2 13b2bc37 2022-10-23 stsp * Copyright (c) 2022 Stefan Sperling <stsp@openbsd.org>
3 13b2bc37 2022-10-23 stsp * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
4 13b2bc37 2022-10-23 stsp * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
5 13b2bc37 2022-10-23 stsp * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
6 13b2bc37 2022-10-23 stsp * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
7 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Markus Friedl. All rights reserved.
8 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
9 13b2bc37 2022-10-23 stsp * Copyright (c) 2001 Theo de Raadt. All rights reserved.
11 13b2bc37 2022-10-23 stsp * Permission to use, copy, modify, and distribute this software for any
12 13b2bc37 2022-10-23 stsp * purpose with or without fee is hereby granted, provided that the above
13 13b2bc37 2022-10-23 stsp * copyright notice and this permission notice appear in all copies.
15 13b2bc37 2022-10-23 stsp * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
16 13b2bc37 2022-10-23 stsp * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
17 13b2bc37 2022-10-23 stsp * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
18 13b2bc37 2022-10-23 stsp * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
19 13b2bc37 2022-10-23 stsp * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
20 13b2bc37 2022-10-23 stsp * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
21 13b2bc37 2022-10-23 stsp * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
25 13b2bc37 2022-10-23 stsp #include <sys/time.h>
26 13b2bc37 2022-10-23 stsp #include <sys/types.h>
27 13b2bc37 2022-10-23 stsp #include <sys/queue.h>
28 13b2bc37 2022-10-23 stsp #include <sys/stat.h>
30 13b2bc37 2022-10-23 stsp #include <ctype.h>
31 13b2bc37 2022-10-23 stsp #include <err.h>
32 13b2bc37 2022-10-23 stsp #include <errno.h>
33 13b2bc37 2022-10-23 stsp #include <event.h>
34 13b2bc37 2022-10-23 stsp #include <imsg.h>
35 13b2bc37 2022-10-23 stsp #include <limits.h>
36 13b2bc37 2022-10-23 stsp #include <sha1.h>
37 13b2bc37 2022-10-23 stsp #include <stdarg.h>
38 13b2bc37 2022-10-23 stsp #include <stdlib.h>
39 13b2bc37 2022-10-23 stsp #include <stdio.h>
40 13b2bc37 2022-10-23 stsp #include <string.h>
41 13b2bc37 2022-10-23 stsp #include <syslog.h>
42 13b2bc37 2022-10-23 stsp #include <unistd.h>
44 13b2bc37 2022-10-23 stsp #include "got_error.h"
45 13b2bc37 2022-10-23 stsp #include "got_path.h"
47 13b2bc37 2022-10-23 stsp #include "log.h"
48 13b2bc37 2022-10-23 stsp #include "gotd.h"
50 13b2bc37 2022-10-23 stsp TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
51 13b2bc37 2022-10-23 stsp static struct file {
52 13b2bc37 2022-10-23 stsp TAILQ_ENTRY(file) entry;
53 13b2bc37 2022-10-23 stsp FILE *stream;
58 13b2bc37 2022-10-23 stsp struct file *newfile(const char *, int);
59 13b2bc37 2022-10-23 stsp static void closefile(struct file *);
60 13b2bc37 2022-10-23 stsp int check_file_secrecy(int, const char *);
61 13b2bc37 2022-10-23 stsp int yyparse(void);
62 13b2bc37 2022-10-23 stsp int yylex(void);
63 13b2bc37 2022-10-23 stsp int yyerror(const char *, ...)
