Apply PR #143 content on top of latest main
This commit is contained in:
+21
-24
@@ -1,26 +1,31 @@
|
||||
#include "compression.h"
|
||||
#include "data.h"
|
||||
#include "log.h"
|
||||
#include <stdint.h>
|
||||
#include <stdlib.h>
|
||||
#include "stdlib.h"
|
||||
#include "string.h"
|
||||
#include <strings.h>
|
||||
#include "zstd.h"
|
||||
|
||||
#define INITIAL_DECOMPRESS_BUF_SIZE (1024 * 1024)
|
||||
|
||||
static const char* SKIP_COMPRESSION_EXTENSIONS[] = {".jpg", ".jpeg", ".png", ".gif", ".mp4", ".mkv",
|
||||
".zip", ".gz", ".xz", ".zst", NULL};
|
||||
|
||||
bool compression_should_skip(const char* path) {
|
||||
if (!path)
|
||||
return false;
|
||||
const char* dot = strrchr(path, '.');
|
||||
if (!dot)
|
||||
return false;
|
||||
for (int i = 0; SKIP_COMPRESSION_EXTENSIONS[i]; i++) {
|
||||
if (strcasecmp(dot, SKIP_COMPRESSION_EXTENSIONS[i]) == 0)
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
Data* data_compress(Data* data_to_compress, int compression_level) {
|
||||
log_message(LOG_LEVEL_DEBUG, "Starting to compress data");
|
||||
|
||||
/* Clamp compression level to valid zstd range [1, 22] */
|
||||
if (compression_level < 1) {
|
||||
log_message(LOG_LEVEL_WARNING, "compression_level %d out of range [1,22], using 1",
|
||||
compression_level);
|
||||
compression_level = 1;
|
||||
} else if (compression_level > 22) {
|
||||
log_message(LOG_LEVEL_WARNING, "compression_level %d out of range [1,22], using 22",
|
||||
compression_level);
|
||||
compression_level = 22;
|
||||
}
|
||||
|
||||
size_t dst_size = ZSTD_compressBound(data_to_compress->size);
|
||||
Data* compressed_data = data_create_empty(dst_size);
|
||||
if (compressed_data == NULL)
|
||||
@@ -79,16 +84,8 @@ Data* data_decompress(Data* compressed_data) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
size_t buf_size = INITIAL_DECOMPRESS_BUF_SIZE;
|
||||
if (!ZSTD_isError(dst_size) && dst_size > 0) {
|
||||
if (dst_size > SIZE_MAX) {
|
||||
log_message(LOG_LEVEL_ERROR,
|
||||
"Decompressed size %llu exceeds addressable memory, using fallback buffer",
|
||||
dst_size);
|
||||
} else {
|
||||
buf_size = (size_t)dst_size;
|
||||
}
|
||||
}
|
||||
size_t buf_size =
|
||||
(!ZSTD_isError(dst_size) && dst_size > 0) ? (size_t)dst_size : INITIAL_DECOMPRESS_BUF_SIZE;
|
||||
Data* uncompressed_data = data_create_empty(buf_size);
|
||||
if (!uncompressed_data) {
|
||||
log_message(LOG_LEVEL_ERROR, "Failed to allocate decompression buffer");
|
||||
|
||||
@@ -2,8 +2,10 @@
|
||||
#define COMPRESSION_H
|
||||
|
||||
#include "data.h"
|
||||
#include <stdbool.h>
|
||||
|
||||
Data* data_compress(Data* data_to_compress, int compression_level);
|
||||
Data* data_decompress(Data* compressed_data);
|
||||
bool compression_should_skip(const char* path);
|
||||
|
||||
#endif
|
||||
|
||||
+25
-108
@@ -4,7 +4,6 @@
|
||||
#include "protocol.h"
|
||||
#include "utils.h"
|
||||
#include <stdbool.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
@@ -15,7 +14,7 @@ Config* config_create(char* version, char* send_directory, char* receive_directo
|
||||
bool use_sendfile, unsigned long long chunk_size) {
|
||||
|
||||
Config* config = malloc(sizeof(Config));
|
||||
if (config == NULL)
|
||||
if (!config)
|
||||
return NULL;
|
||||
config->version = version;
|
||||
config->send_directory = send_directory;
|
||||
@@ -49,10 +48,17 @@ Config* config_create(char* version, char* send_directory, char* receive_directo
|
||||
config->tls_cert = NULL;
|
||||
config->tls_key = NULL;
|
||||
config->tls_ca = NULL;
|
||||
config->follow_symlinks = false;
|
||||
config->partial = false;
|
||||
config->server_host = str_dup("127.0.0.1");
|
||||
config->server_port = 8080;
|
||||
config->timeout = 30;
|
||||
config->contimeout = 10;
|
||||
config->quiet = false;
|
||||
config->backup = false;
|
||||
config->backup_dir = NULL;
|
||||
config->stats = false;
|
||||
config->max_depth = 0;
|
||||
config->log_file = NULL;
|
||||
config->queue_size = 100;
|
||||
return config;
|
||||
}
|
||||
|
||||
@@ -83,8 +89,6 @@ void config_parse_ssh_dest(Config* config) {
|
||||
}
|
||||
|
||||
void config_delete(Config* config) {
|
||||
if (config == NULL)
|
||||
return;
|
||||
free(config->version);
|
||||
free(config->send_directory);
|
||||
free(config->receive_root_directory);
|
||||
@@ -99,6 +103,7 @@ void config_delete(Config* config) {
|
||||
free(config->tls_cert);
|
||||
free(config->tls_key);
|
||||
free(config->tls_ca);
|
||||
free(config->backup_dir);
|
||||
free(config->server_host);
|
||||
free(config);
|
||||
}
|
||||
@@ -136,25 +141,9 @@ bool config_send(int file_descriptor, const Config* config) {
|
||||
return false;
|
||||
if (!send_n_data(file_descriptor, &config->delta_max_file_size, sizeof(unsigned long long)))
|
||||
return false;
|
||||
if (!send_int(file_descriptor, config->exclude_count))
|
||||
if (!send_int(file_descriptor, config->backup))
|
||||
return false;
|
||||
for (int i = 0; i < config->exclude_count; i++) {
|
||||
if (!send_str(file_descriptor, config->exclude_patterns[i]))
|
||||
return false;
|
||||
}
|
||||
if (!send_int(file_descriptor, config->include_count))
|
||||
return false;
|
||||
for (int i = 0; i < config->include_count; i++) {
|
||||
if (!send_str(file_descriptor, config->include_patterns[i]))
|
||||
return false;
|
||||
}
|
||||
if (!send_n_data(file_descriptor, &config->max_size, sizeof(config->max_size)))
|
||||
return false;
|
||||
if (!send_n_data(file_descriptor, &config->min_size, sizeof(config->min_size)))
|
||||
return false;
|
||||
if (!send_int(file_descriptor, config->follow_symlinks))
|
||||
return false;
|
||||
if (!send_int(file_descriptor, config->partial))
|
||||
if (!send_str(file_descriptor, config->backup_dir ? config->backup_dir : ""))
|
||||
return false;
|
||||
Status status;
|
||||
if (!receive_status(file_descriptor, &status))
|
||||
@@ -251,82 +240,19 @@ Config* config_receive(int file_descriptor) {
|
||||
config->tls_cert = NULL;
|
||||
config->tls_key = NULL;
|
||||
config->tls_ca = NULL;
|
||||
config->follow_symlinks = false;
|
||||
config->partial = false;
|
||||
|
||||
#define MAX_PATTERN_COUNT 10000
|
||||
|
||||
// Receive exclude patterns
|
||||
int ec;
|
||||
if (!receive_int(file_descriptor, &ec))
|
||||
config->timeout = 30;
|
||||
config->contimeout = 10;
|
||||
config->quiet = false;
|
||||
config->stats = false;
|
||||
config->max_depth = 0;
|
||||
config->log_file = NULL;
|
||||
config->queue_size = 100;
|
||||
if (!receive_int(file_descriptor, &tmp))
|
||||
goto error;
|
||||
if (ec > MAX_PATTERN_COUNT) {
|
||||
log_message(LOG_LEVEL_ERROR, "Exclude pattern count %d exceeds maximum %d", ec,
|
||||
MAX_PATTERN_COUNT);
|
||||
config->backup = tmp;
|
||||
config->backup_dir = receive_str(file_descriptor);
|
||||
if (config->backup_dir == NULL)
|
||||
goto error;
|
||||
}
|
||||
config->exclude_count = ec;
|
||||
if (ec > 0) {
|
||||
config->exclude_patterns = malloc((size_t)ec * sizeof(char*));
|
||||
if (!config->exclude_patterns) {
|
||||
config->exclude_count = 0;
|
||||
goto error;
|
||||
}
|
||||
for (int i = 0; i < ec; i++) {
|
||||
config->exclude_patterns[i] = receive_str(file_descriptor);
|
||||
if (!config->exclude_patterns[i]) {
|
||||
for (int j = 0; j < i; j++)
|
||||
free(config->exclude_patterns[j]);
|
||||
free(config->exclude_patterns);
|
||||
config->exclude_patterns = NULL;
|
||||
config->exclude_count = 0;
|
||||
goto error;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Receive include patterns
|
||||
int ic;
|
||||
if (!receive_int(file_descriptor, &ic))
|
||||
goto error;
|
||||
if (ic > MAX_PATTERN_COUNT) {
|
||||
log_message(LOG_LEVEL_ERROR, "Include pattern count %d exceeds maximum %d", ic,
|
||||
MAX_PATTERN_COUNT);
|
||||
goto error;
|
||||
}
|
||||
config->include_count = ic;
|
||||
if (ic > 0) {
|
||||
config->include_patterns = malloc((size_t)ic * sizeof(char*));
|
||||
if (!config->include_patterns) {
|
||||
config->include_count = 0;
|
||||
goto error;
|
||||
}
|
||||
for (int i = 0; i < ic; i++) {
|
||||
config->include_patterns[i] = receive_str(file_descriptor);
|
||||
if (!config->include_patterns[i]) {
|
||||
for (int j = 0; j < i; j++)
|
||||
free(config->include_patterns[j]);
|
||||
free(config->include_patterns);
|
||||
config->include_patterns = NULL;
|
||||
config->include_count = 0;
|
||||
goto error;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (!receive_n_data(file_descriptor, &config->max_size, sizeof(config->max_size)))
|
||||
goto error;
|
||||
if (!receive_n_data(file_descriptor, &config->min_size, sizeof(config->min_size)))
|
||||
goto error;
|
||||
int tmp_follow;
|
||||
if (!receive_int(file_descriptor, &tmp_follow))
|
||||
goto error;
|
||||
config->follow_symlinks = tmp_follow;
|
||||
int tmp_partial;
|
||||
if (!receive_int(file_descriptor, &tmp_partial))
|
||||
goto error;
|
||||
config->partial = tmp_partial;
|
||||
|
||||
config->server_host = str_dup("127.0.0.1");
|
||||
config->server_port = 8080;
|
||||
if (!send_status(file_descriptor, STATUS_OK))
|
||||
@@ -337,17 +263,8 @@ error:
|
||||
free(config->version);
|
||||
free(config->send_directory);
|
||||
free(config->receive_root_directory);
|
||||
for (int i = 0; i < config->exclude_count; i++)
|
||||
free(config->exclude_patterns[i]);
|
||||
free(config->exclude_patterns);
|
||||
for (int i = 0; i < config->include_count; i++)
|
||||
free(config->include_patterns[i]);
