Fix LMDB (wrong) context cast, and remove now unnecessary LMDB code (#287)
What changed, and why it matters
This commit fixes a type-casting mistake in the Monero Light Wallet Server's database code. The program was treating its own custom database context as a different, more generic context. That mismatch could corrupt internal accounting of active readers/writers or cause the wrong cleanup code to run when a database transaction ends. The patch also removes a lot of now-redundant LMDB wrapper code and switches the project to use its own dedicated transaction and cursor types so the mistake cannot recur in the same way.
Treat this as a correctness and potential stability fix. Users running monero-lws should upgrade to a build containing this commit. Operators should monitor for database corruption or unexpected LMDB errors after upgrade, and consider re-syncing the light-wallet-server database if prior crashes occurred. No immediate remote exploit is evident from the diff alone.
Security signals we found
Wrong context cast in LMDB transaction cleanup (type confusion)
Custom context reference counting could be corrupted by mismatched deleter
Large code removal reduces attack surface and eliminates duplicated LMDB wrappers
New dedicated lws_lmdb transaction/cursor types enforce correct cleanup path
Evidence from the diff
The core change is in src/lmdb/lws_database.cpp: a new release_read_txn deleter now fetches the environment from the MDB_txn, retrieves the user context with mdb_env_get_userctx, and calls release_context on it. Previously the code relied on generic lmdb::transaction wrappers that apparently reinterpret_cast the user context to the wrong type (the commit title calls this a “wrong context cast”). The rest of the patch propagates the lws_lmdb::* transaction/cursor types through storage.cpp/storage.h, deletes lws_key_stream.h, lws_table.h and lws_value_stream.h, and adds lws_transaction.h with MONERO_LWS_CURSOR and the correct deleters. The bug class is a type confusion / incorrect context cast in a C++ RAII wrapper around LMDB, with potential consequences such as incorrect reference counting, use-after-free, or abort/commit mismanagement.
Changed components
src/lmdb/lws_database.cppsrc/lmdb/lws_database.hsrc/lmdb/lws_transaction.hsrc/db/storage.cppsrc/db/storage.hInspect captured patch +155 / −683
### src/db/storage.cpp
@@ -50,7 +50,6 @@
#include "hex.h"
#include "lmdb/lws_database.h"
#include "lmdb/lws_error.h"
-#include "lmdb/lws_table.h"
#include "lmdb/error.h"
#include "lmdb/key_stream.h"
#include "lmdb/msgpack_table.h"
@@ -367,7 +366,7 @@ namespace db
constexpr const lmdb::msgpack_table<webhook_key, webhook_dupsort, webhook_data> webhooks{
"webhooks_by_account_id,payment_id", (MDB_CREATE | MDB_DUPSORT), &lmdb::less<db::webhook_dupsort>
};
- constexpr const lws_lmdb::basic_table<account_id, webhook_event> events_by_account_id{
+ constexpr const lmdb::basic_table<account_id, webhook_event> events_by_account_id{
"webhook_events_by_account_id,type,block_id,tx_hash,output_id,payment_id,event_id", (MDB_CREATE | MDB_DUPSORT), &lmdb::less<webhook_event>
};
constexpr const lmdb::msgpack_table<account_id, major_index, index_ranges> subaddress_ranges{
@@ -386,7 +385,7 @@ namespace db
}
else
{
- auto new_cur = lmdb::open_cursor<D>(txn, tbl);
+ auto new_cur = lws_lmdb::open_cursor<D>(txn, tbl);
if (!new_cur)
return new_cur.error();
cur = std::move(*new_cur);
@@ -471,7 +470,7 @@ namespace db
void check_blockchain(MDB_txn& txn, MDB_dbi tbl)
{
- cursor::blocks cur = MONERO_UNWRAP(lmdb::open_cursor<cursor::close_blocks>(txn, tbl));
