Files
cproof/src/xmpp/avatar.c
Jabber Developer 72f4f186da
All checks were successful
CI Code / Check spelling (push) Successful in 18s
CI Code / Check coding style (push) Successful in 34s
CI Code / Code Coverage (push) Successful in 2m36s
CI Code / Linux (debian) (push) Successful in 4m41s
CI Code / Linux (ubuntu) (push) Successful in 4m52s
CI Code / Linux (arch) (push) Successful in 5m40s
merge: sync upstream profanity-im/profanity
Sync with upstream profanity-im/profanity.

Major upstream changes incorporated:

Memory management
  - Replace malloc+memset with g_new0 throughout codebase
  - Adopt auto_gchar / auto_gcharv / auto_gerror / auto_jid cleanup macros
  - Replace free() with g_free() for GAlloc'd memory

Editor rewrite
  - Remove pthread-based async editor; use GChildWatch callback API
  - New launch_editor(initial_content, callback, user_data) interface
  - Proper signal handling (SIGINT, SIGTSTP, SIGPIPE reset in child)
  - ui_suspend()/ui_resume() integration for TTY management

OMEMO improvements
  - Dual backend support: libsignal-protocol-c and libomemo-c
  - Proper pre-key removal after use (XEP-0384 compliance)
  - Automatic pre-key regeneration when store drops below threshold
  - New functions: omemo_is_device_active(), omemo_is_jid_trusted()
  - omemo_get_jid_untrusted_fingerprints() for better error messages
  - Fingerprint notifications on new device identity discovery
  - Deterministic pre-key ID generation tracking max_pre_key_id
  - omemo_trust_changed() UI updates on trust state changes

JID validation
  - RFC 6122-compliant validation in jid_is_valid()
  - Character-level checks (RFC 6122 forbidden chars: & ' / : < > @)
  - Length limits: 1023 per component, 3071 total
  - New jid_is_valid_user_jid() for user vs. service JID distinction

Database
  - Schema migration v3: UNIQUE constraint on archive_id for deduplication
  - Triggers for corrected message tracking (replaces_db_id / replaced_by_db_id)
  - db_history_result_t return type, _truncate_datetime_suffix()

UI / console
  - win_warn_needed() / win_warn_sent() warning deduplication hash table
  - PAD_MIN_HEIGHT dynamic pad sizing with PAD_THRESHOLD auto-cleanup
  - Spellcheck integration in input field with Unicode word detection
  - cons_spellcheck_setting() for /settings ui output
  - /[command]? shortcut for command help

Account config
  - Account name sanitization for GKeyFile special chars ([ ] = # \n \r)
  - Replace popen() with g_spawn_sync() for eval_password
  - TLS policy: add "direct" option alongside legacy

Connection
  - Port validation with g_assert (0–65535)
  - SHA-256 certificate fingerprint support (XMPP_CERT_PUBKEY_FINGERPRINT_SHA256)
  - "direct" TLS policy alias for legacy SSL

Common utilities
  - str_xml_sanitize() for XML 1.0 illegal character removal
  - string_matches_one_of() with formatted error messages
  - valid_tls_policy_option() helper
  - prof_date_time_format_iso8601() utility
  - Improved strip_arg_quotes() with backslash unescaping
  - prof_occurrences() uses g_slist_prepend + reverse for performance

PGP / OX
  - Proper GPGME resource cleanup with goto-cleanup pattern
  - g_string_free(xmppuri) leak fix in _ox_key_lookup

CSV export
  - Use GString + g_file_set_contents instead of raw write() syscalls

Tests
  - Restructured into subdirectories: command/, config/, xmpp/, ui/, omemo/, otr/, pgp/
  - New test_cmd_ac.c for autocompleter unit tests
  - Updated stubs for new UI suspend/resume functions

License headers
  - Migrate to SPDX-3.0 identifiers (GPL-3.0-or-later WITH OpenSSL-exception)

────────────────────────────────────────────────────
cproof-specific preservations:

  - XEP-0308 LMC: replace_id ?: id logic in message/stanza/omemo
  - Force encryption: cmd_force_encryption, test_forced_encryption
  - CWE-134: format string protection (cons_show("%s", ...))
  - y_start_pos-based paging in window.c
  - db_history_result_t return type, _truncate_datetime_suffix()

