Make get_xattr_names() even safer at fetching the list of attr names.
[rsync/rsync.git] / rsync.c
... / ...
CommitLineData
1/*
2 * Routines common to more than one of the rsync processes.
3 *
4 * Copyright (C) 1996 Andrew Tridgell
5 * Copyright (C) 1996 Paul Mackerras
6 * Copyright (C) 2003-2007 Wayne Davison
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License along
19 * with this program; if not, visit the http://fsf.org website.
20 */
21
22#include "rsync.h"
23#include "ifuncs.h"
24#if defined HAVE_LIBCHARSET_H && defined HAVE_LOCALE_CHARSET
25#include <libcharset.h>
26#elif defined HAVE_LANGINFO_H && defined HAVE_NL_LANGINFO
27#include <langinfo.h>
28#endif
29
30extern int verbose;
31extern int dry_run;
32extern int preserve_acls;
33extern int preserve_xattrs;
34extern int preserve_perms;
35extern int preserve_executability;
36extern int preserve_times;
37extern int am_root;
38extern int am_server;
39extern int am_sender;
40extern int am_generator;
41extern int am_starting_up;
42extern int allow_8bit_chars;
43extern int protocol_version;
44extern int uid_ndx;
45extern int gid_ndx;
46extern int inc_recurse;
47extern int inplace;
48extern int flist_eof;
49extern int keep_dirlinks;
50extern int make_backups;
51extern struct file_list *cur_flist, *first_flist, *dir_flist;
52extern struct chmod_mode_struct *daemon_chmod_modes;
53#ifdef ICONV_OPTION
54extern char *iconv_opt;
55#endif
56
57#ifdef ICONV_CONST
58iconv_t ic_chck = (iconv_t)-1;
59# ifdef ICONV_OPTION
60iconv_t ic_send = (iconv_t)-1, ic_recv = (iconv_t)-1;
61# endif
62
63static const char *default_charset(void)
64{
65# if defined HAVE_LIBCHARSET_H && defined HAVE_LOCALE_CHARSET
66 return locale_charset();
67# elif defined HAVE_LANGINFO_H && defined HAVE_NL_LANGINFO
68 return nl_langinfo(CODESET);
69# else
70 return ""; /* Works with (at the very least) gnu iconv... */
71# endif
72}
73
74void setup_iconv(void)
75{
76 const char *defset = default_charset();
77# ifdef ICONV_OPTION
78 const char *charset;
79 char *cp;
80# endif
81
82 if (!am_server && !allow_8bit_chars) {
83
84 /* It's OK if this fails... */
85 ic_chck = iconv_open(defset, defset);
86
87 if (verbose > 3) {
88 if (ic_chck == (iconv_t)-1) {
89 rprintf(FINFO,
90 "note: iconv_open(\"%s\", \"%s\") failed (%d)"
91 " -- using isprint() instead of iconv().\n",
92 defset, defset, errno);
93 } else {
94 rprintf(FINFO,
95 "note: iconv_open(\"%s\", \"%s\") succeeded.\n",
96 defset, defset);
97 }
98 }
99 }
100
101# ifdef ICONV_OPTION
102 if (!iconv_opt)
103 return;
104
105 if ((cp = strchr(iconv_opt, ',')) != NULL) {
106 if (am_server) /* A local transfer needs this. */
107 iconv_opt = cp + 1;
108 else
109 *cp = '\0';
110 }
111
112 if (!*iconv_opt || (*iconv_opt == '.' && iconv_opt[1] == '\0'))
113 charset = defset;
114 else
115 charset = iconv_opt;
116
117 if ((ic_send = iconv_open(UTF8_CHARSET, charset)) == (iconv_t)-1) {
118 rprintf(FERROR, "iconv_open(\"%s\", \"%s\") failed\n",
119 UTF8_CHARSET, charset);
120 exit_cleanup(RERR_UNSUPPORTED);
121 }
122
123 if ((ic_recv = iconv_open(charset, UTF8_CHARSET)) == (iconv_t)-1) {
124 rprintf(FERROR, "iconv_open(\"%s\", \"%s\") failed\n",
125 charset, UTF8_CHARSET);
126 exit_cleanup(RERR_UNSUPPORTED);
127 }
128
129 if (verbose > 1) {
130 rprintf(FINFO, "%s charset: %s\n",
131 am_server ? "server" : "client",
132 *charset ? charset : "[LOCALE]");
133 }
134# endif
135}
136
137/* This function converts the characters in the "in" xbuf into characters
138 * in the "out" xbuf. The "len" of the "in" xbuf is used starting from its
139 * "pos". The "size" of the "out" xbuf restricts how many characters can be
140 * stored, starting at its "pos+len" position. Note that the last byte of
141 * the buffer is never used, which reserves space for a terminating '\0'.
