summaryrefslogtreecommitdiff
path: root/contrib/chkpass/chkpass.c
Commit message (Collapse)AuthorAgeFilesLines
* Remove contrib/chkpassPeter Eisentraut2017-09-221-175/+0
| | | | | | | | | | | | | | The recent addition of a test suite for this module revealed a few problems. It uses a crypt() method that is no longer considered secure and doesn't work anymore on some platforms. Using a volatile input function violates internal sanity check assumptions and leads to failures on the build farm. So this module is neither a usable security tool nor a good example for an extension. No one wanted to argue for keeping or improving it, so remove it. Discussion: https://www.postgresql.org/message-id/5645b0d7-cc40-6ab5-c553-292a91091ee7%402ndquadrant.com
* Further cleanup from the strong-random patch.Heikki Linnakangas2016-12-121-2/+7
| | | | | | | | Also use the new facility for generating RADIUS authenticator requests, and salt in chkpass extension. Reword the error messages to be nicer. Fix bogus error code used in the message in BackendStartup.
* Avoid returning undefined bytes in chkpass_in().Tom Lane2015-02-141-3/+3
| | | | | | | | | | | | | | | | We can't really fix the problem that the result is defined to depend on random(), so it is still going to fail the "unstable input conversion" test in parse_type.c. However, we can at least satify valgrind. (It looks like this code used to be valgrind-clean, actually, until somebody did a careless s/strncpy/strlcpy/g on it.) In passing, let's just make real sure that chkpass_out doesn't overrun its output buffer. No need for backpatch, I think, since this is just to satisfy debugging tools. Asif Naeem
* Create function prototype as part of PG_FUNCTION_INFO_V1 macroPeter Eisentraut2014-04-181-12/+0
| | | | | | | | | | | | | | | | | Because of gcc -Wmissing-prototypes, all functions in dynamically loadable modules must have a separate prototype declaration. This is meant to detect global functions that are not declared in header files, but in cases where the function is called via dfmgr, this is redundant. Besides filling up space with boilerplate, this is a frequent source of compiler warnings in extension modules. We can fix that by creating the function prototype as part of the PG_FUNCTION_INFO_V1 macro, which such modules have to use anyway. That makes the code of modules cleaner, because there is one less place where the entry points have to be listed, and creates an additional check that functions have the right prototype. Remove now redundant prototypes from contrib and other modules.
* Prevent potential overruns of fixed-size buffers.Tom Lane2014-02-171-4/+20
| | | | | | | | | | | | | | | | | | | | | | | Coverity identified a number of places in which it couldn't prove that a string being copied into a fixed-size buffer would fit. We believe that most, perhaps all of these are in fact safe, or are copying data that is coming from a trusted source so that any overrun is not really a security issue. Nonetheless it seems prudent to forestall any risk by using strlcpy() and similar functions. Fixes by Peter Eisentraut and Jozef Mlich based on Coverity reports. In addition, fix a potential null-pointer-dereference crash in contrib/chkpass. The crypt(3) function is defined to return NULL on failure, but chkpass.c didn't check for that before using the result. The main practical case in which this could be an issue is if libc is configured to refuse to execute unapproved hashing algorithms (e.g., "FIPS mode"). This ideally should've been a separate commit, but since it touches code adjacent to one of the buffer overrun changes, I included it in this commit to avoid last-minute merge issues. This issue was reported by Honza Horak. Security: CVE-2014-0065 for buffer overruns, CVE-2014-0066 for crypt()
* chkpass: check for NULL return value from crypt()Bruce Momjian2014-01-311-1/+8
| | | | Report from Jozef Mlich using Coverity
* Remove cvs keywords from all files.Magnus Hagander2010-09-201-1/+1
|
* 8.4 pgindent run, with new combined Linux/FreeBSD/MinGW typedef listBruce Momjian2009-06-111-2/+2
| | | | provided by Andrew.
