]> git.netwichtig.de Git - user/henk/code/inspircd.git/blob - src/modules/extra/m_mysql.cpp
m_mysql Fix escaping strings longer than MAXBUF/2
[user/henk/code/inspircd.git] / src / modules / extra / m_mysql.cpp
1 /*
2  * InspIRCd -- Internet Relay Chat Daemon
3  *
4  *   Copyright (C) 2009-2010 Daniel De Graaf <danieldg@inspircd.org>
5  *   Copyright (C) 2006-2007, 2009 Dennis Friis <peavey@inspircd.org>
6  *   Copyright (C) 2006-2009 Craig Edwards <craigedwards@brainbox.cc>
7  *   Copyright (C) 2008 Robin Burchell <robin+git@viroteck.net>
8  *
9  * This file is part of InspIRCd.  InspIRCd is free software: you can
10  * redistribute it and/or modify it under the terms of the GNU General Public
11  * License as published by the Free Software Foundation, version 2.
12  *
13  * This program is distributed in the hope that it will be useful, but WITHOUT
14  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
15  * FOR A PARTICULAR PURPOSE.  See the GNU General Public License for more
16  * details.
17  *
18  * You should have received a copy of the GNU General Public License
19  * along with this program.  If not, see <http://www.gnu.org/licenses/>.
20  */
21
22
23 /* Stop mysql wanting to use long long */
24 #define NO_CLIENT_LONG_LONG
25
26 #include "inspircd.h"
27 #include <mysql.h>
28 #include "sql.h"
29
30 #ifdef _WIN32
31 # pragma comment(lib, "mysqlclient.lib")
32 # pragma comment(lib, "advapi32.lib")
33 # pragma comment(linker, "/NODEFAULTLIB:LIBCMT")
34 #endif
35
36 /* VERSION 3 API: With nonblocking (threaded) requests */
37
38 /* $ModDesc: SQL Service Provider module for all other m_sql* modules */
39 /* $CompileFlags: exec("mysql_config --include") */
40 /* $LinkerFlags: exec("mysql_config --libs_r") rpath("mysql_config --libs_r") */
41
42 /* THE NONBLOCKING MYSQL API!
43  *
44  * MySQL provides no nonblocking (asyncronous) API of its own, and its developers recommend
45  * that instead, you should thread your program. This is what i've done here to allow for
46  * asyncronous SQL requests via mysql. The way this works is as follows:
47  *
48  * The module spawns a thread via class Thread, and performs its mysql queries in this thread,
49  * using a queue with priorities. There is a mutex on either end which prevents two threads
50  * adjusting the queue at the same time, and crashing the ircd. Every 50 milliseconds, the
51  * worker thread wakes up, and checks if there is a request at the head of its queue.
52  * If there is, it processes this request, blocking the worker thread but leaving the ircd
53  * thread to go about its business as usual. During this period, the ircd thread is able
54  * to insert futher pending requests into the queue.
55  *
56  * Once the processing of a request is complete, it is removed from the incoming queue to
57  * an outgoing queue, and initialized as a 'response'. The worker thread then signals the
58  * ircd thread (via a loopback socket) of the fact a result is available, by sending the
59  * connection ID through the connection.
60  *
61  * The ircd thread then mutexes the queue once more, reads the outbound response off the head
62  * of the queue, and sends it on its way to the original calling module.
63  *
64  * XXX: You might be asking "why doesnt he just send the response from within the worker thread?"
65  * The answer to this is simple. The majority of InspIRCd, and in fact most ircd's are not
66  * threadsafe. This module is designed to be threadsafe and is careful with its use of threads,
67  * however, if we were to call a module's OnRequest even from within a thread which was not the
68  * one the module was originally instantiated upon, there is a chance of all hell breaking loose
69  * if a module is ever put in a re-enterant state (stack corruption could occur, crashes, data
70  * corruption, and worse, so DONT think about it until the day comes when InspIRCd is 100%
71  * gauranteed threadsafe!)
