项目github: https://github.com/EZLippi/Tinyhttpd



1. 简介

Tinyhttpd 是J. David Blackstone在1999年写的一个不到 500 行的超轻量型 Http Server,比较适合初学者学习。


This software is copyright 1999 by J. David Blackstone. Permission is granted to redistribute and modify this software under the terms of the GNU General Public License, available at http://www.gnu.org/ .

If you use this software or examine the code, I would appreciate knowing and would be overjoyed to hear about it at jdavidb@sourceforge.net .

This software is not production quality. It comes with no warranty of any kind, not even an implied warranty of fitness for a particular purpose. I am not responsible for the damage that will likely result if you use this software on your computer system.

I wrote this webserver for an assignment in my networking class in 1999. We were told that at a bare minimum the server had to serve pages, and told that we would get extra credit for doing "extras." Perl had introduced me to a whole lot of UNIX functionality (I learned sockets and fork from Perl!), and O'Reilly's lion book on UNIX system calls plus O'Reilly's books on CGI and writing web clients in Perl got me thinking and I realized I could make my webserver support CGI with little trouble.

Now, if you're a member of the Apache core group, you might not be impressed. But my professor was blown over. Try the color.cgi sample script and type in "chartreuse." Made me seem smarter than I am, at any rate. :)

Apache it's not. But I do hope that this program is a good educational tool for those interested in http/socket programming, as well as UNIX system calls. (There's some textbook uses of pipes, environment variables, forks, and so on.)

One last thing: if you look at my webserver or (are you out of mind?!?) use it, I would just be overjoyed to hear about it. Please email me. I probably won't really be releasing major updates, but if I help you learn something, I'd love to know!

Happy hacking!

2. Tinyhttp运作流程



(1) 服务器启动,在指定端口或随机选取端口绑定 httpd 服务。

(2) 收到一个 HTTP 请求时(其实就是 listen 的端口 accpet 的时候),派生一个线程运行 accept_request 函数。

(3) 取出 HTTP 请求中的 method (GET 或 POST) 和 url,。对于 GET 方法,如果有携带参数,则 query_string 指针指向 url 中 ? 后面的 GET 参数。

(4) 格式化 url 到 path 数组,表示浏览器请求的服务器文件路径,在 tinyhttpd 中服务器文件是在 htdocs 文件夹下。当 url 以 / 结尾,或 url 是个目录,则默认在 path 中加上 index.html,表示访问主页。

(5) 如果文件路径合法,对于无参数的 GET 请求,直接输出服务器文件到浏览器,即用 HTTP 格式写到套接字上,跳到(10)。其他情况(带参数 GET,POST 方式,url 为可执行文件),则调用 excute_cgi 函数执行 cgi 脚本。

(6) 读取整个 HTTP 请求并丢弃,如果是 POST 则找出 Content-Length. 把 HTTP 200 状态码写到套接字。

(7) 建立两个管道,cgi_input 和 cgi_output, 并 fork 一个进程。

(8) 在子进程中,把 STDOUT 重定向到 cgi_outputt 的写入端,把 STDIN 重定向到 cgi_input 的读取端,关闭 cgi_input 的写入端 和 cgi_output 的读取端,设置 request_method 的环境变量,GET 的话设置 query_string 的环境变量,POST 的话设置 content_length 的环境变量,这些环境变量都是为了给 cgi 脚本调用,接着用 execl 运行 cgi 程序。

(9) 在父进程中,关闭 cgi_input 的读取端 和 cgi_output 的写入端,如果 POST 的话,把 POST 数据写入 cgi_input,已被重定向到 STDIN,读取 cgi_output 的管道输出到客户端,该管道输入是 STDOUT。接着关闭所有管道,等待子进程结束。这一部分比较乱,见下图说明:

图 1 管道初始状态

图 2 管道最终状态

(10) 关闭与浏览器的连接,完成了一次 HTTP 请求与回应,因为 HTTP 是无连接的。

3. 注意

(1) 修改相关文件的权限


if( (st.st_mode & S_IXUSR) || (st.st_mode & S_IXGRP) ||(st.st_mode & S_IXOTH)){
		//S_IXUSR    00100     owner has execute permission
		//S_IXGRP    00010     group has execute permission
		//S_IXOTH    00001     others have execute permission
		cgi = 1;

因此需要先将index.html的运行权限去除,使用命令 chmod 600 index.html


(2) color.cgi修改




#!/usr/local/bin/perl -Tw


#!/usr/bin/perl -Tw


4. 食用流程

(1) 直接拷贝或者自行敲码

(2) 修改相关文件权限和perl代码(上面有写)

(3) 在项目目录下使用makefile构建

[root@localhost Myhttpd]# make clean
rm httpd
[root@localhost Myhttpd]# make
gcc -g -W -Wall -pthread  -o httpd httpd.c

(4) 运行

[root@localhost Myhttpd]# ./httpd
httpd running on port: 60555

(5) 测试


2) GET

5. 代码


#include <stdio.h>
#include <sys/socket.h>
#include <sys/types.h>
#include <netinet/in.h>
#include <arpa/inet.h>
#include <unistd.h>
#include <ctype.h>
#include <strings.h>
#include <string.h>
#include <sys/stat.h>
#include <pthread.h>
#include <sys/wait.h>
#include <stdlib.h>
#include <stdint.h>

#define ISspace(x) isspace((int)(x))
#define SERVER_STRING "Server: jdbhttpd/0.1.0rn"
#define STDIN   0
#define STDOUT  1
#define STDERR  2

void accept_request(void *arg);
void bad_request(int);
void cat(int, FILE *);
void cannot_execute(int);
void execute_cgi(int, const char *, const char *, const char *);
void headers(int, const char *);
int startup(u_short *);
int get_line(int, char *, int);
void unimplemented(int );
void error_die(const char *);
void not_found(int );
void serve_file(int , const char *);

// Http请求的信息
// GET请求
// GET / HTTP/1.1
// Host:
// Connection: keep-alive
// Upgrade-Insecure-Requests: 1
// User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36
// Accept: text/html,application/xhtml xml,application/xml;q=0.9,image/webp,*/*; q = 0.8
// Accept - Encoding: gzip, deflate, sdch
// Accept - Language : zh - CN, zh; q = 0.8
// Cookie: __guid = 179317988.1576506943281708800.1510107225903.8862; monitor_count = 5
// POST请求
// POST / color1.cgi HTTP / 1.1
// Host: : 47310
// Connection : keep - alive
// Content - Length : 10
// Cache - Control : max - age = 0
// Origin : http ://
// Upgrade - Insecure - Requests : 1
// User - Agent : Mozilla / 5.0 (Windows NT 6.1; WOW64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 55.0.2883.87 Safari / 537.36
// Content - Type : application / x - www - form - urlencoded
// Accept : text / html, application / xhtml   xml, application / xml; q = 0.9, image / webp, */*;q=0.8
// Referer:
// Accept-Encoding: gzip, deflate
// Accept-Language: zh-CN,zh;q=0.8
// Cookie: __guid=179317988.1576506943281708800.1510107225903.8862; monitor_count=281
// Form Data
// color=gray

void accept_request(void *arg){
	int client = (intptr_t)arg;
	char buf[1024];				//读取客户端发送的内容
	char method[255];			//保存请求方法
	char url[255];				//保存请求的url
	char path[512];				//请求路径
	size_t i,j;
	struct stat st;				//查询文件的数据结构
	int cgi = 0;				//是否调用cgi程序
	char *query_string = NULL;	//
	int numchars = 1;				

