2 * Copyright (c) 2016-2019, 2020-2021 Tracey Emery <tracey@traceyemery.net>
3 * Copyright (c) 2004, 2005 Esben Norby <norby@openbsd.org>
4 * Copyright (c) 2004 Ryan McBride <mcbride@openbsd.org>
5 * Copyright (c) 2002, 2003, 2004 Henning Brauer <henning@openbsd.org>
6 * Copyright (c) 2001 Markus Friedl. All rights reserved.
7 * Copyright (c) 2001 Daniel Hartmeier. All rights reserved.
8 * Copyright (c) 2001 Theo de Raadt. All rights reserved.
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
24 #include <sys/ioctl.h>
25 #include <sys/types.h>
26 #include <sys/queue.h>
27 #include <sys/socket.h>
31 #include <netinet/in.h>
33 #include <arpa/inet.h>
50 #include "got_sockaddr.h"
51 #include "got_reference.h"
56 TAILQ_HEAD(files, file) files = TAILQ_HEAD_INITIALIZER(files);
58 TAILQ_ENTRY(file) entry;
64 struct file *newfile(const char *, int);
65 static void closefile(struct file *);
66 int check_file_secrecy(int, const char *);
69 int yyerror(const char *, ...)
70 __attribute__((__format__ (printf, 1, 2)))
71 __attribute__((__nonnull__ (1)));
72 int kw_cmp(const void *, const void *);
78 TAILQ_HEAD(symhead, sym) symhead = TAILQ_HEAD_INITIALIZER(symhead);
80 TAILQ_ENTRY(sym) entry;
87 int symset(const char *, const char *, int);
88 char *symget(const char *);
92 static struct gotwebd *gotwebd;
93 static struct server *new_srv;
94 static struct server *conf_new_server(const char *);
95 int getservice(const char *);
98 int get_addrs(const char *, struct server *, in_port_t);
99 int addr_dup_check(struct addresslist *, struct address *,
100 const char *, const char *);
101 int add_addr(struct server *, struct address *);
102 int host(const char *, struct server *,
103 int, in_port_t, const char *);
116 %token LISTEN WWW_PATH MAX_REPOS SITE_NAME SITE_OWNER SITE_LINK LOGO
117 %token LOGO_URL SHOW_REPO_OWNER SHOW_REPO_AGE SHOW_REPO_DESCRIPTION
118 %token MAX_REPOS_DISPLAY REPOS_PATH MAX_COMMITS_DISPLAY ON ERROR
119 %token SHOW_SITE_OWNER SHOW_REPO_CLONEURL PORT PREFORK RESPECT_EXPORTOK
120 %token UNIX_SOCKET UNIX_SOCKET_NAME SERVER CHROOT CUSTOM_CSS SOCKET
122 %token <v.string> STRING
123 %type <v.port> fcgiport
124 %token <v.number> NUMBER
125 %type <v.number> boolean
129 grammar : /* empty */
131 | grammar varset '\n'
133 | grammar server '\n'
134 | grammar error '\n' { file->errors++; }
137 varset : STRING '=' STRING {
140 if (isspace((unsigned char)*s)) {
141 yyerror("macro name cannot contain "
148 if (symset($1, $3, 0) == -1)
149 fatal("cannot store variable");
156 if (strcasecmp($1, "1") == 0 ||
157 strcasecmp($1, "on") == 0)
159 else if (strcasecmp($1, "0") == 0 ||
160 strcasecmp($1, "off") == 0)
163 yyerror("invalid boolean value '%s'", $1);
171 if ($1 != 0 && $1 != 1) {
172 yyerror("invalid boolean value '%lld'", $1);
179 fcgiport : PORT NUMBER {
180 if ($2 <= 0 || $2 > (int)USHRT_MAX) {
181 yyerror("invalid port: %lld", $2);
189 if ((val = getservice($2)) == -1) {
190 yyerror("invalid port: %s", $2);
200 main : PREFORK NUMBER {
201 if ($2 <= 0 || $2 > PROC_MAX_INSTANCES) {
202 yyerror("prefork is %s: %lld",
203 $2 <= 0 ? "too small" : "too large", $2);
206 gotwebd->prefork_gotwebd = $2;
210 yyerror("chroot path can't be an empty"
216 n = strlcpy(gotwebd->httpd_chroot, $2,
217 sizeof(gotwebd->httpd_chroot));
218 if (n >= sizeof(gotwebd->httpd_chroot)) {
219 yyerror("%s: httpd_chroot truncated", __func__);
225 | UNIX_SOCKET boolean {