+ cursor::blocks cur = MONERO_UNWRAP(lws_lmdb::open_cursor<cursor::close_blocks>(txn, tbl));
std::map<std::uint64_t, crypto::hash> const& points =
storage::get_checkpoints().get_points();
@@ -527,7 +526,7 @@ namespace db
void check_pow(MDB_txn& txn, MDB_dbi tbl)
{
- cursor::pow cur = MONERO_UNWRAP(lmdb::open_cursor<cursor::close_pow>(txn, tbl));
+ cursor::pow cur = MONERO_UNWRAP(lws_lmdb::open_cursor<cursor::close_pow>(txn, tbl));
MDB_val key = lmdb::to_val(pows_version);
int err = mdb_cursor_get(cur.get(), &key, nullptr, MDB_SET);
@@ -726,7 +725,7 @@ namespace db
explicit storage_internal(lws_lmdb::environment env, unsigned create_queue_max)
: lws_lmdb::database(std::move(env)), tables{}, create_queue_max(create_queue_max)
{
- lmdb::write_txn txn = this->create_write_txn().value();
+ lws_lmdb::write_txn txn = this->create_write_txn().value();
assert(txn != nullptr);
tables.blocks = blocks.open(*txn).value();
@@ -1420,7 +1419,7 @@ namespace db
return success();
}
- lmdb::suspended_txn storage_reader::finish_read() noexcept
+ lws_lmdb::suspended_txn storage_reader::finish_read() noexcept
{
if (txn != nullptr)
{
@@ -1504,11 +1503,11 @@ namespace db
return storage{db};
}
- expect<storage_reader> storage::start_read(lmdb::suspended_txn txn) const
+ expect<storage_reader> storage::start_read(lws_lmdb::suspended_txn txn) const
{
MONERO_PRECOND(db != nullptr);
- expect<lmdb::read_txn> reader = db->create_read_txn(std::move(txn));
+ expect<lws_lmdb::read_txn> reader = db->create_read_txn(std::move(txn));
if (!reader)
return reader.error();
### src/db/storage.h
@@ -37,8 +37,8 @@
#include "db/account.h"
#include "db/data.h"
#include "fwd.h"
-#include "lmdb/transaction.h"
#include "lmdb/key_stream.h"
+#include "lmdb/lws_transaction.h"
#include "lmdb/value_stream.h"
#include "wire/msgpack/fwd.h"
@@ -49,21 +49,21 @@ namespace db
{
namespace cursor
{
- MONERO_CURSOR(accounts);
- MONERO_CURSOR(outputs);
- MONERO_CURSOR(spends);
- MONERO_CURSOR(images);
- MONERO_CURSOR(requests);
- MONERO_CURSOR(subaddress_ranges);
- MONERO_CURSOR(subaddress_indexes);
-
- MONERO_CURSOR(blocks);
- MONERO_CURSOR(pow);
- MONERO_CURSOR(accounts_by_address);
- MONERO_CURSOR(accounts_by_height);
+ MONERO_LWS_CURSOR(accounts);
+ MONERO_LWS_CURSOR(outputs);
+ MONERO_LWS_CURSOR(spends);
+ MONERO_LWS_CURSOR(images);
+ MONERO_LWS_CURSOR(requests);
+ MONERO_LWS_CURSOR(subaddress_ranges);
+ MONERO_LWS_CURSOR(subaddress_indexes);
+
+ MONERO_LWS_CURSOR(blocks);
+ MONERO_LWS_CURSOR(pow);
+ MONERO_LWS_CURSOR(accounts_by_address);
+ MONERO_LWS_CURSOR(accounts_by_height);
- MONERO_CURSOR(webhooks);
- MONERO_CURSOR(events);
+ MONERO_LWS_CURSOR(webhooks);
+ MONERO_LWS_CURSOR(events);
}
struct storage_internal;
@@ -85,11 +85,11 @@ namespace db
class storage_reader
{
std::shared_ptr<storage_internal> db;
- lmdb::read_txn txn;
+ lws_lmdb::read_txn txn;
reader_internal curs;
public:
- storage_reader(std::shared_ptr<storage_internal> db, lmdb::read_txn txn) noexcept
+ storage_reader(std::shared_ptr<storage_internal> db, lws_lmdb::read_txn txn) noexcept
: db(std::move(db)), txn(std::move(txn)), curs{}
{}
@@ -179,7 +179,7 @@ namespace db
expect<void> json_debug(std::ostream& out, bool show_keys);
//! \return Read txn that can be re-used via `storage::start_read`.
- lmdb::suspended_txn finish_read() noexcept;
+ lws_lmdb::suspended_txn finish_read() noexcept;
};
//! Wrapper for LMDB on-disk storage of light-weight server data.
@@ -340,7 +340,7 @@ namespace db
expect<void> clear_webhooks(std::vector<boost::uuids::uuid> ids);
//! `txn` must have come from a previous call on the same thread.
