fastcgi.c 40 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768
  1. /*
  2. +----------------------------------------------------------------------+
  3. | Copyright (c) The PHP Group |
  4. +----------------------------------------------------------------------+
  5. | This source file is subject to version 3.01 of the PHP license, |
  6. | that is bundled with this package in the file LICENSE, and is |
  7. | available through the world-wide-web at the following url: |
  8. | https://www.php.net/license/3_01.txt |
  9. | If you did not receive a copy of the PHP license and are unable to |
  10. | obtain it through the world-wide-web, please send a note to |
  11. | license@php.net so we can mail you a copy immediately. |
  12. +----------------------------------------------------------------------+
  13. | Authors: Dmitry Stogov <dmitry@php.net> |
  14. +----------------------------------------------------------------------+
  15. */
  16. #include "php.h"
  17. #include "php_network.h"
  18. #include <string.h>
  19. #include <stdlib.h>
  20. #include <stdio.h>
  21. #include <stdarg.h>
  22. #include <errno.h>
  23. #ifndef MAXFQDNLEN
  24. #define MAXFQDNLEN 255
  25. #endif
  26. #ifdef _WIN32
  27. #include <windows.h>
  28. typedef unsigned int in_addr_t;
  29. struct sockaddr_un {
  30. short sun_family;
  31. char sun_path[MAXPATHLEN];
  32. };
  33. static HANDLE fcgi_accept_mutex = INVALID_HANDLE_VALUE;
  34. static int is_impersonate = 0;
  35. #define FCGI_LOCK(fd) \
  36. if (fcgi_accept_mutex != INVALID_HANDLE_VALUE) { \
  37. DWORD ret; \
  38. while ((ret = WaitForSingleObject(fcgi_accept_mutex, 1000)) == WAIT_TIMEOUT) { \
  39. if (in_shutdown) return -1; \
  40. } \
  41. if (ret == WAIT_FAILED) { \
  42. fprintf(stderr, "WaitForSingleObject() failed\n"); \
  43. return -1; \
  44. } \
  45. }
  46. #define FCGI_UNLOCK(fd) \
  47. if (fcgi_accept_mutex != INVALID_HANDLE_VALUE) { \
  48. ReleaseMutex(fcgi_accept_mutex); \
  49. }
  50. #else
  51. # include <sys/types.h>
  52. # include <sys/stat.h>
  53. # include <unistd.h>
  54. # include <fcntl.h>
  55. # include <sys/socket.h>
  56. # include <sys/un.h>
  57. # include <netinet/in.h>
  58. # include <netinet/tcp.h>
  59. # include <arpa/inet.h>
  60. # include <netdb.h>
  61. # include <signal.h>
  62. # if defined(HAVE_POLL_H) && defined(HAVE_POLL)
  63. # include <poll.h>
  64. # elif defined(HAVE_SYS_POLL_H) && defined(HAVE_POLL)
  65. # include <sys/poll.h>
  66. # endif
  67. # if defined(HAVE_SYS_SELECT_H)
  68. # include <sys/select.h>
  69. # endif
  70. #ifndef INADDR_NONE
  71. #define INADDR_NONE ((unsigned long) -1)
  72. #endif
  73. # ifndef HAVE_SOCKLEN_T
  74. typedef unsigned int socklen_t;
  75. # endif
  76. # ifdef USE_LOCKING
  77. # define FCGI_LOCK(fd) \
  78. do { \
  79. struct flock lock; \
  80. lock.l_type = F_WRLCK; \
  81. lock.l_start = 0; \
  82. lock.l_whence = SEEK_SET; \
  83. lock.l_len = 0; \
  84. if (fcntl(fd, F_SETLKW, &lock) != -1) { \
  85. break; \
  86. } else if (errno != EINTR || in_shutdown) { \
  87. return -1; \
  88. } \
  89. } while (1)
  90. # define FCGI_UNLOCK(fd) \
  91. do { \
  92. int orig_errno = errno; \
  93. while (1) { \
  94. struct flock lock; \
  95. lock.l_type = F_UNLCK; \
  96. lock.l_start = 0; \
  97. lock.l_whence = SEEK_SET; \
  98. lock.l_len = 0; \
  99. if (fcntl(fd, F_SETLK, &lock) != -1) { \
  100. break; \
  101. } else if (errno != EINTR) { \
  102. return -1; \
  103. } \
  104. } \
  105. errno = orig_errno; \
  106. } while (0)
  107. # else
  108. # define FCGI_LOCK(fd)
  109. # define FCGI_UNLOCK(fd)
  110. # endif
  111. #endif
  112. #include "fastcgi.h"
  113. typedef struct _fcgi_header {
  114. unsigned char version;
  115. unsigned char type;
  116. unsigned char requestIdB1;
  117. unsigned char requestIdB0;
  118. unsigned char contentLengthB1;
  119. unsigned char contentLengthB0;
  120. unsigned char paddingLength;
  121. unsigned char reserved;
  122. } fcgi_header;
  123. typedef struct _fcgi_begin_request {
  124. unsigned char roleB1;
  125. unsigned char roleB0;
  126. unsigned char flags;
  127. unsigned char reserved[5];
  128. } fcgi_begin_request;
  129. typedef struct _fcgi_begin_request_rec {
  130. fcgi_header hdr;
  131. fcgi_begin_request body;
  132. } fcgi_begin_request_rec;
  133. typedef struct _fcgi_end_request {
  134. unsigned char appStatusB3;
  135. unsigned char appStatusB2;
  136. unsigned char appStatusB1;
  137. unsigned char appStatusB0;
  138. unsigned char protocolStatus;
  139. unsigned char reserved[3];
  140. } fcgi_end_request;
  141. typedef struct _fcgi_end_request_rec {
  142. fcgi_header hdr;
  143. fcgi_end_request body;
  144. } fcgi_end_request_rec;
  145. typedef struct _fcgi_hash_bucket {
  146. unsigned int hash_value;
  147. unsigned int var_len;
  148. char *var;
  149. unsigned int val_len;
  150. char *val;
  151. struct _fcgi_hash_bucket *next;
  152. struct _fcgi_hash_bucket *list_next;
  153. } fcgi_hash_bucket;
  154. typedef struct _fcgi_hash_buckets {
  155. unsigned int idx;
  156. struct _fcgi_hash_buckets *next;
  157. struct _fcgi_hash_bucket data[FCGI_HASH_TABLE_SIZE];
  158. } fcgi_hash_buckets;
  159. typedef struct _fcgi_data_seg {
  160. char *pos;
  161. char *end;
  162. struct _fcgi_data_seg *next;
  163. char data[1];
  164. } fcgi_data_seg;
  165. typedef struct _fcgi_hash {
  166. fcgi_hash_bucket *hash_table[FCGI_HASH_TABLE_SIZE];
  167. fcgi_hash_bucket *list;
  168. fcgi_hash_buckets *buckets;
  169. fcgi_data_seg *data;
  170. } fcgi_hash;
  171. typedef struct _fcgi_req_hook fcgi_req_hook;
  172. struct _fcgi_req_hook {
  173. void(*on_accept)(void);
  174. void(*on_read)(void);
  175. void(*on_close)(void);
  176. };
  177. struct _fcgi_request {
  178. int listen_socket;
  179. int tcp;
  180. int fd;
  181. int id;
  182. int keep;
  183. #ifdef TCP_NODELAY
  184. int nodelay;
  185. #endif
  186. int ended;
  187. int in_len;
  188. int in_pad;
  189. fcgi_header *out_hdr;
  190. unsigned char *out_pos;
  191. unsigned char out_buf[1024*8];
