• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /***************************************************************************
2  *                                  _   _ ____  _
3  *  Project                     ___| | | |  _ \| |
4  *                             / __| | | | |_) | |
5  *                            | (__| |_| |  _ <| |___
6  *                             \___|\___/|_| \_\_____|
7  *
8  * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
9  *
10  * This software is licensed as described in the file COPYING, which
11  * you should have received as part of this distribution. The terms
12  * are also available at https://curl.se/docs/copyright.html.
13  *
14  * You may opt to use, copy, modify, merge, publish, distribute and/or sell
15  * copies of the Software, and permit persons to whom the Software is
16  * furnished to do so, under the terms of the COPYING file.
17  *
18  * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
19  * KIND, either express or implied.
20  *
21  * SPDX-License-Identifier: curl
22  *
23  ***************************************************************************/
24 #include "tool_setup.h"
25 
26 #include "strcase.h"
27 
28 #define ENABLE_CURLX_PRINTF
29 /* use our own printf() functions */
30 #include "curlx.h"
31 
32 #include "tool_binmode.h"
33 #include "tool_cfgable.h"
34 #include "tool_cb_prg.h"
35 #include "tool_filetime.h"
36 #include "tool_formparse.h"
37 #include "tool_getparam.h"
38 #include "tool_helpers.h"
39 #include "tool_libinfo.h"
40 #include "tool_msgs.h"
41 #include "tool_paramhlp.h"
42 #include "tool_parsecfg.h"
43 #include "tool_main.h"
44 #include "dynbuf.h"
45 #include "tool_stderr.h"
46 
47 #include "memdebug.h" /* keep this as LAST include */
48 
49 #ifdef MSDOS
50 #  define USE_WATT32
51 #endif
52 
53 #define GetStr(str,val) do { \
54   if(*(str)) { \
55     free(*(str)); \
56     *(str) = NULL; \
57   } \
58   if((val)) {              \
59     *(str) = strdup((val)); \
60     if(!(*(str)))          \
61       return PARAM_NO_MEM; \
62   } \
63 } while(0)
64 
65 struct LongShort {
66   const char *letter; /* short name option */
67   const char *lname;  /* long name option */
68   enum {
69     ARG_NONE,   /* stand-alone but not a boolean */
70     ARG_BOOL,   /* accepts a --no-[name] prefix */
71     ARG_STRING, /* requires an argument */
72     ARG_FILENAME /* requires an argument, usually a file name */
73   } desc;
74 };
75 
76 static const struct LongShort aliases[]= {
77   /* 'letter' strings with more than one character have *no* short option to
78      mention. */
79   {"*@", "url",                      ARG_STRING},
80   {"*4", "dns-ipv4-addr",            ARG_STRING},
81   {"*6", "dns-ipv6-addr",            ARG_STRING},
82   {"*a", "random-file",              ARG_FILENAME},
83   {"*b", "egd-file",                 ARG_STRING},
84   {"*B", "oauth2-bearer",            ARG_STRING},
85   {"*c", "connect-timeout",          ARG_STRING},
86   {"*C", "doh-url"        ,          ARG_STRING},
87   {"*d", "ciphers",                  ARG_STRING},
88   {"*D", "dns-interface",            ARG_STRING},
89   {"*e", "disable-epsv",             ARG_BOOL},
90   {"*f", "disallow-username-in-url", ARG_BOOL},
91   {"*E", "epsv",                     ARG_BOOL},
92          /* 'epsv' made like this to make --no-epsv and --epsv to work
93              although --disable-epsv is the documented option */
94   {"*F", "dns-servers",              ARG_STRING},
95   {"*g", "trace",                    ARG_FILENAME},
96   {"*G", "npn",                      ARG_BOOL},
97   {"*h", "trace-ascii",              ARG_FILENAME},
98   {"*H", "alpn",                     ARG_BOOL},
99   {"*i", "limit-rate",               ARG_STRING},
100   {"*I", "rate",                     ARG_STRING},
101   {"*j", "compressed",               ARG_BOOL},
102   {"*J", "tr-encoding",              ARG_BOOL},
103   {"*k", "digest",                   ARG_BOOL},
104   {"*l", "negotiate",                ARG_BOOL},
105   {"*m", "ntlm",                     ARG_BOOL},
106   {"*M", "ntlm-wb",                  ARG_BOOL},
107   {"*n", "basic",                    ARG_BOOL},
108   {"*o", "anyauth",                  ARG_BOOL},
109 #ifdef USE_WATT32
110   {"*p", "wdebug",                   ARG_BOOL},
111 #endif
112   {"*q", "ftp-create-dirs",          ARG_BOOL},
113   {"*r", "create-dirs",              ARG_BOOL},
114   {"*R", "create-file-mode",         ARG_STRING},
115   {"*s", "max-redirs",               ARG_STRING},
116   {"*t", "proxy-ntlm",               ARG_BOOL},
117   {"*u", "crlf",                     ARG_BOOL},
118   {"*v", "stderr",                   ARG_FILENAME},
119   {"*V", "aws-sigv4",                ARG_STRING},
120   {"*w", "interface",                ARG_STRING},
121   {"*x", "krb",                      ARG_STRING},
122   {"*x", "krb4",                     ARG_STRING},
123          /* 'krb4' is the previous name */
124   {"*X", "haproxy-protocol",         ARG_BOOL},
125   {"*y", "max-filesize",             ARG_STRING},
126   {"*z", "disable-eprt",             ARG_BOOL},
127   {"*Z", "eprt",                     ARG_BOOL},
128          /* 'eprt' made like this to make --no-eprt and --eprt to work
129              although --disable-eprt is the documented option */
130   {"*~", "xattr",                    ARG_BOOL},
131   {"$a", "ftp-ssl",                  ARG_BOOL},
132          /* 'ftp-ssl' deprecated name since 7.20.0 */
133   {"$a", "ssl",                      ARG_BOOL},
134          /* 'ssl' new option name in 7.20.0, previously this was ftp-ssl */
135   {"$b", "ftp-pasv",                 ARG_BOOL},
136   {"$c", "socks5",                   ARG_STRING},
137   {"$d", "tcp-nodelay",              ARG_BOOL},
138   {"$e", "proxy-digest",             ARG_BOOL},
139   {"$f", "proxy-basic",              ARG_BOOL},
140   {"$g", "retry",                    ARG_STRING},
141   {"$V", "retry-connrefused",        ARG_BOOL},
142   {"$h", "retry-delay",              ARG_STRING},
143   {"$i", "retry-max-time",           ARG_STRING},
144   {"$k", "proxy-negotiate",          ARG_BOOL},
145   {"$l", "form-escape",              ARG_BOOL},
146   {"$m", "ftp-account",              ARG_STRING},
147   {"$n", "proxy-anyauth",            ARG_BOOL},
148   {"$o", "trace-time",               ARG_BOOL},
149   {"$p", "ignore-content-length",    ARG_BOOL},
150   {"$q", "ftp-skip-pasv-ip",         ARG_BOOL},
151   {"$r", "ftp-method",               ARG_STRING},
152   {"$s", "local-port",               ARG_STRING},
153   {"$t", "socks4",                   ARG_STRING},
154   {"$T", "socks4a",                  ARG_STRING},
155   {"$u", "ftp-alternative-to-user",  ARG_STRING},
156   {"$v", "ftp-ssl-reqd",             ARG_BOOL},
157          /* 'ftp-ssl-reqd' deprecated name since 7.20.0 */
158   {"$v", "ssl-reqd",                 ARG_BOOL},
159          /* 'ssl-reqd' new in 7.20.0, previously this was ftp-ssl-reqd */
160   {"$w", "sessionid",                ARG_BOOL},
161          /* 'sessionid' listed as --no-sessionid in the help */
162   {"$x", "ftp-ssl-control",          ARG_BOOL},
163   {"$y", "ftp-ssl-ccc",              ARG_BOOL},
164   {"$j", "ftp-ssl-ccc-mode",         ARG_STRING},
165   {"$z", "libcurl",                  ARG_STRING},
166   {"$#", "raw",                      ARG_BOOL},
167   {"$0", "post301",                  ARG_BOOL},
168   {"$1", "keepalive",                ARG_BOOL},
169          /* 'keepalive' listed as --no-keepalive in the help */
170   {"$2", "socks5-hostname",          ARG_STRING},
171   {"$3", "keepalive-time",           ARG_STRING},
172   {"$4", "post302",                  ARG_BOOL},
173   {"$5", "noproxy",                  ARG_STRING},
174   {"$7", "socks5-gssapi-nec",        ARG_BOOL},
175   {"$8", "proxy1.0",                 ARG_STRING},
176   {"$9", "tftp-blksize",             ARG_STRING},
177   {"$A", "mail-from",                ARG_STRING},
178   {"$B", "mail-rcpt",                ARG_STRING},
179   {"$C", "ftp-pret",                 ARG_BOOL},
180   {"$D", "proto",                    ARG_STRING},
181   {"$E", "proto-redir",              ARG_STRING},
182   {"$F", "resolve",                  ARG_STRING},
183   {"$G", "delegation",               ARG_STRING},
184   {"$H", "mail-auth",                ARG_STRING},
185   {"$I", "post303",                  ARG_BOOL},
186   {"$J", "metalink",                 ARG_BOOL},
187   {"$6", "sasl-authzid",             ARG_STRING},
188   {"$K", "sasl-ir",                  ARG_BOOL },
189   {"$L", "test-event",               ARG_BOOL},
190   {"$M", "unix-socket",              ARG_FILENAME},
191   {"$N", "path-as-is",               ARG_BOOL},
192   {"$O", "socks5-gssapi-service",    ARG_STRING},
193          /* 'socks5-gssapi-service' merged with'proxy-service-name' and
194             deprecated since 7.49.0 */
195   {"$O", "proxy-service-name",       ARG_STRING},
196   {"$P", "service-name",             ARG_STRING},
197   {"$Q", "proto-default",            ARG_STRING},
198   {"$R", "expect100-timeout",        ARG_STRING},
199   {"$S", "tftp-no-options",          ARG_BOOL},
200   {"$U", "connect-to",               ARG_STRING},
201   {"$W", "abstract-unix-socket",     ARG_FILENAME},
202   {"$X", "tls-max",                  ARG_STRING},
203   {"$Y", "suppress-connect-headers", ARG_BOOL},
204   {"$Z", "compressed-ssh",           ARG_BOOL},
205   {"$~", "happy-eyeballs-timeout-ms", ARG_STRING},
206   {"$!", "retry-all-errors",         ARG_BOOL},
207   {"0",   "http1.0",                 ARG_NONE},
208   {"01",  "http1.1",                 ARG_NONE},
209   {"02",  "http2",                   ARG_NONE},
210   {"03",  "http2-prior-knowledge",   ARG_NONE},
211   {"04",  "http3",                   ARG_NONE},
212   {"05",  "http3-only",              ARG_NONE},
213   {"09",  "http0.9",                 ARG_BOOL},
214   {"1",  "tlsv1",                    ARG_NONE},
215   {"10",  "tlsv1.0",                 ARG_NONE},
216   {"11",  "tlsv1.1",                 ARG_NONE},
217   {"12",  "tlsv1.2",                 ARG_NONE},
218   {"13",  "tlsv1.3",                 ARG_NONE},
219   {"1A", "tls13-ciphers",            ARG_STRING},
220   {"1B", "proxy-tls13-ciphers",      ARG_STRING},
221   {"2",  "sslv2",                    ARG_NONE},
222   {"3",  "sslv3",                    ARG_NONE},
223   {"4",  "ipv4",                     ARG_NONE},
224   {"6",  "ipv6",                     ARG_NONE},
225   {"a",  "append",                   ARG_BOOL},
226   {"A",  "user-agent",               ARG_STRING},
227   {"b",  "cookie",                   ARG_STRING},
228   {"ba", "alt-svc",                  ARG_STRING},
229   {"bb", "hsts",                     ARG_STRING},
230   {"B",  "use-ascii",                ARG_BOOL},
231   {"c",  "cookie-jar",               ARG_STRING},
232   {"C",  "continue-at",              ARG_STRING},
233   {"d",  "data",                     ARG_STRING},
234   {"dr", "data-raw",                 ARG_STRING},
235   {"da", "data-ascii",               ARG_STRING},
236   {"db", "data-binary",              ARG_STRING},
237   {"de", "data-urlencode",           ARG_STRING},
