]> git.saurik.com Git - apt.git/blame - apt-pkg/contrib/fileutl.cc
Do nothing in FileFd::Write() if Size is 0
[apt.git] / apt-pkg / contrib / fileutl.cc
CommitLineData
578bfd0a
AL
1// -*- mode: cpp; mode: fold -*-
2// Description /*{{{*/
578bfd0a
AL
3/* ######################################################################
4
5 File Utilities
6
7 CopyFile - Buffered copy of a single file
8 GetLock - dpkg compatible lock file manipulation (fcntl)
9
614adaa0
MV
10 Most of this source is placed in the Public Domain, do with it what
11 you will
7da2b375 12 It was originally written by Jason Gunthorpe <jgg@debian.org>.
a3a03f5d 13 FileFd gzip support added by Martin Pitt <martin.pitt@canonical.com>
578bfd0a 14
614adaa0
MV
15 The exception is RunScripts() it is under the GPLv2
16
578bfd0a
AL
17 ##################################################################### */
18 /*}}}*/
19// Include Files /*{{{*/
ea542140
DK
20#include <config.h>
21
094a497d 22#include <apt-pkg/fileutl.h>
1cd1c398 23#include <apt-pkg/strutl.h>
094a497d 24#include <apt-pkg/error.h>
b2e465d6 25#include <apt-pkg/sptr.h>
468720c5 26#include <apt-pkg/aptconfiguration.h>
75ef8f14 27#include <apt-pkg/configuration.h>
453b82a3 28#include <apt-pkg/macros.h>
b2e465d6 29
453b82a3
DK
30#include <ctype.h>
31#include <stdarg.h>
32#include <stddef.h>
33#include <sys/select.h>
34#include <time.h>
35#include <string>
36#include <vector>
152ab79e 37#include <cstdlib>
4f333a8b 38#include <cstring>
3010fb0e 39#include <cstdio>
4d055c05 40#include <iostream>
578bfd0a 41#include <unistd.h>
2c206aa4 42#include <fcntl.h>
578bfd0a 43#include <sys/stat.h>
cc2313b7 44#include <sys/time.h>
1ae93c94 45#include <sys/wait.h>
46e39c8e 46#include <dirent.h>
54676e1a 47#include <signal.h>
65a1e968 48#include <errno.h>
8d01b9d6 49#include <glob.h>
fc1a78d8 50#include <pwd.h>
3927c6da 51#include <grp.h>
8d01b9d6 52
75ef8f14 53#include <set>
46e39c8e 54#include <algorithm>
98cc7fd2 55#include <memory>
2cae0ccb 56
7efb8c8e
DK
57#ifdef HAVE_ZLIB
58 #include <zlib.h>
699b209e 59#endif
c4997486
DK
60#ifdef HAVE_BZ2
61 #include <bzlib.h>
62#endif
7f350a37
DK
63#ifdef HAVE_LZMA
64 #include <lzma.h>
2cae0ccb 65#endif
05eab8af
AC
66#include <endian.h>
67#include <stdint.h>
ea542140 68
3927c6da
MV
69#if __gnu_linux__
70#include <sys/prctl.h>
71#endif
72
ea542140 73#include <apti18n.h>
578bfd0a
AL
74 /*}}}*/
75
4d055c05
AL
76using namespace std;
77
614adaa0
MV
78// RunScripts - Run a set of scripts from a configuration subtree /*{{{*/
79// ---------------------------------------------------------------------
80/* */
81bool RunScripts(const char *Cnf)
82{
83 Configuration::Item const *Opts = _config->Tree(Cnf);
84 if (Opts == 0 || Opts->Child == 0)
85 return true;
86 Opts = Opts->Child;
87
88 // Fork for running the system calls
89 pid_t Child = ExecFork();
90
91 // This is the child
92 if (Child == 0)
93 {
cfba4f69
MV
94 if (_config->FindDir("DPkg::Chroot-Directory","/") != "/")
95 {
96 std::cerr << "Chrooting into "
97 << _config->FindDir("DPkg::Chroot-Directory")
98 << std::endl;
99 if (chroot(_config->FindDir("DPkg::Chroot-Directory","/").c_str()) != 0)
100 _exit(100);
101 }
102
614adaa0
MV
103 if (chdir("/tmp/") != 0)
104 _exit(100);
105
106 unsigned int Count = 1;
107 for (; Opts != 0; Opts = Opts->Next, Count++)
108 {
109 if (Opts->Value.empty() == true)
110 continue;
e5b7e019
MV
111
112 if(_config->FindB("Debug::RunScripts", false) == true)
113 std::clog << "Running external script: '"
114 << Opts->Value << "'" << std::endl;
115
614adaa0
MV
116 if (system(Opts->Value.c_str()) != 0)
117 _exit(100+Count);
118 }
119 _exit(0);
120 }
121
122 // Wait for the child
123 int Status = 0;
124 while (waitpid(Child,&Status,0) != Child)
125 {
126 if (errno == EINTR)
127 continue;
128 return _error->Errno("waitpid","Couldn't wait for subprocess");
129 }
130
131 // Restore sig int/quit
132 signal(SIGQUIT,SIG_DFL);
133 signal(SIGINT,SIG_DFL);
134
135 // Check for an error code.
136 if (WIFEXITED(Status) == 0 || WEXITSTATUS(Status) != 0)
137 {
138 unsigned int Count = WEXITSTATUS(Status);
139 if (Count > 100)
140 {
141 Count -= 100;
142 for (; Opts != 0 && Count != 1; Opts = Opts->Next, Count--);
143 _error->Error("Problem executing scripts %s '%s'",Cnf,Opts->Value.c_str());
144 }
145
146 return _error->Error("Sub-process returned an error code");
147 }
148
149 return true;
150}
151 /*}}}*/
152
578bfd0a
AL
153// CopyFile - Buffered copy of a file /*{{{*/
154// ---------------------------------------------------------------------
155/* The caller is expected to set things so that failure causes erasure */
8b89e57f 156bool CopyFile(FileFd &From,FileFd &To)
578bfd0a 157{
2128d3fc
DK
158 if (From.IsOpen() == false || To.IsOpen() == false ||
159 From.Failed() == true || To.Failed() == true)
578bfd0a 160 return false;
e977b8b9 161
578bfd0a 162 // Buffered copy between fds
0c93e388
PT
163 constexpr size_t BufSize = 64000;
164 std::unique_ptr<unsigned char[]> Buf(new unsigned char[BufSize]);
e977b8b9
DK
165 unsigned long long ToRead = 0;
166 do {
167 if (From.Read(Buf.get(),BufSize, &ToRead) == false ||
5df91bc7 168 To.Write(Buf.get(),ToRead) == false)
578bfd0a 169 return false;
e977b8b9 170 } while (ToRead != 0);
578bfd0a 171
ce1f3a2c
DK
172 return true;
173}
174 /*}}}*/
175bool RemoveFile(char const * const Function, std::string const &FileName)/*{{{*/
176{
177 if (FileName == "/dev/null")
178 return true;
179 errno = 0;
180 if (unlink(FileName.c_str()) != 0)
181 {
182 if (errno == ENOENT)
183 return true;
184
185 return _error->WarningE(Function,_("Problem unlinking the file %s"), FileName.c_str());
186 }
e977b8b9 187 return true;
578bfd0a
AL
188}
189 /*}}}*/
190// GetLock - Gets a lock file /*{{{*/
191// ---------------------------------------------------------------------
192/* This will create an empty file of the given name and lock it. Once this
193 is done all other calls to GetLock in any other process will fail with
194 -1. The return result is the fd of the file, the call should call
195 close at some time. */
196int GetLock(string File,bool Errors)
197{
f659b39a
OS
198 // GetLock() is used in aptitude on directories with public-write access
199 // Use O_NOFOLLOW here to prevent symlink traversal attacks
200 int FD = open(File.c_str(),O_RDWR | O_CREAT | O_NOFOLLOW,0640);
578bfd0a
AL
201 if (FD < 0)
202 {
1e3f4083 203 // Read only .. can't have locking problems there.
b2e465d6
AL
204 if (errno == EROFS)
205 {
206 _error->Warning(_("Not using locking for read only lock file %s"),File.c_str());
207 return dup(0); // Need something for the caller to close
208 }
209
578bfd0a 210 if (Errors == true)
b2e465d6
AL
211 _error->Errno("open",_("Could not open lock file %s"),File.c_str());
212
213 // Feh.. We do this to distinguish the lock vs open case..
214 errno = EPERM;
578bfd0a
AL
215 return -1;
216 }
b2e465d6
AL
217 SetCloseExec(FD,true);
218
1e3f4083 219 // Acquire a write lock
578bfd0a 220 struct flock fl;
c71bc556
AL
221 fl.l_type = F_WRLCK;
222 fl.l_whence = SEEK_SET;
223 fl.l_start = 0;
224 fl.l_len = 0;
578bfd0a
AL
225 if (fcntl(FD,F_SETLK,&fl) == -1)
226 {
3d165906
MV
227 // always close to not leak resources
228 int Tmp = errno;
229 close(FD);
230 errno = Tmp;
231
d89df07a
AL
232 if (errno == ENOLCK)
233 {
b2e465d6
AL
234 _error->Warning(_("Not using locking for nfs mounted lock file %s"),File.c_str());
235 return dup(0); // Need something for the caller to close
3d165906
MV
236 }
237
578bfd0a 238 if (Errors == true)
b2e465d6
AL
239 _error->Errno("open",_("Could not get lock %s"),File.c_str());
240
578bfd0a
AL
241 return -1;
242 }
243
244 return FD;
245}
246 /*}}}*/
247// FileExists - Check if a file exists /*{{{*/
248// ---------------------------------------------------------------------
36f1098a 249/* Beware: Directories are also files! */
578bfd0a
AL
250bool FileExists(string File)
251{
252 struct stat Buf;
253 if (stat(File.c_str(),&Buf) != 0)
254 return false;
255 return true;
256}
257 /*}}}*/
36f1098a
DK
258// RealFileExists - Check if a file exists and if it is really a file /*{{{*/
259// ---------------------------------------------------------------------
260/* */
261bool RealFileExists(string File)
262{
263 struct stat Buf;
264 if (stat(File.c_str(),&Buf) != 0)
265 return false;
266 return ((Buf.st_mode & S_IFREG) != 0);
267}
268 /*}}}*/
1cd1c398
DK
269// DirectoryExists - Check if a directory exists and is really one /*{{{*/
270// ---------------------------------------------------------------------
271/* */
272bool DirectoryExists(string const &Path)
273{
274 struct stat Buf;
275 if (stat(Path.c_str(),&Buf) != 0)
276 return false;
277 return ((Buf.st_mode & S_IFDIR) != 0);
278}
279 /*}}}*/
280// CreateDirectory - poor man's mkdir -p guarded by a parent directory /*{{{*/
281// ---------------------------------------------------------------------
282/* This method will create all directories needed for path in good old
283 mkdir -p style but refuses to do this if Parent is not a prefix of
284 this Path. Example: /var/cache/ and /var/cache/apt/archives are given,
285 so it will create apt/archives if /var/cache exists - on the other
286 hand if the parent is /var/lib the creation will fail as this path
287 is not a parent of the path to be generated. */
288bool CreateDirectory(string const &Parent, string const &Path)
289{
290 if (Parent.empty() == true || Path.empty() == true)
291 return false;
292
293 if (DirectoryExists(Path) == true)
294 return true;
295
296 if (DirectoryExists(Parent) == false)
297 return false;
298
299 // we are not going to create directories "into the blue"
9ce3cfc9 300 if (Path.compare(0, Parent.length(), Parent) != 0)
1cd1c398
DK
301 return false;
302
303 vector<string> const dirs = VectorizeString(Path.substr(Parent.size()), '/');
304 string progress = Parent;
305 for (vector<string>::const_iterator d = dirs.begin(); d != dirs.end(); ++d)
306 {
307 if (d->empty() == true)
308 continue;
309
310 progress.append("/").append(*d);
311 if (DirectoryExists(progress) == true)
312 continue;
313
314 if (mkdir(progress.c_str(), 0755) != 0)
315 return false;
316 }
317 return true;
318}
319 /*}}}*/
7753e468 320// CreateAPTDirectoryIfNeeded - ensure that the given directory exists /*{{{*/
b29c3712
DK
321// ---------------------------------------------------------------------
322/* a small wrapper around CreateDirectory to check if it exists and to
323 remove the trailing "/apt/" from the parent directory if needed */
7753e468 324bool CreateAPTDirectoryIfNeeded(string const &Parent, string const &Path)
b29c3712
DK
325{
326 if (DirectoryExists(Path) == true)
327 return true;
328
329 size_t const len = Parent.size();
330 if (len > 5 && Parent.find("/apt/", len - 6, 5) == len - 5)
331 {
332 if (CreateDirectory(Parent.substr(0,len-5), Path) == true)
333 return true;
334 }
335 else if (CreateDirectory(Parent, Path) == true)
336 return true;
337
338 return false;
339}
340 /*}}}*/
46e39c8e
MV
341// GetListOfFilesInDir - returns a vector of files in the given dir /*{{{*/
342// ---------------------------------------------------------------------
343/* If an extension is given only files with this extension are included
344 in the returned vector, otherwise every "normal" file is included. */
b39c1859
MV
345std::vector<string> GetListOfFilesInDir(string const &Dir, string const &Ext,
346 bool const &SortList, bool const &AllowNoExt)
347{
348 std::vector<string> ext;
349 ext.reserve(2);
350 if (Ext.empty() == false)
351 ext.push_back(Ext);
352 if (AllowNoExt == true && ext.empty() == false)
353 ext.push_back("");
354 return GetListOfFilesInDir(Dir, ext, SortList);
355}
356std::vector<string> GetListOfFilesInDir(string const &Dir, std::vector<string> const &Ext,
357 bool const &SortList)
358{
359 // Attention debuggers: need to be set with the environment config file!
