xref: /freebsd/bin/cp/cp.c (revision b9fa1500cb2265b95927e19b9d2119ca26d65be3)
1 /*-
2  * SPDX-License-Identifier: BSD-3-Clause
3  *
4  * Copyright (c) 1988, 1993, 1994
5  *	The Regents of the University of California.  All rights reserved.
6  *
7  * This code is derived from software contributed to Berkeley by
8  * David Hitz of Auspex Systems Inc.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  * 3. Neither the name of the University nor the names of its contributors
19  *    may be used to endorse or promote products derived from this software
20  *    without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32  * SUCH DAMAGE.
33  */
34 
35 /*
36  * Cp copies source files to target files.
37  *
38  * The global PATH_T structure "to" always contains the path to the
39  * current target file.  Since fts(3) does not change directories,
40  * this path can be either absolute or dot-relative.
41  *
42  * The basic algorithm is to initialize "to" and use fts(3) to traverse
43  * the file hierarchy rooted in the argument list.  A trivial case is the
44  * case of 'cp file1 file2'.  The more interesting case is the case of
45  * 'cp file1 file2 ... fileN dir' where the hierarchy is traversed and the
46  * path (relative to the root of the traversal) is appended to dir (stored
47  * in "to") to form the final target path.
48  */
49 
50 #include <sys/types.h>
51 #include <sys/stat.h>
52 
53 #include <assert.h>
54 #include <err.h>
55 #include <errno.h>
56 #include <fts.h>
57 #include <limits.h>
58 #include <signal.h>
59 #include <stdio.h>
60 #include <stdlib.h>
61 #include <string.h>
62 #include <unistd.h>
63 
64 #include "extern.h"
65 
66 #define	STRIP_TRAILING_SLASH(p) {					\
67 	while ((p).p_end > (p).p_path + 1 && (p).p_end[-1] == '/')	\
68 	*--(p).p_end = 0;						\
69 }
70 
71 static char emptystring[] = "";
72 
73 PATH_T to = { to.p_path, emptystring, "" };
74 
75 int Nflag, fflag, iflag, lflag, nflag, pflag, sflag, vflag;
76 static int Hflag, Lflag, Pflag, Rflag, rflag;
77 volatile sig_atomic_t info;
78 
79 enum op { FILE_TO_FILE, FILE_TO_DIR, DIR_TO_DNE };
80 
81 static int copy(char *[], enum op, int, struct stat *);
82 static void siginfo(int __unused);
83 
84 int
85 main(int argc, char *argv[])
86 {
87 	struct stat to_stat, tmp_stat;
88 	enum op type;
89 	int ch, fts_options, r, have_trailing_slash;
90 	char *target;
91 
92 	fts_options = FTS_NOCHDIR | FTS_PHYSICAL;
93 	while ((ch = getopt(argc, argv, "HLPRafilNnprsvx")) != -1)
94 		switch (ch) {
95 		case 'H':
96 			Hflag = 1;
97 			Lflag = Pflag = 0;
98 			break;
99 		case 'L':
100 			Lflag = 1;
101 			Hflag = Pflag = 0;
102 			break;
103 		case 'P':
104 			Pflag = 1;
105 			Hflag = Lflag = 0;
106 			break;
107 		case 'R':
108 			Rflag = 1;
109 			break;
110 		case 'a':
111 			pflag = 1;
112 			Rflag = 1;
113 			Pflag = 1;
114 			Hflag = Lflag = 0;
115 			break;
116 		case 'f':
117 			fflag = 1;
118 			iflag = nflag = 0;
119 			break;
120 		case 'i':
121 			iflag = 1;
122 			fflag = nflag = 0;
123 			break;
124 		case 'l':
125 			lflag = 1;
126 			break;
127 		case 'N':
128 			Nflag = 1;
129 			break;
130 		case 'n':
131 			nflag = 1;
132 			fflag = iflag = 0;
133 			break;
134 		case 'p':
135 			pflag = 1;
136 			break;
137 		case 'r':
138 			rflag = Lflag = 1;
139 			Hflag = Pflag = 0;
140 			break;
141 		case 's':
