annotate src/c/request.c @ 1241:58f5ac1bb849

Check for implicit flows via expressions injected into SQL
author Adam Chlipala <adamc@hcoop.net>
date Thu, 15 Apr 2010 14:21:12 -0400
parents 420e38516dc2
children 236dc296c32d
rev   line source
adamc@853 1 #include <stdio.h>
adamc@853 2 #include <string.h>
adamc@853 3 #include <stdlib.h>
adamc@853 4 #include <sys/types.h>
adamc@853 5 #include <sys/socket.h>
adamc@853 6 #include <netinet/in.h>
adamc@853 7 #include <unistd.h>
adamc@853 8 #include <signal.h>
adamc@853 9
adamc@853 10 #include <pthread.h>
adamc@853 11
adamc@853 12 #include <mhash.h>
adamc@853 13
adamc@853 14 #include "urweb.h"
adamc@853 15
adamc@853 16 #define MAX_RETRIES 5
adamc@853 17
adamc@1152 18 void *memmem(const void *b1, size_t len1, const void *b2, size_t len2);
adamc@1152 19
adamc@856 20 static int try_rollback(uw_context ctx, void *logger_data, uw_logger log_error) {
adamc@853 21 int r = uw_rollback(ctx);
adamc@853 22
adamc@853 23 if (r) {
adamc@856 24 log_error(logger_data, "Error running SQL ROLLBACK\n");
adamc@853 25 uw_reset(ctx);
adamc@1115 26 uw_write(ctx, "HTTP/1.1 500 Internal Server Error\r\n");
adamc@853 27 uw_write(ctx, "Content-type: text/plain\r\n\r\n");
adamc@853 28 uw_write(ctx, "Error running SQL ROLLBACK\n");
adamc@1115 29 uw_set_error_message(ctx, "Database error; you are probably out of storage space.");
adamc@853 30 }
adamc@853 31
adamc@853 32 return r;
adamc@853 33 }
adamc@853 34
adamc@1094 35 uw_context uw_request_new_context(uw_app *app, void *logger_data, uw_logger log_error, uw_logger log_debug) {
adamc@853 36 uw_context ctx = uw_init();
adamc@853 37 int retries_left = MAX_RETRIES;
adamc@1094 38 uw_set_app(ctx, app);
adamc@853 39
adamc@853 40 while (1) {
adamc@853 41 failure_kind fk = uw_begin_init(ctx);
adamc@853 42
adamc@853 43 if (fk == SUCCESS) {
adamc@856 44 log_debug(logger_data, "Database connection initialized.\n");
adamc@853 45 break;
adamc@853 46 } else if (fk == BOUNDED_RETRY) {
adamc@853 47 if (retries_left) {
adamc@856 48 log_debug(logger_data, "Initialization error triggers bounded retry: %s\n", uw_error_message(ctx));
adamc@853 49 --retries_left;
adamc@853 50 } else {
adamc@856 51 log_error(logger_data, "Fatal initialization error (out of retries): %s\n", uw_error_message(ctx));
adamc@853 52 uw_free(ctx);
adamc@853 53 return NULL;
adamc@853 54 }
adamc@853 55 } else if (fk == UNLIMITED_RETRY)
adamc@856 56 log_debug(logger_data, "Initialization error triggers unlimited retry: %s\n", uw_error_message(ctx));
adamc@853 57 else if (fk == FATAL) {
adamc@856 58 log_error(logger_data, "Fatal initialization error: %s\n", uw_error_message(ctx));
adamc@853 59 uw_free(ctx);
adamc@853 60 return NULL;
adamc@853 61 } else {
adamc@856 62 log_error(logger_data, "Unknown uw_begin_init return code!\n");
adamc@853 63 uw_free(ctx);
adamc@853 64 return NULL;
adamc@853 65 }
adamc@853 66 }
adamc@853 67
adamc@853 68 return ctx;
adamc@853 69 }
adamc@853 70
adamc@1094 71 void uw_request_init(uw_app *app, void *logger_data, uw_logger log_error, uw_logger log_debug) {
adamc@853 72 uw_context ctx;
adamc@853 73 failure_kind fk;
adamc@853 74
adamc@853 75 uw_global_init();
adamc@1094 76 uw_app_init(app);
adamc@853 77
adamc@1094 78 ctx = uw_request_new_context(app, logger_data, log_error, log_debug);
adamc@853 79
adamc@853 80 if (!ctx)
adamc@853 81 exit(1);
adamc@853 82
