fix: security hardening (#112-#118)

This commit is contained in:
2026-07-21 16:41:54 +02:00
parent 6b8979a040
commit 86c1d159cb
24 changed files with 665 additions and 90 deletions
+27
View File
@@ -47,6 +47,15 @@ Config* config_create(char* version, char* send_directory, char* receive_directo
config->tls_ca = NULL;
config->server_host = str_dup("127.0.0.1");
config->server_port = 8080;
config->timeout = 30;
config->contimeout = 10;
config->quiet = false;
config->backup = false;
config->backup_dir = NULL;
config->stats = false;
config->max_depth = 0;
config->log_file = NULL;
config->queue_size = 100;
return config;
}
@@ -90,6 +99,7 @@ void config_delete(Config* config) {
free(config->tls_cert);
free(config->tls_key);
free(config->tls_ca);
free(config->backup_dir);
free(config->server_host);
free(config);
}
@@ -127,6 +137,10 @@ bool config_send(int file_descriptor, const Config* config) {
return false;
if (!send_n_data(file_descriptor, &config->delta_max_file_size, sizeof(unsigned long long)))
return false;
if (!send_int(file_descriptor, config->backup))
return false;
if (!send_str(file_descriptor, config->backup_dir ? config->backup_dir : ""))
return false;
Status status;
if (!receive_status(file_descriptor, &status))
return false;
@@ -221,6 +235,19 @@ Config* config_receive(int file_descriptor) {
config->tls_cert = NULL;
config->tls_key = NULL;
config->tls_ca = NULL;
config->timeout = 30;
config->contimeout = 10;
config->quiet = false;
config->stats = false;
config->max_depth = 0;
config->log_file = NULL;
config->queue_size = 100;
if (!receive_int(file_descriptor, &tmp))
goto error;
config->backup = tmp;
config->backup_dir = receive_str(file_descriptor);
if (config->backup_dir == NULL)
goto error;
config->server_host = str_dup("127.0.0.1");
config->server_port = 8080;
if (!send_status(file_descriptor, STATUS_OK))
+10
View File
@@ -3,6 +3,7 @@
#include <stdbool.h>
#include <stdint.h>
#include <stdio.h>
typedef enum { TRANSPORT_TCP, TRANSPORT_SSH } TransportType;
@@ -40,6 +41,15 @@ typedef struct Config {
char* tls_cert;
char* tls_key;
char* tls_ca;
int timeout;
int contimeout;
bool quiet;
bool backup;
char* backup_dir;
bool stats;
int max_depth;
FILE* log_file;
int queue_size;
} Config;
#define PROTOCOL_VERSION "1.3.0"
+6 -1
View File
@@ -108,7 +108,12 @@ DeltaSignature* delta_signature_deserialize(const Data* data) {
return NULL;
}
sig->blocks = malloc(sig->block_count * sizeof(DeltaBlockSig));
uint64_t blocks_size = (uint64_t)sig->block_count * sizeof(DeltaBlockSig);
if (blocks_size > SIZE_MAX) {
free(sig);
return NULL;
}
sig->blocks = malloc((size_t)blocks_size);
if (!sig->blocks) {
free(sig);
return NULL;
+40 -8
View File
@@ -1,4 +1,5 @@
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <libgen.h>
#include <stddef.h>
@@ -42,6 +43,7 @@ File* file_create(const char* path) {
return NULL;
}
file->metadata = NULL;
file->skip = false;
return file;
}
@@ -126,7 +128,12 @@ bool file_send_single_calls(File* file, int file_descriptor, bool use_metadata,
return true;
}
bool file_save_to_disk(const char* root_directory, File* file) {
bool file_save_to_disk(const char* root_directory, File* file, const Config* config) {
(void)config;
if (has_path_traversal(file->path)) {
log_message(LOG_LEVEL_ERROR, "Path traversal detected in file path: %s", file->path);
return false;
}
char* disk_path = path_cat((char*)root_directory, file->path);
if (disk_path == NULL)
return false;
@@ -325,6 +332,13 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
return NULL;
}
if (has_path_traversal(check_path)) {
log_message(LOG_LEVEL_ERROR, "Path traversal detected: %s", check_path);
free(check_path);
send_status(fd, STATUS_ERROR);
return NULL;
}
char* full_path = path_cat(config->receive_root_directory, check_path);
struct stat st;
bool has_old_file = (full_path && stat(full_path, &st) == 0);
@@ -409,37 +423,55 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
}
bool to_disk(const char* path, const void* data, unsigned long long data_size) {
// dirname() may modify its argument and may return a pointer to static storage.