72  *
73  * For a diagram of this system please see http://wiki.inspircd.org/Mysql2
74  */
75
76 class SQLConnection;
77 class MySQLresult;
78 class DispatcherThread;
79
80 struct QQueueItem
81 {
82         SQLQuery* q;
83         std::string query;
84         SQLConnection* c;
85         QQueueItem(SQLQuery* Q, const std::string& S, SQLConnection* C) : q(Q), query(S), c(C) {}
86 };
87
88 struct RQueueItem
89 {
90         SQLQuery* q;
91         MySQLresult* r;
92         RQueueItem(SQLQuery* Q, MySQLresult* R) : q(Q), r(R) {}
93 };
94
95 typedef std::map<std::string, SQLConnection*> ConnMap;
96 typedef std::deque<QQueueItem> QueryQueue;
97 typedef std::deque<RQueueItem> ResultQueue;
98
99 /** MySQL module
100  *  */
101 class ModuleSQL : public Module
102 {
103  public:
104         DispatcherThread* Dispatcher;
105         QueryQueue qq;       // MUST HOLD MUTEX
106         ResultQueue rq;      // MUST HOLD MUTEX
107         ConnMap connections; // main thread only
108
109         ModuleSQL();
110         void init();
111         ~ModuleSQL();
112         void OnRehash(User* user);
113         void OnUnloadModule(Module* mod);
114         Version GetVersion();
115 };
116
117 class DispatcherThread : public SocketThread
118 {
119  private:
120         ModuleSQL* const Parent;
121  public:
122         DispatcherThread(ModuleSQL* CreatorModule) : Parent(CreatorModule) { }
123         ~DispatcherThread() { }
124         virtual void Run();
125         virtual void OnNotify();
126 };
127
128 #if !defined(MYSQL_VERSION_ID) || MYSQL_VERSION_ID<32224
129 #define mysql_field_count mysql_num_fields
130 #endif
131
132 /** Represents a mysql result set
133  */
134 class MySQLresult : public SQLResult
135 {
136  public:
137         SQLerror err;
138         int currentrow;
139         int rows;
140         std::vector<std::string> colnames;
141         std::vector<SQLEntries> fieldlists;
142
143         MySQLresult(MYSQL_RES* res, int affected_rows) : err(SQL_NO_ERROR), currentrow(0), rows(0)
144         {
145                 if (affected_rows >= 1)
146                 {
147                         rows = affected_rows;
148                         fieldlists.resize(rows);
149                 }
150                 unsigned int field_count = 0;
151                 if (res)
152                 {
153                         MYSQL_ROW row;
154                         int n = 0;
155                         while ((row = mysql_fetch_row(res)))
156                         {
157                                 if (fieldlists.size() < (unsigned int)rows+1)
158                                 {
159                                         fieldlists.resize(fieldlists.size()+1);
160                                 }
161                                 field_count = 0;
162                                 MYSQL_FIELD *fields = mysql_fetch_fields(res);
163                                 if(mysql_num_fields(res) == 0)
164                                         break;
165                                 if (fields && mysql_num_fields(res))
166                                 {
167                                         colnames.clear();
168                                         while (field_count < mysql_num_fields(res))
169                                         {
170                                                 std::string a = (fields[field_count].name ? fields[field_count].name : "");
171                                                 if (row[field_count])
172                                                         fieldlists[n].push_back(SQLEntry(row[field_count]));
173                                                 else
174                                                         fieldlists[n].push_back(SQLEntry());
175                                                 colnames.push_back(a);
176                                                 field_count++;
177                                         }
178                                         n++;
179                                 }
180                                 rows++;
181                         }
182                         mysql_free_result(res);
183                         res = NULL;
184                 }
185         }
186
187         MySQLresult(SQLerror& e) : err(e)
188         {
189
190         }
191
192         ~MySQLresult()
193         {
194         }
195
196         virtual int Rows()
197         {
198                 return rows;
199         }
200
201         virtual void GetCols(std::vector<std::string>& result)
202         {
203                 result.assign(colnames.begin(), colnames.end());
204         }
205
206         virtual SQLEntry GetValue(int row, int column)
207         {
