Compare commits

..

3 Commits

Author SHA1 Message Date
TapTap 26be780da2 Merge remote-tracking branch 'origin/fix/refactor-cli-config' into integration/2026-07-29-batch-fix
CI / lint (pull_request) Failing after 12s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
2026-07-29 18:35:33 +02:00
TapTap 0021ca3fcd refactor: config_create(), main(), send_files() - reduce duplication and complexity
CI / lint (pull_request) Failing after 11s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / sanitizers (undefined) (pull_request) Has been skipped
CI / fuzz-build (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / valgrind (pull_request) Has been skipped
- #150: Replace 11-parameter config_create() with config_create() that
  initializes to sensible defaults; callers set fields directly
- #149: Extract validate_config() from main(); reduce main() from 325 to
  281 lines by extracting validation logic into separate function
- #151: Extract run_dry_run(), connect_to_server(), send_manifest(), and
  print_progress() shared helpers from send_files()/send_files_multithreaded()
  to eliminate code duplication
2026-07-29 18:34:10 +02:00
TapTap c75ccfd80b fix: add NULL-checks and input validation in CLI argument parsing (#152)
CI / lint (pull_request) Successful in 12s
CI / sanitizers (address) (pull_request) Successful in 16s
CI / sanitizers (undefined) (pull_request) Successful in 16s
CI / coverage (pull_request) Successful in 10s
CI / fuzz-build (pull_request) Successful in 13s
CI / valgrind (pull_request) Successful in 12s
CI / build-and-test (pull_request) Successful in 54s
- Add NULL-checks for all str_dup() calls in argument parsing
- Replace atoi with strtol + endptr validation for port numbers
- Add errno/endptr validation for strtoull calls (--max-size, --min-size)
- Check str_dup result for exclude/include patterns, server-host, backup-dir
- Validate positional directory arguments for allocation failure
2026-07-29 18:29:32 +02:00
17 changed files with 363 additions and 385 deletions
+157 -78
View File
@@ -99,33 +99,83 @@ static int read_patterns_from_file(const char* filepath, char*** patterns, int*
return -1;
}
*patterns = tmp;
(*patterns)[(*count)++] = str_dup(p);
(*patterns)[*count] = str_dup(p);
if (!(*patterns)[*count]) {
fprintf(stderr, "Error: memory allocation failed for pattern\n");
fclose(fp);
return -1;
}
(*count)++;
}
fclose(fp);
return 0;
}
static bool validate_config(Config* config) {
if (!config->send_directory || !config->receive_root_directory) {
fprintf(stderr, "Error: source and destination directories are required\n");
print_usage();
return false;
}
if (config->use_sendfile && (config->use_chunk_serialization || config->use_compression)) {
fprintf(stderr, "Error: -f/--sendfile cannot be combined with -c (compression) or -s "
"(chunk serialization)\n");
return false;
}
if (config->transport == TRANSPORT_SSH && config->use_sendfile) {
fprintf(stderr, "Error: -f/--sendfile is not supported with SSH transport\n");
return false;
}
if (config->use_incremental && config->use_chunk_serialization) {
fprintf(stderr, "Error: --incremental is not supported with -s (chunk serialization)\n");
return false;
}
if (config->use_incremental && !config->use_metadata) {
log_message(LOG_LEVEL_INFO, "Enabling metadata preservation for --incremental");
config->use_metadata = true;
}
if (config->use_delta && !config->use_incremental) {
fprintf(stderr, "Error: --delta requires --incremental\n");
return false;
}
if (config->use_delta && config->use_chunk_serialization) {
fprintf(stderr, "Error: --delta cannot be combined with -s (chunk serialization)\n");
return false;
}
if (config->use_delta && config->use_sendfile) {
fprintf(stderr, "Error: --delta cannot be combined with -f (sendfile)\n");
return false;
}
if (config->use_delta && !config->use_metadata) {
log_message(LOG_LEVEL_INFO, "Enabling metadata preservation for --delta");
config->use_metadata = true;
}
if (config->use_tls) {
if (!config->tls_cert || !config->tls_key) {
fprintf(stderr, "Error: --tls requires --cert and --key\n");
return false;
}
tls_global_init();
}
return true;
}
int main(int argc, char* argv[]) {
const char* env_source = getenv("FASTSYNC_SOURCE_DIR");
const char* env_dest = getenv("FASTSYNC_DEST_DIR");
const char* env_save = getenv("FASTSYNC_SAVE_TO_DISK");
bool save_to_disk = false;
if (env_save && (strcmp(env_save, "true") == 0 || strcmp(env_save, "1") == 0)) {
save_to_disk = true;
}
int exit_code = 0;
Config* config = NULL;
bool config_owned_by_pipeline = false;
char* config_version = str_dup(PROTOCOL_VERSION);
if (!config_version) {
config = config_create();
if (!config) {
exit_code = 1;
goto cleanup;
}
config = config_create(config_version, NULL, NULL, save_to_disk, false, false, false, false, 5,
false, 0);
if (env_save && (strcmp(env_save, "true") == 0 || strcmp(env_save, "1") == 0))
config->save_to_disk = true;
int positional_args[2];
int positional_count = 0;
@@ -142,7 +192,15 @@ int main(int argc, char* argv[]) {
} else if (strcmp(argv[i], "-n") == 0 || strcmp(argv[i], "--dry-run") == 0) {
config->dry_run = true;
