Commit Graph
168 Commits
Author SHA1 Message Date
Isaac ConnorandClaude Opus 5 5e48bed37c fix: use printf precision for auth hash prefix in zms auth-failure log
The 9-byte auth_prefix buffer tripped -Wformat-truncation because auth is
64 bytes. Use %.8s in the Warning format instead, which truncates at print
time and drops the buffer. Logged output is unchanged: first 8 chars of the
hash plus "..." when longer.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-09 18:16:16 -04:00
Isaac ConnorandClaude Opus 5 d455caa3b0 fix: use snprintf for the auth prefix in the zms auth failure log
strncpy() into a fixed 9-byte buffer trips -Wstringop-truncation at -O2:

  error: 'char* strncpy(char*, const char*, size_t)' output may be
  truncated copying 8 bytes from a string of length 63

The truncation is deliberate (log only the first 8 chars of the auth
hash) and the copy was already safe, since auth_prefix is zero
initialised so the final byte stays NUL. snprintf() expresses the same
intent, always NUL-terminates, and does not warn.

Only reproducible in an optimised build; -O0 Debug trees never see it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 21:43:36 -04:00
Isaac ConnorandClaude Opus 4.8 7cd4be5cfb feat: add nph-zms memory diagnostics refs #5006
Add instrumentation to trace which stream type and workload precede the
occasional runaway memory growth in nph-zms.

- zm_utils: add zm_get_rss_kb() reading resident set size from
  /proc/self/statm
- zms: log a one-shot Debug summary of the decoded request (source, mode,
  monitor/event, connkey, scale, buffer, ttl, rss) so a runaway process
  can be tied to its stream parameters
- MonitorStream/EventStream: emit a periodic Debug RSS trace every 30s.
  The EventStream trace includes frames-vector size and frame_count,
  which scale with reloaded event length and will show whether the
  in-process event reload path drives the growth

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-26 09:48:44 -04:00
Isaac ConnorandClaude Opus 4.7 61d8a7c71d fix: enrich zms auth-failure warning with diagnostic fields
The previous warning ("Unable to authenticate user from <referer>") gave
no way to distinguish the common cases without flipping on Debug:

- Stale auth hash on a long-lived <img src=nph-zms?...> whose TTL expired
- Missing/wrong user= or auth= in URL
- Disabled/deleted user
- REMOTE_ADDR mismatch when ZM_AUTH_HASH_IPS is enabled

Include user, auth-hash prefix, REQUEST_URI, XFF, and REMOTE_ADDR in
the message so the noise is diagnosable from the log alone.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-20 23:00:14 -04:00
Isaac ConnorandClaude Opus 4.6 2526b9b85e feat: install SIGPIPE handler in zms for clean browser-disconnect shutdown
When a browser closes a streaming connection, fwrite to stdout raises
SIGPIPE.  Without a handler the default action terminates the process
immediately, skipping exit_zm() and leaving the DB handle and log
unclosed.

Add zm_pipe_handler that sets zm_terminate so zms falls out of its
streaming loop and exits through the normal shutdown path.  Clarify
the sendFrame comment to match.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-18 09:53:23 -04:00
Isaac ConnorandClaude Opus 4.6 5561829450 fix: include username in auth relay and fix stale auth in stream restart
- Add user= parameter to get_auth_relay() so zms can use the indexed
  Username column instead of iterating all users to validate the hash
- Apply the same fix to Event.php getStreamSrc() and getThumbnailSrc()
- Tighten Monitor.php from isset() to !empty() for consistency
- In MonitorStream.js start(), check if the auth hash in the img src
  matches the current auth_hash before resuming via CMD_PLAY. If stale,
  fall through to rebuild the URL with fresh auth_relay. This prevents
  long-running montage pages from spawning zms with expired credentials.
- Downgrade zms auth failure from Error to Warning

