| Message ID | 20240708210912.566-4-chipitsine@gmail.com |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:298e:b0:59e:d24b:d55c with SMTP id
f14csp2081907max;
Mon, 8 Jul 2024 14:10:17 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AJvYcCUKDrSPL4V3LJtQl2ku7bCXmmazMroSbYxOdhsTcZTbT5BQx2rL4KJQt41DsuGskF1XpBxg5kwKjwleZ1Sgt2xVj4cO+Z4=
X-Google-Smtp-Source:
AGHT+IG1QDxFb44xPjHzyIkKTts+racWFnpZx6T2Nml8sks6/LLH46ODaNwUd75gunCttxaY49Dn
X-Received: by 2002:a17:902:dacb:b0:1fb:19fc:1b44 with SMTP id
d9443c01a7336-1fbb6ec4ef6mr6882185ad.3.1720473016976;
Mon, 08 Jul 2024 14:10:16 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1720473016; cv=none;
d=google.com; s=arc-20160816;
b=bL1AtnPy5rlAmNegBvyjgsWUDRpa1UJseCVvDZnsaW4aIegxjlUoSQGs3Hnx4YS/Lc
MZXN6vvegodTEUHnr1ZywkGbZNgIZoa3fCNB1QPPo52ewsAr/EPTkx3Je5/cJoCnMwh+
Bf8MK0X01Wp9+vhrmDMxoynmDMzMO+AccM5FgqFxJEk1benM30fVHjxIdgAFljGBwUC/
5as5qheC1YHQpfaO9gt6qyKf8yqHy8z9160aNpsAt20e9oyhGZRrXX4GMdVp5tMG0Ezz
KVElQ+txVBDm9Q7Oq2zVYFLV/zAqnImWLrI5R8qMQDDXSGLaLJGxbFGjIJ9Hgxh5zRIB
blmQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20160816;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=9GU+S36f89OeSF0CO+hpcRdsYQyujqbDVpmra/l7goA=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=yhVH9FTcMuX97+CvFRPxC9EDcg957aVq4dZaFMF0j2GFWkKm92beCHvXEDaWfDNeyF
Pn2uwh7EC6mMuaLX6B/K/P166LtRAsvbYUnTEKWGrY42IavQPnMHOybq4d7iOh6vRMjn
pZDt6iiaGLpKGjcnTiLf4B1jzdAz0N4uxWwOZRxb/DLqe9LonoKg8tmRBJoDgY2DMYxy
4r6igwJcyccSkWSlG75xEkv6GO/VqIcbT/aQIuv9p+NJXWGIxHAdePaLXDVdTKEWa0yh
CwR25y8WMWrwAVxyVim/J/vzML9xIdHQarSK7kDxSiFVp9LrIvYCupybG5SiHq+yFpzT
uMHw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=DAfLM+LE;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=JFu667KV;
dkim=neutral (body hash did not verify) header.i=@gmail.com
header.s=20230601 header.b=WHKFPGDs;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com;
dara=fail header.i=@openvpn.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
d9443c01a7336-1fbb6ad00e0si5026825ad.565.2024.07.08.14.10.16
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Mon, 08 Jul 2024 14:10:16 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=DAfLM+LE;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=JFu667KV;
dkim=neutral (body hash did not verify) header.i=@gmail.com
header.s=20230601 header.b=WHKFPGDs;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com;
dara=fail header.i=@openvpn.net
Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com)
by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1sQvcH-0005Zo-7h;
