sftp-client.c revision 98675
1/*
2 * Copyright (c) 2001,2002 Damien Miller.  All rights reserved.
3 *
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
6 * are met:
7 * 1. Redistributions of source code must retain the above copyright
8 *    notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 *    notice, this list of conditions and the following disclaimer in the
11 *    documentation and/or other materials provided with the distribution.
12 *
13 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
14 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
15 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
16 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
17 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
18 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
19 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
20 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
21 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
22 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
23 */
24
25/* XXX: memleaks */
26/* XXX: signed vs unsigned */
27/* XXX: remove all logging, only return status codes */
28/* XXX: copy between two remote sites */
29
30#include "includes.h"
31RCSID("$OpenBSD: sftp-client.c,v 1.32 2002/06/09 13:32:01 markus Exp $");
32
33#include <sys/queue.h>
34
35#include "buffer.h"
36#include "bufaux.h"
37#include "getput.h"
38#include "xmalloc.h"
39#include "log.h"
40#include "atomicio.h"
41
42#include "sftp.h"
43#include "sftp-common.h"
44#include "sftp-client.h"
45
46/* Minimum amount of data to read at at time */
47#define MIN_READ_SIZE	512
48
49struct sftp_conn {
50	int fd_in;
51	int fd_out;
52	u_int transfer_buflen;
53	u_int num_requests;
54	u_int version;
55	u_int msg_id;
56};
57
58static void
59send_msg(int fd, Buffer *m)
60{
61	int mlen = buffer_len(m);
62	int len;
63	Buffer oqueue;
64
65	buffer_init(&oqueue);
66	buffer_put_int(&oqueue, mlen);
67	buffer_append(&oqueue, buffer_ptr(m), mlen);
68	buffer_consume(m, mlen);
69
70	len = atomicio(write, fd, buffer_ptr(&oqueue), buffer_len(&oqueue));
71	if (len <= 0)
72		fatal("Couldn't send packet: %s", strerror(errno));
73
74	buffer_free(&oqueue);
75}
76
77static void
78get_msg(int fd, Buffer *m)
79{
80	u_int len, msg_len;
81	unsigned char buf[4096];
82
83	len = atomicio(read, fd, buf, 4);
84	if (len == 0)
85		fatal("Connection closed");
86	else if (len == -1)
87		fatal("Couldn't read packet: %s", strerror(errno));
88
89	msg_len = GET_32BIT(buf);
90	if (msg_len > 256 * 1024)
91		fatal("Received message too long %d", msg_len);
92
93	while (msg_len) {
94		len = atomicio(read, fd, buf, MIN(msg_len, sizeof(buf)));
95		if (len == 0)
96			fatal("Connection closed");
97		else if (len == -1)
98			fatal("Couldn't read packet: %s", strerror(errno));
99
100		msg_len -= len;
101		buffer_append(m, buf, len);
102	}
103}
104
105static void
106send_string_request(int fd, u_int id, u_int code, char *s,
107    u_int len)
108{
109	Buffer msg;
110
111	buffer_init(&msg);
112	buffer_put_char(&msg, code);
113	buffer_put_int(&msg, id);
114	buffer_put_string(&msg, s, len);
115	send_msg(fd, &msg);
116	debug3("Sent message fd %d T:%d I:%d", fd, code, id);
117	buffer_free(&msg);
118}
119
120static void
121send_string_attrs_request(int fd, u_int id, u_int code, char *s,
122    u_int len, Attrib *a)
123{
124	Buffer msg;
125
126	buffer_init(&msg);
127	buffer_put_char(&msg, code);
128	buffer_put_int(&msg, id);
129	buffer_put_string(&msg, s, len);
130	encode_attrib(&msg, a);
131	send_msg(fd, &msg);
132	debug3("Sent message fd %d T:%d I:%d", fd, code, id);
133	buffer_free(&msg);
134}
135
136static u_int
137get_status(int fd, int expected_id)
