All checks were successful
CI Code / Check spelling (push) Successful in 21s
CI Code / Check coding style (push) Successful in 31s
CI Code / Code Coverage (push) Successful in 2m21s
CI Code / Linux (ubuntu) (push) Successful in 4m30s
CI Code / Linux (debian) (push) Successful in 6m43s
CI Code / Linux (arch) (push) Successful in 10m8s
A flat-file alternative to the SQLite chatlog backend with runtime
switching, full migration tooling, integrity verification, and a
synthetic load harness. SQLite remains the default; both backends share
one dispatch layer (db_backend_t vtable) so callers don't change.
Storage layout
- Per-contact append-only `flatlog/<account>/<contact>/history.log`
under XDG_DATA_HOME, one line per message
- Single-line file header with embedded format-version marker
(FLATFILE_FORMAT_VERSION); reader warns on missing or mismatched
marker, writer and checker stay in sync via preprocessor
stringification
- Deterministic key=value metadata (`id`, `aid`, `corrects`, `to`,
`to_res`, `read`) plus escaped body \u2014 `\|`, `\]`, `\\`, `\n`, `\r`
literals prevent log injection
- Sparse byte-offset index (FF_INDEX_STEP=500) per contact for
O(log n) time-range lookups; rebuilt on inode / size / mtime
change, extended in-place when the file just grew
- Per-contact GHashTable caches for archive_id presence and
stanza_id \u2192 from_jid mapping (O(1) MAM dedup, O(1) LMC sender
validation)
Hardening
- Path-traversal protection: JID directory name normalisation
(`@` \u2192 `_at_`, slashes and `..` rejected at construction); every
per-contact path is anchored under the account's flatlog/
directory and validated before open
- Symlink-attack protection: every fopen / open uses O_NOFOLLOW; on
ELOOP the operation aborts with an error rather than following
- Filesystem permissions: log files created with mode 0600,
directories with mode 0700; both enforced at creation, verified
on each open and reported on drift by `/history verify`
- Atomic crash-safe export: write to a temp file via mkstemp (mode
0600, random suffix, no name collisions between concurrent
exports), fsync, then rename \u2014 partial state never replaces the
live file
- Concurrency: advisory flock(LOCK_EX) held for the duration of
every write, including append from live messages and full rewrite
from export, so two profanity processes can't interleave bytes
on the same log
- DoS / abuse guards:
* FF_MAX_LINE_LEN = 10 MB \u2014 lines longer than this are rejected
at read with a warning; the parser will not allocate
unbounded memory for a single record
* FF_MAX_LMC_DEPTH = 100 \u2014 `corrects:` chain walk stops at this
depth and emits a warning, preventing a malicious correction
cycle from spinning the apply pass
* FF_VERSION_SCAN_MAX = 16 \u2014 header version probe never reads
past 16 leading comment lines, even on garbage input
* Empty / inverted byte-range early-return in page-up read path
so a malformed time filter cannot cause an unbounded scan
* Zero-entry index guard so a file whose every line failed to
parse cannot cause a NULL deref on later page-up
- LMC sender validation: an incoming correction whose sender does
not match the original message's sender is rejected at write
time and surfaced via cons_show_error; a cycle in the apply pass
is broken via a visited-set
- jid_create_from_bare_and_resource treats NULL, empty string, and
the literal "(null)" as no resource and returns a bare jid;
similar normalisation for barejid eliminates the legacy
"user@host/(null)" artefact that leaked into stored fulljids
whenever g_strdup_printf("%s", NULL) ran inside create_fulljid
Commands
- `/history switch sqlite|flatfile` \u2014 runtime backend swap, closes
the old backend and opens the new one without reconnecting
- `/history export [<jid>]` \u2014 SQLite -> flat-file, merging with any
existing flatlog (dedup keyed on a SHA-256 hash mixing stanza_id,
timestamp, from_jid, body \u2014 robust against id reuse by older
clients)
- `/history import [<jid>]` \u2014 flat-file -> SQLite, same merge
semantics, runs inside a single SQLite transaction with rollback
on per-contact failure
- `/history verify [<jid>]` \u2014 integrity check; emits a structured
list of issues (ERROR / WARNING / INFO) per file:
* file-level: missing log, wrong permissions (\u2260 0600), UTF-8
BOM present, CRLF line endings, empty file
* line-level: invalid UTF-8 (with byte offset), embedded
control characters, unparsable lines, timestamps out of
order, duplicate `id:` and `aid:` (tracked separately so a
stanza/archive id collision isn't double-reported)
* cross-line: broken `corrects:` references whose target id is
not present in the file
- `/history backend` \u2014 show currently active backend
- Active backend indicator `[sqlite]` / `[flatfile]` in the status
bar next to the JID
- Roster-JID autocomplete for verify / export / import
- export and import open a SQLite handle on demand when the
flatfile backend is currently active, so migration works
regardless of which backend is live
Tests
- Unit: database_export (parser round-trip, escape/unescape, dedup
key stability, JID normalisation), database_stress (14 cases
exercising rapid writes, large messages, deep LMC chains, MAM
dedup, concurrent contacts)
- Functional: history persistence across reconnects, export /
import round-trip with content equality, MUC migration,
timestamp normalisation across timezones
- Bench harness P1\u2013P5 (synthetic load: bulk insert, time-range
read, page-up scroll, MAM ingest, mixed workload) and failure
modes F1\u2013F17 (page-up cursor and forward-iteration symmetry,
oversized lines, MAM dedup, LMC depth and cycles, BOM/CRLF,
missing log, empty file, mtime+inode flip, broken corrects, etc.)
