1 /*
2  * Copyright (C) the libgit2 contributors. All rights reserved.
3  *
4  * This file is part of libgit2, distributed under the GNU GPL v2 with
5  * a Linking Exception. For full terms see the included COPYING file.
6  */
7 
8 #include "filebuf.h"
9 
10 #include "futils.h"
11 
12 static const size_t WRITE_BUFFER_SIZE = (4096 * 2);
13 
14 enum buferr_t {
15 	BUFERR_OK = 0,
16 	BUFERR_WRITE,
17 	BUFERR_ZLIB,
18 	BUFERR_MEM
19 };
20 
21 #define ENSURE_BUF_OK(buf) if ((buf)->last_error != BUFERR_OK) { return -1; }
22 
verify_last_error(git_filebuf * file)23 static int verify_last_error(git_filebuf *file)
24 {
25 	switch (file->last_error) {
26 	case BUFERR_WRITE:
27 		git_error_set(GIT_ERROR_OS, "failed to write out file");
28 		return -1;
29 
30 	case BUFERR_MEM:
31 		git_error_set_oom();
32 		return -1;
33 
34 	case BUFERR_ZLIB:
35 		git_error_set(GIT_ERROR_ZLIB,
36 			"Buffer error when writing out ZLib data");
37 		return -1;
38 
39 	default:
40 		return 0;
41 	}
42 }
43 
lock_file(git_filebuf * file,int flags,mode_t mode)44 static int lock_file(git_filebuf *file, int flags, mode_t mode)
45 {
46 	if (git_path_exists(file->path_lock) == true) {
47 		git_error_clear(); /* actual OS error code just confuses */
48 		git_error_set(GIT_ERROR_OS,
49 			"failed to lock file '%s' for writing", file->path_lock);
50 		return GIT_ELOCKED;
51 	}
52 
53 	/* create path to the file buffer is required */
54 	if (flags & GIT_FILEBUF_CREATE_LEADING_DIRS) {
55 		/* XXX: Should dirmode here be configurable? Or is 0777 always fine? */
56 		file->fd = git_futils_creat_locked_withpath(file->path_lock, 0777, mode);
57 	} else {
58 		file->fd = git_futils_creat_locked(file->path_lock, mode);
59 	}
60 
61 	if (file->fd < 0)
62 		return file->fd;
63 
64 	file->fd_is_open = true;
65 
66 	if ((flags & GIT_FILEBUF_APPEND) && git_path_exists(file->path_original) == true) {
67 		git_file source;
68 		char buffer[FILEIO_BUFSIZE];
69 		ssize_t read_bytes;
70 		int error = 0;
71 
72 		source = p_open(file->path_original, O_RDONLY);
73 		if (source < 0) {
74 			git_error_set(GIT_ERROR_OS,
75 				"failed to open file '%s' for reading",
76 				file->path_original);
77 			return -1;
78 		}
79 
80 		while ((read_bytes = p_read(source, buffer, sizeof(buffer))) > 0) {
81 			if ((error = p_write(file->fd, buffer, read_bytes)) < 0)
82 				break;
83 			if (file->compute_digest)
84 				git_hash_update(&file->digest, buffer, read_bytes);
85 		}
86 
87 		p_close(source);
88 
89 		if (read_bytes < 0) {
90 			git_error_set(GIT_ERROR_OS, "failed to read file '%s'", file->path_original);
91 			return -1;
92 		} else if (error < 0) {
93 			git_error_set(GIT_ERROR_OS, "failed to write file '%s'", file->path_lock);
94 			return -1;
95 		}
96 	}
97 
98 	return 0;
99 }
100 
git_filebuf_cleanup(git_filebuf * file)101 void git_filebuf_cleanup(git_filebuf *file)
102 {
103 	if (file->fd_is_open && file->fd >= 0)
104 		p_close(file->fd);
105 
106 	if (file->created_lock && !file->did_rename && file->path_lock && git_path_exists(file->path_lock))
107 		p_unlink(file->path_lock);
108 
109 	if (file->compute_digest) {
110 		git_hash_ctx_cleanup(&file->digest);
111 		file->compute_digest = 0;
112 	}
113 
114 	if (file->buffer)
115 		git__free(file->buffer);
116 
117 	/* use the presence of z_buf to decide if we need to deflateEnd */
