mirror of
https://github.com/logos-co/logos-protocol.git
synced 2026-08-27 20:11:07 +00:00
* feat: group-shareable local sockets, stale-socket reaper, bind-failure detection
The QtRO local transport binds each module's unix socket at 0777 & ~umask
(0755) with no way for a second OS user to reach it, discards the listen
result so a failed bind surfaces only as clients hanging, and never cleans up
the socket file — a hard-killed logos_host leaks it forever.
Add a Qt-free helper (logos_socket_paths.{h,cpp}) usable from both the qt_remote
and plain transport paths:
- applySocketPerms(path): chgrp + chmod a bound socket per LOGOS_SOCKET_GROUP /
LOGOS_SOCKET_MODE (chgrp-then-chmod so a half-applied policy is only ever
too strict). No-op when unset, so default behaviour is unchanged. Connecting
to an AF_UNIX socket needs write permission, so 0660 is what lets a group
member in.
- isSocketDead(path): S_ISSOCK && owned-by-us && non-blocking connect returns
ECONNREFUSED/ENOENT. Fails closed on any other outcome, so it never reports
a live socket or a regular file dead.
- reapStaleSockets(dir, prefix): unlink only the dead sockets, never a regular
file that shares the prefix (e.g. a *.lgx build artefact).
Wire it into RemoteTransportHost::publishObject and QtRemoteRegistry:
- construct QRemoteObjectRegistryHost empty and listen via setRegistryUrl() so
a bind failure is observed and logged (with lastError() + the socket path)
instead of leaving a silently-broken host;
- apply the socket-access policy to the freshly-bound local: socket.
The env-driven policy means every process in a node's tree (daemon, logos_host
subprocesses, their children) applies the same rule to every socket it binds
without threading config through each layer — the daemon exports the vars once.
Adds test_socket_paths.cpp (8 gtests): mode/group application, no-op default,
bad-mode rejection, live/dead/regular-file classification, and the reaper
keeping live sockets and regular files while removing only dead ones.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* review: harden socket helpers (gid overflow, socket-owner check, empty-prefix guard, dedup path)
Addressing automated review feedback on the socket helpers:
- resolveGid(): validate strtoul() errno/range so an out-of-range numeric
LOGOS_SOCKET_GROUP is rejected instead of silently truncating to a wrong gid.
- applySocketPerms(): when a policy is requested, stat the path first and refuse
unless it's a socket we own (S_ISSOCK + st_uid == geteuid()), so a malformed
URL can never chmod/chown a stray file. No-op fast path when the env is unset.
- reapStaleSockets(): refuse an empty prefix (would make every dead socket the
process owns a deletion candidate).
- Extract the duplicated `localSocketFilePath()` (Qt QLocalServer name->path
rule) into a shared qt_remote/qt_socket_path.h so RemoteTransportHost and
QtRemoteRegistry can't drift.
Adds tests: non-socket path refused (mode unchanged), empty-prefix reaper no-op.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* feat: transport-aware token validator hook on ModuleProxy (#22)
* feat: transport-aware token validator hook on ModuleProxy
Adds an injectable authorizer so a host (the logoscore daemon) can accept tokens
the built-in issued-token scan doesn't know — specifically operator-issued named
tokens validated against a persistent store — with per-token expiry and
local_only enforced against the transport the call arrived on.
- ModuleProxy::setTokenValidator(std::function<bool(token, transportProtocol)>).
isAuthorized() consults it ONLY after the existing m_tokens + TokenManager
scan fails, so installing a validator is purely additive: it can grant, never
revoke, access the built-in path already allows. Empty (default) = today's
behaviour exactly.
- callRemoteMethod() gains a defaulted `transportProtocol` ("local"). The QtRO
local path (RemoteTransportHost) uses the default; PlainTransportHost::onCall
passes the real wire ("tcp" | "tcp_ssl", fail-closed to non-local on an
unexpected protocol) so a local_only token presented over the network is
rejected. One ModuleProxy is shared across a provider's transports, so the
transport can't be inferred — it must be threaded per call, which the defaulted
arg does without changing the QtRO replica's 3-arg call.
The daemon backs the validator with TokenStore::lookupByToken; other modules
keep the default (no validator) and are unaffected.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* review: split callRemoteMethod into explicit 3-arg + 4-arg overloads; include <utility>
Addressing review feedback:
- Replace the defaulted transportProtocol argument with two explicit Q_INVOKABLE
overloads. The Qt meta-object system matches methods by their full parameter
list and doesn't apply C++ default arguments, so the QtRO/local 3-arg call
must remain a real 3-arg method rather than relying on moc's reduced-arity
generation. The 3-arg form forwards to the transport-aware 4-arg form with
"local"; PlainTransportHost keeps calling the 4-arg form with the real wire.