|
||||
free(config->include_patterns);
|
||||
free(config->tls_cert);
|
||||
free(config->tls_key);
|
||||
free(config->tls_ca);
|
||||
free(config->ssh_destination);
|
||||
free(config->server_host);
|
||||
free(config->backup_dir);
|
||||
free(config);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
+11
-3
@@ -3,6 +3,7 @@
|
||||
|
||||
#include <stdbool.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
|
||||
typedef enum { TRANSPORT_TCP, TRANSPORT_SSH } TransportType;
|
||||
|
||||
@@ -41,11 +42,18 @@ typedef struct Config {
|
||||
char* tls_cert;
|
||||
char* tls_key;
|
||||
char* tls_ca;
|
||||
bool follow_symlinks;
|
||||
bool partial;
|
||||
int timeout;
|
||||
int contimeout;
|
||||
bool quiet;
|
||||
bool backup;
|
||||
char* backup_dir;
|
||||
bool stats;
|
||||
int max_depth;
|
||||
FILE* log_file;
|
||||
int queue_size;
|
||||
} Config;
|
||||
|
||||
#define PROTOCOL_VERSION "2.0.0"
|
||||
#define PROTOCOL_VERSION "1.3.0"
|
||||
#define DEFAULT_CHUNK_SIZE (10 * 1024 * 1024)
|
||||
|
||||
Config* config_create(char* version, char* send_directory, char* receive_directory,
|
||||
|
||||
+6
-1
@@ -108,7 +108,12 @@ DeltaSignature* delta_signature_deserialize(const Data* data) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
sig->blocks = malloc(sig->block_count * sizeof(DeltaBlockSig));
|
||||
uint64_t blocks_size = (uint64_t)sig->block_count * sizeof(DeltaBlockSig);
|
||||
if (blocks_size > SIZE_MAX) {
|
||||
free(sig);
|
||||
return NULL;
|
||||
}
|
||||
sig->blocks = malloc((size_t)blocks_size);
|
||||
if (!sig->blocks) {
|
||||
free(sig);
|
||||
return NULL;
|
||||
|
||||
+92
-246
@@ -3,7 +3,6 @@
|
||||
#include <fcntl.h>
|
||||
#include <libgen.h>
|
||||
#include <stddef.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
@@ -22,9 +21,6 @@
|
||||
#include "protocol.h"
|
||||
#include "utils.h"
|
||||
|
||||
#define STREAM_THRESHOLD (64ULL * 1024 * 1024) /* 64 MB */
|
||||
#define STREAM_CHUNK_SIZE (1ULL * 1024 * 1024) /* 1 MB */
|
||||
|
||||
File* file_create(const char* path) {
|
||||
File* file = (File*)malloc(sizeof(File));
|
||||
if (file == NULL) {
|
||||
@@ -39,7 +35,7 @@ File* file_create(const char* path) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
memcpy(file->path, path, path_len + 1);
|
||||
strcpy(file->path, path);
|
||||
file->data = data_create_reserve(0);
|
||||
if (file->data == NULL) {
|
||||
free(file->path);
|
||||
@@ -47,8 +43,7 @@ File* file_create(const char* path) {
|
||||
return NULL;
|
||||
}
|
||||
file->metadata = NULL;
|
||||
file->type = FILE_TYPE_REGULAR;
|
||||
file->link_target = NULL;
|
||||
file->skip = false;
|
||||
return file;
|
||||
}
|
||||
|
||||
@@ -62,8 +57,6 @@ void file_destroy(void* item) {
|
||||
file->metadata = NULL;
|
||||
free(file->path);
|
||||
file->path = NULL;
|
||||
free(file->link_target);
|
||||
file->link_target = NULL;
|
||||
free(file);
|
||||
}
|
||||
|
||||
@@ -92,14 +85,6 @@ void file_metadata_destroy(void* metadata) {
|
||||
bool file_load_data(File* file) {
|
||||
if (file == NULL)
|
||||
return false;
|
||||
// Symlinks have no data to load
|
||||
if (file->type == FILE_TYPE_SYMLINK)
|
||||
return true;
|
||||
// For streaming files, just record the size, don't load into memory
|
||||
if (file->data->size > STREAM_THRESHOLD) {
|
||||
// Don't allocate; streaming will read directly from disk
|
||||
return true;
|
||||
}
|
||||
if (file->data->data == NULL) {
|
||||
file->data->data = malloc(file->data->size);
|
||||
if (file->data->data == NULL) {
|
||||
@@ -110,87 +95,16 @@ bool file_load_data(File* file) {
|
||||
size_t bytes_read = file_content_to_buffer(file);
|
||||
if (bytes_read != file->data->size) {
|
||||
log_message(LOG_LEVEL_ERROR, "Did not read expected amount of bytes from file");
|
||||
free(file->data->data);
|
||||
file->data->data = NULL;
|
||||
file->data->size = 0;
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
// Stream file content in chunks without loading entire file into RAM
|
||||
static bool file_send_streaming(File* file, int file_descriptor) {
|
||||
unsigned long long total_size = file->data->size;
|
||||
// Send total size prefix (same wire format as send_data)
|
||||
if (!send_n_data(file_descriptor, &total_size, sizeof(total_size)))
|
||||
return false;
|
||||
|
||||
FILE* fp = fopen(file->path, "rb");
|
||||
if (!fp) {
|
||||
perror("Could not open file for streaming");
|
||||
return false;
|
||||
}
|
||||
|
||||
char* buf = malloc(STREAM_CHUNK_SIZE);
|
||||
if (!buf) {
|
||||
fclose(fp);
|
||||
return false;
|
||||
}
|
||||
unsigned long long remaining = total_size;
|
||||
while (remaining > 0) {
|
||||
size_t to_read = (size_t)((remaining < STREAM_CHUNK_SIZE) ? remaining : STREAM_CHUNK_SIZE);
|
||||
size_t nread = fread(buf, 1, to_read, fp);
|
||||
if (nread != to_read) {
|
||||
if (ferror(fp)) {
|
||||
perror("Read error during streaming");
|
||||
}
|
||||
send_status(file_descriptor, STATUS_ERROR);
|
||||
free(buf);
|
||||
fclose(fp);
|
||||
return false;
|
||||
}
|
||||
if (!send_n_data(file_descriptor, buf, nread)) {
|
||||
send_status(file_descriptor, STATUS_ERROR);
|
||||
free(buf);
|
||||
fclose(fp);
|
||||
return false;
|
||||
}
|
||||
remaining -= (unsigned long long)nread;
|
||||
}
|
||||
free(buf);
|
||||
fclose(fp);
|
||||
return true;
|
||||
}
|
||||
|
||||
bool file_send_single_calls(File* file, int file_descriptor, bool use_metadata,
|
||||
int compression_level, bool send_path) {
|
||||
if (send_path && !send_str(file_descriptor, file->path))
|
||||
return false;
|
||||
if (use_metadata && !metadata_send(file_descriptor, file->metadata))
|
||||
return false;
|
||||
|
||||
// Send file type indicator so receiver can distinguish regular from symlink
|
||||
int ft = (int)file->type;
|
||||
if (!send_int(file_descriptor, ft))
|
||||
return false;
|
||||
|
||||
if (file->type == FILE_TYPE_SYMLINK) {
|
||||
// Send link target, then zero-length data
|
||||
if (!send_str(file_descriptor, file->link_target ? file->link_target : ""))
|
||||
return false;
|
||||
Data empty = {NULL, 0};
|
||||
return send_data(file_descriptor, &empty);
|
||||
}
|
||||
|
||||
const Data* data_to_send = file->data;
|
||||
Data* compressed_data = NULL;
|
||||
|
||||
// Streaming mode: for large files without compression, stream from disk
|
||||
if (file->data->size > STREAM_THRESHOLD && compression_level == 0) {
|
||||
return file_send_streaming(file, file_descriptor);
|
||||
}
|
||||
|
||||
if (compression_level > 0) {
|
||||
if (compression_level > 0 && !compression_should_skip(file->path)) {
|
||||
compressed_data = data_compress(file->data, compression_level);
|
||||
if (compressed_data == NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "Failed to compress file data");
|
||||
@@ -198,6 +112,14 @@ bool file_send_single_calls(File* file, int file_descriptor, bool use_metadata,
|
||||
}
|
||||
data_to_send = compressed_data;
|
||||
}
|
||||
if (send_path && !send_str(file_descriptor, file->path)) {
|
||||
data_destroy(compressed_data);
|
||||
return false;
|
||||
}
|
||||
if (use_metadata && !metadata_send(file_descriptor, file->metadata)) {
|
||||
data_destroy(compressed_data);
|
||||
return false;
|
||||
}
|
||||
if (!send_data(file_descriptor, data_to_send)) {
|
||||
data_destroy(compressed_data);
|
||||
return false;
|
||||
@@ -206,38 +128,15 @@ bool file_send_single_calls(File* file, int file_descriptor, bool use_metadata,
|
||||
return true;
|
||||
}
|
||||
|
||||
bool file_save_to_disk(const char* root_directory, File* file) {
|
||||
if (file->type == FILE_TYPE_SYMLINK && file->link_target) {
|
||||
// Validate link_target — reject absolute paths or traversal
|
||||
if (file->link_target[0] == '/' || strstr(file->link_target, "..") != NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal blocked in symlink target: %s",
|
||||
file->link_target);
|
||||
return false;
|
||||
}
|
||||
char* disk_path = path_cat((char*)root_directory, file->path);
|
||||
if (disk_path == NULL)
|
||||
return false;
|
||||
if (strstr(disk_path, "..") != NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal blocked: %s", disk_path);
|
||||
free(disk_path);
|
||||
return false;
|
||||
}
|
||||
unlink(disk_path);
|
||||
bool ok = (symlink(file->link_target, disk_path) == 0);
|
||||
if (ok && file->metadata)
|
||||
file_restore_metadata(disk_path, file->metadata);
|
||||
free(disk_path);
|
||||
return ok;
|
||||
bool file_save_to_disk(const char* root_directory, File* file, const Config* config) {
|
||||
(void)config;
|
||||
if (has_path_traversal(file->path)) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal detected in file path: %s", file->path);
|
||||
return false;
|
||||
}
|
||||
|
||||
char* disk_path = path_cat((char*)root_directory, file->path);
|
||||
if (disk_path == NULL)
|
||||
return false;
|
||||
if (strstr(disk_path, "..") != NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal blocked: %s", disk_path);
|
||||
free(disk_path);
|
||||
return false;
|
||||
}
|
||||
bool ok = to_disk(disk_path, file->data->data, file->data->size);
|
||||
if (ok)
|
||||
file_restore_metadata(disk_path, file->metadata);
|
||||
@@ -263,60 +162,19 @@ static void* old_data_from_path(const char* full_path, unsigned long long old_si
|
||||
return data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Helper: receive data from wire, optionally decompress, and store in file.
