Rev 8155 | Rev 8343 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed
Rev | Author | Line No. | Line |
---|---|---|---|
10 | reyssat | 1 | /* Copyright (C) 1998-2003 XIAO, Gang of Universite de Nice - Sophia Antipolis |
2 | * |
||
3 | * This program is free software; you can redistribute it and/or modify |
||
4 | * it under the terms of the GNU General Public License as published by |
||
5 | * the Free Software Foundation; either version 2 of the License, or |
||
6 | * (at your option) any later version. |
||
7 | * |
||
8 | * This program is distributed in the hope that it will be useful, |
||
9 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
10 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
11 | * GNU General Public License for more details. |
||
12 | * |
||
13 | * You should have received a copy of the GNU General Public License |
||
14 | * along with this program; if not, write to the Free Software |
||
15 | * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. |
||
16 | */ |
||
8185 | bpr | 17 | |
8067 | bpr | 18 | /* line input / output / translation routines |
19 | * and error routines |
||
20 | */ |
||
8185 | bpr | 21 | #include <utime.h> |
22 | #include <sys/socket.h> |
||
23 | #include <sys/un.h> |
||
10 | reyssat | 24 | |
8185 | bpr | 25 | #include "wims.h" |
26 | |||
10 | reyssat | 27 | int is_class_module=0; |
28 | |||
29 | int trusted_module(void); |
||
30 | void phtml_put_base(char *fname,int cache); |
||
31 | void module_error(char msg[]); |
||
32 | void user_error(char msg[]); |
||
33 | void accessfile(char *content, char *type, char *s,...); |
||
34 | int remove_tree(char *p); |
||
35 | void output(char *s,...); |
||
36 | char *_getvar(char *vname); |
||
37 | int checkhost(char *hlist); |
||
38 | |||
39 | char *lastdata; |
||
40 | char lastdatafile[MAX_FNAME+1]; |
||
41 | char *datacache[DATAFIELD_LIMIT]; |
||
42 | int nextdatacache; |
||
43 | struct stat ftst; |
||
44 | char lastftest[MAX_FNAME+1]; |
||
45 | int lastftype; |
||
46 | char outbuf[8192]; |
||
47 | char *outptr; |
||
48 | |||
8185 | bpr | 49 | /* These modules can execute private programs. |
50 | * adm/ modules are always trusted, so need no definition here. |
||
51 | */ |
||
10 | reyssat | 52 | char *trusted_modules=""; |
5505 | bpr | 53 | /* bit 0: module is not trusted. |
54 | * bit 1: file in wimshome. |
||
55 | * bit 2: readdef or file in writable directory. |
||
56 | */ |
||
10 | reyssat | 57 | int untrust=0; /* non-zero if user detrusts the module. */ |
58 | |||
59 | int error_status=0; |
||
60 | char pidbuf[32]; |
||
61 | |||
62 | void delete_pid(void); |
||
63 | |||
5505 | bpr | 64 | /* Internal use only */ |
10 | reyssat | 65 | void _debug(char *s,...) |
66 | { |
||
67 | va_list vp; |
||
68 | char buf[MAX_LINELEN+1]; |
||
69 | |||
70 | va_start(vp,s); |
||
71 | vsnprintf(buf,sizeof(buf),s,vp); |
||
72 | va_end(vp); |
||
73 | setvar("debug",buf); module_error("debug"); |
||
74 | exit(1); |
||
75 | } |
||
76 | |||
77 | |||
5505 | bpr | 78 | /* HTTP response header for non-processed CGI interface */ |
10 | reyssat | 79 | void nph_header(int code) |
80 | { |
||
81 | char *cstr; |
||
82 | switch(code) { |
||
5505 | bpr | 83 | case 200: cstr="OK"; break; |
84 | case 301: cstr="Moved Permanently"; break; |
||
85 | case 302: cstr="Moved Temporarily"; break; |
||
86 | case 420: cstr="WIMS Nested Error"; break; |
||
87 | case 450: cstr="WIMS User Error"; break; |
||
88 | case 500: cstr="WIMS Internal Error"; break; |
||
7646 | bpr | 89 | case 550: cstr="WIMS Module Error"; break; |
5505 | bpr | 90 | default: cstr="ERROR"; break; |
10 | reyssat | 91 | } |
92 | if(httpd_type!=httpd_wims) printf("Status: %d %s\r\n",code,cstr); |
||
93 | else { |
||
5505 | bpr | 94 | char *p, tbuf[256]; |
95 | mystrncpy(tbuf,ctime(&nowtime),sizeof(tbuf)); |
||
96 | for(p=tbuf+strlen(tbuf);p>=tbuf && (*(p-1)=='\n' || *(p-1)=='\r'); p--); |
||
97 | *p=0; |
||
98 | printf("HTTP/1.0 %d %s\r\n\ |
||
10 | reyssat | 99 | Date: %s\r\n\ |
100 | Connection: close\r\n\ |
||
101 | ",code,cstr,tbuf); |
||
102 | } |
||
103 | } |
||
104 | |||
105 | void flushoutput(void) |
||
106 | { |
||
107 | int l2; |
||
108 | if(outptr<=outbuf) return; |
||
109 | l2=outptr-outbuf; |
||
3843 | kbelabas | 110 | if(lastout_file!=-1) (void)write(lastout_file,outbuf,l2); |
10 | reyssat | 111 | else fwrite(outbuf,l2,1,stdout); |
112 | outptr=outbuf; |
||
113 | } |
||
114 | |||
115 | void internal_warn(char msg[]) |
||
116 | { |
||
117 | char buf[1024]; |
||
118 | fprintf(stderr,"wims: %s\n%s\n",msg,strerror(errno)); |
||
119 | snprintf(buf,sizeof(buf),"%s: %s\n",nowstr,msg); |
||
120 | accessfile(buf,"a","%s/internal_error.log",log_dir); |
||
121 | } |
||
122 | |||
123 | /* Internal error: panic and forget about requester. */ |
||
124 | void internal_error(char msg[]) |
||
125 | { |
||
126 | if(error_status<2) { |
||
5505 | bpr | 127 | nph_header(500); |
128 | printf("Cache-Control: no-cache\nPragma: no-cache\r\n\ |
||
10 | reyssat | 129 | Content-type: text/plain\r\n\r\n\r\n\ |
130 | WIMS panick! %s\n%s\n",msg,strerror(errno)); |
||
5505 | bpr | 131 | error_status=2; internal_warn(msg); |
10 | reyssat | 132 | } |
133 | delete_pid(); exit(1); |
||
134 | } |
||
135 | |||
136 | void tex_nospace(char *p) |
||
137 | { |
||
138 | char *p1, *p2; |
||
139 | char buf[MAX_LINELEN+1]; |
||
140 | for(p1=buf,p2=p;*p2 && p1-buf<MAX_LINELEN-4;p2++) { |
||
5505 | bpr | 141 | if(!isspace(*p2)) {*p1++=*p2;continue;} |
142 | while(isspace(*p2)) p2++; |
||
7646 | bpr | 143 | if(*(p1-1)=='\\' || |
5505 | bpr | 144 | (p1>buf && myisalnum(*(p1-1)) && myisalnum(*p2))) |
145 | *p1++=' '; |
||
146 | *p1++=*p2; |
||
10 | reyssat | 147 | } |
148 | *p1++=0; memmove(p,buf,p1-buf); |
||
149 | } |
||
150 | |||
151 | void nametoolong(char *p) |
||
152 | { |
||
153 | char buf[MAX_FNAME+17]; |
||
154 | snprintf(buf,sizeof(buf),"%s...",p); |
||
155 | force_setvar("wims_error_data",buf); |
||
156 | module_error("file_name_too_long"); |
||
157 | } |
||
158 | |||
159 | off_t ftest_size; |
||
160 | |||
5505 | bpr | 161 | /* A simple front-end of stat(). */ |
10 | reyssat | 162 | int ftest(char *fname) |
163 | { |
||
164 | if(strcmp(fname,lastftest)==0) return lastftype; |
||
165 | /* if(fname[0]=='/' || fname[0]=='.') fprintf(stderr,"ftest: %s\n",fname); */ |
||
166 | mystrncpy(lastftest,fname,sizeof(lastftest)); |
||
167 | if(stat(fname,&ftst)) return lastftype=-1; |
||
168 | ftest_size=ftst.st_size; |
||
169 | if(S_ISREG(ftst.st_mode)) { |
||
5505 | bpr | 170 | if((ftst.st_mode&(S_IXUSR|S_IXGRP|S_IXOTH))!=0) return lastftype=is_exec; |
