/* $Id: utils.c,v 1.33 2002-06-15 17:28:19 rjkaes Exp $
*
* Misc. routines which are used by the various functions to handle strings
* and memory allocation and pretty much anything else we can think of. Also,
* the load cutoff routine is in here. Could not think of a better place for
* it, so it's in here.
*
* Copyright (C) 1998 Steven Young
* Copyright (C) 1999,2001 Robert James Kaes (rjkaes@flarenet.com)
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2, or (at your option) any
* later version.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* General Public License for more details.
*/
#include "tinyproxy.h"
#include "buffer.h"
#include "conns.h"
#include "filter.h"
#include "heap.h"
#include "log.h"
#include "network.h"
#include "sock.h"
#include "utils.h"
#define HEADER_SIZE (1024 * 8)
/*
* Build the data for a complete HTTP & HTML message for the client.
*/
int
send_http_message(struct conn_s *connptr, int http_code,
const char *error_title, const char *message)
{
static char *headers = \
"HTTP/1.0 %d %s\r\n" \
"Server: %s/%s\r\n" \
"Date: %s\r\n" \
"Content-Type: text/html\r\n" \
"Content-Length: %d\r\n" \
"Connection: close\r\n" \
"\r\n";
char timebuf[30];
time_t global_time;
size_t message_len = strlen(message);
global_time = time(NULL);
strftime(timebuf, sizeof(timebuf), "%a, %d %b %Y %H:%M:%S GMT",
gmtime(&global_time));
if (write_message(connptr->client_fd,
headers,
http_code, error_title, PACKAGE, VERSION,
timebuf, message_len) < 0)
return -1;
return safe_write(connptr->client_fd, message, message_len);
}
/*
* Display an error to the client.
*/
int
send_http_error_message(struct conn_s *connptr)
{
static char *message = \
"
%s\r\n" \
"\r\n" \
"Cache Error!
\r\n" \
"An error of type %d occurred: %s\r\n" \
"
\r\n" \
"Generated by %s (%s)\r\n" \
"\r\n\r\n";
char *message_buffer;
char *tmpbuf;
size_t size = (1024 * 8); /* start with 8 KB */
ssize_t n;
int ret;
message_buffer = safemalloc(size);
if (!message_buffer)
return -1;
/*
* Build a new line. Keep increasing the size until the line fits.
* See the write_message() function in sock.c for more information.
*/
while (1) {
n = snprintf(message_buffer, size, message,
connptr->error_string, connptr->error_number,
connptr->error_string, PACKAGE, VERSION);
if (n > -1 && n < size)
break;
if (n > - 1)
size = n + 1;
else
size *= 2;
if ((tmpbuf = saferealloc(message_buffer, size)) == NULL) {
safefree(message_buffer);
return -1;
} else
message_buffer = tmpbuf;
}
ret = send_http_message(connptr, connptr->error_number,
connptr->error_string, message_buffer);
safefree(message_buffer);
return ret;
}
/*
* Add the error information to the conn structure.
*/
int
indicate_http_error(struct conn_s* connptr, int number, const char* string)
{
connptr->error_string = safestrdup(string);
if (!connptr->error_string)
return -1;
connptr->error_number = number;
return 0;
}
/*
* Safely creates filename and returns the low-level file descriptor.
*/
int
create_file_safely(const char *filename, bool_t truncate_file)
{
struct stat lstatinfo;
int fildes;
/*
* lstat() the file. If it doesn't exist, create it with O_EXCL.
* If it does exist, open it for writing and perform the fstat()
* check.
*/
if (lstat(filename, &lstatinfo) < 0) {
/*
* If lstat() failed for any reason other than "file not
* existing", exit.
*/
if (errno != ENOENT) {
log_message(LOG_ERR,
"create_file_safely: Error checking file %s: %s.",
filename, strerror(errno));
return -1;
}
/*
* The file doesn't exist, so create it with O_EXCL to make
* sure an attacker can't slip in a file between the lstat()
* and open()
*/
if ((fildes =
open(filename, O_RDWR | O_CREAT | O_EXCL, 0600)) < 0) {
log_message(LOG_ERR,
"create_file_safely: Could not create file %s: %s.",
filename, strerror(errno));
return -1;
}
} else {
struct stat fstatinfo;
int flags;
flags = O_RDWR;
if (!truncate_file)
flags |= O_APPEND;
/*
* Open an existing file.
*/
if ((fildes = open(filename, flags)) < 0) {
log_message(LOG_ERR,
"create_file_safely: Could not open file %s: %s.",
filename, strerror(errno));
return -1;
}
/*
* fstat() the opened file and check that the file mode bits,
* inode, and device match.
*/
if (fstat(fildes, &fstatinfo) < 0
|| lstatinfo.st_mode != fstatinfo.st_mode
|| lstatinfo.st_ino != fstatinfo.st_ino
|| lstatinfo.st_dev != fstatinfo.st_dev) {
log_message(LOG_ERR,
"create_file_safely: The file %s has been changed before it could be opened.",
filename);
close(fildes);
return -1;
}
/*
* If the above check was passed, we know that the lstat()
* and fstat() were done on the same file. Now we check that
* there's only one link, and that it's a normal file (this
* isn't strictly necessary because the fstat() vs lstat()
* st_mode check would also find this)
*/
if (fstatinfo.st_nlink > 1 || !S_ISREG(lstatinfo.st_mode)) {
log_message(LOG_ERR,
"create_file_safely: The file %s has too many links, or is not a regular file: %s.",
filename, strerror(errno));
close(fildes);
return -1;
}
/*
* Just return the file descriptor if we _don't_ want the file
* truncated.
*/
if (!truncate_file)
return fildes;
/*
* On systems which don't support ftruncate() the best we can
* do is to close the file and reopen it in create mode, which
* unfortunately leads to a race condition, however "systems
* which don't support ftruncate()" is pretty much SCO only,
* and if you're using that you deserve what you get.
* ("Little sympathy has been extended")
*/
#ifdef HAVE_FTRUNCATE
ftruncate(fildes, 0);
#else
close(fildes);
if ((fildes =
open(filename, O_RDWR | O_CREAT | O_TRUNC, 0600)) < 0) {
log_message(LOG_ERR,
"create_file_safely: Could not open file %s: %s.",
filename, strerror(errno));
return -1;
}
#endif /* HAVE_FTRUNCATE */
}
return fildes;
}
/*
* Write the PID of the program to the specified file.
*/
void
pidfile_create(const char *filename)
{
int fildes;
FILE *fd;
/*
* Create a new file
*/
if ((fildes = create_file_safely(filename, TRUE)) < 0)
exit(1);
/*
* Open a stdio file over the low-level one.
*/
if ((fd = fdopen(fildes, "w")) == NULL) {
log_message(LOG_ERR,
"pidfile_create: fdopen() error on PID file %s: %s.",
filename, strerror(errno));
close(fildes);
unlink(filename);
exit(1);
}
fprintf(fd, "%ld\n", (long) getpid());
fclose(fd);
}