} else if (strcmp(argv[i], "-p") == 0 && i + 1 < argc) {
config->ssh_port = atoi(argv[++i]);
char* end;
errno = 0;
long val = strtol(argv[++i], &end, 10);
if (errno != 0 || *end != '\0' || val <= 0 || val > 65535) {
fprintf(stderr, "Error: -p must be a valid port number (1-65535)\n");
exit_code = 1;
goto cleanup;
}
config->ssh_port = (int)val;
} else if (strcmp(argv[i], "--delete") == 0) {
config->use_delete = true;
} else if (strcmp(argv[i], "--exclude") == 0 && i + 1 < argc) {
@@ -153,7 +211,13 @@ int main(int argc, char* argv[]) {
goto cleanup;
}
config->exclude_patterns = tmp;
config->exclude_patterns[config->exclude_count++] = str_dup(argv[++i]);
config->exclude_patterns[config->exclude_count] = str_dup(argv[++i]);
if (!config->exclude_patterns[config->exclude_count]) {
fprintf(stderr, "Error: memory allocation failed for exclude pattern\n");
exit_code = 1;
goto cleanup;
}
config->exclude_count++;
} else if (strcmp(argv[i], "--include") == 0 && i + 1 < argc) {
char** tmp = realloc(config->include_patterns, (config->include_count + 1) * sizeof(char*));
if (!tmp) {
@@ -162,11 +226,31 @@ int main(int argc, char* argv[]) {
goto cleanup;
}
config->include_patterns = tmp;
config->include_patterns[config->include_count++] = str_dup(argv[++i]);
config->include_patterns[config->include_count] = str_dup(argv[++i]);
if (!config->include_patterns[config->include_count]) {
fprintf(stderr, "Error: memory allocation failed for include pattern\n");
exit_code = 1;
goto cleanup;
}
config->include_count++;
} else if (strcmp(argv[i], "--max-size") == 0 && i + 1 < argc) {
config->max_size = strtoull(argv[++i], NULL, 10);
char* end;
errno = 0;
config->max_size = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --max-size must be a valid non-negative integer\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--min-size") == 0 && i + 1 < argc) {
config->min_size = strtoull(argv[++i], NULL, 10);
char* end;
errno = 0;
config->min_size = strtoull(argv[++i], &end, 10);
if (errno != 0 || *end != '\0') {
fprintf(stderr, "Error: --min-size must be a valid non-negative integer\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--incremental") == 0) {
config->use_incremental = true;
} else if (strcmp(argv[i], "--delta") == 0) {
@@ -198,9 +282,19 @@ int main(int argc, char* argv[]) {
} else if (strcmp(argv[i], "--source-dir") == 0 && i + 1 < argc) {
free(config->send_directory);
config->send_directory = str_dup(argv[++i]);
if (!config->send_directory) {
fprintf(stderr, "Error: memory allocation failed\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--dest-dir") == 0 && i + 1 < argc) {
free(config->receive_root_directory);
config->receive_root_directory = str_dup(argv[++i]);
if (!config->receive_root_directory) {
fprintf(stderr, "Error: memory allocation failed\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--save-to-disk") == 0) {
config->save_to_disk = true;
} else if (strcmp(argv[i], "-M") == 0 || strcmp(argv[i], "--preserve") == 0) {
@@ -218,8 +312,21 @@ int main(int argc, char* argv[]) {
} else if (strcmp(argv[i], "--server-host") == 0 && i + 1 < argc) {
free(config->server_host);
config->server_host = str_dup(argv[++i]);
if (!config->server_host) {
fprintf(stderr, "Error: memory allocation failed\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--server-port") == 0 && i + 1 < argc) {
config->server_port = atoi(argv[++i]);
char* end;
errno = 0;
long val = strtol(argv[++i], &end, 10);
if (errno != 0 || *end != '\0' || val <= 0 || val > 65535) {
fprintf(stderr, "Error: --server-port must be a valid port number (1-65535)\n");
exit_code = 1;
goto cleanup;
}
config->server_port = (int)val;
} else if (strcmp(argv[i], "--bwlimit") == 0 && i + 1 < argc) {
char* end;
errno = 0;
@@ -274,6 +381,11 @@ int main(int argc, char* argv[]) {
config->backup = true;
} else if (strcmp(argv[i], "--backup-dir") == 0 && i + 1 < argc) {
config->backup_dir = str_dup(argv[++i]);
if (!config->backup_dir) {
fprintf(stderr, "Error: memory allocation failed\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "--stats") == 0) {
config->stats = true;
} else if (strcmp(argv[i], "--max-depth") == 0 && i + 1 < argc) {
@@ -316,6 +428,11 @@ int main(int argc, char* argv[]) {
} else if (strcmp(argv[i], "--fastsync-server-path") == 0 && i + 1 < argc) {
free(config->fastsync_server_path);
config->fastsync_server_path = str_dup(argv[++i]);
if (!config->fastsync_server_path) {
fprintf(stderr, "Error: memory allocation failed\n");
exit_code = 1;
goto cleanup;
}
} else if (strcmp(argv[i], "-v") == 0 || strcmp(argv[i], "--verbose") == 0) {
set_log_level(LOG_LEVEL_DEBUG);
} else if (argv[i][0] == '-') {
@@ -340,8 +457,12 @@ int main(int argc, char* argv[]) {
free(config->receive_root_directory);
config->send_directory = str_dup(argv[positional_args[0]]);
config->receive_root_directory = str_dup(argv[positional_args[1]]);
if (!config->send_directory || !config->receive_root_directory) {
fprintf(stderr, "Error: memory allocation failed for directory paths\n");
exit_code = 1;
goto cleanup;
}
config->save_to_disk = true;
config_parse_ssh_dest(config);