  192. unsigned char reserved[sizeof(fcgi_end_request_rec)];
  193. fcgi_req_hook hook;
  194. int has_env;
  195. fcgi_hash env;
  196. };
  197. /* maybe it's better to use weak name instead */
  198. #ifndef HAVE_ATTRIBUTE_WEAK
  199. static fcgi_logger fcgi_log;
  200. #endif
  201. typedef union _sa_t {
  202. struct sockaddr sa;
  203. struct sockaddr_un sa_unix;
  204. struct sockaddr_in sa_inet;
  205. struct sockaddr_in6 sa_inet6;
  206. } sa_t;
  207. static HashTable fcgi_mgmt_vars;
  208. static int is_initialized = 0;
  209. static int is_fastcgi = 0;
  210. static int in_shutdown = 0;
  211. static sa_t *allowed_clients = NULL;
  212. static sa_t client_sa;
  213. /* hash table */
  214. static void fcgi_hash_init(fcgi_hash *h)
  215. {
  216. memset(h->hash_table, 0, sizeof(h->hash_table));
  217. h->list = NULL;
  218. h->buckets = (fcgi_hash_buckets*)malloc(sizeof(fcgi_hash_buckets));
  219. h->buckets->idx = 0;
  220. h->buckets->next = NULL;
  221. h->data = (fcgi_data_seg*)malloc(sizeof(fcgi_data_seg) - 1 + FCGI_HASH_SEG_SIZE);
  222. h->data->pos = h->data->data;
  223. h->data->end = h->data->pos + FCGI_HASH_SEG_SIZE;
  224. h->data->next = NULL;
  225. }
  226. static void fcgi_hash_destroy(fcgi_hash *h)
  227. {
  228. fcgi_hash_buckets *b;
  229. fcgi_data_seg *p;
  230. b = h->buckets;
  231. while (b) {
  232. fcgi_hash_buckets *q = b;
  233. b = b->next;
  234. free(q);
  235. }
  236. p = h->data;
  237. while (p) {
  238. fcgi_data_seg *q = p;
  239. p = p->next;
  240. free(q);
  241. }
  242. }
  243. static void fcgi_hash_clean(fcgi_hash *h)
  244. {
  245. memset(h->hash_table, 0, sizeof(h->hash_table));
  246. h->list = NULL;
  247. /* delete all bucket blocks except the first one */
  248. while (h->buckets->next) {
  249. fcgi_hash_buckets *q = h->buckets;
  250. h->buckets = h->buckets->next;
  251. free(q);
  252. }
  253. h->buckets->idx = 0;
  254. /* delete all data segments except the first one */
  255. while (h->data->next) {
  256. fcgi_data_seg *q = h->data;
  257. h->data = h->data->next;
  258. free(q);
  259. }
  260. h->data->pos = h->data->data;
  261. }
  262. static inline char* fcgi_hash_strndup(fcgi_hash *h, char *str, unsigned int str_len)
  263. {
  264. char *ret;
  265. if (UNEXPECTED(h->data->pos + str_len + 1 >= h->data->end)) {
  266. unsigned int seg_size = (str_len + 1 > FCGI_HASH_SEG_SIZE) ? str_len + 1 : FCGI_HASH_SEG_SIZE;
  267. fcgi_data_seg *p = (fcgi_data_seg*)malloc(sizeof(fcgi_data_seg) - 1 + seg_size);
  268. p->pos = p->data;
  269. p->end = p->pos + seg_size;
  270. p->next = h->data;
  271. h->data = p;
  272. }
  273. ret = h->data->pos;
  274. memcpy(ret, str, str_len);
  275. ret[str_len] = 0;
  276. h->data->pos += str_len + 1;
  277. return ret;
  278. }
  279. static char* fcgi_hash_set(fcgi_hash *h, unsigned int hash_value, char *var, unsigned int var_len, char *val, unsigned int val_len)
  280. {
  281. unsigned int idx = hash_value & FCGI_HASH_TABLE_MASK;
  282. fcgi_hash_bucket *p = h->hash_table[idx];
  283. while (UNEXPECTED(p != NULL)) {
  284. if (UNEXPECTED(p->hash_value == hash_value) &&
  285. p->var_len == var_len &&
  286. memcmp(p->var, var, var_len) == 0) {
  287. p->val_len = val_len;
  288. p->val = fcgi_hash_strndup(h, val, val_len);
  289. return p->val;
  290. }
  291. p = p->next;
  292. }
  293. if (UNEXPECTED(h->buckets->idx >= FCGI_HASH_TABLE_SIZE)) {
  294. fcgi_hash_buckets *b = (fcgi_hash_buckets*)malloc(sizeof(fcgi_hash_buckets));
  295. b->idx = 0;
  296. b->next = h->buckets;
  297. h->buckets = b;
  298. }
  299. p = h->buckets->data + h->buckets->idx;
  300. h->buckets->idx++;
  301. p->next = h->hash_table[idx];
  302. h->hash_table[idx] = p;
  303. p->list_next = h->list;
  304. h->list = p;
  305. p->hash_value = hash_value;
  306. p->var_len = var_len;
  307. p->var = fcgi_hash_strndup(h, var, var_len);
  308. p->val_len = val_len;
  309. p->val = fcgi_hash_strndup(h, val, val_len);
  310. return p->val;
  311. }
  312. static void fcgi_hash_del(fcgi_hash *h, unsigned int hash_value, char *var, unsigned int var_len)
  313. {
  314. unsigned int idx = hash_value & FCGI_HASH_TABLE_MASK;
  315. fcgi_hash_bucket **p = &h->hash_table[idx];
  316. while (*p != NULL) {
  317. if ((*p)->hash_value == hash_value &&
  318. (*p)->var_len == var_len &&
  319. memcmp((*p)->var, var, var_len) == 0) {
  320. (*p)->val = NULL; /* NULL value means deleted */
  321. (*p)->val_len = 0;
  322. *p = (*p)->next;
  323. return;
  324. }
  325. p = &(*p)->next;
  326. }
  327. }
  328. static char *fcgi_hash_get(fcgi_hash *h, unsigned int hash_value, char *var, unsigned int var_len, unsigned int *val_len)
  329. {
  330. unsigned int idx = hash_value & FCGI_HASH_TABLE_MASK;
  331. fcgi_hash_bucket *p = h->hash_table[idx];
  332. while (p != NULL) {
  333. if (p->hash_value == hash_value &&
  334. p->var_len == var_len &&
  335. memcmp(p->var, var, var_len) == 0) {
  336. *val_len = p->val_len;
  337. return p->val;
  338. }
  339. p = p->next;
  340. }
  341. return NULL;
  342. }
  343. static void fcgi_hash_apply(fcgi_hash *h, fcgi_apply_func func, void *arg)
  344. {
  345. fcgi_hash_bucket *p = h->list;
  346. while (p) {
  347. if (EXPECTED(p->val != NULL)) {
  348. func(p->var, p->var_len, p->val, p->val_len, arg);
  349. }
  350. p = p->list_next;
  351. }
  352. }
  353. #ifdef _WIN32
  354. static DWORD WINAPI fcgi_shutdown_thread(LPVOID arg)
  355. {
  356. HANDLE shutdown_event = (HANDLE) arg;
  357. WaitForSingleObject(shutdown_event, INFINITE);
  358. in_shutdown = 1;
  359. return 0;
  360. }
  361. #else
  362. static void fcgi_signal_handler(int signo)
  363. {
  364. if (signo == SIGUSR1 || signo == SIGTERM) {
  365. in_shutdown = 1;
  366. }
  367. }
  368. static void fcgi_setup_signals(void)
  369. {
  370. struct sigaction new_sa, old_sa;
  371. sigemptyset(&new_sa.sa_mask);
  372. new_sa.sa_flags = 0;
  373. new_sa.sa_handler = fcgi_signal_handler;
  374. sigaction(SIGUSR1, &new_sa, NULL);
  375. sigaction(SIGTERM, &new_sa, NULL);
  376. sigaction(SIGPIPE, NULL, &old_sa);
