1 /* $NetBSD: conf.c,v 1.52 2004-08-09 12:56:47 lukem Exp $ */
4 * Copyright (c) 1997-2004 The NetBSD Foundation, Inc.
7 * This code is derived from software contributed to The NetBSD Foundation
8 * by Simon Burge and Luke Mewburn.
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 * 3. All advertising materials mentioning features or use of this software
19 * must display the following acknowledgement:
20 * This product includes software developed by the NetBSD
21 * Foundation, Inc. and its contributors.
22 * 4. Neither the name of The NetBSD Foundation nor the names of its
23 * contributors may be used to endorse or promote products derived
24 * from this software without specific prior written permission.
26 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
27 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
28 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
29 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
30 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
31 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
32 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
33 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
34 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
35 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
36 * POSSIBILITY OF SUCH DAMAGE.
39 #include <sys/cdefs.h>
41 __RCSID("$NetBSD: conf.c,v 1.52 2004-08-09 12:56:47 lukem Exp $");
44 #include <sys/types.h>
45 #include <sys/param.h>
46 #include <sys/socket.h>
58 #include <stringlist.h>
65 #include <krb5/krb5.h>
69 #include "pathnames.h"
71 static char *strend(const char *, char *);
72 static int filetypematch(char *, int);
76 #define DEFAULT_LIMIT -1 /* unlimited connections */
77 #define DEFAULT_MAXFILESIZE -1 /* unlimited file size */
78 #define DEFAULT_MAXTIMEOUT 7200 /* 2 hours */
79 #define DEFAULT_TIMEOUT 900 /* 15 minutes */
80 #define DEFAULT_UMASK 027 /* 15 minutes */
83 * Initialise curclass to an `empty' state
88 struct ftpconv *conv, *cnext;
90 for (conv = curclass.conversions; conv != NULL; conv = cnext) {
91 REASSIGN(conv->suffix, NULL);
92 REASSIGN(conv->types, NULL);
93 REASSIGN(conv->disable, NULL);
94 REASSIGN(conv->command, NULL);
99 memset((char *)&curclass.advertise, 0, sizeof(curclass.advertise));
100 curclass.advertise.su_len = 0; /* `not used' */
101 REASSIGN(curclass.chroot, NULL);
102 REASSIGN(curclass.classname, NULL);
103 curclass.conversions = NULL;
104 REASSIGN(curclass.display, NULL);
105 REASSIGN(curclass.homedir, NULL);
106 curclass.limit = DEFAULT_LIMIT;
107 REASSIGN(curclass.limitfile, NULL);
108 curclass.maxfilesize = DEFAULT_MAXFILESIZE;
109 curclass.maxrateget = 0;
110 curclass.maxrateput = 0;
111 curclass.maxtimeout = DEFAULT_MAXTIMEOUT;
112 REASSIGN(curclass.motd, xstrdup(_PATH_FTPLOGINMESG));
113 REASSIGN(curclass.notify, NULL);
114 curclass.portmin = 0;
115 curclass.portmax = 0;
116 curclass.rateget = 0;
117 curclass.rateput = 0;
118 curclass.timeout = DEFAULT_TIMEOUT;
119 /* curclass.type is set elsewhere */
120 curclass.umask = DEFAULT_UMASK;
121 curclass.mmapsize = 0;
122 curclass.readsize = 0;
123 curclass.writesize = 0;
124 curclass.sendbufsize = 0;
125 curclass.sendlowat = 0;
127 CURCLASS_FLAGS_SET(checkportcmd);
128 CURCLASS_FLAGS_CLR(denyquick);
129 CURCLASS_FLAGS_SET(modify);
130 CURCLASS_FLAGS_SET(passive);
131 CURCLASS_FLAGS_CLR(private);
132 CURCLASS_FLAGS_CLR(sanenames);
133 CURCLASS_FLAGS_SET(upload);
137 * Parse the configuration file, looking for the named class, and
138 * define curclass to contain the appropriate settings.
