harden: overflow guards, auth-user validation, TLS1.3 policy, build hardening

This commit is contained in:
2026-09-13 00:59:21 +02:00
parent 2a8941ee5c
commit a90e234eb3
9 changed files with 139 additions and 10 deletions
+7
View File
@@ -1,4 +1,5 @@
#include "daemon_conf.h"
#include "credentials.h"
#include "utils.h"
#include <ctype.h>
#include <errno.h>
@@ -192,6 +193,12 @@ static bool apply_module_key(DaemonModule* module, char* key, char* value, char*
const char* user = trim_ws(token);
if (*user == '\0')
continue;
if (!credentials_username_valid(user)) {
set_error(err, err_size, "module '%s': invalid 'auth users' entry '%s'", module->name,
user);
free(list);
return false;
}
char** grown =
realloc(module->auth_users, (size_t)(module->auth_user_count + 1) * sizeof(char*));
if (!grown) {