// We must use a copy of the result to be safe.
char* tmp_path = NULL;
char* directory = NULL;
char* path_dup = str_dup(path);
if (!path_dup)
return false;
const char* dir_result = dirname(path_dup);
char* directory = str_dup(dir_result);
directory = str_dup(dir_result);
free(path_dup);
if (!directory)
return false;
bool ok = true;
if (!mkdir_r(directory)) {
if (!mkdir_r(directory))
goto done;
size_t path_len = strlen(path);
tmp_path = malloc(path_len + 5);
if (!tmp_path) {
ok = false;
goto done;
}
FILE* file_pointer = fopen(path, "wb");
memcpy(tmp_path, path, path_len);
memcpy(tmp_path + path_len, ".tmp", 5);
FILE* file_pointer = fopen(tmp_path, "wb");
if (file_pointer == NULL) {
perror("Could not open File");
perror("Could not open temporary file");
ok = false;
goto done;
}
if (fwrite(data, 1, data_size, file_pointer) != data_size) {
perror("Failed to write all data to disk");
perror("Failed to write all data to temporary file");
fclose(file_pointer);
unlink(tmp_path);
ok = false;
goto done;
}
fclose(file_pointer);
if (rename(tmp_path, path) != 0) {
perror("Failed to atomically rename temporary file");
unlink(tmp_path);
ok = false;
goto done;
}
done:
free(tmp_path);
free(directory);
return ok;
}
+2 -1
View File
@@ -18,6 +18,7 @@ typedef struct {
char* path;
Data* data;
FileMetadata* metadata;
bool skip;
} File;
File* file_create(const char* path);
@@ -32,7 +33,7 @@ size_t file_content_to_buffer(File* file);
FileMetadata* file_metadata_create(const struct stat* stats);
void file_metadata_destroy(void* metadata);
bool to_disk(const char* path, const void* data, unsigned long long data_size);
bool file_save_to_disk(const char* root_directory, File* file);
bool file_save_to_disk(const char* root_directory, File* file, const Config* config);
File* receive_incremental_check(int fd, const Config* config, bool* skipped);
int receive_manifest(int fd, const Config* config, int* next_status);
+15
View File
@@ -5,11 +5,16 @@
static const char* log_level_strings[] = {"DEBUG", "INFO", "WARN", "ERROR"};
static LogLevel current_log_level = LOG_LEVEL_WARNING;
static FILE* log_fp = NULL;
void set_log_level(LogLevel level) {
current_log_level = level;
}
void log_set_file(FILE* fp) {
log_fp = fp;
}
void log_message(LogLevel log_level, char* format, ...) {
if (log_level < current_log_level)
return;
@@ -24,4 +29,14 @@ void log_message(LogLevel log_level, char* format, ...) {
vfprintf(stderr, format, args);
va_end(args);
fprintf(stderr, "\n");
if (log_fp) {
fprintf(log_fp, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t->tm_year + 1900, t->tm_mon + 1,
t->tm_mday, t->tm_hour, t->tm_min, t->tm_sec, log_level_strings[log_level]);
va_start(args, format);
vfprintf(log_fp, format, args);
va_end(args);
fprintf(log_fp, "\n");
fflush(log_fp);
}
}
+3
View File
@@ -1,9 +1,12 @@
#ifndef LOG_H
#define LOG_H
#include <stdio.h>
typedef enum { LOG_LEVEL_DEBUG, LOG_LEVEL_INFO, LOG_LEVEL_WARNING, LOG_LEVEL_ERROR } LogLevel;
void log_message(LogLevel log_level, char* message, ...);
void set_log_level(LogLevel level);
void log_set_file(FILE* fp);
#endif
+41 -2
View File
@@ -105,7 +105,17 @@ int receive_thread(void* pipeline_context) {
Status status;
if (!receive_status(file_descriptor, &status))
return thrd_error;
while (status == STATUS_NEXT || status == STATUS_CHUNK || status == STATUS_CHECK) {
while (status == STATUS_NEXT || status == STATUS_CHUNK || status == STATUS_CHECK ||
status == STATUS_KEEPALIVE || status == STATUS_ABORT ||
status == STATUS_CHECK_BATCH) {
if (status == STATUS_KEEPALIVE) {
send_status(file_descriptor, STATUS_KEEPALIVE);
