Blob


1 /*
2 * Copyright (c) 2018 Stefan Sperling <stsp@openbsd.org>
3 *
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
7 *
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15 */
17 #include <sys/types.h>
18 #include <sys/queue.h>
19 #include <sys/uio.h>
20 #include <sys/syslimits.h>
21 #include <sys/wait.h>
23 #include <stdio.h>
24 #include <stdlib.h>
25 #include <string.h>
26 #include <errno.h>
27 #include <stdint.h>
28 #include <poll.h>
29 #include <imsg.h>
30 #include <sha1.h>
31 #include <zlib.h>
32 #include <time.h>
34 #include "got_object.h"
35 #include "got_error.h"
37 #include "got_lib_sha1.h"
38 #include "got_lib_delta.h"
39 #include "got_lib_inflate.h"
40 #include "got_lib_object.h"
41 #include "got_lib_object_parse.h"
42 #include "got_lib_privsep.h"
43 #include "got_lib_pack.h"
45 #ifndef MIN
46 #define MIN(_a,_b) ((_a) < (_b) ? (_a) : (_b))
47 #endif
49 static const struct got_error *
50 poll_fd(int fd, int events, int timeout)
51 {
52 struct pollfd pfd[1];
53 int n;
55 pfd[0].fd = fd;
56 pfd[0].events = events;
58 n = poll(pfd, 1, timeout);
59 if (n == -1)
60 return got_error_from_errno();
61 if (n == 0)
62 return got_error(GOT_ERR_TIMEOUT);
63 if (pfd[0].revents & (POLLERR | POLLNVAL))
64 return got_error_from_errno();
65 if (pfd[0].revents & (events | POLLHUP))
66 return NULL;
68 return got_error(GOT_ERR_INTERRUPT);
69 }
71 static const struct got_error *
72 read_imsg(struct imsgbuf *ibuf)
73 {
74 const struct got_error *err;
75 size_t n;
77 err = poll_fd(ibuf->fd, POLLIN, INFTIM);
78 if (err)
79 return err;
81 n = imsg_read(ibuf);
82 if (n == -1) {
83 if (errno == EAGAIN) /* Could be a file-descriptor leak. */
84 return got_error(GOT_ERR_PRIVSEP_NO_FD);
85 return got_error(GOT_ERR_PRIVSEP_READ);
86 }
87 if (n == 0)
88 return got_error(GOT_ERR_PRIVSEP_PIPE);
90 return NULL;
91 }
93 const struct got_error *
94 got_privsep_wait_for_child(pid_t pid)
95 {
96 int child_status;
98 waitpid(pid, &child_status, 0);
100 if (!WIFEXITED(child_status))
101 return got_error(GOT_ERR_PRIVSEP_DIED);
103 if (WEXITSTATUS(child_status) != 0)
104 return got_error(GOT_ERR_PRIVSEP_EXIT);
106 return NULL;
109 const struct got_error *
110 got_privsep_recv_imsg(struct imsg *imsg, struct imsgbuf *ibuf, size_t min_datalen)
112 const struct got_error *err;
113 ssize_t n;
115 n = imsg_get(ibuf, imsg);
116 if (n == -1)
117 return got_error_from_errno();
119 while (n == 0) {
120 err = read_imsg(ibuf);
121 if (err)
122 return err;
123 n = imsg_get(ibuf, imsg);
126 if (imsg->hdr.len < IMSG_HEADER_SIZE + min_datalen)
127 return got_error(GOT_ERR_PRIVSEP_LEN);
129 return NULL;
132 static const struct got_error *
133 recv_imsg_error(struct imsg *imsg, size_t datalen)
135 struct got_imsg_error ierr;
137 if (datalen != sizeof(ierr))
138 return got_error(GOT_ERR_PRIVSEP_LEN);
140 memcpy(&ierr, imsg->data, sizeof(ierr));
141 if (ierr.code == GOT_ERR_ERRNO) {
142 static struct got_error serr;
143 serr.code = GOT_ERR_ERRNO;
144 serr.msg = strerror(ierr.errno_code);
145 return &serr;
148 return got_error(ierr.code);
151 /* Attempt to send an error in an imsg. Complain on stderr as a last resort. */
152 void
153 got_privsep_send_error(struct imsgbuf *ibuf, const struct got_error *err)
155 const struct got_error *poll_err;
156 struct got_imsg_error ierr;
157 int ret;
159 ierr.code = err->code;
160 if (err->code == GOT_ERR_ERRNO)
161 ierr.errno_code = errno;
162 else