142 * We return a 0 on success or a -1 on error. An error also sets errno to
143 * E2BIG, EILSEQ, or EINVAL (see below); otherwise errno will be set to 0.
144 * The "in" xbuf is altered to update "pos" and "len". The "out" xbuf has
145 * data appended, and its "len" incremented. If ICB_EXPAND_OUT is set in
146 * "flags", the "out" xbuf will also be allocated if empty, and expanded if
147 * too small (so E2BIG will not be returned). If ICB_INCLUDE_BAD is set in
148 * "flags", any badly-encoded chars are included verbatim in the "out" xbuf,
149 * so EILSEQ will not be returned. Likewise for ICB_INCLUDE_INCOMPLETE with
150 * respect to an incomplete multi-byte char at the end, which ensures that
151 * EINVAL is not returned. Anytime "in.pos" is 0 we will reset the iconv()
152 * state prior to processing the characters. */
153int iconvbufs(iconv_t ic, xbuf *in, xbuf *out, int flags)
154{
155 ICONV_CONST char *ibuf;
156 size_t icnt, ocnt;
157 char *obuf;
158
159 if (!out->size && flags & ICB_EXPAND_OUT)
160 alloc_xbuf(out, 1024);
161
162 if (!in->pos)
163 iconv(ic, NULL, 0, NULL, 0);
164
165 ibuf = in->buf + in->pos;
166 icnt = in->len;
167
168 obuf = out->buf + (out->pos + out->len);
169 ocnt = out->size - (out->pos + out->len) - 1;
170
171 while (icnt) {
172 while (iconv(ic, &ibuf, &icnt, &obuf, &ocnt) == (size_t)-1) {
173 if (errno == EINTR)
174 continue;
175 if (errno == EINVAL) {
176 if (!(flags & ICB_INCLUDE_INCOMPLETE))
177 goto finish;
178 } else if (errno == EILSEQ) {
179 if (!(flags & ICB_INCLUDE_BAD))
180 goto finish;
181 } else {
182 size_t opos = obuf - out->buf;
183 if (!(flags & ICB_EXPAND_OUT)) {
184 errno = E2BIG;
185 goto finish;
186 }
187 realloc_xbuf(out, out->size + 1024);
188 obuf = out->buf + opos;
189 ocnt += 1024;
190 continue;
191 }
192 *obuf++ = *ibuf++;
193 ocnt--, icnt--;
194 }
195 }
196
197 errno = 0;
198
199 finish:
200 in->len = icnt;
201 in->pos = ibuf - in->buf;
202 out->len = obuf - out->buf - out->pos;
203
204 return errno ? -1 : 0;
205}
206#endif
207
208int read_ndx_and_attrs(int f_in, int *iflag_ptr, uchar *type_ptr,
209 char *buf, int *len_ptr)
210{
211 int len, iflags = 0;
212 struct file_list *flist;
213 uchar fnamecmp_type = FNAMECMP_FNAME;
214 int ndx, save_verbose = verbose;
215
216 read_loop:
217 while (1) {
218 ndx = read_ndx(f_in);
219
220 if (ndx >= 0)
221 break;
222 if (ndx == NDX_DONE)
223 return ndx;
224 if (!inc_recurse || am_sender)
225 goto invalid_ndx;
226 if (ndx == NDX_FLIST_EOF) {
227 flist_eof = 1;
228 send_msg(MSG_FLIST_EOF, "", 0, 0);
229 continue;
230 }
231 ndx = NDX_FLIST_OFFSET - ndx;
232 if (ndx < 0 || ndx >= dir_flist->used) {
233 ndx = NDX_FLIST_OFFSET - ndx;
234 rprintf(FERROR,
235 "[%s] Invalid dir index: %d (%d - %d)\n",
236 who_am_i(), ndx, NDX_FLIST_OFFSET,
237 NDX_FLIST_OFFSET - dir_flist->used + 1);
238 exit_cleanup(RERR_PROTOCOL);
239 }
240
241 /* Send everything read from f_in to msg_fd_out. */
242 if (verbose > 3) {
243 rprintf(FINFO, "[%s] receiving flist for dir %d\n",
244 who_am_i(), ndx);
245 }