goto next;
}
if (status == STATUS_ABORT) {
log_message(LOG_LEVEL_INFO, "Received abort from client, cleaning up");
return thrd_error;
}
if (status == STATUS_CHECK) {
bool skipped;
File* file = receive_incremental_check(file_descriptor, config, &skipped);
@@ -117,6 +127,34 @@ int receive_thread(void* pipeline_context) {
}
} else if (status == STATUS_CHUNK) {
receive_chunk_enqueue(file_descriptor, context);
} else if (status == STATUS_CHECK_BATCH) {
int count;
if (!receive_int(file_descriptor, &count))
return thrd_error;
for (int i = 0; i < count; i++) {
char* check_path = receive_str(file_descriptor);
if (!check_path)
return thrd_error;
unsigned long long check_size;
long long check_mtime;
if (!receive_n_data(file_descriptor, &check_size, sizeof(check_size)) ||
!receive_n_data(file_descriptor, &check_mtime, sizeof(check_mtime))) {
free(check_path);
return thrd_error;
}
char* full_path = path_cat(config->receive_root_directory, check_path);
struct stat st;
bool has_old = full_path && stat(full_path, &st) == 0;
bool match = has_old && (unsigned long long)st.st_size == check_size &&
(long long)st.st_mtime == check_mtime;
if (match)
send_status(file_descriptor, STATUS_OK);
else
send_status(file_descriptor, STATUS_NEXT);
free(full_path);
free(check_path);
}
goto next;
} else {
File* file = file_receive(config, file_descriptor);
if (file) {
@@ -126,6 +164,7 @@ int receive_thread(void* pipeline_context) {
log_message(LOG_LEVEL_ERROR, "Failed to receive file");
}
}
next:
if (!receive_status(file_descriptor, &status))
return thrd_error;
}
@@ -156,7 +195,7 @@ int write_thread(void* pipeline_context) {
return thrd_success;
}
if (save_to_disk)
file_save_to_disk(root_directory, file);
file_save_to_disk(root_directory, file, context->config);
file_destroy(file);
}
}
+42
View File
@@ -8,6 +8,10 @@
#include <time.h>
#include <unistd.h>
#define MAX_DATA_SIZE (256ULL * 1024 * 1024) /* 256 MB max per message */
#define RECEIVE_TIMEOUT_SEC 60 /* 60 second per-message timeout */
#define MAX_CONNECTION_MEMORY (1024ULL * 1024 * 1024) /* 1 GB total per connection */
static __thread int io_read_fd = -1;
static __thread int io_write_fd = -1;
static SSL* io_ssl = NULL;
@@ -16,6 +20,8 @@ static unsigned long long io_bwlimit = 0;
static long long bw_tokens = 0;
static struct timespec bw_last_refill = {0, 0};
static __thread unsigned long long total_allocated_bytes = 0;
void io_set_fds(int read_fd, int write_fd) {
io_read_fd = read_fd;
io_write_fd = write_fd;
@@ -92,8 +98,21 @@ bool send_n_data(int file_descriptor, const void* data, size_t data_size) {
bool receive_n_data(int file_descriptor, void* data, size_t data_size) {
log_message(LOG_LEVEL_DEBUG, " Receiving n Data: %zu", data_size);
int fd = io_fd(io_read_fd, file_descriptor);
struct timespec deadline;
clock_gettime(CLOCK_MONOTONIC, &deadline);
deadline.tv_sec += RECEIVE_TIMEOUT_SEC;
size_t total_bytes_received = 0;
while (total_bytes_received < data_size) {
struct timespec now;
clock_gettime(CLOCK_MONOTONIC, &now);
if (now.tv_sec > deadline.tv_sec ||
(now.tv_sec == deadline.tv_sec && now.tv_nsec > deadline.tv_nsec)) {
log_message(LOG_LEVEL_ERROR, "Receive timeout after %ds", RECEIVE_TIMEOUT_SEC);
return false;
}
ssize_t bytes_received;
if (io_ssl)
bytes_received =
@@ -132,6 +151,12 @@ static const char* status_to_string(Status status) {
return "DELTA_SIGNATURE";
case STATUS_DELTA_DATA:
return "DELTA_DATA";
case STATUS_KEEPALIVE:
return "KEEPALIVE";
case STATUS_ABORT:
return "ABORT";
case STATUS_CHECK_BATCH:
return "CHECK_BATCH";
default:
return "UNKNOWN";
}
