Merge branch 'jc/push-cert' into maint
[git] / send-pack.c
1 #include "builtin.h"
2 #include "commit.h"
3 #include "refs.h"
4 #include "pkt-line.h"
5 #include "sideband.h"
6 #include "run-command.h"
7 #include "remote.h"
8 #include "connect.h"
9 #include "send-pack.h"
10 #include "quote.h"
11 #include "transport.h"
12 #include "version.h"
13 #include "sha1-array.h"
14 #include "gpg-interface.h"
15
16 static int feed_object(const unsigned char *sha1, int fd, int negative)
17 {
18         char buf[42];
19
20         if (negative && !has_sha1_file(sha1))
21                 return 1;
22
23         memcpy(buf + negative, sha1_to_hex(sha1), 40);
24         if (negative)
25                 buf[0] = '^';
26         buf[40 + negative] = '\n';
27         return write_or_whine(fd, buf, 41 + negative, "send-pack: send refs");
28 }
29
30 /*
31  * Make a pack stream and spit it out into file descriptor fd
32  */
33 static int pack_objects(int fd, struct ref *refs, struct sha1_array *extra, struct send_pack_args *args)
34 {
35         /*
36          * The child becomes pack-objects --revs; we feed
37          * the revision parameters to it via its stdin and
38          * let its stdout go back to the other end.
39          */
40         const char *argv[] = {
41                 "pack-objects",
42                 "--all-progress-implied",
43                 "--revs",
44                 "--stdout",
45                 NULL,
46                 NULL,
47                 NULL,
48                 NULL,
49                 NULL,
50                 NULL,
51         };
52         struct child_process po = CHILD_PROCESS_INIT;
53         int i;
54
55         i = 4;
56         if (args->use_thin_pack)
57                 argv[i++] = "--thin";
58         if (args->use_ofs_delta)
59                 argv[i++] = "--delta-base-offset";
60         if (args->quiet || !args->progress)
61                 argv[i++] = "-q";
62         if (args->progress)
63                 argv[i++] = "--progress";
64         if (is_repository_shallow())
65                 argv[i++] = "--shallow";
66         po.argv = argv;
67         po.in = -1;
68         po.out = args->stateless_rpc ? -1 : fd;
69         po.git_cmd = 1;
70         if (start_command(&po))
71                 die_errno("git pack-objects failed");
72
73         /*
74          * We feed the pack-objects we just spawned with revision
75          * parameters by writing to the pipe.
76          */
77         for (i = 0; i < extra->nr; i++)
78                 if (!feed_object(extra->sha1[i], po.in, 1))
79                         break;
80
81         while (refs) {
82                 if (!is_null_sha1(refs->old_sha1) &&
83                     !feed_object(refs->old_sha1, po.in, 1))
84                         break;
85                 if (!is_null_sha1(refs->new_sha1) &&
86                     !feed_object(refs->new_sha1, po.in, 0))
87                         break;
88                 refs = refs->next;
89         }
90
91         close(po.in);
92
93         if (args->stateless_rpc) {
94                 char *buf = xmalloc(LARGE_PACKET_MAX);
95                 while (1) {
96                         ssize_t n = xread(po.out, buf, LARGE_PACKET_MAX);
97                         if (n <= 0)
98                                 break;
99                         send_sideband(fd, -1, buf, n, LARGE_PACKET_MAX);
100                 }
101                 free(buf);
102                 close(po.out);
103                 po.out = -1;
104         }
105
106         if (finish_command(&po))
107                 return -1;
108         return 0;
109 }
110
111 static int receive_status(int in, struct ref *refs)
112 {
113         struct ref *hint;
114         int ret = 0;
115         char *line = packet_read_line(in, NULL);
116         if (!starts_with(line, "unpack "))
117                 return error("did not receive remote status");
118         if (strcmp(line, "unpack ok")) {
119                 error("unpack failed: %s", line + 7);
120                 ret = -1;
121         }
122         hint = NULL;
123         while (1) {
124                 char *refname;
125                 char *msg;
126                 line = packet_read_line(in, NULL);
127                 if (!line)
128                         break;
129                 if (!starts_with(line, "ok ") && !starts_with(line, "ng ")) {
130                         error("invalid ref status from remote: %s", line);
131                         ret = -1;
132                         break;
133                 }
134
135                 refname = line + 3;
