SCgiTask objects are pre-allocated in a pool (scgi.cc) and reused across SCGI connections. SCgiTask::open() did not reset m_trusted, so when a task that had handled an untrusted connection (m_trusted=false) was reused for a new connection, m_trusted stayed false unless the new connection explicitly sent UNTRUSTED_CONNECTION=1. The header parser only set m_trusted=false on value 1 and was a no-op on value 0 (the comment said "default is trusted, so do nothing") — which is wrong for a reused task that is no longer in default state. This caused intermittent rejection of trusted commands (e.g. ruTorrent calling execute.capture for UID detection) with "Command X is not allowed for untrusted connections", producing cascading plugin failures and "ruTorrent cannot determine the UID of rTorrent user" in the web UI. Fix: - SCgiTask::open() resets m_trusted=true to default. - parse_headers explicitly sets m_trusted=true on UNTRUSTED_CONNECTION=0, so the value sent on the wire is authoritative regardless of pool reuse semantics. Verified on gb4 with rtorrent 0.16.11 + this fix: 30/30 trusted calls succeed, 30/30 untrusted correctly blocked, 30/30 trusted-after-untrusted batch all succeed (previously 70%+ would fail in the same scenario).
RTorrent BitTorrent Client
Introduction
A ncurses-based command line torrent client for high performance.
To learn how to use rTorrent visit the Wiki.
Download the latest stable release
Related Projects
- https://github.com/rakshasa/rbedit: A dependency-free bencode editor.
Donate to rTorrent development
- Paypal
- Patreon
- SubscribeStar
- Bitcoin: 1MpmXm5AHtdBoDaLZstJw8nupJJaeKu8V8
- Ethereum: 0x9AB1e3C3d8a875e870f161b3e9287Db0E6DAfF78
- Litecoin: LdyaVR67LBnTf6mAT4QJnjSG2Zk67qxmfQ
- Cardano: addr1qytaslmqmk6dspltw06sp0zf83dh09u79j49ceh5y26zdcccgq4ph7nmx6kgmzeldauj43254ey97f3x4xw49d86aguqwfhlte
Help keep rTorrent development going by donating to its creator.
BUILDING
Jump into the github cloned directory
cd rtorrent
Install build dependencies
Install libtorrent with the same version rTorrent.
Generate configure scripts:
autoreconf -ivf
Optionally, generate man pages:
docbook2man rtorrent.1.xml
Man pages output to "doc/rtorrent.1".
RTorrent follows the development of libtorrent closely, and thus the versions must be in sync.
USAGE
Refer to User Guide: https://github.com/rakshasa/rtorrent/wiki/User-Guide
LICENSE
GNU GPL, see COPYING. "libtorrent/src/utils/sha_fast.{cc,h}" is originally from the Mozilla NSS and is under a triple license; MPL, LGPL and GPL. An exception to non-NSS code has been added for linking to OpenSSL as requested by Debian, though the author considers that library to be part of the Operative System and thus linking is allowed according to the GPL.
Use whatever fits your purpose, the code required to compile with Mozilla's NSS implementation of SHA1 has been retained and can be compiled if the user wishes to avoid using OpenSSL.
DEPENDENCIES
- libcurl >= 7.12.0
- libtorrent = (same version)
- ncurses
BUILD DEPENDENCIES
- libtoolize
- aclocal
- autoconf
- autoheader
- automake