118 	if (file->z_buf) {
119 		git__free(file->z_buf);
120 		deflateEnd(&file->zs);
121 	}
122 
123 	if (file->path_original)
124 		git__free(file->path_original);
125 	if (file->path_lock)
126 		git__free(file->path_lock);
127 
128 	memset(file, 0x0, sizeof(git_filebuf));
129 	file->fd = -1;
130 }
131 
flush_buffer(git_filebuf * file)132 GIT_INLINE(int) flush_buffer(git_filebuf *file)
133 {
134 	int result = file->write(file, file->buffer, file->buf_pos);
135 	file->buf_pos = 0;
136 	return result;
137 }
138 
git_filebuf_flush(git_filebuf * file)139 int git_filebuf_flush(git_filebuf *file)
140 {
141 	return flush_buffer(file);
142 }
143 
write_normal(git_filebuf * file,void * source,size_t len)144 static int write_normal(git_filebuf *file, void *source, size_t len)
145 {
146 	if (len > 0) {
147 		if (p_write(file->fd, (void *)source, len) < 0) {
148 			file->last_error = BUFERR_WRITE;
149 			return -1;
150 		}
151 
152 		if (file->compute_digest)
153 			git_hash_update(&file->digest, source, len);
154 	}
155 
156 	return 0;
157 }
158 
write_deflate(git_filebuf * file,void * source,size_t len)159 static int write_deflate(git_filebuf *file, void *source, size_t len)
160 {
161 	z_stream *zs = &file->zs;
162 
163 	if (len > 0 || file->flush_mode == Z_FINISH) {
164 		zs->next_in = source;
165 		zs->avail_in = (uInt)len;
166 
167 		do {
168 			size_t have;
169 
170 			zs->next_out = file->z_buf;
171 			zs->avail_out = (uInt)file->buf_size;
172 
173 			if (deflate(zs, file->flush_mode) == Z_STREAM_ERROR) {
174 				file->last_error = BUFERR_ZLIB;
175 				return -1;
176 			}
177 
178 			have = file->buf_size - (size_t)zs->avail_out;
179 
180 			if (p_write(file->fd, file->z_buf, have) < 0) {
181 				file->last_error = BUFERR_WRITE;
182 				return -1;
183 			}
184 
185 		} while (zs->avail_out == 0);
186 
187 		assert(zs->avail_in == 0);
188 
189 		if (file->compute_digest)
190 			git_hash_update(&file->digest, source, len);
191 	}
192 
193 	return 0;
194 }
195 
196 #define MAX_SYMLINK_DEPTH 5
197 
resolve_symlink(git_buf * out,const char * path)198 static int resolve_symlink(git_buf *out, const char *path)
199 {
200 	int i, error, root;
201 	ssize_t ret;
202 	struct stat st;
203 	git_buf curpath = GIT_BUF_INIT, target = GIT_BUF_INIT;
204 
205 	if ((error = git_buf_grow(&target, GIT_PATH_MAX + 1)) < 0 ||
206 	    (error = git_buf_puts(&curpath, path)) < 0)
207 		return error;
208 
209 	for (i = 0; i < MAX_SYMLINK_DEPTH; i++) {
210 		error = p_lstat(curpath.ptr, &st);
211 		if (error < 0 && errno == ENOENT) {
212 			error = git_buf_puts(out, curpath.ptr);
213 			goto cleanup;
214 		}
215 
216 		if (error < 0) {
217 			git_error_set(GIT_ERROR_OS, "failed to stat '%s'", curpath.ptr);
218 			error = -1;
219 			goto cleanup;
220 		}
221 
222 		if (!S_ISLNK(st.st_mode)) {
223 			error = git_buf_puts(out, curpath.ptr);
224 			goto cleanup;
225 		}
226 
227 		ret = p_readlink(curpath.ptr, target.ptr, GIT_PATH_MAX);
228 		if (ret < 0) {
229 			git_error_set(GIT_ERROR_OS, "failed to read symlink '%s'", curpath.ptr);
230 			error = -1;
231 			goto cleanup;
232 		}
233 
234 		if (ret == GIT_PATH_MAX) {
235 			git_error_set(GIT_ERROR_INVALID, "symlink target too long");
236 			error = -1;
237 			goto cleanup;
238 		}
239 
