]> dgit.raspbian.org Git - git-annex.git/commitdiff
dup stdio handles for P2P proxy
authorJoey Hess <joeyh@joeyh.name>
Mon, 1 Jul 2024 14:04:45 +0000 (10:04 -0400)
committerJoey Hess <joeyh@joeyh.name>
Mon, 1 Jul 2024 14:06:29 +0000 (10:06 -0400)
Special remotes might output to stdout, or read from stdin, which would
mess up the P2P protocol. So dup the handles to avoid any such problem.

Command/P2PStdIO.hs
P2P/IO.hs
doc/todo/git-annex_proxies.mdwn

index 4b38057e5833bf63ac3eb9760cd314237a02df80..910d9cb7cc78b7dc1adcd6c2ba219292f62911a5 100644 (file)
@@ -99,7 +99,7 @@ performProxyCluster clientuuid clusteruuid servermode = do
 proxyClientSide :: UUID -> Annex ClientSide
 proxyClientSide clientuuid = do
        clientrunst <- liftIO (mkRunState $ Serving clientuuid Nothing)
-       return $ ClientSide clientrunst (stdioP2PConnection Nothing)
+       ClientSide clientrunst <$> liftIO (stdioP2PConnectionDupped Nothing)
 
 p2pErrHandler :: Annex () -> (a -> CommandPerform) -> Annex (Either ProtoFailure a) -> CommandPerform
 p2pErrHandler closeconn cont a = a >>= \case
index 15e0dccde4ef05870c57f335ef1b40f24749bb5b..42b53a671ae7472ad43a797e01434e8a51a5ba81 100644 (file)
--- a/P2P/IO.hs
+++ b/P2P/IO.hs
@@ -1,6 +1,6 @@
 {- P2P protocol, IO implementation
  -
- - Copyright 2016-2018 Joey Hess <id@joeyh.name>
+ - Copyright 2016-2024 Joey Hess <id@joeyh.name>
  -
  - Licensed under the GNU AGPL version 3 or higher.
  -}
@@ -16,6 +16,7 @@ module P2P.IO
        , ConnIdent(..)
        , ClosableConnection(..)
        , stdioP2PConnection
+       , stdioP2PConnectionDupped
        , connectPeer
        , closeConnection
        , serveUnixSocket
@@ -104,6 +105,20 @@ stdioP2PConnection g = P2PConnection
        , connIdent = ConnIdent Nothing
        }
 
+-- P2PConnection using stdio, but with the handles first duplicated,
+-- to avoid anything that might output to stdio (eg a program run by a
+-- special remote) from interfering with the connection.
+stdioP2PConnectionDupped :: Maybe Git.Repo -> IO P2PConnection
+stdioP2PConnectionDupped g = do
+       (readh, writeh) <- dupIoHandles
+       return $ P2PConnection
+               { connRepo = g
+               , connCheckAuth = const False
+               , connIhdl = P2PHandle readh
+               , connOhdl = P2PHandle writeh
+               , connIdent = ConnIdent Nothing
+               }
+
 -- Opens a connection to a peer. Does not authenticate with it.
 connectPeer :: Maybe Git.Repo -> P2PAddress -> IO P2PConnection
 connectPeer g (TorAnnex onionaddress onionport) = do
index 50eb5aeef3b03e720b541a3d2e54491857060b27..8d803ec8937ca44fb3764ea97768c0f2e63a94de 100644 (file)
@@ -45,13 +45,6 @@ For June's work on [[design/passthrough_proxy]], remaining todos:
   rather than PUT-FROM or ALREADY-HAVE. Verify that the client processes
   that ok and displays it to the user.
 
-* If a special remote outputs to stdout, or reads from stdin, that will
-  mess up the P2P protocol. Move the special remote proxying into a
-  separate process perhaps, which can be run with stdout and stdin
-  redirected? Or, fix any special remotes that might do that. Are
-  there any left? External special remotes certainly don't since that would
-  mess up their own protocol. Hook special remotes can though.
-
 * Streaming download from proxied special remotes. See design.
 
 * Check annex.diskreserve when proxying for special remotes.