about summary refs log tree commit diff
path: root/shared/nm-utils/nm-secret-utils.c
diff options
context:
space:
mode:
authorSebastien Bacher <seb128@ubuntu.com>2019-05-10 15:07:08 +0200
committerSebastien Bacher <seb128@ubuntu.com>2019-05-22 13:41:30 +0200
commitd57a1dd26f8e9859252b0983c2d2ec3b95eb5714 (patch)
tree46f1146e87af8cc7b58b751f7e575bd0abb2f59d /shared/nm-utils/nm-secret-utils.c
parentad9ed8bfb963266b4eea524131845f406cfc55d7 (diff)
parent85563b7fc7ec2cd21e38debb9b28db342e2e8e7c (diff)
Import Debian changes 1.18.0-1ubuntu1
network-manager (1.18.0-1ubuntu1) eoan; urgency=medium

  * Update to 1.18, merge on Debian, new version includes nwe support for
    policy routing rules and for VLAN filtering for Linux bridge.
  * Remaining Ubuntu changes
    - Use systemd-resolved instead of dnsmasq
    - debian/control:
      + Depend on isc-dhcp-client instead of recommends
      + Recommend network-manager-pptp
      + Suggest avahi-autoipd for IPv4LL support
    - debian/rules, debian/network-manager.postinst:
      + Don't restart NetworkManager on upgrade but recommend restarting
        the computer
    - debian/rules, debian/network-manager.postinst:
      + Don't install sysvinit scripts or migrate from sysvinit
    - debian/network-manager.postinst:
      + Don't add the netdev group.
      + drop in an empty override file for NetworkManager to manage all
        devices for upgrade from any version, as long as there is no
        netplan configuration yet.
    - debian/default-wifi-powersave-on.conf, debian/rules:
      + Install a config file to enable WiFi powersave
    - Enable build tests
    - Add autopkgtests
    - debian/source_network-manager.py, debian/network-manager.install,
      debian/network-manager.links: Add apport hook
    - Add network-manager-config-connectivity-ubuntu package
    - NetworkManager.conf: disable MAC randomization feature. There is no
      easy way for desktop users to disable this feature yet. And there are
      reports that it doesn't work well with some systems.
    - Update Vcs links to point to Ubuntu branch
    - Add patches. See patch descriptions for more details:
      + Provide-access-to-some-of-NM-s-interfaces-to-whoopsie.patch
      + Update-dnsmasq-parameters.patch
      + Disable-general-with-expect.patch
      + libnm-Check-self-still-NMManager-or-not.patch
      + dns-manager-don-t-merge-split-DNS-search-domains.patch (but disabled)
      + Read-system-connections-from-run.patch
    - debian/tests/urfkill-integration - don't stop/start network manager
    - Revert "Add Conflicts to network-manager-dev against deprecated libraries"
      This reverts commit b4acc5e03e2b821e1cccc69529bb70826c741942.  We're still
      building libnm-glib for now, so these packages have a use in Ubuntu.
  * Removed delta, not needed anymore
    - debian/network-manager.maintscript
      + Remove /etc/dbus-1/system.d/nm-ofono.conf
Diffstat (limited to 'shared/nm-utils/nm-secret-utils.c')
-rw-r--r--shared/nm-utils/nm-secret-utils.c161
1 files changed, 0 insertions, 161 deletions
diff --git a/shared/nm-utils/nm-secret-utils.c b/shared/nm-utils/nm-secret-utils.c
deleted file mode 100644
index ec5cc6b1..00000000
--- a/shared/nm-utils/nm-secret-utils.c
+++ /dev/null
@@ -1,161 +0,0 @@
-/* -*- Mode: C; tab-width: 4; indent-tabs-mode: t; c-basic-offset: 4 -*- */
-/* NetworkManager -- Network link manager
- *
- * This library is free software; you can redistribute it and/or
- * modify it under the terms of the GNU Lesser General Public
- * License as published by the Free Software Foundation; either
- * version 2 of the License, or (at your option) any later version.
- *
- * This library is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
- * Lesser General Public License for more details.
- *
- * You should have received a copy of the GNU Lesser General Public
- * License along with this library; if not, write to the
- * Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
- * Boston, MA 02110-1301 USA.
- *
- * (C) Copyright 2018 Red Hat, Inc.
