- mark network.local_port.ipv4/ipv6 safe for untrusted RPC connections (mark_safe matches exact command keys).
- Replace duplicated multi-line port validation with a shared checked_local_port_value helper and single-line lambdas.
Mirror the network.local_address.* command family for ports:
- network.local_port report the best-match local port
- network.local_port.set set both the ipv4 and ipv6 local ports
- network.local_port.ipv4(.set) get/set the ipv4 local port only
- network.local_port.ipv6(.set) get/set the ipv6 local port only
Values are restricted to 0-65535; 0 (default) means unset, and trackers
then report the listening port.
Why: behind multiple layers of NAT the port peers must connect to can
differ from the port rtorrent is listening on. These commands let the
user manually advertise the forwarded public port per address family,
e.g.:
network.local_port.ipv4.set = 6881
network.local_port.ipv6.set = 6882
network.local_port is marked safe for RPC use alongside
network.local_address.
ruTorrent queries these commands for its settings and status pages.
They are all read-only getters with no side effects, safe to expose
for untrusted SCGI connections.
Tested against ruTorrent with both httprpc and multirpc plugins on
servers with active torrents — all modes (list, settings, totals,
open connections) work with zero blocked commands.
1. network.rpc.use_xmlrpc and network.rpc.use_jsonrpc: change from
CMD2_VAR_BOOL_U (getter+setter both safe) to CMD2_VAR_BOOL_U_GET
(getter safe, setter trusted-only). Untrusted callers could
previously disable RPC transports entirely.
2. Remove broad catch(std::exception&) and catch(...) from xmlrpc_c.cc
that masked real defects and altered fault semantics.
3. Revert SCGI callback catch-all to re-throw instead of swallowing
exceptions with a generic error response.
Root cause: network.rpc.use_xmlrpc and network.rpc.use_jsonrpc were not
marked as untrusted-safe, but RpcManager::process() calls them before
dispatching to the protocol handler. When an untrusted request arrived,
call_command() threw untrusted_error for these gatekeepers, which escaped
the callback_interrupt_pollling callback and crashed rtorrent.
Fix: Mark network.rpc.use_xmlrpc/jsonrpc as safe (CMD2_VAR_BOOL_U).
Also harden exception safety:
- SCGI callback catch-all now sends a generic error response instead of
re-throwing, since the callback infrastructure may not support
exception propagation.
- xmlrpc_c.cc now has catch(std::exception&) and catch(...) safety nets
after the specific exception handlers.