2 * Copyright (c) 2019 Ori Bernstein <ori@openbsd.org>
3 * Copyright (c) 2021 Stefan Sperling <stsp@openbsd.org>
5 * Permission to use, copy, modify, and distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18 #include <sys/types.h>
19 #include <sys/queue.h>
37 #include "got_error.h"
38 #include "got_object.h"
40 #include "got_version.h"
41 #include "got_fetch.h"
42 #include "got_reference.h"
44 #include "got_lib_sha1.h"
45 #include "got_lib_delta.h"
46 #include "got_lib_object.h"
47 #include "got_lib_object_parse.h"
48 #include "got_lib_privsep.h"
49 #include "got_lib_pack.h"
50 #include "got_lib_pkt.h"
51 #include "got_lib_gitproto.h"
52 #include "got_lib_ratelimit.h"
53 #include "got_lib_poll.h"
56 #define nitems(_a) (sizeof((_a)) / sizeof((_a)[0]))
59 struct got_object *indexed;
62 static const struct got_capability got_capabilities[] = {
63 { GOT_CAPA_AGENT, "got/" GOT_VERSION_STR },
64 { GOT_CAPA_OFS_DELTA, NULL },
66 { GOT_CAPA_SIDE_BAND_64K, NULL },
68 { GOT_CAPA_REPORT_STATUS, NULL },
69 { GOT_CAPA_DELETE_REFS, NULL },
72 static const struct got_error *
73 send_upload_progress(struct imsgbuf *ibuf, off_t bytes,
74 struct got_ratelimit *rl)
76 const struct got_error *err = NULL;
80 err = got_ratelimit_check(&elapsed, rl);
85 if (imsg_compose(ibuf, GOT_IMSG_SEND_UPLOAD_PROGRESS, 0, 0, -1,
86 &bytes, sizeof(bytes)) == -1)
87 return got_error_from_errno(
88 "imsg_compose SEND_UPLOAD_PROGRESS");
90 return got_privsep_flush_imsg(ibuf);
93 static const struct got_error *
94 send_pack_request(struct imsgbuf *ibuf)
96 if (imsg_compose(ibuf, GOT_IMSG_SEND_PACK_REQUEST, 0, 0, -1,
98 return got_error_from_errno("imsg_compose SEND_PACK_REQUEST");
99 return got_privsep_flush_imsg(ibuf);
102 static const struct got_error *
103 send_done(struct imsgbuf *ibuf)
105 if (imsg_compose(ibuf, GOT_IMSG_SEND_DONE, 0, 0, -1, NULL, 0) == -1)
106 return got_error_from_errno("imsg_compose SEND_DONE");
107 return got_privsep_flush_imsg(ibuf);
110 static const struct got_error *
111 recv_packfd(int *packfd, struct imsgbuf *ibuf)
113 const struct got_error *err;
118 err = got_privsep_recv_imsg(&imsg, ibuf, 0);
122 if (imsg.hdr.type == GOT_IMSG_STOP) {
123 err = got_error(GOT_ERR_CANCELLED);
127 if (imsg.hdr.type != GOT_IMSG_SEND_PACKFD) {
128 err = got_error(GOT_ERR_PRIVSEP_MSG);
132 if (imsg.hdr.len - IMSG_HEADER_SIZE != 0) {
133 err = got_error(GOT_ERR_PRIVSEP_LEN);
143 static const struct got_error *
144 send_pack_file(int sendfd, int packfd, struct imsgbuf *ibuf)
146 const struct got_error *err;
147 unsigned char buf[8192];
150 struct got_ratelimit rl;
152 if (lseek(packfd, 0L, SEEK_SET) == -1)
153 return got_error_from_errno("lseek");
155 got_ratelimit_init(&rl, 0, 500);
158 r = read(packfd, buf, sizeof(buf));
160 return got_error_from_errno("read");
163 err = got_poll_write_full(sendfd, buf, r);
167 err = send_upload_progress(ibuf, wtotal, &rl);
172 return send_upload_progress(ibuf, wtotal, NULL);
175 static const struct got_error *
176 send_error(const char *buf, size_t len)
178 static char msg[1024];
181 for (i = 0; i < len && i < sizeof(msg) - 1; i++) {
182 if (!isprint((unsigned char)buf[i]))
183 return got_error_msg(GOT_ERR_BAD_PACKET,
184 "non-printable error message received from server");
188 return got_error_msg(GOT_ERR_SEND_FAILED, msg);
191 static const struct got_error *
192 send_their_ref(struct imsgbuf *ibuf, struct got_object_id *refid,
196 size_t len, reflen = strlen(refname);
