Compare commits

..

8 Commits

Author SHA1 Message Date
TapTap 261683aaff fix: null check in str_dup, const in file.c
CI / lint (pull_request) Successful in 2m16s
CI / sanitizers (address) (pull_request) Successful in 36s
CI / sanitizers (undefined) (pull_request) Successful in 37s
CI / fuzz-build (pull_request) Successful in 14s
CI / coverage (pull_request) Successful in 30s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
2026-07-30 19:34:17 +02:00
TapTap 15a861747a style: apply clang-format
CI / lint (pull_request) Failing after 2m18s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
2026-07-30 19:16:36 +02:00
TapTap 5f1b27c8ff fix: security #192 #187, bugs #194 #193, quality #195, features #174-#186
CI / lint (pull_request) Failing after 2s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
2026-07-30 19:05:19 +02:00
TapTap 732cd67735 Merge remote-tracking branch 'origin/fix/features-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 50fb7185a8 Merge remote-tracking branch 'origin/fix/quality-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 3062927e07 Merge remote-tracking branch 'origin/fix/bugs-v2' into integration/all-fixes-v2 2026-07-30 19:04:12 +02:00
TapTap 88746c3396 fix: replace strcpy with bounded memory operations (#195)
Replace all uses of strcpy() with memcpy() + explicit NUL termination
or direct assignment for safety and consistency. No behavioral changes.

src/shared/file.c:
  - file_create(): strcpy -> memcpy + explicit NUL (buffer size known)

src/shared/utils.c:
  - mkdir_r(): strcpy -> memcpy for path_duplicate
  - mkdir_r(): strcpy(path_current, "/") -> direct assignment
  - mkdir_r(): strcpy loop -> memcpy + direct assignment
  - str_dup(): strcpy -> memcpy (buffer size known)

