receive-pack.c 42.9 KB
Newer Older
1
#include "builtin.h"
2
#include "lockfile.h"
3
#include "pack.h"
4
#include "refs.h"
5
#include "pkt-line.h"
6
#include "sideband.h"
7
#include "run-command.h"
8
#include "exec_cmd.h"
9 10
#include "commit.h"
#include "object.h"
11
#include "remote.h"
12
#include "connect.h"
13
#include "transport.h"
14
#include "string-list.h"
15
#include "sha1-array.h"
16
#include "connected.h"
17
#include "argv-array.h"
18
#include "version.h"
19 20
#include "tag.h"
#include "gpg-interface.h"
21
#include "sigchain.h"
22

23
static const char receive_pack_usage[] = "git receive-pack <git-dir>";
24

25
enum deny_action {
26
	DENY_UNCONFIGURED,
27 28
	DENY_IGNORE,
	DENY_WARN,
29 30
	DENY_REFUSE,
	DENY_UPDATE_INSTEAD
31 32
};

33 34
static int deny_deletes;
static int deny_non_fast_forwards;
35
static enum deny_action deny_current_branch = DENY_UNCONFIGURED;
36
static enum deny_action deny_delete_current = DENY_UNCONFIGURED;
37 38
static int receive_fsck_objects = -1;
static int transfer_fsck_objects = -1;
39 40
static int receive_unpack_limit = -1;
static int transfer_unpack_limit = -1;
41
static int advertise_atomic_push = 1;
42
static int unpack_limit = 100;
43
static int report_status;
44
static int use_sideband;
45
static int use_atomic;
46
static int quiet;
47
static int prefer_ofs_delta = 1;
48 49
static int auto_update_server_info;
static int auto_gc = 1;
50
static int fix_thin = 1;
51 52
static int stateless_rpc;
static const char *service_dir;
53
static const char *head_name;
54
static void *head_name_to_free;
55
static int sent_capabilities;
56
static int shallow_update;
57
static const char *alt_shallow_file;
58 59
static struct strbuf push_cert = STRBUF_INIT;
static unsigned char push_cert_sha1[20];
60
static struct signature_check sigcheck;
61 62 63 64 65 66 67
static const char *push_cert_nonce;
static const char *cert_nonce_seed;

static const char *NONCE_UNSOLICITED = "UNSOLICITED";
static const char *NONCE_BAD = "BAD";
static const char *NONCE_MISSING = "MISSING";
static const char *NONCE_OK = "OK";
68
static const char *NONCE_SLOP = "SLOP";
69
static const char *nonce_status;
70 71
static long nonce_stamp_slop;
static unsigned long nonce_stamp_slop_limit;
72
static struct ref_transaction *transaction;
73

74 75 76 77 78 79 80 81 82
static enum deny_action parse_deny_action(const char *var, const char *value)
{
	if (value) {
		if (!strcasecmp(value, "ignore"))
			return DENY_IGNORE;
		if (!strcasecmp(value, "warn"))
			return DENY_WARN;
		if (!strcasecmp(value, "refuse"))
			return DENY_REFUSE;
83 84
		if (!strcasecmp(value, "updateinstead"))
			return DENY_UPDATE_INSTEAD;
85 86 87 88 89 90
	}
	if (git_config_bool(var, value))
		return DENY_REFUSE;
	return DENY_IGNORE;
}

91
static int receive_pack_config(const char *var, const char *value, void *cb)
92
{
93 94 95 96 97
	int status = parse_hide_refs_config(var, value, "receive");

	if (status)
		return status;

J
Jan Krüger 已提交
98 99 100 101 102
	if (strcmp(var, "receive.denydeletes") == 0) {
		deny_deletes = git_config_bool(var, value);
		return 0;
	}

103
	if (strcmp(var, "receive.denynonfastforwards") == 0) {
104 105 106 107
		deny_non_fast_forwards = git_config_bool(var, value);
		return 0;
	}

108 109
	if (strcmp(var, "receive.unpacklimit") == 0) {
		receive_unpack_limit = git_config_int(var, value);
110 111 112
		return 0;
	}

113 114 115 116 117
	if (strcmp(var, "transfer.unpacklimit") == 0) {
		transfer_unpack_limit = git_config_int(var, value);
		return 0;
	}

118 119 120 121 122
	if (strcmp(var, "receive.fsckobjects") == 0) {
		receive_fsck_objects = git_config_bool(var, value);
		return 0;
	}

123 124 125 126 127
	if (strcmp(var, "transfer.fsckobjects") == 0) {
		transfer_fsck_objects = git_config_bool(var, value);
		return 0;
	}

128 129 130 131 132
	if (!strcmp(var, "receive.denycurrentbranch")) {
		deny_current_branch = parse_deny_action(var, value);
		return 0;
	}

133 134 135 136 137
	if (strcmp(var, "receive.denydeletecurrent") == 0) {
		deny_delete_current = parse_deny_action(var, value);
		return 0;
	}

138 139 140 141 142
	if (strcmp(var, "repack.usedeltabaseoffset") == 0) {
		prefer_ofs_delta = git_config_bool(var, value);
		return 0;
	}

143 144 145 146 147 148 149 150 151 152
	if (strcmp(var, "receive.updateserverinfo") == 0) {
		auto_update_server_info = git_config_bool(var, value);
		return 0;
	}

	if (strcmp(var, "receive.autogc") == 0) {
		auto_gc = git_config_bool(var, value);
		return 0;
	}

153 154 155 156 157
	if (strcmp(var, "receive.shallowupdate") == 0) {
		shallow_update = git_config_bool(var, value);
		return 0;
	}

158 159
	if (strcmp(var, "receive.certnonceseed") == 0)
		return git_config_string(&cert_nonce_seed, var, value);
160

161 162 163 164 165
	if (strcmp(var, "receive.certnonceslop") == 0) {
		nonce_stamp_slop_limit = git_config_ulong(var, value);
		return 0;
	}

166 167 168 169 170
	if (strcmp(var, "receive.advertiseatomic") == 0) {
		advertise_atomic_push = git_config_bool(var, value);
		return 0;
	}

171
	return git_default_config(var, value, cb);
172 173
}

174
static void show_ref(const char *path, const unsigned char *sha1)
175
{
176 177 178
	if (ref_is_hidden(path))
		return;

179
	if (sent_capabilities) {
180
		packet_write(1, "%s %s\n", sha1_to_hex(sha1), path);
181 182 183 184 185
	} else {
		struct strbuf cap = STRBUF_INIT;

		strbuf_addstr(&cap,
			      "report-status delete-refs side-band-64k quiet");
186 187
		if (advertise_atomic_push)
			strbuf_addstr(&cap, " atomic");
188 189
		if (prefer_ofs_delta)
			strbuf_addstr(&cap, " ofs-delta");
190 191
		if (push_cert_nonce)
			strbuf_addf(&cap, " push-cert=%s", push_cert_nonce);
192 193 194 195 196 197
		strbuf_addf(&cap, " agent=%s", git_user_agent_sanitized());
		packet_write(1, "%s %s%c%s\n",
			     sha1_to_hex(sha1), path, 0, cap.buf);
		strbuf_release(&cap);
		sent_capabilities = 1;
	}
198 199
}

200
static int show_ref_cb(const char *path, const unsigned char *sha1, int flag, void *unused)
201 202 203 204 205 206 207 208 209 210 211 212
{
	path = strip_namespace(path);
	/*
	 * Advertise refs outside our current namespace as ".have"
	 * refs, so that the client can use them to minimize data
	 * transfer but will otherwise ignore them. This happens to
	 * cover ".have" that are thrown in by add_one_alternate_ref()
	 * to mark histories that are complete in our alternates as
	 * well.
	 */
	if (!path)
		path = ".have";
213 214
	show_ref(path, sha1);
	return 0;
215 216
}

