]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/import/pull-job.c
import: rework how verification works
[thirdparty/systemd.git] / src / import / pull-job.c
CommitLineData
db9ecf05 1/* SPDX-License-Identifier: LGPL-2.1-or-later */
56ebfaf1 2
ca78ad1d
ZJS
3#include <fcntl.h>
4#include <sys/stat.h>
56ebfaf1
LP
5#include <sys/xattr.h>
6
b5efdb8a 7#include "alloc-util.h"
3ffd4af2 8#include "fd-util.h"
aa892669 9#include "format-util.h"
eef836ed 10#include "gcrypt-util.h"
89a5a90c 11#include "hexdecoct.h"
1f0f4f3b 12#include "import-util.h"
c004493c 13#include "io-util.h"
26166c88 14#include "machine-pool.h"
6bedfcbb 15#include "parse-util.h"
1f0f4f3b 16#include "pull-common.h"
3ffd4af2 17#include "pull-job.h"
07630cea
LP
18#include "string-util.h"
19#include "strv.h"
89a5a90c 20#include "xattr-util.h"
56ebfaf1 21
dc2c282b 22PullJob* pull_job_unref(PullJob *j) {
56ebfaf1
LP
23 if (!j)
24 return NULL;
25
26 curl_glue_remove_and_free(j->glue, j->curl);
27 curl_slist_free_all(j->request_header);
28
29 safe_close(j->disk_fd);
30
3e2cda69 31 import_compress_free(&j->compress);
56ebfaf1 32
98c38001
LP
33 if (j->checksum_context)
34 gcry_md_close(j->checksum_context);
85dbc41d 35
56ebfaf1
LP
36 free(j->url);
37 free(j->etag);
38 strv_free(j->old_etags);
39 free(j->payload);
98c38001 40 free(j->checksum);
56ebfaf1 41
6b430fdb 42 return mfree(j);
56ebfaf1
LP
43}
44
dc2c282b 45static void pull_job_finish(PullJob *j, int ret) {
56ebfaf1
LP
46 assert(j);
47
3742095b 48 if (IN_SET(j->state, PULL_JOB_DONE, PULL_JOB_FAILED))
56ebfaf1
LP
49 return;
50
68c913fd 51 if (ret == 0) {
dc2c282b 52 j->state = PULL_JOB_DONE;
7079cfef 53 j->progress_percent = 100;
68c913fd
LP
54 log_info("Download of %s complete.", j->url);
55 } else {
dc2c282b 56 j->state = PULL_JOB_FAILED;
56ebfaf1
LP
57 j->error = ret;
58 }
59
60 if (j->on_finished)
61 j->on_finished(j);
62}
63
f14717a7 64static int pull_job_restart(PullJob *j, const char *new_url) {
697be0be 65 int r;
697be0be 66
f14717a7
LP
67 assert(j);
68 assert(new_url);
69
70 r = free_and_strdup(&j->url, new_url);
697be0be
TB
71 if (r < 0)
72 return r;
73
697be0be 74 j->state = PULL_JOB_INIT;
1f0f4f3b 75 j->payload = mfree(j->payload);
697be0be
TB
76 j->payload_size = 0;
77 j->payload_allocated = 0;
78 j->written_compressed = 0;
79 j->written_uncompressed = 0;
697be0be
TB
80
81 r = pull_job_begin(j);
82 if (r < 0)
83 return r;
84
85 return 0;
86}
87
dc2c282b
LP
88void pull_job_curl_on_finished(CurlGlue *g, CURL *curl, CURLcode result) {
89 PullJob *j = NULL;
56ebfaf1
LP
90 CURLcode code;
91 long status;
92 int r;
93
a7f7d1bd 94 if (curl_easy_getinfo(curl, CURLINFO_PRIVATE, (char **)&j) != CURLE_OK)
56ebfaf1
LP
95 return;
96
4c701096 97 if (!j || IN_SET(j->state, PULL_JOB_DONE, PULL_JOB_FAILED))
56ebfaf1
LP
98 return;
99
100 if (result != CURLE_OK) {
101 log_error("Transfer failed: %s", curl_easy_strerror(result));
102 r = -EIO;
103 goto finish;