  377. if (old_sa.sa_handler == SIG_DFL) {
  378. sigaction(SIGPIPE, &new_sa, NULL);
  379. }
  380. }
  381. #endif
  382. void fcgi_set_in_shutdown(int new_value)
  383. {
  384. in_shutdown = new_value;
  385. }
  386. int fcgi_in_shutdown(void)
  387. {
  388. return in_shutdown;
  389. }
  390. void fcgi_terminate(void)
  391. {
  392. in_shutdown = 1;
  393. }
  394. void fcgi_request_set_keep(fcgi_request *req, int new_value)
  395. {
  396. req->keep = new_value;
  397. }
  398. #ifndef HAVE_ATTRIBUTE_WEAK
  399. void fcgi_set_logger(fcgi_logger lg) {
  400. fcgi_log = lg;
  401. }
  402. #else
  403. void __attribute__((weak)) fcgi_log(int type, const char *format, ...) {
  404. va_list ap;
  405. va_start(ap, format);
  406. vfprintf(stderr, format, ap);
  407. va_end(ap);
  408. }
  409. #endif
  410. int fcgi_init(void)
  411. {
  412. if (!is_initialized) {
  413. #ifndef _WIN32
  414. sa_t sa;
  415. socklen_t len = sizeof(sa);
  416. #endif
  417. zend_hash_init(&fcgi_mgmt_vars, 8, NULL, fcgi_free_mgmt_var_cb, 1);
  418. fcgi_set_mgmt_var("FCGI_MPXS_CONNS", sizeof("FCGI_MPXS_CONNS")-1, "0", sizeof("0")-1);
  419. is_initialized = 1;
  420. #ifdef _WIN32
  421. # if 0
  422. /* TODO: Support for TCP sockets */
  423. WSADATA wsaData;
  424. if (WSAStartup(MAKEWORD(2,0), &wsaData)) {
  425. fprintf(stderr, "Error starting Windows Sockets. Error: %d", WSAGetLastError());
  426. return 0;
  427. }
  428. # endif
  429. if ((GetStdHandle(STD_OUTPUT_HANDLE) == INVALID_HANDLE_VALUE) &&
  430. (GetStdHandle(STD_ERROR_HANDLE) == INVALID_HANDLE_VALUE) &&
  431. (GetStdHandle(STD_INPUT_HANDLE) != INVALID_HANDLE_VALUE)) {
  432. char *str;
  433. DWORD pipe_mode = PIPE_READMODE_BYTE | PIPE_WAIT;
  434. HANDLE pipe = GetStdHandle(STD_INPUT_HANDLE);
  435. SetNamedPipeHandleState(pipe, &pipe_mode, NULL, NULL);
  436. str = getenv("_FCGI_SHUTDOWN_EVENT_");
  437. if (str != NULL) {
  438. zend_long ev = ZEND_ATOL(str);
  439. HANDLE shutdown_event = (HANDLE) ev;
  440. if (!CreateThread(NULL, 0, fcgi_shutdown_thread,
  441. shutdown_event, 0, NULL)) {
  442. return -1;
  443. }
  444. }
  445. str = getenv("_FCGI_MUTEX_");
  446. if (str != NULL) {
  447. fcgi_accept_mutex = (HANDLE) ZEND_ATOL(str);
  448. }
  449. return is_fastcgi = 1;
  450. } else {
  451. return is_fastcgi = 0;
  452. }
  453. #else
  454. errno = 0;
  455. if (getpeername(0, (struct sockaddr *)&sa, &len) != 0 && errno == ENOTCONN) {
  456. fcgi_setup_signals();
  457. return is_fastcgi = 1;
  458. } else {
  459. return is_fastcgi = 0;
  460. }
  461. #endif
  462. }
  463. return is_fastcgi;
  464. }
  465. int fcgi_is_fastcgi(void)
  466. {
  467. if (!is_initialized) {
  468. return fcgi_init();
  469. } else {
  470. return is_fastcgi;
  471. }
  472. }
  473. void fcgi_shutdown(void)
  474. {
  475. if (is_initialized) {
  476. zend_hash_destroy(&fcgi_mgmt_vars);
  477. }
  478. is_fastcgi = 0;
  479. if (allowed_clients) {
  480. free(allowed_clients);
  481. }
  482. }
  483. #ifdef _WIN32
  484. /* Do some black magic with the NT security API.
  485. * We prepare a DACL (Discretionary Access Control List) so that
  486. * we, the creator, are allowed all access, while "Everyone Else"
  487. * is only allowed to read and write to the pipe.
  488. * This avoids security issues on shared hosts where a luser messes
  489. * with the lower-level pipe settings and screws up the FastCGI service.
  490. */
  491. static PACL prepare_named_pipe_acl(PSECURITY_DESCRIPTOR sd, LPSECURITY_ATTRIBUTES sa)
  492. {
  493. DWORD req_acl_size;
  494. char everyone_buf[32], owner_buf[32];
  495. PSID sid_everyone, sid_owner;
  496. SID_IDENTIFIER_AUTHORITY
  497. siaWorld = SECURITY_WORLD_SID_AUTHORITY,
  498. siaCreator = SECURITY_CREATOR_SID_AUTHORITY;
  499. PACL acl;
  500. sid_everyone = (PSID)&everyone_buf;
  501. sid_owner = (PSID)&owner_buf;
  502. req_acl_size = sizeof(ACL) +
  503. (2 * ((sizeof(ACCESS_ALLOWED_ACE) - sizeof(DWORD)) + GetSidLengthRequired(1)));
  504. acl = malloc(req_acl_size);
  505. if (acl == NULL) {
  506. return NULL;
  507. }
  508. if (!InitializeSid(sid_everyone, &siaWorld, 1)) {
  509. goto out_fail;
  510. }
  511. *GetSidSubAuthority(sid_everyone, 0) = SECURITY_WORLD_RID;
  512. if (!InitializeSid(sid_owner, &siaCreator, 1)) {
  513. goto out_fail;
  514. }
  515. *GetSidSubAuthority(sid_owner, 0) = SECURITY_CREATOR_OWNER_RID;
  516. if (!InitializeAcl(acl, req_acl_size, ACL_REVISION)) {
  517. goto out_fail;
  518. }
  519. if (!AddAccessAllowedAce(acl, ACL_REVISION, FILE_GENERIC_READ | FILE_GENERIC_WRITE, sid_everyone)) {
  520. goto out_fail;
  521. }
  522. if (!AddAccessAllowedAce(acl, ACL_REVISION, FILE_ALL_ACCESS, sid_owner)) {
  523. goto out_fail;
  524. }
  525. if (!InitializeSecurityDescriptor(sd, SECURITY_DESCRIPTOR_REVISION)) {
  526. goto out_fail;
  527. }
  528. if (!SetSecurityDescriptorDacl(sd, TRUE, acl, FALSE)) {
  529. goto out_fail;
  530. }
  531. sa->lpSecurityDescriptor = sd;
  532. return acl;
  533. out_fail:
  534. free(acl);
  535. return NULL;
  536. }
  537. #endif
  538. static int is_port_number(const char *bindpath)
  539. {
  540. while (*bindpath) {
  541. if (*bindpath < '0' || *bindpath > '9') {
  542. return 0;
  543. }
  544. bindpath++;
  545. }
  546. return 1;
  547. }
  548. int fcgi_listen(const char *path, int backlog)
  549. {
  550. char *s;
  551. int tcp = 0;
  552. char host[MAXPATHLEN];
  553. short port = 0;
  554. int listen_socket;
  555. sa_t sa;
  556. socklen_t sock_len;
  557. #ifdef SO_REUSEADDR
  558. # ifdef _WIN32
  559. BOOL reuse = 1;
  560. # else
  561. int reuse = 1;
  562. # endif
  563. #endif
  564. if ((s = strchr(path, ':'))) {
  565. port = atoi(s+1);
  566. if (port != 0 && (s-path) < MAXPATHLEN) {
  567. strncpy(host, path, s-path);
  568. host[s-path] = '\0';
  569. tcp = 1;
  570. }
  571. } else if (is_port_number(path)) {
  572. port = atoi(path);
  573. if (port != 0) {
  574. host[0] = '\0';
  575. tcp = 1;
  576. }
  577. }
  578. /* Prepare socket address */
  579. if (tcp) {
  580. memset(&sa.sa_inet, 0, sizeof(sa.sa_inet));