138{
139	Buffer msg;
140	u_int type, id, status;
141
142	buffer_init(&msg);
143	get_msg(fd, &msg);
144	type = buffer_get_char(&msg);
145	id = buffer_get_int(&msg);
146
147	if (id != expected_id)
148		fatal("ID mismatch (%d != %d)", id, expected_id);
149	if (type != SSH2_FXP_STATUS)
150		fatal("Expected SSH2_FXP_STATUS(%d) packet, got %d",
151		    SSH2_FXP_STATUS, type);
152
153	status = buffer_get_int(&msg);
154	buffer_free(&msg);
155
156	debug3("SSH2_FXP_STATUS %d", status);
157
158	return(status);
159}
160
161static char *
162get_handle(int fd, u_int expected_id, u_int *len)
163{
164	Buffer msg;
165	u_int type, id;
166	char *handle;
167
168	buffer_init(&msg);
169	get_msg(fd, &msg);
170	type = buffer_get_char(&msg);
171	id = buffer_get_int(&msg);
172
173	if (id != expected_id)
174		fatal("ID mismatch (%d != %d)", id, expected_id);
175	if (type == SSH2_FXP_STATUS) {
176		int status = buffer_get_int(&msg);
177
178		error("Couldn't get handle: %s", fx2txt(status));
179		return(NULL);
180	} else if (type != SSH2_FXP_HANDLE)
181		fatal("Expected SSH2_FXP_HANDLE(%d) packet, got %d",
182		    SSH2_FXP_HANDLE, type);
183
184	handle = buffer_get_string(&msg, len);
185	buffer_free(&msg);
186
187	return(handle);
188}
189
190static Attrib *
191get_decode_stat(int fd, u_int expected_id, int quiet)
192{
193	Buffer msg;
194	u_int type, id;
195	Attrib *a;
196
197	buffer_init(&msg);
198	get_msg(fd, &msg);
199
200	type = buffer_get_char(&msg);
201	id = buffer_get_int(&msg);
202
203	debug3("Received stat reply T:%d I:%d", type, id);
204	if (id != expected_id)
205		fatal("ID mismatch (%d != %d)", id, expected_id);
206	if (type == SSH2_FXP_STATUS) {
207		int status = buffer_get_int(&msg);
208
209		if (quiet)
210			debug("Couldn't stat remote file: %s", fx2txt(status));
211		else
212			error("Couldn't stat remote file: %s", fx2txt(status));
213		return(NULL);
214	} else if (type != SSH2_FXP_ATTRS) {
215		fatal("Expected SSH2_FXP_ATTRS(%d) packet, got %d",
216		    SSH2_FXP_ATTRS, type);
217	}
218	a = decode_attrib(&msg);
219	buffer_free(&msg);
220
221	return(a);
222}
223
224struct sftp_conn *
225do_init(int fd_in, int fd_out, u_int transfer_buflen, u_int num_requests)
226{
227	int type, version;
228	Buffer msg;
229	struct sftp_conn *ret;
230
231	buffer_init(&msg);
232	buffer_put_char(&msg, SSH2_FXP_INIT);
233	buffer_put_int(&msg, SSH2_FILEXFER_VERSION);
234	send_msg(fd_out, &msg);
235
236	buffer_clear(&msg);
237
238	get_msg(fd_in, &msg);
239
240	/* Expecting a VERSION reply */
241	if ((type = buffer_get_char(&msg)) != SSH2_FXP_VERSION) {
242		error("Invalid packet back from SSH2_FXP_INIT (type %d)",
243		    type);
244		buffer_free(&msg);
245		return(NULL);
246	}
247	version = buffer_get_int(&msg);
248
249	debug2("Remote version: %d", version);
250
251	/* Check for extensions */
252	while (buffer_len(&msg) > 0) {
253		char *name = buffer_get_string(&msg, NULL);
254		char *value = buffer_get_string(&msg, NULL);
255
256		debug2("Init extension: \"%s\"", name);
257		xfree(name);
258		xfree(value);
259	}
260
261	buffer_free(&msg);
262
263	ret = xmalloc(sizeof(*ret));
264	ret->fd_in = fd_in;
265	ret->fd_out = fd_out;
266	ret->transfer_buflen = transfer_buflen;
267	ret->num_requests = num_requests;
268	ret->version = version;
269	ret->msg_id = 1;
270
271	/* Some filexfer v.0 servers don't support large packets */
272	if (version == 0)
273		ret->transfer_buflen = MIN(ret->transfer_buflen, 20480);
274
275	return(ret);
276}
277
278u_int
279sftp_proto_version(struct sftp_conn *conn)
280{
281	return(conn->version);
282}
283
284int
285do_close(struct sftp_conn *conn, char *handle, u_int handle_len)
286{
287	u_int id, status;
