Blob


1 /*
2 * Copyright (c) 2018 Stefan Sperling <stsp@openbsd.org>
3 *
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
7 *
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15 */
17 #include <sys/types.h>
18 #include <sys/queue.h>
19 #include <sys/uio.h>
20 #include <sys/syslimits.h>
21 #include <sys/wait.h>
23 #include <stdio.h>
24 #include <stdlib.h>
25 #include <string.h>
26 #include <errno.h>
27 #include <stdint.h>
28 #include <poll.h>
29 #include <imsg.h>
30 #include <sha1.h>
31 #include <zlib.h>
32 #include <time.h>
34 #include "got_object.h"
35 #include "got_error.h"
37 #include "got_lib_sha1.h"
38 #include "got_lib_delta.h"
39 #include "got_lib_inflate.h"
40 #include "got_lib_object.h"
41 #include "got_lib_object_parse.h"
42 #include "got_lib_privsep.h"
43 #include "got_lib_pack.h"
45 #ifndef MIN
46 #define MIN(_a,_b) ((_a) < (_b) ? (_a) : (_b))
47 #endif
49 static const struct got_error *
50 poll_fd(int fd, int events, int timeout)
51 {
52 struct pollfd pfd[1];
53 int n;
55 pfd[0].fd = fd;
56 pfd[0].events = events;
58 n = poll(pfd, 1, timeout);
59 if (n == -1)
60 return got_error_from_errno();
61 if (n == 0)
62 return got_error(GOT_ERR_TIMEOUT);
63 if (pfd[0].revents & (POLLERR | POLLNVAL))
64 return got_error_from_errno();
65 if (pfd[0].revents & (events | POLLHUP))
66 return NULL;
68 return got_error(GOT_ERR_INTERRUPT);
69 }
71 static const struct got_error *
72 read_imsg(struct imsgbuf *ibuf)
73 {
74 const struct got_error *err;
75 size_t n;
77 err = poll_fd(ibuf->fd, POLLIN, INFTIM);
78 if (err)
79 return err;
81 n = imsg_read(ibuf);
82 if (n == -1) {
83 if (errno == EAGAIN) /* Could be a file-descriptor leak. */
84 return got_error(GOT_ERR_PRIVSEP_NO_FD);
85 return got_error(GOT_ERR_PRIVSEP_READ);
86 }
87 if (n == 0)
88 return got_error(GOT_ERR_PRIVSEP_PIPE);
90 return NULL;
91 }
93 const struct got_error *
94 got_privsep_wait_for_child(pid_t pid)
95 {
96 int child_status;
98 waitpid(pid, &child_status, 0);
100 if (!WIFEXITED(child_status))
101 return got_error(GOT_ERR_PRIVSEP_DIED);
103 if (WEXITSTATUS(child_status) != 0)
104 return got_error(GOT_ERR_PRIVSEP_EXIT);
106 return NULL;
109 const struct got_error *
110 got_privsep_recv_imsg(struct imsg *imsg, struct imsgbuf *ibuf, size_t min_datalen)
112 const struct got_error *err;
113 ssize_t n;
115 n = imsg_get(ibuf, imsg);
116 if (n == -1)
117 return got_error_from_errno();
119 while (n == 0) {
120 err = read_imsg(ibuf);
121 if (err)
122 return err;
123 n = imsg_get(ibuf, imsg);
126 if (imsg->hdr.len < IMSG_HEADER_SIZE + min_datalen)
127 return got_error(GOT_ERR_PRIVSEP_LEN);
129 return NULL;
132 static const struct got_error *
133 recv_imsg_error(struct imsg *imsg, size_t datalen)
135 struct got_imsg_error ierr;
137 if (datalen != sizeof(ierr))
138 return got_error(GOT_ERR_PRIVSEP_LEN);
140 memcpy(&ierr, imsg->data, sizeof(ierr));
141 if (ierr.code == GOT_ERR_ERRNO) {
142 static struct got_error serr;
143 serr.code = GOT_ERR_ERRNO;
