2005-08-15 11:54:31 +08:00
|
|
|
/* $Id: utils.c,v 1.40 2005-08-15 03:54:31 rjkaes Exp $
|
2000-02-17 01:32:49 +08:00
|
|
|
*
|
|
|
|
* Misc. routines which are used by the various functions to handle strings
|
|
|
|
* and memory allocation and pretty much anything else we can think of. Also,
|
2000-09-12 08:01:29 +08:00
|
|
|
* the load cutoff routine is in here. Could not think of a better place for
|
|
|
|
* it, so it's in here.
|
2000-02-17 01:32:49 +08:00
|
|
|
*
|
2001-12-20 12:48:52 +08:00
|
|
|
* Copyright (C) 1998 Steven Young
|
2005-07-13 01:39:44 +08:00
|
|
|
* Copyright (C) 1999-2003 Robert James Kaes (rjkaes@users.sourceforge.net)
|
2000-02-17 01:32:49 +08:00
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2, or (at your option) any
|
|
|
|
* later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
* General Public License for more details.
|
|
|
|
*/
|
|
|
|
|
2000-09-12 08:01:29 +08:00
|
|
|
#include "tinyproxy.h"
|
2000-02-17 01:32:49 +08:00
|
|
|
|
2001-10-26 00:58:50 +08:00
|
|
|
#include "conns.h"
|
2002-05-24 02:28:12 +08:00
|
|
|
#include "heap.h"
|
2008-03-09 09:35:50 +08:00
|
|
|
#include "http-message.h"
|
2000-09-12 08:01:29 +08:00
|
|
|
#include "utils.h"
|
2000-02-17 01:32:49 +08:00
|
|
|
|
|
|
|
/*
|
2001-09-16 05:29:59 +08:00
|
|
|
* Build the data for a complete HTTP & HTML message for the client.
|
2000-02-17 01:32:49 +08:00
|
|
|
*/
|
2001-11-22 08:31:10 +08:00
|
|
|
int
|
|
|
|
send_http_message(struct conn_s *connptr, int http_code,
|
2005-08-15 11:54:31 +08:00
|
|
|
const char *error_title, const char *message)
|
2000-02-17 01:32:49 +08:00
|
|
|
{
|
2005-08-15 11:54:31 +08:00
|
|
|
static char *headers[] = {
|
|
|
|
"Server: " PACKAGE "/" VERSION,
|
|
|
|
"Content-type: text/html",
|
|
|
|
"Connection: close"
|
|
|
|
};
|
2001-08-27 11:45:34 +08:00
|
|
|
|
2005-08-15 11:54:31 +08:00
|
|
|
http_message_t msg;
|
2001-08-27 11:45:34 +08:00
|
|
|
|
2005-08-15 11:54:31 +08:00
|
|
|
msg = http_message_create(http_code, error_title);
|
|
|
|
if (msg == NULL)
|
|
|
|
return -1;
|
2001-08-27 11:45:34 +08:00
|
|
|
|
2005-08-15 11:54:31 +08:00
|
|
|
http_message_add_headers(msg, headers, 3);
|
|
|
|
http_message_set_body(msg, message, strlen(message));
|
|
|
|
http_message_send(msg, connptr->client_fd);
|
|
|
|
http_message_destroy(msg);
|
2003-03-14 14:15:27 +08:00
|
|
|
|
2005-08-15 11:54:31 +08:00
|
|
|
return 0;
|
2000-02-17 01:32:49 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2000-09-12 08:01:29 +08:00
|
|
|
* Safely creates filename and returns the low-level file descriptor.
|
2000-02-17 01:32:49 +08:00
|
|
|
*/
|
2001-11-22 08:31:10 +08:00
|
|
|
int
|
2002-12-05 01:06:14 +08:00
|
|
|
create_file_safely(const char *filename, unsigned int truncate_file)
|
2000-02-17 01:32:49 +08:00
|
|
|
{
|
2005-08-15 11:54:31 +08:00
|
|
|
struct stat lstatinfo;
|
|
|
|
int fildes;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* lstat() the file. If it doesn't exist, create it with O_EXCL.
|
|
|
|
* If it does exist, open it for writing and perform the fstat()
|
|
|
|
* check.
|
|
|
|
*/
|
|
|
|
if (lstat(filename, &lstatinfo) < 0) {
|
|
|
|
/*
|
|
|
|
* If lstat() failed for any reason other than "file not
|
|
|
|
* existing", exit.
