mysql selector commands: escape argv[] when used in a query.
[paraslash.git] / command.c
index 030289af8444ac35baddb8e10b30712a542768c9..7df01083b717bf5276d8223af1c57ab4d11d976f 100644 (file)
--- a/command.c
+++ b/command.c
@@ -44,7 +44,7 @@ static unsigned char rc4_buf[2 * RC4_KEY_LEN];
 extern const char *status_item_list[NUM_STAT_ITEMS];
 extern struct misc_meta_data *mmd;
 extern struct gengetopt_args_info conf;
-extern struct audio_file_selector dblist[];
+extern struct audio_file_selector selectors[];
 extern struct audio_format afl[];
 extern struct sender senders[];
 extern char *user_list;
@@ -426,7 +426,7 @@ static char *get_status(struct misc_meta_data *nmmd)
                status_item_list[SI_STATUS_BAR], bar ? bar : "(none)",
                status_item_list[SI_STATUS], status,
                status_item_list[SI_STATUS_FLAGS], flags,
-               status_item_list[SI_SELECTOR], dblist[nmmd->selector_num].name,
+               status_item_list[SI_SELECTOR], selectors[nmmd->selector_num].name,
 
                status_item_list[SI_OFFSET], offset,
                status_item_list[SI_FORMAT], audio_format_name(nmmd->audio_format),
@@ -453,22 +453,21 @@ static int check_sender_args(int argc, char **argv, struct sender_command_data *
        const char *subcmds[] = {"add", "delete", "allow", "deny", "on", "off", NULL};
 
        scd->sender_num = -1;
-       if (argc < 0)
+       if (argc < 2)
                return -E_COMMAND_SYNTAX;
        for (i = 0; senders[i].name; i++)
-               if (!strcmp(senders[i].name, argv[0]))
+               if (!strcmp(senders[i].name, argv[1]))
                        break;
-//     PARA_DEBUG_LOG("%d:%s\n", argc, argv[0]);
+       PARA_DEBUG_LOG("%d:%s\n", argc, argv[1]);
        if (!senders[i].name)
                return -E_COMMAND_SYNTAX;
        scd->sender_num = i;
        for (i = 0; subcmds[i]; i++)
-               if (!strcmp(subcmds[i], argv[1]))
+               if (!strcmp(subcmds[i], argv[2]))
                        break;
        if (!subcmds[i])
                return -E_COMMAND_SYNTAX;
        scd->cmd_num = i;
-//     scd->self = *in_addr;
        mmd_lock();
        if (!senders[scd->sender_num].client_cmds[scd->cmd_num]) {
                mmd_unlock();
@@ -478,31 +477,31 @@ static int check_sender_args(int argc, char **argv, struct sender_command_data *
        switch (scd->cmd_num) {
        case SENDER_ON:
        case SENDER_OFF:
-               if (argc != 1)
+               if (argc != 3)
                        return -E_COMMAND_SYNTAX;
                break;
        case SENDER_DENY:
        case SENDER_ALLOW:
-               if (argc != 2 && argc != 3)
+               if (argc != 4 && argc != 5)
                        return -E_COMMAND_SYNTAX;
-               if (!inet_aton(argv[2], &scd->addr))
+               if (!inet_aton(argv[3], &scd->addr))
                        return -E_COMMAND_SYNTAX;
                scd->netmask = 32;
-               if (argc == 3) {
-                       scd->netmask = atoi(argv[3]);
+               if (argc == 5) {
+                       scd->netmask = atoi(argv[4]);
                        if (scd->netmask < 0 || scd->netmask > 32)
                                return -E_COMMAND_SYNTAX;
                }
                break;
        case SENDER_ADD:
        case SENDER_DELETE:
-               if (argc != 2 && argc != 3)
+               if (argc != 4 && argc != 5)
                        return -E_COMMAND_SYNTAX;
-               if (!inet_aton(argv[2], &scd->addr))
+               if (!inet_aton(argv[3], &scd->addr))
                        return -E_COMMAND_SYNTAX;
                scd->port = -1;
-               if (argc == 3) {
-                       scd->port = atoi(argv[3]);
+               if (argc == 5) {
+                       scd->port = atoi(argv[4]);
                        if (scd->port < 0 || scd->port > 65535)
                                return -E_COMMAND_SYNTAX;
                }
@@ -518,7 +517,7 @@ static int com_sender(int fd, int argc, char **argv)
        int i, ret;
        struct sender_command_data scd;
 