142 			sflag = 1;
143 			break;
144 		case 'v':
145 			vflag = 1;
146 			break;
147 		case 'x':
148 			fts_options |= FTS_XDEV;
149 			break;
150 		default:
151 			usage();
152 		}
153 	argc -= optind;
154 	argv += optind;
155 
156 	if (argc < 2)
157 		usage();
158 
159 	if (Rflag && rflag)
160 		errx(1, "the -R and -r options may not be specified together");
161 	if (lflag && sflag)
162 		errx(1, "the -l and -s options may not be specified together");
163 	if (rflag)
164 		Rflag = 1;
165 	if (Rflag) {
166 		if (Hflag)
167 			fts_options |= FTS_COMFOLLOW;
168 		if (Lflag) {
169 			fts_options &= ~FTS_PHYSICAL;
170 			fts_options |= FTS_LOGICAL;
171 		}
172 	} else if (!Pflag) {
173 		fts_options &= ~FTS_PHYSICAL;
174 		fts_options |= FTS_LOGICAL | FTS_COMFOLLOW;
175 	}
176 	(void)signal(SIGINFO, siginfo);
177 
178 	/* Save the target base in "to". */
179 	target = argv[--argc];
180 	if (strlcpy(to.p_path, target, sizeof(to.p_path)) >= sizeof(to.p_path))
181 		errx(1, "%s: name too long", target);
182 	to.p_end = to.p_path + strlen(to.p_path);
183 	if (to.p_path == to.p_end) {
184 		*to.p_end++ = '.';
185 		*to.p_end = 0;
186 	}
187 	have_trailing_slash = (to.p_end[-1] == '/');
188 	if (have_trailing_slash)
189 		STRIP_TRAILING_SLASH(to);
190 	to.target_end = to.p_end;
191 
192 	/* Set end of argument list for fts(3). */
193 	argv[argc] = NULL;
194 
195 	/*
196 	 * Cp has two distinct cases:
197 	 *
198 	 * cp [-R] source target
199 	 * cp [-R] source1 ... sourceN directory
200 	 *
201 	 * In both cases, source can be either a file or a directory.
202 	 *
203 	 * In (1), the target becomes a copy of the source. That is, if the
204 	 * source is a file, the target will be a file, and likewise for
205 	 * directories.
206 	 *
207 	 * In (2), the real target is not directory, but "directory/source".
208 	 */
209 	r = stat(to.p_path, &to_stat);
210 	if (r == -1 && errno != ENOENT)
211 		err(1, "%s", to.p_path);
212 	if (r == -1 || !S_ISDIR(to_stat.st_mode)) {
213 		/*
214 		 * Case (1).  Target is not a directory.
215 		 */
216 		if (argc > 1)
217 			errx(1, "%s is not a directory", to.p_path);
218 
219 		/*
220 		 * Need to detect the case:
221 		 *	cp -R dir foo
222 		 * Where dir is a directory and foo does not exist, where
223 		 * we want pathname concatenations turned on but not for
224 		 * the initial mkdir().
225 		 */
226 		if (r == -1) {
227 			if (Rflag && (Lflag || Hflag))
228 				stat(*argv, &tmp_stat);
229 			else
230 				lstat(*argv, &tmp_stat);
231 
232 			if (S_ISDIR(tmp_stat.st_mode) && Rflag)
233 				type = DIR_TO_DNE;
234 			else
235 				type = FILE_TO_FILE;
236 		} else
237 			type = FILE_TO_FILE;
238 
239 		if (have_trailing_slash && type == FILE_TO_FILE) {
240 			if (r == -1) {
241 				errx(1, "directory %s does not exist",
242 				    to.p_path);
243 			} else
244 				errx(1, "%s is not a directory", to.p_path);
245 		}
246 	} else
247 		/*
248 		 * Case (2).  Target is a directory.
249 		 */
250 		type = FILE_TO_DIR;
251 
252 	/*
253 	 * For DIR_TO_DNE, we could provide copy() with the to_stat we've
254 	 * already allocated on the stack here that isn't being used for
255 	 * anything.  Not doing so, though, simplifies later logic a little bit
256 	 * as we need to skip checking root_stat on the first iteration and
257 	 * ensure that we set it with the first mkdir().
