1872b698pfg/*-
2872b698pfg * SPDX-License-Identifier: BSD-3-Clause
3872b698pfg *
47d07d2drgrimes * Copyright (c) 1983, 1993
57d07d2drgrimes *	The Regents of the University of California.  All rights reserved.
67d07d2drgrimes *
77d07d2drgrimes * Redistribution and use in source and binary forms, with or without
87d07d2drgrimes * modification, are permitted provided that the following conditions
97d07d2drgrimes * are met:
107d07d2drgrimes * 1. Redistributions of source code must retain the above copyright
117d07d2drgrimes *    notice, this list of conditions and the following disclaimer.
127d07d2drgrimes * 2. Redistributions in binary form must reproduce the above copyright
137d07d2drgrimes *    notice, this list of conditions and the following disclaimer in the
147d07d2drgrimes *    documentation and/or other materials provided with the distribution.
1573e4798brueffer * 3. Neither the name of the University nor the names of its contributors
167d07d2drgrimes *    may be used to endorse or promote products derived from this software
177d07d2drgrimes *    without specific prior written permission.
187d07d2drgrimes *
197d07d2drgrimes * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
207d07d2drgrimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
217d07d2drgrimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
227d07d2drgrimes * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
237d07d2drgrimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
247d07d2drgrimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
257d07d2drgrimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
267d07d2drgrimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
277d07d2drgrimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
287d07d2drgrimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
297d07d2drgrimes * SUCH DAMAGE.
307d07d2drgrimes */
317d07d2drgrimes
327d07d2drgrimes#ifndef lint
337a938e0charnierstatic const char copyright[] =
347d07d2drgrimes"@(#) Copyright (c) 1983, 1993\n\
357d07d2drgrimes	The Regents of the University of California.  All rights reserved.\n";
367d07d2drgrimes#endif /* not lint */
377d07d2drgrimes
387d07d2drgrimes#ifndef lint
397a938e0charnier#if 0
407d07d2drgrimesstatic char sccsid[] = "@(#)fingerd.c	8.1 (Berkeley) 6/4/93";
417a938e0charnier#endif
4220aa19ewollmanstatic const char rcsid[] =
4376f0c92peter  "$FreeBSD$";
447d07d2drgrimes#endif /* not lint */
457d07d2drgrimes
46f047799jedgar#include <sys/types.h>
47a77173abrian#include <sys/param.h>
487d07d2drgrimes#include <sys/socket.h>
497d07d2drgrimes#include <netinet/in.h>
5020aa19ewollman#include <netinet/tcp.h>
517d07d2drgrimes#include <arpa/inet.h>
527d07d2drgrimes#include <errno.h>
537d07d2drgrimes
547d07d2drgrimes#include <unistd.h>
557d07d2drgrimes#include <syslog.h>
56f047799jedgar#include <libutil.h>
577d07d2drgrimes#include <netdb.h>
587d07d2drgrimes#include <stdio.h>
597d07d2drgrimes#include <stdlib.h>
60b2070d4wollman#include <string.h>
617d07d2drgrimes#include "pathnames.h"
62daa291elidl#ifdef USE_BLACKLIST
63daa291elidl#include <blacklist.h>
64daa291elidl#endif
657d07d2drgrimes
6645f0d08cpercivavoid logerr(const char *, ...) __printflike(1, 2) __dead2;
677d07d2drgrimes
687d07d2drgrimesint
69f15fa6aimpmain(int argc, char *argv[])
707d07d2drgrimes{
71f15fa6aimp	FILE *fp;
72f15fa6aimp	int ch;
73f15fa6aimp	char *lp;
74eb6cba1shin	struct sockaddr_storage ss;
7503a2de3stefanf	socklen_t sval;
76da05485des	int p[2], debug, kflag, logging, pflag, secure;
777d07d2drgrimes#define	ENTRIES	50
787d07d2drgrimes	char **ap, *av[ENTRIES + 1], **comp, line[1024], *prog;
7961dd45ebrian	char rhost[MAXHOSTNAMELEN];
807d07d2drgrimes
817d07d2drgrimes	prog = _PATH_FINGER;
8245fc106des	debug = logging = kflag = pflag = secure = 0;
837d07d2drgrimes	openlog("fingerd", LOG_PID | LOG_CONS, LOG_DAEMON);
847d07d2drgrimes	opterr = 0;
85da05485des	while ((ch = getopt(argc, argv, "dklp:s")) != -1)
867d07d2drgrimes		switch (ch) {
87da05485des		case 'd':
88da05485des			debug = 1;
89da05485des			break;
90da05485des		case 'k':
91da05485des			kflag = 1;
92da05485des			break;
937d07d2drgrimes		case 'l':
947d07d2drgrimes			logging = 1;
957d07d2drgrimes			break;
967d07d2drgrimes		case 'p':
977d07d2drgrimes			prog = optarg;
984a461e9wollman			pflag = 1;
997d07d2drgrimes			break;
1007d07d2drgrimes		case 's':
1017d07d2drgrimes			secure = 1;
1027d07d2drgrimes			break;
1037d07d2drgrimes		case '?':
1047d07d2drgrimes		default:
105f2cbc8cpeter			logerr("illegal option -- %c", optopt);
1067d07d2drgrimes		}
1077d07d2drgrimes
10820aa19ewollman	/*
10920aa19ewollman	 * Enable server-side Transaction TCP.