171 | else return lastftype=is_file; |
||
10 | reyssat | 172 | } |
173 | if(S_ISDIR(ftst.st_mode)) return lastftype=is_dir; |
||
174 | if(S_ISFIFO(ftst.st_mode)) return lastftype=is_fifo; |
||
175 | if(S_ISSOCK(ftst.st_mode)) return lastftype=is_socket; |
||
176 | return lastftype=is_unknown; |
||
177 | } |
||
178 | |||
179 | char fnbuf[MAX_FNAME+1]; |
||
180 | |||
5505 | bpr | 181 | /* make a filename and check length */ |
10 | reyssat | 182 | char *mkfname(char buf[], char *s,...) |
183 | { |
||
184 | va_list vp; |
||
185 | char *p; |
||
186 | |||
187 | if(buf==NULL) p=fnbuf; else p=buf; |
||
188 | va_start(vp,s); |
||
189 | vsnprintf(p,MAX_FNAME,s,vp); |
||
190 | va_end(vp); |
||
191 | if(strlen(p)>=MAX_FNAME-1) nametoolong(p); |
||
192 | return p; |
||
193 | } |
||
194 | |||
195 | void sysmask_trigger(char *s) |
||
196 | { |
||
197 | char buf[MAX_FNAME+1]; |
||
198 | struct stat st; |
||
199 | mkfname(buf,"%s/%s",sysmask_trigger_dir,s); |
||
200 | stat(buf,&st); |
||
201 | } |
||
202 | |||
5505 | bpr | 203 | /* read-in a file into buffer. Use open() and read(). |
204 | * Return buffer address which will be malloc'ed if buf=NULL. */ |
||
10 | reyssat | 205 | char *readfile(char *fname, char buf[], long int buflen) |
206 | { |
||
207 | int fd, t, st; |
||
208 | long int l, lc; |
||
209 | char *bf; |
||
210 | t=0; if(buf) buf[0]=0; |
||
211 | st=ftest(fname); if(st!=is_file) { |
||
5505 | bpr | 212 | if(st==is_exec) { /* refuse to open executable file */ |
213 | setvar("executable",fname); module_error("executable"); |
||
214 | } |
||
215 | return NULL; |
||
10 | reyssat | 216 | } |
217 | l=ftst.st_size; if(l<0) return NULL; |
||
218 | if(l>=buflen) { |
||
5505 | bpr | 219 | if(buflen<MAX_LINELEN) l=buflen-1; |
220 | else { |
||
221 | if(strncmp(fname,"modules/",strlen("modules/"))==0) { |
||
222 | setvar(error_data_string,fname); module_error("file_too_long"); |
||
223 | } |
||
224 | else user_error("cmd_output_too_long"); |
||
225 | } |
||
10 | reyssat | 226 | } |
227 | fd=open(fname,O_RDONLY); if(fd==-1) return NULL; |
||
228 | if(buf==NULL) bf=xmalloc(l+8); else {bf=buf;if(l==0) {t=1; l=buflen-1;}} |
||
229 | lc=read(fd,bf,l); close(fd); |
||
7646 | bpr | 230 | if(lc<0 || lc>l || (lc!=l && t==0)) |
5505 | bpr | 231 | {if(buf==NULL) free(bf); else buf[0]=0; return NULL;} |
10 | reyssat | 232 | bf[lc]=0; _tolinux(bf); return bf; |
233 | } |
||
234 | |||
7646 | bpr | 235 | /* Get a line in a stored working file. |
5505 | bpr | 236 | * Buffer length is always MAX_LINELEN. */ |
10 | reyssat | 237 | int wgetline(char buf[], size_t buflen, WORKING_FILE *f) |
238 | { |
||
239 | int i,j; unsigned int n; |
||
240 | i=f->linepointer; buf[0]=0; |
||
241 | if(i>=f->linecnt || f->textbuf==NULL) return EOF; |
||
242 | n=f->lines[i].llen; |
||
243 | if(n>=buflen) n=buflen-1; |
||
244 | if(n>0) memmove(buf,f->lines[i].address,n); buf[n]=0; |
||
245 | for(j=i+1;j<f->linecnt && f->lines[j].isstart==0;j++); |
||
246 | f->l=i; f->linepointer=j; |
||
247 | if(j>=f->linecnt && n==0) return EOF; else return n; |
||
248 | } |
||
249 | |||
250 | int get_cached_file(char *name) |
||
251 | { |
||
252 | int i,l,flag; |
||
253 | l=strlen(name); if(l>=127) return -1; |
||
254 | if(strncmp(module_prefix,module_dir,strlen(module_dir))!=0) flag=8; else flag=0; |
||
255 | for(i=0;i<mcachecnt;i++) { |
||
5505 | bpr | 256 | if(flag==mcache[i].nocache && strcmp(name,mcache[i].name)==0) { |
257 | memmove(&m_file,mcache+i,sizeof(WORKING_FILE)); |
||
258 | m_file.nocache|=4; |
||
259 | return i; |
||
260 | } |
||
10 | reyssat | 261 | } |
262 | return -1; |
||
263 | } |
||
264 | |||
5505 | bpr | 265 | /* Open a work file. Returns 0 if OK. */ |
10 | reyssat | 266 | int open_working_file(WORKING_FILE *f, char *fname) |
267 | { |
||
268 | char *p, *q; |
||
269 | void *vp; |
||
270 | int i,j,k,laststart,lc[LINE_LIMIT]; |
||
271 | |||
272 | f->linecnt=f->linepointer=0; |
||
273 | f->for_idx=f->nocache=0; |
||
274 | f->l=-1; f->lines=NULL; |
||
275 | f->textbuf=readfile(fname,NULL,WORKFILE_LIMIT); |
||
276 | if(f->textbuf==NULL) return -1; |
||
277 | p=f->textbuf; if(*p) { |
||
5505 | bpr | 278 | for(i=0,p--; i<LINE_LIMIT-1 && p!=NULL;p=strchr(p,'\n')) { |
279 | if(i>0) *p=0; |
||
280 | lc[i++]=(++p-f->textbuf); |
||
281 | } |
||
10 | reyssat | 282 | } |
283 | else i=0; |
||
284 | if(i>=LINE_LIMIT-1) module_error("file_too_long"); |
||
285 | lc[i]=lc[i-1]+strlen(f->textbuf+lc[i-1])+1; |
||
286 | f->textbuf[lc[i]]=0; |
||
287 | f->linecnt=i; laststart=0; |
||
288 | f->for_stack=xmalloc(MAX_FOR_LEVEL*sizeof(FOR_STACK)+(i+1)*sizeof(LINE_STRUCT)); |
||
289 | vp=f->for_stack+MAX_FOR_LEVEL; f->lines=vp; |
||
290 | for(j=0;j<i;j++) { |
||
5505 | bpr | 291 | f->lines[j].address=p=(f->textbuf)+lc[j]; |
292 | f->lines[j].llen=lc[j+1]-lc[j]-1; |
||
293 | (f->lines[j]).execcode=(f->lines[j]).varcode=-1; |
||
294 | if(j==0) goto normal; |
||
295 | q=f->lines[laststart].address+f->lines[laststart].llen-1; |
||
296 | if(q>=f->textbuf && *q=='\\') { |
||
297 | f->lines[laststart].llen+=f->lines[j].llen; *q='\n'; |
||
298 | f->lines[j].isstart=f->lines[j].llen=0; |
||
299 | memmove(q+1,p,lc[j+1]-lc[j]); |
||
300 | } |
||
301 | else { |
||
302 | normal: for(q=p;myislspace(*q);q++); |
||
303 | f->lines[j].isstart=1; laststart=j; k=0; |
||
304 | switch(*q) { |
||
305 | /* isstart: bit 1 = start. |
||
306 | * bit 2 = exec |
||
307 | * bit 3 (4) = label |
||
308 | * bit 4 (8) = hard comment (!!) |
||
309 | * bit 5 (16) = soft comment (#) */ |
||
310 | case exec_prefix_char: { |
||
311 | if(myisalpha(q[1])) f->lines[j].isstart=3; |
||
312 | else f->lines[j].isstart=9; |
||
313 | k=1; break; |
||
314 | } |
||
315 | case label_prefix_char: {f->lines[j].isstart=5; k=1; break;} |
||
316 | case comment_prefix_char: {f->lines[j].isstart=17; break;} |
||
317 | default: {f->lines[j].isstart=1; break;} |
||
318 | } |
||
319 | if(k && q>p) {f->lines[j].address=q;f->lines[j].llen-=q-p;} |
||
320 | } |
||
10 | reyssat | 321 | } |
322 | f->lines[i].isstart=1; f->lines[i].llen=0; |
||
323 | f->lines[i].address=(f->textbuf)+lc[i]; |
||
324 | mfilecnt++; return 0; |
||
325 | } |
||
326 | |||
5505 | bpr | 327 | /* close an earlier opened working file */ |
10 | reyssat | 328 | void close_working_file(WORKING_FILE *f, int cache) |
329 | { |
||
330 | f->linepointer=f->l=0; |
||
331 | if(cache && untrust==0 && mcachecnt<MAX_MCACHE && (f->nocache&7)==0) { |
||
5505 | bpr | 332 | memmove(mcache+mcachecnt,f,sizeof(WORKING_FILE)); |
333 | mcachecnt++; |
||
10 | reyssat | 334 | } |
335 | else if((f->nocache&4)==0) { |
||