144 serr.msg = strerror(ierr.errno_code);
145 return &serr;
148 return got_error(ierr.code);
151 /* Attempt to send an error in an imsg. Complain on stderr as a last resort. */
152 void
153 got_privsep_send_error(struct imsgbuf *ibuf, const struct got_error *err)
155 const struct got_error *poll_err;
156 struct got_imsg_error ierr;
157 int ret;
159 ierr.code = err->code;
160 if (err->code == GOT_ERR_ERRNO)
161 ierr.errno_code = errno;
162 else
163 ierr.errno_code = 0;
164 ret = imsg_compose(ibuf, GOT_IMSG_ERROR, 0, 0, -1, &ierr, sizeof(ierr));
165 if (ret != -1) {
166 fprintf(stderr, "%s: error %d \"%s\": imsg_compose: %s\n",
167 getprogname(), err->code, err->msg, strerror(errno));
168 return;
171 poll_err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
172 if (poll_err) {
173 fprintf(stderr, "%s: error %d \"%s\": poll: %s\n",
174 getprogname(), err->code, err->msg, poll_err->msg);
175 return;
178 ret = imsg_flush(ibuf);
179 if (ret == -1) {
180 fprintf(stderr, "%s: error %d \"%s\": imsg_flush: %s\n",
181 getprogname(), err->code, err->msg, strerror(errno));
182 return;
186 static const struct got_error *
187 flush_imsg(struct imsgbuf *ibuf)
189 const struct got_error *err;
191 err = poll_fd(ibuf->fd, POLLOUT, INFTIM);
192 if (err)
193 return err;
195 if (imsg_flush(ibuf) == -1)
196 return got_error_from_errno();
198 return NULL;
201 const struct got_error *
202 got_privsep_send_stop(int fd)
204 const struct got_error *err = NULL;
205 struct imsgbuf ibuf;
207 imsg_init(&ibuf, fd);
209 if (imsg_compose(&ibuf, GOT_IMSG_STOP, 0, 0, -1, NULL, 0) == -1)
210 return got_error_from_errno();
212 err = flush_imsg(&ibuf);
213 imsg_clear(&ibuf);
214 return err;
217 static const struct got_error *
218 send_delta(struct got_delta *delta, struct imsgbuf *ibuf)
220 struct got_imsg_delta idelta;
221 size_t offset, remain;
223 idelta.offset = delta->offset;
224 idelta.tslen = delta->tslen;
225 idelta.type = delta->type;
226 idelta.size = delta->size;
227 idelta.data_offset = delta->data_offset;
228 idelta.delta_len = delta->delta_len;
230 if (imsg_compose(ibuf, GOT_IMSG_DELTA, 0, 0, -1,
231 &idelta, sizeof(idelta)) == -1)
232 return got_error_from_errno();
234 if (imsg_flush(ibuf) == -1)
235 return got_error_from_errno();
237 offset = 0;
238 remain = delta->delta_len;
239 while (remain > 0) {
240 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
242 if (imsg_compose(ibuf, GOT_IMSG_DELTA_STREAM, 0, 0, -1,
243 delta->delta_buf + offset, n) == -1)
244 return got_error_from_errno();
246 if (imsg_flush(ibuf) == -1)
247 return got_error_from_errno();
249 offset += n;
250 remain -= n;
253 return NULL;
256 const struct got_error *
257 got_privsep_send_obj_req(struct imsgbuf *ibuf, int fd, struct got_object *obj)
259 const struct got_error *err = NULL;
260 struct got_imsg_object iobj, *iobjp = NULL;
261 size_t iobj_size = 0;
262 int imsg_code = GOT_IMSG_OBJECT_REQUEST;
264 if (obj) {
265 switch (obj->type) {