  581. sa.sa_inet.sin_family = AF_INET;
  582. sa.sa_inet.sin_port = htons(port);
  583. sock_len = sizeof(sa.sa_inet);
  584. if (!*host || !strncmp(host, "*", sizeof("*")-1)) {
  585. sa.sa_inet.sin_addr.s_addr = htonl(INADDR_ANY);
  586. } else {
  587. #ifdef HAVE_INET_PTON
  588. if (!inet_pton(AF_INET, host, &sa.sa_inet.sin_addr)) {
  589. #else
  590. sa.sa_inet.sin_addr.s_addr = inet_addr(host);
  591. if (sa.sa_inet.sin_addr.s_addr == INADDR_NONE) {
  592. #endif
  593. struct hostent *hep;
  594. if(strlen(host) > MAXFQDNLEN) {
  595. hep = NULL;
  596. } else {
  597. hep = php_network_gethostbyname(host);
  598. }
  599. if (!hep || hep->h_addrtype != AF_INET || !hep->h_addr_list[0]) {
  600. fcgi_log(FCGI_ERROR, "Cannot resolve host name '%s'!\n", host);
  601. return -1;
  602. } else if (hep->h_addr_list[1]) {
  603. fcgi_log(FCGI_ERROR, "Host '%s' has multiple addresses. You must choose one explicitly!\n", host);
  604. return -1;
  605. }
  606. sa.sa_inet.sin_addr.s_addr = ((struct in_addr*)hep->h_addr_list[0])->s_addr;
  607. }
  608. }
  609. } else {
  610. #ifdef _WIN32
  611. SECURITY_DESCRIPTOR sd;
  612. SECURITY_ATTRIBUTES saw;
  613. PACL acl;
  614. HANDLE namedPipe;
  615. memset(&sa, 0, sizeof(saw));
  616. saw.nLength = sizeof(saw);
  617. saw.bInheritHandle = FALSE;
  618. acl = prepare_named_pipe_acl(&sd, &saw);
  619. namedPipe = CreateNamedPipe(path,
  620. PIPE_ACCESS_DUPLEX | FILE_FLAG_OVERLAPPED,
  621. PIPE_TYPE_BYTE | PIPE_WAIT | PIPE_READMODE_BYTE,
  622. PIPE_UNLIMITED_INSTANCES,
  623. 8192, 8192, 0, &saw);
  624. if (namedPipe == INVALID_HANDLE_VALUE) {
  625. return -1;
  626. }
  627. listen_socket = _open_osfhandle((intptr_t)namedPipe, 0);
  628. if (!is_initialized) {
  629. fcgi_init();
  630. }
  631. is_fastcgi = 1;
  632. return listen_socket;
  633. #else
  634. size_t path_len = strlen(path);
  635. if (path_len >= sizeof(sa.sa_unix.sun_path)) {
  636. fcgi_log(FCGI_ERROR, "Listening socket's path name is too long.\n");
  637. return -1;
  638. }
  639. memset(&sa.sa_unix, 0, sizeof(sa.sa_unix));
  640. sa.sa_unix.sun_family = AF_UNIX;
  641. memcpy(sa.sa_unix.sun_path, path, path_len + 1);
  642. sock_len = (size_t)(((struct sockaddr_un *)0)->sun_path) + path_len;
  643. #ifdef HAVE_SOCKADDR_UN_SUN_LEN
  644. sa.sa_unix.sun_len = sock_len;
  645. #endif
  646. unlink(path);
  647. #endif
  648. }
  649. /* Create, bind socket and start listen on it */
  650. if ((listen_socket = socket(sa.sa.sa_family, SOCK_STREAM, 0)) < 0 ||
  651. #ifdef SO_REUSEADDR
  652. setsockopt(listen_socket, SOL_SOCKET, SO_REUSEADDR, (char*)&reuse, sizeof(reuse)) < 0 ||
  653. #endif
  654. bind(listen_socket, (struct sockaddr *) &sa, sock_len) < 0 ||
  655. listen(listen_socket, backlog) < 0) {
  656. close(listen_socket);
  657. fcgi_log(FCGI_ERROR, "Cannot bind/listen socket - [%d] %s.\n",errno, strerror(errno));
  658. return -1;
  659. }
  660. if (!tcp) {
  661. chmod(path, 0777);
  662. } else {
  663. char *ip = getenv("FCGI_WEB_SERVER_ADDRS");
  664. char *cur, *end;
  665. int n;
  666. if (ip) {
  667. ip = strdup(ip);
  668. cur = ip;
  669. n = 0;
  670. while (*cur) {
  671. if (*cur == ',') n++;
  672. cur++;
  673. }
  674. allowed_clients = malloc(sizeof(sa_t) * (n+2));
  675. n = 0;
  676. cur = ip;
  677. while (cur) {
  678. end = strchr(cur, ',');
  679. if (end) {
  680. *end = 0;
  681. end++;
  682. }
  683. if (inet_pton(AF_INET, cur, &allowed_clients[n].sa_inet.sin_addr)>0) {
  684. allowed_clients[n].sa.sa_family = AF_INET;
  685. n++;
  686. #ifdef HAVE_IPV6
  687. } else if (inet_pton(AF_INET6, cur, &allowed_clients[n].sa_inet6.sin6_addr)>0) {
  688. allowed_clients[n].sa.sa_family = AF_INET6;
  689. n++;
  690. #endif
  691. } else {
  692. fcgi_log(FCGI_ERROR, "Wrong IP address '%s' in listen.allowed_clients", cur);
  693. }
  694. cur = end;
  695. }
  696. allowed_clients[n].sa.sa_family = 0;
  697. free(ip);
  698. if (!n) {
  699. fcgi_log(FCGI_ERROR, "There are no allowed addresses");
  700. /* don't clear allowed_clients as it will create an "open for all" security issue */
  701. }
  702. }
  703. }
  704. if (!is_initialized) {
  705. fcgi_init();
  706. }
  707. is_fastcgi = 1;
  708. #ifdef _WIN32
  709. if (tcp) {
  710. listen_socket = _open_osfhandle((intptr_t)listen_socket, 0);
  711. }
  712. #else
  713. fcgi_setup_signals();
  714. #endif
  715. return listen_socket;
  716. }
  717. void fcgi_set_allowed_clients(char *ip)
  718. {
  719. char *cur, *end;
  720. int n;
  721. if (ip) {
  722. ip = strdup(ip);
  723. cur = ip;
  724. n = 0;
  725. while (*cur) {
  726. if (*cur == ',') n++;
  727. cur++;
  728. }
  729. if (allowed_clients) free(allowed_clients);
  730. allowed_clients = malloc(sizeof(sa_t) * (n+2));
  731. n = 0;
  732. cur = ip;
  733. while (cur) {
  734. end = strchr(cur, ',');
  735. if (end) {
  736. *end = 0;
  737. end++;
  738. }
  739. if (inet_pton(AF_INET, cur, &allowed_clients[n].sa_inet.sin_addr)>0) {
  740. allowed_clients[n].sa.sa_family = AF_INET;
  741. n++;
  742. #ifdef HAVE_IPV6
  743. } else if (inet_pton(AF_INET6, cur, &allowed_clients[n].sa_inet6.sin6_addr)>0) {
  744. allowed_clients[n].sa.sa_family = AF_INET6;
  745. n++;
  746. #endif
  747. } else {
  748. fcgi_log(FCGI_ERROR, "Wrong IP address '%s' in listen.allowed_clients", cur);
  749. }
  750. cur = end;
  751. }
  752. allowed_clients[n].sa.sa_family = 0;
  753. free(ip);
  754. if (!n) {
  755. fcgi_log(FCGI_ERROR, "There are no allowed addresses");
  756. /* don't clear allowed_clients as it will create an "open for all" security issue */
  757. }
  758. }
  759. }
  760. static void fcgi_hook_dummy(void) {
  761. return;
  762. }
  763. fcgi_request *fcgi_init_request(int listen_socket, void(*on_accept)(void), void(*on_read)(void), void(*on_close)(void))
  764. {
  765. fcgi_request *req = calloc(1, sizeof(fcgi_request));
  766. req->listen_socket = listen_socket;
  767. req->fd = -1;
  768. req->id = -1;
  769. /*
  770. req->in_len = 0;
  771. req->in_pad = 0;
  772. req->out_hdr = NULL;