5505 | bpr | 336 | if(f->for_stack!=NULL) free(f->for_stack); |
337 | if(f->textbuf!=NULL) free(f->textbuf); |
||
10 | reyssat | 338 | } |
339 | f->for_stack=NULL; f->textbuf=NULL; f->linecnt=0; |
||
340 | } |
||
341 | |||
342 | void free_mcache(void) |
||
343 | { |
||
344 | int i; |
||
345 | untrust=0; |
||
346 | for(i=mcachecnt-1;i>=0;i--) close_working_file(mcache+i,0); |
||
347 | mcachecnt=0; |
||
348 | } |
||
349 | |||
350 | void cleantmpdir(void); |
||
351 | void user_error_log(char msg[]); |
||
352 | |||
353 | void nested_error(char msg[]) |
||
354 | { |
||
355 | fprintf(stderr,"\nNested error! %s\n",msg); |
||
356 | nph_header(420); |
||
357 | printf("\r\n\r\nWIMS error processing aborted on nested error.\r\n\r\n%s\r\n",msg); |
||
358 | delete_pid(); exit(1); |
||
359 | } |
||
360 | |||
5505 | bpr | 361 | /* Send an error message to requester and exit. |
362 | * This is for user errors, language-sensitive. */ |
||
10 | reyssat | 363 | void user_error(char msg[]) |
364 | { |
||
365 | char erfname[MAX_FNAME+1]; |
||
366 | |||
367 | if(error_status) nested_error(msg); |
||
368 | error_status=1; |
||
369 | mkfname(erfname,"%s.%s",user_error_msg_file,lang); |
||
370 | if(ftest(erfname)!=is_file) internal_error("user_error(): error message file not found.\n\ |
||
371 | Bad installation."); |
||
372 | force_setvar("wims_user_error",msg); |
||
7646 | bpr | 373 | if(strcmp(msg,"threshold")!=0) user_error_log(msg); |
374 | memmove(module_prefix,".",2); |
||
10 | reyssat | 375 | if(lastout_file!=-1 && outputing) { |
5505 | bpr | 376 | flushoutput(); close(lastout_file); lastout_file=-1; |
10 | reyssat | 377 | } |
378 | nph_header(450); |
||
7646 | bpr | 379 | phtml_put_base(erfname,0); |
380 | if(strcmp(msg,"double_click")!=0) delete_pid(); |
||
10 | reyssat | 381 | else { |
5505 | bpr | 382 | cleantmpdir(); flushlog(); |
10 | reyssat | 383 | } |
384 | flushoutput(); exit(0); |
||
385 | } |
||
386 | |||
387 | void module_error_log(char msg[]); |
||
388 | |||
5505 | bpr | 389 | /* Messages for module errors. English only. */ |
390 | /* This is really rudimentary for the time being. */ |
||
10 | reyssat | 391 | void module_error(char msg[]) |
392 | { |
||
393 | int send=0; |
||
394 | char *p; |
||
395 | WORKING_FILE mf; |
||
396 | |||
397 | if(error_status) nested_error(msg); |
||
398 | error_status=1; untrust=0; |
||
399 | module_error_log(msg); |
||
400 | nph_header(550); |
||
401 | printf("Server: %s %s (%s)\r\n", SHORTSWNAME,wims_version,LONGSWNAME); |
||
402 | p=getvar("wims_main_font"); |
||
403 | if(p!=NULL && *p!=0) printf("Content-type: text/plain; charset=%s\r\n\r\n",p); |
||
404 | else printf("Content-type: text/plain\r\n\r\n"); |
||
405 | p=getvar(ro_name[ro_module]); if(p==NULL) p="???"; |
||
406 | printf("ERROR.\n\nwims has detected an error in the module '%s'.",p); |
||
407 | if(m_file.l>=0) printf("\n\nIn file '%s', line %d:", |
||
5505 | bpr | 408 | m_file.name,m_file.l+1); |
10 | reyssat | 409 | printf(" %s.\n\n",msg); |
410 | if(open_working_file(&mf,mkfname(NULL,"%s.%s",module_error_msg_file,lang))!=0) |
||
411 | internal_error("module_error(): error message file not found."); |
||
412 | while(wgetline(tmplbuf,MAX_LINELEN,&mf)!=EOF) { |
||
5505 | bpr | 413 | if(tmplbuf[0]!=tag_prefix_char) { |
414 | if(send) {substit(tmplbuf); puts(tmplbuf);} |
||
415 | continue; |
||
416 | } |
||
417 | strip_trailing_spaces(tmplbuf); |
||
418 | if(tmplbuf[1]==0 || strcmp(msg,tmplbuf+1)==0) send=1; |
||
419 | else send=0; |
||
10 | reyssat | 420 | } |
421 | close_working_file(&mf,0); |
||
422 | outptr=outbuf; delete_pid(); exit(1); |
||
423 | } |
||
424 | |||
5505 | bpr | 425 | /* Output kernel routine */ |
10 | reyssat | 426 | void _output_(char *s) |
427 | { |
||
428 | int l,l2; |
||
429 | l=strlen(s); output_length+=l; |
||
430 | if(output_length>=OUTPUT_LENGTH_LIMIT) { |
||
5505 | bpr | 431 | module_error("output_too_long"); return; |
10 | reyssat | 432 | } |
433 | l2=sizeof(outbuf)-(outptr-outbuf); |
||
434 | put: if(l<=l2) { |
||
5505 | bpr | 435 | memmove(outptr,s,l); outptr+=l; return; |
10 | reyssat | 436 | } |
437 | memmove(outptr,s,l2); s+=l2; l-=l2; |
||
3843 | kbelabas | 438 | if(lastout_file!=-1) (void)write(lastout_file,outbuf,sizeof(outbuf)); |
10 | reyssat | 439 | else fwrite(outbuf,sizeof(outbuf),1,stdout); |
440 | outptr=outbuf; l2=sizeof(outbuf); goto put; |
||
441 | } |
||
442 | |||
5505 | bpr | 443 | /* Output with no var. */ |
10 | reyssat | 444 | void output0(char buf[]) |
445 | { |
||
446 | char *p1, *p2, *ps; |
||
447 | int dynsave; |
||
448 | if(backslash_insmath) { |
||
5505 | bpr | 449 | ps=buf; dynsave=instex_usedynamic; |
450 | for(p1=strstr(buf,"\\("); p1; p1=strstr(p2,"\\(")) { |
||
451 | p2=find_matching(p1+2,')'); |
||
452 | if(p2==NULL) break; |
||
453 | if(p1>buf && *(p1-1)=='\\') continue; |
||
454 | *p1=0; if(*(p2-1)=='\\') *(p2-1)=0; *p2++=0; _output_(ps); ps=p2; |
||
455 | instex_usedynamic=1; insmath(p1+2); |
||
456 | } |
||
457 | if(*ps) _output_(ps); instex_usedynamic=dynsave; |
||
10 | reyssat | 458 | } |
459 | else _output_(buf); |
||
460 | } |
||
461 | |||
5505 | bpr | 462 | /* Output routine */ |
10 | reyssat | 463 | void output(char *s,...) |
464 | { |
||
465 | va_list vp; |
||
466 | char buf[4*MAX_LINELEN+1]; |
||
467 | |||
468 | va_start(vp,s); |
||
469 | vsnprintf(buf,sizeof(buf),s,vp); |
||
470 | va_end(vp); |
||
471 | output0(buf); |
||
472 | } |
||
473 | |||
5505 | bpr | 474 | /* read in tmpf in tmp directory, and places in p. |
475 | * Maximal length: MAX_LINELEN. */ |
||
10 | reyssat | 476 | void read_tmp_file(char *p, const char *fname) |
477 | { |
||
478 | char *name, *pp; |
||
479 | name=mkfname(NULL,"%s/%s",tmp_dir,fname); |
||
480 | if(!exec_is_module || !outputing || !direct_exec |
||
481 | || strcmp(fname,"exec.out")!=0) { |
||
5505 | bpr | 482 | readfile(name,p,MAX_LINELEN); |
483 | pp=getvar("wims_exec_dollar_double"); |
||
484 | if(pp && strcmp(pp,"yes")==0) { |
||
485 | for(pp=strchr(p,'$'); pp; pp=strchr(pp+2,'$')) |
||
486 | string_modify(p,pp,pp+1,"$$"); |
||
487 | } |
||
10 | reyssat | 488 | } |
489 | else { |
||
5505 | bpr | 490 | char *s; |
491 | s=readfile(name,NULL,OUTPUT_LENGTH_LIMIT); |
||
492 | if(s==NULL) {*p=0; return;} |
||
493 | if(memcmp(s,"Error: ", strlen("Error: "))==0) mystrncpy(p,s,MAX_LINELEN); |
||
494 | output_length+=strlen(s); |
||
495 | if(output_length>=OUTPUT_LENGTH_LIMIT) module_error("output_too_long"); |
||
496 | else _output_(s); |
||
497 | free(s); *p=0; |
||
498 | chmod(name,S_IRUSR|S_IWUSR); |
||
10 | reyssat | 499 | } |
500 | } |
||
501 | |||
