1ba10db99SColin Percival /*-
24d846d26SWarner Losh * SPDX-License-Identifier: BSD-2-Clause
31de7b4b8SPedro F. Giffuni *
4ba10db99SColin Percival * Copyright 2003-2005 Colin Percival
5ba10db99SColin Percival * All rights reserved
6ba10db99SColin Percival *
7ba10db99SColin Percival * Redistribution and use in source and binary forms, with or without
8ba10db99SColin Percival * modification, are permitted providing that the following conditions
9ba10db99SColin Percival * are met:
10ba10db99SColin Percival * 1. Redistributions of source code must retain the above copyright
11ba10db99SColin Percival * notice, this list of conditions and the following disclaimer.
12ba10db99SColin Percival * 2. Redistributions in binary form must reproduce the above copyright
13ba10db99SColin Percival * notice, this list of conditions and the following disclaimer in the
14ba10db99SColin Percival * documentation and/or other materials provided with the distribution.
15ba10db99SColin Percival *
16ba10db99SColin Percival * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17ba10db99SColin Percival * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
18ba10db99SColin Percival * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19ba10db99SColin Percival * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
20ba10db99SColin Percival * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21ba10db99SColin Percival * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22ba10db99SColin Percival * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23ba10db99SColin Percival * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
24ba10db99SColin Percival * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING
25ba10db99SColin Percival * IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
26ba10db99SColin Percival * POSSIBILITY OF SUCH DAMAGE.
27ba10db99SColin Percival */
28ba10db99SColin Percival
29ba10db99SColin Percival #include <sys/cdefs.h>
30c93b6e5fSXin LI #ifndef WITHOUT_CAPSICUM
3176723b39SAllan Jude #include <sys/capsicum.h>
3276723b39SAllan Jude #endif
3376723b39SAllan Jude
34ba10db99SColin Percival #include <bzlib.h>
35ba10db99SColin Percival #include <err.h>
36ba10db99SColin Percival #include <fcntl.h>
3706ce2764SEd Maste #include <libgen.h>
38e3d9ae4cSEd Maste #include <limits.h>
39*2871b8a1SEd Maste #include <stdckdint.h>
406d9f0e4dSEd Maste #include <stdint.h>
41ce437befSEd Maste #include <stdio.h>
42ce437befSEd Maste #include <stdlib.h>
43ce437befSEd Maste #include <string.h>
44ce437befSEd Maste #include <unistd.h>
45ba10db99SColin Percival
468904d5ecSColin Percival #ifndef O_BINARY
478904d5ecSColin Percival #define O_BINARY 0
488904d5ecSColin Percival #endif
496d9f0e4dSEd Maste #define HEADER_SIZE 32
508904d5ecSColin Percival
5106ce2764SEd Maste static char *newfile;
5206ce2764SEd Maste static int dirfd = -1;
5306ce2764SEd Maste
5406ce2764SEd Maste static void
exit_cleanup(void)5506ce2764SEd Maste exit_cleanup(void)
5606ce2764SEd Maste {