238   {"df", "json",                     ARG_STRING},
239   {"dg", "url-query",                ARG_STRING},
240   {"D",  "dump-header",              ARG_FILENAME},
241   {"e",  "referer",                  ARG_STRING},
242   {"E",  "cert",                     ARG_FILENAME},
243   {"Ea", "cacert",                   ARG_FILENAME},
244   {"Eb", "cert-type",                ARG_STRING},
245   {"Ec", "key",                      ARG_FILENAME},
246   {"Ed", "key-type",                 ARG_STRING},
247   {"Ee", "pass",                     ARG_STRING},
248   {"Ef", "engine",                   ARG_STRING},
249   {"Eg", "capath",                   ARG_FILENAME},
250   {"Eh", "pubkey",                   ARG_STRING},
251   {"Ei", "hostpubmd5",               ARG_STRING},
252   {"EF", "hostpubsha256",            ARG_STRING},
253   {"Ej", "crlfile",                  ARG_FILENAME},
254   {"Ek", "tlsuser",                  ARG_STRING},
255   {"El", "tlspassword",              ARG_STRING},
256   {"Em", "tlsauthtype",              ARG_STRING},
257   {"En", "ssl-allow-beast",          ARG_BOOL},
258   {"Eo", "ssl-auto-client-cert",     ARG_BOOL},
259   {"EO", "proxy-ssl-auto-client-cert", ARG_BOOL},
260   {"Ep", "pinnedpubkey",             ARG_STRING},
261   {"EP", "proxy-pinnedpubkey",       ARG_STRING},
262   {"Eq", "cert-status",              ARG_BOOL},
263   {"EQ", "doh-cert-status",          ARG_BOOL},
264   {"Er", "false-start",              ARG_BOOL},
265   {"Es", "ssl-no-revoke",            ARG_BOOL},
266   {"ES", "ssl-revoke-best-effort",   ARG_BOOL},
267   {"Et", "tcp-fastopen",             ARG_BOOL},
268   {"Eu", "proxy-tlsuser",            ARG_STRING},
269   {"Ev", "proxy-tlspassword",        ARG_STRING},
270   {"Ew", "proxy-tlsauthtype",        ARG_STRING},
271   {"Ex", "proxy-cert",               ARG_FILENAME},
272   {"Ey", "proxy-cert-type",          ARG_STRING},
273   {"Ez", "proxy-key",                ARG_FILENAME},
274   {"E0", "proxy-key-type",           ARG_STRING},
275   {"E1", "proxy-pass",               ARG_STRING},
276   {"E2", "proxy-ciphers",            ARG_STRING},
277   {"E3", "proxy-crlfile",            ARG_FILENAME},
278   {"E4", "proxy-ssl-allow-beast",    ARG_BOOL},
279   {"E5", "login-options",            ARG_STRING},
280   {"E6", "proxy-cacert",             ARG_FILENAME},
281   {"E7", "proxy-capath",             ARG_FILENAME},
282   {"E8", "proxy-insecure",           ARG_BOOL},
283   {"E9", "proxy-tlsv1",              ARG_NONE},
284   {"EA", "socks5-basic",             ARG_BOOL},
285   {"EB", "socks5-gssapi",            ARG_BOOL},
286   {"EC", "etag-save",                ARG_FILENAME},
287   {"ED", "etag-compare",             ARG_FILENAME},
288   {"EE", "curves",                   ARG_STRING},
289   {"f",  "fail",                     ARG_BOOL},
290   {"fa", "fail-early",               ARG_BOOL},
291   {"fb", "styled-output",            ARG_BOOL},
292   {"fc", "mail-rcpt-allowfails",     ARG_BOOL},
293   {"fd", "fail-with-body",           ARG_BOOL},
294   {"fe", "remove-on-error",          ARG_BOOL},
295   {"F",  "form",                     ARG_STRING},
296   {"Fs", "form-string",              ARG_STRING},
297   {"g",  "globoff",                  ARG_BOOL},
298   {"G",  "get",                      ARG_BOOL},
299   {"Ga", "request-target",           ARG_STRING},
300   {"h",  "help",                     ARG_BOOL},
301   {"H",  "header",                   ARG_STRING},
302   {"Hp", "proxy-header",             ARG_STRING},
303   {"i",  "include",                  ARG_BOOL},
304   {"I",  "head",                     ARG_BOOL},
305   {"j",  "junk-session-cookies",     ARG_BOOL},
306   {"J",  "remote-header-name",       ARG_BOOL},
307   {"k",  "insecure",                 ARG_BOOL},
308   {"kd", "doh-insecure",             ARG_BOOL},
309   {"K",  "config",                   ARG_FILENAME},
310   {"l",  "list-only",                ARG_BOOL},
311   {"L",  "location",                 ARG_BOOL},
312   {"Lt", "location-trusted",         ARG_BOOL},
313   {"m",  "max-time",                 ARG_STRING},
314   {"M",  "manual",                   ARG_BOOL},
315   {"n",  "netrc",                    ARG_BOOL},
316   {"no", "netrc-optional",           ARG_BOOL},
317   {"ne", "netrc-file",               ARG_FILENAME},
318   {"N",  "buffer",                   ARG_BOOL},
319          /* 'buffer' listed as --no-buffer in the help */
320   {"o",  "output",                   ARG_FILENAME},
321   {"O",  "remote-name",              ARG_BOOL},
322   {"Oa", "remote-name-all",          ARG_BOOL},
323   {"Ob", "output-dir",               ARG_STRING},
324   {"Oc", "clobber",                  ARG_BOOL},
325   {"p",  "proxytunnel",              ARG_BOOL},
326   {"P",  "ftp-port",                 ARG_STRING},
327   {"q",  "disable",                  ARG_BOOL},
328   {"Q",  "quote",                    ARG_STRING},
329   {"r",  "range",                    ARG_STRING},
330   {"R",  "remote-time",              ARG_BOOL},
331   {"s",  "silent",                   ARG_BOOL},
332   {"S",  "show-error",               ARG_BOOL},
333   {"t",  "telnet-option",            ARG_STRING},
334   {"T",  "upload-file",              ARG_FILENAME},
335   {"u",  "user",                     ARG_STRING},
336   {"U",  "proxy-user",               ARG_STRING},
337   {"v",  "verbose",                  ARG_BOOL},
338   {"V",  "version",                  ARG_BOOL},
339   {"w",  "write-out",                ARG_STRING},
340   {"x",  "proxy",                    ARG_STRING},
341   {"xa", "preproxy",                 ARG_STRING},
342   {"X",  "request",                  ARG_STRING},
343   {"Y",  "speed-limit",              ARG_STRING},
344   {"y",  "speed-time",               ARG_STRING},
345   {"z",  "time-cond",                ARG_STRING},
346   {"Z",  "parallel",                 ARG_BOOL},
347   {"Zb", "parallel-max",             ARG_STRING},
348   {"Zc", "parallel-immediate",       ARG_BOOL},
349   {"#",  "progress-bar",             ARG_BOOL},
350   {"#m", "progress-meter",           ARG_BOOL},
351   {":",  "next",                     ARG_NONE},
352 };
353 
354 /* Split the argument of -E to 'certname' and 'passphrase' separated by colon.
355  * We allow ':' and '\' to be escaped by '\' so that we can use certificate
356  * nicknames containing ':'.  See <https://sourceforge.net/p/curl/bugs/1196/>
357  * for details. */
358 #ifndef UNITTESTS
359 static
360 #endif
parse_cert_parameter(const char * cert_parameter,char ** certname,char ** passphrase)361 void parse_cert_parameter(const char *cert_parameter,
362                           char **certname,
363                           char **passphrase)
364 {
365   size_t param_length = strlen(cert_parameter);
366   size_t span;
367   const char *param_place = NULL;
368   char *certname_place = NULL;
369   *certname = NULL;
370   *passphrase = NULL;
371 
372   /* most trivial assumption: cert_parameter is empty */
373   if(param_length == 0)
374     return;
375 
376   /* next less trivial: cert_parameter starts 'pkcs11:' and thus
377    * looks like a RFC7512 PKCS#11 URI which can be used as-is.
378    * Also if cert_parameter contains no colon nor backslash, this
379    * means no passphrase was given and no characters escaped */
380   if(curl_strnequal(cert_parameter, "pkcs11:", 7) ||
381      !strpbrk(cert_parameter, ":\\")) {
382     *certname = strdup(cert_parameter);
383     return;
384   }
385   /* deal with escaped chars; find unescaped colon if it exists */
386   certname_place = malloc(param_length + 1);
387   if(!certname_place)
388     return;
389 
390   *certname = certname_place;
391   param_place = cert_parameter;
392   while(*param_place) {
393     span = strcspn(param_place, ":\\");
394     strncpy(certname_place, param_place, span);
395     param_place += span;
396     certname_place += span;
397     /* we just ate all the non-special chars. now we're on either a special
398      * char or the end of the string. */
399     switch(*param_place) {
400     case '\0':
401       break;
402     case '\\':
403       param_place++;
404       switch(*param_place) {
405         case '\0':
406           *certname_place++ = '\\';
407           break;
408         case '\\':
409           *certname_place++ = '\\';
410           param_place++;
411           break;
412         case ':':
413           *certname_place++ = ':';
414           param_place++;
415           break;
416         default:
417           *certname_place++ = '\\';
418           *certname_place++ = *param_place;
419           param_place++;
420           break;
421       }
422       break;
423     case ':':
424       /* Since we live in a world of weirdness and confusion, the win32
425          dudes can use : when using drive letters and thus c:\file:password
426          needs to work. In order not to break compatibility, we still use : as
427          separator, but we try to detect when it is used for a file name! On
428          windows. */
429 #ifdef WIN32
430       if((param_place == &cert_parameter[1]) &&
431          (cert_parameter[2] == '\\' || cert_parameter[2] == '/') &&
432          (ISALPHA(cert_parameter[0])) ) {
433         /* colon in the second column, followed by a backslash, and the
434            first character is an alphabetic letter:
435 
436            this is a drive letter colon */
437         *certname_place++ = ':';
438         param_place++;
439         break;
440       }
441 #endif
442       /* escaped colons and Windows drive letter colons were handled
443        * above; if we're still here, this is a separating colon */
444       param_place++;
445       if(*param_place) {
446         *passphrase = strdup(param_place);
447       }
448       goto done;
449     }
450   }
451 done:
452   *certname_place = '\0';
453 }
454 
455 /* Replace (in-place) '%20' by '+' according to RFC1866 */
replace_url_encoded_space_by_plus(char * url)456 static size_t replace_url_encoded_space_by_plus(char *url)
457 {
458   size_t orig_len = strlen(url);
459   size_t orig_index = 0;
460   size_t new_index = 0;
461 
462   while(orig_index < orig_len) {
463     if((url[orig_index] == '%') &&
464        (url[orig_index + 1] == '2') &&
465        (url[orig_index + 2] == '0')) {
466       url[new_index] = '+';
467       orig_index += 3;
468     }
469     else{
470       if(new_index != orig_index) {
471         url[new_index] = url[orig_index];
472       }
473       orig_index++;
474     }
475     new_index++;
476   }
477 
478   url[new_index] = 0; /* terminate string */
479 
480   return new_index; /* new size */
481 }
482 
483 static void
GetFileAndPassword(char * nextarg,char ** file,char ** password)484 GetFileAndPassword(char *nextarg, char **file, char **password)
485 {
486   char *certname, *passphrase;
487   parse_cert_parameter(nextarg, &certname, &passphrase);
488   Curl_safefree(*file);
489   *file = certname;
490   if(passphrase) {
491     Curl_safefree(*password);
492     *password = passphrase;
493   }
494 }
495 
496 /* Get a size parameter for '--limit-rate' or '--max-filesize'.
497  * We support a 'G', 'M' or 'K' suffix too.