163 ierr.errno_code = 0;
164 ret = imsg_compose(ibuf, GOT_IMSG_ERROR, 0, 0, -1, &ierr, sizeof(ierr));
165 if (ret != -1) {
166 fprintf(stderr, "%s: error %d \"%s\": imsg_compose: %s\n",
167 getprogname(), err->code, err->msg, strerror(errno));
168 return;
171 poll_err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
172 if (poll_err) {
173 fprintf(stderr, "%s: error %d \"%s\": poll: %s\n",
174 getprogname(), err->code, err->msg, poll_err->msg);
175 return;
178 ret = imsg_flush(ibuf);
179 if (ret == -1) {
180 fprintf(stderr, "%s: error %d \"%s\": imsg_flush: %s\n",
181 getprogname(), err->code, err->msg, strerror(errno));
182 return;
186 static const struct got_error *
187 flush_imsg(struct imsgbuf *ibuf)
189 const struct got_error *err;
191 err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
192 if (err)
193 return err;
195 if (imsg_flush(ibuf) == -1)
196 return got_error_from_errno();
198 return NULL;
201 const struct got_error *
202 got_privsep_send_stop(int fd)
204 const struct got_error *err = NULL;
205 struct imsgbuf ibuf;
207 imsg_init(&ibuf, fd);
209 if (imsg_compose(&ibuf, GOT_IMSG_STOP, 0, 0, -1, NULL, 0) == -1)
210 return got_error_from_errno();
212 err = flush_imsg(&ibuf);
213 imsg_clear(&ibuf);
214 return err;
217 static const struct got_error *
218 send_delta(struct got_delta *delta, struct imsgbuf *ibuf)
220 struct got_imsg_delta idelta;
221 size_t offset, remain;
223 idelta.offset = delta->offset;
224 idelta.tslen = delta->tslen;
225 idelta.type = delta->type;
226 idelta.size = delta->size;
227 idelta.data_offset = delta->data_offset;
228 idelta.delta_len = delta->delta_len;
230 if (imsg_compose(ibuf, GOT_IMSG_DELTA, 0, 0, -1,
231 &idelta, sizeof(idelta)) == -1)
232 return got_error_from_errno();
234 if (imsg_flush(ibuf) == -1)
235 return got_error_from_errno();
237 offset = 0;
238 remain = delta->delta_len;
239 while (remain > 0) {
240 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
242 if (imsg_compose(ibuf, GOT_IMSG_DELTA_STREAM, 0, 0, -1,
243 delta->delta_buf + offset, n) == -1)
244 return got_error_from_errno();
246 if (imsg_flush(ibuf) == -1)
247 return got_error_from_errno();
249 offset += n;
250 remain -= n;
253 return NULL;
256 const struct got_error *
257 got_privsep_send_obj_req(struct imsgbuf *ibuf, int fd, struct got_object *obj)
259 const struct got_error *err = NULL;
260 struct got_imsg_object iobj, *iobjp = NULL;
261 size_t iobj_size = 0;
262 int imsg_code = GOT_IMSG_OBJECT_REQUEST;
264 if (obj) {
265 switch (obj->type) {
266 case GOT_OBJ_TYPE_TREE:
267 imsg_code = GOT_IMSG_TREE_REQUEST;
268 break;
269 case GOT_OBJ_TYPE_COMMIT:
270 imsg_code = GOT_IMSG_COMMIT_REQUEST;
271 break;
272 /* Blobs are handled in got_privsep_send_blob_req(). */
273 default:
274 return got_error(GOT_ERR_OBJ_TYPE);
277 iobj.type = obj->type;
278 iobj.flags = obj->flags;
279 iobj.hdrlen = obj->hdrlen;
280 iobj.size = obj->size;
281 iobj.ndeltas = 0;
282 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
283 iobj.pack_offset = obj->pack_offset;
285 iobjp = &iobj;
286 iobj_size = sizeof(iobj);
289 if (imsg_compose(ibuf, imsg_code, 0, 0, fd, iobjp, iobj_size) == -1)
290 return got_error_from_errno();
292 err = flush_imsg(ibuf);
293 if (err)
294 return err;
296 if (obj && obj->flags & GOT_OBJ_FLAG_DELTIFIED) {
297 struct got_delta *delta;
298 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
299 err = send_delta(delta, ibuf);