PR #196 (dry-run manifest refactoring) was already applied in a previous
commit - send_dry_run_manifest() and send_delete_manifest() helpers
already exist and are used by both send_files() and
send_files_multithreaded().
2026-07-30 18:49:52 +02:00
TapTap 80768d64d4 fix: security issues #192 #191 #190 #189 #188 #187 2026-07-30 18:49:25 +02:00
10 changed files with 124 additions and 42 deletions
+8 -7
View File
@@ -166,7 +166,7 @@ static int send_single_file(Client* client, File* file, Config* config, bool use
if (!use_incremental) {
if (use_sendfile) {
return send_file_direct_sendfile(file, client->file_descriptor, config->use_metadata) ? 0
: -1;
: -1;
}
return send_file_direct(file, client->file_descriptor, config->use_metadata, compression_level)
? 0
@@ -284,8 +284,8 @@ static int send_chunks_multithreaded(void* pipeline_context) {
} else if (context->config->use_tls) {
client = client_create();
if (!client || !client_connect_tls(client, context->config->server_host,
context->config->server_port, context->config->tls_cert,
context->config->tls_key, context->config->tls_ca)) {
context->config->server_port, context->config->tls_cert,
context->config->tls_key, context->config->tls_ca)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server via TLS\n");
@@ -374,7 +374,8 @@ static int scan_directory_multithreaded(void* pipeline_context) {
context->config->exclude_patterns, context->config->exclude_count,
context->config->include_patterns, context->config->include_count, context->config->max_size,
context->config->min_size, context->config->max_depth, 4, context->config->follow_symlinks,
context->config->copy_links, context->config->safe_links, context->config->copy_unsafe_links, context->config->checksum);
context->config->copy_links, context->config->safe_links, context->config->copy_unsafe_links,
context->config->checksum);
Chunk* current_chunk;
while ((current_chunk = parallel_scanner_next(scanner)) != NULL) {
@@ -485,7 +486,7 @@ int send_files(Config* config) {
} else if (config->use_tls) {
client = client_create();
if (!client || !client_connect_tls(client, config->server_host, config->server_port,
config->tls_cert, config->tls_key, config->tls_ca)) {
config->tls_cert, config->tls_key, config->tls_ca)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server via TLS\n");
@@ -575,8 +576,8 @@ int send_files(Config* config) {
}
if (config->stats) {
double rate = elapsed_total > 0 ? total_bytes / (1048576.0 * elapsed_total) : 0;
fprintf(stderr, "Stats: %d files, %.1f MB, %.1f MB/s\n", total_files,
total_bytes / 1048576.0, rate);
fprintf(stderr, "Stats: %d files, %.1f MB, %.1f MB/s\n", total_files, total_bytes / 1048576.0,
rate);
}
directory_scanner_destroy(scanner);
client_disconnect(client);
+59 -8
View File
@@ -309,12 +309,12 @@ static int parallel_worker_thread(void* arg) {
}
ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata,
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum) {
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum) {
ParallelScanner* ps = calloc(1, sizeof(ParallelScanner));
if (!ps)
return NULL;
@@ -347,11 +347,62 @@ ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata
char* cur_path = path_cat(root_directory, entry->d_name);
if (!cur_path)
continue;
struct stat st;
if (stat(cur_path, &st) != 0) {
struct stat lstats;
if (lstat(cur_path, &lstats) != 0) {
free(cur_path);
continue;
}
bool is_symlink = S_ISLNK(lstats.st_mode);
// Skip symlinks unless the user explicitly enabled following/copying them.
if (is_symlink && !follow_symlinks && !copy_links && !safe_links && !copy_unsafe_links) {
free(cur_path);
continue;
}
// --safe-links: reject symlinks pointing outside the source tree.
if (is_symlink && safe_links) {
char link_target[4096];
ssize_t len = readlink(cur_path, link_target, sizeof(link_target) - 1);
if (len < 0) {
free(cur_path);
continue;
}
link_target[len] = 0;
if (link_target[0] == '/') {
free(cur_path);
continue;
}
}
// --copy-unsafe-links (without --copy-links): only copy absolute symlinks.
if (is_symlink && copy_unsafe_links && !copy_links) {
char link_target[4096];
ssize_t len = readlink(cur_path, link_target, sizeof(link_target) - 1);
if (len < 0) {
free(cur_path);
continue;
}
link_target[len] = 0;
bool unsafe = (link_target[0] == '/');
if (!unsafe) {
free(cur_path);
continue;
}
}
// Determine whether to use lstat or stat results for the entry.
struct stat st;
bool use_lstat_res = is_symlink && follow_symlinks && !copy_links;
if (use_lstat_res) {
st = lstats;
} else {
if (stat(cur_path, &st) != 0) {
free(cur_path);
continue;
}
}
if (S_ISDIR(st.st_mode)) {
array_list_add(subdirs, cur_path);
} else {
+6 -6
View File
@@ -51,12 +51,12 @@ Chunk* directory_scanner_next(DirectoryScanner* scanner);
void directory_scanner_destroy(DirectoryScanner* scanner);
ParallelScanner* parallel_scanner_create(char* root_directory, bool use_metadata,
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum);
unsigned long long chunk_size, char** exclude_patterns,
int exclude_count, char** include_patterns,
int include_count, unsigned long long max_size,
unsigned long long min_size, int max_depth,
int num_threads, bool follow_symlinks, bool copy_links,
bool safe_links, bool copy_unsafe_links, bool checksum);
Chunk* parallel_scanner_next(ParallelScanner* scanner);
void parallel_scanner_destroy(ParallelScanner* scanner);
+20
View File
@@ -12,6 +12,9 @@
#include "metadata.h"
#include "protocol.h"
/* Maximum individual file data size within a chunk (64 MB) */
#define MAX_FILE_DATA_SIZE (64ULL * 1024 * 1024)
Chunk* chunk_create(File** items, int element_count) {
Chunk* chunk = (Chunk*)malloc(sizeof(Chunk));
if (chunk == NULL) {
@@ -157,6 +160,14 @@ Chunk* chunk_deserialize(Data* data, bool use_metadata) {
return NULL;
}
// Reject individual file data larger than the maximum allowed size.
if (file_data_size > MAX_FILE_DATA_SIZE) {
log_message(LOG_LEVEL_ERROR, "File data size %zu exceeds maximum %llu", file_data_size,
(unsigned long long)MAX_FILE_DATA_SIZE);
array_list_delete(files);
return NULL;
}
void* file_data = malloc(file_data_size);
if (file_data == NULL) {
perror("Could not allocate memory for file data");