266 case GOT_OBJ_TYPE_TREE:
267 imsg_code = GOT_IMSG_TREE_REQUEST;
268 break;
269 case GOT_OBJ_TYPE_COMMIT:
270 imsg_code = GOT_IMSG_COMMIT_REQUEST;
271 break;
272 /* Blobs are handled in got_privsep_send_blob_req(). */
273 default:
274 return got_error(GOT_ERR_OBJ_TYPE);
277 iobj.type = obj->type;
278 iobj.flags = obj->flags;
279 iobj.hdrlen = obj->hdrlen;
280 iobj.size = obj->size;
281 iobj.ndeltas = 0;
282 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
283 iobj.pack_offset = obj->pack_offset;
285 iobjp = &iobj;
286 iobj_size = sizeof(iobj);
289 if (imsg_compose(ibuf, imsg_code, 0, 0, fd, iobjp, iobj_size) == -1)
290 return got_error_from_errno();
292 err = flush_imsg(ibuf);
293 if (err)
294 return err;
296 if (obj && obj->flags & GOT_OBJ_FLAG_DELTIFIED) {
297 struct got_delta *delta;
298 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
299 err = send_delta(delta, ibuf);
300 if (err)
301 break;
305 return err;
308 const struct got_error *
309 got_privsep_send_blob_req(struct imsgbuf *ibuf, int outfd, int infd)
311 const struct got_error *err = NULL;
313 if (imsg_compose(ibuf, GOT_IMSG_BLOB_REQUEST, 0, 0, infd, NULL, 0)
314 == -1) {
315 close(infd);
316 close(outfd);
317 return got_error_from_errno();
320 err = flush_imsg(ibuf);
321 if (err) {
322 close(outfd);
323 return err;
326 if (imsg_compose(ibuf, GOT_IMSG_BLOB_OUTFD, 0, 0, outfd, NULL, 0)
327 == -1) {
328 close(outfd);
329 return got_error_from_errno();
332 return flush_imsg(ibuf);
335 const struct got_error *
336 got_privsep_send_obj(struct imsgbuf *ibuf, struct got_object *obj)
338 const struct got_error *err = NULL;
339 struct got_imsg_object iobj;
340 struct got_delta *delta;
342 iobj.type = obj->type;
343 iobj.flags = obj->flags;
344 iobj.hdrlen = obj->hdrlen;
345 iobj.size = obj->size;
346 iobj.ndeltas = obj->deltas.nentries;
347 if (iobj.flags & GOT_OBJ_FLAG_PACKED)
348 iobj.pack_offset = obj->pack_offset;
350 if (imsg_compose(ibuf, GOT_IMSG_OBJECT, 0, 0, -1, &iobj, sizeof(iobj))
351 == -1)
352 return got_error_from_errno();
354 err = flush_imsg(ibuf);
355 if (err)
356 return err;
358 SIMPLEQ_FOREACH(delta, &obj->deltas.entries, entry) {
359 err = send_delta(delta, ibuf);
360 if (err)
361 break;
364 return err;
367 static const struct got_error *
368 receive_delta(struct got_delta **delta, struct imsgbuf *ibuf)
370 const struct got_error *err = NULL;
371 struct imsg imsg;
372 struct got_imsg_delta idelta;
373 uint8_t *delta_buf = NULL;
374 const size_t min_datalen =
375 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_delta));
376 size_t datalen, offset, remain;
378 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
379 if (err)
380 return err;
382 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
383 if (imsg.hdr.type == GOT_IMSG_ERROR)
384 return recv_imsg_error(&imsg, datalen);
386 if (imsg.hdr.type != GOT_IMSG_DELTA)
387 return got_error(GOT_ERR_PRIVSEP_MSG);
388 if (datalen != sizeof(idelta))