@@ -151,6 +176,11 @@ char* receive_str(int file_descriptor) {
size_t size;
if (!receive_n_data(file_descriptor, &size, sizeof(size_t)))
return NULL;
if (size > MAX_DATA_SIZE) {
log_message(LOG_LEVEL_ERROR, "String size %zu exceeds maximum %llu", size,
(unsigned long long)MAX_DATA_SIZE);
return NULL;
}
char* data = (char*)malloc(size + 1);
if (data == NULL)
return NULL;
@@ -177,6 +207,17 @@ Data* receive_data(int file_descriptor) {
unsigned long long size = 0;
if (!receive_n_data(file_descriptor, &size, sizeof(unsigned long long)))
return NULL;
if (size > MAX_DATA_SIZE) {
log_message(LOG_LEVEL_ERROR, "Data size %llu exceeds maximum %llu", size,
(unsigned long long)MAX_DATA_SIZE);
return NULL;
}
if (total_allocated_bytes + size > MAX_CONNECTION_MEMORY) {
log_message(LOG_LEVEL_ERROR, "Per-connection memory limit exceeded (%llu + %llu > %llu)",
(unsigned long long)total_allocated_bytes, size,
(unsigned long long)MAX_CONNECTION_MEMORY);
return NULL;
}
void* data = malloc((size_t)size);
if (data == NULL)
return NULL;
@@ -184,6 +225,7 @@ Data* receive_data(int file_descriptor) {
free(data);
return NULL;
}
total_allocated_bytes += size;
log_message(LOG_LEVEL_DEBUG, "Received %lld data", size);
return data_create(data, (size_t)size);
}
+4 -1
View File
@@ -17,7 +17,10 @@ enum NET_STATUS {
STATUS_MANIFEST,
STATUS_CHECK,
STATUS_DELTA_SIGNATURE,
STATUS_DELTA_DATA
STATUS_DELTA_DATA,
STATUS_KEEPALIVE,
STATUS_ABORT,
STATUS_CHECK_BATCH
};
void io_set_fds(int read_fd, int write_fd);
+10 -3
View File
@@ -118,11 +118,18 @@ Client* client_connect_ssh(const char* destination, int port) {
if (sv[1] > 1)
close(sv[1]);
char ssh_user[512];
size_t ssh_user_len;
if (r.user && r.user[0] != '\0')
snprintf(ssh_user, sizeof(ssh_user), "%s@%s", r.user, r.host);
ssh_user_len = strlen(r.user) + 1 + strlen(r.host) + 1;
else
snprintf(ssh_user, sizeof(ssh_user), "%s", r.host);
ssh_user_len = strlen(r.host) + 1;
char* ssh_user = malloc(ssh_user_len);
if (!ssh_user)
_exit(1);
if (r.user && r.user[0] != '\0')
snprintf(ssh_user, ssh_user_len, "%s@%s", r.user, r.host);
else
snprintf(ssh_user, ssh_user_len, "%s", r.host);
char* ssh_argv[16];
int ac = 0;
+52 -1
View File
@@ -2,6 +2,7 @@
#include "log.h"
#include "protocol.h"
#include <arpa/inet.h>
#include <errno.h>
#include <openssl/ssl.h>
#include <signal.h>
#include <stdio.h>
@@ -11,6 +12,18 @@
#include <sys/wait.h>
#include <unistd.h>
static volatile unsigned int g_active_connections = 0;
static void sigchld_handler(int sig) {
(void)sig;
int saved_errno = errno;
while (waitpid(-1, NULL, WNOHANG) > 0) {
if (g_active_connections > 0)
g_active_connections--;
}
errno = saved_errno;
}
Server* server_create(int port) {
Server* server = (Server*)malloc(sizeof(Server));
if (server == NULL) {
@@ -38,6 +51,8 @@ Server* server_create(int port) {
server->address.sin_port = htons(port);
server->address_length = sizeof(server->address);
server->ssl_ctx = NULL;
server->max_connections = 100;
server->active_connections = 0;
if (bind(server->file_descriptor, (struct sockaddr*)&server->address, server->address_length) <
0) {
@@ -68,7 +83,7 @@ static void accept_loop(Server* server, void (*child_fn)(int, void*), void* chil
perror("Could not listen on port!");
return;
}
signal(SIGCHLD, SIG_IGN);
signal(SIGCHLD, sigchld_handler);
while (1) {
struct sockaddr_in client_addr;
socklen_t client_len = sizeof(client_addr);
@@ -77,6 +92,12 @@ static void accept_loop(Server* server, void (*child_fn)(int, void*), void* chil
perror("Could not accept the connection");
continue;
}
if (g_active_connections >= server->max_connections) {
