mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
ulfius: client_address carries the whole peer sockaddr; forgectrl.auth asserts the loopback report is accepted
The dual-stack listener reports every peer as a sockaddr_in6; ulfius 2.7.15 copied sixteen bytes of it, so forgectrl's loopback-only cooling channel refused the controller's every report (403 loopback only) and the engine never saw a run or an armed window. The recipe carries the patch: a sockaddr_storage allocation and a copy of the family's length, in the dispatcher and in ulfius_copy_request. forgetest: forgectrl.auth asserts POST /cool/state from loopback -> 200 beside the LAN 403, and covers src/peer.*. BRINGUP item 21 and the campaign log record how the campaign on dev 20260824215906 found it.
This commit is contained in:
+65
@@ -0,0 +1,65 @@
|
||||
The client address carries the whole peer sockaddr
|
||||
|
||||
The request's client_address was allocated and copied as
|
||||
sizeof(struct sockaddr), 16 bytes. A dual-stack listener reports every
|
||||
peer as a sockaddr_in6 (28 bytes), so the address bytes a consumer needs
|
||||
to recognize ::1 or a v4-mapped ::ffff:127.0.0.1 lay beyond the copy.
|
||||
Allocate a sockaddr_storage and copy the length the family calls for,
|
||||
here and in ulfius_copy_request().
|
||||
|
||||
Upstream-Status: Pending
|
||||
Signed-off-by: Scott Wiederhold <s.e.wiederhold@gmail.com>
|
||||
|
||||
--- a/src/ulfius.c
|
||||
+++ b/src/ulfius.c
|
||||
@@ -30,6 +30,7 @@
|
||||
#endif
|
||||
|
||||
#include <ctype.h>
|
||||
+#include <netinet/in.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
@@ -515,12 +516,15 @@
|
||||
con_info->max_post_param_size = ((struct _u_instance *)cls)->max_post_param_size;
|
||||
con_info->request->http_protocol = o_strdup(version);
|
||||
con_info->request->http_verb = o_strdup(method);
|
||||
- con_info->request->client_address = o_malloc(sizeof(struct sockaddr));
|
||||
+ con_info->request->client_address = o_malloc(sizeof(struct sockaddr_storage));
|
||||
if (con_info->request->client_address == NULL || con_info->request->http_verb == NULL) {
|
||||
y_log_message(Y_LOG_LEVEL_ERROR, "Ulfius - Error allocating client_address or http_verb");
|
||||
return MHD_NO;
|
||||
}
|
||||
- memcpy(con_info->request->client_address, so_client, sizeof(struct sockaddr));
|
||||
+ memset(con_info->request->client_address, 0, sizeof(struct sockaddr_storage));
|
||||
+ memcpy(con_info->request->client_address, so_client,
|
||||
+ so_client->sa_family == AF_INET6 ? sizeof(struct sockaddr_in6) :
|
||||
+ so_client->sa_family == AF_INET ? sizeof(struct sockaddr_in) : sizeof(struct sockaddr));
|
||||
if (con_info->u_instance->check_utf8) {
|
||||
MHD_get_connection_values (connection, MHD_HEADER_KIND, ulfius_fill_map_check_utf8, con_info->request->map_header);
|
||||
MHD_get_connection_values (connection, MHD_GET_ARGUMENT_KIND, ulfius_fill_map_check_utf8, &con_info->map_url_initial);
|
||||
--- a/src/u_request.c
|
||||
+++ b/src/u_request.c
|
||||
@@ -24,6 +24,7 @@
|
||||
*/
|
||||
#include <ctype.h>
|
||||
+#include <netinet/in.h>
|
||||
#include <stdarg.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <u_private.h>
|
||||
@@ -400,9 +401,12 @@
|
||||
dest->callback_position = source->callback_position;
|
||||
|
||||
if (source->client_address != NULL) {
|
||||
- dest->client_address = o_malloc(sizeof(struct sockaddr));
|
||||
+ dest->client_address = o_malloc(sizeof(struct sockaddr_storage));
|
||||
if (dest->client_address != NULL) {
|
||||
- memcpy(dest->client_address, source->client_address, sizeof(struct sockaddr));
|
||||
+ memset(dest->client_address, 0, sizeof(struct sockaddr_storage));
|
||||
+ memcpy(dest->client_address, source->client_address,
|
||||
+ source->client_address->sa_family == AF_INET6 ? sizeof(struct sockaddr_in6) :
|
||||
+ source->client_address->sa_family == AF_INET ? sizeof(struct sockaddr_in) : sizeof(struct sockaddr));
|
||||
} else {
|
||||
y_log_message(Y_LOG_LEVEL_ERROR, "Ulfius - Error allocating resources for dest->client_address");
|
||||
ret = U_ERROR_MEMORY;
|
||||
@@ -12,6 +12,12 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=40d2542b8c43a3ec2b7f5da31a697b88"
|
||||
SRC_URI = "git://github.com/babelouest/ulfius;protocol=https;branch=master"
|
||||
SRCREV = "a0603447d3ed63c0880db396b9c395fb4bf6b559"
|
||||
|
||||
# The request's client_address is the whole peer sockaddr. Upstream copies
|
||||
# sizeof(struct sockaddr), 16 bytes, which truncates the sockaddr_in6 a
|
||||
# dual-stack listener reports for every peer; forgectrl's loopback-only
|
||||
# report channel reads the mapped address bytes that lie beyond it.
|
||||
SRC_URI += "file://0001-client_address-carries-the-whole-peer-sockaddr.patch"
|
||||
|
||||
S = "${WORKDIR}/git"
|
||||
|
||||
inherit cmake pkgconfig
|
||||
|
||||
Reference in New Issue
Block a user