5505 | bpr | 502 | /* verify whether the module is trusted. |
503 | * Returns 1 if yes, 0 if no. -1 for error. */ |
||
10 | reyssat | 504 | int trusted_module(void) |
505 | { |
||
506 | char *modname, *w, buf[MAX_LINELEN+1]; |
||
507 | int i,n; |
||
5505 | bpr | 508 | static int _trusted=-1; /* avoid repeated computations */ |
7646 | bpr | 509 | |
10 | reyssat | 510 | if(untrust&255) return 0; |
511 | if(_trusted>=0) return _trusted; |
||
512 | modname=getvar(ro_name[ro_module]); |
||
513 | if(modname==NULL || *modname==0) return 0; |
||
7646 | bpr | 514 | if(memcmp(modname,"adm/",strlen("adm/"))==0 || |
515 | memcmp(modname,"classes/",strlen("classes/"))==0 || |
||
10 | reyssat | 516 | strcmp(modname,home_module)==0 || |
517 | memcmp(modname,"help/",strlen("help/"))==0) { |
||
5505 | bpr | 518 | tr: |
519 | if(memcmp(modname,"classes/",strlen("classes/"))==0) |
||
520 | is_class_module=1; |
||
521 | setenv("trusted_module","yes",1); |
||
522 | return _trusted=1; |
||
10 | reyssat | 523 | } |
524 | n=wordnum(trusted_modules); for(i=0;i<n;i++) { |
||
5505 | bpr | 525 | w=fnd_word(trusted_modules,i+1,buf); |
526 | if(strcmp(w,modname)==0) goto tr; |
||
10 | reyssat | 527 | } |
528 | return _trusted=0; |
||
529 | } |
||
530 | |||
7646 | bpr | 531 | /* file should be in the module directory, but |
5505 | bpr | 532 | * it may also be somewhere else. |
533 | * buf[] requires MAX_FNAME+1 length. |
||
534 | * Returns 0 if found. */ |
||
10 | reyssat | 535 | int find_module_file(char *fname, char buf[], int mode) |
536 | { |
||
537 | char *p, dtest[32]; |
||
7646 | bpr | 538 | |
10 | reyssat | 539 | fname=find_word_start(fname); |
540 | if(*fname==0) return -1; |
||
5505 | bpr | 541 | /* Name checking: no directory backtracing. */ |
10 | reyssat | 542 | if(strstr(fname,parent_dir_string)!=NULL) { |
5505 | bpr | 543 | setvar(error_data_string,fname); module_error("illegal_fname"); |
544 | return -1; |
||
10 | reyssat | 545 | } |
546 | p=strchr(fname,'/'); if(p==NULL || p>fname+10) goto openit; |
||
547 | memmove(dtest,fname,p-fname); dtest[p-fname]=0; |
||
548 | if(strcmp(dtest,"datamodule")==0) { |
||
5505 | bpr | 549 | mkfname(buf,"modules/data%s",p); goto lastopen; |
10 | reyssat | 550 | } |
551 | if(strcmp(dtest,"wimshome")==0 && trusted_module()) { |
||
5505 | bpr | 552 | mkfname(buf,"%s%s",getvar("wims_home"),p); goto lastopen; |
10 | reyssat | 553 | } |
554 | if(strcmp(dtest,"writable")==0) { |
||
5505 | bpr | 555 | if(strncmp(p+1,"TEMP_",5)==0 && strchr(p+1,'/')==NULL) { |
556 | mkfname(buf,"%s/%s",tmp_dir,p+1); |
||
557 | } |
||
558 | else { |
||
559 | mkfname(buf,"w/%s/%s",module_prefix,p+1); |
||
560 | } |
||
7646 | bpr | 561 | untrust|=4; |
10 | reyssat | 562 | } |
563 | else { |
||
5505 | bpr | 564 | openit: mkfname(buf,"%s/%s",module_prefix,fname); |
10 | reyssat | 565 | } |
566 | if(mode) return 0; |
||
567 | if(ftest(buf)!=is_file) { |
||
5505 | bpr | 568 | if(lastftype==is_exec) { |
10 | reyssat | 569 | isexec: |
5505 | bpr | 570 | setvar("executable",fname); module_error("executable"); |
571 | return -1; |
||
572 | } |
||
7646 | bpr | 573 | if(strncmp(fname,"adm/",4)==0 && |
5505 | bpr | 574 | (!trusted_module() || is_class_module)) return -1; |
575 | mkfname(buf,"scripts/%s",fname); |
||
576 | lastopen: |
||
577 | if(mode) return 0; |
||
578 | if(ftest(buf)!=is_file) { |
||
579 | if(lastftype==is_exec) goto isexec; |
||
580 | else return -1; |
||
581 | } |
||
10 | reyssat | 582 | } |
583 | return 0; |
||
584 | } |
||
585 | |||
5505 | bpr | 586 | /* check whether a file is user-submitted */ |
587 | /* This is deprecated because of the wimshome/ method. */ |
||
10 | reyssat | 588 | /* int user_file(char *name) { |
589 | if(name[0]=='/' || name[0]=='.' || |
||
7646 | bpr | 590 | strstr(name,"classes/")!=NULL || |
10 | reyssat | 591 | strstr(name,"forums/")!=NULL || |
592 | strstr(name,"sessions/")!=NULL || |
||
593 | strstr(name,"doc/")!=NULL) return 1; else return 0; |
||
594 | } */ |
||
595 | |||
5505 | bpr | 596 | /* returns 1 if violation */ |
10 | reyssat | 597 | int datafile_check(char *name) { |
598 | if((untrust&255)==0) return 0; |
||
599 | if(strncmp(name,"data/",strlen("data/"))==0) return 0; |
||
600 | if(strncmp(name,"authors/",strlen("authors/"))==0) return 0; |
||
5333 | bpr | 601 | if(strncmp(name,"datamodule/",strlen("datamodule/"))==0) return 0; |
10 | reyssat | 602 | return 1; |
603 | } |
||
604 | |||
5505 | bpr | 605 | /* returns 0 if success */ |
10 | reyssat | 606 | void readdatafile(char *name) |
607 | { |
||
608 | char *pp; |
||
609 | if(strcmp(name,lastdatafile)==0) return; |
||
610 | lastdata[0]=0; readfile(name,lastdata,WORKFILE_LIMIT); |
||
611 | mystrncpy(lastdatafile,name,sizeof(lastdatafile)); |
||
612 | datacache[0]=lastdata; nextdatacache=1; |
||
613 | if(lastdata[0]==tag_string[1]) { |
||
5505 | bpr | 614 | datacache[1]=lastdata; nextdatacache++; |
10 | reyssat | 615 | } |
616 | pp=strstr(lastdata,tag_string); |
||
617 | if(pp) datacache[nextdatacache]=pp; |
||
618 | else datacache[nextdatacache]=lastdata+strlen(lastdata); |
||
619 | } |
||
620 | |||
621 | char *_nextdata(char *p) |
||
622 | { |
||
623 | char *pp; |
||
624 | if(!*p) return p; |
||
625 | pp=strstr(p,tag_string); |
||
626 | if(pp) return pp; |
||
627 | else return p+strlen(p); |
||
628 | } |
||
629 | |||
5505 | bpr | 630 | /* datafile structure: number of records. |
631 | * tag=1 if direct access */ |
||
10 | reyssat | 632 | unsigned int datafile_recordnum(char *p) |
633 | { |
||
634 | char nbuf[MAX_LINELEN+1], *pp; |
||
635 | int i, t, ret; |
||
636 | |||
637 | t=untrust; ret=0; |
||
638 | if(direct_datafile) mystrncpy(nbuf,p,sizeof(nbuf)); |
||
639 | else if(datafile_check(p)!=0 || find_module_file(p,nbuf,0)) goto ret; |
||
7646 | bpr | 640 | readdatafile(nbuf); |
10 | reyssat | 641 | for(i=nextdatacache, pp=datacache[i]; *pp;) { |
5505 | bpr | 642 | pp=_nextdata(pp+1); i++; |
643 | if(i<DATAFIELD_LIMIT) { |
||
644 | datacache[i]=pp; nextdatacache=i; |
||
645 | } |
||
10 | reyssat | 646 | } |
647 | ret=i-1; |
||
648 | ret: |
||
649 | untrust=t; |
||
650 | return ret; |
||
651 | } |
||
652 | |||
5505 | bpr | 653 | /* datafile structure: find record n, starting from 1 */ |
10 | reyssat | 654 | char *datafile_fnd_record(char *p, int n, char bf[]) |
655 | { |
||
656 | char nbuf[MAX_LINELEN+1], *pp, *p2; |
||
657 | int i, t; |
||
658 | |||
659 | bf[0]=0; t=untrust; |
||
660 | if(n<0) goto ret; |
||
661 | if(direct_datafile) mystrncpy(nbuf,p,sizeof(nbuf)); |
||
662 | else if(datafile_check(p)!=0 || find_module_file(p,nbuf,0)) goto ret; |
||
663 | readdatafile(nbuf); if(*lastdata==0) goto ret; |