198 len = sizeof(struct got_imsg_send_remote_ref) + reflen;
199 if (len >= MAX_IMSGSIZE - IMSG_HEADER_SIZE)
200 return got_error(GOT_ERR_NO_SPACE);
202 wbuf = imsg_create(ibuf, GOT_IMSG_SEND_REMOTE_REF, 0, 0, len);
204 return got_error_from_errno("imsg_create SEND_REMOTE_REF");
206 /* Keep in sync with struct got_imsg_send_remote_ref definition! */
207 if (imsg_add(wbuf, refid->sha1, SHA1_DIGEST_LENGTH) == -1)
208 return got_error_from_errno("imsg_add SEND_REMOTE_REF");
209 if (imsg_add(wbuf, &reflen, sizeof(reflen)) == -1)
210 return got_error_from_errno("imsg_add SEND_REMOTE_REF");
211 if (imsg_add(wbuf, refname, reflen) == -1)
212 return got_error_from_errno("imsg_add SEND_REMOTE_REF");
215 imsg_close(ibuf, wbuf);
216 return got_privsep_flush_imsg(ibuf);
219 static const struct got_error *
220 send_ref_status(struct imsgbuf *ibuf, const char *refname, int success,
221 struct got_pathlist_head *refs, struct got_pathlist_head *delete_refs)
224 size_t i, len, reflen, errmsglen = 0;
225 struct got_pathlist_entry *pe;
228 const char *errmsg = "";
230 eol = strchr(refname, '\n');
232 return got_error_msg(GOT_ERR_BAD_PACKET,
233 "unexpected message from server");
237 sp = strchr(refname, ' ');
241 errmsglen = strlen(errmsg);
243 for (i = 0; i < errmsglen; ++i) {
244 if (!isprint((unsigned char)errmsg[i])) {
245 return got_error_msg(GOT_ERR_BAD_PACKET,
246 "non-printable error message received "
252 reflen = strlen(refname);
253 if (!got_ref_name_is_valid(refname)) {
254 return got_error_msg(GOT_ERR_BAD_PACKET,
255 "unexpected message from server");
258 TAILQ_FOREACH(pe, refs, entry) {
259 if (strcmp(refname, pe->path) == 0) {
265 TAILQ_FOREACH(pe, delete_refs, entry) {
266 if (strcmp(refname, pe->path) == 0) {
273 return got_error_msg(GOT_ERR_BAD_PACKET,
274 "unexpected message from server");
277 len = sizeof(struct got_imsg_send_ref_status) + reflen + errmsglen;
278 if (len >= MAX_IMSGSIZE - IMSG_HEADER_SIZE)
279 return got_error(GOT_ERR_NO_SPACE);
281 wbuf = imsg_create(ibuf, GOT_IMSG_SEND_REF_STATUS,
284 return got_error_from_errno("imsg_create SEND_REF_STATUS");
286 /* Keep in sync with struct got_imsg_send_ref_status definition! */
287 if (imsg_add(wbuf, &success, sizeof(success)) == -1)
288 return got_error_from_errno("imsg_add SEND_REF_STATUS");
289 if (imsg_add(wbuf, &reflen, sizeof(reflen)) == -1)
290 return got_error_from_errno("imsg_add SEND_REF_STATUS");
291 if (imsg_add(wbuf, &errmsglen, sizeof(errmsglen)) == -1)
292 return got_error_from_errno("imsg_add SEND_REF_STATUS");
293 if (imsg_add(wbuf, refname, reflen) == -1)
294 return got_error_from_errno("imsg_add SEND_REF_STATUS");
295 if (imsg_add(wbuf, errmsg, errmsglen) == -1)
296 return got_error_from_errno("imsg_add SEND_REF_STATUS");
299 imsg_close(ibuf, wbuf);
300 return got_privsep_flush_imsg(ibuf);
303 static const struct got_error *
304 describe_refchange(int *n, int *sent_my_capabilites,
305 const char *my_capabilities, char *buf, size_t bufsize,
306 const char *refname, const char *old_hashstr, const char *new_hashstr)
308 *n = snprintf(buf, bufsize, "%s %s %s",
309 old_hashstr, new_hashstr, refname);
310 if (*n < 0 || (size_t)*n >= bufsize)
311 return got_error(GOT_ERR_NO_SPACE);
314 * We must announce our capabilities along with the first
315 * reference. Unfortunately, the protocol requires an embedded
316 * NUL as a separator between reference name and capabilities,
317 * which we have to deal with here.