300 if (err)
301 break;
305 return err;
308 const struct got_error *
309 got_privsep_send_blob_req(struct imsgbuf *ibuf, int outfd, int infd)
311 const struct got_error *err = NULL;
313 if (imsg_compose(ibuf, GOT_IMSG_BLOB_REQUEST, 0, 0, infd, NULL, 0)
314 == -1) {
315 close(infd);
316 close(outfd);
317 return got_error_from_errno();
320 err = flush_imsg(ibuf);
321 if (err) {
322 close(outfd);
323 return err;
326 if (imsg_compose(ibuf, GOT_IMSG_BLOB_OUTFD, 0, 0, outfd, NULL, 0)
327 == -1) {
328 close(outfd);
329 return got_error_from_errno();
332 return flush_imsg(ibuf);
335 const struct got_error *
336 got_privsep_send_obj(struct imsgbuf *ibuf, struct got_object *obj)
338 const struct got_error *err = NULL;
339 struct got_imsg_object iobj;
340 struct got_delta *delta;
342 iobj.type = obj->type;
343 iobj.flags = obj->flags;
344 iobj.hdrlen = obj->hdrlen;
345 iobj.size = obj->size;
346 iobj.ndeltas = obj->deltas.nentries;
347 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
348 iobj.pack_offset = obj->pack_offset;
350 if (imsg_compose(ibuf, GOT_IMSG_OBJECT, 0, 0, -1, &iobj, sizeof(iobj))
351 == -1)
352 return got_error_from_errno();
354 err = flush_imsg(ibuf);
355 if (err)
356 return err;
358 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
359 err = send_delta(delta, ibuf);
360 if (err)
361 break;
364 return err;
367 static const struct got_error *
368 receive_delta(struct got_delta **delta, struct imsgbuf *ibuf)
370 const struct got_error *err = NULL;
371 struct imsg imsg;
372 struct got_imsg_delta idelta;
373 uint8_t *delta_buf = NULL;
374 const size_t min_datalen =
375 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_delta));
376 size_t datalen, offset, remain;
378 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
379 if (err)
380 return err;
382 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
383 if (imsg.hdr.type == GOT_IMSG_ERROR)
384 return recv_imsg_error(&imsg, datalen);
386 if (imsg.hdr.type != GOT_IMSG_DELTA)
387 return got_error(GOT_ERR_PRIVSEP_MSG);
388 if (datalen != sizeof(idelta))
389 return got_error(GOT_ERR_PRIVSEP_LEN);
391 memcpy(&idelta, imsg.data, sizeof(idelta));
392 imsg_free(&imsg);
394 switch (idelta.type) {
395 case GOT_OBJ_TYPE_OFFSET_DELTA:
396 case GOT_OBJ_TYPE_REF_DELTA:
397 if (idelta.delta_len < GOT_DELTA_STREAM_LENGTH_MIN)
398 return got_error(GOT_ERR_BAD_DELTA);
399 break;
400 default:
401 if (idelta.delta_len != 0)
402 return got_error(GOT_ERR_BAD_DELTA);
403 break;
406 if (idelta.delta_len > 0) {
407 delta_buf = calloc(1, idelta.delta_len);
408 if (delta_buf == NULL)
409 return got_error_from_errno();
411 offset = 0;
412 remain = idelta.delta_len;
413 while (remain > 0) {
414 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
416 err = got_privsep_recv_imsg(&imsg, ibuf, n);
417 if (err)
418 return err;
420 if (imsg.hdr.type == GOT_IMSG_ERROR)
421 return recv_imsg_error(&imsg, datalen);
423 if (imsg.hdr.type == GOT_IMSG_STOP)
424 break;
426 if (imsg.hdr.type != GOT_IMSG_DELTA_STREAM)
427 return got_error(GOT_ERR_PRIVSEP_MSG);
429 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
430 if (datalen != n)
431 return got_error(GOT_ERR_PRIVSEP_LEN);
433 memcpy(delta_buf + offset, imsg.data, n);
434 imsg_free(&imsg);
436 offset += n;
437 remain -= n;
441 *delta = got_delta_open(idelta.offset, idelta.tslen, idelta.type,
442 idelta.size, idelta.data_offset, delta_buf, idelta.delta_len);
