343 13b2bc37 2022-10-23 stsp return (c);
346 13b2bc37 2022-10-23 stsp c = getc(file->stream);
347 13b2bc37 2022-10-23 stsp while (c == '\\') {
348 13b2bc37 2022-10-23 stsp next = getc(file->stream);
349 13b2bc37 2022-10-23 stsp if (next != '\n') {
353 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
354 13b2bc37 2022-10-23 stsp file->lineno++;
355 13b2bc37 2022-10-23 stsp c = getc(file->stream);
358 13b2bc37 2022-10-23 stsp return (c);
362 13b2bc37 2022-10-23 stsp lungetc(int c)
364 13b2bc37 2022-10-23 stsp if (c == EOF)
365 13b2bc37 2022-10-23 stsp return (EOF);
366 13b2bc37 2022-10-23 stsp if (parsebuf) {
367 13b2bc37 2022-10-23 stsp parseindex--;
368 13b2bc37 2022-10-23 stsp if (parseindex >= 0)
369 13b2bc37 2022-10-23 stsp return (c);
371 13b2bc37 2022-10-23 stsp if (pushback_index < MAXPUSHBACK-1)
372 13b2bc37 2022-10-23 stsp return (pushback_buffer[pushback_index++] = c);
374 13b2bc37 2022-10-23 stsp return (EOF);
378 13b2bc37 2022-10-23 stsp findeol(void)
382 13b2bc37 2022-10-23 stsp parsebuf = NULL;
384 13b2bc37 2022-10-23 stsp /* Skip to either EOF or the first real EOL. */
385 13b2bc37 2022-10-23 stsp while (1) {
386 13b2bc37 2022-10-23 stsp if (pushback_index)
387 13b2bc37 2022-10-23 stsp c = pushback_buffer[--pushback_index];
389 13b2bc37 2022-10-23 stsp c = lgetc(0);
390 13b2bc37 2022-10-23 stsp if (c == '\n') {
391 13b2bc37 2022-10-23 stsp file->lineno++;
394 13b2bc37 2022-10-23 stsp if (c == EOF)
397 13b2bc37 2022-10-23 stsp return (ERROR);
401 13b2bc37 2022-10-23 stsp yylex(void)
403 13b2bc37 2022-10-23 stsp unsigned char buf[8096];
404 13b2bc37 2022-10-23 stsp unsigned char *p, *val;
405 13b2bc37 2022-10-23 stsp int quotec, next, c;
410 13b2bc37 2022-10-23 stsp c = lgetc(0);
411 13b2bc37 2022-10-23 stsp while (c == ' ' || c == '\t')
412 13b2bc37 2022-10-23 stsp c = lgetc(0); /* nothing */
414 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
415 13b2bc37 2022-10-23 stsp if (c == '#') {
416 13b2bc37 2022-10-23 stsp c = lgetc(0);
417 13b2bc37 2022-10-23 stsp while (c != '\n' && c != EOF)
418 13b2bc37 2022-10-23 stsp c = lgetc(0); /* nothing */
420 13b2bc37 2022-10-23 stsp if (c == '$' && parsebuf == NULL) {
421 13b2bc37 2022-10-23 stsp while (1) {
422 13b2bc37 2022-10-23 stsp c = lgetc(0);
423 13b2bc37 2022-10-23 stsp if (c == EOF)
424 13b2bc37 2022-10-23 stsp return (0);
426 13b2bc37 2022-10-23 stsp if (p + 1 >= buf + sizeof(buf) - 1) {
427 13b2bc37 2022-10-23 stsp yyerror("string too long");
428 13b2bc37 2022-10-23 stsp return (findeol());
430 13b2bc37 2022-10-23 stsp if (isalnum(c) || c == '_') {
435 13b2bc37 2022-10-23 stsp lungetc(c);
438 13b2bc37 2022-10-23 stsp val = symget(buf);
439 13b2bc37 2022-10-23 stsp if (val == NULL) {
440 13b2bc37 2022-10-23 stsp yyerror("macro '%s' not defined", buf);
441 13b2bc37 2022-10-23 stsp return (findeol());
443 13b2bc37 2022-10-23 stsp parsebuf = val;
444 13b2bc37 2022-10-23 stsp parseindex = 0;
448 13b2bc37 2022-10-23 stsp switch (c) {