208                 if ((row >= 0) && (row < rows) && (column >= 0) && (column < (int)fieldlists[row].size()))
209                 {
210                         return fieldlists[row][column];
211                 }
212                 return SQLEntry();
213         }
214
215         virtual bool GetRow(SQLEntries& result)
216         {
217                 if (currentrow < rows)
218                 {
219                         result.assign(fieldlists[currentrow].begin(), fieldlists[currentrow].end());
220                         currentrow++;
221                         return true;
222                 }
223                 else
224                 {
225                         result.clear();
226                         return false;
227                 }
228         }
229 };
230
231 /** Represents a connection to a mysql database
232  */
233 class SQLConnection : public SQLProvider
234 {
235  public:
236         reference<ConfigTag> config;
237         MYSQL *connection;
238         Mutex lock;
239
240         // This constructor creates an SQLConnection object with the given credentials, but does not connect yet.
241         SQLConnection(Module* p, ConfigTag* tag) : SQLProvider(p, "SQL/" + tag->getString("id")),
242                 config(tag), connection(NULL)
243         {
244         }
245
246         ~SQLConnection()
247         {
248                 Close();
249         }
250
251         // This method connects to the database using the credentials supplied to the constructor, and returns
252         // true upon success.
253         bool Connect()
254         {
255                 unsigned int timeout = 1;
256                 connection = mysql_init(connection);
257                 mysql_options(connection,MYSQL_OPT_CONNECT_TIMEOUT,(char*)&timeout);
258                 std::string host = config->getString("host");
259                 std::string user = config->getString("user");
260                 std::string pass = config->getString("pass");
261                 std::string dbname = config->getString("name");
262                 int port = config->getInt("port");
263                 bool rv = mysql_real_connect(connection, host.c_str(), user.c_str(), pass.c_str(), dbname.c_str(), port, NULL, 0);
264                 if (!rv)
265                         return rv;
266                 std::string initquery;
267                 if (config->readString("initialquery", initquery))
268                 {
269                         mysql_query(connection,initquery.c_str());
270                 }
271                 return true;
272         }
273
274         ModuleSQL* Parent()
275         {
276                 return (ModuleSQL*)(Module*)creator;
277         }
278
279         MySQLresult* DoBlockingQuery(const std::string& query)
280         {
281
282                 /* Parse the command string and dispatch it to mysql */
283                 if (CheckConnection() && !mysql_real_query(connection, query.data(), query.length()))
284                 {
285                         /* Successfull query */
286                         MYSQL_RES* res = mysql_use_result(connection);
287                         unsigned long rows = mysql_affected_rows(connection);
288                         return new MySQLresult(res, rows);
289                 }
290                 else
291                 {
292                         /* XXX: See /usr/include/mysql/mysqld_error.h for a list of
293                          * possible error numbers and error messages */
294                         SQLerror e(SQL_QREPLY_FAIL, ConvToStr(mysql_errno(connection)) + ": " + mysql_error(connection));
295                         return new MySQLresult(e);
296                 }
297         }
298
299         bool CheckConnection()
300         {
301                 if (!connection || mysql_ping(connection) != 0)
302                         return Connect();
303                 return true;
304         }
305
306         std::string GetError()
307         {
308                 return mysql_error(connection);
309         }
310
311         void Close()
312         {
313                 mysql_close(connection);
314         }
315
316         void submit(SQLQuery* q, const std::string& qs)
317         {
318                 Parent()->Dispatcher->LockQueue();
319                 Parent()->qq.push_back(QQueueItem(q, qs, this));
320                 Parent()->Dispatcher->UnlockQueueWakeup();
321         }
322
323         void submit(SQLQuery* call, const std::string& q, const ParamL& p)
324         {
325                 std::string res;
326                 unsigned int param = 0;
327                 for(std::string::size_type i = 0; i < q.length(); i++)
328                 {
329                         if (q[i] != '?')
