2 * Copyright (c) 2018, 2019, 2020 Stefan Sperling <stsp@openbsd.org>
4 * Permission to use, copy, modify, and distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 #include <sys/types.h>
30 #include "got_compat.h"
32 #include "got_error.h"
33 #include "got_object.h"
35 #include "got_lib_delta.h"
36 #include "got_lib_inflate.h"
37 #include "got_lib_object.h"
38 #include "got_lib_object_parse.h"
39 #include "got_lib_privsep.h"
40 #include "got_lib_sha1.h"
42 static volatile sig_atomic_t sigint_received;
45 catch_sigint(int signo)
50 static const struct got_error *
51 read_commit_object(struct got_commit_object **commit, FILE *f,
52 struct got_object_id *expected_id)
54 struct got_object *obj = NULL;
55 const struct got_error *err = NULL;
58 struct got_inflate_checksum csum;
60 struct got_object_id id;
63 memset(&csum, 0, sizeof(csum));
64 csum.output_sha1 = &sha1_ctx;
66 err = got_inflate_to_mem(&p, &len, NULL, &csum, f);
70 SHA1Final(id.sha1, &sha1_ctx);
71 if (memcmp(expected_id->sha1, id.sha1, SHA1_DIGEST_LENGTH) != 0) {
72 char buf[SHA1_DIGEST_STRING_LENGTH];
73 err = got_error_fmt(GOT_ERR_OBJ_CSUM,
74 "checksum failure for object %s",
75 got_sha1_digest_to_str(expected_id->sha1, buf,
80 err = got_object_parse_header(&obj, p, len);
84 if (len < obj->hdrlen + obj->size) {
85 err = got_error(GOT_ERR_BAD_OBJ_DATA);
89 if (obj->type != GOT_OBJ_TYPE_COMMIT) {
90 err = got_error(GOT_ERR_OBJ_TYPE);
94 /* Skip object header. */
96 err = got_object_parse_commit(commit, p + obj->hdrlen, len);
100 got_object_close(obj);
105 main(int argc, char *argv[])
107 const struct got_error *err = NULL;
111 signal(SIGINT, catch_sigint);
113 imsg_init(&ibuf, GOT_IMSG_FD_CHILD);
116 /* revoke access to most system calls */
117 if (pledge("stdio recvfd", NULL) == -1) {
118 err = got_error_from_errno("pledge");
119 got_privsep_send_error(&ibuf, err);
123 /* revoke fs access */
124 if (landlock_no_fs() == -1) {
125 err = got_error_from_errno("landlock_no_fs");
126 got_privsep_send_error(&ibuf, err);
134 struct got_commit_object *commit = NULL;
135 struct got_object_id expected_id;
137 if (sigint_received) {
138 err = got_error(GOT_ERR_CANCELLED);
142 err = got_privsep_recv_imsg(&imsg, &ibuf, 0);
144 if (err->code == GOT_ERR_PRIVSEP_PIPE)
149 if (imsg.hdr.type == GOT_IMSG_STOP)
152 if (imsg.hdr.type != GOT_IMSG_COMMIT_REQUEST) {
153 err = got_error(GOT_ERR_PRIVSEP_MSG);
157 datalen = imsg.hdr.len - IMSG_HEADER_SIZE;
158 if (datalen != sizeof(expected_id)) {
159 err = got_error(GOT_ERR_PRIVSEP_LEN);
162 memcpy(&expected_id, imsg.data, sizeof(expected_id));
165 err = got_error(GOT_ERR_PRIVSEP_NO_FD);
169 /* Always assume file offset zero. */
170 f = fdopen(imsg.fd, "rb");
172 err = got_error_from_errno("fdopen");
176 err = read_commit_object(&commit, f, &expected_id);
180 err = got_privsep_send_commit(&ibuf, commit);
181 got_object_commit_close(commit);
184 if (fclose(f) == EOF && err == NULL)
185 err = got_error_from_errno("fclose");
186 } else if (imsg.fd != -1) {
187 if (close(imsg.fd) == -1 && err == NULL)
188 err = got_error_from_errno("close");
197 if (!sigint_received && err->code != GOT_ERR_PRIVSEP_PIPE) {
198 fprintf(stderr, "%s: %s\n", getprogname(), err->msg);
199 got_privsep_send_error(&ibuf, err);
202 if (close(GOT_IMSG_FD_CHILD) == -1 && err == NULL)
203 err = got_error_from_errno("close");