|
||||
* On success, returns the received Data* (caller owns it). On failure, returns NULL.
|
||||
* If `file_data` is received via receive_data(fd), this function handles decompression
|
||||
* when config->use_compression is set.
|
||||
*/
|
||||
static Data* receive_and_decompress(int fd, const Config* config) {
|
||||
Data* file_data = receive_data(fd);
|
||||
if (file_data == NULL)
|
||||
return NULL;
|
||||
if (config->use_compression) {
|
||||
Data* uncompressed = data_decompress(file_data);
|
||||
data_destroy(file_data);
|
||||
if (uncompressed == NULL)
|
||||
return NULL;
|
||||
file_data = uncompressed;
|
||||
}
|
||||
return file_data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Helper: receive metadata from wire and assign to file.
|
||||
* Returns true on success (metadata may be NULL if absent), false on I/O error.
|
||||
*/
|
||||
static bool receive_and_assign_metadata(int fd, const Config* config, File* file) {
|
||||
if (!config->use_metadata)
|
||||
return true;
|
||||
int meta_ok = 1;
|
||||
file->metadata = metadata_receive(fd, &meta_ok);
|
||||
if (!meta_ok) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
static File* receive_delta_file(int fd, const Config* config, const char* check_path,
|
||||
void* old_data, unsigned long long old_size) {
|
||||
if (!old_data) {
|
||||
send_status(fd, STATUS_ERROR);
|
||||
if (!old_data)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
DeltaSignature* sig = delta_signature_create(old_data, old_size, config->delta_block_size);
|
||||
if (!sig) {
|
||||
send_status(fd, STATUS_ERROR);
|
||||
free(old_data);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
Data* sig_data = delta_signature_serialize(sig);
|
||||
if (!sig_data) {
|
||||
send_status(fd, STATUS_ERROR);
|
||||
delta_signature_destroy(sig);
|
||||
free(old_data);
|
||||
return NULL;
|
||||
@@ -419,16 +277,34 @@ static File* receive_delta_file(int fd, const Config* config, const char* check_
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (!receive_and_assign_metadata(fd, config, file))
|
||||
return NULL;
|
||||
if (config->use_metadata) {
|
||||
int meta_ok = 1;
|
||||
file->metadata = metadata_receive(fd, &meta_ok);
|
||||
if (!meta_ok) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
Data* file_data = receive_and_decompress(fd, config);
|
||||
Data* file_data = receive_data(fd);
|
||||
if (file_data == NULL) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (config->use_compression) {
|
||||
Data* uncompressed = data_decompress(file_data);
|
||||
data_destroy(file_data);
|
||||
if (uncompressed == NULL) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
file_data = uncompressed;
|
||||
}
|
||||
|
||||
data_destroy(file->data);
|
||||
file->data = file_data;
|
||||
return file;
|
||||
@@ -456,30 +332,18 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
char* full_path = path_cat(config->receive_root_directory, check_path);
|
||||
if (full_path && strstr(full_path, "..") != NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal blocked: %s", full_path);
|
||||
free(full_path);
|
||||
if (has_path_traversal(check_path)) {
|
||||
log_message(LOG_LEVEL_ERROR, "Path traversal detected: %s", check_path);
|
||||
free(check_path);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
char* full_path = path_cat(config->receive_root_directory, check_path);
|
||||
struct stat st;
|
||||
bool has_old_file = (full_path && stat(full_path, &st) == 0);
|
||||
unsigned long long old_size = has_old_file ? (unsigned long long)st.st_size : 0;
|
||||
|
||||
// Check for partial file if enabled
|
||||
if (config->partial && !has_old_file && full_path) {
|
||||
char* partial_path = malloc(strlen(full_path) + 20);
|
||||
if (partial_path) {
|
||||
snprintf(partial_path, strlen(full_path) + 20, "%s.fastsync-partial", full_path);
|
||||
has_old_file = (stat(partial_path, &st) == 0);
|
||||
if (has_old_file)
|
||||
old_size = (unsigned long long)st.st_size;
|
||||
free(partial_path);
|
||||
}
|
||||
}
|
||||
|
||||
bool match = has_old_file && (unsigned long long)st.st_size == check_size &&
|
||||
(long long)st.st_mtime == check_mtime;
|
||||
|
||||
@@ -525,86 +389,102 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (!receive_and_assign_metadata(fd, config, file))
|
||||
return NULL;
|
||||
|
||||
int file_type;
|
||||
if (!receive_int(fd, &file_type)) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
file->type = (FileType)file_type;
|
||||
|
||||
if (file->type == FILE_TYPE_SYMLINK) {
|
||||
char* link_target = receive_str(fd);
|
||||
if (link_target) {
|
||||
file->link_target = link_target;
|
||||
if (config->use_metadata) {
|
||||
int meta_ok = 1;
|
||||
file->metadata = metadata_receive(fd, &meta_ok);
|
||||
if (!meta_ok) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
Data* empty_data = receive_data(fd);
|
||||
if (empty_data)
|
||||
data_destroy(empty_data);
|
||||
return file;
|
||||
}
|
||||
|
||||
Data* file_data = receive_and_decompress(fd, config);
|
||||
Data* file_data = receive_data(fd);
|
||||
if (file_data == NULL) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (config->use_compression) {
|
||||
Data* uncompressed = data_decompress(file_data);
|
||||
data_destroy(file_data);
|
||||
if (uncompressed == NULL) {
|
||||
file_destroy(file);
|
||||
send_status(fd, STATUS_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
file_data = uncompressed;
|
||||
}
|
||||
|
||||
data_destroy(file->data);
|
||||
file->data = file_data;
|
||||
return file;
|
||||
}
|
||||
|
||||
bool to_disk(const char* path, const void* data, unsigned long long data_size) {
|
||||
// dirname() may modify its argument and may return a pointer to static storage.
|
||||
// We must use a copy of the result to be safe.
|
||||
char* tmp_path = NULL;
|
||||
char* directory = NULL;
|
||||
|
||||
char* path_dup = str_dup(path);
|
||||
if (!path_dup)
|
||||
return false;
|
||||
const char* dir_result = dirname(path_dup);
|
||||
char* directory = str_dup(dir_result);
|
||||
directory = str_dup(dir_result);
|
||||
free(path_dup);
|
||||
if (!directory)
|
||||
return false;
|
||||
|
||||
bool ok = true;
|
||||
if (!mkdir_r(directory)) {
|
||||
if (!mkdir_r(directory))
|
||||
goto done;
|
||||
|
||||
size_t path_len = strlen(path);
|
||||
tmp_path = malloc(path_len + 5);
|
||||
if (!tmp_path) {
|
||||
ok = false;
|
||||
goto done;
|
||||
}
|
||||
FILE* file_pointer = fopen(path, "wb");
|
||||
memcpy(tmp_path, path, path_len);
|
||||
memcpy(tmp_path + path_len, ".tmp", 5);
|
||||
|
||||
FILE* file_pointer = fopen(tmp_path, "wb");
|
||||
if (file_pointer == NULL) {
|
||||
perror("Could not open File");
|
||||
perror("Could not open temporary file");
|
||||
ok = false;
|
||||
goto done;
|
||||
}
|
||||
if (fwrite(data, 1, data_size, file_pointer) != data_size) {
|
||||
perror("Failed to write all data to disk");
|
||||
perror("Failed to write all data to temporary file");
|
||||
fclose(file_pointer);
|
||||
unlink(tmp_path);
|
||||
ok = false;
|
||||
goto done;
|
||||
}
|
||||
fclose(file_pointer);
|
||||
|
||||
if (rename(tmp_path, path) != 0) {
|
||||
perror("Failed to atomically rename temporary file");
|
||||
unlink(tmp_path);
|
||||
ok = false;
|
||||
goto done;
|
||||
}
|
||||
|
||||
done:
|
||||
free(tmp_path);
|
||||
free(directory);
|
||||
return ok;
|
||||
}
|
||||
|
||||
bool file_send_sendfile(File* file, int file_descriptor, bool use_metadata, int compression_level,
|
||||
bool send_path) {
|
||||
// Handle symlinks
|
||||
if (file->type == FILE_TYPE_SYMLINK) {
|
||||
return file_send_single_calls(file, file_descriptor, use_metadata, compression_level,
|
||||
send_path);
|
||||
}
|
||||
|
||||
// sendfile is incompatible with compression (kernel zero-copy).