} else if (positional_count == 1) {
fprintf(stderr, "Error: missing destination argument\n");
@@ -349,69 +470,27 @@ int main(int argc, char* argv[]) {
exit_code = 1;
goto cleanup;
} else {
if (!config->send_directory && env_source)
if (!config->send_directory && env_source) {
config->send_directory = str_dup((char*)env_source);
if (!config->receive_root_directory && env_dest)
config->receive_root_directory = str_dup((char*)env_dest);
}
if (!config->send_directory || !config->receive_root_directory) {
fprintf(stderr, "Error: source and destination directories are required\n");
print_usage();
exit_code = 1;
goto cleanup;
}
if (config->use_sendfile && (config->use_chunk_serialization || config->use_compression)) {
fprintf(stderr, "Error: -f/--sendfile cannot be combined with -c (compression) or -s (chunk "
"serialization)\n");
exit_code = 1;
goto cleanup;
}
if (config->transport == TRANSPORT_SSH && config->use_sendfile) {
fprintf(stderr, "Error: -f/--sendfile is not supported with SSH transport\n");
exit_code = 1;
goto cleanup;
}
if (config->use_incremental && config->use_chunk_serialization) {
fprintf(stderr, "Error: --incremental is not supported with -s (chunk serialization)\n");
exit_code = 1;
goto cleanup;
}
if (config->use_incremental && !config->use_metadata) {
log_message(LOG_LEVEL_INFO, "Enabling metadata preservation for --incremental");
config->use_metadata = true;
}
if (config->use_delta && !config->use_incremental) {
fprintf(stderr, "Error: --delta requires --incremental\n");
exit_code = 1;
goto cleanup;
}
if (config->use_delta && config->use_chunk_serialization) {
fprintf(stderr, "Error: --delta cannot be combined with -s (chunk serialization)\n");
exit_code = 1;
goto cleanup;
}
if (config->use_delta && config->use_sendfile) {
fprintf(stderr, "Error: --delta cannot be combined with -f (sendfile)\n");
exit_code = 1;
goto cleanup;
}
if (config->use_delta && !config->use_metadata) {
log_message(LOG_LEVEL_INFO, "Enabling metadata preservation for --delta");
config->use_metadata = true;
}
if (config->use_tls) {
if (!config->tls_cert || !config->tls_key) {
fprintf(stderr, "Error: --tls requires --cert and --key\n");
exit_code = 1;
goto cleanup;
if (!config->send_directory) {
fprintf(stderr, "Error: memory allocation failed for source directory\n");
exit_code = 1;
goto cleanup;
}
}
tls_global_init();
if (!config->receive_root_directory && env_dest) {
config->receive_root_directory = str_dup((char*)env_dest);
if (!config->receive_root_directory) {
fprintf(stderr, "Error: memory allocation failed for destination directory\n");
exit_code = 1;
goto cleanup;
}
}
}
if (!validate_config(config)) {
exit_code = 1;
goto cleanup;
}
tcp_set_timeouts(config->timeout, config->contimeout);
+77 -86
View File
@@ -364,62 +364,86 @@ static int load_files_multithreaded(void* pipeline_context) {
}
}
int send_files(Config* config) {
if (config->dry_run) {
DirectoryScanner* scanner = directory_scanner_create(
config->send_directory, config->use_metadata, config->chunk_size, config->exclude_patterns,
config->exclude_count, config->include_patterns, config->include_count, config->max_size,
config->min_size, config->max_depth);
Chunk* chunk;
int file_count = 0;
unsigned long long total_bytes = 0;
printf("Dry run: files to be transferred\n");
while ((chunk = directory_scanner_next(scanner)) != NULL) {
for (int i = 0; i < chunk->element_count; i++) {
printf(" %s (%zu bytes)\n", chunk->items[i]->path, chunk->items[i]->data->size);
total_bytes += chunk->items[i]->data->size;
file_count++;
}
chunk_destroy(chunk);
static int run_dry_run(Config* config) {
DirectoryScanner* scanner = directory_scanner_create(
config->send_directory, config->use_metadata, config->chunk_size, config->exclude_patterns,
config->exclude_count, config->include_patterns, config->include_count, config->max_size,
config->min_size, config->max_depth);
if (!scanner)
return -1;
Chunk* chunk;
int file_count = 0;
unsigned long long total_bytes = 0;
printf("Dry run: files to be transferred\n");
while ((chunk = directory_scanner_next(scanner)) != NULL) {
for (int i = 0; i < chunk->element_count; i++) {
printf(" %s (%zu bytes)\n", chunk->items[i]->path, chunk->items[i]->data->size);
total_bytes += chunk->items[i]->data->size;
file_count++;
}
directory_scanner_destroy(scanner);
printf("Total: %d files, %.1f MB\n", file_count, total_bytes / 1048576.0);
return 0;
chunk_destroy(chunk);
}
directory_scanner_destroy(scanner);
printf("Total: %d files, %.1f MB\n", file_count, total_bytes / 1048576.0);
return 0;
}
Client* client;
static Client* connect_to_server(Config* config) {
if (config->transport == TRANSPORT_SSH) {
if (config->use_sendfile) {
fprintf(stderr, "Error: -f/--sendfile is not supported with SSH transport\n");
return 1;
}
client =
client_connect_ssh(config->ssh_destination, config->ssh_port, config->fastsync_server_path);
if (!client)
return 1;
} else if (config->use_tls) {
client = client_create();
if (!client || !client_connect_tls(client, config->server_host, config->server_port,
