daemon.c 18.6 KB
Newer Older
1 2
#include <signal.h>
#include <sys/wait.h>
3
#include <sys/socket.h>
J
Jason Riedy 已提交
4
#include <sys/time.h>
P
Peter Anvin 已提交
5
#include <sys/poll.h>
6
#include <netdb.h>
7
#include <netinet/in.h>
P
Petr Baudis 已提交
8
#include <arpa/inet.h>
9
#include <syslog.h>
10 11
#include <pwd.h>
#include <grp.h>
12 13
#include "pkt-line.h"
#include "cache.h"
14
#include "exec_cmd.h"
P
Petr Baudis 已提交
15

16
static int log_syslog;
P
Petr Baudis 已提交
17
static int verbose;
18
static int reuseaddr;
P
Petr Baudis 已提交
19

20 21
static const char daemon_usage[] =
"git-daemon [--verbose] [--syslog] [--inetd | --port=n] [--export-all]\n"
P
Petr Baudis 已提交
22
"           [--timeout=n] [--init-timeout=n] [--strict-paths]\n"
23
"           [--base-path=path] [--user-path | --user-path=path]\n"
24 25
"           [--reuseaddr] [--detach] [--pid-file=file]\n"
"           [--user=user [[--group=group]] [directory...]";
26 27

/* List of acceptable pathname prefixes */
28 29
static char **ok_paths;
static int strict_paths;
30 31

/* If this is set, git-daemon-export-ok is not required */
32
static int export_all_trees;
P
Petr Baudis 已提交
33

P
Petr Baudis 已提交
34
/* Take all paths relative to this one if non-NULL */
35
static char *base_path;
P
Petr Baudis 已提交
36

37 38 39 40
/* If defined, ~user notation is allowed and the string is inserted
 * after ~user/.  E.g. a request to git://host/~alice/frotz would
 * go to /home/alice/pub_git/frotz with --user-path=pub_git.
 */
41
static const char *user_path;
42

43
/* Timeout, and initial timeout */
44 45
static unsigned int timeout;
static unsigned int init_timeout;
P
Petr Baudis 已提交
46

47
static void logreport(int priority, const char *err, va_list params)
P
Petr Baudis 已提交
48 49 50 51 52 53 54 55
{
	/* We should do a single write so that it is atomic and output
	 * of several processes do not get intermingled. */
	char buf[1024];
	int buflen;
	int maxlen, msglen;

	/* sizeof(buf) should be big enough for "[pid] \n" */
J
Junio C Hamano 已提交
56
	buflen = snprintf(buf, sizeof(buf), "[%ld] ", (long) getpid());
P
Petr Baudis 已提交
57 58 59 60

	maxlen = sizeof(buf) - buflen - 1; /* -1 for our own LF */
	msglen = vsnprintf(buf + buflen, maxlen, err, params);

61 62 63 64 65
	if (log_syslog) {
		syslog(priority, "%s", buf);
		return;
	}

P
Petr Baudis 已提交
66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82
	/* maxlen counted our own LF but also counts space given to
	 * vsnprintf for the terminating NUL.  We want to make sure that
	 * we have space for our own LF and NUL after the "meat" of the
	 * message, so truncate it at maxlen - 1.
	 */
	if (msglen > maxlen - 1)
		msglen = maxlen - 1;
	else if (msglen < 0)
		msglen = 0; /* Protect against weird return values. */
	buflen += msglen;

	buf[buflen++] = '\n';
	buf[buflen] = '\0';

	write(2, buf, buflen);
}

83
static void logerror(const char *err, ...)
P
Petr Baudis 已提交
84 85 86
{
	va_list params;
	va_start(params, err);
87
	logreport(LOG_ERR, err, params);
P
Petr Baudis 已提交
88 89 90
	va_end(params);
}

91
static void loginfo(const char *err, ...)
P
Petr Baudis 已提交
92 93 94 95 96
{
	va_list params;
	if (!verbose)
		return;
	va_start(params, err);
97
	logreport(LOG_INFO, err, params);
P
Petr Baudis 已提交
98 99
	va_end(params);
}
100