64 13b2bc37 2022-10-23 stsp __attribute__((__format__ (printf, 1, 2)))
65 13b2bc37 2022-10-23 stsp __attribute__((__nonnull__ (1)));
66 13b2bc37 2022-10-23 stsp int kw_cmp(const void *, const void *);
67 13b2bc37 2022-10-23 stsp int lookup(char *);
68 13b2bc37 2022-10-23 stsp int lgetc(int);
69 13b2bc37 2022-10-23 stsp int lungetc(int);
70 13b2bc37 2022-10-23 stsp int findeol(void);
72 13b2bc37 2022-10-23 stsp TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
73 13b2bc37 2022-10-23 stsp struct sym {
74 13b2bc37 2022-10-23 stsp TAILQ_ENTRY(sym) entry;
76 13b2bc37 2022-10-23 stsp int persist;
81 13b2bc37 2022-10-23 stsp int symset(const char *, const char *, int);
82 13b2bc37 2022-10-23 stsp char *symget(const char *);
84 13b2bc37 2022-10-23 stsp static int errors;
86 13b2bc37 2022-10-23 stsp static struct gotd *gotd;
87 13b2bc37 2022-10-23 stsp static struct gotd_repo *new_repo;
88 13b2bc37 2022-10-23 stsp static struct gotd_repo *conf_new_repo(const char *);
89 13b2bc37 2022-10-23 stsp static enum gotd_procid gotd_proc_id;
91 13b2bc37 2022-10-23 stsp typedef struct {
93 13b2bc37 2022-10-23 stsp long long number;
94 13b2bc37 2022-10-23 stsp char *string;
101 0ccf3acb 2022-11-16 stsp %token PATH ERROR ON UNIX_SOCKET UNIX_GROUP USER REPOSITORY PERMIT DENY
102 c2a4f618 2022-11-16 stsp %token RO RW
104 13b2bc37 2022-10-23 stsp %token <v.string> STRING
105 13b2bc37 2022-10-23 stsp %token <v.number> NUMBER
106 13b2bc37 2022-10-23 stsp %type <v.number> boolean
111 13b2bc37 2022-10-23 stsp | grammar '\n'
112 13b2bc37 2022-10-23 stsp | grammar main '\n'
113 13b2bc37 2022-10-23 stsp | grammar repository '\n'
116 13b2bc37 2022-10-23 stsp boolean : STRING {
117 13b2bc37 2022-10-23 stsp if (strcasecmp($1, "1") == 0 ||
118 13b2bc37 2022-10-23 stsp strcasecmp($1, "yes") == 0 ||
119 13b2bc37 2022-10-23 stsp strcasecmp($1, "on") == 0)
121 13b2bc37 2022-10-23 stsp else if (strcasecmp($1, "0") == 0 ||
122 13b2bc37 2022-10-23 stsp strcasecmp($1, "off") == 0 ||
123 13b2bc37 2022-10-23 stsp strcasecmp($1, "no") == 0)
126 13b2bc37 2022-10-23 stsp yyerror("invalid boolean value '%s'", $1);
132 13b2bc37 2022-10-23 stsp | ON { $$ = 1; }
133 13b2bc37 2022-10-23 stsp | NUMBER { $$ = $1; }
136 13b2bc37 2022-10-23 stsp main : UNIX_SOCKET STRING {
137 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
138 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_socket_path, $2,
139 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) >=
140 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) {
141 13b2bc37 2022-10-23 stsp yyerror("%s: unix socket path too long",
149 13b2bc37 2022-10-23 stsp | UNIX_GROUP STRING {
150 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_group_name, $2,
151 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) >=
152 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) {
153 13b2bc37 2022-10-23 stsp yyerror("%s: unix group name too long",
160 13b2bc37 2022-10-23 stsp | USER STRING {
161 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->user_name, $2,
162 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) >=
163 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) {
164 13b2bc37 2022-10-23 stsp yyerror("%s: user name too long", __func__);
172 13b2bc37 2022-10-23 stsp repository : REPOSITORY STRING {
173 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