	//读取http请求的第一行数据(request line),然后把请求方法存进method
	//请求方法 URL 协议版本rn
	numchars = get_line(client, buf, sizeof(buf));
	i = 0; j = 0;
	while(!ISspace(buf[j]) && (i < sizeof(method) -1) ){
		method[i] = buf[j];
		i  ; j  ;
	method[i] = '';
	if(!strcasecmp(method, "GET") == 0 && !strcasecmp(method, "POST") == 0){
		return ;
	if(strcasecmp(method, "POST") == 0){
		cgi = 1;
	i = 0;
	while(ISspace(buf[j]) && (j < sizeof(buf))){
		j  ;
	while(!ISspace(buf[j]) && (i < sizeof(url) - 1) && (j < sizeof(buf))){
		url[i] = buf[j];
		i  ; j  ;
	url[i] = '';
	if(strcasecmp(method, "GET") == 0){
		query_string = url;
		while((*query_string != '?') && (*query_string != '')){
			query_string  ;
		if(*query_string == '?'){
			cgi = 1;
			*query_string = '';
			query_string  ;
	sprintf(path, "htdocs%s", url);
	if(path[strlen(path) - 1] == '/'){
		strcat(path, "index.html");
	if(stat(path, &st) == -1){
		while((numchars > 0) && strcmp("n", buf)){
			numchars = get_line(client, buf, sizeof(buf));
	} else{	//如果存在
		if((st.st_mode & S_IFMT) == S_IFDIR){
			strcat(path, "/index.html");
		if( (st.st_mode & S_IXUSR) || (st.st_mode & S_IXGRP) ||(st.st_mode & S_IXOTH)){
			//S_IXUSR    00100     owner has execute permission
			//S_IXGRP    00010     group has execute permission
			//S_IXOTH    00001     others have execute permission
			//如果是可执行文件,无论是属于用户/组/其他 这三种类型的,将cgi置1
			cgi = 1;
			serve_file(client, path);
		} else{
			execute_cgi(client, path, method, query_string);
	printf("close client!n");

/* Execute a CGI script.  Will need to set environment variables as
 * appropriate.
 * Parameters: client socket descriptor
 *             path to the CGI script */
void execute_cgi(int client, const char *path, const char *method, const char *query_string){
	char buf[1024];			//缓冲区
	int cgi_output[2];		//管道,用于进程交换数据
	int cgi_input[2];
	pid_t pid;				//进程id
	int status;
	int i;
	char c;
	int numchars = 1;
	int content_length = -1;
	buf[0] = 'A';
	buf[1] = '';
	if (strcasecmp(method, "GET") == 0) {
		while ((numchars > 0) && strcmp("n", buf)){  /* read & discard headers */
			numchars = get_line(client, buf, sizeof(buf));
	} else if (strcasecmp(method, "POST") == 0){		//POST请求
		numchars = get_line(client, buf, sizeof(buf));

		//因为只是POST数据部分长度的请求头数据行为 Content-Length: XX
		while ((numchars > 0) && strcmp("n", buf)){
            buf[15] = '';
            if (strcasecmp(buf, "Content-Length:") == 0)
                content_length = atoi(&(buf[16]));		
            numchars = get_line(client, buf, sizeof(buf));
        if (content_length == -1) {
	} else{/*HEAD or other*/
	sprintf(buf, "HTTP/1.0 200 OKrn");
	send(client, buf, strlen(buf), 0);
	if(pipe(cgi_output) < 0){
	if(pipe(cgi_input) < 0){
	//       fork后管道都复制了一份,都是一样的
	//       子进程关闭2个无用的端口,避免浪费             
	//       ×<------------------------->1    output
	//       0<-------------------------->×   input 

