fix(peer): bound public readiness sentinel reads

Reuse the stable 64 KiB non-link version.ini reader in anonymous transfer admission and install recovery. A stale Ready snapshot can no longer turn a locally enlarged sentinel into repeated unbounded request-path reads or diagnostic content.

Test Plan:
- just test
- just clippy
- oversized public-admission sentinel regression
- git diff --check
This commit is contained in:
ddidderr committed 2026-09-12 13:35:54 +02:00
1 parent 3450d27742
commit 9b6f611db0
3 files changed
+22 -10

No files matched your search

+12 -2
View File
@@ -29,7 +29,7 @@ use tokio_util::{
use crate::{
context::PeerCtx,
download::open_catalog_file_for_read,
local_games::version_ini_is_regular_file,
local_games::{read_version_from_ini_bounded, version_ini_is_regular_file},
peer::send_game_file_chunk,
scoped_blocking::scoped_blocking,
stream_install::{send_game_install_stream, send_stream_install_error},
@@ -140,7 +140,7 @@ async fn can_serve_game(ctx: &PeerCtx, game_dir: &std::path::Path, game_id: &str
let expected_version_for_read = expected_version.clone();
scoped_blocking(move || {
expected_version_for_read.as_deref().is_none_or(|expected| {
lanspread_db::db::read_version_from_ini(&game_root)
read_version_from_ini_bounded(&game_root)
.is_ok_and(|version| version.as_deref() == Some(expected))
})
})
@@ -847,6 +847,16 @@ mod tests {
std::fs::write(game_root.join("version.ini"), b"20250101")
.expect("sentinel should be restored");
std::fs::OpenOptions::new()
.write(true)
.open(game_root.join("version.ini"))
.expect("sentinel should open")
.set_len(64 * 1024 + 1)
.expect("sentinel should become oversized");
assert_chunk_rejected(&ctx, content_id, &payload, 0, 7).await;
std::fs::write(game_root.join("version.ini"), b"20250101")
.expect("bounded sentinel should be restored");
std::fs::write(game_root.join("payload.bin"), b"short")
.expect("wrong-sized payload should be written");
assert_chunk_rejected(&ctx, content_id, &payload, 0, 7).await;