5706ce2764SEd Maste
5806ce2764SEd Maste if (dirfd != -1 && newfile != NULL)
5906ce2764SEd Maste if (unlinkat(dirfd, newfile, 0))
6006ce2764SEd Maste warn("unlinkat");
6106ce2764SEd Maste }
6206ce2764SEd Maste
6320bd5941SEd Maste static inline off_t
add_off_t(off_t a,off_t b)6420bd5941SEd Maste add_off_t(off_t a, off_t b)
6520bd5941SEd Maste {
6620bd5941SEd Maste off_t result;
6720bd5941SEd Maste
68*2871b8a1SEd Maste if (ckd_add(&result, a, b))
6920bd5941SEd Maste errx(1, "Corrupt patch");
7020bd5941SEd Maste return result;
7120bd5941SEd Maste }
7220bd5941SEd Maste
offtin(u_char * buf)73ba10db99SColin Percival static off_t offtin(u_char *buf)
74ba10db99SColin Percival {
75ba10db99SColin Percival off_t y;
76ba10db99SColin Percival
77ba10db99SColin Percival y = buf[7] & 0x7F;
78ba10db99SColin Percival y = y * 256; y += buf[6];
79ba10db99SColin Percival y = y * 256; y += buf[5];
80ba10db99SColin Percival y = y * 256; y += buf[4];
81ba10db99SColin Percival y = y * 256; y += buf[3];
82ba10db99SColin Percival y = y * 256; y += buf[2];
83ba10db99SColin Percival y = y * 256; y += buf[1];
84ba10db99SColin Percival y = y * 256; y += buf[0];
85ba10db99SColin Percival
86ce437befSEd Maste if (buf[7] & 0x80)
87ce437befSEd Maste y = -y;
88ba10db99SColin Percival
89ce437befSEd Maste return (y);
90ba10db99SColin Percival }
91ba10db99SColin Percival
9243e0d7bfSEd Schouten static void
usage(void)9343e0d7bfSEd Schouten usage(void)
9443e0d7bfSEd Schouten {
9543e0d7bfSEd Schouten
9643e0d7bfSEd Schouten fprintf(stderr, "usage: bspatch oldfile newfile patchfile\n");
9743e0d7bfSEd Schouten exit(1);
9843e0d7bfSEd Schouten }
9943e0d7bfSEd Schouten
main(int argc,char * argv[])100ba10db99SColin Percival int main(int argc, char *argv[])
101ba10db99SColin Percival {
102ba10db99SColin Percival FILE *f, *cpf, *dpf, *epf;
103ba10db99SColin Percival BZFILE *cpfbz2, *dpfbz2, *epfbz2;
10406ce2764SEd Maste char *directory, *namebuf;
105ba10db99SColin Percival int cbz2err, dbz2err, ebz2err;
106ce437befSEd Maste int newfd, oldfd;
107e3d9ae4cSEd Maste off_t oldsize, newsize;
108e3d9ae4cSEd Maste off_t bzctrllen, bzdatalen;
1096d9f0e4dSEd Maste u_char header[HEADER_SIZE], buf[8];
110ba10db99SColin Percival u_char *old, *new;
111ba10db99SColin Percival off_t oldpos, newpos;
112ba10db99SColin Percival off_t ctrl[3];
1136d9f0e4dSEd Maste off_t i, lenread, offset;
114c93b6e5fSXin LI #ifndef WITHOUT_CAPSICUM
11506ce2764SEd Maste cap_rights_t rights_dir, rights_ro, rights_wr;
11676723b39SAllan Jude #endif
117ba10db99SColin Percival
11843e0d7bfSEd Schouten if (argc != 4)
11943e0d7bfSEd Schouten usage();
120ba10db99SColin Percival
121ba10db99SColin Percival /* Open patch file */
1228904d5ecSColin Percival if ((f = fopen(argv[3], "rb")) == NULL)
123ba10db99SColin Percival err(1, "fopen(%s)", argv[3]);
12476723b39SAllan Jude /* Open patch file for control block */
12576723b39SAllan Jude if ((cpf = fopen(argv[3], "rb")) == NULL)
12676723b39SAllan Jude err(1, "fopen(%s)", argv[3]);