101 102 103 104 105 106
static void NORETURN daemon_die(const char *err, va_list params)
{
	logreport(LOG_ERR, err, params);
	exit(1);
}

107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153
static int avoid_alias(char *p)
{
	int sl, ndot;

	/* 
	 * This resurrects the belts and suspenders paranoia check by HPA
	 * done in <435560F7.4080006@zytor.com> thread, now enter_repo()
	 * does not do getcwd() based path canonicalizations.
	 *
	 * sl becomes true immediately after seeing '/' and continues to
	 * be true as long as dots continue after that without intervening
	 * non-dot character.
	 */
	if (!p || (*p != '/' && *p != '~'))
		return -1;
	sl = 1; ndot = 0;
	p++;

	while (1) {
		char ch = *p++;
		if (sl) {
			if (ch == '.')
				ndot++;
			else if (ch == '/') {
				if (ndot < 3)
					/* reject //, /./ and /../ */
					return -1;
				ndot = 0;
			}
			else if (ch == 0) {
				if (0 < ndot && ndot < 3)
					/* reject /.$ and /..$ */
					return -1;
				return 0;
			}
			else
				sl = ndot = 0;
		}
		else if (ch == 0)
			return 0;
		else if (ch == '/') {
			sl = 1;
			ndot = 0;
		}
	}
}

154
static char *path_ok(char *dir)
155
{
156
	static char rpath[PATH_MAX];
157 158 159 160 161 162 163
	char *path;

	if (avoid_alias(dir)) {
		logerror("'%s': aliased", dir);
		return NULL;
	}

164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188
	if (*dir == '~') {
		if (!user_path) {
			logerror("'%s': User-path not allowed", dir);
			return NULL;
		}
		if (*user_path) {
			/* Got either "~alice" or "~alice/foo";
			 * rewrite them to "~alice/%s" or
			 * "~alice/%s/foo".
			 */
			int namlen, restlen = strlen(dir);
			char *slash = strchr(dir, '/');
			if (!slash)
				slash = dir + restlen;
			namlen = slash - dir;
			restlen -= namlen;
			loginfo("userpath <%s>, request <%s>, namlen %d, restlen %d, slash <%s>", user_path, dir, namlen, restlen, slash);
			snprintf(rpath, PATH_MAX, "%.*s/%s%.*s",
				 namlen, dir, user_path, restlen, slash);
			dir = rpath;
		}
	}
	else if (base_path) {
		if (*dir != '/') {
			/* Allow only absolute */
189
			logerror("'%s': Non-absolute path denied (base-path active)", dir);
P
Petr Baudis 已提交
190 191
			return NULL;
		}
192 193 194 195
		else {
			snprintf(rpath, PATH_MAX, "%s%s", base_path, dir);
			dir = rpath;
		}
P
Petr Baudis 已提交
196 197
	}

198
	path = enter_repo(dir, strict_paths);
199

200 201 202
	if (!path) {
		logerror("'%s': unable to chdir or not a git archive", dir);
		return NULL;
203 204 205
	}

	if ( ok_paths && *ok_paths ) {
J
Junio C Hamano 已提交
206
		char **pp;
207
		int pathlen = strlen(path);
208

J
Junio C Hamano 已提交
209
		/* The validation is done on the paths after enter_repo
210 211 212 213 214
		 * appends optional {.git,.git/.git} and friends, but 
		 * it does not use getcwd().  So if your /pub is
		 * a symlink to /mnt/pub, you can whitelist /pub and
		 * do not have to say /mnt/pub.
		 * Do not say /pub/.
J
Junio C Hamano 已提交
215
		 */
216 217
		for ( pp = ok_paths ; *pp ; pp++ ) {
			int len = strlen(*pp);
J
Junio C Hamano 已提交
218 219 220 221 222
			if (len <= pathlen &&
			    !memcmp(*pp, path, len) &&
			    (path[len] == '\0' ||
			     (!strict_paths && path[len] == '/')))
				return path;
223
		}
224 225 226 227 228
	}
	else {
		/* be backwards compatible */
		if (!strict_paths)
			return path;
229 230
	}

231 232
	logerror("'%s': not in whitelist", path);
	return NULL;		/* Fallthrough. Deny by default */
233
}
234

