2 * SPDX-License-Identifier: BSD-3-Clause
4 * Copyright (c) 1983, 1993
5 * The Regents of the University of California. All rights reserved.
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. Neither the name of the University nor the names of its contributors
16 * may be used to endorse or promote products derived from this software
17 * without specific prior written permission.
19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 #include <sys/types.h>
33 #include <sys/param.h>
34 #include <sys/socket.h>
35 #include <netinet/in.h>
36 #include <netinet/tcp.h>
37 #include <arpa/inet.h>
47 #include "pathnames.h"
49 #include <blacklist.h>
52 void logerr(const char *, ...) __printflike(1, 2) __dead2;
55 main(int argc, char *argv[])
60 struct sockaddr_storage ss;
62 int p[2], debug, kflag, logging, pflag, secure;
64 char **ap, *av[ENTRIES + 1], **comp, line[1024], *prog;
65 char rhost[MAXHOSTNAMELEN];
68 debug = logging = kflag = pflag = secure = 0;
69 openlog("fingerd", LOG_PID | LOG_CONS, LOG_DAEMON);
71 while ((ch = getopt(argc, argv, "dklp:s")) != -1)
91 logerr("illegal option -- %c", optopt);
95 * Enable server-side Transaction TCP.
99 if (setsockopt(STDOUT_FILENO, IPPROTO_TCP, TCP_NOPUSH, &one,
101 logerr("setsockopt(TCP_NOPUSH) failed: %m");
105 if (!fgets(line, sizeof(line), stdin))
108 if (!debug && (logging || pflag)) {
110 if (getpeername(0, (struct sockaddr *)&ss, &sval) < 0)
111 logerr("getpeername: %s", strerror(errno));
112 realhostname_sa(rhost, sizeof rhost - 1,
113 (struct sockaddr *)&ss, sval);
114 rhost[sizeof(rhost) - 1] = '\0';
116 setenv("FINGERD_REMOTE_HOST", rhost, 1);
123 end = memchr(line, 0, sizeof(line));
125 if ((t = malloc(sizeof(line) + 1)) == NULL)
126 logerr("malloc: %s", strerror(errno));
127 memcpy(t, line, sizeof(line));
130 if ((t = strdup(line)) == NULL)
131 logerr("strdup: %s", strerror(errno));
133 for (end = t; *end; end++)
134 if (*end == '\n' || *end == '\r')
136 syslog(LOG_NOTICE, "query from %s: `%s'", rhost, t);
143 for (lp = line, ap = &av[4];;) {
144 *ap = strtok(lp, " \t\r\n");
146 if (secure && ap == &av[4]) {
148 blacklist(1, STDIN_FILENO, "nousername");
150 puts("must provide username\r\n");
155 if (secure && strchr(*ap, '@')) {
157 blacklist(1, STDIN_FILENO, "noforwarding");
159 puts("forwarding service denied\r\n");
163 /* RFC742: "/[Ww]" == "-l" */
164 if ((*ap)[0] == '/' && ((*ap)[1] == 'W' || (*ap)[1] == 'w')) {
167 else if (++ap == av + ENTRIES) {
174 if ((lp = strrchr(prog, '/')) != NULL)
179 logerr("pipe: %s", strerror(errno));
182 fprintf(stderr, "%s", prog);
183 for (ap = comp; *ap != NULL; ++ap)
184 fprintf(stderr, " %s", *ap);
185 fprintf(stderr, "\n");
191 if (p[1] != STDOUT_FILENO) {
192 (void)dup2(p[1], STDOUT_FILENO);
195 dup2(STDOUT_FILENO, STDERR_FILENO);
198 blacklist(0, STDIN_FILENO, "success");
201 write(STDERR_FILENO, prog, strlen(prog));
202 #define MSG ": cannot execute\n"
203 write(STDERR_FILENO, MSG, strlen(MSG));
207 logerr("fork: %s", strerror(errno));
210 if (!(fp = fdopen(p[0], "r")))
211 logerr("fdopen: %s", strerror(errno));
212 while ((ch = getc(fp)) != EOF) {
223 logerr(const char *fmt, ...)
227 (void)vsyslog(LOG_ERR, fmt, ap);