Merge-time fixes:

  - common.c: format-security (-Werror) — cons_show(errmsg) → cons_show("%s", errmsg)
  - database.c: null-deref guard — !msg->timestamp → msg && !msg->timestamp
  - console.c: implicit size_t → int cast — (int)(maxlen + 1)
  - tlscerts.c: %d for size_t — %zu

Build system:
  - Kept autotools (Makefile.am, configure.ac); upstream uses Meson
  - Restored deleted files: bootstrap.sh, autogen.sh, ax_valgrind_check.m4, configure-debug
  - Updated Makefile.am test paths for subdirectory structure
  - Added test_cmd_ac, test_forced_encryption to test sources

Functional tests:
  - Use cproof version; upstream requires stbbr_for_xmlns from updated stabber
  - Not yet available in devs/stabber fork

Closes #64

Merge author: jabber.developer2
Commits authors:
 Michael Vetter <jubalh@iodoru.org>
& Steffen Jaeckel <s@jaeckel.eu>
2026-05-26 17:48:14 +00:00

348 lines
10 KiB
C

/*
* avatar.c
* vim: expandtab:ts=4:sts=4:sw=4
*
* Copyright (C) 2019 - 2026 Michael Vetter <jubalh@iodoru.org>
*
* SPDX-License-Identifier: GPL-3.0-or-later WITH OpenSSL-exception
*/
#include "config.h"
#include <glib.h>
#ifdef HAVE_PIXBUF
#include <gdk-pixbuf-2.0/gdk-pixbuf/gdk-pixbuf.h>
#endif
#include <string.h>
#include <stdio.h>
#include <stdlib.h>
#include <errno.h>
#include <sys/stat.h>
#include "log.h"
#include "xmpp/connection.h"
#include "xmpp/iq.h"
#include "xmpp/message.h"
#include "xmpp/stanza.h"
#include "ui/ui.h"
#include "config/files.h"
#include "config/preferences.h"
typedef struct avatar_metadata
{
char* type;
char* id;
} avatar_metadata;
static GHashTable* looking_for = NULL; // contains nicks/barejids from who we want to get the avatar
static GHashTable* shall_open = NULL; // contains a list of nicks that shall not just downloaded but also opened
const int MAX_PIXEL = 192; // max pixel width/height for an avatar
static void _avatar_request_item_by_id(const char* jid, avatar_metadata* data);
static int _avatar_metadata_handler(xmpp_stanza_t* const stanza, void* const userdata);
static int _avatar_request_item_result_handler(xmpp_stanza_t* const stanza, void* const userdata);
static void
_free_avatar_data(avatar_metadata* data)
{
if (data) {
free(data->type);
free(data);
}
}
static void
_avatar_cleanup(void)
{
if (looking_for) {
g_hash_table_destroy(looking_for);
}
if (shall_open) {
g_hash_table_destroy(shall_open);
}
looking_for = NULL;
shall_open = NULL;
}
void
avatar_pep_subscribe(void)
{
prof_add_shutdown_routine(_avatar_cleanup);
message_pubsub_event_handler_add(STANZA_NS_USER_AVATAR_METADATA, _avatar_metadata_handler, NULL, NULL);
message_pubsub_event_handler_add(STANZA_NS_USER_AVATAR_DATA, _avatar_metadata_handler, NULL, NULL);
// caps_add_feature(XMPP_FEATURE_USER_AVATAR_METADATA_NOTIFY);
_avatar_cleanup();
looking_for = g_hash_table_new_full(g_str_hash, g_str_equal, g_free, NULL);
shall_open = g_hash_table_new_full(g_str_hash, g_str_equal, g_free, NULL);
}
#ifdef HAVE_PIXBUF
gboolean
avatar_set(const char* path)
{
auto_char char* expanded_path = get_expanded_path(path);
auto_gerror GError* err = NULL;
GdkPixbuf* pixbuf = gdk_pixbuf_new_from_file(expanded_path, &err);
if (pixbuf == NULL) {
cons_show_error("An error occurred while opening %s: %s.", expanded_path, PROF_GERROR_MESSAGE(err));
return FALSE;
}
// Scale img
