fix(d5-daemon-core): cppcheck const-correctness, wire module length cap, daemonize chdir/umask, daemon confinement tests

- daemon_conf.c/server.c/test_daemon_conf.c: const-qualify parse/loop pointers;
  scope user_path static inside its block (clears the 9-wave-A cppcheck findings)
- config.c receive_daemon_module: reject invalid/over-long wire module names
  (> DAEMON_MAX_MODULE_NAME) with a clean STATUS_ERROR; client side already
  enforced via daemon_module_name_valid in config_parse_daemon_dest
- server.c daemonize: chdir(/) and umask(0) so module paths resolve from /
  and config-requested file modes are honored; PROTOCOL_VERSION stays 2.15.0
- test_daemon.py: confinement (read-only/unknown no-write anywhere), module-less
  and dot-dot destination refusal, real daemon_detach double-fork path
This commit is contained in:
2026-09-09 18:30:52 +02:00
parent b3d7d64347
commit 7c55409a6b
6 changed files with 127 additions and 11 deletions
+9 -1
View File
@@ -19,6 +19,8 @@
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <errno.h>
#include <sys/stat.h>
#include <openssl/x509.h>
static char* authorized_root;
@@ -459,9 +461,9 @@ static void print_server_usage(void) {
* exists (or when HOME is set), otherwise /etc/fastsyncd.conf. Returns a
* pointer to a static buffer (never NULL). */
static const char* default_daemon_config_path(void) {
static char user_path[PATH_MAX];
const char* home = getenv("HOME");
if (home && *home) {
static char user_path[PATH_MAX];
int n = snprintf(user_path, sizeof(user_path), "%s/.config/fastsync/fastsyncd.conf", home);
if (n > 0 && (size_t)n < sizeof(user_path) && access(user_path, R_OK) == 0)
return user_path;
@@ -496,6 +498,12 @@ static bool daemonize(void) {
if (devnull > STDERR_FILENO)
close(devnull);
}
/* Do not pin the launch CWD (module-relative 'path' entries would resolve
* against an unstable working directory) and drop the restrictive host umask
* so modules can create files/dirs with the modes the config requests. */
if (chdir("/") != 0)
log_message(LOG_LEVEL_WARNING, "daemon: chdir to / failed: %s", strerror(errno));
umask(0);
return true;
}