- * (C) Copyright 2015 - 2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- */
-
-#include "nm-default.h"
-
-#include "nm-secret-utils.h"
-
-/*****************************************************************************/
-
-void
-nm_explicit_bzero (void *s, gsize n)
-{
-	/* gracefully handle n == 0. This is important, callers rely on it. */
-	if (n > 0) {
-		nm_assert (s);
-#if defined (HAVE_DECL_EXPLICIT_BZERO) && HAVE_DECL_EXPLICIT_BZERO
-		explicit_bzero (s, n);
-#else
-		/* don't bother with a workaround. Use a reasonable glibc. */
-		memset (s, 0, n);
-#endif
-	}
-}
-
-/*****************************************************************************/
-
-char *
-nm_secret_strchomp (char *secret)
-{
-	gsize len;
-
-	g_return_val_if_fail (secret, NULL);
-
-	/* it's actually identical to g_strchomp(). However,
-	 * the glib function does not document, that it clears the
-	 * memory. For @secret, we don't only want to truncate trailing
-	 * spaces, we want to overwrite them with NUL. */
-
-	len = strlen (secret);
-	while (len--) {
-		if (g_ascii_isspace ((guchar) secret[len]))
-			secret[len] = '\0';
-		else
-			break;
-	}
-
-	return secret;
-}
-
-/*****************************************************************************/
-
-GBytes *
-nm_secret_copy_to_gbytes (gconstpointer mem, gsize mem_len)
-{
-	NMSecretBuf *b;
-
-	if (mem_len == 0)
-		return g_bytes_new_static ("", 0);
-
-	nm_assert (mem);
-
-	/* NUL terminate the buffer.
-	 *
-	 * The entire buffer is already malloc'ed and likely has some room for padding.
-	 * Thus, in many situations, this additional byte will cause no overhead in
-	 * practice.
-	 *
-	 * Even if it causes an overhead, do it just for safety. Yes, the returned
-	 * bytes is not a NUL terminated string and no user must rely on this. Do
-	 * not treat binary data as NUL terminated strings, unless you know what
-	 * you are doing. Anyway, defensive FTW.
-	 */
-
-	b = nm_secret_buf_new (mem_len + 1);
-	memcpy (b->bin, mem, mem_len);
-	b->bin[mem_len] = 0;
-	return nm_secret_buf_to_gbytes_take (b, mem_len);
-}
-
-/*****************************************************************************/
-
-NMSecretBuf *
-nm_secret_buf_new (gsize len)
-{
-	NMSecretBuf *secret;
-
-	nm_assert (len > 0);
-
-	secret = g_malloc (sizeof (NMSecretBuf) + len);
-	*((gsize *) &(secret->len)) = len;
-	return secret;
-}
-
-static void
-_secret_buf_free (gpointer user_data)
-{
-	NMSecretBuf *secret = user_data;
-
-	nm_assert (secret);
-	nm_assert (secret->len > 0);
-
-	nm_explicit_bzero (secret->bin, secret->len);
-	g_free (user_data);
-}
-
-GBytes *
-nm_secret_buf_to_gbytes_take (NMSecretBuf *secret, gssize actual_len)
-{
-	nm_assert (secret);
-	nm_assert (secret->len > 0);
-	nm_assert (actual_len == -1 || (actual_len >= 0 && actual_len <= secret->len));
-	return g_bytes_new_with_free_func (secret->bin,
-	                                   actual_len >= 0 ? (gsize) actual_len : secret->len,
-	                                   _secret_buf_free,
-	                                   secret);
-}
-
-/*****************************************************************************/
-
-/**
- * nm_utils_memeqzero_secret:
- * @data: the data pointer to check (may be %NULL if @length is zero).
- * @length: the number of bytes to check.
- *
- * Checks that all bytes are zero. This always takes the same amount
- * of time to prevent timing attacks.
- *
- * Returns: whether all bytes are zero.
- */
-gboolean
-nm_utils_memeqzero_secret (gconstpointer data, gsize length)
-{
-	const guint8 *const key = data;
-	volatile guint8 acc = 0;
-	gsize i;
-
-	for (i = 0; i < length; i++) {
-		acc |= key[i];
-		asm volatile("" : "=r"(acc) : "0"(acc));
-	}
-	return 1 & ((acc - 1) >> 8);
-}