aboutsummaryrefslogtreecommitdiff
path: root/hotline/access.go
diff options
context:
space:
mode:
authorJeff Halter <868228+jhalter@users.noreply.github.com>2026-05-29 08:22:49 -0700
committerJeff Halter <868228+jhalter@users.noreply.github.com>2026-05-29 08:22:49 -0700
commit21cf5016d98ff568692e91751d021facbdfc6bb6 (patch)
treef9a9ccfac5dd9252226aef84495f5aeb1cb7383f /hotline/access.go
parentb772019454ebb804c313e717ae98eb68430e780e (diff)
Guard against panics from unchecked type assertions
Replace two unchecked type assertions that could crash the server: - server.go: the file-transfer logger built remoteAddr via a bare ctx.Value(contextKeyReq).(requestCtx) assertion, which panics if the context value is absent or the wrong type. Use the comma-ok form and degrade to an empty string. - access.go: the legacy (< v0.17.0) AccessBitmap YAML array path used byte(v.(int)) with no element-type or bounds check, panicking on a non-int element or an array longer than the [8]byte bitmap. Iterate the slice from the type switch, bounds-check the index, and comma-ok each element, returning a wrapped error so a malformed user file fails to load loudly instead of crashing the server. Add regression tests for the non-int and oversized legacy array cases.
Diffstat (limited to 'hotline/access.go')
-rw-r--r--hotline/access.go11
1 files changed, 9 insertions, 2 deletions
diff --git a/hotline/access.go b/hotline/access.go
index 370f8c2..927e0a9 100644
--- a/hotline/access.go
+++ b/hotline/access.go
@@ -67,8 +67,15 @@ func (bits *AccessBitmap) UnmarshalYAML(unmarshal func(interface{}) error) error
// Mobius versions < v0.17.0 store the user access bitmap as an array of int values like:
// [96, 112, 12, 32, 3, 128, 0, 0]
// This case supports reading of user config files using this format.
- for i, v := range flags.([]interface{}) {
- bits[i] = byte(v.(int))
+ for i, elem := range v {
+ if i >= len(bits) {
+ return fmt.Errorf("unmarshal access bitmap: too many elements (%d, max %d)", len(v), len(bits))
+ }
+ n, ok := elem.(int)
+ if !ok {
+ return fmt.Errorf("unmarshal access bitmap: element %d is %T, want int", i, elem)
+ }
+ bits[i] = byte(n)
}
case map[string]interface{}:
// Mobius versions >= v0.17.0 store the user access bitmap as map[string]bool to provide a human-readable view of