Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 25 additions & 17 deletions .github/workflows/abi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,13 +47,13 @@ jobs:
run: |
cd gitview_pr
mkdir _build && cd _build
cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache ../
cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DENABLE_BONDING=1 -DENABLE_PKTINFO=1 -DENABLE_MAXREXMITBW=1 ../
- id: build
name: Build and dump
run: |
sudo apt install -y abi-dumper
sudo apt install -y tcl
cd gitview_pr/_build && cmake --build ./
sudo apt install -y abi-dumper abi-compliance-checker tcl
cd gitview_pr
cd _build && cmake --build ./
make install DESTDIR=./installdir
SRT_TAG_VERSION=v$(../scripts/get-build-version.tcl full)
echo "SRT_TAG_VERSION=$SRT_TAG_VERSION" >> "$GITHUB_OUTPUT"
Expand Down Expand Up @@ -119,7 +119,7 @@ jobs:
fi
cd gitview_base
mkdir _build && cd _build
cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache ../
cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DENABLE_BONDING=1 -DENABLE_PKTINFO=1 -DENABLE_MAXREXMITBW=1 ../
- id: build_tag
name: Build and dump
if: ${{ success() }}
Expand Down Expand Up @@ -168,22 +168,30 @@ jobs:
path: .
- name: abi-check
run: |
git clone https://github.com/lvc/abi-compliance-checker.git
#cd gitview_pr/submodules
#git submodule update --init abi-compliance-checker
cd abi-compliance-checker && sudo make install && cd ../
#cd ../..
sudo apt install -y abi-dumper abi-compliance-checker tcl
echo "FILESYSTEM state before running abi-check at $PWD"
ls -l
sha256sum libsrt-base.dump
sha256sum libsrt-pr.dump
abi-compliance-checker -l libsrt -old libsrt-base.dump -new libsrt-pr.dump
RES=$?
if (( RES != 0 )); then
echo "ABI/API Compatibility check failed with value $?"
exit $RES
RES=0
abi-compliance-checker -l libsrt -old libsrt-base.dump -new libsrt-pr.dump || RES=$?
# Flatten the report for download-preview
cd compat_reports
REPORT=$(find . -name *.html)
cp $REPORT compat_report.html
cd ..
if (( $RES != 0 )); then
echo "ABI/API Compatibility check failed with value $RES"
echo "RES=$RES" >>$GITHUB_ENV
exit 0
fi
- name: Download report
uses: actions/download-artifact@v8
uses: actions/upload-artifact@v7
with:
path: compat_reports
name: abi-compliance-report
path: compat_reports/compat_report.html
archive: false
- name: Final result
run: |
echo "Final result: $RES"
exit $RES
11 changes: 3 additions & 8 deletions .github/workflows/ubuntu-c++03.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,14 +38,13 @@ jobs:
- name: Set up ccache
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends ccache
sudo apt-get install -y --no-install-recommends ccache tcl cmake libssl-dev gdb
ccache --max-size=200M
ccache --zero-stats
- name: configure
run: |
sudo apt install -y tcl cmake libssl-dev gdb
mkdir _build && cd _build
cmake ../ -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DCMAKE_COMPILE_WARNING_AS_ERROR=ON -DENABLE_STDCXX_SYNC=OFF -DUSE_CXX_STD=03 -DENABLE_ENCRYPTION=ON -DENABLE_UNITTESTS=ON -DENABLE_BONDING=${{ matrix.bonding }} -DENABLE_TESTING=ON -DENABLE_EXAMPLES=ON -DENABLE_CODE_COVERAGE=ON -DCMAKE_EXPORT_COMPILE_COMMANDS=ON -DENABLE_LOGGING=${{ matrix.logging }}
cmake ../ -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DCMAKE_COMPILE_WARNING_AS_ERROR=ON -DENABLE_STDCXX_SYNC=OFF -DUSE_CXX_STD=03 -DENABLE_ENCRYPTION=ON -DENABLE_UNITTESTS=ON -DENABLE_BONDING=${{ matrix.bonding }} -DENABLE_TESTING=ON -DENABLE_EXAMPLES=ON -DCMAKE_EXPORT_COMPILE_COMMANDS=ON -DENABLE_LOGGING=${{ matrix.logging }}