226 gotwebd->unix_socket = $2;
228 | UNIX_SOCKET_NAME STRING {
229 n = snprintf(gotwebd->unix_socket_name,
230 sizeof(gotwebd->unix_socket_name), "%s%s",
231 gotwebd->httpd_chroot, $2);
233 (size_t)n >= sizeof(gotwebd->unix_socket_name)) {
234 yyerror("%s: unix_socket_name truncated",
243 server : SERVER STRING {
246 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
247 if (strcmp(srv->name, $2) == 0) {
248 yyerror("server name exists '%s'", $2);
254 new_srv = conf_new_server($2);
255 log_debug("adding server %s", $2);
261 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
262 if (strcmp(srv->name, $2) == 0) {
263 yyerror("server name exists '%s'", $2);
269 new_srv = conf_new_server($2);
270 log_debug("adding server %s", $2);
272 } '{' optnl serveropts2 '}' {
276 serveropts1 : REPOS_PATH STRING {
277 n = strlcpy(new_srv->repos_path, $2,
278 sizeof(new_srv->repos_path));
279 if (n >= sizeof(new_srv->repos_path)) {
280 yyerror("%s: repos_path truncated", __func__);
287 n = strlcpy(new_srv->site_name, $2,
288 sizeof(new_srv->site_name));
289 if (n >= sizeof(new_srv->site_name)) {
290 yyerror("%s: site_name truncated", __func__);
296 | SITE_OWNER STRING {
297 n = strlcpy(new_srv->site_owner, $2,
298 sizeof(new_srv->site_owner));
299 if (n >= sizeof(new_srv->site_owner)) {
300 yyerror("%s: site_owner truncated", __func__);
307 n = strlcpy(new_srv->site_link, $2,
308 sizeof(new_srv->site_link));
309 if (n >= sizeof(new_srv->site_link)) {
310 yyerror("%s: site_link truncated", __func__);
317 n = strlcpy(new_srv->logo, $2, sizeof(new_srv->logo));
318 if (n >= sizeof(new_srv->logo)) {
319 yyerror("%s: logo truncated", __func__);
326 n = strlcpy(new_srv->logo_url, $2,
327 sizeof(new_srv->logo_url));
328 if (n >= sizeof(new_srv->logo_url)) {
329 yyerror("%s: logo_url truncated", __func__);
335 | CUSTOM_CSS STRING {
336 n = strlcpy(new_srv->custom_css, $2,
337 sizeof(new_srv->custom_css));
338 if (n >= sizeof(new_srv->custom_css)) {
339 yyerror("%s: custom_css truncated", __func__);
345 | LISTEN ON STRING fcgiport {
346 if (get_addrs($3, new_srv, $4) == -1) {
347 yyerror("could not get addrs");
350 new_srv->fcgi_socket = 1;
352 | LISTEN ON SOCKET STRING {
353 if (strcasecmp($4, "off") == 0) {
354 new_srv->unix_socket = 0;
359 new_srv->unix_socket = 1;
361 n = snprintf(new_srv->unix_socket_name,
362 sizeof(new_srv->unix_socket_name), "%s%s",
363 gotwebd->httpd_chroot, $4);
365 (size_t)n >= sizeof(new_srv->unix_socket_name)) {
366 yyerror("%s: unix_socket_name truncated",
375 yyerror("max_repos is too small: %lld", $2);
378 new_srv->max_repos = $2;
380 | SHOW_SITE_OWNER boolean {
381 new_srv->show_site_owner = $2;
383 | SHOW_REPO_OWNER boolean {
384 new_srv->show_repo_owner = $2;
386 | SHOW_REPO_AGE boolean {
387 new_srv->show_repo_age = $2;
389 | SHOW_REPO_DESCRIPTION boolean {
390 new_srv->show_repo_description = $2;
392 | SHOW_REPO_CLONEURL boolean {
393 new_srv->show_repo_cloneurl = $2;
395 | RESPECT_EXPORTOK boolean {
396 new_srv->respect_exportok = $2;
398 | MAX_REPOS_DISPLAY NUMBER {
400 yyerror("max_repos_display is too small: %lld",
404 new_srv->max_repos_display = $2;
406 | MAX_COMMITS_DISPLAY NUMBER {
408 yyerror("max_commits_display is too small:"
412 new_srv->max_commits_display = $2;
416 serveropts2 : serveropts2 serveropts1 nl
423 optnl : '\n' optnl /* zero or more newlines */
435 yyerror(const char *fmt, ...)