217
static void show_one_alternate_sha1(const unsigned char sha1[20], void *unused)
218
{
219
	show_ref(".have", sha1);
220 221 222 223 224 225
}

static void collect_one_alternate_ref(const struct ref *ref, void *data)
{
	struct sha1_array *sa = data;
	sha1_array_append(sa, ref->old_sha1);
226 227
}

228
static void write_head_info(void)
229
{
230 231
	struct sha1_array sa = SHA1_ARRAY_INIT;
	for_each_alternate_ref(collect_one_alternate_ref, &sa);
232
	sha1_array_for_each_unique(&sa, show_one_alternate_sha1, NULL);
233
	sha1_array_clear(&sa);
234
	for_each_ref(show_ref_cb, NULL);
235
	if (!sent_capabilities)
236
		show_ref("capabilities^{}", null_sha1);
237

238 239
	advertise_shallow_grafts(1);

240 241
	/* EOF */
	packet_flush(1);
242 243
}

244 245
struct command {
	struct command *next;
246
	const char *error_string;
247 248
	unsigned int skip_update:1,
		     did_not_exist:1;
249
	int index;
250 251
	unsigned char old_sha1[20];
	unsigned char new_sha1[20];
252
	char ref_name[FLEX_ARRAY]; /* more */
253 254
};

255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290
static void rp_error(const char *err, ...) __attribute__((format (printf, 1, 2)));
static void rp_warning(const char *err, ...) __attribute__((format (printf, 1, 2)));

static void report_message(const char *prefix, const char *err, va_list params)
{
	int sz = strlen(prefix);
	char msg[4096];

	strncpy(msg, prefix, sz);
	sz += vsnprintf(msg + sz, sizeof(msg) - sz, err, params);
	if (sz > (sizeof(msg) - 1))
		sz = sizeof(msg) - 1;
	msg[sz++] = '\n';

	if (use_sideband)
		send_sideband(1, 2, msg, sz, use_sideband);
	else
		xwrite(2, msg, sz);
}

static void rp_warning(const char *err, ...)
{
	va_list params;
	va_start(params, err);
	report_message("warning: ", err, params);
	va_end(params);
}

static void rp_error(const char *err, ...)
{
	va_list params;
	va_start(params, err);
	report_message("error: ", err, params);
	va_end(params);
}

291 292 293 294 295 296 297 298 299 300 301 302 303
static int copy_to_sideband(int in, int out, void *arg)
{
	char data[128];
	while (1) {
		ssize_t sz = xread(in, data, sizeof(data));
		if (sz <= 0)
			break;
		send_sideband(1, 2, data, sz, use_sideband);
	}
	close(in);
	return 0;
}

304 305
#define HMAC_BLOCK_SIZE 64

306
static void hmac_sha1(unsigned char *out,
307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340
		      const char *key_in, size_t key_len,
		      const char *text, size_t text_len)
{
	unsigned char key[HMAC_BLOCK_SIZE];
	unsigned char k_ipad[HMAC_BLOCK_SIZE];
	unsigned char k_opad[HMAC_BLOCK_SIZE];
	int i;
	git_SHA_CTX ctx;

	/* RFC 2104 2. (1) */
	memset(key, '\0', HMAC_BLOCK_SIZE);
	if (HMAC_BLOCK_SIZE < key_len) {
		git_SHA1_Init(&ctx);
		git_SHA1_Update(&ctx, key_in, key_len);
		git_SHA1_Final(key, &ctx);
	} else {
		memcpy(key, key_in, key_len);
	}

	/* RFC 2104 2. (2) & (5) */
	for (i = 0; i < sizeof(key); i++) {
		k_ipad[i] = key[i] ^ 0x36;
		k_opad[i] = key[i] ^ 0x5c;
	}

	/* RFC 2104 2. (3) & (4) */
	git_SHA1_Init(&ctx);
	git_SHA1_Update(&ctx, k_ipad, sizeof(k_ipad));
	git_SHA1_Update(&ctx, text, text_len);
	git_SHA1_Final(out, &ctx);

	/* RFC 2104 2. (6) & (7) */
	git_SHA1_Init(&ctx);
	git_SHA1_Update(&ctx, k_opad, sizeof(k_opad));
341
	git_SHA1_Update(&ctx, out, 20);
342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386
	git_SHA1_Final(out, &ctx);
}

static char *prepare_push_cert_nonce(const char *path, unsigned long stamp)
{
	struct strbuf buf = STRBUF_INIT;
	unsigned char sha1[20];

	strbuf_addf(&buf, "%s:%lu", path, stamp);
	hmac_sha1(sha1, buf.buf, buf.len, cert_nonce_seed, strlen(cert_nonce_seed));;
	strbuf_release(&buf);

	/* RFC 2104 5. HMAC-SHA1-80 */
	strbuf_addf(&buf, "%lu-%.*s", stamp, 20, sha1_to_hex(sha1));
	return strbuf_detach(&buf, NULL);
}

/*
 * NEEDSWORK: reuse find_commit_header() from jk/commit-author-parsing
 * after dropping "_commit" from its name and possibly moving it out
 * of commit.c
 */
static char *find_header(const char *msg, size_t len, const char *key)
{
	int key_len = strlen(key);
	const char *line = msg;

	while (line && line < msg + len) {
		const char *eol = strchrnul(line, '\n');

		if ((msg + len <= eol) || line == eol)
			return NULL;
		if (line + key_len < eol &&
		    !memcmp(line, key, key_len) && line[key_len] == ' ') {
			int offset = key_len + 1;
			return xmemdupz(line + offset, (eol - line) - offset);
		}
		line = *eol ? eol + 1 : NULL;
	}
	return NULL;
}

static const char *check_nonce(const char *buf, size_t len)
{
	char *nonce = find_header(buf, len, "nonce");
387 388
	unsigned long stamp, ostamp;
	char *bohmac, *expect = NULL;
389 390 391 392 393 394 395 396 397 398 399 400 401
	const char *retval = NONCE_BAD;

	if (!nonce) {
		retval = NONCE_MISSING;
		goto leave;
	} else if (!push_cert_nonce) {
		retval = NONCE_UNSOLICITED;
		goto leave;
	} else if (!strcmp(push_cert_nonce, nonce)) {
		retval = NONCE_OK;
		goto leave;
	}

402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446
	if (!stateless_rpc) {
		/* returned nonce MUST match what we gave out earlier */
		retval = NONCE_BAD;
		goto leave;
	}

	/*
	 * In stateless mode, we may be receiving a nonce issued by
	 * another instance of the server that serving the same
	 * repository, and the timestamps may not match, but the
	 * nonce-seed and dir should match, so we can recompute and
	 * report the time slop.
	 *
	 * In addition, when a nonce issued by another instance has
	 * timestamp within receive.certnonceslop seconds, we pretend
	 * as if we issued that nonce when reporting to the hook.
	 */

	/* nonce is concat(<seconds-since-epoch>, "-", <hmac>) */
	if (*nonce <= '0' || '9' < *nonce) {
		retval = NONCE_BAD;
		goto leave;
	}
	stamp = strtoul(nonce, &bohmac, 10);
	if (bohmac == nonce || bohmac[0] != '-') {
		retval = NONCE_BAD;
		goto leave;
	}

	expect = prepare_push_cert_nonce(service_dir, stamp);
	if (strcmp(expect, nonce)) {
		/* Not what we would have signed earlier */
		retval = NONCE_BAD;
		goto leave;
	}

