Compare commits

...

11 Commits

Author SHA1 Message Date
TapTap bf91c5b588 merge: resolve conflict with dev, apply helpers to new options
CI / lint (pull_request) Successful in 23s
CI / sanitizers (address) (pull_request) Successful in 35s
CI / sanitizers (undefined) (pull_request) Successful in 36s
CI / fuzz-build (pull_request) Successful in 14s
CI / coverage (pull_request) Successful in 31s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
2026-08-01 18:14:55 +02:00
TapTap 5eaea9d92e refactor: extract CLI parser helpers, fix validation bugs
CI / lint (pull_request) Successful in 16s
CI / sanitizers (undefined) (pull_request) Successful in 37s
CI / sanitizers (address) (pull_request) Successful in 39s
CI / fuzz-build (pull_request) Successful in 14s
CI / coverage (pull_request) Successful in 32s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
- Add set_string_option(), set_positive_int_option(), set_nonneg_int_option()
  helpers to eliminate duplicated alloc/free/assign patterns
- Replace 14 string-option branches with set_string_option() calls
- Replace 7 integer-option branches with set_positive/nonneg_int_option()
- Fix --info/--debug: replace atoi() with validated parse
- Fix --max-size/--min-size: add strtoull() error checking
- Fix --chunk-size: validate input with error message on failure
2026-08-01 18:12:41 +02:00
TapTap 9d67fcbf92 Merge pull request 'Batch fix: security, bugs, quality, and features (v2)' (#198) from integration/all-fixes-v2 into dev 2026-07-30 19:38:26 +02:00
TapTap 261683aaff fix: null check in str_dup, const in file.c
CI / lint (pull_request) Successful in 2m16s
CI / sanitizers (address) (pull_request) Successful in 36s
CI / sanitizers (undefined) (pull_request) Successful in 37s
CI / fuzz-build (pull_request) Successful in 14s
CI / coverage (pull_request) Successful in 30s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
2026-07-30 19:34:17 +02:00
TapTap 15a861747a style: apply clang-format
CI / lint (pull_request) Failing after 2m18s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
2026-07-30 19:16:36 +02:00
TapTap 5f1b27c8ff fix: security #192 #187, bugs #194 #193, quality #195, features #174-#186
CI / lint (pull_request) Failing after 2s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
2026-07-30 19:05:19 +02:00
TapTap 732cd67735 Merge remote-tracking branch 'origin/fix/features-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 50fb7185a8 Merge remote-tracking branch 'origin/fix/quality-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 3062927e07 Merge remote-tracking branch 'origin/fix/bugs-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 88746c3396 fix: replace strcpy with bounded memory operations (#195)
Replace all uses of strcpy() with memcpy() + explicit NUL termination
or direct assignment for safety and consistency. No behavioral changes.

src/shared/file.c:
  - file_create(): strcpy -> memcpy + explicit NUL (buffer size known)

src/shared/utils.c:
  - mkdir_r(): strcpy -> memcpy for path_duplicate
  - mkdir_r(): strcpy(path_current, "/") -> direct assignment
  - mkdir_r(): strcpy loop -> memcpy + direct assignment
  - str_dup(): strcpy -> memcpy (buffer size known)

PR #196 (dry-run manifest refactoring) was already applied in a previous
commit - send_dry_run_manifest() and send_delete_manifest() helpers
already exist and are used by both send_files() and
send_files_multithreaded().
