fix: address PR #200 review issues
CI / lint (pull_request) Successful in 22s
CI / sanitizers (address) (pull_request) Successful in 37s
CI / sanitizers (undefined) (pull_request) Successful in 36s
CI / fuzz-build (pull_request) Successful in 13s
CI / coverage (pull_request) Successful in 31s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s

- Restore PROTOCOL_VERSION to a forward-compatible 2.1.0 and document wire format
- Add NULL guard to config_delete
- Add pipeline cancellation flag and cancellation-aware queue helper
- Join running threads before destroying pipeline contexts on creation failure
- Fix NULL dereference and memory leaks in manifest/chunk handling
- Fix TLS/TCP socket fd leak on connect error paths
- Add compression-level range validation (1-22)
- Close previous log file before opening a new one
- Use getline for unbounded pattern-file lines
- Fix thread-unsafe localtime() and add log level bounds check
- Fix file_load_data to clean up data on read size mismatch
- Add hard ceiling to decompression buffer growth
- Fix mkdir_r bounds check and restore glob comments
- Add send_str NULL guard and mutex-protect bandwidth limiter
- Update AGENTS.md for per-thread io_ssl contract
This commit is contained in:
2026-08-02 09:20:10 +02:00
parent 1064ae6c19
commit 05a74770ca
16 changed files with 344 additions and 68 deletions
+20 -3
View File
@@ -1,12 +1,13 @@
#include "compression.h"
#include "data.h"
#include "log.h"
#include "stdlib.h"
#include "string.h"
#include <stdlib.h>
#include <string.h>
#include <strings.h>
#include "zstd.h"
#include <zstd.h>
#define INITIAL_DECOMPRESS_BUF_SIZE (1024 * 1024)
#define MAX_DECOMPRESSED_SIZE (100ULL * 1024 * 1024) /* 100 MB hard ceiling */
static const char* SKIP_COMPRESSION_EXTENSIONS[] = {".jpg", ".jpeg", ".png", ".gif", ".mp4", ".mkv",
".zip", ".gz", ".xz", ".zst", NULL};
@@ -84,6 +85,13 @@ Data* data_decompress(Data* compressed_data) {
dst_size = compressed_data->size * 3;
if (dst_size < INITIAL_DECOMPRESS_BUF_SIZE)
dst_size = INITIAL_DECOMPRESS_BUF_SIZE;
if (dst_size > MAX_DECOMPRESSED_SIZE)
dst_size = MAX_DECOMPRESSED_SIZE;
}
if (dst_size > MAX_DECOMPRESSED_SIZE) {
log_message(LOG_LEVEL_ERROR, "Declared decompressed size exceeds %llu bytes",
(unsigned long long)MAX_DECOMPRESSED_SIZE);
return NULL;
}
ZSTD_DCtx* dctx = ZSTD_createDCtx();
@@ -113,7 +121,16 @@ Data* data_decompress(Data* compressed_data) {
return NULL;
}
if (ret > 0 && output.pos == output.size) {
if (buf_size >= MAX_DECOMPRESSED_SIZE) {
log_message(LOG_LEVEL_ERROR, "Decompressed data exceeds %llu bytes",
(unsigned long long)MAX_DECOMPRESSED_SIZE);
ZSTD_freeDCtx(dctx);
data_destroy(uncompressed_data);
return NULL;
}
buf_size *= 2;
if (buf_size > MAX_DECOMPRESSED_SIZE)
buf_size = MAX_DECOMPRESSED_SIZE;
void* new_data = realloc(uncompressed_data->data, buf_size);
if (!new_data) {
log_message(LOG_LEVEL_ERROR, "Failed to grow decompression buffer");
+13
View File
@@ -131,6 +131,8 @@ void config_parse_ssh_dest(Config* config) {
}
void config_delete(Config* config) {
if (config == NULL)
return;
free(config->version);
free(config->send_directory);
free(config->receive_root_directory);
@@ -167,6 +169,16 @@ void config_delete(Config* config) {
free(config);
}
/* Wire format order (must match config_receive and be updated when PROTOCOL_VERSION bumps):
* version, send_directory, receive_root_directory, save_to_disk, use_multithreading,
* use_chunk_serialization, use_compression, use_metadata, compression_level, chunk_size,
* use_sendfile, use_delete, use_incremental, use_delta, delta_block_size, delta_max_file_size,
* backup, backup_dir, follow_symlinks, copy_links, safe_links, copy_unsafe_links,
* preserve_hard_links, preserve_acls, preserve_xattrs, preserve_devices, preserve_sparse,
* update, inplace, append, append_verify, delete_excluded, delete_after, max_delete, relative,
* prune_empty_dirs, temp_dir, partial, partial_dir, suffix, delete_before, checksum,
* compress_choice, status
*/
bool config_send(int file_descriptor, const Config* config) {
if (!send_str(file_descriptor, config->version))
return false;