	/*
	 * By how many seconds is this nonce stale?  Negative value
	 * would mean it was issued by another server with its clock
	 * skewed in the future.
	 */
	ostamp = strtoul(push_cert_nonce, NULL, 10);
	nonce_stamp_slop = (long)ostamp - (long)stamp;

	if (nonce_stamp_slop_limit &&
447
	    labs(nonce_stamp_slop) <= nonce_stamp_slop_limit) {
448 449 450 451 452 453 454 455 456 457 458
		/*
		 * Pretend as if the received nonce (which passes the
		 * HMAC check, so it is not a forged by third-party)
		 * is what we issued.
		 */
		free((void *)push_cert_nonce);
		push_cert_nonce = xstrdup(nonce);
		retval = NONCE_OK;
	} else {
		retval = NONCE_SLOP;
	}
459 460 461

leave:
	free(nonce);
462
	free(expect);
463 464 465
	return retval;
}

466 467 468 469 470 471 472 473
static void prepare_push_cert_sha1(struct child_process *proc)
{
	static int already_done;

	if (!push_cert.len)
		return;

	if (!already_done) {
474 475 476 477
		struct strbuf gpg_output = STRBUF_INIT;
		struct strbuf gpg_status = STRBUF_INIT;
		int bogs /* beginning_of_gpg_sig */;

478 479 480
		already_done = 1;
		if (write_sha1_file(push_cert.buf, push_cert.len, "blob", push_cert_sha1))
			hashclr(push_cert_sha1);
481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498

		memset(&sigcheck, '\0', sizeof(sigcheck));
		sigcheck.result = 'N';

		bogs = parse_signature(push_cert.buf, push_cert.len);
		if (verify_signed_buffer(push_cert.buf, bogs,
					 push_cert.buf + bogs, push_cert.len - bogs,
					 &gpg_output, &gpg_status) < 0) {
			; /* error running gpg */
		} else {
			sigcheck.payload = push_cert.buf;
			sigcheck.gpg_output = gpg_output.buf;
			sigcheck.gpg_status = gpg_status.buf;
			parse_gpg_output(&sigcheck);
		}

		strbuf_release(&gpg_output);
		strbuf_release(&gpg_status);
499
		nonce_status = check_nonce(push_cert.buf, bogs);
500 501
	}
	if (!is_null_sha1(push_cert_sha1)) {
502 503 504
		argv_array_pushf(&proc->env_array, "GIT_PUSH_CERT=%s",
				 sha1_to_hex(push_cert_sha1));
		argv_array_pushf(&proc->env_array, "GIT_PUSH_CERT_SIGNER=%s",
505
				 sigcheck.signer ? sigcheck.signer : "");
506
		argv_array_pushf(&proc->env_array, "GIT_PUSH_CERT_KEY=%s",
507
				 sigcheck.key ? sigcheck.key : "");
508 509
		argv_array_pushf(&proc->env_array, "GIT_PUSH_CERT_STATUS=%c",
				 sigcheck.result);
510
		if (push_cert_nonce) {
511 512 513 514 515 516
			argv_array_pushf(&proc->env_array,
					 "GIT_PUSH_CERT_NONCE=%s",
					 push_cert_nonce);
			argv_array_pushf(&proc->env_array,
					 "GIT_PUSH_CERT_NONCE_STATUS=%s",
					 nonce_status);
517
			if (nonce_status == NONCE_SLOP)
518 519
				argv_array_pushf(&proc->env_array,
						 "GIT_PUSH_CERT_NONCE_SLOP=%ld",
520
						 nonce_stamp_slop);
521
		}
522 523 524
	}
}

J
Junio C Hamano 已提交
525 526
typedef int (*feed_fn)(void *, const char **, size_t *);
static int run_and_feed_hook(const char *hook_name, feed_fn feed, void *feed_state)
527
{
528
	struct child_process proc = CHILD_PROCESS_INIT;
529
	struct async muxer;
530
	const char *argv[2];
J
Junio C Hamano 已提交
531
	int code;
532

533 534
	argv[0] = find_hook(hook_name);
	if (!argv[0])
535
		return 0;
536

537 538 539 540 541 542
	argv[1] = NULL;

	proc.argv = argv;
	proc.in = -1;
	proc.stdout_to_stderr = 1;

543 544 545 546 547 548 549 550 551 552
	if (use_sideband) {
		memset(&muxer, 0, sizeof(muxer));
		muxer.proc = copy_to_sideband;
		muxer.in = -1;
		code = start_async(&muxer);
		if (code)
			return code;
		proc.err = muxer.in;
	}

553 554
	prepare_push_cert_sha1(&proc);

555
	code = start_command(&proc);
556 557 558
	if (code) {
		if (use_sideband)
			finish_async(&muxer);
559
		return code;
560 561
	}

562 563
	sigchain_push(SIGPIPE, SIG_IGN);

J
Junio C Hamano 已提交
564 565 566 567 568 569 570
	while (1) {
		const char *buf;
		size_t n;
		if (feed(feed_state, &buf, &n))
			break;
		if (write_in_full(proc.in, buf, n) != n)
			break;
571
	}
572
	close(proc.in);
573 574
	if (use_sideband)
		finish_async(&muxer);
575 576 577

	sigchain_pop(SIGPIPE);

578
	return finish_command(&proc);
579 580
}

J
Junio C Hamano 已提交
581 582
struct receive_hook_feed_state {
	struct command *cmd;
583
	int skip_broken;
J
Junio C Hamano 已提交
584 585 586 587 588 589 590 591
	struct strbuf buf;
};

static int feed_receive_hook(void *state_, const char **bufp, size_t *sizep)
{
	struct receive_hook_feed_state *state = state_;
	struct command *cmd = state->cmd;

592 593
	while (cmd &&
	       state->skip_broken && (cmd->error_string || cmd->did_not_exist))
J
Junio C Hamano 已提交
594 595 596 597 598 599 600 601 602 603 604 605 606 607 608
		cmd = cmd->next;
	if (!cmd)
		return -1; /* EOF */
	strbuf_reset(&state->buf);
	strbuf_addf(&state->buf, "%s %s %s\n",
		    sha1_to_hex(cmd->old_sha1), sha1_to_hex(cmd->new_sha1),
		    cmd->ref_name);
	state->cmd = cmd->next;
	if (bufp) {
		*bufp = state->buf.buf;
		*sizep = state->buf.len;
	}
	return 0;
}

609 610
static int run_receive_hook(struct command *commands, const char *hook_name,
			    int skip_broken)
J
Junio C Hamano 已提交
611 612 613 614 615 616
{
	struct receive_hook_feed_state state;
	int status;

	strbuf_init(&state.buf, 0);
	state.cmd = commands;
617
	state.skip_broken = skip_broken;
J
Junio C Hamano 已提交
618 619 620 621 622 623 624 625
	if (feed_receive_hook(&state, NULL, NULL))
		return 0;
	state.cmd = commands;
	status = run_and_feed_hook(hook_name, feed_receive_hook, &state);
	strbuf_release(&state.buf);
	return status;
}

626 627 628
static int run_update_hook(struct command *cmd)
{
	const char *argv[5];
629
	struct child_process proc = CHILD_PROCESS_INIT;
630
	int code;
631

632 633
	argv[0] = find_hook("update");
	if (!argv[0])
634 635 636 637 638 639 640
		return 0;

	argv[1] = cmd->ref_name;
	argv[2] = sha1_to_hex(cmd->old_sha1);
	argv[3] = sha1_to_hex(cmd->new_sha1);
	argv[4] = NULL;

641 642 643 644 645 646 647 648 649 650 651
	proc.no_stdin = 1;
	proc.stdout_to_stderr = 1;
	proc.err = use_sideband ? -1 : 0;
	proc.argv = argv;

	code = start_command(&proc);
	if (code)
		return code;
	if (use_sideband)
		copy_to_sideband(proc.err, -1, NULL);
	return finish_command(&proc);
652 653
}

654 655 656 657 658
static int is_ref_checked_out(const char *ref)
{
	if (is_bare_repository())
		return 0;

