• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /***************************************************************************
2  *                                  _   _ ____  _
3  *  Project                     ___| | | |  _ \| |
4  *                             / __| | | | |_) | |
5  *                            | (__| |_| |  _ <| |___
6  *                             \___|\___/|_| \_\_____|
7  *
8  * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
9  *
10  * This software is licensed as described in the file COPYING, which
11  * you should have received as part of this distribution. The terms
12  * are also available at https://curl.se/docs/copyright.html.
13  *
14  * You may opt to use, copy, modify, merge, publish, distribute and/or sell
15  * copies of the Software, and permit persons to whom the Software is
16  * furnished to do so, under the terms of the COPYING file.
17  *
18  * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
19  * KIND, either express or implied.
20  *
21  * SPDX-License-Identifier: curl AND ISC
22  *
23  ***************************************************************************/
24 
25 #include "curl_setup.h"
26 
27 #if defined(USE_SSH)
28 
29 #include <curl/curl.h>
30 #include "curl_memory.h"
31 #include "curl_path.h"
32 #include "escape.h"
33 #include "memdebug.h"
34 
35 #define MAX_SSHPATH_LEN 100000 /* arbitrary */
36 
37 /* figure out the path to work with in this particular request */
Curl_getworkingpath(struct Curl_easy * data,char * homedir,char ** path)38 CURLcode Curl_getworkingpath(struct Curl_easy *data,
39                              char *homedir,  /* when SFTP is used */
40                              char **path) /* returns the  allocated
41                                              real path to work with */
42 {
43   char *working_path;
44   size_t working_path_len;
45   struct dynbuf npath;
46   CURLcode result =
47     Curl_urldecode(data->state.up.path, 0, &working_path,
48                    &working_path_len, REJECT_ZERO);
49   if(result)
50     return result;
51 
52   /* new path to switch to in case we need to */
53   Curl_dyn_init(&npath, MAX_SSHPATH_LEN);
54 
55   /* Check for /~/, indicating relative to the user's home directory */
56   if((data->conn->handler->protocol & CURLPROTO_SCP) &&
57      (working_path_len > 3) && (!memcmp(working_path, "/~/", 3))) {
58     /* It is referenced to the home directory, so strip the leading '/~/' */
59     if(Curl_dyn_addn(&npath, &working_path[3], working_path_len - 3)) {
60       free(working_path);
61       return CURLE_OUT_OF_MEMORY;
62     }
63   }
64   else if((data->conn->handler->protocol & CURLPROTO_SFTP) &&
65           (working_path_len > 2) && !memcmp(working_path, "/~/", 3)) {
66     size_t len;
67     const char *p;
68     int copyfrom = 3;
69     if(Curl_dyn_add(&npath, homedir)) {
70       free(working_path);
71       return CURLE_OUT_OF_MEMORY;
72     }
73     /* Copy a separating '/' if homedir does not end with one */
74     len = Curl_dyn_len(&npath);
75     p = Curl_dyn_ptr(&npath);
76     if(len && (p[len-1] != '/'))
77       copyfrom = 2;
78 
79     if(Curl_dyn_addn(&npath,
80                      &working_path[copyfrom], working_path_len - copyfrom)) {
81       free(working_path);
82       return CURLE_OUT_OF_MEMORY;
83     }
84   }
85 
86   if(Curl_dyn_len(&npath)) {
87     free(working_path);
88 
89     /* store the pointer for the caller to receive */
90     *path = Curl_dyn_ptr(&npath);
91   }
92   else
93     *path = working_path;
94 
95   return CURLE_OK;
96 }
97 
98 /* The get_pathname() function is being borrowed from OpenSSH sftp.c
99    version 4.6p1. */
100 /*
101  * Copyright (c) 2001-2004 Damien Miller <djm@openbsd.org>
102  *
103  * Permission to use, copy, modify, and distribute this software for any
104  * purpose with or without fee is hereby granted, provided that the above
105  * copyright notice and this permission notice appear in all copies.
106  *
107  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
108  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
109  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
110  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
111  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
112  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
113  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
114  */
Curl_get_pathname(const char ** cpp,char ** path,char * homedir)115 CURLcode Curl_get_pathname(const char **cpp, char **path, char *homedir)
116 {
117   const char *cp = *cpp, *end;
118   char quot;
119   unsigned int i, j;
120   size_t fullPathLength, pathLength;
121   bool relativePath = false;
122   static const char WHITESPACE[] = " \t\r\n";
123 
124   DEBUGASSERT(homedir);
125   if(!*cp || !homedir) {
126     *cpp = NULL;
127     *path = NULL;
128     return CURLE_QUOTE_ERROR;
129   }
130   /* Ignore leading whitespace */
131   cp += strspn(cp, WHITESPACE);
132   /* Allocate enough space for home directory and filename + separator */
133   fullPathLength = strlen(cp) + strlen(homedir) + 2;
134   *path = malloc(fullPathLength);
135   if(!*path)
136     return CURLE_OUT_OF_MEMORY;
137 
138   /* Check for quoted filenames */
139   if(*cp == '\"' || *cp == '\'') {
140     quot = *cp++;
141 
142     /* Search for terminating quote, unescape some chars */
143     for(i = j = 0; i <= strlen(cp); i++) {
144       if(cp[i] == quot) {  /* Found quote */
145         i++;
146         (*path)[j] = '\0';
147         break;
148       }
149       if(cp[i] == '\0') {  /* End of string */
150         goto fail;
151       }
152       if(cp[i] == '\\') {  /* Escaped characters */
153         i++;
154         if(cp[i] != '\'' && cp[i] != '\"' &&
155             cp[i] != '\\') {
156           goto fail;
157         }
158       }
159       (*path)[j++] = cp[i];
160     }
161 
162     if(j == 0) {
163       goto fail;
164     }
165     *cpp = cp + i + strspn(cp + i, WHITESPACE);
166   }
167   else {
168     /* Read to end of filename - either to whitespace or terminator */
169     end = strpbrk(cp, WHITESPACE);
170     if(!end)
171       end = strchr(cp, '\0');
172     /* return pointer to second parameter if it exists */
173     *cpp = end + strspn(end, WHITESPACE);
174     pathLength = 0;
175     relativePath = (cp[0] == '/' && cp[1] == '~' && cp[2] == '/');
176     /* Handling for relative path - prepend home directory */
177     if(relativePath) {
178       strcpy(*path, homedir);
179       pathLength = strlen(homedir);
180       (*path)[pathLength++] = '/';
181       (*path)[pathLength] = '\0';
182       cp += 3;
183     }
184     /* Copy path name up until first "whitespace" */
185     memcpy(&(*path)[pathLength], cp, (int)(end - cp));
186     pathLength += (int)(end - cp);
187     (*path)[pathLength] = '\0';
188   }
189   return CURLE_OK;
190 
191   fail:
192   Curl_safefree(*path);
193   return CURLE_QUOTE_ERROR;
194 }
195 
196 #endif /* if SSH is used */
197