- expect<storage_reader> start_read(lmdb::suspended_txn txn = nullptr) const;
+ expect<storage_reader> start_read(lws_lmdb::suspended_txn txn = nullptr) const;
};
} // db
} // lws
### src/lmdb/CMakeLists.txt
@@ -27,7 +27,7 @@
# THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
set(monero-lws-lmdb_sources lws_database.cpp lws_error.cpp)
-set(monero-lws-lmdb_headers lws_database.h lws_error.h lws_key_stream.h lws_table.h lws_value_stream.h msgpack_table.h)
+set(monero-lws-lmdb_headers lws_database.h lws_error.h lws_transaction.h msgpack_table.h)
add_library(monero-lws-lmdb ${monero-lws-lmdb_sources} ${monero-lws-lmdb_headers})
target_include_directories(monero-lws-lmdb PUBLIC "${LMDB_INCLUDE}")
### src/lmdb/lws_database.cpp
@@ -60,6 +60,21 @@ namespace lws_lmdb
}
}
+ void release_read_txn::operator()(MDB_txn* ptr) const noexcept
+ {
+ if (ptr)
+ {
+ MDB_env* const env = mdb_txn_env(ptr);
+ abort_txn{}(ptr);
+ if (env)
+ {
+ context* ctx = reinterpret_cast<context*>(mdb_env_get_userctx(env));
+ if (ctx)
+ release_context(*ctx);
+ }
+ }
+ }
+
expect<environment> open_environment(const char* path, MDB_dbi max_dbs) noexcept
{
MONERO_PRECOND(path != nullptr);
@@ -74,7 +89,7 @@ namespace lws_lmdb
return {std::move(out)};
}
- expect<lmdb::write_txn> database::do_create_txn(unsigned int flags) noexcept
+ expect<lws_lmdb::write_txn> database::do_create_txn(unsigned int flags) noexcept
{
MONERO_PRECOND(handle() != nullptr);
@@ -86,7 +101,7 @@ namespace lws_lmdb
const int err =
mdb_txn_begin(handle(), nullptr, flags, &txn);
if (!err && txn != nullptr)
- return lmdb::write_txn{txn};
+ return lws_lmdb::write_txn{txn};
release_context(ctx);
if (err != MDB_MAP_RESIZED)
@@ -128,7 +143,7 @@ namespace lws_lmdb
return success();
}
- expect<lmdb::read_txn> database::create_read_txn(lmdb::suspended_txn txn) noexcept
+ expect<lws_lmdb::read_txn> database::create_read_txn(lws_lmdb::suspended_txn txn) noexcept
{
if (txn)
{
@@ -139,28 +154,28 @@ namespace lws_lmdb
release_context(ctx);
return {lmdb::error(err)};
}
- return lmdb::read_txn{txn.release()};
+ return lws_lmdb::read_txn{txn.release()};
}
auto new_txn = do_create_txn(MDB_RDONLY);
if (new_txn)
- return lmdb::read_txn{new_txn->release()};
+ return lws_lmdb::read_txn{new_txn->release()};
return new_txn.error();
}
- expect<lmdb::suspended_txn> database::reset_txn(lmdb::read_txn txn) noexcept
+ expect<lws_lmdb::suspended_txn> database::reset_txn(lws_lmdb::read_txn txn) noexcept
{
MONERO_PRECOND(txn != nullptr);
mdb_txn_reset(txn.get());
release_context(ctx);
- return lmdb::suspended_txn{txn.release()};
+ return lws_lmdb::suspended_txn{txn.release()};
}
- expect<lmdb::write_txn> database::create_write_txn() noexcept
+ expect<lws_lmdb::write_txn> database::create_write_txn() noexcept
{
return do_create_txn(0);
}
- expect<void> database::commit(lmdb::write_txn txn) noexcept
+ expect<void> database::commit(lws_lmdb::write_txn txn) noexcept
{
MONERO_PRECOND(txn != nullptr);
const int err = mdb_txn_commit(txn.release());
### src/lmdb/lws_database.h
@@ -36,7 +36,7 @@
#include "common/expect.h"
#include "lmdb/error.h"
-#include "lmdb/transaction.h"
+#include "lmdb/lws_transaction.h"
namespace lws_lmdb
{
@@ -74,7 +74,7 @@ namespace lws_lmdb
//! \return The LMDB environment associated with the object.
MDB_env* handle() const noexcept { return env.get(); }
- expect<::lmdb::write_txn> do_create_txn(unsigned int flags) noexcept;
+ expect<::lws_lmdb::write_txn> do_create_txn(unsigned int flags) noexcept;
public:
database(environment env);
@@ -94,16 +94,16 @@ namespace lws_lmdb
expect<void> resize() noexcept;
//! \return A read only LMDB transaction, reusing `txn` if provided.
- expect<lmdb::read_txn> create_read_txn(lmdb::suspended_txn txn = nullptr) noexcept;
+ expect<lws_lmdb::read_txn> create_read_txn(lws_lmdb::suspended_txn txn = nullptr) noexcept;
//! \return `txn` after releasing context.
- expect<lmdb::suspended_txn> reset_txn(lmdb::read_txn txn) noexcept;
+ expect<lws_lmdb::suspended_txn> reset_txn(lws_lmdb::read_txn txn) noexcept;
//! \return A read-write LMDB transaction.
- expect<lmdb::write_txn> create_write_txn() noexcept;
+ expect<lws_lmdb::write_txn> create_write_txn() noexcept;
//! Commit the read-write transaction.
- expect<void> commit(lmdb::write_txn txn) noexcept;
+ expect<void> commit(lws_lmdb::write_txn txn) noexcept;
/*!
