Subversion Repositories wimsdev

Rev

Rev 10051 | Rev 12242 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
10 reyssat 1
/*    Copyright (C) 1998-2003 XIAO, Gang of Universite de Nice - Sophia Antipolis
2
 *
3
 *  This program is free software; you can redistribute it and/or modify
4
 *  it under the terms of the GNU General Public License as published by
5
 *  the Free Software Foundation; either version 2 of the License, or
6
 *  (at your option) any later version.
7
 *
8
 *  This program is distributed in the hope that it will be useful,
9
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
10
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11
 *  GNU General Public License for more details.
12
 *
13
 *  You should have received a copy of the GNU General Public License
14
 *  along with this program; if not, write to the Free Software
15
 *  Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
16
 */
8185 bpr 17
 
8067 bpr 18
/* line input / output / translation routines
19
 * and error routines
20
 */
8185 bpr 21
#include <utime.h>
22
#include <sys/socket.h>
23
#include <sys/un.h>
10 reyssat 24
 
8185 bpr 25
#include "wims.h"
26
 
10 reyssat 27
int is_class_module=0;
28
 
29
int trusted_module(void);
30
void phtml_put_base(char *fname,int cache);
31
void module_error(char msg[]);
32
void user_error(char msg[]);
33
void accessfile(char *content, char *type, char *s,...);
34
int remove_tree(char *p);
35
void output(char *s,...);
36
char *_getvar(char *vname);
37
int checkhost(char *hlist);
38
 
39
char *lastdata;
40
char lastdatafile[MAX_FNAME+1];
41
char *datacache[DATAFIELD_LIMIT];
42
int  nextdatacache;
43
struct stat ftst;
44
char lastftest[MAX_FNAME+1];
45
int lastftype;
46
char outbuf[8192];
47
char *outptr;
48
 
8185 bpr 49
/* These modules can execute private programs.
50
 * adm/ modules are always trusted, so need no definition here.
51
 */
10 reyssat 52
char *trusted_modules="";
8343 bpr 53
/* bit 0: module is not trusted.
54
  * bit 1: file in wimshome.
55
  * bit 2: readdef or file in writable directory.
56
  */
10 reyssat 57
int untrust=0;  /* non-zero if user detrusts the module. */
58
 
59
int error_status=0;
60
char pidbuf[32];
61
 
62
void delete_pid(void);
63
 
8343 bpr 64
/* Internal use only */
10 reyssat 65
void _debug(char *s,...)
66
{
67
    va_list vp;
68
    char buf[MAX_LINELEN+1];
69
 
70
    va_start(vp,s);
71
    vsnprintf(buf,sizeof(buf),s,vp);
72
    va_end(vp);
73
    setvar("debug",buf); module_error("debug");
74
    exit(1);
75
}
76
 
77
 
8343 bpr 78
/* HTTP response header for non-processed CGI interface */
10 reyssat 79
void nph_header(int code)
80
{
81
    char *cstr;
82
    switch(code) {
5505 bpr 83
      case 200: cstr="OK"; break;
84
      case 301: cstr="Moved Permanently"; break;
85
      case 302: cstr="Moved Temporarily"; break;
86
      case 420: cstr="WIMS Nested Error"; break;
87
      case 450: cstr="WIMS User Error"; break;
88
      case 500: cstr="WIMS Internal Error"; break;
7646 bpr 89
      case 550: cstr="WIMS Module Error"; break;
5505 bpr 90
      default: cstr="ERROR"; break;
10 reyssat 91
    }
92
    if(httpd_type!=httpd_wims) printf("Status: %d %s\r\n",code,cstr);
93
    else {
5505 bpr 94
      char *p, tbuf[256];
95
      mystrncpy(tbuf,ctime(&nowtime),sizeof(tbuf));
96
      for(p=tbuf+strlen(tbuf);p>=tbuf && (*(p-1)=='\n' || *(p-1)=='\r'); p--);
97
      *p=0;
98
      printf("HTTP/1.0 %d %s\r\n\
10 reyssat 99
Date: %s\r\n\
100
Connection: close\r\n\
101
",code,cstr,tbuf);
102
    }
103
}
104
 
105
void flushoutput(void)
106
{
107
    int l2;
108
    if(outptr<=outbuf) return;
109
    l2=outptr-outbuf;
3843 kbelabas 110
    if(lastout_file!=-1) (void)write(lastout_file,outbuf,l2);
10 reyssat 111
    else fwrite(outbuf,l2,1,stdout);
112
    outptr=outbuf;
113
}
114
 
115
void internal_warn(char msg[])
116
{
117
    char buf[1024];
118
    fprintf(stderr,"wims: %s\n%s\n",msg,strerror(errno));
119
    snprintf(buf,sizeof(buf),"%s: %s\n",nowstr,msg);
120
    accessfile(buf,"a","%s/internal_error.log",log_dir);
121
}
122
 
8343 bpr 123
/* Internal error: panic and forget about requester. */
10 reyssat 124
void internal_error(char msg[])
125
{
126
    if(error_status<2) {
5505 bpr 127
      nph_header(500);
128
      printf("Cache-Control: no-cache\nPragma: no-cache\r\n\
10 reyssat 129
Content-type: text/plain\r\n\r\n\r\n\
130
WIMS panick! %s\n%s\n",msg,strerror(errno));
5505 bpr 131
      error_status=2; internal_warn(msg);
10 reyssat 132
    }
133
    delete_pid(); exit(1);
134
}
135
 
136
void tex_nospace(char *p)
137
{
138
    char *p1, *p2;
139
    char buf[MAX_LINELEN+1];
140
    for(p1=buf,p2=p;*p2 && p1-buf<MAX_LINELEN-4;p2++) {
5505 bpr 141
      if(!isspace(*p2)) {*p1++=*p2;continue;}
142
      while(isspace(*p2)) p2++;
7646 bpr 143
      if(*(p1-1)=='\\' ||
5505 bpr 144
         (p1>buf && myisalnum(*(p1-1)) && myisalnum(*p2)))
145
        *p1++=' ';
146
      *p1++=*p2;
10 reyssat 147
    }
148
    *p1++=0; memmove(p,buf,p1-buf);
149
}
150
 
151
void nametoolong(char *p)
152
{
153
    char buf[MAX_FNAME+17];
154
    snprintf(buf,sizeof(buf),"%s...",p);
155
    force_setvar("wims_error_data",buf);
156
    module_error("file_name_too_long");
157
}
158
 
159
off_t ftest_size;
160
 
8343 bpr 161
/* A simple front-end of stat(). */
10 reyssat 162
int ftest(char *fname)
163
{
164
    if(strcmp(fname,lastftest)==0) return lastftype;
165
/* if(fname[0]=='/' || fname[0]=='.') fprintf(stderr,"ftest: %s\n",fname); */
166
    mystrncpy(lastftest,fname,sizeof(lastftest));
167
    if(stat(fname,&ftst)) return lastftype=-1;
168
    ftest_size=ftst.st_size;
169
    if(S_ISREG(ftst.st_mode)) {
5505 bpr 170
      if((ftst.st_mode&(S_IXUSR|S_IXGRP|S_IXOTH))!=0) return lastftype=is_exec;
171
      else return lastftype=is_file;
10 reyssat 172
    }
173
    if(S_ISDIR(ftst.st_mode)) return lastftype=is_dir;
174
    if(S_ISFIFO(ftst.st_mode)) return lastftype=is_fifo;
175
    if(S_ISSOCK(ftst.st_mode)) return lastftype=is_socket;
176
    return lastftype=is_unknown;
177
}
178
 
179
char fnbuf[MAX_FNAME+1];
180
 
8343 bpr 181
/* make a filename and check length */
10 reyssat 182
char *mkfname(char buf[], char *s,...)
183
{
184
    va_list vp;
185
    char *p;
186
 
187
    if(buf==NULL) p=fnbuf; else p=buf;
188
    va_start(vp,s);
189
    vsnprintf(p,MAX_FNAME,s,vp);
190
    va_end(vp);
191
    if(strlen(p)>=MAX_FNAME-1) nametoolong(p);
192
    return p;
193
}
194
 
