2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
32 #include <netinet/in.h>
34 #include <arpa/inet.h>
51 #include "got_reference.h"
55 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
57 TAILQ_ENTRY(file) entry;
63 struct file *newfile(const char *, int);
64 static void closefile(struct file *);
65 int check_file_secrecy(int, const char *);
68 int yyerror(const char *, ...)
69 __attribute__((__format__ (printf, 1, 2)))
70 __attribute__((__nonnull__ (1)));
71 int kw_cmp(const void *, const void *);
77 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
79 TAILQ_ENTRY(sym) entry;
86 int symset(const char *, const char *, int);
87 char *symget(const char *);
91 static struct gotwebd *gotwebd;
92 static struct server *new_srv;
93 static struct server *conf_new_server(const char *);
94 int getservice(const char *);
97 int get_addrs(const char *, const char *, struct server *);
98 int get_unix_addr(const char *, struct server *);
99 int addr_dup_check(struct addresslist *, struct address *);
100 int add_addr(struct server *, struct address *);
112 %token LISTEN WWW_PATH SITE_NAME SITE_OWNER SITE_LINK LOGO
113 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
114 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
115 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
116 %token UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
117 %token SUMMARY_COMMITS_DISPLAY SUMMARY_TAGS_DISPLAY
119 %token <v.string> STRING
120 %token <v.number> NUMBER
121 %type <v.number> boolean
122 %type <v.string> listen_addr
126 grammar : /* empty */
128 | grammar varset '\n'
130 | grammar server '\n'
131 | grammar error '\n' { file->errors++; }
134 varset : STRING '=' STRING {
137 if (isspace((unsigned char)*s)) {
138 yyerror("macro name cannot contain "
145 if (symset($1, $3, 0) == -1)
146 fatal("cannot store variable");
153 if (strcasecmp($1, "1") == 0 ||
154 strcasecmp($1, "on") == 0)
156 else if (strcasecmp($1, "0") == 0 ||
157 strcasecmp($1, "off") == 0)
160 yyerror("invalid boolean value '%s'", $1);
168 if ($1 != 0 && $1 != 1) {
169 yyerror("invalid boolean value '%lld'", $1);
176 listen_addr : '*' { $$ = NULL; }
180 main : PREFORK NUMBER {
181 if ($2 <= 0 || $2 > PROC_MAX_INSTANCES) {
182 yyerror("prefork is %s: %lld",
183 $2 <= 0 ? "too small" : "too large", $2);
186 gotwebd->prefork_gotwebd = $2;
190 yyerror("chroot path can't be an empty"
196 n = strlcpy(gotwebd->httpd_chroot, $2,
197 sizeof(gotwebd->httpd_chroot));
198 if (n >= sizeof(gotwebd->httpd_chroot)) {
199 yyerror("%s: httpd_chroot truncated", __func__);
205 | UNIX_SOCKET_NAME STRING {
206 n = snprintf(gotwebd->unix_socket_name,
207 sizeof(gotwebd->unix_socket_name), "%s%s",
208 gotwebd->httpd_chroot, $2);
210 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
211 yyerror("%s: unix_socket_name truncated",
220 server : SERVER STRING {
223 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
224 if (strcmp(srv->name, $2) == 0) {
225 yyerror("server name exists '%s'", $2);
231 new_srv = conf_new_server($2);
232 log_debug("adding server %s", $2);