- Include <utility> explicitly in module_proxy.h for std::move rather than
relying on an indirect include.
Full protocol suite green (160/160).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
83 lines
3.7 KiB
C++
83 lines
3.7 KiB
C++
#ifndef MODULE_PROXY_H
|
|
#define MODULE_PROXY_H
|
|
|
|
#include <QObject>
|
|
#include <QVariant>
|
|
#include <QVariantList>
|
|
#include <QHash>
|
|
#include <QString>
|
|
#include <QJsonArray>
|
|
|
|
#include <functional>
|
|
#include <utility>
|
|
|
|
class LogosProviderObject;
|
|
|
|
/**
|
|
* @brief ModuleProxy wraps a LogosProviderObject and exposes it as a QObject
|
|
* so that Qt Remote Objects can publish it.
|
|
*
|
|
* All method dispatch, introspection, and event forwarding is delegated
|
|
* to the underlying LogosProviderObject*. For legacy QObject-based plugins,
|
|
* that provider is a QtProviderObject adapter; for new-API plugins it is
|
|
* the plugin's own LogosProviderObject subclass.
|
|
*/
|
|
class ModuleProxy : public QObject
|
|
{
|
|
Q_OBJECT
|
|
|
|
public:
|
|
// A host-installed extra authorizer. Returns true if `token` is valid for a
|
|
// call arriving over `transportProtocol` ("local" | "tcp" | "tcp_ssl").
|
|
// Consulted IN ADDITION to the built-in issued-token scan, so installing one
|
|
// only ever grants access to tokens the built-in scan wouldn't (e.g. the
|
|
// daemon backs it with TokenStore::lookupByToken to make operator-issued
|
|
// named tokens work, with per-token expiry and local_only enforced by the
|
|
// transport it's handed).
|
|
using TokenValidator = std::function<bool(const QString& token,
|
|
const QString& transportProtocol)>;
|
|
|
|
explicit ModuleProxy(LogosProviderObject* provider, QObject* parent = nullptr);
|
|
~ModuleProxy();
|
|
|
|
void setTokenValidator(TokenValidator validator);
|
|
|
|
// Two explicit Q_INVOKABLE overloads rather than one with a defaulted
|
|
// transport arg: the Qt meta-object system matches by full parameter list
|
|
// and does not apply C++ default arguments, so the existing QtRO/local
|
|
// 3-arg call must remain a real 3-arg method. It forwards to the
|
|
// transport-aware 4-arg form with "local" (RemoteTransportHost is always
|
|
// local); remote hosts that know their wire (PlainTransportHost) call the
|
|
// 4-arg form so a transport-sensitive validator (local_only tokens) can
|
|
// enforce it.
|
|
Q_INVOKABLE QVariant callRemoteMethod(const QString& authToken, const QString& methodName, const QVariantList& args = QVariantList());
|
|
Q_INVOKABLE QVariant callRemoteMethod(const QString& authToken, const QString& methodName, const QVariantList& args, const QString& transportProtocol);
|
|
Q_INVOKABLE bool informModuleToken(const QString& authToken, const QString& moduleName, const QString& token);
|
|
bool saveToken(const QString& from_module_name, const QString& token);
|
|
// getPluginInterface() returns the module's whole interface (methods AND
|
|
// events, each tagged with a "type"); getPluginMethods()/getPluginEvents()
|
|
// are the type-filtered views. All three derive from the provider's single
|
|
// getMethods() call — there is no separate getEvents() vtable method, which
|
|
// is what keeps the provider ABI stable across SDK versions.
|
|
Q_INVOKABLE QJsonArray getPluginMethods();
|
|
Q_INVOKABLE QJsonArray getPluginEvents();
|
|
Q_INVOKABLE QJsonArray getPluginInterface();
|
|
|
|
signals:
|
|
void eventResponse(const QString& eventName, const QVariantList& data);
|
|
|
|
private:
|
|
// Returns true when authToken matches a token THIS module has issued (via
|
|
// saveToken / informModuleToken) OR the host-installed validator accepts it
|
|
// for `transportProtocol`. Empty/unknown tokens are rejected. The built-in
|
|
// comparison is constant-time and never early-outs, so neither a correct
|
|
// prefix nor the number of issued tokens leaks through timing.
|
|
bool isAuthorized(const QString& authToken, const QString& transportProtocol) const;
|
|
|
|
LogosProviderObject* m_provider;
|
|
QHash<QString, QString> m_tokens;
|
|
TokenValidator m_validator;
|
|
};
|
|
|
|
#endif // MODULE_PROXY_H
|