443 if (*delta == NULL) {
444 err = got_error_from_errno();
445 free(delta_buf);
448 return err;
451 const struct got_error *
452 got_privsep_get_imsg_obj(struct got_object **obj, struct imsg *imsg,
453 struct imsgbuf *ibuf)
455 const struct got_error *err = NULL;
456 struct got_imsg_object iobj;
457 size_t datalen = imsg->hdr.len - IMSG_HEADER_SIZE;
458 int i;
460 if (datalen != sizeof(iobj))
461 return got_error(GOT_ERR_PRIVSEP_LEN);
463 memcpy(&iobj, imsg->data, sizeof(iobj));
464 if (iobj.ndeltas < 0 ||
465 iobj.ndeltas > GOT_DELTA_CHAIN_RECURSION_MAX)
466 return got_error(GOT_ERR_PRIVSEP_LEN);
468 if (iobj.ndeltas > 0 &&
469 (iobj.flags & GOT_OBJ_FLAG_DELTIFIED) == 0)
470 return got_error(GOT_ERR_BAD_OBJ_DATA);
472 *obj = calloc(1, sizeof(**obj));
473 if (*obj == NULL)
474 return got_error_from_errno();
476 (*obj)->type = iobj.type;
477 (*obj)->flags = iobj.flags;
478 (*obj)->hdrlen = iobj.hdrlen;
479 (*obj)->size = iobj.size;
480 /* id and path_packfile might be copied in by caller */
481 (*obj)->pack_offset = iobj.pack_offset;
482 SIMPLEQ_INIT(&(*obj)->deltas.entries);
483 for (i = 0; i < iobj.ndeltas; i++) {
484 struct got_delta *delta;
485 err = receive_delta(&delta, ibuf);
486 if (err)
487 break;
488 (*obj)->deltas.nentries++;
489 SIMPLEQ_INSERT_TAIL(&(*obj)->deltas.entries, delta,
490 entry);
493 return err;
496 const struct got_error *
497 got_privsep_recv_obj(struct got_object **obj, struct imsgbuf *ibuf)
499 const struct got_error *err = NULL;
500 struct imsg imsg;
501 size_t datalen;
502 const size_t min_datalen =
503 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_object));
505 *obj = NULL;
507 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
508 if (err)
509 return err;
511 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
513 switch (imsg.hdr.type) {
514 case GOT_IMSG_ERROR:
515 err = recv_imsg_error(&imsg, datalen);
516 break;
517 case GOT_IMSG_OBJECT:
518 err = got_privsep_get_imsg_obj(obj, &imsg, ibuf);
519 break;
520 default:
521 err = got_error(GOT_ERR_PRIVSEP_MSG);
522 break;
525 imsg_free(&imsg);
527 return err;
530 const struct got_error *
531 got_privsep_send_commit(struct imsgbuf *ibuf, struct got_commit_object *commit)
533 const struct got_error *err = NULL;
534 struct got_imsg_commit_object icommit;
535 uint8_t *buf;
536 size_t len, total;
537 struct got_object_qid *qid;
539 memcpy(icommit.tree_id, commit->tree_id->sha1, sizeof(icommit.tree_id));
540 icommit.author_len = strlen(commit->author);
541 memcpy(&icommit.tm_author, &commit->tm_author,
542 sizeof(icommit.tm_author));
543 icommit.committer_len = strlen(commit->committer);
544 memcpy(&icommit.tm_committer, &commit->tm_committer,
545 sizeof(icommit.tm_committer));
546 icommit.logmsg_len = strlen(commit->logmsg);
547 icommit.nparents = commit->nparents;
549 total = sizeof(icommit) + icommit.author_len +
550 icommit.committer_len + icommit.logmsg_len +
551 icommit.nparents * SHA1_DIGEST_LENGTH;
552 /* XXX TODO support very large log messages properly */
553 if (total > MAX_IMSGSIZE)
554 return got_error(GOT_ERR_NO_SPACE);
556 buf = malloc(total);
557 if (buf == NULL)
558 return got_error_from_errno();
560 len = 0;
561 memcpy(buf + len, &icommit, sizeof(icommit));
562 len += sizeof(icommit);
563 memcpy(buf + len, commit->author, icommit.author_len);
564 len += icommit.author_len;
565 memcpy(buf + len, commit->committer, icommit.committer_len);