136                 msg = strchr(refname, ' ');
137                 if (msg)
138                         *msg++ = '\0';
139
140                 /* first try searching at our hint, falling back to all refs */
141                 if (hint)
142                         hint = find_ref_by_name(hint, refname);
143                 if (!hint)
144                         hint = find_ref_by_name(refs, refname);
145                 if (!hint) {
146                         warning("remote reported status on unknown ref: %s",
147                                         refname);
148                         continue;
149                 }
150                 if (hint->status != REF_STATUS_EXPECTING_REPORT) {
151                         warning("remote reported status on unexpected ref: %s",
152                                         refname);
153                         continue;
154                 }
155
156                 if (line[0] == 'o' && line[1] == 'k')
157                         hint->status = REF_STATUS_OK;
158                 else {
159                         hint->status = REF_STATUS_REMOTE_REJECT;
160                         ret = -1;
161                 }
162                 if (msg)
163                         hint->remote_status = xstrdup(msg);
164                 /* start our next search from the next ref */
165                 hint = hint->next;
166         }
167         return ret;
168 }
169
170 static int sideband_demux(int in, int out, void *data)
171 {
172         int *fd = data, ret;
173 #ifdef NO_PTHREADS
174         close(fd[1]);
175 #endif
176         ret = recv_sideband("send-pack", fd[0], out);
177         close(out);
178         return ret;
179 }
180
181 static int advertise_shallow_grafts_cb(const struct commit_graft *graft, void *cb)
182 {
183         struct strbuf *sb = cb;
184         if (graft->nr_parent == -1)
185                 packet_buf_write(sb, "shallow %s\n", sha1_to_hex(graft->sha1));
186         return 0;
187 }
188
189 static void advertise_shallow_grafts_buf(struct strbuf *sb)
190 {
191         if (!is_repository_shallow())
192                 return;
193         for_each_commit_graft(advertise_shallow_grafts_cb, sb);
194 }
195
196 static int ref_update_to_be_sent(const struct ref *ref, const struct send_pack_args *args)
197 {
198         if (!ref->peer_ref && !args->send_mirror)
199                 return 0;
200
201         /* Check for statuses set by set_ref_status_for_push() */
202         switch (ref->status) {
203         case REF_STATUS_REJECT_NONFASTFORWARD:
204         case REF_STATUS_REJECT_ALREADY_EXISTS:
205         case REF_STATUS_REJECT_FETCH_FIRST:
206         case REF_STATUS_REJECT_NEEDS_FORCE:
207         case REF_STATUS_REJECT_STALE:
208         case REF_STATUS_REJECT_NODELETE:
209         case REF_STATUS_UPTODATE:
210                 return 0;
211         default:
212                 return 1;
213         }
214 }
215
216 /*
217  * the beginning of the next line, or the end of buffer.
218  *
219  * NEEDSWORK: perhaps move this to git-compat-util.h or somewhere and
220  * convert many similar uses found by "git grep -A4 memchr".
221  */
222 static const char *next_line(const char *line, size_t len)
223 {
224         const char *nl = memchr(line, '\n', len);
225         if (!nl)
226                 return line + len; /* incomplete line */
227         return nl + 1;
228 }
229
230 static int generate_push_cert(struct strbuf *req_buf,
231                               const struct ref *remote_refs,
232                               struct send_pack_args *args,
233                               const char *cap_string,
234                               const char *push_cert_nonce)
235 {
236         const struct ref *ref;
237         char *signing_key = xstrdup(get_signing_key());
238         const char *cp, *np;
239         struct strbuf cert = STRBUF_INIT;
240         int update_seen = 0;
241
242         strbuf_addf(&cert, "certificate version 0.1\n");
243         strbuf_addf(&cert, "pusher %s ", signing_key);
244         datestamp(&cert);
245         strbuf_addch(&cert, '\n');
246         if (args->url && *args->url) {
247                 char *anon_url = transport_anonymize_url(args->url);
248                 strbuf_addf(&cert, "pushee %s\n", anon_url);
249                 free(anon_url);
250         }
251         if (push_cert_nonce[0])
252                 strbuf_addf(&cert, "nonce %s\n", push_cert_nonce);
253         strbuf_addstr(&cert, "\n");
254
255         for (ref = remote_refs; ref; ref = ref->next) {