12776723b39SAllan Jude /* open patch file for diff block */
12876723b39SAllan Jude if ((dpf = fopen(argv[3], "rb")) == NULL)
12976723b39SAllan Jude err(1, "fopen(%s)", argv[3]);
13076723b39SAllan Jude /* open patch file for extra block */
13176723b39SAllan Jude if ((epf = fopen(argv[3], "rb")) == NULL)
13276723b39SAllan Jude err(1, "fopen(%s)", argv[3]);
13376723b39SAllan Jude /* open oldfile */
13476723b39SAllan Jude if ((oldfd = open(argv[1], O_RDONLY | O_BINARY, 0)) < 0)
13576723b39SAllan Jude err(1, "open(%s)", argv[1]);
13606ce2764SEd Maste /* open directory where we'll write newfile */
13706ce2764SEd Maste if ((namebuf = strdup(argv[2])) == NULL ||
13806ce2764SEd Maste (directory = dirname(namebuf)) == NULL ||
13906ce2764SEd Maste (dirfd = open(directory, O_DIRECTORY)) < 0)
14006ce2764SEd Maste err(1, "open %s", argv[2]);
14106ce2764SEd Maste free(namebuf);
14206ce2764SEd Maste if ((newfile = basename(argv[2])) == NULL)
14306ce2764SEd Maste err(1, "basename");
14476723b39SAllan Jude /* open newfile */
14506ce2764SEd Maste if ((newfd = openat(dirfd, newfile,
14606ce2764SEd Maste O_CREAT | O_TRUNC | O_WRONLY | O_BINARY, 0666)) < 0)
14776723b39SAllan Jude err(1, "open(%s)", argv[2]);
14806ce2764SEd Maste atexit(exit_cleanup);
14976723b39SAllan Jude
150c93b6e5fSXin LI #ifndef WITHOUT_CAPSICUM
151a25896caSMariusz Zaborski if (cap_enter() < 0)
15276723b39SAllan Jude err(1, "failed to enter security sandbox");
153a25896caSMariusz Zaborski
15476723b39SAllan Jude cap_rights_init(&rights_ro, CAP_READ, CAP_FSTAT, CAP_SEEK);
15576723b39SAllan Jude cap_rights_init(&rights_wr, CAP_WRITE);
15606ce2764SEd Maste cap_rights_init(&rights_dir, CAP_UNLINKAT);
15776723b39SAllan Jude
15876723b39SAllan Jude if (cap_rights_limit(fileno(f), &rights_ro) < 0 ||
15976723b39SAllan Jude cap_rights_limit(fileno(cpf), &rights_ro) < 0 ||
16076723b39SAllan Jude cap_rights_limit(fileno(dpf), &rights_ro) < 0 ||
16176723b39SAllan Jude cap_rights_limit(fileno(epf), &rights_ro) < 0 ||
16276723b39SAllan Jude cap_rights_limit(oldfd, &rights_ro) < 0 ||
16306ce2764SEd Maste cap_rights_limit(newfd, &rights_wr) < 0 ||
16406ce2764SEd Maste cap_rights_limit(dirfd, &rights_dir) < 0)
16576723b39SAllan Jude err(1, "cap_rights_limit() failed, could not restrict"
16676723b39SAllan Jude " capabilities");
16776723b39SAllan Jude #endif
168ba10db99SColin Percival
169ba10db99SColin Percival /*
170ba10db99SColin Percival File format:
171ba10db99SColin Percival 0 8 "BSDIFF40"
172ba10db99SColin Percival 8 8 X
173ba10db99SColin Percival 16 8 Y
174ba10db99SColin Percival 24 8 sizeof(newfile)
175ba10db99SColin Percival 32 X bzip2(control block)
176ba10db99SColin Percival 32+X Y bzip2(diff block)
177ba10db99SColin Percival 32+X+Y ??? bzip2(extra block)
178ba10db99SColin Percival with control block a set of triples (x,y,z) meaning "add x bytes
179ba10db99SColin Percival from oldfile to x bytes from the diff block; copy y bytes from the
180ba10db99SColin Percival extra block; seek forwards in oldfile by z bytes".