	//       父进程关闭2个无用的端口,避免浪费             
	//       0<-------------------------->×   output
	//       ×<------------------------->1    input
	//       此时父子进程已经可以通信
	if( (pid = fork()) < 0){
		return ;
	if(pid == 0){				//子进程执行cgi脚本
		char meth_env[255];
		char query_env[255];
		char length_env[255];
		//将子进程的输出由标准输出重定向到 cgi_ouput 的管道写端上,1是stdout
		dup2(cgi_output[1], 1);
		//将子进程的输出由标准输入重定向到 cgi_ouput 的管道读端上,0是stdin
		dup2(cgi_input[0], 0);
		//关闭 cgi_ouput 管道的读端与cgi_input 管道的写端
		sprintf(meth_env, "REQUEST_METHOD=%s", method);
		if(strcasecmp(method, "GET") == 0){
			sprintf(query_env, "QUERY_STRING=%s", query_string);
		} else{	//POST
			sprintf(length_env, "CONTENT_LENGTH=%d", content_length);
		execl(path, path, NULL);
	} else{		//父进程
		close(cgi_output[1]);		//父进程关闭cgi_output管道的写端和cgi_input管道的读端
		//如果是 POST 方法的话就继续读 body 的内容,并写到 cgi_input 管道里让子进程去读
		if(strcasecmp(method, "POST") == 0){
			for(i = 0; i < content_length; i  ){
				recv(client, &c, 1, 0);
				write(cgi_input[1], &c, 1);
		while (read(cgi_output[0], &c, 1) > 0){
			send(client, &c, 1, 0);
		close(cgi_output[0]);			//关闭管道
        waitpid(pid, &status, 0);		//等待子进程的退出
//	printf("end cgin");

/* Inform the client that a request it has made has a problem.
 * Parameters: client socket */
void bad_request(int client){
    char buf[1024];

    sprintf(buf, "HTTP/1.0 400 BAD REQUESTrn");
    send(client, buf, sizeof(buf), 0);
    sprintf(buf, "Content-type: text/html;rn");
    send(client, buf, sizeof(buf), 0);
    sprintf(buf, "rn");
    send(client, buf, sizeof(buf), 0);
    sprintf(buf, "<P>Your browser sent a bad request, ");
    send(client, buf, sizeof(buf), 0);
    sprintf(buf, "such as a POST without a Content-Length.rn");
    send(client, buf, sizeof(buf), 0);

/* Inform the client that a CGI script could not be executed.
 * Parameter: the client socket descriptor. */
void cannot_execute(int client){
    char buf[1024];

    sprintf(buf, "HTTP/1.0 500 Internal Server Errorrn");
    send(client, buf, strlen(buf), 0);
    sprintf(buf, "Content-type: text/htmlrn");
    send(client, buf, strlen(buf), 0);
    sprintf(buf, "rn");
    send(client, buf, strlen(buf), 0);
    sprintf(buf, "<P>Error prohibited CGI execution.rn");
    send(client, buf, strlen(buf), 0);

void serve_file(int client, const char *filename){
	FILE *resource = NULL;
	int numchars = 1;
	char buf[1024];
	buf[0] = 'A';
	buf[1] = '';
	while((numchars > 0) && strcmp("n", buf)){
		numchars = get_line(client, buf, sizeof(buf));
	resource = fopen(filename, "r");
	if(resource == NULL){	//打开失败
	} else{					//打开成功
		headers(client, filename);
		cat(client, resource);

/* Return the informational HTTP headers about a file. */
/* Parameters: the socket to print the headers on
 *             the name of the file */
void headers(int client, const char *filename){
	char buf[1024];
	(void)filename;  /* could use filename to determine file type */
	strcpy(buf, "HTTP/1.0 200 OKrn");
	send(client, buf, strlen(buf), 0);
	strcpy(buf, SERVER_STRING);
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "Content-Type: text/htmlrn");
	send(client, buf, strlen(buf), 0);
	strcpy(buf, "rn");
	send(client, buf, strlen(buf), 0);

/* Put the entire contents of a file out on a socket.  This function
 * is named after the UNIX "cat" command, because it might have been
 * easier just to do something like pipe, fork, and exec("cat").
 * Parameters: the client socket descriptor
 *             FILE pointer for the file to cat */
void cat(int client, FILE *resource){
	char buf[1024];

	fgets(buf, sizeof(buf), resource);
	while (!feof(resource)){
		send(client, buf, strlen(buf), 0);
		fgets(buf, sizeof(buf), resource);

