Blob


1 /*
2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
23 %{
24 #include "got_compat.h"
26 #include <sys/ioctl.h>
27 #include <sys/types.h>
28 #include <sys/queue.h>
29 #include <sys/socket.h>
30 #include <sys/stat.h>
32 #include <net/if.h>
33 #include <netinet/in.h>
35 #include <arpa/inet.h>
37 #include <ctype.h>
38 #include <err.h>
39 #include <errno.h>
40 #include <event.h>
41 #include <ifaddrs.h>
42 #include <limits.h>
43 #include <netdb.h>
44 #include <stdarg.h>
45 #include <stdlib.h>
46 #include <stdio.h>
47 #include <string.h>
48 #include <syslog.h>
49 #include <unistd.h>
51 #include "got_sockaddr.h"
52 #include "got_reference.h"
54 #include "proc.h"
55 #include "gotwebd.h"
57 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
58 static struct file {
59 TAILQ_ENTRY(file) entry;
60 FILE *stream;
61 char *name;
62 int lineno;
63 int errors;
64 } *file;
65 struct file *newfile(const char *, int);
66 static void closefile(struct file *);
67 int check_file_secrecy(int, const char *);
68 int yyparse(void);
69 int yylex(void);
70 int yyerror(const char *, ...)
71 __attribute__((__format__ (printf, 1, 2)))
72 __attribute__((__nonnull__ (1)));
73 int kw_cmp(const void *, const void *);
74 int lookup(char *);
75 int lgetc(int);
76 int lungetc(int);
77 int findeol(void);
79 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
80 struct sym {
81 TAILQ_ENTRY(sym) entry;
82 int used;
83 int persist;
84 char *nam;
85 char *val;
86 };
88 int symset(const char *, const char *, int);
89 char *symget(const char *);
91 static int errors;
93 static struct gotwebd *gotwebd;
94 static struct server *new_srv;
95 static struct server *conf_new_server(const char *);
96 int getservice(const char *);
97 int n;
99 int get_addrs(const char *, struct server *, in_port_t);
100 int addr_dup_check(struct addresslist *, struct address *,
101 const char *, const char *);
102 int add_addr(struct server *, struct address *);
103 int host(const char *, struct server *,
104 int, in_port_t, const char *, int);
105 int host_if(const char *, struct server *,
106 int, in_port_t, const char *, int);
107 int is_if_in_group(const char *, const char *);
109 typedef struct {
110 union {
111 long long number;
112 char *string;
113 in_port_t port;
114 } v;
115 int lineno;
116 } YYSTYPE;
118 %}
120 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
121 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
122 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
123 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
124 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
126 %token <v.string> STRING
127 %type <v.port> fcgiport
128 %token <v.number> NUMBER
129 %type <v.number> boolean
131 %%
133 grammar : /* empty */
134 | grammar '\n'
135 | grammar varset '\n'
136 | grammar main '\n'
137 | grammar server '\n'
138 | grammar error '\n' { file->errors++; }
141 varset : STRING '=' STRING {
142 char *s = $1;
143 while (*s++) {
144 if (isspace((unsigned char)*s)) {
145 yyerror("macro name cannot contain "
146 "whitespace");
147 free($1);
148 free($3);
149 YYERROR;
152 if (symset($1, $3, 0) == -1)
153 fatal("cannot store variable");
154 free($1);
155 free($3);
159 boolean : STRING {
160 if (strcasecmp($1, "1") == 0 ||
161 strcasecmp($1, "on") == 0)
162 $$ = 1;
163 else if (strcasecmp($1, "0") == 0 ||
164 strcasecmp($1, "off") == 0)
165 $$ = 0;
166 else {
167 yyerror("invalid boolean value '%s'", $1);
168 free($1);
169 YYERROR;
171 free($1);
173 | ON { $$ = 1; }
174 | NUMBER {
175 if ($1 != 0 && $1 != 1) {
176 yyerror("invalid boolean value '%lld'", $1);
177 YYERROR;
179 $$ = $1;
183 fcgiport : PORT NUMBER {
184 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
185 yyerror("invalid port: %lld", $2);
186 YYERROR;
188 $$ = $2;
190 | PORT STRING {
191 int val;
193 if ((val = getservice($2)) == -1) {
194 yyerror("invalid port: %s", $2);
195 free($2);
196 YYERROR;
198 free($2);
200 $$ = val;
204 main : PREFORK NUMBER {
205 if ($2 <= 0 || $2 > PROC_MAX_INSTANCES) {
206 yyerror("prefork is %s: %lld",
207 $2 <= 0 ? "too small" : "too large", $2);
208 YYERROR;
210 gotwebd->prefork_gotwebd = $2;
212 | CHROOT STRING {
213 if (*$2 == '\0') {
214 yyerror("chroot path can't be an empty"
215 " string");
216 free($2);
217 YYERROR;
220 n = strlcpy(gotwebd->httpd_chroot, $2,
221 sizeof(gotwebd->httpd_chroot));
222 if (n >= sizeof(gotwebd->httpd_chroot)) {
223 yyerror("%s: httpd_chroot truncated", __func__);
224 free($2);
225 YYERROR;
227 free($2);
229 | UNIX_SOCKET boolean {
230 gotwebd->unix_socket = $2;
232 | UNIX_SOCKET_NAME STRING {
233 n = snprintf(gotwebd->unix_socket_name,
234 sizeof(gotwebd->unix_socket_name), "%s%s",
235 strlen(gotwebd->httpd_chroot) ?