|
||||
// If compression is requested, fall back to the regular send path.
|
||||
// NOTE: This is a safety net only — callers must ensure compression_level == 0
|
||||
// before calling file_send_sendfile. The fallback to file_send_single_calls
|
||||
// preserves the send_path contract, but callers should not rely on it for
|
||||
// correctness (the --sendfile flag is validated to be mutually exclusive with
|
||||
// -c/--compress at the CLI layer).
|
||||
if (compression_level > 0)
|
||||
return file_send_single_calls(file, file_descriptor, use_metadata, compression_level,
|
||||
send_path);
|
||||
@@ -614,10 +494,6 @@ bool file_send_sendfile(File* file, int file_descriptor, bool use_metadata, int
|
||||
if (use_metadata && !metadata_send(file_descriptor, file->metadata))
|
||||
return false;
|
||||
|
||||
int ft = (int)file->type;
|
||||
if (!send_int(file_descriptor, ft))
|
||||
return false;
|
||||
|
||||
int fd = open(file->path, O_RDONLY);
|
||||
if (fd == -1) {
|
||||
perror("Could not open file for sendfile");
|
||||
@@ -632,13 +508,8 @@ bool file_send_sendfile(File* file, int file_descriptor, bool use_metadata, int
|
||||
|
||||
off_t offset = 0;
|
||||
while ((unsigned long long)offset < file_size) {
|
||||
size_t send_count = (size_t)(file_size - (unsigned long long)offset);
|
||||
if ((unsigned long long)send_count != file_size - (unsigned long long)offset)
|
||||
send_count = SIZE_MAX;
|
||||
ssize_t sent = sendfile(file_descriptor, fd, &offset, send_count);
|
||||
ssize_t sent = sendfile(file_descriptor, fd, &offset, file_size - offset);
|
||||
if (sent == -1) {
|
||||
if (errno == EINTR)
|
||||
continue;
|
||||
perror("sendfile failed");
|
||||
close(fd);
|
||||
return false;
|
||||
@@ -665,30 +536,6 @@ File* file_receive(const Config* config, int file_descriptor) {
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
// Receive file type indicator
|
||||
int file_type;
|
||||
if (!receive_int(file_descriptor, &file_type)) {
|
||||
file_destroy(file);
|
||||
return NULL;
|
||||
}
|
||||
file->type = (FileType)file_type;
|
||||
|
||||
if (file->type == FILE_TYPE_SYMLINK) {
|
||||
char* link_target = receive_str(file_descriptor);
|
||||
if (link_target == NULL) {
|
||||
file_destroy(file);
|
||||
return NULL;
|
||||
}
|
||||
file->link_target = link_target;
|
||||
// Receive and discard zero-length data
|
||||
Data* empty_data = receive_data(file_descriptor);
|
||||
if (empty_data)
|
||||
data_destroy(empty_data);
|
||||
return file;
|
||||
}
|
||||
|
||||
// Regular file - receive data
|
||||
Data* file_data = receive_data(file_descriptor);
|
||||
if (file_data == NULL) {
|
||||
file_destroy(file);
|
||||
@@ -703,7 +550,6 @@ File* file_receive(const Config* config, int file_descriptor) {
|
||||
}
|
||||
file_data = file_data_uncompressed;
|
||||
}
|
||||
|
||||
data_destroy(file->data);
|
||||
file->data = file_data;
|
||||
return file;
|
||||
|
||||
+2
-3
@@ -20,8 +20,7 @@ typedef struct {
|
||||
char* path;
|
||||
Data* data;
|
||||
FileMetadata* metadata;
|
||||
FileType type;
|
||||
char* link_target;
|
||||
bool skip;
|
||||
} File;
|
||||
|
||||
File* file_create(const char* path);
|
||||
@@ -36,7 +35,7 @@ size_t file_content_to_buffer(File* file);
|
||||
FileMetadata* file_metadata_create(const struct stat* stats);
|
||||
void file_metadata_destroy(void* metadata);
|
||||
bool to_disk(const char* path, const void* data, unsigned long long data_size);
|
||||
bool file_save_to_disk(const char* root_directory, File* file);
|
||||
bool file_save_to_disk(const char* root_directory, File* file, const Config* config);
|
||||
File* receive_incremental_check(int fd, const Config* config, bool* skipped);
|
||||
int receive_manifest(int fd, const Config* config, int* next_status);
|
||||
|
||||
|
||||
+16
-4
@@ -5,19 +5,21 @@
|
||||
|
||||
static const char* log_level_strings[] = {"DEBUG", "INFO", "WARN", "ERROR"};
|
||||
static LogLevel current_log_level = LOG_LEVEL_WARNING;
|
||||
static FILE* log_fp = NULL;
|
||||
|
||||
void set_log_level(LogLevel level) {
|
||||
current_log_level = level;
|
||||
}
|
||||
|
||||
void log_set_file(FILE* fp) {
|
||||
log_fp = fp;
|
||||
}
|
||||
|
||||
void log_message(LogLevel log_level, const char* format, ...) {
|
||||
if (log_level < current_log_level)
|
||||
return;
|
||||
time_t now = time(NULL);
|
||||
struct tm result_buf;
|
||||
const struct tm* t = localtime_r(&now, &result_buf);
|
||||
if (t == NULL)
|
||||
return;
|
||||
const struct tm* t = localtime(&now);
|
||||
|
||||
fprintf(stderr, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t->tm_year + 1900, t->tm_mon + 1,
|
||||
t->tm_mday, t->tm_hour, t->tm_min, t->tm_sec, log_level_strings[log_level]);
|
||||
@@ -27,4 +29,14 @@ void log_message(LogLevel log_level, const char* format, ...) {
|
||||
vfprintf(stderr, format, args);
|
||||
va_end(args);
|
||||
fprintf(stderr, "\n");
|
||||
|
||||
if (log_fp) {
|
||||
fprintf(log_fp, "%04d-%02d-%02d %02d:%02d:%02d [%s]: ", t->tm_year + 1900, t->tm_mon + 1,
|
||||
t->tm_mday, t->tm_hour, t->tm_min, t->tm_sec, log_level_strings[log_level]);
|
||||
va_start(args, format);
|
||||
vfprintf(log_fp, format, args);
|
||||
va_end(args);
|
||||
fprintf(log_fp, "\n");
|
||||
fflush(log_fp);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,9 +1,12 @@
|
||||
#ifndef LOG_H
|
||||
#define LOG_H
|
||||
|
||||
#include <stdio.h>
|
||||
|
||||
typedef enum { LOG_LEVEL_DEBUG, LOG_LEVEL_INFO, LOG_LEVEL_WARNING, LOG_LEVEL_ERROR } LogLevel;
|
||||
|
||||
void log_message(LogLevel log_level, const char* message, ...);
|
||||
void set_log_level(LogLevel level);
|
||||
void log_set_file(FILE* fp);
|
||||
|
||||
#endif
|
||||
|
||||
@@ -105,7 +105,16 @@ int receive_thread(void* pipeline_context) {
|
||||
Status status;
|
||||
if (!receive_status(file_descriptor, &status))
|
||||
return thrd_error;
|
||||
while (status == STATUS_NEXT || status == STATUS_CHUNK || status == STATUS_CHECK) {
|
||||
while (status == STATUS_NEXT || status == STATUS_CHUNK || status == STATUS_CHECK ||
|
||||
status == STATUS_KEEPALIVE || status == STATUS_ABORT || status == STATUS_CHECK_BATCH) {
|
||||
if (status == STATUS_KEEPALIVE) {
|
||||
send_status(file_descriptor, STATUS_KEEPALIVE);
|
||||
goto next;
|
||||
}
|
||||
if (status == STATUS_ABORT) {
|
||||
log_message(LOG_LEVEL_INFO, "Received abort from client, cleaning up");
|
||||
return thrd_error;
|
||||
}
|
||||
if (status == STATUS_CHECK) {
|
||||
bool skipped;
|
||||
File* file = receive_incremental_check(file_descriptor, config, &skipped);
|
||||
@@ -117,6 +126,34 @@ int receive_thread(void* pipeline_context) {
|
||||
}
|
||||
} else if (status == STATUS_CHUNK) {
|
||||
receive_chunk_enqueue(file_descriptor, context);
|
||||
} else if (status == STATUS_CHECK_BATCH) {
|
||||
int count;
|
||||
if (!receive_int(file_descriptor, &count))
|
||||
return thrd_error;
|
||||
for (int i = 0; i < count; i++) {
|
||||
char* check_path = receive_str(file_descriptor);
|
||||
if (!check_path)
|
||||
return thrd_error;
|
||||
unsigned long long check_size;
|
||||
long long check_mtime;
|
||||
if (!receive_n_data(file_descriptor, &check_size, sizeof(check_size)) ||
|
||||
!receive_n_data(file_descriptor, &check_mtime, sizeof(check_mtime))) {
|
||||
free(check_path);
|
||||
return thrd_error;
|
||||
}
|
||||
char* full_path = path_cat(config->receive_root_directory, check_path);
|
||||
struct stat st;
|
||||
bool has_old = full_path && stat(full_path, &st) == 0;
|
||||
bool match = has_old && (unsigned long long)st.st_size == check_size &&
|
||||
(long long)st.st_mtime == check_mtime;
|
||||
if (match)
|
||||
send_status(file_descriptor, STATUS_OK);
|
||||
else
|
||||
send_status(file_descriptor, STATUS_NEXT);
|
||||
free(full_path);
|
||||
free(check_path);
|
||||
}
|
||||
goto next;
|
||||
} else {
|
||||
File* file = file_receive(config, file_descriptor);
|
||||
if (file) {
|
||||
@@ -126,6 +163,7 @@ int receive_thread(void* pipeline_context) {