235
static int upload(char *dir)
236
{
237 238 239 240 241
	/* Timeout as string */
	char timeout_buf[64];
	const char *path;

	loginfo("Request for '%s'", dir);
242

243
	if (!(path = path_ok(dir)))
244
		return -1;
H
H. Peter Anvin 已提交
245

246 247 248
	/*
	 * Security on the cheap.
	 *
249
	 * We want a readable HEAD, usable "objects" directory, and
250 251
	 * a "git-daemon-export-ok" flag that says that the other side
	 * is ok with us doing this.
252 253 254
	 *
	 * path_ok() uses enter_repo() and does whitelist checking.
	 * We only need to make sure the repository is exported.
255
	 */
256

257
	if (!export_all_trees && access("git-daemon-export-ok", F_OK)) {
258
		logerror("'%s': repository not exported.", path);
259 260 261 262
		errno = EACCES;
		return -1;
	}

263 264 265 266 267 268
	/*
	 * We'll ignore SIGTERM from now on, we have a
	 * good client.
	 */
	signal(SIGTERM, SIG_IGN);

269 270
	snprintf(timeout_buf, sizeof timeout_buf, "--timeout=%u", timeout);

271
	/* git-upload-pack only ever reads stuff, so this is safe */
272
	execl_git_cmd("upload-pack", "--strict", timeout_buf, ".", NULL);
273 274 275
	return -1;
}

276
static int execute(struct sockaddr *addr)
277
{
278
	static char line[1000];
279
	int pktlen, len;
280

281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303
	if (addr) {
		char addrbuf[256] = "";
		int port = -1;

		if (addr->sa_family == AF_INET) {
			struct sockaddr_in *sin_addr = (void *) addr;
			inet_ntop(addr->sa_family, &sin_addr->sin_addr, addrbuf, sizeof(addrbuf));
			port = sin_addr->sin_port;
#ifndef NO_IPV6
		} else if (addr && addr->sa_family == AF_INET6) {
			struct sockaddr_in6 *sin6_addr = (void *) addr;

			char *buf = addrbuf;
			*buf++ = '['; *buf = '\0'; /* stpcpy() is cool */
			inet_ntop(AF_INET6, &sin6_addr->sin6_addr, buf, sizeof(addrbuf) - 1);
			strcat(buf, "]");

			port = sin6_addr->sin6_port;
#endif
		}
		loginfo("Connection from %s:%d", addrbuf, port);
	}

304
	alarm(init_timeout ? init_timeout : timeout);
305
	pktlen = packet_read_line(0, line, sizeof(line));
306
	alarm(0);
307

308 309 310 311 312
	len = strlen(line);
	if (pktlen != len)
		loginfo("Extended attributes (%d bytes) exist <%.*s>",
			(int) pktlen - len,
			(int) pktlen - len, line + len + 1);
313 314 315
	if (len && line[len-1] == '\n')
		line[--len] = 0;

316
	if (!strncmp("git-upload-pack ", line, 16))
317
		return upload(line+16);
318

P
Petr Baudis 已提交
319
	logerror("Protocol error: '%s'", line);
320 321 322
	return -1;
}

323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338

/*
 * We count spawned/reaped separately, just to avoid any
 * races when updating them from signals. The SIGCHLD handler
 * will only update children_reaped, and the fork logic will
 * only update children_spawned.
 *
 * MAX_CHILDREN should be a power-of-two to make the modulus
 * operation cheap. It should also be at least twice
 * the maximum number of connections we will ever allow.
 */
#define MAX_CHILDREN 128

static int max_connections = 25;

/* These are updated by the signal handler */
339
static volatile unsigned int children_reaped;
L
Linus Torvalds 已提交
340
static pid_t dead_child[MAX_CHILDREN];
341 342

/* These are updated by the main loop */
343 344
static unsigned int children_spawned;
static unsigned int children_deleted;
345

L
Linus Torvalds 已提交
346
static struct child {
347
	pid_t pid;
J
Junio C Hamano 已提交
348
	int addrlen;
349
	struct sockaddr_storage address;
350 351
} live_child[MAX_CHILDREN];