adamc@853 83 for (fk = uw_initialize(ctx); fk == UNLIMITED_RETRY; fk = uw_initialize(ctx)) {
adamc@856 84 log_debug(logger_data, "Unlimited retry during init: %s\n", uw_error_message(ctx));
adamc@1094 85 uw_rollback(ctx);
adamc@853 86 uw_reset(ctx);
adamc@853 87 }
adamc@853 88
adamc@853 89 if (fk != SUCCESS) {
adamc@856 90 log_error(logger_data, "Failed to initialize database! %s\n", uw_error_message(ctx));
adamc@1094 91 uw_rollback(ctx);
adamc@853 92 exit(1);
adamc@853 93 }
adamc@853 94
adamc@853 95 uw_free(ctx);
adamc@853 96 }
adamc@853 97
adamc@853 98
adamc@853 99 typedef struct uw_rc {
adamc@853 100 size_t path_copy_size;
adamc@853 101 char *path_copy;
adamc@853 102 } *uw_request_context;
adamc@853 103
adamc@853 104 uw_request_context uw_new_request_context(void) {
adamc@853 105 uw_request_context r = malloc(sizeof(struct uw_rc));
adamc@853 106 r->path_copy_size = 0;
adamc@853 107 r->path_copy = malloc(0);
adamc@853 108 return r;
adamc@853 109 }
adamc@853 110
adamc@853 111 void uw_free_request_context(uw_request_context r) {
adamc@853 112 free(r->path_copy);
adamc@853 113 free(r);
adamc@853 114 }
adamc@853 115
adamc@854 116 request_result uw_request(uw_request_context rc, uw_context ctx,
adamc@854 117 char *method, char *path, char *query_string,
adamc@854 118 char *body, size_t body_len,
adamc@856 119 void (*on_success)(uw_context), void (*on_failure)(uw_context),
adamc@856 120 void *logger_data, uw_logger log_error, uw_logger log_debug,
adamc@863 121 int sock,
adamc@863 122 int (*send)(int sockfd, const void *buf, size_t len),
adamc@863 123 int (*close)(int fd)) {
adamc@853 124 int retries_left = MAX_RETRIES;
adamc@853 125 failure_kind fk;
adamc@1134 126 int is_post = 0;
adamc@853 127 char *boundary = NULL;
adamc@1134 128 size_t boundary_len = 0;
adamc@854 129 char *inputs;
adamc@1094 130 const char *prefix = uw_get_url_prefix(ctx);
adamc@1169 131 char *s;
adamc@1169 132
adamc@1169 133 for (s = path; *s; ++s) {
adamc@1169 134 if (s[0] == '%' && s[1] == '2' && s[2] == '7') {
adamc@1169 135 s[0] = '\'';
adamc@1169 136 memmove(s+1, s+3, strlen(s+3)+1);
adamc@1169 137 }
adamc@1169 138 }
adamc@853 139
adamc@1066 140 uw_set_currentUrl(ctx, path);
adamc@1066 141
adamc@854 142 if (!strcmp(method, "POST")) {
adamc@853 143 char *clen_s = uw_Basis_requestHeader(ctx, "Content-length");
adamc@853 144 if (!clen_s) {
adamc@1037 145 clen_s = "0";
adamc@1037 146 /*log_error(logger_data, "No Content-length with POST\n");
adamc@1037 147 return FAILED;*/
adamc@853 148 }
adamc@853 149 int clen = atoi(clen_s);
adamc@853 150 if (clen < 0) {
adamc@856 151 log_error(logger_data, "Negative Content-length with POST\n");
adamc@853 152 return FAILED;
adamc@853 153 }
adamc@853 154
adamc@854 155 if (body_len < clen) {
adamc@856 156 log_error(logger_data, "Request doesn't contain all POST data (according to Content-Length)\n");
adamc@853 157 return FAILED;
adamc@853 158 }
adamc@853 159
adamc@853 160 is_post = 1;
adamc@853 161
adamc@853 162 clen_s = uw_Basis_requestHeader(ctx, "Content-type");
adamc@853 163 if (clen_s && !strncasecmp(clen_s, "multipart/form-data", 19)) {
adamc@853 164 if (strncasecmp(clen_s + 19, "; boundary=", 11)) {
adamc@856 165 log_error(logger_data, "Bad multipart boundary spec");
adamc@853 166 return FAILED;
adamc@853 167 }
adamc@853 168
adamc@853 169 boundary = clen_s + 28;
adamc@853 170 boundary[0] = '-';
adamc@853 171 boundary[1] = '-';
