Address code review: fix setter exposure and narrow catch blocks

1. network.rpc.use_xmlrpc and network.rpc.use_jsonrpc: change from
   CMD2_VAR_BOOL_U (getter+setter both safe) to CMD2_VAR_BOOL_U_GET
   (getter safe, setter trusted-only). Untrusted callers could
   previously disable RPC transports entirely.

2. Remove broad catch(std::exception&) and catch(...) from xmlrpc_c.cc
   that masked real defects and altered fault semantics.

3. Revert SCGI callback catch-all to re-throw instead of swallowing
   exceptions with a generic error response.
This commit is contained in:
Xirvik
2026-03-01 19:25:08 +00:00
committed by Jari Sundell
parent ea16276773
commit ba239bc8c5
3 changed files with 3 additions and 22 deletions
+2 -2
View File
@@ -248,8 +248,8 @@ initialize_command_network() {
CMD2_ANY_U ("network.xmlrpc.size_limit", [](const auto&, const auto&) { return rpc::rpc.size_limit(); });
CMD2_ANY_VALUE_V_U ("network.xmlrpc.size_limit.set", [](const auto&, const auto& arg) { return rpc::rpc.set_size_limit(arg); });
CMD2_VAR_BOOL_U ("network.rpc.use_xmlrpc", true);
CMD2_VAR_BOOL_U ("network.rpc.use_jsonrpc", true);
CMD2_VAR_BOOL_U_GET("network.rpc.use_xmlrpc", true);
CMD2_VAR_BOOL_U_GET("network.rpc.use_jsonrpc", true);
CMD2_ANY ("network.block.ipv4", [nw_config](auto, auto) { return nw_config->is_block_ipv4(); });
CMD2_ANY_VALUE_V ("network.block.ipv4.set", [nw_config](auto, auto& value) { return nw_config->set_block_ipv4(value); });
+1 -12
View File
@@ -3,7 +3,6 @@
#include "rpc/scgi_task.h"
#include <cstdio>
#include <cstring>
#include <unistd.h>
#include <vector>
#include <sys/types.h>
@@ -316,17 +315,7 @@ SCgiTask::receive_call(const char* buffer, uint32_t length) {
});
} catch (...) {
rpc::RpcManager::set_trusted(true);
// Send a generic error response instead of re-throwing, as the
// callback infrastructure may not support exception propagation.
const char* err_xml = "<?xml version=\"1.0\"?><methodResponse><fault><value><struct>"
"<member><name>faultCode</name><value><i8>-500</i8></value></member>"
"<member><name>faultString</name><value><string>Internal error</string></value></member>"
"</struct></value></fault></methodResponse>";
const char* err_json = "{\"jsonrpc\":\"2.0\",\"error\":{\"code\":-32603,\"message\":\"Internal error\"},\"id\":null}";
const char* err = (rpc_type == RpcManager::RPCType::JSON) ? err_json : err_xml;
result_callback(err, std::strlen(err));
return;
throw;
}
rpc::RpcManager::set_trusted(true);
-8
View File
@@ -396,14 +396,6 @@ xmlrpc_call_command(xmlrpc_env* env, xmlrpc_value* args, void* voidServerInfo) {
} catch (torrent::local_error& e) {
xmlrpc_env_set_fault(env, XMLRPC_PARSE_ERROR, e.what());
return NULL;
} catch (std::exception& e) {
xmlrpc_env_set_fault(env, XMLRPC_PARSE_ERROR, e.what());
return NULL;
} catch (...) {
xmlrpc_env_set_fault(env, XMLRPC_PARSE_ERROR, "Unknown exception in command execution.");
return NULL;
}
}