log_message(LOG_LEVEL_WARNING, "Max connections (%u) reached, rejecting",
server->max_connections);
close(fd);
continue;
}
log_message(LOG_LEVEL_INFO, "%s", log_fmt);
pid_t pid = fork();
if (pid == 0) {
@@ -84,6 +105,8 @@ static void accept_loop(Server* server, void (*child_fn)(int, void*), void* chil
child_fn(fd, child_ctx);
close(fd);
_exit(0);
} else if (pid > 0) {
g_active_connections++;
}
close(fd);
}
@@ -110,6 +133,24 @@ void server_accept_loop(Server* server, void (*child_fn)(int, void*), void* chil
accept_loop(server, child_fn, child_ctx, log_fmt);
}
static int g_timeout_sec = 30;
static int g_contimeout_sec = 10;
void tcp_set_timeouts(int timeout_sec, int contimeout_sec) {
if (timeout_sec > 0)
g_timeout_sec = timeout_sec;
if (contimeout_sec > 0)
g_contimeout_sec = contimeout_sec;
}
static void tcp_apply_socket_timeout(int fd) {
struct timeval tv;
tv.tv_sec = g_timeout_sec;
tv.tv_usec = 0;
setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv));
setsockopt(fd, SOL_SOCKET, SO_SNDTIMEO, &tv, sizeof(tv));
}
Client* client_create() {
int file_descriptor = socket(AF_INET, SOCK_STREAM, 0);
if (file_descriptor < 0) {
@@ -133,17 +174,27 @@ Client* client_create() {
bool client_connect(Client* client, char* host, int port) {
client->address.sin_port = htons(port);
client->address.sin_family = AF_INET;
client->address_length = sizeof(client->address);
if (inet_pton(AF_INET, host, &client->address.sin_addr) <= 0) {
perror("Could not convert host address!");
return false;
}
struct timeval ct;
ct.tv_sec = g_contimeout_sec;
ct.tv_usec = 0;
setsockopt(client->file_descriptor, SOL_SOCKET, SO_RCVTIMEO, &ct, sizeof(ct));
setsockopt(client->file_descriptor, SOL_SOCKET, SO_SNDTIMEO, &ct, sizeof(ct));
if (connect(client->file_descriptor, (struct sockaddr*)&client->address, client->address_length) <
0) {
perror("Could not connect to Server!");
return false;
}
tcp_apply_socket_timeout(client->file_descriptor);
return true;
}
+3
View File
@@ -10,6 +10,8 @@ typedef struct Server {
unsigned int address_length;
int file_descriptor;
void* ssl_ctx;
unsigned int max_connections;
volatile unsigned int active_connections;
} Server;
typedef struct Client {
@@ -30,5 +32,6 @@ Client* client_create();
bool client_connect(Client* client, char* host, int port);
void client_disconnect(Client* client);
void client_delete(Client* client);
void tcp_set_timeouts(int timeout_sec, int contimeout_sec);
#endif
+2
View File
@@ -72,6 +72,8 @@ static SSL_CTX* create_ssl_ctx(bool is_server, const char* cert, const char* key
}
SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
SSL_CTX_set_verify_depth(ctx, 4);
} else {
SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL);
}
return ctx;
+19
View File
@@ -149,6 +149,25 @@ void delete_extras(const char* dest_root, ArrayList* manifest) {
delete_extras_walk(dest_root, "", manifest);
}
bool has_path_traversal(const char* path) {
if (!path)
return false;
char* dup = str_dup(path);
if (!dup)
return false;
char* saveptr;
const char* part = strtok_r(dup, "/", &saveptr);
while (part) {
if (strcmp(part, "..") == 0) {
free(dup);
return true;
}
part = strtok_r(NULL, "/", &saveptr);
}
free(dup);
return false;
}
char* path_cat(const char* path1, char* path2) {
if (path1 == NULL || *path1 == '\0')
return str_dup(path2);
+1
View File
@@ -9,5 +9,6 @@ char* str_dup(const char* string);
char* path_cat(const char* path1, char* path2);
bool glob_match(const char* pattern, const char* str);
void delete_extras(const char* dest_root, ArrayList* manifest);
bool has_path_traversal(const char* path);
#endif