11020aa19ewollman	 */
111da05485des	if (!debug) {
11220aa19ewollman		int one = 1;
11320aa19ewollman		if (setsockopt(STDOUT_FILENO, IPPROTO_TCP, TCP_NOPUSH, &one,
11420aa19ewollman			       sizeof one) < 0) {
11520aa19ewollman			logerr("setsockopt(TCP_NOPUSH) failed: %m");
11620aa19ewollman		}
11720aa19ewollman	}
11820aa19ewollman
1197d07d2drgrimes	if (!fgets(line, sizeof(line), stdin))
1207d07d2drgrimes		exit(1);
121f05428ergrimes
122da05485des	if (!debug && (logging || pflag)) {
1234a461e9wollman		sval = sizeof(ss);
1244a461e9wollman		if (getpeername(0, (struct sockaddr *)&ss, &sval) < 0)
1254a461e9wollman			logerr("getpeername: %s", strerror(errno));
1264a461e9wollman		realhostname_sa(rhost, sizeof rhost - 1,
1274a461e9wollman				(struct sockaddr *)&ss, sval);
1284a461e9wollman		rhost[sizeof(rhost) - 1] = '\0';
1294a461e9wollman		if (pflag)
1304a461e9wollman			setenv("FINGERD_REMOTE_HOST", rhost, 1);
1314a461e9wollman	}
1324a461e9wollman
1338f19411sef	if (logging) {
1348f19411sef		char *t;
1358f19411sef		char *end;
1368f19411sef
1378f19411sef		end = memchr(line, 0, sizeof(line));
1388f19411sef		if (end == NULL) {
139f047799jedgar			if ((t = malloc(sizeof(line) + 1)) == NULL)
140f047799jedgar				logerr("malloc: %s", strerror(errno));
1418f19411sef			memcpy(t, line, sizeof(line));
1428f19411sef			t[sizeof(line)] = 0;
1438f19411sef		} else {
144f047799jedgar			if ((t = strdup(line)) == NULL)
145f047799jedgar				logerr("strdup: %s", strerror(errno));
1468f19411sef		}
1478f19411sef		for (end = t; *end; end++)
1488f19411sef			if (*end == '\n' || *end == '\r')
1498f19411sef				*end = ' ';
150a77173abrian		syslog(LOG_NOTICE, "query from %s: `%s'", rhost, t);
1518f19411sef	}
1528f19411sef
153da05485des	comp = &av[2];
154da05485des	av[3] = "--";
155da05485des	if (kflag)
156da05485des		*comp-- = "-k";
157da05485des	for (lp = line, ap = &av[4];;) {
1587d07d2drgrimes		*ap = strtok(lp, " \t\r\n");
1597d07d2drgrimes		if (!*ap) {
160da05485des			if (secure && ap == &av[4]) {
161daa291elidl#ifdef USE_BLACKLIST
162daa291elidl				blacklist(1, STDIN_FILENO, "nousername");
163daa291elidl#endif
1647d07d2drgrimes				puts("must provide username\r\n");
1657d07d2drgrimes				exit(1);
1667d07d2drgrimes			}
1677d07d2drgrimes			break;
1687d07d2drgrimes		}
1697d07d2drgrimes		if (secure && strchr(*ap, '@')) {
170daa291elidl#ifdef USE_BLACKLIST
171daa291elidl			blacklist(1, STDIN_FILENO, "noforwarding");
172daa291elidl#endif
173f1d31d4phk			puts("forwarding service denied\r\n");