288	Buffer msg;
289
290	buffer_init(&msg);
291
292	id = conn->msg_id++;
293	buffer_put_char(&msg, SSH2_FXP_CLOSE);
294	buffer_put_int(&msg, id);
295	buffer_put_string(&msg, handle, handle_len);
296	send_msg(conn->fd_out, &msg);
297	debug3("Sent message SSH2_FXP_CLOSE I:%d", id);
298
299	status = get_status(conn->fd_in, id);
300	if (status != SSH2_FX_OK)
301		error("Couldn't close file: %s", fx2txt(status));
302
303	buffer_free(&msg);
304
305	return(status);
306}
307
308
309static int
310do_lsreaddir(struct sftp_conn *conn, char *path, int printflag,
311    SFTP_DIRENT ***dir)
312{
313	Buffer msg;
314	u_int type, id, handle_len, i, expected_id, ents = 0;
315	char *handle;
316
317	id = conn->msg_id++;
318
319	buffer_init(&msg);
320	buffer_put_char(&msg, SSH2_FXP_OPENDIR);
321	buffer_put_int(&msg, id);
322	buffer_put_cstring(&msg, path);
323	send_msg(conn->fd_out, &msg);
324
325	buffer_clear(&msg);
326
327	handle = get_handle(conn->fd_in, id, &handle_len);
328	if (handle == NULL)
329		return(-1);
330
331	if (dir) {
332		ents = 0;
333		*dir = xmalloc(sizeof(**dir));
334		(*dir)[0] = NULL;
335	}
336
337	for (;;) {
338		int count;
339
340		id = expected_id = conn->msg_id++;
341
342		debug3("Sending SSH2_FXP_READDIR I:%d", id);
343
344		buffer_clear(&msg);
345		buffer_put_char(&msg, SSH2_FXP_READDIR);
346		buffer_put_int(&msg, id);
347		buffer_put_string(&msg, handle, handle_len);
348		send_msg(conn->fd_out, &msg);
349
350		buffer_clear(&msg);
351
352		get_msg(conn->fd_in, &msg);
353
354		type = buffer_get_char(&msg);
355		id = buffer_get_int(&msg);
356
357		debug3("Received reply T:%d I:%d", type, id);
358
359		if (id != expected_id)
360			fatal("ID mismatch (%d != %d)", id, expected_id);
361
362		if (type == SSH2_FXP_STATUS) {
363			int status = buffer_get_int(&msg);
364
365			debug3("Received SSH2_FXP_STATUS %d", status);
366
367			if (status == SSH2_FX_EOF) {
368				break;
369			} else {
370				error("Couldn't read directory: %s",
371				    fx2txt(status));
372				do_close(conn, handle, handle_len);
373				return(status);
374			}
375		} else if (type != SSH2_FXP_NAME)
376			fatal("Expected SSH2_FXP_NAME(%d) packet, got %d",
377			    SSH2_FXP_NAME, type);
378
379		count = buffer_get_int(&msg);
380		if (count == 0)
381			break;
382		debug3("Received %d SSH2_FXP_NAME responses", count);
383		for (i = 0; i < count; i++) {
384			char *filename, *longname;
385			Attrib *a;
386
387			filename = buffer_get_string(&msg, NULL);
388			longname = buffer_get_string(&msg, NULL);
389			a = decode_attrib(&msg);
390
391			if (printflag)
392				printf("%s\n", longname);
393
394			if (dir) {
395				*dir = xrealloc(*dir, sizeof(**dir) *
396				    (ents + 2));
397				(*dir)[ents] = xmalloc(sizeof(***dir));
398				(*dir)[ents]->filename = xstrdup(filename);
399				(*dir)[ents]->longname = xstrdup(longname);
400				memcpy(&(*dir)[ents]->a, a, sizeof(*a));
401				(*dir)[++ents] = NULL;
402			}
403
404			xfree(filename);
405			xfree(longname);
406		}
407	}
408
409	buffer_free(&msg);
410	do_close(conn, handle, handle_len);
411	xfree(handle);
412
413	return(0);
414}
415
416int
417do_ls(struct sftp_conn *conn, char *path)
418{
419	return(do_lsreaddir(conn, path, 1, NULL));
420}
421
422int
423do_readdir(struct sftp_conn *conn, char *path, SFTP_DIRENT ***dir)
424{
425	return(do_lsreaddir(conn, path, 0, dir));
426}
427
428void free_sftp_dirents(SFTP_DIRENT **s)
429{
430	int i;
431
432	for (i = 0; s[i]; i++) {
433		xfree(s[i]->filename);
434		xfree(s[i]->longname);
435		xfree(s[i]);
436	}
437	xfree(s);
438}
439
440int
441do_rm(struct sftp_conn *conn, char *path)
442{
443	u_int status, id;
444
445	debug2("Sending SSH2_FXP_REMOVE \"%s\"", path);