||
664 | if(n>nextdatacache) { |
||
5505 | bpr | 665 | for(i=nextdatacache, pp=datacache[i]; i<n && *pp;) { |
666 | pp=_nextdata(pp+1); i++; |
||
667 | if(i<DATAFIELD_LIMIT) { |
||
668 | datacache[i]=pp; nextdatacache=i; |
||
669 | } |
||
670 | } |
||
10 | reyssat | 671 | } |
672 | else pp=datacache[n]; |
||
673 | if(!*pp) goto ret; |
||
674 | if(n>1 || (n==1 && *pp!=tag_string[1])) pp+=strlen(tag_string); |
||
675 | else if(n==1) pp+=strlen(tag_string)-1; |
||
676 | if(n<nextdatacache) p2=datacache[n+1]; |
||
677 | else { |
||
5505 | bpr | 678 | p2=strstr(pp,tag_string); if(p2==NULL) p2=pp+strlen(pp); |
679 | if(n<DATAFIELD_LIMIT-1 && n==nextdatacache) { |
||
680 | nextdatacache++; datacache[nextdatacache]=p2; |
||
681 | } |
||
10 | reyssat | 682 | } |
683 | if(p2-pp>=MAX_LINELEN) p2=pp+MAX_LINELEN-1; |
||
684 | if(p2<pp) p2=pp; |
||
685 | memmove(bf,pp,p2-pp); bf[p2-pp]=0; |
||
686 | ret: |
||
687 | untrust=t; return bf; |
||
688 | } |
||
689 | |||
690 | char hex2char(char c1, char c2) |
||
691 | { |
||
692 | char tbuf[16]; |
||
693 | if(c1<'0' || c1>'f' || c2<'0' || c2>'f') { |
||
694 | invl: |
||
5505 | bpr | 695 | snprintf(tbuf,sizeof(tbuf),"%%%c%c",c1,c2); |
696 | setvar(error_data_string,tbuf); |
||
697 | user_error("invalid_char_in_query_string"); |
||
10 | reyssat | 698 | } |
699 | c1=toupper(c1);c2=toupper(c2); |
||
700 | if(c1>'9' && c1<'A') goto invl; |
||
701 | if(c2>'9' && c2<'A') goto invl; |
||
702 | if(c1>'F' || c2>'F') goto invl; |
||
703 | if(c1>='A') c1=c1-'A'+'9'+1; |
||
704 | if(c2>='A') c2=c2-'A'+'9'+1; |
||
705 | return (c1-'0')*16+c2-'0'; |
||
706 | } |
||
707 | |||
5505 | bpr | 708 | /* Converts back http escaped chars, slight. Does not check buffer length. |
709 | * Returns converted string length. */ |
||
10 | reyssat | 710 | int _http2env(char outs[], char ins[]) |
711 | { |
||
712 | int j,k,l; |
||
713 | l=strlen(ins); |
||
714 | for(j=k=0;j<l && !isspace(ins[j]);j++,k++) { |
||
5505 | bpr | 715 | if(isspace(ins[j])) { /* skip space characters in query string */ |
716 | k--;continue; |
||
717 | } |
||
718 | if(ins[j]=='%') { |
||
719 | /* skip Carriage-Return. */ |
||
720 | if(ins[j+1]=='0' && (ins[j+2]=='d' || ins[j+2]=='D')) { |
||
721 | j+=2; k--; continue; |
||
722 | } |
||
723 | outs[k]=hex2char(ins[j+1],ins[j+2]); |
||
724 | j+=2; continue; |
||
725 | } |
||
726 | outs[k]=ins[j]; |
||
10 | reyssat | 727 | } |
7646 | bpr | 728 | outs[k]=0; |
10 | reyssat | 729 | return k; |
730 | } |
||
731 | |||
5505 | bpr | 732 | /* Converts back http escaped chars. Does not check buffer length. |
733 | * Returns converted string length. */ |
||
10 | reyssat | 734 | int http2env(char outs[], char ins[]) |
735 | { |
||
736 | int j,k,l; |
||
737 | l=strlen(ins); |
||
738 | for(j=k=0;j<l && !isspace(ins[j]);j++,k++) { |
||
5505 | bpr | 739 | if(isspace(ins[j])) { /* skip space characters in query string */ |
740 | k--;continue; |
||
741 | } |
||
742 | if(ins[j]=='%') { |
||
743 | /* skip Carriage-Return. */ |
||
744 | if(ins[j+1]=='0' && (ins[j+2]=='d' || ins[j+2]=='D')) { |
||
745 | j+=2; k--; continue; |
||
746 | } |
||
747 | outs[k]=hex2char(ins[j+1],ins[j+2]); |
||
748 | j+=2; continue; |
||
749 | } |
||
750 | if(ins[j]=='+') { |
||
751 | outs[k]=' '; continue; |
||
752 | } |
||
753 | if(ins[j]=='?' || ins[j]=='&') { |
||
754 | outs[k]=0; continue; |
||
755 | } |
||
756 | outs[k]=ins[j]; |
||
10 | reyssat | 757 | } |
7646 | bpr | 758 | outs[k]=0; |
10 | reyssat | 759 | return k; |
760 | } |
||
761 | |||
5505 | bpr | 762 | /* translate a string to http querystring style. |
763 | * '&' is not translated. |
||
764 | * Buffer p must be at least MAX_LINELEN. */ |
||
10 | reyssat | 765 | void tohttpquery(char *p) |
766 | { |
||
767 | char trlist[]=" ()[]{}+-*^|/\"\'!:;,<>\n"; |
||
768 | char *pp; |
||
769 | for(pp=p;*pp;pp++) { |
||
5505 | bpr | 770 | if(*pp==' ') { |
771 | *pp='+'; continue; |
||
772 | } |
||
773 | if(strchr(trlist,*pp)==NULL) continue; |
||
774 | if(*pp=='+' && pp>p && *(pp-1)=='&') continue; |
||
775 | if(pp>p && *(pp-1)=='\\') { |
||
776 | ovlstrcpy(pp-1,pp);pp--;continue; |
||
777 | } |
||
778 | if(*pp=='\n') { |
||
779 | string_modify(p,pp,pp+1,"%%0D%%0A");pp+=5; |
||
780 | } |
||
781 | else { |
||
782 | string_modify(p,pp,pp+1,"%%%02X",*pp);pp+=2; |
||
783 | } |
||
10 | reyssat | 784 | } |
785 | } |
||
786 | |||
5505 | bpr | 787 | /* substitute backslash parameters. Internal use only. */ |
10 | reyssat | 788 | void slashsubst(char *p) |
789 | { |
||
790 | char *p1, *p2, *pt, *pp, namebuf[128]; |
||
791 | int n; |
||
792 | |||
793 | n=strlen(mathfont_prefix); memmove(namebuf,mathfont_prefix,n+1); |
||
794 | for(p1=strchr(p,'\\'); p1!=NULL; p1=strchr(p1,'\\')) { |
||
5505 | bpr | 795 | p1++; for(p2=p1; myisalnum(*p2) || *p2=='_'; p2++); |
796 | if(p2<=p1 || p2>p1+100) continue; |
||
797 | memmove(namebuf+n,p1,p2-p1); namebuf[p2-p1+n]=0; |
||
798 | pt=_getvar(namebuf); if(pt==NULL) continue; |
||
799 | if(*p2=='[' && (pp=find_matching(p2+1,']'))!=NULL) { |
||
800 | string_modify(p,pp+1,pp+1,")"); |
||
801 | string_modify(p,p1-1,p1,"$(%s",mathfont_prefix); |
||
802 | } |
||
803 | else string_modify(p,p1-1,p1,"$%s",mathfont_prefix); |
||
10 | reyssat | 804 | } |
805 | } |
||
806 | |||
5505 | bpr | 807 | /* two alarm handlers. */ |
10 | reyssat | 808 | void alarm1(int s) |
809 | { |
||
810 | if(killpid>0 && kill(killpid,SIGKILL)) module_error("timeup"); |
||
811 | killpid=0; |
||
812 | } |
||
813 | |||
814 | void alarm2(int s) |
||
815 | { |
||
816 | cleantmpdir(); |
||
817 | alarm1(s); module_error("timeup"); |
||
818 | } |
||
819 | |||
820 | void finalalarm(void) |
||
821 | { |
||
822 | time_t curr; |
||
823 | curr=time(0); |
||
824 | if(curr>=limtime) alarm2(SIGALRM); |
||
825 | errno=0; |
||
826 | if(signal(SIGALRM,alarm2)==SIG_ERR) |
||
827 | internal_error(strerror(errno)); |
||
828 | alarm(limtime-curr+1); |
||
829 | } |
||
830 | |||
831 | void initalarm(void) |
||
832 | { |
||
833 | limtimex=nowtime+4*rlimit_cpu/3; |
||
834 | limtime=limtimex+2; finalalarm(); |
||
835 | } |
||
836 | |||
837 | void forkalarm(void) |
||
838 | { |
||
839 | time_t curr; |
||
840 | curr=time(0); |
||
841 | if(curr>=limtimex) {alarm1(SIGALRM); return;} |
||
842 | if(signal(SIGALRM,alarm1)==SIG_ERR) |
||
843 | internal_error(strerror(errno)); |
||
844 | alarm(limtimex-curr+1); |
||
845 | } |
||
846 | |||
5505 | bpr | 847 | /* create pid tag */ |
10 | reyssat | 848 | void create_pid(void) |
849 | { |
||
850 | char buf[MAX_FNAME+1], pbuf[256], obuf[MAX_FNAME+1]; |
||
851 | struct stat dst; |
||
852 | struct utimbuf ub; |