240 		/* readlink(2) won't NUL-terminate for us */
241 		target.ptr[ret] = '\0';
242 		target.size = ret;
243 
244 		root = git_path_root(target.ptr);
245 		if (root >= 0) {
246 			if ((error = git_buf_sets(&curpath, target.ptr)) < 0)
247 				goto cleanup;
248 		} else {
249 			git_buf dir = GIT_BUF_INIT;
250 
251 			if ((error = git_path_dirname_r(&dir, curpath.ptr)) < 0)
252 				goto cleanup;
253 
254 			git_buf_swap(&curpath, &dir);
255 			git_buf_dispose(&dir);
256 
257 			if ((error = git_path_apply_relative(&curpath, target.ptr)) < 0)
258 				goto cleanup;
259 		}
260 	}
261 
262 	git_error_set(GIT_ERROR_INVALID, "maximum symlink depth reached");
263 	error = -1;
264 
265 cleanup:
266 	git_buf_dispose(&curpath);
267 	git_buf_dispose(&target);
268 	return error;
269 }
270 
git_filebuf_open(git_filebuf * file,const char * path,int flags,mode_t mode)271 int git_filebuf_open(git_filebuf *file, const char *path, int flags, mode_t mode)
272 {
273 	return git_filebuf_open_withsize(file, path, flags, mode, WRITE_BUFFER_SIZE);
274 }
275 
git_filebuf_open_withsize(git_filebuf * file,const char * path,int flags,mode_t mode,size_t size)276 int git_filebuf_open_withsize(git_filebuf *file, const char *path, int flags, mode_t mode, size_t size)
277 {
278 	int compression, error = -1;
279 	size_t path_len, alloc_len;
280 
281 	/* opening an already open buffer is a programming error;
282 	 * assert that this never happens instead of returning
283 	 * an error code */
284 	assert(file && path && file->buffer == NULL);
285 
286 	memset(file, 0x0, sizeof(git_filebuf));
287 
288 	if (flags & GIT_FILEBUF_DO_NOT_BUFFER)
289 		file->do_not_buffer = true;
290 
291 	if (flags & GIT_FILEBUF_FSYNC)
292 		file->do_fsync = true;
293 
294 	file->buf_size = size;
295 	file->buf_pos = 0;
296 	file->fd = -1;
297 	file->last_error = BUFERR_OK;
298 
299 	/* Allocate the main cache buffer */
300 	if (!file->do_not_buffer) {
301 		file->buffer = git__malloc(file->buf_size);
302 		GIT_ERROR_CHECK_ALLOC(file->buffer);
303 	}
304 
305 	/* If we are hashing on-write, allocate a new hash context */
306 	if (flags & GIT_FILEBUF_HASH_CONTENTS) {
307 		file->compute_digest = 1;
308 
309 		if (git_hash_ctx_init(&file->digest) < 0)
310 			goto cleanup;
311 	}
312 
313 	compression = flags >> GIT_FILEBUF_DEFLATE_SHIFT;
314 
315 	/* If we are deflating on-write, */
316 	if (compression != 0) {
317 		/* Initialize the ZLib stream */
318 		if (deflateInit(&file->zs, compression) != Z_OK) {
319 			git_error_set(GIT_ERROR_ZLIB, "failed to initialize zlib");
320 			goto cleanup;
321 		}
322 
323 		/* Allocate the Zlib cache buffer */
324 		file->z_buf = git__malloc(file->buf_size);
325 		GIT_ERROR_CHECK_ALLOC(file->z_buf);
326 
327 		/* Never flush */
328 		file->flush_mode = Z_NO_FLUSH;
329 		file->write = &write_deflate;
330 	} else {
331 		file->write = &write_normal;
332 	}
333 
334 	/* If we are writing to a temp file */
335 	if (flags & GIT_FILEBUF_TEMPORARY) {
336 		git_buf tmp_path = GIT_BUF_INIT;
337 
338 		/* Open the file as temporary for locking */
339 		file->fd = git_futils_mktmp(&tmp_path, path, mode);
340 
341 		if (file->fd < 0) {
342 			git_buf_dispose(&tmp_path);
343 			goto cleanup;
344 		}
345 		file->fd_is_open = true;
346 		file->created_lock = true;
347 
348 		/* No original path */