389 return got_error(GOT_ERR_PRIVSEP_LEN);
391 memcpy(&idelta, imsg.data, sizeof(idelta));
392 imsg_free(&imsg);
394 switch (idelta.type) {
395 case GOT_OBJ_TYPE_OFFSET_DELTA:
396 case GOT_OBJ_TYPE_REF_DELTA:
397 if (idelta.delta_len < GOT_DELTA_STREAM_LENGTH_MIN)
398 return got_error(GOT_ERR_BAD_DELTA);
399 break;
400 default:
401 if (idelta.delta_len != 0)
402 return got_error(GOT_ERR_BAD_DELTA);
403 break;
406 if (idelta.delta_len > 0) {
407 delta_buf = calloc(1, idelta.delta_len);
408 if (delta_buf == NULL)
409 return got_error_from_errno();
411 offset = 0;
412 remain = idelta.delta_len;
413 while (remain > 0) {
414 size_t n = MIN(MAX_IMSGSIZE - IMSG_HEADER_SIZE, remain);
416 err = got_privsep_recv_imsg(&imsg, ibuf, n);
417 if (err)
418 return err;
420 if (imsg.hdr.type == GOT_IMSG_ERROR)
421 return recv_imsg_error(&imsg, datalen);
423 if (imsg.hdr.type == GOT_IMSG_STOP)
424 break;
426 if (imsg.hdr.type != GOT_IMSG_DELTA_STREAM)
427 return got_error(GOT_ERR_PRIVSEP_MSG);
429 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
430 if (datalen != n)
431 return got_error(GOT_ERR_PRIVSEP_LEN);
433 memcpy(delta_buf + offset, imsg.data, n);
434 imsg_free(&imsg);
436 offset += n;
437 remain -= n;
441 *delta = got_delta_open(idelta.offset, idelta.tslen, idelta.type,
442 idelta.size, idelta.data_offset, delta_buf, idelta.delta_len);
443 if (*delta == NULL) {
444 err = got_error_from_errno();
445 free(delta_buf);
448 return err;
451 const struct got_error *
452 got_privsep_recv_obj(struct got_object **obj, struct imsgbuf *ibuf)
454 const struct got_error *err = NULL;
455 struct imsg imsg;
456 struct got_imsg_object iobj;
457 size_t datalen;
458 int i;
459 const size_t min_datalen =
460 MIN(sizeof(struct got_imsg_error), sizeof(struct got_imsg_object));
462 *obj = NULL;
464 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
465 if (err)
466 return err;
468 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
470 switch (imsg.hdr.type) {
471 case GOT_IMSG_ERROR:
472 err = recv_imsg_error(&imsg, datalen);
473 break;
474 case GOT_IMSG_OBJECT:
475 if (datalen != sizeof(iobj)) {
476 err = got_error(GOT_ERR_PRIVSEP_LEN);
477 break;
480 memcpy(&iobj, imsg.data, sizeof(iobj));
481 if (iobj.ndeltas < 0 ||
482 iobj.ndeltas > GOT_DELTA_CHAIN_RECURSION_MAX) {
483 err = got_error(GOT_ERR_PRIVSEP_LEN);
484 break;
486 if (iobj.ndeltas > 0 &&
487 (iobj.flags & GOT_OBJ_FLAG_DELTIFIED) == 0) {
488 err = got_error(GOT_ERR_BAD_OBJ_DATA);
489 break;
492 *obj = calloc(1, sizeof(**obj));
493 if (*obj == NULL) {
494 err = got_error_from_errno();
495 break;
498 (*obj)->type = iobj.type;
499 (*obj)->flags = iobj.flags;
500 (*obj)->hdrlen = iobj.hdrlen;
501 (*obj)->size = iobj.size;
502 /* id and path_packfile might be copied in by caller */
503 (*obj)->pack_offset = iobj.pack_offset;
504 SIMPLEQ_INIT(&(*obj)->deltas.entries);
505 for (i = 0; i < iobj.ndeltas; i++) {
506 struct got_delta *delta;
507 err = receive_delta(&delta, ibuf);