Create a write transaction, pass it to `f`, then try to commit
@@ -119,7 +119,7 @@ namespace lws_lmdb
{
for (unsigned i = 0; i < attempts; ++i)
{
- expect<lmdb::write_txn> txn = create_write_txn();
+ expect<lws_lmdb::write_txn> txn = create_write_txn();
if (!txn)
return txn.error();
### src/lmdb/lws_key_stream.h
@@ -1,267 +0,0 @@
-// Copyright (c) 2018-2024, The Monero Project
-
-// All rights reserved.
-//
-// Redistribution and use in source and binary forms, with or without modification, are
-// permitted provided that the following conditions are met:
-//
-// 1. Redistributions of source code must retain the above copyright notice, this list of
-// conditions and the following disclaimer.
-//
-// 2. Redistributions in binary form must reproduce the above copyright notice, this list
-// of conditions and the following disclaimer in the documentation and/or other
-// materials provided with the distribution.
-//
-// 3. Neither the name of the copyright holder nor the names of its contributors may be
-// used to endorse or promote products derived from this software without specific
-// prior written permission.
-//
-// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
-// EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
-// MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
-// THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
-// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
-// PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
-// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
-// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
-// THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-#pragma once
-
-#include <boost/range/iterator_range.hpp>
-#include <cstdint>
-#include <cstring>
-#include <iterator>
-#include <lmdb.h>
-#include <utility>
-
-#include "lmdb/lws_value_stream.h"
-#include "span.h"
-
-namespace lws_lmdb
-{
-
- /*!
- An InputIterator for a fixed-sized LMDB key and value. `operator++`
- iterates over keys.
-
- \tparam K Key type in database records.
- \tparam V Value type in database records.
-
- \note This meets requirements for an InputIterator only. The iterator
- can only be incremented and dereferenced. All copies of an iterator
- share the same LMDB cursor, and therefore incrementing any copy will
- change the cursor state for all (incrementing an iterator will
- invalidate all prior copies of the iterator). Usage is identical
- to `std::istream_iterator`.
- */
- template<typename K, typename V>
- class key_iterator
- {
- MDB_cursor* cur;
- epee::span<const std::uint8_t> key;
-
- void increment()
- {
- // MDB_NEXT_MULTIPLE doesn't work if only one value is stored :/
- if (cur)
- key = lmdb::stream::get(*cur, MDB_NEXT_NODUP, sizeof(K), sizeof(V)).first;
- }
-
- public:
- using value_type = std::pair<K, boost::iterator_range<value_iterator<V>>>;
- using reference = value_type;
- using pointer = void;
- using difference_type = std::size_t;
- using iterator_category = std::input_iterator_tag;
-
- //! Construct an "end" iterator.
- key_iterator() noexcept
- : cur(nullptr), key()
- {}
-
- /*!
- \param cur Iterate over keys starting at this cursor position.
- \throw std::system_error if unexpected LMDB error. This can happen
- if `cur` is invalid.
- */
- key_iterator(MDB_cursor* cur)
- : cur(cur), key()
- {
- if (cur)
- key = lmdb::stream::get(*cur, MDB_GET_CURRENT, sizeof(K), sizeof(V)).first;
- }
-
- //! \return True if `this` is one-past the last key.
- bool is_end() const noexcept { return key.empty(); }
-
- //! \return True iff `rhs` is referencing `this` key.
- bool equal(key_iterator const& rhs) const noexcept
- {
- return
- (key.empty() && rhs.key.empty()) ||
- key.data() == rhs.key.data();
- }
-
- /*!
- Moves iterator to next key or end. Invalidates all prior copies of
- the iterator.
- */
- key_iterator& operator++()
- {
- increment();
- return *this;
- }
-
- /*!
- Moves iterator to next key or end.
-
- \return A copy that is already invalidated, ignore
- */
- key_iterator operator++(int)
- {
- key_iterator out{*this};
- increment();
- return out;
- }
-
- //! \pre `!is_end()` \return {current key, current value range}
- value_type operator*() const
- {
- return {get_key(), make_value_range()};
- }
-
- //! \pre `!is_end()` \return Current key
- K get_key() const noexcept
- {
- assert(!is_end());
- K out;
-
- static_assert(std::is_trivially_copyable<K>(), "key is not memcpyable");
- std::memcpy(std::addressof(out), key.data(), sizeof(out));
- return out;
- }
-
- /*!
- Return a C++ iterator over database values from current cursor
- position that will reach `.is_end()` after the last duplicate key
- record. Calling `make_iterator()` will return an iterator whose
- `operator*` will return an entire value (`V`).
- `make_iterator<MONERO_FIELD(account, id)>()` will return an
- iterator whose `operator*` will return a `decltype(account.id)`
- object - the other fields in the struct `account` are never copied
- from the database.