  773. #ifdef TCP_NODELAY
  774. req->nodelay = 0;
  775. #endif
  776. req->env = NULL;
  777. req->has_env = 0;
  778. */
  779. req->out_pos = req->out_buf;
  780. req->hook.on_accept = on_accept ? on_accept : fcgi_hook_dummy;
  781. req->hook.on_read = on_read ? on_read : fcgi_hook_dummy;
  782. req->hook.on_close = on_close ? on_close : fcgi_hook_dummy;
  783. #ifdef _WIN32
  784. req->tcp = !GetNamedPipeInfo((HANDLE)_get_osfhandle(req->listen_socket), NULL, NULL, NULL, NULL);
  785. #endif
  786. fcgi_hash_init(&req->env);
  787. return req;
  788. }
  789. void fcgi_destroy_request(fcgi_request *req) {
  790. fcgi_hash_destroy(&req->env);
  791. free(req);
  792. }
  793. static inline ssize_t safe_write(fcgi_request *req, const void *buf, size_t count)
  794. {
  795. int ret;
  796. size_t n = 0;
  797. do {
  798. #ifdef _WIN32
  799. size_t tmp;
  800. #endif
  801. errno = 0;
  802. #ifdef _WIN32
  803. tmp = count - n;
  804. if (!req->tcp) {
  805. unsigned int out_len = tmp > UINT_MAX ? UINT_MAX : (unsigned int)tmp;
  806. ret = write(req->fd, ((char*)buf)+n, out_len);
  807. } else {
  808. int out_len = tmp > INT_MAX ? INT_MAX : (int)tmp;
  809. ret = send(req->fd, ((char*)buf)+n, out_len, 0);
  810. if (ret <= 0) {
  811. errno = WSAGetLastError();
  812. }
  813. }
  814. #else
  815. ret = write(req->fd, ((char*)buf)+n, count-n);
  816. #endif
  817. if (ret > 0) {
  818. n += ret;
  819. } else if (ret <= 0 && errno != 0 && errno != EINTR) {
  820. return ret;
  821. }
  822. } while (n != count);
  823. return n;
  824. }
  825. static inline ssize_t safe_read(fcgi_request *req, const void *buf, size_t count)
  826. {
  827. int ret;
  828. size_t n = 0;
  829. do {
  830. #ifdef _WIN32
  831. size_t tmp;
  832. #endif
  833. errno = 0;
  834. #ifdef _WIN32
  835. tmp = count - n;
  836. if (!req->tcp) {
  837. unsigned int in_len = tmp > UINT_MAX ? UINT_MAX : (unsigned int)tmp;
  838. ret = read(req->fd, ((char*)buf)+n, in_len);
  839. } else {
  840. int in_len = tmp > INT_MAX ? INT_MAX : (int)tmp;
  841. ret = recv(req->fd, ((char*)buf)+n, in_len, 0);
  842. if (ret <= 0) {
  843. errno = WSAGetLastError();
  844. }
  845. }
  846. #else
  847. ret = read(req->fd, ((char*)buf)+n, count-n);
  848. #endif
  849. if (ret > 0) {
  850. n += ret;
  851. } else if (ret == 0 && errno == 0) {
  852. return n;
  853. } else if (ret <= 0 && errno != 0 && errno != EINTR) {
  854. return ret;
  855. }
  856. } while (n != count);
  857. return n;
  858. }
  859. static inline int fcgi_make_header(fcgi_header *hdr, fcgi_request_type type, int req_id, int len)
  860. {
  861. int pad = ((len + 7) & ~7) - len;
  862. hdr->contentLengthB0 = (unsigned char)(len & 0xff);
  863. hdr->contentLengthB1 = (unsigned char)((len >> 8) & 0xff);
  864. hdr->paddingLength = (unsigned char)pad;
  865. hdr->requestIdB0 = (unsigned char)(req_id & 0xff);
  866. hdr->requestIdB1 = (unsigned char)((req_id >> 8) & 0xff);
  867. hdr->reserved = 0;
  868. hdr->type = type;
  869. hdr->version = FCGI_VERSION_1;
  870. if (pad) {
  871. memset(((unsigned char*)hdr) + sizeof(fcgi_header) + len, 0, pad);
  872. }
  873. return pad;
  874. }
  875. static int fcgi_get_params(fcgi_request *req, unsigned char *p, unsigned char *end)
  876. {
  877. unsigned int name_len, val_len;
  878. while (p < end) {
  879. name_len = *p++;
  880. if (UNEXPECTED(name_len >= 128)) {
  881. if (UNEXPECTED(p + 3 >= end)) return 0;
  882. name_len = ((name_len & 0x7f) << 24);
  883. name_len |= (*p++ << 16);
  884. name_len |= (*p++ << 8);
  885. name_len |= *p++;
  886. }
  887. if (UNEXPECTED(p >= end)) return 0;
  888. val_len = *p++;
  889. if (UNEXPECTED(val_len >= 128)) {
  890. if (UNEXPECTED(p + 3 >= end)) return 0;
  891. val_len = ((val_len & 0x7f) << 24);
  892. val_len |= (*p++ << 16);
  893. val_len |= (*p++ << 8);
  894. val_len |= *p++;
  895. }
  896. if (UNEXPECTED(name_len + val_len > (unsigned int) (end - p))) {
  897. /* Malformed request */
  898. return 0;
  899. }
  900. fcgi_hash_set(&req->env, FCGI_HASH_FUNC(p, name_len), (char*)p, name_len, (char*)p + name_len, val_len);
  901. p += name_len + val_len;
  902. }
  903. return 1;
  904. }
  905. static int fcgi_read_request(fcgi_request *req)
  906. {
  907. fcgi_header hdr;
  908. int len, padding;
  909. unsigned char buf[FCGI_MAX_LENGTH+8];
  910. req->keep = 0;
  911. req->ended = 0;
  912. req->in_len = 0;
  913. req->out_hdr = NULL;
  914. req->out_pos = req->out_buf;
  915. if (req->has_env) {
  916. fcgi_hash_clean(&req->env);
  917. } else {
  918. req->has_env = 1;
  919. }
  920. if (safe_read(req, &hdr, sizeof(fcgi_header)) != sizeof(fcgi_header) ||
  921. hdr.version < FCGI_VERSION_1) {
  922. return 0;
  923. }
  924. len = (hdr.contentLengthB1 << 8) | hdr.contentLengthB0;
  925. padding = hdr.paddingLength;
  926. while (hdr.type == FCGI_STDIN && len == 0) {
  927. if (safe_read(req, &hdr, sizeof(fcgi_header)) != sizeof(fcgi_header) ||
  928. hdr.version < FCGI_VERSION_1) {
  929. return 0;
  930. }
  931. len = (hdr.contentLengthB1 << 8) | hdr.contentLengthB0;
  932. padding = hdr.paddingLength;
  933. }
  934. if (len + padding > FCGI_MAX_LENGTH) {
  935. return 0;
  936. }
  937. req->id = (hdr.requestIdB1 << 8) + hdr.requestIdB0;
  938. if (hdr.type == FCGI_BEGIN_REQUEST && len == sizeof(fcgi_begin_request)) {
  939. fcgi_begin_request *b;
  940. if (safe_read(req, buf, len+padding) != len+padding) {
  941. return 0;
  942. }
  943. b = (fcgi_begin_request*)buf;
  944. req->keep = (b->flags & FCGI_KEEP_CONN);
  945. #ifdef TCP_NODELAY
  946. if (req->keep && req->tcp && !req->nodelay) {
  947. # ifdef _WIN32
  948. BOOL on = 1;
  949. # else
  950. int on = 1;
  951. # endif
  952. setsockopt(req->fd, IPPROTO_TCP, TCP_NODELAY, (char*)&on, sizeof(on));
  953. req->nodelay = 1;
  954. }
  955. #endif
  956. switch ((b->roleB1 << 8) + b->roleB0) {
  957. case FCGI_RESPONDER:
  958. fcgi_hash_set(&req->env, FCGI_HASH_FUNC("FCGI_ROLE", sizeof("FCGI_ROLE")-1), "FCGI_ROLE", sizeof("FCGI_ROLE")-1, "RESPONDER", sizeof("RESPONDER")-1);
  959. break;