2026-07-30 18:49:52 +02:00
TapTap 80768d64d4 fix: security issues #192 #191 #190 #189 #188 #187 2026-07-30 18:49:25 +02:00
11 changed files with 213 additions and 190 deletions
+89 -148
View File
@@ -49,6 +49,37 @@ static bool parse_nonneg_int(const char* s, int* out_val) {
return true;
}
/* Duplicate a string argument into *dest, freeing the old value. Returns 0 on success, -1 on
* failure. */
static int set_string_option(char** dest, const char* value, const char* option_name) {
char* dup = str_dup(value);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for %s\n", option_name);
return -1;
}
free(*dest);
*dest = dup;
return 0;
}
/* Parse a string as a positive integer into *dest. Returns 0 on success, -1 on error. */
static int set_positive_int_option(int* dest, const char* value, const char* option_name) {
if (!parse_positive_int(value, dest)) {
fprintf(stderr, "Error: %s must be a positive integer\n", option_name);
return -1;
}
return 0;
}
/* Parse a string as a non-negative integer into *dest. Returns 0 on success, -1 on error. */
static int set_nonneg_int_option(int* dest, const char* value, const char* option_name) {
if (!parse_nonneg_int(value, dest)) {
fprintf(stderr, "Error: %s must be a non-negative integer\n", option_name);
return -1;
}
return 0;
}
static void print_usage(void);
static int read_patterns_from_file(const char* filepath, char*** patterns, int* count);
@@ -100,9 +131,23 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
}
config->include_patterns[config->include_count++] = dup;
} else if (strcmp(argv[i], "--max-size") == 0 && i + 1 < argc) {
config->max_size = strtoull(argv[++i], NULL, 10);
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --max-size must be a non-negative integer\n");
return -1;
}
config->max_size = val;
} else if (strcmp(argv[i], "--min-size") == 0 && i + 1 < argc) {
config->min_size = strtoull(argv[++i], NULL, 10);
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --min-size must be a non-negative integer\n");
return -1;
}
config->min_size = val;
} else if (strcmp(argv[i], "--incremental") == 0) {
config->use_incremental = true;
} else if (strcmp(argv[i], "--delta") == 0) {
@@ -132,21 +177,11 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
}
}
} else if (strcmp(argv[i], "--source-dir") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --source-dir\n");
if (set_string_option(&config->send_directory, argv[++i], "--source-dir") != 0)
return -1;
}
free(config->send_directory);
config->send_directory = dup;
} else if (strcmp(argv[i], "--dest-dir") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --dest-dir\n");
if (set_string_option(&config->receive_root_directory, argv[++i], "--dest-dir") != 0)
return -1;
}
free(config->receive_root_directory);
config->receive_root_directory = dup;
} else if (strcmp(argv[i], "--save-to-disk") == 0) {
config->save_to_disk = true;
} else if (strcmp(argv[i], "-M") == 0 || strcmp(argv[i], "--preserve") == 0) {
@@ -162,13 +197,8 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->use_chunk_serialization = true;
log_message(LOG_LEVEL_INFO, "Enabled Chunk Serialization");
} else if (strcmp(argv[i], "--server-host") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --server-host\n");
if (set_string_option(&config->server_host, argv[++i], "--server-host") != 0)
return -1;
}
free(config->server_host);
config->server_host = dup;
} else if (strcmp(argv[i], "--server-port") == 0 && i + 1 < argc) {
if (!parse_positive_int(argv[++i], &config->server_port)) {
fprintf(stderr, "Error: invalid --server-port value: %s\n", argv[i]);
@@ -191,69 +221,44 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--progress") == 0) {
config->show_progress = true;
} else if (strcmp(argv[i], "--chunk-size") == 0 && i + 1 < argc) {
unsigned long long val = strtoull(argv[++i], NULL, 10);
if (val > 0)
config->chunk_size = val;
char* end;
errno = 0;
unsigned long long val = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0' || val == 0) {
fprintf(stderr, "Error: --chunk-size must be a positive integer\n");
return -1;
}
config->chunk_size = val;
} else if (strcmp(argv[i], "--tls") == 0) {
config->use_tls = true;
} else if (strcmp(argv[i], "--cert") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --cert\n");
if (set_string_option(&config->tls_cert, argv[++i], "--cert") != 0)
return -1;
}
free(config->tls_cert);