adamc@853 172 boundary_len = strlen(boundary);
adamc@853 173 }
adamc@854 174 } else if (strcmp(method, "GET")) {
adamc@856 175 log_error(logger_data, "Not ready for non-GET/POST command: %s\n", method);
adamc@853 176 return FAILED;
adamc@853 177 }
adamc@853 178
adamc@1094 179 if (!strncmp(path, prefix, strlen(prefix))
adamc@1094 180 && !strcmp(path + strlen(prefix), ".msgs")) {
adamc@853 181 char *id = uw_Basis_requestHeader(ctx, "UrWeb-Client");
adamc@853 182 char *pass = uw_Basis_requestHeader(ctx, "UrWeb-Pass");
adamc@853 183
adamc@853 184 if (sock < 0) {
adamc@856 185 log_error(logger_data, ".msgs requested, but not socket supplied\n");
adamc@853 186 return FAILED;
adamc@853 187 }
adamc@853 188
adamc@853 189 if (id && pass) {
adamc@853 190 unsigned idn = atoi(id);
adamc@864 191 uw_client_connect(idn, atoi(pass), sock, send, close, logger_data, log_error);
adamc@856 192 log_error(logger_data, "Processed request for messages by client %u\n\n", idn);
adamc@853 193 return KEEP_OPEN;
adamc@853 194 }
adamc@853 195 else {
adamc@856 196 log_error(logger_data, "Missing fields in .msgs request: %s, %s\n\n", id, pass);
adamc@853 197 return FAILED;
adamc@853 198 }
adamc@853 199 }
adamc@853 200
adamc@853 201 if (boundary) {
adamc@854 202 char *part = body, *after_sub_headers, *header, *after_header;
adamc@853 203 size_t part_len;
adamc@853 204
adamc@853 205 part = strstr(part, boundary);
adamc@853 206 if (!part) {
adamc@856 207 log_error(logger_data, "Missing first multipart boundary\n");
adamc@853 208 return FAILED;
adamc@853 209 }
adamc@853 210 part += boundary_len;
adamc@853 211
adamc@853 212 while (1) {
adamc@853 213 char *name = NULL, *filename = NULL, *type = NULL;
adamc@853 214
adamc@853 215 if (part[0] == '-' && part[1] == '-')
adamc@853 216 break;
adamc@853 217
adamc@853 218 if (*part != '\r') {
adamc@856 219 log_error(logger_data, "No \\r after multipart boundary\n");
adamc@853 220 return FAILED;
adamc@853 221 }
adamc@853 222 ++part;
adamc@853 223 if (*part != '\n') {
adamc@856 224 log_error(logger_data, "No \\n after multipart boundary\n");
adamc@853 225 return FAILED;
adamc@853 226 }
adamc@853 227 ++part;
adamc@853 228
adamc@853 229 if (!(after_sub_headers = strstr(part, "\r\n\r\n"))) {
adamc@856 230 log_error(logger_data, "Missing end of headers after multipart boundary\n");
adamc@853 231 return FAILED;
adamc@853 232 }
adamc@853 233 after_sub_headers[2] = 0;
adamc@853 234 after_sub_headers += 4;
adamc@853 235
adamc@1134 236 for (header = part; (after_header = strstr(header, "\r\n")); header = after_header + 2) {
adamc@853 237 char *colon, *after_colon;
adamc@853 238
adamc@853 239 *after_header = 0;
adamc@853 240 if (!(colon = strchr(header, ':'))) {
adamc@856 241 log_error(logger_data, "Missing colon in multipart sub-header\n");
adamc@853 242 return FAILED;
adamc@853 243 }
adamc@853 244 *colon++ = 0;
adamc@853 245 if (*colon++ != ' ') {
adamc@856 246 log_error(logger_data, "No space after colon in multipart sub-header\n");
adamc@853 247 return FAILED;
adamc@853 248 }
adamc@853 249
adamc@853 250 if (!strcasecmp(header, "Content-Disposition")) {
adamc@853 251 if (strncmp(colon, "form-data; ", 11)) {
adamc@856 252 log_error(logger_data, "Multipart data is not \"form-data\"\n");
adamc@853 253 return FAILED;
adamc@853 254 }
adamc@853 255
adamc@1134 256 for (colon += 11; (after_colon = strchr(colon, '=')); colon = after_colon) {
