Compare commits

...
19 Commits
31 ... 40
Author SHA1 Message Date
Arjan van de Ven be8a99da53 allow service to start early 2017-05-07 15:42:30 +00:00
Ikey Doherty c9304402e2 Bump v38 to resync configure + tags
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 17:48:59 +00:00
Ikey Doherty 6e202f13f7 Bump v34
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 17:46:10 +00:00
Ikey Doherty 6735f8f6ed nica/files: Ensure we really do break on a read error
Previously nc_copy_file would return true regardless of a source read
error, flagged in analysis. Ensure we bypass the set of ret to true and
return the correct value in all instances.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:44:09 +00:00
Ikey Doherty 8b3777ab99 server: Remove useless assignment of prefix
This particular assignment is never used, as if this path fails, we go to
the thread end. We then reassign prefix after we split the input string.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:38:29 +00:00
Ikey Doherty 84350939ef nica/hashmap: Fix signature issue & item dereference
The signature was incorrect for inserting buckets, as we used an int, not
a boolean. Another issue resolved with this change is the potential
dereferencing of a null pointer by not having checked first if item was
NULL when setting the next pointer.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:35:29 +00:00
Arjan van de Ven 72b1120a40 add --no-same-permissions as well 2017-03-09 14:52:37 +00:00
Auke Kok d3d5fab301 Tag v33 2016-11-01 09:20:19 -07:00
Auke Kok e377433a9d Return on error here too.
Missed a 'return' catching an error.
2016-11-01 09:15:12 -07:00
Auke Kok afa92c77b1 Add reasonable connection timeout limits.
Adds a 30second connection timeout, and a low bandwith timeout
value (at 1kb/sec over 30 seconds) where the attempt will fail.
This provides some feedback to users that network issues are
preventing debug info from being loaded.
2016-11-01 09:15:12 -07:00
Arjan van de Ven a01ce4c329 dumb down due to limited infra 2016-11-01 13:17:49 +00:00
Arjan van de Ven 1eaaac582c use http/2 2016-11-01 12:56:35 +00:00
Arjan van de Ven 935dbee3c7 use CDN urls 2016-11-01 12:53:04 +00:00
Arjan van de Ven 0065ef2670 don't spew the journal 2016-11-01 12:52:17 +00:00
Ikey Doherty b5b4030f7c Release v32
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 19:21:20 +01:00
Ikey Doherty de9e0ce5c5 server: Disallow gdb -p attach, drop CAP_SYS_ADMIN
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 15:03:28 +01:00
Ikey Doherty 9e400bd149 Use correct types in absence of stdatomic.h
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:37:07 +01:00
Ikey Doherty f5a65358af Use pthread mutex in the absence of stdatomic C11 atomics
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:33:26 +01:00
Ikey Doherty c82a007960 Add configure output, and check for stdatomics
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:18:56 +01:00
7 changed files with 121 additions and 15 deletions
+1
View File
@@ -4,6 +4,7 @@ Description=Clear Linux debuginfo daemon
[Service]
Type=simple
ExecStart=/usr/bin/clr_debug_daemon
DefaultDependencies=no
[Install]
WantedBy=multi-user.target
+1
View File
@@ -5,6 +5,7 @@ After=clr_debug_daemon.service
[Service]
Type=simple
ExecStart=/usr/bin/clr_debug_fuse
DefaultDependencies=no
[Install]