@@ -264,6 +276,7 @@ bool config_send(int file_descriptor, const Config* config) {
return true;
}
/* Wire format order: see the comment above config_send. */
Config* config_receive(int file_descriptor) {
Config* config = (Config*)malloc(sizeof(Config));
if (config == NULL)
+2 -1
View File
@@ -128,7 +128,8 @@ typedef struct Config {
char* compress_choice;
} Config;
#define PROTOCOL_VERSION "1.3.0"
/* This version must be bumped whenever config_send / config_receive wire format changes. */
#define PROTOCOL_VERSION "2.1.0"
#define DEFAULT_CHUNK_SIZE (10 * 1024 * 1024)
Config* config_create(void);
+3 -1
View File
@@ -16,7 +16,6 @@
#include "config.h"
#include "data.h"
#include "file.h"
#include "log.h"
#include "metadata.h"
#include "protocol.h"
#include "utils.h"
@@ -96,6 +95,9 @@ bool file_load_data(File* file) {
size_t bytes_read = file_content_to_buffer(file);
if (bytes_read != file->data->size) {
log_message(LOG_LEVEL_ERROR, "Did not read expected amount of bytes from file");
free(file->data->data);
file->data->data = NULL;
file->data->size = 0;
return false;
}
return true;
+9 -5
View File
@@ -18,11 +18,15 @@ void log_set_file(FILE* fp) {
void log_message(LogLevel log_level, const char* format, ...) {
if (log_level < current_log_level)
return;
if (log_level < 0 || log_level >= (int)(sizeof(log_level_strings) / sizeof(log_level_strings[0])))
return;
time_t now = time(NULL);
const struct tm* t = localtime(&now);
struct tm t;
if (!localtime_r(&now, &t))
return;
fprintf(stderr, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t->tm_year + 1900, t->tm_mon + 1,
t->tm_mday, t->tm_hour, t->tm_min, t->tm_sec, log_level_strings[log_level]);
fprintf(stderr, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t.tm_year + 1900, t.tm_mon + 1, t.tm_mday,
t.tm_hour, t.tm_min, t.tm_sec, log_level_strings[log_level]);
va_list args;
va_start(args, format);
@@ -31,8 +35,8 @@ void log_message(LogLevel log_level, const char* format, ...) {
fprintf(stderr, "\n");
if (log_fp) {
fprintf(log_fp, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t->tm_year + 1900, t->tm_mon + 1,
t->tm_mday, t->tm_hour, t->tm_min, t->tm_sec, log_level_strings[log_level]);
fprintf(log_fp, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t.tm_year + 1900, t.tm_mon + 1,
t.tm_mday, t.tm_hour, t.tm_min, t.tm_sec, log_level_strings[log_level]);
va_start(args, format);
vfprintf(log_fp, format, args);
va_end(args);
+83 -24
View File
@@ -26,18 +26,48 @@ PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* que
context->manifest = NULL;
context->progress_bytes = 0;
context->sender_done = false;
if (mtx_init(&context->mutex_scanner, mtx_plain) != thrd_success ||
cnd_init(&context->condition_not_full_scanner) != thrd_success ||
cnd_init(&context->condition_not_empty_scanner) != thrd_success ||
mtx_init(&context->mutex_loader, mtx_plain) != thrd_success ||
cnd_init(&context->condition_not_full_loader) != thrd_success ||
mtx_init(&context->mutex_progress, mtx_plain) != thrd_success ||
cnd_init(&context->condition_not_empty_loader) != thrd_success) {
perror("Error initializing synchronization objects");
free(context);
return NULL;
}
context->cancelled = false;
int init = 0;
if (mtx_init(&context->mutex_scanner, mtx_plain) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_full_scanner) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_empty_scanner) != thrd_success)
goto fail;
init++;
if (mtx_init(&context->mutex_loader, mtx_plain) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_full_loader) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_empty_loader) != thrd_success)
goto fail;
init++;
if (mtx_init(&context->mutex_progress, mtx_plain) != thrd_success)
goto fail;
// cppcheck-suppress unreadVariable
init++;
return context;
fail:
perror("Error initializing synchronization objects");
if (init >= 6)
cnd_destroy(&context->condition_not_empty_loader);
if (init >= 5)
cnd_destroy(&context->condition_not_full_loader);
if (init >= 4)
mtx_destroy(&context->mutex_loader);
if (init >= 3)
cnd_destroy(&context->condition_not_empty_scanner);
if (init >= 2)
cnd_destroy(&context->condition_not_full_scanner);
if (init >= 1)