175 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(repo, &gotd->repos, entry) {
176 13b2bc37 2022-10-23 stsp if (strcmp(repo->name, $2) == 0) {
177 13b2bc37 2022-10-23 stsp yyerror("duplicate repository '%s'", $2);
183 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
184 13b2bc37 2022-10-23 stsp new_repo = conf_new_repo($2);
188 13b2bc37 2022-10-23 stsp | REPOSITORY STRING {
189 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
191 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(repo, &gotd->repos, entry) {
192 13b2bc37 2022-10-23 stsp if (strcmp(repo->name, $2) == 0) {
193 13b2bc37 2022-10-23 stsp yyerror("duplicate repository '%s'", $2);
199 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
200 13b2bc37 2022-10-23 stsp new_repo = conf_new_repo($2);
203 13b2bc37 2022-10-23 stsp } '{' optnl repoopts2 '}' {
207 13b2bc37 2022-10-23 stsp repoopts1 : PATH STRING {
208 13b2bc37 2022-10-23 stsp if (gotd_proc_id == PROC_GOTD) {
209 13b2bc37 2022-10-23 stsp if (!got_path_is_absolute($2)) {
210 13b2bc37 2022-10-23 stsp yyerror("%s: path %s is not absolute",
211 13b2bc37 2022-10-23 stsp __func__, $2);
215 13b2bc37 2022-10-23 stsp if (strlcpy(new_repo->path, $2,
216 13b2bc37 2022-10-23 stsp sizeof(new_repo->path)) >=
217 13b2bc37 2022-10-23 stsp sizeof(new_repo->path)) {
218 13b2bc37 2022-10-23 stsp yyerror("%s: path truncated", __func__);
225 0ccf3acb 2022-11-16 stsp | PERMIT RO STRING {
226 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
227 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
228 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_PERMITTED, GOTD_AUTH_READ, $3);
231 0ccf3acb 2022-11-16 stsp | PERMIT RW STRING {
232 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
233 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
234 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_PERMITTED,
235 0ccf3acb 2022-11-16 stsp GOTD_AUTH_READ | GOTD_AUTH_WRITE, $3);
238 0ccf3acb 2022-11-16 stsp | DENY STRING {
239 0ccf3acb 2022-11-16 stsp if (gotd_proc_id == PROC_GOTD) {
240 0ccf3acb 2022-11-16 stsp conf_new_access_rule(new_repo,
241 0ccf3acb 2022-11-16 stsp GOTD_ACCESS_DENIED, 0, $2);
246 13b2bc37 2022-10-23 stsp repoopts2 : repoopts2 repoopts1 nl
247 13b2bc37 2022-10-23 stsp | repoopts1 optnl
250 13b2bc37 2022-10-23 stsp nl : '\n' optnl
253 13b2bc37 2022-10-23 stsp optnl : '\n' optnl /* zero or more newlines */
254 13b2bc37 2022-10-23 stsp | /* empty */
259 13b2bc37 2022-10-23 stsp struct keywords {
260 13b2bc37 2022-10-23 stsp const char *k_name;
265 13b2bc37 2022-10-23 stsp yyerror(const char *fmt, ...)
267 13b2bc37 2022-10-23 stsp va_list ap;
270 13b2bc37 2022-10-23 stsp file->errors++;
271 13b2bc37 2022-10-23 stsp va_start(ap, fmt);
272 13b2bc37 2022-10-23 stsp if (vasprintf(&msg, fmt, ap) == -1)
273 13b2bc37 2022-10-23 stsp fatalx("yyerror vasprintf");
274 13b2bc37 2022-10-23 stsp va_end(ap);
275 13b2bc37 2022-10-23 stsp logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
277 13b2bc37 2022-10-23 stsp return (0);
281 13b2bc37 2022-10-23 stsp kw_cmp(const void *k, const void *e)
283 13b2bc37 2022-10-23 stsp return (strcmp(k, ((const struct keywords *)e)->k_name));
287 13b2bc37 2022-10-23 stsp lookup(char *s)
289 13b2bc37 2022-10-23 stsp /* This has to be sorted always. */
290 13b2bc37 2022-10-23 stsp static const struct keywords keywords[] = {