141 parse_conf(const char *findclass)
148 char *endp, errbuf[100];
149 char *class, *word, *arg, *template;
152 struct ftpconv *conv, *cnext;
155 REASSIGN(curclass.classname, xstrdup(findclass));
156 /* set more guest defaults */
157 if (strcasecmp(findclass, "guest") == 0) {
158 CURCLASS_FLAGS_CLR(modify);
159 curclass.umask = 0707;
162 infile = conffilename(_PATH_FTPDCONF);
163 if ((f = fopen(infile, "r")) == NULL)
169 (buf = fparseln(f, &len, &line, NULL, FPARSELN_UNESCCOMM |
170 FPARSELN_UNESCCONT | FPARSELN_UNESCESC)) != NULL;
176 if (p[len - 1] == '\n')
184 if (EMPTYSTR(word) || EMPTYSTR(class))
186 if (strcasecmp(class, "none") == 0)
188 if (! (strcasecmp(class, findclass) == 0 ||
189 (template != NULL && strcasecmp(class, template) == 0) ||
191 strcasecmp(class, "all") == 0) )
194 #define CONF_FLAG(Field) \
197 (!EMPTYSTR(arg) && strcasecmp(arg, "off") == 0)) \
198 CURCLASS_FLAGS_CLR(Field); \
200 CURCLASS_FLAGS_SET(Field); \
203 #define CONF_STRING(Field) \
205 if (none || EMPTYSTR(arg)) \
208 arg = xstrdup(arg); \
209 REASSIGN(curclass.Field, arg); \
212 #define CONF_LL(Field,Arg,Min,Max) \
214 if (none || EMPTYSTR(Arg)) \
216 llval = strsuftollx(#Field, Arg, Min, Max, \
217 errbuf, sizeof(errbuf)); \
219 syslog(LOG_WARNING, "%s line %d: %s", \
220 infile, (int)line, errbuf); \
223 curclass.Field = llval; \
229 } else if ((strcasecmp(word, "advertise") == 0)
230 || (strcasecmp(word, "advertize") == 0)) {
231 struct addrinfo hints, *res;
234 memset((char *)&curclass.advertise, 0,
235 sizeof(curclass.advertise));
236 curclass.advertise.su_len = 0;
237 if (none || EMPTYSTR(arg))
240 memset(&hints, 0, sizeof(hints));
242 * only get addresses of the family
243 * that we're listening on
245 hints.ai_family = ctrl_addr.su_family;
246 hints.ai_socktype = SOCK_STREAM;
247 error = getaddrinfo(arg, "0", &hints, &res);
249 syslog(LOG_WARNING, "%s line %d: %s",
250 infile, (int)line, gai_strerror(error));
258 "%s line %d: multiple addresses returned for `%s'; please be more specific",
259 infile, (int)line, arg);
260 goto advertiseparsefail;
262 if (sizeof(curclass.advertise) < res->ai_addrlen || (
264 res->ai_family != AF_INET6 &&
266 res->ai_family != AF_INET)) {
268 "%s line %d: unsupported protocol %d for `%s'",
269 infile, (int)line, res->ai_family, arg);
270 goto advertiseparsefail;
272 memcpy(&curclass.advertise, res->ai_addr,
274 curclass.advertise.su_len = res->ai_addrlen;
277 } else if (strcasecmp(word, "checkportcmd") == 0) {
278 CONF_FLAG(checkportcmd);
280 } else if (strcasecmp(word, "chroot") == 0) {
283 } else if (strcasecmp(word, "classtype") == 0) {
284 if (!none && !EMPTYSTR(arg)) {
285 if (strcasecmp(arg, "GUEST") == 0)
286 curclass.type = CLASS_GUEST;
287 else if (strcasecmp(arg, "CHROOT") == 0)
288 curclass.type = CLASS_CHROOT;
289 else if (strcasecmp(arg, "REAL") == 0)
290 curclass.type = CLASS_REAL;
293 "%s line %d: unknown class type `%s'",
294 infile, (int)line, arg);
299 } else if (strcasecmp(word, "conversion") == 0) {
300 char *suffix, *types, *disable, *convcmd;
304 "%s line %d: %s requires a suffix",
305 infile, (int)line, word);
306 continue; /* need a suffix */
309 NEXTWORD(p, disable);
312 convcmd += strspn(convcmd, " \t");
313 suffix = xstrdup(arg);
314 if (none || EMPTYSTR(types) ||
315 EMPTYSTR(disable) || EMPTYSTR(convcmd)) {
320 types = xstrdup(types);
321 disable = xstrdup(disable);
322 convcmd = xstrdup(convcmd);
324 for (conv = curclass.conversions; conv != NULL;
326 if (strcmp(conv->suffix, suffix) == 0)