|
||||
log_message(LOG_LEVEL_ERROR, "Failed to receive file");
|
||||
}
|
||||
}
|
||||
next:
|
||||
if (!receive_status(file_descriptor, &status))
|
||||
return thrd_error;
|
||||
}
|
||||
@@ -156,7 +194,7 @@ int write_thread(void* pipeline_context) {
|
||||
return thrd_success;
|
||||
}
|
||||
if (save_to_disk)
|
||||
file_save_to_disk(root_directory, file);
|
||||
file_save_to_disk(root_directory, file, context->config);
|
||||
file_destroy(file);
|
||||
}
|
||||
}
|
||||
|
||||
+49
-22
@@ -2,20 +2,27 @@
|
||||
#include "log.h"
|
||||
#include <errno.h>
|
||||
#include <openssl/ssl.h>
|
||||
#include <poll.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <time.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#define MAX_DATA_SIZE (256ULL * 1024 * 1024) /* 256 MB max per message */
|
||||
#define RECEIVE_TIMEOUT_SEC 60 /* 60 second per-message timeout */
|
||||
#define MAX_CONNECTION_MEMORY (1024ULL * 1024 * 1024) /* 1 GB total per connection */
|
||||
|
||||
static __thread int io_read_fd = -1;
|
||||
static __thread int io_write_fd = -1;
|
||||
static SSL* io_ssl = NULL;
|
||||
static SSL* io_ssl;
|
||||
|
||||
static unsigned long long io_bwlimit = 0;
|
||||
static long long bw_tokens = 0;
|
||||
static struct timespec bw_last_refill = {0, 0};
|
||||
|
||||
static __thread unsigned long long total_allocated_bytes = 0;
|
||||
|
||||
void io_set_fds(int read_fd, int write_fd) {
|
||||
io_read_fd = read_fd;
|
||||
io_write_fd = write_fd;
|
||||
@@ -46,12 +53,11 @@ static void bw_throttle(size_t bytes_written) {
|
||||
bw_tokens -= (long long)bytes_written;
|
||||
|
||||
if (bw_tokens < 0) {
|
||||
long long deficit_ns = (long long)((double)(-bw_tokens) / io_bwlimit * 1000000000.0);
|
||||
struct timespec sleep_time, remaining;
|
||||
sleep_time.tv_sec = deficit_ns / 1000000000LL;
|
||||
sleep_time.tv_nsec = deficit_ns % 1000000000LL;
|
||||
while (nanosleep(&sleep_time, &remaining) < 0 && errno == EINTR)
|
||||
sleep_time = remaining;
|
||||
long long deficit_us = (long long)((double)(-bw_tokens) / io_bwlimit * 1000000.0);
|
||||
if (deficit_us >= 1000)
|
||||
poll(NULL, 0, (int)(deficit_us / 1000));
|
||||
else
|
||||
usleep((useconds_t)deficit_us);
|
||||
bw_tokens = 0;
|
||||
clock_gettime(CLOCK_MONOTONIC, &bw_last_refill);
|
||||
}
|
||||
@@ -97,8 +103,21 @@ bool send_n_data(int file_descriptor, const void* data, size_t data_size) {
|
||||
bool receive_n_data(int file_descriptor, void* data, size_t data_size) {
|
||||
log_message(LOG_LEVEL_DEBUG, " Receiving n Data: %zu", data_size);
|
||||
int fd = io_fd(io_read_fd, file_descriptor);
|
||||
|
||||
struct timespec deadline;
|
||||
clock_gettime(CLOCK_MONOTONIC, &deadline);
|
||||
deadline.tv_sec += RECEIVE_TIMEOUT_SEC;
|
||||
|
||||
size_t total_bytes_received = 0;
|
||||
while (total_bytes_received < data_size) {
|
||||
struct timespec now;
|
||||
clock_gettime(CLOCK_MONOTONIC, &now);
|
||||
if (now.tv_sec > deadline.tv_sec ||
|
||||
(now.tv_sec == deadline.tv_sec && now.tv_nsec > deadline.tv_nsec)) {
|
||||
log_message(LOG_LEVEL_ERROR, "Receive timeout after %ds", RECEIVE_TIMEOUT_SEC);
|
||||
return false;
|
||||
}
|
||||
|
||||
ssize_t bytes_received;
|
||||
if (io_ssl)
|
||||
bytes_received =
|
||||
@@ -107,9 +126,9 @@ bool receive_n_data(int file_descriptor, void* data, size_t data_size) {
|
||||
bytes_received =
|
||||
read(fd, (char*)data + total_bytes_received, data_size - total_bytes_received);
|
||||
if (bytes_received <= 0) {
|
||||
if (io_ssl && bytes_received < 0) {
|
||||
if (io_ssl) {
|
||||
int ssl_err = SSL_get_error(io_ssl, (int)bytes_received);
|
||||
if (ssl_err == SSL_ERROR_WANT_READ || ssl_err == SSL_ERROR_WANT_WRITE)
|
||||
if (ssl_err == SSL_ERROR_WANT_WRITE || ssl_err == SSL_ERROR_WANT_READ)
|
||||
continue;
|
||||
}
|
||||
if (bytes_received == 0)
|
||||
@@ -142,16 +161,18 @@ static const char* status_to_string(Status status) {
|
||||
return "DELTA_SIGNATURE";
|
||||
case STATUS_DELTA_DATA:
|
||||
return "DELTA_DATA";
|
||||
case STATUS_KEEPALIVE:
|
||||
return "KEEPALIVE";
|
||||
case STATUS_ABORT:
|
||||
return "ABORT";
|
||||
case STATUS_CHECK_BATCH:
|
||||
return "CHECK_BATCH";
|
||||
default:
|
||||
return "UNKNOWN";
|
||||
}
|
||||
}
|
||||
|
||||
bool send_str(int file_descriptor, const char* data) {
|
||||
if (data == NULL) {
|
||||
log_message(LOG_LEVEL_ERROR, "send_str called with NULL data");
|
||||
return false;
|
||||
}
|
||||
size_t size = strlen(data);
|
||||
if (!send_n_data(file_descriptor, &size, sizeof(size_t)))
|
||||
return false;
|
||||
@@ -165,9 +186,9 @@ char* receive_str(int file_descriptor) {
|
||||
size_t size;
|
||||
if (!receive_n_data(file_descriptor, &size, sizeof(size_t)))
|
||||
return NULL;
|
||||
if (size > MAX_STRING_SIZE) {
|
||||
log_message(LOG_LEVEL_ERROR, "receive_str: size %zu exceeds maximum %zu", size,
|
||||
(size_t)MAX_STRING_SIZE);
|
||||
if (size > MAX_DATA_SIZE) {
|
||||
log_message(LOG_LEVEL_ERROR, "String size %zu exceeds maximum %llu", size,
|
||||
(unsigned long long)MAX_DATA_SIZE);
|
||||
return NULL;
|
||||
}
|
||||
char* data = (char*)malloc(size + 1);
|
||||
@@ -188,18 +209,23 @@ bool send_data(int file_descriptor, const Data* data) {
|
||||
return false;
|
||||
if (!send_n_data(file_descriptor, data->data, data_size))
|
||||
return false;
|
||||
log_message(LOG_LEVEL_DEBUG, "Send %llu data", data_size);
|
||||
log_message(LOG_LEVEL_DEBUG, "Send %lld data", data_size);
|
||||
return true;
|
||||
}
|
||||
|
||||
#define MAX_DATA_SIZE (1024ULL * 1024 * 1024)
|
||||
|
||||
Data* receive_data(int file_descriptor) {
|
||||
unsigned long long size = 0;
|
||||
if (!receive_n_data(file_descriptor, &size, sizeof(unsigned long long)))
|
||||
return NULL;
|
||||
if ((size_t)size != size || size > MAX_DATA_SIZE) {
|
||||
log_message(LOG_LEVEL_ERROR, "receive_data size %llu exceeds limits", size);
|
||||
if (size > MAX_DATA_SIZE) {
|
||||
log_message(LOG_LEVEL_ERROR, "Data size %llu exceeds maximum %llu", size,
|
||||
(unsigned long long)MAX_DATA_SIZE);
|
||||
return NULL;
|
||||
}
|
||||
if (total_allocated_bytes + size > MAX_CONNECTION_MEMORY) {
|
||||
log_message(LOG_LEVEL_ERROR, "Per-connection memory limit exceeded (%llu + %llu > %llu)",
|
||||
(unsigned long long)total_allocated_bytes, size,
|
||||
(unsigned long long)MAX_CONNECTION_MEMORY);
|
||||
return NULL;
|
||||
}
|
||||
void* data = malloc((size_t)size);
|
||||
@@ -209,7 +235,8 @@ Data* receive_data(int file_descriptor) {
|
||||
free(data);
|
||||
return NULL;
|
||||
}
|
||||
log_message(LOG_LEVEL_DEBUG, "Received %llu data", size);
|
||||
total_allocated_bytes += size;
|
||||
log_message(LOG_LEVEL_DEBUG, "Received %lld data", size);
|
||||
return data_create(data, (size_t)size);
|
||||
}
|
||||
|
||||
|
||||
@@ -20,7 +20,10 @@ enum NET_STATUS {
|
||||
STATUS_MANIFEST,
|
||||
STATUS_CHECK,
|
||||
STATUS_DELTA_SIGNATURE,
|
||||
STATUS_DELTA_DATA
|
||||
STATUS_DELTA_DATA,
|
||||
STATUS_KEEPALIVE,
|
||||
STATUS_ABORT,
|
||||
STATUS_CHECK_BATCH
|
||||
};
|
||||
|
||||
void io_set_fds(int read_fd, int write_fd);
|
||||
|
||||
+12
-18
@@ -118,19 +118,20 @@ Client* client_connect_ssh(const char* destination, int port, const char* server
|
||||
if (sv[1] > 1)
|
||||
close(sv[1]);
|
||||
|
||||
char ssh_user[512];
|
||||
int needed;
|
||||
size_t ssh_user_len;
|
||||
if (r.user && r.user[0] != '\0')
|
||||
needed = snprintf(ssh_user, sizeof(ssh_user), "%s@%s", r.user, r.host);
|
||||
ssh_user_len = strlen(r.user) + 1 + strlen(r.host) + 1;
|
||||
else
|
||||
needed = snprintf(ssh_user, sizeof(ssh_user), "%s", r.host);
|
||||
if ((size_t)needed >= sizeof(ssh_user))
|
||||
fprintf(stderr, "Warning: ssh_user string truncated\n");
|
||||
|
||||
size_t ssh_argv_max = 32;
|
||||
char** ssh_argv = calloc(ssh_argv_max, sizeof(char*));
|
||||
if (ssh_argv == NULL)
|
||||
ssh_user_len = strlen(r.host) + 1;
|
||||
char* ssh_user = malloc(ssh_user_len);
|
||||
if (!ssh_user)
|
||||
_exit(1);
|
||||
if (r.user && r.user[0] != '\0')