- All bench tests integrate with the existing make targets and
emit CSV rows for baseline comparison
Author: jabber.developer2 <jabber.developer2@jabber.space>
Reviewed-by: jabber.developer <jabber.developer@jabber.space>
223 lines
5.7 KiB
C
223 lines
5.7 KiB
C
/*
|
|
* jid.c
|
|
* vim: expandtab:ts=4:sts=4:sw=4
|
|
*
|
|
* Copyright (C) 2012 - 2019 James Booth <boothj5@gmail.com>
|
|
*
|
|
* This file is part of Profanity.
|
|
*
|
|
* Profanity is free software: you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* Profanity is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License
|
|
* along with Profanity. If not, see <https://www.gnu.org/licenses/>.
|
|
*
|
|
* In addition, as a special exception, the copyright holders give permission to
|
|
* link the code of portions of this program with the OpenSSL library under
|
|
* certain conditions as described in each individual source file, and
|
|
* distribute linked combinations including the two.
|
|
*
|
|
* You must obey the GNU General Public License in all respects for all of the
|
|
* code used other than OpenSSL. If you modify file(s) with this exception, you
|
|
* may extend this exception to your version of the file(s), but you are not
|
|
* obligated to do so. If you do not wish to do so, delete this exception
|
|
* statement from your version. If you delete this exception statement from all
|
|
* source files in the program, then also delete it here.
|
|
*
|
|
*/
|
|
|
|
#include "config.h"
|
|
|
|
#include <stdlib.h>
|
|
#include <string.h>
|
|
|
|
#include <glib.h>
|
|
|
|
#include "common.h"
|
|
#include "xmpp/jid.h"
|
|
|
|
Jid*
|
|
jid_create(const gchar* const str)
|
|
{
|
|
Jid* result = NULL;
|
|
|
|
/* if str is NULL g_strdup returns NULL */
|
|
gchar* trimmed = g_strdup(str);
|
|
if (trimmed == NULL) {
|
|
return NULL;
|
|
}
|
|
|
|
if (strlen(trimmed) == 0) {
|
|
g_free(trimmed);
|
|
return NULL;
|
|
}
|
|
|
|
if (g_str_has_prefix(trimmed, "/") || g_str_has_prefix(trimmed, "@")) {
|
|
g_free(trimmed);
|
|
return NULL;
|
|
}
|
|
|
|
if (!g_utf8_validate(trimmed, -1, NULL)) {
|
|
g_free(trimmed);
|
|
return NULL;
|
|
}
|
|
|
|
result = malloc(sizeof(struct jid_t));
|
|
result->str = NULL;
|
|
result->localpart = NULL;
|
|
result->domainpart = NULL;
|
|
result->resourcepart = NULL;
|
|
result->barejid = NULL;
|
|
result->fulljid = NULL;
|
|
result->refcnt = 1;
|
|
|
|
gchar* atp = g_utf8_strchr(trimmed, -1, '@');
|
|
gchar* slashp = g_utf8_strchr(trimmed, -1, '/');
|
|
gchar* domain_start = trimmed;
|
|
|
|
if (atp) {
|
|
result->localpart = g_utf8_substring(trimmed, 0, g_utf8_pointer_to_offset(trimmed, atp));
|
|
domain_start = atp + 1;
|
|
}
|
|
|
|
if (slashp) {
|
|
result->resourcepart = g_strdup(slashp + 1);
|
|
result->domainpart = g_utf8_substring(domain_start, 0, g_utf8_pointer_to_offset(domain_start, slashp));
|
|
auto_gchar gchar* barejidraw = g_utf8_substring(trimmed, 0, g_utf8_pointer_to_offset(trimmed, slashp));
|
|
result->barejid = g_utf8_strdown(barejidraw, -1);
|
|
result->fulljid = g_strdup(trimmed);
|
|
} else {
|
|
result->domainpart = g_strdup(domain_start);
|
|
result->barejid = g_utf8_strdown(trimmed, -1);
|
|
}
|
|
|
|
if (result->domainpart == NULL) {
|
|
jid_destroy(result);
|
|
return NULL;
|
|
}
|
|
|
|
result->str = trimmed;
|
|
|
|
return result;
|
|
}
|
|
|
|
Jid*
|
|
jid_create_from_bare_and_resource(const char* const barejid, const char* const resource)
|
|
{
|
|
// NULL, empty, or the literal "(null)" (legacy artefact from earlier
|
|
// builds where g_strdup_printf("%s", NULL) leaked the glibc placeholder
|
|
// into stored data) all mean "no value" for either part. With no usable
|
|
// bare jid there is nothing to construct; with no usable resource we
|
|
// return the bare jid alone.