181ba10db99SColin Percival */
182ba10db99SColin Percival
183ba10db99SColin Percival /* Read header */
1846d9f0e4dSEd Maste if (fread(header, 1, HEADER_SIZE, f) < HEADER_SIZE) {
185ba10db99SColin Percival if (feof(f))
18604708d25SEd Maste errx(1, "Corrupt patch");
187ba10db99SColin Percival err(1, "fread(%s)", argv[3]);
188ba10db99SColin Percival }
189ba10db99SColin Percival
190ba10db99SColin Percival /* Check for appropriate magic */
191ba10db99SColin Percival if (memcmp(header, "BSDIFF40", 8) != 0)
19204708d25SEd Maste errx(1, "Corrupt patch");
193ba10db99SColin Percival
194ba10db99SColin Percival /* Read lengths from header */
195ba10db99SColin Percival bzctrllen = offtin(header + 8);
196ba10db99SColin Percival bzdatalen = offtin(header + 16);
197ba10db99SColin Percival newsize = offtin(header + 24);
1986d9f0e4dSEd Maste if (bzctrllen < 0 || bzctrllen > OFF_MAX - HEADER_SIZE ||
1996d9f0e4dSEd Maste bzdatalen < 0 || bzctrllen + HEADER_SIZE > OFF_MAX - bzdatalen ||
200e3d9ae4cSEd Maste newsize < 0 || newsize > SSIZE_MAX)
20104708d25SEd Maste errx(1, "Corrupt patch");
202ba10db99SColin Percival
203ba10db99SColin Percival /* Close patch file and re-open it via libbzip2 at the right places */
204ba10db99SColin Percival if (fclose(f))
205ba10db99SColin Percival err(1, "fclose(%s)", argv[3]);
2066d9f0e4dSEd Maste offset = HEADER_SIZE;
2076d9f0e4dSEd Maste if (fseeko(cpf, offset, SEEK_SET))
2086d9f0e4dSEd Maste err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset);
209ba10db99SColin Percival if ((cpfbz2 = BZ2_bzReadOpen(&cbz2err, cpf, 0, 0, NULL, 0)) == NULL)
210ba10db99SColin Percival errx(1, "BZ2_bzReadOpen, bz2err = %d", cbz2err);
21120bd5941SEd Maste offset = add_off_t(offset, bzctrllen);
2126d9f0e4dSEd Maste if (fseeko(dpf, offset, SEEK_SET))
2136d9f0e4dSEd Maste err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset);
214ba10db99SColin Percival if ((dpfbz2 = BZ2_bzReadOpen(&dbz2err, dpf, 0, 0, NULL, 0)) == NULL)
215ba10db99SColin Percival errx(1, "BZ2_bzReadOpen, bz2err = %d", dbz2err);
21620bd5941SEd Maste offset = add_off_t(offset, bzdatalen);
2176d9f0e4dSEd Maste if (fseeko(epf, offset, SEEK_SET))
2186d9f0e4dSEd Maste err(1, "fseeko(%s, %jd)", argv[3], (intmax_t)offset);
219ba10db99SColin Percival if ((epfbz2 = BZ2_bzReadOpen(&ebz2err, epf, 0, 0, NULL, 0)) == NULL)
220ba10db99SColin Percival errx(1, "BZ2_bzReadOpen, bz2err = %d", ebz2err);
221ba10db99SColin Percival
222ce437befSEd Maste if ((oldsize = lseek(oldfd, 0, SEEK_END)) == -1 ||
223e3d9ae4cSEd Maste oldsize > SSIZE_MAX ||
224e3d9ae4cSEd Maste (old = malloc(oldsize)) == NULL ||
225ce437befSEd Maste lseek(oldfd, 0, SEEK_SET) != 0 ||
226ce437befSEd Maste read(oldfd, old, oldsize) != oldsize ||
227ce437befSEd Maste close(oldfd) == -1)
228ce437befSEd Maste err(1, "%s", argv[1]);
229e3d9ae4cSEd Maste if ((new = malloc(newsize)) == NULL)
230ce437befSEd Maste err(1, NULL);
231ba10db99SColin Percival
232ce437befSEd Maste oldpos = 0;
233ce437befSEd Maste newpos = 0;
234ba10db99SColin Percival while (newpos < newsize) {
235ba10db99SColin Percival /* Read control data */
236ba10db99SColin Percival for (i = 0; i <= 2; i++) {