238 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
239 if (strcmp(srv->name, $2) == 0) {
240 yyerror("server name exists '%s'", $2);
246 new_srv = conf_new_server($2);
247 log_debug("adding server %s", $2);
249 } '{' optnl serveropts2 '}' {
253 serveropts1 : REPOS_PATH STRING {
254 n = strlcpy(new_srv->repos_path, $2,
255 sizeof(new_srv->repos_path));
256 if (n >= sizeof(new_srv->repos_path)) {
257 yyerror("%s: repos_path truncated", __func__);
264 n = strlcpy(new_srv->site_name, $2,
265 sizeof(new_srv->site_name));
266 if (n >= sizeof(new_srv->site_name)) {
267 yyerror("%s: site_name truncated", __func__);
273 | SITE_OWNER STRING {
274 n = strlcpy(new_srv->site_owner, $2,
275 sizeof(new_srv->site_owner));
276 if (n >= sizeof(new_srv->site_owner)) {
277 yyerror("%s: site_owner truncated", __func__);
284 n = strlcpy(new_srv->site_link, $2,
285 sizeof(new_srv->site_link));
286 if (n >= sizeof(new_srv->site_link)) {
287 yyerror("%s: site_link truncated", __func__);
294 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
295 if (n >= sizeof(new_srv->logo)) {
296 yyerror("%s: logo truncated", __func__);
303 n = strlcpy(new_srv->logo_url, $2,
304 sizeof(new_srv->logo_url));
305 if (n >= sizeof(new_srv->logo_url)) {
306 yyerror("%s: logo_url truncated", __func__);
312 | CUSTOM_CSS STRING {
313 n = strlcpy(new_srv->custom_css, $2,
314 sizeof(new_srv->custom_css));
315 if (n >= sizeof(new_srv->custom_css)) {
316 yyerror("%s: custom_css truncated", __func__);
322 | LISTEN ON listen_addr PORT STRING {
323 if (get_addrs($3, $5, new_srv) == -1) {
324 yyerror("could not get addrs");
330 | LISTEN ON listen_addr PORT NUMBER {
334 n = snprintf(portno, sizeof(portno), "%lld",
336 if (n < 0 || (size_t)n >= sizeof(portno))
337 fatalx("port number too long: %lld",
340 if (get_addrs($3, portno, new_srv) == -1) {
341 yyerror("could not get addrs");
346 | LISTEN ON SOCKET STRING {
347 if (get_unix_addr($4, new_srv) == -1) {
348 yyerror("can't listen on %s", $4);
354 | SHOW_SITE_OWNER boolean {
355 new_srv->show_site_owner = $2;
357 | SHOW_REPO_OWNER boolean {
358 new_srv->show_repo_owner = $2;
360 | SHOW_REPO_AGE boolean {
361 new_srv->show_repo_age = $2;
363 | SHOW_REPO_DESCRIPTION boolean {
364 new_srv->show_repo_description = $2;
366 | SHOW_REPO_CLONEURL boolean {
367 new_srv->show_repo_cloneurl = $2;
369 | RESPECT_EXPORTOK boolean {
370 new_srv->respect_exportok = $2;
372 | MAX_REPOS_DISPLAY NUMBER {
374 yyerror("max_repos_display is too small: %lld",
378 new_srv->max_repos_display = $2;
380 | MAX_COMMITS_DISPLAY NUMBER {
382 yyerror("max_commits_display is too small:"
386 new_srv->max_commits_display = $2;
388 | SUMMARY_COMMITS_DISPLAY NUMBER {
390 yyerror("summary_commits_display is too small:"
394 new_srv->summary_commits_display = $2;
396 | SUMMARY_TAGS_DISPLAY NUMBER {
398 yyerror("summary_tags_display is too small:"
402 new_srv->summary_tags_display = $2;
406 serveropts2 : serveropts2 serveropts1 nl
413 optnl : '\n' optnl /* zero or more newlines */
425 yyerror(const char *fmt, ...)