258 	 */
259 	exit (copy(argv, type, fts_options, (type == DIR_TO_DNE ? NULL :
260 	    &to_stat)));
261 }
262 
263 /* Does the right thing based on -R + -H/-L/-P */
264 static int
265 copy_stat(const char *path, struct stat *sb)
266 {
267 
268 	/*
269 	 * For -R -H/-P, we need to lstat() instead; copy() cares about the link
270 	 * itself rather than the target if we're not following links during the
271 	 * traversal.
272 	 */
273 	if (!Rflag || Lflag)
274 		return (stat(path, sb));
275 	return (lstat(path, sb));
276 }
277 
278 
279 static int
280 copy(char *argv[], enum op type, int fts_options, struct stat *root_stat)
281 {
282 	char rootname[NAME_MAX];
283 	struct stat created_root_stat, to_stat;
284 	FTS *ftsp;
285 	FTSENT *curr;
286 	int base = 0, dne, badcp, rval;
287 	size_t nlen;
288 	char *p, *recurse_path, *target_mid;
289 	mode_t mask, mode;
290 
291 	/*
292 	 * Keep an inverted copy of the umask, for use in correcting
293 	 * permissions on created directories when not using -p.
294 	 */
295 	mask = ~umask(0777);
296 	umask(~mask);
297 
298 	recurse_path = NULL;
299 	if ((ftsp = fts_open(argv, fts_options, NULL)) == NULL)
300 		err(1, "fts_open");
301 	for (badcp = rval = 0; (curr = fts_read(ftsp)) != NULL; badcp = 0) {
302 		switch (curr->fts_info) {
303 		case FTS_NS:
304 		case FTS_DNR:
305 		case FTS_ERR:
306 			warnx("%s: %s",
307 			    curr->fts_path, strerror(curr->fts_errno));
308 			badcp = rval = 1;
309 			continue;
310 		case FTS_DC:			/* Warn, continue. */
311 			warnx("%s: directory causes a cycle", curr->fts_path);
312 			badcp = rval = 1;
313 			continue;
314 		default:
315 			;
316 		}
317 
318 		/*
319 		 * Stash the root basename off for detecting recursion later.
320 		 *
321 		 * This will be essential if the root is a symlink and we're
322 		 * rolling with -L or -H.  The later bits will need this bit in
323 		 * particular.
324 		 */
325 		if (curr->fts_level == FTS_ROOTLEVEL) {
326 			strlcpy(rootname, curr->fts_name, sizeof(rootname));
327 		}
328 
329 		/*
330 		 * If we are in case (2) or (3) above, we need to append the
331 		 * source name to the target name.
332 		 */
333 		if (type != FILE_TO_FILE) {
334 			/*
335 			 * Need to remember the roots of traversals to create
336 			 * correct pathnames.  If there's a directory being
337 			 * copied to a non-existent directory, e.g.
338 			 *	cp -R a/dir noexist
339 			 * the resulting path name should be noexist/foo, not
340 			 * noexist/dir/foo (where foo is a file in dir), which
341 			 * is the case where the target exists.
342 			 *
343 			 * Also, check for "..".  This is for correct path
344 			 * concatenation for paths ending in "..", e.g.
345 			 *	cp -R .. /tmp
346 			 * Paths ending in ".." are changed to ".".  This is
347 			 * tricky, but seems the easiest way to fix the problem.
348 			 *
349 			 * XXX
350 			 * Since the first level MUST be FTS_ROOTLEVEL, base
351 			 * is always initialized.
352 			 */
353 			if (curr->fts_level == FTS_ROOTLEVEL) {
354 				if (type != DIR_TO_DNE) {
355 					p = strrchr(curr->fts_path, '/');
356 					base = (p == NULL) ? 0 :
357 					    (int)(p - curr->fts_path + 1);
358 
359 					if (!strcmp(&curr->fts_path[base],
360 					    ".."))