Mon, 08 Jul 2024 21:09:46 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <chipitsine@gmail.com>) id 1sQvcF-0005Zc-Pa
for openvpn-devel@lists.sourceforge.net;
Mon, 08 Jul 2024 21:09:45 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=Iu652Sjz7Kk9Lmkg96SKh5v7WAbeork+s2ixnBBHtPg=; b=DAfLM+LEG31PNhBrr2KOHnlZHi
hHO3wp35jvaWDOSo1w2Vc3K5enuXgRnY0XQDFD+5U+rY+bcG4r7M1vzLR2HSm7Z/DCi52+tkbpsm0
aiFK93qDr47svDXyST+mzKpQWqNwrD/+WyVmUkKhqE0Uk3x4JTHaGPUzW6RmOj7JS/ws=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=Iu652Sjz7Kk9Lmkg96SKh5v7WAbeork+s2ixnBBHtPg=; b=JFu667KVV6Sdow7FKl+C4oApWV
yasm7AF0hA08eHPZkJMdCclyqEtTJS9vNgSH8UWV2jxOiuI48h0wiAvzsm7zMEATq3IDI8EkcandY
rS1GBLvxaAFLCROAM+FtDPpxgrfcEXmQjIM6JcTQJLOsGe7urXi/2amjwBbp2ILePlOk=;
Received: from mail-wr1-f49.google.com ([209.85.221.49])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95)
id 1sQvcF-0000Ra-CR for openvpn-devel@lists.sourceforge.net;
Mon, 08 Jul 2024 21:09:44 +0000
Received: by mail-wr1-f49.google.com with SMTP id
ffacd0b85a97d-367963ea053so3734802f8f.2
for <openvpn-devel@lists.sourceforge.net>;
Mon, 08 Jul 2024 14:09:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1720472973; x=1721077773;
darn=lists.sourceforge.net;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:from:to:cc:subject:date
:message-id:reply-to;
bh=Iu652Sjz7Kk9Lmkg96SKh5v7WAbeork+s2ixnBBHtPg=;
b=WHKFPGDsItK3oyWekOg66je5jQ8GmF5YaJ6IqwHKKMuBjGLdH6eFmvqGUPLSI5WCv+
JXYXXR/aRFsZ0t9kVhOp8M6foU3OhXEunCPx927dWPaO5Io6IyJrxWZyNGKOnRXE6tu5
64QNw4lohLu8po50NGKgj+GQc6zm7dIzBJlP2OD+rDMvsqIqkqYb2GwvgyctmTCqglap
1ycjXN4Oru8VoRbfMEfQoPxw4j3EYxt1RF2vuUe8C0w4nqCz7a81dvvcIvWAh89tsKMs
zrmd8SLJ2TE5JlxjYVhlA5E+HN4N0b6WzxCSDtYCOqVZWagNMZ0JDaqxXr1GvwtKhBa+
cqWA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1720472973; x=1721077773;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=Iu652Sjz7Kk9Lmkg96SKh5v7WAbeork+s2ixnBBHtPg=;
b=QO3X49WtfufnIcM6np+Ei8hySX0HwlHGyMTpdU6wO7AJ8gV+ie6HG4G8iLA8BiblB0
/+1xHpficVwtn3Q0JjXnHputEYoAC1LZTldF9VIFNJ0v2spL4dEXDmQNmWn1vEX0SkuT
3uQhy8CKRxkw+JN0+FbGYi3pYCpg/LJ+TC9c3C3BozJnn8IIFJ9DU6POMpppXeo0/DRR
VlOYwuOvdLYBUDYbh/UXsCegzL3ej3hCDYK8KDgkB0GLrEp/2g0ETPOBcaaffwYHBUuc
cc21424FYvk60k6DjWsIcJ12QG60EALgELwY7g0xA8oq2mcARUSoyR1Sf5fl9DgH6RHr
F7wA==
X-Gm-Message-State: AOJu0Yzawfrlmxn/VXJZUH1+L1/Nin3hjsUyuZ2MW1PUd3/lodJPXDO1
usHhBldqhR2NldVQRCbd8vNzl71TeNuAZ60h5p7mveJhBsom8C26JuDagg==
X-Received: by 2002:a5d:5258:0:b0:366:ec30:adcd with SMTP id
ffacd0b85a97d-367cea45ce7mr593144f8f.7.1720472973454;
Mon, 08 Jul 2024 14:09:33 -0700 (PDT)
Received: from localhost.localdomain (109-93-166-140.dynamic.isp.telekom.rs.