659
	if (!head_name)
660
		return 0;
661
	return !strcmp(head_name, ref);
662 663
}

664 665 666 667 668
static char *refuse_unconfigured_deny_msg[] = {
	"By default, updating the current branch in a non-bare repository",
	"is denied, because it will make the index and work tree inconsistent",
	"with what you pushed, and will require 'git reset --hard' to match",
	"the work tree to HEAD.",
669 670
	"",
	"You can set 'receive.denyCurrentBranch' configuration variable to",
671 672 673 674
	"'ignore' or 'warn' in the remote repository to allow pushing into",
	"its current branch; however, this is not recommended unless you",
	"arranged to update its work tree to match what you pushed in some",
	"other way.",
675
	"",
676 677
	"To squelch this message and still keep the default behaviour, set",
	"'receive.denyCurrentBranch' configuration variable to 'refuse'."
678 679
};

680
static void refuse_unconfigured_deny(void)
681 682
{
	int i;
683
	for (i = 0; i < ARRAY_SIZE(refuse_unconfigured_deny_msg); i++)
684
		rp_error("%s", refuse_unconfigured_deny_msg[i]);
685 686
}

687 688 689
static char *refuse_unconfigured_deny_delete_current_msg[] = {
	"By default, deleting the current branch is denied, because the next",
	"'git clone' won't result in any file checked out, causing confusion.",
690 691
	"",
	"You can set 'receive.denyDeleteCurrent' configuration variable to",
692 693
	"'warn' or 'ignore' in the remote repository to allow deleting the",
	"current branch, with or without a warning message.",
694
	"",
695
	"To squelch this message, you can set it to 'refuse'."
696 697
};

698
static void refuse_unconfigured_deny_delete_current(void)
699 700 701
{
	int i;
	for (i = 0;
702
	     i < ARRAY_SIZE(refuse_unconfigured_deny_delete_current_msg);
703
	     i++)
704
		rp_error("%s", refuse_unconfigured_deny_delete_current_msg[i]);
705 706
}

707 708 709 710 711 712 713 714 715
static int command_singleton_iterator(void *cb_data, unsigned char sha1[20]);
static int update_shallow_ref(struct command *cmd, struct shallow_info *si)
{
	static struct lock_file shallow_lock;
	struct sha1_array extra = SHA1_ARRAY_INIT;
	const char *alt_file;
	uint32_t mask = 1 << (cmd->index % 32);
	int i;

K
Karsten Blees 已提交
716
	trace_printf_key(&trace_shallow,
717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745
			 "shallow: update_shallow_ref %s\n", cmd->ref_name);
	for (i = 0; i < si->shallow->nr; i++)
		if (si->used_shallow[i] &&
		    (si->used_shallow[i][cmd->index / 32] & mask) &&
		    !delayed_reachability_test(si, i))
			sha1_array_append(&extra, si->shallow->sha1[i]);

	setup_alternate_shallow(&shallow_lock, &alt_file, &extra);
	if (check_shallow_connected(command_singleton_iterator,
				    0, cmd, alt_file)) {
		rollback_lock_file(&shallow_lock);
		sha1_array_clear(&extra);
		return -1;
	}

	commit_lock_file(&shallow_lock);

	/*
	 * Make sure setup_alternate_shallow() for the next ref does
	 * not lose these new roots..
	 */
	for (i = 0; i < extra.nr; i++)
		register_shallow(extra.sha1[i]);

	si->shallow_ref[cmd->index] = 0;
	sha1_array_clear(&extra);
	return 0;
}

746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823
static const char *update_worktree(unsigned char *sha1)
{
	const char *update_refresh[] = {
		"update-index", "-q", "--ignore-submodules", "--refresh", NULL
	};
	const char *diff_files[] = {
		"diff-files", "--quiet", "--ignore-submodules", "--", NULL
	};
	const char *diff_index[] = {
		"diff-index", "--quiet", "--cached", "--ignore-submodules",
		"HEAD", "--", NULL
	};
	const char *read_tree[] = {
		"read-tree", "-u", "-m", NULL, NULL
	};
	const char *work_tree = git_work_tree_cfg ? git_work_tree_cfg : "..";
	struct argv_array env = ARGV_ARRAY_INIT;
	struct child_process child = CHILD_PROCESS_INIT;

	if (is_bare_repository())
		return "denyCurrentBranch = updateInstead needs a worktree";

	argv_array_pushf(&env, "GIT_DIR=%s", absolute_path(get_git_dir()));

	child.argv = update_refresh;
	child.env = env.argv;
	child.dir = work_tree;
	child.no_stdin = 1;
	child.stdout_to_stderr = 1;
	child.git_cmd = 1;
	if (run_command(&child)) {
		argv_array_clear(&env);
		return "Up-to-date check failed";
	}

	/* run_command() does not clean up completely; reinitialize */
	child_process_init(&child);
	child.argv = diff_files;
	child.env = env.argv;
	child.dir = work_tree;
	child.no_stdin = 1;
	child.stdout_to_stderr = 1;
	child.git_cmd = 1;
	if (run_command(&child)) {
		argv_array_clear(&env);
		return "Working directory has unstaged changes";
	}

	child_process_init(&child);
	child.argv = diff_index;
	child.env = env.argv;
	child.no_stdin = 1;
	child.no_stdout = 1;
	child.stdout_to_stderr = 0;
	child.git_cmd = 1;
	if (run_command(&child)) {
		argv_array_clear(&env);
		return "Working directory has staged changes";
	}

	read_tree[3] = sha1_to_hex(sha1);
	child_process_init(&child);
	child.argv = read_tree;
	child.env = env.argv;
	child.dir = work_tree;
	child.no_stdin = 1;
	child.no_stdout = 1;
	child.stdout_to_stderr = 0;
	child.git_cmd = 1;
	if (run_command(&child)) {
		argv_array_clear(&env);
		return "Could not update working tree to new HEAD";
	}

	argv_array_clear(&env);
	return NULL;
}

824
static const char *update(struct command *cmd, struct shallow_info *si)
825
{
826
	const char *name = cmd->ref_name;
827
	struct strbuf namespaced_name_buf = STRBUF_INIT;
828
	const char *namespaced_name, *ret;
829 830
	unsigned char *old_sha1 = cmd->old_sha1;
	unsigned char *new_sha1 = cmd->new_sha1;
831

832
	/* only refs/... are allowed */
833
	if (!starts_with(name, "refs/") || check_refname_format(name + 5, 0)) {
834
		rp_error("refusing to create funny ref '%s' remotely", name);
835
		return "funny refname";
836
	}
837

838 839 840 841
	strbuf_addf(&namespaced_name_buf, "%s%s", get_git_namespace(), name);
	namespaced_name = strbuf_detach(&namespaced_name_buf, NULL);

	if (is_ref_checked_out(namespaced_name)) {
842 843
		switch (deny_current_branch) {
		case DENY_IGNORE:
844
			break;
845
		case DENY_WARN:
846
			rp_warning("updating the current branch");
847
			break;
848
		case DENY_REFUSE:
849
		case DENY_UNCONFIGURED:
850
			rp_error("refusing to update checked out branch: %s", name);
851 852
			if (deny_current_branch == DENY_UNCONFIGURED)
				refuse_unconfigured_deny();
853
			return "branch is currently checked out";
854 855 856 857 858
		case DENY_UPDATE_INSTEAD:
			ret = update_worktree(new_sha1);
			if (ret)
				return ret;
			break;
859
		}
860 861
	}

862
	if (!is_null_sha1(new_sha1) && !has_sha1_file(new_sha1)) {
863 864 865
		error("unpack should have generated %s, "
		      "but I can't find it!", sha1_to_hex(new_sha1));
		return "bad pack";
866
	}
867 868

	if (!is_null_sha1(old_sha1) && is_null_sha1(new_sha1)) {
869
		if (deny_deletes && starts_with(name, "refs/heads/")) {
870
			rp_error("denying ref deletion for %s", name);
871 872 873
			return "deletion prohibited";
		}