508 if (err)
509 break;
510 (*obj)->deltas.nentries++;
511 SIMPLEQ_INSERT_TAIL(&(*obj)->deltas.entries, delta,
512 entry);
514 break;
515 default:
516 err = got_error(GOT_ERR_PRIVSEP_MSG);
517 break;
520 imsg_free(&imsg);
522 return err;
525 const struct got_error *
526 got_privsep_send_commit(struct imsgbuf *ibuf, struct got_commit_object *commit)
528 const struct got_error *err = NULL;
529 struct got_imsg_commit_object icommit;
530 uint8_t *buf;
531 size_t len, total;
532 struct got_object_qid *qid;
534 memcpy(icommit.tree_id, commit->tree_id->sha1, sizeof(icommit.tree_id));
535 icommit.author_len = strlen(commit->author);
536 memcpy(&icommit.tm_author, &commit->tm_author,
537 sizeof(icommit.tm_author));
538 icommit.committer_len = strlen(commit->committer);
539 memcpy(&icommit.tm_committer, &commit->tm_committer,
540 sizeof(icommit.tm_committer));
541 icommit.logmsg_len = strlen(commit->logmsg);
542 icommit.nparents = commit->nparents;
544 total = sizeof(icommit) + icommit.author_len +
545 icommit.committer_len + icommit.logmsg_len +
546 icommit.nparents * SHA1_DIGEST_LENGTH;
547 /* XXX TODO support very large log messages properly */
548 if (total > MAX_IMSGSIZE)
549 return got_error(GOT_ERR_NO_SPACE);
551 buf = malloc(total);
552 if (buf == NULL)
553 return got_error_from_errno();
555 len = 0;
556 memcpy(buf + len, &icommit, sizeof(icommit));
557 len += sizeof(icommit);
558 memcpy(buf + len, commit->author, icommit.author_len);
559 len += icommit.author_len;
560 memcpy(buf + len, commit->committer, icommit.committer_len);
561 len += icommit.committer_len;
562 memcpy(buf + len, commit->logmsg, icommit.logmsg_len);
563 len += icommit.logmsg_len;
564 SIMPLEQ_FOREACH(qid, &commit->parent_ids, entry) {
565 memcpy(buf + len, qid->id, SHA1_DIGEST_LENGTH);
566 len += SHA1_DIGEST_LENGTH;
569 if (imsg_compose(ibuf, GOT_IMSG_COMMIT, 0, 0, -1, buf, len) == -1) {
570 err = got_error_from_errno();
571 goto done;
574 err = flush_imsg(ibuf);
575 done:
576 free(buf);
577 return err;
579 const struct got_error *
580 got_privsep_recv_commit(struct got_commit_object **commit, struct imsgbuf *ibuf)
582 const struct got_error *err = NULL;
583 struct imsg imsg;
584 struct got_imsg_commit_object icommit;
585 size_t len, datalen;
586 int i;
587 const size_t min_datalen =
588 MIN(sizeof(struct got_imsg_error),
589 sizeof(struct got_imsg_commit_object));
590 uint8_t *data;
592 *commit = NULL;
594 err = got_privsep_recv_imsg(&imsg, ibuf, min_datalen);
595 if (err)
596 return err;
598 data = imsg.data;
599 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
600 len = 0;
602 switch (imsg.hdr.type) {
603 case GOT_IMSG_ERROR:
604 err = recv_imsg_error(&imsg, datalen);
605 break;
606 case GOT_IMSG_COMMIT:
607 if (datalen < sizeof(icommit)) {
608 err = got_error(GOT_ERR_PRIVSEP_LEN);
609 break;
612 memcpy(&icommit, data, sizeof(icommit));
613 if (datalen != sizeof(icommit) + icommit.author_len +