adamc@853 257 char *data;
adamc@853 258 after_colon[0] = 0;
adamc@853 259 if (after_colon[1] != '"') {
adamc@856 260 log_error(logger_data, "Disposition setting is missing initial quote\n");
adamc@853 261 return FAILED;
adamc@853 262 }
adamc@853 263 data = after_colon+2;
adamc@853 264 if (!(after_colon = strchr(data, '"'))) {
adamc@856 265 log_error(logger_data, "Disposition setting is missing final quote\n");
adamc@853 266 return FAILED;
adamc@853 267 }
adamc@853 268 after_colon[0] = 0;
adamc@853 269 ++after_colon;
adamc@853 270 if (after_colon[0] == ';' && after_colon[1] == ' ')
adamc@853 271 after_colon += 2;
adamc@853 272
adamc@853 273 if (!strcasecmp(colon, "name"))
adamc@853 274 name = data;
adamc@853 275 else if (!strcasecmp(colon, "filename"))
adamc@853 276 filename = data;
adamc@853 277 }
adamc@853 278 } else if (!strcasecmp(header, "Content-Type")) {
adamc@853 279 type = colon;
adamc@853 280 }
adamc@853 281 }
adamc@853 282
adamc@854 283 part = memmem(after_sub_headers, body + body_len - after_sub_headers, boundary, boundary_len);
adamc@853 284 if (!part) {
adamc@856 285 log_error(logger_data, "Missing boundary after multipart payload\n");
adamc@853 286 return FAILED;
adamc@853 287 }
adamc@853 288 part[-2] = 0;
adamc@853 289 part_len = part - after_sub_headers - 2;
adamc@853 290 part[0] = 0;
adamc@853 291 part += boundary_len;
adamc@853 292
adamc@853 293 if (filename) {
adamc@853 294 uw_Basis_file f = {filename, type, {part_len, after_sub_headers}};
adamc@853 295
adamc@853 296 if (uw_set_file_input(ctx, name, f)) {
adamc@856 297 log_error(logger_data, "%s\n", uw_error_message(ctx));
adamc@853 298 return FAILED;
adamc@853 299 }
adamc@853 300 } else if (uw_set_input(ctx, name, after_sub_headers)) {
adamc@856 301 log_error(logger_data, "%s\n", uw_error_message(ctx));
adamc@853 302 return FAILED;
adamc@853 303 }
adamc@853 304 }
adamc@853 305 }
adamc@853 306 else {
adamc@854 307 inputs = is_post ? body : query_string;
adamc@853 308
adamc@853 309 if (inputs) {
adamc@853 310 char *name, *value;
adamc@853 311
adamc@853 312 while (*inputs) {
adamc@853 313 name = inputs;
adamc@1134 314 if ((inputs = strchr(inputs, '&')))
adamc@853 315 *inputs++ = 0;
adamc@853 316 else
adamc@853 317 inputs = strchr(name, 0);
adamc@853 318
adamc@1134 319 if ((value = strchr(name, '='))) {
adamc@853 320 *value++ = 0;
adamc@853 321 if (uw_set_input(ctx, name, value)) {
adamc@856 322 log_error(logger_data, "%s\n", uw_error_message(ctx));
adamc@853 323 return FAILED;
adamc@853 324 }
adamc@853 325 }
adamc@853 326 else if (uw_set_input(ctx, name, "")) {
adamc@856 327 log_error(logger_data, "%s\n", uw_error_message(ctx));
adamc@853 328 return FAILED;
adamc@853 329 }
adamc@853 330 }
adamc@853 331 }
adamc@853 332 }
adamc@853 333
adamc@856 334 log_debug(logger_data, "Serving URI %s....\n", path);
adamc@853 335
adamc@853 336 while (1) {
adamc@853 337 size_t path_len = strlen(path);
adamc@853 338
adamc@856 339 on_success(ctx);
adamc@853 340
adamc@853 341 if (path_len + 1 > rc->path_copy_size) {
adamc@853 342 rc->path_copy_size = path_len + 1;
adamc@853 343 rc->path_copy = realloc(rc->path_copy, rc->path_copy_size);
adamc@853 344 }
adamc@853 345 strcpy(rc->path_copy, path);
adamc@853 346 fk = uw_begin(ctx, rc->path_copy);
adamc@1065 347 if (fk == SUCCESS || fk == RETURN_INDIRECTLY) {
adamc@853 348 uw_commit(ctx);
adamc@1131 349 if (uw_has_error(ctx)) {