349 		file->path_original = NULL;
350 		file->path_lock = git_buf_detach(&tmp_path);
351 		GIT_ERROR_CHECK_ALLOC(file->path_lock);
352 	} else {
353 		git_buf resolved_path = GIT_BUF_INIT;
354 
355 		if ((error = resolve_symlink(&resolved_path, path)) < 0)
356 			goto cleanup;
357 
358 		/* Save the original path of the file */
359 		path_len = resolved_path.size;
360 		file->path_original = git_buf_detach(&resolved_path);
361 
362 		/* create the locking path by appending ".lock" to the original */
363 		GIT_ERROR_CHECK_ALLOC_ADD(&alloc_len, path_len, GIT_FILELOCK_EXTLENGTH);
364 		file->path_lock = git__malloc(alloc_len);
365 		GIT_ERROR_CHECK_ALLOC(file->path_lock);
366 
367 		memcpy(file->path_lock, file->path_original, path_len);
368 		memcpy(file->path_lock + path_len, GIT_FILELOCK_EXTENSION, GIT_FILELOCK_EXTLENGTH);
369 
370 		if (git_path_isdir(file->path_original)) {
371 			git_error_set(GIT_ERROR_FILESYSTEM, "path '%s' is a directory", file->path_original);
372 			error = GIT_EDIRECTORY;
373 			goto cleanup;
374 		}
375 
376 		/* open the file for locking */
377 		if ((error = lock_file(file, flags, mode)) < 0)
378 			goto cleanup;
379 
380 		file->created_lock = true;
381 	}
382 
383 	return 0;
384 
385 cleanup:
386 	git_filebuf_cleanup(file);
387 	return error;
388 }
389 
git_filebuf_hash(git_oid * oid,git_filebuf * file)390 int git_filebuf_hash(git_oid *oid, git_filebuf *file)
391 {
392 	assert(oid && file && file->compute_digest);
393 
394 	flush_buffer(file);
395 
396 	if (verify_last_error(file) < 0)
397 		return -1;
398 
399 	git_hash_final(oid, &file->digest);
400 	git_hash_ctx_cleanup(&file->digest);
401 	file->compute_digest = 0;
402 
403 	return 0;
404 }
405 
git_filebuf_commit_at(git_filebuf * file,const char * path)406 int git_filebuf_commit_at(git_filebuf *file, const char *path)
407 {
408 	git__free(file->path_original);
409 	file->path_original = git__strdup(path);
410 	GIT_ERROR_CHECK_ALLOC(file->path_original);
411 
412 	return git_filebuf_commit(file);
413 }
414 
git_filebuf_commit(git_filebuf * file)415 int git_filebuf_commit(git_filebuf *file)
416 {
417 	/* temporary files cannot be committed */
418 	assert(file && file->path_original);
419 
420 	file->flush_mode = Z_FINISH;
421 	flush_buffer(file);
422 
423 	if (verify_last_error(file) < 0)
424 		goto on_error;
425 
426 	file->fd_is_open = false;
427 
428 	if (file->do_fsync && p_fsync(file->fd) < 0) {
429 		git_error_set(GIT_ERROR_OS, "failed to fsync '%s'", file->path_lock);
430 		goto on_error;
431 	}
432 
433 	if (p_close(file->fd) < 0) {
434 		git_error_set(GIT_ERROR_OS, "failed to close file at '%s'", file->path_lock);
435 		goto on_error;
436 	}
437 
438 	file->fd = -1;
439 
440 	if (p_rename(file->path_lock, file->path_original) < 0) {
441 		git_error_set(GIT_ERROR_OS, "failed to rename lockfile to '%s'", file->path_original);
442 		goto on_error;
443 	}
444 
445 	if (file->do_fsync && git_futils_fsync_parent(file->path_original) < 0)
446 		goto on_error;
447 
448 	file->did_rename = true;
449 
450 	git_filebuf_cleanup(file);
451 	return 0;
452 
453 on_error:
454 	git_filebuf_cleanup(file);
455 	return -1;
456 }
457 
add_to_cache(git_filebuf * file,const void * buf,size_t len)458 GIT_INLINE(void) add_to_cache(git_filebuf *file, const void *buf, size_t len)
459 {
