fix(p8h-core): escape log paths, fail closed on identity activation, tidy server gate

- A6: escape attacker-controlled file paths and the receive root in log
  lines (file_receive, server, protocol DEBUG) with output_escape()
- A8: identity_set_active() returns bool and fails closed when a requested
  usermap/groupmap cannot be deep-copied; handler refuses the connection
- remove the const cast and duplicate super_mode clamp from
  server_module_gate via an explicit override the handler applies once
- release the identity snapshot on the queue_create failure path
- refactor identity_parse_copy_as to a single cleanup tail and drop the
  duplicated group error format specifier
This commit is contained in:
2026-09-12 15:03:54 +02:00
parent b8db810ee5
commit 6d32bc795b
8 changed files with 207 additions and 106 deletions
+5 -5
View File
@@ -1883,13 +1883,13 @@ static void test_privilege_super_permitted_modes() {
Config* c = config_create();
EXPECT_NOT_NULL(c);
c->super_mode = SUPER_MODE_OFF;
identity_set_active(c);
EXPECT_TRUE(identity_set_active(c));
EXPECT_FALSE(privilege_super_permitted());
c->super_mode = SUPER_MODE_ON;
identity_set_active(c);
EXPECT_TRUE(identity_set_active(c));
EXPECT_TRUE(privilege_super_permitted());
c->super_mode = SUPER_MODE_AUTO;
identity_set_active(c);
EXPECT_TRUE(identity_set_active(c));
EXPECT_TRUE(privilege_super_permitted());
config_delete(c);
@@ -1952,10 +1952,10 @@ static void test_super_does_not_imply_numeric() {
EXPECT_NOT_NULL(c);
c->super_mode = SUPER_MODE_ON;
c->use_metadata = true;
identity_set_active(c);
EXPECT_TRUE(identity_set_active(c));
EXPECT_FALSE(identity_active_enabled());
c->numeric_ids = true;
identity_set_active(c);
EXPECT_TRUE(identity_set_active(c));
EXPECT_TRUE(identity_active_enabled());
identity_clear_active();
config_delete(c);