X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?a=blobdiff_plain;f=src%2Fimport%2Fimport-raw.c;h=5c88cdb007c836830a525a36855e8a9f942c4479;hb=4d858e7d9f39038713f760d7acc64acf7bba2aa7;hp=da72725f3cae9090c64548dedcd014393e4a9477;hpb=0716faad4a846d5f3cdce4bf37648d3254b9332f;p=elogind.git diff --git a/src/import/import-raw.c b/src/import/import-raw.c index da72725f3..5c88cdb00 100644 --- a/src/import/import-raw.c +++ b/src/import/import-raw.c @@ -22,241 +22,187 @@ #include #include #include -#include -#include "hashmap.h" +#include "sd-daemon.h" #include "utf8.h" +#include "strv.h" +#include "copy.h" +#include "btrfs-util.h" +#include "util.h" +#include "macro.h" +#include "mkdir.h" +#include "import-util.h" #include "curl-util.h" #include "qcow2-util.h" +#include "import-job.h" +#include "import-common.h" #include "import-raw.h" -#include "strv.h" -#include "copy.h" - -typedef struct RawImportFile RawImportFile; - -struct RawImportFile { - RawImport *import; - - char *url; - char *local; - - CURL *curl; - struct curl_slist *request_header; - - char *temp_path; - char *final_path; - char *etag; - char **old_etags; - uint64_t content_length; - uint64_t written_compressed; - uint64_t written_uncompressed; - - void *payload; - size_t payload_size; - - usec_t mtime; - - bool force_local; - bool done; - - int disk_fd; - - lzma_stream lzma; - bool compressed; - - unsigned progress_percent; - usec_t start_usec; - usec_t last_status_usec; -}; +typedef enum RawProgress { + RAW_DOWNLOADING, + RAW_VERIFYING, + RAW_UNPACKING, + RAW_FINALIZING, + RAW_COPYING, +} RawProgress; struct RawImport { sd_event *event; CurlGlue *glue; char *image_root; - Hashmap *files; - raw_import_on_finished on_finished; + ImportJob *raw_job; + ImportJob *checksum_job; + ImportJob *signature_job; + + RawImportFinished on_finished; void *userdata; - bool finished; -}; + char *local; + bool force_local; -#define FILENAME_ESCAPE "/.#\"\'" + char *temp_path; + char *final_path; -#define RAW_MAX_SIZE (1024LLU*1024LLU*1024LLU*8) /* 8 GB */ + ImportVerify verify; +}; -static RawImportFile *raw_import_file_unref(RawImportFile *f) { - if (!f) +RawImport* raw_import_unref(RawImport *i) { + if (!i) return NULL; - if (f->import) - curl_glue_remove_and_free(f->import->glue, f->curl); - curl_slist_free_all(f->request_header); - - safe_close(f->disk_fd); + import_job_unref(i->raw_job); + import_job_unref(i->checksum_job); + import_job_unref(i->signature_job); - free(f->final_path); + curl_glue_unref(i->glue); + sd_event_unref(i->event); - if (f->temp_path) { - unlink(f->temp_path); - free(f->temp_path); + if (i->temp_path) { + (void) unlink(i->temp_path); + free(i->temp_path); } - lzma_end(&f->lzma); - free(f->url); - free(f->local); - free(f->etag); - strv_free(f->old_etags); - free(f->payload); - free(f); + free(i->final_path); + free(i->image_root); + free(i->local); + free(i); return NULL; } -DEFINE_TRIVIAL_CLEANUP_FUNC(RawImportFile*, raw_import_file_unref); +int raw_import_new( + RawImport **ret, + sd_event *event, + const char *image_root, + RawImportFinished on_finished, + void *userdata) { -static void raw_import_finish(RawImport *import, int error) { - assert(import); - - if (import->finished) - return; - - import->finished = true; - - if (import->on_finished) - import->on_finished(import, error, import->userdata); - else - sd_event_exit(import->event, error); -} - -static int raw_import_file_make_final_path(RawImportFile *f) { - _cleanup_free_ char *escaped_url = NULL, *escaped_etag = NULL; - - assert(f); + _cleanup_(raw_import_unrefp) RawImport *i = NULL; + int r; - if (f->final_path) - return 