361 						base += 1;
362 				} else
363 					base = curr->fts_pathlen;
364 			}
365 
366 			p = &curr->fts_path[base];
367 			nlen = curr->fts_pathlen - base;
368 			target_mid = to.target_end;
369 			if (*p != '/' && target_mid[-1] != '/')
370 				*target_mid++ = '/';
371 			*target_mid = 0;
372 			if (target_mid - to.p_path + nlen >= PATH_MAX) {
373 				warnx("%s%s: name too long (not copied)",
374 				    to.p_path, p);
375 				badcp = rval = 1;
376 				continue;
377 			}
378 			(void)strncat(target_mid, p, nlen);
379 			to.p_end = target_mid + nlen;
380 			*to.p_end = 0;
381 			STRIP_TRAILING_SLASH(to);
382 
383 			/*
384 			 * We're on the verge of recursing on ourselves.  Either
385 			 * we need to stop right here (we knowingly just created
386 			 * it), or we will in an immediate descendant.  Record
387 			 * the path of the immediate descendant to make our
388 			 * lives a little less complicated looking.
389 			 */
390 			if (curr->fts_info == FTS_D && root_stat != NULL &&
391 			    root_stat->st_dev == curr->fts_statp->st_dev &&
392 			    root_stat->st_ino == curr->fts_statp->st_ino) {
393 				assert(recurse_path == NULL);
394 
395 				if (root_stat == &created_root_stat) {
396 					/*
397 					 * This directory didn't exist when we
398 					 * started, we created it as part of
399 					 * traversal.  Stop right here before we
400 					 * do something silly.
401 					 */
402 					fts_set(ftsp, curr, FTS_SKIP);
403 					continue;
404 				}
405 
406 
407 				if (asprintf(&recurse_path, "%s/%s", to.p_path,
408 				    rootname) == -1)
409 					err(1, "asprintf");
410 			}
411 
412 			if (recurse_path != NULL &&
413 			    strcmp(to.p_path, recurse_path) == 0) {
414 				fts_set(ftsp, curr, FTS_SKIP);
415 				continue;
416 			}
417 		}
418 
419 		if (curr->fts_info == FTS_DP) {
420 			/*
421 			 * We are nearly finished with this directory.  If we
422 			 * didn't actually copy it, or otherwise don't need to
423 			 * change its attributes, then we are done.
424 			 */
425 			if (!curr->fts_number)
426 				continue;
427 			/*
428 			 * If -p is in effect, set all the attributes.
429 			 * Otherwise, set the correct permissions, limited
430 			 * by the umask.  Optimise by avoiding a chmod()
431 			 * if possible (which is usually the case if we
432 			 * made the directory).  Note that mkdir() does not
433 			 * honour setuid, setgid and sticky bits, but we
434 			 * normally want to preserve them on directories.
435 			 */
436 			if (pflag) {
437 				if (setfile(curr->fts_statp, -1))
438 					rval = 1;
439 				if (preserve_dir_acls(curr->fts_statp,
440 				    curr->fts_accpath, to.p_path) != 0)
441 					rval = 1;
442 			} else {
443 				mode = curr->fts_statp->st_mode;
444 				if ((mode & (S_ISUID | S_ISGID | S_ISTXT)) ||
445 				    ((mode | S_IRWXU) & mask) != (mode & mask))
446 					if (chmod(to.p_path, mode & mask) !=
447 					    0) {
448 						warn("chmod: %s", to.p_path);
449 						rval = 1;
450 					}
451 			}
452 			continue;
453 		}
454 
455 		/* Not an error but need to remember it happened. */
456 		if (copy_stat(to.p_path, &to_stat) == -1)
457 			dne = 1;
458 		else {
459 			if (to_stat.st_dev == curr->fts_statp->st_dev &&
460 			    to_stat.st_ino == curr->fts_statp->st_ino) {
461 				warnx("%s and %s are identical (not copied).",
462 				    to.p_path, curr->fts_path);
463 				badcp = rval = 1;
464 				if (S_ISDIR(curr->fts_statp->st_mode))
465 					(void)fts_set(ftsp, curr, FTS_SKIP);
466 				continue;
467 			}
