2 * Copyright (c) 2018 Stefan Sperling <stsp@openbsd.org>
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 #include <sys/types.h>
18 #include <sys/queue.h>
31 #include "got_compat.h"
33 #include "got_error.h"
34 #include "got_object.h"
36 #include "got_lib_delta.h"
37 #include "got_lib_inflate.h"
38 #include "got_lib_object.h"
39 #include "got_lib_object_parse.h"
40 #include "got_lib_privsep.h"
41 #include "got_lib_hash.h"
43 static volatile sig_atomic_t sigint_received;
46 catch_sigint(int signo)
52 main(int argc, char *argv[])
54 const struct got_error *err = NULL;
58 signal(SIGINT, catch_sigint);
60 imsg_init(&ibuf, GOT_IMSG_FD_CHILD);
63 /* revoke access to most system calls */
64 if (pledge("stdio recvfd", NULL) == -1) {
65 err = got_error_from_errno("pledge");
66 got_privsep_send_error(&ibuf, err);
70 /* revoke fs access */
71 if (landlock_no_fs() == -1) {
72 err = got_error_from_errno("landlock_no_fs");
73 got_privsep_send_error(&ibuf, err);
76 if (cap_enter() == -1) {
77 err = got_error_from_errno("cap_enter");
78 got_privsep_send_error(&ibuf, err);
85 struct got_tag_object *tag = NULL;
86 struct got_object_id expected_id;
89 if (sigint_received) {
90 err = got_error(GOT_ERR_CANCELLED);
94 err = got_privsep_recv_imsg(&imsg, &ibuf, 0);
96 if (err->code == GOT_ERR_PRIVSEP_PIPE)
101 if (imsg.hdr.type == GOT_IMSG_STOP)
104 if (imsg.hdr.type != GOT_IMSG_TAG_REQUEST) {
105 err = got_error(GOT_ERR_PRIVSEP_MSG);
109 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
110 if (datalen != sizeof(expected_id)) {
111 err = got_error(GOT_ERR_PRIVSEP_LEN);
114 memcpy(&expected_id, imsg.data, sizeof(expected_id));
116 fd = imsg_get_fd(&imsg);
118 err = got_error(GOT_ERR_PRIVSEP_NO_FD);
122 /* Always assume file offset zero. */
123 err = got_object_read_tag(&tag, fd, &expected_id, 0);
127 err = got_privsep_send_tag(&ibuf, tag);
129 if (fd != -1 && close(fd) == -1 && err == NULL)
130 err = got_error_from_errno("close");
138 if (!sigint_received && err->code != GOT_ERR_PRIVSEP_PIPE) {
139 fprintf(stderr, "%s: %s\n", getprogname(), err->msg);
140 got_privsep_send_error(&ibuf, err);
143 if (close(GOT_IMSG_FD_CHILD) == -1 && err == NULL)
144 err = got_error_from_errno("close");