498   */
GetSizeParameter(struct GlobalConfig * global,const char * arg,const char * which,curl_off_t * value_out)499 static ParameterError GetSizeParameter(struct GlobalConfig *global,
500                                        const char *arg,
501                                        const char *which,
502                                        curl_off_t *value_out)
503 {
504   char *unit;
505   curl_off_t value;
506 
507   if(curlx_strtoofft(arg, &unit, 10, &value)) {
508     warnf(global, "invalid number specified for %s\n", which);
509     return PARAM_BAD_USE;
510   }
511 
512   if(!*unit)
513     unit = (char *)"b";
514   else if(strlen(unit) > 1)
515     unit = (char *)"w"; /* unsupported */
516 
517   switch(*unit) {
518   case 'G':
519   case 'g':
520     if(value > (CURL_OFF_T_MAX / (1024*1024*1024)))
521       return PARAM_NUMBER_TOO_LARGE;
522     value *= 1024*1024*1024;
523     break;
524   case 'M':
525   case 'm':
526     if(value > (CURL_OFF_T_MAX / (1024*1024)))
527       return PARAM_NUMBER_TOO_LARGE;
528     value *= 1024*1024;
529     break;
530   case 'K':
531   case 'k':
532     if(value > (CURL_OFF_T_MAX / 1024))
533       return PARAM_NUMBER_TOO_LARGE;
534     value *= 1024;
535     break;
536   case 'b':
537   case 'B':
538     /* for plain bytes, leave as-is */
539     break;
540   default:
541     warnf(global, "unsupported %s unit. Use G, M, K or B!\n", which);
542     return PARAM_BAD_USE;
543   }
544   *value_out = value;
545   return PARAM_OK;
546 }
547 
548 #ifdef HAVE_WRITABLE_ARGV
cleanarg(argv_item_t str)549 static void cleanarg(argv_item_t str)
550 {
551   /* now that GetStr has copied the contents of nextarg, wipe the next
552    * argument out so that the username:password isn't displayed in the
553    * system process list */
554   if(str) {
555     size_t len = strlen(str);
556     memset(str, ' ', len);
557   }
558 }
559 #else
560 #define cleanarg(x)
561 #endif
562 
563 /* --data-urlencode */
data_urlencode(struct GlobalConfig * global,char * nextarg,char ** postp,size_t * lenp)564 static ParameterError data_urlencode(struct GlobalConfig *global,
565                                      char *nextarg,
566                                      char **postp,
567                                      size_t *lenp)
568 {
569   /* [name]=[content], we encode the content part only
570    * [name]@[file name]
571    *
572    * Case 2: we first load the file using that name and then encode
573    * the content.
574    */
575   ParameterError err;
576   const char *p = strchr(nextarg, '=');
577   size_t nlen;
578   char is_file;
579   char *postdata = NULL;
580   size_t size = 0;
581   if(!p)
582     /* there was no '=' letter, check for a '@' instead */
583     p = strchr(nextarg, '@');
584   if(p) {
585     nlen = p - nextarg; /* length of the name part */
586     is_file = *p++; /* pass the separator */
587   }
588   else {
589     /* neither @ nor =, so no name and it isn't a file */
590     nlen = is_file = 0;
591     p = nextarg;
592   }
593   if('@' == is_file) {
594     FILE *file;
595     /* a '@' letter, it means that a file name or - (stdin) follows */
596     if(!strcmp("-", p)) {
597       file = stdin;
598       set_binmode(stdin);
599     }
600     else {
601       file = fopen(p, "rb");
602       if(!file)
603         warnf(global,
604               "Couldn't read data from file \"%s\", this makes "
605               "an empty POST.\n", nextarg);
606     }
607 
608     err = file2memory(&postdata, &size, file);
609 
610     if(file && (file != stdin))
611       fclose(file);
612     if(err)
613       return err;
614   }
615   else {
616     GetStr(&postdata, p);
617     if(postdata)
618       size = strlen(postdata);
619   }
620 
621   if(!postdata) {
622     /* no data from the file, point to a zero byte string to make this
623        get sent as a POST anyway */
624     postdata = strdup("");
625     if(!postdata)
626       return PARAM_NO_MEM;
627     size = 0;
628   }
629   else {
630     char *enc = curl_easy_escape(NULL, postdata, (int)size);
631     Curl_safefree(postdata); /* no matter if it worked or not */
632     if(enc) {
633       /* replace (in-place) '%20' by '+' according to RFC1866 */
634       size_t enclen = replace_url_encoded_space_by_plus(enc);
635       /* now make a string with the name from above and append the
636          encoded string */
637       size_t outlen = nlen + enclen + 2;
638       char *n = malloc(outlen);
639       if(!n) {
640         curl_free(enc);
641         return PARAM_NO_MEM;
642       }
643       if(nlen > 0) { /* only append '=' if we have a name */
644         msnprintf(n, outlen, "%.*s=%s", (int)nlen, nextarg, enc);
645         size = outlen-1;
646       }
647       else {
648         strcpy(n, enc);
649         size = outlen-2; /* since no '=' was inserted */
650       }
651       curl_free(enc);
652       postdata = n;
653     }
654     else
655       return PARAM_NO_MEM;
656   }
657   *postp = postdata;
658   *lenp = size;
659   return PARAM_OK;
660 }
661 
sethttpver(struct GlobalConfig * global,struct OperationConfig * config,long httpversion)662 static void sethttpver(struct GlobalConfig *global,
663                        struct OperationConfig *config,
664                        long httpversion)
665 {
666   if(config->httpversion &&
667      (config->httpversion != httpversion))
668     warnf(global, "Overrides previous HTTP version option\n");
669 
670   config->httpversion = httpversion;
671 }
672 
getparameter(const char * flag,char * nextarg,argv_item_t cleararg,bool * usedarg,struct GlobalConfig * global,struct OperationConfig * config)673 ParameterError getparameter(const char *flag, /* f or -long-flag */
674                             char *nextarg,    /* NULL if unset */
675                             argv_item_t cleararg,
676                             bool *usedarg,    /* set to TRUE if the arg
677                                                  has been used */
678                             struct GlobalConfig *global,
679                             struct OperationConfig *config)
680 {
681   char letter;
682   char subletter = '\0'; /* subletters can only occur on long options */
683   int rc;
684   const char *parse = NULL;
685   unsigned int j;
686   time_t now;
687   int hit = -1;
688   bool longopt = FALSE;
689   bool singleopt = FALSE; /* when true means '-o foo' used '-ofoo' */
690   ParameterError err;
691   bool toggle = TRUE; /* how to switch boolean options, on or off. Controlled
692                          by using --OPTION or --no-OPTION */
693   static const char *redir_protos[] = {
694     "http",
695     "https",
696     "ftp",
697     "ftps",
698     NULL
699   };
700 #ifdef HAVE_WRITABLE_ARGV
701   argv_item_t clearthis = NULL;
702 #else
703   (void)cleararg;
704 #endif
705 
706   *usedarg = FALSE; /* default is that we don't use the arg */
707 
708   if(('-' != flag[0]) || ('-' == flag[1])) {
709     /* this should be a long name */
710     const char *word = ('-' == flag[0]) ? flag + 2 : flag;
711     size_t fnam = strlen(word);
712     int numhits = 0;
713     bool noflagged = FALSE;
714 
715     if(!strncmp(word, "no-", 3)) {
716       /* disable this option but ignore the "no-" part when looking for it */
717       word += 3;
718       toggle = FALSE;
719       noflagged = TRUE;
720     }
721 
722     for(j = 0; j < sizeof(aliases)/sizeof(aliases[0]); j++) {
723       if(curl_strnequal(aliases[j].lname, word, fnam)) {
724         longopt = TRUE;
725         numhits++;
726         if(curl_strequal(aliases[j].lname, word)) {
727           parse = aliases[j].letter;
728           hit = j;
729           numhits = 1; /* a single unique hit */
730           break;
731         }
732         parse = aliases[j].letter;
733         hit = j;
734       }
735     }
736     if(numhits > 1) {
737       /* this is at least the second match! */
738       return PARAM_OPTION_AMBIGUOUS;
739     }
740     if(hit < 0) {
741       return PARAM_OPTION_UNKNOWN;
742     }
743     if(noflagged && (aliases[hit].desc != ARG_BOOL))
744       /* --no- prefixed an option that isn't boolean! */
745       return PARAM_NO_NOT_BOOLEAN;
746   }
747   else {
748     flag++; /* prefixed with one dash, pass it */
749     hit = -1;
750     parse = flag;
751   }
752 
753   do {
754     /* we can loop here if we have multiple single-letters */
755 
756     if(!longopt) {
757       letter = (char)*parse;
758       subletter = '\0';
759     }
760     else {
761       letter = parse[0];
762       subletter = parse[1];
763     }
764 
765     if(hit < 0) {
766       for(j = 0; j < sizeof(aliases)/sizeof(aliases[0]); j++) {
767         if(letter == aliases[j].letter[0]) {
768           hit = j;
769           break;
770         }
771       }
772       if(hit < 0) {
773         return PARAM_OPTION_UNKNOWN;
774       }
775     }
776 
777     if(aliases[hit].desc >= ARG_STRING) {
778       /* this option requires an extra parameter */
779       if(!longopt && parse[1]) {
780         nextarg = (char *)&parse[1]; /* this is the actual extra parameter */
781         singleopt = TRUE;   /* don't loop anymore after this */
782       }
783       else if(!nextarg)
784         return PARAM_REQUIRES_PARAMETER;
785       else {
786 #ifdef HAVE_WRITABLE_ARGV
787         clearthis = cleararg;
788 #endif
789         *usedarg = TRUE; /* mark it as used */
790       }
791 
792       if((aliases[hit].desc == ARG_FILENAME) &&
793          (nextarg[0] == '-') && nextarg[1]) {
794         /* if the file name looks like a command line option */
795         warnf(global, "The file name argument '%s' looks like a flag.\n",
796               nextarg);
797       }
798     }
799     else if((aliases[hit].desc == ARG_NONE) && !toggle)
800       return PARAM_NO_PREFIX;
801 
802     switch(letter) {
803     case '*': /* options without a short option */
804       switch(subletter) {
805       case '4': /* --dns-ipv4-addr */
806         if(!curlinfo->ares_num) /* c-ares is needed for this */
807           return PARAM_LIBCURL_DOESNT_SUPPORT;
808         /* addr in dot notation */
809         GetStr(&config->dns_ipv4_addr, nextarg);
810         break;
811       case '6': /* --dns-ipv6-addr */
812         if(!curlinfo->ares_num) /* c-ares is needed for this */
813           return PARAM_LIBCURL_DOESNT_SUPPORT;
814         /* addr in dot notation */
815         GetStr(&config->dns_ipv6_addr, nextarg);
816         break;
817       case 'a': /* random-file */
818         break;
819       case 'b': /* egd-file */
820         break;
821       case 'B': /* OAuth 2.0 bearer token */
822         GetStr(&config->oauth_bearer, nextarg);
823         cleanarg(clearthis);
824         config->authtype |= CURLAUTH_BEARER;
825         break;
826       case 'c': /* connect-timeout */
827         err = secs2ms(&config->connecttimeout_ms, nextarg);
828         if(err)
829           return err;
830         break;
831       case 'C': /* doh-url */
832         GetStr(&config->doh_url, nextarg);
833         if(config->doh_url && !config->doh_url[0])
834           /* if given a blank string, we make it NULL again */
835           Curl_safefree(config->doh_url);
836         break;
837       case 'd': /* ciphers */
838         GetStr(&config->cipher_list, nextarg);
839         break;
840       case 'D': /* --dns-interface */
841         if(!curlinfo->ares_num) /* c-ares is needed for this */
842           return PARAM_LIBCURL_DOESNT_SUPPORT;
843         /* interface name */
844         GetStr(&config->dns_interface, nextarg);
845         break;
846       case 'e': /* --disable-epsv */
847         config->disable_epsv = toggle;
848         break;
849       case 'f': /* --disallow-username-in-url */
850         config->disallow_username_in_url = toggle;
851         break;
852       case 'E': /* --epsv */
853         config->disable_epsv = (!toggle)?TRUE:FALSE;
854         break;
855       case 'F': /* --dns-servers */
856         if(!curlinfo->ares_num) /* c-ares is needed for this */
857           return PARAM_LIBCURL_DOESNT_SUPPORT;
858         /* IP addrs of DNS servers */
859         GetStr(&config->dns_servers, nextarg);
860         break;
861       case 'g': /* --trace */
862         GetStr(&global->trace_dump, nextarg);
863         if(global->tracetype && (global->tracetype != TRACE_BIN))
864           warnf(global, "--trace overrides an earlier trace/verbose option\n");
865         global->tracetype = TRACE_BIN;
866         break;
867       case 'G': /* --npn */
868         warnf(global, "--npn is no longer supported\n");
869         break;
870       case 'h': /* --trace-ascii */
871         GetStr(&global->trace_dump, nextarg);
872         if(global->tracetype && (global->tracetype != TRACE_ASCII))
873           warnf(global,
874                 "--trace-ascii overrides an earlier trace/verbose option\n");
875         global->tracetype = TRACE_ASCII;
876         break;
877       case 'H': /* --alpn */
878         config->noalpn = (!toggle)?TRUE:FALSE;
879         break;
880       case 'i': /* --limit-rate */
881       {
882         curl_off_t value;
883         ParameterError pe = GetSizeParameter(global, nextarg, "rate", &value);
884 
885         if(pe != PARAM_OK)
886            return pe;
887         config->recvpersecond = value;
888         config->sendpersecond = value;
889       }
890       break;
891       case 'I': /* --rate (request rate) */
892       {
893         /* support a few different suffixes, extract the suffix first, then
894            get the number and convert to per hour.