246 verbose = 0;
247 send_msg_int(MSG_FLIST, ndx);
248 start_flist_forward(f_in);
249 flist = recv_file_list(f_in);
250 flist->parent_ndx = ndx;
251 stop_flist_forward();
252 verbose = save_verbose;
253 }
254
255 iflags = protocol_version >= 29 ? read_shortint(f_in)
256 : ITEM_TRANSFER | ITEM_MISSING_DATA;
257
258 /* Honor the old-style keep-alive indicator. */
259 if (protocol_version < 30
260 && ndx == cur_flist->used && iflags == ITEM_IS_NEW) {
261 if (am_sender)
262 maybe_send_keepalive();
263 goto read_loop;
264 }
265
266 if (!(flist = flist_for_ndx(ndx))) {
267 int start, used;
268 invalid_ndx:
269 start = first_flist ? first_flist->ndx_start : 0;
270 used = first_flist ? first_flist->used : 0;
271 rprintf(FERROR,
272 "Invalid file index: %d (%d - %d) with iflags %x [%s]\n",
273 ndx, start - 1, start + used -1, iflags, who_am_i());
274 exit_cleanup(RERR_PROTOCOL);
275 }
276 cur_flist = flist;
277
278 if (iflags & ITEM_BASIS_TYPE_FOLLOWS)
279 fnamecmp_type = read_byte(f_in);
280 *type_ptr = fnamecmp_type;
281
282 if (iflags & ITEM_XNAME_FOLLOWS) {
283 if ((len = read_vstring(f_in, buf, MAXPATHLEN)) < 0)
284 exit_cleanup(RERR_PROTOCOL);
285 } else {
286 *buf = '\0';
287 len = -1;
288 }
289 *len_ptr = len;
290
291 if (iflags & ITEM_TRANSFER) {
292 int i = ndx - cur_flist->ndx_start;
293 if (i < 0 || !S_ISREG(cur_flist->files[i]->mode)) {
294 rprintf(FERROR,
295 "received request to transfer non-regular file: %d [%s]\n",
296 ndx, who_am_i());
297 exit_cleanup(RERR_PROTOCOL);
298 }
299 }
300
301 *iflag_ptr = iflags;
302 return ndx;
303}
304
305/*
306 free a sums struct
307 */
308void free_sums(struct sum_struct *s)
309{
310 if (s->sums) free(s->sums);
311 free(s);
312}
313
314/* This is only called when we aren't preserving permissions. Figure out what
315 * the permissions should be and return them merged back into the mode. */
316mode_t dest_mode(mode_t flist_mode, mode_t stat_mode, int dflt_perms,
317 int exists)
318{
319 int new_mode;
320 /* If the file already exists, we'll return the local permissions,
321 * possibly tweaked by the --executability option. */
322 if (exists) {
323 new_mode = (flist_mode & ~CHMOD_BITS) | (stat_mode & CHMOD_BITS);
324 if (preserve_executability && S_ISREG(flist_mode)) {
325 /* If the source file is executable, grant execute
326 * rights to everyone who can read, but ONLY if the
327 * file isn't already executable. */
328 if (!(flist_mode & 0111))
329 new_mode &= ~0111;
330 else if (!(stat_mode & 0111))
331 new_mode |= (new_mode & 0444) >> 2;
332 }
333 } else {
334 /* Apply destination default permissions and turn
335 * off special permissions. */
336 new_mode = flist_mode & (~CHMOD_BITS | dflt_perms);
337 }
338 return new_mode;
339}
340
341int set_file_attrs(const char *fname, struct file_struct *file, stat_x *sxp,
342 const char *fnamecmp, int flags)
343{
344 int updated = 0;
345 stat_x sx2;
346 int change_uid, change_gid;
347 mode_t new_mode = file->mode;
348 int inherit;
349
350 if (!sxp) {
351 if (dry_run)
352 return 1;