195
void sysmask_trigger(char *s)
196
{
197
    char buf[MAX_FNAME+1];
198
    struct stat st;
199
    mkfname(buf,"%s/%s",sysmask_trigger_dir,s);
200
    stat(buf,&st);
201
}
202
 
8343 bpr 203
/* read-in a file into buffer. Use open() and read().
5505 bpr 204
       * Return buffer address which will be malloc'ed if buf=NULL. */
10 reyssat 205
char *readfile(char *fname, char buf[], long int buflen)
206
{
207
    int fd, t, st;
208
    long int l, lc;
209
    char *bf;
210
    t=0; if(buf) buf[0]=0;
211
    st=ftest(fname); if(st!=is_file) {
5505 bpr 212
      if(st==is_exec) { /* refuse to open executable file */
213
          setvar("executable",fname); module_error("executable");
214
      }
215
      return NULL;
10 reyssat 216
    }
217
    l=ftst.st_size; if(l<0) return NULL;
218
    if(l>=buflen) {
5505 bpr 219
      if(buflen<MAX_LINELEN) l=buflen-1;
220
      else {
221
          if(strncmp(fname,"modules/",strlen("modules/"))==0) {
222
            setvar(error_data_string,fname); module_error("file_too_long");
223
          }
224
          else user_error("cmd_output_too_long");
225
      }
10 reyssat 226
    }
227
    fd=open(fname,O_RDONLY); if(fd==-1) return NULL;
228
    if(buf==NULL) bf=xmalloc(l+8); else {bf=buf;if(l==0) {t=1; l=buflen-1;}}
229
    lc=read(fd,bf,l); close(fd);
7646 bpr 230
    if(lc<0 || lc>l || (lc!=l && t==0))
5505 bpr 231
      {if(buf==NULL) free(bf); else buf[0]=0; return NULL;}
10 reyssat 232
    bf[lc]=0; _tolinux(bf); return bf;
233
}
234
 
8343 bpr 235
/* Get a line in a stored working file.
5505 bpr 236
       * Buffer length is always MAX_LINELEN. */
10 reyssat 237
int wgetline(char buf[], size_t buflen, WORKING_FILE *f)
238
{
239
    int i,j; unsigned int n;
240
    i=f->linepointer; buf[0]=0;
241
    if(i>=f->linecnt || f->textbuf==NULL) return EOF;
242
    n=f->lines[i].llen;
243
    if(n>=buflen) n=buflen-1;
11125 georgesk 244
    if(n>0) memmove(buf,f->lines[i].address,n);
245
    buf[n]=0;
10 reyssat 246
    for(j=i+1;j<f->linecnt && f->lines[j].isstart==0;j++);
247
    f->l=i; f->linepointer=j;
248
    if(j>=f->linecnt && n==0) return EOF; else return n;
249
}
250
 
251
int get_cached_file(char *name)
252
{
253
    int i,l,flag;
254
    l=strlen(name); if(l>=127) return -1;
255
    if(strncmp(module_prefix,module_dir,strlen(module_dir))!=0) flag=8; else flag=0;
256
    for(i=0;i<mcachecnt;i++) {
5505 bpr 257
      if(flag==mcache[i].nocache && strcmp(name,mcache[i].name)==0) {
258
          memmove(&m_file,mcache+i,sizeof(WORKING_FILE));
259
          m_file.nocache|=4;
260
          return i;
261
      }
10 reyssat 262
    }
263
    return -1;
264
}
265
 
8343 bpr 266
/* Open a work file. Returns 0 if OK. */
10 reyssat 267
int open_working_file(WORKING_FILE *f, char *fname)
268
{
269
    char *p, *q;
270
    void *vp;
271
    int i,j,k,laststart,lc[LINE_LIMIT];
272
 
273
    f->linecnt=f->linepointer=0;
274
    f->for_idx=f->nocache=0;
275
    f->l=-1; f->lines=NULL;
10051 bpr 276
    strncpy(f->filepath,fname,MAX_FNAME+1);
10 reyssat 277
    f->textbuf=readfile(fname,NULL,WORKFILE_LIMIT);
278
    if(f->textbuf==NULL) return -1;
279
    p=f->textbuf; if(*p) {
5505 bpr 280
      for(i=0,p--; i<LINE_LIMIT-1 && p!=NULL;p=strchr(p,'\n')) {
281
          if(i>0) *p=0;
282
          lc[i++]=(++p-f->textbuf);
283
      }
10 reyssat 284
    }
285
    else i=0;
286
    if(i>=LINE_LIMIT-1) module_error("file_too_long");
287
    lc[i]=lc[i-1]+strlen(f->textbuf+lc[i-1])+1;
288
    f->textbuf[lc[i]]=0;
289
    f->linecnt=i; laststart=0;
290
    f->for_stack=xmalloc(MAX_FOR_LEVEL*sizeof(FOR_STACK)+(i+1)*sizeof(LINE_STRUCT));
291
    vp=f->for_stack+MAX_FOR_LEVEL; f->lines=vp;
292
    for(j=0;j<i;j++) {
5505 bpr 293
      f->lines[j].address=p=(f->textbuf)+lc[j];
294
      f->lines[j].llen=lc[j+1]-lc[j]-1;
295
      (f->lines[j]).execcode=(f->lines[j]).varcode=-1;
296
      if(j==0) goto normal;
297
      q=f->lines[laststart].address+f->lines[laststart].llen-1;
298
      if(q>=f->textbuf && *q=='\\') {
299
          f->lines[laststart].llen+=f->lines[j].llen; *q='\n';
300
          f->lines[j].isstart=f->lines[j].llen=0;
301
          memmove(q+1,p,lc[j+1]-lc[j]);
302
      }
303
      else {
304
          normal: for(q=p;myislspace(*q);q++);
305
          f->lines[j].isstart=1; laststart=j; k=0;
306
          switch(*q) {
307
                  /* isstart: bit 1 = start.
308
                   * bit 2 = exec
309
                   * bit 3 (4) = label
310
                   * bit 4 (8) = hard comment (!!)
311
                   * bit 5 (16) = soft comment (#) */
312
            case exec_prefix_char: {
313
                if(myisalpha(q[1])) f->lines[j].isstart=3;
314
                else f->lines[j].isstart=9;
315
                k=1; break;
316
            }
317
            case label_prefix_char: {f->lines[j].isstart=5; k=1; break;}
318
            case comment_prefix_char: {f->lines[j].isstart=17; break;}
319
            default: {f->lines[j].isstart=1; break;}
320
          }
321
          if(k && q>p) {f->lines[j].address=q;f->lines[j].llen-=q-p;}
322
      }
10 reyssat 323
    }
324
    f->lines[i].isstart=1; f->lines[i].llen=0;
325
    f->lines[i].address=(f->textbuf)+lc[i];
326
    mfilecnt++; return 0;
327
}
328
 
8343 bpr 329
/* close an earlier opened working file */
10 reyssat 330
void close_working_file(WORKING_FILE *f, int cache)
331
{
332
    f->linepointer=f->l=0;
333
    if(cache && untrust==0 && mcachecnt<MAX_MCACHE && (f->nocache&7)==0) {
5505 bpr 334
      memmove(mcache+mcachecnt,f,sizeof(WORKING_FILE));
335
      mcachecnt++;
10 reyssat 336
    }
337
    else if((f->nocache&4)==0) {
5505 bpr 338
      if(f->for_stack!=NULL) free(f->for_stack);
339
      if(f->textbuf!=NULL) free(f->textbuf);
10 reyssat 340
    }
341
    f->for_stack=NULL; f->textbuf=NULL; f->linecnt=0;
342
}
343
 
344
void free_mcache(void)
345
{
346
    int i;
347
    untrust=0;
348
    for(i=mcachecnt-1;i>=0;i--) close_working_file(mcache+i,0);
349
    mcachecnt=0;
350
}
351
 
352
void cleantmpdir(void);
353
void user_error_log(char msg[]);
354
 
355
void nested_error(char msg[])
356
{
357
    fprintf(stderr,"\nNested error! %s\n",msg);
358
    nph_header(420);
359
    printf("\r\n\r\nWIMS error processing aborted on nested error.\r\n\r\n%s\r\n",msg);
360
    delete_pid(); exit(1);
361
}
362
 