432 if (vasprintf(&msg, fmt, ap) == -1)
433 fatalx("yyerror vasprintf");
435 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
441 kw_cmp(const void *k, const void *e)
443 return (strcmp(k, ((const struct keywords *)e)->k_name));
449 /* This has to be sorted always. */
450 static const struct keywords keywords[] = {
451 { "chroot", CHROOT },
452 { "custom_css", CUSTOM_CSS },
453 { "listen", LISTEN },
455 { "logo_url", LOGO_URL },
456 { "max_commits_display", MAX_COMMITS_DISPLAY },
457 { "max_repos_display", MAX_REPOS_DISPLAY },
460 { "prefork", PREFORK },
461 { "repos_path", REPOS_PATH },
462 { "respect_exportok", RESPECT_EXPORTOK },
463 { "server", SERVER },
464 { "show_repo_age", SHOW_REPO_AGE },
465 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
466 { "show_repo_description", SHOW_REPO_DESCRIPTION },
467 { "show_repo_owner", SHOW_REPO_OWNER },
468 { "show_site_owner", SHOW_SITE_OWNER },
469 { "site_link", SITE_LINK },
470 { "site_name", SITE_NAME },
471 { "site_owner", SITE_OWNER },
472 { "socket", SOCKET },
473 { "summary_commits_display", SUMMARY_COMMITS_DISPLAY },
474 { "summary_tags_display", SUMMARY_TAGS_DISPLAY },
475 { "unix_socket_name", UNIX_SOCKET_NAME },
477 const struct keywords *p;
479 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
480 sizeof(keywords[0]), kw_cmp);
488 #define MAXPUSHBACK 128
490 unsigned char *parsebuf;
492 unsigned char pushback_buffer[MAXPUSHBACK];
493 int pushback_index = 0;
501 /* Read character from the parsebuffer instead of input. */
502 if (parseindex >= 0) {
503 c = parsebuf[parseindex++];
512 return (pushback_buffer[--pushback_index]);
515 c = getc(file->stream);
517 yyerror("reached end of file while parsing "
522 c = getc(file->stream);
524 next = getc(file->stream);
529 yylval.lineno = file->lineno;
531 c = getc(file->stream);
547 if (pushback_index < MAXPUSHBACK-1)
548 return (pushback_buffer[pushback_index++] = c);
560 /* Skip to either EOF or the first real EOL. */
563 c = pushback_buffer[--pushback_index];
579 unsigned char buf[8096];
580 unsigned char *p, *val;
587 while (c == ' ' || c == '\t')
588 c = lgetc(0); /* nothing */
590 yylval.lineno = file->lineno;
593 while (c != '\n' && c != EOF)
594 c = lgetc(0); /* nothing */
596 if (c == '$' && parsebuf == NULL) {
602 if (p + 1 >= buf + sizeof(buf) - 1) {
603 yyerror("string too long");
606 if (isalnum(c) || c == '_') {
616 yyerror("macro '%s' not defined", buf);
635 } else if (c == '\\') {
636 next = lgetc(quotec);
639 if (next == quotec || c == ' ' || c == '\t')
641 else if (next == '\n') {
646 } else if (c == quotec) {
649 } else if (c == '\0') {
650 yyerror("syntax error");
653 if (p + 1 >= buf + sizeof(buf) - 1) {
654 yyerror("string too long");
659 yylval.v.string = strdup(buf);
660 if (yylval.v.string == NULL)
661 err(1, "yylex: strdup");
665 #define allowed_to_end_number(x) \
666 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
668 if (c == '-' || isdigit(c)) {
671 if ((unsigned)(p-buf) >= sizeof(buf)) {
672 yyerror("string too long");
676 } while (c != EOF && isdigit(c));
678 if (p == buf + 1 && buf[0] == '-')
680 if (c == EOF || allowed_to_end_number(c)) {
681 const char *errstr = NULL;
684 yylval.v.number = strtonum(buf, LLONG_MIN,
687 yyerror("\"%s\" invalid number: %s",
702 #define allowed_in_string(x) \
703 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
704 x != '{' && x != '}' && \
705 x != '!' && x != '=' && x != '#' && \
708 if (isalnum(c) || c == ':' || c == '_') {
711 if ((unsigned)(p-buf) >= sizeof(buf)) {
712 yyerror("string too long");
716 } while (c != EOF && (allowed_in_string(c)));
720 if (token == STRING) {
721 yylval.v.string = strdup(buf);
722 if (yylval.v.string == NULL)