104 }
105
106 code = curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &status);
107 if (code != CURLE_OK) {
108 log_error("Failed to retrieve response code: %s", curl_easy_strerror(code));
109 r = -EIO;
110 goto finish;
111 } else if (status == 304) {
112 log_info("Image already downloaded. Skipping download.");
85dbc41d 113 j->etag_exists = true;
56ebfaf1
LP
114 r = 0;
115 goto finish;
116 } else if (status >= 300) {
697be0be 117
f14717a7
LP
118 if (status == 404 && j->on_not_found) {
119 _cleanup_free_ char *new_url = NULL;
120
121 /* This resource wasn't found, but the implementor wants to maybe let us know a new URL, query for it. */
122 r = j->on_not_found(j, &new_url);
697be0be
TB
123 if (r < 0)
124 goto finish;
125
f14717a7
LP
126 if (r > 0) { /* A new url to use */
127 assert(new_url);
128
129 r = pull_job_restart(j, new_url);
130 if (r < 0)
131 goto finish;
132
133 code = curl_easy_getinfo(j->curl, CURLINFO_RESPONSE_CODE, &status);
134 if (code != CURLE_OK) {
135 log_error("Failed to retrieve response code: %s", curl_easy_strerror(code));
136 r = -EIO;
137 goto finish;
138 }
697be0be 139
f14717a7
LP
140 if (status == 0)
141 return;
697be0be
TB
142 }
143 }
144
56ebfaf1
LP
145 log_error("HTTP request to %s failed with code %li.", j->url, status);
146 r = -EIO;
147 goto finish;
148 } else if (status < 200) {
149 log_error("HTTP request to %s finished with unexpected code %li.", j->url, status);
150 r = -EIO;
151 goto finish;
152 }
153
dc2c282b 154 if (j->state != PULL_JOB_RUNNING) {
56ebfaf1
LP
155 log_error("Premature connection termination.");
156 r = -EIO;
157 goto finish;
158 }
159
160 if (j->content_length != (uint64_t) -1 &&
161 j->content_length != j->written_compressed) {
162 log_error("Download truncated.");
163 r = -EIO;
164 goto finish;
165 }
166
98c38001 167 if (j->checksum_context) {
85dbc41d
LP
168 uint8_t *k;
169
98c38001 170 k = gcry_md_read(j->checksum_context, GCRY_MD_SHA256);
85dbc41d
LP
171 if (!k) {
172 log_error("Failed to get checksum.");
173 r = -EIO;
174 goto finish;
175 }
176
98c38001
LP
177 j->checksum = hexmem(k, gcry_md_get_algo_dlen(GCRY_MD_SHA256));
178 if (!j->checksum) {
85dbc41d
LP
179 r = log_oom();
180 goto finish;
181 }
182
98c38001 183 log_debug("SHA256 of %s is %s.", j->url, j->checksum);
85dbc41d
LP
184 }
185
56ebfaf1
LP
186 if (j->disk_fd >= 0 && j->allow_sparse) {
187 /* Make sure the file size is right, in case the file was
188 * sparse and we just seeked for the last part */
189
190 if (ftruncate(j->disk_fd, j->written_uncompressed) < 0) {
b6e676ce 191 r = log_error_errno(errno, "Failed to truncate file: %m");
56ebfaf1
LP
192 goto finish;
193 }
194
195 if (j->etag)
196 (void) fsetxattr(j->disk_fd, "user.source_etag", j->etag, strlen(j->etag), 0);
197 if (j->url)
198 (void) fsetxattr(j->disk_fd, "user.source_url", j->url, strlen(j->url), 0);
199
200 if (j->mtime != 0) {
201 struct timespec ut[2];
202