8343 bpr 363
/* Send an error message to requester and exit.
364
 * This is for user errors, language-sensitive.
365
 */
10 reyssat 366
void user_error(char msg[])
367
{
368
    char erfname[MAX_FNAME+1];
369
 
370
    if(error_status) nested_error(msg);
371
    error_status=1;
372
    mkfname(erfname,"%s.%s",user_error_msg_file,lang);
373
    if(ftest(erfname)!=is_file) internal_error("user_error(): error message file not found.\n\
374
Bad installation.");
375
    force_setvar("wims_user_error",msg);
7646 bpr 376
    if(strcmp(msg,"threshold")!=0) user_error_log(msg);
377
    memmove(module_prefix,".",2);
10 reyssat 378
    if(lastout_file!=-1 && outputing) {
5505 bpr 379
      flushoutput(); close(lastout_file); lastout_file=-1;
10 reyssat 380
    }
381
    nph_header(450);
7646 bpr 382
    phtml_put_base(erfname,0);
383
    if(strcmp(msg,"double_click")!=0) delete_pid();
10 reyssat 384
    else {
5505 bpr 385
      cleantmpdir(); flushlog();
10 reyssat 386
    }
387
    flushoutput(); exit(0);
388
}
389
 
390
void module_error_log(char msg[]);
391
 
8343 bpr 392
/* Messages for module errors. English only.
393
 * This is really rudimentary for the time being.
394
 */
10 reyssat 395
void module_error(char msg[])
396
{
397
    int send=0;
398
    char *p;
399
    WORKING_FILE mf;
400
 
401
    if(error_status) nested_error(msg);
402
    error_status=1; untrust=0;
403
    module_error_log(msg);
404
    nph_header(550);
405
    printf("Server: %s %s (%s)\r\n", SHORTSWNAME,wims_version,LONGSWNAME);
406
    p=getvar("wims_main_font");
407
    if(p!=NULL && *p!=0) printf("Content-type: text/plain; charset=%s\r\n\r\n",p);
408
    else printf("Content-type: text/plain\r\n\r\n");
409
    p=getvar(ro_name[ro_module]); if(p==NULL) p="???";
410
    printf("ERROR.\n\nwims has detected an error in the module '%s'.",p);
411
    if(m_file.l>=0) printf("\n\nIn file '%s', line %d:",
5505 bpr 412
                     m_file.name,m_file.l+1);
10 reyssat 413
    printf(" %s.\n\n",msg);
414
    if(open_working_file(&mf,mkfname(NULL,"%s.%s",module_error_msg_file,lang))!=0)
415
      internal_error("module_error(): error message file not found.");
416
    while(wgetline(tmplbuf,MAX_LINELEN,&mf)!=EOF) {
5505 bpr 417
      if(tmplbuf[0]!=tag_prefix_char) {
418
          if(send) {substit(tmplbuf); puts(tmplbuf);}
419
          continue;
420
      }
421
      strip_trailing_spaces(tmplbuf);
422
      if(tmplbuf[1]==0 || strcmp(msg,tmplbuf+1)==0) send=1;
423
      else send=0;
10 reyssat 424
    }
425
    close_working_file(&mf,0);
426
    outptr=outbuf; delete_pid(); exit(1);
427
}
428
 
5505 bpr 429
/* Output kernel routine */
10 reyssat 430
void _output_(char *s)
431
{
432
    int l,l2;
433
    l=strlen(s); output_length+=l;
434
    if(output_length>=OUTPUT_LENGTH_LIMIT) {
5505 bpr 435
      module_error("output_too_long"); return;
10 reyssat 436
    }
437
    l2=sizeof(outbuf)-(outptr-outbuf);
438
    put: if(l<=l2) {
5505 bpr 439
      memmove(outptr,s,l); outptr+=l; return;
10 reyssat 440
    }
441
    memmove(outptr,s,l2); s+=l2; l-=l2;
3843 kbelabas 442
    if(lastout_file!=-1) (void)write(lastout_file,outbuf,sizeof(outbuf));
10 reyssat 443
    else fwrite(outbuf,sizeof(outbuf),1,stdout);
444
    outptr=outbuf; l2=sizeof(outbuf); goto put;
445
}
446
 
5505 bpr 447
/* Output with no var. */
10 reyssat 448
void output0(char buf[])
449
{
450
    char *p1, *p2, *ps;
451
    int dynsave;
452
    if(backslash_insmath) {
5505 bpr 453
     ps=buf; dynsave=instex_usedynamic;
454
     for(p1=strstr(buf,"\\("); p1; p1=strstr(p2,"\\(")) {
455
         p2=find_matching(p1+2,')');
456
         if(p2==NULL) break;
457
         if(p1>buf && *(p1-1)=='\\') continue;
458
         *p1=0; if(*(p2-1)=='\\') *(p2-1)=0; *p2++=0; _output_(ps); ps=p2;
459
         instex_usedynamic=1; insmath(p1+2);
460
     }
11125 georgesk 461
     if(*ps) _output_(ps);
462
     instex_usedynamic=dynsave;
10 reyssat 463
    }
464
    else _output_(buf);
465
}
466
 
5505 bpr 467
/* Output routine */
10 reyssat 468
void output(char *s,...)
469
{
470
    va_list vp;
471
    char buf[4*MAX_LINELEN+1];
472
 
473
    va_start(vp,s);
474
    vsnprintf(buf,sizeof(buf),s,vp);
475
    va_end(vp);
476
    output0(buf);
477
}
478
 
8343 bpr 479
/* read in tmpf in tmp directory, and places in p.
480
 * Maximal length: MAX_LINELEN.
481
 */
10 reyssat 482
void read_tmp_file(char *p, const char *fname)
483
{
484
    char *name, *pp;
485
    name=mkfname(NULL,"%s/%s",tmp_dir,fname);
486
    if(!exec_is_module || !outputing || !direct_exec
487
       || strcmp(fname,"exec.out")!=0) {
5505 bpr 488
      readfile(name,p,MAX_LINELEN);
489
      pp=getvar("wims_exec_dollar_double");
490
      if(pp && strcmp(pp,"yes")==0) {
491
          for(pp=strchr(p,'$'); pp; pp=strchr(pp+2,'$'))
492
            string_modify(p,pp,pp+1,"$$");
493
      }
10 reyssat 494
    }
495
    else {
5505 bpr 496
      char *s;
497
      s=readfile(name,NULL,OUTPUT_LENGTH_LIMIT);
498
      if(s==NULL) {*p=0; return;}
499
      if(memcmp(s,"Error: ", strlen("Error: "))==0) mystrncpy(p,s,MAX_LINELEN);
500
      output_length+=strlen(s);
501
      if(output_length>=OUTPUT_LENGTH_LIMIT) module_error("output_too_long");
502
      else _output_(s);
503
      free(s); *p=0;
504
      chmod(name,S_IRUSR|S_IWUSR);
10 reyssat 505
    }
506
}
507
 
8343 bpr 508
/* verify whether the module is trusted.
509
 * Returns 1 if yes, 0 if no. -1 for error.
510
 */
10 reyssat 511
int trusted_module(void)
512
{
513
    char *modname, *w, buf[MAX_LINELEN+1];
514
    int i,n;
5505 bpr 515
    static int _trusted=-1;      /* avoid repeated computations */
7646 bpr 516
 
10 reyssat 517
    if(untrust&255) return 0;
518
    if(_trusted>=0) return _trusted;
519
    modname=getvar(ro_name[ro_module]);
520
    if(modname==NULL || *modname==0) return 0;
7646 bpr 521
    if(memcmp(modname,"adm/",strlen("adm/"))==0 ||
522
       memcmp(modname,"classes/",strlen("classes/"))==0 ||
10 reyssat 523
       strcmp(modname,home_module)==0 ||
524
       memcmp(modname,"help/",strlen("help/"))==0) {
5505 bpr 525
      tr:
526
      if(memcmp(modname,"classes/",strlen("classes/"))==0)
527
        is_class_module=1;
528
      setenv("trusted_module","yes",1);
529
      return _trusted=1;
10 reyssat 530
    }
531
    n=wordnum(trusted_modules); for(i=0;i<n;i++) {
5505 bpr 532
      w=fnd_word(trusted_modules,i+1,buf);
533
      if(strcmp(w,modname)==0) goto tr;
10 reyssat 534
    }
535
    return _trusted=0;
536
}
537
 