-       if (!argc) {
+       if (argc < 2) {
                char *msg = NULL;
                for (i = 0; senders[i].name; i++) {
                        char *tmp = make_message("%s%s\n",
@@ -530,7 +529,7 @@ static int com_sender(int fd, int argc, char **argv)
                free(msg);
                return ret;
        }
-       ret = check_sender_args(argc - 1, argv + 1, &scd);
+       ret = check_sender_args(argc, argv, &scd);
        if (ret < 0) {
                char *msg;
                if (scd.sender_num < 0)
@@ -559,15 +558,15 @@ static int com_si(int fd, int argc, __unused char **argv)
 {
        int i, ret;
        char *ut;
-       char *selectors = NULL, *sender_info = NULL, *sender_list = NULL;
+       char *selector_string = NULL, *sender_info = NULL, *sender_list = NULL;
        struct mallinfo mi = mallinfo();
 
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
-       for (i = 0; dblist[i].name; i++) {
-               selectors = para_strcat(selectors, dblist[i].name);
-               selectors = para_strcat(selectors, " ");
+       for (i = 0; selectors[i].name; i++) {
+               selector_string = para_strcat(selector_string, selectors[i].name);
+               selector_string = para_strcat(selector_string, " ");
        }
        for (i = 0; senders[i].name; i++) {
                char *info = senders[i].info();
@@ -593,14 +592,14 @@ static int com_si(int fd, int argc, __unused char **argv)
                mmd->num_commands,
                mmd->num_connects,
                conf.loglevel_arg,
-               selectors,
+               selector_string,
                SUPPORTED_AUDIO_FORMATS,
                sender_list,
                sender_info
        );
        mmd_unlock();
        free(ut);
-       free(selectors);
+       free(selector_string);
        free(sender_list);
        free(sender_info);
        return ret;
@@ -609,7 +608,7 @@ static int com_si(int fd, int argc, __unused char **argv)
 /* version */
 static int com_version(int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        return send_buffer(socket_fd, "para_server-" VERSION ", \"" CODENAME "\"\n"
                        COPYRIGHT "\n"
@@ -624,7 +623,7 @@ static int com_sc(int socket_fd, int argc, char **argv)
        char *name = NULL;
        int ret, old = 0, count = -1; /* print af change forever */
 
-       if (argc)
+       if (argc > 1)
                count = atoi(argv[1]);
 repeat:
        mmd_lock();
@@ -639,7 +638,7 @@ repeat:
                name = NULL;
                if (ret < 0)
                        return ret;
-               if (argc && !--count)
+               if (argc > 1 && !--count)
                        return 1;
        }
        usleep(500000);
@@ -654,7 +653,7 @@ static int com_sb(int socket_fd, int argc, char **argv)
                                 * times. Negative value means: print
                                 * forever
                                 */
-       if (argc)
+       if (argc > 1)
                nr = atoi(argv[1]);
        while (nr) {
                mmd_lock();
@@ -684,7 +683,7 @@ static int com_stat(int socket_fd, int argc, char **argv)
 
        signal(SIGUSR1, dummy);
 
-       if (argc)
+       if (argc > 1)
                num = atoi(argv[1]);
        for (;;) {
 
@@ -720,7 +719,7 @@ static int send_description(int fd, struct server_command *cmd, const char *hand
        return 1;
 }
 
-/* always returns string that must be freed by the caller in handeler */
+/* always returns string that must be freed by the caller in handler */
 static struct server_command *get_cmd_ptr(char *name, char **handler)
 {
        struct server_command *cmd = cmd_struct;
@@ -735,8 +734,8 @@ static struct server_command *get_cmd_ptr(char *name, char **handler)
        mmd_lock();
        if (handler)
                *handler = make_message("the %s selector",
-                       dblist[mmd->selector_num].name);
-       cmd = dblist[mmd->selector_num].cmd_list;
+                       selectors[mmd->selector_num].name);
+       cmd = selectors[mmd->selector_num].cmd_list;
        mmd_unlock();
        for (; cmd->name; cmd++)
                if (!strcmp(cmd->name, name))
@@ -751,13 +750,13 @@ static int com_help(int fd, int argc, char **argv)
        char *perms, *handler;
        int ret;
 
