lua sandbox code reformatting

Remove a ton of tabs in nhlua.c and add missing whitespace to a bunch
of 'if(test){' lines and to a few casts.

Also simplify? obj handling during garbage collection (does not fix
the current gc problem) in nhlobj.c.
This commit is contained in:
PatR
2022-05-28 12:35:44 -07:00
parent 5622a4a848
commit 3c402fb312
2 changed files with 313 additions and 313 deletions
+10 -10
View File
@@ -45,26 +45,26 @@ l_obj_check(lua_State *L, int indx)
static int
l_obj_gc(lua_State *L)
{
struct obj *obj, *otmp;
struct _lua_obj *lo = l_obj_check(L, 1);
if (lo && lo->obj) {
if (lo->obj->lua_ref_cnt > 0)
lo->obj->lua_ref_cnt--;
if (lo && (obj = lo->obj) != 0) {
if (obj->lua_ref_cnt > 0)
obj->lua_ref_cnt--;
/* free-floating objects with no other refs are deallocated. */
if (!lo->obj->lua_ref_cnt
&& (lo->obj->where == OBJ_FREE || lo->obj->where == OBJ_LUAFREE)) {
if (Has_contents(lo->obj)) {
struct obj *otmp;
while ((otmp = lo->obj->cobj) != 0) {
if (!obj->lua_ref_cnt
&& (obj->where == OBJ_FREE || obj->where == OBJ_LUAFREE)) {
if (Has_contents(obj)) {
while ((otmp = obj->cobj) != 0) {
obj_extract_self(otmp);
dealloc_obj(otmp);
}
}
dealloc_obj(lo->obj);
obj->where = OBJ_FREE;
dealloc_obj(obj), obj = 0;
}
lo->obj = NULL;
}
return 0;
}
+98 -98
View File
@@ -1429,7 +1429,7 @@ init_u_data(lua_State *L)
static int
nhl_set_package_path(lua_State *L, const char *path)
{
if (LUA_TTABLE != lua_getglobal(L, "package")){
if (LUA_TTABLE != lua_getglobal(L, "package")) {
impossible("package not a table in nhl_set_package_path");
return 1;
};
@@ -1460,9 +1460,10 @@ nhl_pcall(lua_State *L, int nargs, int nresults)
lua_insert(L, 1);
(void)lua_getallocf(L, (void **)&nud);
#ifdef NHL_SANDBOX
if(nud && (nud->steps || nud->perpcall)){
if(nud->perpcall) nud->steps = nud->perpcall;
if(setjmp(nud->jb)){
if (nud && (nud->steps || nud->perpcall)) {
if (nud->perpcall)
nud->steps = nud->perpcall;
if (setjmp(nud->jb)) {
/* panic, because we don't know if the game state is corrupt */
panic("time exceeded");
}
@@ -1470,22 +1471,18 @@ nhl_pcall(lua_State *L, int nargs, int nresults)
#endif
rv = lua_pcall(L, nargs, nresults, 1);
lua_remove(L, 1); // remove handler
lua_remove(L, 1); /* remove handler */
#ifdef NHL_SANDBOX
if(nud
&& (nud->flags & (NHL_SB_REPORT|NHL_SB_REPORT2))
&& (nud->memlimit || nud->osteps || nud->perpcall)
){
if(nud->flags & NHL_SB_REPORT2)
if (nud && (nud->flags & (NHL_SB_REPORT | NHL_SB_REPORT2)) != 0
&& (nud->memlimit || nud->osteps || nud->perpcall)) {
if (nud->flags & NHL_SB_REPORT2)
lua_gc(L, LUA_GCCOLLECT);
pline("Lua context=%p RAM: %lu STEPS:%lu",
(void *)L,
(unsigned long)nud->inuse,
(unsigned long)(nud->perpcall
pline("Lua context=%p RAM: %lu STEPS:%lu", (void *) L,
(unsigned long) nud->inuse,
