git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 10/16] contrib/git-credential-gnome-keyring.c: use secure memory functions for passwds

From
BCBrandon Casey <bcasey@nvidia.com>
Date
Sep 23, 2013, 18:49 UTC
Message-ID
<1379962157-1338-11-git-send-email-bcasey@nvidia.com>
In-Reply-To
<1379962157-1338-1-git-send-email-bcasey@nvidia.com>
From: Brandon Casey <drafnel@gmail.com>

gnome-keyring provides functions for allocating non-pageable memory (if possible) intended to be used for storing passwords. Let's use them.

Signed-off-by: Brandon Casey <drafnel@gmail.com>
---
 .../gnome-keyring/git-credential-gnome-keyring.c    | 21 ++++++---------------
 1 file changed, 6 insertions(+), 15 deletions(-)
diff --git a/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c b/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
index b692e1f..d8a7038 100644
--- a/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
+++ b/contrib/credential/gnome-keyring/git-credential-gnome-keyring.c
@@ -30,6 +30,7 @@
 #include <errno.h>
 #include <glib.h>
 #include <gnome-keyring.h>
+#include <gnome-keyring-memory.h>
 
 /*
  * This credential struct and API is simplified from git's credential.{h,c}
@@ -60,16 +61,6 @@ struct credential_operation
 
 /* ---------------- common helper functions ----------------- */
 
-static inline void free_password(char *password)
-{
-	char *c = password;
-	if (!password)
-		return;
-
-	while (*c) *c++ = '\0';
-	free(password);
-}
-
 static inline void warning(const char *fmt, ...)
 {
 	va_list ap;
@@ -159,8 +150,8 @@ static int keyring_get(struct credential *c)
 	/* pick the first one from the list */
 	password_data = (GnomeKeyringNetworkPasswordData *) entries->data;
 
-	free_password(c->password);
-	c->password = xstrdup(password_data->password);
+	gnome_keyring_memory_free(c->password);
+	c->password = gnome_keyring_memory_strdup(password_data->password);
 
 	if (!c->username)
 		c->username = xstrdup(password_data->user);
@@ -291,7 +282,7 @@ static void credential_clear(struct credential *c)
 	free(c->host);
 	free(c->path);
 	free(c->username);
-	free_password(c->password);
+	gnome_keyring_memory_free(c->password);
 
 	credential_init(c);
 }
@@ -338,8 +329,8 @@ static int credential_read(struct credential *c)
 			free(c->username);
 			c->username = xstrdup(value);
 		} else if (!strcmp(key, "password")) {
-			free_password(c->password);
-			c->password = xstrdup(value);
+			gnome_keyring_memory_free(c->password);
+			c->password = gnome_keyring_memory_strdup(value);
 			while (*value) *value++ = '\0';
 		}
 		/*
-- 
1.8.4.rc4.6.g5555d19


-----------------------------------------------------------------------------------
This email message is for the sole use of the intended recipient(s) and may contain
confidential information.  Any unauthorized review, use, disclosure or distribution
is prohibited.  If you are not the intended recipient, please contact the sender by
reply email and destroy all copies of the original message.
-----------------------------------------------------------------------------------
Previous: Brandon CaseyNext: Brandon Casey
Message 11 of 23 in “Make Gnome Credential helper more Gnome-y and support ancient distros”
  1. 00/16 Make Gnome Credential helper more Gnome-y and support ancient distrosBrandon Casey, Sep 23, 2013
  2. 01/16 contrib/git-credential-gnome-keyring.c: remove unnecessary pre-declarationsBrandon Casey, Sep 23, 2013
  3. 02/16 contrib/git-credential-gnome-keyring.c: remove unused die() functionBrandon Casey, Sep 23, 2013
  4. 03/16 contrib/git-credential-gnome-keyring.c: *style* use "if ()" not "if()" etc.Brandon Casey, Sep 23, 2013
  5. 04/16 contrib/git-credential-gnome-keyring.c: add static where applicableBrandon Casey, Sep 23, 2013
  6. 05/16 contrib/git-credential-gnome-keyring.c: exit non-zero when called incorrectlyBrandon Casey, Sep 23, 2013
  7. 06/16 contrib/git-credential-gnome-keyring.c: strlen() returns size_t, not ssize_tBrandon Casey, Sep 23, 2013
  8. 07/16 contrib/git-credential-gnome-keyring.c: ensure buffer is non-empty before accessingBrandon Casey, Sep 23, 2013
  9. 08/16 contrib/git-credential-gnome-keyring.c: set Gnome application nameBrandon Casey, Sep 23, 2013
  10. 09/16 contrib/git-credential-gnome-keyring.c: use gnome helpers in keyring_object()Brandon Casey, Sep 23, 2013
  11. 10/16 contrib/git-credential-gnome-keyring.c: use secure memory functions for passwdsBrandon Casey, Sep 23, 2013
  12. 11/16 contrib/git-credential-gnome-keyring.c: use secure memory for reading passwordsBrandon Casey, Sep 23, 2013
  13. 12/16 contrib/git-credential-gnome-keyring.c: use glib memory allocation functionsBrandon Casey, Sep 23, 2013
  14. 13/16 contrib/git-credential-gnome-keyring.c: use glib messaging functionsBrandon Casey, Sep 23, 2013
  15. 14/16 contrib/git-credential-gnome-keyring.c: report failure to store passwordBrandon Casey, Sep 23, 2013
  16. 15/16 contrib/git-credential-gnome-keyring.c: support ancient gnome-keyringBrandon Casey, Sep 23, 2013
  17. Felipe ContrerasSep 23, 2013
  18. 16/16 contrib/git-credential-gnome-keyring.c: support really ancient gnome-keyringBrandon Casey, Sep 23, 2013
  19. Felipe ContrerasSep 23, 2013
  20. Jeff KingSep 24, 2013
  21. Junio C HamanoOct 15, 2013
  22. Brandon CaseyOct 15, 2013
  23. Junio C HamanoOct 16, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.