874
		if (!strcmp(namespaced_name, head_name)) {
875 876 877 878
			switch (deny_delete_current) {
			case DENY_IGNORE:
				break;
			case DENY_WARN:
879
				rp_warning("deleting the current branch");
880 881
				break;
			case DENY_REFUSE:
882
			case DENY_UNCONFIGURED:
883
			case DENY_UPDATE_INSTEAD:
884 885
				if (deny_delete_current == DENY_UNCONFIGURED)
					refuse_unconfigured_deny_delete_current();
886
				rp_error("refusing to delete the current branch: %s", name);
887
				return "deletion of the current branch prohibited";
888 889
			default:
				return "Invalid denyDeleteCurrent setting";
890 891
			}
		}
J
Jan Krüger 已提交
892
	}
893

894
	if (deny_non_fast_forwards && !is_null_sha1(new_sha1) &&
J
Junio C Hamano 已提交
895
	    !is_null_sha1(old_sha1) &&
896
	    starts_with(name, "refs/heads/")) {
897
		struct object *old_object, *new_object;
898 899
		struct commit *old_commit, *new_commit;

900 901 902 903 904 905 906 907 908 909 910
		old_object = parse_object(old_sha1);
		new_object = parse_object(new_sha1);

		if (!old_object || !new_object ||
		    old_object->type != OBJ_COMMIT ||
		    new_object->type != OBJ_COMMIT) {
			error("bad sha1 objects for %s", name);
			return "bad ref";
		}
		old_commit = (struct commit *)old_object;
		new_commit = (struct commit *)new_object;
911
		if (!in_merge_bases(old_commit, new_commit)) {
912 913
			rp_error("denying non-fast-forward %s"
				 " (you should pull first)", name);
914
			return "non-fast-forward";
915
		}
916
	}
917
	if (run_update_hook(cmd)) {
918
		rp_error("hook declined to update %s", name);
919
		return "hook declined";
920
	}
921

922
	if (is_null_sha1(new_sha1)) {
923
		struct strbuf err = STRBUF_INIT;
924 925
		if (!parse_object(old_sha1)) {
			old_sha1 = NULL;
926 927 928 929 930 931
			if (ref_exists(name)) {
				rp_warning("Allowing deletion of corrupt ref.");
			} else {
				rp_warning("Deleting a non-existent ref.");
				cmd->did_not_exist = 1;
			}
932
		}
933 934 935 936 937 938 939
		if (ref_transaction_delete(transaction,
					   namespaced_name,
					   old_sha1,
					   0, old_sha1 != NULL,
					   "push", &err)) {
			rp_error("%s", err.buf);
			strbuf_release(&err);
940
			return "failed to delete";
941
		}
942
		strbuf_release(&err);
943
		return NULL; /* good */
944 945
	}
	else {
946
		struct strbuf err = STRBUF_INIT;
947 948 949 950
		if (shallow_update && si->shallow_ref[cmd->index] &&
		    update_shallow_ref(cmd, si))
			return "shallow error";

951 952 953 954 955
		if (ref_transaction_update(transaction,
					   namespaced_name,
					   new_sha1, old_sha1,
					   0, 1, "push",
					   &err)) {
956 957
			rp_error("%s", err.buf);
			strbuf_release(&err);
958

959
			return "failed to update ref";
960
		}
961
		strbuf_release(&err);
962

963
		return NULL; /* good */
J
Junio C Hamano 已提交
964
	}
965 966
}

967
static void run_update_post_hook(struct command *commands)
J
Junio C Hamano 已提交
968
{
969
	struct command *cmd;
970
	int argc;
J
Junio C Hamano 已提交
971
	const char **argv;
972
	struct child_process proc = CHILD_PROCESS_INIT;
973
	char *hook;
J
Junio C Hamano 已提交
974

975
	hook = find_hook("post-update");
976
	for (argc = 0, cmd = commands; cmd; cmd = cmd->next) {
977
		if (cmd->error_string || cmd->did_not_exist)
J
Junio C Hamano 已提交
978 979 980
			continue;
		argc++;
	}
981
	if (!argc || !hook)
982
		return;
983

984
	argv = xmalloc(sizeof(*argv) * (2 + argc));
985
	argv[0] = hook;
J
Junio C Hamano 已提交
986

987
	for (argc = 1, cmd = commands; cmd; cmd = cmd->next) {
988
		if (cmd->error_string || cmd->did_not_exist)
J
Junio C Hamano 已提交
989
			continue;
990
		argv[argc] = xstrdup(cmd->ref_name);
J
Junio C Hamano 已提交
991 992 993
		argc++;
	}
	argv[argc] = NULL;
994 995 996 997 998 999 1000 1001 1002 1003 1004

	proc.no_stdin = 1;
	proc.stdout_to_stderr = 1;
	proc.err = use_sideband ? -1 : 0;
	proc.argv = argv;

	if (!start_command(&proc)) {
		if (use_sideband)
			copy_to_sideband(proc.err, -1, NULL);
		finish_command(&proc);
	}
J
Junio C Hamano 已提交
1005
}
1006

1007 1008
static void check_aliased_update(struct command *cmd, struct string_list *list)
{
1009 1010
	struct strbuf buf = STRBUF_INIT;
	const char *dst_name;
1011 1012 1013 1014 1015 1016
	struct string_list_item *item;
	struct command *dst_cmd;
	unsigned char sha1[20];
	char cmd_oldh[41], cmd_newh[41], dst_oldh[41], dst_newh[41];
	int flag;

1017
	strbuf_addf(&buf, "%s%s", get_git_namespace(), cmd->ref_name);
1018
	dst_name = resolve_ref_unsafe(buf.buf, 0, sha1, &flag);
1019
	strbuf_release(&buf);
1020 1021 1022 1023

	if (!(flag & REF_ISSYMREF))
		return;

1024 1025 1026 1027 1028 1029 1030 1031
	dst_name = strip_namespace(dst_name);
	if (!dst_name) {
		rp_error("refusing update to broken symref '%s'", cmd->ref_name);
		cmd->skip_update = 1;
		cmd->error_string = "broken symref";
		return;
	}

1032
	if ((item = string_list_lookup(list, dst_name)) == NULL)
1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045
		return;

	cmd->skip_update = 1;

	dst_cmd = (struct command *) item->util;

	if (!hashcmp(cmd->old_sha1, dst_cmd->old_sha1) &&
	    !hashcmp(cmd->new_sha1, dst_cmd->new_sha1))
		return;

	dst_cmd->skip_update = 1;

	strcpy(cmd_oldh, find_unique_abbrev(cmd->old_sha1, DEFAULT_ABBREV));
1046
	strcpy(cmd_newh, find_unique_abbrev(cmd->new_sha1, DEFAULT_ABBREV));
1047
	strcpy(dst_oldh, find_unique_abbrev(dst_cmd->old_sha1, DEFAULT_ABBREV));
1048
	strcpy(dst_newh, find_unique_abbrev(dst_cmd->new_sha1, DEFAULT_ABBREV));
1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060
	rp_error("refusing inconsistent update between symref '%s' (%s..%s) and"
		 " its target '%s' (%s..%s)",
		 cmd->ref_name, cmd_oldh, cmd_newh,
		 dst_cmd->ref_name, dst_oldh, dst_newh);

	cmd->error_string = dst_cmd->error_string =
		"inconsistent aliased update";
}

static void check_aliased_updates(struct command *commands)
{
	struct command *cmd;
1061
	struct string_list ref_list = STRING_LIST_INIT_NODUP;
1062 1063 1064

	for (cmd = commands; cmd; cmd = cmd->next) {
		struct string_list_item *item =
1065
			string_list_append(&ref_list, cmd->ref_name);
1066 1067
		item->util = (void *)cmd;
	}
1068
	string_list_sort(&ref_list);
1069