- name: build
# That below is likely SonarQube remains, which was removed earlier.
#run: cd _build && build-wrapper-linux-x86-64 --out-dir ${{ env.BUILD_WRAPPER_OUT_DIR }} cmake --build .
Expand All @@ -56,7 +55,7 @@ jobs:
ulimit -c unlimited
cd _build && ctest --extra-verbose
SUCCESS=$?
if [ -f core.test-srt ]; then gdb -batch ./test-srt -c core -ex bt -ex "info thread" -ex quit; else echo "NO CORE - NO CRY!"; fi;
if [ -f core.test-srt ]; then gdb -batch ./test-srt -c core.test-srt -ex bt -ex "info thread" -ex quit; else echo "NO CORE - NO CRY!"; fi;
test $SUCCESS == 0;
- name: Save ccache
if: ${{ success() && github.event_name != 'pull_request' }}
Expand All @@ -67,7 +66,3 @@ jobs:
- name: Show ccache statistics
if: always()
run: ccache --show-stats
- name: codecov
run: |
source ./scripts/collect-gcov.sh
bash <(curl -s https://codecov.io/bash)
17 changes: 12 additions & 5 deletions .github/workflows/ubuntu-c++11.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,10 +36,13 @@ jobs:
restore-keys: srt-ccache-cxx11-${{ runner.os }}-${{ runner.arch }}-
- name: prepare
run: |
sudo apt update
RUNON=${{ matrix.machine }}
if [[ $RUNON == ubuntu-latest ]]; then
sudo apt install -y gdb
fi
sudo apt install -y tcl cmake
[[ $RUNON == ubuntu-24.04-arm ]] || sudo apt install libssl-dev
- name: Set up ccache
run: |
sudo apt-get update
Expand All @@ -52,7 +55,7 @@ jobs:
ENCRYPTION=ON
[[ $RUNON == ubuntu-24.04-arm ]] && ENCRYPTION=OFF
mkdir _build && cd _build
cmake ../ -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DCMAKE_COMPILE_WARNING_AS_ERROR=ON -DUSE_CXX_STD=11 -DENABLE_STDCXX_SYNC=ON -DENABLE_ENCRYPTION=$ENCRYPTION -DENABLE_UNITTESTS=ON -DENABLE_BONDING=ON -DENABLE_TESTING=ON -DENABLE_EXAMPLES=ON -DENABLE_CODE_COVERAGE=ON -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
cmake ../ -DCMAKE_C_COMPILER_LAUNCHER=ccache -DCMAKE_CXX_COMPILER_LAUNCHER=ccache -DCMAKE_COMPILE_WARNING_AS_ERROR=ON -DUSE_CXX_STD=11 -DENABLE_STDCXX_SYNC=ON -DENABLE_ENCRYPTION=$ENCRYPTION -DENABLE_UNITTESTS=ON -DENABLE_BONDING=ON -DENABLE_TESTING=ON -DENABLE_EXAMPLES=ON -DENABLE_DEBUG=ON -DENABLE_CODE_COVERAGE=ON -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
- name: build
run: cd _build && cmake --build .
- name: test
Expand All @@ -61,7 +64,7 @@ jobs:
ulimit -c unlimited
cd _build && ctest --extra-verbose
SUCCESS=$?
if [ -f core.test-srt ]; then gdb -batch ./test-srt -c core -ex bt -ex "info thread" -ex quit; else echo "NO CORE - NO CRY!"; fi;
if [ -f core.test-srt ]; then gdb -batch ./test-srt -c core.test-srt -ex bt -ex "info thread" -ex quit; else echo "NO CORE - NO CRY!"; fi;
test $SUCCESS == 0;
- name: Save ccache
if: ${{ success() && github.event_name != 'pull_request' }}
Expand All @@ -73,6 +76,10 @@ jobs:
if: always()
run: ccache --show-stats
- name: codecov
run: |
source ./scripts/collect-gcov.sh
bash <(curl -s https://codecov.io/bash)
uses: codecov/codecov-action@v4
with:
token: ${{ secrets.CODECOV_TOKEN }}
# name: codecov
# run: |
# ./scripts/codecov/update.sh
# ./scripts/codecov/codecov upload-process ${CODECOV_TOKEN} --search-dir _build
6 changes: 6 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,12 @@ reorder-tolerance freeze, periodic-NAK disable, or the