291 0ccf3acb 2022-11-16 stsp { "deny", DENY },
292 13b2bc37 2022-10-23 stsp { "on", ON },
293 13b2bc37 2022-10-23 stsp { "path", PATH },
294 0ccf3acb 2022-11-16 stsp { "permit", PERMIT },
295 13b2bc37 2022-10-23 stsp { "repository", REPOSITORY },
296 0ccf3acb 2022-11-16 stsp { "ro", RO },
297 0ccf3acb 2022-11-16 stsp { "rw", RW },
298 13b2bc37 2022-10-23 stsp { "unix_group", UNIX_GROUP },
299 13b2bc37 2022-10-23 stsp { "unix_socket", UNIX_SOCKET },
300 13b2bc37 2022-10-23 stsp { "user", USER },
302 13b2bc37 2022-10-23 stsp const struct keywords *p;
304 13b2bc37 2022-10-23 stsp p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
305 13b2bc37 2022-10-23 stsp sizeof(keywords[0]), kw_cmp);
308 13b2bc37 2022-10-23 stsp return (p->k_val);
310 13b2bc37 2022-10-23 stsp return (STRING);
313 13b2bc37 2022-10-23 stsp #define MAXPUSHBACK 128
315 13b2bc37 2022-10-23 stsp unsigned char *parsebuf;
316 13b2bc37 2022-10-23 stsp int parseindex;
317 13b2bc37 2022-10-23 stsp unsigned char pushback_buffer[MAXPUSHBACK];
318 13b2bc37 2022-10-23 stsp int pushback_index = 0;
321 13b2bc37 2022-10-23 stsp lgetc(int quotec)
323 13b2bc37 2022-10-23 stsp int c, next;
325 13b2bc37 2022-10-23 stsp if (parsebuf) {
326 13b2bc37 2022-10-23 stsp /* Read character from the parsebuffer instead of input. */
327 13b2bc37 2022-10-23 stsp if (parseindex >= 0) {
328 13b2bc37 2022-10-23 stsp c = parsebuf[parseindex++];
329 13b2bc37 2022-10-23 stsp if (c != '\0')
330 13b2bc37 2022-10-23 stsp return (c);
331 13b2bc37 2022-10-23 stsp parsebuf = NULL;
333 13b2bc37 2022-10-23 stsp parseindex++;
336 13b2bc37 2022-10-23 stsp if (pushback_index)
337 13b2bc37 2022-10-23 stsp return (pushback_buffer[--pushback_index]);
339 13b2bc37 2022-10-23 stsp if (quotec) {
340 13b2bc37 2022-10-23 stsp c = getc(file->stream);
341 13b2bc37 2022-10-23 stsp if (c == EOF)
342 13b2bc37 2022-10-23 stsp yyerror("reached end of file while parsing "
343 13b2bc37 2022-10-23 stsp "quoted string");
344 13b2bc37 2022-10-23 stsp return (c);
347 13b2bc37 2022-10-23 stsp c = getc(file->stream);
348 13b2bc37 2022-10-23 stsp while (c == '\\') {
349 13b2bc37 2022-10-23 stsp next = getc(file->stream);
350 13b2bc37 2022-10-23 stsp if (next != '\n') {
354 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
355 13b2bc37 2022-10-23 stsp file->lineno++;
356 13b2bc37 2022-10-23 stsp c = getc(file->stream);
359 13b2bc37 2022-10-23 stsp return (c);
363 13b2bc37 2022-10-23 stsp lungetc(int c)
365 13b2bc37 2022-10-23 stsp if (c == EOF)
366 13b2bc37 2022-10-23 stsp return (EOF);
367 13b2bc37 2022-10-23 stsp if (parsebuf) {
368 13b2bc37 2022-10-23 stsp parseindex--;
369 13b2bc37 2022-10-23 stsp if (parseindex >= 0)
370 13b2bc37 2022-10-23 stsp return (c);
372 13b2bc37 2022-10-23 stsp if (pushback_index < MAXPUSHBACK-1)
373 13b2bc37 2022-10-23 stsp return (pushback_buffer[pushback_index++] = c);
375 13b2bc37 2022-10-23 stsp return (EOF);
379 13b2bc37 2022-10-23 stsp findeol(void)
383 13b2bc37 2022-10-23 stsp parsebuf = NULL;
385 13b2bc37 2022-10-23 stsp /* Skip to either EOF or the first real EOL. */
386 13b2bc37 2022-10-23 stsp while (1) {
387 13b2bc37 2022-10-23 stsp if (pushback_index)
388 13b2bc37 2022-10-23 stsp c = pushback_buffer[--pushback_index];
390 13b2bc37 2022-10-23 stsp c = lgetc(0);
391 13b2bc37 2022-10-23 stsp if (c == '\n') {