895            /s == per second
896            /m == per minute
897            /h == per hour (default)
898            /d == per day (24 hours)
899         */
900         char *div = strchr(nextarg, '/');
901         char number[26];
902         long denominator;
903         long numerator = 60*60*1000; /* default per hour */
904         size_t numlen = div ? (size_t)(div - nextarg) : strlen(nextarg);
905         if(numlen > sizeof(number)-1)
906           return PARAM_NUMBER_TOO_LARGE;
907         strncpy(number, nextarg, numlen);
908         number[numlen] = 0;
909         err = str2unum(&denominator, number);
910         if(err)
911           return err;
912         if(denominator < 1)
913           return PARAM_BAD_USE;
914         if(div) {
915           char unit = div[1];
916           switch(unit) {
917           case 's': /* per second */
918             numerator = 1000;
919             break;
920           case 'm': /* per minute */
921             numerator = 60*1000;
922             break;
923           case 'h': /* per hour */
924             break;
925           case 'd': /* per day */
926             numerator = 24*60*60*1000;
927             break;
928           default:
929             errorf(global, "unsupported --rate unit\n");
930             return PARAM_BAD_USE;
931           }
932         }
933         global->ms_per_transfer = numerator/denominator;
934       }
935       break;
936 
937       case 'j': /* --compressed */
938         if(toggle && !(feature_libz || feature_brotli || feature_zstd))
939           return PARAM_LIBCURL_DOESNT_SUPPORT;
940         config->encoding = toggle;
941         break;
942 
943       case 'J': /* --tr-encoding */
944         config->tr_encoding = toggle;
945         break;
946 
947       case 'k': /* --digest */
948         if(toggle)
949           config->authtype |= CURLAUTH_DIGEST;
950         else
951           config->authtype &= ~CURLAUTH_DIGEST;
952         break;
953 
954       case 'l': /* --negotiate */
955         if(!toggle)
956           config->authtype &= ~CURLAUTH_NEGOTIATE;
957         else if(feature_spnego)
958           config->authtype |= CURLAUTH_NEGOTIATE;
959         else
960           return PARAM_LIBCURL_DOESNT_SUPPORT;
961         break;
962 
963       case 'm': /* --ntlm */
964         if(!toggle)
965           config->authtype &= ~CURLAUTH_NTLM;
966         else if(feature_ntlm)
967           config->authtype |= CURLAUTH_NTLM;
968         else
969           return PARAM_LIBCURL_DOESNT_SUPPORT;
970         break;
971 
972       case 'M': /* --ntlm-wb */
973         if(!toggle)
974           config->authtype &= ~CURLAUTH_NTLM_WB;
975         else if(feature_ntlm_wb)
976           config->authtype |= CURLAUTH_NTLM_WB;
977         else
978           return PARAM_LIBCURL_DOESNT_SUPPORT;
979         break;
980 
981       case 'n': /* --basic for completeness */
982         if(toggle)
983           config->authtype |= CURLAUTH_BASIC;
984         else
985           config->authtype &= ~CURLAUTH_BASIC;
986         break;
987 
988       case 'o': /* --anyauth, let libcurl pick it */
989         if(toggle)
990           config->authtype = CURLAUTH_ANY;
991         /* --no-anyauth simply doesn't touch it */
992         break;
993 
994 #ifdef USE_WATT32
995       case 'p': /* --wdebug */
996         dbug_init();
997         break;
998 #endif
999       case 'q': /* --ftp-create-dirs */
1000         config->ftp_create_dirs = toggle;
1001         break;
1002 
1003       case 'r': /* --create-dirs */
1004         config->create_dirs = toggle;
1005         break;
1006 
1007       case 'R': /* --create-file-mode */
1008         err = oct2nummax(&config->create_file_mode, nextarg, 0777);
1009         if(err)
1010           return err;
1011         break;
1012 
1013       case 's': /* --max-redirs */
1014         /* specified max no of redirects (http(s)), this accepts -1 as a
1015            special condition */
1016         err = str2num(&config->maxredirs, nextarg);
1017         if(err)
1018           return err;
1019         if(config->maxredirs < -1)
1020           return PARAM_BAD_NUMERIC;
1021         break;
1022 
1023       case 't': /* --proxy-ntlm */
1024         if(!feature_ntlm)
1025           return PARAM_LIBCURL_DOESNT_SUPPORT;
1026         config->proxyntlm = toggle;
1027         break;
1028 
1029       case 'u': /* --crlf */
1030         /* LF -> CRLF conversion? */
1031         config->crlf = toggle;
1032         break;
1033 
1034       case 'V': /* --aws-sigv4 */
1035         config->authtype |= CURLAUTH_AWS_SIGV4;
1036         GetStr(&config->aws_sigv4, nextarg);
1037         break;
1038 
1039       case 'v': /* --stderr */
1040         tool_set_stderr_file(nextarg);
1041         break;
1042       case 'w': /* --interface */
1043         /* interface */
1044         GetStr(&config->iface, nextarg);
1045         break;
1046       case 'x': /* --krb */
1047         /* kerberos level string */
1048         if(!feature_spnego)
1049           return PARAM_LIBCURL_DOESNT_SUPPORT;
1050         GetStr(&config->krblevel, nextarg);
1051         break;
1052       case 'X': /* --haproxy-protocol */
1053         config->haproxy_protocol = toggle;
1054         break;
1055       case 'y': /* --max-filesize */
1056         {
1057           curl_off_t value;
1058           ParameterError pe =
1059             GetSizeParameter(global, nextarg, "max-filesize", &value);
1060 
1061           if(pe != PARAM_OK)
1062              return pe;
1063           config->max_filesize = value;
1064         }
1065         break;
1066       case 'z': /* --disable-eprt */
1067         config->disable_eprt = toggle;
1068         break;
1069       case 'Z': /* --eprt */
1070         config->disable_eprt = (!toggle)?TRUE:FALSE;
1071         break;
1072       case '~': /* --xattr */
1073         config->xattr = toggle;
1074         break;
1075       case '@': /* the URL! */
1076       {
1077         struct getout *url;
1078 
1079         if(!config->url_get)
1080           config->url_get = config->url_list;
1081 
1082         if(config->url_get) {
1083           /* there's a node here, if it already is filled-in continue to find
1084              an "empty" node */
1085           while(config->url_get && (config->url_get->flags & GETOUT_URL))
1086             config->url_get = config->url_get->next;
1087         }
1088 
1089         /* now there might or might not be an available node to fill in! */
1090 
1091         if(config->url_get)
1092           /* existing node */
1093           url = config->url_get;
1094         else
1095           /* there was no free node, create one! */
1096           config->url_get = url = new_getout(config);
1097 
1098         if(!url)
1099           return PARAM_NO_MEM;
1100 
1101         /* fill in the URL */
1102         GetStr(&url->url, nextarg);
1103         url->flags |= GETOUT_URL;
1104       }
1105       }
1106       break;
1107     case '$': /* more options without a short option */
1108       switch(subletter) {
1109       case 'a': /* --ssl */
1110         if(toggle && !feature_ssl)
1111           return PARAM_LIBCURL_DOESNT_SUPPORT;
1112         config->ftp_ssl = toggle;
1113         if(config->ftp_ssl)
1114           warnf(global,
1115                 "--ssl is an insecure option, consider --ssl-reqd instead\n");
1116         break;
1117       case 'b': /* --ftp-pasv */
1118         Curl_safefree(config->ftpport);
1119         break;
1120       case 'c': /* --socks5 specifies a socks5 proxy to use, and resolves
1121                    the name locally and passes on the resolved address */
1122         GetStr(&config->proxy, nextarg);
1123         config->proxyver = CURLPROXY_SOCKS5;
1124         break;
1125       case 't': /* --socks4 specifies a socks4 proxy to use */
1126         GetStr(&config->proxy, nextarg);
1127         config->proxyver = CURLPROXY_SOCKS4;
1128         break;
1129       case 'T': /* --socks4a specifies a socks4a proxy to use */
1130         GetStr(&config->proxy, nextarg);
1131         config->proxyver = CURLPROXY_SOCKS4A;
1132         break;
1133       case '2': /* --socks5-hostname specifies a socks5 proxy and enables name
1134                    resolving with the proxy */
1135         GetStr(&config->proxy, nextarg);
1136         config->proxyver = CURLPROXY_SOCKS5_HOSTNAME;
1137         break;
1138       case 'd': /* --tcp-nodelay option */
1139         config->tcp_nodelay = toggle;
1140         break;
1141       case 'e': /* --proxy-digest */
1142         config->proxydigest = toggle;
1143         break;
1144       case 'f': /* --proxy-basic */
1145         config->proxybasic = toggle;
1146         break;
1147       case 'g': /* --retry */
1148         err = str2unum(&config->req_retry, nextarg);
1149         if(err)
1150           return err;
1151         break;
1152       case 'V': /* --retry-connrefused */
1153         config->retry_connrefused = toggle;
1154         break;
1155       case 'h': /* --retry-delay */
1156         err = str2unummax(&config->retry_delay, nextarg, LONG_MAX/1000);
1157         if(err)
1158           return err;
1159         break;
1160       case 'i': /* --retry-max-time */
1161         err = str2unummax(&config->retry_maxtime, nextarg, LONG_MAX/1000);
1162         if(err)
1163           return err;
1164         break;
1165       case '!': /* --retry-all-errors */
1166         config->retry_all_errors = toggle;
1167         break;
1168 
1169       case 'k': /* --proxy-negotiate */
1170         if(!feature_spnego)
1171           return PARAM_LIBCURL_DOESNT_SUPPORT;
1172         config->proxynegotiate = toggle;
1173         break;
1174 
1175       case 'l': /* --form-escape */
1176         config->mime_options &= ~CURLMIMEOPT_FORMESCAPE;
1177         if(toggle)
1178           config->mime_options |= CURLMIMEOPT_FORMESCAPE;
1179         break;
1180 
1181       case 'm': /* --ftp-account */
1182         GetStr(&config->ftp_account, nextarg);
1183         break;
1184       case 'n': /* --proxy-anyauth */
1185         config->proxyanyauth = toggle;
1186         break;
1187       case 'o': /* --trace-time */
1188         global->tracetime = toggle;
1189         break;
1190       case 'p': /* --ignore-content-length */
1191         config->ignorecl = toggle;
1192         break;
1193       case 'q': /* --ftp-skip-pasv-ip */
1194         config->ftp_skip_ip = toggle;
1195         break;
1196       case 'r': /* --ftp-method (undocumented at this point) */
1197         config->ftp_filemethod = ftpfilemethod(config, nextarg);
1198         break;
1199       case 's': { /* --local-port */
1200         /* 16bit base 10 is 5 digits, but we allow 6 so that this catches
1201            overflows, not just truncates */
1202         char lrange[7]="";
1203         char *p = nextarg;
1204         while(ISDIGIT(*p))
1205           p++;
1206         if(*p) {
1207           /* if there's anything more than a plain decimal number */
1208           rc = sscanf(p, " - %6s", lrange);
1209           *p = 0; /* null-terminate to make str2unum() work below */
1210         }
1211         else
1212           rc = 0;
1213 
1214         err = str2unum(&config->localport, nextarg);
1215         if(err || (config->localport > 65535))
1216           return PARAM_BAD_USE;
1217         if(!rc)
1218           config->localportrange = 1; /* default number of ports to try */
1219         else {
1220           err = str2unum(&config->localportrange, lrange);
1221           if(err || (config->localportrange > 65535))
1222             return PARAM_BAD_USE;