mtx_destroy(&context->mutex_scanner);
free(context);
return NULL;
}
void pipeline_context_sender_destroy(PipelineContextSender* context) {
@@ -67,14 +97,30 @@ PipelineContextReceiver* pipeline_context_receiver_create(Config* config, Queue*
context->file_descriptor = file_descriptor;
context->ssl = ssl;
context->receiver_done = false;
if (mtx_init(&context->mutex, mtx_plain) != thrd_success ||
cnd_init(&context->condition_not_full) != thrd_success ||
cnd_init(&context->condition_not_empty) != thrd_success) {
perror("Error initializing synchronization objects");
free(context);
return NULL;
}
context->cancelled = false;
int init = 0;
if (mtx_init(&context->mutex, mtx_plain) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_full) != thrd_success)
goto fail;
init++;
if (cnd_init(&context->condition_not_empty) != thrd_success)
goto fail;
// cppcheck-suppress unreadVariable
init++;
return context;
fail:
perror("Error initializing synchronization objects");
if (init >= 3)
cnd_destroy(&context->condition_not_empty);
if (init >= 2)
cnd_destroy(&context->condition_not_full);
if (init >= 1)
mtx_destroy(&context->mutex);
free(context);
return NULL;
}
void pipeline_context_receiver_destroy(PipelineContextReceiver* context) {
@@ -94,8 +140,13 @@ static bool receive_chunk_enqueue(int file_descriptor, PipelineContextReceiver*
for (int i = 0; i < chunk->element_count; i++) {
File* file = chunk->items[i];
chunk->items[i] = NULL;
queue_enqueue_multithreaded(context->queue, file, &context->mutex,
&context->condition_not_empty, &context->condition_not_full);
if (!queue_enqueue_multithreaded_cancel(context->queue, file, &context->mutex,
&context->condition_not_empty,
&context->condition_not_full, &context->cancelled)) {
file_destroy(file);
chunk_destroy(chunk);
return false;
}
}
chunk_destroy(chunk);
return true;
@@ -129,8 +180,12 @@ int receive_thread(void* pipeline_context) {
if (!skipped) {
if (file == NULL)
return thrd_error;
queue_enqueue_multithreaded(context->queue, file, &context->mutex,
&context->condition_not_empty, &context->condition_not_full);
if (!queue_enqueue_multithreaded_cancel(
context->queue, file, &context->mutex, &context->condition_not_empty,
&context->condition_not_full, &context->cancelled)) {
file_destroy(file);
return thrd_error;
}
}
} else if (status == STATUS_CHUNK) {
if (!receive_chunk_enqueue(file_descriptor, context))
@@ -166,8 +221,12 @@ int receive_thread(void* pipeline_context) {
} else {
File* file = file_receive(config, file_descriptor);
if (file) {
queue_enqueue_multithreaded(context->queue, file, &context->mutex,
&context->condition_not_empty, &context->condition_not_full);
if (!queue_enqueue_multithreaded_cancel(
context->queue, file, &context->mutex, &context->condition_not_empty,
&context->condition_not_full, &context->cancelled)) {
file_destroy(file);
return thrd_error;
}
} else {
log_message(LOG_LEVEL_ERROR, "Failed to receive file");
return thrd_error;
+2
View File
@@ -26,6 +26,7 @@ typedef struct {
mtx_t mutex_progress;
unsigned long long progress_bytes;
bool sender_done;
bool cancelled;
} PipelineContextSender;
typedef struct PipelineContextReceiver {
@@ -37,6 +38,7 @@ typedef struct PipelineContextReceiver {
cnd_t condition_not_full;
cnd_t condition_not_empty;
bool receiver_done;
bool cancelled;
} PipelineContextReceiver;
PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* queue_scanner,
+15
View File
@@ -6,6 +6,7 @@
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <threads.h>
#include <time.h>
#include <unistd.h>
@@ -20,6 +21,8 @@ static __thread SSL* io_ssl;
static unsigned long long io_bwlimit = 0;
static long long bw_tokens = 0;
static struct timespec bw_last_refill = {0, 0};
static mtx_t bw_mutex;
static once_flag bw_mutex_once = ONCE_FLAG_INIT;
static __thread unsigned long long total_allocated_bytes = 0;
@@ -28,15 +31,24 @@ void io_set_fds(int read_fd, int write_fd) {
io_write_fd = write_fd;
}
static void bw_mutex_init(void) {
mtx_init(&bw_mutex, mtx_plain);
}
void io_set_bwlimit(unsigned long long bytes_per_sec) {
call_once(&bw_mutex_once, bw_mutex_init);
mtx_lock(&bw_mutex);
io_bwlimit = bytes_per_sec;
bw_tokens = (long long)io_bwlimit;
