1148771Scperciva/*- 2148771Scperciva * Copyright 2003-2005 Colin Percival 3148771Scperciva * All rights reserved 4148771Scperciva * 5148771Scperciva * Redistribution and use in source and binary forms, with or without 6148771Scperciva * modification, are permitted providing that the following conditions 7148771Scperciva * are met: 8148771Scperciva * 1. Redistributions of source code must retain the above copyright 9148771Scperciva * notice, this list of conditions and the following disclaimer. 10148771Scperciva * 2. Redistributions in binary form must reproduce the above copyright 11148771Scperciva * notice, this list of conditions and the following disclaimer in the 12148771Scperciva * documentation and/or other materials provided with the distribution. 13148771Scperciva * 14148771Scperciva * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 15148771Scperciva * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED 16148771Scperciva * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 17148771Scperciva * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY 18148771Scperciva * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 19148771Scperciva * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 20148771Scperciva * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 21148771Scperciva * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 22148771Scperciva * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING 23148771Scperciva * IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 24148771Scperciva * POSSIBILITY OF SUCH DAMAGE. 25148771Scperciva */ 26148771Scperciva 27148771Scperciva#include <sys/cdefs.h> 28148771Scperciva__FBSDID("$FreeBSD: releng/9.3/usr.bin/bsdiff/bspatch/bspatch.c 306942 2016-10-10 07:19:16Z delphij $"); 29148771Scperciva 30306942Sdelphij#if defined(__FreeBSD__) 31306942Sdelphij#include <sys/param.h> 32306942Sdelphij#if __FreeBSD_version >= 1001511 33306942Sdelphij#include <sys/capsicum.h> 34306942Sdelphij#define HAVE_CAPSICUM 35306942Sdelphij#endif 36306942Sdelphij#endif 37306942Sdelphij 38148771Scperciva#include <bzlib.h> 39306942Sdelphij#include <err.h> 40306942Sdelphij#include <errno.h> 41306942Sdelphij#include <fcntl.h> 42306942Sdelphij#include <libgen.h> 43306942Sdelphij#include <limits.h> 44306942Sdelphij#include <stdint.h> 45306942Sdelphij#include <stdio.h> 46148771Scperciva#include <stdlib.h> 47148771Scperciva#include <string.h> 48148771Scperciva#include <unistd.h> 49148771Scperciva 50164922Scperciva#ifndef O_BINARY 51164922Scperciva#define O_BINARY 0 52164922Scperciva#endif 53306942Sdelphij#define HEADER_SIZE 32 54164922Scperciva 55306942Sdelphijstatic char *newfile; 56306942Sdelphijstatic int dirfd = -1; 57306942Sdelphij 58306942Sdelphijstatic void 59306942Sdelphijexit_cleanup(void) 60306942Sdelphij{ 61306942Sdelphij 62306942Sdelphij if (dirfd != -1 && newfile != NULL) 63306942Sdelphij if (unlinkat(dirfd, newfile, 0)) 64306942Sdelphij warn("unlinkat"); 65306942Sdelphij} 66306942Sdelphij 67148771Scpercivastatic off_t offtin(u_char *buf) 68148771Scperciva{ 69148771Scperciva off_t y; 70148771Scperciva 71306942Sdelphij y = buf[7] & 0x7F; 72306942Sdelphij y = y * 256; y += buf[6]; 73306942Sdelphij y = y * 256; y += buf[5]; 74306942Sdelphij y = y * 256; y += buf[4]; 75306942Sdelphij y = y * 256; y += buf[3]; 76306942Sdelphij y = y * 256; y += buf[2]; 77306942Sdelphij y = y * 256; y += buf[1]; 78306942Sdelphij y = y * 256; y += buf[0]; 79148771Scperciva 80306942Sdelphij if (buf[7] & 0x80) 81306942Sdelphij y = -y; 82148771Scperciva 83306942Sdelphij return (y); 84148771Scperciva} 85148771Scperciva 86306942Sdelphijint main(int argc, char *argv[]) 87148771Scperciva{ 88306942Sdelphij FILE *f, *cpf, *dpf, *epf; 89306942Sdelphij BZFILE *cpfbz2, *dpfbz2, *epfbz2; 90306942Sdelphij char *directory, *namebuf; 91148771Scperciva int cbz2err, dbz2err, ebz2err; 92306942Sdelphij int newfd, oldfd; 93306942Sdelphij off_t oldsize, newsize; 94306942Sdelphij off_t bzctrllen, bzdatalen; 95306942Sdelphij u_char header[HEADER_SIZE], buf[8]; 96148771Scperciva u_char *old, *new; 97306942Sdelphij off_t oldpos, newpos; 98148771Scperciva off_t ctrl[3]; 99306942Sdelphij off_t i, lenread, offset; 100306942Sdelphij#ifdef HAVE_CAPSICUM 101306942Sdelphij cap_rights_t rights_dir, rights_ro, rights_wr; 102306942Sdelphij#endif 103148771Scperciva 104148771Scperciva if(argc!=4) errx(1,"usage: %s oldfile newfile patchfile\n",argv[0]); 105148771Scperciva 106148771Scperciva /* Open patch file */ 107164922Scperciva if ((f = fopen(argv[3], "rb")) == NULL) 108148771Scperciva err(1, "fopen(%s)", argv[3]); 109306942Sdelphij /* Open patch file for control block */ 110306942Sdelphij if ((cpf = fopen(argv[3], "rb")) == NULL) 111306942Sdelphij err(1, "fopen(%s)", argv[3]); 112306942Sdelphij /* open patch file for diff block */ 113306942Sdelphij if ((dpf = fopen(argv[3], "rb")) == NULL) 114306942Sdelphij err(1, "fopen(%s)", argv[3]); 115306942Sdelphij /* open patch file for extra block */ 116306942Sdelphij if ((epf = fopen(argv[3], "rb")) == NULL) 117306942Sdelphij err(1, "fopen(%s)", argv[3]); 118306942Sdelphij /* open oldfile */ 119306942Sdelphij if ((oldfd = open(argv[1], O_RDONLY | O_BINARY, 0)) < 0) 120306942Sdelphij err(1, "open(%s)", argv[1]); 121306942Sdelphij /* open directory where we'll write newfile */ 122306942Sdelphij if ((namebuf = strdup(argv[2])) == NULL || 123306942Sdelphij (directory = dirname(namebuf)) == NULL || 124306942Sdelphij (dirfd = open(directory, O_DIRECTORY)) < 0) 125306942Sdelphij err(1, "open %s", argv[2]); 126306942Sdelphij free(namebuf); 127306942Sdelphij if ((newfile = basename(argv[2])) == NULL) 128306942Sdelphij err(1, "basename"); 129306942Sdelphij /* open newfile */ 130306942Sdelphij if ((newfd = openat(dirfd, newfile, 131306942Sdelphij O_CREAT | O_TRUNC | O_WRONLY | O_BINARY, 0666)) < 0) 132306942Sdelphij err(1, "open(%s)", argv[2]); 133306942Sdelphij atexit(exit_cleanup); 134148771Scperciva 135306942Sdelphij#ifdef HAVE_CAPSICUM 136306942Sdelphij if (cap_enter() < 0) { 137306942Sdelphij /* Failed to sandbox, fatal if CAPABILITY_MODE enabled */ 138306942Sdelphij if (errno != ENOSYS) 139306942Sdelphij err(1, "failed to enter security sandbox"); 140306942Sdelphij } else { 141306942Sdelphij /* Capsicum Available */ 142306942Sdelphij cap_rights_init(&rights_ro, CAP_READ, CAP_FSTAT, CAP_SEEK); 143306942Sdelphij cap_rights_init(&rights_wr, CAP_WRITE); 144306942Sdelphij cap_rights_init(&rights_dir, CAP_UNLINKAT); 145306942Sdelphij 146306942Sdelphij if (cap_rights_limit(fileno(f), &rights_ro) < 0 || 147306942Sdelphij