|
|
if (!barejid || !*barejid || g_strcmp0(barejid, "(null)") == 0) {
|
|
return NULL;
|
|
}
|
|
if (!resource || !*resource || g_strcmp0(resource, "(null)") == 0) {
|
|
return jid_create(barejid);
|
|
}
|
|
auto_char char* jid = create_fulljid(barejid, resource);
|
|
return jid_create(jid);
|
|
}
|
|
|
|
void
|
|
jid_auto_destroy(Jid** jid)
|
|
{
|
|
if (jid == NULL)
|
|
return;
|
|
jid_destroy(*jid);
|
|
}
|
|
|
|
void
|
|
jid_ref(Jid* jid)
|
|
{
|
|
jid->refcnt++;
|
|
}
|
|
|
|
void
|
|
jid_destroy(Jid* jid)
|
|
{
|
|
if (jid == NULL) {
|
|
return;
|
|
}
|
|
if (jid->refcnt > 1) {
|
|
jid->refcnt--;
|
|
return;
|
|
}
|
|
|
|
g_free(jid->str);
|
|
g_free(jid->localpart);
|
|
g_free(jid->domainpart);
|
|
g_free(jid->resourcepart);
|
|
g_free(jid->barejid);
|
|
g_free(jid->fulljid);
|
|
free(jid);
|
|
}
|
|
|
|
gboolean
|
|
jid_is_valid_room_form(Jid* jid)
|
|
{
|
|
return (jid->fulljid != NULL);
|
|
}
|
|
|
|
/*
|
|
* Given a barejid, and resourcepart, create and return a full JID of the form
|
|
* barejid/resourcepart
|
|
* Will return a newly created string that must be freed by the caller
|
|
*/
|
|
char*
|
|
create_fulljid(const char* const barejid, const char* const resource)
|
|
{
|
|
auto_gchar gchar* barejidlower = g_utf8_strdown(barejid, -1);
|
|
return g_strdup_printf("%s/%s", barejidlower, resource);
|
|
}
|
|
|
|
/*
|
|
* Get the nickname part of the full JID, e.g.
|
|
* Full JID = "test@conference.server/person"
|
|
* returns "person"
|
|
*/
|
|
char*
|
|
get_nick_from_full_jid(const char* const full_room_jid)
|
|
{
|
|
auto_gcharv gchar** tokens = g_strsplit(full_room_jid, "/", 0);
|
|
char* nick_part = NULL;
|
|
|
|
if (tokens) {
|
|
if (tokens[0] && tokens[1]) {
|
|
nick_part = strdup(tokens[1]);
|
|
}
|
|
}
|
|
|
|
return nick_part;
|
|
}
|
|
|
|
/*
|
|
* get the fulljid, fall back to the barejid
|
|
*/
|
|
const char*
|
|
jid_fulljid_or_barejid(Jid* jid)
|
|
{
|
|
if (jid->fulljid) {
|
|
return jid->fulljid;
|
|
} else {
|
|
return jid->barejid;
|
|
}
|
|
}
|
|
|
|
gchar*
|
|
jid_random_resource(void)
|
|
{
|
|
auto_char char* rand = get_random_string(4);
|
|
|
|
gchar* result = g_strdup_printf("profanity.%s", rand);
|
|
|
|
return result;
|
|
}
|