  960. case FCGI_AUTHORIZER:
  961. fcgi_hash_set(&req->env, FCGI_HASH_FUNC("FCGI_ROLE", sizeof("FCGI_ROLE")-1), "FCGI_ROLE", sizeof("FCGI_ROLE")-1, "AUTHORIZER", sizeof("AUTHORIZER")-1);
  962. break;
  963. case FCGI_FILTER:
  964. fcgi_hash_set(&req->env, FCGI_HASH_FUNC("FCGI_ROLE", sizeof("FCGI_ROLE")-1), "FCGI_ROLE", sizeof("FCGI_ROLE")-1, "FILTER", sizeof("FILTER")-1);
  965. break;
  966. default:
  967. return 0;
  968. }
  969. if (safe_read(req, &hdr, sizeof(fcgi_header)) != sizeof(fcgi_header) ||
  970. hdr.version < FCGI_VERSION_1) {
  971. return 0;
  972. }
  973. len = (hdr.contentLengthB1 << 8) | hdr.contentLengthB0;
  974. padding = hdr.paddingLength;
  975. while (hdr.type == FCGI_PARAMS && len > 0) {
  976. if (len + padding > FCGI_MAX_LENGTH) {
  977. return 0;
  978. }
  979. if (safe_read(req, buf, len+padding) != len+padding) {
  980. req->keep = 0;
  981. return 0;
  982. }
  983. if (!fcgi_get_params(req, buf, buf+len)) {
  984. req->keep = 0;
  985. return 0;
  986. }
  987. if (safe_read(req, &hdr, sizeof(fcgi_header)) != sizeof(fcgi_header) ||
  988. hdr.version < FCGI_VERSION_1) {
  989. req->keep = 0;
  990. return 0;
  991. }
  992. len = (hdr.contentLengthB1 << 8) | hdr.contentLengthB0;
  993. padding = hdr.paddingLength;
  994. }
  995. } else if (hdr.type == FCGI_GET_VALUES) {
  996. unsigned char *p = buf + sizeof(fcgi_header);
  997. zval *value;
  998. unsigned int zlen;
  999. fcgi_hash_bucket *q;
  1000. if (safe_read(req, buf, len+padding) != len+padding) {
  1001. req->keep = 0;
  1002. return 0;
  1003. }
  1004. if (!fcgi_get_params(req, buf, buf+len)) {
  1005. req->keep = 0;
  1006. return 0;
  1007. }
  1008. q = req->env.list;
  1009. while (q != NULL) {
  1010. if ((value = zend_hash_str_find(&fcgi_mgmt_vars, q->var, q->var_len)) == NULL) {
  1011. q = q->list_next;
  1012. continue;
  1013. }
  1014. zlen = (unsigned int)Z_STRLEN_P(value);
  1015. if ((p + 4 + 4 + q->var_len + zlen) >= (buf + sizeof(buf))) {
  1016. break;
  1017. }
  1018. if (q->var_len < 0x80) {
  1019. *p++ = q->var_len;
  1020. } else {
  1021. *p++ = ((q->var_len >> 24) & 0xff) | 0x80;
  1022. *p++ = (q->var_len >> 16) & 0xff;
  1023. *p++ = (q->var_len >> 8) & 0xff;
  1024. *p++ = q->var_len & 0xff;
  1025. }
  1026. if (zlen < 0x80) {
  1027. *p++ = zlen;
  1028. } else {
  1029. *p++ = ((zlen >> 24) & 0xff) | 0x80;
  1030. *p++ = (zlen >> 16) & 0xff;
  1031. *p++ = (zlen >> 8) & 0xff;
  1032. *p++ = zlen & 0xff;
  1033. }
  1034. memcpy(p, q->var, q->var_len);
  1035. p += q->var_len;
  1036. memcpy(p, Z_STRVAL_P(value), zlen);
  1037. p += zlen;
  1038. q = q->list_next;
  1039. }
  1040. len = (int)(p - buf - sizeof(fcgi_header));
  1041. len += fcgi_make_header((fcgi_header*)buf, FCGI_GET_VALUES_RESULT, 0, len);
  1042. if (safe_write(req, buf, sizeof(fcgi_header) + len) != (ssize_t)sizeof(fcgi_header)+len) {
  1043. req->keep = 0;
  1044. return 0;
  1045. }
  1046. return 0;
  1047. } else {
  1048. return 0;
  1049. }
  1050. return 1;
  1051. }
  1052. int fcgi_read(fcgi_request *req, char *str, int len)
  1053. {
  1054. int ret, n, rest;
  1055. fcgi_header hdr;
  1056. unsigned char buf[255];
  1057. n = 0;
  1058. rest = len;
  1059. while (rest > 0) {
  1060. if (req->in_len == 0) {
  1061. if (safe_read(req, &hdr, sizeof(fcgi_header)) != sizeof(fcgi_header) ||
  1062. hdr.version < FCGI_VERSION_1 ||
  1063. hdr.type != FCGI_STDIN) {
  1064. req->keep = 0;
  1065. return 0;
  1066. }
  1067. req->in_len = (hdr.contentLengthB1 << 8) | hdr.contentLengthB0;
  1068. req->in_pad = hdr.paddingLength;
  1069. if (req->in_len == 0) {
  1070. return n;
  1071. }
  1072. }
  1073. if (req->in_len >= rest) {
  1074. ret = (int)safe_read(req, str, rest);
  1075. } else {
  1076. ret = (int)safe_read(req, str, req->in_len);
  1077. }
  1078. if (ret < 0) {
  1079. req->keep = 0;
  1080. return ret;
  1081. } else if (ret > 0) {
  1082. req->in_len -= ret;
  1083. rest -= ret;
  1084. n += ret;
  1085. str += ret;
  1086. if (req->in_len == 0) {
  1087. if (req->in_pad) {
  1088. if (safe_read(req, buf, req->in_pad) != req->in_pad) {
  1089. req->keep = 0;
  1090. return ret;
  1091. }
  1092. }
  1093. } else {
  1094. return n;
  1095. }
  1096. } else {
  1097. return n;
  1098. }
  1099. }
  1100. return n;
  1101. }
  1102. void fcgi_close(fcgi_request *req, int force, int destroy)
  1103. {
  1104. if (destroy && req->has_env) {
  1105. fcgi_hash_clean(&req->env);
  1106. req->has_env = 0;
  1107. }
  1108. #ifdef _WIN32
  1109. if (is_impersonate && !req->tcp) {
  1110. RevertToSelf();
  1111. }
  1112. #endif
  1113. if ((force || !req->keep) && req->fd >= 0) {
  1114. #ifdef _WIN32
  1115. if (!req->tcp) {
  1116. HANDLE pipe = (HANDLE)_get_osfhandle(req->fd);
  1117. if (!force) {
  1118. FlushFileBuffers(pipe);
  1119. }
  1120. DisconnectNamedPipe(pipe);
  1121. } else {
  1122. if (!force) {
  1123. char buf[8];
  1124. shutdown(req->fd, 1);
  1125. /* read any remaining data, it may be omitted */
  1126. while (recv(req->fd, buf, sizeof(buf), 0) > 0) {}
  1127. }
  1128. closesocket(req->fd);
  1129. }
  1130. #else
  1131. if (!force) {
  1132. char buf[8];
  1133. shutdown(req->fd, 1);
  1134. /* read any remaining data, it may be omitted */
  1135. while (recv(req->fd, buf, sizeof(buf), 0) > 0) {}
  1136. }
  1137. close(req->fd);
  1138. #endif
  1139. #ifdef TCP_NODELAY
  1140. req->nodelay = 0;
  1141. #endif
  1142. req->fd = -1;
  1143. req->hook.on_close();
  1144. }
  1145. }
  1146. int fcgi_is_closed(fcgi_request *req)
  1147. {
  1148. return (req->fd < 0);
  1149. }
  1150. static int fcgi_is_allowed(void) {
  1151. int i;
  1152. if (client_sa.sa.sa_family == AF_UNIX) {
  1153. return 1;
  1154. }
  1155. if (!allowed_clients) {
  1156. return 1;
  1157. }
  1158. if (client_sa.sa.sa_family == AF_INET) {
  1159. for (i = 0; allowed_clients[i].sa.sa_family ; i++) {
  1160. if (allowed_clients[i].sa.sa_family == AF_INET
  1161. && !memcmp(&client_sa.sa_inet.sin_addr, &allowed_clients[i].sa_inet.sin_addr, 4)) {
  1162. return 1;
  1163. }