446
447	id = conn->msg_id++;
448	send_string_request(conn->fd_out, id, SSH2_FXP_REMOVE, path,
449	    strlen(path));
450	status = get_status(conn->fd_in, id);
451	if (status != SSH2_FX_OK)
452		error("Couldn't delete file: %s", fx2txt(status));
453	return(status);
454}
455
456int
457do_mkdir(struct sftp_conn *conn, char *path, Attrib *a)
458{
459	u_int status, id;
460
461	id = conn->msg_id++;
462	send_string_attrs_request(conn->fd_out, id, SSH2_FXP_MKDIR, path,
463	    strlen(path), a);
464
465	status = get_status(conn->fd_in, id);
466	if (status != SSH2_FX_OK)
467		error("Couldn't create directory: %s", fx2txt(status));
468
469	return(status);
470}
471
472int
473do_rmdir(struct sftp_conn *conn, char *path)
474{
475	u_int status, id;
476
477	id = conn->msg_id++;
478	send_string_request(conn->fd_out, id, SSH2_FXP_RMDIR, path,
479	    strlen(path));
480
481	status = get_status(conn->fd_in, id);
482	if (status != SSH2_FX_OK)
483		error("Couldn't remove directory: %s", fx2txt(status));
484
485	return(status);
486}
487
488Attrib *
489do_stat(struct sftp_conn *conn, char *path, int quiet)
490{
491	u_int id;
492
493	id = conn->msg_id++;
494
495	send_string_request(conn->fd_out, id,
496	    conn->version == 0 ? SSH2_FXP_STAT_VERSION_0 : SSH2_FXP_STAT,
497	    path, strlen(path));
498
499	return(get_decode_stat(conn->fd_in, id, quiet));
500}
501
502Attrib *
503do_lstat(struct sftp_conn *conn, char *path, int quiet)
504{
505	u_int id;
506
507	if (conn->version == 0) {
508		if (quiet)
509			debug("Server version does not support lstat operation");
510		else
511			log("Server version does not support lstat operation");
512		return(do_stat(conn, path, quiet));
513	}
514
515	id = conn->msg_id++;
516	send_string_request(conn->fd_out, id, SSH2_FXP_LSTAT, path,
517	    strlen(path));
518
519	return(get_decode_stat(conn->fd_in, id, quiet));
520}
521
522Attrib *
523do_fstat(struct sftp_conn *conn, char *handle, u_int handle_len, int quiet)
524{
525	u_int id;
526
527	id = conn->msg_id++;
528	send_string_request(conn->fd_out, id, SSH2_FXP_FSTAT, handle,
529	    handle_len);
530
531	return(get_decode_stat(conn->fd_in, id, quiet));
532}
533
534int
535do_setstat(struct sftp_conn *conn, char *path, Attrib *a)
536{
537	u_int status, id;
538
539	id = conn->msg_id++;
540	send_string_attrs_request(conn->fd_out, id, SSH2_FXP_SETSTAT, path,
541	    strlen(path), a);
542
543	status = get_status(conn->fd_in, id);
544	if (status != SSH2_FX_OK)
545		error("Couldn't setstat on \"%s\": %s", path,
546		    fx2txt(status));
547
548	return(status);
549}
550
551int
552do_fsetstat(struct sftp_conn *conn, char *handle, u_int handle_len,
553    Attrib *a)
554{
555	u_int status, id;
556
557	id = conn->msg_id++;
558	send_string_attrs_request(conn->fd_out, id, SSH2_FXP_FSETSTAT, handle,
559	    handle_len, a);
560
561	status = get_status(conn->fd_in, id);
562	if (status != SSH2_FX_OK)
563		error("Couldn't fsetstat: %s", fx2txt(status));
564
565	return(status);
566}
567
568char *
569do_realpath(struct sftp_conn *conn, char *path)
570{
571	Buffer msg;
572	u_int type, expected_id, count, id;
573	char *filename, *longname;
574	Attrib *a;
575
576	expected_id = id = conn->msg_id++;
577	send_string_request(conn->fd_out, id, SSH2_FXP_REALPATH, path,
578	    strlen(path));
579
580	buffer_init(&msg);
581
582	get_msg(conn->fd_in, &msg);
583	type = buffer_get_char(&msg);
584	id = buffer_get_int(&msg);
585
586	if (id != expected_id)
587		fatal("ID mismatch (%d != %d)", id, expected_id);
588
589	if (type == SSH2_FXP_STATUS) {
590		u_int status = buffer_get_int(&msg);
591
592		error("Couldn't canonicalise: %s", fx2txt(status));
593		return(NULL);