||
7646 | bpr | 853 | |
10 | reyssat | 854 | if(robot_access || *session_prefix==0) return; |
855 | if(cmd_type==cmd_getframe) return; |
||
856 | mkfname(buf,"%s/.pid",s2_prefix); |
||
5505 | bpr | 857 | /* another process running? */ |
10 | reyssat | 858 | if(readfile(buf,pbuf,sizeof(pbuf))!=NULL) { |
5505 | bpr | 859 | mkfname(obuf,"/proc/%s",pbuf); |
860 | if(stat(obuf,&dst)==0) user_error("double_click"); |
||
10 | reyssat | 861 | } |
862 | snprintf(pidbuf,sizeof(pidbuf),"%u",getpid()); |
||
863 | accessfile(pidbuf,"w","%s",buf); |
||
5505 | bpr | 864 | /* Touch session time */ |
10 | reyssat | 865 | if(strstr(session_prefix,"sessions/")==NULL) return; |
866 | ub.actime=ub.modtime=nowtime; |
||
867 | utime(session_prefix,&ub); |
||
868 | if(strchr(session_prefix,'_')!=NULL) { /* touch parent too */ |
||
5505 | bpr | 869 | char sbuf[MAX_FNAME+1], *p; |
870 | mystrncpy(sbuf,session_prefix,sizeof(sbuf)); |
||
871 | p=strchr(sbuf,'_'); if(p!=NULL) *p=0; |
||
872 | utime(sbuf,&ub); |
||
10 | reyssat | 873 | } |
874 | } |
||
875 | |||
8185 | bpr | 876 | struct mxtab mxtab[MAX_MULTIEXEC]; |
10 | reyssat | 877 | int mxno=0; |
878 | |||
879 | int execredirected(char *cmdf, char *inf, char *outf, char *errf, char *arg[]) |
||
880 | { |
||
881 | pid_t pid; |
||
882 | int status, t; |
||
883 | |||
884 | if(robot_access) return 0; |
||
885 | if(time(0)>=limtimex) { |
||
5505 | bpr | 886 | if(errf!=NULL) |
887 | accessfile("No time left to execute subprograms.\n","w","%s",errf); |
||
888 | return -100; |
||
10 | reyssat | 889 | } |
890 | lastdatafile[0]=lastftest[0]=0; |
||
5505 | bpr | 891 | fflush(NULL); /* flush all output streams before forking |
892 | * otherwise they will be doubled */ |
||
10 | reyssat | 893 | pid=fork(); if(pid==-1) return -1; |
5505 | bpr | 894 | if(!pid) { /* child */ |
895 | char buf[MAX_LINELEN+1]; int k; |
||
896 | (void)nice(10); /* lower priority for children */ |
||
897 | if(is_multiexec) { |
||
898 | dup2(mxtab[multiexec_index].pipe_stdin[0],0); |
||
899 | dup2(mxtab[multiexec_index].pipe_stdout[1],1); |
||
900 | dup2(mxtab[multiexec_index].pipe_stderr[1],2); |
||
901 | } |
||
902 | else { |
||
903 | if(inf!=NULL) (void)freopen(inf,"r",stdin); |
||
904 | if(outf!=NULL) (void)freopen(outf,"w",stdout); |
||
905 | if(errf!=NULL) (void)freopen(errf,"w",stderr); |
||
906 | } |
||
7646 | bpr | 907 | /* This is to patch LinuxPPC uid wrapping |
5505 | bpr | 908 | * for scripts */ |
909 | t=0; if(strchr(cmdf,'/')) { |
||
910 | int tf; |
||
911 | char tbuf[16]; |
||
912 | tf=open(cmdf,O_RDONLY); (void)read(tf,tbuf,8); close(tf); |
||
913 | if(memcmp(tbuf+1,"ELF",3)!=0) t=1; |
||
914 | } |
||
915 | if(wrapexec==-1) { |
||
916 | setreuid(getuid(),getuid());setregid(getgid(),getgid()); |
||
917 | } |
||
918 | if(wrapexec==1 || (t==1 && wrapexec==0)) { |
||
919 | setreuid(geteuid(),geteuid());setregid(getegid(),getegid()); |
||
920 | } |
||
921 | errno=0; |
||
922 | if(strchr(cmdf,'/')) execve(cmdf,arg,environ); |
||
923 | else execvp(cmdf,arg); |
||
924 | snprintf(buf,sizeof(buf),"Failed to execute"); |
||
925 | for(k=0;arg[k];k++) { |
||
926 | t=strlen(buf); |
||
927 | snprintf(buf+t,sizeof(buf)-t," %s",arg[k]); |
||
928 | } |
||
929 | t=strlen(buf); |
||
930 | snprintf(buf+t,sizeof(buf)-t,"\n %s\n",strerror(errno)); |
||
931 | accessfile(buf,"a","%s/exec.fail",tmp_dir); |
||
932 | exit(127); |
||
10 | reyssat | 933 | } |
5505 | bpr | 934 | else { /* parent */ |
7646 | bpr | 935 | wrapexec=0; status=0; |
5505 | bpr | 936 | if(exec_wait && !is_multiexec) { |
937 | killpid=pid; forkalarm(); |
||
938 | waitpid(pid,&status,0); killpid=0; finalalarm(); |
||
939 | } |
||
940 | return WEXITSTATUS(status); |
||
10 | reyssat | 941 | } |
942 | } |
||
943 | |||
5505 | bpr | 944 | /* preparation for resident execution. |
945 | * Returns 1 if already up, otherwise 0. */ |
||
10 | reyssat | 946 | int multiexec(char *cmd, char **abuf) |
947 | { |
||
948 | char *p; |
||
949 | int i; |
||
7646 | bpr | 950 | |
10 | reyssat | 951 | if(robot_access) return 0; |
952 | if(strstr(tmp_dir,"sessions/")==NULL) return 0; |
||
7646 | bpr | 953 | if(strstr(tmp_debug,"yes")!=NULL && checkhost(manager_site)>=1) |
10 | reyssat | 954 | setenv("multiexec_debug","yes",1); |
955 | p=getvar("wims_multiexec"); |
||
956 | if(p==NULL || wordchr(p,cmd)==NULL) return 0; /* not allowed */ |
||
957 | if(!multiexec_random[0]) { |
||
5505 | bpr | 958 | snprintf(multiexec_random, sizeof(multiexec_random), |
959 | "%lX%lX%lX%lX%lX%lX%lX%lX", |
||
960 | random(),random(),random(),random(), |
||
961 | random(),random(),random(),random()); |
||
962 | setenv("multiexec_random",multiexec_random,1); |
||
10 | reyssat | 963 | } |
964 | for(i=0;i<mxno && strcmp(cmd,mxtab[i].cmd)!=0; i++); |
||
965 | multiexec_index=i; |
||
966 | if(i==mxno) { |
||
5505 | bpr | 967 | if(mxno>=MAX_MULTIEXEC) return 0; |
968 | if(pipe(mxtab[i].pipe_stdin)<0) return 0; |
||
969 | if(pipe(mxtab[i].pipe_stdout)<0) return 0; |
||
970 | if(pipe(mxtab[i].pipe_stderr)<0) return 0; |
||
971 | mystrncpy(mxtab[i].cmd,cmd,sizeof(mxtab[i].cmd)); |
||
972 | mxno++; is_multiexec=1; |
||
973 | exportall(); setenv("wims_exec_parm",multiexec_random,1); |
||
974 | execredirected(abuf[0],NULL,NULL,NULL,abuf); |
||
10 | reyssat | 975 | } |
976 | is_multiexec=0; |
||
977 | return 1; |
||
978 | } |
||
979 | |||
5505 | bpr | 980 | /* my system(), but with variable parms |
981 | * More secure than system(), and direct fork. */ |
||
10 | reyssat | 982 | int call_ssh(char *s,...) |
983 | { |
||
984 | va_list vp; |
||
985 | char buf[MAX_LINELEN+1]; |
||
986 | char *arg[1024]; |
||
987 | char *inf=NULL, *outf=NULL, *errf=NULL; |
||
988 | char *cmdf, *p, *p2; |
||
989 | int i, d; |
||
990 | |||
991 | if(robot_access) return 0; |
||
992 | va_start(vp,s); |
||
993 | vsnprintf(buf,sizeof(buf),s,vp); |
||
994 | va_end(vp); |
||
995 | p=find_word_start(buf); if(*p==0) return 0; |
||
996 | cmdf=p; |
||
997 | for(i=0;*p!=0 && i<1000; p=find_word_start(p2)) { |
||
5505 | bpr | 998 | switch(*p) { |
999 | case '\'': { |
||
1000 | p++; p2=strchr(p,'\''); if(p2==NULL) p2=p+strlen(p); |
||
1001 | d=0; break; |
||
1002 | } |
||
1003 | case '"': { |
||
1004 | p++; p2=strchr(p,'"'); if(p2==NULL) p2=p+strlen(p); |
||
1005 | d=0; break; |
||
1006 | } |
||
1007 | default: d=1; p2=find_word_end(p); break; |
||
1008 | } |
||
1009 | if(*p2) *p2++=0; |
||
1010 | if(!d) {arg[i++]=p; continue;} |
||
1011 | switch(*p) { |
||
1012 | case '<': inf=++p; break; |
||
1013 | case '>': { |
||
1014 | p++; if(*p=='&') { |
||
1015 | merge: p++; errf=outf=p; break; |
||