723 err(1, "yylex: strdup");
728 yylval.lineno = file->lineno;
737 check_file_secrecy(int fd, const char *fname)
741 if (fstat(fd, &st)) {
742 log_warn("cannot stat %s", fname);
745 if (st.st_uid != 0 && st.st_uid != getuid()) {
746 log_warnx("%s: owner not root or current user", fname);
749 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
750 log_warnx("%s: group writable or world read/writable", fname);
757 newfile(const char *name, int secret)
761 nfile = calloc(1, sizeof(struct file));
766 nfile->name = strdup(name);
767 if (nfile->name == NULL) {
772 nfile->stream = fopen(nfile->name, "r");
773 if (nfile->stream == NULL) {
774 /* no warning, we don't require a conf file */
779 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
780 fclose(nfile->stream);
790 closefile(struct file *xfile)
792 fclose(xfile->stream);
798 add_default_server(void)
800 new_srv = conf_new_server(D_SITENAME);
801 log_debug("%s: adding default server %s", __func__, D_SITENAME);
805 parse_config(const char *filename, struct gotwebd *env)
807 struct sym *sym, *next;
811 if (config_init(env) == -1)
812 fatalx("failed to initialize configuration");
816 n = snprintf(env->unix_socket_name, sizeof(env->unix_socket_name),
817 "%s%s", D_HTTPD_CHROOT, D_UNIX_SOCKET);
818 if (n < 0 || (size_t)n >= sizeof(env->unix_socket_name))
819 fatalx("%s: snprintf", __func__);
821 file = newfile(filename, 0);
823 add_default_server();
824 sockets_parse_sockets(env);
825 /* just return, as we don't require a conf file */
830 errors = file->errors;
833 /* Free macros and check which have not been used. */
834 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
835 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
836 fprintf(stderr, "warning: macro '%s' not used\n",
841 TAILQ_REMOVE(&symhead, sym, entry);
846 /* just add default server if no config specified */
847 if (gotwebd->server_cnt == 0)
848 add_default_server();
850 /* add the implicit listen on socket where missing */
851 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
852 if (!TAILQ_EMPTY(&srv->al))
854 if (get_unix_addr(env->unix_socket_name, srv) == -1)
855 yyerror("can't listen on %s", env->unix_socket_name);
861 /* setup our listening sockets */
862 sockets_parse_sockets(env);
868 conf_new_server(const char *name)
870 struct server *srv = NULL;
872 srv = calloc(1, sizeof(*srv));
874 fatalx("%s: calloc", __func__);
876 n = strlcpy(srv->name, name, sizeof(srv->name));
877 if (n >= sizeof(srv->name))
878 fatalx("%s: strlcpy", __func__);
879 n = strlcpy(srv->repos_path, D_GOTPATH,
880 sizeof(srv->repos_path));
881 if (n >= sizeof(srv->repos_path))
882 fatalx("%s: strlcpy", __func__);
883 n = strlcpy(srv->site_name, D_SITENAME,
884 sizeof(srv->site_name));
885 if (n >= sizeof(srv->site_name))
886 fatalx("%s: strlcpy", __func__);
887 n = strlcpy(srv->site_owner, D_SITEOWNER,
888 sizeof(srv->site_owner));
889 if (n >= sizeof(srv->site_owner))
890 fatalx("%s: strlcpy", __func__);
891 n = strlcpy(srv->site_link, D_SITELINK,
892 sizeof(srv->site_link));
893 if (n >= sizeof(srv->site_link))
894 fatalx("%s: strlcpy", __func__);
895 n = strlcpy(srv->logo, D_GOTLOGO,
897 if (n >= sizeof(srv->logo))
898 fatalx("%s: strlcpy", __func__);
899 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
900 if (n >= sizeof(srv->logo_url))
901 fatalx("%s: strlcpy", __func__);
902 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
903 if (n >= sizeof(srv->custom_css))
904 fatalx("%s: strlcpy", __func__);
906 srv->show_site_owner = D_SHOWSOWNER;
907 srv->show_repo_owner = D_SHOWROWNER;
908 srv->show_repo_age = D_SHOWAGE;
909 srv->show_repo_description = D_SHOWDESC;
910 srv->show_repo_cloneurl = D_SHOWURL;
