veloxd is the one process that turns an untrusted string into a filesystem destination, and via capture.offer that string can come from a web page. CLAUDE.md §4 and the M1 DoD both name this. daemon/docs/safepath-adversarial.md is the spec, written before the code the way EXT did for shouldCapture: 21 rows — .. traversal (A1/A2), absolute-outside-roots (A3), prefix-match confusion (A4), symlink-out (A7), TOCTOU on a created tail (A8), NUL/control bytes in the leaf that CORE's fuzzer hit through Content-Disposition (A9/A10), degenerate and overlong leaves (A11/A13), overlong dir component (A14), symlinked root (A16), destination-is-a-file (A17), and the legitimate cases that must still pass — non-ASCII (A18), redundant "." (A19), trailing space/dot trimming (A20). fs/safepath.cpp: - sanitize_leaf: strip <0x20 and 0x7F, trim ws, strip trailing dots, reject ""/"."/".."/contains-'/', cap 255 UTF-8 bytes on a codepoint boundary. Mirrors core/src/net/content_disposition.cpp. - canonicalize_root: expand ~ and realpath each allowedRoots entry once, so a symlinked root resolves to its target. - resolve_target: reject relative saveDir and any ".." component lexically; if the dir exists, realpath + component-wise containment (a symlink that escapes is caught, one that stays inside passes); if a tail is missing, realpath+check the deepest existing ancestor then create the tail via an openat/mkdirat O_NOFOLLOW walk and re-derive the final path from the fd. Every failure is -32011 with data.path = the *original* saveDir (never the resolved path). Residual TOCTOU on a pre-existing intermediate dir is documented and closed by CORE's O_NOFOLLOW open of the file. veloxd_fs static lib; veloxd_rpc links it for the download.add wiring next. Test veloxd.safepath is the adversarial table, on a real temp tree. ASan+UBSan and TSan clean; 33 daemon/cli tests green. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Upd9WhG9oppieig5nRDLig
96 lines
4.2 KiB
CMake
96 lines
4.2 KiB
CMake
# daemon/ produces the veloxd binary and the static libraries it is built from.
|
|
# Owned by lane DAEMON. Wired in by PKG via add_subdirectory(daemon) in the root file,
|
|
# guarded on this file existing.
|
|
#
|
|
# Layering (CLAUDE.md §3): depends on velox::core and velox::proto. No Qt. The engine
|
|
# (velox::core) is not linked yet — it arrives when sched/ and the task glue land. This
|
|
# drop is the RPC transports (Unix socket + loopback WebSocket), the SQLite store, and a
|
|
# dispatcher skeleton so the CLI and GUI have a real server to talk to.
|
|
|
|
if(NOT TARGET nlohmann_json::nlohmann_json)
|
|
find_package(nlohmann_json 3.11 REQUIRED)
|
|
endif()
|
|
find_package(Threads REQUIRED)
|
|
find_package(SQLite3 REQUIRED)
|
|
find_package(OpenSSL REQUIRED) # libcrypto: WebSocket accept hash, pairing token hash
|
|
|
|
# --- generated: migrations_embedded.hpp from src/store/migrations/*.sql ---------------
|
|
set(_mig_dir ${CMAKE_CURRENT_SOURCE_DIR}/src/store/migrations)
|
|
set(_mig_hdr ${CMAKE_CURRENT_BINARY_DIR}/generated/migrations_embedded.hpp)
|
|
file(GLOB _mig_srcs ${_mig_dir}/*.sql)
|
|
add_custom_command(
|
|
OUTPUT ${_mig_hdr}
|
|
COMMAND ${CMAKE_COMMAND} -DMIG_DIR=${_mig_dir} -DOUT=${_mig_hdr}
|
|
-P ${CMAKE_CURRENT_SOURCE_DIR}/cmake/embed_migrations.cmake
|
|
DEPENDS ${_mig_srcs} ${CMAKE_CURRENT_SOURCE_DIR}/cmake/embed_migrations.cmake
|
|
COMMENT "Embedding SQL migrations"
|
|
VERBATIM)
|
|
add_custom_target(veloxd_migrations_hdr DEPENDS ${_mig_hdr})
|
|
|
|
# --- veloxd_store — SQLite store, migrations, crypto helpers --------------------------
|
|
add_library(veloxd_store STATIC
|
|
src/util/crypto.cpp
|
|
src/store/sqlite.cpp
|
|
src/store/migrations.cpp
|
|
src/store/pairings.cpp
|
|
${_mig_hdr}
|
|
)
|
|
add_library(velox::daemon_store ALIAS veloxd_store)
|
|
target_include_directories(veloxd_store
|
|
PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src
|
|
PRIVATE ${CMAKE_CURRENT_BINARY_DIR}/generated
|
|
)
|
|
target_compile_features(veloxd_store PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_store PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd_store PUBLIC SQLite::SQLite3 PRIVATE OpenSSL::Crypto)
|
|
|
|
# --- veloxd_fs — the saveDir/filename path-traversal boundary (security) -----------
|
|
# daemon/docs/safepath-adversarial.md is the spec; safepath_test.cpp is that table.
|
|
add_library(veloxd_fs STATIC src/fs/safepath.cpp)
|
|
add_library(velox::daemon_fs ALIAS veloxd_fs)
|
|
target_include_directories(veloxd_fs PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src)
|
|
target_compile_features(veloxd_fs PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_fs PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
|
|
# --- veloxd_sched — the concurrency governor (pure; no engine link yet, see
|
|
# daemon/docs/deferrals.md D4) ---------------------------------------------------
|
|
add_library(veloxd_sched STATIC
|
|
src/sched/schedule_window.cpp
|
|
src/sched/governor.cpp
|
|
)
|
|
add_library(velox::daemon_sched ALIAS veloxd_sched)
|
|
target_include_directories(veloxd_sched PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src)
|
|
target_compile_features(veloxd_sched PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_sched PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd_sched PUBLIC velox::proto nlohmann_json::nlohmann_json)
|
|
|
|
# --- veloxd_rpc — the RPC transports + dispatcher ------------------------------------
|
|
add_library(veloxd_rpc STATIC
|
|
src/rpc/runtime_dir.cpp
|
|
src/rpc/event_loop.cpp
|
|
src/rpc/uds_server.cpp
|
|
src/rpc/ws_frame.cpp
|
|
src/rpc/ws_handshake.cpp
|
|
src/rpc/ws_server.cpp
|
|
src/rpc/pairing.cpp
|
|
src/rpc/dispatcher.cpp
|
|
)
|
|
add_library(velox::daemon_rpc ALIAS veloxd_rpc)
|
|
|
|
target_include_directories(veloxd_rpc PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src)
|
|
target_compile_features(veloxd_rpc PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_rpc PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd_rpc
|
|
PUBLIC velox::proto veloxd_store veloxd_fs nlohmann_json::nlohmann_json Threads::Threads
|
|
)
|
|
|
|
# --- veloxd — the daemon binary -------------------------------------------------------
|
|
add_executable(veloxd src/main.cpp)
|
|
target_compile_features(veloxd PRIVATE cxx_std_23)
|
|
target_compile_options(veloxd PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd PRIVATE veloxd_rpc veloxd_sched)
|
|
|
|
if(VELOX_BUILD_TESTS AND EXISTS ${CMAKE_CURRENT_SOURCE_DIR}/tests/CMakeLists.txt)
|
|
add_subdirectory(tests)
|
|
endif()
|