Fix umask and password memory wipe (#294)

* Fix debug build segfault: add strong overrides for psql_lock/unlock functions

The weak/strong symbol approach requires that psql.c undefs the debug
macros to define function implementations. This means functions in psql.c
call psql_lock()/psql_unlock() as functions, not macros.

In debug builds, these must be strong overrides that call the _do_
variants to properly maintain lockctr/rdlockctr. Without these overrides,
the weak stubs are used which don't update counters, causing assertion
failures in psql_unlock().

Added strong overrides in psql_debug.c for:
- psql_lock() -> psql_do_lock(__FILE__, __LINE__)
- psql_rdlock() -> psql_do_rdlock(__FILE__, __LINE__)
- psql_statement() (calls psql_do_lock directly)

Also made psql_statement, psql_start, and all query/prepare functions
weak in psql.c to allow debug overrides.

Fixes #138

* Fix umask and password memory wipe

- Set umask(0077) in daemonize() to prevent world-readable files
- Wipe password from memory after psync_set_user_pass()

Fixes #203, #204

---------

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
This commit is contained in:
Levi Neely 2026-03-03 11:20:07 +01:00 committed by GitHub
parent 61259858c8
commit c0cc893cc7
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 2 additions and 1 deletions

View File

@ -485,7 +485,7 @@ int daemonize(bool do_commands) {
}
/* Open any logs here */
umask(0);
umask(0077);
sid = setsid();
if (sid < 0) {
exit(EXIT_FAILURE);

View File

@ -442,6 +442,7 @@ static void status_change(pstatus_t *status) {
psync_set_user_pass(clib::pclsync_lib::get_lib().get_username().c_str(),
clib::pclsync_lib::get_lib().get_password().c_str(),
(int)clib::pclsync_lib::get_lib().save_pass_);
clib::pclsync_lib::get_lib().wipe_password();
std::cout << "logging in" << std::endl;
} else if (status->status == PSTATUS_TFA_REQUIRED) {
if (clib::pclsync_lib::get_lib().get_tfa_code().empty()) {