330 conv = (struct ftpconv *)
331 calloc(1, sizeof(struct ftpconv));
333 syslog(LOG_WARNING, "can't malloc");
337 for (cnext = curclass.conversions;
338 cnext != NULL; cnext = cnext->next)
339 if (cnext->next == NULL)
344 curclass.conversions = conv;
346 REASSIGN(conv->suffix, suffix);
347 REASSIGN(conv->types, types);
348 REASSIGN(conv->disable, disable);
349 REASSIGN(conv->command, convcmd);
351 } else if (strcasecmp(word, "denyquick") == 0) {
352 CONF_FLAG(denyquick);
354 } else if (strcasecmp(word, "display") == 0) {
355 CONF_STRING(display);
357 } else if (strcasecmp(word, "homedir") == 0) {
358 CONF_STRING(homedir);
360 } else if (strcasecmp(word, "limit") == 0) {
361 curclass.limit = DEFAULT_LIMIT;
362 REASSIGN(curclass.limitfile, NULL);
363 CONF_LL(limit, arg, -1, LLTMAX);
364 REASSIGN(curclass.limitfile,
365 EMPTYSTR(p) ? NULL : xstrdup(p));
367 } else if (strcasecmp(word, "maxfilesize") == 0) {
368 curclass.maxfilesize = DEFAULT_MAXFILESIZE;
369 CONF_LL(maxfilesize, arg, -1, LLTMAX);
371 } else if (strcasecmp(word, "maxtimeout") == 0) {
372 curclass.maxtimeout = DEFAULT_MAXTIMEOUT;
373 CONF_LL(maxtimeout, arg,
374 MIN(30, curclass.timeout), LLTMAX);
376 } else if (strcasecmp(word, "mmapsize") == 0) {
377 curclass.mmapsize = 0;
378 CONF_LL(mmapsize, arg, 0, LLTMAX);
380 } else if (strcasecmp(word, "readsize") == 0) {
381 curclass.readsize = 0;
382 CONF_LL(readsize, arg, 0, LLTMAX);
384 } else if (strcasecmp(word, "writesize") == 0) {
385 curclass.writesize = 0;
386 CONF_LL(writesize, arg, 0, LLTMAX);
388 } else if (strcasecmp(word, "sendbufsize") == 0) {
389 curclass.sendbufsize = 0;
390 CONF_LL(sendbufsize, arg, 0, LLTMAX);
392 } else if (strcasecmp(word, "sendlowat") == 0) {
393 curclass.sendlowat = 0;
394 CONF_LL(sendlowat, arg, 0, LLTMAX);
396 } else if (strcasecmp(word, "modify") == 0) {
399 } else if (strcasecmp(word, "motd") == 0) {
402 } else if (strcasecmp(word, "notify") == 0) {
405 } else if (strcasecmp(word, "passive") == 0) {
408 } else if (strcasecmp(word, "portrange") == 0) {
409 long minport, maxport;
411 curclass.portmin = 0;
412 curclass.portmax = 0;
413 if (none || EMPTYSTR(arg))
417 "%s line %d: missing maxport argument",
421 minport = strsuftollx("minport", arg, IPPORT_RESERVED,
422 IPPORT_ANONMAX, errbuf, sizeof(errbuf));
424 syslog(LOG_WARNING, "%s line %d: %s",
425 infile, (int)line, errbuf);
428 maxport = strsuftollx("maxport", p, IPPORT_RESERVED,
429 IPPORT_ANONMAX, errbuf, sizeof(errbuf));
431 syslog(LOG_WARNING, "%s line %d: %s",
432 infile, (int)line, errbuf);
435 if (minport >= maxport) {
437 "%s line %d: minport %ld >= maxport %ld",
438 infile, (int)line, minport, maxport);
441 curclass.portmin = (int)minport;
442 curclass.portmax = (int)maxport;
444 } else if (strcasecmp(word, "private") == 0) {
447 } else if (strcasecmp(word, "rateget") == 0) {
448 curclass.maxrateget = curclass.rateget = 0;
449 CONF_LL(rateget, arg, 0, LLTMAX);
450 curclass.maxrateget = curclass.rateget;
452 } else if (strcasecmp(word, "rateput") == 0) {
453 curclass.maxrateput = curclass.rateput = 0;
454 CONF_LL(rateput, arg, 0, LLTMAX);
455 curclass.maxrateput = curclass.rateput;
457 } else if (strcasecmp(word, "sanenames") == 0) {
458 CONF_FLAG(sanenames);
460 } else if (strcasecmp(word, "timeout") == 0) {
461 curclass.timeout = DEFAULT_TIMEOUT;
462 CONF_LL(timeout, arg, 30, curclass.maxtimeout);
464 } else if (strcasecmp(word, "template") == 0) {
467 REASSIGN(template, EMPTYSTR(arg) ? NULL : xstrdup(arg));