566 len += icommit.committer_len;
567 memcpy(buf + len, commit->logmsg, icommit.logmsg_len);
568 len += icommit.logmsg_len;
569 SIMPLEQ_FOREACH(qid, &commit->parent_ids, entry) {
570 memcpy(buf + len, qid->id, SHA1_DIGEST_LENGTH);
571 len += SHA1_DIGEST_LENGTH;
574 if (imsg_compose(ibuf, GOT_IMSG_COMMIT, 0, 0, -1, buf, len) == -1) {
575 err = got_error_from_errno();
576 goto done;
579 err = flush_imsg(ibuf);
580 done:
581 free(buf);
582 return err;
585 const struct got_error *
586 got_privsep_recv_commit(struct got_commit_object **commit, struct imsgbuf *ibuf)
588 const struct got_error *err = NULL;
589 struct imsg imsg;
590 struct got_imsg_commit_object icommit;
591 size_t len, datalen;
592 int i;
593 const size_t min_datalen =
594 MIN(sizeof(struct got_imsg_error),
595 sizeof(struct got_imsg_commit_object));
596 uint8_t *data;
598 *commit = NULL;
600 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
601 if (err)
602 return err;
604 data = imsg.data;
605 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
606 len = 0;
608 switch (imsg.hdr.type) {
609 case GOT_IMSG_ERROR:
610 err = recv_imsg_error(&imsg, datalen);
611 break;
612 case GOT_IMSG_COMMIT:
613 if (datalen < sizeof(icommit)) {
614 err = got_error(GOT_ERR_PRIVSEP_LEN);
615 break;
618 memcpy(&icommit, data, sizeof(icommit));
619 if (datalen != sizeof(icommit) + icommit.author_len +
620 icommit.committer_len + icommit.logmsg_len +
621 icommit.nparents * SHA1_DIGEST_LENGTH) {
622 err = got_error(GOT_ERR_PRIVSEP_LEN);
623 break;
625 if (icommit.nparents < 0) {
626 err = got_error(GOT_ERR_PRIVSEP_LEN);
627 break;
629 len += sizeof(icommit);
631 *commit = got_object_commit_alloc_partial();
632 if (*commit == NULL) {
633 err = got_error_from_errno();
634 break;
637 memcpy((*commit)->tree_id->sha1, icommit.tree_id,
638 SHA1_DIGEST_LENGTH);
639 memcpy(&(*commit)->tm_author, &icommit.tm_author,
640 sizeof((*commit)->tm_author));
641 memcpy(&(*commit)->tm_committer, &icommit.tm_committer,
642 sizeof((*commit)->tm_committer));
644 if (icommit.author_len == 0) {
645 (*commit)->author = strdup("");
646 if ((*commit)->author == NULL) {
647 err = got_error_from_errno();
648 break;
650 } else {
651 (*commit)->author = malloc(icommit.author_len + 1);
652 if ((*commit)->author == NULL) {
653 err = got_error_from_errno();
654 break;
656 memcpy((*commit)->author, data + len,
657 icommit.author_len);
658 (*commit)->author[icommit.author_len] = '\0';
660 len += icommit.author_len;
662 if (icommit.committer_len == 0) {
663 (*commit)->committer = strdup("");
664 if ((*commit)->committer == NULL) {
665 err = got_error_from_errno();
666 break;
668 } else {
669 (*commit)->committer =
670 malloc(icommit.committer_len + 1);
671 if ((*commit)->committer == NULL) {
672 err = got_error_from_errno();
673 break;
675 memcpy((*commit)->committer, data + len,
676 icommit.committer_len);
677 (*commit)->committer[icommit.committer_len] = '\0';
679 len += icommit.committer_len;
681 if (icommit.logmsg_len == 0) {
682 (*commit)->logmsg = strdup("");
683 if ((*commit)->logmsg == NULL) {
684 err = got_error_from_errno();
685 break;
687 } else {
688 (*commit)->logmsg = malloc(icommit.logmsg_len + 1);
689 if ((*commit)->logmsg == NULL) {
690 err = got_error_from_errno();
691 break;
693 memcpy((*commit)->logmsg, data + len,
694 icommit.logmsg_len);
695 (*commit)->logmsg[icommit.logmsg_len] = '\0';
697 len += icommit.logmsg_len;