451 13b2bc37 2022-10-23 stsp quotec = c;
452 13b2bc37 2022-10-23 stsp while (1) {
453 13b2bc37 2022-10-23 stsp c = lgetc(quotec);
454 13b2bc37 2022-10-23 stsp if (c == EOF)
455 13b2bc37 2022-10-23 stsp return (0);
456 13b2bc37 2022-10-23 stsp if (c == '\n') {
457 13b2bc37 2022-10-23 stsp file->lineno++;
459 13b2bc37 2022-10-23 stsp } else if (c == '\\') {
460 13b2bc37 2022-10-23 stsp next = lgetc(quotec);
461 13b2bc37 2022-10-23 stsp if (next == EOF)
462 13b2bc37 2022-10-23 stsp return (0);
463 13b2bc37 2022-10-23 stsp if (next == quotec || c == ' ' || c == '\t')
465 13b2bc37 2022-10-23 stsp else if (next == '\n') {
466 13b2bc37 2022-10-23 stsp file->lineno++;
469 13b2bc37 2022-10-23 stsp lungetc(next);
470 13b2bc37 2022-10-23 stsp } else if (c == quotec) {
473 13b2bc37 2022-10-23 stsp } else if (c == '\0') {
474 13b2bc37 2022-10-23 stsp yyerror("syntax error");
475 13b2bc37 2022-10-23 stsp return (findeol());
477 13b2bc37 2022-10-23 stsp if (p + 1 >= buf + sizeof(buf) - 1) {
478 13b2bc37 2022-10-23 stsp yyerror("string too long");
479 13b2bc37 2022-10-23 stsp return (findeol());
483 13b2bc37 2022-10-23 stsp yylval.v.string = strdup(buf);
484 13b2bc37 2022-10-23 stsp if (yylval.v.string == NULL)
485 13b2bc37 2022-10-23 stsp err(1, "yylex: strdup");
486 13b2bc37 2022-10-23 stsp return (STRING);
489 13b2bc37 2022-10-23 stsp #define allowed_to_end_number(x) \
490 13b2bc37 2022-10-23 stsp (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
492 13b2bc37 2022-10-23 stsp if (c == '-' || isdigit(c)) {
495 13b2bc37 2022-10-23 stsp if ((unsigned)(p-buf) >= sizeof(buf)) {
496 13b2bc37 2022-10-23 stsp yyerror("string too long");
497 13b2bc37 2022-10-23 stsp return (findeol());
499 13b2bc37 2022-10-23 stsp c = lgetc(0);
500 13b2bc37 2022-10-23 stsp } while (c != EOF && isdigit(c));
501 13b2bc37 2022-10-23 stsp lungetc(c);
502 13b2bc37 2022-10-23 stsp if (p == buf + 1 && buf[0] == '-')
503 13b2bc37 2022-10-23 stsp goto nodigits;
504 13b2bc37 2022-10-23 stsp if (c == EOF || allowed_to_end_number(c)) {
505 13b2bc37 2022-10-23 stsp const char *errstr = NULL;
508 13b2bc37 2022-10-23 stsp yylval.v.number = strtonum(buf, LLONG_MIN,
509 13b2bc37 2022-10-23 stsp LLONG_MAX, &errstr);
510 13b2bc37 2022-10-23 stsp if (errstr) {
511 13b2bc37 2022-10-23 stsp yyerror("\"%s\" invalid number: %s",
512 13b2bc37 2022-10-23 stsp buf, errstr);
513 13b2bc37 2022-10-23 stsp return (findeol());
515 13b2bc37 2022-10-23 stsp return (NUMBER);
518 13b2bc37 2022-10-23 stsp while (p > buf + 1)
519 13b2bc37 2022-10-23 stsp lungetc(*--p);
521 13b2bc37 2022-10-23 stsp if (c == '-')
522 13b2bc37 2022-10-23 stsp return (c);
526 13b2bc37 2022-10-23 stsp #define allowed_in_string(x) \
527 13b2bc37 2022-10-23 stsp (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
528 13b2bc37 2022-10-23 stsp x != '{' && x != '}' && \
529 13b2bc37 2022-10-23 stsp x != '!' && x != '=' && x != '#' && \
532 13b2bc37 2022-10-23 stsp if (isalnum(c) || c == ':' || c == '_') {
