FreeBSD src
Go to file
Colin Percival b6be9566d2 Fix buffer overflow in preloaded hostuuid cleaning
When a module of type "hostuuid" is provided by the loader,
prison0_init strips any trailing whitespace and ASCII control
characters by (a) adjusting the buffer length, and (b) zeroing out
the characters in question, before storing it as the system's
hostuuid.

The buffer length adjustment was correct, but the zeroing overwrote
one byte higher in memory than intended -- in the typical case,
zeroing one byte past the end of the hostuuid buffer.  Due to the
layout of buffers passed by the boot loader to the kernel, this will
be the first byte of a subsequent buffer.

This was *probably* harmless; prison0_init runs after preloaded kernel
modules have been linked and after the preloaded /boot/entropy cache
has been processed, so in both cases having the first byte overwritten
will not cause problems.  We cannot however rule out the possibility
that other objects which are preloaded by the loader could suffer from
having the first byte overwritten.

Since the zeroing does not in fact serve any purpose, remove it and
trim trailing whitespace and ASCII control characters by adjusting
the buffer length alone.

Fixes:		c3188289 Preload hostuuid for early-boot use
Reviewed by:	kevans, markj
MFC after:	3 days
2021-05-17 20:07:49 -07:00
.github/workflows Enable GitHub actions CI for stable/13 as well 2021-04-20 09:51:33 +01:00
bin sh: implement persistent history storage 2021-05-10 18:57:13 +02:00
cddl dtrace tests: Fix tst.system.d after ping/ping6 unification 2021-04-23 10:28:09 -04:00
contrib sort: Make NetBSD sort tests compatible with our sort 2021-05-13 09:33:47 -04:00
crypto kerberos.8: Replace dead link 2021-05-16 01:37:09 -04:00
etc sort: Hook NetBSD tests up to the build 2021-05-13 09:34:01 -04:00
gnu dialog: fix macro redefinition 2021-03-01 16:01:44 +01:00
include Vendor import of Gavin D. Howard's bc version 4.0.2 2021-05-12 07:35:58 +02:00
kerberos5 kerberos5: fix the WITH_OPENLDAP build 2021-01-30 00:07:50 -06:00
lib libpmc: fall-back to kernel tables if pmu-events fails 2021-05-13 16:01:24 -03:00
libexec ipfw: reload sysctl.conf variables if needed 2021-05-18 04:03:15 +07:00
release pkgbase: Put openssl in its own package 2021-05-13 17:42:29 +02:00
rescue ping: add a ping6 hard link for backwards compatibility 2020-11-26 18:33:04 +00:00
sbin Correct assert added to dump program. 2021-05-17 16:34:53 -07:00
secure pkgbase: Put openssl in its own package 2021-05-13 17:42:29 +02:00
share Add myself (ygy) as a ports committer 2021-05-16 23:54:25 -04:00
stand loader: gfx_fb_drawrect should use GfxFbBltVideoFill 2021-05-16 11:22:37 +03:00
sys Fix buffer overflow in preloaded hostuuid cleaning 2021-05-17 20:07:49 -07:00
targets Remove kgmon(8) 2021-04-04 00:50:28 +03:00
tests pf tests: More set skip on <ifgroup> tests 2021-05-17 13:48:06 +02:00
tools git-arc(1): fix usage formatting for stage command 2021-05-14 17:34:04 -03:00
usr.bin sort: Hook NetBSD tests up to the build 2021-05-13 09:34:01 -04:00
usr.sbin fstyp(8): define HAVE_ZFS macro when built with zfs 2021-05-14 13:00:24 -08:00
.arcconfig Remove history.immutable from .arcconfig 2021-04-13 12:36:25 +01:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.cirrus.yml Restore Cirrus-CI boot smoke test 2021-05-05 10:05:58 -04:00
.clang-format clang-format: Avoid breaking after the opening paren of function definitions 2020-10-28 11:54:00 +00:00
.gitattributes Add a basic clang-format configuration file 2019-06-07 15:23:52 +00:00
.gitignore gitignore: expand list of ignored files 2021-01-14 17:03:57 +01:00
COPYRIGHT copyrights: Happy New Year 2021 2020-12-31 10:29:44 -05:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Add a pointer to csprng@ for the CSPRNG driver. This is enforced anyway by 2020-09-01 08:02:12 +00:00
Makefile Fix 'make bmake' top-level bootstrapping. 2021-03-06 09:45:08 -08:00
Makefile.inc1 Makefile.inc1: unbreak bootstrap when kbdcontrol does not exist 2021-03-23 20:47:14 -04:00
Makefile.libcompat libcompat: remove redundant path for ncurses 2021-01-07 15:14:52 +01:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc Correct location of libcap_random.so in ObsoleteFiles.inc 2021-05-12 20:34:23 +02:00
README.md Revert "sqlite3: Vendor import of sqlite3 3.35.5" 2021-05-06 13:08:52 -07:00
RELNOTES Spellcheck. 2021-04-12 15:12:19 -07:00
UPDATING UPDATING: fix spelling 2021-05-13 20:26:10 +02:00

FreeBSD Source:

This is the top level of the FreeBSD source directory.

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), FreeBSD handbook on building userland, and Handbook for kernels for more information, including setting make(1) variables.

Source Roadmap:

Directory Description
bin System/user commands.
cddl Various commands and libraries under the Common Development and Distribution License.
contrib Packages contributed by 3rd parties.
crypto Cryptography stuff (see crypto/README).
etc Template files for /etc.
gnu Various commands and libraries under the GNU Public License. Please see gnu/COPYING and gnu/COPYING.LIB for more information.
include System include files.
kerberos5 Kerberos5 (Heimdal) package.
lib System libraries.
libexec System daemons.
release Release building Makefile & associated tools.
rescue Build system for statically linked /rescue utilities.
sbin System commands.
secure Cryptographic libraries and commands.
share Shared resources.
stand Boot loader sources.
sys Kernel sources.
sys/arch/conf Kernel configuration files. GENERIC is the configuration used in release builds. NOTES contains documentation of all possible entries.
tests Regression tests which can be run by Kyua. See tests/README for additional information.
tools Utilities for regression testing and miscellaneous tasks.
usr.bin User commands.
usr.sbin System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see FreeBSD Handbook.