-
- \throw std::system_error if LMDB has unexpected errors.
- \return C++ iterator starting at current cursor position.
- */
- template<typename T = V, typename F = T, std::size_t offset = 0>
- value_iterator<T, F, offset> make_value_iterator() const
- {
- static_assert(std::is_same<T, V>(), "bad MONERO_FIELD usage?");
- return {cur};
- }
-
- /*!
- Return a range from current cursor position until last duplicate
- key record. Useful in for-each range loops or in templated code
- expecting a range of elements. Calling `make_range()` will return
- a range of `T` objects. `make_range<MONERO_FIELD(account, id)>()`
- will return a range of `decltype(account.id)` objects - the other
- fields in the struct `account` are never copied from the database.
-
- \throw std::system_error if LMDB has unexpected errors.
- \return An InputIterator range over values at cursor position.
- */
- template<typename T = V, typename F = T, std::size_t offset = 0>
- boost::iterator_range<value_iterator<T, F, offset>> make_value_range() const
- {
- return {make_value_iterator<T, F, offset>(), value_iterator<T, F, offset>{}};
- }
- };
-
- /*!
- C++ wrapper for a LMDB read-only cursor on a fixed-sized key `K` and
- value `V`.
-
- \tparam K key type being stored by each record.
- \tparam V value type being stored by each record.
- \tparam D cleanup functor for the cursor; usually unique per db/table.
- */
- template<typename K, typename V, typename D>
- class key_stream
- {
- std::unique_ptr<MDB_cursor, D> cur;
- public:
-
- //! Take ownership of `cur` without changing position. `nullptr` valid.
- explicit key_stream(std::unique_ptr<MDB_cursor, D> cur)
- : cur(std::move(cur))
- {}
-
- key_stream(key_stream&&) = default;
- key_stream(key_stream const&) = delete;
- ~key_stream() = default;
- key_stream& operator=(key_stream&&) = default;
- key_stream& operator=(key_stream const&) = delete;
-
- /*!
- Give up ownership of the cursor. `make_iterator()` and
- `make_range()` can still be invoked, but return the empty set.
-
- \return Currently owned LMDB cursor.
- */
- std::unique_ptr<MDB_cursor, D> give_cursor() noexcept
- {
- return {std::move(cur)};
- }
-
- /*!
- Place the stream back at the first key/value. Newly created
- iterators will start at the first value again.
-
- \note Invalidates all current iterators, including those created
- with `make_iterator` or `make_range`. Also invalidates all
- `value_iterator`s created with `key_iterator`.
- */
- void reset()
- {
- if (cur)
- lmdb::stream::get(*cur, MDB_FIRST, 0, 0);
- }
-
- /*!
- \throw std::system_error if LMDB has unexpected errors.
- \return C++ iterator over database keys from current cursor
- position that will reach `.is_end()` after the last key.
- */
- key_iterator<K, V> make_iterator() const
- {
- return {cur.get()};
- }
-
- /*!
- \throw std::system_error if LMDB has unexpected errors.
- \return Range from current cursor position until last key record.
- Useful in for-each range loops or in templated code
- */
- boost::iterator_range<key_iterator<K, V>> make_range() const
- {
- return {make_iterator(), key_iterator<K, V>{}};
- }
- };
-
- template<typename K, typename V>
- inline
- bool operator==(key_iterator<K, V> const& lhs, key_iterator<K, V> const& rhs) noexcept
- {
- return lhs.equal(rhs);
- }
-
- template<typename K, typename V>
- inline
- bool operator!=(key_iterator<K, V> const& lhs, key_iterator<K, V> const& rhs) noexcept
- {
- return !lhs.equal(rhs);
- }
-} // lws_lmdb
-
### src/lmdb/lws_table.h
@@ -1,109 +0,0 @@
-#pragma once
-
-#include <utility>
-
-#include "common/expect.h"
-#include "lmdb/error.h"
-#include "lmdb/lws_key_stream.h"
-#include "lmdb/table.h"
-#include "lmdb/util.h"
-#include "lmdb/lws_value_stream.h"
-
-namespace lws_lmdb
-{
- //! Helper for grouping typical LMDB DBI options when key and value are fixed types.
- template<typename K, typename V>
- struct basic_table : lmdb::table
- {
- using key_type = K;
- using value_type = V;
-
- //! \return Additional LMDB flags based on `flags` value.
- static constexpr unsigned compute_flags(const unsigned flags) noexcept
- {
- return flags | ((flags & MDB_DUPSORT) ? MDB_DUPFIXED : 0);
- }
-
- constexpr explicit basic_table(const char* name, unsigned flags = 0, MDB_cmp_func value_cmp = nullptr) noexcept
- : lmdb::table{name, compute_flags(flags), &lmdb::less<lmdb::native_type<K>>, value_cmp}
- {}
-
- /*!