(unsigned long) (nud->perpcall
? (nud->perpcall - nud->steps)
: (nud->osteps - nud->steps))
);
: (nud->osteps - nud->steps)));
}
#endif
@@ -1588,7 +1585,7 @@ nhl_loadlua(lua_State *L, const char *fname)
ret = FALSE;
goto give_up;
} else {
if(nhl_pcall(L, 0, LUA_MULTRET)) {
if (nhl_pcall(L, 0, LUA_MULTRET)) {
impossible("Lua error: %s", lua_tostring(L, -1));
ret = FALSE;
goto give_up;
@@ -1615,7 +1612,7 @@ nhl_init(nhl_sandbox_info *sbi)
#endif
#ifdef NHL_SANDBOX
if(NHL_VERSION_EXPECTED != LUA_VERSION_RELEASE_NUM){
if (NHL_VERSION_EXPECTED != LUA_VERSION_RELEASE_NUM) {
panic(
"sandbox doesn't know this Lua version: this=%d != expected=%d ",
LUA_VERSION_RELEASE_NUM, NHL_VERSION_EXPECTED);
@@ -1636,10 +1633,9 @@ nhl_init(nhl_sandbox_info *sbi)
#ifdef notyet
if (sbi->flags & NHL_SB_PACKAGE) {
/* XXX Is this still needed? */
if (nhl_set_package_path(L, "./?.lua")){
if (nhl_set_package_path(L, "./?.lua"))
return 0;
}
}
#endif
/* register nh -table, and functions for it */
@@ -1659,7 +1655,7 @@ nhl_init(nhl_sandbox_info *sbi)
l_obj_register(L);
/* nhlib.lua assumes the math table exists. */
if(LUA_TTABLE != lua_getglobal(L, "math")){
if (LUA_TTABLE != lua_getglobal(L, "math")) {
lua_newtable(L);
lua_setglobal(L, "math");
}
@@ -1876,11 +1872,11 @@ static struct e ct_os_files[] = {
static void
nhl_clearfromtable(lua_State *L, int flag, int tndx, struct e *todo)
{
while(todo->when != EOT){
while (todo->when != EOT) {
lua_pushnil(L);
/* if we load the library at all, NEVER items must be erased
* and IFFLAG items should be erased if !flag */
if(todo->when==NEVER || !flag) {
if (todo->when == NEVER || !flag) {
lua_setfield(L, tndx, todo->fnname);
}
todo++;
@@ -1931,16 +1927,15 @@ start_luapat(void)
/* XXX set memory and step limits */
nhl_sandbox_info sbi = {NHL_SB_STRING, 0, 0, 0};
if((luapat = nhl_init(&sbi)) == NULL)
if ((luapat = nhl_init(&sbi)) == NULL)
return FALSE;
/* load a pattern matching function */
rv = luaL_loadstring(luapat,
"function matches(s,p) return not not string.match(s,p) end");
if(rv != LUA_OK){
if (rv != LUA_OK) {
panic("start_luapat: %d",rv);
}
return TRUE;
}
#endif
@@ -1948,7 +1943,7 @@ start_luapat(void)
static void
end_luapat(void)
{
if(luapat){
if (luapat) {
lua_close(luapat);
luapat = NULL;
}
@@ -1973,13 +1968,13 @@ opencheckpat(lua_State *L, const char *ename, int param)
string = lua_tolstring(L, -1, NULL); /* -0,+0 */
lua_pushstring(luapat, string); /* -0,+1 */
if(nhl_pcall(luapat, 2, 1)){ /* -3,+1 */
if (nhl_pcall(luapat, 2, 1)) { /* -3,+1 */
/* impossible("access check internal error"); */
return NHL_SBRV_FAIL;
}
rv = lua_toboolean(luapat, -1); /* -0,+0 */
#if 0
if(lua_resetthread(luapat) != LUA_OK)
if (lua_resetthread(luapat) != LUA_OK)
return NHL_SBRV_FAIL;
is pop sufficient? XXX or wrong - look at the balance
