Fix zlib CVE-2016-9840.
[rsync.git] / token.c
diff --git a/token.c b/token.c
index 7510b99f70162285beff29c645304fe7aa7a5a2a..0a5ed73503d75f63d50dc978210da66434e621f3 100644 (file)
--- a/token.c
+++ b/token.c
@@ -3,7 +3,7 @@
  *
  * Copyright (C) 1996 Andrew Tridgell
  * Copyright (C) 1996 Paul Mackerras
- * Copyright (C) 2003-2007 Wayne Davison
+ * Copyright (C) 2003-2019 Wayne Davison
  *
  * This program is free software; you can redistribute it and/or modify
  * it under the terms of the GNU General Public License as published by
  */
 
 #include "rsync.h"
-#include "zlib/zlib.h"
+#include "itypes.h"
+#include <zlib.h>
 
 extern int do_compression;
+extern int protocol_version;
 extern int module_id;
 extern int def_compress_level;
+extern char *skip_compress;
 
 static int compression_level, per_file_default_level;
 
-/* determine the compression level based on a wildcard filename list */
-void set_compression(char *fname)
+struct suffix_tree {
+       struct suffix_tree *sibling;
+       struct suffix_tree *child;
+       char letter, word_end;
+};
+
+static char *match_list;
+static struct suffix_tree *suftree;
+
+static void add_suffix(struct suffix_tree **prior, char ltr, const char *str)
 {
-       static char *match_list;
-       char *s;
+       struct suffix_tree *node, *newnode;
+
+       if (ltr == '[') {
+               const char *after = strchr(str, ']');
+               /* Treat "[foo" and "[]" as having a literal '['. */
+               if (after && after++ != str+1) {
+                       while ((ltr = *str++) != ']')
+                               add_suffix(prior, ltr, after);
+                       return;
+               }
+       }
 
-       if (!do_compression)
-               return;
+       for (node = *prior; node; prior = &node->sibling, node = node->sibling) {
+               if (node->letter == ltr) {
+                       if (*str)
+                               add_suffix(&node->child, *str, str+1);
+                       else
+                               node->word_end = 1;
+                       return;
+               }
+               if (node->letter > ltr)
+                       break;
+       }
+       if (!(newnode = new(struct suffix_tree)))
+               out_of_memory("add_suffix");
+       newnode->sibling = node;
+       newnode->child = NULL;
+       newnode->letter = ltr;
+       *prior = newnode;
+       if (*str) {
+               add_suffix(&newnode->child, *str, str+1);
+               newnode->word_end = 0;
+       } else
+               newnode->word_end = 1;
+}
 
-       if (!match_list) {
-               char *t, *f = lp_dont_compress(module_id);
-               int len = strlen(f);
-               if (!(match_list = t = new_array(char, len + 2)))
-                       out_of_memory("set_compression");
-               while (*f) {
-                       if (*f == ' ') {
-                               f++;
-                               continue;
-                       }
-                       do {
-                               if (isUpper(f))
-                                       *t++ = toLower(f);
-                               else
-                                       *t++ = *f;
-                       } while (*++f != ' ' && *f);
-                       *t++ = '\0';
+static void add_nocompress_suffixes(const char *str)
+{
+       char *buf, *t;
+       const char *f = str;
+
+       if (!(buf = new_array(char, strlen(f) + 1)))
+               out_of_memory("add_nocompress_suffixes");
+
+       while (*f) {
+               if (*f == '/') {
+                       f++;
+                       continue;
                }
-               /* Optimize a match-string of "*". */
-               if (t - match_list == 2 && match_list[0] == '*') {
-                       t = match_list;
-                       per_file_default_level = 0;
-               } else
-                       per_file_default_level = def_compress_level;
+
+               t = buf;
+               do {
+                       if (isUpper(f))
+                               *t++ = toLower(f);
+                       else
+                               *t++ = *f;
+               } while (*++f != '/' && *f);
+               *t++ = '\0';
+
+               add_suffix(&suftree, *buf, buf+1);
+       }
+
+       free(buf);
+}
+
+static void init_set_compression(void)
+{
+       const char *f;
+       char *t, *start;
+
+       if (skip_compress)
+               add_nocompress_suffixes(skip_compress);
+
+       /* A non-daemon transfer skips the default suffix list if the
+        * user specified --skip-compress. */
+       if (skip_compress && module_id < 0)
+               f = "";
+       else
+               f = lp_dont_compress(module_id);
+
+       if (!(match_list = t = new_array(char, strlen(f) + 2)))
+               out_of_memory("set_compression");
+
+       per_file_default_level = def_compress_level;
+
+       while (*f) {
+               if (*f == ' ') {
+                       f++;
+                       continue;
+               }
+
+               start = t;
+               do {
+                       if (isUpper(f))
+                               *t++ = toLower(f);
+                       else
+                               *t++ = *f;
+               } while (*++f != ' ' && *f);
                *t++ = '\0';
+
+               if (t - start == 1+1 && *start == '*') {
+                       /* Optimize a match-string of "*". */
+                       *match_list = '\0';
+                       suftree = NULL;
+                       per_file_default_level = 0;
+                       break;
+               }
+
+               /* Move *.foo items into the stuffix tree. */
+               if (*start == '*' && start[1] == '.' && start[2]
+                && !strpbrk(start+2, ".?*")) {
+                       add_suffix(&suftree, start[2], start+3);
+                       t = start;
+               }
        }
+       *t++ = '\0';
+}
+
+/* determine the compression level based on a wildcard filename list */
+void set_compression(const char *fname)
+{
+       const struct suffix_tree *node;
+       const char *s;
+       char ltr;
+
+       if (!do_compression)
+               return;
+
+       if (!match_list)
+               init_set_compression();
 
        compression_level = per_file_default_level;
 