360 bool const Debug = _config->FindB("Debug::GetListOfFilesInDir", false);
361 if (Debug == true)
362 {
363 std::clog << "Accept in " << Dir << " only files with the following " << Ext.size() << " extensions:" << std::endl;
364 if (Ext.empty() == true)
365 std::clog << "\tNO extension" << std::endl;
366 else
367 for (std::vector<string>::const_iterator e = Ext.begin();
368 e != Ext.end(); ++e)
369 std::clog << '\t' << (e->empty() == true ? "NO" : *e) << " extension" << std::endl;
370 }
371
46e39c8e 372 std::vector<string> List;
36f1098a 373
69c2ecbd 374 if (DirectoryExists(Dir) == false)
36f1098a
DK
375 {
376 _error->Error(_("List of files can't be created as '%s' is not a directory"), Dir.c_str());
377 return List;
378 }
379
1408e219 380 Configuration::MatchAgainstConfig SilentIgnore("Dir::Ignore-Files-Silently");
46e39c8e
MV
381 DIR *D = opendir(Dir.c_str());
382 if (D == 0)
383 {
384 _error->Errno("opendir",_("Unable to read %s"),Dir.c_str());
385 return List;
386 }
387
388 for (struct dirent *Ent = readdir(D); Ent != 0; Ent = readdir(D))
389 {
b39c1859 390 // skip "hidden" files
46e39c8e
MV
391 if (Ent->d_name[0] == '.')
392 continue;
393
491058e3
DK
394 // Make sure it is a file and not something else
395 string const File = flCombine(Dir,Ent->d_name);
396#ifdef _DIRENT_HAVE_D_TYPE
397 if (Ent->d_type != DT_REG)
398#endif
399 {
69c2ecbd 400 if (RealFileExists(File) == false)
491058e3 401 {
84e254d6
DK
402 // do not show ignoration warnings for directories
403 if (
404#ifdef _DIRENT_HAVE_D_TYPE
405 Ent->d_type == DT_DIR ||
406#endif
69c2ecbd 407 DirectoryExists(File) == true)
84e254d6 408 continue;
491058e3
DK
409 if (SilentIgnore.Match(Ent->d_name) == false)
410 _error->Notice(_("Ignoring '%s' in directory '%s' as it is not a regular file"), Ent->d_name, Dir.c_str());
411 continue;
412 }
413 }
414
b39c1859
MV
415 // check for accepted extension:
416 // no extension given -> periods are bad as hell!
417 // extensions given -> "" extension allows no extension
418 if (Ext.empty() == false)
419 {
420 string d_ext = flExtension(Ent->d_name);
421 if (d_ext == Ent->d_name) // no extension
422 {
423 if (std::find(Ext.begin(), Ext.end(), "") == Ext.end())
424 {
425 if (Debug == true)
426 std::clog << "Bad file: " << Ent->d_name << " → no extension" << std::endl;
5edc3966 427 if (SilentIgnore.Match(Ent->d_name) == false)
491058e3 428 _error->Notice(_("Ignoring file '%s' in directory '%s' as it has no filename extension"), Ent->d_name, Dir.c_str());
b39c1859
MV
429 continue;
430 }
431 }
432 else if (std::find(Ext.begin(), Ext.end(), d_ext) == Ext.end())
433 {
434 if (Debug == true)
435 std::clog << "Bad file: " << Ent->d_name << " → bad extension »" << flExtension(Ent->d_name) << "«" << std::endl;
1408e219 436 if (SilentIgnore.Match(Ent->d_name) == false)
491058e3 437 _error->Notice(_("Ignoring file '%s' in directory '%s' as it has an invalid filename extension"), Ent->d_name, Dir.c_str());
b39c1859
MV
438 continue;
439 }
440 }
46e39c8e 441
b39c1859 442 // Skip bad filenames ala run-parts
46e39c8e
MV
443 const char *C = Ent->d_name;
444 for (; *C != 0; ++C)
445 if (isalpha(*C) == 0 && isdigit(*C) == 0
9d39208a 446 && *C != '_' && *C != '-' && *C != ':') {
b39c1859
MV
447 // no required extension -> dot is a bad character
448 if (*C == '.' && Ext.empty() == false)
449 continue;
46e39c8e 450 break;
b39c1859 451 }
46e39c8e 452
b39c1859 453 // we don't reach the end of the name -> bad character included
46e39c8e 454 if (*C != 0)
b39c1859
MV
455 {
456 if (Debug == true)
457 std::clog << "Bad file: " << Ent->d_name << " → bad character »"
458 << *C << "« in filename (period allowed: " << (Ext.empty() ? "no" : "yes") << ")" << std::endl;
459 continue;
460 }
461
fbb2c7e0
DK
462 // skip filenames which end with a period. These are never valid
463 if (*(C - 1) == '.')
464 {
465 if (Debug == true)
466 std::clog << "Bad file: " << Ent->d_name << " → Period as last character" << std::endl;
467 continue;
468 }
469
470 if (Debug == true)
471 std::clog << "Accept file: " << Ent->d_name << " in " << Dir << std::endl;
472 List.push_back(File);
473 }
474 closedir(D);
475
476 if (SortList == true)
477 std::sort(List.begin(),List.end());
478 return List;
479}
480std::vector<string> GetListOfFilesInDir(string const &Dir, bool SortList)
481{
482 bool const Debug = _config->FindB("Debug::GetListOfFilesInDir", false);
483 if (Debug == true)
484 std::clog << "Accept in " << Dir << " all regular files" << std::endl;
485
486 std::vector<string> List;
487
69c2ecbd 488 if (DirectoryExists(Dir) == false)
fbb2c7e0
DK
489 {
490 _error->Error(_("List of files can't be created as '%s' is not a directory"), Dir.c_str());
491 return List;
492 }
493
494 DIR *D = opendir(Dir.c_str());
495 if (D == 0)
496 {
497 _error->Errno("opendir",_("Unable to read %s"),Dir.c_str());
498 return List;
499 }
500
501 for (struct dirent *Ent = readdir(D); Ent != 0; Ent = readdir(D))
502 {
503 // skip "hidden" files
504 if (Ent->d_name[0] == '.')
505 continue;
506
507 // Make sure it is a file and not something else
508 string const File = flCombine(Dir,Ent->d_name);
509#ifdef _DIRENT_HAVE_D_TYPE
510 if (Ent->d_type != DT_REG)
511#endif
512 {
69c2ecbd 513 if (RealFileExists(File) == false)
fbb2c7e0
DK
514 {
515 if (Debug == true)
516 std::clog << "Bad file: " << Ent->d_name << " → it is not a real file" << std::endl;
517 continue;
518 }
519 }
520
521 // Skip bad filenames ala run-parts
522 const char *C = Ent->d_name;
523 for (; *C != 0; ++C)
524 if (isalpha(*C) == 0 && isdigit(*C) == 0
525 && *C != '_' && *C != '-' && *C != '.')
526 break;
527
528 // we don't reach the end of the name -> bad character included
529 if (*C != 0)
530 {
531 if (Debug == true)
532 std::clog << "Bad file: " << Ent->d_name << " → bad character »" << *C << "« in filename" << std::endl;
533 continue;
534 }
535
b39c1859
MV
536 // skip filenames which end with a period. These are never valid
537 if (*(C - 1) == '.')
538 {
539 if (Debug == true)
540 std::clog << "Bad file: " << Ent->d_name << " → Period as last character" << std::endl;
46e39c8e 541 continue;
b39c1859 542 }
46e39c8e 543
b39c1859
MV
544 if (Debug == true)
545 std::clog << "Accept file: " << Ent->d_name << " in " << Dir << std::endl;
46e39c8e
MV
546 List.push_back(File);
547 }
548 closedir(D);
549
550 if (SortList == true)
551 std::sort(List.begin(),List.end());
552 return List;
553}
554 /*}}}*/
578bfd0a
AL
555// SafeGetCWD - This is a safer getcwd that returns a dynamic string /*{{{*/
556// ---------------------------------------------------------------------
557/* We return / on failure. */
558string SafeGetCWD()
559{
560 // Stash the current dir.
561 char S[300];
562 S[0] = 0;
7f25bdff 563 if (getcwd(S,sizeof(S)-2) == 0)
578bfd0a 564 return "/";
7f25bdff
AL
565 unsigned int Len = strlen(S);
566 S[Len] = '/';
567 S[Len+1] = 0;
578bfd0a
AL
568 return S;
569}
570 /*}}}*/
2ec858bc
MV
571// GetModificationTime - Get the mtime of the given file or -1 on error /*{{{*/
572// ---------------------------------------------------------------------
573/* We return / on failure. */
574time_t GetModificationTime(string const &Path)
575{
576 struct stat St;
577 if (stat(Path.c_str(), &St) < 0)
578 return -1;
579 return St.st_mtime;
580}
581 /*}}}*/
8ce4327b
AL
582// flNotDir - Strip the directory from the filename /*{{{*/
583// ---------------------------------------------------------------------
584/* */
585string flNotDir(string File)
586{
587 string::size_type Res = File.rfind('/');
588 if (Res == string::npos)
589 return File;
590 Res++;
591 return string(File,Res,Res - File.length());
592}
593 /*}}}*/
d38b7b3d
AL
594// flNotFile - Strip the file from the directory name /*{{{*/
595// ---------------------------------------------------------------------
171c45bc 596/* Result ends in a / */
d38b7b3d
AL
597string flNotFile(string File)
598{
599 string::size_type Res = File.rfind('/');
600 if (Res == string::npos)
171c45bc 601 return "./";
d38b7b3d
AL
602 Res++;
603 return string(File,0,Res);
604}
605 /*}}}*/
b2e465d6
AL
606// flExtension - Return the extension for the file /*{{{*/
607// ---------------------------------------------------------------------
608/* */
609string flExtension(string File)
610{
611 string::size_type Res = File.rfind('.');
612 if (Res == string::npos)
613 return File;
614 Res++;
615 return string(File,Res,Res - File.length());
616}
617 /*}}}*/
421c8d10
AL
618// flNoLink - If file is a symlink then deref it /*{{{*/
619// ---------------------------------------------------------------------
620/* If the name is not a link then the returned path is the input. */
621string flNoLink(string File)
622{
623 struct stat St;
624 if (lstat(File.c_str(),&St) != 0 || S_ISLNK(St.st_mode) == 0)
625 return File;
626 if (stat(File.c_str(),&St) != 0)
627 return File;
628
629 /* Loop resolving the link. There is no need to limit the number of
630 loops because the stat call above ensures that the symlink is not
631 circular */
632 char Buffer[1024];
633 string NFile = File;
634 while (1)
635 {
636 // Read the link
3286ad13 637 ssize_t Res;
421c8d10 638 if ((Res = readlink(NFile.c_str(),Buffer,sizeof(Buffer))) <= 0 ||
3286ad13 639 (size_t)Res >= sizeof(Buffer))
421c8d10
AL
640 return File;
641
642 // Append or replace the previous path
643 Buffer[Res] = 0;
644 if (Buffer[0] == '/')
645 NFile = Buffer;
646 else
647 NFile = flNotFile(NFile) + Buffer;
648
649 // See if we are done
650 if (lstat(NFile.c_str(),&St) != 0)
651 return File;
652 if (S_ISLNK(St.st_mode) == 0)
653 return NFile;
654 }
655}
656 /*}}}*/
b2e465d6
AL
657// flCombine - Combine a file and a directory /*{{{*/
658// ---------------------------------------------------------------------
659/* If the file is an absolute path then it is just returned, otherwise
660 the directory is pre-pended to it. */
661string flCombine(string Dir,string File)
662{
663 if (File.empty() == true)
664 return string();
665
666 if (File[0] == '/' || Dir.empty() == true)
667 return File;
668 if (File.length() >= 2 && File[0] == '.' && File[1] == '/')
669 return File;
670 if (Dir[Dir.length()-1] == '/')
671 return Dir + File;
672 return Dir + '/' + File;
673}
674 /*}}}*/
53ac87ac
MV
675// flAbsPath - Return the absolute path of the filename /*{{{*/
676// ---------------------------------------------------------------------
677/* */
678string flAbsPath(string File)
679{
680 char *p = realpath(File.c_str(), NULL);
681 if (p == NULL)
682 {
95278287 683 _error->Errno("realpath", "flAbsPath on %s failed", File.c_str());
53ac87ac
MV
684 return "";
685 }
686 std::string AbsPath(p);
687 free(p);
688 return AbsPath;
689}
690 /*}}}*/
3b5421b4
AL
691// SetCloseExec - Set the close on exec flag /*{{{*/
692// ---------------------------------------------------------------------
693/* */
694void SetCloseExec(int Fd,bool Close)
695{
696 if (fcntl(Fd,F_SETFD,(Close == false)?0:FD_CLOEXEC) != 0)
697 {
698 cerr << "FATAL -> Could not set close on exec " << strerror(errno) << endl;
699 exit(100);
700 }
701}
702 /*}}}*/
703// SetNonBlock - Set the nonblocking flag /*{{{*/
704// ---------------------------------------------------------------------
705/* */
706void SetNonBlock(int Fd,bool Block)
707{
0a8a80e5
AL
708 int Flags = fcntl(Fd,F_GETFL) & (~O_NONBLOCK);
709 if (fcntl(Fd,F_SETFL,Flags | ((Block == false)?0:O_NONBLOCK)) != 0)
3b5421b4
AL
710 {
711 cerr << "FATAL -> Could not set non-blocking flag " << strerror(errno) << endl;
712 exit(100);
713 }
714}
715 /*}}}*/
716// WaitFd - Wait for a FD to become readable /*{{{*/
717// ---------------------------------------------------------------------
b2e465d6 718/* This waits for a FD to become readable using select. It is useful for
6d5dd02a
AL
719 applications making use of non-blocking sockets. The timeout is
720 in seconds. */
1084d58a 721bool WaitFd(int Fd,bool write,unsigned long timeout)
3b5421b4
AL
722{
723 fd_set Set;
cc2313b7 724 struct timeval tv;
3b5421b4
AL
725 FD_ZERO(&Set);
726 FD_SET(Fd,&Set);
6d5dd02a
AL
727 tv.tv_sec = timeout;
728 tv.tv_usec = 0;
1084d58a 729 if (write == true)
b0db36b1
AL
730 {
731 int Res;
732 do
733 {
734 Res = select(Fd+1,0,&Set,0,(timeout != 0?&tv:0));
735 }
736 while (Res < 0 && errno == EINTR);
737
738 if (Res <= 0)
739 return false;
1084d58a
AL
740 }
741 else
742 {
b0db36b1
AL
743 int Res;
744 do
745 {
746 Res = select(Fd+1,&Set,0,0,(timeout != 0?&tv:0));
747 }
748 while (Res < 0 && errno == EINTR);
749
750 if (Res <= 0)
751 return false;
cc2313b7 752 }
1084d58a 753
3b5421b4
AL
754 return true;
755}
756 /*}}}*/
96ae6de5 757// MergeKeepFdsFromConfiguration - Merge APT::Keep-Fds configuration /*{{{*/
54676e1a 758// ---------------------------------------------------------------------
96ae6de5
MV
759/* This is used to merge the APT::Keep-Fds with the provided KeepFDs
760 * set.