442 if (vasprintf(&msg, fmt, ap) == -1)
443 fatalx("yyerror vasprintf");
445 logit(LOG_CRIT, "%s:%d: %s", file->name, yylval.lineno, msg);
451 kw_cmp(const void *k, const void *e)
453 return (strcmp(k, ((const struct keywords *)e)->k_name));
459 /* This has to be sorted always. */
460 static const struct keywords keywords[] = {
461 { "chroot", CHROOT },
462 { "custom_css", CUSTOM_CSS },
463 { "listen", LISTEN },
465 { "logo_url", LOGO_URL },
466 { "max_commits_display", MAX_COMMITS_DISPLAY },
467 { "max_repos", MAX_REPOS },
468 { "max_repos_display", MAX_REPOS_DISPLAY },
471 { "prefork", PREFORK },
472 { "repos_path", REPOS_PATH },
473 { "respect_exportok", RESPECT_EXPORTOK },
474 { "server", SERVER },
475 { "show_repo_age", SHOW_REPO_AGE },
476 { "show_repo_cloneurl", SHOW_REPO_CLONEURL },
477 { "show_repo_description", SHOW_REPO_DESCRIPTION },
478 { "show_repo_owner", SHOW_REPO_OWNER },
479 { "show_site_owner", SHOW_SITE_OWNER },
480 { "site_link", SITE_LINK },
481 { "site_name", SITE_NAME },
482 { "site_owner", SITE_OWNER },
483 { "socket", SOCKET },
484 { "unix_socket", UNIX_SOCKET },
485 { "unix_socket_name", UNIX_SOCKET_NAME },
487 const struct keywords *p;
489 p = bsearch(s, keywords, sizeof(keywords)/sizeof(keywords[0]),
490 sizeof(keywords[0]), kw_cmp);
498 #define MAXPUSHBACK 128
500 unsigned char *parsebuf;
502 unsigned char pushback_buffer[MAXPUSHBACK];
503 int pushback_index = 0;
511 /* Read character from the parsebuffer instead of input. */
512 if (parseindex >= 0) {
513 c = parsebuf[parseindex++];
522 return (pushback_buffer[--pushback_index]);
525 c = getc(file->stream);
527 yyerror("reached end of file while parsing "
532 c = getc(file->stream);
534 next = getc(file->stream);
539 yylval.lineno = file->lineno;
541 c = getc(file->stream);
557 if (pushback_index < MAXPUSHBACK-1)
558 return (pushback_buffer[pushback_index++] = c);
570 /* Skip to either EOF or the first real EOL. */
573 c = pushback_buffer[--pushback_index];
589 unsigned char buf[8096];
590 unsigned char *p, *val;
597 while (c == ' ' || c == '\t')
598 c = lgetc(0); /* nothing */
600 yylval.lineno = file->lineno;
603 while (c != '\n' && c != EOF)
604 c = lgetc(0); /* nothing */
606 if (c == '$' && parsebuf == NULL) {
612 if (p + 1 >= buf + sizeof(buf) - 1) {
613 yyerror("string too long");
616 if (isalnum(c) || c == '_') {
626 yyerror("macro '%s' not defined", buf);
645 } else if (c == '\\') {
646 next = lgetc(quotec);
649 if (next == quotec || c == ' ' || c == '\t')
651 else if (next == '\n') {
656 } else if (c == quotec) {
659 } else if (c == '\0') {
660 yyerror("syntax error");
663 if (p + 1 >= buf + sizeof(buf) - 1) {
664 yyerror("string too long");
669 yylval.v.string = strdup(buf);
670 if (yylval.v.string == NULL)
671 err(1, "yylex: strdup");
675 #define allowed_to_end_number(x) \
676 (isspace(x) || x == ')' || x ==',' || x == '/' || x == '}' || x == '=')
