Blob


1 /*
2 * Copyright (c) 2018 Stefan Sperling <stsp@openbsd.org>
3 *
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
7 *
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15 */
17 #include <sys/types.h>
18 #include <sys/queue.h>
19 #include <sys/uio.h>
20 #include <sys/syslimits.h>
21 #include <sys/wait.h>
23 #include <stdio.h>
24 #include <stdlib.h>
25 #include <string.h>
26 #include <errno.h>
27 #include <stdint.h>
28 #include <poll.h>
29 #include <imsg.h>
30 #include <sha1.h>
31 #include <zlib.h>
32 #include <time.h>
34 #include "got_object.h"
35 #include "got_error.h"
37 #include "got_lib_sha1.h"
38 #include "got_lib_delta.h"
39 #include "got_lib_inflate.h"
40 #include "got_lib_object.h"
41 #include "got_lib_object_parse.h"
42 #include "got_lib_privsep.h"
43 #include "got_lib_pack.h"
45 #ifndef MIN
46 #define MIN(_a,_b) ((_a) < (_b) ? (_a) : (_b))
47 #endif
49 static const struct got_error *
50 poll_fd(int fd, int events, int timeout)
51 {
52 struct pollfd pfd[1];
53 int n;
55 pfd[0].fd = fd;
56 pfd[0].events = events;
58 n = poll(pfd, 1, timeout);
59 if (n == -1)
60 return got_error_from_errno();
61 if (n == 0)
62 return got_error(GOT_ERR_TIMEOUT);
63 if (pfd[0].revents & (POLLERR | POLLNVAL))
64 return got_error_from_errno();
65 if (pfd[0].revents & (events | POLLHUP))
66 return NULL;
68 return got_error(GOT_ERR_INTERRUPT);
69 }
71 static const struct got_error *
72 read_imsg(struct imsgbuf *ibuf)
73 {
74 const struct got_error *err;
75 size_t n;
77 err = poll_fd(ibuf->fd, POLLIN, INFTIM);
78 if (err)
79 return err;
81 n = imsg_read(ibuf);
82 if (n == -1) {
83 if (errno == EAGAIN) /* Could be a file-descriptor leak. */
84 return got_error(GOT_ERR_PRIVSEP_NO_FD);
85 return got_error(GOT_ERR_PRIVSEP_READ);
86 }
87 if (n == 0)
88 return got_error(GOT_ERR_PRIVSEP_PIPE);
90 return NULL;
91 }
93 const struct got_error *
94 got_privsep_wait_for_child(pid_t pid)
95 {
96 int child_status;
98 waitpid(pid, &child_status, 0);
100 if (!WIFEXITED(child_status))
101 return got_error(GOT_ERR_PRIVSEP_DIED);
103 if (WEXITSTATUS(child_status) != 0)
104 return got_error(GOT_ERR_PRIVSEP_EXIT);
106 return NULL;
109 const struct got_error *
110 got_privsep_recv_imsg(struct imsg *imsg, struct imsgbuf *ibuf, size_t min_datalen)
112 const struct got_error *err;
113 ssize_t n;
115 n = imsg_get(ibuf, imsg);
116 if (n == -1)
117 return got_error_from_errno();
119 while (n == 0) {
120 err = read_imsg(ibuf);
121 if (err)
122 return err;
123 n = imsg_get(ibuf, imsg);
126 if (imsg->hdr.len < IMSG_HEADER_SIZE + min_datalen)
127 return got_error(GOT_ERR_PRIVSEP_LEN);
129 return NULL;
132 static const struct got_error *
133 recv_imsg_error(struct imsg *imsg, size_t datalen)
135 struct got_imsg_error ierr;
137 if (datalen != sizeof(ierr))
138 return got_error(GOT_ERR_PRIVSEP_LEN);
140 memcpy(&ierr, imsg->data, sizeof(ierr));
141 if (ierr.code == GOT_ERR_ERRNO) {
142 static struct got_error serr;
143 serr.code = GOT_ERR_ERRNO;
