Compare commits

..

24 Commits

Author SHA1 Message Date
rakshasa 8e5fb72867 Reverted parse value to strtoll with restrictions on input. 2026-09-30 11:57:12 +02:00
Silas Mariusz 880d381839 Mark the system.file.allocate getter untrusted-safe, because d.open reads it. 2026-09-30 10:58:35 +02:00
noctuum b9782c71f5 Do not switch an active download to initial_seed
`confirm_finished` did, and the `input_error` reached `main`.
2026-09-30 10:58:35 +02:00
noctuum 2688f27f0a Check m_entry against size() in set_entry 2026-09-30 10:58:35 +02:00
noctuum 24ce818aaf Read the unpacked object in the raw string case
A list holding one raw string reached this case and threw on `src`.
2026-09-30 10:58:35 +02:00
noctuum 12f3d6fe8f Remove code that has no remaining user
Three declarations had no definition and the rest had no user left.
2026-09-30 10:58:35 +02:00
noctuum 101ce5924c Reset the freed pointers in XmlRpc::cleanup
`is_valid()` tests `m_env`, so it stayed true after `cleanup()`.
2026-09-30 10:58:35 +02:00
noctuum 4bf094b6de Check first against last in parse_object
A command ending in `=` reaches it with an empty range.
2026-09-30 10:58:35 +02:00
noctuum a84743b008 Sort the transfer chunks by index
The default comparison ordered the pointers, not the chunk indexes.
2026-09-30 10:58:35 +02:00
noctuum eebfb5f5e5 Check pthread_sigmask by its return value
`pthread_sigmask` returns the error number and does not set `errno`.
2026-09-30 10:58:35 +02:00
noctuum 991ebdabe0 Reject an empty argument list in execute_lua
`lua.execute` with no arguments dereferenced `args.begin()`.
2026-09-30 10:58:35 +02:00
noctuum 2aaf1cbfd1 Limit tab completion to text before the cursor
`substr` takes a count, so the text after the cursor joined the prefix.
2026-09-30 10:58:32 +02:00
noctuum b5b37a2e07 Guard control in the main catch handlers
A start without HOME throws before control is constructed.
2026-09-30 10:58:20 +02:00
noctuum 4831a44879 Stop at max_active in scheduler.simple.removed
The limit was checked once, then every download was resumed.
2026-09-30 10:58:20 +02:00
xirvik 14c8d2b470 Sync the session directory after committing the renames
Syncing the files alone does not make the new names survive a crash.
2026-09-30 10:58:18 +02:00
Jari Sundell 15756ddadc Reorder mutex and atomic variable declarations 2026-09-30 10:57:28 +02:00
xirvik e0c0d96aba Give SessionManager::m_active its own cache line
Prevents false sharing with the adjacent m_mutex under concurrent access.
2026-09-30 10:57:28 +02:00
xirvik 7fbe54d4dd Make SessionManager::m_active atomic
It is written under m_mutex but read under m_pending_builds_mutex in one place.
2026-09-30 10:57:28 +02:00
xirvik 41209bc14d Guard the download against handlers that erase it mid-close
Track a weak_ptr lifetime handle and make erase ignore re-entrant erase.
2026-09-30 10:57:28 +02:00
xirvik 47eb1432b6 Write session files with O_NOFOLLOW and mode 0600
Also make directory_entry::is_file() report the real type so symlinks are skipped.
2026-09-30 10:57:26 +02:00
xirvik d16263701a rpc: multicall requires methodName as the struct's first member
Faults clearly instead of the confusing positional parse error it replaces.
2026-09-30 10:57:09 +02:00
xirvik d3f4d18164 Bound JSON-RPC input by size and nesting depth
Enforce the nesting bound in one parse, capping allocation by depth, not input size.
2026-09-30 10:57:09 +02:00
xirvik 6c6d2b9333 Range-check global throttle rates before narrowing them to kB.
Multiplying kB back to bytes in unsigned int wrapped 2^32 to 0, which means unlimited.
2026-09-30 10:56:59 +02:00
xirvik f79cb257d7 Reject out-of-range RPC values instead of narrowing them silently.
Guards choke group max, set-port and info-hash length; parsing now uses std::from_chars.
2026-09-23 15:29:37 +00:00
4 changed files with 12 additions and 28 deletions
+2 -5
View File
@@ -1,7 +1,5 @@
#include "config.h" #include "config.h"
#include <memory>
#include "rpc/exec_file.h" #include "rpc/exec_file.h"
// #include <cassert> // #include <cassert>
@@ -83,9 +81,8 @@ ExecFile::execute_object(const torrent::Object& rawArgs, int flags) {
char* argsBuffer[max_args]; char* argsBuffer[max_args];
char** argsCurrent = argsBuffer; char** argsCurrent = argsBuffer;
// On the heap: a buffer of buffer_size does not belong on the stack of whichever thread runs the command. // Size of value strings are less than 24.
auto valueStorage = std::make_unique<char[]>(buffer_size + 1); char valueBuffer[buffer_size+1];
