__msg_parse() turns bytes off a socket into pointers, before anything
has vouched for the peer, and it is the only place in libink that
does. It had no test of its own beyond whatever the other tests
happened to send it, all of it well-formed.
The target checks the parser's contract, not merely that it survived.
A header field must point into the header field array, and terminate
inside it, and the parse must never claim more bytes than it was
handed. Crash-only would pass a parser that walked into the body and
returned fields from there, since those bytes were handed over too.
The expected bounds are derived from the raw header rather than from
the parser, so the two have to agree independently.
Every input is copied into an allocation sized to it first. Reading
past the end of a roomy buffer stays inside the allocation and the
sanitizer never sees it; against an exact one the same read is a
fault, which is where the sharpest findings come from.
Under libFuzzer it is an ordinary fuzz target and named files replay,
which is how a find gets reproduced. With no arguments it runs a
fixed sweep -- every truncation, every single-byte corruption, every
value of the length that decides where the header ends, and seeded
garbage -- so the suite covers the same contract on every build,
without clang or a corpus in the tree. It takes 40 ms.
CI fuzzes it properly on every pull request, keeps the crashers, and
carries the corpus between runs so it reaches deeper over time than
any single run can. Note that clang links the fuzzer runtime against
the newest GCC tree it finds, so the libstdc++ headers have to match
that one and not the default compiler, which is worth saying since
installing the obvious package leaves you exactly where you started.
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
The implementation looks up the named service by using
`svc_parse_jobstr`. The callbacks for `svc_parse_jobstr` has been
augmented to accept a user data parameter. For this use case,
a carrier for the actual signal was needed. The address of the
signal parameter is taken and passed on as a `void *`. The
callback then simply deferences it as an int - the signal number.
This patch adds support for a configure script and with it
support for disabling inetd support. See the output from
./configure --help
* Add configure script
* Sprinkle #ifdef fairy dust on svc.c when inetd support is disabled
* Use GCC built-in autodep calculator (-MMD -MP)
* Fix name space issue with include files, use relative paths
* Disable username/group name to uid/gid functions in static builds
* Bug out (error) if a user tries to build the bootmisc plugin static
Possibly fixes GitHub issue #5 and issue #6.
NOTE: The static build has not received any testing at all!
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
Lots of cleanup and simplification of the main code in this commit.
Most notably libev has been added to take care of the main loop and
monitor services. Still TODO is migrating to use the libev signal
handling.
Convert initctl.c:listen_initctl() to a plugin instead. This also
meant introducing a new form of I/O plugin to finit, also handled
by libev.
Load plugins *after* we've setup the base filesystem (BASEFS) in case
plugins reside on a filesystem not reachable before "mount -a" has run.
This also has the side effect of lining up nicely with the first level
plugin hooks.
If a plugin wants to hook up with a loded service we connect them by
their respective numeric IDs in plugin_register(). I.e., the service
monitor checks if a service has a registered callback, which in turn
decides if a service should be started, stopped or reloaded.
Rip out old EeePC distribution defines from finit.h, none of it really
applies anymore. If you need distribution specific settings this is
the place to put them.
Make hookpoint names (#defines) clearer: after BASEFS, after networking,
after all setup, etc.
Use #inlude_next <signal.h> in signal.h to include system header file!
Simplify service monitor: move essential code to svc.c and rip out
the TIPC dependency. Write your own service.so plugin, or wait for
a more complete example of how to extend service monitoring using
the primitives in svc.c
Signed-off-by: Joachim Nilsson <troglobit@gmail.com>