diff options
| author | Jeff Halter <868228+jhalter@users.noreply.github.com> | 2026-05-29 08:22:49 -0700 |
|---|---|---|
| committer | Jeff Halter <868228+jhalter@users.noreply.github.com> | 2026-05-29 08:22:49 -0700 |
| commit | 21cf5016d98ff568692e91751d021facbdfc6bb6 (patch) | |
| tree | f9a9ccfac5dd9252226aef84495f5aeb1cb7383f /hotline/server.go | |
| parent | b772019454ebb804c313e717ae98eb68430e780e (diff) | |
Guard against panics from unchecked type assertions
Replace two unchecked type assertions that could crash the server:
- server.go: the file-transfer logger built remoteAddr via a bare
ctx.Value(contextKeyReq).(requestCtx) assertion, which panics if the
context value is absent or the wrong type. Use the comma-ok form and
degrade to an empty string.
- access.go: the legacy (< v0.17.0) AccessBitmap YAML array path used
byte(v.(int)) with no element-type or bounds check, panicking on a
non-int element or an array longer than the [8]byte bitmap. Iterate the
slice from the type switch, bounds-check the index, and comma-ok each
element, returning a wrapped error so a malformed user file fails to
load loudly instead of crashing the server.
Add regression tests for the non-int and oversized legacy array cases.
Diffstat (limited to 'hotline/server.go')
| -rw-r--r-- | hotline/server.go | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/hotline/server.go b/hotline/server.go index d757062..7bc6a4a 100644 --- a/hotline/server.go +++ b/hotline/server.go @@ -690,8 +690,12 @@ func (s *Server) handleFileTransfer(ctx context.Context, rwc io.ReadWriter) erro time.Sleep(3 * time.Second) }() + var remoteAddr string + if rc, ok := ctx.Value(contextKeyReq).(requestCtx); ok { + remoteAddr = rc.remoteAddr + } rLogger := s.Logger.With( - "remoteAddr", ctx.Value(contextKeyReq).(requestCtx).remoteAddr, + "remoteAddr", remoteAddr, "login", fileTransfer.ClientConn.Account.Login, "Name", string(fileTransfer.ClientConn.UserName), ) |