J
Junio C Hamano 已提交
352
static void add_child(int idx, pid_t pid, struct sockaddr *addr, int addrlen)
353 354 355
{
	live_child[idx].pid = pid;
	live_child[idx].addrlen = addrlen;
356
	memcpy(&live_child[idx].address, addr, addrlen);
357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402
}

/*
 * Walk from "deleted" to "spawned", and remove child "pid".
 *
 * We move everything up by one, since the new "deleted" will
 * be one higher.
 */
static void remove_child(pid_t pid, unsigned deleted, unsigned spawned)
{
	struct child n;

	deleted %= MAX_CHILDREN;
	spawned %= MAX_CHILDREN;
	if (live_child[deleted].pid == pid) {
		live_child[deleted].pid = -1;
		return;
	}
	n = live_child[deleted];
	for (;;) {
		struct child m;
		deleted = (deleted + 1) % MAX_CHILDREN;
		if (deleted == spawned)
			die("could not find dead child %d\n", pid);
		m = live_child[deleted];
		live_child[deleted] = n;
		if (m.pid == pid)
			return;
		n = m;
	}
}

/*
 * This gets called if the number of connections grows
 * past "max_connections".
 *
 * We _should_ start off by searching for connections
 * from the same IP, and if there is some address wth
 * multiple connections, we should kill that first.
 *
 * As it is, we just "randomly" kill 25% of the connections,
 * and our pseudo-random generator sucks too. I have no
 * shame.
 *
 * Really, this is just a place-holder for a _real_ algorithm.
 */
403
static void kill_some_children(int signo, unsigned start, unsigned stop)
404 405 406 407 408
{
	start %= MAX_CHILDREN;
	stop %= MAX_CHILDREN;
	while (start != stop) {
		if (!(start & 3))
409
			kill(live_child[start].pid, signo);
410 411 412 413
		start = (start + 1) % MAX_CHILDREN;
	}
}

414
static void check_max_connections(void)
415
{
416
	for (;;) {
417
		int active;
418
		unsigned spawned, reaped, deleted;
419

420 421 422 423 424 425 426 427 428 429 430 431
		spawned = children_spawned;
		reaped = children_reaped;
		deleted = children_deleted;

		while (deleted < reaped) {
			pid_t pid = dead_child[deleted % MAX_CHILDREN];
			remove_child(pid, deleted, spawned);
			deleted++;
		}
		children_deleted = deleted;

		active = spawned - deleted;
432 433
		if (active <= max_connections)
			break;
434

435 436 437 438 439 440 441 442 443 444 445
		/* Kill some unstarted connections with SIGTERM */
		kill_some_children(SIGTERM, deleted, spawned);
		if (active <= max_connections << 1)
			break;

		/* If the SIGTERM thing isn't helping use SIGKILL */
		kill_some_children(SIGKILL, deleted, spawned);
		sleep(1);
	}
}

J
Junio C Hamano 已提交
446
static void handle(int incoming, struct sockaddr *addr, int addrlen)
447 448 449 450 451 452 453 454 455 456 457 458 459
{
	pid_t pid = fork();

	if (pid) {
		unsigned idx;

		close(incoming);
		if (pid < 0)
			return;

		idx = children_spawned % MAX_CHILDREN;
		children_spawned++;
		add_child(idx, pid, addr, addrlen);
460

461
		check_max_connections();
462 463 464 465 466 467
		return;
	}

	dup2(incoming, 0);
	dup2(incoming, 1);
	close(incoming);
P
Petr Baudis 已提交
468

469
	exit(execute(addr));
470 471
}

472 473 474
static void child_handler(int signo)
{
	for (;;) {
475 476
		int status;
		pid_t pid = waitpid(-1, &status, WNOHANG);
477 478 479 480 481

		if (pid > 0) {
			unsigned reaped = children_reaped;
			dead_child[reaped % MAX_CHILDREN] = pid;
			children_reaped = reaped + 1;
P
Petr Baudis 已提交
482
			/* XXX: Custom logging, since we don't wanna getpid() */
483
			if (verbose) {
T
Timo Hirvonen 已提交
484
				const char *dead = "";
485 486 487 488 489 490 491
				if (!WIFEXITED(status) || WEXITSTATUS(status) > 0)
					dead = " (with error)";
				if (log_syslog)
					syslog(LOG_INFO, "[%d] Disconnected%s", pid, dead);
				else
					fprintf(stderr, "[%d] Disconnected%s\n", pid, dead);
			}
492 493 494 495 496 497
			continue;
		}
		break;
	}
}