#else
@@ -1998,7 +1993,8 @@ static int (*io_open)(lua_State *) = NULL; /* XXX this may have to be in g T
#endif
void
nhl_pushhooked_open_table(lua_State *L){
nhl_pushhooked_open_table(lua_State *L)
{
int hot = lua_getfield(L, LUA_REGISTRYINDEX, HOOKTBLNAME);
if (hot == LUA_TNONE) {
lua_newtable(L);
@@ -2009,45 +2005,44 @@ nhl_pushhooked_open_table(lua_State *L){
#ifdef notyet
static int
hooked_open(lua_State *L){
hooked_open(lua_State *L)
{
const char *mode;
static boolean never = TRUE;
const char *filename;
int params;
int hot;
if (never){
if(!start_luapat())
if (never) {
if (!start_luapat())
return NHL_SBRV_FAIL;
never = FALSE;
}
filename = luaL_checkstring(L, 1);
/* Unlike io.open, we want to treat mode as non-optional. */
if (lua_gettop(L) < 2){
if (lua_gettop(L) < 2) {
lua_pushstring(L, "r");
}
mode = luaL_optstring(L, 2, "r");
/* sandbox checks */
/* Do we need some ud from the calling state to let this be different
for each call without redoing the HO table?? Maybe for version 2. XXX */
/* Do we need some ud from the calling state to let this be different for
each call without redoing the HO table?? Maybe for version 2. XXX */
params = lua_gettop(L)-1; /* point at first param */
nhl_pushhooked_open_table(L);
hot = lua_gettop(L);
if(lua_type(L, hot) == LUA_TTABLE){
if (lua_type(L, hot) == LUA_TTABLE) {
int idx;
for(
idx=1;
for (idx = 1;
lua_pushinteger(L, idx),
lua_geti(L, hot, idx),
!lua_isnoneornil(L, -1);
idx++
){
++idx) {
/* top of stack is our configtbl[idx] */
switch(lua_type(L, -1)){
switch (lua_type(L, -1)) {
/* lots of options to expand this with other types XXX */
case LUA_TTABLE: {
int moderv, filerv;
@@ -2057,10 +2052,10 @@ hooked_open(lua_State *L){
filerv = opencheckpat(L, "filepat", params);
if (filerv == NHL_SBRV_FAIL)
return moderv;
if(filerv == moderv){
if(filerv == NHL_SBRV_DENY)
if (filerv == moderv) {
if (filerv == NHL_SBRV_DENY)
return NHL_SBRV_DENY;
if(filerv == NHL_SBRV_ACCEPT)
if (filerv == NHL_SBRV_ACCEPT)
goto doopen;
}
break; /* try next entry */
@@ -2072,22 +2067,25 @@ hooked_open(lua_State *L){
} else
return NHL_SBRV_DENY; /* default to "no" */
doopen:
doopen:
lua_settop(L, params+1);
return (*io_open)(L);
}
static boolean
hook_open(lua_State *L){
hook_open(lua_State *L)
{
boolean rv = FALSE;
if(!io_open){
if (!io_open) {
int tos = lua_gettop(L);
lua_pushglobaltable(L);
if(lua_getfield(L, -1, "io") != LUA_TTABLE) goto out;
if (lua_getfield(L, -1, "io") != LUA_TTABLE)
goto out;
lua_getfield(L, -1, "open");
/* The only way this can happen is if someone is messing with us,
* and I'm not sure even that is possible. */
if(!lua_iscfunction(L, -1)) goto out;
if (!lua_iscfunction(L, -1))
goto out;
/* XXX This is fragile: C11 says casting func* to void*