144 serr.msg = strerror(ierr.errno_code);
145 return &serr;
148 return got_error(ierr.code);
151 /* Attempt to send an error in an imsg. Complain on stderr as a last resort. */
152 void
153 got_privsep_send_error(struct imsgbuf *ibuf, const struct got_error *err)
155 const struct got_error *poll_err;
156 struct got_imsg_error ierr;
157 int ret;
159 ierr.code = err->code;
160 if (err->code == GOT_ERR_ERRNO)
161 ierr.errno_code = errno;
162 else
163 ierr.errno_code = 0;
164 ret = imsg_compose(ibuf, GOT_IMSG_ERROR, 0, 0, -1, &ierr, sizeof(ierr));
165 if (ret != -1) {
166 fprintf(stderr, "%s: error %d \"%s\": imsg_compose: %s\n",
167 getprogname(), err->code, err->msg, strerror(errno));
168 return;
171 poll_err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
172 if (poll_err) {
173 fprintf(stderr, "%s: error %d \"%s\": poll: %s\n",
174 getprogname(), err->code, err->msg, poll_err->msg);
175 return;
178 ret = imsg_flush(ibuf);
179 if (ret == -1) {
180 fprintf(stderr, "%s: error %d \"%s\": imsg_flush: %s\n",
181 getprogname(), err->code, err->msg, strerror(errno));
182 return;
186 static const struct got_error *
187 flush_imsg(struct imsgbuf *ibuf)
189 const struct got_error *err;
191 err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
192 if (err)
193 return err;
195 if (imsg_flush(ibuf) == -1)
196 return got_error_from_errno();
198 return NULL;
201 const struct got_error *
202 got_privsep_send_stop(int fd)
204 const struct got_error *err = NULL;
205 struct imsgbuf ibuf;
207 imsg_init(&ibuf, fd);
209 if (imsg_compose(&ibuf, GOT_IMSG_STOP, 0, 0, -1, NULL, 0) == -1)
210 return got_error_from_errno();
212 err = flush_imsg(&ibuf);
213 imsg_clear(&ibuf);
214 return err;
217 static const struct got_error *
218 send_delta(struct got_delta *delta, struct imsgbuf *ibuf)
220 struct got_imsg_delta idelta;
221 size_t offset, remain;
223 idelta.offset = delta->offset;
224 idelta.tslen = delta->tslen;
225 idelta.type = delta->type;
226 idelta.size = delta->size;
227 idelta.data_offset = delta->data_offset;
228 idelta.delta_len = delta->delta_len;
230 if (imsg_compose(ibuf, GOT_IMSG_DELTA, 0, 0, -1,
231 &idelta, sizeof(idelta)) == -1)
232 return got_error_from_errno();
234 if (imsg_flush(ibuf) == -1)
235 return got_error_from_errno();
237 offset = 0;
238 remain = delta->delta_len;
239 while (remain > 0) {
240 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
242 if (imsg_compose(ibuf, GOT_IMSG_DELTA_STREAM, 0, 0, -1,
243 delta->delta_buf + offset, n) == -1)
244 return got_error_from_errno();
246 if (imsg_flush(ibuf) == -1)
247 return got_error_from_errno();
249 offset += n;
250 remain -= n;
253 return NULL;
256 const struct got_error *
257 got_privsep_send_obj_req(struct imsgbuf *ibuf, int fd, struct got_object *obj)
259 const struct got_error *err = NULL;
260 struct got_imsg_object iobj, *iobjp = NULL;
261 size_t iobj_size = 0;
262 int imsg_code = GOT_IMSG_OBJECT_REQUEST;
264 if (obj) {
265 switch (obj->type) {
266 case GOT_OBJ_TYPE_TREE:
267 imsg_code = GOT_IMSG_TREE_REQUEST;
268 break;
269 case GOT_OBJ_TYPE_COMMIT:
270 imsg_code = GOT_IMSG_COMMIT_REQUEST;
271 break;
272 case GOT_OBJ_TYPE_BLOB:
273 imsg_code = GOT_IMSG_BLOB_REQUEST;
274 break;
275 default:
276 return got_error(GOT_ERR_OBJ_TYPE);
279 iobj.type = obj->type;
280 iobj.flags = obj->flags;
281 iobj.hdrlen = obj->hdrlen;
282 iobj.size = obj->size;
283 iobj.ndeltas = obj->deltas.nentries;
284 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
285 iobj.pack_offset = obj->pack_offset;
287 iobjp = &iobj;
288 iobj_size = sizeof(iobj);
291 if (imsg_compose(ibuf, imsg_code, 0, 0, fd, iobjp, iobj_size) == -1)
292 return got_error_from_errno();
294 err = flush_imsg(ibuf);
295 if (err)
296 return err;
298 if (obj && obj->flags & GOT_OBJ_FLAG_DELTIFIED) {
299 struct got_delta *delta;
300 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
301 err = send_delta(delta, ibuf);
302 if (err)
303 break;
307 return err;
310 const struct got_error *
311 got_privsep_send_blob_req(struct imsgbuf *ibuf, int infd)
313 if (imsg_compose(ibuf, GOT_IMSG_BLOB_REQUEST, 0, 0, infd, NULL, 0)
314 == -1)
315 return got_error_from_errno();
317 return flush_imsg(ibuf);
320 const struct got_error *
321 got_privsep_send_blob_outfd(struct imsgbuf *ibuf, int outfd)
323 if (imsg_compose(ibuf, GOT_IMSG_BLOB_OUTFD, 0, 0, outfd, NULL, 0)
324 == -1)
325 return got_error_from_errno();
327 return flush_imsg(ibuf);
330 const struct got_error *
331 got_privsep_send_obj(struct imsgbuf *ibuf, struct got_object *obj)
333 const struct got_error *err = NULL;
334 struct got_imsg_object iobj;
335 struct got_delta *delta;
337 iobj.type = obj->type;
338 iobj.flags = obj->flags;
339 iobj.hdrlen = obj->hdrlen;
340 iobj.size = obj->size;
341 iobj.ndeltas = obj->deltas.nentries;
342 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
343 iobj.pack_offset = obj->pack_offset;
345 if (imsg_compose(ibuf, GOT_IMSG_OBJECT, 0, 0, -1, &iobj, sizeof(iobj))
346 == -1)
347 return got_error_from_errno();
349 err = flush_imsg(ibuf);
350 if (err)
351 return err;
353 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
354 err = send_delta(delta, ibuf);
355 if (err)
356 break;
359 return err;
362 static const struct got_error *
363 receive_delta(struct got_delta **delta, struct imsgbuf *ibuf)
365 const struct got_error *err = NULL;
366 struct imsg imsg;
367 struct got_imsg_delta idelta;
368 uint8_t *delta_buf = NULL;
369 const size_t min_datalen =
370 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_delta));
371 size_t datalen, offset, remain;
373 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
374 if (err)
375 return err;
377 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
378 if (imsg.hdr.type == GOT_IMSG_ERROR)
379 return recv_imsg_error(&imsg, datalen);
381 if (imsg.hdr.type != GOT_IMSG_DELTA)
382 return got_error(GOT_ERR_PRIVSEP_MSG);
383 if (datalen != sizeof(idelta))
384 return got_error(GOT_ERR_PRIVSEP_LEN);
386 memcpy(&idelta, imsg.data, sizeof(idelta));