clock_gettime(CLOCK_MONOTONIC, &bw_last_refill);
mtx_unlock(&bw_mutex);
}
static void bw_throttle(size_t bytes_written) {
if (io_bwlimit == 0)
return;
call_once(&bw_mutex_once, bw_mutex_init);
mtx_lock(&bw_mutex);
struct timespec now;
clock_gettime(CLOCK_MONOTONIC, &now);
@@ -61,6 +73,7 @@ static void bw_throttle(size_t bytes_written) {
bw_tokens = 0;
clock_gettime(CLOCK_MONOTONIC, &bw_last_refill);
}
mtx_unlock(&bw_mutex);
}
void io_set_ssl(SSL* ssl) {
@@ -177,6 +190,8 @@ static const char* status_to_string(Status status) {
}
bool send_str(int file_descriptor, const char* data) {
if (data == NULL)
return false;
size_t size = strlen(data);
if (!send_n_data(file_descriptor, &size, sizeof(size_t)))
return false;
+16
View File
@@ -103,6 +103,22 @@ bool queue_enqueue_multithreaded(Queue* queue, void* item, mtx_t* mutex, cnd_t*
return ok;
}
bool queue_enqueue_multithreaded_cancel(Queue* queue, void* item, mtx_t* mutex,
cnd_t* condition_not_empty, cnd_t* condition_not_full,
const bool* cancelled) {
mtx_lock(mutex);
while (queue_is_full(queue) && (cancelled == NULL || !*cancelled))
cnd_wait(condition_not_full, mutex);
if (cancelled != NULL && *cancelled) {
mtx_unlock(mutex);
return false;
}
bool ok = queue_enqueue(queue, item);
cnd_signal(condition_not_empty);
mtx_unlock(mutex);
return ok;
}
void* queue_dequeue(Queue* queue) {
if (queue == NULL || queue_is_empty(queue)) {
perror("ERROR: Could not dequeue from null or empty queue.");
+3
View File
@@ -20,6 +20,9 @@ bool queue_is_full(const Queue* queue);
bool queue_enqueue(Queue* queue, void* item);
bool queue_enqueue_multithreaded(Queue* queue, void* item, mtx_t* mutex, cnd_t* condition_not_empty,
cnd_t* condition_not_full);
bool queue_enqueue_multithreaded_cancel(Queue* queue, void* item, mtx_t* mutex,
cnd_t* condition_not_empty, cnd_t* condition_not_full,
const bool* cancelled);
void* queue_dequeue(Queue* queue);
void* queue_dequeue_multithreaded(Queue* queue, mtx_t* mutex, cnd_t* condition_not_empty,
cnd_t* condition_not_full, const bool* other_thread_done);
+19 -3
View File
@@ -10,11 +10,13 @@
#include <unistd.h>
bool mkdir_r(const char* path) {
char* path_duplicate = malloc(strlen(path) + 1);
size_t path_len = strlen(path);
char* path_duplicate = malloc(path_len + 1);
if (!path_duplicate)
return false;
memcpy(path_duplicate, path, strlen(path) + 1);
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
memcpy(path_duplicate, path, path_len + 1);
size_t capacity = path_len + 2;
char* path_current = (char*)malloc(capacity * sizeof(char));
if (!path_current) {
free(path_duplicate);
return false;
@@ -33,6 +35,10 @@ bool mkdir_r(const char* path) {
bool ok = true;
while (part != NULL) {
size_t part_len = strlen(part);
if ((size_t)(path_current_position - path_current) + part_len + 2 > capacity) {
ok = false;
break;
}
memcpy(path_current_position, part, part_len);
path_current_position += part_len;
path_current_position[0] = '/';
@@ -64,10 +70,18 @@ char* str_dup(const char* string) {
return new_string;
}
/* Match a glob pattern against a string. Supported wildcards:
* ? matches any single character except '/'.
* * matches any sequence of characters within one path component (no '/').
* ** matches any sequence of characters, including '/' (cross-directory).
* slash-star-star-slash is treated as a cross-directory wildcard when it appears between
* literals.
*/
bool glob_match(const char* pattern, const char* str) {
while (*pattern) {
if (*pattern == '*') {
if (*(pattern + 1) == '*') {
/* globstar: match across directories */
pattern += 2;
if (*pattern == '\0')
return true;
@@ -80,6 +94,7 @@ bool glob_match(const char* pattern, const char* str) {
}
return glob_match(pattern, str);
}
/* single *: match within one path component */
pattern++;
while (*str && *str != '/') {
if (glob_match(pattern, str))
@@ -94,6 +109,7 @@ bool glob_match(const char* pattern, const char* str) {
str++;
} else {
if (*pattern != *str) {
/* allow literal / ** / rest to match any number of directories */
if (*pattern == '/' && *(pattern + 1) == '*' && *(pattern + 2) == '*') {
const char* rest = pattern + 3;
if (*rest == '/')