fix: code quality, memory safety, and install improvements
Critical fixes: - Fix Dockerfile: reorder stages so frontend assets embed into Go binary - Fix Go version 1.25 (nonexistent) to 1.24 across Dockerfile, go.mod, CI - Add graceful game server shutdown on SIGTERM/SIGINT - Order startup tasks: updates complete before auto-start - Fix TOCTOU race in UpdateSettings with atomic Update() method Security: - Add optional AUTH_TOKEN bearer auth middleware on API/WS routes - Fix path traversal in DeleteMod using filepath.Rel instead of HasPrefix - Add input validation for IPPort, ServerParameters, ScheduledUpdate Memory safety: - Cap RPT buffer allocation to 64KB to prevent OOM on large logs - Cap GetLog file read to 10MB - Fix context cancel leak in SteamCmdManager.run() - Remove data-raced cancel field in steamcmd.go - Atomic file writes (write-temp-then-rename) across all managers Reliability: - Log save errors in ProcessManager.Stop() - Atomic file writes prevent corruption on crash Tests: - Add mod_manager_test.go (12 tests: ListWorkshopMods, ListLocalMods, BuildUsageMap, RemoveMod, dirSize) - Add scheduler_test.go (6 tests: Start/Stop, Refresh with empty, invalid, valid, and replaced cron expressions) - Add TestRestart to server_process_test.go CI/Docs: - Add -race flag to go test in CI and Makefile - Add npm lint step to CI - Add Go/npm module caching to CI - Update README: prerequisites, AUTH_TOKEN/GIN_MODE/SERVERS_DIR docs, fix manual quickstart to use make build
This commit is contained in:
@@ -195,7 +195,13 @@ func (h *Handler) StreamRPTLogs(c *gin.Context) {
|
||||
if _, err := f.Seek(currentOffset, io.SeekStart); err != nil {
|
||||
return nil
|
||||
}
|
||||
buf := make([]byte, fi.Size()-currentOffset)
|
||||
remaining := fi.Size() - currentOffset
|
||||
const maxBuf = 64 * 1024
|
||||
bufSize := remaining
|
||||
if bufSize > maxBuf {
|
||||
bufSize = maxBuf
|
||||
}
|
||||
buf := make([]byte, bufSize)
|
||||
n, _ := io.ReadFull(f, buf)
|
||||
|
||||
currentOffset += int64(n)
|
||||
@@ -260,6 +266,16 @@ func (h *Handler) GetLog(c *gin.Context) {
|
||||
}
|
||||
}
|
||||
|
||||
fi, err := os.Stat(path)
|
||||
if err != nil {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
const maxLogSize = 10 * 1024 * 1024
|
||||
if fi.Size() > maxLogSize {
|
||||
c.JSON(http.StatusRequestEntityTooLarge, gin.H{"error": "log file too large, use live streaming"})
|
||||
return
|
||||
}
|
||||
data, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
|
||||
Reference in New Issue
Block a user