/* Inform the client that the requested web method has not been
 * implemented.
 * Parameter: the client socket */
void unimplemented(int client){
	char buf[1024];

	sprintf(buf, "HTTP/1.0 501 Method Not Implementedrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, SERVER_STRING);
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "Content-Type: text/htmlrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "<HTML><HEAD><TITLE>Method Not Implementedrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "</TITLE></HEAD>rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "<BODY><P>HTTP request method not supported.rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "</BODY></HTML>rn");
	send(client, buf, strlen(buf), 0);

/* Give a client a 404 not found status message. */
void not_found(int client){
	char buf[1024];

	sprintf(buf, "HTTP/1.0 404 NOT FOUNDrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, SERVER_STRING);
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "Content-Type: text/htmlrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "<HTML><TITLE>Not Found</TITLE>rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "<BODY><P>The server could not fulfillrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "your request because the resource specifiedrn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "is unavailable or nonexistent.rn");
	send(client, buf, strlen(buf), 0);
	sprintf(buf, "</BODY></HTML>rn");
	send(client, buf, strlen(buf), 0);

int get_line(int sock, char *buf, int size){
	int i = 0;
    char c = '';
    int n;

    while ((i < size - 1) && (c != 'n')){
        n = recv(sock, &c, 1, 0);
        /* DEBUG printf("Xn", c); */
        if (n > 0){
            if (c == 'r'){
                n = recv(sock, &c, 1, MSG_PEEK);
                /* DEBUG printf("Xn", c); */
                if ((n > 0) && (c == 'n'))
                    recv(sock, &c, 1, 0);
                    c = 'n';
            buf[i] = c;
            i  ;
            c = 'n';
    buf[i] = '';

int startup(u_short *port){
	int httpd = 0;
	struct sockaddr_in name;
	httpd = socket(AF_INET, SOCK_STREAM, 0);
	if(httpd == -1){
	memset(&name, 0, sizeof(name));
	name.sin_family = AF_INET;
	name.sin_port = htons(*port);
	name.sin_addr.s_addr = htonl(INADDR_ANY);
	// 设置套接字选项避免地址使用错误  
//    int on=1;  
//   if((setsockopt(httpd,SOL_SOCKET,SO_REUSEADDR,&on,sizeof(on)))<0)  {  
//        error_die("setsockopt failed");  
//        exit(EXIT_FAILURE);  
//    }  
	if(bind(httpd, (struct sockaddr *)&name, sizeof(name)) < 0){
	if (*port == 0) { /* if dynamically allocating a port */ 
		socklen_t  namelen = sizeof(name);
			if (getsockname(httpd, (struct sockaddr *)&name, &namelen) == -1)
		*port = ntohs(name.sin_port);
	if(listen(httpd, 5) < 0){
//	printf("start up OK!n");
	return httpd;

void error_die(const char *sc){
	//包含于<stdio.h>,基于当前的 errno 值,在标准错误上产生一条错误消息。参考《TLPI》P49

int main(void){
	int server_sock = -1;			//服务器的sock文件描述符
	u_short port = 0;
	int client_sock = -1;			//客户端的sock文件描述符
	struct sockaddr_in client_name;	//客户端套接字标签数据结构
	char client_ip[64];				//客户端的ip
	socklen_t client_name_len = sizeof(client_name);
	pthread_t newthread;
	server_sock = startup(&port);	//获得监听sock文件描述符
	printf("httpd running on port: %dn", port);
		client_sock = accept(server_sock, (struct sockaddr *)&client_name, &client_name_len);
		printf("client ip : %st port : %dn",
			inet_ntop(AF_INET, &client_name.sin_addr.s_addr,client_ip,sizeof(client_ip)),
		if(client_sock == -1)
		if (pthread_create(&newthread, NULL, (void *)accept_request, (void *)(intptr_t)client_sock) != 0)
	return 0;

6. 相关

涉及到的有 socket通信, 多进程,多线程(pthread),进程管道通信,http中GET,POST相关数据格式等