config->tls_cert, config->tls_key, config->tls_ca)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server via TLS\n");
return 1;
return NULL;
}
return client_connect_ssh(config->ssh_destination, config->ssh_port,
config->fastsync_server_path);
}
Client* client = client_create();
if (!client)
return NULL;
bool ok;
if (config->use_tls) {
ok = client_connect_tls(client, config->server_host, config->server_port, config->tls_cert,
config->tls_key, config->tls_ca);
} else {
client = client_create();
if (!client || !client_connect(client, config->server_host, config->server_port)) {
if (client)
client_delete(client);
fprintf(stderr, "Error: could not connect to server\n");
return 1;
}
ok = client_connect(client, config->server_host, config->server_port);
}
if (!config_send(client->file_descriptor, config)) {
client_disconnect(client);
if (!ok) {
client_delete(client);
return 1;
fprintf(stderr, "Error: could not connect to server\n");
return NULL;
}
return client;
}
static bool send_manifest(int fd, ArrayList* manifest) {
if (!send_status(fd, STATUS_MANIFEST))
return false;
if (!send_int(fd, manifest->size))
return false;
for (int i = 0; i < manifest->size; i++) {
if (!send_str(fd, (char*)manifest->items[i]))
return false;
}
return true;
}
static void print_progress(unsigned long long total_bytes, time_t start) {
double elapsed = difftime(time(NULL), start);
double rate = elapsed > 0 ? total_bytes / (1048576.0 * elapsed) : 0;
fprintf(stderr, "\rSent %.1f MB (%.1f MB/s) ", total_bytes / 1048576.0, rate);
fflush(stderr);
}
int send_files(Config* config) {
if (config->dry_run)
return run_dry_run(config);
Client* client = connect_to_server(config);
if (!client)
return 1;
if (!config_send(client->file_descriptor, config))
goto send_fail;
DirectoryScanner* scanner = directory_scanner_create(
config->send_directory, config->use_metadata, config->chunk_size, config->exclude_patterns,
config->exclude_count, config->include_patterns, config->include_count, config->max_size,
@@ -461,40 +485,26 @@ int send_files(Config* config) {
time_t now = time(NULL);
if (now - last_progress >= 1) {
last_progress = now;
double elapsed = difftime(now, start);
double rate = elapsed > 0 ? total_bytes / (1048576.0 * elapsed) : 0;
fprintf(stderr, "\rSent %.1f MB (%.1f MB/s) ", total_bytes / 1048576.0, rate);
fflush(stderr);
print_progress(total_bytes, start);
}
}
chunk_destroy(current_chunk);
}
if (config->use_delete) {
if (!send_status(client->file_descriptor, STATUS_MANIFEST)) {
if (!send_manifest(client->file_descriptor, manifest)) {
array_list_delete(manifest);
goto send_fail;
}
if (!send_int(client->file_descriptor, manifest->size)) {
array_list_delete(manifest);
goto send_fail;
}
for (int i = 0; i < manifest->size; i++) {
if (!send_str(client->file_descriptor, (char*)manifest->items[i])) {
array_list_delete(manifest);
goto send_fail;
}
}
array_list_delete(manifest);
}
if (!send_status(client->file_descriptor, STATUS_FINISHED))
goto send_fail;
Status s;
int ok = receive_status(client->file_descriptor, &s) && s == STATUS_OK;
if (config->show_progress) {
double elapsed = difftime(time(NULL), start);
double rate = elapsed > 0 ? total_bytes / (1048576.0 * elapsed) : 0;
fprintf(stderr, "\rSent %.1f MB (%.1f MB/s) Done.\n", total_bytes / 1048576.0, rate);
}
if (config->show_progress)
print_progress(total_bytes, start);
if (config->show_progress)
fprintf(stderr, "Done.\n");
directory_scanner_destroy(scanner);
client_disconnect(client);
client_delete(client);
@@ -508,27 +518,8 @@ send_fail:
}
int send_files_multithreaded(Config* config) {
if (config->dry_run) {
DirectoryScanner* scanner = directory_scanner_create(
config->send_directory, config->use_metadata, config->chunk_size, config->exclude_patterns,
config->exclude_count, config->include_patterns, config->include_count, config->max_size,
config->min_size, config->max_depth);
Chunk* chunk;
int file_count = 0;
unsigned long long total_bytes = 0;
printf("Dry run: files to be transferred\n");
while ((chunk = directory_scanner_next(scanner)) != NULL) {
for (int i = 0; i < chunk->element_count; i++) {
printf(" %s (%zu bytes)\n", chunk->items[i]->path, chunk->items[i]->data->size);
total_bytes += chunk->items[i]->data->size;
file_count++;
}
chunk_destroy(chunk);
}
directory_scanner_destroy(scanner);
printf("Total: %d files, %.1f MB\n", file_count, total_bytes / 1048576.0);
return 0;
}
if (config->dry_run)
return run_dry_run(config);
long pages = sysconf(_SC_AVPHYS_PAGES);
long page_size = sysconf(_SC_PAGE_SIZE);
+1 -1
View File
@@ -69,7 +69,7 @@ int receive_files(Config* config, int fd) {
}
char* full_path = path_cat(config->receive_root_directory, check_path);
struct stat st;
bool has_old = full_path && lstat(full_path, &st) == 0;
bool has_old = full_path && stat(full_path, &st) == 0;
bool match = has_old && (unsigned long long)st.st_size == check_size &&
(long long)st.st_mtime == check_mtime;
if (match)
+2 -9
View File
@@ -78,21 +78,14 @@ Data* data_decompress(Data* compressed_data) {
return NULL;
}
// ZSTD_CONTENTSIZE_UNKNOWN (~2^64) can cause massive allocation;
// fall back to a conservative estimate (3x compressed size) when unknown.
