From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-lf1-f65.google.com (mail-lf1-f65.google.com [209.85.167.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id 87F3444643B for ; Thu, 29 Oct 2020 11:37:34 +0300 (MSK) Received: by mail-lf1-f65.google.com with SMTP id l28so2196421lfp.10 for ; Thu, 29 Oct 2020 01:37:34 -0700 (PDT) From: Cyrill Gorcunov Date: Thu, 29 Oct 2020 11:37:07 +0300 Message-Id: <20201029083707.309206-3-gorcunov@gmail.com> In-Reply-To: <20201029083707.309206-1-gorcunov@gmail.com> References: <20201029083707.309206-1-gorcunov@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: [Tarantool-patches] [PATCH v2 2/2] raft: decode even invalid states of raft List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: tml Cc: Vladislav Shpilevoy We should never trust the request data it can carry anything, thus lets make sure we're not decoding some trash into a string. Signed-off-by: Cyrill Gorcunov --- src/box/lua/info.c | 2 +- src/box/raft.c | 29 +++++++++++++++++++++-------- src/box/raft.h | 6 +++++- 3 files changed, 27 insertions(+), 10 deletions(-) diff --git a/src/box/lua/info.c b/src/box/lua/info.c index cac3fd475..92d48c96c 100644 --- a/src/box/lua/info.c +++ b/src/box/lua/info.c @@ -582,7 +582,7 @@ static int lbox_info_election(struct lua_State *L) { lua_createtable(L, 0, 4); - lua_pushstring(L, raft_state_strs[raft.state]); + lua_pushstring(L, raft_state_str(raft.state)); lua_setfield(L, -2, "state"); luaL_pushuint64(L, raft.volatile_term); lua_setfield(L, -2, "term"); diff --git a/src/box/raft.c b/src/box/raft.c index 7c546de8c..e1e60ce94 100644 --- a/src/box/raft.c +++ b/src/box/raft.c @@ -44,13 +44,6 @@ */ #define RAFT_RANDOM_ELECTION_FACTOR 0.1 -const char *raft_state_strs[] = { - NULL, - "follower", - "candidate", - "leader", -}; - /** Raft state of this instance. */ struct raft raft = { .leader = 0, @@ -70,6 +63,26 @@ struct raft raft = { .election_timeout = 5, }; +/** + * When decoding we should never trust that there is + * a valid data incomes. + */ +const char * +raft_state_str(uint32_t state) +{ + static const char *str[] = { + [0] = "invalid (0)", + [RAFT_STATE_FOLLOWER] = "follower", + [RAFT_STATE_CANDIDATE] = "candidate", + [RAFT_STATE_LEADER] = "leader", + }; + + if (state < lengthof(str)) + return str[state]; + + return "invalid (x)"; +}; + /** * Check if Raft is completely synced with disk. Meaning all its critical values * are in WAL. Only in that state the node can become a leader or a candidate. @@ -291,7 +304,7 @@ raft_request_to_string(const struct raft_request *req) } if (req->state != 0) { rc = snprintf(pos, size, ", state: %s", - raft_state_strs[req->state]); + raft_state_str(req->state)); assert(rc >= 0 && rc < size); pos += rc; size -= rc; diff --git a/src/box/raft.h b/src/box/raft.h index 82d5aa442..8293d7410 100644 --- a/src/box/raft.h +++ b/src/box/raft.h @@ -87,7 +87,11 @@ enum raft_state { RAFT_STATE_LEADER = 3, }; -extern const char *raft_state_strs[]; +/** + * Decode raft state into string representation. + */ +const char * +raft_state_str(uint32_t state); struct raft { /** Instance ID of leader of the current term. */ -- 2.26.2