Signedness security patch from Sebastian Krahmer <krahmer@suse.de> --
[rsync.git] / receiver.c
1 /* 
2    Copyright (C) Andrew Tridgell 1996
3    Copyright (C) Paul Mackerras 1996
4    
5    This program is free software; you can redistribute it and/or modify
6    it under the terms of the GNU General Public License as published by
7    the Free Software Foundation; either version 2 of the License, or
8    (at your option) any later version.
9    
10    This program is distributed in the hope that it will be useful,
11    but WITHOUT ANY WARRANTY; without even the implied warranty of
12    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
13    GNU General Public License for more details.
14    
15    You should have received a copy of the GNU General Public License
16    along with this program; if not, write to the Free Software
17    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
18 */
19
20 #include "rsync.h"
21
22 extern int verbose;
23 extern int recurse;
24 extern int delete_mode;
25 extern int remote_version;
26 extern int csum_length;
27 extern struct stats stats;
28 extern int dry_run;
29 extern int am_server;
30 extern int relative_paths;
31 extern int preserve_hard_links;
32 extern int cvs_exclude;
33 extern int io_error;
34 extern char *tmpdir;
35 extern char *compare_dest;
36 extern int make_backups;
37 extern char *backup_suffix;
38
39 static struct delete_list {
40         dev_t dev;
41         INO_T inode;
42 } *delete_list;
43 static int dlist_len, dlist_alloc_len;
44
45 /* yuck! This function wouldn't have been necessary if I had the sorting
46    algorithm right. Unfortunately fixing the sorting algorithm would introduce
47    a backward incompatibility as file list indexes are sent over the link.
48 */
49 static int delete_already_done(struct file_list *flist,int j)
50 {
51         int i;
52         STRUCT_STAT st;
53
54         if (link_stat(f_name(flist->files[j]), &st)) return 1;
55
56         for (i=0;i<dlist_len;i++) {
57                 if (st.st_ino == delete_list[i].inode &&
58                     st.st_dev == delete_list[i].dev)
59                         return 1;
60         }
61
62         return 0;
63 }
64
65 static void add_delete_entry(struct file_struct *file)
66 {
67         if (dlist_len == dlist_alloc_len) {
68                 dlist_alloc_len += 1024;
69                 delete_list = (struct delete_list *)Realloc(delete_list, sizeof(delete_list[0])*dlist_alloc_len);
70                 if (!delete_list) out_of_memory("add_delete_entry");
71         }
72
73         delete_list[dlist_len].dev = file->dev;
74         delete_list[dlist_len].inode = file->inode;
75         dlist_len++;
76
77         if (verbose > 3)
78                 rprintf(FINFO,"added %s to delete list\n", f_name(file));
79 }
80
81 static void delete_one(struct file_struct *f)
82 {
83         if (!S_ISDIR(f->mode)) {
84                 if (robust_unlink(f_name(f)) != 0) {
85                         rprintf(FERROR,"unlink %s : %s\n",f_name(f),strerror(errno));
86                 } else if (verbose) {
87                         rprintf(FINFO,"deleting %s\n",f_name(f));
88                 }
89         } else {    
90                 if (do_rmdir(f_name(f)) != 0) {
91                         if (errno != ENOTEMPTY && errno != EEXIST)
92                                 rprintf(FERROR,"rmdir %s : %s\n",f_name(f),strerror(errno));
93                 } else if (verbose) {
94                         rprintf(FINFO,"deleting directory %s\n",f_name(f));      
95                 }
96         }
97 }
98
99
100
101
102 /* this deletes any files on the receiving side that are not present
103    on the sending side. For version 1.6.4 I have changed the behaviour
104    to match more closely what most people seem to expect of this option */
105 void delete_files(struct file_list *flist)
106 {
107         struct file_list *local_file_list;
108         int i, j;
109         char *name;
110         extern int module_id;
111         extern int ignore_errors;
112         extern int max_delete;
113         static int deletion_count;
114
115         if (cvs_exclude)
116                 add_cvs_excludes();
117
118         if (io_error && !(lp_ignore_errors(module_id) || ignore_errors)) {
119                 rprintf(FINFO,"IO error encountered - skipping file deletion\n");
120                 return;
121         }
122
123         for (j=0;j<flist->count;j++) {
124                 if (!S_ISDIR(flist->files[j]->mode) || 
125                     !(flist->files[j]->flags & FLAG_DELETE)) continue;
126
127                 if (remote_version < 19 &&
128                     delete_already_done(flist, j)) continue;
129
130                 name = strdup(f_name(flist->files[j]));
131
132                 if (!(local_file_list = send_file_list(-1,1,&name))) {
133                         free(name);
134                         continue;
135                 }
136
137                 if (verbose > 1)
138                         rprintf(FINFO,"deleting in %s\n", name);
139
140                 for (i=local_file_list->count-1;i>=0;i--) {
141                         if (max_delete && deletion_count > max_delete) break;
142                         if (!local_file_list->files[i]->basename) continue;