1016 | } |
||
1017 | else outf=p; |
||
1018 | break; |
||
1019 | } |
||
1020 | case '&': { |
||
1021 | p++; if(*p=='>') goto merge; |
||
1022 | else break; |
||
1023 | } |
||
1024 | case '2': { |
||
1025 | if(*(p+1)=='>') {errf=p+2; break;} |
||
1026 | } |
||
1027 | default: arg[i++]=p; break; |
||
1028 | } |
||
10 | reyssat | 1029 | } |
1030 | arg[i]=NULL; |
||
1031 | return execredirected(cmdf,inf,outf,errf,arg); |
||
1032 | } |
||
1033 | |||
5505 | bpr | 1034 | /* Read/write to a file with variable parms to print filename */ |
10 | reyssat | 1035 | void accessfile(char *content, char *type, char *s,...) |
1036 | { |
||
1037 | va_list vp; |
||
1038 | char buf[MAX_FNAME+1]; |
||
1039 | int fd; |
||
1040 | |||
1041 | if(robot_access) return; |
||
1042 | va_start(vp,s); |
||
1043 | vsnprintf(buf,sizeof(buf),s,vp); |
||
1044 | va_end(vp); |
||
1045 | if(strlen(buf)>=MAX_FNAME-1) nametoolong(buf); |
||
1046 | switch(*type) { |
||
5505 | bpr | 1047 | case 'r': readfile(buf,content,MAX_LINELEN); return; |
1048 | case 'e': readfile(buf,content,MAX_LINELEN/4); return; /* limited read */ |
||
1049 | case 'w': fd=creat(buf,S_IRUSR|S_IWUSR|S_IRGRP|S_IROTH); break; |
||
1050 | case 'a': fd=open(buf,O_WRONLY|O_CREAT|O_APPEND,S_IRUSR|S_IWUSR|S_IRGRP|S_IROTH); break; |
||
1051 | default : return; |
||
10 | reyssat | 1052 | } |
1053 | lastdatafile[0]=lastftest[0]=0; |
||
1054 | if(fd==-1) return; |
||
3843 | kbelabas | 1055 | (void)write(fd,content,strlen(content)); close(fd); |
10 | reyssat | 1056 | } |
1057 | |||
5505 | bpr | 1058 | /* system(), but with variable parms |
1059 | * Uses sh to execute command. */ |
||
10 | reyssat | 1060 | int call_sh(char *s,...) |
1061 | { |
||
1062 | va_list vp; |
||
1063 | char buf[MAX_LINELEN+1]; |
||
1064 | char *abuf[8]; |
||
1065 | |||
1066 | if(robot_access) return 0; |
||
1067 | va_start(vp,s); |
||
1068 | vsnprintf(buf,sizeof(buf),s,vp); |
||
1069 | va_end(vp); |
||
1070 | abuf[0]="sh"; abuf[1]="-c"; abuf[2]=buf; abuf[3]=NULL; |
||
1071 | return execredirected(abuf[0],NULL,NULL,NULL,abuf); |
||
1072 | } |
||
1073 | |||
1074 | void _getdef(char buf[], char *name, char value[]) |
||
1075 | { |
||
1076 | char *p1, *p2, *p3, *p4; |
||
1077 | |||
5505 | bpr | 1078 | if(*name==0) goto nothing; /* this would create segfault. */ |
10 | reyssat | 1079 | for(p1=strstr(buf,name); p1!=NULL; p1=strstr(p1+1,name)) { |
5505 | bpr | 1080 | p2=find_word_start(p1+strlen(name)); |
1081 | if((p1>buf && !isspace(*(p1-1))) || *p2!='=') continue; |
||
1082 | p3=p1; while(p3>buf && *(p3-1)!='\n') p3--; |
||
1083 | p3=find_word_start(p3); |
||
1084 | if(p3<p1 && *p3!='!') continue; |
||
1085 | if(p3<p1) { |
||
1086 | p3++; p4=find_word_end(p3); |
||
1087 | if(find_word_start(p4)!=p1) continue; |
||
1088 | if(p4-p3!=3 || (strncmp(p3,"set",3)!=0 && |
||
1089 | strncmp(p3,"let",3)!=0 && |
||
1090 | strncmp(p3,"def",3)!=0)) { |
||
1091 | if(p4-p3!=6 || strncmp(p3,"define",6)!=0) continue; |
||
1092 | } |
||
1093 | } |
||
1094 | p2++;p3=strchr(p2,'\n'); if(p3==NULL) p3=p2+strlen(p2); |
||
1095 | p2=find_word_start(p2); |
||
1096 | if(p2>p3) goto nothing; |
||
1097 | if(p3-p2>=MAX_LINELEN) user_error("cmd_output_too_long"); |
||
1098 | memmove(value,p2,p3-p2); value[p3-p2]=0; |
||
1099 | strip_trailing_spaces(value); return; |
||
10 | reyssat | 1100 | } |
1101 | nothing: |
||
1102 | value[0]=0; return; |
||
1103 | } |
||
1104 | |||
8155 | bpr | 1105 | /* Get variable definition from a file. |
1106 | * Result stored in buffer value of length MAX_LINELEN. |
||
1107 | */ |
||
10 | reyssat | 1108 | void getdef(char *fname, char *name, char value[]) |
1109 | { |
||
1110 | char buf[MAX_LINELEN+1], tbuf[MAX_LINELEN+1], nbuf[MAX_NAMELEN+1]; |
||
1111 | char *p1, *p2; |
||
1112 | |||
1113 | value[0]=0; if(readfile(fname,buf,sizeof(buf)-16)==NULL) return; |
||
1114 | mystrncpy(value,name,MAX_LINELEN); |
||
1115 | for(p1=value; *p1; p1=p2) { |
||
5505 | bpr | 1116 | while(*p1 && !myisalnum(*p1) && *p1!='_') p1++; |
1117 | if(*p1==0) break; |
||
1118 | for(p2=p1; myisalnum(*p2) || *p2=='_'; p2++); |
||
1119 | if(p2-p1>MAX_NAMELEN) continue; |
||
1120 | memmove(nbuf,p1,p2-p1); nbuf[p2-p1]=0; |
||
1121 | _getdef(buf,nbuf,tbuf); |
||
1122 | string_modify(value,p1,p2,"%s",tbuf); |
||
1123 | p2=p1+strlen(tbuf); |
||
10 | reyssat | 1124 | } |
1125 | } |
||
1126 | |||
1127 | int _setdef_changed; |
||
1128 | |||
1129 | void _setdef(char buf[], char *name, char *value) |
||
1130 | { |
||
1131 | char *p1, *p2, *p3; |
||
1132 | int n; |
||
7646 | bpr | 1133 | |
10 | reyssat | 1134 | for(p1=strstr(buf,name); p1!=NULL; p1=strstr(p1+1,name)) { |
5505 | bpr | 1135 | p2=find_word_start(p1+strlen(name)); |
1136 | if((p1>buf && !isspace(*(p1-1))) || *p2!='=') continue; |
||
1137 | p3=p1; while(p3>buf && *(p3-1)==' ') p3--; |
||
1138 | if(p3>buf && *(p3-1)!='\n') continue; |
||
1139 | p2++;p3=strchr(p2,'\n'); if(p3==NULL) p3=p2+strlen(p2); |
||
1140 | if(strlen(value)!=p3-p2 || strncmp(value,p2,p3-p2)!=0) { |
||
1141 | string_modify(buf,p2,p3,"%s",value); |
||
1142 | _setdef_changed++; |
||
1143 | } |
||
1144 | return; |
||
10 | reyssat | 1145 | } |
1146 | n=strlen(buf); |
||
7646 | bpr | 1147 | if(n>0 && buf[n-1]!='\n') |
10 | reyssat | 1148 | snprintf(buf+n,MAX_LINELEN-n,"\n%s=%s\n",name,value); |
1149 | else |
||
1150 | snprintf(buf+n,MAX_LINELEN-n,"%s=%s\n",name,value); |
||
1151 | _setdef_changed++; |
||
1152 | } |
||
1153 | |||
8155 | bpr | 1154 | /* Set variable definition to a file. */ |
10 | reyssat | 1155 | void setdef(char *fname, char *name) |
1156 | { |
||
1157 | char buf[MAX_LINELEN+1]; |
||
1158 | char *p1, *p2, *p3; |
||
1159 | |||
1160 | _setdef_changed=0; |
||
1161 | if(strchr(name,'=')==NULL) return; |
||
1162 | for(p1=name;*p1;p1++) { |
||
5505 | bpr | 1163 | if(isspace(*p1) && *p1!=' ' && *p1!='\n') *p1=' '; |
1164 | if(*p1==' ') { |
||
1165 | for(p2=p1+1; isspace(*p2) && *p2!='\n'; p2++); |
||
1166 | if(p2>p1+1) ovlstrcpy(p1+1,p2); |
||
1167 | p2=p1+1; if(*p2=='=' || *p2=='\n') ovlstrcpy(p1,p2); |
||
1168 | } |
||
10 | reyssat | 1169 | } |
1170 | if(readfile(fname,buf,sizeof(buf))==NULL) buf[0]=0; |
||
1171 | for(p1=find_word_start(name); p1!=NULL; p1=p2) { |
||
5505 | bpr | 1172 | p2=strchr(p1,'\n'); if(p2!=NULL) *p2++=0; |
1173 | p1=find_word_start(p1); |
||
1174 | p3=strchr(p1,'='); if(p3==NULL) continue; |
||
1175 | *p3++=0; p3=find_word_start(p3); |
||
1176 | _setdef(buf,p1,p3); |
||
10 | reyssat | 1177 | } |
1178 | if(_setdef_changed) accessfile(buf,"w","%s",fname); |
||
1179 | } |
||
1180 | |||
8155 | bpr | 1181 | /* check whether connecting host is part of given list. |