### ABI baseline

This branch merges Haivision **v1.5.7** (`899348d`) as a true merge, retaining
`SRTO_REORDERFREEZE = 120` and deterministic socket teardown. It brings upstream
handshake, ACK, DROPREQ, FEC, bonding and sample-tool hardening. The published
package remains `1.5.6+ceralive.1` until the separate release cutover; this source
sync does not advance the ABI baseline below.

`.github/workflows/abi.yml` compares proposed builds with the immutable
`srt-v1.5.6+ceralive.1` tag: the latest shipped CeraLive source release. This
tests compatibility against the ABI that device consumers actually received,
Expand Down
22 changes: 16 additions & 6 deletions CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
#

cmake_minimum_required (VERSION 3.5 FATAL_ERROR)
set (SRT_VERSION 1.5.6)
set (SRT_VERSION 1.5.7)

set (CMAKE_MODULE_PATH "${CMAKE_CURRENT_SOURCE_DIR}/scripts")
include(CheckSymbolExists)
Expand Down Expand Up @@ -172,6 +172,7 @@ else()
endif()
option(ENABLE_APPS "Should the Support Applications be Built?" ON)
option(ENABLE_BONDING "Should the bonding functionality be enabled?" OFF)
option(ENABLE_EXAMPLES "Compile also examples (NOTE: MAY BE UNSAFE!)" OFF)
option(ENABLE_TESTING "Should the Developer Test Applications be Built?" OFF)
option(ENABLE_PROFILE "Should instrument the code for profiling. Ignored for non-GNU compiler." $ENV{HAI_BUILD_PROFILE})
option(ENABLE_LOGGING "Should logging be enabled" ON)
Expand Down Expand Up @@ -910,13 +911,22 @@ if (ENABLE_PROFILE)
endif()

if (ENABLE_CODE_COVERAGE)
if (HAVE_COMPILER_GNU_COMPAT)
add_definitions(-g -O0 --coverage)
link_libraries(--coverage)
message(STATUS "ENABLE_CODE_COVERAGE: ON")
else()
if (NOT HAVE_COMPILER_GNU_COMPAT)
message(FATAL_ERROR "ENABLE_CODE_COVERAGE: option is not supported on this platform")
endif()

if (ENABLE_DEBUG EQUAL 2)
elseif (NOT ENABLE_DEBUG)
else()
set (ENABLE_STRICTLY_DEBUG_MODE 1)
endif()
if (NOT ENABLE_STRICTLY_DEBUG_MODE)
message(FATAL_ERROR "ENABLE_CODE_COVERAGE: requires ENABLE_DEBUG or Debug build type")
endif()

add_definitions(--coverage)
link_libraries(--coverage)
message(STATUS "ENABLE_CODE_COVERAGE: ON")
endif()

# On Linux pthreads have to be linked even when using C++11 threads
Expand Down
9 changes: 8 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@ In live streaming configurations, the SRT protocol maintains a constant end-to-e
|:-----------------------------------------------------------------------------------------------------------------------------:|:------------------------------------------------------------------------------------:|:---------------------------------------------------------------------------------:|
| [The SRT API](./docs#srt-api-documents) | [IETF Internet Draft](https://datatracker.ietf.org/doc/html/draft-sharabayko-srt-01) | [Sample Apps](./docs#sample-applications) |
| Reference documentation for the SRT library API | The SRT Protocol Internet Draft | Instructions for using test apps (`srt-live-transmit`, `srt-file-transmit`, etc.) |
| [SRT Technical Overview](https://github.com/Haivision/srt/files/2489142/SRT_Protocol_TechnicalOverview_DRAFT_2018-10-17.pdf) | [SRT Deployment Guide](https://www.srtalliance.org/srt-deployment-guide/) | [SRT CookBook](https://srtlab.github.io/srt-cookbook) |
| [SRT Technical Overview](https://github.com/Haivision/srt/files/2489142/SRT_Protocol_TechnicalOverview_DRAFT_2018-10-17.pdf) | [SRT Deployment Guide](https://www3.haivision.com/srt-deployment-guide/) | [SRT CookBook](https://srtlab.github.io/srt-cookbook) |
| Early draft technical overview (precursor to the Internet Draft) | A comprehensive overview of the protocol with deployment guidelines | Development notes on the SRT protocol |
| [Innovation Labs Blog](https://medium.com/innovation-labs-blog/tagged/secure-reliable-transport) | [SRTLab YouTube Channel](https://www.youtube.com/channel/UCr35JJ32jKKWIYymR1PTdpA) | [Slack](https://srtalliance.slack.com) |
| The blog on Medium with SRT-related technical articles | Technical YouTube channel with useful videos | Slack channels to get the latest updates and ask questions <br />[Join SRT Alliance on Slack](https://slackin-srtalliance.azurewebsites.net/) |
Expand Down Expand Up @@ -206,6 +206,13 @@ By contributing code to the SRT project, you agree to license your contribution

## Release History

### CeraLive source sync

This branch includes upstream **v1.5.7** security hardening while retaining the fork's
opt-in reorder freeze and deterministic socket teardown. See
[CeraLive Patch Set](docs/CERALIVE-PATCHES.md). The published runtime package and ABI
reference remain `srt-v1.5.6+ceralive.1` until the separate release cutover.