config->tls_cert = dup;
} else if (strcmp(argv[i], "--key") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --key\n");
if (set_string_option(&config->tls_key, argv[++i], "--key") != 0)
return -1;
}
free(config->tls_key);
config->tls_key = dup;
} else if (strcmp(argv[i], "--ca") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --ca\n");
if (set_string_option(&config->tls_ca, argv[++i], "--ca") != 0)
return -1;
}
free(config->tls_ca);
config->tls_ca = dup;
} else if (strcmp(argv[i], "--timeout") == 0 && i + 1 < argc) {
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --timeout must be a positive integer\n");
if (set_positive_int_option(&config->timeout, argv[++i], "--timeout") != 0)
return -1;
}
config->timeout = val;
} else if (strcmp(argv[i], "--contimeout") == 0 && i + 1 < argc) {
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --contimeout must be a positive integer\n");
if (set_positive_int_option(&config->contimeout, argv[++i], "--contimeout") != 0)
return -1;
}
config->contimeout = val;
} else if (strcmp(argv[i], "-q") == 0 || strcmp(argv[i], "--quiet") == 0 ||
strcmp(argv[i], "--silent") == 0) {
config->quiet = true;
} else if (strcmp(argv[i], "--backup") == 0) {
config->backup = true;
} else if (strcmp(argv[i], "--backup-dir") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --backup-dir\n");
if (set_string_option(&config->backup_dir, argv[++i], "--backup-dir") != 0)
return -1;
}
free(config->backup_dir);
config->backup_dir = dup;
} else if (strcmp(argv[i], "--stats") == 0) {
config->stats = true;
} else if (strcmp(argv[i], "--max-depth") == 0 && i + 1 < argc) {
if (!parse_nonneg_int(argv[++i], &config->max_depth)) {
fprintf(stderr, "Error: --max-depth must be a non-negative integer\n");
if (set_nonneg_int_option(&config->max_depth, argv[++i], "--max-depth") != 0)
return -1;
}
} else if (strcmp(argv[i], "--log-file") == 0 && i + 1 < argc) {
FILE* lf = fopen(argv[++i], "a");
if (!lf) {
@@ -263,12 +268,8 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->log_file = lf;
log_set_file(lf);
} else if (strcmp(argv[i], "--queue-size") == 0 && i + 1 < argc) {
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --queue-size must be a positive integer\n");
if (set_positive_int_option(&config->queue_size, argv[++i], "--queue-size") != 0)
return -1;
}
config->queue_size = val;
} else if (strcmp(argv[i], "--exclude-from") == 0 && i + 1 < argc) {
if (read_patterns_from_file(argv[++i], &config->exclude_patterns, &config->exclude_count) !=
0)
@@ -280,13 +281,9 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--partial") == 0) {
config->partial = true;
} else if (strcmp(argv[i], "--fastsync-server-path") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --fastsync-server-path\n");
if (set_string_option(&config->fastsync_server_path, argv[++i], "--fastsync-server-path") !=
0)
return -1;
}
free(config->fastsync_server_path);
config->fastsync_server_path = dup;
} else if (strcmp(argv[i], "-v") == 0 || strcmp(argv[i], "--verbose") == 0) {
set_log_level(LOG_LEVEL_DEBUG);
} else if (strcmp(argv[i], "-l") == 0 || strcmp(argv[i], "--links") == 0) {
@@ -310,15 +307,14 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "-i") == 0 || strcmp(argv[i], "--itemize-changes") == 0) {
config->itemize_changes = true;
} else if (strcmp(argv[i], "--out-format") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->out_format, argv[++i], "--out-format") != 0)
return -1;
free(config->out_format);
config->out_format = dup;
} else if (strcmp(argv[i], "--info") == 0 && i + 1 < argc) {
config->info_level = atoi(argv[++i]);
if (set_nonneg_int_option(&config->info_level, argv[++i], "--info") != 0)
return -1;
} else if (strcmp(argv[i], "--debug") == 0 && i + 1 < argc) {
config->debug_level = atoi(argv[++i]);
if (set_nonneg_int_option(&config->debug_level, argv[++i], "--debug") != 0)
return -1;
} else if (strcmp(argv[i], "--list-only") == 0) {
config->list_only = true;
} else if (strcmp(argv[i], "-h") == 0 || strcmp(argv[i], "--human-readable") == 0) {
@@ -336,12 +332,8 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--delete-after") == 0) {
config->delete_after = true;
} else if (strcmp(argv[i], "--max-delete") == 0 && i + 1 < argc) {
int val;
if (!parse_nonneg_int(argv[++i], &val)) {
fprintf(stderr, "Error: --max-delete must be a non-negative integer\n");