353 if (link_stat(fname, &sx2.st, 0) < 0) {
354 rsyserr(FERROR_XFER, errno, "stat %s failed",
355 full_fname(fname));
356 return 0;
357 }
358#ifdef SUPPORT_ACLS
359 sx2.acc_acl = sx2.def_acl = NULL;
360#endif
361#ifdef SUPPORT_XATTRS
362 sx2.xattr = NULL;
363#endif
364 sxp = &sx2;
365 inherit = !preserve_perms;
366 } else
367 inherit = !preserve_perms && file->flags & FLAG_DIR_CREATED;
368
369 if (inherit && S_ISDIR(new_mode) && sxp->st.st_mode & S_ISGID) {
370 /* We just created this directory and its setgid
371 * bit is on, so make sure it stays on. */
372 new_mode |= S_ISGID;
373 }
374
375 if (daemon_chmod_modes && !S_ISLNK(new_mode))
376 new_mode = tweak_mode(new_mode, daemon_chmod_modes);
377
378#ifdef SUPPORT_ACLS
379 if (preserve_acls && !S_ISLNK(file->mode) && !ACL_READY(*sxp))
380 get_acl(fname, sxp);
381#endif
382
383#ifdef SUPPORT_XATTRS
384 if (am_root < 0)
385 set_stat_xattr(fname, file, new_mode);
386 if (preserve_xattrs && fnamecmp)
387 set_xattr(fname, file, fnamecmp, sxp);
388#endif
389
390 if (!preserve_times || (S_ISDIR(sxp->st.st_mode) && preserve_times == 1))
391 flags |= ATTRS_SKIP_MTIME;
392 if (!(flags & ATTRS_SKIP_MTIME)
393 && cmp_time(sxp->st.st_mtime, file->modtime) != 0) {
394 int ret = set_modtime(fname, file->modtime, sxp->st.st_mode);
395 if (ret < 0) {
396 rsyserr(FERROR_XFER, errno, "failed to set times on %s",
397 full_fname(fname));
398 goto cleanup;
399 }
400 if (ret == 0) /* ret == 1 if symlink could not be set */
401 updated = 1;
402 }
403
404 change_uid = am_root && uid_ndx && sxp->st.st_uid != (uid_t)F_OWNER(file);
405 change_gid = gid_ndx && !(file->flags & FLAG_SKIP_GROUP)
406 && sxp->st.st_gid != (gid_t)F_GROUP(file);
407#if !defined HAVE_LCHOWN && !defined CHOWN_MODIFIES_SYMLINK
408 if (S_ISLNK(sxp->st.st_mode)) {
409 ;
410 } else
411#endif
412 if (change_uid || change_gid) {
413 if (verbose > 2) {
414 if (change_uid) {
415 rprintf(FINFO,
416 "set uid of %s from %u to %u\n",
417 fname, (unsigned)sxp->st.st_uid, F_OWNER(file));
418 }
419 if (change_gid) {
420 rprintf(FINFO,
421 "set gid of %s from %u to %u\n",
422 fname, (unsigned)sxp->st.st_gid, F_GROUP(file));
423 }
424 }
425 if (am_root < 0) {
426 ;
427 } else if (do_lchown(fname,
428 change_uid ? (uid_t)F_OWNER(file) : sxp->st.st_uid,
429 change_gid ? (gid_t)F_GROUP(file) : sxp->st.st_gid) != 0) {
430 /* shouldn't have attempted to change uid or gid
431 * unless have the privilege */
432 rsyserr(FERROR_XFER, errno, "%s %s failed",
433 change_uid ? "chown" : "chgrp",
434 full_fname(fname));
435 goto cleanup;
436 } else
437 /* a lchown had been done - we have to re-stat if the
438 * destination had the setuid or setgid bits set due
439 * to the side effect of the chown call */
440 if (sxp->st.st_mode & (S_ISUID | S_ISGID)) {
441 link_stat(fname, &sxp->st,
442 keep_dirlinks && S_ISDIR(sxp->st.st_mode));
443 }
444 updated = 1;
445 }
446
447#ifdef SUPPORT_ACLS
448 /* It's OK to call set_acl() now, even for a dir, as the generator
449 * will enable owner-writability using chmod, if necessary.