[109.93.166.140]) by smtp.gmail.com with ESMTPSA id
ffacd0b85a97d-367cdfa079asm684977f8f.68.2024.07.08.14.09.32
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Mon, 08 Jul 2024 14:09:32 -0700 (PDT)
From: Ilia Shipitsin <chipitsine@gmail.com>
To: openvpn-devel@lists.sourceforge.net
Date: Mon, 8 Jul 2024 23:08:20 +0200
Message-ID: <20240708210912.566-4-chipitsine@gmail.com>
X-Mailer: git-send-email 2.43.0.windows.1
In-Reply-To: <20240708210912.566-1-chipitsine@gmail.com>
References: <20240708210912.566-1-chipitsine@gmail.com>
MIME-Version: 1.0
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "util-spamd-1.v13.lw.sourceforge.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Signed-off-by: Ilia Shipitsin --- src/openvpn/auth_token.c
| 8 ++++++++ 1 file changed,
8 insertions(+) diff --git a/src/openvpn/auth_token.c
b/src/openvpn/auth_token.c index 6787ea7d..2278afe6 100644 ---
a/src/openvpn/auth_token.c
+++ b/src/openvpn/auth_token.c @@ -260,6 +260,10 @@ generate_auth_token(
[...] Content analysis details: (-0.2 points, 6.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
DNSWL was blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information. [209.85.221.49 listed in list.dnswl.org]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.221.49 listed in bl.score.senderscore.com]
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE:
The query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.221.49 listed in sa-trusted.bondedsender.org]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail
provider [chipitsine[at]gmail.com]
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily
valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.221.49 listed in wl.mailspike.net]
X-Headers-End: 1sQvcF-0000Ra-CR
Subject: [Openvpn-devel] [PATCH 3/5] src/openvpn/auth_token.c: handle strdup
errors
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1804046714495206782?=
X-GMAIL-MSGID: =?utf-8?q?1804046714495206782?=
|
| Series |
handle strdup errors
|
|
Commit Message
Илья Шипицин
July 8, 2024, 9:08 p.m. UTC
Signed-off-by: Ilia Shipitsin <chipitsine@gmail.com>
---
src/openvpn/auth_token.c | 8 ++++++++
1 file changed, 8 insertions(+)
Comments
Hi, On Mon, Jul 08, 2024 at 11:08:20PM +0200, Ilia Shipitsin wrote: > multi->auth_token = strdup((char *)BPTR(&session_token)); > + if (!multi->auth_token) > + { > + msg( M_FATAL, "Failed allocate memory for multi->auth_token"); > + } I do wonder if this is the right approach here. For "openvpn itself" we have the check_malloc_return() macro, which will purposely not call msg() - as msg() does internal malloc()s, and if we cannot allocate 20 bytes for an auth_token, the chance that msg() will not succeed is fairly high... In plugins or unit tests, the infrastructure is different, but for 3/ and 4/, please resend with multi->auth_token = strdup((char *)BPTR(&session_token)); + check_malloc_return(multi->auth_token); (etc) gert
I'll have a look, thanks! On Mon, Sep 9, 2024, 09:30 Gert Doering <gert@greenie.muc.de> wrote: > Hi, > > On Mon, Jul 08, 2024 at 11:08:20PM +0200, Ilia Shipitsin wrote: > > multi->auth_token = strdup((char *)BPTR(&session_token)); > > + if (!multi->auth_token) > > + { > > + msg( M_FATAL, "Failed allocate memory for multi->auth_token"); > > + } > > I do wonder if this is the right approach here. For "openvpn itself" > we have the check_malloc_return() macro, which will purposely not call > msg() - as msg() does internal malloc()s, and if we cannot allocate > 20 bytes for an auth_token, the chance that msg() will not succeed is > fairly high... > > In plugins or unit tests, the infrastructure is different, but for 3/ and > 4/, please resend with > > multi->auth_token = strdup((char *)BPTR(&session_token)); > + check_malloc_return(multi->auth_token); > > (etc) > > gert > -- > "If was one thing all people took for granted, was conviction that if you > feed honest figures into a computer, honest figures come out. Never > doubted > it myself till I met a computer with a sense of humor." > Robert A. Heinlein, The Moon is a Harsh > Mistress > > Gert Doering - Munich, Germany > gert@greenie.muc.de >
diff --git a/src/openvpn/auth_token.c b/src/openvpn/auth_token.c index 6787ea7d..2278afe6 100644 --- a/src/openvpn/auth_token.c +++ b/src/openvpn/auth_token.c @@ -260,6 +260,10 @@ generate_auth_token(const struct user_pass *up, struct tls_multi *multi) /* free the auth-token if defined, we will replace it with a new one */ free(multi->auth_token); multi->auth_token = strdup((char *)BPTR(&session_token)); + if (!multi->auth_token) + { + msg( M_FATAL, "Failed allocate memory for multi->auth_token"); + } dmsg(D_SHOW_KEYS, "Generated token for client: %s (%s)", multi->auth_token, up->username); @@ -271,6 +275,10 @@ generate_auth_token(const struct user_pass *up, struct tls_multi *multi) * and timestamp in updates */ multi->auth_token_initial = strdup(multi->auth_token); + if (!multi->auth_token_initial) + { + msg( M_FATAL, "Failed allocate memory for multi->auth_token_initial"); + } } gc_free(&gc);