if (set_nonneg_int_option(&config->max_delete, argv[++i], "--max-delete") != 0)
return -1;
}
config->max_delete = val;
} else if (strcmp(argv[i], "--filter") == 0 && i + 1 < argc) {
if (!config->filters)
config->filters = array_list_create(free);
@@ -350,11 +342,8 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
return -1;
array_list_add(config->filters, dup);
} else if (strcmp(argv[i], "--files-from") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->files_from, argv[++i], "--files-from") != 0)
return -1;
free(config->files_from);
config->files_from = dup;
} else if (strcmp(argv[i], "--cvs-exclude") == 0) {
config->cvs_exclude = true;
} else if (strcmp(argv[i], "--prune-empty-dirs") == 0) {
@@ -363,82 +352,44 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
config->relative = true;
} else if (strcmp(argv[i], "-e") == 0 || strcmp(argv[i], "--rsh") == 0) {
if (i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->rsh_command, argv[++i], "-e/--rsh") != 0)
return -1;
free(config->rsh_command);
config->rsh_command = dup;
} else {
fprintf(stderr, "Error: -e/--rsh requires a command argument\n");
return -1;
}
} else if (strcmp(argv[i], "--rsync-path") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->rsync_path, argv[++i], "--rsync-path") != 0)
return -1;
free(config->rsync_path);
config->rsync_path = dup;
} else if (strcmp(argv[i], "--temp-dir") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->temp_dir, argv[++i], "--temp-dir") != 0)
return -1;
free(config->temp_dir);
config->temp_dir = dup;
} else if (strcmp(argv[i], "--compare-dest") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->compare_dest, argv[++i], "--compare-dest") != 0)
return -1;
free(config->compare_dest);
config->compare_dest = dup;
} else if (strcmp(argv[i], "--copy-dest") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->copy_dest, argv[++i], "--copy-dest") != 0)
return -1;
free(config->copy_dest);
config->copy_dest = dup;
} else if (strcmp(argv[i], "--link-dest") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->link_dest, argv[++i], "--link-dest") != 0)
return -1;
free(config->link_dest);
config->link_dest = dup;
} else if (strcmp(argv[i], "--partial-dir") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --partial-dir\n");
if (set_string_option(&config->partial_dir, argv[++i], "--partial-dir") != 0)
return -1;
}
free(config->partial_dir);
config->partial_dir = dup;
} else if (strcmp(argv[i], "--suffix") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup) {
fprintf(stderr, "Error: memory allocation failed for --suffix\n");
if (set_string_option(&config->suffix, argv[++i], "--suffix") != 0)
return -1;
}
free(config->suffix);
config->suffix = dup;
} else if (strcmp(argv[i], "--delete-before") == 0) {
config->delete_before = true;
} else if (strcmp(argv[i], "-T") == 0 && i + 1 < argc) {
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: -T must be a positive integer\n");
if (set_positive_int_option(&config->timeout, argv[++i], "-T") != 0)
return -1;
}
config->timeout = val;
} else if (strcmp(argv[i], "--address") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->address, argv[++i], "--address") != 0)
return -1;
free(config->address);
config->address = dup;
} else if (strcmp(argv[i], "--bind-address") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->bind_address, argv[++i], "--bind-address") != 0)
return -1;
free(config->bind_address);
config->bind_address = dup;
} else if (strcmp(argv[i], "--ipv6") == 0) {
config->ipv6 = true;
} else if (strcmp(argv[i], "--ipv4") == 0) {
@@ -446,28 +397,18 @@ static int parse_args(Config* config, int argc, char* argv[], int* positional_ar
} else if (strcmp(argv[i], "--daemon") == 0) {
config->daemon = true;
} else if (strcmp(argv[i], "--config") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->daemon_config, argv[++i], "--config") != 0)
return -1;
free(config->daemon_config);
config->daemon_config = dup;
} else if (strcmp(argv[i], "--server") == 0) {
config->server_mode = true;
} else if (strcmp(argv[i], "--checksum") == 0) {
config->checksum = true;
} else if (strcmp(argv[i], "--compress-choice") == 0 && i + 1 < argc) {
char* dup = str_dup(argv[++i]);
if (!dup)
if (set_string_option(&config->compress_choice, argv[++i], "--compress-choice") != 0)
return -1;
free(config->compress_choice);
config->compress_choice = dup;
} else if (strcmp(argv[i], "--compress-level") == 0 && i + 1 < argc) {