469 } else if (strcasecmp(word, "umask") == 0) {
472 curclass.umask = DEFAULT_UMASK;
473 if (none || EMPTYSTR(arg))
477 fumask = strtoul(arg, &endp, 8);
478 if (errno || *arg == '\0' || *endp != '\0' ||
481 "%s line %d: invalid umask %s",
482 infile, (int)line, arg);
485 curclass.umask = (mode_t)fumask;
487 } else if (strcasecmp(word, "upload") == 0) {
489 if (! CURCLASS_FLAGS_ISSET(upload))
490 CURCLASS_FLAGS_CLR(modify);
494 "%s line %d: unknown directive '%s'",
495 infile, (int)line, word);
501 REASSIGN(template, NULL);
506 * Show file listed in curclass.display first time in, and list all the
507 * files named in curclass.notify in the current directory.
508 * Send back responses with the prefix `code' + "-".
509 * If code == -1, flush the internal cache of directory names and return.
512 show_chdir_messages(int code)
514 static StringList *slist = NULL;
521 char curwd[MAXPATHLEN];
534 /* Setup list for directory cache */
538 syslog(LOG_WARNING, "can't allocate memory for stringlist");
542 /* Check if this directory has already been visited */
543 if (getcwd(curwd, sizeof(curwd) - 1) == NULL) {
544 syslog(LOG_WARNING, "can't getcwd: %s", strerror(errno));
547 if (sl_find(slist, curwd) != NULL)
551 if (sl_add(slist, cp) == -1)
552 syslog(LOG_WARNING, "can't add `%s' to stringlist", cp);
554 /* First check for a display file */
555 (void)display_file(curclass.display, code);
557 /* Now see if there are any notify files */
558 if (EMPTYSTR(curclass.notify))
561 memset(&gl, 0, sizeof(gl));
562 if (glob(curclass.notify, GLOB_BRACE|GLOB_LIMIT, NULL, &gl) != 0
563 || gl.gl_matchc == 0) {
568 for (rlist = gl.gl_pathv; *rlist != NULL; rlist++) {
569 if (stat(*rlist, &st) != 0)
571 if (!S_ISREG(st.st_mode))
575 reply(-code, "%s", "");
578 reply(-code, "Please read the file %s", *rlist);
580 age = 365 * t->tm_year + t->tm_yday;
581 t = localtime(&then);
582 age -= 365 * t->tm_year + t->tm_yday;
583 reply(-code, " it was last modified on %.24s - %d day%s ago",
584 ctime(&then), age, PLURAL(age));
590 display_file(const char *file, int code)
594 char curwd[MAXPATHLEN];
605 if ((f = fopen(file, "r")) == NULL)
607 reply(-code, "%s", "");
610 (buf = fparseln(f, &len, NULL, "\0\0\0", 0)) != NULL; free(buf)) {
612 if (buf[len - 1] == '\n')
614 cprintf(stdout, " ");
616 for (p = buf; *p; p++) {
622 cprintf(stdout, "%s",
624 curclass.classname : "<unknown>");
628 if (getcwd(curwd, sizeof(curwd)-1)
635 cprintf(stdout, "%s", curwd);
639 if (! EMPTYSTR(emailaddr))
640 cprintf(stdout, "%s",
645 cprintf(stdout, "%s", hostname);
649 if (curclass.limit == -1) {
650 cprintf(stdout, "unlimited");
654 (LLT)curclass.limit);
655 lastnum = curclass.limit;
660 cprintf(stdout, "%d", connections);
661 lastnum = connections;
665 cprintf(stdout, "%s", remotehost);
670 cprintf(stdout, "s");
675 cprintf(stdout, "S");
680 cprintf(stdout, "%.24s", ctime(&now));
684 cprintf(stdout, "%s",
685 pw ? pw->pw_name : "<unknown>");
696 cprintf(stdout, "\r\n");
699 (void)fflush(stdout);
705 * Parse src, expanding '%' escapes, into dst (which must be at least
709 format_path(char *dst, const char *src)
718 for (p = src; *p && len < MAXPATHLEN; p++) {
724 len += strlcpy(dst + len, curclass.classname,
729 len += strlcpy(dst + len, pw->pw_dir,
734 len += strlcpy(dst + len, pw->pw_name,
746 if (len < MAXPATHLEN)
748 dst[MAXPATHLEN - 1] = '\0';
752 * Find s2 at the end of s1. If found, return a string up to (but
753 * not including) s2, otherwise returns NULL.