WantedBy=multi-user.target
+28 -1
View File
@@ -2,7 +2,7 @@
# Process this file with autoconf to produce a configure script.
AC_PREREQ([2.66])
AC_INIT(clr-debug-info, 31, arjan@linux.intel.com)
AC_INIT(clr-debug-info, 38, arjan@linux.intel.com)
AM_INIT_AUTOMAKE([foreign -Wall -W subdir-objects])
AM_SILENT_RULES([yes])
AC_PROG_CC
@@ -27,5 +27,32 @@ AC_ARG_WITH([systemdtmpfilesdir], AS_HELP_STRING([--with-systemdtmpfilesdir=DIR]
test -z "${dir}" && dir=/usr/lib/tmpfiles.d
AC_SUBST(tmpfilesdir, [${dir}])
AC_CHECK_HEADER([stdatomic.h], [have_atomics="yes"], [have_atomics="no"])
if test x$have_atomics = "xyes"; then
AC_DEFINE([HAVE_ATOMIC_SUPPORT], [1], [stdatomic supported by compiler])
else
AC_MSG_WARN([C11 stdatomic support unavailable. Falling back to slow mutex])
fi
AC_CONFIG_FILES([Makefile])
AC_OUTPUT
AC_MSG_RESULT([
clr-debuginfo $VERSION
prefix: ${prefix}
libdir: ${libdir}
sysconfdir: ${sysconfdir}
exec_prefix: ${exec_prefix}
bindir: ${bindir}
datarootdir: ${datarootdir}
compiler: ${CC}
cflags: ${CFLAGS}
ldflags: ${LDFLAGS}
systemd-unit-dir: ${systemdsystemunitdir}
tmpfiles.d: ${tmpfilesdir}
C11 stdatomic support: ${have_atomics}
])
+1
View File
@@ -85,6 +85,7 @@ void try_to_get(const char *path, int pid, time_t timestamp)
if (ret == 0 && cred.pid == pid) {
printf("Recursion\n");
close(sockfd);
return;
}
command = NULL;
+1 -1
View File
@@ -113,7 +113,7 @@ bool nc_copy_file(const char *src, const char *dst, mode_t mode, bool remove_tar
while (true) {
if ((r = read(src_fd, &buffer, sizeof(buffer))) < 0) {
ret = false;
break;
goto end;
}
if (write(dest_fd, buffer, sizeof(buffer)) != r) {
break;
+7 -5
View File
@@ -123,8 +123,8 @@ static inline unsigned nc_hashmap_get_hash(NcHashmap *self, const void *key)
return hash;
}
static bool nc_hashmap_insert_bucket(NcHashmap *self, NcHashmapEntry *buckets, int n_buckets,
unsigned hash, const void *key, void *value)
static int nc_hashmap_insert_bucket(NcHashmap *self, NcHashmapEntry *buckets, int n_buckets,
unsigned hash, const void *key, void *value)
{
NcHashmapEntry *row = &(buckets[hash % n_buckets]);
NcHashmapEntry *head = NULL;
@@ -458,10 +458,12 @@ bool nc_hashmap_iter_next(NcHashmapIter *citer, void **key, void **value)
}
item = &(map->buckets[iter->bucket]);
}
if (item && item->occ) {
goto success;
if (item) {
if (item->occ) {
goto success;
}
item = item->next;
}
item = item->next;
}
return false;
+82 -8
View File
@@ -27,14 +27,15 @@
#define _GNU_SOURCE
#include <errno.h>
#include <linux/capability.h>
#include <malloc.h>
#include <pthread.h>
#include <signal.h>
#include <stdatomic.h>
#include <stddef.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/prctl.h>
#include <sys/socket.h>
#include <sys/stat.h>
#include <sys/types.h>
@@ -46,18 +47,22 @@
#include <curl/curl.h>
#include "config.h"
#ifdef HAVE_ATOMIC_SUPPORT
#include <stdatomic.h>
#endif
static pthread_mutex_t dupes_mutex = PTHREAD_MUTEX_INITIALIZER;
char *urls[2] = { "https://debuginfo.clearlinux.org/debuginfo/",
"https://debuginfo.clearlinux.org/debuginfo/" };
char *urls[2] = { "https://cdn.download.clearlinux.org/debuginfo/",
"https://cdn.download.clearlinux.org/debuginfo/" };
int urlcounter = 1;
static NcHashmap *hash = NULL;
#define MAX_CONNECTIONS 16
static atomic_int current_connection_count = 0;
static int avoid_dupes(const char *url)
{
int retval = 0;
@@ -85,6 +90,10 @@ static int avoid_dupes(const char *url)
return retval;
}
#ifdef HAVE_ATOMIC_SUPPORT
