Skip to content

Commit d00beeb

Browse files
committed
Fix scanner readiness blockers
1 parent d360b91 commit d00beeb

17 files changed

Lines changed: 448 additions & 134 deletions

‎.agents/sow/done/SOW-0029-20260701-ci-scanner-readiness.md‎

Lines changed: 310 additions & 0 deletions
Large diffs are not rendered by default.

‎.codacy/codacy.config.json‎

Lines changed: 5 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -8180,78 +8180,14 @@
81808180
"patternId": "spectral_typed-enum"
81818181
}
81828182
]
8183-
},
8184-
{
8185-
"toolId": "Revive",
8186-
"patterns": [
8187-
{
8188-
"patternId": "Revive_unsecure-url-scheme"
8189-
},
8190-
{
8191-
"patternId": "Revive_imports-blocklist"
8192-
},
8193-
{
8194-
"patternId": "Revive_unchecked-type-assertion"
8195-
},
8196-
{
8197-
"patternId": "Revive_datarace"
8198-
},
8199-
{
8200-
"patternId": "Revive_unconditional-recursion"
8201-
},
8202-
{
8203-
"patternId": "Revive_context-as-argument"
8204-
},
8205-
{
8206-
"patternId": "Revive_context-keys-type"
8207-
},
8208-
{
8209-
"patternId": "Revive_indent-error-flow"
8210-
},
8211-
{
8212-
"patternId": "Revive_receiver-naming"
8213-
},
8214-
{
8215-
"patternId": "Revive_increment-decrement"
8216-
},
8217-
{
8218-
"patternId": "Revive_unexported-return"
8219-
},
8220-
{
8221-
"patternId": "Revive_dot-imports"
8222-
},
8223-
{
8224-
"patternId": "Revive_range"
8225-
},
8226-
{
8227-
"patternId": "Revive_time-naming"
8228-
},
8229-
{
8230-
"patternId": "Revive_unreachable-code"
8231-
},
8232-
{
8233-
"patternId": "Revive_blank-imports"
8234-
},
8235-
{
8236-
"patternId": "Revive_error-return"
8237-
},
8238-
{
8239-
"patternId": "Revive_var-declaration"
8240-
},
8241-
{
8242-
"patternId": "Revive_errorf"
8243-
},
8244-
{
8245-
"patternId": "Revive_superfluous-else"
8246-
},
8247-
{
8248-
"patternId": "Revive_error-naming"
8249-
}
8250-
]
82518183
}
82528184
],
82538185
"exclude": [
82548186
"bench/**",
8255-
"tests/**"
8187+
"benchmarks-*",
8188+
"tests/**",
8189+
"**/*_test.go",
8190+
"**/*_tests.rs",
8191+
"**/tests.rs"
82568192
]
82578193
}

‎CMakeLists.txt‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ if(NOT NETIPC_WINDOWS_RUNTIME)
6262
target_include_directories(netipc_uds PUBLIC
6363
src/libnetdata/netipc/include
6464
)
65-
target_link_libraries(netipc_uds PUBLIC netipc_protocol)
65+
target_link_libraries(netipc_uds PUBLIC netipc_protocol Threads::Threads)
6666

6767
# --- C library: L1 POSIX SHM transport (Linux only) ----------------------
6868

‎src/crates/netipc/Cargo.lock‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎src/crates/netipc/src/service/raw.rs‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,8 +30,7 @@ mod string_reverse;
3030

3131
pub use apps_lookup::{apps_lookup_dispatch, AppsLookupHandler};
3232
pub use cgroups_cache::{
33-
CgroupsCache, CgroupsCacheItem, CgroupsCacheItemView, CgroupsCacheReadGuard,
34-
CgroupsCacheStatus,
33+
CgroupsCache, CgroupsCacheItem, CgroupsCacheItemView, CgroupsCacheReadGuard, CgroupsCacheStatus,
3534
};
3635
pub use cgroups_lookup::{cgroups_lookup_dispatch, CgroupsLookupHandler};
3736
pub use cgroups_snapshot::{snapshot_dispatch, snapshot_max_items, SnapshotHandler};

‎src/crates/netipc/src/service/raw/cgroups_cache.rs‎

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,9 @@ impl CgroupsCacheState {
8787
}
8888

8989
fn lock_mutex<T>(mutex: &Mutex<T>) -> MutexGuard<'_, T> {
90-
mutex.lock().unwrap_or_else(|poisoned| poisoned.into_inner())
90+
mutex
91+
.lock()
92+
.unwrap_or_else(|poisoned| poisoned.into_inner())
9193
}
9294

9395
fn read_lock<T>(lock: &RwLock<T>) -> RwLockReadGuard<'_, T> {
@@ -128,11 +130,7 @@ fn cache_build_buckets(items: &[CgroupsCacheItem]) -> Vec<CgroupsHashBucket> {
128130
}
129131