761 */
762void MergeKeepFdsFromConfiguration(std::set<int> &KeepFDs)
e45c4617 763{
e45c4617
MV
764 Configuration::Item const *Opts = _config->Tree("APT::Keep-Fds");
765 if (Opts != 0 && Opts->Child != 0)
766 {
767 Opts = Opts->Child;
768 for (; Opts != 0; Opts = Opts->Next)
769 {
770 if (Opts->Value.empty() == true)
771 continue;
772 int fd = atoi(Opts->Value.c_str());
773 KeepFDs.insert(fd);
774 }
775 }
96ae6de5
MV
776}
777 /*}}}*/
54676e1a
AL
778// ExecFork - Magical fork that sanitizes the context before execing /*{{{*/
779// ---------------------------------------------------------------------
780/* This is used if you want to cleanse the environment for the forked
781 child, it fixes up the important signals and nukes all of the fds,
782 otherwise acts like normal fork. */
75ef8f14 783pid_t ExecFork()
96ae6de5
MV
784{
785 set<int> KeepFDs;
786 // we need to merge the Keep-Fds as external tools like
787 // debconf-apt-progress use it
788 MergeKeepFdsFromConfiguration(KeepFDs);
e45c4617
MV
789 return ExecFork(KeepFDs);
790}
791
792pid_t ExecFork(std::set<int> KeepFDs)
54676e1a
AL
793{
794 // Fork off the process
795 pid_t Process = fork();
796 if (Process < 0)
797 {
798 cerr << "FATAL -> Failed to fork." << endl;
799 exit(100);
800 }
801
802 // Spawn the subprocess
803 if (Process == 0)
804 {
805 // Setup the signals
806 signal(SIGPIPE,SIG_DFL);
807 signal(SIGQUIT,SIG_DFL);
808 signal(SIGINT,SIG_DFL);
809 signal(SIGWINCH,SIG_DFL);
810 signal(SIGCONT,SIG_DFL);
811 signal(SIGTSTP,SIG_DFL);
75ef8f14 812
be4d908f
JAK
813 DIR *dir = opendir("/proc/self/fd");
814 if (dir != NULL)
75ef8f14 815 {
be4d908f
JAK
816 struct dirent *ent;
817 while ((ent = readdir(dir)))
818 {
819 int fd = atoi(ent->d_name);
820 // If fd > 0, it was a fd number and not . or ..
821 if (fd >= 3 && KeepFDs.find(fd) == KeepFDs.end())
822 fcntl(fd,F_SETFD,FD_CLOEXEC);
823 }
824 closedir(dir);
825 } else {
826 long ScOpenMax = sysconf(_SC_OPEN_MAX);
827 // Close all of our FDs - just in case
828 for (int K = 3; K != ScOpenMax; K++)
829 {
830 if(KeepFDs.find(K) == KeepFDs.end())
831 fcntl(K,F_SETFD,FD_CLOEXEC);
832 }
75ef8f14 833 }
54676e1a
AL
834 }
835
836 return Process;
837}
838 /*}}}*/
ddc1d8d0
AL
839// ExecWait - Fancy waitpid /*{{{*/
840// ---------------------------------------------------------------------
2c9a72d1 841/* Waits for the given sub process. If Reap is set then no errors are
ddc1d8d0
AL
842 generated. Otherwise a failed subprocess will generate a proper descriptive
843 message */
3826564e 844bool ExecWait(pid_t Pid,const char *Name,bool Reap)
ddc1d8d0
AL
845{
846 if (Pid <= 1)
847 return true;
848
849 // Wait and collect the error code
850 int Status;
851 while (waitpid(Pid,&Status,0) != Pid)
852 {
853 if (errno == EINTR)
854 continue;
855
856 if (Reap == true)
857 return false;
858
db0db9fe 859 return _error->Error(_("Waited for %s but it wasn't there"),Name);
ddc1d8d0
AL
860 }
861
862
863 // Check for an error code.
864 if (WIFEXITED(Status) == 0 || WEXITSTATUS(Status) != 0)
865 {
866 if (Reap == true)
867 return false;
ab7f4d7c 868 if (WIFSIGNALED(Status) != 0)
40e7fe0e 869 {
ab7f4d7c
MV
870 if( WTERMSIG(Status) == SIGSEGV)
871 return _error->Error(_("Sub-process %s received a segmentation fault."),Name);
872 else
873 return _error->Error(_("Sub-process %s received signal %u."),Name, WTERMSIG(Status));
40e7fe0e 874 }
ddc1d8d0
AL
875
876 if (WIFEXITED(Status) != 0)
b2e465d6 877 return _error->Error(_("Sub-process %s returned an error code (%u)"),Name,WEXITSTATUS(Status));
ddc1d8d0 878
b2e465d6 879 return _error->Error(_("Sub-process %s exited unexpectedly"),Name);
ddc1d8d0
AL
880 }
881
882 return true;
883}
884 /*}}}*/
f8aba23f 885// StartsWithGPGClearTextSignature - Check if a file is Pgp/GPG clearsigned /*{{{*/
fe5804fc 886bool StartsWithGPGClearTextSignature(string const &FileName)
0854ad8b
MV
887{
888 static const char* SIGMSG = "-----BEGIN PGP SIGNED MESSAGE-----\n";
1c89c98a 889 char buffer[strlen(SIGMSG)+1];
0854ad8b
MV
890 FILE* gpg = fopen(FileName.c_str(), "r");
891 if (gpg == NULL)
892 return false;
893
894 char const * const test = fgets(buffer, sizeof(buffer), gpg);
895 fclose(gpg);
896 if (test == NULL || strcmp(buffer, SIGMSG) != 0)
897 return false;
898
899 return true;
900}
f8aba23f 901 /*}}}*/
d84da499
DK
902// ChangeOwnerAndPermissionOfFile - set file attributes to requested values /*{{{*/
903bool ChangeOwnerAndPermissionOfFile(char const * const requester, char const * const file, char const * const user, char const * const group, mode_t const mode)
904{
905 if (strcmp(file, "/dev/null") == 0)
906 return true;
907 bool Res = true;
908 if (getuid() == 0 && strlen(user) != 0 && strlen(group) != 0) // if we aren't root, we can't chown, so don't try it
909 {
910 // ensure the file is owned by root and has good permissions
911 struct passwd const * const pw = getpwnam(user);
912 struct group const * const gr = getgrnam(group);
913 if (pw != NULL && gr != NULL && chown(file, pw->pw_uid, gr->gr_gid) != 0)
914 Res &= _error->WarningE(requester, "chown to %s:%s of file %s failed", user, group, file);
915 }
916 if (chmod(file, mode) != 0)
917 Res &= _error->WarningE(requester, "chmod 0%o of file %s failed", mode, file);
918 return Res;
919}
920 /*}}}*/
0854ad8b 921
4239dbca
DK
922class FileFdPrivate { /*{{{*/
923 public:
924#ifdef HAVE_ZLIB
925 gzFile gz;
926#endif
927#ifdef HAVE_BZ2
928 BZFILE* bz2;
929#endif
930#ifdef HAVE_LZMA
931 struct LZMAFILE {
932 FILE* file;
933 uint8_t buffer[4096];
934 lzma_stream stream;
935 lzma_ret err;
936 bool eof;
937 bool compressing;
938
25613a61 939 LZMAFILE() : file(NULL), eof(false), compressing(false) { buffer[0] = '\0'; }
4239dbca
DK
940 ~LZMAFILE() {
941 if (compressing == true)
942 {
943 for (;;) {
944 stream.avail_out = sizeof(buffer)/sizeof(buffer[0]);
945 stream.next_out = buffer;
946 err = lzma_code(&stream, LZMA_FINISH);
947 if (err != LZMA_OK && err != LZMA_STREAM_END)
948 {
949 _error->Error("~LZMAFILE: Compress finalisation failed");
950 break;
951 }
952 size_t const n = sizeof(buffer)/sizeof(buffer[0]) - stream.avail_out;
953 if (n && fwrite(buffer, 1, n, file) != n)
954 {
955 _error->Errno("~LZMAFILE",_("Write error"));
956 break;
957 }
958 if (err == LZMA_STREAM_END)
959 break;
960 }
961 }
962 lzma_end(&stream);
963 fclose(file);
964 }
965 };
966 LZMAFILE* lzma;
967#endif
968 int compressed_fd;
969 pid_t compressor_pid;
970 bool pipe;
971 APT::Configuration::Compressor compressor;
972 unsigned int openmode;
973 unsigned long long seekpos;
974 FileFdPrivate() :
975#ifdef HAVE_ZLIB
976 gz(NULL),
977#endif
978#ifdef HAVE_BZ2
979 bz2(NULL),
980#endif
981#ifdef HAVE_LZMA
982 lzma(NULL),
983#endif
984 compressed_fd(-1), compressor_pid(-1), pipe(false),
985 openmode(0), seekpos(0) {};
986 bool InternalClose(std::string const &FileName)
987 {
988 if (false)
989 /* dummy so that the rest can be 'else if's */;
990#ifdef HAVE_ZLIB
991 else if (gz != NULL) {
992 int const e = gzclose(gz);
993 gz = NULL;
994 // gzdclose() on empty files always fails with "buffer error" here, ignore that
995 if (e != 0 && e != Z_BUF_ERROR)
996 return _error->Errno("close",_("Problem closing the gzip file %s"), FileName.c_str());
997 }
998#endif
999#ifdef HAVE_BZ2
1000 else if (bz2 != NULL) {
1001 BZ2_bzclose(bz2);
1002 bz2 = NULL;
1003 }
1004#endif
1005#ifdef HAVE_LZMA
1006 else if (lzma != NULL) {
1007 delete lzma;
1008 lzma = NULL;
1009 }
1010#endif
1011 return true;
1012 }
1013 bool CloseDown(std::string const &FileName)
1014 {
1015 bool const Res = InternalClose(FileName);
1016
1017 if (compressor_pid > 0)
1018 ExecWait(compressor_pid, "FileFdCompressor", true);
1019 compressor_pid = -1;
1020
1021 return Res;
1022 }
1023 bool InternalStream() const {
1024 return false
1025#ifdef HAVE_BZ2
1026 || bz2 != NULL
1027#endif
1028#ifdef HAVE_LZMA
1029 || lzma != NULL
1030#endif
1031 ;
1032 }
1033
1034
1035 ~FileFdPrivate() { CloseDown(""); }
1036};
1037 /*}}}*/
6c55f07a
DK
1038// FileFd Constructors /*{{{*/
1039FileFd::FileFd(std::string FileName,unsigned int const Mode,unsigned long AccessMode) : iFd(-1), Flags(0), d(NULL)
1040{
1041 Open(FileName,Mode, None, AccessMode);
1042}
1043FileFd::FileFd(std::string FileName,unsigned int const Mode, CompressMode Compress, unsigned long AccessMode) : iFd(-1), Flags(0), d(NULL)
1044{
1045 Open(FileName,Mode, Compress, AccessMode);
1046}
1047FileFd::FileFd() : iFd(-1), Flags(AutoClose), d(NULL) {}
1048FileFd::FileFd(int const Fd, unsigned int const Mode, CompressMode Compress) : iFd(-1), Flags(0), d(NULL)
1049{
1050 OpenDescriptor(Fd, Mode, Compress);
1051}
1052FileFd::FileFd(int const Fd, bool const AutoClose) : iFd(-1), Flags(0), d(NULL)
1053{
1054 OpenDescriptor(Fd, ReadWrite, None, AutoClose);
1055}
1056 /*}}}*/
13d87e2e 1057// FileFd::Open - Open a file /*{{{*/
578bfd0a
AL
1058// ---------------------------------------------------------------------