8343 bpr 538
/* file should be in the module directory, but
539
 * it may also be somewhere else.
540
 * buf[] requires MAX_FNAME+1 length.
541
 * Returns 0 if found.
542
 */
10 reyssat 543
int find_module_file(char *fname, char buf[], int mode)
544
{
545
    char *p, dtest[32];
7646 bpr 546
 
10 reyssat 547
    fname=find_word_start(fname);
548
    if(*fname==0) return -1;
8343 bpr 549
/* Name checking: no directory backtracing. */
10 reyssat 550
    if(strstr(fname,parent_dir_string)!=NULL) {
5505 bpr 551
      setvar(error_data_string,fname); module_error("illegal_fname");
552
      return -1;
10 reyssat 553
    }
554
    p=strchr(fname,'/'); if(p==NULL || p>fname+10) goto openit;
555
    memmove(dtest,fname,p-fname); dtest[p-fname]=0;
556
    if(strcmp(dtest,"datamodule")==0) {
5505 bpr 557
      mkfname(buf,"modules/data%s",p); goto lastopen;
10 reyssat 558
    }
559
    if(strcmp(dtest,"wimshome")==0 && trusted_module()) {
5505 bpr 560
      mkfname(buf,"%s%s",getvar("wims_home"),p); goto lastopen;
10 reyssat 561
    }
562
    if(strcmp(dtest,"writable")==0) {
5505 bpr 563
      if(strncmp(p+1,"TEMP_",5)==0 && strchr(p+1,'/')==NULL) {
564
          mkfname(buf,"%s/%s",tmp_dir,p+1);
565
      }
566
      else {
567
          mkfname(buf,"w/%s/%s",module_prefix,p+1);
568
      }
7646 bpr 569
      untrust|=4;
10 reyssat 570
    }
571
    else {
5505 bpr 572
      openit: mkfname(buf,"%s/%s",module_prefix,fname);
10 reyssat 573
    }
574
    if(mode) return 0;
575
    if(ftest(buf)!=is_file) {
5505 bpr 576
      if(lastftype==is_exec) {
10 reyssat 577
isexec:
5505 bpr 578
          setvar("executable",fname); module_error("executable");
579
          return -1;
580
      }
7646 bpr 581
      if(strncmp(fname,"adm/",4)==0 &&
5505 bpr 582
         (!trusted_module() || is_class_module)) return -1;
583
      mkfname(buf,"scripts/%s",fname);
584
      lastopen:
585
      if(mode) return 0;
586
      if(ftest(buf)!=is_file) {
587
          if(lastftype==is_exec) goto isexec;
588
          else return -1;
589
      }
10 reyssat 590
    }
591
    return 0;
592
}
593
 
8343 bpr 594
/* check whether a file is user-submitted
595
 * This is deprecated because of the wimshome/ method.
596
 */
10 reyssat 597
/* int user_file(char *name) {
598
    if(name[0]=='/' || name[0]=='.' ||
7646 bpr 599
       strstr(name,"classes/")!=NULL ||
10 reyssat 600
       strstr(name,"forums/")!=NULL ||
601
       strstr(name,"sessions/")!=NULL ||
602
       strstr(name,"doc/")!=NULL) return 1; else return 0;
8343 bpr 603
}
604
 */
10 reyssat 605
 
8343 bpr 606
/* returns 1 if violation */
10 reyssat 607
int datafile_check(char *name) {
608
    if((untrust&255)==0) return 0;
609
    if(strncmp(name,"data/",strlen("data/"))==0) return 0;
610
    if(strncmp(name,"authors/",strlen("authors/"))==0) return 0;
5333 bpr 611
    if(strncmp(name,"datamodule/",strlen("datamodule/"))==0) return 0;
10 reyssat 612
    return 1;
613
}
614
 
8343 bpr 615
/* returns 0 if success */
10 reyssat 616
void readdatafile(char *name)
617
{
618
    char *pp;
619
    if(strcmp(name,lastdatafile)==0) return;
620
    lastdata[0]=0; readfile(name,lastdata,WORKFILE_LIMIT);
621
    mystrncpy(lastdatafile,name,sizeof(lastdatafile));
622
    datacache[0]=lastdata; nextdatacache=1;
623
    if(lastdata[0]==tag_string[1]) {
5505 bpr 624
      datacache[1]=lastdata; nextdatacache++;
10 reyssat 625
    }
626
    pp=strstr(lastdata,tag_string);
627
    if(pp) datacache[nextdatacache]=pp;
628
    else datacache[nextdatacache]=lastdata+strlen(lastdata);
629
}
630
 
631
char *_nextdata(char *p)
632
{
633
    char *pp;
634
    if(!*p) return p;
635
    pp=strstr(p,tag_string);
636
    if(pp) return pp;
637
    else return p+strlen(p);
638
}
639
 
8343 bpr 640
/* datafile structure: number of records.
641
 * tag=1 if direct access
642
 */
10 reyssat 643
unsigned int datafile_recordnum(char *p)
644
{
645
    char nbuf[MAX_LINELEN+1], *pp;
646
    int i, t, ret;
647
 
648
    t=untrust; ret=0;
649
    if(direct_datafile) mystrncpy(nbuf,p,sizeof(nbuf));
650
    else if(datafile_check(p)!=0 || find_module_file(p,nbuf,0)) goto ret;
7646 bpr 651
    readdatafile(nbuf);
10 reyssat 652
    for(i=nextdatacache, pp=datacache[i]; *pp;) {
5505 bpr 653
      pp=_nextdata(pp+1); i++;
654
      if(i<DATAFIELD_LIMIT) {
655
          datacache[i]=pp; nextdatacache=i;
656
      }
10 reyssat 657
    }
658
    ret=i-1;
659
    ret:
660
    untrust=t;
661
    return ret;
662
}
663
 
8343 bpr 664
/* datafile structure: find record n, starting from 1 */
10 reyssat 665
char *datafile_fnd_record(char *p, int n, char bf[])
666
{
667
    char nbuf[MAX_LINELEN+1], *pp, *p2;
668
    int i, t;
669
 
670
    bf[0]=0; t=untrust;
671
    if(n<0) goto ret;
672
    if(direct_datafile) mystrncpy(nbuf,p,sizeof(nbuf));
673
    else if(datafile_check(p)!=0 || find_module_file(p,nbuf,0)) goto ret;
674
    readdatafile(nbuf); if(*lastdata==0) goto ret;
675
    if(n>nextdatacache) {
5505 bpr 676
      for(i=nextdatacache, pp=datacache[i]; i<n && *pp;) {
677
          pp=_nextdata(pp+1); i++;
678
          if(i<DATAFIELD_LIMIT) {
679
            datacache[i]=pp; nextdatacache=i;
680
          }
681
      }
10 reyssat 682
    }
683
    else pp=datacache[n];
684
    if(!*pp) goto ret;
685
    if(n>1 || (n==1 && *pp!=tag_string[1])) pp+=strlen(tag_string);
686
    else if(n==1) pp+=strlen(tag_string)-1;
687
    if(n<nextdatacache) p2=datacache[n+1];
688
    else {
5505 bpr 689
      p2=strstr(pp,tag_string); if(p2==NULL) p2=pp+strlen(pp);
690
      if(n<DATAFIELD_LIMIT-1 && n==nextdatacache) {
691
          nextdatacache++; datacache[nextdatacache]=p2;
692
      }
10 reyssat 693
    }
694
    if(p2-pp>=MAX_LINELEN) p2=pp+MAX_LINELEN-1;
695
    if(p2<pp) p2=pp;
696
    memmove(bf,pp,p2-pp); bf[p2-pp]=0;
697
    ret:
698
    untrust=t; return bf;
699
}
700
 