1223           config->localportrange -= (config->localport-1);
1224           if(config->localportrange < 1)
1225             return PARAM_BAD_USE;
1226         }
1227         break;
1228       }
1229       case 'u': /* --ftp-alternative-to-user */
1230         GetStr(&config->ftp_alternative_to_user, nextarg);
1231         break;
1232       case 'v': /* --ssl-reqd */
1233         if(toggle && !feature_ssl)
1234           return PARAM_LIBCURL_DOESNT_SUPPORT;
1235         config->ftp_ssl_reqd = toggle;
1236         break;
1237       case 'w': /* --no-sessionid */
1238         config->disable_sessionid = (!toggle)?TRUE:FALSE;
1239         break;
1240       case 'x': /* --ftp-ssl-control */
1241         if(toggle && !feature_ssl)
1242           return PARAM_LIBCURL_DOESNT_SUPPORT;
1243         config->ftp_ssl_control = toggle;
1244         break;
1245       case 'y': /* --ftp-ssl-ccc */
1246         config->ftp_ssl_ccc = toggle;
1247         if(!config->ftp_ssl_ccc_mode)
1248           config->ftp_ssl_ccc_mode = CURLFTPSSL_CCC_PASSIVE;
1249         break;
1250       case 'j': /* --ftp-ssl-ccc-mode */
1251         config->ftp_ssl_ccc = TRUE;
1252         config->ftp_ssl_ccc_mode = ftpcccmethod(config, nextarg);
1253         break;
1254       case 'z': /* --libcurl */
1255 #ifdef CURL_DISABLE_LIBCURL_OPTION
1256         warnf(global,
1257               "--libcurl option was disabled at build-time!\n");
1258         return PARAM_OPTION_UNKNOWN;
1259 #else
1260         GetStr(&global->libcurl, nextarg);
1261         break;
1262 #endif
1263       case '#': /* --raw */
1264         config->raw = toggle;
1265         break;
1266       case '0': /* --post301 */
1267         config->post301 = toggle;
1268         break;
1269       case '1': /* --no-keepalive */
1270         config->nokeepalive = (!toggle)?TRUE:FALSE;
1271         break;
1272       case '3': /* --keepalive-time */
1273         err = str2unum(&config->alivetime, nextarg);
1274         if(err)
1275           return err;
1276         break;
1277       case '4': /* --post302 */
1278         config->post302 = toggle;
1279         break;
1280       case 'I': /* --post303 */
1281         config->post303 = toggle;
1282         break;
1283       case '5': /* --noproxy */
1284         /* This specifies the noproxy list */
1285         GetStr(&config->noproxy, nextarg);
1286         break;
1287        case '7': /* --socks5-gssapi-nec */
1288         config->socks5_gssapi_nec = toggle;
1289         break;
1290       case '8': /* --proxy1.0 */
1291         /* http 1.0 proxy */
1292         GetStr(&config->proxy, nextarg);
1293         config->proxyver = CURLPROXY_HTTP_1_0;
1294         break;
1295       case '9': /* --tftp-blksize */
1296         err = str2unum(&config->tftp_blksize, nextarg);
1297         if(err)
1298           return err;
1299         break;
1300       case 'A': /* --mail-from */
1301         GetStr(&config->mail_from, nextarg);
1302         break;
1303       case 'B': /* --mail-rcpt */
1304         /* append receiver to a list */
1305         err = add2list(&config->mail_rcpt, nextarg);
1306         if(err)
1307           return err;
1308         break;
1309       case 'C': /* --ftp-pret */
1310         config->ftp_pret = toggle;
1311         break;
1312       case 'D': /* --proto */
1313         config->proto_present = TRUE;
1314         err = proto2num(config, built_in_protos, &config->proto_str, nextarg);
1315         if(err)
1316           return err;
1317         break;
1318       case 'E': /* --proto-redir */
1319         config->proto_redir_present = TRUE;
1320         if(proto2num(config, redir_protos, &config->proto_redir_str, nextarg))
1321           return PARAM_BAD_USE;
1322         break;
1323       case 'F': /* --resolve */
1324         err = add2list(&config->resolve, nextarg);
1325         if(err)
1326           return err;
1327         break;
1328       case 'G': /* --delegation LEVEL */
1329         config->gssapi_delegation = delegation(config, nextarg);
1330         break;
1331       case 'H': /* --mail-auth */
1332         GetStr(&config->mail_auth, nextarg);
1333         break;
1334       case 'J': /* --metalink */
1335         errorf(global, "--metalink is disabled\n");
1336         return PARAM_BAD_USE;
1337       case '6': /* --sasl-authzid */
1338         GetStr(&config->sasl_authzid, nextarg);
1339         break;
1340       case 'K': /* --sasl-ir */
1341         config->sasl_ir = toggle;
1342         break;
1343       case 'L': /* --test-event */
1344 #ifdef CURLDEBUG
1345         global->test_event_based = toggle;
1346 #else
1347         warnf(global, "--test-event is ignored unless a debug build!\n");
1348 #endif
1349         break;
1350       case 'M': /* --unix-socket */
1351         config->abstract_unix_socket = FALSE;
1352         GetStr(&config->unix_socket_path, nextarg);
1353         break;
1354       case 'N': /* --path-as-is */
1355         config->path_as_is = toggle;
1356         break;
1357       case 'O': /* --proxy-service-name */
1358         GetStr(&config->proxy_service_name, nextarg);
1359         break;
1360       case 'P': /* --service-name */
1361         GetStr(&config->service_name, nextarg);
1362         break;
1363       case 'Q': /* --proto-default */
1364         GetStr(&config->proto_default, nextarg);
1365         err = check_protocol(config->proto_default);
1366         if(err)
1367           return err;
1368         break;
1369       case 'R': /* --expect100-timeout */
1370         err = secs2ms(&config->expect100timeout_ms, nextarg);
1371         if(err)
1372           return err;
1373         break;
1374       case 'S': /* --tftp-no-options */
1375         config->tftp_no_options = toggle;
1376         break;
1377       case 'U': /* --connect-to */
1378         err = add2list(&config->connect_to, nextarg);
1379         if(err)
1380           return err;
1381         break;
1382       case 'W': /* --abstract-unix-socket */
1383         config->abstract_unix_socket = TRUE;
1384         GetStr(&config->unix_socket_path, nextarg);
1385         break;
1386       case 'X': /* --tls-max */
1387         err = str2tls_max(&config->ssl_version_max, nextarg);
1388         if(err)
1389           return err;
1390         break;
1391       case 'Y': /* --suppress-connect-headers */
1392         config->suppress_connect_headers = toggle;
1393         break;
1394       case 'Z': /* --compressed-ssh */
1395         config->ssh_compression = toggle;
1396         break;
1397       case '~': /* --happy-eyeballs-timeout-ms */
1398         err = str2unum(&config->happy_eyeballs_timeout_ms, nextarg);
1399         if(err)
1400           return err;
1401         /* 0 is a valid value for this timeout */
1402         break;
1403       }
1404       break;
1405     case '#':
1406       switch(subletter) {
1407       case 'm': /* --progress-meter */
1408         global->noprogress = !toggle;
1409         break;
1410       default:  /* --progress-bar */
1411         global->progressmode =
1412           toggle ? CURL_PROGRESS_BAR : CURL_PROGRESS_STATS;
1413         break;
1414       }
1415       break;
1416     case ':': /* --next */
1417       return PARAM_NEXT_OPERATION;
1418     case '0': /* --http* options */
1419       switch(subletter) {
1420       case '\0':
1421         /* HTTP version 1.0 */
1422         sethttpver(global, config, CURL_HTTP_VERSION_1_0);
1423         break;
1424       case '1':
1425         /* HTTP version 1.1 */
1426         sethttpver(global, config, CURL_HTTP_VERSION_1_1);
1427         break;
1428       case '2':
1429         /* HTTP version 2.0 */
1430         sethttpver(global, config, CURL_HTTP_VERSION_2_0);
1431         break;
1432       case '3': /* --http2-prior-knowledge */
1433         /* HTTP version 2.0 over clean TCP */
1434         sethttpver(global, config, CURL_HTTP_VERSION_2_PRIOR_KNOWLEDGE);
1435         break;
1436       case '4': /* --http3 */
1437         /* Try HTTP/3, allow fallback */
1438         if(!feature_http3)
1439           return PARAM_LIBCURL_DOESNT_SUPPORT;
1440         sethttpver(global, config, CURL_HTTP_VERSION_3);
1441         break;
1442       case '5': /* --http3-only */
1443         /* Try HTTP/3 without fallback */
1444         if(!feature_http3)
1445           return PARAM_LIBCURL_DOESNT_SUPPORT;
1446         sethttpver(global, config, CURL_HTTP_VERSION_3ONLY);
1447         break;
1448       case '9':
1449         /* Allow HTTP/0.9 responses! */
1450         config->http09_allowed = toggle;
1451         break;
1452       }
1453       break;
1454     case '1': /* --tlsv1* options */
1455       switch(subletter) {
1456       case '\0':
1457         /* TLS version 1.x */
1458         config->ssl_version = CURL_SSLVERSION_TLSv1;
1459         break;
1460       case '0':
1461         /* TLS version 1.0 */
1462         config->ssl_version = CURL_SSLVERSION_TLSv1_0;
1463         break;
1464       case '1':
1465         /* TLS version 1.1 */
1466         config->ssl_version = CURL_SSLVERSION_TLSv1_1;
1467         break;
1468       case '2':
1469         /* TLS version 1.2 */
1470         config->ssl_version = CURL_SSLVERSION_TLSv1_2;
1471         break;
1472       case '3':
1473         /* TLS version 1.3 */
1474         config->ssl_version = CURL_SSLVERSION_TLSv1_3;
1475         break;
1476       case 'A': /* --tls13-ciphers */
1477         GetStr(&config->cipher13_list, nextarg);
1478         break;
1479       case 'B': /* --proxy-tls13-ciphers */
1480         GetStr(&config->proxy_cipher13_list, nextarg);
1481         break;
1482       }
1483       break;
1484     case '2':
1485       /* SSL version 2 */
1486       warnf(global, "Ignores instruction to use SSLv2\n");
1487       break;
1488     case '3':
1489       /* SSL version 3 */
1490       warnf(global, "Ignores instruction to use SSLv3\n");
1491       break;
1492     case '4':
1493       /* IPv4 */
1494       config->ip_version = CURL_IPRESOLVE_V4;
1495       break;
1496     case '6':
1497       /* IPv6 */
1498       config->ip_version = CURL_IPRESOLVE_V6;
1499       break;
1500     case 'a':
1501       /* This makes the FTP sessions use APPE instead of STOR */
1502       config->ftp_append = toggle;
1503       break;
1504     case 'A':
1505       /* This specifies the User-Agent name */
1506       GetStr(&config->useragent, nextarg);
1507       break;
1508     case 'b':
1509       switch(subletter) {
1510       case 'a': /* --alt-svc */
1511         if(!feature_altsvc)
1512           return PARAM_LIBCURL_DOESNT_SUPPORT;
1513         GetStr(&config->altsvc, nextarg);
1514         break;
1515       case 'b': /* --hsts */
1516         if(!feature_hsts)
1517           return PARAM_LIBCURL_DOESNT_SUPPORT;
1518         GetStr(&config->hsts, nextarg);
1519         break;
1520       default:  /* --cookie string coming up: */
1521         if(nextarg[0] == '@') {
1522           nextarg++;
1523         }
1524         else if(strchr(nextarg, '=')) {
1525           /* A cookie string must have a =-letter */
1526           err = add2list(&config->cookies, nextarg);
1527           if(err)
1528             return err;
1529           break;
1530         }
1531         /* We have a cookie file to read from! */
1532         err = add2list(&config->cookiefiles, nextarg);
1533         if(err)
1534           return err;
1535       }
1536       break;
1537     case 'B':
1538       /* use ASCII/text when transferring */
1539       config->use_ascii = toggle;
1540       break;
1541     case 'c':
1542       /* get the file name to dump all cookies in */