387 imsg_free(&imsg);
389 switch (idelta.type) {
390 case GOT_OBJ_TYPE_OFFSET_DELTA:
391 case GOT_OBJ_TYPE_REF_DELTA:
392 if (idelta.delta_len < GOT_DELTA_STREAM_LENGTH_MIN)
393 return got_error(GOT_ERR_BAD_DELTA);
394 break;
395 default:
396 if (idelta.delta_len != 0)
397 return got_error(GOT_ERR_BAD_DELTA);
398 break;
401 if (idelta.delta_len > 0) {
402 delta_buf = calloc(1, idelta.delta_len);
403 if (delta_buf == NULL)
404 return got_error_from_errno();
406 offset = 0;
407 remain = idelta.delta_len;
408 while (remain > 0) {
409 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
411 err = got_privsep_recv_imsg(&imsg, ibuf, n);
412 if (err)
413 return err;
415 if (imsg.hdr.type == GOT_IMSG_ERROR)
416 return recv_imsg_error(&imsg, datalen);
418 if (imsg.hdr.type == GOT_IMSG_STOP)
419 break;
421 if (imsg.hdr.type != GOT_IMSG_DELTA_STREAM)
422 return got_error(GOT_ERR_PRIVSEP_MSG);
424 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
425 if (datalen != n)
426 return got_error(GOT_ERR_PRIVSEP_LEN);
428 memcpy(delta_buf + offset, imsg.data, n);
429 imsg_free(&imsg);
431 offset += n;
432 remain -= n;
436 *delta = got_delta_open(idelta.offset, idelta.tslen, idelta.type,
437 idelta.size, idelta.data_offset, delta_buf, idelta.delta_len);
438 if (*delta == NULL) {
439 err = got_error_from_errno();
440 free(delta_buf);
443 return err;
446 const struct got_error *
447 got_privsep_get_imsg_obj(struct got_object **obj, struct imsg *imsg,
448 struct imsgbuf *ibuf)
450 const struct got_error *err = NULL;
451 struct got_imsg_object iobj;
452 size_t datalen = imsg->hdr.len - IMSG_HEADER_SIZE;
453 int i;
455 if (datalen != sizeof(iobj))
456 return got_error(GOT_ERR_PRIVSEP_LEN);
458 memcpy(&iobj, imsg->data, sizeof(iobj));
459 if (iobj.ndeltas < 0 ||
460 iobj.ndeltas > GOT_DELTA_CHAIN_RECURSION_MAX)
461 return got_error(GOT_ERR_PRIVSEP_LEN);
463 if (iobj.ndeltas > 0 &&
464 (iobj.flags & GOT_OBJ_FLAG_DELTIFIED) == 0)
465 return got_error(GOT_ERR_BAD_OBJ_DATA);
467 *obj = calloc(1, sizeof(**obj));
468 if (*obj == NULL)
469 return got_error_from_errno();
471 (*obj)->type = iobj.type;
472 (*obj)->flags = iobj.flags;
473 (*obj)->hdrlen = iobj.hdrlen;
474 (*obj)->size = iobj.size;
475 /* id and path_packfile might be copied in by caller */
476 (*obj)->pack_offset = iobj.pack_offset;
477 SIMPLEQ_INIT(&(*obj)->deltas.entries);
478 for (i = 0; i < iobj.ndeltas; i++) {
479 struct got_delta *delta;
480 err = receive_delta(&delta, ibuf);
481 if (err)
482 break;
483 (*obj)->deltas.nentries++;
484 SIMPLEQ_INSERT_TAIL(&(*obj)->deltas.entries, delta,
485 entry);
488 return err;
491 const struct got_error *
492 got_privsep_recv_obj(struct got_object **obj, struct imsgbuf *ibuf)
494 const struct got_error *err = NULL;
495 struct imsg imsg;
496 size_t datalen;
497 const size_t min_datalen =
498 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_object));
500 *obj = NULL;
502 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
503 if (err)