498 499 500 501 502 503 504 505 506 507
static int set_reuse_addr(int sockfd)
{
	int on = 1;

	if (!reuseaddr)
		return 0;
	return setsockopt(sockfd, SOL_SOCKET, SO_REUSEADDR,
			  &on, sizeof(on));
}

P
Peter Anvin 已提交
508 509 510
#ifndef NO_IPV6

static int socksetup(int port, int **socklist_p)
511
{
512 513 514
	int socknum = 0, *socklist = NULL;
	int maxfd = -1;
	char pbuf[NI_MAXSERV];
515

P
Peter Anvin 已提交
516 517
	struct addrinfo hints, *ai0, *ai;
	int gai;
518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550

	sprintf(pbuf, "%d", port);
	memset(&hints, 0, sizeof(hints));
	hints.ai_family = AF_UNSPEC;
	hints.ai_socktype = SOCK_STREAM;
	hints.ai_protocol = IPPROTO_TCP;
	hints.ai_flags = AI_PASSIVE;

	gai = getaddrinfo(NULL, pbuf, &hints, &ai0);
	if (gai)
		die("getaddrinfo() failed: %s\n", gai_strerror(gai));

	for (ai = ai0; ai; ai = ai->ai_next) {
		int sockfd;

		sockfd = socket(ai->ai_family, ai->ai_socktype, ai->ai_protocol);
		if (sockfd < 0)
			continue;
		if (sockfd >= FD_SETSIZE) {
			error("too large socket descriptor.");
			close(sockfd);
			continue;
		}

#ifdef IPV6_V6ONLY
		if (ai->ai_family == AF_INET6) {
			int on = 1;
			setsockopt(sockfd, IPPROTO_IPV6, IPV6_V6ONLY,
				   &on, sizeof(on));
			/* Note: error is not fatal */
		}
#endif

551 552
		if (set_reuse_addr(sockfd)) {
			close(sockfd);
553
			continue;
554 555
		}

556 557 558 559 560 561 562 563 564
		if (bind(sockfd, ai->ai_addr, ai->ai_addrlen) < 0) {
			close(sockfd);
			continue;	/* not fatal */
		}
		if (listen(sockfd, 5) < 0) {
			close(sockfd);
			continue;	/* not fatal */
		}

J
Jonas Fonseca 已提交
565
		socklist = xrealloc(socklist, sizeof(int) * (socknum + 1));
566 567 568 569 570 571 572 573
		socklist[socknum++] = sockfd;

		if (maxfd < sockfd)
			maxfd = sockfd;
	}

	freeaddrinfo(ai0);

P
Peter Anvin 已提交
574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593
	*socklist_p = socklist;
	return socknum;
}

#else /* NO_IPV6 */

static int socksetup(int port, int **socklist_p)
{
	struct sockaddr_in sin;
	int sockfd;

	sockfd = socket(AF_INET, SOCK_STREAM, 0);
	if (sockfd < 0)
		return 0;

	memset(&sin, 0, sizeof sin);
	sin.sin_family = AF_INET;
	sin.sin_addr.s_addr = htonl(INADDR_ANY);
	sin.sin_port = htons(port);

594 595 596 597 598
	if (set_reuse_addr(sockfd)) {
		close(sockfd);
		return 0;
	}

P
Peter Anvin 已提交
599 600 601 602
	if ( bind(sockfd, (struct sockaddr *)&sin, sizeof sin) < 0 ) {
		close(sockfd);
		return 0;
	}
603

604 605 606 607 608
	if (listen(sockfd, 5) < 0) {
		close(sockfd);
		return 0;
	}

H
H. Peter Anvin 已提交
609
	*socklist_p = xmalloc(sizeof(int));
P
Peter Anvin 已提交
610
	**socklist_p = sockfd;
611
	return 1;
P
Peter Anvin 已提交
612 613 614 615 616 617 618 619 620
}