318 * It also requires a linefeed for terminating packet data.
320 if (!*sent_my_capabilites && my_capabilities != NULL) {
322 if (*n >= bufsize - 1)
323 return got_error(GOT_ERR_NO_SPACE);
324 m = snprintf(buf + *n + 1, /* offset after '\0' */
325 bufsize - (*n + 1), "%s\n", my_capabilities);
326 if (m < 0 || *n + m >= bufsize)
327 return got_error(GOT_ERR_NO_SPACE);
329 *sent_my_capabilites = 1;
331 *n = strlcat(buf, "\n", bufsize);
333 return got_error(GOT_ERR_NO_SPACE);
339 static const struct got_error *
340 send_pack(int fd, struct got_pathlist_head *refs,
341 struct got_pathlist_head *delete_refs, struct imsgbuf *ibuf)
343 const struct got_error *err = NULL;
344 char buf[GOT_PKT_MAX];
345 const unsigned char zero_id[SHA1_DIGEST_LENGTH] = { 0 };
346 char old_hashstr[SHA1_DIGEST_STRING_LENGTH];
347 char new_hashstr[SHA1_DIGEST_STRING_LENGTH];
348 struct got_pathlist_head their_refs;
352 char *id_str = NULL, *refname = NULL;
353 struct got_object_id *id = NULL;
354 char *server_capabilities = NULL, *my_capabilities = NULL;
355 struct got_pathlist_entry *pe;
356 int sent_my_capabilites = 0;
358 TAILQ_INIT(&their_refs);
360 if (TAILQ_EMPTY(refs) && TAILQ_EMPTY(delete_refs))
361 return got_error(GOT_ERR_SEND_EMPTY);
364 err = got_pkt_readpkt(&n, fd, buf, sizeof(buf), chattygot);
369 if (n >= 4 && strncmp(buf, "ERR ", 4) == 0) {
370 err = send_error(&buf[4], n - 4);
375 err = got_gitproto_parse_refline(&id_str, &refname,
376 &server_capabilities, buf, n);
380 if (server_capabilities == NULL) {
381 server_capabilities = strdup("");
382 if (server_capabilities == NULL) {
383 err = got_error_from_errno("strdup");
387 if (chattygot && server_capabilities[0] != '\0')
388 fprintf(stderr, "%s: server capabilities: %s\n",
389 getprogname(), server_capabilities);
390 err = got_gitproto_match_capabilities(&my_capabilities,
391 NULL, server_capabilities, got_capabilities,
392 nitems(got_capabilities));
396 fprintf(stderr, "%s: my capabilities:%s\n",
398 my_capabilities ? my_capabilities : "");
401 if (strstr(refname, "^{}")) {
403 fprintf(stderr, "%s: ignoring %s\n",
404 getprogname(), refname);
409 id = malloc(sizeof(*id));
411 err = got_error_from_errno("malloc");
414 if (!got_parse_sha1_digest(id->sha1, id_str)) {
415 err = got_error(GOT_ERR_BAD_OBJ_ID_STR);
418 err = send_their_ref(ibuf, id, refname);
422 err = got_pathlist_append(&their_refs, refname, id);
427 fprintf(stderr, "%s: remote has %s %s\n",
428 getprogname(), refname, id_str);
431 refname = NULL; /* do not free; owned by their_refs */
432 id = NULL; /* do not free; owned by their_refs */
435 if (!TAILQ_EMPTY(delete_refs)) {
436 if (my_capabilities == NULL ||
437 strstr(my_capabilities, GOT_CAPA_DELETE_REFS) == NULL) {
438 err = got_error(GOT_ERR_CAPA_DELETE_REFS);
443 TAILQ_FOREACH(pe, delete_refs, entry) {
444 const char *refname = pe->path;
445 struct got_pathlist_entry *their_pe;
446 struct got_object_id *their_id = NULL;
448 TAILQ_FOREACH(their_pe, &their_refs, entry) {