if (dst_size == ZSTD_CONTENTSIZE_UNKNOWN) {
dst_size = compressed_data->size * 3;
if (dst_size < INITIAL_DECOMPRESS_BUF_SIZE)
dst_size = INITIAL_DECOMPRESS_BUF_SIZE;
}
ZSTD_DCtx* dctx = ZSTD_createDCtx();
if (!dctx) {
log_message(LOG_LEVEL_ERROR, "Failed to create ZSTD decompression context");
return NULL;
}
size_t buf_size = (dst_size > 0) ? (size_t)dst_size : INITIAL_DECOMPRESS_BUF_SIZE;
size_t buf_size =
(!ZSTD_isError(dst_size) && dst_size > 0) ? (size_t)dst_size : INITIAL_DECOMPRESS_BUF_SIZE;
Data* uncompressed_data = data_create_empty(buf_size);
if (!uncompressed_data) {
log_message(LOG_LEVEL_ERROR, "Failed to allocate decompression buffer");
+8 -44
View File
@@ -8,57 +8,21 @@
#include <stdlib.h>
#include <string.h>
Config* config_create(char* version, char* send_directory, char* receive_directory,
bool save_to_disk, bool use_multithreading, bool use_chunk_serialization,
bool use_compression, bool use_metadata, int compression_level,
bool use_sendfile, unsigned long long chunk_size) {
Config* config = malloc(sizeof(Config));
Config* config_create(void) {
Config* config = calloc(1, sizeof(Config));
if (!config)
return NULL;
config->version = version;
config->send_directory = send_directory;
config->receive_root_directory = receive_directory;
config->save_to_disk = save_to_disk;
config->use_multithreading = use_multithreading;
config->use_chunk_serialization = use_chunk_serialization;
config->use_compression = use_compression;
config->use_metadata = use_metadata;
config->show_progress = false;
config->dry_run = false;
config->use_delete = false;
config->compression_level = compression_level;
config->use_sendfile = use_sendfile;
config->chunk_size = chunk_size > 0 ? chunk_size : DEFAULT_CHUNK_SIZE;
config->version = str_dup(PROTOCOL_VERSION);
config->compression_level = 5;
config->chunk_size = DEFAULT_CHUNK_SIZE;
config->ssh_port = 22;
config->transport = TRANSPORT_TCP;
config->ssh_destination = NULL;
config->fastsync_server_path = NULL;
config->exclude_patterns = NULL;
config->exclude_count = 0;
config->include_patterns = NULL;
config->include_count = 0;
config->max_size = 0;
config->min_size = 0;
config->use_incremental = false;
config->use_delta = false;
config->delta_block_size = DELTA_BLOCK_SIZE_DEFAULT;
config->delta_max_file_size = DELTA_MAX_FILE_SIZE;
config->use_tls = false;
config->tls_cert = NULL;
config->tls_key = NULL;
config->tls_ca = NULL;
config->server_host = str_dup("127.0.0.1");
config->server_port = 8080;
config->server_host = str_dup("127.0.0.1");
config->timeout = 30;
config->contimeout = 10;
config->quiet = false;
config->backup = false;
config->backup_dir = NULL;
config->stats = false;
config->max_depth = 0;
config->log_file = NULL;
config->queue_size = 100;
config->delta_block_size = DELTA_BLOCK_SIZE_DEFAULT;
config->delta_max_file_size = DELTA_MAX_FILE_SIZE;
return config;
}
+1 -4
View File
@@ -58,10 +58,7 @@ typedef struct Config {
#define PROTOCOL_VERSION "1.3.0"
#define DEFAULT_CHUNK_SIZE (10 * 1024 * 1024)
Config* config_create(char* version, char* send_directory, char* receive_directory,
bool save_to_disk, bool use_multithreading, bool use_chunk_serialization,
bool use_compression, bool use_metadata, int compression_level,
bool use_sendfile, unsigned long long chunk_size);
Config* config_create(void);
void config_delete(Config* config);
bool config_send(int file_descriptor, const Config* config);
Config* config_receive(int file_descriptor);
-21
View File
@@ -1,6 +1,5 @@
#include "delta.h"
#include "log.h"
#include <stdint.h>
#include <stdlib.h>
#include <string.h>
@@ -8,10 +7,6 @@
#define XXH_IMPLEMENTATION
#include <xxhash.h>
/* Maximum number of blocks/instructions allowed from the wire to prevent OOM */
#define MAX_DELTA_BLOCKS (1024U * 1024U) /* 1M signature blocks */
#define MAX_DELTA_INSTRUCTIONS (1024U * 1024U) /* 1M delta instructions */
uint32_t delta_adler32(const void* data, uint32_t len) {
const uint8_t* p = (const uint8_t*)data;
uint32_t s1 = 1;
@@ -106,14 +101,6 @@ DeltaSignature* delta_signature_deserialize(const Data* data) {
memcpy(&sig->block_count, buf + pos, sizeof(uint32_t));
pos += sizeof(uint32_t);
// Reject unreasonably large block counts to prevent OOM
if (sig->block_count > MAX_DELTA_BLOCKS) {
log_message(LOG_LEVEL_ERROR, "Delta signature block count %u exceeds maximum %u",
sig->block_count, MAX_DELTA_BLOCKS);
free(sig);
return NULL;
}
uint64_t expected = sizeof(uint64_t) + sizeof(uint32_t) + sizeof(uint32_t) +
(uint64_t)sig->block_count * (sizeof(uint32_t) + sizeof(uint32_t));
if (data->size < expected) {
@@ -353,14 +340,6 @@ Delta* delta_deserialize(const Data* data) {
memcpy(&delta->instruction_count, buf + pos, sizeof(uint32_t));
pos += sizeof(uint32_t);
// Reject unreasonably large instruction counts to prevent OOM
if (delta->instruction_count > MAX_DELTA_INSTRUCTIONS) {
log_message(LOG_LEVEL_ERROR, "Delta instruction count %u exceeds maximum %u",
delta->instruction_count, MAX_DELTA_INSTRUCTIONS);
free(delta);
return NULL;
}
delta->instructions = malloc(delta->instruction_count * sizeof(DeltaInstruction));
if (!delta->instructions) {
free(delta);
+3 -58
View File
@@ -134,64 +134,9 @@ bool file_save_to_disk(const char* root_directory, File* file, const Config* con
log_message(LOG_LEVEL_ERROR, "Path traversal detected in file path: %s", file->path);
return false;
}
// Resolve the destination root to its real path, preventing symlink-based escapes.