static atomic_int current_connection_count = 0;
/**
* Get the current connection count atomically
*/
@@ -108,6 +117,46 @@ __nc_inline__ static inline void dec_connection_count(void)
{
atomic_fetch_sub(&current_connection_count, 1);
}
#else /* HAVE_ATOMIC_SUPPORT */
static int current_connection_count = 0;
/* No stdatomic compiler support, fallback to pthread mutex (slower) */
pthread_mutex_t con_count_mutex = PTHREAD_MUTEX_INITIALIZER;
/**
* Get the current connection count via mutex
*/
__nc_inline__ static inline int get_current_connection_count(void)
{
int r;
pthread_mutex_lock(&con_count_mutex);
r = current_connection_count;
pthread_mutex_unlock(&con_count_mutex);
return r;
}
/**
* Increment the connection counter via mutex
*/
__nc_inline__ static inline void inc_connection_count(void)
{
pthread_mutex_lock(&con_count_mutex);
current_connection_count++;
pthread_mutex_unlock(&con_count_mutex);
}
/**
* Decrement the connection counter via mutex
*/
__nc_inline__ static inline void dec_connection_count(void)
{
pthread_mutex_lock(&con_count_mutex);
current_connection_count--;
pthread_mutex_unlock(&con_count_mutex);
}
#endif /* !(HAVE_ATOMIC_SUPPORT) */
static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
{
@@ -140,6 +189,19 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
curl_easy_setopt(curl, CURLOPT_URL, url);
curl_easy_setopt(curl, CURLOPT_WRITEDATA, file);
curl_easy_setopt(curl, CURLOPT_HTTP_VERSION, CURL_HTTP_VERSION_2_0);
/*
* Some sane timeout values to prevent stalls
*
* Connect timeout is for first connection to the server.
* The low speed timeout is for slow downloads. Since many
* files are several mB large, we want to prevent them from
* taking forever. (1kB/sec avg over 30secs).
*/
curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 30);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024);
if (timestamp) {
curl_easy_setopt(curl, CURLOPT_TIMECONDITION, CURL_TIMECOND_IFMODSINCE);
@@ -175,7 +237,7 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
stat(filename, &statbuf);
if (statbuf.st_size > 0 &&
asprintf(&command,
"tar -C /var/cache/debuginfo/%s --no-same-owner -xf %s",
"tar -C /var/cache/debuginfo/%s --no-same-owner --no-same-permissions -xf %s",
prefix,
filename) >= 0) {
if (system(command) != 0) {
@@ -220,7 +282,6 @@ static void *server_thread(void *arg)
if (ret < 0) {
goto thread_end;
}
prefix = buf;
c = strchr(buf, ':');
if (!c) {
goto thread_end;
@@ -273,6 +334,7 @@ static void *server_thread(void *arg)
}
gettimeofday(&after, NULL);
#if 0
if (timedelta(before, after) > 0.6)
printf("Request for %s took %5.2f seconds (%i - %i)\n",
url,
@@ -280,7 +342,7 @@ static void *server_thread(void *arg)
(1.0 * after.tv_usec - before.tv_usec) / 1000000.0,
ret,
(int)timestamp);
#endif
/* tell the other side we're done with the download */
wr = write(fd, "ok", 3);
@@ -300,6 +362,18 @@ int main(__nc_unused__ int argc, __nc_unused__ char **argv)
int curl_done = 0;
const char *required_paths[] = { "/var/cache/debuginfo/lib", "/var/cache/debuginfo/src" };
if (prctl(PR_SET_DUMPABLE, 0) != 0) {
fprintf(stderr,
"Failed to disable PR_SET_DUMPABLE. Do NOT gdb attach this process: %s\n",
strerror(errno));
}
if (geteuid() == 0) {
if (prctl(PR_CAPBSET_DROP, CAP_SYS_ADMIN) != 0) {
fprintf(stderr, "Failed to drop caps: %s\n", strerror(errno));
}
}
for (size_t i = 0; i < ARRAY_SIZE(required_paths); i++) {
const char *req_path = required_paths[i];
if (nc_file_exists(req_path)) {