chiark / gitweb /
www-cgi/: Decentralize the whitelist of environment variables.
[userv-utils] / www-cgi / ucgi.c
CommitLineData
6a580c17 1/*
2 * Usage: as CGI script
3 */
a33962ba 4/*
711a0748 5 * Copyright (C) 1998-1999,2003 Ian Jackson
a33962ba 6 *
7 * This is free software; you can redistribute it and/or modify it
8 * under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with userv-utils; if not, write to the Free Software
19 * Foundation, 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
20 *
21 * $Id$
22 */
6a580c17 23
24#include <stdio.h>
25#include <string.h>
26#include <ctype.h>
27#include <unistd.h>
28#include <sys/types.h>
29#include <sys/wait.h>
30
31#include "ucgi.h"
32
a8e8db26
MW
33static const char *const envok[] = {
34 "AUTH_TYPE",
35 "CONTENT_TYPE",
36 "CONTENT_LENGTH",
37 "DOCUMENT_ROOT",
38 "GATEWAY_INTERFACE",
39 "HTTP_*",
40 "HTTPS",
41 "PATH_INFO",
42 "PATH_TRANSLATED",
43 "QUERY_STRING",
44 "REMOTE_*",
45 "REQUEST_METHOD",
46 "REQUEST_URI",
47 "SCRIPT_*",
48 "SERVER_*",
49 0
50};
51
77a36cae
MW
52struct buildargs {
53 const char **v;
54 int n, max;
55};
56
57static void addarg(struct buildargs *args, const char *a) {
58 if (args->n > args->max) error("too many arguments");
59 args->v[args->n++]= a;
60}
61
f601a2c6
MW
62static void add_userv_var(const char *fulln,
63 const char *en, const char *ev, void *p) {
64 struct buildargs *args= p;
77a36cae
MW
65 size_t l;
66 char *a;
67
68 l= strlen(ev); if (l > MAX_ENVVAR_VALUE) error("environment variable too long");
69 a= xmalloc(strlen(en)+l+6);
70 sprintf(a,"-DE_%s=%s",en,ev);
71 addarg(args, a);
72}
73
6a580c17 74int main(int argc, const char **argv) {
77a36cae 75 char *username;
f601a2c6 76 const char *slash2, *pathi, *av;
6a580c17 77 size_t usernamelen, l;
77a36cae 78 struct buildargs args;
6a580c17 79 pid_t child, rchild;
77a36cae 80 int status;
6a580c17 81
82 l= strlen(argv[0]);
83 if (l>6 && !strcmp(argv[0]+l-6,"-debug")) debugmode= 1;
84
85 if (debugmode) {
86 if (fputs("Content-Type: text/plain\n\n",stdout)==EOF || fflush(stdout))
87 syserror("write stdout");
88 if (dup2(1,2)<0) { perror("dup stdout to stderr"); exit(-1); }
6a3086f1 89 D( printf(";;; UCGI\n"); )
6a580c17 90 }
91
92 if (argc > MAX_ARGS) error("too many arguments");
93
94 pathi= getenv("PATH_INFO");
95 if (!pathi) error("PATH_INFO not found");
6a3086f1
MW
96 D( if (debugmode) {
97 printf(";; find user name...\n"
98 ";; initial PATH_INFO = `%s'\n",
99 pathi);
100 } )
6a580c17 101 if (pathi[0] != '/' || pathi[1] != '~') error("PATH_INFO must start with /~");
102 slash2= strchr(pathi+2,'/'); if (!slash2) error("PATH_INFO must have more than one /");
103 usernamelen= slash2-(pathi+2);
104 if (usernamelen > MAX_USERNAME_LEN) error("PATH_INFO username too long");
105 username= xmalloc(usernamelen+1);
106 memcpy(username,pathi+2,usernamelen); username[usernamelen]= 0;
6a3086f1
MW
107 D( if (debugmode)
108 printf(";; user = `%s'; tail = `%s'\n", username, slash2); )
6a580c17 109 if (!isalpha(username[0])) error("username 1st character is not alphabetic");
110 xsetenv("PATH_INFO",slash2,1);
77a36cae 111
f601a2c6 112 args.n= 0; args.max= argc + MAX_ENVVARS + 10;
77a36cae 113 args.v= xmalloc(args.max * sizeof(*args.v));
6a580c17 114
77a36cae
MW
115 addarg(&args, "userv");
116 if (debugmode) addarg(&args, "-DDEBUG=1");
117
f601a2c6 118 filter_environment(FILTF_WILDCARD, "", envok, add_userv_var, &args);
6a580c17 119
77a36cae
MW
120 addarg(&args, username);
121 addarg(&args, "www-cgi");
122 while ((av= (*++argv))) addarg(&args, av);
123 addarg(&args, 0);
6a580c17 124
125 if (debugmode) {
6a3086f1 126 D( fflush(stdout); )
6a580c17 127 child= fork(); if (child==-1) syserror("fork");
128 if (child) {
129 rchild= waitpid(child,&status,0);
130 if (rchild==-1) syserror("waitpid");
131 printf("\nexit status %d %d\n",(status>>8)&0x0ff,status&0x0ff);
132 exit(0);
133 }
134 }
135
6a3086f1
MW
136 D( if (debugmode) {
137 int i;
138
139 printf(";; final command line...\n");
77a36cae
MW
140 for (i = 0; args.v[i]; i++)
141 printf(";; %s\n", args.v[i]);
6a3086f1
MW
142 fflush(stdout);
143 } )
144
77a36cae 145 execvp("userv",(char*const*)args.v);
6a580c17 146 syserror("exec userv");
147 return -1;
148}