#endif

static int service_loop(int socknum, int *socklist)
{
	struct pollfd *pfd;
	int i;

H
H. Peter Anvin 已提交
621
	pfd = xcalloc(socknum, sizeof(struct pollfd));
P
Peter Anvin 已提交
622 623 624 625 626

	for (i = 0; i < socknum; i++) {
		pfd[i].fd = socklist[i];
		pfd[i].events = POLLIN;
	}
627 628

	signal(SIGCHLD, child_handler);
629 630

	for (;;) {
631
		int i;
P
Peter Anvin 已提交
632

633
		if (poll(pfd, socknum, -1) < 0) {
634
			if (errno != EINTR) {
P
Peter Anvin 已提交
635
				error("poll failed, resuming: %s",
636 637 638
				      strerror(errno));
				sleep(1);
			}
639 640 641 642
			continue;
		}

		for (i = 0; i < socknum; i++) {
P
Peter Anvin 已提交
643
			if (pfd[i].revents & POLLIN) {
644
				struct sockaddr_storage ss;
645
				unsigned int sslen = sizeof(ss);
P
Peter Anvin 已提交
646
				int incoming = accept(pfd[i].fd, (struct sockaddr *)&ss, &sslen);
647 648 649 650 651 652 653 654 655 656 657
				if (incoming < 0) {
					switch (errno) {
					case EAGAIN:
					case EINTR:
					case ECONNABORTED:
						continue;
					default:
						die("accept returned %s", strerror(errno));
					}
				}
				handle(incoming, (struct sockaddr *)&ss, sslen);
658 659 660 661 662
			}
		}
	}
}

663 664 665 666 667 668 669 670 671 672 673 674
/* if any standard file descriptor is missing open it to /dev/null */
static void sanitize_stdfds(void)
{
	int fd = open("/dev/null", O_RDWR, 0);
	while (fd != -1 && fd < 2)
		fd = dup(fd);
	if (fd == -1)
		die("open /dev/null or dup failed: %s", strerror(errno));
	if (fd > 2)
		close(fd);
}

675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692
static void daemonize(void)
{
	switch (fork()) {
		case 0:
			break;
		case -1:
			die("fork failed: %s", strerror(errno));
		default:
			exit(0);
	}
	if (setsid() == -1)
		die("setsid failed: %s", strerror(errno));
	close(0);
	close(1);
	close(2);
	sanitize_stdfds();
}

693 694 695 696 697 698 699 700 701
static void store_pid(const char *path)
{
	FILE *f = fopen(path, "w");
	if (!f)
		die("cannot open pid file %s: %s", path, strerror(errno));
	fprintf(f, "%d\n", getpid());
	fclose(f);
}

702
static int serve(int port, struct passwd *pass, gid_t gid)
P
Peter Anvin 已提交
703 704
{
	int socknum, *socklist;
J
Junio C Hamano 已提交
705

P
Peter Anvin 已提交
706 707 708
	socknum = socksetup(port, &socklist);
	if (socknum == 0)
		die("unable to allocate any listen sockets on port %u", port);
J
Junio C Hamano 已提交
709

710 711 712 713 714
	if (pass && gid &&
	    (initgroups(pass->pw_name, gid) || setgid (gid) ||
	     setuid(pass->pw_uid)))
		die("cannot drop privileges");

P
Peter Anvin 已提交
715
	return service_loop(socknum, socklist);
J
Junio C Hamano 已提交
716
}
P
Peter Anvin 已提交
717

718 719 720
int main(int argc, char **argv)
{
	int port = DEFAULT_GIT_PORT;
721
	int inetd_mode = 0;
722
	const char *pid_file = NULL, *user_name = NULL, *group_name = NULL;
723
	int detach = 0;
724 725 726
	struct passwd *pass = NULL;
	struct group *group;
	gid_t gid = 0;
727 728
	int i;

729 730 731 732 733
	/* Without this we cannot rely on waitpid() to tell
	 * what happened to our children.
	 */
	signal(SIGCHLD, SIG_DFL);