1070 1071 1072 1073
	for (cmd = commands; cmd; cmd = cmd->next) {
		if (!cmd->error_string)
			check_aliased_update(cmd, &ref_list);
	}
1074 1075 1076 1077

	string_list_clear(&ref_list, 0);
}

1078 1079 1080 1081 1082
static int command_singleton_iterator(void *cb_data, unsigned char sha1[20])
{
	struct command **cmd_list = cb_data;
	struct command *cmd = *cmd_list;

1083
	if (!cmd || is_null_sha1(cmd->new_sha1))
1084 1085 1086 1087 1088 1089
		return -1; /* end of list */
	*cmd_list = NULL; /* this returns only one */
	hashcpy(sha1, cmd->new_sha1);
	return 0;
}

1090 1091
static void set_connectivity_errors(struct command *commands,
				    struct shallow_info *si)
1092 1093 1094 1095 1096
{
	struct command *cmd;

	for (cmd = commands; cmd; cmd = cmd->next) {
		struct command *singleton = cmd;
1097 1098 1099
		if (shallow_update && si->shallow_ref[cmd->index])
			/* to be checked in update_shallow_ref() */
			continue;
1100 1101 1102 1103 1104 1105 1106
		if (!check_everything_connected(command_singleton_iterator,
						0, &singleton))
			continue;
		cmd->error_string = "missing necessary objects";
	}
}

1107 1108 1109 1110 1111
struct iterate_data {
	struct command *cmds;
	struct shallow_info *si;
};

1112 1113
static int iterate_receive_command_list(void *cb_data, unsigned char sha1[20])
{
1114 1115
	struct iterate_data *data = cb_data;
	struct command **cmd_list = &data->cmds;
1116 1117
	struct command *cmd = *cmd_list;

1118 1119 1120 1121
	for (; cmd; cmd = cmd->next) {
		if (shallow_update && data->si->shallow_ref[cmd->index])
			/* to be checked in update_shallow_ref() */
			continue;
1122
		if (!is_null_sha1(cmd->new_sha1) && !cmd->skip_update) {
1123 1124 1125 1126 1127 1128 1129
			hashcpy(sha1, cmd->new_sha1);
			*cmd_list = cmd->next;
			return 0;
		}
	}
	*cmd_list = NULL;
	return -1; /* end of list */
1130 1131
}

1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145
static void reject_updates_to_hidden(struct command *commands)
{
	struct command *cmd;

	for (cmd = commands; cmd; cmd = cmd->next) {
		if (cmd->error_string || !ref_is_hidden(cmd->ref_name))
			continue;
		if (is_null_sha1(cmd->new_sha1))
			cmd->error_string = "deny deleting a hidden ref";
		else
			cmd->error_string = "deny updating a hidden ref";
	}
}

1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164
static int should_process_cmd(struct command *cmd)
{
	return !cmd->error_string && !cmd->skip_update;
}

static void warn_if_skipped_connectivity_check(struct command *commands,
					       struct shallow_info *si)
{
	struct command *cmd;
	int checked_connectivity = 1;

	for (cmd = commands; cmd; cmd = cmd->next) {
		if (should_process_cmd(cmd) && si->shallow_ref[cmd->index]) {
			error("BUG: connectivity check has not been run on ref %s",
			      cmd->ref_name);
			checked_connectivity = 0;
		}
	}
	if (!checked_connectivity)
1165
		die("BUG: connectivity check skipped???");
1166 1167
}

1168 1169 1170 1171
static void execute_commands_non_atomic(struct command *commands,
					struct shallow_info *si)
{
	struct command *cmd;
1172 1173
	struct strbuf err = STRBUF_INIT;

1174 1175 1176 1177
	for (cmd = commands; cmd; cmd = cmd->next) {
		if (!should_process_cmd(cmd))
			continue;

1178 1179 1180 1181 1182 1183 1184 1185
		transaction = ref_transaction_begin(&err);
		if (!transaction) {
			rp_error("%s", err.buf);
			strbuf_reset(&err);
			cmd->error_string = "transaction failed to start";
			continue;
		}

1186
		cmd->error_string = update(cmd, si);
1187 1188 1189 1190 1191 1192 1193 1194

		if (!cmd->error_string
		    && ref_transaction_commit(transaction, &err)) {
			rp_error("%s", err.buf);
			strbuf_reset(&err);
			cmd->error_string = "failed to update ref";
		}
		ref_transaction_free(transaction);
1195
	}
1196 1197
	strbuf_release(&err);
}
1198

1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237
static void execute_commands_atomic(struct command *commands,
					struct shallow_info *si)
{
	struct command *cmd;
	struct strbuf err = STRBUF_INIT;
	const char *reported_error = "atomic push failure";

	transaction = ref_transaction_begin(&err);
	if (!transaction) {
		rp_error("%s", err.buf);
		strbuf_reset(&err);
		reported_error = "transaction failed to start";
		goto failure;
	}

	for (cmd = commands; cmd; cmd = cmd->next) {
		if (!should_process_cmd(cmd))
			continue;

		cmd->error_string = update(cmd, si);

		if (cmd->error_string)
			goto failure;
	}

	if (ref_transaction_commit(transaction, &err)) {
		rp_error("%s", err.buf);
		reported_error = "atomic transaction failed";
		goto failure;
	}
	goto cleanup;

failure:
	for (cmd = commands; cmd; cmd = cmd->next)
		if (!cmd->error_string)
			cmd->error_string = reported_error;

cleanup:
	ref_transaction_free(transaction);
1238
	strbuf_release(&err);
1239 1240
}

1241 1242 1243
static void execute_commands(struct command *commands,
			     const char *unpacker_error,
			     struct shallow_info *si)
1244
{
1245
	struct command *cmd;
1246
	unsigned char sha1[20];
1247
	struct iterate_data data;
1248 1249

	if (unpacker_error) {
1250
		for (cmd = commands; cmd; cmd = cmd->next)
1251
			cmd->error_string = "unpacker error";
1252 1253 1254
		return;
	}

1255 1256 1257 1258
	data.cmds = commands;
	data.si = si;
	if (check_everything_connected(iterate_receive_command_list, 0, &data))
		set_connectivity_errors(commands, si);
1259

1260 1261
	reject_updates_to_hidden(commands);

1262
	if (run_receive_hook(commands, "pre-receive", 0)) {
1263 1264 1265 1266
		for (cmd = commands; cmd; cmd = cmd->next) {
			if (!cmd->error_string)
				cmd->error_string = "pre-receive hook declined";
		}
1267 1268 1269
		return;
	}

1270 1271
	check_aliased_updates(commands);

1272
	free(head_name_to_free);
1273
	head_name = head_name_to_free = resolve_refdup("HEAD", 0, sha1, NULL);
1274

1275 1276 1277 1278
	if (use_atomic)
		execute_commands_atomic(commands, si);
	else
		execute_commands_non_atomic(commands, si);
1279

1280 1281
	if (shallow_update)
		warn_if_skipped_connectivity_check(commands, si);
1282 1283
}

1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310
static struct command **queue_command(struct command **tail,
				      const char *line,
				      int linelen)
{
	unsigned char old_sha1[20], new_sha1[20];
	struct command *cmd;
	const char *refname;
	int reflen;

	if (linelen < 83 ||
	    line[40] != ' ' ||
	    line[81] != ' ' ||
	    get_sha1_hex(line, old_sha1) ||
	    get_sha1_hex(line + 41, new_sha1))
		die("protocol error: expected old/new/ref, got '%s'", line);

	refname = line + 82;
	reflen = linelen - 82;
	cmd = xcalloc(1, sizeof(struct command) + reflen + 1);
	hashcpy(cmd->old_sha1, old_sha1);
	hashcpy(cmd->new_sha1, new_sha1);
	memcpy(cmd->ref_name, refname, reflen);
	cmd->ref_name[reflen] = '\0';
	*tail = cmd;
	return &cmd->next;
}