678 if (c == '-' || isdigit(c)) {
681 if ((unsigned)(p-buf) >= sizeof(buf)) {
682 yyerror("string too long");
686 } while (c != EOF && isdigit(c));
688 if (p == buf + 1 && buf[0] == '-')
690 if (c == EOF || allowed_to_end_number(c)) {
691 const char *errstr = NULL;
694 yylval.v.number = strtonum(buf, LLONG_MIN,
697 yyerror("\"%s\" invalid number: %s",
712 #define allowed_in_string(x) \
713 (isalnum(x) || (ispunct(x) && x != '(' && x != ')' && \
714 x != '{' && x != '}' && \
715 x != '!' && x != '=' && x != '#' && \
718 if (isalnum(c) || c == ':' || c == '_') {
721 if ((unsigned)(p-buf) >= sizeof(buf)) {
722 yyerror("string too long");
726 } while (c != EOF && (allowed_in_string(c)));
730 if (token == STRING) {
731 yylval.v.string = strdup(buf);
732 if (yylval.v.string == NULL)
733 err(1, "yylex: strdup");
738 yylval.lineno = file->lineno;
747 check_file_secrecy(int fd, const char *fname)
751 if (fstat(fd, &st)) {
752 log_warn("cannot stat %s", fname);
755 if (st.st_uid != 0 && st.st_uid != getuid()) {
756 log_warnx("%s: owner not root or current user", fname);
759 if (st.st_mode & (S_IWGRP | S_IXGRP | S_IRWXO)) {
760 log_warnx("%s: group writable or world read/writable", fname);
767 newfile(const char *name, int secret)
771 nfile = calloc(1, sizeof(struct file));
776 nfile->name = strdup(name);
777 if (nfile->name == NULL) {
782 nfile->stream = fopen(nfile->name, "r");
783 if (nfile->stream == NULL) {
784 /* no warning, we don't require a conf file */
789 check_file_secrecy(fileno(nfile->stream), nfile->name)) {
790 fclose(nfile->stream);
800 closefile(struct file *xfile)
802 fclose(xfile->stream);
808 add_default_server(void)
810 new_srv = conf_new_server(D_SITENAME);
811 log_debug("%s: adding default server %s", __func__, D_SITENAME);
815 parse_config(const char *filename, struct gotwebd *env)
817 struct sym *sym, *next;
819 if (config_init(env) == -1)
820 fatalx("failed to initialize configuration");
824 file = newfile(filename, 0);
826 add_default_server();
827 sockets_parse_sockets(env);
828 /* just return, as we don't require a conf file */
833 errors = file->errors;
836 /* Free macros and check which have not been used. */
837 TAILQ_FOREACH_SAFE(sym, &symhead, entry, next) {
838 if ((gotwebd->gotwebd_verbose > 1) && !sym->used)
839 fprintf(stderr, "warning: macro '%s' not used\n",
844 TAILQ_REMOVE(&symhead, sym, entry);
852 /* just add default server if no config specified */
853 if (gotwebd->server_cnt == 0)
854 add_default_server();
856 /* setup our listening sockets */
857 sockets_parse_sockets(env);
863 conf_new_server(const char *name)
865 struct server *srv = NULL;
867 srv = calloc(1, sizeof(*srv));
869 fatalx("%s: calloc", __func__);
871 n = strlcpy(srv->name, name, sizeof(srv->name));
872 if (n >= sizeof(srv->name))
873 fatalx("%s: strlcpy", __func__);
874 n = snprintf(srv->unix_socket_name,
875 sizeof(srv->unix_socket_name), "%s%s", D_HTTPD_CHROOT,