256                 if (!ref_update_to_be_sent(ref, args))
257                         continue;
258                 update_seen = 1;
259                 strbuf_addf(&cert, "%s %s %s\n",
260                             sha1_to_hex(ref->old_sha1),
261                             sha1_to_hex(ref->new_sha1),
262                             ref->name);
263         }
264         if (!update_seen)
265                 goto free_return;
266
267         if (sign_buffer(&cert, &cert, signing_key))
268                 die(_("failed to sign the push certificate"));
269
270         packet_buf_write(req_buf, "push-cert%c%s", 0, cap_string);
271         for (cp = cert.buf; cp < cert.buf + cert.len; cp = np) {
272                 np = next_line(cp, cert.buf + cert.len - cp);
273                 packet_buf_write(req_buf,
274                                  "%.*s", (int)(np - cp), cp);
275         }
276         packet_buf_write(req_buf, "push-cert-end\n");
277
278 free_return:
279         free(signing_key);
280         strbuf_release(&cert);
281         return update_seen;
282 }
283
284 #define NONCE_LEN_LIMIT 256
285
286 static void reject_invalid_nonce(const char *nonce, int len)
287 {
288         int i = 0;
289
290         if (NONCE_LEN_LIMIT <= len)
291                 die("the receiving end asked to sign an invalid nonce <%.*s>",
292                     len, nonce);
293
294         for (i = 0; i < len; i++) {
295                 int ch = nonce[i] & 0xFF;
296                 if (isalnum(ch) ||
297                     ch == '-' || ch == '.' ||
298                     ch == '/' || ch == '+' ||
299                     ch == '=' || ch == '_')
300                         continue;
301                 die("the receiving end asked to sign an invalid nonce <%.*s>",
302                     len, nonce);
303         }
304 }
305
306 int send_pack(struct send_pack_args *args,
307               int fd[], struct child_process *conn,
308               struct ref *remote_refs,
309               struct sha1_array *extra_have)
310 {
311         int in = fd[0];
312         int out = fd[1];
313         struct strbuf req_buf = STRBUF_INIT;
314         struct strbuf cap_buf = STRBUF_INIT;
315         struct ref *ref;
316         int need_pack_data = 0;
317         int allow_deleting_refs = 0;
318         int status_report = 0;
319         int use_sideband = 0;
320         int quiet_supported = 0;
321         int agent_supported = 0;
322         unsigned cmds_sent = 0;
323         int ret;
324         struct async demux;
325         const char *push_cert_nonce = NULL;
326
327         /* Does the other end support the reporting? */
328         if (server_supports("report-status"))
329                 status_report = 1;
330         if (server_supports("delete-refs"))
331                 allow_deleting_refs = 1;
332         if (server_supports("ofs-delta"))
333                 args->use_ofs_delta = 1;
334         if (server_supports("side-band-64k"))
335                 use_sideband = 1;
336         if (server_supports("quiet"))
337                 quiet_supported = 1;
338         if (server_supports("agent"))
339                 agent_supported = 1;
340         if (server_supports("no-thin"))
341                 args->use_thin_pack = 0;
342         if (args->push_cert) {
343                 int len;
344
345                 push_cert_nonce = server_feature_value("push-cert", &len);
346                 if (!push_cert_nonce)
347                         die(_("the receiving end does not support --signed push"));
348                 reject_invalid_nonce(push_cert_nonce, len);
349                 push_cert_nonce = xmemdupz(push_cert_nonce, len);
350         }
351
352         if (!remote_refs) {
353                 fprintf(stderr, "No refs in common and none specified; doing nothing.\n"
354                         "Perhaps you should specify a branch such as 'master'.\n");
355                 return 0;
356         }
357
358         if (status_report)
359                 strbuf_addstr(&cap_buf, " report-status");
360         if (use_sideband)
361                 strbuf_addstr(&cap_buf, " side-band-64k");
362         if (quiet_supported && (args->quiet || !args->progress))
363                 strbuf_addstr(&cap_buf, " quiet");
364         if (agent_supported)
365                 strbuf_addf(&cap_buf, " agent=%s", git_user_agent_sanitized());
366
367         /*
368          * NEEDSWORK: why does delete-refs have to be so specific to
369          * send-pack machinery that set_ref_status_for_push() cannot
370          * set this bit for us???