- \tparam U must be same as `V`; used for sanity checking.
- \tparam F is the type within `U` that is being extracted.
- \tparam offset to `F` within `U`.
-
- \note If using `F` and `offset` to retrieve a specific field, use
- `MONERO_FIELD` macro in `src/lmdb/util.h` which calculates the
- offset automatically.
-
- \return Value of type `F` at `offset` within `value` which has
- type `U`.
- */
- template<typename U, typename F = U, std::size_t offset = 0>
- static expect<F> get_value(MDB_val value) noexcept
- {
- static_assert(std::is_same<U, V>(), "bad MONERO_FIELD?");
- static_assert(std::is_trivially_copyable<F>(), "F must be memcpyable");
- static_assert(sizeof(F) + offset <= sizeof(U), "bad field type and/or offset");
-
- if (value.mv_size != sizeof(U))
- return {lmdb::error(MDB_BAD_VALSIZE)};
-
- F out;
- std::memcpy(std::addressof(out), static_cast<char*>(value.mv_data) + offset, sizeof(out));
- return out;
- }
-
- /*!
- \pre `cur != nullptr`.
- \param cur Active cursor on table. Returned in object on success,
- otherwise destroyed.
- \return A handle to the first key/value in the table linked
- to `cur` or an empty `key_stream`.
- */
- template<typename D>
- expect<key_stream<K, V, D>>
- static get_key_stream(std::unique_ptr<MDB_cursor, D> cur) noexcept
- {
- MONERO_PRECOND(cur != nullptr);
-
- MDB_val key;
- MDB_val value;
- const int err = mdb_cursor_get(cur.get(), &key, &value, MDB_FIRST);
- if (err)
- {
- if (err != MDB_NOTFOUND)
- return {lmdb::error(err)};
- cur.reset(); // return empty set
- }
- return key_stream<K, V, D>{std::move(cur)};
- }
-
- /*!
- \pre `cur != nullptr`.
- \param cur Active cursor on table. Returned in object on success,
- otherwise destroyed.
- \return A handle to the first value at `key` in the table linked
- to `cur` or an empty `value_stream`.
- */
- template<typename D>
- expect<value_stream<V, D>>
- static get_value_stream(K const& key, std::unique_ptr<MDB_cursor, D> cur) noexcept
- {
- MONERO_PRECOND(cur != nullptr);
-
- MDB_val key_bytes = lmdb::to_val(key);
- MDB_val value;
- const int err = mdb_cursor_get(cur.get(), &key_bytes, &value, MDB_SET);
- if (err)
- {
- if (err != MDB_NOTFOUND)
- return {lmdb::error(err)};
- cur.reset(); // return empty set
- }
- return value_stream<V, D>{std::move(cur)};
- }
- };
-} // lws_lmdb
-
### src/lmdb/lws_transaction.h
@@ -0,0 +1,96 @@
+// Copyright (c) 2018-2024, The Monero Project
+//
+// All rights reserved.
+//
+// Redistribution and use in source and binary forms, with or without modification, are
+// permitted provided that the following conditions are met:
+//
+// 1. Redistributions of source code must retain the above copyright notice, this list of
+// conditions and the following disclaimer.
+//
+// 2. Redistributions in binary form must reproduce the above copyright notice, this list
+// of conditions and the following disclaimer in the documentation and/or other
+// materials provided with the distribution.
+//
+// 3. Neither the name of the copyright holder nor the names of its contributors may be
+// used to endorse or promote products derived from this software without specific
+// prior written permission.
+//
+// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
+// EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
+// MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
+// THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+// PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
+// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
+// THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+#pragma once
+
+#include <lmdb.h>
+#include <memory>
+
+#include "lmdb/error.h"
+
+//! Uses C++ type system to differentiate between cursors
+#define MONERO_LWS_CURSOR(name) \
+ struct close_ ## name : ::lws_lmdb::close_cursor {}; \
+ using name = std::unique_ptr< MDB_cursor, close_ ## name >;
+
+namespace lws_lmdb
+{
+ struct abort_txn
+ {
+ void operator()(MDB_txn* ptr) const noexcept
+ {
+ if (ptr)
+ mdb_txn_abort(ptr);
+ }
+ };
+
+ /*!
+ Only valid if used via `create_read_txn()`. Decrements active count in
+ associated `context`, and aborts a LMDB transaction (`mdb_txn_abort`).
+ */
+ struct release_read_txn
+ {
+ void operator()(MDB_txn* ptr) const noexcept;
+ // implementation in database.cpp
+ };
+
+ /*!
+ Only valid if used via `create_write_txn()`. Decrements active count in
+ associated `context`, and aborts a LMDB transaction (`mdb_txn_abort`).