877 if (n < 0 || (size_t)n >= sizeof(srv->unix_socket_name))
878 fatalx("%s: snprintf", __func__);
879 n = strlcpy(srv->repos_path, D_GOTPATH,
880 sizeof(srv->repos_path));
881 if (n >= sizeof(srv->repos_path))
882 fatalx("%s: strlcpy", __func__);
883 n = strlcpy(srv->site_name, D_SITENAME,
884 sizeof(srv->site_name));
885 if (n >= sizeof(srv->site_name))
886 fatalx("%s: strlcpy", __func__);
887 n = strlcpy(srv->site_owner, D_SITEOWNER,
888 sizeof(srv->site_owner));
889 if (n >= sizeof(srv->site_owner))
890 fatalx("%s: strlcpy", __func__);
891 n = strlcpy(srv->site_link, D_SITELINK,
892 sizeof(srv->site_link));
893 if (n >= sizeof(srv->site_link))
894 fatalx("%s: strlcpy", __func__);
895 n = strlcpy(srv->logo, D_GOTLOGO,
897 if (n >= sizeof(srv->logo))
898 fatalx("%s: strlcpy", __func__);
899 n = strlcpy(srv->logo_url, D_GOTURL, sizeof(srv->logo_url));
900 if (n >= sizeof(srv->logo_url))
901 fatalx("%s: strlcpy", __func__);
902 n = strlcpy(srv->custom_css, D_GOTWEBCSS, sizeof(srv->custom_css));
903 if (n >= sizeof(srv->custom_css))
904 fatalx("%s: strlcpy", __func__);
906 srv->show_site_owner = D_SHOWSOWNER;
907 srv->show_repo_owner = D_SHOWROWNER;
908 srv->show_repo_age = D_SHOWAGE;
909 srv->show_repo_description = D_SHOWDESC;
910 srv->show_repo_cloneurl = D_SHOWURL;
911 srv->respect_exportok = D_RESPECTEXPORTOK;
913 srv->max_repos_display = D_MAXREPODISP;
914 srv->max_commits_display = D_MAXCOMMITDISP;
915 srv->max_repos = D_MAXREPO;
917 srv->unix_socket = 1;
918 srv->fcgi_socket = 0;
920 TAILQ_INIT(&srv->al);
921 TAILQ_INSERT_TAIL(&gotwebd->servers, srv, entry);
922 gotwebd->server_cnt++;
928 symset(const char *nam, const char *val, int persist)
932 TAILQ_FOREACH(sym, &symhead, entry) {
933 if (strcmp(nam, sym->nam) == 0)
938 if (sym->persist == 1)
943 TAILQ_REMOVE(&symhead, sym, entry);
947 sym = calloc(1, sizeof(*sym));
951 sym->nam = strdup(nam);
952 if (sym->nam == NULL) {
956 sym->val = strdup(val);
957 if (sym->val == NULL) {
963 sym->persist = persist;
964 TAILQ_INSERT_TAIL(&symhead, sym, entry);
969 cmdline_symset(char *s)
974 val = strrchr(s, '=');
978 sym = strndup(s, val - s);
980 fatal("%s: strndup", __func__);
982 ret = symset(sym, val + 1, 1);
989 symget(const char *nam)
993 TAILQ_FOREACH(sym, &symhead, entry) {
994 if (strcmp(nam, sym->nam) == 0) {
1003 getservice(const char *n)
1009 llval = strtonum(n, 0, UINT16_MAX, &errstr);
1011 s = getservbyname(n, "tcp");
1013 s = getservbyname(n, "udp");
1016 return ntohs(s->s_port);
1019 return (unsigned short)llval;
1023 host(const char *s, struct server *new_srv, int max,
1024 in_port_t port, const char *ifname)
1026 struct addrinfo hints, *res0, *res;
1028 struct sockaddr_in *sain;
1029 struct sockaddr_in6 *sin6;
1032 memset(&hints, 0, sizeof(hints));
1033 hints.ai_family = AF_UNSPEC;
1034 hints.ai_socktype = SOCK_STREAM; /* DUMMY */
1035 hints.ai_flags = AI_ADDRCONFIG;