504 return err;
506 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
508 switch (imsg.hdr.type) {
509 case GOT_IMSG_ERROR:
510 err = recv_imsg_error(&imsg, datalen);
511 break;
512 case GOT_IMSG_OBJECT:
513 err = got_privsep_get_imsg_obj(obj, &imsg, ibuf);
514 break;
515 default:
516 err = got_error(GOT_ERR_PRIVSEP_MSG);
517 break;
520 imsg_free(&imsg);
522 return err;
525 const struct got_error *
526 got_privsep_send_commit(struct imsgbuf *ibuf, struct got_commit_object *commit)
528 const struct got_error *err = NULL;
529 struct got_imsg_commit_object icommit;
530 uint8_t *buf;
531 size_t len, total;
532 struct got_object_qid *qid;
534 memcpy(icommit.tree_id, commit->tree_id->sha1, sizeof(icommit.tree_id));
535 icommit.author_len = strlen(commit->author);
536 memcpy(&icommit.tm_author, &commit->tm_author,
537 sizeof(icommit.tm_author));
538 icommit.committer_len = strlen(commit->committer);
539 memcpy(&icommit.tm_committer, &commit->tm_committer,
540 sizeof(icommit.tm_committer));
541 icommit.logmsg_len = strlen(commit->logmsg);
542 icommit.nparents = commit->nparents;
544 total = sizeof(icommit) + icommit.author_len +
545 icommit.committer_len + icommit.logmsg_len +
546 icommit.nparents * SHA1_DIGEST_LENGTH;
547 /* XXX TODO support very large log messages properly */
548 if (total > MAX_IMSGSIZE)
549 return got_error(GOT_ERR_NO_SPACE);
551 buf = malloc(total);
552 if (buf == NULL)
553 return got_error_from_errno();
555 len = 0;
556 memcpy(buf + len, &icommit, sizeof(icommit));
557 len += sizeof(icommit);
558 memcpy(buf + len, commit->author, icommit.author_len);
559 len += icommit.author_len;
560 memcpy(buf + len, commit->committer, icommit.committer_len);
561 len += icommit.committer_len;
562 memcpy(buf + len, commit->logmsg, icommit.logmsg_len);
563 len += icommit.logmsg_len;
564 SIMPLEQ_FOREACH(qid, &commit->parent_ids, entry) {
565 memcpy(buf + len, qid->id, SHA1_DIGEST_LENGTH);
566 len += SHA1_DIGEST_LENGTH;
569 if (imsg_compose(ibuf, GOT_IMSG_COMMIT, 0, 0, -1, buf, len) == -1) {
570 err = got_error_from_errno();
571 goto done;
574 err = flush_imsg(ibuf);
575 done:
576 free(buf);
577 return err;
580 const struct got_error *
581 got_privsep_recv_commit(struct got_commit_object **commit, struct imsgbuf *ibuf)
583 const struct got_error *err = NULL;
584 struct imsg imsg;
585 struct got_imsg_commit_object icommit;
586 size_t len, datalen;
587 int i;
588 const size_t min_datalen =
589 MIN(sizeof(struct got_imsg_error),
590 sizeof(struct got_imsg_commit_object));
591 uint8_t *data;
593 *commit = NULL;
595 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
596 if (err)
597 return err;
599 data = imsg.data;
600 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
601 len = 0;
603 switch (imsg.hdr.type) {
604 case GOT_IMSG_ERROR:
605 err = recv_imsg_error(&imsg, datalen);
606 break;
607 case GOT_IMSG_COMMIT:
608 if (datalen < sizeof(icommit)) {
609 err = got_error(GOT_ERR_PRIVSEP_LEN);
610 break;
613 memcpy(&icommit, data, sizeof(icommit));