392 13b2bc37 2022-10-23 stsp file->lineno++;
395 13b2bc37 2022-10-23 stsp if (c == EOF)
398 13b2bc37 2022-10-23 stsp return (ERROR);
402 13b2bc37 2022-10-23 stsp yylex(void)
404 13b2bc37 2022-10-23 stsp unsigned char buf[8096];
405 13b2bc37 2022-10-23 stsp unsigned char *p, *val;
406 13b2bc37 2022-10-23 stsp int quotec, next, c;
411 13b2bc37 2022-10-23 stsp c = lgetc(0);
412 13b2bc37 2022-10-23 stsp while (c == ' ' || c == '\t')
413 13b2bc37 2022-10-23 stsp c = lgetc(0); /* nothing */
415 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
416 13b2bc37 2022-10-23 stsp if (c == '#') {
417 13b2bc37 2022-10-23 stsp c = lgetc(0);
418 13b2bc37 2022-10-23 stsp while (c != '\n' && c != EOF)
419 13b2bc37 2022-10-23 stsp c = lgetc(0); /* nothing */
421 13b2bc37 2022-10-23 stsp if (c == '$' && parsebuf == NULL) {
422 13b2bc37 2022-10-23 stsp while (1) {
423 13b2bc37 2022-10-23 stsp c = lgetc(0);
424 13b2bc37 2022-10-23 stsp if (c == EOF)
425 13b2bc37 2022-10-23 stsp return (0);
427 13b2bc37 2022-10-23 stsp if (p + 1 >= buf + sizeof(buf) - 1) {
428 13b2bc37 2022-10-23 stsp yyerror("string too long");
429 13b2bc37 2022-10-23 stsp return (findeol());
431 13b2bc37 2022-10-23 stsp if (isalnum(c) || c == '_') {
436 13b2bc37 2022-10-23 stsp lungetc(c);
439 13b2bc37 2022-10-23 stsp val = symget(buf);
440 13b2bc37 2022-10-23 stsp if (val == NULL) {
441 13b2bc37 2022-10-23 stsp yyerror("macro '%s' not defined", buf);
442 13b2bc37 2022-10-23 stsp return (findeol());
444 13b2bc37 2022-10-23 stsp parsebuf = val;
445 13b2bc37 2022-10-23 stsp parseindex = 0;
449 13b2bc37 2022-10-23 stsp switch (c) {
452 13b2bc37 2022-10-23 stsp quotec = c;
453 13b2bc37 2022-10-23 stsp while (1) {
454 13b2bc37 2022-10-23 stsp c = lgetc(quotec);
455 13b2bc37 2022-10-23 stsp if (c == EOF)
456 13b2bc37 2022-10-23 stsp return (0);
457 13b2bc37 2022-10-23 stsp if (c == '\n') {
458 13b2bc37 2022-10-23 stsp file->lineno++;
460 13b2bc37 2022-10-23 stsp } else if (c == '\\') {
461 13b2bc37 2022-10-23 stsp next = lgetc(quotec);
462 13b2bc37 2022-10-23 stsp if (next == EOF)
463 13b2bc37 2022-10-23 stsp return (0);
464 13b2bc37 2022-10-23 stsp if (next == quotec || c == ' ' || c == '\t')
466 13b2bc37 2022-10-23 stsp else if (next == '\n') {
467 13b2bc37 2022-10-23 stsp file->lineno++;
470 13b2bc37 2022-10-23 stsp lungetc(next);
471 13b2bc37 2022-10-23 stsp } else if (c == quotec) {
474 13b2bc37 2022-10-23 stsp } else if (c == '\0') {
475 13b2bc37 2022-10-23 stsp yyerror("syntax error");
476 13b2bc37 2022-10-23 stsp return (findeol());
478 13b2bc37 2022-10-23 stsp if (p + 1 >= buf + sizeof(buf) - 1) {
479 13b2bc37 2022-10-23 stsp yyerror("string too long");
480 13b2bc37 2022-10-23 stsp return (findeol());
484 13b2bc37 2022-10-23 stsp yylval.v.string = strdup(buf);
485 13b2bc37 2022-10-23 stsp if (yylval.v.string == NULL)
486 13b2bc37 2022-10-23 stsp err(1, "yylex: strdup");
487 13b2bc37 2022-10-23 stsp return (STRING);
490 13b2bc37 2022-10-23 stsp #define allowed_to_end_number(x) \
491 13b2bc37 2022-10-23 stsp (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
493 13b2bc37 2022-10-23 stsp if (c == '-' || isdigit(c)) {
496 13b2bc37 2022-10-23 stsp if ((unsigned)(p-buf) >= sizeof(buf)) {
497 13b2bc37 2022-10-23 stsp yyerror("string too long");
498 13b2bc37 2022-10-23 stsp return (findeol());
500 13b2bc37 2022-10-23 stsp c = lgetc(0);