1059/* The most commonly used open mode combinations are given with Mode */
e5f3f8c1 1060bool FileFd::Open(string FileName,unsigned int const Mode,CompressMode Compress, unsigned long const AccessMode)
578bfd0a 1061{
257e8d66 1062 if (Mode == ReadOnlyGzip)
e5f3f8c1 1063 return Open(FileName, ReadOnly, Gzip, AccessMode);
257e8d66 1064
468720c5 1065 if (Compress == Auto && (Mode & WriteOnly) == WriteOnly)
ae635e3c 1066 return FileFdError("Autodetection on %s only works in ReadOnly openmode!", FileName.c_str());
257e8d66 1067
468720c5
DK
1068 std::vector<APT::Configuration::Compressor> const compressors = APT::Configuration::getCompressors();
1069 std::vector<APT::Configuration::Compressor>::const_iterator compressor = compressors.begin();
1070 if (Compress == Auto)
1071 {
468720c5
DK
1072 for (; compressor != compressors.end(); ++compressor)
1073 {
e788a834 1074 std::string file = FileName + compressor->Extension;
468720c5
DK
1075 if (FileExists(file) == false)
1076 continue;
1077 FileName = file;
468720c5
DK
1078 break;
1079 }
1080 }
1081 else if (Compress == Extension)
1082 {
52b47296
DK
1083 std::string::size_type const found = FileName.find_last_of('.');
1084 std::string ext;
1085 if (found != std::string::npos)
1086 {
1087 ext = FileName.substr(found);
1088 if (ext == ".new" || ext == ".bak")
1089 {
1090 std::string::size_type const found2 = FileName.find_last_of('.', found - 1);
1091 if (found2 != std::string::npos)
1092 ext = FileName.substr(found2, found - found2);
1093 else
1094 ext.clear();
1095 }
1096 }
aee1aac6
DK
1097 for (; compressor != compressors.end(); ++compressor)
1098 if (ext == compressor->Extension)
1099 break;
1100 // no matching extension - assume uncompressed (imagine files like 'example.org_Packages')
1101 if (compressor == compressors.end())
1102 for (compressor = compressors.begin(); compressor != compressors.end(); ++compressor)
1103 if (compressor->Name == ".")
468720c5 1104 break;
468720c5 1105 }
aee1aac6 1106 else
468720c5
DK
1107 {
1108 std::string name;
1109 switch (Compress)
1110 {
aee1aac6 1111 case None: name = "."; break;
468720c5
DK
1112 case Gzip: name = "gzip"; break;
1113 case Bzip2: name = "bzip2"; break;
1114 case Lzma: name = "lzma"; break;
1115 case Xz: name = "xz"; break;
aee1aac6
DK
1116 case Auto:
1117 case Extension:
52b47296 1118 // Unreachable
ae635e3c 1119 return FileFdError("Opening File %s in None, Auto or Extension should be already handled?!?", FileName.c_str());
468720c5
DK
1120 }
1121 for (; compressor != compressors.end(); ++compressor)
1122 if (compressor->Name == name)
1123 break;
aee1aac6 1124 if (compressor == compressors.end())
ae635e3c 1125 return FileFdError("Can't find a configured compressor %s for file %s", name.c_str(), FileName.c_str());
468720c5
DK
1126 }
1127
aee1aac6 1128 if (compressor == compressors.end())
ae635e3c 1129 return FileFdError("Can't find a match for specified compressor mode for file %s", FileName.c_str());
e5f3f8c1 1130 return Open(FileName, Mode, *compressor, AccessMode);
aee1aac6 1131}
e5f3f8c1 1132bool FileFd::Open(string FileName,unsigned int const Mode,APT::Configuration::Compressor const &compressor, unsigned long const AccessMode)
aee1aac6
DK
1133{
1134 Close();
aee1aac6
DK
1135 Flags = AutoClose;
1136
1137 if ((Mode & WriteOnly) != WriteOnly && (Mode & (Atomic | Create | Empty | Exclusive)) != 0)
ae635e3c 1138 return FileFdError("ReadOnly mode for %s doesn't accept additional flags!", FileName.c_str());
aee1aac6 1139 if ((Mode & ReadWrite) == 0)
ae635e3c 1140 return FileFdError("No openmode provided in FileFd::Open for %s", FileName.c_str());
468720c5 1141
cd46d4eb
DK
1142 unsigned int OpenMode = Mode;
1143 if (FileName == "/dev/null")
1144 OpenMode = OpenMode & ~(Atomic | Exclusive | Create | Empty);
1145
1146 if ((OpenMode & Atomic) == Atomic)
257e8d66
DK
1147 {
1148 Flags |= Replace;
257e8d66 1149 }
cd46d4eb 1150 else if ((OpenMode & (Exclusive | Create)) == (Exclusive | Create))
257e8d66
DK
1151 {
1152 // for atomic, this will be done by rename in Close()
ce1f3a2c 1153 RemoveFile("FileFd::Open", FileName);
257e8d66 1154 }
cd46d4eb 1155 if ((OpenMode & Empty) == Empty)
578bfd0a 1156 {
257e8d66
DK
1157 struct stat Buf;
1158 if (lstat(FileName.c_str(),&Buf) == 0 && S_ISLNK(Buf.st_mode))
ce1f3a2c 1159 RemoveFile("FileFd::Open", FileName);
257e8d66 1160 }
c4fc2fd7 1161
561f860a 1162 int fileflags = 0;
cd46d4eb 1163 #define if_FLAGGED_SET(FLAG, MODE) if ((OpenMode & FLAG) == FLAG) fileflags |= MODE
561f860a
DK
1164 if_FLAGGED_SET(ReadWrite, O_RDWR);
1165 else if_FLAGGED_SET(ReadOnly, O_RDONLY);
1166 else if_FLAGGED_SET(WriteOnly, O_WRONLY);
4a9db827 1167
561f860a
DK
1168 if_FLAGGED_SET(Create, O_CREAT);
1169 if_FLAGGED_SET(Empty, O_TRUNC);
1170 if_FLAGGED_SET(Exclusive, O_EXCL);
561f860a 1171 #undef if_FLAGGED_SET
52b47296 1172
cd46d4eb 1173 if ((OpenMode & Atomic) == Atomic)
7335eebe
AGM
1174 {
1175 char *name = strdup((FileName + ".XXXXXX").c_str());
1176
dc545c0b 1177 if((iFd = mkstemp(name)) == -1)
7335eebe
AGM
1178 {
1179 free(name);
98b69f9d 1180 return FileFdErrno("mkstemp", "Could not create temporary file for %s", FileName.c_str());
7335eebe
AGM
1181 }
1182
1183 TemporaryFileName = string(name);
7335eebe 1184 free(name);
dc545c0b 1185
230e69d7
DK
1186 // umask() will always set the umask and return the previous value, so
1187 // we first set the umask and then reset it to the old value
1188 mode_t const CurrentUmask = umask(0);
1189 umask(CurrentUmask);
1190 // calculate the actual file permissions (just like open/creat)
1191 mode_t const FilePermissions = (AccessMode & ~CurrentUmask);
1192
1193 if(fchmod(iFd, FilePermissions) == -1)
dc545c0b 1194 return FileFdErrno("fchmod", "Could not change permissions for temporary file %s", TemporaryFileName.c_str());
7335eebe 1195 }
468720c5 1196 else
230e69d7 1197 iFd = open(FileName.c_str(), fileflags, AccessMode);
468720c5 1198
b711c01e 1199 this->FileName = FileName;
cd46d4eb 1200 if (iFd == -1 || OpenInternDescriptor(OpenMode, compressor) == false)
561f860a 1201 {
468720c5 1202 if (iFd != -1)
fc81e8f2 1203 {
561f860a
DK
1204 close (iFd);
1205 iFd = -1;
fc81e8f2 1206 }
ae635e3c 1207 return FileFdErrno("open",_("Could not open file %s"), FileName.c_str());
257e8d66 1208 }
578bfd0a 1209
13d87e2e
AL
1210 SetCloseExec(iFd,true);
1211 return true;
578bfd0a 1212}
257e8d66
DK
1213 /*}}}*/
1214// FileFd::OpenDescriptor - Open a filedescriptor /*{{{*/
1215// ---------------------------------------------------------------------
1216/* */
52b47296 1217bool FileFd::OpenDescriptor(int Fd, unsigned int const Mode, CompressMode Compress, bool AutoClose)
aee1aac6
DK
1218{
1219 std::vector<APT::Configuration::Compressor> const compressors = APT::Configuration::getCompressors();
1220 std::vector<APT::Configuration::Compressor>::const_iterator compressor = compressors.begin();
1221 std::string name;
bce778a3
MV
1222
1223 // compat with the old API
1224 if (Mode == ReadOnlyGzip && Compress == None)
1225 Compress = Gzip;
1226
aee1aac6
DK
1227 switch (Compress)
1228 {
1229 case None: name = "."; break;
1230 case Gzip: name = "gzip"; break;
1231 case Bzip2: name = "bzip2"; break;
1232 case Lzma: name = "lzma"; break;
1233 case Xz: name = "xz"; break;
1234 case Auto:
1235 case Extension:
f97bb523
DK
1236 if (AutoClose == true && Fd != -1)
1237 close(Fd);
ae635e3c 1238 return FileFdError("Opening Fd %d in Auto or Extension compression mode is not supported", Fd);
aee1aac6
DK
1239 }
1240 for (; compressor != compressors.end(); ++compressor)
1241 if (compressor->Name == name)
1242 break;
1243 if (compressor == compressors.end())
f97bb523
DK
1244 {
1245 if (AutoClose == true && Fd != -1)
1246 close(Fd);
ae635e3c 1247 return FileFdError("Can't find a configured compressor %s for file %s", name.c_str(), FileName.c_str());
f97bb523 1248 }
aee1aac6
DK
1249 return OpenDescriptor(Fd, Mode, *compressor, AutoClose);
1250}
52b47296 1251bool FileFd::OpenDescriptor(int Fd, unsigned int const Mode, APT::Configuration::Compressor const &compressor, bool AutoClose)
144c0969
JAK
1252{
1253 Close();
1254 Flags = (AutoClose) ? FileFd::AutoClose : 0;
84baaae9 1255 iFd = Fd;
b711c01e 1256 this->FileName = "";
84baaae9 1257 if (OpenInternDescriptor(Mode, compressor) == false)
468720c5 1258 {
f97bb523 1259 if (iFd != -1 && (
84baaae9 1260 (Flags & Compressed) == Compressed ||
f97bb523
DK
1261 AutoClose == true))
1262 {
468720c5 1263 close (iFd);
f97bb523
DK
1264 iFd = -1;
1265 }
1266 return FileFdError(_("Could not open file descriptor %d"), Fd);
144c0969 1267 }
144c0969 1268 return true;
468720c5 1269}
52b47296 1270bool FileFd::OpenInternDescriptor(unsigned int const Mode, APT::Configuration::Compressor const &compressor)
468720c5 1271{
84baaae9
DK
1272 if (iFd == -1)
1273 return false;
ff477ee1
DK
1274 if (compressor.Name == "." || compressor.Binary.empty() == true)
1275 return true;
1276
7f350a37 1277#if defined HAVE_ZLIB || defined HAVE_BZ2 || defined HAVE_LZMA
