2 * Copyright (c) 2018 Stefan Sperling <stsp@openbsd.org>
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 #include <sys/types.h>
18 #include <sys/queue.h>
31 #include "got_compat.h"
33 #include "got_error.h"
34 #include "got_object.h"
36 #include "got_lib_delta.h"
37 #include "got_lib_inflate.h"
38 #include "got_lib_object.h"
39 #include "got_lib_object_parse.h"
40 #include "got_lib_privsep.h"
41 #include "got_lib_sha1.h"
44 #define nitems(_a) (sizeof(_a) / sizeof((_a)[0]))
47 #define GOT_OBJ_TAG_COMMIT "commit"
48 #define GOT_OBJ_TAG_TREE "tree"
49 #define GOT_OBJ_TAG_BLOB "blob"
50 #define GOT_OBJ_TAG_TAG "tag"
52 static volatile sig_atomic_t sigint_received;
55 catch_sigint(int signo)
60 static const struct got_error *
61 send_raw_obj(struct imsgbuf *ibuf, struct got_object *obj,
62 struct got_object_id *expected_id,
65 const struct got_error *err = NULL;
70 if (lseek(fd, SEEK_SET, 0) == -1) {
71 err = got_error_from_errno("lseek");
75 err = got_object_read_raw(&data, &size, &hdrlen,
76 GOT_PRIVSEP_INLINE_BLOB_DATA_MAX, outfd, expected_id, fd);
80 err = got_privsep_send_raw_obj(ibuf, size, hdrlen, data);
83 if (close(fd) == -1 && err == NULL)
84 err = got_error_from_errno("close");
89 main(int argc, char *argv[])
91 const struct got_error *err = NULL;
92 struct got_object *obj = NULL;
96 struct got_object_id expected_id;
98 signal(SIGINT, catch_sigint);
100 imsg_init(&ibuf, GOT_IMSG_FD_CHILD);
103 /* revoke access to most system calls */
104 if (pledge("stdio recvfd", NULL) == -1) {
105 err = got_error_from_errno("pledge");
106 got_privsep_send_error(&ibuf, err);
110 /* revoke fs access */
111 if (landlock_no_fs() == -1) {
112 err = got_error_from_errno("landlock_no_fs");
113 got_privsep_send_error(&ibuf, err);
116 if (cap_enter() == -1) {
117 err = got_error_from_errno("cap_enter");
118 got_privsep_send_error(&ibuf, err);
124 if (sigint_received) {
125 err = got_error(GOT_ERR_CANCELLED);
129 err = got_privsep_recv_imsg(&imsg, &ibuf, 0);
131 if (err->code == GOT_ERR_PRIVSEP_PIPE)
136 if (imsg.hdr.type == GOT_IMSG_STOP)
139 if (imsg.hdr.type != GOT_IMSG_OBJECT_REQUEST &&
140 imsg.hdr.type != GOT_IMSG_RAW_OBJECT_REQUEST) {
141 err = got_error(GOT_ERR_PRIVSEP_MSG);
145 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
146 if (datalen != sizeof(expected_id)) {
147 err = got_error(GOT_ERR_PRIVSEP_LEN);
150 memcpy(&expected_id, imsg.data, sizeof(expected_id));
153 err = got_error(GOT_ERR_PRIVSEP_NO_FD);
157 err = got_object_read_header(&obj, imsg.fd);
161 if (imsg.hdr.type == GOT_IMSG_RAW_OBJECT_REQUEST) {
162 struct imsg imsg_outfd;
164 err = got_privsep_recv_imsg(&imsg_outfd, &ibuf, 0);
166 if (imsg_outfd.hdr.len == 0)
171 if (imsg_outfd.hdr.type == GOT_IMSG_STOP) {
172 imsg_free(&imsg_outfd);
176 if (imsg_outfd.hdr.type != GOT_IMSG_RAW_OBJECT_OUTFD) {
177 err = got_error(GOT_ERR_PRIVSEP_MSG);
178 imsg_free(&imsg_outfd);
182 datalen = imsg_outfd.hdr.len - IMSG_HEADER_SIZE;
184 err = got_error(GOT_ERR_PRIVSEP_LEN);
185 imsg_free(&imsg_outfd);
188 if (imsg_outfd.fd == -1) {
189 err = got_error(GOT_ERR_PRIVSEP_NO_FD);
190 imsg_free(&imsg_outfd);
193 err = send_raw_obj(&ibuf, obj, &expected_id,
194 imsg.fd, imsg_outfd.fd);
195 imsg.fd = -1; /* imsg.fd is owned by send_raw_obj() */
196 if (close(imsg_outfd.fd) == -1 && err == NULL)
197 err = got_error_from_errno("close");
198 imsg_free(&imsg_outfd);
202 err = got_privsep_send_obj(&ibuf, obj);
204 if (imsg.fd != -1 && close(imsg.fd) == -1 && err == NULL)
205 err = got_error_from_errno("close");
208 got_object_close(obj);
215 if(!sigint_received && err->code != GOT_ERR_PRIVSEP_PIPE) {
216 fprintf(stderr, "%s: %s\n", getprogname(), err->msg);
217 got_privsep_send_error(&ibuf, err);
220 if (close(GOT_IMSG_FD_CHILD) == -1 && err == NULL)
221 err = got_error_from_errno("close");