449 const char *their_refname = their_pe->path;
450 if (got_path_cmp(refname, their_refname,
451 strlen(refname), strlen(their_refname)) == 0) {
452 their_id = their_pe->data;
456 if (their_id == NULL) {
457 err = got_error_fmt(GOT_ERR_NOT_REF,
458 "%s does not exist in remote repository",
463 got_sha1_digest_to_str(their_id->sha1, old_hashstr,
464 sizeof(old_hashstr));
465 got_sha1_digest_to_str(zero_id, new_hashstr,
466 sizeof(new_hashstr));
467 err = describe_refchange(&n, &sent_my_capabilites,
468 my_capabilities, buf, sizeof(buf), refname,
469 old_hashstr, new_hashstr);
472 err = got_pkt_writepkt(fd, buf, n, chattygot);
476 fprintf(stderr, "%s: deleting %s %s\n",
477 getprogname(), refname, old_hashstr);
482 TAILQ_FOREACH(pe, refs, entry) {
483 const char *refname = pe->path;
484 struct got_object_id *id = pe->data;
485 struct got_object_id *their_id = NULL;
486 struct got_pathlist_entry *their_pe;
488 TAILQ_FOREACH(their_pe, &their_refs, entry) {
489 const char *their_refname = their_pe->path;
490 if (got_path_cmp(refname, their_refname,
491 strlen(refname), strlen(their_refname)) == 0) {
492 their_id = their_pe->data;
497 if (got_object_id_cmp(id, their_id) == 0) {
500 "%s: no change for %s\n",
501 getprogname(), refname);
505 got_sha1_digest_to_str(their_id->sha1, old_hashstr,
506 sizeof(old_hashstr));
508 got_sha1_digest_to_str(zero_id, old_hashstr,
509 sizeof(old_hashstr));
511 got_sha1_digest_to_str(id->sha1, new_hashstr,
512 sizeof(new_hashstr));
513 err = describe_refchange(&n, &sent_my_capabilites,
514 my_capabilities, buf, sizeof(buf), refname,
515 old_hashstr, new_hashstr);
518 err = got_pkt_writepkt(fd, buf, n, chattygot);
523 fprintf(stderr, "%s: updating %s %s -> %s\n",
524 getprogname(), refname, old_hashstr,
527 fprintf(stderr, "%s: creating %s %s\n",
528 getprogname(), refname, new_hashstr);
533 err = got_pkt_flushpkt(fd, chattygot);
537 err = send_pack_request(ibuf);
541 err = recv_packfd(&packfd, ibuf);
546 err = send_pack_file(fd, packfd, ibuf);
551 err = got_pkt_readpkt(&n, fd, buf, sizeof(buf), chattygot);
554 if (n >= 4 && strncmp(buf, "ERR ", 4) == 0) {
555 err = send_error(&buf[4], n - 4);
557 } else if (n < 10 || strncmp(buf, "unpack ok\n", 10) != 0) {
558 err = got_error_msg(GOT_ERR_BAD_PACKET,
559 "unexpected message from server");
564 err = got_pkt_readpkt(&n, fd, buf, sizeof(buf), chattygot);
568 err = got_error_msg(GOT_ERR_BAD_PACKET,
569 "unexpected message from server");
571 } else if (n >= 4 && strncmp(buf, "ERR ", 4) == 0) {
572 err = send_error(&buf[4], n - 4);
574 } else if (strncmp(buf, "ok ", 3) == 0) {
575 err = send_ref_status(ibuf, buf + 3, 1,
579 } else if (strncmp(buf, "ng ", 3) == 0) {
580 err = send_ref_status(ibuf, buf + 3, 0,
585 err = got_error_msg(GOT_ERR_BAD_PACKET,
586 "unexpected message from server");
592 err = send_done(ibuf);
594 TAILQ_FOREACH(pe, &their_refs, entry) {
595 free((void *)pe->path);
598 got_pathlist_free(&their_refs);
602 free(server_capabilities);
607 main(int argc, char **argv)