203 timespec_store(&ut[0], j->mtime);
204 ut[1] = ut[0];
205 (void) futimens(j->disk_fd, ut);
206
207 (void) fd_setcrtime(j->disk_fd, j->mtime);
208 }
209 }
210
211 r = 0;
212
213finish:
dc2c282b 214 pull_job_finish(j, r);
56ebfaf1
LP
215}
216
3e2cda69
LP
217static int pull_job_write_uncompressed(const void *p, size_t sz, void *userdata) {
218 PullJob *j = userdata;
56ebfaf1
LP
219 ssize_t n;
220
221 assert(j);
222 assert(p);
8af3cf74
LP
223
224 if (sz <= 0)
225 return 0;
56ebfaf1 226
baaa35ad
ZJS
227 if (j->written_uncompressed + sz < j->written_uncompressed)
228 return log_error_errno(SYNTHETIC_ERRNO(EOVERFLOW),
229 "File too large, overflow");
56ebfaf1 230
baaa35ad
ZJS
231 if (j->written_uncompressed + sz > j->uncompressed_max)
232 return log_error_errno(SYNTHETIC_ERRNO(EFBIG),
233 "File overly large, refusing");
56ebfaf1
LP
234
235 if (j->disk_fd >= 0) {
236
237 if (j->allow_sparse)
238 n = sparse_write(j->disk_fd, p, sz, 64);
e986910e 239 else {
56ebfaf1 240 n = write(j->disk_fd, p, sz);
e986910e
YW
241 if (n < 0)
242 n = -errno;
243 }
b6e676ce 244 if (n < 0)
e986910e 245 return log_error_errno((int) n, "Failed to write file: %m");
baaa35ad
ZJS
246 if ((size_t) n < sz)
247 return log_error_errno(SYNTHETIC_ERRNO(EIO), "Short write");
56ebfaf1
LP
248 } else {
249
250 if (!GREEDY_REALLOC(j->payload, j->payload_allocated, j->payload_size + sz))
251 return log_oom();
252
8af3cf74 253 memcpy(j->payload + j->payload_size, p, sz);
56ebfaf1
LP
254 j->payload_size += sz;
255 }
256
257 j->written_uncompressed += sz;
258
259 return 0;
260}
261
dc2c282b 262static int pull_job_write_compressed(PullJob *j, void *p, size_t sz) {
56ebfaf1
LP
263 int r;
264
265 assert(j);
266 assert(p);
8af3cf74
LP
267
268 if (sz <= 0)
269 return 0;
56ebfaf1 270
baaa35ad
ZJS
271 if (j->written_compressed + sz < j->written_compressed)
272 return log_error_errno(SYNTHETIC_ERRNO(EOVERFLOW), "File too large, overflow");
56ebfaf1 273
baaa35ad
ZJS
274 if (j->written_compressed + sz > j->compressed_max)
275 return log_error_errno(SYNTHETIC_ERRNO(EFBIG), "File overly large, refusing.");
56ebfaf1
LP
276
277 if (j->content_length != (uint64_t) -1 &&
baaa35ad
ZJS
278 j->written_compressed + sz > j->content_length)
279 return log_error_errno(SYNTHETIC_ERRNO(EFBIG),
280 "Content length incorrect.");
56ebfaf1 281
98c38001
LP
282 if (j->checksum_context)
283 gcry_md_write(j->checksum_context, p, sz);
85dbc41d 284
3e2cda69
LP
285 r = import_uncompress(&j->compress, p, sz, pull_job_write_uncompressed, j);
286 if (r < 0)
287 return r;
56ebfaf1
LP
288
289 j->written_compressed += sz;
290
291 return 0;
292}
293
dc2c282b 294static int pull_job_open_disk(PullJob *j) {
56ebfaf1
LP
295 int r;
296
297 assert(j);
298
299 if (j->on_open_disk) {
300 r = j->on_open_disk(j);
301 if (r < 0)
302 return r;
303 }
304
305 if (j->disk_fd >= 0) {
306 /* Check if we can do sparse files */
307
308 if (lseek(j->disk_fd, SEEK_SET, 0) == 0)