* Simplify and standardize conversions between TEXT datums and ordinary CTom Lane2008-03-251-21/+9
| | | | | | | | | | | | | | | | | | | | strings. This patch introduces four support functions cstring_to_text, cstring_to_text_with_len, text_to_cstring, and text_to_cstring_buffer, and two macros CStringGetTextDatum and TextDatumGetCString. A number of existing macros that provided variants on these themes were removed. Most of the places that need to make such conversions now require just one function or macro call, in place of the multiple notational layers that used to be needed. There are no longer any direct calls of textout or textin, and we got most of the places that were using handmade conversions via memcpy (there may be a few still lurking, though). This commit doesn't make any serious effort to eliminate transient memory leaks caused by detoasting toasted text objects before they reach text_to_cstring. We changed PG_GETARG_TEXT_P to PG_GETARG_TEXT_PP in a few places where it was easy, but much more could be done. Brendan Jurd and Tom Lane
* Replace direct assignments to VARATT_SIZEP(x) with SET_VARSIZE(x, len).Tom Lane2007-02-271-12/+14
| | | | | | | | | | | Get rid of VARATT_SIZE and VARATT_DATA, which were simply redundant with VARSIZE and VARDATA, and as a consequence almost no code was using the longer names. Rename the length fields of struct varlena and various derived structures to catch anyplace that was accessing them directly; and clean up various places so caught. In itself this patch doesn't change any behavior at all, but it is necessary infrastructure if we hope to play any games with the representation of varlena headers. Greg Stark and Tom Lane
* Replace some strncpy() by strlcpy().Peter Eisentraut2007-02-071-7/+4
|
* Fix a passel of recently-committed violations of the rule 'thou shaltTom Lane2006-07-141-3/+1
| | | | | have no other gods before c.h'. Also remove some demonstrably redundant #include lines, mostly of <errno.h> which was added to c.h years ago.
* Magic blocks don't do us any good unless we use 'em ... so install oneTom Lane2006-05-301-1/+3
| | | | in every shared library.
* Fix a few places that were checking for the return value of palloc() to beNeil Conway2006-03-191-11/+7
| | | | | non-NULL: palloc() ereports on OOM, so we can safely assume it returns a valid pointer.
* Standard pgindent run for 8.1.Bruce Momjian2005-10-151-3/+3
|
* Make sure contrib C functions are marked strict where needed.Tom Lane2005-01-291-17/+2
| | | | Kris Jurka
* make sure the $Id tags are converted to $PostgreSQL as well ...PostgreSQL Daemon2003-11-291-1/+1
|
* Remove another useless, counterproductive srandom() call.Tom Lane2003-09-071-8/+1
|
* Error message editing in contrib (mostly by Joe Conway --- thanks Joe!)Tom Lane2003-07-241-3/+5
|
* Add missing semicolons to a few PG_FUNCTION_INFO_V1 calls.Tom Lane2002-10-261-6/+6
|
* chkpass_rout returns text so change PG_RETURN_CSTRING to PG_RETURN_TEXT_P.D'Arcy J.M. Cain2002-08-291-2/+2
| | | | | This is currently a cosmetic difference but I make the change now in case the macros diverge one day.
* Fix warningPeter Eisentraut2001-12-191-3/+7
|
* New pgindent run with fixes suggested by Tom. Patch manually reviewed,Bruce Momjian2001-11-051-2/+2
| | | | initdb/regression tests pass.
* pgindent run on all C files. Java run to follow. initdb/regressionBruce Momjian2001-10-251-19/+21
| | | | tests pass.
* Further conversions to Version 1 API. Also, fix boolean return to useD'Arcy J.M. Cain2001-05-301-7/+7
| | | | PG_RETURN_BOOL(0) instead of return 0.
* Upgraded code to use the current version 1 calling conventions.D'Arcy J.M. Cain2001-05-281-32/+47
|
* Changed use of macros for extracting information. According to commentsD'Arcy J.M. Cain2001-05-271-3/+3
| | | | | | in c.h we should be using the visible structure. We should only see de-TOASTed values in this program. The old method refused to compile because the length macro was no longer an lvalue.
* Initial checkin of a contributed type that handles passwords efficiently.D'Arcy J.M. Cain2001-05-031-0/+175