143                         if (remote_version < 19 &&
144                             S_ISDIR(local_file_list->files[i]->mode))
145                                 add_delete_entry(local_file_list->files[i]);
146                         if (-1 == flist_find(flist,local_file_list->files[i])) {
147                                 char *f = f_name(local_file_list->files[i]);
148                                 int k = strlen(f) - strlen(backup_suffix);
149 /* Hi Andrew, do we really need to play with backup_suffix here? */
150                                 if (make_backups && ((k <= 0) ||
151                                             (strcmp(f+k,backup_suffix) != 0))) {
152                                         (void) make_backup(f);
153                                 } else {
154                                         deletion_count++;
155                                         delete_one(local_file_list->files[i]);
156                                 }
157                         }
158                 }
159                 flist_free(local_file_list);
160                 free(name);
161         }
162 }
163
164
165 static int get_tmpname(char *fnametmp, char *fname)
166 {
167         char *f;
168
169         /* open tmp file */
170         if (tmpdir) {
171                 f = strrchr(fname,'/');
172                 if (f == NULL) 
173                         f = fname;
174                 else 
175                         f++;
176                 if (strlen(tmpdir)+strlen(f)+10 > MAXPATHLEN) {
177                         rprintf(FERROR,"filename too long\n");
178                         return 0;
179                 }
180                 slprintf(fnametmp,MAXPATHLEN, "%s/.%s.XXXXXX",tmpdir,f);
181                 return 1;
182         } 
183
184         f = strrchr(fname,'/');
185
186         if (strlen(fname)+9 > MAXPATHLEN) {
187                 rprintf(FERROR,"filename too long\n");
188                 return 0;
189         }
190
191         if (f) {
192                 *f = 0;
193                 slprintf(fnametmp,MAXPATHLEN,"%s/.%s.XXXXXX",
194                          fname,f+1);
195                 *f = '/';
196         } else {
197                 slprintf(fnametmp,MAXPATHLEN,".%s.XXXXXX",fname);
198         }
199
200         return 1;
201 }
202
203
204 static int receive_data(int f_in,struct map_struct *buf,int fd,char *fname,
205                         OFF_T total_size)
206 {
207         int i;
208         unsigned int n,remainder,len,count;
209         OFF_T offset = 0;
210         OFF_T offset2;
211         char *data;
212         static char file_sum1[MD4_SUM_LENGTH];
213         static char file_sum2[MD4_SUM_LENGTH];
214         char *map=NULL;
215         
216         count = read_int(f_in);
217         n = read_int(f_in);
218         remainder = read_int(f_in);
219         
220         sum_init();
221         
222         for (i=recv_token(f_in,&data); i != 0; i=recv_token(f_in,&data)) {
223
224                 show_progress(offset, total_size);
225
226                 if (i > 0) {
227                         extern int cleanup_got_literal;
228
229                         if (verbose > 3) {
230                                 rprintf(FINFO,"data recv %d at %.0f\n",
231                                         i,(double)offset);
232                         }
233
234                         stats.literal_data += i;
235                         cleanup_got_literal = 1;
236       
237                         sum_update(data,i);
238
239                         if (fd != -1 && write_file(fd,data,i) != i) {
240                                 rprintf(FERROR,"write failed on %s : %s\n",fname,strerror(errno));
241                                 exit_cleanup(RERR_FILEIO);
242                         }
243                         offset += i;
244                         continue;
245                 } 
246
247                 i = -(i+1);
248                 offset2 = i*(OFF_T)n;
249                 len = n;
250                 if (i == count-1 && remainder != 0)
251                         len = remainder;
252                 
253                 stats.matched_data += len;
254                 
255                 if (verbose > 3)
256                         rprintf(FINFO,"chunk[%d] of size %d at %.0f offset=%.0f\n",
257                                 i,len,(double)offset2,(double)offset);
258                 
259                 if (buf) {
260                         map = map_ptr(buf,offset2,len);
261                 
262                         see_token(map, len);
263                         sum_update(map,len);
264                 }
265                 
266                 if (fd != -1 && write_file(fd,map,len) != len) {
267                         rprintf(FERROR,"write failed on %s : %s\n",
268                                 fname,strerror(errno));
269                         exit_cleanup(RERR_FILEIO);
270                 }
271                 offset += len;
272         }
273
274         end_progress(total_size);
275
276         if (fd != -1 && offset > 0 && sparse_end(fd) != 0) {
277                 rprintf(FERROR,"write failed on %s : %s\n",
278                         fname,strerror(errno));
279                 exit_cleanup(RERR_FILEIO);
