| Age | Commit message (Collapse) | Author |
|
The FileStore interface returned concrete *os.File from Open/Create/
OpenFile, which no non-filesystem backend (e.g. S3/R2) can produce, and
many file-library hot paths bypassed the interface entirely with direct
os.* / filepath.Walk calls.
Widen the interface to return io.ReadCloser / io.WriteCloser and add
ReadDir, ReadLink, and Walk so directory traversal no longer escapes the
abstraction. Route every file-library call site (fork writers, upload/
download handlers, GetFileNameList, CalcTotalSize/CalcItemCount, the set-
file-info folder rename) through the injected FileStore, and add a
WithFileStore option. OSFileStore keeps byte-identical behavior.
DownloadHandler now nil-guards the optional resource-fork reader instead
of relying on *os.File's nil-receiver tolerance, so a backend returning an
untyped-nil reader does not panic.
|
|
Anchor the path returned by folderUpload.FormattedPath relative to the
upload root so item paths are resolved consistently, matching the
behavior of ReadPath. Resolve each destination path once per item in
UploadFolderHandler and use path.Join in place of manual string
concatenation.
Add test coverage for FormattedPath normalization.
|
|
Startup log:
- Add interface, port, and fileTransferPort fields to the "Hotline
server started" line so operators can see what the server bound to.
- Resolve an empty -interface flag to 0.0.0.0 for display.
Levels:
- Demote the two Redis startup messages (ban management, cleared online
users) from Info to Debug.
Consistency:
- Standardize the error field key to "err" (was "Err" in a few account
handlers) and lowercase "Account" -> "account".
- Standardize the remote-address key to "remoteAddr" (was "RemoteAddr").
- Replace fmt.Sprintf in the tracker-registration message and string
concatenation in the config-dir-init and ban-disconnect messages with
structured fields; use the standard "err" key.
- Give the two bare rLogger.Error(err.Error()) file-transfer calls a
descriptive message and an "err" field.
logger.go:
- Only attach the rotating lumberjack file writer when --log-file is set.
An empty Filename made lumberjack write to a temp file by default.
|
|
A malicious or buggy client could send transaction fields with the wrong
length and trigger runtime panics (slice/index out of range, slice-to-array
conversion, nil deref) in the parsing and handler code. These were caught by
the connection-level recover, so they dropped the client connection and dumped
a stack trace to stdout rather than crashing the process, but they are still
incorrect behavior, a log-flood vector, and a latent crash if the recover
scope ever changes.
Fix at the source and harden the safety net:
- Add ClientIDFromBytes / ChatIDFromBytes helpers that return ok=false on a
length mismatch, and use them in the transaction handlers instead of direct
[2]byte(...) / [4]byte(...) conversions on field data. Nil-check ClientMgr.Get
results, and length-guard FieldOptions and the HandleUpdateUser sub-field
header. Malformed input now yields an error reply (or a clean no-op for
reply-less handlers) instead of panicking.
- Bounds-check FileResumeData.UnmarshalBinary (header length and fork count)
and guard the ForkInfoList[0] accesses against an empty list.
- Bounds-check FlatFileInformationFork parsing (reachable on upload): validate
the fixed header, name, and comment lengths, and fix a latent 72+nameSize
uint16 overflow. Route Write through UnmarshalBinary.
- panic.go: stop printing stack traces to stdout (keep structured logging) so a
client cannot flood stdout by repeatedly triggering a panic.
- handleTransaction: recover per-transaction so one malformed request no longer
tears down the whole client connection.
Adds tests for the new helpers, the hardened resume-data and flat-file-object
decoders, and handler-level malformed-ID handling.
|
|
13 types implemented identical offset-based io.Reader patterns with
5-7 lines of copy-and-offset-tracking code each. Extract a shared
readFrom(p, offset, data) helper and reduce each Read() method to a
one-liner delegating to it.
|
|
|
|
- Replace [4]byte with ForkType in ForkInfoList struct
- Update constants ForkTypeDATA and ForkTypeMACR to use ForkType
- Add String() method to ForkType for better debugging
- Improve consistency with existing type patterns (FieldType, TranType)
- Clean up unused code and improve documentation
|
|
- Replace manual byte slicing with bufio.Scanner for safer parsing
- Add pathSegmentScanner implementing bufio.SplitFunc pattern
- Add comprehensive table tests covering edge cases and special characters
- Improve code safety with proper bounds checking
- Follow established codebase patterns for binary data parsing
|
|
Replace all instances of filepath.Join with path.Join across the codebase
to improve Windows compatibility following the guidance from
https://github.com/golang/go/issues/44305.
Key changes:
- Replaced filepath.Join with path.Join in 14 files
- Updated import statements appropriately
- Resolved variable shadowing issues where function parameters
named 'path' were conflicting with the path package
- Maintained filepath imports where needed for OS-specific functions
like filepath.Walk, filepath.IsAbs, filepath.Dir, and filepath.Base
All tests pass, confirming the changes maintain functionality while
improving cross-platform compatibility.
|
|
This seems to be important on Windows! See #161
|
|
|
|
|
|
|
|
|
|
|
|
* Added ability to reload config, agreement, news, and user accounts without restarting the server by sending SIGHUP to the running process
* Added ability to use modern unix or windows line breaks in Agreement.txt and MessageBoard.txt instead of classic MacOS `\r` breaks.
* Extensive refactor towards swappable backends for the active server state
* Extensive refactored towards making the hotline package generic and re-usable for alternate server implemenations
* Fix bug where users whose accounts have been deleted would not be disconnected
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|