535 13b2bc37 2022-10-23 stsp if ((unsigned)(p-buf) >= sizeof(buf)) {
536 13b2bc37 2022-10-23 stsp yyerror("string too long");
537 13b2bc37 2022-10-23 stsp return (findeol());
539 13b2bc37 2022-10-23 stsp c = lgetc(0);
540 13b2bc37 2022-10-23 stsp } while (c != EOF && (allowed_in_string(c)));
541 13b2bc37 2022-10-23 stsp lungetc(c);
543 13b2bc37 2022-10-23 stsp token = lookup(buf);
544 13b2bc37 2022-10-23 stsp if (token == STRING) {
545 13b2bc37 2022-10-23 stsp yylval.v.string = strdup(buf);
546 13b2bc37 2022-10-23 stsp if (yylval.v.string == NULL)
547 13b2bc37 2022-10-23 stsp err(1, "yylex: strdup");
549 13b2bc37 2022-10-23 stsp return (token);
551 13b2bc37 2022-10-23 stsp if (c == '\n') {
552 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
553 13b2bc37 2022-10-23 stsp file->lineno++;
555 13b2bc37 2022-10-23 stsp if (c == EOF)
556 13b2bc37 2022-10-23 stsp return (0);
557 13b2bc37 2022-10-23 stsp return (c);
561 13b2bc37 2022-10-23 stsp check_file_secrecy(int fd, const char *fname)
563 13b2bc37 2022-10-23 stsp struct stat st;
565 13b2bc37 2022-10-23 stsp if (fstat(fd, &st)) {
566 13b2bc37 2022-10-23 stsp log_warn("cannot stat %s", fname);
567 13b2bc37 2022-10-23 stsp return (-1);
569 13b2bc37 2022-10-23 stsp if (st.st_uid != 0 && st.st_uid != getuid()) {
570 13b2bc37 2022-10-23 stsp log_warnx("%s: owner not root or current user", fname);
571 13b2bc37 2022-10-23 stsp return (-1);
573 13b2bc37 2022-10-23 stsp if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
574 13b2bc37 2022-10-23 stsp log_warnx("%s: group writable or world read/writable", fname);
575 13b2bc37 2022-10-23 stsp return (-1);
577 13b2bc37 2022-10-23 stsp return (0);
580 13b2bc37 2022-10-23 stsp struct file *
581 13b2bc37 2022-10-23 stsp newfile(const char *name, int secret)
583 13b2bc37 2022-10-23 stsp struct file *nfile;
585 13b2bc37 2022-10-23 stsp nfile = calloc(1, sizeof(struct file));
586 13b2bc37 2022-10-23 stsp if (nfile == NULL) {
587 13b2bc37 2022-10-23 stsp log_warn("calloc");
588 13b2bc37 2022-10-23 stsp return (NULL);
590 13b2bc37 2022-10-23 stsp nfile->name = strdup(name);
591 13b2bc37 2022-10-23 stsp if (nfile->name == NULL) {
592 13b2bc37 2022-10-23 stsp log_warn("strdup");
593 13b2bc37 2022-10-23 stsp free(nfile);
594 13b2bc37 2022-10-23 stsp return (NULL);
596 13b2bc37 2022-10-23 stsp nfile->stream = fopen(nfile->name, "r");
597 13b2bc37 2022-10-23 stsp if (nfile->stream == NULL) {
598 13b2bc37 2022-10-23 stsp /* no warning, we don't require a conf file */
599 13b2bc37 2022-10-23 stsp free(nfile->name);
600 13b2bc37 2022-10-23 stsp free(nfile);
601 13b2bc37 2022-10-23 stsp return (NULL);
602 13b2bc37 2022-10-23 stsp } else if (secret &&
603 13b2bc37 2022-10-23 stsp check_file_secrecy(fileno(nfile->stream), nfile->name)) {
604 13b2bc37 2022-10-23 stsp fclose(nfile->stream);
605 13b2bc37 2022-10-23 stsp free(nfile->name);
606 13b2bc37 2022-10-23 stsp free(nfile);