int val;
if (!parse_positive_int(argv[++i], &val)) {
fprintf(stderr, "Error: --compress-level must be a positive integer\n");
if (set_positive_int_option(&config->compression_level, argv[++i], "--compress-level") != 0)
return -1;
}
config->compression_level = val;
} else if (argv[i][0] == '-') {
fprintf(stderr, "Unknown option: %s\n", argv[i]);
print_usage();
+8 -7
View File
@@ -166,7 +166,7 @@ static int send_single_file(Client* client, File* file, Config* config, bool use
if (!use_incremental) {
if (use_sendfile) {
return send_file_direct_sendfile(file, client->file_descriptor, config->use_metadata) ? 0
: -1;
: -1;
}
return send_file_direct(file, client->file_descriptor, config->use_metadata, compression_level)
? 0
@@ -284,8 +284,8 @@ static int send_chunks_multithreaded(void* pipeline_context) {
} else if (context->config->use_tls) {
client = client_create();
if (!client || !client_connect_tls(client, context->config->server_host,
context->config->server_port, context->config->tls_cert,
context->config->tls_key, context->config->tls_ca)) {
context->config->server_port, context->config->tls_cert,
context->config->tls_key, context->config->tls_ca)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server via TLS\n");
@@ -374,7 +374,8 @@ static int scan_directory_multithreaded(void* pipeline_context) {
context->config->exclude_patterns, context->config->exclude_count,
context->config->include_patterns, context->config->include_count, context->config->max_size,
context->config->min_size, context->config->max_depth, 4, context->config->follow_symlinks,
context->config->copy_links, context->config->safe_links, context->config->copy_unsafe_links, context->config->checksum);
context->config->copy_links, context->config->safe_links, context->config->copy_unsafe_links,
context->config->checksum);
Chunk* current_chunk;
while ((current_chunk = parallel_scanner_next(scanner)) != NULL) {
@@ -485,7 +486,7 @@ int send_files(Config* config) {
} else if (config->use_tls) {
client = client_create();
if (!client || !client_connect_tls(client, config->server_host, config->server_port,
config->tls_cert, config->tls_key, config->tls_ca)) {
config->tls_cert, config->tls_key, config->tls_ca)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server via TLS\n");
@@ -575,8 +576,8 @@ int send_files(Config* config) {
}
if (config->stats) {
double rate = elapsed_total > 0 ? total_bytes / (1048576.0 * elapsed_total) : 0;
fprintf(stderr, "Stats: %d files, %.1f MB, %.1f MB/s\n", total_files,
total_bytes / 1048576.0, rate);
fprintf(stderr, "Stats: %d files, %.1f MB, %.1f MB/s\n", total_files, total_bytes / 1048576.0,
rate);
}
directory_scanner_destroy(scanner);
client_disconnect(client);
+59 -8
View File
@@ -309,12 +309,12 @@ static int parallel_worker_thread(void* arg) {
}
ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata,
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum) {
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum) {
ParallelScanner* ps = calloc(1, sizeof(ParallelScanner));
if (!ps)
return NULL;
@@ -347,11 +347,62 @@ ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata
char* cur_path = path_cat(root_directory, entry->d_name);
if (!cur_path)
continue;
struct stat st;
if (stat(cur_path, &st) != 0) {
struct stat lstats;
if (lstat(cur_path, &lstats) != 0) {
free(cur_path);
continue;
}
bool is_symlink = S_ISLNK(lstats.st_mode);
// Skip symlinks unless the user explicitly enabled following/copying them.
if (is_symlink && !follow_symlinks && !copy_links && !safe_links && !copy_unsafe_links) {
free(cur_path);
continue;
}
// --safe-links: reject symlinks pointing outside the source tree.
if (is_symlink && safe_links) {
char link_target[4096];
ssize_t len = readlink(cur_path, link_target, sizeof(link_target) - 1);
if (len < 0) {
free(cur_path);
continue;
}
link_target[len] = 0;
if (link_target[0] == '/') {
free(cur_path);
continue;
}
}
// --copy-unsafe-links (without --copy-links): only copy absolute symlinks.
if (is_symlink && copy_unsafe_links && !copy_links) {
char link_target[4096];
ssize_t len = readlink(cur_path, link_target, sizeof(link_target) - 1);
if (len < 0) {
free(cur_path);
continue;
}
link_target[len] = 0;
bool unsafe = (link_target[0] == '/');
if (!unsafe) {
free(cur_path);
continue;
}
}
// Determine whether to use lstat or stat results for the entry.