501 13b2bc37 2022-10-23 stsp } while (c != EOF && isdigit(c));
502 13b2bc37 2022-10-23 stsp lungetc(c);
503 13b2bc37 2022-10-23 stsp if (p == buf + 1 && buf[0] == '-')
504 13b2bc37 2022-10-23 stsp goto nodigits;
505 13b2bc37 2022-10-23 stsp if (c == EOF || allowed_to_end_number(c)) {
506 13b2bc37 2022-10-23 stsp const char *errstr = NULL;
509 13b2bc37 2022-10-23 stsp yylval.v.number = strtonum(buf, LLONG_MIN,
510 13b2bc37 2022-10-23 stsp LLONG_MAX, &errstr);
511 13b2bc37 2022-10-23 stsp if (errstr) {
512 13b2bc37 2022-10-23 stsp yyerror("\"%s\" invalid number: %s",
513 13b2bc37 2022-10-23 stsp buf, errstr);
514 13b2bc37 2022-10-23 stsp return (findeol());
516 13b2bc37 2022-10-23 stsp return (NUMBER);
519 13b2bc37 2022-10-23 stsp while (p > buf + 1)
520 13b2bc37 2022-10-23 stsp lungetc(*--p);
522 13b2bc37 2022-10-23 stsp if (c == '-')
523 13b2bc37 2022-10-23 stsp return (c);
527 13b2bc37 2022-10-23 stsp #define allowed_in_string(x) \
528 13b2bc37 2022-10-23 stsp (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
529 13b2bc37 2022-10-23 stsp x != '{' && x != '}' && \
530 13b2bc37 2022-10-23 stsp x != '!' && x != '=' && x != '#' && \
533 13b2bc37 2022-10-23 stsp if (isalnum(c) || c == ':' || c == '_') {
536 13b2bc37 2022-10-23 stsp if ((unsigned)(p-buf) >= sizeof(buf)) {
537 13b2bc37 2022-10-23 stsp yyerror("string too long");
538 13b2bc37 2022-10-23 stsp return (findeol());
540 13b2bc37 2022-10-23 stsp c = lgetc(0);
541 13b2bc37 2022-10-23 stsp } while (c != EOF && (allowed_in_string(c)));
542 13b2bc37 2022-10-23 stsp lungetc(c);
544 13b2bc37 2022-10-23 stsp token = lookup(buf);
545 13b2bc37 2022-10-23 stsp if (token == STRING) {
546 13b2bc37 2022-10-23 stsp yylval.v.string = strdup(buf);
547 13b2bc37 2022-10-23 stsp if (yylval.v.string == NULL)
548 13b2bc37 2022-10-23 stsp err(1, "yylex: strdup");
550 13b2bc37 2022-10-23 stsp return (token);
552 13b2bc37 2022-10-23 stsp if (c == '\n') {
553 13b2bc37 2022-10-23 stsp yylval.lineno = file->lineno;
554 13b2bc37 2022-10-23 stsp file->lineno++;
556 13b2bc37 2022-10-23 stsp if (c == EOF)
557 13b2bc37 2022-10-23 stsp return (0);
558 13b2bc37 2022-10-23 stsp return (c);
562 13b2bc37 2022-10-23 stsp check_file_secrecy(int fd, const char *fname)
564 13b2bc37 2022-10-23 stsp struct stat st;
566 13b2bc37 2022-10-23 stsp if (fstat(fd, &st)) {
567 13b2bc37 2022-10-23 stsp log_warn("cannot stat %s", fname);
568 13b2bc37 2022-10-23 stsp return (-1);
570 13b2bc37 2022-10-23 stsp if (st.st_uid != 0 && st.st_uid != getuid()) {
571 13b2bc37 2022-10-23 stsp log_warnx("%s: owner not root or current user", fname);
572 13b2bc37 2022-10-23 stsp return (-1);
574 13b2bc37 2022-10-23 stsp if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
575 13b2bc37 2022-10-23 stsp log_warnx("%s: group writable or world read/writable", fname);
576 13b2bc37 2022-10-23 stsp return (-1);
578 13b2bc37 2022-10-23 stsp return (0);
581 13b2bc37 2022-10-23 stsp struct file *
582 13b2bc37 2022-10-23 stsp newfile(const char *name, int secret)
584 13b2bc37 2022-10-23 stsp struct file *nfile;
586 13b2bc37 2022-10-23 stsp nfile = calloc(1, sizeof(struct file));
587 13b2bc37 2022-10-23 stsp if (nfile == NULL) {
588 13b2bc37 2022-10-23 stsp log_warn("calloc");
589 13b2bc37 2022-10-23 stsp return (NULL);
591 13b2bc37 2022-10-23 stsp nfile->name = strdup(name);