614 icommit.committer_len + icommit.logmsg_len +
615 icommit.nparents * SHA1_DIGEST_LENGTH) {
616 err = got_error(GOT_ERR_PRIVSEP_LEN);
617 break;
619 if (icommit.nparents < 0) {
620 err = got_error(GOT_ERR_PRIVSEP_LEN);
621 break;
623 len += sizeof(icommit);
625 *commit = got_object_commit_alloc_partial();
626 if (*commit == NULL) {
627 err = got_error_from_errno();
628 break;
631 memcpy((*commit)->tree_id->sha1, icommit.tree_id,
632 SHA1_DIGEST_LENGTH);
633 memcpy(&(*commit)->tm_author, &icommit.tm_author,
634 sizeof((*commit)->tm_author));
635 memcpy(&(*commit)->tm_committer, &icommit.tm_committer,
636 sizeof((*commit)->tm_committer));
638 if (icommit.author_len == 0) {
639 (*commit)->author = strdup("");
640 if ((*commit)->author == NULL) {
641 err = got_error_from_errno();
642 break;
644 } else {
645 (*commit)->author = malloc(icommit.author_len + 1);
646 if ((*commit)->author == NULL) {
647 err = got_error_from_errno();
648 break;
650 memcpy((*commit)->author, data + len,
651 icommit.author_len);
652 (*commit)->author[icommit.author_len] = '\0';
654 len += icommit.author_len;
656 if (icommit.committer_len == 0) {
657 (*commit)->committer = strdup("");
658 if ((*commit)->committer == NULL) {
659 err = got_error_from_errno();
660 break;
662 } else {
663 (*commit)->committer =
664 malloc(icommit.committer_len + 1);
665 if ((*commit)->committer == NULL) {
666 err = got_error_from_errno();
667 break;
669 memcpy((*commit)->committer, data + len,
670 icommit.committer_len);
671 (*commit)->committer[icommit.committer_len] = '\0';
673 len += icommit.committer_len;
675 if (icommit.logmsg_len == 0) {
676 (*commit)->logmsg = strdup("");
677 if ((*commit)->logmsg == NULL) {
678 err = got_error_from_errno();
679 break;
681 } else {
682 (*commit)->logmsg = malloc(icommit.logmsg_len + 1);
683 if ((*commit)->logmsg == NULL) {
684 err = got_error_from_errno();
685 break;
687 memcpy((*commit)->logmsg, data + len,
688 icommit.logmsg_len);
689 (*commit)->logmsg[icommit.logmsg_len] = '\0';
691 len += icommit.logmsg_len;
693 for (i = 0; i < icommit.nparents; i++) {
694 struct got_object_qid *qid;
696 qid = calloc(1, sizeof(*qid));
697 if (qid == NULL) {
698 err = got_error_from_errno();
699 break;
701 qid->id = calloc(1, sizeof(*qid->id));
702 if (qid->id == NULL) {
703 err = got_error_from_errno();
704 free(qid);
705 break;
708 memcpy(qid->id, data + len + i * SHA1_DIGEST_LENGTH,
709 sizeof(*qid->id));
710 SIMPLEQ_INSERT_TAIL(&(*commit)->parent_ids, qid, entry);
711 (*commit)->nparents++;
713 break;
714 default:
715 err = got_error(GOT_ERR_PRIVSEP_MSG);
716 break;
719 imsg_free(&imsg);
721 return err;
724 const struct got_error *
725 got_privsep_send_tree(struct imsgbuf *ibuf, struct got_tree_object *tree)
727 const struct got_error *err = NULL;
728 struct got_imsg_tree_object itree;
729 struct got_tree_entry *te;
731 itree.nentries = tree->entries.nentries;
732 if (imsg_compose(ibuf, GOT_IMSG_TREE, 0, 0, -1, &itree, sizeof(itree))