69d6988a
DK
1278 // the API to open files is similar, so setup to avoid code duplicates later
1279 // and while at it ensure that we close before opening (if its a reopen)
1280 void* (*compress_open)(int, const char *) = NULL;
7f350a37
DK
1281 if (false)
1282 /* dummy so that the rest can be 'else if's */;
4239dbca 1283#define APT_COMPRESS_INIT(NAME,OPEN) \
7f350a37 1284 else if (compressor.Name == NAME) \
69d6988a
DK
1285 { \
1286 compress_open = (void*(*)(int, const char *)) OPEN; \
4239dbca 1287 if (d != NULL) d->InternalClose(FileName); \
69d6988a
DK
1288 }
1289#ifdef HAVE_ZLIB
4239dbca 1290 APT_COMPRESS_INIT("gzip", gzdopen)
69d6988a
DK
1291#endif
1292#ifdef HAVE_BZ2
4239dbca 1293 APT_COMPRESS_INIT("bzip2", BZ2_bzdopen)
69d6988a 1294#endif
7f350a37 1295#ifdef HAVE_LZMA
4239dbca
DK
1296 APT_COMPRESS_INIT("xz", fdopen)
1297 APT_COMPRESS_INIT("lzma", fdopen)
7f350a37 1298#endif
69d6988a
DK
1299#undef APT_COMPRESS_INIT
1300#endif
1301
ba667cf7
DK
1302 if (d == NULL)
1303 {
1304 d = new FileFdPrivate();
1305 d->openmode = Mode;
1306 d->compressor = compressor;
7f350a37 1307#if defined HAVE_ZLIB || defined HAVE_BZ2 || defined HAVE_LZMA
f6ffe501 1308 if ((Flags & AutoClose) != AutoClose && compress_open != NULL)
84baaae9
DK
1309 {
1310 // Need to duplicate fd here or gz/bz2 close for cleanup will close the fd as well
1311 int const internFd = dup(iFd);
1312 if (internFd == -1)
1313 return FileFdErrno("OpenInternDescriptor", _("Could not open file descriptor %d"), iFd);
1314 iFd = internFd;
1315 }
69d6988a 1316#endif
ba667cf7 1317 }
ff477ee1 1318
7f350a37 1319#if defined HAVE_ZLIB || defined HAVE_BZ2 || defined HAVE_LZMA
69d6988a 1320 if (compress_open != NULL)
468720c5 1321 {
69d6988a 1322 void* compress_struct = NULL;
468720c5 1323 if ((Mode & ReadWrite) == ReadWrite)
69d6988a 1324 compress_struct = compress_open(iFd, "r+");
468720c5 1325 else if ((Mode & WriteOnly) == WriteOnly)
69d6988a 1326 compress_struct = compress_open(iFd, "w");
468720c5 1327 else
69d6988a
DK
1328 compress_struct = compress_open(iFd, "r");
1329 if (compress_struct == NULL)
468720c5 1330 return false;
69d6988a 1331
7f350a37
DK
1332 if (false)
1333 /* dummy so that the rest can be 'else if's */;
69d6988a 1334#ifdef HAVE_ZLIB
7f350a37 1335 else if (compressor.Name == "gzip")
69d6988a 1336 d->gz = (gzFile) compress_struct;
699b209e 1337#endif
c4997486 1338#ifdef HAVE_BZ2
7f350a37 1339 else if (compressor.Name == "bzip2")
69d6988a 1340 d->bz2 = (BZFILE*) compress_struct;
7f350a37
DK
1341#endif
1342#ifdef HAVE_LZMA
1343 else if (compressor.Name == "xz" || compressor.Name == "lzma")
adbd7eb4 1344 {
7f350a37
DK
1345 uint32_t const xzlevel = 6;
1346 uint64_t const memlimit = UINT64_MAX;
1347 if (d->lzma == NULL)
1348 d->lzma = new FileFdPrivate::LZMAFILE;
1349 d->lzma->file = (FILE*) compress_struct;
21ea1dbb
MV
1350 lzma_stream tmp_stream = LZMA_STREAM_INIT;
1351 d->lzma->stream = tmp_stream;
7f350a37
DK
1352
1353 if ((Mode & ReadWrite) == ReadWrite)
1354 return FileFdError("ReadWrite mode is not supported for file %s", FileName.c_str());
1355
1356 if ((Mode & WriteOnly) == WriteOnly)
1357 {
1358 if (compressor.Name == "xz")
1359 {
1360 if (lzma_easy_encoder(&d->lzma->stream, xzlevel, LZMA_CHECK_CRC32) != LZMA_OK)
1361 return false;
1362 }
1363 else
1364 {
1365 lzma_options_lzma options;
1366 lzma_lzma_preset(&options, xzlevel);
1367 if (lzma_alone_encoder(&d->lzma->stream, &options) != LZMA_OK)
1368 return false;
1369 }
1370 d->lzma->compressing = true;
1371 }
1372 else
1373 {
1374 if (compressor.Name == "xz")
1375 {
1376 if (lzma_auto_decoder(&d->lzma->stream, memlimit, 0) != LZMA_OK)
1377 return false;
1378 }
1379 else
1380 {
1381 if (lzma_alone_decoder(&d->lzma->stream, memlimit) != LZMA_OK)
1382 return false;
1383 }
1384 d->lzma->compressing = false;
1385 }
adbd7eb4 1386 }
69d6988a 1387#endif
c4997486
DK
1388 Flags |= Compressed;
1389 return true;
1390 }
1391#endif
1392
adbd7eb4
DK
1393 // collect zombies here in case we reopen
1394 if (d->compressor_pid > 0)
1395 ExecWait(d->compressor_pid, "FileFdCompressor", true);
561f860a
DK
1396
1397 if ((Mode & ReadWrite) == ReadWrite)
ae635e3c 1398 return FileFdError("ReadWrite mode is not supported for file %s", FileName.c_str());
561f860a
DK
1399
1400 bool const Comp = (Mode & WriteOnly) == WriteOnly;
561f860a
DK
1401 if (Comp == false)
1402 {
adbd7eb4 1403 // Handle 'decompression' of empty files
561f860a
DK
1404 struct stat Buf;
1405 fstat(iFd, &Buf);
1406 if (Buf.st_size == 0 && S_ISFIFO(Buf.st_mode) == false)
1407 return true;
1408
1409 // We don't need the file open - instead let the compressor open it
1410 // as he properly knows better how to efficiently read from 'his' file
1411 if (FileName.empty() == false)
afb093cd 1412 {
561f860a 1413 close(iFd);
afb093cd
DK
1414 iFd = -1;
1415 }
561f860a
DK
1416 }
1417
1418 // Create a data pipe
1419 int Pipe[2] = {-1,-1};
1420 if (pipe(Pipe) != 0)
ae635e3c 1421 return FileFdErrno("pipe",_("Failed to create subprocess IPC"));
561f860a
DK
1422 for (int J = 0; J != 2; J++)
1423 SetCloseExec(Pipe[J],true);
1424
1425 d->compressed_fd = iFd;
1426 d->pipe = true;
1427
1428 if (Comp == true)
1429 iFd = Pipe[1];
1430 else
1431 iFd = Pipe[0];
1432
1433 // The child..
1434 d->compressor_pid = ExecFork();
1435 if (d->compressor_pid == 0)
1436 {
1437 if (Comp == true)
1438 {
1439 dup2(d->compressed_fd,STDOUT_FILENO);
1440 dup2(Pipe[0],STDIN_FILENO);
1441 }
1442 else
1443 {
7f350a37 1444 if (d->compressed_fd != -1)
561f860a
DK
1445 dup2(d->compressed_fd,STDIN_FILENO);
1446 dup2(Pipe[1],STDOUT_FILENO);
1447 }
0b4895d3
DK
1448 int const nullfd = open("/dev/null", O_WRONLY);
1449 if (nullfd != -1)
1450 {
1451 dup2(nullfd,STDERR_FILENO);
1452 close(nullfd);
1453 }
561f860a
DK
1454
1455 SetCloseExec(STDOUT_FILENO,false);
1456 SetCloseExec(STDIN_FILENO,false);
1457
1458 std::vector<char const*> Args;
1459 Args.push_back(compressor.Binary.c_str());
1460 std::vector<std::string> const * const addArgs =
1461 (Comp == true) ? &(compressor.CompressArgs) : &(compressor.UncompressArgs);
1462 for (std::vector<std::string>::const_iterator a = addArgs->begin();
1463 a != addArgs->end(); ++a)
1464 Args.push_back(a->c_str());
1465 if (Comp == false && FileName.empty() == false)
1466 {
bb93178b
DK
1467 // commands not needing arguments, do not need to be told about using standard output
1468 // in reality, only testcases with tools like cat, rev, rot13, … are able to trigger this
1469 if (compressor.CompressArgs.empty() == false && compressor.UncompressArgs.empty() == false)
1470 Args.push_back("--stdout");
561f860a
DK
1471 if (TemporaryFileName.empty() == false)
1472 Args.push_back(TemporaryFileName.c_str());
1473 else
1474 Args.push_back(FileName.c_str());
1475 }
1476 Args.push_back(NULL);
1477
1478 execvp(Args[0],(char **)&Args[0]);
1479 cerr << _("Failed to exec compressor ") << Args[0] << endl;
1480 _exit(100);
1481 }
1482 if (Comp == true)
1483 close(Pipe[0]);
468720c5 1484 else
561f860a 1485 close(Pipe[1]);
561f860a 1486
468720c5 1487 return true;
144c0969 1488}
578bfd0a 1489 /*}}}*/
8e06abb2 1490// FileFd::~File - Closes the file /*{{{*/
578bfd0a
AL
1491// ---------------------------------------------------------------------
1492/* If the proper modes are selected then we close the Fd and possibly
1493 unlink the file on error. */
8e06abb2 1494FileFd::~FileFd()
578bfd0a
AL
1495{
1496 Close();
500400fe 1497 if (d != NULL)
500400fe 1498 d->CloseDown(FileName);
96ab3c6f
MV
1499 delete d;
1500 d = NULL;
578bfd0a
AL
1501}
1502 /*}}}*/
8e06abb2 1503// FileFd::Read - Read a bit of the file /*{{{*/
578bfd0a 1504// ---------------------------------------------------------------------
1e3f4083 1505/* We are careful to handle interruption by a signal while reading
b0db36b1 1506 gracefully. */
650faab0 1507bool FileFd::Read(void *To,unsigned long long Size,unsigned long long *Actual)
578bfd0a 1508{
3286ad13 1509 ssize_t Res;
b0db36b1 1510 errno = 0;
f604cf55
AL
1511 if (Actual != 0)
1512 *Actual = 0;
699b209e 1513 *((char *)To) = '\0';
b0db36b1 1514 do
578bfd0a 1515 {
7f350a37
DK
1516 if (false)
1517 /* dummy so that the rest can be 'else if's */;
7efb8c8e 1518#ifdef HAVE_ZLIB
7f350a37 1519 else if (d != NULL && d->gz != NULL)
c4997486 1520 Res = gzread(d->gz,To,Size);
c4997486
DK
1521#endif
1522#ifdef HAVE_BZ2
7f350a37 1523 else if (d != NULL && d->bz2 != NULL)
c4997486 1524 Res = BZ2_bzread(d->bz2,To,Size);
699b209e 1525#endif
7f350a37
DK
1526#ifdef HAVE_LZMA
1527 else if (d != NULL && d->lzma != NULL)
1528 {
1529 if (d->lzma->eof == true)
1530 break;
1531
1532 d->lzma->stream.next_out = (uint8_t *) To;
1533 d->lzma->stream.avail_out = Size;
1534 if (d->lzma->stream.avail_in == 0)
1535 {
1536 d->lzma->stream.next_in = d->lzma->buffer;
1537 d->lzma->stream.avail_in = fread(d->lzma->buffer, 1, sizeof(d->lzma->buffer)/sizeof(d->lzma->buffer[0]), d->lzma->file);
1538 }
1539 d->lzma->err = lzma_code(&d->lzma->stream, LZMA_RUN);