130132
impl CgroupsCacheSnapshot {
131-
fn from_items(
132-
items: Vec<CgroupsCacheItem>,
133-
systemd_enabled: u32,
134-
generation: u64,
135-
) -> Self {
133+
fn from_items(items: Vec<CgroupsCacheItem>, systemd_enabled: u32, generation: u64) -> Self {
136134
let buckets = cache_build_buckets(&items);
137135
Self {
138136
items,

‎src/crates/netipc/src/service/raw_unix_tests.rs‎

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4604,8 +4604,7 @@ fn test_cache_concurrent_readers_refresh() {
46044604
let guard = cache.read_lock();
46054605
match guard.get(1001, "docker-abc123") {
46064606
Some(view)
4607-
if view.hash == 1001
4608-
&& view.path == "/sys/fs/cgroup/docker/abc123" =>
4607+
if view.hash == 1001 && view.path == "/sys/fs/cgroup/docker/abc123" =>
46094608
{
46104609
let copy = guard.dup(view);
46114610
if copy.hash != view.hash || copy.name != view.name {
@@ -4894,8 +4893,7 @@ fn test_cache_refresh_preserves_old_cache_on_malformed_snapshot_item() {
48944893
status.refresh_failure_count,
48954894
old_status.refresh_failure_count + 1
48964895
);
4897-
let preserved =
4898-
cache_dup(&cache, 1001, "docker-abc123").expect("old cache item should remain");
4896+
let preserved = cache_dup(&cache, 1001, "docker-abc123").expect("old cache item should remain");
48994897
assert_eq!(preserved.hash, old_item.hash);
49004898
assert_eq!(preserved.path, old_item.path);
49014899
assert!(

‎src/go/pkg/netipc/protocol/cgroups_lookup.go‎

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -183,21 +183,24 @@ func (v *CgroupsLookupRequestView) itemBytes(index uint32) ([]byte, []byte, erro
183183
return nil, nil, ErrOverflow
184184
}
185185
}
186-
dirOff64 := uint64(index) * uint64(LookupDirEntrySize)
187-
if dirOff64 > uint64(maxIntValue()) || CgroupsLookupReqHdr > maxIntValue()-int(dirOff64) {
186+
dirOff, ok := checkedInt(uint64(index) * uint64(LookupDirEntrySize))
187+
if !ok || CgroupsLookupReqHdr > maxIntValue()-dirOff {
188188
return nil, nil, ErrOverflow
189189
}
190-
base := CgroupsLookupReqHdr + int(dirOff64) // #nosec G115 -- bounded by maxIntValue above.
190+
base := CgroupsLookupReqHdr + dirOff
191191
if base > len(v.payload)-LookupDirEntrySize {
192192
return nil, nil, ErrOutOfBounds
193193
}
194194
off32 := ne.Uint32(v.payload[base : base+4])
195195
length32 := ne.Uint32(v.payload[base+4 : base+8])
196-
if uint64(off32) > uint64(maxIntValue()) || uint64(length32) > uint64(maxIntValue()) {
196+
off, ok := checkedInt(uint64(off32))
197+
if !ok {
198+
return nil, nil, ErrOutOfBounds
199+
}
200+
length, ok := checkedInt(uint64(length32))
201+
if !ok {
197202
return nil, nil, ErrOutOfBounds
198203
}
199-
length := int(length32) // #nosec G115 -- bounded by maxIntValue above.
200-
off := int(off32) // #nosec G115 -- bounded by maxIntValue above.
201204
item, err := lookupPayloadSlice(v.payload, dirEnd, off, length)
202205
if err != nil {
203206
return nil, nil, err

‎src/go/pkg/netipc/protocol/frame.go‎

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -301,7 +301,7 @@ func BatchDirDecode(buf []byte, itemCount uint32, packedAreaLen uint32) ([]Batch
301301
// Checks alignment and that each entry falls within packedAreaLen.
302302
func BatchDirValidate(buf []byte, itemCount uint32, packedAreaLen uint32) error {
303303
dirSize64 := uint64(itemCount) * 8
304-
if dirSize64 > uint64(maxIntValue()) {
304+
if dirSize64 > maxIntUint64() {
305305
return ErrBadItemCount
306306
}
307307
dirSize := int(dirSize64) // #nosec G115 -- bounded by maxIntValue above.
@@ -331,7 +331,7 @@ func BatchItemGet(payload []byte, itemCount uint32, index uint32) ([]byte, error
331331
}
332332

