Xirvik
f767053297
Mark safe commands with flag_untrusted_safe for whitelist enforcement
...
Annotate all commands that web UIs (ruTorrent) need for normal torrent
management with _U macro variants, which set flag_untrusted_safe.
Commands not marked are blocked by default for untrusted connections.
Safe commands include:
- d.* download getters, state, priorities, custom fields, start/stop
- f.* file getters, priority control
- p.* peer getters, disconnect, ban/snub
- t.* tracker getters, enable/disable
- throttle.* rate getters/setters, peer limits
- network.* read-only queries (getters safe, setters blocked)
- view.list, view.size, view.filter_all, ui.current_view
- load.*, download_list, d.multicall2, d.multicall.filtered
- convert.*, branch/if/and/or/not/cat/value/print
- system.* version/time/status queries (read-only)
- choke_group.* read-only queries
- method.has_key, method.const, method.list_keys, method.get, strings.*
- group.*.view, group.*.ratio.min/max/upload (dynamic, via flag propagation)
Blocked by default (not marked):
- execute*, method.insert/set/redirect, schedule*, import
- log.*, file.append, network.scgi.open_*, view.filter/sort/event_*
- system.shutdown, system.env, group.insert, choke_group.insert
- All user-defined commands (via method.insert)
2026-03-23 15:11:07 +01:00
Xirvik
598914908f
Add untrusted connection security infrastructure (v3)
...
Replace the v2 blacklist approach with a per-command flag system.
Commands must opt in to being available for untrusted connections
via flag_untrusted_safe (0x400), checked in call_command() which
catches all execution paths including nested commands.
Infrastructure changes:
- Add flag_untrusted_safe to CommandMap
- Add untrusted_error exception type for proper error codes
- Enforce trust check in both call_command() overloads
- Add catch blocks in xmlrpc_c, xmlrpc_tinyxml2, and jsonrpc handlers
- Port SCGI trust state management from v2 (thread_local, header parsing)
- Add _U macro variants in command_helpers.h for safe command registration
- Add CMD2_VAR_*_U and CMD2_VAR_*_U_GET variants for variables
2026-03-23 15:11:07 +01:00
rakshasa
38fc815d52
Fix display/UI crash and correctness bugs (@sirus20x6)
2026-03-16 16:08:52 +01:00
Jari Sundell
674ae767aa
Validate parsed int pair arguments for positivity
2026-03-16 13:56:43 +01:00
sirus20x6
0aaa470053
Fix resource leaks and minor issues
...
- Close pipe fds on fork failure in ExecFile::execute
- Add exception-safe fclose in cmd_file_append via try/catch
- Add overflow guards before K/M/G bit shifts in parse_whole_value
- Fix %u format for int* in sscanf (change to %d)
- Fix typo "atter"→"after" in error message
2026-03-16 13:56:43 +01:00
PiloUnk
6f27159627
Refactor full save scheduling with early return
2026-03-16 13:29:33 +01:00
PiloUnk
de163293ab
Avoid missing save scheduling after full save update
2026-03-16 13:29:33 +01:00
PiloUnk
fb4e775689
Fix coalescing resume saves with pending full save
2026-03-16 13:29:33 +01:00
rakshasa
39f186e523
Tagged release 0.16.8.
v0.16.8
2026-03-15 15:43:32 +01:00
Jari Sundell
70e6964823
Fixed various SCGI issues.
2026-03-10 23:25:28 +09:00
rakshasa
7ead88448b
Removed rak/error_number.h from Makefile.am.
v0.16.7
2026-03-04 11:39:25 +01:00
rakshasa
650f0299b5
Tagged release 0.16.7.
2026-03-04 10:47:30 +01:00
rakshasa
5dfb2ae938
Allow dht bootstrap nodes to be added when dht is off.
2026-03-02 09:45:09 +01:00
Jorge Israel Peña
f05a2ae520
Re-send smkx on SIGWINCH to fix arrow keys after terminal reattach
2026-02-19 16:06:42 +01:00
Miroslav Marchev
ecefdba734
dht_add_peer_node is empty, use dht_add_bootstrap_node instead
...
After a refactor dht_add_peer_node became empty function. Replace with dht_add_bootstrap_node to make adding bootstrap nodes work.
2026-02-14 14:32:48 +01:00
Jari Sundell
87666199b3
Added SocketManager to handle reuse of uninterested fd's by the kernel.
2026-01-29 04:00:31 +09:00
Jari Sundell
9489793dcb
Created torrent/runtime include directory.
2026-01-27 08:21:05 +09:00
Jari Sundell
2fa7568165
Remove obsolete SocketFd class.
2026-01-26 19:13:03 +09:00
fffe
f4b718f685
add separate commands for unbuffered logs
2026-01-16 16:10:02 +01:00
Jari Sundell
b233e24465
Deprecated rak::path_expand.
2026-01-08 23:27:53 +09:00
Jari Sundell
289ab046bf
Expand '~/' to $HOME in session path.
2026-01-06 20:44:40 +09:00
Jari Sundell
a8b6a47054
Removed deprecated rak errno and file headers.