1540 if (d->lzma->err == LZMA_STREAM_END)
1541 {
1542 d->lzma->eof = true;
1543 Res = Size - d->lzma->stream.avail_out;
1544 }
1545 else if (d->lzma->err != LZMA_OK)
1546 {
1547 Res = -1;
1548 errno = 0;
1549 }
1550 else
c4b113e6 1551 {
7f350a37 1552 Res = Size - d->lzma->stream.avail_out;
c4b113e6
DK
1553 if (Res == 0)
1554 {
1555 // lzma run was okay, but produced no output…
1556 Res = -1;
1557 errno = EINTR;
1558 }
1559 }
7f350a37
DK
1560 }
1561#endif
1562 else
a3a03f5d 1563 Res = read(iFd,To,Size);
b711c01e 1564
b0db36b1
AL
1565 if (Res < 0)
1566 {
b711c01e 1567 if (errno == EINTR)
c4b113e6
DK
1568 {
1569 // trick the while-loop into running again
1570 Res = 1;
1571 errno = 0;
b711c01e 1572 continue;
c4b113e6 1573 }
7f350a37
DK
1574 if (false)
1575 /* dummy so that the rest can be 'else if's */;
7efb8c8e 1576#ifdef HAVE_ZLIB
7f350a37 1577 else if (d != NULL && d->gz != NULL)
b711c01e
DK
1578 {
1579 int err;
1580 char const * const errmsg = gzerror(d->gz, &err);
1581 if (err != Z_ERRNO)
ae635e3c 1582 return FileFdError("gzread: %s (%d: %s)", _("Read error"), err, errmsg);
b711c01e 1583 }
c4997486
DK
1584#endif
1585#ifdef HAVE_BZ2
7f350a37 1586 else if (d != NULL && d->bz2 != NULL)
c4997486
DK
1587 {
1588 int err;
1589 char const * const errmsg = BZ2_bzerror(d->bz2, &err);
1590 if (err != BZ_IO_ERROR)
c36db2b5 1591 return FileFdError("BZ2_bzread: %s %s (%d: %s)", FileName.c_str(), _("Read error"), err, errmsg);
c4997486 1592 }
7f350a37
DK
1593#endif
1594#ifdef HAVE_LZMA
1595 else if (d != NULL && d->lzma != NULL)
1596 return FileFdError("lzma_read: %s (%d)", _("Read error"), d->lzma->err);
b711c01e 1597#endif
ae635e3c 1598 return FileFdErrno("read",_("Read error"));
b0db36b1 1599 }
578bfd0a 1600
b0db36b1
AL
1601 To = (char *)To + Res;
1602 Size -= Res;
ff477ee1
DK
1603 if (d != NULL)
1604 d->seekpos += Res;
f604cf55
AL
1605 if (Actual != 0)
1606 *Actual += Res;
b0db36b1
AL
1607 }
1608 while (Res > 0 && Size > 0);
1609
1610 if (Size == 0)
1611 return true;
1612
ddc1d8d0 1613 // Eof handling
f604cf55 1614 if (Actual != 0)
ddc1d8d0
AL
1615 {
1616 Flags |= HitEof;
1617 return true;
1618 }
ae635e3c
DK
1619
1620 return FileFdError(_("read, still have %llu to read but none left"), Size);
578bfd0a
AL
1621}
1622 /*}}}*/
032bd56f
DK
1623// FileFd::ReadLine - Read a complete line from the file /*{{{*/
1624// ---------------------------------------------------------------------
1625/* Beware: This method can be quiet slow for big buffers on UNcompressed
1626 files because of the naive implementation! */
1627char* FileFd::ReadLine(char *To, unsigned long long const Size)
1628{
699b209e 1629 *To = '\0';
7efb8c8e 1630#ifdef HAVE_ZLIB
ff477ee1 1631 if (d != NULL && d->gz != NULL)
032bd56f 1632 return gzgets(d->gz, To, Size);
699b209e 1633#endif
032bd56f
DK
1634
1635 unsigned long long read = 0;
40468850
DK
1636 while ((Size - 1) != read)
1637 {
1638 unsigned long long done = 0;
1639 if (Read(To + read, 1, &done) == false)
1640 return NULL;
1641 if (done == 0)
1642 break;
1643 if (To[read++] == '\n')
1644 break;
1645 }
1646 if (read == 0)
032bd56f 1647 return NULL;
40468850 1648 To[read] = '\0';
032bd56f
DK
1649 return To;
1650}
1651 /*}}}*/
8e06abb2 1652// FileFd::Write - Write to the file /*{{{*/
578bfd0a
AL
1653// ---------------------------------------------------------------------
1654/* */
650faab0 1655bool FileFd::Write(const void *From,unsigned long long Size)
578bfd0a 1656{
5df91bc7 1657 ssize_t Res = 1;
b0db36b1 1658 errno = 0;
5df91bc7 1659 while (Res > 0 && Size > 0)
578bfd0a 1660 {
7f350a37
DK
1661 if (false)
1662 /* dummy so that the rest can be 'else if's */;
7efb8c8e 1663#ifdef HAVE_ZLIB
7f350a37
DK
1664 else if (d != NULL && d->gz != NULL)
1665 Res = gzwrite(d->gz,From,Size);
c4997486
DK
1666#endif
1667#ifdef HAVE_BZ2
7f350a37
DK
1668 else if (d != NULL && d->bz2 != NULL)
1669 Res = BZ2_bzwrite(d->bz2,(void*)From,Size);
699b209e 1670#endif
7f350a37
DK
1671#ifdef HAVE_LZMA
1672 else if (d != NULL && d->lzma != NULL)
1673 {
1674 d->lzma->stream.next_in = (uint8_t *)From;
1675 d->lzma->stream.avail_in = Size;
1676 d->lzma->stream.next_out = d->lzma->buffer;
1677 d->lzma->stream.avail_out = sizeof(d->lzma->buffer)/sizeof(d->lzma->buffer[0]);
1678 d->lzma->err = lzma_code(&d->lzma->stream, LZMA_RUN);
1679 if (d->lzma->err != LZMA_OK)
1680 return false;
1681 size_t const n = sizeof(d->lzma->buffer)/sizeof(d->lzma->buffer[0]) - d->lzma->stream.avail_out;
1682 size_t const m = (n == 0) ? 0 : fwrite(d->lzma->buffer, 1, n, d->lzma->file);
1683 if (m != n)
1684 Res = -1;
1685 else
1686 Res = Size - d->lzma->stream.avail_in;
1687 }
699b209e 1688#endif
7f350a37
DK
1689 else
1690 Res = write(iFd,From,Size);
1691
b0db36b1
AL
1692 if (Res < 0 && errno == EINTR)
1693 continue;
1694 if (Res < 0)
1695 {
7f350a37
DK
1696 if (false)
1697 /* dummy so that the rest can be 'else if's */;
c4997486 1698#ifdef HAVE_ZLIB
7f350a37 1699 else if (d != NULL && d->gz != NULL)
c4997486
DK
1700 {
1701 int err;
1702 char const * const errmsg = gzerror(d->gz, &err);
1703 if (err != Z_ERRNO)
ae635e3c 1704 return FileFdError("gzwrite: %s (%d: %s)", _("Write error"), err, errmsg);
c4997486
DK
1705 }
1706#endif
1707#ifdef HAVE_BZ2
7f350a37 1708 else if (d != NULL && d->bz2 != NULL)
c4997486
DK
1709 {
1710 int err;
1711 char const * const errmsg = BZ2_bzerror(d->bz2, &err);
1712 if (err != BZ_IO_ERROR)
ae635e3c 1713 return FileFdError("BZ2_bzwrite: %s (%d: %s)", _("Write error"), err, errmsg);
c4997486 1714 }
7f350a37
DK
1715#endif
1716#ifdef HAVE_LZMA
1717 else if (d != NULL && d->lzma != NULL)
1718 return FileFdErrno("lzma_fwrite", _("Write error"));
c4997486 1719#endif
ae635e3c 1720 return FileFdErrno("write",_("Write error"));
b0db36b1
AL
1721 }
1722
cf4ff3b7 1723 From = (char const *)From + Res;
b0db36b1 1724 Size -= Res;
ff477ee1
DK
1725 if (d != NULL)
1726 d->seekpos += Res;
578bfd0a
AL
1727 }
1728
b0db36b1
AL
1729 if (Size == 0)
1730 return true;
ae635e3c
DK
1731
1732 return FileFdError(_("write, still have %llu to write but couldn't"), Size);
d68d65ad
DK
1733}
1734bool FileFd::Write(int Fd, const void *From, unsigned long long Size)
1735{
5df91bc7 1736 ssize_t Res = 1;
d68d65ad 1737 errno = 0;
5df91bc7 1738 while (Res > 0 && Size > 0)
d68d65ad
DK
1739 {
1740 Res = write(Fd,From,Size);
1741 if (Res < 0 && errno == EINTR)
1742 continue;
1743 if (Res < 0)
1744 return _error->Errno("write",_("Write error"));
1745
cf4ff3b7 1746 From = (char const *)From + Res;
d68d65ad
DK
1747 Size -= Res;
1748 }
d68d65ad
DK
1749
1750 if (Size == 0)
1751 return true;
1752
1753 return _error->Error(_("write, still have %llu to write but couldn't"), Size);
578bfd0a
AL
1754}
1755 /*}}}*/
8e06abb2 1756// FileFd::Seek - Seek in the file /*{{{*/
578bfd0a
AL
1757// ---------------------------------------------------------------------
1758/* */
650faab0 1759bool FileFd::Seek(unsigned long long To)
578bfd0a 1760{
bb93178b
DK
1761 Flags &= ~HitEof;
1762
4239dbca 1763 if (d != NULL && (d->pipe == true || d->InternalStream() == true))
699b209e 1764 {
1abbc47c
DK
1765 // Our poor man seeking in pipes is costly, so try to avoid it
1766 unsigned long long seekpos = Tell();
1767 if (seekpos == To)
1768 return true;
1769 else if (seekpos < To)
1770 return Skip(To - seekpos);
1771
561f860a 1772 if ((d->openmode & ReadOnly) != ReadOnly)
ae635e3c 1773 return FileFdError("Reopen is only implemented for read-only files!");
4239dbca 1774 d->InternalClose(FileName);
afb093cd
DK
1775 if (iFd != -1)
1776 close(iFd);
1777 iFd = -1;
561f860a
DK
1778 if (TemporaryFileName.empty() == false)
1779 iFd = open(TemporaryFileName.c_str(), O_RDONLY);
1780 else if (FileName.empty() == false)
1781 iFd = open(FileName.c_str(), O_RDONLY);
1782 else
6fd947bd
DK
1783 {
1784 if (d->compressed_fd > 0)
1785 if (lseek(d->compressed_fd, 0, SEEK_SET) != 0)
1786 iFd = d->compressed_fd;
500400fe 1787 if (iFd < 0)
ae635e3c 1788 return FileFdError("Reopen is not implemented for pipes opened with FileFd::OpenDescriptor()!");
6fd947bd 1789 }
561f860a
DK
1790
1791 if (OpenInternDescriptor(d->openmode, d->compressor) == false)
ae635e3c 1792 return FileFdError("Seek on file %s because it couldn't be reopened", FileName.c_str());
561f860a
DK
1793
1794 if (To != 0)
1795 return Skip(To);
1abbc47c
DK
1796
1797 d->seekpos = To;
561f860a 1798 return true;
699b209e 1799 }
3286ad13 1800 off_t res;
7efb8c8e 1801#ifdef HAVE_ZLIB
ff477ee1 1802 if (d != NULL && d->gz)
032bd56f 1803 res = gzseek(d->gz,To,SEEK_SET);
a3a03f5d 1804 else
699b209e 1805#endif
a3a03f5d 1806 res = lseek(iFd,To,SEEK_SET);
3286ad13 1807 if (res != (off_t)To)
ae635e3c 1808 return FileFdError("Unable to seek to %llu", To);
1abbc47c 1809
ff477ee1
DK
1810 if (d != NULL)
1811 d->seekpos = To;
727f18af
AL
1812 return true;
1813}
1814 /*}}}*/
1815// FileFd::Skip - Seek in the file /*{{{*/
1816// ---------------------------------------------------------------------