+ */
+ struct abort_write_txn
+ {
+ void operator()(MDB_txn* ptr) const noexcept
+ {
+ release_read_txn{}(ptr);
+ }
+ };
+
+ struct close_cursor
+ {
+ void operator()(MDB_cursor* ptr) const noexcept
+ {
+ if (ptr)
+ mdb_cursor_close(ptr);
+ }
+ };
+
+ template<typename D>
+ inline expect<std::unique_ptr<MDB_cursor, D>>
+ open_cursor(MDB_txn& txn, MDB_dbi tbl) noexcept
+ {
+ MDB_cursor* cur = nullptr;
+ MONERO_LMDB_CHECK(mdb_cursor_open(&txn, tbl, &cur));
+ return std::unique_ptr<MDB_cursor, D>{cur};
+ }
+
+ // The below use the C++ type system to designate `MDB_txn` status.
+
+ using suspended_txn = std::unique_ptr<MDB_txn, abort_txn>;
+ using read_txn = std::unique_ptr<MDB_txn, release_read_txn>;
+ using write_txn = std::unique_ptr<MDB_txn, abort_write_txn>;
+} // lmdb
### src/lmdb/lws_value_stream.h
@@ -1,262 +0,0 @@
-// Copyright (c) 2018-2024, The Monero Project
-
-// All rights reserved.
-//
-// Redistribution and use in source and binary forms, with or without modification, are
-// permitted provided that the following conditions are met:
-//
-// 1. Redistributions of source code must retain the above copyright notice, this list of
-// conditions and the following disclaimer.
-//
-// 2. Redistributions in binary form must reproduce the above copyright notice, this list
-// of conditions and the following disclaimer in the documentation and/or other
-// materials provided with the distribution.
-//
-// 3. Neither the name of the copyright holder nor the names of its contributors may be
-// used to endorse or promote products derived from this software without specific
-// prior written permission.
-//
-// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
-// EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
-// MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
-// THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
-// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
-// PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
-// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
-// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
-// THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-#pragma once
-
-#include <boost/range/iterator_range.hpp>
-#include <cstdint>
-#include <cstring>
-#include <iterator>
-#include <lmdb.h>
-#include <utility>
-
-#include "lmdb/value_stream.h"
-#include "span.h"
-
-namespace lws_lmdb
-{
- /*!
- An InputIterator for a fixed-sized LMDB value at a specific key.
-
- \tparam T The value type at the specific key.
- \tparam F The value type being returned when dereferenced.
- \tparam offset to `F` within `T`.
-
- \note This meets requirements for an InputIterator only. The iterator
- can only be incremented and dereferenced. All copies of an iterator
- share the same LMDB cursor, and therefore incrementing any copy will
- change the cursor state for all (incrementing an iterator will
- invalidate all prior copies of the iterator). Usage is identical
- to `std::istream_iterator`.
- */
- template<typename T, typename F = T, std::size_t offset = 0>
- class value_iterator
- {
- MDB_cursor* cur;
- epee::span<const std::uint8_t> values;
-
- void increment()
- {
- values.remove_prefix(sizeof(T));
- if (values.empty() && cur)
- values = lmdb::stream::get(*cur, MDB_NEXT_DUP, 0, sizeof(T)).second;
- }
-
- public:
- using value_type = F;
- using reference = value_type;
- using pointer = void;
- using difference_type = std::size_t;
- using iterator_category = std::input_iterator_tag;
-
- //! Construct an "end" iterator.
- value_iterator() noexcept
- : cur(nullptr), values()
- {}
-
- /*!
- \param cur Iterate over values starting at this cursor position.
- \throw std::system_error if unexpected LMDB error. This can happen
- if `cur` is invalid.
- */
- value_iterator(MDB_cursor* cur)
- : cur(cur), values()
- {
- if (cur)
- values = lmdb::stream::get(*cur, MDB_GET_CURRENT, 0, sizeof(T)).second;
- }
-
- value_iterator(value_iterator const&) = default;
- ~value_iterator() = default;
- value_iterator& operator=(value_iterator const&) = default;
-
- //! \return True if `this` is one-past the last value.
- bool is_end() const noexcept { return values.empty(); }
-
- //! \return True iff `rhs` is referencing `this` value.
- bool equal(value_iterator const& rhs) const noexcept
- {
- return
- (values.empty() && rhs.values.empty()) ||
- values.data() == rhs.values.data();
- }
-
- //! Invalidates all prior copies of the iterator.
- value_iterator& operator++()
- {
- increment();
- return *this;
- }
-
- //! \return A copy that is already invalidated, ignore
- value_iterator operator++(int)
- {
- value_iterator out{*this};
- increment();
- return out;
- }
-
- /*!
- Get a specific field within `F`. Default behavior is to return
- the entirety of `U`, despite the filtering logic of `operator*`.