1036 error = getaddrinfo(s, NULL, &hints, &res0);
1037 if (error == EAI_AGAIN || error == EAI_NODATA || error == EAI_NONAME)
1040 log_warnx("%s: could not parse \"%s\": %s", __func__, s,
1041 gai_strerror(error));
1045 for (res = res0; res && cnt < max; res = res->ai_next) {
1046 if (res->ai_family != AF_INET &&
1047 res->ai_family != AF_INET6)
1049 if ((h = calloc(1, sizeof(*h))) == NULL)
1054 if (ifname != NULL) {
1055 if (strlcpy(h->ifname, ifname, sizeof(h->ifname)) >=
1056 sizeof(h->ifname)) {
1057 log_warnx("%s: interface name truncated",
1064 h->ss.ss_family = res->ai_family;
1066 if (res->ai_family == AF_INET) {
1067 struct sockaddr_in *ra;
1068 sain = (struct sockaddr_in *)&h->ss;
1069 ra = (struct sockaddr_in *)res->ai_addr;
1070 got_sockaddr_inet_init(sain, &ra->sin_addr);
1072 struct sockaddr_in6 *ra;
1073 sin6 = (struct sockaddr_in6 *)&h->ss;
1074 ra = (struct sockaddr_in6 *)res->ai_addr;
1075 got_sockaddr_inet6_init(sin6, &ra->sin6_addr, 0);
1078 if (add_addr(new_srv, h))
1082 if (cnt == max && res) {
1083 log_warnx("%s: %s resolves to more than %d hosts", __func__,
1091 get_addrs(const char *addr, struct server *new_srv, in_port_t port)
1093 if (strcmp("", addr) == 0) {
1094 if (host("127.0.0.1", new_srv, 1, port, "127.0.0.1") <= 0) {
1095 yyerror("invalid listen ip: %s",
1099 if (host("::1", new_srv, 1, port, "::1") <= 0) {
1100 yyerror("invalid listen ip: %s", "::1");
1104 if (host(addr, new_srv, GOTWEBD_MAXIFACE, port, addr) <= 0) {
1105 yyerror("invalid listen ip: %s", addr);
1113 addr_dup_check(struct addresslist *al, struct address *h, const char *new_srv,
1114 const char *other_srv)
1118 char buf[INET6_ADDRSTRLEN];
1119 const char *addrstr;
1121 TAILQ_FOREACH(a, al, entry) {
1122 if (memcmp(&a->ss, &h->ss, sizeof(h->ss)) != 0 ||
1126 switch (h->ss.ss_family) {
1128 ia = &((struct sockaddr_in *)(&h->ss))->sin_addr;
1131 ia = &((struct sockaddr_in6 *)(&h->ss))->sin6_addr;
1134 yyerror("unknown address family: %d", h->ss.ss_family);
1137 addrstr = inet_ntop(h->ss.ss_family, ia, buf, sizeof(buf));
1140 yyerror("server %s: duplicate fcgi listen "
1141 "address %s:%d, already used by server %s",
1142 new_srv, addrstr, h->port, other_srv);
1144 log_warnx("server: %s: duplicate fcgi listen "
1145 "address %s:%d", new_srv, addrstr, h->port);
1149 yyerror("server: %s: duplicate fcgi listen "
1150 "address, already used by server %s",
1151 new_srv, other_srv);
1153 log_warnx("server %s: duplicate fcgi listen "
1154 "address", new_srv);
1165 add_addr(struct server *new_srv, struct address *h)
1169 /* Address cannot be shared between different servers. */
1170 TAILQ_FOREACH(srv, &gotwebd->servers, entry) {
1173 if (addr_dup_check(&srv->al, h, new_srv->name, srv->name))
1177 /* Tolerate duplicate address lines within the scope of a server. */
1178 if (addr_dup_check(&new_srv->al, h, NULL, NULL) == 0)
1179 TAILQ_INSERT_TAIL(&new_srv->al, h, entry);