309 j->allow_sparse = true;
310 else {
311 if (errno != ESPIPE)
312 return log_error_errno(errno, "Failed to seek on file descriptor: %m");
313
314 j->allow_sparse = false;
315 }
316 }
317
98c38001 318 if (j->calc_checksum) {
eef836ed
YW
319 initialize_libgcrypt(false);
320
baaa35ad
ZJS
321 if (gcry_md_open(&j->checksum_context, GCRY_MD_SHA256, 0) != 0)
322 return log_error_errno(SYNTHETIC_ERRNO(EIO),
323 "Failed to initialize hash context.");
85dbc41d
LP
324 }
325
56ebfaf1
LP
326 return 0;
327}
328
dc2c282b 329static int pull_job_detect_compression(PullJob *j) {
56ebfaf1
LP
330 _cleanup_free_ uint8_t *stub = NULL;
331 size_t stub_size;
332
333 int r;
334
335 assert(j);
336
3e2cda69
LP
337 r = import_uncompress_detect(&j->compress, j->payload, j->payload_size);
338 if (r < 0)
339 return log_error_errno(r, "Failed to initialize compressor: %m");
340 if (r == 0)
56ebfaf1
LP
341 return 0;
342
3e2cda69 343 log_debug("Stream is compressed: %s", import_compress_type_to_string(j->compress.type));
56ebfaf1 344
dc2c282b 345 r = pull_job_open_disk(j);
56ebfaf1
LP
346 if (r < 0)
347 return r;
348
349 /* Now, take the payload we read so far, and decompress it */
350 stub = j->payload;
351 stub_size = j->payload_size;
352
353 j->payload = NULL;
354 j->payload_size = 0;
88a1aadc 355 j->payload_allocated = 0;
56ebfaf1 356
dc2c282b 357 j->state = PULL_JOB_RUNNING;
56ebfaf1 358
dc2c282b 359 r = pull_job_write_compressed(j, stub, stub_size);
56ebfaf1
LP
360 if (r < 0)
361 return r;
362
363 return 0;
364}
365
dc2c282b
LP
366static size_t pull_job_write_callback(void *contents, size_t size, size_t nmemb, void *userdata) {
367 PullJob *j = userdata;
56ebfaf1
LP
368 size_t sz = size * nmemb;
369 int r;
370
371 assert(contents);
372 assert(j);
373
374 switch (j->state) {
375
dc2c282b 376 case PULL_JOB_ANALYZING:
56ebfaf1
LP
377 /* Let's first check what it actually is */
378
379 if (!GREEDY_REALLOC(j->payload, j->payload_allocated, j->payload_size + sz)) {
380 r = log_oom();
381 goto fail;
382 }
383
8af3cf74 384 memcpy(j->payload + j->payload_size, contents, sz);
56ebfaf1
LP
385 j->payload_size += sz;
386
dc2c282b 387 r = pull_job_detect_compression(j);
56ebfaf1
LP
388 if (r < 0)
389 goto fail;
390
391 break;
392
dc2c282b 393 case PULL_JOB_RUNNING:
56ebfaf1 394
dc2c282b 395 r = pull_job_write_compressed(j, contents, sz);
56ebfaf1
LP
396 if (r < 0)
397 goto fail;
398
399 break;
400
dc2c282b
LP
401 case PULL_JOB_DONE:
402 case PULL_JOB_FAILED:
56ebfaf1
LP
403 r = -ESTALE;
404 goto fail;
405
406 default:
407 assert_not_reached("Impossible state.");
408 }
409
410 return sz;
411
412fail:
dc2c282b 413 pull_job_finish(j, r);
56ebfaf1
LP
414 return 0;
415}
416
dc2c282b
LP
417static size_t pull_job_header_callback(void *contents, size_t size, size_t nmemb, void *userdata) {
418 PullJob *j = userdata;
56ebfaf1
LP
419 size_t sz = size * nmemb;
420 _cleanup_free_ char *length = NULL, *last_modified = NULL;
