Polish: NOSIGNAL + HTTPS pin on all transports, bounded kill loop

The three other curl_easy code paths (downloader, piece pool, net_diag)
now set CURLOPT_NOSIGNAL=1L plus PROTOCOLS_STR/REDIR_PROTOCOLS_STR =
"https" — matching what patchdl_http_get already does. SIGPIPE on a
broken connection in a worker thread previously could crash the process;
the protocol pin keeps a redirect from sliding off https.

patchdl_proc_kill_others is now bounded to 8 iterations. If kill returns
success but the process never exits (zombie / unusual proc-table state),
sleep(1) × N would otherwise stall startup indefinitely.

lookup_tsv rejects URLs that don't start with https://. The TSV file
lives under /data/patchdl and is writable by anyone with /data access;
patchdl_http_get's host_allowed gate still applies, but failing earlier
keeps a poisoned line from even reaching the network layer.
This commit is contained in:
Knutwurst committed 2026-06-24 20:41:26 +02:00
1 parent 73c75ddd83
commit c9d721fea6
3 files changed
+21 -1

No files matched your search

+9
View File
@@ -452,6 +452,9 @@ http_download_to_file_progress(const char *url, FILE *fp, long long *bytes_out,
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
/* No total timeout (patches can be large); abort only on a long stall. */
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
@@ -868,6 +871,9 @@ patchdl_http_download_piece(const char *url, int fd,
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_FOLLOWLOCATION, 1L);
curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L);
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_FAILONERROR, 1L); /* 4xx/5xx -> error, no body written */
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 20L);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024L);
@@ -1060,6 +1066,9 @@ patchdl_net_diag(const char *url, char *out_json, size_t sz) {
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 1L);
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 2L);
curl_easy_setopt(curl, CURLOPT_SSL_CIPHER_LIST, "DEFAULT@SECLEVEL=0");
curl_easy_setopt(curl, CURLOPT_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_REDIR_PROTOCOLS_STR, "https");
curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1L);
curl_easy_setopt(curl, CURLOPT_TIMEOUT, 15L);
res = curl_easy_perform(curl);
curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &http_code);
+4 -1
View File
@@ -65,7 +65,10 @@ patchdl_proc_kill_others(const char *name) {
int killed = 0;
pid_t pid;
while ((pid = find_pid(name)) > 0) {
/* Bound the loop: at startup we expect 0-1 stale instance. A pathological
proc table (or kill returning success but the process not exiting) would
otherwise stall startup for sleep(1) × N. */
while (killed < 8 && (pid = find_pid(name)) > 0) {
if (kill(pid, SIGKILL))
break;
killed++;
+8
View File
@@ -27,6 +27,14 @@ lookup_tsv(const char *title_id, char *url_out, size_t url_sz) {
fclose(fp);
return -1;
}
/* Defense in depth: the TSV file lives under /data/patchdl, writable
by anyone with /data access. patchdl_http_get also enforces
host_allowed, but rejecting non-https / non-Sony schemes here means
a poisoned line can't even reach the network layer. */
if (strncmp(url, "https://", 8) != 0) {
fclose(fp);
return -1;
}
memcpy(url_out, url, len + 1);
fclose(fp);
return 0;