@@ -210,6 +221,15 @@ Chunk* receive_chunk_data(int fd, const Config* config) {
return NULL;
}
}
// Reject chunks larger than the maximum allowed size to prevent OOM.
if (data_to_process->size > MAX_CHUNK_SIZE) {
log_message(LOG_LEVEL_ERROR, "Chunk size %zu exceeds maximum %llu", data_to_process->size,
(unsigned long long)MAX_CHUNK_SIZE);
data_destroy(data_to_process);
return NULL;
}
Chunk* chunk = chunk_deserialize(data_to_process, config->use_metadata);
data_destroy(data_to_process);
if (chunk == NULL)
+8 -7
View File
@@ -35,7 +35,8 @@ File* file_create(const char* path) {
return NULL;
}
strcpy(file->path, path);
memcpy(file->path, path, path_len);
file->path[path_len] = '\0';
file->data = data_create_reserve(0);
if (file->data == NULL) {
free(file->path);
@@ -142,7 +143,8 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
}
char* resolved_root = NULL;
const char* actual_root = (partial_dir && config && config->partial) ? partial_dir : root_directory;
const char* actual_root =
(partial_dir && config && config->partial) ? partial_dir : root_directory;
resolved_root = realpath(actual_root, NULL);
if (resolved_root == NULL) {
if (mkdir_r(actual_root)) {
@@ -187,7 +189,7 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
if (backup_path) {
char* backup_dir_path = str_dup(backup_path);
if (backup_dir_path) {
char* bdir = dirname(backup_dir_path);
const char* bdir = dirname(backup_dir_path);
mkdir_r(bdir);
free(backup_dir_path);
}
@@ -222,8 +224,7 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
size_t root_len = strlen(resolved_root);
if (strncmp(resolved_dir, resolved_root, root_len) != 0 ||
(resolved_dir[root_len] != '\0' && resolved_dir[root_len] != '/')) {
log_message(LOG_LEVEL_ERROR, "Path escape detected: %s is outside %s", disk_path,
actual_root);
log_message(LOG_LEVEL_ERROR, "Path escape detected: %s is outside %s", disk_path, actual_root);
free(resolved_dir);
free(resolved_root);
free(disk_path);
@@ -517,8 +518,8 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
return file;
}
bool to_disk(const char* path, const void* data, unsigned long long data_size,
bool inplace, bool sparse) {
bool to_disk(const char* path, const void* data, unsigned long long data_size, bool inplace,
bool sparse) {
char* tmp_path = NULL;
char* directory = NULL;
+2 -2
View File
@@ -34,8 +34,8 @@ bool file_send_sendfile(File* file, int file_descriptor, bool use_metadata, int
size_t file_content_to_buffer(File* file);
FileMetadata* file_metadata_create(const struct stat* stats);
void file_metadata_destroy(void* metadata);
bool to_disk(const char* path, const void* data, unsigned long long data_size,
bool inplace, bool sparse);
bool to_disk(const char* path, const void* data, unsigned long long data_size, bool inplace,
bool sparse);
bool file_save_to_disk(const char* root_directory, File* file, const Config* config);
File* receive_incremental_check(int fd, const Config* config, bool* skipped);
int receive_manifest(int fd, const Config* config, int* next_status);
+2 -2
View File
@@ -14,7 +14,7 @@
#include <threads.h>
PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* queue_scanner,
Queue* queue_loader) {
Queue* queue_loader) {
PipelineContextSender* context = malloc(sizeof(PipelineContextSender));
if (context == NULL)
return NULL;
@@ -58,7 +58,7 @@ void pipeline_context_sender_destroy(PipelineContextSender* context) {
}
PipelineContextReceiver* pipeline_context_receiver_create(Config* config, Queue* queue,
int file_descriptor, SSL* ssl) {
int file_descriptor, SSL* ssl) {
PipelineContextReceiver* context = malloc(sizeof(PipelineContextReceiver));
if (context == NULL)
return NULL;
+2 -2
View File
@@ -40,10 +40,10 @@ typedef struct PipelineContextReceiver {
} PipelineContextReceiver;
PipelineContextSender* pipeline_context_sender_create(Config* config, Queue* queue_scanner,
Queue* queue_loader);
Queue* queue_loader);
void pipeline_context_sender_destroy(PipelineContextSender* context);
PipelineContextReceiver* pipeline_context_receiver_create(Config* config, Queue* queue_receiver,
int file_descriptor, SSL* ssl);
int file_descriptor, SSL* ssl);
void pipeline_context_receiver_destroy(PipelineContextReceiver* context);
int receive_thread(void* pipeline_context);
int write_thread(void* pipeline_context);
+3
View File
@@ -11,6 +11,9 @@
/* Maximum allowed data payload size for receive_data (100 MB) */
#define MAX_DATA_PAYLOAD_SIZE (100ULL * 1024 * 1024)
/* Maximum chunk size (64 MB) — prevents unbounded allocation from the wire */
#define MAX_CHUNK_SIZE (64ULL * 1024 * 1024)
typedef struct ssl_st SSL;
typedef int Status;
+14 -8
View File
@@ -13,7 +13,7 @@ bool mkdir_r(const char* path) {
char* path_duplicate = malloc(strlen(path) + 1);
if (!path_duplicate)
return false;
strcpy(path_duplicate, path);
memcpy(path_duplicate, path, strlen(path) + 1);
char* path_current = (char*)malloc((strlen(path) + 2) * sizeof(char));
if (!path_current) {
free(path_duplicate);
@@ -21,7 +21,8 @@ bool mkdir_r(const char* path) {
}
char* path_current_position = path_current;
if (path[0] == '/') {
strcpy(path_current, "/");
path_current[0] = '/';
path_current[1] = '\0';
path_current_position += 1;
} else {
path_current[0] = '\0';
@@ -31,10 +32,12 @@ bool mkdir_r(const char* path) {
const char* part = strtok_r(path_duplicate, delimiter, &saveptr);
bool ok = true;
while (part != NULL) {
strcpy(path_current_position, part);
path_current_position += strlen(part) * sizeof(char);
strcpy(path_current_position, "/");
path_current_position += sizeof(char);
size_t part_len = strlen(part);
memcpy(path_current_position, part, part_len);
path_current_position += part_len;
path_current_position[0] = '/';
path_current_position[1] = '\0';
path_current_position++;
struct stat st;
if (stat(path_current, &st) != 0) {
if (mkdir(path_current, 0755) != 0) {
@@ -53,8 +56,11 @@ bool mkdir_r(const char* path) {
char* str_dup(const char* string) {
if (string == NULL)
return NULL;
char* new_string = (char*)malloc(strlen(string) + 1);
strcpy(new_string, string);
size_t str_len = strlen(string);
char* new_string = (char*)malloc(str_len + 1);
if (new_string == NULL)
return NULL;
memcpy(new_string, string, str_len + 1);
return new_string;
}