Commit Graph

9 Commits

Author SHA1 Message Date
Levi Neely 358ae595e9
Add memory accounting per subsystem (#371)
* Implement memory accounting infrastructure

* Migrate malloc/calloc to pmem_malloc with subsystem tracking

* Add overflow-safe pmem_malloc_array function

* Migrate pfstasks.c malloc/free to pmem_malloc/pmem_free

* Migrate pnetlibs.c malloc/free to pmem_malloc/pmem_free

* Fix multiplication patterns in pnetlibs.c with pmem_malloc_array

* Migrate ppagecache.c malloc/free to pmem_malloc/pmem_free

* Fix remaining multiplication pattern in ppagecache.c line 3239

* Migrate pssl.c malloc/free to pmem_malloc/pmem_free

* Migrate pcryptofolder.c malloc/free to pmem_malloc/pmem_free

* Migrate pfolder.c malloc/free to pmem_malloc/pmem_free

* Fix multiplication patterns in pfolder.c with overflow checks

* Migrate publiclinks.c malloc/free to pmem_malloc/pmem_free

* Migrate plocalscan.c malloc/free to pmem_malloc/pmem_free

* Migrate psql.c malloc/free to pmem_malloc/pmem_free

* Migrate putil.c malloc/free to pmem_malloc/pmem_free

* Fix multiplication patterns in putil.c encoding functions with overflow checks

* Migrate pfsupload.c malloc/free to pmem_malloc/pmem_free

* Migrate pdiff.c malloc/free to pmem_malloc/pmem_free

* Migrate pcrypto.c malloc/free to pmem_malloc/pmem_free

* Migrate pupload.c malloc/free to pmem_malloc/pmem_free

* Migrate psock.c malloc/free to pmem_malloc/pmem_free

* Fix multiplication pattern in psock.c with overflow checks

* Add panic() with backtrace to psignal module

* Register panic handlers early in main()

* Fix panic() infinite recursion by unregistering handlers before abort()

* Migrate remaining 34 files to pmem_malloc/pmem_free

* Migrate papi.c, ptools.c, pbusinessaccount.c to PMEM_SUBSYS_API

* Fix pcache.c compilation errors - replace he->pmem_free with pmem_free

* Add pmem.h include to pdbg.c

* Add pmem.h include to 10 files missing it

* Fix ptask.c compilation errors - replace s->pmem_free with s->free

* Fix ptask.c callback arguments - remove PMEM_SUBSYS_OTHER from s->free calls

* Fix pmem.c infinite recursion - use raw malloc/free internally

* Fix prand.c mixed allocation - use pmem_free for putil_strdup result

* Migrate psettings.c free() calls to pmem_free()

* Fix all remaining stray free() calls - migrate to pmem_free()

* Fix pnetlibs_debug.c free() call - migrate to pmem_free()

* Add missing pmem.h include to pdevice.c

* Migrate pclsync_lib.cpp free() calls to pmem_free()

* Fix pfolder.c psync_free_string_list to use pmem_free()

* Fix all psync_list_for_each_element_call to use pmem_free wrappers

* Fix all list free wrapper functions - add proper definitions

* Fix rpcclient.cpp mixed allocation - use pmem_free for prpc_sockpath

* Replace all realloc() calls with pmem_realloc()

* Replace all strdup() calls with putil_strdup()

* Fix rpcclient.cpp allocation boundary - use plain malloc/free for RPC responses

* Fix RPC response length calculation - include header size

* Fix control_tools.cpp mixed allocations - use pmem_free for pshm_read results

---------

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
2026-03-08 21:47:22 +01:00
Levi Neely 1bf831c00f
Fix pcl-ue8: operator precedence in GetState() (#360)
Separated assignment from condition so rep contains Call() return value.
Removed incorrect wrapper that prevented state checks from executing.
Now rep values 10/11/12 properly set state.

Fixes #180

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
2026-03-07 19:40:07 +01:00
Levi Neely d5a1c74c43
Fix pcl-6nb: readResponse buffer over-read via unchecked msg->length (#354)
* Fix pcl-6nb.1: readResponse buffer over-read in rpcclient.cpp

Replace malloc'd receive buffer with stack array, fix the broken
validation (msg->length compared against POVERLAY_BUFSIZE rather
than max_value_size which excluded the header), fix the payload-read
loop target (msg->length already includes the header, so the old
`header_size + msg->length` limit over-read), add the missing
`msg->length > total_read` guard before memcpy, and add EINTR
handling in the read loop. Eliminates heap over-read when the daemon
sends msg->length > POVERLAY_BUFSIZE.

Ref GH #184.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Add readResponse validation tests (pcl-6nb)

Six socketpair-based test cases covering oversized msg->length,
total_read underrun, header underflow, truncated header, valid
message, and exact-boundary acceptance.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-07 18:08:56 +01:00
Levi Neely 0f23a32793
Fix input validation: stoull exception and buffer bounds (#297)
- Wrap std::stoull() in try/catch to prevent daemon crash on invalid folder ID
- Add proper read loop for RPC messages to handle partial reads
- Validate msg->length before memcpy to prevent heap over-read
- Handle daemon bugs gracefully (EOF before full message)
- Fix operator precedence in sync remove command

Fixes #205, #206

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
2026-03-03 11:55:54 +01:00
Levi Neely 175a46a109
Fix exception handling and operator precedence bugs (#295)
- Add return statement in catch(...) block to prevent fallthrough
- Fix operator precedence in GetState() to capture Call() return value

Fixes #201, #202

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
2026-03-03 11:25:25 +01:00
Levi Neely 9014edb99a
98 create a pdbg namespace (#139)
* pdbg split from plibs
* pdbg namespace
* add SSLDBGLVL build option
2025-03-13 20:28:09 +01:00
Levi Neely ce6033fe95
130 use trustworthy location for log and socket (#134)
* trustworthy location for log and socket
- socket in => $HOME/.pcloud/prpc.sock (mode 0600)
- debug log => $HOME/.pcloud/debug.log
* documentation updates
2025-03-11 19:03:58 +01:00
Levi Neely 79141898c3
84 security enhancements (#133)
- DoD 5220.22-M compliant memory wipe replaces single-pass zero wipe
- Wipe in-memory request and response messages before freeing
- Wipe in-memory private keys and salt data before freeing
- Wipe all passwords on unlink / logout
- Wipe crypto password on all pcryptofolder_unlock return paths
2025-03-11 15:05:43 +01:00
Levi Neely 28b985649f
rpcclient is now part of the CLI program (#126) 2025-03-09 20:20:33 +01:00