microhttpd-util.c revision cf0fbc49e67b55f8d346fc94de28c90113505297
/*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
/***
This file is part of systemd.
Copyright 2012 Lennart Poettering
Copyright 2012 Zbigniew Jędrzejewski-Szmek
under the terms of the GNU Lesser General Public License as published by
the Free Software Foundation; either version 2.1 of the License, or
(at your option) any later version.
systemd is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public License
along with systemd; If not, see <http://www.gnu.org/licenses/>.
***/
#include <stddef.h>
#include <stdio.h>
#include <string.h>
#ifdef HAVE_GNUTLS
#endif
#include "alloc-util.h"
#include "log.h"
#include "macro.h"
#include "microhttpd-util.h"
#include "string-util.h"
#include "strv.h"
#include "util.h"
char *f;
}
char *buffer,
enum MHD_ResponseMemoryMode mode) {
struct MHD_Response *response;
int r;
if (!response)
return MHD_NO;
return r;
}
const char *message) {
}
}
const char *format, ...) {
char *m;
int r;
if (r < 0)
return respond_oom(connection);
}
#ifdef HAVE_GNUTLS
static struct {
const char *const names[4];
int level;
bool enabled;
} gnutls_log_map[] = {
{ {"0"}, LOG_DEBUG },
{ {"8"}, LOG_DEBUG },
};
log_internal(gnutls_log_map[level].level, 0, NULL, 0, NULL, "gnutls %d/%s: %s", level, gnutls_log_map[level].names[1], message);
} else {
}
}
static void log_reset_gnutls_level(void) {
int i;
if (gnutls_log_map[i].enabled) {
log_debug("Setting gnutls log level to %d", i);
break;
}
}
static int log_enable_gnutls_category(const char *cat) {
unsigned i;
for (i = 0; i < ELEMENTSOF(gnutls_log_map); i++)
gnutls_log_map[i].enabled = true;
return 0;
} else
for (i = 0; i < ELEMENTSOF(gnutls_log_map); i++)
gnutls_log_map[i].enabled = true;
return 0;
}
return -EINVAL;
}
int setup_gnutls_logger(char **categories) {
char **cat;
int r;
if (categories) {
r = log_enable_gnutls_category(*cat);
if (r < 0)
return r;
}
} else
return 0;
}
unsigned status;
int r;
if (r < 0)
return log_error_errno(r, "gnutls_certificate_verify_peers2 failed: %m");
if (r < 0)
return log_error_errno(r, "gnutls_certificate_verification_status_print failed: %m");
}
const gnutls_datum_t *pcert;
unsigned listsize;
int r;
log_error("Failed to retrieve certificate chain");
return -EINVAL;
}
r = gnutls_x509_crt_init(&cert);
if (r < 0) {
log_error("Failed to initialize client certificate");
return r;
}
/* Note that by passing values between 0 and listsize here, you
can get access to the CA's certs */
if (r < 0) {
log_error("Failed to import client certificate");
return r;
}
*client_cert = cert;
return 0;
}
int r;
if (r != GNUTLS_E_SHORT_MEMORY_BUFFER) {
log_error("gnutls_x509_crt_get_dn failed");
return r;
}
if (!*buf)
return log_oom();
return 0;
}
static inline void gnutls_x509_crt_deinitp(gnutls_x509_crt_t *p) {
}
const union MHD_ConnectionInfo *ci;
int r;
*code = 0;
if (!ci) {
log_error("MHD_get_connection_info failed: session is unencrypted");
"Encrypted connection is required");
return -EPERM;
}
if (r < 0) {
"Authorization through certificate is required");
return -EPERM;
}
if (r < 0) {
"Failed to determine distinguished name from certificate");
return -EPERM;
}
if (hostname) {
}
if (r < 0) {
log_warning("Client is not authorized");
"Client certificate not signed by recognized authority");
}
return r;
}
#else
return -EPERM;
}
int setup_gnutls_logger(char **categories) {
if (categories)
log_notice("Ignoring specified gnutls logging categories — gnutls not available.");
return 0;
}
#endif