236 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $2);
237 if (n < 0 ||
238 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
239 yyerror("%s: unix_socket_name truncated",
240 __func__);
241 free($2);
242 YYERROR;
244 free($2);
248 server : SERVER STRING {
249 struct server *srv;
251 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
252 if (strcmp(srv->name, $2) == 0) {
253 yyerror("server name exists '%s'", $2);
254 free($2);
255 YYERROR;
259 new_srv = conf_new_server($2);
260 log_debug("adding server %s", $2);
261 free($2);
263 | SERVER STRING {
264 struct server *srv;
266 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
267 if (strcmp(srv->name, $2) == 0) {
268 yyerror("server name exists '%s'", $2);
269 free($2);
270 YYERROR;
274 new_srv = conf_new_server($2);
275 log_debug("adding server %s", $2);
276 free($2);
277 } '{' optnl serveropts2 '}' {
281 serveropts1 : REPOS_PATH STRING {
282 n = strlcpy(new_srv->repos_path, $2,
283 sizeof(new_srv->repos_path));
284 if (n >= sizeof(new_srv->repos_path)) {
285 yyerror("%s: repos_path truncated", __func__);
286 free($2);
287 YYERROR;
289 free($2);
291 | SITE_NAME STRING {
292 n = strlcpy(new_srv->site_name, $2,
293 sizeof(new_srv->site_name));
294 if (n >= sizeof(new_srv->site_name)) {
295 yyerror("%s: site_name truncated", __func__);
296 free($2);
297 YYERROR;
299 free($2);
301 | SITE_OWNER STRING {
302 n = strlcpy(new_srv->site_owner, $2,
303 sizeof(new_srv->site_owner));
304 if (n >= sizeof(new_srv->site_owner)) {
305 yyerror("%s: site_owner truncated", __func__);
306 free($2);
307 YYERROR;
309 free($2);
311 | SITE_LINK STRING {
312 n = strlcpy(new_srv->site_link, $2,
313 sizeof(new_srv->site_link));
314 if (n >= sizeof(new_srv->site_link)) {
315 yyerror("%s: site_link truncated", __func__);
316 free($2);
317 YYERROR;
319 free($2);
321 | LOGO STRING {
322 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
323 if (n >= sizeof(new_srv->logo)) {
324 yyerror("%s: logo truncated", __func__);
325 free($2);
326 YYERROR;
328 free($2);
330 | LOGO_URL STRING {
331 n = strlcpy(new_srv->logo_url, $2,
332 sizeof(new_srv->logo_url));
333 if (n >= sizeof(new_srv->logo_url)) {
334 yyerror("%s: logo_url truncated", __func__);
335 free($2);
336 YYERROR;
338 free($2);
340 | CUSTOM_CSS STRING {
341 n = strlcpy(new_srv->custom_css, $2,
342 sizeof(new_srv->custom_css));
343 if (n >= sizeof(new_srv->custom_css)) {
344 yyerror("%s: custom_css truncated", __func__);
345 free($2);
346 YYERROR;
348 free($2);
350 | LISTEN ON STRING fcgiport {
351 if (get_addrs($3, new_srv, $4) == -1) {
352 yyerror("could not get addrs");
353 YYERROR;
355 new_srv->fcgi_socket = 1;
357 | LISTEN ON SOCKET STRING {
358 if (strcasecmp($4, "off") == 0) {
359 new_srv->unix_socket = 0;
360 free($4);
361 YYACCEPT;
364 new_srv->unix_socket = 1;
366 n = snprintf(new_srv->unix_socket_name,
367 sizeof(new_srv->unix_socket_name), "%s%s",
368 strlen(gotwebd->httpd_chroot) ?