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-16 10:01:47 -04:00
Isaac Connor 1d552c3204 Move exit_zms to zm.cpp exit_zm. Add time= parsing and prefer loading by event_id if specified 2026-01-05 16:38:35 -05:00
Isaac Connor 799f4f701e Add mode=paused support 2025-09-24 14:03:01 -04:00
Isaac Connor a79a3f645b Default to no limit to fps 2025-08-26 10:24:08 -04:00
Isaac Connor d67649417b prioritise event_id as log file format as we may also specify monitor -id 2025-08-26 10:23:25 -04:00
Isaac Connor d968e243ff Implement mode=single for events, so that we can efficiently just grab a single frame 2024-08-19 18:26:35 -04:00
Isaac Connor 7665c63da0 Add datetime as a zms option 2024-07-09 08:14:15 -04:00
Isaac Connor 1fdfcf3cdd Limit scale to 16x mainly to put an upper bound on the amount of ram we might use. 2024-05-30 12:10:10 -04:00
Aaron Kling c4683d90a9 Format code using astyle google format
Commands used:
astyle --style=google --indent=spaces=2 --keep-one-line-blocks src/*.cpp
astyle --style=google --indent=spaces=2 --keep-one-line-blocks src/*.h
2024-03-26 13:43:58 -05:00
Isaac Connor 01c6df434c Move code to shutdown the process properly into exit_zms and use it when auth fails. The stops a segfault. 2024-02-13 13:14:39 -05:00
Isaac Connor 8617c09f16 Implement new zms parameters frames= which is the # of frames to send when in streaming mode. The idea is to replicate single mode, but allowing for other intermediate images, like Waiting for Connection etc. type=single should only ever send 1 single image. 2024-01-04 11:37:49 -05:00
Isaac Connor a882b71a3b Close db before logterm because dbclose can do logging at debug level. 2023-11-09 14:54:38 -05:00
Isaac Connor 8d0c25c52a Change zmLoadAuthUser to use std::string in arguments. Include passing an optional username to allow the SQL to use an index to only compare to that user for efficiency. 2023-11-08 10:54:54 -05:00
Isaac Connor 2a3b16076c Fix missing %s in format string 2023-06-07 10:02:50 -04:00
Isaac Connor d264985a36 Be more specific about which permission failed, providing a better log message 2023-06-07 09:54:58 -04:00
Isaac Connor 12409e624e Support username and password as auth query params. These happen when using auth_relay=plain. 2023-02-25 13:12:40 -05:00
Isaac Connor d673266235 Stop the dbQueue before closing logs. Since dbQueue.stop() join's the dbQueue thread, it should not log after we return. 2022-05-18 19:00:30 -04:00
Isaac Connor dc055fb240 Remove code handling failure to setStreamStart. This is now ok and handled in runStream 2022-04-28 16:44:39 -04:00
Isaac Connor 45b6c97cc8 Don't exit if we fail to set stream start 2022-04-28 16:42:35 -04:00
Isaac Connor 133553e630 Revert "Merge pull request #3119 from Carbenium/fmt"
This reverts commit 90d930c7c3, reversing
changes made to 0bcb9d276f.
2022-02-27 14:05:14 -05:00
Isaac Connor c5b9ed9451 Revert "Fix zms build"
This reverts commit e6b36bb186.
2022-02-27 13:46:51 -05:00
Isaac Connor e6b36bb186 Fix zms build 2022-02-27 10:41:42 -05:00
Isaac Connor cad57df0bb Merge branch 'master' into fmt 2022-02-26 13:56:20 -05:00
Isaac Connor 7ae9bebea4 Add analysis boolean query param 2022-01-07 12:40:21 -05:00
Isaac Connor a2ae63cefe Merge branch 'master' into fmt 2021-11-16 15:10:45 -05:00
Isaac Connor 848a537a0f Fix zms giving 500 code instead of displaying error image due to not having sent the headers yet. 2021-08-23 18:10:31 -04:00
Peter Keresztes Schmidt d69afc9672 misc: Convert time(nullptr) calls to std::chrono 2021-06-13 23:22:51 +02:00
Peter Keresztes Schmidt a9ad5c5eee Build: Promote libavcodec to a required dependency
FFmpeg is an integral component of ZM. Promote the appropriate libraries to required dependencies.
This reduces the possible build configurations greatly and thus maintenance burden.
2021-06-05 14:25:54 +02:00
Isaac Connor 8f27db5d6f Do not stop dbQueue in logTerm. dbQueue is not just for logging. 2021-05-04 14:22:02 -04:00
Isaac Connor 88147f3f7a add another logInit so that early messages go to zms.log after loading config. Add Image::Initialise so that initialised flag will get set, and add a Deinitialise call so that ram allocated in zm_image gets freed. 2021-05-01 14:49:33 -04:00
Peter Keresztes Schmidt b5f3682d4e utils: some more reshuffling/grouping and formatting 2021-04-04 01:18:34 +02:00
Peter Keresztes Schmidt 67d7872e9a Eliminate non-thread-safe calls to gmtime
gmtime uses an internal static storage to which a pointer is given as return value.
Due to this it is not safe to call gmtime from multiple threads since the same static storage is used.