371          */
372         for (ref = remote_refs; ref; ref = ref->next)
373                 if (ref->deletion && !allow_deleting_refs)
374                         ref->status = REF_STATUS_REJECT_NODELETE;
375
376         if (!args->dry_run)
377                 advertise_shallow_grafts_buf(&req_buf);
378
379         if (!args->dry_run && args->push_cert)
380                 cmds_sent = generate_push_cert(&req_buf, remote_refs, args,
381                                                cap_buf.buf, push_cert_nonce);
382
383         /*
384          * Clear the status for each ref and see if we need to send
385          * the pack data.
386          */
387         for (ref = remote_refs; ref; ref = ref->next) {
388                 if (!ref_update_to_be_sent(ref, args))
389                         continue;
390
391                 if (!ref->deletion)
392                         need_pack_data = 1;
393
394                 if (args->dry_run || !status_report)
395                         ref->status = REF_STATUS_OK;
396                 else
397                         ref->status = REF_STATUS_EXPECTING_REPORT;
398         }
399
400         /*
401          * Finally, tell the other end!
402          */
403         for (ref = remote_refs; ref; ref = ref->next) {
404                 char *old_hex, *new_hex;
405
406                 if (args->dry_run || args->push_cert)
407                         continue;
408
409                 if (!ref_update_to_be_sent(ref, args))
410                         continue;
411
412                 old_hex = sha1_to_hex(ref->old_sha1);
413                 new_hex = sha1_to_hex(ref->new_sha1);
414                 if (!cmds_sent) {
415                         packet_buf_write(&req_buf,
416                                          "%s %s %s%c%s",
417                                          old_hex, new_hex, ref->name, 0,
418                                          cap_buf.buf);
419                         cmds_sent = 1;
420                 } else {
421                         packet_buf_write(&req_buf, "%s %s %s",
422                                          old_hex, new_hex, ref->name);
423                 }
424         }
425
426         if (args->stateless_rpc) {
427                 if (!args->dry_run && (cmds_sent || is_repository_shallow())) {
428                         packet_buf_flush(&req_buf);
429                         send_sideband(out, -1, req_buf.buf, req_buf.len, LARGE_PACKET_MAX);
430                 }
431         } else {
432                 write_or_die(out, req_buf.buf, req_buf.len);
433                 packet_flush(out);
434         }
435         strbuf_release(&req_buf);
436         strbuf_release(&cap_buf);
437
438         if (use_sideband && cmds_sent) {
439                 memset(&demux, 0, sizeof(demux));
440                 demux.proc = sideband_demux;
441                 demux.data = fd;
442                 demux.out = -1;
443                 if (start_async(&demux))
444                         die("send-pack: unable to fork off sideband demultiplexer");
445                 in = demux.out;
446         }
447
448         if (need_pack_data && cmds_sent) {
449                 if (pack_objects(out, remote_refs, extra_have, args) < 0) {
450                         for (ref = remote_refs; ref; ref = ref->next)
451                                 ref->status = REF_STATUS_NONE;
452                         if (args->stateless_rpc)
453                                 close(out);
454                         if (git_connection_is_socket(conn))
455                                 shutdown(fd[0], SHUT_WR);
456                         if (use_sideband)
457                                 finish_async(&demux);
458                         fd[1] = -1;
459                         return -1;
460                 }
461                 if (!args->stateless_rpc)
462                         /* Closed by pack_objects() via start_command() */
463                         fd[1] = -1;
464         }
465         if (args->stateless_rpc && cmds_sent)
466                 packet_flush(out);
467
468         if (status_report && cmds_sent)
469                 ret = receive_status(in, remote_refs);
470         else
471                 ret = 0;
472         if (args->stateless_rpc)
473                 packet_flush(out);
474
475         if (use_sideband && cmds_sent) {
476                 if (finish_async(&demux)) {
477                         error("error in sideband demultiplexer");
478                         ret = -1;
479                 }
480                 close(demux.out);
481         }
482
483         if (ret < 0)
484                 return ret;
485
486         if (args->porcelain)
487                 return 0;
488
489         for (ref = remote_refs; ref; ref = ref->next) {
490                 switch (ref->status) {
491                 case REF_STATUS_NONE:
492                 case REF_STATUS_UPTODATE:
493                 case REF_STATUS_OK:
494                         break;
495                 default:
496                         return -1;
497                 }
498         }
499         return 0;
500 }