369 gotwebd->httpd_chroot : D_HTTPD_CHROOT, $4);
370 if (n < 0 ||
371 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
372 yyerror("%s: unix_socket_name truncated",
373 __func__);
374 free($4);
375 YYERROR;
377 free($4);
379 | MAX_REPOS NUMBER {
380 if ($2 <= 0) {
381 yyerror("max_repos is too small: %lld", $2);
382 YYERROR;
384 new_srv->max_repos = $2;
386 | SHOW_SITE_OWNER boolean {
387 new_srv->show_site_owner = $2;
389 | SHOW_REPO_OWNER boolean {
390 new_srv->show_repo_owner = $2;
392 | SHOW_REPO_AGE boolean {
393 new_srv->show_repo_age = $2;
395 | SHOW_REPO_DESCRIPTION boolean {
396 new_srv->show_repo_description = $2;
398 | SHOW_REPO_CLONEURL boolean {
399 new_srv->show_repo_cloneurl = $2;
401 | RESPECT_EXPORTOK boolean {
402 new_srv->respect_exportok = $2;
404 | MAX_REPOS_DISPLAY NUMBER {
405 if ($2 <= 0) {
406 yyerror("max_repos_display is too small: %lld",
407 $2);
408 YYERROR;
410 new_srv->max_repos_display = $2;
412 | MAX_COMMITS_DISPLAY NUMBER {
413 if ($2 <= 1) {
414 yyerror("max_commits_display is too small:"
415 " %lld", $2);
416 YYERROR;
418 new_srv->max_commits_display = $2;
422 serveropts2 : serveropts2 serveropts1 nl
423 | serveropts1 optnl
426 nl : '\n' optnl
429 optnl : '\n' optnl /* zero or more newlines */
430 | /* empty */
433 %%
435 struct keywords {
436 const char *k_name;
437 int k_val;
438 };
440 int
441 yyerror(const char *fmt, ...)
443 va_list ap;
444 char *msg;
446 file->errors++;
447 va_start(ap, fmt);
448 if (vasprintf(&msg, fmt, ap) == -1)
449 fatalx("yyerror vasprintf");
450 va_end(ap);
451 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
452 free(msg);
453 return (0);
456 int
457 kw_cmp(const void *k, const void *e)
459 return (strcmp(k, ((const struct keywords *)e)->k_name));
462 int
463 lookup(char *s)
465 /* This has to be sorted always. */
466 static const struct keywords keywords[] = {
467 { "chroot", CHROOT },
468 { "custom_css", CUSTOM_CSS },
469 { "listen", LISTEN },
470 { "logo", LOGO },
471 { "logo_url", LOGO_URL },
472 { "max_commits_display", MAX_COMMITS_DISPLAY },
473 { "max_repos", MAX_REPOS },
474 { "max_repos_display", MAX_REPOS_DISPLAY },
475 { "on", ON },
476 { "port", PORT },
477 { "prefork", PREFORK },
478 { "repos_path", REPOS_PATH },
479 { "respect_exportok", RESPECT_EXPORTOK },
480 { "server", SERVER },
481 { "show_repo_age", SHOW_REPO_AGE },
482 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
483 { "show_repo_description", SHOW_REPO_DESCRIPTION },
484 { "show_repo_owner", SHOW_REPO_OWNER },
485 { "show_site_owner", SHOW_SITE_OWNER },
486 { "site_link", SITE_LINK },
487 { "site_name", SITE_NAME },
488 { "site_owner", SITE_OWNER },
489 { "socket", SOCKET },
490 { "unix_socket", UNIX_SOCKET },
491 { "unix_socket_name", UNIX_SOCKET_NAME },
492 };
493 const struct keywords *p;
495 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
496 sizeof(keywords[0]), kw_cmp);
498 if (p)
499 return (p->k_val);
500 else
501 return (STRING);
504 #define MAXPUSHBACK 128
506 unsigned char *parsebuf;
507 int parseindex;
508 unsigned char pushback_buffer[MAXPUSHBACK];
509 int pushback_index = 0;
511 int
512 lgetc(int quotec)
514 int c, next;
516 if (parsebuf) {
517 /* Read character from the parsebuffer instead of input. */
518 if (parseindex >= 0) {
519 c = parsebuf[parseindex++];
520 if (c != '\0')
521 return (c);
522 parsebuf = NULL;
523 } else
524 parseindex++;
527 if (pushback_index)
528 return (pushback_buffer[--pushback_index]);
530 if (quotec) {
531 c = getc(file->stream);