adamc@1131 350 log_error(logger_data, "Fatal error: %s\n", uw_error_message(ctx));
adamc@1131 351
adamc@1131 352 uw_reset_keep_error_message(ctx);
adamc@1131 353 on_failure(ctx);
adamc@1131 354 uw_write_header(ctx, "Content-type: text/html\r\n");
adamc@1131 355 uw_write(ctx, "<html><head><title>Fatal Error</title></head><body>");
adamc@1131 356 uw_write(ctx, "Fatal error: ");
adamc@1131 357 uw_write(ctx, uw_error_message(ctx));
adamc@1131 358 uw_write(ctx, "\n</body></html>");
adamc@1131 359
adamc@1131 360 return FAILED;
adamc@1131 361 } else
adamc@1131 362 return SERVED;
adamc@853 363 } else if (fk == BOUNDED_RETRY) {
adamc@853 364 if (retries_left) {
adamc@856 365 log_debug(logger_data, "Error triggers bounded retry: %s\n", uw_error_message(ctx));
adamc@853 366 --retries_left;
adamc@853 367 }
adamc@853 368 else {
adamc@856 369 log_error(logger_data, "Fatal error (out of retries): %s\n", uw_error_message(ctx));
adamc@853 370
adamc@856 371 try_rollback(ctx, logger_data, log_error);
adamc@853 372
adamc@853 373 uw_reset_keep_error_message(ctx);
adamc@856 374 on_failure(ctx);
adamc@853 375 uw_write_header(ctx, "Content-type: text/plain\r\n");
adamc@853 376 uw_write(ctx, "Fatal error (out of retries): ");
adamc@853 377 uw_write(ctx, uw_error_message(ctx));
adamc@853 378 uw_write(ctx, "\n");
adamc@853 379
adamc@853 380 return FAILED;
adamc@853 381 }
adamc@853 382 } else if (fk == UNLIMITED_RETRY)
adamc@856 383 log_debug(logger_data, "Error triggers unlimited retry: %s\n", uw_error_message(ctx));
adamc@853 384 else if (fk == FATAL) {
adamc@856 385 log_error(logger_data, "Fatal error: %s\n", uw_error_message(ctx));
adamc@853 386
adamc@856 387 try_rollback(ctx, logger_data, log_error);
adamc@853 388
adamc@853 389 uw_reset_keep_error_message(ctx);
adamc@856 390 on_failure(ctx);
adamc@853 391 uw_write_header(ctx, "Content-type: text/html\r\n");
adamc@853 392 uw_write(ctx, "<html><head><title>Fatal Error</title></head><body>");
adamc@853 393 uw_write(ctx, "Fatal error: ");
adamc@853 394 uw_write(ctx, uw_error_message(ctx));
adamc@853 395 uw_write(ctx, "\n</body></html>");
adamc@853 396
adamc@853 397 return FAILED;
adamc@853 398 } else {
adamc@856 399 log_error(logger_data, "Unknown uw_handle return code!\n");
adamc@853 400
adamc@856 401 try_rollback(ctx, logger_data, log_error);
adamc@853 402
adamc@853 403 uw_reset_keep_request(ctx);
adamc@856 404 on_failure(ctx);
adamc@853 405 uw_write_header(ctx, "Content-type: text/plain\r\n");
adamc@853 406 uw_write(ctx, "Unknown uw_handle return code!\n");
adamc@853 407
adamc@853 408 return FAILED;
adamc@853 409 }
adamc@853 410
adamc@856 411 if (try_rollback(ctx, logger_data, log_error))
adamc@853 412 return FAILED;
adamc@853 413
adamc@853 414 uw_reset_keep_request(ctx);
adamc@853 415 }
adamc@853 416 }
adamc@853 417
adamc@856 418 typedef struct {
adamc@1094 419 uw_app *app;
adamc@856 420 void *logger_data;
adamc@856 421 uw_logger log_error, log_debug;
adamc@856 422 } loggers;
adamc@856 423
adamc@853 424 void *client_pruner(void *data) {
adamc@856 425 loggers *ls = (loggers *)data;
adamc@1094 426 uw_context ctx = uw_request_new_context(ls->app, ls->logger_data, ls->log_error, ls->log_debug);
adamc@853 427
adamc@853 428 if (!ctx)
adamc@853 429 exit(1);
adamc@853 430
adamc@853 431 while (1) {
adamc@853 432 uw_prune_clients(ctx);
adamc@853 433 sleep(5);
adamc@853 434 }
adamc@853 435 }