594	} else if (type != SSH2_FXP_NAME)
595		fatal("Expected SSH2_FXP_NAME(%d) packet, got %d",
596		    SSH2_FXP_NAME, type);
597
598	count = buffer_get_int(&msg);
599	if (count != 1)
600		fatal("Got multiple names (%d) from SSH_FXP_REALPATH", count);
601
602	filename = buffer_get_string(&msg, NULL);
603	longname = buffer_get_string(&msg, NULL);
604	a = decode_attrib(&msg);
605
606	debug3("SSH_FXP_REALPATH %s -> %s", path, filename);
607
608	xfree(longname);
609
610	buffer_free(&msg);
611
612	return(filename);
613}
614
615int
616do_rename(struct sftp_conn *conn, char *oldpath, char *newpath)
617{
618	Buffer msg;
619	u_int status, id;
620
621	buffer_init(&msg);
622
623	/* Send rename request */
624	id = conn->msg_id++;
625	buffer_put_char(&msg, SSH2_FXP_RENAME);
626	buffer_put_int(&msg, id);
627	buffer_put_cstring(&msg, oldpath);
628	buffer_put_cstring(&msg, newpath);
629	send_msg(conn->fd_out, &msg);
630	debug3("Sent message SSH2_FXP_RENAME \"%s\" -> \"%s\"", oldpath,
631	    newpath);
632	buffer_free(&msg);
633
634	status = get_status(conn->fd_in, id);
635	if (status != SSH2_FX_OK)
636		error("Couldn't rename file \"%s\" to \"%s\": %s", oldpath,
637		    newpath, fx2txt(status));
638
639	return(status);
640}
641
642int
643do_symlink(struct sftp_conn *conn, char *oldpath, char *newpath)
644{
645	Buffer msg;
646	u_int status, id;
647
648	if (conn->version < 3) {
649		error("This server does not support the symlink operation");
650		return(SSH2_FX_OP_UNSUPPORTED);
651	}
652
653	buffer_init(&msg);
654
655	/* Send rename request */
656	id = conn->msg_id++;
657	buffer_put_char(&msg, SSH2_FXP_SYMLINK);
658	buffer_put_int(&msg, id);
659	buffer_put_cstring(&msg, oldpath);
660	buffer_put_cstring(&msg, newpath);
661	send_msg(conn->fd_out, &msg);
662	debug3("Sent message SSH2_FXP_SYMLINK \"%s\" -> \"%s\"", oldpath,
663	    newpath);
664	buffer_free(&msg);
665
666	status = get_status(conn->fd_in, id);
667	if (status != SSH2_FX_OK)
668		error("Couldn't rename file \"%s\" to \"%s\": %s", oldpath,
669		    newpath, fx2txt(status));
670
671	return(status);
672}
673
674char *
675do_readlink(struct sftp_conn *conn, char *path)
676{
677	Buffer msg;
678	u_int type, expected_id, count, id;
679	char *filename, *longname;
680	Attrib *a;
681
682	expected_id = id = conn->msg_id++;
683	send_string_request(conn->fd_out, id, SSH2_FXP_READLINK, path,
684	    strlen(path));
685
686	buffer_init(&msg);
687
688	get_msg(conn->fd_in, &msg);
689	type = buffer_get_char(&msg);
690	id = buffer_get_int(&msg);
691
692	if (id != expected_id)
693		fatal("ID mismatch (%d != %d)", id, expected_id);
694
695	if (type == SSH2_FXP_STATUS) {
696		u_int status = buffer_get_int(&msg);
697
698		error("Couldn't readlink: %s", fx2txt(status));
699		return(NULL);
700	} else if (type != SSH2_FXP_NAME)
701		fatal("Expected SSH2_FXP_NAME(%d) packet, got %d",
702		    SSH2_FXP_NAME, type);
703
704	count = buffer_get_int(&msg);
705	if (count != 1)
706		fatal("Got multiple names (%d) from SSH_FXP_READLINK", count);
707
708	filename = buffer_get_string(&msg, NULL);
709	longname = buffer_get_string(&msg, NULL);
710	a = decode_attrib(&msg);
711
712	debug3("SSH_FXP_READLINK %s -> %s", path, filename);
713
714	xfree(longname);
715
716	buffer_free(&msg);
717
718	return(filename);
719}
720
721static void
722send_read_request(int fd_out, u_int id, u_int64_t offset, u_int len,
723    char *handle, u_int handle_len)
724{
725	Buffer msg;
726
727	buffer_init(&msg);
728	buffer_clear(&msg);
729	buffer_put_char(&msg, SSH2_FXP_READ);
730	buffer_put_int(&msg, id);
731	buffer_put_string(&msg, handle, handle_len);
732	buffer_put_int64(&msg, offset);
733	buffer_put_int(&msg, len);