0; + assert(ret); - escaped_url = xescape(f->url, FILENAME_ESCAPE); - if (!escaped_url) + i = new0(RawImport, 1); + if (!i) return -ENOMEM; - if (f->etag) { - escaped_etag = xescape(f->etag, FILENAME_ESCAPE); - if (!escaped_etag) - return -ENOMEM; + i->on_finished = on_finished; + i->userdata = userdata; - f->final_path = strjoin(f->import->image_root, "/.raw-", escaped_url, ".", escaped_etag, ".raw", NULL); - } else - f->final_path = strjoin(f->import->image_root, "/.raw-", escaped_url, ".raw", NULL); - if (!f->final_path) + i->image_root = strdup(image_root ?: "/var/lib/machines"); + if (!i->image_root) return -ENOMEM; - return 0; -} - -static int raw_import_file_make_local_copy(RawImportFile *f) { - _cleanup_free_ char *tp = NULL; - _cleanup_close_ int dfd = -1; - const char *p; - int r; + if (event) + i->event = sd_event_ref(event); + else { + r = sd_event_default(&i->event); + if (r < 0) + return r; + } - assert(f); + r = curl_glue_new(&i->glue, i->event); + if (r < 0) + return r; - if (!f->local) - return 0; + i->glue->on_finished = import_job_curl_on_finished; + i->glue->userdata = i; - if (f->disk_fd >= 0) { - if (lseek(f->disk_fd, SEEK_SET, 0) == (off_t) -1) - return log_error_errno(errno, "Failed to seek to beginning of vendor image: %m"); - } else { - r = raw_import_file_make_final_path(f); - if (r < 0) - return log_oom(); + *ret = i; + i = NULL; - f->disk_fd = open(f->final_path, O_RDONLY|O_NOCTTY|O_CLOEXEC); - if (f->disk_fd < 0) - return log_error_errno(errno, "Failed to open vendor image: %m"); - } + return 0; +} - p = strappenda(f->import->image_root, "/", f->local, ".raw"); - if (f->force_local) - (void) rm_rf_dangerous(p, false, true, false); +static void raw_import_report_progress(RawImport *i, RawProgress p) { + unsigned percent; - r = tempfn_random(p, &tp); - if (r < 0) - return log_oom(); + assert(i); - dfd = open(tp, O_WRONLY|O_CREAT|O_EXCL|O_NOCTTY|O_CLOEXEC, 0664); - if (dfd < 0) - return log_error_errno(errno, "Failed to create writable copy of image: %m"); + switch (p) { - /* Turn off COW writing. This should greatly improve - * performance on COW file systems like btrfs, since it - * reduces fragmentation caused by not allowing in-place - * writes. */ - r = chattr_fd(dfd, true, FS_NOCOW_FL); - if (r < 0) - log_warning_errno(errno, "Failed to set file attributes on %s: %m", tp); + case RAW_DOWNLOADING: { + unsigned remain = 80; - r = copy_bytes(f->disk_fd, dfd, (off_t) -1, true); - if (r < 0) { - unlink(tp); - return log_error_errno(r, "Failed to make writable copy of image: %m"); - } + percent = 0; - (void) copy_times(f->disk_fd, dfd); - (void) copy_xattr(f->disk_fd, dfd); + if (i->checksum_job) { + percent += i->checksum_job->progress_percent * 5 / 100; + remain -= 5; + } - dfd = safe_close(dfd); + if (i->signature_job) { + percent += i->signature_job->progress_percent * 5 / 100; + remain -= 5; + } - r = rename(tp, p); - if (r < 0) { - unlink(tp); - return log_error_errno(errno, "Failed to move writable image into place: %m"); + if (i->raw_job) + percent += i->raw_job->progress_percent * remain / 100; + break; } - log_info("Created new local image %s.", p); - return 0; -} - -static void raw_import_file_success(RawImportFile *f) { - int r; + case RAW_VERIFYING: + percent = 80; + break; - assert(f); + case RAW_UNPACKING: + percent = 85; + break; - f->done = true; + case RAW_FINALIZING: + percent = 90; + break; - r = raw_import_file_make_local_copy(f); - if (r < 0) - goto finish; + case RAW_COPYING: + percent = 95; + break; - f->disk_fd = safe_close(f->disk_fd); - r = 0; + default: + assert_not_reached("Unknown progress state"); + } -finish: - raw_import_finish(f->import, r); + sd_notifyf(false, "X_IMPORT_PROGRESS=%u", percent); + log_debug("Combined progress %u%%", percent); } -static int raw_import_maybe_convert_qcow2(RawImportFile *f) { +static int raw_import_maybe_convert_qcow2(RawImport *i) { _cleanup_close_ int converted_fd = -1; _cleanup_free_ char *t = NULL; int r; - assert(f); - assert(f->disk_fd); - assert(f->temp_path); + assert(i); + assert(i->raw_job); - r = qcow2_detect(f->disk_fd); + r = qcow2_detect(i->raw_job->disk_fd); if (r < 0) return log_error_errno(r, "Failed to detect whether this is a QCOW2 image: %m"); if (r == 0) return 0; /* This is a QCOW2 image, let's convert it */ - r = tempfn_random(f->final_path, &t); + r = tempfn_random(i->final_path, &t); if (r < 0) return log_oom(); @@ -264,697 +210,304 @@ static int raw_import_maybe_convert_qcow2(RawImportFile *f) { if (converted_fd < 0) return log_error_errno(errno, "Failed to create %s: %m", t); - r = qcow2_convert(f->disk_fd, converted_fd); + r = chattr_fd(converted_fd, true, FS_NOCOW_FL); + if (r < 0) + log_warning_errno(errno, "Failed to set file attributes on %s: %m", t); + + log_info("Unpacking QCOW2 file."); + + r = qcow2_convert(i->raw_job->disk_fd, converted_fd); if (r < 0) { unlink(t); return log_error_errno(r, "Failed to convert qcow2 image: %m"); } - unlink(f->temp_path); - free(f->temp_path); + unlink(i->temp_path); + free(i->temp_path); - f->temp_path = t; + i->temp_path = t; t = NULL; - safe_close(f->disk_fd); - f->disk_fd = converted_fd; + safe_close(i->raw_job->disk_fd); + i->raw_job->disk_fd = converted_fd; converted_fd = -1; return 1; } -static void raw_import_curl_on_finished(CurlGlue *g, CURL *curl, CURLcode result) { - RawImportFile *f = NULL; - struct stat st; - CURLcode code; - long status; +static int raw_import_make_local_copy(RawImport *i) { + _cleanup_free_ char *tp = NULL; + _cleanup_close_ int dfd = -1; + const char *p; int r; - if (curl_easy_getinfo(curl, CURLINFO_PRIVATE, &f) != CURLE_OK) - return; - - if (!f || f->done) - return; - - f->done = true; - - if (result != CURLE_OK) { - log_error("Transfer failed: %s", curl_easy_strerror(result)); - r = -EIO; - goto fail; - } - - code = curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &status); - if (code != CURLE_OK) { - log_error("Failed to retrieve response code: %s", curl_easy_strerror(code)); - r = -EIO; - goto fail; - } else if (status == 304) { - log_info("Image already downloaded. Skipping download."); - raw_import_file_success(f); - return; - } else if (status >= 300) { - log_error("HTTP request to %s failed with code %li.", f->url, status); - r = -EIO; - goto fail; - } else if (status < 200) { - log_error("HTTP request to %s finished with unexpected code %li.", f->url, status); - r = -EIO; - goto fail; - } - - if (f->disk_fd < 0) { - log_error("No data received."); - r = -EIO; - goto fail; - } + assert(i); + assert(i->raw_job); - if (f->content_length != (uint64_t) -1 && - f->content_length != f->written_compressed) { - log_error("Download truncated."); - r = -EIO; - goto fail; - } - - /* Make sure the file size is right, in case the file was - * sparse and we just seeked for the last part */ - if (ftruncate(f->disk_fd, f->written_uncompressed) < 0) { - log_error_errno(errno, "Failed to truncate file: %m"); - r = -errno; - goto fail; - } + if (!i->local) + return 0; - r = raw_import_maybe_convert_qcow2(f); - if (r < 0) - goto fail; + if (i->raw_job->etag_exists) { + /* We have downloaded this one previously, reopen it */ - if (f->etag) - (void) fsetxattr(f->disk_fd, "user.source_etag", f->etag, strlen(f->etag), 0); - if (f->url) - (void) fsetxattr(f->disk_fd, "user.source_url", f->url, strlen(f->url), 0); + assert(i->raw_job->disk_fd < 0); - if (f->mtime != 0) { - struct timespec ut[2]; + if (!i->final_path) { + r = import_make_path(i->raw_job->url, i->raw_job->etag, i->image_root, ".raw-", ".raw", &i->final_path); + if (r < 0) + return log_oom(); + } - timespec_store(&ut[0], f->mtime); - ut[1] = ut[0]; - (void) futimens(f->disk_fd, ut); + i->raw_job->disk_fd = open(i->final_path, O_RDONLY|O_NOCTTY|O_CLOEXEC); + if (i->raw_job->disk_fd < 0) + return log_error_errno(errno, "Failed to open vendor image: %m"); + } else { + /* We freshly downloaded the image, use it */ - fd_setcrtime(f->disk_fd, f->mtime); - } + assert(i->raw_job->disk_fd >= 0); - if (fstat(f->disk_fd, &st) < 0) { - r = log_error_errno(errno, "Failed to stat file: %m"); - goto fail; + if (lseek(i->raw_job->disk_fd, SEEK_SET, 0) == (off_t) -1) + return log_error_errno(errno, "Failed to seek to beginning of vendor image: %m"); } - /* Mark read-only */ - (void) fchmod(f->disk_fd, st.st_mode & 07444); - - assert(f->temp_path); - assert(f->final_path); + p = strappenda(i->image_root, "/", i->local, ".raw"); - r = rename(f->temp_path, f->final_path); - if (r < 0) { - r = log_error_errno(errno, "Failed to move RAW file into place: %m"); - goto fail; + if (i->force_local) { + (void) btrfs_subvol_remove(p); + (void) rm_rf_dangerous(p, false, true, false); } - free(f->temp_path); - f->temp_path = NULL; - - log_info("Completed writing vendor image %s.", f->final_path); - - raw_import_file_success(f); - return; - -fail: - raw_import_finish(f->import, r); -} - -static int raw_import_file_open_disk_for_write(RawImportFile *f) { - int r; - - assert(f); - - if (f->disk_fd >= 0) - return 0; - - r = raw_import_file_make_final_path(f); + r = tempfn_random(p, &tp); if (r < 0) return log_oom(); - if (!f->temp_path) { - r = tempfn_random(f->final_path, &f->temp_path); - if (r < 0) - return log_oom(); - } - - f->disk_fd = open(f->temp_path, O_RDWR|O_CREAT|O_EXCL|O_NOCTTY|O_CLOEXEC, 0644); - if (f->disk_fd < 0) - return log_error_errno(errno, "Failed to create %s: %m", f->temp_path); + dfd = open(tp, O_WRONLY|O_CREAT|O_EXCL|O_NOCTTY|O_CLOEXEC, 0664); + if (dfd < 0) + return log_error_errno(errno, "Failed to create writable copy of image: %m"); - r = chattr_fd(f->disk_fd, true, FS_NOCOW_FL); + /* Turn off COW writing. This should greatly improve + * performance on COW file systems like btrfs, since it + * reduces fragmentation caused by not allowing in-place + * writes. */ + r = chattr_fd(dfd, true, FS_NOCOW_FL); if (r < 0) - log_warning_errno(errno, "Failed to set file attributes on %s: %m", f->temp_path); - - return 0; -} - -static int raw_import_file_write_uncompressed(RawImportFile *f, void *p, size_t sz) { - ssize_t n; - - assert(f); - assert(p); - assert(sz > 0); - assert(f->disk_fd >= 0); - - if (f->written_uncompressed + sz < f->written_uncompressed) { - log_error("File too large, overflow"); - return -EOVERFLOW; - } - - if (f->written_uncompressed + sz > RAW_MAX_SIZE) { - log_error("File overly large, refusing"); - return -EFBIG; - } - - n = sparse_write(f->disk_fd, p, sz, 64); - if (n < 0) { - log_error_errno(errno, "Failed to write file: %m"); - return -errno; - } - if ((size_t) n < sz) { - log_error("Short write"); - return -EIO; - } - - f->written_uncompressed += sz; - - return 0; -} - -static int raw_import_file_write_compressed(RawImportFile *f, void *p, size_t sz) { - int r; - - assert(f); - assert(p); - assert(sz > 0); - assert(f->disk_fd >= 0); - - if (f->written_compressed + sz < f->written_compressed) { - log_error("File too