460 	memcpy(file->buffer + file->buf_pos, buf, len);
461 	file->buf_pos += len;
462 }
463 
git_filebuf_write(git_filebuf * file,const void * buff,size_t len)464 int git_filebuf_write(git_filebuf *file, const void *buff, size_t len)
465 {
466 	const unsigned char *buf = buff;
467 
468 	ENSURE_BUF_OK(file);
469 
470 	if (file->do_not_buffer)
471 		return file->write(file, (void *)buff, len);
472 
473 	for (;;) {
474 		size_t space_left = file->buf_size - file->buf_pos;
475 
476 		/* cache if it's small */
477 		if (space_left > len) {
478 			add_to_cache(file, buf, len);
479 			return 0;
480 		}
481 
482 		add_to_cache(file, buf, space_left);
483 		if (flush_buffer(file) < 0)
484 			return -1;
485 
486 		len -= space_left;
487 		buf += space_left;
488 	}
489 }
490 
git_filebuf_reserve(git_filebuf * file,void ** buffer,size_t len)491 int git_filebuf_reserve(git_filebuf *file, void **buffer, size_t len)
492 {
493 	size_t space_left = file->buf_size - file->buf_pos;
494 
495 	*buffer = NULL;
496 
497 	ENSURE_BUF_OK(file);
498 
499 	if (len > file->buf_size) {
500 		file->last_error = BUFERR_MEM;
501 		return -1;
502 	}
503 
504 	if (space_left <= len) {
505 		if (flush_buffer(file) < 0)
506 			return -1;
507 	}
508 
509 	*buffer = (file->buffer + file->buf_pos);
510 	file->buf_pos += len;
511 
512 	return 0;
513 }
514 
git_filebuf_printf(git_filebuf * file,const char * format,...)515 int git_filebuf_printf(git_filebuf *file, const char *format, ...)
516 {
517 	va_list arglist;
518 	size_t space_left, len, alloclen;
519 	int written, res;
520 	char *tmp_buffer;
521 
522 	ENSURE_BUF_OK(file);
523 
524 	space_left = file->buf_size - file->buf_pos;
525 
526 	do {
527 		va_start(arglist, format);
528 		written = p_vsnprintf((char *)file->buffer + file->buf_pos, space_left, format, arglist);
529 		va_end(arglist);
530 
531 		if (written < 0) {
532 			file->last_error = BUFERR_MEM;
533 			return -1;
534 		}
535 
536 		len = written;
537 		if (len + 1 <= space_left) {
538 			file->buf_pos += len;
539 			return 0;
540 		}
541 
542 		if (flush_buffer(file) < 0)
543 			return -1;
544 
545 		space_left = file->buf_size - file->buf_pos;
546 
547 	} while (len + 1 <= space_left);
548 
549 	if (GIT_ADD_SIZET_OVERFLOW(&alloclen, len, 1) ||
550 		!(tmp_buffer = git__malloc(alloclen))) {
551 		file->last_error = BUFERR_MEM;
552 		return -1;
553 	}
554 
555 	va_start(arglist, format);
556 	written = p_vsnprintf(tmp_buffer, len + 1, format, arglist);
557 	va_end(arglist);
558 
559 	if (written < 0) {
560 		git__free(tmp_buffer);
561 		file->last_error = BUFERR_MEM;
562 		return -1;
563 	}
564 
565 	res = git_filebuf_write(file, tmp_buffer, len);
566 	git__free(tmp_buffer);
567 
568 	return res;
569 }
570 
git_filebuf_stats(time_t * mtime,size_t * size,git_filebuf * file)571 int git_filebuf_stats(time_t *mtime, size_t *size, git_filebuf *file)
572 {
573 	int res;
574 	struct stat st;
575 
576 	if (file->fd_is_open)
577 		res = p_fstat(file->fd, &st);
578 	else
579 		res = p_stat(file->path_original, &st);
580 
581 	if (res < 0) {
582 		git_error_set(GIT_ERROR_OS, "could not get stat info for '%s'",
583 			file->path_original);
584 		return res;
585 	}
586 
587 	if (mtime)
588 		*mtime = st.st_mtime;
589 	if (size)
590 		*size = (size_t)st.st_size;
591 
592 	return 0;
593 }
594