280         }
281
282         sum_end(file_sum1);
283
284         if (remote_version >= 14) {
285                 read_buf(f_in,file_sum2,MD4_SUM_LENGTH);
286                 if (verbose > 2) {
287                         rprintf(FINFO,"got file_sum\n");
288                 }
289                 if (fd != -1 && 
290                     memcmp(file_sum1,file_sum2,MD4_SUM_LENGTH) != 0) {
291                         return 0;
292                 }
293         }
294         return 1;
295 }
296
297
298 /* main routine for receiver process. Receiver process runs on the
299         same host as the generator process. */
300
301 int recv_files(int f_in,struct file_list *flist,char *local_name,int f_gen)
302 {  
303         int fd1,fd2;
304         STRUCT_STAT st;
305         char *fname;
306         char fnametmp[MAXPATHLEN];
307         char *fnamecmp;
308         char fnamecmpbuf[MAXPATHLEN];
309         struct map_struct *buf;
310         int i;
311         struct file_struct *file;
312         int phase=0;
313         int recv_ok;
314         extern struct stats stats;              
315         extern int preserve_perms;
316         extern int delete_after;
317         struct stats initial_stats;
318
319         if (verbose > 2) {
320                 rprintf(FINFO,"recv_files(%d) starting\n",flist->count);
321         }
322
323         while (1) {      
324                 cleanup_disable();
325
326                 i = read_int(f_in);
327                 if (i == -1) {
328                         if (phase==0 && remote_version >= 13) {
329                                 phase++;
330                                 csum_length = SUM_LENGTH;
331                                 if (verbose > 2)
332                                         rprintf(FINFO,"recv_files phase=%d\n",phase);
333                                 write_int(f_gen,-1);
334                                 continue;
335                         }
336                         break;
337                 }
338
339                 if (i < 0 || i >= flist->count) {
340                         rprintf(FERROR,"Invalid file index %d in recv_files (count=%d)\n", 
341                                 i, flist->count);
342                         exit_cleanup(RERR_PROTOCOL);
343                 }
344
345                 file = flist->files[i];
346                 fname = f_name(file);
347
348                 stats.num_transferred_files++;
349                 stats.total_transferred_size += file->length;
350
351                 if (local_name)
352                         fname = local_name;
353
354                 if (dry_run) {
355                         if (!am_server) {
356                                 log_transfer(file, fname);
357                         }
358                         continue;
359                 }
360
361                 initial_stats = stats;
362
363                 if (verbose > 2)
364                         rprintf(FINFO,"recv_files(%s)\n",fname);
365
366                 fnamecmp = fname;
367
368                 /* open the file */  
369                 fd1 = do_open(fnamecmp, O_RDONLY, 0);
370
371                 if ((fd1 == -1) && (compare_dest != NULL)) {
372                         /* try the file at compare_dest instead */
373                         slprintf(fnamecmpbuf,MAXPATHLEN,"%s/%s",
374                                                 compare_dest,fname);
375                         fnamecmp = fnamecmpbuf;
376                         fd1 = do_open(fnamecmp, O_RDONLY, 0);
377                 }
378
379                 if (fd1 != -1 && do_fstat(fd1,&st) != 0) {
380                         rprintf(FERROR,"fstat %s : %s\n",fnamecmp,strerror(errno));
381                         receive_data(f_in,NULL,-1,NULL,file->length);
382                         close(fd1);
383                         continue;
384                 }
385
386                 if (fd1 != -1 && !S_ISREG(st.st_mode)) {
387                         rprintf(FERROR,"%s : not a regular file (recv_files)\n",fnamecmp);
388                         receive_data(f_in,NULL,-1,NULL,file->length);
389                         close(fd1);
390                         continue;
391                 }
392
393                 if (fd1 != -1 && !preserve_perms) {
394                         /* if the file exists already and we aren't perserving
395                            presmissions then act as though the remote end sent
396                            us the file permissions we already have */
397                         file->mode = st.st_mode;
398                 }
399
400                 if (fd1 != -1 && st.st_size > 0) {
401                         buf = map_file(fd1,st.st_size);
402                         if (verbose > 2)
403                                 rprintf(FINFO,"recv mapped %s of size %.0f\n",fnamecmp,(double)st.st_size);
404                 } else {
405                         buf = NULL;
406                 }
407
408                 if (!get_tmpname(fnametmp,fname)) {
409                         if (buf) unmap_file(buf);
410                         if (fd1 != -1) close(fd1);
411                         continue;
412                 }
413
414                 /* mktemp is deliberately used here instead of mkstemp.