1747d07d2drgrimes			exit(1);
1757d07d2drgrimes		}
1767d07d2drgrimes
1777d07d2drgrimes		/* RFC742: "/[Ww]" == "-l" */
1787d07d2drgrimes		if ((*ap)[0] == '/' && ((*ap)[1] == 'W' || (*ap)[1] == 'w')) {
179da05485des			*comp-- = "-l";
1807d07d2drgrimes		}
1813837a96ru		else if (++ap == av + ENTRIES) {
1823837a96ru			*ap = NULL;
1837d07d2drgrimes			break;
1843837a96ru		}
1857d07d2drgrimes		lp = NULL;
1867d07d2drgrimes	}
1877d07d2drgrimes
188b1d34c6pjd	if ((lp = strrchr(prog, '/')) != NULL)
1897d07d2drgrimes		*comp = ++lp;
1907d07d2drgrimes	else
1917d07d2drgrimes		*comp = prog;
1927d07d2drgrimes	if (pipe(p) < 0)
19320aa19ewollman		logerr("pipe: %s", strerror(errno));
1947d07d2drgrimes
195da05485des	if (debug) {
196da05485des		fprintf(stderr, "%s", prog);
197da05485des		for (ap = comp; *ap != NULL; ++ap)
198da05485des			fprintf(stderr, " %s", *ap);
199da05485des		fprintf(stderr, "\n");
200da05485des	}
201da05485des
2027d07d2drgrimes	switch(vfork()) {
2037d07d2drgrimes	case 0:
2047d07d2drgrimes		(void)close(p[0]);
2054a461e9wollman		if (p[1] != STDOUT_FILENO) {
2064a461e9wollman			(void)dup2(p[1], STDOUT_FILENO);
2077d07d2drgrimes			(void)close(p[1]);
2087d07d2drgrimes		}
2094a461e9wollman		dup2(STDOUT_FILENO, STDERR_FILENO);
2104a461e9wollman
211daa291elidl#ifdef USE_BLACKLIST
212daa291elidl		blacklist(0, STDIN_FILENO, "success");
213daa291elidl#endif
2147d07d2drgrimes		execv(prog, comp);
2154a461e9wollman		write(STDERR_FILENO, prog, strlen(prog));
2164a461e9wollman#define MSG ": cannot execute\n"
2174a461e9wollman		write(STDERR_FILENO, MSG, strlen(MSG));
2184a461e9wollman#undef MSG
2197d07d2drgrimes		_exit(1);
2207d07d2drgrimes	case -1:
22120aa19ewollman		logerr("fork: %s", strerror(errno));
2227d07d2drgrimes	}
2237d07d2drgrimes	(void)close(p[1]);
2247d07d2drgrimes	if (!(fp = fdopen(p[0], "r")))
22520aa19ewollman		logerr("fdopen: %s", strerror(errno));
2267d07d2drgrimes	while ((ch = getc(fp)) != EOF) {
2277d07d2drgrimes		if (ch == '\n')
2287d07d2drgrimes			putchar('\r');
2297d07d2drgrimes		putchar(ch);
2307d07d2drgrimes	}
2317d07d2drgrimes	exit(0);
2327d07d2drgrimes}
2337d07d2drgrimes
2347d07d2drgrimes#include <stdarg.h>
2357d07d2drgrimes
2367d07d2drgrimesvoid
23720aa19ewollmanlogerr(const char *fmt, ...)
2387d07d2drgrimes{
2397d07d2drgrimes	va_list ap;
2407d07d2drgrimes	va_start(ap, fmt);
2417d07d2drgrimes	(void)vsyslog(LOG_ERR, fmt, ap);
2427d07d2drgrimes	va_end(ap);
2437d07d2drgrimes	exit(1);
2447d07d2drgrimes	/* NOTREACHED */
2457d07d2drgrimes}
246