LCOV - code coverage report
Current view: top level - src - net_permissions.cpp (source / functions) Coverage Total Hit
Test: fuzz_coverage.info Lines: 98.8 % 85 84
Test Date: 2025-01-22 04:09:46 Functions: 100.0 % 4 4
Branches: 78.1 % 114 89

             Branch data     Line data    Source code
       1                 :             : // Copyright (c) 2009-2021 The Bitcoin Core developers
       2                 :             : // Distributed under the MIT software license, see the accompanying
       3                 :             : // file COPYING or http://www.opensource.org/licenses/mit-license.php.
       4                 :             : 
       5                 :             : #include <common/messages.h>
       6                 :             : #include <common/system.h>
       7                 :             : #include <net_permissions.h>
       8                 :             : #include <netbase.h>
       9                 :             : #include <util/translation.h>
      10                 :             : 
      11                 :             : using common::ResolveErrMsg;
      12                 :             : 
      13                 :             : const std::vector<std::string> NET_PERMISSIONS_DOC{
      14                 :             :     "bloomfilter (allow requesting BIP37 filtered blocks and transactions)",
      15                 :             :     "noban (do not ban for misbehavior; implies download)",
      16                 :             :     "forcerelay (relay transactions that are already in the mempool; implies relay)",
      17                 :             :     "relay (relay even in -blocksonly mode, and unlimited transaction announcements)",
      18                 :             :     "mempool (allow requesting BIP35 mempool contents)",
      19                 :             :     "download (allow getheaders during IBD, no disconnect after maxuploadtarget limit)",
      20                 :             :     "addr (responses to GETADDR avoid hitting the cache and contain random records with the most up-to-date info)"
      21                 :             : };
      22                 :             : 
      23                 :             : namespace {
      24                 :             : 
      25                 :             : // Parse the following format: "perm1,perm2@xxxxxx"
      26                 :         916 : static bool TryParsePermissionFlags(const std::string& str, NetPermissionFlags& output, ConnectionDirection* output_connection_direction, size_t& readen, bilingual_str& error)
      27                 :             : {
      28                 :         916 :     NetPermissionFlags flags = NetPermissionFlags::None;
      29                 :         916 :     ConnectionDirection connection_direction = ConnectionDirection::None;
      30                 :         916 :     const auto atSeparator = str.find('@');
      31                 :             : 
      32                 :             :     // if '@' is not found (ie, "xxxxx"), the caller should apply implicit permissions
      33         [ +  + ]:         916 :     if (atSeparator == std::string::npos) {
      34                 :         572 :         NetPermissions::AddFlag(flags, NetPermissionFlags::Implicit);
      35                 :         572 :         readen = 0;
      36                 :             :     }
      37                 :             :     // else (ie, "perm1,perm2@xxxxx"), let's enumerate the permissions by splitting by ',' and calculate the flags
      38                 :             :     else {
      39                 :         344 :         readen = 0;
      40                 :             :         // permissions == perm1,perm2
      41                 :         344 :         const auto permissions = str.substr(0, atSeparator);
      42         [ +  + ]:       15576 :         while (readen < permissions.length()) {
      43                 :       15036 :             const auto commaSeparator = permissions.find(',', readen);
      44         [ +  + ]:       15036 :             const auto len = commaSeparator == std::string::npos ? permissions.length() - readen : commaSeparator - readen;
      45                 :             :             // permission == perm1
      46         [ +  - ]:       15036 :             const auto permission = permissions.substr(readen, len);
      47                 :       15036 :             readen += len; // We read "perm1"
      48         [ +  + ]:       15036 :             if (commaSeparator != std::string::npos) readen++; // We read ","
      49                 :             : 
      50   [ +  +  +  + ]:       15036 :             if (permission == "bloomfilter" || permission == "bloom") NetPermissions::AddFlag(flags, NetPermissionFlags::BloomFilter);
      51         [ +  + ]:       14602 :             else if (permission == "noban") NetPermissions::AddFlag(flags, NetPermissionFlags::NoBan);
      52         [ +  + ]:       14221 :             else if (permission == "forcerelay") NetPermissions::AddFlag(flags, NetPermissionFlags::ForceRelay);
      53         [ +  + ]:       14029 :             else if (permission == "mempool") NetPermissions::AddFlag(flags, NetPermissionFlags::Mempool);
      54         [ +  + ]:       13672 :             else if (permission == "download") NetPermissions::AddFlag(flags, NetPermissionFlags::Download);
      55         [ +  + ]:       13233 :             else if (permission == "all") NetPermissions::AddFlag(flags, NetPermissionFlags::All);
      56         [ +  + ]:       12824 :             else if (permission == "relay") NetPermissions::AddFlag(flags, NetPermissionFlags::Relay);
      57         [ +  + ]:       12472 :             else if (permission == "addr") NetPermissions::AddFlag(flags, NetPermissionFlags::Addr);
      58         [ +  + ]:       11904 :             else if (permission == "in") connection_direction |= ConnectionDirection::In;
      59         [ +  + ]:       10497 :             else if (permission == "out") {
      60         [ +  + ]:         588 :                 if (output_connection_direction == nullptr) {
      61                 :             :                     // Only NetWhitebindPermissions() should pass a nullptr.