large, overflow"); - return -EOVERFLOW; - } + log_warning_errno(errno, "Failed to set file attributes on %s: %m", tp); - if (f->content_length != (uint64_t) -1 && - f->written_compressed + sz > f->content_length) { - log_error("Content length incorrect."); - return -EFBIG; + r = copy_bytes(i->raw_job->disk_fd, dfd, (off_t) -1, true); + if (r < 0) { + unlink(tp); + return log_error_errno(r, "Failed to make writable copy of image: %m"); } - if (!f->compressed) { - r = raw_import_file_write_uncompressed(f, p, sz); - if (r < 0) - return r; - } else { - f->lzma.next_in = p; - f->lzma.avail_in = sz; - - while (f->lzma.avail_in > 0) { - uint8_t buffer[16 * 1024]; - lzma_ret lzr; - - f->lzma.next_out = buffer; - f->lzma.avail_out = sizeof(buffer); + (void) copy_times(i->raw_job->disk_fd, dfd); + (void) copy_xattr(i->raw_job->disk_fd, dfd); - lzr = lzma_code(&f->lzma, LZMA_RUN); - if (lzr != LZMA_OK && lzr != LZMA_STREAM_END) { - log_error("Decompression error."); - return -EIO; - } + dfd = safe_close(dfd); - r = raw_import_file_write_uncompressed(f, buffer, sizeof(buffer) - f->lzma.avail_out); - if (r < 0) - return r; - } + r = rename(tp, p); + if (r < 0) { + unlink(tp); + return log_error_errno(errno, "Failed to move writable image into place: %m"); } - f->written_compressed += sz; - + log_info("Created new local image '%s'.", i->local); return 0; } -static int raw_import_file_detect_xz(RawImportFile *f) { - static const uint8_t xz_signature[] = { - '\xfd', '7', 'z', 'X', 'Z', '\x00' - }; - lzma_ret lzr; - int r; - - assert(f); - - if (f->payload_size < sizeof(xz_signature)) - return 0; - - f->compressed = memcmp(f->payload, xz_signature, sizeof(xz_signature)) == 0; - log_debug("Stream is XZ compressed: %s", yes_no(f->compressed)); - - if (f->compressed) { - lzr = lzma_stream_decoder(&f->lzma, UINT64_MAX, LZMA_TELL_UNSUPPORTED_CHECK); - if (lzr != LZMA_OK) { - log_error("Failed to initialize LZMA decoder."); - return -EIO; - } - } - - r = raw_import_file_open_disk_for_write(f); - if (r < 0) - return r; - - r = raw_import_file_write_compressed(f, f->payload, f->payload_size); - if (r < 0) - return r; +static bool raw_import_is_done(RawImport *i) { + assert(i); + assert(i->raw_job); - free(f->payload); - f->payload = NULL; - f->payload_size = 0; + if (i->raw_job->state != IMPORT_JOB_DONE) + return false; + if (i->checksum_job && i->checksum_job->state != IMPORT_JOB_DONE) + return false; + if (i->signature_job && i->signature_job->state != IMPORT_JOB_DONE) + return false; - return 0; + return true; } -static size_t raw_import_file_write_callback(void *contents, size_t size, size_t nmemb, void *userdata) { - RawImportFile *f = userdata; - size_t sz = size * nmemb; +static void raw_import_job_on_finished(ImportJob *j) { + RawImport *i; int r; - assert(contents); - assert(f); + assert(j); + assert(j->userdata); + + i = j->userdata; + if (j->error != 0) { + if (j == i->checksum_job) + log_error_errno(j->error, "Failed to retrieve SHA256 checksum, cannot verify. (Try --verify=no?)"); + else if (j == i->signature_job) + log_error_errno(j->error, "Failed to retrieve signature file, cannot verify. (Try --verify=no?)"); + else + log_error_errno(j->error, "Failed to retrieve image file. (Wrong URL?)"); - if (f->done) { - r = -ESTALE; - goto fail; + r = j->error; + goto finish; } - if (f->disk_fd < 0) { - uint8_t *p; + /* This is invoked if either the download completed + * successfully, or the download was skipped because we + * already have the etag. In this case ->etag_exists is + * true. + * + * We only do something when we got all three files */ - /* We haven't opened the file