701
char hex2char(char c1, char c2)
702
{
703
    char tbuf[16];
704
    if(c1<'0' || c1>'f' || c2<'0' || c2>'f') {
705
invl:
5505 bpr 706
      snprintf(tbuf,sizeof(tbuf),"%%%c%c",c1,c2);
707
      setvar(error_data_string,tbuf);
708
      user_error("invalid_char_in_query_string");
10 reyssat 709
    }
710
    c1=toupper(c1);c2=toupper(c2);
711
    if(c1>'9' && c1<'A') goto invl;
712
    if(c2>'9' && c2<'A') goto invl;
713
    if(c1>'F' || c2>'F') goto invl;
714
    if(c1>='A') c1=c1-'A'+'9'+1;
715
    if(c2>='A') c2=c2-'A'+'9'+1;
716
    return (c1-'0')*16+c2-'0';
717
}
718
 
8343 bpr 719
/* Converts back http escaped chars, slight. Does not check buffer length.
720
 * Returns converted string length.
721
 */
10 reyssat 722
int _http2env(char outs[], char ins[])
723
{
724
    int j,k,l;
725
    l=strlen(ins);
726
    for(j=k=0;j<l && !isspace(ins[j]);j++,k++) {
5505 bpr 727
      if(isspace(ins[j])) {  /* skip space characters in query string */
728
          k--;continue;
729
      }
730
      if(ins[j]=='%') {
8343 bpr 731
/* skip Carriage-Return. */
5505 bpr 732
          if(ins[j+1]=='0' && (ins[j+2]=='d' || ins[j+2]=='D')) {
733
            j+=2; k--; continue;
734
          }
735
          outs[k]=hex2char(ins[j+1],ins[j+2]);
736
          j+=2; continue;
737
      }
738
      outs[k]=ins[j];
10 reyssat 739
    }
7646 bpr 740
    outs[k]=0;
10 reyssat 741
    return k;
742
}
743
 
8343 bpr 744
/* Converts back http escaped chars. Does not check buffer length.
745
 * Returns converted string length.
746
 */
10 reyssat 747
int http2env(char outs[], char ins[])
748
{
749
    int j,k,l;
750
    l=strlen(ins);
751
    for(j=k=0;j<l && !isspace(ins[j]);j++,k++) {
5505 bpr 752
      if(isspace(ins[j])) {  /* skip space characters in query string */
753
          k--;continue;
754
      }
755
      if(ins[j]=='%') {
8343 bpr 756
/* skip Carriage-Return. */
5505 bpr 757
          if(ins[j+1]=='0' && (ins[j+2]=='d' || ins[j+2]=='D')) {
758
            j+=2; k--; continue;
759
          }
760
          outs[k]=hex2char(ins[j+1],ins[j+2]);
761
          j+=2; continue;
762
      }
763
      if(ins[j]=='+') {
764
          outs[k]=' '; continue;
765
      }
766
      if(ins[j]=='?' || ins[j]=='&') {
767
          outs[k]=0; continue;
768
      }
769
      outs[k]=ins[j];
10 reyssat 770
    }
7646 bpr 771
    outs[k]=0;
10 reyssat 772
    return k;
773
}
774
 
8343 bpr 775
/* translate a string to http querystring style.
776
 * '&' is not translated.
777
 * Buffer p must be at least MAX_LINELEN.
778
 */
10 reyssat 779
void tohttpquery(char *p)
780
{
781
    char trlist[]="     ()[]{}+-*^|/\"\'!:;,<>\n";
782
    char *pp;
783
    for(pp=p;*pp;pp++) {
5505 bpr 784
      if(*pp==' ') {
785
          *pp='+'; continue;
786
      }
787
      if(strchr(trlist,*pp)==NULL) continue;
788
      if(*pp=='+' && pp>p && *(pp-1)=='&') continue;
789
      if(pp>p && *(pp-1)=='\\') {
790
          ovlstrcpy(pp-1,pp);pp--;continue;
791
      }
792
      if(*pp=='\n') {
793
          string_modify(p,pp,pp+1,"%%0D%%0A");pp+=5;
794
      }
795
      else {
796
          string_modify(p,pp,pp+1,"%%%02X",*pp);pp+=2;
797
      }
10 reyssat 798
    }
799
}
800
 
8343 bpr 801
/* substitute backslash parameters. Internal use only. */
10 reyssat 802
void slashsubst(char *p)
803
{
804
    char *p1, *p2, *pt, *pp, namebuf[128];
805
    int n;
806
 
807
    n=strlen(mathfont_prefix); memmove(namebuf,mathfont_prefix,n+1);
808
    for(p1=strchr(p,'\\'); p1!=NULL; p1=strchr(p1,'\\')) {
5505 bpr 809
      p1++; for(p2=p1; myisalnum(*p2) || *p2=='_'; p2++);
810
      if(p2<=p1 || p2>p1+100) continue;
811
      memmove(namebuf+n,p1,p2-p1); namebuf[p2-p1+n]=0;
812
      pt=_getvar(namebuf); if(pt==NULL) continue;
813
      if(*p2=='[' && (pp=find_matching(p2+1,']'))!=NULL) {
814
          string_modify(p,pp+1,pp+1,")");
815
          string_modify(p,p1-1,p1,"$(%s",mathfont_prefix);
816
      }
817
      else string_modify(p,p1-1,p1,"$%s",mathfont_prefix);
10 reyssat 818
    }
819
}
820
 
8343 bpr 821
/* two alarm handlers. */
10 reyssat 822
void alarm1(int s)
823
{
824
    if(killpid>0 && kill(killpid,SIGKILL)) module_error("timeup");
825
    killpid=0;
826
}
827
 
828
void alarm2(int s)
829
{
830
    cleantmpdir();
831
    alarm1(s); module_error("timeup");
832
}
833
 
834
void finalalarm(void)
835
{
836
    time_t curr;
837
    curr=time(0);
838
    if(curr>=limtime) alarm2(SIGALRM);
839
    errno=0;
840
    if(signal(SIGALRM,alarm2)==SIG_ERR)
841
      internal_error(strerror(errno));
842
    alarm(limtime-curr+1);
843
}
844
 
845
void initalarm(void)
846
{
847
    limtimex=nowtime+4*rlimit_cpu/3;
848
    limtime=limtimex+2; finalalarm();
849
}
850
 
851
void forkalarm(void)
852
{
853
    time_t curr;
854
    curr=time(0);
855
    if(curr>=limtimex) {alarm1(SIGALRM); return;}
856
    if(signal(SIGALRM,alarm1)==SIG_ERR)
857
      internal_error(strerror(errno));
858
    alarm(limtimex-curr+1);
859
}
860
 
8343 bpr 861
/* create pid tag */
10 reyssat 862
void create_pid(void)
863
{
864
    char buf[MAX_FNAME+1], pbuf[256], obuf[MAX_FNAME+1];
865
    struct stat dst;
866
    struct utimbuf ub;
7646 bpr 867
 
10 reyssat 868
    if(robot_access || *session_prefix==0) return;
869
    if(cmd_type==cmd_getframe) return;
870
    mkfname(buf,"%s/.pid",s2_prefix);
8343 bpr 871
/* another process running? */
10 reyssat 872
    if(readfile(buf,pbuf,sizeof(pbuf))!=NULL) {
5505 bpr 873
      mkfname(obuf,"/proc/%s",pbuf);
874
      if(stat(obuf,&dst)==0) user_error("double_click");
10 reyssat 875
    }
876
    snprintf(pidbuf,sizeof(pidbuf),"%u",getpid());
877
    accessfile(pidbuf,"w","%s",buf);
8343 bpr 878
/* Touch session time */
10 reyssat 879
    if(strstr(session_prefix,"sessions/")==NULL) return;
880
    ub.actime=ub.modtime=nowtime;
881
    utime(session_prefix,&ub);
882
    if(strchr(session_prefix,'_')!=NULL) { /* touch parent too */
5505 bpr 883
      char sbuf[MAX_FNAME+1], *p;
884
      mystrncpy(sbuf,session_prefix,sizeof(sbuf));
885
      p=strchr(sbuf,'_'); if(p!=NULL) *p=0;
886
      utime(sbuf,&ub);
10 reyssat 887
    }
888
}
889
 