// If the root does not yet exist, try to create it so realpath can succeed.
char* resolved_root = realpath(root_directory, NULL);
if (resolved_root == NULL) {
if (mkdir_r(root_directory)) {
resolved_root = realpath(root_directory, NULL);
}
}
if (resolved_root == NULL) {
log_message(LOG_LEVEL_ERROR, "Failed to resolve destination root: %s", root_directory);
char* disk_path = path_cat((char*)root_directory, file->path);
if (disk_path == NULL)
return false;
}
char* disk_path = path_cat(resolved_root, file->path);
if (disk_path == NULL) {
free(resolved_root);
return false;
}
// Ensure the target directory exists so the parent can be resolved for path safety.
char* dir_dup = str_dup(disk_path);
if (!dir_dup) {
free(resolved_root);
free(disk_path);
return false;
}
char* dir_str = dirname(dir_dup);
// Create the directory if needed (no-op if it already exists) so realpath can resolve it.
if (!mkdir_r(dir_str)) {
free(dir_dup);
free(resolved_root);
free(disk_path);
return false;
}
char* resolved_dir = realpath(dir_str, NULL);
free(dir_dup);
if (resolved_dir == NULL) {
log_message(LOG_LEVEL_ERROR, "Failed to resolve directory for: %s", disk_path);
free(resolved_root);
free(disk_path);
return false;
}
// Verify that the resolved directory is inside the resolved root.
// Both are canonical absolute paths — this prevents symlink-based escapes.
size_t root_len = strlen(resolved_root);
if (strncmp(resolved_dir, resolved_root, root_len) != 0 ||
(resolved_dir[root_len] != '\0' && resolved_dir[root_len] != '/')) {
log_message(LOG_LEVEL_ERROR, "Path escape detected: %s is outside %s", disk_path, root_directory);
free(resolved_dir);
free(resolved_root);
free(disk_path);
return false;
}
free(resolved_dir);
free(resolved_root);
bool ok = to_disk(disk_path, file->data->data, file->data->size);
if (ok)
file_restore_metadata(disk_path, file->metadata);
@@ -396,7 +341,7 @@ File* receive_incremental_check(int fd, const Config* config, bool* skipped) {
char* full_path = path_cat(config->receive_root_directory, check_path);
struct stat st;
bool has_old_file = (full_path && lstat(full_path, &st) == 0);
bool has_old_file = (full_path && stat(full_path, &st) == 0);
unsigned long long old_size = has_old_file ? (unsigned long long)st.st_size : 0;
bool match = has_old_file && (unsigned long long)st.st_size == check_size &&
+3 -3
View File
@@ -9,7 +9,7 @@
#include <time.h>
#include <unistd.h>
#define MAX_DATA_SIZE (100ULL * 1024 * 1024) /* 100 MB max per data message */
#define MAX_DATA_SIZE (256ULL * 1024 * 1024) /* 256 MB max per message */
#define RECEIVE_TIMEOUT_SEC 60 /* 60 second per-message timeout */
#define MAX_CONNECTION_MEMORY (1024ULL * 1024 * 1024) /* 1 GB total per connection */
@@ -186,9 +186,9 @@ char* receive_str(int file_descriptor) {
size_t size;
if (!receive_n_data(file_descriptor, &size, sizeof(size_t)))
return NULL;
if (size > MAX_STRING_SIZE) {
if (size > MAX_DATA_SIZE) {
log_message(LOG_LEVEL_ERROR, "String size %zu exceeds maximum %llu", size,
(unsigned long long)MAX_STRING_SIZE);
(unsigned long long)MAX_DATA_SIZE);
return NULL;
}
char* data = (char*)malloc(size + 1);
+2 -5
View File
@@ -5,11 +5,8 @@
#include <stdbool.h>
#include <stddef.h>
/* Maximum allowed string size for receive_str (64 KB) */
#define MAX_STRING_SIZE (64 * 1024)
/* Maximum allowed data payload size for receive_data (100 MB) */
#define MAX_DATA_PAYLOAD_SIZE (100ULL * 1024 * 1024)
/* Maximum allowed string size for receive_str (10 MB) */
#define MAX_STRING_SIZE (10 * 1024 * 1024)
typedef struct ssl_st SSL;
+13 -30
View File
@@ -79,38 +79,25 @@ static SSL_CTX* create_ssl_ctx(bool is_server, const char* cert, const char* key
return ctx;
}
static SSL* wrap_fd_with_ssl(int fd, SSL_CTX* ctx, bool is_server, const char* hostname) {
static SSL* wrap_fd_with_ssl(int fd, SSL_CTX* ctx, bool is_server) {
SSL* ssl = SSL_new(ctx);
if (!ssl) {
log_message(LOG_LEVEL_ERROR, "Failed to create SSL object");
return NULL;
}
SSL_set_fd(ssl, fd);
// Enable hostname verification for client connections when a hostname is provided.
// Must be done before SSL_connect to take effect during the handshake.
if (!is_server && hostname) {
SSL_set1_host(ssl, hostname);
}
// Retry SSL_accept/SSL_connect on WANT_READ/WANT_WRITE (non-blocking handshake)
int ret;
do {
if (is_server)
ret = SSL_accept(ssl);
else
ret = SSL_connect(ssl);
if (is_server)
ret = SSL_accept(ssl);
else
ret = SSL_connect(ssl);
if (ret <= 0) {
int ssl_err = SSL_get_error(ssl, ret);
if (ssl_err == SSL_ERROR_WANT_READ || ssl_err == SSL_ERROR_WANT_WRITE)
continue;
log_message(LOG_LEVEL_ERROR, "SSL %s failed", is_server ? "accept" : "connect");
log_ssl_errors();
SSL_free(ssl);
return NULL;
}
} while (ret <= 0);
if (ret <= 0) {
log_message(LOG_LEVEL_ERROR, "SSL %s failed", is_server ? "accept" : "connect");
log_ssl_errors();
SSL_free(ssl);
return NULL;
}
return ssl;
}
@@ -130,7 +117,7 @@ struct tls_child_ctx {
static void tls_child_fn(int fd, void* arg) {
struct tls_child_ctx* ctx = (struct tls_child_ctx*)arg;
SSL* ssl = wrap_fd_with_ssl(fd, ctx->ssl_ctx, true, NULL);
SSL* ssl = wrap_fd_with_ssl(fd, ctx->ssl_ctx, true);
if (!ssl)
return;
io_set_ssl(ssl);
@@ -164,16 +151,12 @@ bool client_connect_tls(Client* client, char* host, int port, const char* cert_p
return false;
client->ssl_ctx = ctx;
// Pass the server hostname for TLS hostname verification (SSL_set1_host
// is called inside wrap_fd_with_ssl before the handshake when ca_path is set).