237ba10db99SColin Percival lenread = BZ2_bzRead(&cbz2err, cpfbz2, buf, 8);
238ba10db99SColin Percival if ((lenread < 8) || ((cbz2err != BZ_OK) &&
239ba10db99SColin Percival (cbz2err != BZ_STREAM_END)))
24004708d25SEd Maste errx(1, "Corrupt patch");
241ba10db99SColin Percival ctrl[i] = offtin(buf);
24280c7cc1cSPedro F. Giffuni }
243ba10db99SColin Percival
244ba10db99SColin Percival /* Sanity-check */
245e3d9ae4cSEd Maste if (ctrl[0] < 0 || ctrl[0] > INT_MAX ||
246e3d9ae4cSEd Maste ctrl[1] < 0 || ctrl[1] > INT_MAX)
24704708d25SEd Maste errx(1, "Corrupt patch");
2482c8d04d0SXin LI
2492c8d04d0SXin LI /* Sanity-check */
25020bd5941SEd Maste if (add_off_t(newpos, ctrl[0]) > newsize)
25104708d25SEd Maste errx(1, "Corrupt patch");
252ba10db99SColin Percival
253ba10db99SColin Percival /* Read diff string */
254ba10db99SColin Percival lenread = BZ2_bzRead(&dbz2err, dpfbz2, new + newpos, ctrl[0]);
255ba10db99SColin Percival if ((lenread < ctrl[0]) ||
256ba10db99SColin Percival ((dbz2err != BZ_OK) && (dbz2err != BZ_STREAM_END)))
25704708d25SEd Maste errx(1, "Corrupt patch");
258ba10db99SColin Percival
259ba10db99SColin Percival /* Add old data to diff string */
260ba10db99SColin Percival for (i = 0; i < ctrl[0]; i++)
26120bd5941SEd Maste if (add_off_t(oldpos, i) < oldsize)
262ba10db99SColin Percival new[newpos + i] += old[oldpos + i];
263ba10db99SColin Percival
264ba10db99SColin Percival /* Adjust pointers */
26520bd5941SEd Maste newpos = add_off_t(newpos, ctrl[0]);
26620bd5941SEd Maste oldpos = add_off_t(oldpos, ctrl[0]);
267ba10db99SColin Percival
268ba10db99SColin Percival /* Sanity-check */
26920bd5941SEd Maste if (add_off_t(newpos, ctrl[1]) > newsize)
27004708d25SEd Maste errx(1, "Corrupt patch");
271ba10db99SColin Percival
272ba10db99SColin Percival /* Read extra string */
273ba10db99SColin Percival lenread = BZ2_bzRead(&ebz2err, epfbz2, new + newpos, ctrl[1]);
274ba10db99SColin Percival if ((lenread < ctrl[1]) ||
275ba10db99SColin Percival ((ebz2err != BZ_OK) && (ebz2err != BZ_STREAM_END)))
27604708d25SEd Maste errx(1, "Corrupt patch");
277ba10db99SColin Percival
278ba10db99SColin Percival /* Adjust pointers */
27920bd5941SEd Maste newpos = add_off_t(newpos, ctrl[1]);
28020bd5941SEd Maste oldpos = add_off_t(oldpos, ctrl[2]);
28180c7cc1cSPedro F. Giffuni }
282ba10db99SColin Percival
283ba10db99SColin Percival /* Clean up the bzip2 reads */
284ba10db99SColin Percival BZ2_bzReadClose(&cbz2err, cpfbz2);
285ba10db99SColin Percival BZ2_bzReadClose(&dbz2err, dpfbz2);
286ba10db99SColin Percival BZ2_bzReadClose(&ebz2err, epfbz2);
287ba10db99SColin Percival if (fclose(cpf) || fclose(dpf) || fclose(epf))
288ba10db99SColin Percival err(1, "fclose(%s)", argv[3]);
289ba10db99SColin Percival
290ba10db99SColin Percival /* Write the new file */
291ce437befSEd Maste if (write(newfd, new, newsize) != newsize || close(newfd) == -1)
292ba10db99SColin Percival err(1, "%s", argv[2]);
29306ce2764SEd Maste /* Disable atexit cleanup */
29406ce2764SEd Maste newfile = NULL;
295ba10db99SColin Percival
296ba10db99SColin Percival free(new);
297ba10db99SColin Percival free(old);
298ba10db99SColin Percival
299ce437befSEd Maste return (0);
300ba10db99SColin Percival }
301