yet, let's first check what it actually is */ + if (!raw_import_is_done(i)) + return; - p = realloc(f->payload, f->payload_size + sz); - if (!p) { - r = log_oom(); - goto fail; - } + if (!i->raw_job->etag_exists) { + /* This is a new download, verify it, and move it into place */ + assert(i->raw_job->disk_fd >= 0); - memcpy(p + f->payload_size, contents, sz); - f->payload_size = sz; - f->payload = p; + raw_import_report_progress(i, RAW_VERIFYING); - r = raw_import_file_detect_xz(f); + r = import_verify(i->raw_job, i->checksum_job, i->signature_job); if (r < 0) - goto fail; - - return sz; - } - - r = raw_import_file_write_compressed(f, contents, sz); - if (r < 0) - goto fail; + goto finish; - return sz; + raw_import_report_progress(i, RAW_UNPACKING); -fail: - raw_import_finish(f->import, r); - return 0; -} - -static size_t raw_import_file_header_callback(void *contents, size_t size, size_t nmemb, void *userdata) { - RawImportFile *f = userdata; - size_t sz = size * nmemb; - _cleanup_free_ char *length = NULL, *last_modified = NULL; - char *etag; - int r; + r = raw_import_maybe_convert_qcow2(i); + if (r < 0) + goto finish; - assert(contents); - assert(f); + raw_import_report_progress(i, RAW_FINALIZING); - if (f->done) { - r = -ESTALE; - goto fail; - } + r = import_make_read_only_fd(i->raw_job->disk_fd); + if (r < 0) + goto finish; - r = curl_header_strdup(contents, sz, "ETag:", &etag); - if (r < 0) { - log_oom(); - goto fail; - } - if (r > 0) { - free(f->etag); - f->etag = etag; - - if (strv_contains(f->old_etags, f->etag)) { - log_info("Image already downloaded. Skipping download."); - raw_import_file_success(f); - return sz; + r = rename(i->temp_path, i->final_path); + if (r < 0) { + r = log_error_errno(errno, "Failed to move RAW file into place: %m"); + goto finish; } - return sz; - } - - r = curl_header_strdup(contents, sz, "Content-Length:", &length); - if (r < 0) { - log_oom(); - goto fail; + free(i->temp_path); + i->temp_path = NULL; } - if (r > 0) { - (void) safe_atou64(length, &f->content_length); - - if (f->content_length != (uint64_t) -1) { - char bytes[FORMAT_BYTES_MAX]; - log_info("Downloading %s.", format_bytes(bytes, sizeof(bytes), f->content_length)); - } - return sz; - } + raw_import_report_progress(i, RAW_COPYING); - r = curl_header_strdup(contents, sz, "Last-Modified:", &last_modified); - if (r < 0) { - log_oom(); - goto fail; - } - if (r > 0) { - (void) curl_parse_http_time(last_modified, &f->mtime); - return sz; - } + r = raw_import_make_local_copy(i); + if (r < 0) + goto finish; - return sz; + r = 0; -fail: - raw_import_finish(f->import, r); - return 0; +finish: + if (i->on_finished) + i->on_finished(i, r, i->userdata); + else + sd_event_exit(i->event, r); } -static int raw_import_file_progress_callback(void *userdata, curl_off_t dltotal, curl_off_t dlnow, curl_off_t ultotal, curl_off_t ulnow) { - RawImportFile *f = userdata; - unsigned percent; - usec_t n; - - assert(f); +static int raw_import_job_on_open_disk(ImportJob *j) { + RawImport *i; + int r; - if (dltotal <= 0) - return 0; + assert(j); + assert(j->userdata); - percent = ((100 * dlnow) / dltotal); - n = now(CLOCK_MONOTONIC); + i = j->userdata; + assert(i->raw_job == j); + assert(!i->final_path); + assert(!i->temp_path); - if (n > f->last_status_usec + USEC_PER_SEC && - percent != f->progress_percent) { - char buf[FORMAT_TIMESPAN_MAX]; + r = import_make_path(j->url, j->etag, i->image_root, ".raw-", ".raw", &i->final_path); + if (r < 0) + return log_oom(); - if (n - f->start_usec > USEC_PER_SEC && dlnow > 0) { - usec_t left, done; + r = tempfn_random(i->final_path, &i->temp_path); + if (r <0) + return log_oom(); - done = n - f->start_usec; - left = (usec_t) (((double) done * (double) dltotal) / dlnow) - done; + mkdir_parents_label(i->temp_path, 0700); - log_info("Got %u%%. %s left.", percent, format_timespan(buf, sizeof(buf), left, USEC_PER_SEC)); - } else - log_info("Got %u%%.", percent); + j->disk_fd = open(i->temp_path, O_RDWR|O_CREAT|O_EXCL|O_NOCTTY|O_CLOEXEC, 0644); + if (j->disk_fd < 0) + return log_error_errno(errno, "Failed to create %s: %m", i->temp_path); - f->progress_percent = percent; - f->last_status_usec = n; - } + r = chattr_fd(j->disk_fd, true, FS_NOCOW_FL); + if (r < 0) + log_warning_errno(errno, "Failed to set file attributes on %s: %m", i->temp_path); return 0; } -static bool etag_is_valid(const char *etag) { +static void raw_import_job_on_progress(ImportJob *j) { + RawImport *i; - if (!endswith(etag, "\"")) - return false; + assert(j); + assert(j->userdata); - if (!startswith(etag, "\"") && !startswith(etag, "W/\"")) - return false; + i = j->userdata; - return true; + raw_import_report_progress(i, RAW_DOWNLOADING); } -static int raw_import_file_find_old_etags(RawImportFile *f) { - _cleanup_free_ char *escaped_url = NULL; - _cleanup_closedir_ DIR *d = NULL; - struct dirent *de; +int raw_import_pull(RawImport *i, const char *url, const char *local, bool force_local, ImportVerify verify) { int r; - escaped_url = xescape(f->url, FILENAME_ESCAPE); - if (!escaped_url) - return -ENOMEM; - - d = opendir(f->import->image_root); - if (!d) { - if (errno == ENOENT) - return 0; - - return -errno; - } + assert(i); + assert(verify < _IMPORT_VERIFY_MAX); + assert(verify >= 0); - FOREACH_DIRENT_ALL(de, d, return -errno) { - const char *a, *b; - char *u; + if (!http_url_is_valid(url)) + return -EINVAL; - if (de->d_type != DT_UNKNOWN && - de->d_type != DT_REG) - continue; + if (local && !machine_name_is_valid(local)) + return -EINVAL; - a = startswith(de->d_name, ".raw-"); - if (!a) - continue; - - a = startswith(a, escaped_url); - if (!a) - continue; - - a = startswith(a, "."); - if (!a) - continue; - - b = endswith(de->d_name, ".raw"); - if (!b) - continue; - - if (a >= b) - continue; - - u = cunescape_length(a, b - a); - if (!u) - return -ENOMEM; - - if (!etag_is_valid(u)) { - free(u); - continue; - } - - r = strv_consume(&f->old_etags, u); - if (r < 0) - return r; - } + if (i->raw_job) + return -EBUSY; - return 0; -} - -static int raw_import_file_begin(RawImportFile *f) { - int r; - - assert(f); - assert(!f->curl); - - log_info("Getting %s.", f->url); - - r = raw_import_file_find_old_etags(f); + r = free_and_strdup(&i->local, local); if (r < 0) return r; + i->force_local = force_local; + i->verify = verify; - r = curl_glue_make(&f->curl, f->url, f); + /* Queue job for the image itself */ + r = import_job_new(&i->raw_job, url, i->glue, i); if (r < 0) return r; - if (!strv_isempty(f->old_etags)) { - _cleanup_free_ char *cc = NULL, *hdr = NULL; - - cc = strv_join(f->old_etags, ", "); - if (!cc) - return -ENOMEM; - - hdr = strappend("If-None-Match: ", cc); - if (!hdr) - return -ENOMEM; - - f->request_header = curl_slist_new(hdr, NULL); - if (!f->request_header) - return -ENOMEM; - - if (curl_easy_setopt(f->curl, CURLOPT_HTTPHEADER, f->request_header) != CURLE_OK) - return -EIO; - } + i->raw_job->on_finished = raw_import_job_on_finished; + i->raw_job->on_open_disk = raw_import_job_on_open_disk; + i->raw_job->on_progress = raw_import_job_on_progress; + i->raw_job->calc_checksum = verify != IMPORT_VERIFY_NO; - if (curl_easy_setopt(f->curl, CURLOPT_WRITEFUNCTION, raw_import_file_write_callback) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_WRITEDATA, f) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_HEADERFUNCTION, raw_import_file_header_callback) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_HEADERDATA, f) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_XFERINFOFUNCTION, raw_import_file_progress_callback) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_XFERINFODATA, f) != CURLE_OK) - return -EIO; - - if (curl_easy_setopt(f->curl, CURLOPT_NOPROGRESS, 0) != CURLE_OK) - return -EIO; - - r = curl_glue_add(f->import->glue, f->curl); + r = import_find_old_etags(url, i->image_root, DT_REG, ".raw-", ".raw", &i->raw_job->old_etags); if (r < 0) return r; - return 0; -} - -int raw_import_new(RawImport **import, sd_event *event, const char *image_root, raw_import_on_finished on_finished, void *userdata) { - _cleanup_(raw_import_unrefp) RawImport *i = NULL; - int r; - - assert(import); - assert(image_root); - - i = new0(RawImport, 1); - if (!i) - return -ENOMEM; - - i->on_finished = on_finished; - i->userdata = userdata; - - i->image_root = strdup(image_root); - if (!i->image_root) - return -ENOMEM; - - if (event) - i->event = sd_event_ref(event); - else { - r = sd_event_default(&i->event); - if (r < 0) - return r; - } - - r = curl_glue_new(&i->glue, i->event); + r = import_make_verification_jobs(&i->checksum_job, &i->signature_job, verify, url, i->glue, raw_import_job_on_finished, i); if (r < 0) return r; - i->glue->on_finished = raw_import_curl_on_finished; - i->glue->userdata = i; - - *import = i; - i = NULL; - - return 0; -} - -RawImport* raw_import_unref(RawImport *import) { - RawImportFile *f; - - if (!import) - return NULL; - - while ((f = hashmap_steal_first(import->files))) - raw_import_file_unref(f); - hashmap_free(import->files); - - curl_glue_unref(import->glue); - sd_event_unref(import->event); - - free(import->image_root); - free(import); - - return NULL; -} - -int raw_import_cancel(RawImport *import, const char *url) { - RawImportFile *f; - - assert(import); - assert(url); - - f = hashmap_remove(import->files, url); - if (!f) - return 0; - - raw_import_file_unref(f); - return 1; -} - -int raw_import_pull(RawImport *import, const char *url, const char *local, bool force_local) { - _cleanup_(raw_import_file_unrefp) RawImportFile *f = NULL; - int r; - - assert(import); - assert(raw_url_is_valid(url)); - assert(!local || machine_name_is_valid(local)); - - if (hashmap_get(import->files, url)) - return -EEXIST; - - r = hashmap_ensure_allocated(&import->files, &string_hash_ops); + r = import_job_begin(i->raw_job); if (r < 0) return r; - f = new0(RawImportFile, 1); - if (!f) - return -ENOMEM; - - f->import = import; - f->disk_fd = -1; - f->content_length = (uint64_t) -1; - f->start_usec = now(CLOCK_MONOTONIC); + if (i->checksum_job) { + i->checksum_job->on_progress = raw_import_job_on_progress; - f->url = strdup(url); - if (!f->url) - return -ENOMEM; - - if (local) { - f->local = strdup(local); - if (!f->local) - return -ENOMEM; - - f->force_local = force_local; + r = import_job_begin(i->checksum_job); + if (r < 0) + return r; } - r = hashmap_put(import->files, f->url, f); - if (r < 0) - return r; + if (i->signature_job) { + i->signature_job->on_progress = raw_import_job_on_progress; - r = raw_import_file_begin(f); - if (r < 0) { - raw_import_cancel(import, f->url); - f = NULL; - return r; + r = import_job_begin(i->signature_job); + if (r < 0) + return r; } - f = NULL; return 0; } - -bool raw_url_is_valid(const char *url) { - if (isempty(url)) - return false; - - if (!startswith(url, "http://") && - !startswith(url, "https://")) - return false; - - return ascii_is_valid(url); -}