Use gmtime_r instead which allows to pass in a tm struct.

Fixes:
https://github.com/ZoneMinder/zoneminder/security/code-scanning/32
2021-03-21 21:42:02 +01:00
Peter Keresztes Schmidt d9568a98c0 Drop zm_thread which has been replaced by STL implementations 2021-03-04 10:55:46 +01:00
Peter Keresztes Schmidt e18750bb79 logger: Pass std::string as ID during logInit 2021-03-01 22:43:02 +01:00
Peter Keresztes Schmidt 589e5fec26 zms: Use fmt to construct the log ID 2021-03-01 22:43:02 +01:00
Peter Keresztes Schmidt aec4dbc6ff DB: Make connection initialization more predictable and avoid double-initialization
Remove calls to zmDBConnect from various places to avoid possible side-effects/double initialization.
The function should be called once from the main thread of the daemon.

Also split config loading into 2 steps: static and DB config loading. Load the static config before zmDBConnect is called so it has a chance to succeed.
2021-02-07 13:44:41 +01:00
Peter Keresztes Schmidt 0dbc39ee25 Cleanup and reorganize includes
With this commit a unified structure for includes is introduced.
The general rules:
 * Only include what you need
 * Include wherever possible in the cpp and forward-declare in the header

 The includes are sorted in a local to global fashion. This means for the include order:
  0. If cpp file: The corresponding h file and an empty line
  1. Includes from the project sorted alphabetically
  2. System/library includes sorted alphabetically
  3. Conditional includes
2021-02-04 18:02:01 +01:00
Peter Keresztes Schmidt 5a57efdfe2 Replace deprecated C header includes with the C++ ones. 2021-02-04 05:39:03 +01:00
Peter Keresztes Schmidt e09fa1bebf Remove includes of <cinttypes>
Instead of including <cinttypes> directly, zm_define.h should be used
to get the typedef'ed types as well.
2021-02-02 21:37:26 +01:00
Isaac Connor b4fc782778 fifo.h got split into zm_fifo and zm_stream so update the code in zms 2021-03-01 16:49:27 -05:00
Isaac Connor 0f276887ad When can't connect to monitor send an image saying so 2021-01-15 14:43:44 -05:00
Isaac Connor 4d8f45d284 There is no need to copy query. We do not modify it. 2020-11-21 16:59:21 -05:00
Isaac Connor 7653a058a3 More correct code for setting source 2020-11-20 16:31:40 -05:00
Isaac Connor 033e749a57 improve code logic/spacing 2020-11-01 17:16:07 -05:00
Isaac Connor a4b83b0e99 Merge branch 'master' of github.com:zoneminder/ZoneMinder 2020-09-09 12:13:54 -04:00