8185 bpr 890
struct mxtab mxtab[MAX_MULTIEXEC];
10 reyssat 891
int mxno=0;
892
 
893
int execredirected(char *cmdf, char *inf, char *outf, char *errf, char *arg[])
894
{
895
    pid_t pid;
896
    int status, t;
897
 
898
    if(robot_access) return 0;
899
    if(time(0)>=limtimex) {
5505 bpr 900
      if(errf!=NULL)
901
        accessfile("No time left to execute subprograms.\n","w","%s",errf);
902
      return -100;
10 reyssat 903
    }
904
    lastdatafile[0]=lastftest[0]=0;
8343 bpr 905
    fflush(NULL); /* flush all output streams before forking
906
                   * otherwise they will be doubled
907
                   */
10 reyssat 908
    pid=fork(); if(pid==-1) return -1;
5505 bpr 909
    if(!pid) {      /* child */
910
      char buf[MAX_LINELEN+1]; int k;
911
      (void)nice(10);      /* lower priority for children */
912
      if(is_multiexec) {
913
          dup2(mxtab[multiexec_index].pipe_stdin[0],0);
914
          dup2(mxtab[multiexec_index].pipe_stdout[1],1);
915
          dup2(mxtab[multiexec_index].pipe_stderr[1],2);
916
      }
917
      else {
918
          if(inf!=NULL) (void)freopen(inf,"r",stdin);
919
          if(outf!=NULL) (void)freopen(outf,"w",stdout);
920
          if(errf!=NULL) (void)freopen(errf,"w",stderr);
921
      }
8343 bpr 922
/* This is to patch LinuxPPC uid wrapping
923
 * for scripts */
5505 bpr 924
      t=0; if(strchr(cmdf,'/')) {
925
          int tf;
926
          char tbuf[16];
927
          tf=open(cmdf,O_RDONLY); (void)read(tf,tbuf,8); close(tf);
928
          if(memcmp(tbuf+1,"ELF",3)!=0) t=1;
929
      }
930
      if(wrapexec==-1) {
931
          setreuid(getuid(),getuid());setregid(getgid(),getgid());
932
      }
933
      if(wrapexec==1 || (t==1 && wrapexec==0)) {
934
          setreuid(geteuid(),geteuid());setregid(getegid(),getegid());
935
      }
936
      errno=0;
937
      if(strchr(cmdf,'/')) execve(cmdf,arg,environ);
938
      else execvp(cmdf,arg);
939
      snprintf(buf,sizeof(buf),"Failed to execute");
940
      for(k=0;arg[k];k++) {
941
          t=strlen(buf);
942
          snprintf(buf+t,sizeof(buf)-t," %s",arg[k]);
943
      }
944
      t=strlen(buf);
945
      snprintf(buf+t,sizeof(buf)-t,"\n  %s\n",strerror(errno));
946
      accessfile(buf,"a","%s/exec.fail",tmp_dir);
947
      exit(127);
10 reyssat 948
    }
5505 bpr 949
    else {      /* parent */
7646 bpr 950
      wrapexec=0; status=0;
5505 bpr 951
      if(exec_wait && !is_multiexec) {
952
          killpid=pid; forkalarm();
953
          waitpid(pid,&status,0); killpid=0; finalalarm();
954
      }
955
      return WEXITSTATUS(status);
10 reyssat 956
    }
957
}
958
 
8343 bpr 959
/* preparation for resident execution.
960
 * Returns 1 if already up, otherwise 0.
961
 */
10 reyssat 962
int multiexec(char *cmd, char **abuf)
963
{
964
    char *p;
965
    int i;
7646 bpr 966
 
10 reyssat 967
    if(robot_access) return 0;
968
    if(strstr(tmp_dir,"sessions/")==NULL) return 0;
7646 bpr 969
    if(strstr(tmp_debug,"yes")!=NULL && checkhost(manager_site)>=1)
10 reyssat 970
      setenv("multiexec_debug","yes",1);
971
    p=getvar("wims_multiexec");
972
    if(p==NULL || wordchr(p,cmd)==NULL) return 0; /* not allowed */
973
    if(!multiexec_random[0]) {
5505 bpr 974
      snprintf(multiexec_random, sizeof(multiexec_random),
975
             "%lX%lX%lX%lX%lX%lX%lX%lX",
976
             random(),random(),random(),random(),
977
             random(),random(),random(),random());
978
      setenv("multiexec_random",multiexec_random,1);
10 reyssat 979
    }
980
    for(i=0;i<mxno && strcmp(cmd,mxtab[i].cmd)!=0; i++);
981
    multiexec_index=i;
982
    if(i==mxno) {
5505 bpr 983
      if(mxno>=MAX_MULTIEXEC) return 0;
984
      if(pipe(mxtab[i].pipe_stdin)<0) return 0;
985
      if(pipe(mxtab[i].pipe_stdout)<0) return 0;
986
      if(pipe(mxtab[i].pipe_stderr)<0) return 0;
987
      mystrncpy(mxtab[i].cmd,cmd,sizeof(mxtab[i].cmd));
988
      mxno++;      is_multiexec=1;
989
      exportall(); setenv("wims_exec_parm",multiexec_random,1);
990
      execredirected(abuf[0],NULL,NULL,NULL,abuf);
10 reyssat 991
    }
992
    is_multiexec=0;
993
    return 1;
994
}
995
 
8343 bpr 996
/* my system(), but with variable parms
997
 * More secure than system(), and direct fork.
998
 */
10 reyssat 999
int call_ssh(char *s,...)
1000
{
1001
    va_list vp;
1002
    char buf[MAX_LINELEN+1];
1003
    char *arg[1024];
1004
    char *inf=NULL, *outf=NULL, *errf=NULL;
1005
    char *cmdf, *p, *p2;
1006
    int i, d;
1007
 
1008
    if(robot_access) return 0;
1009
    va_start(vp,s);
1010
    vsnprintf(buf,sizeof(buf),s,vp);
1011
    va_end(vp);
1012
    p=find_word_start(buf); if(*p==0) return 0;
1013
    cmdf=p;
1014
    for(i=0;*p!=0 && i<1000; p=find_word_start(p2)) {
5505 bpr 1015
      switch(*p) {
1016
          case '\'': {
1017
            p++; p2=strchr(p,'\''); if(p2==NULL) p2=p+strlen(p);
1018
            d=0; break;
1019
          }
1020
          case '"': {
1021
            p++; p2=strchr(p,'"'); if(p2==NULL) p2=p+strlen(p);
1022
            d=0; break;
1023
          }
1024
          default: d=1; p2=find_word_end(p); break;
1025
      }
1026
      if(*p2) *p2++=0;
1027
      if(!d) {arg[i++]=p; continue;}
1028
      switch(*p) {
1029
          case '<': inf=++p; break;
1030
          case '>': {
1031
            p++; if(*p=='&') {
1032
                merge: p++; errf=outf=p; break;
1033
            }
1034
            else outf=p;
1035
            break;
1036
          }
1037
          case '&': {
1038
            p++; if(*p=='>') goto merge;
1039
            else break;
1040
          }
1041
          case '2': {
1042
            if(*(p+1)=='>') {errf=p+2; break;}
1043
          }
1044
          default: arg[i++]=p; break;
1045
      }
10 reyssat 1046
    }
1047
    arg[i]=NULL;
1048
    return execredirected(cmdf,inf,outf,errf,arg);
1049
}
1050
 
8343 bpr 1051
/* Read/write to a file with variable parms to print filename */
10 reyssat 1052
void accessfile(char *content, char *type, char *s,...)
1053
{
1054
    va_list vp;
1055
    char buf[MAX_FNAME+1];
1056
    int fd;
1057
 