699 for (i = 0; i < icommit.nparents; i++) {
700 struct got_object_qid *qid;
702 qid = calloc(1, sizeof(*qid));
703 if (qid == NULL) {
704 err = got_error_from_errno();
705 break;
707 qid->id = calloc(1, sizeof(*qid->id));
708 if (qid->id == NULL) {
709 err = got_error_from_errno();
710 free(qid);
711 break;
714 memcpy(qid->id, data + len + i * SHA1_DIGEST_LENGTH,
715 sizeof(*qid->id));
716 SIMPLEQ_INSERT_TAIL(&(*commit)->parent_ids, qid, entry);
717 (*commit)->nparents++;
719 break;
720 default:
721 err = got_error(GOT_ERR_PRIVSEP_MSG);
722 break;
725 imsg_free(&imsg);
727 return err;
730 const struct got_error *
731 got_privsep_send_tree(struct imsgbuf *ibuf, struct got_tree_object *tree)
733 const struct got_error *err = NULL;
734 struct got_imsg_tree_object itree;
735 struct got_tree_entry *te;
737 itree.nentries = tree->entries.nentries;
738 if (imsg_compose(ibuf, GOT_IMSG_TREE, 0, 0, -1, &itree, sizeof(itree))
739 == -1)
740 return got_error_from_errno();
742 err = flush_imsg(ibuf);
743 if (err)
744 return err;
746 SIMPLEQ_FOREACH(te, &tree->entries.head, entry) {
747 struct got_imsg_tree_entry ite;
748 uint8_t *buf = NULL;
749 size_t len = sizeof(ite) + strlen(te->name);
751 if (len > MAX_IMSGSIZE)
752 return got_error(GOT_ERR_NO_SPACE);
754 buf = malloc(len);
755 if (buf == NULL)
756 return got_error_from_errno();
758 memcpy(ite.id, te->id->sha1, sizeof(ite.id));
759 ite.mode = te->mode;
760 memcpy(buf, &ite, sizeof(ite));
761 memcpy(buf + sizeof(ite), te->name, strlen(te->name));
763 if (imsg_compose(ibuf, GOT_IMSG_TREE_ENTRY, 0, 0, -1,
764 buf, len) == -1)
765 err = got_error_from_errno();
766 free(buf);
767 if (err)
768 return err;
770 err = flush_imsg(ibuf);
771 if (err)
772 return err;
775 return NULL;
778 const struct got_error *
779 got_privsep_recv_tree(struct got_tree_object **tree, struct imsgbuf *ibuf)
781 const struct got_error *err = NULL;
782 const size_t min_datalen =
783 MIN(sizeof(struct got_imsg_error),
784 sizeof(struct got_imsg_tree_object));
785 struct got_imsg_tree_object itree = { 0 };
786 int nentries = 0;
788 *tree = NULL;
789 get_more:
790 err = read_imsg(ibuf);
791 if (err)
792 goto done;
794 while (1) {
795 struct imsg imsg;
796 size_t n;
797 size_t datalen;
798 struct got_imsg_tree_entry ite;
799 struct got_tree_entry *te = NULL;
801 n = imsg_get(ibuf, &imsg);
802 if (n == 0) {
803 if (*tree && (*tree)->entries.nentries != nentries)
804 goto get_more;
805 break;
808 if (imsg.hdr.len < IMSG_HEADER_SIZE + min_datalen)
809 return got_error(GOT_ERR_PRIVSEP_LEN);
811 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
813 switch (imsg.hdr.type) {
814 case GOT_IMSG_ERROR:
815 err = recv_imsg_error(&imsg, datalen);
816 break;
817 case GOT_IMSG_TREE:
818 /* This message should only appear once. */
819 if (*tree != NULL) {
820 err = got_error(GOT_ERR_PRIVSEP_MSG);
821 break;
823 if (datalen != sizeof(itree)) {
824 err = got_error(GOT_ERR_PRIVSEP_LEN);
825 break;
827 memcpy(&itree, imsg.data, sizeof(itree));
828 *tree = calloc(1, sizeof(**tree));
829 if (*tree == NULL) {
830 err = got_error_from_errno();
831 break;
833 (*tree)->entries.nentries = itree.nentries;
834 SIMPLEQ_INIT(&(*tree)->entries.head);
835 break;
836 case GOT_IMSG_TREE_ENTRY:
837 /* This message should be preceeded by GOT_IMSG_TREE. */
838 if (*tree == NULL) {
839 err = got_error(GOT_ERR_PRIVSEP_MSG);
840 break;
842 if (datalen < sizeof(ite) || datalen > MAX_IMSGSIZE) {