421 char *etag;
422 int r;
423
424 assert(contents);
425 assert(j);
426
3742095b 427 if (IN_SET(j->state, PULL_JOB_DONE, PULL_JOB_FAILED)) {
56ebfaf1
LP
428 r = -ESTALE;
429 goto fail;
430 }
431
dc2c282b 432 assert(j->state == PULL_JOB_ANALYZING);
56ebfaf1
LP
433
434 r = curl_header_strdup(contents, sz, "ETag:", &etag);
435 if (r < 0) {
436 log_oom();
437 goto fail;
438 }
439 if (r > 0) {
440 free(j->etag);
441 j->etag = etag;
442
443 if (strv_contains(j->old_etags, j->etag)) {
444 log_info("Image already downloaded. Skipping download.");
85dbc41d 445 j->etag_exists = true;
dc2c282b 446 pull_job_finish(j, 0);
56ebfaf1
LP
447 return sz;
448 }
449
450 return sz;
451 }
452
453 r = curl_header_strdup(contents, sz, "Content-Length:", &length);
454 if (r < 0) {
455 log_oom();
456 goto fail;
457 }
458 if (r > 0) {
459 (void) safe_atou64(length, &j->content_length);
460
461 if (j->content_length != (uint64_t) -1) {
462 char bytes[FORMAT_BYTES_MAX];
463
464 if (j->content_length > j->compressed_max) {
465 log_error("Content too large.");
466 r = -EFBIG;
467 goto fail;
468 }
469
68c913fd 470 log_info("Downloading %s for %s.", format_bytes(bytes, sizeof(bytes), j->content_length), j->url);
56ebfaf1
LP
471 }
472
473 return sz;
474 }
475
476 r = curl_header_strdup(contents, sz, "Last-Modified:", &last_modified);
477 if (r < 0) {
478 log_oom();
479 goto fail;
480 }
481 if (r > 0) {
482 (void) curl_parse_http_time(last_modified, &j->mtime);
483 return sz;
484 }
485
ff2670ad
LP
486 if (j->on_header) {
487 r = j->on_header(j, contents, sz);
488 if (r < 0)
489 goto fail;
490 }
491
56ebfaf1
LP
492 return sz;
493
494fail:
dc2c282b 495 pull_job_finish(j, r);
56ebfaf1
LP
496 return 0;
497}
498
dc2c282b
LP
499static int pull_job_progress_callback(void *userdata, curl_off_t dltotal, curl_off_t dlnow, curl_off_t ultotal, curl_off_t ulnow) {
500 PullJob *j = userdata;
56ebfaf1
LP
501 unsigned percent;
502 usec_t n;
503
504 assert(j);
505
506 if (dltotal <= 0)
507 return 0;
508
509 percent = ((100 * dlnow) / dltotal);
510 n = now(CLOCK_MONOTONIC);
511
512 if (n > j->last_status_usec + USEC_PER_SEC &&
68c913fd
LP
513 percent != j->progress_percent &&
514 dlnow < dltotal) {
56ebfaf1
LP
515 char buf[FORMAT_TIMESPAN_MAX];
516
517 if (n - j->start_usec > USEC_PER_SEC && dlnow > 0) {
90bc083b 518 char y[FORMAT_BYTES_MAX];
56ebfaf1
LP
519 usec_t left, done;
520
521 done = n - j->start_usec;
522 left = (usec_t) (((double) done * (double) dltotal) / dlnow) - done;
523
90bc083b
LP
524 log_info("Got %u%% of %s. %s left at %s/s.",
525 percent,
526 j->url,
527 format_timespan(buf, sizeof(buf), left, USEC_PER_SEC),
528 format_bytes(y, sizeof(y), (uint64_t) ((double) dlnow / ((double) done / (double) USEC_PER_SEC))));
56ebfaf1
LP
529 } else
530 log_info("Got %u%% of %s.", percent, j->url);
531
532 j->progress_percent = percent;
533 j->last_status_usec = n;
7079cfef
LP
534
535 if (j->on_progress)
536 j->on_progress(j);