734	send_msg(fd_out, &msg);
735	buffer_free(&msg);
736}
737
738int
739do_download(struct sftp_conn *conn, char *remote_path, char *local_path,
740    int pflag)
741{
742	Attrib junk, *a;
743	Buffer msg;
744	char *handle;
745	int local_fd, status, num_req, max_req, write_error;
746	int read_error, write_errno;
747	u_int64_t offset, size;
748	u_int handle_len, mode, type, id, buflen;
749	struct request {
750		u_int id;
751		u_int len;
752		u_int64_t offset;
753		TAILQ_ENTRY(request) tq;
754	};
755	TAILQ_HEAD(reqhead, request) requests;
756	struct request *req;
757
758	TAILQ_INIT(&requests);
759
760	a = do_stat(conn, remote_path, 0);
761	if (a == NULL)
762		return(-1);
763
764	/* XXX: should we preserve set[ug]id? */
765	if (a->flags & SSH2_FILEXFER_ATTR_PERMISSIONS)
766		mode = S_IWRITE | (a->perm & 0777);
767	else
768		mode = 0666;
769
770	if ((a->flags & SSH2_FILEXFER_ATTR_PERMISSIONS) &&
771	    (a->perm & S_IFDIR)) {
772		error("Cannot download a directory: %s", remote_path);
773		return(-1);
774	}
775
776	if (a->flags & SSH2_FILEXFER_ATTR_SIZE)
777		size = a->size;
778	else
779		size = 0;
780
781	buflen = conn->transfer_buflen;
782	buffer_init(&msg);
783
784	/* Send open request */
785	id = conn->msg_id++;
786	buffer_put_char(&msg, SSH2_FXP_OPEN);
787	buffer_put_int(&msg, id);
788	buffer_put_cstring(&msg, remote_path);
789	buffer_put_int(&msg, SSH2_FXF_READ);
790	attrib_clear(&junk); /* Send empty attributes */
791	encode_attrib(&msg, &junk);
792	send_msg(conn->fd_out, &msg);
793	debug3("Sent message SSH2_FXP_OPEN I:%d P:%s", id, remote_path);
794
795	handle = get_handle(conn->fd_in, id, &handle_len);
796	if (handle == NULL) {
797		buffer_free(&msg);
798		return(-1);
799	}
800
801	local_fd = open(local_path, O_WRONLY | O_CREAT | O_TRUNC, mode);
802	if (local_fd == -1) {
803		error("Couldn't open local file \"%s\" for writing: %s",
804		    local_path, strerror(errno));
805		buffer_free(&msg);
806		xfree(handle);
807		return(-1);
808	}
809
810	/* Read from remote and write to local */
811	write_error = read_error = write_errno = num_req = offset = 0;
812	max_req = 1;
813	while (num_req > 0 || max_req > 0) {
814		char *data;
815		u_int len;
816
817		/* Send some more requests */
818		while (num_req < max_req) {
819			debug3("Request range %llu -> %llu (%d/%d)",
820			    (unsigned long long)offset,
821			    (unsigned long long)offset + buflen - 1,
822			    num_req, max_req);
823			req = xmalloc(sizeof(*req));
824			req->id = conn->msg_id++;
825			req->len = buflen;
826			req->offset = offset;
827			offset += buflen;
828			num_req++;
829			TAILQ_INSERT_TAIL(&requests, req, tq);
830			send_read_request(conn->fd_out, req->id, req->offset,
831			    req->len, handle, handle_len);
832		}
833
834		buffer_clear(&msg);
835		get_msg(conn->fd_in, &msg);
836		type = buffer_get_char(&msg);
837		id = buffer_get_int(&msg);
838		debug3("Received reply T:%d I:%d R:%d", type, id, max_req);
839
840		/* Find the request in our queue */
841		for(req = TAILQ_FIRST(&requests);
842		    req != NULL && req->id != id;
843		    req = TAILQ_NEXT(req, tq))
844			;
845		if (req == NULL)
846			fatal("Unexpected reply %u", id);
847
848		switch (type) {
849		case SSH2_FXP_STATUS:
850			status = buffer_get_int(&msg);
851			if (status != SSH2_FX_EOF)
852				read_error = 1;
853			max_req = 0;
854			TAILQ_REMOVE(&requests, req, tq);
855			xfree(req);
856			num_req--;
857			break;
858		case SSH2_FXP_DATA:
859			data = buffer_get_string(&msg, &len);
860			debug3("Received data %llu -> %llu",
861			    (unsigned long long)req->offset,
862			    (unsigned long long)req->offset + len - 1);
863			if (len > req->len)