1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332
static void queue_commands_from_cert(struct command **tail,
				     struct strbuf *push_cert)
{
	const char *boc, *eoc;

	if (*tail)
		die("protocol error: got both push certificate and unsigned commands");

	boc = strstr(push_cert->buf, "\n\n");
	if (!boc)
		die("malformed push certificate %.*s", 100, push_cert->buf);
	else
		boc += 2;
	eoc = push_cert->buf + parse_signature(push_cert->buf, push_cert->len);

	while (boc < eoc) {
		const char *eol = memchr(boc, '\n', eoc - boc);
		tail = queue_command(tail, boc, eol ? eol - boc : eoc - eol);
		boc = eol ? eol + 1 : eoc;
	}
}

1333
static struct command *read_head_info(struct sha1_array *shallow)
1334
{
1335
	struct command *commands = NULL;
1336
	struct command **p = &commands;
1337
	for (;;) {
1338
		char *line;
1339
		int len, linelen;
1340

1341 1342
		line = packet_read_line(0, &len);
		if (!line)
1343
			break;
1344

J
Junio C Hamano 已提交
1345
		if (len == 48 && starts_with(line, "shallow ")) {
1346 1347 1348 1349 1350
			unsigned char sha1[20];
			if (get_sha1_hex(line + 8, sha1))
				die("protocol error: expected shallow sha, got '%s'",
				    line + 8);
			sha1_array_append(shallow, sha1);
1351 1352 1353
			continue;
		}

1354 1355 1356
		linelen = strlen(line);
		if (linelen < len) {
			const char *feature_list = line + linelen + 1;
1357
			if (parse_feature_request(feature_list, "report-status"))
1358
				report_status = 1;
1359
			if (parse_feature_request(feature_list, "side-band-64k"))
1360
				use_sideband = LARGE_PACKET_MAX;
1361 1362
			if (parse_feature_request(feature_list, "quiet"))
				quiet = 1;
1363 1364 1365
			if (advertise_atomic_push
			    && parse_feature_request(feature_list, "atomic"))
				use_atomic = 1;
1366
		}
1367

1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388
		if (!strcmp(line, "push-cert")) {
			int true_flush = 0;
			char certbuf[1024];

			for (;;) {
				len = packet_read(0, NULL, NULL,
						  certbuf, sizeof(certbuf), 0);
				if (!len) {
					true_flush = 1;
					break;
				}
				if (!strcmp(certbuf, "push-cert-end\n"))
					break; /* end of cert */
				strbuf_addstr(&push_cert, certbuf);
			}

			if (true_flush)
				break;
			continue;
		}

1389
		p = queue_command(p, line, linelen);
1390
	}
1391 1392 1393 1394

	if (push_cert.len)
		queue_commands_from_cert(p, &push_cert);

1395
	return commands;
1396 1397
}

1398 1399
static const char *parse_pack_header(struct pack_header *hdr)
{
1400 1401 1402 1403 1404
	switch (read_pack_header(0, hdr)) {
	case PH_ERROR_EOF:
		return "eof before pack header was fully read";

	case PH_ERROR_PACK_SIGNATURE:
1405
		return "protocol error (pack signature mismatch detected)";
1406 1407

	case PH_ERROR_PROTOCOL:
1408
		return "protocol error (pack version unsupported)";
1409 1410 1411 1412 1413 1414 1415

	default:
		return "unknown error in parse_pack_header";

	case 0:
		return NULL;
	}
1416 1417
}

1418 1419
static const char *pack_lockfile;

1420
static const char *unpack(int err_fd, struct shallow_info *si)
1421
{
1422 1423
	struct pack_header hdr;
	const char *hdr_err;
1424
	int status;
1425
	char hdr_arg[38];
1426
	struct child_process child = CHILD_PROCESS_INIT;
1427 1428 1429 1430 1431
	int fsck_objects = (receive_fsck_objects >= 0
			    ? receive_fsck_objects
			    : transfer_fsck_objects >= 0
			    ? transfer_fsck_objects
			    : 0);
1432 1433

	hdr_err = parse_pack_header(&hdr);
1434 1435 1436
	if (hdr_err) {
		if (err_fd > 0)
			close(err_fd);
1437
		return hdr_err;
1438
	}
1439 1440
	snprintf(hdr_arg, sizeof(hdr_arg),
			"--pack_header=%"PRIu32",%"PRIu32,
1441 1442
			ntohl(hdr.hdr_version), ntohl(hdr.hdr_entries));

1443 1444
	if (si->nr_ours || si->nr_theirs) {
		alt_shallow_file = setup_temporary_shallow(si->shallow);
1445 1446
		argv_array_push(&child.args, "--shallow-file");
		argv_array_push(&child.args, alt_shallow_file);
1447 1448
	}

1449
	if (ntohl(hdr.hdr_entries) < unpack_limit) {
1450
		argv_array_pushl(&child.args, "unpack-objects", hdr_arg, NULL);
1451
		if (quiet)
1452
			argv_array_push(&child.args, "-q");
1453
		if (fsck_objects)
1454
			argv_array_push(&child.args, "--strict");
1455
		child.no_stdout = 1;
1456
		child.err = err_fd;
1457
		child.git_cmd = 1;
1458 1459 1460
		status = run_command(&child);
		if (status)
			return "unpack-objects abnormal exit";
1461
	} else {
1462
		int s;
1463 1464
		char keep_arg[256];

1465
		s = sprintf(keep_arg, "--keep=receive-pack %"PRIuMAX" on ", (uintmax_t) getpid());
1466 1467 1468
		if (gethostname(keep_arg + s, sizeof(keep_arg) - s))
			strcpy(keep_arg + s, "localhost");

1469
		argv_array_pushl(&child.args, "index-pack",
1470
				 "--stdin", hdr_arg, keep_arg, NULL);
1471
		if (fsck_objects)
1472
			argv_array_push(&child.args, "--strict");
1473
		if (fix_thin)
1474
			argv_array_push(&child.args, "--fix-thin");
1475 1476 1477 1478 1479
		child.out = -1;
		child.err = err_fd;
		child.git_cmd = 1;
		status = start_command(&child);
		if (status)
1480
			return "index-pack fork failed";
1481 1482 1483 1484 1485 1486
		pack_lockfile = index_pack_lockfile(child.out);
		close(child.out);
		status = finish_command(&child);
		if (status)
			return "index-pack abnormal exit";
		reprepare_packed_git();
1487
	}
1488
	return NULL;
1489 1490
}

1491
static const char *unpack_with_sideband(struct shallow_info *si)
1492 1493 1494 1495 1496
{
	struct async muxer;
	const char *ret;

	if (!use_sideband)
1497
		return unpack(0, si);
1498 1499 1500 1501 1502 1503 1504

	memset(&muxer, 0, sizeof(muxer));
	muxer.proc = copy_to_sideband;
	muxer.in = -1;
	if (start_async(&muxer))
		return NULL;