struct stat st;
bool use_lstat_res = is_symlink && follow_symlinks && !copy_links;
if (use_lstat_res) {
st = lstats;
} else {
if (stat(cur_path, &st) != 0) {
free(cur_path);
continue;
}
}
if (S_ISDIR(st.st_mode)) {
array_list_add(subdirs, cur_path);
} else {
+6 -6
View File
@@ -51,12 +51,12 @@ Chunk* directory_scanner_next(DirectoryScanner* scanner);
void directory_scanner_destroy(DirectoryScanner* scanner);
ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata,
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum);
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum);
Chunk* parallel_scanner_next(ParallelScanner* scanner);
void parallel_scanner_destroy(ParallelScanner* scanner);
+20
View File
@@ -12,6 +12,9 @@
#include "metadata.h"
#include "protocol.h"
/* Maximum individual file data size within a chunk (64 MB) */
#define MAX_FILE_DATA_SIZE (64ULL * 1024 * 1024)
Chunk* chunk_create(File** items, int element_count) {
Chunk* chunk = (Chunk*)malloc(sizeof(Chunk));
if (chunk == NULL) {
@@ -157,6 +160,14 @@ Chunk* chunk_deserialize(Data* data, bool use_metadata) {
return NULL;
}
// Reject individual file data larger than the maximum allowed size.
if (file_data_size > MAX_FILE_DATA_SIZE) {
log_message(LOG_LEVEL_ERROR, "File data size %zu exceeds maximum %llu", file_data_size,
(unsigned long long)MAX_FILE_DATA_SIZE);
array_list_delete(files);
return NULL;
}
void* file_data = malloc(file_data_size);
if (file_data == NULL) {
perror("Could not allocate memory for file data");
@@ -210,6 +221,15 @@ Chunk* receive_chunk_data(int fd, const Config* config) {
return NULL;
}
}
// Reject chunks larger than the maximum allowed size to prevent OOM.
if (data_to_process->size > MAX_CHUNK_SIZE) {
log_message(LOG_LEVEL_ERROR, "Chunk size %zu exceeds maximum %llu", data_to_process->size,
(unsigned long long)MAX_CHUNK_SIZE);
data_destroy(data_to_process);
return NULL;
}
Chunk* chunk = chunk_deserialize(data_to_process, config->use_metadata);
data_destroy(data_to_process);
if (chunk == NULL)
+8 -7
View File
@@ -35,7 +35,8 @@ File* file_create(const char* path) {
return NULL;
}
strcpy(file->path, path);
memcpy(file->path, path, path_len);
file->path[path_len] = '\0';
file->data = data_create_reserve(0);
if (file->data == NULL) {
free(file->path);
@@ -142,7 +143,8 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
}
char* resolved_root = NULL;
const char* actual_root = (partial_dir && config && config->partial) ? partial_dir : root_directory;
const char* actual_root =
(partial_dir && config && config->partial) ? partial_dir : root_directory;
resolved_root = realpath(actual_root, NULL);
if (resolved_root == NULL) {
if (mkdir_r(actual_root)) {
@@ -187,7 +189,7 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
if (backup_path) {
char* backup_dir_path = str_dup(backup_path);
if (backup_dir_path) {
char* bdir = dirname(backup_dir_path);
const char* bdir = dirname(backup_dir_path);
mkdir_r(bdir);
free(backup_dir_path);
}
@@ -222,8 +224,7 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
size_t root_len = strlen(resolved_root);
if (strncmp(resolved_dir, resolved_root, root_len) != 0 ||
(resolved_dir[root_len] != '\0' && resolved_dir[root_len] != '/')) {
log_message(LOG_LEVEL_ERROR, "Path escape detected: %s is outside %s", disk_path,
actual_root);
log_message(LOG_LEVEL_ERROR, "Path escape detected: %s is outside %s", disk_path, actual_root);
free(resolved_dir);
free(resolved_root);
free(disk_path);
@@ -517,8 +518,8 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
return file;
}
bool to_disk(const char* path, const void* data, unsigned long long data_size,
bool inplace, bool sparse) {
bool to_disk(const char* path, const void* data, unsigned long long data_size, bool inplace,
bool sparse) {
char* tmp_path = NULL;
char* directory = NULL;
+2 -2
View File