const char* verify_host = ca_path ? host : NULL;
SSL* ssl = wrap_fd_with_ssl(client->file_descriptor, ctx, false, verify_host);
SSL* ssl = wrap_fd_with_ssl(client->file_descriptor, ctx, false);
if (!ssl) {
SSL_CTX_free(ctx);
client->ssl_ctx = NULL;
return false;
}
client->ssl = ssl;
io_set_ssl(ssl);
return true;
+1 -7
View File
@@ -126,13 +126,7 @@ static void delete_extras_walk(const char* abs_path, const char* rel_path, Array
char* child_abs = path_cat((char*)abs_path, entry->d_name);
char* child_rel = path_cat((char*)rel_path, entry->d_name);
struct stat st;
if (lstat(child_abs, &st) != 0) {
free(child_abs);
free(child_rel);
continue;
}
// Skip symlinks to prevent following them outside the destination tree
if (S_ISLNK(st.st_mode)) {
if (stat(child_abs, &st) != 0) {
free(child_abs);
free(child_rel);
continue;
+1 -9
View File
@@ -37,23 +37,15 @@ def _generate_certs(cert_dir):
], check=True, capture_output=True)
# Server key + CSR + cert (signed by CA)
# Use a config file to include IP SAN 127.0.0.1 so hostname verification passes
san_config = os.path.join(cert_dir, "server_san.conf")
with open(san_config, "w") as f:
f.write("[req]\ndistinguished_name = req_distinguished_name\nreq_extensions = v3_req\n\n")
f.write("[req_distinguished_name]\nCN = localhost\n\n")
f.write("[v3_req]\nsubjectAltName = @alt_names\n\n")
f.write("[alt_names]\nDNS.1 = localhost\nIP.1 = 127.0.0.1\n")
subprocess.run([
"openssl", "req", "-newkey", "rsa:2048", "-nodes",
"-keyout", server_key, "-out", os.path.join(cert_dir, "server.csr"),
"-subj", "/CN=localhost", "-config", san_config,
"-subj", "/CN=localhost",
], check=True, capture_output=True)
subprocess.run([
"openssl", "x509", "-req", "-in", os.path.join(cert_dir, "server.csr"),
"-CA", ca_cert, "-CAkey", ca_key, "-CAcreateserial",
"-out", server_cert, "-days", "1",
"-extfile", san_config, "-extensions", "v3_req",
], check=True, capture_output=True)
# Client key + CSR + cert (signed by CA)
+51 -12
View File
@@ -7,9 +7,17 @@
#include <stdlib.h>
static void test_config_lifecycle() {
Config* cfg = config_create(str_dup("1.0"), str_dup("/src"), str_dup("/dst"), true, true, false,
false, false, 1, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("1.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
cfg->save_to_disk = true;
cfg->use_multithreading = true;
cfg->use_chunk_serialization = false;
cfg->use_compression = false;
cfg->compression_level = 1;
EXPECT_EQ_STR(cfg->version, "1.0");
EXPECT_EQ_STR(cfg->send_directory, "/src");
EXPECT_EQ_STR(cfg->receive_root_directory, "/dst");
@@ -23,9 +31,14 @@ static void test_config_lifecycle() {
}
static void test_config_ssh_dest() {
Config* cfg = config_create(str_dup("1.0"), str_dup("/src"), str_dup("user@host:/dst"), true,
false, false, false, false, 1, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("1.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("user@host:/dst");
cfg->save_to_disk = true;
cfg->compression_level = 1;
EXPECT_EQ_INT(cfg->transport, TRANSPORT_TCP);
EXPECT_NULL(cfg->ssh_destination);
EXPECT_EQ_STR(cfg->receive_root_directory, "user@host:/dst");
@@ -38,8 +51,14 @@ static void test_config_ssh_dest() {
}
static void test_config_ssh_dest_local_path() {
Config* cfg = config_create(str_dup("1.0"), str_dup("/src"), str_dup("/local/path"), true, false,
false, false, false, 1, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("1.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/local/path");
cfg->save_to_disk = true;
cfg->compression_level = 1;
config_parse_ssh_dest(cfg);
EXPECT_EQ_INT(cfg->transport, TRANSPORT_TCP);
EXPECT_NULL(cfg->ssh_destination);
@@ -48,8 +67,14 @@ static void test_config_ssh_dest_local_path() {
}
static void test_config_ssh_dest_no_user() {
Config* cfg = config_create(str_dup("1.0"), str_dup("/src"), str_dup("host:/remote"), true, false,
false, false, false, 1, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("1.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("host:/remote");
cfg->save_to_disk = true;
cfg->compression_level = 1;
config_parse_ssh_dest(cfg);
EXPECT_EQ_INT(cfg->transport, TRANSPORT_SSH);
EXPECT_EQ_STR(cfg->ssh_destination, "host:/remote");
@@ -58,8 +83,14 @@ static void test_config_ssh_dest_no_user() {
}
static void test_pipeline_sender_lifecycle() {
Config* cfg = config_create(str_dup("2.0"), str_dup("/src2"), str_dup("/dst2"), false, false,
true, true, false, 1, false, 0);
Config* cfg = config_create();
free(cfg->version);
cfg->version = str_dup("2.0");
cfg->send_directory = str_dup("/src2");
cfg->receive_root_directory = str_dup("/dst2");
cfg->use_chunk_serialization = true;
cfg->use_compression = true;
cfg->compression_level = 1;
Queue* q1 = queue_create(5, NULL);
Queue* q2 = queue_create(15, NULL);
@@ -75,8 +106,16 @@ static void test_pipeline_sender_lifecycle() {
}
static void test_pipeline_receiver_lifecycle() {
Config* cfg = config_create(str_dup("3.0"), str_dup("/src3"), str_dup("/dst3"), true, true, true,
true, false, 1, false, 0);
Config* cfg = config_create();
free(cfg->version);