char* valueBuffer = valueStorage.get();
char* valueCurrent = valueBuffer; char* valueCurrent = valueBuffer;
if (rawArgs.is_list()) { if (rawArgs.is_list()) {
+1 -1
View File
@@ -10,7 +10,7 @@ namespace rpc {
class ExecFile { class ExecFile {
public: public:
static constexpr unsigned int max_args = 128; static constexpr unsigned int max_args = 128;
static constexpr unsigned int buffer_size = 128 * 1024; static constexpr unsigned int buffer_size = 4096;
static constexpr int flag_expand_tilde = 0x1; static constexpr int flag_expand_tilde = 0x1;
static constexpr int flag_throw = 0x2; static constexpr int flag_throw = 0x2;
+9 -14
View File
@@ -118,32 +118,27 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
if (base != 0 && base != 8 && base != 10 && base != 16) if (base != 0 && base != 8 && base != 10 && base != 16)
throw torrent::input_error("Command::string_to_value_unit(...) received invalid base."); throw torrent::input_error("Command::string_to_value_unit(...) received invalid base.");
const char* first = src;
while (parse_is_space(*src)) while (parse_is_space(*src))
src++; src++;
if (src[0] == '+') if (src[0] == '+')
return first; return src;
if (src[0] == '-') { if (src[0] == '-') {
if (base == 8 || base == 16) if (base == 8 || base == 16)
return first; return src;
if (src[1] == '0') if (src[1] == '0')
return first; return src;
} }
if (base == 10 && src[0] == '0' && (src[1] >= '0' && src[1] <= '9'))
return first;
char* last{}; char* last{};
errno = 0; errno = 0;
*value = strtoll(src, &last, base); *value = strtoll(src, &last, base);
if (errno == ERANGE) if (errno == ERANGE)
return first; return src;
if (last == src) { if (last == src) {
*value = 0; *value = 0;
@@ -153,7 +148,7 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
if (strcasecmp(src, "true") == 0) { *value = 1; return src + strlen("true"); } if (strcasecmp(src, "true") == 0) { *value = 1; return src + strlen("true"); }
if (strcasecmp(src, "false") == 0) { *value = 0; return src + strlen("false"); } if (strcasecmp(src, "false") == 0) { *value = 0; return src + strlen("false"); }
return first; return src;
} }
switch (*last) { switch (*last) {
@@ -161,15 +156,15 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
case 'B': ++last; break; case 'B': ++last; break;
case 'k': case 'k':
case 'K': case 'K':
if (!value_fits_shifted(*value, 10)) return first; // overflow guard if (!value_fits_shifted(*value, 10)) return src; // overflow guard
*value = *value << 10; ++last; break; *value = *value << 10; ++last; break;
case 'm': case 'm':
case 'M': case 'M':
if (!value_fits_shifted(*value, 20)) return first; // overflow guard if (!value_fits_shifted(*value, 20)) return src; // overflow guard
*value = *value << 20; ++last; break; *value = *value << 20; ++last; break;
case 'g': case 'g':
case 'G': case 'G':
if (!value_fits_shifted(*value, 30)) return first; // overflow guard if (!value_fits_shifted(*value, 30)) return src; // overflow guard
*value = *value << 30; ++last; break; *value = *value << 30; ++last; break;
// case ' ': // case ' ':
// case '\0': *value = *value * unit; break; // case '\0': *value = *value * unit; break;
@@ -177,7 +172,7 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
default: default:
if (*value > std::numeric_limits<int64_t>::max() / unit || if (*value > std::numeric_limits<int64_t>::max() / unit ||
*value < std::numeric_limits<int64_t>::min() / unit) *value < std::numeric_limits<int64_t>::min() / unit)
return first; // overflow guard return src; // overflow guard
*value = *value * unit; *value = *value * unit;
break; break;
-8
View File
@@ -71,18 +71,10 @@ rtorrent_Test_Src_SOURCES = $(rtorrent_Test_Common) \
src/test_command_path.h \ src/test_command_path.h \
src/test_command_string.cc \ src/test_command_string.cc \
src/test_command_string.h \ src/test_command_string.h \
src/test_command_throttle.cc \
src/test_command_throttle.h \
src/test_command_tracker.cc \ src/test_command_tracker.cc \
src/test_command_tracker.h \ src/test_command_tracker.h \
src/test_download_list.cc \ src/test_download_list.cc \
src/test_download_list.h \ src/test_download_list.h \
src/test_input_path_input.cc \
src/test_input_path_input.h \
src/test_session_commit.cc \
src/test_session_commit.h \
src/test_session_storer.cc \
src/test_session_storer.h \
src/test_setup.cc \ src/test_setup.cc \
src/test_setup.h \ src/test_setup.h \
src/test_ui_download_list.cc \ src/test_ui_download_list.cc \