@@ -34,8 +34,8 @@ bool file_send_sendfile(File* file, int file_descriptor, bool use_metadata, int
size_t file_content_to_buffer(File* file);
FileMetadata* file_metadata_create(const struct stat* stats);
void file_metadata_destroy(void* metadata);
bool to_disk(const char* path, const void* data, unsigned long long data_size,
bool inplace, bool sparse);
bool to_disk(const char* path, const void* data, unsigned long long data_size, bool inplace,
bool sparse);
bool file_save_to_disk(const char* root_directory, File* file, const Config* config);
File* receive_incremental_check(int fd, const Config* config, bool* skipped);
int receive_manifest(int fd, const Config* config, int* next_status);
+2 -2
View File
@@ -14,7 +14,7 @@
#include <threads.h>
PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* queue_scanner,
Queue* queue_loader) {
Queue* queue_loader) {
PipelineContextSender* context = malloc(sizeof(PipelineContextSender));
if (context == NULL)
return NULL;
@@ -58,7 +58,7 @@ void pipeline_context_sender_destroy(PipelineContextSender* context) {
}
PipelineContextReceiver* pipeline_context_receiver_create(Config* config, Queue* queue,
int file_descriptor, SSL* ssl) {
int file_descriptor, SSL* ssl) {
PipelineContextReceiver* context = malloc(sizeof(PipelineContextReceiver));
if (context == NULL)
return NULL;
+2 -2
View File
@@ -40,10 +40,10 @@ typedef struct PipelineContextReceiver {
} PipelineContextReceiver;
PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* queue_scanner,
Queue* queue_loader);
Queue* queue_loader);
void pipeline_context_sender_destroy(PipelineContextSender* context);
PipelineContextReceiver* pipeline_context_receiver_create(Config* config, Queue* queue_receiver,
int file_descriptor, SSL* ssl);
int file_descriptor, SSL* ssl);
void pipeline_context_receiver_destroy(PipelineContextReceiver* context);
int receive_thread(void* pipeline_context);
int write_thread(void* pipeline_context);
+3
View File
@@ -11,6 +11,9 @@
/* Maximum allowed data payload size for receive_data (100 MB) */
#define MAX_DATA_PAYLOAD_SIZE (100ULL * 1024 * 1024)
/* Maximum chunk size (64 MB) — prevents unbounded allocation from the wire */
#define MAX_CHUNK_SIZE (64ULL * 1024 * 1024)
typedef struct ssl_st SSL;
typedef int Status;
+14 -8
View File
@@ -13,7 +13,7 @@ bool mkdir_r(const char* path) {
char* path_duplicate = malloc(strlen(path) + 1);
if (!path_duplicate)
return false;
strcpy(path_duplicate, path);
memcpy(path_duplicate, path, strlen(path) + 1);
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
if (!path_current) {
free(path_duplicate);
@@ -21,7 +21,8 @@ bool mkdir_r(const char* path) {
}
char* path_current_position = path_current;
if (path[0] == '/') {
strcpy(path_current, "/");
path_current[0] = '/';
path_current[1] = '\0';
path_current_position += 1;
} else {
path_current[0] = '\0';
@@ -31,10 +32,12 @@ bool mkdir_r(const char* path) {
const char* part = strtok_r(path_duplicate, delimiter, &saveptr);
bool ok = true;
while (part != NULL) {
strcpy(path_current_position, part);
path_current_position += strlen(part) * sizeof(char);
strcpy(path_current_position, "/");
path_current_position += sizeof(char);
size_t part_len = strlen(part);
memcpy(path_current_position, part, part_len);
path_current_position += part_len;
path_current_position[0] = '/';
path_current_position[1] = '\0';
path_current_position++;
struct stat st;
if (stat(path_current, &st) != 0) {
if (mkdir(path_current, 0755) != 0) {
@@ -53,8 +56,11 @@ bool mkdir_r(const char* path) {
char* str_dup(const char* string) {
if (string == NULL)
return NULL;
char* new_string = (char*)malloc(strlen(string) + 1);
strcpy(new_string, string);
size_t str_len = strlen(string);
char* new_string = (char*)malloc(str_len + 1);
if (new_string == NULL)
return NULL;
memcpy(new_string, string, str_len + 1);
return new_string;
}