1817/* */
650faab0 1818bool FileFd::Skip(unsigned long long Over)
727f18af 1819{
4239dbca 1820 if (d != NULL && (d->pipe == true || d->InternalStream() == true))
40468850 1821 {
40468850
DK
1822 char buffer[1024];
1823 while (Over != 0)
1824 {
1825 unsigned long long toread = std::min((unsigned long long) sizeof(buffer), Over);
1826 if (Read(buffer, toread) == false)
ae635e3c 1827 return FileFdError("Unable to seek ahead %llu",Over);
40468850
DK
1828 Over -= toread;
1829 }
1830 return true;
1831 }
1832
3286ad13 1833 off_t res;
7efb8c8e 1834#ifdef HAVE_ZLIB
ff477ee1 1835 if (d != NULL && d->gz != NULL)
032bd56f 1836 res = gzseek(d->gz,Over,SEEK_CUR);
a3a03f5d 1837 else
699b209e 1838#endif
a3a03f5d 1839 res = lseek(iFd,Over,SEEK_CUR);
1840 if (res < 0)
ae635e3c 1841 return FileFdError("Unable to seek ahead %llu",Over);
ff477ee1
DK
1842 if (d != NULL)
1843 d->seekpos = res;
1abbc47c 1844
6d5dd02a
AL
1845 return true;
1846}
1847 /*}}}*/
1848// FileFd::Truncate - Truncate the file /*{{{*/
1849// ---------------------------------------------------------------------
1850/* */
650faab0 1851bool FileFd::Truncate(unsigned long long To)
6d5dd02a 1852{
ad5051ef
DK
1853 // truncating /dev/null is always successful - as we get an error otherwise
1854 if (To == 0 && FileName == "/dev/null")
1855 return true;
7f350a37 1856#if defined HAVE_ZLIB || defined HAVE_BZ2 || defined HAVE_LZMA
4239dbca 1857 if (d != NULL && (d->InternalStream() == true
7f350a37 1858#ifdef HAVE_ZLIB
4239dbca 1859 || d->gz != NULL
7f350a37 1860#endif
4239dbca 1861 ))
ae635e3c 1862 return FileFdError("Truncating compressed files is not implemented (%s)", FileName.c_str());
c4997486 1863#endif
6d5dd02a 1864 if (ftruncate(iFd,To) != 0)
ae635e3c
DK
1865 return FileFdError("Unable to truncate to %llu",To);
1866
578bfd0a
AL
1867 return true;
1868}
1869 /*}}}*/
7f25bdff
AL
1870// FileFd::Tell - Current seek position /*{{{*/
1871// ---------------------------------------------------------------------
1872/* */
650faab0 1873unsigned long long FileFd::Tell()
7f25bdff 1874{
1abbc47c
DK
1875 // In theory, we could just return seekpos here always instead of
1876 // seeking around, but not all users of FileFd use always Seek() and co
1877 // so d->seekpos isn't always true and we can just use it as a hint if
1878 // we have nothing else, but not always as an authority…
4239dbca 1879 if (d != NULL && (d->pipe == true || d->InternalStream() == true))
1abbc47c
DK
1880 return d->seekpos;
1881
a3a03f5d 1882 off_t Res;
7efb8c8e 1883#ifdef HAVE_ZLIB
ff477ee1 1884 if (d != NULL && d->gz != NULL)
032bd56f 1885 Res = gztell(d->gz);
a3a03f5d 1886 else
699b209e 1887#endif
a3a03f5d 1888 Res = lseek(iFd,0,SEEK_CUR);
7f25bdff 1889 if (Res == (off_t)-1)
ae635e3c 1890 FileFdErrno("lseek","Failed to determine the current file position");
ff477ee1
DK
1891 if (d != NULL)
1892 d->seekpos = Res;
7f25bdff
AL
1893 return Res;
1894}
1895 /*}}}*/
8190b07a 1896static bool StatFileFd(char const * const msg, int const iFd, std::string const &FileName, struct stat &Buf, FileFdPrivate * const d) /*{{{*/
578bfd0a 1897{
6008b79a
DK
1898 bool ispipe = (d != NULL && d->pipe == true);
1899 if (ispipe == false)
1900 {
1901 if (fstat(iFd,&Buf) != 0)
8190b07a
DK
1902 // higher-level code will generate more meaningful messages,
1903 // even translated this would be meaningless for users
1904 return _error->Errno("fstat", "Unable to determine %s for fd %i", msg, iFd);
003c40d3
DK
1905 if (FileName.empty() == false)
1906 ispipe = S_ISFIFO(Buf.st_mode);
6008b79a 1907 }
699b209e
DK
1908
1909 // for compressor pipes st_size is undefined and at 'best' zero
6008b79a 1910 if (ispipe == true)
699b209e
DK
1911 {
1912 // we set it here, too, as we get the info here for free
1913 // in theory the Open-methods should take care of it already
ff477ee1
DK
1914 if (d != NULL)
1915 d->pipe = true;
699b209e 1916 if (stat(FileName.c_str(), &Buf) != 0)
8190b07a
DK
1917 return _error->Errno("fstat", "Unable to determine %s for file %s", msg, FileName.c_str());
1918 }
1919 return true;
1920}
1921 /*}}}*/
1922// FileFd::FileSize - Return the size of the file /*{{{*/
1923unsigned long long FileFd::FileSize()
1924{
1925 struct stat Buf;
1926 if (StatFileFd("file size", iFd, FileName, Buf, d) == false)
1927 {
1928 Flags |= Fail;
1929 return 0;
699b209e 1930 }
4260fd39
DK
1931 return Buf.st_size;
1932}
1933 /*}}}*/
8190b07a
DK
1934// FileFd::ModificationTime - Return the time of last touch /*{{{*/
1935time_t FileFd::ModificationTime()
1936{
1937 struct stat Buf;
1938 if (StatFileFd("modification time", iFd, FileName, Buf, d) == false)
1939 {
1940 Flags |= Fail;
1941 return 0;
1942 }
1943 return Buf.st_mtime;
1944}
1945 /*}}}*/
4260fd39
DK
1946// FileFd::Size - Return the size of the content in the file /*{{{*/
1947// ---------------------------------------------------------------------
1948/* */
650faab0 1949unsigned long long FileFd::Size()
4260fd39 1950{
650faab0 1951 unsigned long long size = FileSize();
44dc669e 1952
699b209e
DK
1953 // for compressor pipes st_size is undefined and at 'best' zero,
1954 // so we 'read' the content and 'seek' back - see there
4239dbca 1955 if (d != NULL && (d->pipe == true || (d->InternalStream() == true && size > 0)))
699b209e 1956 {
1abbc47c 1957 unsigned long long const oldSeek = Tell();
699b209e
DK
1958 char ignore[1000];
1959 unsigned long long read = 0;
1960 do {
638593bd
DK
1961 if (Read(ignore, sizeof(ignore), &read) == false)
1962 {
1963 Seek(oldSeek);
1964 return 0;
1965 }
699b209e 1966 } while(read != 0);
1abbc47c
DK
1967 size = Tell();
1968 Seek(oldSeek);
699b209e 1969 }
7efb8c8e 1970#ifdef HAVE_ZLIB
44dc669e 1971 // only check gzsize if we are actually a gzip file, just checking for
032bd56f 1972 // "gz" is not sufficient as uncompressed files could be opened with
44dc669e 1973 // gzopen in "direct" mode as well
ff477ee1 1974 else if (d != NULL && d->gz && !gzdirect(d->gz) && size > 0)
9c182afa 1975 {
65c72a4b 1976 off_t const oldPos = lseek(iFd,0,SEEK_CUR);
9c182afa
MP
1977 /* unfortunately zlib.h doesn't provide a gzsize(), so we have to do
1978 * this ourselves; the original (uncompressed) file size is the last 32
1979 * bits of the file */
650faab0 1980 // FIXME: Size for gz-files is limited by 32bit… no largefile support
9c182afa 1981 if (lseek(iFd, -4, SEEK_END) < 0)
fbb89d94 1982 {
638593bd
DK
1983 FileFdErrno("lseek","Unable to seek to end of gzipped file");
1984 return 0;
fbb89d94 1985 }
05eab8af 1986 uint32_t size = 0;
9c182afa 1987 if (read(iFd, &size, 4) != 4)
fbb89d94 1988 {
638593bd
DK
1989 FileFdErrno("read","Unable to read original size of gzipped file");
1990 return 0;
fbb89d94 1991 }
05eab8af 1992 size = le32toh(size);
9c182afa 1993
65c72a4b 1994 if (lseek(iFd, oldPos, SEEK_SET) < 0)
fbb89d94 1995 {
638593bd
DK
1996 FileFdErrno("lseek","Unable to seek in gzipped file");
1997 return 0;
fbb89d94 1998 }
65c72a4b 1999
9c182afa
MP
2000 return size;
2001 }
699b209e 2002#endif
9c182afa 2003
44dc669e 2004 return size;
578bfd0a
AL
2005}
2006 /*}}}*/
8e06abb2 2007// FileFd::Close - Close the file if the close flag is set /*{{{*/
578bfd0a
AL
2008// ---------------------------------------------------------------------
2009/* */
8e06abb2 2010bool FileFd::Close()
578bfd0a 2011{
032bd56f
DK
2012 if (iFd == -1)
2013 return true;
2014
578bfd0a
AL
2015 bool Res = true;
2016 if ((Flags & AutoClose) == AutoClose)
d13c2d3f 2017 {
500400fe
DK
2018 if ((Flags & Compressed) != Compressed && iFd > 0 && close(iFd) != 0)
2019 Res &= _error->Errno("close",_("Problem closing the file %s"), FileName.c_str());
2da8aae5
JAK
2020 }
2021
2022 if (d != NULL)
2023 {
2024 Res &= d->CloseDown(FileName);
2025 delete d;
2026 d = NULL;
d13c2d3f 2027 }
3010fb0e 2028
d3aac32e 2029 if ((Flags & Replace) == Replace) {
3010fb0e 2030 if (rename(TemporaryFileName.c_str(), FileName.c_str()) != 0)
62d073d9
DK
2031 Res &= _error->Errno("rename",_("Problem renaming the file %s to %s"), TemporaryFileName.c_str(), FileName.c_str());
2032
fd3b761e 2033 FileName = TemporaryFileName; // for the unlink() below.
257e8d66 2034 TemporaryFileName.clear();
3010fb0e 2035 }
62d073d9
DK
2036
2037 iFd = -1;
2038
578bfd0a
AL
2039 if ((Flags & Fail) == Fail && (Flags & DelOnFail) == DelOnFail &&
2040 FileName.empty() == false)
ce1f3a2c 2041 Res &= RemoveFile("FileFd::Close", FileName);
3010fb0e 2042
fbb89d94
DK
2043 if (Res == false)
2044 Flags |= Fail;
578bfd0a
AL
2045 return Res;
2046}
2047 /*}}}*/
b2e465d6
AL
2048// FileFd::Sync - Sync the file /*{{{*/
2049// ---------------------------------------------------------------------
2050/* */
2051bool FileFd::Sync()
2052{
b2e465d6 2053 if (fsync(iFd) != 0)
ae635e3c
DK
2054 return FileFdErrno("sync",_("Problem syncing the file"));
2055 return true;
2056}
2057 /*}}}*/
2058// FileFd::FileFdErrno - set Fail and call _error->Errno *{{{*/
2059bool FileFd::FileFdErrno(const char *Function, const char *Description,...)