|
||||
snprintf(ssh_user, ssh_user_len, "%s@%s", r.user, r.host);
|
||||
else
|
||||
snprintf(ssh_user, ssh_user_len, "%s", r.host);
|
||||
|
||||
char* ssh_argv[16];
|
||||
int ac = 0;
|
||||
char port_str[16];
|
||||
ssh_argv[ac++] = "ssh";
|
||||
@@ -141,22 +142,15 @@ Client* client_connect_ssh(const char* destination, int port, const char* server
|
||||
ssh_argv[ac++] = "-o";
|
||||
ssh_argv[ac++] = "ControlPath=~/.cache/fastsync-%r@%h:%p";
|
||||
if (port > 0 && port != 22) {
|
||||
if ((size_t)ac + 2 >= ssh_argv_max) {
|
||||
_exit(1);
|
||||
}
|
||||
ssh_argv[ac++] = "-p";
|
||||
snprintf(port_str, sizeof(port_str), "%d", port);
|
||||
ssh_argv[ac++] = port_str;
|
||||
}
|
||||
if ((size_t)ac + 3 >= ssh_argv_max) {
|
||||
_exit(1);
|
||||
}
|
||||
ssh_argv[ac++] = ssh_user;
|
||||
ssh_argv[ac++] = (char*)(server_path ? server_path : "fastsync-server");
|
||||
ssh_argv[ac++] = "--stdio";
|
||||
ssh_argv[ac] = NULL;
|
||||
execvp("ssh", ssh_argv);
|
||||
free(ssh_argv);
|
||||
perror("exec of ssh failed");
|
||||
ssize_t wret = write(exec_pipe[1], "x", 1);
|
||||
(void)wret;
|
||||
@@ -188,7 +182,7 @@ Client* client_connect_ssh(const char* destination, int port, const char* server
|
||||
return NULL;
|
||||
}
|
||||
client->file_descriptor = sv[0];
|
||||
client->address.ss_family = AF_UNIX;
|
||||
client->address.sin_family = AF_UNIX;
|
||||
client->address_length = 0;
|
||||
client->ssh_child_pid = pid;
|
||||
client->ssl = NULL;
|
||||
|
||||
+78
-166
@@ -3,36 +3,25 @@
|
||||
#include "protocol.h"
|
||||
#include <arpa/inet.h>
|
||||
#include <errno.h>
|
||||
#include <netdb.h>
|
||||
#include <openssl/ssl.h>
|
||||
#include <signal.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/wait.h>
|
||||
#include <unistd.h>
|
||||
|
||||
bool set_socket_timeouts(int fd) {
|
||||
struct timeval tv;
|
||||
tv.tv_sec = 30;
|
||||
tv.tv_usec = 0;
|
||||
static volatile sig_atomic_t g_active_connections = 0;
|
||||
|
||||
int keepalive = 1;
|
||||
if (setsockopt(fd, SOL_SOCKET, SO_KEEPALIVE, &keepalive, sizeof(keepalive)) < 0) {
|
||||
perror("Could not set SO_KEEPALIVE");
|
||||
return false;
|
||||
static void sigchld_handler(int sig) {
|
||||
(void)sig;
|
||||
int saved_errno = errno;
|
||||
while (waitpid(-1, NULL, WNOHANG) > 0) {
|
||||
if (g_active_connections > 0)
|
||||
g_active_connections--;
|
||||
}
|
||||
if (setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)) < 0) {
|
||||
perror("Could not set SO_RCVTIMEO");
|
||||
return false;
|
||||
}
|
||||
if (setsockopt(fd, SOL_SOCKET, SO_SNDTIMEO, &tv, sizeof(tv)) < 0) {
|
||||
perror("Could not set SO_SNDTIMEO");
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
errno = saved_errno;
|
||||
}
|
||||
|
||||
Server* server_create(int port) {
|
||||
@@ -41,29 +30,14 @@ Server* server_create(int port) {
|
||||
perror("Could not allocate space for Server");
|
||||
return NULL;
|
||||
}
|
||||
memset(&server->address, 0, sizeof(server->address));
|
||||
|
||||
// Try IPv6 first, fall back to IPv4
|
||||
int fd = socket(AF_INET6, SOCK_STREAM, 0);
|
||||
sa_family_t domain = AF_INET6;
|
||||
if (fd < 0) {
|
||||
fd = socket(AF_INET, SOCK_STREAM, 0);
|
||||
domain = AF_INET;
|
||||
}
|
||||
if (fd < 0) {
|
||||
int file_descriptor = socket(AF_INET, SOCK_STREAM, 0);
|
||||
if (file_descriptor < 0) {
|
||||
perror("Could not create Socket!");
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (!set_socket_timeouts(fd)) {
|
||||
close(fd);
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
server->file_descriptor = fd;
|
||||
server->ssl_ctx = NULL;
|
||||
server->file_descriptor = file_descriptor;
|
||||
int opt = 1;
|
||||
if (setsockopt(server->file_descriptor, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt))) {
|
||||
perror("Error setting a socket option!");
|
||||
@@ -72,60 +46,20 @@ Server* server_create(int port) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
// Use the domain from the socket we actually created
|
||||
struct sockaddr_storage* addr = &server->address;
|
||||
struct sockaddr_in* addr4 = (struct sockaddr_in*)addr;
|
||||
struct sockaddr_in6* addr6 = (struct sockaddr_in6*)addr;
|
||||
|
||||
if (domain == AF_INET6) {
|
||||
addr6->sin6_family = AF_INET6;
|
||||
addr6->sin6_addr = in6addr_any;
|
||||
addr6->sin6_port = htons(port);
|
||||
addr->ss_family = AF_INET6;
|
||||
server->address_length = sizeof(struct sockaddr_in6);
|
||||
} else {
|
||||
addr4->sin_family = AF_INET;
|
||||
addr4->sin_addr.s_addr = INADDR_ANY;
|
||||
addr4->sin_port = htons(port);
|
||||
addr->ss_family = AF_INET;
|
||||
server->address_length = sizeof(struct sockaddr_in);
|
||||
}
|
||||
server->address.sin_family = AF_INET;
|
||||
server->address.sin_addr.s_addr = INADDR_ANY;
|
||||
server->address.sin_port = htons(port);
|
||||
server->address_length = sizeof(server->address);
|
||||
server->ssl_ctx = NULL;
|
||||
server->max_connections = 100;
|
||||
server->active_connections = 0;
|
||||
|
||||
if (bind(server->file_descriptor, (struct sockaddr*)&server->address, server->address_length) <
|
||||
0) {
|
||||
// If IPv6 bind failed (maybe no IPv6), try IPv4
|
||||
if (domain == AF_INET6) {
|
||||
close(fd);
|
||||
fd = socket(AF_INET, SOCK_STREAM, 0);
|
||||
if (fd < 0) {
|
||||
perror("Could not create IPv4 Socket!");
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
if (!set_socket_timeouts(fd)) {
|
||||
close(fd);
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
server->file_descriptor = fd;
|
||||
setsockopt(server->file_descriptor, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt));
|
||||
memset(addr, 0, sizeof(*addr));
|
||||
addr4->sin_family = AF_INET;
|
||||
addr4->sin_addr.s_addr = INADDR_ANY;
|
||||
addr4->sin_port = htons(port);
|
||||
server->address_length = sizeof(struct sockaddr_in);
|
||||
if (bind(server->file_descriptor, (struct sockaddr*)addr, server->address_length) < 0) {
|
||||
perror("Could not bind server");
|
||||
close(server->file_descriptor);
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
} else {
|
||||
perror("Could not bind server");
|
||||
close(server->file_descriptor);
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
perror("Could not bind server");
|
||||
close(server->file_descriptor);
|
||||
free(server);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return server;
|
||||
@@ -143,36 +77,27 @@ void server_delete(Server** server) {
|
||||
*server = NULL;
|
||||
}
|
||||
|
||||
/* Flag set by server_request_shutdown() to request graceful shutdown
|
||||
of the accept loop. Accessed only from transport_tcp.c so it won't
|
||||
cause linker errors when this file is compiled into client/test targets. */
|
||||
static volatile sig_atomic_t g_tcp_cleanup_requested = 0;
|
||||
|
||||
void server_request_shutdown(void) {
|
||||
g_tcp_cleanup_requested = 1;
|
||||
}
|
||||
|
||||
static void accept_loop(Server* server, void (*child_fn)(int, void*), void* child_ctx,
|
||||
const char* log_fmt) {
|
||||
if (listen(server->file_descriptor, SOMAXCONN) < 0) {
|
||||
perror("Could not listen on port!");
|
||||
return;
|
||||
}
|
||||
signal(SIGCHLD, SIG_IGN);
|
||||
while (!g_tcp_cleanup_requested) {
|
||||
struct sockaddr_storage client_addr;
|
||||
signal(SIGCHLD, sigchld_handler);
|
||||
while (1) {
|
||||
struct sockaddr_in client_addr;
|
||||
socklen_t client_len = sizeof(client_addr);
|
||||
int fd = accept(server->file_descriptor, (struct sockaddr*)&client_addr, &client_len);
|
||||
if (fd < 0) {
|
||||
if (errno == EINTR) {
|
||||
if (g_tcp_cleanup_requested)
|
||||
break;
|
||||
continue;
|
||||
}
|
||||
perror("Could not accept the connection");
|
||||
continue;
|
||||
}
|
||||
set_socket_timeouts(fd);
|
||||
if ((unsigned int)g_active_connections >= server->max_connections) {
|
||||
log_message(LOG_LEVEL_WARNING, "Max connections (%u) reached, rejecting",
|
||||
server->max_connections);
|
||||
close(fd);
|
||||
continue;
|
||||
}
|
||||