532 if (c == EOF)
533 yyerror("reached end of file while parsing "
534 "quoted string");
535 return (c);
538 c = getc(file->stream);
539 while (c == '\\') {
540 next = getc(file->stream);
541 if (next != '\n') {
542 c = next;
543 break;
545 yylval.lineno = file->lineno;
546 file->lineno++;
547 c = getc(file->stream);
550 return (c);
553 int
554 lungetc(int c)
556 if (c == EOF)
557 return (EOF);
558 if (parsebuf) {
559 parseindex--;
560 if (parseindex >= 0)
561 return (c);
563 if (pushback_index < MAXPUSHBACK-1)
564 return (pushback_buffer[pushback_index++] = c);
565 else
566 return (EOF);
569 int
570 findeol(void)
572 int c;
574 parsebuf = NULL;
576 /* Skip to either EOF or the first real EOL. */
577 while (1) {
578 if (pushback_index)
579 c = pushback_buffer[--pushback_index];
580 else
581 c = lgetc(0);
582 if (c == '\n') {
583 file->lineno++;
584 break;
586 if (c == EOF)
587 break;
589 return (ERROR);
592 int
593 yylex(void)
595 unsigned char buf[8096];
596 unsigned char *p, *val;
597 int quotec, next, c;
598 int token;
600 top:
601 p = buf;
602 c = lgetc(0);
603 while (c == ' ' || c == '\t')
604 c = lgetc(0); /* nothing */
606 yylval.lineno = file->lineno;
607 if (c == '#') {
608 c = lgetc(0);
609 while (c != '\n' && c != EOF)
610 c = lgetc(0); /* nothing */
612 if (c == '$' && parsebuf == NULL) {
613 while (1) {
614 c = lgetc(0);
615 if (c == EOF)
616 return (0);
618 if (p + 1 >= buf + sizeof(buf) - 1) {
619 yyerror("string too long");
620 return (findeol());
622 if (isalnum(c) || c == '_') {
623 *p++ = c;
624 continue;
626 *p = '\0';
627 lungetc(c);
628 break;
630 val = symget(buf);
631 if (val == NULL) {
632 yyerror("macro '%s' not defined", buf);
633 return (findeol());
635 parsebuf = val;
636 parseindex = 0;
637 goto top;
640 switch (c) {
641 case '\'':
642 case '"':
643 quotec = c;
644 while (1) {
645 c = lgetc(quotec);
646 if (c == EOF)
647 return (0);
648 if (c == '\n') {
649 file->lineno++;
650 continue;
651 } else if (c == '\\') {
652 next = lgetc(quotec);
653 if (next == EOF)
654 return (0);
655 if (next == quotec || c == ' ' || c == '\t')
656 c = next;
657 else if (next == '\n') {
658 file->lineno++;
659 continue;
660 } else
661 lungetc(next);
662 } else if (c == quotec) {
663 *p = '\0';
664 break;
665 } else if (c == '\0') {
666 yyerror("syntax error");
667 return (findeol());
669 if (p + 1 >= buf + sizeof(buf) - 1) {
670 yyerror("string too long");
671 return (findeol());
673 *p++ = c;
675 yylval.v.string = strdup(buf);
676 if (yylval.v.string == NULL)
677 err(1, "yylex: strdup");
678 return (STRING);
681 #define allowed_to_end_number(x) \
682 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
684 if (c == '-' || isdigit(c)) {
685 do {
686 *p++ = c;
687 if ((unsigned)(p-buf) >= sizeof(buf)) {
688 yyerror("string too long");
689 return (findeol());
691 c = lgetc(0);
692 } while (c != EOF && isdigit(c));
693 lungetc(c);
694 if (p == buf + 1 && buf[0] == '-')
695 goto nodigits;
696 if (c == EOF || allowed_to_end_number(c)) {
697 const char *errstr = NULL;
699 *p = '\0';
700 yylval.v.number = strtonum(buf, LLONG_MIN,
701 LLONG_MAX, &errstr);
702 if (errstr) {
703 yyerror("\"%s\" invalid number: %s",
704 buf, errstr);
705 return (findeol());
707 return (NUMBER);
708 } else {
709 nodigits:
710 while (p > buf + 1)
711 lungetc(*--p);
712 c = *--p;
713 if (c == '-')
714 return (c);
718 #define allowed_in_string(x) \
719 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
720 x != '{' && x != '}' && \