733 == -1)
734 return got_error_from_errno();
736 err = flush_imsg(ibuf);
737 if (err)
738 return err;
740 SIMPLEQ_FOREACH(te, &tree->entries.head, entry) {
741 struct got_imsg_tree_entry ite;
742 uint8_t *buf = NULL;
743 size_t len = sizeof(ite) + strlen(te->name);
745 if (len > MAX_IMSGSIZE)
746 return got_error(GOT_ERR_NO_SPACE);
748 buf = malloc(len);
749 if (buf == NULL)
750 return got_error_from_errno();
752 memcpy(ite.id, te->id->sha1, sizeof(ite.id));
753 ite.mode = te->mode;
754 memcpy(buf, &ite, sizeof(ite));
755 memcpy(buf + sizeof(ite), te->name, strlen(te->name));
757 if (imsg_compose(ibuf, GOT_IMSG_TREE_ENTRY, 0, 0, -1,
758 buf, len) == -1)
759 err = got_error_from_errno();
760 free(buf);
761 if (err)
762 return err;
764 err = flush_imsg(ibuf);
765 if (err)
766 return err;
769 return NULL;
772 const struct got_error *
773 got_privsep_recv_tree(struct got_tree_object **tree, struct imsgbuf *ibuf)
775 const struct got_error *err = NULL;
776 const size_t min_datalen =
777 MIN(sizeof(struct got_imsg_error),
778 sizeof(struct got_imsg_tree_object));
779 struct got_imsg_tree_object itree = { 0 };
780 int nentries = 0;
782 *tree = NULL;
783 get_more:
784 err = read_imsg(ibuf);
785 if (err)
786 goto done;
788 while (1) {
789 struct imsg imsg;
790 size_t n;
791 size_t datalen;
792 struct got_imsg_tree_entry ite;
793 struct got_tree_entry *te = NULL;
795 n = imsg_get(ibuf, &imsg);
796 if (n == 0) {
797 if (*tree && (*tree)->entries.nentries != nentries)
798 goto get_more;
799 break;
802 if (imsg.hdr.len < IMSG_HEADER_SIZE + min_datalen)
803 return got_error(GOT_ERR_PRIVSEP_LEN);
805 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
807 switch (imsg.hdr.type) {
808 case GOT_IMSG_ERROR:
809 err = recv_imsg_error(&imsg, datalen);
810 break;
811 case GOT_IMSG_TREE:
812 /* This message should only appear once. */
813 if (*tree != NULL) {
814 err = got_error(GOT_ERR_PRIVSEP_MSG);
815 break;
817 if (datalen != sizeof(itree)) {
818 err = got_error(GOT_ERR_PRIVSEP_LEN);
819 break;
821 memcpy(&itree, imsg.data, sizeof(itree));
822 *tree = calloc(1, sizeof(**tree));
823 if (*tree == NULL) {
824 err = got_error_from_errno();
825 break;
827 (*tree)->entries.nentries = itree.nentries;
828 SIMPLEQ_INIT(&(*tree)->entries.head);
829 break;
830 case GOT_IMSG_TREE_ENTRY:
831 /* This message should be preceeded by GOT_IMSG_TREE. */
832 if (*tree == NULL) {
833 err = got_error(GOT_ERR_PRIVSEP_MSG);
834 break;
836 if (datalen < sizeof(ite) || datalen > MAX_IMSGSIZE) {
837 err = got_error(GOT_ERR_PRIVSEP_LEN);
838 break;
841 /* Remaining data contains the entry's name. */
842 datalen -= sizeof(ite);
843 memcpy(&ite, imsg.data, sizeof(ite));
844 if (datalen == 0 || datalen > MAX_IMSGSIZE) {
845 err = got_error(GOT_ERR_PRIVSEP_LEN);
846 break;
849 te = got_alloc_tree_entry_partial();
850 if (te == NULL) {
851 err = got_error_from_errno();
852 break;
854 te->name = malloc(datalen + 1);
855 if (te->name == NULL) {