614 if (datalen != sizeof(icommit) + icommit.author_len +
615 icommit.committer_len + icommit.logmsg_len +
616 icommit.nparents * SHA1_DIGEST_LENGTH) {
617 err = got_error(GOT_ERR_PRIVSEP_LEN);
618 break;
620 if (icommit.nparents < 0) {
621 err = got_error(GOT_ERR_PRIVSEP_LEN);
622 break;
624 len += sizeof(icommit);
626 *commit = got_object_commit_alloc_partial();
627 if (*commit == NULL) {
628 err = got_error_from_errno();
629 break;
632 memcpy((*commit)->tree_id->sha1, icommit.tree_id,
633 SHA1_DIGEST_LENGTH);
634 memcpy(&(*commit)->tm_author, &icommit.tm_author,
635 sizeof((*commit)->tm_author));
636 memcpy(&(*commit)->tm_committer, &icommit.tm_committer,
637 sizeof((*commit)->tm_committer));
639 if (icommit.author_len == 0) {
640 (*commit)->author = strdup("");
641 if ((*commit)->author == NULL) {
642 err = got_error_from_errno();
643 break;
645 } else {
646 (*commit)->author = malloc(icommit.author_len + 1);
647 if ((*commit)->author == NULL) {
648 err = got_error_from_errno();
649 break;
651 memcpy((*commit)->author, data + len,
652 icommit.author_len);
653 (*commit)->author[icommit.author_len] = '\0';
655 len += icommit.author_len;
657 if (icommit.committer_len == 0) {
658 (*commit)->committer = strdup("");
659 if ((*commit)->committer == NULL) {
660 err = got_error_from_errno();
661 break;
663 } else {
664 (*commit)->committer =
665 malloc(icommit.committer_len + 1);
666 if ((*commit)->committer == NULL) {
667 err = got_error_from_errno();
668 break;
670 memcpy((*commit)->committer, data + len,
671 icommit.committer_len);
672 (*commit)->committer[icommit.committer_len] = '\0';
674 len += icommit.committer_len;
676 if (icommit.logmsg_len == 0) {
677 (*commit)->logmsg = strdup("");
678 if ((*commit)->logmsg == NULL) {
679 err = got_error_from_errno();
680 break;
682 } else {
683 (*commit)->logmsg = malloc(icommit.logmsg_len + 1);
684 if ((*commit)->logmsg == NULL) {
685 err = got_error_from_errno();
686 break;
688 memcpy((*commit)->logmsg, data + len,
689 icommit.logmsg_len);
690 (*commit)->logmsg[icommit.logmsg_len] = '\0';
692 len += icommit.logmsg_len;
694 for (i = 0; i < icommit.nparents; i++) {
695 struct got_object_qid *qid;
697 qid = calloc(1, sizeof(*qid));
698 if (qid == NULL) {
699 err = got_error_from_errno();
700 break;
702 qid->id = calloc(1, sizeof(*qid->id));
703 if (qid->id == NULL) {
704 err = got_error_from_errno();
705 free(qid);
706 break;
709 memcpy(qid->id, data + len + i * SHA1_DIGEST_LENGTH,
710 sizeof(*qid->id));
711 SIMPLEQ_INSERT_TAIL(&(*commit)->parent_ids, qid, entry);
712 (*commit)->nparents++;
714 break;
715 default:
716 err = got_error(GOT_ERR_PRIVSEP_MSG);
717 break;
720 imsg_free(&imsg);
722 return err;
725 const struct got_error *
726 got_privsep_send_tree(struct imsgbuf *ibuf, struct got_tree_object *tree)
728 const struct got_error *err = NULL;
729 struct got_imsg_tree_object itree;
730 struct got_tree_entry *te;
732 itree.nentries = tree->entries.nentries;