468 			if (!S_ISDIR(curr->fts_statp->st_mode) &&
469 			    S_ISDIR(to_stat.st_mode)) {
470 				warnx("cannot overwrite directory %s with "
471 				    "non-directory %s",
472 				    to.p_path, curr->fts_path);
473 				badcp = rval = 1;
474 				continue;
475 			}
476 			dne = 0;
477 		}
478 
479 		switch (curr->fts_statp->st_mode & S_IFMT) {
480 		case S_IFLNK:
481 			/* Catch special case of a non-dangling symlink. */
482 			if ((fts_options & FTS_LOGICAL) ||
483 			    ((fts_options & FTS_COMFOLLOW) &&
484 			    curr->fts_level == 0)) {
485 				if (copy_file(curr, dne))
486 					badcp = rval = 1;
487 			} else {
488 				if (copy_link(curr, !dne))
489 					badcp = rval = 1;
490 			}
491 			break;
492 		case S_IFDIR:
493 			if (!Rflag) {
494 				warnx("%s is a directory (not copied).",
495 				    curr->fts_path);
496 				(void)fts_set(ftsp, curr, FTS_SKIP);
497 				badcp = rval = 1;
498 				break;
499 			}
500 			/*
501 			 * If the directory doesn't exist, create the new
502 			 * one with the from file mode plus owner RWX bits,
503 			 * modified by the umask.  Trade-off between being
504 			 * able to write the directory (if from directory is
505 			 * 555) and not causing a permissions race.  If the
506 			 * umask blocks owner writes, we fail.
507 			 */
508 			if (dne) {
509 				mode = curr->fts_statp->st_mode | S_IRWXU;
510 				if (mkdir(to.p_path, mode) != 0) {
511 					warn("%s", to.p_path);
512 					(void)fts_set(ftsp, curr, FTS_SKIP);
513 					badcp = rval = 1;
514 					break;
515 				}
516 				/*
517 				 * First DNE with a NULL root_stat is the root
518 				 * path, so set root_stat.  We can't really
519 				 * tell in all cases if the target path is
520 				 * within the src path, so we just stat() the
521 				 * first directory we created and use that.
522 				 */
523 				if (root_stat == NULL &&
524 				    stat(to.p_path, &created_root_stat) != 0) {
525 					warn("%s", to.p_path);
526 					(void)fts_set(ftsp, curr, FTS_SKIP);
527 					badcp = rval = 1;
528 					break;
529 				}
530 				if (root_stat == NULL)
531 					root_stat = &created_root_stat;
532 			} else if (!S_ISDIR(to_stat.st_mode)) {
533 				warnc(ENOTDIR, "%s", to.p_path);
534 				(void)fts_set(ftsp, curr, FTS_SKIP);
535 				badcp = rval = 1;
536 				break;
537 			}
538 			/*
539 			 * Arrange to correct directory attributes later
540 			 * (in the post-order phase) if this is a new
541 			 * directory, or if the -p flag is in effect.
542 			 */
543 			curr->fts_number = pflag || dne;
544 			break;
545 		case S_IFBLK:
546 		case S_IFCHR:
547 			if (Rflag && !sflag) {
548 				if (copy_special(curr->fts_statp, !dne))
549 					badcp = rval = 1;
550 			} else {
551 				if (copy_file(curr, dne))
552 					badcp = rval = 1;
553 			}
554 			break;
555 		case S_IFSOCK:
556 			warnx("%s is a socket (not copied).",
557 			    curr->fts_path);
558 			break;
559 		case S_IFIFO:
560 			if (Rflag && !sflag) {
561 				if (copy_fifo(curr->fts_statp, !dne))
562 					badcp = rval = 1;
563 			} else {
564 				if (copy_file(curr, dne))
565 					badcp = rval = 1;
566 			}
567 			break;
568 		default:
569 			if (copy_file(curr, dne))
570 				badcp = rval = 1;
571 			break;
572 		}
573 		if (vflag && !badcp)
574 			(void)printf("%s -> %s\n", curr->fts_path, to.p_path);
575 	}
576 	if (errno)
577 		err(1, "fts_read");
578 	fts_close(ftsp);
579 	free(recurse_path);
580 	return (rval);
581 }
582 
583 static void
584 siginfo(int sig __unused)
585 {
586 
587 	info = 1;
588 }
589