cap_rights_limit(fileno(cpf), &rights_ro) < 0 || 148306942Sdelphij cap_rights_limit(fileno(dpf), &rights_ro) < 0 || 149306942Sdelphij cap_rights_limit(fileno(epf), &rights_ro) < 0 || 150306942Sdelphij cap_rights_limit(oldfd, &rights_ro) < 0 || 151306942Sdelphij cap_rights_limit(newfd, &rights_wr) < 0 || 152306942Sdelphij cap_rights_limit(dirfd, &rights_dir) < 0) 153306942Sdelphij err(1, "cap_rights_limit() failed, could not restrict" 154306942Sdelphij " capabilities"); 155306942Sdelphij } 156306942Sdelphij#endif 157306942Sdelphij 158148771Scperciva /* 159148771Scperciva File format: 160148771Scperciva 0 8 "BSDIFF40" 161148771Scperciva 8 8 X 162148771Scperciva 16 8 Y 163148771Scperciva 24 8 sizeof(newfile) 164148771Scperciva 32 X bzip2(control block) 165148771Scperciva 32+X Y bzip2(diff block) 166148771Scperciva 32+X+Y ??? bzip2(extra block) 167148771Scperciva with control block a set of triples (x,y,z) meaning "add x bytes 168148771Scperciva from oldfile to x bytes from the diff block; copy y bytes from the 169148771Scperciva extra block; seek forwards in oldfile by z bytes". 170148771Scperciva */ 171148771Scperciva 172148771Scperciva /* Read header */ 173306942Sdelphij if (fread(header, 1, HEADER_SIZE, f) < HEADER_SIZE) { 174148771Scperciva if (feof(f)) 175306942Sdelphij errx(1, "Corrupt patch"); 176148771Scperciva err(1, "fread(%s)", argv[3]); 177148771Scperciva } 178148771Scperciva 179148771Scperciva /* Check for appropriate magic */ 180148771Scperciva if (memcmp(header, "BSDIFF40", 8) != 0) 181306942Sdelphij errx(1, "Corrupt patch"); 182148771Scperciva 183148771Scperciva /* Read lengths from header */ 184306942Sdelphij bzctrllen = offtin(header + 8); 185306942Sdelphij bzdatalen = offtin(header + 16); 186306942Sdelphij newsize = offtin(header + 24); 187306942Sdelphij if (bzctrllen < 0 || bzctrllen > OFF_MAX - HEADER_SIZE || 188306942Sdelphij bzdatalen < 0 || bzctrllen + HEADER_SIZE > OFF_MAX - bzdatalen || 189306942Sdelphij newsize < 0 || newsize > SSIZE_MAX) 190306942Sdelphij errx(1, "Corrupt patch"); 191148771Scperciva 192148771Scperciva /* Close patch file and re-open it via libbzip2 at the right places */ 193148771Scperciva if (fclose(f)) 194148771Scperciva err(1, "fclose(%s)", argv[3]); 195306942Sdelphij offset = HEADER_SIZE; 196306942Sdelphij if (fseeko(cpf, offset, SEEK_SET)) 197306942Sdelphij err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset); 198148771Scperciva if ((cpfbz2 = BZ2_bzReadOpen(&cbz2err, cpf, 0, 0, NULL, 0)) == NULL) 199148771Scperciva errx(1, "BZ2_bzReadOpen, bz2err = %d", cbz2err); 200306942Sdelphij offset += bzctrllen; 201306942Sdelphij if (fseeko(dpf, offset, SEEK_SET)) 202306942Sdelphij err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset); 203148771Scperciva if ((dpfbz2 = BZ2_bzReadOpen(&dbz2err, dpf, 0, 0, NULL, 0)) == NULL) 204148771Scperciva errx(1, "BZ2_bzReadOpen, bz2err = %d", dbz2err); 205306942Sdelphij offset += bzdatalen; 206306942Sdelphij if (fseeko(epf, offset, SEEK_SET)) 207306942Sdelphij err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset); 208148771Scperciva if ((epfbz2 = BZ2_bzReadOpen(&ebz2err, epf, 0, 0, NULL, 0)) == NULL) 209148771Scperciva errx(1, "BZ2_bzReadOpen, bz2err = %d", ebz2err); 210148771Scperciva 211306942Sdelphij if ((oldsize = lseek(oldfd, 0, SEEK_END)) == -1 || 212306942Sdelphij oldsize > SSIZE_MAX || 213306942Sdelphij (old = malloc(oldsize)) == NULL || 214306942Sdelphij lseek(oldfd, 0, SEEK_SET) != 0 || 215306942Sdelphij read(oldfd, old, oldsize) != oldsize || 216306942Sdelphij close(oldfd) == -1) 217306942Sdelphij err(1, "%s", argv[1]); 218306942Sdelphij if ((new = malloc(newsize)) == NULL) 219306942Sdelphij err(1, NULL); 220148771Scperciva 221306942Sdelphij oldpos = 0; 222306942Sdelphij newpos = 0; 223306942Sdelphij while (newpos < newsize) { 224148771Scperciva /* Read control data */ 225306942Sdelphij for (i = 0; i <= 2; i++) { 226148771Scperciva lenread = BZ2_bzRead(&cbz2err, cpfbz2, buf, 8); 227148771Scperciva if ((lenread < 8) || ((cbz2err != BZ_OK) && 228148771Scperciva (cbz2err != BZ_STREAM_END))) 229306942Sdelphij errx(1, "Corrupt patch"); 230306942Sdelphij ctrl[i] = offtin(buf); 231148771Scperciva }; 232148771Scperciva 233148771Scperciva /* Sanity-check */ 234306942Sdelphij if (ctrl[0] < 0 || ctrl[0] > INT_MAX || 235306942Sdelphij ctrl[1] < 0 || ctrl[1] > INT_MAX) 236306942Sdelphij errx(1, "Corrupt patch"); 237303304Sdelphij 238303304Sdelphij /* Sanity-check */ 239306942Sdelphij if (newpos + ctrl[0] > newsize) 240306942Sdelphij errx(1, "Corrupt patch"); 241148771Scperciva 242148771Scperciva /* Read diff string */ 243148771Scperciva lenread = BZ2_bzRead(&dbz2err, dpfbz2, new + newpos, ctrl[0]); 244148771Scperciva if ((lenread < ctrl[0]) || 245148771Scperciva ((dbz2err != BZ_OK) && (dbz2err != BZ_STREAM_END))) 246306942Sdelphij errx(1, "Corrupt patch"); 247148771Scperciva 248148771Scperciva /* Add old data to diff string */ 249306942Sdelphij for (i = 0; i < ctrl[0]; i++) 250306942Sdelphij if ((oldpos + i >= 0) && (oldpos + i < oldsize)) 251306942Sdelphij new[newpos + i] += old[oldpos + i]; 252148771Scperciva 253148771Scperciva /* Adjust pointers */ 254306942Sdelphij newpos += ctrl[0]; 255306942Sdelphij oldpos += ctrl[0]; 256148771Scperciva 257148771Scperciva /* Sanity-check */ 258306942Sdelphij if (newpos + ctrl[1] > newsize) 259306942Sdelphij errx(1, "Corrupt patch"); 260148771Scperciva 261148771Scperciva /* Read extra string */ 262148771Scperciva lenread = BZ2_bzRead(&ebz2err, epfbz2, new + newpos, ctrl[1]); 263148771Scperciva if ((lenread < ctrl[1]) || 264148771Scperciva ((ebz2err != BZ_OK) && (ebz2err != BZ_STREAM_END))) 265306942Sdelphij errx(1, "Corrupt patch"); 266148771Scperciva 267148771Scperciva /* Adjust pointers */ 268148771Scperciva newpos+=ctrl[1]; 269148771Scperciva oldpos+=ctrl[2]; 270148771Scperciva }; 271148771Scperciva 272148771Scperciva /* Clean up the bzip2 reads */ 273148771Scperciva BZ2_bzReadClose(&cbz2err, cpfbz2); 274148771Scperciva BZ2_bzReadClose(&dbz2err, dpfbz2); 275148771Scperciva BZ2_bzReadClose(&ebz2err, epfbz2); 276148771Scperciva if (fclose(cpf) || fclose(dpf) || fclose(epf)) 277148771Scperciva err(1, "fclose(%s)", argv[3]); 278148771Scperciva 279148771Scperciva /* Write the new file */ 280306942Sdelphij if (write(newfd, new, newsize) != newsize || close(newfd) == -1) 281306942Sdelphij err(1, "%s", argv[2]); 282306942Sdelphij /* Disable atexit cleanup */ 283306942Sdelphij newfile = NULL; 284148771Scperciva 285148771Scperciva free(new); 286148771Scperciva free(old); 287148771Scperciva 288306942Sdelphij return (0); 289148771Scperciva} 290