log_message(LOG_LEVEL_INFO, "%s", log_fmt);
|
||||
pid_t pid = fork();
|
||||
if (pid == 0) {
|
||||
@@ -180,6 +105,8 @@ static void accept_loop(Server* server, void (*child_fn)(int, void*), void* chil
|
||||
child_fn(fd, child_ctx);
|
||||
close(fd);
|
||||
_exit(0);
|
||||
} else if (pid > 0) {
|
||||
g_active_connections++;
|
||||
}
|
||||
close(fd);
|
||||
}
|
||||
@@ -194,11 +121,7 @@ static void plain_child_fn(int fd, void* ctx) {
|
||||
}
|
||||
|
||||
bool server_listen(Server* server, void (*handler)(int file_descriptor)) {
|
||||
struct sockaddr_in* addr4 = (struct sockaddr_in*)&server->address;
|
||||
int port = (server->address.ss_family == AF_INET6)
|
||||
? ntohs(((struct sockaddr_in6*)&server->address)->sin6_port)
|
||||
: ntohs(addr4->sin_port);
|
||||
log_message(LOG_LEVEL_INFO, "Start Listening on Port: %d", port);
|
||||
log_message(LOG_LEVEL_INFO, "Start Listening on Port: %d", ntohs(server->address.sin_port));
|
||||
struct plain_ctx ctx = {handler};
|
||||
accept_loop(server, plain_child_fn, &ctx, "Received Connection");
|
||||
return true;
|
||||
@@ -206,23 +129,43 @@ bool server_listen(Server* server, void (*handler)(int file_descriptor)) {
|
||||
|
||||
void server_accept_loop(Server* server, void (*child_fn)(int, void*), void* child_ctx,
|
||||
const char* log_fmt) {
|
||||
struct sockaddr_in* addr4 = (struct sockaddr_in*)&server->address;
|
||||
int port = (server->address.ss_family == AF_INET6)
|
||||
? ntohs(((struct sockaddr_in6*)&server->address)->sin6_port)
|
||||
: ntohs(addr4->sin_port);
|
||||
log_message(LOG_LEVEL_INFO, "Start TLS Listening on Port: %d", port);
|
||||
log_message(LOG_LEVEL_INFO, "Start TLS Listening on Port: %d", ntohs(server->address.sin_port));
|
||||
accept_loop(server, child_fn, child_ctx, log_fmt);
|
||||
}
|
||||
|
||||
static int g_timeout_sec = 30;
|
||||
static int g_contimeout_sec = 10;
|
||||
|
||||
void tcp_set_timeouts(int timeout_sec, int contimeout_sec) {
|
||||
if (timeout_sec > 0)
|
||||
g_timeout_sec = timeout_sec;
|
||||
if (contimeout_sec > 0)
|
||||
g_contimeout_sec = contimeout_sec;
|
||||
}
|
||||
|
||||
static void tcp_apply_socket_timeout(int fd) {
|
||||
struct timeval tv;
|
||||
tv.tv_sec = g_timeout_sec;
|
||||
tv.tv_usec = 0;
|
||||
setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv));
|
||||
setsockopt(fd, SOL_SOCKET, SO_SNDTIMEO, &tv, sizeof(tv));
|
||||
}
|
||||
|
||||
Client* client_create() {
|
||||
Client* client = (Client*)malloc(sizeof(Client));
|
||||
if (client == NULL) {
|
||||
int file_descriptor = socket(AF_INET, SOCK_STREAM, 0);
|
||||
if (file_descriptor < 0) {
|
||||
perror("Could not create Socket!");
|
||||
return NULL;
|
||||
}
|
||||
memset(&client->address, 0, sizeof(client->address));
|
||||
client->address.ss_family = AF_UNSPEC;
|
||||
|
||||
Client* client = (Client*)malloc(sizeof(Client));
|
||||
if (client == NULL) {
|
||||
close(file_descriptor);
|
||||
return NULL;
|
||||
}
|
||||
client->file_descriptor = file_descriptor;
|
||||
client->address.sin_family = AF_INET;
|
||||
client->address_length = sizeof(client->address);
|
||||
client->file_descriptor = -1;
|
||||
client->ssh_child_pid = -1;
|
||||
client->ssl = NULL;
|
||||
client->ssl_ctx = NULL;
|
||||
@@ -230,55 +173,28 @@ Client* client_create() {
|
||||
}
|
||||
|
||||
bool client_connect(Client* client, char* host, int port) {
|
||||
struct addrinfo hints, *res, *rp;
|
||||
memset(&hints, 0, sizeof(hints));
|
||||
hints.ai_family = AF_UNSPEC;
|
||||
hints.ai_socktype = SOCK_STREAM;
|
||||
client->address.sin_port = htons(port);
|
||||
client->address.sin_family = AF_INET;
|
||||
client->address_length = sizeof(client->address);
|
||||
|
||||
char port_str[16];
|
||||
snprintf(port_str, sizeof(port_str), "%d", port);
|
||||
|
||||
int gai_err = getaddrinfo(host, port_str, &hints, &res);
|
||||
if (gai_err != 0) {
|
||||
fprintf(stderr, "getaddrinfo: %s\n", gai_strerror(gai_err));
|
||||
if (inet_pton(AF_INET, host, &client->address.sin_addr) <= 0) {
|
||||
perror("Could not convert host address!");
|
||||
return false;
|
||||
}
|
||||
|
||||
// Try IPv6 first, then IPv4
|
||||
int fd = -1;
|
||||
for (rp = res; rp != NULL; rp = rp->ai_next) {
|
||||
fd = socket(rp->ai_family, rp->ai_socktype, rp->ai_protocol);
|
||||
if (fd < 0)
|
||||
continue;
|
||||
if (!set_socket_timeouts(fd)) {
|
||||
close(fd);
|
||||
fd = -1;
|
||||
continue;
|
||||
}
|
||||
if (connect(fd, rp->ai_addr, rp->ai_addrlen) == 0)
|
||||
break;
|
||||
close(fd);
|
||||
fd = -1;
|
||||
}
|
||||
struct timeval ct;
|
||||
ct.tv_sec = g_contimeout_sec;
|
||||
ct.tv_usec = 0;
|
||||
setsockopt(client->file_descriptor, SOL_SOCKET, SO_RCVTIMEO, &ct, sizeof(ct));
|
||||
setsockopt(client->file_descriptor, SOL_SOCKET, SO_SNDTIMEO, &ct, sizeof(ct));
|
||||
|
||||
if (fd < 0) {
|
||||
if (connect(client->file_descriptor, (struct sockaddr*)&client->address, client->address_length) <
|
||||
0) {
|
||||
perror("Could not connect to Server!");
|
||||
freeaddrinfo(res);
|
||||
return false;
|
||||
}
|
||||
|
||||
// Save the connected address
|
||||
socklen_t addr_len = rp->ai_addrlen;
|
||||
if (addr_len > sizeof(client->address))
|
||||
addr_len = sizeof(client->address);
|
||||
memcpy(&client->address, rp->ai_addr, addr_len);
|
||||
client->address_length = addr_len;
|
||||
freeaddrinfo(res);
|
||||
|
||||
// Close old fd if any and set new one
|
||||
if (client->file_descriptor >= 0)
|
||||
close(client->file_descriptor);
|
||||
client->file_descriptor = fd;
|
||||
tcp_apply_socket_timeout(client->file_descriptor);
|
||||
return true;
|
||||
}
|
||||
|
||||
@@ -289,10 +205,7 @@ void client_disconnect(Client* client) {
|
||||
client->ssl = NULL;
|
||||
io_set_ssl(NULL);
|
||||
}
|
||||
if (client->file_descriptor >= 0) {
|
||||
close(client->file_descriptor);
|
||||
client->file_descriptor = -1;
|
||||
}
|
||||
close(client->file_descriptor);
|
||||
if (client->ssh_child_pid > 0) {
|
||||
int status;
|
||||
waitpid(client->ssh_child_pid, &status, 0);
|
||||
@@ -303,7 +216,6 @@ void client_disconnect(Client* client) {
|
||||
void client_delete(Client* client) {
|
||||
if (client == NULL)
|
||||
return;
|
||||
client_disconnect(client);
|
||||
if (client->ssl_ctx) {
|
||||
SSL_CTX_free(client->ssl_ctx);
|
||||
client->ssl_ctx = NULL;
|
||||
|
||||
@@ -1,21 +1,21 @@
|
||||
#ifndef TRANSPORT_TCP_H
|
||||
#define TRANSPORT_TCP_H
|
||||
|
||||
#include <netdb.h>
|
||||
#include <netinet/in.h>
|
||||
#include <stdbool.h>
|
||||
#include <sys/socket.h>
|
||||
#include <sys/types.h>
|
||||
|
||||
typedef struct Server {
|
||||
struct sockaddr_storage address;
|
||||
struct sockaddr_in address;
|
||||
unsigned int address_length;
|
||||
int file_descriptor;
|
||||
void* ssl_ctx;
|
||||
unsigned int max_connections;
|
||||
volatile unsigned int active_connections;
|
||||
} Server;
|
||||
|
||||
typedef struct Client {
|
||||
struct sockaddr_storage address;
|
||||
struct sockaddr_in address;
|
||||
unsigned int address_length;
|
||||
int file_descriptor;
|
||||
pid_t ssh_child_pid;
|
||||
@@ -28,11 +28,10 @@ bool server_listen(Server* server, void (*handler)(int file_descriptor));
|
||||
void server_accept_loop(Server* server, void (*child_fn)(int, void*), void* child_ctx,
|
||||
const char* log_fmt);
|
||||
void server_delete(Server** server);
|
||||
void server_request_shutdown(void);
|
||||
Client* client_create();
|
||||
bool client_connect(Client* client, char* host, int port);
|
||||
void client_disconnect(Client* client);
|
||||
void client_delete(Client* client);
|
||||
bool set_socket_timeouts(int fd);
|
||||
void tcp_set_timeouts(int timeout_sec, int contimeout_sec);
|
||||
|
||||
#endif
|
||||
|
||||
@@ -5,8 +5,6 @@
|
||||
#include <arpa/inet.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/ssl.h>
|
||||
#include <openssl/x509.h>
|
||||
#include <openssl/x509v3.h>
|
||||
#include <signal.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