  1164. }
  1165. }
  1166. #ifdef HAVE_IPV6
  1167. if (client_sa.sa.sa_family == AF_INET6) {
  1168. for (i = 0; allowed_clients[i].sa.sa_family ; i++) {
  1169. if (allowed_clients[i].sa.sa_family == AF_INET6
  1170. && !memcmp(&client_sa.sa_inet6.sin6_addr, &allowed_clients[i].sa_inet6.sin6_addr, 12)) {
  1171. return 1;
  1172. }
  1173. #ifdef IN6_IS_ADDR_V4MAPPED
  1174. if (allowed_clients[i].sa.sa_family == AF_INET
  1175. && IN6_IS_ADDR_V4MAPPED(&client_sa.sa_inet6.sin6_addr)
  1176. && !memcmp(((char *)&client_sa.sa_inet6.sin6_addr)+12, &allowed_clients[i].sa_inet.sin_addr, 4)) {
  1177. return 1;
  1178. }
  1179. #endif
  1180. }
  1181. }
  1182. #endif
  1183. return 0;
  1184. }
  1185. int fcgi_accept_request(fcgi_request *req)
  1186. {
  1187. #ifdef _WIN32
  1188. HANDLE pipe;
  1189. OVERLAPPED ov;
  1190. #endif
  1191. while (1) {
  1192. if (req->fd < 0) {
  1193. while (1) {
  1194. if (in_shutdown) {
  1195. return -1;
  1196. }
  1197. req->hook.on_accept();
  1198. #ifdef _WIN32
  1199. if (!req->tcp) {
  1200. pipe = (HANDLE)_get_osfhandle(req->listen_socket);
  1201. FCGI_LOCK(req->listen_socket);
  1202. ov.hEvent = CreateEvent(NULL, TRUE, FALSE, NULL);
  1203. if (!ConnectNamedPipe(pipe, &ov)) {
  1204. errno = GetLastError();
  1205. if (errno == ERROR_IO_PENDING) {
  1206. while (WaitForSingleObject(ov.hEvent, 1000) == WAIT_TIMEOUT) {
  1207. if (in_shutdown) {
  1208. CloseHandle(ov.hEvent);
  1209. FCGI_UNLOCK(req->listen_socket);
  1210. return -1;
  1211. }
  1212. }
  1213. } else if (errno != ERROR_PIPE_CONNECTED) {
  1214. }
  1215. }
  1216. CloseHandle(ov.hEvent);
  1217. req->fd = req->listen_socket;
  1218. FCGI_UNLOCK(req->listen_socket);
  1219. } else {
  1220. SOCKET listen_socket = (SOCKET)_get_osfhandle(req->listen_socket);
  1221. #else
  1222. {
  1223. int listen_socket = req->listen_socket;
  1224. #endif
  1225. sa_t sa;
  1226. socklen_t len = sizeof(sa);
  1227. FCGI_LOCK(req->listen_socket);
  1228. req->fd = accept(listen_socket, (struct sockaddr *)&sa, &len);
  1229. FCGI_UNLOCK(req->listen_socket);
  1230. client_sa = sa;
  1231. if (req->fd >= 0 && !fcgi_is_allowed()) {
  1232. fcgi_log(FCGI_ERROR, "Connection disallowed: IP address '%s' has been dropped.", fcgi_get_last_client_ip());
  1233. closesocket(req->fd);
  1234. req->fd = -1;
  1235. continue;
  1236. }
  1237. }
  1238. #ifdef _WIN32
  1239. if (req->fd < 0 && (in_shutdown || errno != EINTR)) {
  1240. #else
  1241. if (req->fd < 0 && (in_shutdown || (errno != EINTR && errno != ECONNABORTED))) {
  1242. #endif
  1243. return -1;
  1244. }
  1245. #ifdef _WIN32
  1246. break;
  1247. #else
  1248. if (req->fd >= 0) {
  1249. #if defined(HAVE_POLL)
  1250. struct pollfd fds;
  1251. int ret;
  1252. fds.fd = req->fd;
  1253. fds.events = POLLIN;
  1254. fds.revents = 0;
  1255. do {
  1256. errno = 0;
  1257. ret = poll(&fds, 1, 5000);
  1258. } while (ret < 0 && errno == EINTR);
  1259. if (ret > 0 && (fds.revents & POLLIN)) {
  1260. break;
  1261. }
  1262. fcgi_close(req, 1, 0);
  1263. #else
  1264. if (req->fd < FD_SETSIZE) {
  1265. struct timeval tv = {5,0};
  1266. fd_set set;
  1267. int ret;
  1268. FD_ZERO(&set);
  1269. FD_SET(req->fd, &set);
  1270. do {
  1271. errno = 0;
  1272. ret = select(req->fd + 1, &set, NULL, NULL, &tv) >= 0;
  1273. } while (ret < 0 && errno == EINTR);
  1274. if (ret > 0 && FD_ISSET(req->fd, &set)) {
  1275. break;
  1276. }
  1277. fcgi_close(req, 1, 0);
  1278. } else {
  1279. fcgi_log(FCGI_ERROR, "Too many open file descriptors. FD_SETSIZE limit exceeded.");
  1280. fcgi_close(req, 1, 0);
  1281. }
  1282. #endif
  1283. }
  1284. #endif
  1285. }
  1286. } else if (in_shutdown) {
  1287. return -1;
  1288. }
  1289. req->hook.on_read();
  1290. if (fcgi_read_request(req)) {
  1291. #ifdef _WIN32
  1292. if (is_impersonate && !req->tcp) {
  1293. pipe = (HANDLE)_get_osfhandle(req->fd);
  1294. if (!ImpersonateNamedPipeClient(pipe)) {
  1295. fcgi_close(req, 1, 1);
  1296. continue;
  1297. }
  1298. }
  1299. #endif
  1300. return req->fd;
  1301. } else {
  1302. fcgi_close(req, 1, 1);
  1303. }
  1304. }
  1305. }
  1306. static inline fcgi_header* open_packet(fcgi_request *req, fcgi_request_type type)
  1307. {
  1308. req->out_hdr = (fcgi_header*) req->out_pos;
  1309. req->out_hdr->type = type;
  1310. req->out_pos += sizeof(fcgi_header);
  1311. return req->out_hdr;
  1312. }
  1313. static inline void close_packet(fcgi_request *req)
  1314. {
  1315. if (req->out_hdr) {
  1316. int len = (int)(req->out_pos - ((unsigned char*)req->out_hdr + sizeof(fcgi_header)));
  1317. req->out_pos += fcgi_make_header(req->out_hdr, (fcgi_request_type)req->out_hdr->type, req->id, len);
  1318. req->out_hdr = NULL;
  1319. }
  1320. }
  1321. int fcgi_flush(fcgi_request *req, int end)
  1322. {
  1323. int len;
  1324. close_packet(req);
  1325. len = (int)(req->out_pos - req->out_buf);
  1326. if (end) {
  1327. fcgi_end_request_rec *rec = (fcgi_end_request_rec*)(req->out_pos);
  1328. fcgi_make_header(&rec->hdr, FCGI_END_REQUEST, req->id, sizeof(fcgi_end_request));
  1329. rec->body.appStatusB3 = 0;
  1330. rec->body.appStatusB2 = 0;
  1331. rec->body.appStatusB1 = 0;
  1332. rec->body.appStatusB0 = 0;
  1333. rec->body.protocolStatus = FCGI_REQUEST_COMPLETE;
  1334. len += sizeof(fcgi_end_request_rec);
  1335. }
  1336. if (safe_write(req, req->out_buf, len) != len) {
  1337. req->keep = 0;
  1338. req->out_pos = req->out_buf;
  1339. return 0;
  1340. }
  1341. req->out_pos = req->out_buf;
  1342. return 1;
  1343. }
  1344. int fcgi_write(fcgi_request *req, fcgi_request_type type, const char *str, int len)
  1345. {
  1346. int limit, rest;
  1347. if (len <= 0) {
  1348. return 0;
  1349. }
  1350. if (req->out_hdr && req->out_hdr->type != type) {
  1351. close_packet(req);
  1352. }
  1353. #if 0
  1354. /* Unoptimized, but clear version */
  1355. rest = len;
  1356. while (rest > 0) {
  1357. limit = sizeof(req->out_buf) - (req->out_pos - req->out_buf);
  1358. if (!req->out_hdr) {
  1359. if (limit < sizeof(fcgi_header)) {