1543       GetStr(&config->cookiejar, nextarg);
1544       break;
1545     case 'C':
1546       /* This makes us continue an ftp transfer at given position */
1547       if(strcmp(nextarg, "-")) {
1548         err = str2offset(&config->resume_from, nextarg);
1549         if(err)
1550           return err;
1551         config->resume_from_current = FALSE;
1552       }
1553       else {
1554         config->resume_from_current = TRUE;
1555         config->resume_from = 0;
1556       }
1557       config->use_resume = TRUE;
1558       break;
1559     case 'd':
1560       /* postfield data */
1561     {
1562       char *postdata = NULL;
1563       FILE *file;
1564       size_t size = 0;
1565       bool raw_mode = (subletter == 'r');
1566 
1567       if(subletter == 'g') { /* --url-query */
1568 #define MAX_QUERY_LEN 100000 /* larger is not likely to ever work */
1569         char *query;
1570         struct curlx_dynbuf dyn;
1571         curlx_dyn_init(&dyn, MAX_QUERY_LEN);
1572 
1573         if(*nextarg == '+') {
1574           /* use without encoding */
1575           query = strdup(&nextarg[1]);
1576           if(!query)
1577             return PARAM_NO_MEM;
1578         }
1579         else {
1580           err = data_urlencode(global, nextarg, &query, &size);
1581           if(err)
1582             return err;
1583         }
1584 
1585         if(config->query) {
1586           CURLcode result =
1587             curlx_dyn_addf(&dyn, "%s&%s", config->query, query);
1588           free(query);
1589           if(result)
1590             return PARAM_NO_MEM;
1591           free(config->query);
1592           config->query = curlx_dyn_ptr(&dyn);
1593         }
1594         else
1595           config->query = query;
1596 
1597         break; /* this is not a POST argument at all */
1598       }
1599       else if(subletter == 'e') { /* --data-urlencode */
1600         err = data_urlencode(global, nextarg, &postdata, &size);
1601         if(err)
1602           return err;
1603       }
1604       else if('@' == *nextarg && !raw_mode) {
1605         /* the data begins with a '@' letter, it means that a file name
1606            or - (stdin) follows */
1607         nextarg++; /* pass the @ */
1608 
1609         if(!strcmp("-", nextarg)) {
1610           file = stdin;
1611           if(subletter == 'b') /* forced data-binary */
1612             set_binmode(stdin);
1613         }
1614         else {
1615           file = fopen(nextarg, "rb");
1616           if(!file)
1617             warnf(global, "Couldn't read data from file \"%s\", this makes "
1618                   "an empty POST.\n", nextarg);
1619         }
1620 
1621         if((subletter == 'b') || /* --data-binary */
1622            (subletter == 'f') /* --json */)
1623           /* forced binary */
1624           err = file2memory(&postdata, &size, file);
1625         else {
1626           err = file2string(&postdata, file);
1627           if(postdata)
1628             size = strlen(postdata);
1629         }
1630 
1631         if(file && (file != stdin))
1632           fclose(file);
1633         if(err)
1634           return err;
1635 
1636         if(!postdata) {
1637           /* no data from the file, point to a zero byte string to make this
1638              get sent as a POST anyway */
1639           postdata = strdup("");
1640           if(!postdata)
1641             return PARAM_NO_MEM;
1642         }
1643       }
1644       else {
1645         GetStr(&postdata, nextarg);
1646         if(postdata)
1647           size = strlen(postdata);
1648       }
1649       if(subletter == 'f')
1650         config->jsoned = TRUE;
1651 
1652       if(config->postfields) {
1653         /* we already have a string, we append this one with a separating
1654            &-letter */
1655         char *oldpost = config->postfields;
1656         curl_off_t oldlen = config->postfieldsize;
1657         curl_off_t newlen = oldlen + curlx_uztoso(size) + 2;
1658         config->postfields = malloc((size_t)newlen);
1659         if(!config->postfields) {
1660           Curl_safefree(oldpost);
1661           Curl_safefree(postdata);
1662           return PARAM_NO_MEM;
1663         }
1664         memcpy(config->postfields, oldpost, (size_t)oldlen);
1665         if(subletter != 'f') {
1666           /* skip this treatment for --json */
1667           /* use byte value 0x26 for '&' to accommodate non-ASCII platforms */
1668           config->postfields[oldlen] = '\x26';
1669           memcpy(&config->postfields[oldlen + 1], postdata, size);
1670           config->postfields[oldlen + 1 + size] = '\0';
1671           config->postfieldsize += size + 1;
1672         }
1673         else {
1674           memcpy(&config->postfields[oldlen], postdata, size);
1675           config->postfields[oldlen + size] = '\0';
1676           config->postfieldsize += size;
1677         }
1678         Curl_safefree(oldpost);
1679         Curl_safefree(postdata);
1680       }
1681       else {
1682         config->postfields = postdata;
1683         config->postfieldsize = curlx_uztoso(size);
1684       }
1685     }
1686     /*
1687       We can't set the request type here, as this data might be used in
1688       a simple GET if -G is used. Already or soon.
1689 
1690       if(SetHTTPrequest(HTTPREQ_SIMPLEPOST, &config->httpreq)) {
1691         Curl_safefree(postdata);
1692         return PARAM_BAD_USE;
1693       }
1694     */
1695     break;
1696     case 'D':
1697       /* dump-header to given file name */
1698       GetStr(&config->headerfile, nextarg);
1699       break;
1700     case 'e':
1701     {
1702       char *ptr = strstr(nextarg, ";auto");
1703       if(ptr) {
1704         /* Automatic referer requested, this may be combined with a
1705            set initial one */
1706         config->autoreferer = TRUE;
1707         *ptr = 0; /* null-terminate here */
1708       }
1709       else
1710         config->autoreferer = FALSE;
1711       ptr = *nextarg ? nextarg : NULL;
1712       GetStr(&config->referer, ptr);
1713     }
1714     break;
1715     case 'E':
1716       switch(subletter) {
1717       case '\0': /* certificate file */
1718         cleanarg(clearthis);
1719         GetFileAndPassword(nextarg, &config->cert, &config->key_passwd);
1720         break;
1721       case 'a': /* CA info PEM file */
1722         GetStr(&config->cacert, nextarg);
1723         break;
1724       case 'b': /* cert file type */
1725         GetStr(&config->cert_type, nextarg);
1726         break;
1727       case 'c': /* private key file */
1728         GetStr(&config->key, nextarg);
1729         break;
1730       case 'd': /* private key file type */
1731         GetStr(&config->key_type, nextarg);
1732         break;
1733       case 'e': /* private key passphrase */
1734         GetStr(&config->key_passwd, nextarg);
1735         cleanarg(clearthis);
1736         break;
1737       case 'f': /* crypto engine */
1738         GetStr(&config->engine, nextarg);
1739         if(config->engine && curl_strequal(config->engine, "list"))
1740           return PARAM_ENGINES_REQUESTED;
1741         break;
1742       case 'g': /* CA cert directory */
1743         GetStr(&config->capath, nextarg);
1744         break;
1745       case 'h': /* --pubkey public key file */
1746         GetStr(&config->pubkey, nextarg);
1747         break;
1748       case 'i': /* --hostpubmd5 md5 of the host public key */
1749         GetStr(&config->hostpubmd5, nextarg);
1750         if(!config->hostpubmd5 || strlen(config->hostpubmd5) != 32)
1751           return PARAM_BAD_USE;
1752         break;
1753       case 'F': /* --hostpubsha256 sha256 of the host public key */
1754         GetStr(&config->hostpubsha256, nextarg);
1755         break;
1756       case 'j': /* CRL file */
1757         GetStr(&config->crlfile, nextarg);
1758         break;
1759       case 'k': /* TLS username */
1760         if(!feature_tls_srp) {
1761           cleanarg(clearthis);
1762           return PARAM_LIBCURL_DOESNT_SUPPORT;
1763         }
1764         GetStr(&config->tls_username, nextarg);
1765         cleanarg(clearthis);
1766         break;
1767       case 'l': /* TLS password */
1768         if(!feature_tls_srp) {
1769           cleanarg(clearthis);
1770           return PARAM_LIBCURL_DOESNT_SUPPORT;
1771         }
1772         GetStr(&config->tls_password, nextarg);
1773         cleanarg(clearthis);
1774         break;
1775       case 'm': /* TLS authentication type */
1776         if(!feature_tls_srp)
1777           return PARAM_LIBCURL_DOESNT_SUPPORT;
1778         GetStr(&config->tls_authtype, nextarg);
1779         if(!curl_strequal(config->tls_authtype, "SRP"))
1780           return PARAM_LIBCURL_DOESNT_SUPPORT; /* only support TLS-SRP */
1781         break;
1782       case 'n': /* no empty SSL fragments, --ssl-allow-beast */
1783         if(feature_ssl)
1784           config->ssl_allow_beast = toggle;
1785         break;
1786 
1787       case 'o': /* --ssl-auto-client-cert */
1788         if(feature_ssl)
1789           config->ssl_auto_client_cert = toggle;
1790         break;
1791 
1792       case 'O': /* --proxy-ssl-auto-client-cert */
1793         if(feature_ssl)
1794           config->proxy_ssl_auto_client_cert = toggle;
1795         break;
1796 
1797       case 'p': /* Pinned public key DER file */
1798         GetStr(&config->pinnedpubkey, nextarg);
1799         break;
1800 
1801       case 'P': /* proxy pinned public key */
1802         GetStr(&config->proxy_pinnedpubkey, nextarg);
1803         break;
1804 
1805       case 'q': /* --cert-status */
1806         config->verifystatus = TRUE;
1807         break;
1808 
1809       case 'Q': /* --doh-cert-status */
1810         config->doh_verifystatus = TRUE;
1811         break;
1812 
1813       case 'r': /* --false-start */
1814         config->falsestart = TRUE;
1815         break;
1816 
1817       case 's': /* --ssl-no-revoke */
1818         if(feature_ssl)
1819           config->ssl_no_revoke = TRUE;
1820         break;
1821 
1822       case 'S': /* --ssl-revoke-best-effort */
1823         if(feature_ssl)
1824           config->ssl_revoke_best_effort = TRUE;
1825         break;
1826 
1827       case 't': /* --tcp-fastopen */
1828         config->tcp_fastopen = TRUE;
1829         break;
1830 
1831       case 'u': /* TLS username for proxy */
1832         cleanarg(clearthis);
1833         if(!feature_tls_srp)
1834           return PARAM_LIBCURL_DOESNT_SUPPORT;
1835         GetStr(&config->proxy_tls_username, nextarg);
1836         break;
1837 
1838       case 'v': /* TLS password for proxy */
1839         cleanarg(clearthis);
1840         if(!feature_tls_srp)
1841           return PARAM_LIBCURL_DOESNT_SUPPORT;
1842         GetStr(&config->proxy_tls_password, nextarg);
1843         break;
1844 
1845       case 'w': /* TLS authentication type for proxy */
1846         if(!feature_tls_srp)
1847           return PARAM_LIBCURL_DOESNT_SUPPORT;
1848         GetStr(&config->proxy_tls_authtype, nextarg);
1849         if(!curl_strequal(config->proxy_tls_authtype, "SRP"))
1850           return PARAM_LIBCURL_DOESNT_SUPPORT; /* only support TLS-SRP */
1851         break;
1852 
1853       case 'x': /* certificate file for proxy */
1854         cleanarg(clearthis);
1855         GetFileAndPassword(nextarg, &config->proxy_cert,
1856                            &config->proxy_key_passwd);
1857         break;
1858 
1859       case 'y': /* cert file type for proxy */
1860         GetStr(&config->proxy_cert_type, nextarg);
1861         break;
1862 
1863       case 'z': /* private key file for proxy */