-       if (!argc) {
+       if (argc < 2) {
                /* no argument given, print list of commands */
                if ((ret = send_description(fd, cmd_struct, "server", 0)) < 0)
                        return ret;
                mmd_lock();
-               handler = para_strdup(dblist[mmd->selector_num].name);
-               cmd = dblist[mmd->selector_num].cmd_list;
+               handler = para_strdup(selectors[mmd->selector_num].name);
+               cmd = selectors[mmd->selector_num].cmd_list;
                mmd_unlock();
                ret = send_description(fd, cmd, handler, 0);
                free(handler);
@@ -794,7 +793,7 @@ static int com_help(int fd, int argc, char **argv)
 /* hup */
 static int com_hup(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        kill(getppid(), SIGHUP);
        return 1;
@@ -803,7 +802,7 @@ static int com_hup(__unused int socket_fd, int argc, __unused char **argv)
 /* term */
 static int com_term(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        kill(getppid(), SIGTERM);
        return 1;
@@ -811,7 +810,7 @@ static int com_term(__unused int socket_fd, int argc, __unused char **argv)
 
 static int com_play(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
        mmd->new_afs_status_flags |= AFS_PLAYING;
@@ -824,7 +823,7 @@ static int com_play(__unused int socket_fd, int argc, __unused char **argv)
 /* stop */
 static int com_stop(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
        mmd->new_afs_status_flags &= ~AFS_PLAYING;
@@ -837,7 +836,7 @@ static int com_stop(__unused int socket_fd, int argc, __unused char **argv)
 /* pause */
 static int com_pause(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
        if (!afs_paused())
@@ -852,17 +851,17 @@ static int com_chs(int fd, int argc, char **argv)
 {
        int i, ret;
 
-       if (!argc) {
+       if (argc == 1) {
                char *selector;
                mmd_lock();
-               selector = para_strdup(dblist[mmd->selector_num].name);
+               selector = para_strdup(selectors[mmd->selector_num].name);
                mmd_unlock();
                ret = send_va_buffer(fd, "%s\n", selector);
                free(selector);
                return ret;
        }
-       for (i = 0; dblist[i].name; i++) {
-               if (strcmp(dblist[i].name, argv[1]))
+       for (i = 0; selectors[i].name; i++) {
+               if (strcmp(selectors[i].name, argv[1]))
                        continue;
                mmd_lock();
                mmd->selector_change = i;
@@ -876,7 +875,7 @@ static int com_chs(int fd, int argc, char **argv)
 /* next */
 static int com_next(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
        mmd->events++;
@@ -888,7 +887,7 @@ static int com_next(__unused int socket_fd, int argc, __unused char **argv)
 /* nomore */
 static int com_nomore(__unused int socket_fd, int argc, __unused char **argv)
 {
-       if (argc)
+       if (argc != 1)
                return -E_COMMAND_SYNTAX;
        mmd_lock();
        if (afs_playing() || afs_paused())
@@ -905,7 +904,7 @@ static int com_ff(__unused int socket_fd, int argc, char **argv)
        unsigned i;
        char c;
 
-       if (!argc)
+       if (argc != 2)
                return -E_COMMAND_SYNTAX;
        if (!(ret = sscanf(argv[1], "%u%c", &i, &c)))
                return -E_COMMAND_SYNTAX;
@@ -942,7 +941,7 @@ static int com_jmp(__unused int socket_fd, int argc, char **argv)
        long unsigned int i;
        int ret;
 
-       if (!argc)
+       if (argc != 2)
                return -E_COMMAND_SYNTAX;
        if (sscanf(argv[1], "%lu", &i) <= 0)
                return -E_COMMAND_SYNTAX;
@@ -1204,7 +1203,7 @@ int handle_connect(int fd, struct sockaddr_in *addr)
                goto err_out;
        /* valid command and sufficient perms */
        alarm(0);
-       argc = split_args(command, &argv, '\n');
+       argc = split_args(command, &argv, "\n");
        mmd_lock();
        mmd->num_commands++;
        mmd_unlock();