756 strend(const char *s1, char *s2)
758 static char buf[MAXPATHLEN];
766 if (l2 >= l1 || l1 >= sizeof(buf))
769 strlcpy(buf, s1, sizeof(buf));
770 start = buf + (l1 - l2);
772 if (strcmp(start, s2) == 0) {
780 filetypematch(char *types, int mode)
782 for ( ; types[0] != '\0'; types++)
797 * Look for a conversion. If we succeed, return a pointer to the
798 * command to execute for the conversion.
800 * The command is stored in a static array so there's no memory
801 * leak problems, and not too much to change in ftpd.c. This
802 * routine doesn't need to be re-entrant unless we start using a
803 * multi-threaded ftpd, and that's not likely for a while...
806 do_conversion(const char *fname)
812 char *cmd, *p, *lp, **argv;
818 for (cp = curclass.conversions; cp != NULL; cp = cp->next) {
819 if (cp->suffix == NULL) {
821 "cp->suffix==NULL in conv list; SHOULDN'T HAPPEN!");
824 if ((base = strend(fname, cp->suffix)) == NULL)
826 if (cp->types == NULL || cp->disable == NULL ||
830 if (strcmp(cp->disable, ".") != 0 &&
831 stat(cp->disable, &st) == 0)
833 /* Does the base exist? */
834 if (stat(base, &st) < 0)
836 /* Is the file type ok */
837 if (!filetypematch(cp->types, st.st_mode))
839 break; /* "We have a winner!" */
842 /* If we got through the list, no conversion */
844 goto cleanup_do_conv;
846 /* Split up command into an argv */
847 if ((sl = sl_init()) == NULL)
848 goto cleanup_do_conv;
849 cmd = xstrdup(cp->command);
853 if (strcmp(lp, "%s") == 0)
855 if (sl_add(sl, xstrdup(lp)) == -1)
856 goto cleanup_do_conv;
859 if (sl_add(sl, NULL) == -1)
860 goto cleanup_do_conv;
875 * Count the number of current connections, reading from
876 * /var/run/ftpd.pids-<class>
877 * Does a kill -0 on each pid in that file, and only counts
878 * processes that exist (or frees the slot if it doesn't).
879 * Adds getpid() to the first free slot. Truncates the file
891 (void)strlcpy(fn, _PATH_CLASSPIDS, sizeof(fn));
892 (void)strlcat(fn, curclass.classname, sizeof(fn));
896 if ((fd = open(fn, O_RDWR | O_CREAT, 0600)) == -1)
898 if (lockf(fd, F_TLOCK, 0) == -1)
900 if (fstat(fd, &sb) == -1)
902 if ((pids = malloc(sb.st_size + sizeof(pid_t))) == NULL)
904 count = read(fd, pids, sb.st_size);
905 if (count < 0 || count != sb.st_size)
907 count /= sizeof(pid_t);
910 for (i = 0; i < count; i++) {
913 if (kill(pids[i], 0) == -1 && errno != EPERM) {
929 count = (last + 1) * sizeof(pid_t);
930 if (lseek(fd, 0, SEEK_SET) == -1)
932 if (write(fd, pids, count) == -1)
934 (void)ftruncate(fd, count);
937 if (lseek(fd, 0, SEEK_SET) != -1)
938 (void)lockf(fd, F_ULOCK, 0);
940 REASSIGN(pids, NULL);