56ebfaf1
LP
537 }
538
539 return 0;
540}
541
dc2c282b
LP
542int pull_job_new(PullJob **ret, const char *url, CurlGlue *glue, void *userdata) {
543 _cleanup_(pull_job_unrefp) PullJob *j = NULL;
0d94088e 544 _cleanup_free_ char *u = NULL;
56ebfaf1
LP
545
546 assert(url);
547 assert(glue);
548 assert(ret);
549
0d94088e 550 u = strdup(url);
9b5b4bed 551 if (!u)
56ebfaf1
LP
552 return -ENOMEM;
553
0d94088e
YW
554 j = new(PullJob, 1);
555 if (!j)
56ebfaf1
LP
556 return -ENOMEM;
557
0d94088e
YW
558 *j = (PullJob) {
559 .state = PULL_JOB_INIT,
560 .disk_fd = -1,
561 .userdata = userdata,
562 .glue = glue,
563 .content_length = (uint64_t) -1,
564 .start_usec = now(CLOCK_MONOTONIC),
565 .compressed_max = 64LLU * 1024LLU * 1024LLU * 1024LLU, /* 64GB safety limit */
566 .uncompressed_max = 64LLU * 1024LLU * 1024LLU * 1024LLU, /* 64GB safety limit */
0d94088e
YW
567 .url = TAKE_PTR(u),
568 };
569
1cc6c93a 570 *ret = TAKE_PTR(j);
56ebfaf1
LP
571
572 return 0;
573}
574
dc2c282b 575int pull_job_begin(PullJob *j) {
56ebfaf1
LP
576 int r;
577
578 assert(j);
579
dc2c282b 580 if (j->state != PULL_JOB_INIT)
56ebfaf1
LP
581 return -EBUSY;
582
583 r = curl_glue_make(&j->curl, j->url, j);
584 if (r < 0)
585 return r;
586
587 if (!strv_isempty(j->old_etags)) {
588 _cleanup_free_ char *cc = NULL, *hdr = NULL;
589
590 cc = strv_join(j->old_etags, ", ");
591 if (!cc)
592 return -ENOMEM;
593
b910cc72 594 hdr = strjoin("If-None-Match: ", cc);
56ebfaf1
LP
595 if (!hdr)
596 return -ENOMEM;
597
ff2670ad
LP
598 if (!j->request_header) {
599 j->request_header = curl_slist_new(hdr, NULL);
600 if (!j->request_header)
601 return -ENOMEM;
602 } else {
603 struct curl_slist *l;
604
605 l = curl_slist_append(j->request_header, hdr);
606 if (!l)
607 return -ENOMEM;
608
609 j->request_header = l;
610 }
611 }
56ebfaf1 612
ff2670ad 613 if (j->request_header) {
56ebfaf1
LP
614 if (curl_easy_setopt(j->curl, CURLOPT_HTTPHEADER, j->request_header) != CURLE_OK)
615 return -EIO;
616 }
617
dc2c282b 618 if (curl_easy_setopt(j->curl, CURLOPT_WRITEFUNCTION, pull_job_write_callback) != CURLE_OK)
56ebfaf1
LP
619 return -EIO;
620
621 if (curl_easy_setopt(j->curl, CURLOPT_WRITEDATA, j) != CURLE_OK)
622 return -EIO;
623
dc2c282b 624 if (curl_easy_setopt(j->curl, CURLOPT_HEADERFUNCTION, pull_job_header_callback) != CURLE_OK)
56ebfaf1
LP
625 return -EIO;
626
627 if (curl_easy_setopt(j->curl, CURLOPT_HEADERDATA, j) != CURLE_OK)
628 return -EIO;
629
dc2c282b 630 if (curl_easy_setopt(j->curl, CURLOPT_XFERINFOFUNCTION, pull_job_progress_callback) != CURLE_OK)
56ebfaf1
LP
631 return -EIO;
632
633 if (curl_easy_setopt(j->curl, CURLOPT_XFERINFODATA, j) != CURLE_OK)
634 return -EIO;
635
636 if (curl_easy_setopt(j->curl, CURLOPT_NOPROGRESS, 0) != CURLE_OK)
637 return -EIO;
638
639 r = curl_glue_add(j->glue, j->curl);
640 if (r < 0)
641 return r;
642
dc2c282b 643 j->state = PULL_JOB_ANALYZING;
56ebfaf1
LP
644
645 return 0;
646}