2026-01-04 03:22:02 +09:00
Zoltan Celedes
110591d5c1
Fix key/value pairs in Lua
...
Previously, the keys and values were swapped in d.custom.items()
2026-01-03 12:20:08 +01:00
rakshasa
ae14baa357
Tagged release 0.16.6.
v0.16.6
2026-01-02 15:22:29 +01:00
rakshasa
0b0c824b4b
Changed magnet metadata handling and added 'magnet.path.set'.
2025-12-31 21:57:52 +01:00
Jari Sundell
def6551488
Properly propagate errors from download session save.
2025-12-30 22:00:34 +09:00
Jari Sundell
787738e36a
Make sure pending builds of session resume get processed.
2025-12-29 09:55:32 +09:00
Jari Sundell
40c2d90c45
Fixed dereferencing of potentially nullptr in SessionManager.
2025-12-25 23:05:08 +09:00
Jari Sundell
4a37fbde0b
Session saving of resume data is added to a pre-queue.
2025-12-23 03:04:47 +09:00
Jari Sundell
4bdeb58eb6
Run multiple session save requests in parallel.
2025-12-22 06:26:35 +09:00
Jari Sundell
5dbb0020dc
Replace ThreadWorker with scgi::ThreadScgi.
2025-12-18 07:43:43 +09:00
Jari Sundell
8f644e65dd
Use separate thread for saving session data.
2025-12-18 06:42:44 +09:00
Jari Sundell
16ff32b88c
Added missing Event::type_name() functions.
2025-12-13 19:06:02 +09:00
Jari Sundell
8806c06f9f
Added timestamp helper commands.
2025-12-10 22:29:42 +09:00
rakshasa
60cfcd37c4
Release 0.16.5.
v0.16.5
2025-12-02 17:51:26 +01:00
rakshasa
a526ba58e9
Release 0.16.4.
v0.16.4
2025-11-25 10:48:11 +01:00
rakshasa
efd9507149
Release 0.16.3.
v0.16.3
2025-11-21 14:39:27 +01:00
Jari Sundell
3d91dfdb33
Valgrind suppressions file for macos.
2025-11-20 15:57:30 +09:00
Jari Sundell
30cec98799
Moved Poll to net namespace.
2025-11-20 03:05:16 +09:00
rakshasa
b825906034
Store copies of command names added to xmlrpc-c.
2025-11-17 20:30:13 +01:00
rakshasa
b05ecb5c5a
Push back views explicitly takes a string.
2025-11-17 09:36:32 +01:00
Jari Sundell
900be334dc
Cleaned up xmlrpc-c string sanitization.
2025-11-17 02:48:32 +09:00
rakshasa
3a1da2fe34
Check if AF_INET6 is supported, or block IPv6 traffic.
2025-11-15 09:17:56 +01:00
Jari Sundell
70750a2bd3
Cleanup of DHT controller.
2025-11-13 00:01:22 +09:00
Jari Sundell
1d2c424a70
Remove throttle from DHT.
2025-11-08 17:51:00 +09:00
rakshasa
8550facf43
Tagged release 0.16.2.
v0.16.2
2025-11-04 15:20:20 +01:00
rakshasa
184ead294a
Export 'group2.*' commands.
2025-11-01 14:35:32 +01:00
Jari Sundell
84bfc491ba
Added dual listening ports when both IPv4 and IPv6 are bound.
2025-11-01 07:24:31 +09:00
Khem Raj
a2e0eca6e3
scripts/common.m4: Insert spaces in shell lists
...
$1=$(echo "$result" | tr -d '\n')
removes all newlines without inserting spaces
That usually isn’t what we want for shell lists.
It should typically be space-separated output.
Fixes a bug seen with yocto where compiler is not a single word
but a string e.g.
ccache aarch64-yoe-linux-musl-clang++ -mcpu=cortex-a72+crc+nocrypto --dyld-prefix=/usr -fstack-protector-strong -O2 -D_FORTIFY_SOURCE=2 -Wformat -Wformat-security -Werror=format-security --sysroot=/mnt/b/yoe/master/build/tmp/work/cortexa72-yoe-linux-musl/libtorrent/0.16.1/recipe-sysroot
It changes it to
ccacheaarch64-yoe-linux-musl-clang++-mcpu=cortex-a72+crc+nocrypto--dyld-prefix=/usr-fstack-protector-strong-O2-D_FORTIFY_SOURCE=2-Wformat-Wformat-security-Werror=format-security--sysroot=/mnt/b/yoe/master/build/tmp/work/cortexa72-yoe-linux-musl/libtorrent/0.16.1/recipe-sysroot
When doing c++17 checks on compiler, resulting in failure
Upstream-Status: Submitted [https://github.com/rakshasa/libtorrent/pull/583 ]
Signed-off-by: Khem Raj <raj.khem@gmail.com >
2025-10-25 11:30:56 +02:00
rakshasa
92eecdfd52
Updated log group documentation.
2025-10-24 15:38:01 +02:00