fix(d5-daemon-core): cppcheck const-correctness, wire module length cap, daemonize chdir/umask, daemon confinement tests
- daemon_conf.c/server.c/test_daemon_conf.c: const-qualify parse/loop pointers; scope user_path static inside its block (clears the 9-wave-A cppcheck findings) - config.c receive_daemon_module: reject invalid/over-long wire module names (> DAEMON_MAX_MODULE_NAME) with a clean STATUS_ERROR; client side already enforced via daemon_module_name_valid in config_parse_daemon_dest - server.c daemonize: chdir(/) and umask(0) so module paths resolve from / and config-requested file modes are honored; PROTOCOL_VERSION stays 2.15.0 - test_daemon.py: confinement (read-only/unknown no-write anywhere), module-less and dot-dot destination refusal, real daemon_detach double-fork path
This commit is contained in:
@@ -1070,6 +1070,16 @@ static bool receive_daemon_module(int fd, Config* c) {
|
||||
char* module = receive_str(fd);
|
||||
if (!module)
|
||||
return false;
|
||||
/* Guard against a hostile client flooding the log with an over-long module
|
||||
* name: only an empty string (module-less) or a valid module name
|
||||
* (bounded by DAEMON_MAX_MODULE_NAME) is accepted. This is an input
|
||||
* guard, not a wire-format change. */
|
||||
if (*module != '\0' && !daemon_module_name_valid(module)) {
|
||||
log_message(LOG_LEVEL_WARNING, "Daemon client sent an invalid or over-long module name");
|
||||
free(module);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return false;
|
||||
}
|
||||
if (*module != '\0') {
|
||||
c->module = module;
|
||||
} else {
|
||||
|
||||
Reference in New Issue
Block a user