fix(d5-daemon-auth): address auth review findings (Wave B)
- test_credentials.c: NUL-terminate the overlong-line stack buffer before make_tmp_file's strlen() (was a stack-buffer-overflow READ under ASan); still exercises the overlong-rejection path. - Add redacted protocol string variants (protocol_send_str_redacted / receive + fd send_str_redacted/receive_str_redacted) and use them for the daemon auth username/digest so --verbose / LOG_DEBUG_ALL never logs a replayable credential while other protocol strings keep their debug trace. - credentials_verify/gate: replace byte-wise-short-circuiting strcmp with a fixed-length constant-time username compare (closes user-enumeration oracle); update doc comment to match. - read_secret_file: preserve password exact bytes (only strip trailing CR/LF) and burn the stack line buffer; document the whitespace behavior. - test_server_cli.c: note the parser zero-inits opts on failure. - Add debug-level daemon test asserting the digest never appears under --verbose. PROTOCOL_VERSION stays 2.15.0.
This commit is contained in:
@@ -101,6 +101,9 @@ static void test_server_cli_preserves_existing_flags() {
|
||||
}
|
||||
|
||||
static void test_server_cli_conflicts() {
|
||||
/* server_cli_parse zero-initializes opts (server_cli_options_default) before
|
||||
* parsing, so `opts` is still safe to pass to server_cli_options_free even
|
||||
* when every parse below returns -1 on failure. */
|
||||
char err[256];
|
||||
ServerCliOptions opts;
|
||||
const char* a1[] = {"s", "--daemon", "--stdio"};
|
||||
|
||||
Reference in New Issue
Block a user