330                                 res.push_back(q[i]);
331                         else
332                         {
333                                 if (param < p.size())
334                                 {
335                                         std::string parm = p[param++];
336                                         // In the worst case, each character may need to be encoded as using two bytes,
337                                         // and one byte is the terminating null
338                                         std::vector<char> buffer(parm.length() * 2 + 1);
339
340                                         // The return value of mysql_escape_string() is the length of the encoded string,
341                                         // not including the terminating null
342                                         unsigned long escapedsize = mysql_escape_string(&buffer[0], parm.c_str(), parm.length());
343 //                                      mysql_real_escape_string(connection, queryend, paramscopy[paramnum].c_str(), paramscopy[paramnum].length());
344                                         res.append(&buffer[0], escapedsize);
345                                 }
346                         }
347                 }
348                 submit(call, res);
349         }
350
351         void submit(SQLQuery* call, const std::string& q, const ParamM& p)
352         {
353                 std::string res;
354                 for(std::string::size_type i = 0; i < q.length(); i++)
355                 {
356                         if (q[i] != '$')
357                                 res.push_back(q[i]);
358                         else
359                         {
360                                 std::string field;
361                                 i++;
362                                 while (i < q.length() && isalnum(q[i]))
363                                         field.push_back(q[i++]);
364                                 i--;
365
366                                 ParamM::const_iterator it = p.find(field);
367                                 if (it != p.end())
368                                 {
369                                         std::string parm = it->second;
370                                         // NOTE: See above
371                                         std::vector<char> buffer(parm.length() * 2 + 1);
372                                         unsigned long escapedsize = mysql_escape_string(&buffer[0], parm.c_str(), parm.length());
373                                         res.append(&buffer[0], escapedsize);
374                                 }
375                         }
376                 }
377                 submit(call, res);
378         }
379 };
380
381 ModuleSQL::ModuleSQL()
382 {
383         Dispatcher = NULL;
384 }
385
386 void ModuleSQL::init()
387 {
388         Dispatcher = new DispatcherThread(this);
389         ServerInstance->Threads->Start(Dispatcher);
390
391         Implementation eventlist[] = { I_OnRehash, I_OnUnloadModule };
392         ServerInstance->Modules->Attach(eventlist, this, sizeof(eventlist)/sizeof(Implementation));
393
394         OnRehash(NULL);
395 }
396
397 ModuleSQL::~ModuleSQL()
398 {
399         if (Dispatcher)
400         {
401                 Dispatcher->join();
402                 Dispatcher->OnNotify();
403                 delete Dispatcher;
404         }
405         for(ConnMap::iterator i = connections.begin(); i != connections.end(); i++)
406         {
407                 delete i->second;
408         }
409 }
410
411 void ModuleSQL::OnRehash(User* user)
412 {
413         ConnMap conns;
414         ConfigTagList tags = ServerInstance->Config->ConfTags("database");
415         for(ConfigIter i = tags.first; i != tags.second; i++)
416         {
417                 if (i->second->getString("module", "mysql") != "mysql")
418                         continue;
419                 std::string id = i->second->getString("id");
420                 ConnMap::iterator curr = connections.find(id);
421                 if (curr == connections.end())
422                 {
423                         SQLConnection* conn = new SQLConnection(this, i->second);
424                         conns.insert(std::make_pair(id, conn));
425                         ServerInstance->Modules->AddService(*conn);
426                 }
427                 else
428                 {
429                         conns.insert(*curr);
430                         connections.erase(curr);
431                 }
432         }
433
434         // now clean up the deleted databases
435         Dispatcher->LockQueue();
