All of lore.kernel.org
 help / color / mirror / Atom feed
From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org, jami.maenpaa@wapice.com,
	Thomas Haller <thaller@redhat.com>
Subject: Re: [PATCH nft 1/2] parser_json: use stdin buffer if available
Date: Wed, 10 Jul 2024 15:53:52 +0200	[thread overview]
Message-ID: <Zo6ScCYWnACpWJsl@orbyte.nwl.cc> (raw)
In-Reply-To: <20240709145953.135124-1-pablo@netfilter.org>

Hi Pablo,

On Tue, Jul 09, 2024 at 04:59:52PM +0200, Pablo Neira Ayuso wrote:
> Since 5c2b2b0a2ba7 ("src: error reporting with -f and read from stdin")
> stdin is stored in a buffer, update json support to use it instead of
> reading from /dev/stdin.
> 
> Some systems do not provide /dev/stdin symlink to /proc/self/fd/0
> according to reporter (that mentions Yocto Linux as example).
> 
> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
> ---
>  src/parser_json.c | 7 +++++++
>  1 file changed, 7 insertions(+)
> 
> diff --git a/src/parser_json.c b/src/parser_json.c
> index ee4657ee8044..4912d3608b2b 100644
> --- a/src/parser_json.c
> +++ b/src/parser_json.c
> @@ -4357,6 +4357,13 @@ int nft_parse_json_filename(struct nft_ctx *nft, const char *filename,
>  	json_error_t err;
>  	int ret;
>  
> +	if (nft->stdin_buf) {
> +		json_indesc.type = INDESC_STDIN;
> +		json_indesc.name = "/dev/stdin";
> +
> +		return nft_parse_json_buffer(nft, nft->stdin_buf, msgs, cmds);
> +	}

Is this sufficient? In nft_run_cmd_from_filename(), nft->stdin_buf is
populated conditionally:

| if (!strcmp(filename, "/dev/stdin") &&
|     !nft_output_json(&nft->output))
|         nft->stdin_buf = stdin_to_buffer();

Later (in the wrapped __nft_run_cmd_from_filename()), we try JSON parsing
conditionally:

| if (nft_output_json(&nft->output) || nft_input_json(&nft->input))
|         rc = nft_parse_json_filename(nft, filename, &msgs, &cmds);

Things got complicated by commit 2034d8c60ed91 ("src: add input flag
NFT_CTX_INPUT_JSON to enable JSON parsing") and my request to remain
compatible, i.e. '-j' flag which enables JSON output shall continue to
make JSON the assumed input format.

So long story short, I guess in order to cover all cases, we have to
enable nft->stdin_buf population also if nft_input_json(...) returns
true, i.e. cover for library users requesting JSON input (but standard
output). WDYT?

Cheers, Phil

  parent reply	other threads:[~2024-07-10 13:53 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-09 14:59 [PATCH nft 1/2] parser_json: use stdin buffer if available Pablo Neira Ayuso
2024-07-09 14:59 ` [PATCH nft 2/2] libnftables: skip useable checks for /dev/stdin Pablo Neira Ayuso
2024-07-10 13:53 ` Phil Sutter [this message]
2024-07-10 14:01   ` [PATCH nft 1/2] parser_json: use stdin buffer if available Phil Sutter
2024-07-10 14:04     ` Pablo Neira Ayuso
2024-07-10 15:15       ` Phil Sutter
  -- strict thread matches above, loose matches on Subject: below --
2024-07-10 15:20 Pablo Neira Ayuso
2024-07-10 15:52 ` Phil Sutter
2024-07-10 15:54   ` Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Zo6ScCYWnACpWJsl@orbyte.nwl.cc \
    --to=phil@nwl.cc \
    --cc=jami.maenpaa@wapice.com \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pablo@netfilter.org \
    --cc=thaller@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.