721 x != '!' && x != '=' && x != '#' && \
722 x != ','))
724 if (isalnum(c) || c == ':' || c == '_') {
725 do {
726 *p++ = c;
727 if ((unsigned)(p-buf) >= sizeof(buf)) {
728 yyerror("string too long");
729 return (findeol());
731 c = lgetc(0);
732 } while (c != EOF && (allowed_in_string(c)));
733 lungetc(c);
734 *p = '\0';
735 token = lookup(buf);
736 if (token == STRING) {
737 yylval.v.string = strdup(buf);
738 if (yylval.v.string == NULL)
739 err(1, "yylex: strdup");
741 return (token);
743 if (c == '\n') {
744 yylval.lineno = file->lineno;
745 file->lineno++;
747 if (c == EOF)
748 return (0);
749 return (c);
752 int
753 check_file_secrecy(int fd, const char *fname)
755 struct stat st;
757 if (fstat(fd, &st)) {
758 log_warn("cannot stat %s", fname);
759 return (-1);
761 if (st.st_uid != 0 && st.st_uid != getuid()) {
762 log_warnx("%s: owner not root or current user", fname);
763 return (-1);
765 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
766 log_warnx("%s: group writable or world read/writable", fname);
767 return (-1);
769 return (0);
772 struct file *
773 newfile(const char *name, int secret)
775 struct file *nfile;
777 nfile = calloc(1, sizeof(struct file));
778 if (nfile == NULL) {
779 log_warn("calloc");
780 return (NULL);
782 nfile->name = strdup(name);
783 if (nfile->name == NULL) {
784 log_warn("strdup");
785 free(nfile);
786 return (NULL);
788 nfile->stream = fopen(nfile->name, "r");
789 if (nfile->stream == NULL) {
790 /* no warning, we don't require a conf file */
791 free(nfile->name);
792 free(nfile);
793 return (NULL);
794 } else if (secret &&
795 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
796 fclose(nfile->stream);
797 free(nfile->name);
798 free(nfile);
799 return (NULL);
801 nfile->lineno = 1;
802 return (nfile);
805 static void
806 closefile(struct file *xfile)
808 fclose(xfile->stream);
809 free(xfile->name);
810 free(xfile);
813 static void
814 add_default_server(void)
816 new_srv = conf_new_server(D_SITENAME);
817 log_debug("%s: adding default server %s", __func__, D_SITENAME);
820 int
821 parse_config(const char *filename, struct gotwebd *env)
823 struct sym *sym, *next;
825 if (config_init(env) == -1)
826 fatalx("failed to initialize configuration");
828 gotwebd = env;
830 file = newfile(filename, 0);
831 if (file == NULL) {
832 add_default_server();
833 sockets_parse_sockets(env);
834 /* just return, as we don't require a conf file */
835 return (0);
838 yyparse();
839 errors = file->errors;
840 closefile(file);
842 /* Free macros and check which have not been used. */
843 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
844 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
845 fprintf(stderr, "warning: macro '%s' not used\n",
846 sym->nam);
847 if (!sym->persist) {
848 free(sym->nam);
849 free(sym->val);
850 TAILQ_REMOVE(&symhead, sym, entry);
851 free(sym);
855 if (errors)
856 return (-1);
858 /* just add default server if no config specified */
859 if (gotwebd->server_cnt == 0)
860 add_default_server();
862 /* setup our listening sockets */
863 sockets_parse_sockets(env);
865 return (0);
868 struct server *
869 conf_new_server(const char *name)
871 struct server *srv = NULL;
873 srv = calloc(1, sizeof(*srv));
874 if (srv == NULL)
875 fatalx("%s: calloc", __func__);
877 n = strlcpy(srv->name, name, sizeof(srv->name));
878 if (n >= sizeof(srv->name))
879 fatalx("%s: strlcpy", __func__);
880 n = snprintf(srv->unix_socket_name,
881 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