592 13b2bc37 2022-10-23 stsp if (nfile->name == NULL) {
593 13b2bc37 2022-10-23 stsp log_warn("strdup");
594 13b2bc37 2022-10-23 stsp free(nfile);
595 13b2bc37 2022-10-23 stsp return (NULL);
597 13b2bc37 2022-10-23 stsp nfile->stream = fopen(nfile->name, "r");
598 13b2bc37 2022-10-23 stsp if (nfile->stream == NULL) {
599 13b2bc37 2022-10-23 stsp /* no warning, we don't require a conf file */
600 13b2bc37 2022-10-23 stsp free(nfile->name);
601 13b2bc37 2022-10-23 stsp free(nfile);
602 13b2bc37 2022-10-23 stsp return (NULL);
603 13b2bc37 2022-10-23 stsp } else if (secret &&
604 13b2bc37 2022-10-23 stsp check_file_secrecy(fileno(nfile->stream), nfile->name)) {
605 13b2bc37 2022-10-23 stsp fclose(nfile->stream);
606 13b2bc37 2022-10-23 stsp free(nfile->name);
607 13b2bc37 2022-10-23 stsp free(nfile);
608 13b2bc37 2022-10-23 stsp return (NULL);
610 13b2bc37 2022-10-23 stsp nfile->lineno = 1;
611 13b2bc37 2022-10-23 stsp return (nfile);
614 13b2bc37 2022-10-23 stsp static void
615 13b2bc37 2022-10-23 stsp closefile(struct file *xfile)
617 13b2bc37 2022-10-23 stsp fclose(xfile->stream);
618 13b2bc37 2022-10-23 stsp free(xfile->name);
619 13b2bc37 2022-10-23 stsp free(xfile);
623 13b2bc37 2022-10-23 stsp parse_config(const char *filename, enum gotd_procid proc_id,
624 13b2bc37 2022-10-23 stsp struct gotd *env)
626 13b2bc37 2022-10-23 stsp struct sym *sym, *next;
628 13b2bc37 2022-10-23 stsp memset(env, 0, sizeof(*env));
630 13b2bc37 2022-10-23 stsp gotd = env;
631 13b2bc37 2022-10-23 stsp gotd_proc_id = proc_id;
632 13b2bc37 2022-10-23 stsp TAILQ_INIT(&gotd->repos);
634 13b2bc37 2022-10-23 stsp /* Apply default values. */
635 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_socket_path, GOTD_UNIX_SOCKET,
636 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_socket_path)) >= sizeof(gotd->unix_socket_path)) {
637 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: unix socket path too long", __func__);
640 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->unix_group_name, GOTD_UNIX_GROUP,
641 13b2bc37 2022-10-23 stsp sizeof(gotd->unix_group_name)) >= sizeof(gotd->unix_group_name)) {
642 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: unix group name too long", __func__);
645 13b2bc37 2022-10-23 stsp if (strlcpy(gotd->user_name, GOTD_USER,
646 13b2bc37 2022-10-23 stsp sizeof(gotd->user_name)) >= sizeof(gotd->user_name)) {
647 13b2bc37 2022-10-23 stsp fprintf(stderr, "%s: user name too long", __func__);
651 13b2bc37 2022-10-23 stsp file = newfile(filename, 0);
652 13b2bc37 2022-10-23 stsp if (file == NULL) {
653 13b2bc37 2022-10-23 stsp /* just return, as we don't require a conf file */
654 13b2bc37 2022-10-23 stsp return (0);
658 13b2bc37 2022-10-23 stsp errors = file->errors;
659 13b2bc37 2022-10-23 stsp closefile(file);
661 13b2bc37 2022-10-23 stsp /* Free macros and check which have not been used. */
662 13b2bc37 2022-10-23 stsp TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
663 13b2bc37 2022-10-23 stsp if ((gotd->verbosity > 1) && !sym->used)
664 13b2bc37 2022-10-23 stsp fprintf(stderr, "warning: macro '%s' not used\n",
666 13b2bc37 2022-10-23 stsp if (!sym->persist) {
667 13b2bc37 2022-10-23 stsp free(sym->nam);
668 13b2bc37 2022-10-23 stsp free(sym->val);
669 13b2bc37 2022-10-23 stsp TAILQ_REMOVE(&symhead, sym, entry);
674 13b2bc37 2022-10-23 stsp if (errors)