1505
	ret = unpack(muxer.in, si);
1506 1507 1508 1509 1510

	finish_async(&muxer);
	return ret;
}

1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557
static void prepare_shallow_update(struct command *commands,
				   struct shallow_info *si)
{
	int i, j, k, bitmap_size = (si->ref->nr + 31) / 32;

	si->used_shallow = xmalloc(sizeof(*si->used_shallow) *
				   si->shallow->nr);
	assign_shallow_commits_to_refs(si, si->used_shallow, NULL);

	si->need_reachability_test =
		xcalloc(si->shallow->nr, sizeof(*si->need_reachability_test));
	si->reachable =
		xcalloc(si->shallow->nr, sizeof(*si->reachable));
	si->shallow_ref = xcalloc(si->ref->nr, sizeof(*si->shallow_ref));

	for (i = 0; i < si->nr_ours; i++)
		si->need_reachability_test[si->ours[i]] = 1;

	for (i = 0; i < si->shallow->nr; i++) {
		if (!si->used_shallow[i])
			continue;
		for (j = 0; j < bitmap_size; j++) {
			if (!si->used_shallow[i][j])
				continue;
			si->need_reachability_test[i]++;
			for (k = 0; k < 32; k++)
				if (si->used_shallow[i][j] & (1 << k))
					si->shallow_ref[j * 32 + k]++;
		}

		/*
		 * true for those associated with some refs and belong
		 * in "ours" list aka "step 7 not done yet"
		 */
		si->need_reachability_test[i] =
			si->need_reachability_test[i] > 1;
	}

	/*
	 * keep hooks happy by forcing a temporary shallow file via
	 * env variable because we can't add --shallow-file to every
	 * command. check_everything_connected() will be done with
	 * true .git/shallow though.
	 */
	setenv(GIT_SHALLOW_FILE_ENVIRONMENT, alt_shallow_file, 1);
}

1558 1559 1560 1561 1562 1563 1564
static void update_shallow_info(struct command *commands,
				struct shallow_info *si,
				struct sha1_array *ref)
{
	struct command *cmd;
	int *ref_status;
	remove_nonexistent_theirs_shallow(si);
1565 1566
	if (!si->nr_ours && !si->nr_theirs) {
		shallow_update = 0;
1567
		return;
1568
	}
1569 1570 1571 1572 1573 1574 1575 1576 1577

	for (cmd = commands; cmd; cmd = cmd->next) {
		if (is_null_sha1(cmd->new_sha1))
			continue;
		sha1_array_append(ref, cmd->new_sha1);
		cmd->index = ref->nr - 1;
	}
	si->ref = ref;

1578 1579 1580 1581 1582
	if (shallow_update) {
		prepare_shallow_update(commands, si);
		return;
	}

1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595
	ref_status = xmalloc(sizeof(*ref_status) * ref->nr);
	assign_shallow_commits_to_refs(si, NULL, ref_status);
	for (cmd = commands; cmd; cmd = cmd->next) {
		if (is_null_sha1(cmd->new_sha1))
			continue;
		if (ref_status[cmd->index]) {
			cmd->error_string = "shallow update not allowed";
			cmd->skip_update = 1;
		}
	}
	free(ref_status);
}

1596
static void report(struct command *commands, const char *unpack_status)
1597 1598
{
	struct command *cmd;
1599 1600 1601 1602
	struct strbuf buf = STRBUF_INIT;

	packet_buf_write(&buf, "unpack %s\n",
			 unpack_status ? unpack_status : "ok");
1603 1604
	for (cmd = commands; cmd; cmd = cmd->next) {
		if (!cmd->error_string)
1605 1606
			packet_buf_write(&buf, "ok %s\n",
					 cmd->ref_name);
1607
		else
1608 1609
			packet_buf_write(&buf, "ng %s %s\n",
					 cmd->ref_name, cmd->error_string);
1610
	}
1611 1612 1613 1614 1615
	packet_buf_flush(&buf);

	if (use_sideband)
		send_sideband(1, 1, buf.buf, buf.len, use_sideband);
	else
J
Jeff King 已提交
1616
		write_or_die(1, buf.buf, buf.len);
1617
	strbuf_release(&buf);
1618 1619
}

1620
static int delete_only(struct command *commands)
1621
{
1622 1623
	struct command *cmd;
	for (cmd = commands; cmd; cmd = cmd->next) {
1624 1625 1626 1627 1628 1629
		if (!is_null_sha1(cmd->new_sha1))
			return 0;
	}
	return 1;
}

J
Junio C Hamano 已提交
1630
int cmd_receive_pack(int argc, const char **argv, const char *prefix)
1631
{
1632
	int advertise_refs = 0;
1633
	int i;
1634
	struct command *commands;
1635 1636 1637
	struct sha1_array shallow = SHA1_ARRAY_INIT;
	struct sha1_array ref = SHA1_ARRAY_INIT;
	struct shallow_info si;
1638

J
Jeff King 已提交
1639 1640
	packet_trace_identity("receive-pack");

1641 1642
	argv++;
	for (i = 1; i < argc; i++) {
J
Junio C Hamano 已提交
1643
		const char *arg = *argv++;
1644 1645

		if (*arg == '-') {
1646 1647 1648 1649 1650
			if (!strcmp(arg, "--quiet")) {
				quiet = 1;
				continue;
			}

1651 1652 1653 1654 1655 1656 1657 1658
			if (!strcmp(arg, "--advertise-refs")) {
				advertise_refs = 1;
				continue;
			}
			if (!strcmp(arg, "--stateless-rpc")) {
				stateless_rpc = 1;
				continue;
			}
1659 1660 1661 1662
			if (!strcmp(arg, "--reject-thin-pack-for-testing")) {
				fix_thin = 0;
				continue;
			}
1663

1664 1665
			usage(receive_pack_usage);
		}
1666
		if (service_dir)
1667
			usage(receive_pack_usage);
1668
		service_dir = arg;
1669
	}
1670
	if (!service_dir)
1671 1672
		usage(receive_pack_usage);

1673
	setup_path();
1674

1675 1676
	if (!enter_repo(service_dir, 0))
		die("'%s' does not appear to be a git repository", service_dir);
1677

1678
	git_config(receive_pack_config, NULL);
1679
	if (cert_nonce_seed)
1680
		push_cert_nonce = prepare_push_cert_nonce(service_dir, time(NULL));
1681

1682 1683 1684 1685 1686
	if (0 <= transfer_unpack_limit)
		unpack_limit = transfer_unpack_limit;
	else if (0 <= receive_unpack_limit)
		unpack_limit = receive_unpack_limit;

1687 1688 1689 1690 1691
	if (advertise_refs || !stateless_rpc) {
		write_head_info();
	}
	if (advertise_refs)
		return 0;
1692

1693
	if ((commands = read_head_info(&shallow)) != NULL) {
1694 1695
		const char *unpack_status = NULL;

1696
		prepare_shallow_info(&si, &shallow);
1697 1698
		if (!si.nr_ours && !si.nr_theirs)
			shallow_update = 0;
1699 1700 1701 1702
		if (!delete_only(commands)) {
			unpack_status = unpack_with_sideband(&si);
			update_shallow_info(commands, &si, &ref);
		}
1703
		execute_commands(commands, unpack_status, &si);
1704
		if (pack_lockfile)
1705
			unlink_or_warn(pack_lockfile);
1706
		if (report_status)
1707
			report(commands, unpack_status);
1708
		run_receive_hook(commands, "post-receive", 1);
1709
		run_update_post_hook(commands);
1710 1711 1712 1713
		if (auto_gc) {
			const char *argv_gc_auto[] = {
				"gc", "--auto", "--quiet", NULL,
			};
1714 1715
			int opt = RUN_GIT_CMD | RUN_COMMAND_STDOUT_TO_STDERR;
			run_command_v_opt(argv_gc_auto, opt);
1716 1717 1718
		}
		if (auto_update_server_info)
			update_server_info(0);
1719
		clear_shallow_info(&si);
1720
	}
1721 1722
	if (use_sideband)
		packet_flush(1);
1723 1724
	sha1_array_clear(&shallow);
	sha1_array_clear(&ref);
1725
	free((void *)push_cert_nonce);
1726 1727
	return 0;
}