882 D_UNIX_SOCKET);
883 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
884 fatalx("%s: snprintf", __func__);
885 n = strlcpy(srv->repos_path, D_GOTPATH,
886 sizeof(srv->repos_path));
887 if (n >= sizeof(srv->repos_path))
888 fatalx("%s: strlcpy", __func__);
889 n = strlcpy(srv->site_name, D_SITENAME,
890 sizeof(srv->site_name));
891 if (n >= sizeof(srv->site_name))
892 fatalx("%s: strlcpy", __func__);
893 n = strlcpy(srv->site_owner, D_SITEOWNER,
894 sizeof(srv->site_owner));
895 if (n >= sizeof(srv->site_owner))
896 fatalx("%s: strlcpy", __func__);
897 n = strlcpy(srv->site_link, D_SITELINK,
898 sizeof(srv->site_link));
899 if (n >= sizeof(srv->site_link))
900 fatalx("%s: strlcpy", __func__);
901 n = strlcpy(srv->logo, D_GOTLOGO,
902 sizeof(srv->logo));
903 if (n >= sizeof(srv->logo))
904 fatalx("%s: strlcpy", __func__);
905 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
906 if (n >= sizeof(srv->logo_url))
907 fatalx("%s: strlcpy", __func__);
908 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
909 if (n >= sizeof(srv->custom_css))
910 fatalx("%s: strlcpy", __func__);
912 srv->show_site_owner = D_SHOWSOWNER;
913 srv->show_repo_owner = D_SHOWROWNER;
914 srv->show_repo_age = D_SHOWAGE;
915 srv->show_repo_description = D_SHOWDESC;
916 srv->show_repo_cloneurl = D_SHOWURL;
917 srv->respect_exportok = D_RESPECTEXPORTOK;
919 srv->max_repos_display = D_MAXREPODISP;
920 srv->max_commits_display = D_MAXCOMMITDISP;
921 srv->max_repos = D_MAXREPO;
923 srv->unix_socket = 1;
924 srv->fcgi_socket = 0;
926 TAILQ_INIT(&srv->al);
927 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
928 gotwebd->server_cnt++;
930 return srv;
931 };
933 int
934 symset(const char *nam, const char *val, int persist)
936 struct sym *sym;
938 TAILQ_FOREACH(sym, &symhead, entry) {
939 if (strcmp(nam, sym->nam) == 0)
940 break;
943 if (sym != NULL) {
944 if (sym->persist == 1)
945 return (0);
946 else {
947 free(sym->nam);
948 free(sym->val);
949 TAILQ_REMOVE(&symhead, sym, entry);
950 free(sym);
953 sym = calloc(1, sizeof(*sym));
954 if (sym == NULL)
955 return (-1);
957 sym->nam = strdup(nam);
958 if (sym->nam == NULL) {
959 free(sym);
960 return (-1);
962 sym->val = strdup(val);
963 if (sym->val == NULL) {
964 free(sym->nam);
965 free(sym);
966 return (-1);
968 sym->used = 0;
969 sym->persist = persist;
970 TAILQ_INSERT_TAIL(&symhead, sym, entry);
971 return (0);
974 int
975 cmdline_symset(char *s)
977 char *sym, *val;
978 int ret;
980 val = strrchr(s, '=');
981 if (val == NULL)
982 return (-1);
984 sym = strndup(s, val - s);
985 if (sym == NULL)
986 fatal("%s: strndup", __func__);
988 ret = symset(sym, val + 1, 1);
989 free(sym);
991 return (ret);
994 char *
995 symget(const char *nam)
997 struct sym *sym;
999 TAILQ_FOREACH(sym, &symhead, entry) {
1000 if (strcmp(nam, sym->nam) == 0) {
1001 sym->used = 1;
1002 return (sym->val);
1005 return (NULL);
1008 int
1009 getservice(const char *n)
1011 struct servent *s;
1012 const char *errstr;
1013 long long llval;
1015 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1016 if (errstr) {
1017 s = getservbyname(n, "tcp");
1018 if (s == NULL)
1019 s = getservbyname(n, "udp");
1020 if (s == NULL)
1021 return (-1);
1022 return ntohs(s->s_port);
1025 return (unsigned short)llval;
1028 int
1029 host(const char *s, struct server *new_srv, int max,
1030 in_port_t port, const char *ifname, int ipproto)
1032 struct addrinfo hints, *res0, *res;
1033 int error, cnt = 0;
1034 struct sockaddr_in *sain;
1035 struct sockaddr_in6 *sin6;