733 if (imsg_compose(ibuf, GOT_IMSG_TREE, 0, 0, -1, &itree, sizeof(itree))
734 == -1)
735 return got_error_from_errno();
737 err = flush_imsg(ibuf);
738 if (err)
739 return err;
741 SIMPLEQ_FOREACH(te, &tree->entries.head, entry) {
742 struct got_imsg_tree_entry ite;
743 uint8_t *buf = NULL;
744 size_t len = sizeof(ite) + strlen(te->name);
746 if (len > MAX_IMSGSIZE)
747 return got_error(GOT_ERR_NO_SPACE);
749 buf = malloc(len);
750 if (buf == NULL)
751 return got_error_from_errno();
753 memcpy(ite.id, te->id->sha1, sizeof(ite.id));
754 ite.mode = te->mode;
755 memcpy(buf, &ite, sizeof(ite));
756 memcpy(buf + sizeof(ite), te->name, strlen(te->name));
758 if (imsg_compose(ibuf, GOT_IMSG_TREE_ENTRY, 0, 0, -1,
759 buf, len) == -1)
760 err = got_error_from_errno();
761 free(buf);
762 if (err)
763 return err;
765 err = flush_imsg(ibuf);
766 if (err)
767 return err;
770 return NULL;
773 const struct got_error *
774 got_privsep_recv_tree(struct got_tree_object **tree, struct imsgbuf *ibuf)
776 const struct got_error *err = NULL;
777 const size_t min_datalen =
778 MIN(sizeof(struct got_imsg_error),
779 sizeof(struct got_imsg_tree_object));
780 struct got_imsg_tree_object itree = { 0 };
781 int nentries = 0;
783 *tree = NULL;
784 get_more:
785 err = read_imsg(ibuf);
786 if (err)
787 goto done;
789 while (1) {
790 struct imsg imsg;
791 size_t n;
792 size_t datalen;
793 struct got_imsg_tree_entry ite;
794 struct got_tree_entry *te = NULL;
796 n = imsg_get(ibuf, &imsg);
797 if (n == 0) {
798 if (*tree && (*tree)->entries.nentries != nentries)
799 goto get_more;
800 break;
803 if (imsg.hdr.len < IMSG_HEADER_SIZE + min_datalen)
804 return got_error(GOT_ERR_PRIVSEP_LEN);
806 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
808 switch (imsg.hdr.type) {
809 case GOT_IMSG_ERROR:
810 err = recv_imsg_error(&imsg, datalen);
811 break;
812 case GOT_IMSG_TREE:
813 /* This message should only appear once. */
814 if (*tree != NULL) {
815 err = got_error(GOT_ERR_PRIVSEP_MSG);
816 break;
818 if (datalen != sizeof(itree)) {
819 err = got_error(GOT_ERR_PRIVSEP_LEN);
820 break;
822 memcpy(&itree, imsg.data, sizeof(itree));
823 *tree = calloc(1, sizeof(**tree));
824 if (*tree == NULL) {
825 err = got_error_from_errno();
826 break;
828 (*tree)->entries.nentries = itree.nentries;
829 SIMPLEQ_INIT(&(*tree)->entries.head);
830 break;
831 case GOT_IMSG_TREE_ENTRY:
832 /* This message should be preceeded by GOT_IMSG_TREE. */
833 if (*tree == NULL) {
834 err = got_error(GOT_ERR_PRIVSEP_MSG);
835 break;
837 if (datalen < sizeof(ite) || datalen > MAX_IMSGSIZE) {
838 err = got_error(GOT_ERR_PRIVSEP_LEN);
839 break;
842 /* Remaining data contains the entry's name. */
843 datalen -= sizeof(ite);
844 memcpy(&ite, imsg.data, sizeof(ite));
845 if (datalen == 0 || datalen > MAX_IMSGSIZE) {
846 err = got_error(GOT_ERR_PRIVSEP_LEN);
847 break;
850 te = got_alloc_tree_entry_partial();
851 if (te == NULL) {
852 err = got_error_from_errno();
853 break;
855 te->name = malloc(datalen + 1);