1864         GetStr(&config->proxy_key, nextarg);
1865         break;
1866 
1867       case '0': /* private key file type for proxy */
1868         GetStr(&config->proxy_key_type, nextarg);
1869         break;
1870 
1871       case '1': /* private key passphrase for proxy */
1872         GetStr(&config->proxy_key_passwd, nextarg);
1873         cleanarg(clearthis);
1874         break;
1875 
1876       case '2': /* ciphers for proxy */
1877         GetStr(&config->proxy_cipher_list, nextarg);
1878         break;
1879 
1880       case '3': /* CRL file for proxy */
1881         GetStr(&config->proxy_crlfile, nextarg);
1882         break;
1883 
1884       case '4': /* no empty SSL fragments for proxy */
1885         if(feature_ssl)
1886           config->proxy_ssl_allow_beast = toggle;
1887         break;
1888 
1889       case '5': /* --login-options */
1890         GetStr(&config->login_options, nextarg);
1891         break;
1892 
1893       case '6': /* CA info PEM file for proxy */
1894         GetStr(&config->proxy_cacert, nextarg);
1895         break;
1896 
1897       case '7': /* CA cert directory for proxy */
1898         GetStr(&config->proxy_capath, nextarg);
1899         break;
1900 
1901       case '8': /* allow insecure SSL connects for proxy */
1902         config->proxy_insecure_ok = toggle;
1903         break;
1904 
1905       case '9': /* --proxy-tlsv1 */
1906         /* TLS version 1 for proxy */
1907         config->proxy_ssl_version = CURL_SSLVERSION_TLSv1;
1908         break;
1909 
1910       case 'A':
1911         /* --socks5-basic */
1912         if(toggle)
1913           config->socks5_auth |= CURLAUTH_BASIC;
1914         else
1915           config->socks5_auth &= ~CURLAUTH_BASIC;
1916         break;
1917 
1918       case 'B':
1919         /* --socks5-gssapi */
1920         if(toggle)
1921           config->socks5_auth |= CURLAUTH_GSSAPI;
1922         else
1923           config->socks5_auth &= ~CURLAUTH_GSSAPI;
1924         break;
1925 
1926       case 'C':
1927         GetStr(&config->etag_save_file, nextarg);
1928         break;
1929 
1930       case 'D':
1931         GetStr(&config->etag_compare_file, nextarg);
1932         break;
1933 
1934       case 'E':
1935         GetStr(&config->ssl_ec_curves, nextarg);
1936         break;
1937 
1938       default: /* unknown flag */
1939         return PARAM_OPTION_UNKNOWN;
1940       }
1941       break;
1942     case 'f':
1943       switch(subletter) {
1944       case 'a': /* --fail-early */
1945         global->fail_early = toggle;
1946         break;
1947       case 'b': /* --styled-output */
1948         global->styled_output = toggle;
1949         break;
1950       case 'c': /* --mail-rcpt-allowfails */
1951         config->mail_rcpt_allowfails = toggle;
1952         break;
1953       case 'd': /* --fail-with-body */
1954         config->failwithbody = toggle;
1955         break;
1956       case 'e': /* --remove-on-error */
1957         config->rm_partial = toggle;
1958         break;
1959        default: /* --fail (hard on errors)  */
1960         config->failonerror = toggle;
1961         break;
1962       }
1963       if(config->failonerror && config->failwithbody) {
1964         errorf(config->global, "You must select either --fail or "
1965                "--fail-with-body, not both.\n");
1966         return PARAM_BAD_USE;
1967       }
1968       break;
1969     case 'F':
1970       /* "form data" simulation, this is a little advanced so lets do our best
1971          to sort this out slowly and carefully */
1972       if(formparse(config,
1973                    nextarg,
1974                    &config->mimeroot,
1975                    &config->mimecurrent,
1976                    (subletter == 's')?TRUE:FALSE)) /* 's' is literal string */
1977         return PARAM_BAD_USE;
1978       if(SetHTTPrequest(config, HTTPREQ_MIMEPOST, &config->httpreq))
1979         return PARAM_BAD_USE;
1980       break;
1981 
1982     case 'g': /* g disables URLglobbing */
1983       config->globoff = toggle;
1984       break;
1985 
1986     case 'G': /* HTTP GET */
1987       if(subletter == 'a') { /* --request-target */
1988         GetStr(&config->request_target, nextarg);
1989       }
1990       else
1991         config->use_httpget = toggle;
1992       break;
1993 
1994     case 'h': /* h for help */
1995       if(toggle) {
1996         if(nextarg) {
1997           global->help_category = strdup(nextarg);
1998           if(!global->help_category)
1999             return PARAM_NO_MEM;
2000         }
2001         return PARAM_HELP_REQUESTED;
2002       }
2003       /* we now actually support --no-help too! */
2004       break;
2005     case 'H':
2006       /* A custom header to append to a list */
2007       if(nextarg[0] == '@') {
2008         /* read many headers from a file or stdin */
2009         char *string;
2010         size_t len;
2011         bool use_stdin = !strcmp(&nextarg[1], "-");
2012         FILE *file = use_stdin?stdin:fopen(&nextarg[1], FOPEN_READTEXT);
2013         if(!file)
2014           warnf(global, "Failed to open %s!\n", &nextarg[1]);
2015         else {
2016           err = file2memory(&string, &len, file);
2017           if(!err && string) {
2018             /* Allow strtok() here since this isn't used threaded */
2019             /* !checksrc! disable BANNEDFUNC 2 */
2020             char *h = strtok(string, "\r\n");
2021             while(h) {
2022               if(subletter == 'p') /* --proxy-header */
2023                 err = add2list(&config->proxyheaders, h);
2024               else
2025                 err = add2list(&config->headers, h);
2026               if(err)
2027                 break;
2028               h = strtok(NULL, "\r\n");
2029             }
2030             free(string);
2031           }
2032           if(!use_stdin)
2033             fclose(file);
2034           if(err)
2035             return err;
2036         }
2037       }
2038       else {
2039         if(subletter == 'p') /* --proxy-header */
2040           err = add2list(&config->proxyheaders, nextarg);
2041         else
2042           err = add2list(&config->headers, nextarg);
2043         if(err)
2044           return err;
2045       }
2046       break;
2047     case 'i':
2048       config->show_headers = toggle; /* show the headers as well in the
2049                                         general output stream */
2050       break;
2051     case 'j':
2052       config->cookiesession = toggle;
2053       break;
2054     case 'I': /* --head */
2055       config->no_body = toggle;
2056       config->show_headers = toggle;
2057       if(SetHTTPrequest(config,
2058                         (config->no_body)?HTTPREQ_HEAD:HTTPREQ_GET,
2059                         &config->httpreq))
2060         return PARAM_BAD_USE;
2061       break;
2062     case 'J': /* --remote-header-name */
2063       config->content_disposition = toggle;
2064       break;
2065     case 'k': /* allow insecure SSL connects */
2066       if(subletter == 'd') /* --doh-insecure */
2067         config->doh_insecure_ok = toggle;
2068       else
2069         config->insecure_ok = toggle;
2070       break;
2071     case 'K': /* parse config file */
2072       if(parseconfig(nextarg, global)) {
2073         errorf(global, "cannot read config from '%s'\n", nextarg);
2074         return PARAM_READ_ERROR;
2075       }
2076       break;
2077     case 'l':
2078       config->dirlistonly = toggle; /* only list the names of the FTP dir */
2079       break;
2080     case 'L':
2081       config->followlocation = toggle; /* Follow Location: HTTP headers */
2082       switch(subletter) {
2083       case 't':
2084         /* Continue to send authentication (user+password) when following
2085          * locations, even when hostname changed */
2086         config->unrestricted_auth = toggle;
2087         break;
2088       }
2089       break;
2090     case 'm':
2091       /* specified max time */
2092       err = secs2ms(&config->timeout_ms, nextarg);
2093       if(err)
2094         return err;
2095       break;
2096     case 'M': /* M for manual, huge help */
2097       if(toggle) { /* --no-manual shows no manual... */
2098 #ifndef USE_MANUAL
2099         warnf(global,
2100               "built-in manual was disabled at build-time!\n");
2101 #endif
2102         return PARAM_MANUAL_REQUESTED;
2103       }
2104       break;
2105     case 'n':
2106       switch(subletter) {
2107       case 'o': /* use .netrc or URL */
2108         config->netrc_opt = toggle;
2109         break;
2110       case 'e': /* netrc-file */
2111         GetStr(&config->netrc_file, nextarg);
2112         break;
2113       default:
2114         /* pick info from .netrc, if this is used for http, curl will
2115            automatically enforce user+password with the request */
2116         config->netrc = toggle;
2117         break;
2118       }
2119       break;
2120     case 'N':
2121       /* disable the output I/O buffering. note that the option is called
2122          --buffer but is mostly used in the negative form: --no-buffer */
2123       config->nobuffer = longopt ? !toggle : TRUE;
2124       break;
2125     case 'O': /* --remote-name */
2126       if(subletter == 'a') { /* --remote-name-all */
2127         config->default_node_flags = toggle?GETOUT_USEREMOTE:0;
2128         break;
2129       }
2130       else if(subletter == 'b') { /* --output-dir */
2131         GetStr(&config->output_dir, nextarg);
2132         break;
2133       }
2134       else if(subletter == 'c') { /* --clobber / --no-clobber */
2135         config->file_clobber_mode = toggle ? CLOBBER_ALWAYS : CLOBBER_NEVER;
2136         break;
2137       }
2138       /* FALLTHROUGH */
2139     case 'o': /* --output */
2140       /* output file */
2141     {
2142       struct getout *url;
2143       if(!config->url_out)
2144         config->url_out = config->url_list;
2145       if(config->url_out) {
2146         /* there's a node here, if it already is filled-in continue to find
2147            an "empty" node */
2148         while(config->url_out && (config->url_out->flags & GETOUT_OUTFILE))
2149           config->url_out = config->url_out->next;
2150       }
2151 
2152       /* now there might or might not be an available node to fill in! */
2153 
2154       if(config->url_out)
2155         /* existing node */
2156         url = config->url_out;
2157       else {
2158         if(!toggle && !config->default_node_flags)
2159           break;
2160         /* there was no free node, create one! */
2161         config->url_out = url = new_getout(config);
2162       }
2163 
2164       if(!url)
2165         return PARAM_NO_MEM;
2166 
2167       /* fill in the outfile */
2168       if('o' == letter) {
2169         if(!*nextarg) {
2170           warnf(global, "output file name has no length\n");
2171           return PARAM_BAD_USE;
2172         }
2173         GetStr(&url->outfile, nextarg);
2174         url->flags &= ~GETOUT_USEREMOTE; /* switch off */
2175       }
2176       else {
2177         url->outfile = NULL; /* leave it */
2178         if(toggle)
2179           url->flags |= GETOUT_USEREMOTE;  /* switch on */
2180         else
2181           url->flags &= ~GETOUT_USEREMOTE; /* switch off */
2182       }
2183       url->flags |= GETOUT_OUTFILE;
2184     }
2185     break;
2186     case 'P':
2187       /* This makes the FTP sessions use PORT instead of PASV */
2188       /* use <eth0> or <192.168.10.10> style addresses. Anything except
2189          this will make us try to get the "default" address.