436         SQLerror err(SQL_BAD_DBID);
437         for(ConnMap::iterator i = connections.begin(); i != connections.end(); i++)
438         {
439                 ServerInstance->Modules->DelService(*i->second);
440                 // it might be running a query on this database. Wait for that to complete
441                 i->second->lock.Lock();
442                 i->second->lock.Unlock();
443                 // now remove all active queries to this DB
444                 for (size_t j = qq.size(); j > 0; j--)
445                 {
446                         size_t k = j - 1;
447                         if (qq[k].c == i->second)
448                         {
449                                 qq[k].q->OnError(err);
450                                 delete qq[k].q;
451                                 qq.erase(qq.begin() + k);
452                         }
453                 }
454                 // finally, nuke the connection
455                 delete i->second;
456         }
457         Dispatcher->UnlockQueue();
458         connections.swap(conns);
459 }
460
461 void ModuleSQL::OnUnloadModule(Module* mod)
462 {
463         SQLerror err(SQL_BAD_DBID);
464         Dispatcher->LockQueue();
465         unsigned int i = qq.size();
466         while (i > 0)
467         {
468                 i--;
469                 if (qq[i].q->creator == mod)
470                 {
471                         if (i == 0)
472                         {
473                                 // need to wait until the query is done
474                                 // (the result will be discarded)
475                                 qq[i].c->lock.Lock();
476                                 qq[i].c->lock.Unlock();
477                         }
478                         qq[i].q->OnError(err);
479                         delete qq[i].q;
480                         qq.erase(qq.begin() + i);
481                 }
482         }
483         Dispatcher->UnlockQueue();
484         // clean up any result queue entries
485         Dispatcher->OnNotify();
486 }
487
488 Version ModuleSQL::GetVersion()
489 {
490         return Version("MySQL support", VF_VENDOR);
491 }
492
493 void DispatcherThread::Run()
494 {
495         this->LockQueue();
496         while (!this->GetExitFlag())
497         {
498                 if (!Parent->qq.empty())
499                 {
500                         QQueueItem i = Parent->qq.front();
501                         i.c->lock.Lock();
502                         this->UnlockQueue();
503                         MySQLresult* res = i.c->DoBlockingQuery(i.query);
504                         i.c->lock.Unlock();
505
506                         /*
507                          * At this point, the main thread could be working on:
508                          *  Rehash - delete i.c out from under us. We don't care about that.
509                          *  UnloadModule - delete i.q and the qq item. Need to avoid reporting results.
510                          */
511
512                         this->LockQueue();
513                         if (!Parent->qq.empty() && Parent->qq.front().q == i.q)
514                         {
515                                 Parent->qq.pop_front();
516                                 Parent->rq.push_back(RQueueItem(i.q, res));
517                                 NotifyParent();
518                         }
519                         else
520                         {
521                                 // UnloadModule ate the query
522                                 delete res;
523                         }
524                 }
525                 else
526                 {
527                         /* We know the queue is empty, we can safely hang this thread until
528                          * something happens
529                          */
530                         this->WaitForQueue();
531                 }
532         }
533         this->UnlockQueue();
534 }
535
536 void DispatcherThread::OnNotify()
537 {
538         // this could unlock during the dispatch, but OnResult isn't expected to take that long
539         this->LockQueue();
540         for(ResultQueue::iterator i = Parent->rq.begin(); i != Parent->rq.end(); i++)
541         {
542                 MySQLresult* res = i->r;
543                 if (res->err.id == SQL_NO_ERROR)
544                         i->q->OnResult(*res);
545                 else
546                         i->q->OnError(res->err);
547                 delete i->q;
548                 delete i->r;
549         }
550         Parent->rq.clear();
551         this->UnlockQueue();
552 }
553
554 MODULE_INIT(ModuleSQL)