- [Release notes](https://github.com/Haivision/srt/releases)
- [SRT versioning](./docs/dev/developers-guide.md#versioning)

Expand Down
2 changes: 2 additions & 0 deletions apps/socketoptions.hpp
Original file line number Diff line number Diff line change
Expand Up @@ -235,6 +235,8 @@ const SocketOption srt_options [] {
{ "tlpktdrop", 0, SRTO_TLPKTDROP, SocketOption::PRE, SocketOption::BOOL, nullptr},
{ "snddropdelay", 0, SRTO_SNDDROPDELAY, SocketOption::POST, SocketOption::INT, nullptr},
{ "nakreport", 0, SRTO_NAKREPORT, SocketOption::PRE, SocketOption::BOOL, nullptr},
{ "srtlapatches", 0, SRTO_SRTLAPATCHES, SocketOption::PRE, SocketOption::BOOL, nullptr},
{ "periodicnakgate", 0, SRTO_PERIODICNAKGATE, SocketOption::PRE, SocketOption::INT, nullptr},
{ "conntimeo", 0, SRTO_CONNTIMEO, SocketOption::PRE, SocketOption::INT, nullptr},
{ "drifttracer", 0, SRTO_DRIFTTRACER, SocketOption::POST, SocketOption::BOOL, nullptr},
{ "lossmaxttl", 0, SRTO_LOSSMAXTTL, SocketOption::POST, SocketOption::INT, nullptr},
Expand Down
59 changes: 57 additions & 2 deletions apps/srt-file-transmit.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -465,6 +465,12 @@ bool DoDownload(UriParser& us, string directory, string filename,
bool connected = false;
int pollid = -1;
string id;
// This will be set to TRUE if the ID has been obtained from the socket,
// while as caller socket it was set to this option beforehand. If it remains
// false, it means that it was the ID passed from the caller and extracted
// from the accepted socket - and as such the name can't be trusted, so
// if a file with this name exists, it will be not overwritten.
bool id_is_local = false;
ofstream ofile;
SRT_SOCKSTATUS status;
SRTSOCKET efd;
Expand Down Expand Up @@ -548,6 +554,7 @@ bool DoDownload(UriParser& us, string directory, string filename,
cerr << "Source connected (caller), id ["
<< id << "]" << endl;
connected = true;
id_is_local = true;
}
}
break;
Expand Down Expand Up @@ -579,10 +586,58 @@ bool DoDownload(UriParser& us, string directory, string filename,

if (!ofile.is_open())
{
const char * fn = id.empty() ? filename.c_str() : id.c_str();
std::string fn;
bool overwrite = false;
if (id.empty())
{
fn = filename;
overwrite = true;
}
else
{
fn = id;
if (id_is_local)
overwrite = true;
}
directory.append("/");
directory.append(fn);
ofile.open(directory.c_str(), ios::out | ios::trunc | ios::binary);

std::ios::openmode flags = ios::out | ios::binary;
if (overwrite)
flags = flags | ios::trunc;
else
{
struct stat state;
int st = stat(directory.c_str(), &state);
if (st == 0) // File can be obtained
{
cerr << "Error: File exists: " << directory << endl;
cerr << "Error: As the name is remote-provided, overwriting denied for security reasons." << endl;
goto exit;
}

// Additionally check if the path is PWD-based;
// reject any foreign-defined paths that are not
// effectively local.

// NOTE: The file is always copied to the directory
// specified locally, with the original filename. Therefore
// it is not allowed that the file contain a path.

static const size_t notfound = std::string::npos;
if ( fn.find('/') != notfound
|| fn.find('\\') != notfound
|| fn.find(':') != notfound
|| fn.find("..") != notfound) // Any parent-referring
{
cerr << "Error: the foreign-specified path reaches outside PWD - REJECTED\n";
cerr << "Path: " << directory << endl;
cerr << "NOTE: remote path is only allowed to point inside the current directory\n";
goto exit;
}
}

ofile.open(directory, flags);

if (!ofile.is_open())
{
Expand Down
Loading
Loading