* doesn't have to work, but POSIX says it does. So it
* _should_ work everywhere but all we can do without messing
@@ -2096,7 +2094,7 @@ hook_open(lua_State *L){
lua_pushcfunction(L, hooked_open);
lua_setfield(L, -1, "open");
rv = TRUE;
out:
out:
lua_settop(L, tos);
}
return rv;
@@ -2107,22 +2105,23 @@ DISABLE_WARNING_CONDEXPR_IS_CONSTANT
#ifdef NHL_SANDBOX
static void
nhlL_openlibs(lua_State *L, uint32_t lflags){
nhlL_openlibs(lua_State *L, uint32_t lflags)
{
/* translate lflags from user-friendly to internal */
if (NHL_SB_DEBUGGING & lflags){
if (NHL_SB_DEBUGGING & lflags) {
lflags |= NHL_SB_DB_SAFE;
}
/* only for debugging the sandbox integration */
if (NHL_SB_ALL & lflags){
if (NHL_SB_ALL & lflags) {
lflags = -1;
} else if (NHL_SB_SAFE & lflags){
} else if (NHL_SB_SAFE & lflags) {
lflags |= NHL_SB_BASE_BASE;
lflags |= NHL_SB_COROUTINE;
lflags |= NHL_SB_TABLE;
lflags |= NHL_SB_STRING;
lflags |= NHL_SB_MATH;
lflags |= NHL_SB_UTF8;
} else if (NHL_SB_VERSION){
} else if (NHL_SB_VERSION) {
lflags |= NHL_SB_BASE_BASE;
}
#ifdef notyet
@@ -2158,7 +2157,7 @@ UNSAFEIO:
*/
#endif
if(lflags & NHL_SB_BASEMASK){
if (lflags & NHL_SB_BASEMASK) {
int baselib;
/* load the entire library ... */
luaL_requiref(L, LUA_GNAME, luaopen_base, 1);
@@ -2175,23 +2174,23 @@ UNSAFEIO:
lua_pop(L, 1);
}
if(lflags & NHL_SB_COROUTINE){
if (lflags & NHL_SB_COROUTINE) {
luaL_requiref(L, LUA_COLIBNAME, luaopen_coroutine, 1);
lua_pop(L, 1);
}
if(lflags & NHL_SB_TABLE){
if (lflags & NHL_SB_TABLE) {
luaL_requiref(L, LUA_TABLIBNAME, luaopen_table, 1);
lua_pop(L, 1);
}
#ifdef notyet
if(lflags & NHL_SB_IO){
if (lflags & NHL_SB_IO) {
luaL_requiref(L, LUA_IOLIBNAME, luaopen_io, 1);
lua_pop(L, 1);
if(!hook_open(L))
if (!hook_open(L))
panic("can't hook io.open");
}
#endif
if(lflags & NHL_SB_OSMASK){
if (lflags & NHL_SB_OSMASK) {
int oslib;
luaL_requiref(L, LUA_OSLIBNAME, luaopen_os, 1);
oslib = lua_gettop(L);
@@ -2200,22 +2199,22 @@ UNSAFEIO:
lua_pop(L, 1);
}
if(lflags & NHL_SB_STRING){
if (lflags & NHL_SB_STRING) {
luaL_requiref(L, LUA_STRLIBNAME, luaopen_string, 1);
lua_pop(L, 1);
}
if(lflags & NHL_SB_MATH){
if (lflags & NHL_SB_MATH) {
luaL_requiref(L, LUA_MATHLIBNAME, luaopen_math, 1);
/* XXX Note that math.random uses Lua's built-in xoshiro256**
* algorithm regardless of what the rest of the game uses.
* Fixing this would require changing lmathlib.c. */
lua_pop(L, 1);
}
if(lflags & NHL_SB_UTF8){
if (lflags & NHL_SB_UTF8) {
luaL_requiref(L, LUA_UTF8LIBNAME, luaopen_utf8, 1);
lua_pop(L, 1);
}
if(lflags & NHL_SB_DBMASK){
if (lflags & NHL_SB_DBMASK) {
int dblib;
luaL_requiref(L, LUA_DBLIBNAME, luaopen_debug, 1);
dblib = lua_gettop(L);
@@ -2236,47 +2235,51 @@ RESTORE_WARNING_CONDEXPR_IS_CONSTANT
* it's worth the processing time), it can be overridden.
