New sanitizer - #8810
Open
arvidn wants to merge 4 commits into
Open
Conversation
|
| Branch | new-sanitizer |
| Testbed | ubuntu-24.04 |
Click to view all benchmark results
| Benchmark | Latency | Benchmark Result nanoseconds (ns) (Result Δ%) | Upper Boundary nanoseconds (ns) (Limit %) |
|---|---|---|---|
| base-v1.torrent | 📈 view plot 🚷 view threshold | 47,710.47 ns(-20.80%)Baseline: 60,237.27 ns | 94,321.46 ns (50.58%) |
| base-v2.torrent | 📈 view plot 🚷 view threshold | 57,187.19 ns(-41.17%)Baseline: 97,207.23 ns | 170,205.64 ns (33.60%) |
| dh_compute_secret | 📈 view plot 🚷 view threshold | 37,575.22 ns(-45.97%)Baseline: 69,548.76 ns | 187,390.00 ns (20.05%) |
| dh_handshake | 📈 view plot 🚷 view threshold | 75,603.94 ns(-45.37%)Baseline: 138,391.08 ns | 369,990.63 ns (20.43%) |
| dh_key_exchange | 📈 view plot 🚷 view threshold | 38,203.34 ns(-43.69%)Baseline: 67,847.55 ns | 178,323.87 ns (21.42%) |
| ip_filter: access, hit | 📈 view plot 🚷 view threshold | 68.84 ns(+5.19%)Baseline: 65.44 ns | 82.21 ns (83.74%) |
| ip_filter: access, miss | 📈 view plot 🚷 view threshold | 70.39 ns(+8.75%)Baseline: 64.72 ns | 80.32 ns (87.64%) |
| many-pad-files.torrent | 📈 view plot 🚷 view threshold | 898,512.25 ns(-47.27%)Baseline: 1,704,089.24 ns | 7,946,741.92 ns (11.31%) |
| merkle: compute root | 📈 view plot 🚷 view threshold | 175,155.37 ns(-25.55%)Baseline: 235,250.53 ns | 511,241.04 ns (34.26%) |
| merkle: create proof | 📈 view plot 🚷 view threshold | 130.06 ns(+3.83%)Baseline: 125.27 ns | 156.68 ns (83.01%) |
| merkle: validate proof | 📈 view plot 🚷 view threshold | 2,042.68 ns(-22.87%)Baseline: 2,648.52 ns | 5,636.64 ns (36.24%) |
| piece picker: add/remove near-seed | 📈 view plot 🚷 view threshold | 138,000.12 ns(-24.10%)Baseline: 181,829.76 ns | 326,491.58 ns (42.27%) |
| piece picker: add/remove seed | 📈 view plot 🚷 view threshold | 29.93 ns(+3.31%)Baseline: 28.97 ns | 37.42 ns (79.98%) |
| piece picker: break one seed | 📈 view plot 🚷 view threshold | 128,064.45 ns(+5.11%)Baseline: 121,840.27 ns | 165,089.41 ns (77.57%) |
| piece picker: get availability | 📈 view plot 🚷 view threshold | 16,555.08 ns(-0.16%)Baseline: 16,582.09 ns | 23,393.98 ns (70.77%) |
| piece picker: mark as downloading, high index | 📈 view plot 🚷 view threshold | 99.96 ns(+4.18%)Baseline: 95.95 ns | 118.73 ns (84.19%) |
| piece picker: mark as downloading, low index | 📈 view plot 🚷 view threshold | 1,765.76 ns(+8.57%)Baseline: 1,626.35 ns | 2,212.26 ns (79.82%) |
| piece picker: pick pieces, after dirty | 📈 view plot 🚷 view threshold | 986,007.17 ns(+0.98%)Baseline: 976,470.20 ns | 1,267,500.41 ns (77.79%) |
| piece picker: pick pieces, clean | 📈 view plot 🚷 view threshold | 43.38 ns(-1.70%)Baseline: 44.13 ns | 52.95 ns (81.92%) |
| piece picker: pick pieces, dense peer | 📈 view plot 🚷 view threshold | 45.10 ns(-0.04%)Baseline: 45.12 ns | 54.27 ns (83.10%) |
| piece picker: pick pieces, sparse peer | 📈 view plot 🚷 view threshold | 283,196.49 ns(-10.86%)Baseline: 317,686.35 ns | 653,264.06 ns (43.35%) |
| piece picker: piece priorities | 📈 view plot 🚷 view threshold | 19,276.02 ns(+4.10%)Baseline: 18,516.80 ns | 23,004.66 ns (83.79%) |
| piece picker: refcount bitfield, 1 bit set | 📈 view plot 🚷 view threshold | 4,935.13 ns(-93.37%)Baseline: 74,460.48 ns | 291,728.59 ns (1.69%) |
| piece picker: refcount bitfield, 10 bits set | 📈 view plot 🚷 view threshold | 5,158.85 ns(-93.12%)Baseline: 74,984.04 ns | 292,980.57 ns (1.76%) |
| piece picker: refcount bitfield, 200 bits set | 📈 view plot 🚷 view threshold | 7,289.68 ns(-90.57%)Baseline: 77,288.52 ns | 297,028.27 ns (2.45%) |
| piece picker: refcount bitfield, 49 bits set | 📈 view plot 🚷 view threshold | 6,112.53 ns(-91.88%)Baseline: 75,321.80 ns | 292,431.83 ns (2.09%) |
| piece picker: refcount bitfield, 50 bits set | 📈 view plot 🚷 view threshold | 6,136.02 ns(-91.86%)Baseline: 75,347.06 ns | 292,567.24 ns (2.10%) |
| piece picker: refcount bitfield, 5000 bits set | 📈 view plot 🚷 view threshold | 39,918.59 ns(-59.25%)Baseline: 97,954.84 ns | 296,058.56 ns (13.48%) |
| rc4_encrypt | 📈 view plot 🚷 view threshold | 30,162.12 ns(-6.96%)Baseline: 32,419.11 ns | 47,447.68 ns (63.57%) |
arvidn
marked this pull request as draft
August 29, 2026 10:25
arvidn
force-pushed
the
new-sanitizer
branch
6 times, most recently
from
September 2, 2026 08:00
5b3b384 to
c59b7b4
Compare
arvidn
marked this pull request as ready for review
September 2, 2026 08:31
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
sanitize_flags deserialization currently casts signed resume-data integers directly to uint32_t without range validation, allowing negative/out-of-range values to wrap into unintended flag sets.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR introduces versioned, configurable filename/path sanitization rules via a new path_sanitize_flags_t bitfield, threads the selected ruleset through torrent parsing and lifetime, and persists it in resume data to avoid silent filename changes across libtorrent upgrades.