int w = gdk_pixbuf_get_width(pixbuf);
int h = gdk_pixbuf_get_height(pixbuf);
if (w >= h && w > MAX_PIXEL) {
int dest_height = (int)((float)MAX_PIXEL / (float)w * (float)h);
GdkPixbuf* new_pixbuf = gdk_pixbuf_scale_simple(pixbuf, MAX_PIXEL, dest_height, GDK_INTERP_BILINEAR);
g_object_unref(pixbuf);
pixbuf = new_pixbuf;
} else if (h > w && w > MAX_PIXEL) {
int dest_width = (int)((float)MAX_PIXEL / (float)h * (float)w);
GdkPixbuf* new_pixbuf = gdk_pixbuf_scale_simple(pixbuf, dest_width, MAX_PIXEL, GDK_INTERP_BILINEAR);
g_object_unref(pixbuf);
pixbuf = new_pixbuf;
}
auto_gchar gchar* img_data = NULL;
gsize len = -1;
if (!gdk_pixbuf_save_to_buffer(pixbuf, &img_data, &len, "png", &err, NULL)) {
cons_show_error("Unable to scale and convert avatar: %s.", PROF_GERROR_MESSAGE(err));
return FALSE;
}
xmpp_ctx_t* const ctx = connection_get_ctx();
xmpp_stanza_t* iq = stanza_create_avatar_data_publish_iq(ctx, img_data, len);
iq_send_stanza(iq);
xmpp_stanza_release(iq);
iq = stanza_create_avatar_metadata_publish_iq(ctx, img_data, len, gdk_pixbuf_get_height(pixbuf), gdk_pixbuf_get_width(pixbuf));
g_object_unref(pixbuf);
iq_send_stanza(iq);
xmpp_stanza_release(iq);
return TRUE;
}
#endif
gboolean
avatar_publishing_disable()
{
xmpp_ctx_t* const ctx = connection_get_ctx();
xmpp_stanza_t* iq = stanza_disable_avatar_publish_iq(ctx);
iq_send_stanza(iq);
xmpp_stanza_release(iq);
return TRUE;
}
gboolean
avatar_get_by_nick(const char* nick, gboolean open)
{
// in case we set the feature, remove it
caps_remove_feature(XMPP_FEATURE_USER_AVATAR_METADATA_NOTIFY);
// save nick in list so we look for this one
g_hash_table_insert(looking_for, strdup(nick), NULL);
// add the feature. this will trigger the _avatar_metadata_notfication_handler handler
caps_add_feature(XMPP_FEATURE_USER_AVATAR_METADATA_NOTIFY);
if (open) {
g_hash_table_insert(shall_open, strdup(nick), NULL);
}
return TRUE;
}
static int
_avatar_metadata_handler(xmpp_stanza_t* const stanza, void* const userdata)
{
const char* from = xmpp_stanza_get_attribute(stanza, STANZA_ATTR_FROM);
if (!from) {
return 1;
}
if (!g_hash_table_contains(looking_for, from)) {
return 1;
}
xmpp_stanza_t* root = NULL;
xmpp_stanza_t* event = xmpp_stanza_get_child_by_ns(stanza, STANZA_NS_PUBSUB_EVENT);
if (event) {
root = event;
}
xmpp_stanza_t* pubsub = xmpp_stanza_get_child_by_ns(stanza, STANZA_NS_PUBSUB);
if (pubsub) {
root = pubsub;
}
if (!root) {
return 1;
}
xmpp_stanza_t* items = xmpp_stanza_get_child_by_name(root, "items");
if (!items) {
return 1;
}
xmpp_stanza_t* item = xmpp_stanza_get_child_by_name(items, "item");
if (item) {
xmpp_stanza_t* metadata = xmpp_stanza_get_child_by_name(item, "metadata");
if (metadata) {
xmpp_stanza_t* info = xmpp_stanza_get_child_by_name(metadata, "info");
if (info) {
const char* id = xmpp_stanza_get_id(info);
const char* type = xmpp_stanza_get_attribute(info, "type");
if (id && type) {
log_debug("Avatar ID for %s is: %s", from, id);
avatar_metadata* data = g_new0(avatar_metadata, 1);
if (data) {
data->type = strdup(type);
data->id = strdup(id);
// request the actual (image) data
_avatar_request_item_by_id(from, data);
}
}
} else {
cons_show("We couldn't get the user's avatar, possibly because they haven't set one or have disabled avatar publishing. "