734 735 736 737 738 739 740 741 742 743 744 745
	for (i = 1; i < argc; i++) {
		char *arg = argv[i];

		if (!strncmp(arg, "--port=", 7)) {
			char *end;
			unsigned long n;
			n = strtoul(arg+7, &end, 0);
			if (arg[7] && !*end) {
				port = n;
				continue;
			}
		}
746 747
		if (!strcmp(arg, "--inetd")) {
			inetd_mode = 1;
A
Andreas Ericsson 已提交
748
			log_syslog = 1;
749 750
			continue;
		}
P
Petr Baudis 已提交
751 752 753 754
		if (!strcmp(arg, "--verbose")) {
			verbose = 1;
			continue;
		}
755 756 757 758
		if (!strcmp(arg, "--syslog")) {
			log_syslog = 1;
			continue;
		}
759 760 761 762
		if (!strcmp(arg, "--export-all")) {
			export_all_trees = 1;
			continue;
		}
763 764
		if (!strncmp(arg, "--timeout=", 10)) {
			timeout = atoi(arg+10);
A
Andreas Ericsson 已提交
765
			continue;
766
		}
767
		if (!strncmp(arg, "--init-timeout=", 15)) {
768
			init_timeout = atoi(arg+15);
A
Andreas Ericsson 已提交
769
			continue;
770
		}
771 772 773 774
		if (!strcmp(arg, "--strict-paths")) {
			strict_paths = 1;
			continue;
		}
P
Petr Baudis 已提交
775 776 777 778
		if (!strncmp(arg, "--base-path=", 12)) {
			base_path = arg+12;
			continue;
		}
779 780 781 782
		if (!strcmp(arg, "--reuseaddr")) {
			reuseaddr = 1;
			continue;
		}
783 784 785 786 787 788 789 790
		if (!strcmp(arg, "--user-path")) {
			user_path = "";
			continue;
		}
		if (!strncmp(arg, "--user-path=", 12)) {
			user_path = arg + 12;
			continue;
		}
791 792 793 794
		if (!strncmp(arg, "--pid-file=", 11)) {
			pid_file = arg + 11;
			continue;
		}
795 796 797 798 799
		if (!strcmp(arg, "--detach")) {
			detach = 1;
			log_syslog = 1;
			continue;
		}
800 801 802 803 804 805 806 807
		if (!strncmp(arg, "--user=", 7)) {
			user_name = arg + 7;
			continue;
		}
		if (!strncmp(arg, "--group=", 8)) {
			group_name = arg + 8;
			continue;
		}
808 809 810 811 812 813 814
		if (!strcmp(arg, "--")) {
			ok_paths = &argv[i+1];
			break;
		} else if (arg[0] != '-') {
			ok_paths = &argv[i];
			break;
		}
815

816 817 818
		usage(daemon_usage);
	}

819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840
	if (inetd_mode && (group_name || user_name))
		die("--user and --group are incompatible with --inetd");

	if (group_name && !user_name)
		die("--group supplied without --user");

	if (user_name) {
		pass = getpwnam(user_name);
		if (!pass)
			die("user not found - %s", user_name);

		if (!group_name)
			gid = pass->pw_gid;
		else {
			group = getgrnam(group_name);
			if (!group)
				die("group not found - %s", group_name);

			gid = group->gr_gid;
		}
	}

841
	if (log_syslog) {
A
Andreas Ericsson 已提交
842
		openlog("git-daemon", 0, LOG_DAEMON);
843
		set_die_routine(daemon_die);
844 845
	}

846 847 848
	if (strict_paths && (!ok_paths || !*ok_paths))
		die("option --strict-paths requires a whitelist");

849
	if (inetd_mode) {
850 851 852 853
		struct sockaddr_storage ss;
		struct sockaddr *peer = (struct sockaddr *)&ss;
		socklen_t slen = sizeof(ss);

854
		freopen("/dev/null", "w", stderr);
855 856 857 858 859

		if (getpeername(0, peer, &slen))
			peer = NULL;

		return execute(peer);
860
	}
861

862 863 864 865
	if (detach)
		daemonize();
	else
		sanitize_stdfds();
866

867 868 869
	if (pid_file)
		store_pid(pid_file);

870
	return serve(port, pass, gid);
871
}