607 13b2bc37 2022-10-23 stsp return (NULL);
609 13b2bc37 2022-10-23 stsp nfile->lineno = 1;
610 13b2bc37 2022-10-23 stsp return (nfile);
613 13b2bc37 2022-10-23 stsp static void
614 13b2bc37 2022-10-23 stsp closefile(struct file *xfile)
616 13b2bc37 2022-10-23 stsp fclose(xfile->stream);
617 13b2bc37 2022-10-23 stsp free(xfile->name);
618 13b2bc37 2022-10-23 stsp free(xfile);
622 13b2bc37 2022-10-23 stsp parse_config(const char *filename, enum gotd_procid proc_id,
623 13b2bc37 2022-10-23 stsp struct gotd *env)
625 13b2bc37 2022-10-23 stsp struct sym *sym, *next;
627 13b2bc37 2022-10-23 stsp memset(env, 0, sizeof(*env));
629 13b2bc37 2022-10-23 stsp gotd = env;
630 13b2bc37 2022-10-23 stsp gotd_proc_id = proc_id;
631 13b2bc37 2022-10-23 stsp TAILQ_INIT(&gotd->repos);
633 13b2bc37 2022-10-23 stsp /* Apply default values. */
634 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_socket_path, GOTD_UNIX_SOCKET,
635 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) >= sizeof(gotd->unix_socket_path)) {
636 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: unix socket path too long", __func__);
639 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_group_name, GOTD_UNIX_GROUP,
640 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) >= sizeof(gotd->unix_group_name)) {
641 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: unix group name too long", __func__);
644 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->user_name, GOTD_USER,
645 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) >= sizeof(gotd->user_name)) {
646 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: user name too long", __func__);
650 13b2bc37 2022-10-23 stsp file = newfile(filename, 0);
651 13b2bc37 2022-10-23 stsp if (file == NULL) {
652 13b2bc37 2022-10-23 stsp /* just return, as we don't require a conf file */
653 13b2bc37 2022-10-23 stsp return (0);
657 13b2bc37 2022-10-23 stsp errors = file->errors;
658 13b2bc37 2022-10-23 stsp closefile(file);
660 13b2bc37 2022-10-23 stsp /* Free macros and check which have not been used. */
661 13b2bc37 2022-10-23 stsp TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
662 13b2bc37 2022-10-23 stsp if ((gotd->verbosity > 1) && !sym->used)
663 13b2bc37 2022-10-23 stsp fprintf(stderr, "warning: macro '%s' not used\n",
665 13b2bc37 2022-10-23 stsp if (!sym->persist) {
666 13b2bc37 2022-10-23 stsp free(sym->nam);
667 13b2bc37 2022-10-23 stsp free(sym->val);
668 13b2bc37 2022-10-23 stsp TAILQ_REMOVE(&symhead, sym, entry);
673 13b2bc37 2022-10-23 stsp if (errors)
674 13b2bc37 2022-10-23 stsp return (-1);
676 13b2bc37 2022-10-23 stsp return (0);
679 13b2bc37 2022-10-23 stsp static struct gotd_repo *
680 13b2bc37 2022-10-23 stsp conf_new_repo(const char *name)
682 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
684 13b2bc37 2022-10-23 stsp if (strchr(name, '\n') != NULL) {
685 13b2bc37 2022-10-23 stsp fatalx("%s: repository names must not contain linefeeds: %s",