415                    because O_EXCL is used on the open, the race condition
416                    is not a problem or a security hole, and we want to
417                    control the access permissions on the created file. */
418                 if (NULL == do_mktemp(fnametmp)) {
419                         rprintf(FERROR,"mktemp %s failed\n",fnametmp);
420                         receive_data(f_in,buf,-1,NULL,file->length);
421                         if (buf) unmap_file(buf);
422                         if (fd1 != -1) close(fd1);
423                         continue;
424                 }
425
426                 /* we initially set the perms without the
427                    setuid/setgid bits to ensure that there is no race
428                    condition. They are then correctly updated after
429                    the lchown. Thanks to snabb@epipe.fi for pointing
430                    this out.  We also set it initially without group
431                    access because of a similar race condition. */
432                 fd2 = do_open(fnametmp,O_WRONLY|O_CREAT|O_EXCL,
433                               file->mode & INITACCESSPERMS);
434
435                 /* in most cases parent directories will already exist
436                    because their information should have been previously
437                    transferred, but that may not be the case with -R */
438                 if (fd2 == -1 && relative_paths && errno == ENOENT && 
439                     create_directory_path(fnametmp) == 0) {
440                         fd2 = do_open(fnametmp,O_WRONLY|O_CREAT|O_EXCL,
441                                       file->mode & INITACCESSPERMS);
442                 }
443                 if (fd2 == -1) {
444                         rprintf(FERROR,"cannot create %s : %s\n",fnametmp,strerror(errno));
445                         receive_data(f_in,buf,-1,NULL,file->length);
446                         if (buf) unmap_file(buf);
447                         if (fd1 != -1) close(fd1);
448                         continue;
449                 }
450       
451                 cleanup_set(fnametmp, fname, file, buf, fd1, fd2);
452
453                 if (!am_server) {
454                         log_transfer(file, fname);
455                 }
456
457                 /* recv file data */
458                 recv_ok = receive_data(f_in,buf,fd2,fname,file->length);
459
460                 log_recv(file, &initial_stats);
461                 
462                 if (buf) unmap_file(buf);
463                 if (fd1 != -1) {
464                         close(fd1);
465                 }
466                 close(fd2);
467                 
468                 if (verbose > 2)
469                         rprintf(FINFO,"renaming %s to %s\n",fnametmp,fname);
470
471                 finish_transfer(fname, fnametmp, file);
472
473                 cleanup_disable();
474
475                 if (!recv_ok) {
476                         if (csum_length == SUM_LENGTH) {
477                                 rprintf(FERROR,"ERROR: file corruption in %s. File changed during transfer?\n",
478                                         fname);
479                         } else {
480                                 if (verbose > 1)
481                                         rprintf(FINFO,"redoing %s(%d)\n",fname,i);
482                                 write_int(f_gen,i);
483                         }
484                 }
485         }
486
487         if (delete_after) {
488                 if (recurse && delete_mode && !local_name && flist->count>0) {
489                         delete_files(flist);
490                 }
491         }
492
493         if (preserve_hard_links)
494                 do_hard_links(flist);
495
496         /* now we need to fix any directory permissions that were 
497            modified during the transfer */
498         for (i = 0; i < flist->count; i++) {
499                 file = flist->files[i];
500                 if (!file->basename || !S_ISDIR(file->mode)) continue;
501                 recv_generator(local_name?local_name:f_name(file),flist,i,-1);
502         }
503
504         if (verbose > 2)
505                 rprintf(FINFO,"recv_files finished\n");
506         
507         return 0;
508 }
509