333333
dirSize64 := uint64(itemCount) * 8
334-
if dirSize64 > uint64(maxIntValue()) {
334+
if dirSize64 > maxIntUint64() {
335335
return nil, ErrBadItemCount
336336
}
337337
dirSize := int(dirSize64) // #nosec G115 -- bounded by maxIntValue above.
@@ -348,7 +348,7 @@ func BatchItemGet(payload []byte, itemCount uint32, index uint32) ([]byte, error
348348
if off%uint32(Alignment) != 0 {
349349
return nil, ErrBadAlignment
350350
}
351-
if uint64(off)+uint64(length) > uint64(packedAreaLen) {
351+
if !uint32RangeWithinInt(off, length, packedAreaLen) {
352352
return nil, ErrOutOfBounds
353353
}
354354

@@ -404,30 +404,31 @@ func NewBatchBuilder(buf []byte, maxItems uint32) *BatchBuilder {
404404
// Add appends an item payload. Handles alignment padding.
405405
func (b *BatchBuilder) Add(item []byte) error {
406406
maxInt := maxIntValue()
407+
itemLen32, itemLenFitsU32 := checkedU32Int(len(item))
407408
// Inline the common case; addSlow preserves the precise error returns for
408409
// overflow and unusual bounds.
409410
if b.itemCount < b.maxItems &&
410411
b.dirEnd >= 0 &&
411412
b.dataOffset >= 0 &&
412413
b.dataOffset <= maxInt-7 &&
413-
uint64(len(item)) <= uint64(^uint32(0)) {
414+
itemLenFitsU32 {
414415
alignedOff := Align8(b.dataOffset)
415-
if uint64(alignedOff) <= uint64(^uint32(0)) &&
416+
alignedOff32, alignedOffFitsU32 := checkedU32Int(alignedOff)
417+
if alignedOffFitsU32 &&
416418
alignedOff <= maxInt-b.dirEnd &&
417419
len(item) <= maxInt-alignedOff {
418420
absPos := b.dirEnd + alignedOff
419421
if len(item) <= maxInt-absPos {
420422
itemEnd := absPos + len(item)
421-
idx64 := uint64(b.itemCount) * 8
422-
if idx64 <= uint64(maxInt) {
423-
idx := int(idx64) // #nosec G115 -- bounded by maxInt above.
423+
idx, ok := checkedInt(uint64(b.itemCount) * 8)
424+
if ok {
424425
if itemEnd <= len(b.buf) && idx <= len(b.buf)-8 {
425426
if alignedOff > b.dataOffset {
426427
clear(b.buf[b.dirEnd+b.dataOffset : b.dirEnd+alignedOff])
427428
}
428429
copy(b.buf[absPos:], item)
429-
ne.PutUint32(b.buf[idx:idx+4], uint32(alignedOff)) // #nosec G115 -- bounded above.
430-
ne.PutUint32(b.buf[idx+4:idx+8], uint32(len(item))) // #nosec G115 -- bounded above.
430+
ne.PutUint32(b.buf[idx:idx+4], alignedOff32)
431+
ne.PutUint32(b.buf[idx+4:idx+8], itemLen32)
431432
b.dataOffset = alignedOff + len(item)
432433
b.itemCount++
433434
return nil
@@ -447,10 +448,12 @@ func (b *BatchBuilder) addSlow(item []byte) error {
447448
return ErrOverflow
448449
}
449450
alignedOff := Align8(b.dataOffset)
450-
if uint64(alignedOff) > uint64(^uint32(0)) {
451+
alignedOff32, ok := checkedU32Int(alignedOff)
452+
if !ok {
451453
return ErrOverflow
452454
}
453-
if uint64(len(item)) > uint64(^uint32(0)) {
455+
itemLen32, ok := checkedU32Int(len(item))
456+
if !ok {
454457
return ErrOverflow
455458
}
456459
if alignedOff > maxIntValue()-b.dirEnd {
@@ -481,16 +484,13 @@ func (b *BatchBuilder) addSlow(item []byte) error {
481484
copy(b.buf[absPos:], item)
482485

483486
// Write directory entry.
484-
idx64 := uint64(b.itemCount) * 8
485-
if idx64 > uint64(maxIntValue()) {
487+
idx, ok := checkedInt(uint64(b.itemCount) * 8)
488+
if !ok {
486489
return ErrOverflow
487490
}
488-
idx := int(idx64) // #nosec G115 -- bounded by maxIntValue above.
489491
if idx > len(b.buf)-8 {
490492
return ErrOverflow
491493
}
492-
alignedOff32 := uint32(alignedOff) // #nosec G115 -- bounded by uint32 max above.
493-
itemLen32 := uint32(len(item)) // #nosec G115 -- bounded by uint32 max above.
494494
ne.PutUint32(b.buf[idx:idx+4], alignedOff32)
495495
ne.PutUint32(b.buf[idx+4:idx+8], itemLen32)
496496

0 commit comments

Comments
 (0)