686 13b2bc37 2022-10-23 stsp getprogname(), name);
689 13b2bc37 2022-10-23 stsp repo = calloc(1, sizeof(*repo));
690 13b2bc37 2022-10-23 stsp if (repo == NULL)
691 13b2bc37 2022-10-23 stsp fatalx("%s: calloc", __func__);
693 0ccf3acb 2022-11-16 stsp STAILQ_INIT(&repo->rules);
695 13b2bc37 2022-10-23 stsp if (strlcpy(repo->name, name, sizeof(repo->name)) >=
696 13b2bc37 2022-10-23 stsp sizeof(repo->name))
697 13b2bc37 2022-10-23 stsp fatalx("%s: strlcpy", __func__);
699 13b2bc37 2022-10-23 stsp TAILQ_INSERT_TAIL(&gotd->repos, repo, entry);
700 13b2bc37 2022-10-23 stsp gotd->nrepos++;
702 13b2bc37 2022-10-23 stsp return repo;
705 0ccf3acb 2022-11-16 stsp static void
706 0ccf3acb 2022-11-16 stsp conf_new_access_rule(struct gotd_repo *repo, enum gotd_access access,
707 0ccf3acb 2022-11-16 stsp int authorization, char *identifier)
709 0ccf3acb 2022-11-16 stsp struct gotd_access_rule *rule;
711 0ccf3acb 2022-11-16 stsp rule = calloc(1, sizeof(*rule));
712 0ccf3acb 2022-11-16 stsp if (rule == NULL)
713 0ccf3acb 2022-11-16 stsp fatal("calloc");
715 0ccf3acb 2022-11-16 stsp rule->access = access;
716 0ccf3acb 2022-11-16 stsp rule->authorization = authorization;
717 0ccf3acb 2022-11-16 stsp rule->identifier = identifier;
719 0ccf3acb 2022-11-16 stsp STAILQ_INSERT_TAIL(&repo->rules, rule, entry);
723 13b2bc37 2022-10-23 stsp symset(const char *nam, const char *val, int persist)
725 13b2bc37 2022-10-23 stsp struct sym *sym;
727 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(sym, &symhead, entry) {
728 13b2bc37 2022-10-23 stsp if (strcmp(nam, sym->nam) == 0)
732 13b2bc37 2022-10-23 stsp if (sym != NULL) {
733 13b2bc37 2022-10-23 stsp if (sym->persist == 1)
734 13b2bc37 2022-10-23 stsp return (0);
736 13b2bc37 2022-10-23 stsp free(sym->nam);
737 13b2bc37 2022-10-23 stsp free(sym->val);
738 13b2bc37 2022-10-23 stsp TAILQ_REMOVE(&symhead, sym, entry);
742 13b2bc37 2022-10-23 stsp sym = calloc(1, sizeof(*sym));
743 13b2bc37 2022-10-23 stsp if (sym == NULL)
744 13b2bc37 2022-10-23 stsp return (-1);
746 13b2bc37 2022-10-23 stsp sym->nam = strdup(nam);
747 13b2bc37 2022-10-23 stsp if (sym->nam == NULL) {
749 13b2bc37 2022-10-23 stsp return (-1);
751 13b2bc37 2022-10-23 stsp sym->val = strdup(val);
752 13b2bc37 2022-10-23 stsp if (sym->val == NULL) {
753 13b2bc37 2022-10-23 stsp free(sym->nam);
755 13b2bc37 2022-10-23 stsp return (-1);
757 13b2bc37 2022-10-23 stsp sym->used = 0;
758 13b2bc37 2022-10-23 stsp sym->persist = persist;
759 13b2bc37 2022-10-23 stsp TAILQ_INSERT_TAIL(&symhead, sym, entry);
760 13b2bc37 2022-10-23 stsp return (0);
764 13b2bc37 2022-10-23 stsp symget(const char *nam)
766 13b2bc37 2022-10-23 stsp struct sym *sym;
768 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(sym, &symhead, entry) {
769 13b2bc37 2022-10-23 stsp if (strcmp(nam, sym->nam) == 0) {
770 13b2bc37 2022-10-23 stsp sym->used = 1;
771 13b2bc37 2022-10-23 stsp return (sym->val);
774 13b2bc37 2022-10-23 stsp return (NULL);