2190          NOTE: this is a changed behavior since the released 4.1!
2191       */
2192       GetStr(&config->ftpport, nextarg);
2193       break;
2194     case 'p':
2195       /* proxy tunnel for non-http protocols */
2196       config->proxytunnel = toggle;
2197       break;
2198 
2199     case 'q': /* if used first, already taken care of, we do it like
2200                  this so we don't cause an error! */
2201       break;
2202     case 'Q':
2203       /* QUOTE command to send to FTP server */
2204       switch(nextarg[0]) {
2205       case '-':
2206         /* prefixed with a dash makes it a POST TRANSFER one */
2207         nextarg++;
2208         err = add2list(&config->postquote, nextarg);
2209         break;
2210       case '+':
2211         /* prefixed with a plus makes it a just-before-transfer one */
2212         nextarg++;
2213         err = add2list(&config->prequote, nextarg);
2214         break;
2215       default:
2216         err = add2list(&config->quote, nextarg);
2217         break;
2218       }
2219       if(err)
2220         return err;
2221       break;
2222     case 'r':
2223       /* Specifying a range WITHOUT A DASH will create an illegal HTTP range
2224          (and won't actually be range by definition). The man page previously
2225          claimed that to be a good way, why this code is added to work-around
2226          it. */
2227       if(ISDIGIT(*nextarg) && !strchr(nextarg, '-')) {
2228         char buffer[32];
2229         curl_off_t off;
2230         if(curlx_strtoofft(nextarg, NULL, 10, &off)) {
2231           warnf(global, "unsupported range point\n");
2232           return PARAM_BAD_USE;
2233         }
2234         warnf(global,
2235               "A specified range MUST include at least one dash (-). "
2236               "Appending one for you!\n");
2237         msnprintf(buffer, sizeof(buffer), "%" CURL_FORMAT_CURL_OFF_T "-", off);
2238         Curl_safefree(config->range);
2239         config->range = strdup(buffer);
2240         if(!config->range)
2241           return PARAM_NO_MEM;
2242       }
2243       else {
2244         /* byte range requested */
2245         const char *tmp_range = nextarg;
2246         while(*tmp_range != '\0') {
2247           if(!ISDIGIT(*tmp_range) && *tmp_range != '-' && *tmp_range != ',') {
2248             warnf(global, "Invalid character is found in given range. "
2249                   "A specified range MUST have only digits in "
2250                   "\'start\'-\'stop\'. The server's response to this "
2251                   "request is uncertain.\n");
2252             break;
2253           }
2254           tmp_range++;
2255         }
2256         GetStr(&config->range, nextarg);
2257       }
2258       break;
2259     case 'R':
2260       /* use remote file's time */
2261       config->remote_time = toggle;
2262       break;
2263     case 's': /* --silent */
2264       global->silent = toggle;
2265       break;
2266     case 'S': /* --show-error */
2267       global->showerror = toggle;
2268       break;
2269     case 't':
2270       /* Telnet options */
2271       err = add2list(&config->telnet_options, nextarg);
2272       if(err)
2273         return err;
2274       break;
2275     case 'T':
2276       /* we are uploading */
2277     {
2278       struct getout *url;
2279       if(!config->url_ul)
2280         config->url_ul = config->url_list;
2281       if(config->url_ul) {
2282         /* there's a node here, if it already is filled-in continue to find
2283            an "empty" node */
2284         while(config->url_ul && (config->url_ul->flags & GETOUT_UPLOAD))
2285           config->url_ul = config->url_ul->next;
2286       }
2287 
2288       /* now there might or might not be an available node to fill in! */
2289 
2290       if(config->url_ul)
2291         /* existing node */
2292         url = config->url_ul;
2293       else
2294         /* there was no free node, create one! */
2295         config->url_ul = url = new_getout(config);
2296 
2297       if(!url)
2298         return PARAM_NO_MEM;
2299 
2300       url->flags |= GETOUT_UPLOAD; /* mark -T used */
2301       if(!*nextarg)
2302         url->flags |= GETOUT_NOUPLOAD;
2303       else {
2304         /* "-" equals stdin, but keep the string around for now */
2305         GetStr(&url->infile, nextarg);
2306       }
2307     }
2308     break;
2309     case 'u':
2310       /* user:password  */
2311       GetStr(&config->userpwd, nextarg);
2312       cleanarg(clearthis);
2313       break;
2314     case 'U':
2315       /* Proxy user:password  */
2316       GetStr(&config->proxyuserpwd, nextarg);
2317       cleanarg(clearthis);
2318       break;
2319     case 'v':
2320       if(toggle) {
2321         /* the '%' thing here will cause the trace get sent to stderr */
2322         Curl_safefree(global->trace_dump);
2323         global->trace_dump = strdup("%");
2324         if(!global->trace_dump)
2325           return PARAM_NO_MEM;
2326         if(global->tracetype && (global->tracetype != TRACE_PLAIN))
2327           warnf(global,
2328                 "-v, --verbose overrides an earlier trace/verbose option\n");
2329         global->tracetype = TRACE_PLAIN;
2330       }
2331       else
2332         /* verbose is disabled here */
2333         global->tracetype = TRACE_NONE;
2334       break;
2335     case 'V':
2336       if(toggle)    /* --no-version yields no output! */
2337         return PARAM_VERSION_INFO_REQUESTED;
2338       break;
2339 
2340     case 'w':
2341       /* get the output string */
2342       if('@' == *nextarg) {
2343         /* the data begins with a '@' letter, it means that a file name
2344            or - (stdin) follows */
2345         FILE *file;
2346         const char *fname;
2347         nextarg++; /* pass the @ */
2348         if(!strcmp("-", nextarg)) {
2349           fname = "<stdin>";
2350           file = stdin;
2351         }
2352         else {
2353           fname = nextarg;
2354           file = fopen(nextarg, FOPEN_READTEXT);
2355         }
2356         Curl_safefree(config->writeout);
2357         err = file2string(&config->writeout, file);
2358         if(file && (file != stdin))
2359           fclose(file);
2360         if(err)
2361           return err;
2362         if(!config->writeout)
2363           warnf(global, "Failed to read %s", fname);
2364       }
2365       else
2366         GetStr(&config->writeout, nextarg);
2367       break;
2368     case 'x':
2369       switch(subletter) {
2370       case 'a': /* --preproxy */
2371         GetStr(&config->preproxy, nextarg);
2372         break;
2373       default:
2374         /* --proxy */
2375         GetStr(&config->proxy, nextarg);
2376         config->proxyver = CURLPROXY_HTTP;
2377         break;
2378       }
2379       break;
2380     case 'X':
2381       /* set custom request */
2382       GetStr(&config->customrequest, nextarg);
2383       break;
2384     case 'y':
2385       /* low speed time */
2386       err = str2unum(&config->low_speed_time, nextarg);
2387       if(err)
2388         return err;
2389       if(!config->low_speed_limit)
2390         config->low_speed_limit = 1;
2391       break;
2392     case 'Y':
2393       /* low speed limit */
2394       err = str2unum(&config->low_speed_limit, nextarg);
2395       if(err)
2396         return err;
2397       if(!config->low_speed_time)
2398         config->low_speed_time = 30;
2399       break;
2400     case 'Z':
2401       switch(subletter) {
2402       case '\0':  /* --parallel */
2403         global->parallel = toggle;
2404         break;
2405       case 'b':   /* --parallel-max */
2406         err = str2unum(&global->parallel_max, nextarg);
2407         if(err)
2408           return err;
2409         if(global->parallel_max > MAX_PARALLEL)
2410           global->parallel_max = MAX_PARALLEL;
2411         else if(global->parallel_max < 1)
2412           global->parallel_max = PARALLEL_DEFAULT;
2413         break;
2414       case 'c':   /* --parallel-connect */
2415         global->parallel_connect = toggle;
2416         break;
2417       }
2418       break;
2419     case 'z': /* time condition coming up */
2420       switch(*nextarg) {
2421       case '+':
2422         nextarg++;
2423         /* FALLTHROUGH */
2424       default:
2425         /* If-Modified-Since: (section 14.28 in RFC2068) */
2426         config->timecond = CURL_TIMECOND_IFMODSINCE;
2427         break;
2428       case '-':
2429         /* If-Unmodified-Since:  (section 14.24 in RFC2068) */
2430         config->timecond = CURL_TIMECOND_IFUNMODSINCE;
2431         nextarg++;
2432         break;
2433       case '=':
2434         /* Last-Modified:  (section 14.29 in RFC2068) */
2435         config->timecond = CURL_TIMECOND_LASTMOD;
2436         nextarg++;
2437         break;
2438       }
2439       now = time(NULL);
2440       config->condtime = (curl_off_t)curl_getdate(nextarg, &now);
2441       if(-1 == config->condtime) {
2442         /* now let's see if it is a file name to get the time from instead! */
2443         curl_off_t filetime = getfiletime(nextarg, global);
2444         if(filetime >= 0) {
2445           /* pull the time out from the file */
2446           config->condtime = filetime;
2447         }
2448         else {
2449           /* failed, remove time condition */
2450           config->timecond = CURL_TIMECOND_NONE;
2451           warnf(global,
2452                 "Illegal date format for -z, --time-cond (and not "
2453                 "a file name). Disabling time condition. "
2454                 "See curl_getdate(3) for valid date syntax.\n");
2455         }
2456       }
2457       break;
2458     default: /* unknown flag */
2459       return PARAM_OPTION_UNKNOWN;
2460     }
2461     hit = -1;
2462 
2463   } while(!longopt && !singleopt && *++parse && !*usedarg);
2464 
2465   return PARAM_OK;
2466 }
2467 
parse_args(struct GlobalConfig * global,int argc,argv_item_t argv[])2468 ParameterError parse_args(struct GlobalConfig *global, int argc,
2469                           argv_item_t argv[])
2470 {
2471   int i;
2472   bool stillflags;
2473   char *orig_opt = NULL;
2474   ParameterError result = PARAM_OK;
2475   struct OperationConfig *config = global->first;
2476 
2477   for(i = 1, stillflags = TRUE; i < argc && !result; i++) {
2478     orig_opt = curlx_convert_tchar_to_UTF8(argv[i]);
2479     if(!orig_opt)
2480       return PARAM_NO_MEM;
2481 
2482     if(stillflags && ('-' == orig_opt[0])) {
2483       bool passarg;
2484 
2485       if(!strcmp("--", orig_opt))
2486         /* This indicates the end of the flags and thus enables the
2487            following (URL) argument to start with -. */
2488         stillflags = FALSE;
2489       else {
2490         char *nextarg = NULL;
2491         if(i < (argc - 1)) {
2492           nextarg = curlx_convert_tchar_to_UTF8(argv[i + 1]);
2493           if(!nextarg) {
2494             curlx_unicodefree(orig_opt);
2495             return PARAM_NO_MEM;
2496           }
2497         }
2498 
2499         result = getparameter(orig_opt, nextarg, argv[i + 1], &passarg,
2500                               global, config);
2501 
2502         curlx_unicodefree(nextarg);
2503         config = global->last;
2504         if(result == PARAM_NEXT_OPERATION) {
2505           /* Reset result as PARAM_NEXT_OPERATION is only used here and not
2506              returned from this function */
2507           result = PARAM_OK;
2508 
2509           if(config->url_list && config->url_list->url) {
2510             /* Allocate the next config */
2511             config->next = malloc(sizeof(struct OperationConfig));
2512             if(config->next) {
2513               /* Initialise the newly created config */
2514               config_init(config->next);
2515 
2516               /* Set the global config pointer */
2517               config->next->global = global;
2518 
2519               /* Update the last config pointer */
2520               global->last = config->next;
2521 
2522               /* Move onto the new config */
2523               config->next->prev = config;
2524               config = config->next;
2525             }
2526             else
2527               result = PARAM_NO_MEM;
2528           }
2529           else {
2530             errorf(global, "missing URL before --next\n");
2531             result = PARAM_BAD_USE;
2532           }
2533         }
2534         else if(!result && passarg)
2535           i++; /* we're supposed to skip this */
2536       }
2537     }
2538     else {
2539       bool used;
2540 
2541       /* Just add the URL please */
2542       result = getparameter("--url", orig_opt, argv[i], &used, global, config);
2543     }
2544 
2545     if(!result)
2546       curlx_unicodefree(orig_opt);
2547   }
2548 
2549   if(!result && config->content_disposition) {
2550     if(config->show_headers)
2551       result = PARAM_CONTDISP_SHOW_HEADER;
2552     else if(config->resume_from_current)
2553       result = PARAM_CONTDISP_RESUME_FROM;
2554   }
2555 
2556   if(result && result != PARAM_HELP_REQUESTED &&
2557      result != PARAM_MANUAL_REQUESTED &&
2558      result != PARAM_VERSION_INFO_REQUESTED &&
2559      result != PARAM_ENGINES_REQUESTED) {
2560     const char *reason = param2text(result);
2561 
2562     if(orig_opt && strcmp(":", orig_opt))
2563       helpf(stderr, "option %s: %s\n", orig_opt, reason);
2564     else
2565       helpf(stderr, "%s\n", reason);
2566   }
2567 
2568   curlx_unicodefree(orig_opt);
2569   return result;
2570 }
2571