856 if (te->name == NULL) {
857 free(te);
858 err = got_error_from_errno();
859 break;
861 memcpy(te->name, imsg.data + sizeof(ite), datalen);
862 te->name[datalen] = '\0';
864 memcpy(te->id->sha1, ite.id, SHA1_DIGEST_LENGTH);
865 te->mode = ite.mode;
866 SIMPLEQ_INSERT_TAIL(&(*tree)->entries.head, te, entry);
867 nentries++;
868 break;
869 default:
870 err = got_error(GOT_ERR_PRIVSEP_MSG);
871 break;
874 imsg_free(&imsg);
876 done:
877 if (*tree && (*tree)->entries.nentries != nentries) {
878 if (err == NULL)
879 err = got_error(GOT_ERR_PRIVSEP_LEN);
880 got_object_tree_close(*tree);
881 *tree = NULL;
884 return err;
887 const struct got_error *
888 got_privsep_send_blob(struct imsgbuf *ibuf, size_t size)
890 struct got_imsg_blob iblob;
892 iblob.size = size;
893 /* Data has already been written to file descriptor. */
895 if (imsg_compose(ibuf, GOT_IMSG_BLOB, 0, 0, -1, &iblob, sizeof(iblob))
896 == -1)
897 return got_error_from_errno();
899 return flush_imsg(ibuf);
902 const struct got_error *
903 got_privsep_recv_blob(size_t *size, struct imsgbuf *ibuf)
905 const struct got_error *err = NULL;
906 struct imsg imsg;
907 struct got_imsg_blob iblob;
908 size_t datalen;
910 err = got_privsep_recv_imsg(&imsg, ibuf, 0);
911 if (err)
912 return err;
914 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
916 switch (imsg.hdr.type) {
917 case GOT_IMSG_ERROR:
918 err = recv_imsg_error(&imsg, datalen);
919 break;
920 case GOT_IMSG_BLOB:
921 if (datalen != sizeof(iblob))
922 err = got_error(GOT_ERR_PRIVSEP_LEN);
923 memcpy(&iblob, imsg.data, sizeof(iblob));
924 *size = iblob.size;
925 /* Data has been written to file descriptor. */
926 break;
927 default:
928 err = got_error(GOT_ERR_PRIVSEP_MSG);
929 break;
932 imsg_free(&imsg);
934 return err;
937 const struct got_error *
938 got_privsep_init_pack_child(struct imsgbuf *ibuf, struct got_pack *pack,
939 struct got_packidx *packidx)
941 struct got_imsg_packidx ipackidx;
942 struct got_imsg_pack ipack;
943 int fd;
945 ipackidx.len = packidx->len;
946 fd = dup(packidx->fd);
947 if (fd == -1)
948 return got_error_from_errno();
950 if (imsg_compose(ibuf, GOT_IMSG_PACKIDX, 0, 0, fd, &ipackidx,
951 sizeof(ipackidx)) == -1)
952 return got_error_from_errno();
954 if (strlcpy(ipack.path_packfile, pack->path_packfile,
955 sizeof(ipack.path_packfile)) >= sizeof(ipack.path_packfile))
956 return got_error(GOT_ERR_NO_SPACE);
957 ipack.filesize = pack->filesize;
959 fd = dup(pack->fd);
960 if (fd == -1)
961 return got_error_from_errno();
963 if (imsg_compose(ibuf, GOT_IMSG_PACK, 0, 0, fd, &ipack, sizeof(ipack))
964 == -1)
965 return got_error_from_errno();
967 return flush_imsg(ibuf);
970 const struct got_error *
971 got_privsep_send_packed_obj_req(struct imsgbuf *ibuf, int idx)
973 struct got_imsg_packed_object iobj;
975 iobj.idx = idx;
977 if (imsg_compose(ibuf, GOT_IMSG_PACKED_OBJECT_REQUEST, 0, 0, -1,
978 &iobj, sizeof(iobj)) == -1)
979 return got_error_from_errno();
981 return flush_imsg(ibuf);