856 free(te);
857 err = got_error_from_errno();
858 break;
860 memcpy(te->name, imsg.data + sizeof(ite), datalen);
861 te->name[datalen] = '\0';
863 memcpy(te->id->sha1, ite.id, SHA1_DIGEST_LENGTH);
864 te->mode = ite.mode;
865 SIMPLEQ_INSERT_TAIL(&(*tree)->entries.head, te, entry);
866 nentries++;
867 break;
868 default:
869 err = got_error(GOT_ERR_PRIVSEP_MSG);
870 break;
873 imsg_free(&imsg);
875 done:
876 if (*tree && (*tree)->entries.nentries != nentries) {
877 if (err == NULL)
878 err = got_error(GOT_ERR_PRIVSEP_LEN);
879 got_object_tree_close(*tree);
880 *tree = NULL;
883 return err;
886 const struct got_error *
887 got_privsep_send_blob(struct imsgbuf *ibuf, size_t size)
889 struct got_imsg_blob iblob;
891 iblob.size = size;
892 /* Data has already been written to file descriptor. */
894 if (imsg_compose(ibuf, GOT_IMSG_BLOB, 0, 0, -1, &iblob, sizeof(iblob))
895 == -1)
896 return got_error_from_errno();
898 return flush_imsg(ibuf);
901 const struct got_error *
902 got_privsep_recv_blob(size_t *size, struct imsgbuf *ibuf)
904 const struct got_error *err = NULL;
905 struct imsg imsg;
906 struct got_imsg_blob iblob;
907 size_t datalen;
909 err = got_privsep_recv_imsg(&imsg, ibuf, 0);
910 if (err)
911 return err;
913 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
915 switch (imsg.hdr.type) {
916 case GOT_IMSG_ERROR:
917 err = recv_imsg_error(&imsg, datalen);
918 break;
919 case GOT_IMSG_BLOB:
920 if (datalen != sizeof(iblob))
921 err = got_error(GOT_ERR_PRIVSEP_LEN);
922 memcpy(&iblob, imsg.data, sizeof(iblob));
923 *size = iblob.size;
924 /* Data has been written to file descriptor. */
925 break;
926 default:
927 err = got_error(GOT_ERR_PRIVSEP_MSG);
928 break;
931 imsg_free(&imsg);
933 return err;
936 const struct got_error *
937 got_privsep_init_pack_child(struct imsgbuf *ibuf, struct got_pack *pack,
938 struct got_packidx *packidx)
940 struct got_imsg_packidx ipackidx;
941 struct got_imsg_pack ipack;
942 int fd;
944 ipackidx.len = packidx->len;
945 fd = dup(packidx->fd);
946 if (fd == -1)
947 return got_error_from_errno();
949 if (imsg_compose(ibuf, GOT_IMSG_PACKIDX, 0, 0, fd, &ipackidx,
950 sizeof(ipackidx)) == -1)
951 return got_error_from_errno();
953 if (strlcpy(ipack.path_packfile, pack->path_packfile,
954 sizeof(ipack.path_packfile)) >= sizeof(ipack.path_packfile))
955 return got_error(GOT_ERR_NO_SPACE);
956 ipack.filesize = pack->filesize;
958 fd = dup(pack->fd);
959 if (fd == -1)
960 return got_error_from_errno();
962 if (imsg_compose(ibuf, GOT_IMSG_PACK, 0, 0, fd, &ipack, sizeof(ipack))
963 == -1)
964 return got_error_from_errno();
966 return flush_imsg(ibuf);
969 const struct got_error *
970 got_privsep_send_packed_obj_req(struct imsgbuf *ibuf, int idx)
972 struct got_imsg_packed_object iobj;
974 iobj.idx = idx;
976 if (imsg_compose(ibuf, GOT_IMSG_PACKED_OBJECT_REQUEST, 0, 0, -1,
977 &iobj, sizeof(iobj)) == -1)
978 return got_error_from_errno();
980 return flush_imsg(ibuf);