2060{
2061 Flags |= Fail;
2062 va_list args;
2063 size_t msgSize = 400;
2064 int const errsv = errno;
2065 while (true)
fbb89d94 2066 {
ae635e3c
DK
2067 va_start(args,Description);
2068 if (_error->InsertErrno(GlobalError::ERROR, Function, Description, args, errsv, msgSize) == false)
2069 break;
2070 va_end(args);
fbb89d94 2071 }
ae635e3c
DK
2072 return false;
2073}
2074 /*}}}*/
2075// FileFd::FileFdError - set Fail and call _error->Error *{{{*/
2076bool FileFd::FileFdError(const char *Description,...) {
2077 Flags |= Fail;
2078 va_list args;
2079 size_t msgSize = 400;
2080 while (true)
2081 {
2082 va_start(args,Description);
2083 if (_error->Insert(GlobalError::ERROR, Description, args, msgSize) == false)
2084 break;
2085 va_end(args);
2086 }
2087 return false;
b2e465d6
AL
2088}
2089 /*}}}*/
699b209e 2090
5dd00edb 2091gzFile FileFd::gzFd() {
7f350a37
DK
2092#ifdef HAVE_ZLIB
2093 return d->gz;
2094#else
2095 return NULL;
2096#endif
2097}
8d01b9d6 2098
f8aba23f 2099// Glob - wrapper around "glob()" /*{{{*/
8d01b9d6
MV
2100std::vector<std::string> Glob(std::string const &pattern, int flags)
2101{
2102 std::vector<std::string> result;
2103 glob_t globbuf;
ec4835a1
ÁGM
2104 int glob_res;
2105 unsigned int i;
8d01b9d6
MV
2106
2107 glob_res = glob(pattern.c_str(), flags, NULL, &globbuf);
2108
2109 if (glob_res != 0)
2110 {
2111 if(glob_res != GLOB_NOMATCH) {
2112 _error->Errno("glob", "Problem with glob");
2113 return result;
2114 }
2115 }
2116
2117 // append results
2118 for(i=0;i<globbuf.gl_pathc;i++)
2119 result.push_back(string(globbuf.gl_pathv[i]));
2120
2121 globfree(&globbuf);
2122 return result;
2123}
2124 /*}}}*/
f8aba23f 2125std::string GetTempDir() /*{{{*/
68e01721
MV
2126{
2127 const char *tmpdir = getenv("TMPDIR");
2128
2129#ifdef P_tmpdir
2130 if (!tmpdir)
2131 tmpdir = P_tmpdir;
2132#endif
2133
68e01721 2134 struct stat st;
0d303f17 2135 if (!tmpdir || strlen(tmpdir) == 0 || // tmpdir is set
dd6da7d2
DK
2136 stat(tmpdir, &st) != 0 || (st.st_mode & S_IFDIR) == 0) // exists and is directory
2137 tmpdir = "/tmp";
2138 else if (geteuid() != 0 && // root can do everything anyway
2139 faccessat(-1, tmpdir, R_OK | W_OK | X_OK, AT_EACCESS | AT_SYMLINK_NOFOLLOW) != 0) // current user has rwx access to directory
68e01721
MV
2140 tmpdir = "/tmp";
2141
2142 return string(tmpdir);
dd6da7d2
DK
2143}
2144std::string GetTempDir(std::string const &User)
2145{
2146 // no need/possibility to drop privs
2147 if(getuid() != 0 || User.empty() || User == "root")
2148 return GetTempDir();
2149
2150 struct passwd const * const pw = getpwnam(User.c_str());
2151 if (pw == NULL)
2152 return GetTempDir();
2153
226c0f64
DK
2154 gid_t const old_euid = geteuid();
2155 gid_t const old_egid = getegid();
dd6da7d2
DK
2156 if (setegid(pw->pw_gid) != 0)
2157 _error->Errno("setegid", "setegid %u failed", pw->pw_gid);
2158 if (seteuid(pw->pw_uid) != 0)
2159 _error->Errno("seteuid", "seteuid %u failed", pw->pw_uid);
2160
2161 std::string const tmp = GetTempDir();
2162
226c0f64
DK
2163 if (seteuid(old_euid) != 0)
2164 _error->Errno("seteuid", "seteuid %u failed", old_euid);
2165 if (setegid(old_egid) != 0)
2166 _error->Errno("setegid", "setegid %u failed", old_egid);
dd6da7d2
DK
2167
2168 return tmp;
68e01721 2169}
f8aba23f 2170 /*}}}*/
c9443c01 2171FileFd* GetTempFile(std::string const &Prefix, bool ImmediateUnlink, FileFd * const TmpFd) /*{{{*/
0d29b9d4
MV
2172{
2173 char fn[512];
c9443c01 2174 FileFd * const Fd = TmpFd == NULL ? new FileFd() : TmpFd;
0d29b9d4 2175
c9443c01
DK
2176 std::string const tempdir = GetTempDir();
2177 snprintf(fn, sizeof(fn), "%s/%s.XXXXXX",
0d29b9d4 2178 tempdir.c_str(), Prefix.c_str());
c9443c01 2179 int const fd = mkstemp(fn);
0d29b9d4
MV
2180 if(ImmediateUnlink)
2181 unlink(fn);
c9443c01 2182 if (fd < 0)
0d29b9d4
MV
2183 {
2184 _error->Errno("GetTempFile",_("Unable to mkstemp %s"), fn);
2185 return NULL;
2186 }
c9443c01 2187 if (!Fd->OpenDescriptor(fd, FileFd::ReadWrite, FileFd::None, true))
0d29b9d4
MV
2188 {
2189 _error->Errno("GetTempFile",_("Unable to write to %s"),fn);
2190 return NULL;
2191 }
0d29b9d4
MV
2192 return Fd;
2193}
f8aba23f
DK
2194 /*}}}*/
2195bool Rename(std::string From, std::string To) /*{{{*/
c1409d1b
MV
2196{
2197 if (rename(From.c_str(),To.c_str()) != 0)
2198 {
2199 _error->Error(_("rename failed, %s (%s -> %s)."),strerror(errno),
2200 From.c_str(),To.c_str());
2201 return false;
f8aba23f 2202 }
c1409d1b
MV
2203 return true;
2204}
f8aba23f
DK
2205 /*}}}*/
2206bool Popen(const char* Args[], FileFd &Fd, pid_t &Child, FileFd::OpenMode Mode)/*{{{*/
7ad2a347
MV
2207{
2208 int fd;
2209 if (Mode != FileFd::ReadOnly && Mode != FileFd::WriteOnly)
2210 return _error->Error("Popen supports ReadOnly (x)or WriteOnly mode only");
2211
2212 int Pipe[2] = {-1, -1};
2213 if(pipe(Pipe) != 0)
7ad2a347 2214 return _error->Errno("pipe", _("Failed to create subprocess IPC"));
5e49cbb7 2215
7ad2a347
MV
2216 std::set<int> keep_fds;
2217 keep_fds.insert(Pipe[0]);
2218 keep_fds.insert(Pipe[1]);
2219 Child = ExecFork(keep_fds);
2220 if(Child < 0)
2221 return _error->Errno("fork", "Failed to fork");
2222 if(Child == 0)
2223 {
2224 if(Mode == FileFd::ReadOnly)
2225 {
2226 close(Pipe[0]);
2227 fd = Pipe[1];
2228 }
2229 else if(Mode == FileFd::WriteOnly)
2230 {
2231 close(Pipe[1]);
2232 fd = Pipe[0];
2233 }
2234
2235 if(Mode == FileFd::ReadOnly)
2236 {
2237 dup2(fd, 1);
2238 dup2(fd, 2);
2239 } else if(Mode == FileFd::WriteOnly)
2240 dup2(fd, 0);
2241
2242 execv(Args[0], (char**)Args);
2243 _exit(100);
2244 }
2245 if(Mode == FileFd::ReadOnly)
2246 {
2247 close(Pipe[1]);
2248 fd = Pipe[0];
8f5b67ae
DK
2249 }
2250 else if(Mode == FileFd::WriteOnly)
7ad2a347
MV
2251 {
2252 close(Pipe[0]);
2253 fd = Pipe[1];
2254 }
8f5b67ae
DK
2255 else
2256 return _error->Error("Popen supports ReadOnly (x)or WriteOnly mode only");
7ad2a347
MV
2257 Fd.OpenDescriptor(fd, Mode, FileFd::None, true);
2258
2259 return true;
2260}
f8aba23f
DK
2261 /*}}}*/
2262bool DropPrivileges() /*{{{*/
fc1a78d8 2263{
8f45798d
DK
2264 if(_config->FindB("Debug::NoDropPrivs", false) == true)
2265 return true;
2266
2267#if __gnu_linux__
2268#if defined(PR_SET_NO_NEW_PRIVS) && ( PR_SET_NO_NEW_PRIVS != 38 )
2269#error "PR_SET_NO_NEW_PRIVS is defined, but with a different value than expected!"
2270#endif
2271 // see prctl(2), needs linux3.5 at runtime - magic constant to avoid it at buildtime
2272 int ret = prctl(38, 1, 0, 0, 0);
2273 // ignore EINVAL - kernel is too old to understand the option
2274 if(ret < 0 && errno != EINVAL)
2275 _error->Warning("PR_SET_NO_NEW_PRIVS failed with %i", ret);
2276#endif
2277
990dd78a
DK
2278 // empty setting disables privilege dropping - this also ensures
2279 // backward compatibility, see bug #764506
2280 const std::string toUser = _config->Find("APT::Sandbox::User");
514a25cb 2281 if (toUser.empty() || toUser == "root")
990dd78a
DK
2282 return true;
2283
ebca2f25
DK
2284 // a lot can go wrong trying to drop privileges completely,
2285 // so ideally we would like to verify that we have done it –
2286 // but the verify asks for too much in case of fakeroot (and alike)
2287 // [Specific checks can be overridden with dedicated options]
2288 bool const VerifySandboxing = _config->FindB("APT::Sandbox::Verify", false);
2289
f1e3c8f0 2290 // uid will be 0 in the end, but gid might be different anyway
8f45798d
DK
2291 uid_t const old_uid = getuid();
2292 gid_t const old_gid = getgid();
fc1a78d8 2293
5f2047ec
JAK
2294 if (old_uid != 0)
2295 return true;
3927c6da 2296
b8dae9a1 2297 struct passwd *pw = getpwnam(toUser.c_str());
fc1a78d8 2298 if (pw == NULL)
b8dae9a1 2299 return _error->Error("No user %s, can not drop rights", toUser.c_str());
3927c6da 2300
f1e3c8f0 2301 // Do not change the order here, it might break things
5a326439 2302 // Get rid of all our supplementary groups first
3b084f06 2303 if (setgroups(1, &pw->pw_gid))
3927c6da
MV
2304 return _error->Errno("setgroups", "Failed to setgroups");
2305
5a326439
JAK
2306 // Now change the group ids to the new user
2307#ifdef HAVE_SETRESGID
2308 if (setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) != 0)
2309 return _error->Errno("setresgid", "Failed to set new group ids");
2310#else
3927c6da 2311 if (setegid(pw->pw_gid) != 0)
5f2047ec
JAK
2312 return _error->Errno("setegid", "Failed to setegid");
2313
fc1a78d8
MV
2314 if (setgid(pw->pw_gid) != 0)
2315 return _error->Errno("setgid", "Failed to setgid");
5a326439 2316#endif
5f2047ec 2317
5a326439
JAK
2318 // Change the user ids to the new user
2319#ifdef HAVE_SETRESUID
2320 if (setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid) != 0)
2321 return _error->Errno("setresuid", "Failed to set new user ids");
2322#else
fc1a78d8
MV
2323 if (setuid(pw->pw_uid) != 0)
2324 return _error->Errno("setuid", "Failed to setuid");
5f2047ec
JAK
2325 if (seteuid(pw->pw_uid) != 0)
2326 return _error->Errno("seteuid", "Failed to seteuid");
5a326439 2327#endif
5f2047ec 2328
ebca2f25
DK
2329 // disabled by default as fakeroot doesn't implement getgroups currently (#806521)
2330 if (VerifySandboxing == true || _config->FindB("APT::Sandbox::Verify::Groups", false) == true)
2331 {
2332 // Verify that the user isn't still in any supplementary groups
2333 long const ngroups_max = sysconf(_SC_NGROUPS_MAX);
2334 std::unique_ptr<gid_t[]> gidlist(new gid_t[ngroups_max]);
2335 if (unlikely(gidlist == NULL))
2336 return _error->Error("Allocation of a list of size %lu for getgroups failed", ngroups_max);
2337 ssize_t gidlist_nr;
2338 if ((gidlist_nr = getgroups(ngroups_max, gidlist.get())) < 0)
2339 return _error->Errno("getgroups", "Could not get new groups (%lu)", ngroups_max);
2340 for (ssize_t i = 0; i < gidlist_nr; ++i)
2341 if (gidlist[i] != pw->pw_gid)
2342 return _error->Error("Could not switch group, user %s is still in group %d", toUser.c_str(), gidlist[i]);
2343 }
2344
2345 // enabled by default as all fakeroot-lookalikes should fake that accordingly
2346 if (VerifySandboxing == true || _config->FindB("APT::Sandbox::Verify::IDs", true) == true)
2347 {
2348 // Verify that gid, egid, uid, and euid changed
2349 if (getgid() != pw->pw_gid)
2350 return _error->Error("Could not switch group");
2351 if (getegid() != pw->pw_gid)
2352 return _error->Error("Could not switch effective group");
2353 if (getuid() != pw->pw_uid)
2354 return _error->Error("Could not switch user");
2355 if (geteuid() != pw->pw_uid)
2356 return _error->Error("Could not switch effective user");
5f2047ec 2357
550ab420 2358#ifdef HAVE_GETRESUID
ebca2f25
DK
2359 // verify that the saved set-user-id was changed as well
2360 uid_t ruid = 0;
2361 uid_t euid = 0;
2362 uid_t suid = 0;
2363 if (getresuid(&ruid, &euid, &suid))
2364 return _error->Errno("getresuid", "Could not get saved set-user-ID");
2365 if (suid != pw->pw_uid)
2366 return _error->Error("Could not switch saved set-user-ID");
550ab420
JAK
2367#endif
2368
2369#ifdef HAVE_GETRESGID
ebca2f25
DK
2370 // verify that the saved set-group-id was changed as well
2371 gid_t rgid = 0;
2372 gid_t egid = 0;
2373 gid_t sgid = 0;
2374 if (getresgid(&rgid, &egid, &sgid))
2375 return _error->Errno("getresuid", "Could not get saved set-group-ID");
2376 if (sgid != pw->pw_gid)
2377 return _error->Error("Could not switch saved set-group-ID");
550ab420 2378#endif
ebca2f25 2379 }
550ab420 2380
ebca2f25
DK
2381 // disabled as fakeroot doesn't forbid (by design) (re)gaining root from unprivileged
2382 if (VerifySandboxing == true || _config->FindB("APT::Sandbox::Verify::Regain", false) == true)
2383 {
2384 // Check that uid and gid changes do not work anymore
2385 if (pw->pw_gid != old_gid && (setgid(old_gid) != -1 || setegid(old_gid) != -1))
2386 return _error->Error("Could restore a gid to root, privilege dropping did not work");
bdc00df5 2387
ebca2f25
DK
2388 if (pw->pw_uid != old_uid && (setuid(old_uid) != -1 || seteuid(old_uid) != -1))
2389 return _error->Error("Could restore a uid to root, privilege dropping did not work");
2390 }
bdc00df5 2391
fc1a78d8
MV
2392 return true;
2393}
f8aba23f 2394 /*}}}*/