675 13b2bc37 2022-10-23 stsp return (-1);
677 13b2bc37 2022-10-23 stsp return (0);
680 13b2bc37 2022-10-23 stsp static struct gotd_repo *
681 13b2bc37 2022-10-23 stsp conf_new_repo(const char *name)
683 13b2bc37 2022-10-23 stsp struct gotd_repo *repo;
685 13b2bc37 2022-10-23 stsp if (strchr(name, '\n') != NULL) {
686 13b2bc37 2022-10-23 stsp fatalx("%s: repository names must not contain linefeeds: %s",
687 13b2bc37 2022-10-23 stsp getprogname(), name);
690 13b2bc37 2022-10-23 stsp repo = calloc(1, sizeof(*repo));
691 13b2bc37 2022-10-23 stsp if (repo == NULL)
692 13b2bc37 2022-10-23 stsp fatalx("%s: calloc", __func__);
694 0ccf3acb 2022-11-16 stsp STAILQ_INIT(&repo->rules);
696 13b2bc37 2022-10-23 stsp if (strlcpy(repo->name, name, sizeof(repo->name)) >=
697 13b2bc37 2022-10-23 stsp sizeof(repo->name))
698 13b2bc37 2022-10-23 stsp fatalx("%s: strlcpy", __func__);
700 13b2bc37 2022-10-23 stsp TAILQ_INSERT_TAIL(&gotd->repos, repo, entry);
701 13b2bc37 2022-10-23 stsp gotd->nrepos++;
703 13b2bc37 2022-10-23 stsp return repo;
706 0ccf3acb 2022-11-16 stsp static void
707 0ccf3acb 2022-11-16 stsp conf_new_access_rule(struct gotd_repo *repo, enum gotd_access access,
708 0ccf3acb 2022-11-16 stsp int authorization, char *identifier)
710 0ccf3acb 2022-11-16 stsp struct gotd_access_rule *rule;
712 0ccf3acb 2022-11-16 stsp rule = calloc(1, sizeof(*rule));
713 0ccf3acb 2022-11-16 stsp if (rule == NULL)
714 0ccf3acb 2022-11-16 stsp fatal("calloc");
716 0ccf3acb 2022-11-16 stsp rule->access = access;
717 0ccf3acb 2022-11-16 stsp rule->authorization = authorization;
718 0ccf3acb 2022-11-16 stsp rule->identifier = identifier;
720 0ccf3acb 2022-11-16 stsp STAILQ_INSERT_TAIL(&repo->rules, rule, entry);
724 13b2bc37 2022-10-23 stsp symset(const char *nam, const char *val, int persist)
726 13b2bc37 2022-10-23 stsp struct sym *sym;
728 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(sym, &symhead, entry) {
729 13b2bc37 2022-10-23 stsp if (strcmp(nam, sym->nam) == 0)
733 13b2bc37 2022-10-23 stsp if (sym != NULL) {
734 13b2bc37 2022-10-23 stsp if (sym->persist == 1)
735 13b2bc37 2022-10-23 stsp return (0);
737 13b2bc37 2022-10-23 stsp free(sym->nam);
738 13b2bc37 2022-10-23 stsp free(sym->val);
739 13b2bc37 2022-10-23 stsp TAILQ_REMOVE(&symhead, sym, entry);
743 13b2bc37 2022-10-23 stsp sym = calloc(1, sizeof(*sym));
744 13b2bc37 2022-10-23 stsp if (sym == NULL)
745 13b2bc37 2022-10-23 stsp return (-1);
747 13b2bc37 2022-10-23 stsp sym->nam = strdup(nam);
748 13b2bc37 2022-10-23 stsp if (sym->nam == NULL) {
750 13b2bc37 2022-10-23 stsp return (-1);
752 13b2bc37 2022-10-23 stsp sym->val = strdup(val);
753 13b2bc37 2022-10-23 stsp if (sym->val == NULL) {
754 13b2bc37 2022-10-23 stsp free(sym->nam);
756 13b2bc37 2022-10-23 stsp return (-1);
758 13b2bc37 2022-10-23 stsp sym->used = 0;
759 13b2bc37 2022-10-23 stsp sym->persist = persist;
760 13b2bc37 2022-10-23 stsp TAILQ_INSERT_TAIL(&symhead, sym, entry);
761 13b2bc37 2022-10-23 stsp return (0);
765 13b2bc37 2022-10-23 stsp symget(const char *nam)
767 13b2bc37 2022-10-23 stsp struct sym *sym;
769 13b2bc37 2022-10-23 stsp TAILQ_FOREACH(sym, &symhead, entry) {
770 13b2bc37 2022-10-23 stsp if (strcmp(nam, sym->nam) == 0) {
771 13b2bc37 2022-10-23 stsp sym->used = 1;
772 13b2bc37 2022-10-23 stsp return (sym->val);
775 13b2bc37 2022-10-23 stsp return (NULL);