  1360. if (!fcgi_flush(req, 0)) {
  1361. return -1;
  1362. }
  1363. }
  1364. open_packet(req, type);
  1365. }
  1366. limit = sizeof(req->out_buf) - (req->out_pos - req->out_buf);
  1367. if (rest < limit) {
  1368. memcpy(req->out_pos, str, rest);
  1369. req->out_pos += rest;
  1370. return len;
  1371. } else {
  1372. memcpy(req->out_pos, str, limit);
  1373. req->out_pos += limit;
  1374. rest -= limit;
  1375. str += limit;
  1376. if (!fcgi_flush(req, 0)) {
  1377. return -1;
  1378. }
  1379. }
  1380. }
  1381. #else
  1382. /* Optimized version */
  1383. limit = (int)(sizeof(req->out_buf) - (req->out_pos - req->out_buf));
  1384. if (!req->out_hdr) {
  1385. limit -= sizeof(fcgi_header);
  1386. if (limit < 0) limit = 0;
  1387. }
  1388. if (len < limit) {
  1389. if (!req->out_hdr) {
  1390. open_packet(req, type);
  1391. }
  1392. memcpy(req->out_pos, str, len);
  1393. req->out_pos += len;
  1394. } else if (len - limit < (int)(sizeof(req->out_buf) - sizeof(fcgi_header))) {
  1395. if (limit > 0) {
  1396. if (!req->out_hdr) {
  1397. open_packet(req, type);
  1398. }
  1399. memcpy(req->out_pos, str, limit);
  1400. req->out_pos += limit;
  1401. }
  1402. if (!fcgi_flush(req, 0)) {
  1403. return -1;
  1404. }
  1405. if (len > limit) {
  1406. open_packet(req, type);
  1407. memcpy(req->out_pos, str + limit, len - limit);
  1408. req->out_pos += len - limit;
  1409. }
  1410. } else {
  1411. int pos = 0;
  1412. int pad;
  1413. close_packet(req);
  1414. while ((len - pos) > 0xffff) {
  1415. open_packet(req, type);
  1416. fcgi_make_header(req->out_hdr, type, req->id, 0xfff8);
  1417. req->out_hdr = NULL;
  1418. if (!fcgi_flush(req, 0)) {
  1419. return -1;
  1420. }
  1421. if (safe_write(req, str + pos, 0xfff8) != 0xfff8) {
  1422. req->keep = 0;
  1423. return -1;
  1424. }
  1425. pos += 0xfff8;
  1426. }
  1427. pad = (((len - pos) + 7) & ~7) - (len - pos);
  1428. rest = pad ? 8 - pad : 0;
  1429. open_packet(req, type);
  1430. fcgi_make_header(req->out_hdr, type, req->id, (len - pos) - rest);
  1431. req->out_hdr = NULL;
  1432. if (!fcgi_flush(req, 0)) {
  1433. return -1;
  1434. }
  1435. if (safe_write(req, str + pos, (len - pos) - rest) != (len - pos) - rest) {
  1436. req->keep = 0;
  1437. return -1;
  1438. }
  1439. if (pad) {
  1440. open_packet(req, type);
  1441. memcpy(req->out_pos, str + len - rest, rest);
  1442. req->out_pos += rest;
  1443. }
  1444. }
  1445. #endif
  1446. return len;
  1447. }
  1448. int fcgi_end(fcgi_request *req) {
  1449. int ret = 1;
  1450. if (!req->ended) {
  1451. ret = fcgi_flush(req, 1);
  1452. req->ended = 1;
  1453. }
  1454. return ret;
  1455. }
  1456. int fcgi_finish_request(fcgi_request *req, int force_close)
  1457. {
  1458. int ret = 1;
  1459. if (req->fd >= 0) {
  1460. ret = fcgi_end(req);
  1461. fcgi_close(req, force_close, 1);
  1462. }
  1463. return ret;
  1464. }
  1465. int fcgi_has_env(fcgi_request *req)
  1466. {
  1467. return req && req->has_env;
  1468. }
  1469. char* fcgi_getenv(fcgi_request *req, const char* var, int var_len)
  1470. {
  1471. unsigned int val_len;
  1472. if (!req) return NULL;
  1473. return fcgi_hash_get(&req->env, FCGI_HASH_FUNC(var, var_len), (char*)var, var_len, &val_len);
  1474. }
  1475. char* fcgi_quick_getenv(fcgi_request *req, const char* var, int var_len, unsigned int hash_value)
  1476. {
  1477. unsigned int val_len;
  1478. return fcgi_hash_get(&req->env, hash_value, (char*)var, var_len, &val_len);
  1479. }
  1480. char* fcgi_putenv(fcgi_request *req, char* var, int var_len, char* val)
  1481. {
  1482. if (!req) return NULL;
  1483. if (val == NULL) {
  1484. fcgi_hash_del(&req->env, FCGI_HASH_FUNC(var, var_len), var, var_len);
  1485. return NULL;
  1486. } else {
  1487. return fcgi_hash_set(&req->env, FCGI_HASH_FUNC(var, var_len), var, var_len, val, (unsigned int)strlen(val));
  1488. }
  1489. }
  1490. char* fcgi_quick_putenv(fcgi_request *req, char* var, int var_len, unsigned int hash_value, char* val)
  1491. {
  1492. if (val == NULL) {
  1493. fcgi_hash_del(&req->env, hash_value, var, var_len);
  1494. return NULL;
  1495. } else {
  1496. return fcgi_hash_set(&req->env, hash_value, var, var_len, val, (unsigned int)strlen(val));
  1497. }
  1498. }
  1499. void fcgi_loadenv(fcgi_request *req, fcgi_apply_func func, zval *array)
  1500. {
  1501. fcgi_hash_apply(&req->env, func, array);
  1502. }
  1503. #ifdef _WIN32
  1504. void fcgi_impersonate(void)
  1505. {
  1506. char *os_name;
  1507. os_name = getenv("OS");
  1508. if (os_name && stricmp(os_name, "Windows_NT") == 0) {
  1509. is_impersonate = 1;
  1510. }
  1511. }
  1512. #endif
  1513. void fcgi_set_mgmt_var(const char * name, size_t name_len, const char * value, size_t value_len)
  1514. {
  1515. zval zvalue;
  1516. zend_string *key = zend_string_init(name, name_len, 1);
  1517. ZVAL_NEW_STR(&zvalue, zend_string_init(value, value_len, 1));
  1518. GC_MAKE_PERSISTENT_LOCAL(key);
  1519. GC_MAKE_PERSISTENT_LOCAL(Z_STR(zvalue));
  1520. zend_hash_add(&fcgi_mgmt_vars, key, &zvalue);
  1521. zend_string_release_ex(key, 1);
  1522. }
  1523. void fcgi_free_mgmt_var_cb(zval *zv)
  1524. {
  1525. pefree(Z_STR_P(zv), 1);
  1526. }
  1527. const char *fcgi_get_last_client_ip()
  1528. {
  1529. static char str[INET6_ADDRSTRLEN];
  1530. /* Ipv4 */
  1531. if (client_sa.sa.sa_family == AF_INET) {
  1532. return inet_ntop(client_sa.sa.sa_family, &client_sa.sa_inet.sin_addr, str, INET6_ADDRSTRLEN);
  1533. }
  1534. #ifdef HAVE_IPV6
  1535. #ifdef IN6_IS_ADDR_V4MAPPED
  1536. /* Ipv4-Mapped-Ipv6 */
  1537. if (client_sa.sa.sa_family == AF_INET6
  1538. && IN6_IS_ADDR_V4MAPPED(&client_sa.sa_inet6.sin6_addr)) {
  1539. return inet_ntop(AF_INET, ((char *)&client_sa.sa_inet6.sin6_addr)+12, str, INET6_ADDRSTRLEN);
  1540. }
  1541. #endif
  1542. /* Ipv6 */
  1543. if (client_sa.sa.sa_family == AF_INET6) {
  1544. return inet_ntop(client_sa.sa.sa_family, &client_sa.sa_inet6.sin6_addr, str, INET6_ADDRSTRLEN);
  1545. }
  1546. #endif
  1547. /* Unix socket */
  1548. return NULL;
  1549. }