      62         [ +  - ]:          62 :                     error = _("whitebind may only be used for incoming connections (\"out\" was passed)");
      63                 :          62 :                     return false;
      64                 :             :                 }
      65                 :         526 :                 connection_direction |= ConnectionDirection::Out;
      66                 :             :             }
      67         [ +  + ]:        9909 :             else if (permission.length() == 0); // Allow empty entries
      68                 :             :             else {
      69         [ +  - ]:          86 :                 error = strprintf(_("Invalid P2P permission: '%s'"), permission);
      70                 :          86 :                 return false;
      71                 :             :             }
      72                 :       15036 :         }
      73                 :         196 :         readen++;
      74                 :         148 :     }
      75                 :             : 
      76                 :             :     // By default, whitelist only applies to incoming connections
      77         [ +  + ]:         768 :     if (connection_direction == ConnectionDirection::None) {
      78                 :             :         connection_direction = ConnectionDirection::In;
      79         [ +  + ]:          52 :     } else if (flags == NetPermissionFlags::None) {
      80                 :          11 :         error = strprintf(_("Only direction was set, no permissions: '%s'"), str);
      81                 :          11 :         return false;
      82                 :             :     }
      83                 :             : 
      84                 :         757 :     output = flags;
      85         [ +  + ]:         757 :     if (output_connection_direction) *output_connection_direction = connection_direction;
      86         [ +  - ]:        1514 :     error = Untranslated("");
      87                 :         757 :     return true;
      88                 :             : }
      89                 :             : 
      90                 :             : }
      91                 :             : 
      92                 :         186 : std::vector<std::string> NetPermissions::ToStrings(NetPermissionFlags flags)
      93                 :             : {
      94                 :         186 :     std::vector<std::string> strings;
      95   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::BloomFilter)) strings.emplace_back("bloomfilter");
      96   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::NoBan)) strings.emplace_back("noban");
      97   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::ForceRelay)) strings.emplace_back("forcerelay");
      98   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::Relay)) strings.emplace_back("relay");
      99   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::Mempool)) strings.emplace_back("mempool");
     100   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::Download)) strings.emplace_back("download");
     101   [ +  +  +  - ]:         186 :     if (NetPermissions::HasFlag(flags, NetPermissionFlags::Addr)) strings.emplace_back("addr");
     102                 :         186 :     return strings;
     103                 :           0 : }
     104                 :             : 
     105                 :         458 : bool NetWhitebindPermissions::TryParse(const std::string& str, NetWhitebindPermissions& output, bilingual_str& error)
     106                 :             : {
     107                 :         458 :     NetPermissionFlags flags;
     108                 :         458 :     size_t offset;
     109         [ +  + ]:         458 :     if (!TryParsePermissionFlags(str, flags, /*output_connection_direction=*/nullptr, offset, error)) return false;
     110                 :             : 
     111                 :         361 :     const std::string strBind = str.substr(offset);
     112   [ +  -  +  - ]:         361 :     const std::optional<CService> addrBind{Lookup(strBind, 0, false)};
     113         [ +  + ]:         361 :     if (!addrBind.has_value()) {
     114   [ +  -  +  - ]:         616 :         error = ResolveErrMsg("whitebind", strBind);
     115                 :         308 :         return false;
     116                 :             :     }
     117   [ +  -  +  + ]:          53 :     if (addrBind.value().GetPort() == 0) {
     118         [ +  - ]:          40 :         error = strprintf(_("Need to specify a port with -whitebind: '%s'"), strBind);
     119                 :          40 :         return false;
     120                 :             :     }
     121                 :             : 
     122                 :          13 :     output.m_flags = flags;
     123         [ +  - ]:          13 :     output.m_service = addrBind.value();
     124   [ +  -  +  - ]:          26 :     error = Untranslated("");
     125                 :          13 :     return true;
     126                 :         361 : }
     127                 :             : 
     128                 :         458 : bool NetWhitelistPermissions::TryParse(const std::string& str, NetWhitelistPermissions& output, ConnectionDirection& output_connection_direction, bilingual_str& error)
     129                 :             : {
     130                 :         458 :     NetPermissionFlags flags;
     131                 :         458 :     size_t offset;
     132                 :             :     // Only NetWhitebindPermissions should pass a nullptr for output_connection_direction.
     133         [ +  + ]:         458 :     if (!TryParsePermissionFlags(str, flags, &output_connection_direction, offset, error)) return false;
     134                 :             : 
     135                 :         396 :     const std::string net = str.substr(offset);
     136         [ +  - ]:         396 :     const CSubNet subnet{LookupSubNet(net)};
     137   [ +  -  +  + ]:         396 :     if (!subnet.IsValid()) {
     138         [ +  - ]:         316 :         error = strprintf(_("Invalid netmask specified in -whitelist: '%s'"), net);
     139                 :         316 :         return false;
     140                 :             :     }
     141                 :             : 
     142                 :          80 :     output.m_flags = flags;
     143                 :          80 :     output.m_subnet = subnet;
     144   [ +  -  +  - ]:         160 :     error = Untranslated("");
     145                 :          80 :     return true;
     146                 :         396 : }
        

Generated by: LCOV version 2.0-1