911 srv->respect_exportok = D_RESPECTEXPORTOK;
913 srv->max_repos_display = D_MAXREPODISP;
914 srv->max_commits_display = D_MAXCOMMITDISP;
915 srv->summary_commits_display = D_MAXSLCOMMDISP;
916 srv->summary_tags_display = D_MAXSLTAGDISP;
918 TAILQ_INIT(&srv->al);
919 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
920 gotwebd->server_cnt++;
926 symset(const char *nam, const char *val, int persist)
930 TAILQ_FOREACH(sym, &symhead, entry) {
931 if (strcmp(nam, sym->nam) == 0)
936 if (sym->persist == 1)
941 TAILQ_REMOVE(&symhead, sym, entry);
945 sym = calloc(1, sizeof(*sym));
949 sym->nam = strdup(nam);
950 if (sym->nam == NULL) {
954 sym->val = strdup(val);
955 if (sym->val == NULL) {
961 sym->persist = persist;
962 TAILQ_INSERT_TAIL(&symhead, sym, entry);
967 cmdline_symset(char *s)
972 val = strrchr(s, '=');
976 sym = strndup(s, val - s);
978 fatal("%s: strndup", __func__);
980 ret = symset(sym, val + 1, 1);
987 symget(const char *nam)
991 TAILQ_FOREACH(sym, &symhead, entry) {
992 if (strcmp(nam, sym->nam) == 0) {
1001 get_addrs(const char *hostname, const char *servname, struct server *new_srv)
1003 struct addrinfo hints, *res0, *res;
1005 struct sockaddr_in *sin;
1006 struct sockaddr_in6 *sin6;
1009 memset(&hints, 0, sizeof(hints));
1010 hints.ai_family = AF_UNSPEC;
1011 hints.ai_socktype = SOCK_STREAM;
1012 hints.ai_flags = AI_PASSIVE | AI_ADDRCONFIG;
1013 error = getaddrinfo(hostname, servname, &hints, &res0);
1015 log_warnx("%s: could not parse \"%s:%s\": %s", __func__,
1016 hostname, servname, gai_strerror(error));
1020 for (res = res0; res; res = res->ai_next) {
1021 if ((h = calloc(1, sizeof(*h))) == NULL)
1024 if (hostname == NULL) {
1025 strlcpy(h->ifname, "*", sizeof(h->ifname));
1027 if (strlcpy(h->ifname, hostname, sizeof(h->ifname)) >=
1028 sizeof(h->ifname)) {
1029 log_warnx("%s: address truncated: %s",
1030 __func__, hostname);
1037 h->ai_family = res->ai_family;
1038 h->ai_socktype = res->ai_socktype;
1039 h->ai_protocol = res->ai_protocol;
1040 memcpy(&h->ss, res->ai_addr, res->ai_addrlen);
1041 h->slen = res->ai_addrlen;
1043 switch (res->ai_family) {
1045 sin = (struct sockaddr_in *)res->ai_addr;
1046 h->port = ntohs(sin->sin_port);
1049 sin6 = (struct sockaddr_in6 *)res->ai_addr;
1050 h->port = ntohs(sin6->sin6_port);
1053 fatalx("unknown address family %d", res->ai_family);
1056 if (add_addr(new_srv, h) == -1) {
1066 get_unix_addr(const char *path, struct server *new_srv)
1069 struct sockaddr_un *sun;
1071 if ((h = calloc(1, sizeof(*h))) == NULL)
1072 fatal("%s: calloc", __func__);
1074 h->ai_family = AF_UNIX;
1075 h->ai_socktype = SOCK_STREAM;
1076 h->ai_protocol = PF_UNSPEC;
1077 h->slen = sizeof(*sun);
1079 sun = (struct sockaddr_un *)&h->ss;
1080 sun->sun_family = AF_UNIX;
1081 if (strlcpy(sun->sun_path, path, sizeof(sun->sun_path)) >=
1082 sizeof(sun->sun_path)) {
1083 log_warnx("socket path too long: %s", sun->sun_path);
1087 return add_addr(new_srv, h);
1091 addr_dup_check(struct addresslist *al, struct address *h)
1095 TAILQ_FOREACH(a, al, entry) {
1096 if (a->ai_family != h->ai_family ||
1097 a->ai_socktype != h->ai_socktype ||
1098 a->ai_protocol != h->ai_protocol ||
1099 a->slen != h->slen ||
1100 memcmp(&a->ss, &h->ss, a->slen) != 0)
1109 add_addr(struct server *new_srv, struct address *h)
1112 struct address *dup;
1114 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1115 if (addr_dup_check(&srv->al, h) == -1) {
1121 if (addr_dup_check(&gotwebd->addresses, h) == 0) {
1122 if ((dup = calloc(1, sizeof(*dup))) == NULL)
1123 fatal("%s: calloc", __func__);
1124 memcpy(dup, h, sizeof(*dup));
1125 TAILQ_INSERT_TAIL(&gotwebd->addresses, dup, entry);
1128 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);