@@ -75,10 +73,6 @@ static SSL_CTX* create_ssl_ctx(bool is_server, const char* cert, const char* key
|
||||
SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
|
||||
SSL_CTX_set_verify_depth(ctx, 4);
|
||||
} else {
|
||||
if (!is_server) {
|
||||
log_message(LOG_LEVEL_WARNING,
|
||||
"No CA path provided — TLS server certificate will not be verified");
|
||||
}
|
||||
SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL);
|
||||
}
|
||||
|
||||
@@ -92,7 +86,6 @@ static SSL* wrap_fd_with_ssl(int fd, SSL_CTX* ctx, bool is_server) {
|
||||
return NULL;
|
||||
}
|
||||
SSL_set_fd(ssl, fd);
|
||||
|
||||
int ret;
|
||||
if (is_server)
|
||||
ret = SSL_accept(ssl);
|
||||
@@ -105,17 +98,6 @@ static SSL* wrap_fd_with_ssl(int fd, SSL_CTX* ctx, bool is_server) {
|
||||
SSL_free(ssl);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
// In client mode, check verification result if peer verification was requested
|
||||
if (!is_server) {
|
||||
long verify_result = SSL_get_verify_result(ssl);
|
||||
if (verify_result != X509_V_OK) {
|
||||
log_message(LOG_LEVEL_ERROR, "TLS certificate verification failed: %ld", verify_result);
|
||||
SSL_free(ssl);
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
return ssl;
|
||||
}
|
||||
|
||||
@@ -153,9 +135,16 @@ bool server_listen_tls(Server* server, void (*handler)(int file_descriptor)) {
|
||||
|
||||
bool client_connect_tls(Client* client, char* host, int port, const char* cert_path,
|
||||
const char* key_path, const char* ca_path) {
|
||||
// Use the common TCP connection logic (with IPv6 support)
|
||||
if (!client_connect(client, host, port))
|
||||
client->address.sin_port = htons(port);
|
||||
if (inet_pton(AF_INET, host, &client->address.sin_addr) <= 0) {
|
||||
perror("Could not convert host address!");
|
||||
return false;
|
||||
}
|
||||
if (connect(client->file_descriptor, (struct sockaddr*)&client->address, client->address_length) <
|
||||
0) {
|
||||
perror("Could not connect to Server!");
|
||||
return false;
|
||||
}
|
||||
|
||||
SSL_CTX* ctx = create_ssl_ctx(false, cert_path, key_path, ca_path);
|
||||
if (!ctx)
|
||||
@@ -168,14 +157,6 @@ bool client_connect_tls(Client* client, char* host, int port, const char* cert_p
|
||||
client->ssl_ctx = NULL;
|
||||
return false;
|
||||
}
|
||||
|
||||
// Set SNI and enable hostname verification
|
||||
SSL_set_tlsext_host_name(ssl, host);
|
||||
X509_VERIFY_PARAM* param = SSL_get0_param(ssl);
|
||||
if (param) {
|
||||
X509_VERIFY_PARAM_set1_host(param, host, 0);
|
||||
}
|
||||
|
||||
client->ssl = ssl;
|
||||
io_set_ssl(ssl);
|
||||
return true;
|
||||
|
||||
+36
-31
@@ -10,23 +10,19 @@
|
||||
#include <unistd.h>
|
||||
|
||||
bool mkdir_r(const char* path) {
|
||||
size_t path_len = strlen(path);
|
||||
char* path_duplicate = malloc(path_len + 1);
|
||||
char* path_duplicate = malloc(strlen(path) + 1);
|
||||
if (!path_duplicate)
|
||||
return false;
|
||||
memcpy(path_duplicate, path, path_len + 1);
|
||||
/* Buffer for building subpaths: path_len + 1 for leading '/' + 1 for null */
|
||||
size_t buf_size = path_len + 2;
|
||||
char* path_current = (char*)malloc(buf_size);
|
||||
strcpy(path_duplicate, path);
|
||||
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
|
||||
if (!path_current) {
|
||||
free(path_duplicate);
|
||||
return false;
|
||||
}
|
||||
size_t pos = 0;
|
||||
char* path_current_position = path_current;
|
||||
if (path[0] == '/') {
|
||||
path_current[0] = '/';
|
||||
path_current[1] = '\0';
|
||||
pos = 1;
|
||||
strcpy(path_current, "/");
|
||||
path_current_position += 1;
|
||||
} else {
|
||||
path_current[0] = '\0';
|
||||
}
|
||||
@@ -35,16 +31,10 @@ bool mkdir_r(const char* path) {
|
||||
const char* part = strtok_r(path_duplicate, delimiter, &saveptr);
|
||||
bool ok = true;
|
||||
while (part != NULL) {
|
||||
size_t part_len = strlen(part);
|
||||
if (pos + part_len + 1 >= buf_size) {
|
||||
ok = false;
|
||||
break;
|
||||
}
|
||||
memcpy(path_current + pos, part, part_len);
|
||||
pos += part_len;
|
||||
path_current[pos] = '/';
|
||||
pos++;
|
||||
path_current[pos] = '\0';
|
||||
strcpy(path_current_position, part);
|
||||
path_current_position += strlen(part) * sizeof(char);
|
||||
strcpy(path_current_position, "/");
|
||||
path_current_position += sizeof(char);
|
||||
struct stat st;
|
||||
if (stat(path_current, &st) != 0) {
|
||||
if (mkdir(path_current, 0755) != 0) {
|
||||
@@ -59,24 +49,22 @@ bool mkdir_r(const char* path) {
|
||||
free(path_current);
|
||||
return ok;
|
||||
}
|
||||
|
||||
char* str_dup(const char* string) {
|
||||
if (string == NULL)
|
||||
return NULL;
|
||||
char* new_string = (char*)malloc(strlen(string) + 1);
|
||||
memcpy(new_string, string, strlen(string) + 1);
|
||||
strcpy(new_string, string);
|
||||
return new_string;
|
||||
}
|
||||
|
||||
bool glob_match(const char* pattern, const char* str) {
|
||||
while (*pattern) {
|
||||
if (*pattern == '*') {
|
||||
/* Check for double-star (globstar) pattern */
|
||||
if (*(pattern + 1) == '*') {
|
||||
pattern += 2;
|
||||
/* Trailing double-star matches everything */
|
||||
if (*pattern == '\0')
|
||||
return true;
|
||||
/* double-star slash: match at any depth */
|
||||
if (*pattern == '/')
|
||||
pattern++;
|
||||
while (*str) {
|
||||
@@ -86,7 +74,6 @@ bool glob_match(const char* pattern, const char* str) {
|
||||
}
|
||||
return glob_match(pattern, str);
|
||||
}
|
||||
/* Single * — does not cross / boundaries */
|
||||
pattern++;
|
||||
while (*str && *str != '/') {
|
||||
if (glob_match(pattern, str))
|
||||
@@ -101,9 +88,7 @@ bool glob_match(const char* pattern, const char* str) {
|
||||
str++;
|
||||
} else {
|
||||
if (*pattern != *str) {
|
||||
/* If pattern has a '/' followed by '**', allow zero path components */
|
||||
if (*pattern == '/' && *(pattern + 1) == '*' && *(pattern + 2) == '*') {
|
||||
/* Skip over slash-double-star and try to match rest against current str */
|
||||
const char* rest = pattern + 3;
|
||||
if (*rest == '/')
|
||||
rest++;
|
||||
@@ -184,17 +169,37 @@ void delete_extras(const char* dest_root, ArrayList* manifest) {
|
||||
delete_extras_walk(dest_root, "", manifest);
|
||||
}
|
||||
|
||||
bool has_path_traversal(const char* path) {
|
||||
if (!path)
|
||||
return false;
|
||||
char* dup = str_dup(path);
|
||||
if (!dup)
|
||||
return false;
|
||||
char* saveptr;
|
||||
const char* part = strtok_r(dup, "/", &saveptr);
|
||||
while (part) {
|
||||
if (strcmp(part, "..") == 0) {
|
||||
free(dup);
|
||||
return true;
|
||||
}
|
||||
part = strtok_r(NULL, "/", &saveptr);
|
||||
}
|
||||
free(dup);
|
||||
return false;
|
||||
}
|
||||
|
||||
char* path_cat(const char* path1, const char* path2) {
|
||||
if (path1 == NULL || *path1 == '\0')
|
||||
return str_dup(path2);
|
||||
if (path2 == NULL || *path2 == '\0')
|
||||
return str_dup(path1);
|
||||
int path1_len = strlen(path1);
|
||||
int path2_len = strlen(path2);
|
||||
size_t path1_len = strlen(path1);
|
||||
size_t path2_len = strlen(path2);
|
||||
size_t offset = 0;
|
||||
if (path1[path1_len - 1] == '/')
|
||||
path1_len -= 1;
|
||||
if (path2[0] == '/') {
|
||||
path2++;
|
||||
offset = 1;
|
||||
path2_len -= 1;
|
||||
}
|
||||
char* new_path = malloc(path1_len + path2_len + 2);
|
||||
@@ -202,7 +207,7 @@ char* path_cat(const char* path1, const char* path2) {
|
||||
return NULL;
|
||||
memcpy(new_path, path1, path1_len);
|
||||
new_path[path1_len] = '/';
|
||||
memcpy(new_path + path1_len + 1, path2, path2_len);
|
||||
memcpy(new_path + path1_len + 1, path2 + offset, path2_len);
|
||||
new_path[path1_len + path2_len + 1] = '\0';
|
||||
return new_path;
|
||||
}
|
||||
|
||||
@@ -9,5 +9,6 @@ char* str_dup(const char* string);
|
||||
char* path_cat(const char* path1, const char* path2);
|
||||
bool glob_match(const char* pattern, const char* str);
|
||||
void delete_extras(const char* dest_root, ArrayList* manifest);
|
||||
bool has_path_traversal(const char* path);
|
||||
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user