*/
#ifndef NHL_ALLOC_ADJUST
#define NHL_ALLOC_ADJUST(d) d = ((d+15) & ~15)
#define NHL_ALLOC_ADJUST(d) d = (((d) + 15) & ~15)
#endif
static void *
nhl_alloc (void *ud, void *ptr, size_t osize, size_t nsize) {
nhl_alloc(void *ud, void *ptr, size_t osize, size_t nsize)
{
nhl_user_data *nud = ud;
if(nud && nud->memlimit){ /* this state is size limited */
uint32_t delta;
if(!ptr){
delta = nsize;
} else {
delta = nsize-osize;
}
if (nud && nud->memlimit) { /* this state is size limited */
uint32_t delta = !ptr ? nsize : nsize - osize;
NHL_ALLOC_ADJUST(delta);
nud->inuse += delta;
if(nud->inuse > nud->memlimit){
if (nud->inuse > nud->memlimit)
return 0;
}
}
if (nsize == 0) {
free(ptr);
return NULL;
} else
}
/*
* FIXME:
* Use of realloc() confuses MONITOR_HEAP.
*/
return realloc(ptr, nsize);
}
static int
nhl_panic (lua_State *L) {
nhl_panic(lua_State *L)
{
const char *msg = lua_tostring(L, -1);
if (msg == NULL) msg = "error object is not a string";
if (msg == NULL)
msg = "error object is not a string";
panic("unprotected error in call to Lua API (%s)\n", msg);
return 0; /* return to Lua to abort */
}
#ifdef NHL_SANDBOX
static void
nhl_hookfn(lua_State *L, lua_Debug *ar UNUSED){
nhl_hookfn(lua_State *L, lua_Debug *ar UNUSED)
{
nhl_user_data *nud;
(void)lua_getallocf(L, (void **)&nud);
(void) lua_getallocf(L, (void **) &nud);
if (nud->steps <= NHL_SB_STEPSIZE)
longjmp(nud->jb, 1);
@@ -2286,41 +2289,36 @@ nhl_hookfn(lua_State *L, lua_Debug *ar UNUSED){
#endif
static lua_State *
nhlL_newstate (nhl_sandbox_info *sbi) {
nhlL_newstate(nhl_sandbox_info *sbi)
{
nhl_user_data *nud = 0;
if(sbi->memlimit || sbi->steps){
nud = nhl_alloc(NULL, NULL, 0, sizeof(struct nhl_user_data));
if(!nud)
if (sbi->memlimit || sbi->steps) {
nud = nhl_alloc(NULL, NULL, 0, sizeof (struct nhl_user_data));
if (!nud)
return 0;
nud->memlimit = sbi->memlimit;
nud->perpcall = 0; /* set up below, if needed */
nud->steps = 0;
nud->osteps = 0;
nud->flags = sbi->flags; /* save reporting flags */
uint32_t sz = sizeof(struct nhl_user_data);
uint32_t sz = sizeof (struct nhl_user_data);
NHL_ALLOC_ADJUST(sz);
nud->inuse = sz;
}
lua_State *L = lua_newstate(nhl_alloc, nud);
#if LUA_VERSION_NUM == 503
# define luai_likely(x) (x)
#endif
if (luai_likely(L)) {
lua_atpanic(L, &nhl_panic);
lua_atpanic(L, nhl_panic);
#if LUA_VERSION_NUM == 504
/* no warning system at the moment - it requires concatenting
* strings to fit NetHack's API XXX */
lua_setwarnf(L, 0, L); /* default is warnings off */
lua_setwarnf(L, (lua_WarnFunction) 0, L);
#endif
}
#ifdef NHL_SANDBOX
if (sbi->steps || sbi->perpcall){
if (sbi->steps || sbi->perpcall) {
if (sbi->steps && sbi->perpcall)
impossible("steps and perpcall both non-zero");
if (sbi->perpcall){
if (sbi->perpcall) {
nud->perpcall = sbi->perpcall;
} else {
nud->steps = sbi->steps;
@@ -2371,3 +2369,5 @@ BUT how do we compact the current history?
new branch, then compress there
XXX
*/
/*nhlua.c*/