864				fatal("Received more data than asked for "
865				      "%d > %d", len, req->len);
866			if ((lseek(local_fd, req->offset, SEEK_SET) == -1 ||
867			     atomicio(write, local_fd, data, len) != len) &&
868			    !write_error) {
869				write_errno = errno;
870				write_error = 1;
871				max_req = 0;
872			}
873			xfree(data);
874
875			if (len == req->len) {
876				TAILQ_REMOVE(&requests, req, tq);
877				xfree(req);
878				num_req--;
879			} else {
880				/* Resend the request for the missing data */
881				debug3("Short data block, re-requesting "
882				    "%llu -> %llu (%2d)",
883				    (unsigned long long)req->offset + len,
884				    (unsigned long long)req->offset +
885				    req->len - 1, num_req);
886				req->id = conn->msg_id++;
887				req->len -= len;
888				req->offset += len;
889				send_read_request(conn->fd_out, req->id,
890				    req->offset, req->len, handle, handle_len);
891				/* Reduce the request size */
892				if (len < buflen)
893					buflen = MAX(MIN_READ_SIZE, len);
894			}
895			if (max_req > 0) { /* max_req = 0 iff EOF received */
896				if (size > 0 && offset > size) {
897					/* Only one request at a time
898					 * after the expected EOF */
899					debug3("Finish at %llu (%2d)",
900					    (unsigned long long)offset,
901					    num_req);
902					max_req = 1;
903				}
904				else if (max_req < conn->num_requests + 1) {
905					++max_req;
906				}
907			}
908			break;
909		default:
910			fatal("Expected SSH2_FXP_DATA(%d) packet, got %d",
911			    SSH2_FXP_DATA, type);
912		}
913	}
914
915	/* Sanity check */
916	if (TAILQ_FIRST(&requests) != NULL)
917		fatal("Transfer complete, but requests still in queue");
918
919	if (read_error) {
920		error("Couldn't read from remote file \"%s\" : %s",
921		    remote_path, fx2txt(status));
922		do_close(conn, handle, handle_len);
923	} else if (write_error) {
924		error("Couldn't write to \"%s\": %s", local_path,
925		    strerror(write_errno));
926		status = -1;
927		do_close(conn, handle, handle_len);
928	} else {
929		status = do_close(conn, handle, handle_len);
930
931		/* Override umask and utimes if asked */
932		if (pflag && fchmod(local_fd, mode) == -1)
933			error("Couldn't set mode on \"%s\": %s", local_path,
934			      strerror(errno));
935		if (pflag && (a->flags & SSH2_FILEXFER_ATTR_ACMODTIME)) {
936			struct timeval tv[2];
937			tv[0].tv_sec = a->atime;
938			tv[1].tv_sec = a->mtime;
939			tv[0].tv_usec = tv[1].tv_usec = 0;
940			if (utimes(local_path, tv) == -1)
941				error("Can't set times on \"%s\": %s",
942				      local_path, strerror(errno));
943		}
944	}
945	close(local_fd);
946	buffer_free(&msg);
947	xfree(handle);
948
949	return(status);
950}
951
952int
953do_upload(struct sftp_conn *conn, char *local_path, char *remote_path,
954    int pflag)
955{
956	int local_fd, status;
957	u_int handle_len, id, type;
958	u_int64_t offset;
959	char *handle, *data;
960	Buffer msg;
961	struct stat sb;
962	Attrib a;
963	u_int32_t startid;
964	u_int32_t ackid;
965	struct outstanding_ack {
966		u_int id;
967		u_int len;
968		u_int64_t offset;
969		TAILQ_ENTRY(outstanding_ack) tq;
970	};
971	TAILQ_HEAD(ackhead, outstanding_ack) acks;
972	struct outstanding_ack *ack;
973
974	TAILQ_INIT(&acks);
975
976	if ((local_fd = open(local_path, O_RDONLY, 0)) == -1) {
977		error("Couldn't open local file \"%s\" for reading: %s",
978		    local_path, strerror(errno));
979		return(-1);
980	}
981	if (fstat(local_fd, &sb) == -1) {
982		error("Couldn't fstat local file \"%s\": %s",
983		    local_path, strerror(errno));
984		close(local_fd);
985		return(-1);
986	}
987	stat_to_attrib(&sb, &a);
988
989	a.flags &= ~SSH2_FILEXFER_ATTR_SIZE;