1036 struct address *h;
1038 if ((cnt = host_if(s, new_srv, max, port, ifname, ipproto)) != 0)
1039 return (cnt);
1041 memset(&hints, 0, sizeof(hints));
1042 hints.ai_family = AF_UNSPEC;
1043 hints.ai_socktype = SOCK_STREAM; /* DUMMY */
1044 hints.ai_flags = AI_ADDRCONFIG;
1045 error = getaddrinfo(s, NULL, &hints, &res0);
1046 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1047 return (0);
1048 if (error) {
1049 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1050 gai_strerror(error));
1051 return (-1);
1054 for (res = res0; res && cnt < max; res = res->ai_next) {
1055 if (res->ai_family != AF_INET &&
1056 res->ai_family != AF_INET6)
1057 continue;
1058 if ((h = calloc(1, sizeof(*h))) == NULL)
1059 fatal(__func__);
1061 if (port)
1062 h->port = port;
1063 if (ifname != NULL) {
1064 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1065 sizeof(h->ifname)) {
1066 log_warnx("%s: interface name truncated",
1067 __func__);
1068 freeaddrinfo(res0);
1069 free(h);
1070 return (-1);
1073 if (ipproto != -1)
1074 h->ipproto = ipproto;
1075 h->ss.ss_family = res->ai_family;
1077 if (res->ai_family == AF_INET) {
1078 struct sockaddr_in *ra;
1079 sain = (struct sockaddr_in *)&h->ss;
1080 ra = (struct sockaddr_in *)res->ai_addr;
1081 got_sockaddr_inet_init(sain, &ra->sin_addr);
1082 } else {
1083 struct sockaddr_in6 *ra;
1084 sin6 = (struct sockaddr_in6 *)&h->ss;
1085 ra = (struct sockaddr_in6 *)res->ai_addr;
1086 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1089 if (add_addr(new_srv, h))
1090 return -1;
1091 cnt++;
1093 if (cnt == max && res) {
1094 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1095 s, max);
1097 freeaddrinfo(res0);
1098 return (cnt);
1101 int
1102 host_if(const char *s, struct server *new_srv, int max,
1103 in_port_t port, const char *ifname, int ipproto)
1105 struct ifaddrs *ifap, *p;
1106 struct sockaddr_in *sain;
1107 struct sockaddr_in6 *sin6;
1108 struct address *h;
1109 int cnt = 0, af;
1111 if (getifaddrs(&ifap) == -1)
1112 fatal("getifaddrs");
1114 /* First search for IPv4 addresses */
1115 af = AF_INET;
1117 nextaf:
1118 for (p = ifap; p != NULL && cnt < max; p = p->ifa_next) {
1119 if (p->ifa_addr == NULL ||
1120 p->ifa_addr->sa_family != af ||
1121 (strcmp(s, p->ifa_name) != 0 &&
1122 !is_if_in_group(p->ifa_name, s)))
1123 continue;
1124 if ((h = calloc(1, sizeof(*h))) == NULL)
1125 fatal("calloc");
1127 if (port)
1128 h->port = port;
1129 if (ifname != NULL) {
1130 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1131 sizeof(h->ifname)) {
1132 log_warnx("%s: interface name truncated",
1133 __func__);
1134 free(h);
1135 freeifaddrs(ifap);
1136 return (-1);
1139 if (ipproto != -1)
1140 h->ipproto = ipproto;
1141 h->ss.ss_family = af;
1143 if (af == AF_INET) {
1144 struct sockaddr_in *ra;
1145 sain = (struct sockaddr_in *)&h->ss;
1146 ra = (struct sockaddr_in *)p->ifa_addr;
1147 got_sockaddr_inet_init(sain, &ra->sin_addr);
1148 } else {
1149 struct sockaddr_in6 *ra;
1150 sin6 = (struct sockaddr_in6 *)&h->ss;
1151 ra = (struct sockaddr_in6 *)p->ifa_addr;
1152 got_sockaddr_inet6_init(sin6, &ra->sin6_addr,
1153 ra->sin6_scope_id);
1156 if (add_addr(new_srv, h))
1157 return -1;
1158 cnt++;
1160 if (af == AF_INET) {
1161 /* Next search for IPv6 addresses */
1162 af = AF_INET6;
1163 goto nextaf;
1166 if (cnt > max) {
1167 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1168 s, max);
1170 freeifaddrs(ifap);
1171 return (cnt);
1174 int
1175 is_if_in_group(const char *ifname, const char *groupname)
