Page MenuHomeFreeBSD

hastd: Use fixed-length protocol names
ClosedPublic

Authored by des on Wed, Sep 9, 9:07 AM.
Tags
None
Referenced Files
F174233030: D59521.diff
Thu, Oct 1, 2:09 PM
Unknown Object (File)
Thu, Oct 1, 6:58 AM
Unknown Object (File)
Wed, Sep 30, 10:35 AM
Unknown Object (File)
Tue, Sep 29, 5:57 PM
Unknown Object (File)
Tue, Sep 29, 3:49 PM
Unknown Object (File)
Sun, Sep 27, 7:08 AM
Unknown Object (File)
Sat, Sep 26, 2:18 PM
Unknown Object (File)
Fri, Sep 25, 9:48 PM

Details

Summary

All communication between hastd nodes and internally between hastd and
its worker children passes through the same pair of send / receive
functions. The receive function uses recv(2) with the MSG_WAITALL flag,
which in theory means we should never get a short read. However, when
handing off a socket to a worker child, we also pass a variable-length
string identifying the type of socket we're passing, and reading this
string relies on a short read. This used to work because the arrival of
the descriptor would interrupt the recv(2) call, but this bug was fixed
when the AF_UNIX code was rewritten a while ago and hastd has been
broken ever since.

Fixing the length of the protocol name to four characters including the
terminating null solves the short-read bug by never requiring a short
read (nothing else in hastd requires one).

Reported by: Martin Vidovic <xtronom@gmail.com>
MFC after: 3 days
Event: EuroBSDcon DevSummit 2026

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

des requested review of this revision.Wed, Sep 9, 9:07 AM

Tested on FreeBSD 15.0-RELEASE-p10, it works fine. I don't see any problems with the code.

This revision is now accepted and ready to land.Wed, Sep 9, 1:19 PM

I note that there's a second copy of all of this in auditdistd, and we probably want to do similar things.

I note that there's a second copy of all of this in auditdistd, and we probably want to do similar things.

See D59565

I can confirm this patch fixes hastd in my setup on physical machines running 16-CURRENT from August 24.

This revision was automatically updated to reflect the committed changes.