-       if (!*match_list)
+       if (!*match_list && !suftree)
                return;
 
        if ((s = strrchr(fname, '/')) != NULL)
@@ -75,9 +184,31 @@ void set_compression(char *fname)
        for (s = match_list; *s; s += strlen(s) + 1) {
                if (iwildmatch(s, fname)) {
                        compression_level = 0;
-                       break;
+                       return;
                }
        }
+
+       if (!(node = suftree) || !(s = strrchr(fname, '.'))
+        || s == fname || !(ltr = *++s))
+               return;
+
+       while (1) {
+               if (isUpper(&ltr))
+                       ltr = toLower(&ltr);
+               while (node->letter != ltr) {
+                       if (node->letter > ltr)
+                               return;
+                       if (!(node = node->sibling))
+                               return;
+               }
+               if ((ltr = *++s) == '\0') {
+                       if (node->word_end)
+                               compression_level = 0;
+                       return;
+               }
+               if (!(node = node->child))
+                       return;
+       }
 }
 
 /* non-compressing recv token */
@@ -178,7 +309,7 @@ send_deflated_token(int f, int32 token, struct map_struct *buf, OFF_T offset,
                                         Z_DEFLATED, -15, 8,
                                         Z_DEFAULT_STRATEGY) != Z_OK) {
                                rprintf(FERROR, "compression init failed\n");
-                               exit_cleanup(RERR_STREAMIO);
+                               exit_cleanup(RERR_PROTOCOL);
                        }
                        if ((obuf = new_array(char, OBUF_SIZE)) == NULL)
                                out_of_memory("send_deflated_token");
@@ -271,9 +402,10 @@ send_deflated_token(int f, int32 token, struct map_struct *buf, OFF_T offset,
        if (token == -1) {
                /* end of file - clean up */
                write_byte(f, END_FLAG);
-       } else if (token != -2) {
+       } else if (token != -2 && do_compression == 1) {
                /* Add the data in the current block to the compressor's
                 * history and hash table. */
+#ifndef EXTERNAL_ZLIB
                do {
                        /* Break up long sections in the same way that
                         * see_deflate_token() does. */
@@ -281,6 +413,8 @@ send_deflated_token(int f, int32 token, struct map_struct *buf, OFF_T offset,
                        toklen -= n1;
                        tx_strm.next_in = (Bytef *)map_ptr(buf, offset, n1);
                        tx_strm.avail_in = n1;
+                       if (protocol_version >= 31) /* Newer protocols avoid a data-duplicating bug */
+                               offset += n1;
                        tx_strm.next_out = (Bytef *) obuf;
                        tx_strm.avail_out = AVAIL_OUT_SIZE(CHUNK_SIZE);
                        r = deflate(&tx_strm, Z_INSERT_ONLY);
@@ -290,6 +424,11 @@ send_deflated_token(int f, int32 token, struct map_struct *buf, OFF_T offset,
                                exit_cleanup(RERR_STREAMIO);
                        }
                } while (toklen > 0);
+#else
+               toklen++;
+               rprintf(FERROR, "Impossible error in external-zlib code (1).\n");
+               exit_cleanup(RERR_STREAMIO);
+#endif
        }
 }
 
@@ -322,7 +461,7 @@ static int32 recv_deflated_token(int f, char **data)
                                rx_strm.zfree = NULL;
                                if (inflateInit2(&rx_strm, -15) != Z_OK) {
                                        rprintf(FERROR, "inflate init failed\n");
-                                       exit_cleanup(RERR_STREAMIO);
+                                       exit_cleanup(RERR_PROTOCOL);
                                }
                                if (!(cbuf = new_array(char, MAX_DATA_COUNT))
                                    || !(dbuf = new_array(char, AVAIL_OUT_SIZE(CHUNK_SIZE))))
@@ -440,6 +579,7 @@ static int32 recv_deflated_token(int f, char **data)
  */
 static void see_deflate_token(char *buf, int32 len)
 {
+#ifndef EXTERNAL_ZLIB
        int r;
        int32 blklen;
        unsigned char hdr[5];
@@ -463,6 +603,8 @@ static void see_deflate_token(char *buf, int32 len)
                        } else {
                                rx_strm.next_in = (Bytef *)buf;
                                rx_strm.avail_in = blklen;
+                               if (protocol_version >= 31) /* Newer protocols avoid a data-duplicating bug */
+                                       buf += blklen;
                                len -= blklen;
                                blklen = 0;
                        }
@@ -470,11 +612,16 @@ static void see_deflate_token(char *buf, int32 len)
                rx_strm.next_out = (Bytef *)dbuf;
                rx_strm.avail_out = AVAIL_OUT_SIZE(CHUNK_SIZE);
                r = inflate(&rx_strm, Z_SYNC_FLUSH);
-               if (r != Z_OK) {
+               if (r != Z_OK && r != Z_BUF_ERROR) {
                        rprintf(FERROR, "inflate (token) returned %d\n", r);
                        exit_cleanup(RERR_STREAMIO);
                }
        } while (len || rx_strm.avail_out == 0);
+#else
+       buf++; len++;
+       rprintf(FERROR, "Impossible error in external-zlib code (2).\n");
+       exit_cleanup(RERR_STREAMIO);
+#endif
 }
 
 /**
@@ -514,6 +661,6 @@ int32 recv_token(int f, char **data)
  */
 void see_token(char *data, int32 toklen)
 {
-       if (do_compression)
+       if (do_compression == 1)
                see_deflate_token(data, toklen);
 }