609 const struct got_error *err = NULL;
613 struct got_pathlist_head refs;
614 struct got_pathlist_head delete_refs;
615 struct got_pathlist_entry *pe;
616 struct got_imsg_send_request send_req;
617 struct got_imsg_send_ref href;
626 TAILQ_INIT(&delete_refs);
628 imsg_init(&ibuf, GOT_IMSG_FD_CHILD);
630 /* revoke access to most system calls */
631 if (pledge("stdio recvfd", NULL) == -1) {
632 err = got_error_from_errno("pledge");
633 got_privsep_send_error(&ibuf, err);
637 /* revoke fs access */
638 if (landlock_no_fs() == -1) {
639 err = got_error_from_errno("landlock_no_fs");
640 got_privsep_send_error(&ibuf, err);
643 if (cap_enter() == -1) {
644 err = got_error_from_errno("cap_enter");
645 got_privsep_send_error(&ibuf, err);
649 if ((err = got_privsep_recv_imsg(&imsg, &ibuf, 0)) != 0) {
650 if (err->code == GOT_ERR_PRIVSEP_PIPE)
654 if (imsg.hdr.type == GOT_IMSG_STOP)
656 if (imsg.hdr.type != GOT_IMSG_SEND_REQUEST) {
657 err = got_error(GOT_ERR_PRIVSEP_MSG);
660 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
661 if (datalen < sizeof(send_req)) {
662 err = got_error(GOT_ERR_PRIVSEP_LEN);
665 memcpy(&send_req, imsg.data, sizeof(send_req));
669 if (send_req.verbosity > 0)
670 chattygot += send_req.verbosity;
672 for (i = 0; i < send_req.nrefs; i++) {
673 struct got_object_id *id;
676 if ((err = got_privsep_recv_imsg(&imsg, &ibuf, 0)) != 0) {
677 if (err->code == GOT_ERR_PRIVSEP_PIPE)
681 if (imsg.hdr.type == GOT_IMSG_STOP)
683 if (imsg.hdr.type != GOT_IMSG_SEND_REF) {
684 err = got_error(GOT_ERR_PRIVSEP_MSG);
687 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
688 if (datalen < sizeof(href)) {
689 err = got_error(GOT_ERR_PRIVSEP_LEN);
692 memcpy(&href, imsg.data, sizeof(href));
693 if (datalen - sizeof(href) < href.name_len) {
694 err = got_error(GOT_ERR_PRIVSEP_LEN);
697 refname = malloc(href.name_len + 1);
698 if (refname == NULL) {
699 err = got_error_from_errno("malloc");
702 memcpy(refname, imsg.data + sizeof(href), href.name_len);
703 refname[href.name_len] = '\0';
706 * Prevent sending of references that won't make any
707 * sense outside the local repository's context.
709 if (strncmp(refname, "refs/got/", 9) == 0 ||
710 strncmp(refname, "refs/remotes/", 13) == 0) {
711 err = got_error_fmt(GOT_ERR_SEND_BAD_REF,
716 id = malloc(sizeof(*id));
719 err = got_error_from_errno("malloc");
722 memcpy(id->sha1, href.id, SHA1_DIGEST_LENGTH);
724 err = got_pathlist_append(&delete_refs, refname, id);
726 err = got_pathlist_append(&refs, refname, id);
736 err = send_pack(sendfd, &refs, &delete_refs, &ibuf);
738 TAILQ_FOREACH(pe, &refs, entry) {
739 free((char *)pe->path);
742 got_pathlist_free(&refs);
743 TAILQ_FOREACH(pe, &delete_refs, entry) {
744 free((char *)pe->path);
747 got_pathlist_free(&delete_refs);
748 if (sendfd != -1 && close(sendfd) == -1 && err == NULL)
749 err = got_error_from_errno("close");
750 if (err != NULL && err->code != GOT_ERR_CANCELLED) {
751 fprintf(stderr, "%s: %s\n", getprogname(), err->msg);
752 got_privsep_send_error(&ibuf, err);