"During this Profanity session, you will receive future changes to this user's avatar.");
}
}
}
return 1;
}
static void
_avatar_request_item_by_id(const char* jid, avatar_metadata* data)
{
caps_remove_feature(XMPP_FEATURE_USER_AVATAR_METADATA_NOTIFY);
xmpp_ctx_t* const ctx = connection_get_ctx();
auto_char char* uid = connection_create_stanza_id();
xmpp_stanza_t* iq = stanza_create_avatar_retrieve_data_request(ctx, uid, data->id, jid);
iq_id_handler_add(uid, _avatar_request_item_result_handler, (ProfIqFreeCallback)_free_avatar_data, data);
iq_send_stanza(iq);
xmpp_stanza_release(iq);
}
static int
_avatar_request_item_result_handler(xmpp_stanza_t* const stanza, void* const userdata)
{
const char* from_attr = xmpp_stanza_get_attribute(stanza, STANZA_ATTR_FROM);
if (!from_attr) {
return 1;
}
if (!g_hash_table_contains(looking_for, from_attr)) {
return 1;
}
g_hash_table_remove(looking_for, from_attr);
xmpp_stanza_t* pubsub = xmpp_stanza_get_child_by_ns(stanza, STANZA_NS_PUBSUB);
if (!pubsub) {
return 1;
}
xmpp_stanza_t* items = xmpp_stanza_get_child_by_name(pubsub, "items");
if (!items) {
return 1;
}
xmpp_stanza_t* item = xmpp_stanza_get_child_by_name(items, "item");
if (!item) {
return 1;
}
xmpp_stanza_t* st_data = xmpp_stanza_get_child_by_name_and_ns(item, "data", STANZA_NS_USER_AVATAR_DATA);
if (!st_data) {
return 1;
}
auto_char char* buf = xmpp_stanza_get_text(st_data);
if (!buf) {
return 1;
}
gsize size;
auto_gchar gchar* de = (gchar*)g_base64_decode(buf, &size);
auto_gchar gchar* path = files_get_data_path("");
GString* filename = g_string_new(path);
g_string_append(filename, "avatars/");
errno = 0;
int res = g_mkdir_with_parents(filename->str, S_IRWXU);
if (res == -1) {
const char* errmsg = strerror(errno);
if (errmsg) {
log_error("Avatar: error creating directory: %s, %s", filename->str, errmsg);
} else {
log_error("Avatar: creating directory: %s", filename->str);
}
}
auto_char char* from = str_replace(from_attr, "@", "_at_");
g_string_append(filename, from);
avatar_metadata* data = (avatar_metadata*)userdata;
// check a few image types ourselves
// if none matches we won't add an extension but linux will
// be able to open it anyways
// TODO: we could use /etc/mime-types
if (g_strcmp0(data->type, "image/png") == 0) {
g_string_append(filename, ".png");
} else if (g_strcmp0(data->type, "image/jpeg") == 0) {
g_string_append(filename, ".jpeg");
} else if (g_strcmp0(data->type, "image/webp") == 0) {
g_string_append(filename, ".webp");
}
auto_gerror GError* err = NULL;
if (g_file_set_contents(filename->str, de, size, &err) == FALSE) {
log_error("Unable to save picture: %s", err->message);
cons_show("Unable to save picture %s", err->message);
} else {
cons_show("Avatar saved as %s", filename->str);
}
// if we shall open it
if (g_hash_table_contains(shall_open, from_attr)) {
auto_gchar gchar* cmdtemplate = prefs_get_string(PREF_AVATAR_CMD);
if (cmdtemplate == NULL) {
cons_show_error("No default `avatar open` command found in executables preferences.");
} else {
auto_gcharv gchar** argv = format_call_external_argv(cmdtemplate, NULL, filename->str);
if (!call_external(argv)) {
cons_show_error("Unable to display avatar: check the logs for more information.");
}
}
g_hash_table_remove(shall_open, from_attr);
}
g_string_free(filename, TRUE);
return 1;
}