843 err = got_error(GOT_ERR_PRIVSEP_LEN);
844 break;
847 /* Remaining data contains the entry's name. */
848 datalen -= sizeof(ite);
849 memcpy(&ite, imsg.data, sizeof(ite));
850 if (datalen == 0 || datalen > MAX_IMSGSIZE) {
851 err = got_error(GOT_ERR_PRIVSEP_LEN);
852 break;
855 te = got_alloc_tree_entry_partial();
856 if (te == NULL) {
857 err = got_error_from_errno();
858 break;
860 te->name = malloc(datalen + 1);
861 if (te->name == NULL) {
862 free(te);
863 err = got_error_from_errno();
864 break;
866 memcpy(te->name, imsg.data + sizeof(ite), datalen);
867 te->name[datalen] = '\0';
869 memcpy(te->id->sha1, ite.id, SHA1_DIGEST_LENGTH);
870 te->mode = ite.mode;
871 SIMPLEQ_INSERT_TAIL(&(*tree)->entries.head, te, entry);
872 nentries++;
873 break;
874 default:
875 err = got_error(GOT_ERR_PRIVSEP_MSG);
876 break;
879 imsg_free(&imsg);
881 done:
882 if (*tree && (*tree)->entries.nentries != nentries) {
883 if (err == NULL)
884 err = got_error(GOT_ERR_PRIVSEP_LEN);
885 got_object_tree_close(*tree);
886 *tree = NULL;
889 return err;
892 const struct got_error *
893 got_privsep_send_blob(struct imsgbuf *ibuf, size_t size)
895 struct got_imsg_blob iblob;
897 iblob.size = size;
898 /* Data has already been written to file descriptor. */
900 if (imsg_compose(ibuf, GOT_IMSG_BLOB, 0, 0, -1, &iblob, sizeof(iblob))
901 == -1)
902 return got_error_from_errno();
904 return flush_imsg(ibuf);
907 const struct got_error *
908 got_privsep_recv_blob(size_t *size, struct imsgbuf *ibuf)
910 const struct got_error *err = NULL;
911 struct imsg imsg;
912 struct got_imsg_blob iblob;
913 size_t datalen;
915 err = got_privsep_recv_imsg(&imsg, ibuf, 0);
916 if (err)
917 return err;
919 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
921 switch (imsg.hdr.type) {
922 case GOT_IMSG_ERROR:
923 err = recv_imsg_error(&imsg, datalen);
924 break;
925 case GOT_IMSG_BLOB:
926 if (datalen != sizeof(iblob))
927 err = got_error(GOT_ERR_PRIVSEP_LEN);
928 memcpy(&iblob, imsg.data, sizeof(iblob));
929 *size = iblob.size;
930 /* Data has been written to file descriptor. */
931 break;
932 default:
933 err = got_error(GOT_ERR_PRIVSEP_MSG);
934 break;
937 imsg_free(&imsg);
939 return err;
942 const struct got_error *
943 got_privsep_init_pack_child(struct imsgbuf *ibuf, struct got_pack *pack,
944 struct got_packidx *packidx)
946 struct got_imsg_packidx ipackidx;
947 struct got_imsg_pack ipack;
948 int fd;
950 ipackidx.len = packidx->len;
951 fd = dup(packidx->fd);
952 if (fd == -1)
953 return got_error_from_errno();
955 if (imsg_compose(ibuf, GOT_IMSG_PACKIDX, 0, 0, fd, &ipackidx,
956 sizeof(ipackidx)) == -1)
957 return got_error_from_errno();
959 if (strlcpy(ipack.path_packfile, pack->path_packfile,
960 sizeof(ipack.path_packfile)) >= sizeof(ipack.path_packfile))
961 return got_error(GOT_ERR_NO_SPACE);
962 ipack.filesize = pack->filesize;
964 fd = dup(pack->fd);
965 if (fd == -1)
966 return got_error_from_errno();
968 if (imsg_compose(ibuf, GOT_IMSG_PACK, 0, 0, fd, &ipack, sizeof(ipack))
969 == -1)
970 return got_error_from_errno();
972 return flush_imsg(ibuf);
975 const struct got_error *
976 got_privsep_send_packed_obj_req(struct imsgbuf *ibuf, int idx)
978 struct got_imsg_packed_object iobj;
980 iobj.idx = idx;
982 if (imsg_compose(ibuf, GOT_IMSG_PACKED_OBJECT_REQUEST, 0, 0, -1,
983 &iobj, sizeof(iobj)) == -1)
984 return got_error_from_errno();
986 return flush_imsg(ibuf);