Changes:
- Add
path_sanitize_flags_t(+ documented historical rulesets anddefault_flags) and expose it viaload_torrent_limits::sanitize_flagsandadd_torrent_params::sanitize_flags. - Persist/restore
sanitize_flagsin resume data and pin it to torrents (including metadata-on-arrival cases like magnet links). - Add/extend unit tests and fuzz coverage for sanitization behavior and resume-data/version fallback logic.
File summaries
| File | Description |
|---|---|
| test/test_torrent_info.cpp | Updates sanitizer helper/tests to be flag-driven and adds coverage for new rules. |
| test/test_sanitizer.cpp | New test exercising combinations of sanitization flags against a purpose-built torrent. |
| test/test_resume.cpp | Adds tests for resume-data sanitize_flags roundtrips and version-based fallback behavior. |
| test/Jamfile | Adds test_sanitizer to test runs/aliases. |
| src/write_resume_data.cpp | Writes sanitize_flags into resume data. |
| src/torrent.cpp | Pins sanitize_flags on torrents and reuses it when parsing metadata later. |
| src/torrent_info.cpp | Implements flag-controlled sanitization rules (invalid chars, formatting chars, DOS reserved names, unicode length counting, trimming). |
| src/read_resume_data.cpp | Reads sanitize_flags (or infers it from writer version) and passes it into torrent parsing. |
| src/load_torrent.cpp | Stamps the parsing ruleset onto returned add_torrent_params. |
| Makefile | Installs new public header and adds test + test torrent to build lists. |
| include/libtorrent/torrent_info.hpp | Extends load_torrent_limits and updates aux::sanitize_path_element() signature to accept limits (incl. sanitize flags). |
| include/libtorrent/path_sanitize_flags.hpp | New public header defining sanitization flags and versioned rulesets. |
| include/libtorrent/libtorrent.hpp | Exposes the new public header via the umbrella include. |
| include/libtorrent/aux_/torrent.hpp | Stores pinned sanitize_flags in torrent internal state and exposes an accessor. |
| include/libtorrent/add_torrent_params.hpp | Adds add_torrent_params::sanitize_flags with documentation about pinning/compatibility. |
| fuzzers/src/torrent_info.cpp | Exercises multiple real-world sanitize rulesets in the fuzzer. |
| fuzzers/src/sanitize_path.cpp | Fuzzes sanitize_path_element() under several rulesets. |
| docs/upgrade_to_2.2.rst | Documents configurable sanitization and the compatibility behavior. |
| docs/hunspell/libtorrent.dic | Adds new sanitizer-related terms to the dictionary. |
| CMakeLists.txt | Installs the new public header. |
| ChangeLog | Notes versioned path-sanitization feature. |
| bindings/python/tests/torrent_info_test.py | Adds Python test coverage for load_torrent_limits.sanitize_flags. |
| bindings/python/src/torrent_info.cpp | Parses sanitize_flags from Python load_torrent_limits dict. |
| bindings/python/src/session.cpp | Exposes add_torrent_params.sanitize_flags and path_sanitize_flags constants to Python. |
| bindings/python/src/converters.cpp | Adds Python converters for path_sanitize_flags_t. |
| bindings/python/libtorrent/init.pyi | Updates stubs for sanitize_flags and introduces path_sanitize_flags constants. |
Review details
- Files reviewed: 26/27 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
arvidn
force-pushed
the
new-sanitizer
branch
from
September 3, 2026 01:21
c59b7b4 to
9784715
Compare
arvidn
force-pushed
the
new-sanitizer
branch
from
September 3, 2026 07:11
9784715 to
f95f4e2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
introduce options for filename sanitization. As a field on
add_torrent_paramsit's saved and restored with resume data, to preserve backwards compatibility.