1182 | * Returns 0 if no, 1 if yes. |
||
1183 | */ |
||
10 | reyssat | 1184 | int checkhost(char *hlist) |
1185 | { |
||
1186 | char buf[MAX_LINELEN+1]; |
||
1187 | char lbuf[1024], hbuf1[256], hbuf2[256]; |
||
1188 | char *p1, *p2, *pb, *pe, *pp; |
||
7646 | bpr | 1189 | |
10 | reyssat | 1190 | if(*remote_addr==0) return 0; |
1191 | snprintf(hbuf1,sizeof(hbuf1),"+%s+",remote_addr); |
||
1192 | if(*remote_host!=0) { |
||
5505 | bpr | 1193 | snprintf(hbuf2,sizeof(hbuf2),"+%s+",remote_host); |
1194 | for(p1=hbuf2; *p1; p1++) *p1=tolower(*p1); |
||
10 | reyssat | 1195 | } |
1196 | else hbuf2[0]=0; |
||
1197 | mystrncpy(buf,find_word_start(hlist),sizeof(buf)); strip_trailing_spaces(buf); |
||
1198 | for(p1=buf; *p1; p1++) { |
||
5505 | bpr | 1199 | *p1=tolower(*p1); |
1200 | if(!myisalnum(*p1) && strchr(".-_",*p1)==NULL) *p1=' '; |
||
10 | reyssat | 1201 | } |
5505 | bpr | 1202 | if(strcmp(buf,"all")==0) return 1; /* all is all */ |
10 | reyssat | 1203 | for(p1=find_word_start(buf); *p1; p1=find_word_start(p2)) { |
5505 | bpr | 1204 | p2=find_word_end(p1); if(*p2) *p2++=0; |
1205 | if(p2-p1<3) continue; |
||
1206 | if(myisalnum(*p1)) pb="+"; else pb=""; |
||
1207 | if(myisalnum(*(p2-1))) pe="+"; else pe=""; |
||
1208 | snprintf(lbuf,sizeof(lbuf),"%s%s%s",pb,p1,pe); |
||
7646 | bpr | 1209 | for(pp=p1; *pp && (myisdigit(*pp) || *pp=='.'); pp++); |
5505 | bpr | 1210 | if(*pp) pp=hbuf2; /* host name */ |
1211 | else pp=hbuf1; /* ip number */ |
||
1212 | if(strstr(pp,lbuf)!=NULL) return 1; /* found */ |
||
10 | reyssat | 1213 | } |
1214 | return 0; |
||
1215 | } |
||
1216 | |||
8155 | bpr | 1217 | /* return 1 if a word of bf2 is a substring of host. |
1218 | * Like checkhost, but with time check. |
||
1219 | * The content of bf2[] is destroyed. |
||
1220 | */ |
||
10 | reyssat | 1221 | int checkhostt(char bf2[]) |
1222 | { |
||
1223 | char *p1, *p2, *p3; |
||
8155 | bpr | 1224 | /* compare with starting time */ |
10 | reyssat | 1225 | for(p1=strchr(bf2,'>'); p1!=NULL; p1=strchr(p1+1,'>')) { |
5505 | bpr | 1226 | if(p1>bf2 && !isspace(*(p1-1))) continue; |
1227 | p3=find_word_start(++p1); p2=find_word_end(p3); |
||
1228 | if(p2-p3!=14) continue; |
||
1229 | p3[8]='.'; p3[11]=':'; if(*p2) *p2++=0; |
||
1230 | if(strncmp(nowstr,p3,14)<0) return 0; |
||
1231 | ovlstrcpy(p1-1,p2); p1-=2; |
||
10 | reyssat | 1232 | } |
8155 | bpr | 1233 | /* compare with ending time */ |
10 | reyssat | 1234 | for(p1=strchr(bf2,'<'); p1!=NULL; p1=strchr(p1+1,'<')) { |
5505 | bpr | 1235 | if(p1>bf2 && !isspace(*(p1-1))) continue; |
1236 | p3=find_word_start(++p1); p2=find_word_end(p3); |
||
1237 | if(p2-p3!=14) continue; |
||
1238 | p3[8]='.'; p3[11]=':'; if(*p2) *p2++=0; |
||
1239 | if(strncmp(nowstr,p3,14)>0) return 0; |
||
1240 | ovlstrcpy(p1-1,p2); p1-=2; |
||
10 | reyssat | 1241 | } |
1242 | p1=find_word_start(bf2); if(*p1==0) return 1; |
||
1243 | return checkhost(p1); |
||
1244 | } |
||
1245 | |||
8155 | bpr | 1246 | /* bad identification */ |
10 | reyssat | 1247 | void bad_ident(void) |
1248 | { |
||
1249 | if(cookiegot[0]!=0) { |
||
1250 | } |
||
1251 | user_error("bad_ident"); |
||
1252 | } |
||
1253 | |||
1254 | void instex_flush(void) |
||
1255 | { |
||
1256 | char *p; |
||
1257 | setenv("texgif_style","",1); |
||
1258 | setenv("texgif_tmpdir",tmp_dir,1); |
||
1259 | setenv("texgif_src",instex_src,1); |
||
1260 | setenv("texgif_outfile",instex_fname,1); |
||
1261 | unsetenv("w_instex_color"); |
||
1262 | getwimstexsize=0; fix_tex_size(); getwimstexsize=1; |
||
1263 | for(p=instex_fname;*p;p++) if(*p=='\n') *p=' '; |
||
1264 | wrapexec=0; call_ssh("%s/%s >%s/ins.Out 2>%s/ins.Err", |
||
5505 | bpr | 1265 | bin_dir,instex_processor, |
1266 | tmp_dir,tmp_dir); |
||
10 | reyssat | 1267 | call_ssh("mv %s %s >/dev/null 2>/dev/null", instex_fname,s2_prefix); |
1268 | instex_src[0]=instex_fname[0]=0; instex_cnt=0; |
||
1269 | } |
||
1270 | |||
8155 | bpr | 1271 | /* put last.phtml */ |
10 | reyssat | 1272 | void putlastout(void) |
1273 | { |
||
1274 | int t; |
||
1275 | if(instex_cnt>0) instex_flush(); |
||
1276 | t=catfile(stdout,"%s/%s",s2_prefix,lastout); |
||
1277 | if(t==0) printf("Content-type: text/plain\r\n\r\n"); |
||
1278 | } |
||
1279 | |||
1280 | struct sockaddr_un sun; |
||
1281 | |||
8155 | bpr | 1282 | /* returns >=0 if OK. */ |
7646 | bpr | 1283 | |
10 | reyssat | 1284 | int kerneld(char *p, int bufsize) |
1285 | { |
||
1286 | int sock, s, t, t1, l, *ip; |
||
1287 | struct timeval tv; |
||
1288 | fd_set rset; |
||
1289 | sock=socket(PF_UNIX,SOCK_STREAM,0); |
||
1290 | s=connect(sock,(const struct sockaddr *)&sun,sizeof(sun)); |
||
1291 | if(s) {bad: close(sock); return -1;} |
||
1292 | ip=(int *) p; |
||
1293 | l=strlen(p+sizeof(int)); *ip=l; |
||
1294 | s=write(sock,p,l+sizeof(int)); if(s!=l+sizeof(int)) goto bad; |
||
1295 | for(t=0, l=bufsize-1; t<l+sizeof(int);) { |
||
5505 | bpr | 1296 | tv.tv_sec=2; tv.tv_usec=0; |
1297 | FD_ZERO(&rset); FD_SET(sock,&rset); |
||
1298 | if(select(sock+1,&rset,NULL,NULL,&tv)<=0) goto bad; |
||
7646 | bpr | 1299 | t1=read(sock,p+t,l+sizeof(int)-t); |
5505 | bpr | 1300 | if(t1+t<sizeof(int)) goto bad; |
7646 | bpr | 1301 | if (t1 < 0) goto bad; |
5505 | bpr | 1302 | l=*ip; if(l<=0) goto bad; |
1303 | if(l>=bufsize-sizeof(int)-4) user_error("cmd_output_too_long"); |
||
1304 | t+=t1; |
||
10 | reyssat | 1305 | } |
1306 | p[l+sizeof(int)]=0; |
||
1307 | close(sock); |
||
1308 | return l+sizeof(int); |
||
1309 | } |
||
1310 | |||
1311 | void _daemoncmd(char *p) |
||
1312 | { |
||
1313 | char buf[MAX_LINELEN+1+sizeof(int)]; |
||
1314 | char *p1, *p2, *p3; |
||
1315 | mystrncpy(buf+sizeof(int),p,sizeof(buf)-sizeof(int)); |
||
7646 | bpr | 1316 | if(kerneld(buf,sizeof(buf))<0) |
10 | reyssat | 1317 | internal_error("Daemon communication error."); |
1318 | p1=find_word_start(buf+sizeof(int)); |
||
1319 | p2=find_word_end(p1); if(*p2) *p2++=0; |
||
1320 | if(strcmp(p1,"OK")==0) { |
||
5505 | bpr | 1321 | mystrncpy(p,p2,MAX_LINELEN); return; |
10 | reyssat | 1322 | } |
1323 | p1=find_word_start(p2); p2=find_word_end(p1); if(*p2) *p2++=0; |
||
7646 | bpr | 1324 | p2=find_word_start(p2); p3=find_word_end(p2); |
10 | reyssat | 1325 | if(*p3) { |
5505 | bpr | 1326 | *p3++=0; p3=find_word_start(p3); strip_trailing_spaces(p3); |
1327 | setvar("wims_error_data",p3); |
||
10 | reyssat | 1328 | } |
1329 | switch(*p1) { |
||
5505 | bpr | 1330 | case '1': user_error(p2); |
1331 | case '2': module_error(p2); |
||
1332 | case '3': |
||
1333 | default: internal_error(p2); |
||
10 | reyssat | 1334 | } |
1335 | *p=0; |
||
1336 | } |
||
1337 |