990	a.flags &= ~SSH2_FILEXFER_ATTR_UIDGID;
991	a.perm &= 0777;
992	if (!pflag)
993		a.flags &= ~SSH2_FILEXFER_ATTR_ACMODTIME;
994
995	buffer_init(&msg);
996
997	/* Send open request */
998	id = conn->msg_id++;
999	buffer_put_char(&msg, SSH2_FXP_OPEN);
1000	buffer_put_int(&msg, id);
1001	buffer_put_cstring(&msg, remote_path);
1002	buffer_put_int(&msg, SSH2_FXF_WRITE|SSH2_FXF_CREAT|SSH2_FXF_TRUNC);
1003	encode_attrib(&msg, &a);
1004	send_msg(conn->fd_out, &msg);
1005	debug3("Sent message SSH2_FXP_OPEN I:%d P:%s", id, remote_path);
1006
1007	buffer_clear(&msg);
1008
1009	handle = get_handle(conn->fd_in, id, &handle_len);
1010	if (handle == NULL) {
1011		close(local_fd);
1012		buffer_free(&msg);
1013		return(-1);
1014	}
1015
1016	startid = ackid = id + 1;
1017	data = xmalloc(conn->transfer_buflen);
1018
1019	/* Read from local and write to remote */
1020	offset = 0;
1021	for (;;) {
1022		int len;
1023
1024		/*
1025		 * Can't use atomicio here because it returns 0 on EOF, thus losing
1026		 * the last block of the file
1027		 */
1028		do
1029			len = read(local_fd, data, conn->transfer_buflen);
1030		while ((len == -1) && (errno == EINTR || errno == EAGAIN));
1031
1032		if (len == -1)
1033			fatal("Couldn't read from \"%s\": %s", local_path,
1034			    strerror(errno));
1035
1036		if (len != 0) {
1037			ack = xmalloc(sizeof(*ack));
1038			ack->id = ++id;
1039			ack->offset = offset;
1040			ack->len = len;
1041			TAILQ_INSERT_TAIL(&acks, ack, tq);
1042
1043			buffer_clear(&msg);
1044			buffer_put_char(&msg, SSH2_FXP_WRITE);
1045			buffer_put_int(&msg, ack->id);
1046			buffer_put_string(&msg, handle, handle_len);
1047			buffer_put_int64(&msg, offset);
1048			buffer_put_string(&msg, data, len);
1049			send_msg(conn->fd_out, &msg);
1050			debug3("Sent message SSH2_FXP_WRITE I:%d O:%llu S:%u",
1051			       id, (unsigned long long)offset, len);
1052		} else if (TAILQ_FIRST(&acks) == NULL)
1053			break;
1054
1055		if (ack == NULL)
1056			fatal("Unexpected ACK %u", id);
1057
1058		if (id == startid || len == 0 ||
1059		    id - ackid >= conn->num_requests) {
1060			u_int r_id;
1061
1062			buffer_clear(&msg);
1063			get_msg(conn->fd_in, &msg);
1064			type = buffer_get_char(&msg);
1065			r_id = buffer_get_int(&msg);
1066
1067			if (type != SSH2_FXP_STATUS)
1068				fatal("Expected SSH2_FXP_STATUS(%d) packet, "
1069				    "got %d", SSH2_FXP_STATUS, type);
1070
1071			status = buffer_get_int(&msg);
1072			debug3("SSH2_FXP_STATUS %d", status);
1073
1074			/* Find the request in our queue */
1075			for(ack = TAILQ_FIRST(&acks);
1076			    ack != NULL && ack->id != r_id;
1077			    ack = TAILQ_NEXT(ack, tq))
1078				;
1079			if (ack == NULL)
1080				fatal("Can't find request for ID %d", r_id);
1081			TAILQ_REMOVE(&acks, ack, tq);
1082
1083			if (status != SSH2_FX_OK) {
1084				error("Couldn't write to remote file \"%s\": %s",
1085				      remote_path, fx2txt(status));
1086				do_close(conn, handle, handle_len);
1087				close(local_fd);
1088				goto done;
1089			}
1090			debug3("In write loop, ack for %u %d bytes at %llu",
1091			   ack->id, ack->len, (unsigned long long)ack->offset);
1092			++ackid;
1093			free(ack);
1094		}
1095		offset += len;
1096	}
1097	xfree(data);
1098
1099	if (close(local_fd) == -1) {
1100		error("Couldn't close local file \"%s\": %s", local_path,
1101		    strerror(errno));
1102		do_close(conn, handle, handle_len);
1103		status = -1;
1104		goto done;
1105	}
1106
1107	/* Override umask and utimes if asked */
1108	if (pflag)
1109		do_fsetstat(conn, handle, handle_len, &a);
1110
1111	status = do_close(conn, handle, handle_len);
1112
1113done:
1114	xfree(handle);
1115	buffer_free(&msg);
1116	return(status);
1117}
1118