-
- \pre `!is_end()`
-
- \tparam U must match `T`, used for `MONERO_FIELD` sanity checking.
- \tparam G field type to extract from the value
- \tparam uoffset to `G` type, or `0` when `std::is_same<U, G>()`.
-
- \return The field `G`, at `uoffset` within `U`.
- */
- template<typename U, typename G = U, std::size_t uoffset = 0>
- G get_value() const noexcept
- {
- static_assert(std::is_same<U, T>(), "bad MONERO_FIELD usage?");
- static_assert(std::is_trivially_copyable<U>(), "value type must be memcpyable");
- static_assert(std::is_trivially_copyable<G>(), "field type must be memcpyable");
- static_assert(sizeof(G) + uoffset <= sizeof(U), "bad field and/or offset");
- assert(sizeof(G) + uoffset <= values.size());
- assert(!is_end());
-
- G value;
- std::memcpy(std::addressof(value), values.data() + uoffset, sizeof(value));
- return value;
- }
-
- //! \pre `!is_end()` \return The field `F`, at `offset`, within `T`.
- value_type operator*() const noexcept { return get_value<T, F, offset>(); }
- };
-
- /*!
- C++ wrapper for a LMDB read-only cursor on a fixed-sized value `T`.
-
- \tparam T value type being stored by each record.
- \tparam D cleanup functor for the cursor; usually unique per db/table.
- */
- template<typename T, typename D>
- class value_stream
- {
- std::unique_ptr<MDB_cursor, D> cur;
- public:
-
- //! Take ownership of `cur` without changing position. `nullptr` valid.
- explicit value_stream(std::unique_ptr<MDB_cursor, D> cur)
- : cur(std::move(cur))
- {}
-
- value_stream(value_stream&&) = default;
- value_stream(value_stream const&) = delete;
- ~value_stream() = default;
- value_stream& operator=(value_stream&&) = default;
- value_stream& operator=(value_stream const&) = delete;
-
- /*!
- Give up ownership of the cursor. `count()`, `make_iterator()` and
- `make_range()` can still be invoked, but return the empty set.
-
- \return Currently owned LMDB cursor.
- */
- std::unique_ptr<MDB_cursor, D> give_cursor() noexcept
- {
- return {std::move(cur)};
- }
-
- /*!
- Place the stream back at the first value. Newly created iterators
- will start at the first value again.
-
- \note Invalidates all current iterators from `this`, including
- those created with `make_iterator` or `make_range`.
- */
- void reset()
- {
- if (cur)
- lmdb::stream::get(*cur, MDB_FIRST_DUP, 0, 0);
- }
-
- /*!
- \throw std::system_error if LMDB has unexpected errors.
- \return Number of values at this key.
- */
- std::size_t count() const
- {
- return lmdb::stream::count(cur.get());
- }
-
- /*!
- Return a C++ iterator over database values from current cursor
- position that will reach `.is_end()` after the last duplicate key
- record. Calling `make_iterator()` will return an iterator whose
- `operator*` will return entire value (`T`).
- `make_iterator<MONERO_FIELD(account, id)>()` will return an
- iterator whose `operator*` will return a `decltype(account.id)`
- object - the other fields in the struct `account` are never copied
- from the database.
-
- \throw std::system_error if LMDB has unexpected errors.
- \return C++ iterator starting at current cursor position.
- */
- template<typename U = T, typename F = U, std::size_t offset = 0>
- value_iterator<U, F, offset> make_iterator() const
- {
- static_assert(std::is_same<U, T>(), "was MONERO_FIELD used with wrong type?");
- return {cur.get()};
- }
-
- /*!
- Return a range from current cursor position until last duplicate
- key record. Useful in for-each range loops or in templated code
- expecting a range of elements. Calling `make_range()` will return
- a range of `T` objects. `make_range<MONERO_FIELD(account, id)>()`
- will return a range of `decltype(account.id)` objects - the other
- fields in the struct `account` are never copied from the database.
-
- \throw std::system_error if LMDB has unexpected errors.
- \return An InputIterator range over values at cursor position.
- */
- template<typename U = T, typename F = U, std::size_t offset = 0>
- boost::iterator_range<value_iterator<U, F, offset>> make_range() const
- {
- return {make_iterator<U, F, offset>(), value_iterator<U, F, offset>{}};
- }
- };
-
- template<typename T, typename F, std::size_t offset>
- inline
- bool operator==(value_iterator<T, F, offset> const& lhs, value_iterator<T, F, offset> const& rhs) noexcept
- {
- return lhs.equal(rhs);
- }
-
- template<typename T, typename F, std::size_t offset>
- inline
- bool operator!=(value_iterator<T, F, offset> const& lhs, value_iterator<T, F, offset> const& rhs) noexcept
- {
- return !lhs.equal(rhs);
- }
-} // lws_lmdb
-Why this scored 32/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.