1177 /* TA: Check this... */
1178 #ifdef HAVE_STRUCT_IFGROUPREQ
1179 unsigned int len;
1180 struct ifgroupreq ifgr;
1181 struct ifg_req *ifg;
1182 int s;
1183 int ret = 0;
1185 if ((s = socket(AF_INET, SOCK_DGRAM, 0)) == -1)
1186 err(1, "socket");
1188 memset(&ifgr, 0, sizeof(ifgr));
1189 if (strlcpy(ifgr.ifgr_name, ifname, IFNAMSIZ) >= IFNAMSIZ)
1190 err(1, "IFNAMSIZ");
1191 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1) {
1192 if (errno == EINVAL || errno == ENOTTY)
1193 goto end;
1194 err(1, "SIOCGIFGROUP");
1197 len = ifgr.ifgr_len;
1198 ifgr.ifgr_groups = calloc(len / sizeof(struct ifg_req),
1199 sizeof(struct ifg_req));
1200 if (ifgr.ifgr_groups == NULL)
1201 err(1, "getifgroups");
1202 if (ioctl(s, SIOCGIFGROUP, (caddr_t)&ifgr) == -1)
1203 err(1, "SIOCGIFGROUP");
1205 ifg = ifgr.ifgr_groups;
1206 for (; ifg && len >= sizeof(struct ifg_req); ifg++) {
1207 len -= sizeof(struct ifg_req);
1208 if (strcmp(ifg->ifgrq_group, groupname) == 0) {
1209 ret = 1;
1210 break;
1213 free(ifgr.ifgr_groups);
1215 end:
1216 close(s);
1217 return (ret);
1218 #else
1219 return (0);
1220 #endif
1223 int
1224 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1226 if (strcmp("", addr) == 0) {
1227 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1",
1228 -1) <= 0) {
1229 yyerror("invalid listen ip: %s",
1230 "127.0.0.1");
1231 return (-1);
1233 if (host("::1", new_srv, 1, port, "::1", -1) <= 0) {
1234 yyerror("invalid listen ip: %s", "::1");
1235 return (-1);
1237 } else {
1238 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr,
1239 -1) <= 0) {
1240 yyerror("invalid listen ip: %s", addr);
1241 return (-1);
1244 return (0);
1247 int
1248 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1249 const char *other_srv)
1251 struct address *a;
1252 void *ia;
1253 char buf[INET6_ADDRSTRLEN];
1254 const char *addrstr;
1256 TAILQ_FOREACH(a, al, entry) {
1257 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1258 a->port != h->port)
1259 continue;
1261 switch (h->ss.ss_family) {
1262 case AF_INET:
1263 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1264 break;
1265 case AF_INET6:
1266 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1267 break;
1268 default:
1269 yyerror("unknown address family: %d", h->ss.ss_family);
1270 return -1;
1272 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1273 if (addrstr) {
1274 if (other_srv) {
1275 yyerror("server %s: duplicate fcgi listen "
1276 "address %s:%d, already used by server %s",
1277 new_srv, addrstr, h->port, other_srv);
1278 } else {
1279 log_warnx("server: %s: duplicate fcgi listen "
1280 "address %s:%d", new_srv, addrstr, h->port);
1282 } else {
1283 if (other_srv) {
1284 yyerror("server: %s: duplicate fcgi listen "
1285 "address, already used by server %s",
1286 new_srv, other_srv);
1287 } else {
1288 log_warnx("server %s: duplicate fcgi listen "
1289 "address", new_srv);
1293 return -1;
1296 return 0;
1299 int
1300 add_addr(struct server *new_srv, struct address *h)
1302 struct server *srv;
1304 /* Address cannot be shared between different servers. */
1305 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1306 if (srv == new_srv)
1307 continue;
1308 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1309 return -1;
1312 /* Tolerate duplicate address lines within the scope of a server. */
1313 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1314 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);
1315 else
1316 free(h);
1318 return 0;