450 *
451 * If set_acl() changes permission bits in the process of setting
452 * an access ACL, it changes sxp->st.st_mode so we know whether we
453 * need to chmod(). */
454 if (preserve_acls && !S_ISLNK(new_mode) && set_acl(fname, file, sxp) == 0)
455 updated = 1;
456#endif
457
458#ifdef HAVE_CHMOD
459 if (!BITS_EQUAL(sxp->st.st_mode, new_mode, CHMOD_BITS)) {
460 int ret = am_root < 0 ? 0 : do_chmod(fname, new_mode);
461 if (ret < 0) {
462 rsyserr(FERROR_XFER, errno,
463 "failed to set permissions on %s",
464 full_fname(fname));
465 goto cleanup;
466 }
467 if (ret == 0) /* ret == 1 if symlink could not be set */
468 updated = 1;
469 }
470#endif
471
472 if (verbose > 1 && flags & ATTRS_REPORT) {
473 if (updated)
474 rprintf(FCLIENT, "%s\n", fname);
475 else
476 rprintf(FCLIENT, "%s is uptodate\n", fname);
477 }
478 cleanup:
479 if (sxp == &sx2) {
480#ifdef SUPPORT_ACLS
481 if (preserve_acls)
482 free_acl(&sx2);
483#endif
484#ifdef SUPPORT_XATTRS
485 if (preserve_xattrs)
486 free_xattr(&sx2);
487#endif
488 }
489 return updated;
490}
491
492RETSIGTYPE sig_int(UNUSED(int val))
493{
494 /* KLUGE: if the user hits Ctrl-C while ssh is prompting
495 * for a password, then our cleanup's sending of a SIGUSR1
496 * signal to all our children may kill ssh before it has a
497 * chance to restore the tty settings (i.e. turn echo back
498 * on). By sleeping for a short time, ssh gets a bigger
499 * chance to do the right thing. If child processes are
500 * not ssh waiting for a password, then this tiny delay
501 * shouldn't hurt anything. */
502 msleep(400);
503 exit_cleanup(RERR_SIGNAL);
504}
505
506/* Finish off a file transfer: renaming the file and setting the file's
507 * attributes (e.g. permissions, ownership, etc.). If the robust_rename()
508 * call is forced to copy the temp file and partialptr is both non-NULL and
509 * not an absolute path, we stage the file into the partial-dir and then
510 * rename it into place. This returns 1 on succcess or 0 on failure. */
511int finish_transfer(const char *fname, const char *fnametmp,
512 const char *fnamecmp, const char *partialptr,
513 struct file_struct *file, int ok_to_set_time,
514 int overwriting_basis)
515{
516 int ret;
517 const char *temp_copy_name = partialptr && *partialptr != '/' ? partialptr : NULL;
518
519 if (inplace) {
520 if (verbose > 2)
521 rprintf(FINFO, "finishing %s\n", fname);
522 fnametmp = fname;
523 goto do_set_file_attrs;
524 }
525
526 if (make_backups > 0 && overwriting_basis && !make_backup(fname))
527 return 1;
528
529 /* Change permissions before putting the file into place. */
530 set_file_attrs(fnametmp, file, NULL, fnamecmp,
531 ok_to_set_time ? 0 : ATTRS_SKIP_MTIME);
532
533 /* move tmp file over real file */
534 if (verbose > 2)
535 rprintf(FINFO, "renaming %s to %s\n", fnametmp, fname);
536 ret = robust_rename(fnametmp, fname, temp_copy_name,
537 file->mode & INITACCESSPERMS);
538 if (ret < 0) {
539 rsyserr(FERROR_XFER, errno, "%s %s -> \"%s\"",
540 ret == -2 ? "copy" : "rename",
541 full_fname(fnametmp), fname);
542 if (!partialptr || (ret == -2 && temp_copy_name)
543 || robust_rename(fnametmp, partialptr, NULL,
544 file->mode & INITACCESSPERMS) < 0)
545 do_unlink(fnametmp);
546 return 0;
547 }
548 if (ret == 0) {
549 /* The file was moved into place (not copied), so it's done. */
550 return 1;
551 }
552 /* The file was copied, so tweak the perms of the copied file. If it
553 * was copied to partialptr, move it into its final destination. */
554 fnametmp = temp_copy_name ? temp_copy_name : fname;
555
556 do_set_file_attrs:
557 set_file_attrs(fnametmp, file, NULL, fnamecmp,
558 ok_to_set_time ? 0 : ATTRS_SKIP_MTIME);
559
560 if (temp_copy_name) {
561 if (do_rename(fnametmp, fname) < 0) {
562 rsyserr(FERROR_XFER, errno, "rename %s -> \"%s\"",
563 full_fname(fnametmp), fname);
564 return 0;
565 }
566 handle_partial_dir(temp_copy_name, PDIR_DELETE);
567 }
568 return 1;
569}
570
571struct file_list *flist_for_ndx(int ndx)
572{
573 struct file_list *flist = cur_flist;
574
575 if (!flist && !(flist = first_flist))
576 return NULL;
577
578 while (ndx < flist->ndx_start-1) {
579 if (flist == first_flist)
580 return NULL;
581 flist = flist->prev;
582 }
583 while (ndx >= flist->ndx_start + flist->used) {
584 if (!(flist = flist->next))
585 return NULL;
586 }
587 return flist;
588}
589
590const char *who_am_i(void)
591{
592 if (am_starting_up)
593 return am_server ? "server" : "client";
594 return am_sender ? "sender" : am_generator ? "generator" : "receiver";
595}