cfg->version = str_dup("3.0");
cfg->send_directory = str_dup("/src3");
cfg->receive_root_directory = str_dup("/dst3");
cfg->save_to_disk = true;
cfg->use_multithreading = true;
cfg->use_chunk_serialization = true;
cfg->use_compression = true;
cfg->compression_level = 1;
Queue* q = queue_create(20, NULL);
PipelineContextReceiver* pcr = pipeline_context_receiver_create(cfg, q, 42);
+3 -2
View File
@@ -154,8 +154,9 @@ static void test_file_send_receive() {
memcpy(file->data->data, content, len);
file->data->size = len;
Config* cfg = config_create(str_dup(PROTOCOL_VERSION), str_dup("/tmp"), str_dup("/tmp"), false,
false, false, false, false, 0, false, 0);
Config* cfg = config_create();
cfg->send_directory = str_dup("/tmp");
cfg->receive_root_directory = str_dup("/tmp");
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
+13 -6
View File
@@ -22,9 +22,10 @@ static void test_sendfile_basic() {
/* Set the size so file_send_sendfile can report it */
file->data->size = len;
Config* cfg = config_create(str_dup(PROTOCOL_VERSION), str_dup("/tmp"), str_dup("/tmp"), false,
false, false, false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
cfg->send_directory = str_dup("/tmp");
cfg->receive_root_directory = str_dup("/tmp");
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
@@ -80,9 +81,10 @@ static void test_sendfile_empty_file() {
EXPECT_NOT_NULL(file);
file->data->size = 0;
Config* cfg = config_create(str_dup(PROTOCOL_VERSION), str_dup("/tmp"), str_dup("/tmp"), false,
false, false, false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
cfg->send_directory = str_dup("/tmp");
cfg->receive_root_directory = str_dup("/tmp");
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
@@ -91,6 +93,7 @@ static void test_sendfile_empty_file() {
pid_t pid = fork();
if (pid == 0) {
/* Child: receive */
close(p[1]);
File* received = file_receive(cfg, p[0]);
close(p[0]);
@@ -161,9 +164,12 @@ static void test_sendfile_compression_fallback() {
file->data->size = (size_t)st.st_size;
EXPECT_TRUE(file_load_data(file));
Config* cfg = config_create(str_dup(PROTOCOL_VERSION), str_dup("/tmp"), str_dup("/tmp"), false,
false, false, true, false, 3, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
cfg->send_directory = str_dup("/tmp");
cfg->receive_root_directory = str_dup("/tmp");
cfg->use_compression = true;
cfg->compression_level = 3;
int p[2];
EXPECT_EQ_INT(pipe(p), 0);
@@ -172,6 +178,7 @@ static void test_sendfile_compression_fallback() {
pid_t pid = fork();
if (pid == 0) {
/* Child: receive */
close(p[1]);
File* received = file_receive(cfg, p[0]);
close(p[0]);
+27 -10
View File
@@ -8,9 +8,12 @@
/* Test pipeline_context_sender_create/destroy with valid arguments */
static void test_sender_create_destroy() {
Config* cfg = config_create(str_dup("1.0"), str_dup("/src"), str_dup("/dst"), false, false, false,
false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("1.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
Queue* q_scanner = queue_create(5, NULL);
EXPECT_NOT_NULL(q_scanner);
@@ -32,9 +35,14 @@ static void test_sender_create_destroy() {
/* Test pipeline_context_receiver_create/destroy with valid arguments */
static void test_receiver_create_destroy() {
Config* cfg = config_create(str_dup("2.0"), str_dup("/src"), str_dup("/dst"), true, true, false,
false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("2.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
cfg->save_to_disk = true;
cfg->use_multithreading = true;
Queue* q = queue_create(20, NULL);
EXPECT_NOT_NULL(q);
@@ -51,9 +59,12 @@ static void test_receiver_create_destroy() {
/* Test that create handles various queue capacities */
static void test_sender_queue_capacities() {
Config* cfg = config_create(str_dup("3.0"), str_dup("/src"), str_dup("/dst"), false, false, false,
false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("3.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
/* Single-element queues */
Queue* q1 = queue_create(1, NULL);
@@ -67,9 +78,12 @@ static void test_sender_queue_capacities() {
/* Test that create handles zero-capacity queues */
static void test_sender_zero_capacity() {
Config* cfg = config_create(str_dup("4.0"), str_dup("/src"), str_dup("/dst"), false, false, false,
false, false, 0, false, 0);
Config* cfg = config_create();
EXPECT_NOT_NULL(cfg);
free(cfg->version);
cfg->version = str_dup("4.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
Queue* q1 = queue_create(0, NULL);
Queue* q2 = queue_create(0, NULL);
@@ -82,8 +96,11 @@ static void test_sender_zero_capacity() {
/* Test receiver with zero file_descriptor */
static void test_receiver_fd_zero() {
Config* cfg = config_create(str_dup("5.0"), str_dup("/src"), str_dup("/dst"), false, false, false,
false, false, 0, false, 0);
Config* cfg = config_create();
free(cfg->version);
cfg->version = str_dup("5.0");
cfg->send_directory = str_dup("/src");
cfg->receive_root_directory = str_dup("/dst");
Queue* q = queue_create(5, NULL);
PipelineContextReceiver* ctx = pipeline_context_receiver_create(cfg, q, 0);
EXPECT_NOT_NULL(ctx);