git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 09/15] contrib/git-credential-gnome-keyring.c: use secure memory functions for passwds

From
Brandon Casey <drafnel@gmail.com>
Date
Sep 23, 2013, 05:08 UTC
Message-ID
<1379912891-12277-10-git-send-email-drafnel@gmail.com>
In-Reply-To
<1379912891-12277-1-git-send-email-drafnel@gmail.com>

gnome-keyring provides functions for allocating non-pageable memory (if possible) intended to be used for storing passwords. Let's use them.

Signed-off-by: Brandon Casey <drafnel@gmail.com>
---
 .../gnome-keyring/git-credential-gnome-keyring.c    | 21 ++++++---------------
 1 file changed, 6 insertions(+), 15 deletions(-)
diff --git a/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c b/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
index 7565765..ff2f48c 100644
--- a/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
+++ b/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
@@ -30,6 +30,7 @@
 #include <errno.h>
 #include <glib.h>
 #include <gnome-keyring.h>
+#include <gnome-keyring-memory.h>
 
 /*
  * This credential struct and API is simplified from git's credential.{h,c}
@@ -60,16 +61,6 @@ struct credential_operation
 
 /* ---------------- common helper functions ----------------- */
 
-static inline void free_password(char *password)
-{
-	char *c = password;
-	if (!password)
-		return;
-
-	while (*c) *c++ = '\0';
-	free(password);
-}
-
 static inline void warning(const char *fmt, ...)
 {
 	va_list ap;
@@ -159,8 +150,8 @@ static int keyring_get(struct credential *c)
 	/* pick the first one from the list */
 	password_data = (GnomeKeyringNetworkPasswordData *) entries->data;
 
-	free_password(c->password);
-	c->password = xstrdup(password_data->password);
+	gnome_keyring_memory_free(c->password);
+	c->password = gnome_keyring_memory_strdup(password_data->password);
 
 	if (!c->username)
 		c->username = xstrdup(password_data->user);
@@ -291,7 +282,7 @@ static void credential_clear(struct credential *c)
 	free(c->host);
 	free(c->path);
 	free(c->username);
-	free_password(c->password);
+	gnome_keyring_memory_free(c->password);
 
 	credential_init(c);
 }
@@ -338,8 +329,8 @@ static int credential_read(struct credential *c)
 			free(c->username);
 			c->username = xstrdup(value);
 		} else if (!strcmp(key, "password")) {
-			free_password(c->password);
-			c->password = xstrdup(value);
+			gnome_keyring_memory_free(c->password);
+			c->password = gnome_keyring_memory_strdup(value);
 			while (*value) *value++ = '\0';
 		}
 		/*
-- 
1.8.4.489.g545bc72
Previous: Brandon CaseyNext: Brandon Casey
Message 12 of 20 in “Make Gnome Credential helper more Gnome-y and support ancient distros”
  1. 00/15 Make Gnome Credential helper more Gnome-y and support ancient distrosBrandon Casey, Sep 23, 2013
  2. 01/15 contrib/git-credential-gnome-keyring.c: remove unnecessary pre-declarationsBrandon Casey, Sep 23, 2013
  3. 02/15 contrib/git-credential-gnome-keyring.c: remove unused die() functionBrandon Casey, Sep 23, 2013
  4. 03/15 contrib/git-credential-gnome-keyring.c: add static where applicableBrandon Casey, Sep 23, 2013
  5. 04/15 contrib/git-credential-gnome-keyring.c: exit non-zero when called incorrectlyBrandon Casey, Sep 23, 2013
  6. 05/15 contrib/git-credential-gnome-keyring.c: set Gnome application nameBrandon Casey, Sep 23, 2013
  7. 06/15 contrib/git-credential-gnome-keyring.c: strlen() returns size_t, not ssize_tBrandon Casey, Sep 23, 2013
  8. 07/15 contrib/git-credential-gnome-keyring.c: ensure buffer is non-empty before accessingBrandon Casey, Sep 23, 2013
  9. Felipe ContrerasSep 23, 2013
  10. Brandon CaseySep 23, 2013
  11. 08/15 contrib/git-credential-gnome-keyring.c: use gnome helpers in keyring_object()Brandon Casey, Sep 23, 2013
  12. 09/15 contrib/git-credential-gnome-keyring.c: use secure memory functions for passwdsBrandon Casey, Sep 23, 2013
  13. 10/15 contrib/git-credential-gnome-keyring.c: use secure memory for reading passwordsBrandon Casey, Sep 23, 2013
  14. 11/15 contrib/git-credential-gnome-keyring.c: use glib memory allocation functionsBrandon Casey, Sep 23, 2013
  15. 12/15 contrib/git-credential-gnome-keyring.c: use glib messaging functionsBrandon Casey, Sep 23, 2013
  16. 13/15 contrib/git-credential-gnome-keyring.c: report failure to store passwordBrandon Casey, Sep 23, 2013
  17. 14/15 contrib/git-credential-gnome-keyring.c: support ancient gnome-keyringBrandon Casey, Sep 23, 2013
  18. 15/15 contrib/git-credential-gnome-keyring.c: support really ancient gnome-keyringBrandon Casey, Sep 23, 2013
  19. John SzakmeisterSep 23, 2013
  20. Brandon CaseySep 23, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.