|
|
|
|
*/
|
|
|
|
if (errno != ENOENT) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: Error checking file %s: %s\n",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
return -EACCES;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* The file doesn't exist, so create it with O_EXCL to make
|
|
|
|
* sure an attacker can't slip in a file between the lstat()
|
|
|
|
* and open()
|
|
|
|
*/
|
|
|
|
if ((fildes =
|
|
|
|
open(filename, O_RDWR | O_CREAT | O_EXCL, 0600)) < 0) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: Could not create file %s: %s\n",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
return fildes;
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
struct stat fstatinfo;
|
|
|
|
int flags;
|
|
|
|
|
|
|
|
flags = O_RDWR;
|
|
|
|
if (!truncate_file)
|
|
|
|
flags |= O_APPEND;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Open an existing file.
|
|
|
|
*/
|
|
|
|
if ((fildes = open(filename, flags)) < 0) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: Could not open file %s: %s\n",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
return fildes;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* fstat() the opened file and check that the file mode bits,
|
|
|
|
* inode, and device match.
|
|
|
|
*/
|
|
|
|
if (fstat(fildes, &fstatinfo) < 0
|
|
|
|
|| lstatinfo.st_mode != fstatinfo.st_mode
|
|
|
|
|| lstatinfo.st_ino != fstatinfo.st_ino
|
|
|
|
|| lstatinfo.st_dev != fstatinfo.st_dev) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: The file %s has been changed before it could be opened\n",
|
|
|
|
PACKAGE, filename);
|
|
|
|
close(fildes);
|
|
|
|
return -EIO;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* If the above check was passed, we know that the lstat()
|
|
|
|
* and fstat() were done on the same file. Now we check that
|
|
|
|
* there's only one link, and that it's a normal file (this
|
|
|
|
* isn't strictly necessary because the fstat() vs lstat()
|
|
|
|
* st_mode check would also find this)
|
|
|
|
*/
|
|
|
|
if (fstatinfo.st_nlink > 1 || !S_ISREG(lstatinfo.st_mode)) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: The file %s has too many links, or is not a regular file: %s\n",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
close(fildes);
|
|
|
|
return -EMLINK;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Just return the file descriptor if we _don't_ want the file
|
|
|
|
* truncated.
|
|
|
|
*/
|
|
|
|
if (!truncate_file)
|
|
|
|
return fildes;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* On systems which don't support ftruncate() the best we can
|
|
|
|
* do is to close the file and reopen it in create mode, which
|
|
|
|
* unfortunately leads to a race condition, however "systems
|
|
|
|
* which don't support ftruncate()" is pretty much SCO only,
|
|
|
|
* and if you're using that you deserve what you get.
|
|
|
|
* ("Little sympathy has been extended")
|
|
|
|
*/
|
2001-05-27 10:38:46 +08:00
|
|
|
#ifdef HAVE_FTRUNCATE
|
2005-08-15 11:54:31 +08:00
|
|
|
ftruncate(fildes, 0);
|
2001-05-27 10:38:46 +08:00
|
|
|
#else
|
2005-08-15 11:54:31 +08:00
|
|
|
close(fildes);
|
|
|
|
if ((fildes =
|
|
|
|
open(filename, O_RDWR | O_CREAT | O_TRUNC, 0600)) < 0) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: Could not open file %s: %s.",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
return fildes;
|
|
|
|
}
|
|
|
|
#endif /* HAVE_FTRUNCATE */
|
|
|
|
}
|
|
|
|
|
|
|
|
return fildes;
|
2000-02-17 01:32:49 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2000-09-12 08:01:29 +08:00
|
|
|
* Write the PID of the program to the specified file.
|
2000-02-17 01:32:49 +08:00
|
|
|
*/
|
2002-11-22 05:51:34 +08:00
|
|
|
int
|
2001-11-22 08:31:10 +08:00
|
|
|
pidfile_create(const char *filename)
|
2000-02-17 01:32:49 +08:00
|
|
|
{
|
2005-08-15 11:54:31 +08:00
|
|
|
int fildes;
|
|
|
|
FILE *fd;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Create a new file
|
|
|
|
*/
|
|
|
|
if ((fildes = create_file_safely(filename, TRUE)) < 0)
|
|
|
|
return fildes;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Open a stdio file over the low-level one.
|
|
|
|
*/
|
|
|
|
if ((fd = fdopen(fildes, "w")) == NULL) {
|
|
|
|
fprintf(stderr,
|
|
|
|
"%s: Could not write PID file %s: %s.",
|
|
|
|
PACKAGE, filename, strerror(errno));
|
|
|
|
close(fildes);
|
|
|
|
unlink(filename);
|
|
|
|
return -EIO;
|
|
|
|
}
|
|
|
|
|
|
|
|
fprintf(fd, "%ld\n", (long)getpid());
|
|
|
|
fclose(fd);
|
|
|
|
return 0;
|
2000-02-17 01:32:49 +08:00
|
|
|
}
|