1058
    if(robot_access) return;
1059
    va_start(vp,s);
1060
    vsnprintf(buf,sizeof(buf),s,vp);
1061
    va_end(vp);
1062
    if(strlen(buf)>=MAX_FNAME-1) nametoolong(buf);
1063
    switch(*type) {
5505 bpr 1064
      case 'r': readfile(buf,content,MAX_LINELEN); return;
1065
      case 'e': readfile(buf,content,MAX_LINELEN/4); return; /* limited read */
1066
      case 'w': fd=creat(buf,S_IRUSR|S_IWUSR|S_IRGRP|S_IROTH); break;
1067
      case 'a': fd=open(buf,O_WRONLY|O_CREAT|O_APPEND,S_IRUSR|S_IWUSR|S_IRGRP|S_IROTH); break;
1068
      default : return;
10 reyssat 1069
    }
1070
    lastdatafile[0]=lastftest[0]=0;
1071
    if(fd==-1) return;
3843 kbelabas 1072
    (void)write(fd,content,strlen(content)); close(fd);
10 reyssat 1073
}
1074
 
8343 bpr 1075
/* system(), but with variable parms
1076
 * Uses sh to execute command.
1077
 */
10 reyssat 1078
int call_sh(char *s,...)
1079
{
1080
    va_list vp;
1081
    char buf[MAX_LINELEN+1];
1082
    char *abuf[8];
1083
 
1084
    if(robot_access) return 0;
1085
    va_start(vp,s);
1086
    vsnprintf(buf,sizeof(buf),s,vp);
1087
    va_end(vp);
1088
    abuf[0]="sh"; abuf[1]="-c"; abuf[2]=buf; abuf[3]=NULL;
1089
    return execredirected(abuf[0],NULL,NULL,NULL,abuf);
1090
}
1091
 
1092
void _getdef(char buf[], char *name, char value[])
1093
{
1094
    char *p1, *p2, *p3, *p4;
1095
 
5505 bpr 1096
    if(*name==0) goto nothing;      /* this would create segfault. */
10 reyssat 1097
    for(p1=strstr(buf,name); p1!=NULL; p1=strstr(p1+1,name)) {
5505 bpr 1098
      p2=find_word_start(p1+strlen(name));
1099
      if((p1>buf && !isspace(*(p1-1))) || *p2!='=') continue;
1100
      p3=p1; while(p3>buf && *(p3-1)!='\n') p3--;
1101
      p3=find_word_start(p3);
1102
      if(p3<p1 && *p3!='!') continue;
1103
      if(p3<p1) {
1104
          p3++; p4=find_word_end(p3);
1105
          if(find_word_start(p4)!=p1) continue;
1106
          if(p4-p3!=3 || (strncmp(p3,"set",3)!=0 &&
1107
             strncmp(p3,"let",3)!=0 &&
1108
             strncmp(p3,"def",3)!=0)) {
1109
            if(p4-p3!=6 || strncmp(p3,"define",6)!=0) continue;
1110
          }
1111
      }
1112
      p2++;p3=strchr(p2,'\n'); if(p3==NULL) p3=p2+strlen(p2);
1113
      p2=find_word_start(p2);
1114
      if(p2>p3) goto nothing;
1115
      if(p3-p2>=MAX_LINELEN) user_error("cmd_output_too_long");
1116
      memmove(value,p2,p3-p2); value[p3-p2]=0;
1117
      strip_trailing_spaces(value); return;
10 reyssat 1118
    }
1119
nothing:
1120
    value[0]=0; return;
1121
}
1122
 
8155 bpr 1123
/* Get variable definition from a file.
1124
 * Result stored in buffer value of length MAX_LINELEN.
1125
 */
10 reyssat 1126
void getdef(char *fname, char *name, char value[])
1127
{
1128
    char buf[MAX_LINELEN+1], tbuf[MAX_LINELEN+1], nbuf[MAX_NAMELEN+1];
1129
    char *p1, *p2;
1130
 
1131
    value[0]=0; if(readfile(fname,buf,sizeof(buf)-16)==NULL) return;
1132
    mystrncpy(value,name,MAX_LINELEN);
1133
    for(p1=value; *p1; p1=p2) {
5505 bpr 1134
      while(*p1 && !myisalnum(*p1) && *p1!='_') p1++;
1135
      if(*p1==0) break;
1136
      for(p2=p1; myisalnum(*p2) || *p2=='_'; p2++);
1137
      if(p2-p1>MAX_NAMELEN) continue;
1138
      memmove(nbuf,p1,p2-p1); nbuf[p2-p1]=0;
1139
      _getdef(buf,nbuf,tbuf);
1140
      string_modify(value,p1,p2,"%s",tbuf);
1141
      p2=p1+strlen(tbuf);
10 reyssat 1142
    }
1143
}
1144
 
1145
int _setdef_changed;
1146
 
1147
void _setdef(char buf[], char *name, char *value)
1148
{
1149
    char *p1, *p2, *p3;
1150
    int n;
7646 bpr 1151
 
10 reyssat 1152
    for(p1=strstr(buf,name); p1!=NULL; p1=strstr(p1+1,name)) {
5505 bpr 1153
      p2=find_word_start(p1+strlen(name));
1154
      if((p1>buf && !isspace(*(p1-1))) || *p2!='=') continue;
1155
      p3=p1; while(p3>buf && *(p3-1)==' ') p3--;
1156
      if(p3>buf && *(p3-1)!='\n') continue;
1157
      p2++;p3=strchr(p2,'\n'); if(p3==NULL) p3=p2+strlen(p2);
1158
      if(strlen(value)!=p3-p2 || strncmp(value,p2,p3-p2)!=0) {
1159
          string_modify(buf,p2,p3,"%s",value);
1160
          _setdef_changed++;
1161
      }
1162
      return;
10 reyssat 1163
    }
1164
    n=strlen(buf);
7646 bpr 1165
    if(n>0 && buf[n-1]!='\n')
10 reyssat 1166
      snprintf(buf+n,MAX_LINELEN-n,"\n%s=%s\n",name,value);
1167
    else
1168
      snprintf(buf+n,MAX_LINELEN-n,"%s=%s\n",name,value);
1169
    _setdef_changed++;
1170
}
1171
 
8155 bpr 1172
/* Set variable definition to a file. */
10 reyssat 1173
void setdef(char *fname, char *name)
1174
{
1175
    char buf[MAX_LINELEN+1];
1176
    char *p1, *p2, *p3;
1177
 
1178
    _setdef_changed=0;
1179
    if(strchr(name,'=')==NULL) return;
1180
    for(p1=name;*p1;p1++) {
5505 bpr 1181
      if(isspace(*p1) && *p1!=' ' && *p1!='\n') *p1=' ';
1182
      if(*p1==' ') {
1183
          for(p2=p1+1; isspace(*p2) && *p2!='\n'; p2++);
1184
          if(p2>p1+1) ovlstrcpy(p1+1,p2);
1185
          p2=p1+1; if(*p2=='=' || *p2=='\n') ovlstrcpy(p1,p2);
1186
      }
10 reyssat 1187
    }
1188
    if(readfile(fname,buf,sizeof(buf))==NULL) buf[0]=0;
1189
    for(p1=find_word_start(name); p1!=NULL; p1=p2) {
5505 bpr 1190
      p2=strchr(p1,'\n'); if(p2!=NULL) *p2++=0;
1191
      p1=find_word_start(p1);
1192
      p3=strchr(p1,'='); if(p3==NULL) continue;
1193
      *p3++=0; p3=find_word_start(p3);
1194
      _setdef(buf,p1,p3);
10 reyssat 1195
    }
1196
    if(_setdef_changed) accessfile(buf,"w","%s",fname);
1197
}
1198
 
8155 bpr 1199
/* check whether connecting host is part of given list.
1200
 * Returns 0 if no, 1 if yes.
1201
 */
10 reyssat 1202
int checkhost(char *hlist)
1203
{
1204
    char buf[MAX_LINELEN+1];
1205
    char lbuf[1024], hbuf1[256], hbuf2[256];
1206
    char *p1, *p2, *pb, *pe, *pp;
7646 bpr 1207
 
10 reyssat 1208
    if(*remote_addr==0) return 0;
1209
    snprintf(hbuf1,sizeof(hbuf1),"+%s+",remote_addr);
1210
    if(*remote_host!=0) {
5505 bpr 1211
      snprintf(hbuf2,sizeof(hbuf2),"+%s+",remote_host);
1212
      for(p1=hbuf2; *p1; p1++) *p1=tolower(*p1);
10 reyssat 1213
    }
1214
    else hbuf2[0]=0;
1215
    mystrncpy(buf,find_word_start(hlist),sizeof(buf)); strip_trailing_spaces(buf);
1216
    for(p1=buf; *p1; p1++) {
5505 bpr 1217
      *p1=tolower(*p1);
1218
      if(!myisalnum(*p1) && strchr(".-_",*p1)==NULL) *p1=' ';
10 reyssat 1219
    }
5505 bpr 1220
    if(strcmp(buf,"all")==0) return 1;      /* all is all */
10 reyssat 1221
    for(p1=find_word_start(buf); *p1; p1=find_word_start(p2)) {
5505 bpr 1222
      p2=find_word_end(p1); if(*p2) *p2++=0;
1223
      if(p2-p1<3) continue;
1224
      if(myisalnum(*p1)) pb="+"; else pb="";
1225
      if(myisalnum(*(p2-1))) pe="+"; else pe="";
1226
      snprintf(lbuf,sizeof(lbuf),"%s%s%s",pb,p1,pe);
7646 bpr 1227
      for(pp=p1; *pp && (myisdigit(*pp) || *pp=='.'); pp++);
5505 bpr 1228
      if(*pp) pp=hbuf2;      /* host name */
1229
      else pp=hbuf1;         /* ip number */
1230
      if(strstr(pp,lbuf)!=NULL) return 1;      /* found */
10 reyssat 1231
    }
1232
    return 0;
1233
}
1234
 
8155 bpr 1235
/* return 1 if a word of bf2 is a substring of host.
1236
 * Like checkhost, but with time check.
1237
 * The content of bf2[] is destroyed.
1238
 */
10 reyssat 1239
int checkhostt(char bf2[])
1240
{
1241
    char *p1, *p2, *p3;
8155 bpr 1242
/* compare with starting time */
10 reyssat 1243
    for(p1=strchr(bf2,'>'); p1!=NULL; p1=strchr(p1+1,'>')) {
5505 bpr 1244
      if(p1>bf2 && !isspace(*(p1-1))) continue;
1245
      p3=find_word_start(++p1); p2=find_word_end(p3);
1246
      if(p2-p3!=14) continue;
1247
      p3[8]='.'; p3[11]=':'; if(*p2) *p2++=0;
1248
      if(strncmp(nowstr,p3,14)<0) return 0;
1249
      ovlstrcpy(p1-1,p2); p1-=2;
10 reyssat 1250
    }
8155 bpr 1251
/* compare with ending time */
10 reyssat 1252
    for(p1=strchr(bf2,'<'); p1!=NULL; p1=strchr(p1+1,'<')) {
5505 bpr 1253
      if(p1>bf2 && !isspace(*(p1-1))) continue;
1254
      p3=find_word_start(++p1); p2=find_word_end(p3);
1255
      if(p2-p3!=14) continue;
1256
      p3[8]='.'; p3[11]=':'; if(*p2) *p2++=0;
1257
      if(strncmp(nowstr,p3,14)>0) return 0;
1258
      ovlstrcpy(p1-1,p2); p1-=2;
10 reyssat 1259
    }
1260
    p1=find_word_start(bf2); if(*p1==0) return 1;
1261
    return checkhost(p1);
1262
}
1263
 
8155 bpr 1264
/* bad identification */
10 reyssat 1265
void bad_ident(void)
1266
{
1267
    if(cookiegot[0]!=0) {
1268
    }
1269
    user_error("bad_ident");
1270
}
1271
 
1272
void instex_flush(void)
1273
{
1274
    char *p;
1275
    setenv("texgif_style","",1);
1276
    setenv("texgif_tmpdir",tmp_dir,1);
1277
    setenv("texgif_src",instex_src,1);
1278
    setenv("texgif_outfile",instex_fname,1);
1279
    unsetenv("w_instex_color");
1280
    getwimstexsize=0; fix_tex_size(); getwimstexsize=1;
1281
    for(p=instex_fname;*p;p++) if(*p=='\n') *p=' ';
1282
    wrapexec=0; call_ssh("%s/%s >%s/ins.Out 2>%s/ins.Err",
5505 bpr 1283
                   bin_dir,instex_processor,
1284
                   tmp_dir,tmp_dir);
10 reyssat 1285
    call_ssh("mv %s %s >/dev/null 2>/dev/null", instex_fname,s2_prefix);
1286
    instex_src[0]=instex_fname[0]=0; instex_cnt=0;
1287
}
1288
 
8155 bpr 1289
/* put last.phtml */
10 reyssat 1290
void putlastout(void)
1291
{
1292
    int t;
1293
    if(instex_cnt>0) instex_flush();
1294
    t=catfile(stdout,"%s/%s",s2_prefix,lastout);
1295
    if(t==0) printf("Content-type: text/plain\r\n\r\n");
1296
}
1297
 
1298
struct sockaddr_un sun;
1299
 
8155 bpr 1300
/* returns >=0 if OK. */
7646 bpr 1301
 
10 reyssat 1302
int kerneld(char *p, int bufsize)
1303
{
1304
    int sock, s, t, t1, l, *ip;
1305
    struct timeval tv;
1306
    fd_set rset;
1307
    sock=socket(PF_UNIX,SOCK_STREAM,0);
1308
    s=connect(sock,(const struct sockaddr *)&sun,sizeof(sun));
1309
    if(s) {bad: close(sock); return -1;}
1310
    ip=(int *) p;
1311
    l=strlen(p+sizeof(int)); *ip=l;
1312
    s=write(sock,p,l+sizeof(int)); if(s!=l+sizeof(int)) goto bad;
1313
    for(t=0, l=bufsize-1; t<l+sizeof(int);) {
5505 bpr 1314
      tv.tv_sec=2; tv.tv_usec=0;
1315
      FD_ZERO(&rset); FD_SET(sock,&rset);
1316
      if(select(sock+1,&rset,NULL,NULL,&tv)<=0) goto bad;
7646 bpr 1317
      t1=read(sock,p+t,l+sizeof(int)-t);
5505 bpr 1318
      if(t1+t<sizeof(int)) goto bad;
7646 bpr 1319
      if (t1 < 0) goto bad;
5505 bpr 1320
      l=*ip; if(l<=0) goto bad;
1321
      if(l>=bufsize-sizeof(int)-4) user_error("cmd_output_too_long");
1322
      t+=t1;
10 reyssat 1323
    }
1324
    p[l+sizeof(int)]=0;
1325
    close(sock);
1326
    return l+sizeof(int);
1327
}
1328
 
1329
void _daemoncmd(char *p)
1330
{
1331
    char buf[MAX_LINELEN+1+sizeof(int)];
1332
    char *p1, *p2, *p3;
1333
    mystrncpy(buf+sizeof(int),p,sizeof(buf)-sizeof(int));
7646 bpr 1334
    if(kerneld(buf,sizeof(buf))<0)
10 reyssat 1335
      internal_error("Daemon communication error.");
1336
    p1=find_word_start(buf+sizeof(int));
1337
    p2=find_word_end(p1); if(*p2) *p2++=0;
1338
    if(strcmp(p1,"OK")==0) {
5505 bpr 1339
      mystrncpy(p,p2,MAX_LINELEN); return;
10 reyssat 1340
    }
1341
    p1=find_word_start(p2); p2=find_word_end(p1); if(*p2) *p2++=0;
7646 bpr 1342
    p2=find_word_start(p2); p3=find_word_end(p2);
10 reyssat 1343
    if(*p3) {
5505 bpr 1344
      *p3++=0; p3=find_word_start(p3); strip_trailing_spaces(p3);
1345
      setvar("wims_error_data",p3);
10 reyssat 1346
    }
1347
    switch(*p1) {
5505 bpr 1348
      case '1': user_error(p2);
1349
      case '2': module_error(p2);
1350
      case '3':
1351
      default: internal_error(p2);
10 reyssat 1352
    }
1353
    *p=0;
1354
}
1355